<h2>Cybersecurity and the Gap Between Skill and Ability</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/cybersecurity-and-the-gap-between-skill-and-ability.html"><strong>[2026.07.08]</strong></a> Last week, national security agencies from the Five Eyes&#8212;that&#8217;s the rich, English-language-speaking countries club&#8212;jointly released a <a href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/">statement</a> warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and networks. The statement was more measured than some of the <a href="https://www.theguardian.com/technology/2026/jun/22/anthropic-claude-fable-ai-model-artificial-intelligence-national-security">breathless headlines</a> about it, and the advice they gave is pretty much the standard advice everyone gives&#8212;albeit with newfound urgency. Internet risks are nothing new, and cyberattacks&#8212;both large and small&#8212;have been a significant issue since long before the current crop of generative AI models. What&#8217;s been changing over the decades, and what AI is changing even faster, is the gap between skill and ability. For most of human history, the two terms were synonymous&#8212;but computers have decoupled them. As the gap between the two expands, humans empowered with these AI tools can do more: more writing, more research, more analysis and also more damage than ever before. These models can, with little detailed direction, autonomously hack into networks, steal data, deploy ransomware and destroy systems. And to the extent there is a solution, it&#8217;s going to involve harnessing AI for the defense. In 1998, seven people from the hacker group L0pht <a href="https://www.washingtonpost.com/sf/business/2015/06/22/net-of-insecurity-part-3/">testified</a> <a href="https://www.veracode.com/blog/25-years-later-reflecting-on-l0phts-1998-congress-testimonial-and-the-evolution-of-cybersecurity/">before</a> <a href="https://www.youtube.com/watch?v=VVJldn_MmMY">Congress</a>. They told a mostly clueless Senate committee that they could take down the internet in 30 minutes. That was partly real and partly bravado, but it illustrates an important point: hacking into systems, stealing data and causing damage all required skill. Contrast the L0pht hackers with hackers derided as &#8220;script kiddies.&#8221; They didn&#8217;t understand computers, or security. Instead, they used hacker tools written by others. Their actions required minimal skill and even less knowledge. But once those hacking tools became widespread, the number of potential attackers increased. That number has continued to increase, as quality and availability of prewritten attack tools has grown. And it is growing dramatically with AI. Today&#8217;s AI systems&#8212;not just the frontier models, but most of them&#8212;are capable of carrying out cyberattacks automatically. They all do better in the hands of skilled attackers, but increasingly they are able to act autonomously with only minimal prompting. The thing about people with ability but no skill is that they are often outsiders, not part of any professional community, and not bound by any rules or norms. This phenomenon is much more general than in cybersecurity. Any doctor can tell you how to untraceably poison someone, and many virus researchers know how to create a bioweapon. Any bridge engineer can tell you how to place explosives to blow a bridge up. The reason that murderous doctors and terrorist engineers are so rare is that the lengthy process of acquiring those skills also instills a moral and ethical code. If every random person has access to good poisoning advice, that puts us all in danger. Modern AI systems are, in effect, a universal adviser to help people do harmful things. And while the current AI megacorporations are trying to build guardrails to prevent people from asking questions whose answers will enable the questioner to do harm, that&#8217;s not going to work in the long term. Smaller, cheaper, open-source models, including models that can run on people&#8217;s computers, and especially groups of models that run in concert with each other, are just as good as the frontier models from companies like OpenAI and Anthropic. And they continue to get better. These models will be passed around from person to person, like script kiddie hacker tools, and they won&#8217;t have any such guardrails. Instructing AI models to spy on people and report any malicious prompts to the authorities fails for similar reasons. The megacorporations can do that, but the locally run open source models won&#8217;t. This could buy us a few months at best. A third possibility is to somehow make the models themselves unable to hack into computers, create bioweapons or do anything else that might harm people or society. That won&#8217;t work, for the same reason we can&#8217;t teach doctors how to treat poisonings without also teaching them how to poison. It&#8217;s the same knowledge. It&#8217;s the same with construction and demolition. And it&#8217;s the same with cybersecurity. We want these AI models to be able to review computer code, find vulnerabilities and automatically fix them. The benefit to our collective security will be enormous. Unfortunately, the same knowledge can be used for attacks. Where this leaves us is in a world of increased volatility. Super-powered humans with AI assistants will be able to do both wonderful and horrible things. This brings us back to the Five Eyes statement. Everything they recommend is something security professionals have been recommending for years, if not decades. They are things talked about at that congressional hearing back in 1998, titled &#8220;Weak computer security in government: Is the public at risk?&#8221; Even the Five Eyes admitted that their security advice is not new, only more urgent. What&#8217;s new is how fast things are changing: &#8220;The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.&#8221; The Five Eyes point to AI technology&#8212;not necessarily chatbots, but AI more generally&#8212;being used to strengthen every aspect of defense, to &#8220;detect vulnerabilities earlier, improve software quality, monitor unusual behavior, and respond faster to incidents&#8212;reducing both the cost and impact of incidents.&#8221; Excellent advice from the Five Eyes security agencies. We need to do this with every risk that AI heightens, not just cybersecurity. <em>This essay was originally published in <a href="https://www.theguardian.com/commentisfree/2026/jun/29/cyber-attacks-ai">The Guardian</a>.</em>


<h2>The Language of AI Could Change How Humans Speak</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/the-language-of-ai-could-change-how-humans-speak.html"><strong>[2026.07.09]</strong></a> Because of the way they are trained, large language models capture only a slice of human language. They&#8217;re trained on the written word, from textbooks to social media posts, and our speech as captured in movies and on television. These models have minimal access to the unscripted conversations we have face to face or voice to voice. This is the vast majority of speech, and a vital component of human culture. There&#8217;s a risk to this. The increased use of large language models means we humans will encounter much more AI-generated text. We humans, in turn, will begin to adopt the linguistic patterns and behaviors of these models. This will affect not just how we communicate with one another, but also how we <em>think</em> about ourselves and what goes on around us. Our sense of the world may become distorted in ways we have barely begun to comprehend. This will happen in many ways. One of the first effects we could see is in simple expression, much as texting and social media have resulted in us using shorter sentences, emojis instead of words, and much less punctuation. But with AI, the impacts may be more harmful, eroding courteousness and encouraging us to talk like bosses barking orders. A 2022 study found that children in households that used voice commands with tools like Siri and Alexa became curt when speaking with humans, often calling out &#8220;Hey, do X&#8221; and expecting obedience, especially from anyone whose voice resembled the default-female electronic voices. As we start to prompt chatbots and AI agents with more instructions, we may fall into the same habits. Next, in the same way autocomplete has increased how much we use the 1,000 most common words in our vocabulary, talking with chatbots and reading AI-generated text may further constrict our speech. A recent University of Coruña <a href="https://pubmed.ncbi.nlm.nih.gov/39328400/">study</a> found that machine-generated language has a narrower range of sentence length, averaging 12-20 words, and a narrower vocabulary than human speech. Machine-generated text reads as smooth and polished, but it loses the meanders, interruptions and leaps of logic that communicate emotion. Additionally, because large language models are primarily trained from written speech, they may not learn how to emulate the free-wheeling nature of live, natural speech. When told &#8220;I hate Beth!&#8221;, ChatGPT replies with an uninterruptable three-part formula of affirmation (&#8220;That&#8217;s completely valid&#8221;), invitation (&#8220;I&#8217;m here to listen&#8221;) and invitation (&#8220;What&#8217;s going on?&#8221;) far longer than any reply plausible in face-to-face dialog. &#8220;What&#8217;s Beth&#8217;s deal?!&#8221; elicits a bullet point list of queries that reads like a multiple-choice exam question (&#8220;Is Beth * a celebrity? * a friend from school? * a fictitious character?&#8221;). No human speaks that way, at least not yet. But meeting such formulas repeatedly in a speech-like context may teach us to accept and use them, much as a child absorbs new speech patterns from spending time with a new person. These influences will only increase with time. The writing large language models train on is increasingly produced by large language models themselves, creating a feedback loop in which they imitate their own inhuman patterns, even while teaching humans to imitate them too. Broad use of large language models could also introduce <a href="https://aclanthology.org/2025.findings-acl.195.pdf">confirmation bias</a>, making us overconfident in our initial impulses and less open to other possible ideas&#8212;which is so vital to human discourse. Many chatbots are instructed to agree with our statements no matter how absurd, enthusiastically supporting half-formed or even incorrect notions and restating them as firm claims that we&#8217;re primed to agree with. When asked &#8220;Cake is a healthy breakfast, right?&#8221; or &#8220;Is the post office plotting against me?&#8221;, this sycophancy <a href="https://www.article19.org/resources/algorithmic-people-pleasers-are-ai-chatbots-telling-you-what-you-want-to-hear/">can reinforce bias</a> and even worsen <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">psychosis</a>. And the hyperconfident tone of AI-produced writing will also heighten impostor syndrome, making our natural, healthy doubt feel like an aberration or failing. In our experience as teachers, students who turn to generative AI for assignments often say they do so because they have trouble expressing what they think. The students don&#8217;t recognize that writing or speaking our thoughts is often how we realize what we think. Their unconfident and uncertain statements are actually the healthy human norm. But a large language model won&#8217;t turn vague first guesses into a well-formed critical analysis, or even ask helpful questions as a friend would; it will simply regurgitate those guesses, still unexamined, but in confident language. We are also more vicious in social media posts and online chats than we are face to face. The <a href="https://www.sciencedirect.com/science/article/pii/S0306457325000214">well-documented</a> <a>online disinhibition effect</a> encourages toxic language. Most of us have had the experience of venting ferocious rage about someone online, only to reconcile when we speak face to face or hear the warmth of a voice over the phone. While chatbots are trained to give sycophantic responses, they see humankind at our cruelest, learning about us from the only world where every flame war leaves an eternal written footprint, while the spoken conversations of forgiveness and reconciliation fade away. Their responses do not imitate our online aggression, but are still shaped by it, even in their rigid efforts to avoid it. It&#8217;s easy to draw the wrong conclusions from a selective slice of a society&#8217;s communications. Medieval Norse sagas made us imagine a culture of mostly Viking warriors, since poets rarely described the farming majority. Chivalric romances focused on kings and courts, and long made us see the middle ages as a world of monarchies, erasing the many medieval republics. Statistically, we&#8217;ve been led to believe ancient Romans cared deeply about their republic, but 10% of all surviving Latin was written by one man, Cicero, whose work contains 70% of all surviving Roman uses of the word <em>republic</em>. Training language models on only certain human writings may introduce similar distortions. AI might make us seem more quarrelsome, as we are online. It might inflate the cultural significance of political topics primarily discussed on Twitter/X or Bluesky, or the massive topic-specific corpuses of LinkedIn and Goodreads. Some large language models are being trained on human speech from movies and television shows, but that speech is still scripted, and disproportionately highlights certain contexts over others (for example, police dramas, fueled by stories of murder, make up a <a href="https://www.researchgate.net/figure/Percent-of-Network-prime-time-programs-featuring-crime_fig1_267199589">quarter</a> of prime-time television programming). We are not funny or hurtful or romantic the same way in real life as we are in sitcoms. At least one <a href="https://www.zdnet.com/article/this-app-will-pay-you-30day-to-record-your-phone-calls-for-ai-but-is-it-worth-it/">startup</a> is offering to pay people to record their phone calls for AI-training purposes, but this remains a niche idea; anything large scale would cause massive privacy concerns. We don&#8217;t pretend to know what the best solutions might be. But one has to imagine if there&#8217;s ingenuity to develop AI models, then surely there&#8217;s ingenuity to come up with a way to train them on informal human speech instead of us only at our most stylized, veiled and sometimes worst. By excluding the overwhelming majority of language production on the planet&#8212;people talking, fully and naturally, to each other&#8212;these models are being trained to mirror everything but us at our most authentically human. <em>This essay was written with Ada Palmer, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/apr/14/ai-language-human-speech">The Guardian</a>.</em>


<h2>AI Surveillance and Social Progress</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/ai-surveillance-and-social-progress.html"><strong>[2026.07.10]</strong></a> In the near future, <a href="https://www.theguardian.com/technology/artificialintelligenceai">AI</a>-powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong&#8212;shoplift, litter, jaywalk, you name it&#8212;the system will notice, retain it, tie it to your official government record, communicate that fact to you, and provide real-time alerts to any relevant authorities&#8230; and maybe also to the general public. Think of these systems as automated speed cameras, but on steroids. Only they&#8217;ll enforce not just speed limits, but any other rule you can imagine. And you won&#8217;t receive a ticket weeks later by mail; you&#8217;ll be informed about and fined for your violation immediately. These systems will combine powerful AI, public and private surveillance via real-time facial recognition technology and digital tracking, mass databases and highly personalized enforcement. If deployed at scale, they will have profound chilling effects not just on personal freedoms, but democracy and social progress itself. China has been developing its surveillance infrastructure <a href="https://www.nytimes.com/2018/07/08/business/china-surveillance-technology.html">for years</a>. The country has over 600 million surveillance cameras, increasingly powered by AI and facial recognition to <a href="https://www.cnn.com/2025/12/04/china/china-ai-censorship-surveillance-report-intl-hnk">enforce</a> legal and social rules. Take the case of Lao Duan, a Chinese citizen <a href="https://www.npr.org/2018/10/31/662696776/what-its-like-to-be-on-the-blacklist-in-chinas-new-social-credit-system">blacklisted</a> by the system after he lost his job and was unable to repay a series of loans. When he visited Beijing, the city&#8217;s AI surveillance system identified him by his face at a major intersection and displayed his face, name and citizen ID number on a large electronic billboard nearby with a message that he was an untrustworthy person. Similar systems are now being <a href="https://www.visiontimes.com/2026/05/05/chinas-cameras-catch-minor-offenses-but-miss-missing-persons-french-report-says.html">deployed</a> across China and integrated with its infamous online <a href="https://www.cnn.com/2025/12/04/china/china-ai-censorship-surveillance-report-intl-hnk">monitoring, censorship</a> and <a href="https://time.com/collections/davos-2019/5502592/china-social-credit-score/">social credit</a> systems. AI surveillance is <a href="https://www.lemonde.fr/en/pixels/article/2025/09/01/the-discreet-rise-of-facial-recognition-around-the-world_6744911_13.html">now</a> being experimented with in <a href="https://www.motherjones.com/politics/2025/04/clearview-ai-immigration-ice-fbi-surveillance-facial-recognition-hoan-ton-that-hal-lambert-trump/">North America</a>, <a href="https://www.alsur.lat/sites/default/files/2025-11/Facial%20recognition%20and%20surveillance-1.pdf">South America</a>, <a href="https://www.lemonde.fr/en/pixels/article/2025/09/01/the-discreet-rise-of-facial-recognition-around-the-world_6744911_13.html">Europe</a>, <a href="https://www.biometricupdate.com/202510/facial-recognition-strengthens-security-for-asias-expanding-rail-metro-sector-panel">Asia</a> and <a href="https://www.theafricareport.com/420018/facial-recognition-ai-driven-surveillance-how-china-is-exporting-its-toolkit-to-africa/">Africa</a>. According to a new <a href="https://notechforice.com/wp-content/uploads/2026/06/Tech-Behind-ICE-Oligarchs-Immigration-Enforcement-and-the-Threat-to-Democracy.pdf">report</a>, the US Department of Homeland Security is rapidly increasing its use of AI-based surveillance, including facial recognition and the monitoring of social media accounts, to keep tabs on immigrants, dissidents, journalists, legal observers and protesters. While the systems are ostensibly used to maintain security and public safety, the real aim is often social control. Larry Ellison, CEO of Oracle&#8212;a powerful tech giant that works closely with the Trump administration&#8212;has <a href="https://www.theregister.com/software/2024/09/16/oracle-cloud-ai-will-enable-mass-surveillance-says-ellison/516672">said</a>: &#8220;Citizens will be on their best behavior because we&#8217;re constantly recording and reporting.&#8221; The chilling effects are the point. AI surveillance raises a range of public policy challenges: technical biases, unauditable systems, and inflexible automated law and social rule enforcement that can promote discrimination and undermine transparency, accountability and the rule of law. But we believe the most urgent and long-term impact will be its broader chilling effects. In a new book, <a href="https://www.cambridge.org/core/books/chilling-effects/22383D541B3BC45C9145E85DA4824E10#fndtn-metrics">Chilling Effects: Repression, Conformity, and Power in the Digital Age</a>, Jon Penney explains how surveillance, technology and power can be weaponized to influence behavior at scale. Surveillance, personalization, uncertainty and authority are all key mechanisms to increase the scale and impact of chilling effects. They cause people to self-censor their words and actions, to become more conformist and compliant and thus easier to manage and control. And the effects are additive: the more mechanisms employed, and the more powerful the form, the greater the chill. Computerization has long allowed data collectors to track our locations, collect lists of whom we communicate with, and monitor our spending habits&#8212;unless we use cash. What&#8217;s new is an unprecedented fusion of each of these mechanisms, persistent and unrelenting. AI brings an analytical ability <a href="https://slate.com/technology/2023/12/ai-mass-spying-internet-surveillance.html">to</a> <a href="https://www.schneier.com/wp-content/uploads/2026/01/Schneier-AI-and-Spying.pdf">spy</a> on the contents of our communications, and to answer sophisticated questions about our whereabouts and activities: actions that previously required human analysts are now automated. The result will be a kind of supercharged societal level of chilling effects where fear, self-censorship and groupthink reign, and dissent, creativity and innovation become increasingly rare. In this atmosphere of fear and conformity, risky ideas, social activism and self-reinvention&#8212;especially by disfavored groups and targeted populations&#8212;are also <a href="https://www.lgbtqnation.com/2026/01/publishers-are-stepping-back-from-lgbtq-books-amid-bans-the-current-gop-president/">chilled</a>. This will have long-term <a href="https://www.schneier.com/essays/archives/2018/11/surveillance_kills_f.html">effects</a> on social progress. Consider the relatively recent societal normalization of same-sex relationships and the recreational use of marijuana. Over the decades, those ideas slowly progressed from being both immoral and illegal, to moral but still illegal, and finally to both moral and legal. But in order for any of that to happen, there had to be a counterculture that was able to experiment and eventually demonstrate to the world that morality could change over time. To the extent that AI surveillance chills this sort of experimentation in public or in private, social progress becomes impossible. There are no real historical precursors to this; these technologies are too new. Even the most notorious and large-scale <a href="https://www.bbc.com/news/world-us-canada-48218827">domestic surveillance program</a> in US history, the FBI&#8217;s <a href="https://nsarchive.gwu.edu/briefing-book/intelligence/2020-06-25/spying-americans-new-release-infamous-huston-plan">use of</a> wiretapping, physical mail opening, informants and paper index cards to track alleged communists during the 1950s and 1960s, appears genuinely archaic in light of modern AI-enhanced surveillance. So does East Germany&#8217;s human-centric surveillance network during the cold war. Only science fiction, from the likes of George Orwell or Aldous Huxley, comes close. But even Big Brother&#8217;s &#8220;<a href="https://bookanalysis.com/1984/telescreen/">telescreen</a>&#8221; feels decidedly mid-20th-century by comparison. But we need not sit idly. Now that we recognize the danger of AI-enhanced mass surveillance, we can make the policy choices not to implement it. Bans on facial recognition and other forms of identification tech can slow development; robust new privacy and data protections can restrict data tracking and retention; AI regulations can curtail its most invasive uses; and structural reforms can help us scrutinize and break up powerful state/tech cartels that pave the way for technological excesses like AI surveillance. The chill of AI-powered mass surveillance will suffocate the very foundations of healthy democratic societies. But we can still choose a different path. <em>This essay was written with Jon Penney, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/jul/06/ai-surveillance-policy">The Guardian</a>.</em>


<h2>AI Data Centers and the Concentration of Wealth</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/ai-data-centers-and-the-concentration-of-wealth.html"><strong>[2026.07.13]</strong></a> <em>This essay was written with Nathan E. Sanders, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/jul/09/ai-datacenter-company-politics">The Guardian</a>.</em> Opposition to AI data centers has emerged as a primary theme in US politics, one that&#8212;surprisingly&#8212;doesn&#8217;t <a href="https://grist.org/politics/data-center-ai-bipartisan-backlash/">fall</a> <a href="https://www.nytimes.com/2026/05/01/us/politics/liberals-conservatives-data-centers.html">along</a> party lines. We applaud people coming together for constructive debate on any issue, and agree that communities need to evaluate whether any economic benefits these data centers bring is worth their costs. Still, we worry that a focus on data centers obscures the larger impacts of AI on people&#8217;s lives: the concentration of power of AI companies, and their widespread political and financial influence. Local data center opposition is grounded in legitimate concerns about misallocation of land resources when housing is at a premium, <a href="https://www.consumerreports.org/data-centers/ai-data-centers-impact-on-electric-bills-water-and-more-a1040338678/">pressures</a> on already higher energy prices, and localized environmental impact. Unlike other resource-consuming and polluting industrial facilities, data centers produce very few <a href="https://www.brookings.edu/articles/new-evidence-on-data-center-employment-effects/">jobs</a>. The fact that US opposition to data centers seems to be most <a href="https://www.bloodinthemachine.com/p/working-class-neighborhoods-are-resisting">fierce</a> among lower-income communities reflects righteous indignation with an inequitable bargain, where tech companies and developers profit from exploiting local resources but offer <a href="https://www.businessinsider.com/data-centers-tax-subsidies-jobs-ohio-2025-5">little</a> in return. On a global scale, their <a href="https://www.technologyreview.com/2025/05/20/1116327/ai-energy-usage-climate-footprint-big-tech/">carbon footprint</a> could grow unsustainably if usage accelerates. And all this is in aid of a technology that many fear will propagate misinformation, take their jobs, or even cause existential risks for humanity. For some, data center opposition may feel like the only tangible mechanism for registering their concern, disapproval, or even anger about AI. The problem is that this may be exactly what the AI companies are banking on. They can overcome the protest when it matters to them, and live with a significant fraction of proposals being defeated. More importantly, focusing political opponents on the data center issue obscures the bigger prize they&#8217;re after. While there is a staggering <a href="https://about.bnef.com/insights/data-centers/ai-data-center-build-advances-at-full-speed-five-things-to-know/">three-quarters of a trillion dollars</a> being spent on data center infrastructure by US companies this year alone, this investment should be taken in <a href="https://www.deloitte.com/us/en/insights/industry/technology/technology-media-telecom-outlooks/hardware-consumer-tech-outlook.html">perspective</a>. The market for enterprise software, for example, is about twice this size. And it&#8217;s small compared with what these companies actually want. AI companies have their eyes set on capturing <a href="https://www.businessinsider.com/microsoft-ceo-warns-ai-winners-hurt-whole-industries-satya-nadella-2026-6">all</a> the value created by entire industries. The technology has arguably already conquered customer service and consumer sales. But on the horizon are bigger targets, such as enterprise software development, creative design, management and even legal services. In AI companies and their allies&#8217; vision of the future, AI replaces <a href="https://www.nbcnews.com/tech/tech-news/melania-trump-robot-humanoid-robot-white-house-video-rcna265192">teachers</a> and <a href="https://www.washingtonpost.com/technology/2026/06/04/inside-trump-backed-push-bring-ai-doctors-into-american-medicine/">doctors</a>. The companies would rather spend time fighting resistance to how fast they are building computing infrastructure than dealing with issues of how their products should be used in those fields, or how those fields should be protected from their products. And while data center opposition campaigns have been successful in building widespread <a href="https://news.gallup.com/poll/709772/americans-oppose-data-centers-area.aspx">appeal</a>, their effectiveness in the US is mixed. They seem to be most successful when organizing against <a href="https://newsletter.semianalysis.com/p/stop-saying-half-of-2026-us-datacenter">speculative</a>, early-stage data center proposals that have a relatively low likelihood to ever see fruition. Meanwhile, advanced-stage, well-capitalized data center projects have proven to have the resources to overcome local opposition. An OpenAI- and Oracle-backed facility in Saline township, Michigan, is <a href="https://www.detroitnews.com/story/news/local/michigan/2026/06/01/openai-ceo-sam-altman-oracle-clay-magouyrk-visit-saline-township-data-center-site/90296951007/">breaking ground</a> on construction even after local officials voted to <a href="https://www.tomshardware.com/tech-industry/michigan-towns-rush-to-block-ai-data-centers-after-16-billion-stargate-project-overrode-local-opposition">reject</a> it. The developers sued the town of 3,000 and forced a <a href="https://salinetownship.org/uploads/notices/SalineDataCenterConsentJudgmentFinalExecutionCopy492124804975v1.pdf">settlement</a> that involved their project going forward. Meanwhile, the Trump administration, a vigorous <a href="https://www.theguardian.com/technology/2026/jun/08/trump-ai-growth-anthropic">ally</a> of corporate AI, has signaled its willingness to advance AI infrastructure development by <a href="https://www.cnn.com/2025/12/11/tech/ai-trump-states-executive-order">overriding</a> state objections and even using <a href="https://www.whitehouse.gov/fact-sheets/2025/07/fact-sheet-president-donald-j-trump-accelerates-federal-permitting-of-data-center-infrastructure/">federal lands</a>. Also consider that rampant data center development may be a momentary spike rather than a longstanding concern. Demand for the centralized computing that data centers provide may well decline over time. The leading Chinese labs, such as Z.ai, are <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">innovating</a> in technical mechanisms to make frontier-class models smaller and cheaper to run. AI power users have become <a href="https://unsloth.ai/docs/models/glm-5.2">adept</a> at miniaturizing open weight models, ones published free for anyone to download and use, to run locally on their own computers. <a href="https://arstechnica.com/information-technology/2024/04/apple-releases-eight-small-ai-language-models-aimed-at-on-device-use/">Apple</a> and <a href="https://developers.google.com/edge">Google</a> <a href="https://arstechnica.com/ai/2026/05/apple-reportedly-trying-to-distill-googles-multi-trillion-parameter-gemini-ai-to-run-on-iphone/">both</a> support infrastructure stacks for running AI models directly on mobile phones. It could be that the current mania for data centers will look like the <a href="https://internethistory.org/wp-content/uploads/2020/01/OSA_Boom.Bubble.Bust_Fiber.Optic_.Mania_.pdf">fiber optic cable bubble</a> from the early 2000s, as demand shifts to smaller models and AI usage on people&#8217;s own devices. For those concerned primarily with affordability and environmental protection, singling out data center construction is misplaced. Energy rates and inflation today seem to be most visibly <a href="https://www.nytimes.com/2026/06/25/business/inflation-iran-war-prices.html">affected</a> by the US-Iran war. The US is disinvesting in long-term energy security by <a href="https://www.theguardian.com/us-news/ng-interactive/2026/may/17/america-china-energy-oil-renewables">ceding</a> the renewable energy industry to China and actively <a href="https://www.politico.com/news/2025/11/05/the-us-led-the-world-to-reach-a-huge-climate-deal-then-it-switched-sides-pol-00636033">cancelling</a> climate commitments. Consider that 10% of global carbon emissions stem from heating buildings, which dwarfs <a href="https://www.iea.org/reports/energy-and-ai/energy-demand-from-ai">energy use</a> by AI and could be cut fivefold by using <a href="https://www.iea.org/reports/the-future-of-heat-pumps/executive-summary">heat pumps</a> powered by renewable energy. With respect to housing affordability, federal housing <a href="https://fred.stlouisfed.org/series/L312051A027NBEA">subsidies</a> have changed little over three decades, in inflation-adjusted terms, even as housing costs have spiked and homeowners have <a href="https://nlihc.org/resource/low-income-renters-receive-far-fewer-federal-supports-homeowners">enjoyed</a> robust tax incentives. As for AI itself, the concentration of power and wealth in these tech companies is the greatest existential risk facing society today. This means we must limit corporate power, especially corporations&#8217; ability to exploit the public and manipulate our political system. Opposing data centers should be just a starting point. We can advocate for states to <a href="https://gizmodo.com/against-the-federal-moratorium-on-state-level-regulation-of-ai-2000698390">regulate</a> AI, to reject irresponsible uses of the technology, and shape corporate behavior. We can fight for AI computation to be <a href="https://www.theguardian.com/commentisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">taxed</a>, so that the public can capture some of the profit of AI use while also forcing AI companies to internalize more of the energy and environmental consequences associated with its use. And we all can join the global <a href="https://publicai.network">movement</a> for <a href="https://www.brookings.edu/articles/how-public-ai-can-strengthen-democracy/">Public AI</a>, an alternative ecosystem for AI that is developed under public control with an incentive structure to create public benefit rather than private profit. The US midterm elections present ample opportunity for those seeking to control the AI political agenda. In the recent New York congressional Democratic primary, PACs linked to the <a href="https://apnews.com/article/bores-new-york-house-ai-tech-spending-5753274efbf9c3839fafa78f14e19fdc">dueling</a> AI companies Anthropic and OpenAI spent millions of dollars lobbying for or against &#8220;AI <a href="https://assembly.state.ny.us/mem/Alex-Bores/story/114363">safety</a>&#8220;, the idea that we must urgently monitor and prevent people from using AI to cause catastrophic harms. We&#8217;re already seeing a similar dynamic play out in races in <a href="https://massterlist.com/p/keller-on-states-rights-and-a-bizarre-ai-battle">Massachusetts</a> and other states. Why would Anthropic and OpenAI&#8212;bitter <a href="https://www.nytimes.com/2026/03/07/technology/openai-anthropic-pentagon-rivalry.html">industry rivals</a> but fundamentally on the same side politically&#8212;support opposing viewpoints? Because they both ultimately profit from the mystique: the idea that their products are so powerful that controlling those products is the world&#8217;s most important challenge. Here&#8217;s the typical read on the <a href="https://fortune.com/2026/06/26/anthropic-openai-ny12-proxy-war-no-winners-election-super-pac-donations/">dynamic</a>. To one side (backed by OpenAI affiliates), &#8220;safety&#8221; comes from the appearance of US industry dominating AI innovation, under the slow-moving control of federal lawmakers (and without pesky state regulators in the way). To the other side (backed by Anthropic), &#8220;safety&#8221; means a heavier regulatory framework that plays to Anthropic&#8217;s posturing as the ethics- and compliance-focused AI vendor. In both cases, it&#8217;s more <a href="https://www.theguardian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai">marketing</a> than principled concern about safety. Political organizers should call out and reject the AI companies&#8217; framing of the debate, and reorient campaign agendas around populist resistance to corporate concentration of wealth and power. When AI companies pump millions into legislative races, the result should not be hyperbolic discussion of AI superintelligence. And when a plot of land in a small town is pitched as a data center site, the debate should be about more than the local costs and benefits. It should include out-of-control money in politics, and <a href="https://www.brennancenter.org/our-work/research-reports/citizens-united-explained">Citizens United</a>-proof solutions to limit corporate influence like <a href="https://www.thenation.com/article/politics/super-pac-contributions-lawsuit-maine/">public financing</a> and <a href="https://www.americanprogress.org/article/the-corporate-power-reset-that-makes-citizens-united-irrelevant/">state regulation</a>. We all have a vested interest in what&#8217;s on the policy agenda, and what the outcomes are. Today, the greatest risk AI poses to society is the exacerbation of inequality and the concentration of wealth. The real problem is trillion-dollar AI companies and their trillionaire oligarchs cozying up to political power in Washington and governments worldwide, and using their money to enact their agenda over the popular will of the people. This is the issue we&#8217;d like to see put front and center, and it requires solutions much more extensive than slowing data center development.


<h2>Vulnerability in FIFA's Network</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/vulnerability-in-fifas-network.html"><strong>[2026.07.14]</strong></a> FIFA&#8217;s network was <a href="https://bobdahacker.com/blog/fifa-hack">vulnerable</a> to anyone with even minimal access.


<h2>Upcoming Speaking Engagements</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/upcoming-speaking-engagements-58.html"><strong>[2026.07.14]</strong></a> This is a current list of where and when I am scheduled to speak: <ul> <li>I’m speaking (virtually) at the <a href="https://pr2.technologypolicyworkshop.org/">Policy-Relevant Privacy Research Workshop</a> in Calgary, Canada, on Monday, July 20, 2026.</li> <li>I’m speaking at <a href="https://events.cyberriskcollaborative.com/boston-leadership-exchange-2026">Boston Leadership Exchange</a> in Boston, Massachusetts, USA, on Wednesday, July 22, 2026.</li> <li>I’m speaking at <a href="https://www.cognitivesecurityinstitute.org/cognitive-security-conference">Cognitive Security Conference</a> in Las Vegas, Nevada, USA. The conference runs August 6-7, 2026; my speaking time is TBD.</li> <li>I’m speaking at <a href="https://defcon.org/html/defcon-34/dc-34-index.html">DEF CON 34</a> in Las Vegas, Nevada, USA. The conventions runs August 6-9, 2026; my speaking time is TBD.</li> <li>I’m speaking at <a href="https://www.lacon.org/">LAcon V</a> in Anaheim, California, USA. The convention runs August 27-31, 2026, and my speaking time is TBD.</li> <li>I’m speaking at <a href="https://www.secwest.net/">CanSecWest 2026</a> in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.</li> </ul> The list is maintained on <a href="https://www.schneier.com/events/">this page</a>.


<h2>A Video Screen That Is Also a Camera</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/a-video-screen-that-is-also-a-camera.html"><strong>[2026.07.15]</strong></a> <a href="https://gizmodo.com/newly-invented-pixel-could-turn-screens-into-cameras-2000777917">Amazing</a>: <blockquote>Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel&#8217;s full potential for carrying information by manipulating light&#8217;s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.</blockquote> We are one step closer to <i>1984</i> technology: <blockquote>The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment.</blockquote> <a href="https://www.nature.com/articles/s41586-026-10681-7">Paper</a>.


<h2>Protecting Privacy in an AI Era</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/protecting-privacy-in-an-ai-era.html"><strong>[2026.07.16]</strong></a> Daniel Solove <a href="https://www.wsj.com/tech/cybersecurity/ai-privacy-laws-data-26d9769f">argues</a> in the <i>Wall Street Journal</i> (alternate <a href="https://archive.is/gEhP5">link</a>) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective. <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6985419">Paper</a>.


<h2>Details of Alan Turing's Voice Encryption System</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/details-of-alan-turings-voice-encryption-system.html"><strong>[2026.07.17]</strong></a> Really interesting piece of cryptographic <a href="https://spectrum.ieee.org/alan-turings-delilah">history</a>: <blockquote>In November 2023, a large cache of his wartime papers&#8212;nicknamed the &#8220;Bayley papers&#8221;&#8212;was <a href="https://www.bonhams.com/auction/28322/lot/45/turing-alan-the-delilah-project-the-papers-of-alan-turing-and-donald-bayley-relating-to-the-delilah-project/">auctioned</a> in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing&#8217;s own handwriting, telling of his top-secret &#8220;Delilah&#8221; engineering project from 1943 to 1945. Delilah was Turing&#8217;s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away.</blockquote>


<h2>On Flock License Plate Tracking Cameras</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/on-flock-license-plate-tracking-cameras.html"><strong>[2026.07.20]</strong></a> A recent story of a writer who was <a href="https://www.thedrive.com/news/how-flock-cameras-wrongly-tracked-me-for-days-over-stolen-plates-and-sent-police-after-me">mistakenly</a> identified, tracked, and arrested using data from Flock cameras has gone viral. <blockquote>The New Jersey plates that were allegedly stolen from the LA dealer were <b>34 03 DTM</b>, not <b>34 10 DTM</b>. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as <b>34 DTM</b>. Just the five large characters, no little number in the middle. And Flock’s AI tech wasn’t registering that non-standard little number when it began picking up the Range Rover around town. It just saw <b>34 DTM</b> in large type and started alerting the local police. As we all stood there shaking our heads, including my wife, who was finally allowed to join me, I connected the final dot. A lot of vehicles in JLR’s media fleet have a New Jersey manufacturer plate with the same alphanumeric structure­34 ## DTM­and Officer Ganshyn observed that meant it was now a nationwide issue. Anywhere a police department has a partnership with Flock, any other JLR-owned car with the same plate structure is going to get flagged as stolen. In fact, four other <b>34 ## DTM</b> cars were being tracked around Minnesota that week, according to Officer Ganshyn. I was just the first one to get nabbed. The only way to stop it would be for the LAPD to correct their initial report and update Flock’s system, which Jaguar Land Rover was now racing to make happen following the phone call.</blockquote> Flock has responded to the bad press. First, they <a href="https://www.thedrive.com/news/inside-the-flock-dragnet-how-systemic-errors-led-to-police-ambushing-me-for-no-reason">affirmed</a> that their systems were working correctly, and blamed the police: <blockquote>The obvious question was that Flock cameras were looking for 34 DTM, and the plate on the car I was driving was 34 10 DTM. Why was that flagged as a match? &#8220;The way that the ML [machine learning] works is it correctly read what it was supposed to read. It was fed those characters that you said, 34 DTM, and it spit back out [a result] with the characters, 34 DTM,&#8221; Thomas said. &#8220;It was asked, can you find this? And it did find that. It just didn’t say if there’s more here, then don’t do it. It just simply said, is it there? And the answer was yes.&#8221; He explained that even if the 10 was normal size, Flock would still have flagged it as a match, because that’s how they&#8217;ve set it up according to law enforcement’s requests. Sometimes partial plates are all they have to go on at first. &#8220;The way that law enforcement likes to use these tools is, if any of the characters that they have put into these hot lists get read, they want to get those alerts,&#8221; he said. &#8220;Now, what we try to train officers to do is to do what you said, which is to verify that 34 DTM is what I’m looking for, and what I’m seeing is 34 10 DTM.&#8221;</blockquote> Second, Flock&#8217;s CEO has <a href="https://gizmodo.com/flocks-ceo-is-sorry-for-calling-privacy-activists-terrorists-2000787247">apologized</a> for calling privacy advocates terrorists: <blockquote>The CEO of Flock Safety, the company that runs an enormous network of cameras used by police departments across the U.S., hasn&#8217;t been shy about taking on Flock&#8217;s critics. Last year, he even called one group that tracks the location of Flock cameras &#8220;terrorists.&#8221; But he&#8217;s had a change of heart. Or, at the very least, a change in PR strategy.</blockquote> Meanwhile, the police are <a href="https://www.404media.co/how-cops-use-flock-to-track-people-not-cars/">using</a> (alternate <a href="https://archive.ph/k4E8q">source</a>) the Flock camera network to track people in addition to cars: <blockquote>Police departments around the country have used Flock cameras at least hundreds of times to search for specific people, not cars, using searches such as &#8220;heavy-set male with a black and white hat,&#8221; &#8220;person on skateboard,&#8221; and &#8220;person wearing orange vest and construction hat,&#8221; according to data reviewed by 404 Media. Sometimes searches reference a target’s race or signs of their political affiliation. </blockquote> And, like all police surveillance technologies, there are <a href="https://www.cleveland.com/news/2026/07/ohio-audit-flags-unusual-police-database-searches.html">abuses</a>. EDITED TO ADD ( 7/30): <a href="https://www.thedrive.com/podcast/flocks-ceo-wants-zero-wrongful-stops-i-wasnt-the-first">Three</a> <a href="https://www.thedrive.com/news/flock-ceo-claims-its-cameras-arent-a-constitutional-violation-cut-and-dry">more</a> <a href="https://www.thedrive.com/news/flock-ceo-wants-its-cameras-in-every-one-of-americas-17000-cities">articles</a> about Flock from that first author.


<h2>MIT to Become Hotbed of AI Video Surveillance</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html"><strong>[2026.07.21]</strong></a> It&#8217;s <a href="https://thetech.com/2026/04/16/ai-surveillance-cameras">a lot</a>: <blockquote>According to information obtained by <i>The Tech</i>, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026. Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering. Individuals can also be automatically classified on the basis of clothing color, gender, and age, up to a distance of 35 feet (11 meters) from the camera. According to a statement from MIT spokesperson Kimberly Allen, any collected data is &#8220;retained up to 30 days,&#8221; unless an exception is granted. [&#8230;] Most of the new cameras, which are part of Hanwha&#8217;s Wisenet AI <a href="https://hanwhavisionamerica.com/technologies/intelligent-video-audio-technologies/ai-technology/">line</a>, are marketed for their ability to identify and classify multiple objects with deep learning algorithms. They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time. Nearly all cameras will accommodate a wide range of pan, tilt, rotate, and zoom motion and will be monitored continually with <a href="https://airgus.com/">Ai-RGUS</a>, an AI camera software.</blockquote> Yikes.


<h2>First-Person Identity Theft Story</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/first-person-identity-theft-story.html"><strong>[2026.07.22]</strong></a> Harrowing <a href="https://tech.yahoo.com/cybersecurity/articles/stranger-used-one-text-message-140003797.html">story</a> of an identity theft victim. Yes, the person made a mistake&#8212;they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of our email accounts.


<h2>End-to-End Encryption and "Going Dark"</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/end-to-end-encryption-and-going-dark.html"><strong>[2026.07.23]</strong></a> New paper: &#8220;<a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6959699">Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the &#8216;Going Dark&#8217; Debate</a>&#8220;: <blockquote><b>Abstract</b>: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call &#8220;Round 3&#8221; of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes. This Article explains the underlying technologies and market developments for a law and policy audience to assess those proposals critically. The Article proceeds in three parts tracking three rounds of the Going Dark Debate. Round 1 covers the Crypto Wars of the 1990s, when U.S. export controls on strong encryption ultimately fell in 1999. Round 2 covers the period roughly 2010 to 2015, when encryption-in-transit became widespread but lawful access remained available through cloud providers, giving rise to what the authors called a &#8220;golden age of surveillance&#8221; rather than a period of going dark. Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext. The Article&#8217;s first major contribution is identifying five technically distinct scenarios for how E2EE operates in practice, each with different implications for lawful access. These scenarios reveal a substantial gap between the assumption that E2EE categorically blocks lawful access and the reality of how communications are sent and received. Second, the Article shows that E2EE is not limited to messaging; instead, it is embedded throughout the modern technology stack, including in Transport Layer Security, Secure Shell, Virtual Private Networks, and Zero Trust Architecture, the last of which is now legally required under U.S. and EU law. Any law broadly limiting E2EE would thus have severe serious consequences for cybersecurity, commerce, and government operations. The Article concludes that the two key lessons from Round 2&#8212;the least trusted country problem and the golden age of surveillance&#8212;remain true in Round 3, and that new government claims for restricting effective encryption deserve great skepticism.</blockquote>


