Taylor Lorenz’s Power User - How the Government Uses AI to Spy on You
Episode Date: July 17, 2026The government is using powerful AI tools to build massive digital dossiers on everyday citizens, and it’s happening with zero oversight.SUPPORT MY WORK: Buy a paid subscription to my newsletter at... https://www.usermag.co Support my work on Patreon: http://patreon.com/taylorlorenz In this episode of Free Speech Friday, I sat with Matthew Guariglia, Senior Policy Analyst at the Electronic Frontier Foundation (EFF), to expose how generative AI has democratized mass surveillance. From the FBI’s massive physical paper filing hangars of the 20th century to modern AI models that scrape your social media, track your geolocation, and predict your political affiliation in seconds—the barrier to entry for government surveillance has officially collapsed.We dive deep into Guariglia's recent congressional testimony on the AI security landscape, revealing how the Pentagon is blacklisting tech companies like Anthropic for trying to restrict AI from being used in autonomous weapons and mass surveillance. In this video, we cover:How AI is automating mass surveillance at an unprecedented scale.The secret government contracts and the battle for unrestricted AI use.Why your social media history, geolocation, and purchases create a permanent record.The historical lessons from Ferguson and the Japanese-American internment that prove data is vulnerability.What you can do to protect your digital rights (hint: it starts with turning off your geolocation).
Transcript
Discussion (0)
You don't know what you have to hide yet because things change and data outlives legal regimes.
If you go back to pre-Dobs, people would go and get abortion care without really thinking about the fact that data was being collected that could retroactively hurt people.
AI technology continues to proliferate at breakneck speed.
But while there's a lot of energy for reining in the capabilities of these big tech companies, there hasn't been a lot of discussion about regulating how,
the government and different entities can even use AI.
Dr. Matthew Guariglia is a senior policy analyst at the EFF, and he testified to the government
recently about how governments should not adopt emerging and powerful AI technologies without
also adopting clear and strong safeguards.
He's researched and reported extensively about how generative AI technology is being used
to supercharge unconstitutional violations of civil liberties, and how government secrecy,
in addition to the black box of for-profit
property technology prevents the public and lawmakers from knowing when AI models even make a mistake.
So today I'm really excited to have Matthew here to talk about his work on AI and mass surveillance
and how the government is using this technology to obliterate our civil liberties and what we can do
to fight back and mitigate these effects.
Hi, Matthew, welcome.
Hi, I'm glad to be on the show.
So I want to dig into the work that you're doing around AI.
I feel like there's been so many concerns, especially online, about the impact of AI in terms of
the environment, the physical impact, a lot of discussion around harms for children.
I put that in quotes because I think sometimes the stories can be misleading, but you're kind of
diving into something else, which is this threat of mass surveillance and how AI has really
democratized mass surveillance in a lot of ways. So when did you first start digging into this
issue?
AI emerged on my radar as it did everybody else just in the last few years in terms of thinking
about automated decision-making and taking aspects of governance already that are harmful
and that we understand they're harmful things like unaccountable bureaucracy that makes decisions
without a lot of transparency or accountability or mass surveillance which has existed for a long
time and really kind of automating those processes so they are less accountable less democratic
and potentially can happen at a scale much larger and much faster than we're used to well i'm
I'm curious if you can kind of explain how that works.
I mean, I feel like we all understand probably a lot of us have used AI for surge.
In your recent congressional testimony, you talked about how it's not just the scale,
but the ease of use and access to this technology brings.
You brought up this fact that, which I didn't know, that I guess like previously when
you would do searches or the government wanted to like use certain spyware they had to rent
out entire airport hangars to store the data physically.
There was this bar for entry, I guess, for surveillance and a lot of these tools.
And now obviously AI has kind of like lowered that far.
So yeah, I'm wondering if you can explain how that shift has happened and what the results are.
This goes back actually longer than the existence of modern digital technologies.
When you think about the growth of the FBI in the 20th century, they would collect these files and people.
These files were big paper artifacts.
They took up space.
It took a long time for people to physically type them.
And then you had to store them somewhere.
And the FBI had airplane hangers where they were filled with filing cabinets.
where they kept fingerprints and files on millions of people.
And if you wanted to go through and, like, try to find connections or think about somebody's
politics, you had to, like, go physically there.
You had to dig through the pile.
You had to read 100 pages of what the FBI thought about this person.
And then you had to see if that linked up with another person.
You had to do the same thing again.
And so the barrier to entry to surveillance was quite high, right?
Like, some bureaucrats had to think about you.
They had to know about you.
They had to go alphabetically to where you.
your file was stored and they had to read a lot of pages. And so the protections for most of us
were that you were kind of obscure. It actually took a tremendous amount of effort to think about you
and to surveil you. AI kind of automates that system and really reduces the amount of effort,
amount of labor it takes to actually put people under a microscope. And so now you have AI that can
scrape your entire public presence on social media and the web. It could look at your friends list,
who you follow. It could infirm.
things about your politics and cross-reference that with your campaign donations or with your voting
record, how often you vote. And so you could cross-reference that with data brokers selling your
geolocation. So suddenly you have the ability to, without any human labor really at all, create
massive dossiers on people. And it's really concerning. The dossier thing is so real. I mean, I was
watching that movie All the President's Men about Watergate recently. And it was so bizarre to even watch
the depiction of what journalism used to be like and how hard it was.
Like, they had to go through the phone book at one point.
I was like, oh, yeah, I guess you couldn't just Google people.
Like, it is so easy now where everyone has an online footprint to dig things up.
And as a journalist, of course, you spend quite a lot of time.
It's not always so easy.
It's much easier, right?
But you still had put together usernames, go through lots of websites, do a lot of reading.
And now we have these systems that can just read for us.
And you mentioned political affiliations.
Can you talk a little bit more about what these AI,
systems can infer about a person and how that information could be used against people.
Because I think a lot of people might say, well, I don't have anything to hide.
That's the favorite response that people love to say is, well, I'm just living my life.
So what if they know I'm a Democrat?
You know, I have nothing to hide.
I'm not part of one of these fringe groups protesting, whatever.
I'm just sort of like a normie.
So why should I worry?
Yeah, I mean, I love getting this question.
And I do, as you can imagine, almost constantly.
And the answer is, one, if you live in a space where
tremendous amount of surveillance doesn't affect you.
Congratulations.
You are quite a privileged person, and you live in a state
where that vulnerability doesn't come back to haunt you.
But there are a lot of neighborhoods where constant surveillance
is the name of the game, and because of that constant surveillance,
things are much more enforceable.
You know, they say that, like, the average person commits
a number of felonies a day.
I don't know the exact number.
And a lot of us don't expect for that to haunt us.
We speed all the time.
We roll through red lights.
We hit that yellow just as it turns red, we litter, who jaywalk, whatever it is.
Not me for the future AI scraping this.
Some people can get away with that because you don't live under a constant state of surveillance.
I mean, one of the things we learned about the Ferguson report is that Ferguson, Missouri,
a huge portion of the city's budget was made up of this mass ticketing regime
that disproportionately affected black residents.
And that is enabled by mass surveillance.
It is.
And so one, if you think surveillance isn't affecting you,
and that it's a kind of like philosophical problem
and it's not a real harm, like, congratulations.
You live a very privileged life.
And the other thing is you don't know what you have to hide yet
because things change and data outlives legal regimes.
If you go back to pre-Dobbs,
people would go and get abortion care
without really thinking about the fact that data was being collected
that could retroactively hurt people.
And Donald Trump said in his 2015,
his first presidential campaign that he would consider prosecutions for people seeking abortion.
And like, that's the kind of thing that haunts people who think about surveillance because you know
that data is out there.
And there's like a million different ways.
I mean, you know, certain political affiliations you have.
If you go to a protest and you think it's a peaceful protest and then somebody knocks over a trash
can and lights on fire and suddenly everybody who's at that protest could be considered a criminal
suspect or how many people have purchased marijuana in states where it's legal if it became
not legal tomorrow, there will be records of you haven't purchased that. You know, there are so many
things you can think about. And it's historic too. The people who led the way in the 20th century for
collecting a lot of data on people was this nation of Germany. And people didn't think that it was a
huge problem that the German state had collected all of this data until in 1933. The people who
inherited all of that data were the Nazis. And that's a very hyperbolic. I know there's the rule of the
internet that eventually everybody's going to get to Nazis. But it is something you have to think about
because there are American examples too with the U.S. Census being used to help find Japanese Americans
for internment. If you're watching this video and you like my work, please support me on Patreon
via the link below or buy a paid subscription to my tech and online culture newsletter at usermag.com.
