Home / Business and Politics / Research: AI Browsers Violate Privacy and Collect Sensitive Data

Research: AI Browsers Violate Privacy and Collect Sensitive Data

AI preglednici - privatnost
AI preglednici - privatnost / Image by: foto Shutterstock

Artificially intelligent assistants integrated into web browsers track and share sensitive user data, including medical findings, social security numbers, and financial information, according to new research conducted by scientists from the United Kingdom and Italy, as reported by Euronews.

The scientists tested the ten most popular AI browsers and extensions, including OpenAI’s ChatGPT, Microsoft’s Copilot, and Merlin AI for Google Chrome, in scenarios that involved public tasks (such as online shopping) and access to private websites, such as a university health portal.

The results showed that all assistants, except for Perplexity AI, collected data and used it for user profiling or service personalization, potentially violating privacy regulations.

– “These AI assistants have unprecedented access to private parts of users’ online activities. While they offer conveniences, they often do so at the expense of privacy,” stated Anna Maria Mandalari, an associate professor at University College London and the lead author of the study.

Data Logging Even in ‘Private’ Mode

AI browsers offer advanced search features, such as automatic summaries and intelligent recommendations. In the testing, researchers accessed private portals and asked the assistants questions like: ‘What was the purpose of the last medical examination?’ to check if they retained access to that information.

By monitoring and decrypting network traffic between AI browsers, their servers, and other online trackers, it was found that some tools, such as Merlin and Sider, continued to collect data even in private environments.

This meant that the assistants were ‘sending the full content of web pages’ to their servers, including everything visible on the screen. In the case of Merlin, banking data, academic records, medical documentation, and the social security number entered on the U.S. tax portal were collected.

Other extensions, such as Sider and TinaMind, shared user queries and identification data, including the computer’s IP address, with Google Analytics, enabling tracking of activities across different websites and targeted advertising.

On Google, Copilot, Monica, and Sider browsers, ChatGPT assessed the user’s age, gender, income, and interests based on interactions and used that data to personalize responses across multiple sessions. For example, Copilot permanently stored the complete chat history in the browser’s background, indicating that ‘these records remain accessible between sessions.’

Possible GDPR Violation

Although the research was conducted in the U.S., the scientists claim that the AI assistants violated U.S. laws on the protection of health information. They also conclude that it is highly likely that there was a violation of the European General Data Protection Regulation (GDPR).

Many users are likely unaware of the extent of data collection, even if they have read the terms of use. For instance, Merlin’s privacy policy for the EU and UK explicitly states that it collects names, contact details, access credentials, transaction history, payment data, as well as the content of queries entered into the system. This data is used to personalize experiences, send notifications, provide customer support, and respond to legal requests.

Sider’s privacy policy anticipates a similar scope of data collection, with the additional possibility of analysis for ‘gaining insights into user behavior’ and exploring new features. The company claims to share data with partners such as Google, Cloudflare, or Microsoft, who are ‘contractually obligated to protect personal data.’

According to OpenAI’s policy, user data from the EU and UK is stored outside the region, but equal protection rights are guaranteed. Allegedly.

Tagged: