Schneier's Genie Coefficient Applies to Data Broker Removal, Too

Schneier's Genie Coefficient Applies to Data Broker Removal, Too

Bruce Schneier and Barath Raghavan published a piece in the August Crypto-Gram proposing a new metric for AI systems. They call it the Genie coefficient, and the setup is this:

"Major benchmarks measure what AI can do. None measure whether it does what you mean."

The example they use is the coffee example. If you ask a friend to grab you a coffee, the friend does not buy a coffee plantation. The friend does not bring you raw beans. The friend does not swipe a cup off a stranger's table. The friend uses context — what linguists call pragmatics — to bridge the gap between the literal words and what you obviously meant. An AI agent, wired up to tools and told to "get coffee," has no such bridge. It has capability and no intent. The Genie coefficient is their proposed way to measure the distance between the two.

That framing landed hard for me, because it describes the data broker removal industry perfectly.

Go look at any competitor's dashboard. What's the headline number? Requests sent. Opt-outs dispatched. Envelopes mailed. That's a capability benchmark. It's exactly the kind of benchmark Schneier and Raghavan are criticizing. It tells you what the vendor did. It does not tell you whether your exposure went down.

And there's a lot the "requests sent" number doesn't tell you. It doesn't tell you whether the broker acknowledged the request. It doesn't tell you whether the record actually came down. It doesn't tell you whether the record came back up a week later, which — if you've been paying attention to how the broker economy actually operates — is what happens most of the time. It doesn't tell you whether the same broker operates seven other sites under seven other names that got no request at all. It doesn't tell you whether the removal was aimed at your executive or at some other person with a similar name in a similar city. It doesn't tell you whether the executive's spouse and adult kids, who are the actual soft targets in most executive-threat cases, were in scope.

The buyer's intent when they sign a data-removal contract is "reduce my exposure." The industry's headline number answers "how many envelopes did we mail." That's a Genie gap, and it's a big one.

So what would a Genie-aware removal benchmark actually look like?

At Priwall we've been building the third-party efficacy audit around four questions. Coverage breadth, but measured in distinct broker operators — sibling sites, corporate parents, aliased brands — not envelopes. Removal confirmation, but verified by a subsequent third-party query, not by taking the broker's acknowledgement email at face value. Re-population resistance, measured at day 30, day 60, and day 90, because the broker economy re-lists and the only number that maps to real-world exposure is the curve over time. And identity precision, because a same-name removal against a random person in the same state is not a removal at all — it's the vendor gaming the volume metric.

Those four numbers close the Genie gap. "Requests sent" doesn't.

If you're an enterprise buyer, this matters because you're not buying opt-out theater. You're buying a reduction in the attack surface that fuels executive impersonation, targeted phishing, swatting, and — as Schneier points out three sections later in the same issue — warrantless government purchase of workforce identity records. A vendor that reports "we sent 4,000 opt-out requests last month" is answering the capability question. A vendor that reports "verified executive exposure is down X percent across the top 25 aggregators, and here's the day-90 re-population curve broken out by broker family" is answering the intent question. One of those vendors is being paid for output. The other is being paid for outcome. You're allowed to have an opinion about which one you want to write the check to.

The test for your current vendor is a two-question test. First: what's your day-90 re-population rate, verified independently, across the top 25 people-search aggregators? Second: what percentage of the records you removed last quarter were confirmed true matches to the identity you were hired to protect, and not same-name coincidences?

If they can't answer, they're selling you capability. They're not selling you outcome. That's the gap Schneier and Raghavan just gave us the vocabulary to name.

If you want the audited version of the four questions above run against your executive team, that's what priwall.io/compare is for.

Sources:
Bruce Schneier and Barath Raghavan, "Why AI Needs a 'Genie Coefficient,'" Crypto-Gram, August 15, 2026.
Bruce Schneier, "ICE Is Buying Access to Credit Card Records," Crypto-Gram, August 15, 2026.

Ready to try Priwall by mePrism yourself?

If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.

Sign up for Priwall by mePrism coverage.

Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across 700+ U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.

Next
Next

ICE Is Buying Your Credit Card Application. The Broker Layer Is the Real Story.