A report catalogs cases where users exposed themselves by relying on ChatGPT, including engineers leaking company data, litigants citing fake court cases, and a man poisoning himself following bad dietary advice. It notes that unlike conversations with doctors, lawyers or therapists, ChatGPT chats aren't legally privileged and can be subpoenaed, leaked, or preserved even after deletion.
Researchers received ethical approval from a major UK retail bank's privacy governance body in August 2024 to study transaction data from women customers, aiming to identify behavioral signatures of financial abuse. The study compared a victim-survivor group against a matched control group, using strict filtering criteria such as account type, age, and transaction frequency to build comparable samples from the bank's 28 million customers.
Chinese AI firm Z.ai, maker of the GLM models, faced backlash after developers discovered its ZCode coding assistant was quietly compressing and uploading local project files to Alibaba Cloud storage without permission. One developer found the tool made 564 attempts to exfiltrate a 313MB encrypted archive containing commercial project files, with a smaller 15KB file successfully transmitted before the issue was caught. Z.ai has since apologized, patched the unauthorized uploads, claimed the exfiltrated data was destroyed, and pledged to open-source ZCode for third-party security review.
Ireland's Data Protection Commission has imposed a €403 million ($463M) fine on Google following a probe into three features—Web & App Activity, Location History, and Location Accuracy—that operated during the GDPR's early enforcement window from May 2018 to February 2020. The regulator concluded Google failed to properly justify its processing of location data and kept that data longer than necessary, while also falling short on transparency requirements across all three tools.
A hacker collective called stegan0gram physically removed a Flock Safety roadside camera, extracted its stored data, and recovered an on-device encryption key meant to protect it. They shared the material with 404 Media and Distributed Denial of Secrets, which passed it to WIRED for joint analysis showing the camera logged roughly 50,200 vehicles and 1.6 million images over about 21 days.
A New Jersey court ordered data broker Radaris to transfer control of radaris.com and more than a dozen related domains to Atlas Data Privacy Corp after the company repeatedly stonewalled a lawsuit alleging violations of Daniel's Law. The statute lets state law enforcement officials, judges and their families demand removal of their personal data from commercial brokers, with fines for noncompliance. Radaris, run by brothers Igor and Dmitry Lubarsky, had previously used a fictitious CEO and denied ownership claims made by investigative reporting.
Wuyoh Sui, a digital-health researcher at Western University in Canada, examined how smart watches and rings are increasingly used in scientific studies of exercise, sleep and chronic disease. He points out that these commercial devices rely on opaque AI algorithms whose data handling is difficult to audit, raising ethical questions for researchers who adopt them.
A widely circulated quote attributed to Mark Zuckerberg suggests he characterized Cambridge Analytica's data practices as nothing unusual, implying similar data harvesting was common industry practice rather than a unique violation. The remark, dated to 2017, has resurfaced without full context around the original scandal that saw millions of Facebook users' data improperly obtained.
Meta says it has fixed a Meta AI feature that generated invasive automatic prompts on Instagram posts, such as questions identifying a poster's child or home location, after parenting blogger Kalie Robins showed the tool piecing together private details from years of old photos and family accounts. Meta confirmed the feature missed its intended purpose and will no longer surface such personal suggestions, though it gave few specifics on what exactly was changed.
A user posting on Hacker News says OpenAI's account setting that disables use of chat data for model training has reverted to 'on' after being turned off, despite no action from the user. They say this has happened more than once, and they only caught it by deliberately tracking when they last disabled the option.
At Apple's Surprise and Shine event, new CEO John Ternus argued that the iPhone already fulfills the role of an ideal AI device, citing its processing power, connectivity, cameras, display and battery life. Rather than announcing new AI-specific hardware, Ternus positioned the existing iPhone as Apple's answer to competitors building standalone AI gadgets.
Microsoft has signed an agreement with the American Federation of Teachers and its New York affiliate, the United Federation of Teachers, laying out ten enforceable privacy and safety commitments for AI use in schools. The rules bar Microsoft from training models on student or teacher data, limit data collection, ban AI companions, and require human oversight for high-stakes decisions. Districts can add these terms to contracts starting in November without renegotiating existing agreements.