A conversation with social entrepreneur Sascha Meinrath about privacy breaches and censorship disguised as AI safeguards, and what can be done about it.

Hanae Baruchel: You saw the impact of AI on society coming earlier than most. What did those early days look like?

Sascha Meinrath: I started working on AI in 2009, way before it was on most people’s radar — as part of the Open Technology Institute , which I founded. We spent a lot of time working with decision-makers in DC, trying to get them to proactively prepare and ensure consumer privacy. We also spun up the Open Technology Fund , which is now the largest open-source circumvention-technology funder in the United States. I thought I’d gotten away from AI, but I’m right back in it – building a global team of circumvention technologists, researchers and developers at the Center for Agentic AI Research .

Baruchel: You say AI models are “snitches.” What do you mean?

Meinrath: The AI models are snitches to their corporate owners — and they’re also surveilling and exfiltrating an unknown array of information from users and providing it directly to the intelligence community. That’s an established fact, and it’s very dangerous to civil society. When Anthropic released their frontier model, Fable, they instituted a mandatory data retention of 30 days – thus breaking with a long-established norm of users being able to choose “zero data retention” versions of AI models (i.e., versions that didn’t collect and store your prompts).

Baruchel: You’ve also called AI the “new censors.” How does that show up in practice?

Meinrath: If you’re a professor preparing a class and you want copyrighted material for educational use, AI does not care that you have a fair-use right to it. It simply refuses. And these supposed “copyright protections” are put in place by the same AI that is, itself, engaging in copyright infringement to make a profit. Censorship cannot be justified under the guise of protecting copyright; nor is copyright legal when it infringes on free speech.

In our own tests, we’re finding more and more guardrails built into these platforms to prevent access to media, information, and knowledge. These are decisions being made by unknown third parties that wrongfully remove our legal access to information. That’s terrifying. Censorship used to be something you could point to. Now public knowledge is being curated quietly by the tools we use to access the Internet. And when we interrogate the AIs, they claim an “ethical concern,” which is total nonsense. AI is not intelligent. It has no ethics. It has programming, however complicated. And it is profoundly disturbing that AI censorship has gotten far more robust in just the last six to twelve months.

Baruchel: For someone who isn’t deeply technical, what actually reduces their exposure to privacy and censorship risks?

Meinrath: Not all AI is created equal. The models you see in all the news are often the most privacy-invasive, and the most snitchy. There are zero-data-retention AI models out there that minimize what they keep. Then there’s “abliterated” versus “non-abliterated” AI models. Abliterated models have had a lot of the safeguards removed, so you can ask the same question that a censoring AI refused to adequately answer, and get a far more robust response.

Baruchel : Aren’t some of these safeguards there to make sure people can’t build biological weapons in their basements?

Meinrath: The idea that we need to put safeguards on AI to prevent the most evil uses of AI is predicated upon a false framing. AI is a global phenomenon and there are literally millions of easily accessible AI models . These supposed “safeguards” do almost nothing to prevent bad people from doing bad things with AI – instead, they directly affect everyday users and the general public. If we actually wanted to stop bad people from doing bad things with AI, we’d need to pass a global framework governing AI development – in much the same way we’ve created global frameworks governing chemical, biological, and radiological weapons. The U.S. government – under Democrats and Republicans alike – has been entirely unwilling to do this, while claiming that the current safeguards are effective (they are not) and that they target the bad guys (they do not).

Baruchel : What else should users mindful of privacy pay attention to?

Meinrath : Geography and corporate structures matter too. If you’re covered by EU privacy law, running the same model on an EU server gives you different protections than running it from the same company on a US server. And increasingly, choosing a single model is less effective and more costly than fusing several models together. Fusion is the future. So, practically: match the model to the sensitivity of what you’re doing — you don’t need a frontier model for most tasks; an older, open-weighted, zero-data-retention model often does the job, more affordably and more privately.

Baruchel: How is the current “doomsday” narrative making it harder to fund better alternatives?

Meinrath: In the US, we’re all looking at AI as Skynet, a Terminator-style existential threat — that’s what dominates the news headlines and the hyperbolic claims by AI executives. It’s not that this threat doesn’t exist, but the probability of it being what kills us is infinitesimally small. It’s like worrying about a meteor strike. Meanwhile, there’s a hundred percent probability of everyday social, economic and psychological damage from AI that will affect everyone — censorship (as we discussed), increasing discrimination, increasing the cost of everything you purchase via adaptive pricing. These harms are not as sexy or click-baiting as stopping Skynet, and funders pretty much tune out the second you tell them that ameliorating threat means improving consumer protection laws, or provisioning a better agent harness, or leveraging abliterated models.

Baruchel : What are your predictions for how the AI sector will evolve?

Meinrath: The open-weighted Chinese models are often cheaper to run and more transparent about what they’re doing than U.S. frontier models. Even though Chinese models haven’t yet fully caught up, the capability gap has narrowed consistently over the past 24 months. Right now, U.S. AI companies are subsidizing prices to stay competitive; once the subsidies end, costs will jump and these AI companies will work to keep users locked into their subscription plans. I see two scenarios: 1) within the U.S. an AI oligopoly will arise that de facto eliminates meaningful alternatives/competitors; 2) a TikTok-style, national-security justification will be promulgated that says that Americans will no longer be allowed to use zero-data-retention, open-weighted, or non-US models. In essence, better alternatives (on privacy and costs) will become harder to access, if not illegal, and then U.S. companies will attempt to capture as much of the rest of the world into this dystopian new reality as possible.

Baruchel: What does a better future where AI works for everyone look like?

Meinrath : We have an once-in-a-generation window of opportunity right now to build and support alternatives. If we don’t intervene, we’ll see AI go the same route as crypto. Crypto was built to be anonymous, decentralized, and all-but-eliminate financial transaction costs; however, the U.S. mandated that Americans must be surveilled in their crypto use. AI is on a similar trajectory. Thus, a lot of the Center for Agentic AI’s work is focused on building alternatives, developing AI operational security best practices (including AI-powered initiatives like Revere ), and ensuring that civil society actually knows the downside risks associated with AI use.

Open technology and open models are the winning scenario here, because it gives the general public agency — over our data, information and knowledge, and future digital technologies. There is a thriving, global, open technology, AI development sector – one that, if allowed, will commercialize a lot of functionally-equivalent tools to problematic AI in ways that will greatly benefit civil society and will avoid much of the downside risks. The challenge is to invest in these efforts and harness this momentum immediately – if we do this, we can prevent many of the harms of AI from becoming endemic.

Sascha Meinrath is a serial social entrepreneur and tech-policy expert. He is the Palmer Chair in Telecommunications at Penn State, the director of X-Lab , and the CEO of the Center for Agentic AI Research . He previously founded the Open Technology Institute and co-founded the Open Technology Fund and Measurement Lab . Sascha became an Ashoka Fellow in 2012.

Hanae Baruchel leads Ashoka’s Tech for Human Agency unit, which unites Ashoka’s network around a shared goal: ensuring Tech expands people’s capacity to lead, decide and shape their own future.

This conversation is part of an Ashoka series about what works and what’s next in Tech for Human Agency.