Your Data, Packaged and Delivered: How a $500/Month AI Tool Shook Congress Awake

Staffers from 12 offices watched a $500-a-month tool built in two weeks expose home addresses, church visits, and exploitable vulnerabilities

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • CivAI built an AI dossier tool in two weeks for $500/month using open-source Chinese AI.
  • Dossiers expose passwords, location patterns, and “vulnerabilities to exploit,” enabling stalking or blackmail.
  • The Government Surveillance Reform Act would ban warrantless government data-broker purchases to close surveillance gaps.

A congressional staffer watches a nonprofit researcher type a name into a search box. Seconds later, the screen fills: church attendance patterns, leaked passwords, routine commute paths, visits to a gun store — all assembled automatically, all sourced from commercial databases anyone can subscribe to. The monthly cost? Less than a gym membership most people aren’t using.

That’s CivAI’s demo. And it’s been running inside Capitol Hill offices since April 2026. The tactics echo those seen in a surveillance app built by U.S. operatives to target civilians abroad.

What the Tool Actually Builds on You

The dossier isn’t hypothetical — it’s your data, reassembled into a targeting profile.

The AI Data Broker Search tool pulls from commercial data brokers, breach dumps, public records, social media, and location datasets to construct profiles on virtually any American who owns a phone. Each dossier includes:

  • Interests, social media accounts, family networks, and employment history
  • Passwords leaked from previous data breaches
  • Location data flagging visits to abortion clinics, churches, and lawmakers’ offices — the same kind of granular tracking documented in cases of apps secretly tracking users every few minutes
  • Predictable daily routines paired with home and work addresses

Each demo dossier shown to staffers also included a section explicitly focused on “potential vulnerabilities to exploit” — a literal roadmap for harassment, blackmail, or stalking.

CivAI built the system in about two weeks using GLM-5.1, a Chinese open-source model known for lower cost and fewer guardrails than Anthropic or OpenAI products. Those closed-model providers formally prohibit tracking individuals and certain profiling uses through their services — but their policies apply to uses of their platforms. Open-source models run independently, and nobody enforces anyone else’s terms of service. That enforcement gap is the entire point of the demo. Data broker access for the tool runs roughly $500 per month.

“Anyone with access to a frontier AI model can buy your data from a broker and reconstruct an intimate picture of your life,” said Rep. Lori Trahan (D-Mass.).

One Fix Everyone Agrees On – and the Law That Could Do It

Bipartisan alarm is rare on Capitol Hill. Legislative follow-through is rarer still.

Staffers from 12 offices — four Republican, eight Democratic — attended the briefings. One Republican House staffer told Politico that the demo made clear constitutional and statutory privacy protections “have not kept pace with modern technology,” and warned that Congress must act before AI and unchecked commercial surveillance erode protections Americans have long relied on. House Judiciary Chair Jim Jordan raised the gun-owner angle separately: AI assembling a de facto gun registry from commercial data broker records is, in his framing, a Fourth Amendment problem that Americans shouldn’t face simply for exercising their Second Amendment rights.

The Government Surveillance Reform Act — backed by Reps. Warren Davidson and Zoe Lofgren and Senators Ron Wyden and Mike Lee — would require warrants for location, browsing, search, and chatbot records, and ban government purchase of Americans’ data without a warrant, closing the data-broker loophole entirely. Section 702 of FISA lapsed for the first time since 2008 amid a deadlock over warrant requirements and related privacy reforms. Rep. Trahan has argued that even the reform bill doesn’t fully address the AI-enabled capabilities CivAI demonstrated.

“The only effective place to limit [AI-enabled surveillance] would be around the access to the data broker… There’s no plausible regulation on an AI company that would be successful there,” said Neil Chilson, head of AI policy at the Abundance Institute.

CivAI isn’t lobbying for one specific law. The organization says it wants “durable attention” on the surveillance risks created when AI meets commercially available personal data. Whether congressional alarm outlasts the demo room is the question that actually matters now.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →