What happened
A joint Stanford HAI / Stanford RegLab policy brief assesses data broker compliance with California's landmark data privacy laws (CCPA and the Delete Act) and finds that only 9% of the 522 self-registered data brokers reviewed fully complied with mandated transparency requirements, while 64% added friction (dark patterns) to consumer rights-request processes and 45% submitted no rights-request metrics at all. The brief further finds that the 2026 California Data Broker Registry shows 32 brokers have disclosed selling consumer data to generative AI developers, tying opaque data-broker practices directly to the AI training-data ecosystem. Authors recommend nationwide data-broker registration laws with automated privacy-rights processing, standardized reporting, and a private right of action. Methodology: manual review of privacy policies and CCPA/Delete Act disclosures for all 522 self-registered California data brokers in 2025.
Why it matters
As AI developers increasingly rely on third-party consumer data purchased from opaque brokers, weak compliance with the nation's most comprehensive data-privacy regime signals a governance gap that generative AI developers and their enterprise customers should anticipate being closed by future regulation or litigation.
Action needed
Assess AI training-data supply chains for reliance on data-broker sourced consumer data and evaluate exposure to forthcoming broker-registration and transparency mandates.