Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction

19 hours 40 minutes ago

The Senate Commerce Committee will vote this week on several censorious and privacy invasive bills: KOSA, the SCREEN Act, Youth AI Privacy Act, and CHATBOT Act. While we appreciate that the Committee is taking the time to look at these bills separately, it’s still impossible to ignore the message Congress is sending to the world: Age-gate the internet and block young people from speaking and accessing lawful speech online. Or else. 

Take action

Tell Congress: don't age-gate the internet

Each of these bills claims to be trying to protect children and teenagers from dangerous situations on and offline—certainly a worthy goal. But the proposed solutions in these bills are unlikely to make children and teenagers safer at all. Rather, they would create sweeping new privacy and data security problems, and force platforms to adopt unconstitutional restrictions on the content they host, for both adults and teenagers. 

There is a better way. Instead of considering these bills, the Senate Commerce Committee should be focusing on a national consumer privacy bill that would protect ALL internet users, or on banning behavioral advertising that tracks us across the web—again, for users of all ages. 

But the bills being considered this week move in the other direction—more information being collected, more surveillance, and less privacy for internet users of all ages. 

Take action

help eff oppose these bills

EFF sent a letter to the Committee with our concerns about these bills. We look forward to continuing to work with them to find a way forward that protects all users. 

India McKinney

Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA

21 hours 23 minutes ago

The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because Amazon did not “authorize” Perplexity to access Amazon users’ accounts. Rejecting that theory, the Ninth Circuit held that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.

That’s the right conclusion, as both a legal and technical matter. As we explained to the court in our amicus brief, the CFAA requires unauthorized “access,” and Perplexity itself does not access Amazon’s servers—users of the Comet browser do. The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.”

The court noted that agentic AI may present novel legal issues, and there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.” And, the court concluded, it is a tool operated by users, not Perplexity. Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity. As the court noted, Amazon might have other viable claims against Perplexity, but invoking the CFAA was both legally baseless and bad policy that “could expose users themselves to criminal liability. 

This is a gratifying decision because all too often, big players use the CFAA to bully upstarts and innovators who offer potentially helpful user tools. When we counsel clients as part of EFF’s Coders Rights Project, CFAA risk is a frequent topic of conversation, even for developers who merely create tools that allow others to access websites in new or different ways. We’ve stood up for these creators before, and we’ll do it again, but it’s helpful to have back up from one of the most influential appellate courts in the country.

Related Cases: Facebook v. Power Ventures
Andrew Crocker

Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds

1 day ago
Developers Must Beware of Ad Libraries that Betray Users’ Privacy

SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found

EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation.    

“Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Cohen said. “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.” 

Cohen and EFF Senior Staff Technologist Bill Budington reviewed the public developer documentation of dozens of widely used advertising SDKs to identify how they handle and communicate with developers about location data.  

In their analysis, they highlighted four advertising SDKs that collect and share a user's location by default for ad targeting whenever the user has given the app location permissions: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. But EFF’s focus on these four does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. In fact, advertising SDKs not discussed in this investigation have been criticized and sued for collecting location data without valid user consent.  

“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads,” Budington said. “Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Developers have a responsibility to protect their users’ from these harms, regardless of advertising SDKs’ default settings.” 

For the EFF report: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy

For more on location data brokers: https://www.eff.org/issues/location-data-brokers 

For more on SDKs: https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data   

Contact:  WilliamBudingtonSenior Staff Technologistbill@eff.org LenaCohenStaff Technologistlcohen@eff.org
Josh Richman

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy

1 day ago

Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.

When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.

Defaults matter, not just for users, but for app developers as well.

An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location by default when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.

This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.

Contents: Data Brokers Harvest Location Information From Advertising Systems

When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.

Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “real-time bidding” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests. 

Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of Gravy Analytics. To prevent location information from being shared with data brokers through RTB, developers must understand the location-sharing practices of their advertising SDKs.

How Advertising SDKs Leak Location Data

Developers don’t have to manually, or even intentionally, share location data for it to be broadcast through RTB auctions. Once a user grants an app permission to access their location, SDKs embedded in the app receive the same access—there are no SDK-specific location permissions. That means advertising SDKs can automatically collect users’ location data and share it in bid requests.

While apps and SDKs can estimate a users’ approximate location from their IP address without requesting any permissions, location permissions provide access to estimates that are more accurate and revealing. Precise location permissions give apps (and their embedded SDKs) access to location estimates within about 160 feet, but sometimes as accurate as 10 feet. Approximate location, a separate permissions level, gives apps access to a location estimate within about 1.2 square miles. 

Developers and advertising SDKs also have a financial incentive to share location data, since it can increase bid prices for an app’s ad space. While many advertising SDKs require developers to configure a setting before collecting and sharing users’ location data in ad requests, this is not always the case. EFF found several advertising SDKs who publicly acknowledge sharing users’ location data by default when embedded in apps granted location permissions. 

EFF Identified Advertising SDKs That Share Location Data by Default

EFF reviewed the public developer documentation of dozens of widely-used advertising SDKs to identify how they handle and communicate with developers about location data. In the following sections, we highlight four advertising SDKs who engage in a particularly egregious practice: collecting a user's location by default for ad targeting whenever a user has given an app location permissions. We reached out to each SDK company and the referenced app developers for comment. One company responded, and as detailed below, subsequently updated its documentation in response to our questions. Another company responded with clarifications to its developer documentation.

We chose to focus on SDKs with this privacy-invasive default because it increases the risk of developers leaking users’ location data without realizing it. Several studies have found that developers tend to stick to SDKs’ default settings. If an advertising SDK transmits location data by default, users' precise location can end up in advertising systems without the developer intentionally enabling location sharing. These SDKs have separate documentation pages that instruct developers to flag users covered by privacy laws like GDPR and COPPA for restricted data processing, but these modes are not the default. 

By analyzing how these four SDKs present their location sharing practices to developers, we hope to illustrate how the design and documentation of advertising SDKs can facilitate location data sharing at scale. Although the advertising SDKs we highlight are not the most prevalent SDKs used, they are embedded in thousands of apps and reach billions of users.

InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives

InMobi claims to reach “2B+ users across 150+ countries” and is the 10th most popular advertising SDK on Android (according to AppBrain and Appfigures at the time of publication). 

InMobi’s “Getting Started with Android SDK Integration” suggests that location sharing is enabled by default, stating “The InMobi SDK automatically forwards location signals when available.” InMobi provides developers with a setting to opt out, but explicitly recommends sharing location data. Developer documentation highlights the financial incentive for location sharing, stating “location-enriched impressions typically yield higher revenue.” 


[Observed on “Getting Started with Android SDK Integration,” 7/31/26]

Apps that use InMobi may not need location information to function or may only need access to approximate location information, but InMobi highly recommends that developers request precise location permissions “to enable accurate ad targeting.” They even encourage developers to request Wi-Fi network information permissions, which (when paired with precise location permissions) provide Wi-Fi access point identifiers that can also be used for location tracking.


