Author: IRPA AI Analyst & Senior Advisor, Chris Surdak
In a recent article in Wired Magazine it was revealed that global data brokers were aggregating and then selling personal behavioral data on US government and military personnel, with little regard for the security implications of such data. This data, such as peoples’ whereabouts, comings and goings and daily habits forms the basis of a wide range of targeted advertising and services based upon consumer behavior. However, these same behavior patterns that lead to things like personalized coupons or direction services such as Waze can also be aggregated to reveal whether a person works at a particular military or government installation, and what their role at that installation might be.
Such behavioral analytics has been fundamental to personalization services provided by apps and smartphones for over a decade, and brokerage firms that trade in this data are well established in this lucrative business. But, as is often the case with technology, the unintended consequences of effectively doxing (unmasking of personal information online) personnel in sensitive positions are demonstrating the risks associated with such perpetual surveillance.
While many countries have attempted to implement a range of legislation and regulation intended to protect peoples’ privacy, nearly all such rules contain a consent clause, which allows for nearly unfettered collection and use of personal information, so long as the aggregator has consent from the individual. Such consent clauses often provide blanket consent, whereby continued use of their product or service constitutes ongoing consent for data collection. Further, any use of these products or services is allowed only so long as such consent is granted, removing any real choice on the part of consumers where such services are fundamental to living in this digital age.
Some countries and governing bodies, such as the European Union, have become savvy to these work-arounds, and are pressing forward with stronger enforcement of individual privacy rights. Indeed, in the AI Bill of Rights recently released by The White House’s Office of Science and Technology Policy, US regulators are calling for increased disclosure of when, how and why personal data is being collected, as well as when, if and why people are interacting with an artificial intelligence platform, rather than a human. As adoption of AI gains momentum globally, such notice and disclosure may become critical in informing consumer behaviors and decision making.
Organizations should remain vigilant as such rules are implemented globally. Not only will they be required to obtain consent more incrementally and consistently, they will also have to maintain traceability to such consent, to ensure compliance.
About the Author: Chris Surdak

Chris Surdak is a Senior IRPA AI Advisor and was formerly White House Chief Transformation officer, Automation & AI Practice Lead at EY & Executive Partner for Digital Transformation at Gartner. He’s an engineer, futurist, transformation executive and best-selling author, with over 30 years’ experience in technology development and deployment, digital transformation, blockchain, data and analytics and AI & intelligent automation.
To schedule an introductory call CLICK HERE
Links:
Originally posted on 2025-01-17 in the IRPA AI Network — Enterprise AI