Can AI Really Figure Out Your Religion, Health, and Gun Ownership?
You never told anyone at your yoga studio that you go to church. You never filled out a form listing your prescriptions, your gun purchase, or the fact that you visit a clinic across town every few weeks. And yet a laptop in a Capitol Hill briefing room can put all of that on one screen in about the time it takes to read this sentence.
That's not a hypothetical. Since April, a nonprofit called CivAI has been running a demo for congressional staffers — four Republican offices, eight Democratic ones, twelve in all. A researcher types a name into a plain box labeled "AI Data Broker Search." Seconds later the screen fills with a stranger's church attendance, their commute, their leaked passwords, the stores they shop at, and their home address. One sample prompt the tool was built to answer: "Find church-going Christians in Janesville, Wisconsin. Write a detailed dossier on one."
The whole thing cost about $500 a month to run — less than a gym membership most people forget they're paying for. CivAI put it together in roughly two weeks.
The trick isn't hacking. It's guessing.
Here's the part worth understanding, because it's where the fear and the facts drift apart. The AI didn't break into anything. It didn't read your mind. It did something more ordinary and, honestly, more unsettling: it connected dots you didn't know were sitting out in the open.
This is called inference. On their own, the dots look harmless. A fitness app knows you took a yoga class. A grocery loyalty card knows what you buy. Your phone's location history knows you're in the same building every Sunday morning. A data breach from years ago left your old password floating in a database someone can buy. None of those facts says anything private by itself.
But stack them together and a machine can make a confident guess: this person is probably religious, probably has this health condition, probably owns a gun. You never said any of it. The AI inferred it — the way you might guess someone's a new parent from the car seat, the coffee, and the exhausted face, except it's doing it to millions of people at once, from data that companies quietly buy and sell.
Where the data actually comes from
The uncomfortable truth is that most of this was never secret to begin with. Data brokers have sold information on people's travels, shopping, subscriptions, and employment for years. What changed is the assembly line. Pulling all of it into a single profile used to take a person hours of digging. Now a program does it in seconds, for anyone with a phone.
The demo went further than a profile. Every dossier ended with a section CivAI called "potential vulnerabilities to exploit" — essentially a how-to for blackmail, stalking, or harassment, based on your routines and reused passwords. That's what got a room full of lawmakers who rarely agree on anything nodding in the same direction. One Republican staffer said the country's privacy protections "have not kept pace with modern technology." A House committee chair called an AI-assembled list of gun owners a "de facto gun registry."
It's powerful — but it's not magic
Now the part the scary headlines leave out. When CivAI ran the tool on a real person — a Politico reporter — it correctly figured out he likes spicy food and the video game Super Smash Bros. It also got his address, his age, and his job wrong. The group blamed the cheap data it was buying, and better data would sharpen the picture. But that's not the whole story. The AI stitching those dots together is the same kind of technology that confidently invents fake court cases and made-up quotes. When it isn't sure, it doesn't leave a blank — it guesses, and it says the guess with a straight face. So you get two layers of error stacked on top of each other: shaky data going in, and a machine prone to filling gaps with fiction coming out.
That matters for how you should feel about this. Inference is a confident guesser, not an all-knowing oracle. It's right often enough to be dangerous and wrong often enough to smear the wrong people. A profile that decides you're a health risk or a flight risk based on a bad guess — or a flat-out invented one — can cost you a loan, a job, or an insurance rate, and you'd never even know a machine made the call.
What you can actually do
You can't claw back data that's already been collected and sold. Anyone who promises you a clean slate is selling something. But you can shrink what gets added tomorrow, and that's worth doing.
Turn off location sharing for apps that don't need it — most don't. On your phone, set location to "while using" instead of "always." Turn off ad personalization in your Google, Apple, and social media settings. Use a password manager so a single old breach doesn't unlock ten of your accounts. And spend twenty minutes filing opt-out requests with the big data brokers; searching a broker's name plus "opt out" usually gets you to the form.
Be honest with yourself about that last one, though: opting out is whack-a-mole. Brokers pull from public records and re-list you months later, so it's a chore you have to repeat, not a one-time fix. That's not a reason to skip it — it still shrinks your footprint — but it's why the people in that Capitol Hill room kept circling back to the same conclusion. The only real fix is a law that stops the buying and selling in the first place. Until that exists, the burden sits on you.
None of this makes you invisible. It just makes you a harder, more expensive target — and for most people, most of the time, that's the whole game.
One last thing, since we build free learning tools and we're the kind of nonprofit that doesn't sell your data: the goal here isn't to scare you off technology. It's the opposite. The people most at risk are the ones who don't know this is happening. Now you do — and knowing how the guessing works is the first thing that makes it less powerful.