Articles

State Privacy Laws Cover Data Collection, Not AI Inferences. That's Starting to Change.

AI inferences from mundane data points create a regulatory gap most state privacy laws don't address. What compliance teams should do now.

Concord Team · Published Wed Sep 02 2026

State Privacy Laws Cover Data Collection, Not AI Inferences. That's Starting to Change.

Most state privacy laws were written to govern a straightforward exchange: a company collects personal data, and the law dictates how that data can be used, shared, or sold. But AI has introduced a category of personal information that sits outside that framework entirely: inferred data.

An AI system doesn't need your medical records to draw conclusions about your health. A GPS coordinate at a medical facility, combined with visit frequency and duration, is enough. A pattern of app usage, search behavior, and location data can surface inferences about beliefs, conditions, and affiliations that a person never disclosed. The raw inputs may look innocuous on their own. The conclusions drawn from combining them are anything but.

The Gap in State Privacy Frameworks

The majority of state privacy laws in the U.S. define "personal data" as information that is collected from or about an individual. Inferences (conclusions derived by an algorithm rather than provided by the person) generally fall outside that definition.

That means an organization could collect a handful of data points well within its stated privacy policy, pass them to a third-party system, and that system could generate sensitive inferences with no obligation to disclose, correct, or delete them. The person those inferences describe may have no idea they exist, let alone any mechanism to contest them.

Privacy and civil-liberties organizations, including the Electronic Frontier Foundation, the Center for Democracy and Technology, and the Electronic Privacy Information Center, have raised this gap as a priority concern. Several proposals are now circulating at the state level:

  • Redefining "personal data" to explicitly include inferences and profiles derived from collected information.
  • Granting deletion and contestation rights for inferred data, not just raw data.
  • Mandating data minimization, requiring organizations to collect only what is necessary for a stated purpose, limiting the raw material available for inference in the first place.

These aren't hypothetical. Connecticut has already begun expanding its privacy framework in this direction. The regulatory trajectory is toward broader definitions and stricter minimization requirements, not narrower ones.

What Compliance Teams Should Do Now

Even if your organization doesn't build inference models, the data you collect and share downstream may feed someone else's. Waiting for the statutes to catch up is a risk, not a strategy.

Two areas deserve attention today:

Map your data flows end to end. Data minimization is impossible without a clear inventory of what data you hold, where it moves, and which third parties receive it. If your data mapping only covers first-party collection and stops at the API boundary, you have a blind spot. A complete data map is the foundation for any minimization effort and for responding to deletion requests that may soon extend to inferred data.

Tighten consent controls at the point of collection. The fewer data points that enter the pipeline, the less raw material is available for inference downstream. Real-time blocking of non-essential cookies and scripts, granular consent by category, and location-aware consent experiences all reduce the surface area. This is where consent management and data mapping work together: you need to know what's being collected before you can meaningfully limit it.

The Direction is Clear

State legislatures are moving to close the inference gap. Organizations that treat inferred data as in-scope now, mapping the flows, minimizing the inputs, and building consent practices that account for downstream use, won't be reacting when the next wave of statutes arrives. They'll already be there.

If your privacy program stops at what you collect, it's time to ask what happens to that data after it leaves your hands. Book a demo or Sign Upto see how Concord's unified approach to consent management and data mapping helps close the gap.