Today, consent is becoming a paperwork problem institutions can no longer hand-wave.
FTC privacy actions this year keep pointing to the same gap. In the cases below, a data broker, a marketing vendor, and public agencies all run into the same practical question. When sensitive data moves through brokers, ad systems, public programs, software pipelines, and AI tools, where is the receipt?
The Federal Trade Commission’s May settlement with Kochava is the clearest example. The FTC said Kochava and its subsidiary would be barred from selling, sharing, or disclosing sensitive location data without affirmative express consent. The agency alleged that location data linked to hundreds of millions of mobile devices could reveal visits to sensitive places such as health facilities and places of worship. The proposed order also requires a sensitive-location data program, supplier assessments to confirm consent, incident reports when third parties share precise location data in violation of contracts, consumer access to names of known recipients, a withdrawal path, and a data-retention schedule.
The Kochava order reads like an operating model. The claim “we had consent” has to survive contact with suppliers, contracts, customer requests, retention schedules, and downstream misuse.
And speaking of consent claims, the FTC’s May action around Cox Media Group’s “Active Listening” advertising service adds another layer. The agency alleged that Cox Media Group, MindSift, and 1010 Digital Works deceived customers by claiming an AI-powered service could target ads using conversations captured from smart devices and that consumers had opted in. According to the FTC, the service did not use voice data and consumers had not meaningfully opted in. The FTC also said clicking through mandatory app terms does not count as opt-in consent for invasive uses such as collecting or using voice data from inside homes.
The FTC’s allegations suggest that AI branding can frame a weak consent story as a technical capability. The audit trail still has to answer the boring questions: what data was collected, what was promised, who supplied it, what the user agreed to, what the buyer was told, and what actually happened.
The federal layer shows the same pressure. GAO’s 2026 report on AI privacy found that OMB’s government-wide AI guidance does not fully address identified privacy risks and challenges for agencies. Experts told GAO that AI use may reveal sensitive information in raw datasets, and that agencies face gaps in tools, workforce skills, privacy impact assessments, consent understanding, and tradeoffs between privacy and AI performance.
Another 2026 GAO report on AI in small business contracting and innovation programs gives the operational version. AI could help agencies with market research, proposal review, fraud prevention, data analysis, and reporting. But SBA had paused most AI use in March 2025 while revising policies, and as of April 2026 the pause remained in place except for seven pilot or pre-pilot projects. GAO also found SBA had not consistently met public AI-use reporting requirements.
That pause shows the actual constraint. Institutions want AI speed, but oversight depends on inventories, roles, privacy rules, public reporting, and documentation. Without those records, AI adoption becomes another place where responsibility dissolves into the tool.
The software layer makes the privacy story even more concrete. CISA’s May alert on Nx Console and GitHub repository compromises described attacks against CI/CD pipelines, code extensions, workflows, and automated accounts. It urged organizations to review logs, audit workflow files, rotate secrets, and watch package sources. That is a different domain from consumer privacy, but the operating lesson rhymes: invisible trust chains need visible evidence.
Across these cases, consent, provenance, and authorization appear to be converging into the same operational gap.
Verification bottleneck
Verification is becoming the scarce institutional function.
- Data moves faster than consumers, agencies, small businesses, and software teams can verify consent, suppliers, recipients, retention, and downstream use.
- AI systems can expose sensitive data through raw datasets, prompts, outputs, workflows, or vendor integrations. Someone has to verify the path and the policy together.
- Software supply-chain attacks show how much trust lives inside updates, extensions, tokens, and automated accounts.
- Watch next: whether consent becomes a living record people can inspect, or stays buried in contracts and terms nobody can reasonably audit.
Opportunities
Where value may appear: consent and provenance receipt packets.
Someone could build practical tools or services for clinics, schools, nonprofits, small agencies, local publishers, law firms, and small businesses: data-source ledgers, supplier consent questionnaires, retention schedules, AI-use inventories, privacy-impact checklists, vendor claim logs, prompt/output provenance folders, and plain-language customer records showing what data was used and why.
Treat this as idea fodder rather than legal, cybersecurity, compliance, procurement, financial, or investment advice. If a system depends on consent, the receipt has to exist before the fight starts.
Sources
- FTC, “FTC to Ban Kochava and Subsidiary from Selling Sensitive Location Data”: https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data
- FTC, “FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million”: https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-require-cox-media-group-two-other-firms-pay-nearly-1-million-settle-charges-they-deceived
- GAO, “Artificial Intelligence: OMB Action Needed to Address Privacy-Related Gaps in Federal Guidance”: https://www.gao.gov/products/gao-26-107681
- GAO, “Artificial Intelligence: Uses and Risks for Small Business Contracting and Innovation Research”: https://www.gao.gov/products/gao-26-107828
- CISA, “Supply Chain Compromises Impact Nx Console and GitHub Repositories”: https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories
