A government should have to defend a policy that could weaken the security of millions of people. That defense should involve evidence, independent scrutiny, and an honest accounting of the risks.
It should not depend on keeping the people affected—and their elected representatives—from understanding what is being demanded.
On September 11, 2026, Senator Ron Wyden and Representative Warren Davidson asked Britain’s Investigatory Powers Tribunal to loosen secrecy surrounding a reported government demand involving Apple’s encryption. According to their announcement, Apple told congressional staff it had permission to brief certain senior U.S. administration officials but was prevented from discussing the issue in detail with Congress. The lawmakers said the full scope of the current demand remained unknown. Source: bipartisan congressional announcement.
On September 17, Reuters reported a further challenge to the British government’s refusal to confirm or deny the notice’s existence. The government argued that disclosure could harm national security; challengers argued that the secrecy undermined open justice. Source: Reuters.
The underlying dispute remains contested. These developments do not establish that Apple has built a backdoor, or that American users’ encryption has been compromised.
They do establish why secrecy deserves scrutiny.
The difference between a promise and a technical limit
Apple’s own documentation explains the relevant distinction. Under standard iCloud protection, Apple holds keys for certain categories of stored information. With Advanced Data Protection enabled, additional categories—including backups, photos, and notes—use end-to-end encryption, with keys available only through the user’s trusted devices. Source: Apple’s security overview.
That difference changes who must be trusted. A service that cannot decrypt protected content places a technical limit on access. A service that can decrypt it must instead control that capability through policies, procedures, and the security of its own systems.
Neither arrangement eliminates every risk. But they are not interchangeable.
Apple’s published UK notice says new users there cannot enable Advanced Data Protection. It also makes an important qualification: protections such as end-to-end encryption for iMessage and FaceTime remain in place. It would be inaccurate to describe the situation as the removal of all encryption from Apple products. Source: Apple’s UK notice.
The real issue is narrower and serious enough: people have lost access to a stronger protection for particular cloud data while the surrounding government demands remain difficult to examine.
Secrecy changes who holds power
Some investigative secrecy is legitimate. Revealing an operation can endanger people, expose methods, or alert a suspect. Public accountability does not require publishing every operational detail.
But protecting an investigation and concealing a policy that changes widely used security systems are different things.
Our position is that the broader the consequences of a demand, the stronger the obligation to explain its legal basis, intended scope, and safeguards. Officials should not be able to turn a debate about public security into a confidential negotiation whose outcome users discover only when a feature disappears.
Companies should face scrutiny, too. Apple is an interested party, not an independent referee. Its claims deserve examination. Meaningful oversight requires enough information to challenge both the government’s justification and the company’s account.
Why Americans should care
This dispute concerns British powers, but the accountability question crosses borders. American lawmakers are asking whether a foreign secrecy requirement is preventing them from evaluating risks involving an American technology company.
The immediate uncertainty matters. We should not pretend to know the contents of a secret demand. We should also reject the idea that uncertainty requires the public to stop asking questions.
A useful test is whether we would accept the same process from a government we distrust. Would assurances from unnamed officials be enough? Would we be comfortable learning that a security feature had changed while the reasons remained inaccessible?
Rights should not depend on confidence in whichever administration currently holds power.
What a better process requires
Governments seeking exceptional access should explain what they want at a level that permits meaningful public debate. Courts should distinguish genuinely sensitive operational details from arguments about legal authority and system design. Independent technical experts should be able to assess proposed changes, and legislators should be able to question companies through appropriate oversight channels.
Those requirements will not resolve every conflict between privacy and investigation. They would make it harder to impose risks without having to defend them.
At Patch the State, we believe strong security is public infrastructure. It protects ordinary people as well as institutions, and changes to it deserve more than private assurances.
If a policy is sound, officials should be prepared to explain its costs.
If they cannot discuss those costs without undermining the policy, the public has another reason to question it.
