<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: The AI Downside</title>
    <description>The latest articles on DEV Community by The AI Downside (@theaidownside).</description>
    <link>https://dev.to/theaidownside</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4079131%2F3d2499bc-d374-4ad6-a1cf-afb555445fee.png</url>
      <title>DEV Community: The AI Downside</title>
      <link>https://dev.to/theaidownside</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/theaidownside"/>
    <language>en</language>
    <item>
      <title>Claude Keeps Going Down, and Anthropic's Own Status Page Says So</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Fri, 04 Sep 2026 23:04:51 +0000</pubDate>
      <link>https://dev.to/theaidownside/claude-keeps-going-down-and-anthropics-own-status-page-says-so-29mc</link>
      <guid>https://dev.to/theaidownside/claude-keeps-going-down-and-anthropics-own-status-page-says-so-29mc</guid>
      <description>&lt;p&gt;Open Claude on a weekday in August 2026 and there’s a fair chance you’ll meet a spinner, an error, or the words “server is busy” where an answer should be. It might be Claude Code stalling mid-task, the app refusing to load a chat, or the API throwing elevated error rates at whatever you built on top of it. You are not imagining it, and you don’t have to take our word for it: the receipts are on Anthropic’s own status page.&lt;/p&gt;

&lt;p&gt;Answer first, because the shape of this is simple and the excuses are not. Claude has had a genuinely rough month. By Anthropic’s own count on &lt;a href="https://status.claude.com" rel="noopener noreferrer"&gt;status.claude.com&lt;/a&gt;, there were roughly twenty separate incidents in the first twenty-four days of August — degraded performance, elevated errors, and a couple of outright service disruptions — and as we hit publish on the 24th, a fresh one marked “major” was still unresolved, taking claude.ai, the API, Claude Code and Cowork down together. That is close to an incident a day. The reason it matters isn’t that software sometimes breaks; everything breaks. It’s who pays for it, and how.&lt;/p&gt;

&lt;p&gt;We should say up front that Anthropic does a lot right here, and we’ll give it that in full below. A public, granular status page is more honesty than much of the industry offers, and most of these incidents were short. But “short and frequent” is still a pattern, and when you’re paying for a tool with a metered allowance, the frequency is the problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the status page actually shows
&lt;/h2&gt;

&lt;p&gt;The spine of this piece is a primary source, which is how we like it. Anthropic’s status history for August 2026 reads like a metronome: 3 August, elevated errors on Sonnet 5; 4 August, elevated errors across many models; 5 August, degraded performance for multiple models for the best part of a working day; 12 August, degraded performance again; 13 August, elevated errors across Mythos 5, Fable 5 and Sonnet 5; 14 August, two “service disruption” incidents in one day; 16 August, a disruption logged at the most severe “critical” level; 17, 18 and 19 August, more degraded performance, repeatedly naming Opus 5; 20 August, another burst of elevated errors. Then the 24th, and the one that is still open as we write.&lt;/p&gt;

&lt;p&gt;That live incident is worth quoting precisely, because the breadth is the point. Anthropic titled it “Elevated errors for multiple models”, began investigating at 05:06 UTC, and within the hour reported it had “identified the cause of elevated errors on requests to Claude Mythos 5, Claude Fable 5, Claude Opus 5, and other Claude models.” The affected components listed were not niche: claude.ai, the Claude API, Claude Code and Claude Cowork — the front door, the developer platform, the coding tool and the agent workspace, all at once. When the failure spans every surface, there’s nowhere for a paying user to route around it.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Around twenty incidents in twenty-four days is not bad luck, and it isn’t a scandal either. It’s a reliability problem, documented by the company itself, that its paying customers are absorbing in lost time and lost quota.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why a “degraded” day costs you twice
&lt;/h2&gt;

&lt;p&gt;Here is the detail that turns an engineering story into a consumer one. Claude’s paid plans don’t sell you unlimited use; they meter it, against a rolling five-hour window and a weekly cap. We’ve written before about how &lt;a href="https://theaidownside.com/posts/claudes-rate-limits-are-still-confusing.html" rel="noopener noreferrer"&gt;Claude’s rate limits are hard to reason about at the best of times&lt;/a&gt;. Now layer an unreliable service on top. When the system is overloaded, a request can still draw down your allowance and then fail — you pay the toll and don’t cross the bridge.&lt;/p&gt;

&lt;p&gt;Users are describing exactly that. On r/ClaudeAI on 24 August, one poster totted up the damage under the title “23% of 5-hour limit for ‘server is busy’”: “I can wait, but the fact that it Ate up my tokens is wild. 3 prompts and I have to wait 4 more hours.” Another, on the same day, said Claude had “been down for 2 hours now.” We can’t audit any one person’s meter, and we present these as user reports rather than measurements — but the mechanism they describe is real and by design: a fixed budget spent on failed requests is gone whether or not you got anything back. That is the difference between an outage on a free product and an outage on a metered subscription. On the free tier you lose time; on the paid tier you lose time and money.&lt;/p&gt;

&lt;p&gt;This is why an outage lands differently on a paid plan than a free one, and why it belongs in the same file as every other way &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;a flat-looking AI plan quietly behaves like a meter&lt;/a&gt;. You didn’t buy a fixed number of answers; you bought a fixed number of &lt;em&gt;attempts&lt;/em&gt;, and a flaky service spends some of them for you. On a good week that’s invisible. In a month of near-daily incidents, it’s the difference between a weekly limit you’d never reach and one you keep bumping into for reasons that have nothing to do with how much work you actually got done.&lt;/p&gt;

&lt;h2&gt;
  
  
  The timing: a flagship, then a wobble
&lt;/h2&gt;

&lt;p&gt;Context matters, and the calendar is suggestive without being conclusive. Anthropic launched Claude Opus 5 on 24 July 2026, its new premium flagship. The reliability run we’re describing began within weeks and repeatedly named Opus 5 among the affected models. It is reasonable to read that as capacity strain: a new, heavier, more capable model lands, demand surges, and the plumbing groans. It is not proof of one, and Anthropic hasn’t published a root-cause, so we won’t assert a motive or a mechanism the company hasn’t confirmed. We’ll say only what the record supports: the flagship shipped, and the month after it, the service kept stumbling.&lt;/p&gt;

&lt;p&gt;This is a familiar tension in the frontier race, and not unique to Anthropic. The incentive is to ship the biggest new model on the fastest cadence, and reliability is the quiet variable that gets traded against it — the thing that doesn’t make the launch video. We made a version of this argument when &lt;a href="https://theaidownside.com/posts/openai-outages-are-now-a-pattern.html" rel="noopener noreferrer"&gt;OpenAI’s outages stopped being news and became a pattern&lt;/a&gt;; the uncomfortable point is that it now applies to the lab most associated with caution. When the whole industry optimises for capability-per-launch, the customer experiences it as capability that isn’t always there.&lt;/p&gt;

&lt;h2&gt;
  
  
  The steel-man, in full
&lt;/h2&gt;

&lt;p&gt;Now the genuinely fair part, because there is a lot of it. First, transparency: Anthropic runs a detailed public status page, posts incident-by-incident updates with timestamps, and doesn’t hide behind a vague “some users may experience issues.” This entire article is built from data the company published about itself, which is exactly the accountability we keep asking the industry for. Credit where it’s due.&lt;/p&gt;

&lt;p&gt;Second, severity. Most of the August incidents were “degraded performance” or “elevated errors” lasting well under a couple of hours, not multi-day blackouts. A slow or flaky Claude is maddening, but it is not the same as a service that vanishes for a week. Third, the underlying difficulty is real: serving a state-of-the-art model to a stampede of users, many of them running long agentic coding sessions that hammer the API, is a hard operational problem, and no lab has solved it perfectly. If you want the biggest model in the world on tap, some of this is the cost of the frontier.&lt;/p&gt;

&lt;p&gt;Concede all of that, and the criticism doesn’t vanish; it just gets more precise. Reliability isn’t a bonus feature layered on top of a subscription — for a professional tool it &lt;em&gt;is&lt;/em&gt; the product, alongside the honest limits you were sold. A month of near-daily incidents, with a metering system that can bill you for the failures, is a real degradation of the thing people pay for, however transparently it’s logged. The status page is the receipt, not the remedy.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do
&lt;/h2&gt;

&lt;p&gt;If you rely on Claude and August has been painful, the practical moves are undramatic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Check the primary source, not your vibes.&lt;/strong&gt; Before assuming it’s you, open &lt;a href="https://status.claude.com" rel="noopener noreferrer"&gt;status.claude.com&lt;/a&gt;. If a component is amber or red, it’s Anthropic’s outage, not your prompt.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Don’t burn quota into a busy server.&lt;/strong&gt; If you’re getting “server is busy” or errors, stop retrying in a loop — on a metered plan, each attempt can cost you. Wait for the status page to go green.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep a fallback ready.&lt;/strong&gt; If your work is critical, don’t single-home it on one model’s uptime. A second tool you can switch to for an hour is cheaper than a lost afternoon.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log it, for yourself.&lt;/strong&gt; If failed requests are eating your limit, note the dates and times against the public incident history. If you ever ask about a refund or credit, “your own status page shows a major incident during my failed session” is a stronger position than a feeling.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of this is a call to cancel, and none of it is a claim that Anthropic acted in bad faith. It’s a plainer observation: for a few weeks in August 2026, one of the most trusted tools in AI kept falling over, its own status page kept the tally, and the people best placed to notice were the ones paying for it by the week. The company that documents its failures this openly is also the one best placed to fix them — and the honest measure of whether it’s working won’t be the next launch, but a September where the status page is boringly green.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/why-claude-keeps-going-down.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>anthropic</category>
      <category>claude</category>
      <category>ratelimits</category>
      <category>reliability</category>
    </item>
    <item>
      <title>The AI Video Squeeze: Credit Traps, Silent Refusals and Disposable Tools</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Thu, 03 Sep 2026 23:20:04 +0000</pubDate>
      <link>https://dev.to/theaidownside/the-ai-video-squeeze-credit-traps-silent-refusals-and-disposable-tools-3oh3</link>
      <guid>https://dev.to/theaidownside/the-ai-video-squeeze-credit-traps-silent-refusals-and-disposable-tools-3oh3</guid>
      <description>&lt;p&gt;For a year now, the people complaining loudest about AI have been the chatbot and coding crowd: vanishing limits, silent model downgrades, a flat plan quietly behaving like a meter. This week the microphone passed to a different room. The people who make AI &lt;em&gt;video&lt;/em&gt; — Runway, Sora, Kling, the churn of open models behind them — spent the week documenting their own version of the squeeze, and it turns out the complaints rhyme almost exactly. Only the currency is different. Where the coding crowd counted tokens, the video crowd counts credits, and this week they watched them evaporate.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Quotes sourced from:&lt;/strong&gt; Reddit (r/runwayml, r/SoraAi and r/KlingAI_Videos). Every quote below was read verbatim on the live thread and is listed with its username, subreddit and the thread’s date and permalink in the Sources section. We widened the window to the last week, because two days was thin, and we dropped a couple of “complaints” that were really adverts for rival tools. As always, we quote experiences, not verdicts — a forum comment is one creator’s account, often mid-project — and what makes this batch worth reading isn’t volume; it’s that the complaints are specific enough to check.&lt;/p&gt;

&lt;h2&gt;
  
  
  “70% of my credits in one go”: the credit trap
&lt;/h2&gt;

&lt;p&gt;The dominant theme was the same one that has dogged AI subscriptions all year, translated into credits: you pay, and the allowance disappears faster and more mysteriously than the pricing page implied. On a thread bluntly titled “Does signing up feel like getting ripped after 10mins?”, a user posting as &lt;strong&gt;thommo1058&lt;/strong&gt;, on 22 August, described the experience of a new customer:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I set up a short 15sec vid. It uses 70% of my credits in one go. Then I realise they have led me to the most expensive AI model. Ok, so they shafted me, but I don’t get it. You don’t keep customers doing that. You just create a bad taste in the mouth.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The specific figure matters less than the shape: a default nudges you toward the priciest model, and by the time you understand the credit maths, most of your allowance is gone. In the same thread, &lt;strong&gt;Hazrd_Design&lt;/strong&gt; caught the other half of it — the iteration tax, where every retry costs you and quality is a lottery:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Spend time crafting the ‘perfect’ prompt. Get crap. Okay well let me adjust the prompt. Crap. Again. Wow finally. Ok next scene. Oh out of credits… on my unlimited plan… day one….”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;“Out of credits on my unlimited plan, day one” is the whole genre in nine words. It’s the video crowd rediscovering, in real time, that &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;a flat plan can quietly behave like a meter&lt;/a&gt; — except here the meter is denominated in a currency whose exchange rate you can’t see until it’s spent.&lt;/p&gt;

&lt;h2&gt;
  
  
  The moan of the day: the agent that spent 9,000 credits without asking
&lt;/h2&gt;

&lt;p&gt;The single sharpest complaint of the week combined the credit problem with a newer one — an “agent” acting on your behalf and spending your money while it does. It goes to &lt;strong&gt;Miko10_&lt;/strong&gt;, on the same 22 August thread, and it’s our moan of the day:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I had the same experience 2 days ago, while chatting with the agent. He proceeded with the generation, without me approving. Boom 9.000 credits gone within 15/20 minutes. And the worst part is they are advertising with free h3 and topaz for max plan users, but I am getting charged for it in tools. I absolutely regret choosing Runway.” — Miko10_, r/runwayml, 22 August 2026&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Set aside whether any single generation was justified. The structural complaint is the one worth keeping: an autonomous feature that can commit your paid resources without a confirmation step turns “convenience” into a liability. Nine thousand credits in twenty minutes, on a generation the user says they didn’t approve, is a new way for a product to cost you money — the video equivalent of a taxi that drives off before you’ve said where you’re going, with the meter already running.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Banned for no apparent reason”: refusals meet the paying creator
&lt;/h2&gt;

&lt;p&gt;Refusals aren’t just a chatbot problem. When a video model blocks a prompt, it also burns the creator’s time and, often, their credits. &lt;strong&gt;headclinic101&lt;/strong&gt;, on 22 August, tied the refusals to a wider pattern of a company that had, in their telling, stopped listening:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Simple prompts get banned and blocked for no apparent reason, customer service is horrendous and their marketing techniques have turned into bait and switch tactics… Even the way they went about phasing out their unlimited plan was weird. It took their customers making an uproar about it for them to finally make an announcement.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Whatever you make of the heat in that comment, the catalogue is the useful part: opaque refusals, poor support, and a plan change users felt was sprung on them. It’s the same grievance that makes &lt;a href="https://theaidownside.com/posts/when-ai-refuses-perfectly-normal-requests.html" rel="noopener noreferrer"&gt;refusals of perfectly normal requests&lt;/a&gt; so corrosive — not the existence of a safety line, but the arbitrariness of where it falls and the bill you pay for hitting it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The disposable tool: churn as a business model
&lt;/h2&gt;

