EFF: Updates
Site-Blocking Will Not Defend IP, No Matter the Bill’s Name
There has been a raft of site-blocking bills in the latest Congress, and the latest is called the “Deterring Extraterritorial Foreign Exploitation of Networks Damaging Intellectual Property” aka the “DEFEND IP Act.” The problem is that instead of “defending IP,” this bill will incentivize censorship, overblocking, and bad faith attempts to block access to a website. DEFEND IP Act, and all of these site-blocking proposals, threaten the open web.
We keep seeing attempts to pass site-blocking legislation–from SOPA/PIPA in 2012 to Block BEARD, FADPA, and ACPA this year. Every one of them has at its core the rotten idea that enforcing copyrights requires building a censorship machine for websites into the architecture of the internet. This is, of course, a disaster for a free and open web. There is no way to create a mechanism for blocking access to an entire website that does not invite both deliberate abuse and lots of collateral harm to free and lawful speech.
DEFEND IP deputizes every service provider into a copyright cop, so long as a rightsholder has accused a website of copyright infringement. Let’s be clear: this isn’t about removing access to an infringing work–that already exists via the DMCA. This isn’t about getting damages from the website or the uploader. It is about making an entire website inaccessible for everyone trying to visit it.
DEFEND IP lets any rightsholder go to a court and get an order requiring service providers to block access to an entire website after alleging copyright infringement. What DEFEND IP does not have is any deterrent for someone seeking to block a website in bad faith. There are no punishments for getting a website blocked for protected speech. There are no meaningful remedies for those whose speech is vanished from the internet due to an entire website being disappeared. It creates a one-stop shop for getting an entire website–again, not an instance of infringement but an entire site hosting all sorts of user content–removed. But for those whose business, speech, or access to information is affected, there is no easy way to get the site restored.
DEFEND IP scales up the extraordinary legal structures that already exist for copyright enforcement. In doing so, it likewise scales up the problems those regimes pose to protected speech.
We see this with DMCA takedowns all the time. We see it with bad faith takedowns used to silence criticism or commentary. We see it with the voluntary use of copyright filters by sites like YouTube, where seconds of sound matching seconds of sound in another video can prevent an entire work from reaching its audience. In these existing systems, there are at least some mechanisms of challenge available to the targeted creator. DEFEND IP has none. Instead, site owners, users, or readers will have to find a lawyer and go to court and hope to challenge the order, a slow, expensive, and daunting process
Those existing systems are already frustrating for the targeted creators and users, but under DEFEND IP a whole class of people doing protected speech will find themselves deplatformed because of the actions of others
This bill is not a defense of creativity or creators. It is a way to reshape the internet by building a vast new infrastructure of censorship. Congress should put aside DEFEND IP and the failed idea of site-blocking laws, for good.
Congress Has Another Site-Blocking Bill, And This One Targets VPNs
Congress is taking another run at site-blocking, a deeply flawed concept that would undermine basic internet infrastructure. Rep. Darrell Issa (R-CA) has introduced the American Copyright Protection Act (ACPA), H.R. 10364, a bill that would give copyright owners a new legal tool to block Americans’ access to foreign websites accused of copyright infringement.
The basic idea is all too familiar, and it’s still dangerous. A copyright owner first asks a court to label a foreign website a “foreign piracy site.” Once that happens, the copyright owner could seek orders requiring internet service providers, DNS providers, and—new and explicit in this bill—VPN providers to take “commercially reasonable steps” to stop their users in the United States from accessing those sites. The decision to label a website as a “foreign piracy site” can happen without the accused site even showing up in court to defend itself.
ACPA Goes Further Than Other Site-Blocking ProposalsIn some ways, the ACPA is even worse than a site-blocking legislation introduced last year, the Foreign Anti-Digital Piracy Act (FADPA), which EFF also opposed. That bill at least excluded companies that provide only VPN services, as well as providers that offer DNS resolution exclusively through encrypted DNS protocols. The ACPA drops those protections. In fact, the bill explicitly includes VPNs among the service providers that can be ordered to block access to a website.
The bill also broadens the definition of a “piracy site.” Last year’s site blocking bill covered sites with “no commercially significant purpose or use” other than infringement. ACPA changes that to sites with “only limited commercially significant purpose or use” beyond infringement. In other words, under ACPA, even a website with legitimate commerce going on could still be labeled a “foreign piracy site” and ultimately blocked for all Americans.
Better Process Still Doesn’t Fix The ProblemThe ACPA includes some procedural protections, such as requiring service providers that could be subject to a blocking order to receive legal notice and an opportunity to respond. The bill also requires courts to consider the potential harm to other websites and internet users before ordering intermediaries to block websites. It further requires the copyright owner to post a bond, in an amount determined by the court, sufficient to cover the costs and damages incurred by any service provider found to have been wrongfully enjoined. The bill also provides a mechanism for operators or users of third-party online services affected by erroneous blocking to seek compensation after the fact in certain circumstances. Finally, a site operator can ask a court to rescind its designation as a “foreign piracy site.”
These safeguards are significant and positive changes, but they don’t solve the basic, and severe, due process problem. The initial decision to label a website a “foreign piracy site” can still be made without the site operator appearing to defend itself. The court can appoint a “special master,” which is an independent expert who helps the judge evaluate evidence, to review the copyright owner’s case—but that step is not required. In any case, a special master is not a lawyer who actually represents the accused website, nor the users whose access to information and speech may be affected.
We know what site-blocking looks like when it’s put into practice. Supporters of site-blocking like to point to its use in other countries. But what we’re seeing in other countries is serious collateral damage to lawful websites. In Italy, 510 benign, non-streaming websites, including a Catholic convent and a telehealth platform, were blocked by the country’s “Piracy Shield” program. In Spain, a site-blocking system blocked more than 550,000 domains during soccer broadcasts, including sites belonging to Greenpeace and Harvard University.
Congress Should Reject Site-Blocking ProposalsMore than a decade ago, Congress abandoned SOPA and PIPA after internet users pushed back against site-blocking and other threats to the open internet. We shouldn't start building that infrastructure now.
ACPA adds some safeguards, but those don’t fundamentally change what Congress is being asked to create: a system for blocking Americans’ access to entire websites at the request of copyright owners. By explicitly bringing VPNs into that system, the bill also reaches into basic tools that people use to access the internet safely and privately. Adding somewhat better procedures to a bad idea doesn’t turn it into a good idea.
Victory! Court Rejects Government Effort to Dismiss Social Media Surveillance Lawsuit
NEW YORK — A lawsuit filed by three labor unions against the Departments of State and Homeland Security for their viewpoint-based surveillance and suppression of protected expression online can move forward, a federal judge ruled yesterday.
On October 1, 2026, Judge Alvin K. Hellerstein of the U.S. District Court for the Southern District of New York rejected the government’s motion to dismiss the lawsuit. The case was filed in October 2025 on behalf of the United Automobile Workers (UAW), Communications Workers of America (CWA), and American Federation of Teachers (AFT). The Electronic Frontier Foundation (EFF), Muslim Advocates (MA), and the Media Freedom & Information Access Clinic (MFIA) represent the labor unions.
This decision is a victory: The Court held that claims that the government’s social media surveillance program is harming the unions’ members, as well as hampering the ability of the unions to associate with their members and potential members, can move forward.
The Court ruled that: "This threat of adverse immigration consequences, under a government whose harsh immigration crackdowns has been heavily publicized and reported on, is certainly enough to 'deter a person of ordinary firmness from the exercise of First Amendment rights.' It is objectively reasonable that noncitizens would limit their expression of disfavored viewpoints under the [Challenged Surveillance Program] given the credible threat of adverse immigration action from the Government."
"The freedom of Plaintiffs' members to speak, associate, and appear publicly is not incidental to union work, but rather is the mechanism through which unions recruit, organize, communicate, and bargain," the Court further explained. "A program alleged to silence members and drive them from the unions' rolls therefore strikes at the unions' representational function itself, which is the 'grounds that bring [their] membership together.'"
Since taking power, the Trump administration has created a mass surveillance program to monitor constitutionally protected speech by noncitizens lawfully present in the U.S. Using AI and other automated technologies, the program surveils the social media accounts of visa and green card holders with the goal of identifying and punishing those who express viewpoints the government disfavors. The surveillance program has been paired with a public intimidation campaign—silencing not just noncitizens with immigration status, but also the families, coworkers, and friends with whom their lives are integrated.
In October 2025, UAW, CWA, and AFT sued the Departments of State and Homeland Security, alleging that this viewpoint-based surveillance program violates the First Amendment and the Administrative Procedure Act.
"No one should have to fear government surveillance or retaliation against their immigration status for expressing their views or participating in their union. We're pleased the Court has allowed this challenge to move forward and will continue fighting to protect the rights of everyone to speak, organize, and advocate without fear," said UAW President Shawn Fain.
"This is a victory for working people, for the labor movement, and for our democracy," said CWA President Claude Cummings Jr. "Our very freedom is under attack by the Trump administration's online surveillance program, and today's decision is a critical first step toward affirming our freedom to speak, to protest, to organize without fear of government retaliation. These essential freedoms underpin our union rights to join together and fight to improve our working conditions. CWA is a fighting union, and our members remain ready to stand together to protect our rights and our freedoms."
"Today’s decision is a critical step toward vindicating our Constitutional right to freedom of speech and rejecting the Trump Administration’s cynical attempts to criminalize and punish those who disagree with them," said AFT President Randi Weingarten. "Government surveillance to monitor the 'opposition' is a tool of dictators that erodes the democratic principles this country was founded on. We will continue to remain vigilant in defending our 250-year-old rights—not just for our members, but for all Americans."
"Our plaintiff-unions have members that have wholly changed the way they interact with social media—including limiting their engagement with union content—because of the government's social media surveillance program," said EFF Senior Staff Attorney Lisa Femia. "Many have stopped posting online together, and have even stopped engaging in offline activities, for fear of being scrutinized or targeted related to immigration benefits. We are pleased that the Court has agreed to let the case proceed, and allow unions and their members to seek justice for infringement of their rights."
"Today’s ruling is an important step forward in holding the government accountable for its ever-expansive online surveillance program that silenced non-citizens, stoking fear that exercise of their protected First Amendment rights could result in unfavorable treatment on their immigration applications or worse." said Sadaf Hasan, Staff Attorney at Muslim Advocates. "We will keep fighting until all non-citizens are able to freely associate, organize, and speak out without the looming threat of visa revocation and immigration enforcement simply because the government dislikes their views."
"Defendants' attempt to evade accountability on specious jurisdictional grounds was rightly rejected by the Court," said Nick Jones, a student in the Media Freedom & Information Access Clinic. "We are excited to see the case now proceed to the merits, where we expect to prevail as well.”
For the ruling: https://www.eff.org/document/uaw-v-dos-opinion-order-denying-motion-dismiss
For more about the litigation: https://eff.org/cases/united-auto-workers-v-us-department-state
Contacts:
Electronic Frontier Foundation: press@eff.org
Muslim Advocates: melissa@muslimadvocates.org
Ola Bini Ordered to Leave Ecuador Under Obscure Accusations
In a new blow to Ola Bini’s legal guarantees, Ecuadorean authorities retained the free software developer and security expert yesterday in Quito and ordered his immediate deportation from the country. He is barred from returning to Ecuador for 10 years.
According to information released by his lawyer, Bini was intercepted by a car with four people who identified themselves as immigration agents. He was then taken to an immigration office without further information or a formal order from a competent authority. There, officials told Bini that his visa had been revoked but didn’t show any supporting document.
Bini's defense filed a habeas corpus to safeguard his freedom and prevent his deportation. Yet, Ecuadorian authorities affirmed that the developer represents a threat or risk to public security and the state structure, and must leave the country. The ground for deportation is a secret report which allegedly asserts that Bini committed acts against the security of Ecuador. The defense could not access its contents.
The deportation hearing started yesterday at 5pm Quito time. Human rights organizations tried to attend the hearing but were denied entry. The hearing was suspended but later reinstalled establishing his immediate deportation. Ola Bini was relocated to Quito's airport and must stay there until fly back to Sweden.
The case that led to Bini's unfounded criminal conviction has expired (the statute of limitations ran out) and the court had already formally lifted all precautionary measures against him. Yesterday's events open a new chapter in the nefarious persecution of Ola Bini by Ecuadorean authorities.
Since Bini’s arbitrary arrest in 2019, EFF has reported about his criminal prosecution fraught with misconceptions and rights violations. The script of what happened yesterday follows the same patterns we saw in the entire case, from its outset with unjustified allegations that Bini was a national security risk. The Observation Mission of Ola Bini’s case, joined by EFF and other digital and human rights organizations, has published reports and raised international awarenness about the perils of this case to the protection of rights online and the beneficial work of security experts.
In a case surrounded by political interests, Ola Bini’s unanimous acquittal by the lower court in 2023 was overturned after the prosecution’s appeal. The majority of the appeals court convicted Bini for attempted unauthorized access of a telecommunications system without actual evidence to corroborate the accusation claims.
Now, once again we must sound the alarm. Ecuadorean authorities must explain the accusations against the security expert. We will remain vigilant and ensure that at least this time his rights are respected.
We Demand More Information on How Marin Cops Illegally Shared Flock ALPR Data
The Marin County Sheriff’s Office is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data from their Flock Safety system with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which has put every driver in the county at risk and is especially dangerous for immigrants, abortion seekers, and other targets of the federal government.
Today, we sent the Marin County Sheriff’s Office (MCSO) a demand letter and request for records under the California Public Records Act following the Point Reyes Light’s recent report that MCSO provided non-California agencies access to its ALPR database. This directly violates California law and the terms of the 2022 Settlement Agreement in our case Lagleva v. Marin County Sheriff.
ALPRs are cameras that capture images of vehicles and upload their location to a searchable, shareable database. They are a mass surveillance technology that collects data indiscriminately on every vehicle on the road.
Sharing ALPR data with out-of-state or federal agencies—for any reason—violates California law (SB 34). If this data is shared for the purpose of assisting with immigration enforcement, agencies violate an additional California law (SB 54).
But network audit logs obtained by Point Reyes Light show that during the final months of 2024, Marin County Sheriff’s Office shared ALPR data with multiple out-of-state and federal agencies, including 254,131 times in November 2024 alone. Many of these searches were conducted by law enforcement in states that impose severe restrictions on reproductive care and have a history of assisting ICE, including Alabama, Indiana, Kentucky, Florida, and Texas.
This sharing violated state law and “exposed sensitive driver location information to misuse by the federal government and by states that lack California’s robust privacy protections,” the letter explains.
This is not the first time MCSO has shared Marin County ALPR information with federal and out-of-state agencies in violation of California law.
Back in 2021, on behalf of community activists, EFF and ACLU sued the Marin County Sheriff for illegally sharing millions of local drivers’ license plate numbers and location data with hundreds of federal and out-of-state agencies, including ICE and Border Patrol.
The parties eventually reached a settlement, under which the Sheriff agreed to stop sharing license plate and location information with agencies outside of California to comply with state laws SB 34 and SB 54.
“MCSO’s November 2024 audit report shows that your office has violated not only SB 34, but the terms of the Lagleva Settlement Agreement as well,” the letter explains.
EFF and ACLU are urging MCSO to launch a thorough audit of its ALPR database, institute new protocols for compliance, and assess penalties for any employee found to be sharing ALPR information out of state.
“While your office claims that it took deliberate steps to disable nationwide data-access capabilities and ensure your system operated within strict privacy safeguards, you have not explained how outside agencies nonetheless obtained access, how you plan to prevent future violations of SB 34 and the Lagleva Settlement Agreement, or why you did not take steps to inform the public and the Marin County Inspector General once you learned about the breach,” the letter explains.
As we’ve demonstrated over and over again, many California agencies continue to ignore these laws, exposing sensitive location information to misuse and putting entire communities at risk. As federal agencies continue to carry out violent ICE raids, and many states enforce harsh, draconian restrictions on abortion, ALPR technology is already being used to target and surveil immigrants and abortion seekers. These incidents have made it clear that having ALPR programs are incompatible with the protection of residents. California agencies, including Marin County Sheriff’s Office, have an obligation to protect the rights of Californians, even when those rights are not recognized by other states or the federal government.
See the full letter here: https://www.eff.org/document/20261001-letter-aclu-norcal-and-eff-marin-sheriff
Challengers Approach: Third Party App Stores Arrive to Google Play
If you are an Android user, you may have noticed it already: Google has begun allowing rival, third-party app stores to be distributed through the Google Play Store. And if you are a developer, you may have noticed new options for billing and distributing your apps.
For years, Epic Games, maker of games such as Fortnite, has been suing Google, alleging violations of antitrust law. Specifically at issue were Google's restrictions on the distribution of alternate app stores through the Play Store, restrictions on app developers who have little practical choice but to distribute their apps through the Play Store, and Google’s rules governing in-app payments and the fees associated with them.
Epic’s challenge ultimately resulted in a court order requiring significant changes to Google’s practices. Among other changes, rival, third-party Android app stores are now allowed to access the Play Store’s catalog and to be distributed through the Google Play Store. Developers also have greater freedom to direct users to alternative payment and distribution options.
These changes give users and developers more choices and create new opportunities for competition in the Android ecosystem, breaking the power Google once had over many facets of the app ecosystem. This is a win for competition and antitrust enforcement. But the benefits can extend beyond competition itself—more meaningful choice can also create opportunities for greater freedom of online expression, privacy, and security.
With alternate app stores able to compete for Android users, Google no longer has the first and last say on what apps can reach users and on what terms. Developers have more options for reaching their audiences, rather than having a single company’s rules determine the terms of access.
More importantly, Android users are no longer trapped in an arrangement of feudal security with Google, where users must depend on the goodwill of a monopolist to protect them and guarantee their safety. If Google does not adequately protect their data or security, Android users can now switch to a competitor that does a better job. And if that competitor fails them, they can choose another.
Competition in the app store market therefore means competition not only over which apps are offered, the user experience, and developer fees, but also over privacy and security. Users and developers gain something fundamental in the process: the ability to choose.
As we’ve previously written, antitrust has never been just about prices—it’s also about power. It is about who gets to control and shape the future of the internet. A world in which a handful of dominant platforms can dictate how users access apps or programs, how developers reach them, and what rules govern those interactions is one in which users have fewer meaningful choices. Without Epic’s successful antitrust challenge and the changes that followed, users would have remained in a world of feudal security, where they would have been left begging their feudal tech lord for more.
The arrival of competitor app stores on Google Play does not solve every problem with the Android ecosystem. But it opens the door to something that dominant platforms have spent years trying to keep out: meaningful competition. And each new competitor gives users another opportunity to choose something better.
Related Cases: Epic Games v. GoogleCourt Agrees with EFF: Utah’s VPN Law Demands a Technical Impossibility
When state lawmakers attempt to rewrite how the internet works, users rely on courts to recognize that laws can’t make technical impossibilities a reality. That’s why we were happy to see that a court has blocked Utah’s attempt to outlaw the privacy protections of Virtual Private Networks (VPNs).
In a win for digital rights, a federal judge has issued a preliminary injunction blocking Utah’s SB 73, the state’s draconian anti-VPN age verification law. The decision comes as EFF submitted our comments to the Utah Department of Commerce, detailing how forcing platforms to detect and block privacy-preserving tools undermines user privacy and security worldwide while demanding the impossible.
What SB 73 DoesSigned into law earlier this year, SB 73 attempted to regulate adult websites by requiring them to block VPN users or to identify the physical location of visitors using them or similar tools that mask their network traffic. It even went so far as to prohibit websites from offering instructions on how to use a VPN to bypass these checks. This made Utah, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates.
The Utah federal court halted enforcement of the law's VPN provisions last week, ruling that the law likely violates the U.S. Constitution’s prohibition on passing laws that significantly burden businesses and people outside Utah’s borders.
SB 73 burdens the rights of all internet users outside of Utah because it requires adult websites to either know every visiting user’s physical location, and then block those in Utah, or to verify every visitor’s age just in case they might be in Utah. The law’s “actual-location provision in practice requires an entity to perform age verification services for every user visiting its site from any location because the entity would violate the law if even one of those users happened to be obfuscating,” the court wrote. The court essentially ruled that Utah has less-burdensome ways to prevent Utah minors from accessing adult websites than requiring all users in the world to comply with SB 73.
Aylo’s lawsuit does not challenge SB 73’s provision prohibiting the websites covered by the law from sharing information about VPNs.
The Legal ChallengeThis court order follows months of legal maneuvering.
Initially set to go into effect in May 2026, SB 73 sparked an immediate constitutional challenge from Aylo, the parent company of major online adult platforms like Pornhub. In response to the lawsuit, Utah and Aylo initially agreed that the state would pause enforcement while the court considered the preliminary injunction request or until administrative rules setting specific compliance terms were finalized. Those proposed compliance rules (R152-78B, see Utah State Bulletin, page 6) were published by the Utah Department of Commerce’s Division of Consumer Protection on September 1st, and EFF submitted formal comments to the Department in opposition. According to the notice, the proposed rules could be effective as soon as October 8, 2026. However, Judge Barlow’s decision means that it cannot be enforced pending further action by the court.
The RulingEFF welcomes Judge Barlow’s ruling, which recognizes the fundamental disconnect between state legislation of the internet and how technology works. In his ruling, Judge Barlow noted that the statute requires a technical impossibility on pain of legal liability. “Aylo is correct that the statute, as amended, now essentially imposes strict liability for entities like it when it comes to determining the location of its websites’ users.”
The court recognized that the problem is that SB 73 “requires entities like Aylo to geolocate its website users with perfection to avoid liability.” But, at the same time, the court acknowledged “that geolocation perfection is not presently possible.”
EFF explained this technical impossibility in our comment to the Department of Commerce. VPNs protect user privacy by routing web traffic through intermediary servers. Because destination websites only see the IP address of the VPN server, they have no reliable mechanism to tell whether a connection originates from Salt Lake City, Seattle, or Shanghai. So, under Utah's current statutory framework, platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely. Judge Barlow agreed, asserting:
Because the law requires perfection in the absence of perfect geolocation tools, Aylo would need to verify those 28 million users—whether located in Salt Lake City, Boston, New Orleans, Anchorage, or Honolulu—to ensure compliance and avoid liability.
The RulemakingThe administrative rules drafted by the state compelled commercial entities to implement "commercially reasonable geolocation obfuscation detection systems", which is a directive, we argue, that demands a technical impossibility.
In our submission to the Utah Department of Commerce, EFF also detailed how these rules force an invasive data collection regime onto internet users everywhere. So, in response to internet users trying to avoid invasive data collection required by age-verification requirements, SB 73 requires even greater surveillance of internet users’ online activities. The Department’s suggested detection heuristics (like monitoring connection latency or device time zones) are notoriously unreliable and easily skewed by normal network conditions. This active surveillance inevitably leads to widespread misclassification, unwarranted access blocks, and severe impacts on users’ privacy far beyond Utah's borders.
You can read EFF’s full comments to the Department of Commerce here.
What Now?As we’ve said time and time again: the internet will always route around censorship.
Mandating invasive tracking and punishing the use of essential security tools turns genuine privacy concerns into mere compliance theater and requires more state-mandated surveillance of internet users who rely on VPNs. As is the case in heavily censored regions, VPN services and obfuscation tools will simply adapt, making this framework fundamentally unsustainable.
As we’ve said time and time again: the internet will always route around censorship.
While Utah legislators have indicated they may attempt to revise the law during the next legislative session, the court's preliminary injunction sets an important precedent: state lawmakers should not weaponize age verification to force dragnet tracking or undermine essential security tools.
As other states consider similar anti-VPN proposals, EFF will continue pushing back against these technically impossible mandates and defending users’ privacy and anonymity. Thus, we urge legislators and regulators to reject anti-privacy rules, prioritize real user security, and safeguard constitutional protections for all users.
Happy Opt Out October! Let’s Find Real Alternatives to the Tech Giants
Over the years, the major tech companies have found all sorts of ways to embed themselves into our lives. We often use their software, their AI tools, their social media, and their operating systems by default without even thinking about potential alternatives. It’s time to rethink that relationship.
Last year, we created Opt Out October to help remind ourselves of the variety of ways we can take back control of our data through small steps inside apps, operating systems, and other various forms. This year, we highlight the idea that sometimes the best way to control your data is to leave a platform, app, or operating system altogether.
To do so, we’ve created a hub of resources sharing ways to find new software that isn’t made by the tech giants, take advantage of the growing universe of new social media options, install a whole new operating system, and better control how various popular tools and software use your data for AI training.
As an incentive, we’ve made merit badges like the one below to help you track your own wins and share them with others. Complete any of these tasks and let the world know by sharing that accomplishment on social media or changing your profile image! Better, more privacy-respecting, and less-enshittified tools are out there. We just have to find and use them.
Head over to our Opt Out October landing page and start taking the first steps to regaining control of the tools and software you use.
Victory! California Appeals Court Refuses to Revive Surveillance Tech CEO’s Meritless Lawsuit Against Journalist
When the rich and powerful try to use the court to silence negative reporting about themselves, it’s worth calling out that behavior for what it is: an attack on free speech. This is why EFF is happy to stand up for reporters who find themselves in that situation.
The California Court of Appeals upheld a lower court’s decision to strike a former Premise Data CEO’s meritless lawsuit against a journalist who exposed the CEO’s secret arrest for felony domestic violence. Jack Poulson, the writer and publisher of All Source Intelligence, reported details from the San Francisco Police Department’s report of the arrest and posted a copy of the report after receiving the document from a confidential source. Poulson later learned the arrest record had been sealed. The CEO, Maury Blackman, sued Poulson, Substack, AWS, and another organization for damages to try and force the removal of Poulson’s reporting from the internet.
The trial court tossed the entire case under California’s anti-SLAPP statute—SLAPP stands for “strategic lawsuit against public participation” and describes cases where the goal isn’t vindication in court so much as it is costing someone time, money, and peace of mind fighting the lawsuit. To fight SLAPP cases, states like California have passed anti-SLAPP laws, which are invaluable tools for protecting the First Amendment. California’s law provides an avenue for early dismissals of these baseless lawsuits, which curtails their intended effect on the target. Blackman appealed the court’s decision, arguing that a court order sealing the arrest overrides Poulson’s right to report the news.
The Court of Appeals correctly rejected Blackman’s appeal and affirmed the decision to throw out the case. The court held that the First Amendment protects Poulson’s publications. As the court explained in its decision, “the First Amendment protects the lawfully obtained truthful publication of the information at issue absent ‘a need to further a state interest of the highest order,’” a standard that Blackman’s privacy interests do not satisfy. The Court also found that Poulson, as the publisher of the All Source Intelligence newsletter, was protected by California’s Shield Law, relying on precedent established by EFF in 2006. The Court also affirmed that Substack and the other website, which had merely temporarily hosted a copy of the arrest record, were immunized from liability by Section 230.
This decision is a win for free speech, for Jack Poulson, and for everybody.
Related Cases: Blackman v. Substack, et al.📱 Hey Siri, How Do I Limit AI Data Access? | EFFector 38.17
With the launch of iOS 27, Apple is rolling out a variety of new AI features to its familiar voice assistant, Siri. But how are AI tools like these handling our data? In our latest EFFector newsletter, we're talking about the privacy complications of AI phone features.
For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers drones and our right to record the law enforcement, video doorbell footage privacy, and how to limit what data Apple's new Siri AI can access.
Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Thorin Klosowski about the difference between AI phone features that are computed on-device and ones that are computed on external servers—and what that means for data protection. You can find the episode and subscribe on your podcast platform of choice:
%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2Ff5abca72-7d82-4e94-9c0b-0d9f991891f0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E
Privacy info.
This embed will serve content from simplecast.com
Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!
While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards
San Francisco's decision to retain its use of Automated License Plate Reader (ALPR) surveillance cameras belies what we know about this spying technology tool: it endangers residents and threatens the privacy and civil liberties of our community. Based on what's in the city's press release and announcement, this policy will do nothing to stop actual harms.
We know innocent drivers will be stopped and menaced by officers because of erroneous matches. We know officers use Flock to stalk potential and past romantic partners. Data will be accessed by Immigration and Customs Enforcement (ICE) and used to deport immigrants. Promising greater penalties for such abuse will not end this. These are not isolated mistakes that another policy can fix. They are consequences of building a system that records everyone’s movements and makes them searchable by police. This is also not unique to a single vendor. From Flock Safety to Motorola to Axon—San Francisco must end its use of ALPRs.
We ultimately cannot rely on new protocols from city officials, and the City’s new policy is woefully inadequate. There is no warrant requirement to search stored ALPR data. An incident or computer-aided dispatch (CAD) number is not judicial authorization. Without a warrant requirement, officers can search stored location data without showing probable cause to a judge, and will. Without judicial control, officers will continue to search the data for abusive reasons. But a warrant requirement alone would not justify retaining the ALPR network: the community is demanding an end to the collection itself.
Additionally, the announced policies include no deadline to delete ALPR data, there is only a 30-day deadline to move data from the vendor’s servers to the city’s servers. City officials must understand that moving data is not deleting it. Whether Flock or SFPD stores the data, it remains a permanent record of where people drive, worship, work, organize, seek care, and spend time with others. Thus, the best practice is deletion. New Hampshire requires deletion in three minutes, and Flock itself has reduced the default retention time to seven days. San Francisco can and should do better.
Lastly, while transparency and documentation are important concepts, better audit logs are not the answer. They can expose abuse only after a search has occurred. They cannot undo the disclosure of someone’s movements or justify collecting everyone’s location data in the first place; especially when we are talking about people’s lives and civil liberties. The city's announced policy does not even require officers to state, in their own words, why they are searching the stored ALPR data—an accountability rule that has exposed abusive searches across the country.
San Francisco is behind many communities that have considered the tradeoffs of ALPR surveillance and made the right choice by ending their contracts. San Francisco must do the same.
Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries
People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, and since the early days of the internet, a dedicated band of activists, lawyers and technologists have fought for a better, more secure and private digital future – a future that’s still attainable.
Cindy Cohn, who just finished a 26-year run with the Electronic Frontier Foundation including 11 years as its executive director, has lived this fight. She says privacy isn’t just about secrecy: It's ultimately about power – who has it, and who has the ability to protect themselves from it.
Welcome to the first episode of “Privacy’s Defenders,” a podcast about the people – lawyers, journalists, hackers, and others – who’ve fought to secure your digital liberties since before most people even knew what the internet was.
%3Ciframe%20height%3D%2252px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F2f955342-7675-4c8c-bb40-fa364d9a569d%3Fdark%3Dtrue%26amp%3Bcolor%3D000000%22%20allow%3D%22autoplay%22%3E%C2%A0%3C%2Fiframe%3E
Privacy info.
This embed will serve content from simplecast.com
(You can also find this episode on the Internet Archive and on YouTube.)
In this episode, Cindy talks with EFF cofounder John Gilmore about how he – an early employee at Sun Microsystems – came together with Lotus Development cofounder Mitch Kapor and cattle rancher, philosopher and Grateful Dead lyricist John Perry Barlow to create EFF as a bulwark against government investigation and prosecution of early internet users.
It’s a story of the Secret Service’s “Operation Sundevil,” jet-setting tech titans, tie-dyed cypherpunks, and a fateful house party in San Francisco’s Haight-Ashbury district amid the earliest days of online communications, setting the stage for the battles that created the internet as we know it and issues we still grapple with today.
The “Privacy’s Defenders” podcast is a follow-up to Cindy’s book, “Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance,” bringing to life pivotal moments in the voices of those who fought for your rights. Sales of “Privacy’s Defender” benefit EFF, so pick up your copy today!
Joanne Elgart Jennings co-produced and created this podcast.
Jarod Sport co-produced, mixed, and mastered it.
Corinne Ruff is our story editor.
We had additional help from Rachel Estabrook and Alison Broverman.
The original music was composed and performed by Nat Keefe of Hot Buttered Rum with Ben Andrews on the fiddle.
And other archival sound came from the Internet Archive's amazing collection, including the snippet of the Grateful Dead song “Cassidy” that John Perry Barlow co-wrote.
EFF to San Francisco Police: Drones are Powerful Surveillance Tools That Require a Robust Policy
The San Francisco Police Department (SFPD) began regularly deploying drones two years ago and has since expanded their use in a way that has outpaced its documented policy and evaded existing local and state oversight of these devices.
The department has a new proposed policy, which continues to be grossly inadequate in protecting privacy and civil liberties. At best, the draft policy continues the SFPD’s pattern of putting vague guardrails on a powerful surveillance tool, but at worst, if implemented, the policy could effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city with few guardrails.
EFF has repeatedly opposed the unaccountable development of the SFPD’s drone program and recently sent a comment to the Police Commission, the local civilian oversight body, about the SFPD’s new proposed policy.
The SFPD has been sidestepping oversight of its drones since 2024. In March 2024, San Francisco voters approved a heavily-funded, billionaire-backed measure, Proposition E, which sought to expand police access to surveillance technology. Among its impacts, Prop E removed drones from oversight required by the 2019 Surveillance Technology Ordinance. Nonetheless, in its haste to purchase drones after Prop E passed, the SFPD knowingly violated California’s AB 481, a state statute requiring law enforcement agencies to get approval from their local elected governing body before purchasing military equipment, including drones. Eventually the SFPD sought retroactive approval from the Board of Supervisors and, soon after, announced that it would be launching a drone-as-first-responder (DFR) program.
Now, San Francisco finally has an opportunity to update the SFPD’s guidance in a way that won’t quickly become stale, as has happened while the SFPD steadily increases the purposes for drone use. Though drones were initially identified as tools to use for specific actions such as vehicle pursuits and active criminal investigations, within a year, the SFPD expanded use cases to include patrol, i.e. unrelated to a specific incident. Along with this mission creep, the SFPD has also steadily and exponentially increased the number of drone flights, from roughly 350 deployments in 2024, to over 1,100 from January to August 2025, to over 3,500 in just the first five months of 2026.
The original draft of an updated policy brought by the SFPD to the local Police Commission, a civilian oversight body, earlier this month provided limited details and proposed allowing police to treat drone flights as an extension of their patrol abilities, paving the way for general surveillance, including of First Amendment-protected activity. The proposal received significant community pushback, and the San Francisco Public Defender’s Office authored a letter describing the policy’s shortcomings. That letter was signed by over a dozen local, state, and national groups, including EFF.
Based on these concerns, the Police Commission deferred taking action until the SFPD addressed them. The SFPD then revised its proposed policy, but this, too, falls short of providing practical guidance to officers and protecting civil liberties, as the Public Defender’s Office identified in a follow-up letter signed by over 40 organizations, including EFF.
EFF’s additional comment to the Police Commission, in part, calls out the incredible gap in oversight of these ballooning drone flights and the immense data collection they facilitate:
The revised policy states that “[unmanned aerial vehicles] may be used as an asset in any situation in which a member may be deployed for a public safety response or when a member onviews criminal activity” but fails to define what is meant by a “public safety response.” The revised policy also provides a definition of “Drone as First Responders,” but it fails to provide any more detail about appropriate DFR deployment. Without appropriate safeguards around deployment and use, drones could be deployed to every call for service, even in situations that are ultimately deemed nonincidents, collecting data along the way that is then stored for 30 days. This type of general patrol could effectively become general surveillance, which SFPD acknowledges is an inappropriate use of their drones and yet is still possible under the vague terms of the current DGO.
The Police Commission is set to consider the matter on October 14. You can read EFF’s full comment here.
EFF to Court: Trump's Use of Truth Social's Pay-To-See-Posts-First Scheme Violates Americans' 1st Amendment Equal Access Rights
EFF legal intern Simar Kaur also contributed to this article.
Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100,000 a month early access to government news, EFF told a federal court.
The First Amendment guarantees that members of the public have equal access to public officials’ public comments, we reminded the court.
EFF filed an amicus brief in support of a motion for a preliminary injunction in the lawsuit filed by The Intercept Media and the Freedom of the Press Foundation against President Trump and other administration officials. The lawsuit challenges their use of Truth Social as their primary social media method of making official announcements when that platform provides people who pay a fee for early access to such posts.
Trump uses his Truth Social account as his primary means of communicating with the public, including to announce military operations and ceasefires, foreign and domestic policy, and the removal and appointment of heads of federal agencies. Earlier in the year, Trump Media, which owns Truth Social, announced “Truth API,” a service that provides investors early access to “market-moving” messages from the president and other high-ranking officials for a fee of up to $100,000 per month.
The plaintiffs, the Freedom of the Press Foundation and The Intercept, contend that the president and other officials’ preferred use of Truth Social with this service violates the First and Fifth Amendments of the Constitution. The plaintiffs are asking the court to immediately prevent the president from posting on Truth Social in a manner that allows him to profit from selling early access to government information.
EFF’s amicus makes two main points.
First, the brief establishes that social media is pervasively used by government officials and agencies as a medium for official communication with the public, including to disseminate critical public safety information and make official announcements.
Second, the brief explains that the challenged practice violates the First Amendment, which guarantees a right to access public officials’ public comments on equal terms with other members of the press and public. Giving some people preferential access must at a minimum be reasonably justified to satisfy First Amendment scrutiny, a test the administration does not meet.
Lining the president and his company's pockets is not a legitimate government interest for restricting timely access to the government's statements. Further, the fact that the public could ultimately access the information from other, less direct channels does not eliminate the need for First Amendment scrutiny; mere delays in timely access still trigger First Amendment scrutiny.
EFF has been advancing the First Amendment right of equal access to government’s public social media posts since at least 2018. We’ve argued that the right of equal access, which is well established in offline contexts, must apply to official government social media posts as well. This case presents an excellent opportunity for a court to directly adopt that position.
DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
Online sports betting company DraftKings is using AI to target customers who are most likely to place losing bets and respond to gambling promotions. This kind of targeting is a form of online behavioral advertising, which is when companies personalize the ads they show you based on the data they’ve collected about you. The more data a company has, the more personalized the ad can be. While DraftKings is using AI to supercharge the harmful effects of online behavioral advertising, EFF has long argued that all behavioral advertising should be banned.
According to the New York Times, DraftKings is using its customers’ betting records to train a machine learning model to find losing gamblers. Once found, DraftKings sends these customers targeted advertising designed to lure them back to the site to place more bets—bets that DraftKings thinks will be losing ones. DraftKings has a business incentive to keep losing gamblers coming back to their site, because these are the users actually making DraftKings money. Unfortunately, those considered “problem gamblers” (people who repeatedly gamble despite harm to themselves, their finances, and their relationships) are highly likely to be targeted by this model. By re-engaging these individuals through targeted promotions aimed at keeping them on the platform, DraftKings is capitalizing on their vulnerability for profit instead of mitigating their risk.
Predatory online behavioral advertising isn’t new, but companies’ use of AI to process data and target customers has magnified its harms. Online behavioral advertising incentivizes the collection of vast quantities of data to power ad tech. Adding AI into the mix means that even more data is collected to train and refine models. Because AI operates as a black box, the humans building the models can rarely predict which data points are the most useful to the AI, driving them to continuously collect more data. AI also allows companies to process enormous data sets much faster, and, as a result, supercharges the harms of online behavioral advertising.
A direct consequence of online behavioral advertising is that it provides the data the surveillance industry needs to run. Data collected for targeted placement of ads is being sold to insurance companies, banks, and state and federal government law enforcement agencies such as CBP. ICE is also taking an interest in the data fueling ad tech: earlier this year, ICE published a Request for Information “seeking information to better understand how the industry’s commercial Big Data and Ad Tech providers can directly support investigations activities.”
DraftKings seems to be using solely “first party data” to target their ads, meaning that they’re using only the data they collect directly from their users and are not buying any additional data from third parties to fuel their machine learning model. This highlights how policy solutions that only limit third-party data sharing and selling would not be enough to prevent these predatory advertisements. Rather, policymakers must ban online behavioral ads.
What DraftKings is doing with their targeted promotions is just one example of how online behavioral advertising causes real harm to real people. But there are ways to take back control over your own data: EFF offers resources such as our Surveillance Self Defense project, along with other tips for how you can protect yourself on mobile apps and on websites.
DraftKings’ use of AI to target losing gamblers illustrates how ad tech evolves and how companies find new ways to use our data against us. This is why EFF believes that all behavioral advertising should be banned. If companies can’t send personalized ads, they’ll have less incentive to collect the behavioral data powering them.
D.C. Circuit Must Vacate a Drone Flight Restriction That Criminalized Recording Immigration Agents
EFF joined an amicus brief with ACLU, ACLU of D.C., National Press Photographers Association, and Professional Photographers of America to urge the D.C. Circuit to vacate an FAA drone flight restriction that violated the First Amendment right to record law enforcement. This is an important case—Levine v. FAA—challenging the ability of the government to punish drone pilots who record law enforcement officers engaged in official business.
As we wrote about earlier this year, the FAA issued a flight restriction for drones that had effectively criminalized the recording of Department of Homeland Security officers, including immigration agents from ICE and CBP, and their vehicles (what the FAA called “mobile assets” including “ground vehicle convoys and their associated escorts”) even if the drone was over half a mile away.
A drone operator, represented by the Reporters Committee for Freedom of the Press, sued the FAA in March [PDF]. But in April, the FAA rescinded the flight restriction.
The petitioner argued in his opening brief that the court should evaluate the legality of the flight restriction even though it was withdrawn. Drone pilots could still be punished for violations that occurred when the flight restriction was in effect. And the FAA could reinstate the flight restriction at any time, given that the rescission did not seem to reflect “a true change of heart” but rather an effort by the agency to avoid judicial review.
The amicus brief, filed in support of the petitioner, noted that drones are unique because they provide “perspectives that cannot be captured by ground-based imagery,” and they “are far more maneuverable than ground-level cameras, and they are both much cheaper and much safer than using a chartered plane or helicopter to record newsworthy events from above.” The brief highlighted that drones have captured “bird’s-eye images of protest activity” and “police uses of force against protestors,” and have “allowed journalists to provide the public with up-to-the-minute information about natural disasters without putting themselves in harm’s way.”
The brief argued that using drones to capture images and video is information-gathering activity protected by the First Amendment (similar to using cell phones to record law enforcement). The brief also argued that the FAA’s flight restriction appeared to be issued specifically to ban the recording of immigration agents and thus hinder accountability for their enforcement actions—it surely wasn’t a coincidence that the FAA imposed “no-drone zones around all roving DHS patrols just as those patrols were provoking intense national backlash.” If that’s true, it would make the FAA’s action a content-based restriction on speech that is subject to strict scrutiny—the highest First Amendment standard—and presumptively unconstitutional. And even under less rigorous standards of First Amendment scrutiny, the flight restriction is unconstitutional because the FAA can’t articulate any valid governmental interest justifying such a sweeping restriction on speech.
Resolving this issue to protect First Amendment rights is especially urgent as government agencies continue to sink billions of dollars into technology designed to counter drones—technology that could easily be deployed against journalists and other people hoping to use drones to document government abuse.
We urge the D.C. Circuit to review the petition and to vacate the FAA’s flight restriction, which would send a message that the government can’t avoid accountability by punishing those who exercise their First Amendment rights.
EU Kids Act Won't Keep the Internet Accountable and Trustworthy
The EU Commission draft law to restrict young people’s access to the internet that it presented last week will come at a high cost: it will put online services behind age gates, expand the use of intrusive age verification, and undermine the privacy of all users.
The EU Kids Act aims to protect children from risks associated with social media, video games, and AI systems by introducing age-based access rules, safety requirements, and stronger enforcement and oversight measures. It presents itself as building on the Digital Services Act (DSA) and puts into “hard law” some of the safety-by-design measures specified in the non-binding DSA guidelines on minors’ protection.
The proposal is built around the following elements: social media age “delay”, safety by design, age assurance and parental responsibility, and strong enforcement. Each of these measures are concerning.
Mandatory Age Gates for Social Media and Video-Sharing PlatformsFollowing the advice of an expert panel, the proposal would create a phased access to social media and video-sharing platforms deemed risky—a threshold met simply by relying on personalized recommender systems or offering “uninterrupted content consumption”: no service accounts for children under 13; restricted accounts under tight parental supervision from 13 to 15; and autonomous accounts in a safe-by-design environment from 15 to 18. Full online access is therefore reserved for adults.
However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups.
If this sounds complex and like a compliance nightmare, that’s because it is. The access delay comes with privacy-intrusive age verification across the board, relying on the EU age verification scheme. For teenagers, this law means significant control in the hands of their parents, who must set up accounts and prove that they are, in fact, parents, adding yet another problematic layer of verification.
In fairness, the Kids Act’s gradual approach at least appears to be designed with some proportionality considerations, rather than imposing a blanket social media ban. Just last month a French court declared such undifferentiated bans unconstitutional. The EU Kids Act distinguishes between age groups and certain services and follows a risk-based approach. This means, for example, that age verification is not required for existing accounts if the provider can tell with a “high degree of confidence” that the user is above the age threshold—a vaguely specified standard.
Yet, the law still indiscriminately covers social media and video-sharing, with virtually all mainstream services being covered by the proposal. The broad scope also sits uneasy with the use of age thresholds, which remain a blunt proxy for maturity. What is more, by focusing heavily on safety and harms, the EU Kids Act pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online. However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups. They also create a powerful infrastructure for control and further entrench the power of big tech.
The proposal exempts not-for-profit encyclopedias, scientific repositories and educational services, as well as open-source software-developing and-sharing platforms. However, no exceptions are foreseen for small and medium-sized enterprises, which will only foster the dominance of resource-laden tech companies that were already investing in similar measures. And we know that most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms.
Safety by Design Across Covered ServicesThe proposal’s second pillar, “safety by design”, casts a wider net. It applies across social media, video-sharing, online games, AI companions, chatbots and even app stores—with varying requirements. Providers must generally make child-safe design the default and can relax from the requirements only if they use age assurance to establish that the user is an adult.
For example, rules on addictive features such as infinite scrolling, safe account settings, and more choice over recommender systems are to provide a safe internet experience to young people. As regards AI companions and chatbots, the proposal requires companies to design their services to reduce minors’ exposure to emotional dependencies and harmful interactions. Online games are covered as well: they must come with contact protections. The law also makes app stores the gate keeper for age-appropriate access, based on an age-rating system.
The devil of these measures lies in the details, but all of them raise fundamental rights concerns and some of them seem poorly suited, if at all, to the decentralized architecture of the Fediverse. The requirement for very large online platforms to set up compliance plans before rolling out new services raises additional questions about the risks of transplanting product-safety doctrines of conformity and risk control into speech regulation. Deciding what is “safe” can easily become a question of what content people can access or share.
Next StepsBy choosing to regulate all these aspects through the Kids Act, the Commission not only but creates a privacy minefield, it also intermingles the digital fairness agenda with the more fundamental-rights heavy questions of age assurance and access to information. An unfortunate policy choice that will politicize well-intentioned efforts to curb manipulative and addictive design practices (read our position on the DFA).
It speaks volume that the Kids Act has not gone through a full impact assessment process, which would typically require a systemic check of alternative policy options and stakeholder consultations. Looking forward, we call on the EU lawmakers to pull the teeth of the most harmful suggestions and to make sure that the new measures don’t erode the fundamental rights of all users.
EFF Statement on California Governor's Executive Order on AI
California Gov. Gavin Newsom's executive order is an opportunity for a needed, thoughtful conversation about artificial intelligence and its potential harms. Everyday Californians are feeling real anxiety about the risks of artificial intelligence, and as an organization that works to ensure technology empowers people, EFF welcomes this order as a way for the state of California to lead a much-needed dialogue that addresses these concerns.
Nonetheless, the most immediate and current concerns with this technology are not about sci-fi scenarios concerning rogue super-intelligence. They are happening right now through biased algorithmic decision-making for employment or government benefits, AI-powered surveillance systems such as Flock cameras, and artificially inflated personalized pricing. People want state and federal leaders to act, and we urge Gov. Newsom to develop thoughtful policies to address those concerns. Today’s EO is a good start.
To that end, EFF supports the focus on expanding the reporting requirements under SB 53 (2025) for loss-of-control incidents, alongside third-party investigations. We urge the administration to consider how to make these third-party investigations available for smaller developers. As the Government Operations Agency prepares its recommendations for the governor, we urge leaders to also realize that the effectiveness of kill switches in advanced AI systems remains an area of active research. As such, they should ensure that - as we’ve previously mentioned - any technology regulation targeting cybersecurity practices at AI labs must be careful, precise, and practical. Moreover, we also caution that government-controlled kill switches run the risk of being used as a form of retaliation against protected speech, as demonstrated by the Trump Administration’s retaliatory actions against Anthropic earlier this year.
Ultimately, true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies by ensuring that algorithmic decision-making in both the government and private sectors respects people’s rights and well-being. We urge Gov. Newsom and the state of California to develop thoughtful policy in collaboration with those most at risk of harm to address these and other concerns.
How to Limit What Apple’s New Siri AI Can Access in iOS 27
Apple’s new operating system is here, and along with it comes a new version of Siri, dubbed with two very familiar letters: AI. As the name suggests, this Siri power-up resembles an AI chatbot more than the often derided voice assistant you might be used to. It has even evolved from a blob you invoke with a verbal command or a button press to a whole app. This update comes with a slew of privacy complications, but you can take some control over what this new Siri can access and use.
There’s no denying that the new version of Siri is far more powerful than it used to be, and arguably more useful at surfacing details on your phone. But that comes at the cost of deeper access. Once enabled, Siri and Spotlight are combined, unifying the interface. Where you may have once just pulled down on the screen to search for an app or contact, you’re now also invoking Siri.
Spotlight and Siri are now visually one and the same.
By default, ask Siri a question and it’ll search through your Apple apps, like Notes, Messages, emails, and more. As time goes on, if the developer chooses to let it, Siri will gain access to more and more third-party apps. If an app developer doesn’t add that support, then Siri AI won’t be able to access the contents of that app (unless it’s shared screenshot-style via a new feature called “on-screen awareness,” which we’ll talk about more in a moment).
For example, if Signal doesn’t choose to implement Siri AI support and you only talk to Bill on Signal, you won’t get an answer when you ask Siri AI, “What was the last photo Bill sent me?” But if you talk to Bill on Apple Messages and ask that same question, Siri AI will summarize what it thinks the photo is.
Sometimes Siri processes this data on your device. Sometimes it uses Apple’s Private Cloud Compute (PCC), which means the data is sent off your device to a cloud server. While you can try digging through the Apple Intelligence Report to figure out what’s sent to PCC, there’s no immediate visual indication from the user’s point of view when data leaves the device or when AI can handle it on the phone, iPad, or Mac itself. In practice, ask Siri AI a question and you’ll never really know if it’s being computed on device or off.
Apple claims what’s sent to PCC is not stored by the company after it is processed, but there are certain types of data or certain apps you might have on your phone that are not worth the risk. That’s especially true if you’re using a feature like Advanced Data Protection, which turns on end-to-end encryption for much of what’s stored in iCloud. Sending data that’s stored with end-to-end encryption off your device and into the cloud—no matter the privacy promises—is a fundamental change to the risk assessment you should make. “Private” means the system is engineered so that Apple shouldn’t be able to see or store the data, but it doesn’t mean it’s encrypted or doesn’t leave the device.
This leaves the privacy of certain apps up to a strange combination of an app developer’s choices and your own. You can, of course, disable Siri entirely (Settings > Siri > "Turn Off Siri"), or choose not to invoke Siri to ask questions, but perhaps you don’t want to fully disable or disengage with the system. Thankfully, you can put some guardrails on Siri AI’s access. Once you’ve updated to iOS 27, here are the steps to take.
Note: only iPhone 15 Pro/Pro Max, as well as all models of the iPhone 16 and newer support Apple’s AI features. Siri AI is currently only available in English, and not available worldwide.
How to Restrict Siri’s Access to the Content Inside AppsBy default, how (and if) Siri AI can access data inside apps is up to the app developer. If an app developer chooses to index the contents of their app, then it may appear in search, and thus be made available to Siri AI. This means the content may pop up during general or direct searches, like “What are my plans for November" might cull information from your calendar, Messages, Notes, and, as they update, third-party apps.
If you do not want Siri to look through certain apps to consider the contents in results, you can tell it not to:
- Open Settings > Apps > [the app you don’t want Siri to look through] > Search
- Disable the option to “Show Content in Search.”
With this setting disabled, when you ask Siri general questions, it will not surface details from the app you selected. For example, if you disable “Show Content in Search” for Messages, it will not be able to read your Messages conversations.
Left: Asking Siri to summarize a message thread with Show Content in Search enabled. Right: With the setting disabled.
There is also an “App Access” setting where you can configure some of the ways Siri interacts with apps. You’d think this is where we’d have gone to revoke access to the content of an app, but alas, this settings page is more about some basic functionality with device personalization, not Siri’s access to the contents of the app.
- Open Settings > Siri > App Access
- Tap an app where you’d like to change Siri’s settings.
On this screen, you’ll find a variety of options, depending on what an app supports. “Learn from this App” sounds nefarious, but is mostly about tracking usage, like how often you open an app, and if a developer supports it, what you interact with.
The rest of the options are mostly about the personalization tweaks that Siri makes, where it suggests apps it thinks you want at the moment in various places, like when searching or sharing. “Show on Home Screen,” “Suggest App,” and “Suggest Notifications” are just about whether you see apps in those places.
For example, if you have a widget of Siri-suggested apps on the home screen, that’s the “Show on Home Screen” toggle. If you see an app recommended in another app, like adding a date to your calendar from an email, that’s “Suggest App.” Apple claims these features all use on-device processing and the data is not stored on servers.
For anything not covered here, refer to this documentation for steps to disable certain features.
The On-Screen Awareness Capability May Be Concerning for Some PeopleThere is one Siri AI feature you (and app developers) can’t do as much about: on-screen awareness, a feature you can invoke at any point to prompt Siri and ask it to explain what you’re looking at and perform certain actions. For example, you can ask it to summarize a web page, cut a recipe you’re reading in half, add an event to your calendar, or try to figure out where a photo was taken. All potentially useful features.
But you can also ask it to summarize or explain a Signal group chat that you're looking at, or a meme in a WhatsApp chat, and the data from that on-screen interaction may be sent to PCC. There is currently no way for you or app developers to block this feature, so it’s up to you, and those you chat with, to simply not use it if you’re concerned about the content of conversations potentially leaving your device. It would be a large improvement to privacy, especially secure chat apps, if Apple provided developers a means to block access to Siri AI’s on-screen awareness tool. Even better if they gave you a single control to block all Siri AI features from an app entirely.
Revoke Access to Training DataBy default, Siri AI won’t collect and use data from your interactions with it for training AI features. But during the setup process, Apple provides a way to opt in, which you might have tapped without thinking about it. If you’d rather your data not get used for training, you can opt out:
- Open Settings > Privacy & Security > Analytics & Improvements
- Disable the option for “Improve Siri & Dictation.”
According to Apple’s privacy documentation, disabling this option should revoke training access to the audio and text from the Siri app.
Go Back to the Old Version of Siri (and Disable Other AI Features)Want nothing to do with any of this but still find Siri useful enough to keep around (or you just have to keep it turned on in order to use CarPlay)? For the time being, you can get the old Siri back, though the process is a bit odd.
- Open up Settings > Screen Time > Content & Privacy Restrictions
- If you have never done so, enable the toggle for “Content & Privacy Restrictions.”
- Tap the Siri option, then “Allowed Siri Version.”
- Select “Siri Classic.”
You can no longer easily disable Apple Intelligence entirely with one tap in the Settings, but on this screen you can also configure other AI features, like disabling the writing and math assistance prompts, turning off image creation, and disallowing the use of extensions. Follow this guide on Apple's site for everything else.
For the most part, Apple’s handling of AI features is far less in-your-face than others, and because of that the privacy implications are easier to untangle. But even still, it’s difficult to know what’s processed on device and what’s sent off, and so the privacy trade-offs are never spelled out as clearly as they should be.
Apple could improve on this by offering an on-device only option for Siri AI and providing a clear, single setting toggle to prevent all AI features in a specific app (it looks like Apple is planning a single privacy toggle in a future update. We'll update if and when it does). In general, Siri’s power-up has also made it blurry and difficult to really figure out what sorts of privacy options exist. “Siri” means many things, both on device and off, ranging from “searching the entire internet for an answer” to “setting a timer,” and users have no straightforward ways to wrangle that data to suit their needs. As it stands, it’s a confusing collection of different toggles that never feel exactly right and which many users might struggle to grasp.
Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs
Secure messaging platforms, like Signal, WhatsApp, and recently, encrypted RCS, operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to guarantee what happens once the message arrives on a phone. As more devices and services introduce more artificial intelligence (AI) features into messaging apps, that line begins to blur.
When AI features are computed entirely on device, it’s less concerning. Yet sometimes the computing requirements are heavy enough that the computation has to be done on a company server. Tech companies tell us they have a solution for this: trusted execution environments (TEEs). But do server-side TEEs really solve the problem?
TEEs exist to serve many different functions, ranging from digital rights management (DRM) content protections to securely storing information in your phone's mobile wallet, but for our purposes, we’ll be focusing on how tech companies use them for their AI tools.
The basic idea is straightforward: most consumer devices aren’t powerful enough to handle the sorts of AI features companies want to offer, so sometimes they send data off your device to more powerful cloud servers to do the computing, then display the results on your device. Since your data is leaving your device, there’s a privacy compromise. For example, if you ask for a messaging app to summarize a conversation, it may offload that computing power to a cloud server, sending the entire contents of your messages to the cloud, then back to your phone.
TEEs supposedly offer a way to keep those requests private. There are several implementations out there, like Apple’s Private Cloud Compute, Google’s Private AI Compute, and WhatsApp’s Private Processing. It’s not just the big tech players, we’ve seen chatbots built with TEEs as well.
TEEs can provide more security and privacy than simply running in the clear, but they are fundamentally different from actual encryption or running locally. Despite the promises of some tech companies, they will never be able to match that level of security and privacy. Because of that, a user’s device should never automatically send data to a TEE. Let’s dig through the reasons why.
What Exactly Is a TEE, Anyway?A TEE is a hardened section of the computer that runs software in a way that’s supposed to be secret even from other processes running on the machine. TEEs also let users check that the code being run is the code that they think is running, and not backdoored code instead, using a process called “attestation.” You may have also heard this referred to as a “secure enclave,” or heard the brand names SGX or TrustZone.
The intention of a cloud-based TEE is simple: a company can run a server in their data center, but still process data that you provide on your behalf without being able to see that information themselves.
Is a TEE Secure?In practice, we've seen multiple cracks and hacks every year that show that it is possible to get at that data. That’s because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to breaking it that would not also upend fundamental understandings of mathematics as a field.
The collective understanding of every mathematician in the world is that standard encryption algorithms are not breakable to the best of the world’s collective knowledge. No responsible engineer builds a system based on a new encryption method until after it’s been offered up for prodding.
Engineering, on the other hand, doesn’t work like that. Every individual system is the product of a group of engineers who put it out into the world, and each product will have its own quirks and bugs that have to be individually discovered and patched. These bugs are found after the system is built, not before. No one has yet built a system that is unbreakable. On the contrary, there is new research all the time that finds new ways to break into TEE systems. They’re patched as they come up, but they’re unlikely to ever become perfect, and certainly not any time soon.
TEEs in particular are a hard engineering problem because the encryption key is physically right there on the device. Building a TEE means keeping a key fully separate and inaccessible while it’s on the same physical device as parts of the system that shouldn’t have access to the key.
Many attacks on TEEs involve “side channels.” In a side channel attack, the attacker measures the electrical impulses or other effects to figure out the timing of operations inside the TEE, then uses that to figure out the key being used. Once they have the key, they can read all the data. Compare that to end-to-end encryption, where the key is never on that machine in the first place, so an attacker would have to also run a similar attack on the user’s device.
Companies who turn to TEEs to protect data want to both have the key on the server and have it protected while still performing complex operations like running an LLM, which makes it much more difficult to protect those keys.
That being said, a TEE versus plaintext on a server is the difference between being able to easily read the data and having to do a bunch of specialized work to get at the data. That work often involves accessing the physical machine. This is most relevant for protecting against mass surveillance, and for many people, that might just be enough security.
But that's the core of the problem. “Secure enough for most cases” and “encrypted as in math” are not the same thing, and it’s important not to conflate the two. And services that currently offer “encryption as in math” have a real downgrade in security when they switch to security based on TEEs.
If you want to dive into the myriad security issues and limitations of TEEs we’ve seen so far, they’re well documented here, here, here, and here.
What Does This Have To Do With LLMs and AI?Sometimes organizations want to offer an LLM that can respond to queries in a private manner. On-device LLMs exist, but they’re limited in size. So, when organizations want to offer the ability to answer queries without being able to see the conversation, they turn to TEEs. That’s a useful way to run a chatbot that’s reasonably private. This is what Apple, Google, WhatsApp, and others are doing.
Why not turn to encryption? After all, LLM inference is just a bunch of math like any other things a computer does. It takes input to a (really big) function and gives an output. We have the math to do that computation in a way that hides the inputs and outputs from the one running the computation, it's just super expensive. It’s called homomorphic encryption, and no one’s figured out how to do it fast enough that it makes sense for this sort of computation.
Instead, the allure of a TEE is that it will run that computation for you inside of a special opaque section of a server. TEE manufacturers try to make it as hard as possible for the person running the TEE to peek inside. But you still have to trust the operator to not put a stethoscope to the box to try to figure out what's happening inside.
In this case, it’s reasonable to consider these systems “privacy-preserving,” but not “encrypted.” That distinction is important, especially when we talk about how the TEEs interact with secure messaging. When someone using an end-to-end encrypted chat app asks an LLM to summarize, review, or store those messages, the content of those messages is leaving the device and going to an unencrypted third-party server somewhere. That’s a major threat to the privacy of secure chat apps, and one that’s increasingly hard for users to take control of.
How Does This Translate to Practical Advice?The answer to this is going to vary based on an individual’s threat model, but a good rule of thumb is that a user’s device should never automatically send data to a TEE. When the person holding a phone can choose what information is sent, even if it’s a chunk of data like “unread messages,” they have the opportunity to pause and consider if that data might be too sensitive to risk sending.
In contrast, when data is sent automatically, the automatic sending becomes a feature of the system as a whole. If the system was previously end-to-end encrypted, adding automatic exfiltration makes the whole system no longer end-to-end encrypted.
Developers: don’t build systems that automatically send data off a device to a TEE, especially when it’s coming from an app that is otherwise end-to-end encrypted.
Users: if developers ignore us and build that system, turn off any automatic data sending features. Take a second to think about how much you’re willing to risk sending data when you choose to send it off the device.
So, What Should I Be Concerned About?TEEs are useful for security in a number of circumstances. Your phone likely has a TEE where it keeps the key that encrypts your biometric unlock data and the base of the keychain where passwords are stored. It also enables certain backup systems, like how you can restore a phone with your passcode or restore WhatsApp or Signal backups.
But when we’re talking about cloud processing, it’s important to be clear this isn’t the same as end-to-end encryption and doesn’t offer the same level of privacy.
Most of our private lives are on our phones and in our messages. We’ve worked for years to secure those messages, with major wins like encrypted RCS, and the continued user experience improvements of Signal and WhatsApp. We’ve even seen real improvements to backup security with features like Advanced Data Protection that bring end-to-end encryption for a variety of data outside of messaging, like notes and photos.
But as companies roll out AI features that interact with these encrypted services, pulling data off devices and into a cloud-based TEE, they’re eroding the privacy protections of end-to-end encryption and risk causing serious confusion around what data is protected and what isn’t.
