Today in Surveillance:
- Norway fined Elkjop 1.8 million euros for forced-consent customer clubs. Datatilsynet found four GDPR infringements in how the electronics retailer bundled loyalty-club consent, the first Nordic enforcement record treating a customer club as a dark pattern. The original complainant, privacy researcher Alexander Hanff, filed five years ago [1][2].
- Anthropic said it is very confident it can re-enable Fable 5 in the coming days. Managing Director of International Chris Ciauri told a Seoul press conference it was the first public timeline since the June 13 export-control directive that pulled access to Anthropic's frontier models [3].
- The ACLU sued the City of Norfolk over its license-plate-reader program. Schmidt v. Norfolk argues the warrantless, continuous capture of every passing plate is an unreasonable search under the Fourth Amendment [4].
- Amazon is investigating engineers who criticized its AI data-center expansion. CNBC reported the company opened internal probes into employees who raised concerns about the buildout, the latest case of a major AI firm scrutinizing its own critics [5].
- ProPublica exposed US demands for African medical and identity data. The State Department is conditioning foreign aid on access to recipient nations' medical, aid, and identity records, a cross-border data-sovereignty grab [6].
Also today: A widely read personal essay, "The AI Hate Progression," documented how AI tools lower the cost of organized harassment [7]. Human Rights Watch disclosed that Bulgaria licensed surveillance-technology exports to rights-violating regimes, exposing a gap in the EU dual-use regime [8].
Norway Fines Elkjop 1.8 Million Euros for Building Forced Consent Into Its Customer Club
Norway's data protection authority, Datatilsynet, fined electronics retailer Elkjop 20 million Norwegian kroner, roughly 1.8 million euros, for the way it ran its customer club. The regulator found four separate GDPR infringements, and the case turns on consent: Elkjop's club required members to accept marketing and data-sharing terms in a bundle, so signing up at all meant signing away choices that the law says must be specific and freely given. The decision, published in early June 2026, also flagged the processing of children's data as an aggravating factor [1][9].
The complaint that produced it is five years old. Privacy researcher Alexander Hanff first told Elkjop its forced-consent setup was unlawful, then filed the case and waited. His account of the long road to the fine carries the reference number and the four-infringement breakdown, and it is the kind of receipt the dark-pattern beat rarely gets: a regulator confirming, in writing, that a loyalty program built on take-it-or-leave-it consent is illegal [1]. This is the same enforcement pattern as Spain's AEPD biometric fines and Luxembourg's CNPD Amazon case, but it is the first time the customer-club class itself, the kind of program nearly every large retailer runs, has been named in a published Nordic ruling.
What makes it matter beyond Norway is the 14-day appeal window, which closes on July 2, 2026. If Elkjop appeals, the case moves from a regulatory precedent to a court precedent and the whole question gets litigated in public. If it does not, the Datatilsynet decision stands as the unchallenged Nordic benchmark, and every other retailer running a bundled-consent loyalty scheme has a written warning to read. Datatilsynet has updated its own guidance on customer clubs in light of the findings, covering bundling, specificity of consent, and third-party sharing of club data [9].
Anthropic Says It Is Very Confident It Can Re-Enable Fable 5 in Coming Days
Chris Ciauri, Anthropic's Managing Director of International, told a Seoul press conference on Wednesday, June 18, that the company is "very confident that in the coming days, the models will become available again." The Korea JoongAng Daily carried the quote, the first public timeline Anthropic has offered since the June 13 export-control directive restricted access to its frontier models, including Fable 5 and the Mythos cyber-defense system, for foreign nationals [3].
Ciauri spoke at the launch of Anthropic's Seoul office, its first physical presence in Asia. The framing was a partnership: the company is building in-region infrastructure for the Korean market even as the directive cuts off some of the customers that infrastructure was meant to serve. The timing is the signal. Until now the company had let the White House dispute play out without committing to a public window. Saying "coming days" in front of Korean press is a bet that the compliance work and the political engagement are both far enough along to risk a deadline.
The export fight has reached Anthropic's overseas carriers too. WIRED reported that SK Telecom, South Korea's largest mobile operator with roughly 27 million subscribers and a partner in the Korean Mythos rollout, sits at the center of the dispute, extending the directive's reach from Anthropic's own workforce to the international partners that delivered its models abroad. The continuing thread, and the open question of which models and regions any re-enable will actually cover, runs through our Anthropic Fable 5 and Mythos coverage [10].
The ACLU Sued Norfolk Over Its License-Plate-Reader Dragnet
The ACLU filed Schmidt v. Norfolk, a Fourth Amendment challenge to the City of Norfolk, Virginia's automatic license plate reader program. The complaint targets the structure of the system, not a single bad search: Norfolk's network of mounted cameras logs every plate that passes, stamps each one with a time and GPS location, and stores it in a database police can query retroactively, all without a warrant and without any suspicion that the driver did anything wrong [4].
The legal question is whether that continuous, warrantless capture of where people drive is a "search" under the Fourth Amendment, and if so whether it is reasonable. The Supreme Court has not answered it directly, and the federal circuits are split. The ACLU's argument leans on the same logic the Court used in its location-tracking rulings: that aggregating enough individually mundane data points reveals a detailed picture of a person's life, which is exactly what a plate-reader database does over weeks and months.
