ChatGPT, Claude, Gemini 같은 AI 챗봇은 기본 설정으로 사용자의 매우 사적인 대화 데이터를 수집·저장하며, 법적 절차에 따라 제3자에게 넘겨질 수 있어 심각한 프라이버시 위협이 되고 있습니다. Signal 창업자 Moxie Marlinspike가 암호학으로 서버가 대화를 감시·기록할 수 없게 만든 'Confer'를 출시하는 등 프라이버시 보호형 AI 서비스 경쟁이 시작되었습니다. 기업용 제로 데이터 유지(ZDR) 정책 등 프라이버시를 지키며 AI를 활용하는 방법이 주요 관건입니다.
번역된 본문
기술 업계가 사용자를 유혹해 가장 깊고 민감한 비밀을 먼 데이터센터의 서버로 보내게 만드는 방법을 고안하고자 했다면, AI 챗봇보다 더 나은 '허니팟'을 만들기 어려웠을 것이다. OpenAI의 ChatGPT, Anthropic의 Claude, Google의 Gemini와 그보다 작은 수많은 경쟁 서비스들은 전 세계 수백만 명에게 심리 상담사, 아이디어 논의 상대, 가상 고해소 역할을 하고 있다. 이러한 AI 모델들은 대부분 기본 설정으로 이 매우 사적인 데이터를 수집·저장하며, 그 공유나 판매 방식에 제한이 없거나, 도구 학습에 사용되거나, 법적 절차를 통해 요구하는 소송 원고나 법 집행기관에 넘겨질 수 있는 경우가 많다.
존스홉킨스대 프라이버시·보안 전공 컴퓨터과학 교수인 맷 그린(Matt Green)은 "지적인 존재가 당신을 바라보고 있는데, 당신은 한 번의 질문씩 자기 삶에 관한 모든 것을 털어놓고 있다"며 "당신에 대한 거대한 프로필을 그것에게 주고 있는 셈"이라고 말했다.
암호학자이자 소프트웨어 개발자인 모키 매틀린스파이크(Moxie Marlinspike)에 따르면 10년 전만 해도 문자 메시지가 대부분의 사람이 기기에서 공유하는 가장 개인적이고 민감한 데이터였다. 보호되지 않은 문자가 초래하는 감시 위험 때문에 그는 2014년 현재 1억 명 이상이 사용하는 종단간 암호화 메신저 '시그널(Signal)'을 만들었다. 이제 그 핵심적인 프라이버시 취약 지점은 AI와의 상호작용으로 옮겨갔다고 그는 말한다. 매틀린스파이크는 "메시징에서 우려했던 것과 같은 일들이 AI 분야에서 벌어지고 있지만, 그 규모는 몇 자릿수 더 크다"며 "사람들이 AI를 개인적 삶에 통합하고 있다. 자신의 깊은 불안, 재정, 건강, 인간관계에 대해 AI와 이야기한다"고 말했다.
그래서 올해 초 그는 사용자가 무엇이든 물을 수 있으면서도 프라이버시를 보존하는 AI 챗봇 'Confer'를 출시했다. 암호학을 활용해 서비스 자체의 서버가 대화를 감시하거나 기록하는 것을 기술적으로 불가능하게 만든 것이다. 그는 서비스를 소개하는 블로그 포스트에서 "Confer는 당신 자신의 생각이 언젠가 당신에게 불리하게 작용하지 않도록 하면서 아이디어를 탐구할 수 있는 서비스로 설계되었다"고 썼다.