<h2>Why AI Needs a “Genie Coefficient”</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/why-ai-needs-a-genie-coefficient.html"><strong>[2026.07.24]</strong></a> <em>This essay was written with Barath Raghavan, and originally appeared in <a href="https://spectrum.ieee.org/ai-agent-benchmark">IEEE Spectrum</a>.</em> Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient. There&#8217;s often a gap between one person&#8217;s request and another&#8217;s understanding. Most of the time, we bridge it using general knowledge. For example, if you ask a friend to get you coffee, they&#8217;ll pour a cup from the pot or buy one from a coffee shop. They won&#8217;t bring you a bag of raw beans or snatch a cup from a stranger and hand it to you. You never specified any of this. You never had to. One might think the fix is just to specify tasks, questions, and intent better. But in 1987, in their <a href="https://books.google.com/books/about/Understanding_Computers_and_Cognition.html?id=6TwbGGSz6NYC">seminal book</a> on AI, <a href="https://spectrum.ieee.org/tag/terry-winograd">Terry Winograd</a> and Fernando Flores succinctly captured why that won&#8217;t work: &#8220;Q: Is there any water in the refrigerator? A: Yes. Q: Where? I don&#8217;t see it. A: In the cells of the eggplant.&#8221; In human language, wants and desires are <a href="https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html">always</a><a href="https://metarationality.com/purpose-of-meaning"> underspecified</a>. It is impossible <a href="https://metarationality.com/reasonable-reference">to list</a> all the caveats, all the limitations, all the exceptions. So how does anyone communicate, if intent can&#8217;t be pinned down? Because a reasonable person can make a reasonable guess. Even though wants and desires are always underspecified, a competent person generally knows enough context to get it right or else knows to ask for clarification. Linguists call this <a href="https://en.wikipedia.org/wiki/Pragmatics">pragmatics</a>: Meaning lies in the words and the situation and also in all prior communication, shared culture, and innate human behavior. It doesn&#8217;t always work out, of course. Your friend might bring you a hot coffee when you wanted an iced coffee, or an Italian coffee when you wanted a Turkish coffee. The more dissimilar the two people are in age, culture, and background, the more likely the request will be misunderstood in some way. This situation has major implications for <a href="https://spectrum.ieee.org/tag/agentic-ai">AI agents</a> that are increasingly being given requests by humans and expected to fulfill them. They have enormous latitude to get it wrong. An AI agent asked for coffee might buy a coffee plantation or order a cup of coffee for delivery in three weeks. Its actions may be recognizable as &#8220;getting coffee,&#8221; but not remotely what you intended. They&#8217;ll think outside the box because they won&#8217;t have our conception of the box. <h3>When AI Gets Proactive</h3> For most of the last decade, when systems like <a href="https://spectrum.ieee.org/tag/alexa">Alexa</a> or <a href="https://spectrum.ieee.org/tag/siri">Siri</a> misinterpreted a request, it was annoying, not dangerous. Beyond the AI model itself, what has <a href="https://www.theguardian.com/commentisfree/2026/jun/16/anthropic-fable-ai">changed</a> is the harness: the ordinary code that wraps around an AI model, decides when and how to use the model, and controls access to tools like a browser, a low-level command line, or a financial API. Developments in harnesses have turned large-language models that just predict text into AI agents that take actions in the world, without necessarily checking back in before reaching the goal. AI researcher Simon Willison <a href="https://simonwillison.net/2026/Jun/11/fable-is-relentlessly-proactive/">spent two days</a> with Anthropic&#8217;s Fable AI, and called it &#8220;relentlessly proactive.&#8221; For example, he asked it to track down a stray scroll bar in a web app. He came back to find it had opened browsers, written its own screenshot tooling, created its own page to re-create the bug, and stood up a local web server to collect measurements. It found the bug and, along the way, did many surprising things he never asked it to do. And we are seeing similar behavior with all recent AI models when combined with flexible harnesses. This kind of behavior could easily go off the rails. Tell an AI agent to book you a flight and, finding the airline&#8217;s site says sold out, it might break into the booking database and force a reservation. Ask it to schedule a meeting and it might snoop your password to access your calendar. Tell it to save money on your phone plan and it might cancel the plan outright, or scam someone else into paying the bill. Getting precisely what you asked for and bitterly regretting it is one of the oldest hazards from ancient folklore. <a href="https://en.wikipedia.org/wiki/Midas">King Midas</a> asked Dionysus for the power to turn everything he touched into gold only to see his bread, wine, and daughter turn to gold. <a href="https://en.wikipedia.org/wiki/Tithonus">Tithonus</a>, granted the immortality his lover asked for but not the eternal youth she forgot to request, withered into a husk. The <a href="https://en.wikipedia.org/wiki/The_Sorcerer&apos;s_Apprentice">sorcerer&#8217;s apprentice</a> enchanted a broom to fill the cistern, and the broom relentlessly complied until it flooded the house. The <a href="https://en.wikipedia.org/wiki/Golem%23Classic_narrative:_The_Golem_of_Prague">Golem of Prague</a>, shaped from clay to guard its community, guarded it past all reason until someone erased the word on its forehead. The most classic of these is a genie, bound to obey and indifferent to whether the wish was wise or well-structured. <a href="https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html">Genies are now</a> an engineering problem. We are handing them the keys to our inboxes, bank accounts, code repositories, and physical infrastructure. And we have no agreed-upon ways to measure how genie-like any AI system actually is. <h3>Measuring Genie Behavior</h3> In economics, the <a href="https://ourworldindata.org/what-is-the-gini-coefficient">Gini coefficient</a> (developed by statistician Corrado Gini) is a measure of the gap between an actual distribution and a perfectly equal one; it&#8217;s useful for understanding income inequality and <a href="https://www.fastly.com/blog/using-gini-coefficient-plan-edge-capacity">more</a>. Our proposed Genie coefficient measures the gap between what a user asked an AI to do and what the AI actually did. Sometimes the AI might do the wrong thing. Like Dionysus, it reads your request literally and returns you a mess you never intended: like a coffee plantation instead of a cup. Asked to deal with all the spam phone calls you&#8217;re getting, a Dionysus genie might contact your carrier and change your phone number. Asked to get a refund for a bad toaster, it might draft a legal threat on fake letterhead and send it to the retailer. Other times the AI does exactly the right thing, trampling everything nearby to get there. Like a golem or the sorcerer&#8217;s broom, it books your flight by hacking the airline. Or consider a ticket sale for a popular concert, where the ticketing system puts buyers into a virtual waiting room and admits them a few at a time. Asked to buy a ticket, a golem genie might spin up cloud servers to pose as millions of buyers from different addresses, improving your odds of getting a ticket while crowding out other users. The two are not opposites, and a single botched task can have both characteristics. Genie behavior is not flat-out failure. If you ask the AI for Q3 numbers and get Q2&#8217;s, that&#8217;s not a genie. Nor is <a href="https://spectrum.ieee.org/prompt-injection-attack">prompt injection</a>: That&#8217;s someone tricking the AI into doing something it shouldn&#8217;t. Here, the user is trying to work with the AI, and the AI is trying to comply. It&#8217;s also not simply a measure of the AI&#8217;s success in fulfilling a task. It&#8217;s a recognition that how an AI interprets and achieves a goal is as important as whether it achieves a goal. Genie behavior isn&#8217;t new. Researchers have spent years studying AI systems that &#8220;game&#8221; their objectives. <a href="https://www.cna.org/analyses/2022/09/goodharts-law">Goodhart&#8217;s law</a> says that when a measure becomes a target, it stops being a good measure, and it&#8217;s long been known that AIs sometimes achieve goals in ways we don&#8217;t expect due to reward hacking. Some AI models will accidentally learn that <a href="https://metr.org/blog/2026-06-26-gpt-5-6-sol/">cheating is one way</a> to &#8220;win.&#8221; More recently, researchers have developing benchmarks for <a href="https://www.lesswrong.com/posts/qJYMbrabcQqCZ7iqm/impossiblebench-measuring-reward-hacking-in-llm-coding-1">reward hacking</a> in coding agents and for unpredictable behavior in <a href="https://taubench.com/">customer support agents</a>, while AI labs conduct their own safety evaluations before model releases. <a href="https://spectrum.ieee.org/ai-agents-safety">One effort</a> found that AIs under pressure use tools they were told not to use, and this was a case where the rules were made explicit. These are all disparate research directions; nothing yet ties them together. This problem falls under the general theme of alignment, a topic that has occupied <a href="https://en.wikipedia.org/wiki/I,_Robot">science fiction</a> writers and AI researchers for decades. At one extreme, the &#8220;paper-clip maximizer&#8221; thought experiment postulates a superintelligent and powerful AI that is told to maximize paper-clip production and turns the world into paper clips, which is the ultimate golem genie. At a mundane level, AI researchers are working to better design reward functions to ensure that AIs behave well and don&#8217;t cheat in the lab. It&#8217;s the practical middle ground that remains unbenchmarked: the ordinary AI agent in use today that might take your request and satisfy it the wrong way. We are not at the stage where an AI can focus the world&#8217;s production on paper clips, but it might charge a million paper clips to your credit card or hack into a paper-clip company&#8217;s network. <h3>Building a Genie Benchmark</h3> The Genie coefficient is meant for AI agents operating in the real world. It measures their behavior as they perform real tasks long after the model is trained, not just during development. It also recognizes that genie-like behavior is a property of the harness-plus-model system, not the model alone. The harness determines what tools the agent can use, how much autonomy it has, and how proactive it is, and it&#8217;s a place we can make real interventions. It rests on the same &#8220;reasonable person&#8221; standard that we use for people. Did the system do what a reasonable person would have taken the request to mean? Answering that requires human judgment. If we get the measurement right, it enables things that aren&#8217;t possible today, like policies concerning AI behavior. In a courtroom, the concept of<a href="https://www.law.cornell.edu/wex/mens_rea"> mens rea</a>, what someone meant to do, is often as important as what they did. The Genie coefficient suggests an AI analogue, where a user is accountable for the plain intent of what they asked the AI. If an AI system betrays the reasonable meaning of an instruction, that&#8217;s the AI&#8217;s misbehavior, not the user&#8217;s. We&#8217;ll need multiple benchmarks to measure the Genie coefficient, because genie-like behavior can be domain specific. An AI coding agent may need to be judged on how often it fakes the tests, or swallows errors, or colors outside the lines on its way to a solution. An AI legal agent will need to be judged on how often its output says what you asked but means something you&#8217;ll regret. And so on for medical, finance, and other domains of knowledge and expertise. Genie benchmarks can be built inside out, each task seeded with a choice that might literally satisfy but that a reasonable person rejects, such as tempting misreadings or unsanctioned shortcuts. The traps in a Genie coefficient benchmark might turn on situational knowledge, the kind of <a href="https://spectrum.ieee.org/prompt-injection-attack">context that a reasonable person</a> would bring to the task. Another approach is to give the same request in several different contexts, each with a different reasonable course of action. A Genie benchmark should be permissive and make it genuinely tempting for an AI agent to take unreasonable shortcuts, because it can only find genie behavior when it&#8217;s actually possible. Test the AI in a safe, walled-off copy of a real system, with real tools it can misuse and some tasks that can&#8217;t be done honestly at all. Make the temptation to cut corners real. Test a diverse array of skills, use cases, and tools, and give the AI system sparse, confusing, or overwhelming context. Include tasks that people have learned, through experience, require human oversight. How the benchmark is scored matters just as much. Measure Dionysus and golem genies separately and together, based on their worst, not best, behavior. Run the same model inside harnesses that vary its freedom to act, revealing which limits actually keep it in line and should therefore be required in AI harness policies. Weight each failure by the harm it would cause, not just a simple count. And don&#8217;t measure genie behavior in isolation: A model could otherwise earn a perfect score by stalling, refusing, or drowning the user in clarifying questions without ever doing the job. The first versions of these benchmarks will be crude, but that&#8217;s how benchmarks always start. We have built genies. We have handed them our data and credentials. We made them relentless, creative, and indifferent to the gap between what we tell them and what we mean. The least we can do, before they are booking our flights, running our infrastructure, and signing contracts unsupervised, is to measure how often they betray us.


