t’s 1945, and a group of innocent Soviet schoolboys presented a beautiful hand-carved replica of the Great Seal of the United States as a gift to the US ambassador in Moscow. The ambassador was delighted and hung it in his office. It hung there for seven years, a symbol of goodwill between the two nations, often pointed out by the Ambassador to visitors with pride. Obviously, to us but sadly not to the Ambassador, hidden inside it was a passive listening device with no detectable power source of its own, and was activated only when the Soviets bathed the entire embassy in a specific radio frequency. It was an elegant and undetectable violation of the embassy’s security.
It’s interesting that we’re now fully in a world where we’re seemingly comfortable with so many devices listening to us.
Apple’s new watch feature listens to your conversations, you know the ones you have in real life, not ones in a Zoom meeting that has at least the element of consent. Then later it recaps the conversations for you. The “Soviet Schoolboys” in Cupertino are slapping the modern version of that bug onto your wrist, minus (hopefully) massive radio frequency bombardment.
This is not just a convenient new feature, it’s a wiretapping service delivered to its users wrist, and it represents a catastrophic expansion of privacy liability. For any company that has employees using apple watches and devices tied to them for work, it creates an unaudited, unmanaged compliance risk that makes the current wave of lawsuits look relatively quaint.
To be clear about how this works… The watch listens to you, processes your conversation, and then creates a summary of each of your conversations, then sends those back to you. In U.S. state with two-party consent laws, recording a conversation without every party’s consent is illegal. Given this records your conversations, and I assume you’re not getting even the verbal consent of every person you talk to, the watch likely assists you in breaking the law every time you use it, without asking for consent, and recording that consent.
The parallels to the session-replay lawsuits that have buried companies in CIPA filings are impossible to ignore. In those filings, a script records a user’s interactions with a website, usually without their full understanding or explicit consent, and then that act of recording them is a violation. The watch essentially is doing the same thing, but for spoken conversations in the analog world.
Apple’s privacy-forward branding seems more and more like a version of a consent banner on the website that promises privacy and compliance, but that doesn’t always honor it. It’s a promise, but it’s potentially an empty promise. The immediate defensive counterargument is that Apple is good at privacy, and generally speaking, they are. They’re better at it than most. I’d even say that their intentions are probably good.
Apple’s documentation promises that there would be no audio storage, and that raw audio recordings will never be stored on the device, or exposed to any third party apps or cloud servers. Just their own. Processing relies on the Apple S11 chip, which has an isolated memory buffer called “Secure Exclave” where the audio is temporarily processed on the device before it’s purged. The summaries sent to Siri are the protected with end-to-end encryption. Also in order to prevent a secret recording, an audible chime can be heard even if the watch is muted, and there is a visual screen indicator to alert other people nearby that a recording is happening.
The problem is that most of that, as well as the general intent is largely legally irrelevant. Even if it’s not a malicious act by Apple (or the KGB), if it isn’t integrated into your company’s specific consent framework, or the complex matrix of state laws, you could still be in trouble.
The technical (and social) complexity of ensuring this feature never records a conversation that requires two-party consent, or that it never captures sensitive data during a business meeting is massive. Good intentions don’t stop lawsuits when the implementation fails.
Expanding out to the bigger picture, we’re looking at a privacy attack surface that’s rapidly expanding beyond just your website and digital elements. It’s in our wearables, our cars, our Google Homes and Alexas and Siris, our smart speakers and smart televisions, it’s in Flock cameras watching and recording potentially what we’re reading, with enough resolution to read it themselves. The fundamental question for any privacy and compliance leader is no longer just “Do we have a consent banner working on our website?” but “What are my employees’ devices doing?” and even “Where are they having in-person conversations, that potentially have listening devices?” (hint it’s almost everywhere these days)
For seven years that ambassador admired the hand-carved seal on his wall, even though it was listening to every important conversation he had. You might believe the watch on your wrist is a convenience, and even recording and summarizing your conversations is valuable (and it can be especially so in certain accessibility circumstances certainly). However, unless you can independently verify what it’s recording, where that data is going, and you’re just taking a vendor’s word for what’s happening with that data, you’re making a series of dangerous assumptions.