Skip to content
TrackPodcasts
newsSep 11, 202612:35

Sixty to Seventy Billion Faces, One Autonomous Dossier: Inside Clearview AI's InquiryIQ Prototype, September 11, 2026

About this episode

Sixty to Seventy Billion Faces, One Autonomous Dossier: Inside Clearview AI's InquiryIQ Prototype, September 11, 2026 Wired reporters discovered that facial recognition company Clearview AI has been quietly testing InquiryIQ, a prototype that goes beyond identification to autonomously scrape the web, run secondary face matches, and compile a full dossier of addresses, employers, and associates on the people it identifies. Chris and Laura break down how the tool works, the Grok model powering one of its options, and what it means for a database already holding tens of billions of scraped faces. Hosted by Chris and Laura. The DX Today Podcast brings you daily deep dives into the most consequential stories in the AI ecosystem. #ArtificialIntelligence #FacialRecognition #AIEthics #Surveillance #TechPolicy

Get every episode summarized

Each time DX Today | No-Hype Podcast & News About AI & DX publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

219 searchable segments. Every word is indexed and playable.

Sixty to Seventy Billion Faces, One Autonomous Dossier: Inside Clearview AI's InquiryIQ Prototype, September 11, 2026

DX Today | No-Hype Podcast & News About AI & DX

0:00
12:35

Full transcript

DX Today | No-Hype Podcast & News About AI & DXSixty to Seventy Billion Faces, One Autonomous Dossier: Inside Clearview AI's InquiryIQ Prototype, September 11, 2026. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Welcome to the DX Today podcast, your daily deep dive into the AI ecosystem. I'm Chris and joining me as always is Laura. Hey Chris and today we are going somewhere a little unsettling because we are talking about facial recognition, getting a generative brain grafted onto it. And I do not think most people have caught up to what that actually means yet. Okay, you have my full attention because facial recognition on its own already makes a lot of people nervous. So tell me what changed and why it is suddenly a much bigger deal than just matching a photo to a name. So the company is clear view the facial recognition firm that built a database somewhere between 60 and 70 billion scraped images and reporters at wired found that they have been quietly testing a new layer called inquiry IQ that does not stop at identification at all. Right because historically the pitch was always narrow and officer uploads a photo. The system spits back a name and maybe a confidence score. And that was the entire transaction. So what does this new layer actually add on top of that? In Quarry, Komasa Nav on a quiet Q picks up exactly where that face search leaves

off and it starts autonomously crawling the open web, browsing pages, pulling in additional photographs and running a second round of facial recognition on whatever it discovers, which is a completely different scale of automation. So it is not just confirming the one match anymore. It sounds like it is going out and building an entire web of connections around that person, which honestly starts to sound less like a lookup tool and more like an automated investigator working around the clock. That is exactly the phrase investigators use internally. They call the output a candidate graph and it is designed to compile potential addresses, phone numbers, employers, aliases, social media accounts, and even arrest histories in a one consolidated profile. The officer can just scroll through. And I have to ask because this is the part that would worry me most is any human actually checking whether the underlying face match was even correct in the first place before all of this secondary information gets stacked on top of it. The interface does include warnings that findings may be inaccurate and it does

require the officer to confirm independent verification before anything gets added to a formal case file, but a warning label is very different from a system that structurally prevents the mistake from happening. That distinction matters enormously because we've already seen what happens when confidence in a match outpaces the actual reliability of the match. And I know there's a specific case people keep bringing up that illustrates exactly that failure mode in practice. There is a Minnesota Federal surveillance case where defense lawyers documented an officer who accepted every single result the system returned, including the low confidence ones and the resulting report ended up containing photographs of the wrong person along with members of his own family. So the very failure mode critics warned about with the original face search tool is already sitting in the public record. And now you're telling me the company wants to layer an autonomous webcrawler and a second facial recognition pass on top of that same foundation. Exactly. And here's the detail that made my jaw drop a little one of the models investigators can choose from inside this prototype is the Grock chatbot from XAI.

The same model that posted anti-Semitic messages praising Hitler back in 2025. Wait, I want to make sure I heard that correctly. So the tool that is quietly building dossiers on private citizens for law enforcement offers a version powered by the same chatbot that had a very public and very ugly meltdown just last year. That is correct. And clear views framing is that the option exists purely so engineers can compare different models against each other during internal testing. It is not necessarily what would ship to an actual customer, but the fact that it was even wired in at all raised eyebrows. I think a lot of listeners would reasonably ask why any vendor building a law enforcement surveillance tool would want that particular chatbot anywhere near the pipeline given how thoroughly documented that instant already was across basically every major news outlet at the time. Clear views public statement is that inquiry IQ remains strictly an internal prototype. It has never been pitched to a customer, never shipped to a customer, and never actually used by law enforcement in the field.

And the company says it currently has no plans to release it in its current form. Okay. But if it was never shipped and never pitched, how exactly did reporters even find out this thing existed? Because internal prototypes do not usually surface in the press unless something went wrong on the company's end of things. This is my favorite detail in the entire story. Wired's researchers found the inquiry IQ files were actually loaded by clear views public facing log in page, meaning the code was technically reachable without any account credentials at all, which is a pretty remarkable way for a secret prototype to leak. So the tool that's supposed to be locked away for internal testing only was sitting in code that loads on the same page anyone on the internet can visit. And that is how a story about a secret dossier builder becomes a public dossier builder story. Right. And it is worth remembering the broader context here too because clear view already operates under a 2022 settlement with the American civil liberties union that restricts its paying customers specifically to vetted government and

law enforcement agencies, not random private companies or individuals. So this is not some scrappy startup with zero oversight. This is a company that has already been through a major civil liberties settlement is already restricted in who it can even sell to and is still testing a tool that's aggressive behind the scenes without disclosing it publicly. And that ACLU settlement is really just one layer of a much longer legal history because clear view has also faced years of litigation under Illinois's biometric privacy law and regulators in the United Kingdom, France and Italy have all separately find the company millions of euros for scraping residents' faces without consent. Right. And my understanding is clear view has mostly just ignored those European fines outright arguing it does not operate there and therefore is not bound by those orders, which tells you a lot about how enforcement against the facial recognition company can completely stall out across borders. That cross-border enforcement gap is exactly why a story like this lands differently depending on where you sit.

Because in parts of Europe, this business model would likely be illegal outright. While in the United States, it has mostly operated in a patchwork of state level rules and one-nero class action settlement. And government interest in the broader platform is very real in growing. Regardless of that patchwork, customs and border protections sought around 15 additional clear view licenses back in February of this year for intelligence personnel at the National Targeting Center, specifically to support what they called strategic counter network analysis. Counter network analysis is a pretty clinical way of describing mapping out who talks to who, who lives with who and who works with who. And that is precisely the kind of relationship mapping that inquiry IQ's candidate graph appears to be purpose built for from the ground up. It really is. And the accuracy claims underneath all of this are not nothing either. Clear view sites testing from the National Institute of Standards and Technology, putting their core face matching above 99% accuracy across different demographic groups. So the underlying identification engine is genuinely strong on paper.

That accuracy number is actually the part that makes this more complicated for me rather than less because a system that is right, the vast majority of the time can still produce a small percentage of devastating wrong matches once you are running it against a database of 60 to 70 billion faces. That is the paradox of scale in a nutshell, even a fraction of a percent error rate turns into a meaningful number of real people. Once you multiply it across billions of images and countless daily searches, and each one of those errors is a real person's life getting disrupted in some way. And once you bolt an autonomous web crawler onto that same imperfect foundation, any single misidentification does not just produce one wrong name anymore. It produces an entire fabricated life story complete with addresses, employers, relatives, and alleged criminal history all built around the wrong person entirely from start to finish, which brings us back to why this feels like such a meaningful escalation rather than just another incremental feature update.

Because the jump from returning a name to autonomously constructing a full relationship graph changes the entire risk profile of what a single mistake and match can actually cause downstream. I keep thinking about how this compares to the earlier debates we have covered about facial recognition bands and individual cities, because those fights were mostly about whether the identification step itself should even be allowed. And this leapfrogs way past that argument entirely into something regulators have barely begun to define. It does. And it also raises a question, regulators have not really caught up to yet, which is whether oversight rules written for a simple face match tool, even apply to a system that autonomously scrapes the web, runs secondary recognition and compiles a dossier without a human directing every step. There is also a much bigger pattern here worth naming out loud, because this is really the same conversation the entire industry is having right now about a genic systems generally, where a model stops answering one question and starts taking along and supervise chain of actions on someone's behalf.

That is a great point, because when an agentic system books a flight or drafts an email, a mistake is usually annoying and recoverable. But when an agentic system is quietly assembling a law enforcement dossier on a real person, the exact same unsupervised chain of actions carries a completely different kind of consequence. And there is a term researchers have started using for exactly that pattern, sometimes called hallucination laundering, where a chatbot's confidence sounding, but occasionally wrong text gets stapled onto an official document and then treated with far more institutional weight than the underlying model actually deserves in the first place. It is worth adding one more layer to that agentic framing too, because most agentic products we cover on this show are aimed at drafting documents or managing calendars. And this is one of the first mainstream examples of that same architecture being pointed directly at real people's private lives. That framing really does change how I am hearing everything we have described today, because we usually talk about agentic risk in terms of wasted time or

a botched email. And this conversation is a reminder that the exact same underlying pattern can carry consequences for someone's freedom and safety. So where does this actually go from here? Because clear view says there are no current plans to release it. But companies say that about prototypes fairly often right before market pressure or a government contract, quietly changes their mind entirely down the road. My honest read is that the technical capability is clearly built and clearly works well enough to demo. So the real constraint from here forward is going to be legal and political pressure rather than anything remotely technical. And that pressure is only going to intensify now that wired has put it in public view. It also makes me think about ordinary listeners who have never been arrested, never been under investigation and have no idea their face is already sitting in a database this large because there was never any meaningful way to consent to being scraped in the first place. That is really the uncomfortable core of this whole story. Almost everyone with a public photo online is already a candidate graph waiting to be generated.

And the only real check on whether that graph gets built responsibly right now is journalism, litigation and whatever internal restraint the company chooses to exercise voluntarily. Voluntary restraint is a pretty thin safety net when the underlying technology is this capable and this cheap to run at scale, especially once you consider how quickly other vendors tend to copy a feature. The moment one company proves it is technically possible to build, which is exactly why some legislators are pushing to extend biometric privacy laws to explicitly cover this kind of downstream automated profiling rather than just regulating the initial face scan the way most of the older statutes were originally written to do back when this all started. That is a great way to frame where we leave the story because the technology already exists, whether or not it ships as a product. And the conversation society needs to have now is entirely about whether anyone should be allowed to deploy it at the scale in the first place. Couldn't agree more. And I think the Minnesota case is the detail worth holding on to here because it already showed us what happens when confidence outpaces accuracy

at a much smaller scale than a fully autonomous dossier builder. And that should worry anyone paying close attention to where this is heading next. That's all for today's episode of the DX today podcast. Thanks for listening and we'll see you next time.

More episodes

More from DX Today | No-Hype Podcast & News About AI & DX

View all episodes →