Writing

You own the device. Do you own what it knows?

Aug 19, 2026 · updated Aug 21, 2026 · privacy, security, data ownership

Cameras, cars, DNA tests, phone records, password managers and AI chats all show the same pattern: when someone else holds the data, their systems become part of your risk.

Essay

The short answer is no, not always. You can own a camera, a car, a phone, a password manager account, a DNA kit result, or an AI subscription, and still depend on someone else’s servers, employees, contractors, credentials, software dependencies, policies, and legal obligations to protect what those products know about you.

That does not mean the cloud is bad or that every technology company is untrustworthy. It means something simpler: when another system holds your data, that system becomes part of your security and privacy boundary.

A camera can see inside a home. A connected car can record where someone drives. Genetic data cannot be rotated like a password. An AI assistant can hold conversations about work, health, money, source code, and personal decisions.

So the better question is: who has to be trusted, and to do what, for this data to stay private, available, and under my control?

The pattern crosses industries

What people use Public example What it shows
Home cameras Ring and Wyze Video can be exposed through account attacks, internal access, or software failure.
Cars GM and OnStar Owning a product does not automatically mean controlling the data it creates.
Genetic testing 23andMe Some exposed data cannot be replaced.
Password managers LastPass Development systems, employees, secrets, backups and metadata all matter.
Telecom AT&T and Odido Providers can hold identity and communications data at enormous scale.
Ticketing and banking Live Nation, Santander Data held in a third-party environment is still your data.
Healthcare clearing Change Healthcare One dependency can affect a very large number of people at once.
AI assistants OpenAI, Google, DeepSeek Conversations are records, and records can be reached.

Owning the product is not the same as controlling its data

In January 2026 the FTC finalized an order with General Motors and OnStar after alleging they collected, used and sold precise geolocation and driving-behavior data from millions of vehicles without adequate notice and affirmative consent. The order requires additional consumer controls and limits certain sharing with consumer reporting agencies.

The distinction gets sharper with genetic information. The UK’s Information Commissioner’s Office fined 23andMe after its 2023 breach, saying unauthorized access affected 155,592 UK residents and could include family trees, health reports, race, ethnicity, location and other account information. When 23andMe later entered bankruptcy proceedings, UK and Canadian regulators publicly called for protections around customer data during and after the sale.

Which raises the question most product pages never answer: what happens to your data when the company holding it changes owners, changes policy, restructures, or disappears?

Third-party infrastructure widens the trust boundary

AT&T told the SEC in 2024 that threat actors accessed an AT&T workspace on a third-party cloud platform and exfiltrated records of customer call and text interactions, covering nearly all of its wireless customers during the relevant periods. The files did not contain call or text content.

Live Nation separately disclosed unauthorized activity in a third-party cloud database environment holding company data, primarily from Ticketmaster. Santander disclosed a related example in May 2024, saying unauthorized access occurred in a Santander database hosted by an external provider, affecting customers in Chile, Spain and Uruguay along with current and some former employees, while stating the database held no transactional data or online banking credentials.

Snowflake later said threat actors had accessed a number of customer accounts, while also saying it found no evidence those incidents resulted from a vulnerability, misconfiguration or breach of the Snowflake platform.

That distinction matters, and it is the one most reporting drops. “Data was stolen from a cloud-hosted environment” does not automatically mean “the cloud provider was hacked.” Credentials, configuration, identity controls, integrations and account policy all sit in between.

Encryption does not erase the surrounding system

LastPass disclosed a sequence of incidents that began with access to its development environment and later led to unauthorized access to cloud backups. The company said the attacker used information stolen in the first incident, targeted an employee, obtained credentials and keys, and copied backup data including customer metadata and backups of customer vault data. Sensitive vault fields stayed encrypted under its zero-knowledge design. Some information, such as website URLs, was not encrypted.

Strong encryption matters. So do endpoints, employees, cloud storage, secrets, metadata and backups.

Centralization can create a large blast radius

The 2024 Change Healthcare ransomware attack shows the scale a single incident can reach. HHS says Change Healthcare reported approximately 192.7 million individuals impacted as of July 31, 2025.

