The Impact of AI on Online Privacy: Understanding the New Risks
Online privacy used to revolve around being cautious about the information you shared. In the past, you had some control over what others could disclose about you, as much of that information was publicly accessible. If a friend posted an unflattering photo on Facebook, you could simply ask them to take it down. However, the landscape of online privacy has drastically shifted with the rise of conversational artificial intelligence (AI).
The Evolving Privacy Landscape
Conversational AI has changed the game significantly. Major technology firms might already know more about you than you’d like to admit—even if you’ve never directly used their services. Tools like ChatGPT and similar AI technologies collect and analyze vast amounts of data, creating complex profiles that can reveal unexpected insights about even non-users.
This issue extends beyond high-profile applications. Numerous chatbots and AI companions can personalize interactions, remember past conversations, and initiate dialogue, blurring the lines of privacy and consent. The very features that enhance user experience raise profound questions about privacy.
Information Shared Without Consent
Recent surveys illuminate a concerning trend: a significant portion of people are sharing personal details with chatbots. In Australia, for instance, a YouGov poll revealed that 15% of adults disclosed intimate thoughts or feelings to a bot, with 11% sharing secrets they’ve never told anyone. This trend is even more pronounced among younger users; the Australian eSafety Commissioner reports that 54% of children aged 10–17 have sought personal advice from chatbots.
These chat interfaces often feel like safe, private spaces, leading users to share not just their own experiences but also sensitive information about others. This can include colleagues, friends, family members, and more—who likely have no idea their personal details are being shared. For example, a colleague could paste your email into a chatbot to solve a work-related problem, exposing your private thoughts. This raises a critical privacy issue: non-users may be inadvertently affected by interactions involving those who do use AI.
Legal Reforms on the Horizon
The implications of AI tracking and profiling extend far beyond mere data collection. Such intimate knowledge could be leveraged in harmful ways, influencing individuals through targeted advertising or even shaping political beliefs. Recognizing this, Australia is contemplating two key sets of legal reforms aimed at safeguarding privacy.
The proposed privacy regulations would enforce fair and reasonable handling of personal information, including a “right to erasure.” This would allow individuals to request the destruction of their data from large digital platforms. Simultaneously, the draft digital duty of care amendment to the Online Safety Act would require online services to assess risks that arise from their usage. Together, these proposals offer a well-rounded approach to protecting privacy, but they also highlight a gap: how can you exercise your right to erasure if you don’t know what data exists about you?
Ensuring Effective Implementation of Laws
To address these challenges, we need to integrate privacy considerations into technology design. Conversational AI should be engineered to identify and discard sensitive information while fulfilling user requests. Providers should be mandated to implement technical solutions that ensure unnecessary user data—and data about third parties—is not retained.
Another critical aspect is that obtaining personal information for immediate responses does not justify its indefinite retention. If a user mentions another person while interacting with a chatbot, that information should not linger in the system for future use, including profiling or ads. This distinction is vital for safeguarding the privacy of everyone involved.
Additionally, data erasure shouldn’t hinge on having an account. Service providers should facilitate the tracking of information held about individuals, including those who haven’t interacted directly. Providing methods for users to request deletions must also be done with security in mind, ensuring sensitive matters—like discussions around domestic violence or whistleblowing—remain confidential.
Emphasizing Transparency
Finally, transparency is essential. Users shouldn’t have to rely solely on AI companies’ assurances about data handling practices. It’s important for these organizations to disclose how they detect, store, and reuse third-party information in a clear, public manner. Regular independent audits and testing can ensure that the safeguards in place are genuinely protecting user data.
As companies profit from user engagement and targeted advertising, they have an ethical responsibility to uphold these standards. The proposed digital duty of care can empower regulatory bodies like the eSafety Commissioner to enforce rules that enhance accountability in these technologies.
What we essentially require is not a ban on conversational AI but a proactive approach that places responsibility on those who create and maintain these systems. Users should be able to benefit from AI-driven tools without shouldering the burden of navigating the privacy risks posed to their lives and the lives of their loved ones.
Inspired by: Source

