Today in Surveillance:
- FISA 702: 24 hours to expiration. The loophole is the story. The Senate has no deal. Democrats won't vote while Bill Pulte runs the intelligence community. Cotton and Grassley are planning a "fallback executive order" with Rubio. The bigger story: the FISA Court's March 2026 certifications already authorize ongoing 702 collection through March 2027. The statute lapses Friday. The surveillance does not [1][2].
- 30 billion Pokemon Go scans are now training military drone navigation. Niantic Spatial's Visual Positioning System, built on player-submitted environmental scans, is now partnered with Vantor (the defense prime that rebranded from Maxar Intelligence in October 2025) for GPS-denied drone navigation. Vantor holds a $70M NGA follow-on. Saudi Arabia's sovereign wealth fund owns the game [3][4][5].
- ServiceNow confirmed federal agencies were exposed in its two-month-old API breach. An unauthenticated Scripted REST endpoint, classified "non-urgent" since April 7, was actively exploited June 2-3. ServiceNow processes IT workflows for federal agencies and Fortune 500. No agency has publicly named the scope of exposure [6][7].
- Cybersecurity researchers publicly walked back from Anthropic's Fable. Red teamers criticized the new model's guardrails and 30-day data retention requirement for Fable and Mythos-class models. TechCrunch published the complaints June 10. This is the AI safety community's first major public break with a frontier lab's policy [8].
- Connecticut became the second state to ban surveillance pricing. Governor Lamont signed HB 5563 on June 4. New York already moved on June 4. Maryland was first. Twenty-four states are considering bills in 2026 [9][10].
- SECURE Data Act post-hearing: state AGs and consumer groups in revolt. The House subcommittee hearing June 3 put HR 8413 back in the spotlight. California's Privacy Protection Agency, EPIC, EFF, and IAPP are aligned against the federal preemption bill [11][12].
- Colorado's AI law takes effect in 19 days. Neural data and biological data are now legally "sensitive." The compliance window for high-risk AI systems closes June 30 [13].
FISA 702: 24 Hours to Expiration. The Statute Lapses. The Surveillance Doesn't.
FISA Section 702 hits its statutory expiration at midnight Friday, June 12. The Senate has no deal. The cloture vote failed 47-52 on June 5, and no path has opened since [1][2].
Here is the political math: Democrats refuse to hand warrantless surveillance authority to Bill Pulte, the acting Director of National Intelligence with no intelligence background. Seven Republicans (the same bloc that revolted June 5) want a warrant requirement before they vote yes. The Trump administration will not accept a warrant requirement and will not withdraw Pulte. That deadlock has held for a week and will not break before midnight Friday [1][2].
On Sunday, Sens. Tom Cotton (R-Ark.) and Chuck Grassley (R-Iowa) sent a letter to Secretary of State Marco Rubio asking the State Department to plan a "fallback executive order" for a "potential significant gap in foreign intelligence collection." That letter is not procedural. It is Republican leadership openly preparing to bypass Congress on Section 702 [1][3].
The legal reality is more interesting. An executive order cannot create new FISA Court certifications or extend existing ones. Those require statutory authority. What it can do is direct the intelligence community to continue collection under other authorities (Executive Order 12333, National Security Letters) with looser minimization rules. The "gap" Cotton and Grassley are planning for is a gap in oversight, not a gap in collection [1][2].
But the real loophole is older. The Foreign Intelligence Surveillance Court reauthorized the existing 702 certifications in March 2026, which keep ongoing collection running through March 2027. So even if the statute lapses Friday at midnight, the surveillance authority itself remains operational for almost another year. The expiration is a political lever, not an operational shutdown [1][2].
EPIC, the Brennan Center, and 5Calls continue pushing for the warrant requirement. AI is adding new urgency: lawmakers are reconsidering Section 702's scope as AI makes it dramatically easier to sift through the massive amounts of data already collected under the program. Surveillance capabilities that were manageable with human analysts become something else entirely when you point a large language model at them [2].
Related: Senate Vote Failed 47-52 | 7-Day Countdown: What Actually Stops | FISA 702: The Complete Guide | Why ICE Cares About 702
30 Billion Pokemon Go Scans Now Train Military Drone Navigation
Niantic Spatial, the standalone company that inherited Niantic's mapping technology after the games business sold to Scopely (Saudi Arabia's Savvy Games Group) for $3.5 billion, announced a partnership with Vantor on December 16, 2025. The two companies are fusing Niantic's ground-level Visual Positioning System, built on roughly 30 billion environmental scans submitted by Pokemon Go players since 2021, with Vantor's Raptor aerial navigation software. The target market: autonomous drones and ground vehicles operating in GPS-denied environments [3][4].
Vantor is not a startup. The company rebranded from Maxar Intelligence on October 1, 2025, and holds a $70 million follow-on award from the National Geospatial-Intelligence Agency under the agency's Global Enhanced GEOINT Delivery program, which serves more than 400,000 U.S. government users [3][5]. Vantor's own corporate copy frames the mission as "forging the new frontier of spatial intelligence" for the "defense, intelligence, and commercial sectors" [5].
Russian GPS jamming in Ukraine, the U.S. military's Drone Dominance evaluations adding GPS denial to Phase II this year, and Shield AI's V-BAT staying airborne when radio links die are all real, well-documented problems. A drone that navigates by what its camera sees, rather than by trusting a satellite signal that can be spoofed, is a meaningful capability. None of that is in dispute [3].
The dispute is about consent. The Pokemon Go scanning terms, which players agreed to in exchange for in-game items, granted Niantic "a transferable, sublicensable license" to the scans. Floris De Hingh, a 34-year-old Dutch player who downloaded Pokemon Go on its first available day in 2016, told Dutch newspaper Trouw he never connected the footage he captured to a system that would steer military drones. "I was just playing a game," he said [3].
Asked directly by Trouw whether the military-bound system relies on Pokemon Go imagery, Vantor said it would not use the game's data going forward. The company then declined to say whether the model it plans to deploy was trained on those scans. Niantic Spatial had already admitted, in a separate context, that the scans trained an "early version" of its navigation model. AI models begin with a dataset and then absorb far more data until the original contributions blur into patterns that can no longer be traced. Once a scan is folded into a model, proving it is or is not in there becomes nearly impossible. The denial is structurally unfalsifiable [3].
Jeroen van den Hoven, a professor of ethics and technology at TU Delft, told Trouw the conclusion is hard to avoid: "Without the huge number of scans from all those gamers, the development of this system would never have progressed so quickly" [3].
Niantic's own "Defense and Intelligence" product page now lists the Vantor partnership as a flagship offering, with copy that explicitly markets "GPS-independent operations" and "real-time situational awareness" for what it calls "decisive mission advantage." In May 2026, Niantic Spatial also achieved "Awardable" status on the Pentagon's Chief Digital and Artificial Intelligence Office Tradewinds Solutions Marketplace, the main portal for evaluating commercial AI vendors [4].
The broader pattern is the same one Citizen Lab documented in its November 2025 investigation of Penlink's Webloc platform, where law enforcement agencies pulled precise geolocation data on individual devices by piggybacking on the real-time bidding auctions that sell ads to your phone. A consumer product collects data for one stated purpose. A third party in the pipeline ends up with a copy. The original user has no visibility, no meaningful consent path, and no way to claw the data back [3].
Related: Full Investigation: Pokemon Go Scans to Military Drones | Citizen Lab: Webloc/Penlink Investigation
ServiceNow Confirms Federal Agencies Were Sitting on Its Open API
ServiceNow disclosed on June 5 that attackers exploited an unauthenticated API endpoint to query customer instance tables, accessing transaction records, names, and contact information. The root cause: a Scripted REST Resource shipped with requires_authentication set to false, meaning the endpoint accepted requests with no session, token, or credential check [6][7].
The timeline is damning. ServiceNow documented the vulnerability internally on April 7 and classified it as "non-urgent," planning to fix it in a future release cycle. Active exploitation began June 2-3, hitting the endpoint from a foreign IP. The emergency patch shipped June 5, three days after the exploitation started and almost two months after the vulnerability was first flagged [6][7].
ServiceNow is enterprise IT workflow software used by federal agencies, Fortune 500 companies, and critical infrastructure operators. The Australia platform release was primarily impacted. Customer notifications went out to specific organizations; ServiceNow has not published a public list. Aviatrix, BleepingComputer, and Anavem all published technical breakdowns last week, but no federal agency has confirmed the scope of its exposure [6][7].
