decrypted · 11 october 2026 · ai and llm security · surveillance and privacy

A failed airline's inbox is up for sale to train an AI: whose data is it?

A bankrupt airline's filing cabinet is heading towards a hyperscaler's AI training pipeline, and this week 121 US lawmakers asked Google to stop. Spirit Airlines announced in May that it would shut down, and Google has now proposed paying $10 million for its internal data, reportedly including about 100 million emails and 500 million Microsoft Teams messages. On Thursday the lawmakers wrote to both companies asking them to halt the deal. It is an American sale, but the question belongs to every UK board: when your company fails, who controls what your staff wrote?

What is being sold

According to The Record, the data would also include employment contracts, timecard records, and payroll and tax information, and Google wants it to train AI models. Google says the data will be deidentified. A Google spokesperson told the outlet the company is not seeking to buy personal information, and that data will either be fully excluded or deidentified by an independent third party before Google receives it. The deal is described as proposed, and I could not confirm whether it has closed. The lawmakers acknowledged Google's assurances, then argued that standard deidentification may not protect employee privacy in the age of modern AI.

Why scrubbing is harder than it sounds

Imagine redacting a diary by blacking out every name. The reader still knows who wrote about "the pilot who argued about the Tuesday rota in Las Vegas". Chat is free text, and identity lives in context, not in the name field. The lawmakers put it plainly: "Removing names, email addresses, or other direct identifiers does not necessarily make a dataset anonymous."

The ICO frames anonymisation the same way: the aim is to reduce the risk of identifying people to a "sufficiently remote level", which is a judgement about risk and not a find-and-replace job.

The Secure by Design lesson

The design decision that created this problem was made years ago, and it was to keep everything. Collaboration tools make storage cheap and deletion an afterthought, so a company accumulates a decade of candid conversation. In insolvency, that archive becomes an asset, and the people who wrote it have no seat at the negotiating table.

Secure by Design says the safest data is the data you no longer hold. For a UK organisation that means:

A retention policy is a configuration setting and an uncomfortable meeting.

What it means for UK control

UK GDPR does not stop at the bankruptcy door. In my reading, a buyer who cannot show that identification risk is remote is holding personal data, with the duties that follow, and UK companies should expect insolvency practitioners and AI developers to ask how clean their archives are.

Also this week

Citrix patches a critical NetScaler flaw. Citrix has fixed CVE-2026-107406, a memory overflow that its bulletin rates CVSS v4.0 9.5 and says can lead to remote code execution or a denial of service. It affects appliances configured as a SAML identity provider or service provider, a common single sign-on role. Citrix says it is not aware of unmitigated exploits, and BleepingComputer reports no evidence of exploitation yet, but NetScaler has a long record of being attacked soon after disclosure. Check the configuration, then upgrade to 14.1-73.46, 13.1-64.29 or later. The design lesson is an old one: an internet-facing login appliance is a front door, so it deserves the shortest possible patching window. Separately, Microsoft says the Windows Update certificates expire on 17 May and 19 June 2027, depending on version, after which devices on unsupported Windows versions will lose access to Windows Update. Supported devices need the July 2026 update or later.

An incident response executive is arrested in the ShinyHunters case. BleepingComputer reports that a Canadian executive from the extortion negotiation industry was arrested in Pennsylvania, with the charges described as conspiracy and extortion offences, and that several outlets link the case to the FBI's ShinyHunters investigation. The complaint is sealed, so what is alleged is unclear, and the man is presumed innocent. The wider point for UK boards is procurement: whoever you hire to handle an extortion sees your worst day in detail, so vet them like any other supplier with privileged access.

Sources

If your chat archives and supplier terms need a hard look, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.