Uncategorized

California’s Broker Registry Shows 32 Companies Selling Health Data to AI Developers, While a Stanford Audit Finds Almost No One Follows the Rules

A Stanford HAI report found that 32 data brokers now sell consumer data directly to generative AI developers under California's broker registry, while only about 9% of registered brokers fully comply with the state's Delete Act — a gap underscored by a separate $45,000 fine against a broker caught selling lists of Alzheimer's patients' personal data.

California's Broker Registry Shows 32 Companies Selling Health Data to AI Developers, While a Stanford Audit Finds Almost No One Follows the Rules

A California Privacy Protection Agency registry update this year revealed that 32 data brokers currently sell consumer information directly to generative AI developers, a disclosure that Stanford’s Institute for Human-Centered AI (HAI) says exposes a largely unregulated pipeline feeding sensitive health and biometric data into AI training and inference systems. The finding comes from a Stanford HAI policy brief released August 11, 2026, which used California’s broker registry as a case study for how data protection law is holding up against the AI boom — and concluded that, in practice, it mostly isn’t.

The Scale of What’s Being Sold

California’s registry, maintained under the state’s 2023 Delete Act, now requires data brokers to disclose for the first time whether they sell information to generative AI companies, a transparency requirement unique to California as of this year’s filings. Beyond the AI-specific disclosure, Bloomberg Law reported that the state’s broader registry listed more than 500 registered brokers, including well-known names like General Motors, T-Mobile and LexisNexis alongside smaller operators that specifically traffic in biometric data and reproductive health information. The registry also showed some California-collected consumer data flowing to foreign buyers and to U.S. government purchasers, broadening the policy conversation beyond AI companies alone.

Almost Nobody Is Actually Complying

The more alarming finding in the Stanford report wasn’t who’s buying the data — it was how few sellers follow the law at all. Stanford researchers found that only about 9% of registered data brokers fully comply with California’s Delete Act, the law meant to let consumers request mass deletion of their data across the broker industry with a single request. Researchers documented brokers routinely using dark patterns to frustrate consumers trying to exercise that right: confusing multi-step web forms, redundant identity verification hurdles, and processes designed to make opt-outs as exhausting as possible. A related investigation covered by 9to5Mac found brokers and AI companies going further still, deploying fake or non-functional opt-out forms that give the appearance of compliance without actually removing anyone’s data from sale.

A Separate Case Shows What’s at Stake: Alzheimer’s Patients’ Data for Sale

The risk isn’t abstract. In a separate enforcement action, the CPPA fined Texas-based broker Rickenbacher Data LLC, doing business as Datamasters, $45,000 and banned it from selling Californians’ data after finding the company had compiled and resold lists identifying 435,245 people with Alzheimer’s disease, 133,142 people categorized under addiction, and 857,449 people with bladder-control conditions — complete with names, home addresses, phone numbers and emails, marketed for targeted advertising. It was the CPPA’s first enforcement action under the Delete Act’s registration requirements, and regulators framed it as a warning shot: the agency said the case illustrates exactly the kind of granular, re-identifiable health condition data that unregistered, unaudited brokers are still moving at scale, even as the same ecosystem now also supplies data to AI model developers.

Why De-Identification No Longer Means Protected

Healthcare privacy law in the U.S. has long rested on the idea that stripping names and direct identifiers from medical data makes it safe to sell or share. Reporting on the intersection of HIPAA and AI has increasingly challenged that assumption: health data that has been \”de-identified\” under HIPAA’s safe harbor rules can still be re-identified when cross-referenced against other commercially available datasets using modern machine learning techniques, effectively reconstituting protected health information outside HIPAA’s reach entirely, since HIPAA governs covered entities like hospitals and insurers, not the broader data broker market. That gap is precisely what lets conditions like Alzheimer’s diagnoses or mental health treatment histories end up in marketing databases legally, because the data has formally exited HIPAA’s jurisdiction by the time it reaches a broker.

Industry and Privacy Advocates Talk Past Each Other

Data brokers and the AI firms that buy from them generally argue this activity is lawful, disclosed (at least nominally) through state registries, and essential to building better consumer products and, in AI’s case, more capable models trained on real-world behavioral and demographic patterns. Privacy researchers counter that disclosure on a government registry is a far cry from meaningful consent, especially when, per Stanford’s findings, the mechanisms consumers are supposed to use to opt out barely function. Health policy advocates go further, arguing that selling lists of people by medical condition for advertising purposes — regardless of whether AI companies are among the buyers — represents exactly the kind of discriminatory data use that privacy law was supposed to prevent, since such lists can be used to target vulnerable populations with predatory financial products or deny them opportunities.

What’s Next

Stanford’s researchers are recommending that other states adopt California-style broker registration and AI-specific disclosure requirements, arguing that without a baseline of visibility into the data broker market, neither regulators nor researchers can evaluate whether existing privacy law is working. In the meantime, expect the CPPA to bring more enforcement actions modeled on the Datamasters case, and expect pressure to build on Congress and other state legislatures to close the de-identification loophole that currently lets sensitive health data move freely between brokers and AI developers once it has technically left HIPAA’s jurisdiction. Whether that closes before AI developers further normalize purchasing third-party behavioral and health data for training remains the central open question.

Photo: Schluesseldienst / PIXABAY via Pixabay