ai mass surveillance privacy sedicii

What AI means for Mass Surveillance and the Fight for Privacy

For decades, mass surveillance was constrained by a simple, practical reality: it was very expensive to perform. Monitoring millions of people required armies of analysts, vast budgets, access to massive amounts of data and enormous infrastructure. That friction — that inefficiency — was, paradoxically, one of democracy’s quiet guardians. A recent MIT Technology Review investigation into AI-enabled surveillance suggests that this protection may now be disappearing….. fast.

A legal paradox sits at the centre of this emerging crisis. In the United States, the Fourth Amendment prohibits the government from searching a citizen’s personal data without a warrant. Yet data brokers — companies that hoover up location data, purchase histories, financial records, and web searches — operate in a legal grey zone. They acquire, assemble and sell that data to anyone willing to pay, including government agencies. The government, technically, isn’t searching your phone; it’s simply buying a dataset that happens to include your phone’s movements. It’s a very subtle difference that most people would agree isn’t really a difference. My data is my data regardless of the route through which it is acquired.

Until recently, the sheer volume of that data provided a form of de facto privacy protection. Deanonymising billions of data points — stripping away pseudonyms, connecting location traces to real identities, linking forum accounts to LinkedIn profiles — required skilled analysts with enormous amounts of time and computing power. AI agents are eroding that protection at alarming speed.

Research from Northeastern University demonstrated that LLM agents can re-identify anonymised individuals from public datasets quickly and cheaply, with each identification attempt taking roughly four minutes and costing less than half a (US) dollar. Other studies show these systems can link pseudonymous social media accounts to real identities, infer users’ locations, incomes, and psychological traits, and identify writers’ native languages. What once required a team of trained intelligence analysts can now, in principle, be performed at industrial scale by software.

The implications are not theoretical for long. Any government or organisation with access to bulk commercial data and powerful AI tools could, in principle, build detailed profiles of millions of citizens simultaneously. The dangers multiply rapidly from there.

Political dissent becomes newly vulnerable. A government with authoritarian instincts could instruct AI agents to identify the real people behind anonymous social media accounts that openly criticise official policy, or compile lists of attendees at political protests by cross-referencing location data. Subtle harassment — airport delays, tax investigations, benefit disruptions — could follow, chilling free expression without any visible act of repression.

The risks extend beyond government. Private companies could deploy identical capabilities against suppliers, job applicants, insurance claimants, or political opponents. Unlike government agencies, which face at least some legal scrutiny, private firms operating in jurisdictions with weak data protection laws could conduct AI-enabled profiling with almost no accountability.

The China precedent is instructive and alarming. Evidence already exists that Chinese technology companies are using LLMs to flag online posts for “public opinion monitoring” — a surveillance priority of the Chinese state. For Uyghur communities, AI-assisted surveillance has contributed directly to internment and forced labour. The technology, once developed and normalised, follows the path of least resistance toward abuse.

Europe’s legal architecture provides meaningfully stronger protections than the American framework, but it is not impervious. The General Data Protection Regulation (GDPR) imposes strict limits on how personal data can be collected, processed, and sold, and explicitly restricts the profiling of individuals without clear legal basis or consent. The data broker industry that fuels American surveillance operates on a far more constrained basis in the European Union, and bulk commercial data purchases by government agencies face significant legal exposure under EU law.

The EU AI Act, now entering force despite some delays, further restricts high-risk AI applications and prohibits most real-time remote biometric surveillance in public spaces. These are meaningful guardrails. Nevertheless, national security exemptions within both GDPR and the AI Act create gaps, and intelligence agencies across Europe have historically pushed the boundaries of what surveillance law permits. The aggregation of government-held data — health records, tax data, social services information — also creates risks if centralisation efforts, whether driven by efficiency arguments, political pressure, or the use of a single vendor, Palantir for example, erode the silos that currently keep that data separate.

The most powerful tool against surveillance remains democratic pressure. The episode in the recent past involving Anthropic and the US Department of Defence — where public backlash forced OpenAI and the Pentagon to revise a surveillance-enabling contract — demonstrates that organised citizen opposition can move corporate and government actors even on opaque national security issues.

Legislatively, citizens should demand that their representatives close the data broker loophole: requiring warrants before any government agency purchases commercially available personal data is an obvious and overdue reform. Supporting digital rights organisations — the Electronic Frontier Foundation, Privacy International, the Centre for Democracy and Technology — amplifies expert advocacy within legislative processes.

At the individual level, basic digital hygiene limits exposure: using privacy-preserving browsers and search engines, auditing app location permissions, opting out of data broker databases where possible, and supporting end-to-end encrypted communications. None of these steps are individually decisive, but collectively they raise the cost of surveillance and reduce the data available for exploitation.

Most fundamentally, the framing must shift. Privacy is not merely a personal preference or a technical inconvenience to be traded away for convenience. It is a structural precondition for political freedom. As Cornell professor Karen Levy observed, inefficiency in surveillance has historically functioned as a privacy protection in its own right. When AI removes that inefficiency entirely, the only remaining protection is law — and law requires citizens who are informed, engaged, willing to demand it and courts willing to uphold it without fear of retribution.

The all-seeing algorithm is not yet fully operational. But the window to constrain it is narrowing.

Scroll to Top