We all know they’re watching us. But we don’t know who ** they** are, nor why nor how they are doing it.

Nobody does anything without reason. So, organizations watch and track us for a purpose. That purpose is always for their benefit, not ours. But who are they? Why and how do they do it, and how many organizations do it? It may appear as if it is just an assault on our privacy, but it’s wider than that – the collected information is a powerful tool for further data theft, for targeting critical industries, and for disrupting governments.

Law enforcement does it in case we have criminal tendencies. Criminals do it in case we have something they can take from us. Intelligence agencies do it in case we have secrets that could be used for their own national benefit. And companies do it to see which products may attract us into purchase. 

All of it affects our privacy, some of it could affect our employment, some of it could affect our bank balance, some could affect our freedom, and some could affect our national interest. In all cases the perpetrators claim they are justified in doing so; and all forms of surveillance are now being supercharged by AI. Our only defenses are regulations and our own awareness.

In what follows, we group those that surveil us with the primary methods they use – but it should be noted that any group could use any surveillance method. We also look at the use of AI in surveillance, and the possibility of controlling surveillance through regulations.

Surveillance by legitimate companies

Companies surveil us for two purposes: vendors for sales purposes and employers for staff ‘control’ purposes.

For the former, the extent of people-watching can be extensive. Last year, TechCrunch reported on a proposed browser from Perplexity that would be powered by AI, able “to collect data on everything users do outside of its own app. This so it can sell premium ads… [CEO Aravind] Srinivas believes that Perplexity’s browser users will be fine with such tracking because the ads should be more relevant to them.”

The browser, Comet, was launched in July 2025. “When I spoke with cryptologist Bruce Schneier a couple years ago,” comments David Ruiz, senior privacy advocate at Malwarebytes, “he warned about AI’s capabilities to comb through actual conversations to find whatever’s deemed valuable – whether that’s for law enforcement purposes or for just selling products. Separately, I worry about AI-powered mental health apps and emotional support chatbots that seemingly require users to divulge sensitive information to function.”

In the UK, the Sun newspaper recently reported that a major supermarket chain plans to roll out facial recognition cameras in 150 more stores before Christmas. “From a privacy standpoint, the rollout of facial recognition technology in supermarkets is a huge concern. Placing citizens under surveillance as they go about their day-to-day shopping has a worrying impact on our freedom and right to privacy,” comments Rebecca Moody, head of data research at Comparitech.

“There’s also the risk of mission creep. Facial recognition may be introduced as a tool for combatting shoplifting, etc., but once it’s installed, who’s to say it won’t be used to monitor shoppers’ buying habits and activity as time goes on?”

And don’t forget that every time you are forced to log in to access a website, the owner knows who you are, when you showed interest, and how to contact you. If that login process sends you an activation code by email, it is also confirming that you haven’t entered a false email address.

Cookies are another tool used by vendors to target specific products at people. Cookies profile us by tracking which websites we visit, thus determining our interests. If we look at a specific product but don’t purchase it, we may find ourselves receiving more adverts for that very same product in different places, courtesy of the cookies on our system. A single website may attempt to place 50 or more of these cookies on our system. The precise number will vary since some browsers block some cookies.

Users are often required by regulations to have the option to refuse ‘non-essential’ cookies. Few of them are actually essential (although some, like session cookies have a useful and valid purpose), but who decides what can be labelled ‘essential’?

A website may give an apparent option to refuse cookies while simultaneously making the process complex, time-intensive and confusing. Some sites give us the option: ‘accept our cookies or pay-to-view’. In many cases we simply give up through time pressure and accept the cookies.

In the end, it is doubtful that many people know what cookies or how many are active for what purpose on their system. A common justification is, “You’re going to receive our adverts, so let’s make them more relevant and less annoying for you.”

Users may also be monitored by their own company. Employers frequently monitor employees’ mood, usually via facial recognition systems. Facial recognition technology and use is a complex subject and globally fragmented. In the EU, it is banned in public places and for emotion recognition in workplaces.

In the US, there is no federal law banning facial recognition or mood monitoring, but a patchwork of individual state and city restrictions. But it’s not just facial mood monitoring.

Email monitoring is also common. In the EU it is controlled: allowed for some reasons, but banned for ‘curiosity’ and ‘covert monitoring’. But it is allowed to investigate misconduct, for security reasons and for regulatory compliance (through which covert monitoring rapidly becomes reasoned monitoring).

In the US, email monitoring is easier and more widespread since there is no overriding ‘right to privacy’ in employment. The ECPA does prohibit unauthorized interception of electronic communications, but with two major exceptions: a wide business purpose exception, and a consent exception (where it requires one party to the communication to agree to the interception). This agreement is usually automatically built into an employee’s contract of employment.

“The workplace may become one of the most significant battlegrounds,” warns Ensar Seker, CISO at SOCRadar. “Many organizations already monitor login times, badge access, endpoint activity, collaboration platforms, and productivity metrics. AI now adds behavioral analytics, sentiment analysis, meeting participation scoring, keystroke analysis, webcam monitoring, and predictive models that attempt to identify burnout, insider threats, or employees likely to resign.

“Some of these tools improve security and operational efficiency. Others cross into invasive surveillance by attempting to infer emotions, motivation, or trustworthiness from imperfect data. Organizations should distinguish between monitoring systems for cybersecurity, which is often necessary, and monitoring human psychology, which carries substantial ethical and legal concerns.”

“In the workplace, consent is a weak protection. An employee can technically refuse monitoring. In practice, refusal may mean losing the job or never getting hired. That is paperwork under pressure, not real choice,” comments Stanislav Kazanov, head of GRC, cybersecurity & sustainability at Innowise.

“I think the stronger approach is accountability for the decision, not only the collection of data,” he continues. “If a company fires someone, demotes someone, cuts their pay, or labels them as a risk because of an automated assessment, the company should have to prove the system was accurate, fair, tested, and explainable.”

Surveillance by criminals

Cybercriminals also use a form of surveillance for finding and targeting victims. The primary initial tool is the infostealer. Infostealers silently enter systems and scrape, bundle (into stealer logs), and exfiltrate any relevant data they can find. These stealer logs are then acquired by initial access brokers who sell them on to criminal gangs.

The infostealer access methodology is most usually assumed to be social engineering. Whatever method is used, it is phenomenally successful. Last year, KELA reported that 4.3 million devices had been infected in 2024.

Originally and primarily a password harvesting tool, infostealers have evolved into full operational context ‘vacuum cleaners’. The modern infostealer is active for a shorter time-period, but steals the ability (especially through session cookies) to return at will and steal more information.

Overall, the modern infostealer might steal session cookie/tokens, saved credentials, SSO and cloud credentials, browser artifacts and system metadata, digital wallets, messaging and email clients, and engage in clipboard hijacking, key logging and taking screenshots.

While this might realistically be called theft rather than surveillance, the effect is the same as surveillance by the bad guys. It is surveillance by malware for the benefit of criminals.

Surveillance by law enforcement agencies

“Public safety is the usual justification, and to be fair, surveillance can help in serious investigations,” comments Kazanov. “It can help identify suspects, find patterns, and respond to threats. The question is how targeted, accurate, necessary, and accountable that surveillance really is.”

“Surveillance has a chilling effect on our freedoms of speech, privacy, and movement. At minimum, it should be targeted and require a court order. I don’t think bulk surveillance of people not suspected of any crime is ever justified,” comments Paul Bischoff, consumer privacy advocate at Comparitech.

A big area of contention in the US is the use of Flock cameras. Flock is the name of the company that makes the cameras, and builds and maintains and shares a massive database of the images it captures. The original intent was to assist law enforcement in finding and tracking stolen vehicles through the vehicles’ number plates.

But just as we have configuration drift in system configurations, so we have usage drift in collected data. “Data collection usually starts out legitimate and useful, then drifts out of control in scale, in detail, in retention, and, most dangerously, in use beyond the originally stated purpose,” comments Alex Polyakov, CTO and co-founder at Adversa AI.

(A Flock style system would be illegal in the EU. The UK has its own ANPR (automatic number plate recognition) system, but it is heavily regulated to prevent it developing into a Flock-like system.)

The data collected by Flock is a complete vehicle fingerprint, including the driver and any passengers. It is shared with police agencies (to be expected) but also homeowners associations (HOAs, which becomes somewhat invasive). Far, far more data than is necessary to detect a stolen vehicle is collected, and that data is shared beyond organizations simply looking for stolen vehicles.

In September 2025, ACLU Oregon reported, “These small, unassuming cameras allow police to potentially sit with unblinking eyes 24/7 on every street corner, in every parking lot, and in every neighborhood. The data captured by Flock’s cameras can reveal very private details about a person’s life, including what meetings a person attends, what doctors’ offices and religious institutions they visit, who a person associates with, and even where they sleep at night.”

Matt Polak, founder and CEO at VanishID, adds, “Law enforcement, and less visibly the intelligence community (IC), buy this data and fuse it with government records using platforms like Palantir to generate insights neither dataset could produce alone. I say ‘less visibly’ deliberately: the Office of the Director of National Intelligence’s (ODNI) own 2023 report admitted the IC purchases commercially available information at scale, precisely because buying it avoids the oversight that collecting it would trigger.”

Ruiz continues, “Law enforcement agencies across the country have found a way to circumvent Americans’ Fourth Amendment rights by simply buying data rather than requesting it through a warrant.”

Dan Moore, senior director of CIAM strategy at FusionAuth, summarizes this disturbing and largely invisible reality: “For law enforcement and government use generally, ‘justified by purpose’ is doing a lot of work, and third-party doctrine has let that logic run for decades. Facial recognition and predictive policing break it though, because ‘public safety’ doesn’t constrain the tool, it just licenses whatever the tool does next, and Cathy O’Neil’s point in Weapons of Math Destruction is exactly this: the system runs at scale once deployed, the feedback loop reinforces itself (more policing generates more arrest data, which ‘justifies’ more policing), and there’s no audit trail checking whether it’s still doing what its purpose claims.”

Apart from all the data gathered through its own direct surveillance, consider the amount of personal data we all give away through social media. All this can be scraped and parceled into massive databases that can be queried with AI providing inferences on potential ‘anti-social’ tendencies. If a database exists, it is a reasonable assumption that law enforcement – and the intelligence agencies – can access it.

Intelligence agencies

The justification of surveillance by its purpose to protect people is a strong argument. “I want our protectors to have maximal data. Law enforcement and the intelligence community are up against adversaries who face zero legal constraints on what they collect. Handicapping the defenders while the attackers operate freely is unilateral disarmament,” comments Polak.

“The real scandal isn’t that the government can access this data; it’s that everyone can. The same broker records an agent queries are available to the cartel tracking that agent’s family, the foreign intelligence service mapping our cleared workforce, and the stalker hunting an ex. When Atlas sued brokers under Daniel’s Law in New Jersey, the complaints described gang members using broker sites to find the home address of an officer investigating them, then surveilling her house. The open data market doesn’t favor the good guys. They’re the ones bound by rules.”

While law enforcement engages in wide scale surveillance data gathering for national purposes, the intelligence agencies give the process an international flavor. Consider the Five Eyes group, comprising the agencies of the US, Canada, UK, Australia and New Zealand. Each agency is likely to have access to the data available to its own national law enforcement organizations.

The group grew out of the WWII cooperative efforts between the UK and US to break Nazi German codes (such as Enigma). After the war the group grew to include Canada, Australia and New Zealand. The Five Eyes name grew from the relevant document classification: ‘AUS/CAN/NZ/UK/US Eyes Only’.

Central to the Five Eyes is the purpose and habit of sharing intelligence information with each other. So, there is a potential line from the internal law enforcement data to a foreign intelligence. If the US NSA is concerned about a possible terrorist cell operating out of London, the NSA could ask the UK’s GCHQ, which could get any relevant data from the NCSC and/or the Metropolitan Police.

Many other national intelligence agencies have agreements to collaborate and share information with the Five Eyes and each other. The potential, then, is that any local surveillance data could be sucked into national law enforcement, gathered by national intelligence and transferred to a foreign national intelligence service.

It doesn’t necessarily require the sharing national agency to be the national agency of the person or group whose information is being shared. “GCHQ‘s Tempora programme tapped undersea fiber-optic cables carrying the bulk of Europe’s internet traffic, while NSA’s PRISM programme accessed data directly from the servers of major technology platforms. Through the Five Eyes intelligence-sharing arrangement, what one nation legally collects, all five effectively possess,” explains Tim Freestone, chief strategy officer at Kiteworks.

“Intelligence agencies have always operated with significant secrecy,” adds Seker, “but AI dramatically expands both the scale and speed of intelligence collection. Open-source intelligence, leaked datasets, social media, breached credentials, location metadata, financial records, facial recognition, and commercial data purchased from brokers can all be fused into highly detailed digital profiles.”

It is also very difficult to keep a tight rein on intelligence agency activities. In the US, the original remit for the NSA was ‘foreign’ intelligence gathering. But the internet made it impossible to separate out purely foreign communications. FISA Section 702 ultimately allows the NSA to collect communications within US borders, including US citizens. The effect was to provide another ‘hub’ of surveillance data for the FBI to draw on, and another way to bypass the Fourth Amendment warrant requirements for searching the communications of Americans.

The good news is that Section 702 recently lapsed. The less good news is that this is unlikely to have any effect on NSA practices, certainly not in the short term.

Using AI to supercharge surveillance

“Surveillance is a necessary part of law enforcement actions in a world where many crimes are committed behind the screen. However, AI-enabled surveillance should be treated with extreme caution. AI models have shown countless problems with bias against specific groups whether based on race, political ideology or religion to name a few,” comments Andrew Chipman, Director of GRC & ISO at Pro Circular. “There are too many opportunities for a model to make catastrophic errors that affect human life.”

He is not alone in such concerns. Ilia Kolochenko, founder at ImmuniWeb, and a practicing lawyer in cybersecurity and data protection, believes the use of AI within surveillance is ‘problematic’. “Many law enforcement units collaborate with private companies that conduct intrusive investigations on the Internet. Many privacy protection mechanisms that require LEAs to first obtain a warrant – or at least to inform the suspect of intrusive monitoring after the fact – do not apply to non-governmental entities that actually perform the work. While this is not necessarily illegal, such tactics clearly fall into a gray area of legal and ethical uncertainty.”

In the end, he adds, “They obtain everything they need in full compliance with the law and applicable procedures – without ever disclosing the underlying methods used to gather the initial intelligence.”

Seker agrees. “Historically, investigations started with suspicion and then data was collected. AI enables the opposite. It collects vast amounts of data first and then lets algorithms determine who appears to be suspicious. That shift increases the risk of false positives, algorithmic bias, and innocent individuals becoming subjects of investigation simply because statistical models identified unusual behavior. The technology itself is not the problem; oversight, transparency, and accountability determine whether its use remains lawful and ethical.”

However, adds Mike Silvey, go-to-market advisor at Atsign, “The terrifying reality of AI surveillance is the illusion of mathematical objectivity. When an algorithm falsely tags a citizen or an employee based on biased training data, that ‘false inference’ becomes an unchallengeable fact. We are rushing into an era where software acts as judge and jury, with zero accountability.”

Of course, the AI system being used to analyze surveilled data is itself an attack surface for foreign intelligence and organized crime. “To catch attacks like prompt injection and agent hijacking, we will need to log the agent’s tool calls, its dialogs with the human operator, and often its reasoning traces. Those traces are unusually sensitive, because a reasoning log can reconstruct everything the agent touched. So, the discipline has to be even harder: monitor what the agent does, not the environment it sees, and erase the records once the activity is shown to be benign and the regulatory storage requirements are met,” says Polyakov.

The good news, he adds, is “The same AI is also good at enforcing minimization. It can prune stale data and flag over-collection or queries that fall outside the stated purpose.”

The bad news is, “Almost nobody points it in that direction, though, because the incentives run toward retention. The technology doesn’t pick a side; incentives and rules do.”

“AI sharpens the problem by generating inferences (predictions about health, politics, and loyalty) from data never collected for those purposes. GDPR grants individuals the right to know what is held about them and to challenge automated decisions,” says Freestone.

“Yet, in practice, opacity renders those rights largely theoretical. The answer starts with secure data exchange. Governing exactly what sensitive content moves, through which channels, to whom, and under what controls. Without that foundation, privacy protections remain aspirational rather than enforceable.”

Jason Griffin, VP of cybersecurity services at Integris, warns, “AI is making surveillance faster, cheaper, and much harder to spot. It can process enormous amounts of data, connect patterns people would never see, and make decisions almost instantly. That can be incredibly valuable for things like fraud detection and cybersecurity, but it also means organizations have to be much more thoughtful about how they use that power.”

He adds, “The conversation shouldn’t be about whether AI should be used for monitoring because it’s already here. The more important question is whether there are clear guardrails around it. Organizations need to be transparent about what they’re collecting, why they’re collecting it, and when AI is influencing decisions. Human judgment still has to be part of the process because accountability can’t be automated.”

Can regulation control rampant surveillance?

Silvey says regulation doesn’t work. “Regulations alone won’t stop out-of-control surveillance; we need a fundamental shift in data architecture. As long as centralized databases exist, they will be abused. The only way to truly protect privacy in the AI era is to ensure the data is never collected or centralized in the first place.”

In real life, of course, the right thing to do rarely gets to be done. Regulations suffer from one major drawback: the internet is global while laws are national, and national attitudes differ across the globe. The EU regularly regulates big business, for example with GDPR and more recently with the EU AI Act. Both are considered the gold standard for their respective subjects. The US, however, believes that inhibition strangles innovation, and has a national tendency toward no or minimal regulation.

EO 14409, signed on June 2, 2026, and titled Promoting Advanced Artificial Intelligence Innovation and Security, proposes a voluntary, innovation-first framework for AI development. The purpose is to maintain ‘global AI dominance’. It doesn’t prohibit the regulation of AI but projects a clear preference for innovation over regulation. Illegal behavior should be controlled via the use of existing federal criminal statutes against cyberattacks, fraud, or unauthorized access to systems, requiring nothing new.

“Regulation can constrain but it rarely governs what it cannot trace. GDPR established foundational principles. Collect only what you need, retain it only as long as necessary, and use it only for the purpose declared. Those rules apply to surveillance data as much as any other,” comments Freestone.

“But the rules have gaps. Law enforcement holds broad exemptions under UK GDPR,” he continues. “Intelligence agencies operate in a classification environment where data flows are invisible to the public and largely beyond judicial scrutiny. Law alone won’t close those gaps. Organizations need to govern sensitive data at the content layer. Knowing exactly what is collected, where it travels, who touches it, and under what policy. That discipline, built into systems rather than bolted on, is what makes accountability real.”

Accountability being the better part of regulation is a common viewpoint. “Regulation works when it does two things: gives individuals enforceable rights and puts real liability on the companies holding the data,” says Polak. We have proof on both counts. The Illinois biometric law, BIPA, has a private right of action, and it changed corporate behavior on facial recognition almost overnight. Companies that shrugged at privacy principles paid attention to nine-figure settlements.

“In New Jersey,” he continues, “Daniel’s Law did the same thing to brokers. Once protected people could demand deletion of their home addresses with liability attached, an industry that had ignored removal requests for a decade suddenly built compliance processes. Brokers respond to legal exposure. Nothing else has moved them.”

“Accountability is achievable even for secretive actors, through tamper-evident audit logs and mandatory query logging, but only where the law compels their use,” comments Polyakov.

But who should be held accountable for what? “Ban facial recognition in one setting, and the same idea may come back as ‘biometric analytics’. Restrict emotion detection, and it may reappear as ‘engagement scoring’ or ‘behavioral risk analysis’. The label changes. The incentive stays,” comments Kazonov.

Even where it is clear that somebody should be accountable for something, who is that someone? “When something goes wrong, everyone can point somewhere else. The employer blames the vendor. The vendor blames the model. The agency says the data came from a lawful source. The person affected is left arguing with a machine-shaped fog.”

Summary

Surveillance is uncontrolled, uncontrollable, largely invisible, rampant and increasing.

It is uncontrolled and uncontrollable because there are too many moving parts: too many different watchers gathering information for too many different purposes under too many different legal regimes.

It is largely invisible because even when we know it is happening, we are told its sole purpose is to protect us from the bad guys. Since I am not a bad guy, it won’t affect me, and I can ignore it.

It is rampant and increasing because knowledge is power. If I know everything about you, I have power over you. I won’t use that power, but I’ll take it just in case…

The key point is that most people simply shrug their shoulders at surveillance. “Since I do nothing wrong, I have nothing to fear. That has always been a questionable statement but is now simply a dangerous viewpoint.

The advance of AI into surveillance, enhancing the collection of personal information, packaging it into massive databases, and then inferring conclusions on the data is worrying. AI cannot be trusted. There is too much scope for bias in the algorithms, bias in the operator and simply faulty logic to rely on it. If I accidentally land on a website frequented by terrorists, an AI could infer I am a terrorist.

And the law cannot or will not protect me.

Maybe it is time for everyone to take the invasiveness and potential danger of surveillance more seriously.

Related: AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask

Related: Senate Extends Surveillance Powers Until April 30 After Chaotic Votes in House