Schmidt v. Norfolk lands as plate-reader fights heat up in statehouses across the country, with pending legislation in Virginia, California, Texas, and New York. A win for the ACLU would force police to justify plate-reader queries in advance rather than explain them after the fact, the same warrant-first principle moving through several of those bills. The case is the clearest legal test yet of whether the dragnet survives constitutional scrutiny.
Amazon Is Investigating Engineers Who Criticized Its AI Data-Center Buildout
CNBC reported on June 18 that Amazon opened internal investigations into engineers who criticized the company's AI data-center expansion. Workers who raised concerns about the pace and scale of the buildout, the power and water it consumes, and the way it is being pushed through, found themselves the subject of HR scrutiny rather than a hearing [5]. Some employees have said publicly that they fear termination for backing limits on the construction.
The pattern is becoming familiar. It echoes the xAI engineer fired after raising Grok safety concerns earlier in June, and it lands in the same week the White House is demanding that AI labs proactively test their models for jailbreaks. The contradiction is hard to miss: regulators want frontier-AI companies to surface their own risks, while the companies themselves are investigating the employees who try to. Our running coverage of corporate retaliation against AI critics sits in the DOJ-xAI national-security brief [11].
The surveillance angle is the workplace itself. Identifying which engineers voiced criticism, in internal channels and out, is an exercise in monitoring employee speech, and the chilling effect is the point even when no one is fired. It is the labor-side version of the identity-and-access questions running through the rest of the day's AI stories: the company decides what to watch, the worker decides whether to risk objecting.
ProPublica: The US Is Demanding African Nations' Medical and Identity Data for Aid
ProPublica reported that the US State Department is demanding access to African nations' medical, aid, and identity data as a condition of receiving foreign assistance. The demand turns aid into a bargaining chip for a cross-border data grab, pressing recipient governments to hand over sensitive records on their own citizens to a foreign power in exchange for funding they depend on [6].
It is the same data-sovereignty fault line running through Europe's push for homegrown infrastructure, only with the power imbalance reversed and far sharper. Medical and identity records are among the most sensitive categories a state holds, and once they cross a border they fall under another government's legal reach, including instruments like the US CLOUD Act. The story is a reminder that the surveillance economy is not only corporate. States collect power over each other's populations too, and aid dependency is one of the oldest levers there is.
Also Today: AI Harassment Essay, Bulgaria's Surveillance Exports
A personal essay titled "The AI Hate Progression," published June 18, drew wide discussion for documenting how generative tools lower the cost of organized harassment. The author traces an escalation from manual abuse to AI-assisted campaigns that scale faster and cheaper than a target can respond, the human-stakes counterpart to the abstract debates about model safety. The piece reads as a ground-level account of what "AI-facilitated harm" looks like for the person on the receiving end [7].
Human Rights Watch disclosed that Bulgaria licensed surveillance-technology exports to governments with records of rights abuses. The EU's dual-use regulation is supposed to stop exactly this, requiring member states to screen surveillance exports for human-rights risk, and the HRW findings expose an enforcement gap inside the bloc. It is the same oversight failure that has dogged the NSO and Predator spyware export debates, this time with an EU member state issuing the licenses [8].
What to Watch
- July 2: Elkjop's appeal window closes. If the retailer appeals the Datatilsynet fine, the customer-club consent question moves from a regulatory record to a court fight. If it does not, the decision stands as the unchallenged Nordic benchmark.
- The coming days: Anthropic's actual Fable 5 re-enable. Ciauri's "coming days" quote set a public clock. Watch which models, regions, and customers any re-enable covers, and whether SK Telecom or the Korean government responds.
- Schmidt v. Norfolk: the first motions and any tier-one outlet pickup, plus movement on the pending plate-reader bills in Virginia, California, Texas, and New York.
- Amazon: any first-party response to the CNBC report, any congressional inquiry, and any worker-side legal filing over the investigations.
- ProPublica follow-up: whether the African Union or affected governments respond to the State Department's data demands, and whether European institutions weigh in.
Sources
- That Privacy Guy, Alexander Hanff: I told them forced consent was unlawful. Five years later it cost Elkjop 1.8 million euros (June 18, 2026)
- State of Surveillance: Norway Fines Elkjop for Forced-Consent Customer Club
- Korea JoongAng Daily: Anthropic confident of re-enabling Mythos, Fable 5 access in coming days, executive says (June 18, 2026)
- ACLU: Schmidt v. Norfolk, do automatic license plate readers violate privacy under the Fourth Amendment?
- CNBC: Amazon investigating engineers who criticized AI data center expansion (June 18, 2026)
- ProPublica: US demands to access Africans' data raise privacy, sovereignty concerns (June 18, 2026)
- xodium.net: The AI Hate Progression (June 18, 2026)
- Human Rights Watch: Bulgaria licensed surveillance exports to rights violators (June 18, 2026)
- Datatilsynet: Administrative fine imposed on Elkjop (June 5, 2026)
- State of Surveillance: Anthropic Fable 5 and Mythos 5: three reports
- State of Surveillance: DOJ Calls Grok Vital National Security Infrastructure