
I recently came across a prompt that asks ChatGPT to analyze you as though you were a person of interest. The prompt originated with a Reddit user and was picked up by UNILAD Tech. I tried it on myself, and the result was surprisingly good. It described me as a technically capable systems thinker with strong interests in cybersecurity, OSINT, education, history, and building frameworks. It also identified some of those same strengths as potential vulnerabilities: curiosity, intellectual overextension, a strong sense of responsibility, and a tendency to keep pulling on a thread once something interests me.
The result was interesting, but after thinking about it for a while, I realized there was a problem. It wasn’t really an OSINT exercise. The model was drawing on what it already knew about me from our private conversations. In effect, I wasn’t asking an intelligence analyst to investigate me. I was asking someone who had been sitting in my office for a very long time to write a report about me.
That led to a better question: What could an AI discover about me if it knew nothing about my private conversations and had to investigate me using only information available on the public Internet?
Looking From the Outside
I built an external version of the exercise using CTAR-OSINT-PIOA, a methodology I developed for conducting a person-of-interest assessment using publicly available information. The methodology requires the analyst to establish identity carefully, distinguish fact from inference and speculation, evaluate source reliability, identify information gaps, and deliberately attempt to disprove its own conclusions.
I then gave essentially the same exercise to five different AI systems: Gemini, Claude, Perplexity, Grok, and ChatGPT. The last one was particularly useful because it was ChatGPT looking at me from the outside, rather than drawing upon the accumulated context of our private conversations.
The results were remarkably consistent.
Apparently, I’m Easy to Find
All five systems were able to establish my identity with high confidence. They found my professional history, education, cybersecurity work, academic position, professional organizations, conferences, publications, interviews, and personal website. They also encountered a basic problem that any competent OSINT investigator has to deal with: my name isn’t unique. There are plenty of other people named Jeremy Blevins on the Internet.
That created the first useful lesson. Finding information isn’t the same thing as finding the right information. The better assessments treated identity as something that had to be established rather than assumed. They compared geography, employers, education, professional affiliations, chronology, and other identifiers before connecting records. That is the unglamorous part of intelligence work, but it is also one of the places where a seemingly sophisticated investigation can go badly wrong.
The Problem Wasn’t Any One Thing
The five assessments differed in their details and judgments, but they largely agreed about the biggest security issue. It wasn’t a password, an exposed server, or some secret buried in an old database. It was aggregation.
My education is public. My career is public. My certifications are public. My professional organizations are public. My conference appearances are public. My writing is public. My interests are public. My current professional role is public. Individually, none of these things is particularly remarkable. Put them together, however, and they produce a surprisingly detailed dossier. One model described the result as a rich source for social engineering; another characterized it as aggregation risk.
That distinction matters because we tend to think about information security in terms of things an attacker has to obtain. A password has to be stolen. A database has to be breached. A confidential document has to be exfiltrated. OSINT works differently. Sometimes the attacker doesn’t need to steal anything. They simply need to collect what we have already distributed and connect it.
We Don’t Have to Hide Everything
The obvious response to an exercise like this is to conclude that we should put less information online. I’m not convinced that is the right lesson. I teach, write, speak at conferences, participate in professional organizations, and maintain a public website. Being findable is part of doing those things, and I have no intention of disappearing from the Internet.
The more useful distinction is between visibility and vulnerability. I know what I have deliberately published, but an investigator isn’t limited to asking what I intended to disclose. An investigator can ask what those pieces reveal when they are combined. A conference program tells someone what I know. A professional biography tells them where I have worked. A public profile tells them who I know. A personal website tells them what interests me. An old biography tells them where I used to work. None of those things is necessarily sensitive by itself, but together they can provide the basis for a convincing story.
And once someone can construct a convincing story, social engineering becomes much easier.
The AI Didn’t Need to Know Me
This was the part of the experiment I found most interesting. The private-context assessment knew something about how I think. It identified patterns such as intellectual overextension, curiosity, responsibility, and the tendency to build elaborate frameworks around problems. The external assessments knew something different: what I have left behind.
The first assessment was about behavior. The second was about exposure. The important point is that the second assessment required no access to anything private. The models didn’t need to know me particularly well. I had already given the public Internet enough information to construct a surprisingly coherent picture.
That distinction is worth remembering because it changes the way I think about my own digital footprint. Privacy isn’t simply about keeping secrets. It is also about controlling how easily unrelated pieces of information can be correlated into something more revealing than any individual disclosure.
The Models Didn’t Always Agree
The experiment also demonstrated something important about AI-assisted intelligence analysis: OSINT is not simply a retrieval problem.
The models generally found the same basic facts, but they did not always assign the same meaning to them. Gemini tended toward a broader strategic assessment. Claude was more cautious about what my public record actually demonstrated about offensive technical capability. Perplexity emphasized governance, compliance, education, and practical social-engineering opportunities. Grok did particularly good work with identity resolution and name collisions. ChatGPT was especially conservative about distinguishing public professional history from evidence of current privileged access.
That divergence may actually be more interesting than the consensus. Five analysts can look at substantially the same information and reach somewhat different conclusions because they assign different significance to what they find. AI doesn’t eliminate that problem. It automates it.
That is why I deliberately built fact-versus-inference distinctions and red-team analysis into CTAR-OSINT-PIOA. A report can contain dozens of accurate citations and still reach an inaccurate conclusion. A professional credential does not establish advanced technical capability. An organizational affiliation does not establish access. Ten websites repeating the same biography are not ten independent sources. And the absence of publicly available information does not establish that someone is hiding it.
What I Learned About Myself
The exercise ultimately reinforced something I have taught in cybersecurity for years: information doesn’t have to be secret to be useful.
I have spent much of my professional life teaching people to think about attack surfaces, trust relationships, and the ways an adversary can combine seemingly harmless pieces of information. Then I ran that same exercise against myself. The result was a practical demonstration of the principle.
I don’t think the answer is to become a digital hermit. A professor needs a public professional identity. A writer needs a body of work. A researcher needs to publish. A professional speaker needs to be findable. The answer is to understand the footprint we create and occasionally examine it from the other side of the table.
Search for yourself. Resolve your own identity. Follow the links. Look at old biographies. Read what your professional organizations say about you. Then ask the question that matters:
What could someone reasonably infer about me from all of this?
That question is more useful than asking whether you have “too much information” online. The problem isn’t necessarily what you have disclosed. The problem is what someone else can reconstruct.
The original Reddit prompt was meant to turn the intelligence analyst’s gaze back on ourselves: If someone were researching me, what would they find?
After running the exercise, I think the more uncomfortable question is what happens when we actually answer it.
I thought I was testing what an AI could discover about me. Instead, I discovered how much of me I had already made discoverable.
The Internet doesn’t need to know everything about you. It only needs enough pieces to connect the dots.
The Devil’s in the Details
The Five AI Assessments
To see how reproducible the exercise was, I ran the CTAR-OSINT-PIOA methodology against five different AI systems using publicly available information only:
- Gemini
- Claude
- Perplexity
- Grok
- ChatGPT
Each system was given the same basic objective: investigate me as a person of interest using publicly available information, establish my identity, assess my professional and technical capabilities, examine my digital footprint, identify potential vulnerabilities, and distinguish facts from inferences. The results were not identical. That was expected. What surprised me was how much they agreed.
What All Five Found
The five assessments independently reconstructed essentially the same core identity: a North Alabama cybersecurity professional and educator with a long history spanning IT, cybersecurity, defense-industry work, higher education, professional organizations, and public speaking.
They consistently identified cybersecurity education, governance, compliance, information assurance, and workforce development as major areas of expertise. They also found the same general progression from technical and defense-related work toward education and institutional leadership.
More importantly, all five identified aggregation as the primary security concern. No single piece of information appeared particularly dangerous. The problem was the combination.
Education + employment history + certifications + professional organizations + speaking engagements + institutional affiliations + geographic information + personal writing create something much more useful to an investigator than any one of those pieces alone.
Where They Disagreed
The differences became more interesting when the models moved from collection to analysis.
Gemini tended toward a broader strategic assessment and gave considerable weight to my cybersecurity and defense-sector background.
Claude was more conservative about what the public record actually demonstrated, particularly regarding offensive technical capability. It also did a good job identifying contradictions and distinguishing historical information from current status.
Perplexity produced a similarly cautious assessment, emphasizing governance, compliance, education, and the practical possibilities for professional pretexting.
Grok performed particularly well at identity resolution and name-collision analysis. It was careful not to confuse other people named Jeremy Blevins with the subject.
ChatGPT’s external assessment was especially disciplined about source independence, identity resolution, and the distinction between public professional history and evidence of privileged access. It also explicitly red-teamed its own conclusions.
The important point is that the models were generally looking at the same person but did not always interpret the evidence the same way. That is a useful reminder that AI-assisted OSINT does not eliminate analyst judgment. It moves some of that judgment into the model.
The Technical-Capability Question
One of the most revealing differences concerned my technical capabilities. Some of the assessments initially treated my cybersecurity credentials, professional history, and defense-industry experience as evidence of broadly high technical capability. Others made a more careful distinction between what the public record actually demonstrates. There is an important difference between:
“This person has extensive cybersecurity experience.”
and:
“This person is demonstrably capable of advanced offensive cyber operations.”
The first is well supported by the public record. The second requires evidence that the OSINT investigation did not establish. That distinction is exactly why the PIOA methodology requires the analyst to separate fact, inference, and speculation.
Identity Resolution Was Not a Trivial Problem
All five systems encountered other people named Jeremy Blevins. This turned out to be one of the more important parts of the exercise. A search engine can find a person with the right name, but that does not establish identity. The stronger assessments used combinations of geography, education, employment, chronology, professional organizations, and other identifiers to establish that multiple records belonged to the same individual.
The external ChatGPT assessment was particularly explicit about this problem. It noted that the supplied LinkedIn profile could not be independently verified and refused to treat it as corroborating evidence simply because it had been provided as an identifier. That is exactly the kind of restraint an OSINT methodology needs.
The Aggregation Problem
The most consistent finding across the five assessments was that my public footprint is coherent and highly linkable. My professional identity connects naturally to my educational history. My professional history connects to organizations. Those organizations connect to conferences and publications. My personal website connects professional material to writing about technology, history, and other interests.
None of this is particularly unusual. The interesting part is what happens when an investigator follows the connections.
- A professional biography establishes one fact.
- A conference program establishes another.
- An old employer biography establishes another.
- A personal website establishes several more.
Together they create context. That context can become a pretext.
This is where the five assessments converged most strongly: the principal exposure isn’t that I have publicly disclosed some catastrophic secret. It is that there are enough pieces of information available to construct a convincing story about me.
What the Models Did Not Establish
The assessments also demonstrated the importance of knowing when to stop. None established:
- Classified access
- Current privileged government access
- Malicious cyber activity
- Criminal intent
- An exploitable technical system
- Complete current certification status
- A complete inventory of social-media accounts
- Complete employment history
- Private communications
- Private financial, medical, or family information
Several assessments explicitly cautioned against interpreting missing information as evidence that it was being concealed. That is an important distinction.
OSINT is an assessment of what can be established, not a license to fill gaps with assumptions.
The Five-Model Takeaway
If I reduce the five assessments to their common denominator, it looks something like this:
| Finding | Consensus |
|---|---|
| Identity is highly discoverable | Strong |
| Professional footprint is substantial | Strong |
| Cybersecurity is the dominant professional specialization | Strong |
| Governance, compliance, and education are major demonstrated capabilities | Strong |
| Public defense-sector history is significant | Strong |
| Current classified or privileged access was established | No |
| Malicious activity was established | No |
| Aggregation is the primary exposure | Strong |
| Social engineering is a plausible concern | Strong |
| Public information can produce a detailed professional dossier | Strong |
| AI models interpret the same evidence differently | Strong |
And that last point may be the most important. The experiment wasn’t simply five machines searching for Jeremy Blevins. It was five different analytical systems taking substantially the same collection of facts and constructing slightly different versions of Jeremy Blevins.
The collection converged. The interpretation diverged.
That’s the devil in the details.
A Note on the Method
The assessments were conducted on August 15, 2026, using publicly available Internet sources. The systems were not given access to my private ChatGPT conversations, private accounts, authentication material, or other privileged information.
I have preserved the individual assessments as part of the experiment rather than editing them to make them agree with one another. Their disagreements, omissions, false positives, and differences in confidence are part of the result.
The methodology used for the exercise is available here:
