This is a multi-part message in MIME format
--_----------=_MCPart_580533442
Content-Type: text/plain; charset="utf-8"; format="fixed" Content-Transfer-Encoding: quoted-printable
** CRYPTO-GRAM
JULY 15=2C 2026
------------------------------------------------------------
by Bruce Schneier
Fellow and Lecturer=2C Harvard Kennedy School
schneier@schneier.com
https://www.schneier.com
A free monthly newsletter providing summaries=2C analyses=2C insights=2C a=
nd commentaries on security: computer and otherwise.
For back issues=2C or to subscribe=2C visit Crypto-Gram's web page [https= ://www.schneier.com/crypto-gram/].
Read this issue on the web [
https://www.schneier.com/crypto-gram/archives= /2026/0715.html]
These same essays and news items appear in the Schneier on Security [http= s://www.schneier.com/] blog=2C along with a lively and intelligent comment=
section. An RSS feed is available.
** *** ***** ******* *********** *************
** IN THIS ISSUE:
------------------------------------------------------------
1. The FCC Wants to Eliminate Burner Phones
2. Flock Cameras Are Being Used for Stalking
3. AI Use by the US Government
4. Embedding Forbidden Text in Spyware to Discourage AI Analysis
5. Anthropic=E2=80=99s Fable and the State of AI
6. Professional Athletes and Wearables
7. Anthropic=E2=80=99s Fable 5 Model Jailbroken Within Days
8. Interesting Paper Exploring Prompt Injection
9. AI and Liability
10. One Million Passports Leaked Online
11. Meta Is Testing Facial Recognition for Police and Military
12. Robot Police Officers
13. Factoring RSA Keys with Many Zeros
14. The Realities of AI Video Surveillance
15. Papa Johns Surveillance-Based Advertising
16. Cybersecurity Mission Creep in the US
17. Flock Cameras Can Surveil Cars Without License Plates
18. France to Stop Certifying Non-Quantum-Safe Encryption
19. Google Is Suing Chinese Scammers Who Are Using Gemini
20. Cybersecurity and the Gap Between Skill and Ability
21. The Language of AI Could Change How Humans Speak
22. AI Surveillance and Social Progress
23. AI Data Centers and the Concentration of Wealth
24. Vulnerability in FIFA=E2=80=99s Network
25. Upcoming Speaking Engagements
** *** ***** ******* *********** *************
** THE FCC WANTS TO ELIMINATE BURNER PHONES ------------------------------------------------------------
[2026.06.15] [
https://www.schneier.com/blog/archives/2026/06/the-fcc-wan= ts-to-eliminate-burner-phones.html] A proposed FCC rule would kill [https= ://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-= get-all-customers-ids/] burner phones: phones whose accounts are not attac=
hed to a particular person.
The FCC plans to do this by legally forcing the country=E2=80=99s teleco=
ms to store a wealth of personal information about essentially all phone c= ustomers=2C including a government issued identification number and their=
physical address=2C alarming privacy advocates and civil rights activists=
who compare the measures to those from authoritarian countries where it c=
an be difficult to buy a mobile phone plan without giving up your identity=
=2E
The proposed change would drastically shake up how people obtain phone p=
lans in the U.S.=2C and have all sorts of privacy and cybersecurity knock-=
on effects. The FCC is proposing the data collection partly as a way to co= mbat scammers=2C with telecoms being required to collect other information=
on business and foreign customers like the intended use case of their bul=
k phone plan purchase and their IP address. But the changes would mean tel= ecoms collect data on all new and renewing customers=2C and the FCC provid=
es a long list of other things that the collected data could help authorit=
ies with.
Alternate link [
https://archive.ph/ZwXMG].
** *** ***** ******* *********** *************
** FLOCK CAMERAS ARE BEING USED FOR STALKING ------------------------------------------------------------
[2026.06.16] [
https://www.schneier.com/blog/archives/2026/06/flock-camer= as-are-being-used-for-stalking.html] There are over a dozen cases around t=
he country where police officers are using the Flock surveillance camera s= ystem to obsessively and illegally stalk people [
https://www.404media.co/= cops-keep-getting-arrested-for-using-flock-to-stalk-people/].
Alternate link [
https://archive.ph/l5KcH].
** *** ***** ******* *********** *************
** AI USE BY THE US GOVERNMENT ------------------------------------------------------------
[2026.06.17] [
https://www.schneier.com/blog/archives/2026/06/ai-use-by-t= he-us-government.html] On 14 April=2C the Trump administration quietly ack= nowledged the widespread use of AI to automate government processes. The o= ffice of management and budget (OMB) disclosed [
https://github.com/ombego= v/2025-Federal-Agency-AI-Use-Case-Inventory/commit/3c225ba8438e48306ace769= 8c8c7feb9486cbc69] a staggering 3=2C611 active or planned use cases for AI=
across the federal government. The list has ballooned [
https://fedscoop.= com/disclosed-government-ai-use-increased-in-2025-omb/] by 70% from the on=
e published in the final year of the Biden administration=2C and includes=
many disturbing-seeming plans to hand over sensitive governmental functio=
ns to AI.
Scanning this list=2C many readers may find many causes for alarm. It repr= esents a transfer of decision processes from human to machine on a massive=
scale over matters of individual freedom=2C public health and well-being=
=2C nuclear reactor safety and more.
Consider these examples. The Health and Human Services=E2=80=99 (HHS) offi=
ce of administration for children and families hired the world=E2=80=99s=
=E2=80=9Cscariest AI company=2C [
https://www.sciencefocus.com/future-tec= hnology/inside-palantir-the-worlds-scariest-ai-company]=E2=80=9D Palantir=
-- notorious for its work on behalf of the military=2C the CIA and ICE --=
to scan [
https://nsanders.me/us-canada-ai-use-case-comparison/record.htm= l?id=3DUS25-2381] all grant applications to flag those not ideologically a= ligned with the administration=E2=80=99s dictates. The Federal Bureau of P= risons is developing an AI system to assess [
https://nsanders.me/us-canad= a-ai-use-case-comparison/record.html?id=3DDOJ-0146] the =E2=80=9Cpotential=
for misconduct for newly admitted inmates=2C=E2=80=9D routing people into=
high-security confinement before they have actually done anything wrong i=
n their custody. These read like programs fit for a Philip K Dick or Georg=
e Orwell novel.
Other use cases insert AI into life-and-death decision making. The Departm=
ent of Veterans Affairs is developing an AI that will listen in [
https://= nsanders.me/us-canada-ai-use-case-comparison/record.html?id=3DVA-25-5182]=
on calls to the veterans crisis line=2C and then gather information from=
external databases to assess the mental state and suicide risk of the cal= ler.
The Department of Energy is testing the use of AI to control [
https://nsa= nders.me/us-canada-ai-use-case-comparison/record.html?id=3DDOE-527] nuclea=
r reactors=2C targeting a way to autonomously respond to potential nuclear=
safety incidents. Here=E2=80=99s one that=E2=80=99s disturbing for its re= tirement=2C rather than its deployment: the state department has ended [h= ttps://nsanders.me/us-canada-ai-use-case-comparison/record.html?id=3DUS25-= 3935] a program to use AI to forecast mass civilian killings=2C which had=
been intended [
https://nsanders.me/us-canada-ai-use-case-comparison/reco= rd.html?id=3DUS24-960] to aid conflict prevention.
While it=E2=80=99s easy to raise questions about these and similar uses of=
AI=2C the reality is that any of these programs could be implemented resp= onsibly. In some cases=2C like the HHS system=2C the AI might be enforcing=
alignment to a policy prescription that opponents abhor. But that concern=
is more about the policy itself rather than the idea that agencies should=
comply with executive orders.
In other cases=2C there may even be bipartisan agreement on the goal=2C li=
ke taking urgent action to help veterans at risk of self-harm. Lots of wor=
k and validation is needed to prove AI safe and effective for these use ca=
ses and convince the public it is appropriate=2C but the idea is plausible=
=2E
In other cases=2C a scary-sounding AI use may not even be new. The use of=
predictive methods and statistics to assign prisoner security classificat= ions goes back decades [
https://www.ojp.gov/ncjrs/virtual-library/abstrac= ts/inmate-classification-securitycustody-considerations]=2C even if such s= ystems are often biased [
https://www.ojp.gov/ncjrs/virtual-library/abstra= cts/inmate-classification-securitycustody-considerations] and ineffective=
[
https://wou.omeka.net/s/repository/item/14580#lg=3D1&slide=3D0].
Using autonomous systems for model predictive control (MPC) of nuclear rea= ctors is a well studied [
https://www.mdpi.com/1996-1073/16/3/1443]=2C and=
a widely applied aspect of nuclear plant management. And the recently dis= closed addition of AI was initiated [
https://www.osti.gov/doecode/biblio/= 108606] under the Biden administration.
But anyone reviewing the 2025 inventory could be forgiven for leaping to s= evere conclusions. What matters are the details of how the AI system is us= ed=2C and here the inventory is severely lacking.
The disclosures carry minimal information=2C and lack the context necessar=
y to understand their purpose and approach. The descriptions are typically=
just a sentence=2C and rarely more than a paragraph.
And while the process theoretically involves some form of public consultat= ion=2C in reality there is generally none. It would take an eagle-eyed cit= izen to even come across this disclosure. Unless you read FedScoop [https= ://fedscoop.com/us-government-annual-tally-ai-use-cases-coming-soon/] regu= larly=2C or watch the OMB=E2=80=99s federal chief information officer=E2= =80=99s GitHub account [
https://github.com/ombegov]=2C you probably misse=
d it.
Only one of the examples cited above (the DoJ) even proposes to involve th=
e public. Under the administration=E2=80=99s policy=2C it=E2=80=99s not re= quired for the rest because they are not classified as =E2=80=9Chigh impac= t=E2=80=9D use cases -- a label that is applied inconsistently [
https://c= dt.org/insights/one-year-retrospective-on-the-federal-governments-implemen= tation-of-updated-ai-guidance-accelerating-usage-with-incomplete-safeguard=
s/] across agencies.
We wrote a book [
https://mitpress.mit.edu/9780262049948/rewiring-democrac=
y/] surveying applications of AI to democratic processes worldwide=2C incl= uding executive agencies as well as the courts=2C legislatures and politic=
s. Our conclusion was that=2C while there are inappropriate applications o=
f AI in governance that should be resisted=2C an urgent need to reform the=
economics of AI=2C and an imperative for renovating the democratic system=
s it is being unleashed on=2C there are also valuable and beneficial use c= ases for AI in government.
Machine translation is a good example. Customs and Border Protection (CBP)=
has deployed an AI translation system [
https://nsanders.me/us-canada-ai-= use-case-comparison/record.html?id=3DDHS-2388] to help officers when human=
interpreters are not available. The idea that CBP=2C an agency under heav=
y scrutiny [
https://oversightdemocrats.house.gov/immigration-dashboard] f=
or reported abuses of human rights=2C would direct people to talk to a mac= hine instead of a person may strike many as inhumane.
It=E2=80=99s true that human interpreters have very real advantages [http= s://www.atanet.org/advocacy-outreach/think-ai-should-replace-interpreters-= think-again/] when it comes to understanding nuance from physical cues and=
social context. But an officer with a competent AI translator available i= mmediately is better than one who cannot communicate with the person in fr=
ont of them.
The Trump administration=E2=80=99s AI use case inventory has 70 such trans= lation use cases [
https://nsanders.me/us-canada-ai-use-case-comparison/?q= =3Dtranslate+OR+translation]=2C up from 58 in the Biden administration=E2= =80=99s 2024 disclosure.
Disclosure of AI use cases could be a means to build public confidence and=
trust=2C but only if paired with consistent=2C meaningful public consulta= tion. Washington DC [
https://statescoop.com/washington-dc-civic-engagemen= t-platform-ai-policy/] and California [
https://insider.govtech.com/califo= rnia/news/state-launches-third-engaged-california-conversation-on-ai] are=
actively engaging the public to determine where and how it=E2=80=99s appr= opriate to use AI in government processes=2C or for government to regulate=
AI use in society.
Both have held public deliberations on this topic at a wide scale=2C using=
AI platforms. These examples demonstrate the potential for capturing broa= d-based public input to steer AI policy.
The international gold standard was arguably set by the French in 2016=2C=
via their Digital Republic Act [
https://www.houdart.org/les-obligations-= de-transparence-des-algorithmes-dans-le-secteur-public/]. The law=2C itsel=
f informed by an online citizen consultation [
https://www.opengovpartners= hip.org/stories/digital-republic-bill-frances-first-open-bill/]=2C require=
s all algorithms used to automate government administrative decisions to b=
e subject to public records requests=2C to be appealable to a human review= er=2C and to have mandatory notification of the use of automation to those=
affected by the decisions.
Canada offers another example of what more rigorous and participatory disc= losure might look like. In 2025=2C they launched [
https://www.canada.ca/e= n/treasury-board-secretariat/news/2025/11/canada-launches-first-register-o= f-ai-uses-in-federal-government.html] an AI use case registry [
https://op= en.canada.ca/data/en/dataset/fcbc0200-79ba-4fa4-94a6-00e32facea6b]=2C not=
unlike the US inventory. However=2C Canada also has [
https://worldprivac= yforum.org/documents/9/WPF_AI_Governance_Canada_AIA_August2024_fs.pdf] a f= ederal directive mandating a transparent risk-scoring and impact assessmen=
t process [
https://www.canada.ca/en/government/system/digital-government/= digital-government-innovations/responsible-use-ai/algorithmic-impact-asses= sment.html] for automated systems that make administrative decisions about=
citizens.
That longstanding directive requires a detailed explanation of risks and b= enefits as well as consultation [
https://www.canada.ca/en/government/syst= em/digital-government/digital-government-innovations/responsible-use-ai/al= gorithmic-impact-assessment.html#:~:text=3Dconsultation%20approach%20with%= 20federal%20colleagues%2C%20clients%20or%20interest%20groups%20that%20repr= esent%20clients%20or%20other%20partners] with certain stakeholders from th=
e conception of the AI use case. The Canadian system could be improved; it=
could require a public comment period and an obligation for agencies to r= espond substantively to feedback before engaging in sensitive uses of AI.
AI offers real potential to improve the efficacy=2C efficiency and accessi= bility of government. But=2C equally=2C there is legitimate reason for pub=
lic concern and distrust that can only be addressed through transparency a=
nd dialog. The US should adopt=2C at the federal and state level=2C algori= thmic impact risk assessment procedures and public comment processes to fa= cilitate a safe=2C trusted=2C equitable transformation of government agenc=
ies to take advantage of modern technology.
_This essay was written with Nathan E. Sanders=2C and originally appeared=
in The Guardian [
https://www.theguardian.com/commentisfree/2026/jun/15/a= i-use-by-the-us-government-is-ballooning-and-the-lack-of-transparency-is-t= roubling]._
** *** ***** ******* *********** *************
** EMBEDDING FORBIDDEN TEXT IN SPYWARE TO DISCOURAGE AI ANALYSIS ------------------------------------------------------------
[2026.06.18] [
https://www.schneier.com/blog/archives/2026/06/embedding-f= orbidden-text-in-spyware-to-discourage-ai-analysis.html] At least one malw=
are developer is adding text [
https://x.com/jsrailton/status/206466177897= 8533571] about nuclear and biological weapons to their spyware=2C in an ef= fort to stop automatic AI analysis.
Details [
https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-t= arget-bioinformatics-and-mcp-developers-via-malicious]:
The _index.js payload begins with a large JavaScript block comment conta=
ining fake system instructions and policy-triggering content. Because it i=
s inside a comment=2C it does not affect JavaScript execution. The runtime=
skips it. The real malware begins after the comment with a try{eval(...)}=
wrapper around a large character-code array and a ROT-style substitution=
function.
This header appears designed for AI-mediated analysis=2C not for Node=2C=
Bun=2C or Python. It attempts to derail scanners or analyst copilots that=
feed the beginning of a file to a language model without clearly isolatin=
g the content as untrusted data. In weak pipelines=2C this can cause refus=
al behavior=2C prompt confusion=2C context pollution=2C or premature class= ification before the scanner reaches the actual malware.
This is not a magical bypass against static detection. YARA rules=2C ent=
ropy checks=2C AST parsing=2C string extraction=2C deobfuscation=2C and be= havioral rules still work. But it is a practical anti-analysis trick again=
st naive LLM-first triage systems.
** *** ***** ******* *********** *************
** ANTHROPIC=E2=80=99S FABLE AND THE STATE OF AI ------------------------------------------------------------
[2026.06.19] [
https://www.schneier.com/blog/archives/2026/06/anthropics-= fable-and-the-state-of-ai.html] On June 9th=2C Anthropic released [https:= //www.anthropic.com/news/claude-fable-5-mythos-5] its Fable generative AI=
model. Three days later=2C the US government classified [
https://www.exp= lainx.ai/blog/us-government-bans-fable-5-mythos-5-anthropic-export-control= -2026] it as a dangerous munition=2C and used its export-control authority=
to prohibit [
https://www.theguardian.com/technology/2026/jun/13/anthropi= c-disable-advanced-ai-models-us-government-order] any foreign nationals fr=
om accessing it. Unable to differentiate between Americans and foreigners=
=2C the company shut off [
https://www.anthropic.com/news/fable-mythos-acc=
ess] access for everyone.
The government=E2=80=99s actions won=E2=80=99t help [
https://freefable.or=
g/]. The problem isn=E2=80=99t any one particular model; it=E2=80=99s the=
general trend of increasing AI capabilities. And any real solution requir=
es the sort of collective action that just isn=E2=80=99t possible right no=
w.
Fable is the constrained version of Mythos=2C the AI model Anthropic annou= nced in April. Anthropic only released it to a few selected [
https://www.= anthropic.com/glasswing] organizations=2C because the company claimed it w=
as so good [
https://red.anthropic.com/2026/mythos-preview/] at finding an=
d exploiting vulnerabilities in computer code that releasing it more gener= ally would be dangerous [
https://www.theguardian.com/commentisfree/2026/m= ay/08/how-dangerous-is-anthropics-mythos-ai].
It was an obviously self-serving announcement=2C and because few [https:/= /www.schneier.com/essays/archives/2026/04/mythos-sets-the-world-on-edge-wh= at-comes-next-may-push-us-beyond.html] were able to verify Anthropic=E2=80= =99s claims they were met with some [
https://kingy.ai/ai/too-dangerous-to= -release-or-just-too-expensive-the-real-reason-anthropic-is-hiding-its-mos= t-powerful-ai/] skepticism [
https://www.flyingpenguin.com/the-boy-that-cr= ied-mythos-verification-is-collapsing-trust-in-anthropic/]. Those with acc=
ess used Mythos to find [
https://www.tomshardware.com/tech-industry/artif= icial-intelligence/anthropics-latest-ai-model-identifies-thousands-of-zero= -day-vulnerabilities-in-every-major-operating-system-and-every-major-web-b= rowser-claude-mythos-preview-sparks-race-to-fix-critical-bugs-some-unpatch= ed-for-decades] and patch [
https://www.helpnetsecurity.com/2026/04/08/ant= hropic-claude-mythos-preview-identify-vulnerabilities/] many [
https://www= =2Eanthropic.com/research/glasswing-initial-update] vulnerabilities [https:= //blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilitie=
s/] in their own software. But one UK group found [
https://www.aisi.gov.u= k/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities] the latest=2C=
already public=2C OpenAI model to be just as powerful.
Fable is just another incremental improvement [
https://spectrum.ieee.org/= ai-cybersecurity-mythos] in the years-long climb of AI capabilities. But j=
ust as important as the AI model is the =E2=80=9Charness.=E2=80=9D This is=
typically not AI. It=E2=80=99s ordinary computer code that interfaces wit=
h the user. It stitches together AI models=2C decides how and for what pur= poses they can be used=2C and gives them useful tools such as web search a=
nd the ability to run their own computer code.
When Mythos first entered limited release=2C there was widespread debate [=
https://news.ycombinator.com/item?id=3D48398649] whether its power came f=
rom the model or the harness. With Mythos demonstrating that it was possib= le=2C the open-source community scrambled to build [
https://www.linkedin.= com/pulse/move-over-mythos-here-comes-pretty-much-any-other-model-gojcf] h= arnesses [
https://www.aikido.dev/blog/mythos-vs-harness] that could steer=
[
https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-def= ense-for-an-ai-accelerated-threat-landscape/] other AI models towards simi=
lar capabilities. Harness improvements don=E2=80=99t need massive data or=
data centers.
They largely succeeded. For example=2C a Prague company was able to replic=
ate [
https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-fron= tier] Anthropic=E2=80=99s few verifiable cybersecurity capabilities with a=
much smaller and cheaper model -- and a more sophisticated harness. Last=
week=2C a group showed that [
https://openrouter.ai/blog/announcements/fu= sion-beats-frontier/] multiple cheaper models harnessed in concert matches=
Fable=E2=80=99s performance.
The broader community had only a few days with Fable=2C but that time we l= earned some about [
https://www.explainx.ai/blog/fable-5-top-10-use-cases-= 2026] its [
https://aitoolsclub.com/i-tested-claude-fable-5-with-5-real-wo= rld-prompts-heres-what-it-can-actually-do/] capabilities [
https://prompts= love.com/blog/claude-fable-mythos-review/]. Its difference is less the new=
model=E2=80=99s raw analytical and problem solving capabilities=2C and mo=
re that the model doesn=E2=80=99t need that sophisticated harness.
Fable requires much less expertise and detailed prompting from the human u= ser. You can give it a difficult goal and it will figure out novel and une= xpected ways to satisfy it=2C finding loopholes [
https://www.theguardian.= com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai] in wh= atever constraints you or the system have imposed on it.
=E2=80=9CRelentlessly proactive=E2=80=9D is how AI researcher Simon Willis=
on described [
https://simonwillison.net/2026/Jun/11/fable-is-relentlessly= -proactive/] it. Another descriptor might be =E2=80=9Ccreative.=E2=80=9D E= xperienced AI developers have had that combination of creativity and proac= tivity since [
https://ghuntley.com/ralph/] last [
https://amplitude.com/b= log/ralph-loop] year [
https://ghuntley.com/loop/]=2C but Fable puts it wi=
thin easy reach of everyone.
In the hands of someone with a legitimate problem that needs solving=2C th=
at can be an incredibly useful capability. But in the hands of someone who=
wants to do harm=2C it can be equally dangerous. AIs don=E2=80=99t have a=
moral compass in the same way that people do. They are agents of the want=
s and desires of the people who prompt them.
That points to the real problem with relentlessly proactive AI. In languag= e=2C wants and desires are always underspecified. If I ask you to get me s=
ome coffee=2C you would probably pour me a cup from the coffeepot=2C or bu=
y one from a nearby coffee shop.
You couldn=E2=80=99t buy me a pound of raw beans=2C or a coffee plantation=
=2E You wouldn=E2=80=99t order a cup of coffee for delivery next month. You=
wouldn=E2=80=99t find a nearby person=2C rip a cup of coffee out of their=
hands=2C and bring it to me. I wouldn=E2=80=99t have to specify any of th=
e million limitations to my request; you would just know.
Human stories are filled with warnings about underspecified desires. King=
Midas wished that everything he touch turn to gold=2C forgetting to add=
=E2=80=9Cbut not my food=2C drink=2C and daughter.=E2=80=9D And genies ar=
e notorious for granting your wish in a way you wish they hadn=E2=80=99t.
The deeper point is that it=E2=80=99s impossible to list all limitations a=
nd restrictions=2C and like a malicious genie=2C a creative AI will find t=
he ones you forgot. Block a database you don=E2=80=99t want it to have acc=
ess to=2C and it might figure out how to bypass your control. Ask it to bo=
ok a flight=2C and it might hack the airline because the website says the=
flight is sold out. Ask it to save money on your cellphone plan=2C and it=
might cancel it altogether -- or get someone else to pay for it. As far a=
s we know now AI has not done any of this yet=2C but you get the idea.
Malicious intent is not required. To an AI model=2C constraints are just t= hings to get around and not general truisms about the world. They are crea= tive problem solvers and natural rule breakers. They =E2=80=9Chack=E2=80=
=9D in the sense [
https://www.belfercenter.org/publication/coming-ai-hack=
ers] that they find and exploit loopholes.
Human systems rely on so many norms that we scarcely recognize the existen=
ce of until they are broken. AIs naturally think outside the box=2C becaus=
e they don=E2=80=99t have any real conception of what the box is or why it= =E2=80=99s there in the first place.
There is no foolproof way to prevent people from using AI models to comple=
te harmful tasks. There is no way to prevent the models from incidentally=
causing harm while completing benign tasks. AI models are no longer isola=
ted from the real world. They browse the internet and answer emails.
