Microsoft commits to sweeping AI privacy rules for students. Will other tech giants follow?

Millions of students every day turn to AI chatbots for help with schoolwork, emotional support and personal advice — often unaware of where their conversations and other personal information end up.

How that data is used — and schools’ role in protecting it — is a growing concern for educators, parents and kids as artificial intelligence becomes a ubiquitous part of the school day, embedded in many of the classroom tools students are required to use.

As the school year started, the country’s two largest school districts, New York City and Los Angeles, announced they were putting the brakes on student use of AI for one year, as they study how to best incorporate the technology into education.

In response to a growing AI and screentime backlash, Microsoft announced last week it had agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers, the country’s second-largest teachers union.

The safety provisions in the agreement are meaningful, but the standards will only be effective if all AI companies, especially the tech giants, sign on, said Josh Golin, executive director of online safety nonprofit Fairplay. He said the agreement sidesteps the question of whether AI products even belong in classrooms, or at what age they should be introduced.

“I worry that a high-profile framework like this will be misunderstood and schools will think, ‘If they’re doing a good job on data privacy and safety, then that means we should be using the tool,’” Golin said.

The AFT said the agreement, which is legally binding and requires third-party audits for compliance, could set an industry standard. Two other leading AI companies, OpenAI and Anthropic, said they also were discussing safety and privacy pacts with the AFT. But Google, the dominant provider of education technology for America’s schools, has not said whether it plans to offer similar protections.

Keep reading

Florida’s Attorney General Sues Netflix For Allegedly Harvesting, Selling Children’s Data

Attorney General James Uthmeier is seeking billions in damages from the company and asked the judge to order Netflix to stop its alleged deceptive practices.

“Parents were told kids’ profiles were a child’s own space – safe, separate, great for kids,” Uthmeier said in a news conference Wednesday.

“Families believed them. But behind the brand, Netflix built something different.”

In the lawsuitJill McLaughlin reporets for The Epoch Times,that Uthmeier claims Netflix offered an ad-free service that promised not to collect or sell data but began to track children and their profiles when it launched an advertising business in 2022.

The streaming service offers an under-12 profile option for children which promotes a non-advertising space, according to the state.

Uthmeier alleges Netflix violated the Florida Deceptive and Unfair Trade Practices Act and the state’s Digital Bill of Rights, including by selling sensitive personal data collected from known children without prior consent.

He seeks a permanent injunction, an order requiring Netflix to purge any deceptively collected data from Floridians, and an end to addictive designs that keep children watching on the platform, in addition to billions of dollars in civil and other monetary relief, he said.

“Parents, not streaming corporations, need to direct the upbringing of children,” Uthmeier said.

In the complaint, Uthmeier stated Netflix’s executive officer Reed Hastings told investors during a Jan. 22, 2020, earnings call the company’s model was not based on using customer data.

“We don’t collect anything, we’re really focused on just making our members happy and we’re not tied up on all that controversy around advertising,” Hastings said.

Hastings also said Netflix wasn’t interested in tracking customers’ locations or other things they were doing. “We want to be the safer spy where you can explore, you can get stimulated, have fun, enjoy, relax, and have none of the controversy around exploiting users with advertising,” Hastings said during the call.

The Netflix executive compared the company to Google, Facebook, and Amazon’s advertising models that used consumer data collection and targeting information, saying Netflix was “not controversial that way.”

Keep reading

Trump Says He Likes Flock Cameras for Law Enforcement – “I Sort of Like Them”

President Trump on Sunday told reporters that he likes the controversial license plate-reading Flock cameras on roads across the country. 

Concerns have been raised by Americans about the right to privacy and unwarranted surveillance on ordinary motorists, tracking their every move and storing the information in a database.

Several Republican lawmakers and state officials have also expressed opposition to the technology.

When asked about the cameras on Sunday, Trump said, “I sort of like them because of that,” noting that law enforcement uses them to apprehend suspects.

“I sort of like them because of that, because of law enforcement, but some people don’t,” Trump said.

“They think it’s an infringement, but I like them.”

Keep reading

Blanch’s DOJ to Investigate Your Private Information Being Given To Election Fraud Groups

Includes YOUR Social Security and Drivers’ License Numbers

The Department of Homeland Security first brought its concerns about this to the Justice Department in September 2025, when Pam Bondi was Attorney General.

More than a year later, Secretary Mullin, who replaced Kristi Noem, wrote to Attorney General Todd Blanche in a letter dated Wednesday, Sept. 2, 2026, that requests DOJ look into the matter. One year later…

What did Bondi do with this information?? But, I digress…

The same fraud machinery that selected a feeble old man, Joe Biden, over a highly capable candidate, is now setting up to seize the US Senate and House in the 2026 midterms.

Maria Bartiromo was handcuffed by Fox for trying to report on it. You will NOT hear this on any news channel.

(Might Maria Bartiromo become the next Press Secretary, replacing Levitt?)

Last Wednesday, the Department of Homeland Security referred possible violations of the Driver’s Privacy Protection Act to the DOJ. The issue is the transfer of millions of pieces of Americans’ sensitive personal information data, from their drivers’ records, to two hard left-wing groups, the Electronic Registration Information Center (ERIC) and the Chan Zuckerberg Foundation.

These two groups – ERIC and the Chan Zuckerberg Initiative (CZI) – have notorious involvement with election “irregularities”. I have written, repeatedly, about both, since 2021.

Just to refresh your memory, in 2020, CZI gave $350 million to a group called Center for Tech and Civic Life (CTCL), under the auspices of Covid protection for election officials and voters. All in all, less than 3% of the Zuckerberg millions was found to have been used for Covid-related protection; of course, exact numbers are difficult to figure, as the CZI is a private philanthropy.

CTCL was founded by former Obama acolytes. Anyone surprised?

The CZI money was termed, “Zuck Bucks”, and was accepted by election officials around the country. For example, Alan Hayes, Supervisor of Elections in Lake County, FL, took $106,000 of it. That’s a lot of Covid masks for his staff…

Twenty-eight states have now banned these “Zuck Bucks”, but it is really all for show. The election fraud criminals will pull a different stunt. Like your drivers’ license information…

In all, at least 25 states received payouts from Zuckerberg in 2020. The states remaining, were either considered “sure Left” or “hopeless”, I’d assume.

Keep reading

ID Verification Breach Exposes Millions of Sensitive Identity Documents

If you ever needed more proof that governments pressuring companies to collect ID data from customers or users is a bad idea, you only have to look at what happened this week. A dark-web service advertised on August 31 has been offering over 153 million scans of driver’s licenses, more than 10 million other identity cards, over 3 million travel documents and/or international IDs, and at least 579,000 medical cards.

The data apparently stems from a company hired to verify people’s identities. The service, called Nexus, was advertised on the Russian-language cybercrime forum Exploit.

Security researcher Brian Krebs found that a blank search on Nexus returned about 11.5 million result pages with roughly 15 results per page. This would support the claim that there were over 153 million license scans in the database, and the number increased by nearly 400,000 in 24 hours.

Nexus itself claimed to have “continuously exfiltrated new data for over a year into our private database” – but this is not verified and could be an advertising claim.

What Krebs was able to verify is that his own Virginia license was among those available on the site. He searched with permission for the licenses of more than a dozen friends and relatives; nine people whose records appeared said that the attached timestamps matched or closely tracked their travels.

In the case of Krebs and his mother, the timestamps corresponded to a June 2025 car rental from Hertz. Their records were created seconds apart, matching their account that they handed both licenses to the rental representative at the same time.

Krebs’s record contained three pairs of images showing the front and back of the license in visible light, infrared, and ultraviolet.

Privacy researcher Zach Edwards also found his license on Nexus. Its timestamp matched a trip to Las Vegas, where he had presented the document to TSA, the Aria hotel and the Planet13 dispensary. Edwards said the dispensary was the only one of the three places where he knew the license had been scanned.

Keep reading

Microsoft knows your entire browser history — and it can send it to the FBI

Virtual Private Networks are meant to shield your browsing history from all manner of prying eyes, including your internet service provider, your workplace or school, and even potential hackers. If you use a VPN with your Windows PC, though, I have some bad news: Microsoft has a full record of your browsing habits, and it can even report your activity to the FBI.

According to court documents released on July 1, a 19-year-old young man working with the cyber criminal group known as Scattered Spider was caught hacking into a computer system belonging to a luxury jewelry store. While inside, the hacker stole company data and demanded $8 million in cryptocurrency for ransom. Ultimately, the jewelry store kicked the hacker out of its system without paying the ransom, and the perpetrator was later arrested and charged.

It’s a simple case of conspiracy, digital intrusion, and fraud … but there’s a catch.

The hacker’s identity should have been hidden from the feds.

Keep reading

Homeland Advanced Recognition Technology: The Largest US Biometric Database You’ve Never Heard Of

After being troubled by delays and budget concerns for nearly a decade, the Homeland Advanced Recognition Technology (HART) program will become the US government’s largest biometric database when it launches in September. The program has also been plagued by privacy concerns raised by the Government Accountability Office (GAO), which has warned that HART has “gaps” in its privacy policies.

HART will be managed by the Department of Homeland Security (DHS) and will store and process biometric data such as digital fingerprints, iris scans, and faceprints that have been gathered by DHS and its various sub-agencies. According to DHS, government agencies may seek to access this data for national security reasons, law enforcement, immigration and border management, intelligence gathering, background investigations for national security positions, and certain positions of public trust.

While HART is set to complete “initial operating capability” in September 2026, the system is not scheduled to be fully completed until 2027. The system was originally announced in 2015 as a replacement for the legacy Automated Biometric Identification System (IDENT), which was originally developed in 1994 as a law enforcement system for collecting and processing biometric data from individuals apprehended by border security or immigration officials. In 2013, the DHS’ Office of Biometric Identity Management (OBIM) began plans to replace IDENT with HART. HART was set to become operational in December 2018 but was delayed numerous times due to budget concerns.

Since the initial announcement regarding the transition from IDENT to HART, the GAO and digital rights groups have raised concerns about the government upgrading and centralizing its repository of sensitive personal information of millions of Americas.

In February 2020, DHS published its original HART Privacy Impact Assessment to “assess and mitigate any potential privacy risks.” While the system wasn’t yet active, DHS said they “anticipated potential privacy risks associated with the privacy sensitive system” and “sought to proactively develop appropriate privacy safeguards to be implemented” throughout HART’s development.

In September 2023, the GAO released their own report detailing what it saw as “gaps” in privacy policies required by the Office of Management and Budget. The GAO said DHS implemented only five of twelve privacy requirements. GAO noted that the 2020 privacy impact assessment was “missing key information,” including on whose data will be stored in the system and the partners with whom the system will share the data.

The GAO report also said the HART program did not have “assurances that partners that provide information to the system will appropriately retain and dispose of personally identifiable information.” GAO concluded by stating that until DHS addressed these “privacy weaknesses,” there is no assurance that the personal data gathered on hundreds of millions of individuals will be “appropriately protected.”

In August 2024, DHS released an updated Privacy Impact Assessment for HART in an attempt to “clarify and address points raised by external oversight bodies.” The assessment provided answers to some of the questions posed by the 2023 GAO report, namely whose information will be stored and with whom it will be shared.

“HART will contain personally identifiable information, including biometric data and associated biographic information, on U.S. citizens, lawful permanent residents, and foreign nationals,” the assessment stated.

The report says biometric data held in HART may be shared with every agency of the DHS, including Customs and Border Protection (CBP), U.S. Immigration and Customs Enforcement (ICE), U.S. Secret Service (USSS), and the Transportation Security Administration (TSA), as well as other federal agencies such as the State Department, the Department of Justice (DOJ), and the Department of Defense (DOD). It also states that biometric data may be shared with “elements of the Intelligence Community (IC).”

Keep reading

DOJ: TikTok to pay $400M in settlement over suit alleging violation of children’s privacy law

The Department of Justice (DOJ) announced a $400 million settlement with TikTok over a lawsuit alleging the company violated the Children’s Online Privacy Protection Act (COPPA).

As part of the agreement with TikTok, its developer ByteDance and related entities, the DOJ said in a Friday press release that the social media giant will pay $300 million immediately and the additional $100 million when certain conditions are met regarding a previous legal dispute with Musical.ly, TikTok’s predecessor.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley Woodward Jr.

“The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations,” Woodward continued.

COPPA dictates that online services aimed at children must obtain parental consent before collecting personal information from users under 13 years old.

