Privacy basics

AI privacy issues: concrete examples and what they mean for your business

July 8, 2026 · 2 min read

Artificial intelligence did not invent privacy problems, but it industrialized them: more data collected, combined faster, with conclusions no one consented to. Here are the AI privacy issues that already produce real cases, with concrete examples, and what existing law already says about them.

1. Training data scraped without consent

Models learn from massive datasets scraped from the public web: photos, forum posts, resumes, faces. "Publicly accessible" and "free to reuse" are not the same thing legally, and regulators have acted on the difference: facial recognition companies built on scraped photos have been ordered to delete data belonging to entire countries' citizens. If your organization fine-tunes a model on customer data, the same question applies: did the purpose people consented to include training?

2. Chatbots that leak what employees type

The fastest-growing leak channel in most companies is an employee pasting client files or source code into a public chatbot. The information leaves the organization, may be retained, and in some configurations can inform future model behavior. Several large firms have banned or restricted public AI tools for exactly this reason; the measured response is a clear internal policy plus enterprise agreements where the data stays out of training.

3. Inference: data nobody ever provided

AI's specialty is deducing what was never disclosed: health status from shopping patterns, mood from typing rhythm, financial stress from browsing. The famous retail case where a chain inferred a customer's pregnancy from purchases predates modern AI; today's models make that inference power ordinary. Privacy law increasingly treats inferred data as personal information, meaning it needs a purpose and a legal basis like any collected data.

4. Automated decisions about people

Credit scoring, resume screening, insurance pricing, content moderation: when an algorithm decides alone, errors and biases scale. This is one of the few AI areas with explicit legislation already in force: GDPR's article 22 and Quebec's Law 25 both give people the right to be informed when a decision is fully automated, to have the data corrected, and to bring their observations to a human being.

5. Biometric surveillance

Face recognition in stores, emotion analysis in job interviews, voice prints in call centers. Biometric data enjoys reinforced protection nearly everywhere: Law 25 requires organizations to declare biometric databases to the regulator 60 days before use, and consent must be explicit. Several retailers have already been sanctioned for camera systems shoppers never knew about.

What a normal business should do

  • Inventory where AI touches personal data in your operations, including the vendors who added it silently.
  • Update your privacy policy if AI processing or automated decisions are part of your service; our privacy policy guide shows where it fits.
  • Keep humans in the loop for decisions that materially affect people, and say so.
  • Write the internal rule for public chatbots before the first incident, not after.
  • Apply the boring fundamentals: minimization, retention limits, consent for what is not essential. They cover most AI risk too, starting with the trackers on your own site.

The consent platform teams actually trust.

Installed in five minutes. Blocks trackers for real, compliant with Law 25 and GDPR, built in Quebec.