
You thought you were talking to AI. Police may see a digital diary
Two recent Israeli cases show how conversations with AI chatbots can reveal intentions, plans and movements long after users thought they had deleted the evidence. The implications extend far beyond criminal investigations.
In two investigations that have come to light in Israel in recent days, artificial intelligence has played an unusual role. It was not a tool that police used to search for suspects, but a repository of digital traces that the people at the center of the investigations themselves left behind.
In one case, an 18-year-old man consulted ChatGPT before allegedly setting fire to a restaurant. In the other, conversations with Google's Gemini reportedly became one of the clues that helped investigators locate a mother and daughter who had disappeared from Israel.
The two cases are completely different from a law-enforcement perspective, but they reveal the same vulnerability. The people at the heart of the investigations appear to have treated their conversations with AI systems as private exchanges, when those conversations could ultimately become significant digital evidence, even when users delete their chat histories or take steps to conceal their identities.
In one case, police investigators used a conversation with ChatGPT as part of the evidence against a suspect accused of setting fire to a branch of the Japanese restaurant chain Japanica.
According to the indictment, the suspect and another accomplice obtained gasoline and incendiary devices, traveled to the restaurant on an electric scooter, wore camouflage clothing and arrived with the intention of setting it on fire. One of them poured flammable material and set the restaurant ablaze while an employee was still inside. The two then fled.
On the face of it, this is a conventional criminal investigation involving security cameras, escape routes, vehicles, phones, connections between suspects and forensic evidence. But investigators also found another kind of trace. It was a conversation with ChatGPT.
According to the indictment and the investigation report, the main suspect had consulted ChatGPT before the arson, asking what punishment could be imposed for burning down a store. ChatGPT responded that the offense could carry a lengthy prison sentence.
But the suspect did not stop there. He then asked what would happen if the premises were closed and no one was there.
For investigators, that second question could be particularly significant. It suggests that the suspect was not merely curious about the legal consequences of arson, but was considering whether the presence or absence of people at the scene would affect the seriousness of the offense.
The conversation does not, by itself, prove that the suspect committed the crime. But it can form part of a chronological narrative by showing what he was thinking about, what questions he asked and how those questions related to what happened later.
In other words, ChatGPT did not “turn in” the suspect. The suspect left the trail himself. The AI system simply became the place where a conversation was recorded, potentially giving investigators a window into his intentions before the crime.
The case of Mali and Liel Yahalomi, a mother and daughter who reportedly planned to leave their existing lives behind and disappear to South America, illustrates just how extensive a person's digital trail can become.
The two had not committed a crime. But because they apparently did not tell anyone about their plans, their sudden disappearance initially raised fears that they had been kidnapped, extorted or targeted by terrorist organizations.
According to reports, the two left Israel, withdrew a significant amount of cash, moved between countries, changed SIM cards and took other steps intended to make themselves harder to trace.
Friends and acquaintances were enlisted in the search, including people with backgrounds in intelligence and cyber operations who collected and analyzed digital information before passing findings to the Unit of International Crime Investigations.
One of the main clues, according to a source familiar with the case, came from Mali's Gemini account, alongside information from other applications she used.
The conversations with the chatbot were reportedly significant because they included questions that appeared to relate directly to the planning of the disappearance. Among them were questions about how to purchase a phone without identification, how to minimize digital traces and which South American countries do not extradite people to Israel.
Here, the role of AI was effectively reversed. A system designed to provide fast, personalized answers became, in retrospect, something resembling a digital diary.
Instead of investigators having to infer what Mali had been planning from scattered clues, the conversations may have revealed the questions she herself had been asking and therefore the problems she was trying to solve.
It is important, however, to distinguish between what has been reported and what is known about the investigation. The publicly available information does not establish exactly how investigators obtained access to the Gemini account.
The account may have remained accessible on a device left behind. Information may have been extracted from a phone or computer using forensic tools. Alternatively, cloud-stored information may have been obtained from Google through an appropriate legal process.
That uncertainty is important because it highlights a broader point. Deleting a conversation from an interface is not necessarily the same thing as making the underlying data inaccessible.
Both cases point to a significant change in investigations in the age of artificial intelligence.
In the past, people trying to conceal a plan, a trip or an intention had to worry about text messages, phone calls, emails, photographs and location data. Today, conversations with AI have joined that list.
The difference is that people tend to interact with chatbots in an unusually natural and intimate way. They ask systems questions they might never write to another person, explain their circumstances and sometimes reveal highly personal information.
Precisely because the interaction feels like a private conversation, it is easy to forget that it is taking place inside a digital service that generates and stores data.
There are ways to increase privacy when using leading AI chatbots. OpenAI's ChatGPT, for example, can be used without logging into an account, while users can also enable Temporary Chat, disable model-improvement settings and delete conversations. They should also avoid creating or sharing public links to sensitive conversations.
In Google's Gemini, users can use Temporary Chat, adjust activity settings, disable certain voice and memory features and limit the use of conversations for model improvement. Some privacy settings, however, can also mean losing access to conversation history.
Anthropic's Claude offers an incognito mode, as well as settings for model improvement and memory. Users can also cancel previously shared links.
But none of these measures should be interpreted as an absolute guarantee of privacy. AI companies may retain some information for limited periods for security, legal or operational purposes, and deleting a conversation from a user's interface does not necessarily mean that every copy of the underlying data has immediately disappeared.
The most effective privacy measure therefore remains the simplest one. Don't tell an AI system something you would not want to become part of a record.
Users should avoid entering identifying information when it is unnecessary and formulate sensitive questions as generally as possible. The more specific the information provided to an AI system, the more useful that conversation can potentially become to someone trying to reconstruct what happened.
The implications extend beyond criminal investigations. As AI systems become increasingly integrated into everyday life, conversations with them are likely to contain an ever-growing amount of information about people's finances, relationships, health, work, travel plans and personal problems.
That creates a strange paradox. People turn to AI because it can feel more private than talking to another person. But the more personal those conversations become, the more valuable they may be to anyone trying to reconstruct a person's actions or intentions.
In both Israeli cases, AI did not play the role of detective or investigator. It played something potentially more consequential. It became a witness.
As artificial intelligence becomes more deeply integrated into people's personal lives, it is also becoming a record of their intentions, fears, plans and decisions.
Even when the person at the center of an investigation tries to disappear, the conversation may remain behind, revealing where they were trying to go.














