Protecting Privacy in an AI Era

Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.

Paper.

Posted on July 16, 2026 at 10:34 AM6 Comments

Comments

Tris Simondsen July 16, 2026 1:17 PM

Solove is entirely correct that the “user control” paradigm is dead. But shifting to “corporate accountability” and “algorithmic liability” introduces a massive verification problem: How do you formally audit the inferences of an autonomous AI?

In classical software, data minimization is a database problem; you simply restrict the fields you collect. In AI, this approach fails. A model can infer latent, highly sensitive attributes from seemingly innocuous observations. You cannot regulate this effectively at the point of collection; you must regulate the epistemic boundary of the agent itself.

If we are to enforce “rigorous data minimization” in an AI era, we need a mathematical architecture for zero-trust inference – the Principle of Epistemic Sovereignty (PES):

https://trissimondsen.wordpress.com/2026/07/16/the-principle-of-epistemic-sovereignty-formalizing-the-zero-trust-boundary-in-ai/

PES treats data minimization not as a policy preference, but as a strict measure-theoretic constraint. It requires that an agent’s posterior inferences depend only on a strictly authorized, F-measurable information interface. If an algorithm’s output relies on “outside-F” dependencies—smuggling in latent, unobservable completions to make its inferences, it violates the Non-Circularity Principle (NCP).

Under this framework, a structural breach of the epistemic boundary isn’t a vague “negligent design” issue; it is a mathematically provable violation of the agent’s authorized interface.

If we want Solove’s vision of algorithmic liability to survive contact with frontier AI, we must move past legal definitions of privacy and establish verifiable, F-measurable boundaries on what a system is mathematically licensed to “know.”

Rontea July 16, 2026 2:19 PM

The modern man, crowned with algorithms and burdened with illusions of control! He believes that by clicking ‘I agree,’ he becomes the sovereign of his own privacy. Yet, in truth, he is a pilgrim wandering through a bazaar of mirrors, where merchants of data weigh his soul in megabytes and sell it by the fragment. Our age, enamored with artificial intelligence, forgets that the intelligence of the human heart is fragile and easily betrayed. The law that trembles before profit is like a priest that blesses the thief. Until companies are made to feel the sting of consequence, our liberty will remain a shadow on the wall of their server rooms.

lurker July 16, 2026 2:24 PM

from the Paper

One example is the right to delete, which allows individuals to ask businesses to erase data they have collected on them. Long part of the data-protection law of the EU, right-to-delete was considered un-American and a nonstarter in the U.S. Now, it is in every state consumer-privacy law, and it isn’t controversial at all.

But they used to say when it’s on the ‘net, it’s there forever. There was even a meme from waay back said

Real men don’t do backups. They just tar-zip it in 1GB chunks, label it donkey-pr0n-nnn, and put it up on anonymous ftp. When they need it a quick search will find it …

ResearcherZero July 18, 2026 2:34 AM

Governments are giving your personal information and private records to companies so that the data can be mined for a variety of reasons and these companies profit enormously by exploiting this data for other profit streams.

This endless supply of data allows tech companies to further develop their products without having to interact with those the personal data belongs to, nor respect their wishes or property. Ownership is flatly ignored.

In Britain for example, Palantir has been given unlimited access to health records. In the United States it has contracts to provide ICE with the means to search through personal date to identify targets to detain and deport. Further access to personal information is obtained by companies like Palantir, through contracts they hold with data brokers and the numerous other companies, that provide your personal information to these data aggregators.

This trade in personal information between businesses and government, completely bypasses the ability of citizens to control how their personal data is accessed and used. Your most private information is contained within these records. Financial and taxation details, health records and consultation notes, educational records, communication, travel, purchasing and employment history. Alongside this data sits all of your family and personal identifiers, such as address, contact details, license plate and registration, age etc.

Your life and movements can be tracked and analysed at the granular level, overlayed with countless other data sources, then used to infer or predict patterns of behavior and interactions with people, objects and places.

This data is traded globally. There are few controls, if any, on how or who can use and abuse this data.

DHS has a contract with Thomson Reuters to access its CLEAR database.

‘https://www.yahoo.com/news/politics/articles/ice-plans-125-million-thomson-184157977.html

The CLEAR database is integrated with Palantir’s surveillance tools to comb for personal data.
https://harici.com.tr/en/thomson-reuters-data-aids-palantir-and-ice-in-targeted-deportation-efforts/

ICE is using personal information provided by data brokers after it was blocked by the courts.
https://www.npr.org/2026/04/21/nx-s1-5786915/ice-immigration-enforcement-data-thomson-reuters

Palantir has additional access to private records via contracts with other departments and businesses.
https://www.computerweekly.com/news/366645878/Palantir-Can-anyone-else-do-what-it-does

To lazy for a name July 19, 2026 5:16 AM

Well, even simple product developers often do not care about privacy. Tested a product just now.

The EULA was a mobile privacy policy that didn’t match the product. Its content didn’t align with the actual behavior of the software. Automatic opt-in, no opt-out and the program itself referred to a different privacy policy (mobile one which also didn’t fit the program) containing trackers. On top of that, data was already sent out before users could even agree.

Unfortunately, that’s just everyday reality in software. And it starts right there.

Whether it’s AI or not.

Irresponsibility among developers. Many of them lie, cheat and make excuses when it comes to user data. Even in europe with under GDPR. Inquiries are ignored and you get threatened or insulted when exposing it.

The worst part is that only a small target clientele is interested in this type of information, and even fewer actually take action with authorities or official complaints. Developers sometimes don’t even know how their own program behaves and even there, many simply don’t care.

People often don’t even understand what it is about and cannot even imagine the scale of it. Yet, it starts with the little things. With the daily use of software on their own devices.

The bureaucracy there has failed as well. Laws like GDPR are paper tigers and many of the culprits are based in the US or other countries where they cannot be held accountable. Fines are

And in America, there seems to be no resistance against the big tech companies and politics who support them. Otherwise, corporations like Microsoft, Meta/Facebook, Amazon, Palantir, Oracle, Adobe, Google or even all the new AI companies wouldn’t be able to just do whatever they want.

The system only protects data one-sidedly. Specifically, that of the people who have power and capital.

And the big criminals of the Big Tech companies are all walking free. Fines for those culprits are also ridiculously low to non-existent.

Nobody is in prison or has been severely punished. Not even for the structural destruction of nature, illegal data collection and processing, water wastage or data scandals of any kind. On the contrary, these individuals even get special privileges, while normal citizens pay double and triple.

How can that be?

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.