Back to news

How AI Is Helping Legal Teams Spot Where Their Consumer Data Is at Risk

Darrow privacy attorney Joe Hughes, writing in the ABA’s Business Law Today, on how AI helps legal teams find where consumer data is exposed — and why privacy litigation is shifting toward data brokers and ad tech vendors.
ABA Business Law Today
read full article

Business Law Today — the American Bar Association Business Law Section’s publication — runs a piece by Darrow privacy attorney Joe Hughes on a question that has become newly urgent for in-house legal teams: not whether their organization collects consumer data, but where that data ends up once it leaves their own systems.

The article’s starting point is a shift in who gets sued. Privacy litigation built around website tracking has historically named the website operator — the healthcare portal, the retailer, the publisher. Hughes argues the center of gravity is moving toward the intermediaries. Darrow analyzed consumer data privacy class actions filed directly in federal courts in the first quarter of 2026 involving allegations of website-based tracking; of the 128 cases identified, over 10 percent targeted advertising technology and data vendors directly rather than the sites that hosted their code.

Courts are giving that theory room to run. In Riganian v. LiveRamp Holdings and Gilligan v. Experian Data Corp., courts declined to accept that collecting data for commercial gain places a defendant outside wiretap liability. In Semien v. PubMatic and Krzyzek v. OpenX Technologies, pseudonymization — long treated across ad tech as a safe harbor — was held not to preclude liability. On the settlement side, Oracle agreed to pay $115 million in 2024, and Google agreed to sweeping injunctive relief over its real-time bidding practices.

The practical obstacle Hughes identifies is visibility. Naming the right intermediary is genuinely hard: in California alone, more than five hundred companies have registered with the state as data brokers, and building a case means defining a class across multiple websites and timeframes, documenting harm, and distinguishing broad consent — a user accepting a general privacy policy — from narrow consent to a specific tracking practice.

This is where the piece makes its case for AI. Legal teams can use it to scan public records and government contracting data for improper data broker arrangements, read tracking behavior on live properties, flag the gap between what a privacy policy promises and what a page actually does, and pattern-match emerging case law for the fact patterns that are triggering liability — work that is impractical to do manually at the scale the ecosystem now operates.

The stakes are set out plainly. In a recent IBM survey, 97 percent of organizations reported an AI-related security incident, and over the last decade just four data breaches involving major data brokers cost U.S. consumers more than $20 billion in losses related to identity theft. Combined with more receptive courts, rising consumer awareness, and expanding state privacy laws, Hughes’s conclusion is that the exposure sitting outside a company’s own walls is now the part most worth mapping.