{"id":113320,"date":"2026-07-21T13:35:08","date_gmt":"2026-07-21T13:35:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/113320\/"},"modified":"2026-07-21T13:35:08","modified_gmt":"2026-07-21T13:35:08","slug":"ai-and-the-commercial-data-loophole","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/113320\/","title":{"rendered":"AI and the Commercial Data Loophole"},"content":{"rendered":"<p>In May 2026, the Pentagon <a href=\"https:\/\/www.war.gov\/News\/Releases\/Release\/Article\/4475177\/classified-networks-ai-agreements\/\" rel=\"nofollow noopener\" target=\"_blank\">announced<\/a> that it had reached deals with eight AI companies\u2014SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services, and Oracle\u2014to \u201cdeploy their advanced AI capabilities on the Department\u2019s classified networks for lawful operational use.\u201d These deals came amid a public dispute between another top AI company, Anthropic, and the Department of Defense. Anthropic\u2019s Claude large language model (LLM) had been integrated into the military\u2019s classified systems as part of a pilot program. That contract had incorporated usage restrictions that <a href=\"https:\/\/www.nytimes.com\/2026\/02\/23\/us\/politics\/pentagon-anthropic-ai.html\" rel=\"nofollow noopener\" target=\"_blank\">prohibited<\/a> the use of Claude for mass domestic surveillance and fully autonomous weapons systems. The Pentagon wanted to eliminate these restrictions and allow the deployment of Claude for \u201cany lawful use.\u201d When Anthropic refused, the Pentagon moved to blacklist the company from defense contracting; Anthropic has sued.<\/p>\n<p><a href=\"https:\/\/www.cbsnews.com\/news\/pentagon-anthropic-feud-ai-military-says-it-made-compromises\/\" rel=\"nofollow noopener\" target=\"_blank\">According<\/a> to the Pentagon\u2019s Chief Technology Officer, no further restriction was needed, because mass surveillance of Americans is already barred by law and Pentagon policies. Except for Anthropic, AI companies have mostly gone along with this construction, with some (e.g., <a href=\"https:\/\/openai.com\/index\/our-agreement-with-the-department-of-war\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a>) stating that their deals with the Defense Department ban mass domestic surveillance.<\/p>\n<p>These reassurances obscure the central question: what counts as mass domestic surveillance? They rest on the unstated assumption that communications metadata and other forms of commercially available information\u2014the detailed records of Americans\u2019 movements, communications, and associations that the government (including the military) purchases from commercial data brokers\u2014are outside the envelope of what counts as surveillance. The government also does not count foreign intelligence programs as mass domestic surveillance even though they sweep up Americans\u2019 communications without a warrant. Yet both types of collection result in the acquisition of vast quantities of Americans\u2019 information, posing serious risks to their privacy and civil liberties. Large language models only increase these risks by making it faster and easier to analyze data across large populations and generate inferences about Americans\u2019 beliefs, associations, and behavior.<\/p>\n<p>Before digging into the details, it is worth emphasizing that the danger of misuse is not hypothetical. The Trump administration has made no secret of its intention to use the government\u2019s <a href=\"https:\/\/www.brennancenter.org\/our-work\/research-reports\/trumps-orders-targeting-antifascism-aim-criminalize-opposition\" rel=\"nofollow noopener\" target=\"_blank\">full powers<\/a> against Americans who <a href=\"https:\/\/pod.wave.co\/podcast\/the-glenn-beck-program\/glenns-tough-message-to-the-ice-shooters-mom-guests-todd-lyons-dr-jay-bhattacharya-92525\" rel=\"nofollow noopener\" target=\"_blank\">oppose<\/a> its policies. Thus far, the <a href=\"https:\/\/www.fema.gov\/sites\/default\/files\/documents\/fema_gpd_ib-566-signed.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Department<\/a> of <a href=\"https:\/\/www.washingtonpost.com\/politics\/2026\/06\/30\/ice-free-speech-new-york\/3a1b39e4-74cf-11f1-b665-5f8be87f3787_story.html\" rel=\"nofollow noopener\" target=\"_blank\">Homeland Security<\/a> and the <a href=\"https:\/\/www.documentcloud.org\/documents\/26371599-bondi-memo-on-countering-domestic-terrorism-and-organized-political-violence-1\/\" rel=\"nofollow noopener\" target=\"_blank\">Department of Justice<\/a> have been the key agencies implementing this objective. At the same time, the administration has moved to bring foreign intelligence authorities to bear on domestic political activity. It has designated foreign groups as terrorist organizations, creating openings to investigate U.S. persons and organizations with any connection to them, however attenuated. The invocation of a foreign nexus could allow the Pentagon\u2019s surveillance capabilities to reach domestic actors.<\/p>\n<p>The military has exploited the mantle of foreign intelligence for domestic political purposes before. During the Vietnam war, the Army\u2019s Continental US (CONUS) Intel program monitored and infiltrated civil rights organizations, anti-war demonstrators, and women\u2019s liberation groups. It ran some 1,500 agents and kept files on at least 100,000 Americans. And President Trump has shown an appetite for inserting the military into domestic matters. In 2025, he <a href=\"https:\/\/www.washingtonpost.com\/national-security\/2026\/02\/11\/national-guard-los-angeles-chicago-portland\/\" rel=\"nofollow noopener\" target=\"_blank\">deployed<\/a> more than 8,000 National Guard troops and active-duty Marines to six American cities to police protests. The Pentagon\u2019s new deals to deploy commercial LLMs on its classified networks provide his administration with a new and powerful surveillance capability that could be turned on Americans.<\/p>\n<p>This post will analyze the risks LLMs pose in the context of commercially available information and a forthcoming second piece will address how they manifest in the context of foreign intelligence surveillance.<\/p>\n<p>A Backgrounder on Metadata and Commercially Available Information<\/p>\n<p>Metadata first burst into public debate when Edward Snowden <a href=\"https:\/\/www.theguardian.com\/world\/2013\/jun\/06\/nsa-phone-records-verizon-court-order\" rel=\"nofollow noopener\" target=\"_blank\">revealed<\/a> that the National Security Agency had been using its authority under Section 215 of the Patriot Act to collect records of Americans\u2019 phone calls\u2014including the phone numbers on either end of each call, along with the times the call started and ended\u2014in bulk. Until then, most surveillance debates had focused on controlling government access to the content of communications. Snowden\u2019s revelations forced policymakers and the public to grapple with what metadata could reveal at scale. Former NSA and CIA director Michael Hayden went so far as to <a href=\"https:\/\/www.justsecurity.org\/10318\/video-clip-director-nsa-cia-we-kill-people-based-metadata\/\" rel=\"nofollow noopener\" target=\"_blank\">declare<\/a> that \u201cwe kill people based on metadata,\u201d an apparent allusion to certain <a href=\"https:\/\/www.thebureauinvestigates.com\/stories\/2014-01-23\/more-than-2-400-dead-as-obamas-drone-campaign-marks-five-years\" rel=\"nofollow noopener\" target=\"_blank\">drone strikes<\/a> carried out by the Obama administration. Congress too recognized the threat to Americans\u2019 privacy posed by bulk collection of metadata, first reforming and then <a href=\"https:\/\/www.congress.gov\/bill\/114th-congress\/house-bill\/2048\/text\/statute\" rel=\"nofollow noopener\" target=\"_blank\">shuttering<\/a> the program.<\/p>\n<p>Around the same time, courts started to grapple with digital data held by third parties (such as banks or phone companies), which was traditionally considered <a href=\"https:\/\/tile.loc.gov\/storage-services\/service\/ll\/usrep\/usrep425\/usrep425435\/usrep425435.pdf\" rel=\"nofollow noopener\" target=\"_blank\">outside<\/a> <a href=\"https:\/\/tile.loc.gov\/storage-services\/service\/ll\/usrep\/usrep442\/usrep442735\/usrep442735.pdf\" rel=\"nofollow noopener\" target=\"_blank\">the scope<\/a> of Fourth Amendment protections. In 2018, the Supreme Court issued a landmark decision in <a href=\"https:\/\/www.supremecourt.gov\/opinions\/17pdf\/16-402_h315.pdf?inline=1\" rel=\"nofollow noopener\" target=\"_blank\">Carpenter v. United States<\/a>, breaking from this doctrine. The Court held that seven days of historical location data from cell phone towers could be so revealing that the government needed a probable cause warrant to compel disclosure by phone companies. Such data, Chief Justice Roberts wrote, constitutes \u201ca detailed chronicle of a person\u2019s physical presence compiled every day, every moment, over several years.\u201d In June 2026, in <a href=\"https:\/\/www.supremecourt.gov\/opinions\/25pdf\/25-112_0am4.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Chatrie v. United States<\/a>, the Court <a href=\"https:\/\/www.supremecourt.gov\/opinions\/25pdf\/25-112_0am4.pdf\" rel=\"nofollow noopener\" target=\"_blank\">extended<\/a> this rationale to the compelled disclosure of location history for even a short time, reasoning that it could reveal a person\u2019s visit to a psychiatrist, an abortion clinic, or a political rally.<\/p>\n<p>By and large, the government has side-stepped this requirement. Agencies simply <a href=\"https:\/\/www.brennancenter.org\/our-work\/research-reports\/closing-data-broker-loophole\" rel=\"nofollow noopener\" target=\"_blank\">buy up<\/a> information on swaths of Americans\u2019 movements, associations, and behavior on the commercial data marketplace, without any warrant, court order, or subpoena. They <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/011521%20CTD%20Discussion%20RFI%20Response_redaction.pdf\" rel=\"nofollow noopener\" target=\"_blank\">take<\/a> the <a href=\"https:\/\/www.buzzfeednews.com\/article\/hamedaleaziz\/ice-dhs-cell-phone-data-tracking-geolocation\" rel=\"nofollow noopener\" target=\"_blank\">position<\/a> that the Carpenter\u00a0warrant requirement does not apply to commercial purchases (e.g., data harvested by apps), but only to the compelled production of records (e.g., from a phone company). The result is that bulk collection of the type that Section 215 made controversial, including the collection of information (like location data) that would otherwise require a warrant to obtain, is now ubiquitous and accomplished at far greater scale via the private sector.<\/p>\n<p>The Department of Defense has <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/signed_wyden_letter_to_dni_re_nsa_purchase_of_domestic_metadata_and_ftc_order_on_data_brokers_with_attachments.pdf\" rel=\"nofollow noopener\" target=\"_blank\">acknowledged<\/a> that it is a customer in this market for commercial data but has not revealed the scope of its purchases and has only provided the most general justifications for acquiring this information. Documents disclosed by lawmakers and in the press suggest that these purchases are vast in scale. In 2020, <a href=\"https:\/\/www.vice.com\/en\/article\/us-military-location-data-xmode-locate-x\/\" rel=\"nofollow noopener\" target=\"_blank\">Motherboard reported<\/a> that U.S. Special Operations Command had bought access to location data harvested from a Muslim prayer app that had more than 98 million downloads worldwide along with other consumer apps with millions of users in the United States. In 2021, the New York Times <a href=\"https:\/\/www.nytimes.com\/2021\/01\/22\/us\/politics\/dia-surveillance-data.html\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> that the Defense Intelligence Agency <a href=\"https:\/\/int.nyt.com\/data\/documenttools\/dni-to-wyden-on-commercially-available-smartphone-locational-data\/5d9f9186c07993b6\/full.pdf\" rel=\"nofollow noopener\" target=\"_blank\">receives<\/a> \u201ccommercially available geolocation metadata aggregated from smartphones,\u201d including location data about devices and users in the United States. Multiple branches of the military have reportedly purchased access to a <a href=\"https:\/\/www.vice.com\/en\/article\/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data\/\" rel=\"nofollow noopener\" target=\"_blank\">database<\/a> of global internet traffic, updated with over 100 billion new records each day, including in some cases individuals\u2019 browsing history and even the contents of their communications. According to the Pentagon, these large-scale warrantless purchases of information do not count as mass domestic surveillance.<\/p>\n<p>Members of Congress have tried to close this gap. The <a href=\"https:\/\/www.congress.gov\/bill\/118th-congress\/house-bill\/4639\" rel=\"nofollow noopener\" target=\"_blank\">Fourth Amendment Is Not For Sale Act<\/a>, which would prohibit federal agencies including the Defense Department from purchasing certain types of sensitive data they would otherwise need a warrant to obtain, <a href=\"https:\/\/clerk.house.gov\/Votes\/2024136\" rel=\"nofollow noopener\" target=\"_blank\">passed the House<\/a> in 2024 with bipartisan support, but the Senate failed to take it up. Similar legislation, including the bipartisan <a href=\"https:\/\/www.congress.gov\/bill\/119th-congress\/senate-bill\/4082\/text\" rel=\"nofollow noopener\" target=\"_blank\">Government Surveillance Reform Act<\/a>, remains pending.<\/p>\n<p>What this means, <a href=\"https:\/\/www.anthropic.com\/news\/statement-department-of-war\" rel=\"nofollow noopener\" target=\"_blank\">according to<\/a> Anthropic\u2019s CEO, is that \u201cunder current law, the government can purchase detailed records of Americans\u2019 movements, web browsing, and associations from public sources without obtaining a warrant.\u201d Layering AI on this information would make it possible \u201cto assemble this scattered, individually innocuous data into a comprehensive picture of any person\u2019s life\u2014automatically and at massive scale.\u201d<\/p>\n<p>Increased Risks Raised by LLMs in the Context of Commercially Available Information<\/p>\n<p>Section 215 of the Patriot Act involved the collection of a single type of information: phone metadata. The information the government now purchases spans dozens of channels, including location, browsing history, financial transactions, social media posts, and app usage. Well before the advent of LLMs, intelligence agencies fused these data streams into consolidated analytical environments, using tools like Palantir\u2019s <a href=\"https:\/\/www.wired.com\/story\/palantir-what-the-company-does\/\" rel=\"nofollow noopener\" target=\"_blank\">Gotham<\/a> platform. The combined data could be used to surface a person\u2019s daily routines, networks of association, and recurring movements. It could produce what is called \u201cpattern of life\u201d analysis, creating an even more comprehensive picture than the one the Supreme Court found so concerning in the Carpenter case.<\/p>\n<p>LLMs\u2014even off-the-shelf products\u2014can do more, and faster. Pre-LLM platforms built pattern-of-life analyses by matching datasets. They typically linked one dataset to another to find shared identifiers within them, such as a name or a telephone number. For example, ICE has used a Palantir tool, <a href=\"https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/privacy_pia_ice_falconsa_january2014.pdf\" rel=\"nofollow noopener\" target=\"_blank\">FALCON-SA<\/a>, to link records across government and commercial databases, surfacing previously unknown connections among individuals and organizations. LLMs, however, can identify a person from the substance and style of what they wrote or said, even in the absence of specific identifiers attached to the data. Several recent studies bear this out. LLM agents have <a href=\"https:\/\/arxiv.org\/abs\/2602.16800\" rel=\"nofollow noopener\" target=\"_blank\">matched<\/a> pseudonymous accounts to public LinkedIn profiles. They have also <a href=\"https:\/\/arxiv.org\/abs\/2601.05918\" rel=\"nofollow noopener\" target=\"_blank\">re-identified<\/a> some participants in a released interview dataset whose identifying details had been redacted.<\/p>\n<p>These models also scale. Earlier tools required analysts to sort information into categories (e.g., name, telephone number) before analysis could begin. As the studies linked above show, however, LLMs can directly absorb unstructured material (e.g., reports, transcripts, posts) and extract facts and infer attributes. The result is that they have the capacity to process more data with fewer people, enabling mass profiling.<\/p>\n<p>Conversely, an intelligence analyst can start with a characteristic and use an LLM to search the dataset for everyone who shares that characteristic. This capability may well be useful for intelligence work, but it can also be used to target people based on their political views. Indeed, studies have shown that LLMs can accurately infer <a href=\"https:\/\/arxiv.org\/abs\/2603.11253\" rel=\"nofollow noopener\" target=\"_blank\">political<\/a> <a href=\"https:\/\/arxiv.org\/abs\/2304.06588\" rel=\"nofollow noopener\" target=\"_blank\">ideology<\/a> and <a href=\"https:\/\/arxiv.org\/abs\/2310.07298\" rel=\"nofollow noopener\" target=\"_blank\">demographic<\/a> attributes from text that does not explicitly disclose those attributes. An analyst can ask the system open-ended questions: Who in this dataset holds \u201c<a href=\"https:\/\/www.uscis.gov\/newsroom\/news-releases\/uscis-to-consider-anti-americanism-in-immigrant-benefit-requests\" rel=\"nofollow noopener\" target=\"_blank\">unAmerican<\/a>\u201d views? Who is likely to take part in an ICE protest? Who is likely to organize an anti-abortion rally?<\/p>\n<p>As developers themselves have recognized, the model\u2019s outputs can also be wrong, triggering serious consequences for individuals. OpenAI\u2019s report on a 2023 model <a href=\"https:\/\/cdn.openai.com\/papers\/gpt-4.pdf\" rel=\"nofollow noopener\" target=\"_blank\">warns<\/a> that it \u201ccan be confidently wrong in its predictions\u201d and cautions that great care is warranted in high-stakes contexts. This is not an isolated flaw. One <a href=\"https:\/\/arxiv.org\/abs\/2505.02151\" rel=\"nofollow noopener\" target=\"_blank\">study<\/a> of five LLMs found that they \u201coverestimate the probability that their answer is correct between 20% and 60%.\u201d Despite these inherent limitations, analysts may succumb to <a href=\"https:\/\/openscholarship.wustl.edu\/cgi\/viewcontent.cgi?article=1166&amp;context=law_lawreview\" rel=\"nofollow noopener\" target=\"_blank\">automation bias<\/a>, treating a system\u2019s output as presumptively correct. Institutional incentives only compound this tendency. Depending on the context, an analyst may reasonably fear blame for failing to act on a missed flag more than for acting on a false one. The consequences could be serious: a denial of immigration benefits on security grounds, a spot on a watchlist that is near impossible to challenge, extra scrutiny at the border, or a visit from a law enforcement officer.<\/p>\n<p>The Current Rules are Inadequate<\/p>\n<p>Existing rules and policies do not meaningfully address these risks. The activities of intelligence agencies are governed primarily by <a href=\"https:\/\/www.odni.gov\/files\/NCSC\/documents\/Regulations\/EO_12333.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Executive Order 12333<\/a> and procedures implementing the order. These authorize the Defense Department to conduct a broad range of defense-related foreign intelligence and counterintelligence activities, including the collection of information about foreign governments, organizations, and persons, including international terrorists and <a href=\"https:\/\/policy.defense.gov\/Portals\/11\/Documents\/DoD%20Framework%20to%20Counter%20Drug%20Trafficking%20and%20Other%20Illicit%20Threat%20Networks%20May%202019.pdf\" rel=\"nofollow noopener\" target=\"_blank\">drug traffickers<\/a>. Some foreign intelligence information may also be used for <a href=\"https:\/\/www.congress.gov\/bill\/118th-congress\/house-bill\/7888\/text#y410005a2-e80b-11f0-a1e4-69761a48a15a\" rel=\"nofollow noopener\" target=\"_blank\">immigration vetting<\/a>.<\/p>\n<p>The types of foreign-linked activity that can be treated as a justifying collection for a foreign intelligence purpose may be stretched even further: the Trump administration has moved to investigate domestic civil society groups and their funders for their purported foreign ties. In 2025, it issued <a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2025\/09\/countering-domestic-terrorism-and-organized-political-violence\/\" rel=\"nofollow noopener\" target=\"_blank\">National Security Presidential Memorandum 7<\/a> with the stated aim of combatting domestic terrorism. The memorandum is so broadly framed as to allow the government to target <a href=\"https:\/\/www.brennancenter.org\/our-work\/research-reports\/trumps-orders-targeting-antifascism-aim-criminalize-opposition\" rel=\"nofollow noopener\" target=\"_blank\">U.S. civil society entities and individuals<\/a> who engage in activities or support views that are adversarial to the administration. For example, even though the administration has generally <a href=\"https:\/\/www.justice.gov\/ag\/media\/1388541\/dl\" rel=\"nofollow noopener\" target=\"_blank\">limited<\/a> implementation of the Foreign Agents Registration Act, NSPM-7 <a href=\"https:\/\/www.federalregister.gov\/d\/2025-19141\/p-13\" rel=\"nofollow noopener\" target=\"_blank\">calls for<\/a> investigations under this law of non-governmental institutions and funders that support a range of supposedly anti-fascist views, including anti-American, anti-capitalist, and anti-Christian. It also has deployed terrorism designations against groups in its crosshairs\u2014such as <a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2025\/11\/designations-of-antifa-ost-and-three-other-violent-antifa-groups\" rel=\"nofollow noopener\" target=\"_blank\">alleged antifa affiliates<\/a> in Europe and <a href=\"https:\/\/ofac.treasury.gov\/recent-actions\/20260121\" rel=\"nofollow noopener\" target=\"_blank\">Palestinian non-profits<\/a>\u2014creating an opening to use foreign intelligence authorities to <a href=\"https:\/\/www.justsecurity.org\/36826\/designate-muslim-brotherhood-foreign-terrorist-organization\/\" rel=\"nofollow noopener\" target=\"_blank\">investigate U.S. organizations<\/a> with any connection to the designated entities, however attenuated.<\/p>\n<p>The malleability of the foreign intelligence framework is compounded by the weakness of rules designed to prevent abuse. The 2024 <a href=\"https:\/\/www.dni.gov\/files\/ODNI\/documents\/CAI\/Commercially-Available-Information-Framework-May2024.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Policy Framework for Commercially Available Information<\/a> contemplates heightened protections for \u201csensitive\u201d commercially available information (CAI). But it notably fails to specify even the most obvious categories of sensitive CAI, such as data that allows location tracking. As noted above, the Supreme Court in Carpenter held that the government must obtain a warrant to obtain cell phone data that allows sustained location tracking, a holding that it recently extended to short-term location tracking in Chatrie. Instead, each agency must decide on the sensitivity of datasets, based on whether the data: 1) contain a \u201csubstantial\u201d volume of Americans\u2019 personally identifiable information; or 2) contain a greater than \u201cde minimis\u201d volume of Americans\u2019 activities that establish a \u201cpattern of life\u201d over an extended period. By doing so, as my Brennan Center colleagues have <a href=\"https:\/\/www.brennancenter.org\/our-work\/analysis-opinion\/intelligence-communitys-policy-commercially-available-data-falls-short\" rel=\"nofollow noopener\" target=\"_blank\">explained<\/a>, the framework lets each agency decide contested issues such as what counts as a \u201csubstantial volume\u201d of Americans\u2019 information or whether data reveals a \u201cpattern of life.\u201d Similarly, although the framework identifies several potentially useful controls (e.g., restricting access, requiring written justification and approval, deleting U.S. person information from datasets), agencies get to decide which of these are needed. Many of these, as I will explain in my forthcoming piece on AI and Warrantless Foreign Intelligence Surveillance, may be rendered less effective with the deployment of LLMs. The CAI Framework does not address this possibility.<\/p>\n<p>In 2024, President Biden issued a <a href=\"https:\/\/bidenwhitehouse.archives.gov\/briefing-room\/presidential-actions\/2024\/10\/24\/memorandum-on-advancing-the-united-states-leadership-in-artificial-intelligence-harnessing-artificial-intelligence-to-fulfill-national-security-objectives-and-fostering-the-safety-security\/\" rel=\"nofollow noopener\" target=\"_blank\">National Security Memorandum on AI<\/a> and accompanying <a href=\"https:\/\/data.aclum.org\/storage\/2025\/01\/WhiteHouse_ai_gov_wp-content_uploads_2024_10_NSM-Framework-to-Advance-AI-Governance-and-Risk-Management-in-National-Security.pdf\" rel=\"nofollow noopener\" target=\"_blank\">framework<\/a> to regulate the use of AI systems across national security data holdings, including CAI. As I have previously explained, the memorandum and framework were an important step forward but left agencies with too much discretion to decide on whether to apply safeguards and was almost <a href=\"https:\/\/www.justsecurity.org\/104242\/memorandum-ai-national-security\/\" rel=\"nofollow noopener\" target=\"_blank\">entirely dependent<\/a> on internal oversight. On June 5, 2026, the Trump administration rescinded the Biden memorandum and framework, replacing it with National Security Presidential <a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2026\/06\/national-security-presidential-memorandum-nspm-11\/\" rel=\"nofollow noopener\" target=\"_blank\">Memorandum 11<\/a>. The new Trump AI memorandum broadly states that the use of AI for national security \u201cmust always be\u00a0consistent with United States civil liberties and protections afforded by the Constitution and laws and regulations safeguarding the privacy of American citizens,\u201d but provides no details on how this mandate is to be executed. A policy framework for national security AI governance and safeguards is slated to be issued in September 2026. As it stands though, the rules are far from adequate to address the risks posed by CAI amplified by LLMs.<\/p>\n<p>Conclusion<\/p>\n<p>Whether the Pentagon\u2019s collection and use of Americans\u2019 data counts as \u201cmass domestic surveillance\u201d turns on how the term is defined. The government places its purchases of commercial information about Americans outside the surveillance envelope because it is not compelling production. But what should concern us is the outcome: the collection and analysis of vast quantities of Americans\u2019 information, regardless of how the information is acquired. By that measure, LLMs increase the civil liberties risks of the Defense Department\u2019s data holdings, and the rules meant to address those risks do not meaningfully mitigate them.<\/p>\n<p>FEATURED IMAGE: This photograph shows a handheld smartphone displaying the icons of some of the main artificial intelligence based apps, including LLMs, chatbots and generative AI, with logos (from L) of Proton AG&#8217;s Lumo, Meta AI, Mistral Vibe (formerly Le Chat), xAI&#8217;s Grok, Microsoft&#8217;s Copilot, Google&#8217;s Gemini, Anthropic&#8217;s Claude, Perplexity, Deepseek, OpenAI&#8217;s Chat GPT, Google&#8217;s Notebook LLM and generative AI music app Suno, in Saint-Mande, east of Paris, on July 15, 2026. (Photo by Martin LELIEVRE \/ AFP via Getty Images)<\/p>\n","protected":false},"excerpt":{"rendered":"In May 2026, the Pentagon announced that it had reached deals with eight AI companies\u2014SpaceX, OpenAI, Google, NVIDIA,&hellip;\n","protected":false},"author":2,"featured_media":113321,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,111,1670,203,331,58088,14701,8783,4073,28336,8526,388,37380],"class_list":["post-113320","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-congress","tag-data","tag-department-of-defense-dod","tag-digital-surveillance","tag-domestic-surveillance","tag-emerging-technology","tag-executive-branch","tag-executive-orders","tag-large-language-models-llms","tag-pentagon","tag-trump-administration-second-term"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=113320"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113320\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/113321"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=113320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=113320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=113320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}