Will AI be used to watch us?

The fear, stated fairly

Cameras, phones, payment cards and online accounts already generate a constant stream of data about where we go and what we do. Until recently, making sense of all that data took a lot of human effort. AI changes that. Faces, voices, number plates and messages can now be sorted and searched automatically. The worry is that this makes it easy for companies to profile us, for criminals to exploit us, and for authorities anywhere to monitor people in ways that chill free expression.

This is not an imaginary concern. Anthropic's CEO, Dario Amodei, who is generally optimistic about AI, has written that "AI seems likely to enable much better propaganda and surveillance" (Amodei, Oct 2024). More than half of the 2,778 AI researchers in the largest survey of the field said that authoritarian rulers using AI to control their populations deserved substantial or extreme concern (Grace et al., JAIR, 2025).

What the evidence says

  • The risk exists, around the world. Investigative reporting has documented the misuse of surveillance technology against journalists and activists in many countries, including in the Middle East.
  • Scams and fraud are the most common everyday harm. The International AI Safety Report 2026 lists scams, deepfakes and manipulation among the main current harms of AI (executive summary). For most people, the most likely privacy harm is fraud, not state monitoring.
  • Data is valuable, and it is regulated. The same data that can be misused also powers services people value, such as the health programmes described on our everyday life page. The question is not whether data is used, but under what rules.

What is genuinely risky

  • Function creep. Data collected for one purpose, such as traffic or health, can later be used for another.
  • Weak enforcement. A law on paper protects no one if it isn't applied, or if people don't know their rights.
  • Security breaches. Large databases attract attackers. Health and genetic data are especially sensitive.

Why there is hope, and what is being done

Data-protection laws now exist across the region.

  • Saudi Arabia's Personal Data Protection Law came into force on 14 September 2023, with full enforcement from 14 September 2024. It gives people rights over their personal data and allows fines of up to SAR 5 million for serious breaches (SDAIA guide).
  • The UAE's Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) sets out rules for how personal data may be processed (UAE Legislation).
  • The UAE Charter for the Development and Use of AI (2024) lists privacy, transparency and accountability among its 12 principles (UAE Government portal).
  • Bahrain's government AI policy (July 2025) includes compliance and awareness among its four pillars, and adopts the GCC Guiding Manual on the Ethics of AI Use.

Technology can protect as well as expose. Privacy-by-design approaches, such as keeping data in the country, limiting who can access it, and anonymising it for research, are increasingly standard. Open standards such as Content Credentials (C2PA) are designed so that provenance records "respect user privacy" and do not require the creator's identity (C2PA explainer).

Researchers are paying attention. The International AI Safety Report treats privacy and manipulation as core issues, and independent journalism continues to hold powerful actors to account.

What you can do

  1. Know your rights. If you live in Saudi Arabia or the UAE, data-protection laws give you rights over your personal data. Ask organisations what they collect and why.
  2. Protect yourself from the most common harm, which is fraud. Be cautious with unexpected calls, voice notes or videos asking for money, even if they seem to come from someone you know.
  3. Share sensitive data deliberately. Health, genetic and location data deserve extra care.
  4. Support transparency. Public bodies and companies that explain how they use AI deserve trust. Those that won't explain deserve questions.