What Security and Privacy Transparency Users Need from Consumer-Facing Generative AI Jiaxun Cao† , Yu Dong‡∗ , Chunxi Zhan‡∗ , Rithvik Neti† , Sai Teja Peddinti§ , Pardis Emami-Naeini†
arXiv:2604.17270v1 [cs.HC] 19 Apr 2026
† Duke University, ‡ Duke Kunshan University, § Google
Abstract
that such risks exist, their mental models of GenAI data practices are often inaccurate [10,48,56,57,91]. Prior work shows that users frequently overestimate the protections provided by GenAI companies [48, 56, 57]. For instance, mistakenly assuming that ChatGPT complies with the Health Insurance Portability and Accountability Act (HIPAA) when used for mental health support [48], or that OpenAI is responsible for ensuring privacy protections for third-party generative pretrained transformers (GPTs) [56]. These prevalent S&P misconceptions point to a gap in current GenAI transparency – users are likely receiving limited or ineffective communication about data practices and associated risks. Much of the current S&P transparency work around GenAI is oriented toward expert audiences, presuming substantially higher technical literacy than most end users. Examples include Google Model Cards [62], Meta System Cards [7], and IBM AI FactSheets [6]. Policy efforts in the U.S. (e.g., Colorado SB24-205 [4]) and beyond (e.g., the EU AI Act [35]) have also remained relatively limited, tending to emphasize organizational accountability and overlook requirements for consumer-facing S&P transparency [66, 67]. However, S&P transparency can shape consumers’ adoption decisions and post-adoption experiences [30, 33, 65, 80]. When transparency is reliable, actionable, and presented in forms that users can readily interpret and act on, it can support informed S&P decision-making and help build trust in the technology [65, 72]. For instance, prior work has proposed privacy labels that present salient information in a digestible format and impact users’ willingness to purchase Internet of Things (IoT) devices [32, 34, 44]. In the GenAI context, however, comparable empirical evidence remains limited – it is unclear whether, what, and how S&P information influences users’ adoption decisions and ongoing use of GenAI tools. Beyond S&P transparency content, prior work has articulated a broader design space spanning multiple dimensions [72], including timing [30, 39], channel [72], modality [86], and user control [74]. Each technology introduces distinct challenges and opportunities across these dimensions that must be accounted for when designing effective trans-
Users increasingly rely on consumer-facing generative AI (GenAI) for tasks ranging from everyday needs to sensitive use cases. Yet, it remains unclear whether and how existing security and privacy (S&P) communications in GenAI tools shape users’ adoption decisions and subsequent experiences. Understanding how users seek, interpret, and evaluate S&P information is critical for designing usable transparency that users can trust and act on. We conducted semi-structured interviews and design sessions with 21 U.S. GenAI users. We find that available S&P information rarely drove initial adoption in practice, as participants often perceived it as incomplete, ineffective, or lacking credibility. Instead, they relied on rough proxies, such as popularity, to infer S&P practices. After adoption, uncertainty about S&P practices constrained participants’ willingness to use GenAI tools, particularly in high-stakes contexts, and, in some cases, contributed to discontinued use. Participants therefore called for transparency that supports decision-making and use, including trustworthy information (e.g., independent evaluations) and usable interfaces (e.g., on-demand disclosure). We synthesize participants’ desired design practices into five dimensions to facilitate systematic future investigation into best practices. We conclude with recommendations for researchers, designers, and policymakers to improve S&P transparency in consumer-facing GenAI.
1
Introduction
Generative AI (GenAI) has seen widespread adoption for diverse purposes, from everyday information seeking to highly sensitive, personal use cases such as health, legal, and financial consultations [73,91]. Security and privacy (S&P) researchers have warned about multiple GenAI risks, including adversarial attacks, data breaches, secondary use, and the sharing or sale of personal data [19, 20, 47, 54, 88, 91]. Yet, empirical evidence suggests that these S&P intrusions often occur without users’ awareness or consent [51]. Even when users are aware * The two authors contributed equally to this work.
1
parency approaches [72]. Motivated by this perspective, we examine whether and how users currently seek, understand, and evaluate existing GenAI S&P information, and what improvements they hope to see in the content and design of GenAI S&P transparency. Accordingly, our work asks three research questions (RQs): • RQ1: What, if any, S&P information about consumerfacing GenAI tools factors into users’ adoption decisions and post-adoption experiences? • RQ2: What are users’ current practices and challenges in seeking, understanding, and evaluating S&P information about consumer-facing GenAI tools? • RQ3: What are users’ preferences and expectations for S&P transparency in consumer-facing GenAI tools? To answer these questions, we conducted 21 semistructured interviews followed by design sessions. Our findings suggest that existing S&P information is often perceived as incomplete, ineffective, and lacking credibility, and rarely drives GenAI adoption decisions. At the same time, participants described pressing needs for effective S&P communication in GenAI – needs they expected to become increasingly consequential as their high-stakes use grows. Across interviews and design sessions, participants articulated specific information needs (e.g., trustworthy independent evaluations) and proposed a rich set of design practices across five dimensions. Grounded in these findings, we discuss design opportunities for advancing GenAI S&P transparency and offer actionable recommendations for S&P researchers, designers, and policymakers. As an exploratory study intended to spur future research on the emerging design space of GenAI S&P transparency, we make three contributions: (1) empirical accounts of how users currently seek, understand, and evaluate GenAI S&P information; (2) a synthesis of participant-informed transparency design practices into a set of dimensions for future design and evaluation; and (3) actionable implications and recommendations for S&P researchers, designers, and policymakers to advance consumer-facing S&P transparency in GenAI.
2
data can enable profiling, as GenAI systems may infer additional attributes, such as users’ sexual orientation, gender, and religious beliefs [56, 85]. These sensitive data are often shared beyond GenAI companies, including with third parties that build applications on top of host GenAI models and may not guarantee users comparable privacy protections [56]. Yet, these S&P harms often unfold with limited user awareness and without informed consent [51, 91]. Moreover, extensive empirical research shows that users’ mental models of GenAI data practices, such as how data is collected, retained, used for training, and reused, are frequently incomplete or incorrect [10, 48, 56, 57, 83, 90, 91]. For example, users may not recognize all stakeholders who can access their data, including internal staff who review conversations for safety [10, 91] and third parties who build GenAI plug-ins (e.g., custom GPTs) [56]. Prior work also finds that users misunderstand the scope of data controls and policies. For instance, Malki et al. [57] report that users often assume deletion or training opt-out removes what the model has already learned. In practice, machine unlearning remains an unsolved problem [82, 87, 89]. Similarly, Ma et al. [56] find that users mistakenly believe OpenAI provides privacy protections for custom GPTs [69, 70]. In more sensitive contexts, such as mental health, users often assume that ChatGPT complies with HIPAA, even though it does not [48]. Such extensive empirical evidence on users’ misconceptions about GenAI S&P practices reveals a significant gap in the current infrastructure for GenAI S&P transparency. Specifically, existing S&P information and how it is communicated may not sufficiently support users in understanding, trusting, and acting on data practices. Our work thus contributes by surfacing whether and what S&P transparency needs users have for a more trustworthy GenAI ecosystem. Existing S&P transparency approaches. While GenAI S&P transparency remains underexplored, existing research on S&P transparency has examined a range of prior technologies [12, 27, 29, 31, 38, 41, 45, 46, 49, 72], including mobile apps [78, 92], IoT [22, 31], and ubiquitous computing systems [49]. A common effort to promote S&P transparency is the use of privacy policies, yet they have been widely criticized for being lengthy and difficult to understand [41, 61]. Towards more effective S&P communication, prior work highlights several design dimensions [72], including timing (when information is presented), channel (where it is presented), modality (how it is presented), and user control (how users can act on it). To improve the readability of privacy policies, alternative transparency approaches have emerged, such as privacy nutrition labels – analogous to food nutrition labels that surface salient information in a concise, standardized format [23, 31, 44]. Prior work has identified and evaluated label factors that matter to consumers. For example, Emami-Naeini et al. [31] found that consumers particularly wanted to know who their data might be shared with. Beyond label content,
Related Work
GenAI S&P risks and users’ (mis)conceptions. The S&P risks of GenAI have been extensively investigated since its emergence. From a security perspective, GenAI systems are vulnerable to adversarial threats, including data poisoning [59], prompt injection [54], and spoofing [79], among others. GenAI can also enable malicious use, such as generating convincing phishing messages [13]. Privacy risks center on extensive data collection, data breaches, and inappropriate use or sale of personal data [19, 20, 47, 56, 88, 91]. With the increasingly human-like and intelligent nature of GenAI tools, users share highly sensitive data [56, 81, 85, 91], such as medical records, personal trauma, and payslips [91]. Such 2
Figure 1: Methodology overview of our main study. We conducted semi-structured interviews, followed by design sketching sessions and follow-up questions. researchers have discussed four common consumer-facing label formats – binary, graded, descriptive, and multi-layer – each with distinct tradeoffs [18, 23, 24, 42]. Yet, in GenAI – particularly around S&P – such empirical and design guidance on what information to prioritize and how best to present it remains scarce. Current real-world examples of GenAI transparency – though not necessarily S&P-oriented – include model cards [62], system cards [7], and datasheets [6], which are technical documentation that summarizes key properties of models and datasets for developers, auditors, and other experts. However, efforts to support consumer-facing S&P transparency in GenAI remain limited. Moreover, we lack empirical insights into whether and how GenAI users seek, interpret, and evaluate the S&P information that is available today. Policy has likewise offered limited support for consumerfacing S&P disclosures in GenAI. In the U.S., there is no comprehensive federal requirement for standardized end-user disclosures, and emerging state laws largely emphasize organizational accountability (e.g., Colorado’s SB24-205 [4] focuses on risk management and documentation for “highrisk” AI in consequential decisions). The EU AI Act [35] introduces user-facing transparency obligations (e.g., notice of AI interaction and of emotion recognition/biometric categorization), but does not specify a format to present these notices, leaving implementation uncertain. Therefore, it is crucial to inform policies with empirical and design insights that can guide GenAI companies’ S&P transparency – both in what information to disclose and how to disclose it.
3
framing it as “understanding users’ perspectives and experiences with GenAI tools.” To capture a comprehensive range of consumer-facing GenAI products, we defined “GenAI tools” in both the pre-screening survey and interviews to include “standalone GenAI apps” (e.g., ChatGPT) and “GenAI features built into other platforms, apps, or smart devices” (e.g., Alexa+). Participant demographics and GenAI usage are detailed in Section 5. Eligibility and pre-screening. Participants eligible for the main study must (1) be at least 18 years old, (2) live in the United States, and (3) have used at least one GenAI tool. In the pre-screening survey, participants answered eligibility questions, provided consent to participate in the survey, indicated their willingness to participate in the 45-60 minute main study, which included an interview and design session on Zoom3 . Participants who were ineligible, did not provide full consent, or were not interested in the main study were redirected to Prolific and compensated at a flat rate of 0.15 USD. Participants who proceeded to the remaining survey reported their Prolific IDs (for compensation purposes), GenAI usage, and demographics. We required a minimum threshold of GenAI usage (i.e., having used at least one GenAI tool) to support richness of insights. All participants who completed the survey were compensated at an hourly rate of 14.26 USD. The median completion time was approximately 3 minutes. Complete recruitment and pre-screening materials are included in Appendix A. Pilot interviews. To assess interview clarity and timing, we conducted two pilot interviews with participants recruited through the first author’s personal connections. Both participants met the main study eligibility criteria. After each pilot, the research team debriefed on question clarity and any difficulties the participant encountered when answering. We then revised unclear questions, reordered prompts to better match a natural conversational flow, and prepared backup prompts for cases where participants struggled to respond.
Methodology
Recruitment. We recruited participants from Prolific1 from August to October, 2025. The Prolific participants were directed to a Qualtrics2 screening survey. To mitigate social desirability [40] and demand characteristics [60], we advertised our study without mentioning its S&P focus, broadly
Main study procedure. To reduce no-shows, we messaged each participant on Prolific one day before the main study
1 www.prolific.com 2 www.qualtrics.com
3 https://zoom.us/
3
to confirm attendance and shared brief instructions for using Zoom Whiteboard4 . We reached data saturation [71] at the seventeenth study, i.e., no additional insights emerged. Aligned with qualitative methodology guidance [37], we conducted four additional studies and did not identify substantially new insights. In total, we conducted 21 interviews and 20 design sessions5 . Each participant received 20 USD in compensation after completing the main study. Figure 1 provides an overview of the main study procedure. Each session involved one primary interviewer and a second researcher taking notes. The full protocol is included in Appendix B. The main study consisted of the following sections: • Section 0: Introduction & GenAI definitions. We asked participants to share their own definitions of GenAI and restated our definition of “GenAI tools” to align our terminology. • Section 1: Consumer-facing AI tool usage. We asked participants about the GenAI tools they used, their purposes of use, any tools they had discontinued and their reasons for discontinuation, and the GenAI tool they used most frequently. For participants who used multiple GenAI tools, we asked them to describe their experiences in general and to note tool-specific differences when relevant. • Section 2: Pre-adoption considerations. To comprehensively capture factors shaping participants’ experiences across their entire use journey, we began by probing their pre-adoption considerations, including what criteria they used to choose a GenAI tool and what information they sought to support that decision. • Section 3: Post-adoption considerations. We then asked participants about the factors shaping their postadoption use. To avoid priming S&P concerns, we first invited participants to describe, in general terms, the perceived benefits and concerns. After they had shared all their initial thoughts, we followed up with questions about their specific S&P considerations and any mitigation practices post-adoption. • Section 4: Practices, challenges, & expectations toward S&P information seeking. We asked participants about their S&P information-seeking practices, including the sources they consulted, how they evaluated and felt about the information they found, and whether it led them to change their behavior or tool choices. We also asked about challenges they encountered and what additional information they wished they had to inform adoption and usage decisions. • Section 5: Design sketching session. To elicit participants’ preferences for how desired S&P information should be presented, we asked them to visualize their ideas after introducing the sketching tools. We empha-
sized that sketches could be rough and should focus on the overall structure and the elements they considered most important. After this onboarding, we asked participants to sketch transparency interfaces for the preadoption and post-adoption stages, if they differed. We then asked participants to walk through their designs and explain their motivations and rationales. Qualitative data analysis. All interviews were audiorecorded and transcribed in English using Zoom’s transcription service. The first author proofread all transcripts prior to analysis to ensure accuracy and readability. Three researchers then conducted an iterative thematic analysis, consistent with prior studies [55,68,84]. The first author served as the primary coder and developed two initial codebooks, one for the interview transcripts and one for participants’ design ideas. These codebooks were refined iteratively through weekly meetings with the full research team. Two secondary coders, one for the interview data and one for the design-session data, then applied the codebooks to 20% of the dataset. We compared the primary and secondary coders’ coding and computed interrater reliability (IRR). When agreement reached Cohen’s κ of 0.7, which is commonly considered “good” [14], we proceeded using the primary coder’s codes. When κ < 0.7, the coders met to discuss and reconcile disagreements and to update the codebook. The secondary coders then applied the revised codebook to an additional 20% of the data, repeating this process until Cohen’s κ reached 0.7. Limitations. As is common in qualitative research, our sample size was relatively small, which may limit the generalizability of our findings in several ways. First, all participants were recruited via Prolific and, combined with our eligibility requirement of prior GenAI use, our sample likely overrepresents relatively active GenAI users. However, participants provided rich accounts of lived experiences, including concrete concerns and decision processes. This aligns with our exploratory goal of identifying where current S&P transparency falls short in practice and what design improvements could better support users. Second, our study relied on selfreported accounts, which may be subject to social desirability bias [40]. To mitigate this influence, we framed recruitment materials without mentioning “security” or “privacy” and recruited on a rolling basis to capture a diverse range of perspectives. Third, as users often develop S&P considerations over time [52], we structured our interview questions and design tasks around pre- and post-adoption phases to capture a broader use journey rather than a single timepoint. However, this framing may have subtly shaped how participants organized their reflections across phases. To mitigate this potential bias, we emphasized throughout the interview and design session that participants could provide the same answers or propose the same design outcomes across both phases if they felt both applied.
4 Getting started with Zoom Whiteboard. 5 One participant did not complete the design session due to time con-
straints.
4
4
Ethics Statement
Following popularity, context fit – namely, how well a tool fits users’ utility needs – was another major driver of adoption (12/21). For example, P9 said:
This study was approved by our Institutional Review Board (IRB). All participants provided informed consent at each study stage, including the pilot sessions, pre-screening survey, and main study sessions. Participation was voluntary, and participants could skip any question, pause, or stop at any time without penalty. All participants, regardless of completion, were compensated at rates consistent with institutional and platform norms. To minimize risk, we avoided requesting sensitive personal identifiers and informed participants that they could keep their camera off throughout the session. We audiorecorded sessions only with explicit consent. Before analysis, the first author proofread and de-identified transcripts and design sketches. We separated compensation identifiers (e.g., Prolific IDs) from research data and used participant codes (e.g., P1–P21) in analysis and reporting. Only the research team had access to the raw data. In publications, we report only de-identified quotes and descriptions and avoid including details that could reasonably re-identify participants.
5
“I’d want to see what benefit I’m going to get from the tool. How it would help me, what its capabilities or features are, and whether it aligns with a problem I’m having.” The third most commonly mentioned factor shaping users’ adoption decisions was the price (7/21), with lower-cost or non-subscription tools perceived as more desirable. For example, P8 mentioned: “How do I evaluate? Most of the time, I go on Google [...] I do a search and I look for prices, because I want to see what’s cheaper [...] I don’t want to pay anything monthly [...] That’s a big factor, the price.” S&P certainty as a desired adoption factor, despite scarce information. When asked – without any S&P prompts – what shaped their adoption decisions, 7/21 participants spontaneously mentioned S&P as an important consideration at adoption. For instance, P5 mentioned: “Initially, I was very hesitant to use any of them [GenAI tools] because I was concerned about privacy.”
Results
However, 10/21 participants complained that needed S&P information about GenAI tools was not readily available or usable at the point of adoption. For example, P21 said:
Our participants represented diverse demographics and exhibited varied levels of GenAI usage. Table 1 summarizes participants’ basic demographics and GenAI usage. Full demographics and GenAI usage information are included in Appendix A.
5.1
RQ1: Factors in GenAI Adoption & Use
5.1.1
Factors in Adoption Decisions
“If there was any AI that was very clear and upfront about things like, ‘we encrypt things,’ or whatever, any company that was transparent about that stuff would be a better green flag [...] But the thing is, I don’t see any of that with any of the AI currently [...] If they were really transparent and open about that, I’d be interested.”
Popularity, utility fit, and price as main drivers of initial adoption. Popularity of a GenAI tool was the most mentioned factor shaping 14/21 participants’ adoption decisions. For instance, P4 explained: “[The primary factor that informed adoption] was just what was out there and being talked about, seeing that other people were getting useful results.” Notably, 10/14 participants treated a tool’s high popularity as a signal of stronger S&P protections. Conversely, tools perceived as less popular prompted resistance to adoption due to S&P concerns (P4, P9). For example, P9 mentioned:
5.1.2
Factors in Post-Adoption Experiences
Output quality driving continued use of GenAI tools. 12/21 participants noted that their continued use of GenAI tools was mainly driven by the perceived quality of outputs, including the perceived accuracy/credibility (8/12) and lack of bias (4/12) of AI-generated information. Participants reported that tools that performed well on these metrics improved their efficiency, reduced cognitive load, or exposed them to more diverse, yet neutral perspectives. For example, P2 said: “The factors were, most importantly, performance, how quickly it works, and its accuracy as well [...] I try the same prompt on many platforms, and the one that gives me the most accurate and best results is the one I continue using.”
“A lot of these tools, like ChatGPT and whatnot, are so big that, if I end up having a problem, everybody else will have a problem, too. So they’re big enough that I feel fairly safe using it. But if there’s a name that seems suspicious to me, or not very big, and I haven’t heard of it, then I’d be very skeptical to try it, so I just wouldn’t even go for it. Reputable names are how I focus on being safe and secure, mostly.”
Additionally, 4/12 participants cared about whether GenAI tools exhibited any biased or overly opinionated behavior. For example, P16 mentioned: “ChatGPT has bias. It has told me that the sources that 5
ID
Most Often Used GenAI Tool(s)
Usage Frequency
Age
Gender
Ethnicity
P1 P2 P3 P4 P5 P6 P7 P8 P9 P10 P11 P12 P13 P14 P15 P16 P17 P18 P19 P20 P21
Copilot Deepseek Alexa+, Gemini ChatGPT ChatGPT, Gemini ChatGPT Gemini Alexa+ ChatGPT ChatGPT Gemini ChatGPT Alexa+, ChatGPT ChatGPT ChatGPT Pi, Copilot Gemini ChatGPT ChatGPT ChatGPT ChatGPT
More than once a day More than once a day More than once a day More than once a day More than once a day More than once a day More than once a day More than once a day Once a week Once a week More than once a day More than once a day More than once a day Once a day Once a month Once a day More than once a day Once a day More than once a day Once a day Once a day
45 - 54 25 - 34 45 - 54 45 - 54 45 - 54 45 - 54 35 - 44 45 - 54 25 - 34 55 - 64 65 - 74 25 - 34 45 - 54 45 - 54 35 - 44 35 - 44 45 - 54 45 - 54 45 - 54 25 - 34 25 - 34
Female Male Female Male Female Male Female Female Male Female Male Male Male Male Female Female Female Male Male Female Non-binary / third gender
White Middle Eastern or North African White Asian White Asian Black or African American White White Asian White Asian White White Black or African American Black & White Asian White White Black & White White
Table 1: Summary of participant demographics and GenAI usage. Full table in Appendix A. it gets are verifiable news [...] but I’ve noticed it’s been very biased towards, politically, a certain direction.”
you would be comparing the privacy level of one against the other. In the case of a law firm, their approach to litigating, for example, you don’t want that known to your opposing party – it could cost a lot if somebody can get hold of the information and somehow use it in a nefarious way.”
S&P uncertainty constraining AI use cases. 10/21 participants pointed out that limited visibility into GenAI tools’ S&P practices made it difficult to adopt concrete, effective risk mitigation strategies. As a result of S&P uncertainty, 3/21 participants chose to reduce or even discontinue their use of some GenAI tools, which in turn undermined the value of personalization. For example, P1 described how she significantly reduced her use of ChatGPT and stopped signing in due to a data breach [75]:
Additionally, 3/10 participants who worked in proprietary content creation raised concerns about content theft and expressed low trust in GenAI’s training practices. P13 explained: “If I was writing a movie script or a TV show that I wanted to keep proprietary, I wouldn’t want anyone to know about it. I don’t trust that they’re not going to use it in their models.”
“I’ve dropped off on ChatGPT a lot over the last week or two, when I found out that they had a leak and that people’s chats were found on Google. That very much bothered me [...] Before, I would log in and let it track what I talked about so that I could get a more personalized experience. But if that means that I have to give up my privacy and what we talk about, it’s not a good tradeoff for me. Now I’m using it for very generic information, and I’m also not logging in.”
3/10 participants expressed uncertainty about whether workplace surveillance might monitor employees’ GenAI tool use. For example, P6 said: “Some AI tools are prohibited at our institute [...] So if I upload a file at work, and the file contains sensitive data [...] But I’m not sure whether all these actions, like data input and file uploading, are monitored by the institute. That is the issue.”
Such constrained use became more pronounced when the perceived S&P stakes were higher. 10/21 participants reported heightened anxiety and discomfort when using GenAI tools in contexts with higher S&P stakes, such as legal support (3/10), proprietary content creation (3/10), work-related tasks (3/10), and others. For instance, P10 worried that sensitive legal information, such as litigation strategy, could be exposed to opposing parties. If using GenAI tools for legal support, P10 indicated that they would compare different tools’ S&P practices, if such information were available:
5.2
RQ2: Current S&P Information Seeking
5.2.1
Sources Used to Find S&P Information
Skimming or summarizing information from official sources. 15/21 participants reported consulting official documentation either by (1) skimming it themselves (13/15) or (2) summarizing it using a GenAI tool (2/15). For instance, P5 described her S&P information-seeking practice:
“For legal uses, which is a lot more sensitive, at that point 6
“I skimmed the terms and conditions on privacy information for ChatGPT and Gemini.”
jumbo, it feels like a smokescreen to confuse people [...] It doesn’t make me feel I have all the information I need to really feel comfortable.”
P20 described her approach of summarizing the information using a GenAI tool:
3/21 participants expressed concerns about ineffective communication of changes to S&P practices. P16 said:
“Looking at the privacy statements they have, even though they make them very difficult and 50 or 60 pages long, where I can’t really read through all of it, I end up having to use AI to summarize it.”
“Sometimes there are pop-ups that say, ‘Hey, we’ve changed something.’ But especially when you’re logged in, if I don’t open a completely new browser and I just pick back up in an old one and change the topic, it’s not a fresh web page. So it doesn’t automatically tell you if there’s a new update. You have to exit and start a new session for that. So it’s not transparent, and it doesn’t notify you every time you visit the page.”
Consulting trusted independent parties’ opinions and lived experiences regarding GenAI tools’ S&P practices. 6/21 participants reported looking into (1) articles (3/6) and (2) online communities (6/6) to find information about the S&P practices of GenAI tools. P2 described reading articles about Grok’s S&P practices, which led him to avoid using it:
Existing S&P transparency perceived as lacking credibility. 8/21 participants were particularly concerned about the credibility of available S&P information. For instance, P3 expressed doubt about official claims in the terms of service:
“I read a lot of articles about Grok AI, for example, and how it works, and how it uses information. Basically, the information is used constantly. It’s sold and given to many vendors [...] That’s why I don’t use it at all.”
“There are a lot of claims that they try to make it as secure as possible, but I don’t know if I believe it. Everything says, ‘We’re good, and we protect your information,’ but I still don’t feel confident in their explanations about how they keep things safe for users.”
P4 reported consulting Reddit for other users’ perspectives on GenAI tools’ S&P practices: “I look at Reddit and see people who are in a similar position to me, using AI tools in similar ways, and what their thoughts were. It helps me get a general sense of what others think about these same topics [S&P practices of GenAI tools].”
P1 talked about how the scandal around ChatGPT users’ chats appearing in public search results [75] heightened her concerns about the credibility of official documentation across consumer-facing GenAI tools:
2/6 participants compared multiple sources to evaluate S&P information. P1 was interested in how S&P practices worked in reality by comparing official documentation with other users’ lived experiences shared online:
“Sure, they can say X, Y, and Z in their privacy policy, but ChatGPT also said X, Y, and Z in their privacy policy, and how it actually played out, and what the reality became, don’t match up. And so you have to wonder in the back of your mind, is that going to happen with Gemini? Is that going to happen with Copilot? Is that going to happen with the ones that are embedded in my bank account?”
“I cross-reference that [official documentation] with what people have said online about the reality of how those things [S&P practices] have played out. Because sometimes what those privacy statements are saying may not actually align with what people are experiencing.”
3/21 participants were worried about the lack of credibility regarding the effectiveness or outcomes of S&P controls provided by GenAI tools. For example, P14 was concerned about not knowing whether their S&P choices were respected when using ChatGPT:
Similarly, P13 relied on online posts to keep up with changes to official documentation: “Google is changing its terms of service. Sometimes, on tech sites, or even on X, or maybe Reddit to some extent, people will post and say the terms of service changed and it’s really bad. So I pay attention to things like that.” 5.2.2
“If I direct it [ChatGPT] not to remember a session, I worry that I don’t have any confirmation that it won’t. If I say, ‘Disregard all session history,’ I can’t really tell whether it did or not.”
