Back to News
Cybersecurity

Reassessing 25 Years of Mass Surveillance: Implications for Cybersecurity and AI

An analysis of the implications of mass surveillance practices over the last 25 years for cybersecurity and AI.

The article co-authored by Bruce Schneier and Cindy Cohn highlights the significant evolution of surveillance practices in the United States post-9/11, transitioning from targeted surveillance to pervasive mass surveillance techniques. Initially justified as a necessary measure for national security, these practices have expanded to encompass a range of law enforcement activities, raising ethical and legal concerns about privacy and civil liberties. The authors argue that the infrastructure supporting mass surveillance has become a routine tool, effectively normalizing invasive monitoring of citizens without adequate oversight or accountability.

For businesses, particularly those in the tech and cybersecurity sectors, this shift necessitates a reevaluation of data privacy policies and practices. Organizations must navigate the complexities of compliance with existing surveillance laws while also protecting customer data from potential misuse by governmental agencies. Moreover, as AI technologies increasingly rely on large datasets for training, the implications of mass surveillance on data integrity and ethical AI practices become ever more pertinent. This ongoing dialogue about surveillance practices not only impacts legal frameworks but also influences public trust in technology and its intersection with civil rights, underscoring the need for a balanced approach to security and privacy in the digital age.

---

*Originally reported by [Schneier on Security](https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html)*