US military disables ad trackers on troops' devices
A letter shared with Sen. Ron Wyden says the Army, Air Force, Navy, Marines, and SOCOM disabled ad tracking on government iPhones, Androids, and Windows PCs. The Air Force change landed in July. Personal devices and contractors on bases remain a gap.

The US Army, Air Force, Navy, Marine Corps, and Special Operations Command have disabled advertising tracking on government-issued devices, according to a letter shared with Senator Ron Wyden. TechCrunch (Zack Whittaker, 4 September 2026) summarized the letter. Reuters first reported the news and the letters.
This is an operational change disclosed through a letter to the senior Democrat on the Senate Intelligence Committee. It is not a public Department of Defense order text, and it is not a statute. It also does not mean every personal phone on every base has gone dark.
The change covers department iPhones, Android devices, and Windows computers on the federal military enterprise network. The services rolled out the protections earlier this year. The Air Force told Wyden it implemented its changes more recently, in July.
The aim is to stop adversaries from using location data derived from apps to target troops on the battlefield or on bases. Disabling the advertising ID makes a person harder to re-identify, because that location data blends with others who also turned it off.
Wyden raised the issue earlier this year after finding that unnamed foreign adversaries had targeted US troops in the Middle East using commercially obtained location data. He called the military's move commendable. He also warned that personal devices of troops and contractors brought onto bases can still expose service members and facilities.
The US intelligence community and the FBI have confirmed they buy this same commercial location data for surveillance without a warrant. That broker market is a retention problem, the same class of question OpenAI's Private Safety Processing tries to answer for API traffic without keeping raw prompts.
Unmanaged endpoints stay in the model. That is the same lesson as unauthorized agents writing to a German programmer wiki, or a partner platform becoming the weak door in OpenAI's Hugging Face incident report.
Issued-device hardening is the part the services can control. OpenAI's Daybreak pledge to frontline defenders puts money on the defense side. It does not close a personal phone on a US base.
This week, a defense contractor CISO, mobile MDM owner, or privacy counsel should inventory government-managed devices versus BYOD on classified-adjacent sites, kill advertising IDs and location-broker SDKs on issued fleets, and treat personal phones on base as still in the threat model.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free