EFF: Updates

Subscribe to EFF: Updates feed
EFF's Deeplinks Blog: Noteworthy news from around the internet
Updated: 6 hours 4 min ago

We Demand More Information on How Marin Cops Illegally Shared Flock ALPR Data

Thu, 10/01/2026 - 5:59pm

The Marin County Sheriff’s Office is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data from their Flock Safety system with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which has put every driver in the county at risk and is especially dangerous for immigrants, abortion seekers, and other targets of the federal government.

Today, we sent the Marin County Sheriff’s Office (MCSO) a demand letter and request for records under the California Public Records Act following the Point Reyes Light’s recent report that MCSO provided non-California agencies access to its ALPR database. This directly violates California law and the terms of the 2022 Settlement Agreement in our case Lagleva v. Marin County Sheriff.

ALPRs are cameras that capture images of vehicles and upload their location to a searchable, shareable database. They are a mass surveillance technology that collects data indiscriminately on every vehicle on the road.

Sharing ALPR data with out-of-state or federal agencies—for any reason—violates California law (SB 34). If this data is shared for the purpose of assisting with immigration enforcement, agencies violate an additional California law (SB 54).  

But network audit logs obtained by Point Reyes Light show that during the final months of 2024, Marin County Sheriff’s Office shared ALPR data with multiple out-of-state and federal agencies, including 254,131 times in November 2024 alone. Many of these searches were conducted by law enforcement in states that impose severe restrictions on reproductive care and have a history of assisting ICE, including Alabama, Indiana, Kentucky, Florida, and Texas.

This sharing violated state law and “exposed sensitive driver location information to misuse by the federal government and by states that lack California’s robust privacy protections,” the letter explains.

This is not the first time MCSO has shared Marin County ALPR information with federal and out-of-state agencies in violation of California law.

Back in 2021, on behalf of community activists, EFF and ACLU sued the Marin County Sheriff for illegally sharing millions of local drivers’ license plate numbers and location data with hundreds of federal and out-of-state agencies, including ICE and Border Patrol.

The parties eventually reached a settlement, under which the Sheriff agreed to stop sharing license plate and location information with agencies outside of California to comply with state laws SB 34 and SB 54.

“MCSO’s November 2024 audit report shows that your office has violated not only SB 34, but the terms of the Lagleva Settlement Agreement as well,” the letter explains.

EFF and ACLU are urging MCSO to launch a thorough audit of its ALPR database, institute new protocols for compliance, and assess penalties for any employee found to be sharing ALPR information out of state.

“While your office claims that it took deliberate steps to disable nationwide data-access capabilities and ensure your system operated within strict privacy safeguards, you have not explained how outside agencies nonetheless obtained access, how you plan to prevent future violations of SB 34 and the Lagleva Settlement Agreement, or why you did not take steps to inform the public and the Marin County Inspector General once you learned about the breach,” the letter explains.

As we’ve demonstrated over and over again, many California agencies continue to ignore these laws, exposing sensitive location information to misuse and putting entire communities at risk. As federal agencies continue to carry out violent ICE raids, and many states enforce harsh, draconian restrictions on abortion, ALPR technology is already being used to target and surveil immigrants and abortion seekers. These incidents have made it clear that having ALPR programs are incompatible with the protection of residents. California agencies, including Marin County Sheriff’s Office, have an obligation to protect the rights of Californians, even when those rights are not recognized by other states or the federal government. 

See the full letter here: https://www.eff.org/document/20261001-letter-aclu-norcal-and-eff-marin-sheriff

Challengers Approach: Third Party App Stores Arrive to Google Play

Thu, 10/01/2026 - 5:25pm

If you are an Android user, you may have noticed it already: Google has begun allowing rival, third-party app stores to be distributed through the Google Play Store. And if you are a developer, you may have noticed new options for billing and distributing your apps. 

For years, Epic Games, maker of games such as Fortnite, has been suing Google, alleging violations of antitrust law. Specifically at issue were Google's restrictions on the distribution of alternate app stores through the Play Store, restrictions on app developers who have little practical choice but to distribute their apps through the Play Store, and Google’s rules governing in-app payments and the fees associated with them. 

Epic’s challenge ultimately resulted in a court order requiring significant changes to Google’s practices. Among other changes, rival, third-party Android app stores are now allowed to access the Play Store’s catalog and to be distributed through the Google Play Store. Developers also have greater freedom to direct users to alternative payment and distribution options.   

These changes give users and developers more choices and create new opportunities for competition in the Android ecosystem, breaking the power Google once had over many facets of the app ecosystem. This is a win for competition and antitrust enforcement. But the benefits can extend beyond competition itself—more meaningful choice can also create opportunities for greater freedom of online expression, privacy, and security. 

With alternate app stores able to compete for Android users, Google no longer has the first and last say on what apps can reach users and on what terms. Developers have more options for reaching their audiences, rather than having a single company’s rules determine the terms of access. 

More importantly, Android users are no longer trapped in an arrangement of feudal security with Google, where users must depend on the goodwill of a monopolist to protect them and guarantee their safety. If Google does not adequately protect their data or security, Android users can now switch to a competitor that does a better job. And if that competitor fails them, they can choose another. 

Competition in the app store market therefore means competition not only over which apps are offered, the user experience, and developer fees, but also over privacy and security. Users and developers gain something fundamental in the process: the ability to choose. 

As we’ve previously written, antitrust has never been just about prices—it’s also about power. It is about who gets to control and shape the future of the internet. A world in which a handful of dominant platforms can dictate how users access apps or programs, how developers reach them, and what rules govern those interactions is one in which users have fewer meaningful choices. Without Epic’s successful antitrust challenge and the changes that followed, users would have remained in a world of feudal security, where they would have been left begging their feudal tech lord for more. 

The arrival of competitor app stores on Google Play does not solve every problem with the Android ecosystem. But it opens the door to something that dominant platforms have spent years trying to keep out: meaningful competition. And each new competitor gives users another opportunity to choose something better. 

Related Cases: Epic Games v. Google

Court Agrees with EFF: Utah’s VPN Law Demands a Technical Impossibility

Thu, 10/01/2026 - 3:57pm

When state lawmakers attempt to rewrite how the internet works, users rely on courts to recognize that laws can’t make technical impossibilities a reality. That’s why we were happy to see that a court has blocked Utah’s attempt to outlaw the privacy protections of Virtual Private Networks (VPNs). 

In a win for digital rights, a federal judge has issued a preliminary injunction blocking Utah’s SB 73, the state’s draconian anti-VPN age verification law. The decision comes as EFF submitted our comments to the Utah Department of Commerce, detailing how forcing platforms to detect and block privacy-preserving tools undermines user privacy and security worldwide while demanding the impossible.  

What SB 73 Does 

Signed into law earlier this year, SB 73 attempted to regulate adult websites by requiring them to block VPN users or to identify the physical location of visitors using them or similar tools that mask their network traffic. It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks. This made Utah, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. 

The Utah federal court halted enforcement of the law's VPN provisions last week, ruling that the law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.  

SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah. The law’s “actual-location provision in practice requires an entity to perform age verification services for every user visiting its site from any location because the entity would violate the law if even one of those users happened to be obfuscating,” the court wrote. The court essentially ruled that Utah has less-burdensome ways to prevent Utah minors from accessing adult websites than requiring all users in the world to comply with SB 73. 

Aylo’s lawsuit does not challenge SB 73’s provision prohibiting the websites covered by the law from sharing information about VPNs. 

The Legal Challenge 

This court order follows months of legal maneuvering.  

Initially set to go into effect in May 2026, SB 73 sparked an immediate constitutional challenge from Aylo, the parent company of major online adult platforms like Pornhub. In response to the lawsuit, Utah and Aylo initially agreed that the state would pause enforcement while the court considered the preliminary injunction request or until administrative rules setting specific compliance terms were finalized. Those proposed compliance rules (R152-78B, see Utah State Bulletin, page 6) were published by the Utah Department of Commerce’s Division of Consumer Protection on September 1st, and EFF submitted formal comments to the Department in opposition. According to the notice, the proposed rules could be effective as soon as October 8, 2026. However, Judge Barlow’s decision means that it cannot be enforced pending further action by the court. 

The Ruling 

EFF welcomes Judge Barlow’s ruling, which recognizes the fundamental disconnect between state legislation of the internet and how technology works. In his ruling, Judge Barlow noted that the statute requires a technical impossibility on pain of legal liability. “Aylo is correct that the statute, as amended, now essentially imposes strict liability for entities like it when it comes to determining the location of its websites’ users.” 

The court recognized that the problem is that SB 73 “requires entities like Aylo to geolocate its website users with perfection to avoid liability.” But, at the same time, the court acknowledged “that geolocation perfection is not presently possible.” 

EFF explained this technical impossibility in our comment to the Department of Commerce. VPNs protect user privacy by routing web traffic through intermediary servers. Because destination websites only see the IP address of the VPN server, they have no reliable mechanism to tell whether a connection originates from Salt Lake City, Seattle, or Shanghai. So, under Utah's current statutory framework, platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely. Judge Barlow agreed, asserting:  

Because the law requires perfection in the absence of perfect geolocation tools, Aylo would need to verify those 28 million users—whether located in Salt Lake City, Boston, New Orleans, Anchorage, or Honolulu—to ensure compliance and avoid liability.

The Rulemaking 

The administrative rules drafted by the state compelled commercial entities to implement "commercially reasonable geolocation obfuscation detection systems", which is a directive, we argue, that demands a technical impossibility.  

In our submission to the Utah Department of Commerce, EFF also detailed how these rules force an invasive data collection regime onto internet users everywhere. So, in response to internet users trying to avoid invasive data collection required by age-verification requirements, SB 73 requires even greater surveillance of internet users’ online activities. The Department’s suggested detection heuristics (like monitoring connection latency or device time zones) are notoriously unreliable and easily skewed by normal network conditions. This active surveillance inevitably leads to widespread misclassification, unwarranted access blocks, and severe impacts on users’ privacy far beyond Utah's borders.  

You can read EFF’s full comments to the Department of Commerce here. 

What Now? 

As we’ve said time and time again: the internet will always route around censorship. 

Mandating invasive tracking and punishing the use of essential security tools turns genuine privacy concerns into mere compliance theater and requires more state-mandated surveillance of internet users who rely on VPNs. As is the case in heavily censored regions, VPN services and obfuscation tools will simply adapt, making this framework fundamentally unsustainable.  

As we’ve said time and time again: the internet will always route around censorship. 

While Utah legislators have indicated they may attempt to revise the law during the next legislative session, the court's preliminary injunction sets an important precedent: state lawmakers should not weaponize age verification to force dragnet tracking or undermine essential security tools.  

As other states consider similar anti-VPN proposals, EFF will continue pushing back against these technically impossible mandates and defending users’ privacy and anonymity. Thus, we urge legislators and regulators to reject anti-privacy rules, prioritize real user security, and safeguard constitutional protections for all users. 

Happy Opt Out October! Let’s Find Real Alternatives to the Tech Giants

Thu, 10/01/2026 - 3:27pm

Over the years, the major tech companies have found all sorts of ways to embed themselves into our lives. We often use their software, their AI tools, their social media, and their operating systems by default without even thinking about potential alternatives. It’s time to rethink that relationship. 

Last year, we created Opt Out October to help remind ourselves of the variety of ways we can take back control of our data through small steps inside apps, operating systems, and other various forms. This year, we highlight the idea that sometimes the best way to control your data is to leave a platform, app, or operating system altogether. 

To do so, we’ve created a hub of resources sharing ways to find new software that isn’t made by the tech giants, take advantage of the growing universe of new social media options, install a whole new operating system, and better control how various popular tools and software use your data for AI training. 

As an incentive, we’ve made merit badges like the one below to help you track your own wins and share them with others. Complete any of these tasks and let the world know by sharing that accomplishment on social media or changing your profile image! Better, more privacy-respecting, and less-enshittified tools are out there. We just have to find and use them.

Head over to our Opt Out October landing page and start taking the first steps to regaining control of the tools and software you use.

Victory! California Appeals Court Refuses to Revive Surveillance Tech CEO’s Meritless Lawsuit Against Journalist

Wed, 09/30/2026 - 6:38pm

When the rich and powerful try to use the court to silence negative reporting about themselves, it’s worth calling out that behavior for what it is: an attack on free speech. This is why EFF is happy to stand up for reporters who find themselves in that situation.

The California Court of Appeals upheld a lower court’s decision to strike a former Premise Data CEO’s meritless lawsuit against a journalist who exposed the CEO’s secret arrest for felony domestic violence. Jack Poulson, the writer and publisher of All Source Intelligence, reported details from the San Francisco Police Department’s report of the arrest and posted a copy of the report after receiving the document from a confidential source. Poulson later learned the arrest record had been sealed. The CEO, Maury Blackman, sued Poulson, Substack, AWS, and another organization for damages to try and force the removal of Poulson’s reporting from the internet.

The trial court tossed the entire case under California’s anti-SLAPP statute—SLAPP stands for “strategic lawsuit against public participation” and describes cases where the goal isn’t vindication in court so much as it is costing someone time, money, and peace of mind fighting the lawsuit. To fight SLAPP cases, states like California have passed anti-SLAPP laws, which are invaluable tools for protecting the First Amendment. California’s law provides an avenue for early dismissals of these baseless lawsuits, which curtails their intended effect on the target. Blackman appealed the court’s decision, arguing that a court order sealing the arrest overrides Poulson’s right to report the news.

The Court of Appeals correctly rejected Blackman’s appeal and affirmed the decision to throw out the case. The court held that the First Amendment protects Poulson’s publications. As the court explained in its decision, “the First Amendment protects the lawfully obtained truthful publication of the information at issue absent ‘a need to further a state interest of the highest order,’” a standard that Blackman’s privacy interests do not satisfy. The Court also found that Poulson, as the publisher of the All Source Intelligence newsletter, was protected by California’s Shield Law, relying on precedent established by EFF in 2006. The Court also affirmed that Substack and the other website, which had merely temporarily hosted a copy of the arrest record, were immunized from liability by Section 230.

This decision is a win for free speech, for Jack Poulson, and for everybody.  

Related Cases: Blackman v. Substack, et al.

📱 Hey Siri, How Do I Limit AI Data Access? | EFFector 38.17

Wed, 09/30/2026 - 12:45pm

With the launch of iOS 27, Apple is rolling out a variety of new AI features to its familiar voice assistant, Siri. But how are AI tools like these handling our data? In our latest EFFector newsletter, we're talking about the privacy complications of AI phone features.

JOIN OUR NEWSLETTER

For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers drones and our right to record the law enforcement, video doorbell footage privacy, and how to limit what data Apple's new Siri AI can access.

Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Thorin Klosowski about the difference between AI phone features that are computed on-device and ones that are computed on external servers—and what that means for data protection. You can find the episode and subscribe on your podcast platform of choice:

%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Ff5abca72-7d82-4e94-9c0b-0d9f991891f0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

   

Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!

While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards

Tue, 09/29/2026 - 5:30pm

San Francisco's decision to retain its use of Automated License Plate Reader (ALPR) surveillance cameras belies what we know about this spying technology tool: it endangers residents and threatens the privacy and civil liberties of our community. Based on what's in the city's press release and announcement, this policy will do nothing to stop actual harms.

We know innocent drivers will be stopped and menaced by officers because of erroneous matches. We know officers use Flock to stalk potential and past romantic partners. Data will be accessed by Immigration and Customs Enforcement (ICE) and used to deport immigrants. Promising greater penalties for such abuse will not end this. These are not isolated mistakes that another policy can fix. They are consequences of building a system that records everyone’s movements and makes them searchable by police. This is also not unique to a single vendor. From Flock Safety to Motorola to Axon—San Francisco must end its use of ALPRs.

We ultimately cannot rely on new protocols from city officials, and the City’s new policy is woefully inadequate. There is no warrant requirement to search stored ALPR data. An incident or computer-aided dispatch (CAD) number is not judicial authorization. Without a warrant requirement, officers can search stored location data without showing probable cause to a judge, and will. Without judicial control, officers will continue to search the data for abusive reasons. But a warrant requirement alone would not justify retaining the ALPR network: the community is demanding an end to the collection itself.

Additionally, the announced policies include no deadline to delete ALPR data, there is only a 30-day deadline to move data from the vendor’s servers to the city’s servers. City officials must understand that moving data is not deleting it. Whether Flock or SFPD stores the data, it remains a permanent record of where people drive, worship, work, organize, seek care, and spend time with others. Thus, the best practice is deletion. New Hampshire requires deletion in three minutes, and Flock itself has reduced the default retention time to seven days. San Francisco can and should do better.

Lastly, while transparency and documentation are important concepts, better audit logs are not the answer. They can expose abuse only after a search has occurred. They cannot undo the disclosure of someone’s movements or justify collecting everyone’s location data in the first place; especially when we are talking about people’s lives and civil liberties. The city's announced policy does not even require officers to state, in their own words, why they are searching the stored ALPR data—an accountability rule that has exposed abusive searches across the country.

San Francisco is behind many communities that have considered the tradeoffs of ALPR surveillance and made the right choice by ending their contracts. San Francisco must do the same.

Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries

Tue, 09/29/2026 - 11:00am

People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, and since the early days of the internet, a dedicated band of activists, lawyers and technologists have fought for a better, more secure and private digital future – a future that’s still attainable.  

Cindy Cohn, who just finished a 26-year run with the Electronic Frontier Foundation including 11 years as its executive director, has lived this fight. She says privacy isn’t just about secrecy: It's ultimately about power – who has it, and who has the ability to protect themselves from it.   

Welcome to the first episode of “Privacy’s Defenders,” a podcast about the people – lawyers, journalists, hackers, and others – who’ve fought to secure your digital liberties since before most people even knew what the internet was.

%3Ciframe%20height%3D%2252px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F2f955342-7675-4c8c-bb40-fa364d9a569d%3Fdark%3Dtrue%26amp%3Bcolor%3D000000%22%20allow%3D%22autoplay%22%3E%C2%A0%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

   

(You can also find this episode on the Internet Archive and on YouTube.)

In this episode, Cindy talks with EFF cofounder John Gilmore about how he – an early employee at Sun Microsystems – came together with Lotus Development cofounder Mitch Kapor and cattle rancher, philosopher and Grateful Dead lyricist John Perry Barlow to create EFF as a bulwark against government investigation and prosecution of early internet users.  

It’s a story of the Secret Service’s “Operation Sundevil,” jet-setting tech titans, tie-dyed cypherpunks, and a fateful house party in San Francisco’s Haight-Ashbury district amid the earliest days of online communications, setting the stage for the battles that created the internet as we know it and issues we still grapple with today. 

The “Privacy’s Defenders” podcast is a follow-up to Cindy’s book, “Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance,” bringing to life pivotal moments in the voices of those who fought for your rights. Sales of “Privacy’s Defender” benefit EFF, so pick up your copy today! 

Joanne Elgart Jennings co-produced and created this podcast.  

Jarod Sport co-produced, mixed, and mastered it.  

Corinne Ruff is our story editor.

We had additional help from Rachel Estabrook and Alison Broverman.

The original music was composed and performed by Nat Keefe of Hot Buttered Rum with Ben Andrews on the fiddle.  

And other archival sound came from the Internet Archive's amazing collection, including the snippet of the Grateful Dead song “Cassidy” that John Perry Barlow co-wrote. 

EFF to San Francisco Police: Drones are Powerful Surveillance Tools That Require a Robust Policy

Mon, 09/28/2026 - 4:30pm

The San Francisco Police Department (SFPD) began regularly deploying drones two years ago and has since expanded their use in a way that has outpaced its documented policy and evaded existing local and state oversight of these devices. 

The department has a new proposed policy, which continues to be grossly inadequate in protecting privacy and civil liberties. At best, the draft policy continues the SFPD’s pattern of putting vague guardrails on a powerful surveillance tool, but at worst, if implemented, the policy could effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city with few guardrails.

EFF has repeatedly opposed the unaccountable development of the SFPD’s drone program and recently sent a comment to the Police Commission, the local civilian oversight body, about the SFPD’s new proposed policy. 

The SFPD has been sidestepping oversight of its drones since 2024. In March 2024, San Francisco voters approved a heavily-funded, billionaire-backed measure, Proposition E, which sought to expand police access to surveillance technology. Among its impacts, Prop E removed drones from oversight required by the 2019 Surveillance Technology Ordinance. Nonetheless, in its haste to purchase drones after Prop E passed, the SFPD knowingly violated California’s AB 481, a state statute requiring law enforcement agencies to get approval from their local elected governing body before purchasing military equipment, including drones. Eventually the SFPD sought retroactive approval from the Board of Supervisors and, soon after, announced that it would be launching a drone-as-first-responder (DFR) program.

Now, San Francisco finally has an opportunity to update the SFPD’s guidance in a way that won’t quickly become stale, as has happened while the SFPD steadily increases the purposes for drone use. Though drones were initially identified as tools to use for specific actions such as vehicle pursuits and active criminal investigations, within a year, the SFPD expanded use cases to include patrol, i.e. unrelated to a specific incident. Along with this mission creep, the SFPD has also steadily and exponentially increased the number of drone flights, from roughly 350 deployments in 2024, to over 1,100 from January to August 2025, to over 3,500 in just the first five months of 2026.

The original draft of an updated policy brought by the SFPD to the local Police Commission, a civilian oversight body, earlier this month provided limited details and proposed allowing police to treat drone flights as an extension of their patrol abilities, paving the way for general surveillance, including of First Amendment-protected activity. The proposal received significant community pushback, and the San Francisco Public Defender’s Office authored a letter describing the policy’s shortcomings. That letter was signed by over a dozen local, state, and national groups, including EFF. 

