Threat patterns
How AI privacy risk evolves
Most privacy advice tells you what to do. It rarely tells you when the advice stopped working. These pages track how a class of risk changes, and which of your controls it has already outrun.
A threat pattern is not an incident report. Incidents age badly, and a list of them tells you little about what to do on Monday. A pattern records how a class of risk moves — and specifically how each generation of it defeats the control that stopped the generation before.
That structure is the point. If a control you rely on was designed against generation one, and the thing you are facing is generation three, you are protected against a problem that no longer exists. Each pattern below therefore separates two things carefully:
- What used to work and no longer does. Recorded so that nobody acts on it. A superseded control presented as current advice is worse than silence.
- What still works. Usually something organisational rather than a product setting, because settings are what each new generation tends to route around.
How to read the status line
Every pattern ends by saying whether a person has read its sources end to end. Where it says they have not, treat the pattern as a draft position: the facts are cited and dated, but nobody has yet sat down with the underlying documents in full. We would rather publish that distinction than quietly imply a level of checking that has not happened.
Where a pattern refers to litigation, it says what is alleged and what a court has actually decided. Those are different things, and an allegation is not a finding. When we get something wrong we correct it and say so — see Corrections.
Looking for how attackers use AI against you — faked calls to change bank details, cloned voices, redirected payments? That is a different dataset and it has its own page. The patterns below are about what AI vendors do with your data.
A worked example
If the patterns below read as abstract, start with the worked example. It takes four rules a careful firm would actually write into an AI policy and shows each one being defeated by a dated change — including the two that arrived as a dialog box somebody clicked through, and the one that was already wrong on the day it was written.
The notetaker everyone can see
How this family has moved:
- Generation 1: The notetaker everyone can see ← this one
- Generation 2: The assistant that joins meetings you never invited it to
- Generation 3: The recorder with no bot to see
A meeting assistant joins the call as a named participant. Other attendees can see it in the participant list.
The control that made this tolerable was disclosure by presence: the tool's own visibility was treated as telling everyone that recording and transcription were happening.
That was never consent. It was a signal, and it worked only for as long as the tool stayed visible.
What still works:
- Say at the start of the meeting that an AI notetaker is running, and put a line in the invite.
- Treat a visible bot as a prompt to disclose, never as the disclosure itself.
- New Zealand is a ONE-party consent jurisdiction: under s216B(2) of the Crimes Act 1961 a person who is a party to a private communication may lawfully record it without the others agreeing. Disclose anyway, for three reasons that do apply - the Privacy Act 2020 requires you to tell people what you are collecting and why (a notification duty, not a consent one); covertly recording colleagues can breach the employment duty of good faith; and any participant sitting in a genuine all-party consent state brings that law to your call.
- Corrected 3 September 2026: this previously said New Zealand was a two-party-consent jurisdiction requiring agreement. It is not. The advice to disclose was right; the reason given for it was wrong.
Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- AI Leakage vendor profile: Fathom - visible-bot architecture, the Fathom Notetaker appears as a named participant.
- AI Leakage vendor profile: Otter.ai.
- Read in full 3 September 2026: every source cited above was read directly at the vendor's own documentation, not via third-party summary.
- Crimes Act 1961 (NZ) s216B(2) - one-party consent. Verified 3 September 2026 through two independent legal summaries that cite the subsection, one of them quoting it directly. NOT read in the original: legislation.govt.nz and the UNODC mirror both refused our fetch with HTTP 403, so the statute text itself remains unread and this pattern is marked unreviewed for that reason.
Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.
The assistant that joins meetings you never invited it to
How this family has moved:
- Generation 1: The notetaker everyone can see
- Generation 2: The assistant that joins meetings you never invited it to ← this one
- Generation 3: The recorder with no bot to see
The assistant connects to a calendar and joins meetings automatically, including meetings organised by other people.
This defeats disclosure by presence for the person who is recorded but never chose the tool. Such people are frequently not account holders, so there is no setting for them to change and no opt-out available to them.
In re Otter.AI Privacy Litigation consolidates four federal class actions filed between August and September 2025, pleading wiretap and California Invasion of Privacy Act claims and, in some cases, biometric claims. The named plaintiff in Brewer was not an Otter account holder.
On 13 August 2026 the court granted Otter's motion to dismiss in part and denied it in part. The federal wiretap, California Invasion of Privacy Act and Illinois biometric claims SURVIVED and proceed. Judge Eumi K. Lee rejected the argument that Otter was merely a tool acting for the meeting host, holding it could be treated as a third-party eavesdropper because it retained the conversations and used them for its own commercial purposes, including training its models. Nothing has been proven on the merits.
What used to work and no longer does:
- Disclosure by presence - the recorded person may never have seen the invite, let alone the participant list.
- Turn it off in settings - the affected person has no account, so has no settings.
What still works:
- Decide as an organisation which meetings may be recorded, and apply that to the calendar rather than to the tool.
- Ask attendees at the start. Do not rely on the tool announcing itself.
- Check whether your assistant auto-joins from the calendar by default, and turn that off unless you want it.