If your organization uses ServiceNow: check whether you received a case notification and review your instance logs for the June 2-5 window. A two-month-old known vulnerability left open until active exploitation is a textbook negligence case. Watch for class action filings in the next 30 days [6][7].
Cybersecurity Researchers Walk Back From Anthropic's Fable
Frontier model safety researchers, including several from independent red-teaming groups, publicly criticized the guardrails on Anthropic's new "Fable" model and the 30-day data retention requirement that applies to Fable and Mythos-class models. TechCrunch published the complaints on June 10 after the story hit Hacker News's front page [8].
The 30-day data retention requirement is the core concern. Frontier model red teamers and evaluators typically work with carefully controlled sandbox environments. A 30-day retention policy means the prompts, generated outputs, and any extracted system prompts sit on Anthropic infrastructure for a full month after the evaluation ends. For researchers working on adversarial or sensitive content (jailbreaks, harmful-generation studies, prompt-injection analysis), that retention window is a data minimization problem. Anthropic has not said whether it offers a shorter-retention opt-in for accredited evaluators [8].
The guardrail complaints are the second front. Researchers testing Fable say the safety filters are more aggressive than on the previous Claude generation, blocking legitimate research prompts. The complaint: filters trained for the consumer product are bleeding into the evaluation surface, which makes it harder to actually probe model behavior [8].
For users, the 30-day retention is the bigger story. If you have ever asked Fable to summarize a sensitive legal situation, draft a healthcare question, or generate a difficult personal communication, the prompt and response sit on Anthropic's infrastructure for 30 days. Frontier model data retention policy is going to be a recurring fight for the rest of 2026 [8].
SECURE Data Act vs State Privacy Laws: One Will Kill the Other
The House Energy and Commerce Subcommittee held its hearing on the SECURE Data Act (HR 8413) on June 3, three days ago. Rep. Brett Guthrie (R-KY) introduced the bill on April 22. The text would establish a single federal privacy standard for the entire country and preempt every state privacy law on the books, not as a floor that states can build on, but as an absolute ceiling [11][12].
The opposition aligned fast. The California Privacy Protection Agency sent a letter opposing the bill, warning it would roll back protections that millions of Californians already rely on. EFF, EPIC, IAPP, and the Future of Privacy Forum all filed critical analysis. The Brennan Center published a side-by-side showing how the bill would gut BIPA, the Illinois biometric privacy law that has been the only real deterrent to corporate biometric collection for the last decade [11][12].
The bill on the table would replace 20-plus state privacy laws with a federal standard that the EFF has called "not a serious piece of privacy legislation." Vermont's strong data broker rules, California's CCPA, Illinois's BIPA, Connecticut's SB4 registry, and Colorado's AI Act would all be overridden [11][12].
The other federal privacy bill in play is HR 8014, the Online Privacy Act, which sets a much stronger floor and does not preempt state laws. The two bills have not been formally compared in committee yet, but consumer and privacy groups are pushing for HR 8014's structure as the alternative. Whoever wins the committee markup shapes American privacy rights for decades [11][12].
Related: Federal Privacy Preemption: The State Law Fight | SECURE Data Act June 3 Hearing Coverage | The Data Broker Loophole
Connecticut Becomes the Second State to Ban Surveillance Pricing
Connecticut Governor Ned Lamont signed HB 5563 on June 4, making Connecticut the second state to ban surveillance pricing by retailers. New York moved on the same day with the One Fair Price Act, and Maryland was first in May 2026. Twenty-four total states are considering similar bills in 2026 [9][10].
Surveillance pricing is the practice of using AI and algorithmic tools to analyze browsing history, location, demographics, and mouse movements to set individualized prices for each shopper. The same customer can pay a different price at the same retailer depending on what the algorithm decides they can afford. Maryland's October 1 effective date is the first real compliance test [9][10].
The grocery chains, retailers, and data brokers that built the surveillance pricing infrastructure are watching the early state compliance tests carefully. The Chamber of Progress, a tech industry coalition, is pushing for a veto of New York's bill. If Hochul signs, New York becomes the third state to ban the practice [9][10].
Related: 24-State Surveillance Pricing Ban Tracker | Connecticut SB4 Data Broker Kill Switch
Colorado AI Act: 19 Days to Compliance
Colorado's "Concerning Consumer Protections for Artificial Intelligence" law takes effect June 30, 2026. The law was postponed from February and the implementation date was pushed to January 1, 2027 in May, but the consumer-facing rights still activate on June 30. Neural data and biological data are legally "sensitive" under the statute, which means explicit consent is required to collect them [13].
The core consumer right: if an AI system makes a decision about you (loan denial, hiring rejection, housing application, insurance pricing, healthcare access), you have the right to appeal the decision and have a human review it. "High-risk AI system" under the law includes any system that makes decisions about education, employment, financial services, government services, healthcare, housing, insurance, and legal services [13].
For developers, the obligations include risk assessments, algorithmic discrimination audits, consumer notifications when AI is making decisions, and disclosure of training data categories. Companies scrambling for compliance have 19 days [13].
Also Today: Yoti/GrapheneOS and the Homan FR Admission
Two stories we covered in detail in yesterday's briefing are still developing.
Yoti age verification reportedly flags GrapheneOS users to authorities. A user attempting Sony PlayStation age verification through Yoti was told their device was "automatically reported to both the authorities and our security team" for running GrapheneOS. Yoti denies the claim, calling the screenshots fabricated. GrapheneOS called it "fearmongering" by a customer support agent. The story matters regardless: age verification systems treat privacy tools as suspicious by default, and Yoti was fined $1.1M by Spain's AEPD in March 2026 for biometric data mishandling [14][15].
Border czar Tom Homan confirmed federal facial recognition on Delaney Hall protesters. On Fox & Friends, Homan said federal investigators used facial recognition and "other investigative tools" to identify anti-ICE demonstrators at the Newark detention facility, claiming FR matched protesters to demonstrations in Portland and Minnesota. Over 80 people have been arrested at the facility since protests began [16][17].
Both pieces are in editor review for full-length coverage. Expect the detailed stories to ship within 48 hours.
What to Watch
- Today, June 11: Last realistic day for a clean FISA 702 vote. If no deal, expect a short-term extension request or preparation for Friday's statutory lapse [1][2].
- Friday, June 12: FISA Section 702 statutory expiration. FISA Court certifications keep collection running until March 2027 regardless. The headline is the lever, not the operational reality [1][2].
- June 17: EFF "LGBTQ+ Solidarity Against Surveillance" event. Watch for new tool announcements and policy asks.
- June 30: Colorado AI Act consumer rights take effect. Neural data and biological data become legally "sensitive" [13].
- June 30: PayPal breach credit monitoring enrollment deadline for affected users.
- July 1: Reddit's new Privacy Policy / User Agreement. AI training opt-out gets harder.
- July 1: Connecticut, Arkansas, and Utah privacy law amendments take effect.
- August 1: California data broker registration requirements.
- August 2: EU AI Act GPAI obligations apply. High-risk rules now delayed to December 2027.
References
- CBS News: Senate fails to extend FISA surveillance program as deadline nears (June 5, 2026)
- Brennan Center: Section 702 FISA 2026 Resource Page
- DroneXL: Pokemon Go Scans Trained the Navigation Tech Now Headed Into Military Drones (June 9, 2026)
- Niantic Spatial: Defense and Intelligence Product Page
- Vantor (formerly Maxar Intelligence): Defense and intelligence contractor, NGA Global Enhanced GEOINT Delivery follow-on
- BleepingComputer: ServiceNow discloses security incident exposing customer data (June 2026)
- Anavem: ServiceNow API Flaw Exposes Customer Data in Security Breach (June 2026)
- TechCrunch: Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable (June 10, 2026)
- Consumer Reports: Statement on Connecticut's Surveillance Pricing Bill Signing (June 2026)
- EPIC: New York Becomes Third State to Pass Surveillance Pricing Ban (June 2026)
- Congress.gov: H.R. 8413 SECURE Data Act
- EFF: The SECURE Data Act is Not a Serious Piece of Privacy Legislation
- TechTimes: Colorado's AI Law Update (June 8, 2026)
- Cybernews: Age checker Yoti tells GrapheneOS users they're getting reported (June 2026)
- GrapheneOS Discussion Forum: User reported to authorities for using GrapheneOS (June 2026)
- Washington Examiner: Homan says most anti-ICE protesters at Delaney Hall are not state residents (June 2026)
- PBS NewsHour: What to know about the protests and arrests outside a New Jersey detention center (June 2026)