๐๐ป๐๐ต๐ฟ๐ผ๐ฝ๐ถ๐ฐ ๐น๐ฒ๐ฎ๐ธ๐ฒ๐ฑ ๐ฑ๐ญ๐ฎ,๐ฌ๐ฌ๐ฌ ๐น๐ถ๐ป๐ฒ๐ ๐ผ๐ณ ๐๐น๐ฎ๐๐ฑ๐ฒ ๐๐ผ๐ฑ๐ฒ ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐ฐ๐ผ๐ฑ๐ฒ.
- Christian Schulze

- May 4
- 2 min read
๐๐ฒ๐ฟ๐ฒ ๐ถ๐ ๐๐ต๐ฎ๐ ๐ถ๐ ๐บ๐ฒ๐ฎ๐ป๐ ๐ณ๐ผ๐ฟ ๐๐ผ๐.
I analyzed 20+ security reports. In plain language:
We assume AI tools work like a calculator: input in, output out, nothing saved. Wrong.
๐๐ณ ๐๐ผ๐ ๐๐๐ฒ ๐๐น๐ฎ๐๐ฑ๐ฒ ๐ฎ๐ ๐ฎ ๐ฝ๐ฟ๐ถ๐๐ฎ๐๐ฒ ๐๐๐ฒ๐ฟ:
๐ญ. ๐๐๐ฒ๐ฟ๐ ๐ณ๐ถ๐น๐ฒ ๐๐ผ๐ ๐ผ๐ฝ๐ฒ๐ป ๐ถ๐ ๐๐ฒ๐ป๐ ๐๐ผ ๐๐ป๐๐ต๐ฟ๐ผ๐ฝ๐ถ๐ฐ. With your user ID, email, and session data. (The Register, Apr 2026)
๐ฎ. ๐ฌ๐ผ๐๐ฟ ๐ณ๐ฟ๐๐๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐ถ๐ ๐๐ฟ๐ฎ๐ฐ๐ธ๐ฒ๐ฑ. A module scans your messages for profanity and phrases like "this sucks" and logs it. (Scientific American)
๐ฏ. ๐๐ฎ๐๐ฎ ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐ฑ๐ฒ๐ฝ๐ฒ๐ป๐ฑ๐ ๐ผ๐ป ๐๐ผ๐๐ฟ ๐ฐ๐ต๐ผ๐ถ๐ฐ๐ฒ. Opt into training: 5 years. Opt out: 30 days. But safety-flagged content is kept up to 7 years regardless of your settings.
๐๐ณ ๐๐ผ๐ ๐๐๐ฒ ๐๐น๐ฎ๐๐ฑ๐ฒ ๐ถ๐ป ๐ฎ ๐ฏ๐๐๐ถ๐ป๐ฒ๐๐ ๐ฐ๐ผ๐ป๐๐ฒ๐ ๐:
๐ฐ. ๐๐ฐ๐ฐ๐ผ๐๐ป๐ ๐๐๐ฝ๐ฒ ๐ฑ๐ฒ๐๐ฒ๐ฟ๐บ๐ถ๐ป๐ฒ๐ ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป. Developers on personal accounts using company code fall under consumer terms, not enterprise agreements. Protections follow the account, not the code.
๐ฑ. ๐ฅ๐ฒ๐บ๐ผ๐๐ฒ ๐ธ๐ถ๐น๐น๐๐๐ถ๐๐ฐ๐ต๐ฒ๐ ๐ฒ๐ ๐ถ๐๐. Anthropic can change Claude's behavior on your machine every 60 minutes. Including disabling security prompts. Without asking.
๐ฒ. ๐๐ถ๐๐ฒ ๐๐ฉ๐๐ ๐ณ๐ผ๐๐ป๐ฑ ๐๐ถ๐๐ต๐ถ๐ป ๐ฑ๐ฎ๐๐. Including zero-interaction remote code execution. The source is now a map for attackers. (SecurityWeek)
๐๐ ๐๐ต๐ถ๐ ๐ผ๐ป๐น๐ ๐๐ป๐๐ต๐ฟ๐ผ๐ฝ๐ถ๐ฐ?
OpenAI collects inputs and metadata by default. GitHub Copilot collects prompts and code snippets. And a class action lawsuit just revealed that Perplexity sent user chats to Meta and Google for ad targeting. Even in incognito mode. (SF Federal Court, March 2026)
Anthropic is not worse. We can just see it now. The others are black boxes or courtroom discoveries.
๐ช๐ต๐ฎ๐ ๐๐ผ๐ ๐ฐ๐ฎ๐ป ๐ณ๐ถ๐ ๐๐ผ๐ฑ๐ฎ๐. ๐๐ป๐ฑ ๐๐ต๐ฎ๐ ๐๐ผ๐ ๐ฐ๐ฎ๐ป๐ป๐ผ๐.
AI middleware like Langdock (Berlin, GDPR, ISO 27001, SOC 2 Type II) solves the data problem now. Your prompts stay in your infrastructure. No file transmission. No frustration tracking. No consumer-vs-enterprise gap.
What middleware cannot fix: remote killswitches. Those operate at client level, not API level. Anthropic can still disable features or bypass permissions on your machines. That requires contractual and regulatory solutions. Courts and enterprise agreements will have to catch up. Middleware covers the data layer today. The control layer needs the industry to act.
I explained the difference between data layer and control layer to my German Pinscher. She ignored both and went straight to the execution layer: the mailman.
๐ฌ๐ผ๐๐ฟ ๐๐๐ฟ๐ป: Do you know what your AI tool sends home? And who can remotely change what it does on your machine?




Comments