Andrew Guthrie Ferguson on Surveillance, Data, and the Erosion of Privacy
Law professor Andrew Guthrie Ferguson argues that the smart devices we buy for convenience have turned us into instruments of our own surveillance, that the data they shed can be used against us in court, and that the legal protections most people assume exist have not kept pace with the technology.
Key ideas
-
Every smart device is a surveillance device, and we pay to install it. Phones, watches, cars, dishwashers, doorbell cameras and voice assistants all send data somewhere, and Ferguson’s thesis is that we have built our lives around ‘self-surveillance’ — voluntarily generating a detailed digital record of where we go, what we buy and what we say. His students, told that their navigation data can be used against them in court, still would not give up Google Maps. The convenience is real; the vulnerability is the price, and most buyers never priced it in.
-
The law protecting this data lags decades behind the technology. The pace of legal change is far slower than the pace of technological change. The controlling Fourth Amendment case on privacy still turns on a payphone; criminal-procedure teaching still cites police retrieving bank records on microfiche. Meanwhile AI, cheap cameras and automated licence-plate readers have transformed the scale, scope and aggregation of data available to police, and neither the Supreme Court nor Congress has built equivalent protections.
-
A warrant is ‘weak sauce’, and no data is beyond its reach. A judicial warrant needs only probable cause — a standard Ferguson estimates at well under 51%, so police can be more likely wrong than right and still obtain one — plus a criminal predicate that need not be serious. Given that, there is no data so private police cannot obtain it: smart-bed data, a period-tracking app, even a pacemaker’s readout (used in a real arson-and-insurance-fraud case to disprove the defendant’s account). Ferguson asks whether some categories should be carved out, or protected by a higher standard.
-
The default has reversed: collect everything first, find a target later. Once, police had to expend effort to surveil a suspect; now ubiquitous cameras and licence-plate readers mean the data is already collected on the off chance it is needed, so looking someone up is trivial. Combined with a more politicised climate of prosecution — where protest, or seeking medical care criminalised in one state, can supply the predicate — this expands who is at risk. Ferguson’s point is bipartisan: gun owners, senators, even Donald Trump have seen their own data turned against them, so no one is safely outside the aperture.
-
AI, facial recognition and predictive policing add algorithmic error to the mix. AI is the game-changer because it makes an unusable ocean of surveillance data searchable — the exact concern behind Anthropic’s refusal to let the Defense Department use its models for mass surveillance. ‘Real-time crime centres’ in some 300 US jurisdictions already fuse city, police and Ring-doorbell feeds and run object recognition to track, say, every blue sweater across a city. Facial recognition, like eyewitness testimony, is confidently wrong: at least nine documented false arrests, and a system that hands detectives a ranked list of suspects while the innocent near-matches are never disclosed to the defence.
Content
The data you shed and the network of data brokers
Ferguson opens his GW Law School seminar by asking students how they travelled to class: not by paper map, not by asking strangers, but by the GPS in their pockets and cars. That navigation data, he tells them, is available to police and prosecutors — and none of them will change the habit. This is the trap of ‘self-surveillance’: modern cars, smartwatches, Amazon Echoes and Ring doorbells are, functionally, surveillance devices we have chosen to buy and depend on. Ferguson uses Google Maps himself and could not get his kids to soccer without it; the book, he stresses, is a meditation on those choices, not a condemnation of them.
The commercial machinery beneath this is the data-broker network. A free flashlight app is free because the payment is your data: your identity as a phone — not your name and address, but the persistent identifier of the device — is sold and resold across a web of brokers, tracking movements, purchases and ‘likes’. Ferguson notes that this advertising infrastructure is now being repurposed for government ends: on the day of recording, a headline reported the Department of Homeland Security using the same ad-tracking data for immigration enforcement, because a phone is a tracking device and enough of its data identifies where people go and who they are. Almost everything done in the digital world is tracked for commercial gain, and any of it can be turned into evidence with a quick subpoena or warrant.
The Fourth Amendment and the reasonable expectation of privacy
The Fourth Amendment — part of the US Bill of Rights — bars the government from ‘unreasonable’ searches of persons, papers, homes and effects, and generally requires a judge’s warrant to search protected things. In plain terms, it is the constitutional rule that the state cannot rummage through your private life without cause and, usually, a judge’s sign-off. But ‘search’ is not self-defining, so courts decide what it means. The seminal case, United States v. Katz, involved FBI agents recording a suspect in a payphone booth; from it comes the test of whether a person has a ‘reasonable expectation of privacy’ — a term of art, Ferguson notes, that does not mean what a layperson would guess. Your home is the easy case: police need a warrant to enter because your expectation of privacy there is settled.
Because the Constitution is deliberately general, its meaning in new situations is set by ‘controlling cases’ — precedents that bind lower courts until overruled. When the Supreme Court asked whether police need a warrant to search the smartphone of an arrested suspect, it said yes, reasoning that a phone holds photos, emails, texts, finances and reading choices more private than the contents of a home. But such rulings, Ferguson observes, typically include a paragraph begging Congress to legislate — the Court is only interpreting an 18th-century document — and Congress mostly has not. The case could have gone the other way on the votes of nine justices.
The third-party doctrine
The hard cases arise when your data is not in your home but held by a company. Cameras and microphones inside your house stream to third-party clouds run by Google or Amazon; the police can go not to you but to the provider. Under what is loosely called the third-party doctrine, data you have shared with a company is treated as having lost much of its Fourth Amendment protection — the idea being that once you hand information to someone else, your expectation of privacy in it weakens. Whether that logic should survive in a world where we ‘share’ the intimate contents of our homes with cloud providers simply to make the devices work is, Ferguson says, an open question the law has not resolved.
The practical upshot is that consent is often manufactured by a checkbox. Because you uploaded doorbell footage to a cloud and clicked ‘I agree’ to terms permitting sharing with law enforcement, police may not even need a warrant to obtain it. Some companies have pushed back — Ring shifted from cloud storage toward on-device storage so that officers must approach the homeowner with a warrant; Apple stores a phone’s face-print on the device rather than the cloud. These are privacy-protective choices, but they are voluntary, made against a legal background that supplies no floor.
Facial recognition and algorithmic policing
Ferguson draws a sharp parallel between facial recognition and eyewitness testimony: both feel authoritative and both are error-prone. Eyewitnesses drive many wrongful convictions, especially under stress or across racial lines; facial recognition has produced at least nine known false arrests of demonstrably innocent people. The deeper problem is disclosure and competence. Facial recognition reduces a face to a ‘face print’ — the geometry of eyes, nose, mouth and ears — and matches a probe photo against a database (often DMV records), returning not one candidate but between six and a hundred, ranked by confidence (95%, 93%, 92%). Detectives, who are not data scientists and cannot fairly be expected to know what ‘95% match’ means, receive a printout naming a suspect. In many cases the use of facial recognition need never be disclosed to the defence, and the other high-ranking candidates — some possibly likelier than the person charged — are never turned over.
Predictive policing extends the same faith in algorithms to forecasting crime. Ferguson distinguishes place-based prediction (sending patrols where crime is statistically likely — bar districts at closing time, poorly lit car parks) from person-based prediction (flagging individuals from prior records and police contact). The early experiments in Chicago and Los Angeles largely failed in theory and practice and were shut down. Yet Ferguson expects AI-branded predictive policing to return within a few years — not because it works, but because it sounds techy and sells. He worries that hard-data evidence, in a courtroom, disarms the scepticism jurors would apply to a human witness.
AI, warrants and the road ahead
The episode is framed by the Anthropic–Defense Department dispute: Anthropic refused to let its AI be used for mass surveillance, and CEO Dario Amodei’s argument — that AI is what makes an otherwise unsearchable ocean of data usable — is, Ferguson says, exactly the concern that should apply to local law enforcement too. The ‘real-time crime centre’, already in some 300 US jurisdictions, is his concrete example: a command centre fusing street, body, car, drone, commercial and Ring cameras, with object-recognition AI that can isolate and track every person or object — search the city for every blue sweater, then follow the bank robber’s blue sweater backwards through time. That ‘time-machine’ power has never existed before, is essentially unregulated, and increasingly runs on private platforms (he names Axon) whose shareholder duties may diverge from the public interest.
Ferguson’s proposed remedies work at several levels. Judicially, he thinks the Fourth Amendment can be read more protectively — and points to a geofence-warrant case before the Supreme Court this term, testing whether police may pull the location data of everyone near a crime scene from Google. Legislatively, he models a solution on the wiretap regime that has governed bedroom microphones since the late 1960s: police can still get the data, but only by convincing a judge to a higher standard, showing no other means exists and minimising unrelated material. He deliberately targets what police and prosecutors may use, rather than comprehensive data-privacy law, because that narrower reform is where everyone is equally at risk and a bipartisan compromise is plausible. At the community level he urges education and modest self-restraint — perhaps you do not need the cat cam. The dystopian endpoint is China’s camera-and-social-credit state; the nearer warning is that what you have already given a single company such as Amazon approximates the wiretap-plus-camera-plus-informant network that would look totalitarian if the government imposed it directly. Asked for his bet, Ferguson is guardedly hopeful: the moment is ‘a wee bit more promising’ than a year ago, because the danger is becoming visible to people who once assumed privilege would protect them.
See also
- Sean Carroll — host
- Gary Marcus on AI's Overstated Intelligence, LLM Economics, and the Limits of Scaling — a companion Mindscape-adjacent conversation on the capabilities and limits of the AI now being turned on surveillance data
- Large Language Models — the AI whose searching power, Ferguson and Amodei argue, transforms an unusable mass of surveillance data into a tool for surveilling everyone