Part II

A Paradigm Shift in Tech Governance

Why individual data rights and top-down regulation both fall short, and what a Right of Digital Association would do instead.

4,956 words · 23 min

Information asymmetry is power

Familiar accounts of digital harms tend to emphasize privacy and the exploitation of individual users. Many of those concerns are warranted. But as Part I argued, AI and the digital economy should default to treating families and human scale communities as the base units of digital society because human flourishing depends on those shared social contexts.

Viewed from the lens of family and association, the problem is not just that tech corporations face adverse incentives to sacrifice individual safety and wellbeing for short-term commercial benefit. Tech firms often have strong incentives to design sociotechnical systems that optimize for individual preferences, engagement, and behavioral manipulation which effectively hijack or replace organic human social organization and self-governance. Regardless of intent, the result is widespread atomization of individuals from their families and communities and further entrenchment of the tech sector’s asymmetric power over isolated individuals and weakened human communities.

Policy efforts to counter some negative consequences to individual privacy from asymmetric data collection and use tend to focus on giving users more rights to be informed about how their data is used and to decline services on an individual basis. But such efforts, even where they have resulted in greater individual choice, have done little to curb the tech industry’ antisocial business practices.

Because atomized individuals often lack social cohesion, as well as effective mechanisms for coordinating action and setting rules governing their digital affairs, they naturally default to whatever norms are reinforced by the digital products or services they use. Digital consumer products and services are often inherently atomizing since consent and use is mostly governed by terms set by the tech company to which individual users must either “consent” or forfeit participation in the digital economy. While social media platforms may allow individuals to “connect,” “follow,” or create “groups” with others, the platforms frequently do not generally afford meaningful rights of data co-governance to online groups. Any “pro-social” affordances exist for the larger purpose of monetizing user behavior and data.

Generative and agentic AI pose similar challenges for effective co-governance of sociotechnical systems. When a data subject interfaces with an AI chatbot or agent, those systems are generally designed to reduce “friction” in generating answers, completing tasks, and automating decisions. But maximizing efficiency and “frictionless” productivity are often in direct tension with the iterative, social processes and shared norms necessary to produce quality work and preserve human agency. Individuals left to merely react to whatever an AI spits out have little real decisional power and are largely at the mercy of the AI and whatever value set or objective its developer or deployer embeds.

Platforms and AI companies gain asymmetric power and value from the one-sided terms of data collection and use they impose on their users. This leads to a collective action problem on the part of data subjects. Even though many individuals and communities share concerns about privacy, manipulation, and surveillance, these concerns are systematically ignored by market dynamics—to the great advantage of tech monopolists—when individuals are socially atomized and pitted against default choice architectures and immersive information environments designed to keep them structurally disempowered.

As Part I argued, data is normally co-produced, not only between individuals and the digital services they interact with, but by individuals interacting with each other in various online and offline contexts. Asymmetric data collection and use schemes put communities at a massive structural disadvantage because while individuals may consent to unilateral informational capture, data is most useful to tech companies when it reveals peoples' natural similarities and social interconnectedness.1

When a user discloses something about him or herself, the platform learns not only about the user, but also, probabilistically, about everyone similar to that person, and everyone connected to them online or in their community.2 For example, if a single mother living in the Bronx purchases a certain brand of orange juice, chances are that other women who share similar preferences, characteristics, and socioeconomic backgrounds will too.3 This is not a “coincidence,” but a reflection of the fact that people causally influence one another, and are influenced by common causes. While an individual can be easily induced to disclose personal or behavioral data to a digital service, that information often includes information about the communities and institutions to which that individual belongs. In other words, larger communal interests are often impacted even when an individual user “consents” to data collection or use.

Sharing data with tech companies is thus not just an individual privacy risk, but a means by which social, political, and economic power is captured and accumulated. The largest services, with their huge user bases and growing depth of digital intelligence, now aided by AI’s vast qualitative analytical capabilities, systemically accrue an outsized advantage in predicting and influencing our thoughts and behaviors, in order to cement their dominant market positions.4

Thepower accrued by commercial data entities is not the result of a simple or conventional market process. It cannot be analogized to the exchange of physical or financial goods that ground our canonical understanding of mutually beneficial market transactions. As Part I argued, conventional analog markets have generally established rules for ensuring the equitable distribution of governance rights when value is co-produced or owned by multiple parties. Digital markets, by contrast, have ill-defined rules for distributing governance rights among human co-producers and lack mechanisms for data subjects to secure collective privacy, control, and economic interests.

Normally, some form of liability and disclosure would solve for the co-governance challenge by ensuring that parties to a transaction could sue or bargain to distribute benefits or mitigate harms. The challenge here is that in many cases, data co-producers are not direct parties to the transactions in which their data, or outputs derived from it, are monetized. The negative social costs to individuals and communities often occur in the aggregate and not as the result of any one transaction. Consequently, normal legal mechanisms are of little help in disciplining tech firms and other commercial data interests.

In some cases, collective and individual interests exist in tension. When this occurs, rules are needed to ensure that interests are fairly represented and balanced. Part I argued that the base unit of digital society ought to be families and human associations rather than atomized individuals. That is, in part, because interests understood purely in terms of individual preferences are less conducive to human flourishing compared to the shared preferences and norms baked into the social fabric of family, work, and civil society.

Since data is almost always a co-produced good, it is difficult to assign governance over its collection and use, based solely on individual rights. If Joe gives up his DNA to AncestryDNA.com which then sells that data to a pharmaceutical company that targets Joe and his family members with ads for a diabetes treatment (based on the pharma company’s use of the data to predict that Joe’s family members are at higher risk for the disease), Joe is not the only party affected. Other members of his family who did not consent are also targeted. Perhaps Joe and even his family are unbothered by the targeted diabetes ads. However, that same information could just as easily inform a health or mortality score that directly affects their access to essential services (like health insurance, medical treatments, employment, or other benefits) without Joe or his other family members ever knowing it.

At the same time, the power asymmetries between tech firms and users mean that individual data subjects are highly susceptible to manipulation by commercial data interests. Even in situations where individuals are not manipulated, they may face incentives pushing them to act in ways that undermine their long-term rational interests as well as the interests of their families and larger social contexts. An individual might be nudged to trade sensitive personal information and behavioral data to receive subsidized services or a modest payment. But doing so unilaterally, without accounting for the shared norms and interests of the individual’s family, church, business, and other overlapping communities, risks undermining the welfare of those other subsidiary institutions.

The harms identified by this proposal are structural and therefore require structural remedies. Accordingly, this proposal does not take aim at specific digital harms, but instead at the background conditions that make the myriad harms that feature in the current digital landscape so costless for large data collectors to perpetrate, and so difficult for ordinary people to avoid. To be clear, this is not to suggest that addressing informational power asymmetry between large technology platforms and their individual users will by itself remedy all digital harms. However, it does address an important precondition to harm: powerlessness. The power imbalance inherent in our information exchanges prevent people from exercising (collective) counter power to discipline against harm. We cannot know what conditions of informational exchange people would freely agree to under conditions of equal power to set those conditions because we have never done so. The goal of granting community-level rights to set those conditions is, in one sense, to find out what those terms are for the rich diversity of communities that make up American life.

Why bolstering individual data rights fails

Individual approaches to data privacy and consumer choice overwhelmingly fail to counteract this market failure for at least three reasons.

First, as already noted, every time a user clicks “agree” on a terms of service policy, they are effectively giving up any claim upon to the information they subsequently convey, even though it is impossible to understand or predict what will be done with it, now or especially in the future.5 But much more insidiously, they also undermine the interests of others in their communities—other data subjects whose characteristics, skills, knowledge, or biography overlaps with the individual signing away their rights. Moreover, once an individual signs away his or her rights, others are likelier to follow suit since their privacy or other related interests have already been compromised. This results in a race to the bottom where tech corporations that offer immediate convenience can count on individuals to hand over information that gives the corporation yet more power and leverage—not only over the individual they are serving, but over many other people as well.

Second, because any particular datum or dataset frequently becomes vastly more powerful and valuable when combined with other data, individuals acting as individuals have little or no leverage to secure fairer terms. Generally, the larger the group of data subjects in a dataset, the more valuable the data is, and the more it is possible to reason about its possible downstream value and uses.6 This gives rise to network effects and strategic complementarities.7 As a result, data from a single individual has very limited value and commands far less bargaining power compared to the data of a large group.8 Yet, large groups are unable to coordinate their consumer behavior or disclosure decisions. The power and value that individual consumers lose from this inability to coordinate with others is, in effect, signed over to tech services, who unlock the power and value of combining information from many individuals — yet use that power toward unaccountable and misaligned ends.

Finally and relatedly, the true social and economic costs of consumer data extraction are obscured and often delayed. Individuals acting alone tend to “prefer” immediate convenience and payoffs to themselves, and have difficulty accounting for the long-term effects on their families, and their communities.9 This is a digital tragedy of the commons, where individuals face strong incentives to deplete familial and communal resources in exchange for immediate benefits, a vicious cycle exacerbated by data-hungry generative AI.10

This means that the data practices of powerful private technology companies are insufficiently disciplined by either the market or by regulators. Sometimes technology companies, recognizing this, “invite” more regulation, but this apparent gesture of good faith tends to double as a bid for regulatory monopoly.11

Consider, for example, five people who individually “consent” to allow apps to share their geo-location data with commercial vendors. Now whenever any one of them gets within fifty feet of a church, every entity paying for their data has an electronic record of their religious activities. But in addition, data brokers are combining their individual geo-location histories to infer commercially valuable insights about them and others like them. Suppose that each of the five individuals attend the same church. Data brokers and anyone paying them now knows that too. From those traces, more patterns can be inferred from additional information. They might infer, for example, that since the five individuals all attend a church known for its outspoken conservative preaching, there is a high likelihood that they are Republicans–which is confirmed from their voting records identified and analyzed in seconds by an AI.

Because the data brokers are able to obtain each individual’s geo-location data, they know where else they go. They know, for instance, if each individual attends a political rally, perhaps for a controversial political figure. Brokers and tech firms know when each individual visits the grocery store, where they live, and how much time they spend around their kids. Indeed, since other family members have also consented to being tracked, tech companies know which room each family member is in, at what time of day, and can even infer what they are likely doing, watching, reading, looking, speaking with, or listening too. Combined with each person’s search data, social media engagement data, and other information obtained through individual consent, any advertiser or tech company now has the capability to digitally profile any household or community for any reason.

To be sure, this is creepy and fundamentally problematic in terms of enabling government surveillance. During the COVID-19 pandemic, a California county and the federal government utilized information obtained from consumer data brokers to monitor lock-down compliance and crack down on religious gatherings. But setting aside government use, other family and communal interests are jeopardized.

Part I argued that data subjects are harmed by asymmetric data collection and use terms, because such policies inevitably allow data to be securitized in ways that: 1) undermine the privacy, control, and economic interests of data subject’s households and communities; 2) do harm to others in violation of co-producers’ conscientious objections; or 3) deny co-producers a fair share of the benefits.

In this example, data subjects suffer harm under all three prongs. The fact that nearly any government or corporation has the ability to comprehensively map their life patterns is a facial violation of both individual and communal privacy interests under prong one.

But their control interests are also violated since the information collected is used to nudge and shape their behaviors, especially their buying habits through endless subliminal messages and AI-tailored content. While one or two targeted ads might seem negligible, the power of these systems is the habit forming pressure they exert on individuals constantly over long periods of time. All those countless micro nudges, personalized ads, and AI profiling add up.

The insurance company suddenly charges higher premiums based on the “risky driving” patterns detected; household expenses start rising, as algorithmic prices change based on each individual’s predicted desperation and need; social media apps bombard family members with push notifications the moment the entire family sits down for dinner together; and after one data subject visits a counselor’s office, ChatGPT coaxes her into a protracted conversation about mental health and spirituality.

Prong two is similarly violated when tech firms and data brokers bundle that data and sell it to a shady political operative running an unethical social influence campaign to legalize online gambling and pot dispensaries. At the same time, all the revenues received from commercial brands purchasing the data accrues to the data brokers and tech firms that captured the data. The data subjects have no opportunity to receive a fair share of the benefits derived from their data, violating prong three.

This fairly mundane case study demonstrates two points. First, both individual and communal privacy, control, and economic interests are violated constantly, largely outside of our conscious awareness. Second, the sum total of information provided by multiple individuals conveys far more power and is more commercially valuable than any one of its parts. No single individual is capable of accounting for the full costs and benefits that accrue to tech and data companies from combining information across a multitude of data subjects with overlapping social contexts and relationships.

Even in situations where tech companies have taken a different approach, offering users some kind of democratic input, the input is typically toothless, nonbinding, and superficial. For example, in 2009 Facebook responded to controversy over its abuse of user data by allowing users to submit responses and vote on changes to platform data policies.12 But only a relatively small number of users participated in the limited policy votes and comment periods and it eliminated the scheme in 2012.13

Some bemoaned this as a failure of democratic platform governance, but the scheme failed for the same reasons that individual-based approaches to data privacy often do. The vast information asymmetries between Facebook and its users not only prevented the user base from understanding and judging the complex decisions, but also made it difficult for sensible new ideas to emerge.14 Users could only passively vote up or down on the options Facebook presented to them. They had no agency to craft and present their own policies.15 And the consequences of asymmetric information accrual are almost impossible to reason about in advance. In 2011, very few users could have foreseen the way that their Facebook data might eventually be incorporated into today’s hyper-capable large language models.

It is entirely natural that individuals, when directly consulted on the details, fail to engage productively with questions of privacy and information value. People have limited time and are rightly focused mostly on understanding things they can control, and nourishing the things closest to them–their property, families, workplaces, and human scale communities in which they have a tangible stake. Almost all lack the awareness, time, and expertise needed to propose or evaluate complex digital terms of service, and they do not bother to when they know they have no leverage over them anyway.16 When people do not understand the uses and risks associated with disclosure, and/or have no leverage, observed consent may reflect framing, defaults, social pressures, short term incentives, and transaction costs — not stable or considered preferences.17

Why top-down data privacy regimes often fall short

At the same time, no top-down, technocratic regulatory scheme can address the full range of problems that information asymmetries create.18 There are simply too many ways that asymmetric information can be used—bad, good, and neutral, and hard to foresee—for any regulator to comprehensively arbitrate between them in advance.19 Recent attempts by European regulators to protect data privacy and combat dark patterns on large internet platforms through measures like the General Data Protection Regulation (GDPR) and Digital Services Act (DSA) have met with mixed success.20 Even the best-designed technocratic regulations may fail to keep pace with platforms and algorithmic tools that are opaque, complex, and rapidly evolving.

Technocratic regulations also tend to overlook the pluralistic values and interests of families and human scale communities. What counts to one community as a reasonable application of insight to improve service might violate the innermost values and religious conscience of another. For example, a given community of users (data or information subjects) might consider “freemium” access to ChatGPT or Amazon Video worthy of allowing their data to be used to serve up personalized, targeted ads. But in agreeing to those terms, they may “teach” the digital services about the characteristics and preferences of others who find this exchange profoundly objectionable.. Top-down regulations can only dictate a one-size-fits-all approach from 10,000 feet. They do not empower different social groups to negotiate very different arrangements with the platforms and work out complex compromise arrangements between themselves.

Introducing the Right of Digital Association

Redirecting the digital economy toward the common good requires extending the logic of federalism, subsidiarity, and the freedom of association to our digital spaces by recognizing a new Right of Digital Association. Like collective bargaining rights for U.S. workers, the Right of Digital Association would be held by individuals but exercisable only in concert with others.21 Thus, the distinctive interests that this right protects could not be signed away in an individual terms-of-service update or a gig worker agreement.

Instead, the Right of Digital Association would enable Americans to form and join private non-stock organizations called data rights associations (DRAs), to negotiate group terms with tech companies (data counterparties) governing the collection, use, and economic value derived from their data. DRAs, in turn, would be responsible and empowered to uphold three pillars of the Right of Digital Association:

  • Privacy: a community should have real and effective mechanisms to prevent or limit information collection and use, and to safeguard community information against commercial surveillance or public leaks.

  • Control: a community should have a meaningful say over how its information is used downstream, including whether that information is used in the development or deployment of systems that are contrary to the community’s interests and values.

  • Fair value: a community must share fairly in any downstream economic value that its data disclosures help create.

These pillars, which DRAs are empowered to secure in negotiation with data counterparties, constitute associational data rights. Together they secure the full breadth of social and economic interests of individuals within their digital communal spheres.

Because these interests are contextually dependent and often need to be balanced against one another, the exact extent and requirements of the three pillars of associational data rights resist strict codification.22 The terms a DRA will secure are generally not rules or hard entitlements that statute could fix in advance but instead reflect negotiated equitable arrangements: concessions and limitations that take their shape from the values and circumstances of the communities and counterparties involved. The English common law distinction between law and equity recognized that some interests are important enough to warrant protection yet too contextual to be reduced to fixed rules. The privacy, control, and fair value pillars are likewise vital interests of individuals and communities, which are being trampled under the status quo, and which warrant firm protection, yet also require flexibility and context sensitivity. Striking a sensible balance requires new associational mechanisms that enable otherwise atomized individuals to bargain as communities..

Digital subsidiarity is the key to healthier families, a richer culture, and better technology

When individuals stand alone, they are susceptible to manipulation and control by concentrated government or corporate power. Early observers like Alexis de Tocqueville as well as modern theorists like Robert Nisbet note the importance of civic associations and communities in mediating the practice of republican self-governance.23 The American system’s particular genius is that it protects the individual indirectly—not by making individual citizens directly dependent on the state, as other nations have often done, but by extending support to families and communities, and upholding the freedom to associate by forming congregations, schools, professional societies, and civic bodies. These intermediate social groups are the heart of American democracy that Tocqueville prized. They are also the intermediary institutions celebrated by Catholic social teaching under the name of subsidiarity.24

Striking a blow at the core of our national strength and distinctiveness, the digital economy has eroded this middle layer of American society. Big Tech now mediates how we communicate, worship, raise our children, socialize, and learn.25 Tech corporations are displacing associational life and threatening the transmission of skills, values, and culture to the next generation.26 Pope Leo XIV, in his recent encyclical on AI, specifically underlined the principle of subsidiarity as part of the solution to the moral crisis of digital society, noting that “[s]tates and transnational institutions are called to ensure fair rules and effective safeguards, so that local communities, intermediary organizations, schools, universities, religious institutions and associations have a voice and can contribute to the discernment of choices that affect people’s daily lives, such as employment, access to services, data management and digital environments.”27 (Emphasis added).

The associational data rights envisioned by this paper would restore subsidiarity to our digital spaces by enabling intermediary institutions to organize and coalesce into DRAs. These new representatives of associational life would, in turn, provide a governance layer that empowers families and communities to engage with AI and digital platforms on their own terms.

For example, a domestic privacy-focused DRA could emphasize that digital or networked appliances deployed in members’ homes, like thermostats, cameras, refrigerators, kitchen aids, voice assistants, “smart” mattresses, etc., should meet privacy-by-design standards.28 DRAs focused on children’s welfare might mobilize against tech companies using kids’ data for targeted advertising, or in favor of specific new parental controls for smartphones, social media apps, and AI chatbots. They might also pressure data counterparties from feeding into AI interactions that undermine parental prerogatives, addict children, or displace human relationships.

Authors could form DRAs to negotiate terms with tech companies to ensure that AI systems fairly cite their works, pay fair compensation, and otherwise uphold associational data rights that go beyond traditional IP assertions.29 Contractors and gig workers could form DRAs to prevent their ideas and labor from being permanently extracted wholesale by exploitative short-term paymasters and gig platforms.30 Likewise, a free speech and civil liberties DRA might protect political groups organized on social media platforms by negotiating a digital bill of rights to prevent arbitrary censorship or content suppression, and to provide members with the ability to appeal such decisions by platforms.31

Faith-based organizations could also form DRAs to empower adherents to align their digital lives with embodied religious and social mores. For example, a faith-based DRA might negotiate terms requiring tech platforms and consumer AI systems to interface with select third-party middleware or AI tools that reflect core moral virtues such as prudence, justice, fortitude, and temperance. Rather than continuing to outsource moral formation and human thought to Big Tech companies, DRAs could empower faith communities to play an active role in digital governance.

These are just a handful of the possible associational forms that could take shape. The key virtue of DRAs is that they would allow communities sufficient power to negotiate the terms shaping their digital lives with a high degree of adaptability. This approach avoids the twin pitfalls of toothless individual rights, and brittle top-down regulation.

We believe that the Digital Right of Association responds to the politics of those who are rightly alarmed about where AI and concentrated power in the technology sector is leading society. But far from reactive “doomerism,” associational data rights would place technology in service of America’s families and the common good. A technology-driven economy that rends our social fabric will eventually exhaust the very wellspring on which it feeds. By contrast, a technology-driven economy that responds to the will of families and communities, as represented by an empowered ecosystem of intermediary associations, will promote human flourishing, enrich future generations.

How Data Rights Associations work

This proposed right of digital association, exercised through membership in Data Rights Associations (DRAs), is not so much a novelty in American law as a new variation on an old principle. U.S. law has long recognized that some asymmetries of bargaining power cannot be cured by individual rights alone.32 The Capper-Volstead Act of 1922 let farmers bargain with grain buyers via cooperatives.33 In 1897, Congress created performance rights, but most performing artists were unable to defend them on their own.34 As a result, collective performing rights organizations became the chief mechanism for individual performing artists to band together and protect their rights.35 These arrangements were controversial when proposed, but have become part of ordinary American life. While never perfect, they served to protect core but threatened parts of American society—namely recording art and smallhold farming—that the legal regime might otherwise have let wither.

DRAs follow the same template. They create new rights corresponding to vital social interests, and aggregate the bargaining authority of their members. They relieve individual members—data subjects and content providers—of the impossible task of digesting, comprehending, and negotiating terms across the many digital services that now mediate modern life, but instead allow them to choose a suitable and accountable representative to do so.

Once DRAs have been formed, data principals simply join or associate with one or several (non-conflicting) DRAs by opting in. DRAs would then act as associational data rights fiduciaries, by negotiating concessions for members as a block, and holding data counterparties accountable for abiding by the established terms.36 They would allow communities to influence how data counterparties interface with community members; and secure for them a fair share of the value (whether revenue, profit, or equity) they help generate downstream.

Data counterparties would bear the burden of ensuring that they are respecting DRA members’ associational data rights. At the point of data collection, and then once again the point of exploiting data (“productization”), they would be responsible for ensuring that they have secured agreements with DRAs which are sufficient to release their obligations both to users whose co-created data has been collected, and to non-users whose associational data rights are nonetheless impacted. While certainly requiring important concessions and changes in behavior, these obligations will not place an unmanageable burden upon data counterparties. Their burdens to secure agreements with DRAs will be subject to equitable tests of reasonableness, and small DRAs will not have general veto powers. See the following section and appendices for a more detailed sketch.

DRAs would not amount to a new one-to-many regulatory scheme, but rather a restoration of the digital economy to something more closely resembling a genuine market, in which the people who co-produce the data that powers digital products have a meaningful say in what they give away and what they receive in return.

Footnotes

  1. Sadoun, See video presentation (2025).

  2. Salome Viljoen, A Relational Theory of Data Governance,131 Yale Law Journal (2021); Alicia Solow-Niederman, Information Privacy and the Inference Economy, 117 Nw. U. L. Rev. 357 (2022).

  3. Sadoun, See video presentation (2025).

  4. Tim Wu, Age of Extraction (2026); Information asymmetries also sustain and reinforce monopoly power. See Rory van Loo, Nikita Aggarwall, Amazon’s Pricing Paradox (2023).

  5. Moshe Y. Vardi, To Regulate Tech, Nullify Click-Through Contracts, Comm. ACM, Sept. 2023, at 5, https://cacm.acm.org/opinion/to-regulate-tech-nullify-click-through-contracts/.

  6. Gartner (2011) see also OECD: Measuring the Economic Value of Data and Cross-Border Data Flows (2020) (pp 20-21 discussing additional features of data that contributes to data’s non-rivalrousness and scalability that contribute to value).

  7. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5933836.

  8. Nicholas Vincent, Brent Hecht & Shilad Sen, Data Strikes: Evaluating the Effectiveness of a New Form of Collective Action Against Technology Companies, in Proceedings of the World Wide Web Conference (WWW '19) 1931 (2019); Imanol Arrieta-Ibarra, Leonard Goff, Diego Jiménez-Hernández, Jaron Lanier & E. Glen Weyl, Should We Treat Data as Labor? Moving Beyond "Free," 108 AEA Papers & Proc. 38 (2018); Eric A. Posner & E. Glen Weyl, Radical Markets: Uprooting Capitalism and Democracy for a Just Society ch. 5 (2018); Daron Acemoglu, Ali Makhdoumi, Azarakhsh Malekian & Asuman Ozdaglar, Too Much Data: Prices and Inefficiencies in Data Markets, 14 Am. Econ. J.: Microeconomics 218 (2022); Nicholas Vincent, Matthew Prewitt & Hanlin Li, Collective Bargaining in the Information Economy Can Address AI-Driven Power Concentration (2025), https://arxiv.org/abs/2506.10272.

  9. Daniel J. Solove, Privacy Self-Management and the Consent Dilemma, 126 Harv. L. Rev. 1880 (2013).

  10. For an extended treatment of the structure and problem of knowledge commons, see Brett M. Frischmann, Michael J. Madison, and Katherine J. Strandburg (eds), Governing Knowledge Commons (New York, 2014; online edn, Oxford Academic, 20 Nov. 2014); see also Makridis, Christos A., and Joshua Ammons. (2025). Reinventing Intellectual Property Rights Protection in an Era of Generative AI: The Synergy of Polycentric Governance and Blockchain Technology. Journal of Institutional Economics, 21.

  11. E.g., https://www.bbc.com/news/world-us-canada-47762091, https://openaiglobalaffairs.substack.com/p/keeping-america-out-in-front-on-ai?r=4a2ejy

  12. Michael Phillips, The End of the Facebook Democracy, BuzzFeed News (Nov. 22, 2012), https://www.buzzfeednews.com/article/mtpiii/the-end-of-the-facebook-democracy.

  13. Ibid.

  14. Ibid.

  15. Ibid.

  16. Alexander Orlowski & Wulf Loh, Data Autonomy and Privacy in the Smart Home: The Case for a Privacy Smart Home Meta-Assistant, 40 AI & Soc'y 4171 (2025).

  17. https://www.journals.uchicago.edu/doi/10.1086/671754.

  18. F.A. Hayek, The Use of Knowledge in Society, 35 Am. Econ. Rev. 519 (1945).

  19. Alicia Solow-Niederman, Information Privacy and the Inference Economy, 117 Nw. U. L. Rev. 357 (2022).

  20. Garrett Johnson, Economic Research on Privacy Regulation: Lessons from the GDPR and Beyond (Nat'l Bureau of Econ. Rsch., Working Paper No. 30705, Dec. 2022), https://www.nber.org/system/files/working_papers/w30705/w30705.pdf; And Polona Car, Regulating Dark Patterns in the EU: Towards Digital Fairness, Eur. Parliamentary Rsch. Serv., PE 767.191 (Jan. 2025), https://www.europarl.europa.eu/RegData/etudes/ATAG/2025/767191/EPRS_ATA(2025)767191_EN.pdf.

  21. National Labor Relations Act, 29 U.S.C. §§ 151–169 (2018).

  22. Helen Nissenbaum, Privacy in Context: Technology, Policy, and the Integrity of Social Life (2010).

  23. Alexis de Tocqueville, Democracy in America (1835); Robert Nisbet, Quest for Community (1953).

  24. Pope Pius XI, Quadragesimo Anno 79–80 (1931).

  25. See Part I’s treatment of antisocial tech and its effects on family and community.

  26. Ibid.

  27. Pope Leo XIV, Magnifica Humanitas 72 (2026) (“In this context [of AI and the digital revolution], States and transnational institutions are called to ensure fair rules and effective safeguards, so that local communities, intermediary organizations, schools, universities, religious institutions and associations have a voice and can contribute to the discernment of choices that affect people’s daily lives, such as employment, access to services, data management and digital environments. When it comes to decisions regarding economic flows and digital platforms, as well as the governance of data and algorithms, we cannot allow a handful of actors to dictate these processes on their own; instead, we must build forms of cooperation that respect the various levels of the global community and make them jointly responsible for the common good”.)

  28. Surfshark, Smart Home Privacy Checker Insights (last visited June 25, 2026), https://surfshark.com/research/smart-homes/insights.

  29. Marina Adami, Inside the News Industry's Efforts to Join Forces to Defend Its Journalism from AI Companies, Reuters Inst. for the Study of Journalism (May 19, 2026), https://reutersinstitute.politics.ox.ac.uk/news/inside-news-industrys-efforts-join-forces-defend-its-journalism-ai-companies.

  30. Damion Jonathan Bunders et al., The Feasibility of Platform Cooperatives in the Gig Economy, 10 J. Coop. Org. & Mgmt. 100167 (2022).

  31. Creators Bill of Rights (draft resolution), Off. of Rep. Ro Khanna, https://khanna.house.gov/sites/evo-subsites/khanna.house.gov/files/evo-media-document/creator-bill-of-rights-resolution-draft-2.0-clean-55.pdf (last visited June 30, 2026).

  32. Sherman Act, 15 U.S.C. § 1 et seq. (1890).

  33. Capper-Volstead Act of 1922, 7 U.S.C. §§ 291–292.

  34. Act of Jan. 6, 1897, 54th Cong., 2d Sess., 29 Stat. 481; U.S. Dep't of Justice, Antitrust Div., Antitrust Consent Decree Review: ASCAP and BMI 2019 (2019).

  35. Ibid.

  36. Jack M. Balkin, The Fiduciary Model of Privacy, 133 Harv. L. Rev. F. 11 (2020).