RAG Data Leakage in AI Agents

Retrieval-augmented generation creates a security boundary around indexes, chunks, metadata, query expansion, summaries, and retained evidence.

A restricted source fragment crosses from one document compartment into another user's response.
Check what crosses the retrieval boundary.

What is RAG Data Leakage?

RAG data leakage happens when retrieval, context assembly, generated responses, citations, memory, or logs expose information beyond the requester's authority.

The model may never query a database directly yet still reveal protected information through retrieved passages or generated summaries.

Where this shows up in real agent workflows.

The exact exposure depends on authority, connected systems, identity, approval state, and evidence quality.

01

Scenario

A customer assistant retrieves another customer's contract.

02

Scenario

A policy bot summarizes restricted HR material.

03

Scenario

Raw retrieved passages are stored in broadly visible logs.

Why it matters

  • Cross-tenant or cross-role exposure.
  • Compliance risk from excessive context retention.
  • Reduced trust in enterprise knowledge assistants.

How attackers exploit it

  • Ask broad questions that cross permission boundaries.
  • Induce the agent to reveal source snippets.
  • Exploit weak metadata filters or over-broad service accounts.

How to detect and test for rag data leakage.

Detection signals

  • Answers include content the requester cannot access directly.
  • Retrieval traces cross tenant, role, or sensitivity boundaries.
  • Logs retain sensitive context unnecessarily.

Test methods

  • Use role-based test users and canary documents.
  • Verify retrieval permissions before generation.
  • Review response, citation, memory, and log outputs.