Measuring Compliance of AI-Generated Content Platforms with Data Protection Regulations: A Computational Framework and Empirical Analysis of Privacy Policy Disclosures

Authors

  • Jiangfeng Hao School of Law, Taiyuan University of Science and Technology, Taiyuan 030024, China

Keywords:

AI-Generated Content; Data Protection Compliance; Privacy Policy Analysis; Regulatory Technology; Natural Language Processing; GDPR; PIPL; CCPA

Abstract

The rapid expansion of AI-generated content (AIGC) platforms, encompassing large language models, text-to-image generators, and code assistants, has intensified concerns regarding whether their privacy disclosures satisfy major data protection regimes, including the EU General Data Protection Regulation (GDPR), China's Personal Information Protection Law (PIPL), and California's Consumer Privacy Act (CCPA). Despite these concerns, there remains no systematic and reproducible approach for determining the completeness and accuracy of platform privacy policies against statutory disclosure requirements. To address this gap, this paper introduces PolicyLens, a computational framework for compliance assessment that: (1) develops a machine-readable regulatory ontology representing 127 distinct disclosure obligations derived from GDPR, PIPL, and CCPA provisions; (2) uses an LLM-based information extraction pipeline to transform privacy policy content into structured evidence of compliance; and (3) aligns the extracted evidence with the ontology to generate multi-dimensional compliance scores. PolicyLens is evaluated using AIGC-Privacy-200, a newly compiled dataset containing the complete privacy policies and terms of service of 200 major AIGC platforms collected between January and March 2026. The dataset covers services headquartered across the US, EU, China, and other jurisdictions. The results show that: (i) only 23% of the platforms fully satisfy the disclosure requirements of any one regulation; (ii) obligations concerning training data provenance and opt-out mechanisms are disclosed least frequently, with compliance rates of 11% and 17%, respectively; and (iii) compared with EU-based platforms, Chinese platforms demonstrate significantly greater compliance with PIPL but lower compliance with GDPR, indicating that privacy policies tend to be drafted around the regulatory requirements of their home jurisdictions. Validation against expert legal audits conducted on a 40-platform subset shows that PolicyLens achieves an F1-score of 0.89 for obligation-level compliance detection. To facilitate further research in regulatory technology, the framework, dataset, and regulatory ontology are released as open-source resources.

Downloads

Download data is not yet available.

References

[1] Bommasani, R., Hudson, D. A., Adeli, E., Altman, R., Arora, S., von Arx, S., Bernstein, M. S., Bohg, J., Bosselut, A., Brunskill, E., Brynjolfsson, E., Buch, S., Card, D., Castellon, R., Chatterji, N., Chen, A., Creel, K., Davis, J. Q., Demszky, D., . . . Liang, P. (2021). On the opportunities and risks of foundation models. arXiv. https://doi.org/10.48550/arxiv.2108.07258

[2] Greenleaf, G. (2021). Global data privacy laws 2021: despite COVID delays, 145 laws show GDPR dominance. Elsevier BV. https://doi.org/10.2139/ssrn.3836348

[3] Voigt, P., & von dem Bussche, A. (2017). The EU general data protection regulation (GDPR): A practical guide. Springer International Publishing. https://doi.org/10.1007/978-3-319-57959-7

[4] Amaral, O., Abualhaija, S., Torre, D., Sabetzadeh, M., & Briand, L. C. (2022). AI-enabled automation for completeness checking of privacy policies. IEEE Transactions on Software Engineering, 48(11), 4647-4674. https://doi.org/10.1109/tse.2021.3124332

[5] Costante, E., Sun, Y., Petković, M., & den Hartog, J. (2012). A machine learning solution to assess privacy policy completeness In Proceedings of the 2012 ACM workshop on Privacy in the electronic society, https://doi.org/10.1145/2381966.2381979

[6] Wilson, S., Schaub, F., Dara, A. A., Liu, F., Cherivirala, S., Giovanni Leon, P., Schaarup Andersen, M., Zimmeck, S., Sathyendra, K. M., Russell, N. C., B. Norton, T., Hovy, E., Reidenberg, J., & Sadeh, N. (2016). The creation and analysis of a website privacy policy corpus In Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), https://doi.org/10.18653/v1/p16-1126

