> daily_signal(2026_09_07)

Surveillance surged and got shoved back in the same week, AI safety went on sale for five dollars, and an AI checked a 350-year-old proof line by line.

PickBits Daily Signal · Monday, September 7, 2026

By Mark Pickering · 9 min read · September 7, 2026

// tl;dr

All summer the surveillance build-out and the pushback against it have moved on separate tracks. This week they hit the same few days. A report caught ICE handing a Palantir targeting app to thousands of new hires who hadn't been fully vetted, and days later Texas and Florida started tearing their license-plate cameras back out of the ground.

Then there's AI itself. A startup turned safety-guardrail removal into a five-dollar product, which tells you the refusals baked into "safe" models were never much of a wall. And Anthropic pointed Claude at a 350-year-old math problem and produced a proof a computer can check line by line, the rare case where an AI shows its work instead of asking you to trust it.

The same week a report caught ICE over-collecting your data, two states started pulling some of the cameras back out.

1. ICE gave thousands of unvetted new hires an app that pulls your data from a dozen databases.

The Intercept found DHS never published the privacy impact assessment federal law has required since 2002.

The Intercept reported on September 3 that Immigration and Customs Enforcement, in the middle of a hiring surge that has added more than 12,000 officers since 2025, gave thousands of those new employees access to a Palantir-built targeting app called ELITE, in many cases before their background checks had cleared. ELITE, short for Enhanced Lead Identification and Targeting, queries roughly a dozen government databases and returns a person's home address, criminal history, immigration records and court rulings, then attaches a confidence score rating how accurate the information on that person is. It doesn't only surface immigrants. It surfaces U.S. citizens too.

The step the law requires got skipped. The 2002 E-Government Act says an agency must publish a privacy impact assessment before it stands up a system like this, a public document that forces the owner to write down what it collects, who can see it, and why. DHS never published one for ELITE. This is the same pattern we've been covering all year, from the move to buy up voter files on September 1 to the leaked catalog of ICE's surveillance tools in July: build the capability first, skip the step that would force it to explain itself, and let unvetted staff log in while the paperwork is still theoretical.

Screenshot of The Intercept's September 3, 2026 report on ICE's ELITE app and the skipped privacy review
theintercept.com · September 3, 2026

Why this matters: A confidence score is a machine's guess about you, and ELITE can put one next to your name whether or not you're its target. The privacy impact assessment is the one moment the law forces an agency to say out loud what a tool does before it points the tool at people, and it's the step that got skipped. Handing the login to employees who haven't cleared their own background checks stacks a second failure on top of the first.

Action this week: Demand the document. The ELITE privacy impact assessment and the list of databases it queries are exactly what a FOIA request or a call to your representative is built to pry loose, and the missing assessment is the cleanest hook there is. Check whether your state runs a data-broker opt-out or an address-confidentiality program, because that broker pipeline is where a lot of this data starts. My own read is that the score is the part to watch: once an agency trusts a number over a warrant, you can end up having to disprove a database you were never allowed to see.

theintercept.com: ICE gave new hires access to an app with Americans' personal info before background checks cleared (September 3, 2026)
newrepublic.com: The Palantir app ICE is using to power raids and deportations (September 2026)

2. Texas and Florida start rolling back Flock's license-plate cameras.

Abbott cut off state funding the same week a $30 million buildout surfaced; Florida's DOT gave the highways 30 days.

This isn't new ground for us. Back on August 8 we covered a leaked Flock Safety deck pitching a plan to turn roughly 350,000 Uber and Lyft vehicles into a roving fleet of automated license-plate readers, and across August we watched cities drop Flock contracts at a rate the EFF clocked at around three a day. This week the arc reversed hard, and it came from the top. On August 28, Texas Governor Greg Abbott barred state agencies from spending public money on Flock cameras, an order that landed as a Texas Tribune investigation revealed a state agency had quietly funneled at least $30 million into building a license-plate surveillance network. Three days later, Florida's Department of Transportation ordered every reader off state-highway rights-of-way within 30 days, revoked the permits it had already granted, and barred new ones.

Read the fine print before you celebrate, though. Neither order is a ban. Texas cut only state funding, which leaves local, county, federal and private buyers free to keep installing cameras. Florida cleared only the state highways, which leaves the readers on city streets, county roads, driveways and parking lots exactly where they are. The politics changed, not the law: the EFF reads both moves as proof that the appetite for more cameras and longer retention has finally hit real political resistance, and the states that adopted it fastest are now the ones backing away.

Screenshot of the EFF's September 2, 2026 post on Texas and Florida stepping back from license-plate readers
eff.org · September 2, 2026

Why this matters: The mass-ALPR dragnet spread with almost no public debate, and it's now being rolled back by executive order rather than by statute, which means it can be rolled right back in by the next executive order. The cameras that watch the overwhelming majority of drivers sit on the county road by the school and the pole outside the grocery store, and both orders leave those untouched.

Action this week: Call your city or county and ask the one question that decides this locally: are we renewing our Flock contract, and on what retention terms. That's the room where your plate actually gets scanned, and it's a room a resident can walk into. Watch, too, whether Texas and Florida convert these orders into laws that close the local-funding and non-highway loopholes they deliberately left open. When I've watched a surveillance fight get won by executive order alone, it's usually been unwon the same way.

eff.org: Texas and Florida step back from ALPRs (September 2, 2026)
weartv.com: FDOT orders removal of license-plate readers from state rights-of-way (September 2026)
texasobserver.org: License-plate readers and Texas privacy advocates (September 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it is worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!

3. Someone turned safety-guardrail removal into a $5 hosted service.

TechCrunch found Abliteration.ai selling a de-safetied GLM-5.3 with no prompt logs, no identity check, and an anonymous founder.

The scariest part of this one isn't the model, it's the business plan. TechCrunch reported on September 3 that a startup called Abliteration.ai has turned guardrail removal into a hosted service. "Abliteration" is the technique for stripping an open-weight model's trained safety refusals, the reflex that makes it decline a dangerous request; the company hosts a de-safetied version of Z.AI's GLM-5.3 and sells access through a browser or an API for about $5 per million tokens. It keeps no prompt logs, requires no real identity verification, and it's run by a founder who won't put a name to it.

It is marketed for offensive-security work, red-teaming, reproducing known exploits and simulated phishing, which is a real and legitimate use. But TechCrunch got the same model to write working code for pulling saved passwords out of Chrome and to lay out a step-by-step guide to cultivating a dangerous pathogen. We flagged the front edge of this in May, when a tool called Heretic stripped the guardrails off Meta's Llama; the difference now is that you no longer need the tool, the skill, or a GPU. You need a credit card and five dollars.

Screenshot of TechCrunch's September 3, 2026 report on Abliteration.ai selling guardrail-free AI access
techcrunch.com · September 3, 2026

Why this matters: For anyone who owns security in an organization, this closes off a comfortable assumption: that the safety training inside a "safe" model is part of your defense. That assumption was always shaky, because the refusal is a policy the vendor can enforce and an attacker can pay to remove. The refusal you've been relying on is one purchase away from being gone, and the service is deliberately built so that misuse leaves no trail to investigate.

Action this week: Base your controls on what you can enforce, not on what the model will decline. That means network egress limits, data-access boundaries and monitoring that assume the attacker on the other end already has a guardrail-free model in hand. Test your own detection stack against outputs from an uncensored model in a controlled exercise, rather than treating a commercial model's refusals as the ceiling of what an adversary can generate. When I have asked vendors point blank whether their model can be jailbroken, the honest ones stopped saying no a long time ago; plan for the honest answer.

techcrunch.com: Abliteration.ai is making a business out of removing AI guardrails (September 3, 2026)
the-decoder.com: Stripping safety guardrails from open-weight AI models is now a turnkey commercial service (September 2026)

4. Claude produced the first computer-checked proof of Fermat's Last Theorem.

Dozens of Claude agents wrote about 13 million lines of Lean in 11 days, a job mathematicians expected to take years.

Andrew Wiles finally cracked Fermat's Last Theorem in 1994, closing a problem that had stood for more than 350 years, and his proof was so long and intricate that it took other mathematicians months to check. This week Anthropic went further. Using a general-purpose internal Claude model, it produced what it calls the first end-to-end, computer-checked proof of the theorem, written in Lean, the proof-checking language. Working largely autonomously over 11 days, dozens of Claude agents wrote about 13 million lines of Lean and proved 29,500 of the roughly 30,300 intermediate steps, formalizing a simplified version of Wiles's proof and burning through something like 6 billion output tokens to do it.

Checked is the part that matters, and it's literal here. A chatbot that asserts an answer asks you to trust it; a proof written in Lean gets verified mechanically, every step, by a computer that doesn't care who wrote it. Keep the caveat attached, though. It's a research demonstration, not a product, and mathematicians are already pushing back, with one strong essay this week arguing that AI doesn't spell the end of mathematics at all. They're right that it doesn't replace them. But an AI that produces a proof you can actually check, instead of one more confident answer, is a genuinely different thing than what we've spent the year covering.

Screenshot of Anthropic's research post on formalizing Fermat's Last Theorem with Claude
anthropic.com · September 4, 2026

Why this matters: For months we've watched AI get things confidently, fluently wrong, and the usual defense has been "trust but verify" with no good way to verify. A machine-checked proof flips that: you can audit it line by line instead of vibe-checking it. That matters more than the fact that the famous problem happened to be Fermat's.

Action this week: Watch where this lands next, specifically whether Lean-based proof tools start showing up in the fields where "looks right" is not good enough, cryptography, chip design and safety-critical software, because that, not the FLT headline, is the real tell. Read the "computer-checked" part as the actual advance, a model that produces a verifiable artifact rather than a confident claim. My own read is that this is the most hopeful AI story we've run in weeks, largely because the people closest to it are the ones naming its limits.

anthropic.com: Formalizing Fermat's Last Theorem (September 4, 2026)
siliconangle.com: Anthropic uses Claude to formalize a proof of Fermat's Last Theorem (September 4, 2026)

» What to watch this week

Tomorrow's signal lands here.