Your Digital Twin Is Already Being Built
The version of you living on servers you never signed up for.

I want to introduce you to someone you have almost certainly never met. They live on servers in data centres you will never visit. They have never spoken to you, but they know your purchase patterns, your location history, your browsing behaviour, your social connections, your health indicators, your financial habits, and hundreds of other attributes inferred from the digital traces you leave behind. They are consulted in decisions about you. What credit product to offer you. What price to charge you. Whether to flag you as a fraud risk. They are bought and sold without your knowledge, updated continuously without your input, and referenced in decisions that shape your life without you ever knowing the reference happened. This person is your digital twin. Unlike the science fiction version, it was built without your consent, does not resemble you in ways you would recognise, and exists to serve interests that are not yours.
This is not a hypothetical about a possible future. It is already infrastructure, operating at scale, already affecting the lives of billions of people. The companies, data sources, and models involved are less visible than the social platforms that supply the input data, but they are no less real, and arguably more consequential in terms of the decisions they shape. Understanding what the digital twin industry actually is, what it does, and what it would take to give people meaningful control over the version of themselves that lives in it, is one of the more urgent tasks in the governance of personal data.

Building a digital twin starts with data that is either directly given, passively collected, or inferred. Directly given data is the information you deliberately submit to services: your name, address, the answers to sign-up forms. Passively collected data is everything harvested from behaviour: location from your phone, browsing patterns through tracking pixels, app usage, purchases through loyalty programs, and the behavioural signatures created by how you interact with devices. Inferred data is perhaps the most significant category: attributes not directly observed but calculated from the combination of the other two, including personality traits, health conditions, relationship status, political views, and psychological vulnerabilities.
The data broker ecosystem that aggregates and trades all of this is large, lightly regulated, and largely invisible to the people whose data it trades. Brokers combine partial records into comprehensive profiles: your purchase history from loyalty programs, your location data from a mapping app, your social activity from a data partnership, your credit history from a bureau, and demographic inferences from a census model, into a profile that none of the original sources could have produced but their combination makes possible. The result is sold to whoever will pay. Advertisers, employers, landlords, insurers, campaigns, sometimes law enforcement.

The AI dimension is what makes the current moment qualitatively different. Machine learning models applied to aggregated data can extract patterns no human analyst could, and generate new attributes by inference, fill gaps in the record by imputation, and predict future behaviour with enough accuracy that the twin becomes a forward-looking model rather than just a backward-looking record. The twin in a broker's database is not a snapshot of who you were. It is a model of who you are and what you are likely to do next.
The most profound thing about the twin that exists without your consent is that you are not its author. Every piece of data in it was collected by someone else, every inference was drawn by an algorithm you did not build and cannot examine, and every attribute was assigned by a process you had no input into. In the specific, consequential sense of the portrait that gets consulted when decisions are made about your credit, your employment, your insurance, and increasingly your interactions with public services, your identity is not something you construct and project. It is something others construct about you and deploy on your behalf.
This matters beyond the specific decisions. Identity is not just a description of who you are. It is an ongoing project of who you are becoming. A world in which the operationally important version of you is an algorithmic model built from your past behaviour, deployed by the institutions that govern your access to opportunity, is a world where the self you are trying to become gets pre-empted by the self the algorithm has already filed.

There is also the specific problem of errors. Twin profiles are built from imperfect data using imperfect inference, and they contain mistakes that can have serious consequences for the people they misrepresent. Credit records contain errors that lock people out of products they should qualify for. Health inferences from purchasing data misclassify people based on correlations that do not apply to them. Fraud risk scores flag the innocent. The people harmed by these mistakes typically have no way to know the profile exists, no right to see it, and no meaningful recourse when a decision based on it hurts them. The digital twin is an author of your life you cannot read and cannot edit.
The governance frameworks that would give people real control over their twins are not technically radical. They involve clear rights to know what data has been collected and what has been inferred, the right to access and contest the profile, and the right to limit the use of that profile to purposes you have meaningfully consented to. Several jurisdictions have some version of these rights. Implementation has generally been inadequate to the scale of the industry. Rights that require you to navigate dozens of separate broker opt-outs, that do not apply to data sold before the law came into force, and that are enforced by regulators with insufficient resources, are not meaningful control.
The digital twin is not going away. The data collection is too entrenched, the ecosystem too profitable, and the regulatory response so far too slow. What can change, with sustained pressure, is who controls the twin. The vision worth working toward is not one where the twin does not exist. It is one where you are its primary author rather than its subject, where the model of you that institutions consult reflects what you have chosen to disclose rather than what others have inferred, and where the accountability for errors rests with the people who built it rather than the people who had to live with the consequences.
You might also like
View all
Are We Giving AI Too Much Control?
Control does not transfer in one moment. It seeps out one small decision at a time.

The Internet Is Being Flooded With AI Slop
Near-zero production costs, and what happens to the signal beneath the flood.