top of page

Opening our eyes to the Panopticon

01 Nov 2025 - 11 Apr 2026

Project team

Dr Katharina Burger

Principal Investigator

Associate Professor in Major Infrastructure Delivery, University College London


Prof Tom Buchanan

Co-Investigator

Professor of Psychology, University of Westminster


Dr Frédéric Tomas

Co-Investigator

Assistant Professor at the Department of Communication and Cognition, Tilburg University


Dr Jeyamohan Neera

Co-Investigator

Assistant Professor in Networks and Cybersecurity, Northumbria University


Soumer Singh Karki

Research Assistant

MsC in Human-Computer Interaction, University College London

Summary

Every day, young adults interact with smart devices, such as phones, watches, voice assistants, and apps, without fully realising how much data they are giving away or what risks this creates for behavioural influence and surveillance. As AI-powered assistants such as Microsoft Copilot and Google Gemini become embedded in everyday life, personal information flows faster and more widely than ever before.

This project focused on the gap between how deeply young adults are monitored by ambient, AI-driven technologies and their awareness of this monitoring. Most existing research focuses on visible surveillance (CCTV, cookies, named platforms) and has not kept pace with the seamless, often invisible nature of AI-driven data collection.

The project explored whether making downstream data consequences visible, e.g. through interactive narratives and staged-disclosure scenarios, could measurably shift surveillance awareness, reduce uncritical use, and surface the kinds of governance arrangements that publics consider legitimate.


Objectives

The original objectives, as set out in the funded proposal, were:

  • Identify and prioritise one high-impact, under-researched consumer technology with surveillance potential (e.g. generative AI copilots, wearables, connected mobility) that young adults (18–21) use in everyday life but may be less aware of in terms of data flows and overreach.

  • Run a controlled behavioural experiment via Prolific to test whether the narrative measurably increases surveillance awareness and reduces complacency.

  • Develop a concise, interactive digital narrative (~10 minutes) embedding a realistic AI surveillance use-case into decision-making dilemmas faced by young adults, delivered entirely online.

  • Synthesise results into a policy brief and public-facing dissemination materials highlighting effective ‘wake-up’ levers for industry, regulators, and educators.

  • Lay the methodological and partnership foundations for a larger SALIENT bid extending the work to other populations and contexts.


Activities

In delivery, the project broadened from a single use case to a three-strand investigation spanning complementary technologies (voice assistants, smart-city systems, and large language models). This adaptation reflected what was feasible within the timeline, which stakeholders were available to engage, and an emerging analytic insight that surveillance awareness is shaped by the form in which data systems are made intelligible - not just by the use case itself. While the work expanded to three strands, all remain anchored to the original objective of understanding how AI-driven data-sharing harms become intelligible to young adults.

The project was delivered through three parallel strands rather than the originally proposed sequential WP1→WP2→WP3 structure. This change enabled the team to generate richer evidence on the central question of how surveillance awareness can be shifted.

Strand 1 - Online behavioural experiment (Prolific, N = 441)

Led by Prof Tom Buchanan. A controlled, single-session online experiment was implemented in Qualtrics with embedded branching logic to simulate a smart-city day out involving an AI-powered voice assistant. Participants were randomly assigned to an experimental condition (in which downstream privacy consequences of voice-assistant use were progressively revealed) or a control condition. Repeated measures of perceived privacy risk, trust, behavioural intention, and intention to reuse were captured at multiple decision points. The Qualtrics survey template and branching logic, together, constitute the interactive narrative prototype originally proposed under WP2. The experiment was completed and analysed within the project timeline.

Strand 2 - Online focus groups (N = 15 across 6 sessions)

Led by Dr Burger. The originally proposed online expert co-design workshop did not proceed: despite outreach, sufficient expert participants could not be recruited within the project window. In response, the team pivoted to a different but complementary activity: six online focus groups with members of the UK general public (recruited via Prolific and snowball sampling) that used a staged-disclosure scenario method. Two smart-city scenarios were tested: a heatwave health-risk monitoring system and an AI-optimised public bus network. The heatwave scenario generated rich, sustained reasoning; the transport scenario surfaced relevant findings but engaged participants less consistently. The two waves of focus groups also enabled a methodological comparison between narrative and explicit-mechanism scenario formats.

Strand 3 - In-person young-adult workshops (N = 20)

Led by Dr Jeyamohan Neera at Northumbria University. The in-person co-design activity with young adults proceeded as planned, but with a refined methodological focus. The workshops included semi-structured think-aloud exercises, in which participants completed a series of prompt-engineering tasks of increasing sensitivity using an AI assistant and worked through scenario validation and critical-moments mapping. This produced a coded thematic dataset on consent behaviour, privacy knowledge and personal application, trust in AI assistants, behaviour profiling, and governance - and offered a granular view of disclosure behaviour among 18–21-year-olds that complements the experimental and focus-group strands.

Cross-strand synthesis and dissemination

Synthesis findings were presented as a poster at the Digital Environments Conference in Manchester (March 2026) and submitted for oral presentation at the BPS Cyberpsychology 2026 conference (decision pending). The focus-group strand is being written up as a manuscript for journal submission, and the in-person workshop strand is being prepared for separate publication. The online behavioural experiment is also being written up as a stand-alone journal publication.

A policy brief, public-facing multimedia summary, and stakeholder guidance have also been produced and are available on request.


