Category: Signals & Safeguards

A concise weekly newsletter tracking surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

  • Signals & Safeguards Issue 17: Flock’s Trust Problem, New Jersey’s Data-Broker Law, and Redmond’s Bundled Surveillance Contract

    Signals & Safeguards

    Issue 17 • Wednesday, July 15, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a Glance

    • LAPD’s audit findings and continuing Flock contract dispute show why surveillance-vendor assurances must be converted into configurations, logs, and contract terms that an independent reviewer can test.
    • The Seventh Circuit rejected Clearview AI’s unusual biometric settlement because differently situated class members did not have adequate representation.
    • New Jersey prohibited sales of sensitive data, while new research shows why privacy rights still fail when each data broker controls its own opt-out and deletion process.
    • Redmond’s $410,762.16 Axon award includes six Skydio drones, 38 vehicle fleet-camera upgrades, and DroneSense livestreaming—and the department already operates fixed Axon plate readers—showing why bundled technology contracts need a complete capability and data-flow inventory.

    Flock’s trust problem is now a governance problem

    The American Civil Liberties Union has assembled a national record of instances in which it says Flock Safety gave police departments, elected officials, or the public inaccurate or misleading accounts of how its automated license plate reader network operates. The July 2 analysis points to disputes involving federal access, national searches, product capabilities, camera status, sharing settings, and vendor control.

    The document is advocacy, not an adjudication. Its most serious examples should therefore be read alongside underlying records and the affected jurisdiction’s response. But the pattern matters even before every disagreement is resolved. A surveillance vendor is not selling an ordinary office product. Its descriptions can determine whether officials approve deployment, what a policy prohibits, what the public believes is possible, and whether a later audit is designed to detect the right risks.

    Issue 16 described how Woodburn learned that its cameras had appeared in broad outside-agency searches through a pilot architecture city officials said they had not knowingly approved. The broader warning is that officials cannot assume contract language, dashboard labels, or a verbal assurance fully describe the live system.

    That problem is especially serious in a networked platform. A local agency may control its own users while the vendor controls hosting, software updates, administrator privileges, integrations, federation rules, default settings, and the practical meaning of a feature name. A city may prohibit national sharing yet remain exposed through a pilot, external search path, inherited configuration, support account, or later product update.

    The clearest example arrived in Los Angeles. In a review of two months of LAPD automated-license-plate-reader activity, the Los Angeles Police Commission’s Office of Inspector General found that ALPR activity contributed to recovery of 337 stolen vehicles. It also identified 161 alerts that officers initially treated as matches to stolen vehicles but that later proved inaccurate. That is not a general error rate across every plate scanned, and the public report does not establish that every inaccurate alert resulted in a vehicle stop.

    The review covered LAPD’s larger, multi-vendor ALPR environment rather than Flock cameras alone. Flock operated 138 pole-mounted cameras within a department-wide network of roughly 2,000 readers. The governance lesson is not that one percentage fully measures one vendor. It is that an independent reviewer could reconstruct alert handling, identify inaccurate matches, and examine data-sharing and contract risks across the system.

    LAPD then allowed its three-year Flock agreement to expire and suspended ordinary access while negotiating stronger terms involving privacy, security, data ownership, and sharing. The Los Angeles Times reported on July 14 that negotiations continue, so the lapse should not be treated as a final decision to abandon Flock. The Police Commission separately supported suspending new Flock deployments and contracts pending additional oversight and public input.

    This is why public bodies should treat material vendor representations as testable contract requirements. Before approval, officials should require a live demonstration of every sharing and administrator screen, a diagram of all local, outside-agency, vendor, and subprocessor access paths, and an export showing the exact audit fields generated by each action.

    The contract should attach the approved configuration, prohibit silent changes, and require written notice and affirmative approval before a pilot, integration, network expansion, administrator role, or new search mode touches local data. It should require preservation of evidence when a disputed representation arises and permit independent technical review. A vendor’s failure to produce the agreed audit evidence should itself be a material breach.

    Why it matters for public officials: Oversight cannot depend on asking the same company that designed the system whether the system complies. The agency needs technical controls and records that allow someone else to reconstruct what happened.

    A practical verification test: Can the agency independently identify every person and organization that searched, viewed, exported, shared, administered, or changed the system—including vendor staff—and can it prove that prohibited access was technically blocked rather than merely discouraged by policy?


    Clearview settlement fails on who represented the class

    The U.S. Court of Appeals for the Seventh Circuit has vacated approval of an unusual nationwide settlement involving Clearview AI. Instead of conventional cash relief, the agreement would have given class members a financial interest tied to about 23 percent of the facial-recognition company’s future value.

    The court did not hold that an equity-like remedy is inherently improper, and it did not decide the underlying biometric-privacy claims. It also did not require additional injunctive relief. The decisive problem was procedural: the settlement created much larger potential benefits for favored state-law subclasses, but the nationwide class lacked representatives who could adequately protect the interests of people in those different groups.

    The case now returns to the district court. The policy conflict remains important. A privacy remedy should compensate affected people and constrain unlawful conduct without making their recovery depend on the future commercial success of the very surveillance practice being challenged.

    For public officials, the lesson is not limited to class actions. Remedies should be evaluated operationally: What conduct stops? What data are deleted? What future collection is restricted? Who receives compensation? Who can enforce the agreement? A settlement can be creative without being accountable.

    “We cannot get past a key procedural problem in the settlement process.”

    — U.S. Court of Appeals for the Seventh Circuit, In re Clearview AI, Inc. Consumer Privacy Litigation (2026)

    New Jersey moves upstream—but privacy rights still need a working compliance system

    New Jersey enacted A5328 on June 30 as P.L. 2026, c.25. The law prohibits selling, offering to sell, or licensing sensitive data and directs the state to create a public registry for data brokers and a newly defined category of data collectors.

    The sensitive-data sales prohibition took effect immediately. The registry provisions are delayed for 270 days and are scheduled to become operative on March 27, 2027. That timing distinction matters: New Jersey has already made the upstream policy choice that covered sensitive information cannot be sold, even though the registration system is not yet operational.

    The prohibition is structurally important because it applies regardless of how many consumers’ records an entity controls or processes and regardless of whether the seller would otherwise fall within the New Jersey Data Privacy Act’s usual thresholds. That avoids a common weakness in privacy statutes: numerical thresholds that leave smaller but highly sensitive datasets outside the rule.

    The law’s definition of sensitive information reaches categories that can expose a person’s body, beliefs, associations, movements, and vulnerability. The precise exceptions, registration disclosures, fees, and enforcement provisions will matter in implementation, but the central policy choice is clear: some data should not become a commercial product merely because a company can collect or infer it.

    This advances the data-broker discussion from Issue 16. A warrant requirement or procurement restriction controls the government buyer. A sales prohibition controls the market that supplies the buyer. Neither approach is complete by itself.

    If government cannot compel sensitive location information without judicial process but can buy a commercially assembled substitute, constitutional protection becomes dependent on the acquisition route. If a state prohibits government purchases but permits unrestricted commercial sale, the same information remains available to private investigators, employers, insurers, landlords, political operatives, abusive partners, and intermediaries that may later sell to government.

    An upstream rule also reduces the burden placed on individuals. A person should not have to identify hundreds of hidden companies, submit separate requests, disclose more identity data, and repeatedly opt out of a market they never knowingly joined.

    Rights on paper still fail at the doorway

    A July UC Irvine study using synthetic identities found that opt-out and deletion processes among California-registered data brokers remained inconsistent, burdensome, and sometimes ineffective. Researchers reported nonresponses, intrusive verification demands, and substantial variation in how requests had to be submitted. These are research findings rather than enforcement judgments, but they test what consumers actually encounter when trying to use rights that exist on paper.

    A separate large-scale study of registered brokers found that only 9 percent of 522 brokers were fully compliant with transparency requirements. In an audit of 250 consumer-request processes, 43 percent made it impossible to exercise all privacy rights and 64 percent introduced at least one feature that created substantial friction.

    Together, the studies illustrate a recurring design failure: the regulated company controls the doorway through which a person must pass to invoke the right against that company.

    The consumer may not know the broker exists. The broker may demand identity documents that create new risk. Names, addresses, emails, and phone numbers may not match the records the broker bought. A deletion request may remove one profile while another affiliate, source, or later purchase recreates it.

    The better model is centralized and testable. California’s Delete Request and Opt-Out Platform provides a developing example: one verifiable request can direct registered brokers to delete covered information, with broker processing requirements beginning August 1, 2026. A state can also prohibit unnecessary identity collection, publish response rates, conduct regulator-run test requests, and impose consequences when firms do not respond or reacquire deleted data.

    Officials should distinguish deletion from suppression. A company may stop displaying a profile while retaining data, hashes, linkage keys, derived attributes, or source relationships that allow the profile to reappear. A meaningful deletion standard should specify what must be erased, what may be retained for legal compliance, how downstream recipients are notified, and how completion is certified.

    A registry should make the market inspectable

    A useful registry should identify each broker’s legal and trade names, parent and affiliates, categories of data collected, original sources, customer categories, sensitive-data practices, government clients, opt-out and deletion methods, retention periods, security incidents, and whether the company honors universal opt-out signals.

    Registration alone is not validation. Regulators should compare claims against sample transactions, consumer requests, website behavior, contracts, and technical data flows. Repeated failure should lead to escalating penalties, suspension from the market, and notice to downstream customers.

    Public agencies should consult the registry before purchasing or accepting commercially sourced data. Procurement files should identify the original collector and every intermediary, not merely the company that signed the government contract.

    The combined safeguard: Restrict collection and sale of sensitive data upstream; require a warrant or equivalent judicial process for government acquisition downstream; and prohibit contractors or partner agencies from doing indirectly what the public body may not do directly.


    The larger risk is what happens when separate databases become one system

    A July 9 Brennan Center report warns that federal agencies are increasingly linking government records with commercially acquired location, biometric, financial, social-media, and other personal information. The report describes the Department of Homeland Security as an emerging hub for this consolidation and says AI-assisted analysis can turn records collected for unrelated purposes into searchable profiles of people’s movements, relationships, beliefs, and activities.

    The warning reaches state and local government. Driver’s-license, benefits, voter-registration, law-enforcement, and other records may be requested or shared for purposes far removed from the reason they were originally collected. Protecting one local database is not enough if its contents can become an input to a much larger federal or commercial system.

    Why it matters for public officials: Data-sharing agreements should state the permitted purpose, prohibit onward transfer and unrelated reuse, require notice and audit records for outside requests, and allow access to be suspended when the receiving agency changes how the information will be used.

    Flock shows why officials need visibility into a vendor’s network and administrator actions. Clearview shows why a remedy must fairly represent differently situated people. Data-broker regulation shows why the original collector and every intermediary matter. Data consolidation shows why risk grows again when once-separate records become one searchable system.

    In each case, accountability fails when review stops at the nearest interface: the local dashboard, the named defendant, the final seller, or the written policy. The safeguard must follow the system from collection through processing, sharing, decision, remedy, and deletion.

    Data minimization includes separation: Before linking systems, document the original purpose and legal authority for every dataset, the people and agencies receiving access, the risks of inaccurate matches, and the conditions for ending the connection.


    Local Watch

    A closer look at how a bundled local purchase connects drones, vehicle cameras, license-plate readers, and livestreaming.

    Redmond adds drones and fleet cameras to an existing Axon surveillance ecosystem

    On June 23, the Redmond City Council approved a five-year, $410,762.16 award to Axon Enterprises and Skydio. The official council packet, pages 76–77, describes two Skydio R10 indoor drones, four Skydio X10 outdoor drones, software for livestreaming and integration with patrol and SWAT operations, and 38 Axon vehicle fleet cameras. The vehicle cameras will expand patrol-car coverage from two views—front-facing and rear-seat—to three by adding a rear-facing camera.

    The agreement also provides for six new drones at the 30-month mark while allowing Redmond Police to retain and use the original six. If the first group remains operational, the department could have as many as 12 Skydio aircraft after the refresh rather than simply exchanging old equipment for new.

    The staff report identifies $100,000 in General Operating Fund reserves for implementation. The remaining payments are scheduled unevenly: $70,256.02 in fiscal year 2026–27, $8,265.41 in 2027–28, and $110,746.91 in each of the following three fiscal years. Because the public packet contains the police staff report rather than the executed agreement and itemized vendor quote, it does not disclose every software license, storage term, administrator role, or data-control provision included in the award.

    The purchase sits inside a larger Axon environment

    Redmond Police already uses Axon body-worn cameras, vehicle cameras, interview-room cameras, Evidence.com, and fixed license-plate-reader cameras, according to the staff report. The new award therefore adds drones and expanded vehicle-camera coverage to an existing evidence and plate-reader environment rather than creating a stand-alone UAS program.

    That distinction matters because surveillance capabilities can be shaped by how separate tools work together. A fixed plate reader may identify a vehicle and location; dispatchers or officers may then use patrol cameras or a drone to follow the response. The staff report does not say that Redmond currently connects fixed-LPR alerts to drone deployments, but both systems are now part of the department’s technology environment and should be governed as a combined workflow when they interact.

    Skydio says the X10’s VT300-Z telephoto package can resolve a license plate from approximately 800 feet under suitable conditions. That is an optical capability: the camera may capture an image in which a plate is legible. It is not, by itself, automated plate recognition, optical-character recognition, or a database search.

    Skydio separately describes drone-response systems that can receive alerts from third-party ALPR platforms. In that type of workflow, the fixed reader produces the plate match and the drone supplies aerial observation. Public records should make clear whether Redmond has enabled such a connection, what legal and policy rules apply, who may authorize a deployment, and what audit trail links the original plate alert to the drone mission.

    DroneSense carries the livestream

    The staff report names DroneSense as the livestreaming platform used by Redmond Police and SWAT during critical incidents and investigations. Redmond’s published UAS information says the department does not store data obtained by a UAS in third-party storage and has no UAS data-sharing agreements with outside agencies.

    Livestreaming through a third-party platform does not necessarily mean that the provider permanently stores the video. It does mean the department should publicly document how the stream is secured and handled: whether DroneSense buffers or retains video or metadata; who can receive a stream; whether recipients can record it; how viewers are authenticated; whether access expires automatically; what viewer logs are created; and where flight telemetry, operator identity, and incident metadata are stored.

    The same records should show whether completed drone recordings enter Evidence.com, whether live feeds can be viewed through an Axon command interface, which company controls administrator settings, and how access is revoked when an incident ends.

    San Francisco shows the risk of weak sharing controls

    A recent San Francisco incident demonstrates why those details matter even when a department has a written security policy. WIRED reported that live feeds from five San Francisco Police Department drones were reachable through a public Skydio ReadyLink without a password or authentication code. The feeds included color and thermal video, real-time location information, and the names and email addresses of drone pilots.

    Researchers archived about 48 hours of activity: 60 videos from 20 flights showing detentions, searches, apartment windows, rooftops, streets, courtyards, unhoused people, and many bystanders who did not appear to be subjects of an investigation. The link had been set to remain active for a year and may have exposed the feeds for roughly six months.

    ReadyLink is not the platform named in Redmond’s staff report; Redmond identifies DroneSense. The control lesson nevertheless applies to any livestreaming system. Authentication, named recipients, short expiration periods, complete viewer logs, and automatic revocation should be mandatory defaults rather than options left to the person creating a link.

    The federal transition should be described precisely

    Redmond’s existing drone fleet includes foreign-manufactured Autel and DJI aircraft. The staff report cites the American Security Drone Act and related National Defense Authorization Act provisions as the reason for moving to U.S.-manufactured Skydio equipment.

    The federal restrictions are narrower than a general ban on commercial sales of all foreign-manufactured drones. Federal acquisition rules restrict federal agencies from procuring or operating covered systems and, beginning December 22, 2025, restrict the use of federal funds to procure or operate prohibited systems, subject to exceptions and waivers. Moving away from Autel and DJI may preserve federal-funding eligibility and reduce the risk that existing aircraft become harder to support, but the legal rule should not be described as a universal sales ban.

    Why it matters locally: Redmond’s award adds indoor and outdoor drones and 38 vehicle cameras to an environment that already includes fixed Axon plate readers, Evidence.com, and DroneSense livestreaming. Oversight should focus on the combined data flows and operational workflows, not only on the label attached to each product.

    Before fixed-LPR alerts are connected to drone response, live-feed access is expanded, storage or retention changes, remote or docked operations begin, or automated analysis is added, Redmond should require public notice, documented legal review, and approval proportionate to the new capability.

    Local verification test: Can Redmond produce the executed agreement, complete product and license inventory, data-flow diagram, fixed-LPR integration map, livestreaming settings, retention rules, viewer logs, and approval history needed to show that the combined system matches its published UAS commitments?

    “There’s a certain trust given to the police to use these things correctly.”

    — Security researcher Sam Curry, quoted by WIRED (2026)

    Warning Signals

    Warning Signals

    Early indicators of how connected systems, software transitions, and delayed maintenance can expand risk before policy catches up.

    Axon Watch: July 31 transition brings AI oversight questions

    Axon says that on July 31 the legacy Axon Evidence experience will be deprecated and the redesigned interface will become the only version available. The deadline does not establish that any AI product will automatically be licensed or enabled for Bend. Availability may depend on licensing, configuration, rollout status, and agency activation.

    But a mandatory interface change is still an oversight point. Officials should request a current feature inventory showing every AI-assisted capability available, licensed, enabled, or planned; the evidence it can analyze; the output it creates; retention and sharing; model providers and subprocessors; audit fields; human-review requirements; and whether activation requires notice, legal review, or Council approval.

    Council question: Which Axon capabilities will be available to Bend after July 31, which are enabled, and what record will show when a new analytical or AI-assisted function is activated?


    A federal information-sharing network was breached after warnings were twice dismissed

    According to Nextgov’s account of an internal Department of Homeland Security incident readout, intruders accessed the Homeland Security Information Network, a platform used to share sensitive but unclassified records with federal, state, local, and international partners, after analysts twice concluded that suspicious activity was a false positive. By the time officials declared a breach, the intruders had installed hidden backdoors and stolen credential files. Public reporting has not established exactly what information was obtained from HSIN.

    The same architecture that lets many agencies exchange information also lets one successful intrusion reach every connected partner. Any agency using a federal or regional sharing network should know who can close an alert, what independent verification occurs before suspicious activity is dismissed, and how partners are notified when the network may be compromised.


    Active exploitation turns maintenance into an emergency

    CISA warned on July 14 about active exploitation of Microsoft SharePoint vulnerabilities and urged organizations to harden affected systems. A vulnerability bulletin becomes a safeguard only when someone knows which systems are affected, has authority to act immediately, verifies that mitigation was completed, and checks whether attackers gained access before the patch.


    Safeguards

    Safeguards

    The strongest protections this week turn assurances into evidence, keep connected systems visible, and establish what happens when technology does not perform as promised.

    Turn vendor promises into enforceable specifications

    Attach the approved configuration, architecture diagram, sharing settings, administrator roles, audit fields, feature inventory, and data-retention schedule to the contract. Require a live demonstration before deployment and after material updates. A statement such as “national sharing is off” should identify every technical pathway the phrase covers, including pilots, federated searches, vendor support accounts, integrations, and inherited defaults.

    Require written notice and affirmative approval before a pilot, integration, new administrator role, subprocessor, network expansion, or policy-changing default touches local data. Preserve both the old and new configuration so reviewers can identify exactly what changed, who approved it, and when the change took effect. Contract remedies should include suspension, corrective work, fee recovery, and termination when a material representation proves false.

    Give the agency independent evidence

    The agency should be able to export complete, tamper-evident logs without vendor assistance. Logs should identify the user and organization, date and time, case number, purpose, legal authority, search terms, datasets, result count, exports, sharing, denied attempts, vendor access, administrator changes, and final disposition.

    The log format and required fields should be contract deliverables rather than whatever a dashboard happens to display. Assign someone outside day-to-day use of the system to review records on a fixed schedule, investigate anomalies, and document corrective action. Contract for independent technical testing, incident preservation, audit cooperation, and meaningful remedies. A vendor’s failure to produce required evidence should itself be a material breach.

    Govern integrations and live links before activation

    Maintain a current diagram of local users, outside agencies, vendor administrators, subprocessors, federated networks, application-programming interfaces, evidence systems, exports, backups, and legal-process pathways. For each route, specify who can authorize access, what purpose is allowed, what data leave the system, how long the connection lasts, and what evidence the action creates.

    Require authentication, short expiration periods, named recipients, viewer logs, and automatic revocation for every live video or data-sharing link. Prohibit public or reusable URLs for police-surveillance feeds and regularly test access from outside the government network. Limit recording and retention to the documented mission; a secure link can still expose unnecessary footage of homes, bystanders, and private spaces.

    Control sensitive data throughout the chain

    Prohibit the sale of sensitive location, biometric, health, communications, and association data upstream. Require a warrant or equivalent judicial authorization when government seeks the same information downstream, regardless of whether it comes from a carrier, platform, advertiser, broker, contractor, or partner agency. Ban indirect acquisition: a public body should not ask another agency or vendor to obtain information it could not lawfully obtain itself.

    Provide one state-run mechanism for access, correction, opt-out, and deletion requests. Define deletion precisely: address source data, derived attributes, linkage keys, backups, downstream recipients, later reacquisition, and certification. A profile that silently reappears was not meaningfully deleted. Before combining datasets, document each source’s original purpose, legal authority for reuse, receiving agencies, matching risks, and the conditions for ending the connection.

    Review software capabilities before deadlines and updates

    A mandatory interface transition should trigger a feature and policy review. Identify every analytical or AI-assisted tool available, licensed, enabled, or planned; the data it can ingest; the output it creates; retention and sharing; model providers and subprocessors; auditability; and the human decision that remains accountable.

    Do not treat interface availability as authorization. New summarization, search, identification, prediction, streaming, remote-operation, or automated-dispatch capabilities should require documented legal review and approval proportionate to their effect. The system should record who activated each feature, the governing policy, the effective date, and whether the feature can be disabled without losing access to unrelated functions.

    Patch, investigate, and plan for failure

    Maintain a current inventory of internet-facing services and unsupported equipment. Assign emergency patch authority, restrict management access, enforce strong authentication, preserve logs, and review for indicators of compromise after active exploitation is announced. Installing an update does not establish that attackers were not already present; agencies should document what was exposed, how far investigators looked back, and why they concluded the environment is safe to return to service.

    For every sensitive system, name who can suspend use, preserve evidence, notify affected people, correct records, commission an independent review, and terminate the contract. Define what must be reported to elected officials and the public after unauthorized access, inaccurate matches, vendor nonperformance, or a policy-changing software update. The morning after an incident is too late to decide who has authority to stop the system.

    Bottom line

    Trust is not an audit. A safeguard exists when an independent reviewer can test the representation, reconstruct the action, identify the responsible person, correct the error, and impose a consequence.

    The common question for Issue 17 is simple: What evidence would prove that the system did what officials were told it would do?

  • Signals & Safeguards Issue 16: Location-Data Warrants, the Data-Broker Loophole, and Proving Safeguards Work

    Signals & Safeguards

    Issue 16 • Wednesday, July 1, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • The Supreme Court held that obtaining even two hours of precise Google Location History is a Fourth Amendment search.
    • Bend strengthened its ALPR policy, but the vendor audits needed to verify compliance had not yet arrived.
    • Bipartisan oversight caused ATF to cancel one commercial-location contract, while the broader data-broker loophole remains.
    • The House passed a broad youth-online-safety package, keeping age checks and data minimization at the center of the debate.

    Using an app is not consent to government access

    The Supreme Court has extended Carpenter‘s protection for cell-phone location records to a more precise form of digital location history – and rejected the idea that a short search or an “optional” smartphone feature falls outside the Fourth Amendment.

    In Chatrie v. United States, police investigating a Virginia bank robbery used a geofence warrant to make Google identify devices near the crime scene. Google first supplied anonymized data for 19 devices. Investigators selected nine for a broader two-hour view, including movement outside the original geofence, and then selected three users whose identities Google disclosed.

    The Court held that police conducted a Fourth Amendment search when they obtained Okello Chatrie’s Location History. That remained true even though the request covered only two hours and the records came from a technology company rather than directly from his phone.

    The majority explained why the information is unlike an ordinary business record. At the time, Location History could record a phone roughly every two minutes, locate it within about 20 meters, and sometimes estimate which floor of a building it occupied. A short slice could expose a home, medical visit, political gathering, school, hospital, or place of worship.

    The Government argued that the period was too brief and that Chatrie had voluntarily enabled the feature. The Court rejected both arguments. Fourth Amendment protection does not begin only after surveillance “goes too far,” and ordinary use of modern apps does not mean that private information is freely available to government.

    The duration issue matters because officers were not following a known suspect for two hours. They were selecting a short interval from an all-encompassing database after the fact. The Court reasoned that a system does not become less intrusive merely because government can use hindsight to choose the most revealing hours. Even one trip can expose a political rally, abortion clinic, criminal-defense lawyer, or other association a person reasonably expects to keep private.

    The Court also rejected an app-by-app version of the third-party doctrine. Google repeatedly prompted users to enable Location History, sometimes warning Android users that devices would not work correctly without it, while not fully explaining the frequency, precision, or potential government access. More broadly, the point of a smartphone is to use apps and cloud services. Sending email, storing photos, or adding a calendar entry should not become blanket consent for government access merely because a company hosts the data.

    The judgment was 6-3. Justice Elena Kagan wrote for five Justices. Justice Neil Gorsuch supplied the sixth vote through a separate concurrence reasoning that digital location history can be a person’s electronic “papers or effects,” even when a company stores it.

    The ruling is important but narrower than saying all geofence warrants are unconstitutional. The Fourth Circuit must still decide whether each stage of this warrant satisfied probable cause and particularity, and whether the good-faith rule affects suppression. Justice Ketanji Brown Jackson, joined by Justice Sonia Sotomayor, would have found at least stages two and three unconstitutional because officers – not a neutral magistrate – chose who received deeper scrutiny.

    Why it matters for public officials: A multi-stage search should not become progressively more intrusive through an internal vendor workflow. A judge should define the narrowing criteria and find probable cause before officials expand the time period, follow devices beyond the original location, or reveal identities.

    Google told the Court that it moved Location History storage from central servers to users’ devices in July 2025 and can no longer respond to this particular centralized demand. The old Google process may be fading, but the Court’s principle reaches a broader question: using an ordinary digital service does not itself surrender constitutional privacy.

    The decision therefore matters beyond geofences. Government databases increasingly allow officials to begin with a place, event, face, plate, device, or pattern and work backward toward a person. The constitutional question is not only whether a warrant exists at the beginning, but whether each material expansion remains tied to probable cause, particularity, and neutral review.


    Bend strengthened its ALPR policy. Now the system has to prove it follows it.

    Bend Police has expanded Policy 428 following Oregon’s new statewide rules for automated license plate readers. The revised policy adds privacy, accountability, and civil-rights language; states that Bend owns its database; and bars use for protected First Amendment activity, federal immigration enforcement, and out-of-state abortion investigations.

    Those are meaningful improvements. The remaining question is whether the technical system and vendor relationship can demonstrate compliance. Oregon law requires 30-day and quarterly vendor audits that agencies must publish promptly after receiving them. As of the June 29 reporting, Bend had not received the required reports from Axon and was working with the company on automated delivery.

    Until the audits exist, the public cannot examine which agencies queried the system, why they searched, or when the searches occurred. The policy calls for 30-day and quarterly reports to be posted quickly after receipt, which makes vendor delivery part of the safeguard rather than a back-office detail. An audit requirement that the vendor cannot or does not produce is not yet an audit system.

    The same distinction applies to encryption. Oregon’s law allows existing contracts to continue for a limited period even if they do not yet meet the new end-to-end-encryption rule, while new contracts and add-ons face the stronger standard. That makes procurement timing, feature activation, and key management important. Officials still need to know what is encrypted, who controls the keys, whether Axon can decrypt or export records, and how support, sharing, legal process, and exceptions are logged.

    Database ownership alone does not answer those questions. A city may “own” the records while a vendor controls the hosting environment, administrator privileges, software updates, integrations, or encryption keys. The practical test is whether Bend can independently inspect every local, outside-agency, and vendor action and can prevent access that conflicts with policy.

    Questions for the next review: Have the required audits arrived? Do they include case number, purpose, user, agency, date, data source, and result? Can Bend see vendor access? Who holds the decryption keys? What happens when a search is denied, an integration is added, or a new feature changes what the system can reveal?

    A written rule is an essential starting point. It becomes a safeguard when the system enforces it and leaves enough evidence for an independent reviewer to verify that it worked.

    “A new technology should not transform what individuals had reasonably thought they could withhold from the Government.”

    — Justice Elena Kagan, Chatrie v. United States (2026)

    Oversight stopped one warrantless tracking contract – not the underlying loophole

    The Bureau of Alcohol, Tobacco, Firearms and Explosives has canceled its contract for Penlink’s Webloc location-surveillance product after bipartisan congressional scrutiny. The cancellation is a concrete example of oversight changing agency behavior – but it also shows how much still depends on discovering one contract at a time.

    According to Senator Ron Wyden and Representative Michael Cloud, Webloc used location information originating in commercial advertising systems. ATF disclosed 341 searches: 55 for training or demonstrations, 64 related to violent-crime matters, and 222 associated with active case numbers.

    In one arson investigation near a defense contractor, the prosecutor and judge reportedly raised serious concerns about the warrantless commercial data. Investigators then obtained a traditional court order for bulk cell-tower information.

    ATF canceled the contract six days after a briefing in which congressional staff raised constitutional concerns, state-law restrictions, and Federal Trade Commission actions against sellers of sensitive location data. The agency also committed to reviewing other contracts for similar adtech-derived information.

    The episode shows why contract inventories matter. A surveillance capability can enter an agency as a subscription, analytics service, demonstration account, data-enrichment feature, or add-on to a broader platform. If officials and the public cannot see the product name, data sources, authorized uses, and query counts, there may be no practical opportunity to test legality before the tool is used in active investigations.

    It also shows that oversight can work. The contract was not canceled because the vendor voluntarily narrowed the product or because an internal policy review happened on schedule. It was canceled after lawmakers obtained records, asked how the data were sourced, compared the practice with constitutional and state-law limits, and forced the agency to explain specific searches.

    This story is related to Chatrie, but the legal routes are different. In Chatrie, government compelled a provider to disclose stored account information. With Webloc, an agency purchased commercially collected location data. The first route is governed by warrant and subpoena doctrine; the second is often called the data-broker loophole because agencies argue that information available for purchase can be acquired without the process normally required for a search.

    That distinction should not determine whether movements receive protection. A visit to a clinic, religious service, union meeting, political gathering, or private home does not become less revealing because the information reached government through an advertiser rather than a cellular carrier.

    A durable rule should follow the sensitivity and use of the data, not the route by which it was obtained. Otherwise, a warrant requirement can be bypassed by purchasing a commercially assembled substitute, and a restriction on one agency can be bypassed by a contractor or another agency with access to the same market.

    The safeguard: Require a warrant or equivalent judicial authorization for sensitive location information regardless of whether the source is a carrier, platform, advertiser, broker, or contractor. Agencies should also disclose the products they use, the legal process attached to each search, and the number and purpose of queries.

    A procurement test for commercially sourced data

    Before buying any investigative dataset, an agency should document the original collector, every intermediary, the collection method, consent or notice, accuracy controls, retention, permitted uses, opt-out process, and whether the seller obtained the information in compliance with law and platform rules. The contract should prohibit substitution of a new source without notice and review.


    Facial recognition cannot remain invisible when it helps identify a defendant

    The New Jersey Supreme Court has unanimously ruled that prosecutors must give criminal defendants basic information about facial-recognition technology used during an investigation – even when the State describes the result only as an investigative lead and does not plan to introduce the software output at trial.

    The case concerns Tybear Miles, who was identified as one of several possible matches after police submitted an Instagram image to a facial-recognition system during a murder investigation. Miles sought information about the system and its use so he could test reliability, examine whether police pursued other candidates, and challenge later identifications influenced by the initial search.

    The court rejected a rigid universal checklist but held that defendants generally must receive information identifying the tool and explaining how it was used in the investigation and prosecution. That basic disclosure can expose the source image, database, candidate list, analyst choices, investigative sequence, and possible alternatives to meaningful review.

    The distinction between a “lead” and evidence can be misleading. A facial-recognition result may never be shown to a jury, yet it can determine whose social-media account is examined, which person is placed in a photo array, which witnesses are re-interviewed, and which competing suspects receive less attention. Later evidence may appear independent even when the initial algorithmic match shaped the entire path of the investigation.

    The justices did not automatically require proprietary source code. A defendant seeking trade-secret material must first show a particularized need. The ruling therefore distinguishes between the minimum facts needed to test a government’s case and deeper technical discovery that may depend on the circumstances.

    That approach also avoids a false choice between total secrecy and unlimited disclosure of proprietary material. Agencies can preserve and disclose operational facts – the probe image, database, candidate rankings, thresholds, analyst steps, and corroboration – without assuming that every case requires the vendor’s source code. If those basic facts reveal a specific reliability problem, a court can then decide whether deeper technical material is necessary.

    The policy lesson is broader than one criminal case. Facial recognition should not be insulated from scrutiny merely by placing its output at the beginning of an investigation rather than in the trial exhibit list. An algorithmic lead can shape who police question, which images witnesses see, what evidence receives attention, and whether another candidate is ignored.

    The safeguard: Preserve the original probe image, all preprocessing, vendor and product version, database description, search settings, complete candidate results, analyst actions, and corroborating steps. Disclose that record early enough for meaningful review.

    What minimum disclosure should answer

    A useful record should show what image entered the system, how it was cropped or enhanced, which database was searched, what threshold or ranking method applied, how many candidates were returned, who reviewed them, and what investigators did next. It should also identify any witness procedure influenced by the result and preserve evidence about candidates who were not pursued.

    Shared pattern

    Congress could challenge Webloc because it learned the contract existed. A defendant can challenge facial recognition only if the State reveals that the tool was used. Oversight fails when the decisive system remains outside the record.

    Visibility is not paperwork. It is the condition that makes constitutional, contractual, and technical safeguards enforceable.

    For public bodies, that means maintaining a current surveillance inventory, publishing contracts and policies, recording each sensitive query, preserving investigative provenance, and giving an independent reviewer enough detail to reconstruct what happened. A safeguard that cannot be inspected or challenged is ultimately dependent on trust.

    Trade secrecy should not erase government accountability. Agencies may protect genuinely proprietary material while still disclosing the tool’s identity, data source, purpose, user, query terms, outputs, human decisions, and consequences. When a vendor cannot support that record, the product is not ready for a public-sector decision that affects liberty.

    “Such basic information will, in most cases, constitute the minimum necessary to safeguard a defendant’s right to a fair trial.”

    — Justice Douglas M. Fasciale, State v. Miles (2026)

    Warning Signals

    Warning Signals

    Early indicators of how surveillance expands: through network defaults, age checks, credential phishing, and reusable search tools.

    Woodburn’s experience shows why sharing architecture must be understood before deployment

    Woodburn has permanently removed its Flock Safety cameras after an audit showed that outside agencies – including federal immigration agencies – had been able to include Woodburn’s network in broad searches.

    The city’s public Q&A provides important context. It reports 3,318,618 searches during the period reviewed, but says 99.99% were multi-network searches rather than searches aimed only at Woodburn; 306 uniquely targeted Woodburn. Homeland Security Investigations and U.S. Border Patrol were among the federal agencies whose broader queries included Woodburn during a Flock pilot program that city officials say they had not been told about.

    The document says the city disabled national lookup in October 2025 and found no federal searches after June 24, 2025. But the most important fact is that Woodburn did not knowingly approve the pilot architecture that allowed its network to appear in those searches. The cameras were ultimately removed in May 2026 after the city ended the contract.

    That nuance does not erase the governance failure. It explains it. A local agency can believe it has not affirmatively shared data while a vendor’s network design silently makes its cameras part of a much larger search surface.

    Before deployment, officials should see the default sharing settings, national-search capabilities, pilot programs, vendor administrator access, notification rules, and every route by which a local database can be included in another agency’s query.

    They should also require a change-control rule: no pilot, federation, network expansion, integration, or new search mode should apply to local data without written notice, legal review, and affirmative approval. Vendor defaults are policy choices when they determine who can search a community’s records.

    The procurement lesson: Ask for a live demonstration of every sharing screen and administrator setting, then attach the approved configuration to the contract. Require notice before the vendor changes a default, joins a pilot, or makes local data searchable through a new network path.


    The KIDS Act clears the House – with age checks still the privacy fault line

    The House passed H.R. 7757, the Kids Internet and Digital Safety Act, on June 29 by a bipartisan 267-117 vote. The package now moves to the Senate and is not law. It combines proposals involving platform design, youth privacy, targeted advertising, AI chatbots, online games, data brokers, parental controls, audits, and research.

    The House package is not the same as the stronger KOSA framework the Senate passed in 2024, and key senators have criticized the compromise. That makes House passage a major status change, not a final policy settlement. Any Senate amendment would require further agreement between the chambers.

    The age-verification provisions require careful attention. The SCREEN Act title directly requires covered platforms substantially devoted to sexual material harmful to minors to use commercially available verification technology and prevent minors from accessing that material. It also limits collection, use, retention, and disclosure of verification data to what is strictly necessary.

    The KOSA title separately says it should not be construed to require age gating or age verification. But other provisions impose duties when a service “knows or should have known” a user is a child or teen. The Electronic Frontier Foundation argues that this pressure will lead broader services to determine users’ ages, including by asking adults to prove they are adults.

    That is an advocacy interpretation, not a settled outcome. But it identifies the key implementation question: Can a service comply without building a persistent identity or age-classification system for everyone?

    The privacy question is not whether protecting children is worthwhile. It is what infrastructure compliance creates. A system that collects identity documents, biometric estimates, device signals, or persistent age labels can become useful for advertising, account linkage, content control, or government access unless reuse and retention are technically and legally prohibited.

    Any final bill should minimize data, prohibit reuse, protect anonymous and pseudonymous access, avoid biometric estimation where less intrusive methods work, publish error rates, and require independent testing for demographic bias. The strongest design proves only the necessary threshold and then forgets the underlying evidence.

    What to watch in the Senate: whether the final package changes the “knows or should have known” standard, narrows or expands direct age-verification duties, preserves state protections, limits data retention, and creates a realistic enforcement path when an age system is inaccurate or discriminatory.


    Treat messaging-app recovery keys like master passwords

    The FBI warns that Russian intelligence-linked actors are impersonating messaging-app support services and trying to obtain verification codes, account PINs, and backup recovery keys.

    A recovery key can be more damaging than an ordinary password. An attacker who obtains one may be able to download historical private and group messages and later take over an account. The old key can remain useful even after the victim creates a new account with the same phone number.

    No legitimate support agent should ask for a backup key, verification code, or PIN. After suspected exposure, generate a new recovery key from inside the application; changing the account alone may not invalidate the compromised key. Regeneration cannot retrieve a backup already downloaded, but it can block future use of the old credential.

    Civic organizations should write this into incident-response plans. If a member reports a suspicious support message, the response should include regenerating the key, reviewing linked devices and active sessions, preserving the phishing message, warning affected groups through a trusted channel, and assuming that messages already restored by the attacker may have been copied.

    The broader lesson is that encrypted messaging still depends on unencrypted human workflows. Attackers often do not break the cryptography; they persuade a user to hand over the recovery path.


    Axon Watch: better logs, easier recurring searches

    Axon’s June 30 Records and Standards notes describe a report-redaction tool that records who made a redaction, when it occurred, and the reason – if the user provides one. They also add reusable saved searches and more precise audit-log timestamps. The rollout began at 11 a.m. Pacific and may continue into the following day; Axon says availability can change.

    These are governance changes, not merely interface changes. A redaction log is stronger when the reason is mandatory and tied to a policy category. If the reason remains optional, an audit may prove that a field was hidden without explaining the legal basis for hiding it.

    Saved searches can improve efficiency, but they can also turn a one-time query into a standing practice. A reusable search may silently encode a broad location, person category, vehicle pattern, or data combination that is run again and again. Agencies should control who may create, share, and execute saved searches, require a purpose and expiration date, and review recurring sensitive queries as surveillance programs rather than personal shortcuts.

    More precise timestamps are useful only if records are retained, protected from alteration, and connected to user identity, case number, query terms, and result handling. Better software fields become safeguards when policy makes them complete and review makes them consequential.


    Safeguards

    Safeguards

    The strongest protections this week control who can take the next, more intrusive step – and make that step provable.

    Put a judge at every material expansion point

    A digital warrant should specify more than the first geographic circle or time window. When a search proceeds in stages, define objective narrowing criteria and require renewed judicial approval before investigators expand the period, follow devices beyond the original location, or reveal identities.

    The order should identify the offense, factual basis, data source, geographic boundary, duration, expected number of affected people, minimization procedure, deletion rule, and the evidence required before moving to the next stage. Investigators should not receive a “roving commission” to decide whose private movements deserve deeper review.

    Apply one constitutional standard to sensitive location data

    Do not let the purchase route determine the privacy rule. Require a warrant or equivalent judicial authorization for sensitive location information obtained from carriers, platforms, advertisers, brokers, or contractors. Record the legal authority, requesting official, case number, purpose, date range, geographic scope, and disposition for every query.

    The rule should cover direct access, subscriptions, trial accounts, demonstrations, enrichment services, federated searches, and records received from another agency. A restriction on compelled disclosure is incomplete if the same movement history can be bought from a commercial intermediary.

    Verify vendor promises with deliverables

    A contract should identify the exact audit reports a vendor must produce, their fields and format, delivery schedule, retention period, public-posting process, and consequences for nonperformance. Encryption terms should state what is encrypted, when, who possesses the keys, and whether the vendor can decrypt or export records.

    A practical contract checklist:

    • Can the agency inspect every local, outside-agency, and vendor action?
    • Must each search include a case number, purpose, and legal authority?
    • Are outside networks and new integrations disabled by default?
    • Must the vendor give notice and resist conflicting legal demands?
    • Does the agency approve pilots, feature activations, and policy-changing updates?
    • Can the agency terminate, obtain deletion certification, and recover fees after a material breach?

    “We own the data” is not enough if the vendor controls administrator access, encryption keys, integrations, or the audit evidence needed to prove compliance.

    Make facial recognition reproducible

    Preserve the original image, all preprocessing, vendor and version, database searched, settings, complete candidate results, analyst decisions, later witness procedures, and corroborating evidence. Disclose the system’s use even when prosecutors call it only a lead.

    Do not treat a candidate list as an identification. Require trained human review, independent corroboration, and a record of why other candidates were rejected. Later witnesses should not be shown a single algorithm-selected person in a way that converts a tentative lead into an apparently independent identification.

