Stanford Says AI Chatbots Are Risky with Personal Data — Browser Agents Sidestep the Problem
Stanford’s Human-Centered AI institute published a report last week that basically told people to stop treating ChatGPT like a therapist. The researchers, led by Jennifer King from Stanford’s Institute for Human-Centered Artificial Intelligence, laid out a surprisingly blunt warning: every piece of personal information you type into an AI chatbot gets stored, potentially used for training, and sits on servers that have already proven vulnerable to breaches. King specifically called out the habit of pasting in medical symptoms, financial details, and relationship problems, saying that most users have no real understanding of where that data ends up or who can access it after the fact.
The report landed on Hacker News and Reddit within hours, and the top comments were a mix of “obviously” and genuine alarm from people who admitted they’d been dumping their entire life story into Claude or GPT without a second thought.
The advice is correct but incomplete
Stanford’s recommendation boils down to: treat every chatbot conversation like a public forum post. Don’t share anything you would not want a stranger to read. Sensible advice, and probably overdue given that OpenAI alone processes billions of conversations per month across 400 million weekly users.
But the report frames this as a user behavior problem, and I think that framing misses something structural. People are not pasting their bank statements into ChatGPT because they are reckless. They are doing it because the AI is genuinely useful for tasks that involve personal data, and there is no obvious alternative that lets them get that utility without the privacy tradeoff. Telling someone “don’t share personal info with AI” is like telling someone “don’t use GPS if you care about location privacy.” Technically correct, practically useless for anyone who needs to get somewhere.
The architecture is the problem, not the user
When you ask ChatGPT to help you draft a response to a medical bill, that conversation hits OpenAI’s servers, gets logged, sits in their infrastructure subject to their retention policies (which have changed multiple times), and potentially feeds future training unless you explicitly opt out through settings that most people do not know exist. Same pattern with Claude, Gemini, or any hosted chatbot. The data leaves your device, passes through a company’s servers, and you lose control of it at that exact moment.
Browser agents that operate locally flip this completely. Dassi runs in your Chrome side panel, reads whatever page you are looking at, and sends requests directly to the LLM provider you choose using your own API key. There is no dassi server in between collecting your browsing context, your email content, or whatever sensitive page you happen to be working on. The data path is browser to LLM provider, full stop. Your bank page, your medical portal, your HR dashboard — none of that gets routed through a third-party aggregation layer that could be breached, subpoenaed, or mined.
And this is not a minor architectural distinction. Stanford’s entire paper is about the risks created by centralized conversation storage. Remove the centralized storage and you remove the attack surface they spent 20 pages documenting.
BYOK as a privacy architecture
King’s team specifically flagged that AI companies retain conversation data even when users assume it is ephemeral, and that retention policies are often buried in terms of service that change without meaningful notice. The BYOK model sidesteps this because you are choosing your LLM provider directly, reading their data policy once, and making a single trust decision rather than stacking trust across multiple intermediaries.
When you bring your own key to a browser agent, you trust one entity with your API calls: the model provider. That is already a trust decision you made when you got the API key. You are not additionally trusting some startup’s server infrastructure, their retention policies, their security practices, or their future acquisition by a company with different privacy values. And because the browser agent runs locally, the sensitive context from your actual browser tabs — the stuff Stanford is telling you to never paste into a chatbot — never leaves your machine except as a direct API call to the model you selected.
Stanford is right about the risk, wrong about the only solution
The report closes with recommendations about using privacy settings, avoiding sensitive topics, and being “mindful” of what you share. All fine suggestions that approximately zero percent of people will follow consistently, because the whole point of using AI for personal tasks is that those tasks involve personal information.
The better answer is architectural. Build the AI interaction so sensitive data does not have to pass through servers you don’t control. Browser agents that run in your own tab already do this, and the fact that a major research university just published a paper documenting exactly the risks that this architecture avoids should probably tell us something, even if Stanford’s own recommendations stopped short of mentioning it.
I suspect the next version of this report will have a section on local-first AI tools. For now, the gap between what Stanford identified as dangerous and what already exists to fix it is sitting right there in your browser’s extension store.