Centralization provides real benefits. It also means some failures affect a very large number of people simultaneously. Resilience is partly a question of how much is able to fail together.

Human access is part of the security model

Coinbase disclosed in 2025 that a threat actor paid multiple contractors or employees in support roles to collect information from internal systems they were authorized to access for their jobs.

If an employee, contractor, administrator, reviewer or service can legitimately access information, that path is part of the security boundary. Not an edge case in it.

AI makes the custody question personal

People increasingly use AI assistants as a place to think, so prompts now carry things that used to stay in private notes, internal documents, source repositories and trusted conversations.

The details vary by product. OpenAI says it does not train on business and API customer data by default. Google’s Gemini Apps Privacy Hub says human reviewers, including trained service providers, review some collected data, and warns users not to enter confidential information they would not want a reviewer to see or Google to use to improve its services.

There is also a legal dimension. OpenAI said in 2025 that The New York Times sought 20 million consumer ChatGPT conversations in copyright litigation, and opposed the request, saying the sample did not include its listed business and API customers. DeepSeek provides a separate security example: in 2025 researchers found a publicly accessible database with sensitive backend information and chat-related records, and Reuters reported the exposed information included software keys and chat logs that appeared to contain user prompts.

In June 2026 Reuters reported that a federal judge allowed a search warrant seeking an executive’s chatbot records. Other courts have reached different conclusions about protection for AI-assisted work, so the law here is genuinely unsettled.

Different issues, same custody question. AI conversations become records, and records held by a third party can become relevant to a security incident or to legal process.

This is not old news

In February 2026, Dutch provider Odido said approximately 6.39 million people were affected by a cyberattack that began with voice phishing against customer-service staff.

On August 13, 2026, Reuters reported that the Cl0p group claimed data theft from nearly 50 companies. Some companies confirmed attempted or possible incidents, others said they had found no evidence of compromised customer data, and Reuters could not independently verify the group’s broader claims.

Which is its own lesson: an attacker’s claim should not quietly become a headline, or a marketing claim. Unverified claims stay labeled as claims.

So what does this actually prove?

It does not prove that cloud services are unsafe, that local infrastructure cannot be compromised, or that any architecture eliminates human error, vulnerable software, stolen credentials or bad configuration.

It does show that every additional custodian, privileged user, account, integration, dependency and remote service becomes part of what has to work correctly for your data to stay private and available.

That is the whole argument for ownership, and it is a narrower argument than the one usually made. The goal is not to trust nobody. It is to avoid a design where trust is the only control you have left.

Common questions

Does owning infrastructure make it impossible to get hacked?

No. Infrastructure you own still needs secure configuration, updates, backups, identity controls, physical protection, monitoring, recovery and careful permissions. Ownership changes where the control boundary sits. It does not delete the security work.

Is this an argument against cloud services?

No. Cloud services are excellent tools. The argument is for choice, portability, explicit permissions, and knowing which systems hold your sensitive data.

Are AI chats private?

It depends on the product, the account type, the settings, the provider’s policies, the integrations, retention rules and legal context. Business offerings often differ significantly from consumer ones, and the difference is worth reading before it matters.

Why does ownership matter if a company has strong security?

Because security is only one part of control. Ownership also affects retention, portability, dependency, availability, permissions, and what happens when a vendor changes its policy, its owner, or its mind.

Sources

  1. FTC final order involving GM and OnStar
  2. UK ICO fine against 23andMe
  3. UK ICO on protections during the 23andMe sale
  4. AT&T Form 8-K on the third-party cloud workspace incident
  5. Live Nation Form 8-K on the third-party cloud database
  6. Santander statement on the third-party hosted database
  7. Snowflake Form 10-Q on customer account access
  8. LastPass security incident update
  9. HHS: Change Healthcare cybersecurity incident FAQ
  10. Coinbase Form 8-K on insider-assisted access
  11. OpenAI on business and API data commitments
  12. Google Gemini Apps Privacy Hub
  13. OpenAI statement on the request for consumer ChatGPT conversations
  14. Reuters on the DeepSeek database exposure
  15. Reuters on the 2026 chatbot records warrant ruling
  16. Odido security update on the voice-phishing incident
  17. Reuters on the Cl0p extortion claims