Protecting Your Data in The Age of Artificial Intelligence

Best Practices (So Far)

While many of the cyber security threats we’ve covered so far in this series are, what we would describe at this point as, old games played with new and more sophisticated technology, the emerging, rapidly changing landscape that merits a closer look is Artificial Intelligence (AI).

In some ways, it is in the “old games played with new and more sophisticated technology” category. It is allowing fraudsters to become more efficient and more sophisticated in the same thing they’ve been trying to do for a long time. And in other ways, it’s different, because the use of AI, in and of itself, poses some additional risks that its worth paying attention to.

And we write this post with a caveat. AI is such a rapidly evolving landscape that best practices today will need to be updated regularly to make sure consumers stay on top of potential threats that are unique to AI.

But there are some guidelines that can start us all out on the right foot, as we continue to interact more with artificial intelligence.

Before you dismiss this article thinking it may not apply due to your age or limited computer and internet use, it’s our opinion that it’s a mistake to assume you’re not engaging with AI. I know a lot of folks who are in opposition to AI, in principle, but also don’t really understand it and just how pervasive it’s recently become. While not all that long ago, you had to seek out specific tools to use AI (like ChatGPT), at this point, both Google’s search engine (that provides that convenient little AI summary at the top of your Google Search) and Google based platforms like Gmail are putting AI tools (like “Help me write”) to work for users almost automatically.

In the short span of a year or two, AI has gone from something you had to seek out to use, to something that is somewhat pervasively in the background of many things you are already using – like Google, Facebook, and Instagram. So, it’s likely that unless you’ve made a concerted effort to disable these things or disengage from the ones you can’t completely disable, you may be interacting with AI in ways that you don’t even realize. And because of that, it’s a good idea for EVERYONE to have at least a basic understanding of how it works, and of some overarching best practices when using AI.

Be Thoughtful About What You’re Sharing with AI

The most important piece of information to understand is that AI works on data. Loads and loads and loads of data are needed for it to do what it does. The more data it has, the better it essentially performs.  A simple to understand example of this is Google’s “help me write” tool in Gmail. How does it help you write an email to a friend that sounds like you – it goes through all your old emails to learn your voice and about your previous interactions with the email recipient you’re writing an email to. Where does this data go? Who has access to it? As of this writing in May 2026, the “help me write” tool does not use your data to do anything but help you write an email. It’s not considered a public AI tool, so it’s not using your data to train its model (beyond training the specific tool that is working for you, to write your email). But the feature that helps summarize your Google search results is a different story.

So, when it comes to data and AI, the first main piece of advice we can give when interacting with any AI model is this: You need to do the research to understand who your data is being shared with and how it can be used, and whether you have any control over that. And it’s not quite as simple as “does Google use my data to train public AI models and can I opt out?” because the answer to that question is it depends on what specific Google AI tool you’re using, whether you’re using a paid workplace subscription or a free retail subscription, and on a whole host of other things.

When in doubt though, it’s best to assume that unless you’ve done the research to prove otherwise, any information and data you’re entering into any social media, email, search engine, or other online platform could be used to train a public AI model and could be used to harvest your data. That should be the default assumption unless you’ve researched and found otherwise. And if that’s the default assumption, it’s in your best interest to not feed it any data that is too specific about you, or that could compromise your identity. When it comes to how you engage with AI, one of the most critical places to be cautious is on social media platforms, where often things that seem harmless or fun, like AI driven quizzes, filters, or games that ask for access to your profile, credentials, or a lot of personal data.  Similarly, be cautious of apps asking for access to more data than it seems like they should need to do their job (like location tracking or access to your contacts or photos).

Stay Up to Date on What AI Can Do

Even if you do everything you can to actively avoid using AI, you still need to understand exactly what it is capable of doing (and keep this information up to date). AI tools are getting better and savvier at rates that are hard for our human brains to imagine.  They are getting faster at data scanning and collection. They are rapidly increasing the extent to which fraudulent credentials can be used and fraudulent identifies can be created (so it’s even more important that we pay attention to the basics we’ve shared in all our previous posts about keeping your credentials unique and well-safeguarded).  

But perhaps even more worth watching is that they are getting far better at impersonating real people, in both online chat type scenarios, and in fraudulent voice and for some, even video deep-fake impersonations. And this is likely to only get more advanced as time goes on. It’s important that you understand what AI is capable of, so that if you get an urgent phone call asking for something from a person you know and are close to (like a family member) you understand that it could be AI.

Even if YOU stay off the internet. Even if YOU avoid AI at all costs, that isn’t enough to isolate you from AI. And because what AI can do is rapidly becoming more sophisticated, we cannot stress enough, rather than just spending all of your time avoiding or railing against AI, please spend some of it trying to learn what AI is capable of doing, right now, and understand that this type of research needs to be continual. Tomorrow’s AI will be more capable than today’s, so the work to understand what it can do so that you can protect yourself from being vulnerable to it also needs to be continual.

Keep a Healthy Level of Skepticism About Your AI Interactions

Abstract green, blue and gold art depicting a magnifying glass to represent healthy skepticism

On the other side of the coin, for those who have embraced AI, who may enjoy engaging with their ChatGPT or appreciate those handy Google summaries that make an internet search feel far more efficient. We encourage you to not get complacent in trusting what AI tells you.

We know that AI is prone to mistakes. The more the models evolve, in theory, the less prone to factual mistakes it will become. But it’s extremely important to continue to verify AI generated answers and content. One should not simply trust that the Google summary at the top of their search has, in fact, given them all relevant information about a topic they are trying to learn about. It’s not hard to still find factual errors or omissions, or to see the same question, asked differently, give a largely different result.

And because large language AI models operate in a voice that for many sound authoritative or trustworthy, it’s important to remember that AI is a good place to start, but there remains no question about the need to verify the accuracy of its findings and recommendations.