> daily_signal(2026_07_16)
California stripped the ID-check-to-browse expansion out of its age-gating law, the first age-gating push to get beaten back all summer.
PickBits Daily Signal · Thursday, July 16, 2026
// tl;dr
- California's legislature removed the browser-and-website expansion from A.B. 1856, and the EFF dropped its opposition to the bill. A.B. 1043 already requires operating systems and app stores to collect ages and bracket users; A.B. 1856 was the vehicle to push those checks out to browsers and websites. That language is gone, an earlier amendment exempted open-source operating systems, and the EFF still calls the underlying law a threat to online anonymity.
- A breach spilled Suno's source code and training manifests: 2,013,545 YouTube Music clips, about 113,879 hours, plus Deezer, Genius, Pond5, Jamendo, Freesound, IMSLP, MuseScore, and podcast feeds. Suno has said it trained on essentially all music of reasonable quality on the open internet and calls that fair use. The manifests itemize it: which sources, how many clips, how many hours.
- 23andMe reached an $18 million settlement with 42 state attorneys general over the October 2023 breach that exposed genetic and ancestry data on 6.9 million people. Investigators found no protections against stolen-credential attacks. The company first denied the breach, then blamed customers for it. The settlement locks in customers' right to delete their data and have their physical samples destroyed, indefinitely.
- Google signed a virtual power-purchase agreement for 100% of the initial output of Arkansas's Steel River Energy Center: 1.6 GW of solar and 2 GW of battery storage, online in 2029. The full project is planned at 2.45 GW of solar and 2.9 GWh of storage, the largest US development of its kind to break ground. Google's electricity use rose 37% last year, driven by AI. It gets the credits, not the electrons.
Since late June, we have covered the KIDS Act and the whistleblower-unmasking database inside it, Britain preparing to point face-scanning AI at asylum-seeking children, the Supreme Court letting Texas's app-store age law take effect, and Illinois passing a device-level version its governor is being urged to veto. Every one of those put ID checks in more places. Today, for the first time, one moved back: California, the state whose laws become everyone's compliance baseline, deleted the piece that would have put an ID checkpoint in front of the open web. Elsewhere today, Suno's training data now has row counts. 23andMe's breach ended with a deletion right written into a settlement instead of a promise in a blog post. And the data-center power crunch, which we have mostly covered as strain on grids and ratepayers, spent the week financing the largest solar-and-storage build in the country.
Today: California dropped ID checks for browsers and websites from A.B. 1856, Suno's leaked manifests itemize 2,013,545 scraped YouTube Music clips, 42 states made 23andMe fund its breach victims' permanent right to delete their DNA, and Google bought the entire first phase of a 2.45-gigawatt Arkansas solar-and-storage project.
1. California deleted the ID-check-to-browse expansion from its age-gating law, and the EFF stood down.
The browser expansion is dead. The app-store age law under it is still on the books.
California's A.B. 1043, passed in 2025, already requires operating systems and app stores to collect users' ages and sort them into brackets. A follow-on bill, A.B. 1856 from Assemblymember Buffy Wicks, had been the vehicle to extend that same framework to browsers and websites, an identity check on loading a webpage. On July 15, the Electronic Frontier Foundation confirmed the legislature removed that expansion language, and, together with an earlier amendment exempting open-source operating systems, that was enough for the EFF to withdraw its opposition to the amended bill.
The retreat is narrow, and the EFF is explicit about that. It still calls A.B. 1043 problematic, because a system that verifies your age ends up holding data that ties your identity to your device, and people speak and browse differently once somebody holds that. What died this week is the worst-case version: verify your age to load a webpage, in the state whose rules the rest of the industry builds to. The app-store age law underneath it survives, and other states are pushing the same expansion. The KIDS Act passed the House this month with the same expansion ambition at federal scale, and Illinois just passed a device-level age-gating bill that digital-rights groups are asking Governor Pritzker to veto. One state stepping back does not reverse the trend. It does mean every group fighting one of these bills just watched the fight work in Sacramento, and they will all cite it.
eff.org: California steps back from dangerous expansion of its age-gating law (July 15, 2026)
leginfo.legislature.ca.gov: A.B. 1856 bill text as amended (2026)
leginfo.legislature.ca.gov: A.B. 1043 bill text (2025)
2. A breach handed the record industry what its Suno lawsuits have been missing: an itemized training list.
The leaked manifests list exactly what Suno trained on, down to the clip count.
A breach of Suno, one of the largest AI music generators, exposed the company's source code and its training manifests. The manifests name sources and count them: 2,013,545 clips from YouTube Music, about 113,879 hours; 12,287 hours from Deezer; 17,615 hours from Genius; plus Pond5, Jamendo, Freesound, the International Music Score Library Project, MuseScore, and podcast RSS feeds. The datasets total at least decades' worth of music. Suno has already said publicly that it trained on essentially all music files of reasonable quality accessible on the open internet, tens of millions of recordings, and argues that doing so is fair use. It faces several major record-industry lawsuits; one has reportedly been settled.
Suno admitting it trained broadly is not news. Suno never said it didn't scrape. Its defense is that scraping is legal, and the manifests do not settle that question. The RIAA has specifically accused Suno of scraping YouTube content, and a manifest labeled youtube_music with a seven-digit row count moves that from allegation to something a plaintiff can put in front of a judge. It also pulls in platforms whose terms forbid scraping, YouTube, Deezer, and Genius among them, who now have their own paper trail whether or not they wanted this fight. We watched authors turn down Anthropic's $1.5 billion settlement last week betting a judge gives them more, and Patreon lock training crawlers out of paid work entirely. Every one of those fights changes when the training data is an itemized list instead of an estimate.
404media.co: Hack reveals Suno AI music generator scraped YouTube, Deezer, and Genius (July 15, 2026)
riaa.com: Recording Industry Association of America (litigation hub)
blog.youtube: YouTube official blog
3. 23andMe will pay 42 states $18 million, and every customer keeps the right to delete their DNA, forever.
Genetic data on 6.9 million people leaked, and genetic data cannot be reset.
23andMe agreed to an $18 million settlement with 42 state attorneys general over the October 2023 breach that exposed genetic and ancestry data on 6.9 million people. The investigation's findings read like a security audit from a much smaller company: no protections against attacks using stolen credentials, insufficient intrusion prevention. The breach itself was credential stuffing, attackers replaying passwords leaked from other sites. And the company's response at the time made it worse: it initially denied that a breach had occurred, then, after confirming it, blamed customers for how their accounts were configured. The settlement mandates new security requirements and preserves two rights indefinitely: customers can delete their personal data, and they can have their physical genetic samples destroyed.
The two rights matter more than the dollar figure because of what happened to the data while the lawyers worked. 23andMe filed for bankruptcy in March 2025, and after a $305 million asset sale in July 2025, the genetic database moved to the 23andMe Research Institute, a nonprofit founded by former CEO Anne Wojcicki. So one of the most sensitive consumer datasets in the country changed hands in the middle of the lawsuit about protecting it. Money alone would have gone to a company that no longer even holds the data. The deletion right follows the DNA itself, to whoever holds it next, and that is what the states got.
therecord.media: 23andMe reaches $18 million settlement with states for massive breach (July 15, 2026)
oag.ca.gov: California Attorney General press releases
23andme.com: account and data-deletion settings
4. Google's AI power bill just financed the biggest solar-and-storage project ever to break ground in the US.
The power demand we keep covering as a problem just financed record supply.
Google signed a long-term virtual power-purchase agreement with developer Cypress Creek Renewables for the Steel River Energy Center in Mississippi County, Arkansas. The full project is planned in three phases totaling 2.45 gigawatts of solar and 2.9 gigawatt-hours of battery storage, with batteries from LG Energy Solution, and is described as the largest solar development of its kind to break ground in the US. Google takes 100% of the initial output, 1.6 GW of solar and 2 GW of battery storage, roughly enough to power 315,000 homes, once it comes online in 2029. The demand side is not subtle: Google's electricity consumption rose 37% last year, driven largely by AI infrastructure.
This is a virtual PPA. Google gets the environmental credits at a fixed price; the electrons go to the grid, and Google's data centers keep drawing whatever mix their local grids serve. Critics point out that this output could simply power those 315,000 homes instead, and they are not wrong. But a project this size does not get built without a creditworthy buyer signed up for decades of output, and the 2.9 GWh of storage, the part that makes solar useful around the clock, is exactly the piece that needs that guarantee. We have covered this arc almost entirely as strain: Seattle engineers investigated for testifying about data-center growth, the Ratepayer Protection Act fight over who pays for the wires, Utah betting on nuclear. Today is the first entry in a while where AI demand is the reason a record-scale clean-energy project got financed.
engadget.com: Google buys Steel River Energy Center's Arkansas solar output to offset emissions (July 14, 2026)
canarymedia.com: Google backs record Arkansas solar-and-battery site (July 2026)
» What to watch this week
- Whether the amended A.B. 1856 passes and where the browser expansion resurfaces. The KIDS Act is in front of the Senate and Illinois's device-level bill is on Governor Pritzker's desk; California proved the expansion can be stripped, and the next few weeks show whether anyone else follows.
- Whether the Suno manifests make it into discovery, and whether YouTube, Deezer, or Genius act on their own terms of service. The record-industry suits were built on inference and admissions, so watch for a plaintiff moving to authenticate the breached documents, and for a platform filing its own claim, which would widen the fight past the labels.
- Whether the remaining states join the 23andMe settlement and whether the Research Institute honors deletion requests at scale. The right exists on paper now; the test is a nonprofit under no revenue pressure processing millions of deletion and sample-destruction requests without friction.
- Whether Steel River's phases two and three reach financing, and who copies the full-output offtake. If phases two and three get financed, and a second hyperscaler signs a full-output deal like this one, this stops being a one-off and starts being how AI demand gets built into the grid.
Tomorrow's signal lands here.