{"slug": "firefoxs-ai-switch-is-off-telemetry-isnt", "title": "Firefox’s AI Switch Is Off. Telemetry Isn’t", "summary": "A Wireshark test of Firefox 155 by blogger Marius confirms that Mozilla's AI kill switch disables generative AI features but leaves telemetry and advertising tracking active, a finding that drew internal criticism from Mozilla. Mozilla CEO Anthony Enzor-DeMeo acknowledged the backlash in an August 25 essay, admitting that only about 1% of users disabled all AI and 3% disabled individual features, and argued that the ability to turn AI off is Firefox's strongest selling point.", "body_md": "My Wireshark test of Firefox 148 showed that its AI kill switch disables generative features, but leaves telemetry and advertising untouched. Six months later, Mozilla’s CEO has called the switch perhaps the most important AI feature of all. I retested it in Firefox 155.\n\nMy [first test of Firefox’s AI kill switch](https://marius.blog/mozilla-firefox-ai-controls/) apparently reached readers I had not expected. I was told that the article made its way into Mozilla’s internal Slack and was discussed there. The verdict: a “hit piece.” The fact that my previous Firefox article had been featured on the cover of the US edition of Linux Magazine probably did not help. Anyone who read it will know that its core consisted of preferences, host lists, and timestamps. The reaction is nevertheless unsurprising. It is a familiar response when someone holds Mozilla’s own behavior up to the company. It is not my fault if Mozilla does not like what my tests revealed about its own behavior.\n\nTo be clear, I know that the AI kill switch does not claim to disable telemetry or advertising. I tested both again because they were part of my previous investigation, and because the response to that article showed why the distinction matters. Many readers told me they had no idea how much tracking Firefox performs in the first place. Others had genuinely understood the AI kill switch as a universal off switch for AI, telemetry, and advertising. Here is an idea, Mozilla: either expand the existing switch or put a second one next to it.\n\nSix months later, Mozilla’s leadership sounds different. On August 25, CEO Anthony Enzor-DeMeo published an essay with the remarkable title “[Trust is earned. Consent is asked. AI skipped both.](https://aed.me/articles/turn-it-off/)” Reading it is disorienting in places: a message from the ivory tower that reaches exactly the conclusion critics had reached months earlier.\n\n## Humility as strategy\n\nEnzor-DeMeo begins with his first day as CEO in December 2025. In interviews around his appointment, he had talked about AI in the browser; after all, the features were optional. Then came the backlash. “It was a gut punch. Frankly, I deserved it,” he writes. “I said the right words and still missed the message.” One of his first decisions as CEO was therefore not to launch another AI feature, but to build the switch that turns them all off. He clearly dislikes the name “kill switch,” preferring [AI Controls](https://blog.mozilla.org/firefox/ai-controls/). He says he accelerated the project partly for personal reasons: he, too, was tired of AI popping up everywhere.\n\nHe had been proud, he writes, that Mozilla could let users decide “how they AI.” Then the feature shipped, followed by the sentence to which the essay gives a paragraph of its own: “Almost nobody used it.” In the months after release, roughly one percent of users reportedly switched off all AI and three percent disabled individual features.\n\nThe CEO’s interpretation is that AI has no fixed definition. Translation is machine learning of the kind that has existed for decades; generative AI is only one subset. Most users left translation enabled while tending to reject the generative features. That is not a free pass, he concedes, citing [Pew Research](https://www.pewresearch.org/internet/2026/06/17/americans-and-ai-2026-chatbots-smart-devices-and-views-on-impact/): about half of US adults now use AI chatbots, yet 59 percent do not trust US companies to develop AI responsibly. His conclusion is that, in a world where companies force AI on their users, Firefox’s strongest argument is “choice and agency.” The final line has the makings of a poster: “The most important AI feature may be the ability to turn it off.”\n\nBy the standards of Mozilla’s usual communications, this is remarkably self-critical. It is also clever public relations. The story retrospectively turns a concession to protesting users into proof of Mozilla’s closeness to those users. And it rests on a foundation directly relevant to this test: the numbers showing who flipped the switch. I will return to those numbers shortly.\n\n## The comment section runs its own test\n\nEnzor-DeMeo promoted his essay in a [LinkedIn post](https://lnkd.in/p/e5aiQgwS) that collected 537 reactions and 53 comments within a week. Nearly every tool he uses had gained an AI feature this year, he wrote, and he could not remember being asked first. The replies are more revealing than the post itself.\n\nProduct manager Olivia O’Hara tried it for herself and installed Firefox from scratch. Her finding: the onboarding flow does not mention that Firefox contains AI features at all, let alone that there is a switch for them. To find it, users have to open the hamburger menu, enter Settings, and select a dedicated tab. “It feels buried,” she wrote, suggesting that the one- and three-percent figures might be artificially low because hardly anyone discovers the switch. Jed Wheeler added dryly that low usage in this case simply meant poor UX. The CEO replied that Mozilla was always open to UX feedback, but had tried to make the switch easy to find: “Settings -> AI Controls.” That is exactly the route O’Hara had just described as buried.\n\nMarketing consultant Shweta Bhatade captured the prevailing mood of this software year: every tool she uses gained an AI panel, none asked first, and after a while it stops feeling like a feature and starts feeling like something happening to you. Enzor-DeMeo responded, “Great insight!” The same observation, made by a journalist six months earlier, was reportedly treated inside his company as a hit piece. Another commenter, Andres Servin, put the core distinction neatly: “optional” and “controlled” are fundamentally different. Users prefer the door locked by default to one that can be locked on request.\n\nThat makes the percentages less conclusive than they first appear. They measure not only approval of AI, but also the discoverability of a switch the browser never shows its users.\n\n## Retesting Firefox 155\n\n[Firefox 155](https://www.firefox.com/en-US/firefox/155.0/releasenotes/) arrived on September 1, and I repeated the measurements the same day. The test machine was a MacBookPro11,1, better known as the 2013 A1502, with a clean installation of Ubuntu 24.04.3. Firefox 155.0 came as a DEB package from Mozilla’s official repository. Wireshark 4.2.2 captured all traffic, and I decrypted TLS through the `SSLKEYLOGFILE`\n\nenvironment variable as before.\n\nEvery browser action took place visibly in a real Xorg session using mouse and keyboard. There was no WebDriver, no remote debugging, and no prepared Firefox profile. Two factory-fresh profiles formed the two series. The A runs covered a cold start, setup followed by idle time, and a fixed browsing scenario in the default state. The B runs repeated those steps with “Block AI Enhancements” enabled and added a restart of the blocked profile. This time I explicitly accounted for the methodological trap in the first test: one-time first-run connections can look like an effect of the switch if they are compared with a warmed-up profile. Both cold starts therefore happened before anyone touched the switch.\n\nThere is good news up front. Firefox has become quieter on its very first launch. Where my March test counted 25 TLS hosts and 76 DNS queries, Firefox 155 produced 14 hosts and 70 queries in each of the two fresh profiles. That is a real improvement, but it has nothing to do with the switch. Comparing the blocked profile’s later nine-host restart with the 14-host first launch would repeat the same warm-profile fallacy: the decrease is a cache effect, not a blocking effect.\n\n## The switch has grown\n\nMozilla has expanded the switch itself. It now sets eleven preferences instead of nine. The additions are `browser.ai.control.smartWindow = \"blocked\"`\n\nand `extensions.ml.enabled = false`\n\n. The confirmation dialog lists six feature areas: translations, PDF alt text, AI tab groups, key points in link previews, Smart Window, and sidebar chatbots. Firefox also notes that blocking affects extensions that use AI supplied by Firefox. Extensions may still contact external AI services independently. Mozilla’s [documentation remains candid](https://support.mozilla.org/en-US/kb/firefox-ai-controls): traditional machine learning for classification, ranking, and personalization is explicitly outside the switch’s remit.\n\n```\nbrowser.ai.control.default = \"blocked\"\nbrowser.ai.control.linkPreviewKeyPoints = \"blocked\"\nbrowser.ai.control.pdfjsAltText = \"blocked\"\nbrowser.ai.control.sidebarChatbot = \"blocked\"\nbrowser.ai.control.smartTabGroups = \"blocked\"\nbrowser.ai.control.smartWindow = \"blocked\"\nbrowser.ai.control.translations = \"blocked\"\nextensions.ml.enabled = false\nbrowser.ml.chat.enabled = false\nbrowser.ml.chat.page = false\nbrowser.ml.linkPreview.enabled = false\n```\n\nThe biggest new addition is Smart Window. A week before Enzor-DeMeo’s essay, Mozilla formally unveiled the prompt-based browsing environment that had appeared in preview builds as AI Window. [Smart Window](https://blog.mozilla.org/en/firefox/firefox-smart-window/) combines web search from AI search provider [Exa](https://blog.mozilla.org/en/firefox/firefox-exa-partnership/), selectable language models, automatic tab-group suggestions, and a visual history preview. The beta initially launched in English for the United States and Canada. It is configured, of all places, inside the settings panel that had been marketed as a kill switch in February.