In an earlier article in this series, I described a man who applies for jobs and never learns why the doors stay closed. An AI screening system drew a conclusion about him (from the cadence of his speech, from a pattern in his employment history, from an association the model absorbed from biased training data), and that conclusion silently shaped his future. He experienced the consequence. He never saw the cause.
That scenario is not rare. It shows up in the everyday use of AI systems in hiring, lending, insurance, education, and healthcare. The conclusions these systems draw about people are invisible, consequential, and almost entirely ungoverned.
This is not because no one has noticed. Legal scholars have identified the gap precisely and persuasively. What remains missing is a mechanism to close it.
In 2019, Sandra Wachter and Brent Mittelstadt published research demonstrating that existing data protection law, including the European Union’s GDPR, widely regarded as the world’s most comprehensive privacy framework, fails to adequately protect individuals against what they called “high-risk inferences.” Their analysis was specific. The GDPR grants robust rights over input data, the information a person provides. You can access your data, correct it, delete it, or port it to another provider. Those are genuine protections.
But the GDPR provides almost no rights over the conclusions drawn from that data. A credit score, a fraud risk assessment, a hiring recommendation, a diagnostic probability, an insurance determination — each of these is new information about you, generated by the system, that you never provided. And under current law, the person affected has no right to know the inference was reached, no right to see it, no systematic mechanism to contest it, and no path to challenge the basis on which it was drawn.
Think about what this means in everyday life. When you apply for a mortgage, the bank’s AI generates an assessment of your creditworthiness based on your financial data combined with patterns learned from millions of other borrowers. That assessment determines your interest rate, or whether you receive an offer at all. You see the outcome: approved at 6.2 percent or denied. You do not see the inference that produced the outcome. You cannot ask the system why it reached its conclusion. You cannot compare its reasoning against your own understanding of your financial situation. The conclusion was drawn in silence, acted upon immediately, and filed where you will never find it.
The same dynamic operates in healthcare. An AI system reviews your medical records and generates a risk prediction, perhaps flagging you as likely to develop a chronic condition within five years. That prediction may influence your insurance premiums, your treatment options, or the priority you receive in a resource-constrained health system. You did not provide that prediction. The system generated it. And you may never know it exists.
Wachter and Mittelstadt named this governance gap with precision. Their work explicitly called for an operational mechanism to close it. That mechanism did not yet exist.
Two developments since their research point toward what that mechanism might look like.
The first is a legal precedent. In 2025, Denmark proposed a pioneering amendment to its copyright law that gives every individual ownership rights over their own body, facial features, and voice. The proposal treats a person’s likeness not merely as something protected by privacy but as something that belongs to them, owned property, not just guarded information.
This matters not because it solves the inference problem; it does not; but because it establishes an extensible principle. Denmark’s proposal protects the outward, recognizable self: what you look like, what you sound like. It does not reach the conclusions a system draws about you. But the ownership principle it establishes, that something generated from your identity belongs to you, is the seed from which a broader framework can grow.
Consider the natural progression. If you own your likeness (your face, your voice), then why not the conclusions drawn from your behavior? If a system generates a prediction about your health, your creditworthiness, or your employability based on data you provided, should that prediction belong to the system that generated it or to the person it describes?
The progression I propose is: likeness, then inference, then learning contribution. Each step extends the same ownership principle one layer deeper. From the surface of the self (what you look and sound like) to the predicted self (what a system concludes about you) to the contributing self (what your behavior teaches a system over time).
Denmark’s proposal is the first step. Inference escrow, which I will describe in the next article, is the second. The learning contribution mechanisms I propose in later articles are the third.
This progression is not culturally specific. In a Western individual-rights framework, the person holds and exercises ownership directly. In a sovereignty-first framework like China’s, the ownership principle can exist but may be subject to state authority in defined cases. In a Global South development framework, the principle can be calibrated to institutional contexts, such as collective digital rights exercised through community or national mechanisms rather than individual litigation.
The principle is portable. The implementation is local. Different societies will build differently from the same starting point.
What matters now is recognizing where we are. The scholarly community has identified the gap. A legal precedent has established the principle of ownership. The extensible progression from likeness through inference to learning contribution has been articulated. What remains unbuilt is the operational mechanism, the governance architecture that would make inference visible, accountable, and subject to the judgment of the person it describes.
The next article describes what that mechanism looks like.
This article is drawn from Digital Sovereignty in the Cognitive Age, available at blogs.inspire-aspire.net.



