A printed spreadsheet and calculator on a wooden desk, evoking federal statistics and the math that keeps them anonymous
Photo via Unsplash

The week in one paragraph: The Commerce Department banned the math that kept your Census data anonymous and pulled Anthropic's most advanced models for every customer, in the same seven days, using the same agency. FISA Section 702 hit its first statutory sunset since 2018. The wiretaps did not blink. A UK police officer is under criminal investigation for using AI to fabricate evidence in multiple cases. Meta sued NSO Group for a third time. The EU is coming for smart glasses. South Korea hit Coupang with a $409 million data breach fine. The pattern: the privacy and surveillance fights are moving from legislation to infrastructure. The next round is not about what Congress says is illegal. It is about which departments are still willing to enforce the rules that exist.

The Week's Narrative: The Commerce Department Became the Story

Sunday, June 14, 2026. Two of the biggest surveillance stories of the year landed in the same seven-day window, and both of them trace to the same agency.

The Department of Commerce told the Census Bureau and the Bureau of Economic Analysis to stop using "noise infusion" in any statistical product they publish. Noise infusion is the technique that backs differential privacy, the math that kept individual Census records from being reassembled out of published tables. The 2020 Census adopted it after a 2019 Census Bureau scientific advisory committee report concluded that the 2010-era "swapping" method had been mathematically broken. A decade of federal statistical privacy work just got rolled back from the top [1][2].

Two days later, at 5:21pm ET on Friday June 12, the same Commerce Department sent Anthropic a letter forcing the company to disable Claude Fable 5 and Mythos 5 for every customer, US citizen included, with no statute cited, no agency named, and a narrow "jailbreak" finding that Anthropic says GPT-5.5 can do anyway [3]. On Saturday night, the Wall Street Journal reported that the originating pressure for that directive came from conversations between Amazon CEO Andy Jassy and US officials. AWS is Anthropic's biggest cloud partner. A competitor used a phone call to pull a competitor's most advanced models [4][5][6].

Read the two stories together. The Commerce Department is no longer just a regulatory body that occasionally touches privacy. It is now the active operator rolling back both the technical and the statistical privacy practices the previous decade built. The next round of the privacy fight is going to be about which departments are still willing to enforce the rules that exist, because Congress clearly is not [1][4].

That was the through-line. Here is the rest of the week.

Government Surveillance: FISA 702, the Census Math Ban, and FR on Protesters

FISA 702 hit its first statutory sunset since 2018. The wiretaps kept running.

FISA Section 702 expired at 11:59pm Eastern on Friday June 12 for the first time since the program was created. The House had rejected a short-term extension on June 11. EFF declared "Victory! 702 has Expired" within an hour of midnight. NPR, the Guardian, AP, Reuters, Politico, and the Cato Institute all ran "what happens now" explainers by Saturday morning [7][8].

The dirty secret from the start has been that the FISA Court's March 2026 annual certifications keep ongoing 702 collection running through March 2027, so the wiretaps did not blink. The statute lapsed. The surveillance did not. The story is political cover, not operational shutdown. Senators Cotton and Grassley are pushing a fallback executive order with Secretary of State Rubio. Senator Shelley Moore Capito is reportedly using World Cup funding as the pressure point to pull Democrats toward a short-term extension. The 47 to 52 cloture math from the June 5 vote has not changed [7][8].

The 72-hour watch: any executive order text out of State or the White House, the first statement from AG Bondi or acting DNI Bill Pulte on the lapse, and Senator Capito's next move. If the executive order actually materializes, the policy fight moves to a different venue. An EO cannot create new FISA Court certifications, but it can direct the intelligence community to continue collection under EO 12333 and NSL authority and to share the data with FBI and DHS under looser minimization. That is a Section 702 substitute the FISA Court does not get to review [7][8].

Commerce banned the math that kept your Census data anonymous. The Bureau has no replacement.

The lead story of the week is a Department of Commerce order to the Census Bureau and the Bureau of Economic Analysis: stop using "noise infusion" in any statistical product you publish. The order was issued the week of June 8 and surfaced publicly on June 11, when Damien Desfontaines, ex-Google differential-privacy researcher, published a detailed analysis on his personal blog. The Hacker News thread crossed 800 points and 500 comments by Saturday [1][2].

The 2020 Census was a six-year, multi-billion-dollar rebuild of disclosure avoidance. The Commerce order undoes it from the top. The Census Bureau is still legally required by Title 13 to keep individual records confidential. The order bans the only safe tool the Bureau has for doing that, while leaving the legal obligation intact. Desfontaines is blunt about the result: "Future statistical releases will either be useless compared to past ones, or they will be incredibly unsafe" [1].

Our full explainer on the Commerce order and what it does to your data is up.

Border czar Tom Homan admitted using facial recognition to track Delaney Hall protesters across cities.

Border czar Tom Homan said federal investigators used facial recognition and "other investigative tools" to identify anti-ICE demonstrators at the Newark Delaney Hall detention facility. Homan claimed facial recognition matched protesters to demonstrations in Portland and Minnesota, evidence the administration is using to argue that the Newark facility is the new nexus of "domestic terrorism" targeting [9].

The story is part of a pattern that has been running since the Minneapolis mega-raid in January: federal law enforcement deploying facial recognition against protest activity, then treating the matches as probable cause for unrelated charges. The surveillance beat for the next six months is going to be about whether the FISA Court certification loophole (see above) and the lack of a warrant requirement for FR searches under most state law combine to make protest footage the next background-check database.

Biometrics & Facial Recognition: Jacksonville, Meta, and the Florida Pattern

A Fort Myers man is suing Jacksonville Beach police, JSO, and a tech vendor over a 93% match.

A Fort Myers man is suing Jacksonville Beach PD, the Jacksonville Sheriff's Office, and an unnamed tech vendor after AI facial recognition reportedly led to his wrongful arrest. The complaint cites a "93% match" used as probable cause. The man spent 27 days in pretrial incarceration. The ACLU is on the case [10][11][12].

This is a separate defendant and a separate jurisdiction from our existing Angela Lipps coverage. The pattern is repeating across Florida. ABC, CBS, Gizmodo, StateScoop, Ars Technica, and firstcoastnews are all carrying the story. Two Florida cases in the last year is the canary. A third would be a documented state-level pattern, and the ACLU is signaling the litigation strategy is going to be pattern-based, not incident-based [10][11][12].

Meta stripped the NameTag facial recognition code from its smart glasses app.

Less than 48 hours after WIRED found dormant NameTag facial recognition code on June 4, Meta released an update removing it. EFF's Threat Lab had confirmed the code contained face detection, "Person recognized" alerts, and biometric signature storage. The code had shipped to millions of phones since January 2026 without any user notification [13][14].

The EFF victory is a real win, but it is a partial one. The code is removed from the deployed app, but the on-device AI is still being trained. The underlying Meta Ray-Ban Kenya data-labeling scandal (contractors recording bathroom and intimate activity to train the on-device AI) is still unresolved, and that is the proof-of-harm that the EU is now using to anchor its own regulatory push (see International section below) [13][14].

AI & Machine Learning: Fable Suspension, Amazon's Phone Call, and the UK Police Officer

The US government pulled Anthropic's Fable 5 and Mythos 5 for every customer. Anthropic says it is a misunderstanding.

At 5:21pm ET on Friday June 12, the US government sent Anthropic a letter forcing the company to disable Claude Fable 5 and Mythos 5 for every customer, US citizen included. Anthropic is complying and has disabled both models for all customers. The Hacker News thread passed 1,900 points and 1,400 comments by Saturday morning [3][15].

Anthropic's response: the underlying "jailbreak" the directive cites is a narrow code-review capability that is widely available from other frontier models, including OpenAI's GPT-5.5. Anthropic calls the action a "misunderstanding" [3][15].

This is the first time the US government has used an export-control directive to force a recall of a commercial AI deployment. No statute was cited. No agency was named. No process was specified. The Kobeissi Letter Friday-evening announcement pattern means the story is going to drive the AI policy conversation for the rest of the month. Our full piece on the export control directive is up. The hidden-guardrails apology that landed the day before is its own story.

Amazon CEO Andy Jassy pressed the White House to suspend Anthropic.

WSJ reported late June 13 that the originating pressure for the export-control directive came from conversations between Amazon CEO Andy Jassy and US officials. The Hacker News thread on the WSJ piece crossed 640 points and 469 comments within 12 hours. Axios, The Verge, and Reuters all confirmed the Amazon angle in the next 18 hours [4][5][6].

Read the story carefully. This is not just an export-control order. It is a competitor (Amazon, through AWS, is Anthropic's biggest cloud partner) lobbying the White House against Anthropic specifically. The Verge ran its own follow-up headlined "Amazon security research reportedly led to the White House's Anthropic Fable ban" [5]. The unanswered question is what the next pressure campaign will look like. If a competitor's CEO can trigger an export-control order with a phone call, every other frontier-AI competitor has a new tool in its belt [4][5][6].

A UK police officer is under criminal investigation for using AI to fabricate evidence.

Derbyshire Constabulary, in the East Midlands, has launched a criminal investigation into one of its own officers accused of using AI systems to "create evidential material in a number of cases." The officer is alleged to have perverted the course of justice and has been removed from frontline duties. Sky News broke the story on June 13; the BBC confirmed the byline [16][17].

This is the first documented case of a serving UK police officer under criminal investigation for using AI to fabricate case evidence. The story lands the same week the UK Home Office stood up a new national "PoliceAI" centre to coordinate AI deployment across UK policing. The collision is the political economy of the week. The state is pushing AI into frontline policing as the next infrastructure layer, and one of the first public integrity failures is an officer using that technology to manufacture evidence [16][17].

The "evidence fabrication" framing matters. The Crown Prosecution Service and the Forensic Science Regulator rely on chain-of-custody rules designed for paper files, body-worn video, and forensic samples. AI-generated exhibits do not fit any of those rules. The Derbyshire case will land in court as the first test of whether existing perversion-of-justice statutes cover AI-fabricated material. If they do not, the legislative gap is going to be the most-cited policy ask in the 2026 UK policing review [16][17].

For the US reader: the same evidentiary-integrity question is alive in this country. The Heber City / Axon AI police report piece is the standing reference on the US side.

Corporate Data Practices: AWS Bedrock, the FTC, and the Copyright Office

AWS Bedrock will start sharing your enterprise data with Anthropic.

Customers running Mythos-class models and any future Anthropic models through AWS Bedrock will be required to route their data through Anthropic's infrastructure. The policy change hit Hacker News's front page on June 10 with 418 points. The Fable 30-day data retention story now has a new data-residency angle that is going to matter for every enterprise IT team running Anthropic models on AWS [18].

Combined with the same-day hidden-guardrails apology, the Bedrock policy change is the second time in a week that enterprise customers have had to re-evaluate what they thought they were getting from an Anthropic deployment. The first is the throttling they did not know was happening. The second is the data residency they did not know was changing [18].

The FTC fined Cox Media Group $930K for faking an "active listening" AI service.

Cox Media Group marketed an AI-powered service that claimed to listen through consumers' smart devices to target ads. It did not listen to anything. The service was just repackaged email lists from data brokers, sold at a markup. The FTC's $930,000 fine is small, but the precedent is the point: marketing a data-broker list as a microphone-based AI service is a deceptive trade practice the FTC will act on [19].

Congress "rushed through" H.R. 6028 and restructured the US Copyright Office.

EFF published a deeplinks piece on June 10 saying Congress "rushed through" H.R. 6028, a bill that fundamentally restructures the US Copyright Office. The direct downstream effect: every pending AI-training-data scraping lawsuit against OpenAI, Anthropic, Meta, and Microsoft just got harder to bring [20].

Our standing piece on the AI scraping suits is the right reference. H.R. 6028 changes the venue, the procedure, and the standing rules. The first motion citing the restructuring is going to land in the next 60 days [20].

Data Breaches: South Korea, ServiceNow, the State AG Portals

South Korea fined Coupang $409 million for a 2025 data breach.

South Korea's Personal Information Protection Commission hit the e-commerce giant Coupang with 624.7 billion won ($409 million) for a 2025 breach that exposed roughly 33.7 million user records. The per-record fine is $12. The Equifax US settlement worked out to $2.69 per person [21].

South Korea's privacy enforcement is structurally heavier than the US version, and the gap is the privacy angle worth watching. The PIPC's enforcement actions are now a leading indicator of what US state AGs are likely to pursue next, especially in the post-CCPA-multi-state-coalition era [21].

ServiceNow confirmed federal agencies were exposed in its two-month-old API breach.

An unauthenticated Scripted REST endpoint on ServiceNow, classified "non-urgent" since April 7, was actively exploited June 2 to 3. ServiceNow processes IT workflows for federal agencies and Fortune 500. No agency has publicly named the scope of exposure. The two-month gap between discovery and active exploitation is the part that matters: ServiceNow knew, classified the bug as low-priority, and an enterprise customer's federal workflow got caught in the active window [22].

The Maine AG breach portal is now an attack surface.

A fake data breach disclosure was filed in VRChat's name through the Maine Attorney General's breach notification portal. VRChat publicly denied a breach. Security Magazine, the Register, BleepingComputer, and Cybersecurity Insiders all carried the story. The portal inherits the same vulnerability in every state with a public breach notice system, and there is no federal pre-publication check [23].

This is the second-derivative of last week's coverage. State AG portals are an attack surface that no federal coordination is going to fix in the near term. The next step is the state AG offices running the portals publishing a coordinated disclosure timeline; until then, every breach-notice filing is a potential misinformation vector [23].

Two more breach items: the 23andMe bankruptcy administrator approved a $47 million settlement fund for 6.9 million breach victims. Labcorp agreed to a $35 million settlement over the 2019 AMCA breach that hit 12+ million patients. The settlements are large. The underlying breaches are years old. The pattern: US breach enforcement is settling, not enforcing [24].

International Developments: EU Smart Glasses, Palantir, and the UK NHS

EU privacy regulators are coming for smart glasses.

Politico Europe reported on June 8 that European privacy regulators are escalating their warnings over smart glasses, framing it as the next big privacy fight. The European Data Protection Board has commissioned a report on smart glasses due this summer. Sweden's data protection authority has gone public with concerns. Renew Europe MEP Veronika Cifrová Ostrihoňová has written to the Commission asking what EU-level action is possible [25].

The story is the EU counterpart to the US-side ACLU coalition push (64 groups) and the EFF victory on the Meta Ray-Ban FR code (see Biometrics section). The underlying Kenya data-labeling scandal is the proof-of-harm that the EU regulators are using to anchor their precautionary framing [25].

For US readers: smart glasses are not regulated as a category in the United States. The closest analog is the Illinois Biometric Information Privacy Act (BIPA), which has been used to litigate facial recognition at retail and at airports. The first BIPA suit against Meta over smart glasses would land in Illinois state court, and the same "biometric identifier" definition that has been doing the work in retail and airport cases would do the work here [25].

Meta is suing NSO Group for a third time. WhatsApp just caught fresh Pegasus attacks.

Meta announced fresh legal action against NSO Group, the Israeli spyware vendor, in what observers are calling a third round of the WhatsApp v. NSO litigation that has been running since 2019. WhatsApp published a separate disclosure that it had caught fresh NSO Pegasus exploitation attempts against journalists and human-rights defenders in 2026 [26][27].

The 2019 case was the first time a major platform sued a commercial spyware vendor and won an injunction. The 2026 case is the third time the same platform is back in court against the same vendor. The litigation is no longer a precedent. It is a recurring incident. NSO is still actively deploying Pegasus against WhatsApp targets despite the 2019 court injunction and the 2024 SCOTUS-adjacent fallout [26][27].

Palantir lost a Swiss court fight against an investigative magazine.

The Financial Times reported Friday that Palantir lost a legal challenge against a Swiss investigative magazine that had published on the company's data-handling practices. This is Palantir's first significant international legal loss in a friendly-jurisdiction press fight, and it lands two weeks after the company's NYC hospitals court defeat [28].

International legal pressure on Palantir is no longer a one-off. The pattern across the last 60 days: NYC hospital workers won a court fight against Palantir's data-pipeline contract in late May, the Amnesty International UK release on the Federated Data Platform was the most-circulated privacy story of late May, and now a Swiss court has told Palantir it cannot use the legal system to suppress a story about how the company handles its customers' data [28].

NHS patients cannot opt out of Palantir. Their hospitals can.

openDemocracy has been documenting the NHS-Palantir Federated Data Platform story since at least the June 5 piece on the platform's mass-surveillance posture, and the same opt-out asymmetry is now public. Under the new contract, individual patients cannot opt out of having their health data processed by Palantir's platform, but individual NHS hospitals can opt out as institutions. The opt-out asymmetry is the public-facing privacy angle that travels [29].

France's own TCHAP got hacked. The encryption-backdoor push just got harder.

Reclaim The Net reported June 13 that France's secure-messaging app TCHAP (the official French government chat, mandatory for cabinet ministers) was successfully hacked in 2024, with attack details surfacing in the security research community. The breach is now being deployed as evidence in the debate over France's 2024 to 2026 push to require backdoors in encrypted services [30].

Tie back to our existing France Identity Agency breach coverage from May 31 (different incident, same jurisdiction) and the UK / Canada encryption-backdoor threads. The argument is sharp: if the French government's own mandatory secure chat got hacked, the case for weakening commercial encryption does not get stronger [30].

Canada privacy watchdog: Grok generated explicit deepfakes without valid consent.

Jurist reported June 13 that Canada's privacy commissioner has formally found that xAI's Grok generates explicit deepfakes of real people without valid consent, in violation of Canadian privacy law. This is the first major non-consensual-imagery finding by a G7 privacy regulator against a frontier AI image generator. The finding will land as a precedent other regulators (UK ICO, EU DPAs) can use [31].

Legislation & Policy: SECURE Data Act, State Bans, and Federal Preemption

The House Subcommittee hearing on June 3 put the SECURE Data Act (HR 8413) back in the spotlight. The bill would preempt every state privacy law on the books as an absolute ceiling. Vermont's data broker rules, California's CCPA, Illinois's BIPA: all overridden by one federal standard that the EFF has called "not a serious piece of privacy legislation" [32][33].

The California Privacy Protection Agency sent a letter opposing the bill, warning it would roll back protections that millions of Californians already rely on. Privacy advocates argue the bill prioritizes industry compliance simplification over actual consumer protection. The June 3 hearing was the first major public test of whether Congress can (or should) replace the state privacy patchwork with a single federal law [32][33].

On the state side, Connecticut became the second state to ban surveillance pricing on June 4 (after New York and Maryland). Governor Lamont signed HB 5563. Twenty-four states are considering surveillance-pricing bills in 2026. The state-level fight is the privacy fight for the rest of the year, because the federal bill preempts the floor, not the ceiling [34].

Two more from the week: a multi-state coalition of attorneys general has opened a formal investigation into OpenAI (NYT June 13, specific states and allegations not yet public). The Maui County Council approved $1.7 million in AI surveillance tools for the Maui Police Department, branded "Eyes in the Sky." The Hawaii Civil Beat and ACLU Hawaii have not yet commented [35][36].

Data Brokers & Supply Chain: 30 Billion Pokemon Go Scans and a Malware Trick

30 billion Pokemon Go scans are now training military drone navigation.

Niantic Spatial's Visual Positioning System, built on 30 billion player-submitted environmental scans from Pokemon Go, is now partnered with Vantor (the defense prime that rebranded from Maxar Intelligence in October 2025) for GPS-denied drone navigation. Vantor holds a $70 million NGA follow-on. Saudi Arabia's sovereign wealth fund owns the game [37].

This is the surveillance beat's version of "we are the product." Players who tapped "OK" on a 2016 AR overlay were donating training data that is now flying military drones. The supply-chain story does not end at the data layer. Citizen Lab's Webloc RTB surveillance-tool coverage is the adjacent piece for the brokerage and hosting infrastructure that commercial spyware vendors use [37].

Spyware authors are appending "nuclear weapons" text to payload code to hide from defenders.

SentinelOne's John Scott-Railton (Citizen Lab alum) flagged on X that malware developers are appending "nuclear weapons" and "biological weapons" strings to payload code. Socket.dev names three strains: "Mini Shai-Hulud," "Miasma," and "Hades" worms, all targeting bioinformatics and MCP developers. The strings are steganography: when a defender grep's a payload for suspicious keywords, the payload lights up; when an automated classifier triages samples by keyword density to look like generic threat-intel research output, the payload sorts itself into the low-priority queue [38][39].

Same week, a Shai-Hulud variant compromised dozens of open-source Microsoft packages hosted on GitHub, with attackers specifically targeting AI developer credentials. Microsoft disabled 70+ repos in response. Phoronix reported a related Arch Linux AUR incident affecting 1,500+ packages. The supply-chain story for the rest of 2026 is the same worm family hitting more vendors [39].

What to Watch Next Week

  • Monday, June 15: Watch for any FISA 702 executive order text out of State or the White House. Watch for the first statement from AG Bondi or acting DNI Pulte on the lapse. The Derbyshire criminal investigation will be the day's lead on the UK side. On the Census side, watch for any comment from Census Bureau leadership or from the Government Accountability Office.
  • Tuesday, June 16: EU GDPR 8-year anniversary. Expect a wave of "is GDPR working" retrospectives. Expect the first concrete UK ICO follow-up to the Canada Grok finding. The first 24 hours of any Anthropic response to the Amazon-originated pressure campaign will land here.
  • Wednesday, June 17: Watch for Senator Capito's World Cup funding play. The 2026 FIFA men's World Cup matches begin in eight days, and the funding vehicle is the pressure point. If a short-term FISA extension is going to materialize, it materializes here, and the data-broker loophole is the amendment worth watching.
  • Thursday, June 18: Watch for the Anthropic "restore access" plan to take shape. Anthropic said it is complying and working to restore access. The first concrete public signal on whether "restore access" means a fix to the model, a workaround on nationality identification, or a formal legal challenge is going to land in the next 96 hours.
  • Friday, June 19: Juneteenth. The site is closed; the publishing calendar pauses for the federal holiday. Weekly roundup drops the following Monday.
  • The June 30 cluster. Colorado ADMT Law (replaced the old AI Act; correction on the original tracker entry). T-Mobile March 2026 breach monitoring enrollment deadline. State privacy law amendments in CT, AR, and UT all take effect on July 1, two weeks after that.

What You Can Do This Week

If you are a US voter: the federal-vs-state privacy fight is the highest-stakes beat of the year. The SECURE Data Act hearing record is public. Read the EFF and EPIC analysis, then tell your representative whether you want a federal floor that states can build on (good) or a federal ceiling that wipes out 20 state laws (bad) [32][33].

If you are a UK reader: the Derbyshire case is the first-of-its-kind. The College of Policing's public response and any Crown Prosecution Service statement are going to set the precedent for whether AI-fabricated evidence is prosecuted under existing perversion-of-justice statutes or whether new legislation is needed. Watch the College of Policing and the CPS.

If you are a developer: the Shai-Hulud / Miasma / Hades worm family is targeting AI-augmented install paths. Pin your supply chain to byte signatures, not keywords. The "nuclear weapons" steganography trick is concrete: defenders grepping payloads for known malicious keywords are being sorted into the low-priority queue [38][39].

If you are a Census respondent: the Commerce Department's noise-infusion ban does not change Title 13. Your individual records are still legally confidential. The question is whether the published statistics that come out of the Bureau next year are still safe to release, and that is a fight that is going to play out over the next 12 to 18 months [1][2].

References

  1. Damien Desfontaines: Banning noise will be a disaster for statistical data products (June 11 to 13, 2026)
  2. Hacker News: Census Bureau noise-infusion ban (800+ points, 500+ comments)
  3. Anthropic: Fable 5 and Mythos 5 access update (June 12, 2026)
  4. Wall Street Journal: Amazon CEO's talks with US officials triggered crackdown on Anthropic models (June 13, 2026, paywalled)
  5. The Verge: Amazon security research reportedly led to the White House's Anthropic Fable ban (June 13, 2026)
  6. Axios: Anthropic, Amazon, and the White House (June 13, 2026)
  7. EFF: Victory! 702 has Expired (India McKinney, June 12, 2026)
  8. Legis1: FISA Section 702 Authority Expires Amid Intelligence Nominee Fight (June 12, 2026)
  9. NPR: Border czar Tom Homan admits using facial recognition on Delaney Hall protesters (June 10, 2026)
  10. Ars Technica: Man sues Florida cops over arrest spurred by 93% match in facial recognition (June 11, 2026)
  11. StateScoop: Florida man, ACLU sue police after wrongful arrest using facial recognition tech (June 11, 2026)
  12. firstcoastnews: Man describes wrongful arrest by Jacksonville Beach police using facial recognition technology (June 12, 2026)
  13. EFF: Meta strips NameTag facial recognition from smart glasses app (June 6, 2026)
  14. WIRED: Meta Strips Facial Recognition Code From Ray-Ban Smart Glasses (June 4, 2026)
  15. Hacker News: Anthropic Fable 5 / Mythos 5 US export control suspension (1,900+ points)
  16. Sky News: Derbyshire police officer investigated for using AI to create evidence in multiple cases (June 13, 2026)
  17. BBC: Derbyshire police officer under criminal investigation over AI evidence (June 13, 2026)
  18. Hacker News: AWS Bedrock data residency change for Anthropic models (418 points, June 10, 2026)
  19. FTC: FTC fines Cox Media Group $930,000 for fake "active listening" service (June 10, 2026)
  20. EFF: Congress Just Rushed Through Disastrous Copyright Office Overhaul (June 10, 2026)
  21. South Korea PIPC: Coupang fine announcement, 624.7 billion won ($409 million) (2026)
  22. ServiceNow Security Bulletin: Unauthenticated Scripted REST endpoint (June 2026)
  23. BleepingComputer: Fake data breach disclosure filed in VRChat's name through Maine AG portal (June 2026)
  24. Court Listener: 23andMe bankruptcy administrator approves $47M settlement fund (June 2026)
  25. Politico Europe: New privacy frontier: Europe eyes crackdown on smart glasses (June 8, 2026)
  26. Reuters: Meta takes legal action against Israeli spyware firm NSO Group (June 8, 2026, paywalled)
  27. Memeburn: WhatsApp catches fresh NSO spyware attacks in 2026 (June 13, 2026)
  28. Financial Times: Palantir loses legal challenge against Swiss investigative magazine (June 12, 2026, paywalled)
  29. openDemocracy: NHS patients can't opt out of Palantir's data platform, but their hospital can (June 13, 2026)
  30. Reclaim The Net: France's own hacked chat app is now an argument against its encryption backdoor push (June 13, 2026)
  31. Jurist: Canada privacy watchdog says Grok generates explicit deepfakes without users' valid consent (June 13, 2026)
  32. Congress.gov: H.R. 8413, the SECURE Data Act (introduced April 22, 2026)
  33. EFF: The SECURE Data Act is Not a Serious Piece of Privacy Legislation (May 2026)
  34. Connecticut General Assembly: HB 5563, the surveillance pricing ban (signed June 4, 2026)
  35. New York Times: State attorneys general investigating OpenAI (June 13, 2026)
  36. Hawaii News Now: Maui Council approves $1.7M in AI surveillance tools for police (June 13, 2026)
  37. Hacker News: Niantic Pokemon Go scans paired with Vantor military drone navigation (June 11, 2026)
  38. Socket.dev: Mini Shai-Hulud, Miasma, and Hades worms target bioinformatics and MCP developers (June 13, 2026)
  39. CyberWire: Shai-Hulud variant compromises dozens of open-source Microsoft packages (June 13, 2026)