Tech News : Meta Pulls Facial Recognition Code From Smart Glasses App

It’s been reported that Meta has quietly removed facial recognition code from the companion app used by its AI-powered smart glasses, reigniting concerns about how far wearable technology companies may be willing to go in their pursuit of always-on artificial intelligence.

What Was Removed?

The controversy centres on an internal system called NameTag, which was discovered inside the Meta AI smartphone app that works alongside the company’s Ray-Ban smart glasses. According to reporting first published by WIRED, the code appeared to support facial recognition capabilities that had never been publicly released.

The system was reportedly designed to convert faces captured by the glasses into unique biometric identifiers, often referred to as faceprints, and compare them against a database stored on the user’s device. Evidence within the software also suggested that faces the system could not identify would be cropped, indexed, and stored locally for future processing.

Most notably, the code was present inside an application installed on tens of millions of devices despite Meta repeatedly stating that no final decision had been made about introducing facial recognition to its smart glasses platform.

Just one day after the findings became public, Meta released an updated version of the app that removed almost all traces of the NameTag system.

Meta’s Response

Meta says the facial recognition system was an internal exploratory project rather than a planned product feature. However, the speed with which the code was removed has inevitably attracted attention.

Reports indicate that the original software contained multiple AI models dedicated to detecting faces, cropping facial images, and converting them into biometric signatures. The app also reportedly contained a “Person recognised” alert that would have been displayed if someone was successfully identified.

Meta has not publicly explained why the code was removed immediately after the discovery or whether the changes had already been planned before the reporting appeared.

Why Facial Recognition In Glasses Is Different

The debate is not really about facial recognition itself. The technology has existed for many years and is already widely used in smartphones, airports, security systems, and consumer applications.

What makes smart glasses different is that they allow facial recognition to move from fixed locations and deliberate actions into everyday social interactions.

Unlike a phone, which requires someone to consciously point a camera at another person, smart glasses can continuously capture information while being worn. Combined with AI, cameras, microphones, and internet connectivity, they create the possibility of real-time identification in public spaces without the knowledge of the people being observed.

Supporters argue that such technology could have legitimate uses. For example, facial recognition could help visually impaired users identify friends, family members, or colleagues. It could also assist people with memory difficulties or cognitive impairments.

Critics, however, have raised concerns that the same technology could be misused for stalking, harassment, surveillance, or the identification of strangers without consent.

Those concerns become even more significant when combined with generative AI systems capable of searching, analysing, and contextualising information automatically.

Part Of A Bigger Strategy

The discovery also provides an insight into Meta’s longer-term ambitions for wearable AI. For example, chief executive Mark Zuckerberg has repeatedly described smart glasses as a future computing platform where AI assistants become constantly available throughout the day. The company’s recent investments in Ray-Ban and Oakley smart glasses reflect a belief that future digital interactions will increasingly move away from smartphones and towards wearable devices.

Facial recognition could potentially play an important role in that vision. An AI assistant capable of recognising people, understanding context, remembering previous interactions, and providing relevant information could become far more useful than one that simply responds to voice commands.

However, it is precisely that capability which raises difficult questions about privacy, consent, and personal data.

The Wider Privacy Challenge

The incident arrives at a time when regulators in Europe, the UK, and the United States are paying closer attention to biometric technologies.

Unlike passwords or usernames, biometric identifiers are linked directly to an individual’s physical characteristics. If compromised or misused, they cannot simply be changed or reset.

Privacy campaigners have long argued that facial recognition requires stronger safeguards than many other forms of personal data because of its potential to identify individuals at scale and without their active participation.

The rapid removal of the NameTag code suggests that Meta recognises the sensitivity of the issue, even if the company insists the feature was only exploratory.

What Does This Mean For Your Business?

For businesses, the story highlights how quickly AI is beginning to move beyond software and into the physical world.

Many organisations are already evaluating AI tools for productivity, automation, and customer service. The next wave of AI innovation is likely to involve wearable devices that can see, hear, interpret, and respond to the environment around them in real time.

That creates new opportunities, particularly in areas such as accessibility, training, field services, logistics, and hands-free information access. At the same time, it introduces new questions around privacy, data governance, consent, and the collection of biometric information.

The wider lesson is that as AI becomes more deeply embedded into everyday devices, businesses will need to think not only about what these systems can do, but also about what employees, customers, and the public are comfortable allowing them to do. The reaction to Meta’s facial recognition experiment suggests those conversations are only just beginning.

Tech News : Lidl Expands Into Mobile Plans With App-Only Strategy

Lidl is expanding into mobile phone plans through a new global partnership, using its scale and loyalty app to offer low-cost, flexible connectivity without traditional contracts.

Why Lidl Is Moving Into Mobile

Lidl’s move into telecommunications is built on a strategic partnership with 1GLOBAL, which gives the retailer the technical platform and regulatory framework needed to operate as a Mobile Virtual Network Operator, or MVNO. This means Lidl can offer mobile services without building its own network, instead using existing infrastructure while focusing on pricing, customer access, and digital delivery.

The company is positioning this as a response to a clear customer need for “easily accessible, flexible, and affordable connectivity of the highest quality without long-term contract commitments”. That focus aligns closely with Lidl’s broader retail model, where simplicity, price transparency, and convenience are central to how it competes.

This is not Lidl’s first step into mobile, as it already operates Lidl Connect in several European markets, but the new partnership significantly expands its ambitions, both geographically and technically.

How Lidl’s New Mobile Offering Works

The most notable aspect of Lidl’s approach is how tightly the service is integrated into its existing ecosystem. For example, rather than just launching as a standalone telecom brand, the new plans will be delivered primarily through the Lidl Plus app, which already has tens of millions of users across Europe.

Within that environment, customers will be able to purchase and manage mobile plans digitally, often using eSIM technology, with no need for physical SIM cards or long-term commitments. Lidl describes this as part of a broader effort to make mobile services “simple, digital, and affordable” for a mass audience.

Julian Beer, Executive Vice President at Lidl International, framed the ambition clearly, stating: “We are democratizing mobile communications. Simple, affordable, and of the highest quality.”

The app-led model also allows Lidl to control the customer relationship directly, rather than relying on traditional retail channels or third-party distributors, which could help reduce costs while increasing customer loyalty.

A Different Approach To Telecom Competition

Lidl’s strategy stands out because it is not trying to compete as a conventional telecom provider. Instead, it is using its existing retail scale, customer base, and digital platform to enter the market from a different angle.

With more than 100 million customers and a presence in over 30 countries, Lidl is effectively turning its loyalty ecosystem into a distribution channel for telecom services. As the company notes, “we are creating an attractive platform for established telecommunications companies” by combining reach, data, and customer engagement.

This model also benefits network operators, which gain additional usage and customer access without having to manage the end-user relationship directly.

Hakan Koç, founder and CEO of 1GLOBAL, highlighted this broader transformation, saying: “We want to make mobile communications as intuitive, flexible, and digital as possible for millions of people.”

How This Compares To Existing UK Mobile Offers

The timing of Lidl’s expansion comes as existing UK mobile providers are already adjusting their pricing and plan structures.

For example, Asda Mobile has recently removed its cheapest 5GB plan priced at £4.50, while slightly reducing the price of its 10GB plan to £5.95 per month. It has introduced new mid-range options, including 50GB for £7.95 and 80GB for £9.50, while increasing the price of its 100GB plan from £10 to £12. These changes apply to 12-month and 24-month contracts, although the company has confirmed there will be no mid-contract price rises.

This highlights a key contrast. Traditional MVNOs like Asda Mobile continue to operate within a familiar structure of fixed plans, contract terms, and tiered pricing. Lidl, by comparison, is moving towards a more flexible, app-based model with short-term or no-contract options, which could appeal to customers who want greater control and fewer commitments.

What Could Hold Lidl Back?

Despite the scale and ambition behind the move, several challenges remain.

Customer trust will be a factor, particularly when it comes to relying on a supermarket brand for a critical service like mobile connectivity. Network quality will depend on local operator partnerships, meaning the experience may vary between regions.

There is also the question of how widely the service will be rolled out, and whether key markets like the UK will be included in the first phase. While Lidl’s reach is significant, telecom markets are heavily regulated and highly competitive, which could slow expansion.

The app-only model, while efficient, may also limit access for customers who prefer more traditional purchasing methods or who are less comfortable managing services digitally.

What Does This Mean For Your Business?

For UK businesses, the immediate impact may be limited, but the wider development matters more than the product itself. Retailers using digital platforms and existing customer ecosystems to enter telecoms shows a clear change in how connectivity is being delivered and sold.

This development shows how industries are increasingly overlapping, with companies using data, apps, and customer relationships to expand into adjacent markets. Businesses that rely on mobile connectivity, whether for staff, operations, or customer engagement, may benefit from more flexible and potentially lower-cost options as competition increases.

There are also implications for customer expectations. As more services move towards app-based, contract-free models, users may begin to expect the same level of simplicity and control across other digital services.

At the same time, the entry of large retailers into telecoms adds pressure to existing providers, which could accelerate changes in pricing, service structure, and customer experience. Businesses that stay aware of these changes will be better placed to take advantage of new options as they emerge, while also understanding how evolving customer expectations could affect their own digital services and offerings.

Tech Tip : Alternatives To Microsoft Lens

Microsoft is retiring its free Lens scanning app, so now is the time to secure your documents and switch to a reliable alternative without losing functionality or control.

Microsoft Lens To Be Removed From iOS and Android App Stores

Microsoft has confirmed that Microsoft Lens will be removed from iOS and Android app stores and eventually disabled for creating new scans, although existing files will remain accessible if the app stays installed and you remain signed in.

Originally launched as Office Lens in 2015, it became widely used in business because it was free, simple and reliable. It allowed users to scan documents, whiteboards and business cards, convert them into searchable PDFs using OCR, and save them locally or to OneDrive, Word, PowerPoint and OneNote.

Microsoft is now directing users towards scanning within Microsoft OneDrive or Microsoft 365 Copilot. However, these do not fully replicate Lens. Features such as business card scanning to OneNote, read-aloud and Immersive Reader integration are not currently available.

For businesses, this means:

– Reviewing document workflows before scanning is disabled
– Exporting important scans before access becomes limited
– Deciding whether cloud-only storage via OneDrive is acceptable
– Considering alternative scanning apps for flexibility.

What to do now

– Export your existing scans
– Open Microsoft Lens
– Save each scan as a PDF
– Store a local copy
– Back up to your chosen cloud storage
– Confirm files open independently of the app.

Switch to OneDrive scanning

– Open the OneDrive app
– Tap the + button
– Select Scan
– Capture your document
– Save to your chosen folder.

Be aware that OneDrive does not support local-only storage.

Use a free alternative – here are some options (please note, these are suggestions and not recommendations).

Adobe Scan

– Download the app
– Sign in with a free account
– Scan documents using the camera
– Save as PDF
– Export to local or cloud storage

Genius Scan

– Install the app
– Capture documents
– Adjust borders
– Export as PDF
– Save locally or to your preferred cloud.

Google Drive (Android)

– Tap +
– Select Scan
– Save as PDF.

The key point is portability. Export everything as standard PDFs, keep copies outside any single app, and avoid relying on proprietary storage. That way, when Microsoft Lens closes, your documents and your workflow remain firmly under your control.

Company Check : Google’s App-Builder Expands To 15 More Countries

Google is widening access to Opal, its no-code AI mini-app builder, to 15 additional countries. However, new research warns that AI-accelerated development is outpacing software security.

What Is Opal?

Opal is a Google Labs experiment that turns a plain-English prompt into a working mini web app. Users describe what they want, then Opal assembles a visual workflow of inputs, AI model calls and outputs. Each step can be opened in an editor to review the prompt, adjust the logic, add new steps, or run the workflow step by step to see what happens and where it fails. Once ready, creators can publish the app to the web and share a link so others can use it with their Google accounts.

Google introduced Opal in the United States in late July 2025 as part of its push to make AI creation accessible to non-developers. The stated aim was essentially to let people turn ideas into small, useful tools without writing code, while keeping the workflow visible so it can be inspected and improved. However, when early U.S. adopters built more than just novelty projects, it seemed to nudge Google to move faster on a global rollout.

Where And When?

On 7 October 2025, Google said Opal would begin rolling out to 15 additional countries. These are Canada, India, Japan, South Korea, Vietnam, Indonesia, Brazil, Singapore, Colombia, El Salvador, Costa Rica, Panama, Honduras, Argentina and Pakistan. Google framed the expansion as a response to the sophistication of early user projects. As Megan Li, senior product manager at Google Labs, put it in a Google blog post, “we did not expect the surge of sophisticated, practical and highly creative Opal apps we got instead,” which made it clear the tool needed to reach “more creators globally.”

That said, the rollout remains within Google Labs and the product is still presented as just experimental, which may be helping Google to manage expectations at this point. For example, Google is giving the message that Opal is designed for rapid prototyping, automation and lightweight utilities, but not really for performance-critical systems. In other words, it’s a step toward broader access rather than the final word on enterprise-grade app building.

What Has Improved?

Alongside the expansion, Google announced two upgrades based around improving reliability and speed. The first is advanced debugging that stays no-code. With this, users can run a workflow step by step in the visual editor, or iterate on a single step in a console panel, with errors surfaced exactly where they occur. The second is a faster core, which means that the new Opal is snappier than before, and steps can run in parallel so complex workflows execute more quickly. Google’s hoping that these changes address common blockers for no-code builders, who need immediate context when something breaks and shorter wait times when experimenting.

Why Now?

Opal lowers the barrier to building AI-powered tools and keeps those experiments inside Google’s ecosystem. It also means that Google gets to learn what people are trying to build, where they get stuck, and which patterns succeed. That feedback loop improves the underlying models, the templates and the product itself. It also positions Google in a growing market where rivals are courting non-technical creators with prompt-to-app tools. Canva has expanded its Magic features, Figma has explored AI-assisted interface creation, and Replit has continued to blur lines between coding assistance and app scaffolding. By scaling Opal, Google can meet users where they are and channel more of that experimentation through its models and accounts.

Users And Teams

For individuals, Opal basically shortens the path from idea to working prototype. To give a few simple examples of how it could be used:

– A marketer could create a content repurposer that uses a brief to output social copy with a few review steps.

– A customer support manager could build a simple intake tool that classifies enquiries and drafts suggested replies for human approval.

– An analyst could chain together a data cleaning step, a summariser and a report generator without waiting for a development slot.

For teams inside businesses, the visual workflow aspect of Opal also matters. For example, people can see the logic, the prompts and the hand-offs between steps, which helps with training, peer review and handover when roles change. Publishing a mini-app as a link also makes internal distribution straightforward. That convenience is precisely why governance needs attention. Without some oversight, useful experiments can turn into shadow tools that handle customer data or trigger actions outside approved processes.

Businesses

Although the latest expansion does not include the UK, many UK organisations may be watching for signals about localisation, policy controls and Workspace integration. The draw is clear, i.e. faster prototypes mean faster experiments with customer journeys, marketing operations, knowledge management and lightweight analytics. The risk is also equally clear – if non-developers can publish AI-driven tools that interact with real data, then security, data protection and auditability have to be part of the pattern from day one. UK firms with regulated obligations will need to map Opal to existing controls for data handling, retention, identity and access, and change management.

Google’s Competitors

Following this wider rollout, Google’s competitors may now see three pressures intensify, which are:

1. Speed to value. Lower latency and parallel steps raise expectations for interactive build-iterate loops.

2. Visibility and trust. Step-level error context tackles a common barrier to adoption, which is uncertainty about what the AI system is doing and why it failed.

3. Distribution. Google can seed Opal where many small tools begin, inside consumer accounts and Workspace environments, which increases the chance of viral internal adoption once the feature reaches more markets.

Challenges And Criticisms

No-code tools typically hit a ceiling with bespoke integrations, complex data governance and strict performance requirements. With this in mind, Opal is unlikely to replace traditional engineering for systems of record or heavily regulated workflows. There are also questions about lock-in, portability and transparency. For example, if a mini-app depends on specific Google prompts or components, migrating it to another platform may not be trivial. Observers of AI-assisted creation have also raised concerns about inconsistency and security weaknesses in generated logic. Even with step-wise debugging, a workflow that calls external models can behave unpredictably across inputs, which complicates testing and assurance.

Security Debt’ In An AI-Accelerated World

This broader concern is reflected in new research from Black Duck, a long-running application security and open source risk specialist now part of Synopsys. For example, in a recent survey of 1,000 security professionals, 81 per cent said application security testing is slowing development and delivery, nearly 60 per cent said their organisations deploy code daily or more, and 46 per cent still rely on manual steps for security. The report warns that these patterns are creating “security debt”, with vulnerabilities left unaddressed as release velocity increases. It also highlights tool sprawl and alert fatigue, with 71 per cent of respondents complaining about noisy and duplicative alerts, and it notes that 61.64 per cent of organisations test less than 60 per cent of their applications. Veracode’s separate analysis adds context, estimating that average remediation times have increased from 171 days in 2020 to 252 days in 2025.

Black Duck’s CEO, Jason Schmitt, has previously said that the findings show traditional approaches to application security are no longer keeping pace with the speed of modern software delivery. The company has advised development teams to move towards integrated, automated security processes that sit directly within their everyday workflows, rather than relying on separate or reactive testing later in the cycle.

How This Connects To Opal And Similar Tools

Opal’s improvements in transparency and debugging make failures easier to spot and discuss, however they do not replace secure design, testing and monitoring. If AI lowers the threshold for building and sharing tools, more people will build more tools, which increases the importance of guardrails that operate at the point of creation. For organisations experimenting with Opal, that means deciding where such tools are permitted, classifying data types that may flow through them, setting standards for prompts and outputs, and ensuring that automated checks run when a mini-app is created and whenever dependencies change.

Black Duck’s long-running audits of commercial codebases routinely find vulnerable open source components and out-of-date dependencies. Even small utilities can pull in libraries, connect to services or incorporate code fragments that carry risk. The lesson here is not to block experimentation. It is also to bring security to where the experimentation happens, to reduce manual steps, and to ensure there is visibility of what has been published, by whom, and with what data access.

What To Watch

For Google, the next test is how Opal scales beyond early adopters, including whether it gains the policy controls and enterprise integrations that larger organisations expect. For rivals, it seems the bar for speed, transparency and distribution has now been nudged a bit higher. For business users, especially in the UK, there is an opportunity to prototype faster while maintaining a clear line of sight on data and permissions (when it rolls out here). For security leaders, the priority is to embed checks in the same workflows that tools like Opal enable, so that velocity and visibility move together rather than in conflict.

What Does This Mean For Your Business?

For Google, the global expansion of Opal signals a growing confidence in the idea that AI-powered app creation can be simplified without losing too much control. It also highlights a clear ambition to (thankfully for many) make natural language the next user interface for software development, i.e. simplifying and democratising software development. Whether that ambition holds depends on how effectively Google can balance accessibility with governance. As more non-developers begin building tools that act on live data, the risk of inconsistency, bias and poor security hygiene rises. That is where the lessons from Black Duck’s research become most relevant. The warning is that automation alone does not guarantee safety, and that speed without embedded checks will always carry hidden costs.

For UK businesses, the wider rollout offers some cautious hope. It shows what could soon be possible for teams wanting to automate small tasks or prototype new ideas without waiting for developer time. However, it’s also a reminder that security, compliance and auditability can’t really be left behind. Firms that already use low-code or AI-assisted systems may now want to consider how no-code tools like Opal might fit within existing frameworks for risk management and data governance. The most successful adopters will likely be those that integrate these tools responsibly, pairing innovation with oversight.

Other stakeholders will also be watching closely – regulators may seek to understand how accountability works when the code itself is generated, while competitors will be under pressure to match Google’s blend of speed and transparency. For users, the immediate value lies in creativity and productivity, but long-term trust will depend on how reliably these mini-apps behave and how safely they handle information. What Opal ultimately represents is a shift towards a more participatory form of software creation, where almost anyone can build, test and share ideas. The challenge now is ensuring that such openness develops alongside the same rigour that businesses and users expect from any other form of technology.

Security Stop-Press: Fake VPN App Drains Bank Accounts Across Europe

A fake Android VPN app has been caught stealing users’ money by giving hackers full control of their phones.

Researchers discovered the malicious app, Modpro IP TV + VPN (also known as Mobdro Pro IP TV + VPN), spreading through unofficial websites. Once installed, it drops a banking trojan called Klopatra, which has infected over 3,000 devices in Spain and Italy.

Klopatra exploits Android’s Accessibility Services to read screens, capture logins, and move money while users sleep. Apparently, it uses “Hidden VNC” to hide its actions and has evolved through more than 40 versions since March 2025, linked to a Turkish-speaking criminal group.

Experts warn that free VPN and IPTV apps can hide malware or weak privacy controls. Users who sideload apps, i.e. install them outside the Play Store, risk bypassing Google’s protections.

Businesses should block sideloaded apps, keep Android devices updated, and train staff to recognise risky downloads. Also, strong permission policies and mobile security tools remain key to stopping such attacks.

News : App Pays You For Your Phone Calls

A new iPhone app that pays users for their call recordings to train AI systems rose rapidly in late September. However, it then went offline after a security flaw exposed user data.

What Neon Is And Who Is Behind It?

Neon is a consumer app that pays users to record their phone calls and sells the anonymised data to artificial intelligence companies for use in training machine learning models. Marketed as a way to “cash in” on phone data, it positions itself as a fairer alternative to tech firms that profit from user data without compensation. The app is operated by Neon Mobile, Inc., whose New York-based founder, Alex Kiam, is a former data broker who previously helped sell training data to AI developers.

Only Just Launched

The app launched in the United States this month (September 2025). According to app analytics tracking, Neon entered the U.S. App Store charts on 18 September, ranking 476th in the Social Networking category. Amazingly, by 25 September, it had climbed to the No. 2 spot, and reached the top 10 overall ! On its peak day, it was downloaded more than 75,000 times. No official launch has yet taken place in the UK.

How Does The App Work?

Neon allows users to place phone calls using its in-app dialler, which routes audio through its servers. Calls made to other Neon users are recorded on both sides, while calls to non-users are recorded on one side only. Transcripts and recordings are then anonymised, with personal details such as names and phone numbers removed, before being sold to third parties. Neon says these include AI firms building voice assistants, transcription systems, and speech recognition tools.

Users are then paid in cash for the calls, credited to a linked account. The earnings model actually promises up to $30 per day, with 30 cents per minute for calls to other Neon users and lower rates for calls to non-users. Referral bonuses are also offered. While consumer data is routinely collected by many apps, Neon stands out because it offers direct financial incentives for the collection of real human speech, a form of data that is more intimate and sensitive than most.

The Legal Language Behind The Data Deal

Neon’s terms of service give the company an unusually broad licence to use and resell recordings. This includes a worldwide, irrevocable, exclusive right to reproduce, host, modify, distribute, and create derivative works from user submissions. The licence is royalty-free, transferable, and allows for sublicensing through multiple tiers. Neon also claims full ownership of outputs created from user data, such as training models or audio derivatives. For most users, this means permanently giving up control over how their voice data may be reused, sold, or processed in future.

Why The App Took Off So Quickly

Neon’s rapid growth appears to have been driven by a combination of curiosity, novelty, and, of course, cash and referral-led incentives. Many users were drawn in by the promise of payment for something they do every day anyway, i.e., talking on the phone. The idea of monetising phone calls is also likely to have appealed particularly to users who are increasingly aware that their data is being collected and sold elsewhere.

Social media posts promoting referral links and earnings screenshots also seem to have really helped fuel viral growth. At the same time, widespread interest in AI tools has normalised the idea of systems that listen, learn, and improve through exposure to large datasets.

What Went Wrong?

