Cover Image for The Other Alignment Problem: Contextual Integrity and Data Use in the Age of AI
Cover Image for The Other Alignment Problem: Contextual Integrity and Data Use in the Age of AI

The Other Alignment Problem: Contextual Integrity and Data Use in the Age of AI

Virtual
Registration
Welcome! To join the event, please register below.
About Event

Ask the Expert ft. Yaxing Yao

Synopsis:

Privacy-enhancing technologies have made remarkable progress protecting data at rest, in transit, and in computation. Far less attention has gone to data in use — the moment a person, application, or AI agent takes information they are fully authorized to access and uses it in a way the original context never contemplated.

This session examines that gap through the lens of contextual integrity. Generative AI has made it acute: employees with legitimate access now paste patient records, student files, and client material into consumer AI tools every day, at a scale traditional controls were never designed to see. Identity has authentication. Access has authorization. Use has almost nothing.

We will look at what the research tells us about how and why this happens, why access-based controls and pattern-matching DLP struggle with unstructured conversational data, and what a usage control layer would need to do: capture purpose, evaluate actual use against it, offer privacy-preserving alternatives such as synthetic or placeholder substitution so work continues, and produce verifiable evidence of what occurred. We will close on what this means as autonomous agents begin acting on data without a human in the loop. The talk draws on a decade of academic work on privacy and human-centered design, and on lessons from deploying these ideas in a live university pilot.

Problem Statement:

Existing privacy controls answer two questions well: who is this person, and what are they allowed to access? Neither answers the question that determines whether privacy is actually preserved — was this data used in a way consistent with the purpose and context under which it was collected?

That gap has always existed, but AI has made it operational. Sensitive data now leaves organizations through unstructured text typed into third-party AI services, frequently through personal accounts on personal devices, by people who are fully authorized to hold that data and are acting in good faith. Nothing in the conventional stack — identity, access management, DLP, or policy and training — can see that moment, intervene in it, or produce evidence about it afterward. The result is a class of privacy loss that is invisible to the organization, irreversible once it occurs, and undocumented when a regulator asks what happened.

Discussion Themes:

This talk will provide an overview of Implicative data with examples and use cases, explore the risks and governance implications of the current standard, and provide a review of the implicative data framework. This talk will enable participants to:

  • Identify implicative data in real systems and use cases

  • Assess privacy, ethical, and security risks beyond traditional “personal data” categories

  • Apply the Implicative data framework and context‑aware governance principles to future proof data governance programs

Related Privacy Enhancing Technologies (PETs):

  • Synthetic data generation: substituting realistic synthetic values for real identifiers so a task can proceed without exposure

    • De-identification, redaction, and pseudonymization: applied dynamically at the point of use rather than as a batch process

    • Purpose limitation and use-limitation enforcement: translating a longstanding Fair Information Practice principle into a runtime control

    • Policy-based and attribute-based usage control (UCON): the research lineage that extends access control into ongoing use

    • Privacy-preserving audit and attestation: evidence that records decisions and metadata rather than content

    • Contextual-integrity-based frameworks: evaluating information flows against contextual norms rather than data classification alone

    • Related but distinct: differential privacy, federated learning, and homomorphic encryption protect data during computation; the controls discussed here address the human interface, where those techniques do not reach

Pre-Discussion Resources:

·        Nissenbaum, H. Privacy in Context: Technology, Policy, and the Integrity of Social Life

·        Lu, Y., Zhang, C., Yang, Y., Yao, Y., & Li, T. From Awareness to Action: Exploring End-User Empowerment Interventions for Dark Patterns in UX — Best Paper Award, CSCW 2024

·        Yaxing Yao publications: https://yaxingyao.github.io/publications.html

·        NSF-supported work on privacy education and design through synthetic persona data generation (NSF SaTC #2426395)

·        Industry data on the scale of the problem: Cyberhaven Labs AI Adoption and Risk Report; Harmonic Security, From Payrolls to Patents; IBM Cost of a Data Breach 2025

Guest Expert: Yaxing Yao

Yaxing Yao, Assistant Professor of Computer Science, Johns Hopkins University; Co-founder and CEO, Readax

Yaxing Yao is an Assistant Professor of Computer Science in the Whiting School of Engineering at Johns Hopkins University, where his research sits at the intersection of human-computer interaction, privacy and security, and accessibility. His work focuses on enhancing people's privacy literacy and giving them meaningful control over their information in increasingly complex socio-technical environments, across contexts including AI, embodied AI agents, and online privacy, and with particular attention to at-risk populations. He publishes at CHI, CSCW, SOUPS, USENIX Security, PoPETS, and ASSETS, and his research has been supported by the National Science Foundation, Google, and Meta. He was previously a postdoctoral researcher at Carnegie Mellon University, and holds a PhD in Information Science from Syracuse University. He is also co-founder of Readax, which builds usage control technology for enterprise AI.

Moderator: Kimberly Lancaster

Trusted Privacy Advisor who Guides Data Protection, Drives Operational Excellence, and Leads with Integrity by aligning with InfoSec, Security, GRC, Compliance, and Data Governance. Board Member, Speaker, and Author.