I asked AI for my best quotes. It handed me things people told me in confidence.

I built a system to surface the best quotes from everything I'd saved. The best lines were things said to me in confidence — and the model couldn't tell. Why the boundary is judgement, not a smarter model.

This week I built myself a small piece of machinery. When I sit down to write one of these posts, I want it to reach into everything I've read and saved over the years and hand me a line that actually fits — a sentence from a book I marked up, a thought I left in the margin, a quote worth building a paragraph around.

So I pointed AI at my own archive and asked a simple question: give me the best quotes I've saved, ranked by how good they are.

It did. And that's where it got uncomfortable.

The best lines were the ones I can never use

The strongest material — by a distance — wasn't from books. It was things people had said to me. A blunt aside across a boardroom table. A founder's off-the-record verdict on a competitor. A manager summarising ten years of pain in one clean sentence. Lines with names attached, sometimes numbers, almost always spoken in a room that everyone in it understood to be private.

The machine had no idea. To the model, a highlight from a published book and a sentence a client said in a closed meeting look identical: both are just text I chose to save because it mattered. It ranked them side by side, cheerfully, best first. And most of the "best" were things I could never publish without betraying the person who said them.

That's the whole problem in one screen. The AI could retrieve everything and rank it. It could not tell me which lines were mine to share.

As Ethan Mollick writes in Co-Intelligence, there's a danger in working with AI that we make ourselves redundant — but also a quieter danger that "we trust AIs for work too much." Ranking your own memories by quality is exactly the kind of work you shouldn't hand over whole.

Why this is about to be everyone's problem

Privacy researchers have a name for what breaks here: contextual integrity. Information carries the norms of the setting it was shared in. A thing said to you in confidence doesn't become publishable just because it now sits in the same searchable box as your book notes. A workplace AI, the same researchers warn, will happily connect ordinary signals and surface a judgement no one asked it to make. The model flattens context. You are the only one in the loop who still remembers which room each sentence was spoken in.

And we are all assembling these boxes now — notes apps, meeting transcribers, "second brains," the assistant that reads your inbox. Personal AI tools quietly build a profile of everything you feed them. The more of your working life you make searchable, the more a helpful model can hand back things you'd forgotten you'd stored — stripped of the context that made them safe to keep.

The fix is a boundary, not a smarter model

So I did the unglamorous thing. I gave the system an explicit rule about where it's allowed to draw quotes from: published books, public talks and podcasts, and things I've said myself. Never a line attributed to a named person from a meeting, a call, a board session, or a client conversation — however good it is, and however plainly it's sitting right there in my own files.

That rule is not something the model could have inferred. It's a judgement about trust, and trust is contextual in a way a ranking function is not. I've argued before that the leverage in this work is the judgement, not the tool. This was the same idea pointed at my own archive. The tool made everything reachable. Deciding what was mine to share stayed my job.

There's a version of me that finds this reassuring rather than annoying. I look after a handful of companies, and I keep a lot of what they tell me — it's how I stay useful between meetings. The discipline that stops the machine quoting a client in a blog post is the same discipline that keeps their words safe in the first place. When I write about building a proper knowledge system, this is the part people skip: a good one isn't just organised, it knows what it is not allowed to repeat.

I've spent months teaching these systems to do more of my week. This was the first time I sat one down and taught it to do less — to leave certain things exactly where they were.

The uncomfortable truth the exercise surfaced is that my most quotable material is, and should stay, unquotable. The machine will keep offering it to me, best first. Saying no is the part that's still mine.

Sources & further reading

External
Forbes Technology Council — AI Security And The New Privacy Problem: Inference With Authority
No Jitter — Personal AI assistants present organizational data risks
Ethan Mollick, Co-Intelligence: Living and Working with AI.

Related posts
The death of generic AI: why deep domain expertise is the only real leverage left
Beyond the junk drawer: mastering knowledge with progressive disclosure and AI
I taught my assistant to prep my week. The hard part was making it stop starting over.

Subscribe to Remco Livain

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe
Work with me →×