You posted a photograph in 2014 to show your friends a night out. You understood what you were
sharing and who you were sharing it with. You did not agree to every future system that would read
it, combine it with other records, and decide something about you.
That is not a worry about surveillance. Surveillance is about being watched. This is about being
judged from inputs you never knew were inputs, by a rule you never saw, in a place you have
never been.
Here is what that actually looks like, in machines that exist right now.
Four machines that get mistaken for one
1. An allegation that travels. Patronscan sells ID scanning to bars and clubs. Venue flags stay
with the venue. Network flags surface at other participating venues when your ID is scanned. The
pitch is exactly what it sounds like: a patron banned at one venue cannot walk down the street and
start fresh at the next.
Say what a flag is. A venue recorded an allegation. It is a report, not a finding, and it travels
with the authority of a finding.
Their policies page publishes the network-versus-venue distinction, the conduct categories, the
retention limits, who has access, the route for removal, and the response windows. It does not
publish how often a dispute ends with a flag changed or removed, and I found no aggregate rate
published anywhere else. The process is documented. Its aggregate outcomes are not.
2. Affiliation, not conduct. In January 2023 the New York Attorney General sought information
about reports that MSG Entertainment used facial recognition to exclude attorneys whose firms were
litigating against it. Nothing was alleged about anyone's behavior. The input was who employed them,
and being on one side of a lawsuit is not wrongdoing.
The litigation is worth two paragraphs, because it answers a question people assume they know.
In Hutcher v Madison Sq. Garden Entertainment Corp. (2023 NY Slip Op 01646), the Appellate
Division agreed that Civil Rights Law § 40-b requires admitting a valid ticket holder to a
theatrical performance or concert. The plaintiffs were right about the statute. The court vacated
the injunction anyway, on a rule it quoted from 1915: where a statute creates a right and
prescribes a remedy, that remedy is exclusive. § 41 supplies it — a penalty of "not less than one
hundred dollars nor more than five hundred dollars." The legislature set that number, not the
venue. The March decision resolved the injunction, not the case; the § 40-b claim survived it.
The statute also does not reach sporting events. It names theatres, music halls, opera houses,
concert halls and circuses. At a basketball game the right in this story does not exist.
3. Inference from exhaust. Tenant screening, credit-based insurance scoring, employment
background checks. Frequently no incident anywhere — a score built from records you never saw,
about something you have not done.
4. The system acts. Not a database that informs a person who decides. Software that observes,
infers, decides, and operates the applications that make the decision real. In August, xAI launched
a persistent agent with its own always-on cloud computer, browser and terminal, signed into your
applications. In September, Anthropic shipped background computer use — the model clicks and types
while you keep working. These are shipped products.
I have not found a public case of one of these deciding about a person at a door. That gap is the
honest state of row four.
Collapse those four and one counterexample takes the argument down. Keep them apart and the
uncomfortable part shows up.
One of these happened to me
I did not go looking for a case. It was not any product named above. It was a vendor identity gate:
a photograph of my driver's license, a biometric scan of my face taken on my phone, an automatic "did not meet the
requirements," and no author on the sentence.
Nothing I was shown named a reviewer, a fact, or a rule. Run it through the three questions at the
end of this piece and watch them all fail. Is the fact wrong? I was never told which fact. Is
the fact right and the rule wrong? I was never shown the rule. If I win, what comes back?
I was not shown a path. That is not the same as no path
existing, and I was never given the difference.
That is not any of the four machines. It is the thing they have in common: a decision returned
with no author on the sentence. I submitted what was asked. I did not finish their process. I hit
the end of it.
Your footprint can do the job of an ID. Its protection depends on the transaction.
A Social Security number is an obvious regulated identifier. Your footprint does some of the same
linking work — the apartment, the job, the ride, the door — but what protects it is not fixed. It
depends on who is using it, for what, and under which regime.
Which protection attaches depends on the information, who is using it, for what, and under which
regime. The photograph does not change. The transaction does.
Hold that 2014 photograph constant.
- A screening firm compiles it and sells it to your employer. In 2011 the FTC concluded a company doing exactly that was a consumer reporting agency, because it "assembles or evaluates" information furnished to third parties who use it for employment eligibility. Public posts, full FCRA obligations: accuracy, notice, dispute.
