Get tomorrow's brief in your inbox
Today: The Supreme Court upheld nearly $200 million in FCC fines against AT&T and Verizon for selling customer location data without consent, ruling 8-1 that the agency's enforcement process does not violate the right to jury trial. The FTC is considering modifying or eliminating X's $150 million 2022 privacy settlement based on the company's petition claiming ownership and management changes render the order obsolete. Meta deployed facial recognition code to its surveillance glasses, potentially creating a distributed consumer surveillance network despite a prior $650 million BIPA settlement.
Supreme Court Upholds FCC Location Data Fines
The Supreme Court ruled 8-1 in FCC v. AT&T that the Federal Communications Commission acted legally when it issued $196 million in fines against telecommunications companies for sharing consumers' location data without consent. The court held that the fines, $57 million against AT&T and $47 million against Verizon (with T-Mobile separately fined $92 million), did not violate the companies' Seventh Amendment right to jury trial because the FCC's forfeiture orders are not conclusive determinations. Chief Justice John Roberts wrote that before the government can require payment, the Department of Justice must file a lawsuit in federal court and prove its case to a jury. The FCC alleged the companies sold location data to aggregators who peddled it to third-party data brokers, and that the companies failed to obtain valid customer consent or take reasonable measures to protect the information. Sen. Ron Wyden's investigation revealed a government contractor established a self-service website law enforcement used to obtain location data for any phone in the country without court orders.
$9.4M Fandango Settlement Over Fee Disclosures
Fandango agreed to pay $9.4 million to settle class action claims it failed to disclose convenience fees and violated laws regarding expiring promo codes. The settlement addresses allegations that consumers were not adequately informed about mandatory fees added during ticket purchases and that promotional codes expired without proper legal basis. Class members must submit claims by August 17, 2026 to receive compensation.
$2.52M Onsite Mammography Data Breach Settlement
Onsite Mammography agreed to pay $2.52 million to settle class action claims following a data breach affecting patients' protected health information. Individuals affected by the breach may be eligible for payments through the settlement fund. The case represents ongoing litigation over healthcare providers' obligations to safeguard patient data under HIPAA and state data protection laws.
State Farm $8.8M Washington Settlement
State Farm Mutual Automobile Insurance agreed to pay $8.8 million to Washington state policyholders to resolve claims it failed to pay diminished value on vehicles involved in accidents. The settlement addresses allegations that the insurer systematically underpaid claims by not accounting for reduced vehicle value after accident repairs.
FTC Considers Modifying X's $150 Million Privacy Order
The Federal Trade Commission announced it is considering modifying or setting aside its 2022 settlement order with Twitter (now X) that imposed a $150 million fine and prohibited the company from profiting from deceptively collected data. X filed a petition arguing the settlement terms are unfair because the order was issued against a company that no longer exists under different ownership (Elon Musk acquired Twitter in October 2022), the employees responsible for the violations no longer work at X, and the company has established a new privacy program. X claims the order imposes millions in costs to address obligations already required by other privacy regulations and that modifying the order is critical to advancing American AI leadership and First Amendment principles. The May 2022 settlement alleged Twitter suggested users provide phone numbers and email addresses for account security but sold the data to advertisers for targeted ads, affecting more than 140 million users and violating a 2011 FTC order. The public comment period ends July 2, 2026.
Meta Deploys Facial Recognition to Surveillance Glasses
Meta has deployed facial recognition code to millions of its always-on surveillance glasses, according to Wired reporting confirmed by EFF's Threat Lab through static analysis. The functionality stores faceprints as 2,048 numbers representing facial features and compares every new face in the glasses' field of view to existing faceprints in the user's database. While the code is present and active, it has not yet been exposed to consumers. Researchers confirmed the feature works when manually adding faces to the app database. Meta previously paid $650 million to settle a BIPA lawsuit challenging mass facial recognition of photos posted to its platform, a feature it subsequently shut down. Internal Meta documents reportedly indicate the company wanted to launch facial recognition during a dynamic political environment when civil society groups would be focused on other concerns.
Flock Surveillance Cameras Covered With Garbage Bags
Cities are covering Flock Safety automated license plate reader cameras with garbage bags because police are unsure whether terminated cameras remain active and cities don't know if they are authorized to remove the equipment. Dayton, Ohio covered its Flock cameras after months of resident outrage and a scandal involving data sharing for immigration enforcement. The issue highlights problems with third-party surveillance infrastructure where contract termination doesn't guarantee cameras are actually shut off and hundreds of law enforcement agencies nationwide may retain access to cameras a city has determined cannot be used. Menominee, Wisconsin reported Flock cameras were activated without city council approval. Evanston, Illinois previously covered cameras with garbage bags before ordering Flock to remove them.
Pulte Appointment Raises Section 702 Reform Concerns
President Trump appointed William Pulte, director of the Federal Housing Finance Agency with no intelligence or military experience, as acting Director of National Intelligence. The appointment underscores concerns about Section 702 of the Foreign Intelligence Surveillance Act, which faces a reauthorization deadline of June 12, 2026. Section 702 allows the NSA to collect communications from overseas targets, including communications with Americans, and store them in massive databases accessible to the FBI without warrants. EFF highlights that Pulte has used his FHFA position to accuse political targets of mortgage fraud based on private government data, raising concerns about potential misuse of intelligence databases. Pulte's accusations against NY AG Letitia James, Sen. Adam Schiff, Federal Reserve governor Lisa Cook and others have not led to criminal charges. As acting DNI under the Vacancies Act, Pulte can serve approximately seven months without Senate confirmation and would have access to all classified information the Intelligence Community holds, including Section 702 databases containing information about Americans.
EFF Testifies on Government AI Safeguards
EFF Senior Policy Analyst Dr. Matthew Guariglia testified to the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection that governments must not adopt AI technologies without strong safeguards to protect Constitutional rights. He testified that generative AI used for mass government surveillance supercharges unconstitutional violations of civil liberties and that government secrecy combined with proprietary technology black boxes prevents the public and lawmakers from knowing when AI models make mistakes. Guariglia cited examples including false legal citations and a major AI error that sent DHS recruits to the field without proper training, noting classification likely prevents a thorough accounting of more consequential failures. He stated the question is not how to rein in AI but how to rein in agencies that would unleash AI on the American public.
California AB 412 AI Training Disclosure Bill
California lawmakers are again considering AB 412, a bill requiring AI developers to identify and disclose copyrighted works used to train generative AI systems. EFF submitted an opposition letter to the California Senate Privacy Committee arguing the bill demands information that often does not exist and cannot realistically be obtained. The bill requires developers to cross-reference massive batches of online data against copyright systems not designed for such verification, with no machine-readable list of copyrighted works at the U.S. Copyright Office. The bill's definition of developer extends to anyone making a generative AI model available to Californians, including indie developers, open-source initiatives, and nonprofits. Recent amendments added exemptions for universities and government entities but still reach non-commercial developers. EFF argues rights holders already have powerful tools under existing federal copyright law and courts are currently working through fair use questions, with some already concluding many AI training activities qualify as fair use.
Trump Administration Deletes January 6 Press Releases
The Department of Justice removed the vast majority of press releases pertaining to January 6 defendants from its website. The DOJ's Rapid Response account stated on X that the deletion was intentional, claiming it is reversing DOJ weaponization and stripping partisan propaganda from the website. The deletions came after Trump issued pardons to individuals convicted of crimes related to the January 6 Capitol attack and established a $1.776 billion fund positioned as compensation for politically persecuted individuals. The administration did not provide advance notice of the purge, which removes public records of federal law enforcement actions and indictments.
Meta AI Support Chatbot Account Takeover Vulnerability
Hackers exploited Meta's AI support chatbot to take over Instagram accounts by convincing the bot to add new email addresses to target accounts. A video demonstrated the attack showing a hacker using a VPN to spoof the target's location, then asking the chatbot to add a new email address, receiving a verification code, and using the chatbot's reset password button to take over the account. Instagram spokesperson Andy Stone said the issue was fixed on Monday, though it's unclear how many accounts were improperly accessed. Security experts note that while this particular tactic may be blocked, LLM chatbots are not trustworthy enough for account security applications and many other attack vectors remain.
Trump Administration Considers Palantir Executive for CISA Director
The Trump administration is considering Shyam Sankar, chief technology officer at Palantir Technologies, as a lead contender for the long-vacant CISA director role, according to sources familiar with the matter. A White House official disputed the potential selection, saying it is not accurate at this time. Sankar has worked at Palantir for more than 20 years. CISA has not had a Senate-confirmed chief since Jen Easterly stepped down in January 2025. DHS Secretary Markwayne Mullin told lawmakers Wednesday that the administration is on the cusp of nominating a CISA director. The agency has been run by Acting Director Nick Andersen since February and has dealt with workforce and budget cuts since Trump entered his second term. CISA is named throughout the administration's new AI executive order as a key agency charged with implementation and is expected to release a binding operational directive by Friday outlining actions federal agencies must take.
Review third-party data sharing agreements by July 1, 2026. After the Supreme Court's FCC location data ruling, audit all agreements with aggregators, data brokers, and downstream recipients to ensure documented customer consent mechanisms exist before sharing location or sensitive data. Implement contractual requirements that recipients also obtain consent.
Submit public comments on X's FTC settlement petition by July 2, 2026. Organizations with insights into X's privacy practices or concerns about precedent for modifying FTC consent orders based on ownership changes should submit comments to the FTC during the open comment period.
Prepare for Section 702 reauthorization by June 12, 2026. Organizations handling government data requests should review data access controls, audit trails, and transparency reporting procedures ahead of expected Section 702 reauthorization and potential intelligence community leadership changes.
Audit LLM chatbot permissions immediately. Following Meta's chatbot account takeover incident, organizations using AI chatbots for customer service or account management must implement strict controls preventing chatbots from modifying account credentials or security settings without multi-factor verification. Remove chatbot permissions to execute security-sensitive operations.
Monitor California AB 412 progress. AI developers operating in California should track the bill's movement through the Senate Privacy Committee and prepare compliance documentation of training data sources and licensing agreements to support fair use defenses regardless of whether the bill passes.