In May 2026, the Pentagon announced that it had reached deals with eight AI companies—SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services, and Oracle—to “deploy their advanced AI capabilities on the Department’s classified networks for lawful operational use.” These deals came amid a public dispute between another top AI company, Anthropic, and the Department of Defense. Anthropic’s Claude large language model (LLM) had been integrated into the military’s classified systems as part of a pilot program. That contract had incorporated usage restrictions that prohibited the use of Claude for mass domestic surveillance and fully autonomous weapons systems. The Pentagon wanted to eliminate these restrictions and allow the deployment of Claude for “any lawful use.” When Anthropic refused, the Pentagon moved to blacklist the company from defense contracting; Anthropic has sued.
According to the Pentagon’s Chief Technology Officer, no further restriction was needed, because mass surveillance of Americans is already barred by law and Pentagon policies. Except for Anthropic, AI companies have mostly gone along with this construction, with some (e.g., OpenAI) stating that their deals with the Defense Department ban mass domestic surveillance.
These reassurances obscure the central question: what counts as mass domestic surveillance? They rest on the unstated assumption that communications metadata and other forms of commercially available information—the detailed records of Americans’ movements, communications, and associations that the government (including the military) purchases from commercial data brokers—are outside the envelope of what counts as surveillance. The government also does not count foreign intelligence programs as mass domestic surveillance even though they sweep up Americans’ communications without a warrant. Yet both types of collection result in the acquisition of vast quantities of Americans’ information, posing serious risks to their privacy and civil liberties. Large language models only increase these risks by making it faster and easier to analyze data across large populations and generate inferences about Americans’ beliefs, associations, and behavior.
Before digging into the details, it is worth emphasizing that the danger of misuse is not hypothetical. The Trump administration has made no secret of its intention to use the government’s full powers against Americans who oppose its policies. Thus far, the Department of Homeland Security and the Department of Justice have been the key agencies implementing this objective. At the same time, the administration has moved to bring foreign intelligence authorities to bear on domestic political activity. It has designated foreign groups as terrorist organizations, creating openings to investigate U.S. persons and organizations with any connection to them, however attenuated. The invocation of a foreign nexus could allow the Pentagon’s surveillance capabilities to reach domestic actors.
The military has exploited the mantle of foreign intelligence for domestic political purposes before. During the Vietnam war, the Army’s Continental US (CONUS) Intel program monitored and infiltrated civil rights organizations, anti-war demonstrators, and women’s liberation groups. It ran some 1,500 agents and kept files on at least 100,000 Americans. And President Trump has shown an appetite for inserting the military into domestic matters. In 2025, he deployed more than 8,000 National Guard troops and active-duty Marines to six American cities to police protests. The Pentagon’s new deals to deploy commercial LLMs on its classified networks provide his administration with a new and powerful surveillance capability that could be turned on Americans.
This post will analyze the risks LLMs pose in the context of commercially available information and a forthcoming second piece will address how they manifest in the context of foreign intelligence surveillance.
A Backgrounder on Metadata and Commercially Available Information
Metadata first burst into public debate when Edward Snowden revealed that the National Security Agency had been using its authority under Section 215 of the Patriot Act to collect records of Americans’ phone calls—including the phone numbers on either end of each call, along with the times the call started and ended—in bulk. Until then, most surveillance debates had focused on controlling government access to the content of communications. Snowden’s revelations forced policymakers and the public to grapple with what metadata could reveal at scale. Former NSA and CIA director Michael Hayden went so far as to declare that “we kill people based on metadata,” an apparent allusion to certain drone strikes carried out by the Obama administration. Congress too recognized the threat to Americans’ privacy posed by bulk collection of metadata, first reforming and then shuttering the program.
Around the same time, courts started to grapple with digital data held by third parties (such as banks or phone companies), which was traditionally considered outside the scope of Fourth Amendment protections. In 2018, the Supreme Court issued a landmark decision in Carpenter v. United States, breaking from this doctrine. The Court held that seven days of historical location data from cell phone towers could be so revealing that the government needed a probable cause warrant to compel disclosure by phone companies. Such data, Chief Justice Roberts wrote, constitutes “a detailed chronicle of a person’s physical presence compiled every day, every moment, over several years.” In June 2026, in Chatrie v. United States, the Court extended this rationale to the compelled disclosure of location history for even a short time, reasoning that it could reveal a person’s visit to a psychiatrist, an abortion clinic, or a political rally.
By and large, the government has side-stepped this requirement. Agencies simply buy up information on swaths of Americans’ movements, associations, and behavior on the commercial data marketplace, without any warrant, court order, or subpoena. They take the position that the Carpenter warrant requirement does not apply to commercial purchases (e.g., data harvested by apps), but only to the compelled production of records (e.g., from a phone company). The result is that bulk collection of the type that Section 215 made controversial, including the collection of information (like location data) that would otherwise require a warrant to obtain, is now ubiquitous and accomplished at far greater scale via the private sector.
The Department of Defense has acknowledged that it is a customer in this market for commercial data but has not revealed the scope of its purchases and has only provided the most general justifications for acquiring this information. Documents disclosed by lawmakers and in the press suggest that these purchases are vast in scale. In 2020, Motherboard reported that U.S. Special Operations Command had bought access to location data harvested from a Muslim prayer app that had more than 98 million downloads worldwide along with other consumer apps with millions of users in the United States. In 2021, the New York Times reported that the Defense Intelligence Agency receives “commercially available geolocation metadata aggregated from smartphones,” including location data about devices and users in the United States. Multiple branches of the military have reportedly purchased access to a database of global internet traffic, updated with over 100 billion new records each day, including in some cases individuals’ browsing history and even the contents of their communications. According to the Pentagon, these large-scale warrantless purchases of information do not count as mass domestic surveillance.
Members of Congress have tried to close this gap. The Fourth Amendment Is Not For Sale Act, which would prohibit federal agencies including the Defense Department from purchasing certain types of sensitive data they would otherwise need a warrant to obtain, passed the House in 2024 with bipartisan support, but the Senate failed to take it up. Similar legislation, including the bipartisan Government Surveillance Reform Act, remains pending.
What this means, according to Anthropic’s CEO, is that “under current law, the government can purchase detailed records of Americans’ movements, web browsing, and associations from public sources without obtaining a warrant.” Layering AI on this information would make it possible “to assemble this scattered, individually innocuous data into a comprehensive picture of any person’s life—automatically and at massive scale.”
Increased Risks Raised by LLMs in the Context of Commercially Available Information
Section 215 of the Patriot Act involved the collection of a single type of information: phone metadata. The information the government now purchases spans dozens of channels, including location, browsing history, financial transactions, social media posts, and app usage. Well before the advent of LLMs, intelligence agencies fused these data streams into consolidated analytical environments, using tools like Palantir’s Gotham platform. The combined data could be used to surface a person’s daily routines, networks of association, and recurring movements. It could produce what is called “pattern of life” analysis, creating an even more comprehensive picture than the one the Supreme Court found so concerning in the Carpenter case.
LLMs—even off-the-shelf products—can do more, and faster. Pre-LLM platforms built pattern-of-life analyses by matching datasets. They typically linked one dataset to another to find shared identifiers within them, such as a name or a telephone number. For example, ICE has used a Palantir tool, FALCON-SA, to link records across government and commercial databases, surfacing previously unknown connections among individuals and organizations. LLMs, however, can identify a person from the substance and style of what they wrote or said, even in the absence of specific identifiers attached to the data. Several recent studies bear this out. LLM agents have matched pseudonymous accounts to public LinkedIn profiles. They have also re-identified some participants in a released interview dataset whose identifying details had been redacted.
These models also scale. Earlier tools required analysts to sort information into categories (e.g., name, telephone number) before analysis could begin. As the studies linked above show, however, LLMs can directly absorb unstructured material (e.g., reports, transcripts, posts) and extract facts and infer attributes. The result is that they have the capacity to process more data with fewer people, enabling mass profiling.
Conversely, an intelligence analyst can start with a characteristic and use an LLM to search the dataset for everyone who shares that characteristic. This capability may well be useful for intelligence work, but it can also be used to target people based on their political views. Indeed, studies have shown that LLMs can accurately infer political ideology and demographic attributes from text that does not explicitly disclose those attributes. An analyst can ask the system open-ended questions: Who in this dataset holds “unAmerican” views? Who is likely to take part in an ICE protest? Who is likely to organize an anti-abortion rally?
As developers themselves have recognized, the model’s outputs can also be wrong, triggering serious consequences for individuals. OpenAI’s report on a 2023 model warns that it “can be confidently wrong in its predictions” and cautions that great care is warranted in high-stakes contexts. This is not an isolated flaw. One study of five LLMs found that they “overestimate the probability that their answer is correct between 20% and 60%.” Despite these inherent limitations, analysts may succumb to automation bias, treating a system’s output as presumptively correct. Institutional incentives only compound this tendency. Depending on the context, an analyst may reasonably fear blame for failing to act on a missed flag more than for acting on a false one. The consequences could be serious: a denial of immigration benefits on security grounds, a spot on a watchlist that is near impossible to challenge, extra scrutiny at the border, or a visit from a law enforcement officer.
The Current Rules are Inadequate
Existing rules and policies do not meaningfully address these risks. The activities of intelligence agencies are governed primarily by Executive Order 12333 and procedures implementing the order. These authorize the Defense Department to conduct a broad range of defense-related foreign intelligence and counterintelligence activities, including the collection of information about foreign governments, organizations, and persons, including international terrorists and drug traffickers. Some foreign intelligence information may also be used for immigration vetting.
The types of foreign-linked activity that can be treated as a justifying collection for a foreign intelligence purpose may be stretched even further: the Trump administration has moved to investigate domestic civil society groups and their funders for their purported foreign ties. In 2025, it issued National Security Presidential Memorandum 7 with the stated aim of combatting domestic terrorism. The memorandum is so broadly framed as to allow the government to target U.S. civil society entities and individuals who engage in activities or support views that are adversarial to the administration. For example, even though the administration has generally limited implementation of the Foreign Agents Registration Act, NSPM-7 calls for investigations under this law of non-governmental institutions and funders that support a range of supposedly anti-fascist views, including anti-American, anti-capitalist, and anti-Christian. It also has deployed terrorism designations against groups in its crosshairs—such as alleged antifa affiliates in Europe and Palestinian non-profits—creating an opening to use foreign intelligence authorities to investigate U.S. organizations with any connection to the designated entities, however attenuated.
The malleability of the foreign intelligence framework is compounded by the weakness of rules designed to prevent abuse. The 2024 Policy Framework for Commercially Available Information contemplates heightened protections for “sensitive” commercially available information (CAI). But it notably fails to specify even the most obvious categories of sensitive CAI, such as data that allows location tracking. As noted above, the Supreme Court in Carpenter held that the government must obtain a warrant to obtain cell phone data that allows sustained location tracking, a holding that it recently extended to short-term location tracking in Chatrie. Instead, each agency must decide on the sensitivity of datasets, based on whether the data: 1) contain a “substantial” volume of Americans’ personally identifiable information; or 2) contain a greater than “de minimis” volume of Americans’ activities that establish a “pattern of life” over an extended period. By doing so, as my Brennan Center colleagues have explained, the framework lets each agency decide contested issues such as what counts as a “substantial volume” of Americans’ information or whether data reveals a “pattern of life.” Similarly, although the framework identifies several potentially useful controls (e.g., restricting access, requiring written justification and approval, deleting U.S. person information from datasets), agencies get to decide which of these are needed. Many of these, as I will explain in my forthcoming piece on AI and Warrantless Foreign Intelligence Surveillance, may be rendered less effective with the deployment of LLMs. The CAI Framework does not address this possibility.
In 2024, President Biden issued a National Security Memorandum on AI and accompanying framework to regulate the use of AI systems across national security data holdings, including CAI. As I have previously explained, the memorandum and framework were an important step forward but left agencies with too much discretion to decide on whether to apply safeguards and was almost entirely dependent on internal oversight. On June 5, 2026, the Trump administration rescinded the Biden memorandum and framework, replacing it with National Security Presidential Memorandum 11. The new Trump AI memorandum broadly states that the use of AI for national security “must always be consistent with United States civil liberties and protections afforded by the Constitution and laws and regulations safeguarding the privacy of American citizens,” but provides no details on how this mandate is to be executed. A policy framework for national security AI governance and safeguards is slated to be issued in September 2026. As it stands though, the rules are far from adequate to address the risks posed by CAI amplified by LLMs.
Conclusion
Whether the Pentagon’s collection and use of Americans’ data counts as “mass domestic surveillance” turns on how the term is defined. The government places its purchases of commercial information about Americans outside the surveillance envelope because it is not compelling production. But what should concern us is the outcome: the collection and analysis of vast quantities of Americans’ information, regardless of how the information is acquired. By that measure, LLMs increase the civil liberties risks of the Defense Department’s data holdings, and the rules meant to address those risks do not meaningfully mitigate them.
Facts Only
* In May 2026, the Pentagon announced deals with eight AI companies: SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services, and Oracle.
