Key Takeaways
- Your AI chat history is a goldmine of intellectual property, personal data, and corporate secrets — yet the platforms guarding it treat security like an afterthought
- Claude's password-less design eliminates credential theft but creates a single point of failure: your email inbox
- Perplexity hides active sessions entirely, forcing users into a nuclear "log out everywhere" option with no visibility into who's watching
- Multi-factor authentication remains optional on platforms where it should be mandatory by default
The conversation you had with ChatGPT last week about your product roadmap. The legal strategy you workshopped with Claude. The medical symptoms you searched on Perplexity. These aren't casual queries — they're the raw material of competitive advantage, attorney-client privilege, and HIPAA-protected health data. Yet the three dominant AI platforms secure this trove with the same rigor as a forum account from 2005.
Start with the inconsistency. ChatGPT and Perplexity offer multi-factor authentication. Claude does not. Anthropic's choice to rely exclusively on emailed login links sounds modern until you realize it shifts the entire threat model to your inbox. Compromise the email, compromise the AI account. No second factor. No hardware key option. No passkey support. Just a magic link that anyone with access to your mail can click. That's not passwordless authentication — it's password delegation to a third party you don't control.
ChatGPT at least shows you the battlefield. Open settings, navigate to active sessions, and you'll see every device, browser, and approximate location holding a live token. Spot an unfamiliar entry? Kill it individually or nuke them all. Then rotate the password through a standard reset flow. The mechanics work. But the default state — no MFA enforced, no login alerts, no anomaly detection — assumes a threat model that evaporated years ago.
Perplexity takes opacity to a new level. The platform simply refuses to show you active sessions. None. Zero visibility. If you suspect intrusion, your only recourse is "Sign out of all sessions," a scorched-earth tactic that logs you out everywhere including the device in your hand. You won't know if the attacker was in Mumbai or Minneapolis. You won't know if they lingered for hours or days. You'll only know they're gone — until they use the same stolen credential to walk back in.
This matters because AI accounts accumulate context. Unlike a breached Netflix account, which reveals your taste in documentaries, a breached AI account reveals your unfinished patent application, your unreleased earnings narrative, your therapy-adjacent journaling. The data is structured, searchable, and exportable. Attackers don't need to read every chat. They can ask the model to summarize your strategic concerns across all conversations. The platform becomes the analyst.
The fix isn't complicated. Enforce MFA by default. Support passkeys and hardware tokens. Surface active sessions with geolocation and device fingerprinting on every platform — not just the two that bother. Send real-time alerts on new logins from new geographies. Treat the session token as the high-value credential it is, rotating it aggressively and invalidating it on password change or security setting modification.
None of this is novel. It's table-stakes security hygiene that banks and email providers implemented a decade ago. The AI platforms aren't lacking engineering capacity — they're lacking incentive. Your chat history doesn't appear on their balance sheet as a liability. Until it does, either through regulation or a catastrophic breach, the burden lands on you.
So check your sessions today. On ChatGPT, click through to Security and Login. On Claude, inspect Account settings. On Perplexity, accept the blindness and cycle the session anyway. Then enable MFA where it exists. Use a password manager. Treat your AI accounts like the intellectual property vaults they've become — because the platforms guarding them still don't.