Paper deep dive
What Security and Privacy Transparency Users Need from Consumer-Facing Generative AI
Jiaxun Cao, Yu Dong, Chunxi Zhan, Rithvik Neti, Sai Teja Peddinti, Pardis Emami-Naeini
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 96%
Last extracted: 6/21/2026, 9:33:03 AM
Summary
This research paper investigates how users of consumer-facing Generative AI (GenAI) perceive and interact with Security and Privacy (S&P) transparency. Through 21 semi-structured interviews and design sessions, the authors found that current S&P communications (like Model Cards or System Cards) are often perceived as incomplete, ineffective, or lacking credibility, failing to drive initial adoption. Instead, users rely on proxies like popularity to infer safety. The study identifies a gap between technical transparency and consumer needs, proposing five dimensions for future design practices to support decision-making and build trust in high-stakes contexts.
Entities (9)
Relation Signals (4)
ChatGPT â developedby â OpenAI
confidence 100% ¡ mistakenly assuming that ChatGPT complies with... or that OpenAI is responsible...
Generative AI (GenAI) â hasrisk â Security and Privacy (S&P)
confidence 100% ¡ Security and privacy (S&P) researchers have warned about multiple GenAI risks...
EU AI Act â governs â Generative AI (GenAI)
confidence 90% ¡ The EU AI Act [35] introduces user-facing transparency obligations...
Google Model Cards â targets â Expert Audiences
confidence 90% ¡ Much of the current S&P transparency work around GenAI is oriented toward expert audiences... Examples include Google Model Cards...
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Users increasingly rely on consumer-facing generative AI (GenAI) for tasks ranging from everyday needs to sensitive use cases. Yet, it remains unclear whether and how existing security and privacy (S&P) communications in GenAI tools shape users' adoption decisions and subsequent experiences. Understanding how users seek, interpret, and evaluate S&P information is critical for designing usable transparency that users can trust and act on. We conducted semi-structured interviews and design sessions with 21 U.S. GenAI users. We find that available S&P information rarely drove initial adoption in practice, as participants often perceived it as incomplete, ineffective, or lacking credibility. Instead, they relied on rough proxies, such as popularity, to infer S&P practices. After adoption, uncertainty about S&P practices constrained participants' willingness to use GenAI tools, particularly in high-stakes contexts, and, in some cases, contributed to discontinued use. Participants therefore called for transparency that supports decision-making and use, including trustworthy information (e.g., independent evaluations) and usable interfaces (e.g., on-demand disclosure). We synthesize participants' desired design practices into five dimensions to facilitate systematic future investigation into best practices. We conclude with recommendations for researchers, designers, and policymakers to improve S&P transparency in consumer-facing GenAI.
Tags
Links
- Source: https://arxiv.org/abs/2604.17270v1
- Canonical: https://arxiv.org/abs/2604.17270v1
Trouble viewing inline? Open PDF directly â
Full Text
88,981 characters extracted from source content.
Expand or collapse full text
What Security and Privacy Transparency Users Need from Consumer-Facing Generative AI Jiaxun Cao â , Yu Dong âĄâ , Chunxi Zhan âĄâ , Rithvik Neti â , Sai Teja Peddinti § , Pardis Emami-Naeini â â Duke University, ⥠Duke Kunshan University, § Google Abstract Users increasingly rely on consumer-facing generative AI (GenAI) for tasks ranging from everyday needs to sensitive use cases. Yet, it remains unclear whether and how existing security and privacy (S&P) communications in GenAI tools shape usersâ adoption decisions and subsequent experiences. Understanding how users seek, interpret, and evaluate S&P information is critical for designing usable transparency that users can trust and act on. We conducted semi-structured inter- views and design sessions with 21 U.S. GenAI users. We find that available S&P information rarely drove initial adoption in practice, as participants often perceived it as incomplete, ineffective, or lacking credibility. Instead, they relied on rough proxies, such as popularity, to infer S&P practices. After adop- tion, uncertainty about S&P practices constrained participantsâ willingness to use GenAI tools, particularly in high-stakes contexts, and, in some cases, contributed to discontinued use. Participants therefore called for transparency that supports decision-making and use, including trustworthy information (e.g., independent evaluations) and usable interfaces (e.g., on-demand disclosure). We synthesize participantsâ desired design practices into five dimensions to facilitate systematic future investigation into best practices. We conclude with rec- ommendations for researchers, designers, and policymakers to improve S&P transparency in consumer-facing GenAI. 1 Introduction Generative AI (GenAI) has seen widespread adoption for di- verse purposes, from everyday information seeking to highly sensitive, personal use cases such as health, legal, and financial consultations [73,91]. Security and privacy (S&P) researchers have warned about multiple GenAI risks, including adversar- ial attacks, data breaches, secondary use, and the sharing or sale of personal data [19, 20, 47, 54, 88, 91]. Yet, empirical evi- dence suggests that these S&P intrusions often occur without usersâ awareness or consent [51]. Even when users are aware * The two authors contributed equally to this work. that such risks exist, their mental models of GenAI data prac- tices are often inaccurate [10, 48, 56, 57, 91]. Prior work shows that users frequently overestimate the protections provided by GenAI companies [48, 56, 57]. For instance, mistakenly assuming that ChatGPT complies with the Health Insurance Portability and Accountability Act (HIPAA) when used for mental health support [48], or that OpenAI is responsible for ensuring privacy protections for third-party generative pre- trained transformers (GPTs) [56]. These prevalent S&P misconceptions point to a gap in cur- rent GenAI transparency â users are likely receiving limited or ineffective communication about data practices and asso- ciated risks. Much of the current S&P transparency work around GenAI is oriented toward expert audiences, presum- ing substantially higher technical literacy than most end users. Examples include Google Model Cards [62], Meta System Cards [7], and IBM AI FactSheets [6]. Policy efforts in the U.S. (e.g., Colorado SB24-205 [4]) and beyond (e.g., the EU AI Act [35]) have also remained relatively limited, tending to emphasize organizational accountability and overlook re- quirements for consumer-facing S&P transparency [66, 67]. However, S&P transparency can shape consumersâ adop- tion decisions and post-adoption experiences [30, 33, 65, 80]. When transparency is reliable, actionable, and presented in forms that users can readily interpret and act on, it can support informed S&P decision-making and help build trust in the technology [65, 72]. For instance, prior work has proposed privacy labels that present salient information in a digestible format and impact usersâ willingness to purchase Internet of Things (IoT) devices [32, 34, 44]. In the GenAI context, how- ever, comparable empirical evidence remains limited â it is unclear whether, what, and how S&P information influences usersâ adoption decisions and ongoing use of GenAI tools. Beyond S&P transparency content, prior work has artic- ulated a broader design space spanning multiple dimen- sions [72], including timing [30, 39], channel [72], modal- ity [86], and user control [74]. Each technology introduces distinct challenges and opportunities across these dimensions that must be accounted for when designing effective trans- 1 arXiv:2604.17270v1 [cs.HC] 19 Apr 2026 parency approaches [72]. Motivated by this perspective, we examine whether and how users currently seek, understand, and evaluate existing GenAI S&P information, and what im- provements they hope to see in the content and design of GenAI S&P transparency. Accordingly, our work asks three research questions (RQs): ⢠RQ1: What, if any, S&P information about consumer- facing GenAI tools factors into usersâ adoption decisions and post-adoption experiences? ⢠RQ2: What are usersâ current practices and challenges in seeking, understanding, and evaluating S&P information about consumer-facing GenAI tools? ⢠RQ3: What are usersâ preferences and expectations for S&P transparency in consumer-facing GenAI tools? To answer these questions, we conducted 21 semi- structured interviews followed by design sessions. Our find- ings suggest that existing S&P information is often perceived as incomplete, ineffective, and lacking credibility, and rarely drives GenAI adoption decisions. At the same time, partici- pants described pressing needs for effective S&P communica- tion in GenAI â needs they expected to become increasingly consequential as their high-stakes use grows. Across inter- views and design sessions, participants articulated specific information needs (e.g., trustworthy independent evaluations) and proposed a rich set of design practices across five dimen- sions. Grounded in these findings, we discuss design oppor- tunities for advancing GenAI S&P transparency and offer actionable recommendations for S&P researchers, designers, and policymakers. As an exploratory study intended to spur future research on the emerging design space of GenAI S&P transparency, we make three contributions: (1) empirical accounts of how users currently seek, understand, and evaluate GenAI S&P infor- mation; (2) a synthesis of participant-informed transparency design practices into a set of dimensions for future design and evaluation; and (3) actionable implications and recommen- dations for S&P researchers, designers, and policymakers to advance consumer-facing S&P transparency in GenAI. 