By Stuart Kerr, Technology Correspondent, LiveAIWire
AI surveillance has moved from a theoretical civil liberties debate to a measurable legislative response in the space of a single year. State legislatures enacted 145 AI-related laws in 2025 alone, with more than a thousand additional bills introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. Deletion requests sent to data brokers rose 398 percent compared with 2024, reaching an average of more than 2,000 requests a month. Those numbers describe something that was not measurable two years ago: a population beginning to understand how much AI-powered surveillance infrastructure now knows about where they are, what they are doing, and what they are likely to do next.
The question of how much AI should know about citizens is no longer theoretical. It is being decided in real time through legislation, a collapsed government contract negotiation, enforcement actions, and the daily choices millions of people make about which apps to install and which permissions to grant. Answering it well requires separating what AI surveillance systems can technically do from what the evidence says they should be trusted to do.
The Scale of What AI Surveillance Systems Can Now See
DataGrail’s analysis of 2,400 popular business software providers found that 63.6 percent did not disclose third-party AI subprocessors in their legal documentation, meaning the AI systems processing personal data were largely invisible to the consumers whose data was being processed. Of the AI systems DataGrail assessed, 32.8 percent participated in at least one high-risk activity, including sensitive data processing and automated decision-making. California has responded by making privacy risk assessments a legal requirement, with organisations required to submit results for annual audits starting in 2028 and each review personally attested to by a company executive under penalty of perjury, a standard that exceeds equivalent GDPR requirements in some respects.
The gap between what organisations disclose about AI surveillance and what it actually does with personal data is not confined to the private sector. It is larger, and more consequential, at the level of government, where the same 42 percent of companies that DataGrail found abandoning AI projects over privacy concerns face no equivalent internal check when the deploying entity is a federal agency rather than a business answerable to customers and regulators.
The Anthropic Collapse That Exposed the Data Broker Loophole
The clearest evidence of where AI surveillance is headed inside government came from a negotiation that fell apart rather than one that succeeded. According to reporting cited by the Electronic Privacy Information Center, talks between Anthropic and the Department of Defense over the use of Anthropic’s AI systems collapsed after Anthropic insisted on safeguards to prevent its models being used for mass surveillance of Americans. The government specifically wanted Anthropic to allow the collection and analysis of unclassified, commercial bulk data on Americans, including geolocation and web browsing history, obtained through what EPIC calls the data broker loophole: buying data commercially to avoid the warrant requirements that would otherwise apply.
That loophole sits alongside a second one, the Section 702 backdoor search authority that lets the government query foreign intelligence data that incidentally sweeps up Americans’ communications, without a warrant. Both are currently in play as Congress debates reauthorising Section 702 of the Foreign Intelligence Surveillance Act. EPIC has endorsed the Government Surveillance Reform Act and the Protect Liberty and End Warrantless Surveillance Act, either of which would close both loopholes, but neither has passed. The practical result is that a government agency was, by its own request, seeking AI surveillance capability that at least one major AI lab was unwilling to build, which is a notable data point about where the industry itself currently draws the line.
Immigration Enforcement Is Where AI Surveillance Escalation Is Most Visible
The most significant expansion of AI surveillance infrastructure in the United States over the past year has been in immigration enforcement. Jake Laperruque, deputy director of the Security and Surveillance Project at the Center for Democracy and Technology, has described the ramp-up of immigration surveillance as alarming, with agencies drawing data from a wide range of commercial sources and pushing for field deployment of new surveillance technologies at a pace security researchers characterise as reckless.
ICE began deploying facial recognition for in-the-field identification in 2025 through an app called Mobile Fortify, which, unlike standard practice, returns a single match rather than a gallery of candidates and does not display a confidence rating, while agency personnel have in documented cases treated the single match as a definitive identification rather than an investigative lead.
The stakes of that AI surveillance practice became concrete rather than hypothetical following the killings of Renee Nicole Good and Alex Pretti by federal agents in Minneapolis in January 2026, an episode that intensified rather than slowed the pace of enforcement technology deployment. Reporting has since documented facial recognition scans being run against activists and protest observers in Minnesota, alongside the use of automated licence plate readers and commercial location-tracking tools purchased from data brokers, to identify and track individuals who had documented or criticised immigration enforcement operations rather than committed any specific crime.
Why Efficacy, Not Just Ethics, Is the Right Test
Laperruque’s core point is empirical rather than purely ideological: lots of AI surveillance technologies have not proven their efficacy, or work only under precise, controlled conditions, yet unvetted and unregulated versions are being built into policing and immigration enforcement in ways that can produce errors with serious human consequences. LiveAIWire’s earlier reporting on facial recognition and the accountability gap in law enforcement found that a 2018 study measured commercial facial recognition error rates of 0.8 percent for light-skinned men against 34.7 percent for darker-skinned women, a forty-fold disparity, and that at least eight Americans have been wrongfully arrested following facial recognition misidentifications treated as definitive rather than probabilistic.
That same reporting found something counterintuitive about public trust: greater technical understanding of how facial recognition works correlates with decreased comfort with police use of it, not increased comfort, which undercuts the common assumption that scepticism reflects ignorance a communications campaign could fix. The strongest predictor of public acceptance is trust in the institution deploying the technology, not familiarity with the technology itself.
The Democratic Accountability Problem Underneath the Technical One
The most significant structural problem with AI surveillance is not technical. It is democratic. Most AI systems deployed for law enforcement, immigration screening, benefits assessment and public space monitoring were not adopted through legislative processes that allowed meaningful public debate. They were procured by agencies as software products and deployed with limited transparency about their capabilities, accuracy rates, or the data they process, and by the time the public becomes aware a system is in use, it is frequently already embedded in operational processes that make it difficult to remove.
The EU AI Act’s classification of real-time biometric identification in public spaces as a prohibited or high-risk practice, and its requirement for fundamental rights impact assessments before deployment in high-risk contexts, is an attempt to insert democratic accountability before deployment rather than after. LiveAIWire’s coverage of why mitigating AI bias is harder than it looks found that the same documentation requirements the EU imposes on commercial high-risk systems are considerably more demanding than what most US law enforcement agencies currently practise, a gap that matters most precisely where the consequences of an error are most severe.
The Consent and Proportionality Framework That Actually Distinguishes Cases
The most useful framework for evaluating any specific AI surveillance application asks four questions: is the surveillance purpose legitimate, is AI the least intrusive means of achieving it, is there meaningful consent or independent oversight, and are the accuracy rates sufficient given the consequences of an error. AI used to detect fraud in financial transactions, with clear consent mechanisms and low error consequence, sits in a fundamentally different category from AI used to identify faces in public spaces with no consent, limited oversight, and errors that can trigger a wrongful arrest or, in immigration contexts, a wrongful detention.
LiveAIWire’s earlier coverage of the AI credit score’s persistent lending gap found the same proportionality logic applies even in lower-stakes commercial contexts: a system’s accuracy on average tells you little about whether it is fair to the specific individual affected by its worst-case error rate.
What the Behavioural Signals Suggest About Where This Settles
The widespread adoption of privacy tools in 2025 suggests a population that, given accessible alternatives, will exercise meaningful choice about how much data it shares. Signal, the encrypted messaging platform, saw a significant spike in downloads through 2025, and its leadership has been explicit that giving AI systems broad access to personal data creates genuine danger, a position that has shaped the company’s deliberate choice not to integrate AI features that would require loosening its end-to-end encryption guarantees.
LiveAIWire’s coverage of the digital resistance movement building AI-powered privacy tools found the same pattern extending into accountability infrastructure: organisations building automated tools to audit government AI systems, request disclosure of error rates, and challenge discriminatory outcomes, precisely the kind of oversight legislation has been slow to mandate directly.
These behavioural signals create market pressure that complements regulatory pressure, even though both remain incomplete. Companies whose business models depend on maximum data collection face a growing segment of the market actively choosing alternatives that collect less, an imperfect signal since it reflects only the choices of people aware enough to exercise them, but a real one nonetheless.
What This Means for the Decade Ahead
The question of how much AI should know about citizens is ultimately a question about which kind of society AI surveillance gets embedded into. A society in which AI systems monitor movement, predict behaviour, assess risk and make consequential decisions about individuals, with limited transparency, constrained oversight and weak accountability, is materially different from one in which those functions remain performed by humans accountable through democratic institutions, or are tightly constrained by law before deployment rather than litigated after harm.
The technical capability to build the first kind of society already exists. Whether democratic institutions can prevent it depends on the pace of regulatory development relative to the pace of deployment, a race in which, on the evidence assembled here, deployment is currently well ahead.
The 398 percent rise in data broker deletion requests suggests a population beginning to exercise rights it has, even where those rights are incomplete. The 145 AI-related laws enacted in a single year suggest legislators beginning to respond to that same pressure. Whether those responses prove adequate to the technology’s actual capability and the pace at which it is being deployed is the defining civil liberties question of the current decade, and on the honest evidence available right now, that question remains genuinely open.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, emerging technology, and their impact on business, society, and everyday life. LiveAIWire publishes original AI journalism every weekday at liveaiwire.com.