Privacy isn't a legal checkbox. It's a design problem, and on Sky Live, it was also a measurable barrier to purchase. This is how I helped turn that risk into a structured process, and two shipped product changes.
Reading time: 8 min
How I approach it
Designing responsibly for AI has been my focus since 2020. The Sky Live work clarified what the gap looks like in practice: making a product genuinely ethical requires intervention at three layers, and most teams only look at one.
Algorithms and datasets. Engineering-led, but design has to be in the room for dataset choices (diversity, edge cases, fairness) because they shape every downstream experience.
How the product is shaped once risks and outcomes are understood. Product and design together. This is where structured risk-mapping does the most work.
How we explain the system to customers and how we let them correct it. Design-led. The privacy-button onboarding, the no-beautifying-filter statement, and the mute-button messaging all live here.
01 · The moment that made this necessary
Sky Live is a camera-first product operating in people's living rooms, processing video, audio, and biometric data to power real-time experiences. The ethical stakes were unusually high: trust, privacy, and responsible AI weren't optional considerations, they were foundational to whether customers adopted the product at all.
Customer sentiment ahead of launch. A 2021 YouGov study put Sky at 35% net trust on Face ID privacy, behind Apple, Samsung, Google, and Netflix. In 2022, 28% of prospective non-buyers named privacy as a reason to pass on Sky Live. A measurable brake on purchase intent, not a theoretical concern.
Drawing on my Oxford coursework in ethics and AI, I joined Sky's Digital Ethics Network, sponsored by the Chief Data Officer. I combined two existing tools, Omidyar's Ethical Explorer and Design Ethically's Layers of Effect, into a single Miro board to forecast ethical impact across Sky Live.
Without it, a set of initiatives wouldn't exist: ethical vetting of AI partners onboarded into Sky Live (NEX, Stingray), adopting Google's ML Kit Pose Detection partly for its ethical track record, and UX changes that helped customers understand and control their data.
02 · Role
I was the only designer in a group otherwise led by data and product. My job was to hold the UX perspective in data-heavy conversations and make sure every risk that came out of the workshop translated into something a product or engineering team could actually act on.
I built the Miro workshop board from scratch, combining two existing ethical design tools into a single cross-team format. I led the workshops across Sky Live teams and owned the Privacy and Inclusivity threads end to end, from framing the risk to shaping the mitigations that landed in product. Three asks were escalated to the Beyond TV directors' board and became active initiatives.
03 · What I built
The centrepiece was a hybrid workshop designed and facilitated on Miro, built around three named stages: lightning talks framing Sky Live from multiple perspectives; a structured risk-mapping block using Ethical Explorer and Layers of Effect tailored to Sky Live; and a "What now?" stage that converted each named risk into actionable insight, a design mitigation, and an owner.
The workshop ran in three stages: a lightning talk to align everyone on what Sky Live does with data; a structured risk-mapping block using Ethical Explorer and Layers of Effect to name and forecast each risk; and a "What now?" stage where every risk came out with a committed action, a named owner, and the people still needed to make it happen. No risk left the workshop unassigned.




A camera-first device in the home introduced real risks: surveillance, stalking, hacking. These needed explicit design mitigations, not just policy statements. I owned this thread from risk framing through to the "Your privacy protected" onboarding and hardware mute-button messaging.
Face detection reliant on ML is fallible and risks excluding users. Children's rights, positive self-image, and non-violent values needed active consideration. I owned this through to the no-beautifying-filters statement in Video Booth.
The remaining threads, held across the DEN: the consent gap between what the service did and what customers understood it to do; Watch Together risks around inappropriate broadcasts and unsupervised children; and model bias from insufficiently diverse training data.
Built on Ethical Explorer and Layers of Effect as a Miro-based template for teams to adopt in their own projects. Served as a shared tool to spark discussion, align stakeholders, and surface the ethical impact of design decisions before they shipped. A workshop-outcomes deck captured the risks and initiatives for ongoing reference.
A series of talks across Sky teams on how designers should approach AI responsibly. Covered practical AI use cases, machine learning concepts, model cards, and the UX challenges of AI-driven products, all pre-GenAI.
04 · How teams used it
There was no formal measurement framework in place at the time, something I'd change if I ran this again. The directional signals we did have: the workshop ran five times, mapped five areas of concern spanning design, product, and engineering, and two other design teams adopted the framework to measure the ethical impact of their own products.
The 26 attendees were senior by design: heads of department, heads of product management, lead interaction designers, senior hardware engineers, and lead software engineers from across Beyond TV, alongside responsible business, propositions, and data ethics leads. The room could approve action, not just discuss it.
The Sky Live onboarding was rewritten to explain the hardware privacy button more clearly. It traces back to the designing-for-trust risk surfaced in the workshop and the "Your privacy protected" statement it seeded.
The family-focused Video Booth app, built around funny filters, shipped with an explicit statement that no beautifying filters were used on faces. A direct response to the inclusivity risks around children's self-image surfaced in the workshop.
05 · What I'd do differently
Two things I'd change. First, the Digital Ethics Network was volunteer-led, run on top of day jobs. I'd make it an official project with dedicated time, especially for the engineering partners whose involvement mattered most and was hardest to secure under voluntary terms.
Second, I'd run the workshop at the start of Sky Live projects, not towards the end. By the time we were forecasting risks, some of the decisions that carried the most ethical weight, around data collection, algorithm choice, and partner selection, were already locked in. Running the workshop pre-commit would have changed which risks could still be prevented versus mitigated.
More work