A calculator on top of printed financial documents on a dark wooden desk, the kind of paperwork that is the data-extraction surface of the AI industry
Photo via Unsplash

Today in Surveillance:

  • OpenAI bled $38.53B in 2025 on $13.07B in revenue. Audited financials leaked to Ed Zitron and independently verified by the Financial Times were published Tuesday by Ryan Merket at RuntimeWire. The thread hit 194 points and 207 comments on Hacker News by 07:30 UTC, up from 7 points at 02:09 UTC, a 27x compound in four hours. The privacy story is what the loss number explains: a company converting user data into revenue at a rate that does not cover its compute burn will widen the data-extraction surface, and the AI-infrastructure subsidies and government contracts that close the gap are the structural surveillance question of the year [1][2][3][4].
  • The 222 members of Peter Thiel's 'Dialog' society are now public. WIRED confirmed the leak June 16 and a separate HN submission the same night disclosed that the leak source is a public GitHub repository at github.com/nzaki-dev/dialog with hard-coded HTML. The 2026 retreat registration list includes General Alexus Grynkewich (NATO supreme allied commander Europe), Treasury Secretary Scott Bessent, Senator Ted Cruz, Palantir cofounder Joe Lonsdale, six PayPal alumni, and the founders of the country's largest data-broker companies. The Dialog chairman is Auren Hoffman, founder of SafeGraph and LiveRamp. The privacy story is the inverse of the usual frame: this is the exposure of the power network itself, not the exposure of private individuals [5][6][7][8][9].
  • Apple's iOS 19 update will make 'Hide My Email' useless. Apple told developers June 15 it is moving every Hide My Email alias from @icloud.com to a new @private.icloud.com subdomain, a fingerprint any service can recognize and block. iCloud+ subscribers get no compensation, no opt-out, and no notice. The morning-cycle brief is on the site. TechCrunch's Zack Whittaker picked up the story overnight [10][11][12].
  • Microsoft Teams now tells your boss when you were in the office. PCWorld reported June 16 that a new 'Workplace Check-in' feature in Microsoft Teams reads the company Wi-Fi network your phone or laptop joins, and posts the result to a per-employee attendance record a manager can view. Microsoft says the feature is disabled by default, the tenant admin decides whether to enable it, and the end user can decline to share. The privacy story is the structural posture: the only advertised opt-out is at the IT-admin layer, not at the employee device [13][14][15].
  • The 'Stop Killing Games' EU citizen initiative failed despite 1.3 million signatures. Dexerto reported June 17 that the European Commission responded with voluntary publisher commitments, not binding law. Once a publisher shutters a game, the consumer loses the data they paid for, and the Commission's response enshrines publisher ownership of consumer data. 154 points and 48 comments on Hacker News. The anti-cloud-control, right-to-repair thread is now the parallel to the Banned Book Library in a Tasmota-flashed Wi-Fi bulb [16][17].

Also today:

  • SpaceX-Cursor $60B crossed 980 points on Hacker News, the third story on the front page. The AI-infrastructure-consolidation arc continues. One entity now controls rockets, global satellite internet, a major social-media platform, a frontier AI lab, and a developer-AI tool with mass adoption. The structural critique is the same one that ran through the Stratechery 'Anthropic's Safety Superpower' anchor on Sunday [22][23][24].
  • DOJ named 'Operation Epic Fury' as one of the Grok-supporting military missions. TechCrunch picked up the Day-3 layer of the DOJ / xAI 'vital' filing June 17. The piece cites a Cameron Stanley DoD declaration that 2,000 munitions were executed in 96 hours using Grok Gov as part of strikes against Iran. The story extends the 'AI is national-security infrastructure' arc the Day-1 and Day-2 briefs covered [20][21].
  • France's DGSI will replace Palantir with ChapsVision. The Guardian reported June 17 that France's domestic intelligence agency will ditch Palantir's AI data tools in favor of ChapsVision, framed by the French PM as a sovereignty decision. Engagement crossed 33 points and 200% growth overnight, the structural-sovereignty beat's biggest gain [22].
  • AMD removed memory encryption from consumer Ryzen silicon. technology.org reported June 16 that AMD is stripping the SME (Secure Memory Encryption) feature from consumer-tier Ryzen CPUs effective with the next silicon revision. The server / EPYC line keeps it. Privacy-protective hardware is now an enterprise tier, not a consumer default [23].

OpenAI Lost $38.53B in 2025. The Loss Is the Surveillance Story.

Audited OpenAI financial documents, viewed by Ed Zitron and independently verified by the Financial Times, were published Tuesday night by Ryan Merket at RuntimeWire [1][2]. The numbers: $13.07B in 2025 revenue, $34B in total costs and expenses, $20.92B loss from operations, and a $38.53B net loss attributable to OpenAI after a $60.35B group net loss was reduced by losses attributed to noncontrolling interests. The Hacker News thread crossed 194 points and 207 comments by 07:30 UTC, up from 7 points at the 02:09 UTC morning cycle, a 27x compound in 4 hours 21 minutes, the biggest engagement compound of the day [4].

The privacy story is not the loss itself, it is what the loss explains. OpenAI is converting user data into revenue at a rate that does not cover its compute burn, and the gap is being closed by capital raises, government contracts (the OpenAI-Pentagon safeguards contract, the Anthropic Fable 5 export-control story), and infrastructure subsidies (the FDCEA expiration on September 30, the Missouri data-center thread, the DOJ xAI 'vital' filing in the same week). The data-extraction surface expands when revenue lags burn: training data, fine-tuning data, RLHF and eval logs, chat logs, and government-data integration all become inputs to the next round of capital [5][6]. The Morning Story thread the State of Surveillance site has been running since March ties the OpenAI financials to the same chain: AI companies are not financially self-sustaining on user-data revenue, so the data-extraction surface expands.

The procedural note: the Fortune piece that circulated at 02:09 UTC carried a $21B-loss number. The Zitron / FT-verified $38.53B figure is the specific audited disclosure that promotes the story from "leak" to "audited financial disclosure." The $17.5B delta between the two numbers is the difference between "we hear it is bad" and "we know the exact figure." OpenAI has not publicly disputed the $38.5B figure as of 07:30 UTC. Watch for: (1) any first-party OpenAI response, (2) tier-1 outlet pickup from Reuters, WSJ, NYT, Bloomberg beyond the FT, and (3) any new IPO-timeline signal that pins the "compute burn before IPO window closes" frame [3].

Peter Thiel's 'Dialog' Society Has 222 Members. A GitHub Repo Published the List.

WIRED's Andy Greenberg confirmed the leak of Peter Thiel's invitation-only 'Dialog' society on June 16 at 20:46 UTC. The follow-up coverage from San (22:50 UTC) and a separate Hacker News submission the same night disclosed that the leak source is a public GitHub repository at github.com/nzaki-dev/dialog, containing hard-coded HTML with the 2026 retreat registration list [7][8][9]. The WIRED piece sat at 115 points and 8 comments by the 07:04 UTC mid-morning cycle, up from 71 points at the 02:09 UTC morning cycle, a 62% compound in 5 hours. The combined engagement across the WIRED piece and the GitHub-repo disclosure is 151 points [10][11].

The 2026 retreat registration list includes General Alexus Grynkewich (NATO supreme allied commander Europe, head of U.S. European Command, took post July 2025), Treasury Secretary Scott Bessent, Senator Ted Cruz, Palantir cofounder Joe Lonsdale, six PayPal alumni, and the founders of the country's largest data-broker companies. The Dialog chairman is Auren Hoffman, founder of SafeGraph and LiveRamp. The named session topics at the August 12-16 retreat near Dublin include "Money (Does?) Buy Happiness," "Bring Back Nuclear," "Navigating WWIII," "Battlefield Technologies," "How's Your Sex Life?," "Build-a-Cult" with the founder of Pray.com, and "Build-a-Party" with a former White House national security official [7].

The original leaker is maia arson crimew, the Swiss hacktivist known for the 2021 No Fly List exposure and the 2021 Verkada surveillance-camera breach. The privacy story is the inverse of the typical personal-data frame: this is the exposure of the power network itself, not the exposure of private individuals. The story lands the same week as the Anthropic Fable 5 power-network story (where Amazon flagged the jailbreak), the DOJ xAI 'vital' filing (where one private company is named national-security infrastructure), and the Stratechery 'Anthropic's Safety Superpower' piece (where the safety commitment is the license to challenge the consolidating incumbent). The combined picture: a small set of private actors is exercising outsized influence on U.S. AI policy, and the first public disclosure of a specific named network's membership has now landed. Watch for: (1) any first-party Thiel / Dialog statement, (2) any response from named individuals, (3) any tier-1 outlet pickup beyond WIRED and San, and (4) any independent verification of the GitHub-repo provenance. The underlying leak has not been independently confirmed by the named individuals as of 07:30 UTC [12].

Apple's iOS 19 Update Makes 'Hide My Email' Useless. TechCrunch Picked Up the Story.

Apple told developers June 15 that it is moving every Hide My Email alias from @icloud.com to a new @private.icloud.com subdomain, a fingerprint any service can recognize and block. The change is the third Apple privacy-product move in two weeks, following the Apple ADP 'secret order' UK story and the Apple Private Cloud Compute 'severely limited' for third-party developers piece. iCloud+ subscribers get no compensation, no opt-out, and no notice. The Hacker News thread sat at 470 points and 246 comments at the 07:04 UTC mid-morning cycle, up from 398 at the 02:09 UTC morning cycle, an 18% compound in 5 hours and the highest engagement of any privacy-product-erosion story of the cycle [13][14].

Overnight, TechCrunch's Zack Whittaker picked up the story (HN id 48566095, 18 points / 1 comment at 07:04 UTC scan, posted 05:29 UTC), the first tier-1 editorial confirmation of the developer-blog post [15]. The structural read is the same one the Apple-privacy-product-erosion beat has been running: Apple sells privacy as a subscription feature (iCloud+), then degrades the privacy guarantee of the feature with a software update, with no compensation to subscribers. The 'iCloud Private Relay' / 'Hide My Email' / 'Advanced Data Protection' / 'Private Cloud Compute' product family is now the privacy-as-a-subscription case study. Watch for: (1) Apple's first-party response to the TechCrunch tier-1 pickup, (2) any class-action filing from iCloud+ subscribers, and (3) Apple's June 20 WWDC 2026 follow-up coverage that may address the change. The dedicated brief is on the site [16].

Microsoft Teams Will Now Tell Your Boss When You Were in the Office

PCWorld reported June 16 at 02:43 UTC that Microsoft is rolling out a new 'Workplace Check-in' feature in Microsoft Teams. When an employee's phone or laptop joins the company Wi-Fi network, Teams updates that person's work location to the office building, and posts the result to a per-employee attendance record a manager can view. Microsoft says the feature is disabled by default, the tenant admin decides whether to enable it, and the end user can decline to share. The privacy story is the structural posture: the same Wi-Fi probe signal a growing fleet of corporate-surveillance vendors already use, deployed by the platform the entire office stack runs on, with the only advertised opt-out at the IT-admin layer rather than at the employee device [17].

The Hacker News thread sat at 43 points and 9 comments at the 02:09 UTC scan, the day's biggest workplace-surveillance break and the canonical employer-as-surveillance-operator story [18]. The privacy hook is the failure mode of the 'employer as surveillance operator' frame: an employer can know which days an employee was in the office, with no employee-side notification, no consent, and no opt-out at the device level. The parallel beats are the Mott Poll 'half of parents track their young adult' piece (the family-side equivalent), the Apple Find My / Google Family Link / Life360 family-surveillance beat (the consumer-product equivalent), and the broader employer-monitoring-software market (Hubstaff, ActivTrak, Time Doctor, Microsoft Productivity Score). The dedicated brief is on the site [19].

What you can do today: (1) check whether your IT admin has enabled Workplace Check-in (Microsoft 365 admin center, Teams admin, location settings), (2) opt out at the device level by turning off Wi-Fi probe requests (OS-level settings, network settings), (3) use cellular-only at work to avoid the Wi-Fi signal entirely, and (4) push for tenant-level IT policy that disables the feature by default. The structural fix is at the tenant admin layer, not at the device layer, and an employee who wants to push back has to go through IT.

The 'Stop Killing Games' EU Citizen Initiative Failed Despite 1.3 Million Signatures

Dexerto reported June 17 at 01:40 UTC that the 'Stop Killing Games' European Citizen Initiative, signed by 1.3 million people and the largest citizen initiative in EU gaming-policy history, failed to secure binding EU legislation. The Commission's response: voluntary publisher commitments rather than binding rules. The Hacker News thread sat at 154 points and 48 comments at the 07:30 UTC scan, the second-highest fresh-engagement story of the morning after OpenAI financials [20][21].

The privacy / civil-liberties angle is the right-to-repair / consumer-control-over-your-data frame. Once a publisher decides to shutter a game (or a service), the consumer loses the data they paid for: game saves, in-game items, account data. The Commission's voluntary-commitments response enshrines publisher ownership of consumer data rather than the consumer's claim to the data they paid for. The structural read: consumer data is treated as the publisher's property, not the consumer's. The parallel beats are the Banned Book Library in a Tasmota-flashed Wi-Fi bulb (the DIY anti-cloud-control piece), the Doctorow 'Unauthorized Bread' thread (the cultural anchor for the right-to-repair beat), and the broader consumer-data-as-publisher-property structural theme. The Stop Killing Games failure is the EU-policy dimension of the same beat the Banned Book Library / Tasmota-ESP32C3 right-to-repair piece covers at the DIY-device level.

Engagement Compounds: SpaceX-Cursor Crossed 980 Points. LinkedIn Backdoor Plateaued at 1,551.

The SpaceX-Cursor $60B deal is now the third story on Hacker News. Reuters published the story June 16 at 10:44 UTC; BBC followed at 12:31 UTC. The combined engagement crossed 980 points and 1,500 comments by the 07:04 UTC mid-morning cycle, up from 886 points at the 02:09 UTC morning cycle, a 10% compound in 5 hours and still growing [22][23][24]. The structural critique is the consolidation story: SpaceX now controls rockets, global satellite internet, a major social-media platform (X), a frontier AI lab (xAI), and a developer-AI tool with mass adoption. The dedicated brief is on the site [25].

The LinkedIn-recruiter backdoor plateaus at 1,551 Hacker News points and roughly 295 comments, still the top privacy/security story of the day. Roman Imankulov's first-person postmortem at roman.pt described the chain: a fake LinkedIn recruiter walked him into a malicious GitHub repo whose `npm prepare` lifecycle hook executed a backdoor the moment he ran `npm install`. The trap was a 250-line `app/test/index.js` file that assembled a URL from six fragments and ran whatever the server returned. What saved him was an AI code-review agent on a throwaway Hetzner VPS that flagged the URL-fragment assembly as suspicious [26][27]. The dedicated brief is on the site [28].

Two more engagement compounds to flag. (1) The Register's 'Fable 5 fix this code' piece crossed 565 points and 324 comments, still growing, the engagement champion of the Anthropic thread and 2.6x the Day-5 Stratechery anchor at 211 points. (2) FIFA World Cup ID attack sat at 264 points, flat from the morning, the BobDaHacker responsible-disclosure piece. Both extend the existing briefs on the site.

Tracker Notes: DOJ Names 'Operation Epic Fury.' France Ditches Palantir. AMD Removes Memory Encryption.

TechCrunch picked up the Day-3 layer of the DOJ / xAI 'vital' filing overnight (HN id 48565429, 74 points / 54 comments at the 07:30 UTC scan, posted 03:42 UTC). The piece frames the Trump administration's filing against the NAACP lawsuit over xAI's unpermitted gas turbines in Mississippi as naming 'Operation Epic Fury' as one of the named military projects that requires Grok, with the 2,000 munitions / 96 hours execution metric and the Maven Smart System detail [29][30]. The story extends the 'AI is national-security infrastructure' arc the Day-1 and Day-2 briefs covered, with the tier-1 editorial confirmation of the named military projects [31].

The Guardian reported June 17 at 00:16 UTC that France's DGSI will ditch Palantir's AI data tools in favor of ChapsVision, framed by the French PM as a sovereignty decision. Engagement crossed 33 points by 07:30 UTC, up from 11 at the 02:09 UTC morning cycle, a 200% compound in 5 hours and the structural-sovereignty beat's biggest gain [32]. The structural-privacy read parallels the European sovereignty push (the Microsoft 'gravity well' piece from June 16) and the broader Palantir-surveillance network coverage on the site. The dedicated brief is on the site [33].

technology.org reported June 16 at 21:25 UTC that AMD is removing the SME (Secure Memory Encryption) feature from consumer-tier Ryzen CPUs, effective with the next silicon revision. The feature was already off by default in the Linux kernel due to a 2021 flaw (Tom's Hardware covered the original CVE), but the silicon-level removal means consumer CPUs no longer have the option to enable it. The server / EPYC line keeps SME / SEV. Engagement sat at 44 points and 1 comment at the 07:30 UTC scan, up from 6 points at 02:09 UTC. The privacy story is the consumer-vs-enterprise split: hardware memory encryption was the last line of defense against DRAM-exfil attacks (cold boot, DMA, malicious kernel modules), and removing the option from consumer silicon means consumer users have no hardware-level memory encryption available while enterprise users do. The structural-privacy read parallels the Apple Hide My Email and Apple Private Cloud Compute 'severely limited' pieces: privacy-protective hardware is now an enterprise tier, not a consumer default [34][35].

What to Watch

  • Today through June 19 (mid-morning watch): OpenAI's first-party response to the $38.5B disclosure. The Fortune piece at 02:09 UTC carried a $21B figure; the FT-verified $38.53B figure is the specific audited disclosure that promotes the story from "leak" to "audited financial disclosure." If OpenAI disputes the figure publicly, the story resets. If tier-1 outlets beyond FT, Ars Technica, and Fortune (Reuters, WSJ, NYT, Bloomberg) pick it up, the engagement compounds further.
  • Today through June 19: Peter Thiel first-party response to the Dialog GitHub-repo disclosure. Any named-individual response. Any tier-1 outlet pickup beyond WIRED and San. The underlying leak has not been independently confirmed by the named individuals as of 07:30 UTC, and any first-party denial or confirmation is the next material development.
  • Today through June 20: Apple first-party response to the TechCrunch Hide My Email tier-1 pickup. Any iCloud+ subscriber class-action filing. Apple WWDC 2026 follow-up coverage June 20 may address the change. The 'third Apple privacy-product change in two weeks' beat is now the structural story the dedicated brief is built on.
  • Today through end of week: Microsoft first-party clarification on the Teams Wi-Fi attendance feature. Any enterprise IT policy that disables the feature by default. Any employee-side pushback at the tenant-admin layer. The structural fix is at the tenant admin layer, not at the device layer, and the employee-side defensive posture is limited.
  • June 19: LinkedIn / GitHub first-party response window (48 hours after the roman.pt backdoor disclosure). The response / non-response is the story. The repo and the LinkedIn profile are still up as of 07:30 UTC.
  • June 19: FIFA / MediaKind / HBS first-party response window (48 hours after BobDaHacker disclosure).
  • June 22: California AB 1043 age-verification bill hearing. The Starmer Australia-plus ID verification beat is the parallel.
  • June 30: T-Mobile March 2026 breach monitoring enrollment deadline. Existing coverage, 'last chance to enroll' peg.
  • August 2: EU AI Act general-purpose AI rules apply. 47 days out.
  • September 30: Federal Data Center Enhancement Act expires with no replacement. Existing coverage, the FDCEA thread is the structural backdrop for the OpenAI financials story and the DOJ xAI 'vital' filing.

References

  1. RuntimeWire: OpenAI leaked financials - Altman compute burn (Ryan Merket, June 16, 2026, 22:36 UTC CT, primary)
  2. Ars Technica: Leaked financial docs show OpenAI is losing billions (June 16, 2026, 16:52 UTC)
  3. Fortune: OpenAI financials leaked - losses revenue profit (June 16, 2026, 23:54 UTC)
  4. Hacker News: OpenAI leaked financials (HN id 48565130, 194 points / 207 comments at 07:30 UTC)
  5. State of Surveillance: OpenAI's Pentagon Surveillance Safeguards Contract (June 2026)
  6. State of Surveillance: Wyden - AI Companies Silent on Government Surveillance (June 2026)
  7. WIRED: A leak just exposed the members of Peter Thiel's secretive 'Dialog' society (Andy Greenberg, June 16, 2026, 20:46 UTC, primary)
  8. GitHub repository: nzaki-dev/dialog (June 17, 2026, the public-facing repo with hard-coded HTML, the technical source)
  9. San: Peter Thiel's Dialog network was super secret - a data leak changed that (June 16, 2026, 22:50 UTC, follow-up)
  10. Hacker News: WIRED Dialog leak (HN id 48561816, 115 points / 8 comments at 07:04 UTC)
  11. Hacker News: GitHub-repo Dialog disclosure (HN id 48566326, 36 points / 9 comments at 07:04 UTC)
  12. State of Surveillance: Peter Thiel's 'Dialog' Leak - GitHub Repo Confirms the Power Network (June 17, 2026)
  13. Arseniy Shestakov: Apple is about to make Hide My Email useless (June 16, 2026, 18:37 UTC, developer-blog primary)
  14. Hacker News: Apple Hide My Email useless (HN id 48559935, 470 points / 246 comments at 07:04 UTC)
  15. TechCrunch: Apple plans to change its Hide My Email privacy feature (Zack Whittaker, June 16, 2026, tier-1 pickup)
  16. State of Surveillance: Apple's iOS 19 Update Makes Hide My Email Useless (June 17, 2026)
  17. PCWorld: From this month onwards this Microsoft programme will keep tabs on your office attendance (June 16, 2026, 02:43 UTC, primary)
  18. Hacker News: Microsoft Teams Wi-Fi office attendance (HN id 48549891, 43 points / 9 comments at 02:09 UTC)
  19. State of Surveillance: Microsoft Teams Will Now Tell Your Boss When You Were in the Office (June 17, 2026)
  20. Dexerto: Stop Killing Games fails to secure EU law despite 1.3M signatures (June 17, 2026, 01:40 UTC, primary)
  21. Hacker News: Stop Killing Games EU failure (HN id 48564696, 154 points / 48 comments at 07:30 UTC)
  22. Reuters: SpaceX to buy Anysphere, operator of Cursor, for $60 billion (June 16, 2026, 10:44 UTC, primary)
  23. BBC: SpaceX agrees to buy Cursor maker Anysphere for $60bn (June 16, 2026, 12:31 UTC)
  24. Hacker News: SpaceX buys Cursor / Anysphere for $60 billion (Reuters thread, HN id 48553224, 980 points / 1,500 comments at 07:04 UTC)
  25. State of Surveillance: SpaceX Buys Cursor / Anysphere for $60 Billion (June 16, 2026)
  26. roman.pt: A backdoor in a LinkedIn job offer (June 15, 2026, 20:00 UTC, primary)
  27. Hacker News: A backdoor in a LinkedIn job offer (HN id 48546294, 1,551 points at 07:30 UTC)
  28. State of Surveillance: A Fake LinkedIn Recruiter Almost Got Me to Run a Backdoor (June 16, 2026)
  29. TechCrunch: DOJ claims xAI's unpermitted gas turbines are a matter of national economic and energy security (June 17, 2026, 03:42 UTC, primary)
  30. Hacker News: DOJ xAI gas turbines TechCrunch pickup (HN id 48565429, 74 points / 54 comments at 07:30 UTC)
  31. State of Surveillance: DOJ Calls Grok Vital National Security Infrastructure (June 16, 2026)
  32. The Guardian: France to ditch Palantir AI data tools for ChapsVision (June 17, 2026, 00:16 UTC, primary)
  33. State of Surveillance: France's DGSI Replaces Palantir With ChapsVision (June 17, 2026)
  34. technology.org: AMD strips memory encryption from consumer Ryzen CPUs (June 16, 2026, 21:25 UTC, primary)
  35. State of Surveillance: AMD Removed Memory Guard From Consumer Ryzen (June 17, 2026)