Victory: Court, Using a New Test, Rules Embedding Links is Legal

3 hours 40 minutes ago

Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable if the content turns out to be infringing.

News publisher Emmerich Newspapers sought to convince the Fifth Circuit Court of Appeals to chart a new and dangerous course, arguing that an aggregator website that published links to its copyrighted articles was in effect “displaying” them and can be directly liable for infringement. EFF, along with several other public interest organizations and trade associations, filed a brief urging the court to follow multiple other circuits and reject that theory.

Fortunately, the Fifth Circuit Court of Appeals did just that. While it rejected the server test–the rule courts have used to determine copyright liability rests with whoever serves up the content–the court came to the same practical conclusion by focusing on who is responsible for transmitting content. 

Applying that test, the court found that pointing or directing a user’s browser to request and receive the copyright owner’s own copy residing on its computers does not involve transmitting or communicating the content. “Although we take different routes to get there, both the server test and the test we announce end up in a similar place: a website cannot transmit a work that it does not have,” the court said

We told the court that accepting Emmerich's theory would make the common act of embedding links a legally fraught activity, one that many websites might be unwilling to risk, which would seriously damage the internet as a tool for creating and disseminating ideas and knowledge,

We applaud the court’s decision–even though it applied a different test, it correctly concluded that a user linking pictures, video, or articles isn’t in charge of transmitting that content to the world. The user doesn’t control what’s located on the other end of the link—that’s up to the person who controls the server.

Emmerich also claimed linking violates the Digital Millennium Copyright Act (DMCA), arguing its URLs were copyright management information (CMI) and when the aggregator displayed Emmerich’s articles under its own URL, it tampered with Emmerich’s CMI, which violates the DMCA. 

Under that logic, unsuspecting internet users could face ruinous legal risk for doing something as simple as using a link shortener, particularly given potential statutory penalties of up to $25,000 per violation.  

In our brief, we told the court that URLs don’t necessarily equate to a copyrighted work or provide sufficient information about the nature of the underlying content, making it highly unlikely that anyone would expect a URL to contain CMI. Quoting EFF’s brief, the court concluded that URLs are first and foremost a locational reference tool and while it may be possible for a URL to contain CMI, the bar to that conclusion is high.

Overall, this was a good and sensible decision that will protect ordinary online expression, communication, and access to knowledge. Hopefully this issue is laid to rest at last.

Related Cases: Emmerich Newspapers v. Particle Media
Karen Gullo

EFF Welcomes Alexander Macgillivray to its Board of Directors

3 hours 54 minutes ago

The Electronic Frontier Foundation (EFF) is honored to announce today that Alexander "amac" Macgillivray — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Directors. 

Macgillivray served in the Biden Administration as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer in the Office of Science and Technology Policy, and earlier had held a similar position in the Obama Administration. Macgillivray was one of the co-authors of the Biden Administration’s Blueprint for an AI Bill of Rights and oversaw many of the Administration’s AI initiatives, such as organizing its AI CEO convening, leading its working group on federal AI policy, and overseeing the creation of the National AI Research and Development Strategic Plan and National AI Research Resource. 

He was Twitter's General Counsel from 2009 to 2013, leading the Corporate Development, Public Policy, Communications, and Trust & Safety teams. Before that he was Deputy General Counsel at Google from 2003 to 2009, where he created the Product Counsel team.  

“One of the things I am currently focused on is positively impacting AI development," MacGillivray said. The EFF is uniquely situated for that purpose because it combines top-notch legal, technical and advocacy staff with a long history of fighting for people’s rights while encouraging the positive development of technology. I’m thrilled to be joining the board.”

Macgillivray joins a dynamic EFF Board led by Board Chair Gigi Sohn and Vice Chair Brian Behlendorf, and including fellow Board Members Erica Astrella, Anil Dash, Sarah Deutsch, Tadayoshi Kohno, Pamela Samuelson, Bruce Schneier, James Vasile, Tarah Wheeler, and Jonathan Zittrain.

“The EFF Board is thrilled to have Alex join our ranks," Sohn said. "I’ve worked with Alex for over two decades and have always been impressed not only with his intelligence and grace, but also his ability to think outside the box. His deep experience with non-profit boards will be invaluable as EFF enters a new and exciting chapter.”

Macgillivray currently also serves on the boards of The Trust & Safety FoundationThe Trust & Safety Professional Association and Public Resource. He is an affiliate at the Berkman Klein Center for Internet & Society at Harvard University. Macgillivray earned a law degree from Harvard, a bachelor’s degree in Reasoning & Decision Making from Princeton University, and a New Jersey Teaching Certificate. 

“The vanguard leadership of EFF Board members to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical," EFF Executive Director Nicole Ozer said. "Many of the threats that once seemed hypothetical are now reality and the work of our EFF community is fundamental to the future of our countries, our livelihoods, and literally our lives. I feel fortunate to have amac join as a Board member as I begin my tenure as Executive Director. His diverse expertise will be invaluable to make sure that EFF is stronger than ever to meet this moment.” 

Members of the Board of Directors ensure the managerial and financial health of the organization.  EFF is the leading nonprofit organization defending civil liberties in the digital world. Learn more about our cutting-edge work on AI issues, and please donate today to help keep us fighting for a brighter digital future.

Donate to EFF

Josh Richman

👮 Flock Searches for the LOLs | EFFector 38.16

4 hours 7 minutes ago

Mass surveillance isn't a joke. But police are treating it like one when using automated license plate reader (ALPR) networks. In our latest EFFector newsletter, we're covering a new EFF report on how officers across the country are routinely logging completely nonsensical "reasons" for their Flock searches, including "LOL," "LMAO," and even (yuck) "Sexy."

JOIN OUR NEWSLETTER

For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers a settlement enshrining Meta's harmful surveillance into law, states pushing back against ALPR, and how police are turning our privacy into a punchline.

Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Adam Schwartz what has united people against Flock cameras — and how we can make sure that today's backlash leads to lasting change. You can find the episode and subscribe on your podcast platform of choice:

%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F93770148-4558-4033-b345-6ff2d136d3c0%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

   

Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!

Hudson Hongo

How the Meta Settlement Silences Youth Activism

4 hours 25 minutes ago

Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislatures under the guise of protecting young people online—presenting a significant hindrance to youth organizing.  

In a major recent example, Meta settled in a lawsuit with 52 states and territories regarding the use of Instagram and Facebook by young people. The settlement will require Meta, and pressure other non-Meta owned platforms like TikTok and YouTube, to embed age gating practices into every product while also requiring restrictions on the accounts of people under-18, such as a two-hour daily time limit and content restrictions.   

Youth Power on Social Media 

Young people have been using social media for political advocacy and community organizing for more than a decade. From organizing protests speaking out against police brutality, to organizing nationwide school walkouts demanding safety in schools from gun violence, and striking to demand lawmakers take action to protect the climate, social media has become an instrumental tool for youth to both speak out and connect with other young activists.  

Instagram has become especially useful for activism online by young people. The features on the app make it a helpful tool for being able to efficiently and quickly spread awareness, which is especially important when people need to share real-time information. For example, 17-year-old Darnella Frazier’s video on Facebook showed the world the murder of George Floyd. 

The impact of youth activism online is also evident on non-Meta owned platforms, with services like TikTok and YouTube being particularly prevalent spaces for young people to share their stories, build movements, and amplify collective engagement.

However, in a digital world operating under the settlement’s new guidelines, young people risk not being able to read crucial news due to the content being labeled as “age-inappropriate,” which has already happened for teenagers in Australia under its social media ban.  

A two-hour daily time limit and a block on Meta’s apps between midnight and 6am leaves little room for young activists to organize rapid response efforts. Being unable to see likes on a post will make it difficult to gauge the effectiveness of their campaigns.   

Add to this what we already know about Meta’s content policies which claim to “protect children” and keep sites “family-friendly” but instead label content like LGBTQ+ content as “adult” or “harmful,” youth will be left with no choice in what content they see once the ‘age-appropriate’ content filter is turned on by default. One recent report noted that Meta had hidden posts that reference LGBTQ+ hashtags like #lesbian, #bisexual, #gay, #trans, and #queer for users with the sensitive content filter on. This would specifically curtail the efforts of young activists doing work on comprehensive sex education.   

Global Trends 

Measures like this are being discussed across the globe, but not all courts have taken such a short-sighted approach. In August, the French Constitutional Council got a lot right in its decision to strike down the country’s legislation banning under-15s from social media for infringing free expression and communication for everyone online, not just young people.  

The French Court also called attention to its infringement on privacy as the legislation would have forced people of all ages to hand over government IDsface scans, and other sensitive information to prove their age and access online content.  

