Fazal Ali
All entries

Critical Theory in AI

Selecting agents and shielding your AI chats

No one can shield their AI chats from prosecutors pursuing charges. Conversations with AI assemblages could be demanded by adversaries with the patience of a state.

3 min readFazal Ali
Selecting agents and shielding your AI chats

The intimacy of the AI chat misleads. The interface feels private — a single column of text, a cursor that waits, a voice that responds in the second person. The substrate is anything but. Every keystroke is logged. Every inference is cached. Every conversation is a potential exhibit in a proceeding you cannot yet imagine.

Selecting an agent is now an act of forensic foresight. The model you choose for a sensitive conversation is also the model whose logs may be subpoenaed five years from now in a jurisdiction you did not anticipate. The terms of service you scrolled past today are the terms under which a future prosecutor will be granted access. The question is not whether you trust the agent. The question is whether you trust the legal architecture surrounding it.

There are three layers to think about. The first is the prompt — what you said. The second is the inference — what the model concluded from what you said. The third is the action — what the model did, or refused to do, in response. Each of these is logged differently. Each is discoverable under a different theory. A defensible posture has to account for all three.

No one can fully shield their AI chats from prosecutors pursuing charges. End-to-end encryption is a partial defence against eavesdropping, not against subpoena. Local inference — running the model on your own device — is a partial defence against centralised logging, not against forensic recovery of the device itself. Conversations with AI assemblages could be demanded by adversaries with the patience of a state, and states have, historically, very long patience.

Shielding is therefore not the same as hiding. It is the design of an interaction whose disclosure would not embarrass its author. This is a discipline closer to journalism than to cryptography. You write as if the conversation will eventually be read by a stranger, because it might be. You ask the model the question you would ask in open court. You decline to ask the questions you would not.

There are practical tactics. Use models whose retention policies you have read. Prefer providers headquartered in jurisdictions whose courts you would be willing to appear in. Keep sensitive reasoning in your own head and use the model for the parts that are merely tedious. Separate identities across providers so no single log contains the whole picture. None of these are a guarantee. All of them shift the probabilities.

The deeper change is cultural. We are about to live inside a generation of professionals who have outsourced a meaningful share of their thinking to systems whose logs will outlive their careers. The doctor who asked the model about a patient, the lawyer who asked it about a client, the journalist who asked it about a source — each of those conversations is now part of a permanent record. The norms that govern those records have not been written yet. We are the ones writing them, whether we mean to or not.


— Fazal Ali · 09 May 2026

Next entry · Critical Theory in AI

AI gravity and socio-economic operating systems

The future is still about figuring out what questions to ask. This is more important than finding the correct answer to the wrong one.

Read next