Signals & Safeguards Issue 18: Flock’s FreeForm Search, New Orleans’ Weaponized-Drone Draft, and Federal Grants as Policy Instruments

Signals & Safeguards

Issue 18 • Wednesday, July 29, 2026

A concise biweekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

At a Glance

  • Police used Flock’s FreeForm feature to search camera footage for people by clothing, tattoos, body type, race, political indicators, and other natural-language descriptions—not merely by license plate.
  • A New Orleans police-drone draft contemplated weapons with written approval from the superintendent while the city was funding a Skydio expansion; public scrutiny preceded an explicit prohibition.
  • Justice Department grant policy gives priority consideration to jurisdictions that cooperate with federal immigration enforcement, showing how funding conditions can redirect local institutions.
  • Cyberattacks reached more than 30 Minnesota water systems, while an Oregon audit warns that obsolete corrections systems create extreme operational and human-safety risk.
  • Axon’s July release adds conversational AI evidence analysis and a consolidated audit trail spanning Evidence, ALPR, Aware, CCTV, cases, devices, and other systems.

Flock FreeForm changes what an ALPR network is

Police departments have used Flock Safety’s FreeForm search feature to search camera footage for people rather than known license plates. According to data reviewed by 404 Media, officers entered natural-language descriptions involving clothing, tattoos, body type, skateboards, construction attire, race, and possible political affiliation. Some searches reportedly queried hundreds of cameras. Flock’s own product page says FreeForm combines natural-language search, video and LPR workflows, cross-agency access, and configurable alerts.

That changes the functional category of the system.

Traditional automated license plate recognition begins with a known or suspected plate and asks where that vehicle appeared. FreeForm can begin with a description and ask the system’s AI and image-recognition tools to identify footage that may match. A network approved as a vehicle-location system can therefore become a retrospective search engine for people, appearance, behavior, and association without adding a new camera.

A city may have evaluated ALPR under rules governing stolen vehicles, wanted plates, parking, or specific investigations. Officials may never have been asked whether officers should be able to search hundreds of cameras for a “heavy-set male,” a person in political clothing, or someone carrying a particular object. Yet software can make those searches possible after the hardware is already installed.

The accuracy problem also changes. A plate query begins with a relatively specific identifier, even though misreads still occur. A natural-language search depends on how software interprets broad visual attributes. Clothing changes. Body type is subjective. Race may be perceived inaccurately. Political affiliation may be inferred from a shirt, sticker, flag, or event rather than established by fact. A ranked result can look investigative while still containing many people who merely resemble a description.

Why it matters for public officials: A contract for license-plate matching should not become standing permission to search people by appearance.

Before enabling FreeForm or similar semantic search, an agency should document the suspected offense, factual basis, case number, approving supervisor, exact search language, cameras and networks queried, complete result set, corroboration, and final disposition. Searches based solely on race, religion, political association, or lawful expressive activity should be prohibited.

The procurement question is simple: Did officials approve a plate-reader system, or did they approve a general-purpose visual search network? If the answer changed through software, the approval process should begin again.

A surveillance drone should not become a weapons platform by administrative approval

A New Orleans Police Department drone manual dated June 21 said small drones could carry weapons with written approval from the superintendent of police. Local reporting by Verite News links both the June draft and the July 1 replacement policy, which prohibits weapons and hazardous materials.

The current prohibition matters. It does not erase the governance warning.

The June draft appeared while the department was seeking money to expand its Skydio Drone as First Responder program in the French Quarter. On June 24, the City Council approved $250,000 for the expansion by a 4–3 vote. Advocates then alerted council members to the weapons language. The draft disappeared June 30. The operative manual dated July 1 now says drones may not carry weapons or hazardous materials, and NOPD says it does not and will not weaponize them.

A formal police manual nevertheless contemplated converting surveillance aircraft into potential use-of-force platforms through written authorization from one police official. That is a categorical change. A drone used to observe, map, record, or arrive before officers is not the same system once it can carry a firearm, explosive, chemical agent, electrical weapon, impact munition, or another force payload.

No new aircraft may be required. The transformation can occur through policy language, payload selection, software, and administrator permission.

