There is a particular kind of betrayal in being charged more for staying. It runs against every instinct a customer brings to a long relationship with a shop, a bank, an insurer. You assume, reasonably, that years of repeat business buy you something: goodwill, a better deal, the warmth of being a known quantity. The opposite is closer to the truth. In a growing number of markets, the longer you remain a customer, the more a pricing system has learned about you, and the higher the figure it concludes you will tolerate. Loyalty is not rewarded. It is metered, modelled and monetised. The system reads your steadfastness as a signal of your inability to leave, and prices the difference.
This is the strange logic at the heart of what regulators have started calling surveillance pricing, and it is worth pausing on how counter-intuitive it is. Surge pricing, the kind that lifts a taxi fare when it rains, at least responds to something visible and shared. Everyone standing on the same wet pavement faces the same multiplier. Surveillance pricing does something else entirely. It responds to you: to your browsing history, your device, your postcode, your past purchases, the financial circumstances it has inferred about you and, crucially, to how trapped you appear to be. By 2026 this is no longer a thought experiment kept warm in economics seminars. It is law in three American states, the subject of formal orders from the United States Federal Trade Commission to eight companies, and the documented practice of firms from grocery delivery platforms to airlines. The question it forces is not whether the technology works. It plainly does. The question is what happens to the idea of a fair public price, the same number for anyone who wants the same thing, when that idea quietly stops being true.
The Difference Between a Crowd and a Person
The vocabulary matters here, because the industry has a strong interest in blurring it. Dynamic pricing is old, familiar and broadly understood. Airlines have flexed fares with demand since deregulation. Hotels lift rates around conferences. Energy tariffs move with wholesale markets. What unites these practices is that the price, however much it jumps, is a fact about the market at a given moment. It is aimed at a condition, not a customer. Two strangers booking the same seat at the same second see the same number.
Surveillance pricing breaks that symmetry. It is the calculation turned inward, away from the conditions of supply and demand and towards the individual standing in front of the screen. The Federal Trade Commission, in the issue spotlight it published in January 2025, drew the line precisely: instead of a price being a static feature of a product, the same product could carry a different price for different people based on consumer data, behaviours, location, time and purchase channel. The agency described an opaque market of third-party intermediaries that use advanced algorithms, artificial intelligence and personal information to categorise individuals and set a targeted price for each. The signals it documented were granular to the point of intimacy: not merely what you bought, but the movement of your cursor across a page, the products you placed in a basket and then abandoned. One example named in the FTC's findings was a cosmetics company tailoring promotions to a customer's skin type and skin tone.
The distinction is not pedantry. It is the whole moral architecture of the thing. A dynamic price is a message the market sends to everyone. A surveillance price is a private message addressed to you alone, written from a profile you cannot read, by a system that knows things about you that you have not agreed to share and may not even know about yourself. The crowd has become a person, and the person has become a target.
The Loyalty Penalty, and Why Britain Saw It First
If you want to understand surveillance pricing before the algorithms arrived, look at British insurance. For years the home and motor insurance markets ran on a practice the industry euphemistically called price walking, and which everyone else called the loyalty penalty. The mechanism was simple and cynical. Insurers offered cheap, often loss-making premiums to new customers to win them, then ratcheted the price upward at each annual renewal, year after year, betting that inertia, busyness or simple trust would stop the customer from shopping around. The longer you stayed, the more you paid, not because your risk had risen but because your loyalty had been identified as exploitable.
The scale of it was extraordinary. In September 2018, Citizens Advice lodged a super-complaint with the Competition and Markets Authority arguing that across five essential markets, mobile, broadband, home insurance, mortgages and savings, British consumers were losing around 4.1 billion pounds a year to the loyalty penalty. That worked out at roughly 877 pounds per affected household, equal to about three per cent of the average household's annual spending. Eight in ten people, the charity found, were paying a significantly higher price in at least one of those markets simply for staying with their existing supplier. The CMA accepted the substance of the complaint when it responded that December.
The Financial Conduct Authority went furthest in the insurance sector. Its market study concluded that six million existing customers would have saved 1.2 billion pounds in a single year had they paid the average price for their actual risk rather than the inflated renewal figure their loyalty had earned them. From January 2022 the FCA banned the practice outright, requiring insurers to offer renewing customers a price no higher than they would quote a new customer for the equivalent policy. It was, in effect, a legal insistence that loyalty must not be priced as a weakness.
What makes this history so relevant is that it was the analogue rehearsal for the digital performance now underway. Price walking was the loyalty penalty done crudely, by hand, with renewal letters and call-centre scripts. It worked because insurers could make a rough guess about who was unlikely to switch. Surveillance pricing is the same instinct supercharged. Where the old insurer guessed at your inertia from your renewal record, the modern pricing engine infers it from hundreds of signals in real time, and applies the penalty not once a year but at the moment of every transaction. The loyalty penalty was never really about insurance. It was about the seller's ability to read a customer's captivity and charge for it, and that ability has grown beyond all recognition. Even the FCA's ban proved porous. Research by the consumer group Which? in 2024, two years after the rules took effect, found that only around one in five car insurance customers had thought to test their renewal quote against what their own insurer would offer them as a new customer, and that just over half of those who did were quoted less for identical cover. Nor was the leakage always accidental: Direct Line Group, having misapplied the new rules, agreed to hand back an estimated 30 million pounds to renewing customers it had overcharged. The penalty, banned in one form, leaks back in others.
The Oldest Dream, Finally Buildable
Economists have a clinical name for the destination all of this is travelling towards. They call it first-degree, or perfect, price discrimination: the seller's fantasy of charging every buyer the exact maximum they are willing to pay, capturing for the company every last scrap of value that, under a single posted price, would have stayed in the customer's pocket. The theory has sat in textbooks for a century. What it always lacked was a mechanism, because individual human beings are historically rather good at concealing their personal ceiling. The single posted price, the same number on the same shelf for everyone, emerged in part because sellers simply could not do better. It was a technological limit that hardened, over time, into something we mistook for a moral norm.
That limit has now dissolved. Lina Khan, who chaired the FTC from 2021 to 2025, put the shift plainly. The idea of charging every individual person according to their individual willingness to pay, she said, had for the most part been a thought experiment. Through the enormous quantity of behavioural and individualised data that brokers and other firms now collect, she went on, the environment had changed: technologically it had become much more possible to serve every individual person an individual price based on everything they knew about you. Her framing of the consequence is the one that has stuck to the debate. We are moving, she warned, from a transparent market with public prices to an opaque world in which we are alone against secret algorithms.
The first public glimpse of the dream came in September 2000, when an Amazon shopper noticed that deleting the cookies from his browser dropped the price of a DVD. The company had been varying prices according to what it could infer about each customer, and in some cases loyal returning buyers were quoted more than newcomers. The backlash was fierce, Amazon retreated, calling it a random test, and the industry drew a careful lesson. Not that personalised pricing was wrong, but that it must never again be visible. For two decades the dream advanced quietly, dressed in the respectable language of demand and yield, until the data and the machine learning matured enough to make the old fantasy operational.
A TV That Costs More in the Car Park
The clearest way to feel surveillance pricing is to watch a price move not because the market shifted, but because you did. In 2019 investigative journalists at the Minneapolis television station KARE 11 documented exactly this on the Target retailer's app. A Samsung 55-inch smart television was listed at 499.99 dollars when a shopper browsed it from home. When the same shopper drove into the car park of a Target store, the app's price for the identical set leapt to 599.99 dollars. The variable was not supply, demand or time of day. It was geolocation: the app could tell the customer was now physically present, less likely to walk away empty-handed, and it priced that captivity at a hundred dollars. The television was not a fluke. Reporters picked ten products at random, from toys to bottled water to vacuum cleaners, and four of them rose in price once they were inside the shop: an Apple Watch band by two dollars, a Shark vacuum cleaner by forty, a Graco child car seat by seventy-two and a Dyson vacuum cleaner by a hundred and forty-eight. The spread is the instructive part. A system that moves a watch strap by two dollars and a vacuum cleaner by a hundred and forty-eight is not applying a blunt in-store surcharge; it is judging, item by item, what the fact of your presence is worth. Target adjusted the app after the investigation, but the episode remains a near-perfect demonstration of the mechanism, because the only thing that changed about the customer was how committed they appeared.
The principle scales far beyond a single retailer's app. The same season the FTC published its findings, the practice was visibly spreading into one of the most price-sensitive markets there is: air travel. In July 2025, the airline Delta confirmed it was expanding the use of artificial intelligence to set fares, working with an Israeli startup called Fetcherr, with the stated ambition of using AI to price a fifth of its domestic network by the end of the year. Three United States senators, Mark Warner, Ruben Gallego and Richard Blumenthal, wrote to the airline demanding answers. Their letter, dated 22 July 2025, warned of prices tailored to an individual consumer's willingness to pay, and cited Fetcherr's chief executive describing the company's use of all the data it could get its hands on. The senators borrowed Khan's most vivid illustration of the danger: a system that charges a higher fare because it knows the traveller just had a death in the family and needs to fly across the country at any cost. Pricing, in other words, calibrated not to the seat but to the customer's pain point, the precise moment of maximum desperation. Delta denied that it used personal data to set individual fares, insisting the AI forecast demand and market conditions rather than identifying any one passenger's willingness to pay. The denial is instructive, and we will return to it, because the more telling fact is not whether Delta is doing it today but that the infrastructure to do it now exists and is being marketed as a route to extraordinary profit.
Who Actually Said Yes
Strip the practice to its foundation and the question that will not go away is one of consent. Somewhere in the architecture of surveillance pricing there is supposed to be a moment at which the customer agreed to be priced as an individual, to have their financial circumstances inferred and held against them, to be charged according to a secret model of who they are. Find that moment. It does not exist.
What exists instead is a chain of consents to other things entirely. You agreed, in some buried clause, to let an app use your location, ostensibly to find your nearest store. You agreed to cookies so the site would remember your basket. You agreed to a loyalty card so you could collect points. You agreed to terms of service no one reads, in exchange for a service you actually wanted. At no point in any of this did a screen ask whether you would consent to those signals being fused into an estimate of your maximum tolerable price, and at no point would a rational person have said yes if it had. The Federal Trade Commission, examining the third-party intermediaries that build these systems, found a market drawing on data both volunteered by consumers and, more troublingly, inferred about them from first and third-party sources. Inference is the crucial word. You cannot meaningfully consent to a conclusion drawn about you that you never disclosed and may not even know is true.
This is what consumer advocates and privacy lawyers mean when they describe surveillance pricing as a black box. The customer cannot see what data the company holds, cannot see how the price was reached, and cannot see what other shoppers are paying for the same item at the same moment. The ordinary apparatus of fairness, the ability to know the reason for a decision and to contest it, simply never engages, because the reason is locked inside a proprietary model and the decision arrives disguised as a fact of nature. A price, to the person looking at it, appears to be something the world has handed down. It does not look like a profile, an accusation or a bet. But that, increasingly, is what it is.
The asymmetry is total. The seller knows the product's cost, the price it is showing you, the prices it is showing everyone else, the model that produced your figure and the data that fed the model. You know one number. You cannot tell whether personalisation is even happening, because a personalised price and a public one look identical: both are simply digits on a screen. The market was supposed to be an information system, aggregating dispersed knowledge into a public signal that let strangers coordinate their behaviour. Surveillance pricing inverts that function. It turns the price from a signal the market sends to you into a signal the seller secretly extracts from you, while you carry on reading the number as though it still carried its old, shared meaning.
What the Models Choose to Notice
There is a comforting story the industry tells about all this, and it deserves a fair hearing before it is dismantled. In theory, the argument runs, the ability to price each customer individually can expand a market rather than merely milk it. A seller who can identify price-sensitive buyers can profitably offer them a discount that brings them into the market, while charging more to those who can comfortably pay. On a whiteboard this looks almost progressive, a kind of automated means-testing that funds cheaper goods for the poor out of the wallets of the rich.
The world runs the logic in reverse. The signals a machine-learning system finds most useful for estimating willingness to pay are, with grim reliability, the same signals that track vulnerability and constraint. A shopper in an area with no rival supermarket within reach has fewer alternatives, and an algorithm can learn to read that absence of competition and charge for it. A household ordering nappies and repeat prescription items has predictable, inelastic demand, and inelasticity is precisely what a pricing model is built to detect and exploit. The customer with limited mobility, least able to drive between shops to compare, is the one least able to escape and therefore, on the model's own cold accounting, the one most worth charging extra. The system does not optimise for fairness. It optimises for revenue. The people with the least room to push back are exactly the people from whom there is most to extract.
A price built from inferred willingness to pay is, in the end, a price built from a model of who you are, and the characteristics that feed such a model are chosen for their predictive power, not their moral acceptability. If income predicts what you will pay, the model uses income, and if it can infer your income from your postcode, your phone and the brands you buy, it is charging you according to your wealth without ever asking your salary. If household size predicts inelastic demand for essentials, the model uses household size, which can mean that a larger and often poorer family faces systematically higher prices on the very goods it cannot do without. Some of these are characteristics that anti-discrimination law has spent a century learning to treat as illegitimate grounds for differential treatment. None is one that an ordinary shopper would knowingly hand over as a reason to be charged more for milk. And here the loyalty penalty completes its circle, for the most predictive signal of all is your own history. The longer the relationship, the richer the profile, the more confident the model becomes about exactly how much you will bear. Devotion, fed into the machine, comes out as leverage.
The Year the Law Began to Notice
For most of this story the law was simply absent. There is still no comprehensive federal statute in the United States governing surveillance pricing, and enforcement has leaned on the general prohibition of unfair or deceptive practices in Section 5 of the FTC Act, an authority written long before anyone imagined a retailer inferring your income from your shopping habits. That gap has begun to narrow at its edges rather than its centre. On 14 April 2026 the Commission issued an advance notice of proposed rulemaking on unfair and deceptive fee practices in online food and grocery delivery, taking comments until 18 May, and among its questions was whether platforms tell customers when the price in front of them has been personalised; the agency has also signalled work towards a policy statement on when failing to disclose the use of personal data to set an individual price becomes a Section 5 problem. That is rulemaking about disclosure in a single sector, not a prohibition, and it leaves the federal position roughly where it has always been.
The states moved faster, and the first of them moved earlier than the headlines of 2026 suggest. New York's Algorithmic Pricing Disclosure Act took effect on 10 November 2025, obliging a seller that uses personal data to set a price to say so, clearly and at the moment of the price, in a notice reading THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA, with civil penalties of up to a thousand dollars for each violation. The same Act bars the use of protected-class data where the effect is a price different from the one offered to others, and Attorney General Letitia James issued a public warning to New Yorkers as it came into force. What changed in 2026, then, was not that the law noticed surveillance pricing for the first time. It was what the law began to ask of it: the move from compelling a seller to confess the practice to forbidding the practice outright. And the centre of gravity is the food on your table.
Maryland moved first on prohibition. On 28 April 2026, Governor Wes Moore signed House Bill 895, the Protection From Predatory Pricing Act, the first law in the country to restrict surveillance pricing in the grocery sector. It takes effect on 1 October 2026. The statute prohibits food retailers above a certain size and third-party delivery services from using a consumer's personal data to set individualised prices, and pairs this with a rule requiring that displayed prices remain fixed for at least one business day, a direct check on the prospect of electronic shelf labels being used to surge the price of essentials minute by minute. Violations are treated as unfair or deceptive trade practices, carrying civil penalties of up to 10,000 dollars for a first offence and 25,000 dollars for repeat conduct. Enforcement rests solely with the state attorney general, who must give a company 45 days to cure a violation before acting, and consumers have no right to sue on their own behalf.
Those limits are not incidental, and Consumer Reports, while welcoming the law, criticised what it called weak enforcement provisions. Analysts at the International Association of Privacy Professionals catalogued the loopholes plainly: the ban bites only on prices customised for an individual, not on prices set for narrow segments of consumers; it establishes no baseline or standard price against which a personalised figure could be measured; and it explicitly exempts loyalty programmes, the very mechanism through which, in the British insurance saga, the loyalty penalty was built. A law that targets surveillance pricing while carving out loyalty schemes is a law with a gap shaped exactly like the original problem.
Connecticut went broader in scope and slower in delivery. Its Senate Bill 4 passed by overwhelming margins, 141 to 6 in the House and 31 to 4 in the Senate, Governor Ned Lamont signed it on 27 May 2026, and it is now Public Act 26-64. Where Maryland confined itself to groceries, Connecticut's law defines surveillance pricing as setting a customised price for a consumer or group of consumers based on personal data collected through any technology, and bans it across retail sellers and third-party delivery services. Businesses outside those categories that price this way are not forbidden to do it, but must label it, in wording substantially similar to THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA, which is New York's device sharpened by a verb. The act also reaches into the machinery that makes surveillance pricing possible, establishing a state registry of data brokers, building towards a single universal mechanism by which a consumer can demand deletion of their records across the whole industry, and prohibiting the sale of precise geolocation data, the very signal that pushed the price of a television up in a Target car park. By attacking the data supply rather than only the pricing output, Connecticut aimed at the root as well as the fruit. Its timetable, though, is staggered, and the pricing ban is the slowest-arriving piece of it: the privacy act amendments, including the prohibition on selling precise geolocation, begin on 1 October 2026, data brokers must register from 1 January 2027, the surveillance pricing restrictions do not bite until 1 July 2027, and the universal deletion mechanism is not in working use until late 2028. The practice was outlawed in Connecticut with more than a year's notice.
Connecticut also carved out much of what Maryland carved out. Loyalty and rewards programmes are permitted provided their terms are clearly posted and available to every eligible consumer, as are discounts offered to retain a customer, and price differences traceable to legitimate factors: delivery cost, timing, supply and demand, pricing errors, network outages. Insurance-licensed entities sit outside the pricing provisions altogether, as do credit decisions governed by the Fair Credit Reporting Act and the Equal Credit Opportunity Act. The loyalty carve-out, then, is not a Maryland eccentricity. It is a defining feature of this first generation of statutes, and it is the most awkward thing about them, because the loyalty penalty is where the story started. Britain spent the better part of a decade establishing that a rewards relationship is precisely the instrument through which a seller learns to price your captivity, and the first American laws against surveillance pricing have written that instrument into the list of things they do not cover.
New Jersey came third, and went at the thing the other two left alone. Governor Mikie Sherrill signed the Fair Price Protection Act on 23 July 2026, banning personalised algorithmic pricing based on personal data, browsing history, location or protected-class status in the grocery sector, while preserving, as its predecessors did, loyalty programmes and bona fide group discounts. It takes effect on 1 August 2027. What makes it the most consequential of the three is not its reach but its enforcement. Maryland and Connecticut hand the whole job to a state attorney general; New Jersey is the first jurisdiction in the country to give the shopper a weapon of their own. A consumer who believes they were charged more than others for identical groceries because of their personal data may sue under the New Jersey Consumer Fraud Act, individually or as a class, and recover treble damages where the conduct was wilful. The attorney general may still sue as well, for actual damages or fifty thousand dollars for each violation, whichever is the greater. That alters the arithmetic of compliance in a way a cure period and a capped penalty do not, because it turns an invisible practice into a litigable one.
These three are the leading edge of a wave rather than its conclusion, and the wave is now large enough to measure. More than forty bills across at least twenty-four states were introduced in 2026 to regulate personalised algorithmic pricing, already outpacing the whole of 2025. New York, having gone first on disclosure, is poised to go further: its One Fair Price Act, which would ban the practice outright rather than merely oblige a seller to admit to it, passed the legislature on 10 June 2026 and awaits the governor's signature, carrying penalties of five thousand dollars for a first offence and twenty thousand for those that follow. Vermont has taken a narrower route, permitting electronic shelf labels but barring price increases within the day except to correct a documented error, which is Maryland's one-business-day freeze rewritten as a rule about the shelf rather than the shopper. Not all of it will land. The wider point is that the law is responding at the level of state lines while the technology operates at national, indeed global, scale. The result, for the time being, is a map in which the legality of being charged a personalised price for a tin of beans depends substantially on which side of a state border you happen to be standing, and across most of the country the practice remains lawful, undisclosed and unmeasured.
Eight Companies and the Industrial Scale of Knowing
The clearest measure of how far this has already gone came when the FTC stopped theorising and started compelling. In July 2024, using its 6(b) authority, which lets it order companies to hand over internal documents whether or not it suspects wrongdoing, the agency issued orders to eight firms that sit, mostly unseen, in the machinery between retailers and shoppers: the payments network Mastercard, the consultancies Accenture and McKinsey and Company, the banking group JPMorgan Chase, and the pricing and personalisation specialists Revionics, Bloomreach, PROS and Task Software. The orders sought to map an opaque market in which intermediaries claim to use advanced algorithms, artificial intelligence and personal information, location, demographics, credit history, browsing and shopping behaviour, to categorise individuals and set a targeted price for each. The Commission voted unanimously to issue them.
When the preliminary findings landed in January 2025, the picture was not of a fringe experiment but of an established industry. The intermediaries examined were, between them, working with at least 250 clients, selling everything from groceries and clothing to health and beauty products and hardware. The capability to price an individual, in other words, is not waiting to be invented. It has been built, sold and installed at scale, wired into the systems of hundreds of well-known sellers. This is why the denials of any particular company, Delta insisting it does not use personal data for fares, the grocery platform Instacart insisting it merely assigns customers to random pricing cohorts, miss the point that industry analysts keep returning to. Instacart's own year makes the point for them. On 18 December 2025 it agreed to pay sixty million dollars in consumer refunds to settle an FTC lawsuit alleging deceptive delivery-fee and subscription practices, and was reported at the same time to be winding up its AI-based price testing. Neither fact is a finding that it ever charged anyone a surveillance price. Both establish that it had the apparatus and the appetite, and that a federal action was what changed its behaviour. Once the machinery is in place, the difference between not profiling you today and profiling you tomorrow is a single configuration change. The capacity is the danger. A loaded weapon does not need to be aimed at you to have altered the room you are standing in.
When a Price Stops Being a Public Fact
It is tempting to frame all of this as a story about money, about whether you personally end up paying a few pounds more or less. That framing is too small. The deeper casualty of surveillance pricing is something most of us have never had to think about because we have never lived without it: the public price, the single shared number that anyone can see, compare, refuse and undercut.
Consider what that shared number does. When a price is public, a shopper who thinks it too high can walk to a competitor. A rival firm that spots an inflated price can undercut it. A journalist can report it, a regulator can investigate it, and a neighbour can compare notes over the fence. The discipline of the market, the pressure that is supposed to keep prices honest, depends entirely on the price being a fact that more than one person can see. Surveillance pricing dissolves that fact. When your price is calculated for you alone, invisible to everyone else including the competitors, journalists and regulators who might otherwise discipline it, the price becomes a private transaction between you and a model. There is nothing for a rival to undercut, because they cannot see it. There is nothing for you to refuse on principle, because you cannot tell whether anyone else would have been charged the same. The very mechanism that makes markets self-correcting is switched off, quietly, one personalised quote at a time.
This is why disclosure remedies, useful as they are, feel inadequate to the scale of the thing. The European Union, through its Omnibus Directive, already requires a trader to tell a consumer when a price has been personalised on the basis of automated decision-making, and since November 2025 New York has required much the same in blunter language. That requirement has already survived the challenge you would expect. The National Retail Federation sued to have the New York label struck down on First Amendment grounds, arguing the state was compelling retailers to recite a misleading, government-scripted opinion about their own conduct. On 8 October 2025 the United States District Court for the Southern District of New York dismissed the case, holding the compelled disclosure plainly factual and not rendered controversial merely because the regulated business would rather not make it. That is a more important precedent than its narrow subject suggests, because it settles the proposition that a company has no constitutional right to conceal that it priced you from your own data. But being told that a price has been tailored to you, without being told from what data, by what logic, or to what end, restores only a sliver of the lost information. It is like being informed that a stranger has formed an opinion of your character, without being told what the opinion is or what evidence it rests on. The grievance is not merely that the price was personalised. It is that it was built from a portrait of you that you did not sit for, that you cannot see, that you cannot correct, and that may be wrong, unfair, or assembled from precisely the characteristics you would have refused to be judged by.
The ordinary intuition that there is something improper here is not economic naivety. It is an accurate perception that a hard-won feature of how markets are supposed to work is being removed, with nothing adequate put in its place. People do not, on the whole, object to a shop making a profit. They object to being individually appraised by a machine and charged according to a secret estimate of how much they can be made to bear, on the basis of data they did not knowingly surrender, with no way to see the number anyone else is paying. That objection is close to universal, and it is the bedrock on which any durable response will be built.
Switching the Lights On
So what is the customer at the invisible checkout actually to do? Honesty requires conceding that individual self-defence is mostly futile. Clearing your cookies, browsing in a private window, comparing prices across two devices: these are the folk remedies of a cruder era. The man who deleted his cookies on Amazon in 2000 found a cheaper DVD because the discrimination then was primitive. It is not primitive now, and a system that fuses hundreds of inferred signals cannot be reliably evaded by a shopper toggling settings. A person should not have to conduct counter-surveillance against their own grocer to be charged a fair price for bread, and the burden of evasion cannot honestly be placed on them.
The more truthful answer is that this is a collective problem requiring collective tools, and the encouraging part of the story is that those tools are beginning, unevenly, to appear. They arrive in three reinforcing layers. The first is sunlight: the dogged work of investigators, researchers and regulators in dragging an invisible practice into view, because surveillance pricing is a practice that struggles to survive being seen. The journalists who watched a television's price climb in a car park, the FTC compelling eight companies to open their books, the senators demanding answers from an airline, are all performing the same act of making the hidden visible so that it can be argued about. The second layer is disclosure as a legal default, the European and now the New York requirement to declare when a price has been personalised, imperfect but better than silence, and now tested and upheld in court. The third, on which the others depend, is substantive law of the kind Maryland, Connecticut and New Jersey enacted in 2026: rules that do not merely require a disclosure to be ignored but forbid the use of certain data and inferences to price the essentials of life, and give an enforcer real teeth. The loopholes in those first laws, the loyalty-scheme carve-out, the silence about consumer segments, the long lead times before the bans actually bite, show how much remains to be built. One of them has already been closed. The most cited weakness of the Maryland and Connecticut statutes was that they left the shopper with nowhere to go, and New Jersey's private right of action, treble damages and all, answers that objection directly. Everywhere else the enforcement gap remains what it was: one attorney general, a cure period, and a civil penalty a national retailer can treat as a rounding error.
What sets the direction of travel is a fact no amount of optimisation can engineer away. People do not want to be charged according to a secret guess about their desperation, and they do not want their loyalty read as a vulnerability to be priced. The British loyalty penalty was banned not because the maths was wrong but because the public found the principle intolerable once it was named. The same naming is now happening to its digital successor, in legislatures, in regulators and in newsrooms, and it is happening because the practice depends, in the end, on staying unnamed.
That naming is no longer a forecast. On 4 August 2026, two days before this piece went to press, the Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing titled Your Data, Their Profit: The Consumer Cost of AI Surveillance Pricing. Senator Josh Hawley chaired it, Senator Dick Durbin sat as ranking member, Lindsay Owens of the Groundwork Collaborative gave evidence, and Hawley opened by naming companies out loud: Staples, Target, Lyft, Amazon. Durbin, on a day when the two parties agreed about very little else, said he had little to add to it. A hearing is not a law, and nothing said in that room obliges anyone to change a single price. But the practice has now been described in public, on the record, by people who disagree about nearly everything, which is the condition under which a thing that survives on obscurity begins to lose.
The next time you confirm an order and the total looks about right, hold for a second the thought that you can no longer verify it is right, because right has quietly stopped meaning the same thing for everyone. The price you see may be the price everyone sees. It may be the price reserved for you alone, the loyal customer the system has finally finished learning. That you can no longer tell the difference is the whole of the problem. Reclaiming the ability to tell, the right to a price that is a public fact rather than a private verdict, is the whole of the answer.

