When was the last time you seriously read a privacy policy from beginning to end?
In the age of AI, the data we hand over every day may reveal far more than we realize. A shopping record, a browsing trace, or a one-time location permission may appear ordinary in isolation. However, once analyzed and combined by algorithms, such data may be used to infer a person’s health status, purchasing power, interests and preferences, and even more sensitive personal characteristics.

I. AI Can Understand Your Data—and It Is Magnifying an Old Problem
The Chinese edition of The Wall Street Journal recently published an article by Daniel J. Solove titled “How to Maintain Our Privacy in the AI Age,” which addresses precisely this issue: when AI can analyze enormous quantities of personal data, are our existing approaches to privacy protection still adequate? [1]
The author, Daniel J. Solove, is a professor at the George Washington University Law School who has long studied privacy law, data security, and technology governance. He developed the influential “taxonomy of privacy,” which divides privacy violations into different categories, including information collection, information processing, information dissemination, and invasion. [2]
Solove warns that the broader environment of this century has not been friendly to privacy. The internet has risen, smartphones track geographic locations, large numbers of companies continuously collect personal data, and surveillance networks continue to expand. AI is now capable of analyzing vast digital records and can infer a great deal of information about individuals. [1]
The problem is that many privacy laws and platform rules still rely on an old approach: companies provide notice, and users give consent. In theory, this gives users a choice. In reality, however, ordinary people find it difficult to understand what they are actually consenting to. How will their data be shared? What risks may arise from a privacy notice? Could those risks become more serious in the future as AI’s analytical capabilities grow? Most people have neither the time nor the professional expertise needed to assess each of these questions individually.
Using everyday consumer data as an example, Solove reminds us that seemingly ordinary shopping records, once analyzed by AI, may be used to infer more sensitive information, such as health conditions, religious beliefs, and political leanings. Solove therefore reaches a key conclusion: most laws today attempt to shift responsibility for protecting privacy onto consumers. But digital technologies are too complex for ordinary people to manage. We need a different strategy—one that holds companies accountable. [1]
II. Privacy Protection Cannot End with “I Have Read and Agree”
For more than two decades, online privacy protection has largely relied on the model of “notice and consent.” Companies draft privacy policies, users click “Agree,” and the processing of their data is then formally authorized.
The problem with this approach is that it places an extremely complex technological and legal issue on the shoulders of ordinary consumers. Users cannot fully understand what data a company collects. They also have difficulty knowing which third parties may use that data, let alone predicting what an AI system may infer from it. Although this arrangement appears to offer users a choice, many people simply click “Agree” so that they can continue using the service.
“I have read and agree” has often become little more than a formality. It appears to respect users’ choices, but it can easily become a tool through which companies shift responsibility. Solove’s proposed direction is clear: privacy protection must move away from consumer self-management and toward corporate accountability.
He notes that food and pharmaceutical manufacturers also operated under inadequate regulation in the past. Formaldehyde was once added to spoiled milk to make it taste sweeter, and it was only after many infants died that stronger regulation was introduced. The automobile industry went through a similar period. Before laws imposed mandatory safety requirements, automobiles were extremely dangerous means of transportation. [1] Food and automobile safety later improved not because consumers became better at protecting themselves, but because the law required companies to assume responsibility for safety. Cars became subject to safety testing, farms became subject to inspection, and accountability mechanisms were introduced for defective products. Innovations such as seat belts and airbags also emerged in response to safety requirements. [1]
Solove argues that privacy protection requires a similar approach. Companies that collect and use data should not be able to avoid liability merely by issuing a privacy policy. When a company’s use of data or AI algorithms creates an unreasonable risk of harm, it should be held accountable. [1]
More specifically, there are at least several possible directions.
(1) Data Minimization
Companies should collect and use data only for the purposes for which it was originally collected and should not arbitrarily expand the scope of its use. Strict implementation of the principle of data minimization is an important means of effectively protecting privacy. The European Union’s General Data Protection Regulation (GDPR) also establishes data minimization as a fundamental principle. [3] China’s Personal Information Protection Law likewise provides that the collection of personal information must be limited to the minimum scope necessary to achieve the purpose of processing. [4]
(2) The Right to Deletion
Solove notes that the right to deletion has long been part of European Union data protection law. Although it was once regarded as impractical in the United States, it has now been incorporated into consumer privacy laws in various U.S. states and no longer generates substantial controversy. [1] This demonstrates that some privacy protections once considered excessively strict are becoming more widely accepted institutional arrangements as the digital environment evolves.
(3) Restricting “Dark Patterns”
“Dark patterns” are deceptive or manipulative technological designs that induce users to share data they would not otherwise have provided. [1] Such designs prevent users from making genuine choices and further undermine the meaning of “consent.”
(4) Holding Irresponsible Technology Design and Harmful Algorithms Accountable
Solove proposes imposing liability for negligent or reckless technology design, holding harmful algorithms accountable, and requiring protective mechanisms to be built into technologies to prevent them from being used to violate privacy. [1]
The logic underlying these proposals is simple: those who control the data, algorithms, and technological systems should bear the corresponding responsibility. Ordinary consumers need rights, but companies need boundaries even more.
III. Implications for China: Turning the Principle of Corporate Responsibility into Action
China has already entered an era in which everyday life is highly digitalized. As of December 2025, China had 1.125 billion internet users, with an internet penetration rate of 80.1%. The number of generative AI users had reached 602 million, representing a penetration rate of 42.8%. [5] Users certainly need to improve their awareness of privacy. However, if privacy protection depends primarily on individuals reading agreements line by line and assessing each risk separately, it will be difficult to establish genuinely effective protection. For China, the priority is to clearly define the boundaries of corporate data collection, the boundaries of algorithmic use, and the boundaries of corporate responsibility when something goes wrong.
China’s existing laws already incorporate this approach. Article 6 of the Personal Information Protection Law requires that the collection of personal information be limited to the minimum scope necessary to achieve the purpose of processing and prohibits excessive collection. Article 9 provides that personal information processors must be responsible for their personal information processing activities and must adopt the measures necessary to protect the security of personal information. [4] The Data Security Law also requires data processors to establish sound, full-process data security management systems, adopt appropriate technical and other necessary measures to safeguard data security, and promptly take remedial, response, and reporting measures when risks are identified or security incidents occur. [6]
The next crucial step is to ensure that these principles are genuinely reflected in corporate conduct.
Companies must not collect as much data as possible simply because it has commercial value. They must not arbitrarily expand the purposes for which data is used merely because users have clicked “Agree.” They must not avoid explanation and accountability simply because algorithms are complex. Nor should they confine privacy protection to policy documents without implementing it in product design, data management, and algorithmic governance.
Privacy risks in the age of AI will become more difficult to detect. In the past, people were primarily concerned about information leaks. Today, they must also guard against information being inferred, combined, used to create profiles, and applied in ways that affect individual opportunities and choices. Many forms of harm may not take the form of an obvious, one-time data breach. Instead, they may occur gradually through long-term data analysis and algorithmic decision-making.
This is also the most important warning conveyed by Solove’s article: ordinary people cannot always be expected to shoulder the burden of privacy protection by themselves.
Individuals can become more vigilant, but they cannot live every day as though they were legal and technical experts. Those that truly need to assume greater responsibility are the companies that control the data, algorithms, and access points to digital platforms.

The central point in discussions of privacy protection in the age of AI is clear:
Data cannot be collected without limits, algorithms cannot be used without constraints, and responsibility cannot be shifted onto users through a privacy policy. Only by placing genuine responsibility on the companies that control data and technology can privacy protection in the age of AI move beyond a purely formal “Agree” button.
References
[1] Daniel J. Solove, “How to Maintain Our Privacy in the AI Age,” The Wall Street Journal (June 23, 2026).
[2] Daniel J. Solove, “A Taxonomy of Privacy,” University of Pennsylvania Law Review, Vol. 154, No. 3, p. 477, 2006.
[3] European Union General Data Protection Regulation (GDPR).
[4] Personal Information Protection Law of the People’s Republic of China.
[5] Policy and International Cooperation Institute of the China Internet Network Information Center, The 57th Statistical Report on China’s Internet Development, February 2026.
[6] Data Security Law of the People’s Republic of China.
Note: Shanli Zhang, the author of this article, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and privacy protection. WeChat: 18811157736. Comments, exchanges, and corrections are welcome.