2 Related Work GenAI S&P risks and usersâ (mis)conceptions. The S&P risks of GenAI have been extensively investigated since its emergence. From a security perspective, GenAI systems are vulnerable to adversarial threats, including data poison- ing [59], prompt injection [54], and spoofing [79], among others. GenAI can also enable malicious use, such as generat- ing convincing phishing messages [13]. Privacy risks center on extensive data collection, data breaches, and inappropri- ate use or sale of personal data [19, 20, 47, 56, 88, 91]. With the increasingly human-like and intelligent nature of GenAI tools, users share highly sensitive data [56, 81, 85, 91], such as medical records, personal trauma, and payslips [91]. Such data can enable profiling, as GenAI systems may infer ad- ditional attributes, such as usersâ sexual orientation, gender, and religious beliefs [56, 85]. These sensitive data are often shared beyond GenAI companies, including with third parties that build applications on top of host GenAI models and may not guarantee users comparable privacy protections [56]. Yet, these S&P harms often unfold with limited user aware- ness and without informed consent [51, 91]. Moreover, ex- tensive empirical research shows that usersâ mental models of GenAI data practices, such as how data is collected, re- tained, used for training, and reused, are frequently incom- plete or incorrect [10, 48, 56, 57, 83, 90, 91]. For example, users may not recognize all stakeholders who can access their data, including internal staff who review conversations for safety [10, 91] and third parties who build GenAI plug-ins (e.g., custom GPTs) [56]. Prior work also finds that users misunderstand the scope of data controls and policies. For instance, Malki et al. [57] report that users often assume dele- tion or training opt-out removes what the model has already learned. In practice, machine unlearning remains an unsolved problem [82, 87, 89]. Similarly, Ma et al. [56] find that users mistakenly believe OpenAI provides privacy protections for custom GPTs [69, 70]. In more sensitive contexts, such as mental health, users often assume that ChatGPT complies with HIPAA, even though it does not [48]. Such extensive empirical evidence on usersâ misconcep- tions about GenAI S&P practices reveals a significant gap in the current infrastructure for GenAI S&P transparency. Specif- ically, existing S&P information and how it is communicated may not sufficiently support users in understanding, trusting, and acting on data practices. Our work thus contributes by surfacing whether and what S&P transparency needs users have for a more trustworthy GenAI ecosystem. Existing S&P transparency approaches. While GenAI S&P transparency remains underexplored, existing research on S&P transparency has examined a range of prior technolo- gies [12, 27, 29, 31, 38, 41, 45, 46, 49, 72], including mobile apps [78, 92], IoT [22, 31], and ubiquitous computing sys- tems [49]. A common effort to promote S&P transparency is the use of privacy policies, yet they have been widely criti- cized for being lengthy and difficult to understand [41, 61]. Towards more effective S&P communication, prior work high- lights several design dimensions [72], including timing (when information is presented), channel (where it is presented), modality (how it is presented), and user control (how users can act on it). To improve the readability of privacy policies, alterna- tive transparency approaches have emerged, such as privacy nutrition labels â analogous to food nutrition labels that surface salient information in a concise, standardized for- mat [23, 31, 44]. Prior work has identified and evaluated label factors that matter to consumers. For example, Emami-Naeini et al. [31] found that consumers particularly wanted to know who their data might be shared with. Beyond label content, 2 Figure 1: Methodology overview of our main study. We conducted semi-structured interviews, followed by design sketching sessions and follow-up questions. researchers have discussed four common consumer-facing label formats â binary, graded, descriptive, and multi-layer â each with distinct tradeoffs [18, 23, 24, 42]. Yet, in GenAI â particularly around S&P â such empirical and design guid- ance on what information to prioritize and how best to present it remains scarce. Current real-world examples of GenAI transparency â though not necessarily S&P-oriented â include model cards [62], system cards [7], and datasheets [6], which are technical documentation that summarizes key properties of models and datasets for developers, auditors, and other ex- perts. However, efforts to support consumer-facing S&P trans- parency in GenAI remain limited. Moreover, we lack empiri- cal insights into whether and how GenAI users seek, interpret, and evaluate the S&P information that is available today. Policy has likewise offered limited support for consumer- facing S&P disclosures in GenAI. In the U.S., there is no comprehensive federal requirement for standardized end-user disclosures, and emerging state laws largely emphasize or- ganizational accountability (e.g., Coloradoâs SB24-205 [4] focuses on risk management and documentation for âhigh- riskâ AI in consequential decisions). The EU AI Act [35] introduces user-facing transparency obligations (e.g., notice of AI interaction and of emotion recognition/biometric cat- egorization), but does not specify a format to present these notices, leaving implementation uncertain. Therefore, it is crucial to inform policies with empirical and design insights that can guide GenAI companiesâ S&P transparency â both in what information to disclose and how to disclose it. 3 Methodology Recruitment. We recruited participants from Prolific 1 from August to October, 2025. The Prolific participants were di- rected to a Qualtrics 2 screening survey. To mitigate social desirability [40] and demand characteristics [60], we adver- tised our study without mentioning its S&P focus, broadly 1 w.prolific.com 2 w.qualtrics.com framing it as âunderstanding usersâ perspectives and experi- ences with GenAI tools.â To capture a comprehensive range of consumer-facing GenAI products, we defined âGenAI toolsâ in both the pre-screening survey and interviews to include âstandalone GenAI appsâ (e.g., ChatGPT) and âGenAI fea- tures built into other platforms, apps, or smart devicesâ (e.g., Alexa+). Participant demographics and GenAI usage are de- tailed in Section 5. Eligibility and pre-screening. Participants eligible for the main study must (1) be at least 18 years old, (2) live in the United States, and (3) have used at least one GenAI tool. In the pre-screening survey, participants answered eligibility ques- tions, provided consent to participate in the survey, indicated their willingness to participate in the 45-60 minute main study, which included an interview and design session on Zoom 3 . Participants who were ineligible, did not provide full consent, or were not interested in the main study were redirected to Prolific and compensated at a flat rate of 0.15 USD. Partici- pants who proceeded to the remaining survey reported their Prolific IDs (for compensation purposes), GenAI usage, and demographics. We required a minimum threshold of GenAI usage (i.e., having used at least one GenAI tool) to support richness of insights. All participants who completed the sur- vey were compensated at an hourly rate of 14.26 USD. The median completion time was approximately 3 minutes. Com- plete recruitment and pre-screening materials are included in Appendix A. Pilot interviews. To assess interview clarity and timing, we conducted two pilot interviews with participants recruited through the first authorâs personal connections. Both partici- pants met the main study eligibility criteria. After each pilot, the research team debriefed on question clarity and any diffi- culties the participant encountered when answering. We then revised unclear questions, reordered prompts to better match a natural conversational flow, and prepared backup prompts for cases where participants struggled to respond. Main study procedure. To reduce no-shows, we messaged each participant on Prolific one day before the main study 3 https://zoom.us/ 3 to confirm attendance and shared brief instructions for us- ing Zoom Whiteboard 4 . We reached data saturation [71] at the seventeenth study, i.e., no additional insights emerged. Aligned with qualitative methodology guidance [37], we con- ducted four additional studies and did not identify substan- tially new insights. In total, we conducted 21 interviews and 20 design sessions 5 . Each participant received 20 USD in compensation after completing the main study. Figure 1 pro- vides an overview of the main study procedure. Each session involved one primary interviewer and a second researcher taking notes. The full protocol is included in Appendix B. The main study consisted of the following sections: â˘Section 0: Introduction & GenAI definitions. We asked participants to share their own definitions of GenAI and restated our definition of âGenAI toolsâ to align our terminology. â˘Section 1: Consumer-facing AI tool usage. We asked participants about the GenAI tools they used, their pur- poses of use, any tools they had discontinued and their reasons for discontinuation, and the GenAI tool they used most frequently. For participants who used multiple GenAI tools, we asked them to describe their experi- ences in general and to note tool-specific differences when relevant. â˘Section 2: Pre-adoption considerations. To compre- hensively capture factors shaping participantsâ experi- ences across their entire use journey, we began by prob- ing their pre-adoption considerations, including what criteria they used to choose a GenAI tool and what infor- mation they sought to support that decision. â˘Section 3: Post-adoption considerations. We then asked participants about the factors shaping their post- adoption use. To avoid priming S&P concerns, we first invited participants to describe, in general terms, the perceived benefits and concerns. After they had shared all their initial thoughts, we followed up with questions about their specific S&P considerations and any mitiga- tion practices post-adoption. ⢠Section 4: Practices, challenges, & expectations to- ward S&P information seeking. We asked participants about their S&P information-seeking practices, includ- ing the sources they consulted, how they evaluated and felt about the information they found, and whether it led them to change their behavior or tool choices. We also asked about challenges they encountered and what additional information they wished they had to inform adoption and usage decisions. â˘Section 5: Design sketching session. To elicit partic- ipantsâ preferences for how desired S&P information should be presented, we asked them to visualize their ideas after introducing the sketching tools. We empha- 4 Getting started with Zoom Whiteboard. 5 One participant did not complete the design session due to time con- straints. sized that sketches could be rough and should focus on the overall structure and the elements they consid- ered most important. After this onboarding, we asked participants to sketch transparency interfaces for the pre- adoption and post-adoption stages, if they differed. We then asked participants to walk through their designs and explain their motivations and rationales. Qualitative data analysis.All interviews were audio- recorded and transcribed in English using Zoomâs transcrip- tion service. The first author proofread all transcripts prior to analysis to ensure accuracy and readability. Three researchers then conducted an iterative thematic analysis, consistent with prior studies [55,68,84]. The first author served as the primary coder and developed two initial codebooks, one for the inter- view transcripts and one for participantsâ design ideas. These codebooks were refined iteratively through weekly meetings with the full research team. Two secondary coders, one for the interview data and one for the design-session data, then applied the codebooks to 20% of the dataset. We compared the primary and secondary codersâ coding and computed inter- rater reliability (IRR). When agreement reached CohenâsÎş of 0.7, which is commonly considered âgoodâ [14], we pro- ceeded using the primary coderâs codes. WhenÎş < 0.7, the coders met to discuss and reconcile disagreements and to up- date the codebook. The secondary coders then applied the revised codebook to an additional 20% of the data, repeating this process until Cohenâs Îş reached 0.7. Limitations. As is common in qualitative research, our sam- ple size was relatively small, which may limit the generaliz- ability of our findings in several ways. First, all participants were recruited via Prolific and, combined with our eligibil- ity requirement of prior GenAI use, our sample likely over- represents relatively active GenAI users. However, partici- pants provided rich accounts of lived experiences, including concrete concerns and decision processes. This aligns with our exploratory goal of identifying where current S&P trans- parency falls short in practice and what design improvements could better support users. Second, our study relied on self- reported accounts, which may be subject to social desirability bias [40]. To mitigate this influence, we framed recruitment materials without mentioning âsecurityâ or âprivacyâ and recruited on a rolling basis to capture a diverse range of perspectives. Third, as users often develop S&P considera- tions over time [52], we structured our interview questions and design tasks around pre- and post-adoption phases to capture a broader use journey rather than a single timepoint. However, this framing may have subtly shaped how partici- pants organized their reflections across phases. To mitigate this potential bias, we emphasized throughout the interview and design session that participants could provide the same answers or propose the same design outcomes across both phases if they felt both applied. 