Strategic Report  ·  2026-08-13

Regulating Data Brokers in the Age of AI: A California Case Study

Strategic ReportMedium impactUnited States
A joint Stanford HAI / Stanford RegLab policy brief assesses data broker compliance with California's landmark data privacy laws (CCPA and the Delete Act) and finds that only 9% of the 522 self-registered data brokers reviewed fully complied with mandated transparency requirements, while 64% added friction (dark patterns) to consumer rights-request processes and 45% submitted no rights-request metrics at all. The brief further finds that the 2026 California Data Broker Registry shows 32 brokers have disclosed selling consumer data to generative AI developers, tying opaque data-broker practices directly to the AI training-data ecosystem. Authors recommend nationwide data-broker registration laws with automated privacy-rights processing, standardized reporting, and a private right of action. Methodology: manual review of privacy policies and CCPA/Delete Act disclosures for all 522 self-registered California data brokers in 2025.
As AI developers increasingly rely on third-party consumer data purchased from opaque brokers, weak compliance with the nation's most comprehensive data-privacy regime signals a governance gap that generative AI developers and their enterprise customers should anticipate being closed by future regulation or litigation.
Assess AI training-data supply chains for reliance on data-broker sourced consumer data and evaluate exposure to forthcoming broker-registration and transparency mandates.
Stanford HAI - Regulating Data Brokers in the Age of AI: A California Case StudyStanford HAI Policy Brief PDF
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →