The US is about to triple its border surveillance towers to 2,300 — a $1 billion expansion EU operators should watch as a vendor-risk signal.
elcome to issue thirteen. This week the United States announced plans to nearly triple its border surveillance tower network, and the bill is over a billion dollars. Alongside that, a US court handed border agents warrantless phone-search powers, and a new EU Court of Justice ruling on platform liability is drawing warnings about collateral damage to free expression. If you use US-built infrastructure anywhere in your AI stack, this week gives you three fresh reasons to revisit your vendor risk register.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We added a vendor surveillance profile check to the Flux compliance scan this week, so you can flag suppliers whose known product lines include indiscriminate surveillance tools.
- Updated The Flux prohibited-practices reference card has been updated to include aerial and acoustic surveillance examples in light of this week's US drone and tower news.
- ICYMI Last week's issue covered Flock Safety scrapping its audio distress-detection pilot under public pressure — the backstory is worth a read alongside this week's surveillance tower story.
US plans to triple border surveillance towers to 2,300 sites, spending over one billion dollars of public money

Scale that should make any vendor-risk manager uncomfortable. A report from the US Government Accountability Office reveals that the Department of Homeland Security plans to grow its border surveillance tower network from 830 towers today to 2,300 by 2034. These systems are not narrow tools: they are trained indiscriminately on towns, school playgrounds, and backyards. The price tag is more than one billion dollars in taxpayer funds.
Why EU operators should care about an American infrastructure project. Many of the sensor, analytics, and AI inference layers powering these towers come from vendors who also sell into European public-sector and enterprise markets. When a supplier's core product is a mass-indiscriminate surveillance network that would be flatly prohibited under the EU AI Act's banned-practices provisions, that tells you something important about their default design philosophy before you sign any procurement contract.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓Court of Justice ruling on platform liability raises fresh concerns about collateral damage to freedom of expression under the Digital Services Act framework.
- ✓AlgorithmWatch publishes analysis on generative AI being used as a tool of sexualised violence, increasing pressure on EU regulators to treat GPAI misuse as a priority enforcement area.
- ✓EU AI Act prohibited-practices provisions remain the clearest global benchmark against indiscriminate biometric surveillance, contrasting sharply with US deployment trends this week.
- ~US DHS plans to nearly triple border surveillance towers from 830 to 2,300 sites by 2034, at a cost exceeding one billion dollars.


- 1EU AI Act Prohibited Practices Guide (European Commission)official
The official Commission summary of the eight categories of AI practices banned outright under Article 5 of the AI Act.
Why we like it. Before signing any vendor contract, cross-referencing the supplier's full product portfolio against this list takes under 30 minutes and can save months of remediation.
- 2AlgorithmWatch AI Observatoryresearch
A running database of algorithmic systems in use across Europe, with harm assessments and civil society commentary.
Why we like it. Useful for checking whether a tool you are evaluating has already been flagged for rights-relevant issues before you deploy it.
- 3EFF Surveillance Self-Defence

A billion dollars is not a signal you can ignore
By John Ferguson
I keep coming back to one sentence in this week's GAO report: towers trained indiscriminately on towns, school playgrounds, and backyards. That is not a bug in the procurement spec. That is the feature.
Here is the thing about building a compliance product for EU operators: I spend a lot of time explaining that the AI Act is not bureaucratic overreach. It is a response to exactly this kind of design philosophy, where mass coverage is the goal and proportionality is an afterthought.
The vendor risk angle is the one I think gets underplayed. Nobody thinks they are buying into surveillance infrastructure. They are buying a tidy analytics dashboard from a US SaaS company. But that company may be two acquisitions away from the entity building these towers, and their engineers share assumptions about what normal data collection looks like.
489 days until high-risk AI rules apply. That sounds like a long time. It is not. If your vendor due diligence process does not yet include a question about what else your supplier builds, this week is a good week to add one.
John Ferguson · Founder, Agentic Fluxus

Short answer.Not automatically, but it should prompt a harder look. Your compliance exposure depends on what the system does in your warehouse, not what the vendor sells elsewhere. That said, a supplier whose core competency is indiscriminate surveillance may import those design assumptions into all their products. Request a data flow diagram, ask explicitly whether any features phone home to shared infrastructure, and document that you asked.
Does your vendor due-diligence process include checking what other products a supplier sells outside your use case?

The US Government Accountability Office confirmed DHS plans to spend over one billion dollars expanding border surveillance towers to 2,300 sites by 2034. The towers are described as trained indiscriminately on towns, school playgrounds, and backyards — language that would map directly onto prohibited-practice territory under the EU AI Act.
The Fourth Circuit court ruled that US border agents can manually search your phone with no suspicion whatsoever. EFF had filed an amicus brief arguing electronic device searches should require a warrant, and lost.

