Privacy and Surveillance

Nina found out her employer was watching her because her laptop battery kept dying.

She opened the task manager to hunt for the culprit and found a background process she didn't recognize. A quick search named it: employee monitoring software. Keystroke logging. A screenshot every few minutes. Mouse-movement tracking. A running tally of which application had her attention and for how long. Nobody had told her. There was no line in her contract, no memo from IT. The software had arrived silently during a routine update and started collecting.

Nina worked in marketing — blog posts, social calendars, the occasional press release. Nothing classified, no sensitive client files. But every word she typed and every site she visited was recorded, timestamped, and stored. When she raised it with her manager, he seemed puzzled that she was bothered. "It's company property," he said. "We have a right to know how it's being used."

Nina left three months later. The surveillance did not leave with her. She still catches herself wondering whether something is watching on her personal devices, years on. That residual unease — the sense of an audience that never quite logs off — is the quiet tax of a world in which monitoring has become the default and privacy the thing you have to argue for.

Nina's story is unremarkable, which is precisely the point. What used to require a supervisor's attention now runs as infrastructure. The change is not that someone decided to watch us more closely. It is that watching became cheap enough to do all the time, to everyone, automatically — and the institutions that once bounded surveillance have quietly dissolved around it.

What the algorithm sees at work

Start with the workplace, because that is where most people meet AI surveillance first and where the legal ground is thinnest.

The categories of monitored behavior have expanded far past the timesheet. Employers now routinely capture keystrokes and typing cadence, periodic or continuous screenshots, the content of emails and chat messages, which applications and websites are open and for how long, "active" versus "idle" time, physical location through badge swipes or GPS for field and delivery workers, webcam images during remote work, and — in call centers especially — the words, tone, and emotional register of every customer conversation. From these streams, systems assemble a productivity score: a single number, updated in real time, that purports to represent how much value a person is generating minute to minute. Amazon's warehouse "time off task" tracking is the best-known example, but the same logic now reaches white-collar work through tools like Microsoft's telemetry, Teramind, ActivTrak, and Hubstaff.

The justifications are familiar and sometimes legitimate — security, compliance, quality assurance, coordinating distributed teams. But the scope has outrun the justification. Employees frequently cannot see what is collected, how long it is kept, who can read it, or how it feeds a decision about their pay, their schedule, or their job. They cannot opt out, and they cannot inspect their own file.

Here is the crucial legal fact, and the answer to the question that anchors this chapter. In the United States, the baseline is permissive. The main federal statute is the Electronic Communications Privacy Act of 1986 (ECPA), written for a world of desk phones and fax machines. It forbids intercepting communications — but carves out two exceptions that swallow the rule at work: the "ordinary course of business" exception and the consent exception. Monitoring done for a business purpose, on employer-owned equipment, is generally lawful, and consent is easily manufactured through an acknowledgment buried in an onboarding packet. There is no federal requirement that an employer tell workers they are being monitored at all. Disclosure obligations exist only in a handful of states: Connecticut and Delaware require advance notice of electronic monitoring, and New York, since 2022, requires employers to notify new hires in writing. That is roughly the extent of it. In most of the country, an employer may do to its workforce exactly what Nina's did — install the software silently and never mention it — and break no law. The default is visibility; privacy is the exception you have to be lucky enough to live in a state that grants.

Why watching got cheap

The deeper story is economic. Surveillance has always been possible; what changed is its cost structure, and that change is what makes comprehensive monitoring newly rational rather than merely conceivable.

Traditional surveillance was expensive because it was human. Watching one person required roughly one watcher — a supervisor on the floor, a detective on a stakeout, an analyst reading a transcript. Cost scaled linearly with coverage: to watch twice as many people, or the same people twice as closely, you hired twice the staff. That linearity was, in practice, the main protection privacy ever had. Nobody could afford to watch everyone all the time, so most behavior went unobserved by default, not by right.

AI severs the link between coverage and cost. The marginal expense of monitoring one more employee, one more camera feed, one more hour of footage, falls toward zero once the model is trained and the pipeline is built. A single system can watch ten thousand workers as easily as ten, flag anomalies across months of history no human could hold in mind, and never tire, never look away, never need a second watcher to watch the watcher. Surveillance shifts from a variable cost you ration to a fixed cost you amortize — and once something is a sunk fixed cost, the incentive runs entirely toward using it more. That inversion, more than any single technology, is why monitoring became continuous. The question stopped being "is this person worth watching?" and became "why would we not watch, since it's already running?"

The face in the crowd

The same cost collapse plays out in public space, most visibly through facial recognition.

