OpenAI Privacy Protections and New York Times Data Demands

OpenAI is legally challenging a demand from The New York Times to turn over 20 million private ChatGPT conversations. The company states this request is an overreach that risks user privacy without aiding the resolution of the ongoing lawsuit between the two parties.

Legal Dispute Over User Conversations

OpenAI is fighting a request from The New York Times to access 20 million randomly sampled ChatGPT conversations from the period of December 2022 to November 2024. The New York Times claims this data is necessary to find examples of users attempting to bypass their paywall.

OpenAI characterizes this demand as a disregard for privacy protections and security practices. The company notes that the Times had previously demanded 1.4 billion conversations and attempted to restrict users' ability to delete their private chats, both of which OpenAI successfully resisted.

Impacted Users and Data Scope

The data demand specifically targets a random sampling of consumer ChatGPT conversations. The following parameters define the scope of the impact:

  • Timeframe: Conversations occurring between December 2022 and November 2024.
  • Excluded Groups: ChatGPT Enterprise, ChatGPT Edu, ChatGPT Business (formerly "Team"), and API customers are not impacted by this demand.
  • Selection Method: The 20 million conversations were randomly sampled from the specified timeframe.

Privacy Mitigations and Security Measures

To protect user information while navigating legal obligations, OpenAI is implementing several safeguards:

  • De-identification: OpenAI is running affected chats through a procedure to scrub personally identifiable information (PII), passwords, and other sensitive data.
  • Secure Storage: Data subject to the court order is stored separately in a secure system under legal hold, accessible only to a small, audited legal and security team.
  • Access Control: OpenAI is pushing for the data to be viewed only by the Times' outside counsel and technical consultants within a secure environment under strict legal protocols.

OpenAI previously offered the New York Times privacy-preserving alternatives, such as targeted searches for text from New York Times articles or high-level data classification of ChatGPT usage, but these options were rejected.

Future Privacy Roadmap

In response to these privacy challenges, OpenAI is accelerating its security roadmap to prevent unauthorized data access. Key planned features include:

  • Client-side encryption: This will ensure messages with ChatGPT remain private and inaccessible to anyone, including OpenAI.
  • Automated safety detection: The company is building fully automated systems to detect safety issues. Human review will be limited to a small, vetted team and reserved only for critical risks, such as cybersecurity threats or threats to life.

OpenAI's Chief Information Security Officer, Dane Stuckey, emphasizes that as AI becomes more integrated into personal lives, privacy protections must become more powerful to maintain user trust.

Sources