Bankruptcy Shield as a Sword: The Startup Gets Acquired Without Being Acquired

The proposed sale of Spirit Airlines’ enormous internal dataset to Google exposes a potentially dangerous new loophole in the AI economy. Google won a bankruptcy auction with a $10 million bid for Spirit’s enterprise data and says the material could help improve its products and AI models. The corpus reportedly includes approximately 100 million emails, 500 million Microsoft Teams messages, software code, operational information and decades of business records. (Reuters)

But there is a threshold question that shouldn’t get lost in the excitement over turning bankrupt companies into AI training datasets: Did Spirit actually own everything it proposed to sell?

Possession Is Not Ownership

Springshot, a technology startup whose proprietary airline-operations platform was embedded in Spirit’s technology stack for its final three years, says potentially not. Springshot has objected that the sale agreement defines the dataset so broadly that it may encompass Springshot’s own intellectual property and proprietary information. It wants the bankruptcy court to require a forensic process separating Spirit’s property from property belonging to third parties before anything goes to Google. (Ars Technica)

Springshot founder Doug Kreuzkamp states the basic principle perfectly: “The possession of IP is not ownership.” After all, a debtor’s server is a container, not a chain of title. It may hold the debtor’s property alongside licensed technology, vendor trade secrets, confidential communications, employee information and intellectual property belonging to somebody else. Bankruptcy shouldn’t improve the debtor’s title.

Bankruptcy as a Sword

That becomes particularly important with AI because bankruptcy can potentially be transformed from a shield for a distressed debtor into a sword for the purchaser. The sequence is straightforward: Startup develops technology → licenses it to customer → technology and know-how become embedded in customer’s systems → customer fails → bankruptcy estate sells its “dataset” → AI company trains on the corpus.

The bankruptcy proceeding has now done something much more consequential than liquidating the debtor’s assets. It may have created an efficient mechanism for aggregating information and transferring it to an AI company for a new use. That’s the loophole.

The Startup Gets Acquired Without Being Acquired

And that’s where this becomes an antitrust problem. Springshot has spent roughly 15 years developing technology used to improve airline operations. Ars reports that Google recently announced a five-year partnership with Ryanair involving airline operational data and Gemini Enterprise—putting Google’s AI efforts in an area where Springshot itself operates. Springshot consequently fears that its proprietary information could end up helping a vastly larger company compete with it.

Think about the alternatives. Google could develop competing technology. It could license Springshot’s technology. It could partner with Springshot. It could potentially acquire Springshot.

Or, potentially: Buy the data estate of Springshot’s bankrupt customer in a bankruptcy auction. That last possibility is profoundly different. Google doesn’t acquire the startup. It potentially acquires what the startup knows. There is no acquisition price paid to the startup. No negotiated license. And no conventional acquisition of the competitor to scrutinize.

As Springshot warns, the precedent could allow large amounts of startup IP to migrate to enormously powerful companies through bankruptcy proceedings. In other words, the startup gets acquired without being acquired. And there may be nothing they can do about it.

A Competition Loophole

That makes the bankruptcy loophole a competition loophole. Startups necessarily expose substantial information to enterprise customers. Integration requires documentation, workflows, support communications, operational data and technical knowledge.

Normally contracts, confidentiality obligations, trade-secret law and property rights establish boundaries around that information. But if those boundaries become uncertain when the customer goes bankrupt, the economics of dealing with large enterprise customers change.

A startup could survive while its customer fails—only to discover that the customer’s bankruptcy estate proposes to sell information embodying the startup’s technology to a company with virtually unlimited resources. The customer went bankrupt, so why should the startup’s competitive advantage be liquidated with it?

Procedure Becomes the Product

There is a broader procedural inversion here. Large corporate defendants have long understood that legal procedures nominally directed against them can sometimes produce valuable affirmative rights. A class action, for example, is ostensibly a device for aggregating claims against a defendant. But settlement can also aggregate something enormously valuable for the defendant: releases and finality.

The procedure itself creates economic value. AI may give bankruptcy proceedings a similar secondary function. Bankruptcy ostensibly protects the debtor and organizes an orderly disposition of its property. Or that’s the party line. But to an AI company seeking enormous quantities of authentic enterprise data, bankruptcy can provide something else: Aggregation.

Instead of negotiating separately with every employee, contractor, vendor and technology supplier whose information resides in a company’s systems, the purchaser buys one enormous “dataset” from the estate. What began as the debtor’s shield risks becoming the purchaser’s sword.

De-Identification Doesn’t Fix Title

Google says it will not receive personal information, and Spirit’s dataset is supposed to undergo de-identification. That’s important for privacy, but it doesn’t resolve ownership. Anonymization is not assignment. Removing a person’s name doesn’t transfer a vendor’s trade secrets. And de-identifying employee communications doesn’t necessarily establish that they can be repurposed for AI training. Privacy, ownership, confidentiality and authorization are separate questions.

A Caution for Startups: Treat Customer Data Like Inventory in a Warehouse

There is a useful analogy here to secured lending. A bank lending against inventory does not assume that everything physically sitting in the borrower’s warehouse belongs to the borrower. It identifies the collateral, determines what rights the borrower actually has in it, perfects its security interest, and worries about priority, proceeds, commingling and property belonging to third parties. So the Spirit case highlight the need to think about creditworthiness as a material deal point.

AI startups may want to start thinking about their data in much the same way. A customer’s servers are increasingly the digital equivalent of the warehouse. They may contain customer-owned information alongside licensed technology, vendor trade secrets, proprietary workflows, confidential communications, derived data and other material the customer merely possesses. If the customer enters bankruptcy, the danger is that all of this gets swept into a broadly defined “enterprise dataset” and auctioned as though possession established ownership. It doesn’t.

That means startups should protect themselves before a customer’s financial distress ever arises. Contracts should clearly establish ownership, permitted uses, AI-training restrictions, return and deletion obligations, and what happens upon insolvency. Proprietary information should be identifiable and segregated where practicable, with sufficient provenance to establish what belongs to whom.

There may even be circumstances where traditional secured-credit techniques deserve consideration as additional protection. But the distinction is important: Ownership is the first line of defense: “That isn’t property of the bankruptcy estate.” A security interest is the second: “If it is property of the estate, our rights have priority.”

A startup generally wants to win the first argument. Carelessly taking a security interest in property the startup claims to own could muddy that position rather than strengthen it, so Article 9 protection requires careful drafting.

The larger caution is simple: Bankruptcy courts have spent generations distinguishing what is in a debtor’s warehouse from what the debtor actually owns. AI should not erase that distinction merely by replacing the warehouse with a server. For startups whose technology becomes embedded in customers’ systems, data-title planning may now need to become as routine as IP assignments, confidentiality provisions and cybersecurity. The time to establish ownership and provenance is before the customer’s servers—and everything sitting inside them—show up in a bankruptcy auction.

The Rule Should Be Simple

AI has transformed old corporate records from storage liabilities into valuable assets. Spirit’s data sale shows just how valuable: companies are bidding millions for records of how real humans communicate, solve problems and operate businesses. That makes it essential to get the rule right now. Before a bankruptcy court asks what is this dataset worth?, it should ask: What exactly did the debtor own?

Bankruptcy can transfer the debtor’s assets. It should not manufacture AI rights the debtor never possessed. And it certainly shouldn’t become a mechanism through which a dominant AI company can acquire the accumulated knowledge of a startup without ever acquiring the startup itself.

Ars Technica’s report on the Spirit/Springshot dispute

Infrastructure, Not Aspiration: Why Permissioned AI Begins With a Hard Reset

Paul Sinclair’s framing of generative music AI as a choice between “open studios” and permissioned systems makes a basic category mistake. Consent is not a creative philosophy or a branding position. It is a systems constraint. You cannot “prefer” consent into existence. A permissioned system either enforces authorization at the level where machine learning actually occurs—or it does not exist at all.

That distinction matters not only for artists, but for the long-term viability of AI companies themselves. Platforms built on unresolved legal exposure may scale quickly, but they do so on borrowed time. Systems built on enforceable consent may grow more slowly at first, but they compound durability, defensibility, and investor confidence over time. Legality is not friction. It is infrastructure. It’s a real “eat your vegetables” moment.

The Great Reset

Before any discussion of opt-in, licensing, or future governance, one prerequisite must be stated plainly: a true permissioned system requires a hard reset of the model itself. A model trained on unlicensed material cannot be transformed into a consent-based system through policy changes, interface controls, or aspirational language. Once unauthorized material is ingested and used for training, it becomes inseparable from the trained model. There is no technical “undo” button.

The debate is often framed as openness versus restriction, innovation versus control. That framing misses the point. The real divide is whether a system is built to respect authorization where machine learning actually happens. A permissioned system cannot be layered on top of models trained without permission, nor can it be achieved by declaring legacy models “deprecated.” Machine learning systems do not forget unless they are reset. The purpose of a trained model is remembering—preserving statistical patterns learned from its data—not forgetting. Models persist, shape downstream outputs, and retain economic value long after they are removed from public view. Administrative terminology is not remediation.

Recent industry language about future “licensed models” implicitly concedes this reality. If a platform intends to operate on a consent basis, the logical consequence is unavoidable: permissioned AI begins with scrapping the contaminated model and rebuilding from zero using authorized data only.

Why “Untraining” Does Not Solve the Problem

Some argue that problematic material can simply be removed from an existing model through “untraining.” In practice, this is not a reliable solution. Modern machine-learning systems do not store discrete copies of works; they encode diffuse statistical relationships across millions or billions of parameters. Once learned, those relationships cannot be surgically excised with confidence. It’s not Harry Potter’s Pensieve.

Even where partial removal techniques exist, they are typically approximate, difficult to verify, and dependent on assumptions about how information is represented internally. A model may appear compliant while still reflecting patterns derived from unauthorized data. For systems claiming to operate on affirmative permission, approximation is not enough. If consent is foundational, the only defensible approach is reconstruction from a clean, authorized corpus.

The Structural Requirements of Consent

Once a genuine reset occurs, the technical requirements of a permissioned system become unavoidable.

Authorized training corpus. Every recording, composition, and performance used for training must be included through affirmative permission. If unauthorized works remain, the model remains non-consensual.

Provenance at the work level. Each training input must be traceable to specific authorized recordings and compositions with auditable metadata identifying the scope of permission.

Enforceable consent, including withdrawal. Authorization must allow meaningful limits and revocation, with systems capable of responding in ways that materially affect training and outputs.

Segregation of licensed and unlicensed data. Permissioned systems require strict internal separation to prevent contamination through shared embeddings or cross-trained models.

Transparency and auditability. Permission claims must be supported by documentation capable of independent verification. Transparency here is engineering documentation, not marketing copy.

These are not policy preferences. They are practical consequences of a consent-based architecture.

The Economic Reality—and Upside—of Reset

Rebuilding models from scratch is expensive. Curating authorized data, retraining systems, implementing provenance, and maintaining compliance infrastructure all require significant investment. Not every actor will be able—or willing—to bear that cost. But that burden is not an argument against permission. It is the price of admission.

Crucially, that cost is also largely non-recurring. A platform that undertakes a true reset creates something scarce in the current AI market: a verifiably permissioned model with reduced litigation risk, clearer regulatory posture, and greater long-term defensibility. Over time, such systems are more likely to attract durable partnerships, survive scrutiny, and justify sustained valuation.

Throughout technological history, companies that rebuilt to comply with emerging legal standards ultimately outperformed those that tried to outrun them. Permissioned AI follows the same pattern. What looks expensive in the short term often proves cheaper than compounding legal uncertainty.

Architecture, Not Branding

This is why distinctions between “walled garden,” “opt-in,” or other permission-based labels tend to collapse under technical scrutiny. Whatever the terminology, a system grounded in authorization must satisfy the same engineering conditions—and must begin with the same reset. Branding may vary; infrastructure does not.

Permissioned AI is possible. But it is reconstructive, not incremental. It requires acknowledging that past models are incompatible with future claims of consent. It requires making the difficult choice to start over.

The irony is that legality is not the enemy of scale—it is the only path to scale that survives. Permission is not aspiration. It is architecture.