It’s only a UTM parameter. So what?

I recently discovered something about ChatGPT that genuinely surprised me. At first it seemed almost trivial, but the more I thought about it, the more uncomfortable I became. After digging into it, I discovered that something very similar may already have played a part in a political controversy in Australia, which made the implications for ordinary ChatGPT users feel rather more significant.

When ChatGPT provides links to external websites, OpenAI adds the following parameter: utm_source=chatgpt.com

The purpose is straightforward. It allows publishers to attribute traffic to ChatGPT for the purpose of analysis and reporting.

OpenAI documents this behaviour in its Help Centre, so the information is technically available. I would not, however, describe that as transparent. There is a considerable difference between documenting something somewhere and making users aware that it is happening.

It rather reminds me of the planning notice concerning the demolition of Arthur Dent’s house in The Hitchhiker’s Guide to the Galaxy. Yes, the information technically existed somewhere. Whether that amounts to meaningful notice is another matter entirely.

Arthur eventually found the plans:

“in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.’”

That is the joke, of course. Making information technically available is not the same thing as meaningfully informing the person affected by it.

OpenAI documenting this behaviour somewhere in its Help Centre may satisfy the first of those descriptions. I am not convinced it satisfies the second.

I certainly was not aware that ChatGPT was modifying outbound links in this way until I happened to notice it. More importantly, there is no prominent privacy control asking whether I actually want it to happen.

At first glance, this probably does not sound sinister. After all, utm_source=chatgpt.com does not contain your name, email address, account number or some unique identifier.

It just says that the visitor came from ChatGPT.

So what is the problem?

Quite a lot, as it happens.

Not all URLs are anonymous

Let us start with the most obvious issue.

Imagine that I ask ChatGPT about something, and it gives me a link to a website where I already have an account.

I click the link.

The URL contains: utm_source=chatgpt.com

The destination now knows that whoever followed that link arrived from ChatGPT.

If I am not logged in (and therefore anonymous to that site), this may not be especially interesting. What happens if I am logged in? Now the site learns something about me that it didn’t know before. It knows I arrived via ChatGPT. It can infer I use ChatGPT regardless of whether I wanted to share this information or not!

The UTM parameter does not need to contain my identity because the website already knows who I am. OpenAI has supplied an additional piece of information that the site can associate with my account. OpenAI has announced to the website: “You arrived here via ChatGPT.”

Perhaps the site also has years of purchase history associated with me. Perhaps it has my browsing history. Perhaps it knows my real name, address, employer or other details. This is all data I (presumably) decided to share. What I did not decide to share was my AI usage nor specifically which AI I am using.

The parameter did not contain any of that information. It did not need to. The recipient already had it; however, OpenAI has now supplied another piece of information that can be correlated with everything else.

Why does that website need to know that I arrived through ChatGPT?

It does not, and we should not conflate need to know with want to know. Sites often want to know such data for analytics purposes, but they don’t need to know. My privacy has now been violated on a want-to-know basis, not even a need-to-know!

So why is this an issue?

What if the website now has a data leak, sells my data or shares it with a 3rd party? Now they also know I use ChatGPT. Now they know I use AI. Now they know more about me than I originally wanted them to know. I never shared this with them; OpenAI did, and I never asked for nor consented to this! Suddenly (hypothetically), I’m getting hundreds of spam emails about AI offers as a direct result of this.

The URL works perfectly well without the parameter. OpenAI adds it because publishers want to measure referral traffic. That is useful to publishers, and I understand why they want it. I just do not care. A third-party company’s desire for better analytics does not trump my privacy.

Metadata doesn’t have to contain a secret to be secret

Anyone who has worked in security for any length of time should already know where this is going.

Metadata can be dangerous. That is not because every piece of metadata is sensitive. The problem is that you have no idea what an apparently insignificant piece of information might later be combined with.

Microsoft learnt this lesson many years ago. Office documents can contain author names, usernames, revision information, comments, file paths, document properties and all sorts of other information that the person sharing the document may never have intended to disclose.

Microsoft provides Document Inspector specifically to help users find and remove this hidden information before publishing or sharing documents. Microsoft itself warns that comments, revision marks and document properties can reveal who worked on a document, changes that were made to it and other information that somebody might not want shared outside their organisation.

There is a particularly relevant real-world example.

