Technology & The Future

The U.S. Government Is Watching You More Efficiently Than Ever — And Outsourcing the Hard Part

For decades, the hard limit on government surveillance was human attention. A December 2025 GAO report and ACLU documentation of federal AI profiling tools reveal what happened when that limit disappeared.

Julian CrossMay 2, 20269 min read
The U.S. Government Is Watching You More Efficiently Than Ever — and Outsourcing the Hard Part

There is an old and somewhat reassuring assumption baked into American civil liberties law: that mass surveillance is self-limiting. The government can legally collect a great deal, but processing all of it requires humans. Analysts. Hours. Institutional attention. The sheer cost of turning raw data into actionable profiles meant that most of what was collected just sat there. The bottleneck was not legal. It was logistical.

That assumption no longer holds. A December 2025 GAO report examining digital workplace surveillance practices inside federal agencies[1], combined with ACLU documentation of AI-powered profiling tools now deployed across federal law enforcement and immigration systems[4], sketches the outline of something that privacy law was never designed to address: a surveillance infrastructure that has quietly automated the part that used to require people. The data was always flowing. Now someone — or something — is actually reading it.

The tools themselves are not secret. Federal agencies have publicly procured AI-assisted threat detection platforms, behavioral analytics software, social media monitoring contracts, and automated risk-scoring systems. What the GAO report makes visible, and what the ACLU's documentation sharpens, is how those tools interact — how they have, piece by piece, removed the friction that previously kept mass monitoring from becoming mass processing. The legal authority often predates the capability. The capability now exceeds what the law ever imagined it would need to govern.

The result is a situation that feels abstract until you follow a single thread through it. An immigrant applying for a visa has their social media accounts scanned by an automated system before a human official reviews the application. A federal employee's digital behavior at work is logged, scored, and flagged by an insider-threat detection platform that nobody in HR is explicitly monitoring in real time. A person of interest in a financial fraud investigation has their public data aggregated and cross-referenced by a commercial data broker whose tools the FBI has licensed. None of these individual steps are new. What is new is that all of them can now happen faster than any oversight mechanism was built to track.

The Bottleneck Was a Feature

Before the phrase "big data" became a corporate sales pitch, the practical limits of surveillance were well understood by the people designing legal frameworks around it. The Fourth Amendment's warrant requirement, the Privacy Act of 1974[2], the various restrictions on domestic intelligence gathering that emerged after the Church Committee revelations in the 1970s[3] — these were all written, implicitly, with a model in mind: the government wants to spy on someone specific. It must make a case. A judge or an administrator reviews it. Resources are allocated. The focus is necessarily narrow because attention is finite.

That model has been under stress for two decades, since mass metadata collection became technically feasible and the post-9/11 legal architecture was rebuilt around it. But algorithmic surveillance represents a qualitatively different shift. It is not simply that more data is being collected. It is that the analysis layer — the part that used to require a human being to form a judgment about another human being — has been partially automated. A risk score is not the same as a wiretap, and courts have been slow to treat it as such. But a risk score derived from behavioral patterns, financial history, location data, and social network mapping is, functionally, a judgment. It just happens to be one that no single person made.

“A risk score derived from behavioral patterns, location data, and social network mapping is, functionally, a judgment. It just happens to be one that no single person made.”

The GAO report's focus on federal workplace surveillance captures one dimension of this. Agencies have deployed monitoring tools that track employee keystrokes, flag anomalous file access, monitor email content for policy violations, and generate automated alerts when behavior deviates from a statistical baseline. The stated purpose is insider threat detection and data security — legitimate concerns, particularly in agencies handling classified information. What the report notes is that the governance structures around these tools are inconsistent: policies about how long behavioral data is retained, who can query it, what triggers human review, and what due process looks like for an employee flagged by the system vary widely across agencies and are frequently underdocumented.

Outsourcing as Cover

One of the structural features that makes this surveillance architecture difficult to scrutinize is the role of private contractors. The federal government does not, for the most part, build these systems itself. It buys them. Or more precisely, it licenses them — often from companies whose primary market is commercial, and whose tools were designed for corporate HR departments, insurance actuaries, or financial risk teams before being adapted, lightly, for government use.

This matters for several reasons. Government surveillance is subject to constitutional constraints, Freedom of Information Act requests, congressional oversight, and inspector general review. Private companies are subject to much less. When a federal agency licenses a commercial data aggregation platform and uses it to generate intelligence on individuals, the underlying data collection — the purchase of location pings from app companies, the aggregation of public records, the compilation of social media histories — happened in the private sector. Courts have been inconsistent about whether the government's use of commercially purchased data triggers Fourth Amendment protections, partly because the legal doctrine of the "third-party rule" holds that information shared with a third party carries reduced privacy expectation. That doctrine was formulated in the 1970s, before the concept of sharing your location with seventeen apps simultaneously was imaginable.

The ACLU's documentation of AI-powered federal profiling tools specifically highlights immigration enforcement and border security as zones where this dynamic is most acute. Systems that assign risk scores to visa applicants, flag travel patterns, and automatically escalate cases for human review have been deployed without systematic public disclosure of how the scoring models work, what variables they weight, or how accuracy is measured across different demographic groups. The agencies involved argue that algorithmic outputs are only advisory — that a human makes the final call. This is formally true in most cases. It is also how most consequential algorithmic systems are defended, across contexts ranging from credit scoring to criminal sentencing, and it has not resolved the underlying problem, which is that a human reviewing an automated recommendation under time pressure is not providing the same quality of oversight as a human conducting an independent analysis.

“A human reviewing an automated recommendation under time pressure is not providing the same quality of oversight as a human conducting an independent analysis.”

What "Legal" Now Covers

The phrase that keeps appearing in discussions of algorithmic government surveillance is "legal authority." Agencies conducting social media monitoring, behavioral profiling, and automated risk scoring typically cite existing statutory authority — anti-terrorism statutes, immigration law, financial intelligence regulations — as the basis for these programs. The argument is that the same authority that permitted a human analyst to review someone's travel history or phone records now permits a machine to do it faster and at greater scale. Legally, this framing has largely survived challenge. Functionally, it papers over a significant change.

Legal authority granted with one capability in mind does not automatically apply cleanly when a new capability makes something orders of magnitude more powerful. A law authorizing investigators to search a suspect's mail does not necessarily translate well to a law authorizing them to read everyone's mail and have an algorithm flag the suspicious ones. The process of scale changes the nature of the act. Mass automated profiling of a population — even using legally obtained data sources — is a categorically different exercise than targeted investigation of individuals with articulated suspicion. The former creates a permanent asymmetry: the state has a continuously updated model of your behavior, and you have no knowledge of it, no ability to correct it, and in most cases no avenue to challenge it.

The Workplace Surveillance Layer

Inside the federal government itself, the workplace monitoring documented in the GAO report represents a parallel dynamic. Federal employees are not the primary subjects of civil liberties concern in the way that visa applicants or criminal suspects are, and insider threat programs have genuine security rationales. But the tools deployed to manage insider risk in federal agencies are, in many cases, the same behavioral analytics platforms sold to private employers for productivity monitoring — adapted for a security context but sharing the same basic architecture. They normalize a model of continuous, automated, baseline-deviation monitoring that treats ordinary behavioral variation as a signal requiring explanation.

What the GAO report documents is less a scandal than a governance gap. The tools were purchased and deployed faster than policies governing their use were written and audited. Data retention timelines are inconsistent. The processes by which an automated flag becomes an HR action or a security investigation are not uniformly defined. Employees may not know they are being monitored in the ways they are being monitored, and in some agencies, the monitoring data sits in systems that are technically accessible to a wider range of agency personnel than the original privacy assessments contemplated. None of this is uniquely surprising. It reflects a consistent pattern in how surveillance technology enters institutions: capability leads, governance follows slowly, and the gap between them is where real risk accumulates.

