Let me be honest with you: I love getting my grocery store mailers.
When my Safeway for U weekly coupons load in the app, or when Kroger’s personalized discounts arrive targeting the exact brand of cereal I buy every two weeks, I feel a genuine thrill. It feels like I get exactly the deals I want without much effort.
I don’t just appreciate this as a consumer; I appreciate it as a technologist. As an AI PM, I’ve spent my career obsessing over this exact kind of personalization. When I built a multimodal recommender system called Find My Ryokan (using text and image embeddings alongside RAG to match travelers with the perfect traditional Japanese inn), my entire goal was utility. I wanted to use data to surface exactly what a user needed, right when they needed it. In my mind, data-driven personalization was the ultimate win-win.
But a recent piece of local news right here in the Seattle area makes me reconsider my stand. The Seattle City Council recently proposed a “Fair and Transparent Pricing” ordinance—dubbed “Equal discounts for all”—which explicitly bans large grocery retailers from using sensitive data (like our browsing history, device metrics, or employment status) to set individualized prices. In response, grocery trade groups pushed back hard, warning that this ordinance would raise prices for everyone and effectively kill loyalty programs.
When I read that defense, I had to stop and ask:
When did customer loyalty programs transform from a reward system into a high-margin surveillance product?
I realized that the exact same data pipelines I build to power helpful recommender systems are being quietly inverted. They aren’t just being used to recommend products anymore. They are being weaponized for something entirely different: surveillance pricing, which is the practice of using personalized consumer data and AI to calculate a consumer’s maximum willingness to pay.
What Is Surveillance Pricing
Let’s start with dynamic pricing, as employed in the recent FIFA World Cup 2026 ticketing. This is when a system adjusts prices based on market-wide factors like overall demand or time of day (think: surge pricing of taxis after a concert).
Surveillance pricing is entirely different. It happens when firms collect massive amounts of deeply personal consumer data, including online behavior, device signals, purchase history, precise location, and third-party data broker profiles. Such data are then fed into machine learning algorithms to set individualized prices, offers, or terms in real time. It is the practice of calculating a specific individual’s maximum “willingness to pay” and extracting it on the fly.
And this isn’t just a few rogue apps; it is a massive, industrialized ecosystem. These pipelines are powered by B2B middlemen (intermediaries like Revionics, Bloomreach, and PROS) who serve at least 250 clients across sectors ranging from online casinos to travel and retail. Worse, this tracking is no longer confined to the web. These algorithms are bleeding into the physical world through electronic shelf labels and in-store interactive kiosks.
As a technologist, I have to ask: when the digital price tag on a physical store shelf changes based on your approaching smartphone, where does personalization end and physical surveillance begin?
Surveillance pricing is an attempt to achieve perfect price discrimination. By charging each of us exactly our maximum threshold, algorithms eliminate our “consumer surplus”—that satisfying feeling of getting a good deal. Although retailers say that this enables them to subsidize lower prices for other people, the way in which these benefits are distributed is completely opaque.
As consumers, how are we supposed to know if we are receiving a genuine deal or being subtly taxed for our brand loyalty?
Regulatory & Political Scrutiny
It is no longer possible to run these data pipelines in secrecy.
In July 2024, the Federal Trade Commission (FTC) launched a formal inquiry into the “opaque market” of surveillance pricing, specifically to learn exactly how widespread these practices are, how the intermediary data brokers operate, and whether they cause consumer harm that existing laws fail to address. Through their subsequent research summaries and issue spotlights, the FTC has documented the exact data sources and modeling approaches used in the industry, including highly redacted, real-world examples of how these pipelines extract consumer surplus.
The political reaction has been fierce. By August 2026, US Senate hearings exposed allegations of data brokers and payment network subsidiaries that classify consumers by emotional state and brand loyalty to determine if they will swallow a price increase. Politicians like Senator Josh Hawley are using these findings to call for aggressive congressional oversight, publicly framing the practice as predatory data-harvesting.
And as I mentioned earlier, this battle is already hitting close to home at the local level in Seattle.
If cities across the country start passing hyper-local pricing transparency laws, how will engineering teams manage the jurisdictional compliance nightmare of location-aware feature flags?
Academic Theory vs. Reality
To understand how a helpful coupon engine mutates into a surveillance tool, we have to look at an economics textbook.
In classical microeconomics, first-degree price discrimination (often called perfect price discrimination) is framed as a highly efficient, almost utopian market model.
The theory works like this: if a seller knows your exact willingness to pay (the absolute maximum amount of money you will sacrifice to procure a good), and charges you exactly that amount, the market is perfectly optimized. Lower-income buyers who can only afford to pay $2 for a staple good are charged exactly $2. Wealthier buyers who can afford $4 are charged $4.
