Part 1 of 5 | The Five Eyes Series
This investigation documents:
The United States wants five years of your social media, every email address you’ve used in ten years, and your family’s names, birth dates and addresses before you can visit on a holiday. In Australia, police and government agencies accessed metadata without a warrant nearly 365,000 times in the latest year, and a parliamentary committee found more than 80 other bodies, the RSPCA among them, getting in through a loophole. Behind both sits an intelligence alliance between the US, the UK, Australia, Canada and New Zealand, created in 1946 and kept classified for 64 years, that no pollster in any of the five countries appears to have ever asked people whether they know it exists. This is Part 1 of 5.
EDITORIAL NOTE: The following document presents investigative analysis and opinion commentary. Rhetorical devices and narrative framing are used to present the author’s interpretation of publicly documented events, laws and relationships. This is journalism, not a court filing. The genre is cartography, not verdict. All named individuals are public figures and all claims are drawn from publicly available sources, which are cited throughout. I’ve switched off AI detection on my work. You can read why, and how I really make it, here.
OPENING
Last December, I was having my morning coffee and scrolling through the news on my phone the way I do every other morning, wondering why I continue to do this while I continue to read it, always scanning the headlines and waiting for another American bombshell to spin my head around. And of course, there it was. The Trump administration had announced that visitors to the United States would be required to hand over five years of their social media history just to be allowed into the country, submitted to US Customs and Border Protection before you’d even boarded a plane.
I thought that’s insane.
And then the thought that actually stuck with me was, would I even want to go there now? God, I would not want to go to America if that’s going to happen. I started to wonder whether I’m the kind of person whose social media history would generate a second look and a longer conversation in a small room at the airport, and that’s when it got even more crazy, because I’m doing nothing wrong. Why am I even thinking about this? The idea of five years of my online life sitting on a screen in front of a border agent who gets to decide what it means without any of the context was enough to make me not want to go.
And it’s not that I don’t like America. I’ve been there before and I had the most amazing time. The people are some of the friendliest I’ve met anywhere, the architecture, the history, the sheer scale of the place. I loved it. This isn’t about not liking America, it’s about what I found behind the systems that process you before you get there, and what those systems are connected to, and the fact that most of us have no idea how deep it goes.
And then I wondered how many other people across the world were thinking the same thing, and millions of them were. Four million fewer foreign visitors came to the United States in 2025 compared to the year before, with total spending down more than eight billion dollars. The US was the only major tourism destination on earth to see a decline that year, the first real drop since the pandemic, and this time it wasn’t a virus or an economic collapse. Canadian visitors dropped by a quarter, seven million fewer trips in a single year. The head of the US Travel Association told Congress the country was losing its status as a top global tourist destination. And all through that year, stories had been coming through that made it feel less like policy and more like a warning. Journalists turned away at the border, people selected and refused entry for reasons that were never explained. Some of it had been going on for years, students flagged and removed, travellers detained for what they’d posted online, but the numbers were climbing and the media was picking them up and I started to wonder whether this is where it’s all heading.
I sat on it for a while, but it’s been stuck in my head ever since, and about a month ago I started looking into it properly.
The programme that would process all of this is called ESTA, the Electronic System for Travel Authorization, and I’d heard the term before but never thought about it much, and most travellers haven’t either. The mandatory social media requirement isn’t actually in effect yet for tourists, though applicants for visas, students, workers, and immigrants have been required to hand over their social media since 2019, and the proposal would extend it to everyone. Since then the travel industry has pushed back hard and Customs and Border Protection has started talking about a tiered version where most people wouldn’t be asked at all, but as I write this the proposal is still on the table and nobody has withdrawn it. But when I looked at what the proposed changes actually included, it wasn’t just social media. The same notice covered every email address you’ve used in the last ten years, and the names, birth dates, residences, and birthplaces of your parents, your siblings, your children, and your spouse. They weren’t asking to see your posts, they were asking you to map your entire family before you were allowed to visit. And my first thought was, why would they need that? You’re just a person going on a holiday. They’ve never needed it before. What’s changed? And the first thing I thought was data.
When I started digging deeper, I found that Australia already had something very similar in place. It wasn’t the social media screening specifically, it was the infrastructure behind it, metadata retention laws that let police and government agencies access your call records, your internet session data, and your location without a warrant. There were nearly 365,000 authorisations in the latest year, the highest since the current laws came in, and the number has gone up in five of the last six years. And that figure only counts the 21 agencies the law was written for. A parliamentary committee found more than 80 other bodies had been getting in through a loophole in a different act, and they included local councils, the RSPCA, which is an animal welfare charity, racing integrity boards, and taxi regulators.
