Signal's Meredith Whittaker says AI agents doing tasks on users' behalf pose security and privacy risks and refers to their use as “putting your brain in a jar”
techcrunch.com/2025/03/07/s... … Paul Rietschka / @prietschka : Agents agents agents! — Yes, Whittaker is right! — Also: agents agents agents! If you say it enough — I've been told — it becomes true! — So, everyone now: agents agents agents! — We can keep this bubble inflating forever if we just hype brittle garbage technology and never expect it to come to market! [embedded post] X: Meredith Whittaker / @mer__edith : I did. Because it does. LinkedIn: Ron F. Del Rosario : 🔥 What an amazing talk with Meredith Whittaker at SXSW talking about the state of personal online security and confidentiality! — 📺 A must watch! … Forums: r/technology : Signal President Meredith Whittaker calls out agentic AI as having ‘profound’ security and privacy issues r/artificial : Signal President Meredith Whittaker calls out agentic AI as having ‘profound’ security and privacy issues BeauHD / Slashdot : Signal President Calls Out Agentic AI As Having ‘Profound’ Security and Privacy Issues
Context & Ripple Effects
Signal president Meredith Whittaker has consistently framed AI debates around concentration of power and the preservation of private communications, including concerns that AI alarmism can entrench large technology platforms. Her SXSW intervention extends that lens from models themselves to the access and authority an agent needs to act for a person.
The warning also anticipates her later argument that deeper agent integration into devices threatens encryption, making this less a generic objection to automation than a challenge to architectures that centralize cross-app personal data and credentials.
First-order effects
- Agent builders and device/platform integrators face sharper scrutiny over what data, account permissions, and encrypted communications an agent can access while acting for a user.
- Signal gains a clear public-positioning distinction: privacy-preserving messaging is cast as potentially incompatible with agents that require broad visibility into a user's digital activity.
Second-order effects
- Pressure shifts toward narrower, revocable permissions and clearer authorization boundaries, because an agent with standing access creates a larger privacy and security exposure than a single-purpose tool.
- Encryption debates become more tightly coupled to agent deployment: providers seeking cross-service functionality may face conflict between convenience features and limits on data access.
Third-order effects
- If agents become a common interface for digital tasks, control over delegated identity, credentials, and context may become a core competitive and governance layer—not merely a product feature.
- The durable fault line is likely to be whether agent ecosystems can provide useful delegation without creating centralized intermediaries able to inspect or act across a person's private digital life.
The trend: Agentic AI is shifting the privacy debate from what models generate to the permissions, data access, and delegated authority required for models to act.