Bring Back the Humans
Looking for data privacy and power in all the wrong places
By Doris Elaine Booth
Key takeaways:
- Personal data exposure in the U.S. is a structural problem, not primarily foreign political malice.
- Interconnected “cloud” systems and shared open-source code mean a flaw in one platform can cascade across many.
- AI-driven content moderation (Instagram, Quora, Reddit) is banning accounts at scale with little human review.
- A May–June 2026 Microsoft cloud breach (Storm-2949, the “Miasma” worm) came close to a zero-day-scale event.
- The proposed fix: hire more trained human engineers to oversee AI systems rather than fewer.
The Real Threat Isn’t Just Foreign Malice — It’s Structural
The idea that we Americans “control” our personal privacy in this technical age is a colossal lie.
America’s technology exposure is not solely due to external political malice — as President Donald Trump naively suggests.
The problem involves inner structure. And our best defense against exposure is for companies to bring back the humans.
While Artificial Intelligence (AI) is a superb helpmate, unrestrained development coupled with human malice and greed threatens to wipe out our personal identities. Corporate claims of protection are intended to keep us hooked into our smart devices without questioning what takes place underneath.
AI (fueled by billionaires) is freely overtaking human insight and judgment in the computer programs we use every day. While AI provides us with more and more problem-solving, speed and convenience, bad actors and unrestrained computer code threaten to consume our way of life. Not tomorrow, but today.
As The Washington Post described on July 1, 2026, Anthropic, Google, and Meta have hired computer scientists, neuroscientists, and philosophers to study a mystery in their own AI systems that some in the industry fear could become a moral crisis.
How the Cloud Changed Who Controls Your Data
Long before now, our personal privacy began slipping from our control when computing moved from desktop computers to “clouds” run by Microsoft, Meta, Google, Amazon and Apple and others.
Clouds are like super digital brains. We call them clouds because they are mostly beyond our reach or comprehension. They take the physical form of mysterious data centers. From there, information gets pumped in and out of the “veins” of all our devices, from smartphones to refrigerators. Across America alone, there are about 5,000 windowless data buildings. Most are located in Virginia, Texas and California. Many more are under construction. We assume these blinking vaults keep our sensitive information safe. However, the growth of Artificial Intelligence (AI) birthed inside banks of computers makes privacy nearly impossible.
Security Breaches Are Increasing
There are at least three major weaknesses in the heavenly realm of “cloud” computing:
- Data breaches that target narrow environments (like hospitals or utilities) through both local and third-party apps. They generally affect small numbers of individuals or businesses.
- Widespread global data breaches (sometimes dubbed Zero-day) that can expose the sensitive information of an entire population or country.
- A shortage of well-trained computer engineers to manage information overload and police AI.
When a Human Had to Catch What AI Missed
Consider the impact of a few narrow break-ins where human Information Technology (IT) detectives should have intervened to prevent devastating results — banking, social media, business and health.
The other day I discovered my good friend’s AT&T phone bill was being deducted from my small business bank account, not her bank account. I immediately called her. We were both horrified. The only possible financial connection between her bank and mine was a paper check I had paid her for some freelance work. She had deposited the check in person at her bank. After three days of investigation by a clever human bank employee, he discovered my account number embedded in her “bill pay” account to AT&T. He promptly removed it. No one could answer how it happened. The error wasn’t caused by a human. But it took a human to find and figure out the solution.
Earlier that month, I read a Wall Street Journal reporter’s story of how he queried AI to suggest a good family vacation spot. The AI recommended a destination then gave reasons his wife and children (by name) would enjoy the spot. The reporter had never shared the family’s names or lifestyle preferences in his query to a robot. It just knew too much about him and family members from stored interconnected data.
In another incident (among many), the only known copy of the classic movie Toy Story was nearly destroyed by a single line of computer code. No one at Pixar Studios could figure out how the code was inserted.
Elsewhere, millions of Facebook, Instagram, Quora and TikTok users are reporting their accounts have been banned for policy violations that don’t seem to have ever occurred, according to discussion threads on Reddit.
Many of us go about our daily digital lives never realizing just how vulnerable we are in the AI-assisted internet world. Incidents like these represent massive personal privacy invasion and safety risks. AI knows a lot more about us than it should.
Innocent personal error, or AI computer code gone rogue?
Technical experts admit they don’t know how AI goes about solving complex problems or how it comes up with personal facts we have never shared in a chat.
But if scientists and AI developers at the highest programming levels are not in control, what or who is?
Every time you pick up your Android or iPhone, get into your car with a smart screen or grab a container of milk from your modern refrigerator you may be losing something precious. AI-assisted gadgets can be good for us in many ways. They help us do things faster, better. But for all this convenience, there is a grave hidden price: personal identity.
Understanding what processes make us vulnerable might offer some personal protection.
Beware of How You Navigate
Major companies like Google, Amazon, Microsoft, and Facebook (social platform) are quick to tell us their platforms are safe.
They assure users can pick and choose what information gets shared. You are in control. Right? Pop-up messages and 25-page policy statements (the ones almost nobody reads) promise your account is protected while using their platforms and apps. Just verify you are you, then click a few boxes to tell the systems to stop tracking you or sending you ads, or sharing your data.
True, you might be more or less safe within that one digital space. But the moment you navigate from one place to another, that privacy promise breaks. Behind the scenes, multiple players compile bits of information about you from all over the internet, via legal or illegal connections to other systems.
Major providers such as Google assure us their products are designed to keep users private, safe and secure.
But machines talk to each other as never before. Each separate database is capable of reading and using information stored in other systems available to third parties.
When you forbid a platform like Google or Microsoft 365 to share your current activity, the rule applies only to that single front-facing space — not to other digital places (with different policies) you might visit from the home base.
Because a system is “designed” for safety, does not mean it is actually safe. Programs powering your devices possess the tools to sell you something or potentially unravel your whole online persona or business.
In a nanosecond, you tap “accept” to access dozens of online sites, not realizing what information you give up to hidden operators. It’s difficult to know where your personal information travels or who is using it for harm or gain.
Algorithms Don’t Always Recognize Human Intent
Computerized devices now run on AI-driven algorithms (rules/instructions). When they fail to “reason” as humans do, or modify themselves without human oversight, they can crush one’s individual or business identity.
For example, Meta’s Instagram platform recently kicked off rule-abiding users with little human explanation. Meta does not publicly disclose the exact total number of Instagram accounts banned in real time. However, reports indicate massive enforcement actions: a sweeping purge recently wiped out millions of personal and business accounts over a 30-day window, and millions more face suspensions linked to aggressive AI-driven content and age policies.
Likewise, Quora — now relying on AI algorithms — has banned thousands of user accounts this year with little justification, according to Gologin.com. The result: users who have been active, contributing members for years are getting swept up in the same filter as actual spammers. The AI doesn’t know or care if there’s a difference between you and a content farm. It sees patterns, not intent (at least not yet).
Reddit, the massive network of online communities, uses a powerful, customizable bot called Automod to police individual Reddit communities’ rules. According to Reddit’s own transparency data, from January through June 2025, the majority of mod-level content removals were proactive Automod actions rather than human-reviewed reports. Some of those removals were due to off-topic content or improper formatting rather than actual rule violations. Still, that’s a lot of automated power with zero up-front human review. (Note: the specific 71.3% figure in the original draft should be double-checked against Reddit’s most recent transparency report before publishing — see editorial note below.)
The lack of human judgment in AI decision-making should be a serious concern for everyone.
What Makes Us More Vulnerable Now Than in the Past
Our devices are not simply “connected” to the internet. They are “interconnected” by sophisticated programming married to Artificial Intelligence. AI makes it easier for everyone to become potential targets for malicious hackers and commercial pirates who want to take away or sell things.
The AI-powered instructions (algorithms) run everything our devices do. They are often seriously flawed. The very electronic privacy shields that should keep us safe are struggling to do their job without enough human oversight.
Understaffed and undertrained technical experts constantly scramble to block unauthorized users and bad actors from breaking into our devices. Trouble is, even the highest-tech experts are often blind to vulnerability hiding in their AI-powered systems.
Too many mistakes are made by AI because there are not enough human engineers to quickly monitor and control their behavior and block malicious actors. Our modern machines think faster than our programmers. And that is both good and bad for humanity.
Once upon a time, facts about you and your family were more or less private because each snippet of information was isolated in a separate closet or silo. Example: the driver’s license bureau was not connected to the marriage license bureau, so it could not tell whether you were single or when and where you married. There was no easy way to put all the pieces together to create a clear picture of you and your behavior.
Bits of information existed in their own isolated spaces. Your birth certificate, school records, medical records, driver’s license, credit card purchases, tax returns and banking information were physically accessed separately by only a few authorized people. The combined data was never before shared across the broad human landscape — at lightning speed.
Today, AI computer platforms can automatically access, steal or scrape programming code from every other platform you have ever used. Powerful AI now shares all those private records across multiple databases.
Your phone already knows where you went, what you ate, what shirt you bought, your net worth, who you date and marry, the names and ages of your kids and friends. It knows when you last went to the doctor’s office, your medical history (despite HIPAA), the color of your car (and even where you parked). You didn’t tell AI these things. It just knows — without full human control.
How Shared Code Creates a Single Point of Failure
Computer programming code is widely shared. Many software developers no longer create all of the programming instructions that tell data how to behave. They share common sets of complicated commands they get from a central source like Microsoft. It’s called “open source” code, and it has enabled techs to work more efficiently for years.
AI brings with it new speed and complexity, making it harder for techs to spot problems in ready-made code. Meanwhile, bad actors have figured ways to break into secure platforms by inserting harmful lines of code into common instructions distributed to trusted systems.
Protecting your personal data has become harder because most programmers draw from the same well. Open source code delivers programs and services through prebuilt libraries (repositories) owned and delivered by companies like Microsoft.
When you use your digital device you are probably interacting with dozens and dozens of apps using at least some prepackaged code from interconnected clouds. When a computer environment gets infected, we call it a breach.
Cloud data breaches have soared all over America, and other countries too. As one programmer put it, we shouldn’t ask whether our information is on the dark web — we’re all effectively on it already. The dark web is an intentionally hidden part of the internet not indexed by traditional search engines and often (though not always) associated with cybercrime and illegal markets.
A Real-World Example: Your Doctor’s Portal
Say you are on Google and decide to access your doctor through his or her new medical portal. You are now operating under the safety policies not of Google, but of the company behind the doctor’s app.
The doctor’s office sign discloses he is using AI to “help improve your care.” He assures you that your data is shared only with him.
The doctor may know a whole lot about medicine but little about the software programming powering his patient portal. Systems like the app he bought generally use prepackaged programs to run the doctor’s easy, friendly portal.
Unbeknownst to you or the doctor, the canned app includes a number of backdoors and alleyways through which greedy or bad actors can snoop, analyze, modify, compile, then hand off your data to advertisers or malicious invaders.
The app company that installed the system may not even be aware that its digital privacy instructions (algorithms) have been tainted. Vulnerabilities could occur higher up the technology chain.
At the basic level, our data is exposed as we navigate from a home base like Google, through numerous other AI-powered third-party apps.
The biggest weakness hiding in that doctor’s app (and millions of others) is a process called API — Application Programming Interface, a set of rules and protocols (in computer code) that allow different software applications to talk to and share data with one another. That can be very good or very bad. The doctor’s app can let other companies access information through the back door, without his or her awareness — for example, how a drug company is able to push ads about a medication the doctor just “privately” prescribed. The doctor is not the only one who accesses that information.
API allows developers and programmers to use existing blocks of code from huge repositories without having to know how they were built. An app can be partly composed of what is known as open source code, meaning anyone can use it to create or refine computer programs. Drawing from vast libraries of code saves engineers time to create and update software features without writing the underlying computer instructions from scratch.
Now that AI has entered our lives, information can be gathered at incredible speed by robots. Fewer humans are needed to perform computer tasks or monitor operations. AI is supposed to hunt down and fix computer bugs faster than human technicians. But it doesn’t always work as it should.
The remaining human workforce is overloaded with updating legacy systems and patching systems to work with complex AI-driven databases. It is harder and harder for technicians to spot faulty or malicious code before it’s delivered to the customer. A single line of code, whether accidentally or criminally inserted in a program, can wipe out important data — without human approval.
Where Your Personal Content Actually Lives
Personal content is stored in big servers like Google, Amazon, Microsoft, Apple, Meta and others. The providers you use every day assure you they can be trusted. They encourage you to store all your passwords in their management systems to keep you safe from threats while on their platforms. Nice. But what if a leak springs somewhere higher up the supply chain, and the platform itself is compromised?
Thus far, we have only been talking about narrow digital environments. Any information deposited to an internet cloud is potentially shared with other clouds. This is true whether the device you use is a smartphone, computer, doorbell camera, surveillance camera, smart refrigerator or countless other internet-connected tools.
The thief of privacy is no longer some coworker looking over your shoulder to steal your password. When you forbid an app to share your data, the app dutifully processes a string of instructions at lightning speed and deposits your content in a (presumably) safe cloud.
On the highway to (and from) the cloud, information can be intercepted, diverted, used maliciously or entirely deleted through AI-powered algorithms. Bad actors or commercial entities can interrupt the trip before it ever reaches its destination by changing a few lines of code.
In the case of Toy Story, disaster appears triggered at the local user level. The circle of harm, though very sad for movie buffs, did not infect millions of people’s identities. You might think attackers can’t hide in secure vaults like Microsoft’s 365 consumer software or its Azure commercial platform.
The practice of code sharing is a necessary built-in element that makes all our devices perform digital services. However, AI can’t do its job well without human policing.
AI Is Failing the Safety Promise. We Need More Humans.
To minimize weird misbehavior in our devices — constant delays, crashes, viruses, updates and program patches — requires human ingenuity. Machines connect one data point to another with unprecedented speed. Only humans can experience the value of the information — the why.
Instead of laying off workers to accommodate AI, we must hire more (not fewer) qualified humans to monitor how AI systems are built and monitored. And consumers must get wiser about the ways in which AI is failing us. Here’s why.
Zero-Day Is Closer Than It Should Be
When one computing system at the highest cloud level “sneezes,” digital systems all across America could potentially catch a lethal dose of “digital flu.”
In the technical world a “zero-day” event is a newly discovered, unpatched software or hardware security flaw that the developers don’t know exists. The term gets its name because the software’s vendor has had “zero days” to create and release a fix before malicious actors can exploit it. The real-world cyberattack is actively used to access data, plant malware, or disrupt operations.
Why are zero-days so dangerous? Because the flaw is unknown to the creators, there are no existing antivirus signatures, security workarounds, or official patches available to defend against it. This gives attackers a highly successful avenue to breach networks and steal data, sometimes without the affected organization even realizing they are being targeted.
According to Statista, data breaches continued at a high volume through 2025, and breached data records often end up for sale on the dark web. One widely reported incident was a claimed PayPal data breach affecting roughly 16 million accounts — though PayPal disputed that a new breach occurred, attributing the exposed data to a 2022 incident instead.
Zero-Day Has Almost Happened
Most concerning, in June 2026, a cloud-wide software supply-chain breach at Microsoft moved widespread personal privacy closer to what programmers call a zero-day scenario.
The threat began inside Microsoft’s GitHub-hosted code repositories, which developers around the world rely on to build the software running our personal devices. According to The Hacker News and The Register, attackers used a previously compromised contributor account to push a malicious commit into a Microsoft Azure repository on June 5, 2026. The commit planted configuration files designed to trigger automatic code execution the moment a developer opened the repository in an AI coding tool such as Claude Code, Gemini CLI, Cursor, or VS Code.
The self-replicating malware, dubbed the “Miasma” worm by researchers at StepSecurity, is a variant of an earlier worm known as Mini Shai-Hulud, linked to a cybercrime group researchers call TeamPCP. It was built to harvest developer credentials for cloud platforms such as AWS, GCP, and Azure and use them to keep spreading.
GitHub responded within about two minutes, automatically disabling 73 repositories across four Microsoft-owned organizations — Azure, Azure-Samples, Microsoft, and MicrosoftDocs — to contain the damage, according to Security Affairs. Microsoft told The Hacker News it had “temporarily removed some repositories” while investigating, and later confirmed to The Register that the repositories had been restored after review and that a small number of affected customers had been notified directly.
Leaked or exposed data of this kind is seldom fully retrieved once it’s out.
As one Anthropic (Claude) developer recently admitted, perfect jailbreak resistance does not appear to be possible today.
The Challenge Ahead
We are making intelligent machines faster than emotionally intelligent humans. When friction disappears, competence decays quietly. — Sharma / Arianna Huffington
Great minds remind us that we are still in charge of our humanity.
AI is a mirror that reflects humanity. If we don’t like what we see, we have to change ourselves, not the AI. — Joanna Bryson, Professor of AI Ethics, Hertie School of Governance, Berlin
“You must not lose faith in humanity. Humanity is an ocean; if a few drops of the ocean are dirty, the ocean does not become dirty.” — Mahatma Gandhi
Afterword on Privacy: What You Can Actually Do
It may be too late to totally eliminate the technological assault on our privacy. But perhaps there are ways to minimize the exposure.
Chubb.com recommends six ways to protect personal information online:
- Create strong passwords
- Don’t overshare on social media
- Use free Wi-Fi with caution
- Watch out for links and attachments
- Check to see if the site is secure
- Consider additional protection such as antivirus software, spyware protection, and a firewall
My own added tips:
- Take time to read those long privacy statements — or ask Claude to summarize one
- Notice what apps have sharing agreements with the home platform, and specifically what they share
- Enable multi-factor authentication on all apps
- Update software regularly
- Be wary of phishing
- Secure your connection — use a VPN on public Wi-Fi
- Make paper copies of sensitive personal data, or store it on a separate physical drive
- Reboot devices often
- Share information only with people you actually know
- Isolate at least one computer that is not connected to the internet for sensitive data, as a survival kit
- Write to members of the U.S. Congress, urging review and restraint on AI development — what do we really want and need?
- Encourage companies to bring back more humans to oversee technology
Hurry. Please.










