AUGUST 20, 2026 21:23
Updated:AUGUST 20, 2026 21:25
Israelis Mali and Liel Yahalomi were reportedly tracked down from Vienna, Austria, to Buenos Aires, Argentina, by using the their chat history with artificial intelligence models, N12 News reported on Saturday.
For cyber expert Osher Cohen, the pair’s discovery proves his point on how it represents a key aspect of how people should rethink the way they interact with AI.
“Users need to gain a new habit: think before you type into an AI chatbot,” Cohen told The Jerusalem Post on Thursday when asked about the privacy of users when searching a term in a chatbot versus doing the same thing with a normal search bar.
“People sometimes treat AI chatbots as if they are speaking privately to themselves. In reality, an AI chatbot is a cloud service. It may be connected to an account, a device, an email address, a browser, an IP address, privacy settings, and data retention policies,” he explained.
Cohen is a cyber specialist and the founder of Yo Secure, an Israeli company that handles digital identity crises, hacked and blocked accounts, online impersonation, social media recovery, and security incidents on digital platforms.
According to him, the main diference stands in the way people engage a chat bot, giving context beyond the question in order to get a more accurate result.
“They give context, explain a situation, ask follow-up questions, test ideas, ask for wording, and sometimes describe things they would not say out loud to another person,” he said.
“In contrast, a regular search is usually short. You type a few words, get links, and decide what to read,” he added.
Cohen also explained that sensitive data should never be entered into an AI chatbot that isn’t properly secured, mainly because it’s easier to overshare when chatting than when searching.
“A search can show what you wanted to know. A conversation with AI can show what you were thinking, what you were worried about, what you were considering, and what you were trying to achieve. From a privacy standpoint, AI conversations can be more sensitive than regular search history because people treat them like a private adviser. But technically, they are still using a digital service,” he said.
Additionally, many users might confuse the search with the AI chatbot now that many of them are directly embedded into the search bar, but this doesn’t change the fact that the tools are different and should be treated in different ways.
“The fact that an AI tool appears inside a search bar does not mean the conversation disappears. It still depends on the company operating the service, whether the user is signed in, the privacy settings, the data retention policy, whether history is enabled, and whether the information may be used for safety, product improvement, or legal compliance,” Cohen said.
“The biggest issue is psychological. When AI is built into search, people feel like they are “just searching”. In practice, they may be creating a richer record than a regular search query,” he added.
According to Cohen, while metadata is stored differently depending on the location of the user, the day-to-day activity remains in cloud servers that are managed by the companies owning the chatbot.
“In most cases, a regular user does not know exactly where the data is stored. Large technology companies use global cloud infrastructure, and information may be processed or stored in different regions, depending on the provider, the product, the type of account, organizational settings, legal requirements, and the company’s internal architecture,” he said.
Additionally, while there are tools that might help with privacy and security, like VPNs, in the end there is a large list of providers, networks, apps, and more that might have access to the data shared in a chatbot even if the user thinks it is protected.
“With AI tools, the safest approach is behavioral, not only technical. With AI tools, the safest approach is behavioral, not only technical. Do not enter passwords, do not enter verification codes, do not enter credit card details, do not upload sensitive legal, medical, or business documents unless you understand the risk, and do not paste customer data into a personal AI account.”
Cohen also explained that, along with the mental practice of avoiding typing something you would not say out loud, people should clearly understand the privacy settings of the chatbot apps they use.
“People should check privacy settings, delete history when it is no longer needed, use temporary or incognito modes when appropriate, and avoid uploading sensitive documents into consumer AI tools,” he recommended.
“Businesses should create an internal AI policy. Employees need to know what they can paste into AI tools and what they cannot. Customer lists, contracts, legal documents, medical information, financial data, and internal strategy should not be casually uploaded into a personal chatbot account,” he added.
He described the AI tools as “an amazing tool, but it is not a safe deposit box,” and concluded: “The danger is not only what AI knows how to answer. The danger is what we choose to tell it.”