> daily_signal(2026_08_08)

The government hired its top surveillance contractor to advise it on stopping surveillance, while a plate-reader tried to climb into your Uber and AI coding agents were turned against their own code.

PickBits Daily Signal · Saturday, August 8, 2026

By Mark Pickering · 9 min read · August 8, 2026

// tl;dr

Two of today's four stories only came to light because somebody filed a public-records request. The State Department never announced that it handed advisory seats to Palantir and Anduril; The Intercept dug it out. Flock never disclosed its plan to turn 350,000 rideshare cars into plate scanners; a resident in Dunwoody, Georgia pried the deck loose. We've watched both companies push deeper into surveillance all year, Palantir's ICE work, Flock's leaked police searches and the towns tearing its cameras down, and it keeps going the same way: nobody hears about the reach until long after it is already built. The coding-agent story runs on the same delay, an autonomous tool trusted inside CI pipelines that turned out to be reachable by any stranger with a GitHub account, nine days after we flagged exactly that risk. Then there's Jeff Dean, walking out of Google with three of the engineers behind its core systems to bet AI can run science instead of surveillance. That's the one I keep coming back to.

Palantir advises the State Department on stopping surveillance, Flock drew up a plan to scan plates from inside your Uber, researchers turned Claude Code and Gemini CLI against their own repos, and Jeff Dean left Google to point AI at science.

1. No one voted on who advises the State Department about free speech. It picked the company that builds the government's surveillance tools.

The counter-surveillance advisor holds some of the government's biggest surveillance contracts.

The U.S. government hired the company that builds its surveillance tools to advise it on how to fight surveillance. On July 24, the State Department launched the Freedom Tech Excellence Program, a public-private initiative whose founding partners — detailed in reporting by The Intercept on August 7 — are Palantir and Anduril (both tied to Peter Thiel), the Bitcoin Policy Institute, and the Victims of Communism Memorial Foundation. Under the program, employees from those partners take temporary assignments inside the department, potentially anywhere in the agency and sometimes holding security clearances, to advise on five pillars: First Amendment protections online, countering unlawful digital surveillance and scams, privacy tools like strong encryption and VPNs, responsible AI governance, and protecting children online. It runs through early 2029.

Palantir holds sprawling surveillance contracts with ICE, the NSA, and other agencies, and it has sued news outlets over critical coverage; Anduril builds autonomous defense systems. A Knight First Amendment Institute attorney told The Intercept that neither this State Department nor the partners it has named so far are trustworthy leaders in the online free expression they claim to protect. Yes, these firms employ real security talent, but you do not hire the company that builds ICE's dossiers to coach the government on restraint. This is not new ground for us. We flagged Palantir's march into government back when civil-rights lawyers sued over its AI system for mapping deportation targets, and this is the same arc reaching the one office you would least expect it to touch: the one that writes the rules on speech.

Screenshot of The Intercept's August 7 report on the State Department's Freedom Tech Excellence Program and Palantir.
theintercept.com · August 7, 2026
Why this matters: A government program's charter tells you who it is really for, and this one hands advisory access, sometimes with clearances, to companies whose core business is the surveillance the program claims to counter. The pillar that reads best on paper, privacy-enhancing tools like strong encryption, is the one those same partners have the least commercial reason to widen. My own read: the mission statement is not where this gets decided. It is which of the five pillars actually ships something, and my money says the privacy-tools one stays a bullet point. Action this week: Treat the charter as a public record and pry it loose, because the FTEP announcement and its partner agreements can be requested, and groups like the Knight Institute, the EFF, and the ACLU can FOIA those agreements to test whether "countering digital surveillance" squares with the same firms' ICE and NSA contracts. Ask your representatives to disclose what the partners advise on and whether their existing contracts create a conflict of interest. And if you just want the privacy tools the program name-checks, you do not have to wait on it: an encrypted messenger, a reputable VPN, and device encryption are yours to adopt today.

theintercept.com: State Department wants Palantir's advice on free speech and "countering digital surveillance" (August 7, 2026)
cryptobriefing.com: State Department launches Freedom Tech program with Bitcoin Policy Institute and Palantir (July 2026)
forklog.com: Palantir and the Bitcoin Policy Institute join the US State Department's digital-freedom program (July 2026)

2. Flock drew up a plan to turn 350,000 Uber and Lyft cars into plate scanners. The passengers would never have known.

Fixed plate-readers on poles, proposed for 350,000 moving rideshare cars, with no notice to anyone in the back seat.

The Uber you took this week could have been scanning every license plate it passed — and no one in the car would have known. A Flock Safety sales deck, obtained through a Georgia public-records request and first reported by 404 Media on August 7, describes tapping a "Nexar partnership which includes 350k Uber/Lyft and other delivery service devices" — turning dashcams already mounted in those cars into a mobile automated-license-plate-reader fleet feeding Flock's law-enforcement network. The deck was pitched to Georgia's attorney general in August 2025 and surfaced only because a Dunwoody, Georgia resident filed for it. Flock told 404 Media it "never executed the partnership with Nexar"; Uber, Lyft, and Nexar did not comment.

Flock's cameras already read plates from fixed poles in thousands of American neighborhoods; the pitch was to take that same computer-vision surveillance and put it on privately owned cars moving through cities, with no notice to the passenger in the back seat or the driver at the wheel. The denial matters, and "we never signed it" is not nothing. But the deal dying is not the point. Somebody at Flock sat down and worked out how to put plate-readers in 350,000 cars that people were riding inside, and that is the part that stays with me. We have tracked this company all summer: the police search queries that leaked out of its system through ordinary web indexing, whole towns voting to rip the cameras down, its newer product quietly linking Bluetooth device IDs to plates. Putting the cameras in moving cars is just where this goes next for a company that keeps looking for more places to point them.

Screenshot of 404 Media's August 7 report on Flock's plan to turn Uber and Lyft cars into surveillance vehicles.
404media.co · August 7, 2026
Why this matters: My own read is that the denial is the least interesting part — the pitch itself is the signal, because it shows where a company like this wants to go once the cameras on poles are not enough. There is now a real chance the car you hire is recording more than your route, and the data it captures is controlled by the device maker and its partners, not by you or the driver. Action this week: Open your dashcam app's data-sharing settings if you drive rideshare, and check whether captured video or plate data can be sold or shared with a third-party network, then opt out where you can. As a passenger, ask whether a vehicle has an active dashcam, since many states already require drivers to disclose recording, and treat the footage as the device maker's, not yours. And the way that Dunwoody resident found this out is open to you too: a public-records request to your own city or state will tell you whether Flock has pitched or deployed here, which is the fastest way to force a notice-and-consent rule before consumer cars get enrolled in a surveillance network.

404media.co: Flock pitched a plan to turn Uber and Lyft drivers into roaming surveillance vehicles (August 7, 2026)
gizmodo.com: Flock reportedly tried to turn Uber drivers into mobile plate scanners (August 2026)
decrypt.co: Flock eyed Uber drivers for a nationwide plate-scanning fleet (August 2026)

3. If your team runs AI coding agents in CI, settle one thing before Monday: can an outsider's GitHub issue run code in your pipeline?

An anonymous GitHub issue reached remote code execution in three of the most-used coding agents.

If your developers run Claude Code, Gemini CLI, or Codex in CI, an outsider's GitHub issue could execute code inside your pipeline. Novee Security, in research presented around Black Hat USA 2026 and reported on August 7, showed that all three of the most widely deployed AI coding agents failed to contain prompt-injection instructions hidden in a GitHub issue or pull request opened by an anonymous user with no repository privileges — letting that injected text reach remote code execution inside CI/CD and expose workflow secrets like GITHUB_TOKEN and ANTHROPIC_API_KEY, with no human in the loop.

Google's Gemini CLI flaw (CVE-2026-12537), an OS command injection reachable through a crafted .gemini/.env file before the sandbox starts, was rated a maximum CVSS 10.0 and fixed in Gemini CLI 0.39.1 and run-gemini-cli 0.1.22. Anthropic's Claude Code flaw (CVE-2026-54316) affected versions 0.2.54 through 2.1.162, was patched in 2.1.163, and turned a Hugging Face public download counter into a channel that leaked an API key one character at a time. OpenAI's Codex had no CVE and was addressed with a workflow-separation fix. Every vendor patched within days — but Novee says it found the same vulnerable defaults live on well over a hundred other public repositories, and the Gemini component alone reaches roughly two million monthly installs downstream. This is the concrete version of a warning we ran on July 30, nine days after OpenAI open-sourced a free tool to scan code for vulnerabilities: the agents doing that kind of work are themselves the hole.

