Who Controls the Digital You? Surveillance, AI Profiling, and Synthetic Identity

Introduction

A television that recognizes what appears on its screen, a conversational AI system that builds a persistent representation of a user, and a generative model that can place a recognizable person into a synthetic nude image initially look like separate ethical problems. The first belongs to consumer privacy, the second to personalization and data governance, and the third to deepfakes, sexual exploitation, and freedom of expression. Treating them as unrelated, however, misses the common structure. Each technology acquires a different kind of authority over the digital representation of a person.

Traditional privacy analysis is strongest when asking who may collect, retain, or disclose information about someone. Identity ethics asks additional questions because digital systems can do more than possess information. They can observe behavior, identify people, infer characteristics, synthesize representations, deploy those representations in new contexts, and retain them after the original interaction has ended. A person’s appearance, voice, conduct, preferences, associations, history, and reputation are not merely data points. Together they form part of the interface through which that person acts and is recognized in the social world (Holcombe, 2026).

Three distinctions organize the cases examined here. Identity extraction occurs when a system captures authentic traces of a person’s behavior. Identity inference occurs when those traces are used to classify, predict, or construct a model of the person. Identity fabrication occurs when technology creates speech, conduct, images, or other representations that did not originate with the person and attaches them to that person’s recognizable identity. These categories are derived from the broader identity-processing sequence of observation, identification, inference, synthesis, deployment, and retention (Holcombe, 2026). The categories overlap in practice, but they identify different moral problems and therefore require different justifications.

1. Smart Televisions and Identity Extraction

Automatic Content Recognition (ACR) allows a smart television to identify material appearing on its screen by generating digital fingerprints and matching them against reference databases. Because recognition can occur at the television’s system level, the relevant content may include more than programs viewed through built-in streaming applications. Independent testing by RTINGS found ACR-related network activity on several televisions and reported that, on some tested models, withdrawing consent or disabling the relevant settings stopped or substantially changed that activity (Wood, 2026).

The commercial rationale is straightforward. Viewing behavior can be used for audience measurement, advertising, household categorization, and personalization. The ethical problem begins when the consumer’s understanding of the transaction differs materially from the manufacturer’s continuing use of the device. A buyer may reasonably understand the exchange as money for a television, while the manufacturer’s business model also treats the television as an ongoing source of behavioral information. RTINGS found that some relevant privacy choices were embedded in broader agreements, described with unfamiliar terminology, or connected to the loss of other features when users declined data collection (Wood, 2026).

The issue has also produced regulatory action. In May 2026, the Texas Attorney General announced an agreement with LG concerning ACR-related viewing-data practices. The agreement requires clearer disclosure and a more direct means of opting out, following litigation alleging unlawful collection of smart-TV viewing information (Office of the Attorney General of Texas, 2026). The existence of ACR and its use for viewing recognition are therefore not speculative. The more precise ethical description is that a device purchased for viewing media can also function as a networked observation system.

The September 2026 LG Allegations

A separate September 2026 investigation reported by The Verge made broader claims about retail LG OLED televisions. According to the report, investigators associated with Gamers Nexus, Level1Techs, and independent security research found behaviors involving local-network scanning, information about nearby devices and Wi-Fi networks, location-related information, and communication with LG Ad Solutions. The report also described alleged microphone recording while a television was in standby and storage of information while the device was offline for later transmission (Preston, 2026).

Those claims should not be treated as equivalent in evidentiary status to the documented existence of ACR. At present, the standby-microphone and offline-storage claims are reported findings from a technical investigation rather than final regulatory findings or a replicated research literature. Verification would require independent reproduction of the packet-capture and device-forensics results, technical documentation or a specific response from LG, or evidence developed through litigation or regulatory investigation. The distinction matters because the ethical case concerning opaque viewing surveillance does not depend upon the stronger allegations being confirmed.

Consent and the Consumer Transaction

The smart-TV case is an example of identity extraction because authentic behavior is converted into a persistent and commercially useful trace. Individual viewing choices may appear trivial, but repeated behavior can support inferences about interests, household composition, language, age, political attention, religion, health concerns, sexuality, entertainment preferences, and purchasing interests. A system does not need to know a person’s name before the behavior becomes useful for classification or advertising.

Formal consent does not settle the moral question. Meaningful authorization requires a reasonable opportunity to understand what is collected, why it is collected, whether it will be combined with other information, how long it will be retained, and whether refusal carries unrelated penalties. The Identity Ethics framework identifies comprehension failure, practical coercion, purpose drift, temporal distance, and collective effects as recurring defects in digital consent (Holcombe, 2026). A lengthy privacy agreement available during setup may satisfy a formal disclosure requirement while still failing to provide meaningful authorization.

This argument does not imply that ACR is inherently impermissible. Some consumers may knowingly accept viewing-data collection in exchange for personalization, advertising-supported services, or lower hardware prices. The normative premise is narrower: access to behavior does not create an unlimited moral entitlement to process that behavior. When collection is difficult to perceive, difficult to refuse, or substantially broader than a reasonable consumer would expect, the quality of the authorization becomes ethically relevant.

2. Conversational AI and Identity Inference

Smart televisions show how ordinary activity can become a behavioral record. Conversational AI raises a further problem because accumulated traces can be transformed into a persistent representation of the person. In 2026, researchers examining 2,050 ChatGPT memory entries contributed by 80 users through GDPR data-access requests reported that only about 4 percent of the sampled entries followed direct requests to remember information. The remaining entries were initiated by the system after information in the conversation was treated as potentially useful for later interactions (Dash et al., 2026).

The researchers called the resulting representation an “algorithmic self-portrait.” Their analysis was not limited to harmless preferences. They reported that 28 percent of the memory entries contained personal data under the GDPR and 7 percent contained special-category personal information. At the participant level, economic information appeared in the memories of 62 percent of users, social-identity information in 57 percent, and health-related information in 35 percent. They also classified 52 percent of all memory entries as containing psychological information, including desires, intentions, emotions, beliefs, perceptions, knowledge, and interpretations (Dash et al., 2026).

These findings do not establish that OpenAI maintains a standardized hidden dossier assigning every user a fixed income level, political affiliation, sexual orientation, vocation, and personality profile. That stronger social-media claim would require evidence of a systematic profiling architecture of that kind. The study supports a narrower conclusion: persistent AI memory can contain personal and psychologically interpretive representations that users did not explicitly ask the system to save (Dash et al., 2026).

Inference Does Not Require Explicit Self-Disclosure

The ethical significance of profiling also cannot be reduced to what a user states explicitly. Research has shown that language models can infer personal characteristics from indirect linguistic signals. Staab et al. (2023), for example, demonstrated privacy leakage through inference from apparently ordinary text. A later study of donated conversational-AI histories reported that an off-the-shelf language model could infer age, gender, and country even when explicit demographic self-identification had been excluded from the dataset (Cögendez et al., 2026).

Political orientation presents a related problem. Karadal and Kekulluoglu (2025) supplied ChatGPT with statements indicating positions on issues such as abortion, gun rights, vaccination, and diversity programs without explicitly assigning partisan identities. The model inferred political orientations from those signals, and the researchers reported differences in subsequent response framing. This does not show that ChatGPT currently labels every user by political affiliation. It does show that conversational language can contain enough information for politically relevant classifications to become inferable.

The distinction between memory and profiling therefore becomes difficult to maintain if personalization is defined only by the absence of a categorical field labeled “political affiliation,” “income,” or “sexual orientation.” A probabilistic model can affect how a system treats a person without storing a simple label. If repeated conversations lead a system to treat a user as financially constrained, politically conservative, socially isolated, risk-averse, or highly anxious, the ethical issue concerns the role of that representation in later interactions, not merely the database format in which it is stored.

Epistemic Authority Over the Person

Identity inference is morally distinct from observation because it creates propositions about the person rather than merely recording what the person did or said. Those propositions may be probabilistic, incomplete, and sometimes wrong. Their fallibility does not eliminate their importance. A mistaken profile can affect what information is presented, what advice is offered, which arguments are emphasized, how strongly a system challenges a user, or what opportunities an institution makes available.

This is a problem of epistemic authority over identity. Institutions routinely make inferences about people, and some inferences are necessary. A physician, teacher, employer, lender, or fraud investigator could not function without interpretation. The relevant moral questions concern justification and use: what may be inferred, from what evidence, for what purpose, with what confidence, and with what opportunity for the person to inspect, contest, or correct the resulting representation? Those questions are not answered by saying that the original data were lawfully collected.

3. Identity Fabrication and Minnesota’s Nudification Law

Identity fabrication introduces a different kind of intervention. Surveillance converts something a person actually did into information. Generative systems can create conduct that never occurred and attach it to a recognizable person. A synthetic voice can make someone appear to say words they never spoke. A generated image can depict sexual exposure that never happened. A fabricated video can associate a person with political, criminal, or intimate conduct for which there is no underlying act.

Within Identity Ethics, the relevant interest is identity integrity, the relationship between a person and the actions, characteristics, and representations attributed to that person (Holcombe, 2026). The harm is not exhausted by informational privacy because the source material can be public and the resulting image can be known to be synthetic. The representation still uses the person’s recognizable identity as an instrument for conduct the person did not authorize. Holcombe’s framework describes this as substituted agency.

What Minnesota Regulates

Minnesota enacted H.F. 1606, codified at Minnesota Statutes § 325E.91, in 2026. The statute defines nudification as altering or generating an image or video so that an identifiable person appears to display an intimate part not shown in the original, where the result is sufficiently realistic that a reasonable person could believe the depicted intimate part belongs to that individual. The law became effective August 1, 2026 (Minnesota Legislature, 2026).

The statute regulates more than the individual creator of an image. It generally prohibits a person controlling a website, application, software program, or service from allowing users to employ that service to nudify an image or from performing the nudification for the user. It also restricts advertising or promotion of such services and authorizes private civil actions and substantial civil penalties (Minnesota Legislature, 2026). The statute therefore places duties on technological intermediaries, not merely on end users.

One feature deserves particular scrutiny. The prohibition does not apply when a service requires substantial individualized technological or artistic skill and judgment to produce the image (Minnesota Legislature, 2026). The exemption distinguishes, at least partly, between automated systems that make nudification easy and tools that require substantial human expertise. That may be defensible as a response to scale, speed, accessibility, and foreseeable misuse. It is not, however, a distinction in the moral status of the final representation. A skilled digital artist and an inexperienced user of an automated generator can produce harms of the same general kind.

xAI’s First Amendment Challenge

xAI, the developer of Grok and Grok Imagine, challenged the Minnesota law and sought a preliminary injunction against enforcement. On September 4, 2026, U.S. District Judge Donovan W. Frank denied that request. The order did not hold that Minnesota’s statute is constitutional. The court concluded that xAI had not established the irreparable harm required for preliminary relief and stated that the constitutional questions would require further consideration as the case proceeded (X.AI LLC v. Ellison, 2026).

The First Amendment objection cannot be dismissed merely because the underlying technology can be used abusively. Generative images are expressive material, and a law restricting what visual representations a system may help produce raises genuine questions about content-based regulation. Conversely, describing the output as “speech” does not resolve the ethical or constitutional problem. The dispute concerns the relationship between expressive liberty and a person’s interest in identity integrity, especially when another actor uses that person’s recognizable body or face to manufacture apparently authentic sexual conduct.

A serious analysis must therefore resist two shortcuts. Treating the case as “free speech versus censorship” understates the interests of the depicted person. Treating it as “victims versus Big Tech” understates the constitutional problem created when the state regulates expressive production. The pending litigation matters because the proper legal balance has not yet been resolved. The ethical analysis can identify the competing interests without pretending that the constitutional question has already been answered.

4. Three Forms of Power Over the Digital Self

Form What the system does Illustrative case Primary ethical concern
Identity extraction Captures authentic behavioral traces Smart-TV viewing recognition Observation, autonomy, meaningful consent
Identity inference Derives traits, categories, or predictions from traces Conversational AI memory and profiling Epistemic authority, opacity, contestability
Identity fabrication Creates new representations attached to a recognizable person AI nudification and synthetic sexual imagery Identity integrity, dignity, substituted agency

The taxonomy matters because the three practices should not be collapsed into a single category called “privacy.” Extraction concerns access to authentic behavior. Inference concerns the authority to transform traces into claims about the person. Fabrication concerns the authority to create new representations and attach them to the person’s identity. Authorization at one stage does not automatically authorize the next. A consumer who permits viewing recognition for audience measurement has not thereby authorized psychological profiling. A person who posts a photograph publicly has not thereby authorized sexual synthesis.

5. Identity as Machine-Readable Infrastructure

Impersonation, rumor, forgery, surveillance, and manipulated images are not new. What has changed is the cost and scale at which representations of people can be processed. A face can function as a biometric identifier, viewing activity as a behavioral profile, a voice recording as training material for a synthetic voice, and a photograph as an input for generated sexual imagery. Past conduct can also become an input to automated predictions about future behavior.

