Résumé exécutif
Sign language artificial intelligence, whether built for recognition, translation, or avatar-based generation, depends structurally on video or biometric capture of Deaf and hard of hearing users. This dependency creates a data governance problem that has received far less institutional scrutiny than the linguistic and comprehension failures documented in prior issues of this series. Across the vendor landscape NCG has reviewed under the SLAT (Sign Language Access Trust) framework, disclosure of what is collected, how long it is retained, whether it is used to train future models, and whether it is shared with third parties is inconsistent at best and absent at worst. This is not a claim that any specific vendor has acted in bad faith. Public evidence does not yet support attribution of intent to any named company, and this issue does not make that attribution. It is a claim that the market has not yet developed a disclosure standard adequate to the sensitivity of the data involved, and that this gap is a governance failure independent of any individual vendor’s conduct. The policy position below argues that consent and disclosure adequacy should be treated as a gating criterion in procurement, not a secondary consideration addressed after functional evaluation.
Problème politique
Sign language capture is biometric capture. Video of a signer’s hands, facial grammar, and body position is not incidental input, comparable to a typed sentence submitted to a text-based system. It is uniquely identifying, it encodes information about disability status by definition, and in many jurisdictions it meets the statutory definition of biometric or special category data subject to heightened protection. Illinois’s Biometric Information Privacy Act (BIPA), for instance, requires written notice and consent before collection of biometric identifiers, and imposes liability independent of proof of actual harm. The European Union’s GDPR (General Data Protection Regulation) classifies data revealing disability-adjacent information, and certain biometric data used for identification, as special category data under Article 9, requiring an explicit legal basis beyond ordinary consent. California’s CCPA (California Consumer Privacy Act) and CPRA (California Privacy Rights Act) impose their own disclosure and opt-out obligations for biometric information.
Despite this regulatory landscape, consumer-facing sign language AI products frequently rely on general-purpose terms of service that were not drafted with Deaf users or biometric capture in mind. Three recurring deficiencies are visible across the vendor snapshots NCG has conducted: first, no separate or conspicuous disclosure that video input constitutes biometric data subject to specific statutory protections; second, no clear statement of whether captured video or derived features are retained for model training, and if so, for how long and under what deletion rights; third, no accessible-format disclosure, meaning the consent language itself is often not translated into ASL or presented in a format usable by the population whose data is being collected. This last point is not a technicality. A disclosure regime that requires literacy in a written second language to understand what is being done with one’s own biometric data is not functioning as informed consent for a population for whom English literacy varies widely and for whom ASL is the primary language of comprehension.
La capture en langue des signes est une capture biométrique.
Analyse institutionnelle
Les dynamiques institutionnelles à l'origine de cette lacune sont structurelles plutôt que délibérées. L'IA en langue des signes est une catégorie de produits jeune, et la plupart des fournisseurs sont de petites entreprises utilisant les mêmes modèles génériques de politique de confidentialité employés dans l'ensemble du secteur logiciel, adaptés a minima, voire pas du tout. Les processus d'achat au niveau institutionnel, quant à eux, ont historiquement évalué ces produits selon des critères fonctionnels : l'avatar restitue-t-il un rendu intelligible, le système de reconnaissance atteint-il une précision acceptable, le fournisseur emploie-t-il du personnel Deaf impliqué dans le développement. La gouvernance des données a été traitée comme une question de conformité juridique ou informatique abordée après la décision d'achat substantielle, lorsqu'elle est abordée du tout. Cet ordre des priorités constitue la véritable défaillance de gouvernance. Au moment où une lacune de gouvernance des données apparaît, que ce soit par une violation, une enquête réglementaire ou une critique publique de la communauté Deaf dont les données ont été concernées, la relation institutionnelle et l'engagement financier sont déjà établis, et le pouvoir de négociation pour exiger des mesures correctives s'en trouve d'autant plus affaibli.
There is also a training data provenance question that sits adjacent to the consent problem but is analytically distinct from it. Several sign language AI systems have been built in part on video corpora drawn from publicly posted content, including content created by Deaf ASL users and educators on social platforms. Whether that use falls within the scope of the platform’s own terms of service, whether it constitutes fair use under copyright law, and whether the individuals whose signing appears in that footage were meaningfully informed that their content would be used to train a commercial AI system, are open questions that NCG has not independently verified for any specific vendor and does not assert as established fact here. The point for governance purposes is that procurement officers evaluating these systems have almost no visibility into training data provenance, and current disclosure norms in the industry do not require vendors to provide it.
Implications en matière de gouvernance
An institution procuring sign language AI is not merely a purchaser of a translation tool. Where the system operates on live video of students, patients, employees, or members of the public, the institution is also a data controller or processor under most applicable privacy frameworks, and it inherits governance exposure from its vendor’s data practices whether or not that exposure was disclosed at the time of purchase. An institution that has not verified a vendor’s data collection, retention, and training-use practices before deployment cannot represent to its own stakeholders, regulators, or the Deaf individuals whose data is being captured, that it has met its own data protection obligations. This is true regardless of the vendor’s actual conduct, because the absence of verified disclosure is itself the governance defect, independent of whether any given vendor turns out to be handling data responsibly.
Position politique de NCG
NCG’s position is that data governance and privacy disclosure adequacy should function as a gating criterion in sign language AI procurement, evaluated before functional performance rather than after it. A vendor’s inability to produce clear, ASL-accessible, jurisdiction-appropriate disclosure of what biometric data is collected, how long it is retained, whether and how it is used in model training, and what deletion rights exist, should be treated as disqualifying for institutional deployment regardless of linguistic or technical performance elsewhere in the evaluation. This position is already operationalized in the SLAT framework’s Data Governance and Privacy and Transparency and Disclosure domains, and this issue argues that those domains warrant elevated weighting relative to the framework’s current calibration, given the statutory exposure institutions face and the comprehension barrier that non-accessible consent language creates for the affected population.
Considérations relatives à la mise en œuvre
Procurement officers evaluating sign language AI should require, as a condition of vendor response, a written data governance disclosure covering the four elements above, request that this disclosure be available in ASL video format in addition to written English, and treat vendor refusal or inability to produce this disclosure as an adverse finding independent of the system’s functional performance. Institutions with existing deployments should conduct a retrospective review rather than waiting for contract renewal, given that governance exposure accrues from the date of deployment rather than the date of discovery. Where a vendor’s training data provenance cannot be verified, institutions should request contractual warranties regarding lawful data sourcing rather than treating the absence of an answer as a neutral unknown.
Références
- Biometric Information Privacy Act, 740 ILCS 14 (Illinois).
- California Consumer Privacy Act of 2018, tel que modifié par la California Privacy Rights Act, Cal. Civ. Code § 1798.100 et suivants.
- Règlement (UE) 2016/679 (Règlement général sur la protection des données), art. 9.
- Federal Trade Commission Act, 15 U.S.C. § 45 (actes ou pratiques déloyaux ou trompeurs).
- Novara Consulting Group, Référentiel Sign Language Access Trust (SLAT), 2026.