Unfortunately, it seems that shortly after Neon became one of the most downloaded apps in the U.S., independent analysis revealed a serious security flaw. The app’s backend was found to be exposing not only user recordings and transcripts but also associated metadata. This included phone numbers, call durations, timestamps, and payment amounts. Audio files could be accessed via direct URLs without authentication, creating a significant privacy risk for anyone whose voice was captured.

Neon’s response was to take the servers offline temporarily. In an email to users, the company said it was “adding extra layers of security” to protect data. However, the email did not mention the specific details of the exposure or what user information had been compromised. The app itself remained listed in the App Store, but was no longer functional due to the server shutdown.

Legal And Ethical Concerns Around Recording

Neon’s approach raises a number of legal questions, particularly around consent and data protection. For example, in the United States, phone call recording laws differ by state. Some states require consent from all participants, while others allow one-party consent. By only recording one side of a call when the other participant is not a Neon user, the company appears to be trying to avoid falling foul of two-party consent laws. However, experts have questioned whether this distinction is sufficient, especially when metadata and transcript content may still reveal personal information about the other party.

In the UK, where GDPR rules apply, the bar for lawful processing of voice data is much higher. Call recordings here are considered personal data, and companies must have a lawful basis to record and process them. This could be consent, contractual necessity, legal obligation, or legitimate interest. In practice, UK organisations must be transparent, inform all parties at the start of a call, and apply strict safeguards around storage, retention, and third-party sharing. If the recording includes special category data, such as health or political views, the legal threshold is even higher.

Why The Terms May Create Future Risk

The app’s terms of service not only cover the use of call data for AI training, but also grant Neon the right to redistribute or modify that data without further input from the user. That includes the right to create and sell synthetic voice products based on recordings, or to allow third-party developers to embed user speech in new datasets. This means that, once the data is sold, users have no real practical way of tracking where it ends up, who uses it, or for what purpose. That includes the potential for misuse in deepfake technologies or other forms of AI-generated impersonation.

Trust Issue For Neon?

The exposure of call data so early in the app’s lifecycle does seem to have caused (not surprisingly) a major trust issue. While the company has said it is fixing the security problem, it will now be subject to much higher scrutiny from app platforms, data buyers, and regulators. If Neon wants to relaunch, it may need to undergo independent security audits, publish full transparency reports, and add explicit call recording notifications and consent features. Commercially, the setback may impact deals with AI firms if those companies decide to distance themselves from controversial datasets.

What About The AI Companies Using Voice Data?

For companies developing speech models, the incident highlights the importance of knowing exactly how training data has been sourced. For example, buyers of voice datasets will now need to ask more detailed questions about licensing, user consent, jurisdiction, and security. Any material flaw in the source of data can invalidate models downstream, especially if it leads to legal challenges or regulatory action. Data provenance and ethical sourcing are likely to become higher priorities in due diligence processes for commercial AI development.

Issues For Users

While Neon claims to anonymise data, voice recordings generally carry an inherent risk. For example, voice is increasingly used as a biometric identifier, and recorded speech can be used to train systems that replicate tone, mannerisms, and emotional expression. For individuals, this could lead to impersonation or fraud. For businesses, there is a separate concern. If employees use Neon to record work calls, they may be exposing client conversations, proprietary information, or regulated data without authorisation. This could result in GDPR breaches, disciplinary action, or reputational harm. Companies should review their mobile and communications policies and block unvetted recording apps from use on managed devices.

Regulators And App Platforms

The rise and fall of Neon within a matter of days really shows how quickly new data models can go from idea to mass adoption. Platforms such as the App Store are now likely to face more pressure to assess the privacy implications of data-for-cash apps before they are allowed to scale. Referral schemes that incentivise covert recording or encourage over-sharing are likely to be reviewed more closely. Regulators may also revisit guidance on audio data, especially where recordings are repackaged and resold to machine learning companies. Voice data governance, licensing standards, and ethical AI sourcing are likely to become more prominent areas of focus in the months ahead.

Evaluating Tools Like Neon

For organisations operating in the UK, the launch of Neon should serve as a prompt to tighten call recording policies and educate staff on data risk. If a similar service becomes available locally, any use would need a clear lawful basis, robust security controls, and transparency for all parties involved. This includes notifying people before recording begins, limiting the types of calls that can be recorded, and putting strict controls on where that data is sent. In regulated industries, the use of external apps to record voice data could also breach sector-specific rules or codes of conduct. A risk assessment and DPIA would be required in most business contexts.

What Does This Mean For Your Business?

The Neon episode shows just how fast the appetite for AI training data is reshaping the boundaries of consumer tech. In theory, Neon offered a way for users to reclaim some value from a data economy that usually runs without them. In practice, it seems to have revealed how fragile the balance is between innovation and responsibility. When that data includes private conversations, even anonymised, the margin for error is narrow. Voice is not like search history or location data because it’s personal, expressive, and hard to replace if misused.

What happened with Neon also appears to show how little control users have once they opt in. For example, the terms of service handed the company almost total freedom to store, repackage, and resell recordings and outputs, with no practical ability for users to track where their voice ends up. Even if users are comfortable making that trade, the people they speak to may not be. From an ethical standpoint, recording conversations for profit, especially with people unaware they are being recorded, raises serious questions about consent and accountability.

For UK businesses, the risks are not just theoretical. If employees start using similar apps to generate income, they could unintentionally upload sensitive or regulated information to unknown third parties. That creates exposure under GDPR, commercial contracts, and sector-specific codes, and may breach client trust. Businesses will need to move quickly to block such apps on company devices and reinforce clear internal rules around recording, call handling, and use of AI data services.

For AI companies, the lesson is equally clear. The hunger for diverse, real-world training data must be matched with rigorous scrutiny of how that data is sourced. Datasets obtained through poorly controlled consumer schemes are more likely to carry risk, not only in terms of legality but also model quality and future auditability. Voice data is especially sensitive, and provenance will now need to be a standard consideration in every procurement and development process.

More broadly, Neon’s brief rise exposes the gap between platform rules, regulatory oversight, and the speed of public adoption. App marketplaces now face growing pressure to vet data-collection models more stringently, particularly those that monetise content recorded from other people. It also raises a wider challenge: how to build the AI systems people want without normalising tools that trade in privacy. As interest in AI grows, the burden of building that future responsibly will only increase for every stakeholder involved.

Security Stop-Press: Malicious AI-Driven Bots Make Up Over a Third of Internet Traffic

Malicious bots now account for 37 per cent of all internet traffic, according to cybersecurity firm Imperva’s 2025 Bad Bot Report, with AI playing a central role in their rapid evolution.

For the first time in a decade, automated traffic (51 per cent) has overtaken human activity online. The rise of accessible AI tools has not only made bots more evasive and effective but also lowered the barrier for low-skilled attackers to launch simple, high-volume attacks.

Imperva warns that bots are increasingly targeting APIs, with 44 per cent of advanced bot traffic now focused on exploiting business logic. These bots scrape data, commit payment fraud, and hijack accounts, often bypassing detection by mimicking human users and leveraging residential proxies, browser spoofing, and CAPTCHA-solving AI.

Tools like ByteSpider (responsible for 54 per cent of AI-powered bot attacks), AppleBot (26 per cent), and ClaudeBot (13 per cent) are being spoofed to launch attacks. Meanwhile, account takeover (ATO) attacks have surged by 54 per cent since 2022, hitting sectors like financial services and telecoms hardest.

Imperva says businesses must urgently adapt by deploying advanced bot detection, securing APIs, applying rate limits, and monitoring for suspicious behaviour. With AI fuelling both the volume and sophistication of attacks, staying ahead requires constant vigilance and smarter defences.

Tech Tip – Quickly Open a Second Instance of Any App

If you need multiple windows of the same app (e.g. File Explorer, Notepad, or Word), you don’t have to navigate menus. Here’s how to quickly and easily open more windows:

How to do it :

– Hold Shift and Click on an open app’s icon in the taskbar.

– This will launch a new window of that app instantly.

– This is perfect for multitasking, such as working on multiple documents at once.