

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
How a court footnote, retention orders, interagency data sharing, and the government's own words reveal what happens when we pour private thought into a chatbot.
Last month, a sentence went viral claiming that if you type into a chatbot, the FBI can get everything. The claim was too broad. The truth may be narrower, and worse.
Worse, because what is at stake is not some dramatic collapse of privacy. It is a daily practice so ordinary that most people do not even register it as exposure. Thought leaves a protected setting, enters a consumer platform, becomes a record, and then falls under rules the user did not write and will almost never see. Catastrophes announce themselves. Habits do not. Habits become infrastructure before the public notices what has changed.
This essay walks through six documents: a footnote, two preservation orders, an executive order on interagency sharing, a national security memorandum, and a budget request. Read one by one, each can be minimized. Read together, they describe an apparatus already in motion, and a desk already inside it.
A conversation is something you have. A record is something someone else keeps. The text box in front of you now performs both functions at once. It feels like conversation. It can become record.
In United States v. Heppner, decided in the Southern District of New York on February 17, 2026, Judge Jed S. Rakoff wrote in a footnote: "But even if certain information that Heppner input into Claude was privileged, he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party."
Read that again, slowly. Speed helps disguise the act.
What happens when the record no longer belongs to the person who created it?
The footnote does not say the attorney-client relationship dissolves because a chatbot exists. It says something narrower, and more unsettling. Whatever Heppner himself carried out of a protected setting and voluntarily shared with Claude could lose privilege the way material shared with any other third party can lose privilege. The room remains protected. What leaves the room may not.
That is old doctrine meeting a new habit. The danger lies in the habit's ordinariness. A doctrine once applied to deliberate disclosure becomes harsher when the third party is a text box millions of people treat as an extension of private thought.
People use consumer chatbots to think through problems, including legal ones. They paste in memos, summaries, draft language, and questions they cannot yet frame in legal terms. Some of that material originated with counsel. Some did not. Not every exchange is privileged. That is not the point. The point is that the text box does not sort those categories for the user, and the user often does not sort them either. The platform feels intimate, immediate, and close enough to thought that the act often does not register as disclosure.
That is the shift. Most users do not believe they are sharing protected material with a third party. They believe they are working privately through a problem. The platform may not honor that distinction. The court may not honor it. The state may not honor it either.
The Heppner footnote may not survive appeal, but the pattern it marks does not depend on its survival. Carpenter v. United States points in a different direction on digital third-party records. A split among district courts is already visible. But appellate uncertainty is not protection in the meantime. Courts sort doctrine on one timetable. Institutions build systems on another. Retention practices, routing rules, and interagency structures can harden before doctrine settles.
The legal tracks must stay distinct. Privilege is not work product. Work product is not Fourth Amendment privacy. Privacy is not retention. Retention is not acquisition. Acquisition by warrant is not acquisition by administrative subpoena or interagency sharing. The sequence that follows does not require those categories to collapse. It requires only that, in practice, they begin to converge in ways that steadily weaken user control.
A ruling declaring that every chatbot exchange destroys privilege would trigger immediate alarm. A footnote this quiet does not. That is why the narrower reading is worse. It marks an ordinary act, repeated every day by people who think they are thinking privately when, in legal effect, they may be disclosing.
The public paraphrase overstated the law. The law understated the habit. Once that shift comes into view, the next question follows: What happens when the record no longer belongs to the person who created it?
The Heppner footnote did not arrive alone. It arrived inside a pattern. The pattern matters more than the sentence.
Courts are sorting several adjacent questions the public keeps collapsing into one. One week before Heppner, in Warner v. Gilbarco, the Eastern District of Michigan rejected the claim that using ChatGPT to work through litigation material automatically destroyed work-product protection. Roughly six weeks later, Morgan v. V2X in the District of Colorado widened the split rather than closing it, recognizing Rule 26(b)(3) protection for AI-assisted material prepared by a pro se litigant while still imposing disclosure obligations and cautioning against uploading confidential information into mainstream AI systems.
Read together, these cases do not settle AI in the abstract. They suggest that courts are sorting channels, control, supervision, and institutional setting. Where the law sees counsel, protective orders, and defined litigation materials, it can still imagine a protected path. Where it sees voluntary disclosure into a consumer platform outside counsel's direction, the protection thins. A law firm inside a controlled environment gets one reading. A person at a kitchen table with a monthly subscription gets another. Ordinary users behave as though the boundary were settled in their favor. It is not. Uncertainty does not reduce the risk. It enlarges it.
Then the preservation orders deepen the problem. Once material becomes platform record, the user no longer controls the baseline that governs how long it exists or when it can be reached.
People still imagine their chat history exists inside a promise. It does not.
On May 13, 2025, in New York Times v. OpenAI, Judge Ona Wang entered a preserve-and-segregate order covering a vast population of user logs. On January 5, 2026, Judge Sidney Stein affirmed production of a 20 million de-identified log sample. His reasoning matters as much as the scale. He wrote that users' privacy interests in that material were weaker than in wiretapped phone calls because the users had voluntarily disclosed the contents to a platform that retained them in the ordinary course of business.
The point is not that one company lost a fight. The point is that deletion baselines can change outside the user's control. They can change in litigation the user is not party to, in a courtroom the user has never heard of, without notice to the person whose records are being kept. The later announcement that the broad preservation obligation ended does not erase that point. It confirms it. The baseline moved once. It can move again.
Even if the Heppner footnote falls on appeal, the preservation and retention architecture does not fall with it. Privilege doctrine is one track. Retention defaults are another, governed by platform terms, contract law, litigation holds, and administrative process. The constitutional fight may proceed in one courtroom while the records keep being kept in another.
Retention exposure is not uniform across users. When OpenAI's broad preservation obligation was in effect, it excluded Enterprise accounts, Edu accounts, and API customers who had contracted for Zero Data Retention. The organizations and professionals with resources to buy safer configurations could obtain them. Ordinary users on consumer accounts could not.
That stratification is a structural feature of the platform layer, not an accident of one lawsuit. Law firms can buy protected configurations. A person at a kitchen table with a monthly subscription cannot. Before the first subpoena arrives, before the first interagency route opens, before any category written into National Security Presidential Memorandum-7 (NSPM-7) is applied to anyone, the exposure is already stratified by who can afford which tier. That stratification will track the sorting that follows.
Retention is not government acquisition. It is the prior condition that makes acquisition possible. People still imagine their chat history exists inside a promise. It does not. It exists inside a current default, and defaults are fragile. A judge can change them. A litigation hold can change them. A production order can change them. The user often learns that only after the fact, if at all. Once a record can be kept, the next question is how it begins to move.
On March 20, 2025, the White House issued an executive order with a title that sounds like office management: "Stopping Waste, Fraud, and Abuse by Eliminating Information Silos." The word "silo" sounds bureaucratic and dull. That is part of its function. It makes a structural change sound merely administrative. The key word is "eliminating."
Taken on its own, the order does not compel any single disclosure. Yet it plainly directs movement. It tells agency heads to ensure that designated officials receive full and prompt access to unclassified records, data, software, and IT systems. It authorizes sharing and consolidation within and across agencies. It calls for unfettered access to comprehensive data from state programs that receive federal funding, to the maximum extent consistent with law. The order treats the seams between agencies not as safeguards, but as obstacles. Boring language often carries the heaviest load because it is designed to pass without alarm. Usually, it does.
Administrative routing does not require a courtroom. It does not require a warrant. It requires an interagency agreement and a technical connection. Once that connection exists, records move under rules the user does not see, into hands the user did not anticipate, for purposes the user was never asked to weigh. Quietly at first. Then routinely. Then as a matter of course.
Once a state can create records, keep them, and move them with reduced friction, it no longer waits passively for events to arrive in fully formed cases.
That matters more when other forms of process reduce friction further. Washington Post reporting in February 2026 described the Department of Homeland Security's use of administrative subpoenas at volumes that experts and former staff estimated in the thousands or tens of thousands. American Civil Liberties Union (ACLU) litigation, including Doe v. DHS, added specific challenged cases to that pattern. Administrative subpoenas are not new. What matters is their operational use: speed, breadth, and limited front-end judicial review.
A system that can demand material quickly behaves differently from one that must persuade a judge before the process begins. A system that does not require a judge at the front end is not meaningfully slowed when a judge at the back end issues a clarifying opinion three years later. By then, the records have moved, and the institutional lesson has been learned.
The warrants aimed at journalist Hannah Natanson reveal the same pattern from another angle. Their significance is not that journalists are uniquely vulnerable. It is that Natanson's case was legible. She had a national byline. Her case could be read, tracked, and contested in public.
Most cases will not look like that. Most people caught in expanding process will be organizers, students, immigrants, and members of communities sorted first under every previous expansion of federal attention. They will not have a national employer or a legal defense fund. Their names will not trend. Their records will still move. The unreadable cases are the condition. The visible ones are the narrow window through which the rest of us glimpse it.
Names matter less than architecture. Replace any one official and the route still exists the next morning. The Information Silos order still stands. The subpoena posture still matters. The warrant machinery still works. Personnel matter. Architecture matters more.
Once a state can create records, keep them, and move them with reduced friction, it no longer waits passively for events to arrive in fully formed cases. It gains the practical ability to sort, correlate, and escalate before the public sees any full story. From there, the next question is unavoidable: What kinds of people has the state already told itself to look for?
The most revealing documents in this essay are not leaked. They are posted. The apparatus does not need secrecy for the first stages of this work. It can describe itself in public because the public rarely reads primary documents until the output becomes undeniable.
Start with NSPM-7, issued on September 25, 2025, under the title "Countering Domestic Terrorism and Organized Political Violence." Read that title carefully. "Domestic terrorism" is one phrase. "Organized political violence" is another. The memorandum joins them into a single operational field. A category this wide gives agencies room to sort more conduct, posture, and association than the public usually imagines when it hears the word "terrorism."
The FBI's Fiscal Year 2027 Budget Request, submitted in March 2026, translates that field into administrative appetite. On page 13, the request states that violent conduct in the United States commonly relates to views associated with anti-Americanism, anti-capitalism, and anti-Christianity; support for the overthrow of the US government; extremism on migration, race, and gender; and hostility toward those who hold traditional American views on family, religion, and morality. That ideological enumeration is the budget's own language. NSPM-7 supplies the broader "investigate, prosecute, and disrupt" frame within which it operates. The categories are framed in terms of political disposition and affiliation rather than completed acts.
Broad security language rarely falls evenly. It reaches certain communities first, long before the public agrees on what the category means or whom it is for.
Appetite alone does not move records. A vehicle does. The same request names it: the NSPM-7 Joint Mission Center, composed of personnel from 10 agencies, which the budget says will integrate intelligence, operational support, and financial analysis to proactively identify networks and prosecute domestic terrorist and related criminal actors.
That phrase matters. Proactive identification of networks is not the same as investigating a specific act after a complaint, a tip, or an arrest. The language moves upstream, away from completed acts and toward recurrent motivations, indicia, and network mapping. When the categories guiding that work are framed in ideological and cultural terms, network mapping does not remain confined to the individuals at any given node. It extends outward. That is how categories begin to function as engines. Broad markers, interagency routes, and a budget request for advance identification: That is the combination now on the page.
These documents do not prove that every citizen who holds one or more of these views is already under active federal investigation. They prove something serious enough. They show that the administration has formalized a broader operational category than most citizens realize, paired it with interagency movement of information, and requested funding for proactive identification under that category. The concern is not a proven dragnet. The concern is that the categories, routes, and funding streams are now broad enough to normalize sorting before a complete individualized case exists.
Kash Patel's name appears on a cover page. Stephen Miller, Russell Vought, and Todd Blanche occupy familiar nodes of power. Those offices matter. But the signature is not the explanation. It is the citation. The explanation is the architecture written into policy, budget language, and routing authority. That architecture will outlast the current roster, and most of the litigation currently aimed at one footnote inside it. Once categories are written, routes are built, and funding is requested, somebody meets them first.
In American practice, that somebody is rarely random. Broad security language rarely falls evenly. It reaches certain communities first, long before the public agrees on what the category means or whom it is for. That is not incidental to the history. That is the history.
The recent treatment of students and faculty involved in campus Palestine solidarity shows the first mechanism clearly: label before case. Visa revocations, detention, and removal proceedings have moved ahead of any settled public showing of unprotected conduct. The label comes first. The individualized case comes later, if it comes at all. That is what proactive identification looks like when policy language leaves the page and lands on a life.
The Stop Cop City prosecutions show the second mechanism: association widening exposure. Protest activity, bail funds, and mutual aid networks were drawn into racketeering and domestic terrorism frames that stretched beyond any single completed act. Once the state begins to map relation, exposure no longer stops where conduct stops. It moves through contact, support, and nearness itself.
The newest entry point into an old machinery does not arrive with sirens or boots at the door. It arrives as invitation. It arrives as convenience. It arrives as a blinking cursor.
Standing Rock shows the third mechanism: records and suspicion moving across institutions. Federal agencies, state police, and private contractors shared surveillance functions across the very seams liberal legal culture likes to treat as safeguards. The point is that, in practice, observations, records, and suspicions moved across a cooperative field. The Information Silos order does not invent that logic. It removes more of its friction.
The post September 11 surveillance of Muslim American communities shows the oldest mechanism: population sorting before any specific act. Whole communities were subjected to preemptive scrutiny because of religion, association, and presumed risk. That template did not disappear when the emergency rhetoric faded. It remained ready for new technologies, new authorizations, new words, and new enemies.
Taken together, these examples reveal recurring forms, not isolated abuses: label before case, association widening exposure, records moving across institutions, populations sorted in advance. None of this depends on a future court adopting the broadest possible reading of Heppner. The apparatus already knows how to work on bodies, files, and communities.
What is new is not the appetite to sort, but the route by which sorting begins. The newest entry point into an old machinery does not arrive with sirens or boots at the door. It arrives as invitation. It arrives as convenience. It arrives as a blinking cursor.
That cursor sits in a text box. That is where the sequence begins, not in a courtroom, not in a budget request, not in a raid after the fact. It begins here, at the tips of your fingers.
Once the record leaves your hands, the rest unfolds elsewhere: in retention policies you did not write, in orders you will never see, in routes built to reduce friction, in agencies already widening the categories through which they read the public. What felt private a moment ago enters systems that are not private at all.
By this point, the sequence should be visible. Ordinary use turns thought into record. Record is kept under terms the user does not control. Kept records travel along routes designed to reduce friction. They enter a state that has already begun defining, in public, the kinds of subjects it intends to sort before complete individualized stories arrive. None of those steps depends on whether one district court footnote survives appellate review. Each proceeds under its own authority and on its own timetable.
Once thought becomes record, and record becomes retainable, movable, sortable, the problem is no longer private. It is structural.
That is why civic literacy now matters at a different level. It is one of the few ways a citizen can see the structure before its output reaches him in a form he can no longer mistake. By the time most people encounter the apparatus as event, surprise is no defense. The route already existed. The category already existed. The records already existed.
That is also why the answer cannot be private caution alone. No defensive posture at one desk can interrupt an architecture built at the level of routes, retention, and category. The venues where architecture is contested are collective: civil liberties litigation at organizations like the ACLU and the Electronic Frontier Foundation; investigative reporting willing to read the documents before the output reaches the front page; and legislative pressure aimed at retention, at sharing, and at the scope of process. That is where the sequence can still be slowed. That is where it can still be narrowed. That is where it can still be broken.
The point is no longer just to be cautious at the desk. The point is to understand what the desk now connects to. Once thought becomes record, and record becomes retainable, movable, sortable, the problem is no longer private. It is structural.
The text box may feel like a place to think. It is also becoming a place where thought changes hands.
"The data marketplace where advertisers go to sell ads for a local store should not be the same place the government goes to evade warrant requirements," the Electronic Frontier Foundation asserted.
Digital rights defenders on Wednesday hailed a U.S. congressional committee's approval of legislation that would protect Americans' data from being purchased by intelligence or law enforcement agencies without a warrant.
Reps. Warren Davidson (R-Ohio), Zoe Lofgren (D-Calif.), Jerry Nadler (D-N.Y.), Andy Biggs (R-Ariz.), Ken Buck (R-Colo.), Pramila Jayapal (D-Wash.), Thomas Massie (R-Ky.), and Sara Jacobs (D-Calif.) on Tuesday reintroduced the Fourth Amendment Is Not for Sale Act (FANFSA) in a bid to close a loophole in federal law exploited by spy agencies and police to collect U.S. citizens' phone and other data without obtaining warrants.
On Wednesday, the House Judiciary Committee quickly moved to advance FANFSA.
"Democrats and Republicans on the House Judiciary Committee just made clear that the data broker loophole must and will be closed."
"The Fourth Amendment protects the right to privacy, and it is not for sale," Davidson said in a statement. "Our bipartisan legislation creates needed reform by prohibiting the government from purchasing Americans' data without judicial oversight. Unconstitutional mass government surveillance must end."
Jayapal, who chairs the Congressional Progressive Caucus, said that "the Fourth Amendment protects Americans from unreasonable search or seizure and it is critical that we not let the government sidestep that right by purchasing data."
"Sensitive data that can cover anything from Americans' location data, internet activity, or healthcare data must be protected," she added. "This is a civil rights issue and it's time to ban this practice."
Groups including Demand Progress, Electronic Frontier Foundation (EFF), Electronic Privacy Information Center (EPIC), and Free Press Action welcomed the committee's FANFSA vote.
"Democrats and Republicans on the House Judiciary Committee just made clear that the data broker loophole must and will be closed," Demand Progress senior policy council Sean Vitka said in a statement. "This is a major step forward for privacy in the digital age."
EPIC deputy director Caitriona Fitzgerald called FANFSA "the latest sign of bipartisan support in Congress to tackle the government's warrantless purchase of Americans' personal data, such as location information and internet records, in circumvention of the Fourth Amendment and statutory protections."
Wednesday's vote precedes the highly anticipated debate later this year over potential reauthorization of Section 702 of the Foreign Intelligence Surveillance Act, a sweeping warrantless mandate that has been abused hundreds of thousands of times, including to spy on protestors, congressional donors, journalists, and others. Section 702 is set to expire at the end of the year unless reauthorized by Congress.
From COINTELPRO—a Federal Bureau of Investigation surveillance, infiltration, and disruption program targeting U.S. leftists in which the FBI funded and armed murderous far-right militants to terrorize dissidents—to the War on Terror-era National Security Agency global mass spying exposed by exiled whistleblower Edward Snowden and monitoring of Black Lives Matter and other activists, the U.S. government has a long history of illegal surveillance of its own citizens.
"News outlets have been filled with headlines in the last year of government agencies, from immigration enforcement to the U.S. military, acquiring location data collected about you by smartphone applications," EFF said in a pro-FANFSA petition. "The data marketplace where advertisers go to sell ads for a local store should not be the same place the government goes to evade warrant requirements."
The House Judiciary Committee's FANFSA vote follows the full lower chamber's unanimous approval last week of the Davidson-Jacobs amendment to the 2024 National Defense Authorization Act that would close a loophole used by the Pentagon and NSA to purchase data that would otherwise require a warrant, court order, or subpoena.
U.S. intelligence agencies have long been accused of paying their way around the Constitution to obtain protected location information in bulk, including data from Muslim dating and prayer apps.
"The government should not be able to buy its way out of the Fourth Amendment. Requiring a warrant for any data not only protects our right to privacy, but our freedoms of association, religion, and belief," Free Press Action vice president of policy and general counsel Matt Wood said in a statement.
"This is a protection that must also extend to personal information scavenged by data brokers," he added. "The Fourth Amendment Is Not For Sale Act closes a legal loophole and ensures that law enforcement and intelligence agencies can't do an end-run around the Constitution."
"Unless U.S. surveillance laws get fixed," said one privacy campaigner, "Meta will have to fundamentally restructure its systems."
Facebook and its parent company, Meta, will soon be forced to "fundamentally" change its social media platform's structure, said one advocate following a ruling announced Monday by a data privacy panel in Ireland.
The Data Protection Commission in Ireland, where Facebook has its European Union headquarters, announced that the European Data Protection Board (EDPB) found the tech company liable for a $1.3 billion fine for transferring and storing data from E.U. users to the United States. The company was given six months to return all personal data to data centers in the E.U. and to stop transferring the information, including photos, communications, and information gathered for targeted ads.
The ruling comes three years after the European Court of Justice (ECJ) determined that data sent from the E.U. was not sufficiently protected from government spying in the U.S. The EDPB on Monday said Facebook has refused to comply with that ruling and the General Data Protection Regulation (GDPR), a set of privacy laws passed five years ago.
By transferring and storing the data of millions of E.U. users, Facebook committed "systematic, repetitive, and continuous" infringements of European users' rights, the EDPB found.
"Facebook has millions of users in Europe, so the volume of personal data transferred is massive," said Andrea Jelinek, chair of the EDPB. "The unprecedented fine is a strong signal to organizations that serious infringements have far-reaching consequences."
A number of tech observers said the monetary fine is relatively inconsequential to the $562 billion company, but pointed to the order that Facebook delete "a decade of data" that it's relied on for targeted advertising.
The "imposition of a major fine reflects the company's continuous failure to secure the data of its users and comply with regulators," said the Real Facebook Oversight Board, a coalition of academics, journalists, and civil rights campaigners. "Meta is one of a few large companies that rely on contractual clauses to allow unfettered access to users' data. Fines may not force Meta to change its behavior, but they are a critical reminder that the company has been found, yet again, to have broken the law."
Susan Li, chief financial officer of Meta, told investors last month that the company makes 10% of its worldwide ad revenue from ads in European countries, suggesting it relies heavily on the practices the EDPB has ruled it must end.
Max Schrems, an Austrian privacy activist who won the case that went to the ECJ in 2020 regarding E.U.-U.S. data sharing, noted that "the fine could have been much higher, given that the maximum fine is more than $4 billion and Meta has knowingly broken the law to make a profit for ten years."
However, "unless U.S. surveillance laws get fixed," said Schrems, "Meta will have to fundamentally restructure its systems."
The U.S. and E.U. are currently working out a data sharing agreement to replace the "Privacy Shield" pact that was struck down in 2020.
To enable Facebook and other companies to continue moving information from the E.U. to the U.S., said Schrems, "the simplest fix would be reasonable limitations in U.S. surveillance law" to assure European officials that users will not be put at risk by American spy agencies.
"There is an understanding on both sides of the Atlantic that we need probable cause and judicial approval of surveillance," said Schrems. "It would be time to grant these basic protections to E.U. customers of U.S. cloud providers. Any other big U.S. cloud provider, such as Amazon, Google or Microsoft could be hit with a similar decision under E.U. law."
Congress is set to reauthorize Section 702 of the Foreign Intelligence Surveillance Act (FISA) this year, and the law is a frequent target of privacy advocates who object to the mass collection of geolocation data and other rights abuses.
Without far-reaching changes to surveillance in the U.S., said Schrems, "the long-term solution seems to be some form of 'federated social network' where most personal data would stay in the E.U., while only 'necessary' transfers would continue—for example when a European sends a direct message to a U.S. friend."
Facebook said Monday that it plans to appeal the decision, but Schrems said the company can likely only "delay the payment of the fine for a bit."
"There is no real chance," he said, "to have this decision materially overturned."
While these bills' supporters aim to hold tech giants accountable for not protecting vulnerable communities, one expert warned, "increasing censorship and weakening encryption would not only be ineffective at solving these concerns, it would in fact exacerbate them."
As the U.S. Senate Judiciary Committee considered a series of bills on Thursday, the ACLU and other digital rights advocates warned against federal legislation that would promote censorship, disincentivize protecting users with strong encryption, and expand law enforcement access to personal data.
A trio of ACLU policy experts sent a letter to the committee about three bills: the Cooper Davis Act, the Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act, and the Strengthening Transparency and Obligation to Protect Children Suffering from Abuse and Mistreatment (STOP CSAM) Act.
"These bills purport to hold powerful companies accountable for their failure to protect children and other vulnerable communities from dangers on their services when, in reality, increasing censorship and weakening encryption would not only be ineffective at solving these concerns, it would in fact exacerbate them," said one of the experts, ACLU senior policy counsel Cody Venzke.
Named for a Kansas teenager who died after taking a pill laced with fentanyl, the Cooper Davis Act (S. 1080) would require social media companies and other communication service providers to give federal agencies information about illicit activity related to the synthetic opioid on their platforms.
The EARN IT Act (S. 1207)—which targets Section 230 of the Communications Decency Act—would remove tech companies' blanket liability protection for civil or criminal law violations related to online child sexual abuse material and establish a national commission to craft voluntary "best practices" for providers.
Sponsored by committee Chair Dick Durbin (D-Ill.), the STOP CSAM Act (S. 1199) would, among other provisions, enable survivors of online child sexual exploitation to bring a civil cause of action against tech companies that promoted or facilitated the abuse.
The ACLU warns that the proposals "would undermine free speech, privacy, and security." As the letter explains:
First, they incentivize platforms to monitor and censor their users' speech and interfere with content moderation decisions. Second, they disincentivize platforms from providing end-to-end encrypted communications services, exposing the public to abusive commercial and government surveillance practices and as a result, dissuading people from communicating with each other electronically about everything from healthcare decisions to business transactions. And third, they expand warrantless government access to private data. As longtime champions of privacy, free speech, and an open internet, we strongly urge you to vote against reporting these bills out of committee.
Despite the ACLU's argument that "there are other avenues to protect children, privacy, and safety online that do not lead to increased surveillance, censorship, and policing," the committee on Thursday unanimously advanced the EARN IT Act, spearheaded by Ranking Member Lindsey Graham (R-S.C.).
As Common Dreams reported Tuesday, the Center for Democracy & Technology led 132 other groups—including the ACLU—in a letter to the panel which says: "We support curbing the scourge of child exploitation online. However, EARN IT will instead make it harder for law enforcement to protect children. It will also result in online censorship that will disproportionately impact marginalized communities."
Fight for the Future, another signatory to that letter, tweeted Thursday that "the dangerous, anti-encryption #EARNITAct passed out of committee this morning. We know this bill—it's back from the dead to restrict the internet and make everyone less safe online."
The group also thanked Sen. Alex Padilla (D-Calif.) for entering the coalition's letter about the EARN IT Act into the record.
Representatives from the ACLU, Electronic Frontier Foundation, Equality Arizona, Fight for the Future, Reframe Health and Justice, and Woodhull Freedom Foundation came together with grassroots organizer Melissa Kadri and Sen. Ron Wyden (D-Ore.) on Wednesday for a press conference on some of the internet bills being considered by Congress.
Along with criticizing the EARN IT and STOP CSAM proposals, the event's speakers sounded the alarm about the Kids Online Safety Act (KOSA) and Restricting the Emergence of Security Threats that Risk Information and Communications Technology (RESTRICT) Act.
Specifically naming Bolivia, China, Cuba, Iran, North Korea, and Russia as "foreign adversaries," the RESTRICT Act (S. 686) would empower the U.S. Department of Commerce to "review, prevent, and mitigate information communications and technology transactions that pose undue risk to our national security."
KOSA, which was officially reintroduced on Tuesday, would increase parental controls, force social media platforms to prevent and mitigate certain harms to minors, and require independent audits.
"I'm a parent of a 12-year-old, and I care deeply about my 12-year-old's future. And for me, I want to ask not just what policies will make the internet more sanitized or safer for my child, but what policies governing the internet will lead to the type of world that I want my child to grow up in," said Fight for the Future director Evan Greer.
"That's a world where she has access to human rights, where she has access to accurate life-saving information about issues like mental health and substance abuse, and where she has access to online community," she continued. "And that is true for so many children, particularly LGBTQ kids who are facing unprecedented assaults across the country."
Citing Fred Rogers' philosophy that what can be mentioned can be managed, Greer added that "a lot of these bills are based on the idea that we protect our kids by sequestering them off from discussion of these important topics; unfortunately, we actually know from evidence and data that that harms our kids, and that our kids are safer when they are able to discuss... with their peers and with experts these issues that affect them. These bills would, unfortunately, cut kids off from those resources, and that's why we believe that they will make kids less safe, and not more safe."
Wyden agreed that "these bills are going to make kids less safe." Specifically, he expressed concern about EARN IT and STOP CSAM bills attacking "the single strongest technology protecting kids and families online," warning that "weakening encryption is probably the premier gift you could give to predators and god-awful people who want to stalk and spy on kids."
"I want to make one quick point about the Kids Online Safety Act: Giving extremist governors the power to decide what content is safe for kids is a nonstarter," he said, calling out the GOP leaders of Florida and Texas. "Ron DeSantis and Greg Abbott are using every bit of power they have to go after queer and trans kids, censor information about reproductive health, and scrub basic history about race in America. I'm not about to give them even more power... I urge my colleagues to focus on elements that are actually going to protect kids rather than just handing big quantities of more power to MAGA Republicans to wage a culture war against children."
"I think the most important thing Congress can do to improve the internet for kids and everybody else is to pass comprehensive privacy legislation," Wyden asserted. "This fight... has been the longest-running battle since the Trojan War, and it's time to take on the special interests and get a strong bill passed."
"Kids should never have been used as an engine of profit for Meta, and it's great that the FTC is continuing to act aggressively," said one advocate who urged broader congressional action.
Children's advocacy and government watchdog groups on Wednesday welcomed the Federal Trade Commission's push to implement new protections for youth users of Meta products including Facebook in response to the company allegedly violating a 2020 privacy order.
Calling the agency's action "long overdue," Fairplay executive director Josh Golin said that "for years, Meta has flouted the law and exploited millions of children and teens in their efforts to maximize profits, with little care as to the harms faced by young users on their platforms."
"The FTC has rightly recognized Meta simply cannot be trusted with young people's sensitive data and proposed a remedy in line with Meta's long history of abuse of children," Golin added.
"The FTC has rightly recognized Meta simply cannot be trusted with young people's sensitive data and proposed a remedy in line with Meta's long history of abuse of children."
Jeff Chester, executive director of the Center for Digital Democracy, similarly said that the FTC's move "is a long-overdue intervention into what has become a huge national crisis for young people."
"Meta and its platforms are at the center of a powerful commercialized social media system that has spiraled out of control, threatening the mental health and well-being of children and adolescents," he asserted. "The company has not done enough to address the problems caused by its unaccountable data-driven commercial platforms."
The FTC said in a statement that the tech giant, which changed its parent company name from Facebook to Meta in 2021, "has failed to fully comply with the order, misled parents about their ability to control with whom their children communicated through its Messenger Kids app, and misrepresented the access it provided some app developers to private user data."
The 2020 order, which the social media company agreed to the previous year, came out of the Cambridge Analytica scandal. It involved a $5 billion fine—which critics condemned as far too low—and followed a 2012 order also related to privacy practices.
"Facebook has repeatedly violated its privacy promises," Samuel Levine, director of the FTC's Bureau of Consumer Protection, declared Wednesday. "The company's recklessness has put young users at risk, and Facebook needs to answer for its failures."
The commission specifically accuses Meta of violating both the 2012 and 2020 orders as well as the FTC Act and the Children's Online Privacy Protection Act (COPPA) Rule. Commissioners are proposing a blanket ban against monetizing the data of minors, pausing the launch of new products and services, extending compliance to merged companies, limiting future uses of facial recognition technology, and strengthening privacy requirements.
The changes would apply to not only Facebook but also other Meta platforms such as Instagram, Oculus, and WhatsApp.
The commission voted 3-0 to issue an order to show cause—though Commissioner Alvaro Bedoya also put out a statement questioning whether the agency has the authority to implement some of the proposals. Meta now has 30 days to respond, after which the FTC will make a final decision on whether to move forward with the changes.
In a statement Wednesday, Meta spokesperson Andy Stone took aim at the commission leader specifically, saying that "FTC Chair Lina Khan's insistence on using any measure—however baseless—to antagonize American business has reached a new low."
Stone also claimed that the FTC's attempt to modify the 2020 order "is a political stunt," accused the commission of trying to "usurp the authority of Congress to set industrywide standards," and vowed to "vigorously fight this action."
While praising the FTC effort and blasting Meta, advocates for children concurred with the company's spokesperson on one point: the need for broader U.S. governmental action to address industry practices.
"Amid a continuing rise in shocking incidents of suicide, self-harm, and online abuse, as well as exposés from industry 'whistleblowers,' Meta is unleashing even more powerful data gathering and targeting tactics fueled by immersive content, virtual reality, and artificial intelligence, while pushing youth further into the metaverse with no meaningful safeguards," said Chester. "Parents and children urgently need the government to institute protections for the 'digital generation' before it is too late."
"Today's action by the FTC limiting how Meta can use the data it gathers will bring critical protections to both children and teens," he continued. "It will require Meta/Facebook to engage in a proper 'due diligence' process when launching new products targeting young people—rather than its current method of 'release first and address problems later approach.' The FTC deserves the thanks of U.S parents and others concerned about the privacy and welfare of our 'digital generation.'"
After also applauding the FTC "for its efforts to hold Meta accountable," Golin called on Congress to pass the Children and Teens' Online Privacy Protection Act, or COPPA 2.0, "because all companies should be prohibited from misusing young people's sensitive data, not just those operating under a consent decree."
"Until Congress acts on its promise to ensure privacy for kids and adults online, it's critical that the agency boldly enforces the law."
Public Citizen executive vice president Lisa Gilbert said in a statement that "kids should never have been used as an engine of profit for Meta, and it's great that the FTC is continuing to act aggressively. Until Congress acts on its promise to ensure privacy for kids and adults online, it's critical that the agency boldly enforces the law."
Though backed by some child advocacy groups, a few legislative proposals intended to protect children online—including the Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act and Kids Online Safety Act (KOSA)—have alarmed organizations that warn about endangering digital privacy and free expression, as Common Dreams reported Tuesday.
As Sens. Ed Markey (D-Mass.) and Bill Cassidy (R-La.) on Wednesday reintroduced COPPA 2.0, Fight for the Future director Evan Greer—who has openly criticized the other measures—said that "we think federal data privacy protections should cover EVERYONE, not just kids, but overall this is a bill that would do some good and it does not have the same censorship concerns as bills like KOSA."
"Stop feeding moral panic and pass a real data privacy law to stop Big Tech companies—including TikTok!—from harvesting and abusing our personal data for profit," a new Fight for the Future petition urges lawmakers.
Data privacy and free speech advocates on Tuesday sounded the alarm about "hypocrisy and censorship" as U.S. House Republicans pushed for a bill to effectively ban TikTok, a video-sharing platform created by the Chinese company ByteDance, across the country.
House Committee on Foreign Affairs Chairman Michael McCaul (R-Texas) held a hearing on "combating the generational challenge of CCP aggression," referring to the Chinese Communist Party, after introducing the Deterring America's Technological Adversaries (DATA) Act last week.
Meanwhile, the U.S.-based group Fight for the Future launched a #DontBanTikTok campaign opposing the bill (H.R. 1153).
"If policymakers want to protect Americans from surveillance, they should advocate for strong data privacy laws."
"If it weren't so alarming, it would be hilarious that U.S. policymakers are trying to 'be tough on China' by acting exactly like the Chinese government," said Fight for the Future director Evan Greer. "Banning an entire app used by millions of people, especially young people, LGBTQ folks, and people of color, is classic state-backed internet censorship."
"TikTok uses the exact same surveillance capitalist business model of services like YouTube and Instagram," she stressed. "Yes, it's concerning that the Chinese government could abuse data that TikTok collects. But even if TikTok were banned, they could access much of the same data simply by purchasing it from data brokers, because there are almost no laws in place to prevent that kind of abuse."
According to Greer, "If policymakers want to protect Americans from surveillance, they should advocate for strong data privacy laws that prevent all companies (including TikTok!) from collecting so much sensitive data about us in the first place, rather than engaging in what amounts to xenophobic showboating that does exactly nothing to protect anyone."
Fight for the Future's campaign includes a petition that is open for signature and sends the same message to lawmakers: "I want my elected officials to ACTUALLY protect my sensitive data from China and other governments. Stop feeding moral panic and pass a real data privacy law to stop Big Tech companies—including TikTok!—from harvesting and abusing our personal data for profit."
In addition to sharing the petition and highlighting the inadequacy of U.S. privacy laws, the campaign site notes that the ACLU is also opposing McCaul's bill, and on Sunday sent a letter to him and Rep. Gregory Meeks (D-N.Y.), the panel's ranking member.
"Having only had a few days to review this legislation, we have not included a comprehensive list of all of H.R. 1153's potential problems in this letter," wrote ACLU federal policy director Christopher Anders and senior policy counsel Jenna Leventoff. "However, the immediately apparent First Amendment concerns are more than sufficient to justify a 'no' vote."
"This legislation would not just ban TikTok—an entire platform, used by millions of Americans daily—but would also erode the important free speech protections included within the Berman Amendment," they continued. "Moreover, its vague and overbroad nature implicates due process and sweeps in otherwise protected speech."
The letter explains that 35 years ago, the Berman Amendment "removed the president's authority to regulate or ban the import or export of 'informational materials, including but not limited to, publications, films, posters, phonograph records, photographs... artworks, and news wire feeds' and later electronic media."
In a statement, Leventoff declared that "Congress must not censor entire platforms and strip Americans of their constitutional right to freedom of speech and expression."
"Whether we're discussing the news of the day, livestreaming protests, or even watching cat videos," she said, "we have a right to use TikTok and other platforms to exchange our thoughts, ideas, and opinions with people around the country and around the world."
Notably, Meeks spoke out against the bill during Tuesday's hearing. Reuters reports that the ranking member "strongly opposed the legislation, saying it would 'damage our allegiances across the globe, bring more companies into China's sphere, destroy jobs here in the United States, and undercut core American values of free speech and free enterprise."
"Google cannot allow its online advertising-focused digital infrastructure to be weaponized against women."
That's according to Sen. Ron Wyden (D-Ore.), Rep. Anna Eshoo (D-Calif.), and 40 other progressives in Congress who sent a letter Tuesday to Google CEO Sundar Pichai urging reforms to data collection and retention practices given the anticipated reversal of Roe v. Wade.
While privacy advocates within and beyond Congress have long raised alarm about location data from devices such as cellphones, such concerns have risen in recent weeks since the leak of a draft U.S. Supreme Court opinion signaling the end of Roe, which affirmed the right to abortion.
If the court's decision to overturn Roe is finalized in the weeks ahead, abortion could swiftly become illegal in over half of U.S. states, according to the pro-choice Guttmacher Institute. It is with that knowledge that more than three dozen federal lawmakers are urging changes at Google.
"We believe that abortion is healthcare," states the letter. "We will fight tooth and nail to ensure that it remains recognized as a fundamental right, and that all people in the United States have control over their own bodies."
"That said, we are concerned that, in a world in which abortion could be made illegal, Google's current practice of collecting and retaining extensive records of cellphone location data will allow it to become a tool for far-right extremists looking to crack down on people seeking reproductive healthcare," it continues. "That's because Google stores historical location information about hundreds of millions of smartphone users, which it routinely shares with government agencies."
As the letter details:
While Google collects and retains customer location data for various business purposes, including to target online ads, Google is not the only entity to make use of this data. Law enforcement officials routinely obtain court orders forcing Google to turn over its customers' location information. This includes dragnet "geofence" orders demanding data about everyone who was near a particular location at a given time. In fact, according to data published by Google, one-quarter of the law enforcement orders that your company receives each year are for these dragnet geofence orders; Google received 11,554 geofence warrants in 2020.
Reporting on the lawmakers' demand, Insider noted that "in March, a federal district judge ruled that Virginia police, in serving Google with a geofence warrant to get location data, violated the Fourth Amendment's protections against unreasonable searches."
The outlet added that "Google did not immediately respond to Insider's request for comments."
Highlighting the differences between what data is generally collected from Google's Android devices versus Apple iPhones with Google applications, the letter asserts that "Apple has shown that it is not necessary for smartphone companies to retain invasive tracking databases of their customers' locations."
"While Google deserves credit for being one of the first companies in America to insist on a warrant before disclosing location data to law enforcement, that is not enough," the letter adds. "If abortion is made illegal by the far-right Supreme Court and Republican lawmakers, it is inevitable that right-wing prosecutors will obtain legal warrants to hunt down, prosecute, and jail women for obtaining critical reproductive healthcare."
According to the lawmakers, "The only way to protect your customers' location data from such outrageous government surveillance is to not keep it in the first place."
The digital rights group Fight for the Future echoed that position Tuesday with its own grassroots letter--which is open for signatures--also "calling on the company to stop amassing users' location data, because in a post-Roe world this data will be weaponized against people seeking abortions."
"Google is choosing to amass this data not to improve the experience of users, but to squeeze out a few extra surveillance-driven advertising dollars," Fight for the Future tweeted Tuesday. "And this business model could soon put abortion-seekers in serious danger."
With their dangerous crusade for an anti-encryption bill in Congress all but dead (for now), the FBI and US Justice Department are now engaged in a multi-pronged attack on all sorts of other privacy rights - this time, with much less public scrutiny.
A report from the nonpartisan Government Accountability Office harshly criticized the FBI last week for its little-discussed but frequently used facial recognition database and called on the bureau to implement myriad privacy and safety protections. It turns out the database has far more photos than anyone thought - 411.9m to be exact - and the vast majority are not mugshots of criminals, but driver's license photos from over a dozen states and passport photos of millions of completely innocent people. The feds searched it over 36,000 times from 2011 to 2015 (no court order needed) while also apparently having no idea how accurate it is.
Worse, the FBI wants its hundreds of millions of facial recognition photos and its entire biometric database, including fingerprints and DNA profiles, to be exempt from important Privacy Act protections. As the Intercept reported two weeks ago: "Specifically, the FBI's proposal would exempt the database from the provisions in the Privacy Act that require federal agencies to share with individuals the information they collect about them and that give people the legal right to determine the accuracy and fairness of how their personal information is collected and used."
In Congress, Senate Republicans are pushing for a vote this week on controversial new warrantless surveillance measures that would let the FBI use unconstitutional National Security Letters to get email records and internet browsing history from countless US citizens - without going to a judge or court at all. The Senate leadership is bringing the measure up to vote by invoking the Orlando attack, despite the fact that we know the FBI had no problem surveilling the Orlando killer when he was previously investigated. It is a blatant attempt to exploit the tragedy in order to gain powers the FBI has long asked for (powers, by the way, the FBI is already reportedly using, despite the justice department telling them it's basically illegal).
The justice department, meanwhile, is busy attempting to implement a new rule for the court system that would make it much easier for the FBI to hack into computers worldwide - including those of hacking victims. Using the obscure process for amending the Federal Rules of Criminal Procedure, the department has convinced the courts that they should be able to get one warrant to potentially hack thousands of computers, and shouldn't have to comply with the normal rules involving getting the court order in the jurisdiction where the crime occurred.
As the Electronic Frontier Foundation has noted, "this is a recipe for disaster," and it is being done by circumventing the normal democratic process. Several organizations (including Freedom of the Press Foundation, the organization I work for) have called on Congress to put a stop to it.
Also, in the courts, the Justice Department has continued to argue that the US government doesn't need a warrant to gather Americans' cell phone location information—even though that type of information can give authorities their precise whereabouts 24 hours a day, seven days a week.
The Justice Department convinced the Fourth Circuit Court of Appeals last month to overturn its previous ruling that police need a probable cause warrant to get such information. The court agreed with the justice department that cellphone users don't have a "reasonable expectation of privacy" around their location, even though it is some of the most intimate information that exists, giving law enforcement officials a detailed picture of your life that even your close friends and family may not know.
Last year, the FBI director disingenuously tried to claim that the pendulum "has swung too far" in the way of privacy despite the fact that the agency has virtually unprecedented access to all sorts of information on Americans. If it wasn't clear before, it should be now: they plan on using any means necessary to further erode the rights of hundreds of millions of citizens in their crusade against privacy.
For the fifth year in a row, global internet freedom continued its downward trend in 2015, with more governments censoring information of public interest while simultaneously expanding surveillance and thwarting privacy tools, according to the annual assessment by the U.S.-based Freedom House released Wednesday.
Since June 2014, 32 of the 65 countries assessed in Freedom on the Net (pdf) saw internet freedom deteriorate, according to the nonprofit, which monitors digital rights and advocates for democracy. Notable declines were documented in Libya, France, and--for the second year running--Ukraine, amid what Freedom House describes as "its territorial conflict and propaganda war with Russia."
While the end is the same--increasing erosion of privacy and human rights afforded by a free and open internet--the means have shifted slightly.
"Governments are increasingly pressuring individuals and the private sector to take down or delete offending content, as opposed to relying on blocking and filtering," explained Sanja Kelly, project director for Freedom on the Net. "They know that average users have become more technologically savvy and can often circumvent state-imposed blocks."
According to the report, authorities in 42 of the 65 countries assessed required private companies or internet users to restrict or delete web content dealing with political, religious, or social issues, up from 37 the previous year. Criticism of the authorities was most likely to attract censorship or punishment. At the same time, news about conflict, corruption allegations against top government or business figures, opposition websites, and satire were also subject to online censorship in over one-third of the countries examined.
In fact, the study found that over 61 percent of all internet users live in countries where criticism of the government, military, or ruling family has been subject to online censorship, and over 58 percent live in countries where bloggers or other internet users have been jailed for sharing content on political, social, and religious issues.
Meanwhile, even as governments in 14 of 65 countries passed new laws to increase surveillance and many more upgraded their surveillance equipment, encryption, and anonymity tools crucial to securing freedom of expression were subject to restrictions worldwide.
"Given the mounting concerns over government surveillance, companies, and internet users have taken up new tools to protect the privacy of their data and identity," the report reads, noting that UN Special Rapporteur David Kaye stated in May 2015 that encryption and anonymity are essential to basic human rights.
"Unfortunately," the report continues, "governments around the world have moved to limit encryption and undermine anonymity for all internet users, often citing the use of these tools by terrorists and criminals. Such restrictions disproportionately threaten the lives and work of human rights activists, journalists, opposition political figures, and members of ethnic, religious, and sexual minorities."