Last Update: 09/29/2026 at 3:33 PM EST

Morning Briefing: Privacy

Thursday, September 17, 2026

September 17, 2026

Privacy Safeguards Advance While Identity Controls Fail

Microsoft’s school AI agreement offers a concrete model of privacy protection: limits on secondary use of student and educator data, independent audits, and family-facing disclosures that become binding for covered schools on November 1.

But the day’s other major developments pointed in the opposite direction. A reported mass exposure of driver’s-license scans is now under FBI investigation; Florida traced access to its driver database to improperly stored police credentials; and Revolut confirmed that a fraudulent government request produced a sensitive data disclosure. The common lesson is less about a single technical flaw than about the weak points surrounding valuable identity data.

Taken together, the picture remains uneven rather than transformational. Narrow contracts and court remedies can impose real constraints, while vendors and institutions still face serious exposure through access management and disclosure workflows.

Microsoft’s agreement with the American Federation of Teachers moves school AI privacy from voluntary assurance toward enforceable contract terms. Covered schools are to receive restrictions on use of student and educator data for AI training, advertising, sales, and unrelated product development, alongside audits and disclosures. Its practical reach and enforcement remain to be tested, but it gives districts a more operational negotiating baseline than broad principles alone.

The FBI investigation into a reported offering of more than 153 million U.S. and Canadian driver’s-license scans has become more consequential as IDScan.net acknowledged possible unauthorized access around September 1. The reported scale and source remain unconfirmed, but WBAY reported that the company’s services handle identity documents across consumer transactions—illustrating the concentrated risk in verification providers.

Three incidents underscored distinct routes into sensitive identity systems. Florida says attackers used credentials improperly stored on a police employee’s personal device; Revolut says a fake request from a legitimate government-domain address induced a disclosure of identity and financial information. Neither case establishes a broad sector-wide failure, but both show how authorized access and trusted communication channels can bypass conventional perimeter defenses.

A New Jersey order transferring 14 Radaris-linked domains in a Daniel’s Law dispute supplied a tangible, if limited, remedy against alleged data-broker noncompliance. KrebsOnSecurity reported that the order followed the defendants’ failure to appear and faces a planned appeal, so it is not a fully litigated merits precedent. Still, it shows removal laws can produce consequences beyond opt-out requests.

Key Points

  • Privacy controls are increasingly being tested at operational choke points: contract terms, credential storage, vendor retention, and verification of government requests. These are implementation questions, not merely questions of whether an organization has a privacy policy.
  • The Microsoft agreement extends the recent move toward institution-specific AI governance. Its significance lies in making limits on secondary data use, auditability, and disclosures enforceable for covered schools—not in establishing an industry-wide standard.
  • Identity documents remain unusually high-value data because a single disclosure can combine image, address, date-of-birth, and financial or behavioral information. The current incidents differ in cause, but each shows why access to such records demands controls beyond protection of the central database.
  • Privacy-removal rules can have practical force through litigation, even while their broader legal durability remains contested. The Radaris order is a concrete outcome, but its procedural posture limits what it can establish.

Implications

Organizations that collect identity documents should review third-party vendor controls, privileged-account handling, and procedures for authenticating government data requests. The day’s incidents show that sensitive data can escape without a direct compromise of core systems.

School districts may gain leverage to demand measurable AI safeguards where statutory protections are incomplete. Whether that model matters beyond Microsoft will depend on coverage, auditing, and comparable commitments from other vendors.

Data-broker compliance risk is becoming more operational where removal obligations are backed by remedies affecting domains and online services. The effect of this particular order will depend on the appeal and related litigation.

Watchpoints

Watch

Whether FBI findings and IDScan.net disclosures clarify the source, authenticity, scope, affected customers, and jurisdictions behind the driver’s-license listing.

Watch

Florida’s account of what records were accessed and whether its investigation identifies broader weaknesses in law-enforcement access to the state database.

Watch

Revolut’s disclosure of the affected population and any regulatory response to its validation of government data requests.

Watch

How Microsoft’s November safeguards are implemented in covered schools, including audit practice and whether other major AI vendors make comparable commitments.

Watch

The appeal and related litigation over the Radaris domains and Daniel’s Law.

Fallout

Yesterday paired narrow advances in enforceable privacy governance with recurring failures around the handling, access, and disclosure of identity data.

School AI Data Governance

Microsoft’s agreement with the American Federation of Teachers creates contract-based limits for AI tools used by covered schools.

Fresh developments

The safeguards are set to take effect November 1 and include restrictions on using student and educator data for AI training, advertising, sales, or unrelated product development, plus audits and family disclosures.

Why we noticed

The agreement gives schools a practical privacy baseline where broad statutory protection is absent, though its coverage and enforcement remain unresolved.

Watch for:

  • Implementation and audit details after the November effective date.
  • Whether OpenAI, Anthropic, Google, or other providers adopt comparable terms.

Identity Data Exposure and Disclosure Controls

Recent incidents show that sensitive identity and financial data can be exposed through vendors, compromised credentials, and fraudulent disclosure requests.

Fresh developments

The FBI is investigating the reported listing of driver’s-license scans potentially linked to IDScan.net; Florida confirmed unauthorized database access through improperly stored police credentials; and Revolut confirmed disclosure after a fraudulent government request.

Why we noticed

The cases point to control failures around access and trusted workflows, not a shared technical cause. Their common risk is the exposure of data that can support impersonation, fraud, and targeted social engineering.

Watch for:

  • Confirmation of the scale and origin of the reported IDScan.net exposure.
  • Florida’s findings on accessed records and affected people.
  • Revolut’s disclosure of affected customers and any regulator response.

Data-Broker Removal Enforcement

A New Jersey court order provided a concrete remedy in a dispute over alleged failures to remove protected personal information from people-search services.

Fresh developments

New reporting detailed an August 26 order transferring 14 Radaris-related domains to Atlas Data Privacy Corp. after defendants failed to appear in Daniel’s Law litigation.

Why we noticed

The order shows that privacy-removal obligations can affect the operation of alleged noncompliant services, while the planned appeal and default posture limit its broader precedential weight.

Watch for:

  • The planned appeal.
  • Outcomes in related Daniel’s Law and constitutional challenges.
  • Whether the transferred domains materially alter access to the disputed personal-information listings.

Final Thought

The day made the central privacy tension clearer: enforceable protections are emerging in specific settings, but the systems entrusted with identity data remain vulnerable wherever access and disclosure controls are treated as routine workflow rather than core security.