Security Stop-Press : Met Police Made 700,000 Data Requests To Tech Firms

A Freedom of Information request has revealed that London’s Metropolitan Police requested communications data from technology companies more than 700,000 times during 2025, highlighting the scale of modern digital surveillance.

The requests covered mobile networks, email providers and online services. Although they generally did not involve message content, they could include metadata such as account details, IP addresses and contact records.

The figures also showed a nearly 500 per cent increase in requests to Lyca Mobile, while data was sought from services including Proton, Signal, Uber and Deliveroo. Some privacy-focused providers disputed aspects of the figures.

For businesses, the findings are a reminder that metadata can reveal a great deal about people, communications and behaviour, making data governance and privacy controls increasingly important.

Tech News : NHS Broadens Contractor Access To Patient Data

Fresh controversy has erupted around the NHS Federated Data Platform after reports claimed Palantir contractors and other external staff could be granted much broader access to identifiable patient data inside one of the NHS’s most sensitive systems.

What’s Happening To Our Health Data?

According to a recent report in the Financial Times, NHS England has approved the creation of a new administrative access role inside its National Data Integration Tenant, or NDIT, which sits at the heart of the NHS Federated Data Platform (FDP).

The NDIT is effectively a controlled environment where identifiable patient data is held before information is pseudonymised and distributed into other operational systems connected to the FDP.

Until now, external personnel working on the platform reportedly had to apply for access to specific datasets individually through what NHS England calls Controlled Data Access requests.

However, it’s been reported that leaked internal briefing documents argued that the process had become operationally difficult and time-consuming, particularly given the scale and complexity of the FDP programme.

As a result, NHS England has reportedly approved a broader “admin” role allowing a small number of approved non-NHS personnel to access data inside the NDIT without repeated case-by-case approvals.

Some critics are even describing the arrangement as effectively creating “unlimited access” for contractors inside part of the NHS’s flagship data infrastructure project.

NHS England has strongly pushed back against suggestions that controls are being weakened, saying the organisation maintains “strict policies in place for managing access to patient data” and carries out “regular audits to ensure compliance”, while also stressing that any external access requires government security clearance and director-level approval.

What Is The Federated Data Platform?

The FDP is one of the NHS’s largest digital transformation projects. The £330 million contract was awarded in 2023 to a consortium led by Palantir Technologies, a US data analytics company best known for its work in defence, intelligence, security, and large-scale data integration.

The platform is designed to connect fragmented NHS operational datasets into a unified system intended to improve waiting list management, resource allocation, planning, and operational efficiency.

NHS England argues the FDP will help modernise healthcare operations and improve patient outcomes by allowing NHS organisations to use data more effectively across trusts and services.

The NHS also insists that patient data remains under NHS control at all times, with Palantir legally acting only as a “data processor” operating under NHS instructions.

Who Are Palantir And Peter Thiel?

Much of the controversy surrounding the FDP stems not simply from the technology itself, but from Palantir’s wider reputation and affiliations.

Palantir Technologies was co-founded in 2003 by billionaire investor Peter Thiel alongside executives linked to PayPal and US intelligence circles.

Thiel is one of Silicon Valley’s most influential and controversial figures. He was an early Facebook investor, co-founder of PayPal, and has longstanding links to conservative US political movements and defence technology investment.

Palantir itself originally built software for US intelligence and military agencies following the September 11 attacks and has since expanded heavily into defence, immigration enforcement, policing, and government analytics worldwide.

The company has worked with organisations including the CIA, FBI, Pentagon, US Immigration and Customs Enforcement (ICE), NATO, and multiple Western defence agencies.

Critics argue that background makes Palantir an uncomfortable fit for handling sensitive NHS infrastructure and patient data, particularly given growing public concern about AI, surveillance, and data concentration inside critical public services.

Supporters, however, argue that Palantir specialises precisely in the kind of large-scale data integration and operational analytics the NHS badly needs.

Why This Matters Politically

The latest reports have reignited long-running concerns from privacy campaigners, MPs, and patient rights groups who argue the NHS risks eroding public confidence if governance boundaries become unclear.

The leaked NHS briefing itself reportedly acknowledged “considerable public interest and concern” around how much access Palantir staff may have to NHS patient data.

Labour MP Rachael Maskell has described the latest development as “dangerous”, while patient advocacy groups questioned why patients had not been more directly consulted.

At the centre of the debate is a broader tension facing governments worldwide.

Modern AI systems and advanced analytics often work best when large datasets can be integrated, connected, and analysed centrally. However, the more powerful and interconnected those systems become, the greater the concerns around access control, oversight, accountability, and misuse.

The NHS insists safeguards remain in place, including role-based access controls, UK-only data storage, security clearances, auditing, and contractual restrictions preventing Palantir from commercialising NHS data or training AI models on it. However, critics argue the issue is increasingly about trust as much as technical controls.

What Does This Mean For Your Business?

For businesses and organisations, the controversy highlights how rapidly debates around AI, analytics, and data governance are moving from technical discussions into questions of trust, transparency, and public legitimacy.

The NHS FDP project also demonstrates how AI and large-scale analytics are increasingly becoming embedded inside critical national infrastructure rather than remaining standalone software tools.

Many organisations are now facing similar tensions themselves, i.e., balancing operational efficiency, automation, and AI capability against privacy concerns, governance expectations, supplier concentration risks, and reputational exposure.

The Palantir row may ultimately become less about one NHS contract and more about how comfortable people are with huge global technology corporations having access to highly sensitive personal health information, particularly as AI-driven systems become more deeply embedded inside essential public services and everyday decision-making.

Security Stop-Press : AI Agents Can Leak Data Through Chat Link Previews

AI agents running inside messaging apps can leak sensitive data through automatic link previews, researchers at AI security firm PromptArmor have warned, creating a zero-click data exfiltration risk.

The flaw reportedly exploits indirect prompt injection. For example, an attacker tricks an agent into generating a malicious URL containing sensitive information, such as API keys, in its query string. Messaging platforms like Slack, Teams, Telegram and Discord often fetch links automatically to generate previews, meaning the data-leaking URL can be requested instantly, without the user clicking it.

PromptArmor said: “In agentic systems with link previews, data exfiltration can occur immediately upon the AI agent responding to the user, without the user needing to click the malicious link.”

To test exposure, the firm created the AITextRisk.com website, which logs preview fetches from different agent and app combinations. Reported at-risk pairings include Microsoft Teams with Copilot Studio and Telegram with OpenClaw, the latter being exposed by default unless link previews are disabled in its configuration.

Businesses using AI agents in messaging platforms should review preview settings urgently, disable link previews in sensitive channels where possible, restrict agent access to secrets, and test their own app and agent pairings to identify potential zero-click data loss risks.

Security Stop-Press : ChatGPT Health Brings New Data Security Risks

OpenAI has launched ChatGPT Health, a dedicated space for health and wellness conversations that allows users to link personal health data, raising fresh security and privacy concerns around highly sensitive information.

OpenAI says more than 230 million people ask health-related questions on ChatGPT each week, prompting the creation of a separate Health environment with additional protections. Health conversations are isolated from standard chats, encrypted, and excluded from model training, while users can connect data from apps such as Apple Health and other wellness platforms with explicit consent.

Despite these safeguards, ChatGPT Health concentrates medical history, lifestyle data, and behavioural context into a single AI account. If an account is compromised through phishing, weak passwords, or reused credentials, attackers could potentially gain access to deeply personal health information rather than just general chat content. OpenAI also stresses that Health is not intended for diagnosis or treatment, as large language models can still produce inaccurate or misleading responses.

For businesses, the risk lies in staff using AI tools with sensitive personal data on accounts that may not be properly secured. Strong password policies, mandatory multi-factor authentication, and clear guidance on linking personal data to AI services are essential steps to reduce exposure as consumer health features increasingly overlap with everyday work technology.

Tech News : EU Renews UK Data Adequacy Decisions Until 2031

The European Commission has renewed its decisions allowing personal data to flow freely between the EU and the UK, confirming that the UK’s data protection framework continues to meet EU standards despite recent legal changes.

Applies To Two Frameworks

The decision, announced on 19 December 2025, extends the EU’s existing data adequacy arrangements with the UK for a further six years, until December 2031. It applies to two parallel frameworks, one under the General Data Protection Regulation and another covering law enforcement data under the Law Enforcement Directive. Together, these decisions determine whether personal data can be transferred from the European Economic Area to the UK without additional safeguards or legal mechanisms.

What Data Adequacy Means In Practice

Under EU law, personal data can only be transferred outside the EU and EEA if the receiving country provides an “adequate” level of protection. Adequacy decisions are adopted by the European Commission and confirm that a third country’s legal and regulatory framework offers protections that are essentially equivalent to those guaranteed under EU law.

For example, when an adequacy decision is in place, organisations can transfer personal data without needing to rely on alternative tools such as standard contractual clauses, binding corporate rules, or case by case risk assessments. For businesses, public bodies, and digital services, this significantly reduces legal complexity, compliance costs, and operational friction.

The UK first received adequacy decisions in 2021, following its departure from the EU. Those decisions were time limited and included a sunset clause, reflecting concerns about future regulatory divergence after Brexit.

Why The Renewal Was Not Automatic

The original UK adequacy decisions were due to expire on 27 December 2025 but, in June 2025, the Commission adopted a technical six month extension to avoid a legal cliff edge while it reassessed the UK’s legal framework. This review was triggered by the passage of the Data (Use and Access) Act, which amended aspects of UK data protection law.

The Act introduced targeted changes, including adjustments to how personal data can be used for research and charitable fundraising, alongside new requirements for organisations to operate clearer data protection complaints procedures. The UK government described the reforms as limited and pragmatic rather than a wholesale departure from GDPR, but they nonetheless required close scrutiny by EU regulators.

During the extension period, the Commission assessed whether the amended UK framework continued to meet the threshold of essential equivalence required under EU law. This assessment covered both general data protection under GDPR and the handling of personal data for policing and criminal justice purposes under the Law Enforcement Directive.

The Role Of EU Oversight Bodies

The renewal decision followed a formal process involving EU institutions and Member States. The European Data Protection Board, which brings together national data protection authorities across the EU, issued an opinion on the UK’s legal framework. Member States then gave their approval through the so-called comitology procedure, which allows national representatives to scrutinise and endorse Commission implementing decisions.

Sufficiently Aligned

The Commission concluded that the UK’s safeguards remain sufficiently aligned with EU standards, including in areas such as individual rights, oversight mechanisms, and restrictions on onward transfers of data to other third countries.

As with the original decisions, the renewed adequacy determinations include safeguards designed to monitor future developments. A review of how the arrangements are functioning is scheduled after four years, with the option to amend, suspend, or revoke adequacy if the UK diverges in ways that undermine data protection.

A Six Year Extension With Built In Limits

The renewed adequacy decisions will now run until 27 December 2031 and include a fresh sunset clause. This essentially means adequacy is not permanent and must be actively reassessed in light of legal, political, and technological changes.

From the Commission’s perspective, this structure balances continuity with control. It provides long-term legal certainty for organisations that depend on EU UK data transfers, while preserving the EU’s ability to intervene if standards fall.

For UK businesses, the extension avoids what many had warned would be a serious disruption. The UK is one of the EU’s largest data partners, with personal data flowing daily for purposes including trade, financial services, health research, cloud computing, advertising, and human resources management.

Economic And Operational Significance

Industry groups and legal experts have repeatedly warned that losing adequacy would impose substantial compliance burdens. Organisations would need to put alternative transfer mechanisms in place, reassess international data flows, and potentially redesign systems and contracts at short notice.

Previous estimates from UK industry bodies have suggested that the administrative cost of relying on standard contractual clauses and transfer risk assessments could run into billions of pounds across the economy. Also, smaller organisations, charities, and public sector bodies would likely be hit hardest.

The Commission explicitly highlighted these practical implications in its announcement. Henna Virkkunen, Executive Vice President for Tech Sovereignty, Security and Democracy, said the renewal “benefits businesses and citizens alike on both sides of the Channel”. She added that it “ensures the free flow of personal data between the EEA and the UK in full compliance with data protection rules while reducing costs and administrative burdens”.

Virkkunen also emphasised continuity for European organisations, stating that the decision allows companies to keep sharing data seamlessly with UK partners, supporting innovation, competitiveness, and trusted digital cooperation.

Law Enforcement And Justice Cooperation

The adequacy decision covering law enforcement data is particularly significant because it underpins data sharing between EU Member States and UK authorities for policing, criminal investigations, and judicial cooperation.

Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, described the United Kingdom as “an important strategic partner for the European Union”. He said the adequacy decisions “form a central pillar of this partnership” by enabling both commercial exchanges and cooperation in the fields of justice and law enforcement.

McGrath added that the renewal reflects the Commission’s assessment that the UK’s legal framework continues to provide robust safeguards for personal data that remain closely aligned with EU standards, including in the context of recent legislative developments.

Ongoing Concerns And Future Scrutiny

It should be noted here, however, that while the renewal provides stability, it does not remove all uncertainty. Privacy advocates and some EU lawmakers have previously raised concerns about the UK’s approach to surveillance, data sharing with third countries, and the potential for future divergence from GDPR principles.

The four year review mechanism is intended to address these risks by allowing the Commission and the European Data Protection Board to reassess adequacy in light of concrete evidence rather than hypothetical concerns. Any significant weakening of protections could still result in suspension or revocation of the decisions.

For now though, it looks as though the Commission’s renewal signals confidence that the UK remains closely aligned with EU data protection standards, while retaining the ability to revisit that judgement if circumstances change.

What Does This Mean For Your Business?

The renewal confirms that the EU continues to see the UK as a trusted destination for personal data, despite political separation and limited legal divergence since Brexit. It removes the immediate risk of disruption to data flows that underpin everyday commercial activity, public services, and cross border cooperation. For now, the legal foundations that allow organisations to move personal data between the EU and UK without additional safeguards remain intact.

For UK businesses, this brings practical certainty. For example, companies operating across borders can continue to rely on existing systems, contracts, and data driven services without having to introduce costly transfer mechanisms or redesign operations at short notice. That stability is particularly important for sectors such as finance, technology, healthcare, research, and professional services, where routine access to EU personal data is fundamental rather than optional.

The decision also has wider implications beyond commerce. Continued adequacy supports cooperation between regulators, law enforcement agencies, and public authorities, ensuring that data sharing for policing, justice, and safeguarding purposes can continue without new legal barriers. At the same time, the inclusion of a sunset clause and a four year review reflects the EU’s ongoing caution, making clear that adequacy depends on sustained alignment rather than historical precedent.

Taken together, the renewal appears to strike a careful balance. In essence, it signals confidence in the UK’s current data protection framework while reinforcing that future reforms will be judged against EU standards. For businesses and other stakeholders, the takeaway message is that the current framework offers breathing space and legal certainty, but long-term stability will depend on how closely the UK continues to track core principles of EU data protection law.

Security Stop-Press: AI Chat Data Harvested Without Clear Consent

It’s been reported that Meta and analytics firms are quietly turning private AI chats into advertising fuel, with little user control and growing legal concerns.

From 16 December 2025, Meta will begin using users’ conversations with Meta AI to personalise ads across Facebook, Instagram, WhatsApp, and Messenger. There’s no opt-out, though the UK, EU, and South Korea are excluded for now. Meta claims sensitive topics like health and politics won’t be used.

Also, startup Profound says it has access to over 150 million real AI chats to help brands analyse how they appear in chatbot results. Experts believe the data comes from browser extensions that log chat content without clear user consent, which is a claim that Profound denies.

Privacy professionals warn that vague permissions like “read all data on websites” may breach UK GDPR and PECR rules, especially when users aren’t fully informed. Similar practices by firms like Onavo and Jumpshot have previously triggered regulatory action.

Businesses should treat AI chats as sensitive data, restrict browser extensions, and demand transparency from any vendor using AI interaction data.

Company Check : Claude In CoPilot & Google Data Commons

Microsoft has confirmed it is adding Anthropic’s Claude models to its Copilot AI assistant, giving enterprise users a new option alongside OpenAI for handling complex tasks in Microsoft 365.

Microsoft Expands Model Choice In Copilot

Microsoft has begun rolling out support for Claude Sonnet 4 and Claude Opus 4.1, two of Anthropic’s large language models, within Copilot features in Word, Excel, Outlook and other Microsoft 365 apps. The update applies to both the Copilot “Researcher” agent, used for generating reports and conducting deep analysis, and Copilot Studio, the tool businesses use to build their own AI assistants.

The move significantly expands Microsoft’s model options. Until now, Copilot was powered primarily by OpenAI’s models, such as GPT‑4 and GPT‑4 Turbo, which run on Microsoft’s Azure cloud. With the addition of Claude, Microsoft is now allowing businesses to choose which AI model they want to power specific tasks, with the aim of offering more flexibility and improved performance in different enterprise contexts.

Researcher users can now toggle between OpenAI and Anthropic models once enabled by an administrator. Claude Opus 4.1 is geared towards deep reasoning, coding and multi‑step problem solving, while Claude Sonnet 4 is optimised for content generation, large‑scale data tasks and routine enterprise queries.

Why Microsoft Is Doing This Now

Microsoft has said the goal is to give customers access to “the best AI innovation from across the industry” and to tailor Copilot more closely to different work needs. However, the timing also reflects a broader shift in Microsoft’s AI strategy.

While Microsoft remains OpenAI’s largest financial backer and primary cloud host, the company is actively reducing its dependence on a single partner. It is building its own in‑house model, MAI‑1, and has recently confirmed plans to integrate AI models from other firms such as Meta, xAI, and DeepSeek. Anthropic’s Claude is the first of these to be made available within Microsoft 365 Copilot.

This change also follows a wave of high‑value partnerships between OpenAI and other tech companies. For example, in recent weeks, OpenAI has secured billions in new infrastructure support from Nvidia, Oracle and Broadcom, suggesting a broader distribution of influence across the AI landscape. Microsoft’s latest move helps hedge against any future change in the balance of that relationship.

Microsoft And Its Customers

The introduction of Claude into Copilot is being made available first to commercial users who are enrolled in Microsoft’s Frontier programme, i.e. the early access rollout for experimental Copilot features. Admins must opt in and approve access through the Microsoft 365 admin centre before staff can begin using Anthropic’s models.

Importantly, the Claude models will not run on Microsoft infrastructure. Anthropic’s AI systems are currently hosted on Amazon Web Services (AWS), meaning that any data processed by Claude will be handled outside Microsoft’s own cloud. Microsoft has made clear that this data flow is subject to Anthropic’s terms and conditions.

This external hosting has raised concerns in some quarters, particularly for organisations operating under strict compliance or data residency requirements. Microsoft has responded by emphasising the opt‑in nature of the integration and the ability for administrators to fully control which models are available to users.

For Microsoft, the move appears to strengthen its claim to be a platform‑agnostic AI provider. By integrating Anthropic alongside OpenAI and offering seamless switching between models in both Researcher and Copilot Studio, Microsoft positions itself as a central point of access for enterprise AI, regardless of where the models originate.

Business Relevance And Industry Impact

The change is likely to be welcomed by business users seeking more powerful or specialised models for specific workflows. It may also create new pressure on OpenAI to continue improving performance and pricing for enterprise use.

From a competitive standpoint, Microsoft’s ability to offer Claude inside its productivity suite puts further distance between Copilot and rival AI products from Google Workspace and Apple’s AI integrations. It also allows Microsoft to keep pace with fast‑moving developments in multi‑model orchestration, the ability to run different tasks through different models depending on context or output goals.

For Microsoft’s competitors in the cloud and productivity space, the integration also highlights a growing interoperability challenge. Anthropic is mainly backed by Amazon, and its models run on both AWS and Google Cloud. Microsoft’s decision to incorporate those models into 365 tools represents a break from traditional cloud loyalty and suggests that, in the era of generative AI, usability and capability may matter more than where the models are hosted.

The Google Data Commons Update

While Microsoft is focusing on model integration, Google has taken a different step by making structured real‑world data easier for AI developers to use. This month, it launched the Data Commons Model Context Protocol (MCP) Server, a new tool that allows developers and AI agents to access public datasets using plain natural language.

The MCP Server acts as a bridge between AI systems and the vast Data Commons database, which includes datasets from governments, international organisations, and local authorities. This means that developers can now build agents that access census data, climate statistics or economic indicators simply by asking for them in natural language, without needing to write complex code or API queries.

The launch aims to address the two long‑standing challenges in AI of hallucination and poor data quality. For example, many generative models are trained on unverified web data, which makes them prone to guessing when they lack information. Google’s approach should, therefore, help ground AI responses in verifiable, structured public datasets, improving both reliability and relevance.

ONE Data Agent

One of the first use cases is the ONE Data Agent, created in partnership with the ONE Campaign to support development goals in Africa. The agent uses the MCP Server to surface health and economic data for use in policy and advocacy work. However, Google has confirmed that the server is open to all developers, and has released tools and sample code to help others build similar agents using any large language model.

For Google, this expands its role in the AI ecosystem beyond model development and into data infrastructure. For developers, it lowers the technical barrier to creating trustworthy data‑driven AI agents and opens up new opportunities in sectors such as education, healthcare, environmental analysis and finance.

What Does This Mean For Your Business?

The addition of Claude to Microsoft 365 Copilot marks a clear move towards greater AI optionality, but it also introduces new complexities for both Microsoft and its enterprise customers. While the ability to switch between models gives businesses more control and the potential for improved task performance, it also means IT teams must assess where and how their data is being processed, especially when it leaves the Microsoft cloud. For some UK businesses operating in regulated sectors, this could raise concerns around data governance, third-party hosting, and contractual clarity. Admin-level opt-in gives organisations some control, but the responsibility for managing risk now falls more squarely on IT decision-makers.

For Microsoft, this is both a technical and strategic milestone. The company is reinforcing its Copilot brand as a neutral gateway to the best models available, regardless of origin. It sends a signal that AI delivery will be less about vendor exclusivity and more about task-specific effectiveness. For competitors, the integration of Anthropic models into Microsoft 365 may accelerate demand for open, composable AI stacks that can handle model switching, multi-agent coordination, and fine-grained prompt routing, especially in workplace applications.

Google’s decision to open up real-world data through the MCP Server supports a different but equally important part of the AI ecosystem. For example, many UK developers struggle to ground their AI agents in reliable facts without investing heavily in custom pipelines. The MCP Server simplifies this process, making structured public data directly accessible in plain language. If adopted widely, it could help reduce hallucinations and increase the usefulness of AI across sectors such as policy, healthcare, sustainability, and finance.

Together, these announcements suggest that the next phase of AI will be shaped not only by which models are most powerful, but also by who can offer the most useful data, the clearest integration paths, and the most practical tools for real-world business use. For UK organisations already exploring generative AI, both moves offer new possibilities, but also demand closer scrutiny of how choices around models and data infrastructure will affect operational control, user trust, and long-term value.

Tech News : Cable-Cutting : Cat And Mouse

New fibre optic sensing technology is being deployed under the Baltic Sea to detect and deter sabotage attempts on Europe’s critical subsea data cables.

Subsea Cables Carry the World’s Internet

Many people may not know that nearly all global internet traffic depends on cables running across the seabed. Although these are slender fibre optic lines, often just a few centimetres thick, they actually carry around 99 per cent of intercontinental data! As such, these cables link whole countries, power financial markets, and support global communications infrastructure.

For example, the seabed beneath the Baltic Sea is criss-crossed by dozens of these connections, linking Sweden, Finland, Estonia, Latvia, Lithuania, Poland and Germany. These cables are essential to both internet access and the flow of electricity from offshore renewables.

However, these undersea cables are exposed and vulnerable to damage, e.g. from anchors or fishing gear, or even from deliberate sabotage, as tensions rise in the region.

Unexplained Cable Damage Has Triggered a Response

Several recent incidents have put the vulnerability of the subsea cables in the Baltic firmly in the spotlight. In late 2023 and early 2024, multiple data and power cables were damaged in unexplained circumstances. Although investigations are still ongoing, European leaders have taken the incidents seriously.

The EU’s New Initiative To Protect The Cables

In February 2025, the European Commission launched a new initiative to protect subsea infrastructure, warning that cable disruptions “risk causing severe interruptions to essential services” across the EU. The strategy sets out new funding, detection systems, mapping efforts and plans for smarter, more secure cables.

The NATO-led “Baltic Sentry” mission, using drones, warships and aircraft to patrol the sea, was also launched in response. However, with thousands of kilometres of seabed to monitor, authorities have found it necessary to turn to a new kind of defence, i.e. smart sensor cables that can detect threats in real-time.

How Fibre Optic Cables Can ‘Hear’ Underwater Activity

The idea is deceptively simple, i.e. use existing fibre optic cables to listen for disturbances. This is made possible by a technique called Distributed Acoustic Sensing (DAS). In short, light pulses are sent down a fibre optic line. When that line is disturbed (by vibrations, movement or temperature changes) it alters the light signal, which can then be analysed.

Examples of what these fibre optic sensor cables can detect include:

– Divers, drones or submersibles near the cable.

– Anchors being dropped or dragged along the seabed.

– Vessels passing overhead, including their size, speed and direction.

– Dredging, tunnelling or unauthorised seabed activity.

During tests, it’s been found that such acoustic sensing systems could detect a diver simply brushing the cable. In one demonstration, a buried cable was even able to pick up nearby footsteps and even a distant gunshot.

Cross-Referenced

The information from the cable can be cross-referenced with satellite images or vessel tracking data to confirm whether suspicious activity is occurring. In practice, it becomes a silent surveillance network lying on the seabed, detecting threats without giving away its presence.

Who’s Building These Systems And Where Are They Being Used?

Several companies are already rolling out this technology, with Germany’s AP Sensing and the Netherlands-based Optics11 leading the charge.

AP Sensing’s solution uses Distributed Fibre Optic Sensing (DFOS) to monitor telecoms cables, power lines and gas pipelines. The company says its system can provide real-time alerts and pinpoint exactly where a disturbance is occurring, even differentiating between routine vessel traffic and potential intrusions.

Although AP Sensing has confirmed that its systems are in place on some cable routes in the North Sea, it has not disclosed specific locations for security reasons. However, the Baltic is a clear focus area for future deployments.

Optics11 is developing systems that can be laid independently of the main cables. The company says these could act as early-warning sensors in strategic zones, e.g. 100km from a critical port or around key gas pipelines.

How The Sensors Are Deployed

Both AP Sensing and Optics11 say that these sensor systems can be deployed without laying new cables. Instead, they rely on something called “dark fibre” which are unused strands within existing fibre optic cables that were installed for future capacity. These dormant fibres can be activated and connected to specialist monitoring equipment on land, turning them into sensing lines without disturbing the cable itself.

If no dark fibre is available, the system can (sometimes) use spare channels on active fibres. In either case, the main undersea cables stay where they are, i.e. there’s no need to slide anything new into the seabed. It’s the light signals running through the fibre that are doing the ‘listening’.

A New Line of Defence – But It Has Limits

While the technology appears to be powerful, it isn’t perfect. For example, one of the key limitations is range. In most cases, disturbances must occur within a few hundred metres of the fibre to be reliably detected, so interrogators (the specialist devices that analyse the signals) must be installed roughly every 100km to keep the system functioning. This, unfortunately, makes full coverage expensive, especially across long distances or in deep water.

Another challenge is what happens after a disturbance is detected. For example, detecting a diver or anchor is useful but without a rapid response capability, there’s still a risk of damage before any intervention can take place.

Also, even the most physically robust cables are not immune. According to Swedish cable manufacturer Hexatronic, although lines are reinforced with metal armouring and thick protective layers, even these can be severed by a deliberate dragging of a ship’s anchor, especially at shallow depths.

Why the Baltic Sea Is Europe’s Top Priority Right Now

The Baltic region has become a focal point for infrastructure protection, and not by coincidence. For example, its shallow waters, heavy commercial traffic and its strategic proximity to Russia all make the area particularly vulnerable. Many of the recent cable damage incidents (and subsequent investigations) have occurred here, prompting coordinated action. In response, the European Commission has laid out a wide-ranging plan that includes:

– Mapping all subsea cables across EU waters by the end of 2025.

– Launching a “Cable Security Toolbox” of protective measures.

– Funding new smart cables with inbuilt sensing capabilities.

– Creating a list of critical “Cable Projects of European Interest”.

– Increasing repair capacity and backup systems to minimise downtime.

These efforts are being coordinated with NATO activities and national security strategies. The EU’s 2025 roadmap also links in with the NIS2 cybersecurity directive and the Critical Entities Resilience (CER) directive, two major legal frameworks designed to harden infrastructure against hybrid threats.

China Introduces a Powerful Deep-Sea Cable Cutter

Whilst this is all happening, China has unveiled a powerful deep-sea cable cutter capable of severing heavily protected undersea lines at depths up to 4,000 meters—beyond existing operational ranges.

Developed by the China Ship Scientific Research Centre and the State Key Laboratory of Deep-sea Manned Vehicles, it can be fitted to both crewed and uncrewed submersibles like Fendouzhe and Haidou. Originally intended for civilian salvage and seabed mining, its dual-use potential could alarm nations reliant on undersea communication cables that carry 95 percent of global data.

This is the first official disclosure of a device that could disrupt critical maritime infrastructure.

What Does This Mean For Your Business?

With geopolitical tensions rising and critical infrastructure increasingly targeted, fibre optic sensing offers a promising (and highly practical) way to spot trouble early. By transforming existing cables into silent surveillance tools, Europe may be beginning to close a dangerous blind spot beneath the waves.

However, as with most emerging technologies, this isn’t a silver bullet. Sensor systems still rely on swift responses from coastguards or military forces to intervene if sabotage is suspected. Their coverage is limited by distance, their deployment by cost. Even the most advanced system can only alert, it can’t physically stop damage from being done in the first place. That said, the strength of this technology lies in its ability to provide that vital early warning, buying time when it matters most.

For the UK, this move towards smarter cable monitoring is not just a continental concern. For example, Britain’s own subsea networks connect it to Europe, North America and beyond, underpinning the data economy, financial services and everyday digital life. UK telecoms providers and energy firms will likely need to follow developments in the Baltic closely, both to understand the risks and to assess the potential of retrofitting their own infrastructure with acoustic sensing capabilities.

At the same time, the opportunity for UK-based firms specialising in cyber-physical systems, marine engineering or signal analytics could be significant. As the EU ramps up investment in cable resilience and NATO deepens its interest in subsea surveillance, demand for this kind of expertise will grow across both civil and defence sectors.

The wider lesson from the Baltic, therefore, is that the digital world doesn’t float in the cloud but it sits on the seabed. As governments, companies and regulators begin to grasp just how critical and exposed that infrastructure really is, technologies like fibre optic sensing are likely to become part of a much broader push to harden Europe’s digital backbone. The challenge now is ensuring that detection leads to action, and that security keeps pace with the threat.

Featured Article : Apple Stops Advanced Data Protection Feature in the UK

Apple has announced the removal of its Advanced Data Protection (ADP) tool from customers in the United Kingdom, following a contentious dispute with the UK government over user data access.

Debate Ignited

The decision, which sees one of the world’s leading tech companies bowing out of a security standoff, has ignited debates over digital privacy, national security, and the future of encryption standards in the UK and beyond.

What is the Advanced Data Protection Tool?

Advanced Data Protection is Apple’s most robust encryption feature, providing end-to-end encryption for users’ iCloud data, including photos, notes, and backups. With ADP enabled, only the account holder can access this information, not even Apple itself can decrypt the data. The feature, introduced globally in late 2022, was designed to offer users greater control and protection against data breaches and cyber-attacks.

However, unlike standard encryption, which allows Apple to access certain user data when presented with a valid legal request, ADP closes off even this possibility. This heightened level of security made it particularly attractive to privacy-conscious users, but it has now become the focal point of a growing dispute between Apple and the UK government.

The UK’s Demand for Access (A ‘Back Door’)

Apple’s decision follows a demand from the UK government, issued under the Investigatory Powers Act 2016 (IPA), which compels companies to provide data access to law enforcement agencies when legally requested. While Apple has long opposed creating “backdoors” into its systems, arguing that any intentional vulnerability could be exploited by cybercriminals, the UK’s insistence on access led to an impasse.

The UK government has not officially confirmed issuing a formal notice under the IPA, maintaining its policy of not commenting on operational matters. However, some media commentators have suggested that UK government pressure has been escalating behind the scenes, and may now have prompted Apple to withdraw ADP for UK customers entirely.

Apple’s Disappointment

In a strongly worded statement, Apple has expressed deep disappointment at having to disable ADP for UK users, and has said: “As we have said many times before, we have never built a backdoor or master key to any of our products, and we never will.”

The company has also highlighted the broader implications of weakening encryption, arguing that such actions would endanger all users by creating vulnerabilities exploitable by malicious actors or cybercriminals. Apple’s stance reflects a broader concern shared by many cybersecurity experts and privacy advocates who fear that undermining encryption in one country could set a dangerous global precedent.

What This Means for UK Apple Users

Apple’s decision essentially means that any Apple user in the UK now attempting to enable ADP will simply receive an error message. Existing users who had previously activated the feature will also see it disabled in the coming weeks.

It seems that while some forms of encryption remain intact (i.e. iMessages, FaceTime communications, and sensitive health data stored on iCloud) and will continue to be protected by end-to-end encryption, while other data types (such as full device backups and photos stored in iCloud) will no longer enjoy the same level of security in the UK. Under standard encryption, Apple retains the ability to access these files and could be compelled to share them with law enforcement upon receipt of a valid warrant.

Security vs. Privacy

The UK government’s push to weaken end-to-end encryption has sparked fierce opposition from privacy campaigners and cybersecurity experts. For example, Professor Alan Woodward, a cybersecurity specialist at the University of Surrey, has been quoted as describing the move as “an act of self-harm” by the government, adding: “All the UK government has achieved is to weaken online security and privacy for UK-based users.”

However, the UK government claims its perspective has been driven by concerns around national security and child protection. This view is supported by some relevant organisations. For example, Rani Govender, policy manager for child safety online at the NSPCC, has been quoted as arguing that encryption could allow offenders to operate undetected, saying: “End-to-end encryption allows offenders to groom and manipulate children and build communities where they can share vile child sexual abuse material without detection.”

It seems, therefore, that the tension between privacy and protection is a delicate balance for tech firms operating under diverse international legal frameworks.

International Backlash and Global Ramifications

Apple’s withdrawal of ADP in the UK has drawn sharp criticism from global privacy advocates and even US lawmakers. For example, Democrat Senator Ron Wyden (from Oregon) has been quoted as calling the move a “dangerous precedent” that authoritarian governments could exploit to justify similar demands in their own jurisdictions.

The broader concern appears to be that once a tech company concedes to one government’s demands for weakened encryption, it becomes increasingly difficult to resist similar pressures from other nations, including those with less regard for human rights and privacy.

Competitors and Market Impact

Apple’s decision could also have repercussions across the wider technology sector. Competitors like Google, Meta (formerly Facebook), and WhatsApp (which also rely on end-to-end encryption) may now face mounting pressure from governments to implement similar data access measures. WhatsApp head Will Cathcart has warned that any weakening of encryption standards would compromise user security worldwide, saying: “If the UK forces a global backdoor into Apple’s security, it will make everyone in every country less safe.”

Also, the decision could erode consumer trust among UK users who are particularly conscious of (and value) their data privacy. Tech-savvy consumers may seek alternatives that continue to offer uncompromised encryption features, potentially benefiting companies headquartered in jurisdictions with stronger privacy protections.

The Future of Encryption in the UK

For now, it seems that, despite its current disappointment, Apple remains hopeful that it will be able to reinstate ADP in the UK in the future. In its official statement, the company highlighted its commitment to user privacy, saying: “Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before.”

However, the ongoing dispute highlights the growing tension between governments seeking broader surveillance powers and technology firms defending user privacy. As the legal and ethical debate continues, UK consumers are left grappling with the uncomfortable reality of diminished digital protections in an increasingly interconnected world.

What Does This Mean for Your Business?

Apple’s removal of Advanced Data Protection (ADP) in the UK is a significant moment in the ongoing global debate over privacy, security, and governmental oversight. While the decision may seem like a straightforward technical adjustment, its broader implications touch upon issues of individual privacy rights, corporate responsibility, and the balance of power between governments and multinational technology firms.

At its core, this move by Apple highlights the increasing pressure technology companies face when navigating conflicting legal frameworks across different jurisdictions. Apple’s steadfast refusal to implement backdoors, despite mounting governmental pressure, aligns with its long-standing commitment to user privacy. However, by disabling ADP for UK users, Apple has effectively signalled that even the most privacy-focused companies must sometimes yield to local laws and regulatory demands, no matter how much they contradict the company’s own policies.

For UK businesses and organisations, this development raises immediate and pressing concerns. Companies that handle sensitive data (such as those in finance, healthcare, or legal sectors) may now find themselves at greater risk of data breaches or unauthorised access. With the most robust form of encryption disabled, organisations may need to reconsider their data protection strategies. This could mean investing in alternative security measures or exploring third-party services that still offer uncompromised encryption. Also, businesses that work internationally may find the regulatory discrepancy between the UK and other regions increasingly difficult to navigate, potentially leading to compliance headaches and increased operational costs.

On the international stage, the ripple effects of Apple’s decision may be far-reaching. Other governments, especially those with poor human rights records, could view this development as an opportunity to justify their own demands for weakened encryption. In this light, the UK’s stance may inadvertently contribute to a global erosion of digital privacy standards, emboldening authoritarian regimes to push for similar concessions from tech companies.

For consumers, the removal of ADP is a reminder of the fragile nature of digital privacy in an age of heightened governmental surveillance. Those in the UK who value strong encryption protections may begin to seek alternatives, potentially favouring services or platforms based in countries with stricter privacy laws. This shift could have longer-term consequences for Apple’s market share in the UK and could drive innovation among competitors aiming to fill the void left by ADP’s removal.

Featured Article : UK Government Demands Apple Reveal Your Data

The UK government has reportedly ordered Apple to grant it access to encrypted data stored in iCloud by users worldwide, a move that has sparked fierce debate over privacy, security, and government surveillance.

IPA

The demand, issued under the Investigatory Powers Act 2016 (IPA), represents one of the most significant clashes between a government and a major technology company over encryption and data protection.

What Has the UK Government Demanded?

According to recent reports (first published by The Washington Post and later confirmed by other media sources), the UK Home Office has served tech giant Apple with a “technical capability notice” under the IPA. This notice legally compels companies to provide law enforcement agencies with access to data, even if it is encrypted.

The government’s demand specifically targets Apple’s Advanced Data Protection (ADP) feature, which offers end-to-end encryption for iCloud storage. This means that only the user has the decryption keys and even Apple itself cannot access the data. By enforcing this demand, the UK government appears to be seeking the ability to bypass or weaken this encryption, potentially gaining access to vast amounts of personal data stored by Apple users worldwide.

It’s been reported that when asked about the order, a Home Office spokesperson declined to confirm or deny its existence, stating, “We do not comment on operational matters, including, for example, confirming or denying the existence of any such notices.”

Why Is the UK Government Doing This?

The UK government argues that encryption enables criminals, including terrorists and child abusers, to evade law enforcement. The National Society for the Prevention of Cruelty to Children (NSPCC) has previously criticised Apple’s encryption policies, arguing that they hinder efforts to track down online child abuse networks.

The UK’s intelligence agencies have long pushed for greater access to encrypted communications, claiming that end-to-end encryption makes it harder to investigate serious crimes. Officials insist that their goal is not mass surveillance but rather targeted access to individuals who pose security threats.

The Global Ramifications of Apple’s Response

The UK’s demand for access to encrypted iCloud data has raised global concerns over privacy and security. Security experts warn that creating a backdoor, even for government use, could expose vulnerabilities that may be exploited by cybercriminals or authoritarian regimes.

Apple now faces a difficult decision. Reports suggest that instead of complying with the UK order, Apple may remove the Advanced Data Protection feature for UK users altogether. While this would protect encryption standards globally, it would leave UK users more vulnerable to potential government access.

Privacy advocates, including Big Brother Watch, have condemned the UK’s move, calling it a “draconian overreach” that could set a precedent for other governments to demand similar access. The U.S.-based Electronic Frontier Foundation described the order as a global security emergency, warning that if Apple concedes, it could open the floodgates for further government-mandated backdoors worldwide.

Also, the timing of the order raises concerns. Recent revelations of large-scale cyber espionage campaigns, including Chinese state-sponsored hacks on telecoms firms, highlight the importance of strong encryption. Critics argue that weakening encryption in the name of security could paradoxically increase risks, exposing sensitive data to foreign adversaries and malicious actors.

The outcome of Apple’s decision will be closely watched by governments, privacy groups, and other tech giants, as it could define the future of encryption policies worldwide.

Privacy and Security Experts React

Privacy campaigners and cybersecurity experts have strongly condemned the UK government’s move.

For example, Rebecca Vincent, interim director of civil liberties group Big Brother Watch, described the demand as “an unprecedented attack on privacy rights that has no place in any democracy” and added that “we all want the government to be able to effectively tackle crime and terrorism, but breaking encryption will not make us safer. Instead, it will erode the fundamental rights and civil liberties of the entire population, and it will not stop with Apple.”

Professor Alan Woodward, a cybersecurity expert from the University of Surrey, has been quoted as saying he was “stunned” by the news, warning that creating a backdoor into encrypted systems poses a significant risk. “Once such an entry point is in place, it is only a matter of time before bad actors also discover it,” he cautioned.

Dangerous Precedent

On his X feed, Professor Woodward also said: “I fear the UK govt is being badly advised in picking this fight. For one thing, President Trump doesn’t welcome foreign regulation of US tech companies.”

Other major tech firms will be closely watching Apple’s response. If the UK government succeeds in forcing Apple to break its encryption, it could set a dangerous precedent, leading to similar demands for data access from other governments worldwide.

Can Apple Stop It?

Apple does have legal avenues to challenge the order. Under the IPA, companies can appeal. However, the law also states that compliance must continue during the appeals process, meaning Apple would have to implement the changes even as it fights the ruling in court.

If Apple refuses to comply outright, the UK government could impose financial penalties or take further legal action against the company. Given Apple’s previous stances on encryption, a legal battle between the tech giant and the UK government seems highly likely.

What Can Apple Users Do to Protect Their Data?

For concerned Apple users, there are a few steps to enhance personal data security:

– Turn off iCloud backups. Without iCloud backups, there would be no cloud-stored data for the government to access. However, this also means losing the ability to recover data if a device is lost or damaged.

– Use local device encryption. Data stored directly on Apple devices remains encrypted with hardware security features, making it more difficult for third parties to access.

– Enable two-factor authentication. This adds an extra layer of security to Apple accounts.

– Stay informed. Users should keep up to date with Apple’s response to this demand and any changes in privacy policies.

What Happens Next?

If the UK government successfully enforces this demand, it could mark the beginning of widespread government intervention in encrypted services. Other Western governments, including the United States, have previously attempted to pressure Apple into providing encryption backdoors, but so far, the company has resisted.

This case could be regarded, therefore, as being a crucial test of how far governments can push back against end-to-end encryption. If Apple bows to UK demands, it could embolden other governments to seek similar access. On the other hand, if Apple stands firm, it could set a precedent for other tech firms to resist government pressure on encryption.

Also, this may not stop with Apple. The UK government has previously targeted encrypted messaging services, such as Meta’s WhatsApp. In 2023, the UK government threatened to ban WhatsApp unless it provided a mechanism to scan encrypted messages for harmful content, a move that was widely criticised by privacy advocates. Other end-to-end encrypted services, including Signal and Telegram, could also face similar demands in the near future.

For now, the battle between Apple and the UK government is far from over. Whether the UK government backs down, Apple fights and wins, or encryption is permanently weakened, the outcome will have lasting implications for digital privacy and security worldwide.

What Does This Mean for Your Business?

The UK government’s demand for access to Apple users’ encrypted data has raised some fundamental questions about the balance between security, privacy, and government oversight in the digital age. While law enforcement agencies argue that such measures are necessary to combat serious crimes, critics warn that undermining encryption sets a dangerous precedent that could weaken security for all users.

At the heart of this debate is the issue of trust i.e., trust in governments to act proportionately and trust in technology companies to uphold user privacy. If Apple concedes to the UK’s demand, it could signal the beginning of wider state intervention in encrypted services, potentially opening the door for similar requests from other nations. However, if Apple refuses, it risks legal repercussions, financial penalties, or even restrictions on its UK operations. This standoff will be watched closely not only by tech firms and governments but also by privacy advocates and cybersecurity experts worldwide.

The case highlights the ever-growing tension between technological advancements and regulatory controls. Encryption is not just a tool for privacy but is also a safeguard against cyber threats, corporate espionage, and authoritarian overreach. Weakening it in the name of security may, paradoxically, create more vulnerabilities rather than resolve them.

Whatever the outcome, this confrontation is unlikely to be the last of its kind. As digital privacy becomes an increasingly contested space, both governments and tech companies will continue to grapple with the difficult task of balancing individual rights with national security. Whether Apple’s response sets a new global standard or merely delays the inevitable, the impact of this battle will be felt far beyond the UK’s borders.

For UK businesses that rely on Apple’s encrypted services, the implications could be significant. Many companies depend on end-to-end encryption to protect sensitive corporate data, financial transactions, and confidential communications. Also, compliance with UK government demands could create conflicts with data protection regulations, such as GDPR, raising legal uncertainties for organisations handling customer and client information. If Apple withdraws certain encryption services from the UK market, businesses may be left searching for alternative, potentially less secure, solutions. In a global economy where data security is paramount, UK firms could find themselves at a competitive disadvantage compared to counterparts operating in jurisdictions with stronger privacy protections.