Six federal appeals courts are now divided 3–3 over whether an automated hash match can qualify as a private search. In last week’s United States v. Brillhart, the Eleventh Circuit held that police could open the matched file without a warrant because doing so revealed nothing materially new. Today’s Supplement 07 takes a closer look at the 3–3 split, how Google’s system works, and what the Eleventh Circuit did—and did not—decide.
The FBI published CJIS Security Policy v6.1 on June 25. Plain Thinking’s independent review found largely what the FBI’s own change summary describes: three packages of omissions, corrections and additions, plus administrative changes. That is the incremental follow-on anticipated after the major v6.0 modernization in December 2024.
Nothing in v6.1 creates a new AI section or AI-specific rule. Its only express reference to artificial intelligence is the same preexisting passage about malware-detection techniques found in v6.0. AI systems that handle criminal-justice information still fall under the policy’s broader controls, but v6.1 is not a new set of AI regulations.
LAPD let its Flock contract expire and stopped using the company’s cameras while seeking firmer data, privacy and security terms. (Los Angeles Times)
A ransomware negotiator received 70 months after admitting he fed client negotiating positions to BlackCat attackers and joined extortion schemes. (Ars Technica)
The U.S. administration is lifting some federal procurement rules for contractors handling sensitive information. (Federal News Network)
NIST, the federal agency that sets technical standards across government and industry, is giving agencies a new checklist for vetting technology suppliers. (Inside Cybersecurity)
Canada’s financial regulator issued new recommended controls for AI agents, including limited access, activity logs and human approval. (OSFI)