2026-10-01 2:03 PM

The Real Story of Feb. 4, 2004

The Real Story of Feb. 4, 2004

The movie version starts at Harvard. This story started with a federal contract carrying a Falls Church mailing address. The distance between the two is shorter than it looks, though it does not run through any secret tunnel. Wired reported the cancellation of the Pentagon’s LifeLog project on Feb. 4, 2004, the same day Facebook launched. The coincidence is real, and so is the problem with building a theory on it: contemporary reporting indicates LifeLog had already been shut down before Wired published, which makes the date a poor foundation for any handoff. There are genuine links in the wider history. Peter Thiel, Facebook’s first major outside investor, co-founded Palantir, and In-Q-Tel, the independent nonprofit strategic investment firm established by the CIA in 1999, invested in Palantir. This story follows those facts where they go, and they go to an industry that grew up alongside the intelligence world, not to a plot to create a social network.

A government lab had imagined a machine-readable human life. Within a few years a consumer product had persuaded hundreds of millions of people, and eventually billions, to record much of their own lives for reasons that had nothing to do with government. Friendships became explicit connections. Schools and employers became affiliations, photographs became identifiable faces, interests became measurable signals, events became timelines, and smartphones later layered on location and device data. Facebook never needed to be designed for surveillance for its data to become useful to investigators, advertisers, campaigns and anyone else who could lawfully obtain or analyze it. People solved much of the collection problem themselves because they wanted the service. What followed was a long, largely separate effort to connect what they had created.

Kill the Program, Keep the Capability

That effort accelerated after Sept. 11, 2001. The attacks exposed how poorly agencies shared what they knew, and “connect the dots” became a national-security mandate. Relevant information had sat in different parts of government without being combined in time to produce a clear warning, and the demand afterward was for systems that could search across agency walls and surface relationships analysts would otherwise miss.

The most visible response came from DARPA’s Information Awareness Office. Its Total Information Awareness program drew together research on large-scale data analysis, identity technology, language processing and pattern recognition, with the aim of detecting possible terrorist activity within enormous volumes of data. Supporters saw better information integration as the obvious lesson of the failures before the attacks. Critics argued that a system designed to find suspicious patterns would inevitably pull millions of people suspected of nothing under government scrutiny. In 2003, Congress cut off funding for the public TIA program, and many Americans took that as the end of the dragnet.

Congress had defunded a program, not the need behind it. Search, identity resolution, network analysis and pattern recognition were still useful, and intelligence agencies still held far more information than analysts could read. Portions of the research associated with the Information Awareness Office were reportedly transferred to or continued through other government efforts, which has fed years of speculation that TIA survived intact in secret. The evidence supports something narrower and more durable: a controversial program can be shut down and its office dismantled while the technical problem it was built to address remains. LifeLog was gone within months. As government stepped back from the idea of recording people’s lives, the private sector moved the other way. Storage became cheap, broadband spread and daily life migrated onto systems that generated records simply by operating. Investigators increasingly lacked not data but the tools to find the useful pieces in a haystack someone else had built.

The FBI Builds a Search Bar

The FBI was already building one of those tools. By January 2005, according to FBI records later obtained by the Electronic Frontier Foundation, the Bureau’s Investigative Data Warehouse held “more than 47 sources of counterterrorism data,” including FBI files, other agencies’ records and open-source news feeds. FBI officials said agents would be able to search up to 100 million pages of international terrorism-related documents in seconds, and by 2007 the system held some 700 million records from 53 databases and was open to roughly 13,000 users, with analytical tools helping investigators find connections across information that had previously been stored separately. That capability existed roughly two decades before today’s argument over artificial intelligence.

The Casino Man’s Question

Some of the most important thinking about connecting records came from Las Vegas. Jeff Jonas, a software entrepreneur, built his early work around casinos, a business where fraud can drain money fast. A casino’s customer lists, employee files and watch lists were worth only as much as its ability to recognize when two seemingly different identities belonged to one person, or when two apparent strangers were working together. Jonas developed technology to answer those questions, and it became known as NORA, for Non-Obvious Relationship Awareness.

Jonas later recounted that history himself at a Department of Homeland Security advisory committee meeting. He said the technology grew out of his casino work and received additional funding from In-Q-Tel before Sept. 11, and that after the attacks his company became involved in counterterrorism programs. No casino was secretly building a government surveillance system. A tool built to catch cheats and hidden relationships in one industry simply fit a nearly identical problem in national security.

The problem sounds simple until you try to solve it. How does a machine work out who is who, and who knows whom, when the answers are scattered across messy records? A person shows up under a legal name in one system, a nickname in another and initials in a third. Addresses change, phone numbers get reassigned, relatives share a house and clerks misspell names every day. A database that recognizes only exact matches will miss all of it. An entity-resolution system is built to decide whether records describe the same real-world person, and once it has made that call, other software can begin mapping the relationships around that person.

At that stage the old fear of one all-knowing government database starts to look dated. No single system has to hold everything about a person if software can determine that records kept in different places describe the same individual and connect them for an authorized user who can reach those sources. Legal and technical separation still matters a great deal. Separation alone, though, no longer guarantees that fragments stay fragments.

The Database That Would Not Die

Jonas helps explain how machines learned to recognize a person across records. Hank Asher helps explain the commercial database industry that now stands between government and much of what it wants to know. Asher was an entrepreneur whose companies became known for assembling and searching vast amounts of information about Americans. He founded Database Technologies, known as DBT, which eventually became part of ChoicePoint. He later founded Seisint, and Seisint’s technology ran one of the most controversial state-federal information-sharing projects of the post-Sept. 11 years.

The project was called the Multistate Anti-Terrorism Information Exchange, or MATRIX. Participating law enforcement agencies used it to search public and commercial information and to examine relationships among people and records. To its supporters, it gave investigators better tools for finding threats buried in information that already existed. To privacy advocates, it let police reach into huge privately assembled datasets full of people who had never been suspected of anything. MATRIX lost federal support and shut down in 2005. Its engine kept running. In July 2004, LexisNexis had announced it would buy Seisint for $775 million, and The Washington Post reported at the time that Seisint’s Accurint service drew on billions of records and could quickly turn up addresses, employment, assets, voter registration and associates. The difference between the two outcomes is the story in miniature. MATRIX had a name, a budget and a political constituency, so lawmakers could argue about it and eventually starve it. Seisint had paying customers well beyond MATRIX, so the capability outlived the program.

That commercial capability eventually reached deep into immigration enforcement. In 2021, The Intercept reported a $16.8 million LexisNexis contract giving ICE access to billions of records, among them credit history, bankruptcy filings, license-plate images and cellular subscriber information. LexisNexis told the outlet its tool contained data “primarily from public government records” and that “the principal non-public data is authorized by Congress.” The scale of use surfaced the next year. Of the 1.2 million searches logged over seven months of 2021, The Intercept reported, more than 630,000 came from Homeland Security Investigations and more than 260,000 searches and reports from Enforcement and Removal Operations, the part of ICE that locates and deports people, and one user alone ran more than 26,000. An ERO assistant director had described the tool as a resource that “should be widely utilized by ERO personnel as an integral part of our mission to protect the homeland through the identification, location, arrest, and removal of noncitizens.” By 2023, according to the outlet, more than 11,000 ICE officials had access.

Critics and the company described that system in very different terms. “The purpose of this program is mass surveillance at its core,” Julie Mao of Just Futures Law told The Intercept, and Emily Tucker of Georgetown’s Center on Privacy & Technology said it “begins to look a lot like indiscriminate, warrantless real-time surveillance capabilities for ICE with respect to any vehicle.” LexisNexis said it “prides itself on the responsible use of data” and that its DHS work “encompasses only data allowed for such uses.” The numbers describe specific periods rather than current use, and they do not establish that every search targeted someone for deportation. What they do describe is an architecture unlike the single government mainframe Americans once feared. An agency has little reason to build its own national file of addresses, phone numbers, property records and old identifiers when a private company already sells searchable access to them. The government does not have to be the collector. It can simply be the customer.

Richmond’s Budget Line

Virginia went shopping for the same capability. In 2011, state budget language described a planned $1.5 million Virginia Intelligence Management System for the Virginia Fusion Center that would provide a means to “track, link, and analyze persons, places, things, and events,” drawing on user input, commercial databases, government databases and the internet. Virginia State Police later reported putting VIMS into operation in October 2013. None of it came from a leak. It was written into a public state budget more than a decade before generative AI became a household term, and it shows that the goal of linking records across sources was fixed long before the software got fast.

Social Networks Drew the Map

While agencies and data brokers paid to discover relationships, social networks talked people into announcing them. Friendster arrived in 2002, MySpace in 2003 and Facebook in 2004, and a wave of platforms followed that turned social life into structured data. A public-records search might show an investigator that two people once shared an address. Social media could show that they knew each other, went to the same event, worked for the same company, appeared in the same photographs and talked in public, and location features let people post exactly where they were.

One research project showed how quickly those posts could become investigative material. In the early 2010s, a major defense contractor developed Rapid Information Overlay Technology, or RIOT, which pulled public information from Facebook, Twitter, Foursquare and other services and displayed it as relationships, locations and patterns. In a demonstration described in contemporary reporting, the software took one employee’s public activity, identified places he visited often and estimated where he was likely to be at certain times. The contractor said RIOT had not been sold commercially and had been shared with government and industry as research. Social networks were not designed for surveillance. A check-in, a photo or a public post could simply be read a second way, as evidence of location or relationships, without a byte of it changing.

Commercial versions followed. In 2020, The Intercept reported that Dataminr, an AI company with special access to Twitter’s full stream of posts, sent police departments real-time alerts about Black Lives Matter protests after the killing of George Floyd, covering protest locations and schedules in cities including Minneapolis, New York, Los Angeles and Chicago. Dataminr and Twitter disputed that this amounted to surveillance. “Alerts on an intersection being blocked are news alerts, not monitoring protests or surveillance,” a company spokesperson said. Any one alert fits that description. A system that gathers thousands of them and delivers them to police as events unfold is harder to describe so simply.

Palantir, the Engine Room

The company most closely associated with connecting records appears on the list Virginia’s senators sent the DHS inspector general in January. Palantir’s history runs through nearly every thread of this story. In-Q-Tel invested in Palantir, and intelligence analysts worked with Palantir engineers as the software took shape. Documents from the Snowden archive published by The Intercept in 2017 described a tool called XKEYSCORE Helper, bearing Palantir branding, that allowed analysts to bring results from XKEYSCORE, the NSA’s broad internet-surveillance system, into Palantir for analysis and visualization. The documents also showed Palantir being used within the Five Eyes intelligence alliance. One British intelligence analyst called it “the best tool I have ever worked with,” adding, “It’s intuitive, i.e. idiot-proof, and can do a lot you never even dreamt of doing.” The Intercept counted at least $1.2 billion in federal contracts since 2009 and reported that Palantir’s working relationship with the NSA ended in 2015.

ICE became a major customer. Under a $41 million contract awarded in 2014, Palantir built the agency’s Investigative Case Management system, which, according to The Intercept, could draw on records from the DEA, FBI and ATF, from Customs and Border Protection’s Analytical Framework for Intelligence, from the student-visa system and from Palantir’s FALCON platform. The system let ICE users bring together information including schooling, family ties, employment, phone records, immigration history, biometrics, criminal history and addresses, and it was designed for as many as 10,000 users at once. Palantir had said publicly, “We do not work for E.R.O.” Yet documents obtained by The Intercept in 2019 showed ICE used ICM in a 2017 operation aimed at parents and relatives of unaccompanied migrant children; the operation resulted in 443 arrests, 35 of them criminal arrests. On a podcast in 2025, CEO Alex Karp called Palantir “the single worst technology to use to abuse civil liberties.” The company did not respond when The Intercept asked about the gap between that statement and the record.

Local police have used the same kind of tool. Sociologist Sarah Brayne, who spent months embedded with the Los Angeles Police Department, told The Intercept about a Palantir engineer who searched 140 million records to narrow down a hypothetical suspect, relying on assumptions that could easily produce false positives, and about secondary surveillance that captured associates of people who had been stopped. One Los Angeles County official summed up the approach: “Consent is anachronistic.” These accounts are not evidence that Palantir is breaking any law today. They illustrate how government and law enforcement users have employed software designed to connect and analyze large collections of records.

Snowden, ICREACH and the Private Pipes

Edward Snowden’s 2013 disclosures reshaped public understanding of National Security Agency programs, telecommunications collection and the legal routes by which intelligence agencies got information from technology companies. Some early accounts described unrestricted direct access to company servers, a characterization the companies disputed, and those legal and technical details matter too much to collapse into a claim that the government simply had everything. The larger shift was clear anyway. The central communications infrastructure of American life, from email and search to cloud storage, phones and social networks, was privately owned, and government’s main problem was becoming access rather than collection.

The same archive held one of the clearest examples of a connecting system government built for itself. The NSA’s ICREACH grew out of an older system dating to the 1990s; then-Director Keith Alexander proposed it in 2006, and it was running as a pilot by late 2007. When The Intercept revealed it in 2014, the outlet likened it to a secret Google. The reporting said more than 1,000 analysts at 23 U.S. agencies, among them the FBI, DEA, CIA and Defense Intelligence Agency, could use it as of 2010 to search more than 850 billion records of calls, emails, cellphone locations and internet chats, and that it could take in 2 billion to 5 billion new records a day. The NSA itself described it as “the first-ever wholesale sharing of communications metadata within the U.S. Intelligence Community.” Fifteen years before ChatGPT, the goal was already one search box reaching across many stores of data.

The Cambridge Analytica scandal later showed that government is only one of many possible second users of social data. Facebook information involving tens of millions of people was harvested through an app and ended up feeding political profiling, which set off investigations around the world. Cambridge Analytica was not an intelligence program, and it should not be described as one. It belongs in this history because it showed how completely information can change purpose once it exists. A utility records your address to turn on the lights. A DMV takes your photo to issue a license, a retailer logs purchases to sell groceries, an app records location to give directions and a registrar keeps your address to assign your precinct. Each record starts with a legitimate purpose, and digitization makes second and third purposes much easier.

Your Location Is a Product

Every phone riding down West Broad belongs to the next chapter. The smartphone became telephone, camera, wallet, ID badge and location beacon at once, and apps and ad networks grew up around persistent identifiers and location data, creating a commercial market that needed no government involvement at all. The FTC’s case against Gravy Analytics and Venntel shows how large that market grew. Beyond the company’s claim of more than 17 billion signals a day from about a billion devices, the commission alleged that consumers generally had no interaction with the companies and did not know the companies had their information, and it said precise location data could reveal visits to medical facilities, religious organizations, correctional facilities, schools and military installations.

Privacy thinking built around the idea that government does the collecting has a gap here. A police department does not need to put a tracker on a billion phones for a billion phones to produce commercially valuable location data, because apps and ad-tech systems create it for their own reasons and brokers sell access downstream. Government purchases of that data have drawn lawsuits and policy fights, because buying it can give an agency a different route to information than direct surveillance would require. The legal answers depend on the data and the circumstances, but the policy question is now squarely in front of legislators. If continuous, precise location tracking demands serious justification when government does it directly, does that interest disappear once the same information is purchased? Government can outsource collection. We must ask Warner, Kaine, Rep. Don Beyer and Simon: Should it be able to outsource responsibility along with it?

The phone matters for another reason. It binds physical identity, communications, accounts, location and authentication into one object that goes everywhere its owner goes. Warner and Kaine’s letter cited DHS’s reactivated contract with Paragon Solutions and a PenLink contract for services the senators described as monitoring social media and tracking mobile devices, though they cited those contracts in asking for an investigation, not as proof that any capability was used unlawfully against anyone. Commercial spyware also deserves separate treatment from public-records searches, because looking up an address and breaking into private communications are different acts under different legal authorities. Before smartphones, your number, photos, messages, location history and logins lived in different places. The phone gathered them into your pocket, and connecting software can spread them back out.

The Plate, the Pole and the Password

This is where the Flock fight that News-Press readers have followed in these pages fits in. Automated license-plate recognition grew through public and commercial channels long before Flock became a household name, with police using readers to find stolen cars and generate leads while repossession and parking businesses built plate collections of their own. One read tells you little: a particular plate at a particular spot at a particular moment. Repeated reads make a movement history. Registration data points toward an owner or household, and addresses, phone numbers and public records can turn the plate into one identifier inside a much larger analytical picture. An officer who watches a car roll through an intersection has seen something in public. A searchable system that can reconstruct everywhere that car went for weeks or months produces a different kind of knowledge, and the difference comes from scale, retention, searchability and connection rather than from the lens. The cameras are acquiring analytical tools, too. In 2020, The Intercept documented video-analytics software such as BriefCam’s “Video Synopsis,” which condenses hours of footage into minutes, and startups building tools to turn video into “structured searchable data.” Police in Hartford used BriefCam to flag suspected drug houses by analyzing “where people go the most.”

Public worry about surveillance technology tends to focus on hackers. Plate-reader systems have exposed a quieter risk that grows with every improvement: the authorized user who abuses legitimate access. Police officers, government employees and hospital staff have always been able to look up records for personal reasons, and searchable networks let them reconstruct in minutes what once took days of legwork. This summer, a Washington Post investigation found officers who had used Flock’s network to track ex-partners and women they knew, often without their own departments knowing, and Flock announced changes after the Post’s reporting. On Sept. 23, prosecutors in Indianapolis charged five police officers with fraud and official misconduct over thousands of Flock searches that audits found had no law enforcement purpose, and one officer also faces stalking charges. Announcing the charges, Marion County Prosecutor Ryan Mears explained that each count is tied to a single plate, “whether or not an officer is alleged to have searched a license plate 10 times, or 100 times, or even 1,000 times.” Indianapolis Police Chief Tanya Terry defended the system itself: “This technology increases safety in our community. It is the misuse we have to focus on.” She has a point about the tool, and it is the same point Simon made about enforcement. Closer to home, Alexandria Police Chief Tarrick McGuire has said his department deletes plate data after 21 days and that “We do not share any information with ICE as it relates to LPRs.” Indianapolis is a reminder that policies are only as strong as the audits behind them, and that logs showing who searched, when, for which identifier, under what case number and with what result matter as much as the rules.

The Dragnet Georgetown Mapped

Combine plates, phones and commercial databases and you get what researchers at Georgetown Law called an American dragnet. Working from hundreds of public-records requests and years of ICE procurement records, the school’s Center on Privacy & Technology concluded that ICE spent about $2.8 billion from 2008 to 2021 on surveillance, data collection and data-sharing programs, building much of that capability by tapping private companies and state and local bureaucracies. For that period, the researchers estimated that ICE had scanned driver’s license photos of roughly one in three American adults, had access to driver’s license data covering about three in four, could track vehicle movements in cities home to about three in four and could potentially locate about three in four through utility records.

Georgetown has said plainly that those findings describe that earlier period and are not an updated inventory. They still show the structure. Information people handed over to get a driver’s license, a utility hookup or a car registration became useful to immigration investigators without ever being collected for immigration enforcement, and none of it started in a single ICE database. That broad commercial and bureaucratic middle layer, between the individual and the agency, is also where a state law like Virginia’s has the least reach.

Watching Becomes an Industry

Silo, the product bought through the contractor with the Falls Church mailing address, belongs to this part of the story. Managed attribution lets investigators watch the open web without the web seeing who is watching. Warner and Kaine’s reference to a proposal for 30 social-media surveillance contractors shows how online investigation can become an assembly line. One detective scrolling a public Facebook page is one thing. A staffed operation that continuously combs platforms, the open web and commercial databases turns public information into a steady intelligence product. That is not automatically illegal; police have long used public information, and social media can contain real evidence of threats, trafficking and fraud. The constitutional concerns sharpen when the scale of collection or analysis starts sweeping in lawful political speech, family members and people who were never the subject of any investigation. Thirty people searching by hand can only do so much. Software that classifies, translates, summarizes and links what they find has no such ceiling, and the practical issue becomes how much of a person’s public life can be reconstructed without anyone deciding that person was worth the effort.

Your Face Becomes a Search Key

Clearview AI built its business on billions of photographs collected from the public internet, and it has drawn national scrutiny for it. On Sept. 10, WIRED reported that the company has been testing an experimental system called InquiryIQ that can take information generated by a facial-recognition search and use it to conduct broader online research. According to the report, the prototype can examine websites and images and organize information it finds about a person, including possible identities, relationships and employment information. Clearview told WIRED that the tool remains experimental and has not been used by law enforcement customers. Nothing in the reporting shows police using it today. It shows where the technology is heading.

Conventional facial recognition answers a narrow question: does an unknown face resemble one tied to an identity in a reference collection? The answer can help, but it is uncertain, which is why responsible policies require human verification and forbid treating a match as proof of identity. InquiryIQ points toward a workflow in which a possible identity is only the starting point for a much wider search, and the face works less like evidence and more like an index key. That raises the cost of error. If the first identification is wrong, an automated system can build a detailed, convincing profile around the wrong person in minutes. Human review has to mean more than clicking “approve” at the end. Investigators need to know which pieces were observed directly, which were purchased, which were inferred and how confident the system was in each link.

Yesterday’s Data Gets Sharper

Old databases can reveal more without anyone collecting anything new. A police archive from 15 years ago may be full of free-text reports that were nearly impossible to search, and language models can now summarize them. Old photographs become searchable as facial recognition improves. Addresses become more useful as entity-resolution systems reconcile misspellings, and location records say more once graph tools can spot people repeatedly in the same place at the same time. Most people assume privacy risk rises only when more is collected. RAVEn’s four-hour test points to the other half: risk also rises when analysis improves, because the record stays the same while what can be learned from it grows. That is an argument for rethinking how long data is kept, since records held for years become raw material for future systems that will understand them better than anyone reading them today.

Why Northern Virginia Keeps Showing Up

Lay the chronology out on a table and Northern Virginia keeps turning up in it. Capital One pioneered information-driven lending from a Falls Church address. The CIA is headquartered in the region, In-Q-Tel works with U.S. intelligence and national-security agencies, and the Pentagon is across the river. Federal contractors cluster in Fairfax, Arlington, Loudoun, Reston, Herndon, Tysons and Chantilly. The Virginia Fusion Center publicly sought software to link government, commercial and internet information. Gravy Analytics was based in Virginia. Data centers fill long stretches of Loudoun and Prince William. None of that requires a theory of coordination. The region holds a concentration of federal customers, technical talent, contractors, cloud infrastructure and capital that makes it a natural home for companies serving government’s appetite for information. Silicon Valley became shorthand for consumer technology, and Northern Virginia became one of the centers of the federal information economy.

The Falls Church mailing address belongs in this story for that reason, but the contractor itself is not the subject of the investigation. Geographic proximity is not evidence of misconduct. Loudoun County’s list of active business accounts, current as of July 1, 2026, shows the contractor at a Falls Church mailing address, and under the September 2025 ICE award to the contractor, the agency bought approximately $1.47 million in Authentic8 Silo licenses for Homeland Security Investigations’ Office of Intelligence. Those records establish the address and the procurement; they do not establish that the Silo work was performed in Falls Church. The News-Press found no evidence that the contractor surveilled Falls Church residents or engaged in wrongdoing. The significance is the procurement and the capability the government purchased, not the identity of the vendor that supplied it.

The physical side of that economy is visible from Route 7 heading west. Loudoun County and its neighbors host one of the densest concentrations of data-center infrastructure in the world, and on Sept. 18 Gov. Abigail Spanberger announced a Data Center Accountability Framework and signed Executive Order 22, creating a Virginia AI Task Force focused on issues including workforce displacement, data privacy and cybersecurity. Three days later, Beyer, who represents Falls Church and co-chairs the Congressional Artificial Intelligence Caucus, called for suspending the FAA’s SMART air-traffic system at Washington-area airports. He said controllers had not been sufficiently involved in testing it and that the roughly 24 million people who travel through Reagan National each year should not be “guinea pigs.” Those are Beyer’s concerns, not a finding that the system is unsafe. Together, the two actions show Virginia officials starting to ask where human judgment belongs once machines move from storing and finding information to shaping decisions.

What the Lawmakers Have Done

Virginia’s delegation has been busy on several fronts. On July 31, 2025, Warner and Kaine joined Sens. Angus King of Maine and Michael Bennet and John Hickenlooper of Colorado in introducing the Immigration Enforcement Identification Safety Act, which would require federal officers doing immigration enforcement to display their agency, name and a unique identifier, bar masks outside tactical and safety exceptions, and help officers remove their personal information from data-broker websites. “Communities around the country have been clear: we should not have armed, masked, and unidentified individuals prowling around neighborhoods,” Warner said. Kaine said the bill would make ICE officers visibly identify themselves while also helping protect them from doxing and physical harm. The day after the two senators sent their Jan. 29 letter, Warner wrote that “ICE’s new information collection tools potentially enable DHS to circumvent the constitutional protections provided by the Fourth Amendment.” The DHS inspector general subsequently opened an audit examining how DHS components, including ICE, collect, store, use and share sensitive personal data and whether those practices comply with the law.

Warner, the vice chairman of the Senate Intelligence Committee, has also pushed a wide-ranging artificial intelligence agenda. On April 30, he and North Carolina Republican Sen. Ted Budd introduced the Workforce Transparency Act, which would have the Labor Department collect and publish de-identified data on how AI is used across the workforce. On July 21, he released a package that included the Secure AI Development Act, requiring secure government testing of advanced AI models before deployment and creating a voluntary safety-incident reporting system; the AI AGENT Act, setting rules for consumer-facing AI agents that act on people’s behalf; the SAFE AI Act, aimed at AI-generated child sexual abuse material and non-consensual intimate images; the Data Center Tax Accountability and Disclosure Act, requiring large AI data centers to disclose energy and water use and tying tax breaks to efficiency standards; a National Workforce Transition Fund; the PHD Talent Act; and a bipartisan Financial Artificial Intelligence Risk Reduction Act with Louisiana Republican Sen. John Kennedy. “Our greatest national security failures often come when we recognize a threat but fail to act until after a crisis,” Warner told Axios.

On Sept. 24, Warner and Sens. Brian Schatz of Hawaii and Andy Kim of New Jersey introduced the Artificial Intelligence Risk Management and Security Act of 2026. It would create a permanent Artificial Intelligence Safety Board in the Commerce Department, drawing on NIST, Commerce, the Cybersecurity and Infrastructure Security Agency, the NSA and the Treasury along with independent technical experts, to set enforceable safety and security standards for the most advanced models. Developers of those models would have to give the board access at least 45 days before public release, file safety plans, report serious incidents within 30 days, or within 72 hours when national security or critical infrastructure is threatened, and meet safeguards for models capable of finding and exploiting software vulnerabilities without direct human prompting, including standards for autonomous agents’ identity, authentication and access. Violations could bring civil penalties of up to $250,000 per violation, per day. On Sept. 29, the three senators asked for unanimous consent to pass it, and Texas Republican Sen. Ted Cruz objected. “We should not miss the moment to put a safety protocol in place now,” Warner said on the floor. The request came the same day President Trump hosted AI executives at the White House, announced he would rename AI “Super Intelligence” and, after the executives signed a voluntary accord he called “morally binding,” said, “There’s a belief that there should be tremendous self-regulation.” Kaine had told reporters on Sept. 16 that AI regulation was “the subject of pretty intense discussion this week” and said in a statement that “Congress needs to come together to put common-sense guardrails in place to ensure this technology is used responsibly.”

On Sept. 17, Warner and Oregon Sen. Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act, which would set mandatory minimum cybersecurity standards for health care providers, health plans, clearinghouses and their business associates and provide $1.3 billion to hospitals, $800 million of it for rural and underserved urban facilities. Warner said cyberattacks compromise Americans’ most sensitive personal information and can disrupt medical care, and Wyden said Americans expect providers to protect what they entrust to them. Nothing in this story suggests ICE has access to those records. The bill illustrates the same divide the rest of this story keeps running into: cybersecurity asks whether an intruder can break in, while data governance asks what happens after someone is legitimately let in.

In Richmond, Simon has argued that plate readers changed character once “the technology became cheaper, more powerful and increasingly networked through private companies like Flock,” because at that point “it became possible to create something very different.” He was describing the same connecting layer this story has been following. Congress, for its part, has confronted one major piece of the commercial-data problem through the Fourth Amendment Is Not For Sale Act, which passed the House in 2024 before a Senate effort to attach it to FISA reauthorization failed 31-61. The frontier-model bill Cruz blocked addresses a different risk entirely. Neither sets rules for the analytical act itself, once information is lawfully in hand. Legislators have written rules for cameras, biometrics, government records, cybersecurity, retention and access, and they have begun fighting over whether the government may buy what it could not obtain directly without legal process. The next privacy fight is over what happens after access is granted.

The Case for the Machines

Any honest look at this architecture has to explain why it exists, and the people in Northern Virginia’s contracting offices, like the officers who patrol Falls Church, are not its villains. Fairfax County police, who expanded their license-plate reader program with Flock cameras in 2022, say the technology has helped recover more than 549 stolen vehicles worth nearly $10 million, supported more than 1,700 felony charges and helped recover 65 firearms and locate 57 missing people, according to WTOP, though critics with DeFlock Fairfax have called for the cameras’ removal. Facial recognition can produce a lead when police have an unknown suspect on video. Commercial databases can help find fugitives whose addresses changed years ago, and relationship analysis can expose trafficking networks, fraud rings and organized crime. Information sharing became a national priority after Sept. 11 because failing to connect information can be catastrophic. If one agency knows one fact and another knows a second, and nobody realizes the two belong together, fragmentation protects the wrong person.

The commercial uses are often just as legitimate. Banks use data to catch fraud and price risk, hospitals analyze records to spot dangerous patterns, retailers forecast inventory and cybersecurity firms correlate signals because individual events can look harmless until they are connected. A society cannot forbid computers from finding relationships without giving up real benefits, and the same tool can serve opposite ends. A plate-reader query can help find a kidnapped child or help an officer stalk an ex-partner. A social-network map can expose a trafficking ring or chart lawful political activity. Entity resolution can catch a fraudster or wrongly merge two innocent people with similar names and addresses. The camera does not know why someone ran the search, and the software does not know whether the authority behind the query is legitimate. People have to decide who can search, what they can search, for what purpose and under what legal authority; what gets connected and how long the results survive; who audits the searches; whether errors can be challenged; and whether the system can show how it reached its conclusion.

When the Dots Are Wrong

The post-Sept. 11 era was haunted by the danger of failing to connect the dots. Faster analysis adds a second danger: connecting dots that do not belong together. People share names, relatives share addresses and phone numbers get reassigned. Commercial data goes stale, public records contain errors, facial-recognition systems produce false matches, social-media relationships get misread and AI-generated summaries can drop context or add mistakes. Entity resolution weighs probabilities and reconciles imperfect evidence, and it can be wrong. The “confidence scores” in ICE’s ELITE app are exactly that kind of probability, and a probability is not a certainty.

Speed makes verification more important, not less. An analyst spending four hours combining records may trip over inconsistencies along the way, while a system that returns a polished answer in under a minute can project a confidence the evidence never earned. If it decides two people are one, every additional source it touches can make the mistake more convincing. A consequential government system should be able to show its work: where each important piece of information came from, when it was obtained, how it was connected and whether each link was observed or inferred. If an address came from a public record, the analyst should see that. If a phone number came from a commercial broker, the provenance should stay visible, and if facial recognition produced a candidate rather than a confirmed identity, that distinction should survive into the final report. Software should not be allowed to turn uncertainty into clean typography on a screen.

The Master Database Never Had to Exist

For decades, popular culture pictured surveillance as one colossal government computer holding everything about everyone, and the image made the remedy seem simple: control what goes in, control who searches it and delete what should not be there. The architecture that actually developed is spread out. Facebook holds social information, the DMV holds license information, the utility holds your address, the phone company holds account records, the credit bureau holds financial history, a data broker may hold location or public-record data, a private plate network holds vehicle sightings and government agencies hold their own files. No single institution necessarily has the whole picture, and real legal and technical barriers keep many of these systems apart. They are not all connected, and this story does not say they are.

The records in this story show how much more becomes possible when several of them are accessible at once. American privacy law grew up protecting information one category at a time, with separate frameworks for health, education, communications, driver and financial records. Those protections still matter, but individually ordinary facts can become revealing once they are connected. An address alone may say little, and so may a vehicle registration, a social-media account or a single location ping. Put the four together and they can describe a daily life. One master database becomes unnecessary when analytical software can assemble the relevant pieces wherever access is allowed, and fragmentation, the accidental protection Americans relied on for generations, offers a little less of it every year.

Convergence, Not Conspiracy

A timeline this strange invites the search for a hidden hand. Wired reports LifeLog’s end on the same day Facebook launches. An early Facebook investor helps create Palantir. In-Q-Tel invests in relationship-analysis technology. A controversial government data program loses its federal backing while the company whose technology powered it sells for $775 million. Social networks become raw material for national-security research, and data brokers sell to government customers. Arranged carelessly, those facts can be made to imply almost anything. Arranged accurately, in order, they tell a more defensible story that needs no villain.

Government did not have to invent every technology, because private companies had their own reasons to build them. It did not have to assemble every database, because commerce built enormous ones on its own. It did not need one master system, because software kept getting better at making separate systems useful together. Banks wanted profit, tech companies wanted users, advertisers wanted attention, data brokers wanted customers, police wanted leads, intelligence agencies wanted threats found and consumers wanted convenience. Each added a piece without needing to know what the whole would become, and the method they converged on — collect, identify, resolve, connect, analyze, act — can describe a marketing campaign, a fraud investigation, an intelligence operation or an immigration case depending on who is at the controls. It could be built in plain sight because nearly every step had an ordinary explanation.

Regulate the Query, Not Just the Sensor

That raises the question of whether rules aimed at individual sensors and databases are still enough. Retention limits on cameras, cybersecurity standards for hospitals, restrictions on biometrics and rules for government records all remain necessary, and the camera still matters. Flock and other plate-reader networks create observations that would not otherwise exist, and retention, sharing, access controls and density decide whether those observations remain isolated leads or harden into movement histories. Those questions deserve lawmakers’ attention in Richmond and Washington alike. The mistake would be assuming that reining in one camera network, or one set of local agreements, settles what happens when information from many sources is connected.

One answer starts with the query. A camera can be subject to retention rules, and so can the search that reaches into its data, along with any entity-resolution request, with a record of who initiated it, which identifiers were used, which datasets were touched, what purpose justified it and what came back. That kind of auditing need not block legitimate investigations; it makes them accountable. Virginia’s plate-reader law already requires audit trails, and Simon’s point about compliance explains why logs have to be read, not just stored. Government purchasing needs daylight as well. Public debate over commercial data usually begins only after a journalist, an advocacy group or a senator stumbles onto a procurement record, as the Silo contract in this story shows, and basic disclosure could tell the public what categories of commercial information an agency buys, how much it spends, what retention rules apply and who may search the product, without revealing a single active investigation.

Back on West Broad

For Falls Church residents, almost all of this stays out of sight, because modern information infrastructure is designed to disappear into ordinary life. You drive down West Broad, carry your phone, buy groceries, pay the electric bill, see your doctor, register to vote, fly out of Reagan National, post a photograph and come home through a region full of government contractors and humming data centers. Each of those moments creates a record for a legitimate reason, held by a different institution under different rules. Nothing in this reporting shows any organization gathering all of them into a dossier on the people of this city, and no single organization needs to. Connecting software becomes powerful wherever it is allowed to reach, without anyone holding everything.

For years the standard privacy warning was to be careful what you post on Facebook, because you never know who might see it. That warning now covers only part of the problem, because much of the information that can describe a life is generated without anyone publishing anything. The world never needed one LifeLog. It built thousands of partial ones: your bank knows one part, your phone another, your social network another, government agencies another, and your grocery store, your hospital and the camera at the intersection still more, while the technical frontier is teaching machines how the pieces fit together. The old question was who has my information. The question this story leaves on the table is who is allowed to ask multiple systems what they collectively know about me, under what authority, and whether anyone checks the answer.

Twenty-two years after Wired reported LifeLog’s end on the day Facebook began, Hollywood is returning to the social network to ask what happened after one platform grew too powerful, and on Sept. 29 the man who launched it sat among the technology executives at a White House lunch where the president announced he would rename AI and called for “tremendous self-regulation.” Northern Virginia is already living inside the question that comes next. It has less to do with whether any one company knows too much, whether Flock has too many cameras or whether ICE can reach one more database than with whether the systems wrapped around modern life can now decide that a face, a plate, a phone, an address, an account, a location, a photograph and a record all belong to the same human being; how quickly that decision can be made; who is permitted to ask for it; and whether the person at the center of the picture will ever know it was drawn.

Disclosure: The News-Press reported this story. AI tools assisted with editing and fact-checking; the facts were verified against the sources cited.

Share:

More Posts

Harvey’s Sells, But Eateries Moving In

This week marked two major developments on the Falls Church development front. First, Thomas Harvey announced on social media that he’s sold his pioneering restaurant, Harvey’s, on W.  Broad after

Send Us A Message