SELINA.ai
Sign in

What Is Surveillance Pricing, and Why Are Regulators Suddenly Defining Their Terms?

For years, "personalized pricing" was a vague anxiety. You'd search for a flight, check again an hour later, and the fare had jumped. Coincidence or targeting? Nobody could say with certainty, and regulators didn't have vocabulary precise enough to act. That changed. The question of what is surveillance pricing now has formal answers from federal investigators, state legislatures, and attorneys general, and those answers are more specific than most headlines suggest. They draw a line that matters: between prices that respond to market conditions and prices that respond to you.

Key Takeaways

What Exactly Do Regulators Mean by "Surveillance Pricing"?

Surveillance pricing is the practice of using detailed personal data about an individual consumer to calculate a price specifically for that person. Federal regulators define it as pricing that draws on location, browsing history, demographics, or behavioral inferences to set individualized prices. The word "individualized" is doing real work in that sentence. A surge fare during a rainstorm is dynamic pricing: it reacts to aggregate demand. A different price for you specifically, because the system inferred your willingness to pay from your browsing pattern last Tuesday, is surveillance pricing.

That distinction is not academic. It determines which side of new state laws a retailer falls on, and it is the exact line that compliance counsel are now coaching companies to document. If your pricing model responds to market conditions (inventory levels, time of day, regional demand curves), you are on defensible ground. If it responds to characteristics of the individual shopper, you are in the zone regulators are targeting.

How Did the FTC Investigation Start, and What Did It Find?

The FTC opened a Section 6(b) investigative study in July 2024, issuing compulsory orders to companies it described as "intermediary" tech vendors. These are firms that sit between retailers and consumers, offering algorithmic pricing tools. The agency's stated goal was to understand third-party intermediaries claiming to use "advanced algorithms, artificial intelligence and other technologies, along with personal information about consumers" to categorize individuals and set targeted prices.

The January 2025 research summaries were specific. FTC staff found that consumer behaviors "ranging from mouse movements on a webpage to the type of products left unpurchased in an online shopping cart" could be tracked and fed into pricing models. The intermediary vendors were not niche players: staff documented them working with at least 250 clients spanning grocery, apparel, and other retail categories.

That number is worth sitting with. Two hundred fifty clients is not a pilot program. It is an established vendor ecosystem selling individualized pricing as a service, at scale, using the same behavioral data that ad-tech pipelines have been collecting for a decade.

Why Are States Moving Faster Than Congress?

Because they can. As of early 2026, more than 40 bills across at least 24 states address surveillance pricing, already outpacing all of 2025's legislative output. Congress has held hearings and opened probes (more on that below), but passing federal legislation requires the kind of bipartisan alignment that privacy and AI topics rarely produce quickly. State legislatures face lower coordination costs.

The result is a patchwork. And a real one, not the hypothetical patchwork that lobbyists invoke to argue for preemptive federal standards. The actual laws already enacted differ substantively in approach.

Which States Have Enacted Laws, and How Do They Differ?

Three models have emerged so far:

Outright bans (sector-specific). Maryland passed the first law in the country banning surveillance pricing for certain food retailers and third-party delivery providers. Connecticut followed with a grocery-focused ban. New Jersey became the third state on July 23, 2026, prohibiting surveillance pricing for groceries with penalties up to $50,000 per violation, treble damages, and a private right of action.

Disclosure requirements. New York's Algorithmic Pricing Disclosure Act, effective since December 2025, takes a different tack. It does not ban the practice. It requires a consumer-facing label. The mandated text reads: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." All caps, no ambiguity. The theory here is that sunlight is the disinfectant: if consumers can see when a price was personalized, competitive pressure will do the rest.

Broader prohibitions (pending). New York's legislature also passed the One Fair Price Act on June 4, 2026, which, if signed by the governor, would prohibit businesses from using surveillance pricing based on browsing history, inferred income, household size, and location. California Assembly Bill 2564 passed the state Assembly on May 27, 2026, and is pending in the Senate. It would prohibit retailers from customizing prices based on personally identifiable information from electronic surveillance technology, with an exception where price differences reflect genuine differences in cost to serve.

That California exception is worth flagging. It carves out cost-based differentiation (shipping to a remote zip code costs more, so the price reflects that) while prohibiting willingness-to-pay inference. It is the most structurally precise definition any state has attempted.

What Is the Federal Government Doing in 2026?

More than the gap year of 2025 suggested. Under FTC Chairman Andrew Ferguson, the agency scaled back broad rulemaking but intensified targeted enforcement. In April 2026, the FTC issued an Advance Notice of Proposed Rulemaking covering total price disclosure, fee transparency, and personalized pricing disclosure. This is not yet a rule. It is the formal step that precedes one, signaling the agency's intent to regulate in this area at the federal level.

Congress is probing from multiple directions. The House Committee on Oversight and Accountability opened an investigation in March 2026 into AI-driven surveillance pricing at travel and platform companies, sending letters requesting documentation on revenue management algorithms, use of consumer data in pricing, testing and experimentation practices, and internal communications describing pricing tools and outcomes. The House Committee on Energy and Commerce launched a parallel inquiry in May 2026 focused on grocery and retail pricing.

A coalition of 16 state attorneys general, led by New York and Tennessee, sent a letter on May 18, 2026, urging the FTC to extend its fee rule to food delivery and to issue a separate rule targeting personalized or surveillance pricing. That letter matters because it signals state-federal coordination, not just parallel activity.

How Does the DOJ's Algorithmic Collusion Case Fit In?

It adds a second legal theory. Surveillance pricing is a unilateral practice: one retailer using your data to set your price. Algorithmic collusion is a coordination problem: multiple competitors feeding data into a shared pricing algorithm, which then converges on higher prices without any human ever making a phone call to a rival.

In November 2025, the DOJ settled with RealPage, restricting data sharing among clients of its shared pricing-algorithm vendor in the rental housing market. The DOJ signaled in June 2026 that criminal enforcement of algorithmic pricing collusion remains on the table. This is a different legal bucket from surveillance pricing (antitrust rather than consumer protection), but the underlying technical infrastructure overlaps: the same vendor ecosystem, the same data pipelines, the same opaque algorithmic decision-making.

What Data Signals Are Actually Being Used?

The FTC's findings are the most granular public account. The signals feeding surveillance pricing models include, per the staff research summaries:

The mouse-movement detail tends to get the headline, but the abandoned-cart signal is arguably more revealing of the economic logic. If you left an item in your cart, the system infers demonstrated intent. The price might go up (you clearly want it) or down (a nudge to convert). Either way, the price is a function of your revealed behavior, not the product's cost or market demand.

Why Is Consumer Trust Collapsing at the Same Time?

52% of consumers now say they trust AI less than humans with their personal data, up from 48% in 2025. That is the largest single year-on-year shift in that dataset. Separately, 68% of U.S. consumers report feeling "taken advantage of" when brands use dynamic pricing, and 80% believe brands with consistent pricing are more trustworthy.

These numbers track. Surveillance pricing is, in a sense, the most consumer-visible manifestation of opaque AI decision-making. You can argue about whether a chatbot's output is biased. You cannot argue about whether you paid more for the same product as the person sitting next to you. The price is concrete, the harm is felt in dollars, and the mechanism is invisible. That combination is corrosive to trust in a way that abstract AI-ethics debates are not.

Half of American shoppers are already using AI to research their next retail purchase, but only about a third trust what it tells them. The gap between adoption and trust is a structural feature of how AI is being deployed in commerce: useful enough to use, opaque enough to distrust.

Is Disclosure Enough, or Do You Need a Ban?

This is the policy design question underneath all the legislative activity, and regulators are answering it differently.

New York's disclosure model bets on market discipline. If you see the label, you can comparison-shop, switch retailers, or use a VPN. The assumption is that informed consumers will punish bad actors. The problem with this theory is that it requires the consumer to bear the cost of vigilance. You need to notice the label, understand what it means, and then take action, every time you shop. That is a high cognitive tax for a low-per-transaction harm.

Maryland, Connecticut, and New Jersey bet on prohibition, at least in groceries. The logic: food is a necessity, price discrimination in necessities is regressive (it hits lower-income consumers harder, since they tend to have less ability to comparison-shop or switch), and the informational asymmetry is too large for disclosure to fix.

California's pending bill attempts a middle path by carving out cost-based differentiation. This is the most intellectually honest approach, because it acknowledges that not all individualized pricing is predatory. Charging more for next-day delivery to a rural address reflects real cost differences. Charging more because the algorithm inferred you will pay it does not.

Is This Really an AI Problem, or a Data Collection Problem?

It is a data collection problem that AI made operationally viable at scale.

The raw material for surveillance pricing is the individualized behavioral profile: your browsing history, your location trail, your purchase patterns, your inferred demographics. This data existed before modern AI. What changed is the cost of processing it into per-consumer price decisions in real time. A decade ago, building a per-shopper pricing model for 250 retail clients required custom engineering. Now, a frontier model can ingest behavioral signals and output a price recommendation with minimal marginal cost per query.

This means that the most durable intervention is upstream: reducing the collection and centralization of individualized behavioral data in the first place. Disclosure labels address the output. Bans address the practice. But the input, the continuous aggregation of per-person behavioral profiles across contexts, is what makes the practice structurally possible.

This is why the surveillance pricing debate is, at its core, a data-minimization debate. If the individualized profile does not exist, it cannot be used to set an individualized price. Every system that collects less, aggregates less, or anonymizes by design is removing a brick from the foundation that surveillance pricing is built on.

What Should You Actually Do About This?

If you are a consumer:

If you are a company that sets prices algorithmically:

Where Does This Go Next?

Three trajectories are worth watching.

First, the California bill. If AB 2564 passes the state Senate and is signed, California's market weight will effectively set a national standard for any retailer operating online, the same way CCPA did for data privacy. The cost-based-differentiation exception will become the template that other states copy or modify.

Second, the FTC's ANPRM. If it advances to a Notice of Proposed Rulemaking, it will be the first federal rule specifically addressing personalized pricing disclosure. The 16-state AG coalition urging the FTC to act gives the agency political cover.

Third, the litigation wave. New Jersey's treble-damages provision is an invitation to the plaintiffs' bar. The first class action that survives a motion to dismiss will define the contours of surveillance-pricing liability for years. The Robinson-Patman Act's reemergence in active cases adds a federal antitrust dimension that could run parallel to state consumer-protection claims.

The common thread across all three: regulators and legislators are no longer asking whether surveillance pricing happens. The FTC study settled that. They are deciding what to do about it, and their answers are becoming law.

The underlying technical reality is unchanged. Surveillance pricing requires a centralized, individualized behavioral profile. Any architecture that prevents that profile from existing, by design rather than by policy, removes the precondition for the practice. The products and systems that will be structurally compliant with wherever these laws land are the ones that minimize data collection at the point of capture, not the ones that promise to delete it later.

If you want an AI assistant built on that principle, where memory is encrypted at rest and files sent through SelinaSEND are zero-knowledge: start a free 7-day trial, no card required.

Frequently Asked Questions

What is surveillance pricing, according to regulators?

It is the practice of using granular personal data, such as browsing history, location, demographics, and behavioral inferences, to set an individualized price for a specific consumer. Regulators distinguish it from dynamic pricing, which responds to market conditions like inventory or demand rather than to characteristics of the individual shopper.

What did the FTC's investigation into surveillance pricing find?

The FTC's Section 6(b) study, opened in July 2024, found that intermediary tech vendors were using signals as fine-grained as mouse movements and abandoned cart contents to set personalized prices, and that these vendors worked with at least 250 retail clients across grocery, apparel, and other categories.

Which states have passed surveillance pricing laws, and how do their approaches differ?

Maryland, Connecticut, and New Jersey have enacted outright bans on surveillance pricing for grocery or food delivery, with New Jersey imposing penalties up to $50,000 per violation. New York instead requires a disclosure label stating the price was set by an algorithm using personal data, while pending bills in New York and California would impose broader prohibitions, with California's version exempting genuine cost-based price differences.

What is the federal government doing about surveillance pricing in 2026?

The FTC issued an Advance Notice of Proposed Rulemaking in April 2026 covering price disclosure and personalized pricing, while the House Oversight and Energy and Commerce Committees opened separate investigations into travel, platform, and grocery pricing practices. Separately, a coalition of 16 state attorneys general urged the FTC to issue a rule targeting surveillance pricing directly.

How does the DOJ's algorithmic collusion case relate to surveillance pricing?

It represents a different legal theory, antitrust coordination among competitors rather than one company individually pricing a consumer, but relies on overlapping vendor infrastructure and data pipelines. The DOJ's November 2025 settlement with RealPage restricted data sharing among clients of a shared pricing algorithm in rental housing, and the DOJ has signaled criminal enforcement of algorithmic collusion remains possible.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai