Security News

US Lawmakers Challenge Google's $10 Million Deal for Failed Airline's Employee Data

The Record · 9 Oct 2026
Key Takeaway If your business closes, is sold or shares data with AI providers, treat staff emails, messages and payroll records as sensitive information and check that removing names alone will not be relied on to protect people's privacy.

More than 100 members of the US Congress have sent a letter to the CEOs of Google and Spirit Airlines, asking them to stop a deal that would hand Google internal data from the failed carrier in exchange for $10 million. Google wants the data to train AI models and has said it will be deidentified. According to Rep. Steven Horsford, the proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records, and payroll and tax information.

The 114 lawmakers, led by Horsford and Sen. Elizabeth Warren, acknowledged Google's statement that it will not receive personally identifiable information and that a third party will scrub the data before transfer. Even so, they warned that conventional safeguards may not be enough to protect employee privacy in the context of modern AI. Removing names, email addresses or other direct identifiers, the letter said, does not necessarily make a dataset anonymous. Almost 1,000 people in Las Vegas alone lost their jobs when Spirit announced plans to shut down in May.

If the deal proceeds, the lawmakers want a deidentification process that takes former employees' feedback into account, as much employee information as possible excluded, limits on how the data can be used, and an independent employee confidentiality review. Google did not immediately respond to a request for comment, and no press contact could be found for Spirit, which is defunct.

AI data privacy employee data data sharing

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.