The suit alleging that TikTok violated this law was filed by the DOJ in 2024, though the Justice Department asserted that the social media company had experienced immense internal changes since that time.

“Since the Justice Department filed its complaint in 2024, TikTok has undergone significant changes to its ownership, management, compliance functions, and privacy practices,” the release stated.

“The company has implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight,” it continued.

In January of this year, TikTok announced that a majority American-owned joint venture was established to comply with President Donald Trump’s 2025 executive order requiring the company’s divestiture in order to keep operating in the U.S.

Keep reading

US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

 A federal case in Atlanta is raising questions about a privacy-focused mobile operating system, with prosecutors arguing that its features were used to erase evidence. The US Department of Justice is attempting to prosecute Atlanta resident Sam Tunick under a federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.

The case centers on Tunick’s use of GrapheneOS, an open-source operating system that works on Google Pixel phones and lets users enter a passcode to wipe a device clean.

Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. “It’s concerning – and sends the message that [GrapheneOS] is criminal by default,” said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

The incident began at Hartsfield-Jackson Atlanta International Airport on January 24 of last year. Tunick had just returned from a trip to the Dominican Republic when he was stopped for questioning. According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for “suspected terrorism activities” because of his alleged association with the movement against Cop City.

Keep reading

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the National Association of Criminal Defense Lawyers (NACDL).

We argued that electronic device searches at the border should require a warrant based on probable cause, but at minimum, regardless of whether an officer searches by hand or with forensic software that plugs into a device and downloads its entire contents for search, the same Fourth Amendment standard should apply to all device searches at the border.

Unfortunately, the court rejected that argument and ruled that a lower standard applies to manual searches, allowing the government to conduct extraordinarily invasive electronic device searches without any suspicion of wrongdoing, simply because the border officer chooses to search by hand rather than with a forensic tool.

The Border Search Exception Meets Your Phone

The Fourth Amendment requires that government searches of persons or property be reasonable, which usually means obtaining a warrant based on probable cause from a judge.

But a warrantless search can still be reasonable if it falls within an exception to the warrant requirement, including the exception that allows officers to search your belongings at the border. The border search exception allows warrantless searches of persons or property crossing the U.S. border, including the functional equivalent of the border such as international airports, given the government’s interests in controlling who and what may enter the country.

Historically, courts have categorized border searches of luggage, vehicles, and personal effects as “routine” and thus reasonable even if conducted without any suspicion that the traveler has engaged in wrongdoing; courts have also held that more invasive “nonroutine” searches, such as certain body searches and searches that damage property, require reasonable suspicion.

But a person’s privacy interests in the personal data on a phone or laptop are extraordinarily different than their limited privacy interests in the contents of their suitcase.

The Supreme Court addressed cell phone privacy in Riley v. California (2014), holding that the search-incident-to-arrest exception to the warrant requirement did not apply to cell phones, thereby generally requiring a warrant for phone searches, at least at the interior of the country. The court recognized the unprecedented privacy interests people have in their cell phones and how even brief manual searches can reveal the “sum of an individual’s private life,” including our political affiliations, religious beliefs, sexuality, and more. Accordingly, the Supreme Court held that because electronic device searches bear “little resemblance” to searches of bags or physical containers, they should be evaluated differently.

Following Riley, the Fourth Circuit considered two border device search cases involving forensic searches, in which border officers used external software to extract and analyze a device’s data.

In U.S. v. Kolsuz (2018), the Fourth Circuit held that a forensic search of a cell phone at the border “must be considered a nonroutine border search, requiring some measure of individualized suspicion” of a transnational offense, but the court declined to decide whether the standard is only reasonable suspicion or instead a probable cause warrant.

Then in U.S. v. Aigbekaen (2019), the Fourth Circuit held that a forensic device search at the border in support of a purely domestic law enforcement investigation requires a warrant. The court also reiterated the general Kolsuz rule for a forensic border-related device search: the “Government must have individualized suspicion of an offense that bears some nexus to the border search exception’s purposes of protecting national security, collecting duties, blocking the entry of unwanted persons, or disrupting efforts to export or import contraband.”

In Belmonte Cardozo, manual searches were finally before the court.

Keep reading