Who Is Watching You Right Now, and What Are They Doing With It?

From supermarket cameras to workplace keystroke logs, surveillance of ordinary people has quietly become a growth industry. AI is making it faster, cheaper, and harder to spot.

ThreatVectr Newsdesk· 4 min read
An AI scanning software code for vulnerabilities
Share

Key points

  • Perplexity's browser, Comet, launched in July 2025 and is designed to collect data on everything users do outside the app in order to sell targeted advertising.
  • A major UK supermarket chain plans to add facial recognition cameras across 150 more stores before the end of 2025.
  • The US has no single federal law banning facial recognition or workplace mood monitoring, leaving employees with little practical protection.
  • Cookies, the small tracking files websites place on your device, can number more than 50 per site and quietly build a detailed profile of your interests.
  • AI is being applied to surveillance by companies, governments, and criminals alike, making the collected data more actionable than ever.

Somebody is almost certainly watching what you do online right now. Probably more than one somebody. The unsettling part is not that this happens; most people have a vague sense of it. The unsettling part is how many different groups are doing it, for how many different reasons, and how little any of us can do about it without help.

A survey of the surveillance landscape, drawn partly from SecurityWeek's own reporting, finds four broad categories of watcher: companies trying to sell you things, employers keeping tabs on staff, governments and intelligence services, and outright criminals. All four groups are now using artificial intelligence, meaning software that can spot patterns in huge amounts of data far faster than any human team, to do it better.

What are companies doing with your data?

Vendors track you to sell you things. That is the blunt version.

Perplexity, the AI search startup, launched a browser called Comet in July 2025. Its stated purpose is to watch what users do across the whole web, not just inside the Perplexity app, so the company can serve more precisely targeted adverts. Chief executive Aravind Srinivas has argued users will appreciate ads that match their actual interests. David Ruiz, senior privacy advocate at security firm Malwarebytes, is less relaxed: "I worry about AI-powered mental health apps and emotional support chatbots that seemingly require users to divulge sensitive information to function."

Supermarkets are moving in a similar direction in the physical world. A major UK chain plans to install facial recognition cameras, cameras that identify specific individuals by mapping their face, across 150 additional stores before Christmas 2025. Rebecca Moody, head of data research at comparison site Comparitech, flags the risk of "mission creep": a system sold as a shoplifting deterrent could easily be repurposed to track buying habits once it is installed.

Then there are cookies. A cookie is a small file a website places on your device to remember you and log your behaviour. A single site may try to place 50 or more cookies on your machine. Regulations in many countries require sites to let you refuse non-essential ones, but the consent screens are frequently designed to make refusal slow and confusing enough that most people simply give up and click accept.

Are employers watching too?

Yes, and increasingly so.

Ensar Seker, chief information security officer at threat-intelligence firm SOCRadar, describes the modern monitored workplace: login times, building-access logs, app activity, and collaboration-platform messages are already standard. AI now layers on top of that, adding keystroke tracking, webcam checks, meeting-participation scores, and software that tries to predict which employees might quit or pose an insider risk.

"Some of these tools improve security," Seker says. "Others cross into invasive surveillance by attempting to infer emotions, motivation, or trustworthiness from imperfect data."

Consent forms in employment contracts offer workers little real protection. Stanislav Kazanov, head of governance and risk at technology consultancy Innowise, puts it plainly: "An employee can technically refuse monitoring. In practice, refusal may mean losing the job or never getting hired. That is paperwork under pressure, not real choice."

In the US, no single federal law prohibits this kind of monitoring. The Electronic Communications Privacy Act, a 1986 law designed to protect private messages from interception, contains a broad business-purpose exception and a consent exception that employers routinely bake into contracts from day one.

What should ordinary people actually do?

A few practical steps cost nothing.

Use a browser that blocks third-party cookies by default; Firefox and Brave both do this out of the box. Read cookie consent screens carefully and choose "reject all" where the option exists; it usually does, just buried. If your employer asks you to install monitoring software on a personal device, ask in writing exactly what it records. And treat any app asking for unusually personal information, especially mental-health or emotion-tracking apps, with real scepticism about what happens to that data.

Regulation is the longer-term lever. The EU's approach, banning facial recognition in public spaces and emotion monitoring at work, gives a rough template for what stronger rules can look like. Whether other jurisdictions follow is a policy question, not a technical one. Awareness, at least, is free.

© 2026 Threat Vectr