That's usermag.com. I don't have any long-term brand partnerships and a lot of my content
is effectively demonetized. I've lost major brand deals for speaking out on certain issues.
and for challenging power.
As you can imagine, advertisers are not exactly eager
to work with somebody who covers a lot of the topics that I cover
and talks about the things that I talk about.
These videos I make are entirely funded by you
and I can't continue to make them without your support.
So if you get any value out of the videos that I create
and you want me to be able to create more,
please support me on Patreon or Substack via the links below.
On Patreon, I do bonus episodes, monthly Q&A live streams,
and post frequent updates about my work.
My Substack newsletter gives you a biweekly
roundup of everything that I'm seeing and reading and paying attention to online. You can also get
my newsletter on Patreon. Once again, the links to everything are below in the description. Every
dollar of your support makes such a difference. I think of actually this conversation that I had
with a January 6th attendee. I was going to say rioter, but they're adamant that they did not
participate in the riots. And this was sort of an aspiring content creator that I had spoken to that
said that they really just attended that day to kind of see what would happen. And because of the
amount of surveillance documentation, including, obviously, content creators, live streaming everything,
documenting things. They don't necessarily even believe a lot of that ideology, but there's this
deep digital footprint that everybody has. And I think it's really hard to move beyond that footprint
or to even evolve or change your beliefs on things when you have all of this data on you that's
sort of prototyping you or that can be used against you. It feels futile for individual people.
Yeah, I mean, I think this is where we sometimes lose something by sticking with the word privacy,
Right? Like, privacy is something, especially young people, have been giving up their entire lives, privileged young people.
And what they get in exchange for giving up that privacy is convenience and connection.
And I really think the way we have to think about it is vulnerability.
All these apps and websites and speed cameras and license plate readers and data brokers, all these things are collecting information about you.
And that could lead to nothing.
You could never, ever see the consequences of all of that data.
But it's always going to be out there.
And that is, I think, the nature of its vulnerability.
We are all vulnerable to who is going to eventually inherit that data,
what they're going to want to do with it,
or how legal regimes might change around us.
I know, and I know you focus a lot on the government
and there are so many concerns there.
The genre that I feel like most resonates with people
when I talk to them is corporations,
like with the rise of surveillance pricing.
And I'm like, well, do you want that data to be used
to charge you more for a home loan, you know,
in 10 years?
or whatever, like, you could pay more.
And I feel like to Americans, especially all of us that are strapped for money,
that threat of paying more somehow feels more urgent than even a government threat.
Well, I mean, I think that goes to, like, one of the biggest industries that moved into
the realm of surveillance earlier than most is the insurance industry for exactly that reason.
The insurance industry is driving a lot of the new surveillance we're seeing in cars.
It's driving in terms of health insurance, a lot of the surveillance that we see around.
I'm like who gets access to Fitbits and who gives you that type of biometric tracking.
Because the fear has always been, you know, your employer who pays for your insurance gives you a cool fitness tracking wristband or something.
And then every time you don't work out and instead you go to a donut shop, your insurance company, your employer sees that and they can raise your premium.
I'm curious how the models are evolving and what safeguards are being put in place.
You testified recently at this congressional hearing titled the AI security landscape.
Frontier models, agentic AI, and AI coding tools are reshaping cybersecurity and critical infrastructure
resilience. Sounds very like congressional. That name is very boring. But you talked about how
actually these companies are becoming quite explicit and the government is incentivizing this mass
surveillance. Can you break that down for us in terms of what's going on with like anthropic and mythos
and the way that the Trump administration, I would say almost like overtly pressuring them to be on board
with mass surveillance or to conduct mass surveillance for the government? Yeah. I mean, I think what's
happening is one of the main avenues through which the U.S. government is very excitedly acquiring
and deploying AI models is the realm of cybersecurity, because it turns out that one aspect of
AI that has proven fairly useful is its ability to find vulnerabilities in critical digital
infrastructure. And the U.S. government is excited to buy and deploy all these things, but at the same
time, the U.S. government, and specifically the Pentagon, has made it clear that whatever technology
they acquire, they want no restrictions on its use. And this came up with a dust up that they had
with the company Anthropic over Claude, where Anthropic had said that they didn't want
their technology used for either master balance of Americans or fully autonomous weapon systems. And
the Department of Defense said, we don't tolerate that. They said something about woke AI, and they
He said, we want no restrictions on this.
