Google’s Spirit Data Deal Raises $10MN Question: Should AI Developers Be Allowed to Buy Enterprise Data for Training?

Google’s bid to purchase data from Spirit Airlines’ bankruptcy selloff raises questions over whether enterprise data should be sold to AI developers for training

5
Security, Privacy & ComplianceNews

Published: August 25, 2026

Nicole Willing

Google has bid $10MN to purchase data from bankrupt U.S. carrier Spirit Airlines, raising a broader question for enterprises. Should AI developers be able to buy the data businesses generate, particularly when that data contains years of operational information, employee activity and customer interactions?

Court filings show that Google was selected as the successful bidder for Spirit’s “deidentified data” at an August 14 bankruptcy auction, beating AI training company Mercor with a $10MN offer. Mercor was named the alternate bidder at $7.5MN.

The transaction still requires approval from the U.S. Bankruptcy Court for the Southern District of New York. A hearing originally scheduled for August 19 has been postponed until September 9 following an objection from the Association of Flight Attendants-CWA (AFA), which represents Spirit’s former flight attendants.

The dataset contains extensive records generated through the airline’s day-to-day operations, including communications, employee records, workflow data and operational information, which makes it valuable to AI developers.

Spirit is looking to sell off its customer data separately, according to a court filing by Dylan Friesner, Vice President in the Restructuring and Special Situations Group of Spirit’s investment banker PJT Partners:

“The Debtors are separately conducting a marketing process for their customer list and anticipate seeking approval for a sale of their customer list at a future hearing.”

Can Scrubbed Data Still Reveal Information?

Under the current proposed sale agreement, a third-party agent will process the dataset before it is transferred to Google.

The agent must take measures to remove or transform data so that it cannot be associated with, used to infer information about, or linked to a particular consumer and excludes categories of personal data covered by data protection laws. But the agreement also requires the process to preserve “referential integrity across the data.”

The AFA noted that this presents a risk that Google can infer information even though it has nominally been removed. Google can also transfer the “deidentified data” to third parties, provided that it contractually obligates those parties to comply with the terms it has agreed to.

The data contains a substantial amount of employee-generated information. According to the AFA’s objection, Spirit’s dataset includes productivity and collaboration data, workflow and process information, HR and legacy operations data and other corporate records. The asset schedule includes 1.09 million time-card records, 175,658 employee records, 3.4 million payroll records and 148,018 employee tax forms. It also includes 100 million emails, 17 million OneDrive items, 20.5 million SharePoint items and 500 million Microsoft Teams items.

The union argues that employees need stronger protections around how this information can subsequently be used. The union has asked the bankruptcy court to exclude flight attendant information from the transaction and prevent it from being transferred, licensed, accessed or used by the buyers or third parties.

The AFA said the transaction’s safeguards are designed around identifying consumers, while much of the material being transferred concerns employees.

“The privacy architecture of this transaction is consumer-facing; its payload is disproportionately employee-facing,” the AFA argued. “Hence, the employee data is far more confidential than the customer data, yet receives far less protection than the customer data.”

The case illustrates why data governance needs to account for context as well as identity. The AFA argues that removing a person’s name from a customer interaction, employee record or internal conversation does not necessarily remove the sensitivity of the information contained within it.

Should Enterprises Be Able To Sell Data for AI Training?

Friesner’s filing indicates how the value of enterprise data is changing. The AI developers were particularly interested in customer data:

“[O]ne initial bid requested certain customer list information; however, by the first round of the Auction, the most competitive bidders had agreed to bid on an asset schedule that expressly excluded PII.”

The auction also shows that data governance was part of the commercial negotiations.

Mercor outbid Google’s initial $5MN offer, proposing to pay $5MN using Google’s proposed third-party process, or $7MN if Mercor could use its own tools to remove identifying information. After further bidding, Mercor offered $10MN subject to using its own process rather than a third party.

Friesner noted that Spirit considered “noneconomic factors, such as whether the sale would provide for a documented and acceptable deidentification process for the Deidentified Data. The Debtors emphasized that, given various privacy laws and other process considerations, these noneconomic factors may be outcome-determinative.”

Data generated through everyday business operations has traditionally been treated as an internal corporate asset, but it is becoming potentially valuable training and evaluation material for AI developers looking for new sources of data to continue advancing their models, this case with real-world examples of workplace interactions. The data can offer a record of how people collaborate, make decisions and complete work inside an enterprise, which public Internet data cannot show.

Suvish Viswanathan, Head of Marketing Europe at Zoho, said in previous CX Today roundtable discussion that enterprise AI conversations increasingly come back to “safety” and control over where data goes.

“There is also this conversation around safety and how much data is in my control, how much of my data is moving out of the system to train public models and things like that.”

“To me this is a very interesting court case,” identity and access management consultant Robin Rahman wrote in a LinkedIn post.

“Where do we draw a line regarding legitimate interest to process the data? As well as using this real-world data for the purpose of training AI models of a third party, remember consent was given to Spirit Airlines not Google.”

“The claim is that the data cannot be used to re-identify the person, meaning anonymization. In that case it is no longer personal data. However, if there is a reasonable way to identify individuals (pseudonymization), it remains personal data.” Rahman added.

“One thing is for sure; this court case will set a precedent for datasets of bankrupted companies. Is this the new digital gold?

The Spirit case is striking because bankruptcy changes the commercial context. Data that was collected while the airline was operating is now being treated as an asset that can be sold alongside other company property.

That creates a difficult question for enterprises adopting AI: Who controls the information created by employees while delivering customer experiences? Should employees have a say when their work becomes part of an AI training dataset? And should those rules change when the company enters bankruptcy?

Data governance may need to account for more than regulatory compliance and cybersecurity. Enterprises may also need clear rules governing whether operational data can be sold, licensed or repurposed for AI development, particularly when it contains employee-generated content.

The September 9 hearing could provide an early indication of how courts approach the growing market for enterprise data as an AI asset.

Security and Compliance
Featured

Share This Post