Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts

Honorable Mention
Explainable AI (XAI)Privacy by Design & User ControlPrivacy Perception & Decision-MakingUI/UX DesignersAI/ML Researchers & EngineersPrivacy Policy Makers

Paper Title

Privy: Envisioning and Mitigating Privacy Risks for Consumer-facing AI Product Concepts

Publication Info

  • Topic area: Privacy risk assessment and mitigation in AI product development.
  • Keywords: Privacy impact assessment, AI privacy risks, generative AI, large language models, privacy engineering, privacy taxonomy, human-AI collaboration, risk mitigation, AI ethics, privacy awareness.

Background and Problem

  • Problem / challenge: AI systems exacerbate privacy risks, yet practitioners lack effective tools to identify and mitigate these risks, especially during early product development stages. Existing frameworks are generic, labor-intensive, and require privacy expertise.
  • Significance: Addressing privacy risks is critical to ensuring ethical AI development and compliance with legal standards, reducing harm to users and stakeholders, and fostering trust in AI products.
  • Motivation and related work: Prior research has explored privacy taxonomies, guidelines, and tools like PIAs, but these are often static, technology-agnostic, and poorly adapted to AI-specific contexts. Generative AI has shown promise in surfacing ethical concerns but has not been applied to privacy risk mitigation.

Solution

  • Proposed approach: Privy, a privacy risk-envisioning tool designed for non-privacy-expert AI practitioners, available in two versions: PrivyTemplate (static worksheet) and PrivyLLM (interactive, LLM-powered interface).
  • Novelty:
    1. Structured workflow linking AI product concepts to privacy risks and mitigation strategies.
    2. Integration of an AI privacy taxonomy tailored to AI-specific risks.
    3. Use of generative AI to enhance risk identification and mitigation brainstorming.
    4. Empirical evaluation demonstrating effectiveness in producing high-quality privacy impact assessments.
  • Procedure and key techniques:
    • Practitioners describe AI product concepts, brainstorm use cases, and summarize AI capabilities and requirements.
    • Identify privacy risks using an AI privacy taxonomy and prioritize them based on relevancy and severity.
    • Brainstorm mitigation strategies iteratively, supported by LLM-generated provocations.
    • Generate shareable privacy impact assessment reports summarizing risks and mitigation plans.

Results

  • Concrete findings:
    • Privy helped practitioners identify diverse privacy risks, with 76% rated as highly relevant and 65% as highly severe by practitioners themselves.
    • Privacy experts rated risks identified using PrivyLLM higher in relevancy (5.09 vs. 4.06), severity (5.46 vs. 4.49), correctness (5.22 vs. 4.04), and clarity (5.13 vs. 3.64) compared to PrivyTemplate.
    • Mitigation plans generated with PrivyLLM were rated higher in effectiveness (4.37 vs. 3.35), usefulness as conversation starters (4.69 vs. 3.42), product specificity (4.96 vs. 3.46), and practicality (4.42 vs. 3.42).
  • Advantage over baselines:
    • PrivyLLM significantly outperformed PrivyTemplate in expert-rated quality of privacy impact assessments.
    • Both versions were rated highly by practitioners for usefulness and usability, with no significant differences in perceived utility.
  • Experiments / evaluation:
    • Between-subjects study with 24 AI practitioners (12 per version) assessing two predefined AI product concepts.
    • Outputs evaluated by 13 privacy experts using a 6-point Likert scale for quality measures.
    • Mixed-methods analysis combining quantitative ratings and qualitative feedback.
  • Limitations and future work:
    • Limited to predefined product concepts; longitudinal studies with real-world teams are needed.
    • Time-constrained sessions may not reflect iterative development cycles.
    • Future tools should incorporate richer information for mitigation strategies and address organizational dynamics in privacy decision-making.

Summary

Privy is a novel tool that enables non-privacy-expert AI practitioners to identify and mitigate privacy risks in early-stage AI product concepts. By combining structured workflows with generative AI, PrivyLLM enhances the quality of privacy impact assessments, helping practitioners surface overlooked risks, validate reasoning, and brainstorm mitigation strategies. Empirical evaluation shows that Privy effectively addresses barriers of awareness, motivation, and ability in privacy work, empowering practitioners to engage critically with privacy-preserving AI innovation. Future research should explore longitudinal deployments, richer mitigation resources, and collaborative features to further advance privacy engineering practices.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/223335/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3791279
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
Honorable Mention
group
Authors
10 authors
sell
Subtopics
Explainable AI (XAI), Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
UI/UX Designers, AI/ML Researchers & Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers