The Fibbing Four Are at It Again “Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?” That was the question Sen. Ron Wyden (D-OR) put to then-Director of National Intelligence James Clapper in an open hearing in 2013. “No sir,” Director Clapper responded, then qualified his statement by saying, “not wittingly.” It has since been proven – and is a matter of government record – that the NSA’s global trawl of data has pulled in the communications of Americans by the millions over the last five years. Quite a record for a surveillance authority enacted by Congress to surveil foreign targets on foreign soil. See for yourself the misuse of this authority revealed in a rare public scolding of the FBI by the secret FISA Court over “widespread violations” of Americans’ privacy with Section 702 data. Or look at the revelations issued by that court of specific instances of how the FBI misused warrantless Section 702 material against U.S. political figures. It is widely reported that the FBI has freely helped itself to Section 702 data, searching the data of more than 19,000 congressional donors, a state judge, and Members of Congress. The Hunter Biden Laptop Deceit In 2016, former Director Clapper was joined by former CIA Director John Brennan, former NSA General Counsel Glenn Gerstell, and former NSA Deputy Director Richard Ledgett, along with almost 50 other former senior intelligence officials in signing a letter released just before the 2020 election. They chimed in on a New York Post story about the contents of a laptop owned by Joe Biden’s son, Hunter. This time, the Fibbing Four solemnly told the American people that the contents of the Hunter Biden laptop had “all the classic earmarks of a Russian intelligence operation.” The FBI later determined that the emails and contents of the laptop were “not tampered with or manipulated.” Even The New York Times was forced to report that the laptop and its contents were genuine. The irony is that former intelligence officials, abusing their continued access to classified information to skew a national election, is about the most Russian thing they could do. Misinformation About Reform Legislation Now Director Clapper, and his Hunter Biden colleagues Brennan, Gerstell, and Ledgett, have fired off another letter. This one is directed at Congress telling Members not to allow any reform amendments to the Foreign Intelligence Surveillance Act authority, Section 702, because that would degrade the government’s ability to protect Americans. “If Congress fails to authorize Section 702, history may judge the lapse of Section 702 authorities as one of the worst intelligence failures of our time,” they write, joined by enough of their colleagues to get the number of signatories up to around 50. “As Members of Congress know, we face sophisticated threats from China, Russia, Iran, and North Korea, including the real possibility of devastating cyber-attacks and state-sponsored terrorism directed at Americans.” These are, of course, real and active threats. But the Fibbing Four gloss over the fact that all of the reform proposals being proposed in Congress contain exceptions for “exigent circumstances.” These exceptions would allow intelligence agencies to react to time-sensitive emergencies, such as the so-called “ticking time bomb” scenario. These reform proposals also contain exceptions for cybersecurity and warrantless searches of metadata, requiring court approval only to examine the content of Americans’ communications. Fool Me Once… The good news is that Congress is getting wise to such shenanigans just before every vote. Before the last Section 702 reauthorization two years ago, the champions of the intelligence community put out a cryptic story about “a serious national security threat” that turned out to be theoretical, not imminent, reports about “Russian space nukes.” Our advice to Congress is to look at the plain language of the reform legislation that allows the intelligence community to continue to defend America – while upholding our constitutional rights as well. We can defend America and obey the Constitution at the same time. Don’t let anyone tell you otherwise. Bob Goodlatte, our senior policy analyst, who also represented Virginia’s 6th District in Congress and chaired the House Judiciary Committee, published an op-ed in the Washington Times.
The debate over the FISA Section 702 surveillance authority is often framed as a clash between national security and privacy. But that framing is flawed – and dangerously so. What Congress now faces is not just a Fourth Amendment question. It is a test of whether warrantless surveillance powers could quietly erode gun rights. A “clean” reauthorization of Section 702 – one that excludes meaningful reforms – is an implicit threat to the Second Amendment.
The American Prospect reports that statements made by Rep. Jim Himes (D-CT), Ranking Member of the House Permanent Select Committee on Intelligence, are raising the question of how well Members of Congress understand the surveillance authorities they oversee.
“I am not aware of any NSA purchases of U.S. person data,” Rep. Himes is quoted as saying in a virtual town hall last week. “And because their targets, by law, are exclusively foreign, they … have no reason and no business buying American data.”
We agree with the last part of that statement. If only the first part were true. In a letter sent in 2023 in response to a query from Sen. Ron Wyden (D-OR), then-NSA Director Gen. Paul Nakasone wrote: “NSA acquires various types of CAI (commercially available information) for foreign intelligence, cybersecurity, and other authorized mission purposes, to include enhancing its signals intelligence (SIGINT) and cybersecurity missions. This may include information associated with electronic devices being used outside and, in certain cases, inside the United States.” Charlie Savage of The New York Times summarized the letter’s content thusly, “The National Security Agency buys certain logs related to Americans’ domestic internet activities from commercial data brokers.” This characterization was under the headline, “N.S.A. Buys Americans’ Internet Data Without Warrants, Letter Says.” Rep. Himes also said that AI “has absolutely nothing to do with 702. Nothing. Full stop.” The American Prospect reports that the Department of Justice’s National Security Division (NSD) budget justification shows that NSD “worked closely” with the intelligence community “to discuss new AI tools that are involved in processing or analyzing FISA-acquired information.” All of which suggests that before the House debates the reauthorization of FISA Section 702 – a program that authorizes foreign surveillance on foreign soil but has often been used to warrantlessly spy on Americans on U.S soil – a deeper discussion with civil liberties groups and a robust House debate are warranted. In facing the looming Section 702 debate, Members of the House need to hear from all sides of the surveillance debate – not just the approved line from the executive branch intelligence agencies. LETTER TO CONGRESS: A Clean Extension of FISA Section 702 Will Undermine Second Amendment Rights4/6/2026
A warning from Bob Goodlatte, former Chairman of the House Judiciary Committee and Senior Policy Advisor at the Project for Privacy and Surveillance Accountability: In the FISA Section 702 reauthorization debate, understand that the stakes go beyond your constituents’ privacy and Fourth Amendment rights. This debate will determine whether warrantless surveillance powers will quietly erode the Second Amendment. A “clean” reauthorization of Section 702 – without meaningful reforms – would lock in a system able to track lawful gun ownership across America. Because many firearms sold in the United States are manufactured abroad, the communications surrounding those transactions – emails, calls, shipping, and logistics data – are often swept into Section 702 databases. As Patrick Eddington of the Cato Institute has reported, this data provides insight into firearm transactions at a level of “commercial granularity” that can rival – or exceed – a formal gun registry. Now consider how this data can be abused when combined with other sources:
Layer these datasets together – add the power of artificial intelligence – and a comprehensive gun ownership database can be assembled, even though Congress has explicitly prohibited a federal gun registry. Without guardrails, current surveillance authorities create a backdoor path to that exact outcome. Government agencies will easily be able to map the political associations and religious affiliations of gun owners. Vote “No” against a “clean” reauthorization of Section 702. Congress must add safeguards to protect our constitutional rights. As Congress prepares to debate the reauthorization of FISA Section 702, lawmakers should understand one simple fact: Americans do not trust the government with their data. A new poll shows that 74 percent of Americans are concerned about the privacy and security of their personal data in government hands. The poll, released last week by the Center for Democracy & Technology (CDT), shows that 79 percent of respondents agreed that: “Congress should use its authority to hold the government accountable when it ignores privacy laws.” “People want their privacy protected,” said CDT’s Elizabeth Laird, “and bipartisan majorities want their elected leaders to do something about it. Lawmakers who ignore privacy are significantly out of step with their constituents.” The high level of public concern about the warrantless access by government agencies to Americans’ data – at the heart of the Section 702 debate – was consistent regardless of respondents’ political affiliation or age group. The survey also revealed specific concerns about how that data is used – and misused: 68 percent are concerned about personal data being shared with law enforcement across the federal, state, and local levels 67 percent are concerned about personal data being shared with the Department of Homeland Security 83 percent are concerned about a breach of a government database exposing their personal data 73 percent agree that, without privacy laws, government agencies would track and monitor anyone they choose 44 percent say they would forgo government benefits rather than risk misuse of their personal data These numbers are a warning. Poll after poll has shown that Americans across the political spectrum are deeply uneasy about how the government collects, searches, and uses their data. That concern is especially acute when it comes to warrantless searches of Americans’ communications under Section 702 – so-called “backdoor searches” that bypass the Fourth Amendment. Nor are these fears hypothetical. From millions of warrantless queries in recent years to the government’s routine purchase of Americans’ data from brokers, the gap between surveillance authorities and constitutional protections has become impossible to ignore. If “trust is the lifeblood of democracy,” then these findings suggest that America is running dangerously low. Congress now faces a choice. It can once again rush through a “clean” reauthorization of Section 702, ignoring both public opinion and constitutional concerns. Or it can act – by requiring warrants for searches of Americans’ communications, closing the data broker loophole, and imposing real oversight. Fortunately, the path forward is clear: —Reform Section 702. —Restore the warrant requirement. —Rebuild public trust. Why National Security Would Be Protected Under the Proposed Section 702 Warrant Requirement4/6/2026
Reading the private communications of Americans – without showing evidence of wrongdoing to obtain a warrant from a judge – violates the Constitution, disrespects American values, and opens the door to abuse. Yet Congress is once again caught up in a debate over the reauthorization of Section 702 of the Foreign Intelligence Surveillance Act (FISA), with some claiming that a warrant rule would endanger lives and national security. The Center for Democracy and Technology and PPSA teamed up to brief Congress on the realities and actual numbers behind these claims about the examination of “U.S. person” queries – searches of people in America whose texts, emails, and calls get caught up in the National Security Agency’s global trawl of data. Here are some of the myth-exploding facts from our brief. MYTH #1: U.S. person queries are immensely important in a broad array of situations, making it dangerous to place restrictions on this important tool. REALITY: Queries only provide value in a limited set of situations – and the proposed warrant rules provide exceptions to account for all of them. Testimony from the intelligence community, the President’s Intelligence Advisory Board, and the Privacy and Civil Liberties Oversight Board uncovered only a few distinct scenarios in which U.S. person queries provided value. And the proposed warrant rule includes exceptions to the warrant requirement that account for them. These exceptions include tracking the signatures of cyber threats, gaining consent from Americans targeted for foreign assassination and kidnapping plots, and tracking Americans’ contacts with suspicious foreign contacts. The government has yet to produce a single instance in which a warrant requirement would have impeded such efforts. Even then, the exceptions in reform proposals allow warrantless inspection of metadata – who contacted whom – leaving the government free to track Americans who are communicating with terrorists or foreign spies. MYTH #2: U.S. person queries need to be done quickly and efficiently in the case of a “ticking time bomb,” and a warrant rule would slow the process down in a manner that endangers Americans’ lives. REALITY: The government has never shown that queries provide such time-sensitive responses. But if they are needed, and the clock is ticking, once again the reform proposals include exceptions for such “exigent circumstances” scenarios. In short, the exigent circumstances, cybersecurity, consent, and metadata exceptions to the proposed warrant requirement allow the government to respond to threats quickly. MYTH #3: Warrants are not feasible given the scale of U.S. person queries – adding a warrant requirement would overwhelm intelligence agencies and the courts. REALITY: By permitting warrantless metadata queries – such as communications logs – the warrant rule ensures that the government will not need to go to court frequently. In 2023, the most recent year for which data is available, the FBI conducted queries for over 57,000 unique U.S. person terms, an unacceptable degree of government overreach and fishing expeditions. Only 1.58 percent of the FBI’s U.S. person queries resulted in FBI agents accessing the content of communications. Thus, even if queries continued to be conducted at the prior rate of 57,000 annually – which is unlikely given that many of these queries were improper or overly broad – a warrant would be potentially applicable to less than 1,000 queries a year. That’s less than three such queries per day on average, hardly an insuperable burden on the FBI and the courts. Because the proposed warrant rule would permit warrantless metadata queries – only requiring court approval to access the content of messages – agencies would be able to confirm when a query will yield a “hit” before devoting any time and effort to seeking a warrant. And most of those two to three queries per day would fall under the exceptions to the warrant requirement. Our brief to Congress concludes: “Americans’ basic rights should not be secondary to bureaucratic hurdles and staffing limits. The exceptions and exemptions built into the warrant proposal would allow the government to remain within the boundaries of the Constitution while also having the means to protect national security.” House Members Should Not Be Stampeded – Congress Has All Year to Debate and Fix Section 7023/31/2026
As the April 20 expiration of FISA Section 702 approaches, a familiar script is playing out on Capitol Hill. Members are warned that any delay in reauthorizing Section 702 – which enables U.S. intelligence agencies to surveil foreign threats – risks allowing a terrorist attack to unfold on American soil. This “you will have blood on your hands” argument is not just wrong. It is a cynical ploy to short-circuit a debate that Congress owes the American people, one that would in no way endanger national security. Here is the reality: Letting the statutory authority of Section 702 lapse does NOT mean America’s surveillance goes dark. Surveillance continues under Section 702 certifications issued by the Foreign Intelligence Surveillance Court, which remain valid until their expiration – currently extending to March 2027. This is not speculation. It is how this law works. As The New York Times has reported, legal directives to communications providers “shall continue in effect” under existing court authorizations. Yet lawmakers are again being told by the intelligence community to act immediately or risk catastrophe. This fear-based messaging has become routine, repeatedly stampeding Congress into reauthorizing Section 702 without strong reforms to protect Americans’ privacy. Enacted by Congress to target foreign threats abroad, Section 702 has been used to conduct millions of warrantless searches of Americans’ communications – peaking at 3.4 million in 2021. These are the predictable results of allowing the government to conduct “backdoor searches” without a warrant. In 2024, a bipartisan amendment to require warrants for searches of Americans’ communications failed in a 212–212 tie in the House. That vote showed how close meaningful reform is – if lawmakers are given the time to pursue it. Supporters of a “clean” extension – one without any reform amendments – are once again promising a debate on reforms later. Such promised reform debates never arrive. Recent history gives no reason to believe that this time will be different. Congress has time to debate well beyond April 20. It has time to patiently consider reforms, such as adding a warrant requirement before 702-derived communications of Americans can be inspected. The choice for Congress is not between national security and civil liberties. It is between rubber-stamping a flawed surveillance authority and doing the hard work of fixing it for their constituents. “Think Minority Report, But for Your Morning Commute” “Zero crash fatalities” was the way some advocates touted the vehicle safety mandates authorized by the infrastructure package that Joe Biden signed in 2021. As admirable as such goals sound, the mandates are an ill-conceived, undefined approach that, from a privacy standpoint, has more holes in them than a cocktail strainer. Now, three years past its original deadline, the NHTSA is barreling ahead with a model-year 2027 implementation while still not having posted a draft rule. The possible design architecture is a nightmare – including AI-powered infrared cameras that actively monitor biometrics (e.g., pupil dilation) to determine whether a driver is “impaired.” “Your car simply watches and decides whether you’re fit to drive,” Gadget Review contributor C. Da Costa writes – “Think Minority Report, but for your morning commute.” Unlike drunk driving laws that already exist and work, warns Lauren Fix, the vagueness of these mandates takes them beyond traditional constitutional safeguards: “No breath test is required. No police officer is involved. The judgment is made by software. Once flagged, the vehicle can refuse to start or restrict operation – and here is the critical issue: there are no federal rules defining how a driver gets out of that lockout. No required appeal process. No mandated reset timeline. No human review. Drivers are placed into what critics now call ‘kill switch jail,’ with no clear exit. This is not targeted enforcement. It applies to every driver, every time, regardless of driving history.” “Advanced impaired driving prevention technology” (in the words of the original mandate) seems unlikely to work as advertised. Instead of saving perhaps 10,000 lives annually, it will merely make already too-expensive vehicles even more expensive as reluctant manufacturers pass these costs on to consumers. From a privacy standpoint, it will create a massive public-private database of biometric data that will be the envy of government agents and hackers alike. In doing so, it will permanently end one of the few remaining bastions of American personal freedom, and one that is already under serious threat – the privacy we enjoy behind the wheel. 404 Media just uncovered something that should unsettle anyone who uses Zoom: An AI-powered site called WebinarTV is using third-party apps to access online meetings and record them, with meeting presenters repackaged and marketed as “experts” in public-facing webinars.
If they're lucky, these unwitting experts – who gain nothing from their newfound notoriety and, indeed, rightly thought they were mere participants in an invited Zoom call – might receive an AI-generated email from an AI-generated agent at AI-based WebinarTV announcing the surprise “rebranding” of their Zoom meeting participation, and perhaps providing the means to opt out. All of this, of course, is after the fact, so it's a privacy-last approach (not to mention that such notifications are probably being routed to spam). For privacy-first users, it's yet another lesson in the ever-growing lecture titled “Pay Attention to Those Settings!” To wit, when informed by 404, Zoom did a review and found that WebinarTV is accessing meeting links that have been publicly shared. That’s the key weakness: Various browser extensions and other digital tools make it possible to record and edit such publicly accessible meetings – even if the meetings themselves aren't being recorded. Using third-party tools (and perhaps their own) WebinarTV is capturing a meeting's audio and video in real time. “Third-party screen recording” is how a Zoom spokesperson described it to 404, while also suggesting that the company was technically powerless to stop it. So it’s up to us for the time being. Consider taking the following steps to avoid getting “webinarred” (or “Zoomjacked”?):
The CEO of WebinarTV told 404 that because the meeting links were publicly accessible, attendees shouldn't have any expectation of privacy. Hence, his company is justified in its actions and isn't guilty of any violations. Our recommendation? See items 1 through 4 above and don't give WebinarTV the satisfaction. In the meantime, and at this rate, caveat emptor. If you want a deeper dive into WebinarTV’s shenanigans, CyberAlberta details the steps. Oxymorons abound in our culture – from eating your “12-ounce poundcake” with “plastic silverware,” to the favorite of spin meisters in this age of Epstein disclosures – “old news.” Count among them the “administrative subpoena” – a perversion of a judicial process at the hands of the executive branch. A subpoena is typically issued by the clerk of a court in the name of the presiding judge, usually seeking the production of documents or other evidence relevant to a case. It can also command a person to appear in court as a witness. This is all in keeping with the Fourth Amendment, which requires judicial review of a search or seizure. Not so with administrative subpoenas, which are executive branch demands for documents with no judicial review whatsoever. Once used sparingly, reliance on administrative subpoenas has exploded since 9/11. They can be deployed not only in serious investigations, but out of curiosity or pique by a government agent. For example, Brent Skorup at the Cato Institute recounts how a Pennsylvania man learned that an administrative subpoena was issued to Google for his computer metadata. What triggered such suspicion? He had emailed a prosecutor urging him not to deport an Afghan immigrant whose plight he had seen in the news. Skorup tracks today’s use of administrative subpoenas as legal “innovations” – coercive, unilateral, and operating absent judicial review –all of which makes them unlike a probable cause warrant or even a subpoena issued under the lax standards of a grand jury. The difference between types of subpoenas, little understood by most Americans, is quite stark, as Skorup notes: “Unlike the grand jury, administrative subpoenas are not anchored in the Constitution or historical practice. Administrative subpoenas are creatures of statute and regulation. Although they trace back to the Interstate Commerce Act of 1887, they were once used sparingly – 19th-century courts held that documents were protected through self-incrimination safeguards – and largely against corporations.” Without judicial oversight, however, administrative subpoenas can now function as tools of warrantless data collection. As PPSA General Counsel Gene Schaerr said, administrative subpoenas “may be likened to a fishing expedition, with Americans as the fish.” During the first Trump administration, the U.S. Department of Justice issued secret subpoenas to telecoms to produce the phone records of two House Members, 43 congressional aides in both parties, and major news organizations in a leak investigation. Not to be outdone, the Biden-appointed special prosecutor Jack Smith subpoenaed telecoms for the phone records of 20 current or former Members of Congress. This practice is a convenient, surreptitious way for government employees to bypass due process and perform general searches of Americans’ personal records. Were Elton John writing a song to describe what’s really going on, the lyrics would start with, “Goodbye, probable cause.” This quiet erosion of a core constitutional safeguard is ripe for review by the U.S. Supreme Court. Only the High Court can recognize this oxymoron for what it is – and restore the constitutional clarity it obscures. Why does PPSA oppose a “clean” extension – without any changes or reforms – of the scandal-ridden Section 702 of the Foreign Intelligence Surveillance Act (FISA)? Recent history shows how much is at stake when the U.S. House votes in April on whether to reauthorize this surveillance authority, and why Congress must allow time for significant debate and reforms. Section 702 was enacted by Congress to enable U.S. intelligence agencies to surveil foreign threats on foreign soil. The intelligence community maintains that the communications of Americans are swept up in the National Security Agency’s global trawl only “incidentally.” Patrick Eddington, a former CIA officer now a Cato Institute policy analyst, writes that the rub is that “the practice is not incidental but a predictable, systematic, and – from the government’s perspective – valuable byproduct of the program.” Here are some examples of what “incidental” looks like:
Three evils emerge from what has become a routine domestic surveillance program.
The intelligence community objects to this characterization, stoutly maintaining that Section 702 is not directed at Americans. To quote Eddington again: “The Foreign Intelligence Surveillance Court (FISC) and multiple congressional oversight reports have documented thousands of such searches annually, many involving wholly domestic criminal investigations with no foreign intelligence nexus.”
PPSA agrees that Section 702 is an important authority, needed to keep Americans safe from foreign threats. We also believe that we can protect civil liberties and national security at the same time. There is no reason for Members of Congress to be panicked by a needless legislative game of chicken. Defenders of civil liberties should stand together to test the value of various reform amendments in the crucible of a much-needed open debate. Researchers at Rice University have worked out how to camouflage your heartbeats from unwanted surveillance with “biometric decoys.” Wait, what? Excuse me, you ask, why might I soon want to camouflage my heartbeat? Remote heart rate monitoring is just one of many threats to privacy emerging from the mushrooming field of biometric tracking. This common, everyday technology ranges from radar-based imaging used for facial authentication to wearables that monitor signals like heart rate variability, respiration, temperature, steps, calories ingested, and the quality of your sleep cycles. Biometric tracking is designed to make everyday life safer and easier, telling you how much of your last night was spent in deep, light, and REM sleep, or whether your heartbeat is showing signs of arrhythmia. In today’s world, however, no good data feed goes unexploited. Off-the-shelf devices such as millimeter-wave radars can be used to eavesdrop on phone conversations and monitor daily movement patterns. They can also be used to monitor subtler signals like breathing and heart rate to gauge your stress, activity, or emotional state. “Sensing technologies are becoming higher resolution and more pervasive, and concerns around what that means for privacy should be taken seriously,” said Edward Knightly, the senior researcher on the study. “It is important to explore potential vulnerabilities and think about how we might address them.” Despite the benefits of biometric monitoring, as with almost all new technologies it comes with a privacy downside. Without policy or legal guardrails, employers might soon monitor your heart rate as soon as you log into your work computer. Or imagine how a negotiator might exploit the knowledge that the person on the other side of the table had a terrible night’s sleep. The complete study was published in the journal Computer Communications via ScienceDirect. And none too soon, given that the market for biometric systems (and their highly desirable data) is expected to roughly double between now and 2030. So it is not too early to worry about such things – as technology can change in a heartbeat. The Threat a “Clean” Reauthorization of Section 702 Poses to Gun Ownership and the Second Amendment3/23/2026
We usually think of the government’s domestic surveillance abuses as violations of the Fourth Amendment protections against warrantless searches. Section 702 of the Foreign Intelligence Surveillance Act (FISA) was enacted to monitor foreign threats on foreign soil. In practice, however, it has been used by the FBI to sweep up the communications of millions of Americans on American soil and to specifically surveil thousands of Americans – all without warrant. Now, with a House vote looming in April, Congress is considering a “clean” reauthorization – one that stiff-arms debate over amendments that would impose basic guardrails on warrantless surveillance of Americans. What is obvious – but just as alarming – is that a “clean” reauthorization could also threaten Americans’ Second Amendment rights. Congress has long prohibited the creation of a federal registry of American gun owners. Yet, as Cato Institute scholar Patrick Eddington explains, Section 702 might offer the government a workaround of the Firearm Owners Protection Act of 1986 “at a level of commercial granularity that a formal registry might never achieve.” How? Many handguns, rifles, and much of the ammunition sold in the United States are manufactured abroad. These foreign manufacturers are caught in the NSA’s global trawl as they communicate with their U.S. operations about everything from inventory management to purchase orders. Eddington writes on the Cato Institute Blog: “When Americans buy a Glock pistol, a Beretta shotgun, or a box of Czech-made Sellier & Bellot ammunition at their local gun store, they likely assume the transaction is between them, the dealer, and perhaps the ATF’s background check system. What they almost certainly don’t know is that the business communications underpinning that entire supply chain – every email, phone call, and text between U.S. importers and their foreign suppliers – is almost certainly being vacuumed up and stored under the Section 702 database.” Layer onto this the current administration’s push to break down long-standing agency data silos under Executive Order 14243. It takes little imagination to see how the FBI, ATF, or the Department of Homeland Security might do exactly what Congress forbids – create a registry of Americans who own firearms. Add artificial intelligence, and the creation of such a registry goes from possible to easy. Worse, Section 702 data is retained for years. Even if the current administration does not exploit this capability, it could become a very useful tool for the next administration. Section 702 thus arms the government with the means to violate not only the Fourth Amendment, but the Second – and even the First. The ability to track what people say, where they go, and whom they associate with opens the door to mapping political, religious, and social networks – core First Amendment activities. More abuses may soon come to light. By April 10, the administration must produce documents in response to a Cato Freedom of Information Act request detailing instances of noncompliance with the law by federal agencies over the last two years. Section 702 has been too prone to scandalous violations of Americans’ rights to give it a green light with no reforms. For the sake of our First, Second, and Fourth Amendment rights, this surveillance authority must be open to debate and reforms. After the end of the pandemic, retail theft became rampant in New York City, as it did in San Francisco, Los Angeles, and elsewhere. Retail theft has evolved into a multibillion-dollar industry for highly organized criminal gangs. Last year, Queens District Attorney Melinda Katz charged a theft ring with hitting Home Depot outlets up to four times a day, only taking breaks from larceny for team lunches. New York Gov. Kathy Hochul said that the state, after toughening laws and putting money behind enforcement, had driven down retail theft crimes in New York City and the state with double-digit reductions. Yet retail theft continues to eat away at the profits of stores, from big chains to mom-and-pop shops. It is understandable that businesses would turn to biometric identifiers to spot serial offenders and block them before they can enter a store. But there is a cost to such surveillance – one that we all pay. “Many of us know the feeling of discovering our credit card information has been stolen,” said New York Councilmember Shahana Hanif. “It’s invasive and frightening, but you can cancel a credit card and get a new one. You cannot cancel your face. You cannot cancel your iris.” Hanif is sponsoring legislation that would prohibit biometric identifying technology in “public accommodation” spaces such as concerts and grocery stores. (Hat tip to Liam Quigley of Gothamist.) The city already requires stores to post notice to customers that they collect biometric data. Is this a simple case of caveat emptor? Or is the better question: should we give up our privacy just to buy groceries? There is more at stake than just what store managers see. It is what happens to this biometric data after it is collected. Hanif’s legislation would stop businesses from selling, leasing, or trading biometric data for profit. It would also require written consent from customers who wish to share their data, including in stores where biometrics are accepted for payment. At the very least, protecting our biometric data – and blocking its sale to other businesses, as well as preventing it from being sold or given to government agencies – would be a reasonable guardrail for New York City and other municipalities to adopt. Majority Oppose Forced AI Surveillance Talk of a “clean reauthorization” of Section 702 of the Foreign Intelligence Surveillance Act (FISA) is growing on Capitol Hill. But as Washington starts to dream of an easy vote that includes no surveillance reforms, the American people are not having it. FISA Section 702 is an authority enacted by Congress to enable the surveillance of foreign threats on foreign soil, but it has often been used by the FBI in recent years to spy on the communications of millions of Americans. Included in that debate is concern over the way in which a dozen federal agencies – ranging from the FBI to the IRS – are purchasing Americans’ personal information from shady third-party data brokers. A new poll commissioned by Demand Progress shows that Americans are paying attention to this threat to privacy – and they don’t like what they see.
The poll also shows that the recent dust-up between the Pentagon and AI company Anthropic is focusing the public’s attention on the potential for the government to use artificial intelligence to drive the surveillance of the American people to unprecedented levels. This is especially true as the administration works to dismantle long-standing information silos and remove safeguards that once limited the sharing of Americans’ private data between agencies – from the Department of Homeland Security to the FBI and the IRS. AI surveillance, with data collected under Section 702, could allow government employees across the federal bureaucracy to run warrantless searches of Americans’ private communications. Combined with the vast amounts of Americans’ personal data that federal agencies purchase from third-party data brokers, AI-run surveillance programs will have truly frightening reach. The poll also shows that Americans are watching the AI debate and that a majority see it as a threat to privacy.
Before Congress embraces a comfortable conformity on a “clean” reauthorization of Section 702 or any other surveillance authority, Members would do well to pay attention to the rising alarm over surveillance among their constituents. The Government Surveillance Reform Act Returns with Strong Support in Both Houses of Congress3/16/2026
The Government Surveillance Reform Act (GSRA), which would stop federal agencies from buying Americans’ most personal data from shady data brokers while reforming Section 702 of the Foreign Intelligence Surveillance Act (FISA), was reintroduced on Thursday with strong bipartisan and bicameral support. Sens. Mike Lee (R-UT) and Ron Wyden (D-OR), and Reps. Warren Davidson (R-OH) and Zoe Lofgren (D-CA) are the sponsors of the GSRA, which balances comprehensive surveillance reform with national security. “It leaves in place the authorities needed to protect the American people from foreign threats, while reforming what Senator Lee calls ‘illegal government spying’ directed at Americans,” said Bob Goodlatte, former Chairman of the House Judiciary Committee and now Senior Policy Advisor to PPSA. Cosponsors of the bill include Sens. Cynthia Lummis (R-WY) and Elizabeth Warren (D-MA), and Reps. Sara Jacobs (D-CA) and Pramila Jayapal (D-WA). Among its many reforms, the GRSA: Closes the backdoor search loophole: By requiring a warrant for the government to inspect Section 702 information, the bill stops federal agents from fishing through warrantlessly obtained data to generate suspicions about Americans. Ends reverses targeting: It prohibits the use of foreign surveillance as a pretext to gather data on Americans. Closes the data broker loophole: The bill bans the practice of federal agencies buying some of our most personal information from data brokers without a warrant. Repeals the “Make Everyone a Spy” provision: The bill repeals a controversial 2024 provision that allows the government to force millions of Americans and companies to secretly spy on its behalf. Updates privacy protections for AI and other modern technologies: The bill’s warrant requirement extends to Americans’ location information, web browsing data, search and chatbot records, and the wealth of data collected by modern vehicles. Expands the use of amici in the secret FISA courts: The bill mandates increased use of amici curiae – experts in privacy and civil liberties – to represent the civil rights of the American people in sensitive cases before secret courts that have no adversarial process. It also provides these advisors to the court with full access to all relevant information needed to do their job. “It has been said that the Government Surveillance Reform Act is the most balanced and comprehensive surveillance reform bill in almost half a century,” Bob Goodlatte said. “It enjoys deep bipartisan and bicameral support because many Members of Congress are alarmed by the abusive and pervasive surveillance of the American people. “This well-crafted legislation must be included in the reauthorization of FISA Section 702 in April.” Chatrie v. United States The Bill of Rights, the first ten amendments to the U.S. Constitution, has an underlying architecture in which each principle and right rests on – and reinforces – the others. We hope that when the U.S. Supreme Court considers Chatrie v. United States, the Justices will see that surveillance, privacy, and expressive freedom are all facets of human liberty. At stake isn’t merely the correct application of the Fourth Amendment’s warrant requirement – that a neutral magistrate must find probable cause and specify the persons or places to be searched – but also the very conditions under which Americans can think, speak, and publish freely. In Chatrie, the question is concrete: whether a geofence warrant – a broad data dragnet that compels companies to disclose the location information of all devices within a specific place and time – satisfies the Fourth Amendment. But the constitutional implications extend to conditions essential for our First Amendment freedoms to flourish. Why the Supreme Court Should Not Try to Untangle Americans’ First and Fourth Amendment Rights In an amicus brief, the Project for Privacy and Surveillance Accountability (PPSA) urges the Supreme Court to rein in geofence warrants. PPSA explains that these are “digital general warrants” incompatible with the Constitution because they invert the Fourth Amendment’s core design. Instead of naming a person or place based on individualized suspicion, they authorize the government to sift through massive data sets to identify potential suspects after a crime has occurred. This practice is not targeted policing. It is suspicionless data mining. These “reverse warrants” are consequential for more than location privacy. The same digital dragnets now being used to capture location data are being deployed in other contexts – keyword warrants, genetic data searches, and other forms of “reverse” searches that sweep up innocent Americans’ information merely because they intersected with a place, word, or characteristic. The chilling effect is real – when people know that their movements, associations, or digital footprints can be turned over to the government without particularized cause, they think twice before seeking information, attending meetings, joining protests, or talking to journalists. Thus, the Fourth Amendment’s privacy protections are not some narrow procedural right that disappears in the face of convenience. A world in which the government can collect comprehensive data about who attended a political rally or who was near a place of worship at a given time – without a warrant – is a world in which expressive liberty is chilled. The Chatrie First Amendment Amici Make This Connection Explicit The amicus brief filed by the Reporters Committee for Freedom of the Press, the Knight First Amendment Institute at Columbia University, and the Foundation for Individual Rights and Expression (FIRE) drills down on the point that Fourth Amendment privacy protections are also about protecting the informational foundations of a free society. “Few investigative tools are more invasive than those that allow government to identify who met with a reporter,” Mara Gassman of the Reporters Committee for Freedom of the Press said in a statement. “There are longstanding safeguards designed to prevent law enforcement from intruding on confidential newsgathering because those intrusions endanger sources and impair public interest reporting. “Dragnet location searches bypass those protections and threaten the independence of the press far beyond a single investigation,” Gassman said. Without the Fourth Amendment’s requirement for particularized description of the targeted person or place, sweeping digital dragnets become the default – location data, communications, browsing behavior, social associations, and even journalists’ sources become vulnerable. And when that happens, the law becomes a tool for monitoring who is where, talking to whom, and concerned about what. Even the perception of surveillance can dampen speech. When combined with the real potential for government access to rich troves of data, the effect is even greater. The Constitutional Order Must Be Preserved The Founders tied the First and Fourth Amendments together because a