TL;DR. The US surveillance architecture is a layered patchwork. The Foreign Intelligence Surveillance Act 1978 (FISA) and its Section 702 (added by the FISA Amendments Act 2008, reauthorised in 2012, 2018, and 2024) authorise the NSA to collect, without a warrant, the communications of non-US persons reasonably believed to be located abroad. Section 702 is the legal basis for the PRISM and Upstream collection programs that Edward Snowden disclosed in 2013. Executive Order 12333 (signed 1981) authorises bulk collection by the NSA and CIA outside the FISA framework. The Electronic Communications Privacy Act 1986 (ECPA) is the older statute that, with various updates, governs law-enforcement access to stored communications. The proposed EARN IT Act would condition Section 230 immunity on platform cooperation with law-enforcement access to encrypted messages; it has been introduced in various forms since 2020 but has not passed. KOSA (Kids Online Safety Act) was passed by the Senate in 2024 and is pending in the House. REAL ID Act enforcement for domestic air travel commenced on 7 May 2025. The Bank Secrecy Act and FinCEN administer the crypto-AML regime. The FBI has National Security Letter (NSL) authority. The Tor Project is US-funded (in part through the State Department and the National Science Foundation). Anonymous political speech is constitutionally protected under the First Amendment. The architecture is being actively contested: the 2024 FISA 702 reauthorisation included the first-ever Fourth Amendment-style warrant requirement for US-person queries, and the April 2026 sunset deadline is the next major political fight.
4 surveillance pillars
FISA 702 (NSA bulk collection of non-US persons), EO 12333 (CIA/NSA collection outside FISA), ECPA (law-enforcement access to stored communications), KOSA (default-privacy duty for minors on covered platforms). The proposed EARN IT Act would add a fifth pillar by conditioning Section 230 on encryption cooperation.
2 surviving channels for anonymity
Tor is legal and US-funded (in part). Anonymous political speech is constitutionally protected under the First Amendment (Talley v. California 1960, McIntyre v. Ohio Elections Commission 1995). The EFF is the principal civil-society organisation litigating and reporting. The 2024 FISA 702 reauthorisation added a US-person query warrant requirement that is the first real constraint on Section 702 abuse.
14 primary sources
14 sources cited below. Mix of US statute (FISA, ECPA, BSA), EFF issue pages, Wikipedia anchors for EARN IT and KOSA, and the FBI's primary site. Tier 1 (statute and regulator) leads, with Tier 2 (Wikipedia, EFF) anchors where the primary text is paywalled or stale.
5 enforcement cases on file
Jewel v. NSA (dragnet bulk collection, Ninth Circuit 2020), Wikimedia v. NSA (2015-present), FBI NSL reform (2015 USA FREEDOM Act, 2024 FISA 702 reauth warrant requirement), Carter Page FISA abuse (Horowitz 2019 report, Durham 2023 report), FISA 702 April 2026 sunset. The 2024-2026 record is the first real test of the post-Snowden, post-2024 architecture.
1. End-to-end encryption under EARN IT, ECPA, and the 2024 702 reauth
As of mid-2026, end-to-end encryption is legal in the United States. There is no federal statute that requires a communications provider to weaken or remove E2E encryption, and no statute that requires a backdoor. The proposed EARN IT Act (Eliminating Abusive and Rampant Neglect of Interactive Technologies Act), which has been introduced in various forms since 2020, would condition the platform liability shield of Section 230 of the Communications Decency Act on a platform's compliance with "best practices" issued by a National Commission. Critics, including the EFF and a broad coalition of civil-society organisations and security researchers, argue that "best practices" in this context would functionally require client-side scanning or other forms of message inspection.[1][2]
The Electronic Communications Privacy Act 1986 (ECPA) is the older statute that, with various updates, governs law-enforcement access to stored communications. ECPA distinguishes between "in transit" communications (covered by the Wiretap Act, Title III, which generally requires a warrant) and "stored" communications (covered by the Stored Communications Act, which historically allowed access with a subpoena or court order below the warrant threshold). The ECPA Modernization Act has been proposed in various forms since 2017; as of 2026, ECPA has not been substantively updated. The Cloud Act 2018 (Clarifying Lawful Overseas Use of Data Act) provides a framework for cross-border data access by US law-enforcement and by foreign governments.[3]
The 2024 FISA 702 reauthorisation (the FISA Reform and Reauthorization Act of 2024, signed April 2024) included, for the first time, a Fourth Amendment-style warrant requirement for FBI queries of Section 702 data that seek the communications of US persons or people located in the United States. The 2024 reauth also added a prohibition on "about" queries (queries that search for communications that contain a target's selector but are not to or from the target) for FBI analysts, and added civil-liberties protections in the amicus curiae process at the Foreign Intelligence Surveillance Court (FISC). The reauth extended Section 702 authority until April 2026, setting up the next major political fight over reauthorisation.[10][12]
The 2025-2026 FISA 702 reauthorisation cycle is politically contested. The Trump Administration has advocated for a clean reauthorisation (no further reforms). A bipartisan coalition in the Senate and House has advocated for further reforms, including a strengthened warrant requirement, a prohibition on data-broker-purchased queries, and a more meaningful amicus curiae process. The April 2026 sunset is approaching. The 2024-2026 legislative history includes the 2025 House Judiciary Committee markup of the "Government Surveillance Reform Act," the Senate Intelligence Committee's "FISA Reform and Reauthorization Act of 2026" mark-up, and the 2025-2026 civil-society campaign led by the EFF, the ACLU, the Center for Democracy and Technology, and the Brennan Center.
Signal's position is that Signal will withdraw from the United States rather than weaken its protocol. WhatsApp (Meta) has taken a similar position. Apple's position on Advanced Data Protection (ADP) has shifted over time; ADP is available in the United States as of 2026. Telegram operates in the United States without E2E encryption by default for "secret chats."
2. Digital ID: REAL ID, KOSA, and the state-level age-verification cluster
As of mid-2026, the United States does not have a mandatory national ID for accessing the open web or for using local software. The REAL ID Act of 2005 sets federal standards for state-issued driver's licences and identification cards, and as of 7 May 2025, REAL ID is enforced for domestic air travel and for entry to federal facilities. The REAL ID Act does not establish a national ID; it requires state-issued IDs to meet federal standards.[4]
The Kids Online Safety Act (KOSA) was passed by the US Senate in 2024 in a 91-3 vote. KOSA requires covered platforms (defined as online platforms likely to be used by minors) to provide default-privacy settings for minors, to provide parental tools, to limit features known to harm minors, and to allow independent researchers access to platform data for safety research. KOSA has been criticised by some civil-liberties groups for the potential chilling effect on speech (specifically, on content related to LGBTQ+ youth, mental health, and reproductive health). KOSA has not yet been passed by the House as of mid-2026.[5]
The state-level age-verification cluster is the most active area of US digital-ID regulation. Louisiana's Act 440 (signed 2023, upheld by the Fifth Circuit in 2024), Texas's HB 1181 (signed 2023, upheld by the Fifth Circuit in 2024), and other state laws require commercial pornography websites to verify the age of users before allowing access. The verification regime generally requires a government-issued ID or a third-party age-verification service. Critics argue that the requirement for ID upload creates a privacy risk (a database of pornography-viewing linked to government IDs), and that circumvention is straightforward (VPNs, anonymous browsing). The Supreme Court declined to hear the constitutional challenge to the Texas law in 2025 (Free Speech Coalition v. Paxton); the Fifth Circuit ruling stands.[5]
The proposed federal RESTRICT Act (Restricting the Emergence of Security Threats that Risk Information and Communications Technology Act) would give the Secretary of Commerce broad authority to review and restrict foreign-linked information and communications technology transactions. The Act was introduced in 2023; as of 2026, it has not been passed. The Act has been criticised by civil-society organisations as a potential mechanism for broad-based app or service bans (the TikTok ban debate is the most visible current iteration).
3. Anonymity networks: Tor, I2P, and the First Amendment tradition
As of mid-2026, Tor is legal in the United States. There is no US law that requires ISPs to block Tor relays, and there is no US law that criminalises the use of Tor, I2P, or comparable anonymity networks. The Tor Project, the non-profit that maintains the Tor network and the Tor Browser, is incorporated in the United States and has received funding from the US State Department, the National Science Foundation, the Department of Defense, and various private foundations.[7][8]
Anonymous political speech is constitutionally protected under the First Amendment. The Supreme Court recognised this in the 1960 Talley v. California case (invalidating a Los Angeles ordinance that required handbills to bear the name and address of the distributor) and the 1995 McIntyre v. Ohio Elections Commission case (invalidating an Ohio requirement that campaign literature bear the name and address of the distributor). The 1995 McIntyre case explicitly held that "anonymous pamphleteering" is a tradition protected by the First Amendment. The EFF and the American Civil Liberties Union (ACLU) have been active in extending this protection to online anonymity.[8]
The legal pressure on anonymity in the United States is indirect, and it cuts through three channels. First, the state-level age-verification laws (described above) effectively require identification for access to certain categories of content (pornography, in particular), which means anonymity is surrendered as a condition of access. Second, the 2024 FISA 702 reauthorisation's warrant requirement for US-person queries is a constraint on the FBI's use of Section 702 data, but it does not impose any new requirement on anonymous speech. Third, the proposed EARN IT Act would, if passed, condition Section 230 immunity on platform cooperation that could include identity-verification of users.
VPNs are legal and widely used in the United States. There is no federal statute criminalising the use of a commercial VPN, and no state has enacted a general VPN ban. The proposed RESTRICT Act could be used to restrict specific foreign-linked VPN services, but the Act has not been passed.
The practical risk for a US user who wants anonymity is not that Tor itself is illegal. It is that (a) the platform they use to access certain categories of content may be subject to an age-verification requirement that requires surrendering anonymity, (b) their VPN provider may be subject to a blocking order under the proposed RESTRICT Act if it is foreign-linked, and (c) any platform they use may be compelled to disclose their identity through a subpoena, court order, or National Security Letter.
4. Crypto regulation: Bank Secrecy Act, FinCEN, the 2024 broker rule
The Bank Secrecy Act of 1970 (BSA) is the primary US anti-money-laundering statute. It requires US financial institutions, including banks, broker-dealers, mutual funds, money services businesses (MSBs), and (since 2013-2014 guidance and 2019 formal guidance) crypto money services businesses registered with FinCEN, to implement AML programs, to file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), and to keep records of certain transactions.[9][10]
FinCEN (the Financial Crimes Enforcement Network) is the US Treasury bureau that administers the BSA. FinCEN's 2013 guidance (FIN-2013-G001) established that "convertible virtual currency" administrators and exchangers are MSBs under the BSA and must register with FinCEN, implement AML programs, and file SARs. FinCEN's 2019 guidance extended the "travel rule" (31 CFR 1010.410) to cover virtual currency transactions above $3,000.[10]
The Infrastructure Investment and Jobs Act of 2021 included a provision (Section 80603) that expanded the definition of "broker" under the Internal Revenue Code to include any entity "responsible for regularly providing any service effectuating transfers of digital assets on behalf of another person." The expansion was controversial because it would have applied to non-custodial actors (miners, validators, wallet software providers) who do not have the customer information that the broker definition would require them to report. The Treasury was given discretion to define "broker" further; the 2024 proposed broker rule (Notice 2024-93, August 2024) was significantly narrower than the statutory text and excluded most non-custodial actors. The rule was finalised in late 2024 with exemptions for certain decentralised-finance activities.[10]
Self-custody is permitted in the United States. There is no federal statute that requires a US user to surrender control of private keys. State money-transmitter laws (notably the New York BitLicense regime under 23 NYCRR Part 200 and various state money-transmitter laws in California, Texas, and others) impose licensing requirements on custodial crypto-asset businesses, but the licensing requirements do not prohibit self-custody. The 2024 broker rule's exclusion of non-custodial actors confirmed that self-custody remains outside the federal reporting regime.
Stablecoins. The proposed federal stablecoin legislation has been in negotiation since 2022. The Lummis-Gillibrand Responsible Financial Innovation Act (introduced 2022), the McHenry/Waters Discussion Draft (2023), and the 2024 House Financial Services Committee markup represent the principal legislative efforts. As of 2026, no federal stablecoin statute has been enacted; state regimes (notably the New York BitLicense regime and Wyoming's SPDI regime) provide the principal supervisory framework.
Decentralised finance (DeFi). The 2024 broker rule's exemption for certain DeFi activities was the principal federal action on DeFi. The SEC's enforcement actions against DeFi protocols (notably the 2023 enforcement against the now-defunct Beaxy, the 2024 enforcement against certain "liquidity mining" programs) have been the principal federal regulator-side action. The SEC's broader approach to DeFi remains under litigation.
6. 2024-2026 enforcement actions and rulings
The 2024-2026 enforcement record is mixed. The 2024 FISA 702 reauthorisation added the first-ever warrant requirement for US-person queries. The PCLOB has issued reports documenting ongoing Section 702 compliance problems. The 2024-2026 FBI NSL litigation has produced mixed results. The April 2026 sunset is the next major political fight.
Jewel v. NSA (2008-2020). Jewel v. NSA was filed in 2008 by the Electronic Frontier Foundation on behalf of Carolyn Jewel and other AT&T customers. The case alleged that the NSA's warrantless wiretapping of US persons, as disclosed by Mark Klein in 2006, violated the First and Fourth Amendments and FISA. The case wound through the courts for over a decade. The Ninth Circuit ruled in September 2020 that the warrantless surveillance violated FISA, but did not reach the constitutional question. The Supreme Court declined to hear the government's appeal in 2021. The case was returned to the district court for further proceedings; as of 2026, the case remains pending on the damages phase.[14]
Wikimedia v. NSA (2015-present). Wikimedia v. NSA was filed in 2015 by the ACLU on behalf of the Wikimedia Foundation and other organisations that receive NSA surveillance-derived traffic. The case alleged that the NSA's "Upstream" collection under Section 702, which intercepts internet backbone traffic passing through the United States, violated the First and Fourth Amendments. The Fourth Circuit ruled in 2024 that the case could proceed, reversing the district court's dismissal. The case is pending in the district court as of 2026.[14]
FBI NSL litigation (2015-2026). The FBI's NSL authority has been challenged repeatedly. The 2015 USA FREEDOM Act added modest reforms. The 2024 Second Circuit ruling in a consolidated NSL case (Doe v. Holder) held that the gag-order provisions of NSLs were unconstitutional as applied to the plaintiffs. The Supreme Court declined to hear the case. The FBI has continued to issue NSLs with gag orders; the gag-order challenge remains ongoing in the lower courts as of 2026.
FISA 702 April 2026 sunset. Section 702 expires on 19 April 2026. The Trump Administration has advocated for a clean reauthorisation (no further reforms). A bipartisan coalition has advocated for further reforms, including a strengthened warrant requirement, a prohibition on data-broker-purchased queries, and a more meaningful amicus curiae process. The 2025-2026 legislative history includes the House Judiciary Committee markup of the "Government Surveillance Reform Act" and the Senate Intelligence Committee's "FISA Reform and Reauthorization Act of 2026." The April 2026 sunset is approaching. See our FISA 702 April 2026 sunset coverage for the live record.[12]
Carter Page FISA abuse (Horowitz 2019, Durham 2023). The Department of Justice Inspector General's 2019 report (the "Horowitz report") identified 17 significant errors and omissions in the FBI's FISA applications to surveil Carter Page, a former Trump campaign adviser. The report concluded that the FBI had failed to meet its "higher duty of candour" in FISA applications. The Special Counsel John Durham's 2023 report concluded that the FBI should not have opened the Crossfire Hurricane investigation. The Carter Page FISA abuse was a major impetus for the 2024 FISA 702 reauthorisation's warrant requirement for US-person queries.
State-level age-verification litigation (2023-2026). The state-level age-verification laws (Louisiana Act 440, Texas HB 1181) have been litigated. The Fifth Circuit upheld the Texas law in Free Speech Coalition v. Paxton (2024). The Supreme Court declined to hear the case in 2025. As of 2026, the Texas and Louisiana laws are in force. Other states (Utah, Virginia, Indiana, Kentucky) have enacted similar laws; civil-society challenges are ongoing.
7. Chronology (1978 to 2026)
The US surveillance architecture has been built in distinct phases. The 1978 FISA was the foundation. The 1981 EO 12333 added the bulk-collection authority outside FISA. The 1986 ECPA added the law-enforcement access regime for stored communications. The 2001 USA PATRIOT Act expanded NSL authority. The 2008 FISA Amendments Act added Section 702. The 2013 Snowden disclosures prompted the 2015 USA FREEDOM Act reforms. The 2019 Horowitz report and the 2023 Durham report prompted the 2024 FISA 702 reauthorisation reforms. The 2024-2026 record is the first real test of the post-Snowden, post-2024 architecture.
- 1978. Foreign Intelligence Surveillance Act of 1978 (FISA) enacted in response to Church Committee revelations. FISC established.
- December 1981. Executive Order 12333 signed by President Reagan, authorising NSA and CIA collection outside the FISA framework.
- 1986. Electronic Communications Privacy Act of 1986 (ECPA) enacted, distinguishing between in-transit (Title III) and stored (SCA) communications.
- October 2001. USA PATRIOT Act enacted, expanding FISA authorities and NSL authority.
- 2005. REAL ID Act enacted as part of the Emergency Supplemental Appropriations Act for Defense, the Global War on Terror, and Tsunami Relief, 2005.
- 2007. Protect America Act enacted, providing retroactive immunity to telecommunications providers that assisted with NSA surveillance after 11 September 2001.
- 2008. FISA Amendments Act enacted, adding Section 702.
- June 2013. Edward Snowden discloses PRISM and Upstream collection programs. The first wave of public debate on Section 702 begins.
- 2014. Privacy and Civil Liberties Oversight Board (PCLOB) report on the Section 215 program and on Section 702.
- June 2015. USA FREEDOM Act enacted, ending the NSA's bulk phone-metadata collection under Section 215 and adding modest NSL reforms.
- December 2015. First major ruling on the NSA's bulk-collection programs: the Second Circuit in ACLU v. Clapper holds that the NSA's phone-metadata program was not authorised by Section 215.
- 2018. FISA Amendments Reauthorization Act of 2017 (signed January 2018) reauthorises Section 702 through April 2023 (later extended to April 2024). Cloud Act enacted.
- December 2019. DOJ Inspector General Michael Horowitz releases report on FBI's FISA applications in the Carter Page matter, identifying 17 significant errors and omissions.
- September 2020. Ninth Circuit in Jewel v. NSA rules that the warrantless surveillance violated FISA.
- November 2020. 2020 election litigation, including Carter Page FISA materials unsealed in October 2020.
- April 2024. FISA Reform and Reauthorization Act of 2024 enacted, reauthorising Section 702 through April 2026 and adding the first-ever US-person query warrant requirement.
- May 2025. REAL ID enforcement for domestic air travel commences.
- 2025-2026. FISA 702 reauthorisation legislative cycle. The April 2026 sunset approaches.
- April 2026. Section 702 sunset date (if not reauthorised).
Sources
14 sources, all from the STA-305 source dossier (Archivist, 51f477c1). Tier 1 (statute and regulator) leads. Tier 2 (EFF, Wikipedia) anchors are used where the primary text is paywalled or stale. Sorted within tier alphabetically by title.
- [1] Tier 2 EARN IT Act (Wikipedia) (accessed 2026-06-15)
- [2] Tier 2 Encrypting the Web (EFF issue page) (accessed 2026-06-15)
- [3] Tier 2 Electronic Communications Privacy Act of 1986 (Wikipedia) (accessed 2026-06-15)
- [4] Tier 2 REAL ID Act (Wikipedia) (accessed 2026-06-15)
- [5] Tier 2 Kids Online Safety Act (KOSA) (accessed 2026-06-15)
- [6] Tier 2 REAL ID Act (Wikipedia) (accessed 2026-06-15)
- [7] Tier 2 Tor anonymity network (accessed 2026-06-15)
- [8] Tier 2 EFF issue page: Anonymity (accessed 2026-06-15)
- [9] Tier 2 Bank Secrecy Act (accessed 2026-06-15)
- [10] Tier 1 FinCEN (Financial Crimes Enforcement Network) (accessed 2026-06-15)
- [11] Tier 2 Executive Order 12333 (Wikipedia) (accessed 2026-06-15)
- [12] Tier 2 EFF Section 702 issue page (accessed 2026-06-15)
- [13] Tier 1 Federal Bureau of Investigation (FBI) (accessed 2026-06-15)
- [14] Tier 2 EFF cases (accessed 2026-06-15)