The Commonplace
Home Three-study pilot Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

Advanced AI lets innocuous data reveal sensitive traits and hands inferential power to non‑firms, creating hard‑to‑anticipate privacy harms; regulators and companies must shift from data‑access rules to policies that target predictive uses and the diffusion of inference capabilities.

When the Vault is Never Opened: AI‐Enabled Inference and the Future of Consumer Privacy
Aaron R. Brough · September 14, 2026 · Consumer Psychology Review
openalex review_meta n/a evidence 8/10 relevance Summary only summary available; pdf_status=paywall DOI Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

OpenAlex

Latest observation:

  1. Aaron R. Brough provider ID
AI raises privacy risks by enabling accurate inferences of sensitive traits from seemingly harmless data and by decentralizing inferential capability beyond firms, producing novel harms that current governance and corporate risk frameworks do not address.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Abstract Most research on consumer privacy assumes that privacy risks stem from unauthorized access to or misuse of sensitive consumer data. This review highlights the need to reassess consumer privacy in response to two ways in which artificial intelligence (AI) is transforming consumer privacy risk. First, AI widens the gap between what consumers intentionally reveal and what can be inferred about sensitive attributes from seemingly nonsensitive information. This increases the risk that privacy harm may arise even when sensitive data were never requested, disclosed, or accessed but instead inferred. Second, AI expands inferential capacity beyond firms to other consumers and non‐firm actors, increasing the risk of interpersonal privacy violations. Building on these arguments, I illustrate five types of AI‐enabled privacy harm and show how each can arise across organizational and interpersonal contexts. Given consumers' limited ability to anticipate, observe, or control AI‐enabled inferences or their consequences, these emerging risks create new challenges for privacy theory, management, and regulation while raising important questions for future research on consumer privacy.

Summary

Main Finding

AI materially changes consumer privacy risk in two fundamental ways: (1) it widens the gap between what consumers intentionally disclose and what sensitive attributes can be inferred from seemingly nonsensitive data, and (2) it decentralizes inferential power, enabling not only firms but also other consumers and non‑firm actors to derive sensitive inferences. These shifts create new, hard‑to‑anticipate privacy harms that challenge existing theory, management practice, and regulation.

Key Points

  • Two core transformations from AI:
    • Inferential amplification: advanced models can predict sensitive traits (health, political views, sexual orientation, etc.) from data consumers consider harmless (browsing patterns, images, purchase histories).
    • Diffusion of capability: inference is no longer exclusive to firms with proprietary data; third parties (other consumers, hobbyists, open‑source developers, adversaries) can combine publicly available signals and models to draw sensitive inferences.
  • Consequence: privacy harms can occur without any explicit disclosure or unauthorized access to sensitive data — harms arise from inferences.
  • The paper organizes emerging harms into five AI‑enabled types (illustrated across organizational and interpersonal settings). While the abstract does not enumerate them, the paper treats harms that include inference‑driven discrimination, reputational exposure, interpersonal violations (stalking/blackmail), automated mistreatment based on inferred traits, and aggregation/reidentification risks.
  • Consumers face limited ability to anticipate, observe, or control these inferences and their downstream uses, creating practical enforcement and governance problems.
  • These developments require rethinking privacy definitions, measurement, corporate governance, and regulatory tools.

Data & Methods

  • Paper type: conceptual review and theoretical synthesis (literature review), not original empirical estimation.
  • Methods used:
    • Review and integration of interdisciplinary literatures on privacy, inference, and AI capabilities.
    • Conceptual framing: distinguishing organizational vs. interpersonal contexts and mapping how AI advances interact with each.
    • Illustrative examples to show how each type of harm can manifest across contexts.
  • No new datasets or econometric identification strategies are reported in the abstract; the contribution is primarily analytic and normative.

