SELINA.ai
Sign in

What Is Surveillance Pricing, and Why It's Splitting Off as Its Own Regulatory Fight

If you sell anything online, or if you buy anything online, the term "surveillance pricing" is about to matter to you more than most of what passes for AI regulation. What is surveillance pricing? It is the practice of using personal data about an individual consumer (browsing history, location, device type, purchase patterns, demographics) to set a price specifically for that person. Not based on supply and demand. Not based on inventory. Based on you. Regulators spent the last two years lumping it in with general AI governance. They are now pulling it out into its own lane, with dedicated hearings, state-level bans, and a vocabulary precise enough to write enforceable law around. That shift matters.

Key Takeaways

How Did Surveillance Pricing Become a Distinct Regulatory Category?

It became distinct when regulators got precise enough to draw a line. The key distinction, now formalized across multiple legislative and enforcement contexts, separates dynamic pricing from surveillance pricing. Dynamic pricing adjusts based on market-level signals: how many seats are left on a flight, what time of day it is, how much demand exists for a hotel room on a holiday weekend. Surveillance pricing adjusts based on signals about you specifically: your zip code, your browsing history on the retailer's site last Tuesday, your device type, your inferred willingness to pay.

That distinction sounds obvious once you hear it. But it took years to get there. For a long time, both practices were discussed under the same umbrella of "algorithmic pricing," and regulators didn't have the vocabulary to write rules that would hit one without hitting the other. Airlines have used yield management (dynamic pricing by any other name) since the 1980s. Nobody serious wants to ban that. The problem is when the algorithm stops looking at how many seats remain and starts looking at whether you searched for the same flight three times on an iPhone 16 Pro Max from a high-income zip code.

The vocabulary problem is real. If your law says "AI-driven pricing," you've banned surge pricing on ride-shares and markdown algorithms at grocery stores. If your law says "surveillance pricing," you can target the practice of using personal behavioral data to extract higher prices from individual consumers. Regulators spent most of 2024 and 2025 struggling with that distinction. By early 2026, they had it.

What Happened to Make This Urgent?

A handful of concrete events pushed surveillance pricing from policy-wonk territory into mainstream political salience.

In December 2025, Consumer Reports documented Instacart charging different shoppers up to 23% more for identical items in the same store. Not different stores. Not different days. The same store, the same item, different prices for different people. That finding did more to accelerate legislation than any white paper.

By January 2026, California's Attorney General launched an investigative sweep, sending inquiry letters to retailers, grocery chains, and hotels about how they use browsing history, location, and demographics to set individualized prices.

In March 2026, the House Committee on Oversight and Government Reform opened a formal investigation into AI-driven surveillance pricing at travel and platform companies. By May, the House Energy and Commerce Committee launched a separate inquiry focused on grocery and retail pricing. Two committees, two investigations, same issue. That's how you know a topic has escaped the gravity of "general AI governance" and become its own thing.

On August 4, 2026, the Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing with an unambiguous title: "Your Data, Their Profit: The Consumer Cost of AI Surveillance Pricing." Not "AI Ethics in Commerce." Not "Algorithmic Fairness." Surveillance pricing, named and isolated.

Which States Have Already Passed Surveillance Pricing Laws?

Three states have enacted bans as of mid-2026, with dozens more in progress.

Maryland was first. On April 28, 2026, the governor signed the Protection from Predatory Pricing Act, banning the use of surveillance data to increase prices in certain industries. Connecticut followed. Then New Jersey enacted the Fair Pricing Protection Act on July 24, 2026, focused on grocery and delivery, with penalties framed around protecting what the bill's sponsors called "shopping cart privacy."

New York passed a disclosure-oriented law rather than an outright ban. And 40 more bills have been introduced across 24 states in 2026 alone.

The numbers matter less than the pattern. This is not a single state doing something unusual. It is a wave, and it is accelerating faster than most founders I talk to realize.

What Are the Two Competing Regulatory Models?

Two fundamentally different approaches are emerging, and which one wins in your jurisdiction determines what you actually have to build.

The first model is disclosure. New York and Connecticut have leaned this direction. The requirement: tell the consumer that the price they see has been personalized based on their data. The theory is that transparency gives consumers the power to respond (clear cookies, use a VPN, shop elsewhere).

The second model is prohibition. Maryland's law and California's proposed AB 2564 take this approach. Don't just tell the consumer. Stop doing it. California's proposed bill includes fines up to $12,500 per violation.

Critics of the disclosure model argue, with some justification, that telling a consumer "this price was personalized for you" doesn't give them a meaningful way to respond. You can't un-browse. You can't change your zip code. The information asymmetry is structural: the retailer has a model trained on millions of transactions; you have a price tag and a vague sense that it might be wrong.

Critics of the prohibition model argue that the line between "market data" and "personal data" is blurrier than legislators think. If a retailer raises prices in a neighborhood because aggregate purchase data shows higher willingness to pay, is that surveillance pricing or dynamic pricing? The answer depends on how granular the data is, which is exactly the kind of fact-intensive question that makes enforcement hard and litigation expensive.

Why Is This Splitting Off from General AI Governance?

Because it is concrete enough to legislate. Most AI governance debates are still stuck at the level of principles. "AI should be fair." "AI should be transparent." "AI should be accountable." These are fine as aspirations. They are nearly useless as compliance requirements.

Surveillance pricing gives regulators something they rarely get: a specific, measurable, consumer-facing harm tied to a specific data practice. Did the algorithm use this person's browsing history to set their price? Yes or no. Did the company collect location data and pass it to a pricing vendor? Yes or no. These questions have answers. That makes them enforceable.

This mirrors a broader pattern in how AI regulation actually matures. It doesn't advance as a single coherent framework. It splinters. Deepfake laws split off from general AI governance. Algorithmic hiring laws split off. Now surveillance pricing is splitting off. Each sub-domain gets specific enough to write enforceable rules only when regulators develop vocabulary precise enough to distinguish the practice they want to regulate from adjacent practices they don't.

For founders watching this space, the fragmentation is actually useful information. Precise definitions create concrete compliance requirements. "Was this price based on individual data or market data?" is a question your system architecture can answer, if you designed it to. "Is your AI responsible?" is not.

Is the Real Problem the Price or the Data Collection?

The data collection. The price is the symptom people notice. The data infrastructure required to generate that price is the structural problem.

To set a personalized price, an algorithm needs to know who you are. It needs your browsing history, your purchase history, your location, your device, your inferred demographics. It needs to build a behavioral profile rich enough to predict your willingness to pay. That profile doesn't just sit in the pricing engine. It exists in the company's data warehouse. It gets shared with analytics vendors. It creates surface area for breaches, for secondary uses the consumer never contemplated, for resale to third parties.

The Groundwork Collaborative's testimony to the Senate makes this point directly: surveillance pricing inherently incentivizes more invasive data collection. The practice itself creates privacy harm independent of whether the resulting price is "unfair." Even if the algorithm decides to charge you the same price it would have charged anyone else, the company still had to build a detailed behavioral profile of you to make that determination. The surveillance happened. The pricing was just the business justification for it.

This framing matters for how you think about compliance. If surveillance pricing laws only regulated the pricing outcome, you could comply by running the algorithm and then discarding the result when it would violate the law. But if the laws (and the enforcement theory behind them) target the data collection that makes surveillance pricing possible, then the only durable compliance strategy is to not collect the data in the first place.

What Does the JetBlue Lawsuit Signal?

It signals that private litigation is arriving alongside regulatory enforcement, which means the risk surface is wider than just agency action.

On April 22, 2026, a plaintiff filed suit against JetBlue Airways, alleging that its use of individualized consumer data collected through website tracking and shared with third-party analytics and pricing vendors violated federal and state privacy and consumer-protection laws. The complaint doesn't just argue "the price was unfair." It argues that the data pipeline itself (collection, sharing with vendors, use for individualized pricing) violated existing law.

This is notable because it doesn't require new legislation. The plaintiff is using existing privacy and consumer-protection statutes. Surveillance pricing laws will add new causes of action, but the JetBlue case shows that the data practices underlying surveillance pricing may already be actionable under current law. If you are collecting behavioral data and passing it to pricing vendors, your legal exposure may predate any surveillance pricing ban in your state.

Why Should Founders Care About This Now?

Because the compliance patchwork is already unmanageable with reactive approaches, and it's going to get worse.

Consider what a company operating nationally faces right now. Maryland bans the practice outright in certain industries. Connecticut requires disclosure. New York requires disclosure with different specifics. New Jersey bans it in grocery and delivery. California has an active AG investigation and a proposed bill with $12,500-per-violation fines. Twenty-four states have active bills with varying definitions of what constitutes "surveillance data," which industries are covered, what exemptions exist, and whether the remedy is disclosure, prohibition, or both.

If your pricing infrastructure ingests personal data, you are now looking at maintaining separate logic per jurisdiction. Or you are looking at a single data practice strict enough to satisfy the most restrictive state. The first approach doesn't scale. The second approach is privacy by design, whether or not you call it that.

This is not abstract. If your product collects browsing behavior, location data, device fingerprints, or purchase history, and any downstream system uses that data to influence what a user pays, you have surveillance pricing exposure. It does not matter that you didn't build a "surveillance pricing engine." If the data flows exist, the exposure exists.

Do Consumers Actually Care, or Is This a Regulator-Driven Issue?

Consumers care. The numbers are stark. A Consumer Reports survey in May 2024 found 66% of Americans opposed retailers charging different prices based on personal information. A follow-up in January 2025 found 76% opposed companies offering discounts through similar data-driven means. That second number is worth sitting with. Consumers are not just opposed to paying more. A majority oppose data-driven discounts, too. The objection is to the surveillance, not just the price.

This is unusual. Most privacy issues poll as concerns but don't drive behavior. People say they care about privacy, then accept cookies without reading the banner. Surveillance pricing is different because the harm is measured in dollars on a receipt. It's tangible. It's personal. And it happens on everyday purchases (groceries, flights, hotels) that consumers make frequently enough to notice patterns.

That consumer salience is what gives regulators political cover to move fast. Privacy legislation usually takes years. Maryland went from bill introduction to governor's signature in months.

What Comes Next? Financial Services as the Next Battleground

Grocery and travel are the current focus. Consumer financial services is almost certainly next.

Financial services has relied on personalized pricing for decades: risk-based loan pricing, individualized insurance premiums, variable credit card rates. The industry will argue that these practices are fundamentally different because they're based on creditworthiness and actuarial risk, not behavioral surveillance. That argument has some merit. But the line blurs when a lender uses browsing behavior, app usage patterns, or social-media-derived signals to adjust an interest rate or fee. If the input data looks like surveillance data, the practice will look like surveillance pricing to regulators, regardless of what the industry calls it.

The practical implication for fintech founders: if your product sets any kind of price, fee, rate, or offer amount, and your model ingests behavioral data beyond traditional underwriting inputs, start tracking these laws now. The grocery-focused bans of 2026 will expand. The definitions will broaden. The question is when, not if.

What Should a Privacy-Conscious Founder Actually Do?

Three things, all structural rather than procedural.

First, audit your data flows for pricing-adjacent uses. Most companies don't have a "surveillance pricing engine" they can point to. What they have is a pricing system that ingests data from multiple sources, some of which include personal behavioral signals. Map those flows. Identify every input to your pricing logic. If any input is derived from individual user behavior rather than aggregate market conditions, you have exposure under at least some of the emerging state laws.

Second, default to minimal data collection. The structural fix for surveillance pricing compliance is not a better disclosure banner. It is not collecting the data that would make surveillance pricing possible. If your system doesn't have a persistent behavioral profile of the user, your pricing algorithm cannot use one. This is the same principle behind privacy-by-design architecture for any sensitive application: the data you never collect is the data that never leaks, never gets subpoenaed, and never triggers a state AG inquiry.

Third, treat the patchwork as a signal, not an anomaly. If you are building a national product and your compliance strategy is "we'll handle each state as it passes a law," you are building technical debt at the speed of legislation. The surveillance pricing patchwork will look, within two years, like the state privacy law patchwork (CCPA, CDPA, CPA, CTDPA, and so on). The companies that navigated that patchwork best were the ones that built to the strictest standard once, rather than maintaining per-state logic.

How Does This Connect to Broader AI Privacy Architecture?

Surveillance pricing is a specific instance of a general problem: AI systems that require large volumes of personal data to function create structural incentives to collect, retain, and process that data in ways that conflict with user privacy. The pricing use case is just the one where the harm became visible and dollar-denominated enough for regulators to act quickly.

If you are building an AI product that handles user data, the lesson from surveillance pricing is that your data architecture is your compliance architecture. The question regulators will ask, in pricing and eventually in other domains, is not "do you have a privacy policy?" It is "does this system require you to build a detailed behavioral profile of each user, and if so, what are you doing with it?"

We built Selina around a related conviction: that an AI assistant can remember context across conversations without requiring the kind of persistent behavioral profiling that surveillance pricing depends on. Memory in Selina is adaptive and encrypted at rest. It exists to make the assistant useful to you, not to model your willingness to pay or your behavioral patterns for third-party consumption. That is a design choice, not a feature. And it is the kind of design choice that, as surveillance pricing law matures, will increasingly separate products that can operate cleanly across jurisdictions from products that cannot.

The regulatory vocabulary is finally catching up to the technical reality. For founders, the window to get your data architecture right is before the next 24 states finish passing their bills.

Start a free 7-day trial, no card required.

Frequently Asked Questions

What is surveillance pricing?

It's the practice of using an individual's personal data, like browsing history, location, device type, or demographics, to set a price specifically for that person, rather than basing it on market conditions like supply and demand.

How is surveillance pricing different from dynamic pricing?

Dynamic pricing adjusts based on market-level signals such as inventory or time of day, while surveillance pricing adjusts based on data about a specific individual, like their zip code or browsing behavior. Regulators only recently developed precise enough vocabulary to legally separate the two practices.

What events made surveillance pricing a mainstream political issue?

A December 2025 Consumer Reports finding that Instacart charged different shoppers up to 23% more for identical items sparked momentum, followed by a California AG investigative sweep, two separate House committee investigations, and an August 2026 Senate hearing titled 'Your Data, Their Profit.'

Which states have passed surveillance pricing laws so far?

Maryland, Connecticut, and New Jersey have enacted laws as of mid-2026, while New York passed a disclosure-based law instead of a ban; more than 40 additional bills have been introduced across 24 states in 2026.

What are the two main regulatory approaches to surveillance pricing?

One model requires disclosure, telling consumers when a price has been personalized (used by New York and Connecticut), while the other model prohibits the practice outright, as seen in Maryland's law and California's proposed AB 2564, which includes fines up to $12,500 per violation.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai