Multiple security surveillance cameras mounted on a pole against a cloudy sky
Photo via Unsplash

TL;DR: DOGE just passed its 100-day mark, and assessments from TechPolicy.Press, Brookings, and Fast Company paint a picture that’s worse than the headlines suggested. Musk’s own AI tool, Grok, is being used to scan federal employees’ communications for anti-Trump and anti-Musk language at the EPA. A DOGE employee signed an agreement to share Social Security data with a political advocacy group trying to overturn election results. 300 million Americans’ Social Security records were transferred to an unauthorized Cloudflare server, and SSA can’t access its own data on that server. DOGE staff use Signal with auto-deleting messages for official business, violating federal records law. The Fourth Circuit vacated protections on April 10, but a district court immediately reopened discovery. And DOGE’s flagship “fraud detection” program? It flagged 2 cases out of 110,000 (a 0.002% hit rate) while slowing SSA processing by 25%.

Grok Is Scanning Government Emails for Disloyalty

DOGE technologists at the Environmental Protection Agency are using Musk’s Grok AI chatbot to scan employee communications for “anti-Trump or anti-Musk language.” Reuters interviewed 20 people familiar with the effort. One manager told an employee directly: “Be careful what you say, what you type and what you do” [1].

Read that again. A private billionaire’s AI tool is monitoring government workers for political loyalty to that same billionaire.

Kathleen Clark, a government ethics expert at Washington University in St. Louis, called it “an abuse of government power to suppress or deter speech that the president of the United States doesn’t like” [1].

The EPA confirmed it was “examining AI for administrative efficiencies” but denied using it for personnel decisions alongside DOGE. The distinction is academic when the tool’s purpose is to flag employees who criticize the boss.

Grok isn’t the only AI DOGE deployed across federal agencies in its first 100 days:

  • CamoGPT: Used by the Army to scan records for references to Diversity, Equity, Inclusion, and Accessibility programs [2]
  • GSAi: A chatbot pushed to 1,500 General Services Administration employees as a “productivity booster” [2]
  • AutoRIF: Accessed and edited to assist mass federal workforce reductions [2]
  • Department of Education: Student and program data fed into AI software on Microsoft Azure for program elimination analysis [2]

Five technology and government ethics specialists told CNBC that feeding sensitive government data into Grok could violate security and privacy laws. The arrangement also hands Musk access to nonpublic federal contracting data from agencies where his companies (Tesla and SpaceX) do business [3].

300 Million Social Security Records on an Unauthorized Server

On June 10, 2025, DOGE requested a complete copy of the NUMIDENT database, the master file for every Social Security card ever issued, covering 300+ million Americans [4].

Aram Moghaddassi, a DOGE-affiliated hire who was co-chief information officer at SSA, authorized the transfer. His rationale: “I have determined the business need is higher than the security risk” [4].

The data went to an unauthorized Cloudflare server. SSA cannot access its own data on that server. Chuck Borges, SSA’s Chief Data Officer, wasn’t informed or consulted. He filed a whistleblower disclosure through the Government Accountability Project on August 26, 2025, documenting “no verified audit or oversight mechanisms” and no “independent security controls, including independent tracking of who is accessing the data and how they are using it” [4].

Borges resigned three days later.

On January 16, 2026, the Trump administration admitted in a court filing that DOGE shared Social Security data on the unauthorized Cloudflare server [4].

That wasn’t the only unauthorized transfer. On March 3, 2025, DOGE sent an encrypted file with roughly 1,000 names and addresses to DHS. By March 24, the data had allegedly been used to check voter rolls for a political advocacy group. A DOGE employee signed an agreement to share SSA data with an unnamed group seeking to overturn election results [5].

The “One Big Beautiful Database”

Brookings laid out the full scope of what DOGE is assembling [6]. Data is flowing from:

  • Treasury: Social Security numbers, tax returns, addresses, birthdates, bank account information
  • SSA: NUMIDENT master file, earnings histories
  • Office of Personnel Management: Background checks, medical records, biometrics, fingerprints, facial recognition data
  • IRS: Tax returns, taxpayer details, employment data
  • CMS: Health records
  • Veterans Affairs: Military and mental health records
  • Education: Student loan data
  • DHS: Immigration verification data
  • CFPB: Consumer financial data

The interface tying it all together? Palantir’s Foundry platform. Peter Thiel’s company holds a $30 million contract with ICE that provides “almost real-time visibility into migrants’ movements” [7]. At least three DOGE members previously worked at Palantir.

Inside the IRS, DOGE leadership ran a “hackathon” to build a “mega API” allowing privileged users to view all agency data from a single access point [6]. ICE aims to arrest 3,000 people daily using this interconnected data [7].

Democracy Now reported DOGE also accessed voter registration records from states including Pennsylvania and Florida [7].

