Teaching The Great Hack in 2026: Data, Power, Consent, AI, and Competing Visions of Technology Law
As part of my Technology Law course at the University of Tulsa College of Law, I recently asked my students to watch the Netflix documentary The Great Hack and write a short analytical reflection.
The assignment was deliberately open-ended. Students could consider personal data as a source of economic and political power; the relationship between consent and structural power; corporate and governmental responsibility; political persuasion and manipulation; the difficulty of regulating technologies after they have transformed markets and social behavior; or the ways in which the Cambridge Analytica controversy might look different today in an environment increasingly shaped by generative artificial intelligence, synthetic content, algorithmic recommendation systems, and sophisticated profiling.
I expressly asked students not to summarize the documentary. Instead, I wanted them to identify something they found important, troubling, convincing, surprising, or debatable—and explain why.
Reading all the responses together produced something more interesting than a collection of individual reactions. The students’ reflections organically formed a map of several competing approaches to Technology Law.
From Platform Responsibility to Individual Responsibility
One group of responses focused primarily on platform power. If social-media companies organize information, collect extraordinary quantities of behavioral data, structure what users encounter, and influence important dimensions of public discourse, can they still be understood exclusively through the conventional paradigm of private enterprise?
A second, particularly prominent stream focused on the relationship between formal consent and structural power. These students questioned whether clicking “I agree” can provide meaningful authorization when individuals cannot realistically understand the downstream uses of their information or anticipate what might subsequently be inferred from apparently innocuous data.
But another perspective pushed in a different direction. Rather than locating responsibility primarily in platforms or government regulators, some students emphasized individual responsibility, digital literacy, and skepticism. Perhaps part of the response to technological power must involve educating individuals to understand that information voluntarily placed into digital environments may become difficult—or impossible—to control.
The tension between these perspectives raises a recurring problem in Technology Law: when should law protect individuals from an environment structured by powerful technological intermediaries, and when should it expect individuals to protect themselves?
Regulation, Misinformation, and Freedom of Expression
Another group identified a different tension. Concern about technologically enabled manipulation does not necessarily establish that governments should regulate misinformation.
Attempts to address false or manipulative information can themselves create difficult questions about freedom of expression and, in the United States, the First Amendment. If government or platforms are expected to distinguish truth from falsity, who exercises that authority, according to what standards, and with what safeguards?
The problem therefore cannot simply be framed as regulation versus non-regulation. Regulation itself redistributes power.
Questioning the Documentary
Some of the most interesting reflections refused to accept The Great Hack as a neutral description of technological reality.
Students questioned its narrative techniques, the portrayal of Cambridge Analytica’s technological sophistication, and whether evidence of profiling and targeted communication necessarily establishes the causal claims sometimes associated with particular electoral outcomes.
This introduces another important dimension of technological literacy: claims about the power of technology themselves require scrutiny.
Companies may exaggerate technological capabilities to attract clients or investors. Critics may sometimes exaggerate those same capabilities to demonstrate danger. Governments may invoke technological threats to justify intervention. Understanding Technology Law therefore requires examining not only technologies, but also the narratives constructed around them.
What Changes When Cambridge Analytica Meets Generative AI?
A particularly important stream of responses transported the documentary’s problems into 2026.
The Cambridge Analytica controversy centered on data collection, profiling, segmentation, behavioral prediction, and targeted communication. Generative AI potentially changes the economics and scale of the final step.
Content no longer necessarily needs to be written, filmed, recorded, or designed individually in advance. Synthetic text, images, audio, and video can increasingly be generated rapidly and inexpensively. Profiling, content generation, personalization, and algorithmic distribution can therefore become parts of the same technological ecosystem.
The question is no longer merely who possesses our data. It is increasingly what can be inferred, generated, personalized, and delivered on the basis of that data.
Is Privacy Law Enough?
Another particularly valuable contribution was to question whether these issues belong exclusively to privacy law.
Concentrations of personal data can also raise questions about antitrust and competition, consumer protection, contracts, corporate governance, platform regulation, freedom of expression, democratic governance, and artificial intelligence regulation.
This is an important methodological point for students of Technology Law: how we characterize a technological problem often determines which body of law we reach for—and different bodies of law identify different harms and offer different remedies.
Technology Law as a Problem of Power
Reading the 34 reflections together ultimately reinforced for me why Technology Law is difficult to confine within conventional doctrinal boundaries.
The same technological phenomenon can simultaneously implicate privacy, contract, competition, corporate responsibility, speech, consumer protection, democratic governance, and artificial intelligence.
More fundamentally, emerging technologies continually redistribute power: between individuals and corporations, corporations and governments, governments and citizens, and increasingly between human decision-makers and automated systems.
The central question is therefore not simply:
Should this technology be regulated?
It is also:
Who gains power from it? Who bears its risks? Who should bear responsibility when harms occur? Which legal framework best captures the problem? What values might regulation protect? What values might regulation itself endanger? And can law respond before technological practices become structurally embedded rather than only after their consequences become visible?
Thirty-four students watched the same documentary and were given the same assignment.
They did not produce one answer.
They produced several competing ways of understanding technology, law, power, responsibility, and individual autonomy.
For a Technology Law classroom, that may have been the most valuable result of all.
Paolo Davide Farah, Paolo Farah