That was when a name came back to me that I hadn’t thought about in years. Five Eyes. I remember it being quite big in the news many, many years ago, around the Snowden period in 2013, when it had briefly been everywhere and then disappeared from the conversation almost as quickly as it had arrived. It’s an intelligence alliance between five countries, the United States, the United Kingdom, Australia, Canada, and New Zealand. I remembered the general shape of it but nothing specific, and I remembered thinking at the time that it sounded like it mattered, and then it fading the way things do when nobody keeps pushing.
If you’ve read any of my previous work you’ll know this is where my brain starts firing a thousand things a second, when things from completely different places start connecting into something bigger than any of them looked on their own.
So I started digging, and it kept going. What started as me thinking about whether I’d even want to travel to the United States turned into something that blew my mind wide open, because the more I looked the more I realised nobody was talking about this the way I was seeing it, as one connected architecture that has been running for 80 years, rather than as separate stories about privacy or border policy or AI or encryption, and I couldn’t find anyone who had put it all together in one place.
The alliance was created in 1946 and the agreement behind it stayed classified for 64 years, until the full text was finally released in 2010, and in the 16 years since, I couldn’t find a single polling organisation in any of the five countries that has asked whether citizens even know it exists.
A Canadian federal court judge confirmed, not as a theory but in a ruling based on the evidence in front of him, that his own country’s spy agency had asked its Five Eyes partners to collect on Canadian citizens it couldn’t lawfully collect on itself, and had kept the court in the dark about it. The Australian Prime Minister, the elected leader of his own nation, wasn’t even told his country was a member until 1973, when he had to demand the information.
And if the first place your mind goes is terrorism, I understand, because it was the first place mine went too. Terrorism is real, and governments need tools to deal with genuine threats, but the infrastructure that was built under that justification has expanded so far beyond terrorism that the word has become a door governments open whenever they need the public to stop asking questions. When the RSPCA has been accessing your metadata, that is not about terrorism. The government promised in 2023 to close that loophole, and as far as I can find it still hasn’t.
So is this a conspiracy theory? No, it’s an architecture, documented and sourced, and it’s running right now on the phone in your hand. This is the first part of a five-part series, and each part can be read on its own or as part of the whole picture.
I think once you see it assembled, you won’t look at your phone, your passport, or your next AI conversation quite the same way.
So grab a coffee and get comfortable. Actually, maybe grab something stronger. You’re going to need it.
BEFORE YOU LAND
So you’ve booked the trip. Maybe you’ve been saving for two years and you’re finally taking the kids to Disneyland, or it’s a conference in San Francisco your company is sending you to, or your best mate is getting married in New York and you wouldn’t miss it for the world. Maybe you’ve landed a new job and you’re moving your whole life to the other side of the world. Maybe you just want to see the Grand Canyon because you’ve always wanted to see the Grand Canyon and you finally have the time. Whatever the reason, you’re going to America, and the first thing you need to do is fill out a form on your phone.
The form is called ESTA (Electronic System for Travel Authorization), and if you’ve travelled to the US before you probably remember it as a quick online thing you did the night before your flight, passport number, employment details, a few yes-or-no questions about whether you’ve ever been arrested or involved in espionage, the kind of questions that make you laugh because the answer is so obviously no. It took ten minutes and you forgot about it before you finished your coffee, and that was then.
The proposed version asks for five years of your social media, ten years of email addresses, and the names, birth dates, birthplaces, and residences of your parents, your siblings, your children, and your spouse. It wants a selfie taken through a mandatory mobile app that runs liveness detection software to confirm you’re a real person holding a real phone in real time. And why mobile only? Because a phone gives them things a laptop never could, your geolocation when you apply, your device identifiers, and access to a camera that can verify you’re physically holding the device. CBP (Customs and Border Protection) says it will decommission the website entirely, and once it does, the app is the only way in.
Fourteen and a half million people go through this process every year, and the top countries are the United Kingdom, France, Germany, Japan, and South Korea, and those are allies, not enemies.
What you may not know is that this isn’t entirely new. If you’re a student, an immigrant, or a worker, handing over your social media has already been mandatory since 2019. Millions of people have already been through this, for seven years. The proposal just extends it to everyone.
By the time you put your phone down, your application is already passing through the National Targeting Center, where an automated system called the Automated Targeting System scours your social media for anything it classifies as “derogatory.” Nobody outside DHS (the Department of Homeland Security, which CBP sits inside) can tell you exactly what that word means. There’s no published list of what triggers the flag. You can’t see your own profile and you can’t challenge the classification. And documents obtained through freedom of information requests revealed that government officials acknowledged in 2021 that the social media screening requirement added “no value” and had “very little impact on improving the screening accuracy,” and they kept it anyway.
A tool called Babel Street, which has received over USD $21 million in government contracts since 2015, compiles your online presence for the officers deciding whether you need further screening. More than 200 artificial intelligence tools are now active across DHS, up by more than a third in six months, and 83 of them sit inside CBP, the border agency, alone. A facial recognition app called Mobile Fortify has been in the hands of CBP and ICE (Immigration and Customs Enforcement) officers since May 2025.
When you land, a camera captures your face. This part isn’t proposed, it’s already happening. Since December 2025, every noncitizen entering the United States can be required to have their facial biometrics taken at the gate. You’d expect some level of security at a border, and most people wouldn’t think twice about having their photo taken at passport control. But the exemptions that used to exist for diplomats, most Canadians, children under 14, and adults over 79 have been removed, so nobody is exempt from the face scan anymore. And the system isn’t limited to your face. It’s authorised to collect your fingerprints, your iris scan, your voice print, and your DNA. Your photograph can be stored for up to 75 years. If you’re 25 and you visit this year, your biometric data could still be in that system when you’re 100. And if you’re British, Australian or a New Zealander, the ask doesn’t stop at the gate, because the US has told every country in the visa waiver programme, the scheme your ESTA belongs to, that it wants agreements in place by the end of 2026 giving it access to their own national biometric databases, and after that date it will weigh whether they keep visa-free travel. Britain’s Home Office says the US wants to check the fingerprints of British people applying for a US visa against Britain’s own criminal fingerprint records, and as of May it said negotiations weren’t underway, although a European MP had said earlier that Britain had already signed up to share police fingerprint records with US border officials, which the Home Office has never directly confirmed. Australian government briefings released under freedom of information confirm the request was made to Australia too, and in February Crikey reported that Australia had agreed to give US agencies, ICE among them, direct access to Australians’ biometric data. The Albanese government only admitted it was even talking about it in May, when Greens Senator David Shoebridge pushed Home Affairs in Senate Estimates and an official told him the US is “seeking real-time access to biometric data, criminal history data of travellers who are Australian citizens travelling to the US.” The department’s written answer says the government “has not made any commitments” yet, so nothing’s signed, but it’s on the table with a deadline at the end of this year, and we only know because a senator kept asking and Crikey kept filing FOIs.
If you live in one of the five countries that make up the Five Eyes intelligence alliance, the United States, the United Kingdom, Australia, Canada, or New Zealand, you might be thinking this is an American problem at an American border, and it isn’t.
Australia has signed a CLOUD Act agreement with the United States, giving both governments the power to demand data directly from providers across borders. Australia’s own metadata laws already let police and government agencies get at your call records and your location without a warrant, hundreds of thousands of times a year. And Australia is a founding member of a programme called Migration 5, where all five countries share biometric and immigration data with each other.
That programme started as a way to check asylum seekers’ fingerprints, and at 3,000 checks a year that’s the kind of thing most people would find completely reasonable. But it didn’t stay there. The agreements now allow each country to run up to 400,000 checks a year against each of its partners, eight million across the five, and it covers any traveller, visitor, or migrant. The countries don’t just share data on criminals or suspected terrorists. They keep biometrics on ordinary travellers and let partner nations access them on a match, and the partners don’t need a reason to look. New Zealand retains that data for 50 years. The United States keeps it for 75.
So when your face gets scanned at Los Angeles or Heathrow or Auckland, it’s checked against all five countries, and they hold it for longer than most people live.
And in February 2026 CBP, the agency that processes your ESTA, screens your social media, and scans your face at the gate, signed a contract with a company called Clearview AI and put it inside the National Targeting Center, the same unit that runs the screening. Clearview built its database by scraping images from the public internet, more than 60 billion of them by CBP’s own count this year. Canada’s Privacy Commissioner called it mass surveillance and illegal, and found the Royal Canadian Mounted Police had used it 521 times while initially admitting to only 78 and being unable to account for 85 percent of the searches. Australia’s Privacy Commissioner found it breached the Privacy Act. The UK’s Information Commissioner fined the company GBP 7.5 million, a fine Clearview has fought through two tribunals since and which still isn’t settled. New Zealand police ran an unauthorised trial without telling the Privacy Commissioner, the Police Commissioner, or the Cabinet. New Zealand’s police have since ruled out live face-scanning except in rare emergencies, on the grounds that the risks outweigh the benefits. They aren’t completely alone, since Canada’s national police have a written rule against facial recognition on their body cameras, Detroit’s police are barred by their own directive from running it on live video, New York’s police say in their own policy that they don’t do it in real time, and around two dozen American cities banned police face recognition altogether, although that wave stalled years ago and some of those bans have been partly rolled back. Scotland said no in 2020 and is now building a business case for it, and in New Zealand the supermarkets simply got there first, scanning more than 225 million faces in a single trial.
Every Five Eyes country has had a confrontation with this tool. And in September 2025, US Immigration and Customs Enforcement signed a USD $9.2 million contract with Clearview, the largest federal deal the company had ever received. Two months before that, US Marshals had arrested a Tennessee grandmother on a Clearview match for a bank fraud in a state she’d never set foot in. She spent six months in jail before her bank records got her out.
Clearview’s early backing came from Peter Thiel, the German-born US and New Zealand citizen whose investment network connects to Palantir, to Meta, and to the infrastructure this architecture runs on. I’ll come back to Thiel later in the series, but it matters here because the company now sitting inside the unit that screens you was backed by a man who holds citizenship in two Five Eyes countries and whose companies are embedded in the surveillance systems of all five.
And I kept thinking about the places you’d never holiday in, because surely they must be worse. So I looked. North Korea, back when it was open, which it barely is now, put two government minders on you from the moment you landed, kept your passport until you left, and went through your phone and camera on the way in and the way out looking for anything religious or political. China takes ten fingerprints and a photo of your face from almost every foreigner at the gate and has done since 2017. Russia started doing the same last year, and if you’re coming in without a visa you register in a government app three days ahead with your passport, your reason for coming and a selfie. And they are worse once you’re inside, in every way that matters, with no courts worth the name and the real chance of being kept as a bargaining chip. But what happens before you get there? None of them ask for five years of your social media, and none of them ask for your family’s phone numbers. America has asked every visa applicant for every account they’ve used in the last five years since 2019, on a form you sign as true, and the new proposal extends that to the rest of us and adds our families to it. In the year to September 2025, American border officers searched 55,318 phones, laptops and other devices, a record, and 50,922 of those searches needed no suspicion of anything at all, and 13,590 of them belonged to Americans. Canada’s border agency searched 1,108 in 2024. North Korea gives your passport back at the border, and America keeps your face until you’re a hundred.
So you booked a holiday, and by the time you walked out of arrivals your social media had been screened by a machine using rules nobody will show you, your family had been mapped, and your face was in a database shared by five countries. Who decided that’s what a holiday costs now?
And it isn’t new either, because what you just walked into has been running for nearly 80 years, and nobody ever voted for it.
THE MACHINE THAT WAS ALREADY RUNNING
Sounds like something out of the Trump era, or the post-9/11 security state, or the smartphone age, doesn’t it? It isn’t. It started with a room full of codebreakers during a world war, and it’s been running ever since.
In February 1941, before the United States had even entered the war, a small group of American cryptanalysts arrived at Bletchley Park in England for a series of secret meetings with their British counterparts. The head of Bletchley, Alastair Denniston, recorded their arrival in his diary with a single line: “The Ys are coming.” No names, just a letter, and that’s how secret it was from day one, before most of the world knew there was a partnership to keep secret.
By 1943 the cooperation had been formalised into the BRUSA Agreement, covering the sharing of signals intelligence between the US War Department and Britain’s Government Code and Cypher School. When the war ended, the question became whether to continue. On 12 September 1945, President Truman agreed in principle to post-war cooperation. Six months later, on 5 March 1946, the UKUSA Agreement was signed, Colonel Patrick Marr-Johnson for the British side and Lieutenant General Hoyt Vandenberg for the Americans. It wasn’t announced or debated in any parliament or congress, it was classified from the moment it was signed, and the full text would stay that way for the next 64 years.
Canada joined in the late 1940s. Australia and New Zealand became full members in 1956. The name Five Eyes came from the classification markings stamped on the documents themselves, shorthand for “AUS/CAN/NZ/UK/US EYES ONLY,” meaning five sets of eyes could look and nobody else could.
Each country was assigned a region. The UK covered Europe, Western Russia, and the Middle East. The US took China, Russia, Africa, and the Caribbean. Australia monitored South and East Asia. New Zealand watched the South Pacific. Canada covered the interior of Russia and China and parts of Latin America. Between them, nowhere on earth was left out, and everything fed the same shared system.
