- Roko's Basilisk
- Posts
- Privacy's Second Renegotiation
Privacy's Second Renegotiation
Plus: Anthropic's record settlement, Google's frozen Gemini chip, and another AI czar walks.
Here's what's on our plate today:
π Why privacy now hinges on who can learn from you.
π° Anthropic's record payout, Google freezing Gemini into silicon, and another AI czar gone.
π§ Brain Snack: every shared prompt is a deposit you can't withdraw.
π Poll: if it's accessible, is it fair to learn from?
Letβs dive in. No floaties needed.

Meet your next hire in as little as five days
Smart hiring for teams that need strong talent now.
Fill key roles faster, without waiting weeks or months for the pipeline to behave.
AI-assisted matching and structured vetting help you find people who fit the role and the team.
Cut time and cost with a process built for scale, not endless back-and-forth.

Build and design your website on Framer - Now with Agents
Framer is a pro website builder trusted by companies like Miro and Perplexity that helps creators, teams and businesses ship production-ready sites faster than ever.
With AI agents built directly into the canvas, teams can design pages, manage CMS content, write copy, add SEO, and audit for issues β all without leaving the tool where the real site lives. Agents bring speed and scale; you bring taste, judgment, and control.
*This is sponsored content

The Laboratory
TL;DR
Privacy was about who could see you. AI made it about who can learn from you.
The old rules broke: Privacy meant controlling access, and that worked because looking at information left it unchanged. Models extract patterns, keep them, and generate from them.
Meta's three days: Muse Image lets strangers pull public Instagram photos into AI images, on by default, with no notification. Nothing about the photos changed; the objection was the learning.
Beyond consumers: Nadella says enterprises pay twice, in money and in proprietary know-how. Publishers argue the open web was for reading, not for training.
The law measures acquisition: Courts called training transformative and penalized only piracy. The White House agrees and defers to judges.
Stakes: Every case turns on one belief, that accessible means learnable. Where that boundary lands defines privacy in the AI era.
The new meaning of privacy in the AI age
For most of human history, privacy meant secrecy. The things people considered private were the things they chose not to share. Social media changed that arrangement by encouraging people to share more of their lives in exchange for connection, audience, and reach. And, as platforms like Facebook, Instagram, LinkedIn, and TikTok grew, privacy shifted from keeping information hidden to controlling who could access it. The settings, audience controls, and permissions that came to define the social media era were all built around that idea.
As a result, the major privacy disputes of the past two decades were largely arguments about access. Whether it was Facebook's Cambridge Analytica scandal or the backlash against facial recognition systems, the central question was who had been allowed to see or collect information. That framework worked because information remained largely static once it was shared. Reading a post or viewing a photograph revealed it to another person, but did not fundamentally change it. AI is challenging that assumption by turning information into something machines can learn from and build upon.
The shift is easy to miss because it does not look like the privacy violations people have spent the past two decades worrying about. Nobody is breaking into an account, bypassing permissions, or gaining access they were never meant to have. The information at issue is often shared publicly and viewed under exactly the conditions its owner intended. The settings are working, the permissions are correct, and no one has been let through a door they should not have used. The argument has moved entirely beyond the door. The clearest place to watch that transition unfold came during a single week in July 2026, when Meta discovered what people were actually objecting to.
What Meta learned in three days
On July 7, 2026, Meta introduced Muse Image, an image generator that allowed users to type the username of a public Instagram account and incorporate that account's photos into AI-generated images. The feature was enabled by default, applied to people who had never opted in, and provided no notification when someone's likeness was used. Three days later, after user and talent agency complaints, Meta withdrew the feature, acknowledging that it had missed the mark, though the model itself continues to operate across Instagram, WhatsApp, and the Meta AI app.
Nothing about the photographs changed during those three days. They were public before the launch and remained public afterward. What changed was that a machine could study those photos, learn a person's features, and use them to generate entirely new images. The discomfort stemmed from seeing personal photos used as raw material for creating new content without consent.
The language we use to talk about privacy was shaped in a world where looking at something did little more than reveal it to another person, but AI has altered that relationship by making observation productive rather than passive. Instead of simply viewing an image, a model can extract patterns from it, retain those patterns, and use them to generate entirely new outputs. As a result, publishing something online no longer only makes it visible to other people; it can also make it useful to machines. What were once two separate acts, sharing information with an audience and contributing to an AI system's capabilities, are increasingly collapsing into one. A person uploads a photo so that others can see it, yet that same photo can simultaneously become material from which a machine learns, generates, and creates in ways the person never anticipated.
That is the shift people are beginning to grapple with, and it extends far beyond photographs of faces. Once AI turns information into capability, the question ceases to be personal. Any organization that shares information with a model faces the same dynamic.
The same trade, now inside the company
The principle at stake extends well beyond photographs of faces. Once a model can extract patterns from information and turn them into capabilities, the same logic applies wherever information meets AI. That shifts the debate from social media users worried about their images to businesses worried about their expertise, revealing that what looks like a consumer privacy issue is increasingly becoming an economic one as well. Five days after Meta's retreat, on July 12, 2026, Microsoft's chief executive made the corporate version of the complaint. Satya Nadella described what he called the 'reverse information paradox', arguing that companies that buy access to AI models pay for intelligence twice: once in money and once in the proprietary knowledge they have to reveal to make the model useful in their own work.
The mechanism is simpler than the phrase suggests. When an employee tells a model that a contract clause does not work that way in their industry, or that a claim should have been flagged differently, they are not merely using the system. They are contributing information about how their organization operates. In many arrangements, that knowledge flows back to the model provider while the company that supplied it retains little visibility into how it is used. Nadella's concern is that the relationship runs largely in one direction, with providers learning continuously about their customers while customers learn almost nothing about the systems they depend on. He also pointed to the tension in an industry that claims broad rights to learn from public information while limiting outsiders' ability to study the models themselves.
The argument conveniently aligns with Microsoft's commercial interests, since Nadella's preferred solution involves companies operating AI in private environments hosted on Microsoft's cloud infrastructure. Yet stripped of the business language, it is fundamentally the same complaint Instagram users had raised a week earlier. In both cases, the objection is that information shared for one purpose is being transformed into capabilities that create value somewhere else.
Long before either group began making that argument, news organizations had already encountered the same dynamic. Publishers spent decades putting reporting on the open web so that people could read it, search engines could index it, and new audiences could discover it. What they did not anticipate was that the same material would become training data for systems capable of producing answers that competed with the source. The dispute that emerged was therefore not simply about copyright, but about whether information made public for distribution had also, by default, become raw material for building someone else's intelligence. That realization pushed news organizations beyond public complaints and into court.
What the publishers have been saying
Publishers have made their case in the language of intellectual property, which has kept the rhyme easy to miss. Their position is that an article being readable on the open web has never meant that a company could absorb it, learn from it, and sell a product built on what it learned. On July 9, 2026, the New York Times, the New York Daily News, and other news organizations asked a Manhattan court to sanction OpenAI, alleging that it had withheld evidence about whether it could search its own systems for their material, an allegation the company denies while continuing to defend its training as fair use, the rule that allows copyrighted material to be used without permission when the result is different enough from the original.
The courts, however, have been answering a narrower question than the one publishers are asking. When a federal judge gave preliminary approval to Anthropic's $1.5B settlement with authors in September 2025, the underlying ruling found that training AI models on books was generally allowed because the process was considered transformative, meaning the model created something new rather than simply reproducing the original work. The legal problem was not the training itself but the fact that some of the books had been obtained from pirate websites. In other words, the court focused on how the material was acquired, not on what the AI learned from it afterward. That leaves publishers, businesses, and Instagram users in a similar position: they worry that AI systems can learn from their information and develop new capabilities, while the legal tools available today are mostly designed to determine whether the information was obtained improperly in the first place.
The gap between what the law permits and what many people find acceptable is not accidental. In its national AI framework released in March 2026, the White House stated that training AI models on copyrighted material does not necessarily violate copyright law and said the courts should continue to resolve the issue. That position aligns closely with the industry's underlying assumption that information available online can be learned from.
Fair game, and a public that disagrees
The tension arises when that assumption meets the people who created the information in the first place. Meta treated public Instagram photos as material for image generation. AI providers often reserve the right to learn from customer interactions. Publishers argue that reporting produced for readers was absorbed into training datasets without permission. Although the details differ, each case reflects the same belief: information that is accessible can also be learned from.
Social media transformed privacy by persuading people to trade secrecy for visibility, replacing a world where privacy meant keeping information hidden with one where it meant controlling access to it. AI is forcing a second renegotiation. The question now is bigger than who gets to see information once it is shared. Now, the question is whether access also grants the right to learn from it, extract value from it, and develop new capabilities from it.
Social media changed what it meant to share information. AI is changing what it means to use it. Where that boundary settles may determine what privacy means in the age of AI.


