-
Participatory AI: A Scandinavian Approach to Human-Centered AI
Authors:
Niklas Elmqvist,
Eve Hoggan,
Hans-Jörg Schulz,
Marianne Graves Petersen,
Peter Dalsgaard,
Ira Assent,
Olav W. Bertelsen,
Akhil Arora,
Kaj Grønbæk,
Susanne Bødker,
Clemens Nylandsted Klokmose,
Rachel Charlotte Smith,
Sebastian Hubenschmid,
Christoph A. Johns,
Gabriela Molina León,
Anton Wolter,
Johannes Ellemose,
Vaishali Dhanoa,
Simon Aagaard Enni,
Mille Skovhus Lunding,
Karl-Emil Kjær Bilstrup,
Juan Sánchez Esquivel,
Luke Connelly,
Rafael Pablos Sarabia,
Morten Birk
, et al. (23 additional authors not shown)
Abstract:
AI's transformative impact on work, education, and everyday life makes it as much a political artifact as a technological one. Current AI models are opaque, centralized, and overly generic. The algorithmic automation they provide threatens human agency and democratic values in both workplaces and daily life. To confront such challenges, we turn to Scandinavian Participatory Design (PD), which was…
▽ More
AI's transformative impact on work, education, and everyday life makes it as much a political artifact as a technological one. Current AI models are opaque, centralized, and overly generic. The algorithmic automation they provide threatens human agency and democratic values in both workplaces and daily life. To confront such challenges, we turn to Scandinavian Participatory Design (PD), which was devised in the 1970s to face a similar threat from mechanical automation. In the PD tradition, technology is seen not just as an artifact, but as a locus of democracy. Drawing from this tradition, we propose Participatory AI as a PD approach to human-centered AI that applies five PD principles to four design challenges for algorithmic automation. We use concrete case studies to illustrate how to treat AI models less as proprietary products and more as shared socio-technical systems that enhance rather than diminish human agency, human dignity, and human values.
△ Less
Submitted 10 June, 2026; v1 submitted 16 September, 2025;
originally announced September 2025.
-
A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them
Authors:
Midas Nouwens,
Janus Bager Kristensen,
Kristjan Maalt,
Rolf Bagge
Abstract:
Online tracking remains problematic, with compliance and ethical issues persisting despite regulatory efforts. Consent interfaces, the visible manifestation of this industry, have seen significant attention over the years. We present robust automated methods to study the presence, design, and third-party suppliers of consent interfaces at scale and the web service consent-observatory.eu to do it w…
▽ More
Online tracking remains problematic, with compliance and ethical issues persisting despite regulatory efforts. Consent interfaces, the visible manifestation of this industry, have seen significant attention over the years. We present robust automated methods to study the presence, design, and third-party suppliers of consent interfaces at scale and the web service consent-observatory.eu to do it with. We examine the top 10,000 websites across 31 countries under the ePrivacy Directive and GDPR (n=254.148). Our findings show that 67% of websites use consent interfaces, but only 15% are minimally compliant, mostly because they lack a reject option. Consent management platforms (CMPs) are powerful intermediaries in this space: 67% of interfaces are provided by CMPs, and three organisations hold 37% of the market. There is little evidence that regulators' guidance and fines have impacted compliance rates, but 18% of compliance variance is explained by CMPs. Researchers should take an infrastructural perspective on online tracking and study the factual control of intermediaries to identify effective leverage points.
△ Less
Submitted 25 March, 2025;
originally announced March 2025.
-
Consent Management Platforms under the GDPR: processors and/or controllers?
Authors:
Cristiana Santos,
Midas Nouwens,
Michael Toth,
Nataliia Bielova,
Vincent Roca
Abstract:
Consent Management Providers (CMPs) provide consent pop-ups that are embedded in ever more websites over time to enable streamlined compliance with the legal requirements for consent mandated by the ePrivacy Directive and the General Data Protection Regulation (GDPR). They implement the standard for consent collection from the Transparency and Consent Framework (TCF) (current version v2.0) propose…
▽ More
Consent Management Providers (CMPs) provide consent pop-ups that are embedded in ever more websites over time to enable streamlined compliance with the legal requirements for consent mandated by the ePrivacy Directive and the General Data Protection Regulation (GDPR). They implement the standard for consent collection from the Transparency and Consent Framework (TCF) (current version v2.0) proposed by the European branch of the Interactive Advertising Bureau (IAB Europe). Although the IAB's TCF specifications characterize CMPs as data processors, CMPs factual activities often qualifies them as data controllers instead. Discerning their clear role is crucial since compliance obligations and CMPs liability depend on their accurate characterization. We perform empirical experiments with two major CMP providers in the EU: Quantcast and OneTrust and paired with a legal analysis. We conclude that CMPs process personal data, and we identify multiple scenarios wherein CMPs are controllers.
△ Less
Submitted 14 April, 2021;
originally announced April 2021.
-
Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence
Authors:
Midas Nouwens,
Ilaria Liccardi,
Michael Veale,
David Karger,
Lalana Kagal
Abstract:
New consent management platforms (CMPs) have been introduced to the web to conform with the EU's General Data Protection Regulation, particularly its requirements for consent when companies collect and process users' personal data. This work analyses how the most prevalent CMP designs affect people's consent choices. We scraped the designs of the five most popular CMPs on the top 10,000 websites i…
▽ More
New consent management platforms (CMPs) have been introduced to the web to conform with the EU's General Data Protection Regulation, particularly its requirements for consent when companies collect and process users' personal data. This work analyses how the most prevalent CMP designs affect people's consent choices. We scraped the designs of the five most popular CMPs on the top 10,000 websites in the UK (n=680). We found that dark patterns and implied consent are ubiquitous; only 11.8% meet the minimal requirements that we set based on European law. Second, we conducted a field experiment with 40 participants to investigate how the eight most common designs affect consent choices. We found that notification style (banner or barrier) has no effect; removing the opt-out button from the first page increases consent by 22--23 percentage points; and providing more granular controls on the first page decreases consent by 8--20 percentage points. This study provides an empirical basis for the necessary regulatory action to enforce the GDPR, in particular the possibility of focusing on the centralised, third-party CMP services as an effective way to increase compliance.
△ Less
Submitted 8 January, 2020;
originally announced January 2020.