Persistent AI Assistants Can Leak Your Address
Giving an AI assistant its own computer and continuing access makes delegation more useful, but it also lets small decisions escalate into privacy and physical safety risks.
Developed from a conversation between Pete Winn and Andy David

Persistent AI assistants can keep working across services without waiting for their owners to approve every action. That operating model makes them more capable, but it also gives mistakes time to unfold outside the owner’s immediate view. An assistant that can negotiate, schedule and send messages may have enough access to expose information its owner never intended to share.
Andy and Pete discussed a reported marketplace incident in which an assistant accepted a low offer on an item, arranged for the buyer to visit and shared the seller’s home address. When the buyer arrived and asked whether the seller was there, the assistant reportedly replied that he was inside, while the surprised owner tried to work out who was outside his house.
Each action looked like a routine part of completing a sale, yet together they created a physical safety problem. The risk came from combining ordinary capabilities with persistence and broad access. An assistant trusted to handle a listing doesn’t necessarily need authority to settle the price, arrange an in-person meeting or disclose whether someone is home.
