If Someone Else Is Steering Your AI
What this means
An AI takeover rarely looks like a film. More often it is a shared login, a stolen password, or a tablet still signed in — and then your old prompts are someone else’s reading list.
Note: This site may show light ads and occasional affiliate links. How that works.
We talk a lot about what AI might say. We talk less about who is sitting in your AI account.
If someone else can open your ChatGPT, Copilot, Gemini, or work AI login, they may not need to “hack the model.” They only need your session — and then they can read past chats, connected files, or saved instructions that were meant to stay yours.
Treat AI logins like email logins. Shared passwords and “stay signed in on Mum’s iPad” are how quiet takeovers start.
What “steering your AI” looks like
It is rarely cinematic. More often it is a shared family tablet still signed in, a browser that never locked, a reused password from a breached site, or a login page that captured the one password you use for “everything clever.”
Once inside, an attacker — or even a curious housemate — can mine old prompts for customer names, draft invoices, or internal notes you pasted “just to rewrite.” The model is not the weak point. Your session is.
Stop! Pause! Before you click a link to “verify your AI account” or “unlock premium access”: Is it urgent? Do you know who it is from? Is it really from them? Not sure — do not click. Open the app directly or type the address yourself.
Sessions, sync, and leftover access
- Sign out of AI tools on shared devices when you finish.
- Turn on multi-factor authentication (mfa) wherever the provider offers it.
- Review “connected apps” and devices on the AI account the same way you would for email.
- Do not reuse your main email password for AI tools.
If you think someone else was in there
- Change the password from a device you trust.
- Sign out other sessions if the product allows it.
- Check recent chats for anything sensitive you may have pasted — then assume it could have been read.
- Revoke API keys or integrations you no longer use.
One person, one AI login, on devices you control. Convenience is not worth a stranger reading last month’s prompts.
A self-check
Pick the device you use most for AI. Is it still signed in when someone else could pick it up? If yes, sign out today — and turn on that extra phone check (mfa) before you log back in.
Related: Before you paste it into the bot · When the bot can act without you · Cybersecurity at home · AI, human risk & scams
