The AI, Privacy, and Security Weekly Update

R. Prescott Stearns Jr.

Into year 7 for this award-winning, light-hearted, lightweight AI privacy and security podcast that spans the globe in terms of issues covered, with topics that draw in everyone from executive to newbie, to tech specialist. For season 7, we've renamed the IT Privacy and Security Weekly Update to the AI, Privacy, and Security Weekly Update to better reflect the content. Your investment of between 15 and 20 minutes a week will bring you up to speed on half a dozen current AI privacy and security stories from around the world to help you improve the management of your own privacy and security.

  1. 17h ago

    Fingerprints. The AI, Privacy, and Security Weekly Update for the week ending August 18th. , 2026.

    EP 305.  In this week's update: Anthropic is adding invisible watermarks to everything Claude writes-and you won't know it's there until someone looks for it. China is racing to the Moon by 2030, and the real competition isn't about flags; it's about water. Meta's AI glasses are so good at recording people without their knowledge that Germany is treating them like a crime. Your WiFi router can identify who you are without a camera, a sensor, or your phone-just by watching the signals bounce around your apartment. The Royal Navy's drones were quietly sending heartbeat signals to an IP address in China for who knows how long. France just blocked its own law to ban kids under 15 from social media because the privacy cost was too high. Your cloud storage provider can disappear tomorrow and take 50 terabytes of your data with them-and you can't do a thing about it. Stripe just bought a gateway that lets developers switch between AI models like they're checking the weather, and it cost $7 billion. A man representing himself in court hid AI instructions inside a legal filing in tiny white font, trying to manipulate the judge into ruling his way. Amazon is buying rare books by the shipment, destroying the physical originals so it can feed them into its AI training data. It's been a week where the question isn't whether you're being tracked, watched, fingerprinted, or fed into someone's machine learning model-it's how many ways it's happening at once.  Let's examine the evidence....

  2. Aug 11

    Verify. The AI, Privacy, and Security Weekly Update for the week ending August 11, 2026.

    Episode 304. n this week's update: New Orleans is about to let AI answer some of its 911 calls - and the question isn't whether it's fast enough, it's what happens the moment it gets a panicked caller wrong. A mother nearly handed $7,500 to a scammer who cloned her son's voice perfectly - and the thing that saved her wasn't technology, it was a five-minute habit her family never got around to until it was almost too late. Memory prices are about to get a lot worse before they get better, and the culprit isn't your next upgrade - it's an AI chip that skips memory entirely by baking the model into the silicon itself. A new study combed through more than a million Reddit posts about AI coding tools, and what it found wasn't a bug - it was developers handing a master key to something that acts like a junior dev with no supervisor. ChatGPT just got dramatically more capable for free users, and OpenAI's real bet isn't smarter answers - it's convincing you to open the app for things you'd never have thought to ask it before. Meta's smart glasses have a nickname now, and it isn't a compliment - the backlash isn't really about the camera, it's about the fact that you can't tell when it's on. Researchers built an AI that reads the way humans actually read - skimming, rereading, getting distracted - and the unsettling part isn't how well it works, it's what that skill could eventually be used for. A federal judge just ruled that a surveillance tool police have used for years is unconstitutional - and the reasoning wasn't about the crime being investigated, it was about everyone who wasn't. A California police department found that a license plate reader marketed at 96% accuracy was wrong 71% of the time in real alerts - and the only thing standing between that error rate and a wrongful arrest was one department's decision to double-check. The world's memory chipmakers have reportedly sold out all of next year's production already - and if you've been putting off a new laptop or phone, the math on waiting just got worse. It's been one of those weeks where the theme keeps repeating itself: the machines are getting faster, cheaper, and more embedded in daily life, but the humans checking their work are the ones actually keeping us safe.  From 911 dispatch to license plate cameras to the chip inside your next laptop, this episode is about what happens in the gap between what AI claims and what AI delivers.  Find the full transcript to this podcast here.

