Today in Surveillance:
- The White House is sitting on a voting-machine vulnerability report 19 weeks before the midterms. Reuters reported on June 20 that the administration is delaying release of a CISA-coordinated vulnerability assessment of US voting-machine infrastructure, with the November 3 midterm elections roughly 19 weeks away [1].
- Norway moved to ban AI in elementary schools. The policy, carrying the same logic as the country's 2024 smartphone ban, would take effect in August 2026, the latest step in a multi-year reversal of in-classroom technology that began with the 2016 tablet rollout [2].
- The UK launched a 75 million pound PoliceAI centre the same week it said it would scan asylum seekers' faces. The Home Office announced the PoliceAI national centre on June 15. On June 20, WIRED reported the same department will use facial age-estimation on asylum seekers [3][4].
- Mysk shipped Loupe, an open-source iOS app that shows what any app can read about you. Loupe reads the public iOS APIs that any third-party app can call with no permission prompt, then shows users the raw values they expose [5].
- Cloudflare introduced temporary accounts for AI agents. The June 20 launch creates short-lived, agent-scoped identities, raising the question of what Cloudflare logs about agents visiting sites and whether those records are shared or reachable by law enforcement [6].
- AMD will reinstate memory encryption on Ryzen 9000 CPUs in July. Tom's Hardware reported AMD will restore TSME through a BIOS update after stripping it via firmware in April, reversing the change "after valuable community feedback" [7].
Also today: An unauthorized alert was pushed to every cell phone in Brazil on Friday night through the same Cell Broadcast channel used for emergency alerts, CNN reported [8]. The "Think of the Children" essay on forcing Real ID for all internet traffic, first published in 2023, resurfaced and re-anchored the age-verification beat [9]. The EFF continued pressing for free court records under the Open Courts Act of 2026, which would retire PACER and eliminate the roughly 150 million dollars in annual fees the federal courts collect to read public documents [10].
The White House Is Sitting on a Voting-Machine Vulnerability Report. The Midterms Are 19 Weeks Away.
Reuters reported on June 20 that the White House is delaying the release of a CISA-coordinated vulnerability assessment of US voting-machine infrastructure, with the November 3 midterm elections roughly 19 weeks out. The report is the kind of disclosure that exists to give election officials, vendors, and the public a chance to patch known weaknesses before ballots are cast. Holding it back narrows that window [1].
The story sits on top of an existing federal-voter-data fight. The disclosure pipeline and the data pipeline are two layers of the same beat. Over the past two months the bigger thread has been the handoff of federal voter data, where the Social Security Administration's data was routed into a Cloudflare-fronted central database. The voting-machine delay is the same question at the disclosure layer: not where the data goes, but what the government chooses to tell the public about how exposed the machines are. Our continuing brief tracks that federal-state-local pipeline [11].
The political-economy question is who knew what, who is holding the report, and what disclosure costs ahead of a midterm cycle. The change comes amid leadership turnover at the Office of the Director of National Intelligence. Watch for a first-party Reuters follow-up naming the specific report and the rejected timeline, any response from CISA or state election officials, and congressional movement, including from a House Intelligence Committee already scheduled to mark up FISA 702 reauthorization the same week [1].
The UK Launched a 75 Million Pound PoliceAI Centre the Same Week It Decided to Scan Asylum Seekers' Faces
The Home Office launched a 75 million pound "PoliceAI" national centre on June 15, according to Public Technology. That is not a research budget, it is a deployment budget: money to operationalize AI across UK policing. Five days later, WIRED reported that the same department will scan the faces of asylum seekers to estimate their age, applying biometric inference to one of the least-protected populations the state interacts with [3][4].
Read together, the two moves describe a single posture: fund the operational layer of police AI and stand up a face-scanning regime in the same week. The asylum face-scan is the sharpest edge because the people subject to it have the least ability to refuse or appeal. Facial age estimation is error-prone, and an error here decides whether someone is treated as a child or an adult by the immigration system [4].
Both stories sit in the wider UK age-verification push, alongside the VPN age-gate fight and the proposed under-16 social media ban that the EFF argues will cause more harm than it prevents. The through-line is identity at the door: age-check the internet, fund the police AI, scan the faces of people who have nowhere else to turn. Watch for the PoliceAI centre's first appointments, the scope of the face-scan pilot and its contractor, and any response from the ICO or civil-liberties coalitions [12].
Mysk Shipped Loupe to Show What Every iOS App Can Read About You
Mysk, the research duo behind a long run of iOS privacy disclosures, released Loupe, an open-source app that surfaces exactly what an installed app can read about a device with no permission prompt. Loupe calls the same public APIs any third-party app can call, then shows the user the raw values those APIs return, organized into passive signals, signals that need permission, and more advanced probes [5].
The point is that the data is already reachable. Apple's App Privacy Report tells you after the fact which sensors an app touched; Loupe shows you, in the moment, the fingerprintable surface any app can quietly read. It includes techniques like URL-scheme probing to detect which other apps are installed and Keychain values that persist across reinstalls, both of which let an app re-identify a user who thought they had a clean slate [5].
This is the user-facing companion to the day's other "privacy is not the default" stories, from AMD's stripped-then-restored memory encryption to the iOS App Privacy Report's limits. Loupe's value is that it is open source and inspectable: the repository itself becomes a running public log of the iOS fingerprinting surface. Watch for any Apple response on the App Privacy Report API or App Store policy, and for EU regulator interest as the AI Act's biometric and inference rules phase in [5].