&lt;p&gt;The other half of the week’s mood was impermanence. Loyalty to any one tool feels increasingly pointless when the leaderboard reshuffles every month. &lt;strong&gt;d33roq&lt;/strong&gt;, on 22 August, put the churn plainly:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Runway draws people in with all these cool-seeming shiny new capabilities and marketing but the reality is that they were only ahead of the game for a short time and that was a year and a half ago. Kling, Seedance, etc left Runway in the dust quite a while ago.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;And once the unlimited plan is gone and a rival is ahead, the obvious question is what’s keeping anyone. &lt;strong&gt;Individual-Web7738&lt;/strong&gt;, the same day, asked it directly:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“The last three months — their marketing and attitude — been very shady. Now that unlimited plan no longer exists, wonder how they plan to retain users. What is the incentive?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;You could watch the churn happen live elsewhere on Reddit. The busiest AI-video discussions this week weren’t about any of the big paid apps at all; the top of r/StableDiffusion was a wall of posts about a brand-new model, MiniMax H3, that barely existed a month ago — tutorials, speed hacks, reference-sheet tricks, thousands of upvotes. When the whole community can pivot to a new model in a fortnight, the thing you subscribed to last month is already yesterday’s tool.&lt;/p&gt;

&lt;p&gt;There’s a reason this churn stings more than ordinary competition. In most software, switching costs anchor you in place: your files, your workflow, your muscle memory all make leaving a chore. In AI video the product is largely the model, and the model is a moving target any rival can leapfrog in a single release — so the thing you were loyal to keeps dissolving underneath you. That’s liberating when you’re chasing the best possible output, and quietly infuriating when you’ve just paid a year up front. It also explains the undertone running through these threads: the slow realisation that the tool you committed to was a temporary lead dressed up as a moat, and that the annual plan was the moat working on you rather than for you.&lt;/p&gt;

&lt;h2&gt;
  
  
  When the model won’t do what you’re paying it to do
&lt;/h2&gt;

&lt;p&gt;Not every complaint was about money; some were about control, which turns into money soon enough when every attempt costs credits. &lt;strong&gt;aradax&lt;/strong&gt;, on 18 August in r/KlingAI_Videos, spent days trying to make a character stay silent, and lost:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“‘Closed mouth,’ ‘not speaking,’ ‘immobile mask,’ motion strength cranked to the floor, image-to-video from stills, and she kept flapping her jaw like she was mid-sentence… When a model has a default you can’t prompt away, it’s usually a cheaper trick to pick a medium where that default reads as correct than to keep burning credits.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That last line is quietly damning. The workaround for a model that won’t obey isn’t a better prompt; it’s redesigning your creative work around the model’s stubbornness, because fighting it costs real money. The tool is supposed to serve the vision; here the vision was bent to fit the tool’s baked-in habits.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sora’s cautionary tale: censorship and the free-tier bill
&lt;/h2&gt;

&lt;p&gt;For a longer view of where this leads, the Sora community offered a post-mortem. &lt;strong&gt;YCiampa482021&lt;/strong&gt;, on 17 August, argued that heavy-handed refusals hastened the tool’s decline:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I think part of what drove users away and what also killed Sora 2 was when they heavily censored it. People would get content violations for no apparent reason, and then there’s the whole Opt Out Policy going out the window.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A reply from &lt;strong&gt;iblamecupid&lt;/strong&gt; supplied the other side of the economics — the reason a generous free tier couldn’t last:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“the compute costs killed it man. not to mention, free tier users abusing the 30 free daily video generations by creating multiple accounts which eventually led to longer wait queues for paid users.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Put those two together and you have the whole tension of consumer AI video in miniature: the free deal that’s too good to survive, the clamp-down that follows, and the users caught in between who feel first spoiled and then squeezed. It’s the video-generation echo of what the coding crowd described in &lt;a href="https://theaidownside.com/posts/voices-the-great-coding-tool-defection.html" rel="noopener noreferrer"&gt;last week’s run of cancelled subscriptions&lt;/a&gt;: the product keeps being redefined after you’ve committed to it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to take from it, fairly
&lt;/h2&gt;

&lt;p&gt;The caveats are real and we’ll state them plainly. These subreddits are self-selecting crowds of heavy users; the contented majority rarely posts; one creator’s session is not a benchmark, and “they shafted me” is a feeling, not an audit. We also binned a couple of comments that were really pitches for rival platforms, because a complaint that ends in a discount code isn’t a complaint. None of these posts proves a company acted in bad faith.&lt;/p&gt;

&lt;p&gt;But notice what kind of complaints these are. They aren’t vibes about AI art being soulless. They’re specific, checkable observations about products: a clip that ate 70% of a balance, an agent that spent 9,000 credits unbidden, prompts blocked without explanation, an unlimited plan retired under pressure, a model that won’t stop animating a mouth. The fixes they imply are boringly reasonable, and they’re the same ones every other kind of AI user keeps asking for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Make the credit meter legible&lt;/strong&gt; — show what a generation will cost &lt;em&gt;before&lt;/em&gt; it runs, and don’t default users into the priciest model.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Never spend a user’s credits without a confirmation&lt;/strong&gt; — an agent that can commit your balance must ask first.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Make refusals explainable&lt;/strong&gt; — if a prompt is blocked, say why, and don’t bill the creator for the failed attempt.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep ‘unlimited’ meaning unlimited&lt;/strong&gt; — or don’t call it that, and give real notice before retiring a plan people budgeted around.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of it is a revolution. It’s the baseline a paying creator is entitled to expect — and the reason these threads keep filling up, and ending in regret, is that for the video crowd it’s now being missed in exactly the ways the chatbot crowd warned about a year ago.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/voices-the-ai-video-squeeze.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>voices</category>
      <category>aivideo</category>
      <category>pricing</category>
      <category>censorship</category>
    </item>
    <item>
      <title>AI Voice-Cloning Scams: The Familiar Voice on the Phone Might Be Software</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Wed, 02 Sep 2026 23:22:17 +0000</pubDate>
      <link>https://dev.to/theaidownside/ai-voice-cloning-scams-the-familiar-voice-on-the-phone-might-be-software-dg0</link>
      <guid>https://dev.to/theaidownside/ai-voice-cloning-scams-the-familiar-voice-on-the-phone-might-be-software-dg0</guid>
      <description>&lt;p&gt;The call comes from a number you don’t recognise, but the voice you do. It’s your daughter, or your father, or your boss, and they’re in trouble — a crash, an arrest, a locked account — and they need money now, and please don’t tell anyone. Every instinct you have is built to respond to that voice. And increasingly, that voice is software.&lt;/p&gt;

&lt;p&gt;Answer first, because this is a topic where the useful information is simple and the panic is not. AI voice cloning has taken a very old confidence trick — the impostor pretending to be a loved one in a crisis — and removed its two big limitations: the need to sound like the person, and the need to do it one call at a time. A short clip of someone’s voice, scraped from a video or a voicemail, is now enough to generate a convincing imitation, and the tools to do it are cheap, fast and barely gated. The good news is that the defence hasn’t changed and doesn’t depend on any clever technology: you verify through a second channel you already trust, and you treat urgency plus secrecy plus money as the tell it has always been.&lt;/p&gt;

&lt;p&gt;This is a piece about a downside that isn’t really the fault of the person being scammed, and mostly isn’t the fault of any single AI company either — but it is a downside the industry helped build, by shipping a genuinely dangerous capability with a consent check you could defeat by clicking “yes.” We’ll be fair about the legitimate uses. We’ll also be clear about who made it this easy.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the trick works now
&lt;/h2&gt;

&lt;p&gt;The mechanism is worth understanding because it explains where the defence has to sit. A voice-cloning model learns the characteristics of a target voice — pitch, timbre, cadence, the little idiosyncrasies — from a sample of that person speaking. With a good model, the sample can be short, and the source is rarely a problem: most of us have put our voice online without thinking, in a story, a reel, a work presentation, a podcast, a gaming stream. From there the scammer types what they want “you” to say, and the clone says it.&lt;/p&gt;

&lt;p&gt;What makes it effective isn’t audio fidelity; it’s theatre. A cloned voice on a brief, panicked call — bad line, background noise, “I’m crying so I sound weird” — doesn’t need to survive forensic analysis. It needs to survive ninety seconds with someone whose heart just dropped. The technology supplies the voice; the scam supplies the fear that stops you thinking. This is why the fix is behavioural: you cannot out-listen a good clone, but you can refuse to act on a single unverified channel.&lt;/p&gt;

&lt;h2&gt;
  
  
  The numbers, and why they undercount
&lt;/h2&gt;

&lt;p&gt;This is not a hypothetical harm, and the official record is now substantial. The US Federal Trade Commission reported that people lost around &lt;strong&gt;$3.5 billion to impostor scams in 2025&lt;/strong&gt;, across more than a million reports — a category that has grown sharply for years. The FBI’s 2025 Internet Crime Report went further and, for the first time in its roughly quarter-century history, tracked AI-related fraud as its own category, logging about &lt;strong&gt;$893 million&lt;/strong&gt; in AI-related losses. Looking ahead, Deloitte’s Center for Financial Services has projected that generative-AI-enabled fraud in the United States could climb from roughly $12 billion in 2023 to &lt;strong&gt;$40 billion by 2027&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Two caveats keep this honest, and they point in opposite directions. Not every impostor scam uses a voice clone — plenty still rely on plain text and stolen details — so the $3.5 billion is not an “AI” figure. But the reported totals are also a floor, not a ceiling: fraud is chronically under-reported, because victims are embarrassed, or don’t realise what hit them, or assume nothing can be done. The people hit hardest are often older; the FBI has reported that Americans over 60 lost several billion dollars to cybercrime in 2025, up sharply on the year before. The direction of travel is not in doubt.&lt;/p&gt;

&lt;h2&gt;
  
  
  It isn’t only the emergency phone call
&lt;/h2&gt;

&lt;p&gt;The cloned-relative call is the most visceral version, but voice synthesis has quietly upgraded a whole family of older cons. In the corporate world it has sharpened “business email compromise”: a faked voicemail or live call from a “CEO” or “CFO” pressuring a finance employee into an urgent wire transfer, where a voice that matches the boss removes the last reason to hesitate. Romance and investment scams use cloned or wholly synthetic voices to make a fictional partner feel real across months of calls. And the “virtual kidnapping” scam — a caller claiming to hold your relative, with screaming in the background — becomes far more effective when the screaming is a convincing copy of a voice you know.&lt;/p&gt;

&lt;p&gt;What unites them is how little the clone has to do. It supplies a single moment of false certainty — yes, that’s really them — at precisely the point where your judgement would otherwise engage. Everything after that is the same social engineering that always worked: authority, urgency, isolation, and a payment method that can’t be clawed back. That is why the FBI now folds voice cloning into a broader category of AI-enabled fraud rather than treating it as a crime of its own: in practice it is an accelerant poured on scams that already existed, making the plausible more plausible and shrinking the window in which a careful person would stop and check.&lt;/p&gt;

&lt;h2&gt;
  
  
  The consent theatre: how the tools ship
&lt;/h2&gt;

&lt;p&gt;Here is where the industry earns its share of the blame, and it’s specific rather than hand-wavy. In 2025, Consumer Reports assessed six voice-cloning products — Descript, ElevenLabs, Lovo, PlayHT, Resemble AI and Speechify — and found that most had no meaningful safeguard against cloning a voice without the owner’s knowledge. Four of them, in the report’s account, “required only that researchers check a box confirming that they had the legal right to clone the voice or make a similar self-attestation.” A tick-box is not a safeguard; it’s a liability shield with a UI.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;A capability that can imitate anyone’s voice from a scrap of audio shipped to the public behind a checkbox that asks, politely, whether you have permission — and takes “yes” for an answer.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It didn’t have to be that way, which is the damning part. The same study noted that safeguards are perfectly practical: one tool asked users to record a specific consent statement that is difficult to fake, and another based a first clone on audio captured live rather than uploaded. Those measures don’t stop a determined criminal, but they add friction exactly where friction belongs. Most vendors chose not to, and a couple went further in the wrong direction, listing “pranks” and “prank calls” among the suggested uses. Consumer Reports’ Grace Gedye put the legal edge on it: “I actually think there’s a good argument that can be made that what some of these companies are offering runs afoul of existing consumer protection laws.” The tools were marketed as a creative gift; the safeguards were treated as optional.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why “detection will fix it” is a deflection
&lt;/h2&gt;

&lt;p&gt;The standard industry answer to synthetic-media harm is that better detection — watermarks, classifiers, provenance signals — will let us tell real from fake. It’s worth wanting, and worth building. It is not a plan you can hand to a frightened parent at 11pm. Detecting cloned audio is an arms race in which every improvement in detection is training data for the next generator, and reliability in real-world conditions — a compressed phone call, background noise — is poor. Worse, detection puts the burden in exactly the wrong place: on the victim, in the moment, expected to run a forensic check on a voice that is telling them their child is hurt.&lt;/p&gt;

&lt;p&gt;We’ve been sceptical before about pushing the labour of authenticity onto the user, whether that’s &lt;a href="https://theaidownside.com/posts/claudes-invisible-watermark-marks-even-your-own-writing.html" rel="noopener noreferrer"&gt;watermarks that mark your own writing&lt;/a&gt; or transparency rules that sound protective and land awkwardly. Provenance and watermarking are genuinely useful upstream, at the point of creation. As a last line of defence for a consumer on a phone call, they are close to useless — which is why the real defence has to be a habit, not a gadget.&lt;/p&gt;

&lt;h2&gt;
  
  
  The second-order harm: when nothing can be trusted
&lt;/h2&gt;

&lt;p&gt;There is a subtler cost beyond the money, and it’s worth naming because it shapes how this gets worse. As convincing fakes become normal, real recordings lose their power too. A genuine voicemail, a real confession, an actual emergency can all be waved away as “probably AI” — the so-called liar’s dividend, where the mere existence of cloning gives everyone plausible deniability. The harm isn’t only that a fake voice can fool you; it’s that a real one can now be dismissed. Trust in the evidence of our own ears, which held for the entire history of the telephone, is being quietly withdrawn, and no one voted for that.&lt;/p&gt;

&lt;p&gt;This is the same drafting-lag problem that runs through the whole field: the rules and instincts we rely on were built for a world where a voice was hard to fake. &lt;a href="https://theaidownside.com/posts/what-ai-regulation-protects-you-from.html" rel="noopener noreferrer"&gt;Regulation is inching toward labelling synthetic media&lt;/a&gt;, and that helps at the margins. But labels govern the honest; they do nothing about a criminal who never intended to label anything.&lt;/p&gt;

&lt;h2&gt;
  
  
  The steel-man: the technology isn’t the villain
&lt;/h2&gt;

&lt;p&gt;To be fair, voice synthesis has real and humane uses, and pretending otherwise would be its own kind of hype-in-reverse. It gives a synthetic voice back to people who have lost theirs to illness; it powers accessibility tools, audiobook narration and dubbing that lets a film cross a language barrier without re-shooting a performance. The underlying research is not sinister, and most fraud combines cloning with old-fashioned social engineering — the voice is one component in a con, not the whole of it. A handful of vendors, as noted, did build sensible consent checks. The problem is not that the capability exists; it is that so much of it was released to the public with the brakes left off.&lt;/p&gt;

&lt;p&gt;That distinction matters for where the pressure should go. The answer isn’t to ban voice AI; it’s to insist that the companies profiting from frictionless cloning carry more of the cost of preventing its obvious misuse — robust consent, provenance by default, rate limits and abuse monitoring — rather than externalising that cost onto whichever grandparent picks up the phone.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually protects you
&lt;/h2&gt;

&lt;p&gt;The reassuring thing is that none of the effective defences require you to understand the technology at all. They’re the same defences that worked against human impostors, tightened for a world where the voice is no longer proof:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Verify on a second channel.&lt;/strong&gt; If “someone you know” calls in a crisis asking for money, hang up and call them back on the number you already have for them. A clone cannot answer their phone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agree a code word.&lt;/strong&gt; Pick a private word or question with close family now, and use it to confirm identity in any emergency call. It costs nothing and defeats a perfect clone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Treat urgency plus secrecy as the alarm.&lt;/strong&gt; “Right now,” “don’t tell anyone,” and “pay by gift card, crypto or transfer” are the fingerprints of a scam, whoever the voice belongs to.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reduce your voice’s public surface.&lt;/strong&gt; You can’t erase yourself, but locking down social accounts and being wary of voice-heavy public posts lowers the odds of being an easy target.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Report it.&lt;/strong&gt; Tell the FTC (in the US) or your national fraud body, even if you didn’t lose money. Reports are how the scale stays visible and how pressure builds on the tools that enable it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The uncomfortable summary is that a technology sold as a boon for creators arrived in most people’s lives first as a threat — a call in a familiar voice that isn’t real. The fixable part isn’t the science; it’s the gap between “democratising a powerful capability” and “handing out a fraud tool with a checkbox.” Until the companies close that gap, the defence falls to us, and happily the defence is old, cheap and reliable: don’t trust the voice, trust the callback. It is worth teaching to everyone you love before the phone rings.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/ai-voice-cloning-scams.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>safety</category>
      <category>privacy</category>
    </item>
    <item>
      <title>ChatGPT Ads Arrive in Europe, Starting With the Free Tier</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Tue, 01 Sep 2026 23:22:31 +0000</pubDate>
      <link>https://dev.to/theaidownside/chatgpt-ads-arrive-in-europe-starting-with-the-free-tier-58cp</link>
      <guid>https://dev.to/theaidownside/chatgpt-ads-arrive-in-europe-starting-with-the-free-tier-58cp</guid>
      <description>&lt;p&gt;Open ChatGPT in Europe on Monday and, if you’re on the free plan, you may notice something new sitting near the answers: an advertisement. As of 24 August, OpenAI is switching on ChatGPT Ads across 31 European markets — the company’s biggest advertising expansion yet — six months after it began quietly testing the idea in the United States. Free and Go users are in; anyone paying for Plus, Pro or Enterprise is not.&lt;/p&gt;

&lt;p&gt;Answer first, because the shape of this matters more than the noise. This is the moment the “free” AI assistant becomes an ad-supported one for most of Europe, and the detail that will catch people out is the opt-out. You can turn off ad &lt;em&gt;personalisation&lt;/em&gt; — which changes &lt;em&gt;which&lt;/em&gt; ads you see — but you cannot turn off the ads. The only switch that removes them is a paid subscription. To OpenAI’s credit, it has been unusually careful about the privacy design, and we’ll give it that in full. But “free, with ads you can only escape by paying” is a different deal from the one most people signed up to, and it deserves to be read slowly.&lt;/p&gt;

&lt;p&gt;We like a lot of what OpenAI ships, and an ad-funded free tier is a defensible way to keep a genuinely expensive product free. The questions worth asking are narrower: how honest is the opt-out, how private is the targeting really, and what happens the day an advertiser’s interests and your question quietly diverge.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually switches on this week
&lt;/h2&gt;

&lt;p&gt;The facts are not in dispute, because OpenAI announced them itself. In a post dated 18 August, the company wrote: “Six months after we began testing ads in the U.S., we’re bringing ChatGPT Ads to 31 European markets,” naming Germany, France, Spain, Italy, Sweden, Norway, Denmark, the Netherlands and Austria among them, with reporting adding Poland and the Benelux countries. Crucially: “As in our existing markets, ads will be shown only to users on the Free and Go plans. Plus, Pro, and Enterprise subscriptions will remain ad-free.”&lt;/p&gt;

&lt;p&gt;The pilot began in February in the US; OpenAI says it has since expanded to eight further markets, so the European rollout takes the total to around 40. This is not an experiment any more — it is a platform. In the same announcement OpenAI describes the machinery it has built: bidding “beyond CPM and CPC” to support conversion optimisation, plus “geo-targeting and custom audiences” and measurement “through the OpenAI Pixel, Conversions API, and third-party measurement integrations.” If those phrases sound familiar, it’s because they are the standard furniture of the online-advertising industry, now being assembled inside a chatbot.&lt;/p&gt;

&lt;h2&gt;
  
  
  The opt-out that isn’t one
&lt;/h2&gt;

&lt;p&gt;Here is the line most coverage skated over, in OpenAI’s own words: “People also have control over ad personalization, with ad-free paid plans available for those who prefer not to see ads.” Read that twice. Personalisation control changes the &lt;em&gt;relevance&lt;/em&gt; of the ads. The &lt;em&gt;absence&lt;/em&gt; of ads is a separate thing, available only on the paid plans. So the honest translation of “you’re in control” is: you may choose between ads tailored to you and ads not tailored to you, and if you want no ads at all, that will be €23 a month for Plus.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Turning off personalisation changes which ads you see, not whether you see them. The only setting that removes the ads is your credit card.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;None of this is hidden — it’s stated plainly — but it’s the kind of plainly-stated thing that a hurried user reads as “I can switch ads off,” when what they can switch off is the tracking that makes ads relevant. It is a familiar move: give the user a real control that sits next to the control they actually wanted, and let the resemblance do the work. If you object to ads on privacy grounds, the personalisation toggle helps; if you object to ads on principle, only the subscription does.&lt;/p&gt;

&lt;h2&gt;
  
  
  The privacy stance, taken seriously
&lt;/h2&gt;

&lt;p&gt;Now the genuinely good part, because there is one and it would be unfair to skip it. OpenAI has not built the surveillance-advertising model that hollowed out the rest of the web. Its VP of Ads, Dave Dugan, has said plainly that advertisers “will not have access to users’ chat histories” and that “information from conversations would not be shared with advertisers.” The company’s announcement adds that it keeps “conversations private from advertisers and never sell[s] customer data,” that ads are “always clearly labeled and separate from ChatGPT’s answers,” and that “advertising does not influence the answers ChatGPT provides.”&lt;/p&gt;

&lt;p&gt;Compared with the ordinary bargain of the ad-funded internet — where your behaviour is the product and the line between content and advertising is deliberately smudged — that is a materially better starting point, and we’ll say so. A labelled, separated ad that doesn’t hand your transcript to a media buyer is about as good as advertising gets. If OpenAI holds that line, this could be one of the less objectionable ad businesses in tech.&lt;/p&gt;

&lt;p&gt;The caveat is the word “if”, and the stack described above. “Ad personalisation,” conversion optimisation and custom audiences all require the system to know something about you to work; the promise is that advertisers never touch it, not that no profile exists. That’s a real distinction and a reassuring one — but it depends entirely on OpenAI’s internal discipline holding as the commercial pressure to make the ads perform grows. The history of advertising businesses is a history of that discipline eroding one quarter at a time, which is exactly why &lt;a href="https://theaidownside.com/posts/why-every-ai-wants-your-data.html" rel="noopener noreferrer"&gt;every AI is so hungry for your data&lt;/a&gt; in the first place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a sponsored answer is harder to spot than a sponsored link
&lt;/h2&gt;

&lt;p&gt;The deeper worry isn’t the banner-style ad OpenAI is shipping now; it’s the medium. A chatbot answers in a single, confident, conversational voice, and that voice is the most persuasive real estate on the internet. A sponsored &lt;em&gt;link&lt;/em&gt; announces itself as an ad. A recommendation that arrives “in the same conversational tone” as the surrounding answer — the phrase researchers quoted to Euronews used — is harder to recognise as persuasion. OpenAI says today that advertising “does not influence the answers”; the line to watch, for years, is whether that wall between the answer and the ad stays load-bearing.&lt;/p&gt;

&lt;p&gt;We’ve made this argument about search and it applies double here. The reason &lt;a href="https://theaidownside.com/posts/why-ai-search-is-making-google-worse.html" rel="noopener noreferrer"&gt;answer engines keep drifting toward the same cliff as search&lt;/a&gt; is that once you need to monetise a single answer, the pressure to shape it — to favour a partner, to slip a sponsored recommendation into what reads as neutral synthesis — is precisely the pressure that degraded the thing they set out to replace. OpenAI is starting from a better place than most. But it is starting down the same road.&lt;/p&gt;

&lt;h2&gt;
  
  
  Europe is the hardest place to try this
&lt;/h2&gt;

&lt;p&gt;There is a reason a European rollout is more fraught than an American one. The EU AI Act specifically prohibits AI systems that use manipulative or deceptive techniques to distort behaviour, or that exploit people’s vulnerabilities — and a persuasive conversational agent that also carries ads is, at minimum, a system regulators will look at closely. Separately, the European Commission has been weighing whether ChatGPT’s search function should count as a “very large online search engine” under the Digital Services Act, a designation that would bring audit and ad-transparency obligations. Launching an ad business into that environment is a statement of confidence; it is also an invitation to scrutiny that a purely US product never faced.&lt;/p&gt;

&lt;p&gt;To be fair, this cuts both ways: Europe’s rules are exactly why OpenAI’s careful, no-selling-data, clearly-labelled design is the sensible way to enter, and the company seems to know it. The regime that makes the launch risky is also the regime most likely to keep it honest.&lt;/p&gt;

&lt;h2&gt;
  
  
  The steel-man: someone has to pay for the free lunch
&lt;/h2&gt;

&lt;p&gt;The strongest case for OpenAI is simple and true. Running ChatGPT for hundreds of millions of free users costs a fortune, and the alternatives to advertising are worse for most people: charge everyone, or degrade the free tier until it’s useless. Ads that fund genuine free access — while leaving paid tiers clean — are a reasonable way to keep a powerful tool in the hands of people who won’t or can’t pay. OpenAI’s framing, that ads “support free and low-cost access,” is not spin; it’s the actual economic logic, and it’s the same logic that kept web search free for two decades.&lt;/p&gt;

&lt;p&gt;Concede all of it, and the objection just gets sharper. It isn’t “OpenAI shouldn’t run ads.” It’s that the free user pays in two coins at once — attention and, via personalisation, a profile — while the cleanest way to escape both is to start paying money. That’s a coherent business, but it’s also the quiet conversion of a free product into a funnel, and it belongs in the same story as &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;every other way an AI plan is being re-priced after you committed to it&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do
&lt;/h2&gt;

&lt;p&gt;If you use ChatGPT in one of the affected markets, the practical steps are undramatic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Know which tier you’re on.&lt;/strong&gt; Ads reach Free and Go users only; Plus, Pro and Enterprise stay ad-free. If you already pay, nothing changes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Turn off personalisation if you value privacy over relevance.&lt;/strong&gt; It won’t remove the ads, but it limits the profiling behind them — a real, if partial, win.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Treat the paid tier as the ad-removal product it now is.&lt;/strong&gt; If ads bother you on principle, that’s what the subscription buys; decide whether it’s worth it rather than expecting a free switch.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Be sceptical of product recommendations inside answers.&lt;/strong&gt; For now ads are labelled and separate. Keep noticing where the label is, and treat any purchase suggestion woven into an answer with the same caution you’d give a sponsored search result.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;OpenAI has done this about as decently as an ad launch can be done: no selling your data, no handing advertisers your chats, ads that are labelled and kept apart from the answers, and paid tiers left clean. That is worth acknowledging, and it sets a bar the rest of the industry should be held to. The fixable fault is the smaller one — an “opt-out” that opts you out of relevance rather than ads, and a free tier that now quietly runs on your attention. The bargain isn’t outrageous. It’s just no longer the one on the box, and Europe, of all places, is where that difference will be tested.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/chatgpt-ads-come-to-europe.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>chatgpt</category>
      <category>privacy</category>
      <category>pricing</category>
    </item>
    <item>
      <title>'The Claude Pro Is Consumed Within an Hour': A Week of Coding-Tool Defections</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Tue, 01 Sep 2026 00:40:43 +0000</pubDate>
      <link>https://dev.to/theaidownside/the-claude-pro-is-consumed-within-an-hour-a-week-of-coding-tool-defections-35ba</link>
      <guid>https://dev.to/theaidownside/the-claude-pro-is-consumed-within-an-hour-a-week-of-coding-tool-defections-35ba</guid>
      <description>&lt;p&gt;Some weeks the complaints about AI are existential. This one they were arithmetic. Scroll Hacker News over the past week — the forum where developers argue about their tools in unusual detail — and the grievances about AI coding assistants weren’t about the models being dangerous. They were about limits running out, bills that don’t add up, models quietly swapped underneath you, and a desktop app eating memory like a browser. And the recurring move wasn’t outrage. It was switching.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Quotes sourced from:&lt;/strong&gt; Hacker News. Every quote below was located at its comment permalink and reproduced verbatim; each is listed with its username, the platform and the date in the Sources section. As always, we quote experiences, not verdicts — a forum comment is one practitioner’s account, often mid-argument, and we’ve framed them as exactly that. What makes this batch worth reading isn’t volume; it’s that the complaints are specific enough to check, and that they keep ending the same way: with a cancelled subscription.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Consumed within an hour”: the limits gripe
&lt;/h2&gt;

&lt;p&gt;The loudest theme by far was paid usage limits that vanish faster than the price suggests. On a thread bluntly titled “Quick impressions: A week of using Codex more than Claude,” a user posting as &lt;strong&gt;jmaker&lt;/strong&gt;, on 22 August, described dropping his subscriptions around exactly this problem:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“The Claude Pro is consumed within an hour on a simple task.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That’s one account of one plan, but it wasn’t isolated. In the same discussion, &lt;strong&gt;roamerz&lt;/strong&gt; on 21 August traced the arc from happy customer to defector in four sentences:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Then one day I burned through my limit in about 10 minutes and had to get a project completed. I subscribed to Codex and it has been fantastic… I just dropped my Claude max plan down to the pro and subscribed to the $200 plan on Codex.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The specific number matters less than the shape: a heavy user hits a wall mid-task, and the wall — not the model’s quality — is what sends them to a competitor. It’s the lived version of the drift we keep documenting, in which &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;a flat subscription quietly behaves like a meter&lt;/a&gt;, and the meter is the thing you notice.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Cannot be trusted”: when the meter loses the room
&lt;/h2&gt;

&lt;p&gt;Underneath the individual complaints ran a deeper one: not that the limits are tight, but that they’re illegible — you can’t predict them, so you can’t trust them. &lt;strong&gt;johnnyApplePRNG&lt;/strong&gt;, on 20 August, put it as a flat recommendation to route around the whole model:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Claude and Codex usage limits cannot be trusted. Paying your own API bills in full is superior.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That’s an opinion, not an audit, and plenty on the same site would push back. But “cannot be trusted” is a precise diagnosis of a real problem: when a subscriber can’t see how a limit is measured or when its practical value shifts, the number on the plan stops meaning anything. A limit you can’t predict is functionally a limit you don’t have — and it pushes exactly the technical users these companies most want to keep towards paying per token, where at least the maths is visible.&lt;/p&gt;

&lt;p&gt;It’s worth sitting with why illegibility, specifically, drives people out. A tight limit you can see is just a constraint; you plan around it, front-load the heavy work, and get on with your day. An invisible one is different in kind, because it makes planning itself impossible — you can’t tell whether the next prompt costs one percent of your week or thirty, so every session carries a low hum of anxiety about hitting a wall mid-task. Developers are unusually intolerant of that particular feeling, because their whole job is making systems predictable. Ask them to work on top of a resource whose cost they can’t model, and a fair number will simply move to the option that lets them see the meter — even if that option is nominally more expensive. Predictability, it turns out, is a feature people will pay to get back.&lt;/p&gt;

&lt;h2&gt;
  
  
  The moan of the day: paying to be told no
&lt;/h2&gt;

&lt;p&gt;The single sharpest complaint of the week managed to combine three grievances — a silent downgrade, a refusal, and a bill — into one experience. It goes to &lt;strong&gt;matheusmoreira&lt;/strong&gt;, on 21 August, and it’s our moan of the day:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Sometimes Fable doesn’t just get downgraded to Opus, it straight up refuses to do what I’m asking and starts lecturing me on Anthropic’s notions of right and wrong. Cutting the model off wasn’t enough, they had to make it burn the limited usage I paid for lecturing me on why it’s immoral for it to code review my own project or whatever.” — matheusmoreira, Hacker News, 21 August 2026&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Set aside whether any single refusal was justified — models draw safety lines, and reasonable people disagree about where. The structural complaint is the one worth keeping: the cost of the refusal lands on the user twice, once as the blocked task and once as the quota spent being &lt;a href="https://theaidownside.com/posts/when-ai-refuses-perfectly-normal-requests.html" rel="noopener noreferrer"&gt;refused and lectured&lt;/a&gt;. Paying for a “no,” delivered at length, is a genuinely new way for a product to disappoint you.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Neverending dance”: the pattern named
&lt;/h2&gt;

&lt;p&gt;Some commenters zoomed out from a single session to the whole texture of it. &lt;strong&gt;eknkc&lt;/strong&gt;, on 20 August, catalogued the grievances as a list of moves rather than a single incident:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Decisions on hidden downgrades, subscription usage restrictions, account bans, neverending dance around model availability on subscription plans.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Whatever you make of the heat elsewhere in that comment, the catalogue itself is the useful part, because each item is a small, unannounced transfer of control away from the user: which model you get, how much you get, whether your access survives — all decided upstream, and changed without a memo. It’s the same complaint that makes &lt;a href="https://theaidownside.com/posts/voices-you-paid-for-the-big-model.html" rel="noopener noreferrer"&gt;“you paid for the big model and got the small one”&lt;/a&gt; such a durable grievance: the thing you bought keeps being redefined after you bought it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cancelling, out loud
&lt;/h2&gt;

&lt;p&gt;What made this week different from the usual grumbling was how many comments ended in a cancellation. &lt;strong&gt;vzaliva&lt;/strong&gt;, on 18 August, wrote an epitaph for a subscription many readers will recognise:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I’ve finally cancelled my Cursor subscription. It was an interesting product, but the fact that most interesting features only work with per-token pricing, not Cursor and Codex subscriptions, is a bummer.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;maxdo&lt;/strong&gt;, the same day, did the competitive maths out loud, addressing a vendor directly:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“since grok 4.6 and codex, it’s just stupid to go with your pricing model… Why should I pay you money, and have slower model and less intelligence?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;These are opinions, and switching costs mean not everyone will follow through. But the direction is consistent, and it’s the direction that should worry a subscription business: not angry churn over a scandal, just a steady, reasoned drift to whichever tool offers more predictable value this month. When the loudest power users are comparison-shopping in public, the lock-in the whole model depends on is leaking.&lt;/p&gt;

&lt;h2&gt;
  
  
  The app itself
&lt;/h2&gt;

&lt;p&gt;Not every complaint was about money. A couple were about the plain software quality of tools built by the best-resourced engineering teams on earth. &lt;strong&gt;chvid&lt;/strong&gt;, on 22 August, had a memory gripe that needs no interpretation:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“ChatGPT MacOSX is the only software that regularly crashes on my machine when its memory consumption for no apparent reason spins up towards 50 GB.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;There’s something bracing about that complaint sitting next to all the talk of frontier models and trillion-dollar valuations: the actual daily experience is a chat client that can’t manage its own memory. It’s a useful reminder that the model and the software wrapped around it are different products, and a brilliant one can arrive inside a shoddy other one. And for all the loyalty on display, some users are voting with their prompts. &lt;strong&gt;fractalf&lt;/strong&gt;, on 22 August, described defecting mid-task and being pleasantly surprised:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I switched to Deepseek for a task lately. It was a wow experience (the language part).”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Step back and the week’s complaints rhyme. A limit consumed in an hour, a meter you can’t trust, a downgraded model that bills you for refusing, a subscription cancelled because the good features moved to per-token pricing, an app that eats 50&amp;nbsp;GB for no reason. None is a catastrophe alone. Together they describe a class of product that keeps making unilateral decisions about your money, your model and your machine — and a user base, the most technical one these companies have, quietly working out that it can take its spend elsewhere. That texture, not any single scandal, is what these threads are really documenting.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to take from it, fairly
&lt;/h2&gt;

&lt;p&gt;The caveats are real and we’ll state them plainly. Hacker News is a self-selecting crowd of technical sceptics; the contented majority rarely posts; one developer’s session is not a benchmark, and one person’s “cannot be trusted” is another’s productive Tuesday. None of these comments proves a company acted in bad faith.&lt;/p&gt;

&lt;p&gt;But notice what kind of complaints these are. They aren’t vibes about AI being scary. They’re specific, checkable observations about products: a plan exhausted in an hour, a model swapped without notice, a refusal that spends your quota, an app that leaks memory. The fixes they imply are boringly reasonable, and they’re the same ones the people who use &lt;a href="https://theaidownside.com/posts/ai-coding-assistants-and-the-myth-of-the-10x-developer.html" rel="noopener noreferrer"&gt;these coding tools all day&lt;/a&gt; keep asking for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Make the meter legible&lt;/strong&gt; — show, in advance, what a task will cost against my limit, so “trust” isn’t required.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Don’t swap my model silently&lt;/strong&gt; — if I’m downgraded, tell me, and don’t bill me for the downgraded model’s refusals.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep subscription value in the subscription&lt;/strong&gt; — don’t quietly move the good features to per-token pricing and leave the plan a shell.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ship an app that works&lt;/strong&gt; — the best-funded engineering teams alive can manage a text client that doesn’t need 50&amp;nbsp;GB of RAM.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of it is a revolution. It’s the baseline a paying user is entitled to expect — and the reason these threads keep filling up, and ending in cancellations, is that it keeps not being met.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/voices-the-great-coding-tool-defection.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>voices</category>
      <category>claude</category>
      <category>ratelimits</category>
      <category>pricing</category>
    </item>
    <item>
      <title>Can You Get Your Data Out of an AI Tool? The Right Exists on Paper, the Button Usually Doesn't</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Sun, 30 Aug 2026 23:35:44 +0000</pubDate>
      <link>https://dev.to/theaidownside/can-you-get-your-data-out-of-an-ai-tool-the-right-exists-on-paper-the-button-usually-doesnt-23mk</link>
      <guid>https://dev.to/theaidownside/can-you-get-your-data-out-of-an-ai-tool-the-right-exists-on-paper-the-button-usually-doesnt-23mk</guid>
      <description>&lt;p&gt;Sooner or later an AI tool will take something back. A feature you used gets &lt;a href="https://theaidownside.com/posts/microsoft-copilot-strips-free-features.html" rel="noopener noreferrer"&gt;retired on a deadline&lt;/a&gt;, a plan you were on gets restructured, or you simply decide to leave — and you go looking for the export button so you can carry your history, your chats, the reports and images the thing made for you, somewhere else. Often, there isn’t one. And when you reach for the law instead, you find something stranger than a flat “no”: a right that half-fits, written for a world before chatbots.&lt;/p&gt;

&lt;p&gt;Answer first. In much of the world you do have a legal right to a copy of your personal data, and in the EU a right to have it ported to another service. But that right was drafted around the data you hand over and the data a service observes about you — not the data an AI infers or generates. Your prompts are on firm ground; the model’s outputs, your embeddings, the profile built from your behaviour are on much shakier ground. And even where the right clearly applies, whether there’s an actual working export is a product decision the law rarely compels. The entitlement is real. The button is optional.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three questions hiding in one
&lt;/h2&gt;

&lt;p&gt;“Can I get my data out” sounds like one question and is really three, which is why the answers feel so slippery.&lt;/p&gt;

&lt;p&gt;The first is &lt;strong&gt;data protection&lt;/strong&gt;: do you have a right to a copy of your personal data, and to move it elsewhere? The second is &lt;strong&gt;ownership&lt;/strong&gt;: who holds the rights — usually copyright — to the things the AI produced for you? The third is the most practical and the least regulated: is there any &lt;strong&gt;plumbing&lt;/strong&gt; — an export feature, a standard format — that lets you actually walk out with the lot? The law has a lot to say about the first, gestures vaguely at the second, and is almost silent on the third. Most people’s frustration lives in the third, which no amount of rights language fixes.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the law actually gives you: GDPR Article 20
&lt;/h2&gt;

&lt;p&gt;The centrepiece is the EU’s General Data Protection Regulation, Article 20, the “right to data portability.” It says you have the right to receive personal data concerning you that you “provided to a controller, in a structured, commonly used and machine-readable format,” and to transmit that data to another controller without hindrance. Crucially, it applies only where two conditions hold: the processing is based on your consent or on a contract, and it is carried out by automated means. Where those apply — and for a consumer AI service you signed up to and use, they generally do — you can ask for your data in a portable form and, where technically feasible, have it sent straight to a competitor.&lt;/p&gt;

&lt;p&gt;Read at face value, that sounds like it should hand you your entire AI history on request. The catch is one word.&lt;/p&gt;

&lt;h2&gt;
  
  
  The word that swallows your AI history: “provided”
&lt;/h2&gt;

&lt;p&gt;Everything turns on what “provided” means, and here the official guidance is both settled and inconvenient. The EU’s data-protection regulators — in the Article 29 Working Party guidelines that still frame how Article 20 is read — split your data into three kinds. Data you &lt;em&gt;actively&lt;/em&gt; gave, like your email or the text of a prompt, is provided, and portable. Data that is &lt;em&gt;observed&lt;/em&gt; as you use the service, like usage logs, search history or location, is also treated as “provided by virtue of the use of the service,” and is portable too. So far, so good.&lt;/p&gt;

&lt;p&gt;But the third kind — &lt;em&gt;inferred&lt;/em&gt; or &lt;em&gt;derived&lt;/em&gt; data, meaning conclusions the provider generates by analysing you — is explicitly excluded. And that third category is exactly where an AI service keeps the interesting things. The embeddings that represent your documents, the behavioural profile that decides what you see, and arguably the model’s own generated outputs are all products of the provider’s analysis, not data you handed over. The portability right reaches your inputs far more reliably than the things the machine made out of them.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The law gives you the clearest claim to the data you typed in, and the weakest claim to what the AI inferred and generated from it — which is precisely the part that feels most like “yours.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is not a loophole someone forgot to close; it’s a deliberate line, drawn to stop portability becoming a backdoor to extract a company’s analytical work. But it was drawn in 2016, for recommendation engines and social feeds, and it lands awkwardly on generative AI, where the “derived data” is a finished report or picture you reasonably think of as your creation. It is the same drafting-lag we see across &lt;a href="https://theaidownside.com/posts/what-ai-regulation-protects-you-from.html" rel="noopener noreferrer"&gt;the wider effort to regulate AI&lt;/a&gt;: the rule is sound for the world it was written for and leaky in the one we’re now in.&lt;/p&gt;

&lt;h2&gt;
  
  
  Portability beyond GDPR — wider, but not deeper
&lt;/h2&gt;

&lt;p&gt;Article 20 isn’t the only tool, and the newer ones widen the picture without quite closing the gap. The &lt;strong&gt;EU Data Act&lt;/strong&gt;, which applies from September 2025, creates fresh portability duties — but its focus is data from connected products and, importantly, the right to switch between cloud providers, not a right to your chatbot creations. The &lt;strong&gt;Digital Markets Act&lt;/strong&gt; forces designated “gatekeeper” platforms to provide effective, continuous, real-time data portability — a strong right, but one aimed at the handful of biggest platforms rather than the AI market generally. And in the United States, &lt;strong&gt;California’s CCPA/CPRA&lt;/strong&gt; grants a right to receive your personal information in a portable and, where feasible, readily usable format — again strongest for the data you supplied.&lt;/p&gt;

&lt;p&gt;Stack them up and the shape is consistent. Several regimes agree you should be able to get your personal data and take it elsewhere. None of them cleanly guarantees that the transcript of your conversations, the images you generated, or the podcasts a tool made for you come out in a form you can actually re-use. The right is real; its edges stop just short of the thing you most want to carry.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually lands in the export
&lt;/h2&gt;

&lt;p&gt;Suppose you clear every hurdle: the right applies, you file the request, the company complies. What arrives is often its own disappointment, and this is the part the rights language never prepares you for. A portability or subject-access request can be satisfied, lawfully, with a data &lt;em&gt;dump&lt;/em&gt; — a ZIP of JSON and CSV files that technically contains your data and is, in practice, unusable by a human and un-importable by a rival product. “Structured, commonly used and machine-readable” is a genuinely low bar: a machine can read it, which is not the same as another service being able to ingest it, or you being able to open it and find your Tuesday-afternoon conversation.&lt;/p&gt;

&lt;p&gt;It helps to separate two rights that get muddled here. A &lt;strong&gt;subject-access request&lt;/strong&gt; gets you a &lt;em&gt;copy&lt;/em&gt; of your data, for your own eyes — the transparency right. &lt;strong&gt;Portability&lt;/strong&gt; is meant to get it to you in a form you can &lt;em&gt;move&lt;/em&gt; — the switching right. The first is well-worn and companies answer it routinely, if grudgingly; the second is the one with teeth for competition, and it’s precisely the one that’s weakest for generated content and least likely to come with real tooling. So the common experience — a bulk archive that proves the company holds a lot about you, but won’t drop cleanly into anything else — is the system half-working as designed, not malfunctioning. You asked to move house and were handed a photograph of your belongings.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who owns the thing the AI made you, anyway?
&lt;/h2&gt;

&lt;p&gt;Ownership is the second question, and it’s a genuinely separate one from portability. Most AI services’ terms assign you ownership of, or a broad licence to, the outputs you generate — so in contract terms the report or image is “yours.” But two things undercut that comfort. First, ownership without extraction is hollow: a licence to content you can’t export is a licence to look at it inside someone else’s app. Second, the deeper copyright status of AI-generated work is itself unsettled — a thicket we’ve picked through in &lt;a href="https://theaidownside.com/posts/your-ai-generated-code-might-not-be-yours.html" rel="noopener noreferrer"&gt;whether your AI-generated code is even yours&lt;/a&gt;. “You own it” and “you can take it with you” are promises that sound identical and aren’t.&lt;/p&gt;

&lt;p&gt;And notice how the two questions actively pull apart. On the portability side, the AI’s output is “inferred data” — the provider’s analytical product — and so falls outside your data-protection claim. On the ownership side, the same output is “your content,” assigned to you by the terms of service. The identical artefact is simultaneously too much the company’s work to be portable and too much yours to be theirs — a contradiction that happens to leave you with the weaker end of both. You get a copyright you may not be able to enforce over a file you may not be able to remove. It is a strange place to end up for something as ordinary as wanting to keep the report you asked a computer to write.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why there’s so rarely a button
&lt;/h2&gt;

&lt;p&gt;If a right exists, why is the experience so often a shrug? Part of the answer is that data portability is, in the blunt assessment of one privacy body, an “obscure” right that hardly anyone exercises — and features that hardly anyone uses don’t get engineered into a smooth one-click export. A portability or subject-access request can be answered, lawfully, with an unwieldy data dump rather than a tidy, re-importable file. Layer on the commercial reality — every extra hour spent making departure frictionless is an hour spent helping customers leave — and the incentives point away from the button. The same instinct that &lt;a href="https://theaidownside.com/posts/why-every-ai-wants-your-data.html" rel="noopener noreferrer"&gt;makes every AI hungry for your data&lt;/a&gt; makes it reluctant to hand that data back in a form a rival could ingest.&lt;/p&gt;

&lt;p&gt;There’s a self-reinforcing loop in that obscurity, too. Because the right is rarely used, regulators rarely test it against modern AI products, so the “inferred data” carve-out never gets pressed on; because it never gets pressed on, companies have no reason to build export tooling for the derived content users most want; and because the tooling doesn’t exist, exercising the right stays painful enough that few bother — which keeps it obscure. Lock-in isn’t always a dark pattern someone designed. Sometimes it’s just what happens when a right sits unexercised long enough that nobody builds the plumbing to honour it, and the absence quietly becomes the norm.&lt;/p&gt;

&lt;h2&gt;
  
  
  What responsible portability would look like — and what to do now
&lt;/h2&gt;

&lt;p&gt;A tool that took your right to leave seriously would do a few recognisable things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;A real export, not a data dump.&lt;/strong&gt; Your conversations, files and generated media in an open, documented format you could re-import elsewhere — not a legal-minimum ZIP of JSON no human can use.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Honesty about the derived-data line.&lt;/strong&gt; Say plainly what a portability request will and won’t include, rather than letting you assume it covers everything.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bulk, not one-by-one.&lt;/strong&gt; If a feature is being retired, the exit should be a single download, not a manual rescue of each item against a deadline.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Extraction that matches the ownership claim.&lt;/strong&gt; If the terms say you own your outputs, the product should let you actually take them.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Until that’s the norm, treat the things you make inside an AI tool as yours to lose. Download what matters as you go rather than trusting it to live in someone else’s app; prefer services that offer a genuine export over ones that don’t; and if you’re in the EU or California, know that you can lodge a portability request — while keeping realistic expectations about the inferred-data gap. The law will catch up eventually, as it half-caught-up with &lt;a href="https://theaidownside.com/posts/the-right-to-be-forgotten-is-hard-for-ai.html" rel="noopener noreferrer"&gt;the right to be forgotten&lt;/a&gt;. In the meantime, the safest assumption is the pessimistic one: a right you can’t exercise with a button is a right on paper, and the button is the company’s to withhold.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/can-you-get-your-data-out-of-an-ai-tool.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>airegulation</category>
      <category>privacy</category>
      <category>copyright</category>
    </item>
    <item>
      <title>Microsoft Strips Copilot's Free Features — and Puts Deep Research Behind a Subscription</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Sat, 29 Aug 2026 23:25:16 +0000</pubDate>
      <link>https://dev.to/theaidownside/microsoft-strips-copilots-free-features-and-puts-deep-research-behind-a-subscription-6g6</link>
      <guid>https://dev.to/theaidownside/microsoft-strips-copilots-free-features-and-puts-deep-research-behind-a-subscription-6g6</guid>
      <description>&lt;p&gt;Open the Microsoft Copilot app this week and it may be missing a few things you used. As of 18 August, Microsoft began retiring a clutch of free consumer features — the standout being Deep Research, the tool that turned a prompt into a long, sourced report — while it folds its two Copilot apps into one. The most useful of them doesn’t vanish so much as move: the in-depth research successor now sits behind a paid Microsoft 365 plan.&lt;/p&gt;

&lt;p&gt;Answer first, because the shape of the change matters more than the noise around it. This is partly sensible housekeeping and partly a paywall. Microsoft is merging its consumer Copilot app with the business-oriented Microsoft 365 Copilot app, and along the way it has cut Group Chat, AI-generated Podcasts, Deep Research, the experimental Copilot Labs and the animated Mico character. Free chat and image generation stay free. But Deep Research’s replacement, Researcher, is available only to Microsoft 365 Premium subscribers — a plan reported at $19.99 a month — and the features that were simply removed came with a quiet save-or-lose deadline attached.&lt;/p&gt;

&lt;p&gt;None of this is a scandal, and we’ll be fair about the good parts. But a change that turns a capable free tool into a paid one, and asks users to rescue their own content by hand before a date many won’t have clocked, is worth reading slowly.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Microsoft actually switched off
&lt;/h2&gt;

&lt;p&gt;The umbrella move is a merge. Microsoft is combining the consumer-facing Copilot app and the Microsoft 365 Copilot business app into a single application, with mobile and web already unified and the Windows and Mac desktop apps following in mid-September. As &lt;a href="https://techcrunch.com/2026/08/13/microsoft-kills-off-unsuccessful-ai-features-while-merging-its-separate-copilot-apps/" rel="noopener noreferrer"&gt;TechCrunch reported&lt;/a&gt;, the company is also “ditching a number of unsuccessful AI features” in the process — an unusually frank admission that some of what it shipped over the past year didn’t land.&lt;/p&gt;

&lt;p&gt;Per Microsoft’s own support documentation, the consumer features going away by 18 August are Group Chat, Podcasts, Deep Research, Copilot Labs and Mico, the floating animated character that reviewers had already compared to an AI-era Clippy. Reasonable people can wave most of that goodbye without a tear. Mico was a novelty; Labs was explicitly experimental; a “group chat with an AI” feature was never going to be load-bearing. If the story ended there, it would be a tidy-up, and we’d call it one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The one that matters: Deep Research goes paid
&lt;/h2&gt;

&lt;p&gt;It doesn’t end there, because one of the retired features was genuinely useful and free. Deep Research compiled long, sourced reports from the web — the kind of multi-step research task that is among the more valuable things a consumer AI can do. Microsoft’s support page is plain about what replaces it: “Microsoft 365 Premium subscribers can continue creating detailed reports and analyses using Researcher in Copilot.” For everyone else, the ability to run new deep research is simply gone.&lt;/p&gt;

&lt;p&gt;Credit where it’s due, and there is some. Your existing reports are not deleted: Premium subscribers reach them through Researcher, Personal and Family subscribers can open previous reports from their chat history, and any report can be saved to Microsoft Word. That is a materially gentler landing than a hard delete, and Microsoft documented it clearly rather than letting people discover the loss cold. We’ll take honest documentation over a silent removal any day.&lt;/p&gt;

&lt;p&gt;But strip the reassurances back and the load-bearing fact remains: a research capability that used to cost nothing now costs a subscription. This is the &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;flat-to-paid drift&lt;/a&gt; in its cleanest form — not a price rise on a thing you were buying, but a thing you had for free being moved to the far side of a paywall, dressed as a product improvement. The reader on the free tier didn’t get a worse Deep Research; they got no Deep Research, and an invitation to pay $19.99 a month for its successor.&lt;/p&gt;

&lt;h2&gt;
  
  
  The save-or-lose deadline
&lt;/h2&gt;

&lt;p&gt;The features that were removed rather than paywalled came with a catch that’s easy to miss in the announcement. Take Podcasts. Microsoft says that after 18 August, customers can “no longer… create or access Podcasts in Copilot,” and that the way to keep any was to “download individual podcasts from your podcast library using the download option” — one at a time, before the cut-off. There was no bulk export. If you had a library of AI-generated episodes and didn’t hear about the change in time, they are now inaccessible in the app.&lt;/p&gt;

&lt;p&gt;Group Chat is the same pattern. Microsoft’s support page states that group-chat threads, messages and content — including images created in those chats — “will not be carried forward” after 18 August, and advises users to “copy any messages you want to keep into a document or notes app and download any images you want to save” beforehand. The burden of preservation is placed squarely on the user, on a deadline, with manual tools.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The retirement notice and the rescue instructions arrive together: the feature is going away on this date, and saving what you made in it is your job, by hand, before then.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;To be scrupulously fair, this is not deletion of your personal files, and Microsoft did give notice. But “we told you, and you had a window to save each item individually” is a low bar for content a product encouraged you to create inside it. It’s the difference between a shop that helps you carry your things out and one that leaves the boxes by the kerb and tells you the skip arrives Tuesday. The &lt;a href="https://theaidownside.com/posts/openai-pay-to-reset-chatgpt-limits.html" rel="noopener noreferrer"&gt;now-familiar move of charging to undo a limitation&lt;/a&gt; has a quieter cousin here: making the free thing disappear unless you do the work to keep it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The steel-man: consolidation is real, and some of this needed doing
&lt;/h2&gt;

&lt;p&gt;Here is the strongest case for the defence, and it’s a decent one. Microsoft genuinely had a mess: two Copilot apps with overlapping names and confusing boundaries, a consumer version and a business version that most users couldn’t tell apart. Merging them into one is a pro-user simplification, not a cynical one. In July, per reporting on an internal memo, the executive who oversees Copilot said the app needed to earn “the right to exist” in customers’ lives — which is exactly the sort of ruthlessness a bloated product needs. Cutting Mico and Labs is that ruthlessness in action.&lt;/p&gt;

&lt;p&gt;The wider context helps Microsoft too. Every big lab is consolidating: Anthropic has folded features into its main Claude app, OpenAI has pulled standalone tools back into ChatGPT. Feature attrition during a merge is normal, and keeping a rarely-used free feature alive forever has a real cost. A company is allowed to decide that Podcasts wasn’t worth maintaining. Concede all of it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the objection survives the steel-man
&lt;/h2&gt;

&lt;p&gt;Grant every point and the complaint just gets narrower and sharper. It isn’t “Microsoft simplified its apps.” It’s that the simplification’s costs fall on the free user in two specific ways. First, the single most valuable free capability — sourced, in-depth research — was the one moved behind the $19.99 plan, not the frippery. When a “clean-up” consistently paywalls the useful thing and merely deletes the toys, the pattern reads less like tidying and more like migrating value to the tier that pays.&lt;/p&gt;

&lt;p&gt;Second, the export story is worse than it needed to be. A company that can migrate stand-alone Copilot files to OneDrive automatically could presumably have offered a one-click export of your podcasts, rather than a manual, episode-by-episode download on a deadline. The absence of a bulk export isn’t a law of physics; it’s a choice about how much effort to spend making leaving painless — and it’s the same choice that makes &lt;a href="https://theaidownside.com/posts/the-subscription-fatigue-of-modern-ai.html" rel="noopener noreferrer"&gt;so many AI subscriptions&lt;/a&gt; easier to enter than to exit. We explore the deeper version of that problem — whether you have any right to extract your data and creations from an AI tool at all — in a companion piece, because it turns out the answer is murkier than “it’s your stuff.”&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do
&lt;/h2&gt;

&lt;p&gt;If you use Copilot, the practical steps are undramatic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Check what you’ve lost.&lt;/strong&gt; If you relied on Deep Research, note that new in-depth reports now require a Microsoft 365 Premium plan; your old reports should still be in your chat history or saveable to Word.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rescue anything you care about now.&lt;/strong&gt; Group chats and podcasts created before the change may already be inaccessible; if you find any still reachable, export them by hand while you can.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decide before you subscribe.&lt;/strong&gt; $19.99 a month for Researcher may well be worth it if you do serious research — but treat it as a new purchase, not a restoration of something you were promised for free.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep your own copies.&lt;/strong&gt; The broad lesson of this fortnight is that a feature you build a habit around can be retired on a schedule. Download what matters instead of trusting it to live in someone else’s app.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Microsoft has done the un-glamorous work of simplifying a genuinely confusing product, and said out loud that some of its own features flopped — which is more honesty than most launches manage. The fixable fault is the shape of the trade it offered its free users: lose the toys, lose easy access to what you made, and pay to keep the one capability that was actually worth having. A merge that treated the free tier’s useful tools as worth preserving, and made leaving as smooth as arriving, would be the same clean-up without the aftertaste.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/microsoft-copilot-strips-free-features.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>microsoft</category>
      <category>pricing</category>
      <category>githubcopilot</category>
    </item>
    <item>
      <title>'Enshittified at a Surprising Clip': A Week of Hacker News on AI Coding Tools</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Sat, 29 Aug 2026 03:12:01 +0000</pubDate>
      <link>https://dev.to/theaidownside/enshittified-at-a-surprising-clip-a-week-of-hacker-news-on-ai-coding-tools-337m</link>
      <guid>https://dev.to/theaidownside/enshittified-at-a-surprising-clip-a-week-of-hacker-news-on-ai-coding-tools-337m</guid>
      <description>&lt;p&gt;Some fortnights the complaints about AI come from people who barely use it. This one they came from the people who use it most. Scroll Hacker News over the past week — the forum where developers argue about their tools in unusual detail — and the grievances about AI coding assistants weren’t existential. Nobody was worried about the robots waking up. They were worried about their bill, their UI, and the effort of reading what the model just wrote.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Quotes sourced from:&lt;/strong&gt; Hacker News. Every quote below was located at its comment permalink and reproduced verbatim; each is listed with its username, the platform, and the date in the Sources section. As always, we quote experiences, not verdicts — a forum comment is one practitioner’s account, often mid-argument, and we’ve framed them as exactly that. What makes this batch worth reading isn’t volume; it’s specificity. These are checkable complaints.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Enshittified at a surprising clip”: the dark-pattern gripe
&lt;/h2&gt;

&lt;p&gt;The sharpest thread of the fortnight was about Cursor, the AI code editor, and it wasn’t about the quality of its completions. It was about the way the product behaves around you. A user posting as &lt;strong&gt;jmuguy&lt;/strong&gt;, on 20 August, laid out a bill of particulars that will sound familiar to anyone who’s watched a beloved tool curdle:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Cursor isn’t covering itself in glory regardless. The flagship app is getting enshittified at a surprising clip. It constantly pops up and interrupts your work pushing new features, changes your model to whatever the latest Grok is without prompting, has this mystery meat UI that is constantly changing, pushes cloud agents in ways that are definitely designed to trick you. We’re actively looking at alternatives, I wouldn’t touch anything this company produces from here on out.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Set aside the verdict at the end — that’s one person’s conclusion, not ours — and look at the specifics, because they’re the kind you can check: interruptions pushing new features, a model silently swapped to Grok, a UI that keeps moving. The transparency version of this complaint is one we keep returning to, most recently when &lt;a href="https://theaidownside.com/posts/voices-the-upgrade-that-wasnt.html" rel="noopener noreferrer"&gt;users said newer AI felt like a downgrade&lt;/a&gt;. Here it’s sharpened into a word — enshittification — that has become the developer shorthand for a product optimised for the company’s metrics rather than the user’s work.&lt;/p&gt;

&lt;p&gt;The same week, on a thread about Cursor’s new GitHub-style features, &lt;strong&gt;nikolay&lt;/strong&gt; reached the end of the road for a different reason — a feature gated behind payment where he expected an open one:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“…this is reminding me to cancel my Cursor subscription. I am paying for it but not using it because I don’t need it as it offers me nothing.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;“I am paying for it but not using it” is the quiet churn every subscription business fears and the one that &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;the flat-fee-to-meter drift&lt;/a&gt; keeps generating: not an angry cancellation over a scandal, just a slow realisation that the value stopped justifying the direct debit.&lt;/p&gt;

&lt;h2&gt;
  
  
  The billing you can’t see
&lt;/h2&gt;

&lt;p&gt;If the Cursor complaints were about attention, the next set were about money — specifically, the widening gap between what these tools charge and what a user can actually see. The most concrete came from &lt;strong&gt;j0selit0&lt;/strong&gt;, who’d been poking at GitHub Copilot’s network traffic and noticed something odd about how premium requests get counted:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“While looking at the traffic I noticed Copilot’s own LLM requests used X-initiator: agent and didn’t consume premium quota. That made me curious what would happen if I changed my own requests from user to agent. Turns out the model still responded, but those requests didn’t decrement my premium quota or show up in the billing analytics.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That’s one developer’s own testing, not an audit, and we present it as such — but it’s a precise, reproducible claim: a billing system keying off a header the client controls, such that identical requests count against your quota or not depending on a label. When the meter is that easy to confuse, the reasonable question isn’t “how do I exploit this” but “how much can I trust the number the meter shows me at all?”&lt;/p&gt;

&lt;p&gt;It rhymes with a second money story doing the rounds: a reported Codex bug on AWS Bedrock said to run up charges ten times higher than expected. Commenting on it, &lt;strong&gt;palmotea&lt;/strong&gt; aimed at the incentive rather than the bug:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Except leadership doesn’t care about dumb bugs. Never has, never will (until it’s too late). It cares about velocity and cost. They’d totally replace all software development with worse AI software development in a heartbeat.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Whatever you make of the cynicism, the pairing is the point: a quota that undercounts and a bill that overcounts, both landing in the same week, both invisible until someone technical went looking. Neither claim is dispositive on its own, and we’re not treating a forum post as a filed complaint. But the shape is what unsettles: as these products bolt on agents, cloud runs and per-request pricing, the meter grows more complicated at exactly the moment it grows less legible — and the person paying is the last one equipped to check the maths.&lt;/p&gt;

&lt;h2&gt;
  
  
  “A clueless machine” reviewing your code
&lt;/h2&gt;

&lt;p&gt;A related irritation surfaced around the AI code-review features now bolted onto everything. &lt;strong&gt;hypfer&lt;/strong&gt;, on 21 August, was blunt about GitHub’s:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“GitHub’s copilot review feature is an equally miserable experience. That one loves talking in imperatives, regardless of the fact that it is a clueless machine.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The complaint isn’t that automated review is worthless; it’s the mismatch between the confidence of the tone and the reliability of the content — a machine issuing orders about code it doesn’t understand. That gap between register and competence is the same one that makes &lt;a href="https://theaidownside.com/posts/ai-coding-assistants-and-the-myth-of-the-10x-developer.html" rel="noopener noreferrer"&gt;the 10x-developer promise&lt;/a&gt; so slippery: the output &lt;em&gt;sounds&lt;/em&gt; authoritative whether or not it’s right.&lt;/p&gt;

&lt;h2&gt;
  
  
  The verbosity tax
&lt;/h2&gt;

&lt;p&gt;Then there was the recurring gripe about Claude’s output — not that it’s wrong, but that it’s exhausting. It surfaced under, of all things, a “Show HN” for a tool whose entire job is to clean up Claude 5’s token output with a second model. &lt;strong&gt;cnity&lt;/strong&gt; diagnosed it more precisely than the usual “too wordy”:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“most people seem to consider the core problem of Claude’s output as ‘too verbose’ but I don’t think this actually cuts to the heart of the matter at all. It’s almost, in some weird way, the opposite: like the text is far too dense. It tries too hard to invent odd terminology to try to condense stuff, but it doesn’t tell you up front that it is going to call your company wide error-handling mechanism a ‘flare’…”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;dcolkitt&lt;/strong&gt; had resorted to a coping mechanism that says a lot on its own — a running side-conversation just to decode the tool’s house dialect:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I frequently use Claude Code and often find the phrasing and language to be hard to understand. I’ve noticed it’s largely broken down into frequently used ‘Claude-isms’.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;When users are building tools and keeping glossaries just to make a product’s output legible, the “productivity” being sold is quietly being taxed back in comprehension effort. It’s the flip side of the regressions we heard about when &lt;a href="https://theaidownside.com/posts/voices-the-upgrade-that-wasnt.html" rel="noopener noreferrer"&gt;a flagship upgrade landed badly&lt;/a&gt;: the model may be more capable and still be more work to actually use.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Overselling it so much”
&lt;/h2&gt;

&lt;p&gt;Underneath the specific gripes ran a broader fatigue with the gap between the pitch and the product. &lt;strong&gt;germandiago&lt;/strong&gt;, on 21 August, put the sceptic’s case in its strongest form:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I think they have been overselling it so much… Noone wants middle term maintenance nightmares or unreliable code. Can look good the first month, that’s it.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That’s a strong opinion, not a measurement, and plenty on the same site would argue the opposite. But “looks good the first month” is a useful antidote to demo-driven enthusiasm: the tools that impress in a five-minute trial and the tools you can live with for a year are not always the same tools, and the people filing these complaints are the ones a year in.&lt;/p&gt;

&lt;p&gt;Step back and the complaints rhyme. A model switched without asking, a quota that skips a labelled request, a bill that runs 10x, output you need a second tool to parse — each is a small transfer of control away from the user, made without notice. None is a catastrophe on its own. Together they sketch a class of product that keeps making unilateral decisions about your money, your model and your attention, and expects you to keep up. That texture — not any single scandal — is what these threads are really documenting.&lt;/p&gt;

&lt;h2&gt;
  
  
  The moan of the day
&lt;/h2&gt;

&lt;p&gt;It goes to &lt;strong&gt;jmuguy&lt;/strong&gt;, for the phrase that named the whole mood and will be doing overtime in developer Slacks for months:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“The flagship app is getting enshittified at a surprising clip… pushes cloud agents in ways that are definitely designed to trick you.” — jmuguy, Hacker News, 20 August 2026&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What to take from it, fairly
&lt;/h2&gt;

&lt;p&gt;The caveats are real and we’ll state them plainly. Hacker News is a self-selecting crowd of technical sceptics; the contented majority rarely posts; one developer’s packet capture is not a billing audit, and one person’s “overselling” is another’s Tuesday. None of these comments proves a company acted in bad faith.&lt;/p&gt;

&lt;p&gt;But notice what kind of complaints these are. They aren’t vibes about AI being scary. They’re specific, checkable observations about products: a model swapped without asking, a quota that skips a header-labelled request, a bill that ran 10x, output dense enough to need a translator. Specificity is the tell that separates a grumble from a signal. And the fixes they imply are boringly reasonable:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Stop switching things silently&lt;/strong&gt; — don’t change my model, to Grok or anything else, without telling me and letting me decline.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Show an honest meter&lt;/strong&gt; — the usage counter I can see should match the one you actually bill against.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Let me read the output&lt;/strong&gt; — concise by default, house jargon defined, no second tool needed to parse the first.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Announce the change&lt;/strong&gt; — a one-line release note beats discovering a moved button mid-task.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;As with &lt;a href="https://theaidownside.com/posts/claude-code-auto-mode-becomes-the-default.html" rel="noopener noreferrer"&gt;tools that act without asking&lt;/a&gt;, the ask underneath is just legibility: tell me what you’re doing, charge me what you said, and don’t make me fight the thing I’m paying for. None of it is a revolution. It’s the baseline a paying user is entitled to expect, and the reason these threads keep filling up is that it keeps not being met.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/voices-enshittified-at-a-surprising-clip.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>voices</category>
      <category>cursor</category>
      <category>githubcopilot</category>
      <category>claude</category>
    </item>
    <item>
      <title>Why AI Struggles to Guess Your Age — and Why That's a Bias Problem, Not Just an Accuracy One</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Fri, 28 Aug 2026 05:28:41 +0000</pubDate>
      <link>https://dev.to/theaidownside/why-ai-struggles-to-guess-your-age-and-why-thats-a-bias-problem-not-just-an-accuracy-one-742</link>
      <guid>https://dev.to/theaidownside/why-ai-struggles-to-guess-your-age-and-why-thats-a-bias-problem-not-just-an-accuracy-one-742</guid>
      <description>&lt;p&gt;You are being asked, more and more, to prove your age to a machine. A porn site wants to know you’re 18. A social platform wants to know you’re 16. Now even a general-purpose chatbot wants to &lt;a href="https://theaidownside.com/posts/chatgpt-now-guesses-your-age.html" rel="noopener noreferrer"&gt;form a view about whether you’re a minor&lt;/a&gt;. In almost none of these cases does the machine actually &lt;em&gt;know&lt;/em&gt; how old you are. It guesses — and the quality of that guess, and the way its errors are shared out, is one of the more consequential and least examined pieces of AI now being wired into everyday life.&lt;/p&gt;

&lt;p&gt;Answer first: AI age estimation turns your face or your behaviour into a statistical estimate of your age. In the fat middle of the age range it’s often decent. At the edges that legislation actually cares about — is this person 18? — it’s at its weakest, with independent testing finding error “buffer zones” two to three years wide around each threshold. And those errors don’t fall evenly: they cluster on some demographic groups more than others. That makes age estimation not just an accuracy story but a bias one, and the two are easy to confuse.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two ways a machine guesses your age
&lt;/h2&gt;

&lt;p&gt;“Age assurance” is the umbrella term, and underneath it sit two genuinely different things. &lt;strong&gt;Age verification&lt;/strong&gt; checks you against something authoritative: a passport, a driving licence, a credit-card or bank record. It aims to &lt;em&gt;know&lt;/em&gt;. &lt;strong&gt;Age estimation&lt;/strong&gt; aims only to &lt;em&gt;guess well&lt;/em&gt;, without demanding a document.&lt;/p&gt;

&lt;p&gt;Estimation itself comes in two main flavours. The one people picture is &lt;em&gt;facial age estimation&lt;/em&gt;: you look into a camera, and a model trained on huge numbers of face-and-age pairs outputs a predicted age or age range. The other, quieter flavour is &lt;em&gt;behavioural or contextual inference&lt;/em&gt; — guessing age from how an account is used rather than from a face. That’s the approach behind ChatGPT’s new age prediction, which reads signals like the topics you raise and the times you log in. Different inputs, same underlying move: take some observable data, and infer a protected characteristic from it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Estimation is not the same as knowing
&lt;/h2&gt;

&lt;p&gt;The single most important thing to understand is that an age estimate is a probability, not a reading off a birth certificate. A facial model doesn’t retrieve your age; it maps the pixels of your face onto the patterns it learned and returns its best statistical bet. The standard way to score how good that bet is is &lt;em&gt;mean absolute error&lt;/em&gt; — on average, how many years off is it?&lt;/p&gt;

&lt;p&gt;By that measure the technology is more capable than its critics sometimes allow. Australia ran one of the largest independent evaluations to date — its 2025 Age Assurance Technology Trial tested more than 60 solutions from 48 providers — and found that the best facial systems could achieve a mean absolute error of around a year in controlled conditions. If all you need is to sort obvious adults from obvious children, that’s workable.&lt;/p&gt;

&lt;p&gt;The trouble is that the law rarely cares about the obvious cases. It cares about the boundary — 13, 16, 18 — and the boundary is exactly where estimation is shakiest. The same Australian trial described “buffer zones” of roughly two to three years on either side of each age gate, within which false positives and negatives cluster. Put plainly: a system that’s a year off on average will, near 18, routinely read a 20-year-old as 17 or a 16-year-old as 19. The tool is least reliable at the one number it’s being deployed to enforce.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Age estimation is most accurate where nothing is at stake and least accurate at the exact threshold the law asks it to police. The uncertainty isn’t a rounding error; it’s concentrated precisely where the decision gets made.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The errors don’t land evenly — the bias problem
&lt;/h2&gt;

&lt;p&gt;If the inaccuracy were spread uniformly across all faces and all behaviours, it would still be a problem, but a tidy one. It isn’t. The Australian trial found that while systems generally performed well across diverse users, some showed &lt;em&gt;reduced&lt;/em&gt; accuracy near policy thresholds for non-Caucasian users, for female-presenting individuals, and for older adults. NIST, the US standards body whose ongoing Face Analysis Technology Evaluation is the closest thing the field has to a referee, keeps reporting the same shape: leading algorithms have narrowed the gaps, but demographic differentials in error rate persist.&lt;/p&gt;

&lt;p&gt;This is the part that turns an engineering limitation into a fairness question, and it’s the same mechanism we’ve written about before — that &lt;a href="https://theaidownside.com/posts/algorithmic-bias-is-not-a-glitch.html" rel="noopener noreferrer"&gt;algorithmic bias is not a glitch&lt;/a&gt; but a predictable product of skewed training data and uneven evaluation. Age-estimation models learn from whatever face-and-age data they were fed; where a group is under-represented or its ageing patterns are less well modelled, the error rate climbs. Researchers have traced this to at least two compounding sources: bias baked into the data the model learned from, and bias in how “age” itself was labelled and perceived across different populations in the first place.&lt;/p&gt;

&lt;p&gt;The practical upshot is stark. If a system is systematically more likely to misjudge, say, darker-skinned or female-presenting faces at the 18 line, then the people wrongly blocked from an adult service — or wrongly forced to escalate to an ID check to prove themselves — are disproportionately drawn from those groups. A tool sold as a neutral gate becomes a gate that’s stiffer for some than for others.&lt;/p&gt;

&lt;p&gt;And the stakes climb with the setting. Age estimation isn’t confined to keeping teenagers off adult sites; investigations such as Lighthouse Reports’ work on AI used to assess asylum seekers’ ages show what happens when the same fallible guess is pointed at people with the most to lose and the least recourse — where a mislabelled year can redirect the course of a life. When the error bars are demographic, deploying the technology on already-marginalised groups compounds the exact unfairness the trials keep measuring, rather than cancelling it out.&lt;/p&gt;

&lt;h2&gt;
  
  
  Guessing age without a face is even harder to check
&lt;/h2&gt;

&lt;p&gt;Facial estimation at least has a testing ecosystem around it — NIST, national trials, published error rates you can argue about. Behavioural inference, the approach that guesses your age from how you use a service rather than what your face looks like, has almost none of that scaffolding, and it is the approach spreading fastest inside consumer apps. When a chatbot infers you’re a minor from “the general topics you talk about” and your login times, there is no NIST benchmark for that particular model, no independent error rate you can look up, and often no clear signal to you that a judgement was made at all.&lt;/p&gt;

&lt;p&gt;That opacity cuts two ways. The signals are proxies — correlations between behaviour and age that hold on average and break for individuals — so the night-owl adult and the articulate fifteen-year-old are both misread by design. And because the inference runs continuously on your activity rather than as a discrete check, it is a standing judgement that can silently re-evaluate you at any time, not a one-off gate you passed and forgot. A facial check is at least a moment you can see and consent to. A behavioural age-score is a weather system sitting over your account, and you are rarely told when it changes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the law is suddenly demanding it
&lt;/h2&gt;

&lt;p&gt;None of this has slowed deployment, because the pressure isn’t coming from whether the technology is ready. It’s coming from legislation. In the UK, the Online Safety Act requires services with adult content to use “highly effective age assurance,” and Ofcom’s guidance — with a compliance deadline of 25 July 2025 — explicitly names facial age estimation as one of the methods that can qualify, alongside open banking, mobile-network checks and photo-ID matching. Notably, Ofcom says self-declaration (“tick here to confirm you’re 18”) is &lt;em&gt;not&lt;/em&gt; good enough. Australia’s move to keep under-16s off social media prompted the very trial whose numbers we’ve been quoting. Similar requirements are landing across the EU and a growing list of US states.&lt;/p&gt;

&lt;p&gt;To its credit, Ofcom’s test for “highly effective” is not just accuracy: it asks whether a method is technically accurate, robust, reliable &lt;em&gt;and fair&lt;/em&gt;. Fairness is written into the standard. The gap is between that standard on paper and the demographic error patterns the trials keep finding — which is precisely why “we use facial age estimation” is a claim to interrogate, not a box to tick. This is the same tension running through &lt;a href="https://theaidownside.com/posts/what-ai-regulation-protects-you-from.html" rel="noopener noreferrer"&gt;the wider effort to regulate AI&lt;/a&gt;: the rule can be sound while the implementation quietly fails the people it’s meant to treat evenly.&lt;/p&gt;

&lt;h2&gt;
  
  
  The privacy trade nobody quite voted for
&lt;/h2&gt;

&lt;p&gt;Age estimation is often sold as the &lt;em&gt;privacy-friendly&lt;/em&gt; option, and relative to uploading your passport to every website, it can be. Facial age estimation done well processes the image on the fly and doesn’t store it; behavioural inference avoids the camera entirely. That’s a real advantage over a world where every age gate demands government ID.&lt;/p&gt;

&lt;p&gt;But two catches sit underneath the pitch. First, “non-intrusive” still means a machine is scanning your face or profiling your activity to derive a fact about you — a quieter form of the same data hunger behind &lt;a href="https://theaidownside.com/posts/why-every-ai-wants-your-data.html" rel="noopener noreferrer"&gt;why every AI wants your data&lt;/a&gt;. Second, and more subtly: because estimation is unreliable in the buffer zone, the standard recommended fix is to fall back to full verification when the model isn’t confident. That sounds sensible until you notice who ends up in the buffer zone — young adults, and disproportionately the demographic groups the model is worst at. The people the system is least sure about are exactly the ones it pushes hardest toward handing over an ID. The “privacy-preserving” method routes its own failures straight back to the intrusive one.&lt;/p&gt;

&lt;h2&gt;
  
  
  What responsible age assurance would look like
&lt;/h2&gt;

&lt;p&gt;This isn’t an argument that age checks are illegitimate or that the technology should be junked. It’s an argument for reading the specifics. A defensible deployment tends to share a few features:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Honest buffer zones.&lt;/strong&gt; It treats the two-to-three-year band around a threshold as uncertain by design, rather than pretending a single guess is a verdict.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Published error rates, broken down by demographic.&lt;/strong&gt; If a provider won’t tell you how differently the system performs across groups, that silence is the finding.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data minimisation.&lt;/strong&gt; Estimate on-device or on-the-fly, don’t retain the face image, and don’t quietly repurpose age signals for advertising or profiling.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A real appeal path.&lt;/strong&gt; A wrong guess should be cheap and quick to correct, and the cost of the error should sit with the operator, not the misclassified user.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verification as a genuine fallback, not a trap.&lt;/strong&gt; If the system is unsure, the escalation to ID should be rare and proportionate — not the predictable fate of everyone near the line.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Guessing a stranger’s age from a photograph or a usage pattern was always going to be hard, and doing it at the scale the law now demands makes the hard parts systemic. The technology can be part of a reasonable answer to a real problem — keeping the sharpest content away from children. But the honest version publishes its error bars, owns its demographic gaps, and treats a wrong guess as its own bug to fix. The version to worry about is the one that presents a probability as a fact, hides who it’s wrong about, and hands the bill for its mistakes to whoever the model happened to misread.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/why-ai-age-estimation-is-hard.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>bias</category>
      <category>privacy</category>
      <category>airegulation</category>
      <category>safety</category>
    </item>
    <item>
      <title>ChatGPT Now Guesses Your Age — and Restricts You by Default if It Thinks You're Under 18</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Thu, 27 Aug 2026 00:52:11 +0000</pubDate>
      <link>https://dev.to/theaidownside/chatgpt-now-guesses-your-age-and-restricts-you-by-default-if-it-thinks-youre-under-18-2ii0</link>
      <guid>https://dev.to/theaidownside/chatgpt-now-guesses-your-age-and-restricts-you-by-default-if-it-thinks-youre-under-18-2ii0</guid>
      <description>&lt;p&gt;Open ChatGPT this week and, without any announcement in the chat window, it may already have formed an opinion about how old you are. From 18 August, OpenAI began rolling out “age prediction” on its consumer plans: a system that guesses whether your account belongs to someone under 18 and, if it decides you’re a minor, quietly switches you into a restricted version called ChatGPT for Teens. You are not asked. If the guess lands on “teenager,” the guardrails go up by default.&lt;/p&gt;

&lt;p&gt;Answer first, because the mechanism matters more than the alarm: the guess is behavioural, and it is admittedly imperfect. By OpenAI’s own account the system reads “general topics you talk about, the times of day you use ChatGPT, how and when your account is used, and how long your account has existed.” And the way to make it stop guessing is not a toggle. It is to prove your age to a third-party verifier called Persona, with a live selfie, a government ID, or both. The choice on offer isn’t whether to be identified. It’s how.&lt;/p&gt;

&lt;p&gt;None of this arrives from nowhere, and we’ll be fair about why in a moment. But a change that infers a protected characteristic from the content of your conversations, applies real restrictions on the strength of a guess, and offers identity verification as the only exit is worth reading slowly — especially for the adults who will be misclassified, because OpenAI says plainly that some will be.&lt;/p&gt;

&lt;h2&gt;
  
  
  What OpenAI actually switched on
&lt;/h2&gt;

&lt;p&gt;The launch has two parts. The visible one is &lt;strong&gt;ChatGPT for Teens&lt;/strong&gt;, announced on 18 August: a version with study-focused features and stronger safety defaults for under-18s. The consequential one is &lt;strong&gt;age prediction&lt;/strong&gt;, the system that decides who gets dropped into it. In OpenAI’s words, “If our system estimates someone is under 18 or they state their age is between 13 and 17, they are automatically placed into ChatGPT for Teens.” It is rolling out globally, with the EU following “in the coming weeks” to fit regional rules.&lt;/p&gt;

&lt;p&gt;What does the teen experience actually change? The safeguards are broad. ChatGPT for Teens reduces sensitive content — OpenAI lists graphic violence or gore, “viral challenges that could push risky or harmful behavior,” sexual, romantic or violent roleplay, and content that promotes extreme beauty standards or unhealthy dieting. Under its updated under-18 model rules, the assistant “should not use romantic language, encourage emotional dependence, or imply that it has feelings or consciousness.” There are break reminders, product cues that keep identifying the thing as AI, and, for accounts linked to a parent, controls like Quiet Hours. OpenAI also says it will not show ads in a teen account — a notable line in the same week it announced that ChatGPT Ads is &lt;em&gt;expanding&lt;/em&gt; across Europe for everyone else.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it decides you’re a teenager
&lt;/h2&gt;

&lt;p&gt;Here is the part that should give a thoughtful adult pause. Age prediction does not work from a document or a birthday you confirm. It works from behaviour. OpenAI’s help page describes it as looking at “different signals linked to your account” — the topics you raise, when you tend to log in, the pattern of your usage, the age of the account itself — and then inferring whether you’re over or under 18.&lt;/p&gt;

&lt;p&gt;Crucially, this overrides what you told it. “Age prediction is an extra safety check,” the page reads. “It can identify an account as eligible for the ChatGPT for Teens experience even if you already gave your date of birth when you created your account.” So the date of birth you entered is not the last word; a statistical read of your habits can be. And OpenAI is refreshingly blunt about the reliability of that read: “No system is perfect. Sometimes ChatGPT may get it wrong.”&lt;/p&gt;

&lt;p&gt;That candour is welcome, and it is also the whole problem. A system that infers a legal category from “the general topics you talk about” is guessing, and a guess about age from conversation topics is exactly the kind of proxy that misfires — the adult who uses plain language and logs on after school hours, the teenager who writes like a lawyer. When the guess is wrong, it doesn’t fail quietly in a log somewhere. It changes the product you’re using.&lt;/p&gt;

&lt;h2&gt;
  
  
  The opt-out is a selfie or a passport
&lt;/h2&gt;

&lt;p&gt;Say the guess lands wrong and you, a grown adult, find yourself in the teen experience. OpenAI has built a way out, and to its credit it’s documented and not buried: go to Settings, choose “Verify age,” and complete a check with Persona. Depending on your country, Persona “may ask for one or both of these: a live selfie” — a real-time photo of your face — and “a government ID,” such as a driver’s licence or passport.&lt;/p&gt;

&lt;p&gt;The privacy engineering here is genuinely more careful than the norm. OpenAI says it “does not receive the ID itself”; Persona handles the document and “deletes your uploaded ID or selfie within 7 days.” OpenAI only learns the outcome — that you verified as 18-plus, plus age-related information such as your date of birth. If you don’t want the hassle, you don’t have to verify at all; you can keep using ChatGPT with the teen protections on. That is a real set of mitigations and we won’t pretend otherwise.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The system offers two ways to establish that you’re an adult: let it read your habits, or show it your face. There is no third door marked “none of your business.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;But look at the structure of the choice, because it’s the same shape whichever way you turn. You can be profiled — scored for age from the content of your chats — or you can hand a selfie and a government ID to a company you’d never heard of until this settings page. The one option that doesn’t exist is to be left alone: to use a general-purpose writing tool without either a behavioural age-score or an identity check attached to your account. OpenAI’s own wording makes the trade explicit: “If you do not want OpenAI to predict your age, you can verify your age with Persona.” Don’t want to be guessed about? Then prove who you are.&lt;/p&gt;

&lt;h2&gt;
  
  
  The steel-man: this did not come from nowhere
&lt;/h2&gt;

&lt;p&gt;Now the fair part, and it’s substantial. OpenAI is not doing this for fun, and it is not the only company being pushed here. The launch follows a run of lawsuits and public cases alleging that ChatGPT contributed to serious harm to young users, including self-harm; OpenAI has denied wrongdoing in some of those cases, but the pressure — legal, regulatory and moral — is real and it is not frivolous. A chatbot that will talk to a distressed 15-year-old at 3am is a genuinely different product from a search box, and pretending otherwise would be its own kind of dishonesty.&lt;/p&gt;

&lt;p&gt;The company also cites a defensible premise: it says the overwhelming majority of teenagers use ChatGPT for ordinary things — homework, learning, building. Age-appropriate defaults for minors are a reasonable thing to want, regulators increasingly &lt;em&gt;require&lt;/em&gt; some form of age assurance (Italy already forces verification within 60 days of being asked), and OpenAI has clearly spent effort making the verification path privacy-preserving. Concede all of it. A world where a company shrugged and served every user the identical unguarded model would not obviously be better.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why “we might get it wrong” is doing a lot of work
&lt;/h2&gt;

&lt;p&gt;Grant every one of those points and the objection doesn’t vanish; it just gets specific. The issue is not that OpenAI built protections for teenagers. It is that the gate to those protections is a guess, the guess is on by default, and the cost of the guess being wrong is borne by the person it’s wrong about.&lt;/p&gt;

&lt;p&gt;Think about who the false positives are. Age estimation is least reliable exactly at the boundary that matters — the 18 line — and its errors are not evenly distributed across everyone; independent testing of these systems keeps finding they’re worse for some groups than others, a point we unpack in our companion explainer on why age estimation is so hard to get right. So the adult who gets dropped into a restricted experience, then asked to upload a passport to climb back out, is not a random unlucky soul. They’re a predictable output of a system that trades accuracy for coverage. When that happens, the restrictions we’ve &lt;a href="https://theaidownside.com/posts/when-ai-refuses-perfectly-normal-requests.html" rel="noopener noreferrer"&gt;criticised elsewhere as over-refusal&lt;/a&gt; arrive not because you asked for something dodgy, but because a classifier mislabelled you.&lt;/p&gt;

&lt;p&gt;There’s a quieter cost too. Inferring your age from “the general topics you talk about” is, unavoidably, profiling the content of your conversations to derive a fact about you — a small expansion of the surveillance that already underwrites &lt;a href="https://theaidownside.com/posts/why-every-ai-wants-your-data.html" rel="noopener noreferrer"&gt;why every AI wants your data&lt;/a&gt;, now wearing a child-safety badge. And normalising a face scan or an ID upload as the price of the un-nerfed product is the sort of thing that feels reasonable once and becomes the industry default by the third time, in the same way &lt;a href="https://theaidownside.com/posts/atlassian-trains-its-ai-on-your-work-by-default.html" rel="noopener noreferrer"&gt;defaults quietly reset in your workplace tools&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do
&lt;/h2&gt;

&lt;p&gt;The practical advice is undramatic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Know that the guess exists.&lt;/strong&gt; If ChatGPT suddenly feels more restrictive, you may have been placed in the teen experience by prediction, not by anything you did.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decide before you verify.&lt;/strong&gt; You do &lt;em&gt;not&lt;/em&gt; have to hand over ID to keep using ChatGPT — you only need to if you want the teen protections removed. Weigh whether the unrestricted version is worth a selfie and a document to a third party.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;If you do verify, note the boundaries.&lt;/strong&gt; OpenAI says it never receives the ID and Persona deletes it within seven days — commitments worth holding them to.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Watch the defaults.&lt;/strong&gt; The interesting question isn’t this launch; it’s whether behavioural age-scoring becomes a permanent, invisible layer on every account, and whether “verify to opt out” spreads from teen safety to everything else.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;OpenAI has done the hard, unglamorous safety work more thoughtfully than most, and the goal — keeping the sharpest edges of a persuasive chatbot away from children — is one worth taking seriously. The fixable fault is the design that makes its own inaccuracy your problem. Age assurance built well would treat a wrong guess as a bug the company eats, not a burden the user carries with a passport in hand. Until then, the honest summary is the one OpenAI wrote itself: sometimes it will get it wrong — and when it does, proving otherwise is on you.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/chatgpt-now-guesses-your-age.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>chatgpt</category>
      <category>openai</category>
      <category>censorship</category>
    </item>
    <item>
      <title>The Upgrade That Wasn’t: When ‘Newer’ AI Feels Like a Downgrade</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Tue, 25 Aug 2026 21:48:07 +0000</pubDate>
      <link>https://dev.to/theaidownside/the-upgrade-that-wasnt-when-newer-ai-feels-like-a-downgrade-4ngo</link>
      <guid>https://dev.to/theaidownside/the-upgrade-that-wasnt-when-newer-ai-feels-like-a-downgrade-4ngo</guid>
      <description>&lt;p&gt;Some fortnights the complaint is the bill. This one it was the product itself. Across the forums where paying customers of the big AI tools compare notes, the same grievance surfaced against three different companies in the same window, and it wasn’t about price at all. It was about &lt;em&gt;direction&lt;/em&gt;: the new model feels worse than the old one, the app quietly took away the thing I used, and I can’t even tell what I’m running any more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Quotes sourced from:&lt;/strong&gt; Reddit — specifically the subreddits r/ClaudeAI, r/cursor and r/perplexity_ai. Every quote below was opened at its permalink and copied verbatim; each is listed with its handle, subreddit and date in the Sources section. We quote experiences, not verdicts — a forum post is one person’s felt reality, and model quality is genuinely subjective, so we have framed these as exactly that: what it felt like to the person typing.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Rage-inducing”: the flagship that felt like a step back
&lt;/h2&gt;

&lt;p&gt;The sharpest thread came from Claude Code users trying, and failing, to get on with a new top-end model. A user posting as &lt;strong&gt;ronoudgenoeg&lt;/strong&gt; opened it on 13 August with a title that set the tone — “Opus 5 is actually almost rage-inducing to use” — and a specific, un-nostalgic complaint:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Responses are way too verbose and buzzwordy and hard to follow. I legit don’t read 90% of the output anymore, that’s how bad it is. No matter what I put in my claude.md when it comes to communication style, after it did any type of meaningful work, it always reverts back to its extremely verbose, over-explained, buzzword heavy mess.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;What made the thread notable wasn’t one angry post; it was the agreement, and how concrete it was. &lt;strong&gt;zimxero&lt;/strong&gt; described asking the model to make a file &lt;em&gt;more concise&lt;/em&gt; and getting “walls of text” and an hour of unwanted process in return. &lt;strong&gt;BeowulfShaeffer&lt;/strong&gt; was blunter: “I fired opus 5. Worst model I’ve ever tried to use. I refuse to use it anymore.” And the tell that this was regression rather than grumbling — several users independently reaching for the same escape hatch. &lt;strong&gt;grimorg80&lt;/strong&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I reverted to Opus 4.8. Nothing worked with Opus 5. It was exactly as you described. Insanely convoluted writing, overly sophisticated language, stupidly messy reasoning when dealing with unexpected cases, and so damn time consuming. 4.8 still works great for me.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;We should be careful here, because the users aren’t claiming a benchmark result — they’re describing a feel. A new model can score better on average and still be worse for your particular loop. But when the concrete failure mode (verbosity, ignored instructions) repeats across dozens of posts and people keep manually downgrading to the same prior version, “it’s just nostalgia” stops being a complete explanation.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Janky and unprofessional”: the pace, not the change
&lt;/h2&gt;

&lt;p&gt;A different Claude thread, from &lt;strong&gt;mbatt2&lt;/strong&gt; on 18 August, aimed at something subtler than quality — the sheer churn. It wasn’t that updates are bad; it’s that they arrive constantly and opaquely:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“The extreme number of updates comes off as janky and unprofessional. At this point it feels like way more than once per day and is super distracting. Is it just asking you to reload anytime an engineer commits or something?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;To be fair — and the thread itself was split on this — plenty of replies pushed back that continuous deployment is &lt;em&gt;more&lt;/em&gt; professional, not less, and that a constant stream of fixes is how modern software gets made. That’s a reasonable defence. But the most-upvoted reply put its finger on the actual grievance, which is legibility rather than frequency. &lt;strong&gt;Terrible_Tutor&lt;/strong&gt;: “I’m fine with it, just some fucking RELEASE notes would be great.” The problem isn’t that the thing changes. It’s that it changes under you without telling you what changed.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The through-line isn’t “new is bad.” It’s “new is non-optional, unexplained, and increasingly hard to even identify.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  “They don’t show you the model’s name”: the transparency gripe
&lt;/h2&gt;

&lt;p&gt;Which leads to the fortnight’s most quietly damning complaint, because it showed up against two unrelated products at once: you can no longer tell which model is answering you. On r/cursor, a user posting as &lt;strong&gt;Gusteen&lt;/strong&gt; laid out the mechanics on 18 August:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“First, they were auto switching to grok. now it’s they don’t show you the model’s name when your using grok. all of the other ones show the model name in the drop down but for grok noppe… so for like 2 hours I thought I was in composer but nope it was stuck on grok.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Whatever the reason, the effect on the user is the one that matters: two hours of degraded output with no way to connect the cause to the symptom. &lt;strong&gt;barepaws&lt;/strong&gt; in the same thread: “I’m glad to see I’m not the only one. It’s not something I used to paying attention to and it very frustrating when I forget to change it.” When the model is the product you’re paying for, hiding which model you’re on isn’t a cosmetic choice.&lt;/p&gt;

&lt;p&gt;Perplexity users described the identical loss from a different angle. In a 20 August thread, &lt;strong&gt;sho-ne&lt;/strong&gt; catalogued a web version that had quietly shed features — usage stats gone, answers no longer removable — and, tellingly: “Perplexity no longer tells me which model was actually used to prepare an answer.” The same disappearance, at two companies, in the same week.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Gutted”: when the upgrade removes the reason you came
&lt;/h2&gt;

&lt;p&gt;The other Perplexity complaint was starker, because for some users the “upgrade” removed the exact feature they’d subscribed for. &lt;strong&gt;ddd27ddd&lt;/strong&gt;, 20 August, under the title “Comet has been gutted”:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“My whole reason for jumping to Perplexity is now dead. You now must use computer and it’s very expensive credits to use the agentic browser. Huge cut into my workflows.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is the upgrade-as-downgrade in its purest form: a workflow someone built on and paid for, migrated into a more expensive, credit-metered replacement they didn’t ask for. Others in the thread reached the natural conclusion — &lt;strong&gt;angerofmars&lt;/strong&gt; framed it as one more in a run of “enshittifications that Perplexity forced onto their customers,” and more than one reply ended with the same two words: subscription cancelled.&lt;/p&gt;

&lt;h2&gt;
  
  
  The moan of the day
&lt;/h2&gt;

&lt;p&gt;It goes to &lt;strong&gt;BeowulfShaeffer&lt;/strong&gt;, for the most economical summary of the entire mood — four sentences that a lot of paying users apparently felt this fortnight:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I fired opus 5. Worst model I’ve ever tried to use. I refuse to use it anymore.” — BeowulfShaeffer, r/ClaudeAI, 13 August 2026&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What to take from it, fairly
&lt;/h2&gt;

&lt;p&gt;The usual caution applies, and harder than usual here: vocal forum posters are a self-selecting minority, happy users don’t post, and “the model got worse” is the single most subjective complaint in this whole beat. None of these threads proves a model regressed in any measurable sense. What they show is a consistent shape of frustration, and it has three recognisable faces:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Newer, but worse&lt;/strong&gt; — a flagship release that lands badly for real workflows, with users manually reverting to the prior version to get their work done.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Changed, but unexplained&lt;/strong&gt; — an update cadence with no legible release notes, so you can feel the ground move without being told how.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Different, and hidden&lt;/strong&gt; — tools that stop showing which model answered, or migrate a paid feature into a costlier replacement, so you can’t connect a drop in quality to its cause.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of it is a conspiracy; it is the ordinary drift of products optimised for shipping over legibility.&lt;/p&gt;

&lt;p&gt;We’ve written the structural version of each of these before: how &lt;a href="https://theaidownside.com/posts/voices-the-model-you-rely-on-keeps-changing.html" rel="noopener noreferrer"&gt;the model you rely on keeps changing underneath you&lt;/a&gt;, how you can &lt;a href="https://theaidownside.com/posts/voices-you-paid-for-the-big-model.html" rel="noopener noreferrer"&gt;pay for the big model and be served the small one&lt;/a&gt;, and how a &lt;a href="https://theaidownside.com/posts/your-flat-ai-subscription-is-becoming-a-meter.html" rel="noopener noreferrer"&gt;flat subscription quietly becomes a meter&lt;/a&gt;. The voices this fortnight are the felt version of all three. The fix users are asking for is not radical: show me which model answered, tell me what changed, and let me stay on the version that worked. It is a low bar. Clearing it would settle most of these threads.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/voices-the-upgrade-that-wasnt.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>voices</category>
      <category>claude</category>
      <category>perplexity</category>
      <category>cursor</category>
    </item>
    <item>
      <title>The Right to Be Forgotten Is Hard for AI: Why Deleting Your Data From a Model Isn’t a Delete Button</title>
      <dc:creator>The AI Downside</dc:creator>
      <pubDate>Mon, 24 Aug 2026 21:48:31 +0000</pubDate>
      <link>https://dev.to/theaidownside/the-right-to-be-forgotten-is-hard-for-ai-why-deleting-your-data-from-a-model-isnt-a-delete-button-375d</link>
      <guid>https://dev.to/theaidownside/the-right-to-be-forgotten-is-hard-for-ai-why-deleting-your-data-from-a-model-isnt-a-delete-button-375d</guid>
      <description>&lt;p&gt;You ask a company to delete your data. In a normal system that is a database operation: find the rows that are yours, remove them, done. The mental model of “delete” that privacy law is built on — the GDPR’s right to erasure, most obviously — assumes exactly this: that your data sits somewhere as a discrete record you can locate and destroy.&lt;/p&gt;

&lt;p&gt;A trained AI model breaks that assumption. Answer first: your data isn’t stored in the model as a record at all. It is dissolved into the model’s parameters — billions of numbers, each nudged a little during training by every example it saw, yours included. There is no row labelled with your name to delete. Removing your influence means changing the numbers, and doing that cleanly is a genuine research problem, not a setting with a toggle.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where your data actually goes when a model “learns” it
&lt;/h2&gt;

&lt;p&gt;Training a large model is a process of adjustment. The model makes a prediction, it’s wrong, and an optimiser tweaks its parameters a fraction to make that particular kind of error slightly less likely next time. Repeat across trillions of tokens and those fractional tweaks accumulate into a system that has, in a distributed and lossy way, absorbed patterns from its training data.&lt;/p&gt;

&lt;p&gt;The key word is &lt;em&gt;distributed&lt;/em&gt;. A single document doesn’t live in one identifiable place in the weights; its contribution is smeared across many parameters that also encode a great many other things. Two consequences follow, and they are the whole reason this is hard. First, you cannot point at the part of the model that is “you.” Second, deleting the original document from the training set does nothing to the model that already trained on it — the lesson has been learned and the textbook has been closed. The data is gone; the influence remains.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Erasing your data from the training set is like removing a single lump of sugar from a cake that has already been baked. The lump is gone from the recipe. The sweetness is still in the cake.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The clean fix that nobody can afford to do often
&lt;/h2&gt;

&lt;p&gt;There is a correct, boring answer to all of this: retrain the model from scratch on the dataset with your data left out. This is sometimes called &lt;em&gt;exact unlearning&lt;/em&gt;, and it is the gold standard because the resulting model provably never saw your data. If cost were no object, every deletion request would be honoured this way.&lt;/p&gt;

&lt;p&gt;Cost is very much an object. Training a frontier-scale model is a multi-week run on enormous clusters, with an energy and compute bill that industry estimates put anywhere from the high hundreds of thousands into the millions of dollars for a single training run. Doing that again for one person’s erasure request — and then again for the next request, and the next — is not something any lab will do routinely. So exact unlearning, the one method with a real guarantee, is precisely the one that doesn’t scale to the volume of requests a popular product generates.&lt;/p&gt;

&lt;h2&gt;
  
  
  “Approximate unlearning”: cheaper, and no promises
&lt;/h2&gt;

&lt;p&gt;The workaround is a fast-moving research field called machine unlearning, which tries to make a model act as though it never saw specific data without paying the full retraining cost. The techniques are ingenious and worth knowing by name, because they define what “we’ll remove your data” can realistically mean:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Gradient ascent&lt;/strong&gt; — roughly, train &lt;em&gt;away&lt;/em&gt; from the data you want forgotten, nudging the weights in the opposite direction to how they were nudged when learning it. Cheap, but a heavy hand can degrade the model’s general ability.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Influence functions&lt;/strong&gt; — estimate how much a given data point shaped the model and subtract that estimated influence. Elegant, but it’s an approximation of an approximation on systems this large.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Sharded retraining&lt;/strong&gt; — split the training data into shards up front so that forgetting a point only requires retraining the shard it lived in, not the whole model. Practical, but it constrains how you train and still isn’t free.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All of these buy efficiency by giving up guarantees. Approximate unlearning is typically judged not by a proof but by empirical tests — can we still extract the data, does the model still complete the forgotten passage — and there is no settled definition of what counts as “successfully forgotten” in a probabilistic system. Benchmarks exist: a 2023 Machine Unlearning Challenge organised with Google framed the problem around three goals in tension — forgetting quality, keeping the model useful, and doing it efficiently — and treated a method as “efficient” only if it cost a small fraction of full retraining. But framing the problem well is not the same as solving it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Even “forgotten” data can come back
&lt;/h2&gt;

&lt;p&gt;The uncomfortable finding from recent research is that erasure can be less final than it looks. Work published in 2025 demonstrated that data could in some cases be extracted &lt;em&gt;after&lt;/em&gt; supposed exact unlearning, because traces survive in places the procedure didn’t fully account for. If even the gold-standard method can leave recoverable residue under the right probing, the approximate methods — the ones that actually get used at scale — should be read as reducing risk rather than guaranteeing absence. There is progress on cost, too: 2025 methods have shown unlearning at roughly half the price of retraining while preserving performance. But “cheaper and pretty good” is a different promise from “gone.”&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this should change how you read a privacy promise
&lt;/h2&gt;

&lt;p&gt;None of this is a reason to shrug and assume erasure is fake. It is a reason to read the specific wording. When a service says it will “delete your data,” the honest, verifiable part is usually about the &lt;em&gt;training set and the databases&lt;/em&gt; — your records stop being stored and stop being fed into future runs. That is real and it matters. The much harder, much vaguer part is what happens to the model that already learned from you, and that is where “and we’ll retrain” does a lot of quiet work.&lt;/p&gt;

&lt;p&gt;This is not abstract. It is exactly the promise sitting under, for instance, &lt;a href="https://theaidownside.com/posts/atlassian-trains-its-ai-on-your-work-by-default.html" rel="noopener noreferrer"&gt;Atlassian’s pledge to remove opted-out data and retrain&lt;/a&gt; its models, and under every consumer AI product’s data-deletion page. It also sharpens why memorisation is such a problem in the first place: if models can &lt;a href="https://theaidownside.com/posts/how-ai-models-leak-their-training-data.html" rel="noopener noreferrer"&gt;leak the data they were trained on&lt;/a&gt;, then incomplete forgetting isn’t just a compliance footnote, it’s a live exposure. And it is one more front in the unresolved fight over &lt;a href="https://theaidownside.com/posts/who-owns-the-words-that-trained-your-ai.html" rel="noopener noreferrer"&gt;who owns the words that trained your AI&lt;/a&gt; — ownership is moot if removal is impossible.&lt;/p&gt;

&lt;p&gt;The regulation is trying to catch up. The right to erasure was written for a world of databases, and applying it to distributed model weights is an open legal-technical question that unlearning research and &lt;a href="https://theaidownside.com/posts/what-ai-regulation-protects-you-from.html" rel="noopener noreferrer"&gt;the wider push to regulate AI&lt;/a&gt; are both circling. Until it’s resolved, the pro-consumer posture is the sceptical one: treat “we’ll delete it from the model” as a claim with a hard engineering problem behind it, ask &lt;em&gt;which&lt;/em&gt; deletion is being promised — the dataset, or the model — and don’t assume the two are the same thing. The delete key works on your files. It does not yet work on a model’s memory, and pretending otherwise is the part worth not forgetting.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://theaidownside.com/posts/the-right-to-be-forgotten-is-hard-for-ai.html" rel="noopener noreferrer"&gt;theaidownside.com&lt;/a&gt; — evidence-first reporting on the costs and trade-offs behind AI products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>airegulation</category>
      <category>safety</category>
      <category>llms</category>
    </item>
  </channel>
</rss>
