I helped plan the Zuckerberg hearing. We panicked over likes — now we give AI our passwords

AP26050035832286.jpg


In April 2018, I was counsel on the Senate Judiciary Committee and helped plan the hearing where Mark Zuckerberg testified before nearly half the Senate.

The immediate issue was Cambridge Analytica. About 300,000 people had used a personality quiz that ultimately gave the developer access to information on as many as 87 million Facebook users, most of whom had never taken the quiz themselves.

People were furious. The story dominated the news, Zuckerberg spent five hours answering questions from senators, and the whole thing even made it into a Saturday Night Live skit.

That hearing helped set off years of debate about what technology companies should be allowed to know about us and what they should be allowed to do with that information. States passed privacy laws. Congress spent years negotiating a federal privacy bill that never quite made it into law. The Federal Trade Commission eventually imposed a $5 billion penalty on Facebook.

On Oct. 9, Aaron Sorkin’s The Social Reckoning, a companion to The Social Network (2010), arrives in theaters. It picks up a few years after that hearing, with the events behind the Wall Street Journal’s “The Facebook Files” and whistleblower Frances Haugen. It is a reminder of how recent that era is and of how quickly the technology has moved since.

Over the past week, I’ve been using Meta’s latest product, Muse, a personal artificial intelligence agent released in the United States in September. To make it more useful, you can connect it to your email, calendar, financial information, health and fitness data, and other services. But the important difference is that Muse doesn’t just collect or organize information. It can do things with it. It can send an email, make a reservation, fill out a form, or buy something on your behalf.

I understand the appeal because I’ve used it. An agent that can find subscriptions you forgot about, coordinate dinner around several calendars, or deal with a canceled flight can give you back real time. Muse is only one example of where the industry is headed.

Still, it is worth noticing how far the baseline has moved. In 2018, Washington erupted over an app that obtained Facebook likes, profile information, and friend data. In 2026, consumers are voluntarily giving a single piece of software access to their own and their families’ inboxes, calendars, financial information, and health data.

The amount of information alone would have been hard to imagine in 2018, but the larger change is that the software can act on it. The Cambridge Analytica app collected data about people. An agent can use far more of that data to send messages, make purchases, and sign you up for things.

Privacy has traditionally been about information: Who has my data? What can they learn from it? Who can they share it with? Agents add another question: What can they do with it?

An agent with access to your inbox can understand a remarkable amount about your work, finances, relationships, and daily life. Give that same agent the ability to send messages, navigate websites, and spend money, and the room for costly mistakes grows considerably.

The industry understands this. Muse, for example, separates some permissions, asks for approval before sensitive actions, and provides users with an activity log. Those are good ideas. But protections vary from product to product, and most consumers have no practical way to know which ones they are getting.

I now lead the Agentic Futures Initiative, a coalition of companies building and deploying this technology. I believe in what agents can do. I also think we should be honest about how quickly our comfort level has shifted, and about the questions that shift raises.

Some of those questions are familiar. Congress never passed a federal privacy law after 2018, and the country has been left with a patchwork of state laws. That was already complicated for platforms. It is more complicated for agents. A single agent working for someone in Virginia might book a hotel in Texas, pay a vendor in California, and email a colleague in New York in the same afternoon. Which state’s rules apply, and does it make sense for the answer to change with every task?

Other questions are new. If an agent makes a purchase you didn’t want, did you authorize it? Who is responsible when an agent follows a malicious instruction hidden in an email? Can the information an agent gathers to complete a task be used for advertising or to train future models? And how would a consumer know?

None of these questions has a settled answer yet. They deserve attention now, while agents are still new.

OPINION — ZUCKERBERG CAN’T BUY HIS WAY OUT OF THIS ONE: A SANTA FE JURY HANDED META A $219 BILLION RECKONING

I remember the atmosphere around that hearing in 2018. Congress was trying to understand how something that seemed relatively harmless — an app, a quiz, some Facebook data — had produced consequences few people had anticipated.

Eight years later, we are about to hand software far more information and far more authority. There have already been a few early incidents, but the technology is still new, and we have time to work together to understand the risks and mitigate them.

Ryan Dattilo is the founding executive director of the Agentic Futures Initiative, a partner at Aquia Group, and a former chief counsel to the Senate and House judiciary committees.

Continue reading...

[ H/T Washington Examiner ]

Comments

There are no comments to display
Back
Top