Back to blog

The Woman Who Said No to the Pentagon, Google, and the Tech World

Meredith Whittaker on Project Maven, what separates Signal from WhatsApp, and why AI agents may become the next major threat to privacy.

Privacy & Governance PrivacyAISignal

Meredith Whittaker, president of Signal

Meredith Whittaker is the president of Signal, a former Google employee, and one of the organizers of the protest against Project Maven. In an interview with Mishal Husain on Bloomberg, she discusses issues that affect everyone who owns a phone — with a degree of candor that is rare in the technology industry.

Whittaker does not resemble the archetypal technology executive. She did not study computer science or grow up assembling a Commodore 64. Her background was in literature and rhetoric, and she entered technology almost by accident. She spent more than a decade at Google, eventually becoming an uncomfortable presence for management — not because she sought confrontation, but because she asked difficult questions. When Google prepared to work with the Pentagon on the military AI initiative Project Maven, she did more than object: she helped organize employees. Thousands spoke out against the project. Whittaker stresses that this was not a story of Meredith versus Google. It was a collective demand from people inside the company who wanted to understand where the technology they were building was headed. Today, Google DeepMind workers are unionizing, while OpenAI employees are also beginning to organize amid talk of an IPO. The trend has not disappeared; it has grown stronger.

Whittaker left Google in 2018. She now leads Signal, a nonprofit messenger built around a principle that sounds almost indecent in the modern technology industry: privacy is a fundamental human right, not an option for the paranoid. She is prepared to pay for defending that right. Signal is funded by donations and operates on an annual budget of roughly $50 million. About 70 percent comes from major donors, with the remaining 30 percent contributed by ordinary users giving $5 to $20 a month. Whittaker describes herself as hood rich: financially comfortable, but nowhere near private-jet wealth. When Husain asks whether she misses that world, Whittaker smiles and replies that she is not rich rich; she is hood rich. The answer carries a trace of exhaustion with an industry in which people can complain about the champagne on a private plane.

The most compelling part begins when Whittaker explains why her position on privacy is not merely ideological, but technically grounded.

The first principle is that encryption either works for everyone or it works for no one. This is not a slogan; it is mathematics. There is no way to create a golden key exclusively for the “good guys,” because every key becomes a vulnerability that someone will eventually find. Authorities in the United Kingdom and the European Union have pushed platforms to introduce device scanning intended to detect child sexual abuse material. Whittaker’s answer is that Signal would rather leave a market than weaken its encryption. She is not bluffing. The company has already said it was prepared to withdraw from the UK during debate over the Online Safety Bill. Her position does not change from one jurisdiction to another: a backdoor introduced in one market compromises protection everywhere else. Signal is one of the few mass-market messengers offering this level of privacy, and it is constantly tested for weaknesses — including, Whittaker suggests, by intelligence agencies in its own country.

The second layer is the difference between Signal and WhatsApp. Many people assume there is little distinction because both use end-to-end encryption. But content encryption and privacy are not the same thing. WhatsApp cannot read the content of an encrypted message, yet it still holds a great deal of surrounding information: your profile, photograph, name, who you communicate with, when and how often you do so, and who belongs to your groups. Whittaker offers a concrete example. Imagine messaging your oncologist. WhatsApp may not know what you wrote, but it knows that you contacted an oncologist. That information can be combined with data from Facebook and Instagram, supplemented with records from data brokers, processed by an AI model, and used, for example, to target pharmaceutical advertising. In Nebraska, Meta gave authorities messages between a woman and her daughter about reproductive health; the conversation became evidence in a criminal case. Signal aims not to collect even metadata. Its source code is open, and its technical choices can be independently inspected.

The third point may be the most alarming for the future. Whittaker describes AI agents such as Microsoft Copilot as an existential threat to privacy. She explains the risk through an everyday example. Imagine asking Copilot to buy Christmas presents. To complete the task, the agent would need access to your credit card, browser, conversations with relatives, calendar, and home address. In practice, that gives it access to applications — including Signal. Whittaker compares this to breaching the blood-brain barrier: breaking the protective boundary between the operating system and individual apps. Three companies control the leading consumer operating systems: Google, Apple, and Microsoft. A product decision inside any one of them could render application-level privacy meaningless for billions of people.

The strongest moment in the interview is her response to questions about protecting children, sexual abuse, and terrorism. She does not evade the subject or dismiss it as someone else’s problem. Her argument is that society is trying to solve an extraordinarily difficult social problem with a technical patch, while often failing to provide enough social workers and investigators to respond when a child reports abuse. If technology alone could solve the problem, it would already have done so: law enforcement has never had access to more data than it does today. In Whittaker’s view, encryption is not the root problem. The deeper failure is society’s reluctance to invest in the institutions that provide real protection.

Whittaker speaks about technology with a skepticism rarely heard from industry leaders. AI, she says, is not magic. It is a statistical model embedded in a hardware-and-software system, constrained by memory and computing power. Marketing departments sell miracles; implementation often turns out to be a structure held together by obsolete libraries, tape, and string.

What remains after the conversation? Whittaker is not asking people to abandon technology. She uses Instagram and a health-tracking app herself. She does not live in the woods or communicate by paper letter. But neither does she accept that the technological future presented to us is inevitable. She may not know whether she can win, she says, but she is willing to fight for her principles. She is also alert to the irony of her position: an American who spent years inside a major technology company now criticizing an industry of which she remains a part.

Her central message is simple: privacy cannot be reduced to individual consumer choice. When the options are accept all or reject all, that is not meaningful consent; it is the appearance of consent. The decisions that matter are made through law, regulation, and public accountability — precisely the mechanisms we currently lack.

More thinking