Perceptions Toward Existing S&P Transparency
P18 raised similar concerns about ChatGPT and Copilot:
Existing S&P transparency perceived as ineffective. The perceived ineffectiveness was associated with two main reasons: (1) participants often did not know what they had agreed to due to lengthy, difficult language (6/21), and (2) changes to S&P practices were not communicated in ways that participants could easily notice or access (3/21). P1 noted:
“I’ve looked at the privacy configuration within ChatGPT and some in Copilot [...] But quite honestly, I don’t have a lot of faith in those toggle switches, that they really offer the privacy they say they do.” Perceived surface-level assurance at a glance. 2/21 participants reported a sense of assurance from existing S&P transparency, often without digesting the details. For instance,
“I don’t feel I’ve found the reality or the truth of the situation. When they have pages and pages of legal mumbo 7
P5 described feeling reassured by privacy policies even without understanding everything:
isn’t going to sell my data, or is going to sell my data? There isn’t really a clearinghouse for that.”
“It [privacy policy] made me feel a little bit better. I didn’t really understand everything I was reading, and I quickly got bored with it, so I just thought, ‘Whatever, I’m just going to go with it. I think it’ll be fine.”’
P4 further specified which evaluation providers he would trust more, drawing an analogy to organic food certification that combines public oversight with reputable private accreditation:
5.3
RQ3: S&P Transparency for GenAI
5.3.1
S&P Transparency Content Wishlist
“We need a combination of government involvement as well as accredited third parties [...] Think about certified organic food. The organization that certifies it has to be in good standing and have a reputation. I think both spaces, the government side and the private industry side, are beneficial. They both have weak spots, but together they complement each other. So it would have to be something like that, where maybe there was certification through the government and third-party certification as well. That would make me feel safe.”
Who has access to user data. 9/21 participants wanted to know whether their data could be accessed by unknown third parties (8/9), models (2/9), or other users (2/9). For instance, P6 wanted to know whether their information was being shared with third parties: “They should show whether the data will be shared, for example with other companies or institutions, and whether it will be shared with third parties.”
Information on data storage, training, and inference. 5/21 participants requested having transparency into what data the GenAI tools store, train, or infer. For instance, P14 requested visibility into what types of data are stored, including metadata and inferred sensitive data:
2/9 participants wanted to know whether and how their data was transmitted, including to models beyond their awareness, as P1 mentioned:
“I would be interested in how much metadata it’s storing, like time of use and usage patterns. And I’d definitely be interested in whether it’s storing my phone number, my address, my political affiliation, and my income level.”
“[It would be good to know] how many different AI systems are you feeding it [data] into? Are you taking it [data], say, if you’re using Alexa+, and you [Alexa+] feed my information into your model, but then you also feed it into another model for comparison purposes? Now my information is in some other model that I’m not aware of, and I didn’t agree to.”
5.3.2
Envisioned Design Practices for GenAI S&P
We categorize participants’ desired design practices for S&P transparency into five dimensions: (1) modality, (2) granularity, (3) explainability and reflectiveness, (4) findability, and (5) timing. Under each dimension, we present representative design ideas from participants. Table 2 summarizes the design dimensions and sub-dimensions, along with their descriptions and representative design ideas.
2/9 participants were also curious about whether their input data, if used for training, might later surface in outputs to other users. For example, P14 said: “If I’m going through a legal problem and talking to it [GenAI tool] a lot about that, I’m interested in knowing whether it uses my sessions to learn from and then advise other people. I’m interested in how it takes someone’s session and applies that to other people’s sessions.”
Combining interactive and static disclosure modalities to lower understanding barriers. 8/20 participants envisioned interactive, on-demand formats that would let them ask questions, clarify terms, and progressively drill down into details. Their sketches illustrated modalities such as an AI-enabled privacy FAQ and expandable cards that reveal additional S&P specifics and explanations on click. These interactive elements appeared most often in participants’ pre-adoption designs, where they described wanting quick, situation-driven answers without having to parse lengthy documentation while still retaining the option to explore deeper details. All 20/20 participants proposed at least one design element in a static modality, where S&P information is presented in a fixed, non-interactive format. Examples included visual cues such as labels that convey S&P assurances at a glance. Participants who proposed these elements described them as useful for quick pre-adoption screening and comparison, especially
Independent evaluations of S&P practices. 4/21 participants called for independent evaluations or audits of GenAI companies’ S&P practices that provide users with more credible, digestible, and comparable insights. For example, P13 envisioned a third-party website that would translate companies’ S&P practices into usable consumer-facing summaries and comparisons: “There should be an independent website that would audit all the companies. So if you had a question about what the terms of service really are, you could go to this website and it would tell you. You could even have AI distill it for you, like take the terms of service and put it into one paragraph, or show it in a chart. Then you could compare your options as a consumer. Which one is the safest, which is the most secure, and which one 8
Design Dimension
Description
Representative Example(s)
Modality: Interactive
S&P information formats that support on-demand user interaction. S&P information formats that are presented in fixed, non-interactive forms.
AI-enabled privacy FAQs; interactive cards.
Granularity: High
Highly detailed information or control types.
Granularity: Low
Less detailed information or control types.
Fine-grained permissions over data uses, recipients, and data types, with configurable time bounds (e.g., “always,” “this session only”). Summaries of most needed data practices only.
Explainability
How clearly the interface communicates what an S&P option means and what it enables. How the interface supports engagement and reflection with S&P information.
Modality: Static
Reflectiveness
Standardized visual cues (labels).
A brief explanation of the toggled choice. Pre-commit confirmation and editing.
Findability: High
S&P information and controls are highlighted and easily located with clear textual, visual, or multimodal cues.
Clear navigation cues (e.g., links or walkthrough animation); standalone privacy icon/section.
Timing: Repeated Timing: One time Timing: Persistent
S&P information is repeatedly presented. S&P information is presented only once. S&P information is persistently presented.
Per-launch warning screens. One-off disclaimers at sign-up. Texts, toggles, badges, or banners that remain visible in the interface and surface critical S&P information, such as the privacy settings currently enabled (e.g., training on/off).
Table 2: Design dimensions, descriptions, and representative design ideas for S&P transparency. when they want a baseline understanding of data practices without digging into details.
S&P practices. Examples included clear navigation cues (e.g., links) that point users to where they can update consent settings during sign-up, as well as a standalone icon or dedicated section for privacy settings post-adoption.
Low granularity pre-adoption, high granularity postadoption. In general, participants preferred low granularity pre-adoption (e.g., a brief summary of the salient S&P information, as specified in Section 5.3.1), but wanted high granularity post-adoption (e.g., fine-grained consent options or controls). In particular, 7/20 participants indicated that existing GenAI tools fell short in providing sufficient permissions, especially around purposes of data usage, data recipients, and the types of data stored, trained, or inferred. Importantly, 3/7 emphasized the need for configurable time bounds for these permissions. For example, users can enable global settings that apply to all sessions by default, while also enabling local, session-specific settings for particular permissions.
Presenting S&P information at the right timing. Timing refers to when S&P information is surfaced during use. Participants described three timing patterns – repeated, onetime, and persistent. Repeated disclosures include per-launch warning screens that caution users against sharing sensitive information. One-time disclosures include a one-off notice at sign-up and just-in-time notices triggered by a specific action. Persistent disclosures include texts, toggles, badges, or banners that remain visible in the interface and surface critical S&P information, such as the privacy settings currently enabled (e.g., training on/off). For example, P13 specifically described a repeated, entry-point disclosure that appears at tool launch to provide a consistent reminder of data practices, analogous to cigarette warnings or car startup screens:
Supporting S&P decision-making through explainability and reflectiveness. 8/20 participants suggested that toggling a consent option should trigger a brief explanation of what the choice enables, what data it affects, and any potential consequences. After reviewing the explanation, users should be able to confirm the settings or revise them before they take effect. Participants described these ideas as a way to mitigate long-standing issues of notice fatigue [15] and habituation [11, 17], where users click through S&P information without processing its content. By pairing pre-commit explanations with opportunities to confirm or edit, these designs create additional moments for users to engage with S&P information and make more informed choices.
“When you open the [GenAI] app, there could be a warning that says, ‘Hey, this is what’s going to happen to your data,’ right when you open it, every time. That’s like what we have with cigarettes. We have a label right on the pack [...] Now, in some cars, it gives you a warning screen right on the interface when you start the car up. Then it goes away, you hit OK, and you can drive. There might be something like that with an AI interface.”
