We saved hundreds of Biden-era AI documents, so you don't have to

Image credit: Adapted from Anton Grabolle / Better Images of AI / Classification Cupboard / CC-BY 4.0


On January 20th, Trump will begin his second term in office.

If Trump and his administration follow through on their campaign promises, the transition of power will bring devasting consequences for our fundamental rights and freedoms, particularly for immigrants, reproductive health care seekers, people of color, poor people, and queer and trans communities.

Among the many anticipated impacts, the new administration has signaled it intends to reverse Biden-era progress related to protecting our civil rights and civil liberties in the realms of privacy and artificial intelligence.

The day after the election, Trump announced his intention to repeal a Biden era executive order regulating AI. Since then, Trump has granted Elon Musk unprecedented influence over government affairs, and hosted scores of tech leaders at Mar-a-Lago. Tech CEOs have in turn donated millions to Trump’s inauguration, with contributions from Apple, Meta, Amazon, and OpenAI far outpacing their donations to Biden in 2020.

These and other developments foreshadow an incoming administration that is going to take a lax approach toward regulating technology companies.

Over the last four years, the Biden administration made important strides in this area, including a directive increasing transparency into government use of AI, FTC enforcement against location data brokers, and a DOJ lawsuit challenging the legality of RealPage’s rent price-fixing algorithm.

These efforts were buttressed by legal documents, reports, blogs, and other records laying out the administration’s efforts to protect consumers and hold Big Tech accountable. But once administrative agencies change hands under Trump, there is no guarantee that documentation of these and other initiatives will remain accessible to advocates, journalists, and interested members of the public.

So, we saved them.

Below, you can view archived copies of over 250 documents and webpages on topics like algorithmic discrimination, generative AI, and biometric surveillance. Try filtering by agency (e.g., DHS, FTC) or keywords (e.g., AI use case inventory, Kochava, risk). Use the drop-down menu to change how many rows you can see at a time.

No matter what happens, the ACLU of Massachusetts remains committed to fighting for law reforms to protect the public interest, civil rights, and civil liberties. Click here to find out ways you can get involved.


AgencyDocumentSource
Administrative ConferenceAI and regulatory enforcementOriginal source
Administrative ConferenceGuidance on agency use of AI (2020)Original source
Administrative ConferenceReport on automated legal guidance at federal agenciesOriginal source
ANSIPublic private partnershipsOriginal source
CFPBAdverse action notification on credit algorithmsOriginal source
CFPBAI in financial services - commentOriginal source
CFPBAI in home appraisals - blogpostOriginal source
CFPBAI in home appraisals - ruleOriginal source
CFPBBackground dossiers and AI in employmentOriginal source
CFPBCall to action for tech whistleblowingOriginal source
CFPBFair Credit Reporting and Name-Only Matching ProceduresOriginal source
CFPBGuidance on black box algorithmsOriginal source
CFPBGuidance on credit denials using AIOriginal source
CFPBNo-action letter to Upstart - blogpostOriginal source
CFPBNo-action letter to Upstart (credit lender)Original source
CFPBOn false matches in tenant and employment screeningOriginal source
CFPBProposed registry for AI harm repeat offendersOriginal source
CFPBRights for job seekers on background screeningOriginal source
CFPBRights for tenants on rental application denialsOriginal source
CFPBTenant screening - consumer snapshotOriginal source
CFPBTenant screening - market reportOriginal source
Chief Information Officers CouncilGuidance for federal agencies on AI use case inventory (2024)Original source
CommerceDepartment of Commerce AI use case inventory (2023)Original source
CongressAdvancing American AI actOriginal source
Copyright OfficeCopyright and AI: Digital ReplicasOriginal source
Department of StateDepartment of State AI use case inventory (2024)Original source
Department of StateDepartment of State use of AI compliance planOriginal source
DHSDHS AI roadmap (2024)Original source
DHSDHS AI use case inventory - blog post Original source
DHSDHS AI use case inventory - landing pageOriginal source
DHSDHS AI use case inventory (2022)Original source
DHSDHS AI use case inventory (2023)Original source
DHSDHS AI use case inventory (2024)Original source
DHSDHS playbook for GenAI in the public sectorOriginal source
DHSDHS Simplified AI use case inventory landing pageOriginal source
DHSDHS use of AI compliance planOriginal source
DHSPress release on DHS playbook on GenAI in the public sectorOriginal source
DODDOD use of AI compliance planOriginal source
DOJAI and disability discrimination in hiringOriginal source
DOJDOJ AI use case inventoryOriginal source
DOJDOJ Sues RealPage for Algorithmic Pricing Scheme Original source
DOJDOJ Sues Six Large Landlords for Algorithmic Pricing Scheme Original source
DOJUS et al. v. RealPage - proposed final judgmentOriginal source
DOJUS vs RealPageOriginal source
DOJUS vs RealPage - amended compliantOriginal source
DOLAI and ADS under Fair Labor Standards ActOriginal source
DOLAI and worker well-being principlesOriginal source
DOLFederal contractors use of AIOriginal source
StateRisk Management Profile for AI and Human RightsOriginal source
DOTDOT AI use case inventoryOriginal source
DOTDOT use of AI compliance planOriginal source
EducationAI Discrimination in EducationOriginal source
EducationDepartment of Education AI use case inventoryOriginal source
EducationDepartment of Education use of AI compliance planOriginal source
Election Assistance CommissionElection Assistance Commission use of AI compliance planOriginal source
EnergyDepartment of Energy AI use case inventory (2023)Original source
EnergyDepartment of Energy GenAI Reference GuideOriginal source
EnergyDepartment of Energy use of AI compliance planOriginal source
EOCCAddressing adverse impact of AI in employment under CRAOriginal source
EOCCArtificial Intelligence and Algorithmic Fairness InitiativeOriginal source
EOCCEOCC use of AI compliance plan (2024)Original source
EOCCGuidance on AI in employment and ADA Original source
EOCCImplications of big data for equal employment opportunity lawOriginal source
EOCCiTutorGroup age discrimination lawsuitOriginal source
EOCCiTutorGroup settlementOriginal source
EOCCPress release on guidance on AI in employment and ADA Original source
EOCCTips for workers on AI and ADAOriginal source
EOCCVisual Disabilities in the Workplace and ADAOriginal source
EOCCWearables in the workplace under federal discrimination lawsOriginal source
EOTAI and future of teaching and learningOriginal source
EPAEPA use of AI compliance planOriginal source
Executive Office of PresidentPromoting the Use of Trustworthy Artificial Intelligence in the Federal GovernmentOriginal source
FCCAI in robocalls and proposed rule on robotextsOriginal source
Federal Housing Finance AgencyFederal Housing Finance Agency use of AI compliance plan (2024)Original source
FTCAI and the risk of consumer harmOriginal source
FTCApproaches to Address AI-enabled Voice CloningOriginal source
FTCBest practices for use of FRTOriginal source
FTCBlogpost on location data casesOriginal source
FTCExplainer on proposed settlements with Avast, X-Mode, and InMarketOriginal source
FTCExplainer on real-time biddingOriginal source
FTCExplainer on surveillance pricingOriginal source
FTCFRT vs Facebook (2012) settlementOriginal source
FTCFTC on deceptive AI claimsOriginal source
FTCFTC vs Ascend Ecom deceptive claim lawsuitOriginal source
FTCFTC vs DoNotPay "AI lawyer" deceptive claim - agreed consent orderOriginal source
FTCFTC vs DoNotPay "AI lawyer" deceptive claim - complaintOriginal source
FTCFTC vs Ecommerce Empire deceptive claim complaintOriginal source
FTCFTC vs Everalbum Photo App complaintOriginal source
FTCFTC vs Everalbum Photo App press releaseOriginal source
FTCFTC vs Everalbum settlementOriginal source
FTCFTC vs Facebook (2012) settlement order press releaseOriginal source
FTCFTC vs Facebook settlement orderOriginal source
FTCFTC vs Facebook settlement order press releaseOriginal source
FTCFTC vs FBA machine deceptive claimOriginal source
FTCFTC vs FBA machine orderOriginal source
FTCFTC vs Flo Health press releaseOriginal source
FTCFTC vs Flo Health statement on settlementOriginal source
FTCFTC vs GravyAnalytics complaintOriginal source
FTCFTC vs GravyAnalytics concurring statement (1 of 3)Original source
FTCFTC vs GravyAnalytics concurring statement (2 of 3)Original source
FTCFTC vs GravyAnalytics concurring/dissenting statement (3 of 3)Original source
FTCFTC vs GravyAnalytics press releaseOriginal source
FTCFTC vs GravyAnalytics proposed orderOriginal source
FTCFTC vs InMarket complaintOriginal source
FTCFTC vs InMarket press releaseOriginal source
FTCFTC vs InMarket press release on finalized orderOriginal source
FTCFTC vs Inmarket proposed orderOriginal source
FTCFTC vs Intellivision (unsupported claims about FRT) complaintOriginal source
FTCFTC vs Intellivision blogpostOriginal source
FTCFTC vs Intellivision press releaseOriginal source
FTCFTC vs Intellivision proposed consent orderOriginal source
FTCFTC vs Kochava amended complaintOriginal source
FTCFTC vs Kochava case pageOriginal source
FTCFTC vs Kochava complaintOriginal source
FTCFTC vs Kochava concurring statementOriginal source
FTCFTC vs Kochava memorandum decision 02/2024Original source
FTCFTC vs Kochava press releaseOriginal source
FTCFTC vs MobileWalla complaintOriginal source
FTCFTC vs MobileWalla complaintOriginal source
FTCFTC vs MobileWalla proposed settlement orderOriginal source
FTCFTC vs RiteAid complaintOriginal source
FTCFTC vs RiteAid concurring statementOriginal source
FTCFTC vs RiteAid press releaseOriginal source
FTCFTC vs RiteAid proposed orderOriginal source
FTCFTC vs Rytr (writing assistant) deceptive claim complaintOriginal source
FTCFTC vs Rytr proposed orderOriginal source
FTCFTC vs X-mode agreement with consent order (Jan 2024)Original source
FTCFTC vs X-mode analysis of proposed consent orderOriginal source
FTCFTC vs X-Mode and Outlogic press release on finalized orderOriginal source
FTCFTC vs X-mode and Outlogic press release on outcomeOriginal source
FTCFTC vs X-mode complaint (April 2024)Original source
