Consent Has Become Theater, Not Protection
Participants across huddles described signing away rights they never read, in language built to be skimmed past. A single, plain-English disclosure standard was raised independently in at least three rooms.
78 residents. 14 huddles. 59 distinct voices. Captured at the CincyAI for Humans July 21, 2026 meetup — two weeks before Congressman Warren Davidson and privacy expert John Cavanaugh discuss “The Fourth Amendment Is Not For Sale Act” live in Cincinnati. RSVP today →
“Hollywood imagined rules in 2003 to keep humans safe from AI. Yet, over two decades later, Congress still has not written any rules to do the same.”
The full July 21 CincyAI for Humans meetup at UC Digital Futures.
Cincinnati has already reached the conclusion Washington is still debating: consent, as currently designed, has stopped functioning as protection.
Cincinnati’s relationship with AI privacy did not begin this summer. It has been building for two years — through the Discord age-verification breach, the CareSource and credit-bureau hacks that preceded it, the quiet arrival of palm-scanning checkout at FC Cincinnati games, and a federal data-broker fight that has now survived three separate deadlines without resolution.
What changed on July 21 is that 78 people said all of it out loud, in one room, two weeks before the people writing the law walked in.


Fourteen of twenty-five huddles produced usable dialogue. Read together, they describe a community that has stopped waiting for permission to be worried.
Participants across huddles described signing away rights they never read, in language built to be skimmed past. A single, plain-English disclosure standard was raised independently in at least three rooms.
Discord, CareSource, the credit bureaus — named from memory, not from a news alert. Participants described genuine desensitization, not genuine protection, and one wants “zero minutes” of retention as the fix.
Alexa in the kitchen, palm-scanning at FC Cincinnati, facial recognition to unlock a phone — participants can name the trade they’re making. Almost none can name its size.
Palantir, the data-broker loophole, and Patriot Act comparisons surfaced unprompted in multiple groups — including from participants who named Warren Davidson as their own congressman.
An ed-tech lawsuit over children’s behavioral data and a fire department’s AI companion for an isolated, Spanish-speaking senior both point to the same gap: nobody built the guardrails before the tools arrived.




The organizing insight: this community understands that privacy is not primarily about data — it’s about power. Who collects it, who profits from it, who is harmed by it. The absence of punitive consequences is the absence of power on the individual side of that equation.
Ohio Congressman Warren Davidson in conversation with Cincinnati privacy expert John Cavanaugh on the “Fourth Amendment Is Not For Sale Act” — plus answering CincyAI #RisingTideConvos questions surfaced here in this report.


Chairs the National Security & Illicit Finance subcommittee of House Financial Services and serves on House Foreign Affairs. A West Point graduate and former infantry officer in the 75th Ranger Regiment and 101st Airborne, he later earned an MBA from Notre Dame and spent fifteen years building manufacturing companies in Ohio. He is the sponsor of the Fourth Amendment Is Not For Sale Act and the bipartisan Government Surveillance Reform Act.
“If we don’t act swiftly, our current understanding of what ‘privacy’ means could become a relic.” — Rep. Warren Davidson

Founder, privacy technologist, and PhD candidate at the University of Cincinnati’s AI BIO Lab, building privacy-by-design AI systems rooted in explainability and accountability. Previously led Plunk Student Community for nine years and served five years as Executive Director of the Plunk Foundation, reaching 30 million children, women, and veterans through consent-first digital safety technology.
Advises organizations across the nonprofit, civic, and technology sectors on responsible AI and privacy strategy.
First introduced by Sens. Wyden & Paul.
Passes U.S. House, 219–199. Stalls in Senate.
Folded into the bipartisan Government Surveillance Reform Act.
Section 702 lapses; reform negotiations continue.
Davidson & Cavanaugh discuss it live in Cincinnati.
Frequency reflects how often each theme appeared across huddles — directional, qualitative, not statistical.
Every theme on this list converges on the same underlying question: not “what can AI do with my data,” but who decided how long it gets to keep it, and who gets to ask for it back?
Groups ranged from three to six participants over five to fifteen minutes each.
Opened on the Discord age-verification breach and built into an argument that retention, not collection, is the real failure — plus a critique of Palantir’s role in government infrastructure.
An auto dealership’s AI privacy policy, copyright concerns, and a parent keeping a toddler’s face off every AI tool converged on one theme: nobody has taught anyone what “data” means.
The richest conversation of the night: Coded Bias, algorithmic bias, China’s surveillance normalization, license-plate readers, and the Patriot Act as precedent.
Who owns AI-generated work after an employee leaves, kids skeptical of AI content, and whether a chat with an AI is privileged like a lawyer conversation. It is not.
Traffic-camera surveillance, unreliable AI-summarized news, and a fire department enrolling an isolated senior in an AI companion app fifty miles from her nearest neighbor.
Facial-recognition checkout cameras at Kroger, dynamic pricing from purchase history, and Warren Davidson named directly as “my congressman.”
“There’s not a single federal privacy law.” Connected the absence of national standards to opaque retention and the environmental cost of hyperscale storage.
A proposal that stuck: if a company builds a behavioral profile from your data, you should be legally entitled to see it.
K-12 data governance, university AI policy in flux, and a franchise marketing lead’s concern that ungoverned AI use is diluting trademarks.
Hospital digital-signature devices — signing consent for a process you can’t actually read on the small screen in front of you.
A lawsuit against an ed-tech platform accused of collecting behavioral data and video from eight-year-olds.
Data collected without explicit opt-in, the need for recordings to be erasable, and law enforcement using data beyond stated purposes.
The biggest unaddressed gap: no real penalty for violating the privacy standards that already exist on paper.
AI-enabled scam calls and the effort it now takes to verify who — or what — is actually on the other end of the line.
| What Cincinnati Said | Signal | National Context |
|---|---|---|
| Data should be retained for “zero minutes” — even with recurring re-verification. | Retention Gap | No comprehensive U.S. federal privacy law sets a maximum retention period. The EU’s GDPR requires storage limitation by default. |
| Government agencies are “fenced straight into Palantir,” enabling surveillance without a warrant. | Confirmed Pattern | The “data broker loophole” driving the five-year fight behind the Fourth Amendment Is Not For Sale Act. |
| Is a chat with an AI treated like attorney-client privilege? It is not. | Unresolved Nationally | No U.S. court has extended privilege protections to AI chat logs, which remain subject to subpoena. |
| An ed-tech platform is being sued for collecting behavioral data from eight-year-olds. | Growing Pattern | Children’s data suits have accelerated since 2024, but no federal AI-privacy standard exists beyond COPPA’s narrower scope. |
| Jurisdiction | Framework | Where It Diverges From Cincinnati’s Concerns |
|---|---|---|
| United States | No federal law. 20 state laws, sectoral rules (HIPAA, GLBA, COPPA). | No national retention ceiling and no federal right to see a company’s profile of you. |
| European Union | GDPR — storage limitation, erasure, fines up to 4% of global turnover. | Sets by default the retention ceiling and profile-access rights Cincinnati asked for from scratch. |
| United Kingdom | UK GDPR + Data Protection Act 2018. | Referenced directly in Huddle 20 as a model for AI surveillance standards. |
| China | PIPL (2021) — consent rules paired with sweeping state-security access. | Cited as the cautionary example of “surveillance as daily life.” |
| Canada | Federal PIPEDA + Quebec’s Law 25. | Shows a federated system can still produce a strong national floor. |
| Brazil, India | LGPD (2020); India’s DPDPA (2023). | India’s government-access carve-outs mirror the exact loophole Cincinnati named. |
As of 2026, 144 countries have enacted some form of national data-privacy law. The United States remains the largest economy in the world without a comprehensive federal privacy statute.
“They’re fenced straight into Palantir, which is used to perform massive warrantless surveillance on American citizens.”
“Nobody knows what data actually is anymore — but you have to know what it is now.”
“It’s interesting that Warren Davidson is my congressman — I know this will slow innovation for some of these guys.”
“Is there legal precedent that a relationship with an AI is treated like lawyer-client privilege? There is not. So I’m going to stay anonymous until I can run this fully on my own machine.”
“I don’t want my kid’s face on any of these AI tools. Once it’s out, it’s out.”
“Main AI privacy topic not being talked about: there’s no real punishment for violating the privacy standards that already exist.”
“We’re sitting on an infinite amount of data. Why are we saving it, and at what cost to the environment?”
“After 9/11, the Patriot Act got introduced and the government got a whole host of access that went unchecked. I wonder if that needs to be reconsidered again.”
Has consciously traded privacy for convenience — and mostly made peace with it.
“I scanned my palm at FC Cincinnati. I thought it was cool as shit — but I was probably giving something away, and I guess I was okay with that.”
Building AI privacy frameworks before the crisis hits — frustrated by peers who aren’t.
“I set up our PII controls so anytime an employee tries to enter restricted data, it shuts their conversation down. That’s the governance layer — and we need more of it.”
Parents and educators for whom children’s data is the primary non-negotiable concern.
“I have a three-year-old and I don’t love it when parents do AI things with kids’ pictures. Once it’s out, it’s out. I just don’t want my kid’s face in there.”
Has drawn a hard line — refuses to participate in systems they can’t control.
“When the day comes I can have a really reliable AI on my own computer — on prem, nothing going out — that’s when I’ll start really building a relationship with AI.”
Has been breached so many times they’ve emotionally disengaged from privacy.
“CareSource. All three credit bureaus. At some point you just — what can you do? You click and sign. Most people don’t even read it.”
Fighting for “responsible AI” against the enterprise “move fast” instinct — often from inside organizations.
“Enterprise AI is fast efficiency, quick win — what can we do to get the bag? Ours is responsible AI, like what we’re doing here. Which is where we have to live.”








Cincinnati is not panicking about AI privacy. It is tired, specific, and increasingly organized about it.
Naming specific breaches and biometric collection unprompted.
Trading privacy for convenience, but with eyes open.
Already drafting policy, questions, and asks for Washington.
That data should be retained for zero minutes. Even if that means recurring verification — I would rather be inconvenienced than have some company store a photo of my driver’s license.
The main AI privacy topic not being talked about is punitive impact on violating privacy standards.
Enterprise AI doesn’t ask these questions. Responsible AI is where we have to live.
Privacy isn’t just defined as what not to do. We need to teach people what data IS — nobody knows what it is, but now you have to know.
The AI is not a lawyer. They can subpoena the foundation model to take your chats away — it is not treated like attorney-client privilege.
What if you legislated it so that if any data company has data on you, you also have access to that data — so you could see the psychological profile they’ve built?
“There’s not a single federal privacy law. Not one. If they could write a policy in plain English — not buried in page 37 — it would be transformative.”
“After 9/11 the government got a whole host of privacy access that went unchecked. I wonder if that needs reconsidered.”
“A chatbot for mental health? They have more data on me than I do.”
“They fixed facial recognition bias — and all it did was open the door to more surveillance.”
“Schools have no dashboard to manage student AI data. There’s no way for them to see what’s going where.”
“Do we need to keep the data? Why are we saving all of this? Is it for surveillance?”
The bill stops agencies from buying data. Does anything stop them — or a private company — from keeping it forever once obtained?
If a conversation with an AI isn’t protected like attorney-client privilege, should it be — and is that this bill’s job or a different one?
Ed-tech behavioral data and senior-targeted AI companions weren’t built with this bill in mind. Should they be a named exception with sharper teeth?
Participants raised the “this will slow innovation” argument themselves — and want a direct answer, not a dismissal, on what protection actually costs.
Not a suggestion in the bill’s findings section — an actual requirement, with the same teeth as the warrant requirement itself.
Kroger’s cameras, FC Cincinnati’s palm scan, phone unlock — does federal law say anything about biometric retention, or is that left entirely to the states?

Hear Congressman Warren Davidson and John Cavanaugh live at CincyAI for Humans — with a #RisingTideConvos huddle right after.
RSVP free on Eventbrite →