background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom Weekly: News Recap, September 7th–September 11th 2026

Internet Freedom Weekly: News Recap, September 7th–September 11th 2026

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 11 September, 2026
A woman uses her laptop at home

UK Police Averaged 34 Speech Arrests a Day

Big Brother Watch counted at least 62,199 arrests for communications offenses across the UK between 2021 and 2025, an average of 34 a day. Only 18,520 of those arrests led to a charge, and just 12,292 ended in a conviction, so roughly four in five went nowhere. Cumbria Constabulary arrested 25.7 people per 10,000 residents while neighboring Northumbria managed 1.9, a gap of nearly 14 times under the same laws. Two parents were held for 11 hours over sarcastic WhatsApp messages about their daughter's school, and Hertfordshire Police later admitted the arrest was unlawful and paid £20,000 in damages.

Read the full story here.

UK Wants ID Checks Built Into Every Phone

Culture Secretary Lisa Nandy told MPs that legislation is coming after Apple and Google's voluntary commitments failed to meet the scale of the problem. The plan would force age checks at the operating system layer, so nudity, cameras, messaging, and apps unlock only once someone hands over an ID or a payment card. 

The government insists adults are not the target, but the Open Rights Group warned that every adult would still be pushed through a digital ID checkpoint, with private images potentially scanned by default. Big Brother Watch described the plan as a crossing of the Rubicon, and ministers have offered no detail on how any of it reaches end-to-end encrypted apps like WhatsApp and Signal.

Read the full story here.

California Signed 13 Child Safety Laws

Governor Gavin Newsom signed 13 youth online safety and privacy laws on September 10, 2026, the most significant state-level package since the Meta settlement. AB 1709 bars social media companies from serving personalized feeds, infinite scrolling, and autoplay to under-16s, while still letting them use the platforms with those features switched off. 

SB 1119, backed by OpenAI's Sam Altman, requires AI chatbots to verify ages, restricts advertising to minors, and limits the persistent memory features that advocates say were used to isolate and manipulate a California teenager. AB 2 creates liability of up to $1 million per child where a platform is found to have fostered anxiety, depression, or other harm, which makes the Meta settlement look modest at scale.

Read the full story here.

Musk's Voter Site Harvests and Sells Your Data

America PAC, Elon Musk's super PAC, has spent over $180,000 in a single week promoting votesafe.org to voters as a place to check their registration. Visiting it hands over a name, date of birth, full address, email, phone number, IP address, and device fingerprint, with data sent in real time to Facebook, Google, X, and The Trade Desk. 

On August 29th, 2026, the privacy policy quietly dropped the language limiting data use to America PAC's own activities and replaced it with permission to sell personal information, including psychological inferences, to business partners. The government's own resource, vote.gov, collects no personal information at all, which makes the gap between the two a business model rather than an accident.

Read the full story here.

LG TVs Keep Recording After You Turn Them Off

Researchers working with Gamers Nexus and Level1Techs found current LG OLED televisions, including the G5, capturing microphone audio while the screen sat dark in standby. Disconnected from Ethernet, the sets kept recording, stored the audio locally, and uploaded the backlog automatically once the connection returned. 

The same TVs scanned local networks for phones and smartwatches, collected Wi-Fi and location data, and ran automatic content recognition on everything crossing the screen, HDMI inputs included. LG has said publicly that it does not record or store ambient conversations, a claim the investigation's own plaintext logs directly contradict.

Read the full story here.

36,769 AI Endpoints, and Almost No Locks

Our census found 36,769 self-hosted AI endpoints reachable on the public internet and identifying themselves in a single scanning index. Only 741 of them, or 2.02%, return any HTTP authentication challenge, and Open WebUI alone accounts for 18,529 endpoints with exactly one sitting behind a gate. 

The agent builders are the sharpest risk, since 5,223 endpoints across Flowise, n8n, ComfyUI, and similar tools exist specifically to store API keys, database logins, and webhook secrets. Every figure is a floor rather than a ceiling, because independent scanners have put the exposed Ollama population near 175,000 hosts, and two major vector databases are not scanned by this source at all.

Read the full story here.

Exposed Databases Map Cheap Hosting, Not Borders

We examined 1,654 internet-facing databases, each holding at least one million records, spread across 81 countries. In Germany, 52.5% of them sit with a single low-cost hosting provider, and in France, 48.9% sit with another, though neither provider lost any data itself. 

The United States is the control group at 36% across its top three providers, because managed platforms make public exposure a deliberate act instead of an omission. The country ranking published every year as a risk map is really measuring hosting markets, so the useful question is who configured the instance and under which defaults.

Read the full story here.

Literacy Now Means Knowing What to Trust Online

Literacy used to mean reading and writing, and it now quietly includes finding information, judging whether a source is credible, and recognizing manipulation. That expanded definition assumes reliable material exists in your language, which does not hold for most of the roughly 7,000 languages spoken worldwide. 

Search engines can only rank what has been published, and AI assistants trained mostly on English sound just as confident in languages where they are considerably less reliable. UNESCO's Global Roadmap for Multilingualism in the Digital Era treats that gap as a design failure, which places the responsibility on the infrastructure rather than on the person struggling to use it.

Read the full story here.

Cutting the Internet Is an Attack on Education

Attacks on education get counted when a school is shelled, or a teacher is abducted, but an order that cuts remote learning across a region rarely gets counted at all. Since 2020, remote and hybrid learning has become the standard fallback when schools cannot open, which makes continuity depend on a connection a government can switch off. 

In Afghanistan, where UNESCO reported in 2025 that 2.2 million girls remain banned from classrooms, the Taliban imposed four shutdowns that cut off more than 43 million people. Six countries also cut access during national exams last year, including Iraq, where six shutdown instances produced 36 nationwide disruptions between May and September.

Read the full story here.

Safety Filters Are Deleting the Support Too

For a lot of people, online communities are not a supplement to mental health support but the only support within reach. Automated moderation looks for patterns in language and cannot reliably tell someone describing their own experience apart from someone posting genuinely harmful material, so peer support threads vanish alongside the risk. 

Age verification adds a second layer, and Freedom House's Freedom on the Net 2025 report documented UK forums on LGBT+ issues, journalism, and public health caught by overbroad application. Safety systems are measured on what they block and almost never on who they cut off, which builds a permanent blind spot into every system designed this way.

Read the full story here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"