6
Improving the findability of S&P information. 9/20 participants’ sketches suggested a strong desire for higher visibility and easy access to information and controls over a tool’s
Discussion
Our findings highlight an alarming status quo – S&P transparency in consumer-facing GenAI tools is often missing 9
Figure 2: We assemble participants’ representative design ideas across the five dimensions into a single prototype spanning pre-adoption (left) and post-adoption (right) phases. In the pre-adoption phase, the prototype presents an independent audit badge in a static format (A), concise explanations (B) paired with granular permission controls (C), and an AI-enabled FAQ about data practices (D). After users make initial choices, the interface summarizes each option with brief explanations and allows users to edit or confirm their settings (E). In the post-adoption phase, users can quickly enable a privacy-preserving mode that remains visible in the interface (F) and view a persistent privacy reminder (H). Users can update privacy preferences via two clear visual entry points (G), and specify whether changes apply globally across sessions (I) or only to the current session (J). To illustrate traceability, we present examples in Figure 3 showing how participants’ original sketches correspond to features in the prototype. or unusable in practice, even as high-stakes use becomes more common (RQ1&RQ2). In response to this challenge, participants described concrete expectations for what S&P information should cover and how it should be communicated to support informed adoption and use (RQ3). We organize participants’ design ideas into five dimensions (see Table 2) and instantiate them in a single interactive prototype that visualizes representative designs across dimensions (see Figure 2). The interactive prototype can be accessed in Appendix A, which is intended to surface an emerging design space of GenAI S&P transparency by illustrating participantinformed design ideas. It is not meant to be comprehensive and does not necessarily reflect best practices. As an exploratory study in this space, our goal is to offer a starting point for designing and evaluating GenAI S&P transparency and to spur more investigation into best practices.
setting [3] that applies to all sessions), making it difficult to manage risk in the most appropriate way as usage contexts shift. (2) Participants perceived data practices as changing frequently without effective communication, leaving them unaware of what has changed and unclear about the current policy (Section 5.2.1). This uncertainty made it harder for participants to make informed S&P decisions, such as what information to share or withhold. This challenge is particularly salient in GenAI because a single general-purpose tool is routinely used across contexts with very different risk levels (e.g., mental health support vs. information seeking [25]), whereas prior digital technologies often let users segment disclosure by setting or audience (e.g., social media platforms allow users to restrict a post’s visibility to specific friend groups [53]). Participants, therefore, called for more contextual, fine-grained controls. However, prior work suggests that offering more controls can introduce trade-offs, notably oversharing – either by creating a false sense of safety or by increasing the burden of managing settings over time [16, 43, 72]. Thus, future research should carefully examine how different levels of S&P transparency granularity influence users’ S&P perceptions and behaviors in real-world settings.
Unique design challenges and opportunities for advancing GenAI S&P transparency. Several unique S&P transparency challenges emerged in the context of GenAI. First, our findings suggest structural design limitations that produce a mitigation-risk misalignment: privacy risks in GenAI tools are constantly shifting, yet participants struggled to align their mitigation strategies accordingly, for two main reasons: (1) Participants often mixed the use of a single GenAI tool for both high-stakes and low-stakes purposes concurrently (Section 5.1.2). However, existing controls in GenAI tools are mostly coarse, global settings (e.g., a training opt-out/opt-in
Second, existing GenAI S&P communication faces a significant “credibility gap.” While independent evaluations have been used to strengthen the credibility of self-attested S&P practices in prior technologies (e.g., the FCC-led Cyber Trust Mark Program for IoT technologies [23]), GenAI still largely 10
Rep eate d
One
Pers is
Inde p
Data
Data
− − −
− −
tent
-Tim
lain
Typ es
Hig h Fi ndab
. Ev als
Refl
Experts Experts Experts Users Users
e
Exp
Google Model Cards [5] Privy (Template-based) [50] Privy (LLM-based) [50] AI Nutrition Facts Label [1] Manus Trust Center [58]
Gra nu
Audience
ract ive
Example
Low
Rec ipie n
ts
ility
Content
Hig
ectiv enes
Timing
Stat ic
abil it
y
larit y
Findability
Inte
hG ranu larit
s
Expl. & Refl.
Granularity y
Modality
Evaluation: = example fulfills criterion; = example partially fulfills criterion or fails; − = criterion not applicable.
Table 3: Mapping a small subset of existing S&P transparency approaches in GenAI to participant-informed design dimensions and information needs. Note: The table format is adapted from [77]. lacks comparable, consumer-legible signals that reduce information asymmetry [63] by clearly communicating what is being assessed, by whom, and what the results imply for users’ data practices (Section 5.3.1). Moreover, policy efforts to advance S&P transparency in GenAI remain limited and have yet to establish industry-wide standards for S&P communication backed by trusted public authorities. Prior work further suggests that credibility-oriented S&P disclosures (e.g., well-designed labels) can increase consumers’ willingness to adopt or purchase privacy- and security-protective technologies [28, 30, 34, 80]. Building on this, future work should further motivate policy efforts by examining (1) what content and forms of independent evaluation outputs (e.g., binary vs. graded, descriptive, or multi-layered labels [23, 26]) best align with GenAI users’ needs, and (2) whether and how independent certifications shape users’ adoption decisions and interactions in the GenAI context. Despite these challenges, GenAI also introduces unique opportunities in the design space of S&P transparency. Participants expressed a need for on-demand S&P explanations delivered through interactive modalities (Section 5.3.2). Prior work on algorithmic transparency has similarly drawn on the UX principle of progressive disclosure [21, 64, 76], suggesting that providing explanations on an “as needed” basis can help users better understand a system and reduce initial errors. Our findings echo this preference in the S&P context for GenAI (Section 5.3.2), particularly given participants’ perceptions of ever-updating data practices in GenAI (Section 5.2.1). However, assessing its effectiveness in shaping users’ S&P understanding and behavior requires further empirical work.
to motivate future work that more systematically investigates and validates best practices for S&P transparency in GenAI. Existing S&P transparency approaches in GenAI tools are largely not consumer-facing. Instead, they often target audiences with substantially higher technical expertise than typical end users. For instance, Google launched developer-facing model cards that help identify a GenAI model’s strengths, limitations, and mitigations through text documentation [5]. Similarly, a recent study [50] proposed Privy, a practitionerfacing tool that guides AI product teams through privacy impact assessments (PIAs) in two versions – static, structured vs. interactive, LLM-based. Their findings suggest that LLMbased PIAs identified more relevant and clear S&P guidance compared to the static, structured version. Our findings also suggest participants’ split preferences for interactive vs. static disclosure in different contexts. Our participants wanted interactive disclosure to provide them with on-demand S&P information, while effective static disclosure to support quick pre-adoption screening and comparison (Section 5.3.2). Limited S&P transparency approaches in GenAI have targeted general users, with the AI Nutrition Facts Label being one example [1]. Similar to IoT label designs [31], the AI nutrition fact label presents a standardized summary of a GenAI model’s data practices to help users quickly understand a model’s data training, sharing, retention, and related practices. More recently, Manus [58] published consumer-facing information about its S&P compliance, including independent audit reports, security controls, subprocessor disclosures, and static FAQs. Many of these emerging practices align with what our participants called for, further underscoring a growing need for consumer-facing transparency in GenAI. In summary, our work introduces an initial design space for S&P transparency in GenAI with user-informed design practices, aiming to help designers, developers, and researchers identify and evaluate design choices when developing S&P
Evaluating existing GenAI S&P transparency through our design dimensions. We compare a small set of existing S&P transparency approaches in GenAI using our proposed design dimensions. Table 3 maps a subset of existing S&P transparency approaches onto these dimensions6 , and is intended
disagreements through discussion. We add content as an additional table dimension to capture what information participants preferred to be included.
6 Two researchers independently audited the listed examples and resolved
11
transparency for end users. Evaluating this small set of examples suggests several emerging patterns in the current GenAI S&P transparency landscape: across the examples, (1) most approaches are expert-facing, leaving a gap in consumerlegible disclosures that support adoption decisions and longterm use; (2) interactive modalities for S&P communication remain underexplored; (3) timing is dominated by persistent availability, with limited support for “just-in-time” disclosure at decision points [30]; (4) most approaches primarily convey information, but do not reliably create moments for users to reflect, confirm, or revise settings before higher-risk actions; (5) independent evaluations are mostly absent; and (6) while many examples offer high granularity, fewer provide a unified experience that supports both quick summaries (low granularity) and deeper drill-down (high granularity).
6.1
require inquiring into empirical research on users’ mental models of GenAI data practices – especially common misconceptions – to inform defaults, explanations, and when (and how) to surface additional controls or information. Policies should help consumers gain industry-wide standardized insights. Participants suggested they would be more likely to trust independent evaluations that combine public oversight with accredited private auditors (Section 5.3.1), pointing to a role for policy in establishing industry-wide, consumer-legible S&P transparency standards. Yet, legally enforceable transparency requirements for consumer-facing GenAI remain scarce within and beyond the U.S. In the U.S., pressure for truthful S&P communication largely arrives through emerging state laws that focus on risk documentation for specific classes of systems (e.g., Colorado SB24-205’s duties and risk-management expectations for “high-risk” AI systems) [4]. A key mismatch for our context is that these U.S.-based efforts tend to prioritize organizational accountability (e.g., internal governance processes and documentation) [66, 67], while less often mandating consumer-legible disclosures about everyday data practices. Outside the U.S., transparency requirements also vary substantially in scope and intended audience – for example, the EU AI Act introduces legally binding transparency obligations for certain AI systems and actors [35], while other efforts are largely non-binding, such as Singapore’s Model AI Governance Framework for Gen AI [9] and the OECD’s Hiroshima AI Process Reporting Framework [8]. Across these policy directions, “transparency” frequently emphasizes safety reporting and technical documentation rather than consumer-facing S&P assurances. Moving forward, policies could shift from primarily enforcing entity accountability to also mandating honest, consumerfacing S&P transparency – e.g., standardized, comparable disclosures and independent certification signals – while guarding against “transparency washing,” such as vague or unverifiable claims, self-issued trust badges without auditable backing, or interface designs that nudge users into disclosure while obscuring critical terms [2, 36].
