# Data Trafficking, "Trafficking", Data Flow Regulations, Genomics, and AI in Global Governance
**Jurisdictional Arbitrage, the Purchase Workaround, and Why Partial Data Is the Actual Threat**
I am not a criminologist and I am not prosecuting anyone. What follows is a description of pipelines — where data originates, which jurisdictions it crosses, which legal constraints it passes around rather than through, who pays for it, and what gets inferred at the far end. The people operating most of these pipelines are doing legal work for defensible reasons. That is exactly why the architecture deserves description rather than accusation.<!--more-->
The prevailing frame says we have a privacy crisis. That frame is wrong, and being wrong about it prevents anyone from seeing the actual structure. **We do not have a privacy problem. We have a precision-engineered data flow system operating as designed.** Data does not leak across borders by accident. It moves along routes built by people who understood the legal terrain, and the regulatory gap between what technology can do and what law has addressed is not a lag. It is where the work gets done.
## The Operator: Move the Cargo to the Jurisdiction
Here is the single mechanism underneath everything in this article, and it is one this body of work has already examined in another form.
When the United States transferred men to a Salvadoran terrorism confinement center under an eighteenth-century wartime statute, it was performing a specific operation: **moving cargo to a jurisdiction where the constraints binding at home do not apply.** Judge Boasberg's finding that the government retained "constructive custody" was significant precisely because it named the maneuver — the transfer was supposed to sever legal responsibility from physical control, and a court held that it did not.
Data pipelines run the identical operator with different cargo. A collection that would require a warrant if performed by an agency does not require one if performed by a company and purchased afterward. Genomic work constrained by domestic research ethics regimes proceeds under a different regime elsewhere. Behavioral analysis that a government could not lawfully conduct on its own citizens becomes a commercial product with a subscription. **In each case the constraint is not defeated. It is stepped around by relocating the activity into a body, a jurisdiction, or a contract to which the constraint does not attach.**
Call it what it is: **jurisdictional arbitrage**, and recognize that the word *trafficking* in the title is doing real work. Trafficking has always meant moving something valuable across a boundary specifically because the boundary changes its legal character. That is what these pipelines do, and it is why the euphemism-laden vocabulary around them — data flows, adequacy decisions, standard contractual clauses, onward transfer — reads like customs paperwork. It is customs paperwork.
## The Purchase Workaround
The clearest instance is domestic and fully documented, and it is the one American readers should understand first.
In *Carpenter v. United States* (2018) the Supreme Court held that acquiring historical cell-site location information constitutes a search requiring a warrant. The holding is unambiguous about the government's obligations when the government does the collecting. It says nothing about what happens when the government **buys** the same information from a company that collected it under terms of service.
That gap is not a theory. The Office of the Director of National Intelligence commissioned a review of **commercially available information**, completed in January 2022 and declassified in June 2023, which found that CAI is available in bulk, includes information sensitive enough that its collection by the government would previously have required legal process, can be used to identify individuals despite claims of anonymization, and raises precisely the concerns *Carpenter* addressed. That is the intelligence community's own panel, in its own words, describing a constitutional constraint being routed around by procurement.
The commercial layer supplying it is documented too. Meta sued **Voyager Labs** in January 2023 for creating more than 38,000 fake accounts to scrape over 600,000 users, in a product marketed to police — Meta's filing described the industry as providing services "including as a way to profile people for criminal behavior," and the matter settled with a permanent injunction in December 2024. The FBI separately contracted with **Babel Street**, which similarly offered collection through fabricated personas and relationship analysis. The Brennan Center has identified half a dozen more vendors pitching or contracted to law enforcement. **Palantir**, **Primer**, and **Two Six Labs** supply analytic layers on top. None of this required anyone to break a law. It required someone to notice that the law binds an actor rather than an activity.
## Cambridge Analytica as the Template
The canonical laundering chain is worth walking because its stages recur everywhere, and because it demonstrates that the mechanism does not need a state at all.
