Uploaded June 2026 | Updated September 2026, 3 weeks ago
Envisioning and Mitigating Privacy Risks for Consumer-Facing AI Product Concepts through Human-AI Teaming
Hao-Ping (Hank) Lee, Carnegie Mellon University
AI creates and exacerbates privacy risks, yet product teams often lack the expertise to spot and mitigate issues early—leaving privacy experts to translate principles and correct late-stage choices. What if teams could draft a solid privacy "first draft" before involving experts? We present Privy, a human-AI teaming tool powered by generative AI (GenAI) that enhances non-privacy-expert practitioners' privacy awareness during AI product ideation. Privy helps teams surface likely privacy risks and propose concrete mitigations, producing high-quality intake artifacts so experts can focus on product-specific, high-impact decisions. We grounded Privy's design in a formative study with 11 practitioners and evaluated it with 24 additional practitioners; 13 independent privacy experts rated the resulting privacy assessments high quality, with relevant risks and appropriate mitigations. Practitioners found Privy useful and usable, reporting improved awareness, motivation, and ability in doing privacy work. We conclude with design roles for integrating GenAI into privacy workflows.
View the full PEPR '26 program at usenix.org/conference/pepr26/program
Envisioning and Mitigating Privacy Risks for Consumer-Facing AI Product Concepts through Human-AI Teaming
Hao-Ping (Hank) Lee, Carnegie Mellon University
AI creates and exacerbates privacy risks, yet product teams often lack the expertise to spot and mitigate issues early—leaving privacy experts to translate principles and correct late-stage choices. What if teams could draft a solid privacy "first draft" before involving experts? We present Privy, a human-AI teaming tool powered by generative AI (GenAI) that enhances non-privacy-expert practitioners' privacy awareness during AI product ideation. Privy helps teams surface likely privacy risks and propose concrete mitigations, producing high-quality intake artifacts so experts can focus on product-specific, high-impact decisions. We grounded Privy's design in a formative study with 11 practitioners and evaluated it with 24 additional practitioners; 13 independent privacy experts rated the resulting privacy assessments high quality, with relevant risks and appropriate mitigations. Practitioners found Privy useful and usable, reporting improved awareness, motivation, and ability in doing privacy work. We conclude with design roles for integrating GenAI into privacy workflows.
View the full PEPR '26 program at usenix.org/conference/pepr26/program










