The New York bill
Part C of New York State's proposed 2026-2027 budget (bills S.9005 in the Senate, A.10005 in the Assembly) would require every 3D printer and every CNC machine sold or delivered in the state to include what the statute calls "blocking technology." The statute defines the term: firmware or software that scans each incoming print file against a "firearms blueprint detection algorithm" and refuses to execute the print if the algorithm flags it as a firearm or firearm component. The bill additionally requires face-to-face sales for any covered device — no mail-order or online delivery. It makes possession or sharing of a "blocked design file" a felony.
The bill does not specify an algorithm. It specifies a function: scan, compare, refuse. Implementation is delegated to commercial vendors. Four major 3D-printer firmware providers — Prusa, Creality, Bambu Lab, Anycubic — ship firmware on the majority of U.S.-consumer 3D printers. None currently ship a firearm-detection algorithm. Each would have to add one to sell in New York. The signature database — which shapes the algorithm would flag — would be maintained by state-certified providers, in practice two or three commercial vendors whose certification process is not yet defined.
The Electronic Frontier Foundation published two posts in April 2026 opposing Part C: "Stop New York's Attack on 3D Printing" and "Print Blocking Won't Work - Permission to Print Part 2." An open-firmware coalition — maintainers of Marlin, Klipper, and RepRap firmware — ran a pilot test of the class of algorithms the bill would certify, against a corpus of non-weapon prints: replacement door handles, architectural models, figurines, household hardware. The pilot's published finding: 17 percent of non-weapon prints triggered the algorithm.
A 17 percent false-positive rate on a fabrication tool is not an inconvenience. It is a design property. A Rochester hobbyist printing a cabinet latch, a Buffalo maker-space teacher printing 40 classroom parts, a Brooklyn artist producing stylized sculpture — each is statistically guaranteed to encounter refusal. The algorithm does not distinguish intent from pattern. The algorithm refuses shapes.
California has parallel legislation. Five other states have similar bills in circulation. If New York's Part C passes, it will be the first U.S. state to mandate device-level content refusal on a fabrication tool.
The ladder
New York's 3D printer bill is the sharpest single entry in a broader architectural shift. The week's privacy and internet-freedom news, read together, describes a ladder of state-mandated refusal regimes:
Permission to speak. The EU's Chat Control regulation — the Child Sexual Abuse Regulation whose third trilogue collapsed on April 17 — would, depending on May 4 outcome, require messaging platforms to scan every message against a detection signature before sending. Signal's president Meredith Whittaker, Tuta's Matthias Pfau, Proton's Andy Yen, and Threema have each publicly committed to withdrawing from the EU market rather than implement client-side scanning. Google, Meta, Microsoft, and Snap will comply with whatever regime the Council, Parliament, and Commission ultimately agree on. The Commission has moved toward Parliament's position — narrower detection orders paired with mandated age verification — and away from the Council's earlier mandate-scanning stance.
Permission to see. The UK Online Safety Act's children's-access assessment deadline passed on April 16. Ninety-plus services are under formal Ofcom investigation. An estimated six million UK adults completed age-verification flows in the past twelve months at intermediaries — Yoti, Persona, Verify, and smaller vendors — who retain identity documents under 6-to-24-month policies. Australia's Social Media Minimum Age Act took effect December 10, 2025. Facebook, Instagram, Snapchat, TikTok, and YouTube are under eSafety investigation. Seventy-six percent of 14-15-year-olds report circumventing the ban. Discord delayed its global age-verification rollout to the second half of 2026. Google's AI age verification continues to roll out. Reddit requires age verification for sensitive subreddits. Each regime routes verification through an intermediary that aggregates identity documents.
Permission to print. New York's Part C. California's parallel legislation. The 17 percent false-positive rate.
Permission to reach. Iran entered Day 51 of the second-longest nationwide internet blackout ever recorded. International connectivity at approximately one percent of pre-war levels. Possession of a Starlink terminal for personal use: six months to two years in prison. Use "with intent to confront the Islamic Republic" or for espionage: execution. Russia's Digital Development Ministry has twelve days before the May 1 per-gigabyte tariff on international data takes effect — 150 rubles per gigabyte above 15 GB monthly, applied at the carrier gateway, billed through the user's digital wallet. China's Great Firewall, the senior member of the category, continues to operate.
Permission to decrypt. The UK Home Office's Technical Capability Notice against Apple. A seven-day Investigatory Powers Tribunal hearing is scheduled for 2026 on whether the Home Office can compel Apple to maintain technical capability for UK access to iCloud user data globally. Apple withdrew Advanced Data Protection for UK users on February 21, 2025. Sens. Wyden, Warren, and Markey demanded a DNI briefing by March 11, 2026. The CLOUD Act's U.S.-UK bilateral specifically excludes UK demands targeting U.S. persons. Whether the TCN mechanism legally bypasses that exclusion is the hearing's central question.
Five rungs. Each is a specific state-mandated moment at which a device, service, or infrastructure element asks permission before the user acts. The permission question is answered against a signature database, an age attestation, a geolocation, a cryptographic capability specification. If the answer is no, the action does not happen.
From observation to refusal
The older surveillance model, the one that dominated the 2013-2020 debates — PRISM, XKeyscore, Snowden's disclosures — was observation. The NSA collected metadata. Facebook tracked behavior. Google aggregated search. The state or the commercial operator observed what the user did. Sometimes the observation was used in downstream enforcement. Sometimes it sat in a database. The user, in almost all cases, still acted. The action was recorded. The recording was consulted later or not.
The emerging model is refusal. The device, the service, or the infrastructure intervenes at the moment of action. The user's print does not print. The user's message is flagged before sending. The user's account cannot access content without age attestation. The user's phone cannot reach international destinations without a tariff or a blackout-exemption. The user's encryption is structurally subject to compelled decryption.
The shift is structural. Observation can, in principle, be reconciled with user autonomy: the user acts; some record of the action exists; the record is used or not based on downstream considerations. Refusal eliminates the action entirely. The user does not act because an intermediate layer has been authorized to refuse on behalf of a policy the user did not choose.
The shift is also harder for existing frameworks to regulate. Observation produced legal debates about warrants, standing, and aggregation. Refusal produces debates about whose algorithm is certified, what signature database is authoritative, and how false-positive rates will be audited. The questions are different. The mechanisms the legal system has developed for the observation era do not fully apply.
The 2013-2020 privacy debate focused on when the state could watch. The 2026 debate focuses on when devices can refuse to serve the user.
The ordinary defense
Against the ladder of refusal, five architectural responses — each already operating at some scale, each partial, each the subject of its own ongoing development.
Devices that do not ask. Open-firmware 3D printers whose codebases refuse to implement the NY Part C signature scanner. Open-source operating systems whose design does not route permission requests through state-certified intermediaries. Self-hosted productivity software that does not phone home. The open-firmware community has already publicly committed to not shipping the Part C scanner. New York's response, if the legislation passes, will test whether possession of non-complying firmware can itself be criminalized.
Services that cannot be compelled. End-to-end-encrypted messaging whose servers cannot read plaintext. Signal's protocol. Tuta, Proton, Threema. A compelled server cannot reveal what the server mathematically cannot see. The architectural answer to Chat Control is that the regulation applies to operators whose infrastructure permits scanning; operators whose infrastructure does not permit scanning either withdraw or ignore.
Federated platforms. Mastodon, Bluesky's AT Protocol, Matrix, Nostr, Farcaster. No single operator holds the content. A state regulator can reach one operator without reaching the network. A compromise at one operator bounds the blast radius. Platforms that operate federated content-moderation can refuse individual regulatory demands without breaking the network.
Peer-to-peer transport. WireGuard's cryptokey routing. Tor's onion routing. URnetwork's residential-node transport, where messages travel across peer devices rather than facilities of licensed carriers. The licensed carrier is the chokepoint that Russia's tariff, Iran's blackout, and China's Great Firewall operate on. Peer-to-peer transport does not transit the chokepoint — or, more accurately, presents a different, harder-to-classify signature at the chokepoint.
User-held identity. Zero-knowledge proofs of age satisfied from a wallet on the user's device. The EU Digital Identity Wallet under eIDAS 2.0 is the leading regulatory path; production deployment is 2027. The architectural claim is that the user's verifiable credential, held in a user-controlled wallet, asserts required attributes without requiring an intermediary to retain the underlying document. The Online Safety Act's six million UK verifications this past year did not use this architecture; the architecture exists and is slowly deploying.
Each response is partial. Each faces regulatory pressure. None is the architectural answer to every refusal regime. Together, they sketch the architectural posture available to a user who, choosing individually, does not accept the default.
The Sunday-morning read
A user in the United States on Sunday, April 19, 2026, is most likely not aware of Part C's specific provisions. They are probably not aware that Chat Control's third trilogue collapsed Friday, or that Russia's tariff takes effect on May 1, or that Apple's UK Technical Capability Notice is moving toward a tribunal hearing this year. They may have a vague sense that their data is "probably out there somewhere" following the week's breach notifications — McGraw Hill's 13.5 million, Rockstar Games' 78.6 million, Booking.com's unspecified millions, ChipSoft's Dutch patients, Basic-Fit's European gym members.
The user has no single action to take that resolves the ladder. The week's news is not a prompt for a purchase or a settings change. It is a description of the operational environment in which the user's device, services, and infrastructure are increasingly being regulated to refuse. The user's choice, to the extent they have one, is between accepting the defaults and choosing the architectural alternatives — Signal for messaging, a self-hosted file service, an open-firmware 3D printer imported from out of state, a mesh-enabled device for local coordination, a federated platform for public communication, and a growing set of more specialized tools for more specific concerns.
The mainstream user will continue to accept the defaults. That is the structural truth. The mainstream architecture — centralized platforms, cloud services, licensed carriers, mandated scanners and verifiers — will continue to be the operational environment the ladder of refusal regimes has been designed around. The architectural alternatives continue to be available for users who choose them.
The specific shift worth naming, as the week closes, is that the regulatory ladder is no longer theoretical. New York's Part C is on the legislative calendar. Chat Control's May 4 trilogue will produce a direction. The Apple TCN hearing is scheduled. Russia's tariff takes effect. Iran's Day 52 begins tomorrow. Each rung has a specific date. Each rung has a specific operational mechanism. Each rung has a specific architectural alternative that the user can choose if they want to.
The observation era was about what the state could see. The refusal era is about what the user can do. The shift is underway. The architectural response is the one that has been under construction for a decade — quieter than the regulatory debate, measurable in growth metrics that do not yet approach the mainstream, but available to the user who chooses.
What the week made visible
Part C of New York's budget is the specific Sunday-morning item. The 17 percent false-positive rate is the ergonomic fact. The signature-database concentration is the architectural fact. The felony threat for possessing blocked design files is the civil-liberties fact. The EFF opposition is the advocacy response. The open-firmware community's commitment not to implement is the architectural response.
Chat Control's third trilogue collapse, the UK OSA six million verifications, Iran's Day 51, Russia's May 1 countdown, Apple's UK TCN progression, Discord's delayed global age verification, Google's AI age verification, Australia's eSafety enforcement pending, the McGraw Hill and Rockstar Games and Booking.com and ChipSoft breaches, the Meta Scale AI Outlier revelations, LockBit 5.0's persistence, Grinex's claimed state-attribution hack — each is a specific entry in the week's news. Each maps onto the ladder or into the parallel data-extraction supply chain that runs alongside the refusal supply chain.
The week's news, taken whole, is the operational reality of the refusal era. The user is at the receiving end of the refusals and the extractions. The architectural alternatives are real and available. The choice, where it exists, is the user's. The refusal era continues whether the choice is made or not.
Part C will pass or not. If it passes, New York's 3D-printing community will deal with the 17 percent false-positive rate, the face-to-face sales requirement, the felony threat. If it does not pass, Part C will return in a future budget cycle or a successor bill. California will take its own action. Other states will watch.
The ladder is not going away. The rungs are being populated. The user's device, somewhere in the chain between the action the user intended and the action that actually happens, is asking permission of a policy the user did not choose.
The architectural response is the devices, services, and infrastructure that do not ask. Their deployment is slow. Their availability is real. The week's news has made visible, rung by rung, what they are an alternative to.
References (6 sources)
Sources
- New York State Senate S.9005; Assembly A.10005; Part C, 2026-2027 budget bills.
- EFF, "Stop New York's Attack on 3D Printing," April 2026.
- EFF, "Print Blocking Won't Work - Permission to Print Part 2," April 2026.
- Bruce Schneier, "3D Printer Surveillance," February 2026.
- Techdirt, "New York's New 3D Printing Law, As Written, Is Extremely Harmful And Annoying," February 2026.
- Reclaim the Net, "New York Budget Bill Proposes Mandatory File-Scanning Tech and In-Person Sales for 3D Printers."
- EFF, "The Dangers of California's Legislation to Censor 3D Printing," April 2026.
- Patrick Breyer, "EU 'Chat Control' Twist: Commissioner Sides with Parliament," April 17, 2026.
- State of Surveillance, "Chat Control Is Dead. Long Live Chat Control."
- EFF, "EU Parliament Blocks Mass-Scanning of Our Chats — What's Next?"
- The Record, "Signal calls on Germany to vote against 'Chat Control.'"
- Compliance Hub Wiki, "EU 'Chat Control' NOT Withdrawn – Just Delayed Again."
- Ofcom, UK Online Safety Act Year 3 compliance briefings.
- Australian eSafety Commissioner compliance report, March 20, 2026.
- TechCrunch, "Discord to roll out age verification next month for full access to its platform."
- EFF, "Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data Breach."
- Tom's Hardware, "Iran's forced nationwide internet blackout becomes second-longest on record."
- IranWire, "Iran Prepares Death Penalty Law for Starlink Internet Use."
- Business and Human Rights Centre, "Iran: Free satellite internet access has been activated."
- NetBlocks, Iran connectivity report, April 18-19, 2026.
- Moscow Times, "Russian websites begin blocking VPN users as internet controls tighten," April 15, 2026.
- Zona.media, "Russia's internet censorship in 2026."
- Techdirt, "Whoops: Russia's Attempt To Block VPNs Causes Major Banking Failure," April 13, 2026.
- Privacy International, "PI Apple TCN Challenge."
- Computer Weekly, "Home Office 'back door' seeks world-wide access to Apple iCloud users' data."
- AppleInsider, "U.S. lawmakers request briefing on the UK's iCloud encryption backdoor plans."
- The Daily Caller, "'Unprecedented Mass Surveillance': Bipartisan Senators Warn Of Privacy Threat Tied To FISA Renewal," April 15, 2026.
- Senate floor record, April 17, 2026 Wyden statement on H.R.8322.
- BleepingComputer, "Data breach at edtech giant McGraw Hill affects 13.5 million accounts," April 16, 2026.
- Cybersecurity News, "Rockstar's GTA Game Hacked - 78.6 Million Records Online."
- TechCrunch, "Booking.com confirms hackers accessed customers' data," April 13, 2026.
- NL Times, "Expect more big hacks, Justice Min. says as ChipSoft confirms leak of patient data," April 17, 2026.
- The Guardian, "Porn, dog poo and social media snaps: the 'taskers' scraping the internet for Meta-owned AI firm," April 7, 2026.
- CoinDesk, "Russia-linked Grinex exchange halts operations after $13 million 'state-backed' hack," April 17, 2026.
- Microsoft Security Blog, "Storm-1175 focuses gaze on vulnerable web-facing assets," April 6, 2026.
- Check Point Research, "LockBit 5.0: Ransomware Gang Returns in Force."
- CISA, April 8, 2026 Iran-linked PLC advisory.
- Tor Project, Arti 2.2.0 release notes.
- EU Digital Identity Wallet eIDAS 2.0 documentation.
- URnetwork, Signal, WireGuard, Matrix, Mastodon 2026 architecture documentation.
This is edition 2026-04-19-01 of the URnetwork daily privacy and internet freedom journal. The companion hot-takes document and the associated images, meme comics, and short-form video are published alongside.