AI Supercharges Surveillance: Who Watches, What They Collect
AI tools are increasing data collection and analysis by companies, criminals, police and intelligence services across retail, workplaces, online platforms and public cameras.
AI-driven systems are expanding how organizations collect and analyze personal data. Companies, criminal groups, law enforcement and intelligence agencies are using automated tools to gather more data, run faster analyses and create records that fall outside many existing rules.
Commercial actors track customers through logins, cookies and apps that collect activity beyond core services to target ads. Some retailers are testing cameras that match faces or measure behavior in stores. Rebecca Moody, head of data research at Comparitech, called supermarket facial recognition “a huge concern” and warned it risked being repurposed to track buying habits. Website login flows and persistent cookies can link identities to browsing and purchase histories.
Employers monitor email, badge access, device activity and collaboration platforms. AI adds behavioral analytics, sentiment scoring, keystroke logging, webcam monitoring and predictive models that flag burnout or likely resignations. Ensar Seker, CISO at SOCRadar, said some tools improve security while others try to infer emotions or trustworthiness from imperfect data. Stanislav Kazanov, head of GRC at Innowise, argued that employee consent is often nominal and that automated assessments used for HR actions should be accurate and explainable.
Cybercriminals use malware known as infostealers to harvest saved credentials, session cookies, single-sign-on tokens, cloud credentials, browser artifacts, digital wallets, messaging clients and keystrokes. Those data sets are packaged into logs and sold to initial access brokers. Security researchers reported about 4.3 million infected devices in 2024, creating persistent access for follow-on fraud and targeted intrusions.
Private camera networks and automatic number-plate readers collect images and license-plate data that can be matched to faces and movements. Critics say data gathered for a narrow purpose can be retained, repurposed and shared with nonpolice parties, producing long-term location histories. Alex Polyakov, CTO at Adversa AI, warned that collection often “drifts out of control in scale, in detail, in retention, and, most dangerously, in use beyond the originally stated purpose.”
Intelligence agencies combine open-source material, leaked datasets, breached credentials, location metadata and commercial data to build profiles. The Five Eyes partners exchange signals and other intelligence; Tim Freestone, chief strategy officer at Kiteworks, observed that data one nation may legally collect often becomes available to others in an intelligence alliance. In some jurisdictions, legal frameworks have allowed collection of communications that touch domestic users; recent changes affect those authorities but long-standing data flows remain.
Experts highlight limits of AI analysis. Models trained on biased or incomplete data can produce false positives or unfair inferences about health, politics or loyalty. Ilia Kolochenko, founder of ImmuniWeb, described AI-enabled surveillance as “problematic,” noting private investigators and firms can perform intrusive online probes without the legal constraints that apply to government agencies. Mike Silvey, a market adviser, warned that algorithmic errors can be treated as unchallengeable facts when systems are used without human review.
Regulatory responses vary. The European Union has implemented rules such as GDPR and an AI regulation that require data minimization and restrict purpose. In the United States, federal policy has favored voluntary, innovation-focused approaches while some states have enacted targeted laws; Illinois’s biometric privacy law created private rights of action that led companies to change facial-recognition practices. Experts say enforceable oversight can include liability, tamper-evident audit logs and mandatory query logging where law compels them, but they note intelligence and certain law enforcement activities often operate with exemptions and limited transparency.
Security and privacy specialists recommend clearer accountability, stronger controls over automated decision-making and more transparency about what data is collected and how AI models are applied. These proposals aim to make data flows, decisions and retention practices auditable under applicable laws.








