AI and the Commercial Data Loophole
In May 2026, the Pentagon announced that it had reached deals with eight AI companies—SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services, and Oracle—to “deploy their advanced AI capabilities on the Department’s classified networks for lawful operational use.” These deals came amid a public dispute between another top AI company, Anthropic, and the Department of Defense. Anthropic’s Claude large language model (LLM) had been integrated into the military’s classified systems as part of a pilot program. That contract had incorporated usage restrictions that prohibited the use of Claude for mass domestic surveillance and fully autonomous weapons systems. The Pentagon wanted to eliminate these restrictions and allow the deployment of Claude for “any lawful use.” When Anthropic refused, the Pentagon moved to blacklist the company from defense contracting; Anthropic has sued.
According to the Pentagon’s Chief Technology Officer, no further restriction was needed, because mass surveillance of Americans is already barred by law and Pentagon policies. Except for Anthropic, AI companies have mostly gone along with this construction, with some (e.g., OpenAI) stating that their deals with the Defense Department ban mass domestic surveillance.
These reassurances obscure the central question: what counts as mass domestic surveillance? They rest on the unstated assumption that communications metadata and other forms of commercially available information—the detailed records of Americans’ movements, communications, and associations that the government (including the military) purchases from commercial data brokers—are outside the envelope of what counts as surveillance. The government also does not count foreign intelligence programs as mass domestic surveillance even though they sweep up Americans’ communications without a warrant. Yet both types of collection result in the acquisition of vast quantities of Americans’ information, posing serious risks to their privacy and civil liberties. Large language models only increase these risks by making it faster and easier to analyze data across large populations and generate inferences about Americans’ beliefs, associations, and behavior.
Before digging into the details, it is worth emphasizing that the danger of misuse is not hypothetical. The Trump administration has made no secret of its intention to use the government’s full powers against Americans who oppose its policies. Thus far, the Department of Homeland Security and the Department of Justice have been the key agencies implementing this objective. At the same time, the administration has moved to bring foreign intelligence authorities to bear on domestic political activity. It has designated foreign groups as terrorist organizations, creating openings to investigate U.S. persons and organizations with any connection to them, however attenuated. The invocation of a foreign nexus could allow the Pentagon’s surveillance capabilities to reach domestic actors.
The military has exploited the mantle of foreign intelligence for domestic political purposes before. During the Vietnam war, the Army’s Continental US (CONUS) Intel program monitored and infiltrated civil rights organizations, anti-war demonstrators, and women’s liberation groups. It ran some 1,500 agents and kept files on at least 100,000 Americans. And President Trump has shown an appetite for inserting the military into domestic matters. In 2025, he deployed more than 8,000 National Guard troops and active-duty Marines to six American cities to police protests. The Pentagon’s new deals to deploy commercial LLMs on its classified networks provide his administration with a new and powerful surveillance capability that could be turned on Americans.
This post will analyze the risks LLMs pose in the context of commercially available information and a forthcoming second piece will address how they manifest in the context of foreign intelligence surveillance.
A Backgrounder on Metadata and Commercially Available Information
Metadata first burst into public debate when Edward Snowden revealed that the National Security Agency had been using its authority under Section 215 of the Patriot Act to collect records of Americans’ phone calls—including the phone numbers on either end of each call, along with the times the call started and ended—in bulk. Until then, most surveillance debates had focused on controlling government access to the content of communications. Snowden’s revelations forced policymakers and the public to grapple with what metadata could reveal at scale. Former NSA and CIA director Michael Hayden went so far as to declare that “we kill people based on metadata,” an apparent allusion to certain drone strikes carried out by the Obama administration. Congress too recognized the threat to Americans’ privacy posed by bulk collection of metadata, first reforming and then shuttering the program.
Around the same time, courts started to grapple with digital data held by third parties (such as banks or phone companies), which was traditionally considered outside the scope of Fourth Amendment protections. In 2018, the Supreme Court issued a landmark decision in Carpenter v. United States, breaking from this doctrine. The Court held that seven days of historical location data from cell phone towers could be so revealing that the government needed a probable cause warrant to compel disclosure by phone companies. Such data, Chief Justice Roberts wrote, constitutes “a detailed chronicle of a person’s physical presence compiled every day, every moment, over several years.” In June 2026, in Chatrie v. United States, the Court extended this rationale to the compelled disclosure of location history for even a short time, reasoning that it could reveal a person’s visit to a psychiatrist, an abortion clinic, or a political rally.
By and large, the government has side-stepped this requirement. Agencies simply buy up information on swaths of Americans’ movements, associations, and behavior on the commercial data marketplace, without any warrant, court order, or subpoena. They take the position that the Carpenter warrant requirement does not apply to commercial purchases (e.g., data harvested by apps), but only to the compelled production of records (e.g., from a phone company). The result is that bulk collection of the type that Section 215 made controversial, including the collection of information (like location data) that would otherwise require a warrant to obtain, is now ubiquitous and accomplished at far greater scale via the private sector.
The Department of Defense has acknowledged that it is a customer in this market for commercial data but has not revealed the scope of its purchases and has only provided the most general justifications for acquiring this information. Documents disclosed by lawmakers and in the press suggest that these purchases are vast in scale. In 2020, Motherboard reported that U.S. Special Operations Command had bought access to location data harvested from a Muslim prayer app that had more than 98 million downloads worldwide along with other consumer apps with millions of users in the United States. In 2021, the New York Times reported that the Defense Intelligence Agency receives “commercially available geolocation metadata aggregated from smartphones,” including location data about devices and users in the United States. Multiple branches of the military have reportedly purchased access to a database of global internet traffic, updated with over 100 billion new records each day, including in some cases individuals’ browsing history and even the contents of their communications. According to the Pentagon, these large-scale warrantless purchases of information do not count as mass domestic surveillance.
Members of Congress have tried to close this gap. The Fourth Amendment Is Not For Sale Act, which would prohibit federal agencies including the Defense Department from purchasing certain types of sensitive data they would otherwise need a warrant to obtain, passed the House in 2024 with bipartisan support, but the Senate failed to take it up. Similar legislation, including the bipartisan Government Surveillance Reform Act, remains pending.
What this means, according to Anthropic’s CEO, is that “under current law, the government can purchase detailed records of Americans’ movements, web browsing, and associations from public sources without obtaining a warrant.” Layering AI on this information would make it possible “to assemble this scattered, individually innocuous data into a comprehensive picture of any person’s life—automatically and at massive scale.”
Increased Risks Raised by LLMs in the Context of Commercially Available Information
Section 215 of the Patriot Act involved the collection of a single type of information: phone metadata. The information the government now purchases spans dozens of channels, including location, browsing history, financial transactions, social media posts, and app usage. Well before the advent of LLMs, intelligence agencies fused these data streams into consolidated analytical environments, using tools like Palantir’s Gotham platform. The combined data could be used to surface a person’s daily routines, networks of association, and recurring movements. It could produce what is called “pattern of life” analysis, creating an even more comprehensive picture than the one the Supreme Court found so concerning in the Carpenter case.
LLMs—even off-the-shelf products—can do more, and faster. Pre-LLM platforms built pattern-of-life analyses by matching datasets. They typically linked one dataset to another to find shared identifiers within them, such as a name or a telephone number. For example, ICE has used a Palantir tool, FALCON-SA, to link records across government and commercial databases, surfacing previously unknown connections among individuals and organizations. LLMs, however, can identify a person from the substance and style of what they wrote or said, even in the absence of specific identifiers attached to the data. Several recent studies bear this out. LLM agents have matched pseudonymous accounts to public LinkedIn profiles. They have also re-identified some participants in a released interview dataset whose identifying details had been redacted.
These models also scale. Earlier tools required analysts to sort information into categories (e.g., name, telephone number) before analysis could begin. As the studies linked above show, however, LLMs can directly absorb unstructured material (e.g., reports, transcripts, posts) and extract facts and infer attributes. The result is that they have the capacity to process more data with fewer people, enabling mass profiling.
Conversely, an intelligence analyst can start with a characteristic and use an LLM to search the dataset for everyone who shares that characteristic. This capability may well be useful for intelligence work, but it can also be used to target people based on their political views. Indeed, studies have shown that LLMs can accurately infer political ideology and demographic attributes from text that does not explicitly disclose those attributes. An analyst can ask the system open-ended questions: Who in this dataset holds “unAmerican” views? Who is likely to take part in an ICE protest? Who is likely to organize an anti-abortion rally?
