Back to School Sale: save 78% Claim offer
Twenty Five Years After September 11: The Emergency Powers That Never Went Home

Twenty Five Years After September 11: The Emergency Powers That Never Went Home

11 Sep, 2026 · Alan Summers

Twenty five years ago today, governments began building the surveillance systems we now live inside, and nearly every one of them was announced as temporary. Some carried expiry dates in the text. France wrote one into the statute: December 31, 2003. Congress attached sunset clauses to the most contested sections of the PATRIOT Act. The argument in the autumn of 2001, in Washington, in Paris and in London, was that an extraordinary moment required extraordinary powers, and that the moment would pass.

It did not pass. The clearest way to see what September 11 did to digital privacy is not to reread the speeches from 2001. It is to read the numbers these same governments published this year.

Illustration of a spy peering through a magnifying glass from inside a computer monitor at a person working at a desk

What Actually Changed in the Weeks After September 11, 2001?

Three things happened almost simultaneously, and only one of them was public at the time.

On October 4, 2001, President Bush signed a memorandum titled “Authorization for Specified Electronic Surveillance Activities During a Limited Period to Detect and Prevent Acts of Terrorism Within the United States.” That programme, later known by the codename Stellar Wind, authorised collection inside the United States without the warrants the Foreign Intelligence Surveillance Act required. It was reauthorised repeatedly, roughly every 30 to 45 days, and it was not disclosed to the public for more than four years. Note the phrase “During a Limited Period” in the title of the document itself.

On October 26, 2001, the USA PATRIOT Act was signed in the Rose Garden. The House passed it 357 to 66 and the Senate 98 to 1, with Senator Russ Feingold the sole vote against. Section 215 let the FBI compel production of “any tangible thing” relevant to a terrorism investigation. Section 505 expanded national security letters, administrative demands that require no judge and that came with a gag order forbidding the recipient from saying they had received one.

And in early 2002 the Pentagon stood up the Information Awareness Office under John Poindexter, whose Total Information Awareness programme proposed to pull financial, travel, medical and communications records into a single searchable system. That one went too far too publicly. A House-Senate appropriations conference voted on September 24, 2003 to defund it. Several of its component research projects were transferred elsewhere in the intelligence community and continued under different names, which is the pattern worth remembering: the programme with the bad name died, the capability did not.

Europe moved on the same clock. France’s loi relative à la sécurité quotidienne, published in the Journal Officiel on November 16, 2001, required telecom operators to retain traffic data for up to a year for the investigation and prosecution of criminal offences. Its Chapter V, containing that provision, was adopted “pour une durée allant jusqu’au 31 décembre 2003”. The United Kingdom’s Anti-terrorism, Crime and Security Act received royal assent on December 14, 2001, with a Part 11 creating a communications data retention scheme, voluntary at first, with a reserve power to make it mandatory.

Why Do These "Temporary" Powers Still Exist in 2026?

Because a temporary power builds an institution around itself, and the institution outlives the deadline.

France shows this most clearly, because the expiry date was written into the law and we can follow exactly what became of it. The 2003 deadline did not get repealed in a single stroke. It was extended to the end of 2005, then carried forward again by the counter-terrorism law of 2006, then extended once more in 2008 to run to 2012, by which point nobody was pretending the arrangement was provisional. Three serial prorogations, each one routine, and the one-year retention obligation settled into French law as a permanent fixture. When the Court of Justice of the European Union made clear that general and indiscriminate retention was incompatible with EU law, the Conseil d’État ruled on April 21, 2021 that “la conservation généralisée aujourd’hui imposée aux opérateurs par le droit français est bien justifiée par une menace pour la sécurité nationale”. The reasoning is worth stating plainly: generalised retention is lawful because there is a national security threat, and the government must periodically re-examine whether the threat still exists. A permanent emergency, subject to review.

The EU-level story runs the same way with more courtroom drama. The Data Retention Directive was adopted on March 15, 2006, in the aftermath of the Madrid and London bombings, obliging member states to require retention of communications metadata. The Court of Justice annulled it on April 8, 2014 in Digital Rights Ireland, holding that it entailed a wide-ranging and particularly serious interference with fundamental rights, not limited to what was strictly necessary. Twelve years later the Commission is drafting a new one. Its ProtectEU strategy of April 2025 launched an impact assessment on retention of data by service providers for criminal proceedings, with a legislative proposal expected during 2026, covering metadata such as IP addresses and subscriber records across a wider range of providers than the directive the Court struck down.

The American version of permanence is stranger still, and it happened three months ago.

Section 702 Expired in June 2026. Why Is It Still Running?

Section 702 of FISA is the authority that matters most to anyone who uses an American internet service. It permits warrantless collection targeting non-US persons reasonably believed to be outside the United States, from providers inside the United States. Communications with those targets get collected too. That is how the accounts of people who were never targets end up in a database that can later be searched.

Congress could not agree on whether the FBI should need a warrant before searching that database for an American’s communications. The deadline arrived and nothing passed. Section 702 expired at midnight on Friday, June 12, 2026, after a series of short extensions including a ten-day stopgap in April.

Collection did not stop. Under the FISA Amendments Act’s transition provisions, acquisitions authorised by certifications and directives already in effect continue until those certifications expire. The FISA Court approved the current certifications in March 2026. The practical effect is that a statute which expired in June 2026 authorises surveillance into March 2027, and the operative deadline for Congress is now set by a court’s certification calendar rather than by the sunset date it wrote for itself.

Of everything in twenty five years of surveillance law, this is the fact I would put in front of anyone who still believes the 2001 bargain had a built-in exit. The sunset clause was the safeguard. It was the promise that emergency powers would be reviewed and could genuinely end. In June 2026 that mechanism was tested for real. It lapsed, and the surveillance carried on.

Is Surveillance Actually Bigger Now Than It Was in 2001?

Yes, and the source for that is the intelligence community’s own annual accounting. ODNI published its thirteenth Annual Statistical Transparency Report in April 2026, covering calendar year 2025.

MeasureCY2022CY2023CY2024CY2025
Estimated Section 702 targets246,073268,590291,824349,823
FBI US person query terms119,38357,0945,5187,413
National security letters issuedn/a11,15810,8548,865
Requests for information within those lettersn/a32,94637,26729,203

FBI query figures are reported over December to November periods, not calendar years.

The target count is the headline. It has risen every year reported here, and the 2025 figure of 349,823 is the largest ever published, a rise of about 20% in a single year. ODNI attributes year to year movement to collection priorities, world events, technical capabilities and target behaviour, among other factors.

The FBI query numbers tell a more interesting story than the raw drop suggests. The collapse from 119,383 to 5,518 followed the 2024 reforms in the Reforming Intelligence and Securing America Act, and ODNI credits technical controls and individual caution. But the 2025 figure ticked back up to 7,413. More pointedly, the Justice Department’s National Security Division found in August 2024 that the FBI was using an advanced filter function to search US persons’ communications that it did not treat as a query, and therefore did not count. The Department’s Inspector General documented the episode in 2025, and the function was not switched off until early that year. A statistic that depends on an agency’s definition of the word “query” is a weaker number than it looks.

National security letters are the quiet giant. In 2025 the FBI issued 8,865 of them, containing 29,203 separate requests for information. These are not court orders. No judge reviews them before they are issued.

What About the Surveillance That Nobody Legislated?

The most significant change since 2001 is not any single statute. It is that the volume of data about ordinary life grew faster than any law governing access to it.

In 2001, following a person’s movements required following the person. Today the location history exists by default, generated by a phone, retained by a company. In June 2023, in response to a Freedom of Information request, ODNI declassified a January 2022 report on commercially available information, which acknowledged that the intelligence community purchases data on Americans from commercial brokers and warned such information “could facilitate blackmail, stalking, harassment, and public shaming”. No warrant is involved. The data is bought.

The border is the other place where the legal architecture of 2001 met the smartphone of 2026. US Customs and Border Protection reports 55,318 searches of electronic devices in fiscal year 2025, up 17.6% from 47,047 the year before. 50,922 were basic searches, which require no suspicion at all. 13,590 involved US citizens. The border search exception long predates 2001, but it was written for suitcases, and a phone is not a suitcase.

Airports show how thoroughly the 2001 posture became the default. TSA’s facial comparison technology now operates at approximately 350 airports nationwide, and the agency states that travellers “may decline the optional photo, without recourse”. Most people do not know that, because a system presented as routine is rarely questioned.

Did Any of This Change How People Behave?

This is the part that is usually asserted and rarely measured. In 2016, Jonathon Penney published a study in the Berkeley Technology Law Journal examining Wikipedia traffic before and after the June 2013 revelations about NSA surveillance programmes. He found that average monthly views of the forty-eight terrorism-related articles he tracked fell about 19.5% after June 2013, and a regression model put the immediate drop-off at over 30% of total views.

Nobody was arrested for reading a Wikipedia article. That is exactly the point. A surveillance system does not have to be used against you to change what you are willing to look up. Knowing it exists is enough, and the cost falls on people who have done nothing wrong.

It also explains why this bargain is so hard to argue about honestly. The benefits of surveillance are specific and easy to announce. The costs are spread thin across millions of people who will never know which search they decided not to run. The courts that eventually looked at the programme built out of Section 215 were not impressed by the benefits. The Second Circuit held in ACLU v. Clapper on May 7, 2015 that the statute never authorised bulk collection of call records at all. The Ninth Circuit went further on September 2, 2020 in United States v. Moalin, finding the bulk collection violated FISA and may have been unconstitutional. Section 215 itself lapsed on March 15, 2020. The programme it was used to justify ran for fourteen years before a court of appeals reached the question of whether the law permitted it.

What Does Any of This Mean for the Person Reading It?

Twenty five years produces a clear picture of what individual action can and cannot do.

It cannot undo the legal architecture. No consumer product changes what a national security letter compels, what a border officer may inspect, or what a FISA Court certification authorises. Anyone marketing a tool as protection against a state is describing a product that does not exist.

What individual choices do reach is the everyday commercial layer of collection that grew up beside the legal one. That layer touches nearly everybody and is governed by very little. Traffic on a network you do not control is visible to whoever runs it, and retention rules like France’s one-year obligation land on internet service providers. Encrypting the connection between your device and a VPN server means the network operator sees a tunnel instead of a list of destinations. That benefit is real, and it is also bounded, and both halves of that sentence matter. Le VPN was founded in Paris in November 2010, keeps connection logs, not activity logs, supports up to 10 simultaneous connections, and offers a 30-day money-back guarantee on a first purchase.

The other lesson is about deadlines, and it is not encouraging. France’s expiry date ran out in 2003 and the power stayed. Section 215 ran to 2020, by which point the programme it justified had already operated for fourteen years. Section 702 ran out three months ago and the collection continues under a court certification into 2027.

Two decisions will shape the next stretch. Congress has to return to Section 702 before those certifications lapse in March 2027, and the European Commission is due to put its data retention proposal on the table. Both are worth watching closely, because they decide whether the emergency that began on a Tuesday morning in September 2001 finally gets argued on its merits, or simply renews itself again while nobody is looking.

For a longer view of how these tools developed, see our guide to online privacy, how strong encryption works, and VPN servers in the United States. Our blog covers new surveillance legislation as it moves.

About the author

Le VPN Blog Editor

Alan Summers has been writing and editing for the Le VPN blog for years, covering online privacy, cyber security, and the best ways to get the most out of a VPN. He keeps a close eye on the news that affects internet freedom around the world and turns it into practical advice for Le VPN readers.

Articles by Alan Summers →

FAQ: September 11, Surveillance Law and Digital Privacy

Set Up the School Year for 78% Less

Campus Wi-Fi, dorm streaming, research without borders - protect every device the family takes to school, for 3 years at $2.22 a month.

Claim offer

30-day money-back guarantee

VTNV Solutions Limited. © 2026 Le VPN. All rights reserved. Sitemap