A funding vote should therefore not function as indirect authorization for every capability the hardware could support. A city ordinance should prohibit police drones from carrying or deploying weapons or payloads intended to injure, incapacitate, threaten, or compel a person. It should also prohibit autonomous target selection and autonomous use of force.

Any proposal to change that rule should require advance publication, a public hearing, legislative approval, a civil-rights and use-of-force analysis, independent technical testing, and reporting after every deployment. A superintendent’s written approval should not be enough.

Shared pattern: Flock FreeForm and the New Orleans draft show the same institutional problem. The public approves one category of technology while later software, payload, or policy decisions move it into another.

“What in the past was ‘unknowable’ suddenly becomes open to view, presenting formerly unimaginable privacy concerns.”

— Justice Elena Kagan, majority opinion, Chatrie v. United States (2026)

Federal funding preferences can change what local police are asked to do

The Justice Department’s 2026 COPS grant framework does more than distribute money. In its announcement of nearly $700 million in grant opportunities, DOJ states that state and local governmental applicants must comply with 8 U.S.C. § 1373. It also says priority consideration will go to jurisdictions that cooperate with federal immigration enforcement and coordinate and participate with the Homeland Security Task Force.

The condition is not confined to a general press release. The FY 2026 COPS Hiring Program page—covering up to $157.5 million for hiring and rehiring officers—repeats the § 1373 requirement. COPS pages for programs including Community Policing Development Microgrants carry similar language. DOJ’s grant index identifies each program and opportunity number.

The specific requirements vary by program, and each Notice of Funding Opportunity must be reviewed before assuming that every grant carries identical conditions. But the broader policy is explicit: immigration cooperation can improve a jurisdiction’s position when competing for federal law-enforcement money.

That can redirect local institutions without changing their hardware.

A police department may apply for officers, training, crisis response, technical assistance, or technology. The public discussion may focus on staffing or crime reduction. Yet scoring preferences, certifications, task-force participation, and information-sharing obligations can influence what the department does, which federal priorities it supports, and which local records become useful to outside agencies.

For Oregon officials, the questions are immediate. What kind of immigration cooperation earns priority consideration? Must the applicant join or coordinate with a federal task force? Would participation expand federal access to jail, dispatch, identity, address, ALPR, or investigative records? Who determines whether the application complies with Oregon sanctuary statutes? What happens if grant conditions change after award? Does the governing body approve the relationship before staff submit the application?

A grant is not merely revenue. It is a policy instrument.

Before applying for or accepting federal public-safety funding, a local government should publish a grant-impact statement identifying every scoring preference and certification; task-force and information-sharing obligations; technology or database access funded by the award; conflicts with state law or local policy; long-term operating costs; and conditions for suspension, repayment, or termination.

More than 30 Minnesota water systems were targeted

A coordinated cyberattack targeted more than 30 Minnesota community water systems on July 26 and 27.

Minnesota IT Services said investigators identified unauthorized access with malicious intent. The FBI contacted affected entities. No statewide request was issued for residents to change their drinking-water use.

In Braham, malicious activity shut down computerized operating controls, temporarily stopping a well and water-treatment plant. The city’s official update and local reporting from CBS Minnesota said there was no physical damage and no effect on water quality or safety.

Attribution remains unresolved. Similarity to earlier activity associated with Iranian-linked actors is not proof of responsibility.

The episode shows how a cybersecurity failure can cross into physical public service. Community water systems often combine aging operational equipment, limited staffing, remote vendor access, internet-facing interfaces, shared or default credentials, incomplete logs, and dependence on automated controls. Restoring a screen or restarting a plant does not by itself prove that an intruder no longer has access.

Public officials should ask what would happen if automated controls were unavailable for an hour, a day, or a week. The answer should include manual operation, staffing, communications, water-quality verification, and the evidence needed before returning the system to normal service.

Oregon Watch: obsolete corrections IT could fail where safety depends on it

A July Oregon Secretary of State audit warns that the Department of Corrections relies on obsolete information systems that create operational, security, and human-safety risk. The technology findings begin in Chapter 3, page 21, and the audit page provides the full report and DOC’s formal response.

The audit examined the Corrections Information System and Offender Management System, which support round-the-clock operations across Oregon, including parole and probation work in all 36 counties.

Auditors found inefficient and paper-based processes, antiquated interfaces, and outdated programming languages that make the systems difficult to maintain or update. The audit says DOC faces “extreme risk” that it may be unable to implement critical enhancements or recover effectively after system failure. The consequences for incarcerated people and correctional staff could be severe.

This is not simply an old-computer problem. Corrections systems affect custody, movement, supervision, staffing, institutional security, rehabilitation, and decisions about people’s lives. If records become unavailable or unreliable, officials need to know which functions fail first, how long institutions can operate safely, which manual processes exist, and whether recovery restores complete and accurate information.

The audit recommends that DOC mitigate organizational, operational, and security risks and conduct an exercise simulating catastrophic failure of the Corrections Information System. DOC agreed, but major target dates extend into 2029.

Shared pattern: Public systems can be redirected by funding conditions or disabled by neglected infrastructure. In both cases, elected officials need to understand the operational commitment before an award or crisis makes the decision for them.

“No one, perhaps not even the President, knows the limits of the power he may seek to exert in this instance, and the parties affected cannot learn the limit of their rights.”

— Justice Robert H. Jackson, concurring, Youngstown Sheet & Tube Co. v. Sawyer (1952)

Warning Signals

Warning Signals

Early indicators of how capabilities expand through software, interfaces, funding, and policy before public oversight catches up.

Axon Watch: Lead Lock changes how agencies search evidence

Axon’s July 2026 release notes introduce Lead Lock, an AI-powered evidence-review tool inside Axon Evidence.

Once enabled, Lead Lock can index supported PDFs, audio, and transcribable video within a case. Investigators can ask natural-language questions, identify entities, flag possible inconsistencies, draw connections across evidence, and receive citations back to source material. Axon’s Lead Lock overview says the tool respects existing evidence permissions and does not replace investigator judgment or make legal conclusions.

Administrators can enable or disable chat history and set the AI index to remain for 30, 60, or 90 days. Axon says Lead Lock activity is logged in the Audit Trail. Its usage guide says users must copy important findings into case notes or reports if they need a permanent record.

Those details create questions ordinary evidence-retention policies may not answer. What exactly is deleted when the AI index expires? Does source evidence remain while embeddings, extracted entities, or other derived material disappear? Are prompts, answers, citations, exports, and deleted chat histories retained? If chat history is disabled, what record remains for later review?

Axon’s July release also introduces a Unified Audit Trail consolidating activity from Agency, Aware, CCTV, ALPR, Evidence, Cases, Devices, and Groups. That may improve review, but the product guide says only six months are displayed directly and older material must be exported. The consolidated export is PDF.

A unified view is not automatically a complete or independent audit system. Agencies should know who can view the trail, what activity is hidden by default, how long records are retained, what machine-readable exports exist, and whether vendor staff or administrators can alter visibility or classification.

Other July changes matter as well:

  • “Reason for access” can be required before users view evidence.
  • AI Case Search can rank evidence containing weapons, vehicles, apparel, objects, and drug paraphernalia.
  • Searchable document text now extends to PDFs and Word files.
  • Records and Standards logs add exact search keywords, IP addresses, browser-level device information, and clearer records of full-document access.

Council question: Which Axon capabilities are available, licensed, enabled, tested, planned, or prohibited locally—and what record shows who activated each one?

The safeguard is to require a current feature inventory and fresh review before enabling analytical tools that change the meaning of evidence search. Product availability is not authorization.

Texas and New York show why “age verification” is too broad a label

The Fifth Circuit’s July 24 ruling on Texas’s SCOPE Act and New York’s final SAFE for Kids rules address different mechanisms that are often grouped under one label.

Texas’s law includes account-age registration, age verification for certain harmful-content services, advertising restrictions, parental controls, and monitoring-and-filtering duties. The Fifth Circuit held that trade groups were likely to succeed in showing that the monitoring-and-filtering requirement was preempted by Section 230. Other challenges failed for standing or were foreclosed by precedent.

New York’s final SAFE for Kids regulations govern algorithmically personalized feeds and nighttime notifications for users under 18 without parental consent. The official rule text distinguishes age estimation, age inference, and age verification; requires certified methods and annual testing; requires an appeal process; and limits how age-assurance data may be used and retained. The rules take effect January 25, 2027.

Legislators should separate the mechanisms:

  • What threshold must be proved?
  • Must every adult participate?
  • Is the method identification, estimation, attestation, device-based inference, or parental approval?
  • What information is collected and retained?
  • Can it be reused for advertising, account linkage, or government access?
  • How are errors corrected?
  • What product features change after classification?

New York’s rule requires at least one alternative to government identification, permits zero-knowledge proof approaches, and says information collected for age assurance or parental consent may not be reused for another purpose. The strongest design proves only the necessary threshold and then forgets the underlying evidence.

Oregon’s privacy leadership needs enforceable authority

On July 21, Oregon Enterprise Information Services appointed Michael Hanna-Butros Meyering as chief privacy and communications officer, while Nik Blosser now focuses on AI as chief AI officer.

The state’s Enterprise Privacy Guidance includes purpose limitation, data minimization, accuracy, security, redress, and accountability. But Oregon describes the guidance as optional and recommended.

A title assigns responsibility. Mandatory review gates, authority to require correction, and power to stop unsafe processing make that responsibility enforceable.

“The Court is obligated—as subtler and more far-reaching means of invading privacy have become available to the Government—to ensure that the progress of science does not erode Fourth Amendment protections.”

— Chief Justice John G. Roberts Jr., majority opinion, Carpenter v. United States (2018)

Safeguards

Safeguards

The strongest protections this issue attach oversight to material changes in capability, configuration, funding, and operational dependence.

Require fresh approval when capability changes

A new approval process should be triggered when a system gains a new search mode, data source, integration, payload, use-of-force function, AI model, inference capability, automated alert, sharing pathway, or physical operational effect.

The trigger should follow actual capability, not the product name.

Attach the live configuration to the public decision

Approval records should include the current feature inventory, architecture and data-flow diagram, administrator roles, sharing settings, search capabilities, retention schedule, audit fields, prohibited uses, and change-control process.

Require notice and approval before pilots, software updates, license changes, payloads, integrations, or administrator settings materially expand what the system can do.

Make logs useful outside the vendor dashboard

Require machine-readable exports that preserve exact search terms, user and organization, case number and purpose, legal authority, data sources, result count, exports and sharing, denied attempts, administrator changes, vendor access, and the policy tied to feature activation.

A PDF summary may be useful for reading. It should not be the only format available for independent analysis.

Govern grants as policy instruments

Before accepting public-safety funding, disclose scoring preferences, certifications, task-force obligations, information sharing, surveillance or analytical technology, state-law conflicts, long-term staffing and operating costs, and termination or repayment consequences.

A governing body should approve the operational commitments, not only the budget amendment.

Plan for physical and human consequences

Failure exercises should ask not only whether data can be restored, but who may be harmed; what decisions become unreliable; what manual fallback exists; how long safe operation can continue; who can suspend the system; and what evidence proves the environment is safe again.

Bottom line

The most important changes in Issue 18 did not require a visibly new system.

Flock added a search method that can look for people rather than known plates. A New Orleans draft contemplated turning observation drones into weapons platforms through police approval. Federal grants use eligibility and priority rules to influence local enforcement. AI changes what investigators can extract from evidence already stored. Obsolete software creates new risk simply by becoming harder to maintain and recover.

Public approval must therefore follow capability, not product labels.

The practical questions are: What can the system do now that it could not do when officials approved it? Who authorized the change? What new data, payload, search, or consequence did it add? What does the system prevent and record? Can an independent reviewer reconstruct what happened?

A safeguard should attach to every material change—not only to the original purchase.

“With all its defects, delays and inconveniences, men have discovered no technique for long preserving free government except that the Executive be under the law, and that the law be made by parliamentary deliberations.”

— Justice Robert H. Jackson, concurring, Youngstown Sheet & Tube Co. v. Sawyer (1952)

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *