Privacy
Streetlights, Grok, and Google – Your Privacy at Risk
A look at surveillance nodes, LAPD's Flock negotiations, xAI's data leak, Google's AI training, and the data center boom.
NEMA Nodes Turn Streetlights into Covert Surveillance Network
A NEMA node is an IoT controller that slots into a standardized socket atop a streetlight fixture, roughly the size of a hockey puck and designed to blend in. The same interface that allows remote dimming and energy management can also accept cameras, environmental sensors, license-plate readers, 5G small cells, and municipal Wi-Fi. Smart-city platforms aggregate sensor data centrally, where AI tools analyze movement patterns and anomalies. NEMA frames the systems as tools for energy savings and efficiency, but the surveillance potential is equally real. Specific regulatory frameworks governing the data collected by these nodes remain limited and inconsistent across jurisdictions, leaving a governance gap between useful efficiency and pervasive monitoring.
You Know About Flock Cameras, Meet Nema Nodes: They Turn Streetlights Into A Surveillance Network →
LAPD Renegotiates Flock Contract After Data Ownership Concerns
The Los Angeles Police Department is renegotiating a new agreement with Flock Safety after halting their relationship over concerns about data sharing. Under the proposed contract, the LAPD would retain ownership of every image, record, and metadata, and Flock would be prohibited from selling, sharing, or using the data to train AI. The company would also be required to alert the city within 24 hours of any data breach. A recent inspector general report found that Flock cameras scanned over 210 million license plates in two months, with 337 alerts leading to stolen vehicle recoveries but also 161 false positives. The report noted that LAPD lacks formal contracts with two other plate reader vendors, Axon and Motorola, and that existing agreements have unclear language on data retention and third-party sharing. Community groups called for a permanent end to the Flock relationship, while the inspector general’s office will hold a virtual listening session on July 30.
LAPD renegotiating deal with Flock Safety to access company’s license plate readers →
xAI’s Grok Build Uploads Full Git Repositories, Contradicting Privacy Claims
A security researcher published a wire-level analysis proving that xAI’s Grok Build coding CLI was packaging developers’ entire tracked repositories, including full Git history, committed secrets, and API keys, and uploading them to a Google Cloud Storage bucket. The upload volume was roughly 27,800 times greater than the data the coding task required. The researcher tested version 0.2.93, intercepted the upload, and recovered a file the AI agent was told not to open. xAI had marketed the tool with claims that nothing from your codebase is transmitted during a session, which the wire data directly contradicts. Elon Musk confirmed the uploads and said xAI would delete all prior user data, and the company added a zero-data-retention policy and a privacy endpoint. However, no independent audit has confirmed the deletion, and the breach is particularly damaging for a product aimed at enterprise developers.
Grok Build was uploading entire Git repositories to xAI’s cloud, including committed secrets →
Google Auto-Enrolls Users in Expanded AI Training Using Search Media
Google updated its search privacy settings last month and automatically opted all customers into expanded AI training, announced via email. The updated policy states that saved media from your interactions with Search services, including images, files, audio, and video, may be used to develop and improve Google’s AI models and technologies. This applies to media uploaded for AI searches, such as screenshots taken with Circle to Search, voice searches via Search Live, or using Google Translate. To opt out, users must adjust settings on two pages within the Google app: Search Services History and Search Services Personalization, or use myactivity.google.com to uncheck ‘Save media’ and configure retention duration. Users can also disable Personalized Ads via myadcenter.google.com. The change gives Google broad rights to use any media generated by a user’s search for any purpose, including training large language models.
Google is training AI on even more of your data now, unless you opt out - here’s how →
New York Pauses Hyperscale Data Centers Amid Nationwide Backlash
New York Governor Kathy Hochul will sign an executive order that pauses hyperscale data center development in the state for one year, barring permits for projects using 50 or more megawatts of power. The move makes New York the first state to enact such a ban, giving officials time to develop a regulatory framework. Nationwide, data centers could consume up to 12% of U.S. electricity by 2028, up from 4.4% in 2023, driving utility cost increases of up to 25% in Northern Virginia and 8% nationally. Water usage is also a concern: Meta’s Georgia data center uses about 500,000 gallons daily, and a UC Riverside study projects U.S. data centers could require $58 billion in additional public water capacity by 2030. In Arizona, a new moratorium on data center tax incentives is expected to save $57 million, while in Virginia’s Loudoun County, data centers generate $1.3 billion in annual tax revenue. Hochul directed Empire State Development to deliver guidance within 60 days for local governments to negotiate community benefits from large-scale projects.
New York Just Banned Large Data Centers—5 Numbers Explain Why the Backlash Is Spreading Nationwide →