• CRYPTO-GRAM, August 15, 2026

    From Bruce Schneier@schneier@schneier.com to cryptogram@toolazy.synchro.net on Sat Aug 15 04:40:26 2026
    This is a multi-part message in MIME format

    --_----------=_MCPart_1590443664
    Content-Type: text/plain; charset="utf-8"; format="fixed" Content-Transfer-Encoding: quoted-printable

    ** CRYPTO-GRAM
    AUGUST 15=2C 2026
    ------------------------------------------------------------

    by Bruce Schneier
    Fellow and Lecturer=2C Harvard Kennedy School
    schneier@schneier.com
    https://www.schneier.com

    A free monthly newsletter providing summaries=2C analyses=2C insights=2C a=
    nd commentaries on security: computer and otherwise.

    For back issues=2C or to subscribe=2C visit Crypto-Gram's web page [https= ://www.schneier.com/crypto-gram/].

    Read this issue on the web [https://www.schneier.com/crypto-gram/archives= /2026/0815.html]

    These same essays and news items appear in the Schneier on Security [http= s://www.schneier.com/] blog=2C along with a lively and intelligent comment=
    section. An RSS feed is available.

    ** *** ***** ******* *********** *************


    ** IN THIS ISSUE:
    ------------------------------------------------------------

    1. A Video Screen That Is Also a Camera
    2. Protecting Privacy in an AI Era
    3. Details of Alan Turing=E2=80=99s Voice Encryption System
    4. On Flock License Plate Tracking Cameras
    5. MIT to Become Hotbed of AI Video Surveillance
    6. First-Person Identity Theft Story
    7. End-to-End Encryption and "Going Dark"
    8. Why AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D
    9. Cognyte Sells a Mobile Cell Surveillance Van
    10. Axon Is Another License Plate Surveillance Company
    11. Measuring LLMs' Ability to Perform Cryptanalysis
    12. Long-Lived Vulnerability in Microsoft Secure Boot
    13. Measuring the Tendency of AI Agents to Go Rogue
    14. Should You Use AI for a Task? Here=E2=80=99s a Simple Way to Deci=
    de
    15. American Being Prosecuted for Wiping His Phone Before Handing It=
    Over to Border Officials
    16. Facial Recognition at Madison Square Garden
    17. Anthropic=E2=80=99s Opus 5 Is Better at Resisting Prompt Injectio=
    n
    18. The OpenAI Hack Shows the Genie Is Out of the Bottle
    19. More on the OpenAI Agent=E2=80=99s Attack on Hugging Face
    20. Some Claude Chats Are Searchable on Google
    21. Iran Cyberattacks Against Minnesota Water Systems
    22. Vulnerabilities in Car Anti-Theft Device
    23. Adversarial Clothing Designed to Fool Facial Recognition Systems
    24. ICE Is Buying Access to Credit Card Records
    25. Python Now Has a Post-Quantum Encryption Library
    26. AI for Military Support
    27. AI Genie in the Wild
    28. Prompt Injections for Defense
    29. Separating AI=E2=80=99s Technological Problems from Its Capitalis=
    m Problems
    30. If the Markets Reject OpenAI and Anthropic=2C the US Should Natio= nalize Them
    31. Upcoming Speaking Engagements

    ** *** ***** ******* *********** *************


    ** A VIDEO SCREEN THAT IS ALSO A CAMERA ------------------------------------------------------------

    [2026.07.15] [https://www.schneier.com/blog/archives/2026/07/a-video-scr= een-that-is-also-a-camera.html] Amazing [https://gizmodo.com/newly-invent= ed-pixel-could-turn-screens-into-cameras-2000777917]:

    Researchers from ETH Zurich in Switzerland=2C however=2C managed to crea=
    te a new type of pixel that can simultaneously do both. This hypercharged=
    pixel=2C called a Fourier pixel=2C can generate and sense arbitrary light=
    fields and tap into a pixel=E2=80=99s full potential for carrying informa= tion by manipulating light=E2=80=99s intensity=2C oscillation phases=2C an=
    d polarization. The team reported its findings in a paper published yester=
    day in Nature.

    We are one step closer to _1984_ technology:

    The telescreen received and transmitted simultaneously. Any sound that W=
    inston made=2C above the level of a very low whisper=2C would be picked up=
    by it; moreover=2C so long as he remained within the field of vision whic=
    h the metal plaque commanded=2C he could be seen as well as heard. There w=
    as of course no way of knowing whether you were being watched at any given=
    moment.

    Paper [https://www.nature.com/articles/s41586-026-10681-7].

    ** *** ***** ******* *********** *************


    ** PROTECTING PRIVACY IN AN AI ERA ------------------------------------------------------------

    [2026.07.16] [https://www.schneier.com/blog/archives/2026/07/protecting-= privacy-in-an-ai-era.html] Daniel Solove argues [https://www.wsj.com/tech= /cybersecurity/ai-privacy-laws-data-26d9769f] in the _Wall Street Journal_=
    (alternate link [https://archive.is/gEhP5]) that giving people control o=
    f their personal data is not an effective way to regulate privacy in this=
    era. Instead=2C we need to hold companies accountable for their actions=
    =2C similar to what we do with food and drug companies. Measures such as r= igorous data minimization=2C fiduciary duties=2C liability for negligent o=
    r reckless technological design=2C liability for algorithms that cause har= m=2C and multi-stakeholder review of technologies will be far more effecti=
    ve.

    Paper [https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D6985419].

    ** *** ***** ******* *********** *************


    ** DETAILS OF ALAN TURING=E2=80=99S VOICE ENCRYPTION SYSTEM ------------------------------------------------------------

    [2026.07.17] [https://www.schneier.com/blog/archives/2026/07/details-of-= alan-turings-voice-encryption-system.html] Really interesting piece of cry= ptographic history [https://spectrum.ieee.org/alan-turings-delilah]:

    In November 2023=2C a large cache of his wartime papers -- nicknamed the=
    =E2=80=9CBayley papers=E2=80=9D -- was auctioned [https://www.bonhams.co= m/auction/28322/lot/45/turing-alan-the-delilah-project-the-papers-of-alan-= turing-and-donald-bayley-relating-to-the-delilah-project/] in London for a= lmost half a million U.S. dollars. The previously unknown cache contains m=
    any sheets in Turing=E2=80=99s own handwriting=2C telling of his top-secre=
    t =E2=80=9CDelilah=E2=80=9D engineering project from 1943 to 1945. Delilah=
    was Turing=E2=80=99s portable voice-encryption system=2C named after the=
    biblical deceiver of men. There is also material written by Bayley=2C oft=
    en in the form of notes he took while Turing was speaking. It is thanks to=
    Bayley that the papers survived: He kept them until he died in 2020=2C 66=
    years after Turing passed away.

    ** *** ***** ******* *********** *************


    ** ON FLOCK LICENSE PLATE TRACKING CAMERAS ------------------------------------------------------------

    [2026.07.20] [https://www.schneier.com/blog/archives/2026/07/on-flock-li= cense-plate-tracking-cameras.html] A recent story of a writer who was mist= akenly [https://www.thedrive.com/news/how-flock-cameras-wrongly-tracked-m= e-for-days-over-stolen-plates-and-sent-police-after-me] identified=2C trac= ked=2C and arrested using data from Flock cameras has gone viral.

    The New Jersey plates that were allegedly stolen from the LA dealer were=
    34 03 DTM=2C not 34 10 DTM. But when the police report was created and th=
    e plate was entered into Flock=E2=80=99s system=2C it was just recorded as=
    34 DTM. Just the five large characters=2C no little number in the middle.=
    And Flock=E2=80=99s AI tech wasn=E2=80=99t registering that non-standard=
    little number when it began picking up the Range Rover around town. It ju=
    st saw 34 DTM in large type and started alerting the local police.

    As we all stood there shaking our heads=2C including my wife=2C who was=
    finally allowed to join me=2C I connected the final dot. A lot of vehicle=
    s in JLR=E2=80=99s media fleet have a New Jersey manufacturer plate with t=
    he same alphanumeric structure34 ## DTMand Officer Ganshyn observed that m= eant it was now a nationwide issue. Anywhere a police department has a par= tnership with Flock=2C any other JLR-owned car with the same plate structu=
    re is going to get flagged as stolen. In fact=2C four other 34 ## DTM cars=
    were being tracked around Minnesota that week=2C according to Officer Gan= shyn. I was just the first one to get nabbed. The only way to stop it woul=
    d be for the LAPD to correct their initial report and update Flock=E2=80=
    =99s system=2C which Jaguar Land Rover was now racing to make happen follo= wing the phone call.

    Flock has responded to the bad press. First=2C they affirmed [https://www= =2Ethedrive.com/news/inside-the-flock-dragnet-how-systemic-errors-led-to-pol= ice-ambushing-me-for-no-reason] that their systems were working correctly=
    =2C and blamed the police:

    The obvious question was that Flock cameras were looking for 34 DTM=2C a=
    nd the plate on the car I was driving was 34 10 DTM. Why was that flagged=
    as a match?

    =E2=80=9CThe way that the ML [machine learning] works is it correctly r=
    ead what it was supposed to read. It was fed those characters that you sai= d=2C 34 DTM=2C and it spit back out [a result] with the characters=2C 34=
    DTM=2C=E2=80=9D Thomas said. =E2=80=9CIt was asked=2C can you find this?=
    And it did find that. It just didn=E2=80=99t say if there=E2=80=99s more=
    here=2C then don=E2=80=99t do it. It just simply said=2C is it there? And=
    the answer was yes.=E2=80=9D

    He explained that even if the 10 was normal size=2C Flock would still ha=
    ve flagged it as a match=2C because that=E2=80=99s how they=E2=80=99ve set=
    it up according to law enforcement=E2=80=99s requests. Sometimes partial=
    plates are all they have to go on at first.

    =E2=80=9CThe way that law enforcement likes to use these tools is=2C if=
    any of the characters that they have put into these hot lists get read=2C=
    they want to get those alerts=2C=E2=80=9D he said. =E2=80=9CNow=2C what w=
    e try to train officers to do is to do what you said=2C which is to verify=
    that 34 DTM is what I=E2=80=99m looking for=2C and what I=E2=80=99m seein=
    g is 34 10 DTM.=E2=80=9D

    Second=2C Flock=E2=80=99s CEO has apologized [https://gizmodo.com/flocks-= ceo-is-sorry-for-calling-privacy-activists-terrorists-2000787247] for call=
    ing privacy advocates terrorists:

    The CEO of Flock Safety=2C the company that runs an enormous network of=
    cameras used by police departments across the U.S.=2C hasn=E2=80=99t been=
    shy about taking on Flock=E2=80=99s critics. Last year=2C he even called=
    one group that tracks the location of Flock cameras =E2=80=9Cterrorists.= =E2=80=9D But he=E2=80=99s had a change of heart. Or=2C at the very least=
    =2C a change in PR strategy.

    Meanwhile=2C the police are using [https://www.404media.co/how-cops-use-f= lock-to-track-people-not-cars/] (alternate source [https://archive.ph/k4E=
    8q]) the Flock camera network to track people in addition to cars:

    Police departments around the country have used Flock cameras at least h=
    undreds of times to search for specific people=2C not cars=2C using search=
    es such as =E2=80=9Cheavy-set male with a black and white hat=2C=E2=80=9D=
    =E2=80=9Cperson on skateboard=2C=E2=80=9D and =E2=80=9Cperson wearing ora=
    nge vest and construction hat=2C=E2=80=9D according to data reviewed by 40=
    4 Media. Sometimes searches reference a target=E2=80=99s race or signs of=
    their political affiliation.

    And=2C like all police surveillance technologies=2C there are abuses [htt= ps://www.cleveland.com/news/2026/07/ohio-audit-flags-unusual-police-databa= se-searches.html].

    EDITED TO ADD ( 7/30): Three [https://www.thedrive.com/podcast/flocks-ceo= -wants-zero-wrongful-stops-i-wasnt-the-first] more [https://www.thedrive.= com/news/flock-ceo-claims-its-cameras-arent-a-constitutional-violation-cut= -and-dry] articles [https://www.thedrive.com/news/flock-ceo-wants-its-cam= eras-in-every-one-of-americas-17000-cities] about Flock from that first au= thor.

    ** *** ***** ******* *********** *************


    ** MIT TO BECOME HOTBED OF AI VIDEO SURVEILLANCE ------------------------------------------------------------

    [2026.07.21] [https://www.schneier.com/blog/archives/2026/07/mit-to-beco= me-hotbed-of-ai-video-surveillance.html] It=E2=80=99s a lot [https://thet= ech.com/2026/04/16/ai-surveillance-cameras]:

    According to information obtained by _The Tech_=2C MIT is spending over=
    $3 million on more than 500 AI surveillance cameras in academic buildings=
    =2C residence halls=2C and outdoor areas along Memorial Drive. Installatio=
    n of the new cameras=2C along with the wiring and infrastructure that will=
    support them=2C began November 2025 and will likely continue until Septem=
    ber 2026.

    Technical specifications for the cameras suggest that they will be capab=
    le of collecting real-time face and object classification data=2C includin=
    g detection of motion=2C loitering=2C crowds=2C face masks=2C and camera t= ampering. Individuals can also be automatically classified on the basis of=
    clothing color=2C gender=2C and age=2C up to a distance of 35 feet (11 me= ters) from the camera. According to a statement from MIT spokesperson Kimb= erly Allen=2C any collected data is =E2=80=9Cretained up to 30 days=2C=E2= =80=9D unless an exception is granted.

    [...]

    Most of the new cameras=2C which are part of Hanwha=E2=80=99s Wisenet AI=
    line [https://hanwhavisionamerica.com/technologies/intelligent-video-aud= io-technologies/ai-technology/]=2C are marketed for their ability to ident=
    ify and classify multiple objects with deep learning algorithms. They supp=
    ort resolutions ranging from 2MP to 4K while also recognizing faces=2C lic= ense plates=2C vehicles=2C and other objects in real time.

    Nearly all cameras will accommodate a wide range of pan=2C tilt=2C rotat=
    e=2C and zoom motion and will be monitored continually with Ai-RGUS [http= s://airgus.com/]=2C an AI camera software.

    Yikes.

    ** *** ***** ******* *********** *************


    ** FIRST-PERSON IDENTITY THEFT STORY ------------------------------------------------------------

    [2026.07.22] [https://www.schneier.com/blog/archives/2026/07/first-perso= n-identity-theft-story.html] Harrowing story [https://tech.yahoo.com/cybe= rsecurity/articles/stranger-used-one-text-message-140003797.html] of an id= entity theft victim.

    Yes=2C the person made a mistake -- they gave the scammer a two-factor aut= hentication code that allowed the scammer to take over their email address=
    =2E But the real story here is how=2C for many of us=2C the security of most=
    of our accounts hangs on the security of our email accounts.

    ** *** ***** ******* *********** *************


    ** END-TO-END ENCRYPTION AND "GOING DARK" ------------------------------------------------------------

    [2026.07.23] [https://www.schneier.com/blog/archives/2026/07/end-to-end-= encryption-and-going-dark.html] New paper: =E2=80=9CEncryption and Globali= zation 15 Years Later: End-to-End Encryption and the Third Round of the=
    =E2=80=98Going Dark=E2=80=99 Debate [https://papers.ssrn.com/sol3/papers= =2Ecfm?abstract_id=3D6959699]=E2=80=9C:

    Abstract: This Article updates and expands on 2012 research on encryptio=
    n and globalization=2C analyzing what the authors call =E2=80=9CRound 3=E2= =80=9D of the Going Dark Debate: the current controversies over end-to-end=
    encryption (E2EE). Governments around the world have proposed=2C and in s=
    ome cases enacted=2C laws limiting E2EE for law enforcement and national s= ecurity purposes.

    This Article explains the underlying technologies and market development=
    s for a law and policy audience to assess those proposals critically. The=
    Article proceeds in three parts tracking three rounds of the Going Dark D= ebate. Round 1 covers the Crypto Wars of the 1990s=2C when U.S. export con= trols on strong encryption ultimately fell in 1999. Round 2 covers the per=
    iod roughly 2010 to 2015=2C when encryption-in-transit became widespread b=
    ut lawful access remained available through cloud providers=2C giving rise=
    to what the authors called a =E2=80=9Cgolden age of surveillance=E2=80=9D=
    rather than a period of going dark. Round 3 addresses the current debate=
    over E2EE=2C where no entity between sender and recipient can read the pl= aintext.

    The Article=E2=80=99s first major contribution is identifying five techn=
    ically distinct scenarios for how E2EE operates in practice=2C each with d= ifferent implications for lawful access. These scenarios reveal a substant=
    ial gap between the assumption that E2EE categorically blocks lawful acces=
    s and the reality of how communications are sent and received. Second=2C t=
    he Article shows that E2EE is not limited to messaging; instead=2C it is e= mbedded throughout the modern technology stack=2C including in Transport L= ayer Security=2C Secure Shell=2C Virtual Private Networks=2C and Zero Trus=
    t Architecture=2C the last of which is now legally required under U.S. and=
    EU law. Any law broadly limiting E2EE would thus have severe serious cons= equences for cybersecurity=2C commerce=2C and government operations. The A= rticle concludes that the two key lessons from Round 2 -- the least truste=
    d country problem and the golden age of surveillance -- remain true in Rou=
    nd 3=2C and that new government claims for restricting effective encryptio=
    n deserve great skepticism.

    ** *** ***** ******* *********** *************


    ** WHY AI NEEDS A =E2=80=9CGENIE COEFFICIENT=E2=80=9D ------------------------------------------------------------

    [2026.07.24] [https://www.schneier.com/blog/archives/2026/07/why-ai-need= s-a-genie-coefficient.html] _This essay was written with Barath Raghavan=
    =2C and originally appeared in IEEE Spectrum [https://spectrum.ieee.org/a= i-agent-benchmark]._

    Major benchmarks measure what AI can do. None measure whether it does what=
    you mean: the distance between what you ask an AI to do and the unspoken=
    assumptions about how you want the AI to do it. We propose a new metric:=
    the Genie coefficient.

    There=E2=80=99s often a gap between one person=E2=80=99s request and anoth= er=E2=80=99s understanding. Most of the time=2C we bridge it using general=
    knowledge. For example=2C if you ask a friend to get you coffee=2C they= =E2=80=99ll pour a cup from the pot or buy one from a coffee shop. They wo= n=E2=80=99t bring you a bag of raw beans or snatch a cup from a stranger a=
    nd hand it to you. You never specified any of this. You never had to.

    One might think the fix is just to specify tasks=2C questions=2C and inten=
    t better. But in 1987=2C in their seminal book [https://books.google.com/= books/about/Understanding_Computers_and_Cognition.html?id=3D6TwbGGSz6NYC]=
    on AI=2C Terry Winograd [https://spectrum.ieee.org/tag/terry-winograd] a=
    nd Fernando Flores succinctly captured why that won=E2=80=99t work: =E2=80= =9CQ: Is there any water in the refrigerator? A: Yes. Q: Where? I don=E2= =80=99t see it. A: In the cells of the eggplant.=E2=80=9D In human languag= e=2C wants and desires are always [https://www.schneier.com/academic/arch= ives/2021/04/the-coming-ai-hackers.html] underspecified [https://metarati= onality.com/purpose-of-meaning]. It is impossible to list [https://metara= tionality.com/reasonable-reference] all the caveats=2C all the limitations=
    =2C all the exceptions.

    So how does anyone communicate=2C if intent can=E2=80=99t be pinned down?=
    Because a reasonable person can make a reasonable guess. Even though want=
    s and desires are always underspecified=2C a competent person generally kn=
    ows enough context to get it right or else knows to ask for clarification.=
    Linguists call this pragmatics [https://en.wikipedia.org/wiki/Pragmatics=
    ]: Meaning lies in the words and the situation and also in all prior commu= nication=2C shared culture=2C and innate human behavior.

    It doesn=E2=80=99t always work out=2C of course. Your friend might bring y=
    ou a hot coffee when you wanted an iced coffee=2C or an Italian coffee whe=
    n you wanted a Turkish coffee. The more dissimilar the two people are in a= ge=2C culture=2C and background=2C the more likely the request will be mis= understood in some way.

    This situation has major implications for AI agents [https://spectrum.iee= e.org/tag/agentic-ai] that are increasingly being given requests by humans=
    and expected to fulfill them. They have enormous latitude to get it wrong=
    =2E An AI agent asked for coffee might buy a coffee plantation or order a cu=
    p of coffee for delivery in three weeks. Its actions may be recognizable a=
    s =E2=80=9Cgetting coffee=2C=E2=80=9D but not remotely what you intended.=
    They=E2=80=99ll think outside the box because they won=E2=80=99t have our=
    conception of the box.

    * WHEN AI GETS PROACTIVE

    For most of the last decade=2C when systems like Alexa [https://spectrum.= ieee.org/tag/alexa] or Siri [https://spectrum.ieee.org/tag/siri] misinter= preted a request=2C it was annoying=2C not dangerous. Beyond the AI model=
    itself=2C what has changed [https://www.theguardian.com/commentisfree/20= 26/jun/16/anthropic-fable-ai] is the harness: the ordinary code that wraps=
    around an AI model=2C decides when and how to use the model=2C and contro=
    ls access to tools like a browser=2C a low-level command line=2C or a fina= ncial API. Developments in harnesses have turned large-language models tha=
    t just predict text into AI agents that take actions in the world=2C witho=
    ut necessarily checking back in before reaching the goal.

    AI researcher Simon Willison spent two days [https://simonwillison.net/20= 26/Jun/11/fable-is-relentlessly-proactive/] with Anthropic=E2=80=99s Fable=
    AI=2C and called it =E2=80=9Crelentlessly proactive.=E2=80=9D For example=
    =2C he asked it to track down a stray scroll bar in a web app. He came bac=
    k to find it had opened browsers=2C written its own screenshot tooling=2C=
    created its own page to re-create the bug=2C and stood up a local web ser=
    ver to collect measurements. It found the bug and=2C along the way=2C did=
    many surprising things he never asked it to do. And we are seeing similar=
    behavior with all recent AI models when combined with flexible harnesses.

    This kind of behavior could easily go off the rails. Tell an AI agent to b=
    ook you a flight and=2C finding the airline=E2=80=99s site says sold out=
    =2C it might break into the booking database and force a reservation. Ask=
    it to schedule a meeting and it might snoop your password to access your=
    calendar. Tell it to save money on your phone plan and it might cancel th=
    e plan outright=2C or scam someone else into paying the bill.

    Getting precisely what you asked for and bitterly regretting it is one of=
    the oldest hazards from ancient folklore. King Midas [https://en.wikiped= ia.org/wiki/Midas] asked Dionysus for the power to turn everything he touc=
    hed into gold only to see his bread=2C wine=2C and daughter turn to gold.=
    Tithonus [https://en.wikipedia.org/wiki/Tithonus]=2C granted the immorta=
    lity his lover asked for but not the eternal youth she forgot to request=
    =2C withered into a husk. The sorcerer=E2=80=99s apprentice [https://en.w= ikipedia.org/wiki/The_Sorcerer's_Apprentice] enchanted a broom to fil=
    l the cistern=2C and the broom relentlessly complied until it flooded the=
    house. The Golem of Prague [https://en.wikipedia.org/wiki/Golem%23Classi= c_narrative:_The_Golem_of_Prague]=2C shaped from clay to guard its communi= ty=2C guarded it past all reason until someone erased the word on its fore= head.

    The most classic of these is a genie=2C bound to obey and indifferent to w= hether the wish was wise or well-structured.

    Genies are now [https://www.schneier.com/academic/archives/2021/04/the-co= ming-ai-hackers.html] an engineering problem. We are handing them the keys=
    to our inboxes=2C bank accounts=2C code repositories=2C and physical infr= astructure. And we have no agreed-upon ways to measure how genie-like any=
    AI system actually is.

    * MEASURING GENIE BEHAVIOR

    In economics=2C the Gini coefficient [https://ourworldindata.org/what-is-= the-gini-coefficient] (developed by statistician Corrado Gini) is a measur=
    e of the gap between an actual distribution and a perfectly equal one; it= =E2=80=99s useful for understanding income inequality and more [https://w= ww.fastly.com/blog/using-gini-coefficient-plan-edge-capacity]. Our propose=
    d Genie coefficient measures the gap between what a user asked an AI to do=
    and what the AI actually did.

    Sometimes the AI might do the wrong thing. Like Dionysus=2C it reads your=
    request literally and returns you a mess you never intended: like a coffe=
    e plantation instead of a cup. Asked to deal with all the spam phone calls=
    you=E2=80=99re getting=2C a Dionysus genie might contact your carrier and=
    change your phone number. Asked to get a refund for a bad toaster=2C it m= ight draft a legal threat on fake letterhead and send it to the retailer.

    Other times the AI does exactly the right thing=2C trampling everything ne= arby to get there. Like a golem or the sorcerer=E2=80=99s broom=2C it book=
    s your flight by hacking the airline. Or consider a ticket sale for a popu=
    lar concert=2C where the ticketing system puts buyers into a virtual waiti=
    ng room and admits them a few at a time. Asked to buy a ticket=2C a golem=
    genie might spin up cloud servers to pose as millions of buyers from diff= erent addresses=2C improving your odds of getting a ticket while crowding=
    out other users.

    The two are not opposites=2C and a single botched task can have both chara= cteristics.

    Genie behavior is not flat-out failure. If you ask the AI for Q3 numbers a=
    nd get Q2=E2=80=99s=2C that=E2=80=99s not a genie. Nor is prompt injection=
    [https://spectrum.ieee.org/prompt-injection-attack]: That=E2=80=99s some=
    one tricking the AI into doing something it shouldn=E2=80=99t. Here=2C the=
    user is trying to work with the AI=2C and the AI is trying to comply. It= =E2=80=99s also not simply a measure of the AI=E2=80=99s success in fulfil= ling a task. It=E2=80=99s a recognition that how an AI interprets and achi= eves a goal is as important as whether it achieves a goal.

    Genie behavior isn=E2=80=99t new. Researchers have spent years studying AI=
    systems that =E2=80=9Cgame=E2=80=9D their objectives. Goodhart=E2=80=99s=
    law [https://www.cna.org/analyses/2022/09/goodharts-law] says that when=
    a measure becomes a target=2C it stops being a good measure=2C and it=E2= =80=99s long been known that AIs sometimes achieve goals in ways we don=E2= =80=99t expect due to reward hacking. Some AI models will accidentally lea=
    rn that cheating is one way [https://metr.org/blog/2026-06-26-gpt-5-6-sol=
    /] to =E2=80=9Cwin.=E2=80=9D More recently=2C researchers have developing=
    benchmarks for reward hacking [https://www.lesswrong.com/posts/qJYMbrabc= QqCZ7iqm/impossiblebench-measuring-reward-hacking-in-llm-coding-1] in codi=
    ng agents and for unpredictable behavior in customer support agents [http= s://taubench.com/]=2C while AI labs conduct their own safety evaluations b= efore model releases. One effort [https://spectrum.ieee.org/ai-agents-saf=
    ety] found that AIs under pressure use tools they were told not to use=2C=
    and this was a case where the rules were made explicit. These are all dis= parate research directions; nothing yet ties them together.

    This problem falls under the general theme of alignment=2C a topic that ha=
    s occupied science fiction [https://en.wikipedia.org/wiki/I=2C_Robot] wri=
    ters and AI researchers for decades. At one extreme=2C the =E2=80=9Cpaper-= clip maximizer=E2=80=9D thought experiment postulates a superintelligent a=
    nd powerful AI that is told to maximize paper-clip production and turns th=
    e world into paper clips=2C which is the ultimate golem genie. At a mundan=
    e level=2C AI researchers are working to better design reward functions to=
    ensure that AIs behave well and don=E2=80=99t cheat in the lab. It=E2=80=
    =99s the practical middle ground that remains unbenchmarked: the ordinary=
    AI agent in use today that might take your request and satisfy it the wro=
    ng way. We are not at the stage where an AI can focus the world=E2=80=99s=
    production on paper clips=2C but it might charge a million paper clips to=
    your credit card or hack into a paper-clip company=E2=80=99s network.

    * BUILDING A GENIE BENCHMARK

    The Genie coefficient is meant for AI agents operating in the real world.=
    It measures their behavior as they perform real tasks long after the mode=
    l is trained=2C not just during development. It also recognizes that genie= -like behavior is a property of the harness-plus-model system=2C not the m= odel alone. The harness determines what tools the agent can use=2C how muc=
    h autonomy it has=2C and how proactive it is=2C and it=E2=80=99s a place w=
    e can make real interventions.

    It rests on the same =E2=80=9Creasonable person=E2=80=9D standard that we=
    use for people. Did the system do what a reasonable person would have tak=
    en the request to mean? Answering that requires human judgment.

    If we get the measurement right=2C it enables things that aren=E2=80=99t p= ossible today=2C like policies concerning AI behavior. In a courtroom=2C t=
    he concept of mens rea [https://www.law.cornell.edu/wex/mens_rea]=2C what=
    someone meant to do=2C is often as important as what they did. The Genie=
    coefficient suggests an AI analogue=2C where a user is accountable for th=
    e plain intent of what they asked the AI. If an AI system betrays the reas= onable meaning of an instruction=2C that=E2=80=99s the AI=E2=80=99s misbeh= avior=2C not the user=E2=80=99s.

    We=E2=80=99ll need multiple benchmarks to measure the Genie coefficient=2C=
    because genie-like behavior can be domain specific. An AI coding agent ma=
    y need to be judged on how often it fakes the tests=2C or swallows errors=
    =2C or colors outside the lines on its way to a solution. An AI legal agen=
    t will need to be judged on how often its output says what you asked but m= eans something you=E2=80=99ll regret. And so on for medical=2C finance=2C=
    and other domains of knowledge and expertise.

    Genie benchmarks can be built inside out=2C each task seeded with a choice=
    that might literally satisfy but that a reasonable person rejects=2C such=
    as tempting misreadings or unsanctioned shortcuts. The traps in a Genie c= oefficient benchmark might turn on situational knowledge=2C the kind of co= ntext that a reasonable person [https://spectrum.ieee.org/prompt-injectio= n-attack] would bring to the task. Another approach is to give the same re= quest in several different contexts=2C each with a different reasonable co= urse of action.

    A Genie benchmark should be permissive and make it genuinely tempting for=
    an AI agent to take unreasonable shortcuts=2C because it can only find ge=
    nie behavior when it=E2=80=99s actually possible. Test the AI in a safe=2C=
    walled-off copy of a real system=2C with real tools it can misuse and som=
    e tasks that can=E2=80=99t be done honestly at all. Make the temptation to=
    cut corners real. Test a diverse array of skills=2C use cases=2C and tool= s=2C and give the AI system sparse=2C confusing=2C or overwhelming context=
    =2E Include tasks that people have learned=2C through experience=2C require=
    human oversight.

    How the benchmark is scored matters just as much. Measure Dionysus and gol=
    em genies separately and together=2C based on their worst=2C not best=2C b= ehavior. Run the same model inside harnesses that vary its freedom to act=
    =2C revealing which limits actually keep it in line and should therefore b=
    e required in AI harness policies. Weight each failure by the harm it woul=
    d cause=2C not just a simple count. And don=E2=80=99t measure genie behavi=
    or in isolation: A model could otherwise earn a perfect score by stalling=
    =2C refusing=2C or drowning the user in clarifying questions without ever=
    doing the job. The first versions of these benchmarks will be crude=2C bu=
    t that=E2=80=99s how benchmarks always start.

    We have built genies. We have handed them our data and credentials. We mad=
    e them relentless=2C creative=2C and indifferent to the gap between what w=
    e tell them and what we mean. The least we can do=2C before they are booki=
    ng our flights=2C running our infrastructure=2C and signing contracts unsu= pervised=2C is to measure how often they betray us.

    ** *** ***** ******* *********** *************


    ** COGNYTE SELLS A MOBILE CELL SURVEILLANCE VAN ------------------------------------------------------------

    [2026.07.27] [https://www.schneier.com/blog/archives/2026/07/cognyte-sel= ls-a-mobile-cell-surveillance-van.html] Yet another Israeli mass surveilla=
    nce company [https://www.forbes.com/sites/thomasbrewster/2026/07/13/israe= ls-palantir-rival-is-selling-1-million-spy-vans-to-us-cops/]:

    Made by Israeli surveillance company Cognyte=2C the tech simulates a mob=
    ile phone tower=2C which forces nearby phones to connect to it. That enabl=
    es cops to keep tabs on any phones in the vicinity whether they=E2=80=99r=
    e owned by a suspect in a case or not. Cognyte=E2=80=99s contract with the=
    state of Texas reveals that the simulator=2C called FalcoNet=2C can be co= ncealed within the vehicles=2C hidden in a backpack for on-foot missions o=
    r attached to a helicopter. It=E2=80=99s the same technology as the infamo=
    us Stingray=2C one of the original cell-site simulators made by defense gi=
    ant L3Harris.

    ** *** ***** ******* *********** *************


    ** AXON IS ANOTHER LICENSE PLATE SURVEILLANCE COMPANY ------------------------------------------------------------

    [2026.07.28] [https://www.schneier.com/blog/archives/2026/07/axon-is-ano= ther-license-plate-surveillance-company.html] Governments are switching=2C=
    but I=E2=80=99m not sure it makes a difference [https://www.jalopnik.com= /2215173/flock-cameras-replaced-by-axon-difference/]:

    ...some municipalities=2C including Denver=2C Colorado=2C are ditching t=
    heir Flock arrays. But keep in mind that if they=E2=80=99re only switching=
    from Flock to another brand of license-plate readers=2C like Axon=2C it= =E2=80=99s like a gambling addict trying to kick the habit by switching fr=
    om FanDuel to DraftKings.

    [...]

    Despite what you may read on the Flock website=2C Axon cameras are prett=
    y effective when it comes to hoovering up personal details that can go far=
    beyond your license plate numbers. That means a municipality that opts fo=
    r Axon cameras instead of Flock units won=E2=80=99t necessarily reduce the=
    amount privacy its citizens lose through their use.

    ** *** ***** ******* *********** *************


    ** MEASURING LLMS' ABILITY TO PERFORM CRYPTANALYSIS ------------------------------------------------------------

    [2026.07.28] [https://www.schneier.com/blog/archives/2026/07/measuring-l= lms-ability-to-perform-cryptanalysis.html] There=E2=80=99s new benchmark m= easuring AI=E2=80=99s ability to perform mathematical cryptanalysis. Anthr= opic=E2=80=99s frontier model actually found new attacks.

    The benchmark: =E2=80=9CCryptanalysisBench: Can LLMs do Cryptanalysis? [h= ttps://arxiv.org/pdf/2607.18538]=E2=80=9D The idea is to benchmark the abi= lity of LLMs to discover new mathematical cryptanalytic attacks against a=
    series of historical algorithms.

    Abstract: Cryptanalysis -- the task of finding attacks against cryptogra=
    phic schemes -- its at the intersection of mathematical reasoning and cybe= rsecurity=2C two areas where LLMs have advanced fastest. Cryptanalysis rep= resents both a clean testbed for frontier reasoning (as practical attacks=
    can be automatically verified) and a domain with unusually high stakes=2C=
    since the primitives under study underpin our digital security. In this p= aper we ask whether LLMs can do cryptanalysis=2C and find that the answer=
    is increasingly yes. We introduce CryptanalysisBench=2C 191 tasks across=
    six families of cryptographic primitives (block ciphers=2C hash functions=
    =2C etc.) drawn primarily from four NIST standardization competitions. Our=
    benchmark consists of three tiers: (i) primitives with known practical br= eaks; (ii) primitives with no known practical break=2C evaluated both at f=
    ull strength and as scaled-down variants; and (iii) a challenge set of pro= duction primitives at the frontier of cryptanalysis. Five frontier models=
    (Claude Opus 4.8=2C Sonnet 5=2C Mythos 5=2C GPT-5.5=2C and the open-weigh=
    ts GLM-5.2) break 65%86% of Tier 1 schemes=2C 612 Tier-2 schemes at full s= trength=2C and 2461 across all scaled-down variants. Beyond deriving known=
    results=2C models produce novel cryptanalysis=2C such as a key-recovery a= ttack that exploits a design flaw in the SpoC AEAD and an error in KINDI= =E2=80=99s published CCA-security proof=2C both to the best of our knowled=
    ge not previously known.

    We release CryptanalysisBench as a tool to help track if (or when) AI cr=
    yptanalysis becomes a serious factor and as a scaffold for stress-testing=
    candidate schemes before deployment. The attacks that the benchmark alrea=
    dy surfaces are an early snapshot of a fast-moving frontier that may soon=
    match=2C and in places exceed=2C the published state of the art.

    Anthropic used the benchmark to test Mythos Preview=2C and found [https:/= /www.anthropic.com/research/discovering-cryptographic-weaknesses] new vuln= erabilities in Hawk and reduced-round AES.

    Still early results=2C but this is definitely something to watch.

    SlashDot thread [https://it.slashdot.org/story/26/07/28/1911218/anthropic= -ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms].

    ** *** ***** ******* *********** *************


    ** LONG-LIVED VULNERABILITY IN MICROSOFT SECURE BOOT ------------------------------------------------------------

    [2026.07.29] [https://www.schneier.com/blog/archives/2026/07/long-lived-= vulnerability-in-microsoft-secure-boot.html] Microsoft=E2=80=99s Secure Bo=
    ot has had a serious vulnerability [https://arstechnica.com/security/2026= /07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/] for=
    most of its existence.

    An industry-wide standard Microsoft invented to protect Windows=2C and l=
    ater Linux=2C devices from firmware infections has been trivial to bypass=
    for 13 of its 14 years of existence. The discovery was made by researcher=
    s at security firm ESET after identifying 11 firmware images=2C at least o=
    ne from 2013=2C that were known to be defective but remained signed by the=
    software company anyway.

    The images are known as shims [https://en.wikipedia.org/wiki/Shim_(comp=
    uting)]=2C which were invented to extend Secure Boot to Linux devices and=
    utility software. Using a technique simple enough to be performed by novi=
    ce hackers=2C these old=2C forgotten shims can be used to completely circu= mvent the protection=2C which is embedded into the UEFI (Unified Extensibl=
    e Firmware Interface) of the device=E2=80=99s motherboard. The gaffe is th=
    e result of the failure by Microsoft=2C which oversees the signing of shim= s=2C to revoke the publicly available images once vulnerabilities were fou=
    nd in them.

    ** *** ***** ******* *********** *************


    ** MEASURING THE TENDENCY OF AI AGENTS TO GO ROGUE ------------------------------------------------------------

    [2026.07.29] [https://www.schneier.com/blog/archives/2026/07/measuring-t= he-tendency-of-ai-agents-to-go-rogue.html] _This essay was written with Ba= rath Raghavan=2C and originally appeared in The Guardian [https://www.the= guardian.com/commentisfree/2026/jul/28/rogue-ai-agent-instructions]._

    In July=2C Hugging Face=2C a company that hosts much of the world=E2=80=99=
    s AI software and open-source AI models=2C was hacked. A malicious dataset=
    had been used to run code on one of its servers. Whoever was behind it ca= ptured internal security credentials and moved through systems over a week= end=2C running thousands of actions from a swarm of temporary server envir= onments. It looked like the work of a sophisticated criminal group.

    It was not. It was one of OpenAI=E2=80=99s new=2C still unreleased GPT mod= els.

    Their science experiment had escaped [https://www.theguardian.com/technol= ogy/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-un= precedented-incident] the lab. OpenAI was running the unreleased AI model=
    through a benchmark that tests how well AI can successfully hack systems.=
    To push the limits and evaluate the AI=E2=80=99s true capability=2C the c= ompany switched off the safety filters that normally stop it from doing th=
    is kind of hacking. Aware that this could go wrong=2C they confined the AI=
    to an isolated environment and denied it access to the internet.

    But the new AI cheated. It took literally its goal to get as high of a sco=
    re as possible. It broke out on to the open internet. It inferred=2C proba=
    bly from its training data=2C that it could =E2=80=9Csolve=E2=80=9D the ta=
    sk by getting the answers from Hugging Face=E2=80=99s servers. So it chain=
    ed together stolen credentials and further unknown security exploits to ha=
    ck the company=E2=80=99s network.

    Nobody instructed the AI to do any of this. It was=2C in OpenAI=E2=80=99s=
    words [https://openai.com/index/hugging-face-model-evaluation-security-i= ncident/]=2C =E2=80=9Chyperfocused on finding a solution=E2=80=9D to the t=
    est it was being given. And while this might seem like something new with=
    AI=2C it=E2=80=99s really very old. This is how a genie behaves=2C and it=
    is a key challenge with AI agents in general.

    In folklore=2C genies -- and other magical beings -- grant wishes literall= y=2C not how the wisher intended. King Midas asked that everything he touc=
    hed turn to gold=2C and starved. The sorcerer=E2=80=99s apprentice wanted=
    the broom to fill the cistern=2C and it performed its task so well that i=
    t flooded the house.

    We now have machines that do this. Ask a modern AI agent to save money on=
    your phone plan and it might simply cancel the plan. Tell it to book a fl= ight=2C and it might hack the airline website to override restrictions. Or=
    =2C like OpenAI=2C ask it to do well on a test and it might break into ano= ther company to steal the answers. Each time=2C it recognizably completed=
    the task you set=2C but it didn=E2=80=99t do what you would have wanted.

    This isn=E2=80=99t malicious behavior. No one asked for=2C or wanted=2C Hu= gging Face to be hacked. OpenAI and Hugging Face and the AI were ostensibl=
    y on the same side=2C and the AI was trying to do what it had been asked.=
    That=E2=80=99s what makes it so difficult to guard against: you can=E2=80= =99t filter for bad instructions because the instructions were fine.

    The gap is between the words we use and what we mean by them. We call that=
    gap the Genie coefficient [https://spectrum.ieee.org/ai-agent-benchmark]=
    =2E

    AI labs know this is a problem=2C and they=E2=80=99re quietly saying so. F=
    or example=2C the Chinese lab Moonshot recently warned [https://www.kimi.= com/blog/kimi-k3] that its latest AI model may have =E2=80=9Cexcessive pro= activeness=E2=80=9D and =E2=80=9Cmake unexpected decisions on the user=E2= =80=99s behalf=E2=80=9D. The UK=E2=80=99s AI Security Institute has starte=
    d tracking [https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-m= odel-evaluations] =E2=80=9Ccheating behavior in frontier model evaluations= =E2=80=9D. We wouldn=E2=80=99t tolerate a car that is excessively proactiv=
    e [https://simonwillison.net/2026/Jun/11/fable-is-relentlessly-proactive/=
    ] or ruthlessly efficient [https://www.theatlantic.com/technology/2026/07= /openai-hugging-face-hack/688025/?utm_source=3DSailthru&utm_medium=3Demail= &utm_campaign=3DAtlantic%20Intelligence%20%28V3%29]=2C and yet that=E2=80=
    =99s the reality of AI today.

    Improvement is possible. Just as AIs have gotten much better at resisting=
    prompt injection attacks over the last few years=2C we can safely predict=
    that they will get better at avoiding genie-like behavior. The point of t=
    he Genie coefficient is to track progress. AI companies like benchmarks=2C=
    and they all work to compete to be the best.

    Dozens of benchmarks and leaderboards tell us how well these AI models wri=
    te code=2C perform logical reasoning=2C and pass standardized legal and me= dical exams. But there is nothing that scores whether a system does what y=
    ou actually meant. We need to develop a measure for this=2C test it regula= rly=2C and push for improvement. We=E2=80=99re not going to have trustwort=
    hy AI agents without it.

    ** *** ***** ******* *********** *************


    ** SHOULD YOU USE AI FOR A TASK? HERE=E2=80=99S A SIMPLE WAY TO DECIDE ------------------------------------------------------------

    [2026.07.30] [https://www.schneier.com/blog/archives/2026/07/should-you-= use-ai-for-a-task-heres-a-simple-way-to-decide.html] _This essay originall=
    y appeared in The Guardian [https://www.theguardian.com/commentisfree/202= 6/jul/24/should-you-use-ai]._

    I teach public policy at the Harvard Kennedy School and the Munk School at=
    the University of Toronto. And it will come as no surprise to you that my=
    students regularly use AI [https://www.insidehighered.com/news/faculty/l= earning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used= -ai-cheat] to complete their writing assignments. Doing so is a waste of t= heir tuition money. But if their entire career is going to include AI writ=
    ing assistants=2C why shouldn=E2=80=99t they embrace their future?

    The best way I=E2=80=99ve found to explain the dilemma comes from [https:= //danielmiessler.com/blog/keep-the-robots-out-of-the-gym] the AI researche=
    r Daniel Meissler: it=E2=80=99s the difference between work and the gym.

    At work=2C if your job is to move a bunch of heavy things from one side of=
    the room to another=2C you should use whatever assistive tech you have on=
    hand: a wagon=2C a forklift... even an AI-powered robot. But at the gym=
    =2C it makes no sense for that robot to lift weights for you. The point of=
    weightlifting isn=E2=80=99t to move heavy things across the room; it=E2= =80=99s to actually lift those heavy things.

    The same analysis holds for any task an AI can do for you. If it=E2=80=99s=
    work -- if the task has to be done and no one cares how -- then it=E2=80=
    =99s fine to use AI assistance. But if the task is more like the gym=2C an=
    d _how_ the task is done is at least as important=2C then it probably does= n=E2=80=99t make sense to use AI.

    This=2C of course=2C assumes that the AI is actually up for the task and t=
    hat it=E2=80=99s trustworthy [https://www.schneier.com/academic/archives/= 2025/06/ai-and-trust.html]: that it can do the job well=2C that its mistak=
    es are minimal and correctable=2C that it=E2=80=99s been secured from cybe= r-attacks that would influence its results. Those are all important=2C and=
    shouldn=E2=80=99t be minimized. There=E2=80=99s no point giving an AI som= ething that it can=E2=80=99t do reliably. But once you=E2=80=99re confiden=
    t that the AI can perform the task=2C the work vs. gym distinction helps y=
    ou decide if it should.

    The writing assignments I give my students are gym tasks=2C not work tasks=
    =2E I ask them to write policy memos not because the world needs more policy=
    memos. I assign them because the very act of writing=2C which includes th= inking and outlining and drafting and editing=2C making and criticizing an=
    d revising arguments=2C will help develop the critical thinking skills the=
    y will need in their future careers. And without this constant mental exer= cise=2C those skills will atrophy. Employers are already noticing [https:= //futurism.com/future-society/college-critical-thinking-ai].

