# AI privacy budgets: Ask for the calculation, not the claim

DevFeed: [AI privacy budgets: Ask for the calculation, not the claim](<https://devfeed.tech/articles/ai-privacy-budgets-ask-for-the-calculation-not-the-claim-58597.md>)

Original publisher: [Read original article](<https://www.cio.com/article/4225087/ai-privacy-budgets-ask-for-the-calculation-not-the-claim.html>)

Author: Nik Kale

Published: 2026-09-23T11:00:00Z

Content type: article

Language: en

Sources: [CIO](<https://devfeed.tech/sources/cio.md>)

Topics: [Differential Privacy](<https://devfeed.tech/topics/differential-privacy.md>), [Federated Learning](<https://devfeed.tech/topics/federated-learning.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [tenant data protection](<https://devfeed.tech/topics/tenant-data-protection.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [artificial-intelligence-budgeting-it-leadership-it-management-privacy-security](<https://devfeed.tech/tags/artificial-intelligence-budgeting-it-leadership-it-management-privacy-security.md>), [budgeting](<https://devfeed.tech/tags/budgeting.md>), [contributor](<https://devfeed.tech/tags/contributor.md>), [differential-privacy](<https://devfeed.tech/tags/differential-privacy.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [federated](<https://devfeed.tech/tags/federated.md>), [federated-learning](<https://devfeed.tech/tags/federated-learning.md>), [isolation](<https://devfeed.tech/tags/isolation.md>), [it-leadership](<https://devfeed.tech/tags/it-leadership.md>), [it-management](<https://devfeed.tech/tags/it-management.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that enterprise AI privacy budgets should be tied to the privacy unit, accounting method, noise and clipping parameters, participant sampling, training rounds, and released model version. A budget value alone does not demonstrate that a model was trained within the stated privacy guarantee.

## Source excerpt

Writing a specification requires a precision that a contract does not. This year, I focused on an internet draft for privacy-preserving federated learning in multi-tenant agent systems. The privacy budget could not go in as a number. It had to be presented with the privacy unit, the accounting method, the noise and clipping parameters, and the round cap, because a specification that leaves those implicit cannot be implemented by anyone. Enterprise contracts quote the number alone. It usually comes with a reassuring sentence: your data will remain in your tenant, local systems will train on the data, updates to the model will be the only data that is shared, those updates will be aggregated and protected with differential privacy, and the resulting guarantee will have a budget expressed as epsilon and delta. It can be technically correct. The issue is that the number in the contract is not, on its own, evidence that the model was trained within that number. Buyers are getting more curious regarding how models were trained and what happens to their data, and finding that most vendors are not prepared to give good answers. For many, the budget expressed is the end of the conversation because a number seems like an answer. The privacy target can be selected before the training begins. The privacy loss the accountant attributes to the run depends on the entity being protected, the sampling of participants, the number of rounds, the clipping of updates, the amount of noise used, the accounting method and which version of the model is subsequently released. If these things are not tied together, a vendor can have a real privacy number and a real privacy mechanism that do not relate to the same training run. The number needs a referent Start with the privacy unit. An epsilon of 3.0 does not help you understand if your protected unit is a single record, user, session, device or an entire tenant. That distinction is highly important when dealing with an enterprise system. For