What is output by a neural network, such as an image classifier, is only a small portion of what the network in a sense "knows" about the data. And the prospect that the network is retaining sensitive user data such as social security numbers could open a new area of concern about AI.