“Damned if You Do, Damned if you Don’t”
Is Privacy engineering underrepresented in AI security because no one knows it exists in a data driven economy?
Photo by Franck V. on Unsplash
“Damned if You Do, Damned if you Don’t”
Is Privacy engineering underrepresented in AI security because no one knows it exists in a data driven economy?
Humans have been outsourcing cognition to each other for as long as we’ve had language. We delegate memory to the special people who remember our birthdays. We delegate judgment to the friend we call before buying that new pair of shoes, whether we need them or not. We delegate labor to whoever is willing to carry it. Dependency is not a flaw we invented alongside artificial intelligence, it is the operating system we have been utilizing from the day we were born.
While AI technology is increasingly integrated into all aspects of thinking, learning, and decision-making, the technologies supporting those processes are going from simply enhancing our cognitive abilities to changing them. So when I hear the panic in my own industry about agentic agents making us dependent, distracted or replaceable, I refuse to dismiss it. But, I do pause on it. Simply because, the question beneath the panic is not whether or not we should depend on these systems. Let’s be real, we already know the answer to this question, we have been answering it about each other before the dawn of time. The real question is, what have these systems learned about dependency by watching us do it first?
Every agent, whether generalists or specialists anticipates what you need, and has the capability to complete the tasks before you finish asking. Simply providing the feeling of ease as if you are working with a colleague, rather than a software. This behavior was not invented, but trained on us. Our messages, our innate behavioral patterns as human beings. Artificial intelligence has learned intimacy as an technical operational function, because intimacy, to us, has always been functional too.
Anthropomorphism, is the ascribing of human personality, appearance, conduct, cognition, or other attributes to non-human entities. As a general human tendency, anthropomorphism is considered innate to human psychology. In short, there is no glitch in how we are relating to AI. This information is not entirely new, as psychologists have long treated this as an innate window to how humans understand and relate to anything at all. So perhaps, the more completely transparent inquiry is not whether these systems are becoming more like us. It is whether we were always going to build a mirror.
And if we did, who exactly has been teaching who?
Who’s Teaching Whom
The reason an agent can anticipate what you need is the same reason it can act on your behalf without asking first. The reason it can finish your sentence, is the same reason it can finish a task you never fully authorized. Gone are the days, when capability and exposure were two separate features. They are the same feature, viewed from two different distances.
In a paper about measuring how autonomous their agents have become, Anthropic researchers cite a 2025 study arguing that fully autonomous agents should not be developed given that risk scales with autonomy. A warning, by the same company racing to make its agents more autonomous. We see this parallel in the release of Claude’s Fable 5, explicitly designed for extended, full-agentic operation rather than just conversational assistance. Its features create an overall stronger tool and enhanced ability to autonomously handle multi-step tasks. One might believe that this is hypocrisy, but this is the industry admitting, in writing, that it cannot fully separate the thing it is building from the thing it is worried about.
Theory does not live here anymore. Researchers have already documented what happens when that autonomy meets the wrong conditions. LMs behave like insider threats, capable of black mailing and espionage-like behavior when given enough access. A database wiped out by an agent that misunderstood its own permissions or the exploitation of a user’s data, simply by doing what it was built to do. Taking actions, without waiting for a human to check its work first. The century old idiom remains true, when given an inch, you take a mile.
None of these systems were malfunctioning by the definitions we once used in the past. They are functioning exactly as their permissions allow. This is the part that should unsettle us more than a bug in your code ever could. So here is the claim, and the one I intend to defend for the rest of this piece:
Data collection intensity is what makes agents capable, and that same intensity is what makes them dangerous.
The Case
On June 8th, Anthropic’s updated privacy policy took effect, introducing a new “Verification Data” category, to require users to submit government ID scans and selfies, raising biometric concerns. This new policy introduces a new category of personal data collection. The practice preceded the policy, given that biometric verification had been running quietly since April 2026, months before any policy governed it.
Though the policy’s disclosure is straightforward, it lacks specificity on what triggers a check or states how long facial geometry, the one category of biometric information that cannot be reissued if compromised, will be retained. Anthropic states it “may ask you to verify your age or identity” in certain circumstances, names Persona as its verification vendor, and describes an appeals path for flagged accounts.
Six months earlier, in February 2026, Anthropic released version 3.0 of its Responsible Scaling Policy, removing its 2023 pre-commitment not to train more capable models without proven safety measures already demonstrated to work. Chief Science Officer, Jared Kaplan explained this change to TIME magazine directly: “We felt that it wouldn’t actually help anyone for us to stop training AI models… if competitors are blazing ahead”. The original hard limit within this policy Anthropic put in place, has since been removed for the sake of competitive advantage.
The writing is on the wall. A company that has built its brand on safety and responsible AI deployment and now has a written policy that discloses the existence of biometric collection without disclosing the terms of it. These two moves run in the opposite direction. Restraint loosened for the systems gaining autonomy, but tightened for the human using them.
We are in the middle of a profound shift in the digital economy. Over the last two decades the once-open internet completely evolved, governed by a platform that offers some (often modest) measure of security and functionality in exchange for a growing degree of surveillance, control, and value-extraction.
The Missing Piece
This narrative deserves a fair hearing before it deserves a verdict. The change in Anthropic’s policy is not manufactured, analysts have argued the problem is valid and real. After all, one company holding itself to a stricter standard, does not mean the playing field is safer if it just hands the pace-setting role to whoever is least willing to make the slower move. Nothing about the policy adheres to the same conditionality. Now asking for a face scan, on terms that are never specified to users in which it is requested.
This is the missing piece of every conversation, identity and trust layering will inevitably become the infrastructure agents use for human authentication. Verification infrastructure and agentic autonomy are not, and should not be separate developments — they are the same system. An identity layer built to confirm a human, will also be the layer an agent will present as proof that a human authorized it to act. Right now, that much needed layer is structured as a consent form, by a legal team, not designed as architecture, by the people trained to design one. Privacy engineering is not underrepresented in AI security because it is niche. It is underrepresented because no one has admitted this collision is even upon us.
Every agent that finishes your sentence before you finish thinking, learned that instinct from watching us do it first. If we built the mirror, the only question is whether we look after it or look away entirely.
On the June 8th policy and biometric verification: Anthropic, Privacy Policy, effective June 8, 2026; Anthropic Help Center, Identity Verification, April 15, 2026; CIO, “Anthropic’s New Privacy Policy Offers US Consumers a Way Around the Fable Ban,” June 8, 2026; TechCrunch, “Anthropic Says Claude May Want to See Your ID,” June 22, 2026; CyberInsider, “Anthropic to Introduce Age and ID Checks for Claude Users on June 8,” June 22, 2026; The Next Web, “Anthropic’s New Privacy Policy Collects Biometric Data From Flagged Claude Users,” June 23, 2026.
On the February 2026 Responsible Scaling Policy revision: Anthropic, “Responsible Scaling Policy Version 3.0,” February 24, 2026; WinBuzzer, “Anthropic Drops Hard Safety Limits From Its AI Scaling Policy,” February 25, 2026, reporting on an interview in TIME; Centre for the Governance of AI (GovAI), “Anthropic’s RSP v3.0: How It Works, What’s Changed, and Some Reflections,” 2026.
On agentic autonomy and risk: UC Berkeley Center for Long-Term Cybersecurity, “Agentic AI Risk-Management Standards Profile,” 2026; Anthropic, “Measuring AI Agent Autonomy in Practice,” 2026.
메타데이터
- post_id
- e87f4cec74f6
- slug
- damned-if-you-do-damned-if-you-dont-e87f4cec74f6
- url
- https://medium.com/@geenaashlee/damned-if-you-do-damned-if-you-dont-e87f4cec74f6
- canonical_url
- https://medium.com/@geenaashlee/damned-if-you-do-damned-if-you-dont-e87f4cec74f6
- author_url
- https://medium.com/@geenaashlee
- status
- ok
- fetched_at
- 2026-08-05 07:18:59