Recommendations
Future S&P research should further validate, measure, and refine suggested design practices in real-world settings. Our work provides preliminary findings that surface exploratory design practices for promoting S&P transparency in GenAI (Section 5.3.2). These practices should be further validated, measured, and refined through future empirical research. Specifically, future work should (1) evaluate the realworld impact of GenAI S&P transparency designs on users’ perceptions and behaviors – for example, how transparency granularity shapes users’ understanding, decision-making, and disclosure practices as contexts and risk levels shift, and whether interactive, on-demand disclosure improves comprehension and reduces errors in practice; and (2) extend this work by translating participants’ credibility concerns into policy-relevant evidence, examining what information and presentation formats for independent evaluation best support users’ needs, which organizations (e.g., Consumer Reports7 , Underwriters Laboratories8 ) users trust more, and whether third-party certification measurably affects users’ adoption and interaction behaviors in the GenAI context. GenAI S&P transparency design should balance flexibility and user burden through evidence-informed defaults. Participants called for more granular, flexible options that better match GenAI’s shifting use contexts and risk levels (Section 5.3.2). At the same time, flexible controls can introduce trade-offs – adding granularity can increase decision burden and may also create a false sense of safety that leads to greater disclosure over time [16, 43, 72]. To balance these concerns, we recommend that designers make the default experiences secure, while offering additional granularity on demand. Moreover, prior work suggests that when data practices reasonably match users’ expectations, they can demand less attention from users [72]. Achieving this goal would also
7
Conclusion
Our findings show that S&P information rarely drove adoption, but S&P uncertainty limited participants’ willingness to use GenAI in high-stakes contexts. Participants sought S&P information from a small set of sources that they viewed as ineffective or lacking credibility. They most wanted clarity about data-access stakeholders, what data are stored, used for training, or inferred, and independent evaluations. Participants’ envisioned transparency interfaces highlighted five design dimensions. Grounded in our findings, we propose recommendations toward promoting S&P transparency for consumer-facing GenAI.
7 https://www.consumerreports.org/ 8 https://www.ul.com/
12
References
[21] John M Carroll and Caroline Carrithers. Training wheels in a user interface. Communications of the ACM, 27(8):800–806, 1984.
[1] Ai nutrition facts. https://nutrition-facts.ai/. Accessed: 2026-01-21.
[22] Claude Castelluccia, Mathieu Cunche, Daniel Le Métayer, and Victor Morel. Enhancing transparency and consent in the iot. In 2018 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), pages 116–119. IEEE, 2018.
[2] Bringing dark patterns to light. https://www.ftc.gov/reports/ bringing-dark-patterns-light. Accessed: 2026-02-05. [3] Chatgpt data controls. https://help.openai.com/en/collectio ns/8471418-data-controls. Accessed: 2026-02-05.
[23] Peter Caven, Ambarish Gurjar, Zitao Zhang, Xinyao Ma, and LJean Camp. Usability, efficacy, and acceptability of the us cyber trust mark. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1–35, 2025.
[4] Colorado sb24-205: Consumer protections for artificial intelligence. https://leg.colorado.gov/bills/sb24-205. Accessed: 202602-05.
[24] Peter J Caven, Shakthidhar Reddy Gopavaram, and L Jean Camp. Integrating human intelligence to bypass information asymmetry in procurement decision-making. In MILCOM 2022-2022 IEEE Military Communications Conference (MILCOM), pages 687–692. IEEE, 2022.
[5] Google model cards. https://modelcards.withgoogle.com/. Accessed: 2026-01-21. [6] Ibm ai factsheets. https://www.ibm.com/docs/en/software-h ub/5.1.x?topic=services-ai-factsheets. Accessed: 2026-0205.
[25] Aaron Chatterji, Thomas Cunningham, David J Deming, Zoe Hitzig, Christopher Ong, Carl Yan Shan, and Kevin Wadman. How people use chatgpt. Technical report, National Bureau of Economic Research, 2025.
[7] Meta system cards. https://ai.meta.com/tools/system-car ds/. Accessed: 2026-02-05. [8] Oecd haip reporting framework. https://transparency.oecd.ai /. Accessed: 2026-02-05.
[26] Yi-Shyuan Chiang, Pardis Emami-Naeini, and Camille Cobb. Iot labels’ impact on security and privacy concerns. In 2025 European Symposium on Usable Security (EuroUSEC), pages 177–190. IEEE, 2025.
[9] AI Verify Foundation. Model ai governance framework for generative ai. Technical report, AI Verify Foundation (Singapore), May 2024.
[27] Lorrie Faith Cranor. Necessary but not sufficient: Standardized mechanisms for privacy notice and choice. J. on Telecomm. & High Tech. L., 10:273, 2012.
[10] Mutahar Ali, Arjun Arunasalam, and Habiba Farrukh. Understanding users’ security and privacy concerns and attitudes towards conversational ai platforms. In 2025 IEEE Symposium on Security and Privacy (SP), pages 298–316. IEEE, 2025.
[28] Lorrie Faith Cranor, Yuvraj Agarwal, and Pardis Emami-Naeini. Internet of things security and privacy labels should empower consumers. Communications of the ACM, 67(3):29–31, 2024.
[11] Bonnie Anderson, Anthony Vance, Brock Kirwan, David Eargle, and Seth Howard. Users aren’t (necessarily) lazy: Using neurois to explain habituation to security warnings. 2014.
[29] Lorrie Faith Cranor, Praveen Guduru, and Manjula Arjula. User interfaces for privacy agents. ACM Transactions on Computer-Human Interaction (TOCHI), 13(2):135–178, 2006.
[12] Rebecca Balebako, Richard Shay, and Lorrie Faith Cranor. Is your inseam a biometric? a case study on the role of usability studies in developing public policy. Proc. USEC, 14(10.14722), 2014.
[30] Serge Egelman, Janice Tsai, Lorrie Faith Cranor, and Alessandro Acquisti. Timing is everything? the effects of timing and placement of online privacy indicators. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pages 319–328, 2009.
[13] Charlotte Bird, Eddie Ungless, and Atoosa Kasirzadeh. Typology of risks of generative text-to-image models. In Proceedings of the 2023 AAAI/ACM Conference on AI, Ethics, and Society, pages 396–410, 2023.
[31] Pardis Emami-Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, and Hanan Hibshi. Ask the experts: What should be on an iot privacy and security label? In 2020 IEEE Symposium on Security and Privacy (SP), pages 447–464. IEEE, 2020.
[14] Nicole J-M Blackman and John J Koval. Interval estimation for cohen’s kappa as a measure of agreement. Statistics in medicine, 19(5):723–741, 2000.
[32] Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. An informative security and privacy “nutrition” label for internet of things devices. IEEE Security & Privacy, 20(2):31– 39, 2021.
[15] Rainer Böhme and Jens Grossklags. The security cost of cheap user interaction. In Proceedings of the 2011 New Security Paradigms Workshop, pages 67–82, 2011. [16] Laura Brandimarte, Alessandro Acquisti, and George Loewenstein. Misplaced confidences: Privacy and the control paradox. Social psychological and personality science, 4(3):340–347, 2013.
[33] Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. Which privacy and security attributes most impact consumers’ risk perception and willingness to purchase iot devices? In 2021 IEEE Symposium on Security and Privacy (SP), pages 519–536. IEEE, 2021.
[17] Cristian Bravo-Lillo, Saranga Komanduri, Lorrie Faith Cranor, Robert W Reeder, Manya Sleeper, Julie Downs, and Stuart Schechter. Your attention please: Designing security-decision uis to make genuine risks harder to ignore. In Proceedings of the Ninth Symposium on Usable Privacy and Security, pages 1–12, 2013.
[34] Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. Are consumers willing to pay for security and privacy of {IoT} devices? In 32nd USENIX Security Symposium (USENIX Security 23), pages 1505–1522, 2023.
[18] L Jean Camp, Shakthidhar Gopavaram, Jayati Dev, and Ece Gumusel. Lessons for labeling from risk communication. In Workshop and Call for Papers on Cybersecurity Labeling Programs for Consumers: Internet of Things (IoT) Devices and Software, pages 1–3. NIST Washington DC, 2021.
[35] European Union. Regulation (eu) 2024/1689 laying down harmonised rules on artificial intelligence (artificial intelligence act). EUR-Lex (Official Journal text), June 2024.
[19] Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramer, and Chiyuan Zhang. Quantifying memorization across neural language models. In The Eleventh International Conference on Learning Representations, 2022. [20] Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. Extracting training data from large language models. In 30th USENIX security symposium (USENIX Security 21), pages 2633–2650, 2021.
[36] Federal Trade Commission. Ftc announces crackdown on deceptive ai claims and schemes. Press Release, September 2024. [37] Jill J Francis, Marie Johnston, Clare Robertson, Liz Glidewell, Vikki Entwistle, Martin P Eccles, and Jeremy M Grimshaw. What is an adequate sample size? operationalising data saturation for theory-based interview studies. Psychology and health, 25(10):1229–1245, 2010.
13
[55] Yijing Liu, Yan Jia, Qingyin Tan, Zheli Liu, and Luyi Xing. How are your zombie accounts? understanding users’ practices and expectations on mobile app account deletion. In 31st USENIX Security Symposium (USENIX Security 22), pages 863–880, 2022.
[38] Huiqing Fu, Yulong Yang, Nileema Shingte, Janne Lindqvist, and Marco Gruteser. A field study of run-time location access disclosures on android smartphones. Proc. USEC, 14(10), 2014. [39] Nathaniel S Good, Jens Grossklags, Deirdre K Mulligan, and Joseph A Konstan. Noticing notice: a large-scale experiment on the timing of software license agreements. In Proceedings of the SIGCHI conference on Human factors in computing systems, pages 607–616, 2007.
[56] Rongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist, and Jose Such. Privacy perceptions of custom gpts by users and creators. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1–18, 2025.
[40] Pamela Grimm. Social desirability bias. Wiley international encyclopedia of marketing, 2010.
[57] Lisa Mekioussa Malki et al. “hoovered up as a data point”: Exploring privacy behaviours, awareness, and concerns among uk users of llmbased conversational agents. In Proceedings on Privacy Enhancing Technologies. ACM, 2025.
[41] Carlos Jensen and Colin Potts. Privacy policies as decision-making tools: an evaluation of online privacy notices. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems, pages 471–478, 2004.
[58] Manus AI. Trust center, 2025. Accessed: 2025-02-02.
[42] Shane D Johnson, John M Blythe, Matthew Manning, and Gabriel TW Wong. The impact of iot security labelling on consumer product choice and willingness to pay. PloS one, 15(1):e0227800, 2020.
[59] Nahema Marchal, Rachel Xu, Rasmi Elasmar, Iason Gabriel, Beth Goldberg, and William Isaac. Generative ai misuse: A taxonomy of tactics and insights from real-world data. arXiv preprint arXiv:2406.13843, 2024.
[43] Mark J Keith, Courtenay Maynes, Paul Benjamin Lowry, and Jeffry Babb. Privacy fatigue: The effect of privacy control complexity on consumer electronic information disclosure. In International Conference on Information Systems (ICIS 2014), Auckland, New Zealand, December, pages 14–17, 2014.
[60] Jim McCambridge, Marijn De Bruin, and John Witton. The effects of demand characteristics on research participant behaviours in nonlaboratory settings: a systematic review. PloS one, 7(6):e39116, 2012. [61] Aleecia M McDonald and Lorrie Faith Cranor. The cost of reading privacy policies. Isjlp, 4:543, 2008.
[44] Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder. A" nutrition label" for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security, pages 1–12, 2009.
[62] Margaret Mitchell, Simone Wu, Andrew Zaldivar, Parker Barnes, Lucy Vasserman, Ben Hutchinson, Elena Spitzer, Inioluwa Deborah Raji, and Timnit Gebru. Model cards for model reporting. In Proceedings of the conference on fairness, accountability, and transparency, pages 220–229, 2019.
[45] Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, and Lorrie Faith Cranor. Standardizing privacy notices: an online study of the nutrition label approach. In Proceedings of the SIGCHI Conference on Human factors in Computing Systems, pages 1573–1582, 2010.
[63] Philipp Morgner, Felix Freiling, and Zinaida Benenson. Opinion: Security lifetime labels-overcoming information asymmetry in security of iot consumer products. In Proceedings of the 11th ACM Conference on Security & Privacy in Wireless and Mobile Networks, pages 208–211, 2018.
[46] Patrick Gage Kelley, Lorrie Faith Cranor, and Norman Sadeh. Privacy as part of the app decision-making process. In Proceedings of the SIGCHI conference on human factors in computing systems, pages 3393–3402, 2013. [47] Nir Kshetri. Cybercrime and privacy threats of large language models. IT Professional, 25(3):9–13, 2023.
[64] Deepa Muralidhar, Rafik Belloum, Kathia Marçal de Oliveira, Ashwin Ashok, and Pardaz Banu Mohammad. The effect of progressive disclosure in the transparency of large language models. In International Conference on Computer-Human Interaction Research and Applications, pages 269–288. Springer, 2024.
[48] Jabari Kwesi, Jiaxun Cao, Riya Manchanda, and Pardis Emami-Naeini. Exploring user security and privacy attitudes and concerns toward the use of {General-Purpose}{LLM} chatbots for mental health. In 34th USENIX Security Symposium (USENIX Security 25), pages 6007–6024, 2025.
[65] Patrick Murmann and Farzaneh Karegar. From design requirements to effective privacy notifications: Empowering users of online services to make informed decisions. International Journal of Human-Computer Interaction, 37(19):1823–1848, 2021.
[49] Marc Langheinrich. A privacy awareness system for ubiquitous computing environments. In international conference on Ubiquitous Computing, pages 237–245. Springer, 2002.
[66] National Institute of Standards and Technology. Artificial intelligence risk management framework (ai rmf 1.0). Technical Report NIST AI 100-1, NIST, 2023.
[50] Hao-Ping Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek, Thomas Serban von Davier, Kyzyl Monteiro, Jason Lin, Shivani Agarwal, Jodi Forlizzi, and Sauvik Das. Privy: Envisioning and mitigating privacy risks for consumer-facing ai product concepts. https://arxiv.org/ abs/2509.23525, September 2025. Accessed: 2026-01-21.
[67] National Institute of Standards and Technology. Artificial intelligence risk management framework: Generative artificial intelligence profile. Technical Report NIST AI 600-1, NIST, 2024.
[51] Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, and Sauvik Das. Deepfakes, phrenology, surveillance, and more! a taxonomy of ai privacy risks. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1–19, 2024.
[68] Alexandra Nisenoff, Arthur Borem, Madison Pickering, Grant Nakanishi, Maya Thumpasery, and Blase Ur. Defining" broken": User experiences and remediation tactics when {Ad-Blocking} or {TrackingProtection} tools break a {Website’s} user experience. In 32nd USENIX Security Symposium (USENIX Security 23), pages 3619–3636, 2023.
[52] Jingjie Li, Kaiwen Sun, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim, Florian Schaub, and Kassem Fawaz. “it’s up to the consumer to be smart”: Understanding the security and privacy attitudes of smart home users on reddit. In 2023 IEEE Symposium on Security and Privacy (SP), pages 2850–2866. IEEE, 2023.
[69] OpenAI. Data processing addendum. https://openai.com/polic ies/data-processing-addendum/, 2024. Accessed: 2025-05-09. [70] OpenAI. Plugin terms. https://openai.com/policies/plugin -terms/, 2024. Accessed: 2025-05-09.
[53] Yabing Liu, Krishna P Gummadi, Balachander Krishnamurthy, and Alan Mislove. Analyzing facebook privacy settings: user expectations vs. reality. In Proceedings of the 2011 ACM SIGCOMM conference on Internet measurement conference, pages 61–70, 2011. [54] Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, et al. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499, 2023.
[71] Benjamin Saunders, Julius Sim, Tom Kingstone, Shula Baker, Jackie Waterfield, Bernadette Bartlam, Heather Burroughs, and Clare Jinks. Saturation in qualitative research: exploring its conceptualization and operationalization. Quality & quantity, 52(4):1893–1907, 2018.
14
[72] Florian Schaub, Rebecca Balebako, Adam L Durity, and Lorrie Faith Cranor. A design space for effective privacy notices. In Eleventh symposium on usable privacy and security (SOUPS 2015), pages 1–17, 2015.
[83] Xingyi Wang, Xiaozheng Wang, Sunyup Park, and Yaxing Yao. Mental models of generative ai chatbot ecosystems. In Proceedings of the 30th International Conference on Intelligent User Interfaces, pages 1016–1031, 2025.
[73] Eike Schneiders, Tina Seabrooke, Joshua Krook, Richard Hyde, Natalie Leesakul, Jeremie Clos, and Joel E Fischer. Objection overruled! lay people can distinguish large language models from lawyers, but still favour advice from an llm. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1–14, 2025.
[84] Miranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno, Elissa M Redmiles, and Franziska Roesner. {SoK}(or {SoLK?)}: On the quantitative study of sociodemographic factors and computer security behaviors. In 33rd USENIX Security Symposium (USENIX Security 24), pages 7011–7030, 2024.
[74] B Schwartz. The paradox of choice: Why more is less harpercollins publishers. New York, NY, 2004.
[85] Laura Weidinger, Jonathan Uesato, Maribeth Rauh, Conor Griffin, PoSen Huang, John Mellor, Amelia Glaese, Myra Cheng, Borja Balle, Atoosa Kasirzadeh, et al. Taxonomy of risks posed by language models. In Proceedings of the 2022 ACM conference on fairness, accountability, and transparency, pages 214–229, 2022.
[75] Amanda Silberling. Your public chatgpt queries are getting indexed by google and other search engines. https://techcrunch.com/2 025/07/31/your-public-chatgpt-queries-are-getting-i ndexed-by-google-and-other-search-engines/. Accessed: 2026-02-05.
[86] Michael S Wogalter, Vincent C Conzola, and Tonya L Smith-Jackson. based guidelines for warning design and evaluation. Applied ergonomics, 33(3):219–230, 2002.
[76] Aaron Springer and Steve Whittaker. Progressive disclosure: When, why, and how do users want algorithmic transparency information? ACM Transactions on Interactive Intelligent Systems (TiiS), 10(4):1–32, 2020.
[87] Jie Xu, Zihan Wu, Cong Wang, and Xiaohua Jia. Machine unlearning: Solutions and challenges. IEEE Transactions on Emerging Topics in Computational Intelligence, 2024. [88] Chiyuan Zhang, Daphne Ippolito, Katherine Lee, Matthew Jagielski, Florian Tramèr, and Nicholas Carlini. Counterfactual memorization in neural language models. Advances in Neural Information Processing Systems, 36:39321–39362, 2023.
