A dark data center aisle between two rows of server racks with green status lights, the physical infrastructure behind the frontier-model extraction, export-control, and national-security stories of the day
Photo via Unsplash

Today in Surveillance:

  • Anthropic accused Alibaba of running the largest known model-extraction campaign against Claude. In a June 10 letter to the Senate Banking Committee, reported by Reuters and CNBC on June 24, Anthropic said Alibaba-affiliated operators ran 28.8 million exchanges through roughly 25,000 fraudulent accounts between April 22 and June 5 to extract Claude's capabilities, in what the company describes as the largest distillation campaign it has documented [1][2][3].
  • The New York Times reported that the NSA lost access to Anthropic's Mythos cyber-defense model. The classified contract that would formalize the relationship has not been finalized, and some Pentagon officials want the NSA to work with other models, amid the same June 12 export-control directive on Anthropic's frontier systems [4][5].
  • OpenAI shipped GPT-5.5-Cyber under its DayBreak program. OpenAI reported 85.6% on CyberGym and 39.5% on ExploitGym, releasing a model in the same capability class that got Anthropic's Fable 5 pulled from export on June 12 [6][7].
  • A Texas jury convicted anti-ICE protesters on terrorism charges, with Signal and zines entered as evidence. The Guardian reported one defendant was sentenced to decades in prison; Signal auto-delete was framed as consciousness of guilt and zine distribution as material support. Ben Werdmuller reads the precedent for everyone who uses encrypted messaging [13][14][15].
  • Meta paused an employee-tracking program after a keystroke-data exposure. WIRED reported that roughly 45,000 internal tables of employee keystrokes, prompts, and private conversations were accessible companywide; more than 1,600 employees had petitioned against the program [10][11][12].
  • Cory Doctorow's "age verification is mass surveillance" op-ed crossed 900 points. The June 23 piece argues every age-verification mandate builds an identity database that links a real person to specific platform activity, and that database is the surveillance prize [8][9].
  • Filippo Valsorda's "vulnerability reports are not special anymore" became the vulnpocalypse story. The former Cloudflare cryptography lead argues LLM-driven discovery has broken the disclosure workflow; a maintainer confirmed receiving roughly a dozen LLM-generated reports a week, all needing triage [16][17].
  • The digital euro cleared a key EU parliamentary hurdle. A central-bank digital currency is financial-surveillance infrastructure by design: transaction-level traceability and programmable spending restrictions, set against the data-sovereignty case for reducing EU reliance on U.S. card networks [18][19].

Also today: The Economist argued the post-9/11 war on terror built the surveillance apparatus now enabling executive-power expansion [22][23]. IPVM's Flock police-chief stalking investigation continued to draw discussion, with all 18 documented abuse cases caught by audit logs only after the fact [20][21]. Anthropic's Claude Tag put a persistent AI agent inside enterprise Slack channels [24], the Anthropic identity-verification thread stayed near the top of the privacy beat ahead of the July 8 rollout [25], and the Apertus sovereign-AI and Lars Andersen raid threads continued from earlier in the week [26][27].

Anthropic Tells the Senate Alibaba Ran the Largest Known Extraction Campaign Against Claude

In a letter dated June 10 to Senate Banking Committee Chair Tim Scott and Ranking Member Elizabeth Warren, Anthropic alleged that operators affiliated with Alibaba ran 28.8 million exchanges through roughly 25,000 fraudulent accounts between April 22 and June 5, 2026, in a coordinated effort to distill the capabilities of its frontier models. Reuters and CNBC both reported the letter on June 24. The reporting and our own brief identify software-engineering and agentic-reasoning as the capabilities Anthropic says were targeted [1][2][3].

Distillation, in this context, means using a target model's outputs to train a competing model. Anthropic frames it as theft of model capability; the framing also functions as evidence of self-policing offered to Washington while the company contests the June 12 export-control directive on its frontier systems. A proposed amendment to must-pass defense legislation would let the government sanction or blacklist foreign firms found to be improperly extracting U.S. model outputs [3].

The surveillance angle is the identity-and-access layer. Anthropic says it detected the campaign because the accounts were fraudulent, which means the company is now reasoning about who is behind each account, the same identity-verification problem driving its July 8 consumer ID rollout. The line between abuse-detection and user-surveillance is exactly the line the rest of the day's frontier-model stories sit on. The full SOS brief tracks the sourcing and the Senate angle [3].

The NSA Lost Access to Mythos. OpenAI Shipped a Cyber Model the Same Week.

The New York Times reported on June 23 that the NSA lost access to Anthropic's Mythos cyber-defense model amid the Fable 5 export-control dispute. The classified contract that would formalize an NSA-Anthropic relationship, covering intelligence analysis and vulnerability detection, has not been finalized, and the Times reported that some Pentagon officials want the agency to find a way to work with other models [4]. The arc is worth holding in view: in April, the story was the NSA using Mythos despite a Pentagon supply-chain-risk designation; in June, it is the NSA losing access amid a new directive. Our Day-1 brief lays out the mechanism and the open questions [5].

OpenAI supplied the counterweight. On June 22 it shipped GPT-5.5-Cyber under its DayBreak program, reporting 85.6% on the CyberGym benchmark and 39.5% on ExploitGym. That is the same class of offensive-security capability that got Anthropic's Fable 5 pulled from export on June 12 [6]. The asymmetry is the story: one lab's frontier cyber model is treated as a national-security asset too dangerous to export, while a competitor ships a comparable capability into general availability. The export-control regime is reacting to individual companies faster than it can set a coherent rule for the capability itself [7].

Doctorow's Age-Verification Op-Ed Crossed 900 Points

Cory Doctorow's June 23 essay, "What we call 'age verification' is actually mass surveillance," crossed 900 points on Hacker News and stayed in active discussion through June 25 [8]. His argument is structural: every age-verification mandate, whether the UK Online Safety Act, US state laws, EU platform rules, or a frontier-lab account policy, creates an identity-verification database that links a real-world person to specific platform activity. The age check is the entry point. The identity database is the prize, and it is a standing target for state and private actors alike.

The op-ed is the editorial through-line for the week. Anthropic's July 8 identity rollout is the producer-side version, where the verification vendor holds the ID and the selfie. The Alibaba-extraction story is the same identity-and-access problem seen from the abuse-detection side. Our Day-2 brief carries the continuing thread [9].

Meta Paused Employee Tracking After a Keystroke-Data Leak

WIRED reported that Meta paused its internal employee-monitoring program, known internally as MCI, after roughly 45,000 internal tables of employee keystrokes, prompts, and private conversations turned out to be accessible across the company. More than 1,600 employees had already petitioned against the program before the exposure surfaced [10][11].

This is surveillance plus a breach. The same data collected to monitor employees, captured at the keystroke level and used in part for AI training, was left readable internally, which turns a monitoring program into an internal data-exposure incident. It is the labor-side counterpart to the consumer-side identity stories: the company decides what to collect, the worker decides whether to object, and the collected data becomes a liability the moment access controls fail. Our brief tracks the petition and the WIRED reporting [12].

A Texas Jury Treated Signal and Zines as Terrorism Evidence

The Guardian reported that a Texas jury convicted anti-ICE protesters on terrorism charges, with one defendant sentenced to decades in prison. Prosecutors presented the defendants' use of Signal, including its disappearing-messages feature, as evidence of intent, and treated the printing and distribution of zines as a form of material support [13]. Ben Werdmuller's essay reads the precedent plainly: when encrypted messaging and independent publishing are entered as evidence of criminality, the tools themselves become risk markers, regardless of what the person was actually doing [14].

The structural point connects to Doctorow's. Surveillance systems watch behavior, not intent, so privacy-protective behavior and genuinely criminal behavior can look identical in the record. A prosecution that begins from "they used Signal" is a prosecution that treats a privacy choice as evidence. Our brief covers the convictions and the sentencing [15].

Valsorda: Vulnerability Reports Are Not Special Anymore

Filippo Valsorda, the cryptographer and former Cloudflare cryptography lead, argued in a June 23 essay that LLM-driven vulnerability discovery has broken the assumptions the disclosure workflow was built on. When finding a bug was a scarce skill, a private report to a vendor carried weight. When a model can generate plausible reports at volume, the privileged channel collapses under triage load. A maintainer publicly confirmed receiving roughly a dozen LLM-generated reports a week, most of which need human review before they can even be dismissed [16][17].

This is the disclosure-side companion to the DayBreak and Mythos stories. The same model capability that makes a frontier cyber model a national-security question also reshapes the everyday trust relationship between security researchers and the projects they report to. The shift from human-vetted reports to machine-generated volume has direct implications for how state actors and vendors alike manage vulnerability knowledge.

The Digital Euro Cleared a Key EU Hurdle

A European Parliament committee advanced the framework for the digital euro, moving the central-bank digital currency a step closer to a planned 2027 launch. The political framing in Brussels is data sovereignty: reducing EU dependence on U.S.-dominated card networks so that European payment data stays under European jurisdiction rather than reachable through instruments like the CLOUD Act [18].

The surveillance reading is built into the design. A central-bank digital currency means transaction-level traceability at the central bank and the technical capacity for programmable restrictions: spending caps, time windows, or category limits encoded into the currency itself. The data-sovereignty gain for the EU is real, and so is the new financial-surveillance surface it creates. Our brief covers the committee vote and the comment-thread debate [19].

Flock Police-Chief Stalking: Every Case Caught After the Fact

IPVM's investigation into police chiefs using Flock Safety's automatic license-plate-reader network to track women continued to draw heavy discussion. The detail that matters most for policy: all 18 documented abuse cases were surfaced by audit logs after the queries had already run. The audit log is a record of what happened, not a control that prevents it [20]. That is the structural argument for the warrant-requirement bills moving in Washington and Colorado, which would force an officer to articulate a reason before querying rather than explain it afterward. Our brief tracks the cases and the legislative response [21].

What to Watch This Week

Wednesday June 25 to Friday June 26. The House Intelligence Committee mark-up on FISA 702 reauthorization is the anchor vehicle for the surveillance-authority fight. The Wyden-Lee Government Surveillance Reform Act remains the only bipartisan, bicameral bill that would require a warrant to search Americans' communications in the 702 database [28].

The Alibaba amendment. Watch whether the proposed sanction-and-blacklist amendment on improper extraction of U.S. model outputs is attached to the defense bill, and whether Alibaba or Chinese regulators respond to Anthropic's allegations [3].

Wednesday July 8. Anthropic's identity-verification requirement takes effect. The first wave of users who fail verification would be locked out of the top Claude models, making the Persona data-retention and law-enforcement-access questions concrete [30].

Sunday August 2. The EU AI Act high-risk compliance deadline phases in, including biometric-inference rules that touch age-verification and identity systems. Expect the first member-state enforcement signals in the weeks after [29].

Sources

  1. Reuters: Anthropic says Alibaba illicitly extracted Claude AI model capabilities, June 24, 2026. https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/
  2. CNBC, Ashley Capoot: Anthropic accuses Alibaba of campaign to illicitly extract AI capabilities, June 24, 2026. https://www.cnbc.com/2026/06/24/anthropic-alibaba-distillation-campaign.html
  3. State of Surveillance: Anthropic Accuses Alibaba of Massive Claude Extraction Campaign, the Day-1 brief with the Senate Banking letter and the proposed amendment. /news/anthropic-alibaba-claude-distillation-june-24-2026
  4. The New York Times: NSA Lost Access to Anthropic Tool, June 23, 2026. https://www.nytimes.com/2026/06/23/us/politics/nsa-lost-access-anthropic-tool.html
  5. State of Surveillance: NSA Lost Access to Mythos Amid Anthropic Dispute, the Day-1 brief. /news/nsa-lost-access-mythos-anthropic-dispute-june-23-2026
  6. OpenAI: DayBreak, securing the world, the GPT-5.5-Cyber announcement with the CyberGym and ExploitGym figures. https://openai.com/index/daybreak-securing-the-world/
  7. State of Surveillance: OpenAI DayBreak Is the Asymmetric Frontier, the brief on GPT-5.5-Cyber and the Fable 5 export contrast. /news/openai-daybreak-gpt-55-cyber-asymmetric-frontier-2026
  8. Cory Doctorow, pluralistic.net: What we call "age verification" is actually mass surveillance, June 23, 2026. https://pluralistic.net/2026/06/23/destroy-the-village/
  9. State of Surveillance: Doctorow Age-Verification Op-Ed Crossed 900, the Day-2 brief. /news/cory-doctorow-age-verification-is-mass-surveillance-2026
  10. WIRED: Meta accidentally let employees access each other's keystroke data, June 2026. https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
  11. WIRED: Meta pauses employee-tracking program following internal security breach, June 2026. https://www.wired.com/story/meta-pauses-employee-tracking-program-following-internal-security-breach/
  12. State of Surveillance: Meta Pauses Its Employee Tracking Program After Internal Data Leak, the brief on the MCI program and petition. /news/meta-pauses-employee-tracking-internal-data-leak-2026
  13. The Guardian: Texas anti-ICE protesters convicted on terrorism charges, June 23, 2026. https://www.theguardian.com/us-news/2026/jun/23/texas-anti-ice-protesters-convicted-terrorism-charges-sentenced-50-years-prison
  14. Ben Werdmuller, werd.io: Signs you're a dangerous terrorist: using Signal, moving zines, June 23, 2026. https://werd.io/signs-youre-a-dangerous-terrorist-using-signal-moving-zines/
  15. State of Surveillance: Texas Convicted Anti-ICE Protesters as Terrorists, the brief on the convictions and evidence. /news/ben-werdmuller-signal-zines-anti-ice-terrorism-2026
  16. Filippo Valsorda, words.filippo.io: Vulnerability reports are not special anymore, June 23, 2026. https://words.filippo.io/vuln-reports/
  17. State of Surveillance: Valsorda Was Right, the Vulnpocalypse Is Real, the Day-2 brief with the maintainer confirmation. /news/vulnerability-reports-not-special-vulnpocalypse-2026
  18. European Central Bank: Digital euro, the official project page. https://www.ecb.europa.eu/euro/digital_euro/html/index.en.html
  19. State of Surveillance: Digital Euro Thread Crossed 200p, the brief on the committee vote and surveillance concerns. /news/digital-euro-clears-eu-parliamentary-hurdle-2026
  20. IPVM: Police Chiefs Track, the investigation into Flock-powered chiefs tracking women. https://ipvm.com/reports/police-chiefs-track
  21. State of Surveillance: Flock Stalking Thread at 615p, 18 Cases, Zero Audit-Log Preventions. /news/flock-police-chiefs-stalking-women-warrants-needed-2026
  22. The Economist, by invitation: How the war on terror primed America for autocracy, June 2, 2026. https://www.economist.com/by-invitation/2026/06/02/how-the-war-on-terror-primed-america-for-autocracy
  23. State of Surveillance: The War on Terror Primed America for Autocracy, the Day-1 brief. /news/war-on-terror-economist-day-1-269p-2026
  24. State of Surveillance: Anthropic's Claude Tag Joins Slack, the brief on the enterprise Slack agent. /news/anthropic-claude-tag-slack-agent-coworker-2026
  25. State of Surveillance: Anthropic ID Thread Crossed 860, the Day-10 identity-verification brief. /news/anthropic-id-verification-consumer-capabilities-july-8-2026
  26. State of Surveillance: Apertus Thread Held 531p, the Day-6 sovereign-AI brief. /news/apertus-sovereign-ai-300p-hn-2026
  27. State of Surveillance: Lars Andersen Thread at 433, the Day-7 brief on the Danish anti-surveillance raid thread. /news/lars-andersen-danish-anti-surveillance-figure-raid-police-2026
  28. State of Surveillance: FISA 702, White House Clean-Extension Showdown, the dedicated FISA 702 vessel. /news/fisa-702-51-days-white-house-clean-extension-showdown-2026
  29. State of Surveillance: EU AI Act August 2026 Biometric Surveillance Explainer, the dedicated EU AI Act vessel. /news/eu-ai-act-august-2026-biometric-surveillance-explainer
  30. State of Surveillance: Anthropic ID Verification Consumer Capabilities July 8, the rollout vessel. /news/anthropic-id-verification-consumer-capabilities-july-8-2026