> daily_signal(2026_08_16)

Flock rewrote its own surveillance rules, Amazon opted every Twitch streamer into AI training, ChatGPT started logging your keystrokes, and Penn gave clinics an AI they can inspect.

PickBits Daily Signal · Sunday, August 16, 2026

By Mark Pickering · 8 min read · August 16, 2026

// tl;dr

Flock spent the summer getting bigger and messier: Los Angeles put its contract on ice in July, and a leaked company playbook showed Flock coaching police on how to sell cameras to city councils before residents could object. This week, after a Washington Post count of 50-plus officers charged with abuse, it rewrote its own privacy rules rather than wait for anyone to write them for it. Amazon skipped asking entirely, opting every Twitch streamer into training its AI and shipping the off switch afterward, with its own product chief admitting an opt-in version would get no takers. OpenAI put out a feature that quietly logs your clicks and keystrokes to a plaintext file, then warned you about the risk itself. None of those three asked first. We have watched companies stop asking all year, Meta with its opt-out defaults, actors having to write AI consent into their contracts. Penn went the other way, open-sourcing a clinical AI you have to opt into, run yourself, and can inspect line by line. This is what we keep waiting for and almost never get.

Fifty-plus officers charged, every Twitch streamer opted in, a plaintext keystroke log on your work Mac, and one free clinical AI you can read line by line.

1. A private company rewrote the privacy rules for a surveillance network it built, because no public body was going to.

The company that runs the license-plate cameras over your street rewrote its own privacy rules this week, and the group that has watched it longest calls the changes theater.

Flock Safety runs the largest automated license-plate-reader network in the country, 120,000 cameras across more than 7,000 agencies, and this week it said it would make its "audit assistance" abuse-detection feature mandatory for every customer by the end of 2026, automatically suspending an account while a review runs. Officers will have to enter an investigation case code for every search, a step that has been optional since July 2025, and default data retention drops from 30 days to 7 except where it is kept as evidence. Agencies can also limit cross-jurisdiction sharing. The changes follow a Washington Post investigation that found at least 50 officers charged with misusing the tools, including a New Bedford, Massachusetts officer accused of stalking an ex and three arrested Georgia sheriff's deputies.

This is not the first crack in Flock's summer. Los Angeles put its contract on ice in July after an inspector-general audit, and a leaked company playbook showed Flock coaching police on how to win over city councils before residents could object during public comment. The ACLU's Chad Marlow called the new measures "retreads of previous inadequate safety measures," pointing out that the case-code requirement failed the first time because officers could simply lie about why they ran a search. My own read is that the 7-day retention cut is real and worth having, and the rest is a company writing rules it can revert whenever it likes. There is no public auditor here. Flock audits Flock.

Screenshot of The Record's August 13, 2026 report on Flock making abuse audits mandatory for police departments
therecord.media · August 13, 2026
Why this matters: The part that is actually missing here is public oversight. A private vendor is writing, and enforcing, the oversight rules for a surveillance network that photographs your car on your own street, and the only body reviewing whether those rules work is the vendor. That is backwards, and it is why the ACLU is right to be skeptical here. Action this week: Look up whether your town's police run Flock (the community-built DeFlock map at deflock.me shows where readers are installed), and if they do, bring the specifics to your city council: get the 7-day retention default and mandatory audit-assistance written into the contract, because a policy Flock can quietly revert is not the same as one your council can enforce. That council meeting is where the actual rules get set, not Flock's press release.

therecord.media: Flock tightens privacy controls amid scandals over officer abuse (August 13, 2026)
technologyreview.com: Flock is tightening its rules in response to a growing surveillance backlash (August 13, 2026)

2. Amazon has been training its AI on your Twitch streams by default, and Twitch shipped the off switch after the fact.

If you have ever streamed on Twitch, Amazon has already used your videos to train its AI, and the toggle that stops it is buried three menus deep.

Every Twitch streamer was enrolled by default into training Amazon's generative AI, the audio and video in their stream recordings, thousands of hours of it, with no upfront email, pop-up, or announcement. On August 12, after backlash, Twitch added a single opt-out toggle under Channel settings → Security and Privacy → Training for Generative AI. Turning it off stops Amazon from using your content to train its "generative AI content models across Amazon," though it does not opt you out of the other AI-supported Twitch features described in the privacy notice. And Twitch's chief product officer, Mike Minton, said the quiet part to TechCrunch: "If this was opt-in, nobody would opt in. That's honestly the answer."

We have been covering this fight from the creator's side all summer: Meta's opt-out-by-default content feature in July, Patreon partnering with Cloudflare to block AI crawlers, Hollywood's actors writing AI consent directly into their contracts. It is the same trick every time: platforms know that if they asked, most people would say no, so they don't ask. Sure, some of this trains the safety and discovery tools people actually use. But that is not why they buried it in a default. Minton said it himself: nobody would opt in, so they opted you in instead.