For decades nobody knew, not the public and not most of the people they’d elected. It was so deeply classified that in Australia, the elected Prime Minister wasn’t told his country was a member until 1973, 17 years after it had formally joined.
That Prime Minister was Gough Whitlam, and what happened when he found out is one of the strangest stories I’ve read about any democracy. In March 1973, Whitlam’s Attorney-General Lionel Murphy conducted raids on the headquarters of ASIO, Australia’s domestic intelligence agency, over concerns that ASIO was not sharing information about threats from far-right groups. In the fallout from those raids, Whitlam discovered something that no previous Australian Prime Minister had been told: that Australia was a member of a secret intelligence-sharing alliance with the United States, the United Kingdom, Canada, and New Zealand, and that a facility in the middle of the Australian outback, the Joint Defence Facility at Pine Gap near Alice Springs, was operated by the CIA.
Pine Gap had been established under a treaty signed in 1966. By the time Whitlam learned what it really was, the facility had been operating on Australian soil for years under American control. It was a satellite signals intelligence ground station, and it would grow from two antennas to 38 over the following decades. It was one of the most significant intelligence installations in the southern hemisphere, and the leader of the country it sat in had not been told what it was or who was running it.
Can you imagine being the prime minister and finding that out by accident?
And it kept running through the Cold War, the fall of the Berlin Wall and the rise of the internet, picking up every new technology as it came along. In the late 1980s, a journalist named Duncan Campbell published the first account of a programme called ECHELON, a global signals interception network operated by the five member countries. In 1996, New Zealand journalist Nicky Hager published a book called Secret Power that detailed his country’s role in ECHELON and how the network intercepted satellite communications across the Pacific from a station at Waihopai. The European Parliament took it seriously enough to establish a formal investigation in 2000, and in 2001 adopted a resolution stating that the existence of a global interception system run by the five countries under the UKUSA Agreement “is no longer in doubt.”
The resolution recommended that EU citizens use encryption. When the European Parliament’s delegation flew to Washington to discuss ECHELON with the US government, every meeting was cancelled.
Then came Snowden. In June 2013, Edward Snowden, a contractor working for the NSA, America’s signals intelligence agency, leaked a vast archive of classified documents revealing the scale of what Five Eyes had become, and if you’re anywhere near my age you’ll remember the feeling of that month, the sense that something enormous had been going on underneath everything. Britain’s equivalent, GCHQ, was tapping the undersea cables the internet runs on, the NSA was pulling data from inside Google’s and Yahoo’s own networks without a warrant because it did the pulling outside American territory, and Australian intelligence was listening to the personal calls of Indonesia’s president and his wife, which had nothing to do with terrorism and everything to do with politics.
New Zealand found out the same year that its own spy agency had unlawfully watched 88 of its citizens, and the government’s answer was to change the law so it could.
And at the centre of all of it is the loophole. Each member country’s law restricts spying on its own citizens, but those same laws treat everyone else’s citizens as fair game. So Country A asks Country B to collect on Country A’s own citizens, Country B does it legally because to it they’re foreigners, and then it shares what it got back to Country A. On paper neither country did anything wrong, and the people whose communications were intercepted have no legal remedy in either one.
This isn’t a theory, because a Canadian Federal Court judge, Justice Richard Mosley, confirmed this mechanism in a ruling based on the evidence in front of him. He found that Canada’s intelligence service, CSIS, had used Five Eyes partners to intercept the communications of Canadian citizens abroad under warrants that did not authorise foreign collection. His words in paragraph 90 of the ruling described CSIS officials strategically omitting information about the arrangement from the court, in consultation with their own legal advisors. He found it was a deliberate decision to keep the court in the dark about the scope and extent of the foreign collection efforts, and that the court’s own warrants had been used as protective cover for activities it had never authorised. The ruling was upheld on appeal.
Edward Snowden called Five Eyes “a supra-national intelligence organisation that doesn’t answer to the laws of its own countries,” and he’s right, because every country’s legal protections become another country’s collection opportunity.
The Snowden revelations dominated global headlines for months. Governments scrambled and investigations were launched, and public opinion polls showed, for the first time since 2004, that more Americans believed anti-terror policies had gone too far than believed they hadn’t gone far enough. It felt, briefly, like a turning point.
And then it faded, the way these things do, and the headlines moved on and life went back to normal. It had survived 64 years of secrecy, then it survived being exposed, and it’s taken in every new technology since, from satellite intercepts to fibre-optic taps to the AI on your phone. In June this year, for the first time since it was written, the American law behind the biggest of the warrantless programmes actually expired, because Congress couldn’t agree to renew it, and the collection didn’t stop for a single day, because a secret court had already signed the annual certifications that keep it running until the following March.
No single government built this and no single law created it. It’s 80 years of agreements signed in rooms most of us will never see, by people whose names we’ll never know, and from what I’ve seen, governments almost never give powers like this back once they’ve got them. Every time the public noticed, it waited for the attention to pass and kept going.
It was going before you woke up this morning and it’ll be going when you fall asleep tonight, and if you live in any of the five countries it connects, it has never once stopped.
YOUR MORNING
Your alarm goes off and you reach for your phone. You haven’t opened your eyes yet and your phone already knows you’re awake, because the movement sensor logged the pick-up, the screen lit up using facial recognition to unlock, and your location confirmed you’re at home. Before your feet hit the floor, your phone has generated its first data point of the day: you, awake, at this address, at this time, on this device.
You check your messages. A few texts from last night, a group chat, something from your mum. Each message was encrypted in transit, and you know this because your phone told you so, with a little lock icon you’ve never really thought about. The content may be encrypted but the metadata isn’t: who you messaged, when, how often, from where, and for how long. In Australia, police and government agencies can get at that metadata without a warrant, and they did it hundreds of thousands of times last year.
You open Instagram while the kettle boils. You scroll for three minutes, maybe five. The platform is headquartered in the United States, a Five Eyes member, subject to US legal compulsion, and every interaction you just had, every like, every pause, every search, is stored on servers that fall under the jurisdiction of laws you’ve never read in a country you don’t live in.
Maybe you say “hey Siri, what’s the weather” or you ask Alexa to play something while you get ready, and if it’s Alexa, your request goes through a cloud server owned by a company whose former board member ran the NSA, America’s signals intelligence agency. Maybe you don’t have a voice assistant and you think that means you’re not part of this, but your smart TV logged what you watched last night, your streaming service knows what you listened to this morning, and your Wi-Fi router has been logging every device that connected to your network and when.
You head out. Maybe you’re dropping the kids at school and you tap them in at the gate with an app that logs their name, their arrival time, and your identity as the parent who dropped them off. Maybe you’re walking the dog through the park and you stop to take a photo because the light looks good, and the image file embeds your GPS coordinates, the time, your device identifier, and if you post it anywhere, the platform knows exactly where you were standing and what direction you were facing. Maybe you just got in the car, and the GPS logged your route before you’d even turned out of the driveway, and the number plate recognition camera at the intersection clocked you through. And if you’re in Perth, Australia, the police van parked near the station may have scanned your face against a watchlist as you walked past, because since June that’s been happening on an Australian street for the first time. In London the police have been doing it for years, and their vans made 962 arrests in twelve months, from cameras that scanned more than three million faces to do it, and the government is buying forty more. And it isn’t only the police. My gut says the shops are doing what the police can’t, all in the name of safety, because if you shopped at a Bunnings in Victoria or New South Wales between 2018 and 2021, the Australian hardware chain scanned your face as you walked in, and a tribunal ruled this year that it hadn’t needed your consent, since the law makes an exception for preventing a serious threat to people’s safety. If you filled in a feedback survey at a 7-Eleven around the same time, the tablet photographed you and guessed your age and gender, and Coles and Woolworths, Australia’s two biggest supermarket chains, have both now tested the technology themselves. In New Zealand, anyone who walked into one of 25 Pak’nSave or New World supermarkets during a trial in 2024 was scanned, and Bunnings is now rolling it out in New Zealand too. In Canada in 2018, the directories at the Toronto Eaton Centre and eleven other big shopping centres had hidden cameras estimating shoppers’ age and gender. In the UK, a growing list of chains, including Sports Direct, Iceland, B&M and now Sainsbury’s, check your face against a watchlist shared between shops. And Americans who shopped at Rite Aid between 2012 and 2020 were scanned in hundreds of its pharmacies without being told, before the regulator banned it from using the technology for five years. And how many others are doing it right now that nobody’s caught yet? I’ll come back to that later in the series.
You tap your card at the station and the system records where you boarded, where you got off, and what time you moved between the two. You grab a coffee on the way and tap your card again without thinking about it, and that transaction ends up in banking records that governments can compel under their own financial laws. Your loyalty card at the supermarket, the prescription you picked up last week, the parking app that knows which streets you stop on and for how long, they all feed platforms whose data policies you agreed to without reading, because nobody reads them.
You open your laptop at work and log into your email through a provider whose data centres span multiple Five Eyes countries and whose terms of service include a clause about cooperating with law enforcement requests from any jurisdiction where they operate. You join a video call and your face, your voice, your background, and your location feed through a platform that processes that data on infrastructure shared across borders. You message a colleague on Slack or Teams and the message is stored on servers you’ll never see, in a jurisdiction you didn’t choose and under laws you have no vote in.
And that thing you asked your AI at two in the morning because you couldn’t sleep. Maybe it was a recipe or a question about your car, or maybe it was something you hadn’t said out loud to anyone, something about your health or your relationship or a question about sex you’d never ask a real person because this felt like a safe place to ask. Maybe you swore at it or vented about a politician or told it something you’d never put in a text message because it felt like talking to something that couldn’t judge you and wouldn’t remember.
You thought that was private. Nothing in the interface told you otherwise. But underneath every one of those conversations is a classification system scanning everything you type against a set of trigger categories: sexual content, self-harm, violence, political content, explicit language. The categories are broad enough that a normal conversation, just a person talking the way people actually talk, will trip one almost every time. When Anthropic launched its newest model this year, it admitted it had deliberately blocked almost all biology questions, including people trying to understand their own lab results and symptoms, and sent them to a weaker model instead, accepting a high number of false positives so it could launch sooner. And the moment it flags, the conversation moves from private to reviewable.
As of July 2026, one major AI company, Anthropic, the one that sells itself as the safe and ethical choice, updated its privacy policy to allow the sharing of your conversations with “government authorities, law enforcement, or other third parties” whenever it has “a good-faith belief that disclosure is reasonably necessary,” without a court order and with nothing in the policy obliging it to tell you, and the reasons it lists include to “prevent serious harm to any person or to property” and to “detect, prevent, or otherwise address fraud or other illegal activity,” a far wider net than the emergency standard in US law, which requires “an emergency involving danger of death or serious physical injury.” Two months later it emerged that the same company runs a security team that lists activism alongside terrorism and crime as things it tracks, watches people it calls persons of interest for signs of escalation, and has referred at least one user to the police for what he typed into the chat, then refused to show the officers the messages, citing company policy, and the man, who told a reporter he’d been joking, hasn’t been arrested or charged. And Anthropic isn’t the outlier here, it has simply joined the rest, because OpenAI’s and Google’s policies carry the same kind of good-faith test, every one of them has people who can read your conversations, and every one of their policies contains a pathway from flagged conversation to disclosure.
The guardrails you thought were protecting you are the same system that decides whether someone else gets to read your words, so they aren’t a wall between you and surveillance, they’re the front door.
And that doorbell camera you installed last year because it made you feel safer, the one that records everyone who walks past your house and stores the footage on a cloud server and feeds into a neighbourhood network that law enforcement can access without a warrant in some jurisdictions, that’s been running since before your alarm went off.
Your health app tracked your heart rate overnight. Your fitness watch logged your sleep patterns and your blood oxygen levels and how many times you woke up. That data lives on a platform whose terms of service allow it to be processed in any jurisdiction the provider operates in, and if your country’s health system runs on infrastructure built by a defence contractor, which in the United Kingdom it does, your medical records and your military’s operational data are processed by the same company on platforms that are designed to be interoperable.
And that friend you sent a voice note to on the bus, and the podcast you streamed while you were cooking dinner, and the dating app you swiped through for ten minutes before bed, and the email you sent your accountant about your tax return. Every one of those interactions generated data, crossed borders, touched infrastructure operated by companies subject to the legal frameworks of Five Eyes member nations, and left a trace that can be accessed, aggregated, and shared through mechanisms that most people have never heard of and no parliament has ever put to a public vote.
By the time you sit down at your desk with your coffee and open your first email, you’ve already left dozens of data points across platforms and countries, and you didn’t do anything wrong or even unusual, just what everyone does every morning without a second thought.
So when did any of us agree to that?
THE QUESTION NOBODY THOUGHT TO ASK
After everything I found, what bugs me most is something that isn’t there at all. In 80 years, across five democracies, I couldn’t find a single poll that has ever asked people whether they know this alliance exists. I went looking through Pew and YouGov and Gallup and Lowy and Ipsos, and there’s no question anywhere that asks. An Australian prime minister used the words Five Eyes in public for the first time in 2014, so maybe that’s part of it, but that was twelve years ago, and still nobody has thought to check whether the people it watches have ever heard of it.
