TL;DR: Large language models have eliminated the last bottleneck protecting your privacy: the inability of governments to actually read the data they collect. The FBI buys your location history. The NSA collects your communications under Section 702. DHS sits on billions of data points from data brokers and social media subpoenas. Until now, the sheer volume of this data made true mass surveillance impractical: there weren’t enough analysts. LLMs fix that. MIT Technology Review, NBC News, and The Conversation all ran investigations in April 2026 documenting how language models could process unstructured data (texts, emails, social media posts, browsing history) and build detailed profiles of millions of Americans simultaneously. Anthropic’s CEO called AI-enabled mass surveillance “a crime against humanity.” The Pentagon declared his company a national security risk for refusing to remove its guardrails.
The Bottleneck That Used to Protect You Is Gone
For decades, privacy had an unlikely ally: incompetence.
Government agencies collected staggering amounts of data on Americans. The NSA hoovers up communications under Section 702. The FBI buys location data from commercial brokers. ICE paid $2.3 million for Webloc, a system that tracks 500 million phones through advertising data. DHS sits on subpoenaed social media records from Google, Meta, Reddit, and Discord [1].
But collecting data and understanding data are different problems. A human analyst can review maybe a few dozen files per day. The FBI conducted 3.4 million warrantless searches of Section 702 data in 2021 alone [2], each one generating results that somebody had to read, cross-reference, and interpret. There was always more data than humans could process.
That bottleneck was your privacy’s last line of defense. And large language models just obliterated it.
What LLMs Actually Do That Old AI Couldn’t
You’ve heard “AI surveillance” before. Facial recognition. Predictive policing. License plate readers. Those systems are dangerous, but they’re narrow. A facial recognition system can match a face to a database. A license plate reader can log where your car was. They can’t read your emails and figure out what you’re planning.
LLMs can.
Here’s the difference. Traditional AI surveillance works on structured data: photos, license plates, GPS coordinates, database entries. Clean, organized, machine-readable. Large language models work on unstructured data. Text messages. Emails. Reddit posts. Medical records. Financial disclosures. Journal entries. Legal filings. Anything written in human language.
Before LLMs, the government could collect your texts but couldn’t efficiently read all of them. It could buy your browsing history but couldn’t extract meaning from the millions of pages you’ve visited. It could subpoena your social media but couldn’t cross-reference your posts with your location data, your financial records, and your medical appointments to build a behavioral profile.
An LLM agent can do all of that. In seconds. For millions of people at once.
How It Works: From Raw Data to Automated Profiles
MIT Technology Review published an investigation on April 21 laying out the threat in detail [3]. The mechanism works like this:
- Data acquisition: The government buys bulk data from commercial brokers (location histories, browsing records, app usage, ad tracking data) or collects it under Section 702. No warrant required for purchased data.
- LLM ingestion: A language model is pointed at the data. Unlike a human analyst who can read a few files per day, an LLM can process thousands of documents per minute. It reads emails, texts, social media posts, and browsing histories the same way you read a paragraph.
- Pattern extraction: The LLM identifies connections a human would miss or would take weeks to find. This person visited a mosque on Fridays and a gun store on Saturdays. This person’s location data shows they attended three protests. This person’s browsing history suggests they’re researching immigration lawyers.
- Profile generation: The model builds a detailed behavioral profile: political leanings, religious affiliation, health conditions, financial status, social network, travel patterns. Automatically. At scale.
- Continuous monitoring: LLM agents can be set to watch for changes. Did someone start visiting a new address? Change their social media behavior? Search for something unusual? The system flags it without any human ever looking at the raw data.
Privacy attorney Anne Toomey McKenna at Penn State described what this data enables: inferences about “whether we own guns, what religion we practice, who we associate with, our political leanings, medical information, place of residence and employment” [1].
Now imagine that analysis happening automatically, for every American, every day.
Why “Friction” Mattered, and Why LLMs Kill It
Privacy researchers use the word “friction” to describe the effort required to surveil someone. Before smartphones, tracking a person meant physically following them or getting a court order for a wiretap. That friction limited surveillance to high-priority targets.
Smartphones reduced friction dramatically. Your phone broadcasts your location constantly. But analyzing that data still required human effort: agents had to sift through records, connect dots, and write reports. As MIT Technology Review put it: when mobile phones became widespread, gathering data about people got much cheaper, but making use of that data remained difficult [3].
LLMs remove the remaining friction entirely. The cost of analyzing one person’s data drops to nearly zero. And when it costs nothing to analyze one person, there’s no reason not to analyze everyone.
That’s the shift. Not from “no surveillance” to “surveillance,” but from targeted surveillance to mass surveillance. From “the government watches suspects” to “the government watches everyone and lets AI decide who’s suspicious.”
Rep. Thomas Massie (R-KY) put it plainly: “There’s virtually nothing the government can’t know about you” [4].
Who’s Building This, and Who Refused
In March 2026, Senator Ron Wyden sent letters to four major AI companies (Anthropic, Google, OpenAI, and xAI) asking whether they prohibit government customers from using their models to analyze commercially purchased data on Americans [4].
Only two companies responded. OpenAI and Elon Musk’s xAI said nothing.
Anthropic said it permits “a small number of national-security customers” to use Claude for foreign intelligence analysis, even when that data “includes incidentally collected U.S.-person information.” But the company drew a line: no “analysis of the product of bulk domestic collection” and no “unauthorized surveillance or tracking of individuals” [4].
Google responded but did not publicly detail its restrictions.
Anthropic’s red lines cost it dearly. In January 2026, CEO Dario Amodei published an essay arguing that AI-enabled mass surveillance constitutes “a crime against humanity” [5]. When the Pentagon demanded Anthropic remove its contractual bans on mass domestic surveillance and fully autonomous weapons, Amodei refused [6].
On February 27, Defense Secretary Pete Hegseth designated Anthropic a “supply chain risk,” a designation typically reserved for companies like Huawei and Kaspersky that pose actual national security threats [7]. The message to every AI company was unmistakable: remove your guardrails, or we’ll destroy your business.
A federal judge later found evidence of “classic illegal First Amendment retaliation” in the Pentagon’s actions [8]. But the damage was done. The chilling effect on other AI companies is real. Most won’t even answer a senator’s letter.
This Isn’t Theoretical. It’s Already Happening.
The CIA announced plans in April 2026 to deploy “AI coworkers” alongside human intelligence analysts, with the goal of eventually letting analysts run teams of AI agents [9]. The agency managed “a few hundred” AI projects last year and recently used AI to generate an intelligence report for the first time.
The NSA uses AI systems for signals intelligence processing. DHS is funding AI platforms that “acquire all 911 call center data to build geospatial heat maps” and software that detects “sentiment and emotion in users’ online posts” [1]. ICE converts agents’ phones into biometric scanners [1].
FBI Director Kash Patel confirmed on March 18, 2026, that the FBI buys Americans’ location data from commercial brokers, including location histories [1]. When Senator Wyden asked if the bureau would stop, Patel said the agency “uses all tools” available [10].
The CIA even credited Section 702 surveillance data (likely processed by AI) with preventing a terror attack at a Taylor Swift concert in Austria [4]. Whether that claim is verifiable or not, it reveals how the intelligence community frames AI-processed surveillance: as indispensable and unquestionable.
Brendan Steinhauser of the Alliance for Secure AI summed it up: “The technology allows basically a panopticon” [4].
The Law Has a Language-Model-Shaped Hole in It
The legal framework governing surveillance was written for a world where humans read wiretap transcripts and analysts reviewed case files. It doesn’t account for AI that can process an entire population’s communications simultaneously.
The Fourth Amendment prohibits unreasonable searches. But the third-party doctrine (a legal theory from 1979) holds that data you share with a company loses its constitutional protection. Your location data, your browsing history, your app usage: all “voluntarily shared” under terms of service nobody reads [1].
FISA Section 702 authorizes warrantless collection of foreign targets’ communications, but “incidental collection” sweeps up millions of Americans’ data in the process [2]. The FBI then searches that data for Americans’ information without a warrant, the so-called “backdoor search” loophole.
Jason Pye of the Due Process Institute explained the problem: “The FBI can then search for a person, for an American, without a warrant” [4].
Now add LLMs to this equation. An agent that can read every incidentally collected communication, cross-reference it with purchased data broker records, and generate a behavioral profile, all without a human ever looking at the raw data. Does that count as a “search” under the Fourth Amendment? Courts haven’t decided. The government is already doing it.
The FISA 702 deadline hits April 30. Speaker Johnson’s reauthorization bill extends the program for three years without a warrant requirement [11]. The Lee-Durbin warrant amendment has been blocked from reaching the floor. Section 702 is about to be renewed, and the AI systems that feed on its data are about to get three more years of raw material.
What You Can Do
- Minimize your data footprint: Every app permission, every account, every terms-of-service checkbox generates data that feeds this system. Audit your phone. Revoke location access from apps that don’t need it. Use a browser with built-in tracking protection.
- Use end-to-end encryption: LLMs can’t read what they can’t access. Signal for messaging. ProtonMail for email. Encrypted cloud storage. If the data is encrypted before it leaves your device, even a language model can’t parse it.
- Block the ad pipeline: Ad trackers are a primary data source for broker-to-government surveillance. Use an ad blocker (uBlock Origin), a DNS-level blocker (NextDNS, Pi-hole), and consider a privacy-focused phone OS like GrapheneOS.
- Demand reform: The Surveillance Accountability Act (H.R. 8470) and the Government Surveillance Reform Act both require warrants for data broker purchases. The FISA 702 vote happens this week. Contact your representative. Call, don’t email: congressional offices count calls.
- Support the companies that push back: When AI companies refuse government pressure to remove surveillance guardrails, they pay a price. The market incentive right now is to comply quietly. That only changes if consumers make privacy a purchasing decision.
The Real Threat Isn’t That AI Exists. It’s That the Data Does.
LLMs didn’t create the surveillance state. Data brokers, weak privacy laws, and the third-party doctrine did. Language models are the accelerant, not the spark.
But the acceleration changes everything. Before LLMs, the government had more data than it could use. That was a feature, not a bug. It meant surveillance was expensive and targeted. You had to matter enough for someone to look at your file.
With LLMs, nobody has to look at your file. The machine reads it, flags it, and moves on. The cost of watching one person drops to zero, so the incentive is to watch everyone. The analyst shortage that used to protect your privacy? Solved. By AI that never sleeps, never gets bored, and never asks whether it should.
Dario Amodei called it a crime against humanity. The Pentagon called him a national security risk for saying so. That tells you everything about which direction this is headed.
References
- The Conversation: US government ramps up mass surveillance with help of AI tech, data brokers, and your apps and devices (April 23, 2026)
- Spectrum News: House set to vote this week on controversial federal surveillance program (April 27, 2026)
- MIT Technology Review: How LLMs could supercharge mass surveillance in the US (April 21, 2026)
- NBC News: AI is making it very easy for the government to spy on you. Some lawmakers are worried. (April 2026)
- Dario Amodei: The Adolescence of Technology (January 2026)
- CNN: Anthropic rejects latest Pentagon offer: ‘We cannot in good conscience accede to their request’ (February 26, 2026)
- CNBC: Anthropic loses appeals court bid to temporarily block Pentagon blacklisting (April 8, 2026)
- TechPolicy.Press: A Timeline of the Anthropic-Pentagon Dispute (2026)
- Defense One: CIA employees will get AI ‘coworkers’ and eventually run teams of AI agents (April 2026)
- TechCrunch: FBI is buying location data to track US citizens, director confirms (March 18, 2026)
- Nextgov: House readies vote to renew FISA 702 without a warrant amendment (April 2026)
Published: April 28, 2026