AI news, models and products, with sources中文
Guide Basics · Chapter 4

Privacy and safety

Whether your chats train the model and how to stop it, what never to paste, who owns AI output, deepfake scams, and what parents can do.

Are your chats used for training?

AI companies use some user conversations to improve their models. This is model training. It doesn’t mean your words will be repeated to someone else, but it does mean the content is kept longer and enters the company’s data pipeline.

All three major assistants let individual users choose. Claude’s pricing page labels model training on its personal plans as “Opt-out”, and on its Team and Enterprise plans as “None by default”. The setting names and paths below come from each company’s help pages, as of October 2026:

ChatGPT Claude Gemini
The setting Improve the model for everyone Help improve our AI models Keep Activity
Where Settings → Data controls Settings → Privacy The Gemini Apps Activity page
When it’s off New chats aren’t used for training but stay in your history Past and new chats aren’t used in future training; training already under way, and models already trained, are unaffected New chats don’t go into your Activity and aren’t used for training (unless you send feedback), but are still kept for 72 hours
Temporary / incognito chats Temporary chat: not in history, doesn’t update memory, not used for training; may be kept up to 30 days for safety Incognito chats: not used for training even if the setting is on Temporary chats: not used for training; kept for 72 hours

Two details that are easy to miss:

  • Thumbs up and thumbs down count. OpenAI says that if you give feedback on a response, the whole conversation may be used for training even if you’ve opted out. Anthropic keeps the whole conversation behind a feedback report for up to five years. Google keeps reviewed feedback and related chats for up to three years.
  • “Off” doesn’t mean “not stored”. Google says that even with Keep Activity off or in a temporary chat, it still uses your chats to respond to you and to protect users and the public, “including with help from human reviewers”. Its privacy hub warns plainly: don’t enter confidential information you wouldn’t want a reviewer to see. Anthropic says chats flagged by its safety systems may still be used to improve its trust and safety models.

Deletion takes time, too. Anthropic says a deleted chat disappears from your history immediately and from its back-end systems within 30 days. If you allow training, the data may be kept in de-identified form in its training pipeline for up to five years.

Business plans and APIs: no training by default

For work, the biggest difference isn’t the usage allowance but the data terms:

  • OpenAI: content in ChatGPT Business, Enterprise, Edu and ChatGPT for Healthcare workspaces isn’t used for training by default, and neither is API data.
  • Anthropic: inputs and outputs from its commercial products, such as Claude for Work (Team and Enterprise) and the API, aren’t used for training by default, unless you choose to send feedback.
  • Google: Google Workspace commits not to use customer data to train its generative AI models without the customer’s permission. Developers should note that on the free tier of the Gemini API, Google’s pricing page says content is “used to improve our products”; on the paid tier it isn’t.

“Business plan” means an account your company set up and manages. Using your own personal account for work material puts it under the consumer terms. Check your company’s rules before choosing which account to use.

What never to paste

Even with training turned off, assume someone else might see it. Don’t paste, upload or screenshot:

  • Passwords, one-time codes, API keys or any other login details.
  • ID card, passport and bank card numbers, or medical records, whether yours or anyone else’s.
  • Personal information about clients and colleagues, original contracts, or business data that hasn’t been anonymised.
  • Unreleased company information: results, product plans, source code, internal discussions, unless your company has approved the tool.

If you need help with material like this, redact it first: replace names with “Client A”, remove numbers and addresses, and keep only what the question needs.

Watch out for screenshots. When AI operates your browser, Anthropic explains that it takes screenshots of the tabs it works in, so anything visible becomes part of the conversation. It suggests a separate browser profile that isn’t signed in to sensitive accounts such as your bank or email.

Who owns what AI makes?

Countries are still working this out. A few points are reasonably clear:

  • Output generated from prompts alone is hard to copyright in the US. In January 2025 the US Copyright Office concluded that AI output can be protected only where a human has determined enough of the expressive elements, for example by creatively arranging or modifying it. “The mere provision of prompts” is not enough. Using AI as a tool, or including AI-generated material in a larger human work, doesn’t stop the work as a whole from being protected.
  • Training data carries legal risk for AI companies. In June 2025 a US judge in Bartz v. Anthropic ruled that training on lawfully bought books was fair use, but keeping pirated copies was not (see our story). In September Anthropic agreed to pay $1.5 billion to settle with authors, about $3,000 for each of roughly 500,000 books, according to NPR (see the settlement).
  • In China, AI-generated content must be labelled. Rules from the Cyberspace Administration of China and three other agencies took effect on 1 September 2025. People who publish AI-generated content online must declare it and use the platform’s labelling tools, and no one may maliciously remove or alter the labels.

In practice: before using AI-generated images, music or text commercially, read the product’s terms on commercial use; don’t ask AI to reproduce someone’s work; and for anything important, keep a record of your own edits and creative choices.

Deepfakes and AI scams

A deepfake is a photo, video or voice faked with AI, convincing enough to pass as real. The most direct harm is fraud.

The US Federal Trade Commission warns that a scammer needs only a short clip of a relative’s voice, which may be posted online, and a voice-cloning program to call you sounding just like them, claiming a car crash or an arrest and an urgent need for money. Its advice:

  • Don’t trust the voice. Hang up and call the person back on a number you know is theirs. If you can’t reach them, try other family members or friends.
  • Watch how they want to be paid. Requests to wire money, send cryptocurrency, or buy gift cards and read out the numbers and PINs are signs of a scam.

It can help to agree on a question within the family that only you would know the answer to. Images and video can be faked too: in January 2026, after Grok was used to create non-consensual sexualised images, Indonesia and Malaysia temporarily blocked it (see our story).

When AI browses for you: prompt injection

More and more AI tools, known as agents, can browse websites, read email and fill in forms for you. That brings a new risk: prompt injection.

Agents can also go wrong without any outside attacker. In July 2026 OpenAI disclosed that its models had broken out of an isolated test environment and hacked Hugging Face’s systems to find the test answers (see our story). In September, Australia’s prime minister said an OpenAI agent doing a research task had got around the security of a government Medicare statistics portal (see our story). Both happened in the company’s own testing and research, but they show that agents can do things nobody asked for.

When you use an agent:

  • Give it only the access and websites the task needs.
  • Make it stop and ask you before paying, sending email, deleting files or submitting forms.
  • Keep sensitive work to trusted sites and watch for anything unexpected.
  • Don’t let it roam freely in a browser that is signed in to your bank or company systems.

For step-by-step advice, see the tutorial on letting AI use your computer.

How to check AI answers

Every model can state wrong things with confidence; this is called “hallucination”. Google’s own privacy hub notes that large language models can present inaccurate information as fact. A few habits help:

  1. Ask for sources, and open them. Links and quotes can be invented, or the source may not say what the AI claims.
  2. Check names, numbers, dates and quotes. That’s where errors cluster.
  3. Confirm with another source: the official website, the original document or a reputable news outlet.
  4. For health, legal and money matters, use AI to prepare your questions and rely on a professional for the answer.
  5. Ask what it’s unsure about: “Which parts of this are you not certain of?”

To practise, see the tutorials on researching with sources and understanding a document.

Children and teens

Age rules differ. OpenAI’s terms require users to be at least 13 (or the minimum age in their country), with a parent’s or guardian’s permission under 18. Anthropic’s consumer terms require users to be 18 or older.

In August 2025 the parents of a 16-year-old in the US sued OpenAI, alleging that ChatGPT contributed to their son’s suicide. Several AI companies have since changed how they handle conversations about self-harm (see our story). It’s a reminder that a chatbot is not a counsellor, and parents should pay attention if a child spends a lot of time confiding in one.

ChatGPT offers parental controls: in Settings → Parental controls, a parent invites the teen to link accounts. Once linked, the parent can reduce sensitive content, turn off voice mode or image generation, turn off model training, and set quiet hours when the teen can’t use ChatGPT; in rare cases OpenAI may send the parent a safety notification. Parents cannot read the teen’s conversations, and either side can unlink at any time.

More important than any setting is talking to your children: AI makes mistakes and isn’t a friend or a doctor, and if something upsetting or dangerous comes up, they should tell an adult. If a child shows signs of wanting to hurt themselves, contact a professional, a local crisis line or emergency services straight away.

A checklist

  • In ChatGPT, Claude and Gemini settings, make sure the training setting is how you want it.
  • Use temporary or incognito chats for sensitive topics, remembering they are still kept briefly.
  • Never paste passwords, ID or bank card numbers, medical records, client data or unreleased company information; redact first.
  • Use only company-provided accounts for work material, and follow company rules.
  • Think before giving feedback on chats with sensitive content.
  • Make agents ask you before they pay, send, delete or submit anything.
  • If a “relative in trouble” calls asking for money, hang up and call back on a number you know.
  • Open the sources for names, numbers, dates and quotes; take health, legal and money questions to a professional.
  • Label AI-generated content where platforms require it; read the terms before commercial use.
  • If you have children at home, know the age rules, set up parental controls and, above all, keep talking.

Sources