Prefer to listen? Here's the narrated myth-vs-reality briefing.
Listen to Privacy and surveillance
Plus unlocks audio streaming. Pro adds downloadable audio, video, certificates, and more.
The Myth
"Every AI tool spies on you" is too broad. Major consumer AI products now offer enterprise-grade privacy modes, on-device processing options (Apple Intelligence, Gemini Nano), and contractual data-isolation tiers. The EU's GDPR, California's CCPA, and 13+ US state privacy laws give consumers meaningful rights to deletion and access.
Sources:Apple Intelligence PrivacyIAPP US State Privacy Tracker
The Reality
Facial recognition in public spaces, behavioral inference from chat logs, and AI-driven surveillance in authoritarian contexts are genuinely concerning. Even in democracies, the combination of always-on smart devices, AI-enhanced data brokers, and weak federal US privacy law creates real risk. "Privacy by default" is still the exception, not the norm. And face matching is now a consumer product with ordinary startup security: in August 2026 researcher Jeremiah Fowler found that ClarityCheck, a service that lets anyone upload a photo and try to identify the person in it, had left about 9 million face images in an unsecured cloud bucket, including children, while telling visitors its image search was private and secure. The deeper problem is not the misconfiguration but who was in the database — people who were never customers, never consented, and had no way to know they were there, which is precisely the case that notice-and-consent privacy law does not reach. A third failure mode sits between the authoritarian case and the careless-startup case, and it is the one democracies actually have to solve: a lawful system, bought openly by an accountable public agency, misused by the people authorized to run it. Reporting in August 2026 identified 46 US police officers accused of using Flock Safety license-plate cameras to track wives, girlfriends and former partners, in departments that mostly did not know it was happening. Nothing was hacked and nothing leaked. The system worked exactly as designed, for the wrong person, which is why access logging and override review matter at least as much as the technology.
The Positive Path
Privacy-preserving AI is a fast-growing research area: federated learning, differential privacy, on-device inference, and homomorphic encryption all let AI work without raw data leaving your device. Tools like Signal's private contact discovery and Apple's Private Cloud Compute prove this is achievable at consumer scale. Learning what to ask of AI tools — and what to share with them — is a meaningful first step.