GAO Diagnoses AI Privacy Risk. It Misses the Records Problem.
The report that almost gets there
I spent some time with a new Government Accountability Office report on artificial intelligence and privacy, and it is a solid piece of work, as GAO reports usually are. It is careful, structured, and methodical, and it does exactly what you would expect: it maps a problem space and shows where policy and guidance are not keeping up with technological change.
As I read through it, however, I kept coming back to the same conclusion: this is not really a privacy story. It is a records story, even though the report never quite calls it that.
The GAO team convenes experts, identifies 10 categories of privacy risk, and lays out 13 implementation challenges federal agencies face when using AI. It then evaluates whether Office of Management and Budget guidance adequately addresses those challenges, and the answer is that it does not, at least not fully or coherently.
The report identifies familiar risks, including data re-identification, secondary use of data, lack of transparency, aggregation of data into new inferences, and the difficulty of separating sensitive data once systems embed it. The challenges are just as familiar, ranging from gaps in the law and a lack of technical capability to workforce shortages, inconsistent privacy impact assessments, and the constant trade-off between performance and privacy.
What the report is actually describing.
All of this is accurate and unsurprising, but when you step back from the policy framing and examine what it actually describes, a different pattern emerges.
The report documents that organizations do not know how they use data, cannot reliably trace their movement across systems, cannot reconstruct how they make decisions, and cannot consistently document the reasoning behind those decisions.
Each of those statements points to a specific evidentiary gap. Together, they describe an environment in which actions occur without full recording, yet one that supports accountability.
That combination of failures is not just about privacy. It reflects a deeper inability to create, capture, and manage records that function as evidence over time.
AI systems do not lack intelligence. They lack memory.
AI systems do not lack memory in the computational sense, as they rely on vast stores of data and significant processing power. They optimize for recall and pattern recognition at scale.
What they lack is memory in the archival sense: the ability to produce and retain structured evidence of what happened, why it happened, and how it can be understood later.
They do not reliably generate records of data provenance, transformation, aggregation, or decision pathways. They do not consistently capture how purpose, consent, and use evolve. Instead, they generate outputs.
Outputs alone are not evidence because they do not include the chain of reasoning required to interpret them, challenge them, or reuse them responsibly.
Secondary use is a records failure.
The report identifies the secondary use of data as a major privacy risk and frames it as a policy problem to be addressed through guidance and controls. It describes how organizations reuse data collected for one purpose for another, often without clear authorization or awareness.
From a records perspective, however, this is a failure to capture and maintain the context of use as part of the record.
Records management has always treated purpose, context, and use as core elements of control. Those elements allow organizations to determine whether reuse is appropriate, authorized, and consistent with original intent.
By contrast, AI systems treat reuse as a default condition rather than an exception. They move, aggregate, and recombine data at scale. When they do not document that movement in a structured way, governance becomes impossible because the context needed to interpret use has already been lost.
Transparency depends on documentation.
The report presents the same pattern in its discussion of transparency by framing the issue as the public not knowing how organizations use their data. This framing suggests a communication problem, but it is actually a documentation problem.
You cannot explain what you cannot reconstruct.
Transparency depends on records that capture the data used, the processing applied, the logic followed, and the decisions made. These are not optional artifacts. They are the foundation of explainability.
If those records do not exist or are incomplete, transparency becomes performative rather than real, as organizations are left to describe processes they cannot fully demonstrate.
The problem of disentanglement
The report presents the difficulty of disentangling sensitive data once systems embed it as a technical limitation that is hard to overcome.
From a records and information perspective, systems that fail to maintain structured relationships among data elements, their origins, and their transformations produce this predictable outcome.
If you do not build those relationships into the system as part of its documentation layer, then you lose the ability to separate, interpret, or control data over time.
You cannot recover disentanglement after the fact. You must design for it at the point of creation and capture, and that design depends on records principles established over decades.
PIAs and the illusion of control
The report’s discussion of privacy impact assessments is equally revealing, because it highlights inconsistency in how agencies document and evaluate risk.
At its core, a privacy impact assessment records the reasoning behind risk. It should document the identified risks, the assumptions made, the accepted trade-offs, and the implemented mitigations.
When those assessments are inconsistent, the problem is not just procedural. It reflects a failure to standardize the creation of governance records.
Without those records, organizations cannot compare decisions across systems, audit them effectively, or build institutional knowledge about what works and what does not.
The result is the appearance of control without the underlying evidence needed to sustain it.
Guidance is not enough.
GAO recommends additional guidance, improved coordination, and more structured information sharing, and those are reasonable steps within the scope of its mandate.
The limitation is that guidance operates at the policy level, while the problem exists at the evidence level.
You can issue comprehensive and well-crafted guidance and still fail if the systems themselves do not produce the records needed to demonstrate compliance and support accountability.
Guidance without an underlying evidence architecture produces undocumented decisions at scale, which increases rather than reduces risk over time.
The missing layer: governance epidata
What is missing, and what the report implicitly points toward without naming, is a layer of structured documentation that captures not just what systems do but how and why they do it.
This is where the concept of governance epidata becomes useful, because it focuses on recording the reasoning behind decisions rather than just their outcomes.
That includes documenting the evidence considered, the alternatives evaluated, the uncertainties acknowledged, and the risks accepted or rejected.
These are the elements that allow decisions to be understood, challenged, and improved over time, and without them, accountability remains incomplete.
This is a familiar problem.
There is a tendency to treat AI as a fundamentally new governance problem. Still, from a records and information science perspective, it appears to be an acceleration of a long-standing issue.
Organizations have always generated more knowledge than they can capture, organize, and transmit, and records management exists to address that imbalance.
What AI changes is the scale, speed, and opacity of decision-making, making the absence of a robust evidentiary infrastructure much more visible and consequential.
In that sense, the GAO report reads less like a description of a new problem and more like a contemporary expression of an old one.
The actual solution
If you take the GAO report seriously, the path forward is not just a better privacy policy or more detailed guidance.
It requires integrating records thinking directly into the design of AI systems so that they produce evidence as a core function rather than as an afterthought.
Organizations must capture provenance and transformation as records, standardize how they document risk reasoning, embed lifecycle and use controls into data architectures, and treat documentation as infrastructure rather than compliance overhead.
These are not incremental changes. They represent a shift in how organizations think about systems, from tools that produce outputs to systems that produce evidence.
Final thought
The report gets the risks right and accurately identifies the gaps, but it stops short of recognizing the nature of the problem it describes.
The issue is not simply that we lack sufficient rules or guidance. It is that we lack the records needed to make those rules meaningful and enforceable.
Until that changes, AI governance will continue to rely on systems that operate without the ability to fully explain themselves, a fragile foundation for accountability in any domain.