Britain has become the unlikely laboratory. London's Metropolitan Police expanded live facial recognition (LFR) sharply through 2024 and 2025 — vans parked at busy junctions, cameras comparing every passing face against a watchlist in real time, an alert firing when the system thinks it has a match. In 2025 the Met moved from mobile deployments to something more consequential: permanent LFR cameras in Croydon, South London, fixed installations meant to run continuously rather than for a day's operation. "Permanent live facial recognition" is a phrase worth pausing on. It does not mean cameras that record, which have existed for decades. It means every face that crosses a stretch of pavement is captured, converted to a biometric template, and checked against a database, every hour of every day, indefinitely — with no moment at which a person is asked, informed, or given a way to decline short of not walking down that street.

For someone in that space, the practical experience is this: you are not a passerby, you are a query. If you match the watchlist, officers are dispatched. If you don't, the system moves on — but the deployment has established, quietly and without a vote, that walking in public now means submitting to a biometric identity check. South Wales Police run comparable systems; cities across Europe, Asia, and North America deploy variants for policing, traffic, and commerce, some tracking shoppers or reading demographics off store cameras to tune advertising. The infrastructure for ubiquitous facial identification now exists and works. The open question is no longer technical feasibility. It is whether societies treat this as normal.

Surveillance broken into piecework

Something structurally new is happening to who runs surveillance, and it matters as much as the technology.

In 2025, Flock Safety — a firm whose automated licence-plate readers and cameras blanket thousands of American neighborhoods — began routing verification work to gig workers: people paid piece rates, working from home, confirming whether the AI's flagged matches were correct and, in doing so, improving the training data. It is efficient and cheap. It is also emblematic.

Traditional surveillance, however invasive, at least sat inside institutions with nominal accountability. Police departments answer to oversight boards and courts. Corporate security teams operate under employment law and internal policy. There was, in principle, a chain of responsibility — a name attached to a decision, a body you could complain to. Disaggregate that work into piecework performed by contractors scattered across jurisdictions, on personal laptops, with no clearance, no training, no institutional identity, and each link in the accountability chain quietly snaps. Who is responsible when a gig reviewer leaks a face, misidentifies a person, or trawls the footage for someone they know? The contractor, who was following the task? The platform, which merely dispatched it? The client, which never touched the data? The answer is no one in particular, and that diffusion is not an accident of the design. For a company deploying surveillance, an arrangement in which responsibility evaporates is a feature. The result is not a single panopticon under one authority but a distributed mesh of private firms and freelance eyes operating in overlapping legal gray zones, with accountability fragmented to near-invisibility.

Biometrics beyond the face

Biometric data is not just fingerprints and faces, and the categories most people don't recognize as biometric are precisely the ones being collected without notice.

Your voice is biometric. Every exchange with Siri, Alexa, or Google Assistant yields a voiceprint usable not only to verify who you are but to estimate your emotional state, stress level, age, and health. Your walk is biometric: gait-recognition systems can pick an individual out of ordinary CCTV footage by the distinctive geometry of their stride — and unlike a password, you cannot change how you walk. Keystroke dynamics — the rhythm and timing of your typing — are distinctive enough to identify you even on an unfamiliar keyboard; banks use them to authenticate, employers to monitor. Mouse paths, scroll behavior, and the precise way you tilt and grip a phone can all be rendered into a behavioral fingerprint by the right model. Most of this is collected silently, as exhaust from ordinary use, with no moment where anyone says "we are now taking your biometrics."

What makes this category distinct is permanence. A breached password is a bad afternoon; you reset it and move on. A breached biometric is a life sentence. You cannot reissue your face, your voice, your gait, or your fingerprints. When a database of biometric templates leaks — and databases leak — the exposure does not expire. This is the strongest argument for treating biometric data as a categorically different class, deserving of consent standards and retention limits far stricter than those for ordinary personal data, precisely because the harm from a breach is irreversible in a way no other data breach is.

The inference problem

The most consequential shift is subtlest: the danger is increasingly not what you hand over, but what the system deduces from it.

The landmark demonstration is the 2018 Stanford study by Michal Kosinski and Yilun Wang, which trained a classifier on around 35,000 facial photographs from a US dating site and reported that, given five images of a person, it distinguished gay from straight men with about 91 percent accuracy and women with about 83 percent — far above human guessers. The paper became a lightning rod, and its epistemics deserve care, because it is exactly the kind of claim that gets repeated in a distorted form. The high numbers describe a narrow, artificial task: ranking a matched pair, one gay and one straight, and picking correctly. Applied to a realistic population, where gay people are a small minority, the same classifier would generate false positives in overwhelming numbers. Critics also argued the model was reading grooming, pose, eyewear, and photo style — cultural presentation — rather than fixed facial structure, and the sample was self-selected, young, and overwhelmingly white. So the honest reading is not "AI can read sexual orientation from your face." It is narrower and, in a way, more unsettling: a cheap model can extract a statistical signal correlated with an intimate trait from images people posted for an unrelated purpose — accurately enough to be dangerous and unreliably enough to be unjust, both at once.

That is the shape of the inference privacy problem in general. You consent to share data A for purpose X. A model uses A to infer B — something you never disclosed and never would — for purpose Y you never agreed to. The inference is invisible. You cannot see it, correct it, or contest it, and it can be wrong about you and still decide your life. Systems have been shown to estimate health status from purchasing records, political leaning from browsing and "like" patterns, and personality traits and income from digital traces gathered for anything but that. The violation is qualitatively different from ordinary data collection because there was no collection to consent to or refuse — the sensitive fact was manufactured, downstream, inside a proprietary model you will never see.

The harms are not hypothetical. Insurers explore inferring health risk from lifestyle and social-media signals to price premiums. Hiring platforms analyzed recorded video interviews to score candidates on "employability" traits — HireVue built a business on facial and vocal analysis before dropping the facial component in 2021 under sustained criticism that it was pseudoscientific and discriminatory, which tells you the practice ran ahead of any evidence it worked. And predictive policing systems infer risk from neighborhood, demographic, and prior-contact data, shaping where officers go and whom they stop. ProPublica's 2016 investigation of the COMPAS recidivism-scoring tool found it wrongly flagged Black defendants as high-risk at roughly twice the rate of white defendants — an inference, opaque and contestable, feeding decisions about human liberty. In each case the person affected has no view of the model, no knowledge of the inference, and no route to challenge a conclusion that may be methodologically shaky but is nonetheless acted upon.

Making inference restrictions enforceable is genuinely hard, precisely because the offending step happens inside a black box. The most promising approaches regulate not the inference itself but its use — barring specific decisions (pricing insurance, screening hires, allocating policing) from relying on attributes derived rather than disclosed — and shifting the burden onto operators to prove, on audit, that a prohibited attribute did not drive an outcome. That is difficult, but it is the only lever that reaches inside proprietary systems, because it does not require seeing the model to catch the harm.

The regulatory race, and who is winning it

Governments are responding, but consistently slower than the technology moves, and the geography of the response tells its own story.

The European Union's AI Act is the most comprehensive framework yet. It entered force in 2024 and phases in over years: its bans on the most objectionable practices and its AI-literacy duties began applying in February 2025, obligations on general-purpose models in August 2025, and the bulk of its high-risk rules in August 2026, with certain provisions reaching further still. The prohibitions matter here — the Act bans social scoring, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, biometric categorization by sensitive traits, and, with narrow law-enforcement exceptions, real-time remote biometric identification in public spaces. But note the timing against deployment. London's permanent cameras and Flock's gig-reviewed network were being switched on in 2025, while Europe's binding high-risk rules only arrived, in force, in 2026 — and Britain, post-Brexit, is outside the Act entirely. Regulation is arriving after the deployment patterns it hopes to govern have already hardened into normal practice, not before. Norms set first are expensive to unset.

The United States offers the opposite lesson: the precedent of absence. There is no federal privacy law and no federal AI statute, and that vacuum is itself a policy choice with consequences. States fill it unevenly. Illinois's Biometric Information Privacy Act (BIPA), passed in 2008, is the sharpest instrument in the country — it requires informed written consent before collecting biometric data and, crucially, gives individuals a private right of action, the right to sue directly. That single feature turned BIPA into the one biometric law companies genuinely fear: it produced Clearview AI's settlement and a $650 million class action against Facebook over photo tagging. California's CCPA, Virginia's VCDPA, and biometric statutes in around twenty states form a patchwork with inconsistent scope and mostly weak enforcement. The practical effect of the patchwork is telling — because BIPA has teeth and the rest largely don't, some firms disable specific features (voice sorting, face grouping) only for Illinois residents rather than change the product everywhere. Regulation without a private right of action gets ignored until litigation forces the issue; the pattern shows that what changes corporate behavior is not the existence of a rule but the credible threat of being sued for breaking it.

China rounds out the picture as the third model: extensive AI governance oriented toward state capacity rather than individual privacy. Formal privacy protections exist on paper and even constrain private companies, but they yield to state security, and the government itself is the largest deployer of facial recognition and predictive policing on earth. The global result is a fragmented, unevenly enforced environment chasing a technology that iterates faster than any legislature.

The acceptance gradient

The most powerful force normalizing surveillance is neither technological nor legal. It is psychological, and it operates without anyone ever being coerced.

Research on public acceptance of facial recognition finds a consistent pattern: the more people trust the deploying institution and the more security benefit they perceive, the more privacy they will trade. Nobody has to force the bargain. Unlocking a phone with your face is genuinely convenient. Airport face scanning genuinely shortens the queue. Loyalty tracking genuinely gets you the discount. Each trade, taken alone, is reasonable — even smart. This is the acceptance gradient: normalization through a long series of individually rational, individually convenient concessions, none of which feels like a decision to surrender privacy, whose cumulative sum is comprehensive continuous monitoring nobody consciously chose. What makes the gradient so hard to interrupt is that there is never a single moment big enough to resist. There is no vote, no contract, no line in the sand — only a thousand small yeses, each too minor to fight, adding up to a default that has quietly flipped from privacy to visibility. Once that default flips, opting out stops being the natural condition and becomes an active, costly, faintly suspicious act: the person who covers the camera, refuses the face scan, declines the app.

Generations compound the drift. People who grew up inside social media and constant digital visibility report measurably different privacy expectations than their elders — more willing, on average, to trade data for convenience, less unsettled by being watched. As those cohorts move into positions of authority, the baseline moves with them, and a concept that once felt fundamental risks being redefined into something smaller, or dissolving altogether. Which raises the question the young in particular may struggle to answer: what would a meaningful private sphere even consist of? Not secrecy, necessarily, but the existence of some unobserved space — a place to think an unfinished thought, hold an unpopular view, or simply be unaccountable to no audience — where the self can form before it is measured.

And one structural fact hangs over all of it. Surveillance infrastructure, once built, is almost never dismantled. It is refined, extended, repurposed, made cheaper — but the cameras do not come down. This is where the darkest question lives, and it is not paranoia but pattern recognition. A capability built for one purpose is available for any purpose its controller later chooses. A network installed to catch shoplifters or count warehouse minutes or find wanted suspects is, in its bones, a network for locating and tracking people — and that is exactly what an authority bent on political control would need. History is not reassuring: the East German Stasi, before computers, achieved near-total monitoring with paper files and informants, and the technical ceiling that once limited such ambitions is gone. The structural risk is that the tools are neutral and the intentions are not permanent. A democracy that builds a surveillance apparatus is trusting every future government to be as restrained as the present one. That is a large bet, made mostly by default, and it is the one being placed right now.

Summary

AI turned surveillance from a costly, human-limited activity into a cheap, continuous, largely invisible feature of ordinary life. A few points are worth holding onto.

  1. At work, the monitored categories now span keystrokes, screenshots, application and website use, active/idle time, email and chat content, location, webcam images, and voice tone and emotion — condensed into real-time productivity scores. The US legal baseline is permissive: the 1986 ECPA lets employers monitor under "business purpose" and consent exceptions, there is no federal duty to disclose monitoring at all, and only a handful of states — Connecticut, Delaware, and New York — require notice.

  2. The enabling change is a collapse in cost structure. Human surveillance scaled one watcher per watched; AI makes the marginal cost of watching one more person approach zero, turning surveillance from a rationed variable cost into a fixed cost whose logic pushes toward watching everyone, always.

  3. Facial recognition is operational, not speculative — London's permanent Croydon cameras are the clearest case of what "permanent live facial recognition" means: every passing face checked against a database, continuously, with no chance to decline.

  4. Biometrics extend well past faces to voiceprints, gait, and keystroke dynamics, collected as exhaust from ordinary use. Their defining feature is permanence — a breached biometric cannot be reset — which justifies categorically stricter protection.

  5. Disaggregating surveillance into gig piecework dissolves accountability, replacing institutions with chains of responsibility with a mesh of contractors in which no one is identifiably responsible when things go wrong.

  6. Inference is the qualitatively new threat. Systems derive undisclosed sensitive attributes — orientation, health, politics — from data shared for unrelated ends. The Stanford orientation study is real but widely overstated; its honest lesson is that cheap models extract dangerous, unreliable signals from innocent data. Documented harms already reach insurance pricing, hiring, and predictive policing, where ProPublica found racially skewed risk scores driving decisions about liberty.

  7. Regulation is arriving after the fact. The EU AI Act's binding high-risk rules landed in 2026, after 2025's deployments; the US federal vacuum leaves a patchwork where only Illinois's BIPA, with its private right of action, reliably changes corporate behavior.

  8. Normalization runs through an acceptance gradient — a thousand convenient yeses with no single moment to refuse — and infrastructure, once built, is essentially never removed. The unresolved risk is repurposing: tools built for security or productivity are, structurally, tools for political control in the wrong hands, and building them is a bet that every future government stays restrained.

Sources

Write succinctly. Answer the question directly, lead with what matters, and stop when you're done. Skip preamble and postamble.

Last updated: 2026-08-05

V2 (in progress) Previous: V1