Blog

Privacy-sensitive information and AI: why responsibility stays with the user

New guidelines from Singapore and AI court cases show organisations remain responsible for privacy-sensitive data, even with external AI models.

July 27, 2026 · Victor Angelier

Regulators and judges are arriving at a strikingly consistent message: whoever lets generative AI loose on privacy-sensitive information remains responsible themselves for lawful processing, confidentiality and the rights of data subjects. This holds true even when the underlying model has been built or hosted by a third party. Recent developments in Singapore and a series of legal analyses from the United States make clear that handling sensitive data in AI use is primarily a governance question, and not merely a technical matter.

Singapore clarifies how privacy rules apply to generative AI

The Personal Data Protection Commission of Singapore published guidelines on the use of personal data in generative AI systems. The guidelines clarify how the Personal Data Protection Act applies to personal data used in developing and deploying generative AI, including the allocation of responsibilities between model developers, providers and deploying organisations, and the treatment of online data as "publicly available". Organisations cannot treat all online data as freely reusable: they must define lawful purposes, protect information throughout the entire AI lifecycle and remain responsible for protecting individuals' data, even when using third-party AI tools.

These guidelines build on the earlier published proposed advisory guidelines on the use of personal data in generative AI, which set out the collection and use of personal data for developing and operating generative AI. They address the allocation of responsibilities across the entire lifecycle and the handling of requests from individuals about that processing. Regulators are thus moving towards explicit, lifecycle-focused guidelines, whereby organisations must anticipate obligations around consent, transparency and accountability when using AI on privacy-sensitive information.

According to a summary from the International Association of Privacy Professionals (IAPP), organisations must obtain consent when they use personal data that individuals have provided through products or services to develop generative AI models, unless a PDPA exception applies. Reusing service data for AI training or analysis is therefore not automatically permitted and often requires fresh consent and clear notices, certainly for privacy-sensitive information.

US case law: public AI tools can destroy protection

On the other side of the world, a comparable picture is emerging. An analysis from IPWatchdog on generative AI and trade secret protection states that sharing confidential or proprietary information with a public generative AI platform, without robust contractual and structural safeguards, is legally comparable to disclosure. Unprotected use of public AI tools can destroy trade secret protection. Companies must therefore deploy access controls, logging, need-to-know restrictions and controlled, contractually secure AI platforms for handling sensitive information.

Even sharper is a client alert from law firm Dorsey & Whitney LLP, which analyses a 2026 ruling from a federal court in New York. Using commercially available generative AI tools to process privileged legal information may cause attorney-client privilege and work product protection to lapse, because of platforms' privacy policies and the absence of a protected relationship. Sensitive and privileged legal information must therefore not be processed via uncontrolled, public AI tools; professional users must verify the data processing and confidentiality guarantees of every AI platform they use.

From a technical question to lifecycle governance

Together, these developments show that privacy-sensitive information and AI use primarily constitute a governance and accountability question. Organisations and professionals would do well to clearly distinguish several steps. First: make a clear distinction between public and non-public data when supplying training and input material. Second: obtain or reassess consent when service data is reused for AI purposes. Third: allocate roles and responsibilities across the generative AI chain, but recognise that deploying organisations remain responsible. And fourth: avoid forwarding confidential or privileged information via public AI tools, unless within contractually controlled, non-training environments.

Precisely at this interface, a verification layer such as IamVera.ai can offer support. Vera is not a chatbot or proprietary language model, but a verification layer that enables control by making the verification steps visible. Pre-processing and anonymisation take place on EU infrastructure; the workflow is designed to send only anonymised content to the selected AI models, and if a privacy check fails, nothing is forwarded. In this way Vera can help to map where sensitive data enters an AI workflow, to test contractual and policy safeguards, and to provide greater visibility into usage through verifiable logs and controls. The professional final judgement always remains with the user, who can thus deploy AI without unnecessarily undermining the protection of privacy, trade secrets or privilege.

← All articles