CalPrivacy Seeks Input on AI Inference and Reidentification Risks: What Businesses Need to Know
Authors
Jason M. Schwent , Hannah Donahue
On August 5, 2026, the California Privacy Protection Agency (CalPrivacy) Audits Division issued a request for input on emerging technology, inference, and identifiability. The request signals possible future audit and compliance requirements and provides insight into how California regulators view privacy risks in artificial intelligence (AI), analytics, and machine learning. The request also serves to help the new Audits Division develop audit frameworks and compliance inquiries under the California Consumer Privacy Act (CCPA). The division plans to proactively assess how organizations apply privacy and cybersecurity requirements, identify compliance challenges, and spot emerging risks.
Focus Area One: Inference
Looking closer at the request: It focuses on technologies that can infer sensitive information from data that is not itself sensitive. CalPrivacy identifies several types of inferences:
- Probabilistic inferences predict the likelihood that a person has a characteristic or condition.
- Latent inferences use machine learning to identify hidden patterns and derive attributes a person never provided.
- Emergent inferences arise when advanced models unexpectedly infer sensitive traits they were not designed to detect.
The agency wants to know how organizations can detect sensitive attributes in AI systems and how auditors can assess a model’s ability to infer information that was never collected. It is also examining how to separate statistical correlations from inferences used in decisions.
This raises a key compliance question for regulators: When does a model-generated prediction become personal information or sensitive personal information under privacy law?
Focus Area Two: Reidentification and Deidentification
The request also addresses reidentification risks in modern data systems and AI models, including:
- Linking datasets across systems and contexts
- Model inversion and extraction attacks
- Exposure of training data through model outputs
- Membership and attribute inference attacks
CalPrivacy also seeks input on “robust and defensible” deidentification standards, especially for data used to train or interact with machine learning models. It is also considering whether combining services in one technology stack increases reidentification risk.
These questions matter as organizations combine first-party, third-party, and AI-generated data, offering expanded opportunities for re-identifying data with its owner and making it harder to determine whether information is truly de-identified.
Why the Request Matters
The request creates no new legal duties, but it may preview regulatory priorities. The Audits Division appears focused on how privacy risks arise in real systems, including AI applications, model architectures, data flows, and vendor integrations.
The request indicates that regulators are looking beyond traditional privacy issues to advanced analytics, predictive modeling, and connected technology systems. As a result, businesses should expect closer review of:
- AI governance
- Data minimization
- Vendor and service-provider relationships
- Deidentification methods
- Monitoring and testing model outputs
- Privacy risk assessment records
Key Takeaways
Organizations subject to the CCPA should review their governance practices against the issues CalPrivacy raised, including:
- Whether AI systems can infer sensitive attributes from nonsensitive data
- How the organization uses those inferences in products, services, or decisions
- Whether de-identification controls work effectively
- Risks from combining datasets, models, vendors, and platforms
- Whether records can demonstrate compliance during an audit
Looking Ahead
CalPrivacy calls this request for input the first in a series of technical inquiries from its Audits Division, signaling continued attention to emerging technology and AI privacy risks. Organizations should track these developments and assess whether their privacy programs address inference, identifiability, and machine learning governance.
Businesses with questions about CalPrivacy’s request or related compliance duties should contact Clark Hill’s Data Privacy, Protection & Cybersecurity Team for help assessing risk, strengthening compliance, and preparing for regulatory scrutiny.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author(s) only and are not necessarily the views of Clark Hill PLC or Clark Hill Solicitors LLP. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.