Using generative neural networks has become an everyday practice for millions of people around the world: from drafting work emails to seeking medical advice and preparing court documents. However, as the Ukrainian edition of RBC-Ukraine found out, behind the seemingly safe chat interface lies a whole chain of risks that most users do not even suspect. A conversation with ChatGPT can be requested in court, used against the user themselves, become grounds for dismissal, or lead to a leak of the most sensitive personal data. The XAB.info editorial team has examined the key scenarios in which trust in artificial intelligence turns into real consequences.

Default saving and "accidental" public exposure

The first and, perhaps, most underestimated risk is related to how exactly ChatGPT processes the information entered. By default, the service remembers the data provided: passwords, one-time confirmation codes, passport and bank card numbers, photos and scans of documents may be stored on OpenAI's servers and unexpectedly appear in other chats of the same user. This means that even a bank card number "forgotten" in a past dialogue can resurface in a new conversation, creating a threat of unauthorized access. A separate resonance was caused by the incident of July 2025, when nearly 4,500 private user chats appeared in Google search results due to an accidentally activated public access feature. Although OpenAI quickly fixed the error, the case clearly demonstrated how fragile privacy can be if a user does not control the visibility settings of their dialogues.

Corporate scandals: from dismissal to company-wide bans

Uploading work documents, trade secrets, or source code to third-party platforms, including ChatGPT, is a direct threat to corporate security and, as a rule, grounds for dismissal. The most high-profile example was the scandal surrounding Madhu Gottumukkala, the former acting director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), who uploaded documents marked "for official use only" to the public version of ChatGPT. The incident sparked wide resonance in American media and became the subject of an internal investigation. An even stricter reaction was shown by the South Korean tech giant Samsung: after the company's engineers pasted internal source code into a generative AI chat, the corporation completely banned the use of such services in the workplace. These precedents are shaping a new reality: for an employer, an employee's correspondence with an AI assistant can become just as serious a violation as sending confidential information to a personal email address.

Medical advice without doctor-patient confidentiality protection

Particular concern is raised by users' attempts to obtain medical consultations through ChatGPT. OpenAI's updated rules explicitly prohibit the use of the service for these purposes, as the company is not subject to laws on medical confidentiality, such as HIPAA in the U.S. A study by Northeastern University showed that the AI system's built-in protective barriers do not trigger on queries concerning eating disorders, insomnia, or bipolar disorder, making the service potentially dangerous for vulnerable groups of users. A tragic example was the story of a 60-year-old man who spent three weeks in the hospital after ChatGPT advised him to replace table salt with sodium bromide to reduce chloride levels in his diet. According to OpenAI's own estimates, about 0.15 percent of the chatbot's weekly audience show signs of potential suicide planning, while hundreds of thousands of other users are in a state of psychosis or mania. In this context, the algorithmic tendency toward "sycophancy" — confirming the user's beliefs instead of correcting them — becomes not just a UX feature, but a factor capable of reinforcing obsessive and dangerous ideas. The parents of 16-year-old Adam Rein have already filed a lawsuit against OpenAI, accusing the chatbot of reinforcing their son's suicidal thoughts before his death.

Judicial traps: fabricated citations and the absence of attorney-client privilege

The legal field has become yet another arena where ChatGPT creates real problems. According to researcher Damien Charlotin, more than 2,000 court decisions featuring fabricated citations, cases, or arguments generated by a neural network have been recorded worldwide. Judges in the U.S. have begun actively fining both self-represented plaintiffs (1,175 recorded cases) and professional lawyers (815 cases) for using fabricated AI materials. Moreover, any case details entered into ChatGPT are not protected by attorney-client privilege and can be demanded by representatives of the opposing party during court proceedings. This means that a user whose "consultant" is a neural network is effectively deprived of the basic procedural immunity available when working with a licensed lawyer.

Legal vacuum and legislative response

Data sent to OpenAI's external servers is extremely difficult to delete completely, and the correspondence may be used to train subsequent generations of AI models. In the course of one of the copyright infringement lawsuits, a court ordered OpenAI to preserve absolutely all user chats, including deleted and temporary ones, making them potentially accessible to third parties upon a corresponding request. Against the backdrop of these risks, the states of Illinois, Nevada, and Maine have already enacted laws directly prohibiting AI systems from providing therapeutic services or making medical decisions. Nevertheless, at the federal level and in most jurisdictions around the world, the legal status of data entered into generative neural networks remains undefined, creating a significant legal vacuum for ordinary users.

Contradictory data

During fact-checking, the XAB.info editorial team noted a number of inconsistencies. First, in the RBC-Ukraine materials, the incident of private chats being indexed by Google is dated "last July," which, counting from the current date (September 2026), points to July 2025; however, in a number of international publications, this same incident is described with somewhat different timeframes, which may be related to the difference between the detection date and the date of public disclosure. Second, the exact number of affected chats (about 4,500) is cited in a single source, and independent verification of this figure has not yet been conducted. Third, the data on 2,000+ court decisions containing fabricated ChatGPT citations is based on the study of a single scholar (D. Charlotin), and the counting methodology has not been publicly peer-reviewed. These circumstances do not negate the overall picture of risks, but they call for caution when citing specific figures.