The Privacy Act of 1974 exists specifically to prevent this. It was written after Watergate to stop the government from building centralized dossiers on citizens. DOGE built one anyway, using data from every major federal agency, and put it on a platform run by a company whose co-founder is a close Trump ally.

Auto-Deleting Signal Messages: Destroying the Evidence in Real Time

DOGE officials conduct government business on Signal with automatic message deletion enabled. American Oversight filed suit on April 23, 2025 (docket 25-1251), naming DOGE, NARA, Elon Musk, Marco Rubio, Amy Gleason, and Steve Davis as defendants [8].

“This administration’s brazen use of Signal and Google Docs represents a calculated strategy to evade transparency laws and illegally destroy the public record,” said Chioma Chukwu, American Oversight’s interim Executive Director [8].

The specifics are damning. Top national security officials used Signal for classified discussions about military strikes in Yemen, with messages set to auto-delete. Michael McDonald and key DOGE team members used Signal with auto-delete for official government business about grant cuts [8].

Kathleen Clark, the government ethics expert, put it simply: “If they’re using Signal and not backing up every message to federal files, then they are acting unlawfully” [8].

DOGE eventually created a policy requiring employees to “capture and transmit” work-related messages from personal devices to work devices. But the policy only says disabling auto-delete would “help with retention and compliance.” It stops short of requiring it [8].

The Courts: One Step Forward, Two Steps Back

On April 10, 2026, the full Fourth Circuit vacated the preliminary injunction that had limited DOGE’s access to SSA data [5].

Judge Toby Heytens wrote the majority opinion, finding that plaintiff organizations (unions and retiree advocates) couldn’t demonstrate irreparable harm. But Judge Robert King partially dissented, writing that the court should have assessed the case “on the basis of the new, corrected record.” King’s reasoning: defendants “provided patently false information to the district court” and prior rulings “were rendered on a materially erroneous record” [5].

The court itself acknowledged the government’s conduct was “alarming,” noting that two DOGE associates accessed sensitive data after the court had issued a temporary restraining order in March [5].

Previously, five federal judges had issued restraining orders or preliminary injunctions against DOGE’s data access. The Supreme Court overturned those 6-3 on June 6, 2025. Justices Kagan, Sotomayor, and Jackson dissented, noting the government showed “no need” and “no interest in complying with existing privacy safeguards” [5].

Justice Ketanji Brown Jackson observed that “DOGE received far broader data access than the SSA customarily affords” [5].

The district court immediately reopened discovery after the Fourth Circuit ruling, allowing plaintiffs to investigate the full scope of DOGE’s data access. At least 12 federal lawsuits are active [6].

The “Fraud Detection” Scorecard: 2 Out of 110,000

DOGE’s stated justification for all of this data access? Rooting out fraud and waste.

The results: DOGE implemented phone-claim checks at SSA. Of 110,000 cases reviewed, 2 were flagged as potentially fraudulent. That’s a hit rate of 0.002%. Meanwhile, the program slowed SSA processing by 25% [2].

Two hundred thousand federal jobs have been cut. Grok monitors workers for political loyalty. 300 million Americans’ records sit on an unauthorized server. Signal chats self-destruct. And the system that justified it all found two suspicious cases out of a hundred thousand.

DOGE has a July 4, 2026 deadline to complete its work. That’s 74 days away.

What You Can Do

  • Check if your data is affected. If you have a Social Security number, your NUMIDENT record is likely on that unauthorized Cloudflare server. You can’t opt out, but you can freeze your credit and set up fraud alerts.
  • Support the lawsuits. Democracy Forward, American Oversight, and the EFF are all actively litigating DOGE’s data access.
  • Contact your representatives. Congress returns this week. The discovery phase will reveal more about the scope of DOGE’s data access. Tell your reps to demand oversight hearings.
  • Federal employees: Know your rights. The Government Accountability Project accepts whistleblower disclosures. Chuck Borges used it. You can too.

References

  1. The New Republic: Elon Musk’s DOGE Is Now Using AI to Spy on Federal Workers (April 2025)
  2. TechPolicy.Press: 100 Days of DOGE: Assessing Its Use of Data and AI to Reshape Government (April 2026)
  3. CNBC: Musk’s DOGE Expanding His Grok AI in U.S. Government, Raising Conflict Concerns (May 2025)
  4. Whistleblowers Blog: Whistleblower Warns of Possible DOGE-Related Social Security Data Leak
  5. Nextgov: Appeals Court Removes Limits on DOGE Access to SSA Data Despite ‘Alarming’ Revelations (April 2026)
  6. Brookings Institution: Privacy Under Siege: DOGE’s “One Big Beautiful Database” (April 2026)
  7. Democracy Now: Palantir: Peter Thiel’s Data-Mining Firm Helps DOGE Build Master Database (June 2025)
  8. American Oversight: Lawsuit Against DOGE for Violating Federal Records Act (April 2025)