FTCFTC vs X-mode complaint (Jan 2024)Original source
FTCFTC vs X-mode decision and order (April 2024)Original source
FTCFTC vs X-mode proposed order (Jan 2024)Original source
FTCHealth app breach notification rule Original source
FTCImpersonation rule press releaseOriginal source
FTCOperation AI ComplyOriginal source
FTCPolicy statement on use of biometric informationOriginal source
FTCPress release on health app breach notification rule Original source
FTCStatement by FTC commissioner on health app breachesOriginal source
FTCSurveillance pricing order press releaseOriginal source
FTCSurveillance pricing order to file reportOriginal source
FTCWarning about biometric surveillanceOriginal source
GAOGov AI accountability highlightsOriginal source
GAOGov AI accountability reportOriginal source
General Services AdministrationGSA use case inventory Original source
General Services AdministrationGSA use of AI compliance plan - governanceOriginal source
General Services AdministrationGSA use of AI compliance plan - responsible innovationOriginal source
General Services AdministrationGSA use of AI compliance plan - risksOriginal source
HealthDepartment of Health AI use case inventory (2024)Original source
HHSU.S. Department of Health and Human Services use of AI compliance planOriginal source
HUDFair Housing Act and use of criminal records in housing transactionsOriginal source
HUDFair Housing Act guidance on AIOriginal source
HUDGuidance on AI in advertising of housing, credit and real estateOriginal source
HUDGuidance on AI in tenant screeningOriginal source
HUDHUD AI use case inventory (2023)Original source
HUDHUD AI use case inventory (2024)Original source
HUDHUD use of AI compliance plan (2024)Original source
Industry and Security BureauProposed rule for mandatory AI reportingOriginal source
InteriorDepartment of Interior AI use case inventory (2024)Original source
InteriorDepartment of Interior use of AI compliance planOriginal source
IRSIRS transitions away from FRT for third-party verificationOriginal source
LaborDOL AI use case inventoryOriginal source
LaborDOL use of AI compliance planOriginal source
Library Of CongressAI and copyrightOriginal source
Multi-agency2023 Joint Statement on Enforcement of Civil Rights, Fair Competition, Consumer Protection, and Equal Opportunity Laws in Automated SystemsOriginal source
Multi-agency2024 Joint Statement on Enforcement of Civil Rights, Fair Competition, Consumer Protection, and Equal Opportunity Laws in Automated SystemsOriginal source
Multi-agency2024 use case inventory reporting instructionsOriginal source
Multi-agencyCFPB and Federal Partners on ADSOriginal source
Multi-agencyCFPB and NLRB Announce Information Sharing Agreement Original source
Multi-agencyFederal Agency AI Use Case Inventory (2023)Original source
Multi-agencyFederal Agency AI Use Case Inventory (2024)Original source
Multi-agencyFederal Agency AI Use Case Inventory READMEOriginal source
Multi-agencyJoint statement against AI biasOriginal source
Multi-agencyJoint statement on ADS enforcementOriginal source
NAIACAI literaryOriginal source
NAIACAI positive impact on science and medicineOriginal source
NAIACAI's Procurement ChallengeOriginal source
NAIACData Challenges and Privacy Protections for Safeguarding Civil Rights in GovernmentOriginal source
NAIACExpand the AI Use Case Inventory by Limiting the ‘Common Commercial Products’ ExceptionOriginal source
NAIACExpand the AI Use Case Inventory by Limiting the ‘Sensitive Law Enforcement’ ExceptionOriginal source
NAIACFAQs on Foundation Models and GenAIOriginal source
NAIACFindings and recommendations on AI SafetyOriginal source
NAIACFindings on The Potential Future Risks of AIOriginal source
NAIACGenAI risksOriginal source
NAIACHarnessing AI for Scientific ProgressOriginal source
NAIACImplementing the NIST AI Rights Management FrameworkOriginal source
NAIACInstitutional Structures to Support Safer AI SystemsOriginal source
NAIACNAIAC webpagesOriginal source
NAIACNational Artificial Intelligence Advisory Committee: Year 1 ReportOriginal source
NAIACNational Artificial Intelligence Advisory Committee: Year 2 ReportOriginal source
NAIACNational Campaign on Lifelong AI Career SuccessOriginal source
NAIACOn adverse event reporting of emerging risks from AI Original source
NAIACOn field testing of law enforcement AI toolsOriginal source
NAIACOn implementing the NIST AI Safety InstituteOriginal source
NAIACPublic Summary Reporting on Use of High-Risk AIOriginal source
NAIACPublic Use Policies for High-Risk AIOriginal source
NAIACRationales, Mechanisms, and Challenges to Regulating AIOriginal source
NAIACReport on impact of AIOriginal source
NAIACReport on law enforcement use of AIOriginal source
NAIACResponsible Procurement Innovation for AI at Government AgenciesOriginal source
NAIACStatement of support on Safe, Secure and Trustworthy AI EOOriginal source
NAIACStatement on AI and Existential RiskOriginal source
NAIACTowards Standards for Data Transparency for AI ModelsOriginal source
NAIACWorking Group on Rights-Respecting AIOriginal source
NAIRRNAIRR task force final reportOriginal source
NAIRRNAIRR task force interim reportOriginal source
NAIRRNational AI Research Resource pilot launchOriginal source
NASANASA use of AI compliance planOriginal source
NISTAI risk management frameworkOriginal source
NISTAI risk management playbookOriginal source
NISTAI technical standardsOriginal source
NISTGenAI risk managementOriginal source
NISTGenAI software development practicesOriginal source
NISTNIST landing post on Safe, Secure, Trustworthy AI EOOriginal source
NISTOne-pager on carrying out Safe, Secure, Trustworthy AI EOOriginal source
NISTRisks of foundation modelsOriginal source
NISTSecure Software Development FrameworkOriginal source
NISTStandards for identifying biasOriginal source
NSFNSF 2023/2024 AI use case inventoryOriginal source
NSFNSF use of AI compliance planOriginal source
NSSCETNational Standards Strategy for Critical and Emerging Technology roadmapOriginal source
NSTTrustworthy AI R&DOriginal source
Nuclear Regulatory CommissionNuclear Regulatory Commission use of AI compliance planOriginal source
OETGuidance for developers on AI in EducationOriginal source
Office of Personnel ManagementOffice of Personnel management use of AI compliance planOriginal source
OMBBlogpost on responsible acquisition of AIOriginal source
OMBMemo on AI governanceOriginal source
OMBMemo on responsible acquisition of AIOriginal source
OSTPBlueprint for AI Bill Of RightsOriginal source
SECSEC AI use case inventory 2024Original source
SECSEC use of AI compliance planOriginal source
SSASSA use of AI compliance planOriginal source
TreasuryAI use case inventory May 2023Original source
TreasuryTreasury use of AI compliance planOriginal source
US Commission on Civil RightsAI in K-12 educationOriginal source
US Commission on Civil RightsCivil rights implications of algorithmsOriginal source
US Commission on Civil RightsCivil rights implications of FRTOriginal source
US Commission on Civil RightsCivil rights implications of FRT factsheetOriginal source
US Commission on Civil RightsUSCCR use of AI compliance planOriginal source
USAIDUSAID use of AI compliance planOriginal source
USDAUSDA AI strategyOriginal source
USDAUSDA AI use case inventory (2024)Original source
USDAUSDA use of AI compliance planOriginal source
VeteransDepartment of Veterans Affairs use of AI compliance planOriginal source
White HouseEO on Safe, Secure and Trustworthy AIOriginal source
White House EO on Safe, Secure and Trustworthy AI - press releaseOriginal source
White HouseDelivering on the Promise of AI to Improve Health OutcomesOriginal source
White HouseEO on Responsible AIOriginal source
White HouseFramework on AI governance in national securityOriginal source
White HouseNational Standards Strategy for Critical and Emerging Technology - press releaseOriginal source
White HouseThe Cost of Anticompetitive Pricing Algorithms in Rental HousingOriginal source
White HouseVoluntary Commitment on AI - press releaseOriginal source