[Observed on “Getting Started with Android SDK Integration,” 7/31/26]

InMobi has been accused of misleading developers over location sharing practices in the past: In 2016, they settled with the FTC over charges that they bypassed users’ location permissions for apps and tracked their precise locations through WiFi network data (Android now requires apps to request location permissions to access this WiFi data too).

BidMachine Updates Previously Inaccurate Developer Documentation After EFF's Technical Analysis Observed Precise Location Data Collection

BidMachine claims to reach over 600 million “direct SDK users.” 

BidMachine reveals that it collects location data by default on the “Advanced Settings” page of its Android SDK Integration guide, stating that the “SDK can automatically track user device location to serve better ads” as long as developers request location permissions for their app. Before publication, EFF reached out to BidMachine for comment, notifying them of our plan to highlight their Android SDK location sharing practices.  


[Observed on “Advanced Settings” on 7/31/26, before EFF asked BidMachine for comment]

After EFF reached out, BidMachine changed their documentation to clarify the practice, but not their default collection of location information once app-level permissions are granted. This updated section still fails to explain how developers can opt out of BidMachine location tracking, which is critical for app developers that require location access for core features but wish to prevent user data from being shared with advertisers.


[Observed on “Advanced Settings” on 8/3/26, after EFF asked BidMachine for comment]

Before EFF reached out, BidMachine’s “App Privacy Details On Google Play” page had stated that they only collected coarse location data and precise location data was “not collected.” However, our technical analysis of two apps, which Exodus Privacy determined include the BidMachine SDK, contradicted this claim: Network requests from the apps QR Scanner and GPS Speedometer to a BidMachine domain include precise location coordinates.


[Observed on “App Privacy Details On Google Play” on 7/31/26, before EFF asked BidMachine for comment]

After EFF reached out, BidMachine also corrected its documentation to make it clear precise location is collected by the SDK whenever the app-level permission is granted:


[Observed on “App Privacy Details On Google Play” on 8/3/26, after EFF asked BidMachine for comment]

com.appswing.qr.barcodescanner.barcodereader_bidmachine.flows

com.ktwapps.speedometer_bidmachine.flows

In response to our request for comment, BidMachine stated that it wasn't possible for them to get location information “unless the user has granted the app the relevant permission through the operating system.” They also stated that“publishers are responsible for configuring their apps' permission and consent flows.”

Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide 

Verve has claimed its HyBid SDK reaches “over 1.5 billion users across more than 10,000 apps worldwide.” 

Verve’s configuration guide for its HyBid Android SDK (formerly called Pubnative HyBid) makes clear that location tracking is “enabled by default,” stating, “If the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.” 


[Observed on “HyBid Android SDK - HyBid Configuration,” 7/31/26]  

Verve’s guidance for data disclosure to the Google Play Store tells a more careful story. Despite the fact that location tracking is enabled by default, the Google Play Data Safety Guidance states that the SDK “does not collect or attempt to collect [location] information independently.”


[Observed on “Google Play Data Safety Guidance,” 7/31/26]  

It also emphasizes user consent, claiming the SDK will only collect location data “if the publishers allows its app to collect location data from users after obtaining user’s explicit consent to such data collection” (emphasis added). The configuration guide lacks recommendations or instructions for obtaining user consent to share location data with Verve, beyond app-level access. Instead, the configuration guide highlights the financial incentives for developers to add location permissions to their app.


[Observed on “HyBid Android SDK - HyBid Configuration,” 7/31/26]  

When reached for comment, Verve clarified that “in its current Android implementation, the SDK reads the cached network-provider location and does not use the GPS data of the end user's device. Furthermore, any geolocation data is coarsened prior to processing, ensuring that location is limited to an accuracy radius of no less than 1,850 feet.” It also said that it contractually requires apps to comply with data protection laws. 

To Verve’s credit, the HyBid SDK is open source, so careful developers can check the code instead of relying on documentation alone. HyBid’s open-source code shows that latitude and longitude coordinates are rounded to two decimal places, and that it does only collect and share network-derived location data, confirming the statement the company sent to us. If an app has precise location permissions, networked-derived location data rounded to two decimal places could be accurate within approximately 0.5 square miles, which is still more precise than the 1.2 square miles typically revealed with Android’s approximate location permission. But even coarse location data, especially when collected repeatedly over time, can reveal movements that should remain private by default.

Verve’s response also conveyed a willingness to revise their documentation: “As part of our ongoing commitment to providing clear and comprehensive developer resources, we continually review and enhance our documentation, and we will take your observations into account as part of that process.”

Huawei Highlights Financial Incentives for Location Data Sharing Before Showing Developers How to Opt Out

Huawei has claimed its Petal Ads SDK is embedded in more than 85,000 apps worldwide.

Huawei’s “Integrating the Petal Ads SDK into an Android App” guide begins with a recommendation that developers obtain location permissions to increase app revenue and an acknowledgement that location sharing will happen by default in apps with location permissions.


[Observed on “Integrating the Petal Ads SDK into an Android App,” 7/31/26]

A separate “Use of Location Data for Ads” page repeats that the Petal Ads SDK will include users’ location information in ad requests if an app has access to location information. Neither of those pages mention that developers can use the setRequestLocation method to disable the default collection of location information (this setting is referenced in the last section of the Ads SDK Compliance Guide). Huawei’s Ads SDK Privacy Statement states that “The SDK and its services will not store precise location information, and will only use it to determine the approximate device location.” However, the guide does not specify how Huawei defines approximate versus precise location data. 


[Observed on “Use of Location Data for Ads,” 7/31/26]

Location Data Sharing Can Happen Without Users’ Knowledge or Meaningful Consent 

In some cases, after an app itself obtains location permission, advertising SDKs can separately obtain and share users’ location information without their knowledge or meaningful consent. Neither app that EFF observed sharing precise location data with BidMachine (QR Scanner and GPS Speedometer) showed a notice or requested consent before doing so. Additionally, neither apps’ Google Play Store “Data safety” section includes location data under “This app may share these data types with third parties.” The lack of transparency and control that users have over their location on mobile apps is dangerous. QR Scanner and GPS Speedometer are just two examples of apps that quietly share users’ location data through advertising SDKs, but they have been downloaded more than 50 million and 10 million times, respectively. 

App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.

Even if users’ were to grant these apps permission to obtain their location data, they would likely not expect their location data to be shared with third parties. Many users don’t know that granting location permissions to an app grants the same permissions to third-party SDKs embedded in the app, or that an app they're using contains code from outside companies. And many apps that request location permissions, like GPS Speedometer, require it for core functionality. App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.

