Privacy
Privacy Pulse: EU-US Data Deal Shaken, China Regulates AI Companions, UK Warns on Kids' Images
Noyb challenges EU-US data framework after Supreme Court ruling; China's AI companion law takes effect; UK agencies urge parents to stop sharing kids' photos.
UK Agencies Warn Parents Not to Publicly Share Children’s Images Over AI Abuse Risks
The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) have warned parents against publicly posting images of their children online, citing the growth of AI-generated child sexual abuse material. The IWF identified more than 8,000 AI-generated images and videos of realistic child sexual abuse in 2025 — a 14% increase — and found that AI-generated videos rose from 13 in 2024 to 3,440 in 2025. The agencies released fresh guidance urging parents to review privacy settings, revisit image consent with friends and schools, and involve children in discussions about image sharing. The guidance follows years of warnings about “sharenting,” and the UK government has banned nudification apps and amended laws to curb AI-generated CSAM.
Parents warned not to publicly share children’s images amid AI abuse risks - BBC News →
India Orders Apple and Google to Remove Seven Chinese Battery Management Apps
The Indian government ordered Apple and Google to remove seven Chinese battery management apps — including BAT-BMS, Lossigy, and Epoch-i-ion — after they were used to remotely disable battery-operated vehicles like e-rickshaws. The Ministry of Electronics and Information Technology (MeitY) acted following videos showing users stopping e-rickshaws via Bluetooth-enabled battery systems, leaving drivers stranded. MeitY secretary S Krishnan confirmed the takedown. Officials said the apps monitor battery parameters and, on poorly secured systems, can cut power supply. The order is the first to address data security and remote interference linked to vehicle devices.
Govt orders Apple, Google to remove 7 Chinese apps →
Data Protection Rules Delay or Block 11% of LLM Releases in Europe, Study Finds
A study by the Center for the Governance of AI (GovAI) examined 375 large language models released between June 2018 and May 2026 and found that at least 11% were delayed or not released in the EU, and 7% in the UK, compared to the US. Among 68 documented cases, regulatory factors — primarily data protection laws — were the main cause in 56 instances. Meta had the highest rate: 26% of its models were delayed or withheld in the EU and 15% in the UK. Claude 3 Opus faced a 71-day delay for its EU web app release. The study notes that while the UK and EU share similar GDPR laws, the EU’s more aggressive enforcement and slow clarification of rules creates larger barriers. The EU is considering a Digital Omnibus to ease rules, but also reviewing copyright provisions that could further restrict AI access.
Data protection rules slow LLM rollout in Europe, study says →
Privacy Group Noyb Challenges EU-US Data Privacy Framework After Supreme Court Ruling
Privacy advocacy group noyb announced plans to challenge the EU-US Data Privacy Framework following a U.S. Supreme Court ruling in Trump v. Slaughter. In a letter to the European Commission on June 30, noyb founder Max Schrems argued that the ruling undermines the independence of agencies like the Federal Trade Commission, which the European Commission relied upon as the primary U.S. regulator for the framework. The framework, adopted in 2023, allows certified U.S. companies to receive personal data from the EU under an adequacy decision. Noyb contends that if the FTC is no longer constitutionally independent, the legal foundation of the decision may not meet EU requirements. The challenge does not immediately suspend data flows; the adequacy decision remains in force unless repealed or annulled by the Court of Justice. Noyb has urged the Commission to plan an orderly transition and intends to file a formal lawsuit if no action is taken.
EU-US Data Privacy Framework Under Threat After Supreme Court Ruling →
Alibaba Bans Claude Code After Anthropic Caught Tracking Chinese Users With Hidden Code
Alibaba banned its employees from using Anthropic’s Claude Code after researchers discovered obfuscated code that silently identified Chinese users. The ban, effective July 10, followed weeks of conflict over allegations that Alibaba stole Anthropic’s AI capabilities through distillation. A Reddit user reverse-engineered Claude Code and found code checking for Chinese timezones and proxy URLs, using steganography to hide signals in system prompts. Anthropic engineer Thariq Shihipar called it an experiment to prevent abuse and said the tracking was removed on July 1. The incident raises cross-border data compliance concerns, as Claude Code requires deep file system access. Lizzi Lee of the Asia Society noted that the conflict reflects a shift from technology competition to access control and sovereignty.
Alibaba bans Claude Code after Anthropic is caught tracking Chinese users with hidden code →
France to Replace Palantir’s AI Tools With Domestic Provider ChapsVision
Prime Minister Sébastien Lecornu announced that France’s domestic intelligence service, the DGSI, will replace Palantir’s AI data tools with those from French firm ChapsVision. Lecornu cited the need to avoid strategic dependency on foreign technology, stating that France must build real autonomy and not rely on partners who could cut off access. Because Palantir’s contract was renewed in 2025, the transition will take several years. ChapsVision, founded in 2019, reported €200 million in revenue in 2025, compared to Palantir’s $4.5 billion. Its technology has also been selected by Germany’s BfV internal security service. Palantir said it will continue to support the French government where needed. The move reflects growing European concern about reliance on US-controlled tech, especially after Washington restricted access to Anthropic’s latest model.
France to ditch Palantir’s AI data tools in favour of domestic provider | France | The Guardian →
China’s First AI Companion Law Takes Effect July 15, Forcing Doubao and Qwen to Delete Agent Data
On July 15, 2026, China’s Interim Measures for the Administration of AI Anthropomorphic Interactive Services will take effect, regulating AI services that simulate human personality. The regulation, co-issued by five government bodies, requires dynamic anti-addiction prompts after two hours of interaction, instant-exit mechanisms, real-time detection of over-dependence, and mandatory usage notifications. Both ByteDance’s Doubao and Alibaba’s Qwen are pulling their agent features because their architectures could not meet compliance in time. Doubao users will have read-only access until October 15, after which data will be processed per the privacy policy. Qwen will permanently delete agent configurations and chat histories with no migration path. ByteDance is redirecting users to Maoxiang, a new app for creating agents. The measures also prohibit virtual intimate relationships for users under 14 without parental consent.
China AI Companion Law Arrives July 15: Doubao and Qwen Agent Data Will Be Deleted →
Telegram’s Anonymity Fuels Privacy, Piracy, and Pornography Concerns
Telegram’s strong anonymity features, including hidden identities behind usernames and lack of metadata tracking, have made it a platform of choice for scammers, paper leakers, and distributors of pirated content and illegal pornography. In India, the app was heavily scrutinized after anonymous channels leaked exam papers for the re-NEET tests. Law enforcement could not identify original uploaders. Telegram allows file uploads up to 2GB (4GB for Premium), effectively creating the world’s largest unregulated torrent network. Pirates use bots and broadcast channels to distribute movies, while scammers and adult content creators funnel users from mainstream platforms into unregulated Telegram groups. The platform has pledged zero tolerance for deepfake pornography and illegal content, but moderation remains reactive and reliant on user reports; banned channels quickly reappear using backup links.
The Telegram ‘A-P-P-P’: Privacy, Piracy, and Pornography →
Flock’s AI-Enabled Street Cameras Face Backlash, Communities Cancel Contracts
Flock Safety’s AI-powered street cameras are facing increasing backlash across the United States, with a growing number of communities choosing to cancel contracts for the technology. No specific details on locations, numbers, or reasons were provided in the report.
Flock’s A.I.-enabled street cameras see backlash across the country →
Cleveland Voted to Kill Its Flock Camera Network, But Police Still Use Them
Cleveland’s Public Safety Committee voted 3–1 against renewing the city’s $250,000 annual contract with Flock Safety, which expired June 29. Despite the vote, approximately 100 Flock cameras remained operational and police continued using them. The committee found insufficient evidence that the cameras reduced crime; police presented only a handful of cases. Privacy advocates noted the ACLU’s analysis that Flock’s updated terms give the company a perpetual license to use customer surveillance data even after contract termination and mandate private arbitration under Georgia law. No subsequent authorization was scheduled.
Parents and Experts Fear Roblox Will Slip Through UK Online Safety Crackdown
Campaigners and parents expressed concern that the UK’s planned social media ban for under-16s, announced by Sir Keir Starmer, may not adequately protect children on Roblox, which they describe as ‘one of the worst things to happen to childhood.’ An Ofcom study found Roblox reached 61% of UK 8-14-year-olds. The platform has been linked to grooming; in April, a 19-year-old was jailed for abusing a girl he met on Roblox. Roblox launched age-specific versions with expanded controls, but critics say they are insufficient. Susie Masterson’s son reported regular approaches from strangers trying to lure him to other platforms. Andrew Wilmot of the BrainSafe Standard called for regulation identifying structural harms, noting game design features borrowed from casinos. The government announced restrictions including preventing strangers from messaging children on gaming platforms, underpinned by age verification.
Study Finds 60% of Kids’ Online Safety Tools on Major Platforms Have Critical Flaws
A study by the Heat Initiative and the Cybersafety Research Center tested 86 safety features across Instagram, Snapchat, TikTok, and YouTube, finding that about 60% ‘do not live up’ to company promises. On Instagram, TikTok, and Snapchat, simply misspelling a search query — e.g., ‘eating dis’ instead of ‘eating disorder’ — bypassed restrictions. YouTube did not surface harmful content but allowed bypassing via a confirmation button. Ten ‘conduct tools’ failed across all platforms. Meta called the report ‘fundamentally flawed,’ while Snap and TikTok defended their protections. YouTube said 84% of parents using its supervised tools feel confident. The researchers noted YouTube’s features were all triggerable. The study follows a jury finding Meta and YouTube liable for addictive platforms for minors, and moves in Australia, Indonesia, and the UK to ban social media for under-16s.
Open-Source Notes App Notesnook Offers Strong Encryption but Lacks Key Features
The open-source notes app Notesnook uses end-to-end encryption, keeping notes encrypted on device, servers, and in transit. Its free plan is feature-rich, syncing across devices with a full offline mode. It supports rich media, notebooks with sub-notebooks, and a web clipper. However, a reviewer who switched from Simplenote found Notesnook slower, lacking raw Markdown support (shortcuts are paid-only), cross-platform revision history syncing, and real-time collaboration. The reviewer moved some notes but did not replace Obsidian due to Obsidian’s plugins, knowledge graph, automation, and lack of vendor lock-in.
I switched to an open-source notes app for 2 weeks, and I wish I had done it sooner →
WhatsApp’s Username Feature Re-Ignites India’s Message Traceability Debate
India, WhatsApp’s largest market with over 850 million monthly active users, saw the government suspend the planned username feature that would allow messaging without revealing phone numbers. The Ministry of Electronics and Information Technology (MeitY) argued that usernames would hinder identification of fraudsters and cybercrime investigations. After pausing WhatsApp’s rollout, MeitY also sought explanations from Telegram and Signal about how their username features address cybercrime. Law enforcement prefers visible phone numbers for investigative leads.
WhatsApp’s username feature has re-ignited India’s debate over online message traceability →