Cloudflare's Agent Accounts and AMD's Returning Memory Encryption
Cloudflare introduced temporary accounts for AI agents on June 20, short-lived identities scoped to a single agent action rather than a standing login. The pitch is operational hygiene: an agent gets a disposable credential instead of a long-lived key. The surveillance question is the audit trail. A temporary account is still an identity, and the records of which agent did what, on whose behalf, and for how long are exactly the kind of logs that can be requested by site owners or compelled by law enforcement [6].
On the hardware side, Tom's Hardware reported that AMD will reinstate Transparent Secure Memory Encryption on Ryzen 9000 CPUs through a BIOS update in July, after stripping it via a firmware change in April. AMD framed the reversal as a response to "valuable community feedback." The pattern is the one worth remembering: a baseline protection was quietly removed, the technical community pushed back in public, and the vendor restored it, with the whole sequence now part of the record [7]. It is the same "privacy as something that can be revoked and restored" theme running through the Loupe and App Privacy Report stories [13].
Norway Moves Against Classroom AI as Brazil's Emergency Channel Is Hijacked
Norway moved to ban AI in elementary schools, extending the same precautionary logic behind its 2024 smartphone ban. The policy, set to take effect in August 2026, continues a multi-year reversal of a classroom-technology push that began with a 2016 tablet rollout, and it lands as research on screens and attention in young children keeps accumulating. It is one of the most consequential children's-technology policy moves in Europe this year, and it runs directly into the EU's own August 2 AI Act deadline for high-risk systems, which includes rules touching classroom and biometric AI [2].
In Brazil, an unauthorized alert was pushed to every cell phone in the country on Friday night, CNN reported. It went out over Cell Broadcast, the same one-to-many channel used for severe-weather and emergency alerts, the equivalent of the Wireless Emergency Alerts system in the United States. The content was a political message rather than a public-safety warning [8]. The lesson is structural: once the state, or anyone who compromises the state's channel, has a push pipe into every pocket, the only real safeguard is control over what gets pushed and a record of who pushed it [14].
What to Watch This Week
Through Friday June 26. The House Intelligence Committee is expected to mark up FISA 702 reauthorization, with bill text anticipated around June 25. The Wyden-Lee Government Surveillance Reform Act remains the only bipartisan, bicameral bill that would require a warrant to search Americans' communications in the 702 database [15][16].
The voting-machine report. Watch for a Reuters follow-up naming the specific assessment and the rejected disclosure timeline, plus any first-party response from CISA or state election officials as the midterm cycle compounds [1].
The UK pre-recess window. Parliament is heading toward summer recess. Watch for the VPN age-gate policy paper, the asylum face-scan pilot's contractor and scope, and any PoliceAI centre appointments [3][12].
Sunday August 2. The EU AI Act high-risk compliance deadline phases in, including rules on classroom, workplace, and biometric AI that sit alongside Norway's school-AI ban. Expect the first member-state enforcement signals in the weeks after [2].
Sources
- Reuters: White House delays release of US voting-machine study as midterms near, June 20, 2026. https://www.reuters.com/world/white-house-delays-release-us-voting-machine-study-midterms-near-2026-06-19/
- State of Surveillance: Norway Imposes Near Ban on AI in Elementary Schools, June 19, 2026. /news/norway-imposes-near-ban-ai-elementary-school-2026
- Public Technology: UK Home Office launches 75 million pound 'PoliceAI' to capitalise on artificial intelligence, June 15, 2026. https://www.publictechnology.net/2026/06/15/public-order-justice-and-rights/home-office-launches-75m-policeai-to-capitalise-on-artificial-intelligence/
- WIRED: The UK will scan asylum seekers' faces for age checks, June 20, 2026. https://www.wired.com/story/facial-age-estimate-uk-asylum-seekers/
- State of Surveillance: Loupe Shows What iOS Apps See. The App Privacy Report Doesn't., June 21, 2026. /news/loupe-ios-fingerprint-surface-passive-tier-2026
- Cloudflare Blog: Temporary Accounts for AI agents, June 20, 2026. https://blog.cloudflare.com/temporary-accounts/
- Tom's Hardware: AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July, June 20, 2026. https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback
- CNN: Unauthorized alert sent to cell phones across Brazil, June 20, 2026. https://www.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam
- nochan.net: Think of the Children: How to Force Real ID for All Internet Traffic, August 29, 2023 (resurfaced June 19, 2026). https://nochan.net/think-of-the-children-how-to-force-real-id-for-all-internet-traffic/
- State of Surveillance: EFF Court Records Should Be Free PACER Open Courts Act 2026, June 18, 2026. /news/eff-court-records-free-pacer-open-courts-act-2026
- State of Surveillance: DOGE SSA Voter Data Scandal Cloudflare One Big Beautiful Database. /news/doge-ssa-voter-data-scandal-cloudflare-one-big-beautiful-database-2026
- State of Surveillance: UK VPN Ban Age-Gate 200p Cross HN Thread, June 20, 2026. /news/uk-vpn-age-gate-under-16-social-media-ban-2026
- State of Surveillance: AMD Reinstates Memory Encryption on Ryzen 9000, June 20, 2026. /news/amd-ryzen-memory-encryption-reinstated-bios-update-2026
- State of Surveillance: Brazil Cell Broadcast Alert Hack Wireless Emergency Attacks, June 20, 2026. /news/brazil-cell-broadcast-alert-hack-wireless-emergency-attacks-2026
- State of Surveillance: FISA 702, White House Clean-Extension Showdown, the dedicated FISA 702 vessel. /news/fisa-702-51-days-white-house-clean-extension-showdown-2026
- State of Surveillance: Wyden Lee Government Surveillance Reform Act Analysis. /news/wyden-lee-government-surveillance-reform-act-analysis-2026