Between Samsung's engineers leaking their own source code into ChatGPT, DeepSeek leaving a database of a million chat logs sitting open with no login required, and Grok's share links somehow getting indexed on Google with 370k private conversations searchable, I've basically stopped believing "trust us" is a real answer from any frontier lab.
None of these were sketchy no-name startups either. These are the companies everyone's building on top of right now.
Before this, I built classified redaction systems for Canadian intelligence, the kind of environment where data moves between jurisdictions constantly and one mistake isn't a fine, it's a real problem. Every transfer had to be checked, reasoned about, and logged, not because anyone assumed bad intent, but because "trust me" isn't a control.
When I started talking to law firms, I kept hearing the same shape of problem. They share just as much sensitive material (litigation, expert witnesses, discovery) and they're bound by real regulation, but nobody had built tooling for it. Most existing tools either block and hold everything or don't watch at all. Now AI adds a door nobody's watching either.