Google Spirit Airlines AI data deal draws Congress warning

Google Spirit Airlines AI data deal draws Congress warning

A group of 114 US federal lawmakers is pressing Google and Spirit Airlines to drop a deal that would hand the tech company a large archive of the defunct carrier's internal data. Google wants it to train AI models and would pay $10 million.

The letter went to the CEOs of both companies on Thursday. It was led by Rep. Steven Horsford, a Democrat representing a Nevada district, and Sen. Elizabeth Warren, a Democrat from Massachusetts. The lawmakers argue that the safeguards Google has promised may not be enough to protect the privacy of former Spirit employees.

What is in the data set

According to a press release from Horsford, the proposed sale covers a very large amount of workplace communication and HR material. It includes:

  • about 100 million emails
  • around 500 million messages sent through Microsoft Teams, the corporate chat platform
  • employment contracts
  • employee and timecard records
  • payroll and tax information

Google has said the data will be deidentified before it is used. It has also stated that it will not receive personally identifiable information and that a third party will scrub the material before the transfer.

The lawmakers acknowledge those commitments in their letter but remain unconvinced. "While we understand that Google has stated that it will not receive personally identifiable information and that the data will undergo third-party scrubbing before its transfer, we are concerned that conventional de-identification safeguards may not be sufficient to protect employee privacy in the context of modern artificial intelligence," they wrote.

Why removing names may not be enough

The core of the objection is technical. Stripping out obvious identifiers does not automatically turn a data set into something anonymous, the letter says.

"Removing names, email addresses, or other direct identifiers does not necessarily make a dataset anonymous," the lawmakers wrote.

Internal emails and chat messages carry a lot of context. Job roles, shift patterns, locations, writing style and references to colleagues can all point back to specific people, even after names are removed. Payroll, tax and timecard records add another layer of sensitive detail. The concern raised in the letter is that modern AI systems trained on such material could make that kind of re-identification easier.

The workers behind the data

The letter also has a local angle. Spirit announced plans in May to shut down. In Las Vegas, parts of which fall within Horsford's district, almost 1,000 people lost their jobs at the airline, according to the press release.

Those former employees are the people whose messages, contracts and pay records would end up in Google's training pipeline. The $10 million payment would go to the failed carrier, not to them.

What lawmakers are asking for

The main request is that the deal be halted. If Google and Spirit decide to go ahead anyway, the lawmakers want several conditions in place. According to the press release, the companies should:

  • build a deidentification process that takes feedback from former employees into account
  • leave out as much employee information as possible from the transfer
  • set limits on how the data can be used
  • carry out an "independent employee confidentiality review"

Google did not immediately respond to a request for comment. Because Spirit is defunct, no press contact could be found for the airline.

Our Take

This case shows how the hunt for AI training data is moving into new territory. Public web content has already been scraped at scale, so internal corporate archives from companies that no longer exist start to look like a valuable resource. A bankrupt or shuttered business has every reason to sell, and its former staff have little say in the matter.

The lawmakers' doubts about deidentification are not new. Regulators in Europe have already taken action over weak anonymization, as seen in the IQVIA fine over health data. Workplace emails and chats may be even harder to clean than structured records, because the identifying details are buried in free text.

The deal also fits a wider pattern of AI companies looking for new data sources, from voice recordings of Claude users to Google's own push for deeper access to user files on desktop. For security and privacy teams, the lesson is that internal communications may outlive the company that produced them. It is worth watching whether Google responds publicly, whether the transfer goes ahead with the conditions lawmakers proposed, and whether this sparks broader rules on selling employee data from defunct firms.