> daily_signal(2026_08_06)

For the second time, a feature you pay Apple for leaks what it promised to hide, the same day a lawsuit says Walmart keeps your voiceprint and the UK moves to curb software that watches you work.

PickBits Daily Signal · Thursday, August 6, 2026

By Mark Pickering · 8 min read · August 6, 2026

// tl;dr

The Apple one is what stuck with me. You pay for iCloud Private Relay specifically so websites cannot see your real IP, and it turns out a single passkey login hands it right over. That is the second Apple privacy feature caught doing the opposite of what it sells, after Hide My Email, and it is why I no longer trust a privacy toggle I cannot test myself. Walmart, meanwhile, is accused of quietly keeping a voiceprint of everyone who calls, the same claim a judge just let proceed against Meta. The UK is trying to make bosses ask before they switch on the keystroke loggers, which is more than the US has ever required. And Akido, for once, pointed AI the other way, at doing a doctor's paperwork so the doctor can actually look at you.

The privacy feature you pay Apple to hide your IP address spent the day leaking it, and it was not the only thing quietly collected from you today.

1. Apple's Private Relay was supposed to hide your IP address. Researchers just showed it doesn't.

The privacy feature you pay Apple to hide your IP address has been handing it out anyway. Researchers Tommy Mysk and Talal Haj Bakry showed that iCloud Private Relay, the iCloud Plus feature marketed as a shield that stops the sites you visit from seeing your real IP, can be bypassed entirely, and the holes are in WebKit, the browser engine Apple requires every iOS browser to use. So this is not a Safari setting you can switch away from; it is systemic to the platform. The cleanest bypass runs through passkeys: when a website triggers a passkey login request, the phone answers the server directly, outside the browser stack Private Relay proxies, and that request carries your true IP. TechCrunch reproduced the leak on the researchers' test page, leaks.psylo.app, on August 5. The two also flagged DNS prefetching and the WebTransport protocol as separate paths to the same exposure.

By their own account, the researchers skipped Apple's disclosure window, pointing to months of delays on past reports, and published a working demo instead. I get why they skipped Apple's process. The part that matters is that this keeps happening: this is the second Apple privacy feature in recent memory caught doing the opposite of its promise. Hide My Email, sold to keep your real address hidden, was found exposing it too. That is the dangerous part of a half-working privacy tool. You act like you are covered, and you are not.

Screenshot of TechCrunch's August 5 report on Apple's iCloud Private Relay leaking users' real IP addresses
techcrunch.com · August 5, 2026
Why this matters: The one place this actually bites is in court. A privacy promise with a hole in it is a marketing claim, and a marketing claim is something a consumer can actually challenge in court. Honestly, Apple keeps shipping the promise well ahead of the product, and the only thing that has ever slowed that down is getting sued. Action this week: Test your own exposure at the researchers' page, leaks.psylo.app, and stop treating Private Relay as a VPN, because it only ever protected Safari traffic. If hiding your IP genuinely matters to you, run a full-tunnel VPN instead. Watch for an Apple WebKit or iOS update that addresses the passkey origin request, and install it the day it ships.

techcrunch.com: PSA: Apple's Private Relay can leak your real IP address (August 5, 2026)
404media.co: Apple's Private Relay is exposing users' real IP addresses (August 2026)
9to5mac.com: iCloud Private Relay can leak your real IP address, researchers find (August 5, 2026)

2. Call a Walmart store, and a lawsuit says its AI quietly keeps a voiceprint of you.

Call a Walmart store to ask about a return, and its AI voice line may be quietly building a permanent print of your voice. That is the claim in Smith v. Walmart, Case No. 1:26-cv-07861 in the Northern District of Illinois: that when customers call a store, Walmart's automated AI voice system collects, stores, and uses their biometric voiceprint with none of the written notice and consent Illinois's Biometric Information Privacy Act requires. A voiceprint is a biometric in the same class as a fingerprint or a face scan, which is the point of BIPA: it is the data you cannot change once it leaks. Walmart's privacy policy does disclose biometric collection, but the suit calls that disclosure inadequate, because BIPA requires affirmative written consent, not a policy line.

We watched this same fight hit Meta a few weeks ago, when a judge refused to throw out the same kind of voiceprint class action and let it proceed past summary judgment. Apple is separately defending a multi-billion-dollar biometric suit over its Photos app. Walmart says its voice templates support fraud prevention, which is a genuine use; the dispute is not whether a voiceprint can be useful but whether a company can build one from your phone call without asking. Under BIPA, that question is worth $1,000 to $5,000 per violation, and Illinois is one of the few states where a private citizen, not just a regulator, can bring the claim.

Screenshot of ClassAction.org's report on the Smith v. Walmart voiceprint biometric-privacy lawsuit in Illinois
classaction.org · July 2026
Why this matters: Your voice just became a permanent ID a retailer keeps, captured on a call you thought was about a return. To me, the fine-print disclosure gives it away: Walmart knew consent mattered and reached for the weakest version of it. What makes Illinois different is that residents there have standing to sue directly, which is why BIPA, not a federal agency, is doing the enforcement. Action this week: Keep your Walmart call records if you are an Illinois resident, because they are what put you in the putative class, and watch for a class notice. Read Walmart's current privacy policy so you know what it now claims to collect. And on any AI voice line, ask to be routed to a human and decline the recording, since consent you never gave is the entire basis of this case.

classaction.org: Walmart lawsuit claims retailer illegally collects Illinois residents' biometric voiceprints from phone calls (July 2026)
courthousenews.com: Walmart accused of collecting customers' voiceprints (July 2026)
news.bloomberglaw.com: Walmart customers sue over AI-generated voiceprints from calls (July 2026)

3. The UK is moving to make bosses ask before installing the software that watches you work.

The UK is moving toward something the US hasn't: making employers ask before they switch on the software that logs your team's keystrokes. The Department for Business and Trade opened a consultation, part of the Make Work Pay reforms and open until September 30, on whether employers must consult recognized unions or elected employee representatives before deploying workplace monitoring technology. The category it covers is deliberately broad: CCTV, location tracking, keystroke logging, AI productivity scoring, biometric systems, and automated decision-making. The Register, citing Chartered Management Institute research, puts the share of UK organizations already monitoring employees' digital activity at roughly one in three.

There is no equivalent consult-first requirement in the US, so the same bossware ships to American workers with no notice at all. Back in June we covered Amazon pulling three engineers into HR the week after they testified about a data center, and Meta exposing data out of its own employee-tracking program. The tool goes on quietly, and workers find out later, if at all. Employers will say monitoring protects security and measures output, and some of that is fair. The UK proposal does not ban the tools anyway. It just makes switching them on a conversation instead of a default.

Screenshot of The Register's August 4 report on the UK weighing a rule to make employers consult staff before installing bossware
theregister.com · August 4, 2026
Why this matters: The gap between the UK and the US is real now, and consult-first is clearly where this is heading. The companies I would not want to be right now are the ones that never wrote down what their monitoring is even for; when disclosure becomes mandatory, they are the ones scrambling. Plenty of this gets sold as productivity, but the people living under it know when it is really about control. Action this week: Inventory what monitoring software is actually deployed on your team, the productivity scoring, the keystroke logging, the in-vehicle cameras, and whether anyone was ever told. Get one answer in writing from whoever owns each contract: what does this tool collect, and how long is it kept. Treat the UK's consult-before-deploy model as the benchmark your own policy will be measured against, because it is the one regulators reach for next.

theregister.com: UK mulls making employers ask before installing bossware (August 4, 2026)
techradar.com: 85% of UK employers admit to spying on their employees, and workers aren't happy (August 2026)
peoplemanagement.co.uk: A third of UK firms deploy bossware to track staff activity, survey reveals (August 2026)

4. An AI that sits in on the visit just gave a million patients 5x more time with their doctor.

An AI that sits in on the doctor's visit just gave a million patients five times more face time with their clinician. The company is Akido, a Los Angeles operator of safety-net, community, and iPad-based street-medicine clinics, the kind that usually get left out, and on July 30 it announced what it calls the first AI-native health system in the US. Its tool, ScopeAI, listens during the appointment and organizes a patient's scattered history and symptoms into a diagnostic head-start in real time, so the clinician spends the visit with the person instead of the screen. This is running, not a pilot: Akido flipped its whole network of 100 clinics onto it, reaching roughly one million patients across California, New York City, and Rhode Island, and says ScopeAI was stress-tested against 203,000 real clinical encounters.

In its LA street-medicine program, Akido reports five times more face-to-face time per visit, a 55% drop in emergency-department use, 53% same-day access, and a 96 Net Promoter Score. Those are the company's own figures, not an independent study. The claims are concrete and checkable, but they still come from the vendor. An ambient system like this is also recording your most sensitive data, and clinics running these tools are not always the HIPAA-covered entities patients assume. So the thing to worry about is not the AI in the room. It is where the recording goes afterward.

Screenshot of HIT Consultant's report on Akido launching its ScopeAI AI-native health system
hitconsultant.net · July 30, 2026
Why this matters: This one is aimed at the patients usually last in line for good care, and it works by taking the typing off the doctor so the visit can actually be about the patient. That is worth rooting for. But it is listening to your appointment, and where that recording goes is the whole caveat. What I like is that the AI took the boring part, the paperwork, instead of the person's job. Action this week: Ask your clinic, if it uses an AI scribe like ScopeAI, what the tool records during your visit and where that data is stored and shared. Watch whether Akido's headline numbers, the five-times face time and the 55% fewer ER visits, hold up in independent review rather than a press release. And if you run a clinic serving underserved patients, benchmark ambient-AI vendors on those outcomes, not just on documentation speed.

hitconsultant.net: Akido unveils first AI-native health system powered by ScopeAI (July 30, 2026)
hcinnovationgroup.com: A growing Akido calls itself first AI-native health system in US (July 2026)
endpoints.news: Akido is expanding AI for patient intake and diagnoses across 100 clinics (July 2026)

» What to watch this week

Tomorrow's signal lands here.