HeadFlash

Privacy

Microsoft Signs 30-Page Student AI Privacy Deal as New Mexico Tests Facebook

Microsoft becomes first major AI developer to accept binding school privacy standards, while New Mexico opens a Cambridge Analytica-linked trial against Facebook.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Microsoft Adopts Binding Student AI Privacy Standards in Deal With Teachers Union-Backed Academy

Microsoft has agreed to legally binding privacy and oversight standards for AI licenses in schools through a 30-page memorandum of agreement with the National Academy for AI Instruction in New York City, making it the first major AI developer to do so. The academy was created in July through a five-year, $23 million partnership between the American Federation of Teachers and Anthropic, Microsoft, and OpenAI. AFT president Randi Weingarten said the union is still negotiating with Anthropic and OpenAI to adopt the standards for their education products, and wants them to become an industry standard while pressing federal and state governments to adopt legal standards for AI in education. She said federal privacy laws protecting health and education data never envisioned AI, so in the absence of such protections tech companies need to take responsibility for products marketed to students, educators, and communities.

The standards will not apply automatically. As of Nov. 1, school districts can ask to add the new language to new or existing contracts with Microsoft products. Microsoft vice chairman and president Brad Smith said the agreement needs teeth, including audit and legal enforcement provisions. The standards use a deliberately broad definition of student data, covering directory information such as names, grades, and behavioral records, plus writing prompts, memory files, work outputs, and data like keystrokes or eye-tracking that could reasonably identify or link to students. De-identified telemetry about how students and teachers use the tools cannot be used to train AI models or create advertising, student profiles, or infer student behavior, but can be used for debugging, security issues, or product improvement. Research suggests de-identifying data does not guarantee someone can never be identified, and studies show AI models can often re-identify people from anonymized data by cross-referencing background facts, writing styles, and inferred information.

Under the agreement language, aside from specific safety-related data, student, educator, or customer data could not be used to train or improve AI models. All data, including that processed by third-party vendors like Khanmigo or PowerSchool, would have to be encrypted with access controls, independently security tested, and backed by breach response plans. Microsoft would have a permanent responsibility to alert customers and mitigate breaches even after a contract ends. Tools would minimize unneeded data collection, with higher-risk tools like biometrics, memory, profiling, and tracking requiring additional review. Students and customers would control export, retention, and deletion of their data, which could not be sold for advertising or product development. Students and families would get plain-language guides, AI tools must provide fair access for students with special needs, and AI companions that simulate human relationships would be explicitly banned. Schools holding a Microsoft license would get notice and control over new features and data use, could export data to switch providers, and breaches would have to be reported within 72 hours and fixed. Anthropic has not officially signed the agreement but said in July it was working with AFT to align its terms and privacy practices with the standards. Michael Mulgrew, president of the United Federation of Teachers, said student privacy was a grave concern the new standards start to address, but he still supports New York City’s one-year ban on student use of AI tools in elementary, middle, and most high schools.

Microsoft Agrees to New Student Privacy Protections for AI. How Ironclad Are They? →

New Mexico Trial Opens Over Facebook Data Privacy in Cambridge Analytica Fallout

Testimony began Wednesday in a trial against Facebook alleging a breach of data privacy. The New Mexico lawsuit stems from the Cambridge Analytica data-breach case. A recorded deposition of Meta founder and CEO Mark Zuckerberg was played for jurors on March 4 in Santa Fe. The trial puts Facebook’s data privacy record under direct scrutiny in a state courtroom, with the company’s chief executive appearing by video rather than in person.

