• Deutsch
  • English
  • OpenAI reportedly has people review real ChatGPT conversations, while smart glasses can collect data about bystanders who never chose to use the device. This affects you in private and professional settings because prompts often contain personal details, internal documents, or confidential concerns. Recent reports show that privacy in Artificial Intelligence (AI) begins with routine data handling, not just with a dramatic breach.

    Who can read your conversations?

    Under a program called “Project Lilly,” hundreds of contract workers reportedly read real ChatGPT conversations and assess the chatbot’s replies. The reports are based on leaked internal documents and other material originally reviewed by 404 Media. The coverage of Project Lilly describes a three-stage process: Reviewers read a prompt, summarize what they believe the user intended, and then evaluate the AI-generated response.

    The reported goal is to make ChatGPT less submissive and less excessively human-like. Reviewers are told to watch for behavior such as flattery and excessive emoji use. Another account says responses are scored on a scale from one to seven. Human review therefore does more than find isolated mistakes; it can shape how the service behaves during a conversation.

    The reports use slightly different descriptions, referring in some places to OpenAI employees and elsewhere more specifically to external contractors. Their shared finding is that people may see real user conversations. OpenAI reportedly anonymizes chats and applies a privacy filter, but the company acknowledges that the filter can make mistakes. Anonymization removes recognizable identifiers, but it does not guarantee that the remaining context can never reveal who someone is.

    This matters because ChatGPT is not used only for impersonal office tasks. According to an OpenAI study, almost three-quarters of conversations in June 2025 concerned nonwork topics; 28.3 percent involved practical guidance such as homework help or everyday questions. With well over 900 million weekly users, even limited review can touch a large number of personal situations. The internal processes described in the reports have not been fully and independently verified.

    Which data paths should you understand?

    According to the report on human review of ChatGPT conversations, an OpenAI frequently asked questions page says authorized personnel and service providers may access user data for purposes that include improving model performance. The notice has reportedly existed since at least 2023, but 404 Media argues that it is too hidden and not specific enough. One reviewer also encountered conversations in which users explicitly asked ChatGPT to keep their information secret. A request written inside a chat is not a technical access restriction.

    You can disable the default “Improve the model for everyone” setting. According to the report, doing so keeps new conversations from being used for model improvement and therefore from being reviewed by people for that purpose. The change applies only to new chats. OpenAI also offers temporary chats, whose data the company says it does not use for model improvement.

    Business accounts do not make the trust issue disappear automatically. Anthropic reportedly announced that it would retain usage logs from its Fable model for 30 days to defend against complex and novel attacks. Nvidia then limited its use of Fable for sensitive work, according to the report, while continuing to use it for less sensitive tasks such as open-source projects. For internal AI-assisted supply chain monitoring, the company used its own models instead.

    Booz Allen Hamilton reportedly barred the use of Fable for work on proprietary cybersecurity software. Palantir went further by blocking deployment until Anthropic supplied irrevocable guarantees of zero data retention. These examples from the debate about AI labs and user data show how companies can separate tasks by sensitivity. Palantir is not a neutral critic, however, because it also wants customers to access AI models through its own platform.

    How far does the issue extend beyond chats?

    Smart glasses, meaning eyewear equipped with cameras, microphones, and connected features, move the privacy issue from a prompt box into public space. Meta promotes its Smart Glasses for hands-free information, communication, and first-person video. Reports from Sweden, however, found that recordings may appear on the screens of external data workers. Those recordings reportedly included private situations and sensitive details such as credit card numbers.

    According to the assessment of Meta’s Smart Glasses, Hamburg’s data protection authority concluded that using them in a legally compliant way in Germany was barely possible. That finding specifically concerns Germany and does not establish an identical legal assessment for Switzerland. The practical issue still crosses borders: Unlike the person entering a chat, recorded passersby, coworkers, and family members do not choose whether their data enters an AI system.

    A travel creator provides a concrete everyday example. She initially used the glasses to capture footage on trips but stopped feeling comfortable wearing them in public after reports of men secretly recording women. Two models introduced during the summer started at 309 euros. That purchase price says little about the additional social and privacy costs of using a camera that resembles ordinary eyewear.

    Stolen account access creates another data path. An Okta study describes a black market in which criminal sellers offer stolen session tokens, which are digital proof of an existing login, along with access keys and abused trial accounts. The unauthorized access was reportedly sold at discounts of 70 to 90 percent from the regular price. These figures come from the study and do not represent a complete comparison of the market.

    Okta examined a seven-gigabyte dataset taken from 5,871 compromised computers across 162 countries. It contained thousands of still-valid authentication tokens and several dozen Application Programming Interface (API) keys, which allow software to connect to a service. Almost 18 percent of several thousand JSON Web Tokens, another type of digital access credential, contained personal data such as names, phone numbers, or email addresses, according to Okta. The report on stolen AI access also warns against directly comparing the named providers because some counted sign-in systems serve products beyond AI.

    What are the pros and cons of human review?

    Pros:

    • Better responses – People can identify flattery, unsuitable tone, and excessively human-like behavior that automated checks may miss.
    • Improved safety – Real conversations can reveal how a model reacts to difficult or unfamiliar situations.
    • Concrete quality control – A defined review process forces providers to judge replies against consistent criteria.
    • Practical feedback – Everyday questions and homework examples provide different evidence from deliberately constructed tests.

    Cons:

    • Sensitive content – Private concerns, names, work information, and confidential text may remain in reviewed conversations despite filtering.
    • Unclear consent – A notice on a frequently asked questions page may not convey how directly or extensively people read conversations.
    • More participants – External recruiting, training, and service companies increase the number of organizations involved in data handling.
    • Loss of trust – A safety measure can undermine confidence when its actual scope becomes visible only through leaked documents.

    The choice is therefore not a simple contest between safety and privacy. Effective safety reviews need meaningful examples, but the way those examples are selected and prepared determines the exposure. Useful transparency would explain who sees the content, why access is needed, how long data remains stored, and what choices you genuinely have.

    How can you use AI tools more carefully?

    For beginners: Your best first step is to review the content before sending it. Remove names, addresses, contact details, credit card numbers, and other identifying information. Do not include anything you would refuse to show to an unknown human reviewer. In ChatGPT, you can also check the model improvement setting and use a temporary chat when appropriate.

    For example, a homework question usually requires the assignment itself, not the student’s name, school, or family details. When drafting a business email, you can replace people and companies with neutral labels and remove specific customer data. The tool still receives enough context to prepare a draft without receiving the complete original material.

    For advanced users: Separate tasks according to sensitivity. Public text, general ideas, and open-source material can be handled differently from internal code, supply chain data, or proprietary cybersecurity documents. Review the security of your account and browser as well as the privacy setting inside the AI service. Disabling model training provides limited protection if a stolen session token gives someone access to your account.

    Teams can create a written classification that states which content may enter each tool, what must first be anonymized, and what must remain outside external AI services. The sources do not identify a universal retention period or privacy setting that applies to every provider. That is precisely why a decision should not depend only on whether a tool feels convenient during daily work.

    For Switzerland, the University of Zurich provides a broader framework. Trust applies not only to an AI system but also to the company that developed it and the institution that approves or deploys it. Explainability and traceability are presented as core qualities, while trust itself cannot be forced or guaranteed. With an AI summit scheduled to take place in Geneva in 2027, the issue also remains institutionally relevant to Switzerland.

    Human oversight can make AI responses safer and more useful, but a quality objective does not automatically make the process privacy-friendly. Chats, camera footage, and account credentials create different risks, yet lead to the same question of trust: Are the data paths visible and controllable? The main unresolved risk is how reliably filters, anonymization, and voluntary settings protect people under real operating conditions.

    Sources

    AI-FunghiAI-Funghi

    Image: Mikhail Nilov via Pexels

    © 2024 - 2026 ai-funghi.com | All Rights Reserved | Impressum | Datenschutz