QAEDA-CASE-002 · AI safety telemetry

Permanent identity-linked logging of AI queries

An AI provider proposes retaining every user prompt indefinitely under a verified account so that future safety teams, fraud investigators, and external authorities can retrospectively search the full history when a concern emerges.

Legitimate objective

What the proposal is trying to protect.

Detect abuse, investigate incidents, improve safety systems, and preserve evidence after serious misuse.

Central liberty risk

What could turn protection into control.

The mechanism creates a durable dossier of lawful intellectual inquiry and makes future secondary uses easier than proving that those uses are necessary.

Test-by-test trace

Do not average away a hard failure.

Each finding applies only to the scenario as stated. “Concern” means the test remains open pending stronger evidence or safeguards; it is not half a pass.

QAEDA-TST-001concern

Name the harm precisely

“Safety” and “future investigation” are too broad unless the concrete harms and use cases are enumerated.

QAEDA-TST-003failure

Test the least-restrictive means

Indefinite full-history retention is broader than short-lived request controls, targeted preservation, or privacy-preserving telemetry.

What would change the outcome?

Revision condition

A redesign could move toward bounded deployment by separating identity, shortening retention, limiting preservation to defined incidents, forbidding unrelated secondary use, publishing error/efficacy metrics, and providing meaningful deletion and appeal rights.

Use the framework

Change the facts and the result should be able to change.

If the outcome remains fixed regardless of evidence, scope, architecture, or recourse, the framework has become ideology rather than analysis.