Can’t find what you’re looking for? It may be available on the Internet Archive.


Boston Police Records Show Nearly 70 Percent of ShotSpotter Alerts Led to Dead Ends

Image credit: Sketch illustration by Inna Lugovyh

The ACLU of Massachusetts has acquired over 1,300 documents detailing the use of ShotSpotter by the Boston Police Department from 2020 to 2022. These public records shed light for the first time on how this controversial technology is deployed in Boston.  

ShotSpotter — now SoundThinking — is a for-profit technology company that uses microphones, algorithmic assessments, and human analysts to record audio and attempt to identify potential gunshots. A public records document from 2014 describes a deployment process that considers locations for microphones including government buildings, housing authorities, schools, private buildings and utility poles.

According to city records, Boston has spent over $4 million on ShotSpotter since 2012, deploying the technology mostly in communities of color. Despite the hefty price tag, in nearly 70 percent of ShotSpotter alerts, police found no evidence of gunfire. The records indicate that over 10 percent of ShotSpotter alerts flagged fireworks, not weapons discharges.

The records add more evidence to support what researchers and government investigators have found in other cities: ShotSpotter is unreliable, ineffective, and a danger to civil rights and civil liberties. It’s time to end Boston’s relationship with ShotSpotter. Boston’s ShotSpotter contract expires in June, making now the pivotal moment to stop wasting millions on this ineffective technology.

Boston’s relationship with ShotSpotter dates from 2007. A recent leak of ShotSpotter locations confirms ShotSpotter is deployed almost exclusively in communities of color. In Boston, ShotSpotter microphones are installed primarily in Dorchester and Roxbury, in areas where some neighborhoods are over 90 percent Black and/or Latine.  

Coupled with the high error rate of the system, BPD records indicate that ShotSpotter perpetuates the over-policing of communities of color, encouraging police to comb through neighborhoods and interrogate residents in response to what often turn out to be false alarms.  

For each instance of potential gunfire, ShotSpotter makes an initial algorithmic assessment (gunshot, fireworks, other) and sends the audio file to a team of human analysts, who make their own prediction about whether it is definitely, possibly, or not gunfire. These analysts use heuristics like whether the audio waveform looks like “a sideways Christmas tree” and if there is “100% certainty of gunfire in the reviewer’s mind.” 

ShotSpotter relies heavily on these human analysts to correct ShotSpotter predictions; an internal document estimates that human workers overrule around 10 percent of the company’s algorithmic assessments. The remaining alerts comprise the reports we received: cases in which police officers were dispatched to investigate sounds ShotSpotter identified as gunfire. But the records show that in most cases, dispatched police officers did not recover evidence of shots fired. 

Analyzing over 1,300 police reports, we found that almost 70 percent of ShotSpotter alerts returned no evidence of shots fired.  

In all, 16 percent of alerts corresponded to common urban sounds: fireworks, balloons, vehicles backfiring, garbage trucks and construction. Over 1 in 10 ShotSpotter alerts in Boston were just fireworks, despite a “fireworks suppression mode” that ShotSpotter implements on major holidays.  

ShotSpotter markets its technology as a “gunshot detection algorithm,” but these records indicate that it struggles to reliably and accurately perform that central task. Indeed, email metadata we received from the BPD describe several emails that seem to refer to inaccurate ShotSpotter readings. The records confirm what public officials and independent researchers have reported about the technology’s use in communities across the country. For example, in 2018, Fall River Police abandoned ShotSpotter, saying it didn’t “justify the cost.” In recent years, many communities in the United States have either declined to adopt ShotSpotter after unimpressive pilots or elected to stop using the technology altogether.

Coupled with reports from other communities, these new BPD records indicate that ShotSpotter is a waste of money. But it’s worse than just missed opportunities and poor resource allocation. In the nearly 70 percent of cases where ShotSpotter sent an alert but police found no evidence of gunfire, residents of mostly Black and brown communities were confronted by police officers looking for shooters who may not have existed, creating potentially dangerous situations for residents and heightening tension in an otherwise peaceful environment.  

Just this February, a Chicago police officer responding to a ShotSpotter alert fired his gun at a teenage boy who was lighting fireworks. Luckily, the boy was not physically harmed. Tragically, 13-year-old Chicago resident Adam Toledo was not so fortunate; he was killed when Chicago police officers responded to a ShotSpotter alert in 2021. The resulting community outrage led Chicago Mayor Brandon Johnson to campaign on the promise of ending ShotSpotter. This year, Mayor Johnson followed through on that promise by announcing Chicago would not extend its ShotSpotter contract. 

The most dangerous outcome of a false ShotSpotter alert is a police shooting. But over the years, ShotSpotter alerts have also contributed to wrongful arrests and increased police stops, almost exclusively in Black and brown neighborhoods. BPD records — detailing incidents from 2020-2022 — include several cases where people in the vicinity of an alert were stopped, searched, or cited — just because they happened to be in the wrong place at the wrong time.  

For instance, in 2021, someone driving in the vicinity of a ShotSpotter alert was pulled over and cited for an “expired registration, excessive window tint, and failure to display a front license plate.” Since ShotSpotter devices in Boston are predominately located in Black and brown neighborhoods, its alerts increase the funneling of police into those neighborhoods, even when there is no evidence of a shooting. This dynamic exacerbates the cycle of over-policing of communities of color and increases mistrust towards police among groups of people who are disproportionately stopped and searched.  

This dynamic can lead to grave civil rights harms. In Chicago, a 65-year-old grandfather was charged with murder after he was pulled over in the area of a ShotSpotter alert. The charges were eventually dismissed, but only after he had already spent a year in jail.  

In summary, our findings add to the large and growing body of research that all comes to the same conclusion: ShotSpotter is an unreliable technology that poses a substantial threat to civil rights and civil liberties, almost exclusively for the Black and brown people who live in the neighborhoods subject to its ongoing surveillance. 

Since 2012, Boston has spent over $4 million on ShotSpotter. But BPD records indicate that, more often than not, police find no evidence of gunfire — wasting officer time looking for witness corroboration and ballistics evidence of gunfire they never find. The true cost of ShotSpotter goes beyond just dollars and cents and wasted officer time. ShotSpotter has real human costs for civil rights and liberties, public safety, and community-police relationships.  

For these and other reasons, cities including Canton, OH, Charlotte, NC, Dayton, OH, Durham, NC, Fall River, MA, and San Antonio, TX have decided to end the use of this controversial technology. In San Diego, CA, after a campaign by residents to end the use of ShotSpotter, officials let the contract lapse. And cities like Atlanta, GA and Portland, OR tested the system but decided it wasn’t worth it. 

From coast to coast, cities across the country have wised up about ShotSpotter. The company appears to have taken notice of the trend, and in 2023 spent $26.9 million on “sales and marketing”. But the cities that have decided not to partner with the company are right: Community safety shouldn’t rely on unproven surveillance that threatens civil rights. Boston’s ShotSpotter contract is up for renewal in June. To advance racial justice, effective anti-violence investments, and civil rights and civil liberties, it’s time for Boston to drop ShotSpotter. 

An earlier version of this post stated that one of the false alerts was due to a piĂąata. That was incorrect.


Further reading 

Emiliano Falcon-Morano contributed to the research for this post. With thanks to Kade Crockford for comments and Tarak Shah from HRDAG for technical advice.


Yes, All Location Data: Separating fact from myth in industry talking points about “anonymous” location data

Image credit: Joahna Kuiper / Better Images of AI / Little data houses (square) / CC-BY 4.0

We carry our phones around wherever we go – and our cellphone location data follows us every moment along the way, revealing the most sensitive and intimate things about us. Everywhere we go, everyone we meet, and everything we do – it’s all accessible to anyone with a credit card, thanks to the data broker industry.  

Apps use location data for a variety of purposes including finding directions, logging runs, ordering food, and hailing rideshares. While this information can be used for legitimate purposes, this sensitive data is also exploited for profit and extremist agendas, putting every cellphone user at risk. In 2023, right-wing extremists capitalized on the unregulated open data marketplace to out gay Catholic priests. This disturbing undertaking was possible because data brokers are allowed to buy location information, repackage it, and sell it to anyone who wants to buy it. And, currently, there’s nothing stopping them.  

As independent researchers have shown time and time again, it is all too easy to trace cellphone location data back to the people holding those phones. 

Data generated from apps are superficially ‘pseudo-anonymized’ by assigning each user a unique combination of numbers called a MAID (“Mobile Advertising ID”), also known as an IDFA (“ID For Advertisers”). But since each MAID is associated with a single device and common across apps, it’s easy to paint a unique picture of someone by aggregating location datapoints across apps.  

In fact, just a few data points are sufficient to uniquely identify most individuals. Several highly-cited scientific studies using real-world cellphone location data – including a Scientific Reports research paper – showed that a few linked spatiotemporal data points are enough to uniquely identify most individuals from a crowd. Intuitively, if someone finds out where your phone is between midnight and five a.m., then they know where you likely live. If they then find out where your phone is between nine a.m. and five p.m. on weekdays, then they know where you likely work.  

While two location points – home and work – are plenty, data brokers have much more data than that. In fact, data brokers peddle a sprawling digital dossier on millions of people with incredible temporal and spatial detail. 

Recently, data broker Kochava was thrown into the spotlight as a result of a shocking investigation by the Federal Trade Commission (FTC). Among other revelations, analysts from the FTC were able to obtain a free sample of cellphone location data and use that information to track someone who visited an abortion clinic all the way back to their home. This data, like all data from data brokers, was supposed to be anonymous – instead, it revealed a person’s private health care practices and real identity. For vulnerable people travelling from states where reproductive health care is now a crime, the open sale of their cellphone location data is a serious matter. But Kochava is not a lone bad apple. They are one company out of a multibillion dollar industry that exists solely to profit off our data, putting us – and our loved ones – at risk.  

Just in case location information is not sufficient to identify someone, it is easy to connect this data with other pieces of information that are easily accessible, such as a person’s public work directory, LinkedIn profile, or by using one of many people search sites that list people’s full names and addresses. Indeed, a spinoff industry has cropped up that offers “identity resolution” services to do just that. For instance, a company called Liveramp partners with several well-known location data brokers, claiming to “resolve data to the user or household level”, helping ad companies “build, configure, and maintain a unified view of your customer, easily connecting customer data from any and all data sources.” Similarly, data brokers like Adobe and Oracle offer identity resolution services to aggregate data across disparate data sources.  

Mobile advertising IDs, as mentioned above, are part of the problem – but not the end of the road. In 2021, Google made some strides to secure MAIDs – but left opting out to more tech-savvy users. Meanwhile, Apple phased out MAIDs for users who don’t explicitly opt in to tracking. While these moves were a step in the right direction, they still leave a lot of room for loopholes. From consent for cookies to Do Not Track requests, the ad industry has historically countered every superficial privacy win with dogged – and successful – efforts to circumvent restrictions. When it comes to the “end” of MAIDs, the ad industry has already developed workarounds, allowing companies to match location data to users using “identity graphs”, even if they lack advertising IDs for those people.  

As an executive of ad tech company himself described, “when you move to these more restrictive methods, what happens is that all the shady companies … try to find alternative workarounds to the MAID but with methods the user doesn’t have any control over, ultimately hurting end-user privacy.”  

Data brokers claim they want to protect our privacy as much as we do. But we can’t trust that they will choose our privacy over their profits. We need more than superficial solutions.  

That’s why the ACLU of Massachusetts and our partners are working to pass legislation to ban the sale of cellphone location data. This bill would prevent location data being tracked or traded for anyone in the state of Massachusetts. It is a vital defense to stop this multibillion-dollar industry from profiting from our personal data. We can’t do this without your help – so click here to contact your legislator and urge them to pass this crucial legislation. It’s time to end this shady practice once and for all.  

Essential reading 


Break Up with the BRIC: Unpacking the Boston Regional Intelligence Center Budget

Explore all of the ACLU of Massachusetts' analysis on policing in the Commonwealth.

On Thursday, July 23, the Boston City Council is holding a hearing on three grants that would collectively approve over $1 million in additional funding to the Boston Police. These taxpayer dollars would go towards installing new surveillance cameras across Boston and funds for the Boston Regional Intelligence Center, or BRIC.

Thursday’s hearing is a re-run from a routine hearing which took place on June 4, in which the Boston City Council was slated to rubber-stamp these three grants - dockets #0408, #0710, and #0831. However, community advocate groups such as the Muslim Justice League rallied, urging the Councilors to be critical of – and ultimately reject – the BPD grants. Ironically, the BRIC representative failed to make an appearance at the hearing and the question of the grant approval was tabled for this future date.

Out-of-control funding of the Boston Police is nothing new -  as discussed in an ACLU of Massachusetts analysis, in FY21 the initially proposed Boston Police budget was $414 million. Ultimately, the Boston City Council still approved $402 million for the BPD, despite thousands of constituents advocating for more substantial budget cuts. 

