AI Data Risks for Whistleblowers and Activists
Surveillance systems and AI tools create overlapping dangers for activists and whistleblowers.

Whistleblowers and activists now face two distinct AI threats, and these do not operate in isolation, but feed each other. The first is external: facial recognition, spyware, and predictive policing systems that governments and employers use to find, track, and preempt dissent before it spreads. The second is self-inflicted, arising from the very tools a person might turn to for help, since a whistleblower drafting a disclosure or an activist researching a legal right often reaches for a chatbot the same way anyone else would, without weighing what that choice leaves behind. Each threat alone would be serious. Together they compound: a single act, like asking an AI tool to explain a legal protection, can leave a data trail inside the platform itself while also feeding behavioral patterns that outside surveillance systems are built to catch. The rest of this piece works through both halves of that pincer, because understanding one without the other leaves a dangerous blind spot for anyone operating in a high-exposure situation.
State surveillance systems built to identify and silence dissent
Governments that want to find and silence dissent no longer rely on a single tool. They build layered systems that combine commercial spyware, informants on the ground, and AI-driven identification, so that a target who slips past one layer is likely caught by another. Morocco offers the clearest documented example of how far this architecture can go. An Amnesty International report names the Direction Générale de la Surveillance du Territoire, or DGST, as the agency responsible for deploying Pegasus spyware against journalists and activists between 2017 and 2021, after years of denial by Moroccan authorities.
The methods Amnesty documented span a wide range of technical sophistication. Some devices were physically infected. Others fell to 1-click attacks that needed a single tap from the victim, and some to zero-click attacks that needed nothing from the victim. Network injection attacks were delivered through Maroc Telecom, the state-owned telecommunications provider, so the infrastructure people rely on for ordinary communication became the delivery mechanism for their own surveillance. Targets were recorded in detention, in their offices, homes, cars, cafes, and airports. Their phone calls were intercepted and their location tracked continuously. Investigators even recruited neighbors of targeted human rights defenders as informants, so the surveillance net extended to families, friends, and professional contacts who had done nothing but know the wrong person.
The scale becomes concrete in the numbers Amnesty assembled. Researchers matched 103 Moroccan phone numbers to individuals selected as potential Pegasus targets, and of those, 65 were identifiable members of civil society: 34 human rights defenders, 22 journalists, and five lawyers. The spyware itself came from a cluster of firms Amnesty describes as a "global economy of techno-oppression," including NSO Group of Israel, the former Italian firm Hacking Team (now operating as Memento Labs), and the British-German firm Gamma Group, maker of FinFisher. Much of what Amnesty was able to piece together came from an insider: a former DGST employee using the pseudonym "Safir," whose testimony investigators corroborated against digital forensics, leaked surveillance data, and interviews with multiple people who had been targeted.
You can see the same dynamic in another country, with different tools and under a different legal system. Reporting from February 2026 described an incident on January 10, 2026, in which an ICE agent approached Nicole Cleland, a 56-year-old volunteer with an ICE watchdog group in Richfield, Minnesota, and addressed her by name despite never having met her, citing facial recognition technology and a body camera as the basis. The inference chain behind that moment runs from a face in a crowd, to a name, to a person's online activity, to a real-world location, a chain that commercially purchased datasets, social media profiles, and any prior encounters on file strengthen whenever a match is only partial. What makes this mechanism self-reinforcing is that photos, videos, or messages shared about a protest, on any platform, can be analyzed by police and used to add participants to watchlists or build profiles that feed further predictive policing. Most people who end up on such a list never find out, and removal, where it is even possible, is rarely straightforward. Morocco and Minnesota are different political systems under different legal frameworks, but the same mechanism, identify once and track indefinitely, runs through both.
The particular risk facial recognition carries for people of color
Facial recognition does not fail evenly across the population it is pointed at, and that unevenness lands hardest on the communities already most likely to be watched. Black individuals account for at least eight out of ten people wrongfully arrested based on faulty facial recognition matches, a gap that turns a flawed technology into a flawed technology with a clear racial pattern.
The human cost of that pattern is visible in the case of Angela Lipps, a Tennessee grandmother detained for nearly six months after authorities relied on a flawed AI facial recognition match, one they failed to adequately verify or corroborate, to extradite her from Tennessee to North Dakota for a crime she had no connection to. Six months is a long time to live inside someone else's mistake, and Lipps's case shows what happens when a system built to move fast skips the step of checking its own work.
That risk does more than punish people after the fact. It changes behavior before anything happens. If facial recognition raises the odds that a demonstrator will face some form of persecution, people have reason to stay home before a protest even begins. In some authoritarian settings, the technology's deterrent power works even when it barely functions, because authorities can lean on the idea of facial recognition surveillance as much as on any functioning system, letting the implied presence of a camera do the work a working camera would otherwise have to do. Does a surveillance tool even need to work well to be effective? These cases both suggest the answer is no, so long as the people being watched believe that it does.
The surveillance that follows corporate whistleblowers inside their own organizations
Street-level activists are not the only people living inside a surveillance net. Corporate insiders, especially at AI companies, now face a threat built from the same technology they help develop. Employers have the technical means to turn their own AI products into real-time leak-detection systems, and that capability creates a lopsided relationship: management can see almost everything an employee does on company systems, while the employee has no way of knowing what threshold of activity might trigger an investigation.
OpenAI's own conduct makes the mechanism concrete. The company used ChatGPT to analyze internal communications, including Slack messages, emails, and internal documents, and cross-reference them against published news articles, tracing the origin of a disclosure in minutes rather than the weeks such an investigation would once have taken. The Wall Street Journal reported that OpenAI dismissed three employees over this process, after allegations they had shared confidential information with a third-party AI safety organization. Other outlets identified the three as Jasmine Wang, Tomek Korbak, and Mikita Balesni, though the Journal itself did not name them. OpenAI declined to identify the outside organization or specify what information was allegedly shared, with a company spokesperson stating only that the individuals "mishandled sensitive information outside established company procedures." The response from outside the company was sharp. Congressional Progressive Caucus Chair Greg Casar said, "Looks like they're firing whistleblowers. What are they hiding?" Shaunna Thomas of the Guardrails Alliance called the firings "the latest example of OpenAI advocating for safety measures in the public eye, but actively making decisions and lobbying against those efforts behind closed doors."
Reporting from May 2026 describes a broader pattern beyond any single company: insiders pursued by attorneys after raising concerns, personal devices reviewed retroactively, and professional networks that quietly cool once a person has been flagged internally. One former safety researcher was told by a recruiter that multiple companies had "concerns" about her, based on conversations she was never shown or told the content of. Blacklisting in Silicon Valley rarely announces itself. It operates through declined meetings, vague recruiter feedback, and opportunities that simply stop appearing.
Some of the resistance to this environment has become public. The "Right to Warn" open letter, signed in June 2024 by current and former staff of OpenAI and Google DeepMind, put internal dissent on the record rather than leaving it to rumor. Daniel Kokotajlo left OpenAI in 2024 after refusing to sign a non-disparagement contract that would have permanently limited what he could say about his time there, a refusal that put roughly $2 million in equity at risk before OpenAI reversed the policy and let him keep it. Not every employee has that kind of leverage or that kind of public attention behind them. Many operate under NDAs that stop short of an outright legal violation but still make an employee think twice before calling a regulator, and in some documented cases, raising a safety concern about a release schedule has quietly found its way into that employee's performance review. Debevoise & Plimpton's March 2026 legal update names the asymmetry directly: employers gain real-time insight into employee behavior, while workers have no equivalent visibility into how their own communications are being analyzed or what triggers a formal look.
The AI Tools Whistleblowers Reach for Can Expose Them
A whistleblower trying to understand a legal protection, or an activist trying to draft a statement, often turns to the same public AI tools everyone else uses, without pausing to ask what happens to that conversation afterward. That instinct is understandable, but it exposes anyone in a high-exposure situation, because nothing typed into a public chatbot carries legal privilege, those queries can be stored and used to train future models, and in some circumstances the underlying data can be turned over in litigation, potentially to the very organization being reported.
The comparison that makes this clearest is professional privilege. Conversations with a lawyer or a therapist carry legal protection built up over decades specifically because society has decided some disclosures need a safe channel. LLM conversations carry no such protection, but people tell a chatbot things they would never say to another human being. That gap between how people use these tools and what legal protection actually covers has not been closed.
The exposure compounds when the content itself is sensitive. Pasting an internal document into a public AI tool can violate a confidentiality agreement and expose the identity of the person who pasted it, both at once, turning a single action into two separate sources of risk. A Stanford study confirmed the mechanism behind part of this problem: six leading U.S. AI companies feed user inputs back into their models to improve capabilities, and the privacy documentation describing this practice is often unclear enough that users struggle to understand what rights they actually have over their own data.
The newest layer of risk comes from agentic systems, the AI tools built to take actions rather than just answer questions. Debevoise & Plimpton's update notes that agentic AI systems can access data or systems beyond what they were authorized to touch, and that a malicious actor can exploit the trust relationships built into these systems to trick an agent into granting privileges it was never supposed to have. Data can leak even when the company that built and deployed the tool never intended it to.
Privacy-Preserving AI Architecture in Practice for People at Risk
Everything described in the previous section follows from a specific set of design choices made about artificial intelligence, not an unavoidable property of the technology itself. A tool built to collect, store, and learn from what users type is structurally at odds with the needs of someone whose safety depends on that input staying private. That tension has nothing to do with bad intent on the part of any provider. It comes from a business model built around data collection meeting a security need that requires the opposite.
Architecture built the other way around produces a different outcome. When a system is designed so that user inputs are never stored, never used to train the underlying model, and never accessible to the provider running it, there is no data sitting anywhere to subpoena, no training corpus that could expose a sensitive query, and no internal log waiting to be handed over in litigation. One tool built on that principle, Confidant, keeps user information with the user rather than the platform, which makes it a credible option for someone who needs real AI capability without taking on the surveillance exposure that comes with the public tools most people default to. No single product solves the whole problem, but the exposure described earlier in this piece is a design decision, and different decisions are already being made.
Institutions are starting to build matching infrastructure on the reporting side. The EU AI Office launched a whistleblower tool on November 24, 2025, built on the recognition that people professionally connected to AI model providers, current or former employees, contractors, and management, are often best positioned to catch a breach early, and that they need a way to report anonymously to act on that position. The tool's own documentation acknowledges a gap: as of August 2, 2026, some protections under the EU's Whistleblower Directive were not yet in effect, so the legal shield lagged behind the reporting channel built to use it. A separate effort, the AI Whistleblower Initiative, founded by Karl Koch with technical co-founder Maximilian Nebl, built a parallel system combining anonymous reporting outlets, legal assistance, and connections to journalists equipped to understand technical claims rather than flatten them. Taken together, these efforts show that secure infrastructure for disclosure is an active and growing field, built by multiple parties working from the same basic premise: that the architecture surrounding a disclosure matters as much as the courage it took to make it.
Legal protections for whistleblowers lagging behind the surveillance tools arrayed against them
Secure tools and careful personal practice can reduce a whistleblower's exposure, but neither one substitutes for a legal framework built to match the surveillance capability now arrayed against them, and that framework remains incomplete. The proposed bipartisan AI Whistleblower Protection Act would shield employees who report critical AI risks even when what they report falls short of clear illegality, closing a gap that has left many insiders unsure if speaking up carries any legal cover. Its passage remains uncertain, and reporting from May 2026 notes a structural imbalance working against it: frontier AI labs are accustomed to negotiating their own terms with regulators and bring substantial legal resources to that negotiating table, resources that individual whistleblowers and the advocacy groups supporting them typically cannot match.
That imbalance is the throughline connecting everything this piece has covered. Morocco's DGST, the ICE encounter in Minnesota, OpenAI's internal use of ChatGPT to trace a leak in minutes, the data-retention practices confirmed by the 2025 Stanford study: each shows a different face of the same underlying asymmetry, in which the party doing the watching has more technical capability than the party being watched has legal protection. Architecture built around privacy, and infrastructure like the EU AI Office's reporting tool or the AI Whistleblower Initiative, can narrow that gap, but only at the margins. Closing it will take legal protection that moves at the same pace as the surveillance and monitoring tools it is meant to check, and right now, the tools are moving faster.
Sources
- Whistleblower reveals how Morocco used a web of surveillance to silence journalists and activists
- Preparing for AI Whistleblowers
- 'Looks Like They're Firing Whistleblowers': Alarm as OpenAI Reportedly Ousts Safety Experts
- EU AI Office launches whistleblower tool to report AI Act breaches
- Morocco: Whistleblower Reveals How Authorities Used a Web of Surveillance to Silence Journalists and Activists
- “We start with the verdict”: Inside Morocco’s Surveillance Machine - Amnesty International Security Lab
- At Least 8 Americans Wrongfully Arrested by Facial Recognition AI


