Today in Surveillance:
- Anthropic is sending staff to Washington. Axios reports the trip next week, after WSJ's June 13 piece on Amazon CEO Andy Jassy's White House meetings. Canadian PM Mark Carney used the moment to warn that the Fable 5 ban "shows risk of relying on big AI models."
- FISA 702 has lapsed for the first time since 2008. Axios confirmed the historic framing June 14. Senators Cotton and Grassley are pushing an executive order to keep NSA "non-content" collection running.
- Police on both sides of the Atlantic are misusing AI tools. The FT picked up the Derbyshire AI evidence case. Tom's Hardware reports several US officers were arrested for using Flock ALPRs to track ex-partners.
- The leading deepfake expert no longer trusts his own eyes. NYT profiled UC Berkeley's Hany Farid. He says detection has lost the race to generation by 6 to 12 months.
- Apple's Private Cloud Compute is "severely limited" for third-party developers. Apple's own developer docs say so. Microsoft 365 Copilot separately named "Anthropic Models" as a subprocessor.
- Signal: UK plan to scan devices for nude images "endangers us all." The Register resurfaced Signal's warning June 14, and a 53-point HN long-read on digitalgrease.dev made the technical case.
- VFS Global runs the world's visa biometrics. Lighthouse Reports calls it a private surveillance contractor. Faces, fingerprints, sometimes iris scans, collected from weak-passport applicants in the Global South.
Anthropic Goes to Washington. Carney Warns on Big AI Models.
Four days into the Fable 5 export-control crisis, Anthropic is sending staff to Washington to meet White House officials next week [1]. Axios broke the trip June 14 evening, and Reuters confirmed it within hours [1][2]. The news landed in the middle of a political cycle that now includes a senior G7 leader openly questioning the wisdom of letting a handful of frontier AI labs sit on top of the world's most consequential technology.
Canadian Prime Minister Mark Carney told Bloomberg June 14 that the Commerce Department's directive suspending Fable 5 and Mythos 5 "shows risk of relying on big AI models" [3]. It is the strongest public statement yet from a head of government on the directive, and it ties a privacy-and-concentration argument to a foreign-policy critique of US AI policy. Business Insider laid out the "whirlwind 24 hours" timeline June 15: the directive itself came together between June 9 and June 12, with Amazon CEO Andy Jassy's conversations with US officials as a likely catalyst [4].
The most-shared piece of the day was a long-read at verysane.ai titled "Did Anthropic ask for this?" which argues that CEO Dario Amodei's June 9 essay on "Policy on the AI Exponential" prefigured and arguably invited the export-control regime [5]. David Sacks weighed in on X, framing the directive as politically motivated. The HN thread on the long-read passed 180 points and 150 comments by Sunday night [5].
Anthropic's four-day arc is now: June 11 apology for silent Fable guardrails, June 12 export control directive, June 13 WSJ report on Jassy's role, June 14 staff trip to Washington. The D.C. leg is the de-escalation phase. The fact that the company is sending people rather than lawyers is the signal that it wants the directive lifted quietly, not litigated.
Related: How Andy Jassy's White House Visit Triggered the Fable 5 Directive | Inside Fable 5's Silent Guardrails and the 30-Day Bedrock Retention
FISA 702 Has Lapsed. It Has Not Done So Since 2008.
Section 702 of the Foreign Intelligence Surveillance Act expired at midnight June 14, the first time the authority has lapsed since Congress enacted it in 2008 [6]. Axios crystallized the historical framing June 14 evening. Senators Cotton and Grassley are pushing an executive-order fallback that would let the NSA keep collecting "non-content" metadata under existing authority; Senator Wyden and the civil-liberties left are demanding the lapse hold [6][7].
The fight is now over what "existing authority" means in practice. The Foreign Intelligence Surveillance Court can renew annual certifications on a rolling basis, so collection on targets with active orders continues. What it cannot do is issue new certifications, which is the long-tail choke point. The big question for the rest of the week is whether the Cotton-Grassley executive order text surfaces publicly. If it does, expect a second wave of press; if it doesn't, expect a quiet extension through a continuing resolution before the political cost of a public fight outweighs the value of a new authorization.
EFF called the lapse a "victory" but warned that NSA upstream collection and FBI backdoor searches of 702 data can still continue under existing certifications [8]. The historic-first framing matters because it puts a date on a privacy story that has been a slow-rolling procedural fight since March.
Related: FISA 702: 72 Hours After the Lapse | Day 1: Wiretaps Are Still Running. No New Ones Can Be Authorized.
UK and US Police Are Misusing AI. Both Are Getting Charged.
Two separate police-AI stories landed June 14, and the pattern is identical: officers using tools their departments did not authorize them to use, with the misuse now leading to criminal charges.
The Financial Times picked up the Derbyshire Constabulary case, in which a UK officer is under criminal investigation for using AI to fabricate evidence in multiple cases [9]. The story first broke June 13 on Sky News and the BBC; the FT's coverage is the signal that the UK policing beat is treating this as a sustained story rather than a one-day spike.
Tom's Hardware surfaced the US parallel June 14: several police officers were arrested for using Flock-style automatic license-plate-reader (ALPR) systems for personal reasons, including tracking ex-partners [10]. Flock's network is in use by thousands of US police departments. The abuse vector is structural: the system queries a plate and returns a vehicle owner, address, and travel history. If you have access, you have a personal-stalking tool, and the audit trail is thin.
The pattern matters because the response has been criminal charges in both countries, not policy reform. That is how police accountability works in 2026: not by changing the systems, but by prosecuting the operators who use them in unauthorized ways. It is a low-throughput model.
Related: UK Officer Under Criminal Investigation for AI-Generated Evidence | When AI Writes the Police Report: Heber City, Axon, and the Frog Case
The Leading Deepfake Expert No Longer Trusts His Own Eyes
The New York Times published a profile of Hany Farid, UC Berkeley professor and one of the most-cited deepfake-detection researchers in the world, headlined "The Leading Deepfake Expert No Longer Trusts His Own Eyes" [11]. Farid's argument: generative tools have crossed a threshold where detection lags generation by 6 to 12 months, and the public needs to be trained to treat images and video as untrusted by default.
Science magazine ran a companion profile: "Deepfakes are everywhere. The godfather of digital forensics is fighting back" [12]. The pair is the most quotable deepfake coverage of the year, and it lands at a moment when the 2026 midterm cycle is in full swing, when Grok's sexualized deepfake crisis is still echoing from Canada, and when YouTube is rolling out biometric-likeness detection for creators [13].
The takeaway for readers is uncomfortable: if the researcher who helped build the field says the field has lost, then the only mitigation left is social. You cannot detect your way out of a deepfake. You can only refuse to believe the first thing you see.
Related: Canada Privacy Commissioner: Grok Sexualized Deepfakes Violated Law | 2026 Midterms: The Deepfake Wild West and the FEC's Failure
Apple's Private Cloud Is "Severely Limited" for Third-Party Developers
Apple published developer documentation June 14 noting that Private Cloud Compute (PCC), the cloud-AI privacy architecture Apple rolled out in 2024, is "severely limited" for third-party developers in the current release [14]. The architecture Apple markets as the most private cloud-AI stack in production is, in practice, only fully available to first-party Apple Intelligence features. Third-party apps get a narrower surface and reduced control over the data flow.
This is a quiet but real privacy beat. Apple has sold PCC as the architectural answer to "your photos go to a server you cannot see." For Apple's own apps that is true. For everyone else, the marketing claim does not survive the developer docs.
Microsoft 365 Copilot added to the one-day double-privacy story the same afternoon: the company's subprocessor notice now lists "Anthropic Models in Microsoft Online Services" as a named subprocessor for Copilot [15]. The configuration matters because Copilot is the most-deployed enterprise AI assistant in the world, and a subprocessor designation means Anthropic's models see enterprise data in a way that was not transparent six months ago.
The two stories together describe a 2026 pattern: privacy architecture is a marketing surface, vendor lock-in at the cloud-AI privacy layer is the default, and the regulators are not yet in the room.
Related: YouTube's Likeness Detection Database: A New Biometric Surface
Signal: UK Plan to Scan Devices for Nude Images "Endangers Us All"
The Register resurfaced Signal's June 9 warning that the UK Online Safety Act's CSAR provisions, which would require platforms to scan encrypted devices for child-sexual-abuse material, "endanger us all" [16]. The resurfacing June 14, plus a long-read on digitalgrease.dev titled "Can't Stop the Signal. Poison It" (53 HN points, 18 comments), pushed the story back into the second cycle of coverage [17].
The technical case is straightforward and damning: client-side scanning is structurally incompatible with end-to-end encryption, because any scanning client has to see plaintext it should not see. Signal's threat to leave the UK market if the law is enforced is the shareable angle, and the digitalgrease long-read makes the engineering case for why the law is a poison-pill, not a fix.
For the privacy community this is the third UK encryption fight of 2026, after the Apple ADP secret order and the dropped-then-reissued Apple encryption order [18][19]. Each one moves the UK closer to a position where encrypted-messaging apps cannot legally operate in the country. The cumulative direction is the story.
Related: Inside the UK Apple ADP Secret Order | Canada's Bill C-22: The Same Playbook, Worse
VFS Global Is a Private Surveillance Contractor Wearing a Visa Lanyard
Lighthouse Reports published a long-form investigation June 14 on VFS Global, the outsourcing giant that runs visa application centers for dozens of governments [20]. The piece documents how VFS profits by handling biometric data, including faces, fingerprints, and sometimes iris scans, collected from "weak-passport" applicants in the Global South, with unclear data-residency controls and a near-monopoly position in the visa-frontend market.
The story is the first long-form look at a vendor that has been quietly running the world's visa biometric pipeline for two decades. The privacy hook is the data: the same faces that go through a visa application in Lagos, Dhaka, or Lima end up in a database whose governance no one has ever audited. The geopolitical hook is the same, but with an asterisk attached to which government can query it.
This is adjacent to our existing coverage of the Delhi C4I safe-city facial-recognition system and the Singapore Woodlands checkpoint facial-recognition deployment [21][22]. The pattern is the same: a private vendor operates a biometric-collection layer, a state accesses the data, and the privacy story is told years after the system is built.
Census Bureau Noise Infusion: No Public Movement, No Story to Tell
The Commerce Department's order banning "noise infusion" from Census Bureau and Bureau of Economic Analysis products is still in effect, and the original Desfontaines post remains the top HN hit for "differential privacy" [23]. No new public pushback from Census, no Congressional Privacy Caucus statement, no academic statistical-society letter. The existing pieces still cover the issue; we are holding the beat for the next official response.
Related: The Census Bureau's Noise Infusion Ban, Explained | The Two Privacy Rollbacks Hiding Inside One Commerce Department
What to Watch
- Next week: Anthropic staff meet White House officials. The text of the Cotton-Grassley executive-order fallback on FISA 702 may surface.
- June 16: EU GDPR 8-year anniversary. Expect a retrospective wave and a state-privacy-patchwork follow-up.
- June 30: T-Mobile March 2026 breach monitoring deadline (15 days). Colorado ADMT Law amendments effective.
- July 1: Virginia facial recognition law takes effect. Connecticut, Arkansas, and Utah privacy-law amendments kick in. Reddit privacy-policy update.
- August 2: EU AI Act general-purpose AI rules apply. High-risk rules still delayed to December 2027.
References
- Axios: Anthropic flies staff to D.C. to clean up the Fable 5 fight (June 14, 2026)
- Reuters: Anthropic staff to meet White House officials next week (June 14, 2026)
- Bloomberg: Carney Says Anthropic Ban Shows Risk of Relying on Big AI Models (June 14, 2026)
- Business Insider: Inside the whirlwind 24 hours that led the White House to slap export controls on Anthropic (June 15, 2026)
- Very Sane AI: Did Anthropic ask for this? (June 14, 2026)
- Axios: Section 702 lapsed for the first time since 2008 (June 14, 2026)
- Senator Wyden: Statement on the lapse of FISA Section 702 (June 14, 2026)
- EFF: Victory! 702 has Expired (June 14, 2026)
- Financial Times: UK police officer under criminal investigation over alleged use of AI (June 14, 2026)
- Tom's Hardware: Police accused of misusing AI license-plate tracking systems (June 14, 2026)
- New York Times: The Leading Deepfake Expert No Longer Trusts His Own Eyes (June 14, 2026)
- Science: Deepfakes are everywhere. The godfather of digital forensics is fighting back (June 14, 2026)
- Office of the Privacy Commissioner of Canada: Grok sexualized deepfake images finding (June 2026)
- Apple Developer: Private Cloud Compute documentation (June 14, 2026)
- Microsoft Learn: Anthropic Models in Microsoft Online Services subprocessor notice (June 14, 2026)
- The Register: Signal says UK plan to scan devices for nude images "endangers us all" (June 9, 2026, resurfaced June 14)
- Digital Grease: Can't Stop the Signal. Poison It. (June 14, 2026)
- State of Surveillance: Inside the UK Apple ADP Secret Order (2026)
- State of Surveillance: The UK Apple Encryption Order, Dropped and Reissued (2026)
- Lighthouse Reports: The Visa Empire: Borders as a Business (June 14, 2026)
- State of Surveillance: Delhi's Citywide C4I Safe-City Facial Recognition (2026)
- State of Surveillance: Singapore Facial Recognition Motorcycles at Woodlands Checkpoint (March 2026)
- Damien Desfontaines: Banning noise (June 2026)