Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor



TL;DR

Signal’s Whittaker warns AI chatbots are not sentient and that agentic systems like Copilot needing access to messages and credit cards are a backdoor.

Signal president Meredith Whittaker has warned that AI chatbots “are not your friends,” “are not conscious beings,” and “are not sentient interlocutors,” pushing back against the growing tendency of users to treat AI systems as trusted companions. The comments came in a Bloomberg interview published this week in which Whittaker laid out her case that the agentic AI vision promoted by companies like Microsoft amounts to a new form of surveillance infrastructure.

Whittaker, who has led the encrypted messaging nonprofit since September 2022, acknowledged that she uses AI tools “to format a document here and there” but drew a hard line at anything more substantive. “I don’t ask them questions,” she said.

I’m very serious about my thinking and writing, and I don’t want the process of working through an idea to be foreclosed or eclipsed by the response of a system that’s averaging what’s already out there,” she added.

Her sharpest criticism was directed at Microsoft AI CEO Mustafa Suleyman’s prediction that users would be able to let Microsoft Copilot handle all their Christmas shopping by eavesdropping on family group chats to determine who wants what. Whittaker methodically listed the access such a system would require: “my credit card, my browser, my Signal, the ability to message my siblings on my behalf, my home address, my calendar.

What you’ve just described is a system with very pervasive access across multiple applications and services,” Whittaker said. “In the context of Signal, it would constitute a kind of a backdoor.

The backdoor framing is deliberate and carries weight coming from the head of Signal, which operates the most widely used end-to-end encrypted messaging protocol in the world. Signal’s encryption is also used by WhatsApp, which has more than two billion users. Whittaker has previously said the organisation would leave the EU rather than comply with any law requiring it to compromise its encryption, a position she reiterated when the European Parliament voted in April to let its ePrivacy derogation expire rather than extend voluntary scanning of private messages for child sexual abuse material.

The core of Whittaker’s argument is that agentic AI systems, which need near-total access to a user’s digital life to function, are structurally incompatible with end-to-end encryption. An AI agent that can read your messages before they are encrypted, or after they are decrypted, renders the encryption irrelevant from a privacy standpoint. It does not matter that the messages are encrypted in transit if a system with root-level access is processing them in plaintext on the device.

Whittaker has been making this case with increasing urgency. In January 2026, she warned at Davos that agentic AI was “perilous” for secure applications. In an essay for The Economist, she accused operating system vendors of “hollowing out” Signal’s ability to guarantee privacy by embedding agents into their platforms.

She has described prompt injection, where an attacker manipulates an AI agent into executing unintended commands, as the likeliest first exploit path against encrypted messaging platforms.

Microsoft is building an entire operating system around agent-first computing with Project Solara, unveiled at Build 2026, which replaces traditional apps with AI agents as the primary interface. Google, Apple, and OpenAI are pursuing similar strategies.

Whittaker’s position is that this architectural shift, where agents mediate every interaction between users and their devices, creates databases of entire digital lives that become prime targets for both hackers and governments.

The interview also touched on the broader AI anthropomorphism problem. Suleyman himself has warned about “seemingly conscious AI” and “AI psychosis,” where users believe chatbots are sentient. Whittaker’s framing was more direct: the systems are designed to mimic empathy and understanding, but the underlying mechanism is pattern-matching across training data, not comprehension.

Treating them as confidants means volunteering sensitive information to systems whose data handling practices are opaque and whose operators have commercial incentives to retain and analyse that data.

Whittaker’s position places her at odds with the dominant narrative in Silicon Valley, where the agentic future is presented as an inevitability that will make users more productive. Her counter-argument is that productivity gains achieved by surrendering control of your messages, calendar, contacts, and financial information to a corporate AI system are not gains at all, but a transaction in which users trade privacy for convenience without understanding the terms.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


The Government’s ‘Company Accounts and Tax Online’ (CATO) filing service allows small companies with the simplest affairs to file their company accounts and corporation tax return simultaneously with Companies House and HMRC. However, if you run a small business and use this service things are about to change.

The Government is closing the CATO portal on 31 March 2026. After that date, companies will no longer be able to file their company accounts and corporation  tax returns for free via CATO. You’ll need to either use commercial software or work with a professional accountant to do it for you. For the many micro‑entities and small companies that currently file on their own, this is a significant shift.

Some businesses may still be able to use a free web‑filing service from Companies House for micro‑entity or dormant accounts, but that only covers the filing of your statutory accounts – not your corporation tax return to HMRC – and that service is also expected to close in the near future. So, it makes sense to address both needs together when planning how you navigate the CATO closure.

Acting early to make life easier

Although CATO shuts on 31st March, many companies and their directors won’t feel the impact until months later, when their next filing deadline comes around. If you wait until that crunch point, you may find yourself:

  • choosing and learning new software under deadline pressure
  • hurriedly migrating or re‑entering data
  • settling for “whatever works right now”, even if it’s not a good long‑term fit.

And the reality is that all of these things increase the risk of making mistakes, filing incorrect data or even filing late, all of which could lead to penalties or in extreme cases being struck off.

If you usually use the Government’s free service and your filing deadline falls between now and 31 March, it’s business as usual for this year. Now is the time to start preparing for the transition. We recommend getting your filings in as early as possible this year to avoid a last-minute rush. This also gives you the space to begin exploring how a professional accountant or bookkeeper can support your business through these changes. Preparation is the key to a successful, stress-free transition next year.

If your filing deadline falls not long after the 31st March, say April, May or June then it would be worth giving some thought, if practical, to trying to file a little earlier this year in order to avoid rushed decisions. If you could file before the 31st March in order to utilise CATO then you’ve effectively bought yourself  a year to make the right long term decision that’s the right strategic fit for you and your business. This isn’t going to be possible in all cases but it’s certainly worth thinking about!   

Regardless of how or when you plan to file your next set of accounts and tax return, the Government is encouraging all CATO users to ensure they download and save all their previously submitted accounts and tax returns via the portal before it closes. After the 31st March you won’t be able to access your historical submissions and you may find you need them in the future. The government has provided instructions on how to do this here.

Why an accountant or bookkeeper is still best practice

For many small businesses, the best route through this change will be to work closely with an accountant or bookkeeper. They can:

  • guide you through software choices and setup
  • help you understand whether your affairs really are “simple enough” to keep doing it yourself or whether it’s time to get expert help from a professional
  • advise on the most suitable approach for your size and sector
  • make sure your bookkeeping, accounts and tax all join up smoothly.

The right software choice and set up coupled with good digital record keeping throughout the year can lead to a streamlined, stress free year end process that’s more about review and approval than last minute data entry, re-keying of data and stressful reconciliations. An experienced advisor can design and run that system with you, as hands on or as hands off as needed, so you stay compliant and confident without needing to become a tax or software expert yourself.

Whilst CATO’s closure is undoubtedly frustrating for many, it’s also a timely reminder to take a step back and make sure your whole set up and year‑end process is fit for the future. Take the opportunity now to talk to an accountant or bookkeeper and put a simple, joined-up plan in place – so when the portal disappears, you’re already one step ahead.

Was this article helpful?

YesNo



Source link