Of course you're right, but bugs in third-party software using your APIs should not cause security issues in stuff you introduce later. Using whitelisting/opt-in vs blacklisting would solve this.
I already don't like how many operating systems retroactively dealt with passwords on the clipboard. "Sensitive" should've been the new default. Passwords aren't the only thing either. If I'm using some app or software that is either messaging, financial, or something medical, even if it just tracks my period, anything I copy originating from there should be treated as sensitive.
Soon you won't be able to write family members "hey, the results are in and I've got testicular cancer" without some data-kraken like Microsoft gobbling that up and feeding it to their AI.
Next thing you know some AI sneaks that into a company-wide mail "Quarterly Results" at your mother's place of work, because your mother has trouble using computers and is happy AI can write mails for her now. If that sounds unlikely to you, then to illustrate here's ChatGPT making that exact mistake:
https://chat.openai.com/share/0130c72e-aa51-4042-b0d0-d12101...