\n\nInternally, the feature is still called AI Window. Both fresh profiles requested a Remote Settings collection named `ai-window-prompts`\n\n23 and 24 seconds after their very first launch. During the B run, the user was still trapped behind Firefox’s mandatory first-run notice at that point; the switch was not yet accessible. The first AI-related server request therefore preceded any opportunity to choose. Consent is asked? Not in those first 24 seconds.\n\n## Telemetry does not understand “blocked”\n\nThe most important direct comparison in the series was visible setup followed by 120 seconds of idle time, once in the default state and once immediately after blocking AI. The result is uneventful, and that is the finding. Both runs contacted nine TLS SNI hosts. Both sent 14 telemetry POST requests to `incoming.telemetry.mozilla.org`\n\n, with exactly the same category distribution, including eight `messaging-system`\n\npings each. Apart from one local multicast destination in the default run, the target list was the same: ad servers, Merino, the Settings CDN, telemetry, all present. The switch did not remove a single one of those hosts.\n\n| Finding | Firefox 148 (March) | Firefox 155 (September) |\n|---|---|---|\n| Direct switch preferences | 9 | 11; Smart Window and Firefox AI in extensions added |\n| Fresh-profile first launch | 25 TLS hosts, 76 DNS queries | 14 TLS hosts, 70 DNS queries |\n| Telemetry after blocking | Continues | Continues: 14 POSTs while idle, 9 after restart |\n| Persistent identifiers | Remain | Remain, confirmed inside decrypted pings |\n| Advertising and Merino | Remain active | Remain active |\n| Temu affiliate DNS | Present | Present, including after a blocked restart |\n`soloist.ai` Sponsored Tile | Consistently present | No longer in the inventory |\n| AI experiment assignment | Chatbot summarization, treatment branch | `copilot-chatbot-sunset` , control branch; remains after blocking |\n| AI request before switch access | Not observed | `ai-window-prompts` during first launch |\n\nAfter the blocked profile restarted, Firefox sent nine more POST requests within 120 seconds. Their Glean client ID, legacy client ID, profile-group ID, and both usage UUIDs were identical to those in the preceding run. The switch rotates nothing and deletes nothing. The blocked profile’s `newtab`\n\nping reported, among other values, `pocket.sponsored_stories_enabled = true`\n\nand `topsites.sponsored_enabled = true`\n\n, along with the partner code for Google search. The usage ping continued to include the operating system, exact kernel, build, distribution, default-browser status, active ticks, and both usage UUIDs. This time the evidence is stronger: I reconstructed 37 complete POST payloads from the decrypted HTTP/2 and HTTP/3 streams.\n\nThe switch was equally inconsequential during actual browsing, at least where data leaving the machine was concerned. The fixed scenario used identical stops with hard-checked destination URLs, from kernel.org to a Netzwelt guide. The default profile reached 22 TLS hosts; the blocked one reached 26. The blocked run was not even quieter. The differences were dynamic debris, an image host here, a consent host there, from which neither a beneficial nor a harmful effect of the switch can be inferred.\n\nNimbus, Mozilla’s experiment system, provides the most ironic result. After restart, its targeting-context ping dutifully reported `browser__ai__control__default = \"blocked\"`\n\n, while keeping the same profile enrolled in the active `copilot-chatbot-sunset`\n\nexperiment’s control branch. The matching preference was still present in `prefs.js`\n\n: `browser.ml.chat.nimbus = \"copilot-chatbot-sunset:control\"`\n\n. Being blocked is not an exit from Mozilla’s experiment system; it becomes another targeting property. The same ping listed eleven further Smart Window microsurvey, What’s New, and promotion campaign slugs as `NotEnrolled`\n\n. That does not prove participation in those campaigns, but it does show an extensive campaign apparatus surrounding the AI features.\n\nThis is where Enzor-DeMeo’s percentages deserve a second look. How does Mozilla know so precisely that one percent disabled everything and three percent switched off individual features? Through the same telemetry the switch leaves untouched and which obediently reports the switch’s state. Anyone who presses “Block AI Enhancements” automatically becomes a data point in the CEO’s success story.