I wonder how many companies put all of the risks of the closed source coding agent collecting loads of data about corporate laptops on their risk register or accounted for it in their compliance processes.

I’m guessing they had the chatbot handle the details.

https://www.theregister.com/2026/04/01/claude_code_source_leak_privacy_nightmare/

Claude Code source leak reveals how much info Anthropic can hoover up about you and your system

: If you loved the data retention of Microsoft Recall, you'll be thrilled with Claude Code

The Register

I personally would be slightly more worried about the security of anything produced by vibecoding enthusiasts than I would be about whether you can get the person who maintains a random Python library that you transitively depend on at four steps remove to sign a disclaimer in triplicate and fax it back to you.

But I’m just a guy who programs the damn computers rather than comes up with security governance policy.