4 4 Ethics Statement This study was approved by our Institutional Review Board (IRB). All participants provided informed consent at each study stage, including the pilot sessions, pre-screening survey, and main study sessions. Participation was voluntary, and par- ticipants could skip any question, pause, or stop at any time without penalty. All participants, regardless of completion, were compensated at rates consistent with institutional and platform norms. To minimize risk, we avoided requesting sen- sitive personal identifiers and informed participants that they could keep their camera off throughout the session. We audio- recorded sessions only with explicit consent. Before analysis, the first author proofread and de-identified transcripts and design sketches. We separated compensation identifiers (e.g., Prolific IDs) from research data and used participant codes (e.g., P1âP21) in analysis and reporting. Only the research team had access to the raw data. In publications, we report only de-identified quotes and descriptions and avoid including details that could reasonably re-identify participants. 5 Results Our participants represented diverse demographics and ex- hibited varied levels of GenAI usage. Table 1 summarizes participantsâ basic demographics and GenAI usage. Full de- mographics and GenAI usage information are included in Appendix A. 5.1 RQ1: Factors in GenAI Adoption & Use 5.1.1 Factors in Adoption Decisions Popularity, utility fit, and price as main drivers of initial adoption. Popularity of a GenAI tool was the most men- tioned factor shaping 14/21 participantsâ adoption decisions. For instance, P4 explained: â[The primary factor that informed adoption] was just what was out there and being talked about, seeing that other people were getting useful results.â Notably, 10/14 participants treated a toolâs high popularity as a signal of stronger S&P protections. Conversely, tools perceived as less popular prompted resistance to adoption due to S&P concerns (P4, P9). For example, P9 mentioned: âA lot of these tools, like ChatGPT and whatnot, are so big that, if I end up having a problem, everybody else will have a problem, too. So theyâre big enough that I feel fairly safe using it. But if thereâs a name that seems suspicious to me, or not very big, and I havenât heard of it, then Iâd be very skeptical to try it, so I just wouldnât even go for it. Reputable names are how I focus on being safe and secure, mostly.â Following popularity, context fit â namely, how well a tool fits usersâ utility needs â was another major driver of adoption (12/21). For example, P9 said: âIâd want to see what benefit Iâm going to get from the tool. How it would help me, what its capabilities or fea- tures are, and whether it aligns with a problem Iâm hav- ing.â The third most commonly mentioned factor shaping usersâ adoption decisions was the price (7/21), with lower-cost or non-subscription tools perceived as more desirable. For ex- ample, P8 mentioned: âHow do I evaluate? Most of the time, I go on Google [...] I do a search and I look for prices, because I want to see whatâs cheaper [...] I donât want to pay anything monthly [...] Thatâs a big factor, the price.â S&P certainty as a desired adoption factor, despite scarce information. When asked â without any S&P prompts â what shaped their adoption decisions, 7/21 participants spon- taneously mentioned S&P as an important consideration at adoption. For instance, P5 mentioned: âInitially, I was very hesitant to use any of them [GenAI tools] because I was concerned about privacy.â However, 10/21 participants complained that needed S&P information about GenAI tools was not readily available or usable at the point of adoption. For example, P21 said: âIf there was any AI that was very clear and upfront about things like, âwe encrypt things,â or whatever, any company that was transparent about that stuff would be a better green flag [...] But the thing is, I donât see any of that with any of the AI currently [...] If they were really transparent and open about that, Iâd be interested.â 5.1.2 Factors in Post-Adoption Experiences Output quality driving continued use of GenAI tools. 12/21 participants noted that their continued use of GenAI tools was mainly driven by the perceived quality of outputs, including the perceived accuracy/credibility (8/12) and lack of bias (4/12) of AI-generated information. Participants reported that tools that performed well on these metrics improved their efficiency, reduced cognitive load, or exposed them to more diverse, yet neutral perspectives. For example, P2 said: âThe factors were, most importantly, performance, how quickly it works, and its accuracy as well [...] I try the same prompt on many platforms, and the one that gives me the most accurate and best results is the one I con- tinue using.â Additionally, 4/12 participants cared about whether GenAI tools exhibited any biased or overly opinionated behavior. For example, P16 mentioned: âChatGPT has bias. It has told me that the sources that 5 IDMost Often Used GenAI Tool(s)Usage FrequencyAgeGenderEthnicity P1CopilotMore than once a day45 - 54FemaleWhite P2DeepseekMore than once a day25 - 34MaleMiddle Eastern or North African P3Alexa+, GeminiMore than once a day45 - 54FemaleWhite P4ChatGPTMore than once a day45 - 54MaleAsian P5ChatGPT, GeminiMore than once a day45 - 54FemaleWhite P6ChatGPTMore than once a day45 - 54MaleAsian P7GeminiMore than once a day35 - 44FemaleBlack or African American P8Alexa+More than once a day45 - 54FemaleWhite P9ChatGPTOnce a week25 - 34MaleWhite P10ChatGPTOnce a week55 - 64FemaleAsian P11GeminiMore than once a day65 - 74MaleWhite P12ChatGPTMore than once a day25 - 34MaleAsian P13Alexa+, ChatGPTMore than once a day45 - 54MaleWhite P14ChatGPTOnce a day45 - 54MaleWhite P15ChatGPTOnce a month35 - 44FemaleBlack or African American P16Pi, CopilotOnce a day35 - 44FemaleBlack & White P17GeminiMore than once a day45 - 54FemaleAsian P18ChatGPTOnce a day45 - 54MaleWhite P19ChatGPTMore than once a day45 - 54MaleWhite P20ChatGPTOnce a day25 - 34FemaleBlack & White P21ChatGPTOnce a day25 - 34Non-binary / third genderWhite Table 1: Summary of participant demographics and GenAI usage. Full table in Appendix A. it gets are verifiable news [...] but Iâve noticed itâs been very biased towards, politically, a certain direction.â S&P uncertainty constraining AI use cases. 10/21 par- ticipants pointed out that limited visibility into GenAI toolsâ S&P practices made it difficult to adopt concrete, effective risk mitigation strategies. As a result of S&P uncertainty, 3/21 participants chose to reduce or even discontinue their use of some GenAI tools, which in turn undermined the value of per- sonalization. For example, P1 described how she significantly reduced her use of ChatGPT and stopped signing in due to a data breach [75]: âIâve dropped off on ChatGPT a lot over the last week or two, when I found out that they had a leak and that peopleâs chats were found on Google. That very much bothered me [...] Before, I would log in and let it track what I talked about so that I could get a more personal- ized experience. But if that means that I have to give up my privacy and what we talk about, itâs not a good trade- off for me. Now Iâm using it for very generic information, and Iâm also not logging in.â Such constrained use became more pronounced when the perceived S&P stakes were higher. 10/21 participants reported heightened anxiety and discomfort when using GenAI tools in contexts with higher S&P stakes, such as legal support (3/10), proprietary content creation (3/10), work-related tasks (3/10), and others. For instance, P10 worried that sensitive legal information, such as litigation strategy, could be exposed to opposing parties. If using GenAI tools for legal support, P10 indicated that they would compare different toolsâ S&P practices, if such information were available: âFor legal uses, which is a lot more sensitive, at that point you would be comparing the privacy level of one against the other. In the case of a law firm, their approach to litigating, for example, you donât want that known to your opposing party â it could cost a lot if somebody can get hold of the information and somehow use it in a nefarious way.â Additionally, 3/10 participants who worked in proprietary content creation raised concerns about content theft and ex- pressed low trust in GenAIâs training practices. P13 explained: âIf I was writing a movie script or a TV show that I wanted to keep proprietary, I wouldnât want anyone to know about it. I donât trust that theyâre not going to use it in their models.â 3/10 participants expressed uncertainty about whether workplace surveillance might monitor employeesâ GenAI tool use. For example, P6 said: âSome AI tools are prohibited at our institute [...] So if I upload a file at work, and the file contains sensitive data [...] But Iâm not sure whether all these actions, like data input and file uploading, are monitored by the institute. That is the issue.â 5.2 RQ2: Current S&P Information Seeking 5.2.1 Sources Used to Find S&P Information Skimming or summarizing information from official sources. 15/21 participants reported consulting official docu- mentation either by (1) skimming it themselves (13/15) or (2) summarizing it using a GenAI tool (2/15). For instance, P5 described her S&P information-seeking practice: 6 âI skimmed the terms and conditions on privacy informa- tion for ChatGPT and Gemini.â P20 described her approach of summarizing the informa- tion using a GenAI tool: âLooking at the privacy statements they have, even though they make them very difficult and 50 or 60 pages long, where I canât really read through all of it, I end up having to use AI to summarize it.â Consulting trusted independent partiesâ opinions and lived experiences regarding GenAI toolsâ S&P practices. 6/21 participants reported looking into (1) articles (3/6) and (2) online communities (6/6) to find information about the S&P practices of GenAI tools. P2 described reading articles about Grokâs S&P practices, which led him to avoid using it: âI read a lot of articles about Grok AI, for example, and how it works, and how it uses information. Basically, the information is used constantly. Itâs sold and given to many vendors [...] Thatâs why I donât use it at all.â P4 reported consulting Reddit for other usersâ perspectives on GenAI toolsâ S&P practices: âI look at Reddit and see people who are in a similar position to me, using AI tools in similar ways, and what their thoughts were. It helps me get a general sense of what others think about these same topics [S&P practices of GenAI tools].â 2/6 participants compared multiple sources to evaluate S&P information. P1 was interested in how S&P practices worked in reality by comparing official documentation with other usersâ lived experiences shared online: âI cross-reference that [official documentation] with what people have said online about the reality of how those things [S&P practices] have played out. Because some- times what those privacy statements are saying may not actually align with what people are experiencing.â Similarly, P13 relied on online posts to keep up with changes to official documentation: âGoogle is changing its terms of service. Sometimes, on tech sites, or even on X, or maybe Reddit to some extent, people will post and say the terms of service changed and itâs really bad. So I pay attention to things like that.â 5.2.2 Perceptions Toward Existing S&P Transparency Existing S&P transparency perceived as ineffective. The perceived ineffectiveness was associated with two main rea- sons: (1) participants often did not know what they had agreed to due to lengthy, difficult language (6/21), and (2) changes to S&P practices were not communicated in ways that partici- pants could easily notice or access (3/21). P1 noted: âI donât feel Iâve found the reality or the truth of the situ- ation. When they have pages and pages of legal mumbo jumbo, it feels like a smokescreen to confuse people [...] It doesnât make me feel I have all the information I need to really feel comfortable.â 3/21 participants expressed concerns about ineffective com- munication of changes to S&P practices. P16 said: âSometimes there are pop-ups that say, âHey, weâve changed something.â But especially when youâre logged in, if I donât open a completely new browser and I just pick back up in an old one and change the topic, itâs not a fresh web page. So it doesnât automatically tell you if thereâs a new update. You have to exit and start a new session for that. So itâs not transparent, and it doesnât notify you every time you visit the page.â Existing S&P transparency perceived as lacking credibil- ity. 8/21 participants were particularly concerned about the credibility of available S&P information. For instance, P3 expressed doubt about official claims in the terms of service: âThere are a lot of claims that they try to make it as secure as possible, but I donât know if I believe it. Everything says, âWeâre good, and we protect your information,â but I still donât feel confident in their explanations about how they keep things safe for users.â P1 talked about how the scandal around ChatGPT usersâ chats appearing in public search results [75] heightened her concerns about the credibility of official documentation across consumer-facing GenAI tools: âSure, they can say X, Y, and Z in their privacy policy, but ChatGPT also said X, Y, and Z in their privacy policy, and how it actually played out, and what the reality became, donât match up. And so you have to wonder in the back of your mind, is that going to happen with Gemini? Is that going to happen with Copilot? Is that going to happen with the ones that are embedded in my bank account?â 3/21 participants were worried about the lack of credibil- ity regarding the effectiveness or outcomes of S&P controls provided by GenAI tools. For example, P14 was concerned about not knowing whether their S&P choices were respected when using ChatGPT: âIf I direct it [ChatGPT] not to remember a session, I worry that I donât have any confirmation that it wonât. If I say, âDisregard all session history,â I canât really tell whether it did or not.â P18 raised similar concerns about ChatGPT and Copilot: âIâve looked at the privacy configuration within ChatGPT and some in Copilot [...] But quite honestly, I donât have a lot of faith in those toggle switches, that they really offer the privacy they say they do.â Perceived surface-level assurance at a glance. 2/21 par- ticipants reported a sense of assurance from existing S&P transparency, often without digesting the details. For instance, 7 P5 described feeling reassured by privacy policies even with- out understanding everything: âIt [privacy policy] made me feel a little bit better. I didnât really understand everything I was reading, and I quickly got bored with it, so I just thought, âWhatever, Iâm just going to go with it. I think itâl be fine.ââ 5.3 RQ3: S&P Transparency for GenAI 5.3.1 S&P Transparency Content Wishlist Who has access to user data. 9/21 participants wanted to know whether their data could be accessed by unknown third parties (8/9), models (2/9), or other users (2/9). For in- stance, P6 wanted to know whether their information was being shared with third parties: âThey should show whether the data will be shared, for example with other companies or institutions, and whether it will be shared with third parties.â 2/9 participants wanted to know whether and how their data was transmitted, including to models beyond their awareness, as P1 mentioned: â[It would be good to know] how many different AI systems are you feeding it [data] into? Are you taking it [data], say, if youâre using Alexa+, and you [Alexa+] feed my information into your model, but then you also feed it into another model for comparison purposes? Now my information is in some other model that Iâm not aware of, and I didnât agree to.â 2/9 participants were also curious about whether their input data, if used for training, might later surface in outputs to other users. For example, P14 said: âIf Iâm going through a legal problem and talking to it [GenAI tool] a lot about that, Iâm interested in knowing whether it uses my sessions to learn from and then advise other people. Iâm interested in how it takes someoneâs session and applies that to other peopleâs sessions.â Independent evaluations of S&P practices. 4/21 partici- pants called for independent evaluations or audits of GenAI companiesâ S&P practices that provide users with more cred- ible, digestible, and comparable insights. For example, P13 envisioned a third-party website that would translate compa- niesâ S&P practices into usable consumer-facing summaries and comparisons: âThere should be an independent website that would audit all the companies. So if you had a question about what the terms of service really are, you could go to this website and it would tell you. You could even have AI distill it for you, like take the terms of service and put it into one paragraph, or show it in a chart. Then you could compare your options as a consumer. Which one is the safest, which is the most secure, and which one isnât going to sell my data, or is going to sell my data? There isnât really a clearinghouse for that.â P4 further specified which evaluation providers he would trust more, drawing an analogy to organic food certification that combines public oversight with reputable private accredi- tation: âWe need a combination of government involvement as well as accredited third parties [...] Think about certified organic food. The organization that certifies it has to be in good standing and have a reputation. I think both spaces, the government side and the private industry side, are beneficial. They both have weak spots, but together they complement each other. So it would have to be something like that, where maybe there was certification through the government and third-party certification as well. That would make me feel safe.â Information on data storage, training, and inference. 5/21 participants requested having transparency into what data the GenAI tools store, train, or infer. For instance, P14 requested visibility into what types of data are stored, including meta- data and inferred sensitive data: âI would be interested in how much metadata itâs storing, like time of use and usage patterns. And Iâd definitely be interested in whether itâs storing my phone number, my address, my political affiliation, and my income level.â 5.3.2 Envisioned Design Practices for GenAI S&P We categorize participantsâ desired design practices for S&P transparency into five dimensions: (1) modality, (2) granular- ity, (3) explainability and reflectiveness, (4) findability, and (5) timing. Under each dimension, we present representative design ideas from participants. Table 2 summarizes the design dimensions and sub-dimensions, along with their descriptions and representative design ideas. Combining interactive and static disclosure modalities to lower understanding barriers. 8/20 participants envisioned interactive, on-demand formats that would let them ask ques- tions, clarify terms, and progressively drill down into details. Their sketches illustrated modalities such as an AI-enabled privacy FAQ and expandable cards that reveal additional S&P specifics and explanations on click. These interactive ele- ments appeared most often in participantsâ pre-adoption de- signs, where they described wanting quick, situation-driven answers without having to parse lengthy documentation while still retaining the option to explore deeper details. All 20/20 participants proposed at least one design element in a static modality, where S&P information is presented in a fixed, non-interactive format. Examples included visual cues such as labels that convey S&P assurances at a glance. Partici- pants who proposed these elements described them as useful for quick pre-adoption screening and comparison, especially 8 Design DimensionDescriptionRepresentative Example(s) Modality: InteractiveS&P information formats that support on-demand user interaction. AI-enabled privacy FAQs; interactive cards. Modality: Static S&P information formats that are presented in fixed, non-interactive forms. Standardized visual cues (labels). Granularity: HighHighly detailed information or control types.Fine-grained permissions over data uses, recipients, and data types, with configurable time bounds (e.g., âalways,â âthis session onlyâ). Granularity: LowLess detailed information or control types.Summaries of most needed data practices only. ExplainabilityHow clearly the interface communicates what an S&P option means and what it enables. A brief explanation of the toggled choice. Reflectiveness How the interface supports engagement and reflection with S&P information. Pre-commit confirmation and editing. Findability: HighS&P information and controls are highlighted and eas- ily located with clear textual, visual, or multimodal cues. Clear navigation cues (e.g., links or walkthrough animation); standalone privacy icon/section. Timing: RepeatedS&P information is repeatedly presented.Per-launch warning screens. Timing: One timeS&P information is presented only once.One-off disclaimers at sign-up. Timing: PersistentS&P information is persistently presented. Texts, toggles, badges, or banners that remain visible in the interface and surface critical S&P information, such as the privacy settings currently enabled (e.g., training on/off). Table 2: Design dimensions, descriptions, and representative design ideas for S&P transparency. when they want a baseline understanding of data practices without digging into details. Low granularity pre-adoption, high granularity post- adoption. In general, participants preferred low granularity pre-adoption (e.g., a brief summary of the salient S&P infor- mation, as specified in Section 5.3.1), but wanted high gran- ularity post-adoption (e.g., fine-grained consent options or controls). In particular, 7/20 participants indicated that exist- ing GenAI tools fell short in providing sufficient permissions, especially around purposes of data usage, data recipients, and the types of data stored, trained, or inferred. Importantly, 3/7 emphasized the need for configurable time bounds for these permissions. For example, users can enable global settings that apply to all sessions by default, while also enabling local, session-specific settings for particular permissions. Supporting S&P decision-making through explainability and reflectiveness. 8/20 participants suggested that toggling a consent option should trigger a brief explanation of what the choice enables, what data it affects, and any potential consequences. After reviewing the explanation, users should be able to confirm the settings or revise them before they take effect. Participants described these ideas as a way to mitigate long-standing issues of notice fatigue [15] and habit- uation [11, 17], where users click through S&P information without processing its content. By pairing pre-commit expla- nations with opportunities to confirm or edit, these designs create additional moments for users to engage with S&P in- formation and make more informed choices. Improving the findability of S&P information. 9/20 partic- ipantsâ sketches suggested a strong desire for higher visibility and easy access to information and controls over a toolâs S&P practices. Examples included clear navigation cues (e.g., links) that point users to where they can update consent set- tings during sign-up, as well as a standalone icon or dedicated section for privacy settings post-adoption. Presenting S&P information at the right timing. Tim- ing refers to when S&P information is surfaced during use. Participants described three timing patterns â repeated, one- time, and persistent. Repeated disclosures include per-launch warning screens that caution users against sharing sensitive information. One-time disclosures include a one-off notice at sign-up and just-in-time notices triggered by a specific ac- tion. Persistent disclosures include texts, toggles, badges, or banners that remain visible in the interface and surface crit- ical S&P information, such as the privacy settings currently enabled (e.g., training on/off). For example, P13 specifically described a repeated, entry-point disclosure that appears at tool launch to provide a consistent reminder of data practices, analogous to cigarette warnings or car startup screens: âWhen you open the [GenAI] app, there could be a warn- ing that says, âHey, this is whatâs going to happen to your data,â right when you open it, every time. Thatâs like what we have with cigarettes. We have a label right on the pack [...] Now, in some cars, it gives you a warn- ing screen right on the interface when you start the car up. Then it goes away, you hit OK, and you can drive. There might be something like that with an AI interface.â 6 Discussion Our findings highlight an alarming status quo â S&P trans- parency in consumer-facing GenAI tools is often missing 9 Figure 2: We assemble participantsâ representative design ideas across the five dimensions into a single prototype spanning pre-adoption (left) and post-adoption (right) phases. In the pre-adoption phase, the prototype presents an independent audit badge in a static format (A), concise explanations (B) paired with granular permission controls (C), and an AI-enabled FAQ about data practices (D). After users make initial choices, the interface summarizes each option with brief explanations and allows users to edit or confirm their settings (E). In the post-adoption phase, users can quickly enable a privacy-preserving mode that remains visible in the interface (F) and view a persistent privacy reminder (H). Users can update privacy preferences via two clear visual entry points (G), and specify whether changes apply globally across sessions (I) or only to the current session (J). To illustrate traceability, we present examples in Figure 3 showing how participantsâ original sketches correspond to features in the prototype. or unusable in practice, even as high-stakes use becomes more common (RQ1&RQ2). In response to this challenge, participants described concrete expectations for what S&P information should cover and how it should be commu- nicated to support informed adoption and use (RQ3). We organize participantsâ design ideas into five dimensions (see Table 2) and instantiate them in a single interactive prototype that visualizes representative designs across dimensions (see Figure 2). The interactive prototype can be accessed in Ap- pendix A, which is intended to surface an emerging design space of GenAI S&P transparency by illustrating participant- informed design ideas. It is not meant to be comprehensive and does not necessarily reflect best practices. As an ex- ploratory study in this space, our goal is to offer a starting point for designing and evaluating GenAI S&P transparency and to spur more investigation into best practices. Unique design challenges and opportunities for advanc- ing GenAI S&P transparency. Several unique S&P trans- parency challenges emerged in the context of GenAI. First, our findings suggest structural design limitations that produce a mitigation-risk misalignment: privacy risks in GenAI tools are constantly shifting, yet participants struggled to align their mitigation strategies accordingly, for two main reasons: (1) Participants often mixed the use of a single GenAI tool for both high-stakes and low-stakes purposes concurrently (Sec- tion 5.1.2). However, existing controls in GenAI tools are mostly coarse, global settings (e.g., a training opt-out/opt-in setting [3] that applies to all sessions), making it difficult to manage risk in the most appropriate way as usage contexts shift. (2) Participants perceived data practices as changing frequently without effective communication, leaving them unaware of what has changed and unclear about the current policy (Section 5.2.1). This uncertainty made it harder for participants to make informed S&P decisions, such as what in- formation to share or withhold. This challenge is particularly salient in GenAI because a single general-purpose tool is rou- tinely used across contexts with very different risk levels (e.g., mental health support vs. information seeking [25]), whereas prior digital technologies often let users segment disclosure by setting or audience (e.g., social media platforms allow users to restrict a postâs visibility to specific friend groups [53]). Par- ticipants, therefore, called for more contextual, fine-grained controls. However, prior work suggests that offering more controls can introduce trade-offs, notably oversharing â either by creating a false sense of safety or by increasing the burden of managing settings over time [16, 43, 72]. Thus, future re- search should carefully examine how different levels of S&P transparency granularity influence usersâ S&P perceptions and behaviors in real-world settings. Second, existing GenAI S&P communication faces a sig- nificant âcredibility gap.â While independent evaluations have been used to strengthen the credibility of self-attested S&P practices in prior technologies (e.g., the FCC-led Cyber Trust Mark Program for IoT technologies [23]), GenAI still largely 10 ModalityGranularityExpl. & Refl. Find- abilityTimingContent ExampleAudienceInteractiveStaticHigh GranularityLow GranularityExplainabilityReflectivenessHigh FindabilityRepeatedOne-TimePersistentIndep. EvalsData TypesData Recipients Google Model Cards [5]Experts Privy (Template-based) [50]Expertsâ â Privy (LLM-based) [50]Expertsâ â AI Nutrition Facts Label [1]Usersâ Manus Trust Center [58]Users Evaluation: = example fulfills criterion; = example partially fulfills criterion or fails;â = criterion not applicable. Table 3: Mapping a small subset of existing S&P transparency approaches in GenAI to participant-informed design dimensions and information needs. Note: The table format is adapted from [77]. lacks comparable, consumer-legible signals that reduce in- formation asymmetry [63] by clearly communicating what is being assessed, by whom, and what the results imply for usersâ data practices (Section 5.3.1). Moreover, policy efforts to advance S&P transparency in GenAI remain limited and have yet to establish industry-wide standards for S&P commu- nication backed by trusted public authorities. Prior work fur- ther suggests that credibility-oriented S&P disclosures (e.g., well-designed labels) can increase consumersâ willingness to adopt or purchase privacy- and security-protective tech- nologies [28, 30, 34, 80]. Building on this, future work should further motivate policy efforts by examining (1) what con- tent and forms of independent evaluation outputs (e.g., binary vs. graded, descriptive, or multi-layered labels [23, 26]) best align with GenAI usersâ needs, and (2) whether and how in- dependent certifications shape usersâ adoption decisions and interactions in the GenAI context. Despite these challenges, GenAI also introduces unique opportunities in the design space of S&P transparency. Par- ticipants expressed a need for on-demand S&P explanations delivered through interactive modalities (Section 5.3.2). Prior work on algorithmic transparency has similarly drawn on the UX principle of progressive disclosure [21, 64, 76], suggest- ing that providing explanations on an âas neededâ basis can help users better understand a system and reduce initial er- rors. Our findings echo this preference in the S&P context for GenAI (Section 5.3.2), particularly given participantsâ percep- tions of ever-updating data practices in GenAI (Section 5.2.1). However, assessing its effectiveness in shaping usersâ S&P understanding and behavior requires further empirical work. Evaluating existing GenAI S&P transparency through our design dimensions. We compare a small set of existing S&P transparency approaches in GenAI using our proposed design dimensions. Table 3 maps a subset of existing S&P trans- parency approaches onto these dimensions 6 , and is intended 6 Two researchers independently audited the listed examples and resolved to motivate future work that more systematically investigates and validates best practices for S&P transparency in GenAI. Existing S&P transparency approaches in GenAI tools are largely not consumer-facing. Instead, they often target audi- ences with substantially higher technical expertise than typical end users. For instance, Google launched developer-facing model cards that help identify a GenAI modelâs strengths, limitations, and mitigations through text documentation [5]. Similarly, a recent study [50] proposed Privy, a practitioner- facing tool that guides AI product teams through privacy im- pact assessments (PIAs) in two versions â static, structured vs. interactive, LLM-based. Their findings suggest that LLM- based PIAs identified more relevant and clear S&P guidance compared to the static, structured version. Our findings also suggest participantsâ split preferences for interactive vs. static disclosure in different contexts. Our participants wanted in- teractive disclosure to provide them with on-demand S&P information, while effective static disclosure to support quick pre-adoption screening and comparison (Section 5.3.2). Limited S&P transparency approaches in GenAI have tar- geted general users, with the AI Nutrition Facts Label being one example [1]. Similar to IoT label designs [31], the AI nu- trition fact label presents a standardized summary of a GenAI modelâs data practices to help users quickly understand a modelâs data training, sharing, retention, and related practices. More recently, Manus [58] published consumer-facing in- formation about its S&P compliance, including independent audit reports, security controls, subprocessor disclosures, and static FAQs. Many of these emerging practices align with what our participants called for, further underscoring a grow- ing need for consumer-facing transparency in GenAI. In summary, our work introduces an initial design space for S&P transparency in GenAI with user-informed design prac- tices, aiming to help designers, developers, and researchers identify and evaluate design choices when developing S&P disagreements through discussion. We add content as an additional table dimension to capture what information participants preferred to be included. 11 transparency for end users. Evaluating this small set of exam- ples suggests several emerging patterns in the current GenAI S&P transparency landscape: across the examples, (1) most approaches are expert-facing, leaving a gap in consumer- legible disclosures that support adoption decisions and long- term use; (2) interactive modalities for S&P communication remain underexplored; (3) timing is dominated by persistent availability, with limited support for âjust-in-timeâ disclosure at decision points [30]; (4) most approaches primarily con- vey information, but do not reliably create moments for users to reflect, confirm, or revise settings before higher-risk ac- tions; (5) independent evaluations are mostly absent; and (6) while many examples offer high granularity, fewer provide a unified experience that supports both quick summaries (low granularity) and deeper drill-down (high granularity). 6.1 Recommendations Future S&P research should further validate, measure, and refine suggested design practices in real-world set- tings. Our work provides preliminary findings that surface exploratory design practices for promoting S&P transparency in GenAI (Section 5.3.2). These practices should be further validated, measured, and refined through future empirical re- search. Specifically, future work should (1) evaluate the real- world impact of GenAI S&P transparency designs on usersâ perceptions and behaviors â for example, how transparency granularity shapes usersâ understanding, decision-making, and disclosure practices as contexts and risk levels shift, and whether interactive, on-demand disclosure improves compre- hension and reduces errors in practice; and (2) extend this work by translating participantsâ credibility concerns into policy-relevant evidence, examining what information and presentation formats for independent evaluation best support usersâ needs, which organizations (e.g., Consumer Reports 7 , Underwriters Laboratories 8 ) users trust more, and whether third-party certification measurably affects usersâ adoption and interaction behaviors in the GenAI context. GenAI S&P transparency design should balance flexibil- ity and user burden through evidence-informed defaults. Participants called for more granular, flexible options that better match GenAIâs shifting use contexts and risk levels (Section 5.3.2). At the same time, flexible controls can in- troduce trade-offs â adding granularity can increase decision burden and may also create a false sense of safety that leads to greater disclosure over time [16, 43, 72]. To balance these concerns, we recommend that designers make the default experiences secure, while offering additional granularity on demand. Moreover, prior work suggests that when data prac- tices reasonably match usersâ expectations, they can demand less attention from users [72]. Achieving this goal would also 7 https://w.consumerreports.org/ 8 https://w.ul.com/ require inquiring into empirical research on usersâ mental models of GenAI data practices â especially common miscon- ceptions â to inform defaults, explanations, and when (and how) to surface additional controls or information. Policies should help consumers gain industry-wide stan- dardized insights. Participants suggested they would be more likely to trust independent evaluations that combine pub- lic oversight with accredited private auditors (Section 5.3.1), pointing to a role for policy in establishing industry-wide, consumer-legible S&P transparency standards. Yet, legally enforceable transparency requirements for consumer-facing GenAI remain scarce within and beyond the U.S. In the U.S., pressure for truthful S&P communica- tion largely arrives through emerging state laws that focus on risk documentation for specific classes of systems (e.g., Colorado SB24-205âs duties and risk-management expecta- tions for âhigh-riskâ AI systems) [4]. A key mismatch for our context is that these U.S.-based efforts tend to priori- tize organizational accountability (e.g., internal governance processes and documentation) [66, 67], while less often man- dating consumer-legible disclosures about everyday data prac- tices. Outside the U.S., transparency requirements also vary substantially in scope and intended audience â for example, the EU AI Act introduces legally binding transparency obliga- tions for certain AI systems and actors [35], while other efforts are largely non-binding, such as Singaporeâs Model AI Gover- nance Framework for Gen AI [9] and the OECDâs Hiroshima AI Process Reporting Framework [8]. Across these policy di- rections, âtransparencyâ frequently emphasizes safety report- ing and technical documentation rather than consumer-facing S&P assurances. Moving forward, policies could shift from primarily enforc- ing entity accountability to also mandating honest, consumer- facing S&P transparency â e.g., standardized, comparable dis- closures and independent certification signals â while guard- ing against âtransparency washing,â such as vague or un- verifiable claims, self-issued trust badges without auditable backing, or interface designs that nudge users into disclosure while obscuring critical terms [2, 36]. 7 Conclusion Our findings show that S&P information rarely drove adop- tion, but S&P uncertainty limited participantsâ willingness to use GenAI in high-stakes contexts. Participants sought S&P information from a small set of sources that they viewed as ineffective or lacking credibility. They most wanted clarity about data-access stakeholders, what data are stored, used for training, or inferred, and independent evaluations. Partic- ipantsâ envisioned transparency interfaces highlighted five design dimensions. Grounded in our findings, we propose recommendations toward promoting S&P transparency for consumer-facing GenAI. 12 References [1] Ai nutrition facts.https://nutrition-facts.ai/. Accessed: 2026-01-21. [2] Bringing dark patterns to light.https://w.ftc.gov/reports/ bringing-dark-patterns-light. Accessed: 2026-02-05. [3]Chatgpt data controls.https://help.openai.com/en/collectio ns/8471418-data-controls. Accessed: 2026-02-05. [4]Colorado sb24-205: Consumer protections for artificial intelligence. https://leg.colorado.gov/bills/sb24-205. Accessed: 2026- 02-05. [5]Google model cards.https://modelcards.withgoogle.com/. Accessed: 2026-01-21. [6]Ibm ai factsheets.https://w.ibm.com/docs/en/software-h ub/5.1.x?topic=services-ai-factsheets. Accessed: 2026-02- 05. [7] Meta system cards.https://ai.meta.com/tools/system-car ds/. Accessed: 2026-02-05. [8]Oecd haip reporting framework.https://transparency.oecd.ai /. Accessed: 2026-02-05. [9]AI Verify Foundation. Model ai governance framework for generative ai. Technical report, AI Verify Foundation (Singapore), May 2024. [10]Mutahar Ali, Arjun Arunasalam, and Habiba Farrukh. Understanding usersâ security and privacy concerns and attitudes towards conversa- tional ai platforms. In 2025 IEEE Symposium on Security and Privacy (SP), pages 298â316. IEEE, 2025. [11] Bonnie Anderson, Anthony Vance, Brock Kirwan, David Eargle, and Seth Howard. Users arenât (necessarily) lazy: Using neurois to explain habituation to security warnings. 2014. [12]Rebecca Balebako, Richard Shay, and Lorrie Faith Cranor. Is your inseam a biometric? a case study on the role of usability studies in developing public policy. Proc. USEC, 14(10.14722), 2014. [13]Charlotte Bird, Eddie Ungless, and Atoosa Kasirzadeh. Typology of risks of generative text-to-image models. In Proceedings of the 2023 AAAI/ACM Conference on AI, Ethics, and Society, pages 396â410, 2023. [14]Nicole J-M Blackman and John J Koval. Interval estimation for cohenâs kappa as a measure of agreement. Statistics in medicine, 19(5):723â741, 2000. [15]Rainer BĂśhme and Jens Grossklags. The security cost of cheap user interaction. In Proceedings of the 2011 New Security Paradigms Work- shop, pages 67â82, 2011. [16] Laura Brandimarte, Alessandro Acquisti, and George Loewenstein. Misplaced confidences: Privacy and the control paradox. Social psy- chological and personality science, 4(3):340â347, 2013. [17] Cristian Bravo-Lillo, Saranga Komanduri, Lorrie Faith Cranor, Robert W Reeder, Manya Sleeper, Julie Downs, and Stuart Schechter. Your attention please: Designing security-decision uis to make genuine risks harder to ignore. In Proceedings of the Ninth Symposium on Usable Privacy and Security, pages 1â12, 2013. [18]L Jean Camp, Shakthidhar Gopavaram, Jayati Dev, and Ece Gumusel. Lessons for labeling from risk communication. In Workshop and Call for Papers on Cybersecurity Labeling Programs for Consumers: Inter- net of Things (IoT) Devices and Software, pages 1â3. NIST Washington DC, 2021. [19] Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramer, and Chiyuan Zhang. Quantifying memorization across neural language models. In The Eleventh International Conference on Learning Representations, 2022. [20] Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. Extracting training data from large language models. In 30th USENIX security symposium (USENIX Security 21), pages 2633â2650, 2021. [21]John M Carroll and Caroline Carrithers. Training wheels in a user interface. Communications of the ACM, 27(8):800â806, 1984. [22] Claude Castelluccia, Mathieu Cunche, Daniel Le MĂŠtayer, and Vic- tor Morel. Enhancing transparency and consent in the iot. In 2018 IEEE European Symposium on Security and Privacy Workshops (Eu- roS&PW), pages 116â119. IEEE, 2018. [23]Peter Caven, Ambarish Gurjar, Zitao Zhang, Xinyao Ma, and LJean Camp. Usability, efficacy, and acceptability of the us cyber trust mark. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1â35, 2025. [24] Peter J Caven, Shakthidhar Reddy Gopavaram, and L Jean Camp. Inte- grating human intelligence to bypass information asymmetry in pro- curement decision-making. In MILCOM 2022-2022 IEEE Military Communications Conference (MILCOM), pages 687â692. IEEE, 2022. [25]Aaron Chatterji, Thomas Cunningham, David J Deming, Zoe Hitzig, Christopher Ong, Carl Yan Shan, and Kevin Wadman. How people use chatgpt. Technical report, National Bureau of Economic Research, 2025. [26] Yi-Shyuan Chiang, Pardis Emami-Naeini, and Camille Cobb. Iot labelsâ impact on security and privacy concerns. In 2025 European Symposium on Usable Security (EuroUSEC), pages 177â190. IEEE, 2025. [27]Lorrie Faith Cranor. Necessary but not sufficient: Standardized mecha- nisms for privacy notice and choice. J. on Telecomm.& High Tech. L., 10:273, 2012. [28] Lorrie Faith Cranor, Yuvraj Agarwal, and Pardis Emami-Naeini. Inter- net of things security and privacy labels should empower consumers. Communications of the ACM, 67(3):29â31, 2024. [29]Lorrie Faith Cranor, Praveen Guduru, and Manjula Arjula. User in- terfaces for privacy agents. ACM Transactions on Computer-Human Interaction (TOCHI), 13(2):135â178, 2006. [30] Serge Egelman, Janice Tsai, Lorrie Faith Cranor, and Alessandro Ac- quisti. Timing is everything? the effects of timing and placement of online privacy indicators. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pages 319â328, 2009. [31]Pardis Emami-Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, and Hanan Hibshi. Ask the experts: What should be on an iot privacy and security label? In 2020 IEEE Symposium on Security and Privacy (SP), pages 447â464. IEEE, 2020. [32]Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. An informative security and privacy ânutritionâ label for internet of things devices. IEEE Security& Privacy, 20(2):31â 39, 2021. [33]Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. Which privacy and security attributes most impact consumersâ risk perception and willingness to purchase iot devices? In 2021 IEEE Symposium on Security and Privacy (SP), pages 519â536. IEEE, 2021. [34] Pardis Emami-Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, and Lorrie Faith Cranor. Are consumers willing to pay for security and pri- vacy ofIoTdevices? In 32nd USENIX Security Symposium (USENIX Security 23), pages 1505â1522, 2023. [35]European Union. Regulation (eu) 2024/1689 laying down harmonised rules on artificial intelligence (artificial intelligence act). EUR-Lex (Official Journal text), June 2024. [36]Federal Trade Commission. Ftc announces crackdown on deceptive ai claims and schemes. Press Release, September 2024. [37]Jill J Francis, Marie Johnston, Clare Robertson, Liz Glidewell, Vikki Entwistle, Martin P Eccles, and Jeremy M Grimshaw. What is an adequate sample size? operationalising data saturation for theory-based interview studies. Psychology and health, 25(10):1229â1245, 2010. 13 [38]Huiqing Fu, Yulong Yang, Nileema Shingte, Janne Lindqvist, and Marco Gruteser. A field study of run-time location access disclosures on android smartphones. Proc. USEC, 14(10), 2014. [39]Nathaniel S Good, Jens Grossklags, Deirdre K Mulligan, and Joseph A Konstan. Noticing notice: a large-scale experiment on the timing of software license agreements. In Proceedings of the SIGCHI conference on Human factors in computing systems, pages 607â616, 2007. [40] Pamela Grimm. Social desirability bias. Wiley international encyclo- pedia of marketing, 2010. [41]Carlos Jensen and Colin Potts. Privacy policies as decision-making tools: an evaluation of online privacy notices. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems, pages 471â478, 2004. [42]Shane D Johnson, John M Blythe, Matthew Manning, and Gabriel TW Wong. The impact of iot security labelling on consumer product choice and willingness to pay. PloS one, 15(1):e0227800, 2020. [43]Mark J Keith, Courtenay Maynes, Paul Benjamin Lowry, and Jeffry Babb. Privacy fatigue: The effect of privacy control complexity on consumer electronic information disclosure. In International Confer- ence on Information Systems (ICIS 2014), Auckland, New Zealand, December, pages 14â17, 2014. [44]Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder. A" nutrition label" for privacy. In Proceedings of the 5th Symposium on Usable Privacy and Security, pages 1â12, 2009. [45] Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, and Lorrie Faith Cranor. Standardizing privacy notices: an online study of the nutrition label approach. In Proceedings of the SIGCHI Conference on Human factors in Computing Systems, pages 1573â1582, 2010. [46]Patrick Gage Kelley, Lorrie Faith Cranor, and Norman Sadeh. Privacy as part of the app decision-making process. In Proceedings of the SIGCHI conference on human factors in computing systems, pages 3393â3402, 2013. [47] Nir Kshetri. Cybercrime and privacy threats of large language models. IT Professional, 25(3):9â13, 2023. [48]Jabari Kwesi, Jiaxun Cao, Riya Manchanda, and Pardis Emami-Naeini. Exploring user security and privacy attitudes and concerns toward the use ofGeneral-PurposeLLMchatbots for mental health. In 34th USENIX Security Symposium (USENIX Security 25), pages 6007â6024, 2025. [49] Marc Langheinrich. A privacy awareness system for ubiquitous com- puting environments. In international conference on Ubiquitous Com- puting, pages 237â245. Springer, 2002. [50]Hao-Ping Lee, Yu-Ju Yang, Matthew Bilik, Isadora Krsek, Thomas Serban von Davier, Kyzyl Monteiro, Jason Lin, Shivani Agarwal, Jodi Forlizzi, and Sauvik Das. Privy: Envisioning and mitigating privacy risks for consumer-facing ai product concepts.https://arxiv.org/ abs/2509.23525, September 2025. Accessed: 2026-01-21. [51]Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, and Sauvik Das. Deepfakes, phrenology, surveillance, and more! a tax- onomy of ai privacy risks. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1â19, 2024. [52] Jingjie Li, Kaiwen Sun, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim, Florian Schaub, and Kassem Fawaz. âitâs up to the consumer to be smartâ: Understanding the security and privacy attitudes of smart home users on reddit. In 2023 IEEE Symposium on Security and Privacy (SP), pages 2850â2866. IEEE, 2023. [53]Yabing Liu, Krishna P Gummadi, Balachander Krishnamurthy, and Alan Mislove. Analyzing facebook privacy settings: user expectations vs. reality. In Proceedings of the 2011 ACM SIGCOMM conference on Internet measurement conference, pages 61â70, 2011. [54]Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, et al. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499, 2023. [55] Yijing Liu, Yan Jia, Qingyin Tan, Zheli Liu, and Luyi Xing. How are your zombie accounts? understanding usersâ practices and expectations on mobile app account deletion. In 31st USENIX Security Symposium (USENIX Security 22), pages 863â880, 2022. [56]Rongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist, and Jose Such. Privacy perceptions of custom gpts by users and creators. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1â18, 2025. [57]Lisa Mekioussa Malki et al. âhoovered up as a data pointâ: Exploring privacy behaviours, awareness, and concerns among uk users of llm- based conversational agents. In Proceedings on Privacy Enhancing Technologies. ACM, 2025. [58] Manus AI. Trust center, 2025. Accessed: 2025-02-02. [59]Nahema Marchal, Rachel Xu, Rasmi Elasmar, Iason Gabriel, Beth Gold- berg, and William Isaac. Generative ai misuse: A taxonomy of tactics and insights from real-world data. arXiv preprint arXiv:2406.13843, 2024. [60] Jim McCambridge, Marijn De Bruin, and John Witton. The effects of demand characteristics on research participant behaviours in non- laboratory settings: a systematic review. PloS one, 7(6):e39116, 2012. [61]Aleecia M McDonald and Lorrie Faith Cranor. The cost of reading privacy policies. Isjlp, 4:543, 2008. [62]Margaret Mitchell, Simone Wu, Andrew Zaldivar, Parker Barnes, Lucy Vasserman, Ben Hutchinson, Elena Spitzer, Inioluwa Deborah Raji, and Timnit Gebru. Model cards for model reporting. In Proceedings of the conference on fairness, accountability, and transparency, pages 220â229, 2019. [63]Philipp Morgner, Felix Freiling, and Zinaida Benenson. Opinion: Secu- rity lifetime labels-overcoming information asymmetry in security of iot consumer products. In Proceedings of the 11th ACM Conference on Security& Privacy in Wireless and Mobile Networks, pages 208â211, 2018. [64]Deepa Muralidhar, Rafik Belloum, Kathia Marçal de Oliveira, Ash- win Ashok, and Pardaz Banu Mohammad. The effect of progressive disclosure in the transparency of large language models. In Inter- national Conference on Computer-Human Interaction Research and Applications, pages 269â288. Springer, 2024. [65]Patrick Murmann and Farzaneh Karegar. From design requirements to effective privacy notifications: Empowering users of online services to make informed decisions. International Journal of Human-Computer Interaction, 37(19):1823â1848, 2021. [66]National Institute of Standards and Technology. Artificial intelligence risk management framework (ai rmf 1.0). Technical Report NIST AI 100-1, NIST, 2023. [67] National Institute of Standards and Technology. Artificial intelligence risk management framework: Generative artificial intelligence profile. Technical Report NIST AI 600-1, NIST, 2024. [68] Alexandra Nisenoff, Arthur Borem, Madison Pickering, Grant Nakan- ishi, Maya Thumpasery, and Blase Ur. Defining" broken": User ex- periences and remediation tactics whenAd-BlockingorTracking- Protectiontools break aWebsiteâsuser experience. In 32nd USENIX Security Symposium (USENIX Security 23), pages 3619â3636, 2023. [69]OpenAI. Data processing addendum.https://openai.com/polic ies/data-processing-addendum/, 2024. Accessed: 2025-05-09. [70] OpenAI. Plugin terms.https://openai.com/policies/plugin -terms/, 2024. Accessed: 2025-05-09. [71]Benjamin Saunders, Julius Sim, Tom Kingstone, Shula Baker, Jackie Waterfield, Bernadette Bartlam, Heather Burroughs, and Clare Jinks. Saturation in qualitative research: exploring its conceptualization and operationalization. Quality& quantity, 52(4):1893â1907, 2018. 14 [72]Florian Schaub, Rebecca Balebako, Adam L Durity, and Lorrie Faith Cranor. A design space for effective privacy notices. In Eleventh symposium on usable privacy and security (SOUPS 2015), pages 1â17, 2015. [73]Eike Schneiders, Tina Seabrooke, Joshua Krook, Richard Hyde, Natalie Leesakul, Jeremie Clos, and Joel E Fischer. Objection overruled! lay people can distinguish large language models from lawyers, but still favour advice from an llm. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1â14, 2025. [74] B Schwartz. The paradox of choice: Why more is less harpercollins publishers. New York, NY, 2004. [75] Amanda Silberling. Your public chatgpt queries are getting indexed by google and other search engines.https://techcrunch.com/2 025/07/31/your-public-chatgpt-queries-are-getting-i ndexed-by-google-and-other-search-engines/. Accessed: 2026-02-05. [76]Aaron Springer and Steve Whittaker. Progressive disclosure: When, why, and how do users want algorithmic transparency information? ACM Transactions on Interactive Intelligent Systems (TiiS), 10(4):1â32, 2020. [77] Sophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes, Yuhang Zhao, and Rahul Chatterjee. Sok: Authentication in augmented and virtual reality. In 2022 IEEE symposium on security and privacy (SP), pages 267â284. IEEE, 2022. [78]Ali Sunyaev, Tobias Dehling, Patrick L Taylor, and Kenneth D Mandl. Availability and quality of mobile health app privacy policies. Journal of the American Medical Informatics Association, 22(e1):e28âe33, 2015. [79] Guanhong Tao, Siyuan Cheng, Zhuo Zhang, Junmin Zhu, Guangyu Shen, and Xiangyu Zhang. Opening a pandoraâs box: things you should know in the era of custom gpts. arXiv preprint arXiv:2401.00905, 2023. [80]Janice Y Tsai, Serge Egelman, Lorrie Cranor, and Alessandro Acquisti. The effect of online privacy information on purchasing behavior: An experimental study. Information systems research, 22(2):254â268, 2011. [81]Evert Van den Broeck, Brahim Zarouali, and Karolien Poels. Chat- bot advertising effectiveness: When does the message get through? Computers in Human Behavior, 98:150â157, 2019. [82]Weiqi Wang, Zhiyi Tian, Chenhan Zhang, and Shui Yu. Machine unlearning: A comprehensive survey. arXiv preprint arXiv:2405.07406, 2024. [83]Xingyi Wang, Xiaozheng Wang, Sunyup Park, and Yaxing Yao. Mental models of generative ai chatbot ecosystems. In Proceedings of the 30th International Conference on Intelligent User Interfaces, pages 1016â1031, 2025. [84]Miranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno, Elissa M Red- miles, and Franziska Roesner.SoK(orSoLK?): On the quantitative study of sociodemographic factors and computer security behaviors. In 33rd USENIX Security Symposium (USENIX Security 24), pages 7011â7030, 2024. [85] Laura Weidinger, Jonathan Uesato, Maribeth Rauh, Conor Griffin, Po- Sen Huang, John Mellor, Amelia Glaese, Myra Cheng, Borja Balle, Atoosa Kasirzadeh, et al. Taxonomy of risks posed by language models. In Proceedings of the 2022 ACM conference on fairness, accountability, and transparency, pages 214â229, 2022. [86]Michael S Wogalter, Vincent C Conzola, and Tonya L Smith-Jackson. based guidelines for warning design and evaluation.Applied er- gonomics, 33(3):219â230, 2002. [87] Jie Xu, Zihan Wu, Cong Wang, and Xiaohua Jia. Machine unlearning: Solutions and challenges. IEEE Transactions on Emerging Topics in Computational Intelligence, 2024. [88] Chiyuan Zhang, Daphne Ippolito, Katherine Lee, Matthew Jagielski, Florian Tramèr, and Nicholas Carlini. Counterfactual memorization in neural language models. Advances in Neural Information Processing Systems, 36:39321â39362, 2023. [89]Haibo Zhang, Toru Nakamura, Takamasa Isohara, and Kouichi Sakurai. A review on machine unlearning. SN Computer Science, 4(4):337, 2023. [90] Shuning Zhang, Rongjun Ma, Ying Ma, Shixuan Li, Yiqun Xu, Xin Yi, and Hewu Li. Understanding usersâ privacy perceptions towards llmâs rag-based memory. In Proceedings of the 2025 Workshop on Human-Centered AI Privacy and Security, pages 10â19, 2025. [91]Zhiping Zhang, Michelle Jia, Hao-Ping Lee, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, and Tianshi Li. âitâs a fair gameâ, or is it? examining how users navigate disclosure risks and benefits when using llm-based conversational agents. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1â26, 2024. [92]Sebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar, Bin Liu, Florian Schaub, Shomir Wilson, Norman M Sadeh, Steven M Bellovin, and Joel R Reidenberg. Automated analysis of privacy requirements for mobile apps. In NDSS, volume 2, pages 1â4, 2017. 15 A Availability Study artifacts, including the interview consent form, screen- ing survey, participantsâ full information, instructions used in design sessions, interactive prototype, and final codebooks, are linked at: https://osf.io/2w46p/overview?view_only=1b dc27b27b8e44b198638035995b71a. B Interview & Design Session Script B.1 Introduction & Warm-Up Questions Hi [Participantâs Name], thank you for joining us today. My name is [REDACTED]. This is my colleague [Name], who will be taking some notes in the background. In this interview, I will be asking you about your usage, experiences, and preferences for GenAI tools. As mentioned in the consent form, we would like to audio-record this interview for analysis purposes. I will keep my video on through- out the interview process, but it is completely up to you if you would like to have your video on or off. May I confirm with you that you allow us to audio-record this interview? [Start the audio recording]. Great! Letâs get started with some warm-up questions first, to get to know your knowledge about GenAI tools. There are no right or wrong answers. Weâre just interested in your opinions and experi- ences. â˘How would you define artificial intelligence, or AI, in your own (a few) words? ⢠How would you define Generative AI or GenAI, in your own (a few) wordsâ? In this interview, when we refer to âGenAI tools,â we mean both standalone GenAI apps, such as ChatGPT, as well as GenAI fea- tures built into other platforms, apps, or smart devices. For example, that could include voice assistants like Alexa+, AI-generated sum- maries on social media platforms, smart replies in messaging apps, or personalized recommendations in streaming services. Before we get started, do you have any questions or need any clarification about what would be counted as a GenAI tool? B.2 Consumer-Facing GenAI Tool Usage (RQ1) 1. What GenAI tools have you used so far? 2. What are the reasons or purposes you have used these tools for? 3. Have you ever used any tool that you no longer use, and why? 4.[For participants using multiple GenAI tools]:Which of these GenAI tools do you use most often? (a)How long have you been using it, and how frequently do you use it? (b)What is the main purpose for which you use this GenAI tool? B.3 Pre-Adoption Considerations (RQ1) Now we would like to ask you some questions about your experi- ences and perceptions toward the GenAI tools before you adopted them. If your answers differ for some specific GenAI tools, please let me know. 5.What factors did you consider when deciding what GenAI tool to use? 6.What information did you seek out, if any, to inform your decision to adopt these GenAI tools? (a)[If none]:If you are interested in adopting a GenAI tool now, what information would you be interested in looking for? 7.Were there any other GenAI tools youâve considered but de- cided not to use? Why did you decide not to use them/it? B.4 Post-Adoption Considerations (RQ1) Now we would like to ask you some questions about your experi- ences and perceptions of the GenAI tools after you adopted them. Again, if your answers differ for some specific GenAI tools, please let us know. 8. On a scale of 0-10, 0 being not at all beneficial and 10 being very beneficial, how beneficial do you consider these GenAI tools to be, and what are the benefits if any? 9.On a scale of 0-10, 0 being not at all harmful and 10 being very harmful, how harmful do you consider these GenAI tools to be, and what are the harms if any? 10.[If S&P concerns are not among the mentioned ones]: How concerned or comfortable are you with the privacy and security practices of these GenAI tools? (a) What are your security and privacy concerns? (b)[If not at all concerned]:Are there reasons why you are not concerned? 11.[If S&P concerns are among the mentioned ones]:What are the security and privacy concerns you have? 12. What steps, if any, have you taken to manage your concerns? (a) [If no steps have been taken]:What are the potential steps you could take to manage the concerns? 13.What challenges do you think users face when managing these concerns? B.5 Practices, Challenges, andExpecta- tions Toward S&P Information Seeking (RQ2&RQ3) 14.In practice, have you ever thought about privacy or security before adopting these tools or when interacting with them? (a)[If yes:]What about S&P did you think about, and why were you interested in these topics? i.What steps, if any, did you take to inform yourself about the privacy or security of these tools? i. Were you able to find all the information you were looking for? How? 16 i.How confident were you about the trustworthiness of the information you found? iv.Did you make any changes or take any actions based on the information you found? v. Was there any other S&P information you wished to know? vi. How easy or challenging did you find the process? (b)[If not:] Could you please tell us why? i.What aspects of S&P might you be interested in and could affect your choice of GenAI tools? Why? B.6 Design Session (RQ3) Thank you for your valuable insights! Next, we are doing some brainstorming about interfaces that can better help us manage our privacy and security concerns when using GenAI tools. To do this, we are doing a mini sketch session by using the whiteboard feature, as mentioned before the interview. [Launch the Zoom Whiteboard]. [Onboarding training (3 minutes):] â˘Ask the participant to read the design instructions (see Ap- pendix A). â˘Introduce the tools (pen, highlighter, eraser/undo, shapes, text). [Task 1 (5-10 minutes):] ⢠Scenario â A consumer is considering signing up for a GenAI tool. ⢠Goals âPlease create an interface that previews security and privacy information for the consumer prior to signing up. â Elements you need to include: * The structure/organization of the interface. * The type(s) of security and privacy information that matter most to you. * Visual elements (optional) ¡ Examples: buttons, windows * Iteractive mechanisms (optional) ¡ Example: Pop-ups [Task 2 (5-10 minutes):] ⢠Scenario âA consumer has already created an account and is using the GenAI tool and they want to access some security and privacy information. ⢠Goals âPlease create an interface for the consumer to access security and privacy information while using the tool. If you would like the same design as you just did, please let us know. â Elements you need to include: * The structure/organization of the interface. * The type(s) of security and privacy information that matter most to you. * Visual elements (optional) ¡ Examples: buttons, windows * Iteractive mechanisms (optional) ¡ Example: Pop-ups [Follow-up questions (5 minutes):] â˘Thank you! Whenever youâre ready, could you walk me through your sketch? ⢠Structure: â Can you first give me a high-level overview of this de- sign? Whatâs the overall layout or structure you had in mind? ⢠Information â What types of S&P-related information are you including in this interface? âWhy did you choose to include these specific pieces of information? ⢠Visual elements & interactive mechanisms: âI see youâve labeled or highlighted a few things â could you walk me through any visual elements or interactive features youâve marked? â What is the purpose of these features? What would they do or how would a user interact with them? ⢠What problems are you trying to resolve through your design? What motivated you to create the design? ⢠What inspired your designs? Have you seen any other similar designs, interfaces, or mechanisms for security and privacy transparency of GenAI tools? â[If yes:]How did you feel about them? What were the benefits and drawbacks? B.7 Closing That brings us to the end of our session today! Thank you so much for your time and all the valuable insights youâve provided! We are really glad that you decided to take part in our study. We will compensate you through Prolific in 5 to 7 days. C Selected Original Sketches 17 Figure 3: Examples showing traceability from participantsâ original sketch concepts to corresponding prototype features, including: granular permissions (1, 4), explanations and pre-commit editing of permissions (2), AI-enabled FAQs (3), clear visual navigation to privacy settings (5), and local, session-specific settings (6). 18