Two weeks, thirteen stories, and an unusually clean split between things that got better and things that got worse. Here is the ledger.

The ledger: things that got better

California switched on a delete button that 600 companies have to answer. As of August 1, every data broker registered in California must check the state’s DROP platform at least once every 45 days and process deletion requests within 45 days. More than 300,000 Californians had already filed before the obligation attached. Non-compliance runs $200 per consumer, per day — arithmetic that makes ignoring the platform a bet-the-company decision rather than a line item. This is the first American privacy mechanism designed to eliminate friction rather than create another right nobody exercises. Full analysis

State attorneys general are now the enforcement engine, and it is working. Pennsylvania sued TikTok on a theory that routes around Section 230 — that the company misrepresented its own safeguards to obtain a 13+ age rating. Utah joined a federal suit against Hims & Hers. Insurers report the frequency of privacy rights claims in H1 2026 doubled year over year. Twenty states have comprehensive laws, most with $7,500–$10,000 per-violation penalties, and nine states’ cure periods have now lapsed. Full analysis

Microsoft patched the passkey chain before it mattered. The worst finding in SpecterOps’s 20+ technique Pass-the-Passkey research combined Windows writing complete WebAuthn assertions to an event log with Entra ID skipping anti-replay checks. CVE-2026-34348 was fixed in July 2026 Windows updates. No FIDO2 cryptography was broken and no private keys were extracted. Passkeys remain the best authentication available to you. Full analysis

The ledger: things that got worse

The Senate advanced four bills that each require knowing every user’s age. On August 5, Commerce moved KOSA, the SCREEN Act, the Youth AI Privacy Act (S. 4199), and the CHATBOT Act. Different sponsors, different targets, one shared mechanism: to apply rules to minors you must assess everyone. EFF’s summary — more collection, more surveillance, less privacy, for users of all ages. Similar laws in California, Texas, and Arkansas have been substantially enjoined on First Amendment grounds. Full analysis

The best data restriction in Congress is attached to the wrong noun. The Youth AI Privacy Act would bar training on chat logs or disclosing them to other firms — the single most important restriction anyone has proposed on conversational AI. It applies only to minors, which forces the age gate, and it carves out collection of a known minor’s data to address undefined “harm to users.” Delete the age qualifier and it is a good bill. Full analysis

The EU AI Act’s surveillance rules slipped sixteen months. August 2, 2026 brought high-risk obligations for Annex I safety components and a €35M / 7% of turnover penalty ceiling. The Annex III categories that actually matter — biometrics, remote biometric identification, emotion recognition, employment, education, migration and border control — now apply from December 2, 2027. The prohibitions remain in force and the GDPR still applies in full; a layer was removed, not the floor. Full analysis

ICE outsourced finding people to the commercial data economy. 13 private companies, open-ended contracts issued December 2025 worth up to $1.2 billion over two years, each vendor eligible for up to 50,000 cases per month. Contractors are handed names and told to exhaust all available technology — data brokers, online research, AI, facial recognition — before escalating to physical surveillance. Estimated reach: up to 1.5 million people. Washington and Maryland have restricted the supply side; forty-eight states have not. Full analysis

Four ad libraries ship your precise location by default. EFF’s investigation named BidMachine, InMobi, Verve’s HyBid, and Huawei’s Petal Ads. Android grants permissions to a process, not to a library, so an ad SDK inherits location access granted for a map feature — and the app’s consent flow and Play Data safety label may say nothing about it, because the developer often doesn’t know either. This is the supply chain that fed the ICE contracts, the priest outing, and the tracking of military personnel. Full analysis

Courts decided nobody is liable for the trackers on your insurer’s site. A federal judge dismissed claims against Blue Shield of California over Google Analytics and the Meta Pixel, reasoning that only the party that intercepts — Google and Meta — can be liable under the wiretapping theory. Weeks later an Illinois judge held that searching for doctors and symptoms on Blue Cross Blue Shield’s site is not protected health information. Both are defensible readings of statutes written before the conduct existed. Full analysis

The custodians got breached. ExfilSquad took names, organisations, and email addresses for 100,000+ UK police officers and criminal justice professionals from the Police National Legal Database, plus data on public “Ask the Police” users. Switzerland’s federal IT office (BIT) found its SharePoint servers compromised on July 28 — roughly 200 accounts, officially credentials only. Herbert Smith Freehills Kramer and Taft Stettinius & Hollister filed breach notices, extending a wave that has hit dozens of US law firms in 2026. Full analysis

The FTC proposed policing what AI models decline to say. The suppression of accuracy policy statement, issued July 1 under Executive Order 14365 and closed for comment July 31, treats steering a model away from the most accurate answer as a potential Section 5 deception — and is explicitly tasked with addressing conflicts with state laws requiring alterations to AI outputs. EFF has asked for withdrawal. Full analysis

And Vegas explained why the age gate can’t work. Across Black Hat (Aug 1–6) and DEF CON 34 (Aug 6–9), EFF argued age verification laws put everyone at risk of security lapses, breaches, and misuse — a systems argument that holds even if you disagree about civil liberties, because a leaked government ID tied to a browsing record is not revocable. Also: adversarial patterns that defeat surveillance camera detection, and another round of connected-device research nobody wants to give and everyone should hear. Full analysis

Do these five things this week

Ranked by how much they actually change, not by how easy they are.

  1. If you live in California, file a DROP request at privacy.ca.gov. Ten minutes, one form, 600+ data brokers legally obligated to delete you. File for everyone in your household who won’t do it themselves. This is the single highest-leverage privacy action available to any American right now, and it expires from nobody’s calendar — but the brokers are processing queues now.

  2. Fix your Android location permissions tonight. Settings → Location → App location permissions. Set everything that isn’t a map to “Ask every time” or Approximate. Then Settings → Privacy → Ads → Delete advertising ID. This directly severs the pipeline described in the EFF SDK investigation — the same pipeline feeding the ICE contracts.

  3. Enable passkeys everywhere they’re offered, and remove the weak fallbacks. A passkey on an account that still allows SMS reset is protected at the strength of SMS. Patch your OS while you’re at it — the worst finding in this week’s passkey research was already fixed in July.

  4. File a complaint with your state attorney general, not just the company. AG offices open investigations on complaint volume, and almost nobody files. In an enforcement landscape run by fifty elected officials, this is the closest thing to a vote you have.

  5. Do not upload a government ID to view lawful content. If the four Senate bills become law you will be asked to, repeatedly, by companies whose core competence is not identity security. That record is permanent, it ties your identity to that visit, and it sits at a vendor you didn’t choose. Decide deliberately every single time.

The pattern

Everything in the worse column failed at a seam.

An ad library inherits a permission granted to an app, because Android’s boundary is the process and not the dependency. A wiretapping statute reaches the party that intercepts but not the party that invited the interceptor. Windows logs an assertion that Entra ID forgets to check twice. A federal statute protects minors, so every adult must prove they aren’t one. The AI Act’s substantive rules arrive on schedule while the categories that matter slip to a date buried in an amendment nobody read.

None of these are failures of the components. Every component works as designed. They fail where designs meet — where a permission model meets a business model, where a 1996 statute meets a 2026 script, where a good provision meets the wrong scope.

The one thing in the better column that genuinely worked, worked for the opposite reason. DROP didn’t add a right. It removed a seam — the gap between having a deletion right and being able to exercise it against 600 companies whose names you don’t know. One registry, one form, one obligation.

That is the whole design lesson, and it is available to any legislature that wants to copy it. Twenty states have comprehensive privacy laws. One of them built the button.