Today in Surveillance:

  • 404 Media reported USPS is putting forward-facing road-scanning cameras in 100 mail trucks in the Washington, DC area for a "community safety" pilot. The dashcam vendor is Next Base. The pilot was slated to start September 21 and is expected to last several months. USPS told 404 Media the system "includes privacy safeguards" and does not record audio [1].
  • 404 Media also documented how a 1980s-era anti-drug program called HIDTA forces cities to funnel ALPR data into a federal database. Cities sign memoranda of understanding that route plate reads through regional hubs; some data can flow onward to the DEA's National License Plate Reader Program and to Customs and Border Protection. The Trump administration gave HIDTA $277 million in additional funding in July 2026 [2].
  • The Register reported British Transport Police spent more than £320,000 on a six-month live facial recognition pilot that scanned over 500,000 faces and produced no correct matches. BTP used NEC's NeoFace M40 system. The single alert was a false positive; nearly 100 officer-hours went into the deployment [3][4].
  • EFF pushed back on San Francisco's draft drone policy, DGO 10.12, calling deployment language too vague and warning it could enable general surveillance of First Amendment-protected activity. The Police Commission is set to reconsider the matter on October 14 [5].
  • EFF called Governor Newsom's September 18 AI executive order "a good start" but criticized its focus on speculative risks over concrete harms already in production. EFF flagged kill-switch language as a potential vector for political retaliation [6].
  • EFF published a step-by-step guide to limiting what Apple's new Siri AI can access in iOS 27. Siri AI's on-screen awareness can read Signal or WhatsApp chats, and Private Cloud Compute may send data off-device with no visual indicator [7].
  • A California appeals court refused to revive a SLAPP suit by surveillance-tech CEO Maury Blackman against journalist Jack Poulson. The court held the First Amendment protects the lawfully obtained publication of sealed arrest records [8].

Continuing threads: The federal-car-surveillance mandate vessel carries the parallel federal-vehicle-collection fight. The Flock city-cancel vessel and the Colorado SB26-070 warrant bill vessel sit alongside the HIDTA piece. The SFPD drone policy vessel is the prior chapter on DGO 10.12. The White House AI Framework vessel covers the federal preemption thread against which California's EO reads.

USPS Is Putting Road-Scanning Cameras in Mail Trucks for "Community Safety"

Joseph Cox reported in 404 Media on September 30 that the US Postal Service is running a limited pilot to mount forward-facing cameras inside mail carrier trucks, starting with 100 vehicles in the Washington, DC area. The dashcam vendor is Next Base, a UK company that sells consumer and fleet cameras with up to 4K recording. The cameras begin recording once the truck is in drive and away from the postal facility, scan and analyze roads, map roadways and sidewalks, and are described in USPS materials as not equipped with ALPR software, despite Next Base marketing claims about license plate capture. USPS told 404 Media the pilot "includes privacy safeguards and requires no additional action from employees." The Postal Service framed the program in a Labor Relations letter to the National Association of Letter Carriers as a way to draw on "the Postal Service's unique ability to collect this valuable data due to the scale and frequency with which our fleet of postal vehicles travel the streets of every community." A USPS spokesperson told 404 Media the cameras will "not block driver's field of vision" and "do not record audio." The pilot was slated to begin September 21 and is expected to last several months [1].

The framing battle is the story. The USPS press line calls the data collection "community safety," which is the same rhetorical work that the NHTSA DADSS drunk-driving-prevention label did for the federal in-car surveillance mandate. A federal mail fleet runs every street in America. A pilot of 100 trucks in Washington, DC is a pilot the same way the postal service's existing 360-degree exterior cameras are a "pilot," which is to say, the proof-of-concept stage of a permanent collection layer. Our federal-car-surveillance mandate vessel covers the parallel federal-vehicle thread that our highest-traffic readers have already followed [1].

HIDTA Forces Cities to Funnel ALPR Data Into a Federal Database

Sam Biddle reported in 404 Media on September 30 that a 1980s-era anti-drug program called HIDTA, the High Intensity Drug Trafficking Areas program run by the White House's Office of National Drug Control Policy, sits behind a pipeline that funnels local automatic license plate reader data into a federal database. The pipeline runs through 33 HIDTA programs covering all 50 states, each with a regional intelligence center. Cities sign memoranda of understanding requiring them to share ALPR data with HIDTA; some MOUs require cities to share data on "Automated License Plate Readers and Law Enforcement Data Sharing Systems" via "commercially available and custom developed data integration systems." Vendors named in the piece include Flock, Axon, ELSAG, and Vigilant. A Randolph County, North Carolina sheriff's office told 404 Media "all data is kept on the Federal Houston-HIDTA database." The Trump administration gave HIDTA $277 million in additional funding in July 2026. In some cases, Biddle reports, data flows onward to the DEA's National License Plate Reader Program and to Customs and Border Protection's LPR system [2].

The legal gimmick is the structural point. The Obama White House once described HIDTA in court as a "grant program" rather than an entity, a framing that the DEA has since used to argue in FOIA litigation that "DEA does not create, possess, maintain, or control HIDTA program records." Local agencies have cited that argument to deny public records requests on their own ALPR data. Cris van Pelt, the creator of HaveIBeenFlocked.com, told 404 Media "the DEA and ONDCP are already aggregating local data behind the scenes" and that "mass surveillance violates fundamental rights, even when it is laundered through fragmented systems." Jeramie Scott of the EPIC Surveillance Oversight Center said "the whole scheme adds another layer of obfuscation" and "if you're pissed about Flock then you should be pissed about this." Our Flock city-cancel vessel is the parallel story on the local-government side, and the California border ALPR vessel covers the federal-state overlap [2].

British Transport Police Spent £320,000 on Live Facial Recognition and Got Zero Matches

Carly Page reported in The Register on September 30 that British Transport Police's six-month live facial recognition pilot at London railway stations scanned more than 500,000 faces, generated a single alert, that alert was a false positive, and no arrests came from the system. BTP used NEC's NeoFace M40 hardware. The cost was more than £320,000. The deployment ate nearly 100 officer-hours. BTP extended the trial until November and expanded it to London Underground. The figures were first disclosed by The Guardian on September 29, drawn from Freedom of Information requests filed by the civil liberties group Liberty [3][4].

The civil-liberties response is sharper than the numbers. Jasleen Chaggar, Senior Legal and Policy Officer at Big Brother Watch, said the figures "would be laughable, if they didn't have such troubling implications for our rights and freedoms" and called it "insulting to waste almost 100 hours of officers' time and £320,000 of public money when it produces such meagre results." Sarah Simms, Senior Policy Officer at Privacy International, said "we are deeply concerned by the results of the British Transport Police's live FRT trial" and that the deployments are "invasive and disproportionate." Earlier in 2026, UK police temporarily suspended live facial recognition deployments after independent testing raised concerns about racial bias at some operating thresholds. The piece is the cleanest effectiveness-failure counter to vendor ROI claims in the public-space facial recognition beat. Our Cook County Briefcam vessel is one of several US-side reference points, and the Congressional Research Service facial-recognition vessel is the federal-side context [3][4].

EFF: San Francisco's Draft Drone Policy Lets the Police Department Fly on Every Call

EFF's September 18 comment to the San Francisco Police Commission argued that the department's proposed drone policy, Department General Order 10.12 governing Unmanned Aircraft Systems Operations, leaves deployment language vague enough to enable general surveillance. EFF's argument: the revised policy says UAVs "may be used as an asset in any situation in which a member may be deployed for a public safety response" but does not define "public safety response." Drones could be deployed to "every call for service, even in situations that are ultimately deemed nonincidents," with collected data stored for 30 days. EFF also noted drone flights grew from roughly 350 in 2024 to over 1,100 between January and August 2025 to over 3,500 in just the first five months of 2026, while use cases expanded from specific incidents to general patrol. The Police Commission is set to reconsider the matter on October 14 [5].

The surveillance angle is the mission-creep ratchet. Prop E in March 2024 removed drones from the city's 2019 Surveillance Technology Ordinance, and SFPD initially violated California's AB 481 by purchasing drones before seeking approval. EFF's framing of DGO 10.12: a policy written broadly enough to cover "general patrol" is a policy that allows the drone fleet to do what the fleet has been growing into. EFF's coalition letter was joined by the San Francisco Public Defender's Office and more than 40 other organizations. Our SFPD drone policy vessel is the prior chapter on DGO 10.12, and the EFF FAA drone amicus vessel covers the federal-side drone-regulation fight [5].

EFF: California's AI Executive Order Focuses on the Wrong Harms

EFF published a statement on September 28 on California Governor Gavin Newsom's September 18 executive order on artificial intelligence. EFF called the EO "a good start" and "an opportunity for a needed, thoughtful conversation," but argued it leans on speculative risks like "rogue super-intelligence" while ignoring concrete harms already in production: biased algorithmic decision-making in employment and government benefits, AI-powered surveillance systems including Flock cameras, and "artificially inflated personalized pricing." EFF also flagged the EO's kill-switch language as a vector for political retaliation, citing "the Trump Administration's retaliatory actions against Anthropic," and warned that "government-controlled kill switches run the risk of being used as a form of retaliation against protected speech." EFF also urged that third-party investigations under SB 53 be made available for smaller developers [6].

The state-versus-federal preemption argument runs underneath. California's AI EO sets the state-level precedent that the federal AI framework will measure itself against. Our White House AI Framework vessel covers the federal preemption side, and the surveillance-pricing bans vessel covers the concrete harm EFF named. EFF's framing tracks the SOS line: the harms worth regulating are the ones already shipping [6].

How to Limit What Apple's New Siri AI Can Reach in iOS 27

EFF published a step-by-step guide on September 18 to limiting what Apple's new Siri AI can access in iOS 27. The privacy risks EFF flagged: Siri AI searches through Apple apps like Notes, Messages, and emails by default, and third-party apps can opt in. "On-screen awareness" lets Siri AI see and summarize whatever is currently displayed on screen, including Signal or WhatsApp chats, with no way for users or developers to block the feature. "Learn from this App" and related settings let Siri track app usage patterns. Data may be sent off-device to Apple's Private Cloud Compute with no visual indicator to users of when this happens [7].

EFF's settings playbook: under Settings, Apps, the relevant app, and Search, disable "Show Content in Search" for each app; under Settings, Privacy and Security, Analytics and Improvements, disable "Improve Siri and Dictation"; under Settings, Screen Time, Content and Privacy Restrictions, Siri, set Allowed Siri Version to "Siri Classic." EFF's structural point is that "there is no way for users or developers to block" on-screen awareness from reading app contents, so the practical mitigation is restricting what reaches the screen in the first place. The guide pairs with EFF's separate essay arguing that adding AI features to secure messengers (Signal, WhatsApp, encrypted RCS) erodes end-to-end encryption guarantees whether or not the AI runs inside a Trusted Execution Environment [7].

California Appeals Court Rejects SLAPP Suit by Surveillance-Tech CEO Against Journalist

EFF reported on September 30 that the California Court of Appeal refused to revive a meritless lawsuit by Maury Blackman, the former CEO of Premise Data, against Jack Poulson, the writer and publisher of the All Source Intelligence newsletter on Substack. Blackman had sued Poulson, Substack, AWS, and another organization after Poulson reported on Blackman's arrest for felony domestic violence, seeking damages and removal of the reporting. The trial court dismissed the case under California's anti-SLAPP statute; the appeals court affirmed, holding the First Amendment protects "the lawfully obtained truthful publication of the information at issue absent a need to further a state interest of the highest order." The court also protected Poulson under California's Shield Law, citing EFF's 2006 precedent, and granted Substack and the other website Section 230 immunity [8].

The press-freedom angle is the structural point. SLAPP suits by surveillance-industry executives against journalists who report on the industry have been a recurring pressure point. A ruling that protects lawfully obtained truthful publication is the rule that lets the next story run [8].

What to Watch This Week

The USPS pilot's data destination. Watch for any FOIA response, union disclosure, or oversight letter that names what is done with the road-scan data after it leaves the truck. The pilot's stated retention and access rules are the variable that determines whether this is a road-mapping exercise or the start of a permanent federal road-collection layer [1].

Brunswick, Georgia and the MOU fight. Watch for whether the city's challenge to the requirement that it sign a HIDTA MOU before installing Axon cameras moves, and whether any other jurisdiction tests the same gating requirement. The structural fight is whether signing the MOU is a prerequisite for operating ALPRs at all [2].

The BTP facial-recognition extension. Watch for whether the November extension of BTP's NEC NeoFace deployment adds a deletion-deadline clause, a judicial authorization gate, or any of the safeguards the UK temporarily suspended earlier in 2026 over racial-bias concerns [3][4].

The San Francisco Police Commission's October 14 vote. Watch for whether DGO 10.12 is amended to define "public safety response" and add retention limits beyond 30 days, or whether it advances as written and the EFF coalition escalates [5].

The Apple iOS 27 Siri AI settings update. Watch for whether Apple ships an opt-out for "on-screen awareness," or whether the only mitigation remains the per-app and per-feature toggles EFF's guide documents [7].

Sources

  1. 404 Media, Joseph Cox: USPS To Put Cameras in Trucks That Scan Roads for "Community Safety," September 30, 2026. https://www.404media.co/usps-to-put-cameras-in-trucks-that-scan-roads-for-community-safety/
  2. 404 Media, Sam Biddle: How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program (HIDTA), September 30, 2026. https://www.404media.co/how-cities-are-forced-to-funnel-license-plate-data-to-a-massive-federal-surveillance-program-hidta/
  3. The Register, Carly Page: UK Rail Cops' £320K Face-Scanning Spree Nets Zero Matches, September 30, 2026. https://www.theregister.com/security/2026/09/30/uk-rail-cops-320k-face-scanning-spree-nets-zero-matches/5299793
  4. The Guardian, September 29, 2026 (FOI disclosure by Liberty, figures cited by The Register). https://www.theguardian.com/uk-news/2026/sep/29/british-transport-police-live-facial-recognition
  5. EFF Deeplinks: EFF to San Francisco Police: Drones Are Powerful Surveillance Tools, September 30, 2026. EFF Deeplinks
  6. EFF Deeplinks: EFF Statement on California Governor's Executive Order on AI, September 30, 2026. https://www.eff.org/deeplinks/2026/09/eff-statement-california-governors-executive-order-ai
  7. EFF Deeplinks: How to Limit What Apple's New Siri AI Can Access in iOS 27, September 30, 2026. https://www.eff.org/deeplinks/2026/09/how-limit-what-apples-new-siri-ai-can-access-ios-27
  8. EFF Deeplinks: Victory! California Appeals Court Refuses to Revive Surveillance Tech CEO's Meritless Lawsuit Against Journalist, September 30, 2026. https://www.eff.org/deeplinks/2026/09/victory-california-appeals-court-refuses-revive-surveillance-tech-ceos-meritless