Privacy
WFP Renews Palantir Deal Despite Leaked Audit Warning
WFP extends Palantir contract amid privacy audit concerns; FBI seeks predictive AI watch lists; wearables lack transparency.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
WFP to renew Palantir contract despite leaked audit flagging privacy risks
The World Food Programme is finalizing a renewal of its five-year agreement with Palantir, despite a leaked internal audit that found inadequate risk management and a lack of proper guidelines on data privacy in the partnership. The audit, conducted by the WFP’s Office of the Inspector General and dated August 2025, lists the problem as high priority and states that key privacy concerns raised by internal and external stakeholders regarding the use of the Digital Operations and Transformation System (DOTS) have not been adequately addressed. The renewal is set to be signed in August, with terms remaining the same as the 2019 contract.
The audit also notes there is no clearly defined exit strategy for DOTS and no clarity on potential costs if the partnership is terminated. A report by independent researchers describes the partnership as a clear conflict of interest, and an expert familiar with the contract said a provision could legally allow Palantir to train its software on UN data. Palantir denies using customer data to train models. The WFP’s SCOPE system is one of the world’s largest biometric databases. The extension comes as the agency faces a 34 percent reduction in funding from major donors in 2025 and plans to cut nearly a third of its global workforce. Some senior WFP staff believe ending the partnership could prompt retaliation from the Trump administration.
Exclusive: WFP to extend Palantir contract despite concerns raised in leaked audit →
FBI seeks predictive AI for terrorist watch list, documents show
The FBI’s Terrorist Screening Center is seeking an artificial intelligence system for predictive policing, according to procurement documents obtained by Reason. A request for information posted in March lists predictive modeling using enhanced data with traceable lineage as one of six requirements, with the solution expected to analyze similarity, pattern alignment, and attribute correlation against existing records to predict where additional relevant information may be derived. The TSC combines government terrorist watch lists into one center and now approaches 2 million names.
The procurement request explicitly mentions National Security Presidential Memorandum-7, which instructs the national security apparatus to focus on threats including anti-Americanism, anti-capitalism, and extremism on migration, race, and gender. The second Trump administration has renamed the TSC to focus on broadly defined threats. At a March 2026 congressional hearing, FBI Director Kash Patel said the TSC has seen a double-digit increase in biometric capabilities and intelligence production. Civil liberties organizations have long criticized the ease of adding names to the watch list and the difficulty of removal, and audits have repeatedly found errors.
Minority report: FBI seeks AI for political watch list →
Most wearables lack transparency reports and end-to-end encryption, EFF finds
The Electronic Frontier Foundation reviewed public-facing policies of ten wearable companies and found that only Apple and Google publish transparency reports, and only Apple offers end-to-end encryption for health data. Around 40 percent of people in the United States own a commercially available wearable health device, and these devices have no special health-related privacy protections. Companies can collect and share data with third parties for marketing, to influence insurance rates, or for their own purposes such as training AI models. Law enforcement has used wearable data in cases, with heart rate and step information determining individuals’ whereabouts.
Apple, Google, and Whoop promise in publicly available documentation to notify users of law enforcement requests, and Oura added such a promise in a June 2026 privacy policy update. No other companies publicly state a policy around notification or transparency reports. The Apple Watch, at least for data stored in the Health app, is the only popular fitness wearable that supports end-to-end encryption, enabled by default. No other popular consumer health wearable offers end-to-end encryption for data it collects and stores online. Most companies instead offer encryption in transit and at rest, meaning they can still see and use the data. The EFF recommends companies publish transparency reports and offer end-to-end encryption or local-only storage options.
Signal drops phone number requirement, but metadata remains a risk
Signal is ending its requirement that every account be tied to a phone number, with code commits showing backend infrastructure for accounts without phone numbers. The phone-number-free path will require a one-time payment instead of SMS verification, according to AboutSignal. The two account types are permanent and distinct, with no pathway between them. Signal CTO Ehren Kret said phone numbers currently function as a cost barrier to bulk account creation, and the payment model is intended to replace that economic friction. Phone-number-based registration has structural liabilities, including SIM-swap attacks and disclosure of phone numbers to law enforcement.
Ethereum co-founder Vitalik Buterin welcomed the change but argued it does not address the deeper problem of behavioral metadata, now exploitable by AI at scale. Researchers at the University of Vienna and SBA Research documented a metadata exploitation attack nicknamed Careless Whisper that exposes behavioral metadata on Signal and WhatsApp without breaking end-to-end encryption. Signal deployed stricter rate limiting in its December 2025 update, providing partial protection, but neither company has implemented a protocol-level fix. Buterin concluded that phone-number-free registration is worth pursuing for operational improvements even if it yields no additional privacy gains, but genuine privacy remains technically unsolved at Signal’s scale.
Signal Removes Phone Numbers; AI Identifies Users by Message Patterns, Not IDs →
Flock pitched turning Uber and Lyft drivers into mobile surveillance network
Flock Safety pitched a plan to convert hundreds of thousands of Uber, Lyft, and delivery drivers into a mobile extension of its license plate reader surveillance network, according to a company presentation obtained by 404 Media. The document describes equipping driver vehicles with dashcams capable of scanning license plates along their routes, expanding Flock’s network beyond its fixed pole-mounted cameras. The presentation centers on a proposed partnership with Nexar, a dashcam maker whose devices are marketed to rideshare drivers and commuters.
The material was shared with 404 Media by a Georgia resident who obtained it through a public records request, after Flock presented it to that state’s attorney general’s office. The presentation cites plans to draw on roughly 350,000 Uber, Lyft, and other delivery devices for the network. Flock told 404 Media the Nexar deal was never actually put into place. It remains unclear whether Uber, Lyft, or their drivers would have known their vehicles were collecting this data. Uber, Lyft, and Nexar did not respond to requests for comment.
Flock pitched turning Uber and Lyft drivers into a mobile surveillance network →
USA Today Co. partners with Palantir to analyze audience data
USA Today Co., the nation’s largest newspaper chain, announced a partnership with Palantir to analyze and monetize user behavior. Chairman and CEO Mike Reed told investors he expects the partnership to strengthen how the company collects, connects and activates audience data to drive more effective and faster monetization. USA Today Co. owns more than 200 local newspapers along with its national daily. The partnership comes as search traffic continues to fall, with the company reporting 158 million unique visitors in the second quarter, down from 180 million in the first quarter.
Palantir has faced controversy for providing technology to Immigration and Customs Enforcement, the U.S. Department of Defense, and the Israeli military. Other media companies that have partnered with Palantir include Axel Springer and Fox News. Reed told investors that all of the company’s data remains its data, and the partnership leverages Palantir’s software to turn anonymous interactions into known relationships. Roberts noted that World Cup coverage generated 97 million pageviews, with search driving nearly 65 percent of that traffic. Reed said he could foresee turning off scraping or making content unavailable for search engine links if a fair licensing deal with Google cannot be reached.
Supreme Court seeks Centre’s response on RTI amendments via data protection law
The Supreme Court sought the Centre’s response on pleas challenging amendments made to the Right to Information Act through the Digital Personal Data Protection Act. The pleas challenge the amendment to Section 8(1)(j) of the RTI Act, which deals with exemptions from disclosure of personal information. The provision was amended by Section 44(3) of the DPDP Act in 2023 to alter how personal data and privacy exemptions are handled in government information requests. The amendment removes key qualifiers and the larger public interest override text, making personal information broadly exempt from public disclosure.
Senior advocate Vrinda Grover said the amendment alters the earlier provision by removing safeguards that balanced privacy concerns with the public’s right to know. Advocate Prashant Bhushan said the balance between the right to information and the right to privacy had already been settled by the top court in a judgment, and that balance has now been dismantled. He said the amendment could result in denial of access to information such as pending charge sheets against public officials or details relating to welfare schemes merely because they could be classified as personal information. The solicitor general informed the bench that the Centre would file its reply within another two-three weeks.
Google tightens Street View blurring requests with new address rules
Starting in July 2026, Google will require more precise information for requests to pixelate properties in Google Street View, according to the Hamburg Commissioner for Data Protection and Freedom of Information. General requests for pixelation will no longer be sufficient; applicants must provide at least the full address of the affected property. For multi-family buildings, additional details such as the floor or a description of the apartment may be required. The new guidelines aim to enable clear identification and prevent misuse, such as applications for buildings or apartments not owned by the applicant.
The fundamental right to pixelation remains unchanged, and owners and tenants can still request permanent blurring of their house facade. Google generally does not require proof of ownership or a rental agreement. The Hamburg data protection officer advises applicants to disclose as little personal information as possible when submitting documents, including redacting third-party names and account data. Submitting an ID card is expressly advised against, despite Google’s statement that submitted documents are deleted within 60 days. The automatic pixelation of faces and license plates remains unchanged.
These Rules for Blurring Now Apply to Google Street View →
Age verification laws are building the internet’s next identity layer
The U.S. House passed the Kids Internet and Digital Safety Act on June 29 with bipartisan support, and E.U. negotiators held what was billed as the final trilogue on Chat Control 2.0 the same week. Both bills retreated on their most-contested measures but retained mandatory age verification. To confirm a visitor is over 18, a platform must check the age and usually the identity of everyone who arrives, including adults. Roughly half of U.S. states enforce age checks, most demanding a government ID or face scan uploaded to each site, with rules differing state by state.
The E.U. is consolidating around a privacy-preserving model: its own age-verification app lets a user prove they are over 18 without revealing anything else. A single vendor reportedly powers age checks for around 60 percent of the websites that require them. Laws mandating verification rarely mandate the method, leaving it to whichever vendor is cheapest and most invasive. The precedent cited is the cookie banner, which resulted from rules that specified the goal of consent but not the mechanism. The U.S. bill heads to a skeptical Senate, and Chat Control 2.0 negotiations continue over the summer. Settling age verification by defaulting to ID uploads into centralized databases would set the template for how A.I. agents prove themselves.
Age Verification Is Building the Internet’s Next Identity Layer →
Chatbots can infer personal details by connecting conversations, test shows
Chatbots such as ChatGPT and Gemini can infer personal details about users by connecting information across many conversations, beyond what users explicitly share. A regular user who had only disclosed surface-level details, such as being a father seeking baby gear recommendations and drywall patching instructions, tested prompts asking what the chatbots had guessed about them. The user was perturbed by the insights the chatbots had gathered from connecting the dots across conversations. The experiment took place in San Francisco, and the findings were reported on Aug. 9, 2026.
4 prompts that can tell you what chatbots really know about you →