[77] Sophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes, Yuhang Zhao, and Rahul Chatterjee. Sok: Authentication in augmented and virtual reality. In 2022 IEEE symposium on security and privacy (SP), pages 267–284. IEEE, 2022.
[89] Haibo Zhang, Toru Nakamura, Takamasa Isohara, and Kouichi Sakurai. A review on machine unlearning. SN Computer Science, 4(4):337, 2023.
[78] Ali Sunyaev, Tobias Dehling, Patrick L Taylor, and Kenneth D Mandl. Availability and quality of mobile health app privacy policies. Journal of the American Medical Informatics Association, 22(e1):e28–e33, 2015.
[90] Shuning Zhang, Rongjun Ma, Ying Ma, Shixuan Li, Yiqun Xu, Xin Yi, and Hewu Li. Understanding users’ privacy perceptions towards llm’s rag-based memory. In Proceedings of the 2025 Workshop on Human-Centered AI Privacy and Security, pages 10–19, 2025.
[79] Guanhong Tao, Siyuan Cheng, Zhuo Zhang, Junmin Zhu, Guangyu Shen, and Xiangyu Zhang. Opening a pandora’s box: things you should know in the era of custom gpts. arXiv preprint arXiv:2401.00905, 2023.
[91] Zhiping Zhang, Michelle Jia, Hao-Ping Lee, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, and Tianshi Li. “it’s a fair game”, or is it? examining how users navigate disclosure risks and benefits when using llm-based conversational agents. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1–26, 2024.
[80] Janice Y Tsai, Serge Egelman, Lorrie Cranor, and Alessandro Acquisti. The effect of online privacy information on purchasing behavior: An experimental study. Information systems research, 22(2):254–268, 2011. [81] Evert Van den Broeck, Brahim Zarouali, and Karolien Poels. Chatbot advertising effectiveness: When does the message get through? Computers in Human Behavior, 98:150–157, 2019.
[92] Sebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar, Bin Liu, Florian Schaub, Shomir Wilson, Norman M Sadeh, Steven M Bellovin, and Joel R Reidenberg. Automated analysis of privacy requirements for mobile apps. In NDSS, volume 2, pages 1–4, 2017.
[82] Weiqi Wang, Zhiyi Tian, Chenhan Zhang, and Shui Yu. Machine unlearning: A comprehensive survey. arXiv preprint arXiv:2405.07406, 2024.
15
A
Availability
5. What factors did you consider when deciding what GenAI tool to use?
Study artifacts, including the interview consent form, screening survey, participants’ full information, instructions used in design sessions, interactive prototype, and final codebooks, are linked at: https://osf.io/2w46p/overview?view_only=1b dc27b27b8e44b198638035995bb71a.
6. What information did you seek out, if any, to inform your decision to adopt these GenAI tools? (a) [If none]: If you are interested in adopting a GenAI tool now, what information would you be interested in looking for?
Interview & Design Session Script
B B.1
7. Were there any other GenAI tools you’ve considered but decided not to use? Why did you decide not to use them/it?
Introduction & Warm-Up Questions
B.4
Hi [Participant’s Name], thank you for joining us today. My name is [REDACTED]. This is my colleague [Name], who will be taking some notes in the background. In this interview, I will be asking you about your usage, experiences, and preferences for GenAI tools. As mentioned in the consent form, we would like to audio-record this interview for analysis purposes. I will keep my video on throughout the interview process, but it is completely up to you if you would like to have your video on or off. May I confirm with you that you allow us to audio-record this interview? [Start the audio recording]. Great! Let’s get started with some warm-up questions first, to get to know your knowledge about GenAI tools. There are no right or wrong answers. We’re just interested in your opinions and experiences.
Now we would like to ask you some questions about your experiences and perceptions of the GenAI tools after you adopted them. Again, if your answers differ for some specific GenAI tools, please let us know. 8. On a scale of 0-10, 0 being not at all beneficial and 10 being very beneficial, how beneficial do you consider these GenAI tools to be, and what are the benefits if any? 9. On a scale of 0-10, 0 being not at all harmful and 10 being very harmful, how harmful do you consider these GenAI tools to be, and what are the harms if any? 10. [If S&P concerns are not among the mentioned ones]: How concerned or comfortable are you with the privacy and security practices of these GenAI tools?
• How would you define artificial intelligence, or AI, in your own (a few) words? • How would you define Generative AI or GenAI, in your own (a few) words’?
(a) What are your security and privacy concerns? (b) [If not at all concerned]: Are there reasons why you are not concerned?
In this interview, when we refer to ‘GenAI tools,’ we mean both standalone GenAI apps, such as ChatGPT, as well as GenAI features built into other platforms, apps, or smart devices. For example, that could include voice assistants like Alexa+, AI-generated summaries on social media platforms, smart replies in messaging apps, or personalized recommendations in streaming services. Before we get started, do you have any questions or need any clarification about what would be counted as a GenAI tool?
B.2
11. [If S&P concerns are among the mentioned ones]: What are the security and privacy concerns you have? 12. What steps, if any, have you taken to manage your concerns? (a) [If no steps have been taken]: What are the potential steps you could take to manage the concerns? 13. What challenges do you think users face when managing these concerns?
Consumer-Facing GenAI Tool Usage (RQ1)
B.5
1. What GenAI tools have you used so far? 2. What are the reasons or purposes you have used these tools for? 3. Have you ever used any tool that you no longer use, and why?
(a) [If yes:] What about S&P did you think about, and why were you interested in these topics?
(a) How long have you been using it, and how frequently do you use it? (b) What is the main purpose for which you use this GenAI tool?
i. What steps, if any, did you take to inform yourself about the privacy or security of these tools? ii. Were you able to find all the information you were looking for? How?
Pre-Adoption Considerations (RQ1)
Now we would like to ask you some questions about your experiences and perceptions toward the GenAI tools before you adopted them. If your answers differ for some specific GenAI tools, please let me know.
Practices, Challenges, and Expectations Toward S&P Information Seeking (RQ2&RQ3)
14. In practice, have you ever thought about privacy or security before adopting these tools or when interacting with them?
4. [For participants using multiple GenAI tools]: Which of these GenAI tools do you use most often?
B.3
Post-Adoption Considerations (RQ1)
16
– Elements you need to include:
iii. How confident were you about the trustworthiness of the information you found? iv. Did you make any changes or take any actions based on the information you found? v. Was there any other S&P information you wished to know? vi. How easy or challenging did you find the process?
* The structure/organization of the interface. * The type(s) of security and privacy information that matter most to you. Visual elements (optional) * · Examples: buttons, windows Iteractive mechanisms (optional) * · Example: Pop-ups
(b) [If not:] Could you please tell us why? i. What aspects of S&P might you be interested in and could affect your choice of GenAI tools? Why?
B.6
[Follow-up questions (5 minutes):] • Thank you! Whenever you’re ready, could you walk me through your sketch?
Design Session (RQ3)
• Structure:
Thank you for your valuable insights! Next, we are doing some brainstorming about interfaces that can better help us manage our privacy and security concerns when using GenAI tools. To do this, we are doing a mini sketch session by using the whiteboard feature, as mentioned before the interview. [Launch the Zoom Whiteboard]. [Onboarding training (3 minutes):]
– Can you first give me a high-level overview of this design? What’s the overall layout or structure you had in mind? • Information
• Ask the participant to read the design instructions (see Appendix A).
– What types of S&P-related information are you including in this interface?
• Introduce the tools (pen, highlighter, eraser/undo, shapes, text).
– Why did you choose to include these specific pieces of information?
[Task 1 (5-10 minutes):]
• Visual elements & interactive mechanisms:
• Scenario
– I see you’ve labeled or highlighted a few things – could you walk me through any visual elements or interactive features you’ve marked?
– A consumer is considering signing up for a GenAI tool. • Goals – Please create an interface that previews security and privacy information for the consumer prior to signing up.
– What is the purpose of these features? What would they do or how would a user interact with them? • What problems are you trying to resolve through your design? What motivated you to create the design?
– Elements you need to include: * The structure/organization of the interface. * The type(s) of security and privacy information that matter most to you. Visual elements (optional) * · Examples: buttons, windows * Iteractive mechanisms (optional) · Example: Pop-ups
• What inspired your designs? Have you seen any other similar designs, interfaces, or mechanisms for security and privacy transparency of GenAI tools? – [If yes:] How did you feel about them? What were the benefits and drawbacks?
B.7
[Task 2 (5-10 minutes):] • Scenario
Closing
That brings us to the end of our session today! Thank you so much for your time and all the valuable insights you’ve provided! We are really glad that you decided to take part in our study. We will compensate you through Prolific in 5 to 7 days.
– A consumer has already created an account and is using the GenAI tool and they want to access some security and privacy information. • Goals
C
– Please create an interface for the consumer to access security and privacy information while using the tool. If you would like the same design as you just did, please let us know.
17
Selected Original Sketches
Figure 3: Examples showing traceability from participants’ original sketch concepts to corresponding prototype features, including: granular permissions (1, 4), explanations and pre-commit editing of permissions (2), AI-enabled FAQs (3), clear visual navigation to privacy settings (5), and local, session-specific settings (6). 18