This creates an asymmetry between embodied persons and institutions operating on representations at computational scale. The existence of that asymmetry does not make every technological use of identity wrongful. Security, accessibility, entertainment, health care, research, fraud prevention, personalization, and ordinary communication all provide legitimate uses. The mistake is to treat technical accessibility as moral availability. Public availability of an image, voice, or behavior may establish access, but access and authorization are different propositions.

Layered Authorization

A more defensible model of digital identity governance attaches authorization to particular operations. Permission to observe does not by itself authorize identification. Identification does not by itself authorize inference. Inference does not by itself authorize synthesis. Synthesis does not by itself authorize unrestricted deployment. The Identity Ethics processing model treats these transitions as morally significant because the interests and risks change as the system moves from observation toward increasingly interventionist uses (Holcombe, 2026).

For consumer technologies, layered authorization would require contextual notice, understandable choices, practical opt-outs, purpose limits, retention limits, and nonpunitive alternatives where feasible. Systems that generate or deploy recognizable representations require stronger safeguards because they can act through a representation of the person rather than merely observe the person. The relevant controls may include specific consent, provenance, restrictions on downstream use, contestability, correction, deletion, and remedies when identity is misattributed or synthetically substituted.

6. Why Data Ownership Is Too Narrow

Digital ethics often begins with the language of ownership: who owns my data, my face, or my voice? Ownership can be legally and commercially important, but it cannot carry the entire moral analysis. People disclose aspects of themselves constantly without surrendering every claim concerning later use. Walking through a public place does not logically authorize permanent behavioral classification. Posting a photograph does not authorize sexual transformation. Speaking publicly does not authorize a third party to clone the voice and attribute new statements to the speaker.

The broader question concerns moral authority over representation: who may observe, infer from, reproduce, modify, and deploy the digital representations through which another person is socially recognized? Framing the issue this way exposes why privacy, publicity rights, copyright, consumer protection, anti-discrimination law, and free-expression doctrine each capture only part of the problem. The underlying moral object is the relationship between the person and the socially operative representation of that person.

7. From Privacy to Identity Integrity

Smart-TV tracking, conversational AI profiling, and nudification occupy different points in the same technological progression. The television converts lived behavior into data. The profiling system converts accumulated data into a model of the person. The generative system can convert data back into fabricated behavior attributed to the person. Between these points lies an infrastructure of identification, prediction, classification, synthesis, deployment, and retention.

Privacy remains indispensable, but its traditional focus on access to information is incomplete once technologies can construct and act upon representations. Identity integrity protects the connection between a person and the actions, characteristics, and communications attributed to that person. A governance system concerned with identity integrity therefore has to ask not only whether information was collected lawfully, but whether the downstream operation was necessary, proportionate, purpose-compatible, contestable, and appropriately authorized.

The strongest normative principle that follows from these cases is proportionate authority over identity. The deeper a technology intervenes in the relationship between a person and the representation through which that person is recognized, the stronger the justification and safeguards should be. Observation ordinarily requires less authority than persistent classification; persistent classification ordinarily requires less authority than synthetic sexual substitution. This is not an argument for absolute individual control, which would make many legitimate social and institutional inferences impossible. It is an argument against treating a single act of access or consent as a blanket license for every downstream use.

8. Conclusion

Smart televisions, conversational AI memory, and synthetic nudification should not be treated as morally identical technologies. Their value as a combined case study lies in the progression they reveal. Digital systems can extract authentic traces of behavior, infer characteristics and vulnerabilities from those traces, and fabricate new conduct attached to a recognizable person. Each step changes the nature of the institutional power being exercised.

The next generation of digital governance therefore cannot be organized around the question “Who may collect information about me?” alone. It must also address who may construct a model of a person, what may be inferred from that model, how those inferences may shape subsequent treatment, and when another actor may manufacture new versions of the person’s speech, appearance, or conduct. Privacy law remains part of that project, but identity ethics identifies the larger problem: digital systems increasingly mediate the relationship between human beings and the representations through which they are known.

9. References

Cögendez, E., Zimmermann, C., & Zufferey, S. (2026). Inferential privacy leakage in anonymized conversational AI logs. arXiv.

