What happened
On October 8, 2026, 119 members of Congress, led by Rep. Steven Horsford (D-NV) and Sen. Elizabeth Warren (D-MA), sent a letter to the CEOs of Google and Spirit Airlines. They asked the companies to halt a deal in which Google pays $10 million for Spirit's internal data to train AI models. Per The Record, the data includes about 100 million emails, 500 million Microsoft Teams messages, employment contracts, timecard records, and payroll and tax information.
Google won the data in a bankruptcy auction. Skift reported that Mercor.io was the backup bidder at $7.5 million, and that an August 14 court filing confirmed the transaction. It also reported that the sale excludes customer data on Spirit's 97.5 million passengers and 52.4 million loyalty members. That detail matters. The dispute is about employees, who never had a customer-style privacy policy to rely on.
Google says it is "not looking to buy any personal information," and that personal data will be "completely excluded or will be deidentified by an independent third party."
The strongest case for the lawmakers
The letter's core claim is technically serious: "Removing names, email addresses, or other direct identifiers does not necessarily make a dataset anonymous." This is correct for free text. Emails and chat messages identify people through context: job titles, routes, a manager's name, a medical leave mentioned in passing, a writing style. A scrubber that removes fields in a payroll table does little against 500 million informal messages. Spirit's roughly 1,000 Las Vegas employees, and thousands more nationally, were also not the ones who agreed to the sale. They lost their jobs, and now their workplace communications are a liquidated asset.
The lawmakers' requests are modest. They ask for a deidentification process that takes former employees' feedback into account, exclusion of as much employee information as possible, limits on how the data may be used, and an independent confidentiality review. None of that would stop the sale.
Why existing law fits poorly
American law does have a template for this situation, but it was built for customers. In 2000, the FTC settled with bankrupt retailer Toysmart. The settlement barred a standalone sale of the customer database, required any buyer to honor the original privacy policy, and required opt-in consent for policy changes. The theory was Section 5 of the FTC Act: selling data against a privacy promise is deceptive. More recently, on March 31, 2025, FTC Chairman Andrew Ferguson wrote to the U.S. Trustee about the 23andMe bankruptcy, saying that "consumers should be able to trust that companies will keep their promises" when it comes to sensitive information.
Both precedents depend on a promise made to consumers. Employee email has no such promise to enforce. Employers typically tell staff their systems are monitored and company-owned. So the Toysmart logic, a broken representation, has nothing to attach to here. The gap is real, and the congressional letter is implicitly asking the companies to fill it voluntarily.
Where the proportionate answer lies
Our view is that this deal should not be blocked and should not set a precedent by default either. Three points follow.
First, bankruptcy sales of data are how creditors, including laid-off workers owed wages, recover value. A rule that made a failed company's data unsaleable would shrink the estate and hurt those same employees. The $10 million is a real input to creditor recoveries. Treating every corporate dataset as untouchable would also chill the ordinary acquisition of failed firms' assets, which is a pro-innovation concern as well as a creditor one.
Second, the right instrument is process, not prohibition. The Toysmart model worked because it set conditions on the transfer. The same approach can be applied to employee data: an independent deidentification audit, filed with the bankruptcy court, that tests re-identification risk on a sample of the actual free text rather than just confirming that name fields were removed. A buyer commitment not to attempt re-identification and not to pass raw data downstream would be a second condition. The FTC already writes versions of this commitment into its orders, defining deidentified data as information with technical safeguards and business processes that prohibit re-identification.
Third, and most important, the free-text problem should be dealt with honestly. If 100 million emails cannot be reliably deidentified, then the honest options are narrower scope or contractual and technical limits on model training use, such as no memorization-prone fine-tuning on raw messages and no output of verbatim content. Lawmakers are right to press on this. They would be on firmer ground asking for those testable commitments than asking for a halt, because a halt gives employees nothing and forecloses the alternative of making the sale safer.
What to watch
The sale still needs approval from the bankruptcy court, so the practical levers are the court process and voluntary commitments from Google and Spirit. If they decline to publish the deidentification methodology, that is itself informative. The longer-term question is whether Congress or the Bankruptcy Code's consumer privacy ombudsman mechanism should cover employee data. Right now the ombudsman and FTC apparatus is oriented toward consumer privacy policies, leaving workers outside it. A narrow fix that extends disclosure and audit requirements to employee records in bankruptcy sales would address that gap without banning data transactions or hardening a precedent that all AI training data is suspect.