Should Americans worry about how AI uses their personal data?
What the cross-survey evidence says about U.S. attitudes toward AI-driven data collection, and where the law is starting to draw real lines.

Should Americans worry about how AI uses their personal data?
Short answer
Yes — and the worry is grounded in measured public sentiment, not just headline anxiety. Major cross-national surveys from 2023 to 2026 show roughly seven-in-ten Americans have little trust in companies to handle AI-driven personal data responsibly, and roughly eight-in-ten expect companies to use that data in ways people will find uncomfortable. The concern is strongest where children, biometric data, and workplaces are involved, and it is no longer purely opinion: the EU AI Act, in force since 2024, now bans several of the practices that concern the public.
Why people are concerned
Three concrete clusters of worry dominate.
Everyday company AI use. Pew Research found that 81% of Americans who have heard of AI expect that AI use by companies will lead to personal information being used in ways people will not be comfortable with, and 80% expect uses that were not originally intended. Among people familiar with AI, 70% say they have little to no trust in companies to make responsible decisions about how they use it; 77% say the same of social-media CEOs admitting mistakes and taking responsibility for data misuse. (Pew Research, 2023-10-18)
Biometric and workplace surveillance. The EU AI Act (Regulation 2024/1689) names several practices the public consistently says it wants stopped, including untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases, AI that infers emotions in workplaces and schools, and real-time remote biometric identification of people in public spaces for law enforcement. (EU AI Act, Article 5; Baker Donelson, 2024-05-16)
Children’s data. 89% of U.S. adults are very or somewhat concerned about social-media platforms knowing personal information about kids, and 71% are worried about how the government uses people’s data — up from 64% in 2019. (Pew Research, 2023-10-18)
What is true
The concern is cross-survey, cross-demographic, and partially codified into law.
- Europeans put it at the top of the list. Eurobarometer’s Spring 2025 survey (Survey 3222, roughly 26,500 respondents across 27 EU member states) found 84% of Europeans think AI requires careful management to protect privacy and ensure workplace transparency — the highest single item in the survey. (Eurobarometer, Survey 3222)
- U.S. experts are at least as worried as the public. Pew Research reported in April 2025 that six-in-ten AI experts (60%) are extremely or very concerned about AI-driven data misuse; on the same question the U.S. public sits at a roughly comparable level. (Pew Research, 2025-04-03)
- The worry is global, not U.S.-only. KPMG’s 2025 study of 48,340 people across 47 countries lists “loss of privacy or intellectual property” as a top-five risk: 82% concerned, 41% highly concerned. (KPMG 2025)
- The trend line points up. KPMG’s longitudinal data show “worried about AI” rising from 49% in 2022 to 62% in 2024, and the share who say benefits outweigh risks falling from 50% to 41% over the same period. (KPMG 2025)
- Statutory floors exist. The EU AI Act’s Article 5 prohibits untargeted facial-image scraping for facial-recognition databases (5(1)(e)), emotion-inference AI in workplaces and schools except for medical or safety reasons (5(1)(f)), biometric categorization to deduce race, political opinions, religion, sex life, or sexual orientation (5(1)(g)), and real-time remote biometric identification of people in public spaces for law enforcement with narrow exceptions (5(1)(h)). Penalties reach €35 million or 7% of worldwide annual turnover, whichever is greater. (EU AI Act, Article 5; Baker Donelson)
- U.S. children’s privacy rules are being updated. The FTC’s amended COPPA Rule, published 2025-04-22 with a compliance date of 2025-10-22, added explicit data-retention limits, internal risk assessments, and parental-notice requirements for AI/ML-processed children’s data. (Federal Register, 2025-04-22; Loeb & Loeb, 2025-05)
- The U.S. has the lowest trust in its own government to regulate AI. Stanford HAI’s 2026 AI Index, restating Pew’s 25-country data, reports 31% trust in the U.S. government to regulate AI versus a 54% global average. Across all 50 U.S. states, 41% of Americans say federal AI regulation will not go far enough, compared with 27% who say it will go too far. (Stanford HAI AI Index 2026; Pew Research, 2025-10-15)
What is exaggerated, misleading, or unsupported
- “AI is universally rejected.” Not supported. KPMG’s 2025 study still finds a majority view AI systems as trustworthy on average, and Stanford HAI’s 2026 synthesis reports the share saying AI offers more benefits than drawbacks rose from 55% in 2024 to 59% in 2025 — even as the share saying AI makes them nervous rose to 52%. The privacy concern sits on top of net-positive expectations, not in place of them. (KPMG 2025; Stanford HAI AI Index 2026)
- “U.S. AI privacy is unregulated.” Unsupported. The FTC’s 2025 COPPA amendment directly addresses AI/ML training on children’s data; Illinois (BIPA), Texas (CUBI), Washington, California (CCPA/CPRA), Colorado, and Virginia have sectoral laws. The EU AI Act is the floor inside the EU but is not the only statute Americans interact with.
