Privacy and Security Risks of AI Chatbots and Companion Apps
AI-powered chatbots and companion applications are raising significant privacy and security concerns as their adoption grows, particularly in sensitive contexts such as romantic or adult interactions. Legal experts highlight that recent litigation is testing how federal and state wiretapping and eavesdropping statutes apply to AI chatbots, with uncertainty over whether insurance policies will cover privacy-related claims. The legal landscape is evolving as courts distinguish between data collected by AI chatbots and traditional analytics tools, and organizations face new challenges in defending against claims of unauthorized interception of communications.
At the same time, the proliferation of AI companion apps and the introduction of adult-oriented features by major platforms like OpenAI's ChatGPT have led to increased requirements for age and identity verification. This has resulted in the collection and storage of sensitive personal information, such as government-issued IDs, which has already been targeted in several high-profile data breaches. Research indicates that a significant portion of users, including minors, are sharing personal information with these bots, and recent incidents have exposed hundreds of thousands of users' data due to misconfigured systems. These developments underscore the urgent need for robust privacy protections and security controls in the rapidly expanding AI chatbot ecosystem.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Privacy and legal experts warn erotic AI chats may expose sensitive user data
By mid-November 2025, multiple security and privacy reports highlighted that users engaging in romantic or erotic chatbot conversations could reveal highly sensitive personal information, creating risks around data retention, disclosure, and potential legal exposure. The coverage emphasized that intimate AI interactions may not remain private and could have insurance, litigation, or identity-related consequences.
OpenAI launches GPT-5 with a more permissive sexual-content policy
OpenAI released GPT-5 and updated its model behavior policy to allow some sexual content, including erotic roleplay, while still prohibiting exploitative or harmful sexual uses. The change prompted renewed scrutiny of privacy and safety risks tied to intimate chatbot interactions.
Sources
3 references tracked. Mallory keeps watching after this page renders.
What security pros should know about insurance coverage for AI chatbot wiretapping claims
helpnetsecurity.com
Open sourceThe price of ChatGPT’s erotic chat? $20/month and your identity | Malwarebytes
malwarebytes.com
Open sourceWhat if your romantic AI chatbot can’t keep a secret?
welivesecurity.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


