Center for Practical AI

CPAI Issue Brief · Privacy & data

AI & Data Protections

There is no comprehensive federal privacy law — so what happens to the data people put into AI depends on their zip code and the fine print.

What’s happening

People type sensitive information into AI tools that feel private but are company servers. That data can be used for training, retained, reviewed by humans, subpoenaed, breached, or sold — and the rules governing it are a patchwork.

What the evidence shows

In the New York Times copyright litigation, a federal court ordered OpenAI to hand over about 20 million de-identified consumer ChatGPT conversations in discovery — ordinary users' chats became evidence in a case they are not party to. "Anonymized" offers thin protection: a Nature Communications study estimated 99.98% of Americans could be re-identified from 15 demographic attributes. The FTC's amended COPPA Rule now requires separate parental consent before a child's data is disclosed to third parties, including for AI training.

~20M

consumer ChatGPT chats ordered produced in discovery

NYT v. OpenAI, 2025 — court order

~20 states

have comprehensive privacy laws in effect; NC is not among them

IAPP / MultiState, 2026

Where it reaches constituents

Every person who uses an AI tool — and, acutely, children, patients, and anyone whose most sensitive data ends up in the least-protected place. The protection you get depends heavily on which state you live in.

The current legal & regulatory landscape

No comprehensive federal consumer-privacy statute exists; sector rules (HIPAA, FERPA, COPPA, GLBA) cover slices. About 20 states have comprehensive privacy laws in effect as of 2026; North Carolina does not. A newer layer of AI-specific state laws (Colorado, Texas, Illinois, California) is arriving alongside them.

Considerations policymakers are weighing

  • ·Baseline data rights that do not depend on the state a person lives in.
  • ·Rules for sensitive categories — genetic, biometric, health, and children's data.
  • ·Transparency about training use, retention, and human review of what users enter.

Listed as live debates, not recommendations. CPAI does not take a position on how these should be resolved.

This brief condenses a full, sourced public guide. The complete evidence and citations:

AI and Your Data

Key sources

Court ruling / legal filingNYT v. OpenAI (2025)Court order to produce 20 million ChatGPT logsIn the New York Times copyright litigation, a federal magistrate ordered OpenAI (November 2025) to produce about 20 million de-identified consumer ChatGPT conversations — a random sample from Dec 2022–Nov 2024, up to 80 million prompt-output pairs — to opposing counsel in discovery; a stay was denied. Ordinary users' chats became evidence in a case they are not party to. A structural fact about data held by a company, not a scandal claim.
Peer-reviewed studyRocher, Hendrickx & de Montjoye (2019)Estimating the success of re-identifications in incomplete datasetsNature Communications. A model estimated that 99.98% of Americans could be correctly re-identified in any dataset using 15 demographic attributes — so 'anonymized' data is often re-identifiable once combined with other data.
Official policy / primary sourceFederal Trade Commission (2025)Amended COPPA RuleThe FTC's amended Children's Online Privacy Protection Rule (final April 2025, effective June 23, 2025) requires separate verifiable parental consent before a child's personal information is disclosed to third parties — including for AI training.
Official policy / primary sourceIAPP / MultiState (2026)U.S. state comprehensive privacy lawsThere is no comprehensive federal consumer-privacy statute; sector rules (HIPAA, FERPA, COPPA, GLBA) cover slices. About 20 states have comprehensive consumer-privacy laws in effect as of 2026 — North Carolina is not among them.
Court ruling / legal filingIn re 23andMe (2025)Bankruptcy and sale of genetic dataAfter 23andMe filed for bankruptcy in 2025, its genetic database became a transferable estate asset; a court approved its sale (about $305 million) to TTAM Research Institute, a nonprofit led by the company's founder, over objections from multiple state attorneys general seeking explicit customer consent. The teaching point: a privacy promise is only as durable as the entity that made it.

A nonpartisan resource

The Center for Practical AI is a nonpartisan 501(c)(3) nonprofit. We provide education, research, and analysis, and we offer briefings and testimony on request. We do not endorse candidates or lobby for or against specific legislation. Everything here describes the evidence and the current landscape — the policy choices are yours.

Want CPAI to brief your office on this?

We provide nonpartisan briefings, research summaries, and testimony on request.

Request a briefing →