← Red Threads

Public officials ask payment networks to use private rules

9 September 2026. Bounded run: who originated the August 2025 multistate NCII intervention, what action it sought, and whether a response or consequence is established. NCII means nonconsensual intimate imagery. This packet does not investigate or link to the offending services themselves.

The instrument and the action

The [22 August 2025 combined letters](http[local research file] contain separate payment and search interventions. Payment addressees are the legal officers of Visa, Mastercard, American Express, PayPal, Google and Apple, addressed as Google Pay and Apple Pay. Block/Cash App is not a payment addressee. The payment body asks for current controls and further action, using existing terms and acceptable-use policies to identify and remove sellers of deepfake NCII tools/content proactively. This is seller-level exclusion, not merely deletion of an individual image.

The payment body does not supply an operative statutory provision, case number, sanction, compulsory response deadline, seller list or named bank instruction. Its First Amendment assurance is the authors' position, not a judicial decision. Prior Pornhub and Civitai cutoffs appear as cited precedents; they cannot be outcomes caused by this later letter. The separate search letter asks for restrictions, warnings and redirects and refers to the Take It Down Act. Neither instrument establishes a recipient's actual subsequent decision. See PDF1-3 and9-11.

Origin and collective endorsement

Pennsylvania's 26 August announcement.

The original visibly uses NAAG letterhead and the 2025 officers: John Formella, William Tong, Marty Jackley and Letitia James, with Brian Kane as executive director. The current September 2026 leadership page belongs to a different observation date. Published May 2026 signature procedures describe a later process; without the actual 2025 circulation record they do not establish the historical approval steps for these letters. Actual sponsor instructions, edits, signature confirmations and transmission/receipt records remain unacquired.

A later threat changes the interpretation

In his [19 September 2025 official newsletter](http[local research file] signatory Raul Labrador describes the coalition letters as a choice between safeguards and legal consequences. Root read the complete substantive body, including the links to the two letters. This makes an account of entirely consequence-free persuasion inadequate: at least one participating AG publicly attached threatened legal consequences to the demand. The newsletter still supplies no filed case, operative order, meeting, recipient response or completed company change. It is not evidence that every co-signatory adopted that later characterization. Its statements about search behavior and prevalence are advocacy claims, not independently tested results in this run.

What this joins, and what it does not

The supported mechanism is coordinated public-office pressure directed at company counsel, seeking decisions under private network rules. This offers a concrete conversion point between government advocacy and commercial exclusion. It does not require proving that an AG owns or controls a payment company. The July Cash App NAAG reimbursement belongs to a different investigation; no allocation or expense record connects that money to this letter campaign.

At the same time, the presence of company discretion does not establish an unconstrained or wholly voluntary choice. Official threats, existing law, reputational exposure and company policy may interact. We need a recipient's reply, counsel assessment, merchant/acquirer instruction, actual restriction or later enforcement record to determine which interaction occurred here. We have no basis to assign these letters responsibility for Steam removals, a general pornography prohibition, or universal identity requirements. The seller-level scope makes collateral reach a concrete question, but actual overbreadth requires a worked case.

Reading and custody

Root read all 15 pages of the NAAG combined-letter web-reader representation in the preceding acquisition phase and all returned text of the Pennsylvania indexed copy in this run. Root reread the retained live Pennsylvania payment body and visually inspected PDF1; the content and 15-page structure match the inspected representations at the substantive clauses, without claiming byte identity across hosts. Root also read the entire retained Pennsylvania announcement main body. Vermont's complete substantive announcement was returned in search; direct reader open returned403, so this packet does not pretend that route succeeded.

The indexed Pennsylvania /2025/09/ PDF URL returned404 through ordinary GET despite a working indexed reader. Its retained pa-letters.pdf is an error response, explicitly marked false in captures-root.json. The exact PDF href in the successful announcement led to pa-letters-live.pdf, a successful original: 1,397,552 bytes, SHA256 75db0aba797ff32ebf992254f169571c2385611f171fb87b6f055e6e09c88a97. PDF metadata shows a September2 modification, not a proven publication or drafting date. No metadata-based authorship inference is made. Pennsylvania announcement: 122,926 bytes, SHA256 c1780ae668b126d546a9dece7107b5171c7bf666a91a3cafdf09cfaa0ed9b120. The failed path is closed, not repeatedly retried.

Independent letter review is in independent-letter-review.md; response-search.md records the bounded outcome lane and any secondary follow-up leads. The letter's cited prevalence infographic has not been audited; its percentages are not adopted as this campaign's findings. No outreach, target-service use, paid route, account access or submission occurred.