FDEInterviews logo
AI Security, Privacy & Governance / 34
hardOpenAIGleanMicrosoft

Write the incident runbook for a data-leak-via-model event: the assistant showed one customer's data to another.

Cross-tenant or cross-user data exposure through a model is the breach that starts regulatory clocks. The runbook has to answer 'whose data, to whom, how many' from logs that most teams never designed for, and contain a leak that may live in a cache or a fine-tuned model, not a deploy.

Updated Aug 2026 · Grounded in real Forward Deployed Engineer interview loops and written to a senior-engineer editorial bar.

Cross-tenant or cross-user data exposure through a model is the breach that starts regulatory clocks. The runbook has to answer 'whose data, to whom, how many' from logs that most teams never designed for, and contain a leak that may live in a cache or a fine-tuned model, not a deploy.

20 answers per topic instead of 10, plus saved progress and bookmarks · no cardor unlock all 523 remaining answers · ₹2,000 / $25
UP NEXT ON YOUR JOURNEY
FEDITOR'S NOTE

This is narrower than the general AI-incident question on purpose: the harm class is confirmed data exposure, so notification clocks dominate the timeline and the forensic question is 'reconstruct disclosure scope from the audit trail.' The instant-fail is treating it as a quality bug and tuning prompts while the GDPR 72-hour clock runs. The senior move is naming the leak source taxonomy (retrieval ACL gap, shared cache, fine-tuned weights, log exposure) because the containment and the can-we-even-fix-it answer differ completely across them, and being honest that a leak baked into weights is not deletable.

DISCUSSION · 0

No comments yet — be the first to share your approach.