You gave an AI access to your card and your social accounts: do you know who built that system?
A new 'AI-powered' service pops up every week asking for access to your email, your social accounts, or your credit card. Almost nobody stops to ask who built the system, where it runs, or what it does with the data.
In the last two years the number of products promising to "automate your life with AI" has exploded: schedule for you, answer your messages, build your résumé, optimize your finances, generate content for your social accounts. To do that, almost all of them ask for the same thing: access to your Google account, permissions on your Instagram or LinkedIn, or your credit card number directly.
The question almost nobody asks before hitting "authorize" is simple: who built this system, where does it run, and what does it do with what you're handing over?
The same pattern everywhere
A polished form, a gradient logo, a button that says "connect with Google" or "sign in with Instagram." Behind that screen there might be a company with a security team, a clear contract, and audited servers, or there might be two people who built the product over a weekend with an AI model, wired up a couple of APIs, and shipped it to free hosting without giving a second thought to how the credentials they receive are stored.
From the outside, both cases look exactly the same. The interface tells you nothing about the infrastructure behind it.
What you're actually handing over
When you connect an account or add a card to one of these services, you're not handing over an isolated piece of data. You're handing over:
- An access token that in many cases stays valid even after you stop using the app, if nobody bothered to revoke it.
- Everything that token can read: contacts, messages, posts, location, spending habits.
- Trust that the data is processed and stored responsibly, something you can't verify by looking at a landing page.
The problem isn't AI itself. The problem is that the barrier to building these services dropped so much that anyone can launch one in days, and that speed almost never comes paired with the same speed in security, compliance, or transparency.
Simple questions before you grant access
You don't need to be a security specialist to filter out most of the risk. Three questions before authorizing any service cover a lot of ground:
- Who's behind it? A real company has an "about us" page, terms of service, and a way to contact them that isn't just a form. If you can't find any of that in two minutes, that's a signal.
- Is it asking for more access than it needs? A service that only needs to read your calendar but asks for permission to send messages on your behalf is overreaching. The broader the permission, the bigger the potential damage if something goes wrong.
- Can I revoke access easily later? Google, Meta, and most banks have a "connected apps" panel. If you've never checked yours, you probably have services in there you stopped using months ago that still have active access.
Why this matters to us at Manivela
We've been closely following the cybersecurity angle applied to organizations that currently have no active auditing at all, and this is the end-user version of the same problem: AI lowered the barrier to building software, but it didn't lower the barrier to building it well. Anyone can spin up a working system in a weekend. Very few stop to think about how the credentials that system receives are protected.
When we build a system for a client, whether it's an internal panel, a social media integration, or any flow that touches sensitive data, the standard is the same: request only the access that's needed, be clear about where each piece of data lives, and document how it can be revoked. Not as an extra, but because it's the difference between a system people can trust and one that works until it doesn't.
If you're about to integrate AI into your business, or just want to understand what you're already giving access to, let's talk.