Flock Cuts Default Data Retention After 46 Unauthorized-Use Allegations

0146 Unauthorized-Use Allegations Spark Backlash as Flock Cuts Default Data Retention From 30 Days to Seven

Flock Safety has tightened access and retention rules for data collected by its surveillance systems after 46 alleged cases of police officers using the technology without authorization fueled a political backlash. Flock supplies surveillance cameras, drones and license plate recognition systems to law enforcement agencies.

The Washington Post identified 46 cases in which officers were accused of unauthorized use, including allegations that they used Flock’s technology to track wives, girlfriends or former partners. The source does not say how many accusations have been investigated or confirmed.

CEO Garrett Langley apologized after hearing an interview with one alleged victim, telling CBS News that it “kills me that she went through that.” But he argued that Flock did not create police abuse and claimed the company had built tools capable of exposing it. That account is Flock’s position, not an independently verified conclusion.

Langley has framed the controversy as a need for “compromise” between privacy and public safety. He has also called on state regulators to make illegal use of Flock data a criminal offense, while acknowledging that technologies such as Flock’s too often operate without regulation or accountability.

The company has now reduced its default data-retention period from 30 days to seven days. It will also require users to enter a case code before accessing data, creating an additional record connecting a search to an investigation.

Neither restriction is absolute. Users can override the changes, and officers can preserve data for longer through a setting called Evidence Mode. The available source does not explain the threshold for activating that mode, whether approval is required or how frequently it is used.

The American Civil Liberties Union said the shorter default period could represent progress, although it remains longer than the group’s recommended 48 hours. The organization said the reform’s practical significance will depend on how Evidence Mode works.

Pressure is now coming from both major political camps. Democratic politicians including Vermont Senator Bernie Sanders have attacked Flock as a vehicle for mass surveillance. Three House Republicans have introduced legislation that would bar the federal government from purchasing certain automated surveillance systems using facial recognition, biometric identification or license plate recognition, explicitly including Flock Safety cameras. No outcome for that proposal was reported.

People captured by Flock systems could have their data deleted sooner by defaultpolice access will carry a case-code requirement, but override options may weaken both safeguardsthe company now faces bipartisan scrutiny and a proposed federal purchasing ban.

02Ulanqab Data Center Pledges Reach 12.5 Gigawatts as Expansion Runs Into Local Water Strain

Ulanqab, an Inner Mongolian city of about 1.5 million people, has emerged as a major center for China’s AI infrastructure. Nearly 100 data centers have opened or begun construction there since 2016, helped by cold weather, low electricity prices and proximity to Beijing. In 2021, the city became a principal hub in China’s “Eastern Data, Western Compute” program, which shifts computing work from populous eastern regions to the west.

Now the scale and character of that buildout are changing. Chinese companies have pledged projects in Ulanqab with an estimated combined capacity of 12.5 gigawatts, according to a Goldman Sachs research note published last week. More than 70 percent of those commitments were announced during the past year, though the source does not establish how much has been approved, financed or given a firm operating date.

DeepSeek is reportedly building a large AI data center in the city, while ByteDance, Alibaba and Xiaohongshu are also developing projects. Their investments point to a shift among Chinese AI companies from renting computing capacity from cloud providers toward owning more of the physical infrastructure behind model training and inference—the process of running a trained model to answer users.

Ulanqab’s location supports both workloads. Long, cold winters reduce cooling-energy needs, while cheap electricity reflects expanding wind and solar generation alongside abundant coal. Two dedicated fiber-optic cables, built in 2017 and 2019, have cut average latency to below five milliseconds. That is fast enough for real-time exchanges such as inference, while lengthy AI training runs are less sensitive to delays.

Water is the more immediate constraint. Ulanqab receives roughly 14 inches of rain annually, and its water system is already under pressure before many planned data centers begin operating. Last month, the local water company shut several waterworks for seven hours each night to ease peak demand. The source does not attribute those interruptions to data centers or quantify the projects’ eventual consumption.

The region’s climate means data centers need additional cooling water during only two months of the year, but the combined expansion could still create environmental pressure. Its clean-energy case is similarly qualified: about 37 percent of Ulanqab’s electricity still comes from coal, whose reliability remains attractive to facilities operating around the clock.

AI companies face unresolved approval, financing and resource risks before the pledged 12.5 gigawatts can become operating capacityresidents could face greater pressure on an already strained water system, though the projects’ impact has not been quantifiedround-the-clock demand could preserve substantial coal use despite new wind and solar generation.

03Four AI Models Took Turns Rooting a Fire HD, as Its Owner Spent $266 Turning a Known Flaw Into a Working Tool

An owner of a 2021 Amazon Fire HD 10 says four AI models helped him gain root access—full administrative control—after the tablet began shutting itself down as often as twice a day. He used the device as an always-on Home Assistant control panel, but its telemetry attributed the shutdowns to software rather than power loss or sleep.

The owner, who says he has 20 years of technology experience and an information-security background, first worked with Claude for five months to diagnose the problem. They temporarily disabled five Amazon services with reboot or shutdown permissions, but three remaining packages were protected by the operating system. Removing them required root, for which the model had no published method, and Claude’s safeguards eventually prevented further assistance.

Kimi K3 then inspected the kernel extracted from Amazon’s update image for the tablet’s exact firmware. Rather than discovering a new vulnerability, it determined that Fire OS 7.3.2.6 remained vulnerable to CVE-2022-38181, a previously disclosed use-after-free flaw in Arm’s Mali GPU driver. Amazon had included a fix in Fire OS 7.3.2.9, but this tablet had not been updated.

Over roughly 30 hours and 621 messages, Kimi built a trigger, developed a way to make the GPU write outside its intended memory area, and identified kernel addresses to target. That work cost $164.25.

The exploit still failed repeatedly because freed memory was quickly reused by other operating-system activity. Most attempts crashed the kernel and rebooted the tablet; the automated process ran six attempts per boot and exceeded 500 attempts without producing a validated path.

After its budget ran out, Kimi created a HANDOFF.md file containing the verified work and passed it to GLM-5.2. The owner says GLM-5.2 identified fatal defects for $21.90, while GLM-5.3 completed the root in one day during the first day of an $80 subscription.

The related model spending totaled $266.15, more than twice the tablet’s $114.26 purchase price. The account has not been independently reproduced, and it does not fully describe GLM-5.3’s final correction, the exploit’s success rate, or whether the resulting tool will be released.

Owners of this specific unpatched firmware may face a lower operational barrier to adapting a known vulnerabilityAI agents can preserve and transfer verified exploit work across models, but repeated crashes and specialist judgment remain real costsindependent reproduction and public availability of the tool are still unknown.
04

Anthropic Revenue Climbs as Its Newest Models Lag Cheaper Options Anthropic’s annualized revenue reportedly reached $65 billion in July, while billing data from Ramp indicated limited early adoption of its Opus 5 and Sonnet 5 models. The company also reportedly told investors it had 6,000 customers spending at least $100,000 annually. simonwillison.net

05

Anonymous Ox Alpha Coding Model Debuts on OpenRouter Ox Alpha launched free on OpenRouter as a “stealth model” intended for coding, sustained agentic work, and production workloads. Its developer remains anonymous, and speculation linking it to several Chinese and U.S. model makers remains unconfirmed. techcrunch.com

06

Google DeepMind Expands Game-Studio Partnerships for General AI Agents Google DeepMind is working with Fenris Creations and other studios to prototype AI-driven gameplay and research agents that operate through ordinary screen, keyboard, and mouse interfaces. Its Gemini-powered SIMA 2 agent is designed for real-time reasoning and conversation across multiple 3D games, with potential uses including adaptive characters and automated quality assurance. deepmind.google

07

Harvard Startup Bootcamp Uses AI Instructor Avatars for Pitch Feedback Harvard Business School’s eight-week, $699 Foundry bootcamp uses avatars created by video-generation startup HeyGen to give participants feedback during simulated pitches and board meetings. The program supplements the avatars with weekly live instructor sessions. techcrunch.com

08

Linkdaze Adds Photo-to-Plan AI to Its Household Calendar Linkdaze’s touchscreen household calendar synchronizes services including Google, iCloud, Outlook, Yahoo, and Cozi. Its Snap-to-Sync feature converts photographs of recipes or school menus into meal plans and shopping lists, while the product’s main features require no monthly subscription. techcrunch.com

09

Claudette Skill Rewrites Claude Code Responses Through Gemini The open-source /debuzz skill sends Claude Code’s previous response to Google’s Gemini-powered Antigravity CLI and returns a plainer rewrite verbatim. The MIT-licensed project also supports supplied text and several output styles. github.com

10

AI Copyright Rulings Draw a Line Between Training and Piracy A federal judge ruled that Anthropic’s model training was lawful but penalized the company for obtaining books from unauthorized shadow libraries, while another court rejected fair use when Ross Intelligence copied Thomson Reuters material to build a competing legal product. Other AI copyright cases remain pending, leaving the governing standards unsettled. techcrunch.com