







To accelerate artificial intelligence development, the government plans to relax consent requirements for access to personal information while introducing tougher penalties for intentional misuse.
Japan relaxes privacy laws to make AI development easy
: Opting out of personal data use won't be an option because Minister says that's a 'very big obstacle' to AI adoption

Japan Cabinet OKs easing data protection law to promote AI development
TOKYO (Kyodo) -- Japan's Cabinet on Tuesday approved a bill to revise the personal data protection law, easing restrictions on using individual inform

Bill to ease data protection law for AI development clears Japan's lower house
TOKYO (Kyodo) -- A bill to revise Japan's personal data protection law passed the House of Representatives on Tuesday, paving the way for eased restri

Spawning.ai
We believe that a future of consenting data will benefit both AI development and the people it is trained on.

Where AI Regulation Stands Today
The White House has released a National Artificial Intelligence Legislative Framework and new executive orders aiming to establish a single, nationwide standard for AI regulation...
AI and Doctrinal Collapse
Artificial intelligence runs on data. But the two legal regimes that govern data—information privacy law and copyright law—are under pressure. Formally, each re
Unlawful by design: Exposing the human rights costs of generative AI - Amnesty International
This briefing examines how standalone generative AI systems, based on unlawful web scraping, are in conflict with international human rights law (IHRL) and standards through their design, development and deployment. While these technologies promise sophisticated automation and efficiency, they rely on data collection and model training practices that abuse privacy rights, enable discrimination, and threaten […]

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.

DataLicenses.org
Machine-readable hints for AI agents/crawlers; easy to adopt, rely on compliance.
Data Minimisation: a Language-Based Approach (Long Version)
Data minimisation is a privacy-enhancing principle considered as one of the pillars of personal data regulations. This principle dictates that personal data collected should be no more than...

Privacy Considerations with AI Tools
Artificial intelligence (AI) tools come in all sorts of flavors. There are notetaking and transcription tools, chatbots, device-wide agentic AI features, grammar and writing tools, translation assistants, AI summaries, and research tools, among others. As a term, “AI” may refer to features in apps, apps themselves, third-party plug-ins, or a...
Artificial Intelligence and the Purpose of Social Systems
The law and ethics of Western democratic states have their basis in liberalism. This extends to regulation and ethical discussion of technology and businesses doing data processing. Liberalism relies on the privacy and autonomy of individuals, their ordering through a public market, and, more recently, a measure of equality guaranteed by the state. We argue that these forms of regulation and ethical analysis are largely incompatible with the techno-political and techno-economic dimensions of artificial intelligence. By analyzing liberal regulatory solutions in the form of privacy and data protection, regulation of public markets, and fairness in AI, we expose how the data economy and artificial intelligence have transcended liberal legal imagination. Organizations use artificial intelligence to exceed the bounded rationality of individuals and each other. This has led to the private consolidation of markets and an unequal hierarchy of control operating mainly for the purpose of shareholder value. An artificial intelligence will be only as ethical as the purpose of the social system that operates it. Inspired by the science of artificial life as an alternative to artificial intelligence, we consider data intermediaries: sociotechnical systems composed of individuals associated around collectively pursued purposes. An attention cooperative, that prioritizes its incoming and outgoing data flows, is one model of a social system that could form and maintain its own autonomous purpose.

Preventing AI extractivism: the case for braiding indigenous data justice with ABS for stronger AI data governance
Artificial-intelligence systems are rapidly reproducing colonial extractivism by harvesting Indigenous linguistic, biometric, geospatial, and ecological data without consent, compensation, or accountability. Biotechnology offers a blueprint for curbing such practices: the Convention on Biological Diversity and its Nagoya Protocol obligate users of genetic resources to obtain Prior Informed Consent, negotiate Mutually Agreed Terms, and share benefits fairly. No comparable framework restrains the digital appropriation that underpins many AI products. Consequently, corporations and states monetize Indigenous knowledge systems under the banners of “open data” and “scientific neutrality,” eroding rights affirmed in the United Nations Declaration on the Rights of Indigenous Peoples (UNDRIP). In response to this rising risk of AI extractivism, we make the case for a binding, sui generis ABS protocol for AI data governance. First, through a series of case studies we demonstrate that AI extraction mirrors the colonial and biopiracy controversies that originally triggered Access‑and‑Benefit‑Sharing (ABS) rules in biotechnology. Second, we translate those rules into a digital register by braiding two Indigenous data‑governance frameworks—OCAP® (Ownership, Control, Access, Possession) and the CARE Principles (Collective Benefit, Authority to Control, Responsibility, Ethics)—inside the ABS triad of consent, terms, and benefit‑sharing. The resulting model grounds technical safeguards in relational accountability and Indigenous legal orders. Such an instrument would compel transparent negotiations with Indigenous rights‑holders, assign enforceable authority over data across the AI lifecycle, and require equitable redistribution of the economic value generated by models trained on Indigenous data. Embedding ABS principles into AI governance offers a decolonial pathway that centers Indigenous epistemologies, promotes ethical foresight, and transforms AI from a vehicle of digital colonialism into a space for algorithmic justice.

Guidelines on transparency obligations for providers and deployers of certain AI systems
These guidelines help providers and deployers of AI systems and competent authorities in ensuring compliance with the transparency obligations under Article 50 of the AI Act.
Search keywords: 個人情報保護法, personal information protection law, personal data protection law * I’m neither “pro-AI” nor “anti-AI.” I’ve been blocked for being perceived as both. —Actually, I’m honestly more anti-AI than pro-AI thus far, aside from specialized models and specific use cases, but I’m willing to consider information that’s new to me

密室で決まったAI特例、個人情報を同意なしで活用 保護と両立手探り

AI開発なら本人同意なく提供 個人情報保護法改正案の問題点とは?:朝日新聞

<社説>個人情報保護法 AI優先の緩和は危険だ:北海道新聞デジタル

実名・住所付きの病歴が本人の同意なく学習される…現役医師が突く高市政権肝いり「国産AI」に潜む“大穴”

個人情報保護法改正案 参院で審議入り 立民“氏名など削除を” | NHKニュース

誰だって秘密にしたい病歴や犯罪歴がAI開発の養分に? 個人情報保護法がもはや「さらし法」に変わる恐れが:東京新聞デジタル