Eight days, twelve stories. Here is the ledger.
The cameras got closer
Live facial recognition went into the London Underground. British Transport Police deployed at Victoria station on 11 August, the first use inside a Tube station, running NEC NeoFace M40 against a wanted-persons watchlist, rotating between stations until November. The legal defence is that non-matches are deleted immediately — which is true, and which describes what happens after every passing face has been converted to a biometric template and searched. Full analysis.
Flock Safety rewrote its own ALPR rules. Default retention 30 days → 7, mandatory audit tooling, case numbers required on all searches by end of 2026, automatic lockouts for abnormal behaviour. It follows at least fifty officers accused of using the plate network to stalk people they knew, including a North Carolina officer arrested this month after 31 searches on her boyfriend’s ex-wife. Every change is an improvement. The word “warrant” appears nowhere. Full analysis.
800 pubs pushed back on wearables. J D Wetherspoon asked customers across its UK estate to switch off Meta smart glasses cameras, calling them enablers of “surreptitious surveillance,” joining Soho House and ATG Theatres. Unenforceable by design — you cannot tell when they are recording, which is the complaint — and still the most significant movement in wearable camera norms since Google Glass. Full analysis.
The government kept buying
ICE withdrew a $125 million sole-source award to Thomson Reuters for CLEAR-based investigative analytics, after fifty-plus vendors responded to the original competitive notice and the requirement was rewritten around one company. A DHS forecast dated 10 August relists it as competitive, above $100 million, with a solicitation expected 24 August. The proposed capability: continuous tracking of up to one million individuals or entities with event-driven alerts and risk scoring.
In the same fortnight, ICE moved on $6.7 million for LexisNexis records — 82 billion data points — with contract language requiring API integration with Palantir and PenLink, an AI-driven identification system, and bulk facial recognition, in service of spotting fraud “before crime and fraud can materialize.” ICE arrested over 51,000 people in July. The procurement got fairer. The surveillance got bigger. Full analysis.
Somebody finally mapped the pipe. DecryptAds launched 12 August with 284 million ad supply-chain records, built by crawling the industry’s own public ads.txt and sellers.json files and joining the graph. For the first time an outsider can see which brokers sit in a given app’s supply chain — including the ones that harvest the real-time bidding stream and sell location traces to ICE and CBP without a warrant. Free, queryable, and roughly a decade overdue. Full analysis.
Nobody’s own systems were breached
The vendor was the perimeter, five times over. Framework told all customers their names, emails, phones, and home addresses were taken — via a third-party business intelligence vendor. Trezor notified ~14,000 hardware wallet buyers across seven countries that their names and shipping addresses are out, via ShipMonk. Ceva Logistics leaked customers of ING, Ajax FC, De Bijenkorf, Bol, Ace & Tate, and Valve simultaneously. Wesco: 2.6 million records. Unlimited Technology Systems: 3.8 million people, SSNs, driver’s licence scans, and diagnoses — from an October 2025 incident notified 1 July 2026, roughly eight months late.
Note who Trezor’s customers are: a verified list of names and home addresses of people who recently bought a device for storing bearer assets. That is not a marketing list. Full analysis.
And the state-run version. The ICO reprimanded ACRO Criminal Records Office after attackers spent seven months inside its website and CMS — with three intrusions undetected across roughly two years. The public-facing portal was running the same software version deployed in September 2019, unpatched for nearly four years. Exposed: passport and driving licence details, National Insurance numbers, bank details, biometrics, and criminal offence data for up to ten thousand people. ACRO could not determine whether the data actually left. The penalty is a letter. Full analysis.
Regulators counted, and Brussels moved the goalposts
Washington published its first Data Privacy Report on 14 August. In 2025: 209 breaches, 8 million-plus residents affected in a state of about 8 million, and over 80% of breaches exposed Social Security numbers. In a survey of 700+ residents across 26 counties, 83% said they had little or no control over who accesses their information. Headline recommendation: a data broker registry — the same plumbing that made California’s DROP possible. Full analysis.
Chat Control 1.0 came back until April 2028. Member states approved the temporary CSAM-scanning derogation in early August, after a July Parliament vote in which 314 MEPs voted to reject it — a majority of votes cast, but short of the 361 absolute majority a second reading requires. Voluntary scanning of unencrypted messages resumes. Signal and WhatsApp contents are untouched; the mandatory-detection fight is still open.
And the AI Act’s flagship date was moved five days before it landed. The Digital Omnibus entered into force 27 July, pushing Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. What did take effect on 2 August: Article 50 transparency, GPAI enforcement powers, and the full penalty regime up to 7% of global turnover. The Article 5 prohibitions — including on real-time remote biometric identification in public — have been live since February 2025, which is worth holding next to the Victoria station deployment in the same week. Full analysis.
The two AI stories
Google bought a dead airline’s corpus for $10 million. A court filing dated 14 August revealed Google won Spirit Airlines’ bankruptcy auction, outbidding Mercor’s $7.5 million, for: 100 million emails, 500 million Teams chats, 7.5 billion passenger transaction records back to 2008, 175,000 employee records back to 1986, and over 30 million recorded customer service calls. Customer and loyalty databases were excluded. Everything else will be “rigorously scrubbed” of personal information by a third party that Google selected and paid. A voice recording is a biometric identifier, and you cannot redact a voice from a recording of a voice. Full analysis.
OpenAI started guessing everyone’s age. ChatGPT for Teens began rolling out 18 August for 13–17 year-olds, with content restrictions, break reminders, and — the best-designed part — a ban on romantic language and on the model claiming feelings or consciousness. Users are enrolled by self-declaration or by an age-prediction system using “behavioural and account-level signals.” Classifying minors requires assessing everyone. OpenAI has not published the classifier’s accuracy, and the remedy for a false positive is uploading government ID. Full analysis.
Meanwhile the checks themselves are collapsing. A convincing forged ID now costs about $15 and half an hour. GenAI document fraud detections are up 90% year over year. The DOJ’s OnlyFake case involved 10,000+ fake IDs across 50 states and 56 countries. Australia’s regulator found more than 8 in 10 under-16s still on social media a year into its ban. Legislatures are mandating document upload at exactly the moment document upload stopped working. Full analysis.
The pattern
Almost every story this week is the same story told in a different vocabulary: a check was performed, and the check did not mean what it was supposed to mean.
BTP checked ten thousand faces and deleted the results, and called that not collecting data. Flock added case numbers to searches and called that accountability, without ever requiring a judge. ACRO ran a criminal records portal that passed whatever internal assurance it had for four years without a patch. Google’s anonymiser will certify a corpus clean for the party that hired it. OpenAI’s classifier will assess your age with an accuracy nobody has published. An age gate will check an ID that cost fifteen dollars to generate.
In each case the verification exists, it is documented, it produces an artefact that satisfies an auditor — and it does not do the thing its existence implies. That is not hypocrisy. It is what happens when the measurable proxy for a protection becomes the protection, and the incentive to make the proxy real disappears the moment the proxy is accepted.
The one genuine exception this week was DecryptAds — because it did not perform a check. It published the underlying data and let anyone else run their own.
What to do this week
-
Disable your advertising ID. Android: Settings → Privacy → Ads → Delete advertising ID. iOS: Settings → Privacy & Security → Tracking → off. This is the single highest-leverage privacy action available on a phone, it takes thirty seconds, and it cuts the supply line that ends at a government contract.
-
Freeze your credit at all three bureaus. Four out of five breaches expose Social Security numbers. Monitoring tells you after; a freeze stops it. It is free.
-
Turn off ChatGPT chat history and model training. Settings → Data Controls. Applies whatever age the classifier thinks you are.
-
Search one privacy policy for “sale of assets.” Any one. That clause is what governs your data when the company dies, and Google just paid $10 million to demonstrate it.
-
If you obtained an ACRO police certificate, place a CIFAS Protective Registration. About £30 for two years. Your passport and licence numbers may be in circulation and nobody can tell you whether they are.
-
Find out whether your city has ALPR cameras, and go to the council meeting. Municipal procurement is the only stage of the surveillance pipeline where a member of the public gets a vote, and these contracts routinely pass on consent agendas with no discussion.
-
California residents: use DROP. It has been live for brokers since 1 August and it remains the strongest consumer privacy mechanism in the country. One request, every registered broker.



