The Pattern Rhymes
This has happened enough times to have a shape, AI or not. These are the AI cases.
In the summer of 2023, Zoom amended its terms of service to claim broad rights over customer data for training and tuning models. Nobody noticed for months. When a technology blog surfaced the clause in August, The Record reported in Zoom revises terms again to say it doesn’t use customer data to train AI models that the company rewrote the language twice inside a week.
Nine months later it was Slack. A post on Hacker News pointed at the privacy principles page, and workspace owners learned they were enrolled by default in machine learning training on messages, content, and files. TechCrunch covered the reaction in Slack under attack over sneaky AI training policy, including the detail that turned irritation into anger: opting out meant emailing a specific address with a specific subject line, and only a workspace owner could send it.
No toggle, no setting.
The terms had been live since at least September 2023, and Slack rewrote the language within days while saying it had changed no practice, which was true and beside the point. Fresh ink on their hands.
This has happened enough times to have a shape, and it doesn’t feel good.
Then June 2024. Adobe pushed a re-acceptance modal, creators read the license language, and the company spent two weeks walking it back. Its own post, Updating Adobe’s Terms of Use, conceded the terms needed to be more precise.
Adobe’s defaults were never the problem; its wording was. The company lost weeks of trust without doing the thing it stood accused of, which tells you that trust does not track behavior. It tracks what people can read and verify.
Slack is its own category, and the one worth studying. Zoom and Adobe reversed. Slack did not: it rewrote the sentence and kept the mechanism, which is a different move wearing the same clothes.
Trust is not a feeling, it is a set of defaults you can audit, and Zoom and Adobe both recovered inside a fortnight because reversal was available to them — a sentence to fix, a toggle to flip, a correction to make in public. Slack fixed the sentence only, and the email address is still the exit.
Same script every time.
- A policy change lands quietly.
- Enrollment is the default.
- Somebody outside the company finds it.
- Then the clarification, the apology, and sometimes the walk-back.
It feels a lot like Fight Club, where the companies are calculating risk and reward.
“My job was to apply the formula: Take the number of vehicles in the field, A, multiply it by the probable rate of failure, B, multiply the result by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don’t do one.”
Sounds like consent spirit, read like this:
“My job was to apply the formula: Take the number of users whose data we ingested, A, multiply it by the probable rate of anyone noticing, B, multiply that by the average settlement per claim, C. A times B times C equals X. If X is less than the cost of building a real consent flow, we don’t build one.”
What is different about Figma is that nothing was walked back at all, and the discovery arrived as a federal complaint. There was no drafting error to fix. The tiered default was announced, explained, defended with a stated rationale, and allowed to take effect on schedule. You cannot clarify a decision that was already clear.
The Sniff Test
Four questions fall out of that pattern, worth naming with their scoring before we run them.
- Consent
- Symmetry
- Disclosure
- Exit
A tool that passes all four treats your work as yours, and three passes is ordinary enough to be worth raising at renewal. But symmetry does not weigh the same as the rest, and a failure there counts for more than the other three combined.