All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
At this very moment, an AI system somewhere could be building a dossier of your life, including your habits, routines, vulnerabilities, and whereabouts, and handing it over to an abusive ex, a stalker, or even a foreign government actor.
And no, this doesn’t necessarily require someone to hack you or break into a system. All it took for CivAI’s demonstration was $500 a month — that’s the price of subscriptions to the kind of commercial data most Americans are unaware of.[1]
Closed-door demonstrations on Capitol Hill by a nonprofit called CivAI have shown lawmakers just how powerful AI has become. It doesn't just find a person; it assembles scattered records into a single profile, and it has alarmed lawmakers on both sides of the aisle.
It knows when you go to church, the kind of things you like to buy online, your favorite coffee shop, and the route you drive every week. It could even know if you’ve been to therapy, find your email login, or potentially guess it based on all the data it already has.
Here are more details about the demonstrations and the steps you can take to protect yourself right now.
AI is making mass surveillance easier
What can you do to protect yourself
Bottom line
How AI can turn your personal data into a dossier
CivAI is a nonprofit that seeks to educate people about the dangers of AI and its capabilities. The Capitol Hill briefings started in late April 2026, amid the congressional debate about renewing FISA Section 702.
As of now, several dozen congressional staffers and lawmakers have seen these briefings. POLITICO’s report is based on interviews with four Republican and eight Democratic staffers, all of whom were kept anonymous because they were not authorized to speak on the record.
The demo starts on a plain page titled AI Data Broker Search and contains a simple input box where one could enter details like a name, phone number, email, or profile URL.
Users can also enter simple prompts like, “Find church-going Christians in Janesville, Wisconsin, and write a detailed dossier on one.” The tool can then pull together information about that individual from various data sources to build a detailed profile.
The tool was built using GLM-5.1, which is an open-source Chinese AI model from Z.ai. The agent connects to several commercial data brokers, with subscriptions costing about $500 per month.
The kind of information the tool uses to profile people doesn’t necessarily come from a fresh data breach or information obtained from illegal sources. Much of it is the kind of information that’s already available through commercial data brokers, although the demonstrations also incorporated data from previous breaches.
According to a staffer who had sat through these briefings, the dossier contained the following results:
- Passwords tied to an individual’s email, surfaced from past data breaches. An example included a gun store owner’s leaked credentials.
- A person’s mental health treatment history.
- Visits to abortion clinics and lawmakers’ offices.
- Predictable routines, such as commute patterns, recurring locations, volunteering activities, and so on.
- A detailed closing section outlining a person’s potential vulnerabilities, or ways a foreign government actor or a malicious party could use the information to harass, blackmail, or stalk the person.
In a separate demo done by CivAI for the POLITICO reporter Alfred Ng, the dossier was able to find real photos of Alfred and accurate details about his fondness for spicy food and Super Smash Bros. However, in this case, the dossier also produced inaccurate results, such as his age, occupation, and address.
CivAI co-founder Sid Hiregowdara said that these errors were due to the low-cost data subscriptions used for this particular demo. Anyone with access to higher-quality data could potentially get more accurate information.
AI is making mass surveillance easier
AI is now at the center of a full-blown surveillance epidemic.
Rep. Lori Trahan said, “Today, anyone with access to a frontier AI model can buy your data from a broker and reconstruct an intimate picture of your life.”
It's not an entirely new revelation that commercial databases already include a lot of your personal information, such as details on your travel, subscriptions, shopping habits, and social media profiles. Commercial databases have offered this raw material for years.
What changed is assembly speed. "These are the earliest days of what AI is going to enable for surveillance," said CivAI co-founder Sid Hiregowdara. "As things become easier, as you can click a button to do things that would've taken a month or had been very arduous before. That's a different level of capability."
One Democratic Senate aide put it more plainly: "The scalability is quite frightening."
This was also made possible, in part, by the lack of guardrails around some AI models. Silicon Valley companies such as OpenAI and Anthropic limit how their AI tools can be used, particularly for surveillance. However, Chinese open-source models like GLM-5.1 have fewer guardrails against surveillance.
As such, CivAI was able to create its dossier model without constraints. Another thing to note is that this isn’t a “government-exclusive” AI system — the underlying model is publicly available.
One wouldn’t need extensive coding or AI experience, or have to do anything illegal, to create something like this. Users could subscribe to data brokers, get the information they need, and potentially create a similar system in a matter of weeks. CivAI itself built its demonstration in about two weeks.
What can you do to protect yourself
Here are a few steps you could take to limit the amount of data these brokers and AI systems have about you:
- Data broker removal services: Data brokers, especially in places like California and Texas where consumers have certain legal privacy rights, usually give you an opt-out option where you could request them to delete any personal information they might have about you. However, doing so on hundreds of data broker websites could be a tedious task and still not be exhaustive. As an alternative, there are several dedicated services like Incogni or DeleteMe that automate this process and can submit removal requests across hundreds of data brokers on your behalf.
- Check if your passwords have been exposed: You can use a website like Have I Been Pwned and enter your email address to see if it has been a part of a data breach. Alternatively, consider using a reliable password manager so that you can set strong passwords for every login and not reuse them across various accounts.
- Limit location access: Check every app on your phone and revisit its location permissions. Only grant location access to those apps that require it for their functioning, such as Google Maps or Apple Maps, and disable permissions for those that could function without your location details.
- Use an identity theft protection service: It can scan hidden parts of the internet, including known breach databases and the dark web, to look for your personally identifiable information. It will alert you if it finds anything. Many providers also offer identity restoration services, which can help you limit the damage caused by leaked personal information.
Bottom line
CivAI’s demonstrations have sent shivers down the spines of Capitol Hill legislators. Many lawmakers have called this a wake-up call for Congress to bring forth strong legislation to prevent such mass surveillance systems, which are capable of pulling together a person's life history, routines, preferences, and vulnerabilities.
Whether the restrictions would come in the form of legislators imposing restrictions on data brokers or regulating AI models with strict provisions is a matter yet to be decided.
Meanwhile, you can take steps to ensure that data brokers or AI systems can access as little information about you as possible.
Avoid posting extensively on social media platforms, especially your location. Next, opt for data broker removal services and check websites like Have I Been Pwned to see if your email ID has been breached. Also consider using an identity theft protection service.