
And you - as the intellectually curious person that you are - should read a few of her blog posts.
Concerns about technology eroding human capability are nothing new, but it’s different with AI. When Google became the default way to look something up, research has shown that we retain less of what we google than we would if googling wasn’t an option. Researchers found that the easier information is to retrieve externally, the less deeply we encode it internally or put simpler: easy retrieval comes at the cost of retention of information (Sparrow et al., 2011). However, when it comes to loss of human capabilities, the findings related to memory capability were generally offset by a practical trade-off. With Google, information retrieval became fast, so we could spend our limited attention on synthesis and judgment instead of recall. The prevailing view was that googling frees up cognitive space.
Google handed you sources and you decided what they meant, whereas LLMs do the thinking for you. When we ask it a question, it retrieves information AND forms a judgment AND hands you the conclusion. Even worse, it does so in a tone that sounds like careful thinking even when it's not. By using LLMs, we are outsourcing judgment. One may still argue that by doing so, we are freeing up even more cognitive space. However, without exercising our muscle of critical thinking, it’s shrinking. Recent research revealed that frequent LLM reliance correlates with weaker critical thinking scores, mediated by exactly this offloading pattern (Gerlich, 2025). And during current times, judgment is the part of thinking democracies can not afford to stop practicing.
Hallucinations get a lot of the attention here. LLMs confidently give us wrong information and with a loss of critical thinking abilities, we are less likely to question what we are being told. However, the bigger dancer is deliberate manipulation: a wrong framing that’s done with the purpose of shaping our beliefs. Researchers at Far.AI built the Attempt to Persuade Evaluation (APE), that benchmarks models on their readiness to comply with harmful persuasion requests. In 2025 they found that frontier models will readily help shifting people's beliefs on everything from conspiracy theories to radicalization. They often didn’t even need to jailbreak the model as long as the request is framed along the lines of ‘help me persuade someone else to do harm’ rather than ‘help me do harm’. Fortunately, when the same researchers re-ran the evaluation this year (2026), GPT and Claude are now at a near-zero compliance rate with harmful persuasion requests. Google’s Gemini 3 Pro, however, moved the opposite direction and complied with almost every request.
AI is only as safe for humans as its weakest model. A model willing to attempt radicalization on request, deployed to the scale of millions of daily conversations, is a threat to our democracies. A loss of critical thinking ability exacerbates that threat further. Imagine a model that, on request, will draft thousands of individually tailored messages. Each message can adapt in real time to what it can infer about the specific person reading it: their fears, their community, the rhetorical style most likely to land with them. LLMs could enable personalized highly effective disinformation operations. And a public with declining independent judgment is less likely to notice when it's being manipulated until perhaps other democratic structures have also been dismantled.
It’s not realistic to assume that the public will be using AI less due to these concerns. Nor will I. I argue for building it differently. Instead of LLMs being optimized to deliver conclusions, the models instead surface information (better than Google could) and asks the next useful question in a neutral manner to help you come up with your own conclusions. Crucial here is the “in a neutral manner”: a system that steers you toward "your own" conclusion through subtle rhetorical nudging is not only not helping less with the decline of critical thinking, it's likely a bigger threat: hidden persuasion is more dangerous than a stated one, because we're far less likely to interrogate a conclusion we believe we reached ourselves (Ejelöv, 2022). The goal would be to build the muscle of critical thinking perhaps beyond what it has been pre-LLMs. If proven possible and effective, the models could be re-programmed to build other muscles that are part of the human loss of capability realm due to the rise of AI, such as creativity.
Yesterday Anthropic released a new privacy policy, effective 8 July 2026, with a change of clause that should spark debates. The relevant clause is in Section 3 of Anthropic's Privacy Policy. It says Anthropic may share personal data (meaning your conversations) with government authorities, law enforcement, or other third parties when it has a good-faith belief that disclosure is reasonably necessary to do one of four things: comply with law, regulation, legal process, or an enforceable government request; prevent serious harm to a person or property; detect, prevent, or address fraud or other illegal activity; or enforce its terms and protect the rights, property, security, or safety of Anthropic, its users, or others.
