Monday, September 28, 2026

AI Already Knows More Than We Realise

Must read

Deleting a post is easy. Removing every copy, inference and trace it has left behind may be far harder. Artificial intelligence is changing not only what can be discovered about us, but what it means to delete information at all.

For two decades, the internet taught users a relatively simple rule: be careful what you publish because information online can be difficult to remove.

Artificial intelligence is making that warning considerably more complicated.

People, companies and governments have spent years placing fragments of themselves online — photographs, biographies, tenders, research papers, company announcements, planning applications, conference presentations, recruitment advertisements and social-media posts.

Now AI systems can search, compare and connect those fragments at a scale no human researcher realistically could.

The result is a new question for the digital age:

If AI can reconstruct information from what remains online, can anything ever truly be deleted?

Investigative journalist Annie Jacobsen offered a striking illustration while researching the U.S. Strategic National Stockpile.

Jacobsen says she asked ChatGPT to identify the stockpile facility nearest her Los Angeles home. The locations of the programme’s operational facilities are not publicly disclosed by the U.S. government for security reasons.

According to her account, the chatbot initially refused. She continued questioning it using specialist terminology and additional context until, she says, it produced a location.

Jacobsen later described finding a heavily secured site whose physical characteristics reinforced her belief that the answer was credible.

The location has not been independently confirmed as a Strategic National Stockpile facility.

But the more important part of the episode is how Jacobsen says the information was found.

According to her account, ChatGPT traced the clue to an old earthquake-emergency document in which information about the location had apparently been included years earlier.

No protected government database needed to be penetrated.

If her account is accurate, the clue was already public.

AI merely connected it to everything else.

Delete Does Not Mean Disappear

That distinction goes to the heart of the emerging problem.

A person can delete a webpage, social-media post or AI conversation.

But deletion from one location does not necessarily remove every copy elsewhere.

A photograph may already have been reposted. An old executive biography may survive in a conference programme. A corporate presentation may have been quoted in another report. Search engines may remove a link while the underlying page remains online.

The original can disappear while the information survives.

For AI systems capable of searching and correlating material across thousands of sources, that matters.

An organisation might remove a sensitive document while leaving behind enough fragments in recruitment advertisements, supplier announcements, employee profiles, procurement notices and archived web pages for much of the same information to be reconstructed.

The document was deleted.

The clues were not.

Then There Is What We Give AI Directly

The problem is no longer confined to information published on the open internet.

Millions of people are now giving AI systems information directly.

Contracts are uploaded for review.

Spreadsheets are submitted for analysis.

Internal reports are summarised.

Emails are rewritten.

Photographs are examined.

Meeting notes, CVs, research papers and financial information are routinely placed into conversational AI systems.

Most major AI services now provide mechanisms for deleting conversations or controlling whether certain data is used for model improvement. OpenAI, for example, says deleted ChatGPT conversations are generally scheduled for permanent deletion from its systems within 30 days, subject to stated legal, security and de-identification exceptions.

But the broader principle is more important than any single company’s policy.

Information can exist simultaneously in several places: the original file, a conversation, a separately stored upload, another user’s copy, an external website or a dataset.

Deleting one instance does not necessarily erase the others.

The Harder Problem Is What Machines Learned

Traditional databases make deletion relatively intuitive.

There is a record.

Find it.

Remove it.

Machine learning is different.

AI models learn statistical relationships by adjusting enormous numbers of numerical parameters during training. They are not simply filing cabinets containing a neat copy of every document they have encountered.

That is why researchers are working on what is known as machine unlearning — techniques designed to remove the influence of particular training data from a model without necessarily rebuilding it completely.

The distinction is important.

Deleting the original training record and eliminating what was derived from it can be two different operations.

Regulators are already confronting that problem.

European data-protection authorities have said that determining whether an AI model is effectively anonymous can depend partly on whether personal information used in its development can later be extracted or inferred.

U.S. regulators have also required companies in some cases to delete not only improperly obtained data, but algorithms or models developed from it.

The emerging principle is straightforward even if the technology is not:

deleting the source does not automatically erase everything produced from the source.

You Cannot Delete an Inference

The problem becomes harder still when the information was never stored anywhere in the first place.

Suppose a company removes the address of a sensitive facility from its website.

That may achieve little if planning documents identify the building, recruitment advertisements reveal the specialists working there, procurement notices show unusual equipment purchases and supplier announcements describe deliveries to the same location.

No surviving document contains the secret.

Together, they may reveal it.

An AI system may therefore not need to retrieve a sensitive fact.

It can infer it.

And an inference creates a different privacy problem.

There may be no original record to delete.

The same principle can apply to people.

Employment histories, conference appearances, photographs, property information, travel references, professional profiles and old interviews can collectively reveal relationships or patterns that the person concerned never explicitly published.

What should be deleted then?

The answer?

Or every clue from which the answer can be reconstructed?

Companies Face a New Kind of Exposure

For businesses, this extends well beyond traditional cybersecurity.

Companies routinely publish annual reports, regulatory filings, vacancies, patents, tender documents, investor presentations, supplier announcements and technical papers.

Employees add another layer through LinkedIn profiles, interviews, conference appearances and academic collaborations.

Historically, much of this material remained effectively obscure.

Finding it required time, expertise and persistence.

AI dramatically reduces that cost.

A competitor, researcher or analyst may increasingly be able to reconstruct parts of a company’s strategy from information that no individual employee ever regarded as confidential.

An AI system could, for example, connect hiring patterns with procurement records and supplier announcements to identify where a company may be expanding, which technologies it is adopting or which market it may be preparing to enter.

The corporate-security question therefore changes.

It is no longer only:

What confidential information have we disclosed?

It becomes:

What confidential information can be reconstructed from everything we have disclosed?

That is a far more difficult audit.

The Mosaic Effect

Security specialists have long recognised a related phenomenon known as the mosaic effect.

A single fragment of information can be harmless.

Hundreds of fragments, viewed together, may become sensitive.

AI changes the economics of that process.

What once required a specialist analyst spending days examining documents can increasingly be performed in minutes.

This gives old information new value.

A forgotten press release from 2012 may suddenly matter when combined with a recruitment notice from 2024 and a supplier contract from 2026.

Each document may be innocuous.

The pattern may not be.

That is why the emerging privacy challenge is not simply about keeping secrets out of databases.

It is about understanding what can be reconstructed from everything surrounding them.

What Can Still Be Taken Back?

There remains a substantial difference between information that can still be controlled and information that has escaped meaningful control.

Private files, personal websites, AI conversations, accounts and social-media posts may often still be deleted by the people who control them.

Search results, third-party databases, copied photographs and material published by others are harder.

Widely replicated information, public records, archived documents, information incorporated into datasets and conclusions that can be inferred from surviving evidence are harder still.

That does not mean deletion is pointless.

Removing obsolete data reduces exposure.

Privacy settings matter.

AI users should understand what they upload and how the service handles it.

Companies should routinely audit what employees, suppliers and departments are collectively revealing online.

Governments may need to reconsider whether documents that appear harmless individually reveal something sensitive when analysed together.

But deletion is no longer the same as forgetting.

There May Be No Complete Reset Button

Jacobsen’s account remains an account rather than independently established proof that ChatGPT identified a genuine Strategic National Stockpile facility.

But the vulnerability it illustrates does not depend on that single episode.

Humans have spent decades documenting themselves.

Companies have documented their operations.

Governments have documented infrastructure, procurement and policy.

Artificial intelligence is becoming increasingly capable of reading those records together.

That creates a profound change in the economics of information.

Privacy once depended heavily on controlling access to individual pieces of information.

Increasingly, it may depend on whether enough surviving pieces remain for a machine to reconstruct what was removed.

The question is therefore no longer simply what AI already knows.

It is what we can still make it forget.

And the most difficult answer may be this:

We can delete information we control, seek removal of copies we do not, and develop technologies to unlearn data already incorporated into machines. But when AI can reconstruct the same conclusion from everything that remains, there may be nothing left to delete.

Related news :AI, Bad Intelligence and the Strike That Killed 123 Children

Egypt, Nvidia Move Towards AI Computing and Skills Partnership

Read also : Egypt’s State Ownership Policy Faces a Valuation Test

Global Debt Tops $365tn as AI Adds to Funding Demands

Recent Articles

- Advertisement -spot_img

Intresting articles