The Accountability Question Nobody Has Answered

What is missing from most of the policy discussion around algorithmic federal surveillance is not a debate about whether it should exist. Some version of it will. It is a serious, workable answer to the accountability question that automated systems uniquely complicate. When a human analyst makes a wrong call — misidentifies a threat, flags an innocent person, acts on faulty inference — there is a chain of human decisions to review. When an algorithm makes that call, the error is diffuse. It lives in the training data, in the variable weighting, in the threshold settings that define what counts as a flag. These are auditable in principle. In practice, the companies that build these systems treat their model architectures as proprietary, and the agencies that buy them often lack the technical capacity to audit them rigorously even when given access.

“The legal authority predates the capability. The capability now exceeds what the law ever imagined it would need to govern.”

There are people working on this: algorithmic auditing researchers, civil liberties lawyers developing new frameworks for automated decision challenges, a handful of legislators pushing for algorithmic transparency requirements in federal procurement. Progress is real but uneven, and it is moving slower than the deployment of the tools it is trying to govern. The basic asymmetry — government can build or buy a new surveillance capability in a procurement cycle, while a legal or regulatory response takes years of litigation and rulemaking — is structural, not incidental. It means the gap between what is technically happening and what accountability frameworks cover will remain wide for the foreseeable future.

The story of algorithmic surveillance is not, in the end, primarily a story about bad actors or dystopian intent. Most of the people deploying these tools believe they are doing something useful — detecting genuine threats, protecting sensitive data, making large systems run more efficiently. What the December 2025 GAO report and the ACLU's documentation together reveal is something more ordinary and harder to fix than malice: a series of incremental procurement decisions and legal interpretations that, assembled, have produced a surveillance infrastructure no one explicitly designed and no single institution is adequately positioned to oversee. The bottleneck was never just a bureaucratic inconvenience. It was, for a long time, the mechanism by which a society with limited appetite for being watched could tolerate a state with broad legal authority to do the watching. Now the bottleneck is gone, and the renegotiation of that arrangement — the slow, contentious process of deciding what accountability looks like when the watcher never blinks — is just beginning.

References

  1. gao.gov (gao.gov)
    Examines federal agency digital workplace surveillance practices, documenting inconsistent governance structures around employee monitoring tools and data retention policies.
  2. Privacy Act of 1974 (justice.gov)
    Establishes the 1974 legal framework governing federal agency collection and use of personal information, providing baseline privacy law that predates modern algorithmic surveillance.
  3. Senate Select Committee to Study Governmental Operations with Respect to Intelligence Activities (senate.gov)
    1970s Senate investigation that produced restrictions on domestic intelligence gathering, representing the legal framework designed around targeted rather than mass surveillance.
  4. All the Ways Palantir is Assisting Trump’s Abusive Removal Campaign (aclu.org)
    Documents Palantir's role in providing AI tools to federal immigration enforcement, demonstrating automated profiling systems deployed without public disclosure of scoring models or demographic accuracy.

About Julian Cross

Julian Cross writes about AI, automation, surveillance, digital identity, labor, human relationships with each other and automation, complex systems and attention — less about what new tools, studies and observations can do in theory than what they're already doing to how we work, spend, relate, and get measured. His work follows leads to the point where it stops being a product and starts being a condition.

More like this

The Redaction Is the Document. How to Read What Governments Leave Out.

The Redaction Is the Document. How to Read What Governments Leave Out.

Silas Crane 10 min
The Algorithm That Hired You Never Had to Explain Itself

The Algorithm That Hired You Never Had to Explain Itself

Julian Cross 10 min
Your Employer Is Training Its Replacement on Your Keystrokes

Your Employer Is Training Its Replacement on Your Keystrokes

Julian Cross 10 min