In 2003, the UK government published its second dossier on Iraq as a Microsoft Word document. Examination of the document’s revision metadata revealed the names of people who had worked on it, including officials in the Foreign Office, Downing Street and the Prime Minister’s press operation. The metadata helped expose the document’s editing history and provenance at a time when the origins and presentation of the dossier had become politically important.

There was nothing inherently secret about the names of those civil servants.

That was not what made the metadata sensitive.

What mattered was the information that could be inferred from those otherwise mundane names: who had worked on the document, where it had passed through and, therefore, something about how it had actually been produced.

The metadata supplied context which the visible document did not.

That is the point.

A piece of metadata does not have to contain somebody’s medical records, bank details or password before it can create a privacy or confidentiality problem. It can be completely ordinary information which becomes significant because of what it reveals when combined with everything else that is already known.

The UK Police vs Metadata leaks

There have been some nasty examples involving UK police documents that show just how serious metadata leakage can become. I am not suggesting that these cases are equivalent to OpenAI adding a ChatGPT referral parameter. They are simply examples of why metadata deserves more attention than it usually gets, and why its consequences can extend far beyond what was originally intended or anticipated.

Crimebodge/Copper Stopper discovered that Devon and Cornwall Police had published a misconduct report concerning an officer who had been granted anonymity.

Throughout the visible document, the officer was referred to as “Officer X”.

Great. Job done.

Except it was not.

The officer’s surname remained embedded in the PDF metadata and was reportedly visible in the browser tab. According to Copper Stopper, a basic Internet search using that surname was enough to discover the officer’s full identity and employment history.

The visible document did not reveal his identity. The metadata supplied the missing piece.

In another case, South Wales Police published a misconduct report which appeared to have had confidential information redacted. Unfortunately, the redaction was defective and supposedly hidden information could still be recovered using basic tools.

These are just a couple of examples of a systematic metadata sanitisation failure uncovered by Crimebodge/Copper Stopper!

These examples are, of course, much more serious than utm_source=chatgpt.com. I am not suggesting that they are equivalent in severity. That is not the point.

The point is that you cannot decide whether information is harmless by looking at it in isolation. You have to consider what happens when somebody combines it with everything else.

Then Australia happened!

This is where things become interesting.

On 17 August 2026, Guardian Australia reported on an Age Check Certification Scheme report relating to technology underpinning Australia’s under-16 social media restrictions. The organisation initially denied using AI to produce the report.

Guardian Australia subsequently identified four links in the report containing metadata that identified ChatGPT as their source. Only after those links had been identified did the organisation concede that ChatGPT had been used to rewrite some of the material. To be clear, we don’t know for sure it was utm_source metadata, but this seems the most likely candidate.

I am deliberately not getting into the separate controversy concerning allegedly incorrect or hallucinated references in that report. That is an entirely different issue. The accuracy of a document, including its facts, citations and sources, is ultimately the responsibility of its author.

Unnecessary metadata silently added by OpenAI is not something a user should have to go hunting for, though. It provides no benefit to the ChatGPT user. Its purpose is to benefit third parties by identifying referral traffic and possibly act as a shill for OpenAI.

I am sorry, but my privacy should not be the price paid for providing somebody else with better analytics, especially when OpenAI has made that decision on my behalf, without giving me any meaningful choice.

The metadata gave the game away.

Something as innocuous-looking as ChatGPT referral metadata disclosed information about how that Australian document had been produced. Not only did that undermine the document, but it also undermines the argument that this information is inherently harmless. If it were meaningless metadata, it would not have been capable of revealing anything, and The Guardian wouldn’t have had a story!

The Australian case demonstrates something else as well. It demonstrates that this behaviour is not transparent.

Consider what happened.

If the people producing the report had been made aware that ChatGPT was embedding provenance information into the links they were copying, is it likely that those parameters would have survived all the way into a published report? Perhaps they still would have done. It seems less likely.

The fact that they survived unnoticed into published material is itself evidence that users may have no idea that this information is present. Saying that the behaviour is mentioned somewhere in OpenAI’s documentation does not change that.

Documentation is not transparency.

For a privacy-affecting behaviour, I think there are three separate questions we should ask ourselves about this metadata tag:

Is it documented?

Yes.

Is the user made aware that it is happening?

Not in any meaningful sense that I can see.

Has the user chosen to allow it?

No.

That is not good enough. That is the complete antithesis of transparency!