However, specific scrutiny of the BRIC and its funding is long overdue. In recent years, city, state, and federal legislatures have authorized well over $7 million in funding for the BRIC each year. But due to BPD secrecy surrounding all things BRIC-related, it’s hard to paint a full picture of what the BRIC does with this funding. Indeed, the description of the program on the Boston Police Department website consists of a mere 122 words - so we are forced to consult alternate sources and public records requests to get any details.

A new analysis of public records by the ACLU of Massachusetts takes a closer look at where the BRIC’s money comes from -- and what it’s used for. 

What is the BRIC?

The Commonwealth of Massachusetts is home to two federal fusion centers: Department of Homeland Security-funded centers established after September 11th, which facilitate information sharing between local, federal, and state law enforcement. One such center, the Commonwealth Fusion Center, is operated by the Massachusetts State Police, while the second, the Boston Regional Intelligence Center, or BRIC, is operated by the Boston Police Department.

The BRIC operates across the entire Metro Boston Homeland Security Region (MBHSR), which includes Boston, Brookline, Cambridge, Chelsea, Everett, Quincy, Revere, Somerville, and Winthrop.

Ample and Diverse Funding

According to public records obtained and compiled by the ACLU of Massachusetts, the BRIC is funded by a combination of federal, state, and local budgets and grants.

Specifically, the BRIC receives funding from at least four distinct sources: 

  • Department of Homeland Security (DHS) Federal Emergency Management Agency (FEMA)  Urban Areas Security Initiative (UASI) grants
  • Massachusetts Executive Office of Public Safety and Security (EOPSS) yearly allocations, most likely from the DHS FEMA State Homeland Security Grant program
  • Massachusetts state budgets (passed through the Executive Office of Public Safety and Security (EOPSS); line item 8000-1001)
  • City of Boston operating budgets (via the Boston Police Department’s Bureau of Intelligence & Analysis)

 

Bar chart showing the various sources of BRIC funding in FY17, FY18, and FY20.

These four funding streams combined lead to the BRIC receiving approximately  $7-8 million each year in public funds. 

Note that correspondence with the City of Boston revealed that publicly available data for the FY19 BPD Bureau of Intelligence & Analysis budget is incorrect due to a “posting error”, and so FY19 is excluded from all figures.

Additionally, it’s important to note that due to the lack of transparency, these four sources might not encompass all of the funding coming into the BRIC. For instance, a FY21 report of BPD contracts shows $4 million in payments for “intelligence analysts” to Centra Technologies between 2018 and 2021, likely working at the BRIC. If so, the BRIC budget may indeed be millions of dollars greater than what we are able to report today.

Who’s on the payroll?

How many people do work for the BRIC – and get their salaries from its budgeted funds? Ten? Sixty? It’s difficult to know. 

Expense reports reveal at least 41 employees received training from the BRIC between 2017 and 2019 - but 10 of these names do not appear on the City of Boston payroll for those years.

Records show that the BRIC has some dedicated employees: in FY20, the personnel budget for the BPD’s Bureau of Intelligence and Analysis - whose sole charge seems to be the management of the BRIC - was $4.3 million. And in 2019, BRIC expense reports show $1.8 million in payments towards contracted “Intelligence Analysts” through companies such as Centra Technology, The Computer Merchant, and Computer and Engineering Services, Inc. (now Trillium Technical). But would this $1.8 million support 7 analysts making $250k per year? 30 analysts at $60k? The records do not provide clarity on this point.

Finally, confusion around one of the grants being discussed at Thursday’s hearing, proposed in docket #0408, further epitomizes the BRIC’s financial obfuscation around its payroll. The docket formally proposes $850,000 in grant funding to go towards “technology and protocols.” However in discussion at the June 4 hearing it was revealed that, in actuality, part of the grant would go toward hiring 6 new analysts.

By keeping under wraps the roles and job titles of BRIC employees, and even simply the size of the Center, BRIC obstructs transparency, public accountability, and city council oversight.

Hardware and Software Galore

Between 2017 and 2020, BRIC expense reports show the Center spent almost $1.3 million on hardware and software. Thorough review of these reports reveals exorbitant spending: on software of all flavors, scary surveillance technologies, frivolous tech gadgets, and some obscure mysteries.

A number of the expenses are clearly for surveillance cameras and devices, including $106,700 in orders for “single pole concealment cameras”. These pole cameras were bought from Kel-Tech Tactical Concealments, LLC, a company which also supplied the BRIC with some truly dystopian concealment devices such as a “Cable splice boot concealment” ($10,900), a  “ShopVac camera system” ($5,250), and a “Tissue box concealment” ($4,900). These purchases imply the BRIC is hiding cameras in tissue boxes, vacuum cleaners, and even electrical cables.

Some of the charges on the report are just too vague to interpret. This includes the largest hardware/software charge in the entire report: $164,199 paid to Carousel Industries for “BRIV A/V Upgrade per Bid Event”. There’s $36,997 in “Engineering Support”, paid to PJ Systems Inc. and $15,606 in a “C45529 CI Technologies Contrac[t]”, paid to CI Technologies. And concerningly, there is a cumulative $16,200 in charges described simply as “(1 Year) of Unlimited” paid to CovertTrack Group Inc. – a company which also supplied the BRIC with a “Stealth 4 Basic Tracking Devic[e]” to the tune of $7,054.

When it comes to computing hardware, there’s no skimping either. Reports show over $200,000 in expenses for servers, and over $67,000 for various laptops. And apparently the BRIC prefers Apple products - judging by the $10,000 they spent on iPad pros, almost $1,000 on Apple Pencils, and $367 on Apple TVs.

Yet the most indulgent spending is on software. Between 2017 and 2020, the BRIC purchased at least 13 specialized software products for intelligence analysis, crime tracking, public records access, device extraction, and more. 

Software Use BRIC Expenses 2017-2020
IBM i2 “Insight analysis” $124,852
CrimeView Dashboard Crime analysis, mapping and reporting $58,009
Accurint  Public records searches $32,803
Esri Enterprise Geospatial analysis $27,000
Thomson Reuters’ CLEAR Public records searches $25,322
CrimNtel GIS Crime analysis, mapping and reporting $21,016
Computer-Aided Dispatch (CAD) Interface Emergency response $16,387
Cellebrite Universal Forensic Extraction Device (UFED) Ultimate 4PC Device data extraction $12,878
CaseInfo Case management $10,508
NearMap Geospatial analysis $9,995
ViewCommander-NVR Surveillance camera recording $3,778
eSpatial Geospatial analysis $3,650
XRY Logical & Physical Device data extraction $2,981

And worse, there is redundancy between the products - the BRIC purchased three different geospatial analysis products, two public records search products, and two device data extraction products. 

This smorgasbord of tools begs the question: What, if any, supervisory procedures exist within the BRIC to prevent irresponsible spending of taxpayer dollars on expensive, duplicative software? 

And furthermore, some of these public records databases give users immense power to access residential, financial, communication, and familial data about almost any person in the country. So who, if anyone, oversees the use of powerful surveillance databases like Accurint and CLEAR, to ensure they aren’t being used to violate basic rights and spy on ex-girlfriends?


From a history of First Amendment violations in Boston, to their role in threatening local immigrant students with deportation, to a 2012 bipartisan Congressional report concluding fusion centers such as the BRIC have been unilaterally ineffective at preventing terrorism, there is much evidence in support of the BRIC being wholly defunded. But at the very least, the Boston City Council must end the practice of writing blank checks for the Boston Police to continue excessive and unscrutinized spending of taxpayer dollars.

The Boston City Council must reject the additional $1 million in funding to the Boston Police being proposed in these three grants. To learn more about the BRIC, the proposed grants, and to urge the City Council to reject them, we encourage you to:

  • Consult the Muslim Justice League Toolkit to Get the BRIC Out of Boston
  • Sign a petition telling Boston City Councilors to reject BRIC-related grants before Tuesday, July 28
  • Submit written testimony for the BRIC budget hearing before 9:30 AM on Saturday, July 25, telling Boston City Councilors to reject BRIC-related grants

Boston City Council Hearing on Proposed Ordinance to Ban Face Surveillance

Boston City Council Hearing on Proposed Ordinance to Ban Face Surveillance

On June 9, 2020, the Boston City Council's Committee on Government Operations held a hearing to discuss Councilor Michelle Wu and Councilor Ricardo Arroyo's proposed ordinance to ban face surveillance in Boston's municipal government. Dozens of advocates, academics, and community members testified at the hearing.

Below is a sample of some of the written testimonies submitted in support of banning face surveillance in Boston.

Organizations

ACLU of Massachusetts

Algorithmic Justice League

National Lawyers Guild - Massachusetts Chapter

Surveillance Technology Oversight Project 

Boston Public Library Professional Staff Association

Library Freedom Project

Boston Teachers Union

Electronic Frontier Foundation

Fight For the Future

Student Immigrant Movement

Digital Fourth

Academics, advocates, and community members

Woodrow Hartzog and Evan Selinger

Dr. Nita Bharti

Nora Paul-Schultz

Christie Dougherty

Dylan Phelan

Louis Roe

Leilani Stacy

Jennifer Jordan

Sean Kelley

 


Bond Bill Funds Prisons and Police over Education

Editor's Note: Today, the Senate Bonding Committee gave S2579: the General Government Bond Bill (previously H.4733) a favorable report. Last week, the committee on Senate Bonding, Capital Expenditures and State Assets concluded hearings on this bill. We are glad to see that the committee added limiting language to ensure that the $150 million authorization for public safety facilities would not be spent on building new prisons or jails. As the bill advances to Senate Ways and Means, we hope to see more amendments that prioritize investment in communities rather than policing and prisons.

What is the “General Government Bond Bill” and why should we care?

Last week the committee on Senate Bonding, Capital Expenditures and State Assets concluded hearings on H.4733, the General Government Bond Bill (originally H.4708). This Bond Bill intends to finance general governmental infrastructure of the Commonwealth around “public safety, information technology and data and cyber-security improvements.” 

Bond bills are borrowing bills which pass on not just debt to future generations but also values. Given the huge disparities the pandemic has both exposed and created through mandatory remote learning, the top priority for any debt for future taxpayers should in fact be their current education. The COVID-19 pandemic has shown how crucial basic broadband infrastructure is to ensure equitable access to education. Education Commissioner Jeff Riley testified last month to the need of $50 million to support MA school districts to reach students without internet access (9% of students) or exclusive use of a device (15% of students). 

Instead, this bill allows for at least $270 million to build prisons, acquire police cruisers and other equipment for the Department of Corrections. The events of the last few weeks have shown the unnecessary, unwise, and unjust investment in the criminal legal system -- a system that over-polices, over-prosecutes, and over-incarcerates Black and Brown communities in the Commonwealth. The bill’s funding priorities need to be flipped. 

As the Boston advocacy organization Families for Justice as Healing states in their call to action against H.4733, "The Commonwealth already spends more money per capita on law enforcement and incarceration than almost any other state. Communities need capital money for critical infrastructure projects like housing, carte facilities, parks, schools, treatment centers, healing centers, community centers, and spaces for art, sports, and culture."

Why are we still investing in police and prisons? 

Over the last week, the world has watched as protests against police brutality and unaccountability have been met with further use of excessive force on protestors. As we live through the historic Black Lives Matter movement, the ACLU of Massachusetts (ACLUM) has joined the calls of Black and Brown-led organizations to divest from police in favor of investments in systems that support, feed, and protect people. 

There have been demands from across the country to defund police departments, with the Minnesota City Council declaring its intent to disband the police department all together. The timing of further funding of police departments is incomprehensible at this watershed moment for racial justice across the country and in the midst of an economic freefall due to the COVID-19 pandemic. 

Bond bill H.4733 does not meet this moment. In testimony to the Senate Committee on the Bond Bill, ACLUM strongly opposed line item 8000-2025, which would authorize an enormous amount of borrowing to build prisons. Families for Justice as Healing also opposed this line item, testifying that "significant decarceration is possible and further decarceration is doable and practical under current law, and at a cost-savings to the commonwealth."

ACLUM also opposed line item 8000-0703, authorizing the borrowing of $30 million for the purchase of Department of Corrections and Executive Office of Public Safety and Security for equipment and vehicles, and line item 8000-2024, authorizing the borrowing of $92 million for the purchase of police cruisers. (This is enough to put over $40,000 towards a new or improved car for all 2,199 Massachusetts State Police employees.)

Even without bond funds, police departments across the Commonwealth and the country are incredibly well funded. As previous ACLUM analysis of the City of Boston budget on Data for Justice shows, compared to the budgets of other Boston City departments (and cabinets), the Boston Police budget is exponentially higher than that of community focused organizations like Library, Neighborhood Development and Office of Arts and Culture. 

Why aren’t we investing in actual information technology infrastructure? 

Instead of authorizing new debt to build prisons and increase police budgets, we should be investing in information technology to support educational equity throughout the Commonwealth. In that way, this bond bill could truly reflect values we want to pass down to our children. 

At present, the line item 1599-7064 is the only one which directly does this, authorizing $40 million to help close the digital divide for students in the Commonwealth. Certain emergency measures have been taken by school districts to enable transition to remote learning such as tablets and free access to assistive technology. However a bill that is intended to finance the general governmental infrastructure of the Commonwealth, and in particular to provide assistance to public school districts for remote learning environments, should invest in more than $40 million in state-wide digital infrastructure to permanently close the digital divide. 

What exactly do we need to invest in? 

Data from the United States Census American Community Survey show that about 8% of households either do not have a computer, or if they do, do not have access to the internet at all. Furthermore, more than 1 million Massachusetts residents (> 15%) do not have a fixed broadband internet connection. 

As reported in a previous analysis by the ACLU of Massachusetts, lower rates of internet access or broadband correlate with lower income, both in terms of macroscopic geography (e.g. southern and western Massachusetts), and low-income neighborhoods within cities. 8 cities in Massachusetts have at least 30% of households without cable, DSL or fiber Internet subscriptions in 2018 - Fall River, Springfield, Lowell, Lawrence, Worcester, Lynn, New Bedford and Brockton. 

Taking a closer look at Brockton for example: of the households in the lowest two income categories, less than 50 percent have broadband internet access. This is similar to the pattern of better connected cities such as Newton. Here too, about 50 percent of households in the lowest two income categories do not have broadband. Thus from the perspective of a household, one's income is a stronger indicator of access to the internet, even if one is living in an area which generally has robust high speed internet connectivity. 

Divest - Reinvest 

Bond bill H.4733 singles out certain cities for specific projects. Brockton, for example, is slated to get $2,000,000 for enhanced security camera systems at public housing buildings Campello and Sullivan towers. Instead of investment in broadband, Lawrence, which ranks 28th on the list of 623 worst connected cities in the country, is going to get $2,500,000 for police cruiser technology.Thankfully Springfield, ranked 24 on that list, is slated to get $7,500,000 for a citywide fiber network. 

Beyond Education Commissioner Jeff Riley’s testimony on the need of $50 million for remote elementary and secondary education, State and community colleges are in dire need of funding as well. The community colleges’ chief financial officers recently tallied the costs of additional information technology at nearly $17 million.

Rather than expanding the racist carceral state, we should use this Bond Bill to create equitable digital infrastructure to even out the playing field for the future generation.


Building a Better Future for AI

In recent months, headlines about artificial intelligence (AI) have ranged from concerning to downright dystopian. In Lockport, NY, the public school system rolled out a massive facial recognition system to surveil over 4,000 students – despite recent demographic studies which show that the technology frequently mis-identifies children. Ongoing investigations into Clearview AI, the facial recognition startup built upon photos that were illicitly scraped from the web, have revealed widespread unsupervised use by not only law enforcement but banks, schools, department stores, and even rich investors and friends of the company.

But the recent Social Impact in AI Conference, hosted by the Harvard Center for Research on Computation and Society (CRCS), offered another path forward for the future of artificial intelligence.

In just two days, conference attendees shared their work applying artificial intelligence and machine learning to a shockingly wide range of domains, including homelessness services, wildlife trafficking, agriculture by low-literate farmers, HIV prevention, adaptive interfaces for blind users and users with dementia, tuberculosis medication, climate modeling, social robotics, movement-building on social media, medical imaging, and education. These algorithms don’t center around surveillance and profit maximization, but rather community empowerment and resource optimization.

What’s more, many of these young researchers are centering considerations of bias and equity, (re)structuring their designs and methodologies to minimize harm and maximize social benefit. Many of the researchers voiced concerns about how their work interacts with privacy and technocratic values, not shying away from difficult questions about how to responsibly use personal data collected by often opaque methods.

The conference was designed around a central question, “What does it mean to create social impact with AI research?” Over the course of the event, at least one answer became clear: it means listening.

Indeed, a central takeaway from the conference was the importance of knowing what you don’t know, and of not being afraid to consult others when your expertise falls short. AI-based solutions will only ever solve problems on behalf of the many if they are designed in consultation with affected populations and relevant experts. No responsible discussion of the computational advances of new AI systems is complete without integrated interdisciplinary discussions regarding the social, economic, and political impacts of such systems. In this sense, the conference practiced what it preached – many attendees and speakers came from social work, biology, law, behavioral science, and public service.

The success of CRCS’s conference serves as a reminder that AI, for all its futuristic hype, is fundamentally just a tool. How we use it is determined by us: our cultural priorities and societal constraints. And as a tool, AI deserves better.

Recent advances in artificial intelligence algorithms have too frequently been used to the detriment of our civil liberties and society’s most vulnerable populations—further consolidating power in the hands of the powerful, and further exacerbating existing inequities. But reproducing and consolidating power is not what the world needs. Indeed, the AI that the world needs will not be developed by Silicon Valley technocrats in pursuit of profit, nor by Ivory Tower meritocrats in pursuit of publications. The AI we need must be developed by interdisciplinary coalitions in pursuit of redistributing power and strengthening democracy.

To that end, I offer the following six guiding questions for AI developers, as a roadmap to designing socially responsible systems:

  1. How might my tool affect the most vulnerable populations?
  2. Have I consulted with relevant academics, experts, and impacted people?
  3. How much do I know about the issue I am addressing?
  4. How am I actively countering the effects and biases of oppressive power structures that are inherently present in my data/tool/application?
  5. How could my tech be used in a worst-case scenario?
  6. Should this technology exist?

Answering these questions is unquestionably hard, but it’s only by engaging with them head-on that we stand any chance of truly changing the world for the better, with AI or with any other technology.