What a system may learn and apply.
First, ask yourself
“Do users of your system authorize what it learns from them and how it applies it?”
Mission statement
🫡Ensure users decide what the system learns from them and how learned behavior is applied.
Key heuristics → Learning Consent
🚀- Learning from user data must be treated as authority delegated by the user.
- Users must know what the system learns from them and for what purpose.
- The scope of learning must be explicit: which data, which features, and for how long.
- Consent rigor must increase with the sensitivity of what is learned.
- Learned behavior must not drive consequential actions without separate authorization.
- Users must be able to inspect and correct what the system has learned about them.
- Withdrawing consent must remove learned data and behavior without loss of user work.
- The scope of learning must not broaden without renewed consent.
- Inferred preferences must remain subordinate to explicit user instructions.
Executive brief
☝️AI systems must learn from users, and act on what they learn, only within consent users can review and revoke.
Core questions → Learning Consent
🤔“What has the system learned from users, and did they agree to it?”
“Can users see it, correct it, or make the system forget it?”
Focus areas
Delegation-first
“What is the system learning without being asked?”
“Which learned behaviors act without explicit confirmation?”
Scope-aware
“Which data and features does learning cover?”
“Is consent global or limited to a specific context?”
Change-aware
“What happens to learned behavior when users withdraw consent?”
“Can learning be paused without losing core functionality?”
AI-aware
“Is inferred intent being treated as permission?”
“Does learning expand authority without explicit approval?”
🧬 UX directives → Learning Consent
Directive92/01
Treat learning from users as delegated authority.
Require explicit consent before user data shapes system behavior.
Directive92/02
Make learning consent clear and comprehensible.
Explain what is learned, from which data, and for what purpose.
Directive92/03
Expose the scope of learning.
Indicate which data, features, and time periods learning covers.
Directive92/04
Scale consent rigor with sensitivity.
Require stronger acknowledgment for learning from personal or high-impact data.
Directive92/05
Separate learning from acting.
Require distinct authorization before learned behavior drives consequential actions.
Directive92/06
Make learned behavior inspectable and correctable.
Allow users to see and edit what the system has learned about them.
Directive92/07
Ensure learning can be withdrawn.
Remove learned data and behavior when users revoke consent, without loss of their work.
Directive92/08
Prevent silent scope expansion.
Require renewed consent if learning extends to new data or purposes.
Directive92/09
Do not treat inference as instruction.
Keep inferred preferences subordinate to what users explicitly state.
Executive summary
⚡- Learning Consent treats learning from users as delegated authority, not a by-product of use.
- It requires explicit, comprehensible consent before user data shapes system behavior.
- The system must make the scope, purpose, and sensitivity of learning clear.
- Learning and acting on what was learned must be authorized separately.
- Users must be able to inspect, correct, and withdraw what the system has learned.
- Learning Consent succeeds when system adaptation remains fully subordinate to explicit user intent.
Success indicators
😎- Users know what the system learns from them.
- Learning occurs only after explicit consent.
- Users can see and correct what the system has learned.
- Withdrawing consent removes learned data and behavior.
- Changes to the scope of learning require renewed consent.
One-line summary
☝️Before a system learns from users, users must choose what it may learn.