Overregulation often leads to circumvention. This is a broad concern surrounding privacy minimums in the United States. If we continue to raise privacy standards, the worry is that companies that depend on data extraction will become more aggressive, invasive, and creative in their collection methods.
This was largely the case when data aggregators and the advertising industry realized cookies were an easy signal to reject, and they began investing heavily in browser fingerprinting technology. This puts a sort of glass ceiling on privacy in which people relinquish it because they're led to believe privacy is only for criminals, dissidents, and bots.
While this concern is real, a recent conversation followed by an ICE RFI describing this omniscient AI interface made it clear that governments are increasingly encouraging, incentivizing, and in some cases requiring high-quality identity data to be collected and pushed into the ad-tech pipeline.
ICE's ask
At the beginning of August, Immigration and Customs Enforcement (ICE) published a Request for Information (RFI) for a "Telecommunications Analysis System" with a myriad of capabilities.
ICE and Homeland Security want a centralized platform that can "support thousands of [government] users, analyze massive datasets (up to 10 TB), and intercept GPS data," among other things.

The system they want is able to ingest and analyze data from...
- Phone providers
- Call detail records
- Cell tower location data
- GPS locations
- Web browsing history
- Financial informations
- Social media records
Placing this otherwise siloed information into an environment where it can be normalized, searched, mapped, compared, and analyzed together. The proposed system allows investigators to use ordinary language to search this data without knowledge of the database or forensic experience.

Historically, the usefulness of enormous datasets were limited by the cost of analysis. An analyst needed to know which database might contain a record, how to find specific identifiers, and how to export the data into something useful. While compute and training costs are not to be scoffed at, the manpower limitation has largely been lifted.
Mandated identifiers
KYC requirements, age verification laws, identity checks, account verification, SIM-registration policies, digital credentials, and child-safety laws are all regulations aimed at different purposes. Yet, they all put pressure on institutions to connect user-activity with some sort of persistent identifier.
While these systems have legitimate use-cases in fraud prevention, adult-content gating, and banking security, it would be remiss to ignore the real harms this long term behavior correlation can cause. If a bank or institution has a verifiable reason to confirm my identity, it should also be their responsibility to ensure that record cannot then be used to connect unrelated transactions, behaviors, and accounts across the economy.
As a society, we are steadily designing anonymity and privacy out of the digital citizenship experience by building government and commercial systems that depend on the abundance and availability of identity records. The retention and AI-ification of this information allows records that are created for safety to be used for investigative or prosecutorial purposes later.
Parallel government programs
This, all while a separate ICE contract is in the procurement pipeline.
What was originally going to be awarded to Thomson Reuters Special Services, has been opened up for competition.
This contract, deleted from the original posting on SAM.gov, outlines DHS's $125 million need for screening, vetting, lead development, criminal analysis, anomaly extraction, automated monitoring, relationship mapping, and identification of potentially criminal or fraudulent behavior before it occurs.

These two systems point in the same direction. The TAS RFI would reduce the labor required to search and correlate billions of communications, location, financial, social, and forensic records. This separate analytical-support contract seeks the personnel and capabilities needed to screen people, develop leads, monitor entities, extract anomalies, map relationships, and identify potentially criminal behavior before it occurs.
Whether these systems ever connect technically is almost beside the point. They rely on the fact that enough information has been collected, retained, and associated with persistent identities to make large-scale correlation possible.
The answer is not to abandon privacy standards or leave the data market unregulated. It is to stop treating identification as the default solution to every regulatory problem. An institution should be able to verify that I am over 18 without learning my identity. It should be able to verify that I am eligible for a service without creating a permanent identifier capable of following me across unrelated systems.
Instead, we are requiring more identifying information upstream while purchasing increasingly powerful systems to correlate it downstream. Whether this is intentional or if its currently being used for malicious purposes is irrelevant, the infrastructure and the capability is there and here to stay.