Dash, A., Das, S., Kirsten, E., Wu, Q., Karnam, S. K., Gummadi, K. P., Holz, T., Zafar, M. B., & Zannettou, S. (2026). The algorithmic self-portrait: Deconstructing memory in ChatGPT. Proceedings of the ACM Web Conference 2026, 3471–3482. https://doi.org/10.1145/3774904.3792671

Holcombe, M. T. (2026). Identity ethics and the distributed self. https://marktholcombe.com/identity-ethics-distributed-self-artificial-intelligence/

Karadal, P., & Kekulluoglu, D. (2025). Prioritize economy or climate action? Investigating ChatGPT response differences based on inferred political orientation. arXiv.

Minnesota Legislature. (2026). Chapter 72, H.F. No. 1606: Prohibition on nudification technology. Office of the Revisor of Statutes. https://www.revisor.mn.gov/laws/2026/0/Session%2BLaw/Chapter/72/

Office of the Attorney General of Texas. (2026, May 11). Attorney General Ken Paxton secures major agreement with LG to protect Texans’ privacy and stop data from being collected without their knowledge. https://www.oag.state.tx.us/news/releases/attorney-general-ken-paxton-secures-major-agreement-lg-protect-texans-privacy-and-stop-data-being

Preston, D. (2026, September 8). LG TVs caught spying even when offline or on standby. The Verge. https://www.theverge.com/tech/991190/lg-tv-spying-standby-recording-wi-fi-scanning-gamers-nexus

Staab, R., Vero, M., Balunović, M., & Vechev, M. (2023). Beyond memorization: Violating privacy via inference with large language models. arXiv.

Wood, M. J. (2026, August 5). Why smart TVs track what you watch: And why it’s so hard to stop them. RTINGS.com. https://www.rtings.com/tv/learn/research/smart-tv-data-privacy

X.AI LLC v. Ellison, Civil No. 26-3425 (DWF/DTS) (D. Minn. Sept. 4, 2026) (memorandum opinion and order denying preliminary injunction). https://docs.justia.com/cases/federal/district-courts/minnesota/mndce/0%3A2026cv03425/235231/54

10. Frequently Asked Questions

What is identity ethics?

Identity ethics examines the moral interests involved when technologies or institutions observe, identify, classify, predict, reproduce, manipulate, or deploy representations of people. It extends beyond informational privacy because a person can be harmed through false attribution, persistent classification, synthetic impersonation, or substituted agency even when no confidential information has been disclosed (Holcombe, 2026).

Do smart TVs actually track what people watch?

Some smart televisions use Automatic Content Recognition to identify material displayed on their screens. Independent testing by RTINGS found ACR-related network activity on several tested televisions, and Texas reached a 2026 agreement with LG requiring clearer disclosure and opt-out mechanisms concerning viewing-data collection (Office of the Attorney General of Texas, 2026; Wood, 2026).

Are LG televisions recording conversations while turned off?

A September 2026 technical investigation reported by The Verge alleged microphone capture while tested LG televisions were in standby and storage of information while offline for later transmission (Preston, 2026). Those allegations should presently be treated as reported findings rather than settled facts. Verification would require independent technical replication, regulatory findings, court-developed technical evidence, or a specific technical response from LG.

What is AI nudification?

Minnesota’s 2026 statute defines nudification as altering or generating an image or video so that an identifiable person appears to display an intimate part that was not shown in the original, with sufficient realism that a reasonable person could believe the depicted intimate part belongs to that individual (Minnesota Legislature, 2026).

Did a court rule that Minnesota’s nudification law is constitutional?

No. On September 4, 2026, the federal district court denied xAI’s request for a preliminary injunction, but the order did not resolve the underlying First Amendment merits. The court left those constitutional questions for further litigation (X.AI LLC v. Ellison, 2026).

Why is synthetic nudity more than a privacy issue?

The harm can remain even when the source photograph is public and viewers know the synthetic image is fake. The representation still associates a recognizable person with sexual exposure or conduct that did not occur. Identity ethics treats this as a problem of identity integrity and substituted agency because another actor uses the person’s recognizable identity as the medium for conduct the person did not authorize (Holcombe, 2026).

What is the difference between identity extraction, inference, and fabrication?

Identity extraction captures authentic traces of behavior. Identity inference uses those traces to derive classifications, predictions, or a model of the person. Identity fabrication creates new speech, conduct, images, or other representations and attaches them to a recognizable person. The distinctions matter because each operation exercises a different kind of power and therefore requires a different ethical justification.