Screenshot of TechCrunch's August 12, 2026 report on Amazon training its AI on Twitch streams by default
techcrunch.com · August 12, 2026
Why this matters: This is the same move we flagged when Meta did it and when Patreon fought back, and it keeps working because the burden always lands on you. Your stream archive is the training set, and the platform's bet is that you will never find the switch. Action this week: Open Channel settings → Security and Privacy, scroll to the bottom, and turn off "Training for Generative AI." It is opt-out, so Amazon keeps using your recordings until you do. If you run a brand or team channel, check every account you control, and start treating "default opt-in to AI training" as a line to look for in the terms of any creator platform you publish to. What I would not do is assume the switch is retroactive; it stops future training, not the hours that already went in.

techcrunch.com: Amazon will train on Twitch streamers' content by default unless they opt out (August 12, 2026)
gizmodo.com: Twitch adds a setting letting users opt out of AI training amid user backlash (August 2026)

3. Your team's AI assistant can now keep a plaintext log of every keystroke, and enabling it is IT's call.

Your company's AI assistant can now keep a searchable, plaintext log of every click and keystroke an employee makes, and any app on that Mac can read it.

OpenAI launched Computer History, a ChatGPT feature for macOS on Business and Enterprise plans that reads your clicks, keystrokes, keyboard shortcuts, and app switches through the operating system's accessibility system and writes them to plaintext Markdown "memory" files, organized by day, so ChatGPT can search your activity and auto-suggest automations. It is opt-in at three levels (workspace admin, individual user, and Memories), and it excludes screenshots, recordings, microphone, and private browsing. It is also unavailable in the EEA, Switzerland, and the UK.

The risk is the part that lands on IT. OpenAI itself warns that those plaintext files can be read by any program running under the same user account, and that they carry a heightened prompt-injection risk: a malicious instruction hidden in web content could tell ChatGPT to go read them. We have watched this same capability creep in from the bossware side for years. The assistant keeps the log this time, and OpenAI is the one flagging the danger. A searchable memory of your work that can suggest automations for you is genuinely useful, and also a plaintext record of your whole day sitting on every enrolled Mac.

Screenshot of The Decoder's August 14, 2026 report on OpenAI's Computer History logging clicks and keystrokes
the-decoder.com · August 14, 2026
Why this matters: A plaintext log of everything an employee did, readable by any local process, is exactly the kind of artifact that turns one compromised app into a full-activity leak, and it lands in the endpoint-policy and procurement lane, not the "try the new feature" one. Action this week: Before anyone enables Computer History in a Business or Enterprise workspace, get three things answered in writing: where the memory files are stored, which processes can read them, and exactly what is excluded. Scope the per-app inclusion list tightly around non-sensitive tools, and keep anything touching health, financial, or customer data off it entirely. When I have asked vendors where a local cache actually lives and who can read it, the vague answer has usually been the answer, so make them put this one in the contract.

the-decoder.com: OpenAI's Computer History turns your clicks and keystrokes into a searchable ChatGPT memory timeline (August 14, 2026)

4. For a clinic that can't afford cloud AI and a doctor who doesn't code, Penn just shipped a free one.

A team at Penn built a medical AI any clinic can run for free on a laptop, and unlike the usual black box, you can watch it show its work.

Researchers at the University of Pennsylvania's RAIL lab released MARC v1, a free, open-source (CC-BY-4.0) framework for clinical AI, on August 13. Instead of one opaque medical chatbot, it splits clinical reasoning across role-specialized agents (one to extract the facts, one to reason, one to generate the answer, one to evaluate it) that pass traceable intermediate outputs, so a wrong answer can be pinned to the exact stage that produced it. A "Decomposer" module auto-writes the agent prompts from a plain-language description, the whole thing is configured in YAML with no code changes, and it runs on a local CPU, built for clinical experts who don't program and for settings that can't pay for cloud AI.

We keep hoping for exactly this, and it is the same move as the Descrybe and Meetily tools we covered earlier this month: the code is open, and anyone can download it and run it. It is also, honestly, early. This is a version-one research preprint on arXiv, and the team publishes no accuracy benchmarks, so what they have shipped is a tool you can run and inspect, not something anyone has proven is right yet. What is new this week is that you can get it and run it today, not that anyone has measured how well it does.

Screenshot of the arXiv abstract for Penn RAIL's open-source MARC v1 clinical-AI framework
arxiv.org · August 13, 2026
Why this matters: The person this is built for is not a hospital CIO with a budget. It is a clinician who treats patients but doesn't code, at a clinic that can't afford a cloud contract, and that is exactly who MARC is aimed at. Being able to run it on a laptop and see why it answered the way it did is the whole point. Action this week: Clone MARC v1 from the Penn-RAIL repository and wire one auditable, multi-step workflow in YAML before you trust any of it. Treat it as a prototype whose every step you can inspect, not a diagnostic. My own read is that shipping the inspectable plumbing, even without a benchmark, is the useful move; the thing to watch is whether real clinics actually pick it up, and whether the team follows the code with measured accuracy.

arxiv.org: MARC v1, a multi-agent framework for clinical AI (arXiv:2608.13476, August 13, 2026)
github.com/Penn-RAIL/MARC-v1: MARC v1 source, YAML-configured, CC-BY-4.0 (August 2026)

» What to watch this week

Tomorrow's signal lands here.