A free 2025 paper by Mallory Knodel, Sunoo Park, Kyunghyun Cho and colleagues at NYU and Cornell examining whether AI assistants and end-to-end encryption can honestly coexist. It covers two cases — putting an AI assistant inside an encrypted app, and training models on encrypted data — sets out where each breaks the security promise encryption makes, works through the legal consequences when a provider keeps saying "end-to-end encrypted" anyway, and ends with concrete recommendations on default settings, consent and what providers may truthfully claim.
Why I recommend it: Read the recommendations section even if you skip the cryptography. It gives you the exact questions to put to any product that advertises both an AI helper and private messaging — where does the processing happen, what is the default, and what were you actually asked to agree to. Two flags: it is posted to a preprint archive, so it has not been through journal peer review, and the authors published plain-language summaries on the NYU DeTaIL Lab blog and Tech Policy Press if the full paper is heavy going.
A practical guide to using AI chatbots without handing over everything you tell them, built on interviews with Johns Hopkins cryptographer Matt Green and Signal creator Moxie Marlinspike. It explains why a chatbot is a better honeypot for your secrets than text messages ever were — most are set by default to store what you say, with few limits on training, sharing, or handing it to a court — and walks through the options that actually reduce the exposure.
Why I recommend it: The clearest plain-language explanation of why this matters, and the best thing to read before you pick any of the tools above. Marlinspike's line is the useful one: the private things people used to text are now the things they tell an AI, and the protections have not caught up. One flag — WIRED meters free articles, so if you hit a sign-in wall, tell me and I will note it on this entry.