EN

Cyber Expert Warns Against Oversharing With AI Chatbots

Nicole Jeffrey

Key Points

  1. Users should think before sharing sensitive information with AI chatbots, cyber specialist Osher Cohen warned.
  2. AI conversations capture more context, concerns and intentions than short, conventional search queries.
  3. Privacy settings and workplace rules can reduce exposure of personal, customer and corporate data.

The latest

Users should treat AI chatbots as cloud services rather than private advisers, cyber specialist Osher Cohen warned, arguing that conversational tools encourage people to disclose far more than conventional search engines. Cohen, founder of Israeli company Yo Secure, said chatbots may be connected to accounts, devices, email addresses, browsers and IP addresses, while information is governed by privacy settings and data-retention policies. His company handles digital identity crises, hacked or blocked accounts, online impersonation, social media recovery and security incidents involving digital platforms.

Details

  • Richer digital record: People often give chatbots extensive context, explain situations, test ideas, request wording and ask follow-up questions. They may also describe matters they would not say aloud to another person. Conventional searches are usually shorter, consisting of a few words followed by links that users choose whether to open.
  • Sensitive conversations: A search query can reveal what someone wanted to know, while an AI exchange may expose what the person was thinking, considering, fearing or trying to achieve. Cohen said this makes AI conversations potentially more sensitive than search histories, particularly when users regard the chatbot as a private adviser.
  • Search-bar confusion: Embedding AI tools within search bars does not make conversations disappear. Data handling still depends on the operator, whether users are signed in, their privacy settings, retention policies, history controls and potential use of information for safety, product improvement or legal compliance. Users may believe they are simply searching while creating a more detailed record.
  • Cloud data handling: Technology companies operate global cloud infrastructure, and chatbot information may be processed or stored across different regions. The location can vary according to the provider, product, account type, organizational settings, legal requirements and internal architecture. Cohen said ordinary users generally do not know exactly where their information is stored.
  • Behavioral safeguards: Cohen advised users never to enter passwords, verification codes or credit card details. Sensitive legal, medical and business documents should not be uploaded without understanding the risk, while customer data should not be pasted into personal AI accounts. Users should also review privacy settings, delete unneeded histories and consider temporary or incognito modes. He described AI as an amazing tool, but not a safe deposit box.
  • Workplace AI rules: Businesses should establish internal policies specifying what employees may enter into AI tools. Cohen identified customer lists, contracts, legal documents, medical information, financial data and internal strategy as material that should not be casually uploaded to personal chatbot accounts. Technical tools such as VPNs are not substitutes for cautious behavior.

What’s next

The next indicator is whether businesses introduce written AI policies and clearly restrict employees from uploading customer, financial, legal and strategic information.

 

What to read next