A federal court's ruling against the Department of Defense narrows the government's ability to use procurement mechanisms as instruments of coercion against AI developers that decline surveillance-related work. The decision, finding that DOD violated the First Amendment by designating Anthropic a supply chain risk after the company refused to permit Claude's use for mass surveillance of U.S. persons or autonomous weapons, does not resolve whether a company's technology-use restrictions constitute protected speech in their own right — that question remains open. What the ruling does close is the most direct pathway: retaliatory procurement blacklisting as a response to a contractor's ethical guardrails. The decision also illuminates the statutory vacuum governing AI use by the military, a gap that congressional and agency rulemakers have yet to address.
Watch level: PREPARE (AI developers with federal contracts, defense procurement counsel, civil liberties practices)
The White House Office of Management and Budget has finalized Memorandum M-26-18, making Login.gov the default federal authentication platform and requiring all covered agencies to migrate public-facing services within two years. High Impact Service Providers face a one-year deadline. The memo directs agencies to phase out commercial identity providers — ID.me and CLEAR are explicitly in scope — unless operational necessity or user-burden considerations apply. Agency CIOs must inventory authentication-dependent websites within 60 days, and NIST has 120 days to publish supporting guidance under SP 800-63-4. The policy reflects a consolidation logic that has been building for several years; finalization marks the transition from aspiration to enforceable obligation.
Watch level: PREPARE (federal agency CIOs, identity verification vendors, GSA compliance teams)
Criticism of Meta's $17 billion multistate settlement is sharpening around a core structural concern: the agreement's mandatory age assurance requirements apply to all users, not only minors, embedding biometric-adjacent verification into Instagram and Facebook at population scale. EFF's formal critique underscores that the settlement reinforces surveillance infrastructure rather than dismantling it, while parental monitoring provisions raise additional questions about platform-mediated family surveillance. The settlement covers 52 jurisdictions — all U.S. states and territories except Florida, New Mexico, and Texas — meaning its age assurance architecture will function as a de facto national standard. Content restriction provisions, particularly around sexual health and reproductive information, add a further layer of enforcement ambiguity.
Watch level: MONITOR (social media platform counsel, civil liberties advocates, state AG offices not party to the settlement)
The House Permanent Select Committee on Intelligence has recommended that CBP collect biometrics from foreign nationals at land border exits and construct traveler profiles from that data — an explicit escalation from prior congressional language on the subject. The recommendation acknowledges that 25 years after the 9/11 Commission first mandated biometric entry-exit, land border departure collection remains unimplemented. The committee's framing raises a tension it does not resolve: it warns against replicating authoritarian surveillance architectures while simultaneously endorsing profile-building on travelers. For organizations with cross-border workforces or supply chains, expanded biometric collection at northern and southern land ports warrants operational attention.
Watch level: MONITOR (immigration counsel, employers with cross-border workforce, civil liberties organizations)
State-level legislative activity on location data and age assurance is producing overlapping compliance obligations that now require affirmative mapping by affected platforms. Connecticut, Maryland, New Jersey, Oregon, and Virginia have each enacted location privacy statutes following the Supreme Court's Chatrie ruling, which established geofence-based data access as a Fourth Amendment search. Simultaneously, California's SB 1013 — which would extend ALPR data retention periods and broaden public agency access — faces organized opposition from CDT, EFF, and EPIC, whose floor alert frames the bill as undermining existing state privacy frameworks. The divergence between states enacting new protections and others potentially rolling them back underscores the fragmentation risk that federal action has not yet resolved.
Watch level: MONITOR (ad-tech and data broker counsel, law enforcement data vendors, California legislative affairs teams)
Still developing: Brazil's ANPD lawsuit against Discord and enforcement action against TikTok: no material change since last reported; enforcement campaign continues with ANPD committed to intensifying actions through 2026. EU Commission designations of ChatGPT, Reddit, and Roblox under the DSA: no material change; compliance deadline of January 2027 stands. California AB 1709 and EFF veto request: no material change; gubernatorial decision pending. Australia's digital identity strategy with erasure rights and IDLock controls: no material change since last reported; legislative development ongoing.
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.