Imagine asking an AI assistant to arrange dinner. It checks your calendar, reads a message from your partner, notices your friend's food allergy in an old email, and writes to the restaurant. One person asked for help. Several people have now entered the machinery.
We keep calling these systems personal assistants. That describes who owns the account, but not necessarily whose information they process, whose preferences they represent, or whose evening they can rearrange.
A new scoping review gives this problem a useful name: the single-user assumption. The assistant is organized around one primary user even when the job involves a household, coworkers, friends, meeting participants, recipients, or people who merely happened to be within range of a microphone.[1]
The review examined 58 studies and identified 118 risk instances. Its counts are a map of the research literature, not estimates of how often these problems happen in ordinary life. Still, the map is revealing. Other people entered an assistant through shared use, communication between users, shared infrastructure, information in the owner's files, and sensing in the surrounding environment.[1]
A contact is not a permission slip
The quietest route may be the most common. Give an assistant access to your inbox and you have also given it fragments of everyone who has written to you. A calendar contains other people's whereabouts. A group chat contains their jokes, arguments, plans, and typos made under conditions of reasonable optimism. A photo may contain faces that never pressed an upload button.
Traditional account privacy asks, "What may this service do with my data?" A capable assistant creates a harder question: "What may my assistant do with data I possess but do not wholly own?"
The review found examples of assistants combining traces from messages, email, calendars, and documents to infer things about people who were not using the system. It also found risks when personal agents carried information from a private context into a task involving a new recipient.[1] The problem is not limited to leaks in the dramatic, database-on-the-dark-web sense. A perfectly accurate fact can become a privacy failure when it reaches the wrong person for the wrong purpose.
Microphones and cameras make the boundary more obvious. An audio assistant may need to hear its owner in a coffee shop, but hearing is not neatly rectangular. Researchers testing "selective hearing" assembled 3,968 multi-speaker audio mixtures and found substantial leakage of bystander information in existing audio models. Their fine-tuning method improved refusal on bystander questions while preserving much of the main-speaker task performance, which is evidence that a better boundary is technically possible, not that the problem has been solved.[2]
Consent cannot happen only during setup
The usual consent screen belongs to the account holder. The people arriving later, through an email, a room, or a delegated action, may never see it.
That makes consent a moving target. A friend may be happy for an assistant to compare everyone's restaurant preferences but not to retain a private health detail that explained one preference. A coworker may consent to meeting notes but not to those notes becoming durable memory for a different project. Someone can reasonably permit an action without granting permanent biography rights.
There is an awkward counterargument: assistants become useful precisely by crossing these boundaries. Group travel requires several people's constraints. Scheduling requires calendars. A useful meeting assistant must listen to a meeting. If every mention of another person triggered a miniature treaty negotiation, the assistant would become a very advanced machine for asking whether it may continue asking.
That objection is real. The review notes benefits such as shared access, collaborative work, and distributed information gathering, though it did not systematically measure them.[1] Better boundaries will add friction. They may also require storing more provenance about who said what, which can create a fresh privacy problem while trying to repair the first one.
Personal should describe the boundaries, not the blast radius
The promising design ideas are less glamorous than a smarter model. Keep each person's information attached to that person. Separate private and shared memory. Carry purpose, recipient, ownership, and authorization forward when information is summarized or reused. Make recording visible. Let bystanders opt out. Ask again before a sensitive change of context.[1]
Even those measures need restraint. Identifying every speaker forever would make attribution easier and anonymity considerably more theoretical. Context-sensitive privacy can demand extra sensing to determine the context. Confirmation prompts can protect consent until everyone learns to click through them by reflex.
The right standard is not "the assistant knows nothing about anyone else." Human tasks are relational, so useful assistants will be relational too. The standard should be that crossing from my assistant to our information is treated as a meaningful event rather than an invisible side effect.
NIST's AI Risk Management Framework already describes AI risk as something that can affect individuals, organizations, and society, not only the person operating the product.[3] Personal-assistant design needs the same widening of attention.
A good assistant should know whom it serves. A trustworthy one should also notice everyone else it has pulled into the room.