How this editorial can be challenged
When a business fails, who gets to decide whether its workers' old conversations become AI training material?
Bankruptcy turns stored records into an asset for creditors, while workers supplied much of their content under the unequal conditions of employment. De-identification can reduce direct exposure but cannot by itself answer whether sensitive messages, safety reports and career histories should be repurposed. The buyer gains a reusable dataset; workers must contest the transfer after the asset has been priced.
A failed company must recover value for creditors and employees owed wages. Thoroughly de-identified data could improve useful models, and forbidding every secondary use would waste information that can be processed safely.
Recovery and privacy are not mutually exclusive. Exclude sensitive employee categories, allow independent review with worker participation, impose enforceable use and retention limits, and require a showing of actual de-identification risk. The buyer should pay for safeguards rather than treating workers' lack of bargaining power as consent.
The Spirit transaction is proposed and subject to court process; the public letter does not prove that Google received raw personal records or that any worker was re-identified. Flock's reported job cuts and Nature's account of scientists' distrust are separate signals, not evidence that the Spirit deal caused either. The ICO's commitments do not mean every developer is compliant.
A public, independent assessment showing that employee records were excluded or irreversibly protected, with binding restrictions, meaningful worker review and no recoverable personal data in the transferred set, would narrow our objection to the sale.
A person does not become a file
The harshest part of a company failure is not the auction. It is the human life scattered through the assets: the emails written to keep a job, the safety report filed in confidence, the accommodation requested in a difficult season. Those records are about people even when the employer owns the servers.
Spirit's proposed sale to Google brings that problem into focus. The 121 lawmakers' letter describes about 100 million emails and 500 million Teams messages, plus employment and tax records. The count comes from the letter's account of public court findings; it is not a measurement of what Google ultimately receives.
Consent under employment is thin
Workers rarely negotiate the terms under which ordinary workplace conversations are recorded, retained and later transferred. They may consent to work systems because refusing would mean losing work. My argument is that such participation should not be retroactively interpreted as consent to a new AI-training purpose.
That is a normative claim, not a ruling about this particular sale. The bankruptcy process has legitimate creditor obligations. But a sale that can exclude sensitive categories and limit downstream use should not skip those options merely because bulk transfer is easier.
Scrubbing is necessary and insufficient
The congressional letter acknowledges Google's statement that personally identifiable information would be removed and third-party scrubbing would occur. That is a meaningful safeguard if done well. The lawmakers ask whether a large collection of messages, payroll information and crew histories can still reveal individuals or small groups through inference.
The right question is not whether every de-identified set is unsafe. It is whether this set has been independently tested, whether sensitive classes were excluded and whether the buyer can be held to limits after it has the data. No public finding cited here establishes a re-identification event.
Three other warning lights
Nature reports scientists who worry about feeding unpublished work into commercial AI tools. OpenAI and Anthropic dispute the suggestion that those particular research ideas were taken from prompts. What remains is a trust problem: unclear boundaries can chill legitimate use even before wrongdoing is shown.
Reuters separately reports planned cuts of roughly 270 jobs at Flock Safety amid backlash over surveillance. That is a company-specific account, not proof that privacy concerns always kill a business. It shows that public acceptance can have a cost that arrives on a different ledger from the product's technical performance.
The regulator's limit and leverage
The UK's ICO says ten major model developers have made or committed to data-protection changes, including clearer transparency and rights mechanisms. It has opened a call for evidence on agentic systems and says autonomous action is not an excuse for poor compliance. Those are regulatory steps, not a certificate of universal safety.
They do suggest a useful design rule: trainable data must have a lawful basis, visible provenance, exercisable rights and safeguards that survive a change in owner. The Spirit court does not answer to the UK regulator, but the underlying question is the same: whose permission counts when AI changes what a record can do?
The bargain worth making
I do not want every dataset locked forever. Research and useful products can benefit from responsibly processed information. I do want the buyer who expects value to carry the burden of showing what was excluded, what remains sensitive and how later use will be constrained.
The Spirit hearing can give a concrete answer or leave a precedent of ambiguity. Years from now, a worker should be able to say what happened to their old records and who is accountable for them. If we cannot give that answer, on what basis do we call the transfer consensual?
Read the reporting
Opinion is ours. The factual record is linked below.
AFA-CWA — congressional letter on proposed Spirit–Google data sale Reuters — lawmakers raise alarm over proposed Spirit data sale ICO — foundation model supervision and agentic AI inquiries Nature — scientists' concerns about AI scooping research