Berkman Klein fellows: bake AI privacy into the architecture
TL;DR
- Two Berkman Klein fellows argue purpose limits belong in AI system architecture, not in contracts or privacy statements.
- Their framework has three parts: purpose limitations, accountable deployment, and transparency with genuine user control.
- They point to FTC settlements against Rite Aid, Drizly, GM and Amazon Alexa as the existing enforcement backdrop for AI privacy.
Purpose limits belong in the code, not the contract. That is the argument Isabel Hahn and Aaron Alva, both Fellows at the Berkman Klein Center for Internet & Society at Harvard University, make in a TechPolicy.Press essay laying out three principles they say should govern AI compliance: purpose limitations, accountable deployment, and transparency with use control.
"Purpose limitations must become architected into AI services, and not merely contractual," the authors write, calling for technical constraints on which tools an agent can call, which data sets it can retrieve, and whether outputs can be used for training. Their framing of agents is blunt: "That shifts AI into a category closer to delegated action, where the user is not controlling nor even observing each action."
The concrete asks are product-level. For services that store memory, Hahn and Alva want "memory dashboards that surface what the AI system remembers and allow users to edit or delete it," plus permission receipts explaining what data an agent accessed and pre-action confirmations before an agent sends a message. They point to FTC settlements against Rite Aid on pre-deployment testing, Drizly on data minimization, GM on connected-services disclosure, and Amazon Alexa on deletion rights, alongside guidance from privacy regulators in the UK, EU, Hong Kong, Singapore and Australia.
The piece closes on the alignment claim: "Unlike the internet advertising economy, where privacy and profit have often been in tension, AI presents an opportunity to align them."
Shared on Bluesky by 2 AI experts
-
Regulators aren't treating AI as an exotic category outside privacy law, write Isabel Hahn and Aaron Alva. They're identifying where familiar principles get harder to operationalize as systems infer, remember, and act.
View on Bluesky →
Originally reported by techpolicy.press
Read the original article →Original headline: Privacy by Architecture Makes AI Compliance Work