<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0" -->

---
title: Signal’s Meredith Whittaker says AI chatbots ‘are not...
description: Signal president Meredith Whittaker warns that AI chatbots are not sentient companions and that agentic AI systems like Microsoft Copilot represent a...
canonical: https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor | daily.dev
og:description: Signal president Meredith Whittaker warns that AI chatbots are not sentient companions and that agentic AI systems like Microsoft Copilot represent a...
og:url: https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0
og:image: https://api.daily.dev/og/posts/kS1M56Qu0.png
og:image:alt: Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor

**[The Next Web](https://daily.dev/sources/tnw)** · 4 min read · 2 upvotes · 0 comments

## Summary

Signal president Meredith Whittaker warns that AI chatbots are not sentient companions and that agentic AI systems like Microsoft Copilot represent a structural backdoor to private data. She argues that AI agents requiring access to messages, calendars, credit cards, and browsers are fundamentally incompatible with end-to-end encryption — because an agent reading plaintext on-device renders encryption irrelevant. Whittaker criticizes the Silicon Valley narrative that agentic AI is an inevitable productivity win, framing it instead as users trading privacy for convenience without understanding the terms. She also highlights prompt injection as a likely first exploit path against encrypted messaging platforms.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/signal-whittaker-ai-chatbots-not-friends-copilot-backdoor-privacy>

## Questions this post answers

### Why does Signal's Meredith Whittaker call agentic AI systems like Copilot a backdoor to encrypted messaging?

She argues that agentic AI needs near-total access to a user's digital life to function, including messages, credit cards, browser, calendar, and contacts, and that an agent reading messages before encryption or after decryption renders end-to-end encryption meaningless from a privacy standpoint since a system with root-level access processes the plaintext directly on the device.

_Developers weighing agentic AI integration against encryption guarantees can follow this debate on daily.dev._

### What does Meredith Whittaker say is the most likely first exploit path against encrypted messaging platforms with AI agents?

She identifies prompt injection, where an attacker manipulates an AI agent into executing unintended commands, as the likeliest first exploit path against encrypted messaging platforms once agents are embedded with pervasive access to user data and communications.

_Engineers building agent-based systems can track emerging prompt injection risks and mitigations on daily.dev._

### What is Microsoft's Project Solara and how does it relate to agent-first computing?

Project Solara is an operating system Microsoft unveiled at Build 2026 that replaces traditional apps with AI agents as the primary interface, part of a broader industry shift toward agent-mediated computing also being pursued by Google, Apple, and OpenAI, which critics say creates centralized databases of users' digital lives.

_Anyone tracking the shift toward agent-first operating systems can follow related coverage on daily.dev._

## Similar posts on daily.dev

- [‘Signal’ President and VP warn agentic AI is insecure, unreliable, and a surveillance nightmare](https://daily.dev/posts/signal-president-and-vp-warn-agentic-ai-is-insecure-unreliable-and-a-surveillance-nightmare-xnmelgefe) · Hacker News · 0 upvotes · 0 comments
- [Signal creator Moxie Marlinspike wants to do for AI what he did for messaging](https://daily.dev/posts/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what-he-did-for-messaging-y1lywwned) · Lobsters · 4 upvotes · 0 comments
- [Microsoft research shows chatbots seeping into everyday life](https://daily.dev/posts/microsoft-research-shows-chatbots-seeping-into-everyday-life-qaclzlzdk) · The Register · 0 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#privacy](https://daily.dev/tags/privacy), [#encryption](https://daily.dev/tags/encryption), [#microsoft-copilot](https://daily.dev/tags/microsoft-copilot)

[View this post on daily.dev](https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor","url":"https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0"},"datePublished":"2026-06-21T10:00:51.417Z","dateModified":"2026-09-14T06:21:59.771Z","description":"Signal president Meredith Whittaker warns that AI chatbots are not sentient companions and that agentic AI systems like Microsoft Copilot represent a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d12485df547ce5439e50dce3dd4d647?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d12485df547ce5439e50dce3dd4d647?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,privacy,encryption,microsoft-copilot","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"Signal’s Meredith Whittaker says AI chatbots ‘are not your friends’ and calls Copilot agents a backdoor"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/signal-s-meredith-whittaker-says-ai-chatbots-are-not-your-friends-and-calls-copilot-agents-a-backd-ks1m56qu0#faq","mainEntity":[{"@type":"Question","name":"Why does Signal's Meredith Whittaker call agentic AI systems like Copilot a backdoor to encrypted messaging?","acceptedAnswer":{"@type":"Answer","text":"She argues that agentic AI needs near-total access to a user's digital life to function, including messages, credit cards, browser, calendar, and contacts, and that an agent reading messages before encryption or after decryption renders end-to-end encryption meaningless from a privacy standpoint since a system with root-level access processes the plaintext directly on the device. Developers weighing agentic AI integration against encryption guarantees can follow this debate on daily.dev."}},{"@type":"Question","name":"What does Meredith Whittaker say is the most likely first exploit path against encrypted messaging platforms with AI agents?","acceptedAnswer":{"@type":"Answer","text":"She identifies prompt injection, where an attacker manipulates an AI agent into executing unintended commands, as the likeliest first exploit path against encrypted messaging platforms once agents are embedded with pervasive access to user data and communications. Engineers building agent-based systems can track emerging prompt injection risks and mitigations on daily.dev."}},{"@type":"Question","name":"What is Microsoft's Project Solara and how does it relate to agent-first computing?","acceptedAnswer":{"@type":"Answer","text":"Project Solara is an operating system Microsoft unveiled at Build 2026 that replaces traditional apps with AI agents as the primary interface, part of a broader industry shift toward agent-mediated computing also being pursued by Google, Apple, and OpenAI, which critics say creates centralized databases of users' digital lives. Anyone tracking the shift toward agent-first operating systems can follow related coverage on daily.dev."}}]}
```

