Industry

Signal's president on why she does not ask chatbots questions

Meredith Whittaker says she does not ask chatbots questions. Her objection is about access, and it deserves arguing with in both directions.

Multi Chats Team
September 29, 2026 · 10 min read

Meredith Whittaker runs the nonprofit foundation behind Signal, which puts her in an unusual position for someone with opinions about AI assistants: hers is a consumer messaging service with no advertising business to defend and no model to train. On 19 June 2026 Bloomberg published a long interview with her, headlined "Encryption Is Under Threat, Says Signal President Meredith Whittaker". Asked what she would like readers to be aware of, in privacy terms, when they use large language models like ChatGPT and Claude, she gave the answer that travelled: "These are not your friends. These are not conscious beings. These are not sentient interlocutors."

She said she sometimes asks chatbots to format documents, but does not ask them questions or treat them as a relationship. She wants to work through uncertainty herself and worries that a system drawing on existing material would interrupt that process.

TechCrunch reported the exchange the next day, 20 June 2026. Lifted out of the conversation, the line reads as a verdict on whether chatbots are clever enough to be worth anyone's time. Read in place, it turns out to be about access, and the access argument is both narrower than the headline and much harder to wave away. Most of it holds. One part of it does not survive contact with how people actually use a chat window, and setting out which is which seemed more useful than nodding along or picking a fight.

Access is the thing she is objecting to

The pivot comes when the interviewer raises the next generation of these products, the autonomous personal assistant, and puts to her a prediction Microsoft AI chief executive Mustafa Suleyman made in an earlier Bloomberg interview: you could be buying your Christmas presents in 2026 through Microsoft Copilot.

Her answer skips past whether Copilot could do it and goes straight to what the assistant would have to be able to reach. In her telling she asks Copilot to consult her siblings' group chat, work out what the family might like, buy the gifts and get them to the right place. Then she adds up the bill: "That would need access to my credit card, my browser, my Signal, the ability to message my siblings on my behalf, my home address [and] my calendar. What you've just described is a system with very pervasive access across multiple applications and services."

Then the line that explains why Signal's president is the one making this argument: "In the context of Signal, it would constitute a kind of a backdoor."

That claim is technical, and it holds up. Signal's guarantee is that a message is readable only on the two devices at either end of the conversation. An assistant on your phone with permission to read your apps breaks none of that. It reads the message after your device has decrypted it, which is exactly where the protection ends. The cryptography stays intact and the confidentiality does not. She gives the general version elsewhere in the interview: "Encryption either works for everyone or it works for no one. There is no way to have a golden key or a special backdoor or access just for the good guys."

None of this requires anyone deciding to attack Signal. Asked whether agents are an existential threat to it, she said: "I do worry. Any one of the operating system vendors that decides to implement an agent with these capacities is ultimately hollowing out the ability for Signal and others to guarantee privacy or data protection. This is a quiet but profound shift that we are witnessing." A platform holder shipping a helpful feature can undo a property a messaging app spent a decade building, and nobody has to intend it.

Why she singles out the shopping assistant

Shopping looks like the harmless end of the assistant market. Nobody is confessing anything to a gift recommender. That is precisely why the example is useful to her, and it does two jobs in the interview.

The first job is scope. Buying presents for a family is an errand with no privacy stakes of its own, and it still needs the assistant to hold a payment card, a home address, a calendar, a browser session and the contents of a private group chat. If the mundane case needs that much, the product sets the shape of the permission and the sensitivity of the task does not. You do not grant access per question. You grant it once, and the reading carries on for as long as the assistant is installed.

The second job is incentive. Pressed on the fact that you can delete chats and ask for them not to be shared, she said: "You can say all sorts of things, but ultimately, the power to determine whether that happens or not is in the hands of the entity that is running that service." Her account of what it might do with them is specific: "[Chats] can be stored, logged, mined for more data [and] tweaked slightly to calibrate the responses to your purported preference on behalf of, say, advertisers. Instead of showing ads, perhaps you say, Find me a very cheap flight, and it finds you one with their preferred advertising partner that is not cheaper."

This is where shopping stops being the harmless case. A banner ad announces itself. A recommendation that has been quietly weighted does not, and no view from the outside lets you tell the two apart. Bloomberg attaches its own footnote here, recording that OpenAI has been introducing ads within ChatGPT for some users while saying they do not influence responses and that the company does not share conversation data with advertisers. Both statements can be true and her point still lands, because a reader cannot check either from where they are sitting.

Compare the three positions directly

Hers is one of three available answers, and it helps to see what each trades. The middle row is what vendors are building towards.

Position

What leaves your device

Who can read it

What you give up

Hers: use them to format, do not ask them questions

A document when you hand one over. No questions, no context, no history worth mining

Whoever runs the formatting service, for as long as it decides to keep the file

Nearly everything assistants are used for

The vendor default: one assistant with access across your apps and services

Whatever the assistant needs to act on your behalf: messages, calendar, contacts, browsing, payment details, address

The operator, its model providers, and whatever its commercial arrangements reach

Any way to audit why you got that answer, and the guarantee your encrypted apps made

The middle: a chat window you open on purpose

Only what you type or attach, one message at a time

The operator, and the provider behind the model you picked, on published terms

Convenience. Nothing is fetched or bought for you unless you go and get it

The columns are the argument. The first column stays small in every row, which is why it carries so little of her case. The weight sits in the second and third, and in the fact that the middle row changes all three at once the moment you approve it, on the strength of a permission prompt read in four seconds.

Where she is right, and where the argument runs past its evidence

Three parts of this are simply correct. The retention point is the strongest: once a conversation sits on someone else's server, your delete button is a request, and the party you are asking holds the commercial interest in the answer. The incentive point has receipts, since assistants are being turned into commercial surfaces on the record, by companies that publish the fact. And the encryption point is one almost nobody else was making in June 2026. An assistant with read access to a decrypted inbox is a real hole in end-to-end encryption, it needs no court order and no cryptographic break, and calling it a backdoor is technically fair.

Where the argument stretches is in the step from those three findings to "I don't ask them questions."

Look at what she keeps and what she drops. She keeps formatting a document, which sends a whole document off her machine. She drops questions, which are usually shorter and often carry less about her than the document. That ordering makes sense on the second reason she gives, about protecting the struggle of working through an idea, and that claim belongs to her writing practice and is entirely hers to make. It does not follow from the privacy argument, and the interview lets the two sit together as though one supported the other. On privacy grounds, risk is a property of the individual question. Asking when the last train leaves is a different act from describing a medical symptom, and a rule that flattens them gives a reader nothing to work with.

The second stretch is the collapsing of categories. The backdoor analysis is exact for an operating-system agent with standing permission across a device. It is much looser applied to an application you open, type a sentence into and close, which has one input, one output and no reach beyond what you put in front of it. Both deserve scrutiny. Treating them as one object throws away the distinction a reader needs in order to act.

The third is the missing half of the retention point. Operator control over deletion is real, and it is the condition of every hosted service anyone already depends on: their email, their photo library, their bank. Every operator holds that power; what varies is what constrains it, meaning the retention schedule it publishes, the processing agreements it signs, the erasure rights a user can enforce and the jurisdiction it answers to. Those constraints are imperfect and they are also not nothing, and the interview does not weigh them. The asymmetry she describes is genuine. The question that follows is which operators have written their limits down in a form you can hold them to.

The settlement most readers reach, and what it still rules out

Since you are reading this on the blog of a company that sells an AI chat app, our own position belongs in the open. We are a chat app and that is the whole of it. We have no integration with an inbox, a calendar, a drive or a shopping account, which we checked in our own codebase before writing this sentence; the one place we touch email is a button that opens your mail client or a Gmail compose window with the text filled in, and it reads nothing back. We do not train on your conversations. What the provider behind a given model does with them varies by model, and the models where we know of a difference carry a notice on their info card in the picker. One thing her argument deserves to have flagged: Intent Detection is on by default on the website and decides per message whether a web search is needed, so a query can leave the app without you pressing anything. The switch is in Settings, then Tool Preferences. For a question you want answered once and not kept, there is a Temporary chat mode, which stays out of your history and out of memory, though a safety copy may be held for up to seven days for abuse prevention. Our privacy policy carries the retention schedule and the list of providers that receive prompts.

The settlement most people arrive at is the bottom row of that table, and it is defensible. Keep the assistant in a window you open deliberately. Let it read what you show it and nothing on either side. When something wants a standing connection to your messages, your mailbox or your card, treat that as a decision of a different order from sending a message, because the grant is permanent and the message is not.

What her argument specifically rules out is narrower than a list of sensitive topics, because it turns on scope. Do not approve a cross-application grant for the sake of one errand; the errand ends and the permission does not. Do not put anything into a chat window whose safety depends on a deletion working later, since the operator decides what deletion means and you cannot verify it. And on any question with money at the end of it, do not let the assistant take the last step. Ask what it is weighing, ask where it got it, then go and look, because a nudged answer looks exactly like a good one.

None of that requires believing the model is conscious, and none of it requires refusing to ask it anything. It requires reading a permission prompt as carefully as you would read a contract, which is most of what she was saying.