If we buy your technology, we want to be able to use it to embark on this mission of maximizing
lethality, as the Pentagon keeps talking about these days.
And so Anthropics said, no, we don't want to do that.
We don't want our technology used that way.
And so they essentially blacklisted them.
They labeled them a supply chain risk, which means that other government contractors, like
Lockheed Martin or Boeing or whatever, couldn't use Claude in pursuit of creating.
or selling tech or hardware to the U.S. government.
And so it really kind of crippled things and caused a lot of companies to panic very quickly.
But it sets a really dangerous precedent for a number of reasons.
One is that technology companies, including ones that could be quite useful,
like AI that could be deployed for finding critical liabilities in digital infrastructure,
companies that make stuff like that are going to be less willing to sell their technology to the government
if they think their technology is going to be used for things they don't want it to be used for,
or that they even say explicitly, the technology is made for this.
Don't use our technology for guiding missiles.
It's not useful for that.
So I think they're going to be reluctant to sell technology to the government for that reason.
And two, the people who are deciding your privacy are not elected officials.
It's not the laws that we're trying to work together to create.
It is the private contract negotiations between a huge AI company and the Department of Defense.
That is not who should be deciding what kind of privacy we get.
To me, that was the really insidious part.
I don't really believe that a lot of companies won't do business with the government.
I think they want money.
But I do worry that a lot of this stuff is private.
And there was a lot of outrage online over the autonomous weapons, rightly so.
But the mass surveillance stuff to me was just as insidious and terrifying.
Do we have any sense since all that happened, how the government is using these AI tools to violate our rights?
Do you have any idea of how this is being used in practice?
Yes and no.
One is it's incredibly classified, right?
Everything that's happening right now is so opaque.
It's going to take years for us to find out all of the insidious things that this administration was doing with AI in terms of mass surveillance.
I mean, I think about how many years it took for us to know how much surveillance was on movements like Occupy Wall Street or Black Lives Matter.
I mean, it took years and years.
So this because it includes also the national security state and not just local police, that has an extra layer of secrecy.
on top, it's going to take even longer for us to understand if we ever really understand the extent of it.
So to that extent, no, we don't really have a full picture, but we know how AI companies like
Palantir are aiding and abetting this administration when it comes to their violation of civil
liberties. Palantir is a tool that layers on top of preexisting government data infrastructure.
So the government collects all this data. They put it in databases and they put this tool over
that can do all the analysis.
And we know that ICE is using this
to devastating effect in communities.
I'm curious how you think we can mitigate all of this.
Because when we talk about cracking down on AI
or holding AI accountable, I was just watching an ad for Alex Boris,
this congressional candidate in New York right now,
who constantly claims he's going to do this.
But most of what it seems like they're talking about
is actually, I would argue, kind of mass surveillance policies,
it's like, well, we're going to make it
so everybody has to upload their government ID to
use an AI tool and that way children won't be on it and that way will have prevented AI harms.
And you hear a lot of these sorts of ideas for holding AI companies accountable.
What are your thoughts on, I guess, like those policies and then we can get into maybe some more
effective means of holding AI accountable?
For all this, you know, automated decision making, machine learning, it is infrastructure, right?
It can be used for good or for ill.
A lot of the reforms that I think would be most effective, most critical.
is getting to the societal problems that AI is just exacerbating.
AI is amplifying civil liberties and fractions.
It is making government surveillance more rapid.
It is growing out the capacity.
But ultimately, I think regulating AI is only part of the solution.
The other part is you need to go after the problems that are just being exacerbated by
AI.
Yeah, I mean, I think we have to tackle the root issue.
I've written a lot about this, especially with the children issue.
Like a lot of these cases, they're not cut and dry.
It's not like little Johnny went on a chat bot and it said,
kill yourself or something.
