AIToday
Large Language ModelsAI Safety & AlignmentAI Regulation & PolicyITmedia AI+Published: Sep 4, 2026, 16:00 JST2 min read

RIZAP employee uploads client data to personal AI service

RIZAP employee uploads client data to personal AI service

Key takeaway

  • A RIZAP employee uploaded customer data to a personal AI service. The data included names, emails, and health details.

  • RIZAP says no third party accessed or used it.

  • They reported to regulators and will contact affected customers.

3 Key Points

  1. What happened

    Fitness company RIZAP reported on September 3 that an employee mistakenly uploaded customer information to an external generative AI service used for personal purposes during work on data for the government's specific health guidance program.

  2. Why it matters

    The data included insurance symbols, email addresses, names, birth dates, genders, partial addresses and phone numbers, plus sensitive personal details like support type and disease info. RIZAP said it confirmed no third-party viewing or use for AI training, but is still checking if the service provider's staff could have seen the data.

  3. What to watch

    RIZAP has notified the Personal Information Protection Commission and will contact affected individuals. It reiterated an internal ban on unauthorized generative AI services to prevent recurrence.

Ask the AI about this article →

Context & Analysis

This incident highlights risks when employees use personal AI tools for work tasks. RIZAP's data was part of a national health checkup and guidance system, making the breach sensitive. The company's confirmation that no third party saw the data or used it for training is a key mitigation, but ongoing checks about the provider's access suggest uncertainty remains.

RIZAP's response—reporting to the commission and notifying affected individuals—shows standard procedure for such leaks. The company's reminder about its ban on unauthorized AI services indicates a focus on internal policy enforcement. However, the fact that an employee used a personal service for work suggests a gap between policy and practice. This could drive other firms to reassess their own AI usage guidelines.

FAQ

What type of data was exposed?
The leaked data included insurance policy numbers, email addresses, names, birth dates, gender, partial addresses and phone numbers, as well as sensitive health guidance support details and disease information.
What is RIZAP doing in response?
RIZAP reported the incident to the Personal Information Protection Commission, will notify affected individuals, and reiterated its ban on unauthorized generative AI services.
Was the data used for AI training?
RIZAP confirmed that no third party outside the AI service provider viewed the data or used it for AI training.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Infosys and CrowdStrike partner on AI-discovered vulnerabilitiesSiliconANGLE AI · 35m ago
  • Cisco sets zero-engineers-coding targetDIGITIMES Asia · 35m ago
  • OpenAI's Astra model thinks beyond human oversightSemafor Tech · 35m ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleNadella: Azure customers already using OpenAI's Astra model