\n\n## Advertising continues, and Temu says hello\n\nFirefox’s ad infrastructure is as unmoved by the switch as it was in March. Both idle runs called the preflight endpoint at `ads.mozilla.org`\n\nand Merino’s picture-of-the-day API, and each established six TLS handshakes with `ads-img.mozilla.org`\n\n. The familiar affiliate tracker `temuaffiliateprogram.pxf.io`\n\nwas prefetched through DNS after just under three seconds in both fresh profiles and after a little over five seconds following the blocked restart. Firefox therefore still resolves the tracking domain of a discount marketplace the user has never visited, whether AI is blocked or not. The captures prove DNS prefetching; they do not show a subsequent TLS connection to that host.\n\nOne host did disappear: `soloist.ai`\n\n, the AI startup promoted through a Sponsored Tile in March, appeared in none of the seven valid Firefox 155 captures. The switch cannot take the credit, because the host was absent both before and after blocking. The advertising inventory changed; the advertising machinery did not.\n\n## Tante reads the essay\n\nMy first article drew on author and sociotechnologist Jürgen Geuter, known online as [tante (@[email protected])](https://tldr.nettime.org/@tante), and his essay “[Hiding behind translations](https://tante.cc/2026/02/03/hiding-behind-translations/).” Enzor-DeMeo’s new essay almost repeats tante’s earlier analysis: AI has no fixed definition, translation is classical machine learning, and generative AI is only one subset. Yet the CEO reaches the opposite conclusion: people left translations enabled. I asked tante to assess the essay.\n\n“Enzor-DeMeo’s article is a strange kind of PR,” he told me. The CEO uses the isolated sentence “Almost nobody used it” as a lever to deflect criticism of Mozilla’s AI focus. “But of course the argument is dishonest: people do not see translation as AI, but Mozilla embedded it in the button, and so AI remains active.” In tante’s view, the kill switch does not give people the “choice and agency” Enzor-DeMeo claims: “Because that would mean meeting people where they are, in their understanding and needs, rather than presenting them with a false choice.”\n\nThe CEO’s own recognition that AI is unpopular does not make his case any stronger in tante’s view. “But it never occurs to him to make all this shit opt-in. Because AI is his only strategy for a company that, as a browser maker, ought to care more about the web.”\n\n## The most important switch\n\nTo be fair, Firefox is measurably better than it was in the spring. According to [StatCounter](https://gs.statcounter.com/browser-market-share), its market share rose from 2.29 percent in February to 2.98 percent in August. Its first launch is substantially quieter, its AI switch covers more features, and the implementation remains sound. The tone from the executive suite is new too. It has been a long time since a Mozilla CEO publicly admitted to missing the message.\n\nOnly the boundary of the switch has not moved by a millimeter. It disables generative features, and nothing else. Telemetry continues with persistent identifiers. Advertising is delivered, affiliate domains are resolved, experiment assignments remain, and the browser contacts its first AI infrastructure before the user can even see the switch. “The most important AI feature may be the ability to turn it off,” Enzor-DeMeo writes. The sentence is true. It merely describes a feature Firefox still does not possess in that broader sense. Anyone who seriously wants to control what the browser sends home still needs `about:config`\n\n, Wireshark, and a healthy dose of suspicion.\n\nThe next step is obvious. A browser that asks on first launch whether its user wants generative features would solve the discoverability problem identified in the LinkedIn comments and turn “choice and agency” into a genuine opt-in instead of a buried opt-out. The technical infrastructure exists; the switch itself proves that. What is missing is the willingness to risk hearing the users’ answer.\n\nThe final word belongs to tante. Enzor-DeMeo concludes that Firefox users taught him something enormously valuable: that an escape hatch, an option, is the most important thing. Tante’s reply is brief: “No. The most important thing would be not to build systems that your user base despises.”", "url": "https://wpnews.pro/news/firefoxs-ai-switch-is-off-telemetry-isnt", "canonical_source": "https://marius.blog/firefox-155-ai-kill-switch-retest/", "published_at": "2026-09-02 12:50:14+00:00", "updated_at": "2026-09-02 13:24:23.696995+00:00", "lang": "en", "topics": ["ai-policy", "ai-products"], "entities": ["Mozilla", "Firefox", "Anthony Enzor-DeMeo", "Marius", "Wireshark", "Pew Research"], "alternates": {"html": "https://wpnews.pro/news/firefoxs-ai-switch-is-off-telemetry-isnt", "markdown": "https://wpnews.pro/news/firefoxs-ai-switch-is-off-telemetry-isnt.md", "text": "https://wpnews.pro/news/firefoxs-ai-switch-is-off-telemetry-isnt.txt", "jsonld": "https://wpnews.pro/news/firefoxs-ai-switch-is-off-telemetry-isnt.jsonld"}}