Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor



TL;DR

Signal’s Whittaker warns AI chatbots are not sentient and that agentic systems like Copilot needing access to messages and credit cards are a backdoor.

Signal president Meredith Whittaker has warned that AI chatbots “are not your friends,” “are not conscious beings,” and “are not sentient interlocutors,” pushing back against the growing tendency of users to treat AI systems as trusted companions. The comments came in a Bloomberg interview published this week in which Whittaker laid out her case that the agentic AI vision promoted by companies like Microsoft amounts to a new form of surveillance infrastructure.

Whittaker, who has led the encrypted messaging nonprofit since September 2022, acknowledged that she uses AI tools “to format a document here and there” but drew a hard line at anything more substantive. “I don’t ask them questions,” she said.

I’m very serious about my thinking and writing, and I don’t want the process of working through an idea to be foreclosed or eclipsed by the response of a system that’s averaging what’s already out there,” she added.

Her sharpest criticism was directed at Microsoft AI CEO Mustafa Suleyman’s prediction that users would be able to let Microsoft Copilot handle all their Christmas shopping by eavesdropping on family group chats to determine who wants what. Whittaker methodically listed the access such a system would require: “my credit card, my browser, my Signal, the ability to message my siblings on my behalf, my home address, my calendar.

What you’ve just described is a system with very pervasive access across multiple applications and services,” Whittaker said. “In the context of Signal, it would constitute a kind of a backdoor.

The backdoor framing is deliberate and carries weight coming from the head of Signal, which operates the most widely used end-to-end encrypted messaging protocol in the world. Signal’s encryption is also used by WhatsApp, which has more than two billion users. Whittaker has previously said the organisation would leave the EU rather than comply with any law requiring it to compromise its encryption, a position she reiterated when the European Parliament voted in April to let its ePrivacy derogation expire rather than extend voluntary scanning of private messages for child sexual abuse material.

The core of Whittaker’s argument is that agentic AI systems, which need near-total access to a user’s digital life to function, are structurally incompatible with end-to-end encryption. An AI agent that can read your messages before they are encrypted, or after they are decrypted, renders the encryption irrelevant from a privacy standpoint. It does not matter that the messages are encrypted in transit if a system with root-level access is processing them in plaintext on the device.

Whittaker has been making this case with increasing urgency. In January 2026, she warned at Davos that agentic AI was “perilous” for secure applications. In an essay for The Economist, she accused operating system vendors of “hollowing out” Signal’s ability to guarantee privacy by embedding agents into their platforms.

She has described prompt injection, where an attacker manipulates an AI agent into executing unintended commands, as the likeliest first exploit path against encrypted messaging platforms.

Microsoft is building an entire operating system around agent-first computing with Project Solara, unveiled at Build 2026, which replaces traditional apps with AI agents as the primary interface. Google, Apple, and OpenAI are pursuing similar strategies.

Whittaker’s position is that this architectural shift, where agents mediate every interaction between users and their devices, creates databases of entire digital lives that become prime targets for both hackers and governments.

The interview also touched on the broader AI anthropomorphism problem. Suleyman himself has warned about “seemingly conscious AI” and “AI psychosis,” where users believe chatbots are sentient. Whittaker’s framing was more direct: the systems are designed to mimic empathy and understanding, but the underlying mechanism is pattern-matching across training data, not comprehension.

Treating them as confidants means volunteering sensitive information to systems whose data handling practices are opaque and whose operators have commercial incentives to retain and analyse that data.

Whittaker’s position places her at odds with the dominant narrative in Silicon Valley, where the agentic future is presented as an inevitability that will make users more productive. Her counter-argument is that productivity gains achieved by surrendering control of your messages, calendar, contacts, and financial information to a corporate AI system are not gains at all, but a transaction in which users trade privacy for convenience without understanding the terms.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Running a manufacturing business is a constant balancing act between the workshop floor and the balance sheet. Right now, that balance is under real pressure.

The current surge in fuel prices is flowing straight through jobs — via fuel surcharges, higher freight, and rising costs for materials like concrete, plastics, copper, and piping. Costs aren’t rising in isolation; they’re compounding across every job.

It’s this kind of pressure that can expose hard truths about profitability for small businesses, similar to what one growing Australian fabrication business found when examining their balance sheet more closely. Despite strong demand and a consistently full workshop, profitability wasn’t keeping pace with revenue. Hidden margin leaks across labour and materials were quietly eroding results.

By connecting operational job costing with financial reporting using Gojee, Xero, and Syft, the business gained the real-time visibility it needed to stop the leaks and recover more than $165,000 in annual margin.

The challenge: Visibility beyond the spreadsheet

The business relied on Xero for its accounting, but like many manufacturers, its operational job costing was tracked separately in spreadsheets and workshop records.

This created a significant data disconnect. Leadership could see their overall financial results, but they couldn’t clearly identify which specific jobs were driving profit and which were costing the business money.

When CFO advisor Amanda Fisher stepped in to assist the finance team, she used Syft to analyse Xero data and uncovered a startling insight. The business had a target gross margin of 32%, but was actually achieving only 29.7%. That gap represented nearly $180,000 in lost profit every year.

“As a CFO, the key to decision-making is real-time data. Syft is perfect for visuals that help business owners understand the big picture. But in manufacturing, the devil is in the detail. That’s where Gojee helps uncover hidden margin leaks and bridge the gap between the factory floor and finance.” 

– Amanda Fisher, Xero accountant & CFO advisor

The solution: A connected tech stack

To bridge the gap, Amanda introduced Gojee to manage job costing and workflows directly alongside Xero. This created a seamless flow of data:

  • Gojee captures real-time labour hours and material purchases on the factory floor.
  • Xero handles the financial transactions, bills, and invoicing.
  • Syft translates that data into visual dashboards for margin analysis and trend tracking.

What the data revealed

Once the business had real-time visibility, three common profit leaks emerged:

  • Labour rework: One project quoted for 720 hours actually took 845 hours, reducing the margin by over $10,000. Annually, labour overruns cost the business approximately $95,625.
  • Materials price variance: Quoting based on estimated costs rather than confirmed supplier invoices led to $66,000 in annual margin erosion.
  • Low-margin jobs: Analysis showed that smaller, complex custom projects often disrupted workshop productivity. One $75,000 project achieved only an 18% margin, far below the 30% expectation.

The results: From reactive to proactive

Armed with these insights, the company adjusted its quoting strategy and began prioritising higher-margin work. Within 12 months, the results were transformative:

Metric Before After
Gross margin 29.7% 31.8%
Annual profit $165K+ recovered

Today, the business doesn’t just work harder; it works smarter. The machines and the team haven’t changed, but the visibility has. By moving from reactive reporting to proactive decision-making, they have turned a busy workshop into a highly profitable one.


Explore apps in the Xero App Store to see how  Xero + connected apps help to uncover hidden profits in your business:

  • Explore Gojee to streamline your job costing.
  • See how Syft can transform your Xero data into powerful financial insights and comprehensive reports.

Was this article helpful?

YesNo



Source link