DeepSeek: The Hot New Chinese AI Chatbot With Big Privacy and Security Issues
The Chinese artificial intelligence (AI) company DeepSeek has rattled the tech industry with the release of free, cheaply made AI models that compete with the best US products such as ChatGPT.
Users are rushing to check out the new chatbot, sending DeepSeekโs AI Assistant to the top of the iPhone and Android app charts in many countries.
However, authorities have sounded a note of caution. US officials are examining the appโs โnational security implicationsโ. Australiaโs former cybersecurity minister said national security agencies will soon issue formal guidance for users.
Why are governments and security experts so concerned? The main issue is the app is made in China and stores data there โ but that doesnโt mean all the worry is just xenophobia.
What information does DeepSeek record?
DeepSeek does not appear to be spyware, in the sense it doesnโt seem to be collecting data without your consent. However, like many online services, it clearly tells you it will record a lot of data about you and your behaviour.
Specifically, the companyโs privacy policy says it collects three categories of information.
First, there is information you provide directly, such as your name and email address and any text you type in or files you upload.
Next, there is automatically collected information, such as what kind of device you are using, your IP address, details of how you use the services, cookies, and payment information.
Finally, there is information from other sources, such as Apple or Google login services, or third-party advertising and analytics companies.
This is broadly similar to the data collected by ChatGPT and Claude.
What does DeepSeek do with the information?
DeepSeek says it uses this information for a range of purposes: to provide services, enforce terms of use, communicate with users, and review and improve performance.
The policy also contains a rather sweeping clause saying the company may use the information to โcomply with our legal obligations, or as necessary to perform tasks in the public interest, or to protect the vital interests of our users and other peopleโ.
DeepSeek also says it may share this information with third parties, including advertising and analytics companies as well as โlaw enforcement agencies, public authorities, copyright holders, or other third partiesโ.
DeepSeek will also keep the information โfor as long as necessaryโ for a broad range of purposes.
Again, this is all fairly standard practice for modern online services.
Causes for concern
Much of the cause for concern around DeepSeek comes from the fact the company is based in China, vulnerable to Chinese cyber criminals and subject to Chinese law.
DeepSeek stores the information it collects โin secure servers located in the Peopleโs Republic of Chinaโ. The company says it maintains โcommercially reasonable technical, administrative, and physical security measuresโ to protect the information.
However, we should keep in mind that China is one of the most cyber crime-prone countries in the world โ ranking third behind Russia and Ukraine in a 2024 study.
So even if DeepSeek does not intentionally disclose information, there is still a considerable risk it will be accessed by nefarious actors.
China is home to a sophisticated ecosystem of cyber crime organisations that often build detailed profiles of potential targets. Microsoft and others have accused the Chinese government of collaborating with cybercrime networks on cybercrime attacks.
These organisations can use personal information to craft convincing targeted phishing attacks, which try to trick people into revealing more sensitive information such as bank details.
Should you download DeepSeek?
So, should you download DeepSeek?
If you are an experienced user who is familiar with online privacy and the capabilities of modern AI systems, go ahead โ but proceed with caution and be very wary about what information you share.
And if youโre less experienced โ if youโre a casual user who is less internet-savvy โ my expert advice is to stay well away. DeepSeek wonโt give you much you canโt get from other chatbots such as ChatGPT or Claude, and it might make your data vulnerable to Chinese cyber criminals and subject to Chinese law.
DeepSeek also raises questions for governments. Efforts to prevent scams and cybercrime often focus on banks, telecommunications companies, and social media platforms โ but what about chatbots?
Mohiuddin Ahmed, Senior Lecturer of Computing and Security, Edith Cowan University
This article is republished from The Conversation under a Creative Commons license. Read the original article.
Observer Voice is the one stop site for National, International news, Editorโs Choice, Art/culture contents, Quotes and much more. We also cover historical contents. Historical contents includes World History, Indian History, and what happened today. The website also covers Entertainment across the India and World.