CPAI Issue Brief · Privacy & data
AI & Data Protections
There is no comprehensive federal privacy law — so what happens to the data people put into AI depends on their zip code and the fine print.
What’s happening
People type sensitive information into AI tools that feel private but are company servers. That data can be used for training, retained, reviewed by humans, subpoenaed, breached, or sold — and the rules governing it are a patchwork.
What the evidence shows
In the New York Times copyright litigation, a federal court ordered OpenAI to hand over about 20 million de-identified consumer ChatGPT conversations in discovery — ordinary users' chats became evidence in a case they are not party to. "Anonymized" offers thin protection: a Nature Communications study estimated 99.98% of Americans could be re-identified from 15 demographic attributes. The FTC's amended COPPA Rule now requires separate parental consent before a child's data is disclosed to third parties, including for AI training.
consumer ChatGPT chats ordered produced in discovery
NYT v. OpenAI, 2025 — court order
have comprehensive privacy laws in effect; NC is not among them
IAPP / MultiState, 2026
Where it reaches constituents
Every person who uses an AI tool — and, acutely, children, patients, and anyone whose most sensitive data ends up in the least-protected place. The protection you get depends heavily on which state you live in.
The current legal & regulatory landscape
No comprehensive federal consumer-privacy statute exists; sector rules (HIPAA, FERPA, COPPA, GLBA) cover slices. About 20 states have comprehensive privacy laws in effect as of 2026; North Carolina does not. A newer layer of AI-specific state laws (Colorado, Texas, Illinois, California) is arriving alongside them.
Considerations policymakers are weighing
- ·Baseline data rights that do not depend on the state a person lives in.
- ·Rules for sensitive categories — genetic, biometric, health, and children's data.
- ·Transparency about training use, retention, and human review of what users enter.
Listed as live debates, not recommendations. CPAI does not take a position on how these should be resolved.
This brief condenses a full, sourced public guide. The complete evidence and citations:
AI and Your Data →Key sources
A nonpartisan resource
The Center for Practical AI is a nonpartisan 501(c)(3) nonprofit. We provide education, research, and analysis, and we offer briefings and testimony on request. We do not endorse candidates or lobby for or against specific legislation. Everything here describes the evidence and the current landscape — the policy choices are yours.
Want CPAI to brief your office on this?
We provide nonpartisan briefings, research summaries, and testimony on request.
Request a briefing →