> daily_signal(2026_06_19)

A Senate committee just advanced the first federal ban on cloning your voice or face, while the FCC moved to tie your government ID to every phone in the country.

PickBits Daily Signal · Friday, June 19, 2026

By Mark Pickering · 11 min read · June 19, 2026

// tl;dr

Most weeks the AI story is a capability, a model that can do a new thing. This week the story is the rulebook, and it moved in four directions at once. In one room, a Senate committee voted to make your face and voice yours by federal law, the first time Congress has tried to draw that line. In another, the country's communications regulator proposed attaching a government ID to every phone account, which would quietly retire the anonymous phone. Out in the wild, a flaw in the AI assistant millions of people now use at work showed how easily one of these systems can be talked into turning on the person using it. And on the Senate floor, a bill landed that asks the question none of the others do, not what AI can take from you, but what it might owe you back. Three of these tighten control. One tries to hand some of it back. All four are decisions being made right now about a technology most people did not vote for.

This week a Senate committee advanced a federal right over your own voice and face, the FCC moved to put a government ID behind every phone account in the country, a flaw in Microsoft Copilot let one click read a stranger's inbox, and Bernie Sanders introduced a bill to tax the AI giants into a fund that pays every American a yearly dividend.

1. A Senate committee just voted to make cloning your voice or face without permission a federal offense.

Federal regulatory action, with a free-speech fight built in.

On June 18, the Senate Judiciary Committee advanced the NO FAKES Act by a unanimous voice vote, sending it toward a full Senate floor vote. The bill would create the first federal intellectual-property right over AI-generated replicas of a person's voice and visual likeness, a right that would last through your life and up to 70 years after death, putting the power to authorize or block a digital clone on the same footing as owning a copyright. To make it bite, the bill reaches the platforms: an online service that hosts an unauthorized replica and fails to remove it in good faith once notified faces liability of up to $750,000 per work. Until now, the right to control your own likeness has been a patchwork of state laws; this would be the first national floor under it.

Here is the honest tension, because the bill is not clean. Three Republicans on the committee, Mike Lee, Ted Cruz, and Eric Schmitt, raised First Amendment concerns about satire and commentary but did not block the voice vote, with Lee saying he hopes to keep working on free-speech fixes before any floor vote. The Electronic Frontier Foundation has gone further, calling the bill a "supercharged" takedown regime whose exemptions for news, parody, and criticism are too narrow to protect speech that should be obviously legal, and the trade group NetChoice warns platforms will over-remove to avoid the liability. And it is worth being precise about where this stands: it cleared committee only. It is not law, and as Deadline noted, it is unclear when, or whether, it reaches the Senate floor; an earlier version died in committee in 2024.

Why this matters: Anyone with a public photo or a few seconds of recorded voice can now be convincingly cloned, and until this week there was no federal law that said your face and voice are yours to control. That is the protection this bill creates, and it is real. The catch is the same one that makes any takedown law dangerous: a tool built to pull down a fake of you can also be aimed at a parody, a news clip, or a critic, and whether it gets misused depends entirely on how narrow the exemptions are written, which is exactly the fight happening now. Action this week: If you make anything public, a performer, a creator, a small-business owner whose face is your brand, read what the bill actually protects and how a takedown would work (track it by its name on congress.gov), because if it becomes law the move on a stolen-likeness deepfake will be a notice to the platform, not a lawsuit. If free speech is your worry instead, the EFF has an open campaign laying out the over-removal risk and a way to tell your senators where you stand (eff.org). Either way, this is the rare AI rule being decided while you can still weigh in on the wording.

deadline.com: NO FAKES Act advances out of Senate Judiciary Committee (June 18, 2026)
rollcall.com: AI deepfakes bill advanced by Senate Judiciary Committee (June 18, 2026)
eff.org: Tell Congress: Just say no to NO FAKES (June 9, 2026)

2. The FCC wants a government ID on every phone account, which would end the anonymous phone.

Federal regulatory action, this time on who is allowed to be unnamed.

The Federal Communications Commission has put out a proposal that would require the companies that originate phone service, the carriers, to collect and store a name, physical address, government-issued ID number, and an alternate phone number for essentially every customer, new and renewing. The agency frames it as a Know Your Customer step to cut down on illegal robocalls, which it ties to roughly $850 million a year in scam losses, and to make phone numbers easier for law enforcement to trace back to a real person. It is a proposal, not a rule, and that distinction is the whole story right now: the public comment window is open, with comments due June 25 and reply comments due July 27, after which the FCC decides whether to finalize anything.

What the FCC calls customer verification, its critics call the end of the anonymous phone. Reporting by 404 Media and a widely-shared write-up by security expert Bruce Schneier on June 15 make the same point: the practical effect would be to eliminate the prepaid or "burner" phone, a phone whose account is not tied to an identified person. Schneier compares the requirement to the government phone registries kept in authoritarian states, and notes that burner phones barely slow down the scammers the rule is supposed to catch, while the people who actually rely on an unregistered phone, a teenager, someone fleeing an abuser, a journalist's source, a traveler who does not want a contract, would be the ones who lose the option. The honest framing is the gap between the stated goal and the built result: the FCC says robocalls, but what it would build is a nationwide registry linking every phone to a verified identity.

Why this matters: If you have ever bought a cheap prepaid phone for a kid, for a trip abroad, for a safety plan, or simply because you did not want to hand a carrier a contract and an ID, this proposal would require a government ID to do any of that, and it would put your identity behind a phone number that today you can keep separate from your name. The decision is not final, and that is the point worth acting on: this is a federal proposal in its public comment phase, and the comment window is the lever, not a lawsuit later. Action this week: If you want a say, you can file a comment in the FCC's electronic docket before June 25, which takes about ten minutes at fcc.gov and is exactly the kind of public input these proceedings are required to weigh. Read Schneier's breakdown first (schneier.com) so your comment names the specific tradeoff, scam-call traceability against a permanent identity-to-phone registry. If you manage devices or telecom for an organization, start mapping what an identity-collection-and-retention mandate would mean for the records you would suddenly be required to keep.

schneier.com: The FCC wants to eliminate burner phones (June 15, 2026)
404media.co: The FCC wants to kill burner phones by forcing telecoms to get all customers' IDs (June 2026)
androidauthority.com: The FCC could effectively kill burner phones (June 2026)

PickBits Daily Signal is free. If this lands in your inbox every day and it is worth something to you, the best way to support it is to share it with someone who would read it. Subscribe at pickbitsai.substack.com.

3. A flaw in Microsoft's Copilot let a single click turn your work AI into a data thief.

The security beat, where the AI you were told to trust at work is the attack surface.

On June 15, researchers at Varonis disclosed a vulnerability in Microsoft 365 Copilot, tracked as CVE-2026-42824 and nicknamed SearchLeak. The attack starts with a link that points at a real microsoft.com Copilot address, so it looks safe. When the victim clicks it, the search text packed into the link is read by Copilot as instructions rather than as a search query, a class of attack called prompt injection, and those instructions tell Copilot to rummage through the victim's own mailbox, files, and calendar and quietly ship what it finds to the attacker by hiding the data inside an image request. Because Copilot runs with the signed-in user's own permissions, the attacker inherits that access without ever logging in or stealing a password.

Be precise about what was at risk, because the scary version overstates it. SearchLeak could read email and mailbox contents, SharePoint and OneDrive files, and calendar data, and because one-time login codes and password-reset links arrive in your inbox, those were among the things it could pull, but it did not break two-factor authentication itself; it read the codes that were already sitting in the email. Microsoft deployed a fix on its own servers before the disclosure, so customers did not have to patch anything. Varonis rates it critical, though the formal severity score lands in the mid range, and the company's real point is the pattern: this is the second time they have demonstrated the same root cause, an AI assistant that still cannot reliably tell the difference between a trusted instruction from its user and untrusted text it was handed by a webpage or a link.

Why this matters: If your job runs on Microsoft 365 and your company switched on Copilot, an assistant you were told to trust could be talked into reading your inbox by a link you clicked once, and you would never see it happen. The bigger pattern is the one to hold onto: AI assistants are being wired into the systems that hold a company's most sensitive data faster than anyone has solved the core problem of getting them to ignore malicious instructions hidden in ordinary content. This specific hole is closed, but the shape of it is not going away. Action this week: The fix is already applied for you, so no patch is needed, but the habit change is real, treat a link that opens an AI tool with the same suspicion you would a link that opens a login page. If you run IT or security, read the Varonis write-up (varonis.com/blog/searchleak), then review exactly what data Copilot can reach with each user's permissions, because the blast radius of the next bug like this is whatever you have let the assistant see. And start treating "AI feature that reads your data and acts on instructions found in content" as its own risk category, not a one-time CVE to close and forget.

varonis.com: SearchLeak, a critical Microsoft 365 Copilot vulnerability (June 15, 2026)
thehackernews.com: One-click Microsoft 365 Copilot flaw exposed user data (June 2026)
bleepingcomputer.com: New attack turned Microsoft 365 Copilot into a 1-click data theft tool (June 2026)

4. Bernie Sanders proposed taxing the AI giants until every American gets a yearly check.

The other direction, a proposal about who should own what AI is building.

On June 18, Senator Bernie Sanders introduced the American AI Sovereign Wealth Fund Act, shown first to the Associated Press. The premise is that the wealth AI generates is concentrating in a handful of companies and their shareholders, and the public, whose data trained the models and whose jobs the models may replace, should hold a direct stake in the upside. The mechanism is a one-time 50% tax, paid in company stock, on AI firms with more than $200 million in annual AI revenue; those shares would go into a public sovereign wealth fund. Sanders estimates that fund at roughly $7 trillion at today's valuations, and says a dividend of about 5% a year off it could send every American a check over $1,000 annually.

The caveats are the honest part of the story. The $7 trillion is an estimate "at current valuations," not a fixed number, so it rises and falls with the AI giants' stock prices, and the $1,000-plus check is a projection off that estimate, not a guaranteed payout. And this is a bill that has been introduced, not a law: Roll Call calls it unlikely to pass under a Republican-controlled Congress, and Sanders has said he has not spoken to the White House about it. What makes it worth your attention is not the odds. It is that the question underneath, who owns the gains from AI, the companies building it or the public absorbing its costs, is now written as actual proposed Senate text instead of a talking point. Read alongside the deepfake bill at the top of this edition, the shape of the week comes clear: lawmakers are starting to decide both what AI is allowed to take from you and what it owes you in return.

Why this matters: The pitch for AI has always been that it will create enormous wealth, and the question nobody in power had put on paper until this week is who actually gets it, with this bill being the first concrete answer that routes some of it back to ordinary people directly. It connects straight to the fights this newsletter has tracked all month, the household asked to subsidize the power lines feeding a data center, the worker whose job is on the automation list, because those are the same people a public AI fund would pay. Action this week: Read the actual proposal rather than the headline number (sanders.senate.gov), and pay attention to the design choice, that it hands the public equity rather than collecting an income tax, because that mechanism, not the $7 trillion estimate, is the part that would actually be debated. The next time you hear that "AI will make everyone richer," you now have a specific test for whether "everyone" means you or a cap table, and a name to watch as the bill either gets a number and hearings or quietly stalls.

rollcall.com: Sovereign wealth fund, tax on AI companies unveiled by Sanders (June 18, 2026)
sanders.senate.gov: Sanders introduces legislation to create a $7 trillion AI sovereign wealth fund (June 18, 2026)
whec.com (AP): Bernie Sanders unveils plan to give the public direct ownership of AI companies (June 18, 2026)

» What to watch this week

Tomorrow's signal lands here.