The Lord of the (Speaking) Rings: Confronting the 7 Legal Shadows of Conversational AI
The Lord of the (speaking) Rings: An interdisciplinary Fellowship to deal with 7 legal issues
This paper presents a multi-disciplinary critique of Conversational User Interfaces (CUI), identifying seven critical legal issues arising from the mass adoption of smart speakers and voice assistants. It calls for a "Fellowship" between legal scholars and HCI designers to implement Privacy by Design (PbD) principles before regulatory gaps jeopardize user rights.
TL;DR
As smart speakers and Conversational User Interfaces (CUI) become our "home butlers" and "portable friends," they bring an unprecedented level of 24/7 surveillance. This paper identifies seven critical legal gaps—ranging from liability in automated shopping to the psychological manipulation of "emotional" AI—and argues that without interdisciplinary intervention, the IoT will become a lawless "Mordor" ruled by the strongest data monopolies.
The Motivation: Sauron’s Eye in Your Living Room
We are entering a phase of Surveillance Capitalism where interconnected ecosystems surround us. The author argues that providing personal data has become an intrinsic "take it or leave it" fee. However, the service providers have a double nature: while they offer convenience in plain sight, they conduct hidden tracking and profiling that exploit users.
The core motivation of this work is to shift from retrospective law (fixing things after they break) to prospective regulation that considers the "cumulative impacts" of AI interactions over time.
Methodology: The Seven Legal Issues
The paper breaks down the CUI legal landscape into seven distinct "shadows":
- Gollum (Profiling & Testing): Users are treated as "crash test dummies." Companies use voice data not just to provide services, but to train facial or vocal recognition AI without transparent consent.
- The Ring (Automated Decisions): When a device mistakenly orders caviar instead of crackers, who is liable? The "black-box" nature of AI makes it impossible for users to prove the mistake.
- Gandalf (Linguistic Liability): Human language is nuanced. If a CUI gives faulty instructions or misinterprets a command, current Terms & Conditions unfairly shift the burden of responsibility to the user.
- The Treasure (Security): Voice interfaces are susceptible to "DolphinAttacks" (inaudible frequencies). If a third party hijacks your "personal" ring, proving your innocence in any resulting action is nearly impossible.
- Théoden (Recognizability): With technologies like Google Duplex, AI can mimic human pauses and inflections. The author argues that "recognisability" should be a mandatory legal requirement.
- Samwise (Loyalty & Influence): Long-term use of CUI creates an emotional bond. Suppliers can exploit this affection to influence commercial or political choices—a clear conflict of interest.
- Frodo’s Blind Trust (Neutrality): CUIs will soon be the primary filter for all information. Unlike search engines that show multiple results, a voice assistant might only give one, creating a massive information monopoly.

Critical Insights & Experiments
The paper highlights recent real-world failures to ground its theory:
- The Alexa Privacy Breach: A case where a couple's private conversation was recorded and emailed to a random contact.
- The Google Duplex Asymmetry: When an AI mimics a human, it places the user in a "weak, asymmetrical" position where they lack awareness of the underlying Big Data tracking.
The Radical "Human Voice" Solution
One of the most provocative suggestions in the paper is to make the use of a human voice in CUI systems illegal. While drastic, this would instantly solve the issue of recognisability and reduce the risk of emotional addiction or manipulation, drawing a hard line between human and machine.
Conclusion and Future Outlook
The paper concludes that the IoT could become a digital "Mordor" without proper "Privacy by Design" (PbD) principles. The value of this work lies in its call for an Interdisciplinary Fellowship: designers must understand the law, and lawyers must understand the technical constraints of HCI.
Key Takeaways:
- Liability Transition: Private law needs to update its view on "AI Agency."
- Neutrality: CUI must be regulated to ensure transparency and plurality in information delivery.
- User Empowerment: Users need full access to their data and metadata to protect against security breaches and misinterpretation.

Ultimately, whether our digital liberties are protected or exploited is "up to us"—the designers and regulators of today.