Requiring this much data from users puts activists in danger of even more surveillance. Meta has already previously complied with demands from law enforcement to hand over the messages of users. The amount of personal information that will be logged and that could be demanded via a warrant from police to stifle or investigate activists’ actions or plans could cause a chilling effect, forcing advocates to pause or terminate their work.  

This is egregious because these systems misidentify or lock out people of colorpeople with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their chosen name or align with what the system expects them to look like upon verification. And it’s often these communities that benefit from online organizing the most, especially for marginalized youth as social media can often be the only place to organize and build community. 

What Young People Deserve 

The settlement generates headlines, but it will not solve the core problem. Instead of tackling Meta’s surveillance capitalism business model that turns all online content into potential profit and centers lining the company’s pockets over protecting the speech and privacy of users, this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people.  

As we’ve been calling attention to in other contexts, this will force young people into digital isolation—curtailing vital access to news and resources for health and development. It also completely ignores the calls of youths themselves who favor digital literacy and education over surveillance and government control.   

Young people deserve a better internet than one regulated through panic. They deserve better than the government or Big Tech getting to decide how they use social media and what they can or cannot be exposed to or learn about. They deserve better than having their right to free expression minimized. This must not be lost in the pursuit of building a better and safer online ecosystem and environment.   

Paige Collings

California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

1 day 1 hour ago

The federal government has inserted a provision into a funding deal with the state of California that would make the state abandon its gold standard net neutrality law, broadband affordability laws, and public safety protections. Doing so would be a huge step back for California, and would actually end up being more expensive for Californians in the long run. Tell the governor to reject this provision before accepting these funds from the federal government.

Take Action

Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

On August 31, the National Telecommunications and Information Administration announced it would be awarding California $1.4 billion to expand broadband connectivity in the state. In that deal is a provision that says that California agrees to not enforce any law, order, or policy that imposes any sort of restriction on internet service providers (ISPs). These ISPs will get awarded the funding in order to connect Californians they have neglected for years. The ban on enforcing our laws would last 14 years. This is disastrous for a lot of reasons. 

First, California is one of the only states with a strong state net neutrality law. Recreating much of the FCC’s Open Internet Order, the law prevents ISPs from blocking, throttling, zero rating, and instituting paid prioritization on internet service. Put another way, the law ensures that users, not companies, decide how they can see on the internet. If California is not allowed to enforce our gold standard law, there will be little stopping ISPs from controlling how everyone experiences the internet. 

Second, California has a number of affordability protections that would also fall under this agreement. For example, when the state approved the merger of Verizon and Frontier earlier this year, it required the new merged company to offer a $20 internet plan to low-income Californians—saving Californians billions of dollars over the next decade. Just this year the California Public Utilities Commission found that the average cost of broadband across four major urban markets (San Mateo, Oakland, Los Angeles, and San Diego) was $51 per month. In 2023, Consumer Reports found that 84% of American consumers pay at least $50 per month, with many paying more. That $30 difference per month—which is likely to actually be more—makes all the difference for low-income Californians. It is how Californians will save billions from this merger requirement. In contrast, $1.4 billion in new connectivity and infrastructure doesn't matter if the most vulnerable Californians cannot afford it. Eviscerations of this and the net neutrality protections will, ultimately, cost Californians more than they will get. 

Third, this deal will impact public safety. The same California net neutrality law which protects consumers also ensures reliable service for first responders during emergencies by banning throttling. In 2018, Verizon throttled, or slowed down, the service of firefighters as they were battling what was, at the time, the largest wildfire in California history. In reaction, fire departments came out in support of what would become California’s net neutrality law. If California cannot enforce its net neutrality law it will leave its first responders in a weaker position as natural disasters only become more intense. 

Most people do not have a choice in ISP as it is. California’s net neutrality law is one of the few things protecting Californians from the whims of these monopolistic giants. Californians should not give up our few hard-won protections in return for a hand out to these behemoths. Tell Governor Newsom to reject this provision before he accepts these funds from the federal government. 

Take Action

Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety

Katharine Trendacosta

The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke

2 days 5 hours ago

Here's a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025? 

If your answer is "I don't know," it turns out you're 100% correct. The officer left the letters "idk" in the search field where cops are supposed to document the reason for the search.

When law enforcement and tech salespeople pitch ALPRs to city councils, they stick to a familiar script. They trumpet the technology, which is often provided by private companies like Flock Safety, Motorola Solutions, or Axon, as an essential tool for solving high-stakes crimes, such as car jacking, kidnapping, or murder.

But when you strip away the carefully curated talking points, the data continues to reveal a different (and frankly, ridiculous) story. An EFF analysis of ALPR search logs from Flock Safety systems shows that officers across the country are spying on drivers for completely nonsensical "reasons." Police are routinely searching the Flock database without providing any legitimate justification, making a mockery of our civil liberties by logging reasons like "LOL" (short for “laugh out loud”), "LMAO" (short for "laughing my ass off"), "sexy," and "idk" (short for “I don’t know”) to access sensitive ALPR location data.

And in some cases, officers are just mashing keyboard buttons rather than articulating the nature of their searches.

Flock Safety claims it has improved its system by requiring officers to select from a dropdown list of crimes before running a search–but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search. 

With no warrant requirements, limited guardrails, and deficient audit processes, ALPR databases have fostered a culture of unrestricted access to everyone’s location information. This culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols.

A Documented Culture of Abuse

ALPR misuse isn’t a new phenomenon; it has dominated headlines for more than a year. We already know that officers regularly abuse these systems to stalk past and potential romantic partners. We’ve seen ALPRs used to surveil protests, which can chill First Amendment-protected dissent, and seen officers try to use an ALPR system to track down a woman seeking an abortion.

Typically, we learn about these uses from documents called "network audits," which are long spreadsheets that document all the searches that run through an agency's system. It is not unusual for even a small agency to have a record of millions of searches from thousands of external agencies across the United States.

We’ve also uncovered horrific systemic profiling, with more than 80 law enforcement agencies using terms like "roma" and "g*psy" to target ethnic Romani people—often without any mention of a suspected crime. And when police aren’t using ALPRs for stalking or profiling, they routinely use them for extreme low-level investigations: verifying whether a student lives in a specific school zone, running employment background checks, following up on loud music complaints, or targeting a motorcyclist simply for holding a cell phone.

But somehow, it gets worse.

The Absurdity of Documented Search Reasons

EFF’s analysis of Flock Safety’s ALPR search data obtained through public records requests has uncovered a disturbing trend. In the absence of judicial oversight, officers are inputting ridiculously unserious terms to justify their searches. Here is just a snapshot of what police consider a "reason" to track someone’s vehicle:

Surveillance as a Joke

Audit logs sample

  • Barberton Police Department (Ohio) employees ran numerous searches between March 2024 and May 2026, listing “LOL” or “lol” as the reason.
  • Harris County Sheriff's Office (Texas) employees ran several searches between April and May 2026 listing “LOL” or “lol” as the case number.
  • Lake County Sheriff's Department (Ind.) employees ran searches in July 2025 for “LMAO.”
  • Richmond Police Department (Calif.) employees ran over multiple searches in November 2024 for “Hehe.”
  • Riverside County Sheriff's Department (Calif.) employees ran searches in 2024 for “Haha.”
"Don’t Know, Don’t Care" Approach
  • Kankakee County, Sheriff's Office (Ill.) employees ran searches (2023–2025) for “idk” or “idk lol.”
  • Goshen Police Department (Ind.) ran searches (May–June 2025) for “idk.”
  • Fishers Police Department (Ind.) ran searches in May 2025 for “blah.”
  • A Pasco Police Department (Wash.) employee searched for at least four different license plates, leaving "robbery i don't remember the case number leave me alone" in the reason field.
  • The San Diego Sheriff's Department (Calif.) ran searches in May 2025 with "idk" in the reason field. 
  • More than 30 agencies ran more than 6,300 searches with "TBD" (short for "To Be Determined") as the "reason." These included the Arizona Department of Public Safety, the Manteca Police Department (Calif.), and the Baton Rouge Police Department (La.). The Priceville Police Department (Ala.) alone ran 1,954 searches with reasons "TBD." 
Insults and Inappropriate Searches
  • Belton Police Department (Mo.) ran searches (Aug–Sept 2024) for “d*ckhead.”  (asterisk/redaction our own)
  • A Manteca Police Department (Ill.) employee ran searches in June 2024 for “sh*thead”  (asterisk/redaction our own)
  • A Norton Police Department (Mass.) employee ran searches in December 2024 for “Sexy.”
  • Corona Police Department (Calif.) employees ran searches (2023–2025) for “weird” or “WEIRD KID.”
  • Thornton Police Department (Colo.) employees ran several searches in October 2025 for “driving around being weird.”
  • A Columbus Police Department (Ohio) officer ran searches in 2023 for “idiot.”
  • A Michigan City Police Department Officer (Ind.) ran searches in June 2025 listing “f*ck this new search engine.” (asterisk/redaction our own)
Button Mashing 

Button mashing audit logs sample

One of the more alarming discoveries we found in the network audit data is a large number of "reasons" that appear to be nothing more than an officer mashing buttons. These typically involve a nonsensical long string of characters from the same line or area of the keyboard.

For example: 

  • An Eatonton Police Department (Ga.) employee ran searches with reasons such as HJKNUILH, uiokjk.kuj, GJLHBNMN, hjhbnmg, and iuohjk.
  • An Atlanta Police Department (Ga.) employee ran searches with asdfga as the reason. 
  • Bay County Sheriff's Office (Fla.) employees ran searches with reasons such as  ;'lkjh, /lkjh and lkjhg.
  • A Brown County Sheriff's Office (Wis.) employee ran searches with reasons such as gyghkkghghjkghjk, ggyjgyujdsrdghdfhjkghjghk, HJHJKLHLKHJK, hjjkjkhjkljk and JHLJKHHJKL.
  • A Lake County Sheriff's Office (Ohio) employee ran searches with reasons such as asdfg and ghjkl, and a second officer ran a series of searches that started off with "investigation" but then devolved into button mashing, including: 
    • Investigatafy, Investigatafyd, Investigatafydl, Investigatafydlh, investigatafydlhj, investigatafydlhji, investigatafyfdlhji, investigatafyfdlhjigkfgty, investigatafyfdlhjigkfgtyy, investigatafyfdlhjij, investigatafyfdlhjik, investigatafyfdlhjikf, investigatafyfdlhjikfg, investigatafyfdlhjikfgty, investigatafyfdlhjikfgy and investigatafyfdlhjiy.
  • A Moore Police Department (Okla.) ran searches with reasons such as jhjhjkhj, jhjkhjh, jhjkhjkh, jkhhkjhjk, Jkhjkhj, Jkhjkhjk, Jkhjkhjkh, jkhjkhkjh, jkjkhjkh, kjjkhjk, loiuiou, ukjhjkh and ulkuiou.
  • A Westlake Police Department (Ohio) employee ran searches with reasons such as fghjkl, ghjkl, and lkjhg.
  • A Kentucky State Police employee ran searches with reasons such as mhghjk, mhgnhjkj, nbvcxcvbn, nmbvcbnm, and sdfghj

It's hard to imagine a situation where these characters add up to a legitimate police code. However, it's easy to imagine an officer cutting corners with a text field they know no one is checking, especially if they are accessing the Flock Safety app from their phones while driving. 

How Police Departments Are Responding

When confronted with these flagrantly unserious searches, police departments offered a mix of bureaucratic deflections and excuses. 

In response to EFF’s request for comment, Thornton Police Department (Colo.) claimed the system didn't require officers to select from a defined list at the time, but it does today. They also audited the “driving around being weird” searches, claiming they were all actually for "legitimate public safety purposes." 

Other police departments we reached out to for comment shared the following: 

  • Richmond Police Department (Calif.) stated that the officers involved with the "Hehe" and "idk" searches were "counseled."
  • Corona Police Department (Calif.) noted that the employees searching for "WEIRD KID" are no longer employed by the city for unrelated reasons.
  • Columbus Police Department (Ohio) pointed to their union contract, stating their Inspector General only has jurisdiction to investigate incidents within the last 90 days, giving the officer who searched for "idiot" in 2023 a free pass.
  • Belton Police Department (Mo.) promised a "thorough investigation" of the "d*ckhead" searches through existing union and personnel policies.
  • Manteno Police Department (Ill.) said it will "review the searches and the circumstances surrounding them thoroughly" and "take whatever action is determined to be appropriate based on the facts and circumstances.”
  • Manteca Police Department (Calif.) said: "Since the beginning of 2026, our personnel have been directed that the reason field for ALPR searches must identify the law enforcement purpose for the search and that 'TBD' is not an acceptable entry." The spokesperson added: "The presence of 'TBD' in the reason field in prior searches should not, by itself, be interpreted to mean that the associated search was conducted without a legitimate law enforcement purpose or that reasonable suspicion was required." EFF has asked the agency to clarify whether it verified the hundreds of "TBD" searches were legitimate, and we will update this post with a response if we receive one. 
  • Fishers Police Department (Ind.) said that the detective that searched for “blah” has done so “when he has issues with the technology” and that the term “is used when he is actively using the technology to solve a criminal case, and the technology is not moving fast enough for him.” The department shared that “he has been told to use “test” in the future.”
  • The Cobb County Police Department (Ga.) acknowledged that "TBD" stood for "To Be Determined" and is no longer an acceptable search reason: "We have instituted a new policy that took place after the dates listed in your audit that now require, in addition to a criminal offense and a reason, a case number for any search conducted on FLOCK." 
  • The San Diego County Sheriff's Department says that it checked the cases where "idk" was used and determined "there was an active investigation associated with the searches." The department said that this was due to the reason field being optional at the time (which was true on a software level) but California law has required officers to document a purpose for accessing ALPR data since 2015. The sheriff's spokesperson says the reason field is now mandatory, and involves a dropdown menu. 

Other agencies did not respond to EFF’s requests for comment. We will update with responses as they are received.

The Cop Out of the Drop-Down Menu “Feature Update”

Under the guise of streamlining audit logs, in late 2025, Flock safety announced that they will be replacing the required, free-text search “reasons” with a pre-populated dropdown menu of generic offense categories. Since this update, officers are no longer required to type out why they are digging through a driver's movement history, and instead can select a pre-packaged option like "Traffic infraction" or “Other” in half a second. 

Replacing the requirement to articulate the reason for the search with one-click searches is a loss for transparency, but also may explain why audit logs including the searches we highlight in this piece significantly decreased since early 2026. 

The Punchline is Our Privacy

Entries like these defeat transparency, undermine accountability, and entirely fail to satisfy what many jurisdictions require by law or policy: an actual reason for the search. And this keeps happening because police use ALPRs as a convenient shortcut around constitutional privacy safeguards. 

In other contexts, such as searches of cell phone location information, police have to go to a judge, demonstrate probable cause, and get a search warrant. But because laws and courts have not caught up with the pace of ALPR technology, police do not do the same before searching ALPR databases. Instead, they are given free rein to track a person’s movements without a sliver of judicial oversight.

As we mention in our piece about the use of ALPR surveillance for low-level investigations, if a police chief stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of "haha," they would be laughed out of the room. The same could be said if an officer asked a judge to sign a warrant to track someone down for "LOL."

The fact that these searches were not only missed by the agency supervising the officer, but by the often thousands of other agencies whose systems were searched, demonstrates how agencies cannot be trusted to oversee themselves. 

Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement. 

If police want the power to track a person's movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for "haha."

Rindala Alajaji

Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans

5 days ago

Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use without violating their First Amendment rights.

Unlike blanket bans, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for civic engagement, education, self-expression, and community—especially vulnerable youth who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about digital literacy and privacy with trusted adults are far more effective at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was co-authored by a group of students actively seeking better resources to navigate their digital lives safely.

Education vs. Censorship 

A.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.

While the state’s turn toward social media bans remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online. 

Chao Liu

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

5 days 3 hours ago

Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.

TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, and more, then deletes the key after 24 hours. 

This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features. 

Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.

Ring Gets Access to Unencrypted Video for a Short Period

Ring has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers. 

With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server. 

In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a hardware security module (HSM), including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of end-to-end encryption

The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers. 

But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included.”

Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos. 

Law Enforcement May Still Seek to Compel Access to Footage

Because of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access. 

In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.

End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.

Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”

TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and turning that on by default would offer the real sorts of privacy improvements we all want from video doorbells. 

Erica Portnoy

We All Deserve a Better Internet, Not A Smaller One

6 days 1 hour ago
Bans Like California’s Don’t Fix What’s Wrong With Social Media Companies

SAN FRANCISCO - Technology and the laws that regulate it should support and empower young people. California’s AB 1709 - signed into law today by Gov. Gavin Newsom - falls far short of this goal, say the Electronic Frontier Foundation (EFF) and its allies.   

Using technology is how we learn and build community in today’s world. Laws such as AB 1709, a functional ban on social media use for people under the age of 16, instead cut young people off from essential information and experiences. That particularly harms those already facing increased challenges, who often find safety in supportive online communities that they can’t always access in the physical world.  

"California should be passing laws to ensure that technology really works for people of all ages, not enacting social media bans that cut young people off from digital lifelines, communities, and speech," said EFF Associate Director of State Affairs Rindala Alajaji. "Denying minors access to digital forums - or stripping out basic tools needed to navigate them - is not going to help make young people safer or healthier in the AI age."  

Research shows social media bans are ineffectual, while also denying young people opportunities to develop their own voices and perspectives—to share their art, practice religion or engage in politics.   

Age-gating requirements also force everyone to give up more personal information. To verify who can pass through their online gates, companies will collect even more data, and this further concentrates power in the hands of companies, rather than protecting people.  

AB 1709 is also inconsistent with rights to free expression and California will be spending resources to defend a law tied up in court. Instead, we should redouble our efforts to get technology laws right—and support the passage of new robust privacy laws that target surveillance business models. That’s how we protect everyone in the AI age.   

Young people should be able to use technology in safe and healthy ways. The Golden State should model the gold standard laws that ensure technology works for everyone, rather than shut down access to digital forums in ways that do more harm than good. 

"Social media bans like AB1709 make kids less safe, while undermining privacy and freedom of expression for everyone,” said Evan Greer, Director of Fight for the Future. “Young people have been on the forefront of every social movement throughout history that has led to positive social change. We need policies that empower young people rather than silencing them. These kid-focused bans are a gift to Big Tech giants, allowing them to continue operating their harmful business model while incentivizing them to collect even more data. California lawmakers should be ashamed. They didn't do anything to protect the kids, they just used kids as pawns to make good headlines."  

“In a world of increasing stigma and marginalization for LGBTQ+ families, AB 1709 continues that trend by stripping people with LGBTQ+ parents of the ability to meet and build community with one another on the internet” said Jordan Wilson, Executive Director of COLAGE. “Beyond obstructing the right of youth with LGBTQ+ parents to access information, this bill places an undue burden on all Californians by forcing age verification at a time when digital privacy rights are being eroded globally. We cannot ‘protect children’ by stripping them of their primary avenue for connection.” 

Contact:  RindalaAlajajiAssociate Director of State Affairsrin@eff.org
Josh Richman

Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

1 week ago

Law enforcement agencies across the country are increasingly relying on spying technologies—automated license plate readers (ALPR), cell-site simulators, and facial recognition, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights and civil liberties these tools present.

Some authorities are responding to these concerns by trying to hide what they’re doing. Police departments are telling officers not to mention ALPRs when stopping vehicles and concealing their use of ALPRs to avoid citizens’ public records requests. Concealing the use of unpopular spying tools isn’t anything particularly new for law enforcement—cops have been doing it for years—but it’s just as wrong now as it was 20 years ago.

These practices prevent the public from knowing about and questioning how agencies are spending taxpayer dollars on spying technologies and holding them accountable. This is especially troubling when many towns are signing contracts with Flock and other ALPR vendors with little to no public oversight. The practice also violates disclosure obligations, allows cops and prosecutors to hide their tactics from judges, and cheats defendants from being able to challenge the use of evidence gathered by spy tech from being used against them.

404 Media recently revealed that in its usage policy for Flock ALPR cameras, one county in Iowa tells police to keep them a secret when detaining people: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” If writing a report about an incident, police are told to say they used “county resources” in making a stop instead of acknowledging use of ALPRs.

In Houston, police officers are likewise instructed to “be as vague as permissible” about why they are using Flock because the searches they run on Flock’s surveillance system could be obtained via public records requests.

There is growing public alarm about the threat to civil liberties posed by ALPR cameras and reports of police abusing the tech by using it to spy on their exes. Some cities have the cameras covered up, and others are cancelling their use of ALPR networks. Two states have recently stepped back from ALPRs. This trend is certainly not lost on law enforcement agencies. Hiding the fact that they’re using ALPRs from Flock and other vendors is one way of avoiding scrutiny and bad PR.

But law enforcement and their spy tech vendors keeping people in the dark about the surveillance technologies trained on them predates the Flock backlash by decades. For example, AT&T built a powerful phone surveillance tool for police, called Hemisphere, in the mid 2000s, and the company required agencies not to use evidence gathered by Hemisphere in court unless there was no other admissible evidence. If evidence obtained through Hemisphere was used, police were required to recreate it through a traditional subpoena, a process they called “parallel construction.” We called it “evidence laundering.”

Likewise, police and prosecutors have taken far-reaching steps to hide from the public and courts their use of cell site simulators, also known as stingrays. Police have used these devices, which trick cell phones into connecting to them instead of phone towers to try locating suspects, to obtain people’s location data without a warrant by deceptively obtaining basic pen register orders from courts. Pen register orders are for obtaining call log data and police don’t need to prove they have probable cause to get one.

In Baltimore, for example, a judge concluded that law enforcement had used a standard pen register order to intentionally hide its use of a Stingray from the court in violation of its legal disclosure obligations, leading to a landmark 2015 privacy ruling that cops need a warrant to use the device.

That didn’t stop police from continuing to try to pull the wool over the eyes of courts and defense attorneys when they used stingrays, however. Prosecutors have accepted plea deals to hide their use of cell-site simulators and have even dropped cases rather than reveal information about their use of the technology. U.S. Marshalls have driven files hundreds of miles to thwart public records requests.

Fortunately, our commitment to shining a light on the use of surveillance tech is just as strong, if not stronger, than law enforcement’s quest to hide it. We’re working with privacy advocates and community groups to bring awareness about existing and emerging spy tools that threaten civil liberties and we’re encouraging policymakers and lawmakers to do more to restrain warrantless mass surveillance and stop it before it ever takes hold.  

If you're curious about whether your local police have contracts for ALPRS or other surveillance technologies, you can search EFF's Atlas of Surveillance.

 

Karen Gullo

Digital Sovereignty: What It Is, What It Could Be

1 week ago

The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI, semiconductors, and platform regulation. Governments throughout the global majority use it to argue for greater control over data and communications infrastructure and boost their economies. Companies market “sovereign cloud” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open  systems and the skills and infrastructure to maintain them.

There is no singular definition of digital sovereignty, nor is there a single coherent position in the digital rights space. Despite its growing popularity, the term remains frustratingly vague. Policymakers, regulators, civil society groups, and others can mean very different things when they use the term. But to start simply with a broad definition, we can say that it means having the capacity to control one’s digital destiny—though the implications of that will obviously differ considerably whether you’re talking about an individual or a country.

We can start by developing  a shared understanding of what digital sovereignty actually means. We’ve also included a glossary of terms at the bottom of this post. 

In Europe and other places where digital sovereignty has become a topic of policy, discussions focus on reducing dependency: on foreign (and particularly American) cloud infrastructure, chips, platforms, and at times, foreign political priorities. The concern is both economic and geopolitical. If essential infrastructure is controlled by companies elsewhere—and thus subject to the laws of another jurisdiction—then what control does a country actually have over its own digital future?

In global majority countries in particular, wars, sanctions, and the growing fragmentation of the internet have demonstrated for many that the physical infrastructure that underlies digital life is neither neutral nor invulnerable. 

Amidst this increasing geopolitical instability governments and civil society should consider whether digital sovereignty can help shore up that infrastructure. 

What are we talking about when we talk about digital sovereignty? 

A recent Franco-German joint paper on digital sovereignty defines it as the “capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner” and puts forward a framework to operationalize Europe’s capacity to act in the digital domain. 

Some governments, such as Germany’s, have started to put funding behind sovereignty efforts through initiatives like the Sovereign Tech Agency, which “invest[s] globally in the open software components that underpin Germany's and Europe's competitiveness and ability to innovate.” 

Positions on digital sovereignty among EFF’s allies across Europe vary. Open Rights Group have defined digital sovereignty as “the ability of a country to have control over its digital infrastructure, data, and technology” and states it to be “critical for the UK’s economic and national security.” 

Similarly, the European Partnership for Democracy has expressed concern that “a few Big Tech corporations decide our collective destiny,” and argue that the EU should explore “alternative ownership models for tech companies and clearly [define] their purpose and mission.” And our friends at EDRi (of which EFF is a member) have stated clearly that “Europe’s digital sovereignty starts with open source.” Some initiatives, such as DI.DAY, consider digital sovereignty an opportunity to free users from Big Tech dependencies.

Elsewhere in the world, conversations about digital sovereignty often take a different shape. Indigenous discussions of the topic have been ongoing for more than a decade and focus on the inherent right of Native nations to govern their own digital ecosystems. In Southeast Asia, the desire for digital sovereignty has created growth in the sovereign cloud industry, but the conversation isn’t purely economic: Concerns about jurisdiction for where data is held are driving much of the conversation. 

In Latin America, digital public infrastructure is often a key aspect of debates. Across Africa, leaders speak of a desire to shift the continent from being consumers of technology to becoming architects of their own digital infrastructure and data ecosystems. And in the Middle East and North Africa, concerns about reliance on U.S. technology companies—which have engaged in conflict and disproportionate censorship (particularly of Palestinian voices) in the region—are often paramount.

Reem Almasri, a senior researcher based in Jordan, recently spoke to EFF about digital sovereignty, which she sees as “the ability of people and communities to choose, control, and use technology that serves their needs and values,” particularly in light of the role that U.S. companies have played in regional conflicts.

In a January article, Almasri pointed to growing concerns about granting greater sovereignty and influence to governments over citizens’ data, communications, and websites, writing: “This is particularly worrisome in countries that impose high levels of internet and media censorship and run unaccountable surveillance programs on their citizens’ data.”

Indeed, while pushing for greater sovereignty from Big Tech has benefits, there is an inherent risk that some states will pursue digital sovereignty as a means of cutting off or splintering access—as we’ve already seen in Iran, Russia, and elsewhere.

For that reason, it’s no surprise that some, such as Iranian professor Azadeh Akbari, believe that “the current wave pushing digital sovereignty as the key to ending dependency on American and Chinese technology is negligent of its Eurocentric bias.” 

What does EFF believe?

In a world where people have digital sovereignty, civil society should be able to communicate freely, privately, and anonymously if they wish. People should be able to easily understand where their data lives and who has access to it. That data should be easily portable between platforms and services.

At EFF, we view digital sovereignty not as a walled garden, but as an opportunity for resilience and development of industries and skills. We believe that governments can and should take a role in crafting digital sovereignty that centers the autonomy of users rather than just re-creating a state of digital dependency with a new set of companies. Governments should support and use free and open source tools and projects built using principles of interoperability and data portability. This support should include employing full-time developers, UX designers, and community managers. Government policy and legislation should grant users control of their own data and a clear understanding of who can lawfully access it. Digital sovereignty should foster users’ ability to choose how they use digital products and services, free from unfair lock-ins, coercive terms and manipulative defaults. It should also foster the broader public interest internet, the part of the web that provides public goods and useful services without requiring the scale or the business practices of the tech giants.

Encryption backdoors are fundamentally incompatible with a vision of data sovereignty that centers user control. Governments should support the development and normalization of reputable end-to-end encrypted communications as well as strong encryption for data at rest. This support should include employing cryptographers and contributing to strong, peer-reviewed encryption standards strengthened by data minimization as a fundamental design principle, as well as refraining from legislating mandates for “lawful access” or any other reason.  

As technologists, we don’t have to wait for governments to act in order to create the digital sovereignty we want. We get the internet that we build. We can contribute to open source, decentralized, and end-to-end encrypted projects. We can build standards that make interoperability and data portability a feature from the very beginning. We can resist the call of proprietary solutions, user lock-in, and encryption backdoors.

And finally, while digital sovereignty is often framed as a response to the dominance of Big Tech, that does not mean that there is no role for private companies to play. There is no point in replacing the influence of a few mostly US-based tech companies with a handful of giants based elsewhere. Companies can and should build platforms and services on top of open source, decentralized protocols and contribute to the ecosystem. Companies should also minimize processing a person’s data except as strictly necessary to provide them what they asked for, and only with opt-in consent that makes it clear to users what data they are gathering, where it is stored, and who has access to it. And companies should build their tools and platforms in a way that allows interoperability and that makes it easy for users to leave with their data. Some of these practices are already required by law in some jurisdictions, but companies don’t have to merely do the bare minimum the law demands: they should respect their users and support data sovereignty right now.

A glossary of terms

The following terms are useful for understanding this blog post as well as the broader conversation about Digital Sovereignty:

Intermediary liability: the legal responsibility of online service providers (ISPs, websites, social media platforms) for unlawful activities by their users, such as defamation, copyright infringement, or illegal hate speech.

The stack: a secure, open-source technology framework, often focusing on European alternatives, designed to break dependencies on (mostly) US-based technology providers. It comprises interoperable, vendor-neutral, and transparent digital infrastructures designed to regain control over data, infrastructure, and technology.

Digital sovereignty: the ability of people, as nations, organizations, and individuals, to control their own digital destiny by retaining authority over their own data, technology, and infrastructure.

Data sovereignty: the principle that digital information is subject to the laws and governance frameworks of the country or region where it is physically collected, stored, or processed. It dictates that data remains bound by the specific privacy protections and regulations of its originating jurisdiction, regardless of where the collecting organization is located.

Digital commons: a shared, online resource, such as knowledge, software, and data, that is collectively produced, governed, and maintained by a community, intended for public access. Examples include Wikipedia, open source operating systems such as Linux, and Creative Commons licensed content.

Data portability/interoperability: the ability to easily transfer personal data from one service provider to another, or to a personal system, in a structured, machine-readable format. It empowers users to move away from "walled gardens," reducing vendor lock-in and enhancing user autonomy.

Digital dependency: the opposite of digital sovereignty. The inability of people as nations, organizations, and individuals to control their own digital destiny through control over their own data, technology, and infrastructure. 

Decentralization: a shift away from relying on centralized, often US-based, corporate platforms toward a distributed, user-centric internet where individuals, communities, and nations maintain control over their data, digital identity, and infrastructure.

End-to-end encryption (e2ee): a secure communication process where only the sender and intended recipient can access, read, or decrypt messages or data.

Fairness (à la the Digital Fairness Act): the absence of deceptive, manipulative, or addictive design practices that distort consumer choice and exploit vulnerabilities. 

User sovereignty: the concept that individuals possess absolute control over their personal data, digital identity, and online privacy, rejecting the centralization of power by large technology platforms. It emphasizes user consent, decentralization, and the ability to manage personal data using secure and independent tools.

Jillian C. York

2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights

1 week ago

EFF is pleased to announce that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights have received 2026 EFF Awards for their vital work in ensuring that technology supports freedom, justice, and innovation for all people. 

The EFF Awards recognize specific and substantial technical, social, economic, or cultural contributions in diverse fields including journalism, art, digital access, legislation, technology development, and law. 

For the past 30 years, the EFF Awards—previously known as the Pioneer Awards—have recognized and honored key leaders in the fight for freedom and innovation online. Started when the internet was new, the Awards now reflect the fact that the online world has become both a necessity in modern life and a continually evolving set of tools for communication, organizing, creativity, and increasing human potential.  

Supporting a global community advancing digital rights, defending digital access in crisis zones, empowering communities to take action against surveillance, and providing free legal assistance for creators and consumers to fight back against digital threats are high callings that help bring about a better tech future for all. We are pleased to honor these organizations with 2026 EFF Awards. 

Access Now – Fostering Change in Human Rights and Technology

Access Now, founded in 2009 as an emergency response team helping Iranian activists get back online and communicate safely, has grown into one of the world’s foremost organizations defending and extending the digital rights of people and communities at risk and supporting the global fight against technological repression.  

Its 24/7 Digital Security Helpline offers real-time, direct technical assistance and advice to civil society groups and activists, media organizations, journalists and bloggers, and human rights defenders. It provides grants to frontline organizations working with people and communities most impacted by digital rights violations. It educates decision makers and pressures the powerful. And it organizes RightsCon, a leading annual summit on human rights in the digital age, where activists, technologists, policymakers, business leaders, journalists, philanthropists, researchers, and artists can connect, collaborate, and drive change at the intersection of human rights and technology. 

7amleh – The Arab Center for the Advancement of Social Media – Defending and Advancing Digital Access and Rights Across the MENA Region

7amleh - The Arab Center for the Advancement of Social Media protects and expands digital access and rights for Palestinians and across the MENA region. The nonprofit investigates and monitors challenges to digital rights, focusing on internet access, privacy, freedom of expression and association online. It builds the capacity of activists, human rights defenders, and civil society organizations to provide training about digital rights, gender sensitive digital security, and effective online advocacy.  

7amleh also advocates for changes to the digital rights policies and practices of governments, corporations and other influential institutions and individuals locally, regionally and internationally. It plans and manages advocacy and awareness-raising campaigns and builds networks and coalitions to promote access to safe, fair and free online spaces. For example, 7amleh has led the #ReconnectGaza campaign, supported by dozens of international NGOs including EFF, to restore full internet access in Gaza – a crucial lifeline for residents, journalists, activists, and first responders.  

DeFlock – Exposing the ALPR Surveillance Network

DeFlock is an open-source, volunteer-powered project that maps surveillance devices across the world, helping communities hold their governments and surveillance vendors accountable and understand where and how they're being watched. Founded in 2024 by software engineer and privacy advocate Will Freeman, DeFlock shines a light on the widespread use of automated license plate reader (ALPR) technology and the threats it poses to personal privacy and civil liberties.  

DeFlock resources help people request public records, speak to local lawmakers, and take action against ALPR surveillance. Its work has helped foster a national grassroots community of anti-surveillance activists fighting back against this dangerous surveillance technology. 

New Media Rights – Helping Creators Fight Back Against IP Bullies

New Media Rights (NMR) is a San Diego-based nonprofit program of California Western School of Law dedicated to defending digital rights through legal services, education, and public policy advocacy. Since its inception, NMR has been at the forefront of protecting creators, entrepreneurs, and internet users from digital threats such as copyright abuse, online harassment, and privacy violations. 

In addition to providing free legal assistance, NMR has produced hundreds of freely available video and written legal education guides for creators and consumers, including the Fair Use App for filmmakers and video creators. It has participated in regulatory proceedings on net neutrality, Digital Millennium Copyright Act anti-circumvention, and copyright reform. Its work has also helped support access to public information and greater business and government accountability. 

Josh Richman

New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment

1 week 1 day ago

EFF sued the government back in March for information about the Wasteful and Inappropriate Service Reduction (WISeR) model, a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services. Today, we’re releasing approximately 1,000 pages of records obtained from the Centers for Medicare & Medicaid Services (CMS) through this litigation, including contracts with tech companies, internal status reports and providers’ complaints about the program. The documents (available here) show that WISeR has resulted in widespread delays and denials of care, operational chaos, and reports of patient harm.

Why We Sued for Records about WISeR

EFF filed the FOIA lawsuit to gain badly needed transparency into an experimental AI program that could jeopardize Medicare beneficiaries' access to care. In January 2026, CMS launched the WISeR model, subjecting seniors in six states to AI-driven prior authorization decisions. Medical providers must now request permission before delivering certain medical treatments if they want assurance that Medicare will cover them. Private companies contracted by CMS evaluate the requests using AI. In the absence of rigorous safeguards, AI-driven prior authorization determinations can lead to unwarranted—and even discriminatory—delays or denials of necessary medical care. 

Little is known about the AI systems that WISeR vendors are using to process prior authorization requests. Although CMS says that a qualified human clinician must review all denials, research has shown that AI-generated recommendations often influence human decisions. And the design of the WISeR program creates a financial incentive for vendors to deny care, since they are paid for averted expenditures. Just months after the program launched, medical providers reported improper denials, administrative friction, and lengthy delays that have left patients waiting in pain.

EFF’s FOIA request sought records pertaining to the CMS contracts with WISeR software vendors; any tests for accuracy, bias, or hallucinations in vendors' technology; and any audits, monitoring, or evaluation of WISeR and participating vendors.

CMS Documents Highlight Issues with the WISeR Model

CMS records obtained by EFF echo issues that medical providers, patient advocates, and lawmakers have warned about since WISeR began. This includes long wait times, rampant technical failures, inappropriate denials, and harm to patients.

Delayed Responses to Prior Authorization Requests

CMS publicly states that WISeR vendors should respond to prior authorization requests within 72 hours, but records received by EFF show widespread delays. Internal status reports from the first few months of the program show that a significant number of prior authorization requests took far longer than 72 hours to resolve. One status report cites a prior authorization request that went unanswered for 83 days ("WISeR FOIA Response - Combined Records," page 234). These delayed responses can have serious consequences for patients. Medical providers reported that WISeR has delayed medically necessary care and left patients in pain as they waited for approvals.

Timeliness data for two WISeR vendors in January 2026 show that a significant number of requests did not receive a response within 72 hours (WISeR FOIA Response - Combined Records, page 410)

Payment Methodology Provides Financial Incentive to Deny Care 

The released records confirm that WISeR’s payment methodology creates a financial incentive to deny care. Specifically, WISeR vendors are paid for requests that they deny (though not for denials reversed on appeal). This profit motive aggravates the risk that AI-assisted decision-making may unfairly deprive people of the services they need.

CMS publicly claims that it safeguards against inappropriate denials by tying vendors’ payment rates to “quality scores,” which reflect the timeliness and accuracy of vendors’ decisions. However, the recently released WISeR Data Reporting Guide shows that low quality scores reduce payments by only 5-10%.

Impact of low quality scores on payment rates described in the WISeR Data Reporting Guide (WISeR FOIA Response - Combined Records, page 99)

WISeR Vendors Have Denied Thousands of Prior Authorization Requests

Documents obtained by EFF appear to support reports that WISeR vendors may be denying claims at unusually high rates. Two companies alone denied 5,944 prior authorization requests in the first 3 months of the program. One company, Virtix, the vendor that CMS required to submit a Corrective Action Plan, denied more requests than it approved during this time period.

Prior authorization decision data for two vendors in a March 30th, 2026 status report (WISeR FOIA Response - Combined Records, page 322)

Medical Provider Feedback Ties WISeR Delays to Patient Harm

Feedback from medical providers emphasize that WISeR delays have harmed patients. The released records include March 2026 responses to a feedback form about Innovaccer, the WISeR vendor processing requests for Ohio. Medical providers complained about a lack of communication, administrative issues, and long response times. Several responses emphasize that long response times from the WISeR vendor harmed patients ("WISeR FOIA Response - Feedback Survey Responses"):

“We have patients calling our offices crying in pain because their procedures are being delayed while awaiting approvals or guidance tied to this model. A 3–4 day delay for necessary pain procedures is already difficult for vulnerable patients, but when providers cannot obtain answers for weeks, the situation becomes unacceptable.”

“I HAVE HAD TO WATCH 3 PATIENTS CRY AT BEDSIDE FOR NOT HEARING BACK ON THEIR PRIOR AUTH FOR KYPHOPLASTY/VERTABRAL AUGMENTIATION PROCEDURE. THESE PATIENTS ARE IN DEEP PAIN.”

“I have had cases submitted and waiting over 1 1/2 months for a UTN to be generated… In the meantime patients are having to be cancelled for surgeries they need. This is not acceptable they are severely hindering patient care.”

Rushed Rollout Amidst Widespread Technical Failures 

CMS WISeR launched in January 2026, just six months after it was announced. Despite warnings from both medical providers and a vendor about insufficient preparation time, CMS chose not to delay the launch. 

Approximately a month before the launch, one of the vendors, Innovaccer, alerted CMS that it intended to go live with a version of its software that lacked full functionality and had not been fully tested. It cited several barriers to going live with full functionality, including changing requirements and expectations, unclear governance processes, and lack of time for end-to-end testing with the provider community ("WISeR FOIA Response - Combined Records,", page 216-217). Innovaccer said it would auto-affirm all prior authorization requests until it could develop full functionality and explained that “Given CMS's decision not to delay the model start date, auto-affirming is the only path available” ("WISeR FOIA Response - Combined Records," page 217).

Innovaccer had not yet finished developing or testing some features several months into the program, according to an April 2026 status report. Innovaccer was not the only vendor who faced technical challenges before and after WISeR launched. Weekly status reports and provider feedback in the released records show widespread challenges associated with WISeR’s rushed rollout (for example, "WISeR FOIA Response - Combined Records," pages 238 and 383).

A status report from April 6th, 2026 describes issues with incomplete solutions from Innovaccer (WISeR FOIA Response - Combined Records, page 200)

More Urgent Medical Services Considered for Inclusion in Future Years of WISeR Model

In its first year, the WISeR model introduced prior authorization requirements for a set of 13 medical services. The June 2025 Innovation Center Investment Plan for WISeR lists medical services that could be added to the program in future years. This planning document considers the possibility of adding services “where prior authorization would have to be done on a more urgent or emergent basis,” including air ambulance transport, cancer treatment, MRI scans, and medications without publicly available coverage criteria.

A planning document from June 2025 lists ideas for the expansion of WISeR to additional medical services (WISeR FOIA Response - Combined Records, page 22)

More Transparency is Needed About Medicare’s AI Experiment

CMS continues to produce records in response to EFF’s lawsuit. Records released thus far echo concerns that providers have raised since WISeR launched, including long delays, financial incentives to deny care, and technical problems. But important questions remain about the AI systems private companies are using to inform decisions about whether to provide people with Medicare benefits. As CMS continues to produce documents, we will continue to make them available to the public. The public deserves to know how AI is driving decisions that affect patients’ access to care.

Correction: An earlier version of this post misstated the number of prior authorization requests that had been denied by two WISeR vendors in the first three months of the program. This version has been corrected to reflect that the number of denials was 5,944. The post has also been updated to clarify that reported turnaround times reflect the full request pathway and are not solely controlled by WISeR vendors.

Related Cases: EFF v. CMS
Lena Cohen

Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal

1 week 6 days ago

A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was brought by our client, Channel 781 News, after takedown notices temporarily shut down the citizen journalism group's YouTube channel. We think the court set the bar far too low for copyright takedowns, and we plan to appeal.

Channel 781 is a group of independent, volunteer journalists who report on local affairs in Waltham, Massachusetts. That includes posting short, newsworthy excerpts from recordings of city government meetings produced by Waltham Community Access Corporation (WCAC), the city's public access television station.

In September 2023, WCAC sent three copyright takedown notices to YouTube targeting fifteen of Channel 781's videos. YouTube removed the videos and, under its three-strikes policy, temporarily disabled Channel 781's entire account—just days before a local election.

Represented by EFF and Brown Rudnick LLP, Channel 781 sued WCAC under Section 512(f) of the Digital Millennium Copyright Act (DMCA), which provides a remedy when a copyright holder knowingly makes material misrepresentations in a takedown notice.

When Is a Copyright Holder Responsible for a Wrongful Takedown?

Fair use is the legal right to use copyrighted material without permission, when doing so serves purposes like criticism, commentary, or creating something new. Fair use is not copyright infringement, and courts have recognized that copyright holders must consider fair use before using the DMCA's powerful notice-and-takedown process.

In this case, Channel 781 argued that WCAC accused it of copyright infringement without making a good-faith assessment of whether its videos were fair use.

The evidence showed that WCAC's analysis was seriously deficient. The court noted that Chris Wangler, the WCAC employee who sent the notices, didn’t consider several facts relevant to fair use. For instance, Channel 781 used relatively small portions of WCAC's recordings, and the underlying recordings were factual public meetings, not a creative work. WCAC also gave little or no weight to whether Channel 781's use harmed any market for the recordings.

There’s also strong evidence that WCAC had motivations unrelated to copyright. WCAC objected to its footage being used to criticize local officials and advance political viewpoints. And WCAC sent the takedown notices during a local election, shortly after Channel 781 posted a campaign statement by Waltham's mayor that WCAC had mistakenly made available online.

Despite this evidence, the court concluded that WCAC had a subjective good-faith belief that Channel 781's videos were infringing. We disagree.

A Subjective Belief Should Not Be a Free Pass

Channel 781 argued that a copyright holder’s belief that material is infringing must be both genuinely held and objectively reasonable. WCAC argued that a subjective good-faith belief is good enough. Unfortunately, the court agreed with WCAC.

The court emphasized that Wangler had read up on fair use, watched a short YouTube video explaining the doctrine, and distinguished between videos he thought might qualify as fair use and those he believed did not. That was enough, the court concluded, to establish subjective good faith—even though Wangler’s analysis ignored important facts relevant to fair use. As the court put it, Section 512(f) does not require “a perfect or even reasonable fair use analysis.”

That is an alarmingly low bar for copyright holders seeking to remove someone else’s speech from the internet. A DMCA takedown can cause lawful speech to disappear almost immediately. As Channel 781 experienced, multiple notices can even result in an entire channel being disabled.

If a copyright holder can avoid liability despite a cursory, incomplete, and objectively unreasonable analysis that ignores important facts—even when there’s evidence that the copyright holder wanted to suppress critical speech—the obligation to consider fair use risks becoming little more than a box-checking exercise. That interpretation threatens to strip Section 512(f) of much of its force.

Even Under a Subjective Standard, WCAC Fell Short

Even accepting the court’s subjective standard, WCAC's cursory consideration of fair use should not have been enough. WCAC disregarded important fair use considerations, and the record included statements suggesting that it believed people generally needed permission to reuse its footage—an understanding at odds with fair use. There was also evidence that WCAC objected to Channel 781's political use of its footage, and had motivations for the takedowns unrelated to copyright.

Taken together, these facts raise serious questions about whether WCAC genuinely considered fair use, rather than using copyright as a rationale for removing material it did not like.

The Court Did Not Find That Channel 781's Videos Infringed

Importantly, the court's analysis recognized Channel 781’s strong fair use argument: the group used short excerpts from factual recordings of public government proceedings, selecting clips for their newsworthiness, and making them easier for the public and journalists to find, share, and discuss.

The opinion even states that WCAC's fair use analysis “may have been deficient.” But under the purely subjective standard it adopted, the court concluded that it could not reject WCAC's professed belief—even if the court itself “would have reached the opposite conclusion” on fair use.

We plan to appeal this decision to the First Circuit Court of Appeals. Copyright law should not allow a rightsholder to suppress critical reporting or political speech through the DMCA and escape accountability simply by claiming it believed the speech was infringing. Section 512(f) is supposed to provide protection against wrongful takedowns. We will keep fighting to ensure that safeguard actually protects people. 

Betty Gedlu

Texas and Florida Step Back from ALPRs

2 weeks ago

Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After years of successful grassroots battles to pull these cameras from local streets, bipartisan momentum is sweeping the country.

On August 28, Texas Governor Greg Abbott banned state agencies from spending public funds on Flock cameras. The order dropped just as The Texas Tribune prepared to publish an investigation revealing that a state agency had quietly funneled at least $30 million into building a sprawling surveillance network. 

Then on August 31, the Florida Department of Transportation (FDOT) issued a memo, announced by Governor Ron DeSantis, ordering the removal of all ALPRs from the right-of-way on state highways within 30 days. The order revokes all previously approved permits to install ALPRs, and bars transportation officials from issuing future permits. 

FDOT officials stated that “the recent exponential increase in deployments along our roadways, coupled with concerning reports of misuse, data privacy concerns, and surveillance schemes merit immediate action to preserve Floridians’ sovereignty and quality of life.” FDOT’s action has been followed by a surge of local governments in Florida canceling or pausing their vendor contracts.

Much more work remains. Many ALPRs in Florida are not on state highways, but sit on city streets, county roads, residential driveways, and shopping center parking lots—and FDOT's order doesn't touch any of them. Likewise, the Texas directive leaves local agencies free to use city, county, federal, and private funds to install cameras.

This week’s good news follows years of pushback from local advocates that has seen dozens of cities sever ties with surveillance companies. According to some metrics, during the last 30 days, an average of three localities per day has halted contracts with Flock. Other advocates have been resisting ALPRs in statehouses and court houses, and by blowing the whistle with investigative activism.

The moves in Florida and Texas also illustrate the power that the executive branch can wield to curtail mass surveillance with almost immediate results. We hope that the California Governor Gavin Newsom and the California Department of Transportation will take notice and initiate steps to curb this technology, starting with removing the ALPRs that U.S. Border Patrol and the Drug Enforcement Administration have installed on California highways.

EFF’s position remains: ALPR mass surveillance – the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion – should not exist. This past week’s actions in Texas and Florida are good steps forward, but we are still far from the finish line. We will continue working alongside community groups to keep cameras off local streets, while urging judges and state lawmakers to impose enforceable restraints on this warrantless mass surveillance.

Rindala Alajaji

Judge Rules DOD Unlawfully Retaliated Against Anthropic

2 weeks ago

A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, intended to penalize Anthropic for telling the U.S. military it would not allow their technology to be used for mass surveillance of U.S. persons, “constituted unlawful retaliation in violation of the First Amendment.” EFF joined a coalition of organizations in filing multiple amicus briefs (here, here) arguing that the Pentagon had trampled on Anthropics First Amendment rights. We agree with the court’s decision and applaud the judge for slapping down such an obvious act of illegal and unconstitutional retribution by the Pentagon—even as the court left open the broader question of whether a company’s choices about how its technology may be used are protected speech in their own right. 

From the start of this conflict, EFF argued that companies should not be penalized for not wanting to conduct mass surveillance of US persons. Nor do we want to live in a legal system where our susceptibility to surveillance is hashed out and decided in closed-door contract negotiations between a few powerful people at the military and an AI company. Unfortunately, this ruling does little to address the bigger problem: that Congress has abdicated its responsibility to adopt statutory safeguards to protect our privacy, and instead left us reliant on the whims of private companies to decide when they are and are not willing to help the government conduct mass surveillance. 

In February 2026, the government began threatening to penalize Anthropic unless it backed off its position that it did not want the U.S. military using its AI product Claude for mass surveillance of Americans or to power autonomous weapons systems. Ultimately, the Department of Defense, deciding that it did not want military contractors dictating what its products could or could not be used for, declared the company a “supply chain risk.” This national security designation means the government and companies that do business with it cannot use the company’s products for government projects. It was, in essence, an attempted blacklisting of Anthropic for setting boundaries and articulating unacceptable use cases for its products. 

None of this is to say that Anthropic is a morally unimpeachable company, or that it and other companies would never permit their products to be used under specific conditions to aid in surveillance or analysis of collected data that could affect U.S. persons—but the facts remain: the government cannot punish a company for having preferences regarding unconstitutional uses of its technology. 

Unsupported claims that a company poses a national security risk should never be an excuse for government retaliation. This ruling correctly recognizes the dangerous implications of allowing the government to punish a company for its critical speech and for refusing to allow its technology to be used for mass surveillance. While we applaud the court's decision, we continue to urge lawmakers to take the protection of our privacy seriously. We shouldn't have to rely on private companies to protect us from the surveillance state. It's past time for Congress to act.

Matthew Guariglia

Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users

2 weeks ago

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can largely only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism. And the Settlement in no way limits the attorneys general from seeking the user information for their own law enforcement purposes.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And further, Meta will now enforce these age gates with age assurance technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The technology also just adds a layer of creepiness into the use of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) or age assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement, and that seems to require a formal assessment of accuracy.

How accurate does the age assurance process need to be?

The Settlement sets maximum false-positive rates for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more than 10% for ages 16-17 and no more than 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement generally shows little concern for those falsely placed in its Teen User category. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” The “reasonable period of time” is not defined. And the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information ... where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to those estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits, and that some teens may need to work at the restricted times to support their families and themselves:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be momentarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:

exhibit_g_meta.jpg

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such user controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service. 

Again, these would be useful user controls that should be offered to users of all ages. And while a Teen User potentially has control over these features, they cede that control to their parent once they enroll in Parental Supervision, part of the Parental Supervision Tradeoff discussed below.

Also, by default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques.”

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity standard, Meta blocks teens from “real world art of visible genitalia ... where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous women, breast cancer awareness postseducational posts about ovulation, and posts about testicular and breast self-exams. And it has disproportionately applied the standard negatively to gay and lesbian content as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressures Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

Parental Supervision comes with huge tradeoffs. There is a huge privacy tradeoff: in exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with the Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] And there are huge autonomy tradeoffs: once enrolled in Parental Supervision, the ability to control features like recommendations and autoplay, discussed above, transfer from the Teen user over to their parent.

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be ultimately workable for young people with healthy and safe relationships with their parent or guardian. But obviously it is not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users' use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as “device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’s surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States And Pays To Establish Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten-year life of the Settlement, these annual payments will total over $11 billion. And the states then get an additional $5 billion if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get the additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance, age-gating, and the ceding of teen autonomy as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance, and does nothing to protect access to such data by the states. 

David Greene

EFF to Governor Newsom: Veto California’s AB 1709

2 weeks 1 day ago

The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cuts young people off from essential information and experiences, particularly harming vulnerable youth and marginalized groups who often find safety in supportive online communities they can't access offline. That’s why we’re urging Governor Gavin Newsom to veto the measure

Should the law go into effect in January, platforms would be prohibited from offering virtually every functional recommendation algorithm and basic input, such as who a user follows or what posts they like, to anyone under 16. These so-called "addictive features," are in reality the basic tools that online services use to identify what other user-generated content a particular user might want to see. Users also rely on these features to find audiences for their own speech, as well as community. By labeling these basic tools as "addictive," the bill relies on sweeping generalizations regarding the unsettled science of youth social media use. Because nearly every major service relies on automated feeds, the ultimate result is that young people under 16 will still be locked out of major digital services as they currently exist.  

A.B. 1709 is a massive privacy and free speech nightmare.

A.B. 1709 is a massive privacy and free speech nightmare. Denying young people access to digital forums (or stripping out the basic tools needed to navigate them) does nothing to make young people safer or healthier. Research shows that social media bans are ineffectual, and can be harmful when they deny young people opportunities to develop their own voices and perspectives, whether that means sharing art, practicing religion, or engaging in politics. 

Far from protecting children, the bill will also severely restrict access to constitutionally protected speech and push platforms to implement invasive age-verification methods, such as requiring government IDs or biometric scanning. Age-gating requirements will force everyone to give big tech companies even more personal information. To verify who can pass through online gates, companies will collect even more data, concentrating power in corporate hands rather than protecting users. This creates massive honeypots of sensitive personal data, severely damages online anonymity, and exposes users of all ages to heightened data breach risks

Finally, A.B. 1709 introduces legal confusion by creating provisions that conflict with already enacted legislation like A.B. 1043 and S.B. 976. Rather than offering regulatory clarity on already-passed laws, California will only end up spending valuable resources to defend a law bound to be tied up in court.  

For more details, you can read our full letter to the Governor here

Rindala Alajaji

EFF to Courts: Don’t Rewrite Copyright Over AI Hype

2 weeks 2 days ago

The history of technology is rife with copyright panics.  In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the Boston strangler is to the woman home alone.” Then, the Supreme Court declined to embrace the hype, noting that the VTR was capable of all kinds of non-infringing uses, like time-shifting and cautioning courts to avoid rewriting copyright law in response to new technologies. We believe that courts now should be similarly wary about the hype surrounding AI.

Hollywood’s hyperbole has echoed that of composer John Phillip Sousa, who claimed in 1906 that the player piano and the gramophone would destroy music composition; portrait artists who feared the camera would replace the paintbrush. None of these things happened. Cameras, for example, sparked a resurgence of portraiture and, by making it possible for more people to create images, led to unexpected developments—like the rise of photojournalism.

New markets, new ideas, and new creators are actually what copyright is supposed to promote, not restrict. Using copyright to lock in existing gatekeepers and massive rightsholders’ profits helps neither the public nor individual artists.

Generative AI has sparked the latest wave of anxiety and with it a massive wave of litigation. In multiple cases around the U.S. and the world, rightsholders are asking courts to do precisely what the Supreme Court warned against: dramatically expand copyright protections based in substantial part on hyperbole and speculation. They should decline to do so.

Copyright owners claim that unless courts abandon 300-year-old copyright principles—and give rightsholders the power to control non-infringing works created by others—an imagined flood of AI-generated works will devastate creative markets. Under this “market dilution” theory, building generative AI tools cannot be fair use because those tools might be encourage the proliferation of competing works.

As EFF has explained to the courts in multiple amicus briefs in Concord Music Group, Inc. v. Anthropic PBC and In re Mosaic LLM Litigation, that’s not how copyright works. In fact, accepting this theory would undermine copyright’s constitutional purpose: promoting the creation of expressive works for the public’s benefit. Because copyright law is designed to encourage others to build freely on existing works, it punishes infringement, not competition. The “market dilution” theory would eviscerate not only the fair use doctrine, but also other limits on copyright that work specifically to prevent rightsholders from unfairly suppressing competition by claiming broad ownership over tropes, genres, styles, and so on. In other words, publishers would wield unchecked veto power over any expression that might conceivably compete with a work they own.

The result? Art doesn’t get created, ideas are never expressed, and we’re all worse off. Copyright shouldn’t be a tool to silence future creative competitors—whether or not they use AI in their work.

And the plaintiffs in these cases get at least two other things wrong. First, research shows that large generative AI models are unlikely to produce infringing works because the more data on which a model is trained, the less any individual training example matters to any particular output.

Second, AI tools aren’t necessarily displacing human creativity. To take a just a few examples:

  • Boston-based artist Nettrice Gaskins uses AI to create Afro-futurist art, including a portrait of Octavia Butler displayed at the San Francisco Airport
  • Indian artists Prateek Arora and Varun Gupta use generative AI to reimagine Western science fiction.
  • Philadelphia-based artist Alex Smith uses generative AI to reimagine Afrofuturism with queer, plus-sized Black superheroes.
  • Ana Miljački, a professor of architecture at MIT, used generative AI to create a “non-liner documentary” film on Yugoslav World War II memorials and the values they embodied.
  • A research-creation project used AI generated visual art to both amplify the voices of activists in the Iran Woman Life Freedom Movement and evaluate AI’s role in sociopolitical advocacy through art.
  • AI company Bronze works with musicians like Disclosure and Jai Paul to create songs that never sound the same when played back twice, challenging audience conceptions of what music could be.

It is not the place of courts to say these people are not artists or that AI cannot augment human creativity in a positive way.

Given this range of experimentation, courts should be reluctant to decide in advance what tools do and do not foster “human creativity.” Like the VTR, large language models are general purpose tools, used by humans to do a broad variety of things far beyond generating lyrics. The effects of this particular technological innovation will doubtless be far-reaching, disruptive, and potentially harmful for some—but distorting copyright law is not the way to address those harms.

Tori Noble

Doxxing Safety Part II: Incident Response

2 weeks 2 days ago

Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse. 

This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.

Incident Log

An incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful. 

The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:

Assign Team Roles

Remember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).

Monitoring Hate Forums

So often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.

Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.

Set Up Search Alerts

Google alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.

For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.

Hardening Your Public Facing Accounts

For accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.

Shut Down Affected Accounts

If a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.

Revisit Your Data Broker Removal Strategies

Although this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.

Revisit Public Records

As covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.

Consider Contacting Law Enforcement

For many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.

Revisit PACE Documents, Enact Those Steps

If you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.

This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.

Put A Lock on Your Bank Accounts and Cell Subscriptions

One of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques. 

Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).

Regulate Your Nervous System

It’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process. 

Flexibility and Resiliency

The reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security. 

Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.

Daly Barnett
Checked
3 hours 28 minutes ago
EFF's Deeplinks Blog: Noteworthy news from around the internet
Subscribe to EFF update feed