Today in Surveillance:

  • Texas and Florida both moved against Flock in the same week. Governor Greg Abbott banned state agencies from spending public money on Flock Safety cameras on August 28, and Governor Ron DeSantis announced a Florida Department of Transportation order on August 31 pulling every ALPR out of state highway right-of-way within 30 days [1][2].
  • Police departments are now asking Axon to redesign its fixed ALPR so it does not look like a Flock camera. During an August 26 Axon webinar titled "From backlash to trust," Chief Customer Officer Mike Wagers raised the redesign request and CEO Rick Smith confirmed the company is "looking at" changing the general shape of its Outpost unit [3].
  • A Texas sheriff's sergeant used Axon's Draft One AI to draft the report on a Flock-led search for a woman who self-administered an abortion. Johnson County Sergeant Damien Bethel ran the woman's plate through Flock and pulled her addresses from TransUnion's TLO database, then had the AI write the narrative, including a summary of "the legal implications" [4].
  • The UK Cyber Security and Resilience Bill puts criminal liability on AI users and datacenters, not on the model vendors. Lords amendments that would have brought vendors within scope, required "red line" assurances, or given the Secretary of State emergency shutdown powers were rejected [5].
  • Boston Scientific's cardiac-device remote monitoring has been offline since August 25. New implants cannot activate remote transmitters, and ShinyHunters separately claimed 284 million records stolen from McKesson's Snowflake and Salesforce instances, with a $55.2 million ransom demand [6].
  • A legacy Lenovo SSO integration let attackers reach roughly 5,000 Dropbox business accounts. Fewer than a third had files actually accessed, and none of the affected accounts had two-factor authentication enabled [7].

Also today: Yesterday's briefing on the Florida "Deputy of the Year" stalking case continued to draw attention alongside the new Abbott and FDOT actions [1]. EFF's Deeplinks write-up on the Texas and Florida orders ties both decisions to the same underlying pattern of warrantless ALPR queries that our Flock destruction coverage has tracked since the start of the year [1].

Texas and Florida Both Step Back From Flock Cameras

Two of the country's largest states took different but reinforcing actions against the same vendor within three days, and the pair is the strongest signal yet that the ALPR backlash is moving from city council chambers to governors' offices. Governor Greg Abbott banned Texas state agencies from spending public funds on Flock Safety cameras on August 28, 2026, EFF reported on September 3. The action followed a Texas Tribune investigation showing that a state agency had funneled at least $30 million in state funds into a Flock surveillance network. Abbott's order applies only to state agency spending. Cities, counties, and federal pass-through funding are not affected, and private buyers can still purchase Flock cameras directly [1].

Florida's move came three days later and reached further inside a single agency's footprint. On August 31, 2026, the Florida Department of Transportation issued bulletin eom26-01, announced publicly by Governor Ron DeSantis, ordering every ALPR removed from state highway right-of-way within 30 days, revoking prior permits, and refusing new ones. The FDOT memo cited "the recent exponential increase in deployments along our roadways, coupled with concerning reports of misuse, data privacy concerns, and surveillance schemes" as the basis for the action. The order does not reach city streets, county roads, residential driveways, or shopping-center parking lots. EFF's write-up notes that a surge of local Florida governments canceled or paused vendor contracts in the days that followed [1][2].

Read together, the two orders do not end Flock's footprint in either state. Texas affects a funding stream; Florida affects state-controlled pavement. But the political direction is the same, and the timing is short enough that it reads as a coordinated signal. For a public that has watched roughly 90,000 Flock cameras come down in city cancellations since the start of the year, the question is no longer whether the network is under pressure. It is whether the next round of restrictions reaches the local and county contracts the two orders leave untouched [1].

Cops Want Axon's ALPR to Look Less Like a Flock Camera

The second leg of the day's Flock story is the procurement response. During an August 26 Axon webinar titled "From backlash to trust," Axon Chief Customer Officer Mike Wagers asked whether the company could redesign its Outpost fixed ALPR so it did not look exactly like a Flock camera, 404 Media reported. Wagers framed the request around officer safety: cameras that look identical to the targets of recent vandalism are themselves targets. Axon CEO Rick Smith confirmed the company is considering the change, telling the audience: "We are looking at [...] do we change the general shape" [3].

Smith pointed to Axon's Lightpost, a higher-mounted unit the company says is "harder to vandalize," and suggested the more durable answer was to make the technology more visible. His framing, as 404 Media quoted it, was that explicit signage about camera location and the city policies that govern them would do more to prevent tampering than camouflage would. The redesign conversation is significant because it is the first documented case in which a major ALPR vendor has publicly tied procurement to the visual profile of a competitor's hardware, in response to an organized wave of physical attacks on that competitor's network [3].

For a reader who has been following the Flock cluster, the Axon moment is the supply-side echo of the demand-side cancellations. The same vandalism wave that helped drive the Flock camera destructions is now reshaping the look of the cameras law enforcement buys next. The outposts still read plates either way. The question for civil liberties is the same question it has been: who is in the network, who is watching, and what stops an officer from running a query that has nothing to do with a case [3][4].

Axon's Draft One AI Wrote the Report on the Flock Abortion Search

404 Media reported this week on a Johnson County, Texas sheriff's sergeant who used Axon's Draft One product, a body-camera-to-report generative AI, to draft his portion of the report on a Flock-led search for a woman who had self-administered an abortion. Sergeant Damien Bethel ran the woman's vehicle through Flock to try to locate her and her children across cities, and used TransUnion's TLO credit-header database to look up her addresses and vehicle information. He then had Draft One draft the narrative section of his report, which included the acknowledgement line: "I acknowledge this report was generated using Draft One by Axon" [4].

The AI-drafted narrative summarized deputies' legal reasoning in plain language: "Deputies discussed the legal implications of the situation, noting that while the girlfriend self-administered the abortion pill, there were no criminal charges applicable under current Texas law." The report also notes that deputies "considered the possibility of a civil lawsuit against the pharmaceutical company that supplied the pill." The supporting body-camera, in-car, and on-scene image evidence sits in AXON Evidence Library and WatchGuard Evidence Library, which the Johnson County Sheriff's Office has refused to release to 404 Media or to the Electronic Frontier Foundation [4].

The investigation was prompted by the woman's abusive partner, not by a family member or a clinic, and the officer who ran the Flock search never went to her home. His report frames the search as a welfare check, on the grounds that he feared the partner might have harmed her. 404 Media reports there is no family-driven concern in any of the underlying police documents. Flock's CEO, Garrett Langley, has continued to tell law-enforcement audiences that the search was a family-driven welfare check, a characterization 404 Media reports is not supported by the police documents. The case sits inside the same Flock abuse pattern our September 2 briefing tracked, with the new wrinkle that the narrative half of the report was written by a generative AI that read the body-camera audio and assembled a legal summary for the deputy's signature [4].

UK Cyber Bill Targets AI Users, Not the Vendors

The UK government's Cyber Security and Resilience (Network and Information Systems) Bill, proposed in the 2024 King's Speech and introduced in Parliament in November 2025, is now moving through the House of Lords with criminal liability pinned to regulated entities rather than to the companies that build the models they use. The Register reported the Lords debate on September 2. In-scope organizations, including AI users, datacenter operators, and managed service providers, would face penalties of up to £100,000 per day for failing to protect against specific cyber threats. The list of in-scope organizations is set by ministers [5].

The Lords considered three amendments to bring the model vendors themselves within scope: a duty on vendors to demonstrate their products cannot cross defined "red lines," an explicit reference to evading human oversight or aiding in chemical-weapons development as line-crossing behavior, and an emergency-shutdown power for the Secretary of State over AI systems or datacenters. All three were rejected. The Lords cited the existing AI Cyber Security Code of Practice and the Government Cyber Action Plan, both voluntary frameworks, as sufficient. Baroness Kidron was the sharpest critic on the record, arguing that "allowing tech companies to set and mark their own homework endangers the public and our national security" [5].

The surveillance reading is structural. The UK is choosing to regulate the downstream operator, the company that buys the model and runs it inside a datacenter, while leaving the upstream builder under voluntary commitments. The choice repeats a pattern the UK Online Safety Act set in the encryption debate: the regulatory hook is the entity that touches the end user, not the entity that supplies the capability. For the next round of AI-enabled harms, that is the line the Lords' amendments were trying to redraw [5].

Healthcare Cyberattacks: Pacemaker Monitoring Down, McKesson Records Alleged

The Register's August 31 healthcare roundup ties two long-running threads together. Boston Scientific disclosed an ongoing cyberattack that began August 25 and has disrupted the company's ability to process and ship orders, including the remote monitoring that lets implanted cardiac devices transmit data to clinicians. New implants cannot activate remote monitoring communicators until the systems are restored, with the exception of insertable cardiac monitors, which pair via the Clinic Assistant app. CrowdStrike is assisting the response, and The Register reports there has been no unauthorized activity seen since August 25 [6].

McKesson, the drug distributor, confirmed a separate breach after ShinyHunters claimed responsibility and posted an alleged 284 million records from McKesson's Snowflake and Salesforce instances. The claim includes full names, addresses, phone numbers, dates of birth, Social Security numbers, appointment details, illness specifics such as cancer locations, and doctor-patient emails. The entry vector, per ShinyHunters' post, was voice phishing of multiple McKesson employees. The ransom demand was $55.2 million. McKesson told The Register the Oncology and Multispecialty and Medical-Surgical business units are affected, and that distribution centers remain operational [6].

The wider healthcare pattern is the same one our prior September 1 briefing tracked on Boston Scientific's order-processing outage. Medtronic, the pacemaker manufacturer, was breached in April. Exact Sciences, a cancer diagnostics business, was hit in July, with 109 million email addresses subsequently dumped. Carhartt, a retailer, disclosed 12.9 million affected people in Have I Been Pwned, about half the number ShinyHunters initially claimed. The privacy exposure is layered: medical data combined with financial identifiers combined with contact information produces a complete identity kit, and the providers that hold it sit downstream of an attacker economy that has gotten efficient at voice phishing the same employee over and over [6].

A Legacy Lenovo Login Exposed Roughly 5,000 Dropbox Business Accounts

The Register reported on September 2 that attackers exploited a legacy single-sign-on integration between Lenovo and Dropbox to reach roughly 5,000 Dropbox business accounts. The flaw was in Lenovo's email verification flow: attackers registered new Lenovo IDs using the email addresses of Dropbox users, then used those IDs to log in to the linked Dropbox accounts without ever entering a Dropbox password. The compromise window ran from August 4 to August 21 [7].

The scale is narrower than the healthcare story, but the mechanism is the same template: an old SSO trust becomes a side door. Fewer than a third of the affected accounts had files actually accessed, and none of the affected accounts had two-factor authentication enabled. Dropbox expired all sessions logged in through Lenovo IDs, severed the account-link integration, and urged affected users to reset Dropbox and personal email passwords and turn on 2FA. Lenovo told Reuters its own customers were unaffected and that its investigation was ongoing [7].

The surveillance angle is the identity layer. The legacy integration tied a corporate SSO to a separate vendor's identity system, and the email verification step was the only thing standing between an attacker and the linked account. When the verification step is "we trust whatever email you give us," the link is only as strong as the weakest identity provider in the chain. For any organization running a similar SSO mesh, the Lenovo-Dropbox incident is the case study to put in front of whoever owns the integration list [7].

What to Watch

Whether Texas or Florida follows up with broader orders. Abbott's ban is on state agency funds; FDOT's order is on state highway right-of-way. Both leave local and county contracts untouched. Watch for county-level resolutions, attorney-general letters, or legislative hearings that try to extend either action [1].

The Johnson County evidence release. EFF and 404 Media have both asked for the body-camera and on-scene image evidence that sits in Axon Evidence Library and WatchGuard Evidence Library. The next signal is whether the sheriff's office releases any portion of the file, and on what legal theory [4].

The Axon redesign timeline. Rick Smith said the company is "looking at" changing the shape of the Outpost. The first published design change, and the first order from a department that cites the redesign as a procurement reason, is the inflection point [3].

Boston Scientific's restoration. The Register's reporting says no unauthorized activity has been seen since August 25. Watch the next 8-K and the company's earnings call for an operational update on order processing and remote-monitoring reactivation [6].

The McKesson data exposure. ShinyHunters posted the alleged 284 million records with a $55.2 million demand. Watch whether the data appears on a leak site, whether McKesson confirms the figure, and whether the patient-data exposure triggers HIPAA enforcement actions beyond the breach disclosure [6].

The UK CSR Bill in the Commons. Lords amendments on vendor liability, "red line" assurances, and emergency shutdown were rejected. Watch whether any of those provisions reappear in the Commons round, and how the Government responds to Baroness Kidron's "mark their own homework" line [5].

Sources

  1. Electronic Frontier Foundation, Deeplinks, Rindala Alajaji and Adam Schwartz: Texas and Florida Step Back from ALPRs (September 3, 2026; the August 28 Abbott order, the $30 million Texas Tribune figure, the August 31 FDOT bulletin eom26-01, the DeSantis announcement, the FDOT reasoning language, and the local-cancellation aftermath). https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs
  2. State of Surveillance: Flock Cameras Destroyed Nationwide in ICE Backlash (the standing coverage of the cancel wave and the warrant-requirement debate that the new Texas and Florida actions extend). /news/flock-cameras-destroyed-nationwide-ice-backlash-2026
  3. 404 Media, Joseph Cox: Cops Are Asking Axon to Make Their Cameras Look Different From Flock So People Don't Destroy Them (September 2026; the August 26 "From backlash to trust" webinar, Mike Wagers's redesign request, Rick Smith's "do we change the general shape" quote, and the Lightpost comparison). https://www.404media.co/cops-are-asking-axon-to-make-their-cameras-look-different-from-flock-so-people-dont-destroy-them/
  4. 404 Media, Jason Koebler: Texas Police Used AI to Write Report About Using Flock to Search for Woman Who Had Abortion (September 2026; the Johnson County Sheriff's Office investigation, Sergeant Damien Bethel's Flock and TLO queries, the Draft One acknowledgement line, the "legal implications" summary, and the AXON Evidence Library / WatchGuard Evidence Library refusal). https://www.404media.co/texas-police-used-ai-to-write-report-about-using-flock-to-search-for-woman-who-had-abortion/
  5. The Register: UK cyber bill targets AI users, not the vendors building the models (September 2, 2026; the CSR Bill introduction date, the £100,000 daily fine, the three rejected Lords amendments, the voluntary AI Cyber Security Code of Practice, and Baroness Kidron's "mark their own homework" quote). https://www.theregister.com/security/2026/09/02/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it/5293738
  6. The Register, Jessica Lyons: Healthcare cyberattacks hit pacemakers and millions of patient records (August 31, 2026; the Boston Scientific cardiac-device remote-monitoring outage, the McKesson breach, ShinyHunters' 284 million records and $55.2 million demand, the Oncology and Multispecialty and Medical-Surgical units, the Medtronic and Exact Sciences references, and the Carhartt Have I Been Pwned figure). https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537
  7. The Register: Legacy Lenovo login opens 5,000 Dropbox accounts to attackers (September 2, 2026; the August 4 to August 21 compromise window, the Lenovo email-verification flaw, the 2FA absence, Dropbox's session expiration and integration severance, and the Lenovo statement to Reuters). https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924