Because every possible mutually beneficial transaction occurs, this model theoretically eliminates deadweight loss (the economic inefficiency that plagues normal markets when prices are set too high for some and too low for others). Everyone gets access to the market, and output is maximized.
But that theory assumes a fair, transparent exchange of utility (the total satisfaction or value you receive from a good).
The reality of modern surveillance pricing is a masterclass in information asymmetry. The seller knows everything about your habits, your location, and your desperation, while you know absolutely nothing about their pricing logic. Consumers don’t know they are being dynamically segmented, stripping them of the ability to comparison shop. Instead of expanding access by lowering prices for those in need, these algorithms operate in the dark to weaponize urgency and private data, and extract 100% of your consumer surplus (the difference between what you are willing to pay and what you actually pay). It turns a theoretically efficient market into a zero-sum wealth transfer.
When you look at the recent data, the gap between the academic ideal and the algorithmic reality reveals four glaring concerns.
The 4 Core Concerns
1. Discrimination and Unfairness
When prices detach from supply and demand, everyday essentials become a gamble based on hidden consumer profiling. Instead of charging people based on what it costs to deliver a good, companies charge based on what the algorithm thinks it can get away with. Personalized pricing can easily lead to higher prices for certain groups or individuals, potentially reinforcing socioeconomic disparities based on geolocation or demographic inferences.
Evidence: Investigations by Consumer Reports and the Groundwork Collaborative, and concurrent August 2026 Senate Subcommittee hearing on AI Surveillance Pricing presented a massive exposé on Instacart. Different shoppers were offered completely different prices for the exact same groceries at the exact same pickup location. Astoundingly, nearly 75% of items tested saw price swings as high as 23%, costing an average family an extra $1,200 per year.
Crucially, following severe public exposure and regulatory pushback, Instacart officially halted its AI pricing experiments.
As product managers, this raises a vital question: If public outcry is required to stop predatory feature testing, why aren’t we establishing ethical guardrails before these experiments ever reach production?
2. Lack of Transparency
Consumers typically have absolutely no idea they are being profiled, nor do they understand why they are seeing a different price than the person sitting next to them. In this case, they are entirely stripped of their ability to assess fair market value when the price they see on a screen is dynamically generated just for them. You cannot comparison shop when the price is an illusion.
Evidence: The digital and physical worlds are quietly colluding against the buyer. Target was caught updating app prices based on a user’s physical proximity. A Dyson vacuum jumped $148 the moment a user stepped inside the store, because the algorithm deduced that since the user was inside, their commitment to buy was higher. Similarly, Staples has a history of altering online prices based simply on a user’s IP address and how close they lived to a rival brick-and-mortar competitor.
Meanwhile, Consumer Reports uncovered Kroger’s secret shopper profiles, revealing that Kroger’s data science division, 84.51°, generated $527 million in profit in a single year, representing over 35% of its entire net income. To move at this scale, Kroger operates 84.51° as a high-speed “shadow brand” unencumbered by legacy systems, as highlighted by Forbes. They utilize a centralized “AI Factory” platform and agentic AI frameworks to rapidly scale models across the enterprise. Furthermore, they have seamlessly consolidated consumer insights and loyalty programs into a single retail media network (Kroger Precision Marketing) to activate CPG ads directly against our purchase histories.
When a grocery store makes more than a third of its profit selling consumer data profiles rather than selling food, who is the real product? Are loyalty programs just a Trojan horse for high-margin data brokerage?
3. Privacy and Data-Harvesting
The engine powering this pricing model requires an invasive, continuous collection of granular personal data, moving far beyond basic demographics into “creepy” real-time behavioral tracking.
Evidence: The FTC’s ongoing Surveillance Pricing study and its January 2025 Staff Research Summaries revealed that middleman analytics firms build complex user segmentation profiles tracking micro-behaviors, including exact mouse movements on a webpage, items abandoned in carts, and credit footprints. Senate hearing testimonies further revealed that credit card subsidiaries, like Mastercard’s Dynamic Yield, use this data to tag consumers with psychological profiles (like “confident” or “in love with JetBlue”) solely to calculate their absolute maximum they will pay before abandoning a cart.
4. Market Power and Exploitation
Firms with superior data infrastructure and modeling capabilities hold massive asymmetrical leverage, allowing them to identify and tax human desperation.
Evidence: One of the most visceral examples from the Senate hearings involved the sheer exploitation of urgency. A user urgently trying to book a last-minute JetBlue flight for a funeral might see their price artificially inflated based on their frantic browser history and low device battery. As Dr. Lindsay Owens testified, that price surge has nothing to do with jet fuel costs or seat availability, but an algorithm recognizing and taxing a consumer’s desperation.
If our data pipelines are sophisticated enough to detect human grief and urgency, why are they being used to trigger a price surge instead of offering assistance?
Furthermore, a monthslong investigation by Consumer Reports into Uber and Lyft dynamic pricing revealed that the platforms routinely charged different users dramatically different rates for identical rides at the exact same time, with a median price spread of 50%. Worse, the investigation uncovered “fake discounts”, where strikethrough promotional deals actually resulted in higher costs than the un-discounted rate shown to a neighboring user.
When A/B testing degrades into deceptive UI patterns and price gouging, how can tech platforms expect to maintain long-term user trust?
Architecture: Compliance Debt vs. Security
From an engineering perspective, this exposes monolithic compliance debt. If your pricing engine breaks because you remove a user’s PII (or the behavioral features derived from it), your architecture is too tightly coupled. In a resilient architecture, the identity and behavioral feature set (personalization signals, usage history, device context) should be decoupled from the pricing engine (which handles inventory, demand, cost, and policy-approved features). If a user crosses a jurisdictional boundary such as the Seattle city limit, a properly designed system should be able to toggle a feature flag or policy rule, dropping restricted behavioral variables without breaking the checkout flow. If your pricing pipeline requires a user’s raw PII to function, you have built a surveillance tool instead of a dynamic pricing system.
However, security and data science professionals will tell you that it’s never a simple refactoring to split these signals. The device telemetry (battery life, device type, fingerprints) and behavioral signals (clicks, mouse movements, session patterns) used to extract maximum profit are often the exact same signals used to detect bots, account takeovers, and inventory scalping. You can see this in the multi-signal approach in platforms such as the Outseer Risk Engine. Banning them entirely blinds the system’s anti-fraud defense.
So, how do we build infrastructure that satisfies both security and compliance? As PMs and architects, we need to build centralized policy layers. Rather than passing raw PII directly to a pricing engine, we can utilize Privacy-Enhancing Technologies (PETs) such as differential privacy or data clean rooms. We keep full-fidelity anti-fraud systems intact while exposing only aggregated, non-identifying risk scores, or differentially private aggregates to the checkout and pricing flow.
Furthermore, civil society is beginning to audit our systems from the outside. Consumer Reports published an open-source GitHub repository detailing their empirical testing methodology for ride-hailing algorithms.
Could open-source, community-driven algorithmic auditing become the new standard for holding black-box pricing systems accountable?
Practical Takeaways
For Product Leaders
In this political atmosphere, we should expect dramatically increased scrutiny. Firms using individualized or highly personalized pricing will have to document their algorithmic practices, conduct rigorous fairness and compliance risk assessments, and prioritize long-term customer trust by building transparency and consumer-friendly privacy controls directly into the product.
Interestingly, corporations are already building counter-narratives. Kroger recently highlighted their commitment to a “Responsible AI” (RAI) framework, boasting an internal AI Governance council made of legal, privacy, and security stakeholders to enforce accountability.
But as a product builder, I remain skeptical. Can an internal governance council truly protect consumers when the company’s underlying business model is predicated on extracting their maximum willingness to pay?
As product leaders, we need to change how we measure success. It is easy to present a dashboard showing a 15% bump in short-term Gross Merchandise Value (GMV) by squeezing highly motivated buyers. It is much harder to quantify the silent exodus of users who realize they are being manipulated.
We need to shift from optimizing for highest immediate cart value to optimizing for long-term value (LTV), transparency, and trust. We can adopt a form of personalization that is based on context or cohorts. For example, by segmenting users into broad groups rather than individual targets.
The true test of product leadership isn’t just knowing how to build an algorithmic engine, but knowing how to build the guardrails that constrain it.
For the Users
As consumers, we should always assume personalized pricing is happening behind the scenes. Because we will rarely see explanations or opt-outs, we must be cautious about sharing data. We can interfere with data ingestion pipelines so that algorithms can’t accurately record your behavior:
- Air-Gap Research and Purchasing: Use one browser for casual research, and a completely different, hardened browser solely to execute the final transaction to break session continuity that algorithms rely on to measure your “urgency”.
- Spoof Hardware and Location: Because device telemetry sets baseline prices, checking out on an older mobile device or routing traffic through a VPN can bypass demographic profiling.
- Upgrade Privacy Tooling: Because Google’s Manifest V3 architecture limits the capabilities of ad-blockers on Chromium browsers, use dedicated tools:
- uBlock Origin: The gold standard for dynamic filtering (on Firefox).
- Privacy Badger: An EFF tool that catches invisible trackers via heuristic learning.
- Brave Browser: Offers built-in tracking shields and fingerprint randomization out of the box.
Reference
This video from Consumer Reports provides a visual breakdown of its investigation into how AI pricing algorithms dynamically alter fares for different users requesting identical rides on Uber and Lyft.