Skip to content
← Explore all topics

Surveillance & Commercial Data

Adtech, location data, residential proxies, ACR, spyware — surveillance built on legally-bought commercial data.

23 briefings
The Architecture of the Watched World
Chokepoint DoctrineJuly 14, 2026
The Architecture of the Watched World

I saw The Lives of Others in 2011, and it shook me to my core — not the cruelty of the Stasi, but the ordinariness of it: a life catalogued by professionals simply doing their jobs. I have spent the years since watching a version of that filing system being rebuilt, not by a police state but by democracies, for reasons that are mostly good, using tools most people carry willingly in their pockets. This DSI assessment maps the six-layer identity-and-surveillance stack now in deployment across the EU, UK, Australia and beyond — identity wallets, age verification, message scanning, biometric driver monitoring, ambient audio, and behavioural data — each introduced with a genuine justification, and ungoverned in combination. It corrects the viral misreading of what Von der Leyen actually said, sets the 1984 Stasi against the 2026 stack, and closes with five dated, falsifiable forecasts and the risks I would put on any register I was responsible for. The Stasi needed forty years, 91,000 staff and 175,000 informants. The equivalent capability now needs an app, a camera, and a terms-of-service agreement — and there is no wall to tear down.

The Ship and the Iceberg
Chokepoint DoctrineJuly 12, 2026
The Ship and the Iceberg

Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.

No Means No. Except When It Does.
Regulatory ForesightJuly 9, 2026
No Means No. Except When It Does.

On 9 July 2026 the European Parliament revived Chat Control 1.0 — three months after rejecting it. A majority of MEPs still voted against (314 to 276, 17 abstentions), but under the second-reading procedure the EPP engineered, blocking it required an absolute majority of 361. Opponents fell 47 short. The vote count is not the story. The procedure that inverted the burden of proof — timed for the last day before recess — is.

The Sixth Attempt
EU Regulatory LandscapeJuly 8, 2026
The Sixth Attempt

The EU's 'Chat Control' is back for the sixth time - and the way it is coming back matters more than whether it passes. Chat Control 1.0, the interim derogation letting US platforms voluntarily scan unencrypted messages for CSAM, expired on 3 April 2026 after Parliament rejected an extension 311-228 (not, as claimed, by a single vote). The Council is reviving it through a formally 'new' law with identical content: an urgent-procedure vote cleared the way 331-304 on 7 July, with the substantive vote on Thursday 10 July - the last sitting day before recess, when 361 members (an absolute majority) would be needed to stop it. Whose interest does this serve? Several at once: a genuine child-protection case; institutional pressure (four Commissioners lobbied MEPs); the EPP closing a 'legal gap' while dodging the Chat Control 2.0 vote its members are blocking; and - the interest nobody names - legal-cover restoration for Meta, Google, Microsoft and Snap, who have scanned without authorisation since April. My assessment: this is not the EU overriding democracy but circumventing it through procedure while keeping formal cover - harder to name, and harder to stop. And the surveillance architecture (EUDI Wallet, age verification, ADDW cameras) keeps building regardless of Thursday's vote. Every box is governed; the intersection is no one's job.

The Camera That Cannot Be Turned Off
Chokepoint DoctrineJuly 8, 2026
The Camera That Cannot Be Turned Off

Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.

The Credential You Can't Change
Chokepoint DoctrineJuly 7, 2026
The Credential You Can't Change

Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.

Every Box Is Governed. The Space Between Is No One's Job.
Chokepoint DoctrineJuly 4, 2026
Every Box Is Governed. The Space Between Is No One's Job.

Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.

Your Smart TV Is Someone Else's Criminal Infrastructure
Chokepoint DoctrineJuly 3, 2026
Your Smart TV Is Someone Else's Criminal Infrastructure

On 2 July 2026, the FBI and IRS Criminal Investigation seized NetNut, a residential proxy service run by the NASDAQ-listed Israeli company Alarum Technologies, after Google and partners degraded the Popa botnet — roughly two million consumer devices, including the Android TV box and smart television under millions of ordinary homes, enrolled with little or no consent. A residential proxy routes criminal traffic through real home connections, so when a target checks the source it sees your ISP and your city, not a data centre. In one week of June 2026, Google's Threat Intelligence Group counted 316 distinct threat clusters — criminal and nation-state — using NetNut exit nodes; a comparable network, IPIDEA, carried APT28, Sandworm, and Volt Typhoon. My assessment: the FBI's advice to avoid cheap streaming boxes is correct and insufficient, and this is not a botnet you kill but a market you would have to close, resilient because the same infrastructure serves legitimate ad-verification and nation-state espionage alike. The connected device is the permanent weak point: the risk rides an access path you never chose to open. What to do today: segment your smart devices onto a separate network, and ask what the box under your television does when the television is off.

