Skip to main content

    AI App Safety: Questions Before Sharing Sensitive Information

    Before sharing sensitive information with an AI app, check who publishes it, what data it receives and whether you can limit or remove access.

    By ZoraSafe · Content reviewed · Originally published

    An app name is not proof of safety

    An AI application may rely on models and services supplied by other organizations. A familiar name does not tell you which components are running or how the app handles your information. This is a consumer decision guide, not a report that a specific current service is compromised.

    Sources: NSA and partners: Deploying AI systems securely

    Check the decision you control

    1. Get the app from the publisher’s verified distribution channel.
    2. Read its data-use and retention terms before submitting work, financial or family information.
    3. Limit permissions and avoid sending account credentials or recovery codes.
    4. If an unexpected message asks you to install an AI tool or sign in, verify the request independently.

    Sources: FTC: How to recognize and avoid phishing scams

    Related guidance: Kids’ Phones: Balance Safety Controls and Privacy

    If something seems wrong

    Stop sharing sensitive material, review connected-account access and use the provider’s support route. If credentials or payments were exposed, follow the relevant recovery process.

    Technical teams should also examine model provenance and execution risk; that is covered in the companion developer checklist, rather than repeated here.

    Sources: FTC: How to recover your hacked email or social media account

    Related guidance: Tech Support Scams: Do Not Grant Unexpected Remote Access

    Sources and product references

    Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.