I’ve been thinking about something lately, and the more I sit with it, the more it bothers me. Frankly, I hope it bothers you too, and that you take action to fix it.
When people think about AI privacy at all, they think of it like a settings menu. Flip a switch that promises some level of privacy, then forget about it. But it’s way bigger than that.
Here’s what I mean. You don’t talk to an AI the way you’d talk in a meeting. You talk to it the way you talk to yourself. The raw brain dump, the rough draft, the half-baked idea, the question you’d be embarrassed to ask out loud. That stuff used to live in your head until you decided otherwise. Now it lands on someone else’s machine.
Think about how your mind actually works. Every thought you’ve ever had started where nobody else could see it. You imagine all sorts of things in there. You contradict yourself, entertain something crazy, or change your mind five times before your coffee is ready. None of it exists in the world until you choose to put it out there. Privacy is the default. You decide what gets shared, and when, and with whom. That order matters. Private first, revealed second. It’s how thinking has always worked. You try your ideas in the dark, keep the ones that survive, and show the world the version you want to show.
Now look at how we use AI. We don’t finish the thought and then type it in. The thinking happens with the machine. The machine is part of the process itself, so the thinking isn’t private anymore. It’s watched by default.

If you run a company, this should keep you up at night.
This is not a philosophy problem. For a business, it’s an operational intelligence problem. Every prompt your employees send is a little piece of how your company thinks. Your pricing logic. Product plans nobody has announced. Legal exposure. Code. This is not simply data. It’s your judgement, written down. And if all of it flows into a large language model you don’t control, running on infrastructure without privacy guarantees, you aren’t using a tool anymore. You’re shipping the inside of your company to a stranger and hoping they’re careful with it. But hope is not a good strategy.
This gets more pressing as models get cheaper and easier to swap out, your data ends up all over the place, and the model itself is no longer the valuable thing. The valuable thing is what sits between your data and whatever models you happen to be using at the moment. Your company should own that application layer by using a harness, also called an orchestration layer or control plane, which holds the context your AI will use. Importantly, the harness lets you switch models without rebuilding everything.
The harness is where you can create AI agents that get things done for you. Think of them as specialized teammates, like an engineer, a customer expert, a researcher, or your personal assistant. Each teammate is set up as a bot (a profile) in Hermes. This separation of expertise minimizes redundant processes, reduces cost, and maintains a high level of intelligence. You can give them access to the tools you already use, which frees you from using many different user interfaces daily. For example, your personal assistant could scan you inbox and prep your daily calls for you. You simply interact with your AI teammates via the harness.
There’s another piece that your harness setup will fix. Privacy isn’t just about who sees your data. It’s about whether your data is isolated from everyone else’s, and whether you can take it back when you mess up. Because you will mess up. You’ll paste the wrong thing into a prompt, send a file you didn’t mean to send, trust a vendor you shouldn’t have. Human error is still one of the biggest drivers of data incidents. When your thinking lives on infrastructure that isn’t private, a mistake doesn’t just stay a mistake. It becomes a permanent record you can’t edit, can’t isolate from the rest of the pile, and can’t recover from on your own terms. Real sovereignty means your data sits in its own space, separated from everything else, and when you need to undo something, the system actually lets you. Set up properly, your harness runs on a local or cloud instance you control and keeps your data (brain) all in one place, private and fixable.
Companies and their IT departments need to figure this out now. The ones that wait will learn a painful lesson. You can’t press undo on the data already sent to these models.
Individuals are in the same boat.
AI is already in your work. It’s creeping into your money. It’s sitting right next to your identity, with how you write, how you make decisions, what you’re curious about, and who you’re trying to become. And the catch is that the more useful these tools get, the more honest you are with them. Your honesty is exactly what makes them work well for you.
Your prompts add up to a map of how you think. Give it enough time and that map becomes detailed enough to basically be you. Your taste. Your blind spots. Your health worries. So ask yourself who is holding that power.
