Flock Safety's reforms are cosmetic at best — and the surveillance vendor story is a preview of what EU AI Act audits will expose.
elcome to issue sixteen. This week's headlines are light on Brussels and heavy on the kind of vendor behaviour that keeps procurement leads up at night. Flock Safety, the mass-surveillance company that has been haemorrhaging contracts across the US, rolled out a set of reforms this week that the EFF called 'too little, too late' — and the gap between a vendor's press release and its actual practices is exactly the compliance risk the EU AI Act was designed to address. We also look at what the EFF's own internal AI image policy tells us about the disclosure expectations that are quietly becoming the new baseline for any organisation that touches generative tools.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We added a vendor accountability checklist to the Flux compliance toolkit this week, prompted by the Flock Safety reforms story — use it to stress-test any supplier's announced changes against actual contractual and technical obligations.
- Updated Our GPAI model obligations tracker has been updated to reflect the post-2 August status of the code-of-practice process, so you can see at a glance which providers have and have not declared compliance.
- ICYMI If you missed issue fifteen, the US Senate Commerce Committee advanced four separate AI and platform bills in a single session — the product re-engineering fallout for EU operators is still unfolding and worth a read.
Flock Safety Rolls Out Reforms After Mass Contract Cancellations, But Critics Say the Fixes Are Largely Cosmetic

The backlash finally moved the needle, just not very far. Flock Safety, a vendor of automated licence plate readers used by hundreds of law enforcement agencies, announced a set of reforms this week after towns across the US began cancelling or suspending contracts. The EFF reviewed the package and concluded it is a mix of genuinely overdue changes and cosmetic gestures that leave the fundamental architecture of mass surveillance intact.
For EU operators, this is a live case study in vendor accountability. The EU AI Act places real obligations on operators who deploy or procure high-risk AI systems, including requirements for ongoing human oversight and the ability to audit and correct a system's behaviour. Flock's story illustrates what happens when a vendor's reforms are driven by reputational pressure rather than genuine technical accountability. The gap between the press release and the product is precisely the gap the Act is designed to close.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓No new legislative moves from Brussels this week — the post-summer lull continues.
- ✓The 2 August deadline for GPAI model providers to comply with the Act's code-of-practice obligations remains the most recent hard milestone.
- ✓EU operators are in a holding pattern as supervisory authority structures are still being finalised across member states.
- ~Flock Safety released a reform package for its automated licence plate reader network after widespread US contract cancellations, drawing sharp criticism from the EFF.
- ~EFF published its internal AI image policy, confirming all images are human-made with rare exceptions — a transparency move that sets an informal benchmark for disclosure.


- 1EFF Surveillance Self-Defensedue diligence
A practical guide from the Electronic Frontier Foundation covering how surveillance technologies work and what data they collect.
Why we like it. Understanding the technical realities behind vendor claims is the first step to meaningful procurement due diligence under the AI Act.
- 2EU AI Act Article 9 Checklist (ALTAI)compliance
The European Commission's Assessment List for Trustworthy AI, covering risk management requirements for high-risk systems.
Why we like it. It maps directly to the vendor audit questions you should be asking before any high-risk AI procurement decision.
- 3AlgorithmWatch AI Act Trackermonitoring

The Gap Between the Press Release and the Product Is Where Your Liability Lives
By John Ferguson
This week's Flock Safety story is one I keep coming back to. A vendor faces public backlash, loses contracts, and responds with a reform package. On the surface, that looks like accountability working. Read the EFF's analysis and you realise the reforms are largely cosmetic. The underlying system is unchanged. The press release is not the product.
This matters enormously for EU AI Act compliance. The Act does not care what a vendor announced. It cares what the system actually does, what data it processes, how it makes decisions, and whether a human can genuinely intervene. If you are the operator deploying that system, you are in the frame.
The practical lesson is straightforward but underused: every time a vendor announces a reform, update, or improvement, ask for the technical documentation that backs it up. Ask specifically what changed in the model, the data pipeline, or the human oversight mechanism. If they cannot answer in concrete terms, treat the reform as unverified.
468 days to the December 2027 deadline. That sounds like a long time until you factor in contract renewal cycles, procurement timelines, and the legal review your team has not started yet. The Flock Safety story is a useful alarm clock. Do not wait for your own contract cancellations to start asking harder questions of your vendors.
John Ferguson · Founder, Agentic Fluxus

Short answer.Yes, and do not rely on the press release alone. Ask the vendor for the technical documentation and change log behind the reforms. Check whether your contract includes audit rights. If the system qualifies as high-risk under the Act, you as the operator share responsibility for ensuring it meets the requirements, regardless of what the vendor announced publicly.
When a vendor you use announces a reform or update to their AI system, what is your first move?

Flock Safety announced a reform package to its mass licence plate surveillance network after scores of towns cancelled contracts — but the EFF found the changes were a mix of long-overdue fixes and cosmetic gestures. The fundamental mass-surveillance architecture remained untouched.
The EFF published an explainer confirming that all images on its platforms are made by human beings, with only rare documented exceptions. It is a small transparency note, but it quietly sets a disclosure benchmark that many larger organisations have not matched.