* These deals involve deploying advanced AI capabilities on the Department’s classified networks for lawful operational use.
* Anthropic's Claude LLM was integrated into military classified systems under usage restrictions prohibiting mass domestic surveillance and autonomous weapons systems.
* The Pentagon sought to eliminate these restrictions for Claude deployment, which Anthropic refused.
* The Pentagon moved to blacklist Anthropic from defense contracting, prompting a lawsuit.
* The Pentagon CTO stated no further restrictions were needed because mass surveillance of Americans is already barred by law and policies.
* AI companies like OpenAI have stated their deals with the Defense Department ban mass domestic surveillance.
* Surveillance involves the acquisition of information on Americans’ movements, communications, and associations from commercial data brokers without warrants or court orders.
* The Department of Defense has purchased access to location data harvested from apps and global internet traffic, including browsing history and communications, in vast scales.
* The Fourth Amendment Is Not For Sale Act was passed by the House in 2024 but failed in the Senate.
* The CAI Framework contemplates protections for "sensitive" commercially available information but lacks specific definitions for data like location tracking.
Executive Summary
The Pentagon has reached deals with eight AI companies—SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services, and Oracle—to deploy their advanced AI capabilities on classified networks for lawful operational use. This occurred amidst a dispute with Anthropic, whose Claude LLM was previously integrated into military systems under restrictions against mass domestic surveillance and autonomous weapons. The Pentagon sought to remove these restrictions, but Anthropic refused, leading the Pentagon to consider blacklisting the company. Officials asserted no further restrictions were needed, claiming that deals with companies like OpenAI ban mass domestic surveillance.
The core of the dispute revolves around defining what constitutes mass domestic surveillance. The government assumes that communications metadata and commercially available information—records of Americans’ movements, communications, and associations purchased from commercial data brokers—are outside the scope of surveillance. While the government does not count foreign intelligence programs as mass domestic surveillance despite their collection of American communications, both mechanisms result in vast acquisition of American information, increasing privacy risks. Large language models amplify these risks by making it faster and easier to analyze large populations for inferences about behavior.
The analysis notes that the government currently purchases large-scale data from the commercial marketplace without warrants or subpoenas, a practice that has expanded due to landmark court cases like *Carpenter v. United States*, which addressed location data tracking. While legislation exists to restrict government purchases of sensitive data, existing rules are deemed inadequate to address the risks posed when LLMs are layered over this commercially available information.
Full Take
The dynamic described involves a systemic shift where vast, commercially accessible datasets are being weaponized through LLMs to enable surveillance capabilities that previously required more explicit legal constraints. The central tension lies between the government's justification of warrantless collection based on commercial data purchases and the constitutional protections for privacy established by rulings like *Carpenter*. The narrative moves from metadata collection (Snowden) to location tracking, and now potentially to inferring complex patterns of life via AI analysis.
The pattern of development suggests an erosion of the legal boundary around "mass domestic surveillance," where the definition is being fluidly managed by agency discretion rather than fixed legal precedent. The reliance on commercial data brokers blurs accountability; by treating bulk purchases from the private sector as permissible, the government effectively outsources the collection mechanism while retaining the ultimate authority over the resulting information. LLMs act as an accelerant to this trend, transforming scattered, individually innocuous data points into actionable profiles, which then interact dangerously with existing frameworks like Foreign Intelligence Surveillance Act authorities.
The resistance framework—the CAI Framework and subsequent AI memoranda—demonstrates a systemic failure in establishing concrete guardrails against these new technologies. Agencies are left to self-determine the sensitivity of information, creating an open-ended space where mass profiling can occur under the guise of operational necessity. The implication is that technical advancements outpace regulatory capacity, allowing latent vulnerabilities in existing powers—like those exploited during wartime history—to be repurposed for domestic political objectives through these novel AI tools. What becomes crucial is how accountability is enforced when the mechanism of collection (commercial data) is decoupled from warrant requirements, and the analytical tool (LLM) masks the resultant inferences.
Bridge Questions: If agencies are left to define what constitutes a "pattern of life" in the absence of explicit legal definitions, what mechanisms can be established to subject these definitions to independent judicial review? How can legal frameworks effectively govern the application of foreign intelligence authorities when domestic political objectives are being pursued through ostensibly commercial data acquisition? What is the threshold at which the use of LLMs, even on lawfully acquired data, crosses the line from permissible operational analysis into actionable domestic surveillance?