Based on these concerns, the Police Commission deferred taking action until the SFPD addressed them. The SFPD then revised its proposed policy, but this, too, falls short of providing practical guidance to officers and protecting civil liberties, as the Public Defender’s Office identified in a follow-up letter signed by over 40 organizations, including EFF.

EFF’s additional comment to the Police Commission, in part, calls out the incredible gap in oversight of these ballooning drone flights and the immense data collection they facilitate:

The revised policy states that “[unmanned aerial vehicles] may be used as an asset in any situation in which a member may be deployed for a public safety response or when a member onviews criminal activity” but fails to define what is meant by a “public safety response.” The revised policy also provides a definition of “Drone as First Responders,” but it fails to provide any more detail about appropriate DFR deployment. Without appropriate safeguards around deployment and use, drones could be deployed to every call for service, even in situations that are ultimately deemed nonincidents, collecting data along the way that is then stored for 30 days. This type of general patrol could effectively become general surveillance, which SFPD acknowledges is an inappropriate use of their drones and yet is still possible under the vague terms of the current DGO. 

The Police Commission is set to consider the matter on October 14. You can read EFF’s full comment here.

EFF to Court: Trump's Use of Truth Social's Pay-To-See-Posts-First Scheme Violates Americans' 1st Amendment Equal Access Rights

Fri, 09/25/2026 - 5:04pm

EFF legal intern Simar Kaur also contributed to this article.

Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100,000 a month early access to government news, EFF told a federal court.

The First Amendment guarantees that members of the public have equal access to public officials’ public comments, we reminded the court.

EFF filed an amicus brief in support of a motion for a preliminary injunction in the lawsuit filed by The Intercept Media and the Freedom of the Press Foundation against President Trump and other administration officials. The lawsuit challenges their use of Truth Social as their primary social media method of making official announcements when that platform provides people who pay a fee for early access to such posts. 

Trump uses his Truth Social account as his primary means of communicating with the public, including to announce military operations and ceasefires, foreign and domestic policy, and the removal and appointment of heads of federal agencies. Earlier in the year, Trump Media, which owns Truth Social, announced “Truth API,” a service that provides investors early access to “market-moving” messages from the president and other high-ranking officials for a fee of up to $100,000 per month.

The plaintiffs, the Freedom of the Press Foundation and The Intercept, contend that the president and other officials’ preferred use of Truth Social with this service violates the First and Fifth Amendments of the Constitution. The plaintiffs are asking the court to immediately prevent the president from posting on Truth Social in a manner that allows him to profit from selling early access to government information.

EFF’s amicus makes two main points.

First, the brief establishes that social media is pervasively used by government officials and agencies as a medium for official communication with the public, including to disseminate critical public safety information and make official announcements.

Second, the brief explains that the challenged practice violates the First Amendment, which guarantees a right to access public officials’ public comments on equal terms with other members of the press and public. Giving some people preferential access must at a minimum be reasonably justified to satisfy First Amendment scrutiny, a test the administration does not meet.

Lining the president and his company's pockets is not a legitimate government interest for restricting timely access to the government's statements. Further, the fact that the public could ultimately access the information from other, less direct channels does not eliminate the need for First Amendment scrutiny; mere delays in timely access still trigger First Amendment scrutiny.

EFF has been advancing the First Amendment right of equal access to government’s public social media posts since at least 2018. We’ve argued that the right of equal access, which is well established in offline contexts, must apply to official government social media posts as well. This case presents an excellent opportunity for a court to directly adopt that position. 

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising

Thu, 09/24/2026 - 4:11pm

Online sports betting company DraftKings is using AI to target customers who are most likely to place losing bets and respond to gambling promotions. This kind of targeting is a form of online behavioral advertising, which is when companies personalize the ads they show you based on the data they’ve collected about you. The more data a company has, the more personalized the ad can be. While DraftKings is using AI to supercharge the harmful effects of online behavioral advertising, EFF has long argued that all behavioral advertising should be banned. 

According to the New York Times, DraftKings is using its customers’ betting records to train a machine learning model to find losing gamblers. Once found, DraftKings sends these customers targeted advertising designed to lure them back to the site to place more bets—bets that DraftKings thinks will be losing ones. DraftKings has a business incentive to keep losing gamblers coming back to their site, because these are the users actually making DraftKings money. Unfortunately, those considered “problem gamblers” (people who repeatedly gamble despite harm to themselves, their finances, and their relationships) are highly likely to be targeted by this model. By re-engaging these individuals through targeted promotions aimed at keeping them on the platform, DraftKings is capitalizing on their vulnerability for profit instead of mitigating their risk. 

Predatory online behavioral advertising isn’t new, but companies’ use of AI to process data and target customers has magnified its harms. Online behavioral advertising incentivizes the collection of vast quantities of data to power ad tech. Adding AI into the mix means that even more data is collected to train and refine models. Because AI operates as a black box, the humans building the models can rarely predict which data points are the most useful to the AI, driving them to continuously collect more data. AI also allows companies to process enormous data sets much faster, and, as a result, supercharges the harms of online behavioral advertising. 

A direct consequence of online behavioral advertising is that it provides the data the surveillance industry needs to run. Data collected for targeted placement of ads is being sold to insurance companies, banks, and state and federal government law enforcement agencies such as CBP. ICE is also taking an interest in the data fueling ad tech: earlier this year, ICE published a Request for Information “seeking information to better understand how the industry’s commercial Big Data and Ad Tech providers can directly support investigations activities.”  

DraftKings seems to be using solely “first party data” to target their ads, meaning that they’re using only the data they collect directly from their users and are not buying any additional data from third parties to fuel their machine learning model. This highlights how policy solutions that only limit third-party data sharing and selling would not be enough to prevent these predatory advertisements. Rather, policymakers must ban online behavioral ads.   

What DraftKings is doing with their targeted promotions is just one example of how online behavioral advertising causes real harm to real people. But there are ways to take back control over your own data: EFF offers resources such as our Surveillance Self Defense project, along with other tips for how you can protect yourself on mobile apps and on websites.  

DraftKings’ use of AI to target losing gamblers illustrates how ad tech evolves and how companies find new ways to use our data against us. This is why EFF believes that all behavioral advertising should be banned. If companies can’t send personalized ads, they’ll have less incentive to collect the behavioral data powering them.  

D.C. Circuit Must Vacate a Drone Flight Restriction That Criminalized Recording Immigration Agents

Mon, 09/21/2026 - 6:59pm

EFF joined an amicus brief with ACLU, ACLU of D.C., National Press Photographers Association, and Professional Photographers of America to urge the D.C. Circuit to vacate an FAA drone flight restriction that violated the First Amendment right to record law enforcement. This is an important case—Levine v. FAA—challenging the ability of the government to punish drone pilots who record law enforcement officers engaged in official business. 

As we wrote about earlier this year, the FAA issued a flight restriction for drones that had effectively criminalized the recording of Department of Homeland Security officers, including immigration agents from ICE and CBP, and their vehicles (what the FAA called “mobile assets” including “ground vehicle convoys and their associated escorts”) even if the drone was over half a mile away. 

A drone operator, represented by the Reporters Committee for Freedom of the Press, sued the FAA in March [PDF]. But in April, the FAA rescinded the flight restriction. 

The petitioner argued in his opening brief that the court should evaluate the legality of the flight restriction even though it was withdrawn. Drone pilots could still be punished for violations that occurred when the flight restriction was in effect. And the FAA could reinstate the flight restriction at any time, given that the rescission did not seem to reflect “a true change of heart” but rather an effort by the agency to avoid judicial review. 

The amicus brief, filed in support of the petitioner, noted that drones are unique because they provide “perspectives that cannot be captured by ground-based imagery,” and they “are far more maneuverable than ground-level cameras, and they are both much cheaper and much safer than using a chartered plane or helicopter to record newsworthy events from above.” The brief highlighted that drones have captured “bird’s-eye images of protest activity” and “police uses of force against protestors,” and have “allowed journalists to provide the public with up-to-the-minute information about natural disasters without putting themselves in harm’s way.” 

The brief argued that using drones to capture images and video is information-gathering activity protected by the First Amendment (similar to using cell phones to record law enforcement). The brief also argued that the FAA’s flight restriction appeared to be issued specifically to ban the recording of immigration agents and thus hinder accountability for their enforcement actions—it surely wasn’t a coincidence that the FAA imposed “no-drone zones around all roving DHS patrols just as those patrols were provoking intense national backlash.” If that’s true, it would make the FAA’s action a content-based restriction on speech that is subject to strict scrutiny—the highest First Amendment standard—and presumptively unconstitutional. And even under less rigorous standards of First Amendment scrutiny, the flight restriction is unconstitutional because the FAA can’t articulate any valid governmental interest justifying such a sweeping restriction on speech. 

Resolving this issue to protect First Amendment rights is especially urgent as government agencies continue to sink billions of dollars into technology designed to counter drones—technology that could easily be deployed against journalists and other people hoping to use drones to document government abuse.  

We urge the D.C. Circuit to review the petition and to vacate the FAA’s flight restriction, which would send a message that the government can’t avoid accountability by punishing those who exercise their First Amendment rights. 

  

EU Kids Act Won't Keep the Internet Accountable and Trustworthy

Mon, 09/21/2026 - 8:27am

The EU Commission draft law to restrict young people’s access to the internet that it presented last week will come at a high cost: it will put online services behind age gates, expand the use of intrusive age verification, and undermine the privacy of all users. 

The EU Kids Act aims to protect children from risks associated with social media, video games, and AI systems by introducing age-based access rules, safety requirements, and stronger enforcement and oversight measures. It presents itself as building on the Digital Services Act (DSA) and puts into “hard law” some of the safety-by-design measures specified in the non-binding DSA guidelines on minors’ protection. 

The proposal is built around the following elements: social media age “delay”, safety by design, age assurance and parental responsibility, and strong enforcement. Each of these measures are concerning.  

Mandatory Age Gates for Social Media and Video-Sharing Platforms 

Following the advice of an expert panel, the proposal would create a phased access to social media and video-sharing platforms deemed risky—a threshold met simply by relying on personalized recommender systems or offering “uninterrupted content consumption”: no service accounts for children under 13; restricted accounts under tight parental supervision from 13 to 15; and autonomous accounts in a safe-by-design environment from 15 to 18. Full online access is therefore reserved for adults. 

However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups.

If this sounds complex and like a compliance nightmare, that’s because it is. The access delay comes with privacy-intrusive age verification across the board, relying on the EU age verification scheme. For teenagers, this law means significant control in the hands of their parents, who must set up accounts and prove that they are, in fact, parents, adding yet another problematic layer of verification. 

In fairness, the Kids Act’s gradual approach at least appears to be designed with some proportionality considerations, rather than imposing a blanket social media ban. Just last month a French court declared such undifferentiated bans unconstitutional. The EU Kids Act distinguishes between age groups and certain services and follows a risk-based approach. This means, for example, that age verification is not required for existing accounts if the provider can tell with a “high degree of confidence” that the user is above the age threshold—a vaguely specified standard.  

Yet, the law still indiscriminately covers social media and video-sharing, with virtually all mainstream services being covered by the proposal. The broad scope also sits uneasy with the use of age thresholds, which remain a blunt proxy for maturity. What is more, by focusing heavily on safety and harms, the EU Kids Act pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online. However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups. They also create a powerful infrastructure for control and further entrench the power of big tech. 

The proposal exempts not-for-profit encyclopedias, scientific repositories and educational services, as well as open-source software-developing and-sharing platforms. However, no exceptions are foreseen for small and medium-sized enterprises, which will only foster the dominance of resource-laden tech companies that were already investing in similar measures. And we know that most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms. 

Safety by Design Across Covered Services 

The proposal’s second pillar, “safety by design”, casts a wider net. It applies across social media, video-sharing, online games, AI companions, chatbots and even app stores—with varying requirements. Providers must generally make child-safe design the default and can relax from the requirements only if they use age assurance to establish that the user is an adult. 

For example, rules on addictive features such as infinite scrolling, safe account settings, and more choice over recommender systems are to provide a safe internet experience to young people. As regards AI companions and chatbots, the proposal requires companies to design their services to reduce minors’ exposure to emotional dependencies and harmful interactions. Online games are covered as well: they must come with contact protections. The law also makes app stores the gate keeper for age-appropriate access, based on an age-rating system. 

The devil of these measures lies in the details, but all of them raise fundamental rights concerns and some of them seem poorly suited, if at all, to the decentralized architecture of the Fediverse. The requirement for very large online platforms to set up compliance plans before rolling out new services raises additional questions about the risks of transplanting product-safety doctrines of conformity and risk control into speech regulation. Deciding what is “safe” can easily become a question of what content people can access or share.  

Next Steps  

By choosing to regulate all these aspects through the Kids Act, the Commission not only but creates a privacy minefield, it also intermingles the digital fairness agenda with the more fundamental-rights heavy questions of age assurance and access to information. An unfortunate policy choice that will politicize well-intentioned efforts to curb manipulative and addictive design practices (read our position on the DFA). 

It speaks volume that the Kids Act has not gone through a full impact assessment process, which would typically require a systemic check of alternative policy options and stakeholder consultations. Looking forward, we call on the EU lawmakers to pull the teeth of the most harmful suggestions and to make sure that the new measures don’t erode the fundamental rights of all users. 

EFF Statement on California Governor's Executive Order on AI

Fri, 09/18/2026 - 7:25pm

California Gov. Gavin Newsom's executive order is an opportunity for a needed, thoughtful conversation about artificial intelligence and its potential harms. Everyday Californians are feeling real anxiety about the risks of artificial intelligence, and as an organization that works to ensure technology empowers people, EFF welcomes this order as a way for the state of California to lead a much-needed dialogue that addresses these concerns. 

Nonetheless, the most immediate and current concerns with this technology are not about sci-fi scenarios concerning rogue super-intelligence. They are happening right now through biased algorithmic decision-making for employment or government benefits, AI-powered surveillance systems such as Flock cameras, and artificially inflated personalized pricing. People want state and federal leaders to act, and we urge Gov. Newsom to develop thoughtful policies to address those concerns. Today’s EO is a good start. 

To that end, EFF supports the focus on expanding the reporting requirements under SB 53 (2025) for loss-of-control incidents, alongside third-party investigations. We urge the administration to consider how to make these third-party investigations available for smaller developers. As the Government Operations Agency prepares its recommendations for the governor, we urge leaders to also realize that the effectiveness of kill switches in advanced AI systems remains an area of active research. As such, they should ensure that - as we’ve previously mentioned - any technology regulation targeting cybersecurity practices at AI labs must be careful, precise, and practical. Moreover, we also caution that government-controlled kill switches run the risk of being used as a form of retaliation against protected speech, as demonstrated by the Trump Administration’s retaliatory actions against Anthropic earlier this year.

Ultimately, true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies by ensuring that algorithmic decision-making in both the government and private sectors respects people’s rights and well-being. We urge Gov. Newsom and the state of California to develop thoughtful policy in collaboration with those most at risk of harm to address these and other concerns.

How to Limit What Apple’s New Siri AI Can Access in iOS 27

Fri, 09/18/2026 - 5:55pm

Apple’s new operating system is here, and along with it comes a new version of Siri, dubbed with two very familiar letters: AI. As the name suggests, this Siri power-up resembles an AI chatbot more than the often derided voice assistant you might be used to. It has even evolved from a blob you invoke with a verbal command or a button press to a whole app. This update comes with a slew of privacy complications, but you can take some control over what this new Siri can access and use. 

There’s no denying that the new version of Siri is far more powerful than it used to be, and arguably more useful at surfacing details on your phone. But that comes at the cost of deeper access. Once enabled, Siri and Spotlight are combined, unifying the interface. Where you may have once just pulled down on the screen to search for an app or contact, you’re now also invoking Siri. 

Spotlight and Siri are now visually one and the same.

By default, ask Siri a question and it’ll search through your Apple apps, like Notes, Messages, emails, and more. As time goes on, if the developer chooses to let it, Siri will gain access to more and more third-party apps. If an app developer doesn’t add that support, then Siri AI won’t be able to access the contents of that app (unless it’s shared screenshot-style via a new feature called “on-screen awareness,” which we’ll talk about more in a moment). 

For example, if Signal doesn’t choose to implement Siri AI support and you only talk to Bill on Signal, you won’t get an answer when you ask Siri AI, “What was the last photo Bill sent me?” But if you talk to Bill on Apple Messages and ask that same question, Siri AI will summarize what it thinks the photo is.

Sometimes Siri processes this data on your device. Sometimes it uses Apple’s Private Cloud Compute (PCC), which means the data is sent off your device to a cloud server. While you can try digging through the Apple Intelligence Report to figure out what’s sent to PCC, there’s no immediate visual indication from the user’s point of view when data leaves the device or when AI can handle it on the phone, iPad, or Mac itself. In practice, ask Siri AI a question and you’ll never really know if it’s being computed on device or off.

Apple claims what’s sent to PCC is not stored by the company after it is processed, but there are certain types of data or certain apps you might have on your phone that are not worth the risk. That’s especially true if you’re using a feature like Advanced Data Protection, which turns on end-to-end encryption for much of what’s stored in iCloud. Sending data that’s stored with end-to-end encryption off your device and into the cloud—no matter the privacy promises—is a fundamental change to the risk assessment you should make. “Private” means the system is engineered so that Apple shouldn’t be able to see or store the data, but it doesn’t mean it’s encrypted or doesn’t leave the device.

This leaves the privacy of certain apps up to a strange combination of an app developer’s choices and your own. You can, of course, disable Siri entirely (Settings > Siri > "Turn Off Siri"), or choose not to invoke Siri to ask questions, but perhaps you don’t want to fully disable or disengage with the system. Thankfully, you can put some guardrails on Siri AI’s access. Once you’ve updated to iOS 27, here are the steps to take. 

Note: only iPhone 15 Pro/Pro Max, as well as all models of the iPhone 16 and newer support Apple’s AI features. Siri AI is currently only available in English, and not available worldwide.

How to Restrict Siri’s Access to the Content Inside Apps

By default, how (and if) Siri AI can access data inside apps is up to the app developer. If an app developer chooses to index the contents of their app, then it may appear in search, and thus be made available to Siri AI. This means the content may pop up during general or direct searches, like “What are my plans for November" might cull information from your calendar, Messages, Notes, and, as they update, third-party apps.

If you do not want Siri to look through certain apps to consider the contents in results, you can tell it not to:

  • Open Settings > Apps > [the app you don’t want Siri to look through] > Search
  • Disable the option to “Show Content in Search.” 

With this setting disabled, when you ask Siri general questions, it will not surface details from the app you selected. For example, if you disable “Show Content in Search” for Messages, it will not be able to read your Messages conversations. 

Left: Asking Siri to summarize a message thread with Show Content in Search enabled. Right: With the setting disabled.

There is also an “App Access” setting where you can configure some of the ways Siri interacts with apps. You’d think this is where we’d have gone to revoke access to the content of an app, but alas, this settings page is more about some basic functionality with device personalization, not Siri’s access to the contents of the app.

  • Open Settings > Siri > App Access
  • Tap an app where you’d like to change Siri’s settings.

On this screen, you’ll find a variety of options, depending on what an app supports. “Learn from this App” sounds nefarious, but is mostly about tracking usage, like how often you open an app, and if a developer supports it, what you interact with.

The rest of the options are mostly about the personalization tweaks that Siri makes, where it suggests apps it thinks you want at the moment in various places, like when searching or sharing. “Show on Home Screen,” “Suggest App,” and “Suggest Notifications” are just about whether you see apps in those places. 

For example, if you have a widget of Siri-suggested apps on the home screen, that’s the “Show on Home Screen” toggle. If you see an app recommended in another app, like adding a date to your calendar from an email, that’s “Suggest App.” Apple claims these features all use on-device processing and the data is not stored on servers.

For anything not covered here, refer to this documentation for steps to disable certain features.

The On-Screen Awareness Capability May Be Concerning for Some People

There is one Siri AI feature you (and app developers) can’t do as much about: on-screen awareness, a feature you can invoke at any point to prompt Siri and ask it to explain what you’re looking at and perform certain actions. For example, you can ask it to summarize a web page, cut a recipe you’re reading in half, add an event to your calendar, or try to figure out where a photo was taken. All potentially useful features.

But you can also ask it to summarize or explain a Signal group chat that you're looking at, or a meme in a WhatsApp chat, and the data from that on-screen interaction may be sent to PCC. There is currently no way for you or app developers to block this feature, so it’s up to you, and those you chat with, to simply not use it if you’re concerned about the content of conversations potentially leaving your device. It would be a large improvement to privacy, especially secure chat apps, if Apple provided developers a means to block access to Siri AI’s on-screen awareness tool. Even better if they gave you a single control to block all Siri AI features from an app entirely.

Revoke Access to Training Data

By default, Siri AI won’t collect and use data from your interactions with it for training AI features. But during the setup process, Apple provides a way to opt in, which you might have tapped without thinking about it. If you’d rather your data not get used for training, you can opt out:

  • Open Settings > Privacy & Security > Analytics & Improvements
  • Disable the option for “Improve Siri & Dictation.” 

According to Apple’s privacy documentation, disabling this option should revoke training access to the audio and text from the Siri app.

Go Back to the Old Version of Siri (and Disable Other AI Features)

Want nothing to do with any of this but still find Siri useful enough to keep around (or you just have to keep it turned on in order to use CarPlay)? For the time being, you can get the old Siri back, though the process is a bit odd.

  • Open up Settings > Screen Time > Content & Privacy Restrictions
  • If you have never done so, enable the toggle for “Content & Privacy Restrictions.”
  • Tap the Siri option, then “Allowed Siri Version.” 
  • Select “Siri Classic.”

You can no longer easily disable Apple Intelligence entirely with one tap in the Settings, but on this screen you can also configure other AI features, like disabling the writing and math assistance prompts, turning off image creation, and disallowing the use of extensions. Follow this guide on Apple's site for everything else.

For the most part, Apple’s handling of AI features is far less in-your-face than others, and because of that the privacy implications are easier to untangle. But even still, it’s difficult to know what’s processed on device and what’s sent off, and so the privacy trade-offs are never spelled out as clearly as they should be. 

Apple could improve on this by offering an on-device only option for Siri AI and providing a clear, single setting toggle to prevent all AI features in a specific app (it looks like Apple is planning a single privacy toggle in a future update. We'll update if and when it does). In general, Siri’s power-up has also made it blurry and difficult to really figure out what sorts of privacy options exist. “Siri” means many things, both on device and off, ranging from “searching the entire internet for an answer” to “setting a timer,” and users have no straightforward ways to wrangle that data to suit their needs. As it stands, it’s a confusing collection of different toggles that never feel exactly right and which many users might struggle to grasp.

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

Fri, 09/18/2026 - 5:53pm

Secure messaging platforms, like Signal, WhatsApp, and recently, encrypted RCS, operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to guarantee what happens once the message arrives on a phone. As more devices and services introduce more artificial intelligence (AI) features into messaging apps, that line begins to blur. 

When AI features are computed entirely on device, it’s less concerning. Yet sometimes the computing requirements are heavy enough that the computation has to be done on a company server. Tech companies tell us they have a solution for this: trusted execution environments (TEEs). But do server-side TEEs really solve the problem?

TEEs exist to serve many different functions, ranging from digital rights management (DRM) content protections to securely storing information in your phone's mobile wallet, but for our purposes, we’ll be focusing on how tech companies use them for their AI tools. 

The basic idea is straightforward: most consumer devices aren’t powerful enough to handle the sorts of AI features companies want to offer, so sometimes they send data off your device to more powerful cloud servers to do the computing, then display the results on your device. Since your data is leaving your device, there’s a privacy compromise. For example, if you ask for a messaging app to summarize a conversation, it may offload that computing power to a cloud server, sending the entire contents of your messages to the cloud, then back to your phone.

TEEs supposedly offer a way to keep those requests private. There are several implementations out there, like Apple’s Private Cloud Compute, Google’s Private AI Compute, and WhatsApp’s Private Processing. It’s not just the big tech players, we’ve seen chatbots built with TEEs as well.

TEEs can provide more security and privacy than simply running in the clear, but they are fundamentally different from actual encryption or running locally. Despite the promises of some tech companies, they will never be able to match that level of security and privacy. Because of that, a user’s device should never automatically send data to a TEE. Let’s dig through the reasons why.

What Exactly Is a TEE, Anyway?

A TEE is a hardened section of the computer that runs software in a way that’s supposed to be secret even from other processes running on the machine. TEEs also let users check that the code being run is the code that they think is running, and not backdoored code instead, using a process called “attestation.” You may have also heard this referred to as a “secure enclave,” or heard the brand names SGX or TrustZone.

The intention of a cloud-based TEE is simple: a company can run a server in their data center, but still process data that you provide on your behalf without being able to see that information themselves.

Is a TEE Secure?

In practice, we've seen multiple cracks and hacks every year that show that it is possible to get at that data. That’s because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to breaking it that would not also upend fundamental understandings of mathematics as a field. 

The collective understanding of every mathematician in the world is that standard encryption algorithms are not breakable to the best of the world’s collective knowledge. No responsible engineer builds a system based on a new encryption method until after it’s been offered up for prodding.

Engineering, on the other hand, doesn’t work like that. Every individual system is the product of a group of engineers who put it out into the world, and each product will have its own quirks and bugs that have to be individually discovered and patched. These bugs are found after the system is built, not before. No one has yet built a system that is unbreakable. On the contrary, there is new research all the time that finds new ways to break into TEE systems. They’re patched as they come up, but they’re unlikely to ever become perfect, and certainly not any time soon. 

TEEs in particular are a hard engineering problem because the encryption key is physically right there on the device. Building a TEE means keeping a key fully separate and inaccessible while it’s on the same physical device as parts of the system that shouldn’t have access to the key.

Many attacks on TEEs involve “side channels.” In a side channel attack, the attacker measures the electrical impulses or other effects to figure out the timing of operations inside the TEE, then uses that to figure out the key being used. Once they have the key, they can read all the data. Compare that to end-to-end encryption, where the key is never on that machine in the first place, so an attacker would have to also run a similar attack on the user’s device.

Companies who turn to TEEs to protect data want to both have the key on the server and have it protected while still performing complex operations like running an LLM, which makes it much more difficult to protect those keys.

That being said, a TEE versus plaintext on a server is the difference between being able to easily read the data and having to do a bunch of specialized work to get at the data. That work often involves accessing the physical machine. This is most relevant for protecting against mass surveillance, and for many people, that might just be enough security.

But that's the core of the problem. “Secure enough for most cases” and “encrypted as in math” are not the same thing, and it’s important not to conflate the two. And services that currently offer “encryption as in math” have a real downgrade in security when they switch to security based on TEEs. 

If you want to dive into the myriad security issues and limitations of TEEs we’ve seen so far, they’re well documented here, here, here, and here.

What Does This Have To Do With LLMs and AI?

Sometimes organizations want to offer an LLM that can respond to queries in a private manner. On-device LLMs exist, but they’re limited in size. So, when organizations want to offer the ability to answer queries without being able to see the conversation, they turn to TEEs. That’s a useful way to run a chatbot that’s reasonably private. This is what Apple, Google, WhatsApp, and others are doing.

Why not turn to encryption? After all, LLM inference is just a bunch of math like any other things a computer does. It takes input to a (really big) function and gives an output. We have the math to do that computation in a way that hides the inputs and outputs from the one running the computation, it's just super expensive. It’s called homomorphic encryption, and no one’s figured out how to do it fast enough that it makes sense for this sort of computation.

Instead, the allure of a TEE is that it will run that computation for you inside of a special opaque section of a server. TEE manufacturers try to make it as hard as possible for the person running the TEE to peek inside. But you still have to trust the operator to not put a stethoscope to the box to try to figure out what's happening inside. 

In this case, it’s reasonable to consider these systems “privacy-preserving,” but not “encrypted.” That distinction is important, especially when we talk about how the TEEs interact with secure messaging. When someone using an end-to-end encrypted chat app asks an LLM to summarize, review, or store those messages, the content of those messages is leaving the device and going to an unencrypted third-party server somewhere. That’s a major threat to the privacy of secure chat apps, and one that’s increasingly hard for users to take control of.

How Does This Translate to Practical Advice?

The answer to this is going to vary based on an individual’s threat model, but a good rule of thumb is that a user’s device should never automatically send data to a TEE. When the person holding a phone can choose what information is sent, even if it’s a chunk of data like “unread messages,” they have the opportunity to pause and consider if that data might be too sensitive to risk sending.

In contrast, when data is sent automatically, the automatic sending becomes a feature of the system as a whole. If the system was previously end-to-end encrypted, adding automatic exfiltration makes the whole system no longer end-to-end encrypted.

Developers: don’t build systems that automatically send data off a device to a TEE, especially when it’s coming from an app that is otherwise end-to-end encrypted.

Users: if developers ignore us and build that system, turn off any automatic data sending features. Take a second to think about how much you’re willing to risk sending data when you choose to send it off the device.

So, What Should I Be Concerned About?

TEEs are useful for security in a number of circumstances. Your phone likely has a TEE where it keeps the key that encrypts your biometric unlock data and the base of the keychain where passwords are stored. It also enables certain backup systems, like how you can restore a phone with your passcode or restore WhatsApp or Signal backups.

But when we’re talking about cloud processing, it’s important to be clear this isn’t the same as end-to-end encryption and doesn’t offer the same level of privacy. 

Most of our private lives are on our phones and in our messages. We’ve worked for years to secure those messages, with major wins like encrypted RCS, and the continued user experience improvements of Signal and WhatsApp. We’ve even seen real improvements to backup security with features like Advanced Data Protection that bring end-to-end encryption for a variety of data outside of messaging, like notes and photos. 

But as companies roll out AI features that interact with these encrypted services, pulling data off devices and into a cloud-based TEE, they’re eroding the privacy protections of end-to-end encryption and risk causing serious confusion around what data is protected and what isn’t.

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

Thu, 09/17/2026 - 9:16pm

With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. 

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public's security.

When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else's computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.

Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.

As with any technology regulation, those targeting cybersecurity practices at AI labs must be careful, precise, and practical.

California’s “Addictive Feeds” Law Violates Teens’ First Amendment Rights

Thu, 09/17/2026 - 3:43pm

A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week.

The case, Meta v. Bonta, challenges SB 976, which requires that teen social media users get their parents’ permission before seeing other users’ recommended speech on their social media feeds. The legal challenge to SB 976 has largely centered on how the law violates social media services’ First Amendment rights to curate user-generated content and present it as they see fit.

But the friend-of-of the-court brief EFF filed along with the Center for Democracy & Technology and the Wikimedia Foundation shows that the law violates teen users’ First Amendment rights, too.

“SB 976 frustrates young people’s ability to use the internet to its full potential, prohibiting them from relying on tools that disseminate their speech and help them view and interact with other users’ speech,” the brief argues.

Recommendation systems have a dual purpose on social media: they help all users discover speech and content by other users, and to get their own speech in front of a wider audience.

“SB 976 creates significant, constitutionally violative, burdens on young users’ ability to read and comment on the news, discuss politics, find and share art, share their religious beliefs, or even practice their religion with fellow members of their faith,” the brief argues. “There is simply too much content on services for users to sift through manually, and young users may not know what to search for or even how to find content.”

Because SB 976 creates such broad burdens on teens’ ability to distribute and receive speech, it should be struck down on First Amendment grounds. But as EFF’s brief argues, the First Amendment doesn’t stop California and other states from passing laws that help all users, regardless of age, avoid major social media services’ harmful surveillance business models.

“One could imagine a law that required services to minimize the amount of data they collect, or limit using more invasive data analysis practices, such as tracking users across multiple services, analyzing keystrokes, and other surveillance-intensive practices,” the brief argues. “Such restrictions likely would serve the state’s aim of protecting all internet users—including minors—and would be more narrowly tailored to addressing the harms those practices cause than SB 976.”

Victory! Appeals Court Rejects Expansive New Copyright Claim

Wed, 09/16/2026 - 6:47pm

 The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyright liability.  

The case involves Section 1202 of the DMCA, which prohibits intentionally removing copyright management information (CMI) like an author’s name or a copyright notice, from a copyrighted work. Open AI and Microsoft used code from Github as part of the training data for their LLMs, along with billions of other works. A group of anonymous Github contributors sued, alleging the new code coming out of these LLMs was similar to theirs—but with the CMI stripped out.  

The Ninth Circuit correctly agreed with what we said in our brief: removing copyright information from a copyrighted work is fundamentally different from creating a new work that didn't have CMI in the first place. Section 1202 of the Digital Millennium Copyright Act was intended to serve as a backstop for traditional copyrights in the digital age—not to create a new, more expansive right to inhibit otherwise non-infringing uses. 

As we also explained, accepting the Does’ theory would have created a brand-new source of liability for otherwise perfectly lawful activities, undermining creativity and innovation far beyond the specific context of AI development. Copyright holders would be able to file costly lawsuits against all kinds of legitimate users, such as artists making remixes based on older works, teachers adapting works for a classroom presentation, engineers reverse engineering code to understand it better, and search engines that help us all navigate the web. The risks would have fallen especially hard on independent software developers and other small creators. Large companies can afford to litigate these claims in federal court for years, if necessary. But an independent programmer facing massive statutory damages may simply have to settle, even when their underlying use is completely lawful. That’s why EFF fights to make sure courts don’t expand copyright beyond what Congress authorized.  

Copyright law still protects programmers when their work is unlawfully copied. They can still bring copyright infringement claims if someone uses a model to reproduce their code. Additionally, the plaintiffs’ contract claims against the AI companies are still in play. The specific holding here was narrow but important: that the absence of copyright information from a new work does not mean, by itself, that someone illegally removed it.  

That’s the correct result. New technologies will keep raising hard questions about copyright. Courts should answer those questions by applying the rights that Congress actually authorized, not by inventing new rights that could harm expression and lawful use for everyone.  

Additional Reading:  

Victory: Court, Using a New Test, Rules Embedding Links is Legal

Wed, 09/16/2026 - 12:50pm

Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable if the content turns out to be infringing.

News publisher Emmerich Newspapers sought to convince the Fifth Circuit Court of Appeals to chart a new and dangerous course, arguing that an aggregator website that published links to its copyrighted articles was in effect “displaying” them and can be directly liable for infringement. EFF, along with several other public interest organizations and trade associations, filed a brief urging the court to follow multiple other circuits and reject that theory.

Fortunately, the Fifth Circuit Court of Appeals did just that. While it rejected the server test–the rule courts have used to determine copyright liability rests with whoever serves up the content–the court came to the same practical conclusion by focusing on who is responsible for transmitting content. 

Applying that test, the court found that pointing or directing a user’s browser to request and receive the copyright owner’s own copy residing on its computers does not involve transmitting or communicating the content. “Although we take different routes to get there, both the server test and the test we announce end up in a similar place: a website cannot transmit a work that it does not have,” the court said. 

We told the court that accepting Emmerich's theory would make the common act of embedding links a legally fraught activity, one that many websites might be unwilling to risk, which would seriously damage the internet as a tool for creating and disseminating ideas and knowledge,

We applaud the court’s decision–even though it applied a different test, it correctly concluded that a user linking pictures, video, or articles isn’t in charge of transmitting that content to the world. The user doesn’t control what’s located on the other end of the link—that’s up to the person who controls the server.

Emmerich also claimed linking violates the Digital Millennium Copyright Act (DMCA), arguing its URLs were copyright management information (CMI) and when the aggregator displayed Emmerich’s articles under its own URL, it tampered with Emmerich’s CMI, which violates the DMCA. 

Under that logic, unsuspecting internet users could face ruinous legal risk for doing something as simple as using a link shortener, particularly given potential statutory penalties of up to $25,000 per violation.  

In our brief, we told the court that URLs don’t necessarily equate to a copyrighted work or provide sufficient information about the nature of the underlying content, making it highly unlikely that anyone would expect a URL to contain CMI. Quoting EFF’s brief, the court concluded that URLs are first and foremost a locational reference tool and while it may be possible for a URL to contain CMI, the bar to that conclusion is high.

Overall, this was a good and sensible decision that will protect ordinary online expression, communication, and access to knowledge. Hopefully this issue is laid to rest at last.

Related Cases: Emmerich Newspapers v. Particle Media

Pages