The Inference You Never Agreed To
Cambridge Analytica was never about the data people gave up. It was about what could be worked out about the people who gave up nothing. Meta just made that the business model.
The scandal was never the data they took
In 2013, roughly 270,000 people took a personality quiz on Facebook. They were paid a dollar or two each. They consented. From those 270,000 quizzes, a firm called Cambridge Analytica walked away with the profiles of up to 87 million people, almost none of whom had ever heard its name. The 270,000 was the consent. The 87 million was the inference.
That gap, between what people handed over and what was worked out about them, is what put Mark Zuckerberg in front of the United States Congress. On 16 December 2025, Meta turned the same gap into a privacy policy.
Go back to what the app collected. It was called This Is Your Digital Life, built by a researcher named Aleksandr Kogan. People answered some questions. The app read their Facebook likes. On its own, a list of pages someone has liked is close to worthless. A few hundred thousand people admitting they like a band, a brand, a footy team. Nobody pays much for that.
What Kogan’s collaborators did with it is where the value sat. They ran the likes through a model that turned them into personality scores, the five-trait profile psychologists call OCEAN: openness, conscientiousness, extraversion, agreeableness, neuroticism. From there came predicted political leanings, predicted susceptibility to particular messages, predicted who could be moved and who couldn’t. None of that was collected. All of it was derived.
The 87 million figure tells you where the deriving pointed. Fewer than 300,000 people took the quiz. The rest were reached through their friends, harvested through a Facebook feature called Open Graph that let an app pull data on the friends of anyone who installed it. Those people were never asked. They never saw a consent screen. They became profiles because someone they knew clicked a button.
The lesson the world took from this was “Facebook leaked data.” The lesson it should have taken was a different one. The thing of value was never the raw data. It was the inference built on top of it. The records were the raw material. The conclusions were the product.
Hold onto that, because it’s the whole story of what’s happening now.
You can withhold a fact, you can’t withhold a conclusion
Most of how we think about privacy is built around disclosure. You decide what to share. You read the box, you tick it or you don’t, you hand over your email or you keep it back. The law works this way too. Consent. Notice. The right to see what’s held about you. Every one of those mechanisms assumes the thing being protected is the thing you disclosed.
Inference breaks that assumption.
The value in modern data isn’t in the facts you typed. It’s in what can be worked out by matching those facts against everyone else’s. You didn’t tell them you were pregnant. You changed your browsing in a way that, across millions of other people, lines up with early pregnancy. You didn’t tell them your marriage was in trouble. Your messaging to one person dropped off in a shape the model has seen ten thousand times. You didn’t disclose your politics. You don’t have to. The system reads them off a hundred signals you’d never think to hide.
How strong is the matching? In 2015, researchers at Cambridge’s Psychometrics Centre showed that a model fed nothing but a person’s Facebook likes judged their personality more accurately than their colleagues, their friends, their family. Ten likes were enough to beat a work colleague. A hundred and fifty beat a parent or a sibling. Three hundred, and the model read the person more accurately than their own husband or wife. That was a decade ago, on public likes alone, before anyone had handed a machine their private conversations.
This is the part that defeats consent. You can choose what to disclose. You cannot choose what can be concluded about you from what you’ve disclosed, and from what the people around you have disclosed. A conclusion isn’t something you hand over. It’s something done to you. The privacy debate has spent twenty years arguing about the first and ignoring the second.
Cambridge Analytica was the proof of concept. A few hundred thousand disclosures, matched and modelled, produced usable predictions about tens of millions of people who disclosed nothing. The harvesting was the scandal of the week. The matching was the real capability, and it never went away. It got better.
Meta didn’t need a loophole this time
What made 2018 a scandal was that it was unauthorised. A third-party app exploited a feature it shouldn’t have had. A researcher passed data to a political firm against Facebook’s terms. There was a villain to name and a loophole to close. Facebook could stand up, shut Open Graph, pay its fine, and present itself as the wronged party. The FTC eventually imposed a $5 billion penalty, the largest it had ever handed down for a privacy violation. The framing throughout was breach. Somebody took something they weren’t supposed to.
In December 2025, Meta did the same kind of thing with none of the breach.
On 1 October 2025, the company announced that from 16 December it would use people’s interactions with Meta AI, its assistant, to target advertising and personalise content across Facebook, Instagram and WhatsApp. It’s not only the typed conversation. The change covers every interaction with the assistant: the questions you ask, the voice you speak to it, the images it generates for you, and the photos and videos you hand it to look at, including the ones captured through Meta’s Ray-Ban glasses. No rogue app. No leak. No third party. The data goes straight from you to Meta and stays inside Meta. Everything Cambridge Analytica had to steal, Meta now gathers through the front door, with a policy update standing in for the break-in.
There’s no opt-in. There’s no opt-out. If you don’t want your conversations feeding your ad profile, your only move is to stop using Meta AI altogether. The change applies almost everywhere. The exceptions are the European Union, the United Kingdom and South Korea, the places where privacy law is strong enough to force Meta to carve them out.
That carve-out is worth sitting with. Meta knows exactly which jurisdictions won’t let it do this. It’s doing it everywhere else.
The regulators were warned. A coalition led by the Electronic Privacy Information Center asked the FTC to step in and halt the practice before it started, arguing that Meta was building the precise kind of profiling its 2019 settlement was meant to restrain. The chatbot data started flowing on schedule.
The confessional is the richest data source ever built
Here’s why the chatbot matters more than anything that came before it.
For twenty years the raw material of the targeting machine was behaviour. What you liked, what you clicked, where you paused, who you followed. Rich, but oblique. The machine had to infer your interior from your exterior, because the interior was the one thing you never typed into a public box.
A chatbot collapses that distance. People tell a chatbot things they would never post. They ask it about the lump they found. They paste in the email from the lawyer. They talk about the marriage, the debt, the diagnosis, the thing that’s keeping them up at two in the morning. The whole design of the thing invites disclosure, because it feels like a private conversation and not a form. It feels like talking to someone who’s listening.
It isn’t. It’s the most direct line into a person’s interior that consumer technology has ever built, and since December it’s wired straight to the ad machine.
There’s a structural pull here that one Fortune piece named plainly. Once your conversations are the asset, the incentive is to build the bot to keep you talking. Engagement stops being about time on a feed and becomes about depth of disclosure. The longer and more openly you talk, the more there is to mine. A product that profits from your confessions has every reason to become a better confessor.
Cambridge Analytica had to model your personality from your likes. Meta doesn’t have to model it. You’re telling it directly.
The cleanest case is a child who never had an account
And you’re rarely only talking about yourself. Look again at who was in that 87 million. Most of them never took the quiz. They were profiled through someone else’s friend list, reached because a person they knew clicked a button. You didn’t have to touch Cambridge Analytica to end up in its model. You only had to know someone who did.
Facebook has been building profiles of people who aren’t on Facebook for years. They’ve got a name: shadow profiles, assembled from users’ uploaded contact lists, from the like button sitting on millions of other websites, from tracking pixels scattered across the internet. In 2018, Zuckerberg told Congress the company collects data on people who never signed up. Pressed by Representative Ben Luján about profiling people “who have never signed a consent,” he said it was for security.
The chatbot pours petrol on this. People don’t only confess about themselves. They describe everyone in their lives. A grandparent asks for advice about a grandchild. A parent pastes in the email from the school. Someone types out a partner’s drinking, a sibling’s diagnosis, the details of an ex in a custody fight. Names, ages, schools, health, relationships, all attached to people who never opened the app.
Then there’s the camera. Meta now sells glasses with a lens on the front, and the pictures and video they capture can be analysed by its AI and used to point ads. Worn at a kid’s birthday party, they turn everyone in frame into input: the children who can’t consent, the parents who never agreed to be recorded, the neighbour who only came for the cake. The shadow profile used to be built from contact lists and like buttons. Now it can be built from a lens on someone’s face.
The sharpest version is a child. A minor can’t consent in law. They’ve got no account to delete, no setting to find, no notice they were ever told. A profile of them starts building the moment the adults around them start talking to the machine, assembled before they’re old enough to know the platform exists, and waiting for them when they are.
Consent was meant to be the protection. Inference walked around it. Then it walked around membership, because you needn’t be on the platform to be modelled by it. Here it walks around the last line of all. The system doesn’t need you. It needs someone who loves you and a text box.
The exclusions give the game away
Surely the sensitive stuff is walled off. Meta says it is. It won’t use the most sensitive categories of conversation to target ads: religion, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, trade union membership. Read that list back. It’s a near-perfect inventory of the things people most need protected, which means Meta knows precisely what it’s sitting on.
Two problems with the reassurance.
The first is in the fine print. Those conversations won’t be used to target ads, but they can still be stored and used to “improve” the product. The sensitive disclosure doesn’t get targeted. It still gets kept. It still trains the machine that profiles everyone.
The second is the one this whole piece is about. You don’t need the protected fact if you can infer the proxy. Meta doesn’t have to record that someone is gay to show them ads that track with it; it has the adjacent signals that predict it. It doesn’t have to log a religion or a voting intention when a thousand other data points stand in. The redline sits on the disclosed fact. The inference walks straight around it. A ban on collecting the sensitive category, with the matching engine left running underneath, protects almost nothing. It protects the word. It leaves the conclusion untouched.
The line they drew today, they can move tomorrow
Here’s what the December change doesn’t touch. The decade of photos already sitting in your account, the back-catalogue of faces and places and dates, isn’t in it. That change is about your interactions with the assistant from here on. The old archive sits to one side.
That boundary is a choice. It’s a setting in a policy document, and policy documents get edited. This change was an edit. The one before it was an edit. Nothing in the architecture keeps the archive out. There’s a sentence holding it back, and sentences get rewritten on a Tuesday with a notification nobody reads.
