The AI Trust Crisis

Mounting privacy scandals and opaque data practices are eroding public trust in AI and cloud platforms, with Dropbox’s default sharing of user files with OpenAI cited as a fresh example. Commenters argue that even if companies promise not to “train on” personal data, the mere act of transmitting it to third parties, combined with weak consent mechanisms and limited legal enforcement, makes such assurances hard to believe. Many see end-to-end encryption, local or self-hosted AI models, and stronger regulation as the only realistic ways to regain control over personal information in an increasingly data‑hungry ecosystem.

Dropbox, OpenAI, and Consent

  • Many are angered that Dropbox’s “use third‑party AI” setting was enabled by default and framed as “consent” after the fact.
  • People distinguish sharply between:
    • Training models on public web data, versus
    • Sending private, paid cloud storage data to third parties, even “temporarily” or “only for inference.”
  • Several view this as a consent and fraud problem, not just a wording problem: doing something first, then burying it in TOS, is seen as illegitimate.
  • Some note possible regulatory trouble (GDPR, HIPAA/BAA) if private or regulated data was shared without explicit agreement.

Trust, Law, and Enforcement

  • Broad sentiment: large tech firms have burned trust repeatedly; users now default to disbelief even when companies deny misuse.
  • There is skepticism that reputational risk or fines meaningfully deter bad behavior; penalties are seen as “cost of doing business.”
  • GDPR is viewed as directionally right but under‑enforced and gamed with dark patterns.
  • Some argue existing concepts like fraud and unconscionable contracts already apply; others think digital TOS and weak regulators make this mostly theoretical.

Privacy Threat Model Beyond “Training”

  • Several stress the main risk isn’t just model training but:
    • Extra parties gaining read access,
    • Logs and temporary storage,
    • Rogue employees, security breaches, and unclear data flows.
  • A recurring theme: “if I pay for storage, you shouldn’t send my files anywhere without explicit, informed, opt‑in consent.”

Local Models, Encryption, and Self‑Hosting

  • Many see local or self‑hosted models as the long‑term answer: better privacy, fewer trust assumptions, and adequate performance given hardware trends.
  • Recommended mitigations: client‑side/end‑to‑end encryption (Cryptomator, Boxcryptor‑like tools), Syncthing, Signal, self‑hosted NAS + VPN/WireGuard/Tailscale.
  • Some accept convenience trade‑offs; others now plan to leave Dropbox for alternatives or encrypted overlays.

Broader “AI Trust Crisis”

  • Participants link AI distrust to a wider “post‑trust” environment: data‑hungry business models, weak accountability, and opaque ML systems.
  • There is disagreement over how much AI firms differ from the rest of tech, but broad agreement that current “trust us” messaging is inadequate without verifiable constraints and transparency.