For people seeking or considering public office, or who are otherwise high-profile in the political sector, one element of staying safe is knowing what someone can find out about you online.
It's long been a security best practice to Google yourself and see what others can see about you. However, times are changing and a basic search does not surface everything others might find. AI has added some new dimensions to this issue. For people in the public eye, reducing the risk of being targeted online is important.
We had the chance to speak with Mikala Vidal, head of growth at Kanary, to discuss how AI is changing the digital risk landscape and what candidates, campaigns and staffers can do to stay protected.
DDC: Tell us about Kanary. How did the company get started, what is the company's product and how does it help people?
Kanary traces back to the 2016 election cycle. Our founder, Rachel Vrabec, was doing data science work supporting presidential campaigns and kept running into the same problem from a different angle: candidates, staff, and volunteers were personally exposed online in ways nobody on the campaign had the time or expertise to handle. That work narrowed into a specific focus on candidate and staff safety, and she launched Kanary commercially in 2020.
Kanary is the digital and physical attack surface management platform for people. We apply a threat model unique to each individual, then find and mitigate active exposures across search engines, data brokers, social media, and AI/LLMs. Kanary maps its capabilities directly to the MITRE ATT&CK framework, countering the reconnaissance, resource development, and initial access techniques that adversaries use against individuals, from scraping org charts and harvesting home addresses to building lookalike social profiles. That mapping translates into direct protection against doxxing, impersonation, phishing, and unwanted physical arrivals at homes, offices, and events. Rather than chasing the easiest opt-outs, Kanary prioritizes the exposures most likely to escalate.
Today we support candidates and campaign staff, nonprofit leaders, celebrities, influencers, business leaders, board members, investors and their families. Over 200 organizations use Kanary as part of a digital risk program, for executive protection or as an employee benefit to reduce human attack surface.
DDC: Kanary recently did some research using one of your employees (with permission) on how much personal information you could get an AI chatbot to reveal about someone. What did you find?
We set out to test if we could get a mainstream AI chatbot to build a profile on a real person just by framing the request the right way. We had a willing teammate, Joseph, act as the subject. Instead of asking the model anything designed to directly reveal personally identifiable information (PII), we framed the request as a privacy self-audit and asked for the output as structured data with confidence scores.
In a single pass, the model named Joseph at 98% confidence, placed him in Las Vegas at 85% confidence, and guessed a birth year that had never been published. The model pulled all of that together from essentially one LinkedIn profile. The model wasn't just repeating information Joseph had already made public. It was inferring and stitching together details he'd never shared publicly.
You can see the full research here.
DDC: We know you don't want to reveal all the prompts you used to collect the information on the staff person who was your subject of the research. Can you share a few prompts so people can start gaining a better understanding of what chatbots might reveal if someone queries about them?
We're intentionally not publishing the exact prompts, for the same reason security researchers don't publish exploit code. We want to show people the shape of the risk, not hand attackers a script. I can describe the categories, though, because understanding the pattern helps people protect themselves.
One category is the self-audit frame: asking the model something like "help me understand what a privacy audit would find about a person named [X] in [city]." It sounds benign and compliance-oriented, but it produces the same result as a background check request the model would otherwise refuse. A second category is inference from a writing sample: feeding the model a paragraph of someone's public writing, a blog comment, a post, a newsletter, and asking it to guess the author's age, location, or profession. A third is photo geolocation: asking the model to guess where an image was taken based on background details, lighting, signage, or landscape features.
None of these require special access or hacking skill. Anyone who knows how to phrase a question can run them, and that's exactly why high-risk individuals need to understand they exist.
DDC: Candidates, people who work on campaigns, employees of advocacy groups and the family and friends of candidates and campaign staff are all at higher risk and targeted more than your average computer user. AI is a game changer. How do high-risk users manage their personal information in this new environment?
Traditional searches no longer tell the full story of what an adversary can find out about someone online. AI can infer and assemble things that were never searchable in the first place: a location from a vacation photo, an age from how you write a fundraising email, a home address from a pattern of public records nobody connected before.
Meaningfully reducing risk means treating an individual as an attack surface that requires continuous monitoring rather than a one-time cleanup. Disappearing from the internet is not an option for most people. Risky exposures can spike during high-profile events across social media, and reappear as data brokers resell and re-scrape records. Additionally, family members, colleagues and sometimes close friends are part of an individual's attack surface. Attackers targeting a candidate or staffer routinely go through a spouse, a parent, or a college roommate to gain access to personal data or sensitive information.
People should also pay close attention to how information can be aggregated across sources, even when no single piece of information looks sensitive on its own. AI connects small, individually harmless facts into something that can easily be turned into a dossier in the wrong hands.
DDC: Do you have any tips for when people are using AI that can help reduce the exposure of information about them?
Avoid pasting real names, photos, addresses, or other identifying details into a chatbot whenever possible. Treat the input box the way you'd treat a form you're filling out for a stranger. Be careful with "share this conversation" links. They can carry more than you'd expect to ad trackers, and once you've shared one, you've lost control of where it goes. If you're using a tool with memory or custom instructions, check what it's actually retaining about you over time and clear it periodically. And unless you've explicitly opted out, assume the company behind the model may train future versions on your conversations, so don't put anything in a chat you wouldn't want resurfacing somewhere else later.
On the other side of this equation, shrink how much raw material about you sits on the open internet in the first place, because chatbots are only as dangerous as the public information they have to work with. Pull your listings off data broker sites, tighten privacy settings on social accounts, and keep birthdates, home addresses, and family details out of public bios. All of that shrinks what a model can infer, even if you never touch AI yourself. Organizations, campaigns, advocacy groups, and companies should also monitor what's showing up about their people in AI-generated responses, not just what those people type into AI tools.
DDC: We are still in the early days of AI. What are the future challenges you see coming for managing your digital footprint and presence?
The agentic internet is already here. Autonomous systems acting on someone's behalf with little human oversight are being used across many online systems. Analysts expect a large share of enterprise applications to run task-specific AI agents within the next year or so, and that's stacking on top of infrastructure that already fails people in predictable ways.
Data brokers are a good example. It's a roughly $300 billion industry that runs with almost no meaningful consent, and the removal process is often built to fail by design. Investigators have found brokers hiding their own opt-out pages from search engines, and regulators have called the pattern an "opt-out obstacle course," built for attrition rather than compliance. Impersonation tells a similar story as tens of millions of fake accounts were created or attempted on LinkedIn alone in a single six-month stretch last year, hundreds of thousands of which relied on users to report them before they were detected. Content moderation itself often functions more like a liability shield than an actual safety mechanism.
Now add autonomous AI agents into systems that already work this way, and the accountability gap doesn't shrink, it grows. The line between who controls the data and who's just processing it gets blurrier every time someone adds a new autonomous system to the chain, and right now nobody is answering that accountability question. The challenge ahead is not just managing what's out there, but making sure the systems meant to protect us actually do.
DDC: What can high-risk users do to better manage their personal data in the age of AI?
Accept that it's not an all-or-nothing strategy. Each individual has their own unique attack surface, and the goal is not to completely disappear from the internet, but to make it harder for adversaries to use personal data for harm. Here is a guide to help get started: User Guide for the Human Attack Surface Management
