AIToday
Large Language ModelsAI Safety & AlignmentAI Regulation & PolicyITmedia AI+Published: Sep 4, 2026, 13:01 JST2 min read

RIZAP employee leaks client data via personal AI

RIZAP employee leaks client data via personal AI

Key takeaway

  • RIZAP Group apologized after an employee leaked client data to a personal AI.

  • The leak included names, medical conditions, and insurance details.

  • RIZAP says the data was not used for AI training.

3 Key Points

  1. What happened

    RIZAP Group apologized on September 3 after a subsidiary employee mistakenly uploaded client personal data, including names and medical conditions, to a personal external generative AI service. The company has not disclosed the number of cases.

  2. Why it matters

    The leaked data came from RIZAP's specific health guidance system and included sensitive personal information such as insurance card numbers, addresses, phone numbers, and disease details for hypertension and diabetes. This raises serious privacy concerns for clients and business partners.

  3. What to watch

    RIZAP says the AI operator confirmed the files were not used for model training, but it is still checking whether the operator's staff could have viewed the data. The company will notify affected clients and partners individually once confirmed.

Ask the AI about this article →

Context & Analysis

RIZAP Group's apology highlights the risks of employees using personal AI tools for work-related tasks. The company, which provides health guidance services to corporations and health insurance associations, saw a worker upload sensitive client data during a data aggregation task. The leak included names, medical conditions, and insurance details—information that could cause significant harm if misused.

The company says the AI operator confirmed that files containing personally identifiable information are not used for model training, and because the data was deleted within 24 hours, it believes the data was not used for learning. However, RIZAP is still checking whether the operator's staff could have viewed the information. This uncertainty is a key concern for affected clients.

In response, RIZAP is reiterating its ban on using unauthorized generative AI for business, continuing education on data protection, and considering adopting an AI management system alongside its existing information security management system. This incident serves as a reminder that even with safeguards, the human factor remains a critical vulnerability in data security.

FAQ

What data was leaked?
The leaked data included names, birthdates, gender, insurance card numbers, email addresses, and for some people, home addresses and phone numbers. It also included sensitive health information like hypertension and diabetes status.
When did the leak happen?
The data was registered in the specific health guidance management system between January 1 and August 19. The upload occurred during a data aggregation task, and the company deleted the chat history within 24 hours.
What is RIZAP doing in response?
RIZAP reported the incident to the Personal Information Protection Commission and is coordinating notifications to affected clients and partners. It also plans to ban unauthorized AI use, continue education, and consider adopting an AI management system.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Infosys and CrowdStrike partner on AI-discovered vulnerabilitiesSiliconANGLE AI · 1h ago
  • Cisco sets zero-engineers-coding targetDIGITIMES Asia · 1h ago
  • OpenAI's Astra model thinks beyond human oversightSemafor Tech · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articlePalantir Stock Surges on Expanded PwC AI Deal