In a recent decision challenging Google’s Gemini AI features, a California federal court held that allegations concerning an AI tool’s capabilities, without facts showing actual access or use of plaintiffs’ data, were insufficient to demonstrate the “concrete” harm required for Article III standing. Thele v. Google LLC, 2026 WL 1970746 (N.D. Cal. July 7, 2026). The court’s reasoning reflects a principle with potentially broad application: alleging what an AI tool could do is not enough to establish an Article III injury—plaintiffs must plausibly allege what it actually did.
The plaintiffs claimed that Google historically required users to opt in to Gemini as a “Smart” feature, but later enabled Gemini for Gmail, Chat, and Meet by default unless they affirmatively disabled the setting. According to the complaint, Gemini therefore tracked users’ “private communications” without their knowledge or consent and “could have” gleaned sensitive “financial, medical, employment” or other information. Based on those allegations, plaintiffs asserted claims under the California Invasion of Privacy Act, the California Computer Data Access and Fraud Act, the Stored Communications Act, among others.
The Court concluded that the plaintiffs “have not met their burden to demonstrate how they have been ‘concretely harmed.’” Although the complaint identified categories of sensitive information that Gemini “could have” accessed, the plaintiffs did “not identify what – if any – personal data Gemini actually accessed or used.” Instead, they claimed only that Gemini “could be used to track their data,” which the Court held was “insufficient to allege an injury in fact” required for Article III standing. The Court also held that the plaintiffs lacked standing to seek injunctive relief because they had not alleged a “real or immediate threat” of future harm, particularly where they could “eliminate any risk of future harm by disabling the feature they say puts them at risk.”
The decision underscores that allegations about what an AI tool could do, without allegations about what it actually did, may be insufficient to establish Article III standing. The decision may prove particularly significant as courts confront a growing wave of AI-related privacy claims.