Why is this possible ???
The real question is why is the 'AI' trained on such data ???
By now you know that if the data is 'in' the 'AI' then it can be extracted with the right prompting.
If you do not give the 'AI' access to stuff that is 'risky' then you cannot suffer from the 'risky data' being used/extracted by Ne'er-do-wells.
This highlights the dubious methodology of training the 'AI' on as much data as you can 'hoover up' on the pretext that the more you throw at the 'AI' the better it will be !!!
You are telling ALL the potential customers of these 'AI' systems that 'your data is at risk if you give it to the 'AI'' ... BUT don't worry we are getting 'better' at hiding the 'good stuff' .... NOT !!!
How 'flawed' does this 'AI' mania, with NEW flaws appearing everyday, have to get before you decide that there has to be a better way !!!
'AI' is a Sci-Fi dream that however much you may want it cannot be delivered with current technology.
'Pretend intelligent' computers solves a problem that DID NOT exist ... BUT does create a whole new set of problems that you did not have before 'AI' was conceived !!!
'AI' is 'Artificial problem creation' for any business that cares about its data and the security/privacy issues that go with holding large amounts of data.
:)