Skip to main content
Live
Main content

Signal's Whittaker: AI chatbots are not your friends, and Copilot shopping is a backdoor

The Signal president pushes back on the agentic-AI pitch from Microsoft's Mustafa Suleyman, calling pervasive app access a privacy backdoor.

Jaeden Schafer
Editor in Chief · · 4 min read
Signal's Whittaker: AI chatbots are not your friends, and Copilot shopping is a backdoor

Signal President Meredith Whittaker used a Bloomberg interview published June 20, 2026 to draw a hard line under the consumer AI assistant pitch, telling readers that ChatGPT, Claude, and their peers are not companions and should not be treated as such. Her sharper claim landed on agentic AI: Microsoft AI CEO Mustafa Suleyman's vision of Copilot handling a user's Christmas shopping, she argued, would amount to a backdoor into Signal itself. The framing matters because Signal's product promise rests on the idea that no third party — including the operating system or an assistant layered on top of it — can read a user's messages.

Whittaker's objection is structural, not aesthetic. To deliver on Suleyman's holiday-shopping demo, Copilot would need to listen to the family group chat to figure out what each relative wants, then act on the user's behalf. That requires standing access to the messaging app, the browser, the calendar, the address book, and a payment method.

These are not your friends. These are not conscious beings. These are not sentient interlocutors.
Meredith Whittaker, Signal President

On her own use of the tools, Whittaker said she runs AI through narrow, formatting-style tasks rather than as a thinking partner. She framed the distinction in epistemic terms: a chatbot that averages the public internet is, by design, a regression toward the existing consensus on any question.

Key facts

  • 01Signal President Meredith Whittaker told Bloomberg that AI chatbots like ChatGPT and Claude are not friends, conscious, or sentient.
  • 02Whittaker said she uses AI tools to format documents but does not ask them questions, to avoid having her thinking shaped by averaged outputs.
  • 03She framed Microsoft AI CEO Mustafa Suleyman's pitch — Copilot handling Christmas shopping by reading the family group chat — as a backdoor into Signal.
  • 04An agentic shopping assistant would need access to a user's credit card, browser, Signal, messaging, home address, and calendar, Whittaker said.
  • 05The interview ran June 20, 2026, days after Suleyman pitched Copilot's holiday shopping use case.

That is a different critique than the safety-and-bias arguments that have dominated AI policy discussions. Whittaker is making a writer's case — that delegating the act of working through an idea to a statistical summarizer is a quiet way of giving up the work that produces the idea.

The Suleyman scenario she pushed back on is the current frontier pitch from Microsoft's consumer AI group: Copilot as a persistent agent that observes signals across a user's accounts and acts without prompting for each step. Microsoft has been steering Copilot toward this agentic posture for the past year, with shopping, scheduling, and travel as the wedge use cases.

Whittaker's enumeration of what Copilot would need to touch — credit card, browser, Signal, the ability to message siblings on the user's behalf, home address, calendar — is a useful inventory of the actual surface area an agent requires. None of those permissions are exotic; each one already exists somewhere in the consumer stack. The novelty is the assistant holding all of them at once and acting across them autonomously.

From Signal's vantage point, the question is whether an agent reading messages on a user's device, even with that user's consent, breaks the confidentiality model the app sells. Signal's encryption protects messages in transit and at rest; it does not protect against software running on the endpoint that the user has authorized to read the screen.

Whittaker's choice of the word backdoor is deliberate. In cryptography policy, a backdoor traditionally refers to a mandated capability for a third party — usually a government — to access plaintext. Extending the term to a consumer AI assistant that the user opted into is a stretch in the strict technical sense, and Whittaker is doing it on purpose to highlight that the practical effect is similar: a second reader of every message.

Related · from this week
Momfluencers pitch ChatGPT as a 'coparent' as AI gender gap widens
Jaeden Schafer · 5 min read →

The countervailing argument, which Microsoft and other agent-builders will make, is that users want this. The holiday-shopping demo polls well because the work it replaces is genuinely tedious, and the data access it requires is data the user already shares with multiple apps individually. Whether that aggregation crosses a privacy line is a product-design question, and reasonable users will answer it differently.

Whittaker's intervention is also notable for who isn't making it. Most of the named critics of agentic AI in 2026 have come from outside the messaging-app world; Signal, with roughly the highest privacy-credibility ceiling in consumer software, is a different kind of voice to have on the record. Her comments arrived the same week Nobel laureate John Jumper announced his move from Google DeepMind to Anthropic, a reminder that the talent and the critique are now flowing through the same small set of names.

The practical stake for the AI industry is whether the agent pitch survives contact with the messaging-app threat model. Microsoft, OpenAI, Anthropic, and Google are all pushing agent products that need broad device access to be useful, and they are all going to bump into the same permission surface Whittaker described. Signal cannot block an agent that the user has authorized at the OS level, but it can make the cost of that authorization legible — and a public framing of agent permissions as a backdoor is a cheap, durable way to do exactly that. Expect Microsoft and its peers to respond not by narrowing the agent's reach, but by working harder on the consent UX that makes the reach feel voluntary.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

OpenAI logo
Analysis

Momfluencers pitch ChatGPT as a 'coparent' as AI gender gap widens

A new wave of creators is selling $37 custom GPTs to overwhelmed mothers, framing AI as the household partner husbands aren't.

Jaeden Schafer5 min read
Microsoft logo
Security

Mustafa Suleyman says AI threats are real and Anthropic is making them worse

Microsoft's AI chief published a 37-page Humanist AI Code of Conduct and a companion essay attacking Anthropic's model-welfare stance.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI faces sanctions bid after allegedly hiding 78M ChatGPT logs from NYT

News plaintiffs say OpenAI concealed pre-searched log samples for two years while claiming the searches were technically infeasible.

Jaeden Schafer5 min read