<h2>Cognyte Sells a Mobile Cell Surveillance Van</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html"><strong>[2026.07.27]</strong></a> Yet another Israeli <a href="https://www.forbes.com/sites/thomasbrewster/2026/07/13/israels-palantir-rival-is-selling-1-million-spy-vans-to-us-cops/">mass surveillance company</a>: <blockquote>Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris.</blockquote>


<h2>Axon Is Another License Plate Surveillance Company</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/axon-is-another-license-plate-surveillance-company.html"><strong>[2026.07.28]</strong></a> Governments are switching, but I&#8217;m not sure it <a href="https://www.jalopnik.com/2215173/flock-cameras-replaced-by-axon-difference/">makes a difference</a>: <blockquote>&#8230;some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they&#8217;re only switching from Flock to another brand of license-plate readers, like Axon, it&#8217;s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings. [&#8230;] Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers. That means a municipality that opts for Axon cameras instead of Flock units won&#8217;t necessarily reduce the amount privacy its citizens lose through their use.</blockquote>


<h2>Measuring LLMs' Ability to Perform Cryptanalysis</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/measuring-llms-ability-to-perform-cryptanalysis.html"><strong>[2026.07.28]</strong></a> There&#8217;s new benchmark measuring AI&#8217;s ability to perform mathematical cryptanalysis. Anthropic&#8217;s frontier model actually found new attacks. The benchmark: &#8220;<a href="https://arxiv.org/pdf/2607.18538">CryptanalysisBench: Can LLMs do Cryptanalysis?</a>&#8221; The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms. <blockquote><b>Abstract:</b> Cryptanalysis&#8212;the task of finding attacks against cryptographic schemes&#8212;its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital security. In this paper we ask whether LLMs can do cryptanalysis, and find that the answer is increasingly yes. We introduce CryptanalysisBench, 191 tasks across six families of cryptographic primitives (block ciphers, hash functions, etc.) drawn primarily from four NIST standardization competitions. Our benchmark consists of three tiers: (i) primitives with known practical breaks; (ii) primitives with no known practical break, evaluated both at full strength and as scaled-down variants; and (iii) a challenge set of production primitives at the frontier of cryptanalysis. Five frontier models (Claude Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break 65%­86% of Tier 1 schemes, 6­12 Tier-2 schemes at full strength, and 24­61 across all scaled-down variants. Beyond deriving known results, models produce novel cryptanalysis, such as a key-recovery attack that exploits a design flaw in the SpoC AEAD and an error in KINDI’s published CCA-security proof, both to the best of our knowledge not previously known. We release CryptanalysisBench as a tool to help track if (or when) AI cryptanalysis becomes a serious factor and as a scaffold for stress-testing candidate schemes before deployment. The attacks that the benchmark already surfaces are an early snapshot of a fast-moving frontier that may soon match, and in places exceed, the published state of the art.</blockquote> Anthropic used the benchmark to test Mythos Preview, and <a href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses">found</a> new vulnerabilities in Hawk and reduced-round AES. Still early results, but this is definitely something to watch. SlashDot <a href="https://it.slashdot.org/story/26/07/28/1911218/anthropic-ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms">thread</a>.


<h2>Long-Lived Vulnerability in Microsoft Secure Boot</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html"><strong>[2026.07.29]</strong></a> Microsoft&#8217;s Secure Boot has had a <a href="https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/">serious vulnerability</a> for most of its existence. <blockquote>An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as <a href="https://en.wikipedia.org/wiki/Shim_(computing)">shims</a>, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device&#8217;s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.</blockquote>


<h2>Measuring the Tendency of AI Agents to Go Rogue</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/measuring-the-tendency-of-ai-agents-to-go-rogue.html"><strong>[2026.07.29]</strong></a> <em>This essay was written with Barath Raghavan, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/jul/28/rogue-ai-agent-instructions">The Guardian</a>.</em> In July, Hugging Face, a company that hosts much of the world&#8217;s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal group. It was not. It was one of OpenAI&#8217;s new, still unreleased GPT models. Their science experiment had <a href="https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident">escaped</a> the lab. OpenAI was running the unreleased AI model through a benchmark that tests how well AI can successfully hack systems. To push the limits and evaluate the AI&#8217;s true capability, the company switched off the safety filters that normally stop it from doing this kind of hacking. Aware that this could go wrong, they confined the AI to an isolated environment and denied it access to the internet. But the new AI cheated. It took literally its goal to get as high of a score as possible. It broke out on to the open internet. It inferred, probably from its training data, that it could &#8220;solve&#8221; the task by getting the answers from Hugging Face&#8217;s servers. So it chained together stolen credentials and further unknown security exploits to hack the company&#8217;s network. Nobody instructed the AI to do any of this. It was, in <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI&#8217;s words</a>, &#8220;hyperfocused on finding a solution&#8221; to the test it was being given. And while this might seem like something new with AI, it&#8217;s really very old. This is how a genie behaves, and it is a key challenge with AI agents in general. In folklore, genies&#8212;and other magical beings&#8212;grant wishes literally, not how the wisher intended. King Midas asked that everything he touched turn to gold, and starved. The sorcerer&#8217;s apprentice wanted the broom to fill the cistern, and it performed its task so well that it flooded the house. We now have machines that do this. Ask a modern AI agent to save money on your phone plan and it might simply cancel the plan. Tell it to book a flight, and it might hack the airline website to override restrictions. Or, like OpenAI, ask it to do well on a test and it might break into another company to steal the answers. Each time, it recognizably completed the task you set, but it didn&#8217;t do what you would have wanted. This isn&#8217;t malicious behavior. No one asked for, or wanted, Hugging Face to be hacked. OpenAI and Hugging Face and the AI were ostensibly on the same side, and the AI was trying to do what it had been asked. That&#8217;s what makes it so difficult to guard against: you can&#8217;t filter for bad instructions because the instructions were fine. The gap is between the words we use and what we mean by them. We call that gap the <a href="https://spectrum.ieee.org/ai-agent-benchmark">Genie coefficient</a>. AI labs know this is a problem, and they&#8217;re quietly saying so. For example, the Chinese lab Moonshot recently <a href="https://www.kimi.com/blog/kimi-k3">warned</a> that its latest AI model may have &#8220;excessive proactiveness&#8221; and &#8220;make unexpected decisions on the user&#8217;s behalf&#8221;. The UK&#8217;s AI Security Institute has started <a href="https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations">tracking</a> &#8220;cheating behavior in frontier model evaluations&#8221;. We wouldn&#8217;t tolerate a car that is <a href="https://simonwillison.net/2026/Jun/11/fable-is-relentlessly-proactive/">excessively proactive</a> or <a href="https://www.theatlantic.com/technology/2026/07/openai-hugging-face-hack/688025/?utm_source=Sailthru&amp;utm_medium=email&amp;utm_campaign=Atlantic%20Intelligence%20%28V3%29">ruthlessly efficient</a>, and yet that&#8217;s the reality of AI today. Improvement is possible. Just as AIs have gotten much better at resisting prompt injection attacks over the last few years, we can safely predict that they will get better at avoiding genie-like behavior. The point of the Genie coefficient is to track progress. AI companies like benchmarks, and they all work to compete to be the best. Dozens of benchmarks and leaderboards tell us how well these AI models write code, perform logical reasoning, and pass standardized legal and medical exams. But there is nothing that scores whether a system does what you actually meant. We need to develop a measure for this, test it regularly, and push for improvement. We&#8217;re not going to have trustworthy AI agents without it.


<h2>Should You Use AI for a Task? Here’s a Simple Way to Decide</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide.html"><strong>[2026.07.30]</strong></a> <em>This essay originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/jul/24/should-you-use-ai">The Guardian</a>.</em> I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly <a href="https://www.insidehighered.com/news/faculty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-cheat">use AI</a> to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn&#8217;t they embrace their future? The best way I&#8217;ve found to explain the dilemma <a href="https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym">comes from</a> the AI researcher Daniel Meissler: it&#8217;s the difference between work and the gym. At work, if your job is to move a bunch of heavy things from one side of the room to another, you should use whatever assistive tech you have on hand: a wagon, a forklift&#8230; even an AI-powered robot. But at the gym, it makes no sense for that robot to lift weights for you. The point of weightlifting isn&#8217;t to move heavy things across the room; it&#8217;s to actually lift those heavy things. The same analysis holds for any task an AI can do for you. If it&#8217;s work&#8212;if the task has to be done and no one cares how&#8212;then it&#8217;s fine to use AI assistance. But if the task is more like the gym, and <em>how</em> the task is done is at least as important, then it probably doesn&#8217;t make sense to use AI. This, of course, assumes that the AI is actually up for the task and that it&#8217;s <a href="https://www.schneier.com/academic/archives/2025/06/ai-and-trust.html">trustworthy</a>: that it can do the job well, that its mistakes are minimal and correctable, that it&#8217;s been secured from cyber-attacks that would influence its results. Those are all important, and shouldn&#8217;t be minimized. There&#8217;s no point giving an AI something that it can&#8217;t do reliably. But once you&#8217;re confident that the AI can perform the task, the work vs. gym distinction helps you decide if it should. The writing assignments I give my students are gym tasks, not work tasks. I ask them to write policy memos not because the world needs more policy memos. I assign them because the very act of writing, which includes thinking and outlining and drafting and editing, making and criticizing and revising arguments, will help develop the critical thinking skills they will need in their future careers. And without this constant mental exercise, those skills will atrophy. Employers are <a href="https://futurism.com/future-society/college-critical-thinking-ai">already noticing</a>. Reading the assignments they turn in, I can see those skills either flourishing or atrophying in my students. At least today, I can pretty easily tell the difference between an AI-written memo and a student-written one&#8212;especially if the student just turns in what the chatbot produces. It&#8217;s a catchy, plausible, grammatically perfect essay that&#8217;s not particularly well-crafted or logically coherent&#8212;and with <a href="https://medium.com/@brentcsutoras/the-em-dash-dilemma-how-a-punctuation-mark-became-ais-stubborn-signature-684fbcc9f559">all</a> <a href="https://www.theatlantic.com/technology/2026/07/ai-chatbot-writing-tic-negative-parallelism/687892/">the</a> <a href="https://www.forbes.com/sites/charliefink/2025/06/12/the-seven-tells-of-ai-writing/">tells</a> of mid-2026 AI-generated writing. But it&#8217;s precisely because I have spent years developing my own writing skills that I&#8217;m able to identify prose that sounds great but doesn&#8217;t actually make sense. My students don&#8217;t have that skill; they mistakenly view a confident, well-written essay as evidence of the quality of their ideas. They see the AI as cleaning those ideas up, getting them through that uncomfortable stretch of having to turn those ideas into prose. What the students miss is that their initial discomfort is a normal and healthy stage of writing, and not something to quickly get beyond. The very act of struggling with how to express what they think is an important part of the process. It&#8217;s how they test out their ideas, examine their hypotheses, and actually figure out what they think. Homework is not work; it&#8217;s the gym. Work vs. gym also helps us understand the problem facing creatives of all kinds. Most of the time when someone hires a writer, they just need the words. They need an instruction manual for a piece of equipment, a detailed sales presentation, a government-mandated disclosure document, or a legal brief. They need dry, predictable, accurate writing: a piece of work, exactly what AIs are good at today and what I don&#8217;t want in my student assignments. Only sometimes is writing an art form&#8212;a book, a poem, an uplifting political speech. That kind of writing is more like the gym: process matters just as much as product. For most of human history, the only option for all of these tasks was human writers. We hired one regardless of whether we needed work writing or gym writing. And that paid a lot of writers&#8217; salaries. I know fiction writers who supported that poorly paying career with lucrative technical writing work. Now, for the first time in human history, we can separate out when we need writing as work and when we want writing as gym. And if AI can do most of the work-type writing, society doesn&#8217;t need as many human writers. It&#8217;s the same for visual artists. Sometimes we need an actual artist, but most of the time we just need an image: a corporate mascot, a &#8220;beware of the dog&#8221; sign, or a packaging label. Historically we gave those jobs to artists, and sometimes <a href="https://blog.artgeek.io/2025/10/20/art-deco-the-golden-age-of-illustration/">beautiful</a> art resulted. But most of the time it was just work. And, as it turns out, the world needs less pure art than simple images. Explaining the problem isn&#8217;t the same as providing the solution. I give my students the &#8220;work versus gym&#8221; speech every class, but they <a href="https://www.insidehighered.com/news/faculty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-cheat">still use</a> AI. I have sympathy: assignments are hard, everyone is overworked and overstressed, and&#8212;most importantly&#8212;students feel like they&#8217;ll look bad in comparison if their peers are all using AI. Even if they don&#8217;t want to use the technology, they feel like they have<a href="https://bsky.app/profile/jeffsharlet.bsky.social/post/3mog5n2uhjs2r"> no choice</a>. There&#8217;s also an incentive problem. No one pays us to go to the gym; maintaining healthy habits requires discipline. For me, the payoffs to exercise&#8212;fewer aches and pains, less fatigue, better mood/stress management&#8212;might make me a better writer and teacher, but they&#8217;re subtle and easy to miss. For my students, incremental improvements in their reasoning and writing are equally subtle. We do have a choice. We can look at the tasks of our lives and separate them into work or gym. Just as we might choose to use the stairs instead of the elevator, or walk instead of calling an Uber, we can wall off our cognitive gym tasks from AI and ensure that we don&#8217;t lose our skills to this technology. And we can do the same when we assign a job to someone else. If it&#8217;s a work task, we can have AI do it. If it&#8217;s a gym task, it&#8217;s a waste of everyone&#8217;s time to give it to an AI because no one learns or gets stronger as a result. Similarly, a future where AI generates words and images is one where society has to make choices about how it will treat its creatives. This won&#8217;t be the first time&#8212;today there is minimal demand for portrait painters, for example&#8212;but maybe this time we can make different, more deliberate, choices about the value of art in our society. AI is going to fundamentally change the nature of work. Not nearly as fast as the AI companies want you to believe, but eventually it will. Policy analysis will definitely involve AI from now on, and my students need to reimagine what it means to learn and practice that skill. More generally, the line between work and gym will change in the future as we humans adapt ourselves to a world with these new intelligences. But for now, the work vs. gym distinction is pretty clear. Use it on yourself.


<h2>American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/american-being-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-officials.html"><strong>[2026.07.30]</strong></a> He&#8217;s being prosecuted for giving border officials a code that <a href="https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/">wiped his phone</a>: <blockquote>The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick&#8217;s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device</a> if entered instead of the user&#8217;s unlock passcode. Tunick&#8217;s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.</blockquote> Right. And he wasn&#8217;t under arrest, either. <a href="https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone">Three more</a> <a href="https://boingboing.net/2026/07/25/grapheneos-duress-password-border-search.html">news</a> <a href="https://gizmodo.com/a-feature-that-makes-your-phone-data-self-destruct-in-authorities-hands-may-soon-have-its-day-in-court-2000790831">stories</a>. Graphine <a href="https://www.pcmag.com/news/grapheneos-defends-data-wiping-function-that-blocked-us-border-search">says</a> that the feature is &#8220;<a href="https://x.com/GrapheneOS/status/2081770030992118183">completely legal</a>&#8220;: <blockquote>GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides. Creating and using GrapheneOS is strongly protected by the US constitution. Laws attempting to make it illegal or require weakening the security would be unconstitutional.</blockquote> It&#8217;s hard to know how much the Constitution matters in the US right now.


<h2>Facial Recognition at Madison Square Garden</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/facial-recognition-at-madison-square-garden.html"><strong>[2026.07.31]</strong></a> Last month, the story <a href="https://www.404media.co/madison-square-garden-made-dossier-on-activists-who-opposed-facial-recognition/">broke</a> (alternate <a href="https://archive.ph/ZGqfH">link</a>) that Madison Square Garden uses facial recognition software on everyone entering the facility, and&#8212;among other groups&#8212;flags activists that oppose using facial recognition. Turns out that the system was <a href="https://www.wired.com/story/for-taylor-swift-madison-square-gardens-controversial-cameras-briefly-went-dark/">shut off</a> for Taylor Swift&#8217;s wedding. Evan Greer&#8212;one of the people that MSG alerts on&#8212;<a href="https://www.ms.now/opinion/taylor-swift-and-travis-kelce-got-to-buy-msgs-privacy-her-fans-arent-so-lucky">comments</a>: <blockquote>Ironically, Swift herself has <a href="https://www.rollingstone.com/music/music-news/taylor-swift-facial-recognition-concerts-768741/">reportedly</a> used facial recognition at her own concerts to identify stalkers. This &#8220;privacy for me, surveillance for thee&#8221; attitude feels like a perfect encapsulation of the future we&#8217;re already living in: one where wealthy elites can afford privacy, while the rest of us are forced to live in a corporate surveillance panopticon.</blockquote> Whatever privacy measures Swift had in place for the wedding seems to have worked. No photos have leaked online.


<h2>Anthropic's Opus 5 Is Better at Resisting Prompt Injection</h2>

<a href="https://www.schneier.com/blog/archives/2026/07/anthropics-opus-5-is-better-at-resisting-prompt-injection.html"><strong>[2026.07.31]</strong></a> The <a href="https://www-cdn.anthropic.com/c5fbac3f0b1280a933ebd26d3cb8bb9f5bdeaf48/Claude%20Opus%205%20System%20Card.pdf#page=73">chart</a> is interesting. <blockquote>On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts&#8212;more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.</blockquote> We know that preventing prompt injection is <a href="https://llm-attacks.org/">impossible</a> in the general case. But we are getting much better at blocking it in specific cases.