An academic researcher builds an app for stated research purposes. The app's permissions harvest not only its users but their social graphs — roughly 87 million profiles. Academic collection becomes a commercial asset when transferred to a private firm. The firm, positioned within a group with defense and information-operations lineage, sells psychographic targeting to political clients. At no point in that chain does the data cross an obvious threshold of illegality; it crosses **four changes of legal character** — research consent to platform terms to commercial ownership to political application — and each transition strips a constraint that applied at the previous stage.
That is the template. Collect under one justification, transfer under another, apply under a third. And the reason it recurs is that the intermediate steps are individually defensible, which is precisely the property that makes a laundering chain a laundering chain rather than a crime.
## Offshore Genomics
Genomic work is where the arbitrage has the highest stakes, and the reasons are structural rather than sinister.
Domestic human-subjects research operates under institutional review boards, informed consent doctrine, HIPAA where clinical data is involved, and a dense body of professional ethics. Those constraints exist for excellent reasons and they impose real costs in time, scope, and permissible experimental design. Work that cannot clear them domestically does not simply stop. It relocates — to jurisdictions with lighter review, to consortia with different governance, to commercial entities whose consent instrument is a checkbox, or to populations whose regulatory protection is thinner.
The consequence that matters is not primarily ethical. **It is that genomic data is a strategic asset with permanent value and no expiry.** A password can be changed and a location history goes stale. A genome does not. It identifies its bearer for life, identifies relatives who never consented to anything, and supports inference — ancestry, disease risk, and eventually far more — for as long as it exists anywhere. A population's genomic corpus is therefore a durable intelligence holding, which is why national security officials have warned about foreign collection of American genomic data and why the 23andMe bankruptcy proceedings turned a consumer genetics database into a live question of who acquires several million people's sequences and under what conditions.
## Crypto Runs Both Directions
Cryptographic infrastructure appears twice in this architecture and the two appearances are opposites, which is why treating it as one thing produces confusion.
On the acquisition side, **cryptocurrency is a settlement rail for transactions that want deniability.** Purchasing datasets, paying scrapers, compensating access brokers, and funding collection through intermediaries all become materially easier when settlement does not route through a correspondent bank with know-your-customer obligations and a compliance department that files suspicious activity reports. That is not a claim that any particular purchase happened this way. It is a claim about friction: **the pipeline described above has a payments problem, and one class of instrument solves it.**
On the governance side, cryptography is the only serious candidate for the thing the entire architecture lacks. **Provenance.** Verifiable credentials, content credentials and C2PA attestation, cryptographic signing at point of capture, decentralized identifiers, and hash-chained audit logs make it possible to establish that a given record originated where it claims, has not been altered, and passed through a specific chain of custody with specific authorizations. Applied to this problem, that machinery answers questions no privacy regime has ever answered: not *should this data exist*, which is a lost argument, but **who touched it, under what authority, and can any of it be reconstructed later if a person contests what was concluded about them.**
That is the same demand this body of work has made of every classifier in the collection. Provenance infrastructure sits between observation and adjudication so that whatever becomes actionable remains reconstructible rather than merely asserted — the architecture developed in [[The X Ledger|The X Ledger]] — and it is the only version of "data governance" that survives contact with an environment where the data is already everywhere.
## The War With Empire Layer
Now the strategic dimension, which has moved from argument to regulation in the last eighteen months.
Executive Order 14117, signed 28 February 2024, directed the Attorney General to restrict transactions giving countries of concern access to Americans' bulk sensitive personal data. The implementing final rule — DOJ's **Data Security Program**, codified at 28 CFR Part 202 — took effect **8 April 2025**, with full compliance expected by 8 July 2025, security and audit requirements from 6 October 2025, and enforcement actions beginning **6 October 2026**. DOJ describes the program in its own guidance as establishing "**what are effectively export controls**" preventing foreign adversaries from accessing government-related data and bulk **genomic, geolocation, biometric, health, and financial** data. The countries of concern are named: China including Hong Kong and Macau, Cuba, Iran, North Korea, Russia, and Venezuela.