- Your employer searches your name and finds it himself. The consumer-report route may not apply. That does not mean no law applies. EEOC and FTC guidance is explicit that background information is subject to federal anti-discrimination law "regardless of how you got the information." Remove the reporting company and the regime changes. It does not disappear.
- A venue network attaches it to a flag. A different regime again, largely private.
- An agent retains it, infers from it, and acts. Automation does not delete the organization that deployed it or the transaction underneath. Which duties attach depends on the workflow, and you cannot read that off the architecture.
Four handlings of one photograph, four sets of rules — not because the photograph changed, and not
because any of them is a lawless zone, but because which regime applies is a function of the
transaction, and the transaction is invisible to you.
You cannot know that when you post. You especially cannot know it in advance, because some of those
hallways were built after you posted.
Correcting a fact and contesting an inference are different rights
If a file has your birthday wrong, there is a procedure. If a system has your birthday, employer,
travel and associates all correct, and concludes from them that you are high risk, correcting the
records accomplishes nothing. Every input was already right. The conclusion was the problem.
California's Attorney General addressed this directly in Opinion 20-303. It is an opinion, not a
court holding, and that distinction matters. The reasoning does not:
"when a business processes personal information to make an inference about the consumer's
propensities, then the inference itself becomes part of the consumer's profile, and must be
disclosed. A business might draw an inference about a consumer based in whole or in part on
publicly available information... Under the CCPA, the inference must be disclosed to the
consumer, even if the public information itself need not be disclosed."
The conclusion drawn about you can carry more disclosure obligation than the public facts behind
it. The inference is a separate object. A proprietary algorithm does not automatically make its
individualized output a trade secret.
Three limits. One state. An AG opinion. And California separately provides a right to request
correction of inaccurate information (Civ. Code § 1798.106) — a third thing again. Access to an
inference, correction of a wrong fact, and forcing a decision reversed are three different rights,
and having the first does not get you the third.
One date keeps this honest: California's automated-decision-making rules took effect January 1
2026, and businesses using ADMT for significant decisions have until January 1 2027 to comply.
This is a gap scheduled to partially close.
"Human in the loop" is not a claim. A human can approve every action, approve only payments,
approve one objective at the start, review afterward, or merely be able to intervene. All five ship
under "human oversight." The question is where exactly authority sits.
The numbers, and where they are going
This is not a forecast. These are dated facts about a system already running.
California built a delete button and half a million people pressed it. The Delete Act created
DROP, a single platform where one request reaches every registered data broker. It opened January 1
- By August 13 more than 475,000 Californians had filed (Governor's office, Aug 13). By August 25 the agency reported more than 500,000 registered and 654 data brokers in the system (CalPrivacy, Aug 25).
Registration is a business and the state priced it. A broker's annual registration fee is
$6,000. From August 1 2026 brokers must access DROP at least every 45 days. The penalties
are two separate meters: $200 for each day a broker fails to register, and $200 for each
deletion request for each day it fails to delete.
Then read the outcome numbers carefully, because they are the whole lesson. On August 25 the
agency reported tens of millions of records deleted, that 99.9% of consumers had their
profile deleted by at least one broker, and that the typical user had been removed by over 40
brokers. It also reported that about 25% of brokers had reported processing deletion requests.
Put those next to each other. 99.9% having at least one deletion proves reach, not completion.
Being removed by more than 40 brokers is a real result. But 654 is the system census, not that
person's denominator — DROP reports five separate statuses, including Record not found for brokers
that never held your data or could not match you from what you entered, Exempted for records a broker may lawfully keep, and Pending,
and brokers have up to 90 days to report.
So the honest reading is narrower and still hard: I have not found a published consumer-level
measure of how many people reached a fully resolved state across every broker that actually held
their data, or how long that took. Reach is published. Completion is not.
And I made this mistake myself while drafting this section, which is the point: a number is only
as good as the population it counted, and the trap does not spare the person writing about it.
The first enforcement action is the thesis in one sentence. In August 2026 California brought
its first action under both the CCPA and the Delete Act, against LocateSmarter LLC, for failing to
register and for requiring Californians to provide unnecessary data — the last four digits of
their Social Security number — before they could opt out. Total: $116,490.
(agency decision)
To switch off the sale of a record the law already covered, you had to hand over part of a more
sensitive identifier. California treated that extra demand as unlawful. The protection existed.
The company put a disclosure in the way of using it.
And read what the company was selling. Names, dates of birth, Social Security numbers, phones,
emails, employment, driver's license, bankruptcy records, litigation history — and inferences about
consumer characteristics, including whether a person is "litigious." The agency's own line:
"Inferences are a protected form of personal information under California law."
The arena used who employed you. The broker sold whether you sue. Same family of input. Not the
same machine.
And the next date is already set. California's automated-decision-making rules take full effect
for businesses using ADMT in significant decisions on January 1 2027. Whatever the gap is today,
part of it closes on a schedule, in one state, for covered businesses.
The claims that get to skip the evidence
Everything above had to be sourced. A flag is an allegation until someone adjudicates it. An AG
opinion is not a ruling. A staff letter is not a court order. That standard is not optional if you
want to be believed.
Now apply it to the loudest AI claim in circulation.
On September 3, Senator Sanders and Rep. Casar announced legislation to ban artificial
superintelligence and pause advanced AI development until a cabinet-level regulator exists, with a
corporate death penalty and up to twenty years imprisonment for violations.
Read the announcement for what it defines. It does define the class, broadly: systems that surpass
human intelligence, systems capable of overthrowing governments, systems with dangerous abilities
such as subverting shutdown commands. It also names who would decide: a proposed cabinet-level
regulator with an advisory board. What I did not find in the announcement or the one-page summary
is a benchmark or evaluation protocol for deciding when a system has crossed the prohibited
threshold. Up to twenty years in prison hangs on that threshold. The full bill text is still
described as forthcoming.
Read it for what happens next. The proposal names real instruments: "international agreements,
allied coordination, and policies such as export controls." Those are not nothing. What the public
material does not show is a mechanism that can compel a government or developer outside U.S.
jurisdiction that refuses to cooperate.
And when someone says advanced AI will end the world, ask the next question: by what mechanism,
and for what reason? Not "it will be very smart." A stated pathway you can check.
Notice what each side is required to produce. A person disputing a bar flag files into a documented
process with a published response window. A prohibition on a technology class travels as news with a
summary and no published threshold. I am not claiming anyone measured those two against each other.
I am asking the same question of both: what evidence would turn this into an enforceable
decision?
That asymmetry is the same defect this entire piece is about. How a claim gets treated depends on
who is making it and where it lands, not on what is behind it. A senator can announce a
prohibition on a technology class with a broad definition, no published operational threshold, and no bill text and it is news. You will need
receipts to get a listing corrected.
None of that is an argument for building anything anyone wants. It is an argument that the danger
worth legislating is the one you can describe: what is collected, what gets inferred from it, who
gets to act on the inference, and what you can do about it. That is not a ban on the technology.
It is a ban on a use. The difference is the entire distance between a law that could work and a
press release.
What is actually happening while that argument runs
Nobody has to coordinate any of this.
Safety teams study models. Privacy teams study data. Utilities study load. Cities study zoning.
Congress studies regulation. Each is competent inside its own boundary. The technology crosses all
of them in a single product release.
Preparation is fragmented. Deployment is integrated.
Every participant has an independent reason to accelerate one layer. Each decision can be rational
and the sum still moves faster than anyone chose.
Three questions that are not the same question
- Is the fact wrong? There is usually a process for that.
- Is the fact right and the rule wrong? A system can identify your employer perfectly. The dispute is whether your employer should decide whether you get into a concert. Correcting the record cannot touch that. Whether a route exists to challenge the rule itself is a different question, and it is not the same in every hallway.
- If you win, what comes back, and when? A published response deadline is measurable. Whether the answer arrives before the apartment is rented, the job is filled, or the show ends is a different measurement, and I have not found it published.
Before a record decides something about you, you should be able to ask why it belongs in that
decision. Afterward, you need to know who can change the result.
If you have one of these, I want it
I am collecting real cases before building anything, not after. Mine is above.
If a decision about you turned on a record — a rental, a job, a claim, a door, an account — I want
four things, with every identifying detail removed:
- What information was used, and did you know it was an input?
- Was the problem a wrong fact, an unsupported inference, or the rule itself?
- Who could change the decision, and what happened when you challenged it?
- Did the correction reach everyone who got the error, and did it restore the opportunity?
Don't post anything that identifies you or anyone else. I am after the shape, not the file.
Top comments (0)