The Root of Trust That Already Leaked
Chokepoint DoctrineJune 28, 2026
The Root of Trust That Already Leaked

In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.

The Crypto-Agility Audit
Practitioner OperationsJune 12, 2026
The Crypto-Agility Audit

NIS2 Article 21 requires “state-of-the-art” cryptography. DORA Article 6 requires emerging-risk monitoring of quantum. CRA Article 11 names crypto-agility as a design property. CNSA 2.0 sets a January 2027 contractor floor. Each framework audits a procedural shell. The substantive obligation lives in the union — and the audit that maps across the four is the one that almost no organisation has yet run. Crypto-agility is a property of architecture, not a control. The state-of-the-art has moved. The audit has not yet caught up. The supervisory practice is on a calendar that will close the gap whether the organisation prepares or not. The practitioner playbook for the PQC migration the regulators are actually asking for, mapped to the regulators actually doing the asking.

The Irreversible Layer
Chokepoint DoctrineJune 9, 2026
The Irreversible Layer

Part III of the Governance Gap trilogy. The class of risks where post-activation governance cannot reverse the consequences. Three thresholds: the Kessler cascade in LEO that becomes self-sustaining once triggered, the HNDL harvest already in progress against the Mosca inequality (15-year confidentiality data generated from 2020 onwards is already in the risk window), and the inference permanence where Yeagley’s behavioural model meets Q-Day content decryption. The 1,400-fold qubit reduction in three months. Google’s 2029 internal deadline. CNSA 2.0 in January 2027. DORA quantum risk monitoring active since January 2025. The governance gap that cannot be closed after the risk activates — because the activation itself changes the conditions under which governance is possible. The time to close it is before the activation. The Chokepoint Doctrine series, complete.

Intelligence Brief — Week of 8 June 2026
Intelligence BriefJune 8, 2026
Intelligence Brief — Week of 8 June 2026

Inaugural DSI Intelligence Brief. Mike Yeagley — the government contractor named in Senator Wyden’s 28 May 2026 letter, the person who in 2016 tracked US special operations forces from Fort Liberty to a covert Lafarge cement factory in Syria using commercially purchased advertising data — has now responded to Wyden in a formal congressional letter. The response advances the argument in three directions: the inference layer (“You no longer carry a name. You carry a pattern. Behaviour is your identity.”), the ambiguity doctrine (privacy as the standing condition of the operator’s life, maintained by architecture, not as a setting), and a decision-forcing body with a 90-day deadline to set technical standards for what applications may collect on a Department of War–managed device. Also: the EU age-verification piece concludes the regulatory series; the connected vehicle piece arrives later in the week.

The Room Has Been Watching
Chokepoint DoctrineJune 5, 2026
The Room Has Been Watching

Smart-TV ACR (Automatic Content Recognition) fingerprints the screen every 500 milliseconds, captures every HDMI input — work laptops, consoles, paired phones — ties the fingerprint to the household IP, and sells. Samsung admitted the architecture out loud in 2015 (in writing, in its privacy policy, transmitting plaintext audio to a third party). The Vizio FTC settlement was 2017. The Texas Attorney General sued five manufacturers in December 2025; Samsung settled on 26 February 2026; Sony, LG, Hisense and TCL are still fighting. The European Union has GDPR and the ePrivacy Directive and has not enforced. This is the fourth node of the DSI commercial-surveillance mosaic after adtech, connected vehicle, and the Handala OSINT convergence. Orwell got the architecture right and the operator wrong: the modern telescreen works for whoever pays.

Call Your Families. Say Goodbye.
Chokepoint DoctrineJune 2, 2026
Call Your Families. Say Goodbye.

On 27 April 2026 the Iranian MOIS cover group Handala (Storm-0842) sent personalised WhatsApp messages to US service members at Naval Support Activity Bahrain naming them by rank, unit, and personal phone number, and the next day published the claimed details of 2,379 named US Marines — home address, family, daily commute, shopping habits, nightly leisure. The data was not stolen. It was bought. This convergence article ties the DSI adtech surveillance piece, the connected vehicle piece, and the Handala profile from the Stryker article into a single argument: three commercial data streams, one mosaic, one targeting package, no breach.

The Surveillance That Nobody Had to Hack
Chokepoint DoctrineJune 2, 2026
The Surveillance That Nobody Had to Hack

USCENTCOM has confirmed it: US forces in active war zones have been targeted using commercial location data bought from adtech brokers. No exploit. No malware. No insider. Just a credit card and a dataset. The Pentagon was first warned in 2016, when contractor Mike Yeagley tracked JSOC personnel from Fort Liberty to a covert facility inside a Lafarge cement factory in Syria using advertising data. A decade later the institutional response has remained a guidance document telling soldiers to review their privacy settings. This DSI piece maps the chain, the reverse pattern of life tradecraft, the carrier layer nobody is regulating, and what adequate protection actually requires.

The Car That Knows Too Much: How the Connected Vehicle Became the Most Invasive Data Collection Device You Own
Chokepoint DoctrineJune 1, 2026
The Car That Knows Too Much: How the Connected Vehicle Became the Most Invasive Data Collection Device You Own

130,000 UK Mercedes records on a cybercrime forum. Toyota's decade-long location-data exposure across 2.15 million customers. VW feeding driver location to law enforcement. The Mercedes breach is the visible surface rupture; the architecture beneath is a surveillance contract you signed when you bought the car.

The Corpus Is the Workforce
Strategic AnalysisMay 20, 2026
The Corpus Is the Workforce

On or around 30 April 2026, a leaked internal Meta all-hands recording articulated, in language attributed to Mark Zuckerberg and not substantively contested by the company, a doctrinal position on AI training data sourcing that the leak's juxtaposition with imminent layoffs made operationally legible. The doctrine has a three-stage operational structure: AI replaces the contractor, the employee trains the AI, the AI replaces the employee. This piece names the doctrine, locates it in the documented record of the past month, identifies the structural verification problem the 'strip-out' assurance produces, examines the strategic-secrecy framing that revealed the firm's true governance posture, traces the compounding economics that make the doctrine irresistible without governance discipline, and proposes the augmentation alternative — opt-in compensated training data contribution, shared productivity gains, verifiable disclosure, explicit board-level doctrinal commitment — that workforce-productive AI architecture actually requires. AI should make organisations productive, not redundant. The claim is a doctrinal position with operational, legal, and competitive consequences. The choice is on every board's desk.

Bit by Bit
Strategic AnalysisApril 22, 2026
Bit by Bit

On April 9, Finance Minister Smotrich described territorial expansion as state policy in two words. Ten days later, Argentina signed over water infrastructure to the expanding state's national utility. The pattern is not hidden. It does not need to be.

Chat Control Is Dead. Long Live Chat Control.
EU Regulatory LandscapeApril 21, 2026
Chat Control Is Dead. Long Live Chat Control.

The EU's mass surveillance proposal has failed four times in four years -- under Belgium, Hungary, Denmark, and the European Parliament. Each failure produced a narrower, more legally sophisticated successor. DSI maps the pattern, names the three catalysts, and predicts when the fifth attempt succeeds.

The Compliance Gap You Could Drive a Forklift Through: Why an $18 Billion Industry Still Can't Tell You If It Passes
Risk IntelligenceApril 20, 2026
The Compliance Gap You Could Drive a Forklift Through: Why an $18 Billion Industry Still Can't Tell You If It Passes

Jaguar Land Rover shut down for five weeks. Nucor halted steel production. Both made the same calculation: when you cannot prove IT/OT segmentation holds, you stop everything. An $18 billion monitoring industry can tell you what's on your network — but not whether it passes IEC 62443. This special report maps the gap between 160,000 newly regulated EU entities and the 33 certifications issued last year.

The EU's Digital Governance Paradox: Age Verification, Chat Control, and the Quiet Architecture of Who Controls the Internet
EU Regulatory LandscapeApril 20, 2026
The EU's Digital Governance Paradox: Age Verification, Chat Control, and the Quiet Architecture of Who Controls the Internet

Within twenty days in March and April 2026, the EU rejected mass surveillance of private messages by a single vote and launched a government age verification app built on the same infrastructure as the EU Digital Identity Wallet. The two decisions are not contradictory in intent. They are contradictory in architecture. This is Part 1 of the DSI EU Regulatory Landscape series.

The Invisible Theatre: Fifth Generation Warfare and the War You Don't Know You're Fighting
Intelligence AssessmentMarch 28, 2026
The Invisible Theatre: Fifth Generation Warfare and the War You Don't Know You're Fighting

Imagine waking up tomorrow morning and everything looks normal. Your phone alarm goes off. You scroll through your news feed over coffee. By nine o'clock you have consumed forty-seven pieces of content, been captured by fourteen cameras, and generated enough behavioural data to fill a filing cabinet — and not one moment of your morning felt like a battlefield. That is the point. That is the design.

The Digital Crossroads: When Your Identity Becomes Your Prison
Digital IdentityMarch 1, 2026
The Digital Crossroads: When Your Identity Becomes Your Prison

Digital Identity: The Battle for Your Digital Soul — Part 1. Imagine waking up to find your smartphone has become your ankle bracelet. After two decades in Scandinavia, I've seen how quickly digital infrastructure becomes invisible once it's normalised.