Read that plainly. **The United States has classified human data as a controlled export, with genomic data at the top of the list.** That is not a privacy measure and it was never presented as one. It is a recognition that a sufficiently large corpus of a population's biological and behavioral data is a weapons-relevant material.
The reason is inference, and this is where the article's original insight about partial data becomes strategically load-bearing. An adversary AI does not need to steal a classified document to learn its contents. Given enough fragments — travel patterns, procurement records, personnel movements, health anomalies in a cohort, publication gaps, the sudden relocation of people with particular specialties — a sufficiently capable model reconstructs the shape of the secret from the negative space around it. **Aggregation defeats classification.** Every individually unclassified fragment is a term in an equation whose solution is classified, and the historical assumption that secrets are protected by controlling documents rather than by controlling correlations no longer holds.
Which is the actual content of not wanting to be captured by an adversary's AI. It is not a fear of surveillance in the ordinary sense. It is the recognition that **a model trained on enough of your population knows things about your state that your state never wrote down.**
## Partial Data Is the Threat
Which brings the argument to the claim I made in the original version and now want to state precisely, because it is the one people find counterintuitive and it is the one that connects this article to every other piece in this body of work.
The danger is not that too much is known. **The danger is that too little is known confidently.** A complete record is auditable, contestable, and correctable. A fragment is none of those things, and a system reasoning from fragments does not return uncertainty — it returns a confident answer built on a truncated input, because that is what these systems are constructed to do.
This is the classifier problem in its most general form and it is the through-line of everything I have written on this subject. A status classifier running on tattoos and nationality filled a terrorism facility with the wrong men. A susceptibility classifier operating in the non-criminal space flags children with no identified ideology. A targeting pipeline that accelerates generation without accelerating verification delivers each error with perfect precision. **In every case the failure is not excessive information. It is a decision made on partial information at a threshold set by someone who does not bear the error.**
Filtering, truncation, and selective disclosure are therefore not privacy protections. They are **error generators**, and the people they harm most are the ones whose full record would have exonerated them.
## The Constitutional Bind, Stated Honestly
Here is the tension this whole architecture exists inside of, and pretending it does not exist is what makes most writing on the subject useless.
There are things a society ought to be able to do that its constitutional order makes difficult. Identifying a person on a pathway toward mass violence early enough to interrupt it — and early enough to get him help rather than a cell — requires exactly the kind of pattern visibility across exactly the kind of correlated sources that domestic law constrains, correctly and for excellent historical reasons. That constraint has a cost measured in bodies, and anyone who denies it is not being principled but innumerate.
And the constraint does not eliminate the activity. **It relocates it** — to private vendors, to purchased data, to allied services under arrangements that raise their own questions, to offshore processing. The prediction and prevention apparatus mapped in [[The Prediction and Prevention Stack and the Institutions Building It|The Prediction and Prevention Stack and the Institutions Building It]] and the screening layer examined in [[Extremist Elicitation, Remediation, and Classification|Extremist Elicitation, Remediation, and Classification]] both run substantially on inputs of this kind. So the practical question is not whether the capability exists. It is whether it operates **inside a constraint regime or outside one**, and the current answer is: partly outside, in the places where nobody is required to say what they did.
That is the worst configuration available. The capability without the constraint is a status classifier waiting to happen. The constraint without the capability is a body count. **What is needed is not less data movement but governed data movement**, and the governance has to attach to the activity rather than to the actor — because attaching it to the actor is what created the purchase workaround in the first place.
## What Would Make This Legitimate
The same short list governs here as everywhere else in this work, and it translates cleanly into data terms.
**Mark the pathway, not the person.** What is retained durably should be the recurrence route and its provenance, not a permanent dossier on a human being, and no representation may become ontologically identical with the person it describes.
**Attach constraints to activities, not actors.** If a warrant is required to collect it, a warrant should be required to buy it. The purchase workaround is not a clever reading of *Carpenter*; it is a defect, and it is fixable by statute.
**Build provenance in.** Cryptographic attestation at capture, signed chain of custody, and reconstructible authorization are the only mechanism that makes any of this auditable after the fact — and auditability is what converts an accusation into a claim a person can contest.
**Build the clearing power into the flagging power.** Any system that can generate a designation must be able to remove one, and the subject must be able to invoke it. **The same instrument that implicates must be able to exonerate**, which is the strongest argument for complete records over fragmentary ones and the reason my original position on privacy was closer to right than it sounded.
**Run the maturation clock.** Opacity during the standing-up of a survival-critical capability may be unavoidable. Opacity that hardens into permanent asymmetry is the signature of every emergency regime that told a public it could not know yet and then arranged never to be asked again.
I said in the first version of this that I wanted all my data going everywhere, and people found that shocking. The refined version is narrower and I will stand on it: **I would rather be completely known by a system that must show its work than partially known by one that does not have to.** The first can be corrected. The second cannot even be argued with — and in a world where the pipelines already exist and the fragments are already moving, the fight worth having is not about the flow. It is about the ledger.
---
[[about/About Bryant McGill|Bryant McGill]] is a Wall Street Journal and USA Today bestselling author, systems architect, technologist, and strategic advisor, as well as a Congressionally Recognized Ambassador of Goodwill and United Nations–appointed Global Champion. His work spans naval intelligence systems, computational linguistics, artificial intelligence, digital transformation, and civilizational governance architecture. His forward analysis on U.S.–Israel Pax Silica frameworks has appeared in Jewish/Jerusalem News Syndicate (JNS).
---
## References
**Data export controls**
- [Executive Order 14117](https://www.federalregister.gov/documents/2024/03/01/2024-04573/preventing-access-to-americans-bulk-sensitive-personal-data-and-united-states-government-related), 28 February 2024.
- Department of Justice, [Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons](https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern), final rule effective 8 April 2025, 28 CFR Part 202.
- Covington & Burling, [DOJ Releases Guidance Regarding Implementation of Bulk Sensitive Data Executive Order](https://www.cov.com/en/news-and-insights/insights/2025/04/doj-releases-guidance-regarding-implementation-of-bulk-sensitive-data-executive-order).
**The purchase workaround**
- [Carpenter v. United States, 585 U.S. 296 (2018)](https://supreme.justia.com/cases/federal/us/585/16-402/).
- Office of the Director of National Intelligence, [Senior Advisory Group Panel on Commercially Available Information](https://www.dni.gov/files/ODNI/documents/assessments/ODNI-Declassified-Report-on-CAI-January2022.pdf), January 2022, declassified June 2023.
- Meta, [Leading the Fight Against Scraping-for-Hire](https://about.fb.com/news/2023/01/leading-the-fight-against-scraping-for-hire/).
- Brennan Center for Justice, [Meta Sues Surveillance Firm That Worked with Police](https://www.brennancenter.org/our-work/analysis-opinion/meta-sues-surveillance-firm-worked-police).
**Provenance infrastructure**
- [Coalition for Content Provenance and Authenticity (C2PA)](https://c2pa.org/).
- W3C, [Verifiable Credentials Data Model](https://www.w3.org/TR/vc-data-model/) and [Decentralized Identifiers](https://www.w3.org/TR/did-core/).
## Collection and ontology routes
This article enters the [[collections/Gamification|Gamification Collection]] as its jurisdiction-and-flow branch. It identifies a common maneuver: move data, capital, biological material, or persons until the originating jurisdiction's constraints no longer attach, then return an actionable result to the original system.
Follow [[wiki/Algorithmic Governance|Algorithmic Governance]] for the institutional use of returned outputs, [[wiki/Information Asymmetry|Information Asymmetry]] for the unequal visibility of the pipeline, [[wiki/Provenance|Provenance]] for reconstructing origin and transformation, and [[articles/gamification/Extraterritorial Removal of Domestic Extremists|Extraterritorial Removal of Domestic Extremists]] for the person-level analogue. [[articles/gamification/The X Ledger|The X Ledger]] offers the counter-design: persistent evidence whose transformations and adjudicative status remain traceable.