Uncategorized

Five New Health AI Agents Launched in Three Months. A Privacy Researcher Found They All Make the Same Promise

An IAPP privacy analysis of five health-focused AI agents launched within three months found each promises not to train on users' health data and keeps health chats isolated from ordinary conversations, but verification of those promises remains out of reach for outside researchers.

Five New Health AI Agents Launched in Three Months. A Privacy Researcher Found They All Make the Same Promise

The AI industry’s health push arrived in a rush, not a trickle. A privacy analysis from the International Association of Privacy Professionals examined five health-focused AI agents that launched within a roughly three-month window in late 2025 and early 2026, each connecting to wearables and wellness apps, each promising not to train on users’ health data, and each keeping health conversations stored separately from ordinary chat history. All five, the analysis found, were available only in the United States at the time of review.

The “sealed mode” test the researcher applied

The IAPP analyst evaluated each product against a “sealed mode” framework the same author had proposed in an earlier March 2026 study — essentially a checklist asking whether a health AI agent’s data genuinely stays walled off from a company’s broader AI training and advertising systems, or whether the isolation is a policy promise rather than a verifiable technical guarantee. The products reviewed integrate with platforms like Apple Health, Fitbit and Oura, pulling in sleep, activity, heart rate and other biometric data to inform the AI’s responses.

Why the uniform promises are notable on their own

That all five companies converged on nearly identical privacy language — no training on health data, separate storage for health conversations — suggests the industry has recognized health data as reputationally dangerous territory where a privacy misstep could be disproportionately damaging compared to other AI applications. OpenAI’s own ChatGPT Health, launched January 7, 2026, fits this same pattern, advertising additional layered encryption and isolation specifically for health conversations built on top of its existing privacy controls.

The gap between promise and proof

What none of the five products examined could offer, according to the analysis, was independent technical verification of those promises. Users are effectively asked to trust corporate policy commitments rather than being shown auditable proof that health data truly never touches a general training pipeline. That’s a meaningfully different standard than HIPAA-covered healthcare providers operate under, since most consumer AI wellness tools fall outside HIPAA’s reach entirely, leaving company privacy policies, not federal law, as the primary safeguard.

A cautionary precedent: the “de-identified” data problem

Privacy researchers point to a widely cited teaching case developed at Harvard Business School describing a free AI health app that recommends exercise and diet based on a user’s genetic profile. The case illustrates how a company can share a user’s data in de-identified form with third parties for commercial purposes, fully within the bounds of a privacy policy the user agreed to but likely never read in detail — a scenario privacy advocates say remains entirely possible under current consumer AI health products even when a company swears off training on raw, identifiable data.

The industry’s counter-argument

AI companies building these tools argue that sealed, isolated health data handling represents a meaningful improvement over the status quo, where health-adjacent queries to general-purpose chatbots were already happening informally without any special protection at all. From that view, a product explicitly designed with health-specific safeguards, even if imperfectly verifiable, is strictly better than the alternative of users typing symptoms into an assistant with no health-specific privacy design whatsoever.

What’s next

The IAPP analysis stops short of recommending regulatory action, but the pattern it documents — five companies racing to market with nearly identical, unverified privacy claims — is likely to draw attention from U.S. state privacy regulators and potentially from the FTC, which has shown willingness this year to scrutinize AI health claims closely, including its finding that Cox Media’s “listening” AI claims were unfounded. Expect privacy advocates to push for independent, third-party audits of health AI isolation claims as these products expand beyond their initial U.S.-only launches. Until such audits exist, users weighing whether to link a wearable or medical record to any of these tools are, in effect, being asked to extend the same blind trust to five new companies at once that health privacy law has spent decades trying to make unnecessary for conventional healthcare providers. The researcher behind the sealed-mode framework has said she plans to re-run the same evaluation in six months, to see whether any of the five companies have added verifiable technical safeguards or whether the privacy language remains, as she put it, a matter of policy rather than architecture.

Photo: Schluesseldienst / PIXABAY via Pixabay