- “Experts and the public disagree on this.” Misleading. On data misuse specifically, Pew’s April 2025 data show experts and the public at broadly comparable levels of concern. The wider public–expert gap on AI is about jobs and personal benefit, not about data misuse. (Pew Research, 2025-04-03)
What remains uncertain
- How effectively the EU AI Act will be enforced. The prohibited-practices provisions have applied since mid-2025, but enforcement data — first penalties, first member-state actions — is thin as of August 2026.
- What workplace monitoring will look like in the U.S. Pew’s February 2025 workplace study reports 52% of U.S. workers worried versus 28% hopeful about workplace AI, but it covers general AI sentiment, not monitoring specifically. (Pew Research, 2025-02-25) A dedicated post-AI-Act poll on emotion-inference and HR-tech has not yet appeared.
- Whether the COPPA amendment will measurably change behavior. Compliance started 2025-10-22; the FTC’s first annual safe-harbor report after that date is the earliest read on real-world impact.
- Generative-AI training-data consent. Lawsuits such as NYT v. OpenAI and Getty v. Stability AI are leading indicators; public-opinion surveys on training-data consent are lagging indicators and uneven.
Where we are likely headed
Editorial judgment, not a research result. Over the next two to five years, three shifts look more likely than not.
First, the EU AI Act’s high-risk obligations (including biometrics, employment, and education) take effect 2 December 2027, and U.S. vendors selling into the EU are likely to extend those practices globally because parallel systems are cheaper than jurisdiction-by-jurisdiction ones. (European Commission)
Second, U.S. state legislatures are likely to keep layering AI-specific amendments onto existing biometric and consumer-privacy statutes; a comprehensive federal AI-privacy law is plausible but not guaranteed given the 31% trust level in the U.S. government’s ability to regulate AI. (Stanford HAI AI Index 2026)
Third, expect the public–private trust gap to stay wide or widen. KPMG’s longitudinal data already show trust falling in 13 of 17 countries; without visible industry accountability (clear breach disclosure, deletion on request, child-data isolation), the worry crosses into policy. (KPMG 2025)
What this means for people and small businesses
For individuals: read the data and permissions screens before clicking accept on a new AI product, especially anything handling voice, face, or children. Use the deletion and export tools that companies are required to provide under existing laws. Treat unexpected reuses of your data as a reportable event, not a curiosity.
For small businesses using AI vendors: ask the vendor three questions before signing. Where does our data live, and who can train on it? What happens to our inputs and outputs when we cancel? Is there a documented subprocessor list and breach-notification timeline? If the answers are vague, the privacy risk is real, even if the feature is cheap.
For anyone building products with AI: the EU AI Act’s Article 5 list — facial scraping, emotion inference, biometric categorization, real-time public biometric ID — is the de facto list of what global users do not want. Building the opposite of that list is cheaper than retrofitting later.
Bottom line
The worry is real, measured, and starting to be regulated. Eight-in-ten Americans expect company AI to misuse their data, and roughly the same share of Europeans want AI managed carefully. The EU AI Act has already drawn hard lines on biometric scraping, workplace emotion inference, and real-time public biometric identification. The U.S. has updated its children’s-privacy rule and is layering state laws, but a comprehensive federal AI-privacy law is unlikely in the near term. Treat the concern as serious, not as panic — and act on the parts you can control, starting with what your data is being used for right now.
Sources
- Pew Research — How Americans View Data Privacy (2023-10-18)
- Pew Research — How the US Public and AI Experts View AI (2025-04-03)
- Pew Research — US workers more worried than hopeful about workplace AI (2025-02-25)
- Pew Research — Trust in the EU, U.S. and China to regulate AI (2025-10-15)
- Eurobarometer — AI and the future of work, Survey 3222 (Spring 2025)
- KPMG — Trust, Attitudes and Use of AI 2025
- Stanford HAI — AI Index 2026, Public Opinion chapter
- EU AI Act, Article 5 — Prohibited AI Practices (Regulation 2024/1689)
- European Commission — Regulatory Framework for AI
- Baker Donelson — Analyzing the EU AI Act: Spotlight on Biometrics (2024-05-16)
- FTC — Amended COPPA Rule, Federal Register (2025-04-22)
- Loeb & Loeb — Children's Online Privacy in 2025: The Amended COPPA Rule



Submit a take
Have a different read on this? Drop a comment below — your email isn't published, and I read every one. Nothing leaves the site until I approve it.