AI Chatbots Expose Sensitive Data
Coverage from Precedence Research, Startup Fortune, and others

Consumer AI chatbots increasingly process personal, confidential, and health information, while providers differ in how they store conversations, use them for model improvement, review them, and honor deletion or opt-out requests.
ChatGPT, Claude, Gemini, and Grok offer varying controls and enterprise protections, but disabling training does not necessarily erase prior data or prevent temporary retention. The rollout of connected health features adds practical utility while raising questions about breach exposure, consent, medical reliability, and whether data remains covered by healthcare privacy protections.
The story broadens from OpenAI’s sensitive-data features to a comparative examination of privacy practices across major consumer AI providers. New testing and retention findings make unclear deletion, secondary use, and disclosure risks more concrete, while health-data concerns remain a major application.
The story is sharpened around specific ChatGPT product rollouts for finance and health, with clearer claims about data protections and a new human-review safety feature for self-harm cases. The cyber incident is also reframed as a Japanese allegation involving a teenager and rotating IPs, rather than a more general disruptive-code example.
