Key Takeaways
- Israeli cyber‑security expert Osher Cohen warns that AI chatbots are cloud services, not private diaries, and that users often overshare sensitive information because they treat the interaction as a confidential conversation.
- The case of Mali and Liel Yahalomi—tracked from Vienna to Buenos Aires through their AI chat history—illustrates how readily personal data can be harvested when users forget that AI conversations are stored and may be accessed for safety, product improvement, or legal compliance.
- Unlike a typical search query, an AI chat retains context, follow‑up questions, and personal reflections, making the conversation log potentially more revealing than a simple search history.
- Protective measures must be behavioural: avoid entering passwords, verification codes, credit‑card details, or sensitive documents into consumer AI tools; regularly delete history; use incognito or temporary modes; and understand each platform’s privacy settings.
- Organizations should institute clear internal AI policies that define what employees may and may not paste into personal or corporate AI accounts, especially regarding customer lists, contracts, medical or financial data, and internal strategy.
The Vienna‑to‑Buenos Aires trail
On Saturday, N12 News reported that Israeli citizens Mali and Liel Yahalomi were located by investigators who followed their chat history with an artificial‑intelligence model, tracing the pair from Vienna, Austria, to Buenos Aires, Argentina. The story highlighted how a seemingly innocuous AI conversation can become a digital breadcrumb trail when users forget that the exchange is stored on remote servers.
Who is Osher Cohen?
Osher Cohen is a cyber‑security specialist and the founder of Yo Secure, an Israeli firm that helps clients recover from digital identity crises, hacked accounts, online impersonation, and security incidents on various platforms. In an interview with The Jerusalem Post, Cohen explained that the Yahalomi case underscores a broader lesson about how people interact with AI chatbots.
The illusion of privacy
Cohen stressed a common misconception: “Users need to gain a new habit: think before you type into an AI chatbot.” He observed that many people treat AI chatbots as if they are speaking privately to themselves, unaware that the service is hosted in the cloud. “An AI chatbot is a cloud service. It may be connected to an account, a device, an email address, a browser, an IP address, privacy settings, and data retention policies,” he said.
How AI chat differs from a regular search
According to Cohen, the main difference lies in the way users engage a chatbot. “They give context, explain a situation, ask follow‑up questions, test ideas, ask for wording, and sometimes describe things they would not say out loud to another person.” In contrast, a regular search is usually brief: “You type a few words, get links, and decide what to read.” This richer interaction means that AI conversations can reveal far more about a user’s thoughts, worries, and intentions than a simple query string.
Why oversharing is risky
Because users perceive the chat as a private adviser, they often divulge sensitive data they would never enter into a search bar. Cohen warned, “A search can show what you wanted to know. A conversation with AI can show what you were thinking, what you were worried about, what you were considering, and what you were trying to achieve.” From a privacy standpoint, AI logs can be more revealing than search histories, yet they reside on the same cloud infrastructure that powers search engines.
Embedded AI and the psychological trap
Many browsers now embed AI assistants directly into the search bar, blurring the line between a traditional search and a conversational model. Cohen cautioned that this does not erase the underlying risks: “The fact that an AI tool appears inside a search bar does not mean the conversation disappears. It still depends on the company operating the service, whether the user is signed in, the privacy settings, the data retention policy, whether history is enabled, and whether the information may be used for safety, product improvement, or legal compliance.” He added that the biggest issue is psychological: “When AI is built into search, people feel like they are ‘just searching’. In practice, they may be creating a richer record than a regular search query.”
Where the data lives
Cohen noted that, regardless of geography, the day‑to‑day activity of an AI chat ends up on cloud servers managed by the service provider. “In most cases, a regular user does not know exactly where the data is stored. Large technology companies use global cloud infrastructure, and information may be processed or stored in different regions, depending on the provider, the product, the type of account, organizational settings, legal requirements, and the company’s internal architecture.” Even tools like VPNs cannot guarantee protection because numerous third‑party networks, apps, and services may still access the shared data.
Behavioural safeguards over technical fixes
Given the limitations of purely technical solutions, Cohen advocated a behavioural approach: “With AI tools, the safest approach is behavioural, not only technical. Do not enter passwords, do not enter verification codes, do not enter credit card details, do not upload sensitive legal, medical, or business documents unless you understand the risk, and do not paste customer data into a personal AI account.” He reiterated this point twice for emphasis, underscoring that user habits are the first line of defence.
Practical steps for individuals
Cohen recommended a handful of concrete actions: check the privacy settings of the chatbot app, delete history when it is no longer needed, use temporary or incognito modes when appropriate, and refrain from uploading sensitive documents into consumer AI tools. He also urged users to adopt the mental habit of asking themselves whether they would say the same thing aloud to another person before typing it into the bot.
Guidance for businesses
For organizations, Cohen advised establishing an internal AI policy that clearly defines what employees may and may not paste into AI tools. “Customer lists, contracts, legal documents, medical information, financial data, and internal strategy should not be casually uploaded into a personal chatbot account,” he said. Training staff on these boundaries and monitoring compliance can help prevent inadvertent data leaks that could lead to reputational harm, regulatory penalties, or competitive disadvantage.
A final warning
Cohen concluded with a memorable metaphor: “He described the AI tools as ‘an amazing tool, but it is not a safe deposit box,’ and concluded: ‘The danger is not only what AI knows how to answer. The danger is what we choose to tell it.’” This reminder captures the core message: while AI can augment productivity and creativity, the responsibility for what we share rests squarely on the user.
By following the behavioural habits outlined above—thinking before typing, regularly pruning chat histories, and respecting organisational AI policies—individuals and companies can enjoy the benefits of conversational AI without unintentionally exposing their most sensitive information.
https://www.jpost.com/business-and-innovation/tech-and-start-ups/article-906147

