How to Use AI With Your Privacy Intact


If the tech industry sought to create a method of seducing users into sending their deepest, most sensitive secrets to a server in a faraway data center, it would be hard-pressed to create a better honeypot than an AI chatbot.

OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini, and their countless smaller competitors have become therapists, sounding boards, and virtual confession booths for millions of people around the world. Almost all of those AI models are set by default to collect and store that highly private data with, in many cases, no restrictions on how it’s shared or sold, used to further train the tools, or handed over to any lawsuit plaintiff or law enforcement agency that demands it through a legal process.

“You have this intelligent thing staring back at you, and you’re basically telling it, one question at a time, every possible thing there is to know about your life,” says Matt Green, a privacy- and security-focused computer science professor at Johns Hopkins University. “You’re giving it this huge profile on you.”

A decade ago, text messages represented perhaps the most personal, sensitive data that most people shared from their devices, says cryptographer and software developer Moxie Marlinspike. The surveillance dangers invited by unprotected texting are what pushed him in 2014 to create Signal, the end-to-end encrypted messenger now used by well over a hundred million people. Now, he says, that critical point of privacy vulnerability has shifted to people’s interactions with AI.

“Those same things I was concerned about with messaging are happening in the AI space, but several orders of magnitude more significantly,” says Marlinspike. “People are integrating AI into their personal lives. They talk with it about their deepest insecurities, their finances, their health, their relationships.”

So earlier this year, Marlinspike launched Confer, an AI chatbot designed to allow users to ask it anything while preserving their privacy, using cryptography to technically prevent the service’s own server from being able to surveil or log their conversations. “Confer is designed to be a service where you can explore ideas without your own thoughts potentially conspiring against you someday,” he wrote in a blog post introducing it.

Marlinspike’s private AI tool is, in fact, just one standout among a new generation of AI services that promise to remedy the pervasive privacy invasion that these chatbots represent. Some advertise that they never record conversations as a policy. Others offer to anonymize them. A few, like Confer, seek to create actual technological guardrails that restrict their own access to users’ secrets.

The result of that nascent competition to create less surveillance-prone AI is a growing crowd of tools, often ones that offer confusing assurances for users as they seek to adopt an increasingly unavoidable technology without losing control of their secrets. Here’s WIRED’s guide to using AI with your privacy intact.

Zero Data Retention

When you start typing into one of the big three AI chatbots—ChatGPT, Claude, or Gemini—it’s safest to start with a baseline expectation of approximately zero real privacy from anyone who is determined to access your conversation records and has a legal path to obtaining them. That includes the owner of the service, advertisers or other companies they partner with, contractors who help fine-tune the systems, law enforcement agencies, or even someone who manages to subpoena the records as part of a civil lawsuit.

The simplest, strong exception to that rule is a contract between you—or more likely, your employer—and an AI provider that legally prevents them from retaining those records, a provision that’s come to be known as zero data retention, or ZDR. OpenAI, Anthropic, and Google all offer ZDR policies for their enterprise versions, which when enabled generally require that they immediately delete records of users’ interactions with a chatbot as soon as they’re processed.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *