Few stories illustrate the gap between “what data subjects think they agreed to” and “what actually happens to their data” as vividly as the one that broke in June 2026. Millions of people who spent years scanning parks, murals and landmarks to catch Pokémon on their smartphones have discovered that those scans didn’t stay in the game. They became part of the training data behind a navigation system now being adapted for military drones operating in GPS-denied environments — including, potentially, war zones.
For anyone working in data protection or information security, this isn’t really a story about Pokémon. It’s a case study in purpose limitation failure, consent decay, and the practical impossibility of “unlearning” personal data once it’s inside a trained model.
What actually happened
Back in 2020 and 2021, Niantic — the company behind Pokémon Go — introduced “AR Mapping” tasks and Powered-Up PokéStops, inviting players to scan real-world locations with their phone cameras in exchange for in-game rewards. Over time this produced an enormous dataset: reportedly around 30 billion ground-level scans of streets, buildings and public spaces, now owned by Niantic Spatial, the spin-off created after Niantic’s gaming division was sold in 2025.
That dataset was used to train Niantic’s spatial AI foundation models — systems designed to help machines recognise and navigate physical environments from camera imagery alone, without relying on GPS. Niantic Spatial has since partnered with Vantor, a US defence contractor, to combine this navigation technology with drone and autonomous-systems positioning software. Vantor separately holds a US Army contract worth up to $217 million for related terrain-data work. Both companies maintain that the raw scans were not handed directly to Vantor, and that participation in the scanning feature was opt-in and covered by the privacy policies in force at the time.
Why this matters beyond the headlines
1. Purpose limitation is only as strong as your foundation-model boundary
Under UK GDPR and the Data Protection Act 2018, personal data collected for one purpose (helping a game recognise a landmark) shouldn’t be repurposed for a materially different, unforeseeable one (training navigation AI later adapted for military use) without a fresh lawful basis or, at minimum, a compatibility assessment. The difficulty here is structural: once ground-level scans are absorbed into a foundation model’s weights, the “purpose” attached to the original data effectively dissolves into the model’s general capability. The data hasn’t been deleted or even necessarily identifiable anymore — but its influence persists indefinitely, in a form that resists the kind of purpose-specific control that data protection law assumes is possible.
2. Consent given in 2021 rarely anticipates use in 2026
Even where scanning was genuinely opt-in, “informed consent” depends on the data subject being able to reasonably foresee the downstream use. Very few Pokémon Go players scanning a mural in a park could have anticipated that the same imagery might one day underpin GPS-denied navigation for autonomous military systems. This is the practical reality behind the frequently repeated complaint that people don’t read lengthy terms-of-service documents before playing a mobile game. Consent obtained for a narrow, fun, low-stakes purpose does not stretch cleanly to cover a high-stakes, dual-use purpose five years later — regardless of what the small print technically permitted.
3. "We didn't share the raw data" doesn't close the risk
Both companies have emphasised that scan data itself wasn’t transferred to Vantor — only the resulting trained models. From a strict data-sharing-agreement perspective, that distinction matters. From a data protection risk perspective, it’s less reassuring than it sounds. Academic and technical commentary on this story has noted that once training data is absorbed into a model, tracing or extracting any individual contribution becomes practically impossible — which cuts both ways. It limits some re-identification risks, but it also means data subjects have no realistic route to verify what became of their information, exercise erasure rights over it, or audit how much influence their contribution actually had.
4. Dual-use AI turns a commercial DPIA into a geopolitical one
Organisations building foundation models from user-contributed data increasingly need to consider not just “who is our direct customer” but “what could this model plausibly become part of downstream.” A Data Protection Impact Assessment written in 2021 for an augmented-reality gaming feature could not reasonably have flagged battlefield navigation as a foreseeable end use — but it illustrates why DPIAs for any large-scale spatial, biometric or imagery dataset now need to explicitly consider secondary and tertiary use by licensees, partners, and partners-of-partners, especially where the underlying technology has an obvious dual civilian/defence application (positioning, object recognition, terrain mapping).
What organisations should take from this
For any business collecting user-generated imagery, location, or spatial data — not just gaming companies — this case is a useful prompt to revisit a few fundamentals:
- Re-examine “foundation model” clauses in your privacy notices. If user data trains a general-purpose model rather than a single product feature, your notice needs to say so in terms a lay user would actually understand, and should address likely categories of downstream licensing.
- Build in periodic re-assessment of purpose compatibility, particularly for datasets that will be used to train models with a multi-year shelf life. What was compatible at collection may not remain compatible as the model’s applications expand.
- Extend due diligence to your licensees’ licensees. Contractual assurances that “we don’t share raw data” are necessary but not sufficient; the risk exposure follows the trained capability, not just the dataset.
- Treat dual-use potential as a standing DPIA criterion for any spatial, imagery, or biometric data project — not as an edge case to be assessed only if a defence contract is already on the table.
The Pokémon Go story is memorable precisely because the contrast is so stark — a children’s mobile game feeding into battlefield drone navigation. But the underlying pattern is entirely ordinary in modern AI development: broad, ambiguous consent; data absorbed into models whose downstream uses are neither disclosed nor easily traceable; and a widening gap between what data subjects believe they agreed to and what their data is actually doing, years later, in contexts nobody mentioned at the time.



