Signal's Meredith Whittaker says deeper integration of AI agents into devices is “perilous” for encryption, since agents need access to lots of data across apps
Artificial intelligence agents that autonomously carry out tasks pose a threat to secure apps such as Signal …Forums:SlashdotForums:Msmash /Slashdot:AI Agents ‘Perilous’ for Secure Apps Such as Signal, Whittaker Says
Context & Ripple Effects
Whittaker has consistently cast agentic systems as a privacy problem rather than merely an AI feature: Signal previously warned that agents acting on users’ behalf create security and privacy risks. This report sharpens that argument around the access an agent needs to work across apps.
It also fits Signal’s broader opposition to mechanisms that erode private communications, including its warning that upload moderation could undermine encrypted messaging. The key issue is whether device-level AI can perform broad tasks without creating a privileged path to sensitive user data.
First-order effects
- The warning raises the design stakes for AI-agent and device platforms: cross-app task execution may require data access that conflicts with the isolation secure apps rely on.
- For Signal and similar services, agent integrations become a trust and product-boundary question, not simply a convenience feature.
Second-order effects
- Device makers and AI developers face pressure to show that agents can limit permissions and data exposure while still completing multi-app tasks; otherwise secure-app providers may resist or constrain integrations.
- The debate widens the competitive value of agent architectures that can operate with narrower access, rather than treating broad device context as a default requirement.
Third-order effects
- If embedded agents become a standard device interface, encryption may increasingly depend on operating-system and agent permission models as well as messaging protocols.
- The longer-running conflict between functionality demands and private communications could shift from explicit scanning proposals to the privileged access required for automated assistance.
The trend: This is one data point in the expansion of the agentic attack surface, as ambient AI capabilities make access control a central test of encrypted-service integrity.