- Ask whether the tool trains on what it records. After the 13 August 2026 ruling that is not only a privacy preference: the court treated a vendor's own use of the recording as what distinguishes an eavesdropper from a participant.
Why the second one holds and the first did not. The control this generation defeated rested on how things were arranged, and the arrangement stopped holding. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- In re Otter.AI Privacy Litigation, four cases consolidated 22 October 2025, N.D. Cal. (Brewer v. Otter.ai Inc., No. 5:25-cv-06911, filed August 2025).
- Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399-SEM-DJQ (C.D. Ill.), filed 18 December 2025 by Katelin Cruz pleading BIPA sections 15(a) and 15(b); VOLUNTARILY DISMISSED 11 March 2026 with no responsive pleading ever filed, so nothing was decided. Complaint read in full 3 September 2026.
- AI Leakage vendor profile: Otter.ai.
- In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal.), order on motion to dismiss, 13 August 2026 - granted in part, denied in part.
- NOT marked reviewed, 3 September 2026: the 13 August 2026 order in In re Otter.AI has been read only through two independent reports of it, not in the original. CourtListener disallows automated fetching, so the order itself remains unread. The Cruz v. Fireflies complaint, by contrast, WAS read in full.
Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.
The recorder with no bot to see
How this family has moved:
- Generation 1: The notetaker everyone can see
- Generation 2: The assistant that joins meetings you never invited it to
- Generation 3: The recorder with no bot to see ← this one
The assistant captures microphone and system audio directly on the user's own device. No participant joins the call, so there is nothing in the participant list for anyone to notice.
This defeats disclosure by presence completely rather than partially, and the absence of a visible bot is marketed as a feature.
Chamberlain v. Granola pleads seven claims including intrusion upon seclusion, the federal Electronic Communications Privacy Act, and California Invasion of Privacy Act sections 631 and 632. The complaint quotes the vendor's own marketing to argue the lack of disclosure is a deliberate design choice, and notes that the people captured are frequently not account holders. Nothing has been proven and no response had been filed at the time of writing.
What used to work and no longer does:
- Disclosure by presence - there is no presence at all.
- Check the participant list - the recorder never appears in it.
- Anything that depends on the recorded person being able to detect the tool.
What still works:
- Disclosure has to come from the person running the tool. No technical signal will do it for them any more.
- Put it in the invite and say it at the start.
- Assume any meeting may be captured by somebody else's tool, and treat what you say accordingly.
Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- Chamberlain v. Granola, Inc. and Granola Labs Ltd., No. 3:26-cv-07926-EMC, N.D. Cal., filed 30 July 2026.
- AI Leakage vendor profile: Granola.
- NOT marked reviewed, 3 September 2026: the Chamberlain v. Granola complaint has been read only through a law-firm client alert, not in the original. Everything else here was read directly.
Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.
The bargain nobody reads: free products train on what you type
How this family has moved:
- Generation 1: The bargain nobody reads: free products train on what you type ← this one
- Generation 2: Paying does not make you the customer
- Generation 3: The default flips under you
- Generation 4: Training on what you record stops being a preference and becomes a legal line
A free consumer AI product uses your inputs to improve its models, and says so in terms you accepted without reading.
The control that made this tolerable was disclosure plus choice: it is in the terms, and you can pay for something else.
That control assumed two things which the later generations break - that paying changes the default, and that the default you checked is the default you still have.
What still works:
- Decide what may be typed into a free AI product at all, and make that an organisational rule rather than an individual judgement.
- Assume anything pasted into a consumer tier may be used to improve the product, whatever the current setting says.
Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- AI Leakage vendor profiles: ChatGPT, Claude, Gemini, Perplexity - all record training on by default on consumer tiers with an opt-out.
- Read in full 3 September 2026: every source cited above was read directly at the vendor's own documentation, not via third-party summary.
Every source behind this pattern has been read in full.
Paying does not make you the customer
How this family has moved:
- Generation 1: The bargain nobody reads: free products train on what you type
- Generation 2: Paying does not make you the customer ← this one
- Generation 3: The default flips under you
- Generation 4: Training on what you record stops being a preference and becomes a legal line
The paid individual tier carries the same training default as the free one. ChatGPT Plus and Pro, Claude Pro and Max, GitHub Copilot Pro, Pro+ and Max, Perplexity Pro - all are consumer terms with training on by default and an opt-out you must find.
This defeats the most common control people actually rely on, which is not reading the terms but the belief that 'I pay for this, so I am the customer rather than the product'.
It is also where the money argument inverts: on several products the jump to a business tier, where training is contractually excluded, is small. GitHub Copilot Pro to Business is $9 a user a month.
What used to work and no longer does:
- 'I pay for it, so they are not training on it' - false on every major consumer AI product we rate.
- 'The paid tier is the safe tier' - the safe tier is the COMMERCIAL tier, which is a different thing and often costs less than the top individual plan.
What still works:
- For any client or commercial work, use the business or enterprise tier, where training exclusion is contractual rather than a toggle.
- Price the upgrade before assuming it is expensive. It is frequently cheaper than the premium individual plan people buy instead.
- If you must use an individual tier, turn the setting off and record who did it and when.
Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- AI Leakage vendor profiles, all re-verified 3 September 2026 against vendor documentation: ChatGPT (OpenAI help centre lists Free, Plus and Pro as training-on by default; Business, Enterprise, Edu and API excluded); Claude (consumer tiers on by default, commercial terms excluded); GitHub Copilot (Free, Pro, Pro+ and Max on by default from 24 April 2026, Business and Enterprise excluded).
- Read in full 3 September 2026: every source cited above was read directly at the vendor's own documentation, not via third-party summary.
Every source behind this pattern has been read in full.
The default flips under you
How this family has moved:
- Generation 1: The bargain nobody reads: free products train on what you type
- Generation 2: Paying does not make you the customer
- Generation 3: The default flips under you ← this one
- Generation 4: Training on what you record stops being a preference and becomes a legal line
A product that did not train on your content starts doing so, and the change arrives as a dialog you click through.
Anthropic announced the change for consumer Claude on 28 August 2025; contemporaneous reporting described the training toggle in the acceptance pop-up as automatically set to on beneath a prominent Accept button. GitHub did the same for Copilot Free, Pro, Pro+ and Max with effect from 24 April 2026.
This defeats the control that survived generation two, which was to check the setting once - at purchase, at procurement, at policy-writing time. A setting checked in March can be a different setting in May without anyone at your end doing anything.
What used to work and no longer does:
- 'We checked the training setting when we adopted the tool' - the vendor can change the default afterwards.
- 'It is in our AI policy, which we reviewed at the start of the year' - a policy naming a vendor's posture is a snapshot, and it decays.
- 'We would have noticed' - these changes arrive as terms-acceptance dialogs, which are designed to be clicked through.
What still works:
- Re-check the training setting on a schedule rather than at adoption, and treat a terms-update dialog as a trigger to re-check rather than an interruption.
- Write the policy against the QUESTION, not the vendor's current answer: 'training must be off wherever client data is entered', not 'Vendor X does not train'.
- Prefer commercial tiers, where the exclusion is contractual and cannot be flipped by a product decision.
Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- Anthropic: Updates to our Consumer Terms and Privacy Policy (announced 28 August 2025).
- TechCrunch, 28 August 2025, reporting the acceptance dialog with the training toggle automatically set to on.
- GitHub Blog: Updates to GitHub Copilot interaction data usage policy, effective 24 April 2026.
- Both re-read 3 September 2026.
- Read in full 3 September 2026: every source cited above was read directly at the vendor's own documentation, not via third-party summary.
Every source behind this pattern has been read in full.
Training on what you record stops being a preference and becomes a legal line
How this family has moved:
- Generation 1: The bargain nobody reads: free products train on what you type
- Generation 2: Paying does not make you the customer
- Generation 3: The default flips under you
- Generation 4: Training on what you record stops being a preference and becomes a legal line ← this one
On 13 August 2026, in In re Otter.AI Privacy Litigation, the court granted Otter's motion to dismiss in part and denied it in part. Federal wiretap, California Invasion of Privacy Act and Illinois biometric claims survived and proceed.
The reasoning is what matters here. Otter argued it was merely a tool acting for the meeting host. The court rejected that and held it could be treated as a THIRD-PARTY EAVESDROPPER, because it retained the conversations and used them for its own commercial purposes, INCLUDING TRAINING MACHINE-LEARNING MODELS.
So the question 'does this tool train on what it records' is no longer only a privacy preference to be toggled. A US court has treated a vendor's own use of the recording as the thing that distinguishes a participant from an eavesdropper. Nothing has been proven on the merits; this is the pleading stage. But the theory has survived, and it reaches any meeting tool that trains on what it captures.
What used to work and no longer does:
- 'Training is a privacy preference, so we handle it in the privacy policy' - it now also bears on wiretap and consent exposure.
- 'The host consented, so the tool is covered' - that is precisely the argument the court declined to accept at this stage.
- 'We turned training off, so this does not apply to us' - it applies to what the vendor did with recordings you have already made, not only to what it does next.
What still works:
- Ask of any meeting tool, in writing, whether it trains on captured content and on which tiers. Treat the answer as a contractual question, not a settings question.
- Where the answer is yes on your tier, either move to a tier where the exclusion is contractual, or stop recording conversations you do not have express consent to record.
- Disclosure to every participant, out loud and in the invite, is the control that survives all four generations of this pattern.
Why the second one holds and the first did not. The control this generation defeated rested on how things were arranged, and the arrangement stopped holding. What still works rests on how you are organised - decided before the moment rather than in it.
Sources:
- In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal.), order on motion to dismiss, 13 August 2026, granted in part and denied in part.
- National Law Review report of the order; UC Today report of the order. Both read 2 September 2026.
- AI Leakage vendor profiles recording training-by-default on meeting tools: Fathom (all tiers), Granola (Free and Business), Otter (Free and Pro).
- NOT marked reviewed, 3 September 2026: the 13 August 2026 order in In re Otter.AI has been read only through two independent reports of it, not in the original. CourtListener disallows automated fetching, so the order itself remains unread. The Cruz v. Fireflies complaint, by contrast, WAS read in full.
Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.