Location Privacy Issues Extend Beyond These Four SDKs

Our initial focus on four advertising SDKs does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. Advertising SDKs not discussed in this report have been criticized and sued for allegations that they collect location data without valid user consent. 

The issues we’ve highlighted around privacy-invasive defaults, financial incentives, and unclear documentation extend beyond the specific SDKs we analyzed. Multiple studies have found that advertising SDKs often steer developers toward increased data collection through their design and documentation. A 2021 study found that popular advertising SDKs used dark patterns to nudge developers towards sharing more sensitive data. A 2024 study identified discrepancies between several SDKs’ documentation and their actual data collection practices. And a 2025 study concluded that developers have minimal influence over SDKs’ data transmission, often leaving them with the choice of accepting SDKs' invasive data collection or avoiding them entirely. 

Fighting Back Against AdTech Companies That Enable and Encourage Location Data Sharing 

EFF’s analysis shows that advertising SDKs don’t just allow developers to share location data–they often encourage it. Default settings, financial incentives, and unclear documentation can make sharing users’ location the easiest option for developers.

Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.

Developers

Developers should carefully evaluate all third-party SDKs they include in their apps and disable unnecessary data collection whenever possible. Regardless of advertising SDKs’ default settings, developers have a responsibility to protect their users’ location data. But protecting users’ privacy shouldn’t depend on developers reading the right piece of SDK documentation. Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location. 

Regulators

Regulators should continue to hold app developers accountable when they unlawfully share personal data and include libraries which subject users to privacy harms, as they have in the past. But they should also scrutinize the companies whose SDKs encourage these practices at scale. Otherwise, companies can continue to design SDKs that make invasive data sharing the default while shifting the responsibility and consequences to developers who include their tools. 

Legislators

The US is in dire need of a federal law to protect all Americans’ location privacy, one which doesn’t preempt stronger state privacy laws, and has a private right of action empowering individuals to sue those who violate their privacy. Countries across the globe should likewise enact legislation that protects their users’ location privacy. Everyone deserves privacy as a universal human right.

Legislators can address the root of the problem by banning online behavioral advertising. This would remove the primary incentive for companies to track and share your personal data. It would also prevent users' precise locations from being broadcast to data brokers through RTB auctions. 

Until then, developers should be wary of ad libraries that betray their users’ location privacy.

Notes on Methodology

We were interested in looking at network traffic for various Android ads SDKs that send precise location by default when granted location permissions. We chose Android for this investigation because of the relative openness of and our familiarity with analysis on the platform. We’ve used publicly available resources like Exodus Privacy and AppBrain to identify popular ads SDKs and the apps which include them.

In a lab setting, we set up a machine to view our own http(s) traffic using mitmproxy from our test device, and connect the test device to that machine in order to view our real-time traffic.  Where needed, we use the dynamic instrumentation toolkit Frida to ensure the traffic we generate can be analyzed.

We’ve included flows files in this post, which can be opened in mitmproxy to show the requests we’ve observed with location coordinates.

Lena Cohen

Technology's Power in the Hands of the People

1 day 5 hours ago

In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world's largest computer security gathering. If you're there during this summer security week, be sure to say hello to us at BSides Las Vegas, Black Hat Briefings, and DEF CON 34. While tech companies align with governments to target the people, our community is harnessing technology to fight back. Will you lend your support this year?

JOIN EFF

EFF’s relentless work in the legal system makes a meaningful difference for privacy and free expression everywhere. But we also know that your rights won't wait while the wheels of justice turn.

Sometimes hacking the system means creating tools and resources to protect your rights today. That includes EFF’s Privacy Badger, Certbot, Surveillance Self-Defense guide, and the countless security trainings that our team conducts for vulnerable populations—all thanks to EFF member support.

Technology is inseparable from our workplaces, schools, healthcare, the justice system, and our democratic process. If you think tech should benefit everyone and not just accumulate wealth and control for the powerful, then congratulations: We'd like to welcome you to the team.

Hayley and Joe take a break from EFF’s Activism Team to show off EFF’s DEF CON member t-shirt.

For a limited time only: Get EFF’s “Many Hands Make Light Work” t-shirt designed for the DEF CON 34 hacker conference by EFF artist Hannah Diaz. Don’t miss the link to the online puzzle incorporated into the design! With the strength of community and the spirit of curiosity, we can hack anything.

Many thanks to our puzzlemasters Aaron Steimle (AKA Elegin) and Kevin Hulin (AKA CryptoK). Elegin is our longtime collaborator on the EFF shirt puzzle, and previously a multiyear winner of this very contest. CryptoK is a crypto puzzle enthusiast and also develops challenges for the DEF CON Crypto and Privacy Village's Gold Bug Contest.

Members can also choose from EFF’s puffy stickers, the internet tracker-obsessed Privacy Badger embroidered sweatshirt, and our ALPR-focused “Claw Back” t-shirt.

EFF member t-shirt designs: Claw Back and Many Hands Make Light Work

EFF fights to protect fundamental rights for everyone, and your privacy and free expression have never been more important. Support the cause today! Together we can make sure that technology supports freedom, justice, and innovation for all people.

Aaron Jue

The Senate Should Reject KOSA's Privacy Risks

1 day 20 hours ago

The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the SCREEN Act, the CHATBOT Act, and the Youth AI Privacy Act, the Kids Online Safety Act (KOSA) would push companies to collect more information about their users while creating new incentives to restrict lawful speech.

Take action

Tell Congress: KOSA endangers the privacy of all

KOSA Pushes Platforms Toward Age Verification

The Senate version of KOSA imposes a “duty of care” on online services, including social media, to avoid exposing young people to certain material the law deems harmful. But those obligations only work if online services know which users are minors. That means more platforms will be pressured to implement age verification or age estimation systems.

That’s not a bill that increases privacy—it’s one that creates new privacy problems. Whether companies verify ages by checking government IDs, performing facial analysis, checking your bank records, or collecting other personal information, all of these systems require the handing over of more sensitive data, simply to access lawful online speech and services. They also create new databases of personal information that can be breached, misused, or demanded by governments.

Everyone deserves privacy online. Congress could push for a bill that protects privacy for all users, but that’s not what they’re doing here. Instead, KOSA and the other bills coming up for a vote this week push online services to adopt systems that require people to identify themselves before they can speak, read, or participate online.

KOSA Still Creates Incentives to Censor Lawful Speech

Some online content isn’t appropriate for minors. Families, schools, and communities all have important roles to play in helping children navigate the internet. But KOSA takes those decisions away from families and the young people who have a First Amendment right to speak and access information online. It instead empowers government officials to enforce how online services handle lawful speech. 

And by empowering elected attorneys general in states across the country to enforce KOSA, the bill means those elected officials, rather than your family, deciding what’s appropriate online content for teens. Even more likely, it will lead to limits on what minors and adults are able to see at all, as companies shut down potentially controversial forums in order to avoid legal action from government bureaucrats. 

The latest version of KOSA once again includes a broad "duty of care" requiring platforms to mitigate a wide range of alleged harms to minors.

Whatever disclaimers and exceptions the bill includes, the practical effect is unchanged. When platforms face liability for content that someone later claims contributed to harms like anxiety, eating disorders, or substance use, the safest response is to remove lawful speech or shut down forums discussing those topics altogether. 

More worrisome, the potential liability KOSA creates may push online services to either remove speech well in advance of a young person seeing it, or block young people’s access so they never see it. That will likely include forums where people try to help each other, find community and recovery resources for the exact harms listed in the bill, like gambling and drug addiction. In trying to protect young people, KOSA may actually cut them off from valuable sources of support. 

We've explained these censorship risks in detail before, and they remain just as real in the latest version of the bill.

Congress Should Reject KOSA

Minors deserve meaningful privacy protections online—as do adults. But KOSA moves in the opposite direction by encouraging more age verification, as well as more legal pressure for platforms to monitor and restrict lawful speech.

The Senate Commerce Committee should reject KOSA, along with the other bills in this legislative package, and instead pursue comprehensive privacy legislation that protects everyone—not just minors—without undermining privacy, security, or free expression.

Take action

Congress shouldn't set the rules for what we see online

Joe Mullin

EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act

1 day 20 hours ago

EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states:

While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.

As we’ve previously explained, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own Privacy Badger. As we illustrate in the letter: 

Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives. 

Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.

Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won't fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.

You can read the full letter here. For a deeper dive into why crawlers and scrapers are vital for the open web, check out this blog post.

Rindala Alajaji

EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal

1 day 21 hours ago

The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers. 

The new proposed policy builds on, and directly references, the Trump administration’s  “Preventing Woke AI in the Federal Government” executive order—a nightmare for civil liberties that seeks to strong-arm AI companies into modifying their models to conform with the its ideological agenda. In recently filed comments, EFF,  Public Knowledge, and Fight for the Future call for the FTC to stop its unconstitutional efforts to regulate lawful speech, override state laws, and intimidate AI developers into ideological alignment with the Trump administration.

The government may not install itself as the arbiter of truth.

In the joint comments, we outline three critical flaws within the latest proposed policy. First, it violates the First Amendment. The policy calls for the Commission to become the judge of which AI outputs meet an undefined standard of accuracy. Installing the FTC as the authority of this sort of viewpoint-based judgment is a prior restraint on speech. Additionally, the policy’s proposed solution to address speech concerns compounds, rather than properly limits, the likely harms to speech. As we say in our comments: the government may not install itself as the arbiter of truth. 

Second, it exceeds the FTC’s legal authority by claiming that its federal regulatory rules can override, or “preempt,” laws in states that have passed to regulate artificial intelligence use. This is clearly an attempt to target state laws the administration disagrees with. For example, the policy specifically criticizes Colorado's automated decisionmaking law, which applies when automated technology is used to consider consequential decisions such as those around employment, access to housing, health care, and insurance. We noted to the FTC that characterizing this law as one that requires AI companies to “suppress accuracy,” or encourages deception, is itself inaccurate. In any case, the FTC lacks the authority to put its rules in place over state law, unless Congress directly delegates it that power. It has been given no such power here.

Third, the policy is vague and sets the stage for improper jawboning of AI developers and companies that use AI tools (deployers). Jawboning is a term for situations in which the government urges private companies or people to censor another's speech. The proposal, as written, creates an enforcement regime that would put a thumb on the scale in favor of certain partisan speech and ideals. This will lead companies to censor only what the administration interprets as biased or untruthful. Yet, in our filing, we note that the FTC itself can't define an objective standard for what “bias” means, conceding the “exact line of what constitutes bias may be difficult to draw.”

There is work the FTC should be doing to protect consumers in the age of AI. In our comments, we conclude by saying:

[We] implore the Commission to focus on its core strengths and the mission for which it is so urgently needed—promoting structural market competition and protecting consumers from real unfair and deceptive acts and practices—in both the burgeoning and critically important AI industry and across the broader technology marketplace.

EFF and our partners have always urged the FTC to police genuine deception in technology markets. We have also consistently opposed government efforts to dictate what private speakers may say. That’s why we urge the FTC to withdraw this proposal. 

You can read our full comments here

Tori Noble

The Youth AI Privacy Act’s Privacy Paradox

1 day 22 hours ago

The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bills under consideration this week—require more data collection and make it harder for people to access lawful speech online. 

While the bill is narrower than some other proposed chatbot bills, it still has massive data security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.

This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing "harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are already targets of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more. 

The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors. 

Mandating Design is Regulating Speech

The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push alerts and notifications.  

We have seen this same type of restriction, sometimes called “age appropriate design code” in several states, including in California, Texas, and Arkansas. Unfortunately, these restrictions run into constitutional problems. In fact, federal courts have largely blocked these laws from going into effect because they likely violate the First Amendment rights of all internet users and the online services they regulate. Specifically, these laws interfere with internet users’ First Amendment rights to either speak or access speech online, and they also violate the rights on online services to decide how they will present information on their sites. 

Similarly, the Supreme Court has repeatedly ruled that “minors are entitled to a significant measure of First Amendment protection.” This does not mean that parents or guardians can’t set their own rules for their families—they can and they should, based on the needs and circumstances of the individual teenagers. But it does mean that Congress cannot adopt a “one size fits all” regulation that sets a restrictive government default that affects the First Amendment rights of all internet users, including teenagers. 

Maddie Daly

EFF at BSidesLV, Black Hat, and DEF CON 👨‍💻

2 days 5 hours ago

It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.

EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don't hesitate to reach out to info@eff.org where our intake team is ready to assist! Share a brief summary of the issue, and we'll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our Coders' Rights Project page.

Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You'll probably spot us roaming the conference halls, but we'd love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we'll have our limited-edition DEF CON 34 t-shirt on hand. We're excited to see them—and other EFF gear—take over each conference!

EFF Staff Presentations Privacy's Defenders: How Hackers Helped and Can Do So Again

Hackers have a long history standing up for justice and that history has a lot to teach and inspire the hackers of today as we face a world with 360-degree surveillance that is increasingly marshaled against us by both companies and governments. My talk will tell background and stories from my book, Privacy's Defender, that tells the story of my 30 years working with EFF to try to protect security and privacy in the digital age. Cards on the table: I'm trying to recruit you to join in the fight.
WHERE: Florentine F | BSides Las Vegas
WHEN: Monday, August 3 @ 11:00
WHO: Cindy Cohn - Former EFF Executive Director 

Ask EFF at BSidesLV

Panelists from the EFF Staff will give brief updates on key topics in their expertise before turning it over to BSides attendees to ask their burning questions about policy, advocacy and making the future of tech brighter. It's a dynamic session fostering engaging discussions on digital rights featuring an EFF staff attorney, activist, and public interest technologist.
WHERE: Florentine F | BSides Las Vegas
WHEN: Tuesday, August 4 @ 14:00
WHO: EFF's Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley Pederson, and Cindy Cohn

What Election Security Researchers Need to Know about Section 1201 of the Digital Millennium Copyright Act

WHERE: Voting Village | DEF CON
WHEN: Friday, August 7, 10:30-11:00
WHO: EFF Staff Attorney Tori Noble

Privacy's Defender: How Hackers Protected the Internet Before and Can Do It Again

EFF's Outgoing Executive Director Cindy Cohn' presents her first-person stories from her recently published book, Privacy's Defender, that take you Inside the privacy battles that have shaped today's Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.
WHERE: Creator Stage 1 | DEF CON
WHEN: Friday, August 7, 15:00-16:30
WHO: Former EFF Executive Director, Cindy Cohn

Why Mandatory Age Verification Keeps Us All Less Safe

WHERE: Creator Stage 7 | DEF CON
WHEN: Saturday, August 8, 13:30-14:30
WHO: EFF Director of Engineering Alexis Hancock & EFF Social Media and Video Manager Kenyatta Thomas

ESP32 As A Counter-Surveillance Platform

Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative. This presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities. Applications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. We will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.
WHERE: Main Track 1 | DEF CON
WHEN: Sunday, August 9, 10:00-11:00
WHO: EFF Senior Staff Technologist Cooper Quintin

Tactical Advocacy: Panel & Peer Sessions with EFF

WHERE: Policy Village | DEF CON
WHEN: Sunday, August 9, 12:30-14:00
WHO: EFF's Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori Noble, Rory Mir & Cindy Cohn

EFF Contests at DEF CON 34 EFF Benefit Poker Tournament

We’re going all in on internet freedom. Take a break from hacking the Gibson to face off with your competition at the tables—and benefit EFF! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all. Join us on Friday, August 7 at 12:00 at theHorseshoe Poker Room. Play for glory. Play for money. Play for the future of the web.
WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109
WHEN: Friday, August 7, 12:00-15:00

Beard and Mustache Contest

Yes, it's exactly what it sounds like. Join EFF at the intersection of facial hair and hacker culture. Spectate, heckle, or compete in any of four categories: Full beard, Partial Beard, Moustache  Only, or Freestyle (anything goes so create your own facial apparatus!). Prizes! Donations to EFF! Beard oil!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Friday, August 7, 13:00-15:00

Tech Trivia Contest

Join us for some tech trivia on Saturday, August 8! EFF's privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture. The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear. Invite your friends OR show up and make new friends! Did someone say BRIBES? The world is unfair! You too could influence the judges to add a point or two to your team's tally. Overall Bribe winner also wins a custom badge!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Saturday, August 8, 17:00-20:00

Privacy's Defender Book Signing with Cindy Cohn

Grab a copy of former EFF Executive Director Cindy Cohn's new book, Privacy's Defender—and get it signed—while at DEF CON 34!
WHERE: Exhibit Hall West 4 (Book Signings)
WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00 

Join the Cause!

Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or donate to become an EFF member. We'll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you're not in Vegas!

Join EFF

Support Security & Digital Innovation

Christian Romero

Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy

5 days ago

California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.

Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.

Take Action: Tell Your Senator to OPPOSE A.B. 1709

A "Compromise" That Still Denies Access

Under the newly amended Section 22683, platforms are prohibited from offering "addictive features" to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls "addictive feeds," auto-play, and anything else the Attorney General designates in future rulemaking.

However, the bill defines "addictive feeds" so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended "in whole or in part, on information provided by the user." That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive," the bill also makes broad conclusions about the unsettled science behind social media use, youth, and addiction.

Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.

Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional right to access information and participate in public discourse.

AB 1709 Still Forces Invasive Age Verification

The amendments do not eliminate the privacy threats posed by age gating. Although the bill references the age-signaling framework in AB 1043, Section 22684 explicitly states that a covered platform "shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check. 

Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive honeypots of sensitive personal data, destroying online anonymity and exposing users of all ages to security breaches. And relying on biometric systems to verify users’ ages is problematic because the systems have historically had high error rates estimating ages across race and gender lines.

Take Action: Tell Your Senator to OPPOSE A.B. 1709

Lawmakers Must Reject AB 1709

The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like SB 976. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.

Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.

We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.

Rindala Alajaji

The SCREEN Act Threatens Privacy Far Beyond Adult Websites

5 days ago

The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.  

Take action

protect your right to browse the web privately

Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.

The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. 

The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. 

Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information. 

In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.

The SCREEN Act Attacks Your Right To Use VPNs

The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking. 

VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server's IP address, not your actual location. It's like sending a letter through a P.O. box so the recipient doesn't know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.

The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users. 

Take action

Tell Congress to oppose the screen act

India McKinney

The CHATBOT Act Forces One Parenting Model On Every Family

5 days ago

Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems. 

Take action

Tell Congress not to age-gate the internet

The Bill Requires AI Companies To Build Family Monitoring Systems 

Parents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life. 

The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system. 

As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls. 

This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI. 

The CHATBOT Act Creates New Privacy Risks For Families 

Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages. 

And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures. 

The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks. 

Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system. 

Take action

Tell Congress to oppose the chatbot act

The CHATBOT Act Applies A Children’s Law To Teenagers 

The CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers. 

That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.  

In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users. 

But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires. 

The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student. 

Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system—the bill’s only option is to create a family account.

Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant. 

The CHATBOT Act Will Pressure AI Companies To Check Users’ Ages 

The bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18. 

Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification.  Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes. 

Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law. 

A Better Way Forward

Congress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families. 

Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now. 

Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues. 

Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.

Take action

stop this bill

Joe Mullin

EFF Guide to Recording Law Enforcement

5 days 5 hours ago

This post is available as a printable one page handout in English and Spanish.

Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can come with risks. Below are important legal and practical considerations related to recording the police and other law enforcement officers.

Can I legally record the police or immigration officers?

Yes. All Americans have a First Amendment right to record law enforcement. This includes local police and federal officers such as those from Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). Although the Supreme Court has not squarely ruled on the issue, nine different federal appellate courts have recognized and affirmed this right, relying on decades of Supreme Court precedent.

Courts typically frame the right to record law enforcement as the right to record officers exercising their official duties in public. This right extends to bystanders as well as people recording their own interactions with law enforcement, such as livestreaming their own traffic stops. The right also applies to private places where the recorder has a legal right to be, such as in their own home.

You may take photos, or record video and audio. Courts have held that wiretap laws, which generally protect private conversations, do not prohibit civilians from audio recording law enforcement. That’s because officers exercising their official duties, particularly in public, do not have a reasonable expectation of privacy. Neither do civilians in public places who speak to law enforcement in a manner audible to passersby.

What are some limitations on the right to record law enforcement?

Courts have been clear that behavior that obstructs or interferes with effective law enforcement or the protection of public safety is not protected. Officers can't order you to move because you are recording, but they may order you to move for public safety reasons even if you are recording.

If the law enforcement officer is off-duty or is in a private space that you don’t also have a right to be in, your right to record the officer may be limited. For example, a Los Angeles jury in 2026 found two women guilty of felony stalking after they followed an ICE agent to his home and livestreamed the pursuit.

What are some other considerations when recording officers?

Even if you believe you are appropriately exercising your First Amendment right to record law enforcement, officers may nevertheless escalate the situation and/or retaliate against you. Below are some things to keep in mind.

  • Stay calm and courteous.
  • If you are a bystander, stand at a safe distance from the scene that you are recording. But note that officers may approach and confront you, closing that distance in an effort to accuse you of interfering with and possibly also assaulting a federal officer.
  • Be alert and mindful of the possibility that officers may illegally retaliate against you in a number of ways, including arrest, destruction of your device, and bodily harm. They may also try to retaliate by harming the person being arrested. 
  • Consider the sensitive nature of recording in the context of an arrest. For example, the person being arrested or their loved ones may be concerned about exposing their immigration status, so think about obtaining consent or blurring out faces in any version you publish to focus on ICE/CBP conduct (while still retaining the original video). 
  • Law enforcement may not search your cell phone or other device without a warrant based on probable cause from a judge, even if you are under arrest. Thus, you may refuse a request from an officer to review or delete what you recorded. You also may refuse to unlock your phone or provide your passcode.
What can I do to protect my footage?

How well protected your photos or video footage are depends on both the device and the way you’re recording. If you’re uploading video to a livestreaming service, it can save that video to the cloud if you enable that setting. But what if you want to protect your recordings  stored locally?

Modern smartphones generally protect data, including videos, using encryption. This means if your phone is locked and protected by a strong passphrase, it is more difficult for an officer to delete what you’ve stored on the device. Removing biometrics such as face and fingerprint unlock can protect your device contents further. You can check your settings by following the steps in our Surveillance Self-Defense guides (see below) to ensure device encryption is turned on.

Want more information?
  • Read more about your right to record law enforcement: https://www.eff.org/issues/right-record
  • Read EFF’s Surveillance Self-Defense technical guide: https://ssd.eff.org
Sophia Cope

🏃 Fitness Tracker Privacy Fails | EFFector 38.14

1 week ago

Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies that make fitness trackers doing to protect our sensitive data from prying eyes? A lot less than they could be, it turns out. We're explaining what companies can do to protect your health data, and more, with our EFFector newsletter

JOIN OUR NEWSLETTER

For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers the rapid rise of police drone programs, a disappointing ruling on electronic device searches at the U.S. border, and how fitness trackers are falling down when it comes to protecting our health data.

Prefer to listen in? EFFector is now available on all major podcast platforms. This time, we're chatting with EFF Senior Security and Privacy Activist Thorin Klosowski about the health fitness tracker landscape and your privacy. You can find the episode and subscribe on your podcast platform of choice:

%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F8cabd912-722d-436b-a498-815da45f01bf%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

Privacy info. This embed will serve content from simplecast.com

   

Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!

Christian Romero

San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing

1 week ago

The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, collate, and store as much of our personal data as possible, and then monetize it through use and sale. When it comes to surveillance pricing, that looks like corporations offering the same product to two different people at two different prices, based on harvested personal information. That's why EFF supports A.B. 2654, authored by Assemblymember Chris Ward, which bans this harmful practice. 

As an organization based in San Francisco, EFF was proud to learn that the San Francisco Board of Supervisors had also introduced a resolution to similarly support the legislation. However,  we were disappointed to learn the San Francisco Board of Supervisors has since stalled a vote on the resolution stating their own support for A.B. 2654 after receiving an email from the San Francisco Chamber of Commerce criticizing the bill using well-worn and debunked concerns. We’ve sent the Supervisors a letter asking them to reconsider.

Banning surveillance pricing would be good for consumers. The FTC has found that companies will set higher prices based on personal information. “For instance,” the FTC found last year, “if a consumer is profiled as a new parent, the consumer may intentionally be shown higher-priced baby thermometers on the first page of their in-app search results, based on their residential zip code and time of purchase.” Let's say that again: the U.S. government has found that companies may seek to use surveillance pricing to charge parents searching for a thermometer in the middle of the night more money in a time of need.

Privacy is a human right, not something that people should understand as a currency to give away or protect based on how it will impact the price of groceries. EFF has long opposed pay-for-privacy schemes, in which a company charges a higher price to a customer who refuses to submit to processing of their personal data. Surveillance pricing is another version of that practice. You should never have to worry that your privacy rights depend on how much you make.

At a time when prices for everyday goods continue to climb, some surveillance pricing defenders note that using personal information could lead to lower prices for some consumers. Yet some recent studies indicate there will be losers and winners  based on factors such as whether a consumer is willing or able to switch products. Who loses or wins also will turn on the accuracy of the underlying data – yet surveillance pricing is often based on false information.

That said, even if surveillance pricing has the capability to lead to lower prices (which it often doesn't) we oppose it as just another way that corporations try to make customers pay for their privacy.

The San Francisco Chamber of Commerce’s concerns are fully addressed in the text of A.B. 2654. The Chamber raises questions about how businesses will comply with the law. But the bill is quite clear: “a retailer shall not engage in surveillance pricing.” It also has a clear definition of what “surveillance pricing” is. The banned practice is defined as: “[i] a customized price for a good for a specific consumer or group of consumers, [ii] based, in whole or in part, on personally identifiable information collected through electronic surveillance,” including if that information is “acquired from a third party.” In other words, “surveillance pricing” is a customized price based on personal information.

The SF  Chamber’s letter also asks about the bill's “treatment of discounts and loyalty programs.” In this way, too, A.B. 2654 is quite clear. The bill includes three broad carveouts that ensure it doesn't disrupt loyalty programs and discounts:

  • First, for price differences “based solely on costs associated with providing the good to different consumers.”
  • Second, for a discount offered to a consumer who is taking steps to terminate a service.
  • Third, for a discount, conspicuously posted on a retailer’s website, that is uniformly available based on (1) criteria anyone can meet, such as signing up for a mailing list, (2) membership in a broadly defined group, such as seniors, or (3) participation in a loyalty program.

An opt-in senior discount to the movies is not the problem. The systematic collection of all of our personal information to determine whether someone is a senior and if so whether they should pay more or less for that matinee is. 

As we said in our blog post outlining our support for this bill:

Surveillance pricing is very similar to online behavioral advertising, a business practice that EFF urges governments to ban. Both practices incentivize all businesses to collect as much of our personal data as possible, in order to later monetize it. Both practices lead some businesses to collate and store our data into dossiers about us for later use. Both practices use these surveillance-based dossiers to manipulate and limit our economic choices, by altering the advertisements and prices we see online.

We urge the San Francisco Board of Supervisors to join the coalition of groups that support A.B. 2564, and stand against companies mining our personal information to charge us different prices for the same thing. 

You can read our letter to the Supervisors here.

Matthew Guariglia

Why Are Gay Bars Building Databases of Their Patrons?

1 week 1 day ago

Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition.

A broader privacy concern also deserves scrutiny. For years, PatronScan has marketed itself not just as an ID-verification tool, but as a system that allows bars and clubs to identify patrons, keep records about them, and share information across venues. As one news article published in 2019 documented, PatronScan built a network that allowed participating bars to flag patrons and share information about them with other establishments. 

And in California, it’s not at all clear how PatronScan’s business model of scanning IDs and sharing the information from those scans with other bars comports with the law. California’s ID privacy law, which was amended in 2018 to add ID “scans,” states that no businesses shall “retain or use” any information from a scanned ID card except for limited purposes such as to verify age, comply with a legal requirement, or prevent fraud. 

A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database.

Californians should be deeply concerned about businesses that collect information from government-issued IDs and use it to build databases about where people go, whom they associate with, and whether they should be allowed into other public gathering places. That concern is especially strong in LGBTQ+ spaces, which have long served as refuges for people to go without being tracked, monitored, or put on lists. 

We reached out to Patronscan with questions regarding their practices and their views on California ID law. They referred us to their published FAQ question “Is Patronscan privacy compliant in California?” which claims that the use of Patronscan kiosks is legal in California. They also said “Patronscan does not do facial recognition in North America, or any kind of automated analysis of the ID or the live photo image.” 

The California Legislature Has Investigated PatronScan’s Business Model 

In 2018, the California Legislature published bill analyses (on that year's AB 2769) that went into detail about PatronScan’s business. Reviewing PatronScan's own materials, the California Senate Judiciary Committee found that the company had collected and retained information on 561,087 customers in Sacramento alone during the first five months of 2018—a remarkable figure for a city whose population had only recently topped 500,000.

Lawmakers also found that at that time, PatronScan retained information for at least 90 days or longer in some cases, shared information among participating bars, and maintained bans that lasted an average of more than 19 years. A PatronScan “Public Safety Report” used 10,000 scans collected on a single day to report on “where customers live, how far they have traveled, and how many different venues the customers patronized.” 

This was not simply checking IDs at the door. PatronScan was building a database. 

An immigrants’ rights group, the Coalition for Human Immigrant Rights (CHIRLA), wrote about its concern at the time with these growing ID databases, saying that “placing individuals on a database that labels them a "threat to public safety" has “significant immigration consequences that could lead to deportation, revoking of current status, or denial of future immigration relief.” 

Today, Patronscan states that it retains personal information about all customers for 21 days, and about flagged customers for up to five years. This includes the customer’s name, date of birth, photograph, gender, and zip code. It also includes the dates and times that the customer entered particular bars. Such databases are a grave privacy threat. Personal data is routinely stolen by thieves, misused by a company’s employees, seized by government agencies, and diverted to new purposes by a company’s executives. 

California Law Still Bans ID-Scan Databases, And Bars Should Follow That Law

In 2018, California lawmakers closed what they viewed as a loophole. Existing law already prohibited businesses from retaining or using information obtained when they “swiped” a driver's license, except for the narrow purposes of legal requirements (like a judicial warrant) or “preventing fraud, abuse, or material misrepresentation.” 

After reviewing companies like PatronScan, the Legislature amended the law to make clear that the same restrictions that apply to businesses that “swipe” ID cards also apply when those IDs are “scanned.” PatronScan opposed that change, arguing it wanted to preserve the ability to share information among bars so participating venues could decide whether to admit patrons.

The bill became law anyway. Yet PatronScan continues to market and sell a system that apparently retains information from scanned IDs, and allows participating venues to flag patrons and share information across its network. 

At a minimum, that raises serious questions about how those practices fit with California's existing ID privacy law. Bar and nightlife venue owners who utilize PatronScan should think twice about its effects on their customers, and consider going back to standard, visual ID checks. These physical checks have been effective at keeping underage patrons out of 21-and-over venues for decades, and don’t present the serious privacy dangers of creating a private database of bar patrons. 

For venues serving vulnerable communities like immigrants or the LGBTQ+ community, the stakes of using this technology are even higher. It’s disappointing and alarming to see some of California’s more well-known LGBTQ+ nightlife spots instead lining up as PatronScan’s early adopters. A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. These businesses should reject PatronScan, return to the standard ID checks that every other bar has been able to utilize, and prove to their customers that their privacy and security still matters. 

Joe Mullin

Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!

1 week 2 days ago

EFF’s first EFFecting Change livestream was all the way back in July of 2024. Maybe you've caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your daily commute! Either way, if you want to stay on top of these monthly conversations, you can now subscribe to our new podcast feed for EFFecting Change—starting with our conversation on the Right to Repair movement with Adam Savage and iFixit CEO Kyle Wiens:

%3Ciframe%20height%3D%22200px%22%20width%3D%22100%25%22%20frameborder%3D%22no%22%20scrolling%3D%22no%22%20seamless%3D%22%22%20src%3D%22https%3A%2F%2Fplayer.simplecast.com%2F1ffaef7d-fd63-4133-8f3e-c28a98ff9f60%3Fdark%3Dfalse%22%20allow%3D%22autoplay%22%3E%3C%2Fiframe%3E Privacy info. This embed will serve content from simplecast.com

   

This new feed will include the full conversations with our panelists, posted after the livestream ends. Subscribe today to get each stream straight to your podcast player of choice. You can also find other podcasts by EFF at eff.org/podcast.

And mark your calendar for the next EFFecting Change livestream: Who the Machine Serves. EFF Executive Director Nicole Ozer and Cory Doctorow will be having a conversation on AI, tackling what needs to happen now to ensure AI actually works for everyone, not just those in power. RSVP today!

Want to ensure EFF can keep inviting expert panelists to chat about the future of technology and how it impacts you? Support our work today.

Donate to EFF

Christian Romero

Farmers Are Getting Control Of Their Equipment Back

1 week 5 days ago

For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few "authorized" repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major win for farmers and right to repair advocates, John Deere must soon provide farmers with not just the tools and resources to finally repair their own John Deere equipment, but also access to future updates for said equipment.

In 2025, the Federal Trade Commission (FTC) brought a suit against farm equipment manufacturer John Deere, alleging John Deere used their control over equipment repair tools and resources to limit the ability of farmers and independent repair providers (IRPs) to repair John Deere equipment. Earlier this month, John Deere reached a settlement with the FTC in which they will immediately make available a tranche of repair resources, then continue to make further resources available until the end of the year. Five states joined the FTC in this suit, and over the next 10 years these states will work alongside the FTC to ensure John Deere complies with this settlement. 

It is worth noting there is a second, farmer-initiated antitrust lawsuit against John Deere, also concerning a farmer’s right to repair their own equipment. In April, John Deere agreed to a $99 million settlement in that case, which also includes right to repair provisions.

This fight is just one example of how, as machines become increasingly computerized, companies like John Deere restrict your ability to repair machines behind software subject to legal regimes that don’t just lock down repair, but make unauthorized repair a potential criminal offense. 

John Deere’s market dominance in farm equipment led to an extraordinary power over access to the tools and resources of repair. John Deere actively restricted who had access to repair tools, and monopolized who could do the repair. This revenue stream—and control of it—is built into the business models of a lot of the technology we buy today. It also encourages companies to move away from the kinds of devices that can be easily fixed at home to ones that offer bells and whistles no one wants but makes repair difficult—like app-enabled toasters. 

This whole saga with John Deere has been an exemplar of the greater need for right to repair laws, policy, and enforcement.  There was a time when you bought a tractor and with some know-how and a manual could fix it yourself. It is easy to envision why someone with John Deere farm equipment might find it inconvenient to wait for John Deere approved repairpeople to come and fix any broken equipment. Especially when it meant waiting for days or weeks. Especially if it meant their crop was withering on the vine. This settlement will help ensure this is no longer the case. 

But it’s not just about farm equipment; If you can’t fix it, you don’t own it. While some might feel more willing to agree they “shouldn’t” futz with laptops or smartphone, it still stands that — whether it’s farm equipment, a car, a laptop, or even your phone — if you legally cannot fix it yourself, if you must go hat in hand to an “approved provider,” you are at the mercy of a corporation. It is why EFF continues to support right to repair laws that ensure people truly own what they buy. And it is why EFF continues to fight for exemptions to the law that makes it most difficult to tinker and repair your own devices.

Chao Liu

Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country

1 week 5 days ago

Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial surveillance and data collection even in areas patrol officers typically can't reach.

As of February 2026, over 1,000 public safety agencies—including police, fire, and other emergency management agencies—had received Federal Aviation Administration (FAA) waivers needed to automate drone operations and launch a DFR program, according to a recent Freedom of Information Act (FOIA) release listing agencies that have obtained Part 91 waivers since the FAA streamlined and sped up the process in April 2025.

The changes led to a massive increase in the number of waivers issued. Only 976 DFR waivers had been granted since the first DFR program launched in 2018 through April 2025, according to an FAA representative. The agency issued more waivers between April 2025 and February 2026 than it had in the previous seven years combined.

A map illustrating the locations of police departments and other public safety agencies that have received Part 91 waivers, making it possible for them to launch drone-as-first-responder programs. (This map image links to Google Maps, which is governed by Google's privacy policy)

The new FAA process for waivers and the rush of police departments to obtain them signifies a shift in law enforcement's use of drones: from human-operated aerial surveillance to AI-based autonomous drone use. 

Typically, a drone operator is only permitted to fly in areas that can still be seen by the pilot, and that drone pilot needs to be certified under FAA Part 107. To fly drones “Beyond Visual Line of Sight” (BVLOS) requires additional approval from the FAA, as do flights above 200 feet, due to the risk of colliding with planes and other aircrafts. Without such approval, an officer could not pilot a drone from a desk inside a building and fly it to a call across the city because they could not possibly have line of sight on the drone. 

FAA rules for police drones also required a human operator to manually fly the device to a scene, but DFR technology has become a more common and more automated police technology. DFR programs increasingly rely on artificial intelligence to automate drone flights from launchpads placed around the city, often atop municipal buildings, and make it possible for one drone operator to “fly” multiple devices at once. Though not every police department that has received BVLOS has launched a DFR program yet, by going through this process, every department on this list has signified it has strong enough interest to clear the necessary regulatory hurdles.

Police departments and the companies that sell DFR equipment claim that these drones make it easier for officers to establish “situational awareness” of a scene before they arrive. Early drone adoption centered on similar claims, particularly related to high-risk situations like vehicular accidents or incidents involving an armed suspect. However, these kinds of situations may make up only a small portion of deployments, which often occur in response to low-risk calls for service related to unhoused people, mental health concerns, and loud music, as a Government Technology analysis of the system in Chula Vista, California, found. 

DFR programs have become important sources of revenue for companies like Flock Safety and Axon, the latter of which reported that its DFR platform has become one of the company’s fastest growing sectors. Axon is also known for products like the TASER and the Fusus camera system that lets police integrate viewing of public and private cameras. 

Footage from drone flights is streamed back to a police office, and it can be stored, shared, and analyzed like other video. Turning drone footage into fodder for automated license plate reader (ALPR) networks, for example, requires very little additional software, and Flock Safety was quietly able to turn its drones into “flying ALPRs” last year

The normalization of police DFR programs jeopardizes privacy in communities across the country. As flying cameras, drones can capture footage from areas typically inaccessible to a casual patrol officer—backyards, roofs, through windows—at distances that leave subjects of surveillance completely unaware of the spy in the sky. A recent leak of drone footage from the San Francisco Police Department illustrated the ease with which surreptitious drone flights could observe innocent individuals for minutes without them realizing it. EFF's Atlas of Surveillance contains a list of police departments with drones, including those with DFR programs.

While daytime DFR use grows, police departments are exploring other ways to expand overhead surveillance. In October 2024, the Campbell Police Department in California announced it had received the first FAA approval for BVLOS operations at night, claiming it was the “first to incorporate radar technology with electro-optical sensors to enhance airspace monitoring, enabling a single remote pilot to safely deploy drones both day and night.”  

As communities consider drone use, it’s crucial that they have a say in whether the program is acquired at all, not just how it's run once purchased. Throughout the process, police should be transparent with the community and comply with local regulations about its adoption.

Many cities provide portals that log the flight paths and reasons for each drone flight, often in real time, an important transparency practice. In California, under AB 481, police departments are required to provide advance notice of intent to acquire drones, establish policies before they’re procured, and provide annual updates on their uses—giving communities and city councils the opportunity, before any contract is signed, to weigh in or object to the acquisition itself. 

For police departments and communities considering drone use, clear policies on appropriate use, transparency around deployment, and regular re-evaluation—including the choice to discontinue a program that isn't working—are all vital for protecting people’s privacy and security. 

Beryl Lipton
Checked
1 hour 38 minutes ago
EFF's Deeplinks Blog: Noteworthy news from around the internet
Subscribe to EFF update feed