Signal's Whittaker Says AI Chatbots Aren't Your Friends. She's Describing a Routing Problem.
Meredith Whittaker, who runs Signal, said today that AI chatbots “are not your friends,” and the quote went everywhere before lunch. The framing is sticky. It’s also, I think, slightly the wrong frame, because “friend” makes it sound like an emotional problem when the thing she’s actually pointing at is plumbing.
Strip the warmth-and-betrayal language off and what’s left is a question about where your words go after you type them. That’s it. That’s the whole warning. When you talk to a cloud chatbot, the sentence you wrote leaves your machine, travels to a server you don’t own, gets processed next to a profile that may or may not exist about you, and comes back. Whittaker has spent years saying this about the broader surveillance economy. The chatbot is just the newest pipe.
The “friend” word is doing too much work
I get why she used it. It’s a good line and it travels. But calling a model a not-friend smuggles in a psychological story. You trusted it, it was secretly logging you, betrayal. And that story lets people off the hook, because most of us know not to pour our hearts out to a stranger, so we nod and move on and keep pasting our quarterly numbers into a text box anyway.
The numbers don’t care whether you felt a bond. They left your device regardless. A spreadsheet of customer emails is not a confession, and a chatbot doesn’t have to feel like a friend for it to ship that spreadsheet somewhere you can’t see. So the betrayal framing, weirdly, undersells it. The problem is structural, and it happens whether or not you were emotionally invested.
Where does the sentence actually travel?
Picture the path. You’re on a webpage with something you want summarized. You open a cloud assistant in another tab, you copy the content over, you hit send. Now there are at least two parties holding that content: the model provider, and whatever logging, retention, or “we may use this to improve our services” clause sits in the terms you didn’t read.
For most casual questions, fine, who cares. Ask it to explain a tax form in general and there’s nothing to leak.
But the useful work is never the general question. The useful work is “draft a reply to this customer,” “pull the line items off this invoice,” “rewrite this internal doc.” All of those need the specific, sensitive thing in front of you. And the moment you feed that specific thing into a cloud chatbot, you’ve done the exact thing Whittaker is warning about, no matter how careful your prompt hygiene was, because the architecture routes it outward by default and no setting buried in a menu quietly changes how the request physically moves across the network.
Two ways to make the route shorter
There’s a deeper version of the fix, which Signal embodies: end-to-end encryption, no central server reading your messages. You can’t really do full E2E with a remote LLM, because the model has to read the plaintext to answer. Something somewhere has to see the words. That’s just true.
So the realistic move isn’t “no server ever sees it.” It’s “shorten the route and pick who’s on it.” Two changes do most of that work:
- Run the agent where the data already lives (your own browser, your own logged-in tab), so nothing gets copy-pasted into a second service.
- Bring your own key, so the only model that sees your text is the provider you chose, billed to you directly, with no extra middleman aggregating requests in between.
That second one is the part people skip. BYOK doesn’t make the LLM provider vanish. It removes the other company: the wrapper, the proxy, the “free” tool that sits between you and the model and takes a copy on the way through. We wrote more about why that middle layer is the actual liability in AI Data Mining Makes BYOK Essential.
This is the boring version of her point
Dassi is built around exactly this routing question, which is why Whittaker’s quote landed for me as a confirmation rather than a threat. It’s a Chrome extension that runs in your browser’s side panel and reads the tab you’re already on, the one where you’re already logged in. There’s no second service to paste into. You wire it to your own LLM key (Claude, GPT, Gemini, whichever), and your page content goes to that provider and stops there.
Same model quality. Different plumbing. The sentence you typed takes the short road instead of the scenic tour through three companies’ logs.
None of this requires you to believe the chatbot was plotting against you. You can think the model is useful, even delightful, and still want the data to take a path you can draw on a napkin. Whittaker frames it as friendship because friendship sells the headline. I’d frame it as: know the route, then pick a shorter one.
She’s right that you shouldn’t confide in a chatbot. But the more useful version of her warning isn’t about confiding. It’s about the invoice you uploaded last Tuesday without thinking about it once. If you want that kind of help without that kind of route, a browser agent on your own key is the structural answer rather than a promise, and you can grab the extension here if you’d rather your data stay put.
Anyway. The chatbot was never your friend. It was also never supposed to be. It’s a pipe, and the only question worth asking about a pipe is where it drains.