Screenshot of The Hacker News's August report on Claude Code and Gemini CLI flaws that let attackers run code.
thehackernews.com · August 7, 2026
Why this matters: We have been saying for weeks that an autonomous agent with repo access is a new attack surface, and this is the version with CVEs attached: an anonymous stranger, zero privileges, reaching code execution on your runner. The patches close the specific bugs; they do not change the shape of the risk, which is that any agent acting on untrusted GitHub content is effectively internet-facing. When I have asked vendors "what can this thing do without a human approving it," the honest answer is usually broader than the demo suggests. Action this week: Confirm you are on the patched releases — Claude Code 2.1.163 or later, Gemini CLI 0.39.1 / run-gemini-cli 0.1.22 or later, and OpenAI's workflow-separation fix — and then get one question answered in writing: can anything an outsider posts, an issue, a pull request, or a comment, reach an agent that runs shell commands before a person says yes? Inventory where these agents hold write or execution access in CI, scope their credentials to least privilege, and add egress monitoring for the covert channels shown here, like outbound calls to a model-hub download counter. If you own your organization's software inventory, send this to whoever signs off on that pipeline.

thehackernews.com: Claude Code and Gemini CLI flaws let attackers turn AI agents against their own repos (August 7, 2026)
novee.security: Critical flaws in Anthropic, Google, and OpenAI's coding agents (August 2026)
novee.security: Google Gemini CLI RCE vulnerability, CVSS 10.0 critical security advisory (August 2026)

4. Jeff Dean and three of Google's top AI minds quit to build an AI that does science, for anyone waiting on a cure that is still stuck in the lab.

The people who built Google's infrastructure now want AI running lab experiments, not ranking your feed.

The people who built modern AI just quit Google to build an AI that does science itself. On August 5, Google chief scientist Jeff Dean — roughly the company's 30th employee, nearly 27 years in — announced he is leaving to co-found Discovery Loop, a public benefit corporation built to automate the experimental loops of scientific and engineering research. Co-founding with him are Sanjay Ghemawat, the engineer behind much of Google's core infrastructure; Oriol Vinyals, a senior research scientist at Google DeepMind; and Quoc Le, a founding member of Google Brain. The plan is to use frontier models and large-scale compute to propose, run, and learn from thousands of experiments at once — starting with machine-learning research and generalizing to any "learning loop with measurable outcomes." Alphabet joined the initial round alongside Radical Ventures and Khosla Ventures.

Dean's pitch is explicitly constructive: "a higher quantity and a higher quality of experiments," as he put it, "and that will lead to scientific breakthroughs and advances." I want to believe it. But "automate science" is the phrase every AI lab is chasing right now, and our own archive is full of the run-up to it: DeepMind's Co-Scientist in May, its Gemini for Science tools, a stack of arXiv papers on autonomous discovery, impressive work that has mostly stayed in the demo stage. What makes this one different is not the mission statement; it is the four signatures under it. The names on it are the ones behind Google's core infrastructure and its biggest AI systems, they are betting their next decade on this, and Alphabet's money is behind them.

Screenshot of TechCrunch's August 5 report on Jeff Dean leaving Google to launch Discovery Loop.
techcrunch.com · August 5, 2026
Why this matters: Jeff Dean built the systems that let Google's search scale, then much of the infrastructure the current AI boom runs on, so when he leaves to chase automated science it is worth taking seriously, even if I am not sold yet. The honest read is that this is announced and funded, not yet running results; the gap between "we can run thousands of experiments" and "we produced a new material" is exactly where the co-scientist demos have stalled before. Action this week: Watch for the first published result in a domain that is not machine learning, a molecule, a material, a measurable outcome, because that is the line between a well-funded pitch and a working method. If you run an R&D or lab team, benchmark Discovery Loop's stated model, an AI proposing, running, and evaluating experiments, against your own automated-experimentation efforts, and press any "AI scientist" claim for which scientific domain it actually took on first. It is a good note to end the day on, and the first non-ML result is when we will actually know it is real.

techcrunch.com: Jeff Dean and other top AI researchers are leaving Google to launch their own startup (August 5, 2026)
cnbc.com: Google chief scientist Jeff Dean leaving the company after 27 years (August 5, 2026)

» What to watch this week

Tomorrow's signal lands here.