Privacy, Surveillance, and the AI Data Economy
- Explain how facial recognition systems collect and process biometric data, and identify why accuracy disparities by race mean that errors disproportionately harm communities of color
- Describe three documented categories of harm from AI surveillance — the Clearview AI database, wrongful arrests from facial recognition mismatches, and commercial and government surveillance at scale — using verified cases and data
- Identify the major legal frameworks governing AI surveillance — GDPR Article 22, Illinois BIPA, and EU AI Act Article 50 — and explain what specific rights individuals have in each jurisdiction
The 50 Billion Faces No One Consented To
In February 2020, a New York Times investigation revealed that a company called Clearview AI had built a facial recognition database unlike anything that had existed before. By scraping publicly posted images from Facebook, Instagram, YouTube, Venmo, and thousands of other websites, Clearview assembled a collection of more than three billion photos. By 2025, that database had grown to over 50 billion images — the faces of the vast majority of adults in the United States and hundreds of millions of people in Europe, Australia, and South America.
None of these people were asked for permission. None were told. The photos were scraped from platforms where users posted them to connect with friends and family — not to enroll in a government-accessible biometric database. Clearview sold access to law enforcement agencies across the United States, allowing officers to run an unknown face against the database and get back a name, a location, and a history of that person's photos.
Data protection authorities in five European countries found that Clearview violated the GDPR and issued fines: Italy (€20 million, March 2022), France (€20 million, October 2022), Greece (€20 million, July 2022), the United Kingdom (£7.5 million, May 2022), and the Netherlands (€30.5 million, September 2024). Total fines across five countries exceed €100 million. As of October 2025 — when privacy advocacy organization noyb filed criminal charges against Clearview and its founder — none of those fines had been collected. Clearview, incorporated in the United States, had largely refused to comply with European enforcement orders.
The Clearview case is not an outlier. It is an illustration of how AI surveillance can scale — and how slowly law catches up.
How AI Surveillance Works
The term "AI surveillance" covers a range of technologies, but the underlying logic is consistent: sensors collect data about people in physical or digital space; AI systems analyze that data to identify, classify, or predict; and the results feed into decisions about those people.
Facial Recognition
A facial recognition system captures an image, extracts a numerical representation of the geometry of a face — distances between eyes, nose, jaw, and other landmarks — and compares that representation against a database of known faces to find a match. The system returns the closest match above a confidence threshold, which police may use to identify an unknown suspect, grant or deny building access, or flag someone for further scrutiny.
Accuracy is uneven. A 2024 NIST evaluation of 189 facial recognition algorithms found that false positive rates — incorrect matches — were 10 to 100 times higher for Black individuals compared to white individuals across the majority of algorithms tested. When these systems err, they err most often against the people who can least afford the consequences of a wrongful identification.
Behavioral and Location Tracking
Beyond faces, AI surveillance systems aggregate data from mobile location signals, web browsing history, purchase records, social media activity, and connected devices. This behavioral data is bought, sold, and combined by data brokers — companies whose entire business is collecting and selling information about individuals. The Federal Trade Commission has estimated that U.S. data brokers hold information on virtually every American adult.
When behavioral data is combined with facial recognition, the result is a comprehensive profile: not just "this person was at this location" but "this person attends these events, donates to these causes, associates with these people, and has these medical and financial circumstances." A 2024 ACLU investigation found that this combination had been used to monitor Black Lives Matter activists, environmental protesters, and Muslim communities based solely on protected First Amendment activity — with no criminal predicate required.
Wrongful Arrests: When Surveillance Gets the Wrong Person
In January 2020, Detroit police arrested Robert Williams outside his home, in front of his wife and two young daughters. A shoplifter had stolen watches from a Detroit store in 2018. Police ran a blurry surveillance image through a facial recognition system. The system returned Williams's expired driver's license as the closest match — a match that was plainly wrong; the images looked little alike. Williams was held overnight and shown the surveillance photo. He held it up next to his own face. "I hope you all don't think all Black men look alike," he reportedly said.
Williams v. City of Detroit settled in June 2024, producing what the ACLU described as the strongest police facial recognition constraints achieved to that point in the United States. But it was not isolated. By April 2026, the ACLU had documented more than a dozen wrongful arrests in which facial recognition provided the only or primary evidence against an innocent person. Every documented case involved a person of color — consistent with NIST's finding that false positive rates are 10 to 100 times higher for Black individuals in most tested algorithms.
Other documented cases include Nijeer Parks, arrested in Woodbridge, New Jersey in 2019 for a shoplifting incident he had no connection to — police proceeded despite DNA and fingerprint analysis pointing elsewhere. And Michael Oliver, arrested in Detroit in 2019 despite visible physical differences between him and the suspect in the reference photo, including full sleeve tattoos visible in both images and plainly not matching.
Surveillance at Scale: Government and Commercial
The wrongful arrest cases involve a specific, identifiable individual wrongly accused. But surveillance harms can also be structural: the chilling of free expression, the erosion of anonymity in public spaces, and the creation of permanent records of movement and association that can be accessed in ways people never anticipated.
Government
U.S. Customs and Border Protection processed more than 300 million facial recognition transactions in fiscal year 2024 — at airport checkpoints, border crossings, and immigration enforcement. The Brennan Center for Justice documented more than 60 U.S. police departments using predictive policing systems in 2024, including in Los Angeles, Chicago, and Atlanta. Predictive policing directs law enforcement attention toward individuals and communities predicted to commit future crimes based on data reflecting historical policing patterns — patterns that already embed documented racial disparities.
Commercial
The National Retail Federation estimated that 30% of large U.S. retailers deployed facial recognition in stores by 2025, primarily for loss prevention. Madison Square Garden Entertainment deployed facial recognition to identify and bar entry to attorneys involved in litigation against the company — a use that drew First Amendment challenges from civil liberties advocates. A 2024 breach of a Verkada security camera network exposed biometric data from 150 client organizations including hospitals, schools, and corporate offices. Biometric templates, unlike passwords, cannot be changed if compromised.
What the Law Says
Surveillance law varies significantly by jurisdiction. No single federal law in the United States comprehensively regulates government or commercial facial recognition.
What You Can Do
- If you are in the EU: GDPR Article 22 gives you the right to request human review of any decision made through automated processing that significantly affects you — a loan rejection, a job screening outcome, a benefit denial. Exercise this right in writing to the organization that made the decision.
- If you are in Illinois: Illinois BIPA gives you the right to sue companies that collect your facial geometry, fingerprints, or other biometric identifiers without written consent. Several class actions have resulted in settlements of hundreds of millions of dollars; Facebook paid $650 million in 2021, Google paid $100 million in 2022.
- Reduce your data broker exposure: Services like OptOutPrescreen.com (free for credit data) and paid services like DeleteMe allow removal from many data broker databases. This does not eliminate all records but reduces the surface available for aggregation into behavioral profiles.
- Document and report: If you believe facial recognition contributed to an incorrect action against you, document the circumstances and contact the ACLU, a local civil liberties organization, or your data protection authority. Pattern evidence is how investigations and legislation begin.
- Support local and state legislation: City-level facial recognition bans have been achieved through local organizing. Several U.S. states are currently considering biometric privacy laws modeled on BIPA. These campaigns are among the most structurally impactful actions available to individuals concerned about AI surveillance.
The next lesson examines a different kind of AI-enabled harm — one that targets truth itself. Deepfakes and AI-generated synthetic media have made it possible to put words in anyone's mouth and place images in any context, at scale and at speed. What does it mean for information and trust when you cannot believe your own eyes?
- Clearview AI built a 50+ billion face database by scraping social media without consent; five EU authorities imposed over €100M in fines, but as of late 2025, none had been collected and criminal charges were filed as enforcement escalated
- By April 2026, the ACLU documented more than a dozen wrongful arrests directly caused by facial recognition mismatches — all involving people of color, consistent with NIST's finding that false positive rates are 10–100× higher for Black individuals in most tested algorithms
- AI surveillance operates at massive scale: CBP processed 300M facial recognition transactions in FY2024; 30% of large U.S. retailers used facial recognition by 2025; predictive policing ran in 60+ police departments — often without meaningful public notice or opt-out
- GDPR Article 22 (EU), Illinois BIPA, and EU AI Act Article 50 (enforceable August 2026) create rights around biometric data and automated decisions, but coverage is uneven — there is no federal U.S. law comprehensively regulating government or commercial facial recognition
- Practical protections include invoking GDPR or BIPA rights in writing, reducing data broker exposure, documenting and reporting AI-driven harms to regulators and civil liberties organizations, and supporting local biometric privacy legislation