> daily_signal(2026_08_06)
For the second time, a feature you pay Apple for leaks what it promised to hide, the same day a lawsuit says Walmart keeps your voiceprint and the UK moves to curb software that watches you work.
PickBits Daily Signal · Thursday, August 6, 2026
// tl;dr
- Apple's iCloud Private Relay, the paid feature that promises to hide your IP address, has been leaking it. Researchers Tommy Mysk and Talal Haj Bakry found three flaws in WebKit, the engine every iOS browser must use, that let a website pull your real IP through a passkey request. They published without warning Apple, citing past delays, and there is no fix announced yet.
- Call a Walmart store and an AI voice system may be building a permanent voiceprint of you without consent, a new Illinois lawsuit says. Smith v. Walmart claims the company captured customers' voice biometrics with no written consent and no deletion policy, which Illinois's BIPA law forbids. Statutory damages run $1,000 to $5,000 per violation.
- The UK moved to make employers consult staff before switching on monitoring software, a line the US has not drawn. A Department for Business and Trade consultation, open until September 30, would require consulting unions or elected reps before deploying keystroke logging, AI productivity scores, or biometric badges. Roughly one in three UK organizations already monitors workers' digital activity.
- An AI that listens in on the doctor's visit gave a million patients five times more face time with their clinician, its maker says. Akido flipped its 100 clinics onto ScopeAI, which organizes a patient's history in real time, and reports a 55% drop in ER visits in its LA street-medicine program. The caveat is what it records.
The Apple one is what stuck with me. You pay for iCloud Private Relay specifically so websites cannot see your real IP, and it turns out a single passkey login hands it right over. That is the second Apple privacy feature caught doing the opposite of what it sells, after Hide My Email, and it is why I no longer trust a privacy toggle I cannot test myself. Walmart, meanwhile, is accused of quietly keeping a voiceprint of everyone who calls, the same claim a judge just let proceed against Meta. The UK is trying to make bosses ask before they switch on the keystroke loggers, which is more than the US has ever required. And Akido, for once, pointed AI the other way, at doing a doctor's paperwork so the doctor can actually look at you.
The privacy feature you pay Apple to hide your IP address spent the day leaking it, and it was not the only thing quietly collected from you today.
1. Apple's Private Relay was supposed to hide your IP address. Researchers just showed it doesn't.
The privacy feature you pay Apple to hide your IP address has been handing it out anyway. Researchers Tommy Mysk and Talal Haj Bakry showed that iCloud Private Relay, the iCloud Plus feature marketed as a shield that stops the sites you visit from seeing your real IP, can be bypassed entirely, and the holes are in WebKit, the browser engine Apple requires every iOS browser to use. So this is not a Safari setting you can switch away from; it is systemic to the platform. The cleanest bypass runs through passkeys: when a website triggers a passkey login request, the phone answers the server directly, outside the browser stack Private Relay proxies, and that request carries your true IP. TechCrunch reproduced the leak on the researchers' test page, leaks.psylo.app, on August 5. The two also flagged DNS prefetching and the WebTransport protocol as separate paths to the same exposure.
By their own account, the researchers skipped Apple's disclosure window, pointing to months of delays on past reports, and published a working demo instead. I get why they skipped Apple's process. The part that matters is that this keeps happening: this is the second Apple privacy feature in recent memory caught doing the opposite of its promise. Hide My Email, sold to keep your real address hidden, was found exposing it too. That is the dangerous part of a half-working privacy tool. You act like you are covered, and you are not.
techcrunch.com: PSA: Apple's Private Relay can leak your real IP address (August 5, 2026)
404media.co: Apple's Private Relay is exposing users' real IP addresses (August 2026)
9to5mac.com: iCloud Private Relay can leak your real IP address, researchers find (August 5, 2026)
2. Call a Walmart store, and a lawsuit says its AI quietly keeps a voiceprint of you.
Call a Walmart store to ask about a return, and its AI voice line may be quietly building a permanent print of your voice. That is the claim in Smith v. Walmart, Case No. 1:26-cv-07861 in the Northern District of Illinois: that when customers call a store, Walmart's automated AI voice system collects, stores, and uses their biometric voiceprint with none of the written notice and consent Illinois's Biometric Information Privacy Act requires. A voiceprint is a biometric in the same class as a fingerprint or a face scan, which is the point of BIPA: it is the data you cannot change once it leaks. Walmart's privacy policy does disclose biometric collection, but the suit calls that disclosure inadequate, because BIPA requires affirmative written consent, not a policy line.
We watched this same fight hit Meta a few weeks ago, when a judge refused to throw out the same kind of voiceprint class action and let it proceed past summary judgment. Apple is separately defending a multi-billion-dollar biometric suit over its Photos app. Walmart says its voice templates support fraud prevention, which is a genuine use; the dispute is not whether a voiceprint can be useful but whether a company can build one from your phone call without asking. Under BIPA, that question is worth $1,000 to $5,000 per violation, and Illinois is one of the few states where a private citizen, not just a regulator, can bring the claim.
classaction.org: Walmart lawsuit claims retailer illegally collects Illinois residents' biometric voiceprints from phone calls (July 2026)
courthousenews.com: Walmart accused of collecting customers' voiceprints (July 2026)
news.bloomberglaw.com: Walmart customers sue over AI-generated voiceprints from calls (July 2026)
3. The UK is moving to make bosses ask before installing the software that watches you work.
The UK is moving toward something the US hasn't: making employers ask before they switch on the software that logs your team's keystrokes. The Department for Business and Trade opened a consultation, part of the Make Work Pay reforms and open until September 30, on whether employers must consult recognized unions or elected employee representatives before deploying workplace monitoring technology. The category it covers is deliberately broad: CCTV, location tracking, keystroke logging, AI productivity scoring, biometric systems, and automated decision-making. The Register, citing Chartered Management Institute research, puts the share of UK organizations already monitoring employees' digital activity at roughly one in three.
There is no equivalent consult-first requirement in the US, so the same bossware ships to American workers with no notice at all. Back in June we covered Amazon pulling three engineers into HR the week after they testified about a data center, and Meta exposing data out of its own employee-tracking program. The tool goes on quietly, and workers find out later, if at all. Employers will say monitoring protects security and measures output, and some of that is fair. The UK proposal does not ban the tools anyway. It just makes switching them on a conversation instead of a default.
theregister.com: UK mulls making employers ask before installing bossware (August 4, 2026)
techradar.com: 85% of UK employers admit to spying on their employees, and workers aren't happy (August 2026)
peoplemanagement.co.uk: A third of UK firms deploy bossware to track staff activity, survey reveals (August 2026)
4. An AI that sits in on the visit just gave a million patients 5x more time with their doctor.
An AI that sits in on the doctor's visit just gave a million patients five times more face time with their clinician. The company is Akido, a Los Angeles operator of safety-net, community, and iPad-based street-medicine clinics, the kind that usually get left out, and on July 30 it announced what it calls the first AI-native health system in the US. Its tool, ScopeAI, listens during the appointment and organizes a patient's scattered history and symptoms into a diagnostic head-start in real time, so the clinician spends the visit with the person instead of the screen. This is running, not a pilot: Akido flipped its whole network of 100 clinics onto it, reaching roughly one million patients across California, New York City, and Rhode Island, and says ScopeAI was stress-tested against 203,000 real clinical encounters.
In its LA street-medicine program, Akido reports five times more face-to-face time per visit, a 55% drop in emergency-department use, 53% same-day access, and a 96 Net Promoter Score. Those are the company's own figures, not an independent study. The claims are concrete and checkable, but they still come from the vendor. An ambient system like this is also recording your most sensitive data, and clinics running these tools are not always the HIPAA-covered entities patients assume. So the thing to worry about is not the AI in the room. It is where the recording goes afterward.
hitconsultant.net: Akido unveils first AI-native health system powered by ScopeAI (July 30, 2026)
hcinnovationgroup.com: A growing Akido calls itself first AI-native health system in US (July 2026)
endpoints.news: Akido is expanding AI for patient intake and diagnoses across 100 clinics (July 2026)
» What to watch this week
- Whether Apple ships a WebKit fix for the passkey origin request, and whether this failure draws the kind of false-advertising challenge Apple's other privacy tools have. A patch is the easy part. What actually matters is whether a second privacy-feature failure turns Private Relay into a legal problem, not just a technical one.
- Whether Smith v. Walmart survives Walmart's motion to dismiss, coming off the Meta voiceprint case that just cleared summary judgment. The BIPA voiceprint theory is being tested on a second big defendant in a month, and if both hold up, more companies running AI phone lines are going to get sued over it.
- Whether the UK consultation, open until September 30, lands as a real consult-first requirement or a watered-down guidance note. Watch whether it keeps the broad definition of monitoring technology or lets employers carve out "security" tools until the rule is hollow.
- Whether Akido's ScopeAI numbers hold up outside its own reporting, and whether regulators ask what the tool records. The face-time and ER-visit figures are the kind of claim that either survives an independent look or quietly disappears from the next press release; the data-handling question has barely been asked.
Tomorrow's signal lands here.