This extensive report examines the security risks associated with using confidential material in ChatGPT models, particularly for Transmission System Operators (TSOs) like Denmark’s Energinet, which manage critical national infrastructure. It thoroughly analyses how the use of uncontrolled external AI models, such as those from OpenAI, conflicts with crucial legislation including GDPR and the NIS2 Directive, potentially leading to data leakage, unauthorised access, and compliance breaches. The document outlines various scenarios where confidential information could be compromised and contrasts the risk profiles of public cloud-based AI versus on-premise solutions. Finally, it proposes a range of technical and organisational measures to mitigate these risks, aiming to balance the efficiency and innovation offered by AI with the imperative for robust security.