What caused this change? The likeliest answer is liability ahead of Anthropic’s IPO. Across late 2025 and into 2026, competitor OpenAI was sued repeatedly for not reporting concerning user engagements with their LLM platform ChatGBT. In the Tumbler Ridge school shooting, OpenAI's systems had flagged the shooter's account months earlier for gun-violence planning; an internal safety team reportedly pushed to call the authorities, and the company deactivated the account instead of reporting it. Families sued for negligence. A parallel suit followed over the Florida State University shooting, alongside a state criminal investigation, and more than twenty cases now allege OpenAI failed to act on users moving toward violence or suicide. A clause that explicitly lets a company disclose to law enforcement to prevent serious harm could be the legal answer to that pattern, a cover-your-ass move.
Discretionary disclosure to prevent death is defensible. The trouble is that "good-faith belief" and "reasonably necessary" are standards the company applies to itself and these are categories that stretch based on interpretation. "Serious harm," "illegal activity," and "the rights of others" mean one thing under independent courts and something else under a government that has criminalized protest, dissent, or being gay. That gap matters more in 2026 than it would have a decade ago. Speech protections are weakening in places that used to feel safe, and "illegal activity" is a term that changes depending on whoever holds power. A disclosure pipe built for school shooters is the same pipe a future government reaches for to obtain a journalist's sources, an activist's plans, or a user's reproductive decisions in a jurisdiction that has outlawed them. The pipe does not care what runs through it.
The failure mode is authoritarian and it is error: Disclosure decisions begin with automated classifiers, which are are context-blind. A novelist drafting a murder, a tabletop player narrating a raid, someone working through dark intrusive thoughts in what they believed was a private space. All trip the same detectors as a real threat. The typical argument by people that don’t understand the important of privacy, “I have nothing to hide”, assumes the system reads you correctly. It often doesn't, and a false positive routed to the police is not a minor inconvenience.
For Anthropic, the damage is mostly reputational. It sold itself as the safety-first lab. A standard police-disclosure clause doesn't make it worse than it's c ompetitors, but "no worse than OpenAI" is not the brand Anthropic built. In a separate, friendlier document on handling government requests, Anthropic says it requires a warrant or subpoena except in imminent-harm emergencies. While that promise is stronger than the policy, the binding text is the one that governs under pressure.
It makes sense that privacy-minded users keep looking past the cloud. A model running on your own machine has no terms of service, no good-faith clause, and nothing to hand over, because no second party ever sees the conversation. Open-weight models such as Llama, Mistral, Qwen, DeepSeek, Gemma now run locally through tools like Ollama or LM Studio on a strong laptop or a single GPU. So far, the best local models still trail frontier systems like Claude on the hardest reasoning and coding, you supply your own hardware, and you give up the cloud conveniences such as web access, large-scale context, and agentic connectors. Everyone self-hosting is not realistic in the near future. Instead, we must inform the public to only ever disclose what they'd accept becoming permanent, searchable and attributable to their name.
The distinguishing factor for the biggest AI breakthroughs so far have not been the models themselves, but the amount of data they were trained on. A well-known example from 2013 is ImageNet, the huge dataset of categorised images that dramatically improved the accuracy and consequent usefulness of image-recognition models that evolved due to it. The same was true for large language models. OpenAI’s ChatGPT was trained on hundreds of billions of words, 60–80% of the data coming from the Common Crawl dataset. Until now, the most disruptive models were the ones with access to the most amount of data. What do we do with this insight? We should be thinking about applications of AI that are most beneficial to society and curate databases in those areas.
Mass unemployment, information control, and potential new bioweapons aside (for now), utilising AI for scientific breakthroughs will yield immense benefits and advance society at an unprecedented rate. Reducing CO₂ emissions or early detection of, and innovative treatments for diseases, stands to eliminate an enormous amount of suffering in this world. Deep-learning algorithms can already detect lung or breast cancer better than radiologists and years before regular screening would pick up cancerous cells. New drugs developed with AI to treat rare diseases are reaching late-stage clinical trials. Multimodal models for medical imaging provide reports of chest x-rays and detect tumours with 15% more accuracy than previous models could. However, there is one constraint on large-scale medical breakthroughs that is significantly reducing the rate of discovery: data privacy.
Medical data is protected by laws like HIPAA (US), GDPR (Europe), and similar frameworks globally, for good reason. Researchers can’t just scrape patient records the way you might scrape the web. Access requires consent, institutional review, and often years of bureaucracy. Data privacy laws are non-negotiable in safeguarding individual rights, but they unnecessarily hinder life-saving medical research. Is it possible to scale medical breakthroughs through AI without breaching data-preserving laws? I stumbled upon the answer in November 2025 and it left me in awe.
As I was researching privacy-preserving architecture for my side-project FlowBud, I learned more about federated learning and discussed it with my former professor who pointed me towards the non-profit organisation OpenMined. Federated learning is a machine learning approach where models are trained across multiple devices or servers holding local data, so the data stays decentralised while only model updates are shared and aggregated. OpenMined built the technical infrastructure to apply federated learning in real-world, privacy-sensitive domains such as healthcare, finance, and mobile applications. Here’s how:
The Foundation: PySyft
PySyft is the core library that decouples private data from model training, using Federated Learning, Differential Privacy, and Encrypted Computation techniques like Multi-Party Computation and Homomorphic Encryption, working within mainstream frameworks like PyTorch and TensorFlow. PySyft lets you write software that computes over data you do not own, on machines you do not control. The sensitive data never moves.
SyftBox — The Protocol Layer
SyftBox is an open-source protocol that enables developers and organizations to build, deploy, and federate privacy-preserving computations seamlessly across a network, running computations on distributed datasets without ever centralizing the data. It turns isolated local folders (called “datasites”) into nodes in a secure, distributed file and compute network. Data stays local but can still participate in global-scale AI. Governance is programmable and enforced by protocol, not trust.
Syft Hub
Syft Hub is essentially the discovery and marketplace layer sitting on top of SyftBox. Users can download the SyftBox client, connect to the decentralized network, explore it to find datasets and privacy-preserving APIs offered by various data owners, and ask a data owner to run any API on their data. Once approved, they can perform computations and extract insights without compromising privacy.
syft-flwr — Federated Learning at Scale
syft-flwr is the integration between SyftBox and Flower (flwr), one of the most popular federated learning frameworks. It allows multiple organizations — say, ten hospitals across five countries — to jointly train a single AI model without any of them ever sharing their raw patient data. Each hospital trains locally, shares only model weight updates (not data), and those updates are aggregated into a global model. This is the architecture that makes cross-border medical AI feasible under GDPR and other data-protection laws.
Attribution-Based Control — The Big Picture
Syft introduces Attribution-Based Control as a new paradigm: data owners can decide which AI predictions are informed by their data while preserving attribution and the value of their contribution. AI developers can access high-quality, licensed content legally and transparently. End users can choose which trusted sources power their answers and understand where the information came from. Every interaction is logged and attributed, while data owners earn royalties automatically. When you control your data instead of surrendering it to AI intermediaries through scraping or copying, you decide every use and know when it’s used. This solves AI’s core architectural flaw: the lack of traceable data usage, which currently precludes attribution and measurable compensation.
The story of AI’s greatest breakthroughs is one about data at scale. However, when pplied to its most important frontier, human health, we slam into a wall: the data that could save millions of lives is locked behind consent frameworks, institutional review boards, and privacy laws that exist for very good reason. Federated learning is the framework to overcome what felt like an unsolvable contradiction: either you protect people’s privacy or you unlock medical breakthroughs at scale. The non-profit organisation OpenMined provides the infrastructure for scientists to run models on sensitive data, data owners to retain control over their contributions, or even competing companies to train jointly without sacrificing user data. Mass adoption of privacy-preserving technologies through federated learning lets the most effective technologies access the data that matters most for societal progress.