Privacy risks from medical AI tools are not shared equally

August 7, 2026

(Nature) – Privacy attacks can reveal whether someone’s medical data was used to train an AI model. People who differ from the majority are the most vulnerable to such attacks.

The use of artificial-intelligence tools in medicine has hinged on an implicit bargain. Patients and health systems permit sensitive records to be used for research, usually after de-identification so that names and other pieces of personal information are removed. In return, researchers and developers create tools that could improve health care, for example by enabling earlier diagnoses and new treatments. This bargain relies on the assumption that it is impossible for people who have access to an AI model to infer information about individuals whose data were used to train it. Writing in Nature, Knolle et al.1 show that, in the context of powerful machine-learning models, this assumption is often untrue. (Read More)