Meta has already moved this exact line once. Since June 2024, its policy lets it train Meta AI on the public posts and images of every adult user, the historical archive included. Captions, comments, Stories, photos going back years. The back-catalogue is already feeding the model. The only question left is which uses get switched on next.
Then there’s the scale. Facebook and Instagram together hold the largest private collection of human photographs ever assembled. Decades of weddings, funerals, hospital visits, kids growing up one frame at a time, most of it tagged with names, dates, locations and who’s standing next to whom. No government ever built a face-and-life dataset like it. It’s sitting there, already labelled by the people in it.
Even the opt-out admits the trap. In the places where you can object, Meta says your data can still be used if you turn up in a photo someone else posted, or get named in their caption. The escape hatch doesn’t cover the people the system is best at reaching through someone else.
The aperture has only ever widened. No policy update has narrowed it. The archive will be pulled fully into the targeting and inference machine. The open question is when the policy says so, and whether anyone notices the Tuesday it does.
This is the same machine that ran in 2016, now it’s infrastructure
In 2016, psychographic targeting was a hack. A bolt-on, riding on stolen data, run by a firm most people had never heard of, scrambling to turn harvested likes into campaign messages. It was crude, it was contested, and people still argue about how well it worked.
What’s being built now is something else. It’s infrastructure.
Meta is spending on a scale that’s hard to hold in your head. Its 2026 capital guidance runs to as much as $135 billion, reportedly close to two-thirds of the revenue it expects that year. It’s building data centres named like something out of mythology. Prometheus, due online in 2026. Hyperion, in Louisiana, a complex Zuckerberg has described as eventually covering a footprint comparable to a serious slice of Manhattan. The stated aim is fully automated advertising by the end of 2026, where the machine generates and targets the ads with the human taken out of the loop, and a personal AI agent sitting with every user.
Sit those facts beside each other. The richest interior-data source ever built, feeding the largest privately owned persuasion engine ever built, aimed by automation at whatever outcome someone is willing to pay for.
One line in all of this gets less attention than it earns: fully automated advertising. When a human writes an ad, a human can be held to it. Someone approved the message, and the message can be shown to a journalist, a regulator, an opponent. When the machine generates a unique message for one person and shows it to no one else, that check disappears. The ad that moved you was assembled for you, seen by you, and gone. This is the dark-ads problem from 2016, the worry that political messages could be micro-targeted with no public record, built into the plumbing and run at population scale.
In 2016, moving an election meant someone had to steal the data first. By 2026, the data arrives with consent, the profiles are built continuously, and the targeting runs itself. The capability that took a scandal to assemble last time is standing infrastructure now, available to any advertiser, including the political ones, every day of the year. Nobody has to steal a thing. The machine is on, and it’s for hire.
Security is the smaller half of the problem
Most of the worry about all this gets filed under security. Could it be breached. Could it leak. Could a bad actor get inside. Those are fair questions, and the history isn’t reassuring. But the security framing misses the larger harm, and it misses it badly.
Grant Meta perfect security. No breach, ever. No leak, no rogue app, no repeat of 2018. The inferred profile of you, the one assembled from your conversations and your behaviour and the conversations and behaviour of everyone like you, still exists. It’s still accurate. It’s still rentable by anyone who can place an ad.
That’s the harm. The profile doesn’t have to escape to do its work. It only has to exist, sit in good order, and be there to be aimed at you. The breach model pictures the danger as the data getting out. The danger is the data working as designed, in a system doing exactly what it was built to do.
You can’t patch your way out of that. There’s no security control that protects you from a conclusion that was meant to be drawn. The thing you’d most want kept safe is a thing that, on every axis that counts, shouldn’t have been built.
Democracy in the age of inference
You can change a password. You can get a new card, a new email, a new number. Every defensive move privacy hands the individual assumes the thing at risk is a piece of information you hold and can rotate.
You can’t rotate a conclusion. The profile a system has built of you, out of a decade of your signals and a billion other people’s, isn’t a credential you control. You can’t change it, see it, or take it back. You can stop feeding it. It’s already built.
That’s why consent was the wrong unit all along. We spent twenty years arguing about what people should be willing to share. Ticking boxes. Reading notices. Opting in and opting out. The whole debate assumed the danger lived in disclosure. The danger lived in derivation, and derivation never needed your permission.
Here’s where it lands on democracy. A citizen’s vote is meant to come from their own reasoning, formed in their own time, out of reach of any single party that knows precisely which fear to press and precisely when to press it. Cambridge Analytica was a warning that this could be engineered at scale. The response was outrage, a fine, a round of hearings, and then the machine that made it possible got rebuilt. Bigger. With the data flowing in by consent and the targeting running itself.
The question was never what you’re willing to share. It’s what can be known about you whether you share it or not, and who gets to act on that knowledge in the weeks before you vote.
In 2018 we called it a scandal. In 2025 Meta called it a privacy policy. The only thing that changed is that this time, nobody had to break in.