Privacy

An AI assistant gives up as many as 54.6% of secrets after a change of subject


A test with 1,000 dialogues shows that sensitive data mentioned at the start remains extractable long afterward, even if the conversation has drifted.

September 25, 2026 · Translated from the Spanish original

What happened

Why it matters

The number

54.6% is the ceiling of dialogue-level leakage measured across the three models evaluated.

Context

It’s the third piece this month on the same blind spot. The note on the lethal trifecta in ChatGPT for work placed the risk in the combination of private data, external content and the ability to send. PrivDrift shows the first of the three is enough.

What’s next

Bottom line

The public debate in Chile about postponing the data protection law was framed in terms of compliance deadlines. The problem this paper measures doesn’t wait for the deadline: it’s already in the context window of the sessions opened today.

This note describes a technical finding and does not constitute legal advice.

Sources

Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.

Related notes

← All notes