Implications for AI Economics

  • Market failures and externalities:
    • Inference externalities: consumers’ nonsensitive signals can create negative externalities when others infer traits, lowering welfare but not reflected in market exchanges.
    • Information asymmetry widens: firms may be able to extract value from inferences that consumers neither understand nor can price, complicating models of consumer surplus and privacy valuation.
    • Competition and entry: democratization of inference reduces firms’ informational exclusivity, altering incentives for data collection, investment in proprietary data, and market power dynamics.
  • Measurement and modeling challenges:
    • Standard economic models that treat privacy as control over revealed attributes are incomplete; need models where unobserved inferences alter probability distributions over consumer types and decision utilities.
    • Valuing privacy must account for inferential risk (probability and harm of downstream uses), not just probability of direct disclosure.
  • Policy and regulation implications:
    • Existing data‑centric regulations (focused on access or explicit categories) may miss harms arising from inferences; regulators may need to cover inferences as a regulated class.
    • Potential policy tools: limits on certain predictive inferences (especially for sensitive traits), obligations to disclose inferential uses, algorithmic audits, liability for harmful uses of inferences, data‑use restrictions that consider derivative inferences, and incentives for privacy‑protecting technologies (e.g., differential privacy, federated learning).
    • Enforcement must grapple with attribution problems (who inferred what) and cross‑actor harms (non‑firm actors).
  • Research agenda for AI economics:
    • Quantify inferential risk: how often and how accurately sensitive attributes can be inferred from common nonsensitive data streams.
    • Welfare analysis: how inference‑driven harms affect consumer surplus, market outcomes, and social welfare under different regulatory regimes.
    • Mechanism design: contracts, disclosure regimes, and marketplace institutions that internalize inference externalities.
    • Empirical study of diffusion: how open models and public data change the distribution of inferential power across actors and markets.
    • Policy evaluation: cost–benefit of banning certain inferences vs. alternative interventions (liability, transparency, consumer control).
  • Practical implications for firms and regulators:
    • Firms should reassess risk management to include downstream inferential harms (even from ostensibly harmless data).
    • Regulators should consider inference‑aware frameworks, focusing not only on data categories but also on predictive uses and third‑party capabilities.
    • Consumer protections may need to expand to address interpersonal privacy violations enabled by AI (e.g., stalking, doxxing) in addition to firm behavior.

Assessment

Paper Typereview_meta Evidence Strengthn/a — This is a conceptual literature review and theoretical synthesis that presents arguments and illustrative examples rather than original empirical tests or causal identification; therefore there is no empirical strength to rate. Methods Rigormedium — The paper shows clear conceptual framing (e.g., inferential amplification and diffusion of capability) and integrates interdisciplinary literatures, but it does not report systematic review protocols, empirical measurement, or formal identification strategies; claims rely on synthesis and illustrative cases rather than reproducible empirical analysis. SampleNo original dataset; the paper synthesizes interdisciplinary literature on privacy, inference, and AI capabilities and uses illustrative examples and case studies to demonstrate harms across organizational and interpersonal contexts. Themesgovernance org_design GeneralizabilityNo empirical quantification of prevalence or magnitude, so applicability across sectors and populations is uncertain, Rapidly evolving AI capabilities could change the specific inferences and actors implicated, Jurisdictional and institutional differences (privacy laws, enforcement capacity) limit direct policy transferability, Illustrative examples may not be representative of typical consumer experiences, Recommendations are high-level and may not map cleanly to sector-specific constraints or technological architectures

Claims (10)

ClaimDirectionOutcomeConfidence & EvidenceDetails
AI increases the gap between what consumers intentionally disclose and what sensitive attributes can be inferred from seemingly nonsensitive data. Consumer Welfare negative Consumer privacy risk from inferential disclosure
Reading fidelity high
Study strength low
not reported
0.12
AI enables sensitive traits such as health status, political views, and sexual orientation to be predicted from data consumers may regard as harmless. Ai Safety And Ethics negative Accuracy and availability of sensitive-attribute inference from nonsensitive data
Reading fidelity high
Study strength low
not reported
0.12
AI diffuses inferential power beyond firms with proprietary data, enabling other consumers, hobbyists, open-source developers, and adversaries to derive sensitive inferences from public signals and models. Market Structure negative Distribution of inferential capability across actors
Reading fidelity high
Study strength low
not reported
0.12
Privacy harms can occur without explicit disclosure of sensitive information or unauthorized access to sensitive data because harms can arise from inferences. Consumer Welfare negative Occurrence of privacy harm through inference
Reading fidelity high
Study strength low
not reported
0.12
AI-enabled inferences can create harms including discrimination, reputational exposure, stalking or blackmail, automated mistreatment, and aggregation or reidentification risks. Ai Safety And Ethics negative Types of privacy and social harms caused by AI-enabled inference
Reading fidelity medium
Study strength low
not reported
0.07
Consumers have limited ability to anticipate, observe, or control AI-driven inferences and their downstream uses. Consumer Welfare negative Consumer ability to anticipate, monitor, and control inferential uses of data
Reading fidelity high
Study strength low
not reported
0.12
Consumers’ nonsensitive signals can generate inference externalities that reduce welfare without being reflected in market exchanges. Consumer Welfare negative Consumer welfare effects of third-party inferences
Reading fidelity high
Study strength speculative
not reported
0.04
The democratization of inference reduces firms’ informational exclusivity and may alter incentives for data collection, investment in proprietary data, and market power. Market Structure mixed Firm informational advantage, data-investment incentives, and market power
Reading fidelity high
Study strength speculative
not reported
0.04
Existing data-centric regulations may fail to address harms arising from AI-generated inferences rather than direct access to or disclosure of protected data. Governance And Regulation negative Coverage and effectiveness of privacy regulation
Reading fidelity high
Study strength speculative
not reported
0.04
Effective enforcement of AI-enabled inference harms is complicated by attribution problems and by harms caused by non-firm actors. Governance And Regulation negative Enforceability and attribution of responsibility for harmful inferences
Reading fidelity high
Study strength speculative
not reported
0.04

Notes