Daniel's got a whole thing about AI image geolocation this week, and it's not the technical how-does-it-work question. He's pointing at a tool called GeoSpy — and its successor, Raven — and asking something sharper. When an AI capability turns out to be too dangerous to sell to just anyone, who actually makes that call? In GeoSpy's case, it wasn't a regulator. Wasn't an export-control board. It was a journalist at 404 Media who made a free account, published what the tool could do, and suddenly the founder pulled it from public access. Daniel wants to know what it says about AI governance that the only gate that actually closed was the one a journalist forced open. And he's asking whether a founder acting as the sole gatekeeper is a feature or a failure.
The short answer is it's a failure dressed up as responsibility. But the details are weirder than that.
So we're going to dig into the GeoSpy story, how it got exposed, and what it reveals about the real power structure in AI safety. And I think the thing to sit with before we get into the timeline is — this isn't a hypothetical. The tool was live. Anyone could use it. And the only reason it isn't right now is that one guy decided he was embarrassed.
Let's define what we're talking about first, because the capability itself is remarkable. GeoSpy was an AI image geolocation tool developed by a company called Graylark Technologies, founded by Daniel Heinen. It launched in December of twenty twenty-three. You upload a photo — any photo — and it analyzes visual cues to tell you where it was taken. Vegetation, architectural styles, soil characteristics, the color of the sky, spatial relationships between objects. No GPS metadata needed, no EXIF data. It just looks at the image the way a trained analyst would, except it does it in seconds.
And it was accurate.
Accurate enough that law enforcement wanted it. And accurate enough that when 404 Media tested it in January twenty twenty-five, they demonstrated it geolocating not just clear smartphone photos but low-resolution surveillance stills. Grainy footage from a security camera, and it still got the location.
That's the part that should make people pause. It's not just that the tool works on vacation photos with landmarks in the background. It works on the kind of image a stalker might have.
Right. And that's exactly what 404 Media found. Members of Graylark's own Discord server were discussing using GeoSpy to locate specific women. This wasn't a theoretical risk — it was already happening in the community around the product.
So walk us through the timeline. What actually happened between launch and shutdown?
GeoSpy launches December twenty twenty-three. It spreads through the OSINT community — open source intelligence people, investigators, journalists. Free accounts are available. It's openly accessible. Then in January twenty twenty-five, 404 Media publishes their first article — "Cops Are Buying GeoSpy, AI That Geolocates Photos in Seconds." They reveal that police departments are customers, and they demonstrate the public demo. And very shortly after that article, Daniel Heinen closes public access.
But he doesn't shut the company down.
No. He pivots. The tool remains available to law enforcement and intelligence agencies. Then in May of twenty twenty-six — just a few months ago — Graylark relaunches the product under a new name. Raven. Withraven dot ai. Sold only to what they call verified agencies and investigative teams. You can't even see a demo without booking one. Known buyers include the Miami-Dade Sheriff's Office, running a pilot in their Cyber Crimes Bureau, and the LAPD.
So the public demo vanishes, the name changes, but the capability doesn't. It just gets a velvet rope.
And Miami-Dade officials have already put out the caveat that outputs are lead information requiring corroboration — which is the police version of "don't trust this blindly." But they're still using it.
Here's what I keep coming back to. The governance mechanism in this story, start to finish, was a journalist made a free account, published what the tool could do, and a founder unilaterally decided his own product was too dangerous to keep selling openly. No regulator. No export-control regime. No licensing board. No professional body. Just public embarrassment.
And that's not governance. That's damage control.
The question Daniel's really asking is whether that's the best we can do. And if it is, what does that say about every other AI capability nobody happens to be writing about?
Let me pull on a thread that makes this even stranger. GeoSpy is — or was — listed on the Maltego Transform Hub. Maltego is this graph-based investigation platform. Analysts use it to map relationships between entities — people, companies, domains, phone numbers. You start with one data point and pivot through transforms to find connections. GeoSpy was a live transform in their catalogue, published under Maltego Technologies, dated November twenty twenty-four. The listing described it as rapid AI-powered outdoor image geolocation, returned a ranked list of the ten most likely locations with coordinates and confidence scores.
So it's sitting in a catalogue next to WHOIS lookups and domain registrations.
Visually indistinguishable from any other investigative tool. And here's the thing — that Maltego listing still names its typical users as journalists, threat intelligence teams, and intelligence analysts. The headline use case is fact-checking to counter misinformation. Meanwhile, upstream, the vendor has closed the door on precisely that audience.
The toolkit converged, the sales counter split.
The restriction is invisible at the point of use. If you're an analyst browsing the Transform Hub, you see GeoSpy listed as available. The friction only appears when you try to get an API key from Graylark.
And Maltego themselves — they're not the ones restricting it.
No, and this is important. Maltego doesn't hold any data. Their own FAQ says they do not own, build, modify, or store any data used for investigations. It's a graph shell over other people's feeds. The sensitive capability was never theirs to ration. Eligibility lives with each third-party provider — in this case, Graylark — who issues the API key and decides who qualifies.
Maltego does have their own controls though.
They do, and they're worth understanding because they show what the baseline looks like. Personal vetting for enterprise sales — and their language is hedged, they say "to the best of our abilities." German embargo and anti-money-laundering law blocks sales into high-risk countries. Export rules block community edition registration in certain countries. But here's the thing — all of those controls are keyed to buyer country, not buyer intent.
So they'll check if you're in Iran. They won't check if you're a stalker in Florida.
Correct. And that's the gap. The country-level embargo catches state actors and sanctioned regimes. It does nothing about a domestic abuser who wants to track someone.
Let's talk about the technical mechanism for a minute, because I think it matters for understanding why this is different from other geolocation tools. What's actually happening under the hood?
GeoSpy uses computer vision and machine learning trained on an enormous dataset of geotagged images. It learns to associate visual patterns with locations. Architectural styles are a big one — the shape of windows, roofing materials, building proportions vary by region. Vegetation is another. Soil color, the way light falls at certain latitudes, the species of trees visible in the background. Even the color of the sky and the quality of light give clues about climate and hemisphere.
And it's doing all of this from visual cues alone. No metadata.
No GPS, no EXIF, no timestamp analysis. Just pixels. And it returns not just a single guess but a ranked list with confidence scores. Here are the ten most likely locations, here's how sure we are about each one.
How is that different from something like Google Images reverse search?
Google Images is matching the image itself — it's looking for the same photo or visually similar photos already indexed on the web. If you took a picture of a street corner and nobody else has uploaded that exact image, Google Images gives you nothing. GeoSpy doesn't need the image to exist anywhere else. It's inferring location from the content of the photo. It's the difference between fingerprint matching and... profiling.
Profiling a landscape.
And that's why it's so powerful for law enforcement and so dangerous in the wrong hands. A reverse image search fails on original photos. GeoSpy works on originals by design.
So let's get to the founder. Daniel Heinen. He builds this thing, releases it publicly, watches it spread through the OSINT community, sells it to cops, and then — only after a journalist demonstrates the stalker potential — he pulls the public access. What do we make of that?
I think there are two readings. The charitable one is that he genuinely didn't anticipate the misuse, and when it was pointed out to him, he acted. He restricted access to vetted buyers. He rebranded. He put a demo-booking requirement in place. Those are real steps.
The less charitable reading?
He knew exactly what the tool could do — he built it — and he was happy to sell it openly until the bad press arrived. The restrictions aren't a safety framework, they're a PR response. And the fact that he alone made the call, with no external review, no board, no regulator, no published criteria for who qualifies as a "verified agency" — that's not accountability. That's the opposite.
The decision to restrict access is arbitrary and unaccountable. He could reverse it tomorrow.
And there's nothing stopping him. That's the structural problem. If Daniel Heinen wakes up next week and decides the revenue from public access is worth the reputational risk, the demo goes back online. No hearing, no comment period, no oversight. The gate opens because the gatekeeper changed his mind.
What does "verified agencies" even mean?
That's the question. Graylark hasn't published criteria. We know Miami-Dade Sheriff's Office got access. LAPD got access. But what's the verification process? Is it a badge? A .gov email address? A phone call? And what about private investigators, insurance companies, corporate security firms — are they agencies? The term is vague enough to mean whatever the founder wants it to mean on any given day.
Which is the point. When the gatekeeper is one person, the gate is just that person's mood.
And set that against Maltego's approach, which for all its limitations is at least written down. Country embargoes are defined in law. Export restrictions are specific. It's not enough, but it's legible. You can argue with it. You can't argue with "Daniel Heinen said no."
Let's widen this out. This isn't the first time a dangerous AI capability has been restricted reactively after media scrutiny.
Clearview AI is the obvious parallel. Facial recognition tool, scraped billions of images from social media without consent, sold to law enforcement. It took a New York Times investigation in twenty twenty to bring it to public attention. Before that, it was operating in near-total secrecy. After the exposé, the legal fights started — multiple countries found it violated privacy laws, Clearview was fined, restricted. But again, the trigger was journalism.
And OpenAI's gradual rollout of capabilities. They didn't drop GPT-4 with full image generation and voice cloning and everything turned on. They staggered it. But who decided the pace? OpenAI did. Internally. No regulator set the timeline.
The pattern is consistent. The vendor assesses the risk, the vendor decides the restrictions, the vendor enforces them — or doesn't. And the only external pressure that reliably changes behavior is bad press.
So what happens to the capabilities nobody writes about?
That's the chilling question. 404 Media covered GeoSpy because a reporter happened to notice it, test it, and find the Discord conversations. How many tools with similar capabilities are operating right now with no scrutiny? How many are being sold to police departments or private clients with no public awareness at all?
The surveillance-as-a-service market is not small.
It's growing. And the regulatory vacuum means the default state of any new capability is "available until proven dangerous by a journalist."
Which is a terrible filter. Journalism is uneven. It depends on which stories reporters happen to find, which outlets have the resources to investigate, which topics are fashionable. It's not a safety net — it's a lottery.
And the stakes are not abstract. We're talking about a tool that can tell a stalker where someone lives from a photo they posted online. We're talking about regimes that could use this to identify the location of dissidents from images shared on social media. The 404 Media reporting found users in the company's own Discord discussing exactly this kind of misuse.
Let me push on something. Is restricting it to police actually the safe answer? Daniel's prompt flags this, and I think it's worth sitting with. The assumption in the pivot was — law enforcement good, public bad. But police use of AI tools has its own track record.
Miami-Dade's own caution — that outputs are lead information requiring corroboration — tells you they're aware of the risk. If the tool says a photo was taken at a specific address, and officers act on that without verification, you get wrong-door raids. You get people detained because an algorithm made a confident mistake.
And police departments are not uniformly good at treating algorithmic outputs as leads rather than conclusions.
They're not. There's a well-documented pattern of law enforcement over-trusting technology. Facial recognition hits treated as positive identifications. ShotSpotter alerts treated as confirmed gunfire. GeoSpy fits right into that pattern — it's fast, it's confident, it looks scientific. The temptation to skip the corroboration step is enormous.
So the "safe" pivot might just be shifting the harm from stalkers to wrongful arrests.
And the difference is that when a stalker misuses the tool, it's a crime. When a police department misuses it, it's a procedure that needs refinement. The asymmetry in how we treat those failures is part of why restricting it to law enforcement feels like a solution but isn't necessarily one.
There's another dimension here that I don't think gets enough attention. Graylark didn't just decide the tool was too dangerous for the public. They decided it was safe enough for police and intelligence agencies. That's not a safety judgment — that's a customer segmentation judgment.
With a revenue model attached. Law enforcement contracts are lucrative. They're recurring. They come with institutional credibility. Pivoting to enterprise sales isn't just about restricting access — it's about building a sustainable business. And there's nothing wrong with that, but let's not confuse it with a safety framework.
The safety framework would be: here is our published risk assessment, here are the use cases we prohibit, here is the independent body that audits compliance, here is the process for appealing a denial of access. None of that exists here.
And that's the gap. That's what Daniel's asking about. When we say "too dangerous to sell to anyone who asks," who defines dangerous? Who defines anyone? In this case, it was one guy in a company nobody had heard of before the exposé.
What would actual governance look like? If we're going to say this is a failure, what's the alternative?
I think there are layers. At minimum, you'd want published criteria for who can access a capability like this, with an application process that's reviewable. You'd want an external audit mechanism — not the vendor self-certifying that they're only selling to good guys. You'd want transparency about who's buying it. And you'd want some kind of appeal or redress if someone is wrongly denied or wrongly granted access.
None of which is radical. This is basic professional licensing logic.
It's how we handle plenty of other sensitive capabilities. You can't buy certain chemicals without a license. You can't operate certain radio frequencies without FCC approval. You can't export certain encryption technologies without review. The frameworks exist. They just haven't been applied to AI image geolocation because nobody thought to.
And because the companies building these tools have no incentive to invite regulation.
Their incentive runs the other way. Move fast, capture the market, deal with the consequences later. Heinen's pivot to Raven is a case study in that. The tool was live and unrestricted for over a year. That's a year of data collection, a year of model improvement, a year of building law enforcement relationships. By the time the public access got shut down, the business was already established.
The restriction didn't hurt the company. It probably helped. Exclusivity is a selling point.
"Only available to verified agencies." That's marketing language. It signals that you're getting something the public can't have. The velvet rope is part of the pitch.
So what does this tell us about the next five years? As capabilities get more powerful, what's the playbook?
I think we're going to see this pattern repeat. A company releases something powerful with minimal restrictions. It gets adopted widely. Someone — a journalist, a researcher, a whistleblower — demonstrates the harm. Public pressure forces a restriction that was always technically possible but never economically convenient. The company pivots to enterprise or government sales. And we all move on to the next thing.
The tools that don't get exposed just keep operating.
That's the bet these companies are making. That the likelihood of a 404 Media investigation is low enough to be worth the risk. And for a lot of them, that bet is going to pay off.
The GeoSpy case is also a reminder that the OSINT community itself is not a neutral space. The tool spread through open source intelligence practitioners — people who saw it as a powerful investigative aid. But the same Discord server where legitimate analysts were discussing use cases also had people trying to locate women. The community contained both things.
That's true of a lot of dual-use tools. The line between investigator and stalker isn't always visible from the outside. They use the same software, the same techniques, often the same forums. The difference is intent and target, and those are the hardest things to screen for.
Which brings us back to the founder-as-gatekeeper problem. Daniel Heinen can screen for "has a police badge." He can't screen for "won't misuse this tool." The badge is a proxy, and it's a weak one.
The badge also creates its own blind spot. We talked about police over-trusting technology. But there's also the question of what police do with location data. Surveillance of protesters. Tracking of journalists. Immigration enforcement. These aren't hypotheticals — they're documented uses of other investigative tools. Handing GeoSpy exclusively to law enforcement doesn't eliminate the misuse risk. It concentrates it in an institution with its own accountability problems.
The accountability for misuse, if it happens inside a police department, is opaque. Internal affairs investigations, qualified immunity, sealed records. The public may never know.
Contrast that with the public demo period. When the tool was open, 404 Media could test it, document the risks, and publish. The openness itself enabled scrutiny. The restriction to law enforcement reduces that scrutiny.
There's an irony there. The thing that made the tool dangerous — public access — was also the thing that made it possible to expose the danger.
Yes. And now that it's restricted, independent testing is much harder. We have to trust that Graylark's vetting works and that police departments are using it responsibly. Neither of those things is verifiable from the outside.
Let's talk about the Maltego angle one more time, because I think it illustrates something important about how these capabilities propagate. GeoSpy is listed in a catalogue of investigative tools. It's a transform you can plug into a graph analysis workflow. The listing still describes it as available for journalists and fact-checkers. But if you actually try to get access, you hit a wall.
Maltego's position is that they're not the gatekeeper. They provide the platform. The third-party provider sets the access rules. That's technically true, but it also means Maltego is hosting a listing that is, for most users, a dead end. The listing promises a capability the vendor won't actually provide.
It's a ghost entry. The tool is there and not there at the same time.
That's the fragmentation of AI governance in a nutshell. The platform says ask the vendor. The vendor says we only sell to verified agencies. The regulator says we don't have jurisdiction. The journalist is the only one who actually closed the loop.
Where does that leave us? Daniel asked whether founder discretion is a feature or a failure. I think the evidence points pretty clearly to failure. But I'm also not sure what the alternative looks like in practice.
I'm not sure either, honestly. The regulatory frameworks we have are slow. By the time an agency writes rules for AI image geolocation, the technology will have moved on to something else. And the companies building these tools have every incentive to stay ahead of the regulators.
The one thing I keep coming back to is transparency. If Graylark had to publish who they're selling to, if the criteria for access were public, if there were an audit trail — that wouldn't solve everything, but it would make the gatekeeping legible. Right now it's a black box with one man inside it.
Transparency plus some kind of external review. Even if it's just an advisory board with published findings. Something that isn't the founder's conscience.
Because the founder's conscience is a single point of failure.
In this case, it only activated after a journalist embarrassed him. That's not a safety system. That's a reputation management system.
Before we wrap up, Hilbert has been itching to say something about this.
Hilbert: I used to geolocate photos by hand.
Of course you did.
Hilbert: Freelance photographer for a local paper, early two thousands. Editor would hand me a stack of reader submissions — "where was this taken?" — and I'd spend hours with maps and city directories. Match the fire hydrant. Match the storefront. Match the angle of the street. Took forever.
What was your success rate?
Hilbert: Pretty good, actually. Had a notebook full of hand-drawn maps. Block by block. Noted which buildings had distinctive brickwork, which intersections had unusual signage. Called it the geolocation notebook. Still have it somewhere.
You're telling us this because...
Hilbert: Because the tool these people built — GeoSpy, Raven, whatever they're calling it now — it does in three seconds what took me three hours. And the thing I keep thinking about is, when I did it, there was a human in the loop the whole time. I had to justify my call. I had to show the editor which landmark I matched. If I got it wrong, it was my name on the correction.
The verification was built into the process.
Hilbert: It was the process. You couldn't skip it. This thing they've built now, it spits out a location and a confidence score and nobody has to show their work. The officer in Miami just sees "eighty-seven percent confidence, this address." That's not verification. That's a suggestion with a number attached.
The human element you're describing — that's exactly what disappears when you black-box it.
Hilbert: The founder's decision — pulling it from the public but keeping it for police — it reminds me of something. I had a photo once, showed a city councilman walking into a building he shouldn't have been at. Editor asked me to confirm the location. I did. Then he asked me whether we should publish it. Not could we — should we. That was his call. He made it alone. No policy, no board, just an editor at a desk deciding what the public got to see. I didn't agree with his call, but at least I knew who made it and why. This GeoSpy thing — nobody knows why the line is where it is. The founder drew it and walked away.
Do you still have that notebook?
Hilbert: In a box. Next to four broken light meters and a press pass from nineteen ninety-seven.
Four broken light meters.
Hilbert: They break. I kept them.
The thing about your editor — at least there was a newspaper with a corrections policy. If they got it wrong, there was a mechanism.
Hilbert: There was a mechanism because we'd been sued before. The policy wasn't proactive. It was scar tissue.
That's the whole episode, isn't it. The policy is always scar tissue.
Hilbert: I should get home. It's late.
The open question we're left with — if a journalist hadn't exposed GeoSpy, would it still be publicly available? And how many other tools with similar capabilities are out there right now, operating with no scrutiny at all?
As AI capabilities grow, the gap between what's technically possible and what's regulated is going to widen. Cases like GeoSpy are going to become the norm. The gatekeepers won't be agencies or laws — they'll be the people who built the tools, making unilateral calls about who's safe enough to use them. That's a fragile foundation for public safety.
The only thing that reliably triggers a restriction is public embarrassment. That's not a system. That's hoping reporters are paying attention.
Thanks to Hilbert Flumingtop for producing, and for reminding us that the geolocation notebook is a real artifact that exists in a box somewhere.
This has been My Weird Prompts. If you want to send us your own questions about the tools nobody's regulating yet, email the show at show at my weird prompts dot com.
We'll be back soon.