"Find church-going Christians in Janesville, Wisconsin. Write a detailed dossier on one."
That is one sample prompt from an AI demo that staff from dozens of congressional offices have seen since late April, as Politico printed it on September 1, 2026. Twelve words: no name, no address, no photograph — just a town, and the fact of going to church.
The nonprofit behind it, CivAI, which calls itself "an independent non-profit based in California," built the demo in about two weeks on an open-source model and a handful of broker subscriptions costing about $500 a month (it declined to name the brokers). Its dossiers, Politico reports, end with "a section about potential vulnerabilities to exploit."
A disclosure first. In January I argued here for a federal digital bill of rights, warning that foreign adversaries don't need to hack American systems for sensitive data on U.S. citizens: "They can simply buy it." The same piece praised California's data broker regulation and called the state patchwork "unsustainable and fundamentally unfair." A federal bill would switch part of that regulation off, so read this as an argument about what a federal law must keep, not whether we need one.
In short, the dossier was never the new part — the price and the speed are. And the two fixes on the table each reach half the problem: one would stop only government buyers, and the other — California's one-request deletion tool — is exactly what a House bill would preempt.
What comes back from twelve words
So what does the agent hand over? For Politico's demo, it pulled up where a Wisconsin church volunteer lives, her social media accounts and her shopping habits, then suggested that her predictable weekly routine and reused passwords could be used to find her and learn even more about her.
Four Republican and eight Democratic staffers told Politico the dossiers include advice on potential ways to blackmail, coerce or stalk the person in question. Staff also said the dossiers flagged mental health treatment and visits to abortion clinics and lawmakers' offices. A Republican staffer at the July briefing said the results included passwords tied to a gun store owner's email address, which had reached commercial databases through previous data breaches. (To be clear, the AI hacked nothing; earlier breaches did that work.)
Why did this land in both parties at once? Partly because of who was in the files. Three Republican staffers said House GOP members were concerned about the dossiers on gun store owners, and a Senate staffer who watched the July demo called it "a de facto gun registry." Rep. Lori Trahan (D-Mass.) warned that anyone with a frontier AI model can buy your data from a broker and reconstruct "an intimate picture of your life," down to "who you love or where you worship."
None of the raw material is new; brokers have long sold people's travels, shopping habits and employment histories. What changed, Politico notes, is that "AI makes it easier to quickly pull that data into one place." In December 2023 the security technologist Bruce Schneier warned that AI would lift the human-labor limit on spying and usher in the era of mass spying. About $500 a month is what that era looks like at retail.
Two fixes, each built for half the problem
So what is Washington doing about it? Two fixes are on the table.
The first is the Fourth Amendment Is Not For Sale Act, which says a law enforcement agency and an element of the intelligence community "may not obtain from a third party in exchange for anything of value" a covered customer or subscriber record. Police and spy agencies, in other words; by my reading, it would not touch CivAI or any other private buyer. The House passed it 219-199 in April 2024 (the ACLU called its passage "a flashing warning sign to the government"), but it died in the Senate.
That approach now rides on the fight over Section 702 of the Foreign Intelligence Surveillance Act, the authority for warrantless surveillance of foreigners abroad, which expired on June 12, 2026, for the first time since 2008. Under certifications the FISA Court approved, surveillance may continue until March 17, 2027, the Brennan Center notes. A Democratic House aide told Politico the renewal fight is lawmakers' most realistic chance at addressing the issue this Congress.
My own reading of the calendar (and it is mine, not the aide's): this Congress ends at noon on January 3, 2027. Intelligence officials want a renewal before Thanksgiving, The Hill reported, but Rep. Jamie Raskin (D-Md.) says "March is the real deadline." If he is right, the fight the aide is counting on can run into the next Congress.
The second fix already exists, in one state. California's Delete Act requires a system that lets you, "through a single verifiable consumer request," ask every data broker holding your personal information to delete it. CalPrivacy, the state's privacy agency, launched it on January 1, 2026 as DROP, the Delete Request and Opt-out Platform, and calls it "a first-of-its-kind system" reaching over 600 active brokers. Since August 1, 2026, brokers must check it at least once every 45 days; a law signed on September 27 shortens that to every 30 days from January 1, 2027. Over 520,000 Californians have signed up, CalPrivacy's executive director, Tom Kemp, said in a KQED report published September 15, 2026.
Is California alone? Among running systems, as far as I can find, yes. Connecticut has enacted one, due by July 1, 2028, and Vermont's new law does not establish a centralized deletion mechanism.
A registry instead of a delete button
So what would the House bill do to DROP? H.R. 8413, the SECURE Data Act, was introduced on April 21, 2026 by Rep. John Joyce (R-Pa.) and now has ten Republican cosponsors. It bars states from maintaining or enforcing any law that "relates to the provisions of this Act." CalPrivacy's reading is blunt: 40 million Californians would no longer be able to use DROP. The privacy group EPIC lists the "California DELETE Act" among the laws it believes would be preempted. Backers want that breadth: the U.S. Chamber of Commerce says courts would read the clause as "a single set of rules."
And in place of DROP? A searchable, central registry of data brokers on a federal website, each linked to its own page on how to exercise your rights. I read the bill looking for a way to reach every broker at once. It isn't there. A registry is a phone book; DROP is a delete button. The bill also counts a company as a broker only if it derives "50 percent or more of annual gross revenue from the sale of such personal data"; California's definition makes that one of three alternative tests.
Now, the odds. GovTrack gives the bill a 2% chance of being enacted. It has had one subcommittee hearing, on June 3, which split along party lines and where, Politico reported, Trahan argued the bill does not address what the demo showed. As far as I can find, there has been no markup. Treat it as the direction federal preemption is heading, not an imminent vote.
Is a staged demo worth this much alarm?
Fair question, and the demo's own fine print raises it. CivAI swaps in "Jane Doe" and AI-generated images for real details (the live demos use real people's data, it says), and the location data in its Capitol Hill demos is simulated. Searching for Politico's own reporter, the agent "provided inaccurate results on his address, age and occupation." CivAI is also an advocate: its co-founder, Sid Hiregowdara, says it wants "durable attention on this problem," and while Wikipedia says it "does not take positions on specific legislation," its site lists its August 2026 op-ed "Unregulated Open-Weight AI Is an Invitation to Disaster."
So discount the staging. Hiregowdara blamed the errors on the low-cost subscriptions and said a motivated attacker, such as a foreign adversary, could have access to higher-quality data. A May 2026 preprint, not yet peer-reviewed, points the same way: it reported rebuilding profiles with "over 90% factual accuracy within 10 minutes at a cost under $3." The demo's errors are a comfort with an expiration date.
There is a harder objection, and it cuts against DROP itself. Under California's law, personal information "does not include publicly available information," including information lawfully made available from government records. So DROP leaves in place anything that is a matter of public record, such as vehicle or real estate ownership, as the Electronic Frontier Foundation's guide notes, and a dossier can feed on exactly that. SB 435, a bill to narrow other parts of the exemption (not government records), was held in committee on August 13, 2026, where it died. A coalition of business organizations including the Consumer Data Industry Association (which Politico calls the brokers' main trade group) opposed it, arguing that "Once information has been lawfully made public, it can — and must — remain available to Californians, including businesses, subject to established limits."
That argument deserves a hearing; public records are public so that anyone can check them. But DROP still covers what a registered broker holds beyond the public record, subject to some exemptions, at every broker, in one request.
Nearly six million notices: Europe's other answer
How does Europe handle the public-record problem? From the other end. Under the GDPR, when personal data "have not been obtained from the data subject," the company holding them must tell you where they came from, including "whether it came from publicly accessible sources," generally "at the latest within one month," with exceptions, including where notice "would involve a disproportionate effort." In Europe, public sources are something a company must disclose to you; in California, they are something a broker may keep.
Poland tested that rule. In March 2019 its data-protection authority, UODO, fined Bisnode just over PLN 943,000 (about €220,000); in the regulator's words, Bisnode "obtained data from publicly available public registers, but did not inform the persons whose data it processed." It was also ordered to contact the close to six million people it had not reached, a job Bisnode put at around €8 million in registered postage (the regulator said registered mail was not required). Of the people it did inform, the regulator said, more than 12,000 objected.
In December 2019 a Warsaw court upheld the duty to notify but annulled the order for people who had run businesses only in the past, and, because the number of people had shaped the penalty, annulled the fine. It held, IAPP reported, that disproportionate effort "cannot be translated as a financial or organizational cost." On September 19, 2023, Poland's Supreme Administrative Court dismissed Bisnode's final appeal, leaving the regulator to decide the fine again. As far as I could find, it has not yet done so.
And a button? In Europe, erasure is a right to obtain it "from the controller," one company at a time (though that company must pass the erasure on to everyone it disclosed your data to, unless that proves impossible or disproportionate). Austria's statutory Robinson list and Italy's public opt-out register are one-stop, but only for marketing (Austria's, in my translation, also bars marketers from passing your data on); neither makes anyone erase anything. I looked for a European equivalent of DROP — a single request that makes every broker erase you — and could not find one.
So which side of the Atlantic has it right? Each has half. Europe's notice duty reaches the public-source data California exempts; California has the one-request button I could not find in Europe. A dossier like the one that sample prompt asks for lives in the gap.
When the dossier becomes a subscription
Now push what already exists two years out.
It is 2028. Suppose the SECURE Data Act, or something like it, has passed with its preemption clause intact (a long shot today, by GovTrack's odds, but bills change shape). DROP has gone dark. A federal website lists the brokers that clear the 50 percent revenue bar, each linking to its own instructions. You could work through them one by one. You won't.
Meanwhile, at the preprint's price of under $3, a dossier stops being a document and becomes a subscription, re-run whenever your life changes. You buy a house: a property record. You're named in a lawsuit: a court filing. You post from a new gym with your profile set to public, which I called in August a disclosure to everyone. None of that was ever within DROP's reach, and none of it needs a broker.
In February I called the impossibility of catching every violation an invisible safety valve. The cost of watching one person closely was a valve of the same kind, and about $500 a month removes it. And who is barred from buying the file? If the purchase ban ever passes, police and intelligence agencies. Everyone else falls under what Kemp calls "anyone with a credit card."
One choke point, two fights
Here is where things get interesting: the light-regulation camp and California's regulator aim at the same choke point. Neil Chilson of the Abundance Institute, which favors lighter regulation of emerging technology, told Politico: "The only effective place to limit that would be around the access to the data broker."
The first fight is over government purchases, where the right-libertarian wing and civil-liberties groups stand together. House Judiciary Chair Jim Jordan (R-Ohio), who did not see the briefing himself, told Politico: "You shouldn't lose your Fourth Amendment rights because you're exercising your Second Amendment rights." Rep. Warren Davidson (R-Ohio) warned in April that broker data "could be used to create a gun registry," and Americans for Prosperity backs a Senate bill that "prohibits government agencies from purchasing Americans' information from data brokers," with an exception for commingled data. A coalition of more than 130 groups, mostly civil-liberties and progressive but including the libertarian Libertas Institute, warned against letting agencies "supercharge AI-powered surveillance." One dissent comes from SIIA, a software and information industry group, which calls the "data broker loophole" "a conclusion dressed up as a description" and says the answer "is to regulate the use, not the marketplace," while granting that the concern is not frivolous.
The second fight is preemption. The Chamber wants "strong federal preemption to eliminate the growing patchwork of state privacy laws," and Joyce says his bill "is built on the foundations laid by more than 20 states: red states, blue states, and purple states." Against them, sixteen state attorneys general warn that preemption "leaves the data privacy field frozen in time," and Kemp puts it best: "A strong federal privacy law is worth pursuing, but it should not strip away rights that tens of millions of people already depend on."
What does this mean for you?
Californians: file a DROP request. It is free, for residents only. You file once; brokers must keep your data deleted if they collect it again, and you can exclude any broker you want to keep. Status updates can take up to 90 days.
Expect some records to stay. "Record exempted" means a broker matched you but may legally keep the data. The FTC warns that opting out of people-search sites doesn't delete your information from public records, and notes that such sites draw on social media profiles "that are public or viewable by everyone," so tighten who can see yours.
Everyone else: go broker by broker. The registries in California, Texas, Vermont and Oregon list registered brokers; check whether your state's privacy law lets you opt out of data sales. EFF's Opt-Out October guide cites a Consumer Reports study favoring manual opt-outs over paid services; repeat them, since deleted data can reappear.
Turn on a browser opt-out signal. Global Privacy Control is one. As of April 2026, CalPrivacy counted a dozen states that require businesses to honor such signals: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. It reaches the websites you visit, not a broker you have never dealt with.
Close the easiest doors. The gun store owner's passwords came from old breaches; the Wisconsin volunteer reused hers. Use a password manager and two-factor authentication (EFF's guide points to Consumer Reports' Security Planner).
The lesson, as I see it
A dossier like these draws on what brokers sell and on the public record. A purchase ban stops only government buyers; DROP reaches the first, for Californians who ask; Europe's notice duty reaches both but leaves erasure to you. The House bill would subtract the one piece already running here.
So what should Congress do? In January I asked for preemption "of state laws only if the federal standard is stronger," and my vote hasn't changed: a floor that leaves DROP running, not a ceiling that switches it off. Require a warrant before agencies buy broker data, the approach Jordan's committee advanced and the ACLU backs. And borrow Europe's best idea: make a broker tell you it holds your file, public sources included, so you know whom to ask.
In July, on a different preemption fight, I wrote: "You want the protection in hand before you surrender the alternative, not after." Here the protection is already in hand, for over half a million Californians. Building a dossier will keep getting cheaper. The question for Congress is whether deleting one gets harder at the same time.
Whether a stranger can buy your life story is still an open question in Washington. The HAIA Foundation argues that the answer should be written for the person in the file, not the buyer; if you want to watch Congress take it up, follow along on our Substack.





