Medical AI privacy risks fall unevenly
Medical AI development has relied on a trade-off in which patients and health systems allow sensitive records to be used for research after de-identification. The expectation is that removing names and other personal details protects individuals while enabling tools that could improve care, including earlier diagnoses and new treatments.
Powerful machine-learning models can weaken that privacy bargain. Privacy attacks can reveal whether someone’s medical data was used to train an AI model, challenging the assumption that access to a model cannot expose information about its training data. The risk is not distributed evenly: people whose data differ from the majority are the most vulnerable, raising concerns that medical AI systems may create unequal privacy burdens alongside their clinical promise.