  3. Aug 6 ·  Bonus

    EP 303. Gorgones. Deep Dive. The AI, Privacy, and Security Weekly Update for the week ending August 3, 2026.

    Artificial intelligence has fundamentally changed the cybersecurity landscape by reducing the expertise needed to launch sophisticated attacks. Open-weight AI models now automate reconnaissance, vulnerability analysis, and exploit development, allowing attackers to scale operations in minutes instead of days. The Zhuhai-linked "knaithe" campaign demonstrated this shift by combining DeepSeek with the Hermes Agent Framework to autonomously identify and target vulnerabilities. Although configuration barriers prevented successful exploitation, the attackers exposed their own API keys and logs, highlighting operational security risks for both defenders and adversaries. Nation-state actors are increasingly targeting critical infrastructure as a tool of strategic coercion. Iran's CyberAv3ngers group has progressed from website defacements to manipulating industrial control systems in water and energy facilities. Recent attacks on Minnesota water utilities disrupted operations and created risks to water treatment, demonstrating how cyberattacks can produce real-world physical effects without conventional military action. Data sovereignty and supply chain security remain major concerns. Attackers breached Liechtenstein's beneficial ownership registry by bypassing rate limits and exposing sensitive ownership records, undermining trust in a jurisdiction built on financial privacy. Meanwhile, ShinyHunters continues exploiting third-party IT service platforms to steal credentials and compromise organizations through trusted suppliers, creating lasting consequences that cannot be undone by ransom payments. Defensive innovation is shifting toward stronger system design rather than reactive filtering. New techniques isolate sensitive AI knowledge, while formal verification enables machine-checkable reasoning that improves trust and reliability. These advances strengthen AI security but cannot replace effective governance. Confidence in surveillance technology is also weakening. Investigations into Flock Safety's automated license plate reader network found gaps between public claims and operational practices, prompting dozens of municipalities to cancel deployments and reinforcing the need for transparency and accountability. Overall, AI is accelerating offensive cyber capabilities, critical infrastructure is becoming a routine target, and organizations must combine resilient technology with strong governance to defend against increasingly automated threats.

    EP 303. Gorgones. Deep Dive. The AI, Privacy, and Security Weekly Update for the week ending August 3, 2026.
  4. Jul 30 ·  Bonus

    EP 302. Deep Dive into the Records. The AI, Privacy, Security Weekly Update for the Week ending July 28th., 2026

    1. Saudi Arabia – World’s Largest AI HackathonKanz (AI hiring platform) ran an 8-day free event (July 15–22) targeting 100,000 complete beginners — teachers, job seekers, business owners, etc. — with the goal of a Guinness World Record. Participants built real apps/agents using no-code tools (Lovable, n8n, Replit, Magnific, Claude, etc.) and earned certificates plus portfolio projects. Registration surged past 50,000. It builds on prior programs with strong female participation and workforce outcomes. Upshot: AI building no longer requires a coding background; accessible programs are becoming genuine on-ramps.2. California – DROP Data Deletion PlatformThe Delete Act’s DROP platform (live Jan 2026) lets California residents submit one request to delete data from ~600 registered data brokers. Identity verification uses California Identity Gateway/Login.gov; identifiers are normalized and hashed so the state never sees or shares raw personal data. Brokers must check every 45 days from Aug 1, 2026, fully delete matches, and report back. Applies to large processors worldwide; heavy fines and future audits. Upshot: A privacy win worth using if you’re in California; likely to be copied elsewhere.3. Australia – Origin Energy BreachAustralia’s largest energy provider confirmed a breach potentially affecting a large portion of its ~5 million customers (hacker claimed ~2 million). Sensitive PII was leaked online. Utility data heightens risks for identity theft and further infrastructure attacks. Upshot: Change passwords and watch for phishing if affected.4. Anthropic – Claude Opus 5New flagship model launched at $5/$25 per million tokens (half Fable 5’s input price), with 1M token context and adjustable “effort” levels. It outperforms or matches its pricier sibling on key benchmarks. Upshot: Forces reevaluation of vendor pricing vs. performance for coding/knowledge work.5. Kimi K3 – Largest Open-Weight ModelMoonshot AI released a 2.8-trillion-parameter model (1.4 TB weights). Within days, it was used to discover dozens of zero-days and build working exploits far faster than before. Fully open weights mean no usage restrictions. Upshot: Major step-change for vulnerability research timelines; treat as a serious new threat-intelligence factor.6. South Korea – 10-Month Diplomatic BreachAttackers accessed the National Diplomatic Academy system undetected from April 2025 to February 2026, stealing data on ~6,000 Ministry of Foreign Affairs personnel (including 360 overseas diplomats). Upshot: Dwell time is the bigger issue — invest in better detection.7. Suno Music-AI Breach (Nov 2025)55 million users’ names, phones, and addresses exposed; only now public ~8 months later. Upshot: Check Have I Been Pwned; AI company breaches can stay hidden for long periods.8. U.S. – AI Kill Switch ActBipartisan bill (Reps. Lieu & Moran, introduced July 23) requires frontier models (≥$100M training cost) to maintain shutdown/throttling capability. DHS (with Commerce & DNI) could order action for catastrophic risks. Fines up to $20M/day. Predates recent high-profile AI incidents but cites them. Upshot: Frontier developers should assess compliance readiness; some form of this is increasingly likely.

    EP 302. Deep Dive into the Records. The AI, Privacy, Security Weekly Update for the Week ending July 28th., 2026
  5. Jul 29 ·  Bonus

    One Request, 600 Companies and one Deep Dive: Inside California's New Data Deletion Machine

    California’s Delete Act (SB 362) introduced DROP (Delete Request and Opt-out Platform), which launched on January 1, 2026. It lets residents submit one deletion request that automatically propagates to all registered data brokers in the state—currently around 500 companies. The Core Problem It Solves Data brokers collect and resell personal information from people they’ve never directly interacted with. Before DROP, individuals had to manually find each broker, submit separate requests, and hope for compliance with no centralized tracking.How DROP Works Residency Verification: Users prove they’re Californian via the California Identity Gateway or Login.gov (no permanent state account needed). This avoids redundant collection of sensitive data by brokers.Provide Identifiers: Users submit details like name (and former names), date of birth, ZIP code, email, phone, mobile advertising IDs (MAID), connected TV IDs, and VINs. More identifiers improve matching accuracy across brokers.Centralized Submission: One request is sent to all registered brokers.Privacy-Preserving Matching: California does not share raw personal data. Instead, it normalizes and hashes identifiers, creating deletion lists. Brokers hash their own records and compare hashes. Matches trigger deletion without exposing underlying data—similar in concept to lightweight privacy-preserving techniques.Recurring Compliance Cycle: Starting August 1, 2026, brokers must check DROP at least every 45 days (via API or download), process new requests, and honor prior deletions through ongoing suppression.Multi-Identifier Lists: Separate hashed lists exist for different data types; brokers use those relevant to their holdings.Full Deletion: A match requires deleting all associated records for that individual, not just the matching identifier, and preventing future sales.Reporting and Transparency: Brokers report completion status back through DROP, allowing users to track progress from pending to completed.Ongoing Obligation: Deletion is not one-time; brokers must maintain suppression lists indefinitely.Global Reach: Any data broker processing significant volumes of Californians’ data (threshold ~100,000 records) must register and comply, regardless of headquarters location.Broker Burden: Requires new infrastructure for hashing pipelines, scheduled polling, cross-identifier matching, suppression, and reporting. The state provides documentation, webinars, and test environments.Enforcement: Third-party audits begin in 2028 and recur every three years. Fines reach $200 per consumer per day for noncompliance.Scope and Requirements Why It Matters DROP targets brokers handling highly sensitive data (geolocation, biometrics, SSNs). Beyond faster deletions, it compels the industry to adopt stronger technical privacy and security practices. The architecture is innovative: the state coordinates mass privacy actions across hundreds of companies without ever holding or seeing raw personal data. If successful under real-world load from August 2026 onward, it could become a model for other states and countries—enabling deletion at scale without relying on trust. Closing Insight: The real breakthrough isn’t just the deletion feature but the underlying privacy infrastructure that makes coordinated, verifiable, and secure data removal possible.

  6. Jul 29 ·  Bonus

    Can AI Education Go Viral? A Deep Dive Inside the World's Biggest AI Hackathon

    The Kanz initiative (ka.nz/hack) was far more than a hackathon. It was a bold, free global program to democratize AI by enabling everyone, from complete beginners to experts, to build and publish real AI applications in one week. Fully sponsored and aligned with Saudi Vision 2030, it combined daily structured training, hands-on building, community energy, and a successful Guinness World Record attempt. Standout innovations: No coding required, AI-first approach: "Build first, learn by creating." Participants used cutting-edge tools (Claude, NotebookLM, Replit, HeyGen, Suno, Gamma, etc.) to create apps, agents, images/videos, avatars, music, presentations, and automations—emphasizing practical results over theory. 7-day tangible curriculum: Daily sessions (evenings KSA time) produced immediate outputs. Everyone published a working app on Day 1 and left with a portfolio, verified certificate (Saudi HRSD + Lebanese American University), and real skills.Strong incentives: MacBooks, Kindles, watches, job opportunities, and employer spotlights. Projects were AI-graded then judged, with top entries showcased.Radical inclusivity: Targeted teachers, marketers, business owners, job seekers, designers, and absolute beginners—not just coders.~51,700 registrations.24,800+ live participants from 150+ countries.~197,000 training hours.Guinness World Record (July 15, 2026): 14,075 learners in one AI video lesson — officially adjudicated. ka.nz3,500+ AI projects built, including practical tools like real-time fact-checkers and automation systems.Massive scale and success: Success drivers: zero cost, instant results, vibrant global community, modern tools, and partnerships. It proved AI creation can be accessible to everyone, not just engineers, potentially sparking countless innovations and careers. Deep Dive: Roy Baladi Roy Baladi, CEO of Kanz, is the visionary behind it. With a dual degree in Computer Science & Finance from Virginia Tech (Math minor) and 15+ years in tech/finance, he has built marketplaces and inclusive hiring platforms. Background: Wall Street derivatives experience (Citi), product roles at LearnVest and SmartRecruiters, Chief Marketplace Officer at PerkSpot. He founded/led Jobs for Lebanon (Board President): 5,000+ employers, 25,000+ seekers, 750+ hires. Through Kanz and Jobs for Humanity, he has reached over 1M people with AI tools and training, placing thousands (including underrepresented talent and Saudi women via Saudiaat). Philosophy: Roy views AI as a practical empowerment tool for employment, agency, and lifelong learning. He focuses on removing barriers, teaching by building, and using technology to restore humanity to hiring. Prior programs trained 2,000+ in agentic AI. The hackathon scaled this mission globally. Why It Matters: Digital literacy now means building with AI. Kanz didn't just teach chatbots-it empowered tens of thousands to create. If even a fraction of projects become tools or businesses, the impact will far outlast the record. Roy Baladi's work shows large-scale AI education is not only possible-it's transformative.

4.5
out of 5
4 Ratings

About

Into year 7 for this award-winning, light-hearted, lightweight AI privacy and security podcast that spans the globe in terms of issues covered, with topics that draw in everyone from executive to newbie, to tech specialist. For season 7, we've renamed the IT Privacy and Security Weekly Update to the AI, Privacy, and Security Weekly Update to better reflect the content. Your investment of between 15 and 20 minutes a week will bring you up to speed on half a dozen current AI privacy and security stories from around the world to help you improve the management of your own privacy and security.

You Might Also Like