Outputs

Completed outputs:

  • Conference poster: ‘Seeing the system: How making data systems visible changes public understanding’ -Burger, Buchanan, Neera, Tomas, and Karki. Presented at the SPRITE+ Manchester conference, March 2026.

  • Submitted conference abstract (decision pending): ‘Hey Google, sell my data! Learning about the privacy implications of AI voice assistants influences our attitudes and intentions to use them’ -Buchanan, Karki, Burger, Neera, and Tomas. BPS Cyberpsychology 2026.


Available outputs:


Ongoing work on deliverables:

  • Behavioural experiment dataset: cleaned dataset from the Prolific study (N = 441), to be deposited on the Open Science Framework (OSF).

  • Qualtrics survey template with branching logic (used in the Prolific experiment). Status: available on request

  • Draft journal manuscripts

  • Focus-group dataset and short report: anonymised transcript excerpts and a synthesis report on collective harms and the role of scenario design in public reasoning.

  • In-person workshop dataset: twenty think-aloud interviews with 18–21-year-olds, including a coded thematic framework (consent, privacy knowledge, trust, behaviour profiling, governance).

  • Prolific experiment. Possible destination: Computers in Human Behaviour - Reports


Impact

Key findings:

The three strands converge on a single message that we describe as intelligibility as a prerequisite for legitimacy: the consequences of data-sharing in algorithmic systems must be made intelligible to enable critique and accountability.

Strand 1 (experimental) found that making the downstream privacy consequences of AI voice assistants visible through an interactive narrative significantly shifted participants' attitudes. In the experimental condition, perceived privacy risk increased (3.48 → 3.92), trust in the technology decreased (3.12 → 2.99), and intention to use decreased (3.34 → 3.07). Participants exposed to the privacy-consequences condition were significantly less likely to say they would want to use the tool again.

Strand 2 (qualitative) showed that the participants rarely reached for the language of ‘privacy.’ They reason instead in terms of fairness, responsibility, distributive justice, and stigma. The focus-group strand identified that function creep is experienced as a gradient (‘a wide area you drift into’) rather than a discrete line crossed; that individual consent is widely seen as inadequate to systems that act on aggregates; that publics distinguish sharply between aggregate ‘monitoring’ and individual ‘surveillance,’ with mobility tracking marked as the threshold of unacceptability; and that harm is structurally relocated from the model to the institutional decisions made on its outputs.

Strand 3 in the in-person young-adult strand found that participants possess substantial knowledge of data aggregation and behavioural profiling but rarely apply it to their own behaviour, with a striking gap between what they know in theory and what they do in practice. We also noticed that most participants' mental models regarding AI privacy risks are largely drawn from prior experience with social media.

Social impact:

The project provides direct benefit to young adults (18–21) at a pivotal moment in their legal and civic autonomy by exposing them to the hidden risks of AI-driven surveillance through engaging, realistic formats. The experimental evidence shows that exposure to consequences is sufficient to reduce uncritical reuse - a low-cost, scalable intervention with potential application in education and digital-literacy contexts.

Policy and regulatory impact:

Findings are directly relevant to regulators (e.g. the ICO), policymakers, and AI industry actors. The most consequential implication is that frameworks built around individual consent may be insufficient for systems that act on groups, neighbourhoods, and populations. The qualitative research strands highlight the need for governance arrangements that treat system design objective functions as political artefacts subject to deliberative scrutiny, and match the unit of consent to the unit of action. These propositions align with UKRI’s ‘Building a Secure and Resilient World’ theme and with current debates on AI governance.

Educational and organisational impact:

Educators and civil society organisations gain actionable insights into narrative elements that shape surveillance literacy. The emerging finding from the qualitative focus groups is that participants reason in terms of fairness, responsibility, and social impact (rather than ‘privacy’). This may be significant for how communications and curricula are framed: messaging anchored in distributive consequences may complement more traditional messaging anchored in personal data rights.

Methodological impact:

The project develops and tests three complementary methods that can be reused across the SPRITE+ community: (i) interactive Qualtrics-with-branching-logic narratives for behavioural experimentation; (ii) staged-disclosure focus group scenarios that capture the temporal phenomenology of data systems; and (iii) think-aloud prompt-engineering tasks that surface the gap between stated and enacted privacy behaviour. The Prolific dataset (to be released via OSF) supports replication and extension.


Future work

The team’s primary ambition is to leverage these findings as the empirical foundation for a larger SALIENT bid extending the work to other populations, demographics, and surveillance contexts.

Immediate post-project activities:

  • Wider release of the policy brief, stakeholder guidance and public-facing multimedia summary. With the funded period closed, dissemination will proceed through no-cost channels: newsletters and member networks; the submitted BPS Cyberpsychology 2026 presentation and forthcoming journal manuscripts; and UCL and partner-university research blogs, press contacts, and team networks. The PI will coordinate.

  • Deposit of the Prolific dataset on OSF.

  • Submission of the focus-group manuscript, the stand-alone experiment paper, and preparation of journal output from the in-person workshop strand.

Opportunities for involvement:

  • Researchers working on TIPS, digital literacy, cyberpsychology, HCI, and surveillance studies are invited to engage in the SALIENT bid.

  • Practitioners (educators, charities, regulators, technology designers) are encouraged to engage with the policy brief and multimedia summary, and to consider participating in future co-design and stakeholder activities.

The narrative prototype and Prolific dataset are available for reuse and extension by the SPRITE+ community.

bottom of page