Privacy
EU vs Big Tech, Spyware Exposed, and Your Data’s New Frontiers
From Brussels to Texas, privacy battles escalate: AI access mandates, mass surveillance revelations, and wearable data risks.
EU Orders Google to Grant Rival AI Apps Equal Android Access
The European Commission formally ordered Google to give third-party AI services the same access to Android device features that Gemini has, under the Digital Markets Act. Google must allow AI apps to access 11 features, including voice commands, completing actions across apps, and accessing on-device AI models, with most changes required by August 1, 2027. The EC is making many of the same demands of Google that it made of Apple, which opted not to launch Siri AI in the EU after failing to reach an agreement on privacy and security standards. Google argued the requirements risk undermining vital privacy and security guardrails for millions of Europeans, but plans to continue advocating for a balanced approach.
EU Orders Google to Give Rival AI Apps the Same Android Access as Gemini →
LG TVs and Monitors Surveil Users and Install Bloatware Without Consent
An investigation by Gamers Nexus found that newer LG UltraGear and UltraFine monitors automatically install the LG Monitor App Installer and McAfee Scam Detector on Windows computers without user permission. According to LG’s own documentation, the installer has full access to all system resources and collects data on location, hardware, online activity, account logins, and contact information. The issue also affects some older models after firmware updates. For older LG smart TVs, users can avoid new terms of use by skipping webOS updates, but that means no longer receiving security patches.
LG TVs and monitors said to surveil users and install bloatware without asking →
ICE Shared Improper Medicaid Data with Palantir for Deportation Efforts
Medicaid officials improperly shared data about millions of people with ICE in January 2025, which ICE then shared with the data analytics firm Palantir for use in its ELITE app. The revelation came in a motion filed by more than 20 Democratic attorneys general who sued over the data-sharing agreement. A federal judge had already paused data sharing after federal officials admitted sharing data that exceeded a court order, including a dataset of refugees containing U.S. citizens and another of millions of people including legal immigrants. ICE was ordered to delete the data, but subsequent searches found that half a dozen users still had copies, and additional improper sharing occurred in an attempt to share data from non-suing states. The judge warned that if the federal government cannot be careful, it cannot use the information.
ICE shared Medicaid data it wasn’t supposed to have with Palantir →
Madison Square Garden Sues WIRED Over Secret Celebrity Watchlist Report
Madison Square Garden Entertainment filed a defamation lawsuit against WIRED magazine over a report that the venue keeps a secret watchlist of celebrities with risk scores. The lawsuit accuses WIRED of using stolen data to invent a false narrative that MSG targets LGBTQ celebrities. WIRED’s article claimed the database contains nearly 40,000 names, with roughly 400 risk scores ranging from low risk to DO NOT HOST, tagging celebrities who criticise the venue. The data was exposed after the hacking group ShinyHunters breached MSG’s systems. MSG argues the data was part of a standard relationship management system and that WIRED ignored normal fields like addresses and dietary preferences. WIRED said it stands by its reporting and will fight the case.
Trump Claims China Stole 220 Million U.S. Voter Files in Massive Breach
Donald Trump said during a primetime address on July 17, 2026 that newly declassified documents show China acquired 220 million U.S. voter files in what he called the largest election-data compromise in history. The breach began during the 2020 election cycle and exposed names, addresses, phone numbers, and political party preferences. Intelligence assessments warn that Russia, China, Iran, and North Korea have the capability to compromise election infrastructure, and that centralized voter registration databases remain most vulnerable. The White House release also cites a DHS review identifying roughly 278,000 noncitizens registered to vote in federal elections. Trump directed the FBI and DOJ to investigate the Michigan voter registration matter.
Trump says China stole 220 million U.S. voter files in largest election-data breach →
Inside Pegasus: Amnesty Reveals Evolution of NSO’s Spyware System
Amnesty International’s Security Lab published a detailed analysis of Pegasus spyware, based on newly disclosed material including WhatsApp documents. The report shows that Pegasus is not autonomous; NSO Group builds exploits, operates anonymized infrastructure, and runs a Network Operation Centre that monitors systems but cannot view collected data. The leaked Pegasus Project dataset is independently corroborated: test infection attempts from NSO’s own dashboards match specific phone numbers and dates in the dataset, contradicting NSO’s denials. The system uses unique attack accounts per customer, creating fingerprints that validate attribution. The analysis covers infection vectors from zero-click exploits like Heaven and Dragonfly to one-click attacks, and describes how forensic traces can be identified because NSO registers unique infrastructure per customer.
Inside Pegasus: The evolution of the world’s most notorious spyware system →
Meta Patents Technology for Continuous Mood Detection via Voice Analysis
A patent published July 2 describes a Meta system that records all audible communications and combines them with contextual factors like time of day, location, and user activity. Audio would be transcribed and an emotional-state machine learning model would interpret verbal and nonverbal cues to determine emotional indicators. The patent states the system improves emotional inference by aligning multimodal sensor inputs on synchronized timelines. Its stated goal is to better tailor workouts to emotional state, and it also discusses connecting audio inputs to medication timing. Amazon previously launched a similar feature with the Halo Band but removed microphones after backlash and discontinued the product in 2023. A Meta spokesperson said patents are often filed for concepts that may or may not be implemented.
Meta Patents Technology to Detect Your Mood by Constantly Analyzing Your Tone of Voice →
San Francisco Demands Apple and Google Remove AI Nudify Apps
San Francisco City Attorney David Chiu sent cease-and-desist letters to Apple and Google demanding removal of 13 AI-powered apps that can create nonconsensual nude images. Eight apps were on Apple’s App Store and five on Google Play. The letters accuse the companies of aiding and abetting the sale of illegal deepfake pornography by hosting the apps and taking a cut of proceeds, likely earning millions. The city gave 28 days to comply or face civil penalties of at least $25,000 per violation. Google said it removed all five identified apps and has suspended hundreds of similar apps. Apple said it removed three apps and is terminating developer accounts. Both companies already prohibit such content, raising questions about how the apps passed review.
San Francisco warns Apple and Google to stop profiting from AI nudify apps →
EU Revives Voluntary Chat Scanning Law, Excluding Encrypted Messages
The European Parliament revived a temporary derogation to e-Privacy rules on July 9, allowing big tech platforms to voluntarily scan private messages for child sexual abuse material (CSAM). The interim measures will remain in force until 2028 and do not apply to end-to-end encrypted messages used by apps like WhatsApp or Signal. Digital rights groups call the rules Chat Control and argue they amount to mass surveillance. Critics say the policy outsources law enforcement to private companies without safeguards. Supporters like MEP Jeroen Lenaers say it closes a legal loophole and reject claims of mass surveillance. Negotiations on a permanent regulation are set to resume after summer, and the permanent version will not include scanning encrypted messages.
Why the EU’s so-called Chat Control law has privacy experts up in arms →
Texas DPS Spent $4.5 Million on Four Chevy Tahoes with Surveillance Gear
The Texas Department of Public Safety requested approval to spend $4,487,500 on a Cognyte surveillance setup in March 2026, citing an emergency purchase necessary to protect state personnel and property. The total included four 2026 Chevrolet Tahoes at $150,000 each and FalcoNet systems that intercept the connection between a phone and cell tower to track people secretly. The FalcoNet system can be mounted on vehicles, backpacks, or helicopters. The Supreme Court ruled in Chatrie v. United States that people have a reasonable expectation of privacy in location data and that even short-term tracking counts as a search under the Fourth Amendment. The technology is already in use in Florida, and similar purchase orders show it is sold in modular deployment kits.
How Texas Police Spent $4.5 Million on Four Chevy Tahoes →
EFF Finds Only Apple Encrypts Health Data on Wearables
The Electronic Frontier Foundation published an investigation into the privacy practices of ten consumer wearable companies on July 15, 2026. Only Apple implements end-to-end encryption for health data by default, requiring two-factor authentication. Every other major platform — Garmin, Oura, Whoop, Fitbit/Google, and others — stores health data with company-held decryption keys, meaning a subpoena can compel production of readable data. Only Apple and Google publish transparency reports on government data requests. Amazfit, whose parent company is Chinese, acknowledges that national security requests can result in disclosure under China’s National Intelligence Law. The EFF noted that health AI features typically require server-side computation, making end-to-end encryption a design trade-off, and that consumer wearable companies are not covered by HIPAA.
Fitness Trackers Are a Subpoena Away: EFF Finds Only Apple Encrypts Health Data →
Incoming UK PM Burnham Scraps Digital ID Plans, Redirects Funds
Andy Burnham will scrap plans for a government-issued digital ID for all British adults when he becomes prime minister, shifting focus to cost-of-living priorities. The scheme, initially introduced by Sir Keir Starmer, had already been watered down to voluntary after nearly three million people signed a petition opposing it. The Office for Budget Responsibility estimated the programme would cost £1.8bn over three years, though Downing Street rejected that figure. Burnham’s spokesperson said the time and resource will go instead to helping with the cost of living. Deputy Labour leader Lucy Powell said the money saved is not insignificant and will be reprioritised. Conservatives accused Burnham of claiming credit for a decision already taken, while Liberal Democrats praised the move as ending a huge waste of taxpayers’ money.
Burnham to scrap digital ID to focus on ‘helping with cost of living’ →
EU-Funded Herta Security Runs Banned Facial Recognition on 4,000 Indian Cameras
An investigation by Investigate Europe, India’s Reporters’ Collective, and Tech Policy Press found that Herta Security, a Spanish company, runs facial recognition technology on an estimated 4,000 cameras across Indian railway stations, prisons, and city surveillance systems. Herta has received more than €3.3 million in EU research grants since 2020. Four legal scholars concluded that at least two of the Indian deployments would violate the EU AI Act if operated on EU soil, as the Act bans real-time remote biometric identification in public spaces. The EU AI Act does not prohibit exporting such systems, and facial recognition software is not on the dual-use control list. Herta’s largest grant, €2.36 million, was for a project designed to perform crowd behavior analysis. India’s data protection law exempts law enforcement from consent requirements, and there is no legal route for misidentified individuals to seek redress. Italian MEP Brando Benifei called the findings a dangerous double standard.
EU-Funded Herta Security Runs Banned Facial Recognition on 4,000 Indian Cameras →