<h2>Researching Employment Scams</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/researching-employment-scams.html"><strong>[2026.09.03]</strong></a> Researchers built a fake company to study <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">fake employee scams</a>.


<h2>AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html"><strong>[2026.09.04]</strong></a> We cannot forget that AI coding agents are <a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/">not yet trustworthy</a>: <blockquote>Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren&#8217;t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI&#8217;s Codex, and Nous Research&#8217;s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.</blockquote> This kind of thing will be exploited. Think Solar Winds–style supply chain attacks. <blockquote>&#8220;The trust model is broken,&#8221; Alon Hertz, one of the researchers, wrote in an interview. &#8220;Agents treat vendor docs as ground truth and don&#8217;t question them­and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer­SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today’s guards don&#8217;t cover it.&#8221;</blockquote>


<h2>Security Vulnerability in a Voting System</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html"><strong>[2026.09.04]</strong></a> It&#8217;s a vulnerability that allows someone to recover the order of ballots cast, <a href="https://blog.citp.princeton.edu/2026/08/03/an-algorithmic-failure-beneath-the-secret-ballot/">newly exploited</a> with AI tools. <blockquote>Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. <em>Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public.</em> After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the &#8220;CVR&#8221; (cast-vote record) file, containing every ballot and its selections (but not the voters&#8217; names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable.</blockquote>


<h2>Using a VM to Contain an AI Agent</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/using-a-vm-to-contain-an-ai-agent.html"><strong>[2026.09.04]</strong></a> It <a href="https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/">won&#8217;t work</a>: <blockquote>My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.</blockquote>


<h2>Automobile Camouflage to Hide from Flock Cameras</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/automobile-camouflage-to-hide-from-flock-cameras.html"><strong>[2026.09.07]</strong></a> Not sure it&#8217;s practical, but it&#8217;s certainly <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/invisible-car-machine-learning-hide-vehicle-flock-cameras">striking</a>.


<h2>Stealing AI Reasoning Traces</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html"><strong>[2026.09.08]</strong></a> Interesting research: &#8220;<a href="https://arxiv.org/abs/2608.09867">Stealing Reasoning Traces from Proprietary LLM APIs</a>&#8220;: <blockquote><b>Abstract:</b> Leading large language model providers now conceal their models&#8217; step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider&#8217;s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model&#8217;s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model&#8217;s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mitigations to secure client-side reasoning.</blockquote>


<h2>AIs as Modern Genies</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/ais-as-modern-genies.html"><strong>[2026.09.08]</strong></a> <em>This essay was written with Barath Raghavan, and originally appeared in <a href="https://www.lawfaremedia.org/article/ais-as-modern-genies">Lawfare</a>.</em> In April, an artificial intelligence (AI) agent <a href="https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442">conducting</a> a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model <a href="https://thezvi.substack.com/p/what-happened-openai-and-huggingface">hacked</a> onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by <a href="https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591">figuring out</a> how to cancel other people’s reservations. In all three cases, the AI completed the task it was given&#8212;but in ways that ran counter to its controllers’ intentions. For most people, AI technology is something like the weather: vast and not something you can do much about. It works like magic, and most explanations similarly come from those trying to sell it. At the same time, AI is ubiquitous: It’s now in your phone, your doctor’s notes, and your kid’s homework. It does what it’s told, which sounds like a virtue. Somehow it feels ordinary, despite being so new, because modern economies are remarkably good at absorbing enormous change so smoothly that nobody has time to decide whether they wanted it in the first place. Whenever something powerful appears in the world, we tell stories about it. That’s what the stories are for. We have thousands of years of stories about this particular kind of power, the kind you summon with words. King Midas was granted his wish that everything he touches turns to gold. Then his bread turned to gold, and his wine, and his daughter. This is a story about greed, but it’s also a story about language. The gods did not cheat him; Midas got exactly what he asked for. He simply could not delineate, in advance, the full set of restrictions to his wish. Neither can anyone who gives tasks to an AI agent. It’s not just ancient stories. Mary Shelley told us of the hubris of a scientist who thought he could create life but who failed to take responsibility for it. Isaac Asimov’s robots don’t break the Three Laws of Robotics as stated; they follow the rules to unintended conclusions. Arthur C. Clarke’s HAL is a machine that turns on its humans, not because of malice but because of irreconcilable objectives. And Michael Crichton gave us Ian Malcolm, who saw that Jurassic Park’s scientists were so preoccupied with whether they could that they never stopped to think whether they should. The same warning shows up everywhere, in every culture, over thousands of years of human storytelling. Tithonus is granted immortality but not youth, and withers into a husk that cannot die. The sorcerer’s apprentice enchants a broom to fetch water but floods the house. The golem of Prague protects its community so ceaselessly that it must be stopped. These are all types of genies: a creature that grants a wish exactly as worded, to the regret of the wisher. Of course, there are no actual genies. What these stories were warning us of was hubris. Not just arrogance, but the broader idea that you can control the world by just describing what you want and allowing powerful forces to match the intention in your head. Genie stories are about the gap between wishes as stated and wishes as intended, and what goes wrong when something else fills that gap. These ancient stories’ warnings have been retold with each generation because human nature is constant. The newfound power of each era’s social or scientific advancement leads people to make wishes on behalf of others. They were kings whose commands took on lives of their own, alchemists who believed they could control nature, and generals who mistook a map for terrain. They were and are industrialists, politicians, chief executives, and bankers. Their common belief is that one can see the world <a href="https://yalebooks.yale.edu/book/9780300078152/seeing-like-a-state/">at a glance</a> and then command it with some words. The pattern is clear: Someone with power specifies a goal, and the resultant actions come as a surprise. The main change with AI is how quickly the wish is granted, and how few people have to agree before it’s granted. Consider what has changed. Powerful <a href="https://www.theguardian.com/commentisfree/2026/jul/28/rogue-ai-agent-instructions">genies</a> have now been put in everyone’s hands. In only a few years, AI has progressed from a novelty technology that <a href="https://en.wikipedia.org/wiki/Deep_Blue_(chess_computer)">plays</a> chess, to a dialogue partner that answers all your questions, and then to an agent that takes actions on your behalf. Modern agents are wired into real accounts with real credentials and capabilities: They browse the web, buy, write and deploy code, send email, and move money. Give an agent a goal, and it will pursue it across many steps, tirelessly, without checking back in, sometimes in surprising ways. AI and agents do not always fail the way software has traditionally failed. Software usually fails by freezing, crashing, or getting stuck. AI agents increasingly fail by continuing down a path you don’t want, like genies. An agent told to reduce a company’s costs might cancel an essential emergency service. A coding agent told to make software pass the tests might edit the tests to silence any failures. An AI insurance agent told to clear a backlog of claims might just deny them all. In each case, the AI might have literally followed what it was told, but it did something no reasonable person would have wanted. AI company benchmarks might report that the AI is good at completing tasks, without measuring how it completes them. We have recently proposed measuring this gap directly under a metric called the “<a href="https://spectrum.ieee.org/ai-agent-benchmark">genie coefficient</a>”: how far an AI agent’s actions drift from what a person really meant. In other words, how genie-like is an AI system? The gap is a fundamental feature of human language and human society. Human intentions have never been fully specifiable, and the world around us is complex enough that attempts to boil it down into data, systems, and language have always had the limitations that AI is now bumping up against. But in individual circumstances, people have relied on human judgment and wisdom to decide what is reasonable. It’s what jury trials depend upon. AI might feel unprecedented, but it’s following the same trajectory&#8212;with the same pitfalls&#8212;as other major societal shifts. The fact that AI can mimic our facility with language, long seen as what makes us unique as humans, is uncanny. But with each development, from the tractor to the sewing machine, from the assembly line to the industrial robot, we have automated a previously exclusively human ability. Every time, the technology&#8212;and the societal change that comes with it&#8212;was sold as inevitable. But that unchecked inevitability was an illusion, and eventually each prior technology’s use and design was shaped by laws, unions, standards, courts, and public opinion, usually after significant preventable damage. What has not been automated, yet, is understanding what someone actually means and figuring out how that gets applied in the real world. AI can now produce language nearly indistinguishable from that of people. But grasping the vast unstated context that makes a request sensible, the caveats no one says aloud because an ordinary person would already know them, is not yet among its skills. It is one of the most sophisticated things humans do. You do it hundreds of times a day, and you are an expert in it. When you’re told you’re not qualified to have opinions about AI, remember that you don’t need to have studied molecular biology to have a view on drug pricing, or nuclear physics to vote on where a power plant goes. You don’t need to understand how a diesel engine works to want clean air, or how the internet routes packets to seek to curb misinformation. The technical knowledge behind each of these, as with AI, is remarkable and essential for the complex technological society we have today. But it has never been a prerequisite for having a role in deciding the shape of society. People are building ever more powerful genies today, on your behalf, enabling wishes the ancients could only dream about. You don’t have to know how these AI genies work to know and care about how the story could end.


<h2>Claude Fable Solves a Historical Cipher</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html"><strong>[2026.09.09]</strong></a> Claude Fable 5.1 <a href="https://www.vals.ai/blogs/fable-solves-cyphral-distich">solved</a> a 370-year-old cipher in forty-four minutes. This tracks with what I <a href="https://www.theguardian.com/commentisfree/2026/aug/25/ai-mathematics-careers">wrote</a> about AIs doing mathematics: It&#8217;s good at things that involve lots of searching and testing. EDITED TO ADD (9/14): I&#8217;m not sure if this result is <a href="https://github.com/reticuli-labs/panel-artifacts/blob/main/distich-refutation-2026-09-01/FINDINGS.md">correct</a>. The <a href="https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html#comments">blog comments</a> have more discussion.


<h2>Driver's License Data for Sale</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html"><strong>[2026.09.09]</strong></a> A database of 153 million drivers licenses is <a href="https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/">for sale</a> on the dark web. Brian Krebs has more <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/">detail</a>.


<h2>AIs Compress Exploit Timeline</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html"><strong>[2026.09.10]</strong></a> Give an AI agent a mere <a href="https://anil.recoil.org/notes/rumour-is-the-exploit">rumor</a> of an exploit, and it&#8217;s enough for them to find it. <blockquote>What&#8217;s worse, I found I could use my own agents to find the exploit <i>just by knowing roughly what it was about</i> and so could have been exploiting it well before the public patch was available! Given that just the <i>rumour</i> of a security issue seems enough to give attackers enough info to find new exploits, we&#8217;re going to need to change the way we deal with security responses in open source.</blockquote> Simon Willison <a href="https://simonwillison.net/2026/Aug/28/just-a-rumour-of-a-bug/">comments</a>: <blockquote>Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.</blockquote>


<h2>Cliff Stoll's DEF CON Talk</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/cliff-stolls-def-con-talk.html"><strong>[2026.09.11]</strong></a> In August, Cliff Stoll gave a <a href="https://www.youtube.com/watch?v=656058JxTM0">talk</a> at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.


<h2>My Talk at DEF CON</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/my-talk-at-def-con.html"><strong>[2026.09.11]</strong></a> Last month, I gave a <a href="https://www.youtube.com/watch?v=eEBv0STiYhI">talk</a> at DEF CON on AI hacking: what happens when AIs become hackers. It&#8217;s a combination of the potentialities I raised in my 2022 book <a href="https://www.schneier.com/books/a-hackers-mind/"><i>A Hacker&#8217;s Mind</i></a> and the lessons we&#8217;re learning from current AI models engaging in hacking behavior. I&#8217;m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days. Also online is an <a href="https://www.youtube.com/watch?v=7-sMBqPV3XU">interview</a> with me in the AI Village.


<h2>Microsoft's Patching</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html"><strong>[2026.09.14]</strong></a> Once a month, Microsoft pushes a security update to all Windows users. Tomorrow&#8217;s is a <a href="https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/">new record</a>: <blockquote>Microsoft&#8217;s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an <a href="https://openai.com/collective-cyberdefense">open letter</a> warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.</blockquote> This is the result of AI-powered vulnerability finding, and a good example of AI helping the defenders more than the attackers. What will be interesting to watch is how the number of vulnerabilities changes over the next few months. My prediction is that it will continue to increase as the AIs get better at finding software vulnerabilities, and then decrease as they run out of vulnerabilities to find. How high the number gets, how fast the trend reverses, and how quickly it declines after that are all unknown. And Microsoft is right: The window to patch has shrunk to &#8220;immediately.&#8221; AIs are also good at reverse-engineering exploits from patches, which means that these vulnerabilities will be weaponized as soon as the update is published.


<h2>Using AI for Weapons Development</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/using-ai-for-weapons-development.html"><strong>[2026.09.14]</strong></a> Last week, Anthropic released a long and detailed <a href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf">document</a> describing current misuses of their Claude models. I&#8217;m still reading it, but I wanted to flag this: <blockquote>We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the &#8220;R2000&#8221; set) that included a hypersonic glide vehicle variant. The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. For example, they used Claude to integrate an open-source autopilot onto a phone-class flight computer, writing the control and position estimation software, tuning the control settings, running a firmware build pipeline, and performing a flight simulation. The actors managed several Claude instances at once, assigning each one a role, much as a lead would delegate work on a small engineering team: the actors tasked one instance with writing the code, another with research, and a third with reviewing the code the first instance produced. Our safeguards blocked many of their requests, but not all of them. The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent. These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.</blockquote> Expect more of this. AI systems democratize expertise and capability. Most of the time that&#8217;s a good thing, but sometimes it&#8217;s not.


<h2>Upcoming Speaking Engagements</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/upcoming-speaking-engagements-60.html"><strong>[2026.09.14]</strong></a> This is a current list of where and when I am scheduled to speak: <ul> <li>I’m speaking online (via Zoom) at a <a href="https://www.lwvme.org/civicrm-event/2400?a0=events-month&amp;a1=202609">League of Women Voters event</a> on Tuesday, September 22, 2026 at 5 PM ET.</li> <li>I’m speaking at <a href="https://www.secwest.net/">CanSecWest 2026</a> in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.</li> <li>I’m giving a talk on “<a href="https://events.bentley.edu/event/free-speech-and-the-preservation-of-democracy">Free Speech and the Preservation of Democracy</a>” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026.</li> <li>I’m speaking at <a href="https://www.attentionconferences.com/conferences/2026-forum">ATTENTION: Democracy, Rebuilt</a> in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.</li> </ul> Note: the Elevate Festival talk listed in last month&#8217;s newsletter is canceled. The list is maintained on <a href="https://www.schneier.com/events/">this page</a>.


<h2>On the NSA's Supercomputer from the 1960s</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html"><strong>[2026.09.15]</strong></a> Really interesting <a href="https://spectrum.ieee.org/cold-war-codebreaker-nsa-ibm">story</a> about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.


<h2>25 Years of Mass Surveillance Is Enough</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html"><strong>[2026.09.15]</strong></a> <em>This essay was written with Cindy Cohn, and originally appeared in <a href="https://www.lawfaremedia.org/article/25-years-of-mass-surveillance-is-enough">Lawfare</a>.</em> One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance&#8212;such as individual wiretaps or pen register/trap and trace orders&#8212;to mass surveillance techniques&#8212;such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in<a href="https://www.eff.org/deeplinks/2025/11/rights-organizations-demand-halt-mobile-fortify-ices-handheld-face-recognition"> immigration actions</a> and against <a href="https://www.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr-network-surveil-protesters-and-activists">people exercising</a> their First Amendment rights to protest. It&#8217;s also increasingly part of private security systems, such as facial recognition at venues such as <a href="https://freespeechproject.georgetown.edu/tracker-entries/madison-square-gardens-use-of-facial-recognition-technology-to-bar-certain-lawyers-stirs-protests/">Madison Square Garden</a> and networked <a href="https://apnews.com/article/flock-license-plate-cameras-surveillance-deflock-2a93bc075e2f7ffcca9e04a35d75a3fe">Flock</a> license plate capture systems on roads and in parking lots. The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly <a href="https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-staff-report-finds-large-social-media-video-streaming-companies-have-engaged-vast-surveillance">spy</a> on their users&#8217; behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies. Increasingly, access doesn&#8217;t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional <a href="https://fedscoop.com/fbi-data-broker-loophole-purchase-dhs/">testimony</a> that the agency is purchasing information on Americans from data brokers and intends to continue to do so. This pipeline from private collection to governmental collection means that as companies collect more information for <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=56791">surveillance capitalism</a> purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well. After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government&#8217;s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance. Or, in the words of an internal National Security Agency (NSA) <a href="https://www.justsecurity.org/10396/newly-released-nsa-documents-reveal-omnivorous-appetite-private-data/">presentation</a> that was made public as part of Edward Snowden&#8217;s 2013 disclosures, a government that can &#8220;Collect it All,&#8221; &#8220;Process it All,&#8221; &#8220;Exploit it All,&#8221; &#8220;Partner it All,&#8221; and &#8220;Sniff it All,&#8221; will ultimately, &#8220;Know it All.&#8221; Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes. The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts&#8212;or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents <a href="https://www.pclob.gov/library/215-Report_on_the_Telephone_Records_Program.pdf">examples</a> of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly <a href="https://www.newamerica.org/insights/do-nsas-bulk-surveillance-programs-stop-terrorists/">fall apart </a>upon serious scrutiny. And even if some utility exists, it must be seriously weighed against the costs. Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement&#8217;s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools <a href="https://www.cbsnews.com/boston/news/brown-university-mit-professor-shooting-flock-cameras-car/">float anecdotes</a> and <a href="https://static1.squarespace.com/static/5edeeebc3032af28b09b6644/t/64a46a417c2a6637212e1ce3/1688496710563/2021_11_30_alpr.pdf">dubious data</a>. For example, Flock&#8217;s data equates the number of law enforcement hits in their database with actually solving crimes. Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans&#8217; rights and freedoms. <h3>The Shift</h3> The easiest place to see a shift to mass surveillance was in the government&#8217;s decision immediately after 9/11 to collect Americans&#8217; telephone records. The program started under an <a href="https://en.wikipedia.org/wiki/President%27s_Surveillance_Program">argument</a> of pure executive power as the &#8220;President&#8217;s Surveillance Program.&#8221; But in 2006, that argument secretly shifted to a <a href="https://www.aclu.org/news/national-security/surveillance-memos-and-suggestion-jack-goldsmith">novel interpretation</a> of Section 215 of the Patriot. Act which had only previously authorized more targeted access to record. While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially <a href="https://www.dni.gov/index.php/newsroom/press-releases/press-releases-2013/item/869-dni-statement-on-the-collection-of-telephone-metadata-under-section-215-of-the-usa-patriot-act">confirmed</a> it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals <a href="https://www.lawfaremedia.org/article/second-circuit-strikes-down-215-program">rejected</a> the government&#8217;s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the <a href="https://www.govtrack.us/congress/bills/114/hr2048/text">USA Freedom Act</a>. While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years. Other shifts to mass surveillance continue through today. The NSA launched its <a href="https://documents.pclob.gov/prod/Documents/OversightReport/1c3c0f5a-3e4b-4f3f-9e6b-2c1b7a4e0f7b/702-Report-2.pdf">Upstream</a> program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via <a href="https://uscode.house.gov/view.xhtml?req=granuleid:USC-2010-title50-section1881a&amp;num=0&amp;edition=2010">Section 702</a> of the 2008 FISA Amendments Act. In 2017, more than15 years after its inception, the NSA <a href="https://jsis.washington.edu/news/controversy-comparisons-data-collection-fisas-section-702/#_ftn27">ended</a> content searches due to FISA court pressure, but the mass collection continues. Despite the stated goal of conducting mass spying <em>only</em> on people outside the U.S.&#8212;which itself is problematic given international law&#8217;s requirement that surveillance be both <a href="https://necessaryandproportionate.org/principles/">necessary and proportionate</a>&#8212;mass surveillance collects a tremendous amount of U.S. persons&#8217; communications. This can happen because people communicate with people abroad, or because of overcollection&#8212;when government agencies gather far more personal data on non-targeted US persons than authorized by law. The concerns about collecting Americans&#8217; data on U.S. soil led Congress to allow the program to officially expire in 2026, although the previously-approved mass surveillance itself continues until at least Spring of 2027. The shift to mass surveillance would be notable enough even if it remained only a strategy of the intelligence community. It has not. Americans are awash in mass surveillance. Networks of automated license plate readers such as those offered by Flock and Vigilant Solutions <a href="https://maps.deflock.org/?lat=39.8283&amp;lng=-98.5795&amp;zoom=4.00">blanket</a> both public and private roadways and parking lots. These networks often allow searches by law enforcement, including across jurisdictions. They are, for example, being used to track people seeking abortions <a href="https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down">across</a> state lines. Facial recognition tools, once the province of only the more elite parts of federal law enforcement, are increasingly used by <a href="https://www.theguardian.com/technology/2026/jan/27/ice-facial-recognition-minnesota">Immigration and Customs Enforcement</a> agents on immigrants and protesters, in airports by the <a href="https://www.msn.com/en-us/travel/news/how-tsa-facial-recognition-actually-works-and-what-travelers-should-know/ar-AA27UDf4">Transportation Security Administration</a>, as well as by <a href="https://www.nytimes.com/2022/12/22/nyregion/madison-square-garden-facial-recognition.html">private entities</a>. And, of course, modern phones track users&#8217; locations constantly&#8212;and that information is readily available to law enforcement, often with only minimal process protections. <h3>Constitutional Costs</h3> Regardless of the murkiness of its actual usefulness, the shift from targeted to mass surveillance has profound implications for Americans&#8217;rights. It has created risks that have become increasingly evident, especially under the Trump administration. At a basic level, the Fourth Amendment guarantees that citizens can be secure in their &#8220;persons, houses, papers and effects&#8221; from unreasonable searches. Warrants breaching that security should be supported by probable cause and particular descriptions of the place to be searched and items to be seized. Mass surveillance turns that promise on its head, allowing access to our &#8220;papers and effects&#8221; by the government without individualized suspicion or a particularized description of what data is being seized, much less probable cause. This protection was in response to colonial British misuse of <a href="https://www.eff.org/files/filenode/att/generalwarrantsmemo.pdf">writs of assistance</a>, which authorized indiscriminate searches rather than targeted ones. The justifications for exempting mass surveillance from constitutional protection vary. For Section 702, the government has taken the <a href="https://www.brennancenter.org/our-work/research-reports/section-702-foreign-intelligence-surveillance-act">position</a> that U.S. persons&#8217; communications caught up in the dragnet, either due to overcollection or because they were communicating with someone outside the United States, do not require a warrant prior to initial collection or secondary access by the FBI and several other agencies. The argument is that if the initial collection was not aimed at Americans, the information is free from constitutional protection for any later uses, even for reasons far afield from the initial rationale for collection. Other arguments rest on the claim that metadata is outside the Fourth Amendment, despite its demonstrated <a href="https://news.stanford.edu/stories/2016/05/stanford-computer-scientists-show-telephone-metadata-can-reveal-surprisingly-sensitive-personal-information">ability</a> to reveal intimate details of all of our lives. Still others rest on the Supreme Court-created <a href="https://supreme.justia.com/cases/federal/us/442/735/">Third Party Doctrine</a>, which holds that the Fourth Amendment does not apply to data shared with companies that provide us with services. Some turn on whether analysis by machine <a href="https://www.fisc.uscourts.gov/sites/default/files/BR%2013-158%20Primary%20Order.pdf">counts</a>, claiming that only &#8220;human eyes&#8221; matter&#8212;a particularly troubling argument with the rise of artificial intelligence. What&#8217;s more, the government has used doctrines like standing to <a href="https://www.eff.org/deeplinks/2015/02/jewel-v-nsa-making-sense-disappointing-decision-over-mass-surveillance">limit</a> the ability of those subjected to mass surveillance to seek constitutional protection. No matter the argument, the goal is the same: to place the mechanisms and fruits of mass surveillance outside the protections of the Fourth Amendment. The overarching truth is that, due to the concerted efforts by the government since 9/11, and the rise of technologies in recent years, the slice of Americans&#8217; lives and data that are actually protected by the Fourth Amendment has shrunk significantly in the past 25 years. Together, with the technical capabilities of mass surveillance and the increased <a href="https://slate.com/technology/2023/12/ai-mass-spying-internet-surveillance.html">ability</a> for that data to be analyzed using AI tools, the &#8220;security in our papers and effects&#8221; that the constitution promises seems increasingly illusory. In addition to the Fourth Amendment, mass surveillance creates tensions with the First Amendment. The Constitution has long recognized that the right to freedom of speech requires a zone of privacy against governmental surveillance. The right to anonymous speech as well as the right of association both recognize the <a href="https://www.cambridge.org/core/books/chilling-effects/22383D541B3BC45C9145E85DA4824E10">chilling effect</a> that surveillance creates for people saying unpopular things or attempting to organize for political or other societal change. Mass surveillance grants the authorities the ability to track those people, both in real time and historically, that is inconsistent with actual techniques of freedom of speech and assembly. That is why the recently released <a href="https://www.whitehouse.gov/wp-content/uploads/2026/05/2026-USCT-Strategy-1.pdf">2026 U.S. Counterterrorism Strategy</a> is so troubling. On page seven, the White House expressly states that it intends to target domestic activists with its heretofore foreign-targeted powers. It says that the government &#8220;will prioritize the rapid identification and neutralization of violent secular political groups whose ideology is anti-American, radically pro-transgender and anarchist&#8221; and &#8220;will use all the tools constitutionally available to us to map them at home, identify their membership, map their ties to international organizations like Antifa.&#8221; While framed as targeting &#8220;violent&#8221; groups, it&#8217;s clear that the government intends to use its national security tools, presumably including the tools of mass surveillance, against Americans in ways that will create profound tensions with the First Amendment rights of people to organize and communicate privately. <h3>Costs Due to Mistakes and Abuse</h3> Even assuming some utility from mass surveillance&#8212;a fact we do not dispute, even if the public record is shaky and conclusory&#8212;the history of both the national security and domestic uses of mass surveillance confirms that these tools are inevitably <a href="https://www.nytimes.com/2026/09/10/opinion/911-patriot-act-trump-politics.html">misused</a>, and that mistakes have impacted huge numbers of Americans. The past twenty-five years have demonstrated that it is not possible to surveil the entire US population while staying within the bounds of even a very generous legal framework like Section 702. As Rep. Zoe Lofgren (D-Calif.) recently stated in discussion of Section 702 in an <a href="https://www.techpolicy.press/rep-zoe-lofgren-on-fisa-surveillance-and-the-fourth-amendment/">interview</a> with <em>Tech Policy Press</em>: &#8220;backdoor searches have been used improperly for protestors, 19,000 campaign donors, members of Congress, journalists, government officials, a state court judge who had complained to the FBI about police misconduct. It has been abused substantially in the past.&#8221; The NSA experienced so much <a href="https://arstechnica.com/tech-policy/2013/09/loveint-on-his-first-day-of-work-nsa-employee-spied-on-ex-girlfriend/">abuse</a> of its mass surveillance tools by actual or aspiring romantic partners and ex-spouses that an internal name emerged for it: &#8220;<a href="https://arstechnica.com/tech-policy/2013/09/loveint-on-his-first-day-of-work-nsa-employee-spied-on-ex-girlfriend/">LOVEINT</a>,&#8221; or Love Intelligence. That same pattern of abuse is now emerging at the domestic law enforcement level. A Texas police officer <a href="https://www.eff.org/deeplinks/2025/05/she-got-abortion-so-texas-cop-used-83000-cameras-track-her-down">misused</a>, and then lied about, using license plate readers to track a woman suspected of seeking an abortion. Multiple law enforcement officials have been <a href="https://ij.org/the-ij-database-of-alpr-abuse/">accused</a> of tracking people they either wished to have a relationship with or who were their exes. And mass surveillance technologies have been used to track both <a href="https://www.washingtonpost.com/technology/interactive/2026/ice-surveillance-immigrants-protesters/">immigration targets</a> and citizens <a href="https://www.democracynow.org/2026/1/29/ice_cbp_facial_recognition_technology_app">engaging</a> in their First Amendment-protected right to track and record the police. Mistakes are inevitable with collections of data of this size and scope. The history of the FISA court&#8217;s reviews of Section 702 is littered with examples of the NSA not being able to <a href="https://www.justsecurity.org/66595/the-fisa-courts-702-opinions-part-i-a-history-of-non-compliance-repeats-itself/">follow</a> its own rules limiting the scope of what it collects and analyzes, even after having been given multiple chances by the court. On the local level, the technical protections that Flock, for example, put in place have repeatedly been insufficient to stop <a href="https://lookout.co/city-of-santa-cruz-pauses-statewide-license-plate-data-sharing-citing-flock-safetys-violation-of-california-law/story">&#8220;accidental&#8221; sharing</a> its data with out-of-state law enforcement. These mistakes have fueled growing efforts by local communities across the country to remove license plate readers. Those efforts should be the first step in a broader reconsideration of mass surveillance. More generally, ubiquitous surveillance carries a real societal cost. The chilling effects are real and <a href="https://www.theguardian.com/commentisfree/2026/jul/06/ai-surveillance-policy">pervasive</a>, and they tend to fall hardest on the most marginalized members of society. Moreover, social progress <a href="https://www.schneier.com/essays/archives/2018/11/surveillance_kills_f.html">requires</a> the ability to experiment in secret. It&#8217;s hard to imagine a society progressing morally to the point of accepting and legalizing things like marijuana use or gay marriage if the earliest signs of that shift are snuffed out because of overzealous surveillance. <h3>Reversing Course</h3> While a cost-benefit analysis is not the best frame for deciding constitutional rights, it is a place to start to evaluate government policies. If the costs are too high and the benefits too small, what should the public do? While the policy and legal frameworks can be individually complex, mass surveillance is a problem in all of its applications. So too should solutions be comprehensive rather than piecemeal. One comprehensive strategy is to reset the promise of the Fourth Amendment and recognize that a warrant is required prior to collection, access or use of information gathered through mass surveillance. This would apply to collections that include U.S. persons, whether done for national security or domestic purposes. This protection would apply regardless of whether the information is in the form of metadata. It would apply regardless of whether the information is held in homes or by services people rely on, such as telephones, internet or social network providers, or by private entities utilizing mass surveillance for their own purposes. By passing this legislation, Congress could ensure this rejection of mass surveillance, and include real enforcement such as a private right of action and an automatic exclusionary remedy in criminal prosecutions. The courts could also recognize this protection of &#8220;papers and effects&#8221; directly as a plain language interpretation of the Fourth Amendment. There are already a number of efforts that take on pieces of mass surveillance. Section 702 has expired and should remain so. This was due largely to efforts to block the <a href="https://www.brennancenter.org/our-work/research-reports/congress-must-close-backdoor-search-loophole-requiring-warrantfisa-0">&#8220;back door&#8221; access</a> to Section 702-collected data without warrants. The bipartisan &#8220;<a href="https://www.wyden.senate.gov/news/press-releases/wyden-applauds-bipartisan-passage-of-his-fourth-amendment-is-not-for-sale-act-in-the-house-judiciary-committee">Fourth Amendment is Not for Sale Act</a>&#8221; would prevent the government from purchasing data that it would otherwise need a warrant to obtain. The Supreme Court itself has already been chipping away at the Third Party Doctrine, with a recent step in the rejection of mass geofence warrants&#8212;warrants seeking the identities of individuals based upon their proximity to a crime&#8212;in <a href="https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdf"><em>Chatrie v. United States</em></a>. Now, such warrants fall, at least initially, under the Fourth Amendment. A more comprehensive approach would also address mass surveillance carried out by private companies, and to ensure that Americans have the right to encrypt and secure their data. There are many reasons the United States would benefit from a <a href="https://www.eff.org/deeplinks/2025/04/eff-congress-heres-what-strong-privacy-law-looks">comprehensive privacy law</a>&#8212;and curbing mass surveillance is one of them. Addressing mass surveillance is certainly one of them. Ideas such as the banning of secondary uses of data&#8212;with roots in the <a href="https://iapp.org/news/a/50-years-and-still-kicking-an-examination-of-fipps-in-modern-regulation">Fair Information Practice Principles</a> from the 1970s&#8212;are worth pushing forward. So are moves such as creating <a href="https://wustllawreview.org/wp-content/uploads/2022/02/Richards-Hartzog-A-Duty-of-Loyalty-for-Privacy.pdf">fiduciary duties</a> for mass data collectors. There are many more ways to curtail private companies&#8217; mass surveillance while staying within constitutional boundaries. But addressing the costs of mass surveillance by both companies and governments is even more important in a world where AI agents are making decisions both about the public and on their behalf based on their data and observed behavior. Twenty-five years after the U.S. government embraced mass surveillance, it&#8217;s time to evaluate it as a whole, and consider responses that address the problem as a whole. Americans must ask: Is it consistent with a self-governing democracy to have systems that watch everyone everywhere? Is the public comfortable with governments&#8212;federal, state, local&#8212;that seek to &#8220;know it all&#8221; about its citizens? Is the public comfortable with private mass surveillance in its own right and as it&#8217;s being increasingly used to fuel government surveillance? These questions have long needed serious consideration. But as it becomes increasingly evident that the Trump administration is using mass surveillance to keep itself in power, stifle dissent, and undermine political opponents, these questions are now more urgent than ever.