Brain Snack (for Builders)
![]() | π‘Every prompt you send to a shared model is a deposit into someone else's training data, and there's no withdrawal slip. Before you pipe proprietary workflows into a public API, ask what edge you're quietly handing the provider. Keep the crown jewels on open weights you run yourself. |

Outperform the competition
Business is hard. And sometimes you donβt really have the necessary tools to be great in your job. Well, Open Source CEO is here to change that.
Tools & resources, ranging from playbooks, databases, courses, and more.
Deep dives on famous visionary leaders.
Interviews with entrepreneurs and playbook breakdowns.
Are you ready to see whatβs all about?
*This is sponsored content

Quick Bits, No Fluff
Anthropic's $1.5B book deal is final: A San Francisco judge signed off on the largest copyright payout in US history, roughly $3k a book, while leaving the underlying "training is fair use" ruling untouched.
Google wants to freeze Gemini into silicon: A server chip codenamed "Frozen v2" would hardwire the model's architecture into the hardware for up to 10x more efficiency, with deployment targeted around 2028.
Another AI czar walks: CAISI director Chris Fall resigned after just three months, the latest exit from a top AI-standards post that's become a revolving door since David Sacks left in March.

Wednesday Poll
AI turned privacy from who can see your data into who can learn from it. Where should that line fall? |
|
Meme Of The Day

The Toolkit
Together AI: Cloud platform for running and fine-tuning open-source models on your own data, keeping your edge in-house.
VEED: Browser-based video editor with AI subtitles, dubbing, and one-click translation, no timeline-wrangling or heavy software required.
Superhuman: AI email client that drafts replies, summarizes threads, and clears your inbox faster than you can procrastinate.

Rate This Edition
What did you think of today's email? |






