A guest post. Kyle Schneps is Director of Policy at DCG, where for five years he has advocated for digital assets, open-source AI, and privacy-preserving technologies. He is a former US diplomat and national security official. Follow him on X.
In 1989 much of your life was already on file. It just wasn’t in any one file.
Your deed sat in one county’s recorder office. The lawsuit from your twenties sat in a courthouse two states away. Your voter registration, your divorce, the news blurb about you from a local paper — each was a public record, open to anyone willing to track it down. But tracking it down was riddled with hurdles. Putting a person together from those pieces meant travel across geography, navigating bureaucracies, paying clerks and investigators, and asking questions of people disinclined to answer. The cost of infringing on an ordinary person’s privacy was so high that, outside the famous and the suspected, it was rarely paid.
Privacy was inherent in that cost. It wasn’t that your personal information was hidden and padlocked, but that reassembling it was prohibitively expensive. The Supreme Court even named this notion in 1989, in Department of Justice v. Reporters Committee, when journalists asked the FBI for the criminal record of a businessman tied to a corruption investigation. Much of his record was public but fragmented. The FBI refused to release its compiled version, and the Court agreed. Scattered across jurisdictions, the justices wrote, the information enjoyed a “practical obscurity.” Gathered into one file, it became something different, and the individual had a right to keep it that way. The facts were public. The compilation was not.
Practical obscurity never really entered the public discourse, though it describes the privacy most people experienced. Not secrecy. Not a right you had to assert. Just the reliable fact that analog data compilation was hardly ever worth the effort.
Notice, too, what practical obscurity asked of you: nothing. You never opted in. It covered the careful and the careless identically, because the burden of effort sat entirely with whoever wanted to know. Nearly every privacy protection built since inverts that concept. Cookie banners, privacy policies, opt-outs, broker removal requests — all exist only if you find and act on them, and they protect you precisely as far as you keep up. We replaced a protection that ran on its own with one that runs on your personal time and vigilance.
The first crack came with digitization. Records went online, and an industry grew up to compile them. By the mid-2000s anyone with twenty dollars could buy a profile from a people-search site, and Google would give you a rough one for free. But two obstacles remained. What twenty dollars bought was a pile — addresses, phone numbers, docket numbers — that took effort, judgment, and time to make legible. And the pile was thin: the old lawsuit, the local news item, the untagged photo on social media were still littered across sources most searches never reached.
AI erases these last vestiges of practical obscurity. A model with search tools reads the deed, the docket, the old news item, and the photographs. It returns not a pile but a biography: where you have lived and with whom, what you were sued over, what all of it seems to mean. It does this in minutes, even unattended, for anyone. The inversion is now complete: assembling you costs nothing, and staying unassembled is your job alone. The biography is also often partly wrong, which is its own harm — you cannot correct a file you never see.
The facts were always there. What changed is who can afford to assemble them. A few large institutions — agencies, insurers, data brokers — could always pay, and they did it quietly, out of sight, answerable to no one in particular. People tolerated that less because it was acceptable than because whoever held the file was a faceless entity, easy to wave away. AI makes those institutions more capable still. But the new thing is everyone else. What practical obscurity actually kept at bay was anyone with a personal reason to look — the landlord choosing between applicants, the ex you moved away from, the scammer who needs a convincing story — and it kept them at bay because looking was hard work. Now looking is so easy it’s no work at all.
This is not a case for going back to 1989, or for AI doomerism. Practical obscurity was an accident of bureaucracy and circumstance; it hid the slumlord from his tenants as readily as it hid you from a bad actor. AI simply removed a friction that happened to be doing an important job. That job — protecting people who do nothing to protect themselves — now needs an architecture of its own.
For the public record, the question is a legal one and for another essay. But a large share of our exposure is not the public record. It is the documents we are needlessly required to surrender whole — the license, the tax return, the passport — to prove a single fact. Here the answer is technical, and it deserves a name. Practical obscurity made your file expensive to assemble. Engineered obscurity makes it impossible to assemble, unless you decide otherwise.
To see what that means, start with the problem it solves. A convenience store scans your license — name, address, birthdate, document number — to learn that you are over twenty-one. New age-verification laws make websites do the same, and the websites keep a copy. A lender takes the full tax return to confirm that income clears a threshold. An exchange takes your passport to confirm you are not on a sanctions list. Each answers a yes-or-no question by surrendering the entire document. Why? Because we digitized the data but kept the analog procedures.
The procedures can change now. Thanks to cryptographic innovations, new data architectures are deployed, not proposed. Zero-knowledge payment systems have been doing this since 2016. An ordinary payment network keeps a permanent record of who you are, where you were, what you bought, and from whom — all to confirm one thing: that the money is real and has not already been spent. A zero-knowledge system automatically allows the payer to attach a proof of exactly that, and the network checks the proof and moves on, without storing vulnerable data on the sender, the recipient, or the amount. Identity is following. A mobile driver’s license can already release a signed “over 21” and nothing else, and it is live in Apple’s wallet for apps and websites; Google went a step further last year, shipping a proof that reveals no field at all — only that the signed birthdate clears the line — and handed to the Linux Foundation this month. Statistics have made the same turn. The 2020 Census published its tables with calibrated noise, so that no individual can be reconstructed from the counts, and a UN pilot now lets national statistics offices compute joint results across borders without any of them seeing another’s raw records. Finance is waiting on regulators, but the shape of the solution is the same in every case: confirmation without compilation. The question gets answered, the data never changes hands, and there is little left to assemble, steal, or sell.
The privacy check-box and the opt-out were never real substitutes for obscurity. They hand the file over, ask the recipient to promise, and leave the difficult work of self-protection to ordinary people, indefinitely. Privacy technology puts the burden back where practical obscurity kept it: on whoever wants to know. Whoever asks gets only what they actually need, and nothing more. The analog world gave us practical obscurity by accident. We can give ourselves engineered obscurity on purpose.
As we edited this, a relevant paper came out. Practical obscurity is dead:
For more on the potential zero-knowledge tech has to limit the sensitive data we leak just to use the internet, see this recent post from Peter.
What else we’re reading
If you found this interesting, please consider sharing and subscribing. It helps us grow.
We’re officially open to guest posts. Get in touch if you have something to say.