    Map every route into and out of the system

    A sharing diagram should identify local users, outside agencies, vendor administrators, subcontractors, federated networks, application-programming interfaces, exports, backups, and legal-process pathways. For each route, specify who can authorize access, what purpose is allowed, what data leave the system, how long the connection lasts, and what evidence the action creates.

    Review the diagram whenever a contract is renewed, a pilot begins, an integration is enabled, or a software update changes search or sharing. Woodburn’s experience shows that an agency can misunderstand its own exposure when the vendor’s network architecture changes the practical meaning of “sharing.”

    Make audit evidence usable, not ceremonial

    A useful audit record needs the user and agency, date and time, case number, stated purpose, legal authority, search terms, datasets queried, result count, exports, sharing, and final disposition. It should also record denied attempts, administrator changes, vendor access, retention overrides, and creation or reuse of saved searches.

    Assign someone independent of day-to-day users to review the logs on a fixed schedule. Publish aggregate reports quickly, investigate anomalies, document corrective action, and preserve detailed records long enough for litigation, public-records review, and contract enforcement. A log no one reads is storage, not oversight.

    Build age assurance to forget, not remember

    Reveal no more than the minimum fact necessary – such as whether an age threshold is met – and do not create a reusable identity record. Prohibit secondary use, advertising, cross-service tracking, indefinite retention, and conversion of an age check into a biometric profile. Require appropriate legal process before government access.

    Legislation should require public documentation of the method, error rates, demographic testing, retention schedule, appeal process, and all downstream recipients. A child-protection system should not quietly become identity infrastructure for every adult who uses the service.

    Treat recovery keys as offline secrets

    Store backup recovery keys separately from the device and account they protect. Never send them through chat, email, forms, or a support conversation. Regenerate the key immediately after suspected exposure and review linked devices and active sessions.

    Organizations should designate a trusted channel for security alerts and rehearse what happens after compromise. Preserve the fraudulent message, warn affected groups, rotate related credentials, and assume that any backup already downloaded may be outside your control.

    Govern recurring searches as policy, not convenience

    Saved searches, alerts, watchlists, and automated recurring queries can become standing surveillance programs. Require a documented purpose, owner, approval period, review date, access list, and deletion rule. Audit not only who ran a search but also who created the template and how often it was reused.

    A recurring query should expire unless someone affirmatively renews it. Material changes to search terms, geography, datasets, or sharing should trigger a new review. The easier software makes repetition, the more important it becomes to distinguish a lawful one-time inquiry from ongoing monitoring.

    Plan for failure before deployment

    Every sensitive system should have an incident plan that covers unauthorized access, inaccurate matches, vendor nonperformance, exposed credentials, unlawful outside queries, and policy-changing software updates. Name the decision-maker, evidence-preservation steps, notification duties, suspension authority, correction process, and conditions for terminating the system.

    Failure planning changes incentives before anything goes wrong. Vendors know which records they must preserve and what breach consequences apply; staff know when to stop using a tool; affected people have a correction path; and elected officials receive facts rather than reassurances.

    Bottom line

    The strongest safeguards this week all control the next step. A judge must control when a location search widens. A contract must control whether a vendor delivers an audit. Discovery must reveal when an algorithm shaped an investigation. An age check must not become a lasting identity system. And a recovery key must remain outside the reach of anyone pretending to offer support.

    The common test is operational: Who can take the next step? What evidence must they provide? What does the system prevent? What does it log? Who can inspect the record, correct an error, or impose a consequence?

    A safeguard is not what a policy promises. It is what the system prevents, records, reveals, and allows someone to challenge.

  • Signals & Safeguards Issue 15: Repurposed Databases, Data Brokers, and the Search Layer

    Signals & Safeguards

    Issue 15 • Wednesday, June 24, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • A federal court set aside the government’s 2025 overhaul of the SAVE system after sensitive records were repurposed for bulk voter screening and produced inaccurate citizenship flags.
    • ICE reportedly turned to a data broker for tax-identifier records after direct federal sharing faced legal barriers.
    • Eugene is beginning the harder work of governing surveillance citywide rather than debating one tool at a time.
    • Age verification is advancing through Congress, state law, litigation, and increasingly automated estimates of who is a child.

    Federal databases became a voter-screening system—and a court said the government skipped the rules

    A federal judge has set aside the federal government’s 2025 overhaul of the Systematic Alien Verification for Entitlements system, known as SAVE, after finding that agencies unlawfully combined sensitive records and transformed an administrative verification tool into a system for mass voter screening.

    SAVE is not new. It was built to help government agencies verify citizenship or immigration status when people apply for certain public benefits, licenses, and other services. The court did not eliminate that longstanding function. It instead vacated the 2025 modifications that dramatically changed what the system could search and how it could be used.

    According to the 75-page opinion, the modified system differed from the earlier version in three major ways. It added records about people born in the United States, connected SAVE to Social Security Administration records—including full or partial Social Security numbers—and allowed government users to upload lists for bulk searches rather than checking one person at a time.

    Those changes matter because they altered both the scale and the purpose of the system. A database designed to verify an individual’s eligibility for a service became a tool that states could use to compare large voter lists against federal records. The court found that the agencies violated provisions of the Social Security Act and the Privacy Act, including statutory and procedural protections governing how personal information is disclosed and how federal record systems are changed.

    The accuracy problem was not hypothetical. The court described naturalized citizens whose Social Security records had not been updated and who were identified as potential noncitizens. Some were required to provide proof of citizenship within 30 days to protect their registrations. The record included citizens whose registrations were wrongfully canceled, including one person who learned of the cancellation only later.

    This does not mean election officials should ignore reliable evidence that someone is ineligible. It means that a match produced by a repurposed database should not be treated as a fact without understanding where the data came from, how current it is, what error rate exists, and what process allows an eligible person to correct the record before losing a right.

    The case also illustrates why bulk search is not merely a technical upgrade. Searching one identified person for a documented reason is different from uploading millions of names to see who a system flags. Once bulk screening becomes available, an administrative database can become a general eligibility, enforcement, or suspicion engine.

    Why it matters for Bend: Local and state governments hold sensitive information because residents apply for licenses, permits, utilities, benefits, housing, jobs, school services, and emergency assistance. The original collection may be lawful and necessary. The next question is whether those records can later be combined, searched, or repurposed for a substantially different objective without public notice, accuracy testing, correction rights, or a new decision by elected officials.

    The safeguard is not a promise that data will be used responsibly. It is a rule that identifies the authorized purpose, limits the searchable records, documents every query, tests for error, notifies people before adverse action, and provides a meaningful way to correct mistakes.


    When direct government access is blocked, agencies may buy the data instead

    A nearly $10 million procurement reviewed by 404 Media indicates that Immigration and Customs Enforcement is purchasing records related to Individual Taxpayer Identification Numbers through a commercial data provider.

    An ITIN is a tax-processing number issued by the Internal Revenue Service to people who need to file federal taxes but are not eligible for a Social Security number. ITIN holders include people with different immigration and residency circumstances; possession of an ITIN should not by itself be treated as proof of unlawful presence.

    The reported procurement is significant because a federal court had already blocked an arrangement under which the IRS would directly share taxpayer information with the Department of Homeland Security. Senator Ron Wyden told 404 Media that buying related information from a private broker appeared to be an end-run around taxpayer-privacy law and the court’s order.

    That is an allegation about the apparent purpose and legal effect of the contract, not a final judicial ruling on the procurement itself. But the mechanism raises a policy problem that extends well beyond immigration enforcement: a restriction on direct government access may provide little protection if an agency can purchase the same or similar information from a commercial intermediary.

    Data brokers rarely sell only a single raw field. Commercial products can link identifiers to names, addresses, phone numbers, relatives, property records, employment information, location histories, or other records. Even when each source began as a separate administrative or commercial record, the broker’s value comes from connecting them.

    That creates a form of policy laundering. Government may be barred from compelling one agency to disclose a sensitive record, yet still acquire a commercially assembled product that reveals or predicts substantially the same information. The practical safeguard therefore has to regulate acquisition, not merely direct sharing.

    Why it matters for Oregon: Oregon has already recognized that data-broker relationships can become immigration-enforcement pathways. But the broader lesson applies to every public body: laws and contracts should address broker purchases, enrichment services, vendor-derived identifiers, downstream matching, retention, secondary use, disclosure to outside agencies, and deletion when authority expires.

    Public officials should also ask vendors to document the origin of every data category they sell. “Commercially available” does not answer whether the original collection was consensual, accurate, current, lawful for the new purpose, or capable of correction.


    Shared pattern

    The SAVE case and the reported ICE procurement involve different institutions and different legal questions. One concerns federal databases repurposed for voter screening. The other concerns commercially acquired records used for immigration enforcement. The shared governance problem is the same: a limit on collection or direct sharing does not protect people if sensitive information can later be combined, purchased, or searched through another route.

    The search layer is the policy layer. Whoever controls what questions the system can answer may possess more practical power than the institution that originally collected the data.

    “In the pre-computer age, the greatest protections of privacy were neither constitutional nor statutory, but practical.”

    — Justice Samuel A. Alito Jr., concurring, United States v. Jones (2012)

    Eugene is moving from one surveillance dispute to a citywide governance system

    Eugene City Councilors have directed staff to begin developing a broader policy for surveillance technology, moving the discussion beyond the city’s earlier controversy over Flock automated license plate readers.

    The decision is important because it treats surveillance as a governance category rather than a series of unrelated purchases. Eugene is not currently debating whether to reactivate its Flock cameras. Instead, councilors are asking what rules should apply whenever any department considers a technology capable of identifying, tracking, recording, profiling, or analyzing people.

    City staff reviewed approaches used by Portland, Berkeley, and San Jose. According to KLCC, several councilors were especially interested in San Jose’s risk-based model, which applies citywide and requires greater oversight when a proposed technology presents a higher risk to privacy or civil liberties. Portland’s process includes privacy-impact assessments during procurement and a public inventory of city technologies that can be used for surveillance.

    Those models separate several decisions that are often blurred together.

    An agency-use policy tells employees how to operate a system after it exists. A procurement rule asks what information must be disclosed before money is committed. A public-approval process determines when elected officials and residents should have a role. An oversight system requires reporting, audits, and review after deployment. A city can have one of these without the others.

    That distinction helps explain why a police policy alone is not enough. A department may write careful rules for current uses while a contract permits vendor access, outside-agency sharing, future analytics, or automatic product upgrades. A procurement process may review price and legal compliance without examining civil-rights risk. A council may approve a device without knowing that later software changes can substantially expand what it does.

    Eugene staff also identified a question many governments avoid: whether the city should review technology already in use. A forward-looking approval process can prevent new problems, but it does not reveal what departments already operate, what records those systems retain, what databases they connect to, or which vendors can access them. A citywide inventory is the starting point for meaningful governance because officials cannot oversee tools they do not know exist.

    Eugene’s final policy has not been written or adopted. Staff said the process could take at least six months and may proceed in phases, particularly if the city reviews existing systems and department-specific rules. Councilors also called for meaningful public participation, which could extend the timeline.

    That is not a weakness. Surveillance policy should not be rushed merely because technology procurement usually moves quickly. The purpose of a durable framework is to decide the rules before the next vendor presentation, grant deadline, emergency request, or contract renewal compresses the decision.

    Why it matters for Bend: Bend’s current ALPR debate demonstrates the limits of reviewing one administrative policy or contract at a time. A durable, CCOPS-aligned process should apply before surveillance technology is purchased, activated, expanded, connected to another system, renewed, or upgraded with a materially new feature.

    At minimum, that process should require:

    • a citywide inventory of existing and proposed systems;
    • a plain-language description of capability, not merely the product name;
    • a privacy and civil-rights impact assessment;
    • the proposed purpose and prohibited uses;
    • data sources, retention, sharing, and vendor access;
    • security architecture and breach responsibilities;
    • independent audit requirements;
    • public reporting on use, searches, errors, complaints, and misuse;
    • fresh approval before significant expansion or integration.

    Eugene’s approach should not be treated as proof that its eventual policy will be perfect. Its value is that the city is asking the right institutional question: how should surveillance be governed across the whole government before the next tool becomes a fait accompli?


    Kansas City plans to turn bus cameras into live identity searches

    Kansas City’s transit authority is preparing to add facial-recognition software to cameras on public buses. Images of passengers would be compared in real time against active alerts for banned riders, missing persons, and people on law-enforcement watchlists designated by the transportation authority.

    That is a meaningful change in function. A conventional security camera records what occurred so footage can be reviewed later. Live facial recognition asks a different question about everyone entering the camera’s view: does this face match someone on a list?

    The Missouri state government declined expected funding because of concerns about the facial-recognition component, but the project is moving forward with local and federal funding. The initial deployment has been delayed, not abandoned, and could eventually reach as many as 30 buses.

    The vendor says facial data associated with nonmatches will not be retained. That is a relevant safeguard, but it does not resolve the main governance questions. The transit authority reportedly may retain ordinary bus footage locally for as long as five years. More important, deletion of a nonmatching template does not determine who can be placed on a watchlist, what evidence supports the placement, how long someone remains listed, or how a person can challenge an error.

    “Banned rider” can also cover very different circumstances. A narrowly documented temporary exclusion after a serious assault is not the same as an indefinite administrative list built from complaints or disputed conduct. Missing-person alerts may involve people who need assistance, but they also raise questions about consent, family conflict, and whether every reported missing adult should trigger automated identification. Law-enforcement lists may range from judicial warrants to investigative interest that has never been tested in court.

    A facial-recognition match should not itself justify detention, removal, questioning, or adverse action. Systems can be wrong because the image is poor, the watchlist record is outdated, the algorithm performs unevenly, or two people look similar. Human review helps only when the reviewer receives independent information and is expected to challenge rather than confirm the machine.

    Why it matters locally: Cities increasingly add analytics to cameras that were approved for more limited purposes. Officials may hear that “the cameras already exist” or that the change is merely a software upgrade. But converting recording equipment into a live identification system is a new surveillance decision and should require a new public review.

    Before deployment, officials should define eligible watchlists, evidentiary standards, maximum listing periods, independent accuracy testing, confirmation procedures, prohibited uses, notice and appeal rights, retention, audit access, and the approval required for expansion.

    The oversight question is not simply whether the technology works

    A system may correctly identify many people and still be poorly governed. The deeper questions are who defines success, which errors count, who bears the consequences, and whether a limited pilot can become permanent infrastructure without another vote. The safeguard is to establish those rules before the first live search, not after the first public controversy.

    “Awareness that the Government may be watching chills associational and expressive freedoms.”

    — Justice Sonia Sotomayor, concurring, United States v. Jones (2012)

    Warning Signals

    Warning Signals

    These items point toward where identity systems, vendor platforms, and searchable public records may be heading next.

    Age verification is advancing through both legislation and litigation

    House Energy and Commerce Committee leaders released revised bipartisan text of the Kids Internet and Digital Safety Act, or KIDS Act, on June 22. The measure has not passed the House, but its age-verification language is now concrete enough to evaluate.

    Title I would apply to publicly accessible platforms where more than one-third of the material is sexual material harmful to minors. Those services would have to use commercially available technology to determine whether a user is likely a minor and prevent minors from accessing the covered material. A user simply checking a box or stating that they are an adult would not be sufficient.

    The bill contains several safeguards that should be recognized rather than ignored. Verification data could not be collected, used, transferred, disclosed, or retained beyond what is strictly necessary for the age check. Platforms could hire outside verification providers but would remain legally responsible. Reasonable administrative, technical, and physical security would be required. The text also says it does not require submission of government-issued identification.

    Those provisions reduce some risks, but they do not determine the actual architecture. Platforms would choose the specific verification technology, subject to statutory requirements. The difference between a privacy-preserving age token, a facial estimate, a credit-history check, a phone-account signal, and an identity-document upload is substantial. So is the difference between learning only “over 18” and retaining enough information to link an age decision to a persistent account.

    The bill would require a Government Accountability Office review after implementation, including effectiveness, privacy, security, and effects on speech and behavior. That is useful, but it would occur after verification systems have been deployed. Legislators should also require testing, transparency, and independent review before broad implementation.

    At the same time, emergency applications remain pending at the U.S. Supreme Court over Texas’s App Store Accountability Act. The Texas law reaches more broadly by requiring app stores to determine users’ ages and obtain parental consent before minors download applications. Applicants are asking the Court to undo a Fifth Circuit stay that allowed the law to take effect while constitutional litigation proceeds. Texas filed its response June 22, additional briefs were filed through June 23, and no order was listed as this issue was prepared.

    The federal bill and the Texas case should not be treated as interchangeable. One targets access to a defined category of adult material; the other makes an app store an age and parental-permission gatekeeper across the application ecosystem. The comparison shows why the mechanism matters as much as the stated objective.

    Oregon’s question should be architectural: Which services must request an age signal? Does the system return only a broad category, or a persistent identity record? Who keeps the evidence? Can it be reused, sold, linked, or subpoenaed? Can adults continue accessing lawful speech anonymously? How are mistakes corrected? Who is responsible when a child is classified as an adult—or an adult is locked out as a child?


    An age estimate can become a legal decision

    The United Kingdom plans to use facial-age estimation in 2027 to help assess the ages of asylum seekers who lack documents. Internal government testing obtained by WIRED, Lighthouse Reports, and The Independent shows why that use is materially different from an age estimate used to suggest child-friendly settings.

    The testing reportedly found that systems regularly mistook some children for adults and performed worse for people from Sub-Saharan Africa. For female Sub-Saharan African subjects, the estimated age was off by an average of 4.6 years—enough, in a borderline case, to classify a child as an adult.

    That error can affect detention, housing, legal protections, and access to services. The system is not merely recommending content; it is helping place a person on one side of a legal boundary.

    High-stakes age estimation should therefore never be decisive on its own. Governments should publish performance by age and demographic group, disclose uncertainty rather than a falsely precise number, prohibit adverse action based solely on the estimate, provide independent review and appeal, and limit retention and reuse of facial images.

    The lesson applies to Oregon even if the proposed system is less consequential. Technology that produces an age category is making a probabilistic judgment. Policy must be designed around the possibility that the judgment is wrong.


    Axon Watch: Records is making linked people and vehicles easier to surface

    Axon’s June 16 Records update changed incident and standalone-report search results so they display linked people and vehicles. Incident cards also show the roles those people and vehicles played.

    That may save officers and records staff time. It also makes relational information more visible at the search stage. A person who was a witness, reporting party, passenger, property owner, or otherwise associated with an incident can become easier to surface across repeated queries even when the person was never suspected of wrongdoing.

    Axon has additional changes scheduled for June 30. Those include saved search configurations, searches using attached evidence identifiers, improved searches by report author, a report-redaction tool, and audit-log timestamps precise to hundredths of a second. The redaction tool and more precise logs may strengthen accountability when permissions and review are well designed. Saved searches and broader search options increase the need to govern recurring queries.

    Public agencies should ask:

    • Which roles may search, export, redact, or save queries?
    • Must a query include a case number or documented purpose?
    • Can a saved search repeatedly surface records about uninvolved people?
    • Are searches and exports visible to supervisors and independent auditors?
    • Who may change redactions, and is the reason recorded?
    • Are new search features enabled automatically or activated after agency approval?
    • Does a contract treat a materially expanded search capability as a new feature requiring policy review?

    Procurement should not freeze its analysis at the product’s capabilities on signing day. Platform software changes over time, and the search layer can expand without a new camera, device, or contract headline.


    Madison Square Garden reportedly cataloged critics of facial recognition

    404 Media reports that Madison Square Garden compiled a document containing public comments and social-media posts from people who criticized the venue’s facial-recognition program. The document was found in a 45-gigabyte cache of company data stolen by hackers and later reviewed by the publication.

    The reporting does not by itself establish what MSG intended to do with the list. But the existence of a document titled around facial-recognition activists illustrates a serious governance risk: the institution operating a surveillance system may also possess the ability to catalogue the people challenging that system.

    Public criticism is part of oversight. It should not become a reason to add someone to an internal profile, watchlist, access restriction, or enhanced-surveillance category. Organizations using biometrics should adopt explicit rules prohibiting retaliation or heightened monitoring based on protected criticism, advocacy, journalism, or legal representation.


    Direction of travel

    This week’s Signals point toward identity becoming a reusable query. Age systems estimate whether someone is a child. Facial recognition asks whether a rider appears on a list. Records platforms surface associated people and vehicles. Institutions can compile information about critics. The safeguard is not only collecting fewer data. It is narrowing what questions systems are allowed to answer—and ensuring that every consequential answer can be examined, challenged, and corrected.


    Safeguards

    Safeguards

    The strongest protections this week are structural: govern the search, bind the vendor, preserve correction rights, and make misuse provable.

    Write the warrant rule, audit access, and termination right into the contract

    Shaker Heights, Ohio, has amended its Flock Safety contract and adopted access rules that offer a concrete example of turning privacy promises into enforceable terms.

    The city says Flock may not access, preserve, use, or disclose Shaker Heights data to a government authority or other third party without a court-issued search warrant. The contract rejects disclosure based merely on subpoenas, administrative demands, informal inquiries, preservation letters, national-security letters, investigatory convenience, generalized public-safety claims, or the vendor’s own contractual interests.

    The vendor must provide prompt written notice before disclosure and give the city an opportunity to seek protective relief. Flock must also make reasonable efforts to resist, narrow, quash, or otherwise challenge legal process that conflicts with the contract.

    The city receives on-demand access to audit logs covering searches by users inside and outside Shaker Heights. If Flock violates the assurances, the city may terminate without penalty and receive a refund.

    Shaker Heights also limited access so that no federal agency, agency outside Ohio, or agency participating in a 287(g) immigration-enforcement agreement may search the city’s data. The city contacted 434 jurisdictions that had requested access and required them to agree to the restrictions. Its internal police policy requires searches to be connected to a specific department case number or undercover case identifier.

    These provisions do not answer every concern. The city still operates 18 license plate readers, and local officials and residents must still evaluate camera locations, retention, authorized purposes, effectiveness, errors, audit review, and whether the network should continue. A contract is not a substitute for legislation, public oversight, or constitutional limits.

    But it shows what it means to negotiate rather than accept vendor boilerplate. “We own the data” is not enough if the vendor can respond to demands, preserve records, permit outside searches, or change access without meaningful city control.

    A practical procurement checklist for Bend:

    • What legal process must the vendor require before disclosure?
    • Must the city receive advance notice?
    • Is the vendor required to resist or narrow an improper demand?
    • Can the city inspect every internal, external, and vendor search?
    • Are outside agencies denied access by default?
    • Must each local search include a case number and purpose?
    • Does the contract prohibit sales, demonstrations, model training, or product development using city data?
    • What happens if the vendor violates the rule?
    • Can the city terminate without penalty and obtain deletion certification?
    • Do materially new features require affirmative approval before activation?

    Good contract language cannot prevent every abuse. It can make improper access harder, more visible, and legally consequential.


    Outsourcing a public service does not outsource responsibility for the data

    Texas Parks and Wildlife reported that an unauthorized actor may have obtained personal information belonging to more than three million hunting and fishing license customers through the vendor that operates the state’s licensing system.

    The potentially exposed information included driver-license data, passport numbers when supplied, email addresses, phone numbers, and residential addresses. The agency said Social Security numbers, birth dates, and financial information were not obtained. Texas Cyber Command detected the incident, and the agency says it and the vendor have strengthened access controls and monitoring.

    The incident demonstrates why a vendor-operated portal remains public infrastructure. Residents did not choose the contractor or negotiate its security practices. They provided information because the state required or requested it to deliver a government service.

    Before a vendor receives resident data, a public contract should identify every data field collected and why it is necessary. It should define privileged-access rules, multifactor authentication, encryption and key control, logging, monitoring, subcontractors, vulnerability management, incident-notification deadlines, evidence preservation, public communication, deletion at contract end, and responsibility for remediation.

    Officials should also ask whether a less sensitive identifier would work. A system cannot leak information it never collected or retained.


    Patch the system—and invalidate what attackers may already have stolen

    CISA confirmed active exploitation of a critical Splunk Enterprise vulnerability that can allow an unauthenticated, network-reachable attacker to create or truncate files through an exposed PostgreSQL sidecar endpoint. Splunk urged customers to upgrade fixed versions, and CISA imposed an accelerated deadline on federal agencies. Where immediate patching is impossible, disabling the affected sidecar service can remove the attack path, although it may disrupt dependent pipelines.

    Splunk deserves special attention because organizations often use it to collect the logs needed to understand other security incidents. If the monitoring system is compromised, altered, or unavailable, defenders may lose both operational capability and evidence.

    The week’s Fortinet warning adds a second lesson. CISA said compromised credentials associated with roughly 74,000 firewall and VPN devices had been exposed and used in attacks. This was not simply a reminder to install a patch. Credentials, active sessions, tokens, and keys stolen earlier can remain useful after vulnerable software has been updated.

    The practical response is broader:

    • inventory affected and internet-exposed systems;
    • patch supported versions;
    • disable vulnerable services when patching must be delayed;
    • rotate administrative and VPN passwords, keys, tokens, and service credentials;
    • terminate active sessions;
    • enforce phishing-resistant multifactor authentication where possible;
    • remove management interfaces from the public internet;
    • inspect successful logins, new accounts, configuration changes, and lateral movement;
    • preserve critical logs outside the potentially compromised monitoring environment.

    Patching closes a software flaw. Incident response must also invalidate what an attacker may already possess.


    Make privacy rights operational

    Vermont enacted S.71, now Act 145, adding another state model for consumer privacy and online-surveillance regulation. The specific provisions will matter, but the larger design lesson is that privacy rights work only when people can realistically exercise them and regulators can enforce them.

    A statute should identify who is responsible, create understandable request and correction processes, limit secondary use, provide implementation guidance, fund enforcement, and require records that allow violations to be proven. A right buried behind separate requests to hundreds of companies is much weaker than a right supported by a centralized or standardized process.

    Bottom line

    This week’s stories are connected by searchability. Sensitive data become more powerful when agencies can combine records, vendors can sell access, cameras can identify faces, and software can surface relationships across incidents.

    The strongest safeguards govern that power directly: define the permitted purpose, require a case number or legal basis, limit the datasets and watchlists, give people a meaningful way to correct errors, log every search, let an independent reviewer inspect those logs, and make vendors contractually responsible when they cross the line.

    Collecting less remains essential. But once data exist, the next safeguard is controlling what the system is allowed to reveal.

  • Signals & Safeguards Issue 14: Age Verification, ALPR Accountability, and Searchable Systems

    Signals & Safeguards

    Issue 14 • Wednesday, June 17, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • Section 702 expired legislatively, but the warrant fight did not end.
    • ALPR accountability is no longer hypothetical: misuse, tracking claims, private-camera sharing, and audit-log gaps are now concrete governance problems.
    • Cyber patch windows are shrinking as exploited vulnerabilities, AI-assisted attacks, and research-sector targeting accelerate.
    • Identity checks are spreading into phones, age verification, platform access, and encrypted communications.

    Section 702 expired on paper, but the warrant fight did not

    Congress allowed Section 702 to lapse after a short-term extension failed, but the practical surveillance fight is not over. Reuters explains that Section 702 allows warrantless collection targeting foreigners abroad, while also sweeping in communications involving Americans. The Guardian, AP, and the Brennan Center all point to the same unresolved question: when U.S. person communications are searched, should the government need a warrant?

    The important nuance is that “expired” does not necessarily mean “stopped.” Existing certifications may allow surveillance activity to continue for a period even after the statutory deadline. That makes the public-facing safeguard question sharper, not weaker. The debate is no longer only about whether Section 702 exists on paper. It is about whether searches involving Americans’ communications should require clear legal authority before they happen.

    The warrant issue also became entangled with unrelated politics. Reuters reported that Trump opposed renewal unless it was paired with proof-of-citizenship voting legislation. That does not change the civil-liberties question. A surveillance law that can reach Americans’ communications should not depend on unrelated legislative leverage.

    Why it matters for Bend: Section 702 is a federal intelligence law, not a city camera program. But the governance lesson travels. Broad search authority, weak front-end limits, secret interpretations, and after-the-fact review can become normalized unless public institutions insist on clear authority, narrow access, and usable oversight before sensitive searches occur.


    ALPR accountability is no longer hypothetical

    Automated license plate reader oversight is now an evidence problem, not a theory problem. Recent reporting shows officer misuse, private-camera networks, retail deployments, vendor-access questions, leaked search metadata, event-surveillance buildouts, and disagreement over whether systems “track people” or simply record vehicles.

    InvestigateTV / WRDW reported that Flock says its cameras do not track people, while training material describes following vehicles or suspects from “location to location.” 404 Media reported on police officers arrested or accused after allegedly using Flock systems to stalk or monitor people. AP reported on a Westchester County lawsuit involving a large ALPR system with 1.6 billion scans, nearly 600 cameras, and access by more than 50 outside agencies.

    The same issue is spreading beyond police-owned cameras. Retail parking-lot ALPR systems can still become public-safety data sources if their databases are shared, searched, or made available to law enforcement. Dayton Daily News and other reporting on retailers using Flock cameras show why “private” does not always mean “outside public surveillance.”

    The safeguard question is not only whether a camera reads plates. It is who can search the resulting record, how long the data is kept, whether outside agencies can query it, whether private databases can become police tools, whether vendor employees can access the system, and whether every search can be audited later.

    Why it matters for Bend: Bend already learned that access rules matter before systems go live. Any ALPR proposal should be judged by the audit trail it creates, not only by the problem it promises to solve. A system that cannot answer who searched, why they searched, what they saw, and whether the result was shared is not just missing a technical feature. It is missing the oversight system.


    Patch windows are shrinking because exploitation is getting faster

    Cybersecurity is becoming a timing problem. Reuters reported that U.S. officials shortened the remediation window for certain exploited vulnerabilities to three days as AI-assisted threats rise. CISA also continued adding known exploited vulnerabilities to its catalog, reinforcing the same practical lesson: once a flaw is being actively exploited, public agencies may not have weeks to decide what to do.

    The current-week examples cut across sectors. Reuters reported that Chinese-linked hackers targeted U.S. and Canadian research facilities over the past year, including academic, medical, military, AI, unmanned-vehicle, cyber-warfare, and medical-research targets. Reuters also reported cyber incidents involving iRhythm and an attempted extortion claim involving Novo Nordisk.

    The lesson for public institutions is not simply “patch faster.” It is to know which systems are exposed, who owns the fix, whether the vendor has patched, whether logs were reviewed, whether credentials or accounts changed, and whether dependent systems are affected. Cybersecurity is no longer only an IT department issue. It is public infrastructure governance.

    Why it matters for Bend: Cities, counties, schools, clinics, libraries, utilities, and vendors all depend on systems that can become public-sector risk points. Officials do not need to understand every exploit. They do need clear answers about exposure, patch timing, vendor proof, log review, and continuity plans.


    Shared pattern: searchability is the power

    The strongest stories this week point in the same direction: searchable systems need visible safeguards. Section 702 raises the question of who can search communications and under what authority. ALPR systems raise the question of who can search movement records and whether misuse can be proven. Cyber incidents expose the risk of large stores of sensitive data. Identity systems decide who must prove themselves before ordinary access. Police-tech platforms determine what becomes searchable next.

    The safeguard question is the same across all of them: who can search, why can they search, what legal authority applies, how long data is kept, whether vendors can access it, and whether misuse can be detected after the fact.


    Warning Signals

    Warning Signals

    These items point toward where search power, identity checks, platform access, vendor systems, and data governance may be heading next.

    Private cameras can still become public surveillance systems

    Retail ALPR systems are a reminder that “private” cameras can still become public-safety infrastructure. Dayton Daily News reported on Flock cameras used by retailers and shopping centers, while other reporting has pointed to Lowe’s, Home Depot, and similar parking-lot deployments.

    The privacy issue is not only who owns the pole or camera. It is who can search the plate data, whether police can access the database, how long records are retained, whether shoppers are meaningfully notified, and whether vendor sharing settings turn private parking lots into law-enforcement search points.


    Phone numbers may become identity checkpoints

    The FCC’s proposed “know your customer” proceeding would push phone providers toward stronger identity collection for subscribers. The stated goals include fraud reduction, robocall enforcement, and accountability. But the design matters.

    A phone number is often the gateway to work, housing, banking, medical care, two-factor authentication, family communication, and public services. If ordinary phone access requires more identity documentation, policymakers should ask who is excluded, what information is stored, how long it is retained, whether it can be shared with law enforcement, and whether anonymous or low-documentation options remain available.


    Age checks are becoming identity infrastructure

    France’s age-check fight shows how online child-safety rules are becoming identity-infrastructure debates. Reuters reported that an EU court said France can enforce age checks against porn sites based in other EU countries. At the same time, the UK is debating under-16 social-media restrictions, U.S. lawmakers are advancing kids’ online-safety proposals, and state age-verification laws continue to spread.

    Child safety is a legitimate policy goal. The safeguard question is whether the law protects children without forcing everyone else to prove identity, weaken anonymity, turn private vendors into access gatekeepers, or create reusable records of lawful online activity.


    Lawful-access bills can become encryption-access bills

    Canada’s Bill C-22 debate is a useful warning signal for other democracies. Reporting from iPhone in Canada and legal commentary around the bill say Apple and Google warned that lawful-access language could pressure companies to break or weaken end-to-end encryption, limit disclosure to users, or create new government-access obligations.

    The details are Canadian, but the pattern is broader. When governments seek faster access to digital evidence, the line between lawful process and infrastructure redesign can become blurry. Encryption policy should be debated directly, not buried inside broad access powers.


    AI chats can become legal records

    A New York judge blocked a subpoena seeking ChatGPT records in a lender lawsuit, according to Reuters. The ruling protected the records in that case, but the subpoena itself is the signal.

    AI prompts, chats, drafts, uploaded files, and account logs may become discoverable records, depending on context. Public agencies, advocacy groups, businesses, and lawyers should treat AI tools as record-creating systems, not just brainstorming spaces. Sensitive legal, personnel, constituent, or strategy work should not be pasted into tools without clear rules for retention, access, privilege, and disclosure.


    AI support bots should not control the keys

    The reported Meta AI / Instagram account-recovery incident shows why AI systems need hard permission boundaries. If an AI support system can grant account access, change recovery information, override verification, or alter enforcement status, then the AI is not just answering questions. It is controlling access.

    The safeguard is simple: AI should not hold the keys by itself. Account recovery, permissions, identity verification, enforcement decisions, and high-impact changes need strong verification, human escalation, audit logs, and rollback plans.


    Security features should not disappear quietly

    Reports that AMD removed or disabled a memory-encryption feature from some consumer Ryzen systems are a useful security-governance warning. The technical details matter less than the policy lesson: security features can be enabled, disabled, tiered, or moved behind enterprise product lines in ways ordinary users may not notice.

    Public agencies and institutions should ask vendors what security features are actually enabled, which features require higher-priced products, whether firmware or licensing changes can disable protections, and how customers will be notified if a security feature is removed or downgraded.


    Axon Watch: police-tech contracts are becoming platform commitments

    Axon’s June Records and Standards release notes are a reminder that public-safety technology keeps expanding after the original purchase. Recent release notes include report redaction with audit-log tracking, search tools tied to people and vehicles, saved searches, Evidence ID search, analytics privilege copying, site-attribute restrictions, and more precise audit-log timestamps.

    That is why Axon should be reviewed as a platform vendor, not only a device vendor. A body-camera, Taser, RMS, ALPR, drone, redaction, or AI feature may be introduced through a contract, amendment, release note, configuration setting, or bundled subscription. Public officials should ask not only what is being bought today, but what future searches, integrations, retention rules, vendor access, and audit logs the platform will make possible tomorrow.


    Surveillance pricing is becoming a consumer-protection issue

    Surveillance pricing is moving from theory to statutes and lawsuits. EPIC reports that Connecticut became the second state to enact a surveillance-pricing ban, while EFF is backing a California bill to restrict personalized pricing based on personal data. Courthouse News also reported on a class-action lawsuit over an alleged surveillance-pricing scheme.

    The policy issue is simple: data collected to identify, predict, or profile people can also become data used to set the price they see. Privacy law and consumer-protection law are starting to converge.


    Direction of travel

    This week’s Signals point toward one pattern: identity and access are becoming control layers. Phone numbers, age gates, encrypted services, AI accounts, retail ALPRs, security features, and police-tech platforms all decide who can enter, who can search, who can verify, and who can be watched. The safeguard challenge is to protect people without making ordinary life depend on persistent identity trails and invisible vendor systems.


    Safeguards

    Safeguards

    A safeguards page works best when it turns broad concerns into practical questions public officials can ask before systems are purchased, connected, searched, expanded, or renewed.

    Require authority before sensitive searches

    Sensitive searches should require clear authority before they happen, not only after-the-fact review. That authority might be a warrant, court order, statute, documented case need, or narrowly defined emergency exception. But the rule should be written before the system becomes routine.

    This applies across systems: communications searches, ALPR searches, biometric searches, law-enforcement databases, immigration-enforcement access, geofence-style searches, public-benefits records, school records, and sensitive civic data. If a search can reveal where someone has been, who they communicate with, what they believe, what services they use, or whether they may be flagged by government, the threshold should be higher than convenience.

    The practical question is simple: before a person searches sensitive data, what must they document, who reviews it, and how can misuse be proven later?

    Treat ALPR audit logs as the oversight system

    ALPR oversight should not depend on trust alone. It should depend on records that can be reviewed.

    A useful ALPR audit log should show who searched, what they searched, when they searched, why they searched, whether the search was tied to a case number or documented purpose, whether a hit was acted on, whether the result was shared, and whether an outside agency or vendor employee accessed the system.

    That does not mean exposing everyone’s raw location history to the public. It means protecting individual plate data while making the governance system visible. Public officials should be able to see scan counts, hit rates, false-hit procedures, retention rules, sharing settings, outside-agency access, vendor-access logs, misuse investigations, and policy exceptions.

    A system that cannot answer who searched, why, and what happened next is not just missing a technical feature. It is missing the oversight system.

    Make vendor access visible before approval

    Vendor access is part of surveillance oversight. Contracts should not leave it vague.

    Before approving or renewing a system, public officials should know whether vendor employees can access live feeds, stored footage, plate data, case files, audit logs, search tools, support dashboards, training environments, or analytics systems. They should also know whether vendor access is logged, whether customers are notified, whether data can be used for product development, sales demonstrations, AI training, quality review, or troubleshooting, and whether access can be disabled by default.

    The safest rule is narrow access by design: no vendor access except for documented support needs, no sales or demo use without written permission, no product-development reuse without explicit approval, and no silent access to public-agency data.

    Patch quickly, then verify what happened

    When a vulnerability is already being exploited, the first question is not whether an agency plans to patch. It is whether the exposed system has already been identified, assigned, fixed, and reviewed.

    Public agencies should ask vendors and internal teams the same basic questions: Are we affected? Which systems are exposed? When was the patch applied? Who verified it? Were logs reviewed? Were accounts created, changed, or abused? Were credentials rotated? Were dependent systems affected? Were backups tested? Were users or partner agencies notified?

    Fast patching matters, but patching alone is not the whole safeguard. A patched system may still have compromised accounts, altered settings, copied data, or persistence mechanisms left behind. The fix should include proof, log review, and a short written record of what changed.

    Delete old sensitive data before it becomes breach fuel

    The best breach response starts before the breach. Collect less data, keep it for less time, separate sensitive records, and delete what no longer serves a clear public purpose.

    Old records become dangerous when they remain searchable after their original purpose has passed. A school platform, police system, vendor database, health app, personnel file, grant system, or public-records archive can become a breach problem years later if sensitive data is kept by default.

    Retention limits should be treated as security controls. If data is no longer needed, no longer legally required, and no longer serving the public purpose for which it was collected, deletion is not a loss. It is a safeguard.

    “The Government’s position fails to contend with the seismic shifts in digital technology that made possible the tracking of not only Carpenter’s location but also everyone else’s, not for a short period but for years and years.”

    — Chief Justice John G. Roberts Jr., majority opinion, Carpenter v. United States (2018)

    Governance Safeguards

    Governance Safeguards

    The strongest safeguards are built before sensitive data becomes too useful to give up.

    Keep AI away from the keys

    AI systems should not be allowed to control account recovery, permissions, identity verification, enforcement decisions, or high-impact access changes without hard limits.

    A support bot that can grant account access is not just a chatbot. It is an access-control system. An AI tool that can change permissions, summarize evidence, draft reports, flag people, alter workflows, or trigger decisions needs more than a prompt box and a terms-of-service page.

    Useful safeguards include human review for high-impact actions, least-privilege access, separate logs for AI actions, rollback plans, prompt-injection testing, escalation rules, and clear bans on using AI outputs as the sole basis for account recovery, discipline, arrest, eligibility, denial of service, or enforcement action.

    Do not make identity the price of ordinary access

    Age checks, phone-ID rules, Real ID requirements, social-media restrictions, account verification systems, and anti-fraud tools can all serve legitimate goals. But they can also make ordinary life depend on persistent identity trails.

    Policymakers should ask whether a system verifies what it actually needs to know, or whether it collects more identity than necessary. A service may need to know that a person is old enough, eligible, or authorized. It may not need to store a copy of a government ID, keep a reusable identity profile, or link lawful activity across platforms.

    Good identity policy should include privacy-preserving alternatives, data minimization, short retention, vendor limits, appeal rights, and options for people without stable documents, stable addresses, safe disclosure conditions, or conventional ID access.

    Ask what security features are actually enabled

    Security should not depend on assumptions. If a product advertises encryption, isolation, logging, retention controls, access limits, or audit tools, public agencies should ask whether those protections are actually enabled in the version they are buying.

    Officials should also ask whether features depend on a higher-priced tier, firmware setting, license term, subscription level, cloud configuration, or optional module. If a vendor removes, disables, downgrades, or paywalls a security feature, customers should receive clear notice before they rely on a protection that may no longer exist.

    The practical question is not “does this product have security?” It is: which protections are active, who controls them, what changes can disable them, and how will we know?

    Make public reporting routine, not exceptional

    Oversight works better when public reporting is scheduled before controversy begins. The La Pine data-center transparency petition is a local example: large data infrastructure raises questions about power, water, generators, noise, and public accountability even when it is not a surveillance system by itself.

    The same reporting habit should apply to sensitive technology systems: publish enough information to evaluate system purpose, data collected, vendor access, retention period, outside-agency access, number of searches, number of hits, false matches, corrective actions, policy violations, and renewal dates.

    Use a pre-approval checklist before systems go live

    Before launch, renewal, expansion, or feature activation, officials should be able to answer basic questions: What data is collected? Who can access it? What outside agencies can search it? What can the vendor see? How long is data retained? What requires a warrant, case number, or documented purpose? What audit logs exist? Who reviews the logs? What is reported publicly?

    A checklist is not bureaucracy for its own sake. It is a way to keep small procurement decisions from quietly becoming large public-governance decisions after data is already flowing.

    Bottom line

    The strongest safeguard this week is visible control over search power.

    Whether the system is Section 702, ALPR, cyber incident response, identity verification, AI account recovery, surveillance pricing, or a police-tech platform, the public needs the same basic answers: who can search, why they can search, what authority applies, how long data is kept, whether vendors can access it, whether identity checks are truly necessary, and whether misuse can be proven after the fact.

    Collect less. Connect less. Search less. Retain less. Log every exception. Make vendor access visible. Require authority before sensitive searches. Build privacy into the system before the data becomes too useful to give up.

  • Signals & Safeguards — Issue 13

    Signals & Safeguards

    Issue 13 • Wednesday, June 10, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    – Section 702 is nearing another deadline, but the fight is really about searches, warrants, and control of a powerful intelligence database.

    – The Supreme Court’s FCC decision over telecom location-data fines is a reminder that metadata is sensitive data.

    – Breach victims are often notified late, after exposed data may already be circulating.

    – Facial recognition is moving toward ordinary consumer devices, from doorbells to smart glasses.

    – Age gates, Axon updates, AI-tool compromises, campus cameras, and ad-tech data all ask who can turn sensitive data into a searchable system.


    Section 702 is now a warrant fight and a governance fight

    Section 702 of the Foreign Intelligence Surveillance Act is aimed at foreign intelligence targets outside the United States. But Americans’ communications can be swept in when they communicate with those targets, and federal agencies can later search that data without a warrant.

    That is why civil-liberties groups have focused on the search stage, not only the collection stage. The Brennan Center explains the warrant fight around U.S.-person queries; the ACLU is urging Congress to require stronger protections; and Cato warns that AI could raise the stakes by helping generate or launder investigative predicates.

    As of June 9, 2026, Reuters reports that Section 702 is set to expire June 12, after multiple short-term extensions and continuing disagreement over privacy protections. The plain-English issue is simple: a foreign-intelligence database becomes more powerful later if searches are too easy, too broad, or too weakly reviewed.

    Why this matters in Bend: Federal surveillance law shapes the privacy environment local governments operate in. If broad collection, weak search limits, and after-the-fact oversight become normal federally, local officials should be careful not to import the same logic into city technology, public-safety tools, vendor contracts, or data-sharing agreements.


    Metadata is sensitive data

    The Supreme Court’s decision siding with the FCC in the wireless-carrier fine dispute is a useful reminder that location data is not harmless just because it is metadata. Reuters reports that the case involved FCC fines connected to carriers’ sharing of customer location data, including fines of $57 million for AT&T and nearly $47 million for Verizon, with additional fines for T-Mobile and Sprint.

    Location metadata can reveal where people live, work, worship, seek care, gather, travel, and protest. The same principle applies beyond telecoms: license-plate scans, ad-tech location trails, smart-device records, voter files, school logs, and vendor-access records can all become sensitive when tied to real people.

    “Metadata absolutely tells you everything about somebody’s life. If you have enough metadata, you don’t really need content.”

    — Stewart Baker, former NSA General Counsel

    Why this matters for Oregonians: Oregon privacy policy should treat metadata as sensitive data, especially when public agencies, vendors, telecoms, or data brokers can connect it to names, addresses, devices, vehicles, or places.


    Breach victims are often the last to know

    A breach is not the only harm. Delayed notice can become a second harm. Troy Hunt’s “1000 data breaches later” essay argues that disclosure lag has grown worse even as breach databases, credential stuffing, identity fraud, and public leak sites have made exposed data more immediately useful to attackers.

    The people whose data was exposed may be the last ones to know, even when the data is already searchable, traded, or used in phishing. The safeguard lesson is direct: people cannot protect themselves from exposed data they are not told about.

    Why this matters for Oregonians: A delayed breach notice can leave residents exposed while stolen data is already circulating. Public agencies and vendors should disclose what happened, what data was affected, when they knew, and what people can actually do next.


    Meta smart glasses and Ring show facial recognition moving into ordinary devices

    Facial recognition is no longer only a government-system issue. WIRED reported that Meta removed face-recognition components from its Meta AI smart-glasses companion app after WIRED found unreleased face-recognition code. WIRED reported that the system was not publicly activated. The warning is that consumer wearables are moving toward biometric capability before clear public rules are ready.

    Reuters separately reports that Amazon’s Ring has been sued in a proposed class action alleging that its “Familiar Faces” feature unlawfully collected and stored face images without consent. That claim is an allegation in a lawsuit, not a court finding. Taken together, smart glasses and doorbells show how biometric infrastructure can enter everyday life through private devices as well as public contracts.

    Why this matters in Bend: Surveillance can enter a community through private devices as well as public contracts. Doorbells, smart glasses, storefront cameras, and platform features can create biometric data trails even when City Council never votes on a camera system.


    Warning Signals

    Warning Signals

    These items point toward where surveillance systems, identity infrastructure, public-safety platforms, and data governance may be heading next.

    Age gates are becoming identity gates

    Child safety is a legitimate policy goal. But the design of age-verification systems matters. EFF warns that age gates are spreading globally and can pressure people to prove age or identity before accessing ordinary online services. The risk is not only inconvenience. Broad age verification can normalize government-ID checks, biometric scans, wallet credentials, operating-system-level age signals, or private verification vendors as the price of ordinary internet access.

    Why this matters for Oregonians: Oregon can pursue child-safety goals without turning ordinary internet access into an identity-check system. Future proposals should minimize data collection, avoid government-ID retention, protect lawful anonymous speech, limit vendor reuse, and require independent audits.


    Axon Watch: public-safety platforms keep expanding

    Axon should not be understood only as body cameras, Tasers, or ALPR. Its May 2026 release notes and June Records and Standards release notes show continuing software and records-system updates. Echodyne also announced a public-safety radar partnership with Axon on May 27, saying the partnership supports safer and more scalable drone operations across law enforcement, homeland security, and Drone as First Responder programs.

    A feature appearing in release notes or a vendor ecosystem does not mean it has been deployed locally. But it does show the direction of the platform public agencies may be buying into.

    Why this matters in Bend: Bend and Deschutes County are already making decisions inside the Axon ecosystem. Officials should distinguish between the tools being purchased today and the platform capabilities that may become available later through updates, integrations, AI features, drones, radar, records systems, or real-time operations.


    AI developer tools are becoming supply-chain targets

    TechCrunch reports that Microsoft shut down dozens of GitHub-hosted open-source projects after hackers apparently injected password-stealing malware into tools used with AI development apps, including Claude Code, Gemini CLI, and VS Code. AI development tools can have access to local files, credentials, API keys, source code, and developer workflows. A trusted tool can become a high-leverage attack path if it is compromised.


    Campus safety systems are becoming campus surveillance systems

    CBS8 reports that more than 1,300 AI-enabled cameras have been installed across San Diego State University. Times of San Diego, republishing Daily Aztec reporting, says cameras are placed in hallways, entryways, common areas, and dorm buildings. Public institutions may deploy AI-enabled surveillance under a safety rationale before students, staff, or the public fully understand scope, capabilities, retention rules, access permissions, or oversight.

    Why this matters for Oregonians: Public schools, colleges, and universities should not treat AI-enabled camera systems as ordinary safety equipment. Officials should disclose capabilities, camera-location policies, retention rules, access permissions, vendor access, audit logs, and whether footage can be searched or shared outside the institution.


    Sanctuary policy only works if data channels cannot route around it

    Immigration enforcement does not depend only on government-owned databases. WIRED reported earlier this year that ICE issued a request for information about commercial “Big Data and Ad Tech” products that could support investigations, including tools that may involve location data from advertising technology. A formal state or local policy can be weakened if enforcement agencies route around it through commercial data, shared databases, vendors, ALPR networks, or ad-tech data.

    Why this matters for Oregonians: Oregon’s sanctuary protections are only as strong as the database permissions, vendor contracts, and commercial-data channels behind them. If enforcement can route around state limits through ad-tech data, ALPR systems, shared databases, or brokers, policy protection may fail at the technical layer.


    Public memory is becoming harder to preserve

    Techdirt, citing Nieman Lab, reports that more than 340 local news sites are now limiting the Internet Archive’s ability to preserve their stories. Publisher concerns about AI scraping are real, but the public-interest cost is also real: local accountability depends on records people can find, compare, cite, and revisit after a contract, policy, meeting, or public-safety decision fades from the front page.

    For surveillance oversight, archiving is not nostalgia. It is evidence. If local reporting, meeting records, procurement pages, and public explanations disappear or become hard to retrieve, residents and officials lose the timeline needed to evaluate promises, changes, renewals, and vendor claims.


    Data-center opposition is becoming a surveillance issue

    Communities may oppose AI data centers for ordinary civic reasons: electricity, water, land use, rates, noise, transparency, and local control. The warning signal is what happens when lawful opposition is pulled into threat-intelligence, extremism, or security-monitoring frames without clear boundaries.

    Public agencies should distinguish credible threats from lawful civic participation. Protest, petitions, testimony, public-records requests, and neighborhood organizing should not become surveillance triggers merely because the underlying project is politically or economically important.


    Direction of travel

    This week’s Signals point toward one pattern: identity, access, and memory are becoming control layers. Age checks, Axon platform features, AI development tools, campus cameras, ad-tech data, smart glasses, doorbells, telecom location records, and local archives all shape who can be identified, searched, remembered, or forgotten.


    Safeguards

    Safeguards

    A safeguards page works best when it is practical: less data, cleaner boundaries, stronger access controls, and fewer shortcuts.

    Require breach notice people can act on

    Breach notice should not be vague, delayed, or written mainly to reduce institutional embarrassment. People need facts they can use: when the organization first learned of the incident; what categories of data were affected; whether data was accessed, copied, sold, posted, or merely exposed; what systems were involved; what users should do next; what the organization has already done; whether law enforcement or regulators were notified; and where the public can find updates.

    This applies to public agencies, schools, utilities, healthcare providers, nonprofits, civic groups, and vendors holding resident data.


    Patch what attackers are already exploiting

    CISA’s Known Exploited Vulnerabilities catalog exists because some vulnerabilities are not theoretical. They are already being used. CISA added one known-exploited vulnerability on June 5 and two more on June 8. Public officials should ask vendors and internal IT teams whether any systems touching public records, evidence, payments, schools, utilities, emergency services, or public-facing portals are exposed to KEV-listed vulnerabilities.

    • Are we affected?
    • When was it patched?
    • Were logs reviewed after patching?
    • Were admin accounts created, changed, or accessed?
    • Were customers or partner agencies notified?
    • What systems depend on this vendor or platform?
    • What is the backup plan if access has to be shut down?

    Protect recovery keys, backup codes, and high-risk credentials

    TechCrunch reports that hackers are targeting Signal users’ backups in a phishing campaign. The important point is not that Signal’s encryption was broken. The risk is social engineering: tricking people into surrendering backup or recovery material.

    Recovery keys, backup codes, password-manager secrets, API keys, admin tokens, and emergency access codes should be treated as high-risk secrets. Secure services should not proactively ask users to send them. Good safeguards include phishing-resistant MFA, hardware security keys for high-risk accounts, password managers with strong recovery practices, offline backup codes, and clear rules for how staff verify security requests.


    Treat school platforms as civic infrastructure

    Federal Student Aid has posted a technology-security alert for an ongoing cybersecurity incident involving Canvas, updated May 29. Reuters and AP reported in May that Instructure reached an agreement with the ShinyHunters hacking group after the Canvas incident. Instructure said affected data included names, email addresses, student ID numbers, and messages, but not passwords, birth dates, government IDs, or financial data.

    Schools should treat learning-management systems as civic infrastructure, not just classroom software. These systems can hold assignments, grades, accommodations, messages, family contacts, student IDs, staff information, and records students need during high-pressure periods.

    Why this matters for Oregonians: Districts, colleges, and universities should require incident timelines, breach-notice rules, access logs, data minimization, vendor limits, phishing-response plans, and continuity plans for assignments and records.


    Public-safety grants need technology and data guardrails

    The Justice Department announced the Model Cities Initiative on June 3, describing it as a whole-of-city approach directing nearly $300 million in federal funding toward selected cities. The safeguard is not to reject every public-safety grant. The safeguard is to read the conditions before a community accepts the money.

    Before accepting funds, officials should disclose required technology tools, data-sharing conditions, federal task-force participation, ALPR, facial-recognition, drone, AI, or real-time operations components, reporting obligations, vendor platform commitments, audit logs, retention rules, and whether data can be searched or shared outside the local agency.

    Why this matters in Bend: Public-safety funding should not quietly commit the community to surveillance tools, federal data-sharing expectations, vendor platforms, or long-term reporting obligations. Conditions should be visible before acceptance, not discovered after systems are already in motion.


    Before AI touches public systems, set the purpose limits

    EFF reports that Dr. Matthew Guariglia testified to a House Homeland Security subcommittee that governments should not adopt powerful AI technologies without strong safeguards to protect constitutional rights. For this safeguards page, the practical rule is simple: do not connect AI to records, cameras, case files, benefits systems, schools, evidence platforms, or enforcement workflows until the purpose, data access, human review, error process, logs, retention, and vendor-use limits are clear.

    “At this level the question is not how do we rein in AI, it’s how do we rein in the agencies that would unleash AI on the American public.”

    — Dr. Matthew Guariglia, Electronic Frontier Foundation


    Governance Safeguards

    Governance Safeguards

    The strongest safeguards are built before sensitive data becomes too useful to give up.

    The question is no longer whether sensitive data exists. It does. The question is whether public institutions can prove who accessed it, why, and under what enforceable limits.

    Treat metadata as sensitive data

    Metadata can describe a life without quoting a message. Location pings, plate scans, search logs, device identifiers, camera detections, call records, badge swipes, student-platform logs, and vendor access records can reveal patterns of movement, association, belief, health, work, school, and protest.

    For Oregon policymakers, the key move is to stop treating metadata as harmless simply because it is not message content. Useful safeguards include purpose limits, shorter retention, access logs, case-number requirements, warrant requirements where appropriate, vendor-use restrictions, and public reporting.

    Require audit logs before launch, renewal, or expansion

    Do not approve surveillance or sensitive-data systems that cannot answer basic questions: who searched; what they searched; why they searched; what they accessed; whether the result was shared; whether the search was tied to a case number, warrant, emergency, or documented purpose; and whether an outside reviewer can verify the answer.

    A system without usable audit logs does not merely have a technical gap. It has an accountability gap.

    Why this matters in Bend: Audit logs are the difference between oversight and reassurance. For ALPR, Axon tools, evidence systems, AI features, drones, records platforms, or vendor dashboards, officials should be able to verify who searched, why they searched, what they accessed, and whether the result was shared.

    Limit vendor, outside-agency, federal, and immigration-enforcement access by default

    Access should be narrow by default and expanded only with clear legal authority, documented purpose, logs, retention limits, and review. That means no outside-agency access unless explicitly approved; no vendor access except for documented support needs; no sales, demo, training, or product-development use without written permission; no immigration-enforcement access unless legally required; no federal or out-of-state access without a clear legal basis and logged review; and no data sharing without purpose fields, retention limits, and periodic public reporting.

    Why this matters for Oregonians: State and local privacy rules can be undermined if outside agencies, federal users, or vendors retain broad access by default. Access limits should be technical, contractual, logged, and enforceable – not merely aspirational.

    Make public reporting routine, not exceptional

    Oversight works better when public reporting is scheduled before controversy begins. Agencies should publish enough information to evaluate sensitive systems without exposing individual residents’ raw data.

    Public reporting should include: system purpose, data collected, vendor, retention period, outside-agency access, vendor access, number of searches, number of hits, false matches or complaints, policy violations, corrective action, and renewal dates.

    That is especially important for systems that can expand through software updates, new integrations, agency-to-agency sharing, or vendor platform changes. A public report should show whether a system is still doing what officials said it would do.

    Use a pre-approval checklist before sensitive systems go live

    Before launch, renewal, expansion, or feature activation, officials should be able to answer: What data is collected? Who can access it? What outside agencies can search it? What can the vendor see? How long is data retained? What requires a warrant, case number, or documented purpose? What audit logs exist? Who reviews the logs? What is reported publicly? What happens if the system is misused?

    Before approval, renewal, or feature activation, the public should be able to see the purpose, the data, the access rules, the logs, the retention period, and the consequences for misuse.

    A simple governance test for sensitive systems

    Bottom line

    The best safeguards this week are upstream safeguards: collect less, connect less, search less, retain less, and log every exception. Whether the system is Section 702, telecom location data, ALPR, Axon software, school platforms, public-safety grants, or AI, the oversight problem is the same once data becomes searchable.

    “Sensitive data should not become useful faster than oversight becomes enforceable.”

    Public trust depends on private protections.

  • Signals & Safeguards — Issue 12: ALPR Oversight, Access Pathways, and Practical Privacy Safeguards

    Issue 12 • Wednesday, June 3, 2026

    Signals & Safeguards newsletter masthead

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • ALPR oversight reached Congress, but the first sweeping federal restriction failed in committee.
    • EFF’s new mission-creep examples show why purpose limits need technical enforcement, not just policy language.
    • Vendor platforms are expanding after purchase, making release notes part of the oversight record.
    • New location, platform, and device-signal examples show surveillance moving through access pathways, not just cameras.

    ALPR oversight reached Congress, but the first sweeping restriction failed

    Automated license plate readers are no longer only a city-contract or police-policy issue. This month, ALPR oversight reached Congress. WIRED reported that Representatives Scott Perry and Jesús “Chuy” García introduced a bipartisan amendment to a federal highway bill that would have barred recipients of Title 23 federal highway funds from using ALPRs for any purpose other than tolling. ACLU and partner groups urged the Committee to support the amendment; EPIC joined a coalition pressing the same case. Demand Progress later reported that the committee rejected it.

    Why it matters for public officials: Congress did not settle the question. Local and state governments still have to decide what rules apply before ALPR systems are purchased, renewed, expanded, or connected to larger networks.


    Mission creep shows why purpose limits matter

    EFF’s latest ALPR analysis documents the practical reason purpose limits matter: ALPR networks have been used for school residency verification, employment background checks, and noise or loud-music complaints — uses that do not feature in most public debates over whether to deploy plate readers. Once a location database exists, more users and more purposes will try to reach it. If the rules are vague, a system’s actual use can drift far beyond the original public explanation.

    Why it matters for public officials: Purpose limits should be written before deployment and enforced technically. A policy that says “serious investigations only” is weak if the software still permits broad searches for administrative, civil, or low-level purposes.


    Bend and Oregon show why policy must match permissions

    Bend and Oregon remain useful case studies, but the lesson is broader than either jurisdiction. Earlier reporting from The Source Weekly found that ICE, CBP, and Homeland Security Investigations queried Bend Police Department Flock Safety data 279 times in the first three weeks after the cameras went live. Separately, OPB reported that a lawsuit alleges Oregon State Police allowed federal immigration authorities to query Oregonians’ data through shared law-enforcement databases for years, despite Oregon’s sanctuary laws. OSP denies wrongdoing. The Oregon Capital Chronicle reported the same allegations.

    Those examples should not be repeated as old news. They should be treated as a practical reminder: a privacy rule only works if the database permissions, access settings, and audit logs match the rule.

    Why it matters for Bend and Deschutes County: Written policy matters, but it is only one layer. Contract terms, vendor settings, sharing permissions, system configuration, audit logs, and public reports all have to point in the same direction.

    “If it is law, it will be found in our books. If it is not to be found there, it is not law.”
    — Lord Camden, Entick v. Carrington (1765)


    Policy 428 appears stronger, but oversight still needs proof

    Bend Police Department’s updated Policy 428 appears to add stronger ALPR safeguards, including shorter retention for non-investigatory plate data, search logging, audit and reporting requirements, prohibited-use language, and vendor-contract requirements. That matters. It is a real improvement over a weaker policy baseline.

    But a policy is not the whole oversight system. The next questions are whether the publicly posted version is final, whether any contract or add-on incorporates the same limits, whether system settings enforce them, and whether audit reports will be usable enough for Council and residents.

    Why it matters for public officials: A policy states the rule. A contract binds the vendor. A system configuration prevents improper access. Audit logs show what happened. Public reports let elected officials verify the result. All five layers matter — and they should align before deployment, not after.

    Shared pattern

    The strongest stories on this page point in the same direction: surveillance power expands through access pathways. A local camera, a vendor database, a federal search request, a shared records system, or a platform setting can each change who can reach sensitive data. Oversight has to follow the path the data actually takes.


    Commercial location data is a national-security problem

    Reuters reported that U.S. military personnel deployed to war zones have reportedly been targeted using commercially available location data, with lawmakers warning such data can reveal troop movements and patterns of life.

    The reminder applies at every level: data collected for advertising can become useful for intelligence, enforcement, stalking, coercion, or political pressure. Public policy should treat commercial location data as sensitive infrastructure, not a marketing issue.


    Online speech, anonymity, and age checks are becoming enforcement surfaces

    Bloomberg Law reported that the Justice Department used grand-jury subpoenas to seek identifying and financial information from Reddit and X in investigations involving anonymous criticism of ICE tactics. The Verge summarized the reporting in similar terms.

    Age verification belongs in the same warning pattern. Child safety online is a legitimate policy goal, but systems that require identity documents, facial scans, third-party verification, or persistent proof of age can reduce the ability to read, speak, browse, or associate online without creating an identity trail. EFF has warned that age-check systems can become privacy infrastructure for everyone, not only children.

    The safe framing is narrow but important: when platform records, financial information, age checks, and identity-verification vendors can all be used to identify anonymous users, data minimization and legal-process rules become free-speech safeguards. Lawmakers should separate child-safety goals from systems that normalize persistent identity checks for ordinary lawful speech.

    “The makers of our Constitution undertook to secure conditions favorable to the pursuit of happiness. They conferred, as against the Government, the right to be let alone.”
    — Justice Louis Brandeis, dissenting in Olmstead v. United States (1928)


    Warning Signals

    These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.

    Warning Signals section header

    Axon Watch: release notes are part of the oversight record

    Police-technology platforms do not remain frozen after purchase. Axon RMS June 2026 release notes include Records and Standards updates involving form rollback logging, validation, access-profile configuration, and Axon DataStore notes about physical-table read access for replication accounts.

    That is not a scandal or a breach. It is a governance signal. Product updates can affect records workflows, database replication, audit visibility, search behavior, and who can reach what inside a public-safety records environment.

    Oversight question: Does the agency provide elected officials with a periodic platform change log covering major software releases, enabled features, disabled features, database-access changes, audit-log changes, AI tools, and new integrations?


    LPR systems are moving toward broader signal correlation

    Leonardo’s ELSAG SignalTrace product shows where license-plate-reader ecosystems may be heading. The company describes a system that can collect electronic signals from phones, smartwatches, fitness trackers, RFID tags, Bluetooth, Wi-Fi, and vehicle components, then correlate those patterns with LPR data. Leonardo says the tool does not decrypt device content — but movement patterns can be inferred from the devices people carry, not just the plates on their vehicles.

    Why officials should watch it: A procurement described as “license plate reader” today may sit inside a larger vendor ecosystem tomorrow. Public review should cover roadmaps, integrations, and adjacent capabilities, not only the first device installed.


    Drone-first-responder programs are becoming routine infrastructure

    Drone-first-responder programs continue moving from special-use tools toward routine 911 response. San Francisco Police Department now exceeds 600 drone flights per month, Dallas launched a drone-first-responder program tied to a larger public-safety technology platform, and Coral Springs approved an Axon-linked DFR expansion through an existing agreement. Meanwhile, Ohio is debating warrant and equipment rules.

    Why officials should watch it: Drone programs can normalize faster than governance frameworks. The pilot stage is the best moment to define launch rules, livestream access, retention, evidence use, mutual-aid sharing, audit logs, and public reporting.

    Direction of travel

    This week’s signals point to a broader pattern: public-safety technology is becoming a platform environment. Plate readers can connect to device signals. Evidence systems can connect to records, AI tools, and partner sharing. Commercial location data can become intelligence. Online speech can become legal-process data. Drones can become routine response infrastructure.

    The safeguard question is not only what the tool does on day one. It is what the system can connect to next.

    “As with GPS information, the time-stamped data provides an intimate window into a person’s life, revealing not only his particular movements, but through them his familial, political, professional, religious, and sexual associations.”
    — Chief Justice John Roberts, Carpenter v. United States (2018)


    Safeguards

    Good safeguards usually start with less data and clearer boundaries.

    Safeguards section header

    Define access before deployment, not after the first complaint

    Before any camera, database, drone program, records platform, or evidence system is approved, the governing body should be able to answer in plain language: who can search this data? Can federal agencies reach it directly or indirectly? Can outside agencies search it? Can the vendor see, export, or reuse it? Can partner agencies receive alerts or shared results? If those questions do not have documented answers, the policy is not finished.

    Troy, New York’s model — written limits on immigration and First Amendment searches, nationwide-lookup restrictions, and mandatory audits before cameras stayed live — offers a useful template.


    Make the contract match the policy — and the software match the contract

    A policy manual is not a safeguard if the vendor platform ignores it. Purpose limits should appear in account permissions, sharing settings, role-based access controls, retention configurations, vendor support restrictions, and integration rules. The practical test is simple: if the policy prohibits a use, can the system still do it with two clicks? If yes, the policy needs technical enforcement.

    Axon RMS June 2026 release notes discussing physical-table read access for replication accounts are a reminder that routine product updates can change what a vendor can reach inside a records system — which is why contract language on data access should be reviewed at renewal, not just at procurement.


    Require audit logs that elected officials can actually read

    Audit logs should not be symbolic. Useful logs capture who searched, what agency they represented, what documented purpose they gave, whether a case number or legal process existed, what result was returned, and whether the data was exported or shared. Public audit reporting should protect sensitive investigative details, but it should still give elected officials and residents enough information to evaluate whether the system is being used as promised.


    Keep identity and movement data from becoming permanent trails

    Age-verification systems, account-linking tools, location analytics, ALPR networks, and device-signal systems should minimize data by design. A system built to answer a narrow question — such as whether a user meets an age threshold or whether a vehicle is connected to a specific investigation — should not create a permanent identity or movement trail. Good safeguards include short retention, no secondary use, no vendor reuse for advertising or product development, no unnecessary biometric or government-ID retention, and independent security review.


    Before approval, renewal, or expansion, ask:

    • What data is collected, and what data is deliberately not collected?
    • How long is it retained, and who can search it?
    • Can outside agencies, federal agencies, or immigration-enforcement agencies access it directly or indirectly?
    • What can the vendor see, change, export, or use for support, training, demos, or product development?
    • Are searches logged with user, agency, purpose, case number, result, and sharing activity?
    • Are audit results published in a usable public format?
    • Do the policy, contract, and system configuration require the same safeguards?
    • Who approves new integrations, AI features, sharing settings, or platform expansions?
    • What happens if the vendor changes the product after approval?

    Bottom line: The best safeguards this week are disciplined ones: define access before deployment, make the contract match the policy, make the software enforce the contract, log every search, publish usable audit results, and collect less data than the technology makes possible. Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.

    “What a person knowingly exposes to the public, even in his own home or office, is not a subject of Fourth Amendment protection. But what he seeks to preserve as private, even in an area accessible to the public, may be constitutionally protected.”
    — Justice Potter Stewart, Katz v. United States (1967)


    Signals and Safeguards footer

  • Signals & Safeguards: Issue 10 – ALPR Oversight, Police-Tech Platforms, and Practical Privacy Safeguards

    Issue 10 • Wednesday, May 20, 2026

    Signals & Safeguards newsletter masthead

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    – ALPR oversight is becoming a democracy issue, not just a police-camera issue.

    – Local, private, and federal plate-reader access is turning ordinary movement into searchable infrastructure.

    – Axon’s financials, contracts, and release notes show police technology becoming a changing software-and-data platform.

    – The safeguard question is consistent: who gets access, under what limits, and who can prove misuse?

    ALPR oversight is becoming a democracy issue

    The strongest surveillance story this week is not one camera system by itself. It is the fight over who gets to approve, search, share, and shut down a network once it is already in place.

    In Troy, New York, a dispute over Flock license plate readers escalated after residents objected to cameras installed without meaningful public input, the City Council voted to end the program, and the mayor declared a state of emergency to keep the cameras operating. The fight became larger than Flock: it became a dispute over emergency authority, public consent, and whether elected bodies can still control surveillance systems once public-safety claims are used to preserve them.

    The pattern is appearing elsewhere. In Cleveland and nearby communities, residents and advocates are challenging Flock deployments over privacy, immigration-enforcement access, and uncertainty about who can search the system. In Bend, The Source Weekly reported that federal immigration officials made 279 queries into Bend’s Flock Safety data in the first three weeks after the cameras went live, and Bend Police reportedly did not authorize those searches.

    The federal layer makes the issue sharper. Reporting from 404 Media says the FBI wants to buy nationwide access to license plate reader data. If local and private cameras can become part of a national movement-search network, then approving a few cameras is not only a local equipment decision. It is a decision about whether local vehicle-location data can become searchable far beyond the community that generated it.

    The public-safety case should not be dismissed. ALPRs can help find stolen vehicles, locate suspects, and respond to serious threats. But that is exactly why governance has to come first. A system useful enough to solve crimes is also useful enough to misuse, over-share, or repurpose.

    Why it matters for Bend: Bend has already seen how quickly the question can move from “Should we install cameras?” to “Who searched the data, why, and what did they see?” Bend and Redmond are also working through automated traffic-enforcement systems, which are not the same as ALPRs but raise overlapping questions about vendors, retention, access, audit logs, public notice, error correction, and repurposing.

    The Fourth Amendment line is being tested at the border and at the front door

    Two legal fights point to the same question: when the government intrudes into highly private spaces, do old safeguards still have practical force?

    EFF is urging the Fourth Circuit to require warrants for electronic-device searches at the border. Phones and laptops are not ordinary containers. They hold messages, photos, location trails, health information, financial records, work files, source communications, family details, and years of private life. A border search of a phone can reveal far more than a search of luggage.

    The same principle appears in the home-entry context. Lawfare has criticized DHS’s defense of immigration home entries based on administrative warrants, arguing that an administrative document issued inside the enforcement system is not the same as a judicial warrant signed by a neutral judge. That distinction matters because the home has long received the strongest Fourth Amendment protection.

    The point is not that the government can never search a device, enter a home, or enforce immigration law. The point is that process matters most when the stakes are high. A real warrant requirement forces the government to state facts, define the scope, and persuade a neutral decision-maker before the intrusion happens.

    Why it matters for Bend: federal privacy norms shape the environment local governments operate in. If device searches, home entries, database queries, and surveillance partnerships become easier at the federal level, local officials should be more careful about importing low-friction access into city systems, vendor contracts, and data-sharing agreements.

    Immigration surveillance vendors need verification before deployment

    Immigration enforcement is increasingly tied to vendor systems, mobile access, and large searchable databases. That makes vendor verification a civil-liberties safeguard, not a procurement formality.

    The Lever reported on Edge Ops, an ICE surveillance vendor connected to a system described as mapping immigrants’ routines and locations. The reporting raised basic due-diligence questions about the company’s public claims, executives, clients, and marketing materials. Separately, 404 Media reported that ICE agents have access to a large list of people on their phones through Palantir-linked systems.

    The concern is not only what data exists. It is how easily that data becomes available in the field. Mobile access changes the meaning of a database. If agents can carry searchable identity, address, location, case, or association information on a phone, the public needs to know who can search it, what legal threshold applies, whether searches are logged, whether results can be shared, and how errors are corrected.

    This is the same access problem that appears in ALPR systems. Surveillance oversight is often less about the sensor and more about the database behind it. Who can search? Who can export? Who can share? Who audits? Who can prove misuse?

    Why it matters for Bend: Bend residents’ information may pass through city, county, state, vendor, and federal systems. A privacy rule or sanctuary policy only works if the database permissions behind it match the public promise.

    Shared pattern

    The strongest stories this week point to the same lesson: access is the real policy.

    A camera is not just a camera if its records can be searched by outside agencies. A body camera is not just a body camera if its footage feeds a cloud platform, AI report-writing tools, evidence workflows, and long-term data storage. A phone is not just a device if it contains years of private life. A database is not just a database if field agents can query it from an app. A data center is not just a building if it reshapes local power, water, land-use, and infrastructure decisions.

    The safeguard question is consistent across all of them: who gets access, under what authority, with what limits, with what logs, and with what public ability to review the answer?

    “The liberty of every man is at the mercy of every petty officer.”— James Otis, arguing against writs of assistance (1761)

    Police-tech vendors are becoming public-safety platforms

    Axon is no longer just a TASER and body-camera vendor. Its own Q1 2026 financials show a public-safety platform business built around hardware, software, cloud evidence storage, AI tools, analytics, subscriptions, drones, real-time operations, and long-term agency relationships. Axon reported Q1 2026 revenue of $807 million, up 34% year over year.

    That platform model is showing up in public contracts. Baltimore approved a $153 million Axon agreement for body-worn cameras, TASERs, and other public-safety tools, while some city leaders questioned whether the agreement was the best deal for taxpayers. Savannah approved a 10-year, $27 million Axon agreement. Connecticut State Police rolled out upgraded TASERs, body-worn cameras, AI translation capabilities, VR training, drones, and evidence-management tools as part of a broader modernization package.

    Those examples matter because they show how police technology is becoming a bundle: hardware, cloud storage, evidence systems, report workflows, analytics, AI features, training tools, subscriptions, and future upgrades. The public may hear “body cameras” or “TASERs,” but the contract can also shape data access, retention, search tools, audit logs, and the agency’s ability to leave later.

    Investors have noticed the same shift. Business Insider reported that an Axon pitch at the Sohn conference emphasized AI tools such as automated police-report drafting from body-camera footage. That is a market signal: public-safety data, AI workflows, and subscription platforms are becoming part of the growth story.

    For public officials, procurement is no longer simply “buying a tool.” It can mean entering a long-term platform relationship where today’s contract shapes tomorrow’s data access, integrations, AI features, analytics, storage, and switching costs. That does not make every feature harmful, but it does mean elected oversight has to continue after the purchase vote.

    Why it matters for Bend: Axon-style contracts should be reviewed as evolving governance systems, not static equipment purchases. Council and staff should know which features are enabled, who has administrator access, what data moves into vendor cloud systems, and whether new AI or analytics tools can be added without a fresh public discussion.

    Warning Signals

    These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.

    Signals section header

    Platform Watch: Axon software updates show why oversight cannot stop at purchase

    Axon’s May 2026 Records and Standards release notes show how a police-technology platform can change after a contract is approved. The May 19 rollout touches report writing, embedded photos, Evidence links, search behavior, audit-log display, chain-of-custody records, property labels, mobile notes, and DataStore access controls.

    Some changes may improve clarity or accountability. Axon says users will be able to insert photos directly into report narrative text across both Records and Standards in training environments. The embedded photos appear as thumbnails and link back to the Evidence details page in Axon Evidence.

    The strongest accountability item is DataStore v2 row-level access control. Axon says agencies previously used custom views to share DataStore access while protecting sensitive records such as Internal Affairs files, juvenile records, ongoing investigations, and restricted content. The new preview feature lets administrators exclude rows a user is not authorized to see, but restriction enforcement is off by default and must be enabled by administrators.

    Oversight question: Does the agency provide Council with a quarterly platform change log showing major software releases, enabled features, administrator settings, audit-log exports, DataStore access, vendor access, and any new AI, analytics, evidence, search, or access-control tools?

    Movement data is escaping public categories

    ALPRs are moving from city streets into ordinary consumer spaces. Reporting on Lowe’s and Home Depot shows how retailers can use license plate readers in parking lots for theft prevention and safety. Connecticut lawmakers have moved to restrict some police ALPR sharing, but those rules do not cover private retailers.

    Connected cars raise the same concern from another direction. The Guardian reported that General Motors agreed to pay $12.75 million to settle California claims that it sold drivers’ location and driving-behavior data to data brokers without proper consent. The point is not that cars, stores, or cameras are identical systems. The point is that each can create movement records outside the categories people usually associate with government surveillance.

    Traffic cameras add a local wrinkle. Bend and Redmond are working through automated traffic enforcement. Traffic cameras are not the same as Flock or retail ALPRs, but the governance questions overlap: retention, access, vendor contracts, audit logs, public notice, error correction, and whether data collected for one purpose can later be repurposed.

    Data-center infrastructure is becoming a local consent fight

    Data centers are no longer an abstract technology story. They are becoming local governance questions about power, water, land use, jobs, taxes, infrastructure costs, emergency services, and public trust.

    La Pine residents have raised concerns about a proposed data-center project connected to BoxMiner, and the City of La Pine has published a release summarizing what has come before Council. Central Oregon coverage shows the concern is not only whether a project is legal. It is whether residents understand the long-term costs, commitments, and infrastructure consequences before decisions are effectively locked in.

    National polling suggests this concern is not unique to Central Oregon. Gallup reported broad public opposition to AI data centers in respondents’ local areas. The best framing is not “no data centers.” It is “public-infrastructure decisions need public-infrastructure scrutiny.”

    AI is shortening the distance between flaw and exploit

    Google says it disrupted a hacking operation that used AI to help discover and exploit a previously unknown vulnerability. AP, Reuters, Axios, and The Hacker News all covered versions of the same warning: AI can help attackers move faster from finding a weakness to testing and deploying an exploit.

    The week’s other cybersecurity stories reinforce the same practical lesson. Microsoft patched 138 vulnerabilities. CISA added a newly exploited vulnerability to its Known Exploited Vulnerabilities catalog. A WooCommerce Funnel Builder flaw was reportedly under active exploitation. Krebs reported that a CISA contractor exposed AWS GovCloud credentials in a public GitHub repository.

    The safeguard is boring but urgent: inventory exposed systems, patch actively exploited flaws first, remove unsupported devices, use phishing-resistant MFA, scan code repositories for secrets, rotate exposed credentials quickly, and require vendors to disclose patch and incident timelines.

    “In questions of power, then, let no more be heard of confidence in man, but bind him down from mischief by the chains of the Constitution.”— Thomas Jefferson, Kentucky Resolutions draft (1798)

    Safeguards

    Safeguards works best when they’re practical: less data, cleaner boundaries, stronger access controls, usable audit logs, and fewer shortcuts.

    Safeguards section header

    Require public rules before deployment or emergency continuation

    Camera systems, ALPR networks, drones, ShotSpotter-style tools, and police-tech platforms should not go live first and receive rules later.

    Public rules should answer basic questions before deployment: what data is collected, how long it is retained, who can search it, whether outside agencies can access it, whether federal or immigration-enforcement access is allowed, whether vendor employees can access it, whether searches require case numbers or documented purposes, whether audit logs are exportable, and how misuse is punished.

    Emergency authority deserves special care. If an emergency declaration is used to preserve or expand a surveillance system after ordinary political approval breaks down, the declaration should be narrow, time-limited, publicly justified, and subject to prompt council review.

    Treat police-tech contracts as governance documents

    A police-technology contract is not just a purchase order. It can define data access, AI features, evidence storage, audit logs, vendor permissions, integrations, renewal leverage, and exit costs for years.

    Before approving or renewing a platform contract, public officials should ask what the contract makes possible later. What AI tools can be added? Where is the data stored? Who can access it? Can the vendor use agency data for training, product development, support, demos, or analytics? What outside agencies can search the system? What records are retained after termination? Can the agency export complete audit logs and evidence records if it leaves?

    Require quarterly platform change logs

    For major police-tech and public-data systems, agencies should provide Council with a short quarterly change log covering major software releases, enabled or deferred features, AI or analytics tools, search changes, evidence-workflow changes, access-control changes, administrator roles, vendor access, DataStore or reporting access, audit-log export capability, retention changes, and new sharing relationships.

    This is not anti-technology. It is basic oversight for systems that do not stay frozen after purchase.

    Make warrants and notice real

    A warrant requirement only works if the warrant process is real. Courts need specific facts, narrow scope, and neutral review before high-intrusion searches. That matters for border-device searches, home entries, geofence searches, cloud records, account data, and sensitive databases.

    Notice also matters. H.R.6048, the NDO Fairness Act, is worth tracking because people cannot challenge improper electronic searches if they never learn the search happened. Delayed notice may be justified in some investigations, but secrecy should be narrow, time-limited, and based on specific facts.

    Treat movement and biometric data as high-risk data

    Vehicle telematics, retail ALPRs, hotel reservations, phone location, connected devices, school platforms, and traffic-camera systems can reveal where people live, work, worship, seek care, shop, protest, attend school, or travel. Biometric data raises even greater stakes because faces, fingerprints, and palm prints cannot be reset like passwords.

    The NYC Health + Hospitals breach is a reminder that biometric and medical data create permanent risk when exposed. Public agencies and vendors should collect less biometric data, store it separately when collection is necessary, encrypt it, limit access, shorten retention, document every search, and provide clear breach notice and deletion rules.

    Judge privacy bills by what they prevent, not what they promise

    A weak privacy bill can give people familiar rights – access, correction, deletion, portability, or opt-outs – while still allowing broad data collection, weak default protections, preemption of stronger state laws, limited enforcement, or loopholes for data brokers and sensitive data. A serious privacy law should reduce unnecessary collection, preserve stronger state protections, regulate data brokers, protect sensitive data by default, create usable deletion and correction processes, and provide real enforcement.

    Bottom line

    The best safeguards this week are not exotic. They are the boring controls that make powerful systems governable: public rules before deployment, narrow access, clear warrants, meaningful notice, exportable audit logs, short retention, vendor verification, platform change logs, data minimization, and fast patching. Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.

    “No man is allowed to be a judge in his own cause, because his interest would certainly bias his judgment, and, not improbably, corrupt his integrity.”— James Madison, Federalist No. 10 (1787)

  • Signals & Safeguards – Issue 9

    Issue 9 • Wednesday, May 13, 2026

    Signals & Safeguards newsletter masthead

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • Bend’s Flock experience shows why outside access and audit logs are not technical details. They are the oversight system.
    • Oregon’s sanctuary-law lawsuit shows that privacy rules must be enforceable at the database level, not just written into policy.
    • Location data, DMV records, platform data, and biometrics are becoming immigration-enforcement inputs.
    • Courts and lawmakers are beginning to test whether digital searches need stronger limits.

    Bend’s Flock data shows why audit logs are not optional

    The strongest local surveillance story this week is not hypothetical. According to The Source Weekly, federal immigration officials made 279 queries into Bend’s Flock Safety data in the first three weeks after the cameras went live. Bend Police did not authorize those searches, and the reporting says it was unclear what, if any, data may have been retrieved.

    That is the core governance problem. A surveillance system can be installed for one stated purpose, then become useful to agencies, vendors, or outside users who were not central to the original public debate. If officials cannot later answer who searched the system, why they searched it, what they saw, and whether the results were shared, then the public is being asked to trust a system that cannot be independently verified.

    This does not require assuming bad faith by local officials. It shows why good-faith intentions are not enough. Access controls, audit logs, outside-agency limits, vendor-access limits, and public reporting have to exist before a system goes live.

    Why it matters for Bend: Bend’s own experience shows that surveillance oversight cannot stop at approval. Councilors and staff need to know who can search local systems, what outside agencies can access, what vendors can see, and whether every search leaves a usable record.

    Oregon’s sanctuary-law fight is also a database-access fight

    The Bend Flock story now sits inside a larger Oregon data-sharing dispute. OPB reports that a lawsuit filed in Multnomah County Circuit Court alleges Oregon State Police allowed federal immigration authorities to access Oregonians’ data through shared law-enforcement databases for years, despite Oregon’s sanctuary laws. OSP denies wrongdoing.

    The Source Weekly reports that the complaint alleges federal immigration authorities queried state-run data about Oregonians 1.4 million times between February 2025 and February 2026, an average of 3,835 queries each day.

    The important lesson is practical: a sanctuary policy is only as strong as the database permissions behind it. If an agency is legally barred from using data for immigration enforcement, the system should not rely on informal restraint. It should have technical controls that prevent improper access, audit logs that expose improper use, and consequences when policy and practice diverge.

    Oregon lawmakers have already started moving in that direction. SB 1587, effective June 5, prohibits public bodies from disclosing personally identifiable information to a data broker unless the broker attests that the information will not be sold or transferred for federal immigration-law enforcement, with exceptions.

    Why it matters for Bend: Bend residents’ information may pass through city, county, state, vendor, and law-enforcement systems. A sanctuary policy or privacy rule only protects people if the underlying databases actually enforce it through permissions, purpose limits, and audit logs.

    “You must first enable the government to control the governed; and in the next place oblige it to control itself.”
    — James Madison, The Federalist No. 51 (1788)

    Location data is sensitive even when someone buys it

    Immigration enforcement is not limited to government-owned databases. Reporting on DHS, PenLink, and commercial location tools fits a broader pattern: agencies can increasingly rely on vendors, data brokers, and analytics platforms to locate, identify, or investigate people without collecting the raw data themselves.

    That is why the FTC’s proposed order against Kochava matters. The FTC says it will prohibit Kochava and a subsidiary from selling, sharing, or disclosing sensitive location data without consumers’ affirmative express consent, after alleging that the company sold location data from hundreds of millions of mobile devices.

    California’s DMV story shows the same concern from the government-records side. CalMatters reports that California is preparing to share detailed driver’s-license information with a national motor-vehicle database, including information affecting more than 1 million unauthorized immigrants with California licenses.

    The shared pattern is simple: data collected for one purpose can become useful for another. Driver records, location trails, license plates, account data, and public-benefits records may all begin as administrative information. Once connected, queried, sold, or shared, they can become enforcement infrastructure.

    Why it matters for Bend: Local governments increasingly depend on vendors and data systems they do not fully control. If commercially available location or identity data can be bought, searched, or combined with public records, then procurement and contract language become privacy safeguards.

    Geofence warrants show why proximity is not suspicion

    Courts are beginning to draw clearer lines around location searches. The Minnesota Supreme Court ruled that Google geofence data used to identify a murder suspect was unconstitutional, reversed a second-degree murder conviction, and said law enforcement needs a warrant to obtain private cellphone information from Google.

    A geofence search works backward. Instead of starting with a suspect and seeking evidence about that person, investigators ask for information about devices near a place during a certain time window, then narrow the list. That can be useful in investigations, but it also risks treating ordinary presence near a location as a reason to be pulled into a police search.

    The same concern is now before the U.S. Supreme Court in Chatrie v. United States, which asks how the Fourth Amendment applies when police use geofence warrants to identify people by location rather than by individualized suspicion.

    Why it matters for Bend: The same principle applies locally: people should not become investigative leads merely because a phone, plate, or device was near a place at a particular time. Local policy can help prevent broad searches from becoming routine before courts settle every boundary.

    Shared pattern

    The strongest stories this week point in one direction: access is the story. Who can search Bend’s Flock data? Who can query Oregon driver or criminal records? Who can buy or analyze location data? Who can receive DMV information? Who can obtain platform data? Who can turn proximity, protest activity, or routine civic records into an investigative lead?

    Privacy safeguards fail when access is undefined, unlogged, or routed through systems the public cannot see.

    “The price of lawful public dissent must not be a dread of subjection to an unchecked surveillance power.”
    — Justice Lewis F. Powell Jr., United States v. U.S. District Court (Keith), 407 U.S. 297 (1972)


    Warning Signals

    These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.

    Signals section header

    Vendor access is part of surveillance oversight

    404 Media reported on a Flock-related story involving camera access at a children’s gymnastics center for a sales pitch. The larger lesson is that surveillance oversight cannot focus only on police use. Vendor access can be just as important.

    If a vendor can access camera feeds, system data, search tools, customer dashboards, support logs, demos, or training environments, contracts should state exactly what employees can access, for what purpose, how access is logged, whether data can be used for sales or product development, and whether customers or the public are notified.

    Police-tech vendors are becoming platform companies

    Axon reported Q1 2026 revenue of $807 million, up 34% year over year, and highlighted growth across software, connected devices, AI products, counter-drone tools, real-time operations, body cameras, and TASER products.

    That is not just an earnings story. It is a market signal. Public-safety technology is moving from individual devices toward integrated platforms: cameras, cloud storage, AI features, real-time operations, evidence systems, subscriptions, and future upgrades bundled into vendor ecosystems.

    For public officials, procurement is no longer just “buying a tool.” It can mean entering a long-term platform relationship where today’s contract shapes tomorrow’s data access, integrations, analytics, and switching costs.

    ALPRs are moving into ordinary consumer spaces

    License plate readers are not only appearing on police vehicles or city streets. Retailers such as Home Depot and Lowe’s are also using ALPR systems in parking lots for theft prevention and public-safety purposes.

    That shift matters because private ALPR networks can still generate sensitive location records. They may operate under weaker public oversight than city-owned systems, may be governed mainly by contract, and may still become useful to law enforcement. The safeguard question is not only who owns the camera, but who can search the plate data, how long it is kept, and where else it can go.

    School platforms are civic infrastructure

    The Canvas cyberattack shows that education platforms are no longer just classroom convenience tools. WIRED reported that thousands of schools were disrupted after Instructure shut down Canvas access following a breach by ShinyHunters. Reuters later reported that the incident affected nearly 9,000 schools globally, with stolen data including student names, email addresses, and private messages among students, teachers, and staff.

    When one education platform goes down, students can lose access to assignments, grades, messages, and course materials during critical periods. Afterward, exposed student and staff data can become phishing material. Schools, cities, libraries, utilities, and public agencies increasingly depend on cloud platforms that should be treated as civic infrastructure.

    AI is compressing the vulnerability window

    Google says it disrupted hackers using AI to exploit an unknown weakness in a company’s digital defenses. AP reports that Google found evidence of AI helping attackers exploit a previously unknown vulnerability, and other reporting says the exploit could bypass 2FA on a web-based administration tool.

    The lesson is practical: defenders may have less time. AI can help attackers find logic flaws, test exploit paths, and move faster from discovery to attempted compromise. That makes routine safeguards more important: reduce exposed admin panels, patch quickly, require strong MFA, monitor logs, limit privileges, and ask vendors for clear incident and patch timelines.

    Identity checks are becoming the default answer

    Age verification, VPN restrictions, phone-number identity proposals, digital IDs, and platform verification systems all point toward the same trend: more ordinary activities may require identity proof.

    Child safety, fraud prevention, and robocall reduction are real policy goals. But identity checks are not neutral. They can create new databases, weaken anonymity, expose lawful activity, and make private vendors gatekeepers for speech, communications, and access.

    Direction of travel

    This week’s Signals point toward the same pattern: public and private systems are becoming more searchable, more connected, and more dependent on vendor infrastructure. ALPR networks, police-tech platforms, education systems, cloud records, AI security tools, identity checks, and data brokers all raise the same question: when a system becomes useful, who gets access next?


    Safeguards

    A safeguards page works best when it is practical: less data, cleaner boundaries, stronger access controls, and fewer shortcuts.

    Safeguards section header

    Require audit logs before launch or renewal

    Do not approve surveillance or data systems that cannot answer basic questions: who searched, what they searched, why they searched, what they accessed, whether the result was shared, whether the search was tied to a case number, warrant, emergency, or documented purpose, and whether an outside reviewer can verify the answer.

    This applies to ALPR systems, state databases, vendor dashboards, cloud evidence systems, education platforms, AI tools, and data-broker products. A system without usable audit logs does not merely have a technical gap. It has an accountability gap.

    Limit outside-agency, federal, immigration-enforcement, and vendor access by default

    Access should be narrow by default and expanded only with a clear reason. Local governments should not rely on broad sharing settings, informal assurances, or vendor defaults.

    • no outside-agency access unless explicitly approved;
    • no immigration-enforcement access unless legally required;
    • no vendor access except for documented support needs;
    • no sales, demo, training, or product-development use without written permission;
    • no data sharing without logs, purpose fields, retention limits, and periodic public reporting.

    If a system can be searched by people outside the agency that collected the data, that fact should be visible to elected officials before approval and to the public before renewal.

    Treat public data as held in trust

    Public agencies collect sensitive information because residents need licenses, utilities, schools, benefits, permits, emergency services, and basic civic infrastructure. That does not mean the data should become a general-purpose resource for brokers, vendors, or enforcement pipelines.

    A public-data-trust approach would treat resident data as something government holds on behalf of the public, with duties of loyalty, transparency, narrow use, and enforceable limits. The key question would shift from “can this data be accessed?” to “does this use serve the public purpose for which the data was collected?”

    Use state-level digital civil-rights models

    Montana offers one model worth watching. Voters amended the state constitution to explicitly protect electronic data and communications from unreasonable search and seizure. Montana later restricted state law enforcement from purchasing or otherwise acquiring sensitive personal data from brokers without a judicial warrant.

    Oregon’s SB 1587 points in the same direction by limiting public-body disclosures of personally identifiable information to data brokers when that information may be used for federal immigration-law enforcement. Legislatures can write clearer rules before sensitive data flows into vendor systems, data brokers, or enforcement pipelines.

    Ask vendors when they patched

    The cPanel, Ivanti, Palo Alto, Linux kernel, and water-system cybersecurity stories all point to the same practical safeguard: exposed infrastructure needs a fast patch process. Public officials should expect clear answers: are we exposed, when was it patched, were logs reviewed, were any accounts created or changed, were affected customers notified, what systems depend on this vendor or platform, and what is the backup plan if access is shut down?

    Do not invite a permanent record into every meeting by default

    AI notetakers and meeting bots can be useful. They can also turn informal discussion into searchable records stored by a vendor. Organizations should decide which meetings may be recorded, who can consent, where transcripts are stored, how long they are retained, whether vendors can use the data, and when legal, personnel, strategy, or sensitive constituent discussions require the bot to be removed.

    “There is no cloud – only somebody else’s computer.”

    Cloud tools are still computers, databases, employees, contracts, retention policies, subpoenas, breach risks, and access logs. Convenience should not override recordkeeping, consent, privilege, or privacy decisions.

    Bottom line

    The best safeguards this week are practical and boring by design: collect less data, connect fewer systems, limit outside access, require case numbers or documented purposes, log every search, review the logs, shorten retention, make vendor access visible, treat public data as held in trust, patch exposed systems quickly, and make misuse provable.

    Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.

  • Signals & Safeguards — Issue 8

    Wednesday, May 6, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards newsletter masthead

    At a glance

    • Congress extended Section 702 for 45 days, but the fight over warrant requirements, U.S. person searches, and public release of a secret FISC opinion is still ahead.
    • Immigration enforcement is showing what happens when separate surveillance tools become one searchable enforcement stack.
    • ALPR transparency fights are spreading, raising a basic question: how can the public oversee surveillance systems it is not allowed to see?
    • Age-verification laws are moving fast, and the next debate may be whether child-safety rules quietly become identity-check infrastructure for everyone.

    Main Stories

    Congress extends Section 702 — and leaves the warrant fight unresolved

    Congress passed a short-term extension of Section 702, avoiding an immediate lapse but pushing the real surveillance reform fight into June. The key development is not only the extension. It is the transparency window that now follows.

    Senator Ron Wyden says he secured a commitment to release a classified Foreign Intelligence Surveillance Court opinion before the next debate. That matters because Section 702 is often described as foreign-intelligence surveillance, but the core civil-liberties fight is about what happens when Americans’ communications are searched after they are collected.

    The next debate should not be treated as a routine renewal. It is a chance to ask whether warrantless searches, compliance violations, and secret court interpretations are being corrected or simply carried forward.

    Why it matters for Bend: federal surveillance law shapes the broader privacy environment local governments operate in. When national systems normalize broad collection, after-the-fact oversight, and weak search limits, local officials should be careful not to import the same logic into city technology, public-safety tools, vendor contracts, or data-sharing agreements.

    Immigration enforcement shows what a surveillance stack can do

    The clearest surveillance warning this week is not one tool by itself. It is the stack.

    Recent reporting and scholarship point to immigration enforcement systems drawing from a broad mix of tools and data sources: license plate readers, facial recognition, smartphone location data, social media monitoring, commercial records, biometric systems, benefits records, and federal databases. The civil-liberties concern is not only whether any one tool is lawful in isolation. It is what happens when identity, location, movement, association, and online activity can be combined inside one enforcement pipeline.

    That is why local data decisions are never purely local. A city camera, an ALPR hit, a vendor database, a jail record, or a public record may later become useful to a federal agency for a purpose the original collector did not emphasize.

    Why it matters for Bend: local governments should think about surveillance infrastructure as part of a larger ecosystem. Strong policy should address not only what a city collects, but also retention, secondary use, federal access, vendor access, immigration-enforcement sharing, audit logs, and whether residents can understand how their data may travel.

    Shared pattern

    The strongest stories this week point in the same direction: surveillance power grows when separate systems become searchable together. Section 702, immigration enforcement, ALPR networks, data brokers, voter records, and biometric tools may look like separate policy debates. In practice, they all raise the same governance question: who can connect sensitive data, under what authority, with what transparency, and what meaningful safeguards?

    ALPR secrecy is becoming a public-oversight problem

    Automated license plate readers are no longer just a police-camera issue. They are becoming a public-records issue, a vendor-accountability issue, and a democratic-oversight issue.

    EFF warns that open-records laws have helped the public understand how ALPR systems are deployed and shared, but some states are now moving to block public access to broad categories of ALPR information. The concern is not that raw plate scans should be exposed. It is that secrecy laws can also hide basic oversight information: camera locations, sharing reports, scan counts, hit rates, false matches, vendor access, and the scope of deployment.

    Privacy and transparency should not be treated as opposites. Communities do not need public exposure of every driver’s movements to evaluate whether an ALPR system is safe, lawful, or worth renewing. But they do need enough information to know who can search the data, how long records are retained, what outside agencies can access, whether vendor employees can use the system, and whether misuse is actually punished.

    Why it matters for Bend: public oversight works best before surveillance infrastructure becomes normal. If camera locations, sharing rules, audit logs, vendor access, and query practices are hidden from the public, then elected officials are forced to rely on assurances instead of evidence.

    Sensitive civic data is becoming a federal access target

    A federal judge dismissed the Justice Department’s lawsuit seeking detailed Arizona voter information, but the case is still a warning about sensitive civic data.

    Voter rolls can include names, addresses, birth dates, driver’s license numbers, and partial Social Security numbers. Even when the stated purpose is election integrity or eligibility review, the privacy question remains: who receives the data, what other databases it is checked against, how errors are corrected, and whether people are flagged without meaningful due process.

    This fits a larger pattern. Voter records, bank records, immigration records, vehicle records, health data, and commercial data all become more powerful when they are linkable. The risk is not only a breach. The risk is that ordinary administrative records become inputs for identity screening, eligibility checks, enforcement targeting, or automated suspicion.

    Why it matters for Bend: local and state records are often collected for narrow civic reasons. Public officials should ask what happens when those records are requested for broader state or federal purposes, especially when the data is sensitive, error-prone, or difficult for ordinary people to correct.

    “The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding.”

    Justice Louis Brandeis, dissenting in Olmstead v. United States

    Signals

    Early indicators worth tracking

    These items are included because they point toward where surveillance systems, business incentives, identity infrastructure, and data governance may be heading next.

    Signals section header

    Age verification is becoming identity infrastructure

    Child safety online is a legitimate policy goal. But the design of age-verification laws matters.

    Utah’s VPN-focused age-verification law, Michigan’s minors’ social-media bills, Apple’s digital ID rollout, the GUARD Act debate, Colorado’s age-attestation proposal, and UK under-16 restrictions all point toward the same emerging conflict: whether protecting children online will require adults to prove identity, surrender anonymity, or rely on private verification vendors.

    The Oregon angle is important. Oregon’s 2025 age-verification bill is dead, but similar proposals are likely to return. That gives lawmakers time to separate child-safety goals from identity-check infrastructure before the next bill is drafted.

    A strong proposal should minimize data collection, avoid government-ID retention, protect anonymous access to lawful speech, limit vendor reuse, and require independent audits.

    Facial-recognition oversight is still lagging behind deployment

    Facial recognition is moving into policing, border enforcement, retail security, event security, schools, and public spaces faster than oversight systems are maturing.

    The problem is not only accuracy, though false matches remain a serious risk. The deeper issue is governance: who can run a face search, what database is used, whether the person is notified, whether a human verifies the match, and whether the result can trigger detention, questioning, or denial of services.

    A password can be changed. A face cannot. That makes biometric data different from ordinary data. Facial recognition should be treated as a high-risk surveillance capability, not as a routine software feature.

    Consumer surveillance is becoming an everyday price and mobility issue

    Maryland’s move against grocery-store surveillance pricing, the FTC’s GM/OnStar geolocation case, and reporting on LinkedIn browser-extension scanning all point to the same consumer-privacy shift.

    Surveillance is no longer limited to obvious government systems or social-media advertising. It is appearing in cars, grocery stores, professional platforms, insurance pipelines, loyalty programs, and device fingerprints.

    That matters because privacy harms become harder to see when they are embedded in ordinary life. Vehicle data can influence insurance treatment, shopping data can affect prices, and browser characteristics can become part of a professional identity profile.

    Consumer privacy, data minimization, and anti-discrimination safeguards are becoming cost-of-living issues as well as civil-liberties issues.

    AI agents are moving from chat tools into systems that act

    AI agents are different from ordinary chatbots because they can connect to tools, databases, workflows, and accounts. Cybersecurity agencies from the U.S., U.K., Canada, Australia, and New Zealand now warn that agentic AI is already being used in critical infrastructure and defense contexts, often with more access than organizations can safely monitor or control.

    The warning signal is simple: when AI can take actions, permissions become policy. A poorly governed AI agent could alter files, change access controls, send messages, trigger workflows, or erase logs.

    That makes identity management, auditability, least privilege, and human approval essential.

    Direction of travel

    This week’s Signals point toward one pattern: identity is becoming the control layer. Age checks, biometric systems, ALPR networks, AI agents, consumer profiles, and vendor databases all depend on deciding who someone is, where they have been, what they are allowed to access, and what risk category they belong in.

    The safeguard challenge is to protect people without making every ordinary activity require a persistent identity trail.


    Safeguards

    Practical habits that lower risk

    A safeguards page works best when it is practical. These are the protections, governance habits, and design choices that stood out while sourcing this issue.

    Safeguards section header

    Secure AI agents before giving them real permissions

    AI agents should not receive broad access just because they are useful. Treat them like powerful service accounts with unpredictable behavior.

    Useful safeguards include least-privilege access, verified agent identities, short-lived credentials, separate logs for agent actions, human approval for high-impact tasks, prompt-injection testing, and rollback plans before agents are connected to real systems.

    The key principle is reversibility. If an AI agent can alter files, permissions, records, workflows, or decisions, the organization needs a way to understand what happened and undo damage quickly.

    Make privacy rights usable, not just theoretical

    California’s DROP system is worth watching because it makes data-broker deletion and opt-out rights easier to exercise. The platform lets California residents send one request to more than 500 registered data brokers.

    That is the right design lesson for privacy policy: rights are stronger when ordinary people can actually use them. A privacy law that requires residents to find hundreds of data brokers, submit hundreds of requests, and track hundreds of responses is formally protective but practically weak.

    For policymakers, the safeguard question is simple: does the law create a right, or does it create a usable process?

    Treat ALPR transparency as a privacy safeguard

    ALPR oversight should not require exposing everyone’s raw location history. But it should require enough public information to evaluate the system.

    Useful safeguards include public camera-location policies with narrow exceptions, short retention limits, case-number or purpose requirements for searches, audit logs reviewed outside the chain of command, public sharing reports, limits on federal and out-of-state access, vendor-access logs, and clear penalties for misuse.

    The key distinction is simple: protect individual plate data, but do not hide the governance system.

    Patch exposed systems before small flaws become public-sector incidents

    CISA says the “Copy Fail” Linux vulnerability is now being exploited in the wild. Other recent warnings involving cPanel and compromised software packages point to the same lesson: cybersecurity often fails through routine infrastructure.

    Admin panels, hosting systems, Linux servers, cloud workloads, software dependencies, and vendor-managed tools may not be glamorous, but they can become high-impact attack paths.

    Practical habits still matter: inventory exposed admin systems, patch critical vulnerabilities quickly, require MFA for administrative access, review software dependencies, disable unused services, and make vendors disclose incident and patch timelines.

    For public agencies, cybersecurity is not only an IT concern. It is a public-trust concern.

    A warrant requirement only works if the warrant process is real

    A warrant requirement is one of the most important privacy safeguards, but the word “warrant” should not be treated as magic. Courts still need reliable facts, clear limits, and meaningful review.

    If weak or unverified information becomes enough to search, seize, track, or detain someone, then the safeguard becomes procedural decoration.

    That principle connects back to Section 702, ALPR searches, device searches, location data, and biometric identification. Oversight should ask not only whether a permission slip exists, but whether the standard behind it is strong enough to protect innocent people.

    “The right to be let alone is indeed the beginning of all freedom.”

    Justice William O. Douglas

    Bottom line

    The best safeguards this week are not complicated: collect less data, connect fewer systems, require stronger reasons for access, log every search, limit retention, keep vendors out of secondary use, and make privacy rights easy to exercise.

    Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.

  • Signals & Safeguards – Issue 7 • Wednesday, April 29, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    Signals & Safeguards newsletter masthead

    At a glance

    • Section 702 reauthorization is now teeing up for House floor action under a closed rule, after warrant-related reform amendments were blocked in Rules and the April 30 deadline remained one day away.
    • Florida investigators documented thousands of license-plate-reader searches tracking protesters, while Bend just turned on its own automated camera system; Oregon’s new ALPR law gives the public new tools to ask the procurement and retention questions that matter.
    • The most consequential surveillance architecture this week is the kind operated by private vendors with light access controls — an AI cybersecurity model leak, a $130 million IRS data-linkage platform, and global telecom-tracking infrastructure running since at least 2022.

    Section 702 reauthorization moves toward the House floor without warrant votes

    As Issue 7 went to publication, the House Rules Committee had reported a closed rule for S. 1318, teeing up leadership’s Section 702 reauthorization for possible House floor action today. The House Majority Leader’s schedule lists S. 1318, the Foreign Intelligence Accountability Act, as legislation considered pursuant to a rule. The rule matters because it does not simply set debate time; it determines what amendments the House will actually be allowed to vote on.

    The answer, for now, is narrow. The Rules report provides for consideration of S. 1318 under a closed rule, with the text of Rules Committee Print 119-27 considered adopted as modified only by the amendment printed in Part C. That Part C amendment, offered by Rep. Rick Crawford, is an oversight and penalties clarification: it directs the intelligence community inspector general to determine whether referred queries violate law, rules, or regulations or constitute abuse of authority, and clarifies that criminal penalties apply to query-procedure violations relating to U.S.-person queries.

    What did not make it through Rules is the more consequential reform fight. A motion to make in order a Biggs amendment creating a warrant requirement for covered U.S.-person queries of Section 702-acquired information was defeated 6-6. A motion to make in order a Massie amendment prohibiting reverse targeting under Section 702 was defeated 4-7. Another Massie amendment narrowing the expanded definition of electronic communication service provider was also defeated. In practical terms, the warrant fight reached the Rules Committee, but not the House floor.

    That procedural outcome changes the framing from yesterday’s version. The story is no longer just that Section 702 was stalled while leaders scrambled. The story is that leadership’s three-year extension is moving forward through a rule that blocks separate floor votes on warrant-related amendments. The core substantive question remains the same: whether the government should be able to search Americans’ communications collected under a foreign-intelligence authority without first getting judicial approval.

    One important detail still tempers the cliff framing: most surveillance authorities under Section 702 can continue through March 2027 under existing certifications even if Congress fails to act before April 30. That does not make the deadline meaningless, but it does make the procedural drama somewhat narrower than the rhetoric suggests. The practical urgency is real; the deeper signal is the pattern. When reform is offered, the fight often happens at the procedural gate before the public ever sees a clean floor vote.

    Why it matters for Bend: the warrant fight has been deferred for six issues of this newsletter. Whether S. 1318 passes today, stalls again, or becomes part of another procedural bargain, the local lesson does not change. Federal guardrails remain contested and fragile. That makes local procurement rules, retention limits, access logs, and public oversight more important, not less, because local governments cannot assume that federal law will provide the missing friction later.

    Florida documented thousands of plate-reader searches against protesters. Bend just turned on its own cameras.

    Treasure Coast Newspapers published the strongest piece of investigative reporting on automated license plate readers in years. Reporter Jack Lemnus reviewed more than five million Flock Safety searches across Florida and found that dozens of police departments, sheriff’s offices, and campus police had used the system to track drivers tied to protests including No Kings, 50501, Hands Off, and immigration-enforcement actions.

    Three Treasure Coast agencies that publicly say they do not actively participate in immigration enforcement ran at least 25 immigration-related searches in 2025; statewide, immigration-related Flock queries rose 82% from 2024 to 2025. Sebastian Police, Vero Beach Police, and Port St. Lucie Police were among the named departments using Flock cameras; Stuart Police uses a similar Vigilant Solutions system. Some agencies declined to provide camera counts.

    The TCPalm investigation lands inside a larger national pattern. The Electronic Frontier Foundation’s analysis of approximately 12 million Flock search logs, first reported by 404 Media, found that more than 50 federal, state, and local agencies ran protest-related searches across a ten-month window covering the 50501 movement, Hands Off! protests, and the June and October No Kings demonstrations. In one widely discussed case from last year, a Texas sheriff’s deputy in Johnson County searched 83,000 Flock cameras nationwide tracking a woman who had sought an abortion in Illinois, with the search reason logged as “had an abortion, search for female.” The newsletter has flagged similar use-case drift since Issue 1.

    Oregon now provides one of the strongest state-level frameworks in the country to ask the questions Florida’s records expose. Senate Bill 1516, signed into law by Governor Tina Kotek on March 31 with an emergency clause, took effect immediately. The law restricts how law enforcement uses ALPR systems, limits sharing, requires audit logging, and — most significantly — creates a private right of action allowing Oregonians to sue private companies that sell or otherwise improperly use ALPR data.

    The Oregon Law Center documented that in June 2025, agencies outside Oregon searched the networks of Oregon’s local law enforcement agencies hundreds of times on behalf of ICE. A University of Washington report from October 2025 found that Border Patrol had access to at least ten Washington police departments’ camera databases without explicit authorization. Both findings sit directly under SB 1516’s new framework.

    Surveillance from above is part of the same story. The Intercept documented that LAPD’s Drone as First Responder program flew 32 drone flights over the March 28 No Kings protest in downtown Los Angeles, including nine that began before any dispersal order. Drones lingered over the Metropolitan Detention Center and the Little Tokyo intersection for hours. Skydio’s own marketing materials say its X10 drones can read license plates from 800 feet and identify individuals from more than 2,500 feet.

    The Bend hook lands directly inside this national arc. Bend Police activated four new red-light and speed cameras on Wednesday, April 15, operated under contract by Verra Mobility. In approximately five days — through 7:54 a.m. on Monday, April 20 — the cameras logged 352 events, a rate of roughly 70 per day, with red-light events outnumbering speed events roughly two-to-one. Tickets are not yet being issued during the 30-day warning period; ticketing begins May 15. Camera locations are SE Reed Market Road and SE 3rd Street, NE 27th Street and NE Neff Road, and SE Powers Road and US Highway 97.

    Why it matters for Bend: Bend’s deployment is happening under SB 1516’s new legal framework, which gives the council and the public tools they did not have a month ago. The questions that matter are not whether the cameras catch red-light runners. The questions are: what data does Verra retain, for how long, and where? Who has access? Are the cameras capturing license-plate data on every passing vehicle, including non-violators? Are there logs of who queries the system and why, and is anyone reviewing those logs? Florida shows how “missing people and stolen cars” can quietly become “people who attended a protest.” Oregon’s law gives Bend clearer footing to answer those questions before the warning period ends.

    The most consequential surveillance architecture this week is operated by private vendors

    Three separate stories this week describe the same structural pattern: surveillance and security infrastructure increasingly operated by private contractors with weak access controls, broad scope, and limited public accountability, even as it is integrated more deeply into government and financial systems.

    Anthropic confirmed an unauthorized-access incident at Claude Mythos Preview through one of its third-party vendor environments. Mythos was launched April 7 as part of a curated rollout to enterprise and government partners and publicly described as too dangerous for general release because of its software-vulnerability-finding capabilities. The breach occurred on launch day: a small group reportedly obtained access through a third-party Anthropic contractor whose credentials were apparently shared, then used educated guesses about Anthropic’s URL naming patterns to reach the model. Whatever the merit of the model’s marketing, the substantive question is the same one this newsletter asks of every vendor-mediated system: vendor controls are the actual perimeter.

    Anthropic also responded to Senator Ron Wyden’s letter on AI surveillance access by saying its policy bars unauthorized surveillance and analysis of bulk-domestic-collection data, while acknowledging an exception for a small number of national-security customers using models for foreign-intelligence analysis in accordance with law — including foreign intelligence that includes incidentally collected U.S.-person information. That phrase tracks the same Section 702 architecture now in front of Congress.

    The Intercept reported on Palantir’s Lead and Case Analytics platform, used by IRS Criminal Investigation since 2018. The IRS has paid Palantir more than $130 million for a platform that links tax records, Affordable Care Act data, bank statements, FinCEN data, and cryptocurrency wallet data. Social-relationship mapping is core to the design: the system analyzes networks of people, including calls, texts, emails, and IP-address relationships, and helps investigators establish new relationships among actors.

    Citizen Lab published Bad Connection, documenting two global telecommunications-surveillance campaigns. One combines SS7 and Diameter signaling to track mobile-subscriber locations; the other uses SIMjacker attacks and has logged more than 15,700 location-tracking attempts since October 2022. The structural finding is the most important: these vulnerabilities are inherent to global telecommunications design and business practices, not simply software bugs.

    Why it matters: capabilities the public might assume are tightly held by accountable government agencies are often operated through private vendors with substantial access, weak access controls, and customer lists the public cannot easily see. Mythos leaked through a contractor on day one. Palantir’s LCA platform has expanded across administrations without sustained public deliberation. The telecom-tracking infrastructure documented by Citizen Lab has operated for years despite repeated public reporting. Together, they describe the actual perimeter of modern surveillance, and where its real controls and failures live.


    Warning Signals

    These items point toward where surveillance systems and governance fights may be heading next. The strongest signals this week describe the gap between marketing and actual data flow — workplace tools quietly becoming AI training data, child-safety frameworks becoming identity-verification infrastructure, and pushback against federal practice producing visible but limited change.

    Signals section header

    Workplace data is becoming AI training data through three different routes

    Three pieces of reporting this month describe the same shift through different mechanisms. Atlassian announced that starting August 17, customer metadata and in-app data from Jira, Confluence, and other cloud products will be used to train its AI tools by default — with the opt-out tiered by paywall. Free and Standard customers cannot opt out of metadata collection at all; Premium turns in-app collection off by default but keeps metadata mandatory; only Enterprise customers can opt out of both. The change affects roughly 300,000 customers, with retention periods up to seven years.

    Reuters separately reported that Meta’s Superintelligence Labs has begun installing keystroke and mouse-movement tracking on employee computers to generate training data, based on internal memos and on-the-record vendor confirmation. Forbes reporter Anna Tong documented an emerging market in which defunct startups sell their Slack archives, email threads, and code libraries to AI developers through brokers like SimpleClosure’s Asset Hub, which has processed nearly 100 deals in the past year. In none of the three cases do the workers whose communications become training data typically have notice or consent.

    Why it matters for Bend: government and HIPAA-regulated organizations are exempt from Atlassian’s new policy, but smaller Oregon contractors, school districts, and nonprofits running Free or Standard tiers are not. The procurement and IT-policy questions are immediate: what tools are being used, what data is being retained, and whether vendor AI defaults have changed underneath ordinary work.

    Identity-verification mandates keep arriving disguised as child-safety laws

    A Boston Globe op-ed by Evan Greer of Fight for the Future and Nathalie Marechal of Northeastern’s Institute for Information, the Internet and Democracy makes the substantive case against pending Massachusetts proposals to ban under-14s from social media and require age verification — an argument that applies equally to similar bills in other states. The unstated price of these laws is mandatory identity infrastructure for all users, not just minors. Earlier this year, hackers stole 70,000 Discord users’ data from the company’s age-assurance vendor — a concrete harm, not a hypothetical. California’s A.B. 1709, currently being fast-tracked through the Assembly, would extend the ban to age 16 and create a new state e-Safety Advisory Commission to enforce it.

    The op-ed authors note that the Department of Homeland Security has already used administrative subpoenas this year to demand information about anonymous social-media accounts that monitor and criticize ICE — exactly the kind of accountability journalism that requires the anonymity these laws would weaken. The risk is not that child safety is unimportant. The risk is that a child-safety frame can normalize account-to-identity linkage for everyone.

    Why it matters for Bend: Issue 4 covered the OpenAI-funded Parents & Kids Safe AI Coalition shaping legislation that mirrored the company’s own product positioning. The pattern continues: child-safety language is being used to build identity infrastructure that will affect every user, while biometric-data centralization, breach risk concentration, and age-verification vendors are underweighted in the debate.

    Federal practice gets pushed back from multiple directions, with mixed but real results

    This was an unusually concentrated week of pushback against federal enforcement and surveillance practices. The American Civil Liberties Union, Common Cause, and other plaintiffs filed a lawsuit on April 21 challenging the Justice Department’s demand that all 50 states and the District of Columbia turn over voter-registration records, after 12 states complied and DOJ sued 30 states; five states — Michigan, Oregon, California, Massachusetts, and Rhode Island — have had cases dismissed. The Electronic Frontier Foundation filed suit on April 22 against DHS and ICE over administrative subpoenas issued without judicial approval to tech companies including Amazon, Apple, Google, Meta, Reddit, and X — subpoenas DHS withdrew when challenged.

    NBC News reported on April 24, based on two senior DHS officials and two immigration attorneys, that ICE has verbally instructed field offices to stop entering homes without judicial warrants and has drastically curtailed arrests inside immigration courthouses, reversing the policy memorialized in a May 2025 memo Issue 3 covered when its legal authority first came into question. New York Times reporter Elizabeth Williamson disclosed that the FBI had investigated her after her February 28 article on FBI Director Kash Patel’s security arrangements for his girlfriend; FBI agents queried federal databases for her information before the Justice Department ended the investigation, citing no legal basis. Separately, the Ninth Circuit Court of Appeals issued a 3-0 decision on April 22 prohibiting California from enforcing part of its federal-officer identification law on Supremacy Clause grounds, a ruling with direct implications for Oregon’s HB 4138 mask-ban law passed in March.

    Why it matters for Bend: the pushback is real and produces visible change, but it is also uneven and reversible. ICE’s rollback was verbal, not memorialized. The DOJ stopped the FBI investigation only after agents had already queried databases. The Ninth Circuit ruling makes Oregon’s mask-ban law substantially more vulnerable than it was a month ago. State and local guardrails still matter, but a verbal change can be verbally reversed.

    Florida AG opens criminal probe of OpenAI over FSU shooting

    Florida Attorney General James Uthmeier announced a rare criminal investigation of OpenAI on April 21 over the April 17, 2025 FSU shooting that killed two people and wounded six. Per Uthmeier’s announcement and court filings reportedly including more than 200 AI messages entered into evidence, the suspect used ChatGPT for guidance on weapons selection, ammunition, and timing. Uthmeier said that if a person had given the same guidance, the office would be charging that person with murder. OpenAI responded that the model provided factual responses to questions with information available across public sources online.

    The case follows a separate lawsuit over a February 2026 mass shooting in British Columbia, in which the Wall Street Journal reported that OpenAI’s internal safety systems had flagged the shooter’s account and company leaders considered alerting law enforcement before deciding not to. The policy problem is not only content moderation. It is how companies, prosecutors, and legislatures define responsibility when high-risk interaction logs already exist, internal systems flag danger, and public reporting later reveals the company had enough context to consider intervention.

    Why it matters: Issue 5 covered OpenAI’s support for an Illinois bill that would limit the company’s liability for catastrophic model harms. The Florida case is the kind of harm such a bill would shield against.

    A comprehensive bipartisan-curiosity surveillance bill enters Congress

    Rep. Thomas Massie introduced H.R. 8470, the Surveillance Accountability Act, on April 23. The bill would require warrants for almost all federal searches including digital searches; close the third-party-data loophole by requiring warrants for data held by ISPs, banks, cloud providers, and data brokers regardless of vendor consent; explicitly cover biometric data including facial scans and gait analysis, ALPR data, and vehicle-movement patterns; and create a Bivens-style federal cause of action with attorney’s fees against federal employees who violate Fourth Amendment rights.

    It is, in effect, a legislative compendium of the policy concerns this newsletter has documented across six issues. Massie has libertarian-Republican credentials but bills introduced under his name often do not advance. The proposal’s main significance is what it tells us about where the bipartisan civil-liberties center could converge if either party builds toward it. Co-sponsors include Rep. Lauren Boebert and Rep. Warren Davidson; the Davidson connection is notable given his support this week for Speaker Johnson’s much narrower Section 702 reauthorization.

    Why it matters: the same week a comprehensive warrant-based bill enters the House, a far narrower 702 reauthorization with no warrant requirement is the only legislation in serious negotiation. The contrast is the story.

    Driver populations get GPS and impairment-detection mandates

    Maryland passed bipartisan legislation requiring repeat-offender drivers facing license suspension to install Intelligent Speed Assistance technology — GPS-aware systems that prevent vehicles from exceeding the local speed limit. If signed by Gov. Wes Moore, the law takes effect October 1. The federal Department of Transportation, meanwhile, faces a September 2027 statutory deadline to mandate advanced drunk and impaired-driving prevention technology in all new passenger vehicles under Section 24220 of the 2021 Infrastructure Investment and Jobs Act.

    NHTSA missed its November 2024 rulemaking deadline and now describes, in a February 2026 Report to Congress, accuracy problems serious enough that even 99.9% detection accuracy would generate millions of false-positive vehicle restrictions per year. Both mandates are sold as discrete safety interventions for narrow populations. Both establish GPS, sensor, and biometric infrastructure that becomes standard in passenger vehicles regardless of driver classification.

    Why it matters for Bend: Issue 6 flagged that device defaults are becoming the new front line for identity and behavior infrastructure. These are the vehicle equivalents.

    Direction of travel: identity infrastructure is being built underneath consumer software, vehicles, and child-safety legislation while courts and watchdogs catch up after the architecture is already in place.

    “Ultimately, arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.”

    Edward Snowden

    Practical habits that lower risk

    These are the practical protections and patching habits that stood out most clearly this week. The strongest safeguards are still disciplined ones: faster patching, narrower data, and fewer assumptions about what default settings actually do.

    Safeguards section header

    CISA’s April KEV deadline passed Monday — but the patch picture is widening, not narrowing

    CISA added eight more vulnerabilities to its Known Exploited Vulnerabilities catalog on April 13, with a federal remediation deadline of April 27. The additions included flaws in Cisco SD-WAN Manager and Syncro Zimbra, alongside an actively exploited Microsoft Exchange vulnerability tied to Storm-1175 Medusa ransomware operations. Microsoft’s April Patch Tuesday separately addressed 165 vulnerabilities, the second-largest monthly batch on record.

    Practical safeguard: treat KEV deadlines as a minimum floor, not the whole patch strategy. Systems that face the public internet, email, identity, remote access, and vendor management deserve faster review than ordinary monthly patch cycles.

    NIST narrows the scope of CVE analysis at the National Vulnerability Database

    NIST announced that it will prioritize enrichment only for CVEs in CISA’s KEV catalog, federal-government software, or critical software under Executive Order 14028. CVEs outside those criteria will still be listed, but many will no longer receive automatic enrichment with the metadata organizations use to judge severity.

    Why it matters: organizations that rely on NVD enrichment should add other sources to their patch workflow, especially for software outside federal use. The default authoritative source is still valuable, but it is no longer comprehensive enough to carry the whole risk picture.

    A privacy-tool vulnerability defeats Tor’s “New Identity” reset

    Researchers Dai Nguyen and Martin Bajanik disclosed CVE-2026-6770, a Firefox/Tor vulnerability involving the IndexedDB.databases() API. Any website could derive a stable identifier by creating named databases and observing returned ordering. The identifier persisted across websites and across privacy resets users would expect to clear it, including Tor Browser’s New Identity reset.

    Practical safeguard: keep privacy tools updated, and do not treat a privacy promise as the same thing as a guarantee. The lesson is not that Tor is unsafe; it is that privacy depends on implementation details that can fail quietly.

    macOS updates are also social-engineering safeguards now

    Apple released macOS Tahoe 26.4.1 on April 9, building on a late-March security update addressing WebKit issues, Mail privacy problems, iCloud sensitive-data exposure, and Crash Reporter behavior. Apple also added Terminal protection against potentially harmful pasted commands. Within days, Jamf Threat Labs documented a ClickFix-style attack using the applescript:// URL scheme to open Script Editor instead of Terminal and bypass the new protection.

    Practical takeaway: keep macOS current; leave Background Security Improvements on automatic install; and treat prompts asking you to paste commands or install software outside a normal update flow as suspicious by default. A recruiter, meeting invite, verification step, or update prompt can be part of the attack path.

    Bottom line: the strongest safeguards this week are still the unglamorous ones — faster patching when exploited vulnerabilities land, less default trust in vendor relationships, shorter retention periods, narrower access, and concrete audit-log questions asked before infrastructure becomes routine. The law is in effect now. The cameras already are too.

    “Experience should teach us to be most on our guard to protect liberty when the government’s purposes are beneficent. Men born to freedom are naturally alert to repel invasion of their liberty by evil-minded rulers. The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding.”

    Olmstead v. U.S., 277 U.S. 438 (1928) (dissenting) — Louis D. Brandeis

    Disciplined safeguards are deliberately boring. That is why they last.