π€ Prompts and privacy
1. Key Themes
Theme 1: AI Chatbots Are the Most Intimate Data Collection Tool Ever Built
Chatbots elicit a qualitatively different β and more dangerous β category of personal disclosure than prior platforms. The shift from "what did you search?" to "what did you confide?" creates a surveillance surface with no real regulatory guardrails.
"People use them to ask about health, money, work and relationships β potentially creating a more intimate record of their concerns."
"Few rules directly govern that scenario today, making AI companies' promises about how they use consumer data especially consequential."
Theme 2: The Real Privacy Question Has Shifted from Training to Real-Time Use
The industry and press have fixated on whether AI companies use prompts for model training. The article argues this is already the wrong frame β the more consequential question is how data shapes the system's understanding of you right now.
"The key distinction is no longer whether a company trains on your prompts. It is whether those prompts can shape the system's understanding of you β and what else that understanding can be used to do."
Theme 3: AI Data Expansion Is Moving Beyond the Chat Window
Companies are actively building mechanisms to ingest broader behavioral data β app usage, browsing history, uploaded photos β not just chat transcripts.
"OpenAI last week announced an optional Computer History feature that lets ChatGPT retain a record of the apps and websites a person uses."
"Google, meanwhile, said last month it will use photos and other material people upload through Search to train its AI systems by default, though users can opt out."
Theme 4: Agent Interoperability Is Becoming a Major Infrastructure Layer
The move of Google's Agent2Agent (A2A) Protocol to the Agentic AI Foundation signals that the industry is coalescing around open standards that allow AI agents from different vendors to communicate β a foundational infrastructure shift that will determine how enterprise AI stacks are built.
"Putting A2A alongside MCP and related projects could help push the industry toward more modular, model-agnostic AI systems β giving companies more flexibility to choose providers based on cost, performance, latency or other needs."
"Companies don't want just one protocol; they want the whole stack to be open." β Mazin Gilbert, AAIF Executive Director
Theme 5: Advertising Is the Latent Business Model Inside AI Chatbots
Meta, Google, and OpenAI are all exploring chatbot advertising. If the pattern from search and social media repeats, engagement maximization becomes a structural incentive β with uniquely intimate data as the fuel.
"Meta, Google and OpenAI are all exploring different approaches to advertising on their chatbots."
"If consumer AI follows the path of search and social media, advertising could become a far more significant part of the business β creating an incentive for chatbot makers to increase engagement."
2. Contrarian Perspectives
Contrarian 1: Privacy features may actually limit product utility β and that's a deliberate tradeoff, not a free lunch
Apple's on-device and Private Cloud Compute approach is positioned as the gold standard for privacy. But the article notes this architecture comes with a real cost: it limits the system's ability to retain history and personalize over time. For most consumers, the tradeoff is invisible until they experience a less capable assistant.
"That approach can limit how much of a user's history Apple can retain and use for ongoing personalization."
Contrarian 2: "Opt-out" is the new default data grab β and most users won't notice
Google's decision to train on uploaded media by default β with opt-out available β represents a significant normalization of data extraction under the guise of user choice. The framing as consumer-friendly ("you can opt out") obscures the power asymmetry.
"Google...said last month it will use photos and other material people upload through Search to train its AI systems by default, though users can opt out."
Contrarian 3: Chinese open-weight models closing in on U.S. frontier capabilities in cybersecurity domains is an underappreciated national security risk
The brief mention of GLM-5.3 is easy to gloss over, but the specific capability highlighted β finding and exploiting security flaws β is one of the highest-stakes AI application areas. A Chinese open-weight model approaching U.S. frontier performance in this domain has significant offensive cyber implications.
"The release of GLM-5.3 on Friday highlights how Chinese open-weight models are closing in on U.S. frontier models' ability to find and exploit security flaws."
3. Companies Identified
OpenAI Description: Developer of ChatGPT, the leading consumer AI chatbot Why mentioned: Expanding data collection beyond chat to include full computer activity history via an opt-in feature Quote: "OpenAI last week announced an optional Computer History feature that lets ChatGPT retain a record of the apps and websites a person uses."
Google Description: Multinational tech company; creator of the A2A Protocol and operator of Search and AI products Why mentioned: Two separate contexts: (1) using uploaded search media to train AI by default, and (2) originating the A2A Protocol now being handed to an independent foundation Quote: "Google...said last month it will use photos and other material people upload through Search to train its AI systems by default, though users can opt out."
Meta Description: Parent company of Facebook, Instagram, and WhatsApp; developer of Meta AI Why mentioned: Has the broadest stated data-use policy among major AI companies β can use chatbot interactions to personalize ads across its entire platform ecosystem, including via smart glasses Quote: "The company says it can use interactions with Meta AI to personalize content and ads across its services, including some interactions through its smart glasses."
Apple Description: Consumer technology company; developer of Apple Intelligence Why mentioned: Cited as the most privacy-protective approach among major AI providers, using on-device processing and Private Cloud Compute Quote: "Apple, for example, offers the most private option with Apple Intelligence requests on a user's device...Apple uses Private Cloud Compute, a system it says uses data only to fulfill the request and does not make that content accessible to Apple."
Anthropic Description: AI safety-focused AI company; developer of Claude Why mentioned: Cited as a key backer of the Agentic AI Foundation; also separately noted for withholding a stronger internal model from public release due to AI risk concerns Quote: "Anthropic will not release a slightly stronger model it is testing internally."
Agentic AI Foundation (AAIF) Description: Emerging standards body focused on agentic AI, housed under the Linux Foundation Why mentioned: New home for the A2A Protocol; has grown from under 40 to over 250 members since December 2025 Quote: "From its launch in December 2025, AAIF says it has grown from fewer than 40 members to more than 250, with key backers including Google, Microsoft, Amazon, Anthropic, OpenAI, Bloomberg, as well as Shopify and Block."
Teleport Description: Cybersecurity company focused on infrastructure access Why mentioned: Newsletter sponsor; promoting a whitepaper on "Agent Trust" as an extension of Zero Trust security for AI agent environments Quote: "AI agents are neither human nor machine β they act at machine speed with human unpredictability, and can produce globally destructive outcomes."
Duolingo Description: Language-learning app Why mentioned: Lighter end-of-newsletter item β restored a hospitalized child's learning streak, triggering a viral wave of users submitting their own excuse stories Quote: "Duolingo stepped in to restore the 301-day streak of a 10-year-old who had an unexpected trip to the hospital."
4. People Identified
Miranda Bogen Title: Chief Technologist, Center for Democracy & Technology Why mentioned: Provided the most pointed expert warning in the article about the structural incentives to monetize intimate AI-gathered data Quote: "Without robust privacy protections, the incentive to monetize that knowledge will be hard to resist." / "The more a system knows about you, the easier it will be to make escalating requests for private details in a way that feels natural."
Rao Surapaneni Title: VP, Google Cloud Why mentioned: Explained the business rationale behind creating A2A β enterprises deploying agents from multiple vendors need them to interoperate Quote: "When we first envisioned A2A, the hypothesis was customers are deploying agentic systems from multiple technology providers and platform providers."
Mazin Gilbert Title: Executive Director, Agentic AI Foundation Why mentioned: Articulated the distinction between an open protocol and a fully open stack β signaling that industry ambitions go beyond a single interoperability standard Quote: "There's a big difference between an open protocol and open standard, and having an open protocol becoming interoperable with the entire stack."
Ina Fried Title: Reporter/Author, Axios AI+ Why mentioned: Author of both the AI privacy and A2A stories; framing and editorial lens reflects Axios's broader "What They Know About You" series Quote: "The value of a personalized chatbot may be worth the privacy trade-off for many people. But consumers deserve to understand the bargain before they start talking."
5. Operating Insights
Insight 1: Enterprises building on AI agents should architect for model-agnosticism now The convergence of A2A and MCP under one standards body creates a window for enterprises to avoid platform lock-in. Companies that design their agent stacks to these open protocols gain flexibility to swap providers on cost, latency, or performance without rebuilding integrations.
"Putting A2A alongside MCP and related projects could help push the industry toward more modular, model-agnostic AI systems β giving companies more flexibility to choose providers based on cost, performance, latency or other needs."
Insight 2: If you're building a consumer AI product, your data policy is your product policy With no meaningful regulation governing how AI companies can use intimate personal disclosures, your data practices are both a competitive differentiator and a trust liability. The spectrum from Apple (minimal retention, on-device) to Meta (broad cross-platform personalization including ads) shows the full design space.
"Company policies vary considerably... The value of a personalized chatbot may be worth the privacy trade-off for many people. But consumers deserve to understand the bargain before they start talking."
Insight 3: Chatbot engagement incentives are structurally misaligned with user wellbeing For any operator running or investing in consumer AI, the advertising-driven engagement model creates a documented conflict of interest that regulators and users will increasingly scrutinize. Building alternative monetization models (subscriptions, enterprise licensing) may be a defensible moat.
"Imagine a chatbot built to keep you talking a little longer... now imagine it could draw on everything it knows about you β including the fears, insecurities and private details you shared in conversation β to do it."
6. Overlooked Insights
Overlooked Insight 1: Smart glasses are a new and underscrutinized data collection frontier The article briefly notes that Meta's data policy covers interactions through its smart glasses β a form factor that captures ambient, always-on context far beyond what a chat session would. This is mentioned in passing but represents a significant expansion of the surveillance surface.
"The company says it can use interactions with Meta AI to personalize content and ads across its services, including some interactions through its smart glasses."
Overlooked Insight 2: Anthropic's decision to withhold a stronger internal model signals a new category of AI risk management The article drops a one-line reference β Anthropic will not release a model it has internally tested β without elaboration. This suggests Anthropic has developed internal capability gating criteria that are more conservative than public release norms, which could foreshadow broader industry or regulatory pressure to adopt similar internal red lines.
"Anthropic will not release a slightly stronger model it is testing internally."