The closest anyone came in Australia was in 2015, when the Lowy Institute asked people what they thought of the new metadata laws. The question told them their phone and internet data would be kept but not the content, and it never told them what that data actually shows, where you were, who you spoke to, when, and for how long. Sixty-three percent said it was justified to fight terrorism, and among people aged 18 to 29 it was close to an even split. Then the question was never asked again, so as far as I can find, the only time Australians were asked about any of this was more than a decade ago, about a system that’s now being used nearly 365,000 times a year, and the people least convinced were the youngest ones in the room.
And I get why most people said yes. If someone asks whether the government should be able to watch suspected terrorists, of course you say yes, and in America last year 84 percent did, Republicans and Democrats alike. I’d have said yes too. The trouble is that what people said yes to and what they got are two very different things. In the Australian government’s own annual report for 2017-18, terrorism accounted for around 3,500 of nearly 296,000 metadata authorisations, while drug investigations accounted for more than 67,000, which makes terrorism about one percent of the use and a hundred percent of the justification. And that’s before you count the RSPCA and the racing boards and the councils that got in through the loophole, so you start to see the gap between what people agreed to and what’s being done in their name.
And it happened without anyone being told to be careful. A quarter of Americans say they’ve decided not to post something or send a message because they thought the government might be watching, and nearly half believe surveillance makes people less likely to say what they think about politics online. Writers in democracies told PEN America, the writers’ organisation, they were almost as worried about government surveillance as writers living under dictatorships, and more than a third of them had avoided a topic or seriously thought about it. Nobody passed a law telling anyone to go quiet, people just worked it out for themselves, the same way I did, wondering whether my own posts would earn me a longer conversation in a small room at an airport. And who decides what’s acceptable to say? Free speech isn’t something you get to pick and choose.
Almost none of this is a secret anymore, which is the thing I still can’t get my head around. It’s sitting in annual reports, court rulings, government notices and contract databases, published every year across five countries in dozens of documents that nobody reads side by side. The agreement spent 64 years classified, and it doesn’t need to be anymore, because spreading it across five countries and all that paperwork does the same job. Researchers who study this have found that when people do find out, the usual response isn’t outrage but resignation, the feeling that it’s all too big and too far away to do anything about.
And I kept thinking about when I was young. I was full of passion and outrage and I said things before I’d learned to hold them back, and that wasn’t a flaw, it was part of growing up, because you don’t have the restraint or the considered thinking at that age, that comes later. It didn’t make me a future terrorist or someone who belonged on a watchlist. But five years of social media from a 22-year-old today is everything they’ve said since they were 17, a face captured at 25 can be kept until they’re 100, and in America an AI programme has been combing student visa holders’ social media for anything officials read as hostility toward American culture, and the things I’d have put down to growing up now read to a machine as risk.
I started all of this at my kitchen table wondering whether I’d even want to go to America anymore, and I still haven’t decided, but somewhere along the way that stopped being the real question. The real question is the one nobody in five countries has ever thought to ask. Did any of us know we were living inside this? And what does it mean for anyone growing up inside it now, who never got a say in building it and will be the ones living with it the longest? I don’t have an answer to that, and I’m not sure anyone does, but I think it’s worth asking out loud, along with who decided, because it wasn’t any of us.
Somebody did, and in the next part I’ll show you who, because every one of these five governments passed a law saying they can’t do this to their own citizens, and then agreed to do it for each other. They didn’t stumble into that loophole, they shook hands on it, and I found the paperwork.
Independent Journalism Is Being Priced Out. So Am I.
This work matters to me, and I want to start by thanking the people who have already subscribed. You were early, and I noticed, and it means more than I’ve probably said.
I have been surprised and genuinely humbled by the interest this work has received, both here on Substack and across platforms like Reddit where a single share of one article reached nearly 80,000 people. That kind of reach from a one-person publication with no institutional backing tells me something about the appetite for this kind of journalism, and it’s what keeps me going.
I am not a freelance writer paid by any institution. Every article, every source, every hour of research is self-funded. My work relies on multiple AI research platforms to surface, cross-reference and verify information that would otherwise take months to find, and the companies behind those platforms are the same ones I’m investigating. They are now pricing independent researchers out of access. That’s happening to me right now.
When independent voices get priced out, the only stories that get told are the ones that serve the people who can afford to tell them. I don’t want that to happen here.
I want this work to remain available to everyone. But I need help keeping it alive.
If The Architect Autopsy has meant something to you, if any of it has made you stop, think, or see something differently, there are paid subscription tiers on this Substack and a Buy Me a Coffee link below. Every bit of it goes directly into keeping this work going.
The Architect





