Personal OPSEC in an AI surveillance world
Behavioral and physical security habits — limiting your voice/photo footprint, spotting AI-assisted pretexting — distinct from account-security hardening.
The two things that got cheap to fake
Two raw materials that impersonation scams need — a sample of your voice and a clear image of your face — are now trivial for a stranger to collect and turn into a synthetic double. A few seconds of audio lifted from a posted video, or a handful of clear photos, is enough for widely available tools to produce a usable clone. This is a different problem from the account-takeover risk covered in Digital Identity Hardening: an attacker can run a fully convincing social-engineering attack against your family without ever touching a password, using a synthetic version of you or a relative to manipulate someone else into acting.
The FBI's Internet Crime Complaint Center has warned that generative AI has cut the time and effort criminals need to build a convincing impersonation, and specifically advises limiting the public photos and audio available of family members.
What to actually do
- Treat your voice and face as data, not just content. Every public video, voicemail greeting, or livestream is a potential sample; you don’t have to stop posting, but default to private accounts for anything with sustained, clear audio or video of you or your children.
- Assume individual facts get cross-referenced. A convincing pretext rarely needs one dramatic detail — it needs three or four ordinary ones (a pet’s name, a travel date, a child’s school) combined into a plausible story. Be deliberate about which of these are ever public at the same time.
- Build social-engineering skepticism as a habit, not a lecture. AI has made phishing emails and pretexting calls dramatically more fluent and personalized; the old tells — bad grammar, generic greetings — are no longer reliable warning signs.
- Verify out-of-band for anything unusual, every time. A callback to a known number or your family’s agreed safe word (see Deepfake and Voice-Clone Defense) resolves doubt in seconds without insulting anyone.
What this doesn’t solve
None of this stops a determined, resourced attacker targeting your family specifically — no set of habits fully closes that gap. It also isn’t a substitute for account-level security: this page reduces what an attacker can find and use to build a pretext, while digital identity hardening reduces what they can do once they’ve found it. Both layers matter, and neither is complete without the other.
Sources
Federal Bureau of Investigationwarns that generative AI has cut the time and effort criminals need to build a convincing impersonation.
FBI Internet Crime Complaint Center, Primary
Full register of everything this manual cites: source index.