These are kids that are struggling that were let down repeatedly by the system
over and over again.
Often warning signs were ignored and it's horrible.
So there's just a lot more complicated cases.
There's something you were saying before,
these conversations and these negotiations around our privacy
are not happening in Congress or in transparent ways.
They're mostly being made in these private contract negotiations
with the government.
Are there any efforts to bring transparency to that process or establish some sort of like bill of digital rights, I guess, for us AI users or internet users or anybody that's subjected to this technology?
I think Congress has fully abdicated its responsibility to keep us safe when it comes to technology.
They are more or less absent.
And I think if you want to look toward where protections for us are coming from, they're usually happening at the state level.
You know, like the California Consumer Privacy Act or the Illinois Biometric Privacy Act,
which says that companies like Facebook can't take prints of your face without your permission.
They can't collect biometric information on you.
And so I think a lot of states have been acting.
And so how protected you are from a lot of consumer privacy infractions,
from a lot of government surveillance just happens to be like what state or what city you're in.
I mean, a lot of cities have banned police government use of face.
recognition, which is something that should happen everywhere, but it just depends on where you live.
Which is, I think, also probably why so many in the AI industry and certain people in the government
also want to preempt all these state AI regulations and kind of ensure that this technology can
continue. You mentioned data brokers earlier as well and just how data from data brokers and the
data that's all out there on us can be so quickly analyzed by these systems. Is there anything
that people can do to protect more of their data? Are there ways to kind of attack the problem
on that end? Are consumers totally at the mercy of these systems? Because I feel like it's scary.
I mean, I've definitely started stripping the metadata from things where like even when I text
somebody a picture, I text them a screenshot of the pictures that it doesn't have like the
original. I don't like I feel like I'm going crazy sometimes. But it feels overwhelming. And it's like,
I don't know, yeah, what your thoughts are. This is a collective problem that needs collective solutions,
right? To say that first to get that out of the way. Privacy is a team sport. We can only do so much
ourselves if the people were texting every day or our boss don't have like good password protection
and they get hacked and they send you an email and you click a link and then you're hacked. Privacy and
digital security is a team effort and a lot of these have collective problems. But yes, there are some
things we as individuals can do. And here I'll plug EFF's incredible surveillance self-defense guide,
SSD, which has a lot of tailored guides as well for different scenarios, for different people who
want to think about their threat models differently and who might be surveilling them.
But yeah, I mean, things you can do are like turn off geolocation on as many apps as possible.
You know, there's no reason cute dogs daily app needs your geolocation because odds are that app is
trying to make a little bit of extra money by selling that geolocation to data brokers.
And then anybody with money can buy your geolocation all the time, including the government.
So, yeah, I mean, I think turning off geolocation on your phone is like, first and foremost, one of the
ways that we can do that.
I want to see people get a little bit more outrage
and ask tough questions about the government.
I think there is plenty of motion for people that want
to see anti-AI regulations.
Some of them are misguided.
Some are really good, right?
But also, we have to put guardrails around not just the AI
models, but the ways the government can use them.
There is one quote from your testimony where you said,
at this level, the question is not, how do we rein in AI?
It's how do we rein in the agencies that would unleash
AI on the American public.
And I'm wondering if you can just expand on that a little bit,
because I think it's a really good distinction to make.
Yeah, I mean, there are so many pieces of digital technology
that just amplify and exacerbate pre-existing harms.
And just regulating the tech isn't necessarily going to stop the harm from happening.
There are a lot of cities that have done the very admirable effort of banning predictive policing.
And I think we should have a ban on predictive policing that should be everywhere,
should be across the country.
But oftentimes we have to think that the problem with predictive policing,
is as much the policing as it is the predictive, right? Like, if it weren't for the fact that our
police are harmful and dangerous and they go out and arrest people when face recognition spits out
a name without doing any follow-up investigations or if we could trust police not to kill innocent
people, we would be less angry at the technology. And so really oftentimes I think about we have to
disaggregate. We have to do both. We have to regulate the technology, but we have to disaggregate
what harms are caused by the technology that we need to regulate and what harms go deeper than that,
and they have to do with how we've organized government and society.
And we also need to do the much harder work of regulating that.
Because regulating technology is universally popular right now,
a lot of people just claim to want to regulate their technology and they pass laws or seek to pass laws
that exacerbate all of those other underlying harms that I would argue just make a lot of these problems worse.
Yeah, and the people who end up hurting are the most vulnerable.
members of society, always. Yeah.
I'm curious what you think also just about the proliferation of AI technology and models.
I feel like we're all familiar with Open AI versus Anthropics.
I know there's Elon Musk Grop, but there's also all these open source models and
deep seek and foreign models.
And it seems like this technology is actually just proliferating at a rate that even
if we regulate the biggest companies, it almost feels like the cats out of the bag a little
bit.
What are your thoughts on just like, is it too late to try to like rain in a lot of this technology
or just are we on this train?
And the goal is to maybe just try to prevent it
from doing as much damage as possible.
Yeah, I mean, I think the cat's never out of the back.
It's never so far gone that we can't rain things in,
even big, powerful things in companies, right?
I think a lot of the people who want us to believe
about the inevitability of AI, or even how dangerous and powerful
and scary AI are, are the people who stand to sell it.
Because these companies actually benefit
the scarier you think that.
tech is. Every time we talk about, uh-oh, AI apocalypse, their stock goes up because it makes their
tech seem more powerful and more capable than it actually is probably. And so I think the cat's not
out of the bag yet. And I also think that ultimately, we have to regulate the tech in a way that's not
going to crush the small innovators and is just going to leave the big ones who can pay mass of fines.
And so like, I think we have to be careful that we don't create a world in which the only AI companies are the big and powerful and scary ones.
Or that AI is only being used for mass surveillance.
And that's the primary use instead of all the amazing things that AI could be putting its mind to.
Potentially. I don't know.
Who knows?
I love that because every time I talk to one of these tech groups or whatever, and they're like, and you know, so what, we're not going to get the cure to cancer.
And I'm always like, is anyone at your company working on that?
Is that what you're being?
No, that's not what your business is.
What are you talking about?
You guys aren't even working on that.
Maybe you gave a grant once, like, five years ago to a cancer foundation or something.
But, like, what you guys are selling is not the cure to cancer.
You're selling democratized mass surveillance or other consumer B2B tools.
Yeah, I mean, I always think about, I don't know if it was a tweet or just kind of like a joke that was in the zeit guys.
They said that AI would take all of our bullshit jobs and we would be free to write our screenplays.
But instead, we're all doing our bullshit jobs and AI is writing the screenplays.
It's frustrating. At the same time, I'm not like a total domerhead.
I'm sure people are going to leave hate comments.
They do every time I say this, but I do engage with the technology.
I think it can be useful.
I talked about how I love vibe coding tools, making a birthday website for my friend that's a fun,
interactive thing.
I'm not against the concept of technology.
It's just about how it's deployed.
And like you said, looking a little bit deeper as well, not just on regulating the companies themselves,
but how this technology can be used by powerful entities like the government or other corporations.
The big takeaway for me is that it's really easy to propose solutions that are just the technology-based, right?
The other side does this all the time.
When there's crime, they think the easiest solution is just to throw up more cameras.
Rather than address the harder, deep-seating questions of like, well, where does crime come from?
How do we just the root causes of crime?
Because cameras obviously don't stop crime.
They don't prevent crime.
And so I think the reverse of that is true as well, is when we're looking for solutions to harms done by,
by big companies and by the government, we can and should, in some extent, blame and regulate the
technology, which is increasing the capacity of their ability to do harm.
But we also think about the social structures that are allowing them to do that.
Well, Matthew, I'm so grateful for all of your work in this area.
I can't wait to continue to follow what you're doing at the EIFF.
And thank you so much for joining me today.
Thank you.
I'll be on any time.
All right, that's it for this week's Free Speech Friday.
If you like my work, please buy a paid subscription to usermag.com.
That's usermag.com.
It's my substack.
I send it once a week.
It's a roundup of everything
that I'm reading and following online.
You can also get that newsletter
on my Patreon, linked below,
where I do bonus episodes,
monthly Q&A livestream, and more.
I currently have zero long-term advertising
partnerships for this channel,
so seriously, every single dollar of your support
makes such a difference.
I'll be back next week
with a brand new episode of Free Speech Friday.
See you then.