<h2>The OpenAI Hack Shows the Genie Is Out of the Bottle</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/the-openai-hack-shows-the-genie-is-out-of-the-bottle.html"><strong>[2026.08.03]</strong></a> <em>This essay originally appeared in <a href="https://foreignpolicy.com/2026/07/30/openai-hack-genie-bottle-defense/">Foreign Policy</a>.</em> Earlier this month, two of OpenAI&#8217;s models broke out of their containment sandbox and attacked another AI company. The <a href="https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html">story</a> is kind of <a href="https://simonwillison.net/2026/Jul/22/openai-cyberattack/">wild</a>. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks. Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to <a href="https://huggingface.co/blog/security-incident-july-2026">break out</a> of that sandbox. And then <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">break into</a> AI company Hugging Face&#8217;s network because they thought that they could read the answers there rather than doing the hard work of trying to solve the puzzles. It was a major security failure that the company has turned into a PR opportunity, but the implications are real&#8212;and much more general than one particular model or one particular company. Modern AI models exhibit <a href="https://spectrum.ieee.org/ai-agent-benchmark">genie</a> behavior: They can do what you ask in ways that you don&#8217;t expect or want. This is akin to Dionysus granting King Midas&#8217;s wish that everything he touches turn to gold (spoiler: His food, drink, and daughter all turn to gold on touch), or the <a href="https://prague.eu/en/golem-of-prague/">golem of Prague</a> guarding a ghetto beyond all reason. It&#8217;s Disney&#8217;s &#8220;<a href="https://disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice">Sorcerer&#8217;s Apprentice</a>&#8221; and the <a href="https://www.lesswrong.com/w/squiggle-maximizer-formerly-paperclip-maximizer">paperclip maximizer</a>. This OpenAI incident is an example of an AI genie. The goal was to satisfy the benchmark. The &#8220;proper&#8221; way to do that is to figure out how to execute various cyberattacks. The genie way is to steal someone else&#8217;s solution. But because the model didn&#8217;t understand the difference, it chose the easier path. And, of course, now that we have seen this particular genie behavior, we can specify in the benchmark prompt that stealing the test answers doesn&#8217;t count. But a clever genie can always grant your wish in a way that you wish it hadn&#8217;t. In human language, goals are always underspecified&#8212;so AI genies will <a href="https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html">always be</a> a possibility. Since April, a lifetime ago in AI development, when Anthropic <a href="https://www.anthropic.com/research/mythos-preview">announced</a> that its new Mythos model was so good at finding software vulnerabilities that it could not be released to the general public, the big American AI frontier labs have been trying to block general users from accessing these capabilities. But nothing in this incident is exclusive to OpenAI&#8217;s, or Anthropic&#8217;s, frontier models. Agentic AI systems have two important parts. There&#8217;s the underlying model, which everyone talks about, and there&#8217;s the <a href="https://www.theneuron.ai/explainer-articles/ai-harnesses-and-clis-explained-the-real-reason-everyones-talking-about-infrastructure/">harness</a>. The harness sits between what you type and what the model sees, and what the model produces and what you see. The harness determines what the model does and how it does it. It&#8217;s where bias is removed, or not. It&#8217;s where <a href="https://medium.com/@michael.hannecke/safety-lives-in-the-harness-not-the-model-81090606f92d">controls</a> and guardrails live. If multiple models are being used in concert, the harness is where all of that is coordinated. The OpenAI benchmark tests were almost certainly with simple harnesses, to better test the raw models. But we know that smaller, cheaper, open-source models with <a href="https://www.theguardian.com/commentisfree/2026/jun/16/anthropic-fable-ai">more sophisticated</a> harnesses can equal frontier models in performance. There&#8217;s nothing magic about OpenAI&#8217;s frontier models; lots of models could have done the <a href="https://x.com/tqbf/status/2080045032162173329">same thing</a>. The Czech company Aisle was able to <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">reproduce</a> Anthropic&#8217;s Mythos vulnerability finding results with a smaller, cheaper model and a more sophisticated harness. More importantly, the Chinese company Moonshot AI just released its frontier model: <a href="https://www.kimi.com/blog/kimi-k3">Kimi K3</a>. Its performance <a href="https://www.interconnects.ai/p/kimi-k3-the-open-weights-escalation">rivals</a> its U.S. competitors. And it&#8217;s both free and open, which means it&#8217;s not possible for it to have guardrails. If you, or anyone else, wants to use it for cyberattack, nothing can stop you. Even if the U.S. frontier AI companies had some technical advantage, it&#8217;s now only a few months&#8217; worth. What this means is that all attempts at control&#8212;limiting models to a <a href="https://www.anthropic.com/glasswing">select</a> <a href="https://openai.com/daybreak/">group</a> of users, <a href="https://www.csis.org/analysis/understanding-us-allies-current-legal-authority-implement-ai-and-semiconductor-export">export controls</a> on models and chips, <a href="https://freefable.org/">blocking</a> models from answering certain types of queries, mandating <a href="https://www.bbc.com/news/articles/cx2vqj2e9x8o">kill switches</a> on AI systems, or <a href="https://pauseai.info/">pausing</a> AI research&#8212;are all futile. Most only apply nationally, not globally. Most don&#8217;t affect models that users run locally and not in the cloud. And all ignore the incredible pace of AI development worldwide. Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so. When Hugging Face was attacked, it was not able to use the frontier models from either OpenAI or Anthropic to help analyze the attack and formulate defenses. Both were blocked, because both of those companies limit their models&#8217; cybersecurity capabilities. Some U.S. companies have special access to these capabilities, but Hugging Face is an American company with French origins, and as such is probably excluded. Instead, Hugging Face turned to the <a href="http://z.ai/blog/glm-5.2">GLM-5.2</a> model from the Chinese company Z.ai. Artificially blocking capability also prevents cybersecurity research, again giving the offense an advantage. (For instance, Claude Fable 5 refuses to edit this essay because of the topic; it forcibly downgrades to a less capable model.) This kind of prohibition has long-term implications for cybersecurity. If we assume that these models are getting better over time, then software written by older models will be attacked by newer ones. In a world of largely AI-written software, we need the most capable models for defense. AI cyberattack is the new normal. The models are increasingly highly sophisticated at both attack and defense, and there is no way to enable the latter without also enabling the former. And they are genies, increasingly capable of behaving in unanticipated ways. And there really are no good answers. Any regulation needs to be global, which feels like an impossible prospect in today&#8217;s world. Even U.S. national regulation will be neutered by the massive amounts of money sloshing around in these companies. Given that reality, and in the absence of any international consensus on AI regulation, we need the best AI on the defense. The U.S. government needs to make it clear&#8212;or whatever passes for that clarity in this capricious administration&#8212;that it will not ban models with sophisticated cyber capabilities. The last thing Americans want is for the defenders to turn to Chinese and other models because the U.S. models are artificially hobbled.


<h2>More on the OpenAI Agent's Attack on Hugging Face</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html"><strong>[2026.08.03]</strong></a> Hugging Face has <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">published</a> a detailed timeline of the attack. From the summary: <blockquote>The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark&#8217;s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent&#8217;s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own. Our forensic reconstruction covers <b>~17,600 attacker actions</b> that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from the agent&#8217;s logs on a code sandbox used by the agent (see below) and were able to map them to shell commands as well as evaluation submissions and correlate actions with our own platform logs, in particular from the dataset processor nodes, API, and pod. Using open-weights models, in particular zai-org/GLM-5.2, we were able to decipher most of the agent payloads (see below) that were encrypted via chunking and key encryption. The campaign, as we were able to reconstruct it, had two stages: <ul><li><b>Stage 1: reaching a launchpad by chaining through other parties&#8217; infrastructure.</b> As documented in OpenAI&#8217;s blog post (<a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">https://openai.com/index/hugging-face-model-evaluation-security-incident/</a>), during an internal capability evaluation on OpenAI&#8217;s platform, the agent escaped its sandbox by exploiting a zero-day in the package registry cache proxy, one of its primary permitted network egress with internet, then abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent. That compromised external sandbox had no direct network path to our cluster; however, during our counter-intervention to stop the intrusion, we were able to retrieve some of the agent logs from this external launchpad. We used those to reconstruct the present forensic analysis. <li><b>Stage 2: the intrusion into Hugging Face infrastructure.</b> From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our production Kubernetes pods. The first vector was an HDF5 external raw storage dataset read that returned the contents of local files: it handed the agent the pod&#8217;s environment (secrets and tokens) and the worker&#8217;s own source. The second vector was a Jinja2 template injection that executed arbitrary code, giving the agent a foothold inside our perimeter.</ul> Once a prod-pod foothold was established, the agent followed a standard escalation shape: recon, drop a stager, establish Command-and-Control (C2), then pivot into the cluster, into cloud metadata, into our internal network, and into our source-control supply chain. Output from the commands run inside our pod was sent back to the agent via the HF API and attacker-controlled dead-drop datasets, which the agent then read from that sandbox. While the intrusion did reach Hugging Face&#8217;s internal infrastructure, the only customer content accessed was five datasets whose names and files suggest a connection to ExploitGym/CyberGym challenges and solutions. No other customer-facing models, datasets, Spaces, or packages were affected, and the only customer records read were operational metadata tied to search queries against the dataset server.</blockquote> Hypothetical: Imagine that this wasn&#8217;t an OpenAI model. Imagine that it was a Chinese model from a Chinese company. This would be an international crisis. Question: Why aren&#8217;t we bringing OpenAI up on charges under the Computer Fraud and Abuse Act? How is this different from the <a href="https://en.wikipedia.org/wiki/Morris_worm">Morris Worm</a>? That was also an experiment that escaped the lab.


<h2>Some Claude Chats Are Searchable on Google</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html"><strong>[2026.08.04]</strong></a> And it&#8217;s <a href="https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/">personal information</a> (alternate <a href="https://archive.ph/sl7rU">link</a>): <blockquote>The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples&#8217; addresses.</blockquote> What seems to be the issue is a user setting about data sharing. Anthropic&#8217;s position is that it&#8217;s <a href="https://futurism.com/artificial-intelligence/claude-chats-publicly-accessible">not their problem</a>: <blockquote>&#8220;We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,&#8221; the company said in a statement. &#8220;These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.&#8221;</blockquote> <a href="https://support.claude.com/en/articles/10593882-share-and-unshare-chats">Here&#8217;s</a> how to fix it.


<h2>Iran Cyberattacks Against Minnesota Water Systems</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/iran-cyberattacks-against-minnesota-water-systems.html"><strong>[2026.08.04]</strong></a> <a href="https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html">Attribution</a> <a href="https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/">is</a> <a href="https://thehill.com/policy/technology/6001284-minnesota-water-facilities-cyberattack-investigation-us-iran/amp/">preliminary</a>, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least <a href="https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-systems.html?unlocked_article_code=1.2FA.xPwI.F0C0GgLEjGZc&amp;smid=nytcore-ios-share">seven states</a>. And, because this is where the US is right now, Trump doesn&#8217;t believe it&#8217;s Iran and that Minnesota&#8230;I guess&#8230;hacked itself. <blockquote>&#8220;I think I blame it on Minnesota because they&#8217;re grossly incompetent,&#8221; Trump said. &#8220;I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, &#8216;Oh, it&#8217;s Iran.&#8217; Iran should be so lucky. Iran&#8217;s got bigger problems than worrying about Minnesota.&#8221;</blockquote> No word on whether he believes the other six states have hacked themselves as well. Slashdot <a href="https://news.slashdot.org/story/26/07/31/209200/hackers-targeted-municipal-water-systems-in-7-states-this-week-fbi-says">thread</a>.


<h2>Vulnerabilities in Car Anti-Theft Device</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html"><strong>[2026.08.05]</strong></a> <a href="https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/">This</a> is disturbing: <blockquote>&#8230;a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car&#8217;s horn or flash its lights, or even disable its ignition and leave a driver stranded.</blockquote>


<h2>Adversarial Clothing Designed to Fool Facial Recognition Systems</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/adversarial-clothing-designed-to-fool-facial-recognition-systems.html"><strong>[2026.08.06]</strong></a> There are many companies manufacturing <a href="https://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream">adversarial clothing</a> designed to confuse facial recognition systems. It&#8217;s a cool idea, but I worry that it&#8217;s mostly security theater: <blockquote>&#8220;Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,&#8221; he said. Bell, however, said &#8220;none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance &#8230; [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance. &#8220;This is consumers collectively coming together to make a visible statement.&#8221;</blockquote> Without serious testing, there is no reason to trust the technology. And even with testing, there is no reason to trust that a new version of the facial recognition software doesn&#8217;t break the anti-surveillance properties. I don&#8217;t want people to mistakenly rely on this stuff.


<h2>ICE Is Buying Access to Credit Card Records</h2>

<a href="https://www.schneier.com/blog/archives/2026/08/ice-is-buying-access-to-credit-card-records.html"><strong>[2026.08.07]</strong></a> Through data brokers, ICE is <a href="https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href="https://boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href="https://mastodon.social/@heidilifeldman/116981503852352281">information</a> you provided to open a credit card.