ISCAP Proceedings: Abstract Presentation
AI Autonomy and Responsibility for Third-Party Privacy
Pranith Abbaraju
Appalachian State University
Gunjan Batra
Kennesaw State University
Abstract
Privacy decisions increasingly involve information that individuals do not personally own. When users delegate tasks to AI systems, the resulting information flows may affect individuals who are neither participants in the AI interaction nor decision makers in the disclosure process. This tension becomes particularly salient with agentic AI, which can autonomously access and process information across emails, documents, and other communication environments while pursuing objectives delegated by users. Although users authorize these systems to perform tasks, they may not explicitly authorize them to access or process information about others. Prior information systems research demonstrates that individuals can impose privacy externalities on others through disclosure of third-party information (Cao et al., 2018), yet limited attention has been given to how responsibility for such consequences is understood when information access is delegated to increasingly autonomous AI.
Drawing on Agency Theory (Jensen & Meckling, 1976), we examine AI autonomy as a condition that may alter how responsibility for third-party privacy is allocated. Agency Theory posits that delegation separates decision authority from execution while creating challenges related to control and accountability. In the context of agentic AI, this separation becomes important because an AI agent may independently retrieve and process information while pursuing an objective authorized by the user. As AI autonomy increases, the distance between the user's authorization decision and the agent's subsequent information-access behavior may therefore expand, potentially shifting perceptions of responsibility for resulting third-party privacy consequences.
We propose a survey study examining how perceived AI autonomy relates to perceived responsibility for third-party privacy, responsibility attribution, perceived privacy consequences, and willingness to delegate information-access tasks to AI. By extending Agency Theory to AI-mediated third-party privacy, this research introduces the principal–agent–third-party relationship as a distinct locus of analysis. The study contributes to information systems privacy research by examining responsibility not only for an individual's own information practices but also for privacy consequences experienced by others as a result of delegated AI actions. More broadly, the study advances understanding of how increasing AI autonomy may reshape responsibility boundaries within emerging AI-mediated information environments.
References
Cao, Z., Hui, K.-L., & Xu, H. (2018). An economic analysis of peer disclosure in online social communities. Information Systems Research, 29(3), 546–566. https://doi.org/10.1287/isre.2017.0744
Jensen, M. C., & Meckling, W. H. (1976). Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics, 3(4), 305–360. https://doi.org/10.1016/0304-405X(76)90026-X