Skip to content

Rights and contracts

AI laws in 2026: what US companies need to know before sharing data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Most AI laws in force in 2026 regulate the companies that build or deploy AI systems, not the businesses that supply their records. For a US company sharing data, the rules that bite are usually older: state privacy laws, contracts, wiretap and trade secret law, and the FTC's deception standard. Check those first, then ask what your buyer owes.

Key takeaways

  • AI-specific laws mostly place duties on developers and deployers; data suppliers feel them through buyer documentation requests.
  • State privacy laws apply directly when licensed records contain personal information, and some reach employee and business contact records.
  • Your own privacy notice and customer contracts can restrict sharing even where no statute does.
  • Call recordings, chat transcripts and email archives raise consent questions under wiretap laws that long predate AI.
  • Each law is assessed deal by deal with counsel, because the same dataset can raise different issues for different buyers and uses.

Which AI laws actually apply to a company supplying data?#

The AI laws that apply to a data supplier are mostly general laws about personal information, communications, confidentiality and fair dealing, not the new statutes with AI in their names. Those newer laws are written for model developers and for businesses that use AI to make decisions about people.

A general counsel preparing to license support tickets, CRM histories or engineering records should therefore sort the rules into two groups: laws that bind the company directly because of what is in the records, and laws that bind the buyer and reach the company only through contract and documentation requests. The table below is a starting map, not a complete list, and every row may apply differently depending on your records and your buyer.

Which AI laws actually apply to a company supplying data?
Law or law familyWhat it governsApplies to data suppliers?
State comprehensive privacy laws, such as the CCPACollection, sale and sharing of personal informationYes, directly, when licensed records contain personal information
GDPR and UK GDPRPersonal data of people in the EU and UKYes, if records include EU or UK personal data
Colorado AI Act (repealed and reenacted in narrower form by SB 26-189 in May 2026, effective January 1, 2027)As reenacted, mainly consumer-notice duties for certain AI systems, enforced by the Attorney General; the original high-risk-system duties were scaled backRarely directly; buyers may ask about intended uses
California AB 2013Training data documentation by generative AI developersIndirectly; the developer may ask you to describe your dataset
EU AI ActProviders of AI systems and general-purpose AI models in the EU marketIndirectly; buyers may need inputs for training content summaries
FTC Act Section 5Unfair or deceptive practices, including broken privacy promisesYes; what you license must match what you told people
Federal and state wiretap lawsRecording and intercepting communicationsYes, for call recordings and some chat or session data
Trade secret lawConfidential business informationYes, both to protect your secrets and to respect others' secrets you hold
Sector laws such as HIPAA, GLBA, FCRA and COPPAHealth, financial, credit report and children's dataYes, wherever those data types appear in the records

Why AI-specific laws rarely bind the supplier directly#

AI-specific laws rarely bind the supplier because their duties attach to building, offering or deploying an AI system, and a company licensing historical records does none of those things. The obligations to publish training data documentation, assess risk or explain automated decisions sit with the developer or the deployer.

The supplier still feels these laws. A developer that must describe its training sources will ask you for provenance, date ranges, whether personal information was present and how it was removed. Expect those requests in diligence questionnaires and in the license itself, often as representations you are asked to sign.

  • Where the records came from and which systems produced them.
  • The date range covered and how recently the records were collected.
  • Whether the records contained personal information and what preparation removed it.
  • What rights you hold to license the records and any restrictions on use.
  • Whether any records came from third parties, such as customers or vendors.

What state privacy laws expect before records leave the company#

State privacy laws expect a company to know whether its licensed records contain personal information and, if they do, to have a lawful basis and accurate notice for disclosing it. Under several state laws, making personal information available to another business for value may count as a sale, which can bring opt-out and contract requirements.

Properly de-identified information is usually treated differently, but the definitions tend to require more than deleting names. Many expect technical measures against re-identification plus public and contractual commitments, so the preparation method and the license terms both matter.

The list of states keeps growing: comprehensive privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026. Coverage also differs by state. California's law can reach employee and business contact records, which matters for HR files, email archives and CRM contact histories, while the Colorado Attorney General states that the Colorado Privacy Act does not cover people acting in a commercial or employment context. Map which states' residents appear in each record family before deciding what preparation is needed.

Some companies that license data also ask whether state data broker registration laws reach them. The answer turns on how each law defines a broker and on whether you have a direct relationship with the people in the records, so treat it as a separate question for counsel.

Older laws that matter most for operational records#

Operational records raise legal questions that predate AI, and those questions usually decide the licensable scope. Recorded sales and support calls can trigger consent questions under federal and state wiretap laws, especially in states that require every party's consent. Chat widgets and session replay tools on websites have drawn similar claims.

Trade secret law cuts both ways. Licensing your own playbooks or pricing logic may weaken secrecy protection unless the license keeps confidentiality obligations in place, and records that hold a customer's confidential information may be covered by an NDA or a confidentiality clause. The FTC Act matters wherever your privacy policy, terms of service or sales materials promised something the license would contradict.

A pre-sharing checklist for general counsel#

A pre-sharing checklist turns a broad legal question into a set of documents to pull and decisions to record. Work through it before any sample leaves the company, and keep the answers in one file that the rights review and the buyer's diligence can both use.

  • Map the record families: personal information, employee data, communication content, customer confidential information and third-party code.
  • Identify where the people in the records live, including any EU or UK residents.
  • Collect the privacy notices in effect when the records were created and the current version.
  • Pull customer contracts, NDAs and vendor terms for confidentiality, data use and no-AI-training language.
  • Choose the preparation method, such as removal, de-identification or aggregation, and document it.
  • Ask the buyer which AI-law obligations it carries and what it needs from you to meet them.
  • Allocate risk in the license: limited representations, permitted use, deletion and audit terms.

Illustrative example: a software company maps its exposure#

Illustrative: a fictional accounts payable software company in Ohio wants to license Zendesk tickets linked to Jira issues and GitHub pull requests. Its customers are mostly US businesses, with a few in Europe. Counsel finds that the privacy notice mentions service providers but not licensing, that ticket text includes names and email addresses of customer staff and occasional invoice numbers, and that several enterprise contracts prohibit using customer data to train AI.

The company excludes tickets from the restricted customers and from European accounts, removes personal details and invoice numbers, and updates its privacy notice for future records. It gives the buyer a written description of sources, date range and preparation method to support the buyer's own disclosures. The licensed scope is narrower than the first idea, but every remaining record has a documented basis.

SourceX handles legal review in the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Contracts, notices and the record types in scope are reviewed before any preparation starts, and each party's counsel assesses the applicable laws for that specific deal. SourceX does not give legal advice.

The results go into a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization. That single record answers most of the documentation questions a developer brings from its own AI-law obligations, without the supplier rebuilding the answers for each request.

Frequently asked questions

Is there a federal law that governs licensing business data for AI training?

At publication there is no single federal statute written for licensing business records to AI developers. Federal exposure usually comes through existing law: the FTC Act, sector laws such as HIPAA, GLBA and FCRA, copyright and federal wiretap law. Congress and federal agencies continue to debate AI rules, so confirm the current position with counsel before signing.

Does de-identifying the records take them outside privacy laws?

Often, but only if the preparation meets the specific law's standard. Many definitions require technical safeguards against re-identification plus commitments not to re-identify, and some require the recipient to make the same commitment. Removing names alone may not be enough, especially for free-text records such as tickets and emails.

Are we responsible for what the buyer does with the data?

Your exposure depends largely on the license. A clear permitted-use clause, a ban on re-identification, limits on use for decisions about individuals and audit rights reduce the chance that a buyer's conduct reflects on you. Counsel should also review what you knew about the intended use when you signed.

Does the buyer's location change which laws apply?

It can. Transfers of personal data outside the United States may raise cross-border rules, and some national security rules restrict certain transfers of sensitive personal data to foreign parties. Screen the buyer's ownership and location early, before preparation work begins.

How often should we revisit this review?

Revisit it for each new deal and whenever a license is renewed or expanded. State AI and privacy laws continue to change, and a scope that was clean for one buyer and one use may not be for the next.

Sources

  • The Colorado AI Act (SB 24-205), signed May 17, 2024, was originally effective February 1, 2026; its effective date was delayed to June 30, 2026, and on May 14, 2026 Governor Polis signed SB 26-189, which repealed and reenacted the law in a narrower form effective January 1, 2027. Source
  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026. Source
  • The Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context and does not apply to data maintained for employment records purposes. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify