HeadFlash

Privacy

Privacy in Focus: Satellites, Scraping, and Surveillance Backlash

From thermal satellites to gunshot detectors, this week's privacy news reveals growing tensions between tech capabilities and civil liberties.

Listen

UK Thermal Satellite Raises Alarm Over Surveillance Capabilities

SatVu’s HotSat-2 thermal imaging satellite, launched on March 30, 2026, can monitor industrial operations, detect movement inside buildings, and determine whether equipment at facilities such as nuclear reactors is active or idle based on heat signatures. The company has demonstrated this capability at the Yokosuka Naval Base in Japan, the Ruwais Refinery in the UAE, and Albuquerque International Airport. On June 29, the satellite transitioned from a technology demonstration to an operational system. While no documented evidence shows SatVu has violated privacy, the potential for pervasive monitoring—including of a nuclear facility in North Korea—has drawn sharp concern. The company says its stated applications include national security and monitoring activity in areas of “strategic importance.” HotSat-2 is intended as the first step toward a full constellation of thermal imaging satellites, amplifying worries about unchecked orbital surveillance.

This UK Satellite’s Thermal Camera Raises Major Privacy Concerns →

Patreon Deploys Network-Level Block Against AI Crawlers

Patreon announced a partnership with Cloudflare to block AI training crawlers from accessing creator content on its platform. The block is implemented at the network level on all posts and is already live. CEO Jack Conte stated on Instagram that ‘crawlers can stay the fuck off Patreon’ unless creators receive credit, compensation, and consent. Drew Rowny, Patreon’s SVP of Product, said the block targets known AI training crawlers while allowing search crawlers that help creators grow their audience. The move follows Cloudflare’s earlier announcement that it would block AI crawlers by default unless website owners grant permission or receive compensation. In May, Conte posted a 43-minute video arguing that the AI industry has failed to compensate creators, and that consent, credit, and compensation are all currently denied. Starting in September, new domains onboarding to Cloudflare will have training and agent bots blocked by default on pages that display ads.

Patreon Blocks Crawlers From Stealing Creators’ Work for AI Training →

Google Adds AI Disclosure Labels to Adverts

Google announced a new feature that adds a ‘How this ad was made’ section to its My Ad Center panel, visible via the three-dot menu or info icon on ads in Search, YouTube, or Discover. Advertisers using generative AI tools to create an ad will have a disclosure displayed in the panel; for ads created on other platforms, Google provides transparency controls so the advertiser can indicate whether AI was used. Google will not actively verify these labels unless local law requires an AI label, and a spokesperson stated that advertisers are responsible for accuracy and compliance. The feature is part of broader transparency efforts. In May, Google introduced SynthID, an invisible watermarking system for AI-generated content. The new labels aim to help people identify when an ad has been created or edited using generative AI, though enforcement relies on advertiser honesty in most jurisdictions.

New Google Tags Will Tell You When an Ad Was Made or Altered Using AI →

LAPD Suspends Use of Flock Surveillance Cameras Over Data Concerns

The Los Angeles Police Department stopped working with Flock Safety on July 11 over concerns about how the surveillance technology company uses data. Flock operates 138 pole-mounted cameras in Los Angeles that track vehicles reported stolen or registered to known fugitives. The LAPD’s three-year agreement with Flock was set to expire Saturday, and Chief Information Officer Dean Gialamas said the department seeks clearer terms about data ownership and what happens with collected data. The city attorney’s office had been working on a new contract, but its status is now unclear. A Flock spokesperson called the decision a ‘surprise’ and expressed confidence that discussions could clear up ‘misconceptions.’ Reports that Flock shared license plate data with U.S. Immigration and Customs Enforcement have led smaller cities to end their relationships with the company. An audit by LAPD Inspector General Matthew Barragan, released Friday, recommended suspending new deployments of automatic license plate readers and new contracts, and requiring all contracts go through the Board of Police Commissioners. Privacy advocacy group Stop LAPD Spying has sued the city to obtain agreements with Flock.

LAPD suspends use of Flock surveillance cameras over privacy issues →

Meta Patent Describes AI That Continuously Tracks Emotions via Voice

Meta filed a patent (US 2026/0182881 A1) on December 16, 2025, published July 2, 2026, for a system that continuously listens to a user’s voice to detect emotions and build a timeline of emotional trends. The system ties mood to location, activity, and time of day, recording spoken words across many situations and transcribing them. An AI analyzes tone, pace, and other nonverbal cues, and notes context such as time, location, activity, or app in use. Over time, it produces summaries of emotional patterns with specific transcript quotations as supporting evidence. The patent frames the technology as a fitness coaching tool, but the core method is written broadly. The system requires persistent ambient voice recording, not triggered by a wake word. Meta operates Ray-Ban smart glasses and is developing further wearable devices, which are natural form factors for always-on audio. The patent raises significant privacy questions about continuous audio surveillance in everyday environments.

Meta Patent: AI That Tracks Your Emotions Over Time →

Gunshot Detection Systems Face Privacy and Accuracy Backlash Across U.S.

Gunshot detection systems, including Flock Safety’s Raven and SoundThinking’s ShotSpotter, have been deployed in several cities to speed police response to shootings, but pushback over privacy, accuracy, and installation problems has led multiple jurisdictions to abandon or restrict the technology. In San José, California, and Champaign, Illinois, officials stopped using the system after finding it was much worse at detecting gunshots than claimed. In Champaign, only 8% of alerts led officers to a scene where shots appeared to have been fired. In San José, accuracy hovered around 50% initially, rising to 80% after recalibration, but the system was still removed. In Jackson, Mississippi, devices were installed on private property without consent and left despite the city’s request for removal. In Roanoke, Virginia, at least 30 devices were installed in wrong locations due to data entry errors, and the city repealed the installation ordinance on July 6. The technology also sparked concerns about eavesdropping; Flock’s former product manager confirmed devices record five-second audio snippets and send them to the cloud for analysis, occasionally capturing parts of conversations. A privacy assessment by NYU Law found the risk of voice surveillance ‘extremely low,’ but the Electronic Frontier Foundation questioned the legality of a now-discontinued ‘human distress’ detection feature under state eavesdropping laws. In Portland, Oregon, a survey found 51% opposed the devices and nearly 80% expressed some level of privacy concern, leading the city to abandon plans. Despite the backlash, some cities like Pontiac, Michigan, renewed contracts after a free pilot showed data used in nine cases including homicides.

Is the government listening? Gunshot detectors spark backlash →

EDPB Guidelines Tighten Rules on Web Scraping for AI Training

The European Data Protection Board adopted Guidelines 03/2026 on web scraping for generative AI on July 7, 2026. The 22-page document, open for public consultation until October 30, applies to organizations that scrape data themselves or obtain pre-scraped datasets to build or fine-tune AI models. The guidelines distinguish targeted from untargeted scraping and define a four-step process: defining collection criteria, extraction, cleaning, and structuring/storing. Joint controllership arises when two organizations jointly decide collection criteria and model development. Crucially, the EDPB deems consent unworkable as a legal basis for scraping because organizations have no direct relationship with individuals. Legitimate interest under Article 6(1)(f) is the expected legal basis, subject to a three-part test. The guidelines require data minimization, including considering synthetic data, defining precise collection criteria, and excluding websites used mainly by minors. For special categories of data, the CJEU ruling in GC and Others (C-136/17) applies by analogy, requiring filters before collection and deletion of such data as soon as identified. The guidelines note that once a model is trained, personal data cannot be easily deleted, and machine unlearning is noted as a possible future alternative.

EDPB blocks AI firms from using consent as an excuse to scrape →

Meta removed a controversial feature from its Muse Image model that allowed users to generate AI images of other people by @-mentioning their public Instagram accounts without requiring consent. The feature was enabled by default, and users had to manually opt out through Instagram’s settings to prevent their photos from being used. Meta admitted ‘this feature missed the mark’ and shut it down days after announcing it. The company said it wanted to offer a creative tool while giving people control, but the implementation drew widespread criticism. In Europe, the feature likely would not have survived due to stricter data protection rules. Meta may have borrowed the idea from OpenAI’s now-discontinued Sora app, which let users create cameos and, with permission, allow others to use them. The feature was a viral hit at launch but interest quickly faded. The episode highlights ongoing tensions between AI-driven creativity and user consent in online platforms.

Meta kills Muse Image feature that let anyone generate AI photos of Instagram users without consent →

Google’s New Search Services History Setting May Use Photos and Voice for AI Training

Google is rolling out a new setting called Search Services History that controls whether activity from Search services is saved when a user is signed into a Google Account. This can include images uploaded, files queried, voice searches, Search Live recordings, and Translate speaking practice audio. A subsetting called Save Media, when turned on, allows Google to save media from Search services interactions, and that saved media may be used to improve Google’s AI models and technologies. Google states that saved media may also help users revisit past visual searches or continue a Search Live conversation. The new settings are based on prior choices for Web & App Activity and Search Personalization. Turning off Save Media stops Google from saving media from future interactions for training, but previously saved media may still be used to improve technologies unless the user deletes it. If saved media has already been selected to train AI models, it is no longer connected to the user’s account and may be kept for up to four years. The setting does not cover Gemini Apps, YouTube, NotebookLM, or Google Voice, which have their own controls.

Google may use your photos and voice to train AI →

Meta Disables Camera on AI Glasses If LED Light Is Tampered With

Meta updated its second-generation AI glasses so the camera automatically disables when the device detects that the capture LED has been physically tampered with or destroyed. The capture LED is a white light on the front of every pair that blinks briefly during photo capture and continuously during video recording and has no off switch by design. An earlier safeguard disabled the camera if the LED was blocked by tape or a finger, but did not address modification or destruction of the LED itself. Meta stated it observed users moving beyond simple obstruction to sophisticated efforts to modify or destroy the LED, prompting the new detection capability. The company did not disclose the specific sensor mechanism. Meta also works across its platforms to remove advertisements and listings promoting tampering services, bans accounts found doing so, and pursues legal action. The update arrives alongside California Senate Bill 1130, introduced in February 2026, which would make it a criminal offense to disable or sell technology capable of disabling an indicator light on a wearable recording device, with penalties up to $10,000 for repeat violations. Meta stated further privacy features are planned as the glasses grow in popularity, with millions of daily users, but did not specify a timeline.

Meta blocks camera on AI glasses if LED light is destroyed →

Taboola Turns DeeperDive AI Answers Into Ad Inventory for Any Chatbot

Taboola opened the monetization engine behind its DeeperDive answer engine to outside generative AI companies on June 16, 2026, offering conversational AI providers a way to convert user queries directly into advertising revenue. DeeperDive, first launched in June 2025, is an AI answer engine embedded across publisher websites that draws responses from that publisher’s own archive. Taboola stated the tool now generates tens of millions of AI-powered answers every month for more than 7 million users, with categories like politics, sports, finance, entertainment, and shopping being most popular. The monetization layer relies on large language models, retrieval systems, and Taboola’s proprietary intent graph, powered by NVIDIA accelerated computing. Publishers integrating DeeperDive do not pay for the service and receive a share of advertising revenue. Taboola CEO Adam Singolda framed the move as building the economic layer of the AI internet, noting that subscriptions alone cannot fund all AI services. The announcement was timed to precede the Cannes Lions International Festival of Creativity. The expansion raises privacy questions about how user queries are used for targeted advertising, though Taboola describes it as permission-based publisher content.

Taboola turns 7 million DeeperDive users into ad inventory for any chatbot →