Respecting your users' dread of the clankers

https://thoughtbot.com/blog/respecting-your-users-dread-of-the-clankers

People today have a spectrum of opinions on AI: we range from all-in, overly enthusiastic vibe-lifers to luddite curmudgeons. I personally have been from one side to the other and back over the course of this week.

Us AI skeptics have good reasons for our fear/hatred/disgust even as we use LLMs daily:

  • adverse effects on the environment and the economy
  • data misuse
  • training on works of unwilling authors
  • bias, hallucinations and lack of accountability
  • stealing our jobs
  • and more!

So please build your AI products to let me opt in.

Opting in progressively

The idea is to cater to everyone on the AI love/hate spectrum. You do that by giving me granular control over just how much AI is used, and just which personal data is shoveled into the firebox. I want to

  1. see how my data will be used by AI
  2. see what benefit I get
  3. grant permission

And I don’t want to do that by reading through your Terms of Use and Privacy Policy. It needs to be in context because I will decide on a case-by-case basis.

I want to grant zero permission up front. I want you to ask me for permission when you need it. No AI until I say so.

iOS popup requesting permission to send notifications, with allow/don't allow buttons

In mobile apps you already use this pattern to request extra permissions like location sharing and push notifications. You know that if you pop a notification as soon as the app opens, I’m going to say no. So you wait until you can demonstrate usefulness. We call this pattern a “soft ask” or “pre-prompt” or “pretty please”.

It’s the same way with AI: if your registration screen says “hey BTW we’re going to send all your data to LLMs and force you to chat with our AI agent!” I will have misgivings. But if you wait a bit and say “hey, we see that you’re stuck on this form - want to enable our agent to help?” - I will probably say yes, and I will probably say sure you can consume my data for it. You have shown that you respect my choice and you have demonstrated value.

Once I’ve given the OK to use AI, that doesn’t mean I’m OK with you shipping it every single byte of data you’ve compiled about me. Sure, it’ll make your AI more productive and accurate if it can access all my PII, credit card statements, and health information. I don’t care. Again - you need to prove value.

I haven’t granted wholesale permission with the click of one checkbox and submit button. You need to ask for permission progressively, and then let me retract my permission later.

How your agent can ask for permission progressively

It’s all about the context and prompting. Here are some techniques I’ve used or observed:

Conditionally build the list of agent tools or skills based on what the user has given access to.

In your LLM system prompt, give a list of the data items that the user has and has not consented to sharing.

Prompt your agent to ask for permission. Something like “This user (has/has not) given you access to their financial accounts. You may ask for permission to access the accounts - direct the user to their Settings screen to enable access.” or maybe “This user has granted read-only access to their document. If you need to edit it, please ask for write access, and explain exactly what you need it for.” Make sure the agent knows that “NO!” is a valid answer. It shouldn’t guess or hallucinate if it doesn’t have the real stuff.

The important parts are to let the LLM know

  • what does it currently have access to?
  • what could it get access to?
  • how can it use that data to benefit the user?
  • how can the user grant access?

Pre-approval

If you can’t do just-in-time consent, then you’ll need to get consent ahead of time. And remember - keep it granular and tell me how I benefit. If I’m linking health data to your app, you need more than just a single “yes please deliver my entire disease history to Anthropic” “Allow additional information sharing with our business partners" checkbox. Instead consider something like

  • [ ] allow our AI agent to book appointments on your behalf
  • [ ] share anonymized appointment notes with LLM partners so we can give you a summary
  • [ ] review X-rays and other radiology imaging with AI to flag abnormalities

Ask for permission to use data with AI at the place where you’re collecting that data. If I’m filling out a registration form - that’s where I should grant permission to share the data in that form. If I’m connecting my calendar, that’s where I should grant permission to let an AI manipulate my calendar.

Clawback

If I can give your LLM permission to slurp up my PII, I better be able to revoke that permission! So give me a user interface for that. Show me what the AI is consuming today and what it’s used for and what the effects will be if I uncheck the checkbox.

If I change my mind and want to remove AI access to my data, that means really removing it. Clear your prompt caching. Sanitize agent conversation histories. Delete your logs. Remove AI access to those tool calls.

Do not tempt me! I dare not take it, not even to keep it safe, unused. The wish to wield it would be too great for my strength. –Gandalf

movie still of Gandalf with caption "Don't tempt me, Frodo!"

With chat-style agentic AI, you have the new ability to ask for lots and lots of freeform sensitive data. It’s a free text input field and I might accidentally reveal more than I wanted: API keys, passwords, library card numbers. DON’T TAKE IT. You don’t want the responsibility of safeguarding my PII or secrets. You don’t need to risk Claude going on a spending spree.

How can your agent reject PII and secrets?

Here are some techniques I’ve used:

Prompt the agent to avoid asking for secrets. When I worked on an agent that could configure API calls, we added a system prompt instructing the LLM to never ask for API keys, tokens, or passwords. The LLM should instead teach the user how to provide this info in a secure manner. We also asked the system prompt never to repeat private, secret data given by the user. Just because it hit our logs once doesn’t mean it’s fair game for the agent to use as context.

Detect PII and secrets in the browser, before they even get to the agent. I used regular expressions to detect API keys. You could also use a lightweight ML model to detect frequently shared PII. Then warn the user “hey, looks like you dropped this - are you sure you want to share it with us?”. Or censor it out. thoughtbot’s top_secret Ruby gem does this same thing on the server-side.

What if he says no?

So what do you do if I say “no thanks, no AI please?” The same thing you’d do if I said “no I won’t share my location data”. You give me the fallback option. The manual one. Maybe my experience is not so great or maybe I have to do more work. But my principles remain intact.

A tale as old as the internet

Guess what - all this advice isn’t new for LLMs. It’s a spin on the demands coming from the privacy movements of the early 2000s and before, back when we learned how our data was being taken by governments and sold to spammers. All I ask is to let me control my exposure to AI, and give me a good reason to hand over my data to the robots.

About thoughtbot

We've been helping engineering teams deliver exceptional products for over 20 years. Our designers, developers, and product managers work closely with teams to solve your toughest software challenges through collaborative design and development. Learn more about us.