Border Cyber Group | Public Interest Series | June 2026


The Eggs

In December 2025, a coalition of consumer researchers recruited 437 volunteers across the United States and sent them, simultaneously, to order groceries through Instacart from the same stores at the same time for the same items. The results were unambiguous. At a single Safeway in Washington, D.C., one dozen eggs were listed at five different prices — ranging from $3.99 to $4.79 — shown to five different customers at the exact same moment. The same shelf. The same carton. The same eggs. A 23% spread, determined not by any feature of the product, but by features of the buyer.

The investigation, published jointly by Consumer Reports, Groundwork Collaborative, and More Perfect Union, found that nearly 75% of grocery items on the platform were being offered to different customers at different prices. Extrapolated across a typical family's annual spending, the researchers estimated the practice added approximately $1,200 per year to some customers' bills — a figure they called an "invisible AI tax."

Instacart's explanation was that the price differences were the product of "randomised tests" conducted through Eversight, an AI pricing platform it had acquired in 2022 for $59 million. The company insisted the tests were not based on personal data. The FTC responded by issuing a civil investigative demand — the agency's formal mechanism for compelling document disclosure — before Instacart had finished issuing its press releases. Within days, the company announced it would halt the pricing experiments entirely. Not because a court had ordered it to. Because the backlash, regulatory and public, had arrived faster than its legal team could manage.

This matters because of what it reveals about the decision to run the experiments in the first place. Instacart built the capability, deployed it across its platform, exposed hundreds of thousands of consumers to it, and then framed its discontinuation as a response to "customer feedback." The sequence is instructive. The question is not whether Instacart made a mistake. The question is what kind of system produces this mistake as a predictable output.


A Distinction Worth Making

Before proceeding, a line must be drawn that most coverage of this topic is either unwilling or unable to hold.

Dynamic pricing — prices that change based on supply and demand — is a market mechanism as old as markets themselves. A flight on Christmas Eve costs more than a flight in February because demand is high and seats are finite. A hotel room during a music festival commands a premium because rooms are scarce and buyers are many. Consumers can dislike this on the receiving end; there is no dishonesty in the disliking. But the mechanism is, at minimum, legible. The price tells you something true about the relationship between what is available and how many people want it.

Surveillance pricing is categorically different. Here, the input is not the state of the market. The input is you — specifically, what an algorithm has inferred about your individual willingness to pay, derived from your browsing history, your purchase patterns, your device, your location, your app usage, the hour you tend to shop, and the behavioural signatures your digital life leaves behind. The price is not a signal about the market. It is a verdict about you. And you cannot see the reasoning, cannot verify the inference, and in most jurisdictions cannot opt out of the process.

The conflation of these two mechanisms — and it is a deliberate conflation, sustained by industry communications departments and absorbed by much of the press — serves one constituency. When a company practices surveillance pricing and is challenged on it, it can point to the decades-long acceptance of dynamic pricing and say: this is normal, this is how markets work, this is what airlines have always done. Calling both practices by the same name is not a clarification. It is camouflage, and it is highly effective camouflage because it transplants legitimacy from a practice people have grudgingly accepted onto a practice that is structurally different and substantially more invasive.


The Infrastructure

The Instacart investigation was revelatory, but Instacart is a delivery platform — a digital intermediary operating entirely through apps and websites. The more consequential infrastructure story is happening in physical space, in the aisles of ordinary grocery stores, and it is happening at a scale that has attracted relatively little public attention given what it portends.

Walmart is rolling out electronic shelf labels — digital price tags replacing paper ones — to every one of its approximately 4,600 U.S. stores by the end of 2026. The labels, sourced from French manufacturer VusionGroup, are already deployed in roughly 2,300 locations. Where paper tags required employees to physically walk every aisle and replace individual stickers — a process that could take days across a large store — digital labels allow every price in every store to be changed simultaneously from a centralised system, instantly, from a single interface.

Walmart has been careful about how it describes this. The company says prices are "people-led" — that a human associate must review and authorise every change, that updates happen outside shopping hours, that prices are the same for all customers in any given store, and that the technology simply modernises how prices are displayed. A grocery industry consultant at AlixPartners, Matt Hamory, put the underlying tension plainly: dynamic pricing "is playing with fire," he said, because "there is an element of consumer trust being eroded because they don't know that they're getting the best price at any moment."

What Walmart does not foreground in its public statements is that in January 2026, it was awarded a U.S. patent for a "system and method for dynamically and automatically updating item prices," and that in March 2026, it received a second patent for a machine learning tool designed to forecast consumer demand and recommend prices across product categories including food, clothing, and housewares. Neither patent is limited to the operational efficiency use cases the company describes in its communications. The first covers a system for e-commerce. The second applies machine learning to predict what consumers will buy and at what price — and to generate pricing recommendations accordingly.

The company has built the hardware network. It has patented the decision-making software. It has the technical capability to change 120,000 prices simultaneously across 4,600 stores. And it has publicly assured consumers that it will not use that capability in the way it was architecturally designed to be used.

That assurance is doing an extraordinary amount of work.

Walmart is not alone. Kroger has been experimenting with electronic shelf labels, updating digital tags to reflect online prices or weekly promotions. Whole Foods adopted the technology as early as 2016. This is not an outlier decision by one unusually aggressive retailer. It is an industry-wide infrastructure transition, proceeding largely without public debate, at the end of which the physical price tag — the one legible, static, unambiguous datum that has anchored the consumer's understanding of cost for generations — will have been replaced by a software-managed display that can be updated in seconds from a server room.


What the Algorithm Knows

The data that powers surveillance pricing is worth examining in detail, because the scope of it is not widely understood outside technical circles.

The FTC's January 2025 market study — the agency's most comprehensive assessment of the practice to date — found that third-party pricing intermediaries, hired by at least 250 retail clients spanning grocery chains and apparel retailers, were tracking mouse movements on web pages, abandoned shopping cart contents, demographic inferences, and real-time location data to set individualised prices. These intermediaries operate behind the scenes, invisible to consumers, processing behavioural signals that the consumer has no reason to connect to the price they see on screen.

The algorithm does not need to know your name. It needs your patterns. And from your patterns — the hour you tend to shop, the device you use, the postcode you shop from, the speed at which you add items to your cart and whether you pause on the price, the categories you browse before you buy — it can infer your income bracket, your urgency, your price sensitivity, and — most valuably from the seller's perspective — your inability to walk away.

Instacart's own patent applications, filed between 2017 and 2025, explicitly reference the use of personal, behavioural, and demographic data to tailor promotions and group customers into "subpopulations" defined by factors including purchase history, buying behaviour, age, gender, household size, and household income. When Consumer Reports confronted the company with this, Instacart responded that patent applications routinely use "overly broad and all-encompassing language" to "protect innovation and preserve optionality." This is a technically accurate defence of an epistemically evasive position: the patent describes what the system can do; the company's word is all that stands between the capability and its deployment.

The canonical example of how far this logic extends comes from Uber, which faced accusations — denied by the company — of using a rider's phone battery level as a pricing signal, on the theory that a customer with 10% charge remaining is more desperate and therefore willing to pay more. Uber denies the practice. But the accusation revealed something important: the logic is entirely coherent within the architecture of surveillance pricing. A battery percentage is a measure of urgency. Urgency is a measure of willingness to pay. The algorithm optimises for willingness to pay. The inference chain is clean.


The Discrimination That Goes Unnamed

There is a dimension of this problem that has received less attention than it deserves, perhaps because naming it precisely requires saying something that makes certain audiences uncomfortable.

If an algorithm sets prices based on behavioural data — browsing patterns, purchase history, device type, location, time of day — that data will inevitably correlate with race, income, neighbourhood, age, and disability status. Not because anyone programmed the system to discriminate on those bases. But because human behaviour is shaped by socioeconomic circumstance, and an algorithm trained on that behaviour will reproduce those correlations in its outputs. A person shopping from a lower-income postcode on an older device with a browsing history that reflects financial constraint will be assessed differently by the system than a person shopping from an affluent suburb on a new phone with a history of discretionary spending. The algorithm did not decide to charge them differently on the basis of who they are. But the outcome is functionally identical.

This is not algorithmic discrimination in the legally actionable sense — at least not yet, not as a settled matter of case law. But it is discrimination with a user interface. The redlining of the digital marketplace, conducted at inference speed, with no paper trail linking the disparity to any protected characteristic, and no mechanism by which the affected consumer can know it happened.

A separate Consumer Reports investigation into Kroger's data practices found that the company was constructing detailed profiles of individual shoppers through its loyalty program — including inferences about income, family size, education level, and gender. One shopper who exercised their rights under a state privacy law to request their data received a 62-page document. That profile is not a byproduct of the loyalty program. It is the product. The discounts are the price paid by the consumer for delivering data that is worth more to the company than the discount costs.


The Logical Endpoint

There is an analytical tradition in economics that describes what is happening here with clinical precision. It is called perfect price discrimination — or, in its formal classification, first-degree price discrimination. The concept predates the digital age by more than a century, articulated in theoretical terms by the economist Arthur Pigou in 1920. The idea is simple: rather than setting a single price for a product, a seller charges each individual buyer the maximum they are willing to pay. In doing so, the seller captures the entirety of what economists call consumer surplus — the gap between what the buyer would have been prepared to pay and what they actually paid. That surplus, which in a normal market accrues to the consumer, is instead transferred to the seller.

In textbook economics, perfect price discrimination has always been described as theoretically optimal from the producer's standpoint and practically impossible to achieve at scale, because it requires perfect information about every buyer's individual circumstances. The seller must know not just the prevailing demand curve but each person's precise position on it.

AI does not deliver perfect information. But it delivers an increasingly close approximation. And the direction of travel is clear. The data collection is accelerating. The models are improving. The infrastructure — electronic shelf labels, delivery app pricing layers, real-time behavioural tracking — is being built at scale, before the regulatory frameworks designed to constrain it have been established.

The textbook consequence of perfect price discrimination, were it fully realised, is that the buyer is left with no surplus at all. Every penny of value they would have retained by paying less than their maximum is extracted by the seller instead. In markets for discretionary goods, this is an injustice of the familiar kind: the consumer pays more than they should, the shareholder benefits, and the analysis proceeds. But the question that most coverage of surveillance pricing declines to ask directly is what this logic produces when applied not to discretionary goods but to essential ones.

Shelter, food, water, medicine, and energy are what economists call inelastic goods — meaning that demand for them does not respond proportionally to price changes, because the alternative to buying them is not going without a luxury. The alternative is going without. An algorithm optimising for maximum willingness to pay does not have a category called "essential good" that triggers different behaviour. It finds the maximum and charges it, whether the product is a third pair of trainers or a month's insulin.

This is not a hypothetical trajectory. In August 2024, the U.S. Department of Justice filed an antitrust suit against RealPage, a Texas-based property management software company whose algorithmic pricing tools covered approximately 16 million rental units. The DOJ alleged that RealPage's software collected non-public, competitively sensitive data from competing landlords — vacancy rates, lease terms, achieved rents — and used it to generate pricing recommendations that effectively coordinated rent increases across properties that were supposed to be competing with each other. The result was not personalised pricing in the conventional sense but cartel-like alignment of rents across markets, achieved through a shared algorithmic intermediary rather than a smoke-filled room. In November 2025, RealPage settled without admitting wrongdoing, agreeing to a seven-year consent decree restricting its data practices.

The mechanism in the RealPage case was not identical to the personalised pricing practiced by Instacart. But the underlying logic — using aggregated data to extract maximum price from a market characterised by constrained choices — is structurally continuous with it. The same algorithmic architecture applied to food in the digital aisles, and to housing in the rental market. In both cases, the buyer's options are constrained. In both cases, the algorithm's task is to find the edge of what the buyer can bear. In housing, the edge of what you can bear is the difference between having a roof and not having one.


The Regulatory Response and Its Limits

The legislative response to surveillance pricing has been faster than such responses typically are, which reflects the unusual combination of political pressures driving it: cost-of-living grievances, data privacy concerns, and a broadly felt sense that something structurally unfair is occurring, even among people who cannot fully articulate its mechanism.

In November 2025, New York became the first state to enact a surveillance pricing law, under Governor Kathy Hochul. The Algorithmic Pricing Disclosure Act, enacted as part of the state budget and effective from November 2025, requires companies to display a clear statement alongside any algorithmically set price: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." The New York Attorney General's office subsequently challenged Instacart's compliance, arguing the company had buried its disclosures in fine print — on a page accessible only through a link in the platform's footnotes.

In April 2026, Maryland became the first state to go beyond disclosure and ban the practice outright — at least within a defined sector. Governor Wes Moore signed House Bill 895, the Protection From Predatory Pricing Act, into law on April 28th. The Act prohibits food retailers and third-party delivery services from using customers' personal data to charge individualised prices for food products, and also bars the use of what it defines as "protected class data" in pricing decisions — an explicit acknowledgement of the discrimination risk. Civil penalties run from $10,000 per violation to $25,000 for repeat offenders. The law takes effect October 1, 2026.

Consumer Reports, which was involved throughout the legislative process, described the final Act as insufficient. Its enforcement provisions are weak: there is no private right of action, meaning individual consumers cannot sue; only the state's Attorney General can bring enforcement proceedings, and only after giving the violating company 45 days' notice of a violation and the opportunity to correct it before any legal consequence attaches. The disclosure requirements of New York's law, imperfect as they are, at least create an audit trail. Maryland's outright ban is harder to verify without enforcement teeth proportionate to the practice it targets.

At the federal level, Congressman Josh Gottheimer introduced the No Rigged Grocery Prices Act on May 18, 2026, with bipartisan co-sponsorship, which would extend a prohibition similar to Maryland's to the national level. Senator Ben Ray Luján has separately proposed legislation that would ban electronic shelf labels outright in any grocery store exceeding 10,000 square feet — a threshold that would effectively halt the digital label rollout across most of American grocery retail. The House Committee on Oversight and Government Reform, under Chairman James Comer, has sent document requests to Booking Holdings, Expedia, Uber, Lyft, and Instacart. More than 60 pricing-related bills are currently active across state legislatures.

The regulatory picture, in other words, is one of rapid and genuine legislative mobilisation. The question is whether it is moving faster than the infrastructure being built to render it moot.


The Sequencing Problem

This is the analysis that is consistently missing from coverage of surveillance pricing, and it is the one that matters most.

The standard narrative of technology regulation runs approximately as follows: a new technology emerges, causes harm, generates public outcry, attracts regulatory attention, and is eventually constrained by law. The sequence presupposes that the harm is the reason for the response. What is distinctive about surveillance pricing is that the infrastructure is being built, and has been built, in advance of any legal constraint on its most aggressive applications — and the companies building it have spent that unregulated interval establishing the technical architecture, the data flows, the algorithmic capabilities, and the commercial relationships that any future regulatory regime will have to contend with as facts on the ground.

Walmart's electronic shelf labels are not a future capability. They are being installed now, in every store, at a pace Walmart itself says cannot come fast enough. The patents for automated, AI-driven price optimisation are filed and approved. The data pipelines that feed the algorithms exist and are expanding. By the time legislation achieves national effect — if it does — the physical and computational infrastructure of surveillance pricing will be as deeply embedded in the retail supply chain as the barcode.

This is not a coincidence, and characterising it as one is a category error. The construction of capability in advance of regulation is a strategy, not an accident. It is the same strategy that has structured the build-out of social media, financial technology, and large-scale data brokerage: move faster than the state, establish the network effects and supply chain dependencies that make unwinding the technology prohibitively disruptive, and then negotiate from a position of infrastructural entrenchment when regulation finally arrives. The RealPage settlement is illustrative here: after years of alleged market manipulation across 16 million rental units, the outcome was a seven-year consent decree with no fines, no admission of wrongdoing, and no judicial finding of illegality. The infrastructure of coordination remained intact.

There is also a question — less frequently raised than it should be — about what the regulatory framework being built actually regulates. Maryland's law covers food retailers above 15,000 square feet. New York's disclosure requirement applies to online retail. Neither addresses the data brokers who sit between the consumer and the retailer, aggregating behavioural profiles that the retailer itself may not formally hold. Neither addresses the pricing intermediaries, like Eversight, whose commercial purpose is precisely to abstract the pricing decision away from the retailer into a layer of AI that the retailer can then plausibly disclaim. The consent decree obliging a company to disclose when a price was set by an algorithm using your personal data presupposes that there is a chain of custody traceable enough to establish that fact. In the actual architecture of modern retail pricing, that chain is deliberately obscured.


What This Is

Surveillance pricing is typically described, even by its critics, in terms of fairness — as something that disadvantages some consumers relative to others, that lacks transparency, that ought to come with disclosure. These criticisms are accurate, and they are insufficient.

What surveillance pricing represents, at the level of structural analysis, is the technical realisation of a project that capital has always pursued: the elimination of the buyer's negotiating position by perfecting the seller's information advantage. In every market transaction, both parties hold incomplete information. The buyer does not know the seller's true cost. The seller does not know the buyer's true willingness to pay. This mutual opacity is what creates the conditions in which a price is negotiated — or, in mass retail, in which a single posted price represents a compromise between what the seller can get from the most price-sensitive buyers and what it forgoes by not extracting more from the least price-sensitive ones. The gap between the posted price and the maximum any individual buyer would have paid is consumer surplus: value that stays with the consumer.

The explicit objective of surveillance pricing — stated this way in the commercial literature that promotes it, in the pitch decks of pricing AI companies, in the economics textbook accounts of first-degree price discrimination — is to eliminate that surplus. To take everything the buyer would have left on the table. To make the price not a market signal but a personalised extraction, calibrated to what the algorithm infers about this specific person's ability to resist.

Applied to luxury goods, this is a transfer of wealth from buyers to shareholders, mediated by an algorithm. Applied to food, it is an extraction mechanism operating on people whose budgets are already constrained, whose options are already limited, and who — in the 47.9 million households the USDA counts as food-insecure in 2024 — have the least capacity to absorb the difference. Applied to housing, as the RealPage case demonstrated, it coordinates the extraction upward across an entire rental market.

The technology does not distinguish between these cases. It does not have a subroutine that checks whether the good in question is essential before proceeding with the extraction. It finds the maximum you can be made to pay and it charges you that. The question of whether the good is something you can decline to buy — or whether declining means going hungry, going unhoused, or going without medication — is not a variable in the optimisation.

Calling this "personalised pricing" is the industry's preferred framing, and it is an extraordinary piece of language management. The word "personalised" carries connotations of tailoring, of service, of something done for you. What is being described is a system designed to know you well enough to take more from you. The personalisation is in the service of the extraction, not the consumer.


The Watchman

There is a phrase in the literature of financial regulation — "regulatory capture" — that describes the process by which the agencies established to oversee an industry come to serve that industry's interests rather than the public's. The concept does not fully describe what is happening with surveillance pricing, but something adjacent to it is visible in the structure of the response.

New York's disclosure law was written, in part, in consultation with retail industry stakeholders. Its enforcement mechanism — requiring disclosure "clearly and conspicuously" near a price — was immediately tested by Instacart's practice of placing its disclosure on a page accessible only by clicking through fine print, and found wanting. Maryland's prohibition contains carve-outs for loyalty programs, which are one of the primary mechanisms through which individualised pricing data is collected. The No Rigged Grocery Prices Act, whatever its merits, was introduced three years after Instacart acquired Eversight and began deploying it at scale.

The FTC's January 2025 research summary on surveillance pricing produced findings that the agency described as disturbing. It took no enforcement action, having already lost much of its investigative authority in the intervening legal and political landscape. The civil investigative demand to Instacart is a data-gathering instrument, not a charging document. The House Oversight Committee's document requests to five companies are investigative instruments operating in a Congress that has not yet passed a single federal law on the subject.

Meanwhile, the infrastructure buildout continues. The algorithms improve. The data flows deepen. Every purchase, every hesitation in an online cart, every click-through from a targeted discount, is another training example for the model that sets the next price.

The question the eggs in that Washington, D.C. Safeway actually posed was not whether Instacart was behaving badly. It was whether the system that produced the behaviour has any internal mechanism that would prevent it from continuing. The answer, examining the evidence, is that it does not. The mechanism is external — regulatory, legal, and political — and it is being built, with genuine urgency, by people who understand what is at stake. The question is whether it is being built fast enough, and whether it addresses the right things, before the infrastructure it is meant to constrain becomes too embedded to meaningfully constrain at all.

The algorithm is watching. The question — the only question that matters — is who is watching the algorithm.


Border Cyber Group produces independent investigative analysis at the intersection of technology, security, and power. bordercybergroup.com

If you would like to support our work, buy us a coffee!: https://bordercybergroup.com/#/portal/support