매틀린스파이크의 프라이빗 AI 도구는 사실 이런 챗봇이代表하는 만연한 프라이버시 침해를 해결하겠다고 약속하는 차세대 AI 서비스 중 하나의 돋보이는 사례일 뿐이다. 일부는 정책상 대화를 절대 기록하지 않는다고 광고하고, 다른 일부는 익명화를 제공하며, Confer처럼 자사의 사용자 비밀 접근을 제한하는 실제 기술적 안전장치를 만들려는 곳도 있다. 감시에 덜 취약한 AI를 만들려는 이 초기 경쟁의 결과로 도구들이 늘어나고 있지만, 점점 피할 수 없게 되는 기술을 채택하면서 비밀에 대한 통제권을 잃지 않으려는 사용자에게 이들은 종종 혼란스러운 보장을 제공한다. 다음은 WIRED가 소개하는 프라이버시를 지키며 AI를 사용하는 방법이다.
제로 데이터 유지(ZDR)
3대 AI 챗봇(ChatGPT, Claude, Gemini)에 입력하기 시작할 때, 대화 기록에 접근하려는 의지가 있고 법적으로 접근 경로가 있는 사람에게는 사실상 프라이버시가 거의 없다는 기대치에서 출발하는 것이 가장 안전하다. 여기에는 서비스 소유자, 광고주 등 제휴사, 시스템 미세조정을 돕는 외주업체, 법 집행기관, 심지어 민사소송의 일환으로 기록을 소환장으로 확보한 사람도 포함된다.
이 원칙에 대한 가장 단순하고 강력한 예외는 사용자—정확히는 사용자의 고용주—와 AI 제공업체 간의 계약으로, 기록 유지를 법적으로 금지하는 조항이다. 이른바 '제로 데이터 유지(Zero Data Retention, ZDR)'로 알려진 조항이다. OpenAI, Anthropic, Google은 모두 기업용 버전에 ZDR 정책을 제공하며, 활성화 시 일반적으로 …
Comment Loader Save Story Save this story Comment Loader Save Story Save this story If the tech industry sought to create a method of seducing users into sending their deepest, most sensitive secrets to a server in a faraway data center , it would be hard-pressed to create a better honeypot than an AI chatbot . OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini, and their countless smaller competitors have become therapists, sounding boards, and virtual confession booths for millions of people around the world. Almost all of those AI models are set by default to collect and store that highly private data with, in many cases, no restrictions on how it’s shared or sold, used to further train the tools, or handed over to any lawsuit plaintiff or law enforcement agency that demands it through a legal process. “You have this intelligent thing staring back at you, and you’re basically telling it, one question at a time, every possible thing there is to know about your life,” says Matt Green, a privacy- and security-focused computer science professor at Johns Hopkins University. “You're giving it this huge profile on you.” A decade ago, text messages represented perhaps the most personal, sensitive data that most people shared from their devices, says cryptographer and software developer Moxie Marlinspike . The surveillance dangers invited by unprotected texting are what pushed him in 2014 to create Signal , the end-to-end encrypted messenger now used by well over a hundred million people. Now, he says, that critical point of privacy vulnerability has shifted to people’s interactions with AI. “Those same things I was concerned about with messaging are happening in the AI space, but several orders of magnitude more significantly,” says Marlinspike. “People are integrating AI into their personal lives. They talk with it about their deepest insecurities, their finances, their health, their relationships.” So earlier this year, Marlinspike launched Confer , an AI chatbot designed to allow users to ask it anything while preserving their privacy, using cryptography to technically prevent the service’s own server from being able to surveil or log their conversations. “Confer is designed to be a service where you can explore ideas without your own thoughts potentially conspiring against you someday,” he wrote in a blog post introducing it. Marlinspike’s private AI tool is, in fact, just one standout among a new generation of AI services that promise to remedy the pervasive privacy invasion that these chatbots represent. Some advertise that they never record conversations as a policy. Others offer to anonymize them. A few, like Confer, seek to create actual technological guardrails that restrict their own access to users’ secrets. The result of that nascent competition to create less surveillance-prone AI is a growing crowd of tools, often ones that offer confusing assurances for users as they seek to adopt an increasingly unavoidable technology without losing control of their secrets. Here’s WIRED’s guide to using AI with your privacy intact. Zero Data Retention When you start typing into one of the big three AI chatbots—ChatGPT, Claude, or Gemini—it’s safest to start with a baseline expectation of approximately zero real privacy from anyone who is determined to access your conversation records and has a legal path to obtaining them. That includes the owner of the service, advertisers or other companies they partner with, contractors who help fine-tune the systems , law enforcement agencies, or even someone who manages to subpoena the records as part of a civil lawsuit. The simplest, strong exception to that rule is a contract between you—or more likely, your employer—and an AI provider that legally prevents them from retaining those records, a provision that’s come to be known as zero data retention, or ZDR. OpenAI, Anthropic, and Google all offer ZDR policies for their enterprise versions, which when enabled generally require that they immediately delete records of users’ interactions with a chatbot as soon as they’re processed. Even these ZDR policies, which are only available for paid enterprise and developer accounts rather than for average users, have significant exceptions. Anthropic, for instance, doesn’t offer ZDR for its most sophisticated “Mythos-class” models like Fable 5.1, due to what it describes as the potential for misuse like scamming or hacking and even “autonomous misbehavior,” such as AI agents independently hacking targets to carry out their unwitting users’ requests, as has occurred in several high-profile AI-driven breaches . OpenAI also announced last month that its ZDR implementations will analyze user activity prior to deletion—on the customer’s systems rather than its own, it says—and, if it detects abuse, flag it for the customer organization. OpenAI says its system, known as Private Safety Processing, will even alert OpenAI’s staff if it detects abuse in some cases, though without revealing the content of the conversation to them. Google, too, warns that it logs some Gemini prompts for abuse monitoring even with ZDR enabled, but without the user’s Google ID or IP address included—though that “sanitized” data can in some cases still pinpoint a particular person when the request itself includes identifiable information. Policies, Promises, and Proxies Regardless of those protections and exceptions, the paid, enterprise-level, contractual promises of ZDR are out of reach for the vast majority of non-corporate AI users. Instead, many consumer-targeted AI services ask us to settle for the far weaker, pinky-swear promises they’ve made not to log our conversations. Privacy-focused cloud services company Proton, for instance, offers the AI chatbot Lumo, which it describes as “AI where every conversation is private.” That privacy, however, isn’t based on the technical guarantees of end-to-end encryption, like Proton’s other services such as Proton Mail and Proton Drive . Instead, it simply promises not to log users’ conversations, and users have to trust that Proton will adhere to that privacy policy—which, in Proton’s case, is at least backed by the company’s long track record as a privacy-focused company. “A promise is not as good as a mathematical guarantee,” Yen told WIRED in an interview last month , “but a promise made by the right people is still actually quite substantial.” Other privacy-focused AI services like Venice.ai and Duck.ai, the AI chatbot offered by long-running private search engine DuckDuckGo, offer similar vows about keeping no logs of your conversations. Both services, however, relay your chat requests to other services such as Claude or ChatGPT, essentially acting as a proxy for your conversation that limits what information the underlying AI model can collect about you. (Duck.ai lets the user choose which third-party model they’re using. Venice.ai appears to automatically route conversations to different services based on the request, without always making clear to the user which one it’s using, as well as answering queries with an AI model hosted on its own infrastructure in some cases. Venice.ai also touts other privacy features, like using “trusted execution environment” systems to cryptographically prevent logging of conversations—more on that below—but when WIRED attempted to reach out to Venice.ai’s staff to ask more questions about these privacy features, its AI response bot only repeatedly referred us to a nonworking email address.) Using an anonymity proxy offers some privacy protection compared with using ChatGPT or Claude directly. Yet when they relay your requests to those services, Duck.ai and Venice.ai’s own promises about their retention of data become significantly less meaningful, points out Johns Hopkins’ Green. That’s because your chat messages can still be collected by that underlying AI model and, even stripped of any identifying metadata, those messages can often contain identifiable info