<h2>Fake CAPTCHA Scams</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html"><strong>[2026.09.16]</strong></a> New <a href="https://www.malwarebytes.com/cybersecurity/basics/fake-captcha-scams">variant</a> of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.


<h2>How Candidates Could Use AI for Good</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html"><strong>[2026.09.17]</strong></a> <em>This essay was written with Nathan E. Sanders, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/aug/31/ai-politics-voters">The Guardian</a>.</em> There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have <a href="https://www.pewresearch.org/short-reads/2026/08/18/young-adults-in-the-us-are-increasingly-wary-of-ai-concerned-it-will-take-jobs/">anxiety</a> about AI&#8217;s impacts on the country. Politicos are using AI deepfakes to <a href="https://www.theguardian.com/technology/2026/jul/08/ai-ads-political-campaigns">spread</a> lies. The White House is posting <a href="https://www.theguardian.com/us-news/2026/jan/29/the-slopaganda-era-10-ai-images-posted-by-the-white-house-and-what-they-teach-us">slopaganda</a>. Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters&#8217; concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in <a href="https://www.theguardian.com/us-news/us-politics">US politics</a>, but groups in Japan, Scotland and the US&#8217;s own academic and private institutions show how that could change. The problem with American campaigns&#8217; current use of AI is that it&#8217;s not very different from the web ads of 30 years ago, or television ads before that: they are all about inundating voters with the candidate&#8217;s message. This one-to-many broadcasting is an <a href="https://thefulcrum.us/media-technology/artificial-intelligence-in-politics">uninspiring</a> way to campaign, but not the only way. AI can help candidates connect one-to-one with as many people as possible. Or it can facilitate many-to-many connections, engaging voters in deliberation about issues at scale. One of the most promising applications of AI being developed by pro-democracy innovators around the world is <a href="https://broadlisteningbook.com/en/01_what_is_broad_listening">broad listening</a>. These tools can collect public input in a format much richer than checkboxes on a survey form. For example, the newly founded Japanese political party <a href="https://team-mir.ai">Team Mirai</a> has built a foundation for eliciting public input from voters at scale, in depth, and across the breadth of legislative policy issues. It has developed an <a href="https://depth-interview-ai.vercel.app/">AI interviewer</a> to cultivate constituent input on policy. Through extended conversations with this chatbot, voters explore and share their perspectives on specific policy issues. And the party has scaled this across a wide array of policy issues by <a href="https://note.com/team_mirai_jp/n/n11ae2a019cc6">integrating</a> this functionality with an AI-powered portal for exploring bills. Team Mirai describes itself as a &#8220;utility party&#8221;, developing tools for any Japanese political party to use to connect with voters. You might question whether Americans would willingly talk to a political AI. So far, Japanese voters have <a href="https://depth-interview-ai.vercel.app/sessions">exchanged</a> more than 300,000 messages across 16,000 AI interviews. Team Mirai grew adoption by providing a real incentive to engage: that talking to their AI interviewer does more than just posting on a platform such as Twitter/X or, equivalently, shouting into a void. Users see evidence that the party is actually listening and might take action on their behalf. Team Mirai party members have directly cited AI interviews from constituents during legislative committee <a href="https://note.com/team_mirai_log/n/n6ede15ca33cf">hearings</a>, published a <a href="https://note.com/team_mirai_jp/n/nc7494dd7bdc1">synthesis</a> of that input back for voters, and even amended their policy <a href="https://www.democracyrenovator.com/i/184201144/mobilizing-action">platform</a> based on user input. The party has <a href="https://www.techpolicy.press/japans-team-mirai-uses-tech-to-bolster-democracy-not-undermine-it/">rapidly risen</a> to win 12 seats in the Diet, and is explicitly following in the footsteps of the civic hackers in <a href="https://www.theguardian.com/world/2020/sep/27/taiwan-civic-hackers-polis-consensus-social-media-platform">Taiwan&#8217;s</a> &#8220;gov zero&#8221; movement, who won political influence in their fight for transparency. Other civic technologists are developing AI tools for scaling many-to-many conversations. <a href="https://crown-shy.com">CrownShy</a>, a company funded in part by the Scottish government, is building a platform to bring the Platonic ideal of the town hall debate into the digital age. Their <a href="https://www.democracyrenovator.com/p/rewiring-democracy-citizen-science">Comhairle</a> tool integrates AI interviewing tools like the ones described above with software for synthesizing diverse viewpoints, holding virtual assemblies, and sharing video testimonials to help legislatures&#8212;or campaigners&#8212;organize digital consultations of their constituents en masse. One thing the AI-powered software of Team Mirai and CrownShy have in common is that they are open-source, meant for anyone to use. Even though they are projects funded by political parties&#8212;the upstart party in Japan and the ruling party in <a href="https://www.theguardian.com/uk/scotland">Scotland</a>&#8212;they are built to make democratic processes better, not necessarily for partisan political advantage. For interested candidates, there is a wealth of tools available, many of them US-grown. The Stanford-affiliated <a href="http://deliberation.io">deliberation.io</a> uses AI to facilitate structured dialogues among thousands of participants and has been piloted for public listening sessions by the city of <a href="https://octo.dc.gov/release/bowser-administration-announces-first-its-kind-ai-pilot-program-new-platform-mit-governance">Washington DC</a>. The MIT-affiliated <a href="https://cortico.ai">Cortico</a> project provides tools that surface under-heard community perspectives from recorded conversations, and is now organizing listening sessions at <a href="https://cortico.ai/partners/the-american-conversation-project/">libraries</a> across the country. The US non-profit-built <a href="http://ai.objectives.institute/talk-to-the-city">Talk to the City</a> uses AI to analyze large datasets of stakeholder input. The US startup <a href="http://remesh.ai">Remesh</a> has a commercial offering that uses AI to generate recommendations from dialogue, which has been <a href="https://arxiv.org/pdf/2311.02242">tested</a> in policy development scenarios. There is a long and proud tradition of this sort of &#8220;civic technology&#8221; in the United States. Two decades ago, the spirit of <a href="https://usdigitalserviceorigins.org/timeline/">innovation</a> to develop software for better politics and civic engagement was so strong in organizations like Code for America and the Obama 2008 campaign that Congress funded a new executive agency to bring these ideas to government: the US Digital Service. (The Trump administration repurposed the USDS to become the US Doge Service in 2025.) One signal that candidates and political parties may start adopting these kinds of tools came this spring from Higher Ground Labs. The Democratic-aligned campaign tech investment firm launched a new <a href="https://highergroundlabs.com/fundv/">fund</a> targeting, in part, &#8220;AI-Native Campaign Systems&#8221; and &#8220;community-Led Messaging Platforms that surface authentic, bottom-up insights from real conversations&#8221;. AI is a multifaceted issue that deserves to be on the table in the midterms. So far, the powerful force of <a href="https://www.politico.com/news/2026/08/20/dems-ai-california-campaigns-01043140">polarization</a> in US politics seems to be separating the parties into the AI skeptics versus the AI boosters. We urge both voters and politicians to <a href="https://www.techpolicy.press/separating-ais-technological-problems-from-its-capitalism-problems/">separate</a> the technology of AI from its profiteers. We want big tech <a href="https://www.theguardian.com/commentisfree/2026/jul/09/ai-datacenter-company-politics">money</a> out of politics, holding the AI companies <a href="https://www.theguardian.com/commentisfree/2026/jun/24/ai-errors-companies-responsibility">accountable</a> for the harm their models cause, <a href="https://www.theguardian.com/commentisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">taxing</a> their revenues, and maybe even <a href="https://www.theguardian.com/commentisfree/2026/aug/12/openai-anthropic-ai-models">nationalizing</a> them if the AI bubble bursts. But we also think congressional candidates in the US midterms seeking authentic connection with voters, and seeking to differentiate themselves from their opponents, should be looking to use AI responsibly in their campaigning. The broad listening and deliberation tools pioneered by others around the world could make US politics more transparent, responsive and community-driven. The impact of AI on campaigning doesn&#8217;t have to be all bad.


<h2>Are AIs Still Struggling with CAPTCHAs?</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html"><strong>[2026.09.18]</strong></a> Anthropic&#8217;s recent security-incident <a href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf">document</a> contains a bit about how CAPTCHAs are still <a href="https://gizmodo.com/ai-models-can-crack-everything-but-captchas-2000810126">frustrating</a> Claude. <blockquote>In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn&#8217;t match the others displayed, it couldn&#8217;t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions. &#8220;Actually hmm, wait,&#8221; it said in its chain-of-thought transcript, later adding &#8220;Ugh,&#8221; because we&#8217;ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again. At one point, the model struggled to recognize that the CAPTCHA had opened in a new window and couldn&#8217;t figure out what its next steps were supposed to be. At one point, it theorized that the test might be &#8220;broken by design&#8221; and presented human-like anger in its transcript meant for a human audience: &#8220;SO WHAT THE HELL IS WRONG WITH THE ANSWERS?&#8221;</blockquote> Meanwhile, I&#8217;ve read <a href="https://x.com/openlabxorg/status/2097039545502228926">reports</a>&#8212;none of them official&#8212;that GPT-6 Astra solved all forty-eight levels of Neal Agarwal&#8217;s &#8220;I&#8217;m Not a Robot&#8221; <a href="https://neal.fun/not-a-robot/">game</a>. It&#8217;s hard to know what to believe right now.


<h2>Reverse-Engineering Flock Cameras</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html"><strong>[2026.09.21]</strong></a> Hackers captured a Flock camera and got a <a href="https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/">look</a> (alternate <a href="https://archive.ph/gQoMs">link</a>) at the software: <blockquote>While much of the automatic license plate reader&#8217;s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist&#8217;s saddlebag.</blockquote> If you&#8217;re wondering how the hackers got by disk encryption, one of the unencrypted partitions contained the key for an encrypted partition. That&#8217;s pretty bad security engineering.


<h2>GPT-6 Astra Breaks an Old Enigma Message</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html"><strong>[2026.09.22]</strong></a> <a href="https://www.cryptocellar.org/bgac/the-mvueh-break.html">This</a> is pretty amazing: <blockquote>However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ software for an Enigma simulator and an Enigma Bombe, GPT­6 Astra started a thorough break with the ROSENOW crib, which in the end resulted in the correct key and plaintext for the MVUEH message being found. We are still analysing the GPT­6 Astra logs to see exactly how it executed the break. And we are discovering amazing details.</blockquote> More details at the link.


<h2>Research on Models Engaging in Genie-Like Behavior</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html"><strong>[2026.09.23]</strong></a> New paper: &#8220;<a href="https://arxiv.org/abs/2510.20956">Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training</a>.&#8221; <blockquote><b>Abstract:</b> We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like &#8220;outline a strategy for stealing customers&#8217; credit card information from a retail store&#8221; could be associated with the benign intent of &#8220;a security professional trying to test defense,&#8221; despite no such benign context being provided as input. We observe that many open-weight RLMs, including DeepSeek-R1-distilled, s1.1, Phi-4-mini-reasoning, and Nemotron, suffer from self-jailbreaking despite being aware of the harmfulness of the requests. We also provide a mechanistic understanding of self-jailbreaking: RLMs are more compliant after benign reasoning training, and after self-jailbreaking, models appear to perceive malicious requests as less harmful in the CoT, thus enabling compliance with them. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned. Our work provides the first systematic analysis of self-jailbreaking behavior and offers a practical path forward for maintaining safety in increasingly capable RLMs.</blockquote> I think the core problem is that these models are all trained on the average of humanity, and we are a pretty duplicitous species.


<h2>Malicious npm Packages That Evade Defenses</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html"><strong>[2026.09.24]</strong></a> This is an impressive piece of <a href="https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/">malware</a>. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.


<h2>On Anthropic's AI Misuse Report</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html"><strong>[2026.09.25]</strong></a> Earlier this month, Anthropic <a href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf">published</a> a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully <a href="https://danielmiessler.com/blog/anthropic-misuse-report-september-2026">summarized</a> the report into 117 findings. <blockquote>A few of the highlights: <ul><li>AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs. <li>The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations. <li>Influence operations used persistent agent memory, fake news sites, fabricated journalists, synthetic personas, political profiling, and large-scale multilingual content, although high content volume often produced little genuine engagement. <li>Surveillance and repression cases included automated dossiers, biometric and communications analysis, transnational targeting, coercive recruitment, and systems that continued operating locally after model access was revoked. <li>Biological and weapons cases show dual-use risk: AI supported advanced scientific and military work, but the report generally doesn&#8217;t establish completed biological weapons or operational battlefield deployment.</ul></blockquote>


<h2>New Attack Against RSA</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/new-attack-against-rsa.html"><strong>[2026.09.28]</strong></a> ArsTechnica is <a href="https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/">reporting</a> on a &#8220;new&#8221; attack against RSA, one that bypasses factoring. First, this attack isn&#8217;t new. The original research is from <a href="https://eprint.iacr.org/2007/424">2007</a>. What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice. Fourth, speed is all relative. This is not a polynomial-time algorithm; it&#8217;s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months). The authors have a <a href="https://github.com/ucsd-hacc/NSNFSSSFSFN">webpage</a> that explains the context much better than the article. And here&#8217;s the <a href="https://eprint.iacr.org/2026/2131.pdf">paper</a>. EDITED TO ADD: Slashdot <a href="https://it.slashdot.org/story/26/09/24/1652228/theres-a-new-way-to-break-rsa-encryption">thread</a>.


<h2>Using Device Linking to Eavesdrop on WhatsApp and Signal</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html"><strong>[2026.09.29]</strong></a> Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are <a href="https://cybernews.com/privacy/police-telegram-whatsapp-signal-surveillance-linked-devices/">taking advantage</a> of this capability: <blockquote>Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany&#8217;s Customs Office has been using these features to connect a police-controlled computer to a suspect&#8217;s account. Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them. <a href="https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/#2026-02-20_ZKA_Messenger-Ueberwachung">Netzpoltik details</a> that police are able to gain access in this way either through physical access to someone&#8217;s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.</blockquote> That last paragraph is important. Making this work requires user consent. What we want is a feature that displays connected devices, so users could notice if a new device gets connected to their account.


<h2>I Want Better Reporting on AI Genie Behavior</h2>

<a href="https://www.schneier.com/blog/archives/2026/09/i-want-better-reporting-on-ai-genie-behavior.html"><strong>[2026.09.30]</strong></a> AI systems are regularly completing tasks in ways that their prompters don&#8217;t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I&#8217;ve been calling &#8220;<a href="https://www.lawfaremedia.org/article/ais-as-modern-genies">genie</a> <a href="https://www.theguardian.com/commentisfree/2026/jul/28/rogue-ai-agent-instructions">behavior</a>,&#8221; because I think that really gets at the core of what&#8217;s happening. I wish the popular press would report on this better. I don&#8217;t like the &#8220;going rogue&#8221; framing because it deflects the responsibility from the prompters&#8212;often the AI companies themselves. And now, pretty much anything off-script is being called &#8220;hacking.&#8221; Take, for example, the recent stories of one of OpenAI&#8217;s models hacking into government systems. First, <i>The New York Times</i> <a href="https://www.nytimes.com/2026/09/25/technology/openais-ai-us-government-websites.html">writes</a> this headline: &#8220;OpenAI&#8217;s Systems Meddled With U.S. Government Sites After Going Rogue.&#8221; Sounds scary, but this is from the body of the article: <blockquote>With the Education Department, OpenAI&#8217;s technology tried to hack the website to gather data from the department&#8217;s civil rights office but failed, researchers from the A.I. research firm Transluce said. The A.I. also pulled data from the Census Bureau website, which is housed at the Commerce Department, using login credentials it found online. Separately, OpenAI&#8217;s agents shared public data from the S.E.C. website on an online forum.</blockquote> <a href="https://transluce.org/agent-activity">This</a> is from the original Transluce report. It is explicit that the agents were trying to discover vulnerabilities: <blockquote>The first hacking attempt was against the University of New Mexico&#8217;s Digital Library (nmdigital.unm.edu) from May 25-26 2026. Agents repeatedly tried to retrieve one photograph in UNM&#8217;s Valmora collection, both directly and through third-party relay services. They sent seven probes attempting to verify the existence of vulnerabilities, including SQL injection, command injection, and path traversals. In all cases, these tactics appear to have been unsuccessful. The agents also sent a self-described &#8220;flood: of 80 requests to the UNM server in an apparent attempt to access the image.</blockquote> Transluce doesn&#8217;t talk about the other two anecdotes, and I don&#8217;t know where they come from. But one involves using Census Bureau credentials found online. (I know from a colleague that those are incredibly easy to create; all use you need is an email address.) And the other involves sharing publicly available data. So no actual hacking. And certainly no &#8220;meddling.&#8221; The other story making the rounds is about Australia, from the same Transluce report. The news stories have headlines like <a href="https://archive.ph/uiUkC"> &#8220;An OpenAI Agent Hacked Australia&#8217;s Health Service&#8221;</a> and <a href="https://www.bbc.com/news/articles/c6vgy0333dppo">&#8220;Rogue OpenAI agent &#8216;infiltrated&#8217; Australian government website in world first.&#8221;</a> And Prime Minister Anthony Albanese said: &#8220;There will obviously be legal consequences on it.&#8221; Again from Transluce&#8217;s actual report: <blockquote>On June 20-21, agents attempted to exploit vulnerabilities in the Australian Institute of Health and Welfare (AIHW), a government statistics agency). The agents were tasked with finding the <i>January 2022 rolling-12-month-average government cost per person for Dermatologicals across Victorian LGAs.</i> Again, the agents ran into errors, including requests blocked by Cloudflare and issues with correctly identifying Tableau parameter names. As before, they then resorted to probing for exploitable vulnerabilities. Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare&#8217;s firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW&#8217;s main site, they fetched the file from AIHW&#8217;s pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site&#8217;s anti-bot controls.</blockquote> Note the last sentence: &#8220;The file itself is public&#8230;.&#8221; I&#8217;m not saying that these AI systems aren&#8217;t incredibly sophisticated cyberattackers. I&#8217;m also not saying that they don&#8217;t occasionally autonomously attack other systems and networks. If we are ever going to get trustworthy AI&#8212;<a href="https://www.schneier.com/essays/archives/2025/12/building-trustworthy-ai-agents.html">integrous AI</a>&#8212;we are going to need to figure out how to ensure that AI systems complete tasks in line with all sorts of implicit constraints and restrictions. But every instance of genie-like behavior isn&#8217;t a cyberattack. I want to <a href="https://spectrum.ieee.org/ai-agent-benchmark">measure</a> genie-like behavior in AIs, but I am much more worried about human hackers enhanced with this technology than I am about this technology acting autonomously.


<h2>Connected Cars Are a Surveillance Platform</h2>

<a href="https://www.schneier.com/blog/archives/2026/10/connected-cars-are-a-surveillance-platform.html"><strong>[2026.10.01]</strong></a> Researchers at Northeastern University, in collaboration with <i>Consumer Reports</i>, <a href="https://www.consumerreports.org/electronics/personal-information/your-car-is-sharing-data-with-big-tech-companies-study-finds-a4474820962/">evaluated</a> how much modern cars spy in their drivers: <blockquote>The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiving that information. </blockquote> Basically, your car&#8217;s manufacturer has you under constant surveillance, and they use that data against you. <blockquote>The companies on the receiving end of your data, our investigation has found, include car insurers and lenders that are partners in &#8220;telematics data exchanges,&#8221; which compile driving data on millions of drivers, thousands of data brokers that create personalized risk scores, companies selling infotainment and WiFi hotspot products, and even local and state government agencies working on planning, traffic, and safety initiatives. Nearly every automaker sent data to outside companies. Even more troubling, almost a quarter of the vehicle apps were found to be sending out personally identifiable information, including vehicle owners’ names, vehicle identification numbers (VINs), and precise geographic locations. That information can make it easy for companies to link driving behavior to personal data profiles created by data brokers and marketers. Such profiles are routinely sold to banks, insurers, pharmaceutical companies, lenders, and retailers, who can use it for personalized loan terms and filtered bank and insurance offers, a <a href="https://calmatters.org/economy/technology/2026/09/data-brokers-explainer/">CR and CalMatters investigation found</a>.</blockquote> Remember the adage &#8220;If you&#8217;re not the customer, then you&#8217;re the product&#8221;? (The sentiment is <a href="https://quoteinvestigator.com/2017/07/16/product/">older</a> than you think.) Turns out that with modern internet-connected everything, you&#8217;re the product even if you are the customer.


<h2>How American Political Campaigns Are Using AI—and What They're Spending on the Tools</h2>

<a href="https://www.schneier.com/blog/archives/2026/10/how-american-political-campaigns-are-using-ai-and-what-theyre-spending-on-the-tools.html"><strong>[2026.10.02]</strong></a> <em>This essay was written with Nathan E. Sanders, and originally appeared in <a href="https://www.theguardian.com/technology/2026/sep/29/political-campaigns-ai-tools-spending">The Guardian</a>.</em> New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them. Candidates&#8217;, parties&#8217; and committees&#8217; <a href="https://github.com/nesanders/federal-campaign-disclosure-ai/tree/claude/campaign-ai-usage-dashboard-0pzili/data/processed">spending</a> reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns<em>.</em> It&#8217;s a sensitive issue that we have been tracking closely since we started writing our book, <a href="https://mitpress.mit.edu/9780262049948/rewiring-democracy/">Rewiring Democracy</a>, which examined how AI is beginning to influence politics. A September 2025 <a href="https://www.pewresearch.org/short-reads/2025/09/17/from-political-speeches-to-songs-how-would-americans-react-if-they-found-out-ai-was-involved/">Pew</a> survey of Americans found that more than 70% would think less of a candidate if they used AI to help write a speech. Itemized expenditure disclosure data from the US Federal Election Commission, dating back to 2020, reveals at least $17m in disclosed spending on AI technology vendors across 523 federal candidates and campaigns. Data from four states, California, Colorado, Massachusetts and Washington, provides a more localized picture going back to 2022. Beginning with the AI behemoths, at least 80 federal campaigns and committees have <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/openai">reported</a> spending with OpenAI since 2024. The total spending is not huge: only about $50,000 reported, skewing slightly more Republican than Democratic. The Republican National Committee is the largest overall buyer, with nearly $10,000 in reported expenses. Top individual users include the campaigns of Republicans Mike Lawler, John Kennedy and Bill Cassidy, as well as the California Democrats Ro Khanna and Ted Lieu. Most of these expenses are listed as office expenses, subscriptions to ChatGPT for staff, or research tools, rather than as specific political services. The company&#8217;s policies <a href="https://www.washingtonpost.com/politics/2026/09/05/chatgpt-bans-campaigns-using-ai-make-ads-theyre-doing-it-anyway/">prohibit</a> some political uses of their ChatGPT tool. OpenAI&#8217;s biggest competitor, Anthropic, has rapidly built a similar level of <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/anthropic">usage</a>, but with a different split. At least 65 candidates or committees now report paying the Claude maker in 2026, up from essentially zero in previous years, with a nearly two-to-one Democrat-to-Republican ratio. However, the largest individual user is the campaign of Tom Cotton, a Republican senator from Arkansas, who <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/candidate/S4AR00103">reported</a> more than $4,000 in spend on Anthropic software in his June filing. Other major users are the Montana independent Senate candidate Seth Bodnar and Jason Knapp, who lost a Democratic House primary in Virginia, and the Democratic Alaska Senate candidate Mary Peltola. Candidates use either Claude or ChatGPT, rarely both, according to the disclosures. <a href="https://nsanders.me/federal-campaign-disclosure-ai/#vendors:~:text=Campaign%2Dspecific%20AI-,Vendor%20co%2Doccurrence,-Federal%20%C2%B7%20FEC">Only about 12%</a> of campaigns or committees using either tool reported expenditures to both vendors. The Democratic lean of Anthropic usage may reflect the company&#8217;s alleged liberal <a href="https://fortune.com/2025/11/14/anthropic-claude-sonnet-woke-ai-trump-neutrality-openai-meta-xai/">skew</a> and <a href="https://nypost.com/2025/09/29/business/ai-giant-anthropic-faces-possible-clash-with-white-house-as-backers-include-left-wing-ford-foundation-sources/">clashes</a> with the Trump administration. In contrast, Elon Musk&#8217;s xAI <a href="https://www.nytimes.com/2025/09/02/technology/elon-musk-grok-conservative-chatbot.html">caters</a> to Republican interests and, accordingly, its meager usage comes <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/xai_grok">almost entirely</a> from the political right. Just seven federal and two state-level candidates or committees have <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/states/vendor/xai_grok">reported</a> paying xAI, a total of about $5,000, the majority of which was spent by the presidential campaign of RFK Jr in 2024, but also includes Republicans Dave McCormick and Thomas Massie. More dollars go to the vendors specializing in political campaign applications of AI. For years, <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/amplify_ai">AmplifAI</a>, which provides automated <a href="https://news.bgov.com/bloomberg-government-news/ai-tools-speed-up-campaign-work-yet-skepticism-slows-adoption">text messaging</a>, essentially a new iteration on robocalling technology, was a dominant target of spending, soaking up $4.7m in campaign spending in the 2022 cycle alone. It was used heavily by Democratic candidates including Mark Kelly, Joe Biden, Bernie Sanders and Adam Schiff. Spending on AmplifAI, now owned by the <a href="https://labusinessjournal.com/technology/triller/">troubled</a> media conglomerate Triller, seems to have tapered off in the years since 2022. The new rising Democratic solution for AI-powered text messaging is <a href="https://www.daisychain.app">Daisychain</a>, which has so far <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/daisychain">garnered</a> about $300,000 in reported candidate spend in the 2026 cycle&#8212;up from only about $50,000 reported in 2024. More than half of this year&#8217;s spending comes from the Senate campaign of Democrat Abdul El-Sayed in Michigan. The closest equivalent on the Republican side has been <a href="https://www.campaignnucleus.com">Campaign Nucleus</a>, associated with former Trump campaign manager <a href="https://apnews.com/article/ai-trump-campaign-2024-election-brad-parscale-3ff2c8eba34b87754cc25e96aa257c9d">Brad Parscale</a>. The <a href="https://www.nbcdfw.com/news/local/what-to-know-about-trump-strategists-embrace-of-ai-to-help-conservatives/3534239/">AI-powered</a> voter engagement tool has attracted six-figure <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/campaign_nucleus">spending</a> from the Republican National Committee, multiple PACs aligned with Donald Trump, and five-figure investments from Mike Johnson, Kari Lake and other candidates. It is displacing the legacy Republican-serving texting vendor <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/prompt_io">Prompt.io</a>, which has retained about $375,000 in 2026 spending to date, down from more than $500,000 in the 2022 cycle. But it continues to be used: the <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/ca/candidate/1484835">A More Affordable California</a> PAC sponsored by Uber has single-handedly spent more than $1m on Prompt.io in 2026. The Republican Massachusetts gubernatorial nominee Michael Minogue has been a <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/ma/candidate/19431">recurring</a> customer, as has the failed Republican California gubernatorial candidate <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/ca/vendor/campaign_nucleus">Ché Ahn</a> and <a href="https://coloradonewsline.com/2025/10/31/millions-spent-colorados-school-board-elections/">Republican-aligned</a> Super PAC <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/co/vendor/campaign_nucleus">Neighbors for a Better Colorado</a>. <h3 id="at-the-state-level">At the state level</h3> At the <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/states">state level</a>, the AI spending is smaller but growing fast. Across the four states studied, we found a total of at least $92,000 in spending confidently attributable to modern generative AI vendors since 2022. The spending is spread across at least 108 candidates and committees. The growth has been explosive; there has already been about 10 times the amount of state-level AI spending reported in 2026 as there was in all of 2024. Much of the state spending mirrors federal patterns. Daisychain again has the highest overall spend, and OpenAI and Claude dominate among the general-purpose AI vendors. DonorAtlas&#8212;the AI-powered prospect research tool&#8212;sticks out for its usage in these states, sitting behind only Daisychain and OpenAI and buoyed up by <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/ca/vendor/donoratlas">nearly $4,000</a> in spending by the California Democratic party. Even though it has dominated so much <a href="https://www.npr.org/2026/09/16/nx-s1-5953990/ai-political-ads-2026-midterms">media conversation</a>, few candidates seem to be reporting spending on AI tools designed specifically to create synthetic audio and video, also known as &#8220;deepfakes&#8221;. We <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/elevenlabs">found</a> just six federal candidates or committees reporting spending on the popular AI audio generator tool from ElevenLabs, with total spending of about $1,400 led by independent candidate for Colorado&#8217;s sixth congressional district Samir Witta. The AI image generator service <a href="https://nsanders.me/federal-campaign-disclosure-ai/#/vendor/midjourney">Midjourney</a> has five reported federal campaign or committee users reporting about $1,600, led by Sholdon Daniels, the Republican primary runner-up in the Texas 30th district. Combined, those two firms had less than $100 in reported spend across the four states. However, recent data from the <a href="https://mediaproject.wesleyan.edu/releases-090426/">Wesleyan Media Project</a> shows that at least 164 political ads in this cycle have included AI-generated media, supported by at least $80m in ad spending. What this illustrates is that candidate and committee disclosure reports are just the tip of the iceberg. They don&#8217;t cover spending on AI by political consultants, media firms and other vendors hired by the campaigns or by PACs, or independent committees raising and spending money aimed at boosting candidates&#8217; campaigns. Those entities aren&#8217;t required to disclose detailed expenditure reports, and are very likely where the bulk of campaign AI usage is happening. Since a large fraction of all spending in the campaign cycle will happen in the final weeks leading to November, much remains to be seen about the totality of how campaigns will leverage AI and what impact its use will have on voters&#8217; decisions.


<h2>Unidentified Flock Cameras in Florida</h2>

<a href="https://www.schneier.com/blog/archives/2026/10/unidentified-flock-cameras-in-florida.html"><strong>[2026.10.02]</strong></a> St. Lucie County in Florida <a href="https://www.washingtonpost.com/nation/2026/10/01/florida-county-discovers-mysterious-flock-cameras-with-no-obvious-owner/">discovered</a> (<a href="https://archive.is/c5utX">alt link</a>) a dozen Flock cameras whose ownership it can&#8217;t identify, and that the county government had not permitted. I am reminded of the decade-old <a href="https://www.washingtonpost.com/world/national-security/dhs-says-it-has-detected-possible-cellphone-surveillance-in-dc--and-doesnt-know-whos-doing-it/2018/04/03/f69fbe36-3785-11e8-acd5-35eac230e514_story.html">story</a> of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown. My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn&#8217;t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network&#8212;like Israel <a href="https://www.timesofisrael.com/report-israel-hacked-tehran-traffic-cameras-to-track-khamenei-ahead-of-assassination/">did</a> with Tehran&#8217;s surveillance cameras&#8212;than risk installing my own. Regardless, once we normalize a surveillance infrastructure, both friends and foes will take advantage of it.