Privacy
FBI biometric database exemption draws civil liberties pushback
FBI seeks to strip Privacy Act protections from its biometric mega-database as states move to mandate age checks at the operating system level.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FBI moves to exempt biometric mega-database from Privacy Act rules
The FBI has proposed exempting its Next Generation Identification system from parts of the Privacy Act, a move that would deny individuals the right to know what data the bureau holds on them and eliminate its obligation to correct inaccurate records. NGI, assembled since 2008, contains faces, fingerprints, iris scans and tattoos on tens of millions of people, collected not only during arrests but also for immigration, background checks and state licensing. The Government Accountability Office criticized the FBI for hiding information about the scope of its face recognition program, and the system has unresolved accuracy flaws that may disproportionately affect communities of color. EFF joined scores of civil liberties organizations in filing comments opposing the waiver.
No Privacy Rollback for the FBI’s Biometric Mega-Database | EFF Action Center →
Three US states pass laws forcing operating systems to collect user ages
California, Colorado and Illinois have passed laws requiring operating systems to collect users’ ages, with California’s Digital Age Assurance Act taking effect Jan. 1, 2027. It applies to closed-source systems including Windows, macOS, Android and ChromeOS, requiring age prompts during setup and sharing a bracket with apps: under 13, 13-16, 16-18, or over 18. Developers are deemed to have actual knowledge of the age range, creating legal duties under COPPA. Colorado’s SB26-051 takes effect July 1, 2028, and Illinois’ HB5511 on Jan. 1, 2028. EFF’s Aaron Mackey expects compliance to resemble age verification in practice, potentially requiring a credit card, facial scan or government ID.
Your Computer Might Demand Your Age Soon, No Matter Where You Live →
OpenAI contractors manually review ChatGPT chats under Project Lily
OpenAI uses hundreds of contractors under a program called Project Lily to manually review real ChatGPT conversations as part of model evaluation, according to records obtained by 404 Media. The workers, called prompt reviewers, examine anonymised conversations to check whether answers fit the prompt and to flag excessive AI-speak, condescension and sycophancy. Guidelines forbid the bot from acting human or sharing personal details. One reviewer called the job very rote but noted pay above $50 an hour. Logs undergo a process intended to remove identifying information, but OpenAI acknowledged some sensitive details can still get through, especially in shorter sessions. OpenAI updated its opt-out guidance but did not mention human contractors reviewing transcripts.
OpenAI Has Hundreds of Contractors Reading Your ChatGPT Chats Under ‘Project Lily’ →
Hackers extract Flock Safety camera data, exposing tracking capabilities
Hackers from a collective called stegan0gram removed a Flock Safety camera, copied nearly all its stored data and shared the files with 404 Media and WIRED. They recovered an encryption key stored on the device, unlocking videos of thousands of vehicle detections. Analysis showed the software explicitly detects people as well as vehicles, plates and bicycles. Logs recorded about 21 days of activity, photographing roughly 50,200 vehicles and generating about 1.6 million images, with a typical day logging around 3,300 vehicles. The plate detector sometimes mistook bumper stickers and dealership frames for plates. Flock said the removal was illegal, maintains a vulnerability disclosure policy and received no report through it. No evidence of face recognition beyond Android defaults was found.
Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People →
Spain’s AEPD receives first report of AI-agent-powered data breach
Spain’s data protection agency, the AEPD, received a notification of an attack allegedly carried out with an AI agent powered by a known large language model. The reporting organization said the agent searched for flaws, logged into its systems and probed applications for additional vulnerabilities. In the final stages, it modified personal data and accessed financial documents. The AEPD has not yet investigated or verified the information. The agency said AI does not create new threats but can increase the speed, scale and adaptability of cyberattacks, and warned that risk management should explicitly account for AI-assisted attacks. It urged stronger digital identity and credential security, noting manual intervention is no longer sufficient.
Spain’s data agency gets first report of AI-powered data breach →