New Mexico trial tests Facebook’s data privacy record →

Apple Watch Series 12 Adds Conversation Recording and Ambient Siri Recap

Apple announced the Apple Watch Series 12 at its fall event, the first hosted by CEO John Ternus, alongside the foldable iPhone Duo. The watch includes an AI-infused Siri and features marketed under the name Audio Intelligence within the Apple Intelligence umbrella, relying on Apple’s latest AI models. Live Rewind lets Apple Watch Series 12 owners double-press the digital crown to get a transcript of the last 15 seconds of any conversation. Ron Huang, Apple’s VP of sensing and connectivity, said the feature is useful for recalling a book recommendation, a colleague’s idea, or something not heard the first time. Siri Recap uses ambient listening to capture summaries, key points, and notes from a user’s daily conversations; users can keep it always on or set it to turn on at specific times each day.

Huang said the raw audio will be completely inaccessible, even to Apple, and the feature will not identify or attribute speakers. Apple said in its press release that the watch will play an audible chime when Live Rewind is activated so people nearby can hear they were recorded and transcribed. Apple did not specify whether Siri Recap will have a similar function to alert bystanders. Meta Glasses, which also feature an LED light to indicate recording, have been dubbed pervert glasses online, and users circumvented that protection. Earlier this year, the NYPD counterterrorism unit reportedly warned in a memo that the glasses could be used for surveillance. Buyers of such technology may consent to being monitored, but bystanders they record do not necessarily consent.

If Meta Glasses Freak You Out, Wait Until You Hear About the New Apple Watch Features →

Border Patrol Predictive Teams Used Financial Data to Prompt Traffic Stops, Investigation Finds

A 404 Media investigation has uncovered previously unreported Border Patrol units called Predictive Intelligence Targeting Teams, or PITT, which analyze information about Americans and pass findings to local law enforcement, enabling stops of people the federal government considers potentially suspicious even when they are not suspected of a specific crime. In one example, Kyle William Olson was driving across Montana in May when Border Patrol analyst Matthew Phelps reviewed law enforcement-sensitive databases and identified what he described as financial activity patterns commonly associated with illicit narcotics activity, and also reviewed Olson’s previous arrest and criminal history. Phelps sent that information to Montana Highway Patrol Sgt. James Beck as part of what Phelps described as general interdiction efforts, and Beck subsequently stopped Olson, officially citing an obstructed license plate. Officers made Olson get out of his vehicle, tested his blood, and charged him with driving under the influence; authorities later charged him with possession with intent to distribute marijuana found in his vehicle.

Exactly what financial information Border Patrol was examining remains unclear. Customs and Border Protection declined to tell 404 Media what financial activity it monitors or whether it obtains warrants for that information, saying it does not discuss its specific analytical methods, data sources, targeting criteria, investigative techniques, system capabilities, or deployment details. The agency’s refusal to explain the underlying data is significant because the government apparently does not need to tell the officer conducting a traffic stop why someone was originally flagged; in Olson’s case the officer could point to an obstructed license plate as the stated reason for the stop while the financial analysis that prompted the investigation remained hidden. The PITT program is not limited to Montana. 404 Media identified teams in Border Patrol’s Spokane Sector, which covers the border with Canada, and its Laredo Sector, which covers the border with Mexico. CBP operates 20 sectors nationwide but declined to say whether additional PITT teams exist.

Rob Frommer, a senior attorney at the Institute for Justice, told 404 Media that combining mass surveillance with predictive policing is a recipe for tyranny, arguing that programs like PITT treat Americans as potential suspects rather than citizens. The alleged mechanics of the Olson stop have a name: parallel construction, a law enforcement technique in which investigators receive information from a sensitive or secret source, then create a separate investigative trail that conceals how the investigation actually began. The practice previously received attention in 2013, when Reuters published an investigation into the Drug Enforcement Administration’s Special Operations Division; according to that report, the DEA unit was passing intelligence from sources including the NSA to ordinary law enforcement agencies, and agents were instructed to conceal the origin of the information. Jake Laperruque, deputy director of the Security and Surveillance Project at the Center for Democracy & Technology, told 404 Media that genuine probable cause cannot be synthetically generated, arguing that Border Patrol appeared to be using parallel construction to conceal the reason behind the traffic stops. The government’s ability to obtain and analyze information held by financial institutions and other data custodians is rooted in decades-old American law. The third-party doctrine generally holds that people have a diminished expectation of privacy in information they voluntarily provide to another party, a principle the Supreme Court established in cases including United States v. Miller, a 1976 case involving bank records, and Smith v. Maryland, a case regarding telephone records.

The U.S. Government Is Using Your Financial Data to Decide Who Gets Pulled Over →

Inside Jammertest, Norway’s Open-Air Effort to Stress-Test GPS Against Jamming and Spoofing

Harald Hauglin is chief engineer of time and frequency metrology at the Norwegian Metrology Service and a participant in Jammertest, an annual open-air testing event hosted by Norwegian authorities on Andøya, a remote island 300km (186 miles) north of the Arctic Circle. The 2024 event was the third official year of Jammertest and was held in the village of Bleik. Its purpose is to test commercial GNSS receivers against intense, artificial interference, modelling the event on white-hat hackathons, with tests conducted openly and results shared among government and commercial attendees on the final night. Global Navigation Satellite Systems transmit ultra-accurate time in addition to navigation signals, and power grids, telecommunications networks, stock markets and transit services depend on that synchronisation. Satellite transmissions are weak and can be overwhelmed or hijacked by stronger signals. Since Russia’s full-scale invasion of Ukraine, such interference has risen dramatically. In May, an RAF plane experienced GPS jamming near the Russian border, and in September 2025 the Swedish Transport Agency said interference was a daily occurrence. Norway’s government is among several preparing for GNSS becoming a strategic vulnerability.

Two main kinds of GNSS interference exist: jamming, which overwhelms signals so the service is unavailable, and spoofing, which hijacks radio waves to offer a false location and time to a receiver. The two most dangerous attack scenarios are extended jamming, a sustained total wipe-out long enough to run down back-up timing and cause knock-on issues, and a slow-burn, sophisticated spoofing attack that goes unnoticed or uncontained, preventing back-up systems from activating. How long a power grid or other digital system can remain synchronised without GNSS depends on how much a government or company spends on land-based clocks and fibre optic cables to transfer time with extreme precision. At the 2024 Jammertest, two test flights were conducted on the first afternoon: a Norwegian rescue helicopter and a small plane flown by a pilot from Eurocontrol, the European aviation safety body. GNSS manipulation fed false information to receivers on both flights, creating location tracks that did not reflect the actual flight paths. The helicopter’s location on the flight tracker appeared to move in overlapping, panicked swirls, while Eurocontrol’s test plane showed odd, paperclip-like patterns with extreme turns, though the plane had flown wide, graceful loops above the town. On the second morning, Hauglin and colleagues gradually raised the power of spoofing equipment over 40 minutes, strengthening a decoy signal; a beacon marking their location on a Google Maps display moved out into the Norwegian Sea. Clock drift caused by interference was tracked in nanoseconds by comparing GPS time to an uninterrupted reference time delivered via fibre-optic cables to a GNSS receiver on the other side of a mountain, safe from interference.

Alternatives to GNSS are being proposed or developed. White Rabbit, a precision timing system developed at Cern in Switzerland, can deliver time accurately to less than a nanosecond, using fibre optic cables and atomic reference clocks instead of satellites, and is much harder to hack. Dana Goward, co-founder of the Resilient Timing and Navigation Foundation, who has campaigned for policies to protect GPS since 2013, said there is no silver bullet and a combination of systems is needed. In 2024, Goward said spoofing was only going to get worse because it is cheap and easy, and that one of the biggest risks could come from other GNSS systems themselves. Tomas Levin, senior engineer for the roads administration and one of the organisers of Jammertest, said the event’s openness is partly intended to show that Norway is becoming more resilient, adding: So come on, Russia, go ahead.

On a remote island, these GPS hackers are preparing for an invisible war →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches