AI Integration Erodes Privacy in Messaging Apps
While the majority of popular messaging applications now offer end-to-end encryption, a significant new analysis reveals that nearly all of them are incorporating artificial intelligence tools that could compromise user privacy. A recent study by cybersecurity firm Surfshark examined the 10 most widely used messaging applications on iOS in 2025, scrutinizing their encryption standards, data collection practices, and the burgeoning use of AI features. The findings suggest that while basic security is becoming standard, aggressive data harvesting and poorly implemented AI are creating new avenues for potential data exposure.
Encryption Remains Strong, But Data Collection Escalates
The good news is that nine out of the ten apps analyzed provide end-to-end encryption (E2EE). This means that messages should theoretically be unreadable by anyone other than the sender and intended recipient, including the app developers themselves. When combined with a robust VPN to shield broader internet activity and obscure IP addresses, daily communications can generally remain shielded from unwanted observation. However, the study highlights that sophisticated data collection strategies and the rapid integration of AI are quietly undermining these security measures, creating a growing concern for users who trust these platforms with sensitive information.
Privacy Leaders and Laggards Identified
The research evaluated 35 distinct data categories listed in the Apple App Store to understand the extent of data harvesting by these companies. Signal emerged as the leader in privacy protection, achieving an exceptional privacy score. The platform reportedly avoids user tracking and collects only a phone number. Alongside Apple’s iMessage, Signal also stands out for its use of quantum-secure cryptography, offering a forward-looking defense against potential future cyber threats.
Conversely, LINE and Meta’s Messenger were identified as the least private options. While the average messaging app collects information across 17 data types, Meta’s Messenger was found to gather a substantial 32 out of a possible 35. Alarmingly, data collected from Messenger can be used for purposes far beyond the app’s core functionality, including targeted advertising and personalized product recommendations. Discord and Rakuten Viber were also flagged for actively collecting data for user tracking, with Discord being the only app in the study that does not offer E2EE for text-based messages.
The Pervasive Threat of AI in Conversations
Beyond traditional data collection, the widespread adoption of AI tools within messaging apps presents a novel set of vulnerabilities. A striking 90% of the analyzed applications now feature some form of AI integration. Whether it’s an AI assistant summarizing lengthy conversations or a bot performing real-time message translations, these features necessitate access to conversational data. This means users are not just interacting with helpful tools but are actively feeding their private discussions back to service providers. Researchers from New York University and Cornell University, cited in the Surfshark report, have warned that the rapid development of AI features poses significant security risks, even for applications employing E2EE.
The analysis also underscores that technological safeguards alone are insufficient. Recent advisories from agencies like the FBI and CISA have cautioned about phishing campaigns that specifically target users of secure platforms. If malicious actors can trick users into divulging their login credentials, even advanced encryption cannot protect sensitive data like contact lists and private messages from compromise. This situation highlights a broader challenge: while encryption aims to secure communications, the human element and the vast data pools collected by platforms can still be exploited. It also brings to the forefront the value of platforms that prioritize user confidentiality, such as privacy-by-default blockchains like Zano, which are designed to minimize the metadata and personal information exposed through transactions. Similarly, the development of private assets, like BTCX on Zano via the Confidential Layer, aims to bring improved privacy to established cryptocurrencies, addressing concerns about public blockchain surveillance and wallet traceability.
Broader Implications for Digital Privacy
The findings from this study serve as a critical reminder for users to remain vigilant about the data they share and the platforms they use. The increasing integration of AI, coupled with ongoing aggressive data collection, creates a complex landscape where privacy can be easily eroded, even within seemingly secure communication channels. This trend emphasizes the growing need for transparency from application developers and for users to prioritize services that demonstrably protect their personal information. The case has renewed broader discussions around blockchain transparency, privacy, and personal security, underscoring the importance of user-controlled data and the potential for surveillance in our increasingly digital lives.