As developers themselves have recognized, the model’s outputs can also be wrong, triggering serious consequences for individuals. OpenAI’s report on a 2023 model warns that it “can be confidently wrong in its predictions” and cautions that great care is warranted in high-stakes contexts. This is not an isolated flaw. One study of five LLMs found that they “overestimate the probability that their answer is correct between 20% and 60%.” Despite these inherent limitations, analysts may succumb to automation bias, treating a system’s output as presumptively correct. Institutional incentives only compound this tendency. Depending on the context, an analyst may reasonably fear blame for failing to act on a missed flag more than for acting on a false one. The consequences could be serious: a denial of immigration benefits on security grounds, a spot on a watchlist that is near impossible to challenge, extra scrutiny at the border, or a visit from a law enforcement officer.
The Current Rules are Inadequate
Existing rules and policies do not meaningfully address these risks. The activities of intelligence agencies are governed primarily by Executive Order 12333 and procedures implementing the order. These authorize the Defense Department to conduct a broad range of defense-related foreign intelligence and counterintelligence activities, including the collection of information about foreign governments, organizations, and persons, including international terrorists and drug traffickers. Some foreign intelligence information may also be used for immigration vetting.
The types of foreign-linked activity that can be treated as a justifying collection for a foreign intelligence purpose may be stretched even further: the Trump administration has moved to investigate domestic civil society groups and their funders for their purported foreign ties. In 2025, it issued National Security Presidential Memorandum 7 with the stated aim of combatting domestic terrorism. The memorandum is so broadly framed as to allow the government to target U.S. civil society entities and individuals who engage in activities or support views that are adversarial to the administration. For example, even though the administration has generally limited implementation of the Foreign Agents Registration Act, NSPM-7 calls for investigations under this law of non-governmental institutions and funders that support a range of supposedly anti-fascist views, including anti-American, anti-capitalist, and anti-Christian. It also has deployed terrorism designations against groups in its crosshairs—such as alleged antifa affiliates in Europe and Palestinian non-profits—creating an opening to use foreign intelligence authorities to investigate U.S. organizations with any connection to the designated entities, however attenuated.
The malleability of the foreign intelligence framework is compounded by the weakness of rules designed to prevent abuse. The 2024 Policy Framework for Commercially Available Information contemplates heightened protections for “sensitive” commercially available information (CAI). But it notably fails to specify even the most obvious categories of sensitive CAI, such as data that allows location tracking. As noted above, the Supreme Court in Carpenter held that the government must obtain a warrant to obtain cell phone data that allows sustained location tracking, a holding that it recently extended to short-term location tracking in Chatrie. Instead, each agency must decide on the sensitivity of datasets, based on whether the data: 1) contain a “substantial” volume of Americans’ personally identifiable information; or 2) contain a greater than “de minimis” volume of Americans’ activities that establish a “pattern of life” over an extended period. By doing so, as my Brennan Center colleagues have explained, the framework lets each agency decide contested issues such as what counts as a “substantial volume” of Americans’ information or whether data reveals a “pattern of life.” Similarly, although the framework identifies several potentially useful controls (e.g., restricting access, requiring written justification and approval, deleting U.S. person information from datasets), agencies get to decide which of these are needed. Many of these, as I will explain in my forthcoming piece on AI and Warrantless Foreign Intelligence Surveillance, may be rendered less effective with the deployment of LLMs. The CAI Framework does not address this possibility.
In 2024, President Biden issued a National Security Memorandum on AI and accompanying framework to regulate the use of AI systems across national security data holdings, including CAI. As I have previously explained, the memorandum and framework were an important step forward but left agencies with too much discretion to decide on whether to apply safeguards and was almost entirely dependent on internal oversight. On June 5, 2026, the Trump administration rescinded the Biden memorandum and framework, replacing it with National Security Presidential Memorandum 11. The new Trump AI memorandum broadly states that the use of AI for national security “must always be consistent with United States civil liberties and protections afforded by the Constitution and laws and regulations safeguarding the privacy of American citizens,” but provides no details on how this mandate is to be executed. A policy framework for national security AI governance and safeguards is slated to be issued in September 2026. As it stands though, the rules are far from adequate to address the risks posed by CAI amplified by LLMs.
Conclusion
Whether the Pentagon’s collection and use of Americans’ data counts as “mass domestic surveillance” turns on how the term is defined. The government places its purchases of commercial information about Americans outside the surveillance envelope because it is not compelling production. But what should concern us is the outcome: the collection and analysis of vast quantities of Americans’ information, regardless of how the information is acquired. By that measure, LLMs increase the civil liberties risks of the Defense Department’s data holdings, and the rules meant to address those risks do not meaningfully mitigate them.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.