Donald Gainsborough is a political strategist and a leading voice in the evolution of legislative technology policy, currently serving at the helm of Government Curated. With a career built on navigating the friction between rapid digital innovation and the slow-moving gears of bureaucracy, he has become a go-to advisor for understanding how local mandates impact global tech giants. As the New York City Council begins to exert its influence over the titans of the artificial intelligence industry, Gainsborough provides a unique perspective on the intersection of urban governance and the high-stakes world of data privacy. Today, we sit down to discuss the implications of the city’s recent summons to major AI developers and the underlying data mechanisms that are fueling the current regulatory firestorm.
The New York City Council is currently calling on major developers like OpenAI and Anthropic to answer for their data practices; what does this summon signal for the broader tech industry?
This move by the Council is a definitive signal that the era of “move fast and break things” in the AI space is meeting a very hard wall of municipal accountability. By bringing leaders from companies like OpenAI and Anthropic into a formal hearing, the city is asserting that it will not be a passive observer while these models are trained on the digital footprints of millions of New Yorkers. It is a bold move to bridge the gap between abstract algorithmic development and the tangible privacy concerns of citizens who feel their data is being harvested without clear boundaries. We are seeing a shift where local governments are leveraging their market size to demand the kind of transparency that has been missing at the federal level, specifically regarding how training data is sourced and the ethical cost of that acquisition.
When we look at the mechanics of how these companies gather information, how do things like first-party and third-party cookies play into the larger conversation about AI training sets?
To understand the scale of data ingestion, you have to look at the bedrock of web tracking, which begins with first-party cookies that sites use to remember your language preferences or login status. While these seem harmless and functional, the real complexity arises with third-party cookies—those set by domains other than the one you are currently visiting—which are the primary tools for the aggressive marketing and advertising efforts we see today. These cookies act as breadcrumbs that allow companies to build incredibly detailed behavioral profiles, which are then used to “teach” AI models how humans communicate, shop, and think. The Council is essentially asking these developers to prove that their models aren’t just sophisticated aggregators of this third-party data, which is often collected and sold in ways the average user would find startlingly intrusive.
Many platforms argue that certain tracking is unavoidable for a website to work; how does the distinction between “strictly necessary” and “performance” cookies complicate the privacy debate?
The technical defense often rests on the idea of “strictly necessary” cookies, which are vital for the proper functioning of a site, such as ensuring a privacy banner appears or remembering a user’s choice to opt-out. Because these are essential for the site to even load correctly, companies typically don’t allow users to opt-out of them, and they are generally not classified as a “sale” of data under frameworks like the CCPA. However, the gray area expands when we talk about performance cookies or functional cookies that monitor site health and user interactions to “improve the experience.” The debate in the NYC hearing will likely center on whether AI firms are using these “performance” labels as a catch-all to justify the collection of massive data streams that ultimately serve as fuel for their proprietary models.
If a user decides they don’t want their information being part of the “sale of personal data,” how effective are the current opt-out mechanisms like the toggle switches we see today?
The current opt-out systems, while legally required in many jurisdictions, are often designed with significant friction that discourages the average person from actually using them. Even when you find the toggle switch to opt-out of the “sale” of your personal information, that choice is usually limited to the specific browser and the specific device you are using at that moment. Because many of these companies do not track your privacy preferences across different devices or various properties, your decision to protect your data on your phone doesn’t automatically carry over to your laptop. This fragmentation means a person has to manually opt-out dozens of times across their digital life, a reality that the NYC Council is likely to challenge as they push for more universal and persistent privacy protections.
Looking at the technical side, why is it that these privacy settings don’t follow a person across different platforms, and what does that mean for data integrity for AI training?
The industry often defends this limitation by stating they don’t want to track you across different properties just to sync a privacy setting, which is a bit of a circular argument. When a site warns you that your selection will only take effect on “this browser, this device and this website,” they are operating within a siloed technical framework that prioritizes the immediate session over the user’s long-term intent. For AI developers, this creates a data landscape that is both incredibly deep and frustratingly disconnected, requiring them to use sophisticated identity resolution to stitch together a profile. This “stitching” process is exactly what regulators are worried about, as it often happens behind the scenes and bypasses the explicit “do not sell” commands that a user might have toggled on a different device.
What is your forecast for the relationship between municipal government and AI developers?
Over the coming period, specifically from 2026 to 2028, we will see a dramatic move toward localized “data sovereignty” laws where cities like New York set the global gold standard for transparency. I predict that we will move away from the “toggle-per-site” model toward a centralized digital identity where a user’s privacy choices are respected across all platforms by default, rather than by exception. This will force AI companies to move toward “clean room” data practices where they must prove the provenance of every byte used in their training sets. It won’t be enough to say the data was “available”; they will have to show it was “consented,” and that shift will fundamentally change the economics of the entire technology sector.
