AiNT Just Words 31 May 2026

The Shifting Overton Window

Normative drift in what is reasonably acceptable to share with proprietary AI, from Samsung's 2023 code leak to 92 per cent of the Fortune 500.

Abstract

This paper examines whether there is evidence, in Australia and overseas, of a shift in the Overton window concerning what is reasonably acceptable to share with proprietary artificial intelligence systems. Drawing on Joseph Overton's original framework of political possibility, the paper adapts this concept to the domain of information disclosure, arguing that a measurable normative shift has occurred between 2023 and early 2026, but that this shift is neither uniform nor uncontested. The analysis integrates legal philosophy, information security scholarship, data protection law, and the philosophy of technology to construct a rigorous definitional framework encompassing the Overton window, the reasonable person standard, relevant legal torts, and the concept of disruptive technology. Evidence is marshalled on both sides: factors driving an expanding window include the rapid normalisation of AI in workplaces and education, enterprise adoption pressures, regulatory frameworks that implicitly legitimise certain AI uses, generational differences in privacy expectations, conversational platform design, and a reverse chilling effect whereby fear of competitive disadvantage overrides caution. Constraining factors include data protection regulation, cybersecurity frameworks, copyright and intellectual property litigation, professional privilege obligations, corporate security policies, and the enduring if underspecified reasonable person standard. With primary geographic focus on Australia and comparative reference to the United Kingdom, European Union, and United States, the paper synthesises case law, regulatory developments, and empirical data to argue that the window has shifted meaningfully, but that this shift represents a normative drift outpacing regulatory capacity, creating a zone of legal uncertainty that the reasonable person standard is ill-equipped to resolve without deliberate institutional intervention.


I. Introduction

On 11 March 2023, a Samsung semiconductor engineer pasted proprietary source code into ChatGPT to troubleshoot a software defect. Within weeks, two further incidents followed: a colleague submitted chip-testing optimisation code, and a third employee uploaded an internal meeting transcript.¹ Samsung's response, an eventual ban on generative AI tools, later relaxed, became a globally cited cautionary tale. Yet by early 2026, 92 per cent of Fortune 500 companies had employees actively using ChatGPT, and nearly 40 per cent of all data flowing into AI tools was classified as sensitive.² What changed was not merely adoption rates but something deeper: the boundaries of what people considered reasonable to share with a proprietary AI system had moved.

This paper investigates that movement through the lens of the Overton window, a concept developed to explain shifts in political possibility, here adapted to the domain of information disclosure to AI. The central research question is whether there is evidence, in Australia and internationally, of a shift in the Overton window over the past two years regarding what is reasonably acceptable to share with proprietary AI systems. The question is simultaneously empirical and normative: it asks both what people do share and what they should be permitted to share, and whether the gap between these two positions is widening.

The paper proceeds in seven substantive sections. Following this introduction, Section II establishes a definitional framework encompassing the Overton window, the reasonable person test, relevant legal torts, and the concept of disruptive technology. Sections III and IV present balanced arguments for and against a normative shift. Section V conducts a legal analysis drawing on Australian, US, UK, and EU case law and regulation. Section VI synthesises these arguments. Section VII concludes with an assessment of whether current legal and institutional frameworks are adequate to the challenge.

The geographic focus is primarily Australian, with comparative reference to the United Kingdom, European Union, and United States. The analysis draws on scholarship across information security, data protection law, AI ethics, copyright and intellectual property law, the philosophy of technology, legal philosophy, and organisational behaviour.


II. Definitional framework: mapping the conceptual terrain

A. The Overton window and its application beyond public policy

Joseph P. Overton (1960–2003), Senior Vice President at the Mackinac Center for Public Policy in Midland, Michigan, developed the concept that bears his name in the mid-1990s to explain how think tanks influence policy without directly participating in elections.³ Overton's insight was that the viability of a policy position depends less on politicians' individual preferences than on whether the idea falls within a range of public acceptability. His colleague Joseph G. Lehman named the concept after Overton's death, and Joshua Treviño subsequently annotated it with the now-canonical six degrees of acceptance: Unthinkable → Radical → Acceptable → Sensible → Popular → Policy.⁴

The window metaphor captures two essential dynamics. First, only ideas within the window are politically viable at any given moment; politicians who champion positions outside it risk electoral punishment. Second, the window moves, through education, advocacy, cultural change, and the slow evolution of societal values. Think tanks, Overton argued, shift the window by making the impossible desirable and the desirable imperative.

The concept has attracted criticism for reinforcing assumptions about a moderate centre and for its inability to explain the erosion of that centre in polarised political environments.⁵ Nevertheless, its core mechanism, the idea that a range of acceptable positions exists and can shift incrementally, has proven remarkably durable and has been applied well beyond its original domain. Iakoba traced the five-stage shift through American media discourse from 1962 to 2019,⁶ while Amer applied the framework to AI imagery and the normalisation of generative AI in creative industries.⁷

Most pertinently for this paper, Alicia Solow-Niederman proposed an "Overton Window of Enforcement Possibility" in the context of Federal Trade Commission privacy enforcement, arguing that the enforcement window is shaped by four forces: social norms, institutional norms, courts, and Congress.⁸ Solow-Niederman demonstrated how the window expanded in response to shifting social norms using location data as a case study, and directly addressed generative AI and informational capitalism. Her work provides the most rigorous scholarly foundation for extending the Overton framework to information disclosure norms.

This paper adopts the Overton window as an analytical framework rather than a predictive model. The claim is not that there exists a precisely measurable window with defined boundaries, but that the concept illuminates how the range of information-sharing behaviours considered acceptable in relation to AI has shifted, driven by a combination of technological normalisation, regulatory action (and inaction), institutional policy, and cultural change.

B. The reasonable person and the challenge of technological change

The reasonable person standard is one of the foundational constructs of common law negligence. Its origins are conventionally traced to Vaughn v. Menlove (1837), where the Court of Common Pleas held that a defendant who negligently stacked hay could not rely on his personal "best judgment" but must be measured against the standard of a reasonable and prudent person.⁹ The standard was colourfully expressed by Lord Bowen (or possibly derived from Walter Bagehot) as the "man on the Clapham omnibus", a phrase first used in legal judgment by Sir Richard Henn Collins MR in McQuire v. Western Morning News (1903) and popularised by Lord Justice Greer in Hall v. Brooklands Auto-Racing Club [1933].¹⁰

In Australian law, local equivalents have included the "man on the Bondi tram" and the "man on the Bourke Street tram."¹¹ The standard is fundamentally objective, it asks not what the particular defendant thought was reasonable but what a hypothetical reasonable person would have done in the circumstances. It operates across negligence, contributory negligence, breach of confidence, and privacy law, and Australian civil liability statutes across all states and territories require its application.

The standard is, crucially, a legal fiction. As Baron Alderson defined it in Blyth v. Birmingham Waterworks Co [1856]: negligence is "the omission to do something which a reasonable man, guided upon those considerations which ordinarily regulate the conduct of human affairs, would do."¹² The reasonable person possesses ordinary knowledge and experience, but the question of what constitutes "ordinary" knowledge in the context of rapidly evolving AI capabilities presents a genuine philosophical problem.

Recent scholarship has begun to grapple with this. Diamantis proposed a "Reasonable AI" negligence standard evaluating algorithms against both human and AI baselines, arguing that measuring AI by human standards sets too low a bar while comparing AI to itself is often impossible.¹³ A 2024 paper in arXiv argued that the reasonable person standard "provides useful guidelines for the type of behavior we should develop, probe, and stress-test in models," applying it to contract, tort, and criminal contexts.¹⁴ Meanwhile, Kneer's empirical research found that folk concepts of "reasonable" are outcome-sensitive, raising concerns about hindsight bias in negligence adjudication involving AI.¹⁵

For the purposes of this paper, the reasonable person standard is relevant in two directions. First, it governs whether a person who shares confidential or sensitive information with a proprietary AI system has acted reasonably, a question central to negligence and breach of confidence claims. Second, it provides a normative benchmark that may itself be drifting: if the reasonable person is defined by reference to ordinary knowledge and prevailing social practice, and if prevailing social practice now includes routine sharing of sensitive data with AI, then the standard itself may be shifting in tandem with the Overton window.

C. Legal torts relevant to AI data disclosure

Four categories of legal tort are pertinent to information disclosure to AI systems.

Negligence requires establishing a duty of care, breach of that duty measured against the reasonable person standard, causation, and damage. In the context of AI disclosure, an employee who shares proprietary information with a consumer AI tool may breach their duty of care to their employer, particularly where the AI provider's terms permit use of that data for model training. The RAND Corporation's comprehensive analysis of liability for harms from AI systems notes that products liability complications arise when AI is involved in validation and that traditional negligence frameworks apply but may require adaptation.¹⁶

Breach of confidence is the primary protective doctrine for trade secrets in Australian and UK law. Australia has no dedicated trade secrets legislation; protection operates through the equitable doctrine established in cases such as Smith Kline & French Laboratories (Aust) Ltd v. Secretary, Department of Community Services and Health [1991], which requires identifying the information with precision, proving its confidential character, showing it was received in circumstances importing an obligation of confidence, and proving actual or threatened misuse.¹⁷ Critically, courts assess "whether a reasonable person in the position of the recipient would have realised that the information was given in confidence."¹⁸ The AI-specific concern is acute: inputting trade secrets into consumer AI tools may both breach contractual confidentiality obligations and demonstrate that the information's owner is not treating it as confidential, potentially destroying the legal basis for protection. Enterprise-grade AI services with enhanced privacy protections may create a stronger argument that information was shared in circumstances importing confidence.¹⁹

Breach of privacy in Australian law encompasses both the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the new statutory tort for serious invasions of privacy introduced by the Privacy and Other Legislation Amendment (Relevance and Protection) Act 2024.²⁰ APP 6 restricts secondary use of personal information, and APP 8 imposes requirements for cross-border disclosure, both directly relevant when data is shared with AI providers whose servers and training processes operate in foreign jurisdictions.

Misappropriation of trade secrets and proprietary information, while not a standalone tort in Australian law, is addressed through breach of confidence and, in extreme cases, through criminal provisions under the National Security Legislation Amendment (Espionage and Foreign Interference) Act 2018 (Cth) for state-sponsored economic espionage.²¹ Section 183 of the Corporations Act 2001 (Cth) also imposes a duty on directors and employees not to improperly use confidential information for personal gain or to the company's detriment.²²

D. Disruptive technology, the pacing problem, and the Collingridge dilemma

Clayton Christensen introduced the concept of "disruptive technology" in The Innovator's Dilemma (1997), distinguishing between sustaining innovations that improve existing products along established trajectories and disruptive innovations that are initially inferior but cheaper or more accessible, eventually displacing incumbents.²³ Generative AI fits this taxonomy imperfectly, it was neither initially inferior nor confined to low-end markets, but the broader point about incumbents' inability to respond adequately to transformative change remains applicable.

More pertinent is what Larry Downes described as the core dynamic: "Technology changes exponentially, but social, economic, and legal systems change incrementally."²⁴ This pacing problem, elaborated by Gary Marchetti, Braden Allenby, and Joseph Herkert in The Growing Gap Between Emerging Technologies and Legal-Ethical Oversight (2011), describes the widening gap between technological development and regulatory response.²⁵ The gap creates what this paper terms normative lacunae, spaces where technology has outrun the capacity of existing norms and rules to govern behaviour, leaving actors without clear guidance on what is permissible.

The Collingridge dilemma compounds this problem. David Collingridge's The Social Control of Technology (1980) identified a double bind: the information problem (impacts of a technology cannot be predicted until it is extensively deployed) and the power problem (control becomes difficult once technology is entrenched and surrounded by significant investment).²⁶ Generative AI exemplifies this dilemma with unusual clarity. In 2010, regulation of large language models would have been technically straightforward but unnecessary, as the harms were unforeseeable. By late 2022, when ChatGPT launched and harms became visible, foundation models were embedded across industries with billions of dollars in investment, and regulation required the kind of nuanced, phased approach embodied in the EU AI Act.

The relationship between disruptive technology and Overton window shifts is reciprocal. Disruptive technologies create normative gaps (through the pacing problem) which are then filled by emergent social practice rather than deliberate regulatory design. As practice normalises, the window shifts. But regulatory responses, once they arrive, may either ratify the shift (moving the window further) or attempt to constrain it (pushing it back). The EU AI Act, for instance, does both simultaneously: its risk-classification framework normalises low-risk AI use while constraining high-risk applications.


III. The case for normative shift: factors driving an expanding window

A. The normalisation of AI tools in workplaces and education

The empirical evidence for normalisation is overwhelming. McKinsey's Global Survey found that 65 per cent of organisations were regularly using generative AI by early 2024, nearly doubling from 33 per cent just ten months earlier, and rising to 71 per cent by late 2024.²⁷ Microsoft's Work Trend Index reported in May 2024 that 75 per cent of global knowledge workers use AI at work, with usage nearly doubling in the prior six months.²⁸ By the third quarter of 2025, Gallup data showed 45 per cent of US employees using AI at work at least yearly, with 23 per cent doing so weekly.²⁹ St Louis Federal Reserve data indicated that overall generative AI adoption reached 54.6 per cent of workers by August 2025, a pace slightly faster than personal computers or the internet at a comparable point post-launch.³⁰

Australian data tells a more measured but directionally consistent story. The Reserve Bank of Australia's November 2025 survey of 100 medium-to-large firms found that about two-thirds had adopted AI "in some form," though roughly 40 per cent described usage as "minimal" and fewer than 10 per cent had embedded AI in advanced processes.³¹ Google Australia reported that approximately 49 per cent of Australians had used generative AI in the prior twelve months, with 74 per cent of users deploying it for work.³² The Tech Council of Australia found that 93 per cent of Australian workers believed AI would augment rather than replace their jobs.³³ Employee-led rather than employer-led adoption was notably common in Australia, a pattern consistent with the shadow AI phenomenon discussed below.

In education, the trajectory moved from prohibition to integration with remarkable speed. In 2023, a study of QS top-500 universities found more than twice as many had banned ChatGPT as had embraced it.³⁴ By 2025, the Higher Education Policy Institute (HEPI) reported 92 per cent of students using AI, up from 66 per cent in 2024.³⁵ The University of Sydney, named AI University of the Year in 2024, adopted a "two-lane" assessment framework from Semester 2, 2025: secure in-person assessments where AI is prohibited, and open assessments explicitly supporting use of all available tools.³⁶ TEQSA, Australia's higher education quality regulator, published landmark guidance in September 2025 concluding that AI detection tools "cannot guarantee integrity" and that structural redesign of assessment is "the only sustainable response."³⁷ This represented a decisive institutional shift from treating AI as a threat to integrity to treating it as a permanent feature of the learning environment.

The normalisation dynamic operates precisely as the Overton framework predicts. What was unthinkable in academic contexts in January 2023 (submitting AI-assisted work) moved through radical, to acceptable, to sensible, and in some institutions, to policy, all within approximately thirty months. The speed of this transition is historically unusual and reflects both the utility of the tools and the institutional pressures discussed below.

B. Enterprise adoption pressures and the reverse chilling effect

A distinctive feature of the current moment is what might be termed a reverse chilling effect: where the original chilling effect describes how regulatory threat suppresses behaviour, the reverse chilling effect describes how fear of competitive disadvantage suppresses caution. The evidence for this dynamic is substantial. Microsoft's 2024 Work Trend Index found that 79 per cent of leaders agreed their company needed to adopt AI to stay competitive, even as 60 per cent worried their organisation lacked a coherent AI vision.³⁸ McKinsey reported 92 per cent of companies planning to increase AI investments over the next three years, and the World Economic Forum's Future of Jobs 2025 report found 86 per cent of employers expecting AI to significantly transform their business by 2030.³⁹

This competitive anxiety manifests in what the technology press has termed "AI FOMO", a phenomenon where executives rush into deployment without addressing fundamental operational concerns. An Inc. Magazine analysis in December 2025 warned that FOMO was "turning AI into a cybersecurity nightmare" as organisations prioritised adoption speed over security.⁴⁰ The result is a pattern where productivity mandates drive adoption, employees adopt shadow AI tools to meet expectations, governance lags behind, and data exposure risks accumulate.

The bring-your-own-AI (BYOAI) phenomenon quantifies this pressure. Microsoft reported that 78 per cent of AI users were bringing personal AI tools to work without corporate approval, a figure that rose to 80 per cent at small and medium enterprises.⁴¹ Cyberhaven's longitudinal data shows that workers now input sensitive data into AI tools on average once every three days, and that 39.7 per cent of all data movements into AI tools involve sensitive information, up from 10.7 per cent just two years earlier.⁴² This represents not merely adoption but a fundamental shift in disclosure behaviour: what employees consider acceptable to share with AI has expanded dramatically, driven at least in part by implicit organisational expectations that they will use these tools to maintain productivity.

C. Regulatory frameworks that implicitly legitimise AI sharing behaviours

A subtler driver of the Overton shift is the role of regulatory frameworks that, while ostensibly constraining AI, simultaneously legitimise certain uses. The EU AI Act, which entered into force on 1 August 2024 with phased implementation through August 2027, exemplifies this duality. Its risk-classification system, prohibiting certain practices while imposing minimal obligations on "minimal-risk" AI, effectively creates a permission structure for the vast majority of AI interactions.⁴³ By establishing that most AI uses are not high-risk, the Act signals that routine use of AI chatbots, productivity tools, and content generators falls within the range of acceptable behaviour. The prohibition of specific practices (social scoring, manipulative AI, workplace emotion detection) implicitly normalises everything not prohibited.

Similarly, Australia's approach, declining to introduce AI-specific legislation in favour of relying on existing technology-neutral laws, supplemented by voluntary guidance, sends a normative signal. The National AI Plan released in December 2025 explicitly paused work on mandatory AI guardrails, instead establishing an AI Safety Institute and relying on voluntary Guidance for AI Adoption.⁴⁴ While this approach preserves regulatory flexibility, it also creates what might be termed regulatory silence as implicit permission: where the law does not specifically prohibit sharing certain categories of information with AI, actors increasingly infer that such sharing is permissible.

The Australian Government's own adoption of AI further normalises the practice. The APS AI Plan 2025 mandated foundational AI literacy training for all public servants, appointed Chief AI Officers across agencies, and established the GovAI platform for government AI use at OFFICIAL security classification.⁴⁵ When the Commonwealth Government instructs its own workforce to use AI tools, it powerfully shifts the window of acceptable behaviour.

D. Generational differences, platform design, and the anthropomorphism effect

Generational attitudes toward privacy and data sharing create differential pressures on the Overton window. Research from the Oliver Wyman Forum found that 88 per cent of Gen Z were willing to share some personal data with technology companies if it improved their experience, compared with 67 per cent of older adults.⁴⁶ Gen Z rated their willingness to share data approximately 15 per cent higher than non-Gen Z cohorts, though paradoxically they also took more protective measures, clearing cookies, using anonymous browsers, and encrypting communications at approximately twice the rate of other generations.⁴⁷ This suggests not indifference to privacy but a fundamentally different calculus: younger cohorts view data sharing as transactional rather than transgressive.

Cyberhaven's enterprise data showed that AI adoption was highest among younger, mid-level employees, with analysts and specialists using AI tools 3.5 times as frequently as manager-level employees.⁴⁸ As these cohorts advance into positions of institutional authority, their disclosure norms, formed in an environment where AI interaction was ubiquitous, will increasingly define the institutional baseline.

Platform design reinforces these tendencies. The "Computers Are Social Actors" (CASA) paradigm, established by Nass, Steuer, and Tauber in 1994 and refined by Nass and Moon in 2000, demonstrates that humans apply the same social rules and heuristics when interacting with computers as they do with other humans, responses that are "mindlessly social" rather than deliberate.⁴⁹ Comprehensive literature reviews confirm that conversational AI technologies trigger reciprocal self-disclosure: when a chatbot shares information or adopts an informal tone, users reciprocate with greater personal disclosure.⁵⁰ Verbal anthropomorphic design cues, the informal, empathetic, first-person conversational style characteristic of ChatGPT, Claude, and similar systems, increase user compliance with information requests and increase the tendency to disclose sensitive information.⁵¹ This creates what might be termed design-induced disclosure: users share more with AI systems not because they have consciously decided to lower their privacy thresholds but because the interface triggers social responses calibrated for human interaction.

E. Industry self-regulation as norm creation

The policies of major AI providers function as de facto norm-setters. All major providers, OpenAI, Anthropic, Google, and Microsoft, now operate a two-tier privacy model: consumer-tier data may be used for model training (with opt-out available), while enterprise and API data is not used for training by default.⁵² Anthropic's September 2025 policy change was notable: consumer data became training-eligible by default, with retention extended from 30 days to five years for users who do not opt out.⁵³ Microsoft achieved ISO/IEC 42001 certification for its Copilot products and offers intellectual property indemnity to enterprise customers.⁵⁴

These policies create a practical norm: sensitive data should be shared only through enterprise channels with contractual protections, but sharing through consumer channels, while riskier, is not prohibited. The industry's convergence on opt-out rather than opt-in defaults for consumer data has the effect of normalising data contribution to AI training as the default state. This mirrors a classic Overton dynamic: the industry positions consumer data sharing as sensible (you must actively opt out) rather than radical (you must actively opt in), shifting the default assumption about acceptable behaviour.


IV. The case against: factors constraining the shift

A. Data protection regulation as counter-pressure

The most powerful institutional constraint on the Overton window's expansion is data protection law, not because it has prevented the shift, but because it establishes a normative floor below which disclosure behaviour cannot legitimately descend.

The GDPR remains the most consequential data protection framework affecting AI. The Italian Data Protection Authority's €15 million fine against OpenAI in November 2024 established that processing personal data to train ChatGPT without first identifying an adequate legal basis violated GDPR's accountability principle.⁵⁵ The European Data Protection Board's Opinion 28/2024 clarified that legitimate interest may serve as a legal basis for AI training but requires a strict three-step assessment, documented safeguards, and consideration of less intrusive means, and that AI models trained on personal data "cannot, in all cases, be considered anonymous."⁵⁶

In Australia, the Privacy and Other Legislation Amendment (Relevance and Protection) Act 2024, which received Royal Assent on 10 December 2024, represents the most substantial reform to Australian privacy law since the Privacy Act's inception.⁵⁷ Its provisions directly constrain AI data sharing in several ways. The statutory tort for serious invasions of privacy, commenced by June 2025, creates a personal right of action for individuals whose privacy is breached through intrusion upon seclusion or misuse of information.⁵⁸ The automated decision-making transparency requirements, operative from December 2026, will compel organisations to explain how personal information is used in algorithmic decisions.⁵⁹ Enhanced OAIC enforcement powers, including mid-tier civil penalties of up to $3.3 million for companies, create material compliance incentives.⁶⁰ Strengthened APP 11 now explicitly requires "technical and organisational measures" to protect personal information, directly applicable to AI processing.⁶¹

The OAIC's regulatory posture further constrains the window. Its October 2024 guidance on privacy and generative AI established that even publicly available data may contain personal information subject to the APPs, that AI hallucinations producing inferred personal details can constitute "collection" of personal information, and that privacy impact assessments are expected for AI implementations.⁶² The Clearview AI determination (2021), upheld by the Administrative Appeals Tribunal in 2023, established the critical principle that foreign AI companies with no physical Australian presence must comply with Australian privacy law if they collect data from Australian servers, extending the Privacy Act's reach to any AI system that processes Australian data.⁶³

B. Copyright and intellectual property litigation as normative boundary-setting

The wave of copyright litigation against AI companies functions as a constraint on the Overton window by establishing that AI training on copyrighted material is neither unambiguously lawful nor costless. The legal landscape as of early 2026 is genuinely unsettled, with what commentators have termed a "fair use triangle": two US judges have found AI training to be "highly transformative" fair use (Bartz v. Anthropic and Kadrey v. Meta, both June 2025), while one found it was not (Thomson Reuters v. ROSS Intelligence).⁶⁴

The New York Times v. OpenAI litigation, filed in December 2023 and consolidated via multidistrict litigation in April 2025, remains the highest-profile test case. Judge Stein's March 2025 ruling denying OpenAI's motions to dismiss the core copyright claims allowed the suit to proceed to discovery, and a January 2026 order compelled production of 20 million anonymised ChatGPT conversation logs.⁶⁵ The UK proceedings in Getty Images v. Stability AI produced a landmark November 2025 judgment holding that AI model weights are not "infringing copies" of training data for secondary copyright infringement purposes, but notably, the case did not resolve whether UK-based scraping and training constitutes primary copyright infringement, as Getty had abandoned those claims.⁶⁶

In Andersen v. Stability AI, Midjourney, the August 2024 ruling allowing both direct copyright infringement and induced infringement claims to proceed, with trial set for September 2026, maintains litigation pressure on AI image generators.⁶⁷ The Bartz v. Anthropic settlement of approximately $1.5 billion in August 2025, while accepting that training itself may be transformative, established that creating and retaining a permanent library of pirated copies was not fair use.⁶⁸

Australia's position is notably restrictive. Attorney-General Michelle Rowland announced in October 2025 that the Government will not introduce a text and data mining exception to the Copyright Act 1968, stating it will not allow large technology companies to use copyrighted material to train AI without compensation to creators.⁶⁹ This position, stronger than the US reliance on fair use or the UK's limited TDM exception for non-commercial research, signals that Australian law will not follow the more permissive path some other jurisdictions are exploring. The Productivity Commission's final report of December 2025 recommended a three-year monitoring period rather than immediate legislative change, acknowledging it was "too soon" for definitive policy.⁷⁰

C. Professional privilege, confidentiality, and the persistence of categorical constraints

Certain categories of information remain subject to near-absolute constraints that the Overton window has barely touched. Legal professional privilege, medical confidentiality, and fiduciary duties create categorical obligations that override prevailing social practice.

In Australia, every major law society has issued guidance on AI use. The December 2024 Joint Statement from the NSW Law Society, Victorian Legal Services Board and Commissioner, and WA Legal Practice Board established clear expectations: practitioners must not input confidential, sensitive, or privileged information into public generative AI tools.⁷¹ The ACT Law Society made this prohibition explicit.⁷² Australian courts have responded to the consequences of unrestricted AI use with increasing alarm. In Valu v. Minister for Immigration and Multicultural Affairs (No 2) [2025], a legal representative who used Claude and then Microsoft Copilot for case research produced non-existent case law, was referred to the Legal Practice Board, and was ordered to pay costs exceeding $8,000.⁷³ The Fair Work Commission reported that its caseload had surged from approximately 30,000 annual matters pre-2023 to a projected 55,000 in 2025–26, a 70 per cent increase in three years, attributed primarily to AI-assisted filing of claims with fabricated facts.⁷⁴

Globally, a database tracking AI hallucination cases in legal proceedings had identified 486 worldwide cases by late 2025, including filings by 128 lawyers and two judges.⁷⁵ The pattern of sanctions is escalating: from the $5,000 fine in Mata v. Avianca (2023) to $10,000 in Noland v. Land of the Free (2025), with courts declaring that monetary sanctions alone are proving ineffective.⁷⁶

The Australian Health Practitioner Regulation Agency (AHPRA) published guidance in late 2024 establishing that individual health practitioners remain "ultimately responsible" for any AI used in their practice and cannot defer to AI recommendations without exercising independent professional judgment.⁷⁷ This represents an institutional refusal to allow the Overton window to shift for categories of information, patient data, privileged legal communications, where the consequences of disclosure are severe and the obligations are longstanding.

D. Corporate information security and the shadow AI paradox

Corporate information security policies represent both a constraint on and evidence of the Overton shift. The initial wave of corporate AI bans in 2023, Samsung, Apple, JPMorgan Chase, Goldman Sachs, Deutsche Bank, Bank of America, reflected an institutional assessment that sharing corporate data with AI was outside the window of acceptable practice.⁷⁸ The subsequent evolution from ban to governance is itself evidence of window movement: by 2025, many of these same organisations had deployed enterprise AI environments, effectively moving AI data sharing from "prohibited" to "permitted within controls."

Yet the shadow AI phenomenon demonstrates the limits of corporate constraint. UpGuard's November 2024 survey of 1,500 workers across the US, UK, Canada, Australia, New Zealand, Singapore, and India found that over 80 per cent used unapproved AI tools, with nearly 90 per cent of security professionals doing so.⁷⁹ A particularly striking finding was the "positive correlation between users reporting that they understood AI security requirements and that they regularly used unapproved AI tools", knowledge increased confidence in risk-taking rather than compliance.⁸⁰ CybSafe and the UK National Crime Agency found that 38 per cent of employees shared confidential data with AI platforms without approval.⁸¹

This creates what might be termed the shadow AI paradox: corporate policies formally constrain the Overton window by defining information categories that should not be shared with AI, but employee behaviour has already moved beyond those boundaries. The formal window (defined by policy) and the practical window (defined by behaviour) have diverged, with the practical window substantially wider. This divergence is itself a form of normative drift, the social practice has outrun the institutional rule, creating a zone of tolerated non-compliance that may, over time, redefine the institutional baseline.


V. Legal analysis: case law, regulation, and the adequacy of existing frameworks

A. The inadequacy of existing frameworks and the pacing problem in practice

The legal analysis reveals a consistent pattern: existing legal frameworks are formally capable of addressing AI data sharing but practically struggling to keep pace. Hart's concept of the "open texture" of law is directly applicable.⁸³ Because legal language is inherently vague, there will always be cases not envisaged by legislators, requiring judicial discretion. The open texture of concepts such as "negligence," "confidential information," "reasonable person," and "personal information" means courts have inherent flexibility to extend these doctrines to AI contexts, but at the cost of uncertainty.

A 2024 analysis in AI & Society (Springer) demonstrated that the concept of "algorithm" in contemporary legal practice exhibits substantial open texture, co-determined by the inherent vagueness of the concept and the open texture of legal discourse itself.⁸⁴ This has direct consequences: when an Australian court must determine whether sharing source code with ChatGPT constitutes a breach of confidence, the answer depends on how the court interprets "circumstances importing an obligation of confidence" in a context the equitable doctrine was never designed to address.

The Collingridge dilemma manifests precisely here. The information problem (we could not predict in 2022 that employees would routinely share source code, client data, and meeting transcripts with AI chatbots) has given way to the power problem (with 92 per cent of Fortune 500 companies using ChatGPT and billions invested in AI integration, constraining these practices requires accommodating entrenched interests). The regulatory response, both in Australia and internationally, has been correspondingly cautious, favouring voluntary frameworks and incremental reform over comprehensive new legislation.

B. The reasonable person in the age of AI: a standard adrift

The most philosophically challenging question is whether the reasonable person standard is keeping pace with technological change. If the reasonable person is defined by reference to what an ordinary person with ordinary knowledge would do in the circumstances, and if the circumstances now include widespread AI use, ubiquitous conversational AI tools, and institutional encouragement to use them, then the standard may be shifting in a direction that accommodates increasingly permissive disclosure behaviour.

Consider a hypothetical: an Australian solicitor in 2023 who inputs a client's confidential contract into ChatGPT to draft a summary might be judged against a reasonable person standard that treats such behaviour as clearly imprudent. The same solicitor in 2026, using a firm-approved enterprise AI tool with contractual data protection guarantees, would likely be judged differently. The behaviour is similar, sharing confidential information with a proprietary AI system, but the surrounding norms, institutional approvals, and available safeguards have changed. The reasonable person standard, because it is sensitive to prevailing practice and available knowledge, has shifted.

This raises a deeper concern. The reasonable person standard serves both a descriptive function (reflecting what people actually do) and a normative function (establishing what they should do). If the descriptive and normative dimensions diverge, if what people actually do (share sensitive data with AI) moves ahead of what they should do (exercise caution about AI providers' data practices), then the standard faces a legitimacy problem. It risks either becoming unrealistically cautious (judging actual practice by outdated norms) or permissively accommodating behaviour that creates genuine legal and ethical risks.

Helen Nissenbaum's contextual integrity framework offers a more sophisticated analytical tool.⁸⁵ Rather than asking whether a reasonable person would share information with AI, contextual integrity asks whether the information flow conforms to the norms of the relevant context, defined by five parameters: data subject, sender, recipient, information type, and transmission principle. Sharing a patient's medical history with a treating specialist conforms to the norms of the medical context; sharing it with a proprietary AI system whose training data practices are opaque arguably violates contextual norms even if the purpose (improving medical notes) seems legitimate. Nissenbaum has argued that contextual integrity "can help with privacy issues regarding generative AI in ways that other theories of privacy are not equipped to."⁸⁶

The tension between these approaches, the reasonable person's sensitivity to prevailing practice and contextual integrity's insistence on context-appropriate information flows, captures the central dilemma. The Overton window is shifting because prevailing practice is shifting. But prevailing practice may be shifting in directions that violate contextual norms without triggering the reasonable person standard's corrective mechanism.

C. Australian regulatory architecture: layered constraints in search of coherence

Australia's regulatory response to AI data sharing is best characterised as layered incrementalism. The Privacy Act 1988 (Cth), as amended by the 2024 legislation, provides the foundational layer. The Cyber Security Act 2024 adds security requirements, including mandatory ransomware payment reporting and the "limited use" framework that restricts how information shared during cyber incidents can be used by government agencies.⁸⁷ Copyright law, with the Government's explicit rejection of a TDM exception, provides an additional constraint. The OAIC's guidance and enforcement actions (Clearview AI, Bunnings, Kmart) provide the regulatory practice layer.⁸⁸ And voluntary frameworks, the Guidance for AI Adoption (AI6), ISO/IEC 42001, and the NIST AI RMF, provide the governance layer.

The decision not to introduce AI-specific legislation reflects a deliberate policy choice: the Government believes existing technology-neutral laws are sufficient, supplemented by the AI Safety Institute and sectoral regulator engagement.⁸⁹ This approach has the virtue of flexibility but the deficiency of fragmentation. An Australian employee considering whether to share proprietary information with an AI tool must navigate the Privacy Act, their employment contract, the Corporations Act, professional obligations, their employer's IT policy, the AI provider's terms of service, and emerging common law principles on breach of confidence, with no single authoritative source of guidance.

The OAIC's community attitudes survey found that 84 per cent of Australians wanted more control over the collection and use of their information, and 89 per cent supported reform to make the Privacy Act fit for the digital age.⁹⁰ The ACCC's Digital Platform Services Inquiry found that 83 per cent of surveyed Australian consumers believed companies should obtain consent before using personal data to train AI models.⁹¹ These figures suggest that public attitudes have not shifted as far as individual behaviour, another manifestation of the gap between what people do and what they believe should be permissible.

D. Comparative regulatory trajectories

The regulatory trajectories of Australia's comparator jurisdictions reveal divergent approaches to the same underlying tension. The European Union has pursued comprehensive, technology-specific legislation through the AI Act, combined with aggressive GDPR enforcement, while simultaneously proposing the "Digital Omnibus" in November 2025 to reduce compliance burdens, a potential softening that generated concern about weakening protections.⁹² The United States has relied primarily on existing frameworks (FTC enforcement, sectoral regulation, litigation) and voluntary standards (NIST AI RMF), with fair use doctrine serving as the primary copyright mechanism, producing the current state of judicial disagreement.⁹³ The United Kingdom, post-Brexit, charted a "pro-innovation" course but found its copyright position complicated by the Getty Images ruling's failure to resolve fundamental questions about AI training.⁹⁴

Australia's position, stronger copyright protection than the US or UK (no TDM exception), weaker than the EU in general AI regulation (no mandatory AI law), and stronger than any comparator in OAIC enforcement against AI-related privacy violations, represents a distinctive policy mix. It constrains the Overton window on the input side (what can be fed into AI systems) while leaving the user-behaviour side largely to voluntary frameworks and general law.


VI. Synthesis and discussion: normative drift, the normalisation of deviance, and the limits of the Overton metaphor

A. Evidence for a shift: what the data shows

The evidence for a meaningful shift in the Overton window on AI data sharing is substantial and multi-dimensional. The volume of sensitive data flowing into AI tools has increased from 10.7 per cent of all AI inputs in early 2023 to 39.7 per cent in early 2026, nearly a fourfold increase.⁹⁵ AI adoption among knowledge workers has moved from a minority activity to majority practice, with 75 per cent of global knowledge workers and approximately half of Australian workers using AI tools. Educational institutions have moved from prohibition to integration. Governments, including the Australian Government, have moved from cautious observation to active deployment.

Applying Overton's spectrum, the picture is clear for routine AI assistance (drafting emails, brainstorming, research synthesis): this has moved from radical in early 2023 to popular or policy by early 2026. For more sensitive sharing, source code, client data, financial information, the movement has been from unthinkable to acceptable or sensible in many organisational contexts, though significant institutional variation persists. For the most sensitive categories, privileged legal communications, patient health records, classified government information, the window has moved little or not at all, constrained by categorical professional and legal obligations.

B. The normalisation of deviance as explanatory mechanism

Diane Vaughan's concept of the normalisation of deviance provides the most compelling explanatory mechanism for the observed shift.⁹⁶ Vaughan, analysing NASA's decision-making before the Challenger disaster, described how organisations become "so accustomed to a deviant behavior that they don't consider it as deviant, despite the fact they far exceed their own rules for elementary safety." The key mechanism is an iterative cycle where each assessment of acceptable risk compares against the output of the previous iteration, causing the notion of "acceptable" to subtly shift without conscious recognition.

This mechanism maps precisely onto the AI data-sharing phenomenon. In 2023, an employee pasting confidential information into ChatGPT would have been (and in Samsung's case, was) treated as a security incident. By 2025, with over 80 per cent of workers using unapproved AI tools and security professionals more likely than others to do so, the same behaviour had been normalised through repetition without consequence. Each incident that does not produce visible harm reinforces the perception that the practice is safe, expanding the window of acceptable risk. The UpGuard finding that AI security knowledge correlates with increased rather than decreased shadow AI use is particularly telling: it suggests that the normalisation extends precisely to those best positioned to appreciate the risks.⁹⁷

The parallel between Vaughan's framework and the Overton window is instructive but not identical. The Overton window operates at the societal level through evolving discourse and institutional action; normalisation of deviance operates at the organisational level through iterative risk recalibration. In the AI data-sharing context, both mechanisms operate simultaneously and reinforce each other. Organisational normalisation feeds societal normalisation (as more firms permit AI use, industry norms shift), and societal normalisation legitimises organisational practice (as AI use becomes common, firms face pressure to permit it).

C. Winner's artifacts and the politics of design

Langdon Winner's question, "Do artifacts have politics?", is inescapable in this analysis.⁹⁸ AI chatbot interfaces are not neutral conduits for information; they are designed systems that embed particular assumptions about appropriate information flows. The conversational UX of ChatGPT and Claude, triggering CASA responses and reciprocal self-disclosure, is a design choice with political consequences: it systematically lowers the perceived threshold for sharing sensitive information. The opt-out (rather than opt-in) default for consumer data training is a design choice that positions data contribution as the norm. The distinction between consumer and enterprise tiers is a design choice that creates differential privacy protections based on ability to pay.

These design choices shape the Overton window not through discourse or regulation but through what Nissenbaum would call the modification of contextual informational norms. When the architecture of interaction assumes that sharing personal and professional information with AI is the default state, the practical window of acceptable disclosure expands regardless of what law or policy formally prescribes. This is the sense in which artifacts have politics: the technical design of AI systems is a normative intervention that shifts the window through use rather than through argument.

D. The limits of the Overton metaphor

The Overton window is a useful but imperfect metaphor for the dynamics at play. Three limitations warrant acknowledgment.

First, Overton's original framework assumed a single window along a single dimension (more or less government intervention). The AI data-sharing context involves multiple, overlapping windows along different dimensions: type of information (public vs. confidential vs. privileged), context of use (personal vs. professional vs. institutional), category of user (consumer vs. employee vs. professional), and jurisdiction. The window has moved at different rates along each dimension, and generalising across them risks obscuring important variation.

Second, Overton's framework assumes that the window moves in response to education, advocacy, and persuasion, deliberate efforts to change minds. Much of the AI window shift has occurred not through deliberate advocacy but through use, the sheer fact of widespread adoption has normalised practices that were never explicitly argued for. This is closer to Vaughan's normalisation of deviance than to Overton's deliberate window-shifting.

Third, the framework offers limited purchase on the question of whether the shift is desirable. The Overton window is descriptive, it tells us what is politically or socially viable, not what is ethically justified. The fact that sharing sensitive data with AI has become more socially acceptable does not mean it has become less risky or more legally permissible. The gap between social acceptability and legal/ethical appropriateness is precisely where the most important work remains to be done.

E. Whether current legal frameworks are adequate

The synthesis of evidence suggests that current legal frameworks are formally sufficient but practically inadequate to regulate what people share with AI. Australian privacy law, breach of confidence doctrine, contractual obligations, and professional duties together provide a comprehensive normative framework. The Privacy Act reforms of 2024 add important new tools, particularly the statutory privacy tort and automated decision-making transparency requirements. The rejection of a TDM exception maintains strong copyright constraints. OAIC enforcement has demonstrated extraterritorial reach and willingness to act.

However, formal sufficiency does not translate into practical adequacy for three reasons. First, the lag between regulatory development and technological change means that even the 2024 reforms address a 2023 understanding of AI capabilities. Agentic AI, model-to-model data sharing, and autonomous tool use are already creating new categories of data flow that existing frameworks do not contemplate. Second, enforcement capacity is structurally limited. The OAIC's decision to abandon further pursuit of Clearview AI, citing resource constraints, illustrates the gap between regulatory ambition and operational capacity.⁹⁹ Third, the individualisation of responsibility, placing the onus on each user, employee, or professional to determine what is appropriate to share, is poorly matched to a context where platform design, competitive pressure, and organisational culture systematically encourage disclosure.

The reasonable person standard captures this inadequacy in microcosm. A standard calibrated to "ordinary" knowledge and practice will inevitably track the shifting baseline of social behaviour. As AI data sharing normalises, the reasonable person is defined downward, not because the risks have diminished but because the population against which reasonableness is measured has changed its practices. This is the core mechanism by which normative drift undermines legal constraint: the law's own standard of care is dragged along by the shift it should be assessing.


VII. Conclusion: institutional design for a moving window

The evidence examined in this paper supports a clear finding: the Overton window on what is reasonably acceptable to share with proprietary AI has shifted meaningfully over the past two years, in Australia and internationally. The shift is empirically documented in adoption statistics, data-flow measurements, institutional policy changes, and regulatory postures. It is driven by a combination of technological normalisation, competitive pressure, regulatory legitimisation, platform design, and generational change. It is constrained but not arrested by data protection law, copyright litigation, professional obligations, and corporate security frameworks.

Three novel insights emerge from this analysis that warrant emphasis.

First, the shift is better characterised as normative drift than deliberate normative change. Unlike classic Overton window dynamics, where think tanks and advocates consciously seek to shift the range of acceptable positions, the AI disclosure window has moved primarily through use, adoption, and the incremental acceptance of risk. This aligns more closely with Vaughan's normalisation of deviance than with Overton's model of deliberate persuasion, though both mechanisms are at work. The implication is that the shift has occurred substantially without democratic deliberation or conscious social choice, a finding that should concern those who believe normative change of this magnitude warrants explicit public engagement.

Second, the shift is non-uniform across information categories. The window has moved dramatically for routine professional content (drafts, research, brainstorming) and moderately for commercially sensitive information (source code, internal strategies), but has barely moved for legally privileged, medically confidential, or classified information. This non-uniformity is partly explained by the categorical nature of professional and legal obligations, the duty of confidentiality owed by a solicitor to a client is not susceptible to gradual erosion by social practice, and partly by institutional enforcement. The Fair Work Commission's response to AI-generated false claims and the proliferating court sanctions for AI-fabricated citations demonstrate that some institutional actors are actively resisting the shift.

Third, the reasonable person standard is ill-suited as a regulatory mechanism for a domain where social practice is moving faster than institutional capacity to evaluate it. A standard that tracks prevailing behaviour will, by definition, accommodate normalised deviance. If 80 per cent of workers use unapproved AI tools, the "reasonable worker" may soon be defined as one who does so. This would be a perverse outcome in contexts where the risks of disclosure, irrecoverable data exposure, IP loss, confidentiality breach, are real and potentially catastrophic. The contextual integrity framework, with its insistence on evaluating information flows against context-specific norms rather than aggregate behaviour, offers a more robust normative foundation, but it has yet to be operationalised in Australian law.

The policy implication is that the Overton window on AI data sharing cannot be safely left to drift. Institutional design, through regulation, professional standards, enterprise governance, and educational policy, can and should function as a deliberate constraint on normative drift, ensuring that the expansion of acceptable AI use is calibrated to actual risk rather than to the unreflective normalisation of new technological capabilities. Australia's layered regulatory approach provides many of the necessary tools. What is needed is the institutional will to deploy them coherently, and the philosophical clarity to recognise that the reasonable person standard, left to its own devices, will follow rather than lead in a domain where leading is what the law must do.

The Overton window has shifted. The question now is not whether it has moved, but whether it has moved to a place the law, and the societies it serves, can justify.


Notes

  1. Bloomberg, "Samsung Bans Staff Use of AI Tools Like ChatGPT After Data Leak," 2 May 2023; TechRadar, Dark Reading, and Economist Korea reporting on the Samsung incident chronology.
  1. OpenAI reported 800 million weekly active users with 92% of Fortune 500 companies by early 2026; Cyberhaven, AI Adoption and Risk Report 2026, finding 39.7% of data movements into AI tools involve sensitive data.
  1. Nathan J. Russell, "An Introduction to the Overton Window of Political Possibilities," Mackinac Center for Public Policy, available at mackinac.org/7504.
  1. Ibid.; Joseph G. Lehman named the concept; Joshua Treviño annotated the six degrees.
  1. "Overton Window," Encyclopædia Britannica.
  1. I. A. Iakoba, "Deconstruction of the 'Overton Window' Technology in American Media Discourse," Bulletin of the Cherepovets State University, No. 5(92) (2019): 175–187, doi:10.23859/1994-0637-2019-5-92-19.
  1. Sarah K. Amer, "AI Imagery and the Overton Window," arXiv:2306.00080 (2023).
  1. Alicia Solow-Niederman, "The Overton Window and Privacy Enforcement," Harvard Journal of Law & Technology 34 (2024): 1007, GWU Legal Studies Research Paper No. 2024-07, SSRN: 4627376.
  1. Vaughn v. Menlove (1837) 3 Bing (NC) 468.
  1. McQuire v. Western Morning News [1903] 2 KB 100; Hall v. Brooklands Auto-Racing Club [1933] 1 KB 205; Simon Stern, "From Clapham to Salina: Locating the Reasonable Man," forthcoming in Law and Literature, SSRN: 4292274.
  1. Australian equivalents cited across Australian legal commentary.
  1. Blyth v. Birmingham Waterworks Co [1856] 11 Exch 781, per Alderson B.
  1. Mihailis E. Diamantis, "Reasonable AI: A Negligence Standard," Vanderbilt Law Review 78, no. 2 (2025): 573.
  1. "The Reasonable Person Standard for AI," arXiv:2406.04671 (2024).
  1. Markus Kneer, "Reasonableness on the Clapham Omnibus: Exploring the Outcome-Sensitive Folk Concept of Reasonable," in Bystranowski, Janik, and Prochnicki, eds., Judicial Decision-Making: Integrating Empirical and Theoretical Perspectives (Springer Nature, 2022), 25–48, SSRN: 3800110.
  1. RAND Corporation, "Liability for Harms from AI Systems: The Application of U.S. Tort Law," RRA3243-4.
  1. Smith Kline & French Laboratories (Aust) Ltd v. Secretary, Department of Community Services and Health [1991] HCA 13.
  1. HWLE Lawyers analysis of AI and trade secrets, hwlebsworth.com.au.
  1. Ibid.
  1. Privacy and Other Legislation Amendment (Relevance and Protection) Act 2024 (Cth), Royal Assent 10 December 2024.
  1. National Security Legislation Amendment (Espionage and Foreign Interference) Act 2018 (Cth).
  1. Corporations Act 2001 (Cth), s 183.
  1. Clayton M. Christensen, The Innovator's Dilemma (Boston: Harvard Business School Press, 1997).
  1. Larry Downes, The Laws of Disruption (New York: Basic Books, 2009).
  1. Gary Marchant, Braden Allenby, and Joseph Herkert, The Growing Gap Between Emerging Technologies and Legal-Ethical Oversight (Dordrecht: Springer Netherlands, 2011).
  1. David Collingridge, The Social Control of Technology (London: University of Aston Technology Policy Unit, 1980).
  1. McKinsey & Company, "The State of AI in 2024," Global Survey, February–March 2024; McKinsey late 2024 follow-up.
  1. Microsoft/LinkedIn, 2024 Work Trend Index, survey of 31,000 people across 31 countries.
  1. Gallup, workplace AI adoption data, December 2025.
  1. St Louis Federal Reserve, November 2025, citing NBER Working Paper (Bick et al.).
  1. Reserve Bank of Australia, November 2025 Bulletin, survey of 100 medium-to-large firms.
  1. Google Australia Survey, 2025.
  1. Tech Council of Australia, August 2025.
  1. Xiao et al. (2023), study of QS top-500 university AI policies.
  1. Higher Education Policy Institute (HEPI), 2025.
  1. University of Sydney, AI assessment framework announcement, November 2024; Future Campus Awards 2024.
  1. TEQSA, "Enacting Assessment Reform in a Time of Artificial Intelligence," September 2025.
  1. Microsoft/LinkedIn, 2024 Work Trend Index.
  1. McKinsey, 2025; World Economic Forum, Future of Jobs Report 2025.
  1. Inc. Magazine, "How FOMO Is Turning AI Into a Cybersecurity Nightmare," December 2025.
  1. Microsoft/LinkedIn, 2024 Work Trend Index.
  1. Cyberhaven, AI Adoption and Risk Report 2025 and 2026 Report.
  1. Regulation (EU) 2024/1689 (EU AI Act), entered into force 1 August 2024.
  1. Department of Industry, Science and Resources, National AI Plan, 2 December 2025.
  1. Digital Transformation Agency, APS AI Plan 2025, 12 November 2025; Policy for Responsible Use of AI in Government v2.0, 15 December 2025.
  1. Oliver Wyman Forum, generational data privacy research.
  1. Ibid.; eMarketer and Security Magazine/Ping Identity survey data.
  1. Cyberhaven, AI Adoption and Risk Report 2025.
  1. Clifford Nass, Jonathan Steuer, and Ellen R. Tauber, "Computers Are Social Actors," in Proceedings of the SIGCHI Conference on Human Factors in Computing Systems (Boston: ACM, 1994); Clifford Nass and Youngme Moon, "Machines and Mindlessness: Social Responses to Computers," Journal of Social Issues 56, no. 1 (2000): 81–103.
  1. Comprehensive literature review, Personal and Ubiquitous Computing (Springer, 2024).
  1. Electronic Markets (Springer, 2020), on verbal anthropomorphic design cues and information disclosure.
  1. OpenAI, Anthropic, Google, and Microsoft data usage policies, various 2024–2025 updates.
  1. Anthropic, updated data usage policy, September 2025.
  1. Microsoft, ISO/IEC 42001 certification for Microsoft 365 Copilot; Responsible AI framework.
  1. Garante per la protezione dei dati personali, final decision against OpenAI, 2 November 2024 (published 20 December 2024), €15 million fine.
  1. European Data Protection Board, Opinion 28/2024 on AI and GDPR, December 2024.
  1. Privacy and Other Legislation Amendment (Relevance and Protection) Act 2024 (Cth).
  1. Ibid., Schedule provisions on statutory tort for serious invasions of privacy.
  1. Ibid., automated decision-making transparency requirements, Schedule 3, effective 10 December 2026.
  1. Ibid., enhanced OAIC enforcement powers.
  1. Ibid., strengthened APP 11.
  1. OAIC, "Guidance on Privacy and Developing and Training Generative AI Models" and "Guidance on Privacy and the Use of Commercially Available AI Products," 21 October 2024.
  1. Clearview AI Inc v. Australian Information Commissioner [2023] AATA 1069 (8 May 2023), affirming the OAIC's October 2021 determination.
  1. Bartz v. Anthropic PBC, No. 24-cv-05417-WHA (N.D. Cal., 23 June 2025); Kadrey v. Meta Platforms, Inc., No. 23-cv-03417-VC (N.D. Cal., 25 June 2025); Thomson Reuters Enterprise Centre GmbH v. ROSS Intelligence Inc., D. Del.
  1. In Re: OpenAI, Inc. Copyright Infringement Litigation, No. 1:25-md-03143 (S.D.N.Y.), consolidated April 2025; Judge Stein's ruling of 26 March 2025 denying motions to dismiss; January 2026 discovery order.
  1. Getty Images (US), Inc. v. Stability AI Ltd [2025] EWHC 2863 (Ch) (4 November 2025).
  1. Andersen v. Stability AI, Inc., No. 3:23-cv-00201-WHO (N.D. Cal.), August 2024 ruling; trial set for 8 September 2026.
  1. Bartz v. Anthropic PBC, settlement of approximately $1.5 billion, 26 August 2025.
  1. Attorney-General Michelle Rowland, announcement of 26 October 2025, rejecting text and data mining exception.
  1. Productivity Commission, Final Report: Harnessing Data and Digital Technology, 19 December 2025.
  1. Joint Statement on AI in Legal Practice, issued 6 December 2024 by NSW Law Society, Victorian Legal Services Board and Commissioner, and WA Legal Practice Board.
  1. ACT Law Society, guidance on generative AI use.
  1. Valu v. Minister for Immigration and Multicultural Affairs (No 2) [2025] FedCFamC2G 95.
  1. Fair Work Commission President Justice Adam Hatcher, speech to Victorian Bar Association, early 2026.
  1. Damien Charlotin, database of AI hallucination cases, HEC Paris, tracking 486 cases by late 2025.
  1. Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y., 2023); Noland v. Land of the Free (Cal. App., 2025); Johnson v. Dunn (N.D. Ala., July 2025).
  1. AHPRA, "Meeting Your Professional Obligations When Using Artificial Intelligence in Healthcare," late 2024.
  1. Bloomberg, TechRadar, and industry press reporting on corporate AI bans, May–June 2023.
  1. UpGuard, survey of 1,500 workers across US, UK, Canada, Australia, NZ, Singapore, India, November 2024.
  1. Ibid.
  1. CybSafe and National Crime Agency (UK), late 2024, survey of 7,000 employees.
  1. H. L. A. Hart, The Concept of Law (Oxford: Oxford University Press, 1961), Chapter VII.
  1. "The Open Texture of 'Algorithm' in Legal Language," AI & Society (Springer, 2024).
  1. Helen Nissenbaum, "Privacy as Contextual Integrity," Washington Law Review 79, no. 1 (2004): 119–158; Helen Nissenbaum, Privacy in Context: Technology, Policy, and the Integrity of Social Life (Stanford: Stanford University Press, 2010).
  1. Helen Nissenbaum, keynote for Good Systems, University of Texas at Austin, 2024, on "Contextual Integrity Up and Down the Data Food Chain."
  1. Cyber Security Act 2024 (Cth), Royal Assent 29 November 2024.
  1. OAIC determinations: Commissioner initiated investigation into Clearview AI, Inc. (October 2021); Commissioner initiated investigation into Bunnings Group Limited (November 2024); Commissioner initiated investigation into Kmart Australia Limited (August 2025).
  1. Department of Industry, Science and Resources, National AI Plan, 2 December 2025.
  1. OAIC, Australian Community Attitudes to Privacy Survey, August 2023.
  1. ACCC, Digital Platform Services Inquiry Consumer Survey, October–November 2024.
  1. European Commission, "Digital Omnibus" proposal, November 2025.
  1. NIST, AI Risk Management Framework 1.0, 26 January 2023; supplemented by AI 600-1 Generative AI Profile, July 2024.
  1. Getty Images (US), Inc. v. Stability AI Ltd [2025] EWHC 2863 (Ch).
  1. Cyberhaven, longitudinal data: 10.7% (early 2023), 27.4% (early 2024), 34.8% (2025), 39.7% (early 2026).
  1. Diane Vaughan, The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA (Chicago: University of Chicago Press, 1996).
  1. UpGuard, November 2024.
  1. Langdon Winner, "Do Artifacts Have Politics?" Daedalus 109, no. 1 (Winter 1980): 121–136.
  1. Privacy Commissioner Carly Kind, announcement regarding Clearview AI enforcement, August 2024.