Companies change their policies. They get acquired. They get breached. Governments send nasty letters. Some safety reviewer somewhere decides your conversation crossed a line you didn’t know existed. You don’t get a vote in any of that. These systems are moving deeper into our thoughts, our work, our money, and our identity every single day. Once being watched feels normal, it’s nearly impossible to get your privacy back.
The infrastructure harness sits between human minds and machine minds. Paired with private AI, genuine sovereignty becomes possible.
The safety story is heavy.
Most of the industry is building toward the same future. Your interactions with AI get watched by default, filtered by default, watermarked, and it’s all framed as protection.
Protection from what? From the possibility that you might ask the wrong question, or think in a direction that someone in an office somewhere decided was unsafe.
I’d just point out that surveillance systems are always framed as acts of kindness, protection, or public care, because that’s how they gain widespread acceptance. It’s for society. It’s for the children. It’s for your own good. But the same companies telling us these models are powerful and dangerous are the ones insisting they should be watching us use them. Notice the irony.
Which group of humans do you actually trust with a live feed of how your thinking? An AI lab’s board of directors? The current government? Whatever government comes next?
If you don’t have a good answer, don’t use systems without privacy guarantees. Erik Voorhees, the founder of Venice.ai, put it well:
If the AI company stores your conversations, they will be leaked eventually. The only safe solution is that they cannot be stored by the company.
That’s the real problem. Not the chatbot or interface. The structure sitting underneath all of it.
So what does privacy actually look like?
For an individual, you think with a machine without that thinking being stored, scored, or fed into a model you have zero control over. You ask the real question without wondering if it flags you. You own what you create. Delete it, export it, control it. You get access to intelligence without surrendering your private mind.
For a company, it looks like owning the layer that holds your data and whatever models you choose, and those models will probably be open source and/or open weights. Swapping models without rebuilding the business. Real guarantees, not promises, that your work isn’t leaking into someone’s training set, a competitor’s hands, or a records request you’ll never even see. Running sensitive work on infrastructure you can actually inspect.
And for all of us, it looks like rejecting a premise that has been sneaking in unchallenged. That safety requires surveillance, and that intelligence should be observable by default. Because a mind that knows it’s being watched doesn’t think the same way. It gets smaller. More careful. More compliant. That’s a change in thought itself, and a bad one. Scale it up across a whole civilization and it stops being a privacy problem. You have a hindered people.
Two paths
One is already built and keeps getting upgraded. It’s centralized, observed, and mediated by a handful of companies that hold your thoughts and set the limits on your words. It’s convenient, extremely well funded, and they are desperate to go public or already have. Some of these stories will not end well.
The other path is available and works beautifully. Your intelligence stays private by default. The machine that helps you think answers to you only.
The first path doesn’t require a decision. You just keep doing what you’re doing.
The alternative requires demanding something. The right to think without being watched. It’s the foundation your mind stands on. If you don’t demand it and win it, you’ve lost some of your humanity.
Ok James, this seems important. What can I do?
Install a model agnostic harness like Hermes agent on your own computer. As you use it, Hermes builds skills on your computer with your thoughts and information. Or you can pre-build the harness by storing and organizing personal or company data in it before you even start using it (the brain). Hermes Agent and Cursor are two of the most popular harnesses.
Use the harness with models that have privacy guarantees, like the ones offered by Venice.ai. They have several options. Anonymous via a proxy, which is not suitable for IP or sensitive data. Private through zero data retention contracts. And verifiable privacy with end-to-end encryption to a trusted execution environment.
If you’re using AI just for yourself and don’t want a harness, use a web interface like Venice.ai with the privacy guarantees above. Your web browser essentially becomes the harness and stores conversations locally. One thing to remember when cleaning up your browser and clearing the cache. Don’t delete your conversations, because they can’t be retrieved. It’s free to start with a few select models, and pro plans are available. There are already four million of us using it. Here’s a referral link where you and I both get $10 of inference when you sign up for a pro plan.
Or run the harness with an AI model installed on your own local computer. Not feasible for most people and most computers.
The world is changing fast. Don’t surrender your sovereignty. Stop trusting most ai providers. Contact me if you want help.
Leave a Reply