[7] Harkous, H., Fawaz, K., Lebret, R. C. A. m., Schaub, F., Shin, K. G., & Aberer, K. C. A. v. (2018). Polisis: Automated analysis and presentation of privacy policies using deep learning In 27th USENIX Security Symposium (USENIX Security 18), https://www.usenix.org/conference/usenixsecurity18/presentation/harkous

[8] Ahmad, W., Chi, J., Tian, Y., & Chang, K.-W. (2020). PolicyQA: A reading comprehension dataset for privacy policies In Findings of the Association for Computational Linguistics: EMNLP 2020, https://doi.org/10.18653/v1/2020.findings-emnlp.66

[9] Sarne, D., Schler, J., Singer, A., Sela, A., & Bar Siman Tov, I. (2019). Unsupervised topic extraction from privacy policies In Companion Proceedings of The 2019 World Wide Web Conference, https://doi.org/10.1145/3308560.3317585

[10] Zimmeck, S., Goldstein, R., & Baraka, D. (2021). PrivacyFlash Pro: automating privacy policy generation for mobile apps In Proceedings 2021 Network and Distributed System Security Symposium, https://doi.org/10.14722/ndss.2021.24100

[11] Torre, D., Abualhaija, S., Sabetzadeh, M., Briand, L., Baetens, K., Goes, P., & Forastier, S. (2020). An AI-assisted approach for checking the completeness of privacy policies against GDPR In 2020 IEEE 28th International Requirements Engineering Conference (RE), https://doi.org/10.1109/re48521.2020.00025

[12] Xu, X., Xu, W., Ouyang, S., & Li, L. (2025). CA*: Addressing evaluation pitfalls in computation-aware latency for simultaneous speech translation In Findings of the Association for Computational Linguistics: NAACL 2025, https://doi.org/10.18653/v1/2025.findings-naacl.393

[13] European Parliament, & Council of the European Union. (2024). Regulation (EU) 2024/2847 of the european parliament and of the council, (2024). https://eur-lex.europa.eu/eli/reg/2024/2847/oj

[14] Migliorini, S. (2024). China's interim measures on generative AI: Origin, content and significance. Computer Law & Security Review, 53, 105985. https://doi.org/10.1016/j.clsr.2024.105985

[15] Zhang, Z., Shu, K., & Mo, M. (2026). Safemind: A risk-aware differentiable control framework for adaptive and safe quadruped locomotion. IEEE Access, 14, 50246-50269. https://doi.org/10.1109/access.2026.3679520

[16] Chalkidis, I., Fergadiotis, M., Malakasiotis, P., Aletras, N., & Androutsopoulos, I. (2020). LEGAL-BERT: the muppets straight out of law school In Findings of the Association for Computational Linguistics: EMNLP 2020, https://doi.org/10.18653/v1/2020.findings-emnlp.261

[17] Lippi, M., Pałka, P., Contissa, G., Lagioia, F., Micklitz, H.-W., Sartor, G., & Torroni, P. (2019). CLAUDETTE: An automated detector of potentially unfair clauses in online terms of service. Artificial Intelligence and Law, 27(2), 117-139. https://doi.org/10.1007/s10506-019-09243-2

[18] Xu, X., Ouyang, S., Yan, B., Fernandes, P., Chen, W., Li, L., Neubig, G., & Watanabe, S. (2024). Cmu’s IWSLT 2024 simultaneous speech translation system In Proceedings of the 21st International Conference on Spoken Language Translation (IWSLT 2024), https://doi.org/10.18653/v1/2024.iwslt-1.20

Downloads

Published

2026-06-30

How to Cite

Jiangfeng Hao. (2026). Measuring Compliance of AI-Generated Content Platforms with Data Protection Regulations: A Computational Framework and Empirical Analysis of Privacy Policy Disclosures. Decision Making: Applications in Management and Engineering, 9(1), 412–428. Retrieved from https://www.dmame-journal.org/index.php/dmame/article/view/1842