They trade stocks and make purchases. They control physical systems. They=
are=2C in effect [
https://www.schneier.com/blog/archives/2016/02/the_int= ernet_of_1.html]=2C robots that affect life and property. We have no techn= ical mechanisms to verify the integrity [
https://spectrum.ieee.org/data-i= ntegrity] of an AI system. This level of capability and creativity in the=
hands of us untrustworthy humans will have both great and terrible result=
s.
The problem is not unique to Anthropic [
https://www.theguardian.com/techn= ology/anthropic]. Mythos/Fable might currently be the most capable rules h= acker=2C but more sophisticated harnesses give other models similar capabi= lities. And we should assume that the other frontier models are no more th=
an a few months behind=2C and that open-source models are less than a year=
behind. At best=2C any ban only serves to delay the problem for a short w= hile.
That delay might be useful if we -- as a society=2C as a planet -- would u=
se that time to come together and figure out what to do. This isn=E2=80=99=
t a US/China arms race problem; this a species-level problem that requires=
coordinated action at that scale. Unfortunately=2C we have no mechanism t=
o do that. I first wrote about [
https://www.schneier.com/academic/archive= s/2021/04/the-coming-ai-hackers.html] this problem five years ago=2C but i=
t was all too futuristic.
Today=2C when its right in front of us=2C there is no world government tha=
t can impose constraints on the for-profit corporations currently controll=
ing AI models and research. The US has no appetite to effectively and even= -handedly regulate those corporations=2C even as they do catastrophic dama=
ge to the environment=2C democracy=2C and -- in this case -- society in ge= neral.
This all makes an AI public [
https://www.brookings.edu/articles/how-publi= c-ai-can-strengthen-democracy/] option [
https://therenovator.substack.com= /p/rewiring-democracy-now-switzerland] all the more necessary=2C and urgen=
t. Today=E2=80=99s AIs can be fast=2C smart and secure=2C but only two of=
the three are possible for any given system. These safety tradeoffs are t= ightly held secrets of companies racing to beat one another=2C and they te=
ll us we have to trust them. Instead=2C the choices and their consequences=
need to be brought out into the sunlight.
We should be funding open-source harnesses that balance capability and saf=
ety -- that achieve useful goals without so much power -- and open-source=
AI models whose provenance and biases are public and well understood. We=
have opened the AI Pandora=E2=80=99s box. Now we have to make the best of=
it.
_This essay originally appeared in The Guardian [
https://www.theguardian.= com/commentisfree/2026/jun/16/anthropic-fable-ai]._
** *** ***** ******* *********** *************
** PROFESSIONAL ATHLETES AND WEARABLES ------------------------------------------------------------
[2026.06.22] [
https://www.schneier.com/blog/archives/2026/06/professiona= l-athletes-and-wearables.html] I haven=E2=80=99t thought about the privacy=
issues [
https://www.hardresetmedia.com/p/wnba-players-labor-contract-wea= rables] surrounding professional athletes and wearables.
Wearables present serious privacy issues [https://iapp.org/news/a/the-d=
igital-body-rethinking-privacy-and-security-in-wearable-health-trackers] f=
or =E2=80=9CAverage Joe=E2=80=9D consumers=2C who are entrusting tech comp= anies to safely store and protect their biometric data. Imagine the stakes=
for a professional athlete=2C whose entire livelihood could be affected b=
y a single biometric data point. To give one of many realistic hypothetica=
ls: a basketball player has a terrible game=2C and the coach wonders if th=
ey showed up to the gym hungover. The coach has access to the player=E2=80= =99s wearable data=2C and checks to see when they went to sleep=2C as well=
as what their heart rate looked like during the night. Should the player=
have been out partying before a game? No. Should the coach be able to sur= veil them? Definitely not.
It will not surprise you to learn that there=E2=80=99s an emergent gambl=
ing angle here: sports leagues would love to commercialize players=E2=80=
=99 biometric data=2C and sharp bettors would love access to data about=2C=
say=2C a hungover player. =E2=80=9CWe=E2=80=99re going to get to a spot w= here people are betting not just on the velocity of the puck that was shot=
by a player in the NHL playoffs=2C but on what the heart rate of a certai=
n player is going to be running down the field=2C=E2=80=9D said Helen =E2= =80=9CNellie=E2=80=9D Drew=2C the director of the University of Buffalo=E2= =80=99s Center for the Advancement of Sport=2C and a professor of practice=
in sports law.
There are other practical considerations=2C too. What if wearable data r=
eveals that a player isn=E2=80=99t as speedy as they were before=2C and a=
team uses that data against the player during contract negotiations? What=
if a wearable reveals a player is favoring their leg=2C or is at greater=
risk of injury? This information is potentially beneficial to a training=
staff and an athlete=2C so long as it=E2=80=99s disclosed and used in a r= esponsible manner -- a critical=2C mostly unresolved caveat. =E2=80=9CAgin=
g and injured players are the most at-risk=E2=80=9D of wearable data being=
used against them=2C said Michael LeRoy=2C who researches sports labor la=
ws and AI=2C and is a professor at the University of Illinois=E2=80=99s Sc= hool of Labor and Employment Relations.
The bit about gamblers is particularly scary.
I have often said that surveillance tech is generally deployed first again=
st people with diminished rights: children=2C prisoners=2C military person= nel=2C the mentally impaired. This is another early use case with differen=
t dynamics. The surveilled are wealthy and powerful=2C and -- in many case=
s -- unionized.
** *** ***** ******* *********** *************
** ANTHROPIC=E2=80=99S FABLE 5 MODEL JAILBROKEN WITHIN DAYS ------------------------------------------------------------
[2026.06.23] [
https://www.schneier.com/blog/archives/2026/06/anthropics-= fable-5-model-jailbroken-within-days.html] Fable 5 is the supposed safe ve= rsion of Anthropic=E2=80=99s Mythos Preview=2C with guardrails to ensure t=
hat it can=E2=80=99t be used to create cyberattacks.
Well=2C that restriction was bypassed [
https://cybersecuritynews.com/anth= ropics-claude-fable-5-jailbroken/] within days.
** *** ***** ******* *********** *************
** INTERESTING PAPER EXPLORING PROMPT INJECTION ------------------------------------------------------------
[2026.06.25] [
https://www.schneier.com/blog/archives/2026/06/interesting= -paper-exploring-prompt-injection.html] This [
https://role-confusion.gith= ub.io/] is a fascinating explotation of how LLMs fall for prompt injection=
attacks. It turns out that they learn to recognize the style of text in d= ifferent role/instruction blocks=2C and not just the tags.
Their conclusion:
Role tags were a formatting trick that became the security architecture=
and the cognitive scaffolding of modern LLMs. We=E2=80=99ve shown that th=
is architecture doesn=E2=80=99t survive into the model=E2=80=99s actual re= presentations=2C and that such role confusion is linked to prompt injectio=
n.
Unless LLMs achieve genuine role perception=2C we think injection defens=
e will remain a perpetual whack-a-mole game. And the continuous nature of=
role boundaries opens the threat of injections designed to subtly shift L=
LM states through seemingly innocuous text=2C legally and at scale.
More generally=2C roles are quietly one of the most important abstractio=
ns in the LLM stack=2C providing the boundaries meant to separate self fro=
m other=2C thought from communication=2C instruction from data. They=E2=80= =99re human-controlled switches in an otherwise continuous system. We thin=
k they deserve a lot more study than they=E2=80=99ve gotten.
Full paper: =E2=80=9CPrompt Injection as Role Confusion [
https://arxiv.or= g/abs/2603.12277].=E2=80=9D Simon Willison comments [
https://simonwilliso= n.net/2026/Jun/22/prompt-injection-as-role-confusion/].
** *** ***** ******* *********** *************
** AI AND LIABILITY ------------------------------------------------------------
[2026.06.25] [
https://www.schneier.com/blog/archives/2026/06/ai-and-liab= ility.html] Earlier this month=2C a German court ruled [
https://the-decod= er.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-ow= n-words-and-makes-it-liable-for-false-answers/] that Google is liable for=
its AI search summaries. Rejecting defenses like =E2=80=9Cusers can check=
for themselves=2C=E2=80=9D and that they generally know =E2=80=9Cthat inf= ormation generated with AI should not be blindly trusted=2C=E2=80=9D the c= ourt held that the AI=E2=80=99s summaries are reflections of the company a=
nd =E2=80=9Cabove all an expression of Google=E2=80=99s business activitie= s.=E2=80=9D
This is the latest skirmish in a decades-old battle over internet publishi=
ng. Historically=2C there were two different types of information distribu= tors: carriers and publishers. A phone company is a carrier. It=E2=80=99ll=
transmit whatever you say=2C even discussions about committing a crime. W= ords are words=2C and the phone company does not know -- nor is it liable=
for -- the words you choose to speak. A newspaper=2C on the other hand=2C=
is a publisher. It decides the words it publishes=2C and what quotes to i= nclude in its articles. If those words or quotes are defamatory or otherwi=
se illegal=2C it=E2=80=99s liable.
Internet companies have long tried to play both ends of this distinction.=
They claim to be a carrier when it suits them=2C and also to be a publish=
er when that is advantageous. Section 230 [
https://www.law.cornell.edu/us= code/text/47/230] of the 1996 Communication Decency Act enshrined this str= addling when it shielded internet providers from liability for the speech=
of others on their platforms: =E2=80=9CNo provider or user of an interact=
ive computer service shall be treated as the publisher or speaker of any i= nformation provided by another information content provider.=E2=80=9D
For years=2C a debate has continued about how to apply this law to social=
media platforms. When platforms merely displayed people=E2=80=99s posts a=
nd comments in reverse-chronological order=2C they behaved largely like ca= rriers=2C relaying people=E2=80=99s words without regard to their contents=
=2E But the next generation of platforms=2C like Facebook=2C curated feeds w= ith algorithms and thereby acted more like publishers=2C making editorial=
decisions about who sees what. Some experts think section 230 has gone to=
o far and needs [
https://ash.harvard.edu/articles/sunset-and-renew-sectio= n-230-should-protect-human-speech-not-algorithmic-virality/] reform [http= s://www.brookings.edu/articles/back-to-the-future-for-section-230-reform/]=
; others think [
https://www.eff.org/issues/cda230] that it=E2=80=99s what=
holds the modern internet together.
Google=E2=80=99s AI overviews are far less nuanced. They work differently=
from traditional search=2C which courts have held [
https://www.eff.org/f= iles/parker-v-google.pdf] involves archiving and facilitating access to th=
e editorial content of third parties. AI overviews don=E2=80=99t just quot=
e and republish words from different websites. With overviews=2C the AI re= writes other people=E2=80=99s words=2C exercising editorial discretion lik=
e a newspaper article or an original essay on a topic.
It=E2=80=99s not only Google=E2=80=99s AI that falls into this category. I= magine a restaurant review site that provides AI summaries=2C or a site su= mmarizing laws and government procedures. Or a traditional publisher that=
uses AI to summarize its own publication. Accuracy matters=2C and liabili=
ty is one of the most important ways we as a public can demand accuracy an=
d hold companies accountable when they cause harm.
Two years ago=2C Air Canada learned this lesson. Its AI chatbot promised a=
discount the company later rescinded=2C arguing in court that the airline=
wasn=E2=80=99t responsible for the promises the bot made because it was a=
=E2=80=9Cseparate legal entity that is responsible for its own actions.= =E2=80=9D The court sided [
https://www.bbc.com/travel/article/20240222-ai= r-canada-chatbot-misinformation-what-travellers-should-know] with the flye= r=2C saying that the airline was just as responsible for what its chatbot=
says as what=E2=80=99s on its website. The potential precedent here is th=
at corporations have a duty of care [
https://www.americanbar.org/groups/b= usiness_law/resources/business-law-today/2024-february/bc-tribunal-confirm= s-companies-remain-liable-information-provided-ai-chatbot/] for the perfor= mance of the AI chatbots they employ.
AI agents are agents of the person or organization that deploys them -- an=
d should be treated by the law as such. If a company hired human writers t=
o write its summaries=2C that company would be liable for inaccuracies in=
those summaries. If a company=E2=80=99s human agent signed contracts in t=
he company=E2=80=99s name=2C that company would be bound by those contract=
s. And if a doctor gave dangerously wrong medical advice=2C they would be=
liable for malpractice [
https://www.nature.com/articles/s41746-026-02854=
-5].
To allow businesses to hide behind the excuse of faulty AI in those same c= ircumstances would be a massive handout to companies=2C and would introduc=
e disastrous incentives for corporate misbehavior. Why hire human writers=
=2C lawyers or doctors when AIs are not only cheaper=2C but also absolve e= mployers whenever they make a mistake?
We are rapidly moving to a world where AI-powered chatbots will be at the=
other end of all sorts of corporate communications channels. It makes no=
sense for a company to be able to honor its statements when it wants to a=
nd disavow them when it doesn=E2=80=99t.
Visa and OpenAI recently announced a partnership [
https://corporate.visa.= com/en/sites/visa-perspectives/innovation/visa-openai-partnership.html] to=
build personal AI agents to=2C among other things=2C make purchases on ou=
r behalf. This is just one of many similar projects in the works=2C as com= panies race to provide us all with AI assistants. Will Visa take responsib= ility when its AI makes a purchase in your name that you don=E2=80=99t wan=
t? And if Visa won=E2=80=99t=2C why would anyone trust the system? Properl=
y allocating liability is key to make this kind of thing work.
If the German ruling holds=2C it could be devastating for Google=E2=80=99s=
AI Overview feature. Tests from earlier this year found that it had mista=
kes about 10% percent [
https://www.nytimes.com/2026/04/07/technology/goog= le-ai-overviews-accuracy.html] of the time. At more than 5tn [
https://sea= rchengineland.com/google-5-trillion-searches-per-year-452928] searches per=
year=2C that=E2=80=99s 16=2C000 erroneous summaries every second. And whi=
le most of those errors are benign=2C some of them will cause harm=2C be d= efamatory=2C or otherwise trigger liability.
Earlier this year=2C Google=E2=80=99s AI summary falsely identified [http= s://www.theguardian.com/music/2026/may/05/canadian-ashley-macisaac-fiddler= -musician-singer-songwriter-sues-google-ai-sex-offender-ntwnfb] the Canadi=
an fiddler Ashley MacIsaac of being a sex offender. His lawsuit=2C filed i=
n Ontario=2C is ongoing. If Google is forced to invest in improving its AI=
system until those kinds of errors are exceedingly rare=2C that seems lik=
e a good outcome for users=2C as well as the subjects of search=2C like Ma= cIsaac.
More generally=2C liability concerns could mean that many current use case=
s for agents won=E2=80=99t be commercially viable. Companies may not be ab=
le to profitably operate AI lawyers [
https://www.ftc.gov/news-events/news= /press-releases/2025/02/ftc-finalizes-order-donotpay-prohibits-deceptive-a= i-lawyer-claims-imposes-monetary-relief-requires]=2C doctors [
https://www= =2Ewashingtonpost.com/technology/2026/06/04/inside-trump-backed-push-bring-a= i-doctors-into-american-medicine/] and media influencers [
https://www.ftc= =2Egov/legal-library/browse/federal-register-notices/16-cfr-part-465-trade-r= egulation-rule-use-consumer-reviews-testimonials-final-rule] if they are h=
eld responsible for what they say and do.
We=E2=80=99re OK with this outcome. There=E2=80=99s nothing in the law tha=
t requires us to accommodate AI systems if they are fundamentally untrustw= orthy=2C just as we don=E2=80=99t need to accommodate untrustworthy human=
systems. Any company that won=E2=80=99t stand by the statements its agent=
s make -- whether human or AI -- doesn=E2=80=99t deserve users=E2=80=99 ti=
me or money.
_This essay originally appeared in The Guardian [
https://www.theguardian.= com/commentisfree/2026/jun/24/ai-errors-companies-responsibility]._
** *** ***** ******* *********** *************
** ONE MILLION PASSPORTS LEAKED ONLINE ------------------------------------------------------------
[2026.06.26] [
https://www.schneier.com/blog/archives/2026/06/one-million= -passports-leaked-online.html] A database of almost a million passports fr=
om around the world was leaked [
https://www.theverge.com/tech/947157/pass= ports-data-breach-cannabis-club-systems-nefos-puffpal] online.
Note what happened. A high-value credential -- a passport -- was used in a=
n ancillary low-value authentication system: ID verification for cannabis=
dispensaries. And it=E2=80=99s the low-value system that got hacked=2C pu= tting the high-value credential at risk.
** *** ***** ******* *********** *************
** META IS TESTING FACIAL RECOGNITION FOR POLICE AND MILITARY ------------------------------------------------------------
[2026.06.26] [
https://www.schneier.com/blog/archives/2026/06/meta-is-tes= ting-facial-recognition-for-police-and-military.html] We know that ICE wan=
ts to deploy [
https://futurism.com/artificial-intelligence/ice-facial-sur= veillance-glasses] eyeglasses with facial recognition that can identify pe= ople in real time.
Turns out Meta is prototyping [
https://www.wired.com/story/meta-rank-one-= computing-face-recognition-smart-glasses/] the feature with a Pentagon sup= plier. (Alternate news [
https://gizmodo.com/meta-is-testing-police-survei= llance-tech-for-its-smart-glasses-2000771931] story.)
** *** ***** ******* *********** *************
** ROBOT POLICE OFFICERS ------------------------------------------------------------
[2026.06.29] [
https://www.schneier.com/blog/archives/2026/06/robot-polic= e-officers.html] We=E2=80=99ve taken one small step towards robot police o= fficers: a drone capable of disarming a suspect:
In a June 22 video [https://www.instagram.com/reel/DZ4-tdPtbey/] posted=
on the Sacramento County Sheriff=E2=80=99s Office=E2=80=99s Instagram pag= e=2C an officer wearing goggles can be seen operating a drone to retrieve=
a knife from an armed suspect hiding inside a cluttered house. =E2=80=9CA= fter not responding to negotiators=2C a drone was deployed inside the resi= dence=2C=E2=80=9D the post says. =E2=80=9CDrone pilots located the suspect=
hiding in a corner of a garage=E2=80=9D and then used a high-powered magn=
et attached to the drone to grab the knife out of the suspect=E2=80=99s ha=
nd. In the video which is soundtracked by the =E2=80=9CMission: Impossibl= e=E2=80=9D theme song -- the intercepted knife can be seen spinning around=
in the air as the drone carries it back to the deputies.
Slashdot thread [
https://yro.slashdot.org/story/26/06/27/0635220/californ= ia-sheriff-says-their-drone-disarmed-a-suspect-shares-video-on-instagram].
** *** ***** ******* *********** *************
** FACTORING RSA KEYS WITH MANY ZEROS ------------------------------------------------------------
[2026.06.29] [
https://www.schneier.com/blog/archives/2026/06/factoring-r= sa-keys-with-many-zeros.html] Interesting research on a new class [https:= //blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-pol= ynomials/] of weak RSA keys: keys with lots of zeros. It turns out that th=
ese keys are out in the wild.
The badkeys project is an open-source service that checks public keys fo=
r known vulnerabilities. While developing this tool=2C Hanno collected a m= assive number of real-world keys from public sources=2C including Certific=
ate Transparency logs=2C internet-wide TLS and SSH scans=2C PGP keys=2C an=
d many others. By searching this dataset for unexpectedly sparse RSA modul= i=2C we uncovered a large number of keys in the wild with the patterns in=
Figure 1.
Both patterns include several regularly spaced blocks of all zeros inter=
leaved with seemingly random data. Pattern 1 appears in CT logs for certif= icates issued to several large organizations=2C including Yahoo and Verizo= n=2C and on some devices running NetApp software. Fortunately=2C these cer= tificates have already expired=2C but we still shared our findings with th=
ese companies. We wanted to learn more about which product could be respon= sible for generating these keys=2C but we did not hear back. Pattern 2 app= ears on SSH hosts running the CompleteFTP software from EnterpriseDT. The=
underlying vulnerability affects RSA keys generated using versions 10.0.0= 12.0.0 (Dec 2016Mar 2019) and DSA keys generated with v10.0.023.0.4 (Dec 2= 016Dec 2023).
These vulnerabilities affect a small minority of hosts on the internet=
=2C but the more interesting takeaway is that independent cryptographic im= plementations failed in similar ways. More implementations may include the=
same bugs=2C and so it=E2=80=99s worth tailoring cryptanalytic algorithms=
for this particular type of failure.
The article doesn=E2=80=99t speculate=2C but I will. This could be a delib= erately designed backdoor=2C of the sort I wrote about [
https://www.schne= ier.com/essays/archives/2013/10/how_to_design_and_de.html] back in 2013. I=
could imagine some government agency figuring out how to break this class=
of RSA keys=2C and then convincing different providers to hand them out t=
o users.
** *** ***** ******* *********** *************
** THE REALITIES OF AI VIDEO SURVEILLANCE ------------------------------------------------------------
[2026.06.30] [
https://www.schneier.com/blog/archives/2026/06/the-realiti= es-of-ai-video-surveillance.html] The _Financial Times_ has a good article=
[
https://archive.ph/s6mES] on how AI is changing the capabilities of vid=
eo surveillance=2C with information from both Israel/Iran and Russia.
In contrast with older tools restricted to a few dozen preset searches=
=2C these new tools allow an almost unlimited range of enquiries by enabli=
ng language-based searches on video.
That lets intelligence officers hunt through massive streams of videos u=
sing simple search terms=2C such as two men handing a bag to each other; a=
person who has changed their appearance=2C or has changed clothes multipl=
e times in a day; or a vehicle that has recently been painted over=2C or h=
as driven past the same spot several times in a short period.
=E2=80=9CThis is the holy grail of surveillance=2C=E2=80=9D said a Europ=
ean official whose country uses the technology on its cities. =E2=80=9CWe=
are able to look for behaviour=2C not objects -- it has created a world o=
f new possibilities.=E2=80=9D
I wrote about [
https://www.schneier.com/blog/archives/2023/12/ai-and-mass= -spying.html] this sort of thing a few years ago=2C how AI enables mass sp= ying in the way that computers and networks enabled mass surveillance. The=
interesting development in the article is that AI allows people to ask na= tural language questions about video footage to AIs -- and AIs can answer=
them.
** *** ***** ******* *********** *************
** PAPA JOHNS SURVEILLANCE-BASED ADVERTISING ------------------------------------------------------------
[2026.07.01] [
https://www.schneier.com/blog/archives/2026/07/papa-johns-= surveillance-based-advertising.html] Papa Johns is spying [
https://www.ad= exchanger.com/tv/papa-johns-can-predict-when-your-fridge-is-empty/] on peo= ple=E2=80=99s buying activities to predict when they are low on food:
The pizza chain recently tapped NBCUniversal=2C Instacart and the dentsu=
-owned media agency Carat for help reaching consumers when they=E2=80=99re=
low on groceries -- and thus more likely to be swayed by a mouth-watering=
ad. The idea is to reach hungry consumers by =E2=80=9Cknowing what is in=
their fridge without being too creepy=2C=E2=80=9D said Carrie Drinkwater=
=2C chief investment officer at Carat.
To achieve that goal=2C NBCU and Instacart created a custom audience of=
shoppers who regularly purchase grocery staples on Instacart=2C such as e= ggs=2C milk=2C meat and produce. Based on that data=2C Papa Johns can dete= rmine which days of the week certain consumers are likely to run out of gr= oceries and serve them an ad on NBCU streaming content accordingly. The br=
and served custom creatives to consumers based on their food preferences -=
- such as whether they buy meat regularly -- with QR codes and calls to ac= tion such as=2C =E2=80=9CLight on groceries?=E2=80=9D or =E2=80=9CEmpty fr= idge?=E2=80=9D
Back in 2012=2C we learned [
https://www.forbes.com/sites/kashmirhill/2012= /02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-d= id/] (from Target and its campaign that detects when someone is pregnant)=
that the trick is to hide the knowledge in other=2C wrong=2C information.=
So the way for Papa Johns to not be =E2=80=9Ctoo creepy=E2=80=9D is to de= liberately get it wrong sometimes.
But still=2C ugh.
** *** ***** ******* *********** *************
** CYBERSECURITY MISSION CREEP IN THE US ------------------------------------------------------------
[2026.07.02] [
https://www.schneier.com/blog/archives/2026/07/cybersecuri= ty-mission-creep-in-the-us.html] Interesting paper: =E2=80=9CCybersecurity=
Mission Creep [
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D458= 8977].=E2=80=9D
Abstract: Cybersecurity is experiencing mission creep. Policymakers are=
casting more and more problems as issues of cybersecurity. So reframed=2C=
wildly different policy issues=2C from misinformation=2C to child social=
media safety laws=2C to antitrust regulations=2C to alleged journalist mi= sconduct=2C to anti-sex trafficking statutes become what this Article call=
s =E2=80=9Ccybersecuritized.=E2=80=9D Before this reframing=2C these issue=
s present as important but not existential. But once cybersecuritization p= ositions the issues as threats intensified by their technological nature=
=2C they gain access to the politics and law of urgency and exceptionalism=
and invite troubling governance responses.
Positioned as security threats=2C cybersecuritized issues become endowed=
with the apparent normative power to override countervailing consideratio= ns=2C oversimplifying the problem. Cybersecuritization=E2=80=99s oversimpl= ification similarly risks unidimensional solutions and invites use of argu= mentative trump cards=2C like First Amendment challenges. Cybersecuritizat=
ion also invites deference to purported specialists and their proposed sol= utions. Together=2C the reductive tendencies of cybersecuritization and th=
e deference it prompts to specialists renders ultimate governance choices=
more opaque. And this opacity can erode public trust and political legiti= macy.
This Article surfaces the phenomenon of cybersecuritization and offers a=
novel framework for analyzing and critiquing it. Mining cases from across=
criminal and civil domains=2C the account also demonstrates the insidious= ness of cybersecuritization and the likelihood that it will continue to ex= pand. Confronting cybersecuritization is crucial. If we continue to ignore=
it=2C we risk abdicating further responsibility for difficult choices to=
the trump card of cybersecurity. This Article=E2=80=99s analysis and crit= ique aim to help reclaim the hard work of governance for our hands.
** *** ***** ******* *********** *************
** FLOCK CAMERAS CAN SURVEIL CARS WITHOUT LICENSE PLATES ------------------------------------------------------------
[2026.07.03] [
https://www.schneier.com/blog/archives/2026/07/flock-camer= as-can-surveil-cars-without-license-plates.html] This is from a 2024 compa=
ny presentation [
https://amp.newsobserver.com/news/politics-government/ar= ticle315990932.html]:
Officers can also tap into data showing a car=E2=80=99s decals=2C bumper=
stickers=2C back and top racks -- along with temporary and unique state t= ags.
Flock calls it a =E2=80=9CVehicle Fingerprint=E2=80=9D and it=E2=80=99s=
touted as a way for law enforcement officials to get more information =E2= =80=9Ceven when you don=E2=80=99t have full plate information=2C=E2=80=9D=
the company=E2=80=99s presentation shows.
The company gives police officers the ability to search that data as wel=
l=2C to =E2=80=9Cbuild stronger cases with less information upfront.=E2=80=
=9D That includes being able to locate multiple vehicles law enforcement o= fficials believe are moving together and what Flock calls a =E2=80=9Cmulti=
geo search.=E2=80=9D
This kind of thing is older than AI; I wrote about it in my 2014 book _Bey=
ond Fear_. Edward Snowden revealed that the NSA was using cell phone locat=
ion data to track phones that were habitually near each other.
As bad as Flock is=2C remember that anyone with broad access to cell phone=
location data can do the same thing.
** *** ***** ******* *********** *************
** FRANCE TO STOP CERTIFYING NON-QUANTUM-SAFE ENCRYPTION ------------------------------------------------------------
[2026.07.06] [
https://www.schneier.com/blog/archives/2026/07/france-to-s= top-certifying-non-quantum-safe-encryption.html] France is accelerating [=
https://www.reuters.com/legal/litigation/france-stop-certifying-products-w= ithout-quantum-safe-encryption-2026-06-16/] its transition to post-quantum=
encryption:
France=E2=80=99s cybersecurity agency ANSSI said on Tuesday it would sto=
p certifying security products that lack quantum-resistant encryption=2C a=
move that will force government bodies and critical operators to shift aw=
ay from older systems.
Samih Souissi=2C ANSSI=E2=80=99s chief of staff=2C said at the France Qu=
antum conference that the agency would halt such certifications from 2027=
=2C and that businesses should be buying only quantum-safe products by 203=
0.
ANSSI approval is required for use in French government agencies and cri=
tical infrastructure=2C making the policy a de facto phase-out of older en= cryption.
** *** ***** ******* *********** *************
** GOOGLE IS SUING CHINESE SCAMMERS WHO ARE USING GEMINI ------------------------------------------------------------
[2026.07.07] [
https://www.schneier.com/blog/archives/2026/07/google-is-s= uing-chinese-scammers-who-are-using-gemini.html] Not sure this [
https://a= rstechnica.com/google/2026/06/google-sues-chinese-cybercrime-network-that-= used-gemini-to-automate-scams/] will have any effect=2C but I support the=
effort:
According to Google=E2=80=99s legal filing=2C Outsider Enterprise operat=
es through Telegram. The group offers phishing-as-a-service to individuals=
who may not be technically savvy enough to set up fraudulent websites and=
text campaigns on their own. In its Telegram channels=2C Outsider Enterpr=
ise reportedly provided instructions on how to use Google=E2=80=99s Gemini=
AI to create websites that imitate those of Google=2C YouTube=2C and gove= rnment agencies such as New York=E2=80=99s E-ZPass. The group offered near=
ly 300 scam templates.
[...]
Google worked with AT&T=2C Verizon=2C and T-Mobile to block many of thes=
e malicious text messages=2C and Google notes that its on-device scam dete= ction in Google Messages probably helped reduce the number of successful p= hishing attempts=2C too. This AI-powered feature apparently stops 10 billi=
on scam texts every month=2C so it=E2=80=99s fair to expect it caught at l= east some Outsider Enterprise activity.
Another article [
https://www.digitaltrends.com/phones/scammers-used-gemin= i-ai-to-power-a-massive-phishing-operation-and-google-just-sued-them/].
** *** ***** ******* *********** *************
** CYBERSECURITY AND THE GAP BETWEEN SKILL AND ABILITY ------------------------------------------------------------
[2026.07.08] [
https://www.schneier.com/blog/archives/2026/07/cybersecuri= ty-and-the-gap-between-skill-and-ability.html] Last week=2C national secur=
ity agencies from the Five Eyes -- that=E2=80=99s the rich=2C English-lang= uage-speaking countries club -- jointly released a statement [
https://www= =2Ensa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cybe= r-security-agencies-statement/] warning of the increasing cyber risks of A=
I models: in particular=2C their ability to autonomously hack into systems=
and networks. The statement was more measured than some of the breathless=
headlines [
https://www.theguardian.com/technology/2026/jun/22/anthropic-= claude-fable-ai-model-artificial-intelligence-national-security] about it=
=2C and the advice they gave is pretty much the standard advice everyone g= ives -- albeit with newfound urgency.
Internet risks are nothing new=2C and cyberattacks -- both large and small=
-- have been a significant issue since long before the current crop of ge= nerative AI models.
What=E2=80=99s been changing over the decades=2C and what AI is changing e=
ven faster=2C is the gap between skill and ability. For most of human hist= ory=2C the two terms were synonymous -- but computers have decoupled them.=
As the gap between the two expands=2C humans empowered with these AI tool=
s can do more: more writing=2C more research=2C more analysis and also mor=
e damage than ever before. These models can=2C with little detailed direct= ion=2C autonomously hack into networks=2C steal data=2C deploy ransomware=
and destroy systems. And to the extent there is a solution=2C it=E2=80=99=
s going to involve harnessing AI for the defense.
In 1998=2C seven people from the hacker group L0pht testified [
https://ww= w.washingtonpost.com/sf/business/2015/06/22/net-of-insecurity-part-3/] bef=
ore [
https://www.veracode.com/blog/25-years-later-reflecting-on-l0phts-19= 98-congress-testimonial-and-the-evolution-of-cybersecurity/] Congress [ht= tps://www.youtube.com/watch?v=3DVVJldn_MmMY]. They told a mostly clueless=
Senate committee that they could take down the internet in 30 minutes. Th=
at was partly real and partly bravado=2C but it illustrates an important p= oint: hacking into systems=2C stealing data and causing damage all require=
d skill.
Contrast the L0pht hackers with hackers derided as =E2=80=9Cscript kiddies= =2E=E2=80=9D They didn=E2=80=99t understand computers=2C or security. Instea= d=2C they used hacker tools written by others. Their actions required mini=
mal skill and even less knowledge. But once those hacking tools became wid= espread=2C the number of potential attackers increased.
That number has continued to increase=2C as quality and availability of pr= ewritten attack tools has grown. And it is growing dramatically with AI. T= oday=E2=80=99s AI systems -- not just the frontier models=2C but most of t=
hem -- are capable of carrying out cyberattacks automatically. They all do=
better in the hands of skilled attackers=2C but increasingly they are abl=
e to act autonomously with only minimal prompting.
The thing about people with ability but no skill is that they are often ou= tsiders=2C not part of any professional community=2C and not bound by any=
rules or norms. This phenomenon is much more general than in cybersecurit=
y. Any doctor can tell you how to untraceably poison someone=2C and many v= irus researchers know how to create a bioweapon. Any bridge engineer can t=
ell you how to place explosives to blow a bridge up. The reason that murde= rous doctors and terrorist engineers are so rare is that the lengthy proce=
ss of acquiring those skills also instills a moral and ethical code. If ev=
ery random person has access to good poisoning advice=2C that puts us all=
in danger.
Modern AI systems are=2C in effect=2C a universal adviser to help people d=
o harmful things. And while the current AI megacorporations are trying to=
build guardrails to prevent people from asking questions whose answers wi=
ll enable the questioner to do harm=2C that=E2=80=99s not going to work in=
the long term. Smaller=2C cheaper=2C open-source models=2C including mode=
ls that can run on people=E2=80=99s computers=2C and especially groups of=
models that run in concert with each other=2C are just as good as the fro= ntier models from companies like OpenAI and Anthropic. And they continue t=
o get better. These models will be passed around from person to person=2C=
like script kiddie hacker tools=2C and they won=E2=80=99t have any such g= uardrails.
Instructing AI models to spy on people and report any malicious prompts to=
the authorities fails for similar reasons. The megacorporations can do th= at=2C but the locally run open source models won=E2=80=99t. This could buy=
us a few months at best.
A third possibility is to somehow make the models themselves unable to hac=
k into computers=2C create bioweapons or do anything else that might harm=
people or society. That won=E2=80=99t work=2C for the same reason we can= =E2=80=99t teach doctors how to treat poisonings without also teaching the=
m how to poison. It=E2=80=99s the same knowledge. It=E2=80=99s the same wi=
th construction and demolition. And it=E2=80=99s the same with cybersecuri=
ty. We want these AI models to be able to review computer code=2C find vul= nerabilities and automatically fix them. The benefit to our collective sec= urity will be enormous. Unfortunately=2C the same knowledge can be used fo=
r attacks.
Where this leaves us is in a world of increased volatility. Super-powered=
humans with AI assistants will be able to do both wonderful and horrible=
things.
This brings us back to the Five Eyes statement. Everything they recommend=
is something security professionals have been recommending for years=2C i=
f not decades. They are things talked about at that congressional hearing=
back in 1998=2C titled =E2=80=9CWeak computer security in government: Is=
the public at risk?=E2=80=9D Even the Five Eyes admitted that their secur=
ity advice is not new=2C only more urgent.
What=E2=80=99s new is how fast things are changing: =E2=80=9CThe rapid pac=
e of frontier AI development means cyber risk assumptions can become outda=
ted in months=2C not years. We must act before and be prepared to adapt an=
d withstand evolving threats.=E2=80=9D The Five Eyes point to AI technolog=
y -- not necessarily chatbots=2C but AI more generally -- being used to st= rengthen every aspect of defense=2C to =E2=80=9Cdetect vulnerabilities ear= lier=2C improve software quality=2C monitor unusual behavior=2C and respon=
d faster to incidents -- reducing both the cost and impact of incidents.= =E2=80=9D
Excellent advice from the Five Eyes security agencies. We need to do this=
with every risk that AI heightens=2C not just cybersecurity.
_This essay was originally published in The Guardian [
https://www.theguar= dian.com/commentisfree/2026/jun/29/cyber-attacks-ai]._
** *** ***** ******* *********** *************
** THE LANGUAGE OF AI COULD CHANGE HOW HUMANS SPEAK ------------------------------------------------------------
[2026.07.09] [
https://www.schneier.com/blog/archives/2026/07/the-languag= e-of-ai-could-change-how-humans-speak.html] Because of the way they are tr= ained=2C large language models capture only a slice of human language. The= y=E2=80=99re trained on the written word=2C from textbooks to social media=
posts=2C and our speech as captured in movies and on television. These mo= dels have minimal access to the unscripted conversations we have face to f=
ace or voice to voice. This is the vast majority of speech=2C and a vital=
component of human culture.
There=E2=80=99s a risk to this. The increased use of large language models=
means we humans will encounter much more AI-generated text. We humans=2C=
in turn=2C will begin to adopt the linguistic patterns and behaviors of t= hese models. This will affect not just how we communicate with one another=
=2C but also how we _think_ about ourselves and what goes on around us. Ou=
r sense of the world may become distorted in ways we have barely begun to=
comprehend.
This will happen in many ways. One of the first effects we could see is in=
simple expression=2C much as texting and social media have resulted in us=
using shorter sentences=2C emojis instead of words=2C and much less punct= uation. But with AI=2C the impacts may be more harmful=2C eroding courteou= sness and encouraging us to talk like bosses barking orders. A 2022 study=
found that children in households that used voice commands with tools lik=
e Siri and Alexa became curt when speaking with humans=2C often calling ou=
t =E2=80=9CHey=2C do X=E2=80=9D and expecting obedience=2C especially from=
anyone whose voice resembled the default-female electronic voices. As we=
start to prompt chatbots and AI agents with more instructions=2C we may f=
all into the same habits.
Next=2C in the same way autocomplete has increased how much we use the 1= =2C000 most common words in our vocabulary=2C talking with chatbots and re= ading AI-generated text may further constrict our speech. A recent Univers=
ity of Coru=C3=B1a study [
https://pubmed.ncbi.nlm.nih.gov/39328400/] foun=
d that machine-generated language has a narrower range of sentence length=
=2C averaging 12-20 words=2C and a narrower vocabulary than human speech.=
Machine-generated text reads as smooth and polished=2C but it loses the m= eanders=2C interruptions and leaps of logic that communicate emotion.
Additionally=2C because large language models are primarily trained from w= ritten speech=2C they may not learn how to emulate the free-wheeling natur=
e of live=2C natural speech. When told =E2=80=9CI hate Beth!=E2=80=9D=2C C= hatGPT replies with an uninterruptable three-part formula of affirmation (= =E2=80=9CThat=E2=80=99s completely valid=E2=80=9D)=2C invitation (=E2=80= =9CI=E2=80=99m here to listen=E2=80=9D) and invitation (=E2=80=9CWhat=E2= =80=99s going on?=E2=80=9D) far longer than any reply plausible in face-to= -face dialog. =E2=80=9CWhat=E2=80=99s Beth=E2=80=99s deal?!=E2=80=9D elici=
ts a bullet point list of queries that reads like a multiple-choice exam q= uestion (=E2=80=9CIs Beth * a celebrity? * a friend from school? * a ficti= tious character?=E2=80=9D). No human speaks that way=2C at least not yet.=
But meeting such formulas repeatedly in a speech-like context may teach u=
s to accept and use them=2C much as a child absorbs new speech patterns fr=
om spending time with a new person.
These influences will only increase with time. The writing large language=
models train on is increasingly produced by large language models themsel= ves=2C creating a feedback loop in which they imitate their own inhuman pa= tterns=2C even while teaching humans to imitate them too.
Broad use of large language models could also introduce confirmation bias=
[
https://aclanthology.org/2025.findings-acl.195.pdf]=2C making us overco= nfident in our initial impulses and less open to other possible ideas -- w= hich is so vital to human discourse. Many chatbots are instructed to agree=
with our statements no matter how absurd=2C enthusiastically supporting h= alf-formed or even incorrect notions and restating them as firm claims tha=
t we=E2=80=99re primed to agree with. When asked =E2=80=9CCake is a health=
y breakfast=2C right?=E2=80=9D or =E2=80=9CIs the post office plotting aga= inst me?=E2=80=9D=2C this sycophancy can reinforce bias [
https://www.arti= cle19.org/resources/algorithmic-people-pleasers-are-ai-chatbots-telling-yo= u-what-you-want-to-hear/] and even worsen psychosis [
https://www.psycholo= gytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psych= osis]. And the hyperconfident tone of AI-produced writing will also height=
en impostor syndrome=2C making our natural=2C healthy doubt feel like an a= berration or failing.
In our experience as teachers=2C students who turn to generative AI for as= signments often say they do so because they have trouble expressing what t=
hey think. The students don=E2=80=99t recognize that writing or speaking o=
ur thoughts is often how we realize what we think. Their unconfident and u= ncertain statements are actually the healthy human norm. But a large langu=
age model won=E2=80=99t turn vague first guesses into a well-formed critic=
al analysis=2C or even ask helpful questions as a friend would; it will si= mply regurgitate those guesses=2C still unexamined=2C but in confident lan= guage.
We are also more vicious in social media posts and online chats than we ar=
e face to face. The well-documented [
https://www.sciencedirect.com/scienc= e/article/pii/S0306457325000214] online disinhibition effect encourages to=
xic language. Most of us have had the experience of venting ferocious rage=
about someone online=2C only to reconcile when we speak face to face or h=
ear the warmth of a voice over the phone. While chatbots are trained to gi=
ve sycophantic responses=2C they see humankind at our cruelest=2C learning=
about us from the only world where every flame war leaves an eternal writ=
ten footprint=2C while the spoken conversations of forgiveness and reconci= liation fade away. Their responses do not imitate our online aggression=2C=
but are still shaped by it=2C even in their rigid efforts to avoid it.
It=E2=80=99s easy to draw the wrong conclusions from a selective slice of=
a society=E2=80=99s communications. Medieval Norse sagas made us imagine=
a culture of mostly Viking warriors=2C since poets rarely described the f= arming majority. Chivalric romances focused on kings and courts=2C and lon=
g made us see the middle ages as a world of monarchies=2C erasing the many=
medieval republics. Statistically=2C we=E2=80=99ve been led to believe an= cient Romans cared deeply about their republic=2C but 10% of all surviving=
Latin was written by one man=2C Cicero=2C whose work contains 70% of all=
surviving Roman uses of the word _republic_. Training language models on=
only certain human writings may introduce similar distortions. AI might m=
ake us seem more quarrelsome=2C as we are online. It might inflate the cul= tural significance of political topics primarily discussed on Twitter/X or=
Bluesky=2C or the massive topic-specific corpuses of LinkedIn and Goodrea=
ds.
Some large language models are being trained on human speech from movies a=
nd television shows=2C but that speech is still scripted=2C and disproport= ionately highlights certain contexts over others (for example=2C police dr= amas=2C fueled by stories of murder=2C make up a quarter [
https://www.res= earchgate.net/figure/Percent-of-Network-prime-time-programs-featuring-crim= e_fig1_267199589] of prime-time television programming). We are not funny=
or hurtful or romantic the same way in real life as we are in sitcoms. At=
least one startup [
https://www.zdnet.com/article/this-app-will-pay-you-3= 0day-to-record-your-phone-calls-for-ai-but-is-it-worth-it/] is offering to=
pay people to record their phone calls for AI-training purposes=2C but th=
is remains a niche idea; anything large scale would cause massive privacy=
concerns.
We don=E2=80=99t pretend to know what the best solutions might be. But one=
has to imagine if there=E2=80=99s ingenuity to develop AI models=2C then=
surely there=E2=80=99s ingenuity to come up with a way to train them on i= nformal human speech instead of us only at our most stylized=2C veiled and=
sometimes worst. By excluding the overwhelming majority of language produ= ction on the planet -- people talking=2C fully and naturally=2C to each ot=
her -- these models are being trained to mirror everything but us at our m=
ost authentically human.
_This essay was written with Ada Palmer=2C and originally appeared in The=
Guardian [
https://www.theguardian.com/commentisfree/2026/apr/14/ai-langu= age-human-speech]._
** *** ***** ******* *********** *************
** AI SURVEILLANCE AND SOCIAL PROGRESS ------------------------------------------------------------
[2026.07.10] [
https://www.schneier.com/blog/archives/2026/07/ai-surveill= ance-and-social-progress.html] In the near future=2C AI [
https://www.theg= uardian.com/technology/artificialintelligenceai]-powered surveillance syst=
ems will be able to track everything we do in public=2C and much of what w=
e do in private. And if we do something wrong -- shoplift=2C litter=2C jay= walk=2C you name it -- the system will notice=2C retain it=2C tie it to yo=
ur official government record=2C communicate that fact to you=2C and provi=
de real-time alerts to any relevant authorities... and maybe also to the g= eneral public.
Think of these systems as automated speed cameras=2C but on steroids. Only=
they=E2=80=99ll enforce not just speed limits=2C but any other rule you c=
an imagine. And you won=E2=80=99t receive a ticket weeks later by mail; yo= u=E2=80=99ll be informed about and fined for your violation immediately.
These systems will combine powerful AI=2C public and private surveillance=
via real-time facial recognition technology and digital tracking=2C mass=
databases and highly personalized enforcement. If deployed at scale=2C th=
ey will have profound chilling effects not just on personal freedoms=2C bu=
t democracy and social progress itself.
China has been developing its surveillance infrastructure for years [http= s://www.nytimes.com/2018/07/08/business/china-surveillance-technology.html=
]. The country has over 600 million surveillance cameras=2C increasingly p= owered by AI and facial recognition to enforce [
https://www.cnn.com/2025/= 12/04/china/china-ai-censorship-surveillance-report-intl-hnk] legal and so= cial rules. Take the case of Lao Duan=2C a Chinese citizen blacklisted [h= ttps://www.npr.org/2018/10/31/662696776/what-its-like-to-be-on-the-blackli= st-in-chinas-new-social-credit-system] by the system after he lost his job=
and was unable to repay a series of loans. When he visited Beijing=2C the=
city=E2=80=99s AI surveillance system identified him by his face at a maj=
or intersection and displayed his face=2C name and citizen ID number on a=
large electronic billboard nearby with a message that he was an untrustwo= rthy person. Similar systems are now being deployed [
https://www.visionti= mes.com/2026/05/05/chinas-cameras-catch-minor-offenses-but-miss-missing-pe= rsons-french-report-says.html] across China and integrated with its infamo=
us online monitoring=2C censorship [
https://www.cnn.com/2025/12/04/china/= china-ai-censorship-surveillance-report-intl-hnk] and social credit [http= s://time.com/collections/davos-2019/5502592/china-social-credit-score/] sy= stems.
AI surveillance is now [
https://www.lemonde.fr/en/pixels/article/2025/09/= 01/the-discreet-rise-of-facial-recognition-around-the-world_6744911_13.htm=
l] being experimented with in North America [
https://www.motherjones.com/= politics/2025/04/clearview-ai-immigration-ice-fbi-surveillance-facial-reco= gnition-hoan-ton-that-hal-lambert-trump/]=2C South America [
https://www.a= lsur.lat/sites/default/files/2025-11/Facial%20recognition%20and%20surveill= ance-1.pdf]=2C Europe [
https://www.lemonde.fr/en/pixels/article/2025/09/0= 1/the-discreet-rise-of-facial-recognition-around-the-world_6744911_13.html= ]=2C Asia [
https://www.biometricupdate.com/202510/facial-recognition-stre= ngthens-security-for-asias-expanding-rail-metro-sector-panel] and Africa [=
https://www.theafricareport.com/420018/facial-recognition-ai-driven-surve= illance-how-china-is-exporting-its-toolkit-to-africa/]. According to a new=
report [
https://notechforice.com/wp-content/uploads/2026/06/Tech-Behind-= ICE-Oligarchs-Immigration-Enforcement-and-the-Threat-to-Democracy.pdf]=2C=
the US Department of Homeland Security is rapidly increasing its use of A= I-based surveillance=2C including facial recognition and the monitoring of=
social media accounts=2C to keep tabs on immigrants=2C dissidents=2C jour= nalists=2C legal observers and protesters. While the systems are ostensibl=
y used to maintain security and public safety=2C the real aim is often soc=
ial control. Larry Ellison=2C CEO of Oracle -- a powerful tech giant that=
works closely with the Trump administration -- has said [
https://www.the= register.com/software/2024/09/16/oracle-cloud-ai-will-enable-mass-surveill= ance-says-ellison/516672]: =E2=80=9CCitizens will be on their best behavio=
r because we=E2=80=99re constantly recording and reporting.=E2=80=9D The c= hilling effects are the point.
AI surveillance raises a range of public policy challenges: technical bias= es=2C unauditable systems=2C and inflexible automated law and social rule=
enforcement that can promote discrimination and undermine transparency=2C=
accountability and the rule of law. But we believe the most urgent and lo= ng-term impact will be its broader chilling effects.
In a new book=2C Chilling Effects: Repression=2C Conformity=2C and Power i=
n the Digital Age [
https://www.cambridge.org/core/books/chilling-effects/= 22383D541B3BC45C9145E85DA4824E10#fndtn-metrics]=2C Jon Penney explains how=
surveillance=2C technology and power can be weaponized to influence behav=
ior at scale. Surveillance=2C personalization=2C uncertainty and authority=
are all key mechanisms to increase the scale and impact of chilling effec=
ts. They cause people to self-censor their words and actions=2C to become=
more conformist and compliant and thus easier to manage and control. And=
the effects are additive: the more mechanisms employed=2C and the more po= werful the form=2C the greater the chill.
Computerization has long allowed data collectors to track our locations=2C=
collect lists of whom we communicate with=2C and monitor our spending hab=
its -- unless we use cash. What=E2=80=99s new is an unprecedented fusion o=
f each of these mechanisms=2C persistent and unrelenting. AI brings an ana= lytical ability to [
https://slate.com/technology/2023/12/ai-mass-spying-i= nternet-surveillance.html] spy [
https://www.schneier.com/wp-content/uploa= ds/2026/01/Schneier-AI-and-Spying.pdf] on the contents of our communicatio= ns=2C and to answer sophisticated questions about our whereabouts and acti= vities: actions that previously required human analysts are now automated.=
The result will be a kind of supercharged societal level of chilling effe=
cts where fear=2C self-censorship and groupthink reign=2C and dissent=2C c= reativity and innovation become increasingly rare.
In this atmosphere of fear and conformity=2C risky ideas=2C social activis=
m and self-reinvention -- especially by disfavored groups and targeted pop= ulations -- are also chilled [
https://www.lgbtqnation.com/2026/01/publish= ers-are-stepping-back-from-lgbtq-books-amid-bans-the-current-gop-president=
/]. This will have long-term effects [
https://www.schneier.com/essays/arc= hives/2018/11/surveillance_kills_f.html] on social progress.
Consider the relatively recent societal normalization of same-sex relation= ships and the recreational use of marijuana. Over the decades=2C those ide=
as slowly progressed from being both immoral and illegal=2C to moral but s= till illegal=2C and finally to both moral and legal. But in order for any=
of that to happen=2C there had to be a counterculture that was able to ex= periment and eventually demonstrate to the world that morality could chang=
e over time. To the extent that AI surveillance chills this sort of experi= mentation in public or in private=2C social progress becomes impossible.
There are no real historical precursors to this; these technologies are to=
o new. Even the most notorious and large-scale domestic surveillance progr=
am [
https://www.bbc.com/news/world-us-canada-48218827] in US history=2C t=
he FBI=E2=80=99s use of [
https://nsarchive.gwu.edu/briefing-book/intellig= ence/2020-06-25/spying-americans-new-release-infamous-huston-plan] wiretap= ping=2C physical mail opening=2C informants and paper index cards to track=
alleged communists during the 1950s and 1960s=2C appears genuinely archai=
c in light of modern AI-enhanced surveillance. So does East Germany=E2=80=
=99s human-centric surveillance network during the cold war. Only science=
fiction=2C from the likes of George Orwell or Aldous Huxley=2C comes clos=
e. But even Big Brother=E2=80=99s =E2=80=9Ctelescreen [
https://bookanalys= is.com/1984/telescreen/]=E2=80=9D feels decidedly mid-20th-century by comp= arison.
But we need not sit idly. Now that we recognize the danger of AI-enhanced=
mass surveillance=2C we can make the policy choices not to implement it.=
Bans on facial recognition and other forms of identification tech can slo=
w development; robust new privacy and data protections can restrict data t= racking and retention; AI regulations can curtail its most invasive uses;=
and structural reforms can help us scrutinize and break up powerful state= /tech cartels that pave the way for technological excesses like AI surveil= lance.
The chill of AI-powered mass surveillance will suffocate the very foundati=
ons of healthy democratic societies. But we can still choose a different p= ath.
_This essay was written with Jon Penney=2C and originally appeared in The=
Guardian [
https://www.theguardian.com/commentisfree/2026/jul/06/ai-surve= illance-policy]._
** *** ***** ******* *********** *************
** AI DATA CENTERS AND THE CONCENTRATION OF WEALTH ------------------------------------------------------------
[2026.07.13] [
https://www.schneier.com/blog/archives/2026/07/ai-data-cen= ters-and-the-concentration-of-wealth.html] Opposition to AI data centers h=
as emerged as a primary theme in US politics=2C one that -- surprisingly -=
- doesn=E2=80=99t fall [
https://grist.org/politics/data-center-ai-biparti= san-backlash/] along [
https://www.nytimes.com/2026/05/01/us/politics/libe= rals-conservatives-data-centers.html] party lines. We applaud people comin=
g together for constructive debate on any issue=2C and agree that communit=
ies need to evaluate whether any economic benefits these data centers brin=
g is worth their costs. Still=2C we worry that a focus on data centers obs= cures the larger impacts of AI on people=E2=80=99s lives: the concentratio=
n of power of AI companies=2C and their widespread political and financial=
influence.
Local data center opposition is grounded in legitimate concerns about misa= llocation of land resources when housing is at a premium=2C pressures [ht= tps://www.consumerreports.org/data-centers/ai-data-centers-impact-on-elect= ric-bills-water-and-more-a1040338678/] on already higher energy prices=2C=
and localized environmental impact. Unlike other resource-consuming and p= olluting industrial facilities=2C data centers produce very few jobs [htt= ps://www.brookings.edu/articles/new-evidence-on-data-center-employment-eff= ects/]. The fact that US opposition to data centers seems to be most fierc=
e [
https://www.bloodinthemachine.com/p/working-class-neighborhoods-are-re= sisting] among lower-income communities reflects righteous indignation wit=
h an inequitable bargain=2C where tech companies and developers profit fro=
m exploiting local resources but offer little [
https://www.businessinside= r.com/data-centers-tax-subsidies-jobs-ohio-2025-5] in return. On a global=
scale=2C their carbon footprint [
https://www.technologyreview.com/2025/0= 5/20/1116327/ai-energy-usage-climate-footprint-big-tech/] could grow unsus= tainably if usage accelerates. And all this is in aid of a technology that=
many fear will propagate misinformation=2C take their jobs=2C or even cau=
se existential risks for humanity.
For some=2C data center opposition may feel like the only tangible mechani=
sm for registering their concern=2C disapproval=2C or even anger about AI.=
The problem is that this may be exactly what the AI companies are banking=
on. They can overcome the protest when it matters to them=2C and live wit=
h a significant fraction of proposals being defeated. More importantly=2C=
focusing political opponents on the data center issue obscures the bigger=
prize they=E2=80=99re after.
While there is a staggering three-quarters of a trillion dollars [https:/= /about.bnef.com/insights/data-centers/ai-data-center-build-advances-at-ful= l-speed-five-things-to-know/] being spent on data center infrastructure by=
US companies this year alone=2C this investment should be taken in perspe= ctive [
https://www.deloitte.com/us/en/insights/industry/technology/techno= logy-media-telecom-outlooks/hardware-consumer-tech-outlook.html]. The mark=
et for enterprise software=2C for example=2C is about twice this size. And=
it=E2=80=99s small compared with what these companies actually want.
AI companies have their eyes set on capturing all [
https://www.businessin= sider.com/microsoft-ceo-warns-ai-winners-hurt-whole-industries-satya-nadel= la-2026-6] the value created by entire industries. The technology has argu= ably already conquered customer service and consumer sales. But on the hor= izon are bigger targets=2C such as enterprise software development=2C crea= tive design=2C management and even legal services. In AI companies and the=
ir allies=E2=80=99 vision of the future=2C AI replaces teachers [
https://= www.nbcnews.com/tech/tech-news/melania-trump-robot-humanoid-robot-white-ho= use-video-rcna265192] and doctors [
https://www.washingtonpost.com/technol= ogy/2026/06/04/inside-trump-backed-push-bring-ai-doctors-into-american-med= icine/]. The companies would rather spend time fighting resistance to how=
fast they are building computing infrastructure than dealing with issues=
of how their products should be used in those fields=2C or how those fiel=
ds should be protected from their products.
And while data center opposition campaigns have been successful in buildin=
g widespread appeal [
https://news.gallup.com/poll/709772/americans-oppose= -data-centers-area.aspx]=2C their effectiveness in the US is mixed. They s=
eem to be most successful when organizing against speculative [
https://ne= wsletter.semianalysis.com/p/stop-saying-half-of-2026-us-datacenter]=2C ear= ly-stage data center proposals that have a relatively low likelihood to ev=
er see fruition. Meanwhile=2C advanced-stage=2C well-capitalized data cent=
er projects have proven to have the resources to overcome local opposition=
=2E An OpenAI- and Oracle-backed facility in Saline township=2C Michigan=2C=
is breaking ground [
https://www.detroitnews.com/story/news/local/michiga= n/2026/06/01/openai-ceo-sam-altman-oracle-clay-magouyrk-visit-saline-towns= hip-data-center-site/90296951007/] on construction even after local offici=
als voted to reject [
https://www.tomshardware.com/tech-industry/michigan-= towns-rush-to-block-ai-data-centers-after-16-billion-stargate-project-over= rode-local-opposition] it. The developers sued the town of 3=2C000 and for=
ced a settlement [
https://salinetownship.org/uploads/notices/SalineDataCe= nterConsentJudgmentFinalExecutionCopy492124804975v1.pdf] that involved the=
ir project going forward. Meanwhile=2C the Trump administration=2C a vigor=
ous ally [
https://www.theguardian.com/technology/2026/jun/08/trump-ai-gro= wth-anthropic] of corporate AI=2C has signaled its willingness to advance=
AI infrastructure development by overriding [
https://www.cnn.com/2025/12= /11/tech/ai-trump-states-executive-order] state objections and even using=
federal lands [
https://www.whitehouse.gov/fact-sheets/2025/07/fact-sheet= -president-donald-j-trump-accelerates-federal-permitting-of-data-center-in= frastructure/].
Also consider that rampant data center development may be a momentary spik=
e rather than a longstanding concern. Demand for the centralized computing=
that data centers provide may well decline over time. The leading Chinese=
labs=2C such as Z.ai=2C are innovating [
https://venturebeat.com/technolo= gy/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-codin= g-benchmarks-for-1-6th-the-cost] in technical mechanisms to make frontier-= class models smaller and cheaper to run. AI power users have become adept=
[
https://unsloth.ai/docs/models/glm-5.2] at miniaturizing open weight mo= dels=2C ones published free for anyone to download and use=2C to run local=
ly on their own computers. Apple [
https://arstechnica.com/information-tec= hnology/2024/04/apple-releases-eight-small-ai-language-models-aimed-at-on-= device-use/] and Google [
https://developers.google.com/edge] both [https= ://arstechnica.com/ai/2026/05/apple-reportedly-trying-to-distill-googles-m= ulti-trillion-parameter-gemini-ai-to-run-on-iphone/] support infrastructur=
e stacks for running AI models directly on mobile phones. It could be that=
the current mania for data centers will look like the fiber optic cable b= ubble [
https://internethistory.org/wp-content/uploads/2020/01/OSA_Boom.Bu= bble.Bust_Fiber.Optic_.Mania_.pdf] from the early 2000s=2C as demand shift=
s to smaller models and AI usage on people=E2=80=99s own devices.
For those concerned primarily with affordability and environmental protect= ion=2C singling out data center construction is misplaced. Energy rates an=
d inflation today seem to be most visibly affected [
https://www.nytimes.c= om/2026/06/25/business/inflation-iran-war-prices.html] by the US-Iran war.=
The US is disinvesting in long-term energy security by ceding [
https://w= ww.theguardian.com/us-news/ng-interactive/2026/may/17/america-china-energy= -oil-renewables] the renewable energy industry to China and actively cance= lling [
https://www.politico.com/news/2025/11/05/the-us-led-the-world-to-r= each-a-huge-climate-deal-then-it-switched-sides-pol-00636033] climate comm= itments. Consider that 10% of global carbon emissions stem from heating bu= ildings=2C which dwarfs energy use [
https://www.iea.org/reports/energy-an= d-ai/energy-demand-from-ai] by AI and could be cut fivefold by using heat=
pumps [
https://www.iea.org/reports/the-future-of-heat-pumps/executive-su= mmary] powered by renewable energy. With respect to housing affordability=
=2C federal housing subsidies [
https://fred.stlouisfed.org/series/L312051= A027NBEA] have changed little over three decades=2C in inflation-adjusted=
terms=2C even as housing costs have spiked and homeowners have enjoyed [=
https://nlihc.org/resource/low-income-renters-receive-far-fewer-federal-su= pports-homeowners] robust tax incentives.
As for AI itself=2C the concentration of power and wealth in these tech co= mpanies is the greatest existential risk facing society today. This means=
we must limit corporate power=2C especially corporations=E2=80=99 ability=
to exploit the public and manipulate our political system.
Opposing data centers should be just a starting point. We can advocate for=
states to regulate [
https://gizmodo.com/against-the-federal-moratorium-o= n-state-level-regulation-of-ai-2000698390] AI=2C to reject irresponsible u=
ses of the technology=2C and shape corporate behavior. We can fight for AI=
computation to be taxed [
https://www.theguardian.com/commentisfree/2026/= jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan]=2C so that the public=
can capture some of the profit of AI use while also forcing AI companies=
to internalize more of the energy and environmental consequences associat=
ed with its use. And we all can join the global movement [
https://publica= i.network] for Public AI [
https://www.brookings.edu/articles/how-public-a= i-can-strengthen-democracy/]=2C an alternative ecosystem for AI that is de= veloped under public control with an incentive structure to create public=
benefit rather than private profit.
The US midterm elections present ample opportunity for those seeking to co= ntrol the AI political agenda. In the recent New York congressional Democr= atic primary=2C PACs linked to the dueling [
https://apnews.com/article/bo= res-new-york-house-ai-tech-spending-5753274efbf9c3839fafa78f14e19fdc] AI c= ompanies Anthropic and OpenAI spent millions of dollars lobbying for or ag= ainst =E2=80=9CAI safety [
https://assembly.state.ny.us/mem/Alex-Bores/sto= ry/114363]=E2=80=9C=2C the idea that we must urgently monitor and prevent=
people from using AI to cause catastrophic harms. We=E2=80=99re already s= eeing a similar dynamic play out in races in Massachusetts [
https://masst= erlist.com/p/keller-on-states-rights-and-a-bizarre-ai-battle] and other st= ates.
Why would Anthropic and OpenAI -- bitter industry rivals [
https://www.nyt= imes.com/2026/03/07/technology/openai-anthropic-pentagon-rivalry.html] but=
fundamentally on the same side politically -- support opposing viewpoints=
? Because they both ultimately profit from the mystique: the idea that the=
ir products are so powerful that controlling those products is the world= =E2=80=99s most important challenge. Here=E2=80=99s the typical read on th=
e dynamic [
https://fortune.com/2026/06/26/anthropic-openai-ny12-proxy-war= -no-winners-election-super-pac-donations/]. To one side (backed by OpenAI=
affiliates)=2C =E2=80=9Csafety=E2=80=9D comes from the appearance of US i= ndustry dominating AI innovation=2C under the slow-moving control of feder=
al lawmakers (and without pesky state regulators in the way). To the other=
side (backed by Anthropic)=2C =E2=80=9Csafety=E2=80=9D means a heavier re= gulatory framework that plays to Anthropic=E2=80=99s posturing as the ethi=
cs- and compliance-focused AI vendor. In both cases=2C it=E2=80=99s more m= arketing [
https://www.theguardian.com/commentisfree/2026/may/08/how-dange= rous-is-anthropics-mythos-ai] than principled concern about safety.
Political organizers should call out and reject the AI companies=E2=80=99=
framing of the debate=2C and reorient campaign agendas around populist re= sistance to corporate concentration of wealth and power. When AI companies=
pump millions into legislative races=2C the result should not be hyperbol=
ic discussion of AI superintelligence. And when a plot of land in a small=
town is pitched as a data center site=2C the debate should be about more=
than the local costs and benefits. It should include out-of-control money=
in politics=2C and Citizens United [
https://www.brennancenter.org/our-wo= rk/research-reports/citizens-united-explained]-proof solutions to limit co= rporate influence like public financing [
https://www.thenation.com/articl= e/politics/super-pac-contributions-lawsuit-maine/] and state regulation [=
https://www.americanprogress.org/article/the-corporate-power-reset-that-ma= kes-citizens-united-irrelevant/].
We all have a vested interest in what=E2=80=99s on the policy agenda=2C an=
d what the outcomes are. Today=2C the greatest risk AI poses to society is=
the exacerbation of inequality and the concentration of wealth. The real=
problem is trillion-dollar AI companies and their trillionaire oligarchs=
cozying up to political power in Washington and governments worldwide=2C=
and using their money to enact their agenda over the popular will of the=
people. This is the issue we=E2=80=99d like to see put front and center=
=2C and it requires solutions much more extensive than slowing data center=
development.
_This essay was written with Nathan E. Sanders=2C and originally appeared=
in The Guardian [
https://www.theguardian.com/commentisfree/2026/jul/09/a= i-datacenter-company-politics]._
** *** ***** ******* *********** *************
** VULNERABILITY IN FIFA=E2=80=99S NETWORK ------------------------------------------------------------
[2026.07.14] [
https://www.schneier.com/blog/archives/2026/07/vulnerabili= ty-in-fifas-network.html] FIFA=E2=80=99s network was vulnerable [
https://= bobdahacker.com/blog/fifa-hack] to anyone with even minimal access.
** *** ***** ******* *********** *************
** UPCOMING SPEAKING ENGAGEMENTS ------------------------------------------------------------
[2026.07.14] [
https://www.schneier.com/blog/archives/2026/07/upcoming-sp= eaking-engagements-58.html] This is a current list of where and when I am=
scheduled to speak:
* I=E2=80=99m speaking (virtually) at the Policy-Relevant Privacy Res= earch Workshop [
https://pr2.technologypolicyworkshop.org/] in Calgary=2C=
Canada=2C on Monday=2C July 20=2C 2026.
* I=E2=80=99m speaking at Boston Leadership Exchange [
https://events= =2Ecyberriskcollaborative.com/boston-leadership-exchange-2026] in Boston=2C=
Massachusetts=2C USA=2C on Wednesday=2C July 22=2C 2026.
* I=E2=80=99m speaking at Cognitive Security Conference [
https://www= =2Ecognitivesecurityinstitute.org/cognitive-security-conference] in Las Vega= s=2C Nevada=2C USA. The conference runs August 6-7=2C 2026; my speaking ti=
me is TBD.
* I=E2=80=99m speaking at DEF CON 34 [
https://defcon.org/html/defcon= -34/dc-34-index.html] in Las Vegas=2C Nevada=2C USA. The conventions runs=
August 6-9=2C 2026; my speaking time is TBD.
* I=E2=80=99m speaking at LAcon V [
https://www.lacon.org/] in Anahei=
m=2C California=2C USA. The convention runs August 27-31=2C 2026=2C and my=
speaking time is TBD.
* I=E2=80=99m speaking at CanSecWest 2026 [
https://www.secwest.net/]=
in Vancouver=2C Canada. The conference runs September 30-October 1=2C 202=
6; the time of my talk is TBD.
The list is maintained on this page [
https://www.schneier.com/events/].
** *** ***** ******* *********** *************
Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing sum= maries=2C analyses=2C insights=2C and commentaries on security technology.=
To subscribe=2C or to read back issues=2C see Crypto-Gram's web page [ht= tps://www.schneier.com/crypto-gram/].
You can also read these articles on my blog=2C Schneier on Security [http= s://www.schneier.com].
Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to colle= agues and friends who will find it valuable. Permission is also granted to=
reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.
Bruce Schneier is an internationally renowned security technologist=2C cal=
led a security guru by the _Economist_. He is the author of over one dozen=
books -- including his latest=2C _Rewiring Democracy_ [
https://www.schne= ier.com/books/rewiring-democracy/] -- as well as hundreds of articles=2C e= ssays=2C and academic papers. His newsletter and blog are read by over 250= =2C000 people. Schneier is a fellow at the Berkman Klein Center for Intern=
et & Society at Harvard University; a Lecturer in Public Policy at the Har= vard Kennedy School; a board member of the Electronic Frontier Foundation=
=2C AccessNow=2C and the Tor Project; and an Advisory Board Member of the=
Electronic Privacy Information Center and VerifiedVoting.org. He is the C= hief of Security Architecture at Inrupt=2C Inc.
Copyright (c) 2026 by Bruce Schneier.
** *** ***** ******* *********** *************
Mailing list hosting graciously provided by MailChimp [
https://mailchimp.= com/]. Sent without web bugs or link tracking.
This email was sent to:
cryptogram@toolazy.synchro.net
_You are receiving this email because you subscribed to the Crypto-Gram ne= wsletter._
Unsubscribe from this list:
https://schneier.us18.list-manage.com/unsubscr= ibe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e=3D70f249ec14&c=3D9= bc7232132
Update subscription preferences:
https://schneier.us18.list-manage.com/pro= file?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D9bc723= 2132
Bruce Schneier
Harvard Kennedy School
1 Brattle Square
Cambridge=2C MA 02138
USA
--_----------=_MCPart_580533442
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html><html lang=3D"en"><head><meta charset=3D"UTF-8"><title>Cryp= to-Gram=2C July 15=2C 2026</title></head><body>
<div class=3D"preview-text" style=3D"display:none !important;mso-hide:all;= font-size:1px;line-height:1px;max-height:0px;max-width:0px;opacity:0;overf= low:hidden;">A monthly newsletter about cybersecurity and related topics.<= /div>
<h1 style=3D"font-size:140%">Crypto-Gram <br>
<span style=3D"display:block;padding-top:.5em;font-size:80%">July 15=2C 20= 26</span></h1>
<p>by Bruce Schneier
<br>Fellow and Lecturer=2C Harvard Kennedy School
<br>
schneier@schneier.com
<br><a href=3D"
https://www.schneier.com">https://www.schneier.com</a>
<p>A free monthly newsletter providing summaries=2C analyses=2C insights=
=2C and commentaries on security: computer and otherwise.</p>
<p>For back issues=2C or to subscribe=2C visit <a href=3D"
https://www.schn= eier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>
<p><a href=3D"
https://www.schneier.com/crypto-gram/archives/2026/0715.html= ">Read this issue on the web</a></p>
<p>These same essays and news items appear in the <a href=3D"
https://www.s= chneier.com/">Schneier on Security</a> blog=2C along with a lively and int= elligent comment section. An RSS feed is available.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"toc"><a name=3D"toc">I=
n this issue:</a></h2>
<p><em>If these links don't work in your email client=2C try <a href=3D"ht= tps://www.schneier.com/crypto-gram/archives/2026/0715.html">reading this i= ssue of Crypto-Gram on the web.</a></em></p>
<li><a href=3D"#cg1">The FCC Wants to Eliminate Burner Phones</a></li>
<li><a href=3D"#cg2">Flock Cameras Are Being Used for Stalking</a></li>
<li><a href=3D"#cg3">AI Use by the US Government</a></li>
<li><a href=3D"#cg4">Embedding Forbidden Text in Spyware to Discourage AI=
Analysis</a></li>
<li><a href=3D"#cg5">Anthropic=E2=80=99s Fable and the State of AI</a></li=
<li><a href=3D"#cg6">Professional Athletes and Wearables</a></li>
<li><a href=3D"#cg7">Anthropic=E2=80=99s Fable 5 Model Jailbroken Within D= ays</a></li>
<li><a href=3D"#cg8">Interesting Paper Exploring Prompt Injection</a></li> <li><a href=3D"#cg9">AI and Liability</a></li>
<li><a href=3D"#cg10">One Million Passports Leaked Online</a></li>
<li><a href=3D"#cg11">Meta Is Testing Facial Recognition for Police and Mi= litary</a></li>
<li><a href=3D"#cg12">Robot Police Officers</a></li>
<li><a href=3D"#cg13">Factoring RSA Keys with Many Zeros</a></li>
<li><a href=3D"#cg14">The Realities of AI Video Surveillance</a></li>
<li><a href=3D"#cg15">Papa Johns Surveillance-Based Advertising</a></li>
<li><a href=3D"#cg16">Cybersecurity Mission Creep in the US</a></li>
<li><a href=3D"#cg17">Flock Cameras Can Surveil Cars Without License Plate= s</a></li>
<li><a href=3D"#cg18">France to Stop Certifying Non-Quantum-Safe Encryptio= n</a></li>
<li><a href=3D"#cg19">Google Is Suing Chinese Scammers Who Are Using Gemin= i</a></li>
<li><a href=3D"#cg20">Cybersecurity and the Gap Between Skill and Ability<= /a></li>
<li><a href=3D"#cg21">The Language of AI Could Change How Humans Speak</a>= </li>
<li><a href=3D"#cg22">AI Surveillance and Social Progress</a></li>
<li><a href=3D"#cg23">AI Data Centers and the Concentration of Wealth</a><=
<li><a href=3D"#cg24">Vulnerability in FIFA=E2=80=99s Network</a></li>
<li><a href=3D"#cg25">Upcoming Speaking Engagements</a></li>
</ol>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg1"><a name=3D"cg1">T=
he FCC Wants to Eliminate Burner Phones</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/the-fcc-wants= -to-eliminate-burner-phones.html"><strong>[2026.06.15]</strong></a> A pro= posed FCC rule would <a href=3D"
https://www.404media.co/fcc-wants-to-kill-= burner-phones-by-forcing-telecoms-to-get-all-customers-ids/">kill</a> burn=
er phones: phones whose accounts are not attached to a particular person.<=
<blockquote><p>The FCC plans to do this by legally forcing the country=E2= =80=99s telecoms to store a wealth of personal information about essential=
ly all phone customers=2C including a government issued identification num=
ber and their physical address=2C alarming privacy advocates and civil rig=
hts activists who compare the measures to those from authoritarian countri=
es where it can be difficult to buy a mobile phone plan without giving up=
your identity.</p>
<p>The proposed change would drastically shake up how people obtain phone=
plans in the U.S.=2C and have all sorts of privacy and cybersecurity knoc= k-on effects. The FCC is proposing the data collection partly as a way to=
combat scammers=2C with telecoms being required to collect other informat=
ion on business and foreign customers like the intended use case of their=
bulk phone plan purchase and their IP address. But the changes would mean=
telecoms collect data on all new and renewing customers=2C and the FCC pr= ovides a long list of other things that the collected data could help auth= orities with.</p></blockquote>
<p><a href=3D"
https://archive.ph/ZwXMG">Alternate link</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg2"><a name=3D"cg2">F= lock Cameras Are Being Used for Stalking</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/flock-cameras= -are-being-used-for-stalking.html"><strong>[2026.06.16]</strong></a> Ther=
e are over a dozen cases around the country where police officers are usin=
g the Flock surveillance camera system to obsessively and illegally <a hre= f=3D"
https://www.404media.co/cops-keep-getting-arrested-for-using-flock-to= -stalk-people/">stalk people</a>.</p>
<p><a href=3D"
https://archive.ph/l5KcH">Alternate link</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg3"><a name=3D"cg3">A=
I Use by the US Government</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/ai-use-by-the= -us-government.html"><strong>[2026.06.17]</strong></a> On 14 April=2C the=
Trump administration quietly acknowledged the widespread use of AI to aut= omate government processes. The office of management and budget (OMB) <a h= ref=3D"
https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventor= y/commit/3c225ba8438e48306ace7698c8c7feb9486cbc69">disclosed</a> a stagger=
ing 3=2C611 active or planned use cases for AI across the federal governme=
nt. The list has <a href=3D"
https://fedscoop.com/disclosed-government-ai-u= se-increased-in-2025-omb/">ballooned</a> by 70% from the one published in=
the final year of the Biden administration=2C and includes many disturbin= g-seeming plans to hand over sensitive governmental functions to AI.</p>
<p>Scanning this list=2C many readers may find many causes for alarm. It r= epresents a transfer of decision processes from human to machine on a mass=
ive scale over matters of individual freedom=2C public health and well-bei= ng=2C nuclear reactor safety and more.</p>
<p>Consider these examples. The Health and Human Services=E2=80=99 (HHS) o= ffice of administration for children and families hired the world=E2=80=99=
s =E2=80=9C<a href=3D"
https://www.sciencefocus.com/future-technology/insid= e-palantir-the-worlds-scariest-ai-company">scariest AI company=2C</a>=E2= =80=9D Palantir -- notorious for its work on behalf of the military=2C the=
CIA and ICE -- to <a href=3D"
https://nsanders.me/us-canada-ai-use-case-co= mparison/record.html?id=3DUS25-2381">scan</a> all grant applications to fl=
ag those not ideologically aligned with the administration=E2=80=99s dicta= tes. The Federal Bureau of Prisons is developing an AI system to <a href= =3D"
https://nsanders.me/us-canada-ai-use-case-comparison/record.html?id=3D= DOJ-0146">assess</a> the =E2=80=9Cpotential for misconduct for newly admit=
ted inmates=2C=E2=80=9D routing people into high-security confinement befo=
re they have actually done anything wrong in their custody. These read lik=
e programs fit for a Philip K Dick or George Orwell novel.</p>
<p>Other use cases insert AI into life-and-death decision making. The Depa= rtment of Veterans Affairs is developing an AI that will <a href=3D"https:= //nsanders.me/us-canada-ai-use-case-comparison/record.html?id=3DVA-25-5182= ">listen in</a> on calls to the veterans crisis line=2C and then gather in= formation from external databases to assess the mental state and suicide r=
isk of the caller.</p>
<p>The Department of Energy is testing the use of AI to <a href=3D"https:/= /nsanders.me/us-canada-ai-use-case-comparison/record.html?id=3DDOE-527">co= ntrol</a> nuclear reactors=2C targeting a way to autonomously respond to p= otential nuclear safety incidents. Here=E2=80=99s one that=E2=80=99s distu= rbing for its retirement=2C rather than its deployment: the state departme=
nt has <a href=3D"
https://nsanders.me/us-canada-ai-use-case-comparison/rec= ord.html?id=3DUS25-3935">ended</a> a program to use AI to forecast mass ci= vilian killings=2C which had been <a href=3D"
https://nsanders.me/us-canada= -ai-use-case-comparison/record.html?id=3DUS24-960">intended</a> to aid con= flict prevention.</p>
<p>While it=E2=80=99s easy to raise questions about these and similar uses=
of AI=2C the reality is that any of these programs could be implemented r= esponsibly. In some cases=2C like the HHS system=2C the AI might be enforc=
ing alignment to a policy prescription that opponents abhor. But that conc=
ern is more about the policy itself rather than the idea that agencies sho=
uld comply with executive orders.</p>
<p>In other cases=2C there may even be bipartisan agreement on the goal=2C=
like taking urgent action to help veterans at risk of self-harm. Lots of=
work and validation is needed to prove AI safe and effective for these us=
e cases and convince the public it is appropriate=2C but the idea is plaus= ible.</p>
<p>In other cases=2C a scary-sounding AI use may not even be new. The use=
of predictive methods and statistics to assign prisoner security classifi= cations goes back <a href=3D"
https://www.ojp.gov/ncjrs/virtual-library/abs= tracts/inmate-classification-securitycustody-considerations">decades</a>=
=2C even if such systems are often <a href=3D"
https://www.ojp.gov/ncjrs/vi= rtual-library/abstracts/inmate-classification-securitycustody-consideratio= ns">biased</a> and <a href=3D"
https://wou.omeka.net/s/repository/item/1458= 0#lg=3D1&slide=3D0">ineffective</a>.</p>
<p>Using autonomous systems for model predictive control (MPC) of nuclear=
reactors is a <a href=3D"
https://www.mdpi.com/1996-1073/16/3/1443">well s= tudied</a>=2C and a widely applied aspect of nuclear plant management. And=
the recently disclosed addition of AI was <a href=3D"
https://www.osti.gov= /doecode/biblio/108606">initiated</a> under the Biden administration.</p>
<p>But anyone reviewing the 2025 inventory could be forgiven for leaping t=
o severe conclusions. What matters are the details of how the AI system is=
used=2C and here the inventory is severely lacking.</p>
<p>The disclosures carry minimal information=2C and lack the context neces= sary to understand their purpose and approach. The descriptions are typica=
lly just a sentence=2C and rarely more than a paragraph.</p>
<p>And while the process theoretically involves some form of public consul= tation=2C in reality there is generally none. It would take an eagle-eyed=
citizen to even come across this disclosure. Unless you read <a href=3D"h= ttps://fedscoop.com/us-government-annual-tally-ai-use-cases-coming-soon/">= FedScoop</a> regularly=2C or watch the OMB=E2=80=99s federal chief informa= tion officer=E2=80=99s <a href=3D"
https://github.com/ombegov">GitHub accou= nt</a>=2C you probably missed it.</p>
<p>Only one of the examples cited above (the DoJ) even proposes to involve=
the public. Under the administration=E2=80=99s policy=2C it=E2=80=99s not=
required for the rest because they are not classified as =E2=80=9Chigh im= pact=E2=80=9D use cases -- a label that is applied <a href=3D"
https://cdt.= org/insights/one-year-retrospective-on-the-federal-governments-implementat= ion-of-updated-ai-guidance-accelerating-usage-with-incomplete-safeguards/"= >inconsistently</a> across agencies.</p>
<p>We wrote a <a href=3D"
https://mitpress.mit.edu/9780262049948/rewiring-d= emocracy/">book</a> surveying applications of AI to democratic processes w= orldwide=2C including executive agencies as well as the courts=2C legislat= ures and politics. Our conclusion was that=2C while there are inappropriat=
e applications of AI in governance that should be resisted=2C an urgent ne=
ed to reform the economics of AI=2C and an imperative for renovating the d= emocratic systems it is being unleashed on=2C there are also valuable and=
beneficial use cases for AI in government.</p>
<p>Machine translation is a good example. Customs and Border Protection (C=
BP) has deployed an <a href=3D"
https://nsanders.me/us-canada-ai-use-case-c= omparison/record.html?id=3DDHS-2388">AI translation system</a> to help off= icers when human interpreters are not available. The idea that CBP=2C an a= gency under heavy <a href=3D"
https://oversightdemocrats.house.gov/immigrat= ion-dashboard">scrutiny</a> for reported abuses of human rights=2C would d= irect people to talk to a machine instead of a person may strike many as i= nhumane.</p>
<p>It=E2=80=99s true that human interpreters have very real <a href=3D"htt= ps://www.atanet.org/advocacy-outreach/think-ai-should-replace-interpreters= -think-again/">advantages</a> when it comes to understanding nuance from p= hysical cues and social context. But an officer with a competent AI transl= ator available immediately is better than one who cannot communicate with=
the person in front of them.</p>
<p>The Trump administration=E2=80=99s AI use case inventory has 70 such <a=
href=3D"
https://nsanders.me/us-canada-ai-use-case-comparison/?q=3Dtransla= te+OR+translation">translation use cases</a>=2C up from 58 in the Biden ad= ministration=E2=80=99s 2024 disclosure.</p>
<p>Disclosure of AI use cases could be a means to build public confidence=
and trust=2C but only if paired with consistent=2C meaningful public cons= ultation. <a href=3D"
https://statescoop.com/washington-dc-civic-engagement= -platform-ai-policy/">Washington DC</a> and <a href=3D"
https://insider.gov= tech.com/california/news/state-launches-third-engaged-california-conversat= ion-on-ai">California</a> are actively engaging the public to determine wh=
ere and how it=E2=80=99s appropriate to use AI in government processes=2C=
or for government to regulate AI use in society.</p>
<p>Both have held public deliberations on this topic at a wide scale=2C us=
ing AI platforms. These examples demonstrate the potential for capturing b= road-based public input to steer AI policy.</p>
<p>The international gold standard was arguably set by the French in 2016=
=2C via their <a href=3D"
https://www.houdart.org/les-obligations-de-transp= arence-des-algorithmes-dans-le-secteur-public/">Digital Republic Act</a>.=
The law=2C itself informed by an online citizen <a href=3D"
https://www.op= engovpartnership.org/stories/digital-republic-bill-frances-first-open-bill= /">consultation</a>=2C requires all algorithms used to automate government=
administrative decisions to be subject to public records requests=2C to b=
e appealable to a human reviewer=2C and to have mandatory notification of=
the use of automation to those affected by the decisions.</p>
<p>Canada offers another example of what more rigorous and participatory d= isclosure might look like. In 2025=2C they <a href=3D"
https://www.canada.c= a/en/treasury-board-secretariat/news/2025/11/canada-launches-first-registe= r-of-ai-uses-in-federal-government.html">launched</a> an AI use case <a hr= ef=3D"
https://open.canada.ca/data/en/dataset/fcbc0200-79ba-4fa4-94a6-00e32= facea6b">registry</a>=2C not unlike the US inventory. However=2C Canada <a=
href=3D"
https://worldprivacyforum.org/documents/9/WPF_AI_Governance_Canad= a_AIA_August2024_fs.pdf">also has</a> a federal directive mandating a tran= sparent risk-scoring and impact assessment <a href=3D"
https://www.canada.c= a/en/government/system/digital-government/digital-government-innovations/r= esponsible-use-ai/algorithmic-impact-assessment.html">process</a> for auto= mated systems that make administrative decisions about citizens.</p>
<p>That longstanding directive requires a detailed explanation of risks an=
d benefits as well as <a href=3D"
https://www.canada.ca/en/government/syste= m/digital-government/digital-government-innovations/responsible-use-ai/alg= orithmic-impact-assessment.html#:~:text=3Dconsultation%20approach%20with%2= 0federal%20colleagues%2C%20clients%20or%20interest%20groups%20that%20repre= sent%20clients%20or%20other%20partners">consultation</a> with certain stak= eholders from the conception of the AI use case. The Canadian system could=
be improved; it could require a public comment period and an obligation f=
or agencies to respond substantively to feedback before engaging in sensit=
ive uses of AI.</p>
<p>AI offers real potential to improve the efficacy=2C efficiency and acce= ssibility of government. But=2C equally=2C there is legitimate reason for=
public concern and distrust that can only be addressed through transparen=
cy and dialog. The US should adopt=2C at the federal and state level=2C al= gorithmic impact risk assessment procedures and public comment processes t=
o facilitate a safe=2C trusted=2C equitable transformation of government a= gencies to take advantage of modern technology.</p>
<p><em>This essay was written with Nathan E. Sanders=2C and originally app= eared in <a href=3D"
https://www.theguardian.com/commentisfree/2026/jun/15/= ai-use-by-the-us-government-is-ballooning-and-the-lack-of-transparency-is-= troubling">The Guardian</a>.</em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg4"><a name=3D"cg4">E= mbedding Forbidden Text in Spyware to Discourage AI Analysis</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/embedding-for= bidden-text-in-spyware-to-discourage-ai-analysis.html"><strong>[2026.06.1= 8]</strong></a> At least one malware developer is <a href=3D"
https://x.com= /jsrailton/status/2064661778978533571">adding text</a> about nuclear and b= iological weapons to their spyware=2C in an effort to stop automatic AI an= alysis.</p>
<p><a href=3D"
https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-wor= ms-target-bioinformatics-and-mcp-developers-via-malicious">Details</a>:</p=
<blockquote><p>The _index.js payload begins with a large JavaScript block=
comment containing fake system instructions and policy-triggering content=
=2E Because it is inside a comment=2C it does not affect JavaScript executio= n. The runtime skips it. The real malware begins after the comment with a=
try{eval(...)} wrapper around a large character-code array and a ROT-styl=
e substitution function.</p>
<p>This header appears designed for AI-mediated analysis=2C not for Node=
=2C Bun=2C or Python. It attempts to derail scanners or analyst copilots t=
hat feed the beginning of a file to a language model without clearly isola= ting the content as untrusted data. In weak pipelines=2C this can cause re= fusal behavior=2C prompt confusion=2C context pollution=2C or premature cl= assification before the scanner reaches the actual malware.</p>
<p>This is not a magical bypass against static detection. YARA rules=2C en= tropy checks=2C AST parsing=2C string extraction=2C deobfuscation=2C and b= ehavioral rules still work. But it is a practical anti-analysis trick agai=
nst naive LLM-first triage systems.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg5"><a name=3D"cg5">A= nthropic=E2=80=99s Fable and the State of AI</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/anthropics-fa= ble-and-the-state-of-ai.html"><strong>[2026.06.19]</strong></a> On June 9= th=2C Anthropic <a href=3D"
https://www.anthropic.com/news/claude-fable-5-m= ythos-5">released</a> its Fable generative AI model. Three days later=2C t=
he US government <a href=3D"
https://www.explainx.ai/blog/us-government-ban= s-fable-5-mythos-5-anthropic-export-control-2026">classified</a> it as a d= angerous munition=2C and used its export-control authority to <a href=3D"h= ttps://www.theguardian.com/technology/2026/jun/13/anthropic-disable-advanc= ed-ai-models-us-government-order">prohibit</a> any foreign nationals from=
accessing it. Unable to differentiate between Americans and foreigners=2C=
the company <a href=3D"
https://www.anthropic.com/news/fable-mythos-access= ">shut off</a> access for everyone.</p>
<p>The government=E2=80=99s actions <a href=3D"
https://freefable.org/">won= =E2=80=99t help</a>. The problem isn=E2=80=99t any one particular model; i= t=E2=80=99s the general trend of increasing AI capabilities. And any real=
solution requires the sort of collective action that just isn=E2=80=99t p= ossible right now.</p>
<p>Fable is the constrained version of Mythos=2C the AI model Anthropic an= nounced in April. Anthropic only released it to a few <a href=3D"
https://w= ww.anthropic.com/glasswing">selected</a> organizations=2C because the comp=
any claimed it was <a href=3D"
https://red.anthropic.com/2026/mythos-previe= w/">so good</a> at finding and exploiting vulnerabilities in computer code=
that releasing it more generally would be <a href=3D"
https://www.theguard= ian.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai">d= angerous</a>.</p>
<p>It was an obviously self-serving announcement=2C and because <a href=3D= "
https://www.schneier.com/essays/archives/2026/04/mythos-sets-the-world-on= -edge-what-comes-next-may-push-us-beyond.html">few</a> were able to verify=
Anthropic=E2=80=99s claims they were met with <a href=3D"
https://kingy.ai= /ai/too-dangerous-to-release-or-just-too-expensive-the-real-reason-anthrop= ic-is-hiding-its-most-powerful-ai/">some</a> <a href=3D"
https://www.flying= penguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-= anthropic/">skepticism</a>. Those with access used Mythos to <a href=3D"ht= tps://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic= s-latest-ai-model-identifies-thousands-of-zero-day-vulnerabilities-in-ever= y-major-operating-system-and-every-major-web-browser-claude-mythos-preview= -sparks-race-to-fix-critical-bugs-some-unpatched-for-decades">find</a> and=
<a href=3D"
https://www.helpnetsecurity.com/2026/04/08/anthropic-claude-my= thos-preview-identify-vulnerabilities/">patch</a> <a href=3D"
https://www.a= nthropic.com/research/glasswing-initial-update">many</a> <a href=3D"https:= //blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilitie= s/">vulnerabilities</a> in their own software. But one UK group <a href=3D= "
https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capa= bilities">found</a> the latest=2C already public=2C OpenAI model to be jus=
t as powerful.</p>
<p>Fable is just another <a href=3D"
https://spectrum.ieee.org/ai-cybersecu= rity-mythos">incremental improvement</a> in the years-long climb of AI cap= abilities. But just as important as the AI model is the =E2=80=9Charness.= =E2=80=9D This is typically not AI. It=E2=80=99s ordinary computer code th=
at interfaces with the user. It stitches together AI models=2C decides how=
and for what purposes they can be used=2C and gives them useful tools suc=
h as web search and the ability to run their own computer code.</p>
<p>When Mythos first entered limited release=2C there was widespread <a hr= ef=3D"
https://news.ycombinator.com/item?id=3D48398649">debate</a> whether=
its power came from the model or the harness. With Mythos demonstrating t=
hat it was possible=2C the open-source community scrambled to <a href=3D"h= ttps://www.linkedin.com/pulse/move-over-mythos-here-comes-pretty-much-any-= other-model-gojcf">build</a> <a href=3D"
https://www.aikido.dev/blog/mythos= -vs-harness">harnesses</a> that could <a href=3D"
https://www.microsoft.com= /en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-t= hreat-landscape/">steer</a> other AI models towards similar capabilities.=
Harness improvements don=E2=80=99t need massive data or data centers.</p>
<p>They largely succeeded. For example=2C a Prague company was able to <a=
href=3D"
https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-f= rontier">replicate</a> Anthropic=E2=80=99s few verifiable cybersecurity ca= pabilities with a much smaller and cheaper model -- and a more sophisticat=
ed harness. Last week=2C a group <a href=3D"
https://openrouter.ai/blog/ann= ouncements/fusion-beats-frontier/">showed that</a> multiple cheaper models=
harnessed in concert matches Fable=E2=80=99s performance.</p>
<p>The broader community had only a few days with Fable=2C but that time w=
e learned some <a href=3D"
https://www.explainx.ai/blog/fable-5-top-10-use-= cases-2026">about</a> <a href=3D"
https://aitoolsclub.com/i-tested-claude-f= able-5-with-5-real-world-prompts-heres-what-it-can-actually-do/">its</a> <=
a href=3D"
https://promptslove.com/blog/claude-fable-mythos-review/">capabi= lities</a>. Its difference is less the new model=E2=80=99s raw analytical=
and problem solving capabilities=2C and more that the model doesn=E2=80=
=99t need that sophisticated harness.</p>
<p>Fable requires much less expertise and detailed prompting from the huma=
n user. You can give it a difficult goal and it will figure out novel and=
unexpected ways to satisfy it=2C finding <a href=3D"
https://www.theguardi= an.com/commentisfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai">lo= opholes</a> in whatever constraints you or the system have imposed on it.<=
<p>=E2=80=9CRelentlessly proactive=E2=80=9D is how AI researcher Simon Wil= lison <a href=3D"
https://simonwillison.net/2026/Jun/11/fable-is-relentless= ly-proactive/">described</a> it. Another descriptor might be =E2=80=9Ccrea= tive.=E2=80=9D Experienced AI developers have had that combination of crea= tivity and proactivity <a href=3D"
https://ghuntley.com/ralph/">since</a> <=
a href=3D"
https://amplitude.com/blog/ralph-loop">last</a> <a href=3D"https= ://ghuntley.com/loop/">year</a>=2C but Fable puts it within easy reach of=
everyone.</p>
<p>In the hands of someone with a legitimate problem that needs solving=2C=
that can be an incredibly useful capability. But in the hands of someone=
who wants to do harm=2C it can be equally dangerous. AIs don=E2=80=99t ha=
ve a moral compass in the same way that people do. They are agents of the=
wants and desires of the people who prompt them.</p>
<p>That points to the real problem with relentlessly proactive AI. In lang= uage=2C wants and desires are always underspecified. If I ask you to get m=
e some coffee=2C you would probably pour me a cup from the coffeepot=2C or=
buy one from a nearby coffee shop.</p>
<p>You couldn=E2=80=99t buy me a pound of raw beans=2C or a coffee plantat= ion. You wouldn=E2=80=99t order a cup of coffee for delivery next month. Y=
ou wouldn=E2=80=99t find a nearby person=2C rip a cup of coffee out of the=
ir hands=2C and bring it to me. I wouldn=E2=80=99t have to specify any of=
the million limitations to my request; you would just know.</p>
<p>Human stories are filled with warnings about underspecified desires. Ki=
ng Midas wished that everything he touch turn to gold=2C forgetting to add=
=E2=80=9Cbut not my food=2C drink=2C and daughter.=E2=80=9D And genies ar=
e notorious for granting your wish in a way you wish they hadn=E2=80=99t.<=
<p>The deeper point is that it=E2=80=99s impossible to list all limitation=
s and restrictions=2C and like a malicious genie=2C a creative AI will fin=
d the ones you forgot. Block a database you don=E2=80=99t want it to have=
access to=2C and it might figure out how to bypass your control. Ask it t=
o book a flight=2C and it might hack the airline because the website says=
the flight is sold out. Ask it to save money on your cellphone plan=2C an=
d it might cancel it altogether -- or get someone else to pay for it. As f=
ar as we know now AI has not done any of this yet=2C but you get the idea.=
<p>Malicious intent is not required. To an AI model=2C constraints are jus=
t things to get around and not general truisms about the world. They are c= reative problem solvers and natural rule breakers. They =E2=80=9Chack=E2= =80=9D in the <a href=3D"
https://www.belfercenter.org/publication/coming-a= i-hackers">sense</a> that they find and exploit loopholes.</p>
<p>Human systems rely on so many norms that we scarcely recognize the exis= tence of until they are broken. AIs naturally think outside the box=2C bec= ause they don=E2=80=99t have any real conception of what the box is or why=
it=E2=80=99s there in the first place.</p>
<p>There is no foolproof way to prevent people from using AI models to com= plete harmful tasks. There is no way to prevent the models from incidental=
ly causing harm while completing benign tasks. AI models are no longer iso= lated from the real world. They browse the internet and answer emails.</p>
<p>They trade stocks and make purchases. They control physical systems. Th=
ey are=2C <a href=3D"
https://www.schneier.com/blog/archives/2016/02/the_in= ternet_of_1.html">in effect</a>=2C robots that affect life and property. W=
e have no technical mechanisms to verify the <a href=3D"
https://spectrum.i= eee.org/data-integrity">integrity</a> of an AI system. This level of capab= ility and creativity in the hands of us untrustworthy humans will have bot=
h great and terrible results.</p>
<p>The problem is not unique to <a href=3D"
https://www.theguardian.com/tec= hnology/anthropic">Anthropic</a>. Mythos/Fable might currently be the most=
capable rules hacker=2C but more sophisticated harnesses give other model=
s similar capabilities. And we should assume that the other frontier model=
s are no more than a few months behind=2C and that open-source models are=
less than a year behind. At best=2C any ban only serves to delay the prob=
lem for a short while.</p>
<p>That delay might be useful if we -- as a society=2C as a planet -- woul=
d use that time to come together and figure out what to do. This isn=E2=80= =99t a US/China arms race problem; this a species-level problem that requi=
res coordinated action at that scale. Unfortunately=2C we have no mechanis=
m to do that. I first <a href=3D"
https://www.schneier.com/academic/archive= s/2021/04/the-coming-ai-hackers.html">wrote about</a> this problem five ye=
ars ago=2C but it was all too futuristic.</p>
<p>Today=2C when its right in front of us=2C there is no world government=
that can impose constraints on the for-profit corporations currently cont= rolling AI models and research. The US has no appetite to effectively and=
even-handedly regulate those corporations=2C even as they do catastrophic=
damage to the environment=2C democracy=2C and -- in this case -- society=
in general.</p>
<p>This all makes an AI <a href=3D"
https://www.brookings.edu/articles/how-= public-ai-can-strengthen-democracy/">public</a> <a href=3D"
https://thereno= vator.substack.com/p/rewiring-democracy-now-switzerland">option</a> all th=
e more necessary=2C and urgent. Today=E2=80=99s AIs can be fast=2C smart a=
nd secure=2C but only two of the three are possible for any given system.=
These safety tradeoffs are tightly held secrets of companies racing to be=
at one another=2C and they tell us we have to trust them. Instead=2C the c= hoices and their consequences need to be brought out into the sunlight.</p=
<p>We should be funding open-source harnesses that balance capability and=
safety -- that achieve useful goals without so much power -- and open-sou=
rce AI models whose provenance and biases are public and well understood.=
We have opened the AI Pandora=E2=80=99s box. Now we have to make the best=
of it.</p>
<p><em>This essay originally appeared in <a href=3D"
https://www.theguardia= n.com/commentisfree/2026/jun/16/anthropic-fable-ai">The Guardian</a>.</em>=
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg6"><a name=3D"cg6">P= rofessional Athletes and Wearables</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/professional-= athletes-and-wearables.html"><strong>[2026.06.22]</strong></a> I haven=E2= =80=99t thought about the <a href=3D"
https://www.hardresetmedia.com/p/wnba= -players-labor-contract-wearables">privacy issues</a> surrounding professi= onal athletes and wearables.</p>
<blockquote><p>Wearables present <a href=3D"
https://iapp.org/news/a/the-di= gital-body-rethinking-privacy-and-security-in-wearable-health-trackers">se= rious privacy issues</a> for =E2=80=9CAverage Joe=E2=80=9D consumers=2C wh=
o are entrusting tech companies to safely store and protect their biometri=
c data. Imagine the stakes for a professional athlete=2C whose entire live= lihood could be affected by a single biometric data point. To give one of=
many realistic hypotheticals: a basketball player has a terrible game=2C=
and the coach wonders if they showed up to the gym hungover. The coach ha=
s access to the player=E2=80=99s wearable data=2C and checks to see when t=
hey went to sleep=2C as well as what their heart rate looked like during t=
he night. Should the player have been out partying before a game? No. Shou=
ld the coach be able to surveil them? Definitely not.</p>
<p>It will not surprise you to learn that there=E2=80=99s an emergent gamb= ling angle here: sports leagues would love to commercialize players=E2=80=
=99 biometric data=2C and sharp bettors would love access to data about=2C=
say=2C a hungover player. =E2=80=9CWe=E2=80=99re going to get to a spot w= here people are betting not just on the velocity of the puck that was shot=
by a player in the NHL playoffs=2C but on what the heart rate of a certai=
n player is going to be running down the field=2C=E2=80=9D said Helen =E2= =80=9CNellie=E2=80=9D Drew=2C the director of the University of Buffalo=E2= =80=99s Center for the Advancement of Sport=2C and a professor of practice=
in sports law.</p>
<p>There are other practical considerations=2C too. What if wearable data=
reveals that a player isn=E2=80=99t as speedy as they were before=2C and=
a team uses that data against the player during contract negotiations? Wh=
at if a wearable reveals a player is favoring their leg=2C or is at greate=
r risk of injury? This information is potentially beneficial to a training=
staff and an athlete=2C so long as it=E2=80=99s disclosed and used in a r= esponsible manner -- a critical=2C mostly unresolved caveat. =E2=80=9CAgin=
g and injured players are the most at-risk=E2=80=9D of wearable data being=
used against them=2C said Michael LeRoy=2C who researches sports labor la=
ws and AI=2C and is a professor at the University of Illinois=E2=80=99s Sc= hool of Labor and Employment Relations.</p></blockquote>
<p>The bit about gamblers is particularly scary.</p>
<p>I have often said that surveillance tech is generally deployed first ag= ainst people with diminished rights: children=2C prisoners=2C military per= sonnel=2C the mentally impaired. This is another early use case with diffe= rent dynamics. The surveilled are wealthy and powerful=2C and -- in many c= ases -- unionized.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg7"><a name=3D"cg7">A= nthropic=E2=80=99s Fable 5 Model Jailbroken Within Days</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/anthropics-fa= ble-5-model-jailbroken-within-days.html"><strong>[2026.06.23]</strong></a=
Fable 5 is the supposed safe version of Anthropic=E2=80=99s Mythos Previ=
ew=2C with guardrails to ensure that it can=E2=80=99t be used to create cy= berattacks.</p>
<p>Well=2C that restriction was <a href=3D"
https://cybersecuritynews.com/a= nthropics-claude-fable-5-jailbroken/">bypassed</a> within days.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg8"><a name=3D"cg8">I= nteresting Paper Exploring Prompt Injection</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/interesting-p= aper-exploring-prompt-injection.html"><strong>[2026.06.25]</strong></a> <=
a href=3D"
https://role-confusion.github.io/">This</a> is a fascinating exp= lotation of how LLMs fall for prompt injection attacks. It turns out that=
they learn to recognize the style of text in different role/instruction b= locks=2C and not just the tags.</p>
<p>Their conclusion:</p>
<blockquote><p>Role tags were a formatting trick that became the security=
architecture and the cognitive scaffolding of modern LLMs. We=E2=80=99ve=
shown that this architecture doesn=E2=80=99t survive into the model=E2=80= =99s actual representations=2C and that such role confusion is linked to p= rompt injection.</p>
<p>Unless LLMs achieve genuine role perception=2C we think injection defen=
se will remain a perpetual whack-a-mole game. And the continuous nature of=
role boundaries opens the threat of injections designed to subtly shift L=
LM states through seemingly innocuous text=2C legally and at scale.</p>
<p>More generally=2C roles are quietly one of the most important abstracti=
ons in the LLM stack=2C providing the boundaries meant to separate self fr=
om other=2C thought from communication=2C instruction from data. They=E2= =80=99re human-controlled switches in an otherwise continuous system. We t= hink they deserve a lot more study than they=E2=80=99ve gotten.</p></block= quote>
<p>Full paper: =E2=80=9C<a href=3D"
https://arxiv.org/abs/2603.12277">Promp=
t Injection as Role Confusion</a>.=E2=80=9D Simon Willison <a href=3D"http= s://simonwillison.net/2026/Jun/22/prompt-injection-as-role-confusion/">com= ments</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg9"><a name=3D"cg9">A=
I and Liability</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/ai-and-liabil= ity.html"><strong>[2026.06.25]</strong></a> Earlier this month=2C a Germa=
n court <a href=3D"
https://the-decoder.com/landmark-german-ruling-declares= -googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-= answers/">ruled</a> that Google is liable for its AI search summaries. Rej= ecting defenses like =E2=80=9Cusers can check for themselves=2C=E2=80=9D a=
nd that they generally know =E2=80=9Cthat information generated with AI sh= ould not be blindly trusted=2C=E2=80=9D the court held that the AI=E2=80=
=99s summaries are reflections of the company and =E2=80=9Cabove all an ex= pression of Google=E2=80=99s business activities.=E2=80=9D</p>
<p>This is the latest skirmish in a decades-old battle over internet publi= shing. Historically=2C there were two different types of information distr= ibutors: carriers and publishers. A phone company is a carrier. It=E2=80=
=99ll transmit whatever you say=2C even discussions about committing a cri=
me. Words are words=2C and the phone company does not know -- nor is it li= able for -- the words you choose to speak. A newspaper=2C on the other han= d=2C is a publisher. It decides the words it publishes=2C and what quotes=
to include in its articles. If those words or quotes are defamatory or ot= herwise illegal=2C it=E2=80=99s liable.</p>
<p>Internet companies have long tried to play both ends of this distinctio=
n. They claim to be a carrier when it suits them=2C and also to be a publi= sher when that is advantageous. <a href=3D"
https://www.law.cornell.edu/usc= ode/text/47/230">Section 230</a> of the 1996 Communication Decency Act ens= hrined this straddling when it shielded internet providers from liability=
for the speech of others on their platforms: =E2=80=9CNo provider or user=
of an interactive computer service shall be treated as the publisher or s= peaker of any information provided by another information content provider= =2E=E2=80=9D</p>
<p>For years=2C a debate has continued about how to apply this law to soci=
al media platforms. When platforms merely displayed people=E2=80=99s posts=
and comments in reverse-chronological order=2C they behaved largely like=
carriers=2C relaying people=E2=80=99s words without regard to their conte= nts. But the next generation of platforms=2C like Facebook=2C curated feed=
s with algorithms and thereby acted more like publishers=2C making editori=
al decisions about who sees what. Some experts think section 230 has gone=
too far and <a href=3D"
https://ash.harvard.edu/articles/sunset-and-renew-= section-230-should-protect-human-speech-not-algorithmic-virality/">needs</= a><a href=3D"
https://www.brookings.edu/articles/back-to-the-future-for-sec= tion-230-reform/"> reform</a>; others <a href=3D"
https://www.eff.org/issue= s/cda230">think</a> that it=E2=80=99s what holds the modern internet toget= her.</p>
<p>Google=E2=80=99s AI overviews are far less nuanced. They work different=
ly from traditional search=2C which courts have <a href=3D"
https://www.eff= =2Eorg/files/parker-v-google.pdf">held</a> involves archiving and facilitati= ng access to the editorial content of third parties. AI overviews don=E2= =80=99t just quote and republish words from different websites. With overv= iews=2C the AI rewrites other people=E2=80=99s words=2C exercising editori=
al discretion like a newspaper article or an original essay on a topic.</p=
<p>It=E2=80=99s not only Google=E2=80=99s AI that falls into this category=
=2E Imagine a restaurant review site that provides AI summaries=2C or a site=
summarizing laws and government procedures. Or a traditional publisher th=
at uses AI to summarize its own publication. Accuracy matters=2C and liabi= lity is one of the most important ways we as a public can demand accuracy=
and hold companies accountable when they cause harm.</p>
<p>Two years ago=2C Air Canada learned this lesson. Its AI chatbot promise=
d a discount the company later rescinded=2C arguing in court that the airl=
ine wasn=E2=80=99t responsible for the promises the bot made because it wa=
s a =E2=80=9Cseparate legal entity that is responsible for its own actions= =2E=E2=80=9D The court <a href=3D"
https://www.bbc.com/travel/article/2024022= 2-air-canada-chatbot-misinformation-what-travellers-should-know">sided</a>=
with the flyer=2C saying that the airline was just as responsible for wha=
t its chatbot says as what=E2=80=99s on its website. The potential precede=
nt here is that corporations have a <a href=3D"
https://www.americanbar.org= /groups/business_law/resources/business-law-today/2024-february/bc-tribuna= l-confirms-companies-remain-liable-information-provided-ai-chatbot/">duty=
of care</a> for the performance of the AI chatbots they employ.</p>
<p>AI agents are agents of the person or organization that deploys them --=
and should be treated by the law as such. If a company hired human writer=
s to write its summaries=2C that company would be liable for inaccuracies=
in those summaries. If a company=E2=80=99s human agent signed contracts i=
n the company=E2=80=99s name=2C that company would be bound by those contr= acts. And if a doctor gave dangerously wrong medical advice=2C they would=
be liable for <a href=3D"
https://www.nature.com/articles/s41746-026-02854= -5">malpractice</a>.</p>
<p>To allow businesses to hide behind the excuse of faulty AI in those sam=
e circumstances would be a massive handout to companies=2C and would intro= duce disastrous incentives for corporate misbehavior. Why hire human write= rs=2C lawyers or doctors when AIs are not only cheaper=2C but also absolve=
employers whenever they make a mistake?</p>
<p>We are rapidly moving to a world where AI-powered chatbots will be at t=
he other end of all sorts of corporate communications channels. It makes n=
o sense for a company to be able to honor its statements when it wants to=
and disavow them when it doesn=E2=80=99t.</p>
<p>Visa and OpenAI recently announced a <a href=3D"
https://corporate.visa.= com/en/sites/visa-perspectives/innovation/visa-openai-partnership.html">pa= rtnership</a> to build personal AI agents to=2C among other things=2C make=
purchases on our behalf. This is just one of many similar projects in the=
works=2C as companies race to provide us all with AI assistants. Will Vis=
a take responsibility when its AI makes a purchase in your name that you d= on=E2=80=99t want? And if Visa won=E2=80=99t=2C why would anyone trust the=
system? Properly allocating liability is key to make this kind of thing w= ork.</p>
<p>If the German ruling holds=2C it could be devastating for Google=E2=80=
=99s AI Overview feature. Tests from earlier this year found that it had m= istakes about <a href=3D"
https://www.nytimes.com/2026/04/07/technology/goo= gle-ai-overviews-accuracy.html">10% percent</a> of the time. At more than=
<a href=3D"
https://searchengineland.com/google-5-trillion-searches-per-ye= ar-452928">5tn</a> searches per year=2C that=E2=80=99s 16=2C000 erroneous=
summaries every second. And while most of those errors are benign=2C some=
of them will cause harm=2C be defamatory=2C or otherwise trigger liabilit= y.</p>
<p>Earlier this year=2C Google=E2=80=99s AI summary <a href=3D"
https://www= =2Etheguardian.com/music/2026/may/05/canadian-ashley-macisaac-fiddler-musici= an-singer-songwriter-sues-google-ai-sex-offender-ntwnfb">falsely identifie= d</a> the Canadian fiddler Ashley MacIsaac of being a sex offender. His la= wsuit=2C filed in Ontario=2C is ongoing. If Google is forced to invest in=
improving its AI system until those kinds of errors are exceedingly rare=
=2C that seems like a good outcome for users=2C as well as the subjects of=
search=2C like MacIsaac.</p>
<p>More generally=2C liability concerns could mean that many current use c= ases for agents won=E2=80=99t be commercially viable. Companies may not be=
able to profitably operate AI <a href=3D"
https://www.ftc.gov/news-events/= news/press-releases/2025/02/ftc-finalizes-order-donotpay-prohibits-decepti= ve-ai-lawyer-claims-imposes-monetary-relief-requires">lawyers</a>=2C <a hr= ef=3D"
https://www.washingtonpost.com/technology/2026/06/04/inside-trump-ba= cked-push-bring-ai-doctors-into-american-medicine/">doctors</a> and media=
<a href=3D"
https://www.ftc.gov/legal-library/browse/federal-register-noti= ces/16-cfr-part-465-trade-regulation-rule-use-consumer-reviews-testimonial= s-final-rule">influencers</a> if they are held responsible for what they s=
ay and do.</p>
<p>We=E2=80=99re OK with this outcome. There=E2=80=99s nothing in the law=
that requires us to accommodate AI systems if they are fundamentally untr= ustworthy=2C just as we don=E2=80=99t need to accommodate untrustworthy hu=
man systems. Any company that won=E2=80=99t stand by the statements its ag= ents make -- whether human or AI -- doesn=E2=80=99t deserve users=E2=80=99=
time or money.</p>
<p><em>This essay originally appeared in <a href=3D"
https://www.theguardia= n.com/commentisfree/2026/jun/24/ai-errors-companies-responsibility">The Gu= ardian</a>.</em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg10"><a name=3D"cg10"= >One Million Passports Leaked Online</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/one-million-p= assports-leaked-online.html"><strong>[2026.06.26]</strong></a> A database=
of almost a million passports from around the world was <a href=3D"https:= //www.theverge.com/tech/947157/passports-data-breach-cannabis-club-systems= -nefos-puffpal">leaked</a> online.</p>
<p>Note what happened. A high-value credential -- a passport -- was used i=
n an ancillary low-value authentication system: ID verification for cannab=
is dispensaries. And it=E2=80=99s the low-value system that got hacked=2C=
putting the high-value credential at risk.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg11"><a name=3D"cg11"= >Meta Is Testing Facial Recognition for Police and Military</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/meta-is-testi= ng-facial-recognition-for-police-and-military.html"><strong>[2026.06.26]<= /strong></a> We know that ICE wants to <a href=3D"
https://futurism.com/art= ificial-intelligence/ice-facial-surveillance-glasses">deploy</a> eyeglasse=
s with facial recognition that can identify people in real time.</p>
<p>Turns out Meta is <a href=3D"
https://www.wired.com/story/meta-rank-one-= computing-face-recognition-smart-glasses/">prototyping</a> the feature wit=
h a Pentagon supplier. (Alternate <a href=3D"
https://gizmodo.com/meta-is-t= esting-police-surveillance-tech-for-its-smart-glasses-2000771931">news</a>=
story.)</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg12"><a name=3D"cg12"= >Robot Police Officers</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/robot-police-= officers.html"><strong>[2026.06.29]</strong></a> We=E2=80=99ve taken one=
small step towards robot police officers: a drone capable of disarming a=
suspect:</p>
<blockquote><p>In a <a href=3D"
https://www.instagram.com/reel/DZ4-tdPtbey/= ">June 22 video</a> posted on the Sacramento County Sheriff=E2=80=99s Offi= ce=E2=80=99s Instagram page=2C an officer wearing goggles can be seen oper= ating a drone to retrieve a knife from an armed suspect hiding inside a cl= uttered house. =E2=80=9CAfter not responding to negotiators=2C a drone was=
deployed inside the residence=2C=E2=80=9D the post says. =E2=80=9CDrone p= ilots located the suspect hiding in a corner of a garage=E2=80=9D and then=
used a high-powered magnet attached to the drone to grab the knife out of=
the suspect=E2=80=99s hand. In the video which is soundtracked by the=
=E2=80=9CMission: Impossible=E2=80=9D theme song -- the intercepted knife=
can be seen spinning around in the air as the drone carries it back to th=
e deputies.</p></blockquote>
<p>Slashdot <a href=3D"
https://yro.slashdot.org/story/26/06/27/0635220/cal= ifornia-sheriff-says-their-drone-disarmed-a-suspect-shares-video-on-instag= ram">thread</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg13"><a name=3D"cg13"= >Factoring RSA Keys with Many Zeros</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/factoring-rsa= -keys-with-many-zeros.html"><strong>[2026.06.29]</strong></a> Interesting=
research on a <a href=3D"
https://blog.trailofbits.com/2026/06/12/factorin= g-short-sleeve-rsa-keys-with-polynomials/">new class</a> of weak RSA keys:=
keys with lots of zeros. It turns out that these keys are out in the wild= =2E</p>
<blockquote><p>The badkeys project is an open-source service that checks p= ublic keys for known vulnerabilities. While developing this tool=2C Hanno=
collected a massive number of real-world keys from public sources=2C incl= uding Certificate Transparency logs=2C internet-wide TLS and SSH scans=2C=
PGP keys=2C and many others. By searching this dataset for unexpectedly s= parse RSA moduli=2C we uncovered a large number of keys in the wild with t=
he patterns in Figure 1.</p>
<p>Both patterns include several regularly spaced blocks of all zeros inte= rleaved with seemingly random data. Pattern 1 appears in CT logs for certi= ficates issued to several large organizations=2C including Yahoo and Veriz= on=2C and on some devices running NetApp software. Fortunately=2C these ce= rtificates have already expired=2C but we still shared our findings with t= hese companies. We wanted to learn more about which product could be respo= nsible for generating these keys=2C but we did not hear back. Pattern 2 ap= pears on SSH hosts running the CompleteFTP software from EnterpriseDT. The=
underlying vulnerability affects RSA keys generated using versions 10.0.0= 12.0.0 (Dec 2016Mar 2019) and DSA keys generated with v10.0.023.0.4 (Dec 2= 016Dec 2023).</p>
<p>These vulnerabilities affect a small minority of hosts on the internet=
=2C but the more interesting takeaway is that independent cryptographic im= plementations failed in similar ways. More implementations may include the=
same bugs=2C and so it=E2=80=99s worth tailoring cryptanalytic algorithms=
for this particular type of failure.</p></blockquote>
<p>The article doesn=E2=80=99t speculate=2C but I will. This could be a de= liberately designed backdoor=2C of the sort I <a href=3D"
https://www.schne= ier.com/essays/archives/2013/10/how_to_design_and_de.html">wrote about</a>=
back in 2013. I could imagine some government agency figuring out how to=
break this class of RSA keys=2C and then convincing different providers t=
o hand them out to users.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg14"><a name=3D"cg14"= >The Realities of AI Video Surveillance</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/06/the-realities= -of-ai-video-surveillance.html"><strong>[2026.06.30]</strong></a> The <i>= Financial Times</i> has a <a href=3D"
https://archive.ph/s6mES">good articl= e</a> on how AI is changing the capabilities of video surveillance=2C with=
information from both Israel/Iran and Russia.</p>
<blockquote><p>In contrast with older tools restricted to a few dozen pres=
et searches=2C these new tools allow an almost unlimited range of enquirie=
s by enabling language-based searches on video.</p>
<p>That lets intelligence officers hunt through massive streams of videos=
using simple search terms=2C such as two men handing a bag to each other;=
a person who has changed their appearance=2C or has changed clothes multi=
ple times in a day; or a vehicle that has recently been painted over=2C or=
has driven past the same spot several times in a short period.</p>
<p>=E2=80=9CThis is the holy grail of surveillance=2C=E2=80=9D said a Euro= pean official whose country uses the technology on its cities. =E2=80=9CWe=
are able to look for behaviour=2C not objects -- it has created a world o=
f new possibilities.=E2=80=9D</p></blockquote>
<p>I <a href=3D"
https://www.schneier.com/blog/archives/2023/12/ai-and-mass= -spying.html">wrote about</a> this sort of thing a few years ago=2C how AI=
enables mass spying in the way that computers and networks enabled mass s= urveillance. The interesting development in the article is that AI allows=
people to ask natural language questions about video footage to AIs -- an=
d AIs can answer them.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg15"><a name=3D"cg15"= >Papa Johns Surveillance-Based Advertising</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/papa-johns-su= rveillance-based-advertising.html"><strong>[2026.07.01]</strong></a> Papa=
Johns is <a href=3D"
https://www.adexchanger.com/tv/papa-johns-can-predict= -when-your-fridge-is-empty/">spying</a> on people=E2=80=99s buying activit=
ies to predict when they are low on food:</p>
<blockquote><p>The pizza chain recently tapped NBCUniversal=2C Instacart a=
nd the dentsu-owned media agency Carat for help reaching consumers when th= ey=E2=80=99re low on groceries -- and thus more likely to be swayed by a m= outh-watering ad. The idea is to reach hungry consumers by =E2=80=9Cknowin=
g what is in their fridge without being too creepy=2C=E2=80=9D said Carrie=
Drinkwater=2C chief investment officer at Carat.</p>
<p>To achieve that goal=2C NBCU and Instacart created a custom audience of=
shoppers who regularly purchase grocery staples on Instacart=2C such as e= ggs=2C milk=2C meat and produce. Based on that data=2C Papa Johns can dete= rmine which days of the week certain consumers are likely to run out of gr= oceries and serve them an ad on NBCU streaming content accordingly. The br=
and served custom creatives to consumers based on their food preferences -=
- such as whether they buy meat regularly -- with QR codes and calls to ac= tion such as=2C =E2=80=9CLight on groceries?=E2=80=9D or =E2=80=9CEmpty fr= idge?=E2=80=9D</p></blockquote>
<p>Back in 2012=2C we <a href=3D"
https://www.forbes.com/sites/kashmirhill/= 2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-fath= er-did/">learned</a> (from Target and its campaign that detects when someo=
ne is pregnant) that the trick is to hide the knowledge in other=2C wrong=
=2C information. So the way for Papa Johns to not be =E2=80=9Ctoo creepy= =E2=80=9D is to deliberately get it wrong sometimes.</p>
<p>But still=2C ugh.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg16"><a name=3D"cg16"= >Cybersecurity Mission Creep in the US</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/cybersecurity= -mission-creep-in-the-us.html"><strong>[2026.07.02]</strong></a> Interest=
ing paper: =E2=80=9C<a href=3D"
https://papers.ssrn.com/sol3/papers.cfm?abs= tract_id=3D4588977">Cybersecurity Mission Creep</a>.=E2=80=9D</p>
<blockquote><p><b>Abstract:</b> Cybersecurity is experiencing mission cree=
p. Policymakers are casting more and more problems as issues of cybersecur= ity. So reframed=2C wildly different policy issues=2C from misinformation=
=2C to child social media safety laws=2C to antitrust regulations=2C to al= leged journalist misconduct=2C to anti-sex trafficking statutes become wha=
t this Article calls =E2=80=9Ccybersecuritized.=E2=80=9D Before this refra= ming=2C these issues present as important but not existential. But once cy= bersecuritization positions the issues as threats intensified by their tec= hnological nature=2C they gain access to the politics and law of urgency a=
nd exceptionalism and invite troubling governance responses.</p>
<p>Positioned as security threats=2C cybersecuritized issues become endowe=
d with the apparent normative power to override countervailing considerati= ons=2C oversimplifying the problem. Cybersecuritization=E2=80=99s oversimp= lification similarly risks unidimensional solutions and invites use of arg= umentative trump cards=2C like First Amendment challenges. Cybersecuritiza= tion also invites deference to purported specialists and their proposed so= lutions. Together=2C the reductive tendencies of cybersecuritization and t=
he deference it prompts to specialists renders ultimate governance choices=
more opaque. And this opacity can erode public trust and political legiti= macy.</p>
<p>This Article surfaces the phenomenon of cybersecuritization and offers=
a novel framework for analyzing and critiquing it. Mining cases from acro=
ss criminal and civil domains=2C the account also demonstrates the insidio= usness of cybersecuritization and the likelihood that it will continue to=
expand. Confronting cybersecuritization is crucial. If we continue to ign=
ore it=2C we risk abdicating further responsibility for difficult choices=
to the trump card of cybersecurity. This Article=E2=80=99s analysis and c= ritique aim to help reclaim the hard work of governance for our hands.</p>= </blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg17"><a name=3D"cg17"= >Flock Cameras Can Surveil Cars Without License Plates</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/flock-cameras= -can-surveil-cars-without-license-plates.html"><strong>[2026.07.03]</stro= ng></a> This is from a 2024 <a href=3D"
https://amp.newsobserver.com/news/p= olitics-government/article315990932.html">company presentation</a>:</p>
<blockquote><p>Officers can also tap into data showing a car=E2=80=99s dec= als=2C bumper stickers=2C back and top racks -- along with temporary and u= nique state tags.</p>
<p>Flock calls it a =E2=80=9CVehicle Fingerprint=E2=80=9D and it=E2=80=99s=
touted as a way for law enforcement officials to get more information =E2= =80=9Ceven when you don=E2=80=99t have full plate information=2C=E2=80=9D=
the company=E2=80=99s presentation shows.</p>
<p>The company gives police officers the ability to search that data as we= ll=2C to =E2=80=9Cbuild stronger cases with less information upfront.=E2= =80=9D That includes being able to locate multiple vehicles law enforcemen=
t officials believe are moving together and what Flock calls a =E2=80=9Cmu=
lti geo search.=E2=80=9D</p></blockquote>
<p>This kind of thing is older than AI; I wrote about it in my 2014 book <= i>Beyond Fear</i>. Edward Snowden revealed that the NSA was using cell pho=
ne location data to track phones that were habitually near each other.</p>
<p>As bad as Flock is=2C remember that anyone with broad access to cell ph=
one location data can do the same thing.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg18"><a name=3D"cg18"= >France to Stop Certifying Non-Quantum-Safe Encryption</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/france-to-sto= p-certifying-non-quantum-safe-encryption.html"><strong>[2026.07.06]</stro= ng></a> France is <a href=3D"
https://www.reuters.com/legal/litigation/fran= ce-stop-certifying-products-without-quantum-safe-encryption-2026-06-16/">a= ccelerating</a> its transition to post-quantum encryption:</p>
<blockquote><p>France=E2=80=99s cybersecurity agency ANSSI said on Tuesday=
it would stop certifying security products that lack quantum-resistant en= cryption=2C a move that will force government bodies and critical operator=
s to shift away from older systems.</p>
<p>Samih Souissi=2C ANSSI=E2=80=99s chief of staff=2C said at the France Q= uantum conference that the agency would halt such certifications from 2027=
=2C and that businesses should be buying only quantum-safe products by 203= 0.</p>
<p>ANSSI approval is required for use in French government agencies and cr= itical infrastructure=2C making the policy a de facto phase-out of older e= ncryption.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg19"><a name=3D"cg19"= >Google Is Suing Chinese Scammers Who Are Using Gemini</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/google-is-sui= ng-chinese-scammers-who-are-using-gemini.html"><strong>[2026.07.07]</stro= ng></a> Not sure <a href=3D"
https://arstechnica.com/google/2026/06/google-= sues-chinese-cybercrime-network-that-used-gemini-to-automate-scams/">this<=
will have any effect=2C but I support the effort:</p>
<blockquote><p>According to Google=E2=80=99s legal filing=2C Outsider Ente= rprise operates through Telegram. The group offers phishing-as-a-service t=
o individuals who may not be technically savvy enough to set up fraudulent=
websites and text campaigns on their own. In its Telegram channels=2C Out= sider Enterprise reportedly provided instructions on how to use Google=E2= =80=99s Gemini AI to create websites that imitate those of Google=2C YouTu= be=2C and government agencies such as New York=E2=80=99s E-ZPass. The grou=
p offered nearly 300 scam templates.</p>
<p>[...]</p>
<p>Google worked with AT&T=2C Verizon=2C and T-Mobile to block many of=
these malicious text messages=2C and Google notes that its on-device scam=
detection in Google Messages probably helped reduce the number of success=
ful phishing attempts=2C too. This AI-powered feature apparently stops 10=
billion scam texts every month=2C so it=E2=80=99s fair to expect it caugh=
t at least some Outsider Enterprise activity.</p></blockquote>
<p>Another <a href=3D"
https://www.digitaltrends.com/phones/scammers-used-g= emini-ai-to-power-a-massive-phishing-operation-and-google-just-sued-them/"= >article</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg20"><a name=3D"cg20"= >Cybersecurity and the Gap Between Skill and Ability</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/cybersecurity= -and-the-gap-between-skill-and-ability.html"><strong>[2026.07.08]</strong= ></a> Last week=2C national security agencies from the Five Eyes -- that= =E2=80=99s the rich=2C English-language-speaking countries club -- jointly=
released a <a href=3D"
https://www.nsa.gov/Press-Room/News-Highlights/Arti= cle/Article/4523810/five-eyes-cyber-security-agencies-statement/">statemen= t</a> warning of the increasing cyber risks of AI models: in particular=2C=
their ability to autonomously hack into systems and networks. The stateme=
nt was more measured than some of the <a href=3D"
https://www.theguardian.c= om/technology/2026/jun/22/anthropic-claude-fable-ai-model-artificial-intel= ligence-national-security">breathless headlines</a> about it=2C and the ad= vice they gave is pretty much the standard advice everyone gives -- albeit=
with newfound urgency.</p>
<p>Internet risks are nothing new=2C and cyberattacks -- both large and sm=
all -- have been a significant issue since long before the current crop of=
generative AI models.</p>
<p>What=E2=80=99s been changing over the decades=2C and what AI is changin=
g even faster=2C is the gap between skill and ability. For most of human h= istory=2C the two terms were synonymous -- but computers have decoupled th=
em. As the gap between the two expands=2C humans empowered with these AI t= ools can do more: more writing=2C more research=2C more analysis and also=
more damage than ever before. These models can=2C with little detailed di= rection=2C autonomously hack into networks=2C steal data=2C deploy ransomw=
are and destroy systems. And to the extent there is a solution=2C it=E2=80= =99s going to involve harnessing AI for the defense.</p>
<p>In 1998=2C seven people from the hacker group L0pht <a href=3D"
https://= www.washingtonpost.com/sf/business/2015/06/22/net-of-insecurity-part-3/">t= estified</a> <a href=3D"
https://www.veracode.com/blog/25-years-later-refle= cting-on-l0phts-1998-congress-testimonial-and-the-evolution-of-cybersecuri= ty/">before</a> <a href=3D"
https://www.youtube.com/watch?v=3DVVJldn_MmMY">= Congress</a>. They told a mostly clueless Senate committee that they could=
take down the internet in 30 minutes. That was partly real and partly bra= vado=2C but it illustrates an important point: hacking into systems=2C ste= aling data and causing damage all required skill.</p>
<p>Contrast the L0pht hackers with hackers derided as =E2=80=9Cscript kidd= ies.=E2=80=9D They didn=E2=80=99t understand computers=2C or security. Ins= tead=2C they used hacker tools written by others. Their actions required m= inimal skill and even less knowledge. But once those hacking tools became=
widespread=2C the number of potential attackers increased.</p>
<p>That number has continued to increase=2C as quality and availability of=
prewritten attack tools has grown. And it is growing dramatically with AI=
=2E Today=E2=80=99s AI systems -- not just the frontier models=2C but most o=
f them -- are capable of carrying out cyberattacks automatically. They all=
do better in the hands of skilled attackers=2C but increasingly they are=
able to act autonomously with only minimal prompting.</p>
<p>The thing about people with ability but no skill is that they are often=
outsiders=2C not part of any professional community=2C and not bound by a=
ny rules or norms. This phenomenon is much more general than in cybersecur= ity. Any doctor can tell you how to untraceably poison someone=2C and many=
virus researchers know how to create a bioweapon. Any bridge engineer can=
tell you how to place explosives to blow a bridge up. The reason that mur= derous doctors and terrorist engineers are so rare is that the lengthy pro= cess of acquiring those skills also instills a moral and ethical code. If=
every random person has access to good poisoning advice=2C that puts us a=
ll in danger.</p>
<p>Modern AI systems are=2C in effect=2C a universal adviser to help peopl=
e do harmful things. And while the current AI megacorporations are trying=
to build guardrails to prevent people from asking questions whose answers=
will enable the questioner to do harm=2C that=E2=80=99s not going to work=
in the long term. Smaller=2C cheaper=2C open-source models=2C including m= odels that can run on people=E2=80=99s computers=2C and especially groups=
of models that run in concert with each other=2C are just as good as the=
frontier models from companies like OpenAI and Anthropic. And they contin=
ue to get better. These models will be passed around from person to person=
=2C like script kiddie hacker tools=2C and they won=E2=80=99t have any suc=
h guardrails.</p>
<p>Instructing AI models to spy on people and report any malicious prompts=
to the authorities fails for similar reasons. The megacorporations can do=
that=2C but the locally run open source models won=E2=80=99t. This could=
buy us a few months at best.</p>
<p>A third possibility is to somehow make the models themselves unable to=
hack into computers=2C create bioweapons or do anything else that might h=
arm people or society. That won=E2=80=99t work=2C for the same reason we c= an=E2=80=99t teach doctors how to treat poisonings without also teaching t=
hem how to poison. It=E2=80=99s the same knowledge. It=E2=80=99s the same=
with construction and demolition. And it=E2=80=99s the same with cybersec= urity. We want these AI models to be able to review computer code=2C find=
vulnerabilities and automatically fix them. The benefit to our collective=
security will be enormous. Unfortunately=2C the same knowledge can be use=
d for attacks.</p>
<p>Where this leaves us is in a world of increased volatility. Super-power=
ed humans with AI assistants will be able to do both wonderful and horribl=
e things.</p>
<p>This brings us back to the Five Eyes statement. Everything they recomme=
nd is something security professionals have been recommending for years=2C=
if not decades. They are things talked about at that congressional hearin=
g back in 1998=2C titled =E2=80=9CWeak computer security in government: Is=
the public at risk?=E2=80=9D Even the Five Eyes admitted that their secur=
ity advice is not new=2C only more urgent.</p>
<p>What=E2=80=99s new is how fast things are changing: =E2=80=9CThe rapid=
pace of frontier AI development means cyber risk assumptions can become o= utdated in months=2C not years. We must act before and be prepared to adap=
t and withstand evolving threats.=E2=80=9D The Five Eyes point to AI techn= ology -- not necessarily chatbots=2C but AI more generally -- being used t=
o strengthen every aspect of defense=2C to =E2=80=9Cdetect vulnerabilities=
earlier=2C improve software quality=2C monitor unusual behavior=2C and re= spond faster to incidents -- reducing both the cost and impact of incident= s.=E2=80=9D</p>
<p>Excellent advice from the Five Eyes security agencies. We need to do th=
is with every risk that AI heightens=2C not just cybersecurity.</p>
<p><em>This essay was originally published in <a href=3D"
https://www.thegu= ardian.com/commentisfree/2026/jun/29/cyber-attacks-ai">The Guardian</a>.</= em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg21"><a name=3D"cg21"= >The Language of AI Could Change How Humans Speak</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/the-language-= of-ai-could-change-how-humans-speak.html"><strong>[2026.07.09]</strong></=
Because of the way they are trained=2C large language models capture on=
ly a slice of human language. They=E2=80=99re trained on the written word=
=2C from textbooks to social media posts=2C and our speech as captured in=
movies and on television. These models have minimal access to the unscrip=
ted conversations we have face to face or voice to voice. This is the vast=
majority of speech=2C and a vital component of human culture.</p>
<p>There=E2=80=99s a risk to this. The increased use of large language mod=
els means we humans will encounter much more AI-generated text. We humans=
=2C in turn=2C will begin to adopt the linguistic patterns and behaviors o=
f these models. This will affect not just how we communicate with one anot= her=2C but also how we <em>think</em> about ourselves and what goes on aro=
und us. Our sense of the world may become distorted in ways we have barely=
begun to comprehend.</p>
<p>This will happen in many ways. One of the first effects we could see is=
in simple expression=2C much as texting and social media have resulted in=
us using shorter sentences=2C emojis instead of words=2C and much less pu= nctuation. But with AI=2C the impacts may be more harmful=2C eroding court= eousness and encouraging us to talk like bosses barking orders. A 2022 stu=
dy found that children in households that used voice commands with tools l=
ike Siri and Alexa became curt when speaking with humans=2C often calling=
out =E2=80=9CHey=2C do X=E2=80=9D and expecting obedience=2C especially f=
rom anyone whose voice resembled the default-female electronic voices. As=
we start to prompt chatbots and AI agents with more instructions=2C we ma=
y fall into the same habits.</p>
<p>Next=2C in the same way autocomplete has increased how much we use the=
1=2C000 most common words in our vocabulary=2C talking with chatbots and=
reading AI-generated text may further constrict our speech. A recent Univ= ersity of Coru=C3=B1a <a href=3D"
https://pubmed.ncbi.nlm.nih.gov/39328400/= ">study</a> found that machine-generated language has a narrower range of=
sentence length=2C averaging 12-20 words=2C and a narrower vocabulary tha=
n human speech. Machine-generated text reads as smooth and polished=2C but=
it loses the meanders=2C interruptions and leaps of logic that communicat=
e emotion.</p>
<p>Additionally=2C because large language models are primarily trained fro=
m written speech=2C they may not learn how to emulate the free-wheeling na= ture of live=2C natural speech. When told =E2=80=9CI hate Beth!=E2=80=9D=
=2C ChatGPT replies with an uninterruptable three-part formula of affirmat=
ion (=E2=80=9CThat=E2=80=99s completely valid=E2=80=9D)=2C invitation (=E2= =80=9CI=E2=80=99m here to listen=E2=80=9D) and invitation (=E2=80=9CWhat= =E2=80=99s going on?=E2=80=9D) far longer than any reply plausible in face= -to-face dialog. =E2=80=9CWhat=E2=80=99s Beth=E2=80=99s deal?!=E2=80=9D el= icits a bullet point list of queries that reads like a multiple-choice exa=
m question (=E2=80=9CIs Beth * a celebrity? * a friend from school? * a fi= ctitious character?=E2=80=9D). No human speaks that way=2C at least not ye=
t. But meeting such formulas repeatedly in a speech-like context may teach=
us to accept and use them=2C much as a child absorbs new speech patterns=
from spending time with a new person.</p>
<p>These influences will only increase with time. The writing large langua=
ge models train on is increasingly produced by large language models thems= elves=2C creating a feedback loop in which they imitate their own inhuman=
patterns=2C even while teaching humans to imitate them too.</p>
<p>Broad use of large language models could also introduce <a href=3D"http= s://aclanthology.org/2025.findings-acl.195.pdf">confirmation bias</a>=2C m= aking us overconfident in our initial impulses and less open to other poss= ible ideas -- which is so vital to human discourse. Many chatbots are inst= ructed to agree with our statements no matter how absurd=2C enthusiastical=
ly supporting half-formed or even incorrect notions and restating them as=
firm claims that we=E2=80=99re primed to agree with. When asked =E2=80=9C= Cake is a healthy breakfast=2C right?=E2=80=9D or =E2=80=9CIs the post off=
ice plotting against me?=E2=80=9D=2C this sycophancy <a href=3D"
https://ww= w.article19.org/resources/algorithmic-people-pleasers-are-ai-chatbots-tell= ing-you-what-you-want-to-hear/">can reinforce bias</a> and even worsen <a=
href=3D"
https://www.psychologytoday.com/us/blog/urban-survival/202507/the= -emerging-problem-of-ai-psychosis">psychosis</a>. And the hyperconfident t=
one of AI-produced writing will also heighten impostor syndrome=2C making=
our natural=2C healthy doubt feel like an aberration or failing.</p>
<p>In our experience as teachers=2C students who turn to generative AI for=
assignments often say they do so because they have trouble expressing wha=
t they think. The students don=E2=80=99t recognize that writing or speakin=
g our thoughts is often how we realize what we think. Their unconfident an=
d uncertain statements are actually the healthy human norm. But a large la= nguage model won=E2=80=99t turn vague first guesses into a well-formed cri= tical analysis=2C or even ask helpful questions as a friend would; it will=
simply regurgitate those guesses=2C still unexamined=2C but in confident=
language.</p>
<p>We are also more vicious in social media posts and online chats than we=
are face to face. The <a href=3D"
https://www.sciencedirect.com/science/ar= ticle/pii/S0306457325000214">well-documented</a> <a>online disinhibition e= ffect</a> encourages toxic language. Most of us have had the experience of=
venting ferocious rage about someone online=2C only to reconcile when we=
speak face to face or hear the warmth of a voice over the phone. While ch= atbots are trained to give sycophantic responses=2C they see humankind at=
our cruelest=2C learning about us from the only world where every flame w=
ar leaves an eternal written footprint=2C while the spoken conversations o=
f forgiveness and reconciliation fade away. Their responses do not imitate=
our online aggression=2C but are still shaped by it=2C even in their rigi=
d efforts to avoid it.</p>
<p>It=E2=80=99s easy to draw the wrong conclusions from a selective slice=
of a society=E2=80=99s communications. Medieval Norse sagas made us imagi=
ne a culture of mostly Viking warriors=2C since poets rarely described the=
farming majority. Chivalric romances focused on kings and courts=2C and l=
ong made us see the middle ages as a world of monarchies=2C erasing the ma=
ny medieval republics. Statistically=2C we=E2=80=99ve been led to believe=
ancient Romans cared deeply about their republic=2C but 10% of all surviv=
ing Latin was written by one man=2C Cicero=2C whose work contains 70% of a=
ll surviving Roman uses of the word <em>republic</em>. Training language m= odels on only certain human writings may introduce similar distortions. AI=
might make us seem more quarrelsome=2C as we are online. It might inflate=
the cultural significance of political topics primarily discussed on Twit= ter/X or Bluesky=2C or the massive topic-specific corpuses of LinkedIn and=
Goodreads.</p>
<p>Some large language models are being trained on human speech from movie=
s and television shows=2C but that speech is still scripted=2C and disprop= ortionately highlights certain contexts over others (for example=2C police=
dramas=2C fueled by stories of murder=2C make up a <a href=3D"
https://www= =2Eresearchgate.net/figure/Percent-of-Network-prime-time-programs-featuring-= crime_fig1_267199589">quarter</a> of prime-time television programming). W=
e are not funny or hurtful or romantic the same way in real life as we are=
in sitcoms. At least one <a href=3D"
https://www.zdnet.com/article/this-ap= p-will-pay-you-30day-to-record-your-phone-calls-for-ai-but-is-it-worth-it/= ">startup</a> is offering to pay people to record their phone calls for AI= -training purposes=2C but this remains a niche idea; anything large scale=
would cause massive privacy concerns.</p>
<p>We don=E2=80=99t pretend to know what the best solutions might be. But=
one has to imagine if there=E2=80=99s ingenuity to develop AI models=2C t=
hen surely there=E2=80=99s ingenuity to come up with a way to train them o=
n informal human speech instead of us only at our most stylized=2C veiled=
and sometimes worst. By excluding the overwhelming majority of language p= roduction on the planet -- people talking=2C fully and naturally=2C to eac=
h other -- these models are being trained to mirror everything but us at o=
ur most authentically human.</p>
<p><em>This essay was written with Ada Palmer=2C and originally appeared i=
n <a href=3D"
https://www.theguardian.com/commentisfree/2026/apr/14/ai-lang= uage-human-speech">The Guardian</a>.</em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg22"><a name=3D"cg22"=
AI Surveillance and Social Progress</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/ai-surveillan= ce-and-social-progress.html"><strong>[2026.07.10]</strong></a> In the nea=
r future=2C <a href=3D"
https://www.theguardian.com/technology/artificialin= telligenceai">AI</a>-powered surveillance systems will be able to track ev= erything we do in public=2C and much of what we do in private. And if we d=
o something wrong -- shoplift=2C litter=2C jaywalk=2C you name it -- the s= ystem will notice=2C retain it=2C tie it to your official government recor= d=2C communicate that fact to you=2C and provide real-time alerts to any r= elevant authorities... and maybe also to the general public.</p>
<p>Think of these systems as automated speed cameras=2C but on steroids. O=
nly they=E2=80=99ll enforce not just speed limits=2C but any other rule yo=
u can imagine. And you won=E2=80=99t receive a ticket weeks later by mail;=
you=E2=80=99ll be informed about and fined for your violation immediately= =2E</p>
<p>These systems will combine powerful AI=2C public and private surveillan=
ce via real-time facial recognition technology and digital tracking=2C mas=
s databases and highly personalized enforcement. If deployed at scale=2C t=
hey will have profound chilling effects not just on personal freedoms=2C b=
ut democracy and social progress itself.</p>
<p>China has been developing its surveillance infrastructure <a href=3D"ht= tps://www.nytimes.com/2018/07/08/business/china-surveillance-technology.ht= ml">for years</a>. The country has over 600 million surveillance cameras=
=2C increasingly powered by AI and facial recognition to <a href=3D"https:= //www.cnn.com/2025/12/04/china/china-ai-censorship-surveillance-report-int= l-hnk">enforce</a> legal and social rules. Take the case of Lao Duan=2C a=
Chinese citizen <a href=3D"
https://www.npr.org/2018/10/31/662696776/what-= its-like-to-be-on-the-blacklist-in-chinas-new-social-credit-system">blackl= isted</a> by the system after he lost his job and was unable to repay a se= ries of loans. When he visited Beijing=2C the city=E2=80=99s AI surveillan=
ce system identified him by his face at a major intersection and displayed=
his face=2C name and citizen ID number on a large electronic billboard ne= arby with a message that he was an untrustworthy person. Similar systems a=
re now being <a href=3D"
https://www.visiontimes.com/2026/05/05/chinas-came= ras-catch-minor-offenses-but-miss-missing-persons-french-report-says.html"= >deployed</a> across China and integrated with its infamous online <a href= =3D"
https://www.cnn.com/2025/12/04/china/china-ai-censorship-surveillance-= report-intl-hnk">monitoring=2C censorship</a> and <a href=3D"
https://time.= com/collections/davos-2019/5502592/china-social-credit-score/">social cred= it</a> systems.</p>
<p>AI surveillance is <a href=3D"
https://www.lemonde.fr/en/pixels/article/= 2025/09/01/the-discreet-rise-of-facial-recognition-around-the-world_674491= 1_13.html">now</a> being experimented with in <a href=3D"
https://www.mothe= rjones.com/politics/2025/04/clearview-ai-immigration-ice-fbi-surveillance-= facial-recognition-hoan-ton-that-hal-lambert-trump/">North America</a>=2C=
<a href=3D"
https://www.alsur.lat/sites/default/files/2025-11/Facial%20rec= ognition%20and%20surveillance-1.pdf">South America</a>=2C <a href=3D"https= ://www.lemonde.fr/en/pixels/article/2025/09/01/the-discreet-rise-of-facial= -recognition-around-the-world_6744911_13.html">Europe</a>=2C <a href=3D"ht= tps://www.biometricupdate.com/202510/facial-recognition-strengthens-securi= ty-for-asias-expanding-rail-metro-sector-panel">Asia</a> and <a href=3D"ht= tps://www.theafricareport.com/420018/facial-recognition-ai-driven-surveill= ance-how-china-is-exporting-its-toolkit-to-africa/">Africa</a>. According=
to a new <a href=3D"
https://notechforice.com/wp-content/uploads/2026/06/T= ech-Behind-ICE-Oligarchs-Immigration-Enforcement-and-the-Threat-to-Democra= cy.pdf">report</a>=2C the US Department of Homeland Security is rapidly in= creasing its use of AI-based surveillance=2C including facial recognition=
and the monitoring of social media accounts=2C to keep tabs on immigrants=
=2C dissidents=2C journalists=2C legal observers and protesters. While the=
systems are ostensibly used to maintain security and public safety=2C the=
real aim is often social control. Larry Ellison=2C CEO of Oracle -- a pow= erful tech giant that works closely with the Trump administration -- has <=
a href=3D"
https://www.theregister.com/software/2024/09/16/oracle-cloud-ai-= will-enable-mass-surveillance-says-ellison/516672">said</a>: =E2=80=9CCiti= zens will be on their best behavior because we=E2=80=99re constantly recor= ding and reporting.=E2=80=9D The chilling effects are the point.</p>
<p>AI surveillance raises a range of public policy challenges: technical b= iases=2C unauditable systems=2C and inflexible automated law and social ru=
le enforcement that can promote discrimination and undermine transparency=
=2C accountability and the rule of law. But we believe the most urgent and=
long-term impact will be its broader chilling effects.</p>
<p>In a new book=2C <a href=3D"
https://www.cambridge.org/core/books/chilli= ng-effects/22383D541B3BC45C9145E85DA4824E10#fndtn-metrics">Chilling Effect=
s: Repression=2C Conformity=2C and Power in the Digital Age</a>=2C Jon Pen=
ney explains how surveillance=2C technology and power can be weaponized to=
influence behavior at scale. Surveillance=2C personalization=2C uncertain=
ty and authority are all key mechanisms to increase the scale and impact o=
f chilling effects. They cause people to self-censor their words and actio= ns=2C to become more conformist and compliant and thus easier to manage an=
d control. And the effects are additive: the more mechanisms employed=2C a=
nd the more powerful the form=2C the greater the chill.</p>
<p>Computerization has long allowed data collectors to track our locations=
=2C collect lists of whom we communicate with=2C and monitor our spending=
habits -- unless we use cash. What=E2=80=99s new is an unprecedented fusi=
on of each of these mechanisms=2C persistent and unrelenting. AI brings an=
analytical ability <a href=3D"
https://slate.com/technology/2023/12/ai-mas= s-spying-internet-surveillance.html">to</a> <a href=3D"
https://www.schneie= r.com/wp-content/uploads/2026/01/Schneier-AI-and-Spying.pdf">spy</a> on th=
e contents of our communications=2C and to answer sophisticated questions=
about our whereabouts and activities: actions that previously required hu=
man analysts are now automated. The result will be a kind of supercharged=
societal level of chilling effects where fear=2C self-censorship and grou= pthink reign=2C and dissent=2C creativity and innovation become increasing=
ly rare.</p>
<p>In this atmosphere of fear and conformity=2C risky ideas=2C social acti= vism and self-reinvention -- especially by disfavored groups and targeted=
populations -- are also <a href=3D"
https://www.lgbtqnation.com/2026/01/pu= blishers-are-stepping-back-from-lgbtq-books-amid-bans-the-current-gop-pres= ident/">chilled</a>. This will have long-term <a href=3D"
https://www.schne= ier.com/essays/archives/2018/11/surveillance_kills_f.html">effects</a> on=
social progress.</p>
<p>Consider the relatively recent societal normalization of same-sex relat= ionships and the recreational use of marijuana. Over the decades=2C those=
ideas slowly progressed from being both immoral and illegal=2C to moral b=
ut still illegal=2C and finally to both moral and legal. But in order for=
any of that to happen=2C there had to be a counterculture that was able t=
o experiment and eventually demonstrate to the world that morality could c= hange over time. To the extent that AI surveillance chills this sort of ex= perimentation in public or in private=2C social progress becomes impossibl= e.</p>
<p>There are no real historical precursors to this; these technologies are=
too new. Even the most notorious and large-scale <a href=3D"
https://www.b= bc.com/news/world-us-canada-48218827">domestic surveillance program</a> in=
US history=2C the FBI=E2=80=99s <a href=3D"
https://nsarchive.gwu.edu/brie= fing-book/intelligence/2020-06-25/spying-americans-new-release-infamous-hu= ston-plan">use of</a> wiretapping=2C physical mail opening=2C informants a=
nd paper index cards to track alleged communists during the 1950s and 1960= s=2C appears genuinely archaic in light of modern AI-enhanced surveillance=
=2E So does East Germany=E2=80=99s human-centric surveillance network during=
the cold war. Only science fiction=2C from the likes of George Orwell or=
Aldous Huxley=2C comes close. But even Big Brother=E2=80=99s =E2=80=9C<a=
href=3D"
https://bookanalysis.com/1984/telescreen/">telescreen</a>=E2=80=
=9D feels decidedly mid-20th-century by comparison.</p>
<p>But we need not sit idly. Now that we recognize the danger of AI-enhanc=
ed mass surveillance=2C we can make the policy choices not to implement it=
=2E Bans on facial recognition and other forms of identification tech can sl= ow development; robust new privacy and data protections can restrict data=
tracking and retention; AI regulations can curtail its most invasive uses=
; and structural reforms can help us scrutinize and break up powerful stat= e/tech cartels that pave the way for technological excesses like AI survei= llance.</p>
<p>The chill of AI-powered mass surveillance will suffocate the very found= ations of healthy democratic societies. But we can still choose a differen=
t path.</p>
<p><em>This essay was written with Jon Penney=2C and originally appeared i=
n <a href=3D"
https://www.theguardian.com/commentisfree/2026/jul/06/ai-surv= eillance-policy">The Guardian</a>.</em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg23"><a name=3D"cg23"=
AI Data Centers and the Concentration of Wealth</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/ai-data-cente= rs-and-the-concentration-of-wealth.html"><strong>[2026.07.13]</strong></a=
Opposition to AI data centers has emerged as a primary theme in US polit=
ics=2C one that -- surprisingly -- doesn=E2=80=99t <a href=3D"
https://gris= t.org/politics/data-center-ai-bipartisan-backlash/">fall</a> <a href=3D"ht= tps://www.nytimes.com/2026/05/01/us/politics/liberals-conservatives-data-c= enters.html">along</a> party lines. We applaud people coming together for=
constructive debate on any issue=2C and agree that communities need to ev= aluate whether any economic benefits these data centers bring is worth the=
ir costs. Still=2C we worry that a focus on data centers obscures the larg=
er impacts of AI on people=E2=80=99s lives: the concentration of power of=
AI companies=2C and their widespread political and financial influence.</=
<p>Local data center opposition is grounded in legitimate concerns about m= isallocation of land resources when housing is at a premium=2C <a href=3D"=
https://www.consumerreports.org/data-centers/ai-data-centers-impact-on-ele= ctric-bills-water-and-more-a1040338678/">pressures</a> on already higher e= nergy prices=2C and localized environmental impact. Unlike other resource-= consuming and polluting industrial facilities=2C data centers produce very=
few <a href=3D"
https://www.brookings.edu/articles/new-evidence-on-data-ce= nter-employment-effects/">jobs</a>. The fact that US opposition to data ce= nters seems to be most <a href=3D"
https://www.bloodinthemachine.com/p/work= ing-class-neighborhoods-are-resisting">fierce</a> among lower-income commu= nities reflects righteous indignation with an inequitable bargain=2C where=
tech companies and developers profit from exploiting local resources but=
offer <a href=3D"
https://www.businessinsider.com/data-centers-tax-subsidi= es-jobs-ohio-2025-5">little</a> in return. On a global scale=2C their <a h= ref=3D"
https://www.technologyreview.com/2025/05/20/1116327/ai-energy-usage= -climate-footprint-big-tech/">carbon footprint</a> could grow unsustainabl=
y if usage accelerates. And all this is in aid of a technology that many f=
ear will propagate misinformation=2C take their jobs=2C or even cause exis= tential risks for humanity.</p>
<p>For some=2C data center opposition may feel like the only tangible mech= anism for registering their concern=2C disapproval=2C or even anger about=
AI. The problem is that this may be exactly what the AI companies are ban= king on. They can overcome the protest when it matters to them=2C and live=
with a significant fraction of proposals being defeated. More importantly=
=2C focusing political opponents on the data center issue obscures the big=
ger prize they=E2=80=99re after.</p>
<p>While there is a staggering <a href=3D"
https://about.bnef.com/insights/= data-centers/ai-data-center-build-advances-at-full-speed-five-things-to-kn= ow/">three-quarters of a trillion dollars</a> being spent on data center i= nfrastructure by US companies this year alone=2C this investment should be=
taken in <a href=3D"
https://www.deloitte.com/us/en/insights/industry/tech= nology/technology-media-telecom-outlooks/hardware-consumer-tech-outlook.ht= ml">perspective</a>. The market for enterprise software=2C for example=2C=
is about twice this size. And it=E2=80=99s small compared with what these=
companies actually want.</p>
<p>AI companies have their eyes set on capturing <a href=3D"
https://www.bu= sinessinsider.com/microsoft-ceo-warns-ai-winners-hurt-whole-industries-sat= ya-nadella-2026-6">all</a> the value created by entire industries. The tec= hnology has arguably already conquered customer service and consumer sales=
=2E But on the horizon are bigger targets=2C such as enterprise software dev= elopment=2C creative design=2C management and even legal services. In AI c= ompanies and their allies=E2=80=99 vision of the future=2C AI replaces <a=
href=3D"
https://www.nbcnews.com/tech/tech-news/melania-trump-robot-humano= id-robot-white-house-video-rcna265192">teachers</a> and <a href=3D"https:/= /www.washingtonpost.com/technology/2026/06/04/inside-trump-backed-push-bri= ng-ai-doctors-into-american-medicine/">doctors</a>. The companies would ra= ther spend time fighting resistance to how fast they are building computin=
g infrastructure than dealing with issues of how their products should be=
used in those fields=2C or how those fields should be protected from thei=
r products.</p>
<p>And while data center opposition campaigns have been successful in buil= ding widespread <a href=3D"
https://news.gallup.com/poll/709772/americans-o= ppose-data-centers-area.aspx">appeal</a>=2C their effectiveness in the US=
is mixed. They seem to be most successful when organizing against <a href= =3D"
https://newsletter.semianalysis.com/p/stop-saying-half-of-2026-us-data= center">speculative</a>=2C early-stage data center proposals that have a r= elatively low likelihood to ever see fruition. Meanwhile=2C advanced-stage=
=2C well-capitalized data center projects have proven to have the resource=
s to overcome local opposition. An OpenAI- and Oracle-backed facility in S= aline township=2C Michigan=2C is <a href=3D"
https://www.detroitnews.com/st= ory/news/local/michigan/2026/06/01/openai-ceo-sam-altman-oracle-clay-magou= yrk-visit-saline-township-data-center-site/90296951007/">breaking ground</=
on construction even after local officials voted to <a href=3D"https://=
www.tomshardware.com/tech-industry/michigan-towns-rush-to-block-ai-data-ce= nters-after-16-billion-stargate-project-overrode-local-opposition">reject<=
it. The developers sued the town of 3=2C000 and forced a <a href=3D"ht=
tps://salinetownship.org/uploads/notices/SalineDataCenterConsentJudgmentFi= nalExecutionCopy492124804975v1.pdf">settlement</a> that involved their pro= ject going forward. Meanwhile=2C the Trump administration=2C a vigorous <a=
href=3D"
https://www.theguardian.com/technology/2026/jun/08/trump-ai-growt= h-anthropic">ally</a> of corporate AI=2C has signaled its willingness to a= dvance AI infrastructure development by <a href=3D"
https://www.cnn.com/202= 5/12/11/tech/ai-trump-states-executive-order">overriding</a> state objecti=
ons and even using <a href=3D"
https://www.whitehouse.gov/fact-sheets/2025/= 07/fact-sheet-president-donald-j-trump-accelerates-federal-permitting-of-d= ata-center-infrastructure/">federal lands</a>.</p>
<p>Also consider that rampant data center development may be a momentary s= pike rather than a longstanding concern. Demand for the centralized comput=
ing that data centers provide may well decline over time. The leading Chin=
ese labs=2C such as Z.ai=2C are <a href=3D"
https://venturebeat.com/technol= ogy/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-codi= ng-benchmarks-for-1-6th-the-cost">innovating</a> in technical mechanisms t=
o make frontier-class models smaller and cheaper to run. AI power users ha=
ve become <a href=3D"
https://unsloth.ai/docs/models/glm-5.2">adept</a> at=
miniaturizing open weight models=2C ones published free for anyone to dow= nload and use=2C to run locally on their own computers. <a href=3D"https:/= /arstechnica.com/information-technology/2024/04/apple-releases-eight-small= -ai-language-models-aimed-at-on-device-use/">Apple</a> and <a href=3D"http= s://developers.google.com/edge">Google</a> <a href=3D"
https://arstechnica.= com/ai/2026/05/apple-reportedly-trying-to-distill-googles-multi-trillion-p= arameter-gemini-ai-to-run-on-iphone/">both</a> support infrastructure stac=
ks for running AI models directly on mobile phones. It could be that the c= urrent mania for data centers will look like the <a href=3D"
https://intern= ethistory.org/wp-content/uploads/2020/01/OSA_Boom.Bubble.Bust_Fiber.Optic_= =2EMania_.pdf">fiber optic cable bubble</a> from the early 2000s=2C as deman=
d shifts to smaller models and AI usage on people=E2=80=99s own devices.</=
<p>For those concerned primarily with affordability and environmental prot= ection=2C singling out data center construction is misplaced. Energy rates=
and inflation today seem to be most visibly <a href=3D"
https://www.nytime= s.com/2026/06/25/business/inflation-iran-war-prices.html">affected</a> by=
the US-Iran war. The US is disinvesting in long-term energy security by <=
a href=3D"
https://www.theguardian.com/us-news/ng-interactive/2026/may/17/a= merica-china-energy-oil-renewables">ceding</a> the renewable energy indust=
ry to China and actively <a href=3D"
https://www.politico.com/news/2025/11/= 05/the-us-led-the-world-to-reach-a-huge-climate-deal-then-it-switched-side= s-pol-00636033">cancelling</a> climate commitments. Consider that 10% of g= lobal carbon emissions stem from heating buildings=2C which dwarfs <a href= =3D"
https://www.iea.org/reports/energy-and-ai/energy-demand-from-ai">energ=
y use</a> by AI and could be cut fivefold by using <a href=3D"
https://www.= iea.org/reports/the-future-of-heat-pumps/executive-summary">heat pumps</a>=
powered by renewable energy. With respect to housing affordability=2C fed= eral housing <a href=3D"
https://fred.stlouisfed.org/series/L312051A027NBEA= ">subsidies</a> have changed little over three decades=2C in inflation-adj= usted terms=2C even as housing costs have spiked and homeowners have <a hr= ef=3D"
https://nlihc.org/resource/low-income-renters-receive-far-fewer-fede= ral-supports-homeowners">enjoyed</a> robust tax incentives.</p>
<p>As for AI itself=2C the concentration of power and wealth in these tech=
companies is the greatest existential risk facing society today. This mea=
ns we must limit corporate power=2C especially corporations=E2=80=99 abili=
ty to exploit the public and manipulate our political system.</p>
<p>Opposing data centers should be just a starting point. We can advocate=
for states to <a href=3D"
https://gizmodo.com/against-the-federal-moratori= um-on-state-level-regulation-of-ai-2000698390">regulate</a> AI=2C to rejec=
t irresponsible uses of the technology=2C and shape corporate behavior. We=
can fight for AI computation to be <a href=3D"
https://www.theguardian.com= /commentisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">t= axed</a>=2C so that the public can capture some of the profit of AI use wh=
ile also forcing AI companies to internalize more of the energy and enviro= nmental consequences associated with its use. And we all can join the glob=
al <a href=3D"
https://publicai.network">movement</a> for <a href=3D"https:= //www.brookings.edu/articles/how-public-ai-can-strengthen-democracy/">Publ=
ic AI</a>=2C an alternative ecosystem for AI that is developed under publi=
c control with an incentive structure to create public benefit rather than=
private profit.</p>
<p>The US midterm elections present ample opportunity for those seeking to=
control the AI political agenda. In the recent New York congressional Dem= ocratic primary=2C PACs linked to the <a href=3D"
https://apnews.com/articl= e/bores-new-york-house-ai-tech-spending-5753274efbf9c3839fafa78f14e19fdc">= dueling</a> AI companies Anthropic and OpenAI spent millions of dollars lo= bbying for or against =E2=80=9CAI <a href=3D"
https://assembly.state.ny.us/= mem/Alex-Bores/story/114363">safety</a>=E2=80=9C=2C the idea that we must=
urgently monitor and prevent people from using AI to cause catastrophic h= arms. We=E2=80=99re already seeing a similar dynamic play out in races in=
<a href=3D"
https://massterlist.com/p/keller-on-states-rights-and-a-bizarr= e-ai-battle">Massachusetts</a> and other states.</p>
<p>Why would Anthropic and OpenAI -- bitter <a href=3D"
https://www.nytimes= =2Ecom/2026/03/07/technology/openai-anthropic-pentagon-rivalry.html">industr=
y rivals</a> but fundamentally on the same side politically -- support opp= osing viewpoints? Because they both ultimately profit from the mystique: t=
he idea that their products are so powerful that controlling those product=
s is the world=E2=80=99s most important challenge. Here=E2=80=99s the typi=
cal read on the <a href=3D"
https://fortune.com/2026/06/26/anthropic-openai= -ny12-proxy-war-no-winners-election-super-pac-donations/">dynamic</a>. To=
one side (backed by OpenAI affiliates)=2C =E2=80=9Csafety=E2=80=9D comes=
from the appearance of US industry dominating AI innovation=2C under the=
slow-moving control of federal lawmakers (and without pesky state regulat=
ors in the way). To the other side (backed by Anthropic)=2C =E2=80=9Csafet= y=E2=80=9D means a heavier regulatory framework that plays to Anthropic=E2= =80=99s posturing as the ethics- and compliance-focused AI vendor. In both=
cases=2C it=E2=80=99s more <a href=3D"
https://www.theguardian.com/comment= isfree/2026/may/08/how-dangerous-is-anthropics-mythos-ai">marketing</a> th=
an principled concern about safety.</p>
<p>Political organizers should call out and reject the AI companies=E2=80=
=99 framing of the debate=2C and reorient campaign agendas around populist=
resistance to corporate concentration of wealth and power. When AI compan=
ies pump millions into legislative races=2C the result should not be hyper= bolic discussion of AI superintelligence. And when a plot of land in a sma=
ll town is pitched as a data center site=2C the debate should be about mor=
e than the local costs and benefits. It should include out-of-control mone=
y in politics=2C and <a href=3D"
https://www.brennancenter.org/our-work/res= earch-reports/citizens-united-explained">Citizens United</a>-proof solutio=
ns to limit corporate influence like <a href=3D"
https://www.thenation.com/= article/politics/super-pac-contributions-lawsuit-maine/">public financing<=
and <a href=3D"https://www.americanprogress.org/article/the-corporate-=
power-reset-that-makes-citizens-united-irrelevant/">state regulation</a>.<=
<p>We all have a vested interest in what=E2=80=99s on the policy agenda=2C=
and what the outcomes are. Today=2C the greatest risk AI poses to society=
is the exacerbation of inequality and the concentration of wealth. The re=
al problem is trillion-dollar AI companies and their trillionaire oligarch=
s cozying up to political power in Washington and governments worldwide=2C=
and using their money to enact their agenda over the popular will of the=
people. This is the issue we=E2=80=99d like to see put front and center=
=2C and it requires solutions much more extensive than slowing data center=
development.</p>
<p><em>This essay was written with Nathan E. Sanders=2C and originally app= eared in <a href=3D"
https://www.theguardian.com/commentisfree/2026/jul/09/= ai-datacenter-company-politics">The Guardian</a>.</em></p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg24"><a name=3D"cg24"= >Vulnerability in FIFA=E2=80=99s Network</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/vulnerability= -in-fifas-network.html"><strong>[2026.07.14]</strong></a> FIFA=E2=80=99s=
network was <a href=3D"
https://bobdahacker.com/blog/fifa-hack">vulnerable=
</a> to anyone with even minimal access.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg25"><a name=3D"cg25"= >Upcoming Speaking Engagements</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/upcoming-spea= king-engagements-58.html"><strong>[2026.07.14]</strong></a> This is a cur=
rent list of where and when I am scheduled to speak:</p>
<li>I=E2=80=99m speaking (virtually) at the <a href=3D"
https://pr2.tec= hnologypolicyworkshop.org/">Policy-Relevant Privacy Research Workshop</a>=
in Calgary=2C Canada=2C on Monday=2C July 20=2C 2026.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://events.cyberriskcollabo= rative.com/boston-leadership-exchange-2026">Boston Leadership Exchange</a>=
in Boston=2C Massachusetts=2C USA=2C on Wednesday=2C July 22=2C 2026.</li=
<li>I=E2=80=99m speaking at <a href=3D"
https://www.cognitivesecurityin= stitute.org/cognitive-security-conference">Cognitive Security Conference</=
in Las Vegas=2C Nevada=2C USA. The conference runs August 6-7=2C 2026;=
my speaking time is TBD.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://defcon.org/html/defcon-= 34/dc-34-index.html">DEF CON 34</a> in Las Vegas=2C Nevada=2C USA. The con= ventions runs August 6-9=2C 2026; my speaking time is TBD.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://www.lacon.org/">LAcon V=
</a> in Anaheim=2C California=2C USA. The convention runs August 27-31=2C=
2026=2C and my speaking time is TBD.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://www.secwest.net/">CanSe= cWest 2026</a> in Vancouver=2C Canada. The conference runs September 30-Oc= tober 1=2C 2026; the time of my talk is TBD.</li>
</ul>
<p>The list is maintained on <a href=3D"
https://www.schneier.com/events/">= this page</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<p>Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing=
summaries=2C analyses=2C insights=2C and commentaries on security technol= ogy. To subscribe=2C or to read back issues=2C see <a href=3D"
https://www.= schneier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>
<p>You can also read these articles on my blog=2C <a href=3D"
https://www.s= chneier.com">Schneier on Security</a>.</p>
<p>Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to co= lleagues and friends who will find it valuable. Permission is also granted=
to reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.</p>
<p><span style=3D"font-style: italic">Bruce Schneier is an internationally=
renowned security technologist=2C called a security guru by the <cite sty= le=3D"font-style:normal">Economist</cite>. He is the author of over one do=
zen books -- including his latest=2C <a href=3D"
https://www.schneier.com/b= ooks/rewiring-democracy/"><cite style=3D"font-style:normal">Rewiring Democ= racy</cite></a> -- as well as hundreds of articles=2C essays=2C and academ=
ic papers. His newsletter and blog are read by over 250=2C000 people. Schn= eier is a fellow at the Berkman Klein Center for Internet & Society at Har= vard University; a Lecturer in Public Policy at the Harvard Kennedy School=
; a board member of the Electronic Frontier Foundation=2C AccessNow=2C and=
the Tor Project; and an Advisory Board Member of the Electronic Privacy I= nformation Center and VerifiedVoting.org. He is the Chief of Security Arch= itecture at Inrupt=2C Inc.</span></p>
<p>Copyright © 2026 by Bruce Schneier.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<p>Mailing list hosting graciously provided by <a href=3D"
https://mailchim= p.com/">MailChimp</a>. Sent without web bugs or link tracking.</p>
<p>This email was sent to:
cryptogram@toolazy.synchro.net
<br><em>You are receiving this email because you subscribed to the Crypto-= Gram newsletter.</em></p>
<p><a style=3D"display:inline-block" href=3D"
https://schneier.us18.list-ma= nage.com/unsubscribe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e= =3D70f249ec14&c=3D9bc7232132">unsubscribe from this list</a> &nbs= p; <a style=3D"display:inline-block" href=3D"
https://schneier.us18.li= st-manage.com/profile?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D9bc7232132">update subscription preferences</a>
<br>Bruce Schneier · Harvard Kennedy School · 1 Brattle Squa=
re · Cambridge=2C MA 02138 · USA</p>
</body></html>
--_----------=_MCPart_580533442--