“In Australia, though, it served the public interest”

Perhaps it did! That does not make the mechanism acceptable.

Imagine that I punch somebody in the face. As a result, they go to hospital and miss their flight. The aeroplane crashes. Does that make me a hero for punching them? Of course it doesn’t. A beneficial consequence does not retrospectively justify the act that caused it.

The Australian disclosure happened to expose something that journalists and the public had a legitimate interest in knowing.

Fine.

The next disclosure might not. That is exactly the problem. Neither OpenAI nor anybody else can know in advance what the context will be.

What if revealing ChatGPT use actually harms someone?

Imagine that somebody works for a company where ChatGPT is not permitted. They use it anyway. ChatGPT helps them research something and supplies several useful sources. They copy those sources into a report and submit it.

Hidden inside the links is:

utm_source=chatgpt.com

Someone notices.

The employee gets fired. Perhaps they broke company policy. Perhaps they deserved to get fired. Perhaps the company’s policy is ridiculous. None of that matters to the privacy question.

None of those circumstances gives OpenAI the right to disclose evidence of that person’s ChatGPT usage without their knowledge or consent. The employer’s relationship with its employee is one issue. OpenAI’s relationship with its user is another.

Whether somebody was entitled to use ChatGPT has nothing to do with whether OpenAI was entitled to disclose the fact that they did.

You do not lose your privacy because somebody else might have had a legitimate reason to want the information.

“You should have removed the UTM parameter”

I can already hear this argument. The user should check what they are publishing. Yes, they should; however, that’s not the point! There is also a fairly large problem with using that as an excuse for OpenAI.

ChatGPT’s output is not necessarily WYSIWYG.

A link might appear on screen as:

Interesting article about security

The hyperlink underneath that text could be:

https://example.com/article?utm_source=chatgpt.com

If I copy formatted output from ChatGPT into another application, that underlying hyperlink can travel with it. I can proofread the entire document without ever seeing it.

Ironically, this is the same security issue that allows spammers and phishers to exploit many rich-text and HTML-based email clients! What you see in a hyperlink isn’t always what you get!

What I read on screen is not necessarily what I copy.

To discover the additional metadata, I may need to inspect the hyperlink target, paste the URL somewhere that exposes it, examine the HTML or run every URL through a sanitising tool.

Seriously?

OpenAI took a functional URL, added information to it that I did not request, did not need and might not even be able to see, and it is somehow my responsibility to discover and remove it?

No.

Do not add it without asking me in the first place.

The fact that a knowledgeable user can discover and remove the metadata is not the same thing as informed choice.

OpenAI already understands the principle

Here is the odd part.

OpenAI’s own documentation concerning ChatGPT-generated links explains that URLs can transmit information to third-party websites. It even discusses examples in which information contained within a generated URL might be disclosed to the destination when the user follows it.

OpenAI’s stated concern is keeping users in control of what information is shared.

Good. I agree 100%.

Why, then, does that principle not apply to information that OpenAI itself adds to the URL?

If information contained in a URL can be privacy-sensitive enough that the user should have control over whether it is disclosed, OpenAI should not bolt its own provenance information onto that URL without offering the same choice.

The source of the information does not change the privacy principle.

A rather wonderful bit of irony

While looking into all of this, I came across an article discussing DeepSeek, AI and data privacy.

Several of the reference links within that post contain:

utm_source=chatgpt.com

That gives me at least some evidence that ChatGPT was involved somewhere in the research or production workflow behind the article.

Is that a problem for the author?

Probably not. I have no idea whether the author intended to inform me of how sources were obtained, and there’s nothing necessarily wrong with using ChatGPT to gather sources.

Perhaps they are happy for everybody to know. Perhaps they disclosed their use of ChatGPT elsewhere. Perhaps they did not realise those parameters were present. Perhaps they would rather I had not been able to infer it.

I do not know. Neither does OpenAI. That is the whole point.

The significance is not for me, OpenAI or the destination publisher to decide.

It belongs to the person whose workflow is being exposed.

Security works by assuming the worst

One of the basic lessons in security engineering is that you do not design a defence around the assumption that everything will be used in the most benign possible context. On the contrary, you have to assume the worst and work backwards, not assume the best and work forwards.

It’s like the principle of “Least Privilege”. You don’t give users all permissions and then disable them as problems arise. You give them the least number of privileges possible and enable them (where appropriate) as problems arise! Why? Because as far as security is concerned, it’s generally far safer and easier to deal with missing data than it is leaked (confidential) data!

So for this particular case of referral attribution, you ask what information is being exposed. You ask whether exposing it is necessary. You ask who can observe it. You ask what else they might already know. You ask what happens when it is correlated with other information. You ask what the worst reasonable consequence might be.

Put another way, you create a robust threat model!

When considering utm_source=chatgpt.com, I think the important questions are these:

Is this information required for the user to follow the link?

No.

Has the user chosen to disclose it?

No.

Can OpenAI know what other information the recipient already possesses?

No.

Can OpenAI know whether the destination already knows exactly who the user is?

No.

Can OpenAI know where this URL will eventually be copied, published or archived?

No.

Can OpenAI guarantee that revealing ChatGPT provenance will never matter to the user?

Absolutely not.

At that point, the correct security decision seems pretty obvious.

Do not disclose it unless the user chooses to.

This should be opt-in

I am not arguing that OpenAI must never provide referral information. If somebody is happy to help publishers understand how much traffic ChatGPT sends them, that is fine. Give them the option.

Something like:

Share ChatGPT referral attribution with external websites

When enabled, links opened from ChatGPT may identify ChatGPT as the referral source to the destination website.

Put it prominently in ChatGPT’s Privacy or Data Controls settings. Explain what it does. Explain why it exists. Explain who receives the information. Most importantly, default it to Off.

It should not be buried in an obscure advanced configuration page. It should not be mentioned only in documentation that users have no reason to read. It should not be something that users discover years later when they happen to inspect one of their URLs.

The user should be made aware of the behaviour before the information is disclosed and should make an explicit choice about whether to allow it.

That is what meaningful privacy control looks like.

Copied links are arguably even worse

There is another important distinction. When somebody clicks directly from ChatGPT, OpenAI can at least describe the parameter as referral attribution. Once I copy the URL elsewhere, however, the nature of the information changes.

It is no longer merely referral information. It becomes provenance information.

I can paste it into:

  • An email.
  • A company report.
  • An academic paper.
  • A forum post.
  • A blog.
  • A government document.

It can sit there for years. Nobody even needs to follow the link. They merely need to inspect it. Australia has already demonstrated this in the real world. That is not hypothetical. It happened.

I think both interactive referral attribution and copied provenance should be under explicit user control.

This is not merely a question of cleaning URLs when they are copied or exported. The same privacy issue exists when somebody clicks a link directly from ChatGPT. The destination may already know exactly who that person is, and OpenAI has no way of knowing whether revealing that they arrived through ChatGPT is harmless, sensitive or potentially damaging.

OpenAI may want to provide referral attribution to publishers. Publishers may want to receive it. Neither of those interests gives OpenAI the right to make that disclosure on the user’s behalf. Neither trumps my privacy!

Whether ChatGPT identifies itself as the source of a visit should be the user’s decision.

If the user chooses not to share referral attribution, direct links should be clean. Copied, exported and published URLs should also be clean. There should not be a lesser standard of privacy merely because the user clicked the link rather than copied it.

Copied URLs should be clean.

“They are a private company. They can do what they want.”

I can already hear another argument.

OpenAI is a private company. Nobody is forcing me to use ChatGPT. If I do not like what it does, I can stop using it.

That is true, as far as it goes.

It does not, however, follow that a private company can simply do whatever it likes and wash its hands of the consequences.

Private companies are still subject to the law. Depending on the circumstances, disclosures of information can give rise to questions of privacy, confidentiality, contract, data protection and, potentially, civil liability. “We are a private company” is not some magical exemption from responsibility.

More importantly, my objection here is not primarily about what OpenAI stores or processes internally. It is about OpenAI deliberately adding information to a URL which may then be disclosed to somebody else. That disclosure can have consequences which OpenAI cannot possibly know in advance. Australia has already demonstrated that.

The ChatGPT provenance embedded in links contained within the Age Check Certification Scheme report helped reveal that ChatGPT had been involved in producing material after the organisation had initially denied using AI.

In that particular case, the disclosure happened to serve the public interest. The mechanism did not know that; it simply disclosed the information. Next time the consequences may be very different.

I have a rather more personal example.

Before OpenAI introduced this behaviour, I used ChatGPT extensively while preparing an employment case concerning my redundancy. I used it to research issues, test arguments and help prepare a considerable amount of legal material. The dispute eventually went to ACAS and the company agreed to settle.

Now imagine that the sources and links within documents I had prepared had silently contained:

utm_source=chatgpt.com

I might never have noticed.

The company or its lawyers might have.

Would that necessarily have destroyed my case?

No.

Could it have been used to question how documents had been prepared, attack the reliability or independence of my research, distract from the substantive arguments, or otherwise weaken my negotiating position?

Quite possibly.

I will never know, because fortunately the attribution mechanism did not exist at the time.

That is precisely the point.

OpenAI could not possibly have known what those links were going to be used for, who would eventually see them, or what significance evidence of ChatGPT use might have had in that particular dispute.

Nor can it know today.

A referral parameter which is completely harmless when I click through to read a newspaper article might be much more significant when the same URL appears in an employment dispute, a court document, an academic paper, an internal company report or a confidential communication.

OpenAI does not know the context. It does not know the recipient. It does not know the consequences. Yet it has chosen to make the disclosure anyway.

There is then a second problem.

Even if somebody believes OpenAI is perfectly entitled to offer a service which discloses referral attribution to third parties, I still need to know that this is part of the bargain before I can decide whether I am willing to accept it.

To the best of my knowledge, when automatic utm_source=chatgpt.com attribution was introduced, ChatGPT did not present users with a prominent notice explaining that outbound links would begin revealing ChatGPT as their source.

I certainly do not remember being told. I was not asked whether I wanted it. I discovered it because I happened to inspect a URL.

Had OpenAI told me:

We are going to start adding information to outbound links which tells destination websites that you are using ChatGPT. This information may also remain in URLs that you copy into other documents.

I would have said no. I was never given that opportunity.

That is what makes the “private company” argument particularly weak.

A company can set the terms on which it offers a service, subject to the law. The customer must at least have a meaningful opportunity to know what those terms are and decide whether they are acceptable.

You cannot meaningfully choose whether to accept a privacy-affecting behaviour when you have not been made aware that it exists.

OpenAI made a decision about what information I would disclose to third parties. It did not know what consequences that disclosure might have for me. It did not ask whether I accepted that risk. It did not even meaningfully tell me that it had introduced it.

Being a private company does not give OpenAI the right to choose my privacy for me.

The metadata can also be wrong

Another problem with embedding provenance information into URLs is that it does not necessarily remain attached to the person who originally used ChatGPT.

Imagine that I create a document containing several links supplied by ChatGPT. I send that document to somebody else. They open it and click one of those links.

The URL still contains:

utm_source=chatgpt.com

The destination is now being told that this visitor arrived from ChatGPT.

Except they did not. They arrived from my document.

If the destination is a website where that person is already logged in, the situation becomes even stranger. The website may associate their account with a supposed ChatGPT referral which never happened.

The metadata is no longer merely disclosing information.

It is disclosing incorrect information.

The same problem exists in the opposite direction.

Imagine that somebody on my team uses ChatGPT while preparing a document. I do not know that they have done so.

They send the document to me. I proofread it (remember, embedded links are not WYSIWYG), approve it and publish it on behalf of the company. Somebody later examines the links and finds: utm_source=chatgpt.com

What conclusion are they likely to draw? Perhaps that I used ChatGPT to write the document. Perhaps that my company routinely uses ChatGPT to prepare official material. Perhaps that the document itself was AI-generated.

None of those conclusions necessarily follows from the presence of the parameter. Perhaps one employee merely used ChatGPT to locate a source. Perhaps they copied a single link from a conversation. Perhaps the person who ultimately approved and published the document never used ChatGPT at all.

The provenance has escaped from the context in which it was created and become attached to everybody downstream.

That matters:

  • There are organisations with contractual restrictions on the use of generative AI.
  • There are employers with internal policies governing its use.
  • There are professions and regulated environments in which the provenance of a document, how it was prepared and what tools were used may be significant.
  • There are legal proceedings in which questions about authorship, evidence, research methodology or document preparation can matter.
  • There are also organisations that simply do not want customers, competitors or the press concluding their use of AI.

A stray UTM parameter could therefore create suspicion about a person or organisation that never used ChatGPT at all.

Australia demonstrates the problem from the other direction.

It’s likely those parameters were treated as evidence that ChatGPT had played some part in the production of the report. In that case, the inference turned out to have substance. That does not mean the same inference will always be correct.

Once these URLs are copied, forwarded, edited, incorporated into other documents and eventually published, OpenAI has no idea who is responsible for the final material or what relationship that person has with ChatGPT.

The metadata cannot distinguish between:

“This person used ChatGPT.”

and:

“At some point in this document’s history, somebody copied a URL that came from ChatGPT.”

Those are very different statements.

Yet utm_source=chatgpt.com makes no such distinction.

That creates a particularly uncomfortable combination:

  • The parameter can disclose information that the original user did not choose to reveal.
  • It can attribute ChatGPT use to somebody who did not use it.
  • It can imply something about how a document was produced that is not actually true.
  • It can then persist indefinitely after the original context has disappeared.

In the wrong circumstances, those false inferences could have professional, contractual, reputational or even legal consequences.

OpenAI cannot know where a URL will eventually end up. It cannot know who will eventually click it. It cannot know who will eventually publish it. It cannot know what conclusions somebody will draw from seeing it. Most importantly, it cannot guarantee that those conclusions will even be correct.

This is another very good reason why provenance should not be silently attached to URLs in the first place.

I have challenged OpenAI

I have now raised this directly with OpenAI’s Privacy Team. I feel strongly about privacy, and I feel strongly about personal choice and autonomy!

For me, the underlying principle is simple:

If ChatGPT is going to disclose additional information about my use of ChatGPT to a third party, I should be told clearly and given the choice before that disclosure occurs.

The fact that the information seems insignificant to somebody else is irrelevant.

They do not know the context.

They do not know who is receiving it.

They do not know what other information it might be combined with.

Most importantly, they do not get to decide what I am comfortable disclosing.

That is my decision.

This is not an argument against using AI

I want to make one thing very clear before I finish: I have no problem with people using AI. I use it all the time. I use it to help with research, explore ideas, test arguments, improve drafts, check whether something makes sense and help turn rough thoughts into something coherent.

That does not mean I simply ask an AI to write something and then publish whatever comes back!

I do the research. I decide what I think. I challenge the output. I correct it. I remove things I disagree with. I rewrite things that do not sound like me. I refine the wording until it says what I actually mean.

The result is still my work, my judgement and my words.

That distinction matters because this article is not an attack on AI use, nor is it an attempt to excuse people who misuse AI.

If somebody uses an AI system in circumstances where they are prohibited from doing so, whether by an employer, a contract, a professional rule or some other obligation, that is a separate issue. I am not condoning that.

What I am saying is that it is not the AI provider’s job to expose them.

In this case, OpenAI happens to be the company that dropped the ball.

The problem is not that ChatGPT is AI.

The problem is that OpenAI made a design decision which can disclose information about a user’s use of the service to third parties, without giving that user meaningful control over whether the disclosure happens.

The point is this:

  • OpenAI does not know the circumstances.
  • It does not know whether revealing AI use is harmless.
  • It does not know whether the user had permission.
  • It does not know whether the provenance will be misunderstood.
  • It does not know whether somebody else will later inherit the URL and be wrongly associated with AI use.
  • It does not know whether the disclosure could damage somebody professionally, contractually, reputationally or legally.

That is why this matters to me.

This is about privacy.

It is about autonomy.

It is about informed choice.

It is about whether a company gets to decide, on my behalf, what information about my use of its product is disclosed to somebody else.

In this case, I think OpenAI has badly missed the point.

utm_source=chatgpt.com looks trivial, but the Australian situation has already shown that metadata is not necessarily harmless. Those parameters helped reveal that ChatGPT had been involved in work where that involvement had initially been denied.

In that case, the disclosure happened to expose something the public had a legitimate interest in knowing. The same mechanism could just as easily produce a very different outcome next time.

That is the problem.

OpenAI made what probably looked like a tiny product decision.

Add a referral parameter.

Help publishers measure traffic.

Simple.

Except privacy failures often begin with decisions that look innocuous when viewed in isolation. The harm appears later, when the information reaches a context the designer did not anticipate.

No AI provider can anticipate every context. Neither can I. That is precisely why the decision should not belong to the provider.

And finally, in the interests of full disclosure, ChatGPT did help me research and draft this article. I chose to tell you that. That is exactly how it should work!

If information about my use of an AI service is going to be disclosed to somebody else, I should know about it, I should understand it, and I should be the one who decides whether that disclosure happens.