Figure 1. West Texas Landscape, January 2026.

Talk

"There will be less privacy, of course": How and Why People in 10 Countries Expect AI Will Affect Privacy in the Future

Conference Talk, Symposium on Usable Privacy and Security (SOUPS), 2023 · August 8, 2023

39 slides · ~2,400 words · ~12 min

Paper"There will be less privacy, of course": How and Why People in 10 Countries Expect AI Will Affect Privacy in the Future →

Cite the paper
@inproceedings{kelley2023there,
  title     = {"There will be less privacy, of course": How and Why People in 10 Countries Expect AI Will Affect Privacy in the Future},
  author    = {Kelley, Patrick Gage and Cornejo, Celestina and Hayes, Lisa and Jin, Ellie Shuo and Sedley, Aaron and Thomas, Kurt and Yang, Yongwei and Woodruff, Allison},
  year      = {2023},
  booktitle = {Proceedings of the 19th Symposium on Usable Privacy and Security (SOUPS '23), 579–603, 2023},
  url       = {https://pgk.io/papers/2023-there-will-be-less-privacy-of-course-how-and-why-people-in/},
}

Below, is an approximate summary of what I said at SOUPS 2023, presenting a piece of our global AI attitudes survey work, cleaned up for readability.

Hi everyone, I’m Patrick Gage Kelley, a researcher with Trust & Safety at Google, presenting our work from Ipsos & Google, on how people felt about AI affecting their future.

At Google right now — and maybe in many of the places you work, or in the conversations you’re having — you might be hearing a lot about AI. We are too. And we find that it’s interesting to think about AI, and to ask people what they are thinking about AI. When we do that, people bring up many different topics. They don’t just talk about privacy, like some of us here at SOUPS might prefer or hope — they talk about how AI is going to impact healthcare, education, sustainability, all sorts of things AI is going to have some impact on. In some past work we did, we found that something between 90 and 95% of people around the world believe that AI is just going to have huge impacts on society in the future.

For this work, we wanted to dig into privacy specifically. We asked participants:

In the next 10 years, what do you think will happen in [your country], we filled in the blank, because of Artificial Intelligence?

And framing this towards privacy, their choices were: more privacy, less privacy, no change, or don’t know.

We did this in 10 countries, which you can see on this map.

Two important caveats here.

  1. This data was collected about two years ago now — in the summer of 2021 — which means this was before ChatGPT was widely a media darling, before the generative-AI revolution that’s happening now.
  2. This was before Russia invaded Ukraine. If that had already happened, we wouldn’t have done this survey work in Russia — but Russia is one of the countries in this sample, we have and analyzed those Russian responses.

All of this was conducted in-language, through online panels, which means that everything you’ll see throughout the rest of this talk is in translation — these are the English translations that we used, and we’ll come back to that in a few minutes.

So for one example: if we go back to that question — what’s going to happen because of AI in 10 years — in Germany, of our respondents, about a thousand people in Germany, ~10% said they would have more privacy because of AI. The optimists. And ~56% said they would have less privacy, and the rest said they weren’t sure.

If we take out those “no change” and “don’t knows” — say, okay, we’re not going to count the people who don’t have strong opinions about what AI is going to do — we can think of the rest of this as a ratio of about 0.18.

And if we look at this across all of the countries we surveyed — across all 10 countries — privacy was generally expect to get worse by ~49% of all respondents. And only made better by ~22%. Which means Germany was a little bit below the (more) optimistic average, here with a ratio of 0.45.

And if we look across all of the other societal implications that I mentioned earlier, we see that privacy has the smallest ratio here, or the worst negative-to-positive impact. So again, we look across 10,000 peoples responses, we see that privacy is one of the things they think will be most negatively impacted by AI — as opposed to things like education, or healthcare, or transportation, or general quality of life. In fact, across the surveys of AI that we’ve been doing for several years now, in these 10 countries and others, we actually see that people are quite optimistic about AI — even when there are things they’re continually worried about: like job loss, like privacy, like AI harming people’s ability to interact with other humans.

But as people are quite positive about AI, and privacy is a noted weakness — we wanted to dive deeper into this question of how AI is going to impact privacy, we asked directly:

In what ways will Artificial Intelligence affect privacy in the future? Please be specific.

We collected open-ended responses from just over 9,800 people. Working with our partners at Ipsos, we coded each of those responses in-language — so if they were originally written in Russian, they were coded by a Russian speaker — based on a codebook of 368 codes.

This means we had a total corpus of ~100,000 words where people were saying this is how I feel AI is going to affect privacy — about 10 words per response overall; of course some of these are very short, others are much longer — and we assigned over 24,000 codes.

For reviewers out there who respond to my papers with things like why didn’t you have two coders and just calculate an inter-rater reliability? Using in-language experts, means we have many people doing this coding, not just two grad students doing the whole thing, so we use a different system of quality checks to make sure this data is valid; those are described in more detail in the paper.

Overall, if we look at response quality:

~75% of respondents expressed something we think of as a privacy statement.

~18% said something that was like an “I don’t know” or “it won’t” or something else we were unable to code.

And ~8% were other, unrelated answers — these include things like the robots are going to come kill us all, and while we love to know what people are thinking, that’s not actually about privacy, so it doesn’t get coded as a privacy statement.

From that 75% of responses, we looked across the codes, we read their responses, we discussed various themes, we did some bucketing, and we landed on four different themes that we saw around privacy.

So, the first theme is data at risk. Overall, respondents felt that AI needs lots of data to be successful, and so it’s going to be gathered from multiple devices, it’s going to be cross-linked, it’s going to be aggregated, it’s going to be made available online — and this making it available and putting it together makes it vulnerable to misuse and hackers.

I’ll be sharing quotes for each of our themes. You can look at things like AI needs data — people saying it requires a lot of human data; that for machines to think, they must analyze and base their decisions on data. People understand these AI systems need a lot of data to function.

We see people responding that it requires multiple, connected sources — it’s on their phones, it’s on the internet, it’s on every device: the AI knows what I’m doing at all times

And all that data is cross-linked and brought together.

So we see participants saying things like they can use this to take innocuous information from the internet to gain insight into the lives of people and reveal things.

This also means that data is available. We have a participant here saying I’m afraid there will be some glitch in the system and all my information will be open to a stranger — or a big leak of data that could put this data out into the open space of the internet.

And worse — they know it’s not just mistakes or accidental data leaks, but it could be available to hackers. Hackers will understand there are these huge amounts of data.

Our second theme is highly personal. This isn’t just collecting lots and lots of data — it’s not just scraping Wikipedia and Reddit. Respondents understood this was from highly personal data that could be used to develop precise personal insights.

So we see people describing:

it’ll brazenly violate personal life

it’ll collect our words and our actions down to the smallest detail.

And we also understand — not just that it’s collecting personal data about you, but that it’s going to reveal personal insights, it’s going to reveal you, it’s going to find patterns from that data.

It’s going to pull in these understandings of ourselves — sometimes, people thought, in ways that we might not even understand ourselves, something we’ve commonly heard across privacy research.

This will be used, potentially, by companies to influence decisions and behavior:

large corporations will ruthlessly use AI to market their products or services to a wider demographic; it’ll be impossible to resist the advertising.

Our third theme is without consent. Overall — and you can see all the numbers for this by country in the paper; all four of these themes came up in every country we looked at data from — this one was the most uncommon of the four themes, but respondents did feel, and sometimes mention, that scaled personal data collection occurs without meaningful consent, sometimes without awareness, and that data provision is a requirement to get access to these services.

So effectively: if you want to use these services, you must give out your data — and in many cases you can’t use a service that might be AI-powered without using that AI part of it; the AI is just a piece of it, and you sort of must do it.

People’s data will be invaded whether they know and give their consent or not.

Invasion of privacy by spying on me without my consent.

It’s beyond what the majority of people will know — companies will use our data and we won’t even know. The ideas is that we can’t even really give consent, because most people don’t know this is happening, or understand what is really happening.

The useful features will be available in exchange for the disclosure of personal information — that it requires people to reveal themselves.

Our final theme is state and surveillance. While we’ve talked a bit already about corporations, using insights for capitalist reasons, our respondents also identified many ways that AI could be used by governments to support surveillance and monitoring.

So: AI conducts surveillance;

AI will be the ultimate spy;

I feel like I’m being monitored at all times; it’s like a device with eyes and ears that is watching you 24/7 and storing your personal information.

AI is omnipresent — it’s there all the time, on all the time, it’ll be monitoring everything.

AI identifies people — we see the idea of facial recognition being able to automatically identify, more accurately, individuals.

And AI serves state purposes:

the use of machines to determine a person’s risk to the country;

details about all citizens will be collected;

it’s possible to spy on the population even more easily than now.

So overall, this is a summary of the four themes we saw, with all the descriptions of the concepts we saw within those themes.

I want to frame a few takeaways from this work.

Our first takeaway is that people had, overall, really thoughtful responses. The narratives, the language we saw here, was aligned with popular press, aligned with expert opinion, and aligned with policy briefs. There are, of course, people who had vague and fuzzy concepts — these are open-ended responses, we weren’t asking them about a list of things, we weren’t testing their knowledge of these concepts — but we saw really thoughtful understanding about what AI is doing, and these main themes are not contradictory: they make sense and they align with many of the concerns experts have stressed.

We see this both as a way to say: in a lot of privacy research, people don’t understand things — whether it’s how encrypted email really works or how to configure privacy or security settings; we’ve seen this throughout the talks today. This is one where people really do seem to be developing, at least at a broad level, a sense of what AI is doing with their data and what it needs to function, and what it might mean for society.

Which means we believe we can engage people with solutions. We think this is a great moment for civic participation, because people are not completely uninformed — they do have a good sense of what AI might be doing, and some of the basics of how it uses data or how consent is given (or not). So whether we’re building privacy-enhancing technologies to prevent some of these harms, whether we’re thinking about educational efforts, whether we’re thinking about participatory design work — we should bring people into those conversations, because they have an interest in AI, and they have pretty good mental models that align with the ways we, as experts, might be thinking about some of these questions.

We also tell our product developers at Google, and our product teams — as well as the community — that we think this is a great way to look at these four concerns: as a roadmap for when we’re developing AI systems. If you think through these concerns as the things that might limit people’s use of an AI system, or their comfort with one — how are we going to use these themes to say, well, here’s where you actually do have consent to turn this on, or to have it be on but not necessarily have access to all of your data; here are ways where you can say, these are the limits we have on the government use of this type of AI system. These are ways to address the concerns people have.

And finally — although I didn’t get into it today in the talk, there’s more in the paper — ~22% of our respondents thought they would have more privacy because of AI, in the open-ended responses. About 12% said something free-form, unprompted, about how AI might help fight hackers, or help build new crypto systems, and other solutions they proposed. I think this is a great moment where we can leverage this. This isn’t just an optimistic halo effect — people are very excited about AI; they were not as excited about AI with privacy — but where are the moments where we can get them excited about AI as a way to protect their privacy, or as a tool to help them?

Here’s just a summary of all the themes and the takeaways on one slide.

And with that, I would love to take questions for a minute or two. Thank you so much.

← Back to Talks