top of page

Data Privacy in an Age of Inference

An analysis of why privacy must protect not only the information people disclose, but also what data systems claim to know about them.

Nicholas E. Stewart

1785344114.png

Privacy law was built around disclosure. It governs what people choose to share, what companies collect, and what they sell. But increasingly, the most consequential information about a person is never disclosed at all. Instead, it is inferred from behavioral data, allowing systems to derive sexual orientation, gender identity, health status, and other sensitive characteristics without an individual's knowledge or consent. Existing privacy frameworks were not designed for this reality, leaving a growing gap between what the law protects and what modern technologies can determine.

Left unaddressed, this gap will continue to erode meaningful privacy protections, expand opportunities for discrimination and surveillance, and leave individuals with few practical ways to challenge or prevent algorithmic inference. Protecting privacy in the age of AI requires moving beyond disclosure-based frameworks toward legal standards that recognize inference itself as a distinct source of harm.

In response, this policy briefing, a collaboration between the Justice Education Project and LGBT Tech, examines how inferential AI has outpaced existing privacy law and why traditional remedies such as consent, access, correction, and deletion are increasingly inadequate. Drawing on recent research, federal enforcement actions, and emerging legal developments, it offers a roadmap for policymakers seeking to build privacy protections that account not only for the data people reveal, but also for what machines can now guess. 

bottom of page