Consent collected for a diagnosis does not authorise training an algorithm
A class action in the United States accuses Tempus AI of using genetic data collected for diagnosis to train artificial intelligence models and for commercial agreements with the pharmaceutical industry, without new consent. The case concerns any organisation considering reusing data collected for one purpose.
Raffaella Aghemo
In February 2025 Tempus AI, a US healthcare artificial intelligence company, acquired Ambry Genetics, a genetic testing laboratory, for 600 million dollars. The acquisition brought with it the genetic data of hundreds of thousands of patients, collected by Ambry for the diagnosis and screening of inherited diseases.
Since then, several class actions have been filed, later consolidated into a single proceeding, Farrier et al. v. Tempus AI, before the federal court for the Northern District of Illinois. The plaintiffs claim that Tempus used that genetic data to train its own AI models, and that it also shared it, through licensing agreements, with more than seventy pharmaceutical and biotechnology companies, including names such as AstraZeneca, Pfizer and Bristol Myers Squibb, in deals the claims put at over a billion dollars combined. All of it, they claim, without written consent specific to these uses, in violation of Illinois genetic information privacy law.
The proceeding is still open: in early May the court appointed the plaintiffs' executive committee, a procedural step that marks the start of the case's active phase, not a verdict. The allegations remain to be proven.
But the legal point at the centre of the case does not depend on the outcome, and it concerns any organisation that handles data, not only healthcare ones. Consent collected for a specific purpose, in this case a genetic diagnosis, does not automatically extend to other uses, such as training an artificial intelligence model or transferring it to a commercial partner. When an organisation acquires another company, it acquires its data too, but not necessarily the right to use it for purposes other than the original ones. A change in data ownership does not change the boundaries of the consent that made it lawful.
The plaintiffs add a second argument, technical but relevant for anyone relying on anonymisation as a compliance shortcut: they claim that genetic data is by nature difficult to truly anonymise, because even stripped of direct identifiers it can, in many cases, be traced back to a specific individual. Whether the argument will hold up in court is not yet known, but the principle it invokes is already today the more prudent standard to adopt: treating a piece of data as anonymous simply because it lacks a name and address is a risky assumption, not a guarantee.
For an organisation integrating artificial intelligence into its processes, the Tempus AI case offers a concrete reminder. Whenever data collected for one purpose is redirected towards a new use, particularly training an AI system, the question to ask is not whether the data is available. It is whether the original consent covers that too.