California Tightens Tech Rules for Kids, Plus 3 Stories
California signed 13 new laws Thursday aimed at the increasingly messy intersection of children, social media, artificial intelligence and privacy. There are enough pieces in the package that “California regulates kids online” doesn’t really tell you much, so the useful question is: what actually changed?
The most visible rule prohibits social-media platforms from giving users under 16 certain features California considers addictive, including autoplay and algorithmic feeds based on a user’s history and profile. “Adam’s Law,” named for 16-year-old Adam Raine, puts new requirements on companion-chatbot companies: crisis protocols when a child expresses suicidal thoughts, parental controls, notifications when a child disables safety settings, independent child-safety audits and annual risk assessments. Another law covers companion chatbots built into toys. Others expand protections around targeted advertising, K-12 student data and AI-generated or digitally altered child sexual-abuse material.
That is a much broader approach than simply asking a teenager to type a birthday into a box.
It’s also worth separating the law from the sales pitch around the law. Governor Gavin Newsom’s office calls these the strongest child-safety chatbot and social-media laws in the country. That is the state describing its own legislation. Civil-liberties groups including the Electronic Frontier Foundation have argued that some child-safety proposals can become overly restrictive or force intrusive age checks, while technology companies have warned that restrictions can reduce useful personalization. Those questions don’t disappear because the legislation passed with bipartisan support.
What I find more interesting is the direction of travel. Regulators are moving away from treating every bad outcome as a problem for parents to solve one setting at a time and toward asking whether the product itself was designed in a way that creates predictable risks for children. A Texas judge reached a related conclusion this week from a different direction, finding TikTok liable for misleading consumers about what its Restricted Mode actually filtered. The specific laws and lawsuits differ, but the common question is becoming harder for technology companies to dodge: if you advertise a safety feature, does it actually do what a reasonable parent thinks it does?
For families outside California, there isn’t a button to change this morning. The practical takeaway is simpler. Built-in parental controls and “restricted” modes are tools, not guarantees, and the companies making increasingly personal AI products for children are starting to face obligations that look more like safety engineering than a terms-of-service disclaimer.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
WatchGuard’s old Firebox flaw is now tied to ransomware
WatchGuard Firebox administrators have a much less philosophical assignment.
CISA now says CVE-2025-14733, a critical WatchGuard Fireware OS vulnerability first patched in December 2025, has been used in ransomware campaigns. WatchGuard originally disclosed the flaw during an active campaign against edge-networking equipment and told customers to update immediately. If a Firebox is still running an affected version nine months later, “immediately” has acquired some additional emphasis.
The vulnerability is an out-of-bounds write in the Fireware iked process. In plain English, specially crafted network traffic can make the software write data outside the memory area it was supposed to use. On vulnerable IKEv2 VPN configurations, an unauthenticated remote attacker can turn that into arbitrary code execution.
WatchGuard’s fixed branches start at Fireware 2025.1.4, 12.11.6, 12.5.15 and 12.3.1 Update 4 for the affected FIPS branch. The company’s advisory also contains indicators of attack and post-exploitation activity.
That last part matters now. Installing current firmware closes the vulnerability going forward. It does not travel backward in time and evict an attacker who got in before the update. If an appliance was exposed while vulnerable, especially if it remained unpatched after December’s active-exploitation warning, the right question is not only “what version is it running?” but “was it compromised?” Patch it, then investigate it.
This is one of the recurring problems with edge devices. Firewalls and VPN appliances are supposed to protect everything behind them, which also means they’re wonderful targets. They’re internet-facing, highly privileged and sometimes treated like infrastructure that gets installed once and quietly becomes furniture. Furniture usually doesn’t run a VPN service.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Anthropic says Claude is showing up in real malicious workflows
Anthropic’s newest threat-intelligence reporting is a different kind of security story because almost every important claim comes from Anthropic’s own visibility into Claude usage.
The company says it has blocked actors using Claude in cyber operations, surveillance, influence campaigns and weapons-related work. Reuters reports that Anthropic attributed activity to actors linked to Russia, China and Yemen, and says the company identified misuse by the cybercrime group ShinyHunters. The Associated Press reports another case in which a user sought help drafting a grant proposal for gain-of-function work involving chikungunya virus — research intended to change traits such as transmissibility or immune evasion.
Those are serious claims. They are not the same thing as independent investigators proving that Claude built a weapon or caused a biological incident.
That distinction matters because AI-security reporting has acquired a bad habit of compressing “a user asked a model for help with something dangerous,” “the model meaningfully improved the user’s capability,” and “the dangerous thing happened” into one dramatic sentence. Those are three different propositions.
The useful part of Anthropic’s report is that we’re getting more evidence about how general-purpose models fit into real malicious workflows. They can help draft, translate, research, write code, summarize stolen material, automate repetitive steps and lower the amount of specialized labor needed for parts of an operation. Sometimes safeguards stop that. Sometimes attackers try to route around them. And as the models get more capable, the same capabilities that make them useful to defenders become more useful to attackers.
For businesses, that reinforces a point that has come up repeatedly this week: an AI system’s permissions matter at least as much as its personality. If an agent can reach email, repositories, cloud consoles, customer records or payment systems, the important security control is what the environment actually permits it to do — not the sentence in the prompt telling it to behave.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Clearview AI tests a face-search tool that can build a broader profile
Finally, Clearview AI is testing a prototype that shows what happens when facial recognition gets connected to a modern AI research pipeline.
Wired reports that the tool, called InquiryIQ, can take information from a Clearview facial-recognition search and automatically search the web for additional details such as aliases, employers, addresses, social-media accounts and associates. It can also work with demographic fields including age, gender and race. Clearview told Wired that no law-enforcement customer has used InquiryIQ and described it as an internal experimental prototype, with human review still essential.
That limitation needs to stay attached to the story. This is not “police across America now have an AI dossier button.”
Clearview’s existing scale is already worth understanding, though. The company says its platform searches more than 70 billion facial images gathered from public web sources and is available to vetted government and law-enforcement users. Its own materials describe facial recognition as a lead-generation tool whose results should be corroborated with other evidence.
InquiryIQ raises a different question: what happens when AI removes the labor that used to put a practical limit on how much publicly available information an investigator could assemble about one person?
None of the individual pieces of information necessarily has to be secret. A workplace can be public. An old username can be public. A social account can be public. An address may be public. The privacy change comes from making all of those fragments cheap and fast to assemble around a face.
There are legitimate investigative uses for that. There are also obvious risks when a facial match is wrong, an AI-generated association is wrong, or a tool makes expansive profiling so effortless that it becomes routine. “A human reviews it” is an important safeguard. It is not a magic spell that makes automation neutral.
That’s why the prototype matters before it ships. The important policy questions are easier to ask while a capability is still being tested than after it quietly becomes standard procedure.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- California Governor’s Office: child-safety chatbot and social-media legislation
- Associated Press: California’s new child-tech laws
- Reuters: California enacts new curbs on social media for children
- Reuters: Texas TikTok Restricted Mode ruling
- WatchGuard PSIRT: CVE-2025-14733
- BleepingComputer: CISA links WatchGuard flaw to ransomware
- Associated Press: Anthropic’s latest AI misuse report
- Reuters: Anthropic disrupts malicious Claude use
- Wired: Clearview AI’s InquiryIQ prototype
- Clearview AI: platform overview and database scale
