Earlier this summer, the General Services Administration awarded Xcelerare Solutions and its subcontractor, Socure, a five-year, $163 million contract to run AI identity checks through Login.gov, the front door most Americans use to access their federal services and benefits. In practice, this means that one of the major AI vendors now sits behind the login page for nearly every layer of government.
Socure and similar firms belong to a category of companies that have slipped beyond the reach of nearly every privacy protection we have. These companies are called Massive Data Aggregators, and they have become the de facto gatekeeper to American services.
These companies make money by scraping billions of data points about you available online, ranging from geolocation history to keystroke patterns to your social media habits, and feed them into an AI model that creates a risk score or a behavioral profile about you and sells it to those willing to pay for it. And this differentiation matters because nearly every data broker law on the books defines a data broker by revenue from selling raw data. So, companies that sell a score that is derived from your raw data bypass this type of legislation.
This is not a loophole they stumbled into. It is a deliberate architecture model.
Voters have started to take note, too. In a recent Cygnal poll, 81.3 percent of respondents said a company that scores your data should follow the same types of rules as the companies that sell it directly.
Individuals who have been de-banked, denied credit or otherwise pushed out of the financial system often have thin, inconsistent or outdated data trails. These create the gaps that a Massive Data Aggregator’s model fills in with inferences about who that person is.
Take a rural person who has no regular paycheck, sporadic credit activity tied to a seasonable outcome, a rural route address that doesn’t match standard postal formats, or little-to-no digital footprint. To an AI model trained on salaried or digitally active norms, that rural person doesn’t look consistent. Instead, he looks suspicious and will likely be flagged. Consequently, that individual will have a tough time getting through. The same scenario is plausible for a business owner who takes most of his income in cash or a retiree living on Social Security with no active credit line.
None of these instances are fraud, but they do exist outside the narrow band of behavior these AI risk-scoring models are designed to recognize, and a negative risk score can be detrimental. This is called debanking, and Massive Data Aggregators are the engine that can automate it on a national scale.
A few weeks ago, Socure announced it was going one step beyond checking someone’s identity once and is moving toward continuous monitoring. That means evaluating a person’s risk on a continuing basis throughout the lifecycle of an account, with no recourse to correct. It’s the same type of deal that’s already drawing public scrutiny with companies like Amazon’s Ring, for example. Socure is proposing the same always-on model for your identity that Americans are already largely against. In that same Cygnal poll, 91.6 percent of respondents rejected the idea that AI has the final say over whether or not someone gets access to a government benefit.
Fraud is real, and taxpayers deserve protection from it. However, we’ve let Washington scale a $163 million surveillance machine without basic guardrails. We need to require independent audits of these systems’ accuracy, guaranteeing that a human being can review and correct any wrongful denial or red flag in a timely manner that doesn’t negatively affect the user, forcing real transparency about what’s being tracked and where that information is coming.
Currently, Massive Data Aggregators have free rein and no one is holding them accountable. Lawmakers need to define Massive Data Aggregators through legislation like an expanded Data Broker Registration Act and regulate them the way we regulate data brokers.
Americans deserve to know whether a company is collecting their most personal details to infer their party registration, veteran status or where their kids go to school based on ordinary data points that you didn’t agree to hand over. Americans deserve full autonomy over their data. And they deserve the right to see it, challenge it, and take it back efficiently and on time.














Gerard Scimeca | INSIDE SOURCES
Recent Articles
Chino Valley Animal Shelter Reduces Adoption Fees as Shelter Reaches Capacity
Findlay Subaru Prescott Hosts “Puppy Wish Party” to Surprise Local Wish Kid with Her Dream Dachshund
Victory Wealth Services Announces Annual Sock Drive to Support Local Homeless Shelters
Free Garden Classes for September at Watters Garden Center