free society depends on privacy from arbitrary governmental intrusion and liberty of thought, speech, and press. When courts dilute the requirements for probable cause and particularity – as the Fourth Circuit did in Chatrie – they undermine that constitutional order. Chatrie presents the Supreme Court with a chance to reaffirm the Fourth Amendment’s historic protections and avoid acquiescing to a surveillance state. The Project for Privacy & Surveillance Accountability has filed an amicus brief in the U.S. Supreme Court case United States v. Chatrie, warning that geofence warrants threaten not only Americans’ Fourth Amendment rights, but also our religious liberty and freedom of association. PPSA previously urged the Court to hear this case and rein in geofence warrants as modern digital general warrants. These warrants compel technology companies to turn over location data for every device within a defined geographic area. Investigators then sift through the movements of potentially hundreds –sometimes thousands – of people in hopes of identifying a suspect. Now that the Court has granted review, PPSA explains in its amicus brief that this dragnet surveillance exposes something far more sensitive than physical location. Location data can reveal belief, identity, and association. “Geofence warrants also threaten core First Amendment freedoms by enabling surreptitious mass intrusions into sensitive spaces like places of worship,” the PPSA brief explains. A geofence warrant could easily capture the identities of everyone attending a church service, synagogue gathering, mosque prayer, or religious conference. In practice, that means the government could obtain what amounts to a list of worshippers. The facts of the case illustrate the danger. The geofence search used by investigators in Chatrie encompassed Journey Christian Church in Midlothian, Virginia, capturing the location data of anyone present at the church at that time who carried a smartphone with Google location services enabled. That possibility raises profound First Amendment concerns. Location data can expose deeply personal religious information, including “faith affiliation; sacrament participation; belief shifts via changing attendance or visiting a new church; or involvement in recovery ministries.” The Supreme Court has long recognized that government surveillance of association can chill constitutional rights. Americans who believe their religious participation may be quietly recorded by the government may think twice before attending services or participating in religious life. That chilling effect is precisely what the First Amendment was designed to prevent. PPSA’s brief urges the Court to recognize that geofence warrants do more than raise Fourth Amendment questions about search and seizure. They also threaten the First Amendment freedoms that protect Americans’ ability to worship, gather, and associate without government monitoring. After all, in the digital age, tracking where people go can reveal who they are, what they believe, and whom they stand beside. The Supreme Court now has the opportunity to make clear that the Constitution protects those freedoms from the reach of dragnet surveillance. In the Terminator movies, the grand finale is often a robot-on-robot fight to the death. That is happening in real life as well – except it is not always the good robot that wins. Artificial intelligence is the most powerful digital tool ever created. Now a disturbing breakthrough in criminal enterprise has emerged: using one AI system to hack another. At stake is the security of nearly everything – personal identities, bank accounts, and perhaps soon every commercial and government activity secured by blockchain, not to mention trillions of dollars of value stored in cryptocurrency. Nilesh Christopher of The Los Angeles Times reports that Gambit, an Israeli cybersecurity firm, revealed last month that hackers used Anthropic’s Claude AI system to steal 150 gigabytes of data from Mexican government computers. The heist exposed the personal information associated with roughly 195 million identities (some duplicates) drawn from nine Mexican agencies – including tax records, vehicle registrations, birth certificates, and property ownership data. Claude is designed to resist exactly this kind of abuse. Anthropic, like other AI companies, maintains teams dedicated to stress-testing their chatbots and probing them for weaknesses. But AI can do almost anything faster and better – including hacking. Gambit found that the attackers were able to “jailbreak” Claude with the help of another AI: OpenAI’s ChatGPT. The second system reportedly analyzed Claude and helped reveal the credentials needed to weaponize it. This development threatens the foundations of emerging AI-driven and blockchain-based systems. Curtis Simpson told Christopher that because AI “doesn’t sleep … it collapses the cost of sophistication to near zero.” In other words, cybercrime no longer requires a digital army of hackers hunched over laptops in Shanghai or Tirana, fueled by endless supplies of Club-Mate and Cheetos. With the right prompts, AI can attack a problem relentlessly – probing, testing, and refining its methods until it succeeds. And the target surface is growing. With the consolidation of Americans’ personal data from dozens of federal agencies under the Trump administration, AI-enabled hackers may soon be able to dip into one enormous resource instead of many smaller ones. As blockchain systems spread across finance and government, expect AI tools to become not just powerful allies – but dangerous adversaries to one another. This development suggests a growing need for startups with deeper expertise in the cyberdefense of AI. It also suggests that for all the contributions of the Ph.D. philosopher hired by Anthropic to instill a sense of ethics in Claude, gaps still remain. Companies might want to look to the world of science-fiction and devise commandments as strict as Isaac Azimov’s “Three Laws of Robotics[A1],” designed to prevent robots from harming humans. Only in this case, such rules would prevent AI from harming other AI systems – and the rest of us in the process. “National security and civil liberties are not mutually exclusive,” said Rep. Andy Biggs (R-AZ). “We can give our intelligence professionals the tools they need to target foreign threats while ensuring that Americans are not subjected to unconstitutional surveillance.” Rep. Biggs last week underscored that philosophy by reintroducing the Protect Liberty and End Warrantless Surveillance Act. His bill would bring powerful reforms to Section 702, which authorizes federal intelligence agencies to spy on foreign targets on foreign soil but has often been used by the FBI to spy on Americans. This authority must be reauthorized by April 20 or expire. Among its many provisions, the Protect Liberty Act would:
Despite talk on the Hill of a “clean” reauthorization of Section 702, Rep. Biggs’ bill should get the attention of civil liberties champions across the ideological spectrum, from the House Freedom Caucus to Demand Progress. Polls show that vast majorities of Americans in both parties are deeply concerned about government agencies that treat privacy as a luxury and the Fourth Amendment as a nuisance. “The Protect Liberty Act is the most important government surveillance reform measure in several generations – protecting Americans’ constitutional rights while leaving in place important authorities to keep the American people safe from foreign threats,” said Bob Goodlatte, former Chairman of the House Judiciary Committee and Senior Policy Advisor to PPSA. “FISA Section 702 was enacted by Congress to enable the surveillance of foreign threats on foreign soil, but has been used in recent years by the FBI for domestic spying,” Goodlatte said. “It has been abused to spy on millions of Americans, including judges, sitting Members of Congress, 19,000 donors to a congressional campaign, and countless others. “PPSA commends Subcommittee Chairman Andy Biggs for bringing this reform into the debate over the reauthorization of Section 702,” Goodlatte said. “We are hopeful that Republicans and Democrats on the House Judiciary Committee will once again pass it and that President Trump will sign it into law." The Internet of Things (IoT) strikes again. Most modern vehicles possess a tire pressure monitoring system (TPMS), a legal requirement since 2007. A recent study shows that it is possible to capture unencrypted Wi-Fi messages sent by TPMS sensors. Each sensor sends a unique ID number, which makes tracking specific vehicles child’s play for a hacker. Think about this for a moment – the average car or truck is broadcasting four such unique IDs (one per tire), with no need for license plate readers with high-tech cameras and AI software. That, says the IMDEA Networks Institute, “makes TPMS-based tracking cheaper, harder to detect, and more difficult to avoid than camera-based surveillance, and therefore a stronger privacy threat.” A motivated hacker need only place a series of low-cost receivers near the appropriate parking lots and roads. Within weeks: “These tire sensor signals can be used to follow vehicles and learn their movement patterns. This means a network of inexpensive wireless receivers could quietly monitor the patterns of cars in real-world environments. Such information could reveal daily routines, such as work arrival times or travel habits.” It gets worse: TPMS signals can even be captured from moving vehicles. Some sensors reveal actual tire pressure values (as opposed to merely “Low”), which could, for example, be used to determine if a vehicle is carrying a heavy payload or to distinguish vehicles by type. Pretty soon we’re in Mission: Impossible territory. As is so often the case with the IoT, safety was the motivation behind the development of tire pressure monitoring systems in the first place. Because privacy was never a consideration, privacy-by-design protections were missing from the start. The result is a familiar IoT pattern: unencrypted signals and wide-open vulnerabilities becoming the rule rather than the exception. When it comes to privacy issues, safety never seems to stay in its lane. “Our findings show the need for manufacturers and regulators to improve protection in future vehicle sensor systems,” notes researcher Yago Lizarribar. If nothing changes, yet another safety tool will be perverted into an instrument of general population surveillance. But change does not seem to be an industry priority. As Aaron Pruner of CNET points out, we’ve had sixteen years to address this vulnerability. A study by Rutgers University and the University of South Carolina identified the problem in 2010, a mere three years after TPMS was mandated. Which means that if TPMS sensors were kids, they’d be old enough by now to start driving – and be tracked every mile of the way. The media reported on the drama of the Pentagon’s AI contracts as a horse race: Anthropic tried to limit what the War Department could do with the company's Claude AI product. The administration subsequently rescinded all government contracts with the company. OpenAI offered its products as the alternative and won the day. But beneath this drama lies a deeper and more dangerous reality: In the absence of meaningful guardrails, the AI tech of any company can be used for surveillance and – if combined with data collected under Section 702 of the Foreign Intelligence Surveillance Act (FISA) – could allow government employees across the federal bureaucracy to run searches on Americans’ private communications. Such AI-powered surveillance could extend far beyond the Department of War’s use cases and even the Justice Department’s FBI investigations. Government AI-enabled mass surveillance of the domestic population would:
The danger of AI surveillance in a government that shares data between agencies should prompt Congress to strengthen Fourth Amendment privacy protections. With such a vast datascape available to the world's most powerful government – where many existing restrictions have already been weakened – we otherwise risk the irrevocable loss of personal privacy and the rise of a permanent surveillance state. We need to come to terms with the fact that AI tech makes rummaging through our private lives and personal histories easier and faster than anyone could have imagined even a few years ago. Americans’ communications could become permanently accessible to the prying eyes of government agents in almost any agency with a whim (or a political directive) to pursue. It wasn't supposed to be this way. AI was supposed to have guardrails, as was Section 702, enacted by Congress to enable the surveillance of foreign threats on foreign soil, but has instead been used by the government to search the private communications of Americans without a warrant. RISAA was a noble attempt to rein in the misuse of Section 702 as a domestic spy tool. Its reforms included oversight and restrictions on FBI searches involving people inside the United States. It implemented rules for queries involving high-profile groups or individuals. It established training and accountability measures, while enhancing oversight of the two secret courts FISA created. These were important reforms, but they were weakened by last-minute changes to the bill. When Section 702 comes up for renewal next month – this time in the context of an AI juggernaut – it may well be our last chance to protect our freedoms while protecting national security. The Wisconsin Supreme Court recently upheld the conviction of Andreas W. Rauch Sharak for possession of child pornography. This crime is contemptible – and we support every lawful means to apprehend and convict the vile people who traffic in such material. But it needs to be pointed out that in this case, the court and prosecutors sidestepped the need for a probable cause warrant, as required by the Fourth Amendment. In so doing, they inadvertently widened a loophole in the treatment of data held by third parties, from Google to Apple, from servers to the cloud. As a result, the privacy of law-abiding Americans and the security of our most personal and intimate data are now more vulnerable than ever. The Case Rauch Sharak’s conviction involves Google, which routinely flags files containing potential child sexual abuse material (CSAM) for the National Center for Missing & Exploited Children. If that non-profit organization deems files to contain child pornography, they are forwarded on to law enforcement. In this case, the files were referred to the Jefferson County Sheriff’s Office in Wisconsin, where a detective viewed them without a warrant. The detective then obtained a search warrant to search Rauch Sharak’s home and devices. This resulted in Rauch Sharak being charged with 15 counts of possession of child pornography. Wisconsin’s Ruling The state’s highest court upheld a circuit court’s conviction on the grounds that Google had not acted as “an instrument or agent of the government.” This distinction matters, because if Google was deemed a government actor, its searches would necessarily be subject to the Fourth Amendment’s requirement that law enforcement obtain a warrant based on individualized probable cause before conducting a search. Nor did the court believe that the detective needed to obtain a warrant to view the forwarded files. “In this case, we determine that law enforcement did not need a warrant before opening and viewing the files in the CyberTip because law enforcement’s search falls under the private search doctrine,” the Wisconsin Supreme Court held. “Under that doctrine, the government does not conduct a ‘search’ under the Fourth Amendment when it repeats a search by a private actor and stays within the scope of the private search.” The court also stated: “Seemingly without exception, federal circuit courts and other state supreme courts have held that ESPs [electronic service providers] like Google are private actors when searching for CSAM on their platforms.” We commend Google for its “zero tolerance” policy for CSAM in its terms of service. But when the government gets involved, so should the Fourth Amendment. PPSA’s Brief In our amicus brief before the Wisconsin Supreme Court, PPSA took issue with such “overbroad interpretations of the third-party doctrine.” The court overlooked a major exception to the private-actor theory – Carpenter v. United States (2018) – in which the U.S. Supreme Court unanimously held that obtaining a suspect’s historical cell-site data constituted a search under the Fourth Amendment. We told the court that “Carpenter recognized that the Fourth Amendment protects privacy interests that would have been recognized as reasonable at the time of the Founding, notwithstanding advances in technology that make encroachments upon such interests easier.” Like the postal systems of early America, the Founders would have easily understood that individuals maintain an expectation of privacy when entrusting personal communications or materials to third parties for storage or delivery. Today, however, it is nearly impossible to store private information without relying on third-party providers like Google, Apple, Amazon, and others. For users, the password-protected accounts of Google Photos would have established a subjective expectation of privacy. The evidence also clearly shows that when Google conducts automated searches, it may function less like a private actor and more like a deputized investigator. At least one court applied state law holding a third party that possesses CSAM-detection software may face liability if it fails to deploy it. Google – a heavily regulated company operating under significant legal pressure – thus begins to resemble a government partner, raising serious Fourth Amendment concerns. In the wake of this ruling, the government’s ability to compel private actors like Google to perform warrantless searches will only grow. Powers used today to catch CSAM crimes could be used tomorrow to open up our emails, texts, personal photos, and online searches to the government for any reason it chooses. According to the Wisconsin Supreme Court’s interpretation of the private search doctrine, if Google viewed your data, then the government can too. That means the Fourth Amendment becomes a dead letter for any data entrusted to a third party, i.e., nearly all data in our digital age. As lower courts continue to chip away at Carpenter, the Supreme Court has an opportunity in United States v. Chatrie to revisit these issues for the first time since Carpenter. We hope they decide to reaffirm the clear, bright constitutional line defining when digital searches conducted through private intermediaries become government action – and when Americans’ most personal data must be protected from unreasonable searches and seizures. There is a point early in a marriage when spouses get comfortable and uninhibited around each other in the bedroom and even the bathroom. That’s because there is no third set of eyes in the room… unless one of them just happens to be wearing a pair of smart glasses. We recently covered the perils and pitfalls of Meta adding facial recognition software to its Ray-Ban smartglasses. Now Victor Tangermann of Futurism has uncovered a genuine horror story about private images captured by these glasses, millions of which are already in circulation. Meta, in order to refine its AI imaging, sends footage from consumers’ glasses to contractors in Kenya and other countries to label them for training. This tedious process is necessary to enable AI to learn to recognize everyday objects. At that point, almost anything recorded by Meta glasses is liable to be sent abroad for data annotation. “I saw a video, where a man puts the glasses on the bedside table and leaves the room,” one data annotator told two newspapers in Sweden. “Shortly afterwards his wife comes in and changes her clothes.” Another data annotator said: “In some videos you see someone going to the toilet, or getting undressed.” Tangermann reports that other footage included “imagery of people’s bank cards, users watching porn, or even filming entire ‘sex scenes.’” Meta customers have no recourse. Data protection lawyer Kleanthi Sardeli told the Swedish press, “Once the material has been fed into the models, the user in practice loses control over how it is used.” Of course, as the Internet of Things weaves together Ring cameras, cloud-based voice-activated AI assistants, baby monitors, and robot vacuums, we are all subject to being surreptitiously recorded at, well, inconvenient moments. But none of them have the reach into personal privacy that happens when one spouse is wearing a pair of smart glasses and the other announces that the toilet paper holder is empty. Rep. Jim Jordan, Chairman of the House Judiciary Committee, and Rep. Brian Mast, Chairman of the House Foreign Affairs Committee, are urging the United Kingdom Home Secretary to reveal details of a secret order to Apple that may kill encryption for Americans and Apple customers around the world. The secret order involves Apple’s Advanced Data Protection, which offers customers end-to-end encryption so strong that even Apple itself does not have the ability to break it. As a result, journalists and their sources, women and their children hiding from stalkers, dissidents around the world, businesses communicating about proprietary products, and people who simply value their privacy, all rely on Apple’s ADP to protect their communications. In February 2025, the UK Home Office – roughly equivalent to the U.S. Department of Homeland Security – issued a Technical Capability Notice (TCN) to Apple demanding access to end-to-end encrypted data stored in Apple’s iCloud. In order to be able to continue to serve Britons with other products and services, and to protect customers’ privacy, Apple was forced to comply with the law by disabling ADP for 35 million iPhone users in the UK. This had the additional unfortunate effect of depriving Americans and people from around the world of the ability to privately communicate with UK Apple customers – including with other Americans inside the UK. The UK’s Gag Order – an American Company Cannot Talk to Its Government “However, it remains unclear whether this action satisfies the UK’s demands, particularly as the order reportedly extends to data of users outside the UK, including American citizens,” Jordan and Mast wrote in a letter to Home Secretary Shabana Mahmood. Such an order is not only in violation of the Clarifying Lawful Overseas Use of Data (CLOUD) Act, which authorizes the U.S. to enter into data-sharing agreements with the UK and a few other countries, but prohibits orders that require providers to decrypt data. Incredibly, the UK government’s TCN imposes a gag order on Apple that makes it a criminal violation for this American company to petition or even discuss the order with the U.S. Department of Justice. The “Bare Details” of the TCN Are Not Enough Since then, a tribunal in the UK rejected the idea that “the revelation of the bare details of the case would be damaging to the public interest or prejudicial to national security.” Late last year, the Investigatory Powers Commissioner, which advises Prime Minister Keir Starmer, agreed with the tribunal’s ruling, saying that disclosure of some details about the TCN is necessary for “a mature and informed public debate.” Yet no such briefing is in the works, which is why the chairmen are now making a direct request to UK Home Secretary Mahmood to provide a briefing that would spell out the terms of the TCN to the committees by March 11. What’s more, the committees need more than the “bare details” of the TCN to ensure that the actions of the UK government are within the terms of the CLOUD Act. Otherwise, how could Chairmen Jordan and Mast ascertain if the order weakens “the security, privacy, and constitutional rights of American citizens”? PPSA applauds the chairmen for taking this stand for the right of Americans. The U.S. Can Suspend the CLOUD Act Agreement with the UK Bob Goodlatte, former Chairman of the House Judiciary Committee and PPSA Senior Policy Advisor, who helped lead the passage of the CLOUD Act in 2018, is pointing to a way out if the UK does not respond to Jordan and Mast. In a letter to Attorney General Pam Bondi on Dec. 12, Goodlatte noted that the CLOUD Act was intended to streamline cross-border cooperation, but “was never intended by Congress to be leveraged by a foreign partner to compel any form of ‘backdoor’ access or other types of decryption assistance.”
The letter from Chairmen Jordan and Mast did not invoke the possibility of taking this strong action. But Home Secretary Mahmood would be wise to realize that this is likely a step the Trump administration and Congress will take if the British government continues to remain resistant to American concerns. |
Categories
All
|

RSS Feed