AI systems can create sensitive attributes that a person never disclosed and cannot meaningfully inspect.
Privacy in the Age of AI
The death of anonymity and inference control
If an AI can infer what you never disclosed, what exactly did you consent to?
Privacy moves beyond secrecy toward contextual integrity, inference, aggregation, biometric identification, differential privacy, and the ability to contest information flows.
Join the live roomBefore class
Map one everyday AI information flow: actors, attributes, transmission principle, inferred data, and consequence.
After class
Revise the flow with one technical safeguard, one institutional safeguard, and one remedy.
The promise
By the end of this room…
- 01Apply contextual integrity to an AI information flow.
- 02Explain re-identification, inference, and aggregation risk.
- 03Interpret differential privacy as a governance choice as well as a technical guarantee.
- 04Design consent, purpose limitation, and deletion around derived data.
Why this week now
Signals, not scene-setting.
Privacy-preserving statistics redistribute error and utility; the budget is a public choice, not a magic setting.
Biometric search exposes the gap between formal deletion orders and global enforcement capacity.
Run of show
Provoke → frame → work → argue → synthesize.
- 0:00provocation
Commit before the concepts
A system accurately infers a sensitive fact from data you knowingly shared. Was your privacy violated?
Live activity · week 4 opening - 0:15frame
Privacy is an information-flow norm
AI systems can create sensitive attributes that a person never disclosed and cannot meaningfully inspect.
- 0:45discussion
Reading tension
Student leaders present the assigned readings as a clash of defensible positions, then moderate questions that expose the hidden assumptions.
- 1:10frame
From anonymity to inference control
Privacy-preserving statistics redistribute error and utility; the budget is a public choice, not a magic setting.
- 1:35break
Break
Ten minutes. Leave the room's unresolved question visible.
- 1:45forensics
Clearview × Census disclosure-avoidance lab
Role-based groups work the anchor case through technical, legal, stakeholder, and normative lenses.
Deliverable · A two-minute finding with evidence, uncertainty, and an actionable remedy.Live activity · week 4 forensics - 2:25controversy
Age-verification structured controversy
Assigned positions, side-switch, and a joint recommendation that names the value or stakeholder it leaves exposed.
Live activity · week 4 controversy - 2:50synthesis
Re-vote and leave a trace
Repeat the opening vote, inspect what moved, and submit the strongest argument you still reject.
Live activity · week 4 exit
Case room
Evidence before opinion.
Clearview AI
Can consent and deletion be enforced after a global biometric index exists?
2020 Census differential privacy
Who bears utility loss when privacy is protected statistically?
Reading stack
Read the tension, not the bibliography.
- 01CorePrivacy as Contextual Integrity ↗
Helen Nissenbaum
- 02CurrentDisclosure Avoidance and the 2020 Census ↗
U.S. Census Bureau
Evidence ledger
Every case has a receipt.
3 primary, scholarly, or first-party sources
Privacy as Contextual Integrity
Nissenbaum reframes privacy as appropriate information flow within social contexts.
Privacy framework ↗Disclosure Avoidance and the 2020 Census
A real deployment of differential privacy with measurable privacy–utility and representation trade-offs.
Technical program record ↗Clearview AI ordered to delete facial recognition data
A cross-jurisdictional case about scraping, consent, biometric inference, and enforcement limits.
Regulatory finding ↗