{"id":630506,"date":"2025-12-13T17:31:30","date_gmt":"2025-12-13T17:31:30","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/630506\/"},"modified":"2025-12-13T17:31:30","modified_gmt":"2025-12-13T17:31:30","slug":"i-work-at-google-in-ai-security-things-i-would-never-tell-chatbots","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/630506\/","title":{"rendered":"I Work at Google in AI Security: Things I Would Never Tell Chatbots"},"content":{"rendered":"<p>This as-told-to essay is based on a conversation with 31-year-old Harsh Varshney, who works at Google and lives in New York. The following has been edited for length and clarity.<\/p>\n<p>AI has quickly become a silent partner in our daily lives, and I can&#8217;t imagine life without <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/ai-tools-doubled-income-save-me-fifteen-hours-each-week-2025-9\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">AI tools<\/a>.<\/p>\n<p>Day-to-day, they help me with deep research, note-taking, coding, and online searches.<\/p>\n<p>But my job means I&#8217;m very aware of the privacy concerns associated with using AI. I&#8217;ve worked at Google since 2023 and spent two years as a software engineer on the privacy team, building infrastructure to protect user data. I then switched to the Chrome AI security team, where I help secure Google Chrome from malicious threats, like hackers and those who use <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/ai-agent-managers-new-job-2025-11\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">AI agents<\/a> to conduct phishing campaigns.<\/p>\n<p><a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/ai-benchmark-best-model-compare-meta-openai-deepseek-google-2025-4\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">AI models<\/a> use data to generate helpful responses, and we users need to protect our private information so that harmful entities, like cybercriminals and data brokers, can&#8217;t access it.<\/p>\n<p>Here are four habits I&#8217;ve made that I believe are essential for protecting my data while using AI.<\/p>\n<p><strong>Treat AI like a public postcard<\/strong><\/p>\n<p>Sometimes, a false sense of intimacy with AI can lead people to share information online that they never would otherwise. <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/ai-startup-unicorns-with-tiny-teams-2025-5\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">AI companies<\/a> may have<strong> <\/strong>employees who work on improving the privacy aspects of their models, but it&#8217;s not advisable to share credit card details, Social Security numbers, your home address, personal medical history, or other personally identifiable information with AI chatbots.<\/p>\n<p>Depending on the version being used,<strong> <\/strong>the information shared with public<strong> <\/strong>AI chatbots can be used to train future models and generate responses that are more relevant. This could result in &#8220;training leakage,&#8221; where the model memorizes personal information about one user<strong> <\/strong>and later regurgitates it in responses to another. Plus, there&#8217;s the risk of data breaches, which would expose what you&#8217;ve shared with a chatbot.<\/p>\n<p>I treat AI chatbots<strong> <\/strong>like a public postcard. If I wouldn&#8217;t write a piece of information on a postcard that could be seen by anyone, I wouldn&#8217;t share it with a public AI tool. I&#8217;m not confident about how my data could be used for future training.<\/p>\n<p><strong>Know which &#8216;room&#8217; you&#8217;re in<\/strong><\/p>\n<p>It&#8217;s important to identify whether you&#8217;re using a more public AI tool or an enterprise-grade one.<\/p>\n<p>While it&#8217;s uncertain how conversations are used for training public AI models, companies can<strong> <\/strong>pay for<strong> <\/strong>&#8220;enterprise&#8221; models. Here, models aren&#8217;t typically meant to train on user conversations, so it&#8217;s safer for employees to talk about their work and company projects.<\/p>\n<p>Think of it like having a conversation in a crowded coffee shop where you could be overheard, versus a confidential meeting in your office that stays within the room.<\/p>\n<p>There have reportedly been instances where employees have accidentally <a target=\"_self\" href=\"https:\/\/www.businessinsider.com\/samsung-chatgpt-bard-data-leak-bans-employee-use-report-2023-5\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">leaked company data<\/a> to ChatGPT. If you work on unreleased company projects or are trying to get a patent, you probably don&#8217;t want to discuss your plans with a non-enterprise-grade chatbot due to the risk of leakage.<\/p>\n<p>I don&#8217;t discuss projects I&#8217;m working on at Google with public chatbots. Instead, I use an enterprise model, even for tasks as small as editing a work email. I&#8217;m much more comfortable sharing my information because my conversations aren&#8217;t used for training, but I still minimize the personal information I share.<\/p>\n<p><strong>Delete your history regularly<\/strong><\/p>\n<p>AI chatbots usually keep a history of your conversations, but I recommend deleting it on both enterprise and public models regularly to protect your user privacy in the long term. Due to the risk of your account being compromised, it&#8217;s a good precautionary habit to have, even if you&#8217;re confident you aren&#8217;t putting private data into the tools.<\/p>\n<p>Once, I was surprised that an enterprise <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/openai-chatgpt-5-1-google-gemini-3-how-they-compare-2025-12\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">Gemini chatbot<\/a> was able to tell me my exact address, even though I didn&#8217;t remember sharing it. It turned out, I had previously asked it to help me refine an email, which included my address. Because the tool has long-term memory features, enabling it to remember information from previous conversations, it could identify what my address was and retain it.<\/p>\n<p>Sometimes, if I&#8217;m searching for things I don&#8217;t want the chatbot to remember, I&#8217;ll use a special mode, a bit like incognito mode, where the bots don&#8217;t store my history or use the information to train models. <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/ai-job-changes-chatgpt-gemini-five-years-ey-experiment-2025-11\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">ChatGPT and Gemini<\/a> call this the &#8220;temporary chat&#8221; feature.<\/p>\n<p><strong>Use well-known AI tools<\/strong><\/p>\n<p>It&#8217;s better to use AI tools that are well-known and are more likely to have clear privacy frameworks and other guardrails in place.<\/p>\n<p>Other than Google&#8217;s products, I like to use OpenAI&#8217;s ChatGPT and <a target=\"_self\" class=\"\" href=\"https:\/\/www.businessinsider.com\/anthropic-claude-opus-4-5-beats-every-human-engineering-test-2025-11\" data-track-click=\"{&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;tout_click&quot;,&quot;index&quot;:&quot;bi_value_unassigned&quot;,&quot;product_field&quot;:&quot;bi_value_unassigned&quot;}\" rel=\"noopener\">Anthropic&#8217;s Claude<\/a>.<\/p>\n<p>It&#8217;s also helpful to review the privacy policies of any tools you use. Sometimes, they&#8217;ll explain more about how your data is used to train the model. In the privacy settings, you can also look for a section with the option to &#8220;improve the model for everyone.&#8221; By making sure that setting is turned off, you&#8217;re preventing your conversations from being used for training.<\/p>\n<p>AI technology is incredibly powerful, but we must be cautious to ensure our data and identities are safe when we use it.<\/p>\n<p>Do you have a story to share about using AI to help you at work? Contact this reporter at <a target=\"_blank\" href=\"https:\/\/www.businessinsider.com\/mailto:ccheong@businessinsider.com\" data-track-click=\"{&quot;click_type&quot;:&quot;other&quot;,&quot;element_name&quot;:&quot;body_link&quot;,&quot;event&quot;:&quot;outbound_click&quot;}\" rel=\" nofollow noopener\">ccheong@businessinsider.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"This as-told-to essay is based on a conversation with 31-year-old Harsh Varshney, who works at Google and lives&hellip;\n","protected":false},"author":2,"featured_media":630507,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3163],"tags":[323,1942,53,16,15],"class_list":{"0":"post-630506","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-technology","11":"tag-uk","12":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/115713454054438380","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/630506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=630506"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/630506\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/630507"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=630506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=630506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=630506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}