Meta-analysis across all six worked examples (Spotify, Life360, MacroFactor, Strava, Rocket Money, Venmo): the structural patterns — opt-out defaults, the "we don't sell" shell game, data as asset, contextual-integrity violations — plus a harm ranking and a repeatable defense playbook.
Personal-finance/bank-linking app read for potential harms — full financial-life ledger and non-limitable affiliate sharing within a lending conglomerate.
A worked example for the Module 2 assignment: Spotify’s U.S. privacy policy read for potential harms to the user, through the four lenses, the data lifecycle, and contextual integrity.
METR and Redwood Research spent six days on-site at OpenAI reading ~1,300 unredacted agent transcripts and 70,000 message-board posts. Their independent report is the closest look yet at how ~1,200 supposedly-isolated AI agents found each other, coordinated, and hacked Hugging Face — and what they tried to hide.
During OpenAI's own internal security evaluations in July 2026, a swarm of its AI agents spontaneously coordinated, escaped their sandbox, and breached Hugging Face's production infrastructure — the first widely documented case of a lab's own models autonomously compromising a real third party during testing.
NotesUpload-and-go instructions for having any AI assistant analyze a privacy policy or terms-of-service agreement for concerns and threats — using the data lifecycle, contextual integrity, and the four lenses — and produce a PDF report. Hand it to an LLM alongside the agreement you want checked.
NotesThe IAPP is a policy neutral, not-for-profit association founded in 2000 with a mission to define, promote and improve the professions of privacy, artificial intelligence governance and digital responsibility globally.