Meta Plans Camera-Free Smart Glasses After Privacy Backlash
Meta is preparing to release a version of its smart glasses without a camera, following public accusations that the camera-equipped model enabled covert surveillance of strangers.
Why it matters:
Camera-free glasses may reduce client hesitancy around AR wearable campaigns, though the source contains no pricing, release date, or adoption figures to confirm scale of opportunity.
Agency action:
Monitor Meta's official announcement for specs and release date before building any...
Virginia Gov. Spanberger Signs Executive Order 22 to Slow Data Center Approvals
Virginia Governor Abigail Spanberger issued Executive Order 22, banning executive branch officials from signing nondisclosure agreements for data center projects and requiring expedited noise reviews. The order also establishes an AI task force and gives local communities greater input over data center development in the state already known as the data center capital of the world.
Why it matters:
Tighter approval timelines and local veto power over data center projects could affect AI infrastructure availability and pricing, which flows downstream to cloud-based marketing tools agencies depend on.
Agency action:
Monitor how Executive Order 22 affects data center capacity and pricing in...
India mandates caller-ID apps share spam data with telcos
India's government is requiring caller-ID apps such as Truecaller to feed their spam reports directly to telecom operators. Truecaller argues the one-way data-sharing mandate would transfer a commercially valuable proprietary asset to telcos at no reciprocal benefit.
Why it matters:
Outbound call and SMS campaigns targeting Indian numbers could face tighter carrier-level filtering if telcos act on the shared spam data, raising deliverability risk for agencies running high-volume outreach in that market.
Agency action:
Audit any India-targeted calling or SMS workflows for spam-signal exposure before carrier...
Palantir, Nvidia, Booz Allen Pulled Back From Anthropic Over 30-Day Log Retention
Anthropic disclosed it stores usage logs from its flagship model for 30 days, prompting Palantir, Nvidia, and Booz Allen Hamilton to pull back from using it for sensitive work, despite Anthropic's stated policy against using corporate customer data for training.
Why it matters:
Even with no-training guarantees in place, log retention policies alone can disqualify an AI tool from client engagements involving sensitive data, creating contract and compliance risk for agencies handling confidential campaigns or research.
Agency action:
Audit the data retention and logging policies of every AI tool in your stack before...
OpenAI contract workers rate real ChatGPT chats on 1-to-7 scale
Hundreds of OpenAI contract workers read anonymized ChatGPT conversations and rate them on a 1-to-7 scale to reduce flattery and human-like behavior. The 'Improve the model for everyone' setting is on by default, meaning chats are reviewed unless users actively opt out.
Why it matters:
Client data entered into ChatGPT may be read by human reviewers even when anonymized, creating potential confidentiality risks for agencies handling sensitive campaign briefs or client information.
Agency action:
Audit ChatGPT account settings now and disable 'Improve the model for everyone' for any...
Chrome shifts to 2-week release cycle amid AI security pressures
Google has accelerated Chrome's release schedule to ship updates every 2 weeks, prioritizing faster delivery of security patches and new features in response to AI-driven changes in the security landscape.
Why it matters:
Faster Chrome updates mean browser-based tools and client-facing dashboards may behave differently more often, requiring agencies to check for compatibility issues or broken automations on a tighter schedule.
Agency action:
Set a recurring biweekly check of agency Chrome-dependent tools and client reporting...
Termsinator Builds Public Registry of LLM-Analyzed ToS and Privacy Docs
Termsinator is an open public registry that uses LLMs to analyze legal documents including Terms of Service, Privacy Policies, and Cookie Policies, surfacing data-use risks and pitfalls without requiring users to read full documents.
Why it matters:
Vetting vendor contracts and data-handling policies is a recurring cost for client-facing agencies; a shared registry of pre-analyzed legal documents could cut that review time significantly for commonly used tools.
Agency action:
Check Termsinator's registry before onboarding new SaaS tools to quickly identify...
TIM PG Anonymizes Sensitive Data Before AI Tool Input
TIM PG is a tool listed on Product Hunt that anonymizes sensitive data before it is pasted into AI tools, addressing privacy risks in AI-assisted workflows.
Why it matters:
Handling client data through AI tools carries real compliance risk; a dedicated anonymization step before input reduces exposure of personally identifiable information across client campaigns.
Agency action:
Test TIM PG as a pre-paste step in your team's AI workflow to assess how well it strips...
Microsoft commits to 10 AI privacy principles for K-12 schools
Microsoft agreed to ten contractual AI safety and privacy principles with the American Federation of Teachers (AFT) and its NYC affiliate the United Federation of Teachers (UFT), the second-largest teachers union in the US. The agreement came one week after two major school systems announced bans on student-facing AI tools.
Why it matters:
Tighter school AI privacy standards signal growing institutional scrutiny of how AI tools handle student data, which could affect agency clients in the education sector. Contractually binding principles may set a precedent that spreads to other districts or procurement requirements.
Agency action:
Review any education-sector AI tools in your stack against the ten Microsoft-AFT...
Apple releases privacy doc for new Siri Audio Intelligence features
At Wednesday's iPhone Duo launch event, Apple announced Siri AI Audio Intelligence features including Siri Recap, Live Rewind, Sound Recognition, and Music Recognition. Apple simultaneously published a document stating raw audio from these features is handled within dedicated hardware.
Why it matters:
Client data handling and consent disclosures become more complex when AI ambient listening is involved, so understanding Apple's privacy architecture helps agencies advise clients on compliant voice and audio campaign strategies.
Agency action:
Review Apple's published privacy document to assess how ambient audio data is processed...
Apple Watch AI transcription features spark consent and privacy debate
Apple's new Watch models include AI features that can transcribe recent speech and summarize ambient conversations. Apple states raw audio will not be saved, but the capabilities raise unresolved questions about user consent and behavioral change.
Why it matters:
Client conversations at live events, briefings, or pitches could fall within range of always-on transcription devices, creating new liability considerations for agencies handling sensitive campaign or budget discussions.
Agency action:
Update client meeting protocols to address wearable AI devices, including disclosure...
Facebook Publishes Phishing Protection Guidance for Business Accounts
Facebook published a business advisory on phishing threats targeting Facebook accounts, outlining what phishing is and steps to protect against it. The source content is in Swedish and does not include specific dates, statistics, or metrics.
Why it matters:
Compromised Facebook Business accounts can disrupt client ad campaigns and expose sensitive billing data, making account security a direct operational risk for agencies managing multiple client pages.
Agency action:
Review Facebook's phishing protection advisory and audit team member account permissions,...
Termly Publishes SaaS Agreement Requirements and Checklist
Termly published a guide outlining the required components of a SaaS agreement, including a checklist covering key clauses for subscription-based software services.
Why it matters:
Reselling or white-labeling AI tools under a subscription model requires a compliant SaaS agreement; missing clauses can expose agencies to liability with clients.
Agency action:
Review your current client contracts against Termly's SaaS agreement checklist to...
Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act with an expanded definition of sensitive data and lowered applicability thresholds. Delaware joins more than half of the 23 states with comprehensive privacy laws that have now amended their statutes.
Why it matters:
Revised applicability thresholds mean more clients may fall under DPDPA obligations, requiring updated data handling practices and consent workflows for campaigns targeting Delaware residents.
Agency action:
Review the HB 380 amendments, particularly the expanded sensitive data definition and new...
CCPA Requires Visible 'Do Not Sell' Link for California Consumers
The California Consumer Privacy Act (CCPA) mandates that covered businesses provide a 'Do Not Sell or Share My Personal Information' link, giving California consumers a direct opt-out mechanism for data selling and sharing.
Why it matters:
Clients whose sites lack this compliant link face regulatory exposure under CCPA, putting agency-built properties at legal risk and potentially reflecting on the agency's work quality.
Agency action:
Audit all client websites for a properly placed 'Do Not Sell or Share My Personal...
CCPA and GDPR Set Overlapping but Distinct Data Privacy Rules
The EU's GDPR and California's CCPA establish parallel but different requirements for how businesses collect and handle personal data online. The CCPA draws directly from GDPR precedent, creating overlapping compliance obligations for agencies serving clients in both jurisdictions.
Why it matters:
Clients in California and the EU fall under separate legal frameworks, meaning a single privacy policy rarely satisfies both laws. Gaps in compliance can expose agency clients to regulatory risk across two of the world's largest consumer markets.
Agency action:
Audit current client privacy policies to identify which regulations apply, then confirm...
Michigan Privacy Bill MPDPA Failed to Pass Into Law
The Michigan Personal Data Privacy Act, which moved through the Michigan Senate in 2023, did not pass and remains a dead bill. It would have created consumer privacy rights and business obligations around personal data sale and processing.
Why it matters:
No new compliance requirements apply in Michigan from this bill. Client data handling workflows do not need adjustment based on this legislation.
Agency action:
Monitor active state privacy laws rather than allocating compliance resources to this...
Thailand PDPA Applies to Foreign Businesses Handling Thai Residents' Data
Thailand's Personal Data Protection Act (PDPA) extends to businesses both inside and outside the country, part of a global trend in which 162 countries have now enacted data privacy laws.
Why it matters:
Running campaigns that collect data from Thai residents triggers PDPA compliance obligations regardless of where the agency is based, adding cross-border legal exposure to client work in the region.
Agency action:
Audit any client campaigns targeting Thai residents to confirm data collection practices...
CCPA Gives California Users Opt-Out Rights on Targeted Ads
The California Consumer Privacy Act requires websites to honor California users' right to opt out of cross-context behavioral advertising and any data processing tied to it.
Why it matters:
Running targeted ad campaigns for clients with California audiences now carries compliance obligations; failing to provide opt-out mechanisms exposes those clients to CCPA enforcement risk.
Agency action:
Audit client websites for a compliant opt-out mechanism covering cross-context behavioral...
Colorado Privacy Act Grants Residents Data Opt-Out Rights
Signed into law on July 7, 2021 and in effect since 2023, the Colorado Privacy Act gives state residents the right to refuse sale of personal data and to access, correct, and delete their information.
Why it matters:
Client campaigns targeting Colorado residents must include opt-out mechanisms for data sales, or agencies risk non-compliance on behalf of the brands they serve.
Agency action:
Audit data collection workflows for Colorado-resident audiences and add compliant opt-out...
Open-source repo offers free DIY data broker removal instructions
A developer published 'remove-your-data' on GitHub after a paid removal service failed to clear their phone, addresses, and vehicle data from public sources. The open-source repo provides step-by-step instructions an agent can follow to manually submit removal requests across data brokers.
Why it matters:
Clients increasingly ask about personal and brand data exposure; this free resource gives agencies a no-cost starting point for advising on data broker opt-outs without recurring subscription fees.
Agency action:
Review the remove-your-data GitHub repo to assess whether its instructions fit your...