Signals & Safeguards

A concise weekly newsletter tracking surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

  • Signals & Safeguards Issue 19: Flock’s OS Investigate, the CDLIS Data Fight, and Sensors Hidden in Familiar Objects

    Signals & Safeguards

    Issue 19 • Wednesday, August 26, 2026

    A concise biweekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    The most important privacy decision often happens after collection

    A record may begin as a plate read, body-camera frame, licensing file, or router signal. Its consequences change when systems fuse it with other data, infer new relationships, convert it into evidence, or open it to outside searches.

    At a Glance

    • Data fusion can create knowledge no agency collected directly.
    • Software updates can change a system’s real capability without new hardware.
    • Retention, access, and audit rules must follow the data wherever it moves.

    The decision point keeps moving downstream: routine records (plates, files, dispatch) get pulled into one searchable layer through fusion, that layer supports new inference (identity, association, pattern), and inference drives action (an alert, a retention decision, a sharing decision). Most rules still attach to the original collection — how long a plate read is kept, who may view a case file. Fusion weakens those boundaries unless purpose, access, retention, and audit rules follow the information into the combined system.

    Flock’s new AI layer turns separate records into investigative prompts

    WIRED reconstructed Flock’s OS Investigate interface from code the company’s own login pages served to anyone who loaded them. Reporters Dhruv Mehrotra and Dell Cameron found 69 prewritten prompts and 45 tools designed to reach plate scans, camera metadata, case files, dispatch logs, arrest records, commercial identity records, and other sources. The prompts include finding frequent visitors to a neighborhood, identifying vehicles that travel together, and turning plates into names or addresses. Flock says the product remains in development and may change before broader release.

    The policy issue is no longer only whether a plate camera should exist. Once separately governed datasets sit behind one interface, a query can reconstruct movement and association at a scale that raises Fourth Amendment and modern-general-warrant concerns.

    The governance gap: Most rules attach to the original collection — how long an ALPR read is kept, who may view a case file, or why a dispatch record exists. Fusion weakens those boundaries unless purpose, access, retention, and audit rules follow the information into the combined system. Before deployment, ask: Which datasets can be joined? Which fields become searchable? Can prompts infer associates or routines? Who can export results? Which audit record survives?


    A licensing database becomes a federal target

    Oregon and other states are challenging federal demands for personal information concerning approximately 17 million commercial drivers — including names, dates of birth, Social Security numbers, license numbers, and issuing states.

    What happened

    The Commercial Driver’s License Information System (CDLIS) exists so states can determine whether an applicant is already licensed elsewhere. The states supply and own the records; the American Association of Motor Vehicle Administrators (AAMVA) operates the system on their behalf.

    According to Oregon’s complaint, the Federal Motor Carrier Safety Administration demanded five years of records for every driver and threatened federal funding when AAMVA resisted. A related Department of Homeland Security subpoena sought the same data. The states argue that federal agencies are attempting to build a separate copy without public notice or clear limits on later use or sharing.

    On August 20, a federal judge issued a temporary restraining order barring transfer of the plaintiff states’ records while the court considers a preliminary injunction. The order is temporary, but it is an important early recognition that bulk access cannot be treated as an ordinary administrative request.

    Why it matters beyond driver licensing

    The dispute is a purpose-limitation case in unusually clear form. A record may be accurate, useful, and lawfully collected for one program. None of those facts establishes that a different agency should receive the entire database for a different mission.

    Centralized public systems are attractive precisely because they eliminate the cost of collecting information again. Driver, voter, benefits, education, health, and law-enforcement records can become inputs to unrelated investigations when the requesting agency treats availability as permission.

    The safeguards should travel with the information

    Purpose limitation should bind the original agency, every recipient, and every contractor. A data-sharing agreement should identify the permitted use, legal authority, fields disclosed, users, retention period, onward-transfer rules, and the event that ends access.

    Bulk transfer deserves heightened scrutiny because it reverses the ordinary investigative sequence. Instead of identifying a person and seeking information tied to a factual basis, government first acquires a population-scale database and decides later which records may become useful. That architecture can produce the functional equivalent of a modern general warrant: collect the records first, preserve the ability to search them, and supply the justification only after a person becomes interesting.

    The transfer test: What was the original statutory purpose? Which exact fields are necessary now? Why would targeted legal process be insufficient? Who may search, export, or combine the records? Does the recipient face the same retention and disclosure rules? Can access be suspended and every copy deleted? What public report will show how the data were used?

    Legislative principle: Information collected under one authority should not become a general-purpose investigative asset merely because a centralized copy is technically convenient. Require necessity, minimization, notice, auditability, and a defined end point before secondary access begins.


    Make privacy rights usable — without building another identity trail

    California DROP moves the burden from individuals to brokers

    California’s Delete Request and Opt-out Platform (DROP) allows a resident to send one request to more than 600 registered data brokers. Brokers must retrieve requests on a recurring schedule, delete eligible information, and direct service providers and contractors to do the same.

    By August 25, the state reported more than 500,000 registrations. Approximately one quarter of registered brokers had already reported processing requests; 99.9 percent of participating consumers had a profile deleted by at least one broker, and the typical user had information removed by more than 40.

    The institutional design matters. Traditional privacy rights often require people to identify hundreds of companies they have never heard of, locate separate forms, verify themselves repeatedly, and return later to see whether the request was honored. Centralization makes the right practical and gives the regulator a common compliance surface to inspect.

    Deletion still needs a technical definition. A broker can stop displaying a profile while retaining source data, linkage keys, derived attributes, backups, or relationships that allow the profile to reappear. A meaningful standard should address inferences, downstream recipients, later reacquisition, legal exceptions, and certification of completion. The most valuable feature may be the regulator’s ability to compare claims across the market — running test requests, comparing broker response rates, and imposing escalating consequences when a company ignores the platform or reacquires information it was required to erase.

    Meta settlement: safer defaults meet the age-assurance problem

    A proposed multistate settlement would require major changes for teenage users of Instagram and Facebook, including default daily limits, overnight blocks, school-hour notification controls, safer content settings, stronger parental tools, age assurance, and independent auditing.

    The design provisions offer a useful alternative to rules that place all responsibility on children or parents. A protective default changes the environment before harm occurs. An independent auditor creates a record outside the platform’s own public assurances.

    Age assurance remains the privacy fault line. A system intended to protect minors can require every user to prove or estimate age, creating pressure to collect government identification, facial images, device signals, or behavioral information. The protective rule can become a population-wide identity system if minimization is not built in.

    A privacy-preserving standard should prove only the necessary threshold and then forget the evidence used to reach it: do not retain government ID when a less intrusive method works; separate age confirmation from browsing and account history; prohibit advertising, profiling, product development, and law-enforcement reuse; publish error rates and independently test demographic performance; provide correction and appeal when a person is classified incorrectly; and require short retention and deletion that includes vendors and subprocessors.

    Shared lesson: Centralization can make a right easier to exercise and make a database more attractive to misuse. Pair usability with minimization, strict purpose limits, short retention, strong security, public reporting, and independent verification.


    Warning Signals

    Warning Signals: new sensors hide inside familiar objects and familiar workflows

    Smart glasses make ambient recording harder to see

    VICE reports that teen boys are using camera-equipped smart glasses to record and harass girls in schools and other everyday settings. The form factor matters because ordinary social cues no longer reveal that recording is occurring. A person may notice a raised phone; glasses can remain pointed at someone throughout an interaction.

    Brisbane supplied a concrete institutional response. The city prohibited nonconsensual recording with phones, action cameras, smart glasses, and other camera-enabled devices at all 21 council pools. Staff can enforce the condition of entry even where general public-space law would otherwise permit recording.

    The safeguard follows capability rather than shape. A policy limited to phones will fail when the same recording function moves into glasses, earbuds, jewelry, vehicles, or another object.

    Routers can become motion sensors through software

    Comcast’s Wi-Fi Motion capability illustrates a different expansion path. Network equipment installed to provide connectivity can use changes in radio signals to infer movement in a home. The device does not need a conventional camera to acquire a sensing function. This is why procurement inventories should record latent and update-enabled capabilities. Officials need notice when an ordinary device begins collecting a new data type, making a new inference, or sending information to a new service.

    SignalTrace connects vehicles, devices, and association

    Ars Technica reports that Leonardo’s SignalTrace pairs automated license plate reader observations with Bluetooth or radio-frequency device signals. That combination can associate a vehicle with a device and infer which devices — and potentially which people — travel together.

    The shift is qualitative. A plate reader traditionally produces a time-and-location record about a vehicle. Device detection adds a second identifier. Repeated co-location can then become social-network evidence even when neither person was originally the subject of an investigation. Association is not guilt. Family members, coworkers, rideshare passengers, neighbors, protesters, journalists, and bystanders can move together for innocent reasons. A system that ranks associates should not silently convert proximity into suspicion.

    The common pattern: Glasses become concealed cameras. Routers become motion sensors. Plate readers become device-and-association systems. The governance trigger should be the new capability, not the purchase date of the original hardware. Require renewed notice and approval when a system adds a data type, inference, matching method, real-time alert, sharing pathway, or automated decision.

    Procurement question: What can this device become after a software update, and what record will show that the new function was reviewed before activation?


    Axon Watch: one ecosystem can move from capture to identity to evidence

    Edmonton tests body-camera facial recognition

    Edmonton police are testing an Axon-supported workflow (Associated Press) that compares faces captured by body-worn cameras against police watch lists. During the pilot, officers do not receive identifications in the field; results are reviewed afterward. That boundary matters because after-the-fact analysis can become real-time officer alerting through a later product or policy change.

    Before any expansion, officials should know who enters a person on the watch list, what evidence is required, how long the entry remains, which model and threshold are used, how demographic performance was tested, and how a person corrects a false association.

    Fleet 3 turns a plate record into evidence

    Axon’s August release notes say agencies can enable officers to convert an ALPR read or hit directly into evidence from the Fleet 3 Dashboard. Users may add or edit the owner, title, ID, category, and tags before the record uploads, and the conversion receives priority over video uploads.

    This is a retention decision disguised as workflow convenience. A short-retention surveillance record should not become longer-term evidence merely because someone clicks “convert.” Require an existing case, individualized relevance, a named decision-maker, and an audit record that preserves the original capture and every later change.

    Fusus exposes configuration — preserve it: the same August release notes add diagnostic visibility into the ALPR alert pipeline. Agencies should preserve configuration snapshots before and after material changes so a later reviewer can reconstruct what sources, routes, filters, and alert settings were actually enabled.

    Long contracts consolidate capabilities and leverage

    Baton Rouge approved a long-term Axon agreement reported at more than $31 million. The package brings multiple functions under one vendor relationship, including records and AI-assisted report writing, Fusus, and other Axon services. (Note: I could not independently verify the specific dollar figure or procurement record for this item before publishing — flagging for your review rather than linking to an unconfirmed source.) Consolidation can reduce administrative friction while increasing switching costs and integration risk. Oversight should follow the combined data flows: which product can read another product’s records, which administrator spans systems, which retention rule controls a copy, and what remains exportable if the contract ends.

    Apex pauses a DroneSense amendment for review

    Apex, North Carolina pulled an Axon contract amendment from its consent agenda and sent it for committee review after residents raised concerns. The city already had drones; the proposed change concerned DroneSense software and related capability. That distinction is exactly why review was appropriate.

    Public oversight should not depend on whether a proposal includes a new physical sensor. Software can add remote operation, livestream distribution, alert integration, mapping, evidence transfer, automated analysis, or new administrator access to equipment already in service.

    Vendor switching is not capability reform

    National reporting from NPR shows Axon, Motorola, Verkada, and other vendors positioning themselves to inherit business from jurisdictions leaving Flock. A different logo does not answer what is collected, how long it is retained, who can search it, or what integrations remain.

    Axon Watch test: Ask which capabilities are available, licensed, enabled, or planned; what activates each one; which data cross product boundaries; and whether the agency can disable one feature without losing unrelated functions.


    Safeguards

    Safeguards: put approval, evidence, and limits at every expansion point

    1. Require approval for material new capabilities

    Treat a software update, integration, new model, search field, livestream route, or outside database as a governance event when it changes what the system can reveal or do.

    2. Require a warrant or bind access to a real investigation

    Use judicial authorization for retrospective movement searches where constitutionally required. At minimum require a case or CAD number, qualifying offense, factual basis, named user, and purpose before access.

    3. Justify every move into longer-term evidence

    Identify each retained record individually. Preserve the original capture, reason for retention, linked case, decision-maker, later edits, exports, and the date the longer retention ends.

    4. Make logs usable outside the vendor dashboard

    Agencies should export complete, tamper-evident records showing users, organizations, searches, results, denied attempts, vendor access, configuration changes, sharing, and corrective action.

    5. Make the contract follow every copy

    Apply retention, deletion, sanctuary-law, public-record, incident, and audit requirements to vendors, subprocessors, integrations, backups, downstream recipients, and contract closeout.


    Oversight is becoming concrete

    Congress. Sen. Josh Hawley opened a Judiciary subcommittee investigation into Flock’s collection, retention, access, and dissemination practices, with documents requested by September 8.

    Pflugerville. The city ended its Flock agreement after records reportedly showed that 459 outside organizations conducted nearly 1.6 million searches that included the city’s network over six months.

    Salt Lake City. Officials have considered requiring an active case number before officers access ALPR information — a more enforceable rule than a generic free-text investigative purpose.

    The closing principle: procurement is policy

    A system’s real rules are determined by configuration, integrations, contract terms, administrator roles, and access pathways — not merely the purpose stated when it was purchased.

    The goal is not to block every tool. It is to restore checks and balances before collection, fusion, retention, and outside access become permanent infrastructure.


    Signals & Safeguards is the newsletter of Jonathan Westmoreland, founder of Bend Privacy Alliance · jonathanwestmoreland.com · Published August 26, 2026.

  • Signals & Safeguards: ALPR Edition

    Signals & Safeguards — ALPR Edition. Bend Privacy Alliance. Privacy, Transparency, Civil Rights.

    Published four days ahead of the National Week of Action Against ALPRs (August 16–22, 2026). Signals & Safeguards now publishes every other week; this special edition is devoted entirely to automated license plate readers.

    In anticipation of the National Week of Action Against ALPRs, running August 16–22, this special edition is devoted entirely to automated license plate readers — the small roadside cameras now creating searchable records of millions of drivers’ movements across the country. It publishes four days before the Week of Action begins. Nothing in this edition describes a vote, removal, or investigation as complete unless it had already happened at the time of writing.

    Scale, for Context

    Flock Safety’s roughly 120,000-camera network — which includes both automated license-plate readers and separate pan-tilt-zoom video cameras — now stands in every state but Alaska, under contract with about 7,000 law enforcement agencies, some 40% of all police departments in the country. The company is now valued at $8.4 billion. — The New York Times; CNN

    This Happened Here

    Bend, Oregon — June 2025–January 2026

    This isn’t a hypothetical for Bend. In June 2025, during the first three weeks of what was supposed to be a year-long Flock Safety pilot, federal immigration officials — ICE, CBP, and Homeland Security Investigations — accessed Bend Police Department’s camera data 279 times. Bend PD had not authorized any of it.

    The cause, according to police officials themselves, was a single setting: a “Lookup” function left in its factory-default “National” position rather than switched to “State” or “Local,” reportedly the result of a supervising captain’s oversight. That one unflipped toggle opened Bend’s camera data to every agency running a National Lookup query anywhere in the country. City Council turned the cameras off at its January 7, 2026 business meeting. — The Source Weekly

    The lesson generalizes directly: a policy on paper — “we don’t share with immigration enforcement” — is not the same thing as a technical setting that actually enforces it. Bend’s own experience is the clearest local proof of that gap.

    1.4 million

    Queries of Oregonians’ driver and criminal records by federal immigration authorities, alleged in a May 2026 lawsuit against Oregon State Police — including 176,576 by ICE alone and 21,363 by Homeland Security Investigations, with Customs and Border Protection and the remainder of DHS accounting for the bulk of the total.

    The lawsuit, filed May 5 by the Rural Organizing Project, alleges Oregon State Police has for years allowed federal immigration authorities to query Oregonians’ data through its Law Enforcement Data System — an average of roughly 3,835 queries a day. The complaint says OSP has held these data-sharing agreements since 2007, and that a February request from Rural Organizing Project to terminate them was declined. OSP has denied wrongdoing; a spokesperson told OPB the agency “is committed to following Oregon Sanctuary Laws and has not taken any actions that would violate those laws.” — The Source Weekly; OPB; AOL

    Section One

    How Far the Network Could Grow

    The debate over ALPRs has mostly been about fixed cameras — mounted on poles, at intersections, on toll gantries. A document obtained by 404 Media shows Flock pitched something considerably larger: a plan to partner with dashcam maker Nexar and turn roughly 350,000 rideshare and delivery drivers’ dashcams into a mobile, privately operated plate-collection network. The presentation was prepared for Georgia’s Office of the Attorney General in August 2025. Flock told 404 Media the Nexar partnership was never executed. — 404 Media

    But the presentation still documents the scale of the mobile collection network the company had pitched — and reframes the question this special edition keeps returning to: not just how many fixed cameras exist, but how much of the country’s movement a company like Flock is willing to propose capturing next.

    Section Two

    Same Capability, Different Vendor Name

    Several jurisdictions responding to Flock controversy have not stopped using ALPR technology — they’ve switched vendors. 404 Media reports that cities dropping Flock are, in some cases, immediately replacing it with Axon license plate readers, which can use existing streetlight infrastructure and blend into surroundings. — 404 Media

    Stanford ended its Flock contract and moved to Genetec, with university-controlled data storage and a stated 30-day retention policy. — Stanford News; KQED

    Douglas County, Colorado is replacing 50 Flock cameras with a nearly $23 million, 10-year Axon contract that adds 50 more cameras. Flock’s CEO publicly disputes the sheriff’s characterization of data ownership. — Axios Denver

    Pleasanton, California shows what can go wrong even when a jurisdiction intends to leave a vendor: a city memo says three Motorola/Vigilant cameras kept collecting data until July 8, 2026, months after the city believed it had terminated the contract in October 2025. The legacy system reportedly wasn’t configured to log outside-agency searches, so the city couldn’t determine whether a federal agency had queried the data without authorization. — City of Pleasanton memo

    Changing brands is not the same as changing practice. A genuine safeguard has to follow the capability — retention limits, audit logging, access verification — not the logo on the camera housing.

    Section Three

    What Departments Don’t Want Said Out Loud

    404 Media obtained a Wapello County, Iowa “standard operating procedures” document, dated November 2025, that instructs deputies: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE” and “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” Where a report must explain how a vehicle was located, the policy recommends language such as “using county resources.” The document does carve out one exception — it instructs deputies to tell the truth if directly asked by someone like an attorney. Sheriff Don Phillips defended the policy, saying deputies independently confirm any plate, warrant, or stolen-vehicle report before acting, and that disclosing the camera system would reveal investigative methods to people trying to evade it. The county has four Flock cameras under a contract signed in late 2024. — 404 Media

    This is a policy about concealment, not a single officer’s judgment call, and it raises real questions about parallel construction, discovery obligations, and what the public is entitled to know about how a stop began. A related 404 Media story describes an incident in which a driver’s Flock-tracked interstate travel — including a trip to a state where marijuana is legal — reportedly became part of the stated justification for a stop and search. — 404 Media

    Charlotte-Mecklenburg police released a previously undisclosed data-sharing agreement with Flock only after journalist pressure and after Officer Seth Elliott, 25, was arrested and charged with illegally accessing a government computer. Court records allege a friend facing drug charges in Watauga County asked Elliott to run a plate; Elliott is accused of using Flock and the state’s CJLEADS database to identify it as belonging to an undercover officer, then passing that identity back to the drug suspect — an allegation, not an adjudicated fact. CMPD owns no Flock cameras itself but had access through its MOU with a broader regional network. — WCNC; WBTV

    Section Four

    When Access Becomes a Tool for Personal Use

    A Washington Post national investigation gives structural shape to what might otherwise look like scattered local incidents: officers with broad camera-network access allegedly using it to track people in their personal lives, including former partners. Its value is explaining the mechanism — authorized access can be repurposed with very little friction — not adding another isolated case to a list.

    That mechanism shows up repeatedly at the local level:

    • DeKalb County, Georgia — eight metro Atlanta police officers reportedly suspended for policy violations involving Flock cameras used for personal reasons. — WSB-TV
    • Savannah, Georgia — six police employees under investigation after an internal audit flagged potential misuse. Savannah had previously appeared in Flock’s own promotional material, one of four departments WIRED found facing misuse allegations after being featured that way. — WJCL; WIRED
    • Baytown, Texas — an officer resigned while internal-affairs and criminal investigations remained open; the resignation does not end the investigation. — ABC13

    The New York Times’ national reporting adds two more data points: a Texas officer used Flock’s cameras to track a woman across state lines who was suspected of self-administering an abortion, and the paper describes officers around the country abusing camera access to track romantic partners — with some cases resulting in discipline or termination. Separately, Los Angeles and Dayton, Ohio both suspended their Flock contracts specifically to keep immigration authorities from accessing camera data; Dayton reportedly resorted to physically covering its cameras with trash bags in the interim. — The New York Times

    This is not an exhaustive incident list. The pattern is the point: a system built for one stated purpose creates access that is very easy to use for another.

    Section Five

    Does It Actually Work?

    Effectiveness evidence is mixed, deployment-specific, and should not be flattened into a single number.

    The Atlanta Community Press Collective compared FBI clearance-rate data against an eightfold increase in Atlanta’s integrated camera network — more than 28,000 cameras combining Flock, Ring, and other systems — and found major-crime clearance rates largely unchanged. A peer-reviewed evaluation of a major ALPR expansion in Atlantic City found no overall reduction in violent crime, though the authors did find associations with reduced shootings, motor-vehicle theft, and property crime; shooting clearance rates did not significantly improve in their data (one coauthor was an Atlantic City police captain). — Shjarback & Sarkos, Justice Evaluation Journal

    Accuracy is a separate question from effectiveness. Business Insider’s review of Roseville, California records found Flock incorrectly read license plates in 71% of 1,427 stolen-vehicle and felony alerts sent to police during 2023–2024 — repeated character errors, blurry images, missed vehicles. Flock attributed part of the performance to atypical camera placement and older hardware; Roseville disputed the company’s claim that performance had improved. Critically, Roseville says independent human verification caught the bad alerts before they became stops or arrests — a deployment-specific rate, not a universal one.

    A third data point: the New York Times reports that a 2024 study found Flock’s cameras increased case clearance rates by 9%, but 404 Media and others criticized the finding because Flock itself had partnered with the researchers and selected which agencies were included — a conflict-of-interest problem distinct from Atlanta’s and Atlantic City’s more independent numbers above. Boulder, Colorado offers a competing claim: the city says its 31 cameras produced a 34.5% decline in motor vehicle theft. — The New York Times

    What a false positive actually costs. Amber Newell was driving on I-94 near Brookfield, Wisconsin — a Milwaukee suburb — on August 6 when a Flock camera flagged her car as connected to a Milwaukee homicide investigation. Brookfield officers surrounded her vehicle with guns drawn; a passenger had to put his hands out the window in view of passing traffic. Milwaukee police later acknowledged the alert should have been cleared from the system days earlier — an employee had simply never removed it. This was not an isolated incident for Newell: she had already been through a nearly identical stop, guns drawn, the previous Monday. Milwaukee police were explicit that this was not a Flock technology failure but a data-entry mistake — worth sitting with, since it means the safeguard that failed was human process, not the camera hardware. Newell says her daughter is now afraid to ride in the car. — Local 12/WITI; FOX6

    Section Six

    Communities That Took Final Action

    These are completed outcomes — votes taken, contracts ended, cameras coming down — not proposals still in progress:

    • Santa Cruz, California — city council voted 6–1 in January 2026 to cancel its Flock contract after sustained resident organizing and reports of out-of-state data access; a Week-of-Action anniversary rally is planned there. — Lookout Santa Cruz
    • Lago Vista, Texas — unanimous council vote to remove Flock cameras. — KVUE
    • Stoughton, Wisconsin — council voted to terminate a two-year, $25,000 Flock agreement just seven months after signing it, paying a reported $12,500 early-termination fee; the resolution requires camera removal and deletion of collected data. Stoughton is reportedly the seventh Dane County entity not to renew a Flock contract. — Channel 3000
    • El Cerrito, California — council voted 3–2 not to renew its Flock contract, after it came to light that federal agencies — including possible ICE access — had queried data from the city’s 40 cameras without police knowledge. Cameras stopped collecting June 6 when the contract expired, with physical removal scheduled through August 18. — NBC Bay Area
    • Chandler, Arizona — the city will end access to and remove 40 fixed cameras after a routine audit found an anomaly officials could not explain. Chandler says no member of the public had their privacy compromised, and the city may later solicit a different vendor. — City of Chandler
    • Narragansett, Rhode Island — town council voted unanimously on August 3 to terminate its Flock contract immediately, becoming the second Rhode Island community to do so within eight days, after South Kingstown’s cancellation on July 27. No replacement vendor had been announced as of publication. A state bill that would have required municipal approval before installation and shortened the state’s default retention period died in the legislature this session. — WPRI; Boston Globe; UpriseRI

    Section Seven

    Communities Still in the Fight

    • Milford, Connecticut — 64 speakers and three hours of public testimony before officials delayed a moratorium vote. — CT Insider
    • Boerne, Texas (near San Antonio) — nearly 900 petition signatures gathered within days; an official who previously supported the cameras is reportedly reconsidering. — MySA
    • Conroe and League City, Texas — Flock camera questions could go before voters in both cities. — Chron
    • Salt Lake City — the council is weighing ordinance proposals covering permitted uses, access tracking, camera placement, and outside data sharing; no vendor named and no policy yet adopted. — Axios Salt Lake City
    • Newtown, Connecticut — council voted unanimous support for drafting a moratorium resolution, referred to an ordinance committee. — News-Times
    • Lake City, Florida — a useful counterpoint: the council voted 2–3 against putting a Flock camera question on the November ballot. Organizing does not guarantee a vote, let alone a win. — News4JAX

    Section Eight

    What Government Oversight Looks Like

    Connecticut’s Governor Ned Lamont has called for a 30-day review by the state’s police training board, statewide guidance, and asked municipalities to pause new ALPR installations while the review proceeds — specifically naming retention, access, sharing, and permissible-use rules as the open policy questions. — Office of Governor Ned Lamont

    West Virginia lawmakers questioned a Flock representative directly and, by the reporting available, remained unconvinced the company’s answers addressed their Fourth Amendment and privacy concerns. — West Virginia Watch

    In Congress, Republican Rep. Keith Self of Texas — a conservative former Army colonel — introduced a bill in July that would require federal law enforcement to get a warrant before accessing or querying state and local ALPR data. The Policing Project at NYU’s law school counts 13 states that now require independent audits of ALPR systems to catch officer misuse; Texas is not one of them. — The New York Times

    Oregon Sidebar

    Oregon is not starting from zero. SB 1516, which took effect March 31, 2026, already sets a 30-day retention limit, restricts use and sharing of ALPR data, and requires public policies, audits, and vendor civil liability. Central Oregon readers should understand these rules already exist here, even as gaps remain — which is exactly why a 2027 legislative concept to strengthen the law is already in progress. The gap between rules on paper and rules in practice is exactly what the Bend and OSP stories in the opening pages illustrate.

    Section Nine

    In the Courts

    • Westchester County, New York — motorists suing over roughly 1.6 billion license plate scans collected on nearly 600 readers, alleging outside data sharing and raising a constitutional challenge. — Associated Press, via LegalNews.com
    • Wichita, Kansas (Grimmett v. City of Wichita) — a state constitutional challenge to a nearly 200-reader network, seeking declaratory relief, an injunction, and deletion of historical records. These are the plaintiff’s allegations and legal theory, not court findings. — Kansas Justice Institute
    • Motorola/Vigilant — a proposed class action alleging improper collection, retention, interstate sharing, security failures, and monetization of plate data. — Legal Newsline
    • New York City — tenants suing to block NYPD access to a housing-authority camera network of nearly 20,000 cameras that reportedly also incorporates license-plate-reader data. — New York Focus
    • Norfolk, Virginia (Schmidt v. City of Norfolk) — a federal judge ruled in January 2026 that Norfolk’s roughly 172–176-camera ALPR program does not currently amount to unconstitutional “dragnet-style” surveillance, but explicitly left the door open: ALPR surveillance “could become too intrusive” at some point, and “at least in Norfolk, Virginia, the answer is: not today.” A court filing in the case found the cameras had logged plaintiff Lee Schmidt’s own vehicle 526 times in about four and a half months. Plaintiffs, represented by the Institute for Justice, plan to appeal. — WHRO; NBC News

    Section Ten

    Beyond Police Departments

    ALPR data does not stay inside one department’s database. The Brennan Center’s catalog of Department of Homeland Security surveillance tools documents more than $2.9 billion obligated since January 2021 across video, biometric, location, and data-purchase systems, and identifies widespread state and local data-sharing arrangements with DHS. In Park City, Utah, the local sheriff confirmed that cameras feeding a shared network have been queried by ICE, which has paid for access, for roughly eight years. — TownLift

    Nashville’s airport shows the same dynamic at a smaller scale: audit logs the Nashville Banner obtained show more than 75,000 searches by Tennessee police departments and sheriff’s offices, plus nearly 2,500 by airport police, this year alone — including at least one search logged as an immigration case. Flock’s standard policy deletes cloud data after 30 days, but airport policy directs staff to move each shift’s data onto internal servers for a minimum of three years.

    Spokane — manual plate collection outside any Flock system. Mother Jones, reporting on public records, found that a Spokane Police Department detective who also serves as a Homeland Security Investigations task-force officer wrote a July 2025 report describing her own and a colleague’s collection of vehicle, license-plate, and social-media information from people near Spokane’s ICE field office — including bystanders not accused of any wrongdoing. Some of that information was uploaded to Evidence.com, a digital evidence platform owned by Axon. This is not a Flock or ALPR story — no automated camera network was involved — but it illustrates that plate-and-movement surveillance happens through channels well outside the ALPR debate.

    On the commercial side, Digital Recognition Network markets more than 500 million plate scans monthly across 300-plus U.S. markets to lenders, insurers, and repossession companies — a private data-broker layer that operates independently of any police department, with hardware that reportedly rides on tow trucks scanning ordinary residential streets. A recent California Court of Appeal ruling in Mata v. Digital Recognition Network favored the company — but on narrow grounds: DRN had actually published the privacy policy state law requires, and the plaintiff couldn’t show a concrete injury beyond the fact of being scanned. A separate case, Bartholomew v. Parking Concepts, cuts the other way: it held that failing to post a required privacy policy is itself actionable harm, with damages starting at $2,500 per violation — now driving a wave of new California class actions. Posting a policy isn’t much of a privacy protection; not posting one now carries real legal exposure. — legal analysis

    Removing a police department’s Flock contract does not touch this commercial layer at all.

    What Action Looks Like

    The Week of Action is decentralized by design — no single event, but community organizing, public records requests, council testimony, and camera mapping happening in parallel across the country.

    The New Yorker followed activists conducting a public “spy hunt” in Atlanta, mapping camera locations with the DeFlock tool. The Muslim Justice League’s Massachusetts coalition work reflects a much broader statewide pattern: at least nine of the roughly 106 Massachusetts communities that had contracted with Flock have recently cut ties, including Cambridge, Framingham, and Salem. Framingham let its contract lapse in June after a 700-person resident campaign; the police chief there confirmed Flock had been used in about 200 cases over four years. — Boston Institute for Nonprofit Journalism; Boston Globe

    The New York Times profile adds a fitting example of individual-level organizing: DeFlock, the crowdsourced camera-mapping app, was created by software engineer Will Freeman after he kept noticing cameras on a cross-country drive. The app has been downloaded more than 350,000 times and has mapped some 125,000 readers nationwide. Freeman, who now lives in Boulder, requested his own camera records from Boulder police, was refused, and filed suit in May arguing the camera network amounts to an unconstitutional “warrantless surveillance dragnet.” — The New York Times

    1. Retention limits — How long is data kept, and is that limit enforced technically — not just on paper?
    2. Outside-search logging — Is every access by another agency logged in a way the public or an auditor can actually review?
    3. Contract closeout verification — When a contract ends, is deactivation confirmed independently, not just assumed? Pleasanton (Section Two) is the cautionary example.

    The ACLU’s national campaign hub and its companion guide on fighting ALPR deployment locally both go further, with model contract language and legislative approaches.


    Join Us: Surveillance in Our Community

    Surveillance in Our Community — A Community Conversation. August 19th, 5:00pm, Central Library, 61956 SE Santorini St, Bend, OR 97702. Join the conversation. Community education event during the ALPR National Week of Action.

    Wednesday, August 19 · 5:00–7:00 PM · Central Library, Bend
    61956 SE Santorini St, Bend, OR 97702

    Bend Privacy Alliance invites Central Oregon readers to join the conversation — what local technology collects, who has access, and why oversight matters. A community education event during the ALPR National Week of Action.

    Event Details & Registration


    Signals & Safeguards is the newsletter of Jonathan Westmoreland, founder of Bend Privacy Alliance · jonathanwestmoreland.com · Published August 12, 2026.
    All underlined source names in this edition are clickable links to the original reporting.

  • Signals & Safeguards Issue 18: Flock’s FreeForm Search, New Orleans’ Weaponized-Drone Draft, and Federal Grants as Policy Instruments

    Signals & Safeguards

    Issue 18 • Wednesday, July 29, 2026

    A concise biweekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a Glance

    • Police used Flock’s FreeForm feature to search camera footage for people by clothing, tattoos, body type, race, political indicators, and other natural-language descriptions—not merely by license plate.
    • A New Orleans police-drone draft contemplated weapons with written approval from the superintendent while the city was funding a Skydio expansion; public scrutiny preceded an explicit prohibition.
    • Justice Department grant policy gives priority consideration to jurisdictions that cooperate with federal immigration enforcement, showing how funding conditions can redirect local institutions.
    • Cyberattacks reached more than 30 Minnesota water systems, while an Oregon audit warns that obsolete corrections systems create extreme operational and human-safety risk.
    • Axon’s July release adds conversational AI evidence analysis and a consolidated audit trail spanning Evidence, ALPR, Aware, CCTV, cases, devices, and other systems.

    Flock FreeForm changes what an ALPR network is

    Police departments have used Flock Safety’s FreeForm search feature to search camera footage for people rather than known license plates. According to data reviewed by 404 Media, officers entered natural-language descriptions involving clothing, tattoos, body type, skateboards, construction attire, race, and possible political affiliation. Some searches reportedly queried hundreds of cameras. Flock’s own product page says FreeForm combines natural-language search, video and LPR workflows, cross-agency access, and configurable alerts.

    That changes the functional category of the system.

    Traditional automated license plate recognition begins with a known or suspected plate and asks where that vehicle appeared. FreeForm can begin with a description and ask the system’s AI and image-recognition tools to identify footage that may match. A network approved as a vehicle-location system can therefore become a retrospective search engine for people, appearance, behavior, and association without adding a new camera.

    A city may have evaluated ALPR under rules governing stolen vehicles, wanted plates, parking, or specific investigations. Officials may never have been asked whether officers should be able to search hundreds of cameras for a “heavy-set male,” a person in political clothing, or someone carrying a particular object. Yet software can make those searches possible after the hardware is already installed.

    The accuracy problem also changes. A plate query begins with a relatively specific identifier, even though misreads still occur. A natural-language search depends on how software interprets broad visual attributes. Clothing changes. Body type is subjective. Race may be perceived inaccurately. Political affiliation may be inferred from a shirt, sticker, flag, or event rather than established by fact. A ranked result can look investigative while still containing many people who merely resemble a description.

    Why it matters for public officials: A contract for license-plate matching should not become standing permission to search people by appearance.

    Before enabling FreeForm or similar semantic search, an agency should document the suspected offense, factual basis, case number, approving supervisor, exact search language, cameras and networks queried, complete result set, corroboration, and final disposition. Searches based solely on race, religion, political association, or lawful expressive activity should be prohibited.

    The procurement question is simple: Did officials approve a plate-reader system, or did they approve a general-purpose visual search network? If the answer changed through software, the approval process should begin again.

    A surveillance drone should not become a weapons platform by administrative approval

    A New Orleans Police Department drone manual dated June 21 said small drones could carry weapons with written approval from the superintendent of police. Local reporting by Verite News links both the June draft and the July 1 replacement policy, which prohibits weapons and hazardous materials.

    The current prohibition matters. It does not erase the governance warning.

    The June draft appeared while the department was seeking money to expand its Skydio Drone as First Responder program in the French Quarter. On June 24, the City Council approved $250,000 for the expansion by a 4–3 vote. Advocates then alerted council members to the weapons language. The draft disappeared June 30. The operative manual dated July 1 now says drones may not carry weapons or hazardous materials, and NOPD says it does not and will not weaponize them.

    A formal police manual nevertheless contemplated converting surveillance aircraft into potential use-of-force platforms through written authorization from one police official. That is a categorical change. A drone used to observe, map, record, or arrive before officers is not the same system once it can carry a firearm, explosive, chemical agent, electrical weapon, impact munition, or another force payload.

    No new aircraft may be required. The transformation can occur through policy language, payload selection, software, and administrator permission.

    A funding vote should therefore not function as indirect authorization for every capability the hardware could support. A city ordinance should prohibit police drones from carrying or deploying weapons or payloads intended to injure, incapacitate, threaten, or compel a person. It should also prohibit autonomous target selection and autonomous use of force.

    Any proposal to change that rule should require advance publication, a public hearing, legislative approval, a civil-rights and use-of-force analysis, independent technical testing, and reporting after every deployment. A superintendent’s written approval should not be enough.

    Shared pattern: Flock FreeForm and the New Orleans draft show the same institutional problem. The public approves one category of technology while later software, payload, or policy decisions move it into another.

    “What in the past was ‘unknowable’ suddenly becomes open to view, presenting formerly unimaginable privacy concerns.”

    — Justice Elena Kagan, majority opinion, Chatrie v. United States (2026)

    Federal funding preferences can change what local police are asked to do

    The Justice Department’s 2026 COPS grant framework does more than distribute money. In its announcement of nearly $700 million in grant opportunities, DOJ states that state and local governmental applicants must comply with 8 U.S.C. § 1373. It also says priority consideration will go to jurisdictions that cooperate with federal immigration enforcement and coordinate and participate with the Homeland Security Task Force.

    The condition is not confined to a general press release. The FY 2026 COPS Hiring Program page—covering up to $157.5 million for hiring and rehiring officers—repeats the § 1373 requirement. COPS pages for programs including Community Policing Development Microgrants carry similar language. DOJ’s grant index identifies each program and opportunity number.

    The specific requirements vary by program, and each Notice of Funding Opportunity must be reviewed before assuming that every grant carries identical conditions. But the broader policy is explicit: immigration cooperation can improve a jurisdiction’s position when competing for federal law-enforcement money.

    That can redirect local institutions without changing their hardware.

    A police department may apply for officers, training, crisis response, technical assistance, or technology. The public discussion may focus on staffing or crime reduction. Yet scoring preferences, certifications, task-force participation, and information-sharing obligations can influence what the department does, which federal priorities it supports, and which local records become useful to outside agencies.

    For Oregon officials, the questions are immediate. What kind of immigration cooperation earns priority consideration? Must the applicant join or coordinate with a federal task force? Would participation expand federal access to jail, dispatch, identity, address, ALPR, or investigative records? Who determines whether the application complies with Oregon sanctuary statutes? What happens if grant conditions change after award? Does the governing body approve the relationship before staff submit the application?

    A grant is not merely revenue. It is a policy instrument.

    Before applying for or accepting federal public-safety funding, a local government should publish a grant-impact statement identifying every scoring preference and certification; task-force and information-sharing obligations; technology or database access funded by the award; conflicts with state law or local policy; long-term operating costs; and conditions for suspension, repayment, or termination.

    More than 30 Minnesota water systems were targeted

    A coordinated cyberattack targeted more than 30 Minnesota community water systems on July 26 and 27.

    Minnesota IT Services said investigators identified unauthorized access with malicious intent. The FBI contacted affected entities. No statewide request was issued for residents to change their drinking-water use.

    In Braham, malicious activity shut down computerized operating controls, temporarily stopping a well and water-treatment plant. The city’s official update and local reporting from CBS Minnesota said there was no physical damage and no effect on water quality or safety.

    Attribution remains unresolved. Similarity to earlier activity associated with Iranian-linked actors is not proof of responsibility.

    The episode shows how a cybersecurity failure can cross into physical public service. Community water systems often combine aging operational equipment, limited staffing, remote vendor access, internet-facing interfaces, shared or default credentials, incomplete logs, and dependence on automated controls. Restoring a screen or restarting a plant does not by itself prove that an intruder no longer has access.

    Public officials should ask what would happen if automated controls were unavailable for an hour, a day, or a week. The answer should include manual operation, staffing, communications, water-quality verification, and the evidence needed before returning the system to normal service.

    Oregon Watch: obsolete corrections IT could fail where safety depends on it

    A July Oregon Secretary of State audit warns that the Department of Corrections relies on obsolete information systems that create operational, security, and human-safety risk. The technology findings begin in Chapter 3, page 21, and the audit page provides the full report and DOC’s formal response.

    The audit examined the Corrections Information System and Offender Management System, which support round-the-clock operations across Oregon, including parole and probation work in all 36 counties.

    Auditors found inefficient and paper-based processes, antiquated interfaces, and outdated programming languages that make the systems difficult to maintain or update. The audit says DOC faces “extreme risk” that it may be unable to implement critical enhancements or recover effectively after system failure. The consequences for incarcerated people and correctional staff could be severe.

    This is not simply an old-computer problem. Corrections systems affect custody, movement, supervision, staffing, institutional security, rehabilitation, and decisions about people’s lives. If records become unavailable or unreliable, officials need to know which functions fail first, how long institutions can operate safely, which manual processes exist, and whether recovery restores complete and accurate information.

    The audit recommends that DOC mitigate organizational, operational, and security risks and conduct an exercise simulating catastrophic failure of the Corrections Information System. DOC agreed, but major target dates extend into 2029.

    Shared pattern: Public systems can be redirected by funding conditions or disabled by neglected infrastructure. In both cases, elected officials need to understand the operational commitment before an award or crisis makes the decision for them.

    “No one, perhaps not even the President, knows the limits of the power he may seek to exert in this instance, and the parties affected cannot learn the limit of their rights.”

    — Justice Robert H. Jackson, concurring, Youngstown Sheet & Tube Co. v. Sawyer (1952)

    Warning Signals

    Warning Signals

    Early indicators of how capabilities expand through software, interfaces, funding, and policy before public oversight catches up.

    Axon Watch: Lead Lock changes how agencies search evidence

    Axon’s July 2026 release notes introduce Lead Lock, an AI-powered evidence-review tool inside Axon Evidence.

    Once enabled, Lead Lock can index supported PDFs, audio, and transcribable video within a case. Investigators can ask natural-language questions, identify entities, flag possible inconsistencies, draw connections across evidence, and receive citations back to source material. Axon’s Lead Lock overview says the tool respects existing evidence permissions and does not replace investigator judgment or make legal conclusions.

    Administrators can enable or disable chat history and set the AI index to remain for 30, 60, or 90 days. Axon says Lead Lock activity is logged in the Audit Trail. Its usage guide says users must copy important findings into case notes or reports if they need a permanent record.

    Those details create questions ordinary evidence-retention policies may not answer. What exactly is deleted when the AI index expires? Does source evidence remain while embeddings, extracted entities, or other derived material disappear? Are prompts, answers, citations, exports, and deleted chat histories retained? If chat history is disabled, what record remains for later review?

    Axon’s July release also introduces a Unified Audit Trail consolidating activity from Agency, Aware, CCTV, ALPR, Evidence, Cases, Devices, and Groups. That may improve review, but the product guide says only six months are displayed directly and older material must be exported. The consolidated export is PDF.

    A unified view is not automatically a complete or independent audit system. Agencies should know who can view the trail, what activity is hidden by default, how long records are retained, what machine-readable exports exist, and whether vendor staff or administrators can alter visibility or classification.

    Other July changes matter as well:

    • “Reason for access” can be required before users view evidence.
    • AI Case Search can rank evidence containing weapons, vehicles, apparel, objects, and drug paraphernalia.
    • Searchable document text now extends to PDFs and Word files.
    • Records and Standards logs add exact search keywords, IP addresses, browser-level device information, and clearer records of full-document access.

    Council question: Which Axon capabilities are available, licensed, enabled, tested, planned, or prohibited locally—and what record shows who activated each one?

    The safeguard is to require a current feature inventory and fresh review before enabling analytical tools that change the meaning of evidence search. Product availability is not authorization.

    Texas and New York show why “age verification” is too broad a label

    The Fifth Circuit’s July 24 ruling on Texas’s SCOPE Act and New York’s final SAFE for Kids rules address different mechanisms that are often grouped under one label.

    Texas’s law includes account-age registration, age verification for certain harmful-content services, advertising restrictions, parental controls, and monitoring-and-filtering duties. The Fifth Circuit held that trade groups were likely to succeed in showing that the monitoring-and-filtering requirement was preempted by Section 230. Other challenges failed for standing or were foreclosed by precedent.

    New York’s final SAFE for Kids regulations govern algorithmically personalized feeds and nighttime notifications for users under 18 without parental consent. The official rule text distinguishes age estimation, age inference, and age verification; requires certified methods and annual testing; requires an appeal process; and limits how age-assurance data may be used and retained. The rules take effect January 25, 2027.

    Legislators should separate the mechanisms:

    • What threshold must be proved?
    • Must every adult participate?
    • Is the method identification, estimation, attestation, device-based inference, or parental approval?
    • What information is collected and retained?
    • Can it be reused for advertising, account linkage, or government access?
    • How are errors corrected?
    • What product features change after classification?

    New York’s rule requires at least one alternative to government identification, permits zero-knowledge proof approaches, and says information collected for age assurance or parental consent may not be reused for another purpose. The strongest design proves only the necessary threshold and then forgets the underlying evidence.

    Oregon’s privacy leadership needs enforceable authority

    On July 21, Oregon Enterprise Information Services appointed Michael Hanna-Butros Meyering as chief privacy and communications officer, while Nik Blosser now focuses on AI as chief AI officer.

    The state’s Enterprise Privacy Guidance includes purpose limitation, data minimization, accuracy, security, redress, and accountability. But Oregon describes the guidance as optional and recommended.

    A title assigns responsibility. Mandatory review gates, authority to require correction, and power to stop unsafe processing make that responsibility enforceable.

    “The Court is obligated—as subtler and more far-reaching means of invading privacy have become available to the Government—to ensure that the progress of science does not erode Fourth Amendment protections.”

    — Chief Justice John G. Roberts Jr., majority opinion, Carpenter v. United States (2018)

    Safeguards

    Safeguards

    The strongest protections this issue attach oversight to material changes in capability, configuration, funding, and operational dependence.

    Require fresh approval when capability changes

    A new approval process should be triggered when a system gains a new search mode, data source, integration, payload, use-of-force function, AI model, inference capability, automated alert, sharing pathway, or physical operational effect.

    The trigger should follow actual capability, not the product name.

    Attach the live configuration to the public decision

    Approval records should include the current feature inventory, architecture and data-flow diagram, administrator roles, sharing settings, search capabilities, retention schedule, audit fields, prohibited uses, and change-control process.

    Require notice and approval before pilots, software updates, license changes, payloads, integrations, or administrator settings materially expand what the system can do.

    Make logs useful outside the vendor dashboard

    Require machine-readable exports that preserve exact search terms, user and organization, case number and purpose, legal authority, data sources, result count, exports and sharing, denied attempts, administrator changes, vendor access, and the policy tied to feature activation.

    A PDF summary may be useful for reading. It should not be the only format available for independent analysis.

    Govern grants as policy instruments

    Before accepting public-safety funding, disclose scoring preferences, certifications, task-force obligations, information sharing, surveillance or analytical technology, state-law conflicts, long-term staffing and operating costs, and termination or repayment consequences.

    A governing body should approve the operational commitments, not only the budget amendment.

    Plan for physical and human consequences

    Failure exercises should ask not only whether data can be restored, but who may be harmed; what decisions become unreliable; what manual fallback exists; how long safe operation can continue; who can suspend the system; and what evidence proves the environment is safe again.

    Bottom line

    The most important changes in Issue 18 did not require a visibly new system.

    Flock added a search method that can look for people rather than known plates. A New Orleans draft contemplated turning observation drones into weapons platforms through police approval. Federal grants use eligibility and priority rules to influence local enforcement. AI changes what investigators can extract from evidence already stored. Obsolete software creates new risk simply by becoming harder to maintain and recover.

    Public approval must therefore follow capability, not product labels.

    The practical questions are: What can the system do now that it could not do when officials approved it? Who authorized the change? What new data, payload, search, or consequence did it add? What does the system prevent and record? Can an independent reviewer reconstruct what happened?

    A safeguard should attach to every material change—not only to the original purchase.

    “With all its defects, delays and inconveniences, men have discovered no technique for long preserving free government except that the Executive be under the law, and that the law be made by parliamentary deliberations.”

    — Justice Robert H. Jackson, concurring, Youngstown Sheet & Tube Co. v. Sawyer (1952)
  • Signals & Safeguards Issue 17: Flock’s Trust Problem, New Jersey’s Data-Broker Law, and Redmond’s Bundled Surveillance Contract

    Signals & Safeguards

    Issue 17 • Wednesday, July 15, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a Glance

    • LAPD’s audit findings and continuing Flock contract dispute show why surveillance-vendor assurances must be converted into configurations, logs, and contract terms that an independent reviewer can test.
    • The Seventh Circuit rejected Clearview AI’s unusual biometric settlement because differently situated class members did not have adequate representation.
    • New Jersey prohibited sales of sensitive data, while new research shows why privacy rights still fail when each data broker controls its own opt-out and deletion process.
    • Redmond’s $410,762.16 Axon award includes six Skydio drones, 38 vehicle fleet-camera upgrades, and DroneSense livestreaming—and the department already operates fixed Axon plate readers—showing why bundled technology contracts need a complete capability and data-flow inventory.

    Flock’s trust problem is now a governance problem

    The American Civil Liberties Union has assembled a national record of instances in which it says Flock Safety gave police departments, elected officials, or the public inaccurate or misleading accounts of how its automated license plate reader network operates. The July 2 analysis points to disputes involving federal access, national searches, product capabilities, camera status, sharing settings, and vendor control.

    The document is advocacy, not an adjudication. Its most serious examples should therefore be read alongside underlying records and the affected jurisdiction’s response. But the pattern matters even before every disagreement is resolved. A surveillance vendor is not selling an ordinary office product. Its descriptions can determine whether officials approve deployment, what a policy prohibits, what the public believes is possible, and whether a later audit is designed to detect the right risks.

    Issue 16 described how Woodburn learned that its cameras had appeared in broad outside-agency searches through a pilot architecture city officials said they had not knowingly approved. The broader warning is that officials cannot assume contract language, dashboard labels, or a verbal assurance fully describe the live system.

    That problem is especially serious in a networked platform. A local agency may control its own users while the vendor controls hosting, software updates, administrator privileges, integrations, federation rules, default settings, and the practical meaning of a feature name. A city may prohibit national sharing yet remain exposed through a pilot, external search path, inherited configuration, support account, or later product update.

    The clearest example arrived in Los Angeles. In a review of two months of LAPD automated-license-plate-reader activity, the Los Angeles Police Commission’s Office of Inspector General found that ALPR activity contributed to recovery of 337 stolen vehicles. It also identified 161 alerts that officers initially treated as matches to stolen vehicles but that later proved inaccurate. That is not a general error rate across every plate scanned, and the public report does not establish that every inaccurate alert resulted in a vehicle stop.

    The review covered LAPD’s larger, multi-vendor ALPR environment rather than Flock cameras alone. Flock operated 138 pole-mounted cameras within a department-wide network of roughly 2,000 readers. The governance lesson is not that one percentage fully measures one vendor. It is that an independent reviewer could reconstruct alert handling, identify inaccurate matches, and examine data-sharing and contract risks across the system.

    LAPD then allowed its three-year Flock agreement to expire and suspended ordinary access while negotiating stronger terms involving privacy, security, data ownership, and sharing. The Los Angeles Times reported on July 14 that negotiations continue, so the lapse should not be treated as a final decision to abandon Flock. The Police Commission separately supported suspending new Flock deployments and contracts pending additional oversight and public input.

    This is why public bodies should treat material vendor representations as testable contract requirements. Before approval, officials should require a live demonstration of every sharing and administrator screen, a diagram of all local, outside-agency, vendor, and subprocessor access paths, and an export showing the exact audit fields generated by each action.

    The contract should attach the approved configuration, prohibit silent changes, and require written notice and affirmative approval before a pilot, integration, network expansion, administrator role, or new search mode touches local data. It should require preservation of evidence when a disputed representation arises and permit independent technical review. A vendor’s failure to produce the agreed audit evidence should itself be a material breach.

    Why it matters for public officials: Oversight cannot depend on asking the same company that designed the system whether the system complies. The agency needs technical controls and records that allow someone else to reconstruct what happened.

    A practical verification test: Can the agency independently identify every person and organization that searched, viewed, exported, shared, administered, or changed the system—including vendor staff—and can it prove that prohibited access was technically blocked rather than merely discouraged by policy?


    Clearview settlement fails on who represented the class

    The U.S. Court of Appeals for the Seventh Circuit has vacated approval of an unusual nationwide settlement involving Clearview AI. Instead of conventional cash relief, the agreement would have given class members a financial interest tied to about 23 percent of the facial-recognition company’s future value.

    The court did not hold that an equity-like remedy is inherently improper, and it did not decide the underlying biometric-privacy claims. It also did not require additional injunctive relief. The decisive problem was procedural: the settlement created much larger potential benefits for favored state-law subclasses, but the nationwide class lacked representatives who could adequately protect the interests of people in those different groups.

    The case now returns to the district court. The policy conflict remains important. A privacy remedy should compensate affected people and constrain unlawful conduct without making their recovery depend on the future commercial success of the very surveillance practice being challenged.

    For public officials, the lesson is not limited to class actions. Remedies should be evaluated operationally: What conduct stops? What data are deleted? What future collection is restricted? Who receives compensation? Who can enforce the agreement? A settlement can be creative without being accountable.

    “We cannot get past a key procedural problem in the settlement process.”

    — U.S. Court of Appeals for the Seventh Circuit, In re Clearview AI, Inc. Consumer Privacy Litigation (2026)

    New Jersey moves upstream—but privacy rights still need a working compliance system

    New Jersey enacted A5328 on June 30 as P.L. 2026, c.25. The law prohibits selling, offering to sell, or licensing sensitive data and directs the state to create a public registry for data brokers and a newly defined category of data collectors.

    The sensitive-data sales prohibition took effect immediately. The registry provisions are delayed for 270 days and are scheduled to become operative on March 27, 2027. That timing distinction matters: New Jersey has already made the upstream policy choice that covered sensitive information cannot be sold, even though the registration system is not yet operational.

    The prohibition is structurally important because it applies regardless of how many consumers’ records an entity controls or processes and regardless of whether the seller would otherwise fall within the New Jersey Data Privacy Act’s usual thresholds. That avoids a common weakness in privacy statutes: numerical thresholds that leave smaller but highly sensitive datasets outside the rule.

    The law’s definition of sensitive information reaches categories that can expose a person’s body, beliefs, associations, movements, and vulnerability. The precise exceptions, registration disclosures, fees, and enforcement provisions will matter in implementation, but the central policy choice is clear: some data should not become a commercial product merely because a company can collect or infer it.

    This advances the data-broker discussion from Issue 16. A warrant requirement or procurement restriction controls the government buyer. A sales prohibition controls the market that supplies the buyer. Neither approach is complete by itself.

    If government cannot compel sensitive location information without judicial process but can buy a commercially assembled substitute, constitutional protection becomes dependent on the acquisition route. If a state prohibits government purchases but permits unrestricted commercial sale, the same information remains available to private investigators, employers, insurers, landlords, political operatives, abusive partners, and intermediaries that may later sell to government.

    An upstream rule also reduces the burden placed on individuals. A person should not have to identify hundreds of hidden companies, submit separate requests, disclose more identity data, and repeatedly opt out of a market they never knowingly joined.

    Rights on paper still fail at the doorway

    A July UC Irvine study using synthetic identities found that opt-out and deletion processes among California-registered data brokers remained inconsistent, burdensome, and sometimes ineffective. Researchers reported nonresponses, intrusive verification demands, and substantial variation in how requests had to be submitted. These are research findings rather than enforcement judgments, but they test what consumers actually encounter when trying to use rights that exist on paper.

    A separate large-scale study of registered brokers found that only 9 percent of 522 brokers were fully compliant with transparency requirements. In an audit of 250 consumer-request processes, 43 percent made it impossible to exercise all privacy rights and 64 percent introduced at least one feature that created substantial friction.

    Together, the studies illustrate a recurring design failure: the regulated company controls the doorway through which a person must pass to invoke the right against that company.

    The consumer may not know the broker exists. The broker may demand identity documents that create new risk. Names, addresses, emails, and phone numbers may not match the records the broker bought. A deletion request may remove one profile while another affiliate, source, or later purchase recreates it.

    The better model is centralized and testable. California’s Delete Request and Opt-Out Platform provides a developing example: one verifiable request can direct registered brokers to delete covered information, with broker processing requirements beginning August 1, 2026. A state can also prohibit unnecessary identity collection, publish response rates, conduct regulator-run test requests, and impose consequences when firms do not respond or reacquire deleted data.

    Officials should distinguish deletion from suppression. A company may stop displaying a profile while retaining data, hashes, linkage keys, derived attributes, or source relationships that allow the profile to reappear. A meaningful deletion standard should specify what must be erased, what may be retained for legal compliance, how downstream recipients are notified, and how completion is certified.

    A registry should make the market inspectable

    A useful registry should identify each broker’s legal and trade names, parent and affiliates, categories of data collected, original sources, customer categories, sensitive-data practices, government clients, opt-out and deletion methods, retention periods, security incidents, and whether the company honors universal opt-out signals.

    Registration alone is not validation. Regulators should compare claims against sample transactions, consumer requests, website behavior, contracts, and technical data flows. Repeated failure should lead to escalating penalties, suspension from the market, and notice to downstream customers.

    Public agencies should consult the registry before purchasing or accepting commercially sourced data. Procurement files should identify the original collector and every intermediary, not merely the company that signed the government contract.

    The combined safeguard: Restrict collection and sale of sensitive data upstream; require a warrant or equivalent judicial process for government acquisition downstream; and prohibit contractors or partner agencies from doing indirectly what the public body may not do directly.


    The larger risk is what happens when separate databases become one system

    A July 9 Brennan Center report warns that federal agencies are increasingly linking government records with commercially acquired location, biometric, financial, social-media, and other personal information. The report describes the Department of Homeland Security as an emerging hub for this consolidation and says AI-assisted analysis can turn records collected for unrelated purposes into searchable profiles of people’s movements, relationships, beliefs, and activities.

    The warning reaches state and local government. Driver’s-license, benefits, voter-registration, law-enforcement, and other records may be requested or shared for purposes far removed from the reason they were originally collected. Protecting one local database is not enough if its contents can become an input to a much larger federal or commercial system.

    Why it matters for public officials: Data-sharing agreements should state the permitted purpose, prohibit onward transfer and unrelated reuse, require notice and audit records for outside requests, and allow access to be suspended when the receiving agency changes how the information will be used.

    Flock shows why officials need visibility into a vendor’s network and administrator actions. Clearview shows why a remedy must fairly represent differently situated people. Data-broker regulation shows why the original collector and every intermediary matter. Data consolidation shows why risk grows again when once-separate records become one searchable system.

    In each case, accountability fails when review stops at the nearest interface: the local dashboard, the named defendant, the final seller, or the written policy. The safeguard must follow the system from collection through processing, sharing, decision, remedy, and deletion.

    Data minimization includes separation: Before linking systems, document the original purpose and legal authority for every dataset, the people and agencies receiving access, the risks of inaccurate matches, and the conditions for ending the connection.


    Local Watch

    A closer look at how a bundled local purchase connects drones, vehicle cameras, license-plate readers, and livestreaming.

    Redmond adds drones and fleet cameras to an existing Axon surveillance ecosystem

    On June 23, the Redmond City Council approved a five-year, $410,762.16 award to Axon Enterprises and Skydio. The official council packet, pages 76–77, describes two Skydio R10 indoor drones, four Skydio X10 outdoor drones, software for livestreaming and integration with patrol and SWAT operations, and 38 Axon vehicle fleet cameras. The vehicle cameras will expand patrol-car coverage from two views—front-facing and rear-seat—to three by adding a rear-facing camera.

    The agreement also provides for six new drones at the 30-month mark while allowing Redmond Police to retain and use the original six. If the first group remains operational, the department could have as many as 12 Skydio aircraft after the refresh rather than simply exchanging old equipment for new.

    The staff report identifies $100,000 in General Operating Fund reserves for implementation. The remaining payments are scheduled unevenly: $70,256.02 in fiscal year 2026–27, $8,265.41 in 2027–28, and $110,746.91 in each of the following three fiscal years. Because the public packet contains the police staff report rather than the executed agreement and itemized vendor quote, it does not disclose every software license, storage term, administrator role, or data-control provision included in the award.

    The purchase sits inside a larger Axon environment

    Redmond Police already uses Axon body-worn cameras, vehicle cameras, interview-room cameras, Evidence.com, and fixed license-plate-reader cameras, according to the staff report. The new award therefore adds drones and expanded vehicle-camera coverage to an existing evidence and plate-reader environment rather than creating a stand-alone UAS program.

    That distinction matters because surveillance capabilities can be shaped by how separate tools work together. A fixed plate reader may identify a vehicle and location; dispatchers or officers may then use patrol cameras or a drone to follow the response. The staff report does not say that Redmond currently connects fixed-LPR alerts to drone deployments, but both systems are now part of the department’s technology environment and should be governed as a combined workflow when they interact.

    Skydio says the X10’s VT300-Z telephoto package can resolve a license plate from approximately 800 feet under suitable conditions. That is an optical capability: the camera may capture an image in which a plate is legible. It is not, by itself, automated plate recognition, optical-character recognition, or a database search.

    Skydio separately describes drone-response systems that can receive alerts from third-party ALPR platforms. In that type of workflow, the fixed reader produces the plate match and the drone supplies aerial observation. Public records should make clear whether Redmond has enabled such a connection, what legal and policy rules apply, who may authorize a deployment, and what audit trail links the original plate alert to the drone mission.

    DroneSense carries the livestream

    The staff report names DroneSense as the livestreaming platform used by Redmond Police and SWAT during critical incidents and investigations. Redmond’s published UAS information says the department does not store data obtained by a UAS in third-party storage and has no UAS data-sharing agreements with outside agencies.

    Livestreaming through a third-party platform does not necessarily mean that the provider permanently stores the video. It does mean the department should publicly document how the stream is secured and handled: whether DroneSense buffers or retains video or metadata; who can receive a stream; whether recipients can record it; how viewers are authenticated; whether access expires automatically; what viewer logs are created; and where flight telemetry, operator identity, and incident metadata are stored.

    The same records should show whether completed drone recordings enter Evidence.com, whether live feeds can be viewed through an Axon command interface, which company controls administrator settings, and how access is revoked when an incident ends.

    San Francisco shows the risk of weak sharing controls

    A recent San Francisco incident demonstrates why those details matter even when a department has a written security policy. WIRED reported that live feeds from five San Francisco Police Department drones were reachable through a public Skydio ReadyLink without a password or authentication code. The feeds included color and thermal video, real-time location information, and the names and email addresses of drone pilots.

    Researchers archived about 48 hours of activity: 60 videos from 20 flights showing detentions, searches, apartment windows, rooftops, streets, courtyards, unhoused people, and many bystanders who did not appear to be subjects of an investigation. The link had been set to remain active for a year and may have exposed the feeds for roughly six months.

    ReadyLink is not the platform named in Redmond’s staff report; Redmond identifies DroneSense. The control lesson nevertheless applies to any livestreaming system. Authentication, named recipients, short expiration periods, complete viewer logs, and automatic revocation should be mandatory defaults rather than options left to the person creating a link.

    The federal transition should be described precisely

    Redmond’s existing drone fleet includes foreign-manufactured Autel and DJI aircraft. The staff report cites the American Security Drone Act and related National Defense Authorization Act provisions as the reason for moving to U.S.-manufactured Skydio equipment.

    The federal restrictions are narrower than a general ban on commercial sales of all foreign-manufactured drones. Federal acquisition rules restrict federal agencies from procuring or operating covered systems and, beginning December 22, 2025, restrict the use of federal funds to procure or operate prohibited systems, subject to exceptions and waivers. Moving away from Autel and DJI may preserve federal-funding eligibility and reduce the risk that existing aircraft become harder to support, but the legal rule should not be described as a universal sales ban.

    Why it matters locally: Redmond’s award adds indoor and outdoor drones and 38 vehicle cameras to an environment that already includes fixed Axon plate readers, Evidence.com, and DroneSense livestreaming. Oversight should focus on the combined data flows and operational workflows, not only on the label attached to each product.

    Before fixed-LPR alerts are connected to drone response, live-feed access is expanded, storage or retention changes, remote or docked operations begin, or automated analysis is added, Redmond should require public notice, documented legal review, and approval proportionate to the new capability.

    Local verification test: Can Redmond produce the executed agreement, complete product and license inventory, data-flow diagram, fixed-LPR integration map, livestreaming settings, retention rules, viewer logs, and approval history needed to show that the combined system matches its published UAS commitments?

    “There’s a certain trust given to the police to use these things correctly.”

    — Security researcher Sam Curry, quoted by WIRED (2026)

    Warning Signals

    Warning Signals

    Early indicators of how connected systems, software transitions, and delayed maintenance can expand risk before policy catches up.

    Axon Watch: July 31 transition brings AI oversight questions

    Axon says that on July 31 the legacy Axon Evidence experience will be deprecated and the redesigned interface will become the only version available. The deadline does not establish that any AI product will automatically be licensed or enabled for Bend. Availability may depend on licensing, configuration, rollout status, and agency activation.

    But a mandatory interface change is still an oversight point. Officials should request a current feature inventory showing every AI-assisted capability available, licensed, enabled, or planned; the evidence it can analyze; the output it creates; retention and sharing; model providers and subprocessors; audit fields; human-review requirements; and whether activation requires notice, legal review, or Council approval.

    Council question: Which Axon capabilities will be available to Bend after July 31, which are enabled, and what record will show when a new analytical or AI-assisted function is activated?


    A federal information-sharing network was breached after warnings were twice dismissed

    According to Nextgov’s account of an internal Department of Homeland Security incident readout, intruders accessed the Homeland Security Information Network, a platform used to share sensitive but unclassified records with federal, state, local, and international partners, after analysts twice concluded that suspicious activity was a false positive. By the time officials declared a breach, the intruders had installed hidden backdoors and stolen credential files. Public reporting has not established exactly what information was obtained from HSIN.

    The same architecture that lets many agencies exchange information also lets one successful intrusion reach every connected partner. Any agency using a federal or regional sharing network should know who can close an alert, what independent verification occurs before suspicious activity is dismissed, and how partners are notified when the network may be compromised.


    Active exploitation turns maintenance into an emergency

    CISA warned on July 14 about active exploitation of Microsoft SharePoint vulnerabilities and urged organizations to harden affected systems. A vulnerability bulletin becomes a safeguard only when someone knows which systems are affected, has authority to act immediately, verifies that mitigation was completed, and checks whether attackers gained access before the patch.


    Safeguards

    Safeguards

    The strongest protections this week turn assurances into evidence, keep connected systems visible, and establish what happens when technology does not perform as promised.

    Turn vendor promises into enforceable specifications

    Attach the approved configuration, architecture diagram, sharing settings, administrator roles, audit fields, feature inventory, and data-retention schedule to the contract. Require a live demonstration before deployment and after material updates. A statement such as “national sharing is off” should identify every technical pathway the phrase covers, including pilots, federated searches, vendor support accounts, integrations, and inherited defaults.

    Require written notice and affirmative approval before a pilot, integration, new administrator role, subprocessor, network expansion, or policy-changing default touches local data. Preserve both the old and new configuration so reviewers can identify exactly what changed, who approved it, and when the change took effect. Contract remedies should include suspension, corrective work, fee recovery, and termination when a material representation proves false.

    Give the agency independent evidence

    The agency should be able to export complete, tamper-evident logs without vendor assistance. Logs should identify the user and organization, date and time, case number, purpose, legal authority, search terms, datasets, result count, exports, sharing, denied attempts, vendor access, administrator changes, and final disposition.

    The log format and required fields should be contract deliverables rather than whatever a dashboard happens to display. Assign someone outside day-to-day use of the system to review records on a fixed schedule, investigate anomalies, and document corrective action. Contract for independent technical testing, incident preservation, audit cooperation, and meaningful remedies. A vendor’s failure to produce required evidence should itself be a material breach.

    Govern integrations and live links before activation

    Maintain a current diagram of local users, outside agencies, vendor administrators, subprocessors, federated networks, application-programming interfaces, evidence systems, exports, backups, and legal-process pathways. For each route, specify who can authorize access, what purpose is allowed, what data leave the system, how long the connection lasts, and what evidence the action creates.

    Require authentication, short expiration periods, named recipients, viewer logs, and automatic revocation for every live video or data-sharing link. Prohibit public or reusable URLs for police-surveillance feeds and regularly test access from outside the government network. Limit recording and retention to the documented mission; a secure link can still expose unnecessary footage of homes, bystanders, and private spaces.

    Control sensitive data throughout the chain

    Prohibit the sale of sensitive location, biometric, health, communications, and association data upstream. Require a warrant or equivalent judicial authorization when government seeks the same information downstream, regardless of whether it comes from a carrier, platform, advertiser, broker, contractor, or partner agency. Ban indirect acquisition: a public body should not ask another agency or vendor to obtain information it could not lawfully obtain itself.

    Provide one state-run mechanism for access, correction, opt-out, and deletion requests. Define deletion precisely: address source data, derived attributes, linkage keys, backups, downstream recipients, later reacquisition, and certification. A profile that silently reappears was not meaningfully deleted. Before combining datasets, document each source’s original purpose, legal authority for reuse, receiving agencies, matching risks, and the conditions for ending the connection.

    Review software capabilities before deadlines and updates

    A mandatory interface transition should trigger a feature and policy review. Identify every analytical or AI-assisted tool available, licensed, enabled, or planned; the data it can ingest; the output it creates; retention and sharing; model providers and subprocessors; auditability; and the human decision that remains accountable.

    Do not treat interface availability as authorization. New summarization, search, identification, prediction, streaming, remote-operation, or automated-dispatch capabilities should require documented legal review and approval proportionate to their effect. The system should record who activated each feature, the governing policy, the effective date, and whether the feature can be disabled without losing access to unrelated functions.

    Patch, investigate, and plan for failure

    Maintain a current inventory of internet-facing services and unsupported equipment. Assign emergency patch authority, restrict management access, enforce strong authentication, preserve logs, and review for indicators of compromise after active exploitation is announced. Installing an update does not establish that attackers were not already present; agencies should document what was exposed, how far investigators looked back, and why they concluded the environment is safe to return to service.

    For every sensitive system, name who can suspend use, preserve evidence, notify affected people, correct records, commission an independent review, and terminate the contract. Define what must be reported to elected officials and the public after unauthorized access, inaccurate matches, vendor nonperformance, or a policy-changing software update. The morning after an incident is too late to decide who has authority to stop the system.

    Bottom line

    Trust is not an audit. A safeguard exists when an independent reviewer can test the representation, reconstruct the action, identify the responsible person, correct the error, and impose a consequence.

    The common question for Issue 17 is simple: What evidence would prove that the system did what officials were told it would do?

  • Signals & Safeguards Issue 16: Location-Data Warrants, the Data-Broker Loophole, and Proving Safeguards Work

    Signals & Safeguards

    Issue 16 • Wednesday, July 1, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • The Supreme Court held that obtaining even two hours of precise Google Location History is a Fourth Amendment search.
    • Bend strengthened its ALPR policy, but the vendor audits needed to verify compliance had not yet arrived.
    • Bipartisan oversight caused ATF to cancel one commercial-location contract, while the broader data-broker loophole remains.
    • The House passed a broad youth-online-safety package, keeping age checks and data minimization at the center of the debate.

    Using an app is not consent to government access

    The Supreme Court has extended Carpenter‘s protection for cell-phone location records to a more precise form of digital location history – and rejected the idea that a short search or an “optional” smartphone feature falls outside the Fourth Amendment.

    In Chatrie v. United States, police investigating a Virginia bank robbery used a geofence warrant to make Google identify devices near the crime scene. Google first supplied anonymized data for 19 devices. Investigators selected nine for a broader two-hour view, including movement outside the original geofence, and then selected three users whose identities Google disclosed.

    The Court held that police conducted a Fourth Amendment search when they obtained Okello Chatrie’s Location History. That remained true even though the request covered only two hours and the records came from a technology company rather than directly from his phone.

    The majority explained why the information is unlike an ordinary business record. At the time, Location History could record a phone roughly every two minutes, locate it within about 20 meters, and sometimes estimate which floor of a building it occupied. A short slice could expose a home, medical visit, political gathering, school, hospital, or place of worship.

    The Government argued that the period was too brief and that Chatrie had voluntarily enabled the feature. The Court rejected both arguments. Fourth Amendment protection does not begin only after surveillance “goes too far,” and ordinary use of modern apps does not mean that private information is freely available to government.

    The duration issue matters because officers were not following a known suspect for two hours. They were selecting a short interval from an all-encompassing database after the fact. The Court reasoned that a system does not become less intrusive merely because government can use hindsight to choose the most revealing hours. Even one trip can expose a political rally, abortion clinic, criminal-defense lawyer, or other association a person reasonably expects to keep private.

    The Court also rejected an app-by-app version of the third-party doctrine. Google repeatedly prompted users to enable Location History, sometimes warning Android users that devices would not work correctly without it, while not fully explaining the frequency, precision, or potential government access. More broadly, the point of a smartphone is to use apps and cloud services. Sending email, storing photos, or adding a calendar entry should not become blanket consent for government access merely because a company hosts the data.

    The judgment was 6-3. Justice Elena Kagan wrote for five Justices. Justice Neil Gorsuch supplied the sixth vote through a separate concurrence reasoning that digital location history can be a person’s electronic “papers or effects,” even when a company stores it.

    The ruling is important but narrower than saying all geofence warrants are unconstitutional. The Fourth Circuit must still decide whether each stage of this warrant satisfied probable cause and particularity, and whether the good-faith rule affects suppression. Justice Ketanji Brown Jackson, joined by Justice Sonia Sotomayor, would have found at least stages two and three unconstitutional because officers – not a neutral magistrate – chose who received deeper scrutiny.

    Why it matters for public officials: A multi-stage search should not become progressively more intrusive through an internal vendor workflow. A judge should define the narrowing criteria and find probable cause before officials expand the time period, follow devices beyond the original location, or reveal identities.

    Google told the Court that it moved Location History storage from central servers to users’ devices in July 2025 and can no longer respond to this particular centralized demand. The old Google process may be fading, but the Court’s principle reaches a broader question: using an ordinary digital service does not itself surrender constitutional privacy.

    The decision therefore matters beyond geofences. Government databases increasingly allow officials to begin with a place, event, face, plate, device, or pattern and work backward toward a person. The constitutional question is not only whether a warrant exists at the beginning, but whether each material expansion remains tied to probable cause, particularity, and neutral review.


    Bend strengthened its ALPR policy. Now the system has to prove it follows it.

    Bend Police has expanded Policy 428 following Oregon’s new statewide rules for automated license plate readers. The revised policy adds privacy, accountability, and civil-rights language; states that Bend owns its database; and bars use for protected First Amendment activity, federal immigration enforcement, and out-of-state abortion investigations.

    Those are meaningful improvements. The remaining question is whether the technical system and vendor relationship can demonstrate compliance. Oregon law requires 30-day and quarterly vendor audits that agencies must publish promptly after receiving them. As of the June 29 reporting, Bend had not received the required reports from Axon and was working with the company on automated delivery.

    Until the audits exist, the public cannot examine which agencies queried the system, why they searched, or when the searches occurred. The policy calls for 30-day and quarterly reports to be posted quickly after receipt, which makes vendor delivery part of the safeguard rather than a back-office detail. An audit requirement that the vendor cannot or does not produce is not yet an audit system.

    The same distinction applies to encryption. Oregon’s law allows existing contracts to continue for a limited period even if they do not yet meet the new end-to-end-encryption rule, while new contracts and add-ons face the stronger standard. That makes procurement timing, feature activation, and key management important. Officials still need to know what is encrypted, who controls the keys, whether Axon can decrypt or export records, and how support, sharing, legal process, and exceptions are logged.

    Database ownership alone does not answer those questions. A city may “own” the records while a vendor controls the hosting environment, administrator privileges, software updates, integrations, or encryption keys. The practical test is whether Bend can independently inspect every local, outside-agency, and vendor action and can prevent access that conflicts with policy.

    Questions for the next review: Have the required audits arrived? Do they include case number, purpose, user, agency, date, data source, and result? Can Bend see vendor access? Who holds the decryption keys? What happens when a search is denied, an integration is added, or a new feature changes what the system can reveal?

    A written rule is an essential starting point. It becomes a safeguard when the system enforces it and leaves enough evidence for an independent reviewer to verify that it worked.

    “A new technology should not transform what individuals had reasonably thought they could withhold from the Government.”

    — Justice Elena Kagan, Chatrie v. United States (2026)

    Oversight stopped one warrantless tracking contract – not the underlying loophole

    The Bureau of Alcohol, Tobacco, Firearms and Explosives has canceled its contract for Penlink’s Webloc location-surveillance product after bipartisan congressional scrutiny. The cancellation is a concrete example of oversight changing agency behavior – but it also shows how much still depends on discovering one contract at a time.

    According to Senator Ron Wyden and Representative Michael Cloud, Webloc used location information originating in commercial advertising systems. ATF disclosed 341 searches: 55 for training or demonstrations, 64 related to violent-crime matters, and 222 associated with active case numbers.

    In one arson investigation near a defense contractor, the prosecutor and judge reportedly raised serious concerns about the warrantless commercial data. Investigators then obtained a traditional court order for bulk cell-tower information.

    ATF canceled the contract six days after a briefing in which congressional staff raised constitutional concerns, state-law restrictions, and Federal Trade Commission actions against sellers of sensitive location data. The agency also committed to reviewing other contracts for similar adtech-derived information.

    The episode shows why contract inventories matter. A surveillance capability can enter an agency as a subscription, analytics service, demonstration account, data-enrichment feature, or add-on to a broader platform. If officials and the public cannot see the product name, data sources, authorized uses, and query counts, there may be no practical opportunity to test legality before the tool is used in active investigations.

    It also shows that oversight can work. The contract was not canceled because the vendor voluntarily narrowed the product or because an internal policy review happened on schedule. It was canceled after lawmakers obtained records, asked how the data were sourced, compared the practice with constitutional and state-law limits, and forced the agency to explain specific searches.

    This story is related to Chatrie, but the legal routes are different. In Chatrie, government compelled a provider to disclose stored account information. With Webloc, an agency purchased commercially collected location data. The first route is governed by warrant and subpoena doctrine; the second is often called the data-broker loophole because agencies argue that information available for purchase can be acquired without the process normally required for a search.

    That distinction should not determine whether movements receive protection. A visit to a clinic, religious service, union meeting, political gathering, or private home does not become less revealing because the information reached government through an advertiser rather than a cellular carrier.

    A durable rule should follow the sensitivity and use of the data, not the route by which it was obtained. Otherwise, a warrant requirement can be bypassed by purchasing a commercially assembled substitute, and a restriction on one agency can be bypassed by a contractor or another agency with access to the same market.

    The safeguard: Require a warrant or equivalent judicial authorization for sensitive location information regardless of whether the source is a carrier, platform, advertiser, broker, or contractor. Agencies should also disclose the products they use, the legal process attached to each search, and the number and purpose of queries.

    A procurement test for commercially sourced data

    Before buying any investigative dataset, an agency should document the original collector, every intermediary, the collection method, consent or notice, accuracy controls, retention, permitted uses, opt-out process, and whether the seller obtained the information in compliance with law and platform rules. The contract should prohibit substitution of a new source without notice and review.


    Facial recognition cannot remain invisible when it helps identify a defendant

    The New Jersey Supreme Court has unanimously ruled that prosecutors must give criminal defendants basic information about facial-recognition technology used during an investigation – even when the State describes the result only as an investigative lead and does not plan to introduce the software output at trial.

    The case concerns Tybear Miles, who was identified as one of several possible matches after police submitted an Instagram image to a facial-recognition system during a murder investigation. Miles sought information about the system and its use so he could test reliability, examine whether police pursued other candidates, and challenge later identifications influenced by the initial search.

    The court rejected a rigid universal checklist but held that defendants generally must receive information identifying the tool and explaining how it was used in the investigation and prosecution. That basic disclosure can expose the source image, database, candidate list, analyst choices, investigative sequence, and possible alternatives to meaningful review.

    The distinction between a “lead” and evidence can be misleading. A facial-recognition result may never be shown to a jury, yet it can determine whose social-media account is examined, which person is placed in a photo array, which witnesses are re-interviewed, and which competing suspects receive less attention. Later evidence may appear independent even when the initial algorithmic match shaped the entire path of the investigation.

    The justices did not automatically require proprietary source code. A defendant seeking trade-secret material must first show a particularized need. The ruling therefore distinguishes between the minimum facts needed to test a government’s case and deeper technical discovery that may depend on the circumstances.

    That approach also avoids a false choice between total secrecy and unlimited disclosure of proprietary material. Agencies can preserve and disclose operational facts – the probe image, database, candidate rankings, thresholds, analyst steps, and corroboration – without assuming that every case requires the vendor’s source code. If those basic facts reveal a specific reliability problem, a court can then decide whether deeper technical material is necessary.

    The policy lesson is broader than one criminal case. Facial recognition should not be insulated from scrutiny merely by placing its output at the beginning of an investigation rather than in the trial exhibit list. An algorithmic lead can shape who police question, which images witnesses see, what evidence receives attention, and whether another candidate is ignored.

    The safeguard: Preserve the original probe image, all preprocessing, vendor and product version, database description, search settings, complete candidate results, analyst actions, and corroborating steps. Disclose that record early enough for meaningful review.

    What minimum disclosure should answer

    A useful record should show what image entered the system, how it was cropped or enhanced, which database was searched, what threshold or ranking method applied, how many candidates were returned, who reviewed them, and what investigators did next. It should also identify any witness procedure influenced by the result and preserve evidence about candidates who were not pursued.

    Shared pattern

    Congress could challenge Webloc because it learned the contract existed. A defendant can challenge facial recognition only if the State reveals that the tool was used. Oversight fails when the decisive system remains outside the record.

    Visibility is not paperwork. It is the condition that makes constitutional, contractual, and technical safeguards enforceable.

    For public bodies, that means maintaining a current surveillance inventory, publishing contracts and policies, recording each sensitive query, preserving investigative provenance, and giving an independent reviewer enough detail to reconstruct what happened. A safeguard that cannot be inspected or challenged is ultimately dependent on trust.

    Trade secrecy should not erase government accountability. Agencies may protect genuinely proprietary material while still disclosing the tool’s identity, data source, purpose, user, query terms, outputs, human decisions, and consequences. When a vendor cannot support that record, the product is not ready for a public-sector decision that affects liberty.

    “Such basic information will, in most cases, constitute the minimum necessary to safeguard a defendant’s right to a fair trial.”

    — Justice Douglas M. Fasciale, State v. Miles (2026)

    Warning Signals

    Warning Signals

    Early indicators of how surveillance expands: through network defaults, age checks, credential phishing, and reusable search tools.

    Woodburn’s experience shows why sharing architecture must be understood before deployment

    Woodburn has permanently removed its Flock Safety cameras after an audit showed that outside agencies – including federal immigration agencies – had been able to include Woodburn’s network in broad searches.

    The city’s public Q&A provides important context. It reports 3,318,618 searches during the period reviewed, but says 99.99% were multi-network searches rather than searches aimed only at Woodburn; 306 uniquely targeted Woodburn. Homeland Security Investigations and U.S. Border Patrol were among the federal agencies whose broader queries included Woodburn during a Flock pilot program that city officials say they had not been told about.

    The document says the city disabled national lookup in October 2025 and found no federal searches after June 24, 2025. But the most important fact is that Woodburn did not knowingly approve the pilot architecture that allowed its network to appear in those searches. The cameras were ultimately removed in May 2026 after the city ended the contract.

    That nuance does not erase the governance failure. It explains it. A local agency can believe it has not affirmatively shared data while a vendor’s network design silently makes its cameras part of a much larger search surface.

    Before deployment, officials should see the default sharing settings, national-search capabilities, pilot programs, vendor administrator access, notification rules, and every route by which a local database can be included in another agency’s query.

    They should also require a change-control rule: no pilot, federation, network expansion, integration, or new search mode should apply to local data without written notice, legal review, and affirmative approval. Vendor defaults are policy choices when they determine who can search a community’s records.

    The procurement lesson: Ask for a live demonstration of every sharing screen and administrator setting, then attach the approved configuration to the contract. Require notice before the vendor changes a default, joins a pilot, or makes local data searchable through a new network path.


    The KIDS Act clears the House – with age checks still the privacy fault line

    The House passed H.R. 7757, the Kids Internet and Digital Safety Act, on June 29 by a bipartisan 267-117 vote. The package now moves to the Senate and is not law. It combines proposals involving platform design, youth privacy, targeted advertising, AI chatbots, online games, data brokers, parental controls, audits, and research.

    The House package is not the same as the stronger KOSA framework the Senate passed in 2024, and key senators have criticized the compromise. That makes House passage a major status change, not a final policy settlement. Any Senate amendment would require further agreement between the chambers.

    The age-verification provisions require careful attention. The SCREEN Act title directly requires covered platforms substantially devoted to sexual material harmful to minors to use commercially available verification technology and prevent minors from accessing that material. It also limits collection, use, retention, and disclosure of verification data to what is strictly necessary.

    The KOSA title separately says it should not be construed to require age gating or age verification. But other provisions impose duties when a service “knows or should have known” a user is a child or teen. The Electronic Frontier Foundation argues that this pressure will lead broader services to determine users’ ages, including by asking adults to prove they are adults.

    That is an advocacy interpretation, not a settled outcome. But it identifies the key implementation question: Can a service comply without building a persistent identity or age-classification system for everyone?

    The privacy question is not whether protecting children is worthwhile. It is what infrastructure compliance creates. A system that collects identity documents, biometric estimates, device signals, or persistent age labels can become useful for advertising, account linkage, content control, or government access unless reuse and retention are technically and legally prohibited.

    Any final bill should minimize data, prohibit reuse, protect anonymous and pseudonymous access, avoid biometric estimation where less intrusive methods work, publish error rates, and require independent testing for demographic bias. The strongest design proves only the necessary threshold and then forgets the underlying evidence.

    What to watch in the Senate: whether the final package changes the “knows or should have known” standard, narrows or expands direct age-verification duties, preserves state protections, limits data retention, and creates a realistic enforcement path when an age system is inaccurate or discriminatory.


    Treat messaging-app recovery keys like master passwords

    The FBI warns that Russian intelligence-linked actors are impersonating messaging-app support services and trying to obtain verification codes, account PINs, and backup recovery keys.

    A recovery key can be more damaging than an ordinary password. An attacker who obtains one may be able to download historical private and group messages and later take over an account. The old key can remain useful even after the victim creates a new account with the same phone number.

    No legitimate support agent should ask for a backup key, verification code, or PIN. After suspected exposure, generate a new recovery key from inside the application; changing the account alone may not invalidate the compromised key. Regeneration cannot retrieve a backup already downloaded, but it can block future use of the old credential.

    Civic organizations should write this into incident-response plans. If a member reports a suspicious support message, the response should include regenerating the key, reviewing linked devices and active sessions, preserving the phishing message, warning affected groups through a trusted channel, and assuming that messages already restored by the attacker may have been copied.

    The broader lesson is that encrypted messaging still depends on unencrypted human workflows. Attackers often do not break the cryptography; they persuade a user to hand over the recovery path.


    Axon Watch: better logs, easier recurring searches

    Axon’s June 30 Records and Standards notes describe a report-redaction tool that records who made a redaction, when it occurred, and the reason – if the user provides one. They also add reusable saved searches and more precise audit-log timestamps. The rollout began at 11 a.m. Pacific and may continue into the following day; Axon says availability can change.

    These are governance changes, not merely interface changes. A redaction log is stronger when the reason is mandatory and tied to a policy category. If the reason remains optional, an audit may prove that a field was hidden without explaining the legal basis for hiding it.

    Saved searches can improve efficiency, but they can also turn a one-time query into a standing practice. A reusable search may silently encode a broad location, person category, vehicle pattern, or data combination that is run again and again. Agencies should control who may create, share, and execute saved searches, require a purpose and expiration date, and review recurring sensitive queries as surveillance programs rather than personal shortcuts.

    More precise timestamps are useful only if records are retained, protected from alteration, and connected to user identity, case number, query terms, and result handling. Better software fields become safeguards when policy makes them complete and review makes them consequential.


    Safeguards

    Safeguards

    The strongest protections this week control who can take the next, more intrusive step – and make that step provable.

    Put a judge at every material expansion point

    A digital warrant should specify more than the first geographic circle or time window. When a search proceeds in stages, define objective narrowing criteria and require renewed judicial approval before investigators expand the period, follow devices beyond the original location, or reveal identities.

    The order should identify the offense, factual basis, data source, geographic boundary, duration, expected number of affected people, minimization procedure, deletion rule, and the evidence required before moving to the next stage. Investigators should not receive a “roving commission” to decide whose private movements deserve deeper review.

    Apply one constitutional standard to sensitive location data

    Do not let the purchase route determine the privacy rule. Require a warrant or equivalent judicial authorization for sensitive location information obtained from carriers, platforms, advertisers, brokers, or contractors. Record the legal authority, requesting official, case number, purpose, date range, geographic scope, and disposition for every query.

    The rule should cover direct access, subscriptions, trial accounts, demonstrations, enrichment services, federated searches, and records received from another agency. A restriction on compelled disclosure is incomplete if the same movement history can be bought from a commercial intermediary.

    Verify vendor promises with deliverables

    A contract should identify the exact audit reports a vendor must produce, their fields and format, delivery schedule, retention period, public-posting process, and consequences for nonperformance. Encryption terms should state what is encrypted, when, who possesses the keys, and whether the vendor can decrypt or export records.

    A practical contract checklist:

    • Can the agency inspect every local, outside-agency, and vendor action?
    • Must each search include a case number, purpose, and legal authority?
    • Are outside networks and new integrations disabled by default?
    • Must the vendor give notice and resist conflicting legal demands?
    • Does the agency approve pilots, feature activations, and policy-changing updates?
    • Can the agency terminate, obtain deletion certification, and recover fees after a material breach?

    “We own the data” is not enough if the vendor controls administrator access, encryption keys, integrations, or the audit evidence needed to prove compliance.

    Make facial recognition reproducible

    Preserve the original image, all preprocessing, vendor and version, database searched, settings, complete candidate results, analyst decisions, later witness procedures, and corroborating evidence. Disclose the system’s use even when prosecutors call it only a lead.

    Do not treat a candidate list as an identification. Require trained human review, independent corroboration, and a record of why other candidates were rejected. Later witnesses should not be shown a single algorithm-selected person in a way that converts a tentative lead into an apparently independent identification.

    Map every route into and out of the system

    A sharing diagram should identify local users, outside agencies, vendor administrators, subcontractors, federated networks, application-programming interfaces, exports, backups, and legal-process pathways. For each route, specify who can authorize access, what purpose is allowed, what data leave the system, how long the connection lasts, and what evidence the action creates.

    Review the diagram whenever a contract is renewed, a pilot begins, an integration is enabled, or a software update changes search or sharing. Woodburn’s experience shows that an agency can misunderstand its own exposure when the vendor’s network architecture changes the practical meaning of “sharing.”

    Make audit evidence usable, not ceremonial

    A useful audit record needs the user and agency, date and time, case number, stated purpose, legal authority, search terms, datasets queried, result count, exports, sharing, and final disposition. It should also record denied attempts, administrator changes, vendor access, retention overrides, and creation or reuse of saved searches.

    Assign someone independent of day-to-day users to review the logs on a fixed schedule. Publish aggregate reports quickly, investigate anomalies, document corrective action, and preserve detailed records long enough for litigation, public-records review, and contract enforcement. A log no one reads is storage, not oversight.

    Build age assurance to forget, not remember

    Reveal no more than the minimum fact necessary – such as whether an age threshold is met – and do not create a reusable identity record. Prohibit secondary use, advertising, cross-service tracking, indefinite retention, and conversion of an age check into a biometric profile. Require appropriate legal process before government access.

    Legislation should require public documentation of the method, error rates, demographic testing, retention schedule, appeal process, and all downstream recipients. A child-protection system should not quietly become identity infrastructure for every adult who uses the service.

    Treat recovery keys as offline secrets

    Store backup recovery keys separately from the device and account they protect. Never send them through chat, email, forms, or a support conversation. Regenerate the key immediately after suspected exposure and review linked devices and active sessions.

    Organizations should designate a trusted channel for security alerts and rehearse what happens after compromise. Preserve the fraudulent message, warn affected groups, rotate related credentials, and assume that any backup already downloaded may be outside your control.

    Govern recurring searches as policy, not convenience

    Saved searches, alerts, watchlists, and automated recurring queries can become standing surveillance programs. Require a documented purpose, owner, approval period, review date, access list, and deletion rule. Audit not only who ran a search but also who created the template and how often it was reused.

    A recurring query should expire unless someone affirmatively renews it. Material changes to search terms, geography, datasets, or sharing should trigger a new review. The easier software makes repetition, the more important it becomes to distinguish a lawful one-time inquiry from ongoing monitoring.

    Plan for failure before deployment

    Every sensitive system should have an incident plan that covers unauthorized access, inaccurate matches, vendor nonperformance, exposed credentials, unlawful outside queries, and policy-changing software updates. Name the decision-maker, evidence-preservation steps, notification duties, suspension authority, correction process, and conditions for terminating the system.

    Failure planning changes incentives before anything goes wrong. Vendors know which records they must preserve and what breach consequences apply; staff know when to stop using a tool; affected people have a correction path; and elected officials receive facts rather than reassurances.

    Bottom line

    The strongest safeguards this week all control the next step. A judge must control when a location search widens. A contract must control whether a vendor delivers an audit. Discovery must reveal when an algorithm shaped an investigation. An age check must not become a lasting identity system. And a recovery key must remain outside the reach of anyone pretending to offer support.

    The common test is operational: Who can take the next step? What evidence must they provide? What does the system prevent? What does it log? Who can inspect the record, correct an error, or impose a consequence?

    A safeguard is not what a policy promises. It is what the system prevents, records, reveals, and allows someone to challenge.

  • Signals & Safeguards Issue 15: Repurposed Databases, Data Brokers, and the Search Layer

    Signals & Safeguards

    Issue 15 • Wednesday, June 24, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • A federal court set aside the government’s 2025 overhaul of the SAVE system after sensitive records were repurposed for bulk voter screening and produced inaccurate citizenship flags.
    • ICE reportedly turned to a data broker for tax-identifier records after direct federal sharing faced legal barriers.
    • Eugene is beginning the harder work of governing surveillance citywide rather than debating one tool at a time.
    • Age verification is advancing through Congress, state law, litigation, and increasingly automated estimates of who is a child.

    Federal databases became a voter-screening system—and a court said the government skipped the rules

    A federal judge has set aside the federal government’s 2025 overhaul of the Systematic Alien Verification for Entitlements system, known as SAVE, after finding that agencies unlawfully combined sensitive records and transformed an administrative verification tool into a system for mass voter screening.

    SAVE is not new. It was built to help government agencies verify citizenship or immigration status when people apply for certain public benefits, licenses, and other services. The court did not eliminate that longstanding function. It instead vacated the 2025 modifications that dramatically changed what the system could search and how it could be used.

    According to the 75-page opinion, the modified system differed from the earlier version in three major ways. It added records about people born in the United States, connected SAVE to Social Security Administration records—including full or partial Social Security numbers—and allowed government users to upload lists for bulk searches rather than checking one person at a time.

    Those changes matter because they altered both the scale and the purpose of the system. A database designed to verify an individual’s eligibility for a service became a tool that states could use to compare large voter lists against federal records. The court found that the agencies violated provisions of the Social Security Act and the Privacy Act, including statutory and procedural protections governing how personal information is disclosed and how federal record systems are changed.

    The accuracy problem was not hypothetical. The court described naturalized citizens whose Social Security records had not been updated and who were identified as potential noncitizens. Some were required to provide proof of citizenship within 30 days to protect their registrations. The record included citizens whose registrations were wrongfully canceled, including one person who learned of the cancellation only later.

    This does not mean election officials should ignore reliable evidence that someone is ineligible. It means that a match produced by a repurposed database should not be treated as a fact without understanding where the data came from, how current it is, what error rate exists, and what process allows an eligible person to correct the record before losing a right.

    The case also illustrates why bulk search is not merely a technical upgrade. Searching one identified person for a documented reason is different from uploading millions of names to see who a system flags. Once bulk screening becomes available, an administrative database can become a general eligibility, enforcement, or suspicion engine.

    Why it matters for Bend: Local and state governments hold sensitive information because residents apply for licenses, permits, utilities, benefits, housing, jobs, school services, and emergency assistance. The original collection may be lawful and necessary. The next question is whether those records can later be combined, searched, or repurposed for a substantially different objective without public notice, accuracy testing, correction rights, or a new decision by elected officials.

    The safeguard is not a promise that data will be used responsibly. It is a rule that identifies the authorized purpose, limits the searchable records, documents every query, tests for error, notifies people before adverse action, and provides a meaningful way to correct mistakes.


    When direct government access is blocked, agencies may buy the data instead

    A nearly $10 million procurement reviewed by 404 Media indicates that Immigration and Customs Enforcement is purchasing records related to Individual Taxpayer Identification Numbers through a commercial data provider.

    An ITIN is a tax-processing number issued by the Internal Revenue Service to people who need to file federal taxes but are not eligible for a Social Security number. ITIN holders include people with different immigration and residency circumstances; possession of an ITIN should not by itself be treated as proof of unlawful presence.

    The reported procurement is significant because a federal court had already blocked an arrangement under which the IRS would directly share taxpayer information with the Department of Homeland Security. Senator Ron Wyden told 404 Media that buying related information from a private broker appeared to be an end-run around taxpayer-privacy law and the court’s order.

    That is an allegation about the apparent purpose and legal effect of the contract, not a final judicial ruling on the procurement itself. But the mechanism raises a policy problem that extends well beyond immigration enforcement: a restriction on direct government access may provide little protection if an agency can purchase the same or similar information from a commercial intermediary.

    Data brokers rarely sell only a single raw field. Commercial products can link identifiers to names, addresses, phone numbers, relatives, property records, employment information, location histories, or other records. Even when each source began as a separate administrative or commercial record, the broker’s value comes from connecting them.

    That creates a form of policy laundering. Government may be barred from compelling one agency to disclose a sensitive record, yet still acquire a commercially assembled product that reveals or predicts substantially the same information. The practical safeguard therefore has to regulate acquisition, not merely direct sharing.

    Why it matters for Oregon: Oregon has already recognized that data-broker relationships can become immigration-enforcement pathways. But the broader lesson applies to every public body: laws and contracts should address broker purchases, enrichment services, vendor-derived identifiers, downstream matching, retention, secondary use, disclosure to outside agencies, and deletion when authority expires.

    Public officials should also ask vendors to document the origin of every data category they sell. “Commercially available” does not answer whether the original collection was consensual, accurate, current, lawful for the new purpose, or capable of correction.


    Shared pattern

    The SAVE case and the reported ICE procurement involve different institutions and different legal questions. One concerns federal databases repurposed for voter screening. The other concerns commercially acquired records used for immigration enforcement. The shared governance problem is the same: a limit on collection or direct sharing does not protect people if sensitive information can later be combined, purchased, or searched through another route.

    The search layer is the policy layer. Whoever controls what questions the system can answer may possess more practical power than the institution that originally collected the data.

    “In the pre-computer age, the greatest protections of privacy were neither constitutional nor statutory, but practical.”

    — Justice Samuel A. Alito Jr., concurring, United States v. Jones (2012)

    Eugene is moving from one surveillance dispute to a citywide governance system

    Eugene City Councilors have directed staff to begin developing a broader policy for surveillance technology, moving the discussion beyond the city’s earlier controversy over Flock automated license plate readers.

    The decision is important because it treats surveillance as a governance category rather than a series of unrelated purchases. Eugene is not currently debating whether to reactivate its Flock cameras. Instead, councilors are asking what rules should apply whenever any department considers a technology capable of identifying, tracking, recording, profiling, or analyzing people.

    City staff reviewed approaches used by Portland, Berkeley, and San Jose. According to KLCC, several councilors were especially interested in San Jose’s risk-based model, which applies citywide and requires greater oversight when a proposed technology presents a higher risk to privacy or civil liberties. Portland’s process includes privacy-impact assessments during procurement and a public inventory of city technologies that can be used for surveillance.

    Those models separate several decisions that are often blurred together.

    An agency-use policy tells employees how to operate a system after it exists. A procurement rule asks what information must be disclosed before money is committed. A public-approval process determines when elected officials and residents should have a role. An oversight system requires reporting, audits, and review after deployment. A city can have one of these without the others.

    That distinction helps explain why a police policy alone is not enough. A department may write careful rules for current uses while a contract permits vendor access, outside-agency sharing, future analytics, or automatic product upgrades. A procurement process may review price and legal compliance without examining civil-rights risk. A council may approve a device without knowing that later software changes can substantially expand what it does.

    Eugene staff also identified a question many governments avoid: whether the city should review technology already in use. A forward-looking approval process can prevent new problems, but it does not reveal what departments already operate, what records those systems retain, what databases they connect to, or which vendors can access them. A citywide inventory is the starting point for meaningful governance because officials cannot oversee tools they do not know exist.

    Eugene’s final policy has not been written or adopted. Staff said the process could take at least six months and may proceed in phases, particularly if the city reviews existing systems and department-specific rules. Councilors also called for meaningful public participation, which could extend the timeline.

    That is not a weakness. Surveillance policy should not be rushed merely because technology procurement usually moves quickly. The purpose of a durable framework is to decide the rules before the next vendor presentation, grant deadline, emergency request, or contract renewal compresses the decision.

    Why it matters for Bend: Bend’s current ALPR debate demonstrates the limits of reviewing one administrative policy or contract at a time. A durable, CCOPS-aligned process should apply before surveillance technology is purchased, activated, expanded, connected to another system, renewed, or upgraded with a materially new feature.

    At minimum, that process should require:

    • a citywide inventory of existing and proposed systems;
    • a plain-language description of capability, not merely the product name;
    • a privacy and civil-rights impact assessment;
    • the proposed purpose and prohibited uses;
    • data sources, retention, sharing, and vendor access;
    • security architecture and breach responsibilities;
    • independent audit requirements;
    • public reporting on use, searches, errors, complaints, and misuse;
    • fresh approval before significant expansion or integration.

    Eugene’s approach should not be treated as proof that its eventual policy will be perfect. Its value is that the city is asking the right institutional question: how should surveillance be governed across the whole government before the next tool becomes a fait accompli?


    Kansas City plans to turn bus cameras into live identity searches

    Kansas City’s transit authority is preparing to add facial-recognition software to cameras on public buses. Images of passengers would be compared in real time against active alerts for banned riders, missing persons, and people on law-enforcement watchlists designated by the transportation authority.

    That is a meaningful change in function. A conventional security camera records what occurred so footage can be reviewed later. Live facial recognition asks a different question about everyone entering the camera’s view: does this face match someone on a list?

    The Missouri state government declined expected funding because of concerns about the facial-recognition component, but the project is moving forward with local and federal funding. The initial deployment has been delayed, not abandoned, and could eventually reach as many as 30 buses.

    The vendor says facial data associated with nonmatches will not be retained. That is a relevant safeguard, but it does not resolve the main governance questions. The transit authority reportedly may retain ordinary bus footage locally for as long as five years. More important, deletion of a nonmatching template does not determine who can be placed on a watchlist, what evidence supports the placement, how long someone remains listed, or how a person can challenge an error.

    “Banned rider” can also cover very different circumstances. A narrowly documented temporary exclusion after a serious assault is not the same as an indefinite administrative list built from complaints or disputed conduct. Missing-person alerts may involve people who need assistance, but they also raise questions about consent, family conflict, and whether every reported missing adult should trigger automated identification. Law-enforcement lists may range from judicial warrants to investigative interest that has never been tested in court.

    A facial-recognition match should not itself justify detention, removal, questioning, or adverse action. Systems can be wrong because the image is poor, the watchlist record is outdated, the algorithm performs unevenly, or two people look similar. Human review helps only when the reviewer receives independent information and is expected to challenge rather than confirm the machine.

    Why it matters locally: Cities increasingly add analytics to cameras that were approved for more limited purposes. Officials may hear that “the cameras already exist” or that the change is merely a software upgrade. But converting recording equipment into a live identification system is a new surveillance decision and should require a new public review.

    Before deployment, officials should define eligible watchlists, evidentiary standards, maximum listing periods, independent accuracy testing, confirmation procedures, prohibited uses, notice and appeal rights, retention, audit access, and the approval required for expansion.

    The oversight question is not simply whether the technology works

    A system may correctly identify many people and still be poorly governed. The deeper questions are who defines success, which errors count, who bears the consequences, and whether a limited pilot can become permanent infrastructure without another vote. The safeguard is to establish those rules before the first live search, not after the first public controversy.

    “Awareness that the Government may be watching chills associational and expressive freedoms.”

    — Justice Sonia Sotomayor, concurring, United States v. Jones (2012)

    Warning Signals

    Warning Signals

    These items point toward where identity systems, vendor platforms, and searchable public records may be heading next.

    Age verification is advancing through both legislation and litigation

    House Energy and Commerce Committee leaders released revised bipartisan text of the Kids Internet and Digital Safety Act, or KIDS Act, on June 22. The measure has not passed the House, but its age-verification language is now concrete enough to evaluate.

    Title I would apply to publicly accessible platforms where more than one-third of the material is sexual material harmful to minors. Those services would have to use commercially available technology to determine whether a user is likely a minor and prevent minors from accessing the covered material. A user simply checking a box or stating that they are an adult would not be sufficient.

    The bill contains several safeguards that should be recognized rather than ignored. Verification data could not be collected, used, transferred, disclosed, or retained beyond what is strictly necessary for the age check. Platforms could hire outside verification providers but would remain legally responsible. Reasonable administrative, technical, and physical security would be required. The text also says it does not require submission of government-issued identification.

    Those provisions reduce some risks, but they do not determine the actual architecture. Platforms would choose the specific verification technology, subject to statutory requirements. The difference between a privacy-preserving age token, a facial estimate, a credit-history check, a phone-account signal, and an identity-document upload is substantial. So is the difference between learning only “over 18” and retaining enough information to link an age decision to a persistent account.

    The bill would require a Government Accountability Office review after implementation, including effectiveness, privacy, security, and effects on speech and behavior. That is useful, but it would occur after verification systems have been deployed. Legislators should also require testing, transparency, and independent review before broad implementation.

    At the same time, emergency applications remain pending at the U.S. Supreme Court over Texas’s App Store Accountability Act. The Texas law reaches more broadly by requiring app stores to determine users’ ages and obtain parental consent before minors download applications. Applicants are asking the Court to undo a Fifth Circuit stay that allowed the law to take effect while constitutional litigation proceeds. Texas filed its response June 22, additional briefs were filed through June 23, and no order was listed as this issue was prepared.

    The federal bill and the Texas case should not be treated as interchangeable. One targets access to a defined category of adult material; the other makes an app store an age and parental-permission gatekeeper across the application ecosystem. The comparison shows why the mechanism matters as much as the stated objective.

    Oregon’s question should be architectural: Which services must request an age signal? Does the system return only a broad category, or a persistent identity record? Who keeps the evidence? Can it be reused, sold, linked, or subpoenaed? Can adults continue accessing lawful speech anonymously? How are mistakes corrected? Who is responsible when a child is classified as an adult—or an adult is locked out as a child?


    An age estimate can become a legal decision

    The United Kingdom plans to use facial-age estimation in 2027 to help assess the ages of asylum seekers who lack documents. Internal government testing obtained by WIRED, Lighthouse Reports, and The Independent shows why that use is materially different from an age estimate used to suggest child-friendly settings.

    The testing reportedly found that systems regularly mistook some children for adults and performed worse for people from Sub-Saharan Africa. For female Sub-Saharan African subjects, the estimated age was off by an average of 4.6 years—enough, in a borderline case, to classify a child as an adult.

    That error can affect detention, housing, legal protections, and access to services. The system is not merely recommending content; it is helping place a person on one side of a legal boundary.

    High-stakes age estimation should therefore never be decisive on its own. Governments should publish performance by age and demographic group, disclose uncertainty rather than a falsely precise number, prohibit adverse action based solely on the estimate, provide independent review and appeal, and limit retention and reuse of facial images.

    The lesson applies to Oregon even if the proposed system is less consequential. Technology that produces an age category is making a probabilistic judgment. Policy must be designed around the possibility that the judgment is wrong.


    Axon Watch: Records is making linked people and vehicles easier to surface

    Axon’s June 16 Records update changed incident and standalone-report search results so they display linked people and vehicles. Incident cards also show the roles those people and vehicles played.

    That may save officers and records staff time. It also makes relational information more visible at the search stage. A person who was a witness, reporting party, passenger, property owner, or otherwise associated with an incident can become easier to surface across repeated queries even when the person was never suspected of wrongdoing.

    Axon has additional changes scheduled for June 30. Those include saved search configurations, searches using attached evidence identifiers, improved searches by report author, a report-redaction tool, and audit-log timestamps precise to hundredths of a second. The redaction tool and more precise logs may strengthen accountability when permissions and review are well designed. Saved searches and broader search options increase the need to govern recurring queries.

    Public agencies should ask:

    • Which roles may search, export, redact, or save queries?
    • Must a query include a case number or documented purpose?
    • Can a saved search repeatedly surface records about uninvolved people?
    • Are searches and exports visible to supervisors and independent auditors?
    • Who may change redactions, and is the reason recorded?
    • Are new search features enabled automatically or activated after agency approval?
    • Does a contract treat a materially expanded search capability as a new feature requiring policy review?

    Procurement should not freeze its analysis at the product’s capabilities on signing day. Platform software changes over time, and the search layer can expand without a new camera, device, or contract headline.


    Madison Square Garden reportedly cataloged critics of facial recognition

    404 Media reports that Madison Square Garden compiled a document containing public comments and social-media posts from people who criticized the venue’s facial-recognition program. The document was found in a 45-gigabyte cache of company data stolen by hackers and later reviewed by the publication.

    The reporting does not by itself establish what MSG intended to do with the list. But the existence of a document titled around facial-recognition activists illustrates a serious governance risk: the institution operating a surveillance system may also possess the ability to catalogue the people challenging that system.

    Public criticism is part of oversight. It should not become a reason to add someone to an internal profile, watchlist, access restriction, or enhanced-surveillance category. Organizations using biometrics should adopt explicit rules prohibiting retaliation or heightened monitoring based on protected criticism, advocacy, journalism, or legal representation.


    Direction of travel

    This week’s Signals point toward identity becoming a reusable query. Age systems estimate whether someone is a child. Facial recognition asks whether a rider appears on a list. Records platforms surface associated people and vehicles. Institutions can compile information about critics. The safeguard is not only collecting fewer data. It is narrowing what questions systems are allowed to answer—and ensuring that every consequential answer can be examined, challenged, and corrected.


    Safeguards

    Safeguards

    The strongest protections this week are structural: govern the search, bind the vendor, preserve correction rights, and make misuse provable.

    Write the warrant rule, audit access, and termination right into the contract

    Shaker Heights, Ohio, has amended its Flock Safety contract and adopted access rules that offer a concrete example of turning privacy promises into enforceable terms.

    The city says Flock may not access, preserve, use, or disclose Shaker Heights data to a government authority or other third party without a court-issued search warrant. The contract rejects disclosure based merely on subpoenas, administrative demands, informal inquiries, preservation letters, national-security letters, investigatory convenience, generalized public-safety claims, or the vendor’s own contractual interests.

    The vendor must provide prompt written notice before disclosure and give the city an opportunity to seek protective relief. Flock must also make reasonable efforts to resist, narrow, quash, or otherwise challenge legal process that conflicts with the contract.

    The city receives on-demand access to audit logs covering searches by users inside and outside Shaker Heights. If Flock violates the assurances, the city may terminate without penalty and receive a refund.

    Shaker Heights also limited access so that no federal agency, agency outside Ohio, or agency participating in a 287(g) immigration-enforcement agreement may search the city’s data. The city contacted 434 jurisdictions that had requested access and required them to agree to the restrictions. Its internal police policy requires searches to be connected to a specific department case number or undercover case identifier.

    These provisions do not answer every concern. The city still operates 18 license plate readers, and local officials and residents must still evaluate camera locations, retention, authorized purposes, effectiveness, errors, audit review, and whether the network should continue. A contract is not a substitute for legislation, public oversight, or constitutional limits.

    But it shows what it means to negotiate rather than accept vendor boilerplate. “We own the data” is not enough if the vendor can respond to demands, preserve records, permit outside searches, or change access without meaningful city control.

    A practical procurement checklist for Bend:

    • What legal process must the vendor require before disclosure?
    • Must the city receive advance notice?
    • Is the vendor required to resist or narrow an improper demand?
    • Can the city inspect every internal, external, and vendor search?
    • Are outside agencies denied access by default?
    • Must each local search include a case number and purpose?
    • Does the contract prohibit sales, demonstrations, model training, or product development using city data?
    • What happens if the vendor violates the rule?
    • Can the city terminate without penalty and obtain deletion certification?
    • Do materially new features require affirmative approval before activation?

    Good contract language cannot prevent every abuse. It can make improper access harder, more visible, and legally consequential.


    Outsourcing a public service does not outsource responsibility for the data

    Texas Parks and Wildlife reported that an unauthorized actor may have obtained personal information belonging to more than three million hunting and fishing license customers through the vendor that operates the state’s licensing system.

    The potentially exposed information included driver-license data, passport numbers when supplied, email addresses, phone numbers, and residential addresses. The agency said Social Security numbers, birth dates, and financial information were not obtained. Texas Cyber Command detected the incident, and the agency says it and the vendor have strengthened access controls and monitoring.

    The incident demonstrates why a vendor-operated portal remains public infrastructure. Residents did not choose the contractor or negotiate its security practices. They provided information because the state required or requested it to deliver a government service.

    Before a vendor receives resident data, a public contract should identify every data field collected and why it is necessary. It should define privileged-access rules, multifactor authentication, encryption and key control, logging, monitoring, subcontractors, vulnerability management, incident-notification deadlines, evidence preservation, public communication, deletion at contract end, and responsibility for remediation.

    Officials should also ask whether a less sensitive identifier would work. A system cannot leak information it never collected or retained.


    Patch the system—and invalidate what attackers may already have stolen

    CISA confirmed active exploitation of a critical Splunk Enterprise vulnerability that can allow an unauthenticated, network-reachable attacker to create or truncate files through an exposed PostgreSQL sidecar endpoint. Splunk urged customers to upgrade fixed versions, and CISA imposed an accelerated deadline on federal agencies. Where immediate patching is impossible, disabling the affected sidecar service can remove the attack path, although it may disrupt dependent pipelines.

    Splunk deserves special attention because organizations often use it to collect the logs needed to understand other security incidents. If the monitoring system is compromised, altered, or unavailable, defenders may lose both operational capability and evidence.

    The week’s Fortinet warning adds a second lesson. CISA said compromised credentials associated with roughly 74,000 firewall and VPN devices had been exposed and used in attacks. This was not simply a reminder to install a patch. Credentials, active sessions, tokens, and keys stolen earlier can remain useful after vulnerable software has been updated.

    The practical response is broader:

    • inventory affected and internet-exposed systems;
    • patch supported versions;
    • disable vulnerable services when patching must be delayed;
    • rotate administrative and VPN passwords, keys, tokens, and service credentials;
    • terminate active sessions;
    • enforce phishing-resistant multifactor authentication where possible;
    • remove management interfaces from the public internet;
    • inspect successful logins, new accounts, configuration changes, and lateral movement;
    • preserve critical logs outside the potentially compromised monitoring environment.

    Patching closes a software flaw. Incident response must also invalidate what an attacker may already possess.


    Make privacy rights operational

    Vermont enacted S.71, now Act 145, adding another state model for consumer privacy and online-surveillance regulation. The specific provisions will matter, but the larger design lesson is that privacy rights work only when people can realistically exercise them and regulators can enforce them.

    A statute should identify who is responsible, create understandable request and correction processes, limit secondary use, provide implementation guidance, fund enforcement, and require records that allow violations to be proven. A right buried behind separate requests to hundreds of companies is much weaker than a right supported by a centralized or standardized process.

    Bottom line

    This week’s stories are connected by searchability. Sensitive data become more powerful when agencies can combine records, vendors can sell access, cameras can identify faces, and software can surface relationships across incidents.

    The strongest safeguards govern that power directly: define the permitted purpose, require a case number or legal basis, limit the datasets and watchlists, give people a meaningful way to correct errors, log every search, let an independent reviewer inspect those logs, and make vendors contractually responsible when they cross the line.

    Collecting less remains essential. But once data exist, the next safeguard is controlling what the system is allowed to reveal.

  • Signals & Safeguards Issue 14: Age Verification, ALPR Accountability, and Searchable Systems

    Signals & Safeguards

    Issue 14 • Wednesday, June 17, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • Section 702 expired legislatively, but the warrant fight did not end.
    • ALPR accountability is no longer hypothetical: misuse, tracking claims, private-camera sharing, and audit-log gaps are now concrete governance problems.
    • Cyber patch windows are shrinking as exploited vulnerabilities, AI-assisted attacks, and research-sector targeting accelerate.
    • Identity checks are spreading into phones, age verification, platform access, and encrypted communications.

    Section 702 expired on paper, but the warrant fight did not

    Congress allowed Section 702 to lapse after a short-term extension failed, but the practical surveillance fight is not over. Reuters explains that Section 702 allows warrantless collection targeting foreigners abroad, while also sweeping in communications involving Americans. The Guardian, AP, and the Brennan Center all point to the same unresolved question: when U.S. person communications are searched, should the government need a warrant?

    The important nuance is that “expired” does not necessarily mean “stopped.” Existing certifications may allow surveillance activity to continue for a period even after the statutory deadline. That makes the public-facing safeguard question sharper, not weaker. The debate is no longer only about whether Section 702 exists on paper. It is about whether searches involving Americans’ communications should require clear legal authority before they happen.

    The warrant issue also became entangled with unrelated politics. Reuters reported that Trump opposed renewal unless it was paired with proof-of-citizenship voting legislation. That does not change the civil-liberties question. A surveillance law that can reach Americans’ communications should not depend on unrelated legislative leverage.

    Why it matters for Bend: Section 702 is a federal intelligence law, not a city camera program. But the governance lesson travels. Broad search authority, weak front-end limits, secret interpretations, and after-the-fact review can become normalized unless public institutions insist on clear authority, narrow access, and usable oversight before sensitive searches occur.


    ALPR accountability is no longer hypothetical

    Automated license plate reader oversight is now an evidence problem, not a theory problem. Recent reporting shows officer misuse, private-camera networks, retail deployments, vendor-access questions, leaked search metadata, event-surveillance buildouts, and disagreement over whether systems “track people” or simply record vehicles.

    InvestigateTV / WRDW reported that Flock says its cameras do not track people, while training material describes following vehicles or suspects from “location to location.” 404 Media reported on police officers arrested or accused after allegedly using Flock systems to stalk or monitor people. AP reported on a Westchester County lawsuit involving a large ALPR system with 1.6 billion scans, nearly 600 cameras, and access by more than 50 outside agencies.

    The same issue is spreading beyond police-owned cameras. Retail parking-lot ALPR systems can still become public-safety data sources if their databases are shared, searched, or made available to law enforcement. Dayton Daily News and other reporting on retailers using Flock cameras show why “private” does not always mean “outside public surveillance.”

    The safeguard question is not only whether a camera reads plates. It is who can search the resulting record, how long the data is kept, whether outside agencies can query it, whether private databases can become police tools, whether vendor employees can access the system, and whether every search can be audited later.

    Why it matters for Bend: Bend already learned that access rules matter before systems go live. Any ALPR proposal should be judged by the audit trail it creates, not only by the problem it promises to solve. A system that cannot answer who searched, why they searched, what they saw, and whether the result was shared is not just missing a technical feature. It is missing the oversight system.


    Patch windows are shrinking because exploitation is getting faster

    Cybersecurity is becoming a timing problem. Reuters reported that U.S. officials shortened the remediation window for certain exploited vulnerabilities to three days as AI-assisted threats rise. CISA also continued adding known exploited vulnerabilities to its catalog, reinforcing the same practical lesson: once a flaw is being actively exploited, public agencies may not have weeks to decide what to do.

    The current-week examples cut across sectors. Reuters reported that Chinese-linked hackers targeted U.S. and Canadian research facilities over the past year, including academic, medical, military, AI, unmanned-vehicle, cyber-warfare, and medical-research targets. Reuters also reported cyber incidents involving iRhythm and an attempted extortion claim involving Novo Nordisk.

    The lesson for public institutions is not simply “patch faster.” It is to know which systems are exposed, who owns the fix, whether the vendor has patched, whether logs were reviewed, whether credentials or accounts changed, and whether dependent systems are affected. Cybersecurity is no longer only an IT department issue. It is public infrastructure governance.

    Why it matters for Bend: Cities, counties, schools, clinics, libraries, utilities, and vendors all depend on systems that can become public-sector risk points. Officials do not need to understand every exploit. They do need clear answers about exposure, patch timing, vendor proof, log review, and continuity plans.


    Shared pattern: searchability is the power

    The strongest stories this week point in the same direction: searchable systems need visible safeguards. Section 702 raises the question of who can search communications and under what authority. ALPR systems raise the question of who can search movement records and whether misuse can be proven. Cyber incidents expose the risk of large stores of sensitive data. Identity systems decide who must prove themselves before ordinary access. Police-tech platforms determine what becomes searchable next.

    The safeguard question is the same across all of them: who can search, why can they search, what legal authority applies, how long data is kept, whether vendors can access it, and whether misuse can be detected after the fact.


    Warning Signals

    Warning Signals

    These items point toward where search power, identity checks, platform access, vendor systems, and data governance may be heading next.

    Private cameras can still become public surveillance systems

    Retail ALPR systems are a reminder that “private” cameras can still become public-safety infrastructure. Dayton Daily News reported on Flock cameras used by retailers and shopping centers, while other reporting has pointed to Lowe’s, Home Depot, and similar parking-lot deployments.

    The privacy issue is not only who owns the pole or camera. It is who can search the plate data, whether police can access the database, how long records are retained, whether shoppers are meaningfully notified, and whether vendor sharing settings turn private parking lots into law-enforcement search points.


    Phone numbers may become identity checkpoints

    The FCC’s proposed “know your customer” proceeding would push phone providers toward stronger identity collection for subscribers. The stated goals include fraud reduction, robocall enforcement, and accountability. But the design matters.

    A phone number is often the gateway to work, housing, banking, medical care, two-factor authentication, family communication, and public services. If ordinary phone access requires more identity documentation, policymakers should ask who is excluded, what information is stored, how long it is retained, whether it can be shared with law enforcement, and whether anonymous or low-documentation options remain available.


    Age checks are becoming identity infrastructure

    France’s age-check fight shows how online child-safety rules are becoming identity-infrastructure debates. Reuters reported that an EU court said France can enforce age checks against porn sites based in other EU countries. At the same time, the UK is debating under-16 social-media restrictions, U.S. lawmakers are advancing kids’ online-safety proposals, and state age-verification laws continue to spread.

    Child safety is a legitimate policy goal. The safeguard question is whether the law protects children without forcing everyone else to prove identity, weaken anonymity, turn private vendors into access gatekeepers, or create reusable records of lawful online activity.


    Lawful-access bills can become encryption-access bills

    Canada’s Bill C-22 debate is a useful warning signal for other democracies. Reporting from iPhone in Canada and legal commentary around the bill say Apple and Google warned that lawful-access language could pressure companies to break or weaken end-to-end encryption, limit disclosure to users, or create new government-access obligations.

    The details are Canadian, but the pattern is broader. When governments seek faster access to digital evidence, the line between lawful process and infrastructure redesign can become blurry. Encryption policy should be debated directly, not buried inside broad access powers.


    AI chats can become legal records

    A New York judge blocked a subpoena seeking ChatGPT records in a lender lawsuit, according to Reuters. The ruling protected the records in that case, but the subpoena itself is the signal.

    AI prompts, chats, drafts, uploaded files, and account logs may become discoverable records, depending on context. Public agencies, advocacy groups, businesses, and lawyers should treat AI tools as record-creating systems, not just brainstorming spaces. Sensitive legal, personnel, constituent, or strategy work should not be pasted into tools without clear rules for retention, access, privilege, and disclosure.


    AI support bots should not control the keys

    The reported Meta AI / Instagram account-recovery incident shows why AI systems need hard permission boundaries. If an AI support system can grant account access, change recovery information, override verification, or alter enforcement status, then the AI is not just answering questions. It is controlling access.

    The safeguard is simple: AI should not hold the keys by itself. Account recovery, permissions, identity verification, enforcement decisions, and high-impact changes need strong verification, human escalation, audit logs, and rollback plans.


    Security features should not disappear quietly

    Reports that AMD removed or disabled a memory-encryption feature from some consumer Ryzen systems are a useful security-governance warning. The technical details matter less than the policy lesson: security features can be enabled, disabled, tiered, or moved behind enterprise product lines in ways ordinary users may not notice.

    Public agencies and institutions should ask vendors what security features are actually enabled, which features require higher-priced products, whether firmware or licensing changes can disable protections, and how customers will be notified if a security feature is removed or downgraded.


    Axon Watch: police-tech contracts are becoming platform commitments

    Axon’s June Records and Standards release notes are a reminder that public-safety technology keeps expanding after the original purchase. Recent release notes include report redaction with audit-log tracking, search tools tied to people and vehicles, saved searches, Evidence ID search, analytics privilege copying, site-attribute restrictions, and more precise audit-log timestamps.

    That is why Axon should be reviewed as a platform vendor, not only a device vendor. A body-camera, Taser, RMS, ALPR, drone, redaction, or AI feature may be introduced through a contract, amendment, release note, configuration setting, or bundled subscription. Public officials should ask not only what is being bought today, but what future searches, integrations, retention rules, vendor access, and audit logs the platform will make possible tomorrow.


    Surveillance pricing is becoming a consumer-protection issue

    Surveillance pricing is moving from theory to statutes and lawsuits. EPIC reports that Connecticut became the second state to enact a surveillance-pricing ban, while EFF is backing a California bill to restrict personalized pricing based on personal data. Courthouse News also reported on a class-action lawsuit over an alleged surveillance-pricing scheme.

    The policy issue is simple: data collected to identify, predict, or profile people can also become data used to set the price they see. Privacy law and consumer-protection law are starting to converge.


    Direction of travel

    This week’s Signals point toward one pattern: identity and access are becoming control layers. Phone numbers, age gates, encrypted services, AI accounts, retail ALPRs, security features, and police-tech platforms all decide who can enter, who can search, who can verify, and who can be watched. The safeguard challenge is to protect people without making ordinary life depend on persistent identity trails and invisible vendor systems.


    Safeguards

    Safeguards

    A safeguards page works best when it turns broad concerns into practical questions public officials can ask before systems are purchased, connected, searched, expanded, or renewed.

    Require authority before sensitive searches

    Sensitive searches should require clear authority before they happen, not only after-the-fact review. That authority might be a warrant, court order, statute, documented case need, or narrowly defined emergency exception. But the rule should be written before the system becomes routine.

    This applies across systems: communications searches, ALPR searches, biometric searches, law-enforcement databases, immigration-enforcement access, geofence-style searches, public-benefits records, school records, and sensitive civic data. If a search can reveal where someone has been, who they communicate with, what they believe, what services they use, or whether they may be flagged by government, the threshold should be higher than convenience.

    The practical question is simple: before a person searches sensitive data, what must they document, who reviews it, and how can misuse be proven later?

    Treat ALPR audit logs as the oversight system

    ALPR oversight should not depend on trust alone. It should depend on records that can be reviewed.

    A useful ALPR audit log should show who searched, what they searched, when they searched, why they searched, whether the search was tied to a case number or documented purpose, whether a hit was acted on, whether the result was shared, and whether an outside agency or vendor employee accessed the system.

    That does not mean exposing everyone’s raw location history to the public. It means protecting individual plate data while making the governance system visible. Public officials should be able to see scan counts, hit rates, false-hit procedures, retention rules, sharing settings, outside-agency access, vendor-access logs, misuse investigations, and policy exceptions.

    A system that cannot answer who searched, why, and what happened next is not just missing a technical feature. It is missing the oversight system.

    Make vendor access visible before approval

    Vendor access is part of surveillance oversight. Contracts should not leave it vague.

    Before approving or renewing a system, public officials should know whether vendor employees can access live feeds, stored footage, plate data, case files, audit logs, search tools, support dashboards, training environments, or analytics systems. They should also know whether vendor access is logged, whether customers are notified, whether data can be used for product development, sales demonstrations, AI training, quality review, or troubleshooting, and whether access can be disabled by default.

    The safest rule is narrow access by design: no vendor access except for documented support needs, no sales or demo use without written permission, no product-development reuse without explicit approval, and no silent access to public-agency data.

    Patch quickly, then verify what happened

    When a vulnerability is already being exploited, the first question is not whether an agency plans to patch. It is whether the exposed system has already been identified, assigned, fixed, and reviewed.

    Public agencies should ask vendors and internal teams the same basic questions: Are we affected? Which systems are exposed? When was the patch applied? Who verified it? Were logs reviewed? Were accounts created, changed, or abused? Were credentials rotated? Were dependent systems affected? Were backups tested? Were users or partner agencies notified?

    Fast patching matters, but patching alone is not the whole safeguard. A patched system may still have compromised accounts, altered settings, copied data, or persistence mechanisms left behind. The fix should include proof, log review, and a short written record of what changed.

    Delete old sensitive data before it becomes breach fuel

    The best breach response starts before the breach. Collect less data, keep it for less time, separate sensitive records, and delete what no longer serves a clear public purpose.

    Old records become dangerous when they remain searchable after their original purpose has passed. A school platform, police system, vendor database, health app, personnel file, grant system, or public-records archive can become a breach problem years later if sensitive data is kept by default.

    Retention limits should be treated as security controls. If data is no longer needed, no longer legally required, and no longer serving the public purpose for which it was collected, deletion is not a loss. It is a safeguard.

    “The Government’s position fails to contend with the seismic shifts in digital technology that made possible the tracking of not only Carpenter’s location but also everyone else’s, not for a short period but for years and years.”

    — Chief Justice John G. Roberts Jr., majority opinion, Carpenter v. United States (2018)

    Governance Safeguards

    Governance Safeguards

    The strongest safeguards are built before sensitive data becomes too useful to give up.

    Keep AI away from the keys

    AI systems should not be allowed to control account recovery, permissions, identity verification, enforcement decisions, or high-impact access changes without hard limits.

    A support bot that can grant account access is not just a chatbot. It is an access-control system. An AI tool that can change permissions, summarize evidence, draft reports, flag people, alter workflows, or trigger decisions needs more than a prompt box and a terms-of-service page.

    Useful safeguards include human review for high-impact actions, least-privilege access, separate logs for AI actions, rollback plans, prompt-injection testing, escalation rules, and clear bans on using AI outputs as the sole basis for account recovery, discipline, arrest, eligibility, denial of service, or enforcement action.

    Do not make identity the price of ordinary access

    Age checks, phone-ID rules, Real ID requirements, social-media restrictions, account verification systems, and anti-fraud tools can all serve legitimate goals. But they can also make ordinary life depend on persistent identity trails.

    Policymakers should ask whether a system verifies what it actually needs to know, or whether it collects more identity than necessary. A service may need to know that a person is old enough, eligible, or authorized. It may not need to store a copy of a government ID, keep a reusable identity profile, or link lawful activity across platforms.

    Good identity policy should include privacy-preserving alternatives, data minimization, short retention, vendor limits, appeal rights, and options for people without stable documents, stable addresses, safe disclosure conditions, or conventional ID access.

    Ask what security features are actually enabled

    Security should not depend on assumptions. If a product advertises encryption, isolation, logging, retention controls, access limits, or audit tools, public agencies should ask whether those protections are actually enabled in the version they are buying.

    Officials should also ask whether features depend on a higher-priced tier, firmware setting, license term, subscription level, cloud configuration, or optional module. If a vendor removes, disables, downgrades, or paywalls a security feature, customers should receive clear notice before they rely on a protection that may no longer exist.

    The practical question is not “does this product have security?” It is: which protections are active, who controls them, what changes can disable them, and how will we know?

    Make public reporting routine, not exceptional

    Oversight works better when public reporting is scheduled before controversy begins. The La Pine data-center transparency petition is a local example: large data infrastructure raises questions about power, water, generators, noise, and public accountability even when it is not a surveillance system by itself.

    The same reporting habit should apply to sensitive technology systems: publish enough information to evaluate system purpose, data collected, vendor access, retention period, outside-agency access, number of searches, number of hits, false matches, corrective actions, policy violations, and renewal dates.

    Use a pre-approval checklist before systems go live

    Before launch, renewal, expansion, or feature activation, officials should be able to answer basic questions: What data is collected? Who can access it? What outside agencies can search it? What can the vendor see? How long is data retained? What requires a warrant, case number, or documented purpose? What audit logs exist? Who reviews the logs? What is reported publicly?

    A checklist is not bureaucracy for its own sake. It is a way to keep small procurement decisions from quietly becoming large public-governance decisions after data is already flowing.

    Bottom line

    The strongest safeguard this week is visible control over search power.

    Whether the system is Section 702, ALPR, cyber incident response, identity verification, AI account recovery, surveillance pricing, or a police-tech platform, the public needs the same basic answers: who can search, why they can search, what authority applies, how long data is kept, whether vendors can access it, whether identity checks are truly necessary, and whether misuse can be proven after the fact.

    Collect less. Connect less. Search less. Retain less. Log every exception. Make vendor access visible. Require authority before sensitive searches. Build privacy into the system before the data becomes too useful to give up.

  • Signals & Safeguards — Issue 13

    Signals & Safeguards

    Issue 13 • Wednesday, June 10, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    – Section 702 is nearing another deadline, but the fight is really about searches, warrants, and control of a powerful intelligence database.

    – The Supreme Court’s FCC decision over telecom location-data fines is a reminder that metadata is sensitive data.

    – Breach victims are often notified late, after exposed data may already be circulating.

    – Facial recognition is moving toward ordinary consumer devices, from doorbells to smart glasses.

    – Age gates, Axon updates, AI-tool compromises, campus cameras, and ad-tech data all ask who can turn sensitive data into a searchable system.


    Section 702 is now a warrant fight and a governance fight

    Section 702 of the Foreign Intelligence Surveillance Act is aimed at foreign intelligence targets outside the United States. But Americans’ communications can be swept in when they communicate with those targets, and federal agencies can later search that data without a warrant.

    That is why civil-liberties groups have focused on the search stage, not only the collection stage. The Brennan Center explains the warrant fight around U.S.-person queries; the ACLU is urging Congress to require stronger protections; and Cato warns that AI could raise the stakes by helping generate or launder investigative predicates.

    As of June 9, 2026, Reuters reports that Section 702 is set to expire June 12, after multiple short-term extensions and continuing disagreement over privacy protections. The plain-English issue is simple: a foreign-intelligence database becomes more powerful later if searches are too easy, too broad, or too weakly reviewed.

    Why this matters in Bend: Federal surveillance law shapes the privacy environment local governments operate in. If broad collection, weak search limits, and after-the-fact oversight become normal federally, local officials should be careful not to import the same logic into city technology, public-safety tools, vendor contracts, or data-sharing agreements.


    Metadata is sensitive data

    The Supreme Court’s decision siding with the FCC in the wireless-carrier fine dispute is a useful reminder that location data is not harmless just because it is metadata. Reuters reports that the case involved FCC fines connected to carriers’ sharing of customer location data, including fines of $57 million for AT&T and nearly $47 million for Verizon, with additional fines for T-Mobile and Sprint.

    Location metadata can reveal where people live, work, worship, seek care, gather, travel, and protest. The same principle applies beyond telecoms: license-plate scans, ad-tech location trails, smart-device records, voter files, school logs, and vendor-access records can all become sensitive when tied to real people.

    “Metadata absolutely tells you everything about somebody’s life. If you have enough metadata, you don’t really need content.”

    — Stewart Baker, former NSA General Counsel

    Why this matters for Oregonians: Oregon privacy policy should treat metadata as sensitive data, especially when public agencies, vendors, telecoms, or data brokers can connect it to names, addresses, devices, vehicles, or places.


    Breach victims are often the last to know

    A breach is not the only harm. Delayed notice can become a second harm. Troy Hunt’s “1000 data breaches later” essay argues that disclosure lag has grown worse even as breach databases, credential stuffing, identity fraud, and public leak sites have made exposed data more immediately useful to attackers.

    The people whose data was exposed may be the last ones to know, even when the data is already searchable, traded, or used in phishing. The safeguard lesson is direct: people cannot protect themselves from exposed data they are not told about.

    Why this matters for Oregonians: A delayed breach notice can leave residents exposed while stolen data is already circulating. Public agencies and vendors should disclose what happened, what data was affected, when they knew, and what people can actually do next.


    Meta smart glasses and Ring show facial recognition moving into ordinary devices

    Facial recognition is no longer only a government-system issue. WIRED reported that Meta removed face-recognition components from its Meta AI smart-glasses companion app after WIRED found unreleased face-recognition code. WIRED reported that the system was not publicly activated. The warning is that consumer wearables are moving toward biometric capability before clear public rules are ready.

    Reuters separately reports that Amazon’s Ring has been sued in a proposed class action alleging that its “Familiar Faces” feature unlawfully collected and stored face images without consent. That claim is an allegation in a lawsuit, not a court finding. Taken together, smart glasses and doorbells show how biometric infrastructure can enter everyday life through private devices as well as public contracts.

    Why this matters in Bend: Surveillance can enter a community through private devices as well as public contracts. Doorbells, smart glasses, storefront cameras, and platform features can create biometric data trails even when City Council never votes on a camera system.


    Warning Signals

    Warning Signals

    These items point toward where surveillance systems, identity infrastructure, public-safety platforms, and data governance may be heading next.

    Age gates are becoming identity gates

    Child safety is a legitimate policy goal. But the design of age-verification systems matters. EFF warns that age gates are spreading globally and can pressure people to prove age or identity before accessing ordinary online services. The risk is not only inconvenience. Broad age verification can normalize government-ID checks, biometric scans, wallet credentials, operating-system-level age signals, or private verification vendors as the price of ordinary internet access.

    Why this matters for Oregonians: Oregon can pursue child-safety goals without turning ordinary internet access into an identity-check system. Future proposals should minimize data collection, avoid government-ID retention, protect lawful anonymous speech, limit vendor reuse, and require independent audits.


    Axon Watch: public-safety platforms keep expanding

    Axon should not be understood only as body cameras, Tasers, or ALPR. Its May 2026 release notes and June Records and Standards release notes show continuing software and records-system updates. Echodyne also announced a public-safety radar partnership with Axon on May 27, saying the partnership supports safer and more scalable drone operations across law enforcement, homeland security, and Drone as First Responder programs.

    A feature appearing in release notes or a vendor ecosystem does not mean it has been deployed locally. But it does show the direction of the platform public agencies may be buying into.

    Why this matters in Bend: Bend and Deschutes County are already making decisions inside the Axon ecosystem. Officials should distinguish between the tools being purchased today and the platform capabilities that may become available later through updates, integrations, AI features, drones, radar, records systems, or real-time operations.


    AI developer tools are becoming supply-chain targets

    TechCrunch reports that Microsoft shut down dozens of GitHub-hosted open-source projects after hackers apparently injected password-stealing malware into tools used with AI development apps, including Claude Code, Gemini CLI, and VS Code. AI development tools can have access to local files, credentials, API keys, source code, and developer workflows. A trusted tool can become a high-leverage attack path if it is compromised.


    Campus safety systems are becoming campus surveillance systems

    CBS8 reports that more than 1,300 AI-enabled cameras have been installed across San Diego State University. Times of San Diego, republishing Daily Aztec reporting, says cameras are placed in hallways, entryways, common areas, and dorm buildings. Public institutions may deploy AI-enabled surveillance under a safety rationale before students, staff, or the public fully understand scope, capabilities, retention rules, access permissions, or oversight.

    Why this matters for Oregonians: Public schools, colleges, and universities should not treat AI-enabled camera systems as ordinary safety equipment. Officials should disclose capabilities, camera-location policies, retention rules, access permissions, vendor access, audit logs, and whether footage can be searched or shared outside the institution.


    Sanctuary policy only works if data channels cannot route around it

    Immigration enforcement does not depend only on government-owned databases. WIRED reported earlier this year that ICE issued a request for information about commercial “Big Data and Ad Tech” products that could support investigations, including tools that may involve location data from advertising technology. A formal state or local policy can be weakened if enforcement agencies route around it through commercial data, shared databases, vendors, ALPR networks, or ad-tech data.

    Why this matters for Oregonians: Oregon’s sanctuary protections are only as strong as the database permissions, vendor contracts, and commercial-data channels behind them. If enforcement can route around state limits through ad-tech data, ALPR systems, shared databases, or brokers, policy protection may fail at the technical layer.


    Public memory is becoming harder to preserve

    Techdirt, citing Nieman Lab, reports that more than 340 local news sites are now limiting the Internet Archive’s ability to preserve their stories. Publisher concerns about AI scraping are real, but the public-interest cost is also real: local accountability depends on records people can find, compare, cite, and revisit after a contract, policy, meeting, or public-safety decision fades from the front page.

    For surveillance oversight, archiving is not nostalgia. It is evidence. If local reporting, meeting records, procurement pages, and public explanations disappear or become hard to retrieve, residents and officials lose the timeline needed to evaluate promises, changes, renewals, and vendor claims.


    Data-center opposition is becoming a surveillance issue

    Communities may oppose AI data centers for ordinary civic reasons: electricity, water, land use, rates, noise, transparency, and local control. The warning signal is what happens when lawful opposition is pulled into threat-intelligence, extremism, or security-monitoring frames without clear boundaries.

    Public agencies should distinguish credible threats from lawful civic participation. Protest, petitions, testimony, public-records requests, and neighborhood organizing should not become surveillance triggers merely because the underlying project is politically or economically important.


    Direction of travel

    This week’s Signals point toward one pattern: identity, access, and memory are becoming control layers. Age checks, Axon platform features, AI development tools, campus cameras, ad-tech data, smart glasses, doorbells, telecom location records, and local archives all shape who can be identified, searched, remembered, or forgotten.


    Safeguards

    Safeguards

    A safeguards page works best when it is practical: less data, cleaner boundaries, stronger access controls, and fewer shortcuts.

    Require breach notice people can act on

    Breach notice should not be vague, delayed, or written mainly to reduce institutional embarrassment. People need facts they can use: when the organization first learned of the incident; what categories of data were affected; whether data was accessed, copied, sold, posted, or merely exposed; what systems were involved; what users should do next; what the organization has already done; whether law enforcement or regulators were notified; and where the public can find updates.

    This applies to public agencies, schools, utilities, healthcare providers, nonprofits, civic groups, and vendors holding resident data.


    Patch what attackers are already exploiting

    CISA’s Known Exploited Vulnerabilities catalog exists because some vulnerabilities are not theoretical. They are already being used. CISA added one known-exploited vulnerability on June 5 and two more on June 8. Public officials should ask vendors and internal IT teams whether any systems touching public records, evidence, payments, schools, utilities, emergency services, or public-facing portals are exposed to KEV-listed vulnerabilities.

    • Are we affected?
    • When was it patched?
    • Were logs reviewed after patching?
    • Were admin accounts created, changed, or accessed?
    • Were customers or partner agencies notified?
    • What systems depend on this vendor or platform?
    • What is the backup plan if access has to be shut down?

    Protect recovery keys, backup codes, and high-risk credentials

    TechCrunch reports that hackers are targeting Signal users’ backups in a phishing campaign. The important point is not that Signal’s encryption was broken. The risk is social engineering: tricking people into surrendering backup or recovery material.

    Recovery keys, backup codes, password-manager secrets, API keys, admin tokens, and emergency access codes should be treated as high-risk secrets. Secure services should not proactively ask users to send them. Good safeguards include phishing-resistant MFA, hardware security keys for high-risk accounts, password managers with strong recovery practices, offline backup codes, and clear rules for how staff verify security requests.


    Treat school platforms as civic infrastructure

    Federal Student Aid has posted a technology-security alert for an ongoing cybersecurity incident involving Canvas, updated May 29. Reuters and AP reported in May that Instructure reached an agreement with the ShinyHunters hacking group after the Canvas incident. Instructure said affected data included names, email addresses, student ID numbers, and messages, but not passwords, birth dates, government IDs, or financial data.

    Schools should treat learning-management systems as civic infrastructure, not just classroom software. These systems can hold assignments, grades, accommodations, messages, family contacts, student IDs, staff information, and records students need during high-pressure periods.

    Why this matters for Oregonians: Districts, colleges, and universities should require incident timelines, breach-notice rules, access logs, data minimization, vendor limits, phishing-response plans, and continuity plans for assignments and records.


    Public-safety grants need technology and data guardrails

    The Justice Department announced the Model Cities Initiative on June 3, describing it as a whole-of-city approach directing nearly $300 million in federal funding toward selected cities. The safeguard is not to reject every public-safety grant. The safeguard is to read the conditions before a community accepts the money.

    Before accepting funds, officials should disclose required technology tools, data-sharing conditions, federal task-force participation, ALPR, facial-recognition, drone, AI, or real-time operations components, reporting obligations, vendor platform commitments, audit logs, retention rules, and whether data can be searched or shared outside the local agency.

    Why this matters in Bend: Public-safety funding should not quietly commit the community to surveillance tools, federal data-sharing expectations, vendor platforms, or long-term reporting obligations. Conditions should be visible before acceptance, not discovered after systems are already in motion.


    Before AI touches public systems, set the purpose limits

    EFF reports that Dr. Matthew Guariglia testified to a House Homeland Security subcommittee that governments should not adopt powerful AI technologies without strong safeguards to protect constitutional rights. For this safeguards page, the practical rule is simple: do not connect AI to records, cameras, case files, benefits systems, schools, evidence platforms, or enforcement workflows until the purpose, data access, human review, error process, logs, retention, and vendor-use limits are clear.

    “At this level the question is not how do we rein in AI, it’s how do we rein in the agencies that would unleash AI on the American public.”

    — Dr. Matthew Guariglia, Electronic Frontier Foundation


    Governance Safeguards

    Governance Safeguards

    The strongest safeguards are built before sensitive data becomes too useful to give up.

    The question is no longer whether sensitive data exists. It does. The question is whether public institutions can prove who accessed it, why, and under what enforceable limits.

    Treat metadata as sensitive data

    Metadata can describe a life without quoting a message. Location pings, plate scans, search logs, device identifiers, camera detections, call records, badge swipes, student-platform logs, and vendor access records can reveal patterns of movement, association, belief, health, work, school, and protest.

    For Oregon policymakers, the key move is to stop treating metadata as harmless simply because it is not message content. Useful safeguards include purpose limits, shorter retention, access logs, case-number requirements, warrant requirements where appropriate, vendor-use restrictions, and public reporting.

    Require audit logs before launch, renewal, or expansion

    Do not approve surveillance or sensitive-data systems that cannot answer basic questions: who searched; what they searched; why they searched; what they accessed; whether the result was shared; whether the search was tied to a case number, warrant, emergency, or documented purpose; and whether an outside reviewer can verify the answer.

    A system without usable audit logs does not merely have a technical gap. It has an accountability gap.

    Why this matters in Bend: Audit logs are the difference between oversight and reassurance. For ALPR, Axon tools, evidence systems, AI features, drones, records platforms, or vendor dashboards, officials should be able to verify who searched, why they searched, what they accessed, and whether the result was shared.

    Limit vendor, outside-agency, federal, and immigration-enforcement access by default

    Access should be narrow by default and expanded only with clear legal authority, documented purpose, logs, retention limits, and review. That means no outside-agency access unless explicitly approved; no vendor access except for documented support needs; no sales, demo, training, or product-development use without written permission; no immigration-enforcement access unless legally required; no federal or out-of-state access without a clear legal basis and logged review; and no data sharing without purpose fields, retention limits, and periodic public reporting.

    Why this matters for Oregonians: State and local privacy rules can be undermined if outside agencies, federal users, or vendors retain broad access by default. Access limits should be technical, contractual, logged, and enforceable – not merely aspirational.

    Make public reporting routine, not exceptional

    Oversight works better when public reporting is scheduled before controversy begins. Agencies should publish enough information to evaluate sensitive systems without exposing individual residents’ raw data.

    Public reporting should include: system purpose, data collected, vendor, retention period, outside-agency access, vendor access, number of searches, number of hits, false matches or complaints, policy violations, corrective action, and renewal dates.

    That is especially important for systems that can expand through software updates, new integrations, agency-to-agency sharing, or vendor platform changes. A public report should show whether a system is still doing what officials said it would do.

    Use a pre-approval checklist before sensitive systems go live

    Before launch, renewal, expansion, or feature activation, officials should be able to answer: What data is collected? Who can access it? What outside agencies can search it? What can the vendor see? How long is data retained? What requires a warrant, case number, or documented purpose? What audit logs exist? Who reviews the logs? What is reported publicly? What happens if the system is misused?

    Before approval, renewal, or feature activation, the public should be able to see the purpose, the data, the access rules, the logs, the retention period, and the consequences for misuse.

    A simple governance test for sensitive systems

    Bottom line

    The best safeguards this week are upstream safeguards: collect less, connect less, search less, retain less, and log every exception. Whether the system is Section 702, telecom location data, ALPR, Axon software, school platforms, public-safety grants, or AI, the oversight problem is the same once data becomes searchable.

    “Sensitive data should not become useful faster than oversight becomes enforceable.”

    Public trust depends on private protections.

  • Signals & Safeguards — Issue 12: ALPR Oversight, Access Pathways, and Practical Privacy Safeguards

    Issue 12 • Wednesday, June 3, 2026

    Signals & Safeguards newsletter masthead

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • ALPR oversight reached Congress, but the first sweeping federal restriction failed in committee.
    • EFF’s new mission-creep examples show why purpose limits need technical enforcement, not just policy language.
    • Vendor platforms are expanding after purchase, making release notes part of the oversight record.
    • New location, platform, and device-signal examples show surveillance moving through access pathways, not just cameras.

    ALPR oversight reached Congress, but the first sweeping restriction failed

    Automated license plate readers are no longer only a city-contract or police-policy issue. This month, ALPR oversight reached Congress. WIRED reported that Representatives Scott Perry and Jesús “Chuy” García introduced a bipartisan amendment to a federal highway bill that would have barred recipients of Title 23 federal highway funds from using ALPRs for any purpose other than tolling. ACLU and partner groups urged the Committee to support the amendment; EPIC joined a coalition pressing the same case. Demand Progress later reported that the committee rejected it.

    Why it matters for public officials: Congress did not settle the question. Local and state governments still have to decide what rules apply before ALPR systems are purchased, renewed, expanded, or connected to larger networks.


    Mission creep shows why purpose limits matter

    EFF’s latest ALPR analysis documents the practical reason purpose limits matter: ALPR networks have been used for school residency verification, employment background checks, and noise or loud-music complaints — uses that do not feature in most public debates over whether to deploy plate readers. Once a location database exists, more users and more purposes will try to reach it. If the rules are vague, a system’s actual use can drift far beyond the original public explanation.

    Why it matters for public officials: Purpose limits should be written before deployment and enforced technically. A policy that says “serious investigations only” is weak if the software still permits broad searches for administrative, civil, or low-level purposes.


    Bend and Oregon show why policy must match permissions

    Bend and Oregon remain useful case studies, but the lesson is broader than either jurisdiction. Earlier reporting from The Source Weekly found that ICE, CBP, and Homeland Security Investigations queried Bend Police Department Flock Safety data 279 times in the first three weeks after the cameras went live. Separately, OPB reported that a lawsuit alleges Oregon State Police allowed federal immigration authorities to query Oregonians’ data through shared law-enforcement databases for years, despite Oregon’s sanctuary laws. OSP denies wrongdoing. The Oregon Capital Chronicle reported the same allegations.

    Those examples should not be repeated as old news. They should be treated as a practical reminder: a privacy rule only works if the database permissions, access settings, and audit logs match the rule.

    Why it matters for Bend and Deschutes County: Written policy matters, but it is only one layer. Contract terms, vendor settings, sharing permissions, system configuration, audit logs, and public reports all have to point in the same direction.

    “If it is law, it will be found in our books. If it is not to be found there, it is not law.”
    — Lord Camden, Entick v. Carrington (1765)


    Policy 428 appears stronger, but oversight still needs proof

    Bend Police Department’s updated Policy 428 appears to add stronger ALPR safeguards, including shorter retention for non-investigatory plate data, search logging, audit and reporting requirements, prohibited-use language, and vendor-contract requirements. That matters. It is a real improvement over a weaker policy baseline.

    But a policy is not the whole oversight system. The next questions are whether the publicly posted version is final, whether any contract or add-on incorporates the same limits, whether system settings enforce them, and whether audit reports will be usable enough for Council and residents.

    Why it matters for public officials: A policy states the rule. A contract binds the vendor. A system configuration prevents improper access. Audit logs show what happened. Public reports let elected officials verify the result. All five layers matter — and they should align before deployment, not after.

    Shared pattern

    The strongest stories on this page point in the same direction: surveillance power expands through access pathways. A local camera, a vendor database, a federal search request, a shared records system, or a platform setting can each change who can reach sensitive data. Oversight has to follow the path the data actually takes.


    Commercial location data is a national-security problem

    Reuters reported that U.S. military personnel deployed to war zones have reportedly been targeted using commercially available location data, with lawmakers warning such data can reveal troop movements and patterns of life.

    The reminder applies at every level: data collected for advertising can become useful for intelligence, enforcement, stalking, coercion, or political pressure. Public policy should treat commercial location data as sensitive infrastructure, not a marketing issue.


    Online speech, anonymity, and age checks are becoming enforcement surfaces

    Bloomberg Law reported that the Justice Department used grand-jury subpoenas to seek identifying and financial information from Reddit and X in investigations involving anonymous criticism of ICE tactics. The Verge summarized the reporting in similar terms.

    Age verification belongs in the same warning pattern. Child safety online is a legitimate policy goal, but systems that require identity documents, facial scans, third-party verification, or persistent proof of age can reduce the ability to read, speak, browse, or associate online without creating an identity trail. EFF has warned that age-check systems can become privacy infrastructure for everyone, not only children.

    The safe framing is narrow but important: when platform records, financial information, age checks, and identity-verification vendors can all be used to identify anonymous users, data minimization and legal-process rules become free-speech safeguards. Lawmakers should separate child-safety goals from systems that normalize persistent identity checks for ordinary lawful speech.

    “The makers of our Constitution undertook to secure conditions favorable to the pursuit of happiness. They conferred, as against the Government, the right to be let alone.”
    — Justice Louis Brandeis, dissenting in Olmstead v. United States (1928)


    Warning Signals

    These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.

    Warning Signals section header

    Axon Watch: release notes are part of the oversight record

    Police-technology platforms do not remain frozen after purchase. Axon RMS June 2026 release notes include Records and Standards updates involving form rollback logging, validation, access-profile configuration, and Axon DataStore notes about physical-table read access for replication accounts.

    That is not a scandal or a breach. It is a governance signal. Product updates can affect records workflows, database replication, audit visibility, search behavior, and who can reach what inside a public-safety records environment.

    Oversight question: Does the agency provide elected officials with a periodic platform change log covering major software releases, enabled features, disabled features, database-access changes, audit-log changes, AI tools, and new integrations?


    LPR systems are moving toward broader signal correlation

    Leonardo’s ELSAG SignalTrace product shows where license-plate-reader ecosystems may be heading. The company describes a system that can collect electronic signals from phones, smartwatches, fitness trackers, RFID tags, Bluetooth, Wi-Fi, and vehicle components, then correlate those patterns with LPR data. Leonardo says the tool does not decrypt device content — but movement patterns can be inferred from the devices people carry, not just the plates on their vehicles.

    Why officials should watch it: A procurement described as “license plate reader” today may sit inside a larger vendor ecosystem tomorrow. Public review should cover roadmaps, integrations, and adjacent capabilities, not only the first device installed.


    Drone-first-responder programs are becoming routine infrastructure

    Drone-first-responder programs continue moving from special-use tools toward routine 911 response. San Francisco Police Department now exceeds 600 drone flights per month, Dallas launched a drone-first-responder program tied to a larger public-safety technology platform, and Coral Springs approved an Axon-linked DFR expansion through an existing agreement. Meanwhile, Ohio is debating warrant and equipment rules.

    Why officials should watch it: Drone programs can normalize faster than governance frameworks. The pilot stage is the best moment to define launch rules, livestream access, retention, evidence use, mutual-aid sharing, audit logs, and public reporting.

    Direction of travel

    This week’s signals point to a broader pattern: public-safety technology is becoming a platform environment. Plate readers can connect to device signals. Evidence systems can connect to records, AI tools, and partner sharing. Commercial location data can become intelligence. Online speech can become legal-process data. Drones can become routine response infrastructure.

    The safeguard question is not only what the tool does on day one. It is what the system can connect to next.

    “As with GPS information, the time-stamped data provides an intimate window into a person’s life, revealing not only his particular movements, but through them his familial, political, professional, religious, and sexual associations.”
    — Chief Justice John Roberts, Carpenter v. United States (2018)


    Safeguards

    Good safeguards usually start with less data and clearer boundaries.

    Safeguards section header

    Define access before deployment, not after the first complaint

    Before any camera, database, drone program, records platform, or evidence system is approved, the governing body should be able to answer in plain language: who can search this data? Can federal agencies reach it directly or indirectly? Can outside agencies search it? Can the vendor see, export, or reuse it? Can partner agencies receive alerts or shared results? If those questions do not have documented answers, the policy is not finished.

    Troy, New York’s model — written limits on immigration and First Amendment searches, nationwide-lookup restrictions, and mandatory audits before cameras stayed live — offers a useful template.


    Make the contract match the policy — and the software match the contract

    A policy manual is not a safeguard if the vendor platform ignores it. Purpose limits should appear in account permissions, sharing settings, role-based access controls, retention configurations, vendor support restrictions, and integration rules. The practical test is simple: if the policy prohibits a use, can the system still do it with two clicks? If yes, the policy needs technical enforcement.

    Axon RMS June 2026 release notes discussing physical-table read access for replication accounts are a reminder that routine product updates can change what a vendor can reach inside a records system — which is why contract language on data access should be reviewed at renewal, not just at procurement.


    Require audit logs that elected officials can actually read

    Audit logs should not be symbolic. Useful logs capture who searched, what agency they represented, what documented purpose they gave, whether a case number or legal process existed, what result was returned, and whether the data was exported or shared. Public audit reporting should protect sensitive investigative details, but it should still give elected officials and residents enough information to evaluate whether the system is being used as promised.


    Keep identity and movement data from becoming permanent trails

    Age-verification systems, account-linking tools, location analytics, ALPR networks, and device-signal systems should minimize data by design. A system built to answer a narrow question — such as whether a user meets an age threshold or whether a vehicle is connected to a specific investigation — should not create a permanent identity or movement trail. Good safeguards include short retention, no secondary use, no vendor reuse for advertising or product development, no unnecessary biometric or government-ID retention, and independent security review.


    Before approval, renewal, or expansion, ask:

    • What data is collected, and what data is deliberately not collected?
    • How long is it retained, and who can search it?
    • Can outside agencies, federal agencies, or immigration-enforcement agencies access it directly or indirectly?
    • What can the vendor see, change, export, or use for support, training, demos, or product development?
    • Are searches logged with user, agency, purpose, case number, result, and sharing activity?
    • Are audit results published in a usable public format?
    • Do the policy, contract, and system configuration require the same safeguards?
    • Who approves new integrations, AI features, sharing settings, or platform expansions?
    • What happens if the vendor changes the product after approval?

    Bottom line: The best safeguards this week are disciplined ones: define access before deployment, make the contract match the policy, make the software enforce the contract, log every search, publish usable audit results, and collect less data than the technology makes possible. Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.

    “What a person knowingly exposes to the public, even in his own home or office, is not a subject of Fourth Amendment protection. But what he seeks to preserve as private, even in an area accessible to the public, may be constitutionally protected.”
    — Justice Potter Stewart, Katz v. United States (1967)


    Signals and Safeguards footer

  • Signals & Safeguards Issue 11: Bend’s ALPR Decision, the FBI’s Nationwide Plate-Reader Push, and the New Hampshire Model

    Signals & Safeguards newsletter masthead

    Issue 11 • Wednesday, May 27, 2026

    A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.

    At a glance

    • Bend is now expected to get public input before the next vote on stationary Axon ALPR cameras.
    • Federal reporting shows the FBI wants nationwide, near-real-time access to license-plate-reader data.
    • ALPR is spreading beyond fixed police cameras into state networks, vendor platforms, and school-bus systems.
    • The key oversight question is access: who can search the data, for what purpose, under what limits, and with what public proof?

    Bend’s next ALPR decision should not be treated as a routine contract add-on

    Bend’s next surveillance decision is no longer theoretical. After shutting down its Flock Safety cameras earlier this year, Bend officials are now considering stationary Axon automated license plate reader cameras.

    The first important development came from The Source Weekly, which reported that Bend officials were looking at Axon as a possible new stationary ALPR vendor. According to the reporting, the proposal could be handled as an add-on to Bend’s existing Axon contract, and more than 70 Bend Police cruisers have already used Axon Fleet 3 camera systems with ALPR capabilities since July 2023. (Source Weekly, May 20)

    That matters because a stationary ALPR system is not just another camera. It creates a searchable record of vehicle movements. It can connect to vendor systems, agency workflows, evidence platforms, audit logs, retention settings, and future software features. If the rules are weak at the start, the public may not understand what was approved until the system is already in place.

    The second important development is better news for public oversight. A follow-up Source Weekly story reported that, after public interest, City Manager Eric King would bring the stationary ALPR decision to Council for a vote and allow public input before the decision moves forward. The same article reported that Axon and Bend Police would evaluate two demonstration ALPR units and begin phased installation of cameras at Bend entry and exit points in the coming year, according to King’s report. (Source Weekly, May 22)

    That process matters. Bend residents should not have to learn about surveillance expansion only after contract language, demo units, or vendor workflows are already in motion. Public input is strongest before a system becomes normal, before data starts flowing, and before future upgrades are treated as minor technical changes.

    Why it matters for Bend: Bend has already learned that ALPR oversight cannot stop at vendor selection. The public needs clear answers before any stationary ALPR system returns: who can search the data, whether outside agencies can access it, whether federal immigration searches are technically blocked, how long plate data is retained, what audit logs show, whether vendor staff can access the system, and whether future features can be activated without a new public process.


    The FBI’s ALPR request shows why local camera decisions can become national access decisions

    Bend’s decision does not happen in isolation. National reporting now shows why local ALPR rules need to account for federal access before the data exists.

    404 Media reported that the FBI wants to buy nationwide access to automated license plate reader data, which could allow the agency to track vehicles, and by extension people, across the country without a warrant. WIRED framed the request as an effort to obtain “near real-time” access to U.S. license plate readers, and Ars Technica reported that the FBI wants U.S.-wide access to license plate cameras with data in near real time. (404 Media) (WIRED) (Ars Technica)

    That is the national context for local ALPR decisions. A city may approve cameras for stolen vehicles, serious crimes, or public-safety emergencies. But once plate scans enter a vendor network, the data may become valuable to other agencies, other jurisdictions, and future search tools that were not central to the original local debate.

    This does not require assuming bad faith by local officials. It simply recognizes how surveillance infrastructure works. The usefulness of a system grows when it connects to other systems. That is why access limits, retention limits, audit logs, purpose rules, vendor-access controls, and public reporting need to be built before deployment, not negotiated after the data becomes useful to others.

    Why it matters for Bend: If Bend brings stationary ALPR back through Axon, the policy question should not be limited to whether the cameras help police solve crimes. Councilors and residents should also ask what network the cameras join, whether Bend data can be searched outside the city, whether outside access is disabled by default, and whether future sharing requires public notice and Council approval.

    “A dependence on the people is, no doubt, the primary control on the government; but experience has taught mankind the necessity of auxiliary precautions.”
    — James Madison, The Federalist No. 51 (1788)


    School-bus cameras could become mobile ALPR infrastructure

    ALPR expansion is not limited to fixed cameras on poles or cameras mounted on police vehicles.

    404 Media reported that BusPatrol has installed AI cameras on tens of thousands of school buses and now wants to let law enforcement search the license-plate data those buses collect while driving. The original purpose is school-bus safety and stop-arm enforcement. The warning signal is what happens when that safety system becomes a mobile plate-reader network. (404 Media)

    That shift matters because public approval for one purpose does not automatically justify another. Residents may support camera enforcement to protect children at bus stops while still objecting to broad police searches of location data collected across neighborhoods.

    The safeguard lesson is direct: purpose limits need to be written before deployment. A school-bus safety system should not become general law-enforcement infrastructure without public notice, public debate, retention limits, access restrictions, and audit logs.

    Use New Hampshire as the strict ALPR model

    New Hampshire offers one of the clearest examples of strict ALPR regulation. Under New Hampshire RSA 261:75-b, number-plate scanning devices are limited to law-enforcement use and may be used only for specific purposes, such as identifying stolen vehicles, wanted or missing persons, suspended or revoked registrations, outstanding warrants, or vehicles connected to certain criminal investigations. (NH RSA 261:75-b)

    The law also says an ALPR alert alone does not create reasonable suspicion for a stop; an officer must visually confirm the plate or develop independent reasonable suspicion. Routine scanned-plate data may not be recorded or transmitted and must be purged within three minutes, unless the alert leads to a citation, arrest, protective custody, or another specified documented action. HB 1059 removed the scheduled repeal of the law, making that framework permanent. (BillTrack50 HB 1059)

    That model matters because it shows ALPR safeguards do not have to be vague. A law or policy can define who may use the system, what purposes are allowed, how quickly data must disappear, what confirmation is required before action, and what cannot be shared.

    Shared pattern: ALPR is becoming network infrastructure

    The strongest stories this week point in one direction: ALPR is no longer only a local camera purchase. Fixed city cameras, police vehicle cameras, state pilots, vendor platforms, retail parking lots, and school-bus systems can all generate searchable vehicle-location data.

    A tool introduced for one purpose can later become useful for another: stolen-car recovery, traffic enforcement, immigration enforcement, retail security, school-bus safety, federal investigations, or broad movement tracking.

    That is why Bend’s next step matters. The central question is no longer only, “Should this camera be installed?” It is, “What network does this camera join, who can search it, what vendors or subcontractors can access it, how long the data remains useful, and whether the public can verify the answers?”

    Surveillance oversight works best before the system becomes infrastructure.

    “Experience should teach us to be most on our guard to protect liberty when the government’s purposes are beneficent.”
    — Justice Louis Brandeis, dissenting in Olmstead v. United States (1928)


    Warning Signals

    These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.

    Warning Signals section header

    Axon Watch: evidence platforms are expanding around AI, records, sharing, and retention

    This week’s Axon Watch is not only about new features. It is about how public-safety technology is becoming a connected platform: cameras, evidence storage, records, AI report drafting, case review, partner sharing, retention rules, and audit trails.

    Axon’s May 2026 release notes show several changes officials should watch closely. In Axon Evidence, the May DEMS update includes Case Agent, an AI tool that can reason over selected case evidence and provide citation-backed responses; Advanced Case Sharing, which gives partner organizations controlled access to shared cases and evidence; more human-readable audit-trail exports; configurable media-view permissions; evidence-search API rate-limit changes; and retention categories that can be configured from one day up to 99 years. (Axon DEMS May 2026 release notes)

    Axon Records also received May updates affecting report writing, report search, audit-log sorting, and DataStore access controls. Axon’s cameras and sensors release notes show the continuing deployment cadence for the device side of the same ecosystem. (Axon RMS May 2026 release notes) (Axon Cameras and Sensors May 2026 release notes)

    Draft One deserves special attention. Axon’s own product guide says Draft One can be used on “any playable audio/video files supported by Axon Evidence,” not just body-worn camera footage. That means the oversight question is broader than “Can AI draft a police report from body-camera audio?” It is: what evidence types can feed AI-generated narratives, who can run the tool, how drafts are reviewed, whether edits are auditable, and whether the final report clearly reflects what came from the officer rather than the system. (Axon Draft One product guide)

    This matters because Axon’s AI business is not a side experiment. Investor-facing reporting says Axon’s AI revenue grew sharply in Q1 2026, alongside broader growth in software, connected devices, records, and real-time operations. (Axon Q1 2026 AI revenue item)

    For public officials, the key point is simple: when a vendor platform expands, oversight has to expand with it. ALPR, body cameras, evidence storage, AI report drafting, records systems, case sharing, and retention settings should not be reviewed as isolated tools if they operate inside the same ecosystem.


    Cleveland shows why written ALPR limits need technical enforcement

    Cleveland appears to be another warning about the gap between policy promises and system behavior. Reporting mirrored by MSN says records showed Cleveland’s Flock network was used for immigration-related searches, with the city blaming Flock and drones after logs showed searches that raised concerns. (MSN mirror)

    If a city says ALPR will not be used for immigration enforcement, that promise has to be reflected in technical controls. Are outside agencies blocked by default? Are search purposes required? Are federal queries technically prevented? Are vendor settings independently reviewed? Are audit logs public enough for elected officials and residents to verify compliance?


    Vehicle privacy now includes apps, stores, accounts, and purchase histories

    Vehicle surveillance is no longer only about cameras reading plates. Forbes reported that federal prosecutors demanded identifying information from Apple, Google, and Amazon connected to users of the EZ Lynk vehicle-tuning app. The reporting says the demand sought information including names, addresses, IP addresses, and purchase histories, and that the demand to Google alone could cover more than 100,000 users. (Forbes)

    Cars and vehicle-related behavior can now be connected through license plates, app stores, cloud accounts, connected-car services, purchase histories, repair tools, insurance systems, location data, and payment records. The safeguard question is not only whether a camera can see a car. It is whether vehicle-related data can be used to identify large groups of people after the fact.


    Age verification is becoming identity infrastructure

    Child safety online is a legitimate public goal. But the design of age-verification rules matters. Georgia Tech researchers reported that online age checks can create privacy risk when verification systems collect and share sensitive data such as face images and device fingerprints. EFF also warned that lawmakers are moving toward broad youth social-media restrictions while the evidence base remains contested. (Newswise / Georgia Tech) (EFF)

    The trend is broader than ID upload. Colorado’s OS-level age-data proposal, Meta’s AI-based age enforcement, and similar proposals point toward systems where apps, operating systems, platforms, or AI models infer or verify age before people can access ordinary online spaces. (Reclaim the Net) (TechNewsWorld)

    Direction of travel

    This week’s signals point in the same direction: data collected for one purpose is becoming useful for another. ALPR systems can become federal search tools. Evidence platforms can become AI report-writing systems. Age checks can become identity infrastructure. Vehicle apps can become investigative datasets. The safeguard challenge is to define access before the system becomes too widespread to limit.


    Safeguards

    A safeguards page works best when it gives officials practical models: shorter retention, narrower access, public review, usable audit logs, and clear limits before systems become infrastructure.

    Safeguards section header

    Look to Connecticut and Troy for access and immigration-use guardrails

    New Hampshire is not the only model. Connecticut’s SB 397 offers another strong example because it connects ALPR limits with immigration-enforcement protections. The details should be reviewed carefully before copying the language, but the policy lesson is clear: ALPR rules can address civil-rights concerns directly, including whether local data can be used to support federal immigration enforcement.

    Troy, New York, offers a city-level example. After public conflict over Flock cameras, the mayor and council agreed on new rules that included stronger limits on data sharing, annual audits, restrictions on immigration-enforcement use, limits involving public demonstrations, and controls around nationwide lookup features. (Times Union)

    For Bend, the lesson is not to copy any one jurisdiction word for word. The lesson is that guardrails can be written before approval. A city can require narrow purpose limits, outside-agency restrictions, immigration-use rules, audit access, public reporting, and Council review before cameras are installed.


    Cambridge shows cities can reassess and shut tools down

    Surveillance oversight should not end at the purchase date. Cambridge, Massachusetts, recently voted to end its ShotSpotter contract after public debate and a close Council vote. The decision shows that cities can reassess surveillance tools after deployment and decide that a system no longer meets local standards for trust, accuracy, cost, civil rights, or public accountability. (Cambridge Day)

    That matters for ALPR because approval should not be treated as permanent. Any new Bend policy should include renewal dates, public reporting, independent review of audit logs, complaint pathways, and a real off-ramp if the system fails to meet the community’s standards.


    Treat procurement ethics as a privacy safeguard

    Surveillance procurement is not just about price and features. It is also about public trust. Bend already has a procurement ethics and reporting page that describes ethics commitments, reporting options, and a confidential third-party reporting tool for concerns involving fraud, misconduct, policy violations, or ethics issues. Oregon law also limits gifts from sources with legislative or administrative interests, and Oregon ethics rules help define when a source has an interest in public decisions, contracts, or use of public funds. (City of Bend procurement ethics) (ORS 244.025) (Oregon ethics rules)

    Those rules matter in surveillance procurement because vendor relationships can shape public infrastructure for years. Demo units, pilots, add-ons, contract amendments, software subscriptions, AI upgrades, and support access should all be documented clearly.

    When the product is surveillance infrastructure, procurement ethics become privacy safeguards. Public officials should know what vendor contacts occurred, what features were demonstrated, what contract pathway is being used, whether subcontractors or support staff can access data, and whether future add-ons will return to Council before activation.


    Do not let cybersecurity become the forgotten access-control layer

    Reuters reported that vulnerability exploitation surpassed stolen credentials as an initial breach vector in Verizon’s 2026 breach report, while AI is helping attackers move faster. Separately, Axios reported that a senator requested a classified briefing after CISA and DHS credentials were exposed through a contractor’s GitHub repository, and WIRED reported on a software-supply-chain attack spree that compromised developer tools and open-source ecosystems. (Reuters) (Axios) (WIRED)

    The practical lesson is simple: access controls are only as strong as the systems behind them. Public agencies should require MFA, least-privilege access, credential rotation, secrets scanning, vendor incident reporting, software dependency review, patch timelines, and logs that show when vendors, subcontractors, or contractors accessed sensitive systems.

    Bottom line

    The best safeguards this week are practical: require public review before expansion, narrow the purpose, shorten retention, block outside access by default, prohibit immigration-use unless clearly authorized by law, require visual confirmation before enforcement action, log every search, audit the logs, disclose vendor and subcontractor access, and make shutdown or nonrenewal a real option.

    Public input is the primary control. But public input works best when it is backed by auxiliary precautions: enforceable rules, technical limits, audit trails, and consequences before surveillance systems become too widespread to limit.

    “If men were angels, no government would be necessary.”
    — James Madison, The Federalist No. 51 (1788)


    Signals and Safeguards footer