REVIEW 3 major objections 4 minor 17 references
Acceptability of AI Assistants for Privacy: Perceptions of Experts and Users on Personalized Privacy Assistants
T0 review · 3 major / 4 minor · reviewed 2026-08-04 · deepseek-v4-flash
Pith's one-line read Acceptance of personalized privacy assistants hinges on three condition clusters, not just perceived usefulness.
desk verdict A transparent, exploratory focus-group study whose three-theme account of PPA acceptability (Design, External, Systemic) is plausible and useful, but the legally literate EU sample makes those themes hypotheses to validate, not settled findings. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is a qualitative focus-group study built around a hypothetical PPA called TamagotchIA, a described assistant that combines manual and automated learning from declarative and observational knowledge. Participants reacted to this concrete scenario in five focus groups (12 experts, 26 users); transcripts were analyzed with reflexive thematic analysis, using open and organic coding with no pre-set framework. The three themes emerged from this analysis, and then the paper maps them onto the UTAUT model to show where existing acceptance constructs fall short.
What would settle it
A large representative survey across EU and non-EU countries that measures the three themes alongside standard UTAUT variables (performance expectancy, effort expectancy, social influence) and tests whether systemic conditions (provider type, monopoly concerns, cost model) add incremental predictive power for behavioral intention to use a PPA. If systemic conditions show no incremental predictive validity beyond UTAUT, the paper's core claim would be undercut.
Extended reading notes
Core claim
The study identifies three principal themes—Design Elements, External Conditions, and Systemic Conditions—that together shape the acceptability of personalized privacy assistants. Users' and experts' willingness to accept a PPA depends on more than perceived usefulness or ease of use; it depends on who provides the assistant, how it handles transparency and control, what regulatory and oversight mechanisms surround it, and whether it entrenches monopoly power. The Systemic Conditions theme captures distrust of big tech providers, preferences for public or public–private provision, ambivalence about free versus paid models, and fear of data centralization. The paper proposes extending UTAUT w
Load-bearing premise
The findings rest on a small convenience sample—26 users recruited from one Dutch law faculty and a dozen experts from an author-organized workshop dominated by legal and social scientists—so the themes may not hold beyond this EU, legally informed, academically homogeneous group.
Editorial extensions
If this is right
- Designers should treat transparency (explanations of decisions, data logs, open-source code) and user control (kill switch, overridable decisions) as mandatory features, not optional extras.
- Policymakers need to clarify accountability, provide regulatory oversight (e.g., by data protection authorities), and establish interoperability standards before PPAs become broadly acceptable.
- Provider type matters: commercial PPAs from big tech are broadly distrusted, so acceptance depends on the existence of public or public–private alternatives.
- Technology-acceptance models such as UTAUT should add systemic conditions as a distinct construct and broaden facilitating conditions to include regulation, oversight, and enforcement.
- User and expert views diverge on payment: experts favor free public services, while many users accept paid models with a free tier, so business model choices affect acceptance.
Reading between the lines
- If systemic conditions are real determinants, then a PPA's acceptance will depend more on its market structure than on its interface quality; identical software could be accepted when offered by a public body and rejected when offered by a big tech company.
- The findings likely generalize beyond privacy to other delegated AI decisions, where provider identity and monopoly risk may shape acceptance as much as performance expectancy.
- A cross-cultural test could reveal whether these themes are EU-specific: in less regulated jurisdictions, concerns about oversight and enforcement may be weaker, suggesting the EU legal context inflates their importance.
- The paper's reflection on frictionless design implies a counterintuitive design extension: adding deliberate frictions, such as periodic preference reflection prompts, might increase long-term acceptance by preserving user agency.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper reports a qualitative focus-group study (five groups; 26 potential users and 11–12 domain experts) on the acceptability of personalized privacy assistants (PPAs). The authors identify three main themes—Design Elements, External Conditions, and Systemic Conditions—that they argue should be incorporated into technology acceptance models such as UTAUT, and they draw design, regulatory, and policy implications. The manuscript is transparent about its exploratory nature and discusses limitations such as EU-specific recruitment and the imbalance between expert and user groups.
Significance. If accepted at face value, the study is a useful early exploration of user and expert views on PPAs, a topic with scarce direct empirical evidence. The concrete contributions are the proposed three-theme taxonomy, the explicit linkage to UTAUT constructs, and the policy-oriented discussion (e.g., provider type, monopoly concerns, oversight). The paper is also honest in noting that the proposed UTAUT extension would require rigorous construct validation. Its main value is as a hypothesis-generating qualitative study rather than as a confirmatory test of an acceptance model.
major comments (3)
- [Discussion / 'Extending technology acceptance models...'] The central claim about extending UTAUT is presented in stronger terms than the evidence supports. The paper states that Systemic Conditions 'could create a distinct construct for UTAUT' and then concedes that this 'demands rigorous construct validation before it can be integrated.' Yet the abstract and conclusion present the findings as 'theoretical extensions' and assert that acceptability 'cannot be reduced to AI technology or privacy alone.' Without discriminant-validity or predictive-validity evidence, the stronger formulations overstate what a qualitative study can establish. Recommend consistently framing the UTAUT extension as a set of hypotheses for future quantitative work, and softening the abstract/conclusion accordingly.
- [Methodology (participant recruitment and analysis)] The sample is narrow: 26 users recruited from one Dutch law faculty via snowball sampling, and 12 experts from an author-organized workshop with a heavy legal/social-science concentration. The paper acknowledges EU-specificity, but it does not discuss how this legally literate, EU-focused participant pool may have privileged certain themes, particularly Systemic Conditions (public vs. market providers, monopoly avoidance). In addition, coding was performed by the first author alone, and the Results section contains no participant quotes or other raw-data excerpts to support the themes. This combination makes the three-theme structure a credible but weakly evidenced reconstruction. The manuscript should either provide a thicker audit trail (e.g., representative quotes, coding examples) or explicitly limit the generality claims, which would strengthen the contribution.
- [Methodology, FG4-5 question guide] The paper states that the FG4-5 guide was structured around UTAUT2 constructs but that these were 'not used as a theoretical framework for analysis.' This distinction between data collection and analysis is helpful, but the wording of the questions (usefulness, ease of use, social influence, facilitating conditions, price value) may have steered participants toward UTAUT-aligned responses. The later mapping of themes to UTAUT is therefore somewhat circular even if the coding was open. The authors should address this possibility directly, for instance by specifying what steps were taken to remain open to non-UTAUT topics and by acknowledging this as a limitation in the interpretation of the UTAUT extension.
minor comments (4)
- [Abstract / Table 1] The abstract reports expert n = 11, while Table 1 reports 12 participants (8 Law, 2 Social Science, 1 Philosophy, 1 Industry). Please reconcile this inconsistency.
- [Methodology / Limitations] The paper would benefit from more participant demographic detail (e.g., age, gender, non-academic backgrounds) to help the reader judge transferability. The current description is limited to data-protection-law knowledge.
- [Results] The Results section is presented as aggregated narrative with no direct quotes. Including at least one illustrative quotation per sub-theme would substantially strengthen the credibility of the thematic analysis and is standard practice for reflexive thematic analysis.
- [References] The 'Privacy Assistant Project' reference (accessed 2025) lacks a URL or detailed bibliographic information; please complete the entry.
Circularity Check
No significant circularity: qualitative thematic findings are not derived from the UTAUT framework, and proposed extensions are explicitly tentative.
full rationale
The paper's central claim is a qualitative thematic analysis of five focus groups, not a predictive derivation. The three themes (Design Elements, External Conditions, Systemic Conditions) were produced through reflexive thematic analysis with open coding; the authors explicitly state that the UTAUT2-structured question guide for FG4-5 'was not used as a theoretical framework for analysis.' The later mapping of themes to UTAUT in the Discussion is presented as a post-hoc interpretive proposal, not as an empirical prediction or fitted result. The paper explicitly defers validation ('Systemic Conditions as a new theoretical construct for UTAUT demands rigorous construct validation before it can be integrated'), so the extension is not claimed to be forced. The single self-citation (Tamò-Larrieux et al. 2021) supports a normative suggestion about a 'right to customization' and does not carry the empirical argument. Sample homogeneity and single-coder analysis are validity limitations, not circularity, and no equation, fitted parameter, or self-citation chain reduces the findings to the inputs.
Assumptions & free parameters
assumptions (3)
- domain assumption Participants' evaluations of a hypothetical PPA (TamagotchIA) reliably indicate their acceptability of real PPAs.
- domain assumption Reflexive thematic analysis by a single researcher can identify valid themes from focus group transcripts.
- domain assumption The convenience sample of Dutch law-faculty-affiliated users and legal/social-science experts represents the broader population of potential PPA users.
Cite this review
Pith. "Pith review of Acceptability of AI Assistants for Privacy: Perceptions of Experts and Users on Personalized Privacy Assistants." pith.science (2026). https://pith.science/paper/AZYHA7BJ
@misc{pith2026250908554,
author = {Pith},
title = {Pith review of: Acceptability of AI Assistants for Privacy: Perceptions of Experts and Users on Personalized Privacy Assistants},
year = {2026},
howpublished = {\url{https://pith.science/paper/AZYHA7BJ}},
note = {Machine review of arXiv:2509.08554}
}
read the original abstract
Individuals increasingly face an overwhelming number of tasks and decisions. To cope with the new reality, there is growing research interest in developing intelligent agents that can effectively assist people across various aspects of daily life in a tailored manner, with privacy emerging as a particular area of application. Artificial intelligence (AI) assistants for privacy, such as personalized privacy assistants (PPAs), have the potential to automatically execute privacy decisions based on users' pre-defined privacy preferences, sparing them the mental effort and time usually spent on each privacy decision. This helps ensure that, even when users feel overwhelmed or resigned about privacy, the decisions made by PPAs still align with their true preferences and best interests. While research has explored possible designs of such agents, user and expert perspectives on the acceptability of such AI-driven solutions remain largely unexplored. In this study, we conducted five focus groups with domain experts (n = 11) and potential users (n = 26) to uncover key themes shaping the acceptance of PPAs. Factors influencing the acceptability of AI assistants for privacy include design elements (such as information sources used by the agent), external conditions (such as regulation and literacy education), and systemic conditions (e.g., public or market providers and the need to avoid monopoly) to PPAs. These findings provide theoretical extensions to technology acceptance models measuring PPAs, insights on design, and policy implications for PPAs, as well as broader implications for the design of AI assistants.
Figures
Reference graph
Works this paper leans on
-
[1]
What is your initial impression of TamagotchIA? How do you perceive it might be useful?
-
[2]
Who is more acceptable for you to provide Tam- agotchIA? The EU? States? Big Techs like Google? NGOs? Or someone else? Why?
-
[3]
What are the must-have features TamagotchIA needs to have for you to accept it? Sub-question: What about the no-go features to avoid?
-
[4]
Imagine TamagotchIA can use various information sources to provide personalized privacy for you, such as your privacy preferences, previous privacy settings, on- line behavior, and demographics; which source of infor- mation do you feel most comfortable with and why? (a) Sub-question: Are there specific concerns or prefer- ences you have regarding how Tam...
-
[5]
How likely would you accept TamagotchIA once it be- comes available, and in which aspect? Why or why not? FG 4-5 Opening: Can you briefly explain your main privacy concerns on- line? For example, in social media, web browsing?
-
[6]
Do you think people should pay for TamagotchIA? If so, how much do you think TamagotchIA should cost? Why?
-
[7]
Do you think that using TamagotchIA could become a habit? Do you see any potential barriers to using it in your daily digital activity?
-
[8]
Who is more acceptable for you to provide Tam- agotchIA? The EU? States? Big Techs like Google? NGOs? Or someone else? Why? Closing: How likely would you accept TamagotchIA once it becomes available, and in which aspect? Why or why not?
Show all 17 references
-
[10]
To what degree do you ex- pect the TamagotchIA will benefit your privacy? Provide examples of possible benefits
What is your initial impression of TamagotchIA? Would it be useful? Please explain. To what degree do you ex- pect the TamagotchIA will benefit your privacy? Provide examples of possible benefits
-
[11]
Do you think TamagotchIA will be easy to use? If not, what efforts do you associate with its use?
-
[12]
Do you believe your family or friends should use Tam- agotchIA once it is available? Why?
-
[13]
What resources and support would you expect to be avail- able in order to use TamagotchIA?
-
[14]
Would you enjoy using TamagotchIA? Why or why not?
-
[811]
Wagner, I
Springer. Wagner, I. 2023. Privacy policies across the ages: content of privacy policies 1996–2021. ACM Transactions on Privacy and Security, 26(3): 1–32. Xiong, Y .; Shi, Y .; Pu, Q.; and Liu, N. 2024. More trust or more risk? User acceptance of artificial intelligence virtua...
2023
-
[2003]
MIS quarterly, 425–478
User acceptance of information technology: Toward a unified view. MIS quarterly, 425–478. V ogelsang, K.; Steinh¨user, M.; and Hoppe, U. 2013. A qual- itative approach to examine technology acceptance. Vu, K.-P. L.; Chambers, V .; Garcia, F. P.; Creekmur, B.; Su- laitis, J.; N...
2013
-
[2023]
Why should I read the privacy policy, I just need the ser- vice
AI trainer: Autoencoder based approach for squat analysis and correction. IEEE Access, 11: 107135–107149. Chedrawi, C.; Kazoun, N.; and Kokkinaki, A. 2024. The role of AI agents in fostering inclusivity for HEIs’ students with special needs against backdrops of the accreditati...
2024 arXiv
-
[2024]
Information Systems Frontiers, 1–22
Enablers and inhibitors of AI-powered voice assis- tants: a dual-factor approach by integrating the status quo bias and technology acceptance model. Information Systems Frontiers, 1–22. Bawden, D.; and Robinson, L. 2009. The dark side of infor- mation: overload, anxiety and ot...
2009
Reviewed August 4, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.