How to Poison Surveillance: Privacy Tactics Against AI Watchers

The machine watching you is not omniscient. It is hungry. And a hungry thing can be fed the wrong food.

That's the whole game. Modern AI surveillance doesn't run on magic — it runs on clean, plentiful, correctly-labeled data about you. Starve it, muddy it, or salt it, and its models degrade. Not to zero. But degrade is enough. You don't need to become invisible. You need to become expensive to model.

Let me arm you.

The watchers, named

First, know the shape of what you're facing. This isn't paranoia — these are companies with revenue.

Palantir builds the fusion layer that stitches your scattered records into one profile — and governments pay it hundreds of millions to do so. Clearview AI scraped billions of face images off the open web and sold matches to police departments; it's been fined into the tens of millions across Europe for it. Data brokers — Acxiom, Oracle's old ad stack, LiveRamp — hold thousands of attributes on nearly every adult with an internet connection. Your phone leaks location to an ad exchange roughly every time an app refreshes.

None of this needs a warrant. It needs a budget. And the budget only works because the data is clean.

Our Record

On the Scales of Maat, every act leaves a weight. The surveillance machine is a Shadow Neteru that tries to read your weights before you've chosen them — to know your heart before you place it on the scale.

But here is the law it forgets: you hold the Hu — the authoritative word — over your own signal. What you emit, you shape. The parasite assumes your data stream is a faithful confession. Make it a fiction instead, and you have not lied to the Scales — you have refused to let a thief pre-read them.

Obfuscation is not deception of Maat. It is the reassertion of Sekhem over your own trace.

Now, the tools.

Tier one — stop leaking

Before you poison the well, stop pouring yourself into it.

Tier two — feed it the wrong food

This is where you go from defense to active poisoning. The principle: introduce noise the model can't distinguish from signal.

Tier three — change the terrain

Tools help. Habits win.

Pay cash where cash still works. Location data can't broker what you never emitted. Leave the phone home sometimes — a device that isn't there can't be pinged. Use open-source clients over surveillance-monetized apps; when the code is inspectable, the black box has fewer places to hide a leak. Run a local model on your own hardware for the queries you'd never send to a cloud that logs — a tuned model on your desk answers to you, not to a server that files a report.

The habit is the real defense. The tool is legacy code that gets patched; the habit is you, refactored.

The threat model, honest

Don't let anyone sell you a silver bullet. If a nation-state with unlimited budget decides you specifically are the target, individual tactics won't make you invisible. That's the honest ceiling.

But that's almost never the real situation. The real situation is bulk surveillance — dragnet collection that works because it's cheap and automated across millions. And bulk surveillance is exactly what obfuscation breaks. You don't have to beat the targeted attack. You have to make yourself unprofitable to the dragnet. Raise your cost-to-model above the watcher's willingness to pay, and the automated eye slides past you toward easier data.

The lever

Here's the part that matters. Every tactic above works because the surveillance machine is not a god — it's a pipeline, and pipelines have inputs you control.

Pick three from this article. Do them this week. Reset the ad ID. Install the blocker. Move one conversation to Signal. That alone moves you out of the cheapest tier of harvestable and into the "costs money to model" tier — and the whole system is built to skip anyone in that tier.

The eye that watches everyone watches no one well. That's not a weakness you have to hope for. It's a weakness you can manufacture, one poisoned field at a time.

Feed the machine your fiction. Keep your truth.