HeadFlash

Privacy

The Surveillance State Expands: Drones, Wearables, and Chat Control

From autonomous police drones to browser fingerprinting and EU message scanning, privacy is under siege on multiple fronts.

Listen

FAA Streamlines Drone Waivers, Sparking Surge in Police Surveillance Programs

Over 1,000 public safety agencies in the U.S. had received FAA waivers for automated drone operations as of February 2026, according to a recent FOIA release. The FAA issued more waivers between April 2025 and February 2026 than in the previous seven years combined, marking a dramatic shift from human-operated aerial surveillance to AI-based autonomous drone use. Only 976 waivers had been granted from the first drone-as-first-responder (DFR) program in 2018 through April 2025. Flying drones beyond visual line of sight (BVLOS) and above 200 feet requires additional approval, but police departments are rushing to adopt the technology. DFR programs increasingly rely on artificial intelligence to automate flights from launchpads atop municipal buildings, allowing one operator to manage multiple drones simultaneously. Companies like Flock Safety and Axon have turned DFR into a major revenue stream, with Axon reporting it as one of its fastest growing sectors. A Government Technology analysis of the system in Chula Vista, California, found that deployments often target low-risk calls involving unhoused people, mental health concerns, and loud music. Drone footage can capture images from backyards, roofs, and through windows at distances that leave subjects unaware, and a recent leak of drone footage from the San Francisco Police Department illustrated surreptitious observation of innocent individuals. Some cities provide public portals logging flight paths and reasons for each flight in real time, and California’s AB 481 requires police departments to provide advance notice of intent to acquire drones and annual updates on use.

Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country | Electronic Frontier Foundation →

Browser fingerprinting is an advanced tracking method that queries technical details about a device—such as operating system, GPU drivers, screen resolution, time zone, installed fonts, and hardware specs—to create a unique digital identifier for a browser, bypassing the need for cookies. Techniques include canvas fingerprinting, WebGL rendering, font enumeration, AudioContext cues, and hardware details. The Electronic Frontier Foundation’s Cover Your Tracks tool allows users to run free scans to check what data their browser leaks. A scan of a Chromium-based Arc Browser after disabling cookies and trackers revealed 18.26 bits of identifying information, including a unique fingerprint via Canvas and WebGL rendering. Safari introduced Advanced Tracking and Fingerprinting Protection with iOS 17 and macOS Sonoma, and users can enable it for all browsing. Microsoft Edge offers fingerprinting protection at its lowest privacy settings, and users can enhance it by selecting Strict tracking prevention. Firefox bundles fingerprinting and cookie protection under Enhanced Tracking Protection, allowing users to block fingerprinters in all windows. Brave provides fingerprinting protection via its Shields component, which scrambles data collected by fingerprinting APIs. Chrome does not offer built-in fingerprinting protection after Google shuttered its Privacy Sandbox component in April 2025, but third-party extensions like Canvas Blocker, Fingerprint Spoofer, and StealthHound can help. However, Chrome’s Manifest V3 extension framework prevents extensions from injecting code into a web page before it finishes loading, giving fingerprinting technologies time to collect data before spoofing mechanisms activate.

How to Stop Browser Fingerprinting, the Latest Method for Tracking Your Activity Across the Internet →

EU ‘Chat Control’ Legislation Stalled Over Mass Surveillance Concerns

The European Union’s proposed ‘Chat Control’ legislation, first developed in 2021 and now seeking approval in a watered-down form, would allow messaging platforms, social media platforms, and email providers to scan private digital communications for Child Sexual Abuse Material (CSAM). The legislation is currently stalled because the European Parliament and the Council have not agreed on a final text. The legislative process is divided into two frameworks: an interim measure (Chat Control 1.0) and a proposed permanent regulation (Chat Control 2.0). Chat Control 1.0 creates an exemption to the EU’s ePrivacy Directive, allowing platforms to scan unencrypted communications on a voluntary basis. Chat Control 2.0 is the European Commission’s proposal for a permanent, mandatory law that would require technology companies to implement ‘client-side scanning,’ intercepting and analysing messages directly on a user’s device before they are encrypted. Digital rights organisations and technical experts warn that the automated AI filters used for scanning are unreliable and prone to false positives, and that ordinary family photos or messages could be flagged as illegal, triggering automatic reports to law enforcement and undermining the presumption of innocence.

Should the EU scan your private messages with ‘Chat Control’? Take our poll. →

Invisible Surveillance: Smart Wearables Challenge UK Privacy Laws

Smart glasses and other wearable devices with cameras, microphones, location-tracking, and AI assistants are becoming nearly indistinguishable from ordinary spectacles, making surveillance increasingly invisible. UK data protection law under the UK GDPR requires organizations to be transparent about what personal data they collect and why, but the undetectable nature of wearable technology challenges the ability of individuals to consent to data processing. In workplaces, employers are attracted to smart glasses for productivity benefits, but the same technology can record conversations, track locations, monitor task completion times, and capture where a worker directs attention, with AI tools analyzing this data to create employee behavior profiles. Under UK employment and data protection law, employers must ensure monitoring is necessary, proportionate, and justified, and the Information Commissioner’s Office has emphasized that workplace monitoring should not be excessive or unnecessarily intrusive. In the public sector, healthcare providers and emergency responders are exploring wearables, but patients and service users may be unaware that wearable devices are being used around them or how resulting data is stored, processed, or shared. Educational institutions face pressure to protect academic integrity as affordable smart glasses and AI-enabled wearable software make real-time cheating harder to detect, with some institutions investing in Bluetooth signal jammers, devices that scan for active radio frequencies emitted by smart glasses, and advanced proctoring software that uses AI to flag suspicious eye movements, raising questions around privacy, data protection, and procedural fairness.

Smart wearables challenge UK privacy laws through invisible surveillance →

Trump’s DOJ Nominee Wants to Ban Online Porn and Prosecute Big Tech

President Donald Trump has nominated Adam Candeub to lead antitrust enforcement at the Department of Justice. Candeub currently serves as general counsel for the Federal Communications Commission. In a report titled ‘Restoring Obscenity Regulation in an Internet Age,’ published by the Heritage Foundation, Candeub argued for criminalizing pornography to protect marriage and promote human flourishing. He applauded the Supreme Court’s 2025 decision in Free Speech Coalition v. Paxton, which allowed for mandatory ID checks on websites with content deemed ‘harmful to minors,’ and wrote that the decision ‘opens the door both to a reconsideration of the current legal structure governing obscenity and, perhaps, to a return to the regulatory approach of the past.’ Candeub proposed increasing online surveillance to enforce blocks on minors viewing sexual content, stating that ‘age estimations can be made simply by analyzing publicly available online information such as your email address or even pictures of your hand movements.’ He advocated for using state and federal laws to prosecute porn websites and other online entities, noting that ‘motivated state and local prosecutors could still get convictions in conservative communities, and national prosecutors could go against the big platforms like Google.’ Candeub was also a key player in the first Trump administration’s effort to get rid of Section 230. In his Project 2025 chapter on the Federal Trade Commission, Candeub wrote that large internet platforms ‘have avoided significant antitrust liability or prosecution’ and suggested the FTC should investigate whether businesses are using ‘fashionable moral beliefs’ like diversity, equity, and inclusion for nefarious purposes. As DOJ antitrust head, Candeub would take over the department’s ongoing antitrust matters involving Big Tech, including Google’s appeal of the landmark ruling deeming it an online search monopoly and the department’s 2024 lawsuit accusing Apple of illegally monopolising smartphone markets.

Trump’s new DOJ nominee wants to ban online porn and prosecute Big Tech →