The tech industry’s endeavor to entice users into disclosing their most personal secrets to distant servers has found a formidable ally in AI chatbots. Platforms like OpenAI’s ChatGPT, Anthropic’s Claude, and Google’s Gemini have evolved into virtual therapists and confessionals for millions globally. These AI models typically operate under default settings that allow for the collection and storage of sensitive data, often lacking strict guidelines on data sharing or usage. This means that the information could potentially be utilized for further training, or even disclosed to legal authorities when demanded through lawful requests.
Matt Green, a professor specializing in privacy and security at Johns Hopkins University, notes the implications of engaging with these AI systems. Users frequently share detailed aspects of their lives, building comprehensive profiles that may be susceptible to exploitation. The reality is that the exchange of information has shifted from traditional text messaging—which many once regarded as personal—to interactions with AI, illustrating a new vulnerability. Moxie Marlinspike, a prominent cryptographer and the creator of the encrypted messaging app Signal, asserts that the risk of surveillance is far more significant in AI interactions compared to earlier forms of digital communication.
In response to these challenges, Marlinspike has developed Confer, an AI chatbot that prioritizes user privacy through cryptographic protections. This tool is designed to enable personal exploration without the fear of future ramifications from disclosed thoughts. As highlighted in his introduction to Confer, the goal is to allow users to engage freely without the potential for their private musings to betray them later.
Confer represents a growing segment of AI tools that advocate for user privacy. Some services profess not to retain conversations, while others propose anonymization strategies. However, few take the additional step of implementing technological barriers that restrict their own access to users’ sensitive discussions. This competition among platforms focused on reducing surveillance has resulted in a diverse range of offerings, leaving users to navigate the complexities of adopting new technology without compromising their privacy.
When engaging with major AI chatbots like ChatGPT, Claude, or Gemini, users should begin with an understanding that true privacy may be elusive. Those determined to access conversation logs—ranging from service providers and advertisers to law enforcement—can potentially do so, especially in jurisdictions where legal pathways exist. Exceptions to this reality are few; one notable avenue is the zero data retention (ZDR) agreements offered by various AI firms to enterprise clients, which mandate the immediate deletion of user interactions post-processing.
This landscape of AI technology and privacy demands that business owners stay vigilant. Cybersecurity risks are dynamically evolving, as exemplified by shifting vulnerabilities from text messaging to AI interactions. Adopting AI technologies comes with inherent responsibilities, particularly in understanding the implications for data privacy and user confidentiality.
The attacks leveraging AI technologies can often align with tactics in the MITRE ATT&CK Matrix, particularly concerning initial access, where attackers may exploit user data for entry, or employ techniques related to persistence and privilege escalation. Those engaged in AI interactions may need to consider the full spectrum of threats, ensuring robust safeguards against potential exploitation. As the sophistication of cyber threats grows, maintaining control over sensitive user information becomes essential for securing both personal and organizational data.