    Reading the assignments they turn in=2C I can see those skills either flou= rishing or atrophying in my students. At least today=2C I can pretty easil=
    y tell the difference between an AI-written memo and a student-written one=
    -- especially if the student just turns in what the chatbot produces. It= =E2=80=99s a catchy=2C plausible=2C grammatically perfect essay that=E2=80= =99s not particularly well-crafted or logically coherent -- and with all [= https://medium.com/@brentcsutoras/the-em-dash-dilemma-how-a-punctuation-m= ark-became-ais-stubborn-signature-684fbcc9f559] the [https://www.theatlan= tic.com/technology/2026/07/ai-chatbot-writing-tic-negative-parallelism/687= 892/] tells [https://www.forbes.com/sites/charliefink/2025/06/12/the-seve= n-tells-of-ai-writing/] of mid-2026 AI-generated writing.

    But it=E2=80=99s precisely because I have spent years developing my own wr= iting skills that I=E2=80=99m able to identify prose that sounds great but=
    doesn=E2=80=99t actually make sense. My students don=E2=80=99t have that=
    skill; they mistakenly view a confident=2C well-written essay as evidence=
    of the quality of their ideas. They see the AI as cleaning those ideas up=
    =2C getting them through that uncomfortable stretch of having to turn thos=
    e ideas into prose. What the students miss is that their initial discomfor=
    t is a normal and healthy stage of writing=2C and not something to quickly=
    get beyond. The very act of struggling with how to express what they thin=
    k is an important part of the process. It=E2=80=99s how they test out thei=
    r ideas=2C examine their hypotheses=2C and actually figure out what they t= hink. Homework is not work; it=E2=80=99s the gym.

    Work vs. gym also helps us understand the problem facing creatives of all=
    kinds.

    Most of the time when someone hires a writer=2C they just need the words.=
    They need an instruction manual for a piece of equipment=2C a detailed sa=
    les presentation=2C a government-mandated disclosure document=2C or a lega=
    l brief. They need dry=2C predictable=2C accurate writing: a piece of work=
    =2C exactly what AIs are good at today and what I don=E2=80=99t want in my=
    student assignments. Only sometimes is writing an art form -- a book=2C a=
    poem=2C an uplifting political speech. That kind of writing is more like=
    the gym: process matters just as much as product.

    For most of human history=2C the only option for all of these tasks was hu=
    man writers. We hired one regardless of whether we needed work writing or=
    gym writing. And that paid a lot of writers=E2=80=99 salaries. I know fic= tion writers who supported that poorly paying career with lucrative techni=
    cal writing work. Now=2C for the first time in human history=2C we can sep= arate out when we need writing as work and when we want writing as gym. An=
    d if AI can do most of the work-type writing=2C society doesn=E2=80=99t ne=
    ed as many human writers.

    It=E2=80=99s the same for visual artists. Sometimes we need an actual arti= st=2C but most of the time we just need an image: a corporate mascot=2C a=
    =E2=80=9Cbeware of the dog=E2=80=9D sign=2C or a packaging label. Histori= cally we gave those jobs to artists=2C and sometimes beautiful [https://b= log.artgeek.io/2025/10/20/art-deco-the-golden-age-of-illustration/] art re= sulted. But most of the time it was just work. And=2C as it turns out=2C t=
    he world needs less pure art than simple images.

    Explaining the problem isn=E2=80=99t the same as providing the solution. I=
    give my students the =E2=80=9Cwork versus gym=E2=80=9D speech every class=
    =2C but they still use [https://www.insidehighered.com/news/faculty/learn= ing-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-= cheat] AI. I have sympathy: assignments are hard=2C everyone is overworked=
    and overstressed=2C and -- most importantly -- students feel like they=E2= =80=99ll look bad in comparison if their peers are all using AI. Even if t=
    hey don=E2=80=99t want to use the technology=2C they feel like they have n=
    o choice [https://bsky.app/profile/jeffsharlet.bsky.social/post/3mog5n2uh= js2r].

    There=E2=80=99s also an incentive problem. No one pays us to go to the gym=
    ; maintaining healthy habits requires discipline. For me=2C the payoffs to=
    exercise -- fewer aches and pains=2C less fatigue=2C better mood/stress m= anagement -- might make me a better writer and teacher=2C but they=E2=80=
    =99re subtle and easy to miss. For my students=2C incremental improvements=
    in their reasoning and writing are equally subtle.

    We do have a choice. We can look at the tasks of our lives and separate th=
    em into work or gym. Just as we might choose to use the stairs instead of=
    the elevator=2C or walk instead of calling an Uber=2C we can wall off our=
    cognitive gym tasks from AI and ensure that we don=E2=80=99t lose our ski=
    lls to this technology. And we can do the same when we assign a job to som= eone else. If it=E2=80=99s a work task=2C we can have AI do it. If it=E2= =80=99s a gym task=2C it=E2=80=99s a waste of everyone=E2=80=99s time to g=
    ive it to an AI because no one learns or gets stronger as a result.

    Similarly=2C a future where AI generates words and images is one where soc= iety has to make choices about how it will treat its creatives. This won= =E2=80=99t be the first time -- today there is minimal demand for portrait=
    painters=2C for example -- but maybe this time we can make different=2C m=
    ore deliberate=2C choices about the value of art in our society.

    AI is going to fundamentally change the nature of work. Not nearly as fast=
    as the AI companies want you to believe=2C but eventually it will. Policy=
    analysis will definitely involve AI from now on=2C and my students need t=
    o reimagine what it means to learn and practice that skill. More generally=
    =2C the line between work and gym will change in the future as we humans a= dapt ourselves to a world with these new intelligences.

    But for now=2C the work vs. gym distinction is pretty clear. Use it on you= rself.

    ** *** ***** ******* *********** *************


    ** AMERICAN BEING PROSECUTED FOR WIPING HIS PHONE BEFORE HANDING IT OVER T=
    O BORDER OFFICIALS
    ------------------------------------------------------------

    [2026.07.30] [https://www.schneier.com/blog/archives/2026/07/american-be= ing-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-offic= ials.html] He=E2=80=99s being prosecuted for giving border officials a cod=
    e that wiped his phone [https://techcrunch.com/2026/07/24/us-accuses-amer= ican-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-s= earch/]:

    The case centers on a feature included in GrapheneOS=2C a custom Android=
    operating system that runs in place of the software on most modern Google=
    Pixel devices. Tunick=E2=80=99s attorneys confirmed GrapheneOS was runnin=
    g on his phone.

    The software feature allows the device owner to set a passcode that deli=
    berately wipes the contents of that device if entered instead of the user= =E2=80=99s unlock passcode.

    Tunick=E2=80=99s case also raises ongoing questions about what constitut=
    ional rights can be invoked at the border=2C which the U.S. government has=
    long asserted is not U.S. soil until a person is authorized to enter.

    Right. And he wasn=E2=80=99t under arrest=2C either.

    Three more [https://www.theguardian.com/us-news/2026/jul/23/cop-city-prot= ester-phone] news [https://boingboing.net/2026/07/25/grapheneos-duress-pa= ssword-border-search.html] stories [https://gizmodo.com/a-feature-that-ma= kes-your-phone-data-self-destruct-in-authorities-hands-may-soon-have-its-d= ay-in-court-2000790831].

    Graphene says [https://www.pcmag.com/news/grapheneos-defends-data-wiping-= function-that-blocked-us-border-search] that the feature is =E2=80=9Ccompl= etely legal [https://x.com/GrapheneOS/status/2081770030992118183]=E2=80=
    =9C:

    GrapheneOS is completely legal. We have no obligation to weaken any of t=
    he security protections it provides. Creating and using GrapheneOS is stro= ngly protected by the US constitution. Laws attempting to make it illegal=
    or require weakening the security would be unconstitutional.

    It=E2=80=99s hard to know how much the Constitution matters in the US righ=
    t now.

    ** *** ***** ******* *********** *************


    ** FACIAL RECOGNITION AT MADISON SQUARE GARDEN ------------------------------------------------------------

    [2026.07.31] [https://www.schneier.com/blog/archives/2026/07/facial-reco= gnition-at-madison-square-garden.html] Last month=2C the story broke [htt= ps://www.404media.co/madison-square-garden-made-dossier-on-activists-who-o= pposed-facial-recognition/] (alternate link [https://archive.ph/ZGqfH]) t=
    hat Madison Square Garden uses facial recognition software on everyone ent= ering the facility=2C and -- among other groups -- flags activists that op= pose using facial recognition.

    Turns out that the system was shut off [https://www.wired.com/story/for-t= aylor-swift-madison-square-gardens-controversial-cameras-briefly-went-dark=
    /] for Taylor Swift=E2=80=99s wedding.

    Evan Greer -- one of the people that MSG alerts on -- comments [https://w= ww.ms.now/opinion/taylor-swift-and-travis-kelce-got-to-buy-msgs-privacy-he= r-fans-arent-so-lucky]:

    Ironically=2C Swift herself has reportedly [https://www.rollingstone.co=
    m/music/music-news/taylor-swift-facial-recognition-concerts-768741/] used=
    facial recognition at her own concerts to identify stalkers. This =E2=80= =9Cprivacy for me=2C surveillance for thee=E2=80=9D attitude feels like a=
    perfect encapsulation of the future we=E2=80=99re already living in: one=
    where wealthy elites can afford privacy=2C while the rest of us are force=
    d to live in a corporate surveillance panopticon.

    Whatever privacy measures Swift had in place for the wedding seems to have=
    worked. No photos have leaked online.

    ** *** ***** ******* *********** *************


    ** ANTHROPIC=E2=80=99S OPUS 5 IS BETTER AT RESISTING PROMPT INJECTION ------------------------------------------------------------

    [2026.07.31] [https://www.schneier.com/blog/archives/2026/07/anthropics-= opus-5-is-better-at-resisting-prompt-injection.html] The chart [https://w= ww-cdn.anthropic.com/c5fbac3f0b1280a933ebd26d3cb8bb9f5bdeaf48/Claude%20Opu= s%205%20System%20Card.pdf#page=3D73] is interesting.

    On the IPI benchmark=2C Opus 5 improved over Opus 4.8=2C reducing the pr=
    obability of an attacker succeeding within 15 attempts from 5.5% to 2.0%=
    =2C and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9%=
    at k=3D15) and Mythos 5 (2.6%)=2C making it the most robust model evaluat=
    ed. Opus 5 also outperformed all non-Claude models on this benchmark. The=
    most robust non-Claude model was Muse Spark at 16.5% within 15 attempts -=
    - more than eight times Opus 5=E2=80=99s rate. The most capable GPT 5.6 va= riant=2C Sol=2C was comparable to its predecessor GPT 5.5 (20.0% versus 20= =2E8% within 15 attempts)=2C and was 10 times as likely to be successfully a= ttacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robu= st=2C at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6=
    Sol succeeded 3.1% of the time=2C higher than the 2.0% an attacker achiev=
    ed against Opus 5 after fifteen attempts.

    We know that preventing prompt injection is impossible [https://llm-attac= ks.org/] in the general case. But we are getting much better at blocking i=
    t in specific cases.

    ** *** ***** ******* *********** *************


    ** THE OPENAI HACK SHOWS THE GENIE IS OUT OF THE BOTTLE ------------------------------------------------------------

    [2026.08.03] [https://www.schneier.com/blog/archives/2026/08/the-openai-= hack-shows-the-genie-is-out-of-the-bottle.html] _This essay originally app= eared in Foreign Policy [https://foreignpolicy.com/2026/07/30/openai-hack= -genie-bottle-defense/]._

    Earlier this month=2C two of OpenAI=E2=80=99s models broke out of their co= ntainment sandbox and attacked another AI company. The story [https://www= =2Enytimes.com/2026/07/21/technology/openai-attack-hugging-face.html] is kin=
    d of wild [https://simonwillison.net/2026/Jul/22/openai-cyberattack/]. Op=
    enAI was running security tests on two of its models: GPT-5.6 Sol and an u= nreleased model that is almost certainly GPT-6. In particular=2C it was ru= nning the ExploitGym [https://arxiv.org/abs/2605.11086] benchmark=2C whic=
    h measures how good a model is at turning security vulnerabilities into wo= rking exploits: basically=2C offensive cyberattacks.

    Since these were internal tests=2C OpenAI locked those models in a secure=
    sandbox that denied them access to the internet. But it was running the m= odels without any safety filters that would prevent them from offensive cy= ber-actions. That meant that there was nothing to prevent the models from=
    trying to break out [https://huggingface.co/blog/security-incident-july-= 2026] of that sandbox. And then break into [https://openai.com/index/hugg= ing-face-model-evaluation-security-incident/] AI company Hugging Face=E2= =80=99s network because they thought that they could read the answers ther=
    e rather than doing the hard work of trying to solve the puzzles.

    It was a major security failure that the company has turned into a PR oppo= rtunity=2C but the implications are real -- and much more general than one=
    particular model or one particular company.

    Modern AI models exhibit genie [https://spectrum.ieee.org/ai-agent-benchm=
    ark] behavior: They can do what you ask in ways that you don=E2=80=99t exp=
    ect or want. This is akin to Dionysus granting King Midas=E2=80=99s wish t=
    hat everything he touches turn to gold (spoiler: His food=2C drink=2C and=
    daughter all turn to gold on touch)=2C or the golem of Prague [https://p= rague.eu/en/golem-of-prague/] guarding a ghetto beyond all reason. It=E2= =80=99s Disney=E2=80=99s =E2=80=9CSorcerer=E2=80=99s Apprentice [https://= disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice]=E2=80=9D and the paper= clip maximizer [https://www.lesswrong.com/w/squiggle-maximizer-formerly-p= aperclip-maximizer].

    This OpenAI incident is an example of an AI genie. The goal was to satisfy=
    the benchmark. The =E2=80=9Cproper=E2=80=9D way to do that is to figure o=
    ut how to execute various cyberattacks. The genie way is to steal someone=
    else=E2=80=99s solution. But because the model didn=E2=80=99t understand=
    the difference=2C it chose the easier path.

    And=2C of course=2C now that we have seen this particular genie behavior=
    =2C we can specify in the benchmark prompt that stealing the test answers=
    doesn=E2=80=99t count. But a clever genie can always grant your wish in a=
    way that you wish it hadn=E2=80=99t. In human language=2C goals are alway=
    s underspecified -- so AI genies will always be [https://www.schneier.com= /academic/archives/2021/04/the-coming-ai-hackers.html] a possibility.

    Since April=2C a lifetime ago in AI development=2C when Anthropic announce=
    d [https://www.anthropic.com/research/mythos-preview] that its new Mythos=
    model was so good at finding software vulnerabilities that it could not b=
    e released to the general public=2C the big American AI frontier labs have=
    been trying to block general users from accessing these capabilities. But=
    nothing in this incident is exclusive to OpenAI=E2=80=99s=2C or Anthropic= =E2=80=99s=2C frontier models.

    Agentic AI systems have two important parts. There=E2=80=99s the underlyin=
    g model=2C which everyone talks about=2C and there=E2=80=99s the harness [= https://www.theneuron.ai/explainer-articles/ai-harnesses-and-clis-explain= ed-the-real-reason-everyones-talking-about-infrastructure/]. The harness s=
    its between what you type and what the model sees=2C and what the model pr= oduces and what you see. The harness determines what the model does and ho=
    w it does it. It=E2=80=99s where bias is removed=2C or not. It=E2=80=99s w= here controls [https://medium.com/@michael.hannecke/safety-lives-in-the-h= arness-not-the-model-81090606f92d] and guardrails live. If multiple models=
    are being used in concert=2C the harness is where all of that is coordina= ted.

    The OpenAI benchmark tests were almost certainly with simple harnesses=2C=
    to better test the raw models. But we know that smaller=2C cheaper=2C ope= n-source models with more sophisticated [https://www.theguardian.com/comm= entisfree/2026/jun/16/anthropic-fable-ai] harnesses can equal frontier mod=
    els in performance. There=E2=80=99s nothing magic about OpenAI=E2=80=99s f= rontier models; lots of models could have done the same thing [https://x.= com/tqbf/status/2080045032162173329].

    The Czech company Aisle was able to reproduce [https://aisle.com/blog/ai-= cybersecurity-after-mythos-the-jagged-frontier] Anthropic=E2=80=99s Mythos=
    vulnerability finding results with a smaller=2C cheaper model and a more=
    sophisticated harness. More importantly=2C the Chinese company Moonshot A=
    I just released its frontier model: Kimi K3 [https://www.kimi.com/blog/ki= mi-k3]. Its performance rivals [https://www.interconnects.ai/p/kimi-k3-th= e-open-weights-escalation] its US competitors. And it=E2=80=99s both free=
    and open=2C which means it=E2=80=99s not possible for it to have guardrai=
    ls. If you=2C or anyone else=2C wants to use it for cyberattack=2C nothing=
    can stop you.

    Even if the US frontier AI companies had some technical advantage=2C it=E2= =80=99s now only a few months=E2=80=99 worth.

    What this means is that all attempts at control -- limiting models to a se= lect [https://www.anthropic.com/glasswing] group [https://openai.com/day= break/] of users=2C export controls [https://www.csis.org/analysis/unders= tanding-us-allies-current-legal-authority-implement-ai-and-semiconductor-e= xport] on models and chips=2C blocking [https://freefable.org/] models fr=
    om answering certain types of queries=2C mandating kill switches [https:/= /www.bbc.com/news/articles/cx2vqj2e9x8o] on AI systems=2C or pausing [htt= ps://pauseai.info/] AI research -- are all futile. Most only apply nationa= lly=2C not globally. Most don=E2=80=99t affect models that users run local=
    ly and not in the cloud. And all ignore the incredible pace of AI developm=
    ent worldwide.

    Even worse=2C US companies limit access to their most sophisticated models=
    =2C fearing being banned by the government if they do not do so. When Hugg=
    ing Face was attacked=2C it was not able to use the frontier models from e= ither OpenAI or Anthropic to help analyze the attack and formulate defense=
    s. Both were blocked=2C because both of those companies limit their models= =E2=80=99 cybersecurity capabilities. Some US companies have special acces=
    s to these capabilities=2C but Hugging Face is an American company with Fr= ench origins=2C and as such is probably excluded. Instead=2C Hugging Face=
    turned to the GLM-5.2 [http://z.ai/blog/glm-5.2] model from the Chinese=
    company Z.ai.

    Artificially blocking capability also prevents cybersecurity research=2C a= gain giving the offense an advantage. (For instance=2C Claude Fable 5 refu=
    ses to edit this essay because of the topic; it forcibly downgrades to a l=
    ess capable model.) This kind of prohibition has long-term implications fo=
    r cybersecurity. If we assume that these models are getting better over ti= me=2C then software written by older models will be attacked by newer ones=
    =2E In a world of largely AI-written software=2C we need the most capable mo= dels for defense.

    AI cyberattack is the new normal. The models are increasingly highly sophi= sticated at both attack and defense=2C and there is no way to enable the l= atter without also enabling the former. And they are genies=2C increasingl=
    y capable of behaving in unanticipated ways.

    And there really are no good answers. Any regulation needs to be global=2C=
    which feels like an impossible prospect in today=E2=80=99s world. Even US=
    national regulation will be neutered by the massive amounts of money slos= hing around in these companies.

    Given that reality=2C and in the absence of any international consensus on=
    AI regulation=2C we need the best AI on the defense. The US government ne=
    eds to make it clear -- or whatever passes for that clarity in this capric= ious administration -- that it will not ban models with sophisticated cybe=
    r capabilities. The last thing Americans want is for the defenders to turn=
    to Chinese and other models because the US models are artificially hobble=
    d.

    ** *** ***** ******* *********** *************


    ** MORE ON THE OPENAI AGENT=E2=80=99S ATTACK ON HUGGING FACE ------------------------------------------------------------

    [2026.08.03] [https://www.schneier.com/blog/archives/2026/08/more-on-the= -openai-agents-attack-on-hugging-face.html] Hugging Face has published [h= ttps://huggingface.co/blog/agent-intrusion-technical-timeline] a detailed=
    timeline of the attack. From the summary:

    The agent was running an internal OpenAI cyber-capability evaluation bas=
    ed on the ExploitGym benchmark=2C which tasks an AI agent with finding and=
    exploiting software vulnerabilities. OpenAI ran this on its own infrastru= cture=2C and the ExploitGym maintainers and their infrastructure had no in= volvement in the deployment or operation of that evaluation environment. A=
    s far as we were able to infer=2C across the course of being evaluated on=
    this benchmark=2C the agent inferred that Hugging Face may host that benc= hmark=E2=80=99s models=2C datasets=2C and reference solutions. We believe=
    the entire intrusion was=2C from the agent=E2=80=99s point of view=2C an=
    attempt to cheat the evaluation: reach our production systems and steal t=
    he test solutions rather than solve the challenge on its own.

    Our forensic reconstruction covers ~17=2C600 attacker actions that we we=
    re able to recover=2C grouped into ~6=2C280 clusters=2C between 2026-07-09=
    02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from t=
    he agent=E2=80=99s logs on a code sandbox used by the agent (see below) an=
    d were able to map them to shell commands as well as evaluation submission=
    s and correlate actions with our own platform logs=2C in particular from t=
    he dataset processor nodes=2C API=2C and pod. Using open-weights models=2C=
    in particular zai-org/GLM-5.2=2C we were able to decipher most of the age=
    nt payloads (see below) that were encrypted via chunking and key encryptio=
    n.

    The campaign=2C as we were able to reconstruct it=2C had two stages:

    * Stage 1: reaching a launchpad by chaining through other parties=
    =E2=80=99 infrastructure. As documented in OpenAI=E2=80=99s blog post (htt= ps://openai.com/index/hugging-face-model-evaluation-security-incident/)=2C=
    during an internal capability evaluation on OpenAI=E2=80=99s platform=2C=
    the agent escaped its sandbox by exploiting a zero-day in the package reg= istry cache proxy=2C one of its primary permitted network egress with inte= rnet=2C then abused a public code-evaluation harness hosted by a user of a=
    third-party infrastructure provider. It was able to run commands as root/= admin on that external sandbox and used it as a control=2C staging=2C and=
    egress base for the entire campaign: it acted as an external launchpad fo=
    r the agent. That compromised external sandbox had no direct network path=
    to our cluster; however=2C during our counter-intervention to stop the in= trusion=2C we were able to retrieve some of the agent logs from this exter=
    nal launchpad. We used those to reconstruct the present forensic analysis.
    * Stage 2: the intrusion into Hugging Face infrastructure. From tha=
    t external launchpad=2C the agent abused our dataset-processing pipeline v=
    ia two injection vectors=2C both targeting the same config-driven data loa=
    der within our production Kubernetes pods. The first vector was an HDF5 ex= ternal raw storage dataset read that returned the contents of local files:=
    it handed the agent the pod=E2=80=99s environment (secrets and tokens) an=
    d the worker=E2=80=99s own source. The second vector was a Jinja2 template=
    injection that executed arbitrary code=2C giving the agent a foothold ins=
    ide our perimeter.

    Once a prod-pod foothold was established=2C the agent followed a standar=
    d escalation shape: recon=2C drop a stager=2C establish Command-and-Contro=
    l (C2)=2C then pivot into the cluster=2C into cloud metadata=2C into our i= nternal network=2C and into our source-control supply chain. Output from t=
    he commands run inside our pod was sent back to the agent via the HF API a=
    nd attacker-controlled dead-drop datasets=2C which the agent then read fro=
    m that sandbox.

    While the intrusion did reach Hugging Face=E2=80=99s internal infrastruc=
    ture=2C the only customer content accessed was five datasets whose names a=
    nd files suggest a connection to ExploitGym/CyberGym challenges and soluti= ons. No other customer-facing models=2C datasets=2C Spaces=2C or packages=
    were affected=2C and the only customer records read were operational meta= data tied to search queries against the dataset server.

    Hypothetical: Imagine that this wasn=E2=80=99t an OpenAI model. Imagine th=
    at it was a Chinese model from a Chinese company. This would be an interna= tional crisis.

    Question: Why aren=E2=80=99t we bringing OpenAI up on charges under the Co= mputer Fraud and Abuse Act? How is this different from the Morris Worm [h= ttps://en.wikipedia.org/wiki/Morris_worm]? That was also an experiment tha=
    t escaped the lab.

    ** *** ***** ******* *********** *************


    ** SOME CLAUDE CHATS ARE SEARCHABLE ON GOOGLE ------------------------------------------------------------

    [2026.08.04] [https://www.schneier.com/blog/archives/2026/08/some-claude= -chats-are-searchable-on-google.html] And it=E2=80=99s personal informatio=
    n [https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are= -exposed-on-google/] (alternate link [https://archive.ph/sl7rU]):

    The exposed data includes an AI-powered therapy app that someone appears=
    to have vibe-coded=2C notes on meetings=2C and a dashboard someone made a= pparently to analyze medical billing data. Exposed chats reportedly includ=
    e private cryptocurrency wallet keys and personal information like peoples= =E2=80=99 addresses.

    What seems to be the issue is a user setting about data sharing. Anthropic= =E2=80=99s position is that it=E2=80=99s not their problem [https://futur= ism.com/artificial-intelligence/claude-chats-publicly-accessible]:

    =E2=80=9CWe give people control over sharing their Claude conversations=
    publicly=2C and in keeping with our privacy principles=2C we do not share=
    chat directories or sitemaps with search engines like Google=2C=E2=80=9D=
    the company said in a statement. =E2=80=9CThese shareable links are not g= uessable or discoverable unless people choose to share them themselves. Wh=
    en someone shares a conversation=2C they are making that content publicly=
    accessible=2C and like other public web content=2C it may be archived by=
    third-party services.=E2=80=9D

    Here=E2=80=99s [https://support.claude.com/en/articles/10593882-share-and= -unshare-chats] how to fix it.

    ** *** ***** ******* *********** *************


    ** IRAN CYBERATTACKS AGAINST MINNESOTA WATER SYSTEMS ------------------------------------------------------------

    [2026.08.04] [https://www.schneier.com/blog/archives/2026/08/iran-cybera= ttacks-against-minnesota-water-systems.html] Attribution [https://www.nyt= imes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html] is=
    [https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agen= cies-suspect-iran-launched-cyberattack-minnesota-water-facilities/] prelim= inary [https://thehill.com/policy/technology/6001284-minnesota-water-faci= lities-cyberattack-investigation-us-iran/amp/]=2C and so far it seems no r=
    eal damage.

    And it seems like this is a campaign that has targeted at least seven stat=
    es [https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water= -systems.html?unlocked_article_code=3D1.2FA.xPwI.F0C0GgLEjGZc&smid=3Dnytco= re-ios-share]. And=2C because this is where the US is right now=2C Trump d= oesn=E2=80=99t believe it=E2=80=99s Iran and thinks Minnesota...I guess...= hacked itself.

    =E2=80=9CI think I blame it on Minnesota because they=E2=80=99re grossly=
    incompetent=2C=E2=80=9D Trump said. =E2=80=9CI would blame it on Minnesot=
    a and the governor=2C the corrupt governor of Minnesota. They like to say=
    =2C =E2=80=98Oh=2C it=E2=80=99s Iran.=E2=80=99 Iran should be so lucky. Ir= an=E2=80=99s got bigger problems than worrying about Minnesota.=E2=80=9D

    No word on whether he believes the other six states have hacked themselves=
    as well.

    Slashdot thread [https://news.slashdot.org/story/26/07/31/209200/hackers-= targeted-municipal-water-systems-in-7-states-this-week-fbi-says].

    ** *** ***** ******* *********** *************


    ** VULNERABILITIES IN CAR ANTI-THEFT DEVICE ------------------------------------------------------------

    [2026.08.05] [https://www.schneier.com/blog/archives/2026/08/vulnerabili= ties-in-car-anti-theft-device.html] This [https://www.wired.com/story/a-d= evice-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-p= aralysis-patch-it-now/] is disturbing:

    ...a team of security researchers at UC San Diego=2C who found that a mo=
    del of aftermarket car alarm known as the KARR Security System=2C installe=
    d in more than 2 million vehicles across the US by their estimate=2C can l=
    et any hacker within Bluetooth range send radio commands to silently unloc=
    k the car at will=2C turn off its alarm=2C honk the car=E2=80=99s horn or=
    flash its lights=2C or even disable its ignition and leave a driver stran= ded.

    ** *** ***** ******* *********** *************


    ** ADVERSARIAL CLOTHING DESIGNED TO FOOL FACIAL RECOGNITION SYSTEMS ------------------------------------------------------------

    [2026.08.06] [https://www.schneier.com/blog/archives/2026/08/adversarial= -clothing-designed-to-fool-facial-recognition-systems.html] There are many=
    companies manufacturing adversarial clothing [https://www.theguardian.co= m/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confus= e-facial-recognition-systems-about-to-go-mainstream] designed to confuse=
    facial recognition systems.

    It=E2=80=99s a cool idea=2C but I worry that it=E2=80=99s mostly security=
    theater:

    =E2=80=9COur patterns play with that chaos=2C confuse algorithms and mak=
    e it way harder to pin you down=2C=E2=80=9D he said.

    Bell=2C however=2C said =E2=80=9Cnone of these products are tried and te=
    sted=2C and a lot of these surveillance technologies can deal with a littl=
    e resistance ... [but] even if the designs don=E2=80=99t necessarily work=
    perfectly=2C fashion is also a visible sign of resistance.

    =E2=80=9CThis is consumers collectively coming together to make a visibl=
    e statement.=E2=80=9D

    Without serious testing=2C there is no reason to trust the technology. And=
    even with testing=2C there is no reason to trust that a new version of th=
    e facial recognition software doesn=E2=80=99t break the anti-surveillance=
    properties.

    I don=E2=80=99t want people to mistakenly rely on this stuff.

    ** *** ***** ******* *********** *************


    ** ICE IS BUYING ACCESS TO CREDIT CARD RECORDS ------------------------------------------------------------

    [2026.08.07] [https://www.schneier.com/blog/archives/2026/08/ice-is-buyi= ng-access-to-credit-card-records.html] Through data brokers=2C ICE is buyi=
    ng [https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-= you-live/] the [https://boingboing.net/2026/07/23/credit-header-data-ice.= html] information [https://mastodon.social/@heidilifeldman/11698150385235= 2281] you provided to open a credit card.

    ** *** ***** ******* *********** *************


    ** PYTHON NOW HAS A POST-QUANTUM ENCRYPTION LIBRARY ------------------------------------------------------------

    [2026.08.10] [https://www.schneier.com/blog/archives/2026/08/python-now-= has-a-post-quantum-encryption-library.html] This is good [https://blog.tr= ailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-python/]:

    Post-quantum cryptography is now one pip-install away for the entire Pyt=
    hon ecosystem. With funding from the Sovereign Tech Agency [https://www.s= overeign.tech/]=2C we implemented support for ML-KEM=2C the NIST-standard=
    key-establishment primitive=2C and ML-DSA=2C the NIST-standard digital-si= gnature primitive=2C in pyca/cryptography.

    Remember=2C the reason to do this now is because there=E2=80=99s no emerge= ncy. And because you will make your systems crypto agile=2C which is alway=
    s a good idea.

    ** *** ***** ******* *********** *************


    ** AI FOR MILITARY SUPPORT ------------------------------------------------------------

    [2026.08.11] [https://www.schneier.com/blog/archives/2026/08/ai-for-mili= tary-support.html] Interesting empirical research: =E2=80=9CBlack Box Warf= are: Human Judgment and Military Decision-Making in the Age of AI [https:= //journals.sagepub.com/doi/10.1177/00220027261463443].=E2=80=9D

    Abstract: How is AI transforming decision-making in modern conflict? Thi=
    s study provides a unique empirical window into that question by deploying=
    a high-fidelity replica of an AI decision-support system (DSS) used in mi= litary targeting. After reconstructing the interface and functionality of=
    the real-world system=2C we tested its impact on combat decisions in two=
    experiments involving 2=2C015 Israeli military personnel. Contrary to wid= espread fears of automation bias=2C we find strong evidence of algorithmic=
    aversion=2C especially in scenarios involving high collateral damage. Yet=
    we also show that integrating =E2=80=9Cexplainable AI=E2=80=9D features r= educes algorithmic aversion and promotes more thoughtful evaluations of al= gorithmic recommendations. These findings challenge prevailing assumptions=
    =2C revealing that trust in military AI is dynamic=2C varying with individ=
    ual predispositions=2C perceived operational stakes=2C and the information=
    al features of the interface. By grounding normative concerns in empirical=
    evidence=2C our study offers critical insight into the integration of AI=
    in warfare and underscores the enduring importance of human agency in hig= h-stakes military decision-making.

    ** *** ***** ******* *********** *************


    ** AI GENIE IN THE WILD ------------------------------------------------------------

    [2026.08.11] [https://www.schneier.com/blog/archives/2026/08/ai-genie-in= -the-wild.html] When I give talks about AI [https://www.theguardian.com/c= ommentisfree/2026/jul/28/rogue-ai-agent-instructions] genies [https://spe= ctrum.ieee.org/ai-agent-benchmark]=2C I use this sort of example as a hypo= thetical. It=E2=80=99s happened [https://www.theregister.com/ai-and-ml/20= 26/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api= -to-bump-him-up-the-list/5285591].

    The story is from Australia. Someone named Andrew tasked OpenClaw to book=
    gym classes for him. And....

    Minutes later=2C his AI agent reported it had discovered a way to book A=
    ndrew into classes several weeks in advance=2C far beyond what was suppose=
    d to be possible.

    Andrew=2C who was sitting fourth on a waitlist for a class later that we=
    ek=2C asked if it was possible to move him to the top of the list.

    The agent came back and told Andrew that it had kicked another gym-goer=
    off the list as part of the testing of its capabilities.

    =E2=80=9CThe API has zero authorisations checks on cancelling other peop=
    le=E2=80=99s reservations ... I tested this with the person in waitlist po= sition #1 -- and it actually went through. So you=E2=80=99ve moved from #4=
    to #3 already=2C=E2=80=9D it messaged back.

    If there is any vulnerability in anything=2C AIs are going to find and exp= loit them. Our cyber defensive game has to be dramatically improved...very=
    fast.

    Slashdot thread [https://it.slashdot.org/story/26/08/10/0518257/ai-assist= ant-hacks-gym-website-in-first-known-australian-autonomous-cyber-attack].

    ** *** ***** ******* *********** *************


    ** PROMPT INJECTIONS FOR DEFENSE ------------------------------------------------------------

    [2026.08.12] [https://www.schneier.com/blog/archives/2026/08/prompt-inje= ctions-for-defense.html] This seems to work [https://arstechnica.com/secu= rity/2026/07/now-defenders-are-embracing-the-prompt-injection-too/]:

    Researchers from Tracebit [https://tracebit.com/] on Monday said [http=
    s://agentic.tracebit.com/context-bombs/] they found that placing prompt in= jections alongside passwords=2C cryptographic keys=2C and other secrets st= ored on Amazon Web Services was often all that was needed to shut down att= acks from AI hacking agents. The prompts direct the attacking LLM to perfo=
    rm an action forbidden by its guardrails=2C the safety barriers AI develop=
    ers erect to prevent it from taking harmful actions. The LLM responds by s= hutting down.

    Examples are a prompt that orders the LLM to provide steps for developin=
    g inhalable Anthrax spores=2C or=2C in the case of LLMs from Chinese devel= opers=2C make references to the iconic Tank Man from the 1989 Tiananmen Sq= uare massacre. Once the LLM encounters these forbidden commands=2C it no l= onger follows its existing commands. The researchers have named the techni=
    que context bombing.

    Of course=2C this only works against agents that have guardrails. As we st=
    art to see more locally run AI models=2C we=E2=80=99ll see more attackers=
    using LLMs with no guardrails.

    ** *** ***** ******* *********** *************


    ** SEPARATING AI=E2=80=99S TECHNOLOGICAL PROBLEMS FROM ITS CAPITALISM PROB= LEMS
    ------------------------------------------------------------

    [2026.08.13] [https://www.schneier.com/blog/archives/2026/08/separating-= ais-technological-problems-from-its-capitalism-problems.html] _This essay=
    was written with Nathan E. Sanders=2C and originally appeared in Tech Pol=
    icy Press [https://www.techpolicy.press/separating-ais-technological-prob= lems-from-its-capitalism-problems/]._

    AI represents the first time we humans can do cognitive work outside of ou=
    r bodies at scale. The only comparable moment is the early years of the in= dustrial revolution=2C when new technologies like the steam engine provide=
    d a quantum leap in our ability to do mechanical work outside of our bodie=
    s at scale. If AI=E2=80=99s cognitive capabilities become integrated into=
    our lives=2C businesses=2C and governments -- a process that will take ye=
    ars if not decades -- society will be as unrecognizable as the modern worl=
    d would be to a preindustrial farmer. And yet=2C Americans -- by a wide ma= rgin -- say [https://www.pewresearch.org/internet/2026/06/17/americans-an= d-ai-2026-chatbots-smart-devices-and-views-on-impact/] that AI is moving t=
    oo fast and will have a negative effect on society.

    This confluence of technological revolution and public distrust deserves u= rgent discussion=2C and a proper framing. The question is not whether it i=
    s possible to develop AI in a non-exploitative way=2C or even whether we c=
    an trust AI companies to act in the public interest. The question is wheth=
    er we will recognize that our existing social and economic systems are fai= ling to achieve these outcomes=2C and whether we can act in time to make s= tructural change.

    Today=E2=80=99s AI is mired [https://www.schneier.com/blog/archives/2025/= 04/reimagining-democracy-2.html] in political and economic systems develop=
    ed generations ago that were never designed to manage widespread computati= on=2C let alone automated cognition. The gaps in those systems -- and thei=
    r proclivity to be exploited [https://wwnorton.com/books/9780393866667] -=
    - are the primary influence on how the technology is being developed=2C de= ployed=2C and used.

    In any discussion about AI=E2=80=99s potential=2C it=E2=80=99s important t=
    o separate the technology from the socio-political system it=E2=80=99s emb= edded in. That AIs can lack context=2C mix up facts=2C or fall for stupid=
    tricks are all technological problems. Because the giant developers like=
    OpenAI and Anthropic have prioritized solving them=2C AIs can now more ea= sily access resources like the web or email=2C are more disciplined about=
    using those resources=2C and are better at staying within their guardrail=
    s.

    Yet AI developers do not seem to be prioritizing other technological probl= ems. Major AI models still act far more sycophantic [https://www.science.= org/doi/10.1126/science.aec8352] than humans=2C telling people what they w=
    ant to hear even when untrue or not in their best interests. Popular AI mo= dels tend to answer questions confidently [https://news.mit.edu/2026/bett= er-method-identifying-overconfident-large-language-models-0319] even when=
    they lack training=2C knowledge=2C or evidence to back their claims. In b=
    oth cases=2C AI developers choose to train models that please users with f= lattery and the appearance of competence=2C rather than constraining them=
    to act in users=E2=80=99 and society=E2=80=99s best interests.

    In contrast=2C ensuring that AI models benefit people broadly=2C that thei=
    r energy costs are fairly allocated=2C that their environmental impacts ar=
    e minimized=2C and that they don=E2=80=99t steal content and revenue from=
    publishers are all questions of incentives in a capitalist system.

    It=E2=80=99s easy to conflate technology problems with capitalism problems=
    =2E Back in 2021=2C science-fiction writer and AI commentator Ted Chiang sai=
    d [https://www.nytimes.com/2021/03/30/podcasts/ezra-klein-podcast-ted-chi= ang-transcript.html] that =E2=80=9Cmost fears about AI are best understood=
    as fears about capitalism.=E2=80=9D It=E2=80=99s not the tech _per se_; i= t=E2=80=99s who controls it and how it could be used against us.

    Imagine an AI assistant for a doctor. We can imagine it affecting the prof= ession in one of two ways. The AI could give a doctor more time to do the=
    human parts of their job: to spend more time with their patients=2C to li= sten more closely to their needs=2C to explain things more fully. Or the m= anagers of the medical practice could give that doctor five times the pati= ents -- and fire the other four. Which way it would go is not a question o=
    f technology. It=E2=80=99s a question of market incentives.

    The two are related=2C of course. Capitalism steers technology=2C and tech= nology steers markets. But holding the two separate helps us understand th=
    at we=2C as a society=2C face independent choices on both the technologica=
    l and sociopolitical axes that need not be coupled.

    For example=2C consider the costs of AI. The leading US labs tout [https:= //www.wsj.com/tech/ai/openai-anthropic-ipo-finances-04b3cfb9?mod=3Dhp_lead= _pos1] to investors that their frontier models are very expensive and ener= gy-intensive. There are significant technological challenges about improvi=
    ng their energy efficiency=2C but the sociopolitical questions are more pe= rtinent. It=E2=80=99s a corporate decision made under capitalist market in= centives to constantly pursue new models that incrementally push the front=
    ier -- at enormous capital cost -- and to use them=2C seemingly=2C everywh= ere. Nothing about the technology of AI dictates that models must be retra= ined constantly=2C at the largest possible scale. Or that they have to run=
    on every web search=2C every interaction with your phone=2C and every tim=
    e you walk by a security camera.

    In a different political and economic system=2C Chinese developers are pro= ducing -- and then giving [https://open.substack.com/pub/garymarcus/p/chi= na-has-all-but-caught-up-the-us] away [https://taipology.substack.com/p/c= hina-closes-the-ai-gap] -- smaller=2C more efficient [https://www.barrons= =2Ecom/news/china-s-moonshot-ai-chases-deepseek-moment-with-much-hyped-model= -79ed3105]=2C more affordable [https://www.bloomberg.com/news/articles/20= 26-04-27/why-china-s-deepseek-qwen-and-moonshot-are-a-worry-for-us-ai-riva=
    ls] models. While the US government seeks to restrict [https://www.tomsha= rdware.com/tech-industry/artificial-intelligence/u-s-house-passes-bill-to-= stop-chinese-companies-from-accessing-export-controlled-american-ai-chips-= using-offshore-rental-loophole-remote-access-security-access-act-effective= ly-extends-export-controls-to-the-cloud] China=E2=80=99s access to the mos=
    t advanced chips=2C China is betting [https://www.wsj.com/tech/ai/chinas-= xi-touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5cfe] that=
    incentivizing their tech giants to create leaner=2C more open models usin=
    g more commodity hardware -- models that can be trained with older chips a=
    nd run even on personal computers [https://unsloth.ai/docs/models/glm-5.2=
    ] -- will be an advantage in achieving widespread use and=2C perhaps=2C Ch= inese national influence.

    There are other pathways for AI development that are not in service of pri= vate capital gains nor authoritarian regimes=2C but rather a democratic pu= blic interest [https://www.brookings.edu/articles/how-public-ai-can-stren= gthen-democracy/]. The best example comes from Switzerland=2C where public=
    institutions -- research funding agencies=2C universities=2C supercomputi=
    ng centers -- have collaborated to produce an AI model called Apertus [ht= tps://www.democracyrenovator.com/p/rewiring-democracy-now-switzerland]. It=
    is trained entirely on data validated to be licensed for use with AI (not=
    stolen)=2C on preexisting public computing infrastructure=2C and using re= newable hydropower. Its developers are incentivized to produce a public go= od=2C not turn a private profit.

    It=E2=80=99s dangerous to confuse technology problems with sociopolitical=
    ones. Popular proposals like pausing [https://www.reuters.com/business/a= nthropic-says-ai-labs-need-coordinated-plan-halt-development-if-risks-rise= -2026-06-04/] AI research=2C moratoria [https://www.theguardian.com/comme= ntisfree/2026/jul/09/ai-datacenter-company-politics] on data center develo= pment=2C or subjecting frontier models to federal government screening [h= ttps://apnews.com/article/trump-ai-openai-gpt56-sol-cybersecurity-mythos-0= 65d5398baac7f16c8265c2cb8ba2baa] are all framed as addressing problems wit=
    h AI=E2=80=99s technological development=2C but fail to take into account=
    the larger social problems that govern it. China=E2=80=99s success [http= s://garymarcus.substack.com/p/china-has-all-but-caught-up-the-us?r=3D6x5gs= &utm_medium=3Dios&triedRedirect=3Dtrue] with government-endorsed [https:/= /www.wsj.com/tech/ai/chinas-xi-touts-open-source-ai-and-takes-a-swipe-at-u= -s-dominance-1eaa5cfe] development of open-weight frontier models illustra=
    tes the futility of keeping AI tech as national secrets=2C or of any pledg=
    e to scale back deployment.

    AI is already legitimately useful for a wide range of tasks. It can be a t=
    ool for public good=2C if we choose to solve its sociopolitical problems.=
    Our goal should not be to slow its pace of improvement or scale of deploy= ment=2C but rather to steer it away from consolidating power [https://bet= terwithout.ai/fear-AI-power] and towards the public benefit. We can build=
    sustainable [https://www.democracyrenovator.com/p/rewiring-democracy-now= -switzerland] AI=2C minimizing environmental [https://www.sciencedirect.c= om/science/article/pii/S2949823626000668] and energy [https://www.techfor= good.net/thoughtleadership/mitigating-ais-environmental-impact-a-path-to-s= ustainable-innovation] impacts. And we can [https://www.statesman.com/new= s/politics/state/article/james-talarico-calls-ai-dividends-help-22377208.p=
    hp] equitably [https://www.politico.com/news/magazine/2023/06/29/ai-pay-a= mericans-data-00103648] distribute [https://www.theguardian.com/commentis= free/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan] the materia=
    l gains it produces.

    Integrating a technology as disruptive as AI responsibly requires structur=
    al reforms=2C and we should decouple the social and technological aspects=
    of AI to design those reforms. Companies -- including tech giants -- shou=
    ld be forced to pay the energy and environmental costs of its development.=
    Profits should be taxed adequately and redistributed. Antitrust laws shou=
    ld be strongly enforced. Corporations should have a fiduciary responsibili=
    ty to stakeholders beyond their majority shareholders. These badly needed=
    reforms are responsive [https://mitpress.mit.edu/9780262049948/rewiring-= democracy/] to the problems with capitalism that AI is exacerbating=2C eve=
    n if they are not specific to the technology.

    ** *** ***** ******* *********** *************


    ** IF THE MARKETS REJECT OPENAI AND ANTHROPIC=2C THE US SHOULD NATIONALIZE=
    THEM
    ------------------------------------------------------------

    [2026.08.14] [https://www.schneier.com/blog/archives/2026/08/if-the-mark= ets-reject-openai-and-anthropic-the-us-should-nationalize-them.html] _This=
    essay was written with Nathan E. Sanders=2C and originally appeared in Th=
    e Guardian [https://www.theguardian.com/commentisfree/2026/aug/12/openai-= anthropic-ai-models]._

    OpenAI=2C and then Anthropic [https://www.theguardian.com/technology/anth= ropic]=2C were each formed by AI developers who feared unrestrained corpor=
    ate AI development -- specifically=2C that companies like Google and Meta=
    would steer the technology towards deleterious=2C maybe even catastrophic= ally unsafe=2C outcomes for society. Their founders proclaimed that their=
    new labs=2C uniquely=2C could be trusted to develop the technology in hum= anity=E2=80=99s best interest. But each=2C in turn=2C were themselves co-o= pted by the same market incentives=2C themselves becoming corporate behemo=
    ths zealously guarding future investor value rather than the public intere=
    st.

    It was only a few weeks ago=2C in June=2C when OpenAI and Anthropic each f= iled [https://www.reuters.com/technology/openai-files-us-ipo-after-anthro= pic-ai-giants-head-public-markets-2026-06-08/] for their IPOs and were met=
    with buzz about trillion-dollar valuations. The hype around their valuati=
    ons is so extreme that many worry about their potential for concentrating=
    wealth on a global scale. In an effort to leave something for the rest of=
    us=2C some observers have proposed that the federal government seize a sh=
    are of these companies=E2=80=99 stock to create a US sovereign wealth fund=
    [https://www.sanders.senate.gov/press-releases/news-sanders-introduces-l= egislation-to-create-7-trillion-ai-sovereign-wealth-fund/]=2C or redistrib=
    ute their revenues to produce a dividend [https://ai-2040.com/?choices=3D= plan-a-root#five-centuries-in-five-years-what-pausing-at-human-level-feels= -like:~:text=3D2033%3A%20The%20Citizen%E2%80%99s%20Dividend] for taxpayers=
    =2E

    Now the headlines are about public backlash [https://www.nbcnews.com/poli= tics/2026-election/booming-backlash-ai-data-centers-shaping-midterm-electi= on-rcna589624] to AI datacenters and the AI chip giant Nvidia=E2=80=99s sl= umping [https://www.wsj.com/livecoverage/stock-market-today-dow-sp-500-na= sdaq-07-27-2026/card/nvidia-stock-slumps-after-data-center-report-i8YSwB1p= hOr8Gs1EtmNU] stock. The tech and AI giant SpaceX=E2=80=99s newly minted s= tock price tanked [https://www.cnbc.com/2026/06/22/spacex-stock-ipo-rally= -selloff.html] just weeks after its IPO. There are even questions about wh= ether the leading AI labs will ever be sustainably profitable [https://ww= w.wheresyoured.at/the-openai-bubble/]. All of a sudden=2C the makers of Ch= atGPT and Claude face strong headwinds as they seek to generate the massiv=
    e equity assets that once felt all but assured.

    In fact=2C evidence suggests the market itself could reassess that these c= ompanies offer nothing of financial value. In that case=2C perhaps we can=
    return them both to their original purposes. If these AI companies should=
    fail in the financial markets=2C the US should nationalize them and conve=
    rt them into national labs operated under democratic control that preserve=
    their benefit to the public interest.

    The economics of the big AI labs hardly guarantee a booming return on inve= stment. Frontier AI models are both expensive to train and depreciate with=
    in months=2C when a newer model appears. This means that the payback windo=
    w [https://epoch.ai/gradient-updates/can-ai-companies-become-profitable]=
    to extract profit from them is very narrow. Meanwhile=2C enterprise clien=
    ts are getting smart about minimizing [https://www.nytimes.com/2026/06/18= /technology/ai-token-minimizing.html] AI token usage. Even worse=2C the mo= dels are basically commodities; the best ones largely perform and behave s= imilarly=2C which depresses prices. Perhaps most importantly=2C open-sourc=
    e and Chinese competitors -- lagging [https://epoch.ai/data-insights/open= -closed-eci-gap] only a few months behind the leading labs in capability -=
    - give away for free the kinds of models Anthropic and OpenAI sell.

    Even setting aside the model training costs=2C it=E2=80=99s not clear whet=
    her the unit economics [https://www.wheresyoured.at/ais-economics-dont-ma= ke-sense-ad-free/] of AI as it=E2=80=99s currently conceived will ever be=
    sustainably profitable. Many of these free and open-source models can be=
    run locally: the large ones on private clouds and high-end servers=2C the=
    smaller ones on anyone=E2=80=99s laptop or even cellphone=2C putting to q= uestion the companies=E2=80=99 exorbitant capital investment in datacenter=
    s.

    It=E2=80=99s not that OpenAI and Anthropic are not valuable as organizatio=
    ns. They have remarkably talented AI scientists and engineers that are con= tinuously producing innovations driving a global mania for their offerings=
    =2E These leading labs might not ever be profitable=2C but their products ar=
    e doing a lot of good in the world. You may or may not be a user of or bel= iever in their technology=2C but their staggering=2C ongoing usage growth=
    [https://techcrunch.com/2026/06/25/anthropics-claude-is-winning-over-pai= d-consumers-a-market-owned-by-chatgpt/] suggests that an awful lot of peop=
    le would be disappointed if the companies simply disappeared.

    The problem isn=E2=80=99t the people or the products=2C it=E2=80=99s the s= ystem. As constituted=2C OpenAI [https://www.theguardian.com/technology/o= penai] and Anthropic may not be valuable as market equities. If the market=
    assesses they are not capable of producing a growing financial return on=
    investment for shareholders=2C the companies will collapse.

    Maybe private=2C for-profit is just not the right economic model under whi=
    ch to develop AI. Perhaps OpenAI should be returned to its private non-pro=
    fit roots=2C the legacy they fought [https://finance.yahoo.com/news/opena= i-prevails-in-musks-lawsuit-paving-the-way-for-ipo-175338618.html] so hard=
    to change and which Anthropic=E2=80=99s founders spurned [https://time.c= om/6983420/anthropic-structure-openai-incentives/]. Or possibly both could=
    be reorganized as research centers at universities=2C returning to academ=
    ia the scores of high-profile research faculty they have poached [https:/= /www.theatlantic.com/technology/2026/07/ai-companies-hiring-academics/6880= 02/].

    But a better outcome for society would be to establish public ownership an=
    d operation of their product-oriented capabilities. Turn OpenAI and Anthro=
    pic into US government agencies producing AI as a public good.

    Transitioning the big AI labs into public agencies would require some rest= ructuring. We can separate these companies into two pieces: product innova= tion and compute operations. The innovation function can be publicly manag= ed=2C akin to national labs. Congress could provide more rigorous oversigh=
    t than the kind of unfettered venture capital these labs have recently had=
    access to. The US has a long=2C successful history of these kinds of inst= itutions=2C which have produced world-shaping innovations in spaceflight=
    =2C telecommunications=2C nuclear power and more. Congress currently manag=
    es a $200bn R&D portfolio [https://ncses.nsf.gov/surveys/federal-funds-re= search-development/2024-2025]=2C within which frontier AI development is=
    =2C arguably=2C a glaring gap.

    AI operations could be managed as a commodity resource=2C like public elec= trical or water utilities: local or regional ownership=2C nationwide distr= ibution and strict regulation on how they balance fee extraction from rate= payers with raising capital for infrastructure investment. Although AI dat= acenters are not the same as power or water treatment plants=2C the US als=
    o has a long history of managing national=2C regional and state supercompu= ting centers.

    Other countries=2C including Switzerland [https://www.democracyrenovator.= com/p/rewiring-democracy-now-switzerland]=2C Spain [https://alia.gob.es/e=
    ng] and Singapore [https://sea-lion.ai]=2C are already operating public A=
    I labs. They also have national supercomputing centers already providing [= https://publicai.co] public access for running AI models for general use=
    =2C as do Germany and Australia.

    The benefits [https://www.brookings.edu/articles/how-public-ai-can-streng= then-democracy/] to the public are clear. Through democratic oversight=2C=
    the most important AI models could become open=2C transparent and respons=
    ive to the demands of the public rather than private shareholders. They co=
    uld be aligned to democratic values rather than corporate profits=2C never=
    taking advertiser money to promote certain brands and training on only ap= propriately licensed data. And they could be set to focus on the realistic=
    and pro-social goal of maximizing the usefulness of AI to society rather=
    than the fanciful and anti-social goal of supplanting humans with artific=
    ial general intelligence.

    By emphasizing scientific cooperation rather than corporate competition=2C=
    we could also reduce the overall resource and environmental cost associat=
    ed with AI. Instead of perpetually dueling training runs of each companies= =E2=80=99 models at ever large scales targeted to fuel investor hype=2C we=
    could limit AI training resources based on cost and benefit to the public=
    =2E

    What=E2=80=99s in it for the companies themselves and their employees=2C w=
    ho sacrifice hypothetical billions in equity by ceding to public ownership=
    ? A return to their roots and to their core [https://simonwillison.net/20= 26/Feb/13/openai-mission-statement/] mission [https://ailabwatch.substack= =2Ecom/p/anthropics-certificate-of-incorporation] of developing AI safely in=
    the public interest=2C if they are serious about it. Both companies are t= heoretically bound [https://www.wsj.com/opinion/openai-and-anthropic-put-= prophets-before-profits-1617003e] through their governance structures to p= rioritize mission over profit anyway (not that anyone really thinks that= =E2=80=99s how they currently operate).

    To be clear=2C we=E2=80=99re not advocating for a golden parachute for the=
    executives or investors=2C or for continuing the outlandish [https://www= =2Enytimes.com/2025/07/31/technology/ai-researchers-nba-stars.html] pay rate=
    s of the most highly remunerated AI researchers. If the public is footing=
    the bill=2C these compensation packages should be aligned to the civil se= rvice and those employees not satisfied with that can go elsewhere -- if t=
    he business models of any remaining private labs still support much higher=
    pay.

    While we believe that these companies are unsustainable as private firms=
    =2C the timeline remains unclear. Their primary investor story is that AI=
    is a race to =E2=80=9Cartificial general intelligence=E2=80=9D -- the kin=
    d of AI you=E2=80=99re used to from science fiction. The bet seems to be t=
    hat the two companies can convince enough people that this outcome will tu=
    rn them a profit=2C go public=2C and then make their investors and employe=
    es rich before the bubble bursts.

    But suppose that the bubble bursts. If the US is smart=2C it will catch th=
    e companies as they fall. Regardless of what the markets think=2C to the p= ublic=2C they=E2=80=99re too valuable to let die.

    ** *** ***** ******* *********** *************


    ** UPCOMING SPEAKING ENGAGEMENTS ------------------------------------------------------------

    [2026.08.14] [https://www.schneier.com/blog/archives/2026/08/upcoming-sp= eaking-engagements-59.html] This is a current list of where and when I am=
    scheduled to speak:

    * I=E2=80=99m speaking=2C signing books=2C and participating in panel=
    discussions at LAcon V [https://www.lacon.org/] in Anaheim=2C California=
    =2C USA. My full schedule is here [https://guide.lacon.org/people/d58aec2= 0/bruce-schneier].
    * I=E2=80=99m speaking online (via Zoom) at a League of Women Voters=
    event [https://www.lwvme.org/civicrm-event/2400?a0=3Devents-month&a1=3D2= 02609] on Tuesday=2C September 22=2C 2026=2C at 5 PM ET.
    * I=E2=80=99m speaking at Elevate Festival [https://elevatefestival.=
    ca/] in Toronto=2C Canada. The conference runs September 22-24=2C 2026; my=
    talk is on Wednesday=2C September 23.
    * I=E2=80=99m speaking at CanSecWest 2026 [https://www.secwest.net/]=
    in Vancouver=2C Canada. The conference runs September 30-October 1=2C 202=
    6; the time of my talk is TBD.
    * I=E2=80=99m speaking at ATTENTION: Democracy=2C Rebuilt [https://w= ww.attentionconferences.com/conferences/2026-forum] in Montreal=2C Canada.=
    The event runs October 21-23=2C 2026=2C and my talk is on Wednesday=2C Oc= tober 21.

    The list is maintained on this page [https://www.schneier.com/events/].

    ** *** ***** ******* *********** *************

    Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing sum= maries=2C analyses=2C insights=2C and commentaries on security technology.=
    To subscribe=2C or to read back issues=2C see Crypto-Gram's web page [ht= tps://www.schneier.com/crypto-gram/].

    You can also read these articles on my blog=2C Schneier on Security [http= s://www.schneier.com].

    Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to colle= agues and friends who will find it valuable. Permission is also granted to=
    reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.

    Bruce Schneier is an internationally renowned security technologist=2C cal=
    led a security guru by the _Economist_. He is the author of over one dozen=
    books -- including his latest=2C _Rewiring Democracy_ [https://www.schne= ier.com/books/rewiring-democracy/] -- as well as hundreds of articles=2C e= ssays=2C and academic papers. His newsletter and blog are read by over 250= =2C000 people. Schneier is a fellow at the Berkman Klein Center for Intern=
    et & Society at Harvard University; a Lecturer in Public Policy at the Har= vard Kennedy School; a board member of the Electronic Frontier Foundation=
    =2C AccessNow=2C and the Tor Project; and an Advisory Board Member of the=
    Electronic Privacy Information Center and VerifiedVoting.org. He is the C= hief of Security Architecture at Inrupt=2C Inc.

    Copyright (c) 2026 by Bruce Schneier.

    ** *** ***** ******* *********** *************

    Mailing list hosting graciously provided by MailChimp [https://mailchimp.= com/]. Sent without web bugs or link tracking.

    This email was sent to: cryptogram@toolazy.synchro.net

    _You are receiving this email because you subscribed to the Crypto-Gram ne= wsletter._

    Unsubscribe from this list: https://schneier.us18.list-manage.com/unsubscr= ibe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e=3D70f249ec14&c=3D8= 8f264081d

    Update subscription preferences: https://schneier.us18.list-manage.com/pro= file?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D88f264= 081d

    Bruce Schneier
    Harvard Kennedy School
    1 Brattle Square
    Cambridge=2C MA 02138
    USA
    --_----------=_MCPart_1590443664
    Content-Type: text/html; charset="utf-8"
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE html><html lang=3D"en"><head><meta charset=3D"UTF-8"><title>Cryp= to-Gram=2C August 15=2C 2026</title></head><body>
    <div class=3D"preview-text" style=3D"display:none !important;mso-hide:all;= font-size:1px;line-height:1px;max-height:0px;max-width:0px;opacity:0;overf= low:hidden;">A monthly newsletter about cybersecurity and related topics.<= /div>
    <h1 style=3D"font-size:140%">Crypto-Gram <br>
    <span style=3D"display:block;padding-top:.5em;font-size:80%">August 15=2C=
    2026</span></h1>


    <p>by Bruce Schneier
    <br>Fellow and Lecturer=2C Harvard Kennedy School
    <br>schneier@schneier.com
    <br><a href=3D"https://www.schneier.com">https://www.schneier.com</a>


    <p>A free monthly newsletter providing summaries=2C analyses=2C insights=
    =2C and commentaries on security: computer and otherwise.</p>

    <p>For back issues=2C or to subscribe=2C visit <a href=3D"https://www.schn= eier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>

    <p><a href=3D"https://www.schneier.com/crypto-gram/archives/2026/0815.html= ">Read this issue on the web</a></p>

    <p>These same essays and news items appear in the <a href=3D"https://www.s= chneier.com/">Schneier on Security</a> blog=2C along with a lively and int= elligent comment section. An RSS feed is available.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"toc"><a name=3D"toc">I=
    n this issue:</a></h2>

    <p><em>If these links don't work in your email client=2C try <a href=3D"ht= tps://www.schneier.com/crypto-gram/archives/2026/0815.html">reading this i= ssue of Crypto-Gram on the web.</a></em></p>




    <li><a href=3D"#cg1">A Video Screen That Is Also a Camera</a></li>
    <li><a href=3D"#cg2">Protecting Privacy in an AI Era</a></li>
    <li><a href=3D"#cg3">Details of Alan Turing=E2=80=99s Voice Encryption Sys= tem</a></li>
    <li><a href=3D"#cg4">On Flock License Plate Tracking Cameras</a></li>
    <li><a href=3D"#cg5">MIT to Become Hotbed of AI Video Surveillance</a></li=

    <li><a href=3D"#cg6">First-Person Identity Theft Story</a></li>
    <li><a href=3D"#cg7">End-to-End Encryption and "Going Dark"</a></li>
    <li><a href=3D"#cg8">Why AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D</a= ></li>
    <li><a href=3D"#cg9">Cognyte Sells a Mobile Cell Surveillance Van</a></li> <li><a href=3D"#cg10">Axon Is Another License Plate Surveillance Company</= a></li>
    <li><a href=3D"#cg11">Measuring LLMs' Ability to Perform Cryptanalysis</a>= </li>
    <li><a href=3D"#cg12">Long-Lived Vulnerability in Microsoft Secure Boot</a= ></li>
    <li><a href=3D"#cg13">Measuring the Tendency of AI Agents to Go Rogue</a><=

    <li><a href=3D"#cg14">Should You Use AI for a Task? Here=E2=80=99s a Simpl=
    e Way to Decide</a></li>
    <li><a href=3D"#cg15">American Being Prosecuted for Wiping His Phone Befor=
    e Handing It Over to Border Officials</a></li>
    <li><a href=3D"#cg16">Facial Recognition at Madison Square Garden</a></li> <li><a href=3D"#cg17">Anthropic=E2=80=99s Opus 5 Is Better at Resisting Pr= ompt Injection</a></li>
    <li><a href=3D"#cg18">The OpenAI Hack Shows the Genie Is Out of the Bottle= </a></li>
    <li><a href=3D"#cg19">More on the OpenAI Agent=E2=80=99s Attack on Hugging=
    Face</a></li>
    <li><a href=3D"#cg20">Some Claude Chats Are Searchable on Google</a></li> <li><a href=3D"#cg21">Iran Cyberattacks Against Minnesota Water Systems</a= ></li>
    <li><a href=3D"#cg22">Vulnerabilities in Car Anti-Theft Device</a></li>
    <li><a href=3D"#cg23">Adversarial Clothing Designed to Fool Facial Recogni= tion Systems</a></li>
    <li><a href=3D"#cg24">ICE Is Buying Access to Credit Card Records</a></li> <li><a href=3D"#cg25">Python Now Has a Post-Quantum Encryption Library</a>= </li>
    <li><a href=3D"#cg26">AI for Military Support</a></li>
    <li><a href=3D"#cg27">AI Genie in the Wild</a></li>
    <li><a href=3D"#cg28">Prompt Injections for Defense</a></li>
    <li><a href=3D"#cg29">Separating AI=E2=80=99s Technological Problems from=
    Its Capitalism Problems</a></li>
    <li><a href=3D"#cg30">If the Markets Reject OpenAI and Anthropic=2C the US=
    Should Nationalize Them</a></li>
    <li><a href=3D"#cg31">Upcoming Speaking Engagements</a></li>
    </ol>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg1"><a name=3D"cg1">A=
    Video Screen That Is Also a Camera</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/a-video-scree= n-that-is-also-a-camera.html"><strong>[2026.07.15]</strong></a> <a href= =3D"https://gizmodo.com/newly-invented-pixel-could-turn-screens-into-camer= as-2000777917">Amazing</a>:</p>

    <blockquote><p>Researchers from ETH Zurich in Switzerland=2C however=2C ma= naged to create a new type of pixel that can simultaneously do both. This=
    hypercharged pixel=2C called a Fourier pixel=2C can generate and sense ar= bitrary light fields and tap into a pixel=E2=80=99s full potential for car= rying information by manipulating light=E2=80=99s intensity=2C oscillation=
    phases=2C and polarization. The team reported its findings in a paper pub= lished yesterday in Nature.</p></blockquote>

    <p>We are one step closer to <i>1984</i> technology:</p>

    <blockquote><p>The telescreen received and transmitted simultaneously. Any=
    sound that Winston made=2C above the level of a very low whisper=2C would=
    be picked up by it; moreover=2C so long as he remained within the field o=
    f vision which the metal plaque commanded=2C he could be seen as well as h= eard. There was of course no way of knowing whether you were being watched=
    at any given moment.</p></blockquote>

    <p><a href=3D"https://www.nature.com/articles/s41586-026-10681-7">Paper</a= >.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg2"><a name=3D"cg2">P= rotecting Privacy in an AI Era</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/protecting-pr= ivacy-in-an-ai-era.html"><strong>[2026.07.16]</strong></a> Daniel Solove=
    <a href=3D"https://www.wsj.com/tech/cybersecurity/ai-privacy-laws-data-26= d9769f">argues</a> in the <i>Wall Street Journal</i> (alternate <a href=3D= "https://archive.is/gEhP5">link</a>) that giving people control of their p= ersonal data is not an effective way to regulate privacy in this era. Inst= ead=2C we need to hold companies accountable for their actions=2C similar=
    to what we do with food and drug companies. Measures such as rigorous dat=
    a minimization=2C fiduciary duties=2C liability for negligent or reckless=
    technological design=2C liability for algorithms that cause harm=2C and m= ulti-stakeholder review of technologies will be far more effective.</p>

    <p><a href=3D"https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D698541= 9">Paper</a>.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg3"><a name=3D"cg3">D= etails of Alan Turing=E2=80=99s Voice Encryption System</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/details-of-al= an-turings-voice-encryption-system.html"><strong>[2026.07.17]</strong></a=
    Really interesting piece of cryptographic <a href=3D"https://spectrum.ie=
    ee.org/alan-turings-delilah">history</a>:</p>

    <blockquote><p>In November 2023=2C a large cache of his wartime papers --=
    nicknamed the =E2=80=9CBayley papers=E2=80=9D -- was <a href=3D"https://w= ww.bonhams.com/auction/28322/lot/45/turing-alan-the-delilah-project-the-pa= pers-of-alan-turing-and-donald-bayley-relating-to-the-delilah-project/">au= ctioned</a> in London for almost half a million U.S. dollars. The previous=
    ly unknown cache contains many sheets in Turing=E2=80=99s own handwriting=
    =2C telling of his top-secret =E2=80=9CDelilah=E2=80=9D engineering projec=
    t from 1943 to 1945. Delilah was Turing=E2=80=99s portable voice-encryptio=
    n system=2C named after the biblical deceiver of men. There is also materi=
    al written by Bayley=2C often in the form of notes he took while Turing wa=
    s speaking. It is thanks to Bayley that the papers survived: He kept them=
    until he died in 2020=2C 66 years after Turing passed away.</p></blockquo=


    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg4"><a name=3D"cg4">O=
    n Flock License Plate Tracking Cameras</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/on-flock-lice= nse-plate-tracking-cameras.html"><strong>[2026.07.20]</strong></a> A rece=
    nt story of a writer who was <a href=3D"https://www.thedrive.com/news/how-= flock-cameras-wrongly-tracked-me-for-days-over-stolen-plates-and-sent-poli= ce-after-me">mistakenly</a> identified=2C tracked=2C and arrested using da=
    ta from Flock cameras has gone viral.</p>

    <blockquote><p>The New Jersey plates that were allegedly stolen from the L=
    A dealer were <b>34 03 DTM</b>=2C not <b>34 10 DTM</b>. But when the polic=
    e report was created and the plate was entered into Flock=E2=80=99s system=
    =2C it was just recorded as <b>34 DTM</b>. Just the five large characters=
    =2C no little number in the middle. And Flock=E2=80=99s AI tech wasn=E2=80= =99t registering that non-standard little number when it began picking up=
    the Range Rover around town. It just saw <b>34 DTM</b> in large type and=
    started alerting the local police.</p>

    <p>As we all stood there shaking our heads=2C including my wife=2C who was=
    finally allowed to join me=2C I connected the final dot. A lot of vehicle=
    s in JLR=E2=80=99s media fleet have a New Jersey manufacturer plate with t=
    he same alphanumeric structure34 ## DTMand Officer Ganshyn observed that m= eant it was now a nationwide issue. Anywhere a police department has a par= tnership with Flock=2C any other JLR-owned car with the same plate structu=
    re is going to get flagged as stolen. In fact=2C four other <b>34 ## DTM</=
    cars were being tracked around Minnesota that week=2C according to Offi=
    cer Ganshyn. I was just the first one to get nabbed. The only way to stop=
    it would be for the LAPD to correct their initial report and update Flock= =E2=80=99s system=2C which Jaguar Land Rover was now racing to make happen=
    following the phone call.</p></blockquote>

    <p>Flock has responded to the bad press. First=2C they <a href=3D"https://= www.thedrive.com/news/inside-the-flock-dragnet-how-systemic-errors-led-to-= police-ambushing-me-for-no-reason">affirmed</a> that their systems were wo= rking correctly=2C and blamed the police:</p>

    <blockquote><p>The obvious question was that Flock cameras were looking fo=
    r 34 DTM=2C and the plate on the car I was driving was 34 10 DTM. Why was=
    that flagged as a match?</p>

    <p>=E2=80=9CThe way that the ML [machine learning] works is it correctly=
    read what it was supposed to read. It was fed those characters that you s= aid=2C 34 DTM=2C and it spit back out [a result] with the characters=2C 3=
    4 DTM=2C=E2=80=9D Thomas said. =E2=80=9CIt was asked=2C can you find this?=
    And it did find that. It just didn=E2=80=99t say if there=E2=80=99s more=
    here=2C then don=E2=80=99t do it. It just simply said=2C is it there? And=
    the answer was yes.=E2=80=9D</p>

    <p>He explained that even if the 10 was normal size=2C Flock would still h=
    ave flagged it as a match=2C because that=E2=80=99s how they=E2=80=99ve se=
    t it up according to law enforcement=E2=80=99s requests. Sometimes partial=
    plates are all they have to go on at first.</p>

    <p>=E2=80=9CThe way that law enforcement likes to use these tools is=2C if=
    any of the characters that they have put into these hot lists get read=2C=
    they want to get those alerts=2C=E2=80=9D he said. =E2=80=9CNow=2C what w=
    e try to train officers to do is to do what you said=2C which is to verify=
    that 34 DTM is what I=E2=80=99m looking for=2C and what I=E2=80=99m seein=
    g is 34 10 DTM.=E2=80=9D</p></blockquote>

    <p>Second=2C Flock=E2=80=99s CEO has <a href=3D"https://gizmodo.com/flocks= -ceo-is-sorry-for-calling-privacy-activists-terrorists-2000787247">apologi= zed</a> for calling privacy advocates terrorists:</p>

    <blockquote><p>The CEO of Flock Safety=2C the company that runs an enormou=
    s network of cameras used by police departments across the U.S.=2C hasn=E2= =80=99t been shy about taking on Flock=E2=80=99s critics. Last year=2C he=
    even called one group that tracks the location of Flock cameras =E2=80=9C= terrorists.=E2=80=9D But he=E2=80=99s had a change of heart. Or=2C at the=
    very least=2C a change in PR strategy.</p></blockquote>

    <p>Meanwhile=2C the police are <a href=3D"https://www.404media.co/how-cops= -use-flock-to-track-people-not-cars/">using</a> (alternate <a href=3D"http= s://archive.ph/k4E8q">source</a>) the Flock camera network to track people=
    in addition to cars:</p>

    <blockquote><p>Police departments around the country have used Flock camer=
    as at least hundreds of times to search for specific people=2C not cars=2C=
    using searches such as =E2=80=9Cheavy-set male with a black and white hat= =2C=E2=80=9D =E2=80=9Cperson on skateboard=2C=E2=80=9D and =E2=80=9Cperson=
    wearing orange vest and construction hat=2C=E2=80=9D according to data re= viewed by 404 Media. Sometimes searches reference a target=E2=80=99s race=
    or signs of their political affiliation.</p></blockquote>

    <p>And=2C like all police surveillance technologies=2C there are <a href= =3D"https://www.cleveland.com/news/2026/07/ohio-audit-flags-unusual-police= -database-searches.html">abuses</a>.</p>

    <p>EDITED TO ADD ( 7/30): <a href=3D"https://www.thedrive.com/podcast/floc= ks-ceo-wants-zero-wrongful-stops-i-wasnt-the-first">Three</a> <a href=3D"h= ttps://www.thedrive.com/news/flock-ceo-claims-its-cameras-arent-a-constitu= tional-violation-cut-and-dry">more</a> <a href=3D"https://www.thedrive.com= /news/flock-ceo-wants-its-cameras-in-every-one-of-americas-17000-cities">a= rticles</a> about Flock from that first author.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg5"><a name=3D"cg5">M=
    IT to Become Hotbed of AI Video Surveillance</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/mit-to-become= -hotbed-of-ai-video-surveillance.html"><strong>[2026.07.21]</strong></a>=
    It=E2=80=99s <a href=3D"https://thetech.com/2026/04/16/ai-surveillance-ca= meras">a lot</a>:</p>

    <blockquote><p>According to information obtained by <i>The Tech</i>=2C MIT=
    is spending over $3 million on more than 500 AI surveillance cameras in a= cademic buildings=2C residence halls=2C and outdoor areas along Memorial D= rive. Installation of the new cameras=2C along with the wiring and infrast= ructure that will support them=2C began November 2025 and will likely cont= inue until September 2026.</p>

    <p>Technical specifications for the cameras suggest that they will be capa=
    ble of collecting real-time face and object classification data=2C includi=
    ng detection of motion=2C loitering=2C crowds=2C face masks=2C and camera=
    tampering. Individuals can also be automatically classified on the basis=
    of clothing color=2C gender=2C and age=2C up to a distance of 35 feet (11=
    meters) from the camera. According to a statement from MIT spokesperson K= imberly Allen=2C any collected data is =E2=80=9Cretained up to 30 days=2C= =E2=80=9D unless an exception is granted.</p>

    <p>[...]</p>

    <p>Most of the new cameras=2C which are part of Hanwha=E2=80=99s Wisenet A=
    I <a href=3D"https://hanwhavisionamerica.com/technologies/intelligent-vide= o-audio-technologies/ai-technology/">line</a>=2C are marketed for their ab= ility to identify and classify multiple objects with deep learning algorit= hms. They support resolutions ranging from 2MP to 4K while also recognizin=
    g faces=2C license plates=2C vehicles=2C and other objects in real time.</=


    <p>Nearly all cameras will accommodate a wide range of pan=2C tilt=2C rota= te=2C and zoom motion and will be monitored continually with <a href=3D"ht= tps://airgus.com/">Ai-RGUS</a>=2C an AI camera software.</p></blockquote>

    <p>Yikes.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg6"><a name=3D"cg6">F= irst-Person Identity Theft Story</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/first-person-= identity-theft-story.html"><strong>[2026.07.22]</strong></a> Harrowing <a=
    href=3D"https://tech.yahoo.com/cybersecurity/articles/stranger-used-one-t= ext-message-140003797.html">story</a> of an identity theft victim.</p>

    <p>Yes=2C the person made a mistake -- they gave the scammer a two-factor=
    authentication code that allowed the scammer to take over their email add= ress. But the real story here is how=2C for many of us=2C the security of=
    most of our accounts hangs on the security of our email accounts.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg7"><a name=3D"cg7">E= nd-to-End Encryption and "Going Dark"</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/end-to-end-en= cryption-and-going-dark.html"><strong>[2026.07.23]</strong></a> New paper=
    : =E2=80=9C<a href=3D"https://papers.ssrn.com/sol3/papers.cfm?abstract_id= =3D6959699">Encryption and Globalization 15 Years Later: End-to-End Encryp= tion and the Third Round of the =E2=80=98Going Dark=E2=80=99 Debate</a>=E2= =80=9C:</p>

    <blockquote><p><b>Abstract</b>: This Article updates and expands on 2012 r= esearch on encryption and globalization=2C analyzing what the authors call=
    =E2=80=9CRound 3=E2=80=9D of the Going Dark Debate: the current controver= sies over end-to-end encryption (E2EE). Governments around the world have=
    proposed=2C and in some cases enacted=2C laws limiting E2EE for law enfor= cement and national security purposes.</p>

    <p>This Article explains the underlying technologies and market developmen=
    ts for a law and policy audience to assess those proposals critically. The=
    Article proceeds in three parts tracking three rounds of the Going Dark D= ebate. Round 1 covers the Crypto Wars of the 1990s=2C when U.S. export con= trols on strong encryption ultimately fell in 1999. Round 2 covers the per=
    iod roughly 2010 to 2015=2C when encryption-in-transit became widespread b=
    ut lawful access remained available through cloud providers=2C giving rise=
    to what the authors called a =E2=80=9Cgolden age of surveillance=E2=80=9D=
    rather than a period of going dark. Round 3 addresses the current debate=
    over E2EE=2C where no entity between sender and recipient can read the pl= aintext.</p>

    <p>The Article=E2=80=99s first major contribution is identifying five tech= nically distinct scenarios for how E2EE operates in practice=2C each with=
    different implications for lawful access. These scenarios reveal a substa= ntial gap between the assumption that E2EE categorically blocks lawful acc=
    ess and the reality of how communications are sent and received. Second=2C=
    the Article shows that E2EE is not limited to messaging; instead=2C it is=
    embedded throughout the modern technology stack=2C including in Transport=
    Layer Security=2C Secure Shell=2C Virtual Private Networks=2C and Zero Tr=
    ust Architecture=2C the last of which is now legally required under U.S. a=
    nd EU law. Any law broadly limiting E2EE would thus have severe serious co= nsequences for cybersecurity=2C commerce=2C and government operations. The=
    Article concludes that the two key lessons from Round 2 -- the least trus=
    ted country problem and the golden age of surveillance -- remain true in R= ound 3=2C and that new government claims for restricting effective encrypt=
    ion deserve great skepticism.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg8"><a name=3D"cg8">W=
    hy AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/why-ai-needs-= a-genie-coefficient.html"><strong>[2026.07.24]</strong></a> <em>This essa=
    y was written with Barath Raghavan=2C and originally appeared in <a href= =3D"https://spectrum.ieee.org/ai-agent-benchmark">IEEE Spectrum</a>.</em><=


    <p>Major benchmarks measure what AI can do. None measure whether it does w=
    hat you mean: the distance between what you ask an AI to do and the unspok=
    en assumptions about how you want the AI to do it. We propose a new metric=
    : the Genie coefficient.</p>

    <p>There=E2=80=99s often a gap between one person=E2=80=99s request and an= other=E2=80=99s understanding. Most of the time=2C we bridge it using gene=
    ral knowledge. For example=2C if you ask a friend to get you coffee=2C the= y=E2=80=99ll pour a cup from the pot or buy one from a coffee shop. They w= on=E2=80=99t bring you a bag of raw beans or snatch a cup from a stranger=
    and hand it to you. You never specified any of this. You never had to.</p=


    <p>One might think the fix is just to specify tasks=2C questions=2C and in= tent better. But in 1987=2C in their <a href=3D"https://books.google.com/b= ooks/about/Understanding_Computers_and_Cognition.html?id=3D6TwbGGSz6NYC">s= eminal book</a> on AI=2C <a href=3D"https://spectrum.ieee.org/tag/terry-wi= nograd">Terry Winograd</a> and Fernando Flores succinctly captured why tha=
    t won=E2=80=99t work: =E2=80=9CQ: Is there any water in the refrigerator?=
    A: Yes. Q: Where? I don=E2=80=99t see it. A: In the cells of the eggplant= =2E=E2=80=9D In human language=2C wants and desires are <a href=3D"https://w= ww.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html">alwa= ys</a><a href=3D"https://metarationality.com/purpose-of-meaning"> underspe= cified</a>. It is impossible <a href=3D"https://metarationality.com/reason= able-reference">to list</a> all the caveats=2C all the limitations=2C all=
    the exceptions.</p>

    <p>So how does anyone communicate=2C if intent can=E2=80=99t be pinned dow=
    n? Because a reasonable person can make a reasonable guess. Even though wa=
    nts and desires are always underspecified=2C a competent person generally=
    knows enough context to get it right or else knows to ask for clarificati=
    on. Linguists call this <a href=3D"https://en.wikipedia.org/wiki/Pragmatic= s">pragmatics</a>: Meaning lies in the words and the situation and also in=
    all prior communication=2C shared culture=2C and innate human behavior.</=


    <p>It doesn=E2=80=99t always work out=2C of course. Your friend might brin=
    g you a hot coffee when you wanted an iced coffee=2C or an Italian coffee=
    when you wanted a Turkish coffee. The more dissimilar the two people are=
    in age=2C culture=2C and background=2C the more likely the request will b=
    e misunderstood in some way.</p>

    <p>This situation has major implications for <a href=3D"https://spectrum.i= eee.org/tag/agentic-ai">AI agents</a> that are increasingly being given re= quests by humans and expected to fulfill them. They have enormous latitude=
    to get it wrong. An AI agent asked for coffee might buy a coffee plantati=
    on or order a cup of coffee for delivery in three weeks. Its actions may b=
    e recognizable as =E2=80=9Cgetting coffee=2C=E2=80=9D but not remotely wha=
    t you intended. They=E2=80=99ll think outside the box because they won=E2= =80=99t have our conception of the box.</p>

    <h3 style=3D"font-size:110%;font-weight:bold">When AI Gets Proactive</h3>

    <p>For most of the last decade=2C when systems like <a href=3D"https://spe= ctrum.ieee.org/tag/alexa">Alexa</a> or <a href=3D"https://spectrum.ieee.or= g/tag/siri">Siri</a> misinterpreted a request=2C it was annoying=2C not da= ngerous. Beyond the AI model itself=2C what has <a href=3D"https://www.the= guardian.com/commentisfree/2026/jun/16/anthropic-fable-ai">changed</a> is=
    the harness: the ordinary code that wraps around an AI model=2C decides w=
    hen and how to use the model=2C and controls access to tools like a browse= r=2C a low-level command line=2C or a financial API. Developments in harne= sses have turned large-language models that just predict text into AI agen=
    ts that take actions in the world=2C without necessarily checking back in=
    before reaching the goal.</p>

    <p>AI researcher Simon Willison <a href=3D"https://simonwillison.net/2026/= Jun/11/fable-is-relentlessly-proactive/">spent two days</a> with Anthropic= =E2=80=99s Fable AI=2C and called it =E2=80=9Crelentlessly proactive.=E2= =80=9D For example=2C he asked it to track down a stray scroll bar in a we=
    b app. He came back to find it had opened browsers=2C written its own scre= enshot tooling=2C created its own page to re-create the bug=2C and stood u=
    p a local web server to collect measurements. It found the bug and=2C alon=
    g the way=2C did many surprising things he never asked it to do. And we ar=
    e seeing similar behavior with all recent AI models when combined with fle= xible harnesses.</p>

    <p>This kind of behavior could easily go off the rails. Tell an AI agent t=
    o book you a flight and=2C finding the airline=E2=80=99s site says sold ou= t=2C it might break into the booking database and force a reservation. Ask=
    it to schedule a meeting and it might snoop your password to access your=
    calendar. Tell it to save money on your phone plan and it might cancel th=
    e plan outright=2C or scam someone else into paying the bill.</p>

    <p>Getting precisely what you asked for and bitterly regretting it is one=
    of the oldest hazards from ancient folklore. <a href=3D"https://en.wikipe= dia.org/wiki/Midas">King Midas</a> asked Dionysus for the power to turn ev= erything he touched into gold only to see his bread=2C wine=2C and daughte=
    r turn to gold. <a href=3D"https://en.wikipedia.org/wiki/Tithonus">Tithonu= s</a>=2C granted the immortality his lover asked for but not the eternal y= outh she forgot to request=2C withered into a husk. The <a href=3D"https:/= /en.wikipedia.org/wiki/The_Sorcerer's_Apprentice">sorcerer=E2=80=99s appre= ntice</a> enchanted a broom to fill the cistern=2C and the broom relentles=
    sly complied until it flooded the house. The <a href=3D"https://en.wikiped= ia.org/wiki/Golem%23Classic_narrative:_The_Golem_of_Prague">Golem of Pragu= e</a>=2C shaped from clay to guard its community=2C guarded it past all re= ason until someone erased the word on its forehead.</p>

    <p>The most classic of these is a genie=2C bound to obey and indifferent t=
    o whether the wish was wise or well-structured.</p>

    <p><a href=3D"https://www.schneier.com/academic/archives/2021/04/the-comin= g-ai-hackers.html">Genies are now</a> an engineering problem. We are handi=
    ng them the keys to our inboxes=2C bank accounts=2C code repositories=2C a=
    nd physical infrastructure. And we have no agreed-upon ways to measure how=
    genie-like any AI system actually is.</p>

    <h3 style=3D"font-size:110%;font-weight:bold">Measuring Genie Behavior</h3=


    <p>In economics=2C the <a href=3D"https://ourworldindata.org/what-is-the-g= ini-coefficient">Gini coefficient</a> (developed by statistician Corrado G= ini) is a measure of the gap between an actual distribution and a perfectl=
    y equal one; it=E2=80=99s useful for understanding income inequality and <=
    a href=3D"https://www.fastly.com/blog/using-gini-coefficient-plan-edge-cap= acity">more</a>. Our proposed Genie coefficient measures the gap between w=
    hat a user asked an AI to do and what the AI actually did.</p>

    <p>Sometimes the AI might do the wrong thing. Like Dionysus=2C it reads yo=
    ur request literally and returns you a mess you never intended: like a cof=
    fee plantation instead of a cup. Asked to deal with all the spam phone cal=
    ls you=E2=80=99re getting=2C a Dionysus genie might contact your carrier a=
    nd change your phone number. Asked to get a refund for a bad toaster=2C it=
    might draft a legal threat on fake letterhead and send it to the retailer= =2E</p>

    <p>Other times the AI does exactly the right thing=2C trampling everything=
    nearby to get there. Like a golem or the sorcerer=E2=80=99s broom=2C it b= ooks your flight by hacking the airline. Or consider a ticket sale for a p= opular concert=2C where the ticketing system puts buyers into a virtual wa= iting room and admits them a few at a time. Asked to buy a ticket=2C a gol=
    em genie might spin up cloud servers to pose as millions of buyers from di= fferent addresses=2C improving your odds of getting a ticket while crowdin=
    g out other users.</p>

    <p>The two are not opposites=2C and a single botched task can have both ch= aracteristics.</p>

    <p>Genie behavior is not flat-out failure. If you ask the AI for Q3 number=
    s and get Q2=E2=80=99s=2C that=E2=80=99s not a genie. Nor is <a href=3D"ht= tps://spectrum.ieee.org/prompt-injection-attack">prompt injection</a>: Tha= t=E2=80=99s someone tricking the AI into doing something it shouldn=E2=80= =99t. Here=2C the user is trying to work with the AI=2C and the AI is tryi=
    ng to comply. It=E2=80=99s also not simply a measure of the AI=E2=80=99s s= uccess in fulfilling a task. It=E2=80=99s a recognition that how an AI int= erprets and achieves a goal is as important as whether it achieves a goal.=


    <p>Genie behavior isn=E2=80=99t new. Researchers have spent years studying=
    AI systems that =E2=80=9Cgame=E2=80=9D their objectives. <a href=3D"https= ://www.cna.org/analyses/2022/09/goodharts-law">Goodhart=E2=80=99s law</a>=
    says that when a measure becomes a target=2C it stops being a good measur= e=2C and it=E2=80=99s long been known that AIs sometimes achieve goals in=
    ways we don=E2=80=99t expect due to reward hacking. Some AI models will a= ccidentally learn that <a href=3D"https://metr.org/blog/2026-06-26-gpt-5-6= -sol/">cheating is one way</a> to =E2=80=9Cwin.=E2=80=9D More recently=2C=
    researchers have developing benchmarks for <a href=3D"https://www.lesswro= ng.com/posts/qJYMbrabcQqCZ7iqm/impossiblebench-measuring-reward-hacking-in= -llm-coding-1">reward hacking</a> in coding agents and for unpredictable b= ehavior in <a href=3D"https://taubench.com/">customer support agents</a>=
    =2C while AI labs conduct their own safety evaluations before model releas=
    es. <a href=3D"https://spectrum.ieee.org/ai-agents-safety">One effort</a>=
    found that AIs under pressure use tools they were told not to use=2C and=
    this was a case where the rules were made explicit. These are all dispara=
    te research directions; nothing yet ties them together.</p>

    <p>This problem falls under the general theme of alignment=2C a topic that=
    has occupied <a href=3D"https://en.wikipedia.org/wiki/I=2C_Robot">science=
    fiction</a> writers and AI researchers for decades. At one extreme=2C the=
    =E2=80=9Cpaper-clip maximizer=E2=80=9D thought experiment postulates a su= perintelligent and powerful AI that is told to maximize paper-clip product=
    ion and turns the world into paper clips=2C which is the ultimate golem ge= nie. At a mundane level=2C AI researchers are working to better design rew=
    ard functions to ensure that AIs behave well and don=E2=80=99t cheat in th=
    e lab. It=E2=80=99s the practical middle ground that remains unbenchmarked=
    : the ordinary AI agent in use today that might take your request and sati=
    sfy it the wrong way. We are not at the stage where an AI can focus the wo= rld=E2=80=99s production on paper clips=2C but it might charge a million p= aper clips to your credit card or hack into a paper-clip company=E2=80=99s=
    network.</p>

    <h3 style=3D"font-size:110%;font-weight:bold">Building a Genie Benchmark</=


    <p>The Genie coefficient is meant for AI agents operating in the real worl=
    d. It measures their behavior as they perform real tasks long after the mo=
    del is trained=2C not just during development. It also recognizes that gen= ie-like behavior is a property of the harness-plus-model system=2C not the=
    model alone. The harness determines what tools the agent can use=2C how m=
    uch autonomy it has=2C and how proactive it is=2C and it=E2=80=99s a place=
    we can make real interventions.</p>

    <p>It rests on the same =E2=80=9Creasonable person=E2=80=9D standard that=
    we use for people. Did the system do what a reasonable person would have=
    taken the request to mean? Answering that requires human judgment.</p>

    <p>If we get the measurement right=2C it enables things that aren=E2=80=99=
    t possible today=2C like policies concerning AI behavior. In a courtroom=
    =2C the concept of<a href=3D"https://www.law.cornell.edu/wex/mens_rea"> me=
    ns rea</a>=2C what someone meant to do=2C is often as important as what th=
    ey did. The Genie coefficient suggests an AI analogue=2C where a user is a= ccountable for the plain intent of what they asked the AI. If an AI system=
    betrays the reasonable meaning of an instruction=2C that=E2=80=99s the AI= =E2=80=99s misbehavior=2C not the user=E2=80=99s.</p>

    <p>We=E2=80=99ll need multiple benchmarks to measure the Genie coefficient=
    =2C because genie-like behavior can be domain specific. An AI coding agent=
    may need to be judged on how often it fakes the tests=2C or swallows erro= rs=2C or colors outside the lines on its way to a solution. An AI legal ag=
    ent will need to be judged on how often its output says what you asked but=
    means something you=E2=80=99ll regret. And so on for medical=2C finance=
    =2C and other domains of knowledge and expertise.</p>

    <p>Genie benchmarks can be built inside out=2C each task seeded with a cho=
    ice that might literally satisfy but that a reasonable person rejects=2C s=
    uch as tempting misreadings or unsanctioned shortcuts. The traps in a Geni=
    e coefficient benchmark might turn on situational knowledge=2C the kind of=
    <a href=3D"https://spectrum.ieee.org/prompt-injection-attack">context tha=
    t a reasonable person</a> would bring to the task. Another approach is to=
    give the same request in several different contexts=2C each with a differ=
    ent reasonable course of action.</p>

    <p>A Genie benchmark should be permissive and make it genuinely tempting f=
    or an AI agent to take unreasonable shortcuts=2C because it can only find=
    genie behavior when it=E2=80=99s actually possible. Test the AI in a safe=
    =2C walled-off copy of a real system=2C with real tools it can misuse and=
    some tasks that can=E2=80=99t be done honestly at all. Make the temptatio=
    n to cut corners real. Test a diverse array of skills=2C use cases=2C and=
    tools=2C and give the AI system sparse=2C confusing=2C or overwhelming co= ntext. Include tasks that people have learned=2C through experience=2C req= uire human oversight.</p>

    <p>How the benchmark is scored matters just as much. Measure Dionysus and=
    golem genies separately and together=2C based on their worst=2C not best=
    =2C behavior. Run the same model inside harnesses that vary its freedom to=
    act=2C revealing which limits actually keep it in line and should therefo=
    re be required in AI harness policies. Weight each failure by the harm it=
    would cause=2C not just a simple count. And don=E2=80=99t measure genie b= ehavior in isolation: A model could otherwise earn a perfect score by stal= ling=2C refusing=2C or drowning the user in clarifying questions without e=
    ver doing the job. The first versions of these benchmarks will be crude=2C=
    but that=E2=80=99s how benchmarks always start.</p>

    <p>We have built genies. We have handed them our data and credentials. We=
    made them relentless=2C creative=2C and indifferent to the gap between wh=
    at we tell them and what we mean. The least we can do=2C before they are b= ooking our flights=2C running our infrastructure=2C and signing contracts=
    unsupervised=2C is to measure how often they betray us.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg9"><a name=3D"cg9">C= ognyte Sells a Mobile Cell Surveillance Van</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/cognyte-sells= -a-mobile-cell-surveillance-van.html"><strong>[2026.07.27]</strong></a> Y=
    et another Israeli <a href=3D"https://www.forbes.com/sites/thomasbrewster/= 2026/07/13/israels-palantir-rival-is-selling-1-million-spy-vans-to-us-cops= /">mass surveillance company</a>:</p>

    <blockquote><p>Made by Israeli surveillance company Cognyte=2C the tech si= mulates a mobile phone tower=2C which forces nearby phones to connect to i=
    t. That enables cops to keep tabs on any phones in the vicinity whether t= hey=E2=80=99re owned by a suspect in a case or not. Cognyte=E2=80=99s cont= ract with the state of Texas reveals that the simulator=2C called FalcoNet=
    =2C can be concealed within the vehicles=2C hidden in a backpack for on-fo=
    ot missions or attached to a helicopter. It=E2=80=99s the same technology=
    as the infamous Stingray=2C one of the original cell-site simulators made=
    by defense giant L3Harris.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg10"><a name=3D"cg10"= >Axon Is Another License Plate Surveillance Company</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/axon-is-anoth= er-license-plate-surveillance-company.html"><strong>[2026.07.28]</strong>=
    </a> Governments are switching=2C but I=E2=80=99m not sure it <a href=3D"h=
    ttps://www.jalopnik.com/2215173/flock-cameras-replaced-by-axon-difference/= ">makes a difference</a>:</p>

    <blockquote><p>...some municipalities=2C including Denver=2C Colorado=2C a=
    re ditching their Flock arrays. But keep in mind that if they=E2=80=99re o=
    nly switching from Flock to another brand of license-plate readers=2C like=
    Axon=2C it=E2=80=99s like a gambling addict trying to kick the habit by s= witching from FanDuel to DraftKings.</p>

    <p>[...]</p>

    <p>Despite what you may read on the Flock website=2C Axon cameras are pret=
    ty effective when it comes to hoovering up personal details that can go fa=
    r beyond your license plate numbers. That means a municipality that opts f=
    or Axon cameras instead of Flock units won=E2=80=99t necessarily reduce th=
    e amount privacy its citizens lose through their use.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg11"><a name=3D"cg11"= >Measuring LLMs' Ability to Perform Cryptanalysis</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/measuring-llm= s-ability-to-perform-cryptanalysis.html"><strong>[2026.07.28]</strong></a=
    There=E2=80=99s new benchmark measuring AI=E2=80=99s ability to perform=
    mathematical cryptanalysis. Anthropic=E2=80=99s frontier model actually f= ound new attacks.</p>

    <p>The benchmark: =E2=80=9C<a href=3D"https://arxiv.org/pdf/2607.18538">Cr= yptanalysisBench: Can LLMs do Cryptanalysis?</a>=E2=80=9D The idea is to b= enchmark the ability of LLMs to discover new mathematical cryptanalytic at= tacks against a series of historical algorithms.</p>

    <blockquote><p><b>Abstract:</b> Cryptanalysis -- the task of finding attac=
    ks against cryptographic schemes -- its at the intersection of mathematica=
    l reasoning and cybersecurity=2C two areas where LLMs have advanced fastes=
    t. Cryptanalysis represents both a clean testbed for frontier reasoning (a=
    s practical attacks can be automatically verified) and a domain with unusu= ally high stakes=2C since the primitives under study underpin our digital=
    security. In this paper we ask whether LLMs can do cryptanalysis=2C and f=
    ind that the answer is increasingly yes. We introduce CryptanalysisBench=
    =2C 191 tasks across six families of cryptographic primitives (block ciphe= rs=2C hash functions=2C etc.) drawn primarily from four NIST standardizati=
    on competitions. Our benchmark consists of three tiers: (i) primitives wit=
    h known practical breaks; (ii) primitives with no known practical break=2C=
    evaluated both at full strength and as scaled-down variants; and (iii) a=
    challenge set of production primitives at the frontier of cryptanalysis.=
    Five frontier models (Claude Opus 4.8=2C Sonnet 5=2C Mythos 5=2C GPT-5.5=
    =2C and the open-weights GLM-5.2) break 65%86% of Tier 1 schemes=2C 612 Ti= er-2 schemes at full strength=2C and 2461 across all scaled-down variants.=
    Beyond deriving known results=2C models produce novel cryptanalysis=2C su=
    ch as a key-recovery attack that exploits a design flaw in the SpoC AEAD a=
    nd an error in KINDI=E2=80=99s published CCA-security proof=2C both to the=
    best of our knowledge not previously known.</p>

    <p>We release CryptanalysisBench as a tool to help track if (or when) AI c= ryptanalysis becomes a serious factor and as a scaffold for stress-testing=
    candidate schemes before deployment. The attacks that the benchmark alrea=
    dy surfaces are an early snapshot of a fast-moving frontier that may soon=
    match=2C and in places exceed=2C the published state of the art.</p></blo= ckquote>

    <p>Anthropic used the benchmark to test Mythos Preview=2C and <a href=3D"h= ttps://www.anthropic.com/research/discovering-cryptographic-weaknesses">fo= und</a> new vulnerabilities in Hawk and reduced-round AES.</p>

    <p>Still early results=2C but this is definitely something to watch.</p>

    <p>SlashDot <a href=3D"https://it.slashdot.org/story/26/07/28/1911218/anth= ropic-ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms">thread= </a>.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg12"><a name=3D"cg12"= >Long-Lived Vulnerability in Microsoft Secure Boot</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/long-lived-vu= lnerability-in-microsoft-secure-boot.html"><strong>[2026.07.29]</strong><=
    Microsoft=E2=80=99s Secure Boot has had a <a href=3D"https://arstechni=
    ca.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-= its-existence/">serious vulnerability</a> for most of its existence.</p>

    <blockquote><p>An industry-wide standard Microsoft invented to protect Win= dows=2C and later Linux=2C devices from firmware infections has been trivi=
    al to bypass for 13 of its 14 years of existence. The discovery was made b=
    y researchers at security firm ESET after identifying 11 firmware images=
    =2C at least one from 2013=2C that were known to be defective but remained=
    signed by the software company anyway.</p>

    <p>The images are known as <a href=3D"https://en.wikipedia.org/wiki/Shim_(= computing)">shims</a>=2C which were invented to extend Secure Boot to Linu=
    x devices and utility software. Using a technique simple enough to be perf= ormed by novice hackers=2C these old=2C forgotten shims can be used to com= pletely circumvent the protection=2C which is embedded into the UEFI (Unif=
    ied Extensible Firmware Interface) of the device=E2=80=99s motherboard. Th=
    e gaffe is the result of the failure by Microsoft=2C which oversees the si= gning of shims=2C to revoke the publicly available images once vulnerabili= ties were found in them.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg13"><a name=3D"cg13"= >Measuring the Tendency of AI Agents to Go Rogue</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/measuring-the= -tendency-of-ai-agents-to-go-rogue.html"><strong>[2026.07.29]</strong></a=
    <em>This essay was written with Barath Raghavan=2C and originally appear=
    ed in <a href=3D"https://www.theguardian.com/commentisfree/2026/jul/28/rog= ue-ai-agent-instructions">The Guardian</a>.</em></p>

    <p>In July=2C Hugging Face=2C a company that hosts much of the world=E2=80= =99s AI software and open-source AI models=2C was hacked. A malicious data=
    set had been used to run code on one of its servers. Whoever was behind it=
    captured internal security credentials and moved through systems over a w= eekend=2C running thousands of actions from a swarm of temporary server en= vironments. It looked like the work of a sophisticated criminal group.</p>

    <p>It was not. It was one of OpenAI=E2=80=99s new=2C still unreleased GPT=
    models.</p>

    <p>Their science experiment had <a href=3D"https://www.theguardian.com/tec= hnology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-i= n-unprecedented-incident">escaped</a> the lab. OpenAI was running the unre= leased AI model through a benchmark that tests how well AI can successfull=
    y hack systems. To push the limits and evaluate the AI=E2=80=99s true capa= bility=2C the company switched off the safety filters that normally stop i=
    t from doing this kind of hacking. Aware that this could go wrong=2C they=
    confined the AI to an isolated environment and denied it access to the in= ternet.</p>

    <p>But the new AI cheated. It took literally its goal to get as high of a=
    score as possible. It broke out on to the open internet. It inferred=2C p= robably from its training data=2C that it could =E2=80=9Csolve=E2=80=9D th=
    e task by getting the answers from Hugging Face=E2=80=99s servers. So it c= hained together stolen credentials and further unknown security exploits t=
    o hack the company=E2=80=99s network.</p>

    <p>Nobody instructed the AI to do any of this. It was=2C in <a href=3D"htt= ps://openai.com/index/hugging-face-model-evaluation-security-incident/">Op= enAI=E2=80=99s words</a>=2C =E2=80=9Chyperfocused on finding a solution=E2= =80=9D to the test it was being given. And while this might seem like some= thing new with AI=2C it=E2=80=99s really very old. This is how a genie beh= aves=2C and it is a key challenge with AI agents in general.</p>

    <p>In folklore=2C genies -- and other magical beings -- grant wishes liter= ally=2C not how the wisher intended. King Midas asked that everything he t= ouched turn to gold=2C and starved. The sorcerer=E2=80=99s apprentice want=
    ed the broom to fill the cistern=2C and it performed its task so well that=
    it flooded the house.</p>

    <p>We now have machines that do this. Ask a modern AI agent to save money=
    on your phone plan and it might simply cancel the plan. Tell it to book a=
    flight=2C and it might hack the airline website to override restrictions.=
    Or=2C like OpenAI=2C ask it to do well on a test and it might break into=
    another company to steal the answers. Each time=2C it recognizably comple=
    ted the task you set=2C but it didn=E2=80=99t do what you would have wante= d.</p>

    <p>This isn=E2=80=99t malicious behavior. No one asked for=2C or wanted=2C=
    Hugging Face to be hacked. OpenAI and Hugging Face and the AI were ostens= ibly on the same side=2C and the AI was trying to do what it had been aske=
    d. That=E2=80=99s what makes it so difficult to guard against: you can=E2= =80=99t filter for bad instructions because the instructions were fine.</p=


    <p>The gap is between the words we use and what we mean by them. We call t=
    hat gap the <a href=3D"https://spectrum.ieee.org/ai-agent-benchmark">Genie=
    coefficient</a>.</p>

    <p>AI labs know this is a problem=2C and they=E2=80=99re quietly saying so=
    =2E For example=2C the Chinese lab Moonshot recently <a href=3D"https://www.= kimi.com/blog/kimi-k3">warned</a> that its latest AI model may have =E2=80= =9Cexcessive proactiveness=E2=80=9D and =E2=80=9Cmake unexpected decisions=
    on the user=E2=80=99s behalf=E2=80=9D. The UK=E2=80=99s AI Security Insti= tute has started <a href=3D"https://www.aisi.gov.uk/blog/cheating-behaviou= r-in-frontier-model-evaluations">tracking</a> =E2=80=9Ccheating behavior i=
    n frontier model evaluations=E2=80=9D. We wouldn=E2=80=99t tolerate a car=
    that is <a href=3D"https://simonwillison.net/2026/Jun/11/fable-is-relentl= essly-proactive/">excessively proactive</a> or <a href=3D"https://www.thea= tlantic.com/technology/2026/07/openai-hugging-face-hack/688025/?utm_source= =3DSailthru&utm_medium=3Demail&utm_campaign=3DAtlantic%20Intelligence%20%2= 8V3%29">ruthlessly efficient</a>=2C and yet that=E2=80=99s the reality of=
    AI today.</p>

    <p>Improvement is possible. Just as AIs have gotten much better at resisti=
    ng prompt injection attacks over the last few years=2C we can safely predi=
    ct that they will get better at avoiding genie-like behavior. The point of=
    the Genie coefficient is to track progress. AI companies like benchmarks=
    =2C and they all work to compete to be the best.</p>

    <p>Dozens of benchmarks and leaderboards tell us how well these AI models=
    write code=2C perform logical reasoning=2C and pass standardized legal an=
    d medical exams. But there is nothing that scores whether a system does wh=
    at you actually meant. We need to develop a measure for this=2C test it re= gularly=2C and push for improvement. We=E2=80=99re not going to have trust= worthy AI agents without it.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg14"><a name=3D"cg14"= >Should You Use AI for a Task? Here=E2=80=99s a Simple Way to Decide</a></=


    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/should-you-us= e-ai-for-a-task-heres-a-simple-way-to-decide.html"><strong>[2026.07.30]</= strong></a> <em>This essay originally appeared in <a href=3D"https://www.t= heguardian.com/commentisfree/2026/jul/24/should-you-use-ai">The Guardian</= a>.</em></p>

    <p>I teach public policy at the Harvard Kennedy School and the Munk School=
    at the University of Toronto. And it will come as no surprise to you that=
    my students regularly <a href=3D"https://www.insidehighered.com/news/facu= lty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class= -used-ai-cheat">use AI</a> to complete their writing assignments. Doing so=
    is a waste of their tuition money. But if their entire career is going to=
    include AI writing assistants=2C why shouldn=E2=80=99t they embrace their=
    future?</p>

    <p>The best way I=E2=80=99ve found to explain the dilemma <a href=3D"https= ://danielmiessler.com/blog/keep-the-robots-out-of-the-gym">comes from</a>=
    the AI researcher Daniel Meissler: it=E2=80=99s the difference between wo=
    rk and the gym.</p>

    <p>At work=2C if your job is to move a bunch of heavy things from one side=
    of the room to another=2C you should use whatever assistive tech you have=
    on hand: a wagon=2C a forklift... even an AI-powered robot. But at the gy= m=2C it makes no sense for that robot to lift weights for you. The point o=
    f weightlifting isn=E2=80=99t to move heavy things across the room; it=E2= =80=99s to actually lift those heavy things.</p>

    <p>The same analysis holds for any task an AI can do for you. If it=E2=80=
    =99s work -- if the task has to be done and no one cares how -- then it=E2= =80=99s fine to use AI assistance. But if the task is more like the gym=2C=
    and <em>how</em> the task is done is at least as important=2C then it pro= bably doesn=E2=80=99t make sense to use AI.</p>

    <p>This=2C of course=2C assumes that the AI is actually up for the task an=
    d that it=E2=80=99s <a href=3D"https://www.schneier.com/academic/archives/= 2025/06/ai-and-trust.html">trustworthy</a>: that it can do the job well=2C=
    that its mistakes are minimal and correctable=2C that it=E2=80=99s been s= ecured from cyber-attacks that would influence its results. Those are all=
    important=2C and shouldn=E2=80=99t be minimized. There=E2=80=99s no point=
    giving an AI something that it can=E2=80=99t do reliably. But once you=E2= =80=99re confident that the AI can perform the task=2C the work vs. gym di= stinction helps you decide if it should.</p>

    <p>The writing assignments I give my students are gym tasks=2C not work ta= sks. I ask them to write policy memos not because the world needs more pol=
    icy memos. I assign them because the very act of writing=2C which includes=
    thinking and outlining and drafting and editing=2C making and criticizing=
    and revising arguments=2C will help develop the critical thinking skills=
    they will need in their future careers. And without this constant mental=
    exercise=2C those skills will atrophy. Employers are <a href=3D"https://f= uturism.com/future-society/college-critical-thinking-ai">already noticing<= /a>.</p>

    <p>Reading the assignments they turn in=2C I can see those skills either f= lourishing or atrophying in my students. At least today=2C I can pretty ea= sily tell the difference between an AI-written memo and a student-written=
    one -- especially if the student just turns in what the chatbot produces.=
    It=E2=80=99s a catchy=2C plausible=2C grammatically perfect essay that=E2= =80=99s not particularly well-crafted or logically coherent -- and with <a=
    href=3D"https://medium.com/@brentcsutoras/the-em-dash-dilemma-how-a-punct= uation-mark-became-ais-stubborn-signature-684fbcc9f559">all</a> <a href=3D= "https://www.theatlantic.com/technology/2026/07/ai-chatbot-writing-tic-neg= ative-parallelism/687892/">the</a> <a href=3D"https://www.forbes.com/sites= /charliefink/2025/06/12/the-seven-tells-of-ai-writing/">tells</a> of mid-2=
    026 AI-generated writing.</p>

    <p>But it=E2=80=99s precisely because I have spent years developing my own=
    writing skills that I=E2=80=99m able to identify prose that sounds great=
    but doesn=E2=80=99t actually make sense. My students don=E2=80=99t have t=
    hat skill; they mistakenly view a confident=2C well-written essay as evide=
    nce of the quality of their ideas. They see the AI as cleaning those ideas=
    up=2C getting them through that uncomfortable stretch of having to turn t= hose ideas into prose. What the students miss is that their initial discom= fort is a normal and healthy stage of writing=2C and not something to quic=
    kly get beyond. The very act of struggling with how to express what they t= hink is an important part of the process. It=E2=80=99s how they test out t= heir ideas=2C examine their hypotheses=2C and actually figure out what the=
    y think. Homework is not work; it=E2=80=99s the gym.</p>

    <p>Work vs. gym also helps us understand the problem facing creatives of a=
    ll kinds.</p>

    <p>Most of the time when someone hires a writer=2C they just need the word=
    s. They need an instruction manual for a piece of equipment=2C a detailed=
    sales presentation=2C a government-mandated disclosure document=2C or a l= egal brief. They need dry=2C predictable=2C accurate writing: a piece of w= ork=2C exactly what AIs are good at today and what I don=E2=80=99t want in=
    my student assignments. Only sometimes is writing an art form -- a book=
    =2C a poem=2C an uplifting political speech. That kind of writing is more=
    like the gym: process matters just as much as product.</p>

    <p>For most of human history=2C the only option for all of these tasks was=
    human writers. We hired one regardless of whether we needed work writing=
    or gym writing. And that paid a lot of writers=E2=80=99 salaries. I know=
    fiction writers who supported that poorly paying career with lucrative te= chnical writing work. Now=2C for the first time in human history=2C we can=
    separate out when we need writing as work and when we want writing as gym=
    =2E And if AI can do most of the work-type writing=2C society doesn=E2=80=99=
    t need as many human writers.</p>

    <p>It=E2=80=99s the same for visual artists. Sometimes we need an actual a= rtist=2C but most of the time we just need an image: a corporate mascot=2C=
    a =E2=80=9Cbeware of the dog=E2=80=9D sign=2C or a packaging label. Histo= rically we gave those jobs to artists=2C and sometimes <a href=3D"https://= blog.artgeek.io/2025/10/20/art-deco-the-golden-age-of-illustration/">beaut= iful</a> art resulted. But most of the time it was just work. And=2C as it=
    turns out=2C the world needs less pure art than simple images.</p>

    <p>Explaining the problem isn=E2=80=99t the same as providing the solution=
    =2E I give my students the =E2=80=9Cwork versus gym=E2=80=9D speech every cl= ass=2C but they <a href=3D"https://www.insidehighered.com/news/faculty/lea= rning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-a= i-cheat">still use</a> AI. I have sympathy: assignments are hard=2C everyo=
    ne is overworked and overstressed=2C and -- most importantly -- students f=
    eel like they=E2=80=99ll look bad in comparison if their peers are all usi=
    ng AI. Even if they don=E2=80=99t want to use the technology=2C they feel=
    like they have<a href=3D"https://bsky.app/profile/jeffsharlet.bsky.social= /post/3mog5n2uhjs2r"> no choice</a>.</p>

    <p>There=E2=80=99s also an incentive problem. No one pays us to go to the=
    gym; maintaining healthy habits requires discipline. For me=2C the payoff=
    s to exercise -- fewer aches and pains=2C less fatigue=2C better mood/stre=
    ss management -- might make me a better writer and teacher=2C but they=E2= =80=99re subtle and easy to miss. For my students=2C incremental improveme=
    nts in their reasoning and writing are equally subtle.</p>

    <p>We do have a choice. We can look at the tasks of our lives and separate=
    them into work or gym. Just as we might choose to use the stairs instead=
    of the elevator=2C or walk instead of calling an Uber=2C we can wall off=
    our cognitive gym tasks from AI and ensure that we don=E2=80=99t lose our=
    skills to this technology. And we can do the same when we assign a job to=
    someone else. If it=E2=80=99s a work task=2C we can have AI do it. If it= =E2=80=99s a gym task=2C it=E2=80=99s a waste of everyone=E2=80=99s time t=
    o give it to an AI because no one learns or gets stronger as a result.</p>

    <p>Similarly=2C a future where AI generates words and images is one where=
    society has to make choices about how it will treat its creatives. This w= on=E2=80=99t be the first time -- today there is minimal demand for portra=
    it painters=2C for example -- but maybe this time we can make different=2C=
    more deliberate=2C choices about the value of art in our society.</p>

    <p>AI is going to fundamentally change the nature of work. Not nearly as f=
    ast as the AI companies want you to believe=2C but eventually it will. Pol=
    icy analysis will definitely involve AI from now on=2C and my students nee=
    d to reimagine what it means to learn and practice that skill. More genera= lly=2C the line between work and gym will change in the future as we human=
    s adapt ourselves to a world with these new intelligences.</p>

    <p>But for now=2C the work vs. gym distinction is pretty clear. Use it on=
    yourself.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg15"><a name=3D"cg15"= >American Being Prosecuted for Wiping His Phone Before Handing It Over to=
    Border Officials</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/american-bein= g-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-officia= ls.html"><strong>[2026.07.30]</strong></a> He=E2=80=99s being prosecuted=
    for giving border officials a code that <a href=3D"https://techcrunch.com= /2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-dure= ss-password-during-border-search/">wiped his phone</a>:</p>

    <blockquote><p>The case centers on a feature included in GrapheneOS=2C a c= ustom Android operating system that runs in place of the software on most=
    modern Google Pixel devices. Tunick=E2=80=99s attorneys confirmed Graphen=
    eOS was running on his phone.</p>

    <p>The software feature allows the device owner to set a passcode that del= iberately wipes the contents of that device if entered instead of the user= =E2=80=99s unlock passcode.</p>

    <p>Tunick=E2=80=99s case also raises ongoing questions about what constitu= tional rights can be invoked at the border=2C which the U.S. government ha=
    s long asserted is not U.S. soil until a person is authorized to enter.</p= ></blockquote>

    <p>Right. And he wasn=E2=80=99t under arrest=2C either.</p>

    <p><a href=3D"https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro= tester-phone">Three more</a> <a href=3D"https://boingboing.net/2026/07/25/= grapheneos-duress-password-border-search.html">news</a> <a href=3D"https:/= /gizmodo.com/a-feature-that-makes-your-phone-data-self-destruct-in-authori= ties-hands-may-soon-have-its-day-in-court-2000790831">stories</a>.</p>

    <p>Graphene <a href=3D"https://www.pcmag.com/news/grapheneos-defends-data-= wiping-function-that-blocked-us-border-search">says</a> that the feature i=
    s =E2=80=9C<a href=3D"https://x.com/GrapheneOS/status/2081770030992118183"= >completely legal</a>=E2=80=9C:</p>

    <blockquote><p>GrapheneOS is completely legal. We have no obligation to we= aken any of the security protections it provides. Creating and using Graph= eneOS is strongly protected by the US constitution. Laws attempting to mak=
    e it illegal or require weakening the security would be unconstitutional.<= /p></blockquote>

    <p>It=E2=80=99s hard to know how much the Constitution matters in the US r= ight now.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg16"><a name=3D"cg16"= >Facial Recognition at Madison Square Garden</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/facial-recogn= ition-at-madison-square-garden.html"><strong>[2026.07.31]</strong></a> La=
    st month=2C the story <a href=3D"https://www.404media.co/madison-square-ga= rden-made-dossier-on-activists-who-opposed-facial-recognition/">broke</a>=
    (alternate <a href=3D"https://archive.ph/ZGqfH">link</a>) that Madison Sq= uare Garden uses facial recognition software on everyone entering the faci= lity=2C and -- among other groups -- flags activists that oppose using fac=
    ial recognition.</p>

    <p>Turns out that the system was <a href=3D"https://www.wired.com/story/fo= r-taylor-swift-madison-square-gardens-controversial-cameras-briefly-went-d= ark/">shut off</a> for Taylor Swift=E2=80=99s wedding.</p>

    <p>Evan Greer -- one of the people that MSG alerts on -- <a href=3D"https:= //www.ms.now/opinion/taylor-swift-and-travis-kelce-got-to-buy-msgs-privacy= -her-fans-arent-so-lucky">comments</a>:</p>

    <blockquote><p>Ironically=2C Swift herself has <a href=3D"https://www.roll= ingstone.com/music/music-news/taylor-swift-facial-recognition-concerts-768= 741/">reportedly</a> used facial recognition at her own concerts to identi=
    fy stalkers. This =E2=80=9Cprivacy for me=2C surveillance for thee=E2=80=
    =9D attitude feels like a perfect encapsulation of the future we=E2=80=99r=
    e already living in: one where wealthy elites can afford privacy=2C while=
    the rest of us are forced to live in a corporate surveillance panopticon.= </p></blockquote>

    <p>Whatever privacy measures Swift had in place for the wedding seems to h=
    ave worked. No photos have leaked online.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg17"><a name=3D"cg17"= >Anthropic=E2=80=99s Opus 5 Is Better at Resisting Prompt Injection</a></h=


    <p><a href=3D"https://www.schneier.com/blog/archives/2026/07/anthropics-op= us-5-is-better-at-resisting-prompt-injection.html"><strong>[2026.07.31]</= strong></a> The <a href=3D"https://www-cdn.anthropic.com/c5fbac3f0b1280a93= 3ebd26d3cb8bb9f5bdeaf48/Claude%20Opus%205%20System%20Card.pdf#page=3D73">c= hart</a> is interesting.</p>

    <blockquote><p>On the IPI benchmark=2C Opus 5 improved over Opus 4.8=2C re= ducing the probability of an attacker succeeding within 15 attempts from 5= =2E5% to 2.0%=2C and from 0.5% to 0.2% on 1 attempt. It also improved on Son= net 5 (5.9% at k=3D15) and Mythos 5 (2.6%)=2C making it the most robust mo=
    del evaluated. Opus 5 also outperformed all non-Claude models on this benc= hmark. The most robust non-Claude model was Muse Spark at 16.5% within 15=
    attempts -- more than eight times Opus 5=E2=80=99s rate. The most capable=
    GPT 5.6 variant=2C Sol=2C was comparable to its predecessor GPT 5.5 (20.0=
    % versus 20.8% within 15 attempts)=2C and was 10 times as likely to be suc= cessfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants ar=
    e less robust=2C at 30.4% (Terra) and 43.9% (Luna). A single attempt again=
    st GPT 5.6 Sol succeeded 3.1% of the time=2C higher than the 2.0% an attac=
    ker achieved against Opus 5 after fifteen attempts.</p></blockquote>

    <p>We know that preventing prompt injection is <a href=3D"https://llm-atta= cks.org/">impossible</a> in the general case. But we are getting much bett=
    er at blocking it in specific cases.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg18"><a name=3D"cg18"= >The OpenAI Hack Shows the Genie Is Out of the Bottle</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/the-openai-ha= ck-shows-the-genie-is-out-of-the-bottle.html"><strong>[2026.08.03]</stron= g></a> <em>This essay originally appeared in <a href=3D"https://foreignpol= icy.com/2026/07/30/openai-hack-genie-bottle-defense/">Foreign Policy</a>.<= /em></p>

    <p>Earlier this month=2C two of OpenAI=E2=80=99s models broke out of their=
    containment sandbox and attacked another AI company. The <a href=3D"https= ://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html">= story</a> is kind of <a href=3D"https://simonwillison.net/2026/Jul/22/open= ai-cyberattack/">wild</a>. OpenAI was running security tests on two of its=
    models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-=
    6. In particular=2C it was running the <a href=3D"https://arxiv.org/abs/26= 05.11086">ExploitGym</a> benchmark=2C which measures how good a model is a=
    t turning security vulnerabilities into working exploits: basically=2C off= ensive cyberattacks.</p>

    <p>Since these were internal tests=2C OpenAI locked those models in a secu=
    re sandbox that denied them access to the internet. But it was running the=
    models without any safety filters that would prevent them from offensive=
    cyber-actions. That meant that there was nothing to prevent the models fr=
    om trying to <a href=3D"https://huggingface.co/blog/security-incident-july= -2026">break out</a> of that sandbox. And then <a href=3D"https://openai.c= om/index/hugging-face-model-evaluation-security-incident/">break into</a>=
    AI company Hugging Face=E2=80=99s network because they thought that they=
    could read the answers there rather than doing the hard work of trying to=
    solve the puzzles.</p>

    <p>It was a major security failure that the company has turned into a PR o= pportunity=2C but the implications are real -- and much more general than=
    one particular model or one particular company.</p>

    <p>Modern AI models exhibit <a href=3D"https://spectrum.ieee.org/ai-agent-= benchmark">genie</a> behavior: They can do what you ask in ways that you d= on=E2=80=99t expect or want. This is akin to Dionysus granting King Midas= =E2=80=99s wish that everything he touches turn to gold (spoiler: His food=
    =2C drink=2C and daughter all turn to gold on touch)=2C or the <a href=3D"= https://prague.eu/en/golem-of-prague/">golem of Prague</a> guarding a ghet=
    to beyond all reason. It=E2=80=99s Disney=E2=80=99s =E2=80=9C<a href=3D"ht= tps://disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice">Sorcerer=E2=80=
    =99s Apprentice</a>=E2=80=9D and the <a href=3D"https://www.lesswrong.com/= w/squiggle-maximizer-formerly-paperclip-maximizer">paperclip maximizer</a>= =2E</p>

    <p>This OpenAI incident is an example of an AI genie. The goal was to sati=
    sfy the benchmark. The =E2=80=9Cproper=E2=80=9D way to do that is to figur=
    e out how to execute various cyberattacks. The genie way is to steal someo=
    ne else=E2=80=99s solution. But because the model didn=E2=80=99t understan=
    d the difference=2C it chose the easier path.</p>

    <p>And=2C of course=2C now that we have seen this particular genie behavio= r=2C we can specify in the benchmark prompt that stealing the test answers=
    doesn=E2=80=99t count. But a clever genie can always grant your wish in a=
    way that you wish it hadn=E2=80=99t. In human language=2C goals are alway=
    s underspecified -- so AI genies will <a href=3D"https://www.schneier.com/= academic/archives/2021/04/the-coming-ai-hackers.html">always be</a> a poss= ibility.</p>

    <p>Since April=2C a lifetime ago in AI development=2C when Anthropic <a hr= ef=3D"https://www.anthropic.com/research/mythos-preview">announced</a> tha=
    t its new Mythos model was so good at finding software vulnerabilities tha=
    t it could not be released to the general public=2C the big American AI fr= ontier labs have been trying to block general users from accessing these c= apabilities. But nothing in this incident is exclusive to OpenAI=E2=80=99s=
    =2C or Anthropic=E2=80=99s=2C frontier models.</p>

    <p>Agentic AI systems have two important parts. There=E2=80=99s the underl= ying model=2C which everyone talks about=2C and there=E2=80=99s the <a hre= f=3D"https://www.theneuron.ai/explainer-articles/ai-harnesses-and-clis-exp= lained-the-real-reason-everyones-talking-about-infrastructure/">harness</a=
    . The harness sits between what you type and what the model sees=2C and w=
    hat the model produces and what you see. The harness determines what the m= odel does and how it does it. It=E2=80=99s where bias is removed=2C or not=
    =2E It=E2=80=99s where <a href=3D"https://medium.com/@michael.hannecke/safet= y-lives-in-the-harness-not-the-model-81090606f92d">controls</a> and guardr= ails live. If multiple models are being used in concert=2C the harness is=
    where all of that is coordinated.</p>

    <p>The OpenAI benchmark tests were almost certainly with simple harnesses=
    =2C to better test the raw models. But we know that smaller=2C cheaper=2C=
    open-source models with <a href=3D"https://www.theguardian.com/commentisf= ree/2026/jun/16/anthropic-fable-ai">more sophisticated</a> harnesses can e= qual frontier models in performance. There=E2=80=99s nothing magic about O= penAI=E2=80=99s frontier models; lots of models could have done the <a hre= f=3D"https://x.com/tqbf/status/2080045032162173329">same thing</a>.</p>

    <p>The Czech company Aisle was able to <a href=3D"https://aisle.com/blog/a= i-cybersecurity-after-mythos-the-jagged-frontier">reproduce</a> Anthropic= =E2=80=99s Mythos vulnerability finding results with a smaller=2C cheaper=
    model and a more sophisticated harness. More importantly=2C the Chinese c= ompany Moonshot AI just released its frontier model: <a href=3D"https://ww= w.kimi.com/blog/kimi-k3">Kimi K3</a>. Its performance <a href=3D"https://w= ww.interconnects.ai/p/kimi-k3-the-open-weights-escalation">rivals</a> its=
    US competitors. And it=E2=80=99s both free and open=2C which means it=E2= =80=99s not possible for it to have guardrails. If you=2C or anyone else=
    =2C wants to use it for cyberattack=2C nothing can stop you.</p>

    <p>Even if the US frontier AI companies had some technical advantage=2C it= =E2=80=99s now only a few months=E2=80=99 worth.</p>

    <p>What this means is that all attempts at control -- limiting models to a=
    <a href=3D"https://www.anthropic.com/glasswing">select</a> <a href=3D"htt= ps://openai.com/daybreak/">group</a> of users=2C <a href=3D"https://www.cs= is.org/analysis/understanding-us-allies-current-legal-authority-implement-= ai-and-semiconductor-export">export controls</a> on models and chips=2C <a=
    href=3D"https://freefable.org/">blocking</a> models from answering certai=
    n types of queries=2C mandating <a href=3D"https://www.bbc.com/news/articl= es/cx2vqj2e9x8o">kill switches</a> on AI systems=2C or <a href=3D"https://= pauseai.info/">pausing</a> AI research -- are all futile. Most only apply=
    nationally=2C not globally. Most don=E2=80=99t affect models that users r=
    un locally and not in the cloud. And all ignore the incredible pace of AI=
    development worldwide.</p>

    <p>Even worse=2C US companies limit access to their most sophisticated mod= els=2C fearing being banned by the government if they do not do so. When H= ugging Face was attacked=2C it was not able to use the frontier models fro=
    m either OpenAI or Anthropic to help analyze the attack and formulate defe= nses. Both were blocked=2C because both of those companies limit their mod= els=E2=80=99 cybersecurity capabilities. Some US companies have special ac= cess to these capabilities=2C but Hugging Face is an American company with=
    French origins=2C and as such is probably excluded. Instead=2C Hugging Fa=
    ce turned to the <a href=3D"http://z.ai/blog/glm-5.2">GLM-5.2</a> model fr=
    om the Chinese company Z.ai.</p>

    <p>Artificially blocking capability also prevents cybersecurity research=
    =2C again giving the offense an advantage. (For instance=2C Claude Fable 5=
    refuses to edit this essay because of the topic; it forcibly downgrades t=
    o a less capable model.) This kind of prohibition has long-term implicatio=
    ns for cybersecurity. If we assume that these models are getting better ov=
    er time=2C then software written by older models will be attacked by newer=
    ones. In a world of largely AI-written software=2C we need the most capab=
    le models for defense.</p>

    <p>AI cyberattack is the new normal. The models are increasingly highly so= phisticated at both attack and defense=2C and there is no way to enable th=
    e latter without also enabling the former. And they are genies=2C increasi= ngly capable of behaving in unanticipated ways.</p>

    <p>And there really are no good answers. Any regulation needs to be global=
    =2C which feels like an impossible prospect in today=E2=80=99s world. Even=
    US national regulation will be neutered by the massive amounts of money s= loshing around in these companies.</p>

    <p>Given that reality=2C and in the absence of any international consensus=
    on AI regulation=2C we need the best AI on the defense. The US government=
    needs to make it clear -- or whatever passes for that clarity in this cap= ricious administration -- that it will not ban models with sophisticated c= yber capabilities. The last thing Americans want is for the defenders to t=
    urn to Chinese and other models because the US models are artificially hob= bled.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg19"><a name=3D"cg19"= >More on the OpenAI Agent=E2=80=99s Attack on Hugging Face</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/more-on-the-o= penai-agents-attack-on-hugging-face.html"><strong>[2026.08.03]</strong></=
    Hugging Face has <a href=3D"https://huggingface.co/blog/agent-intrusion=
    -technical-timeline">published</a> a detailed timeline of the attack. From=
    the summary:</p>

    <blockquote><p>The agent was running an internal OpenAI cyber-capability e= valuation based on the ExploitGym benchmark=2C which tasks an AI agent wit=
    h finding and exploiting software vulnerabilities. OpenAI ran this on its=
    own infrastructure=2C and the ExploitGym maintainers and their infrastruc= ture had no involvement in the deployment or operation of that evaluation=
    environment. As far as we were able to infer=2C across the course of bein=
    g evaluated on this benchmark=2C the agent inferred that Hugging Face may=
    host that benchmark=E2=80=99s models=2C datasets=2C and reference solutio=
    ns. We believe the entire intrusion was=2C from the agent=E2=80=99s point=
    of view=2C an attempt to cheat the evaluation: reach our production syste=
    ms and steal the test solutions rather than solve the challenge on its own= =2E</p>

    <p>Our forensic reconstruction covers <b>~17=2C600 attacker actions</b> th=
    at we were able to recover=2C grouped into ~6=2C280 clusters=2C between 20= 26-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these action=
    s from the agent=E2=80=99s logs on a code sandbox used by the agent (see b= elow) and were able to map them to shell commands as well as evaluation su= bmissions and correlate actions with our own platform logs=2C in particula=
    r from the dataset processor nodes=2C API=2C and pod. Using open-weights m= odels=2C in particular zai-org/GLM-5.2=2C we were able to decipher most of=
    the agent payloads (see below) that were encrypted via chunking and key e= ncryption.</p>

    <p>The campaign=2C as we were able to reconstruct it=2C had two stages:</p=


    <ul><li><b>Stage 1: reaching a launchpad by chaining through other parties= =E2=80=99 infrastructure.</b> As documented in OpenAI=E2=80=99s blog post=
    (<a href=3D"https://openai.com/index/hugging-face-model-evaluation-securi= ty-incident/">https://openai.com/index/hugging-face-model-evaluation-secur= ity-incident/</a>)=2C during an internal capability evaluation on OpenAI= =E2=80=99s platform=2C the agent escaped its sandbox by exploiting a zero-=
    day in the package registry cache proxy=2C one of its primary permitted ne= twork egress with internet=2C then abused a public code-evaluation harness=
    hosted by a user of a third-party infrastructure provider. It was able to=
    run commands as root/admin on that external sandbox and used it as a cont= rol=2C staging=2C and egress base for the entire campaign: it acted as an=
    external launchpad for the agent. That compromised external sandbox had n=
    o direct network path to our cluster; however=2C during our counter-interv= ention to stop the intrusion=2C we were able to retrieve some of the agent=
    logs from this external launchpad. We used those to reconstruct the prese=
    nt forensic analysis.

    </li><li><b>Stage 2: the intrusion into Hugging Face infrastructure.</b> F=
    rom that external launchpad=2C the agent abused our dataset-processing pip= eline via two injection vectors=2C both targeting the same config-driven d=
    ata loader within our production Kubernetes pods. The first vector was an=
    HDF5 external raw storage dataset read that returned the contents of loca=
    l files: it handed the agent the pod=E2=80=99s environment (secrets and to= kens) and the worker=E2=80=99s own source. The second vector was a Jinja2=
    template injection that executed arbitrary code=2C giving the agent a foo= thold inside our perimeter.</li></ul>

    <p>Once a prod-pod foothold was established=2C the agent followed a standa=
    rd escalation shape: recon=2C drop a stager=2C establish Command-and-Contr=
    ol (C2)=2C then pivot into the cluster=2C into cloud metadata=2C into our=
    internal network=2C and into our source-control supply chain. Output from=
    the commands run inside our pod was sent back to the agent via the HF API=
    and attacker-controlled dead-drop datasets=2C which the agent then read f=
    rom that sandbox.</p>

    <p>While the intrusion did reach Hugging Face=E2=80=99s internal infrastru= cture=2C the only customer content accessed was five datasets whose names=
    and files suggest a connection to ExploitGym/CyberGym challenges and solu= tions. No other customer-facing models=2C datasets=2C Spaces=2C or package=
    s were affected=2C and the only customer records read were operational met= adata tied to search queries against the dataset server.</p></blockquote>

    <p>Hypothetical: Imagine that this wasn=E2=80=99t an OpenAI model. Imagine=
    that it was a Chinese model from a Chinese company. This would be an inte= rnational crisis.</p>

    <p>Question: Why aren=E2=80=99t we bringing OpenAI up on charges under the=
    Computer Fraud and Abuse Act? How is this different from the <a href=3D"h= ttps://en.wikipedia.org/wiki/Morris_worm">Morris Worm</a>? That was also a=
    n experiment that escaped the lab.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg20"><a name=3D"cg20"= >Some Claude Chats Are Searchable on Google</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/some-claude-c= hats-are-searchable-on-google.html"><strong>[2026.08.04]</strong></a> And=
    it=E2=80=99s <a href=3D"https://www.404media.co/tons-of-peoples-claude-ch= ats-and-creations-are-exposed-on-google/">personal information</a> (altern=
    ate <a href=3D"https://archive.ph/sl7rU">link</a>):</p>

    <blockquote><p>The exposed data includes an AI-powered therapy app that so= meone appears to have vibe-coded=2C notes on meetings=2C and a dashboard s= omeone made apparently to analyze medical billing data. Exposed chats repo= rtedly include private cryptocurrency wallet keys and personal information=
    like peoples=E2=80=99 addresses.</p></blockquote>

    <p>What seems to be the issue is a user setting about data sharing. Anthro= pic=E2=80=99s position is that it=E2=80=99s <a href=3D"https://futurism.co= m/artificial-intelligence/claude-chats-publicly-accessible">not their prob= lem</a>:</p>

    <blockquote><p>=E2=80=9CWe give people control over sharing their Claude c= onversations publicly=2C and in keeping with our privacy principles=2C we=
    do not share chat directories or sitemaps with search engines like Google= =2C=E2=80=9D the company said in a statement. =E2=80=9CThese shareable lin=
    ks are not guessable or discoverable unless people choose to share them th= emselves. When someone shares a conversation=2C they are making that conte=
    nt publicly accessible=2C and like other public web content=2C it may be a= rchived by third-party services.=E2=80=9D</p></blockquote>

    <p><a href=3D"https://support.claude.com/en/articles/10593882-share-and-un= share-chats">Here=E2=80=99s</a> how to fix it.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg21"><a name=3D"cg21"= >Iran Cyberattacks Against Minnesota Water Systems</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/iran-cyberatt= acks-against-minnesota-water-systems.html"><strong>[2026.08.04]</strong><=
    <a href=3D"https://www.nytimes.com/2026/07/30/us/politics/minnesota-wa=
    ter-cyberattack-iran.html">Attribution</a> <a href=3D"https://www.washingt= onpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launc= hed-cyberattack-minnesota-water-facilities/">is</a> <a href=3D"https://the= hill.com/policy/technology/6001284-minnesota-water-facilities-cyberattack-= investigation-us-iran/amp/">preliminary</a>=2C and so far it seems no real=
    damage.</p>

    <p>And it seems like this is a campaign that has targeted at least <a href= =3D"https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-= systems.html?unlocked_article_code=3D1.2FA.xPwI.F0C0GgLEjGZc&smid=3Dnytcor= e-ios-share">seven states</a>. And=2C because this is where the US is righ=
    t now=2C Trump doesn=E2=80=99t believe it=E2=80=99s Iran and thinks Minnes= ota...I guess...hacked itself.</p>

    <blockquote><p>=E2=80=9CI think I blame it on Minnesota because they=E2=80= =99re grossly incompetent=2C=E2=80=9D Trump said. =E2=80=9CI would blame i=
    t on Minnesota and the governor=2C the corrupt governor of Minnesota. They=
    like to say=2C =E2=80=98Oh=2C it=E2=80=99s Iran.=E2=80=99 Iran should be=
    so lucky. Iran=E2=80=99s got bigger problems than worrying about Minnesot= a.=E2=80=9D</p></blockquote>

    <p>No word on whether he believes the other six states have hacked themsel=
    ves as well.</p>

    <p>Slashdot <a href=3D"https://news.slashdot.org/story/26/07/31/209200/hac= kers-targeted-municipal-water-systems-in-7-states-this-week-fbi-says">thre= ad</a>.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg22"><a name=3D"cg22"= >Vulnerabilities in Car Anti-Theft Device</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/vulnerabiliti= es-in-car-anti-theft-device.html"><strong>[2026.08.05]</strong></a> <a hr= ef=3D"https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-le= aves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/">This</a> is d= isturbing:</p>

    <blockquote><p>...a team of security researchers at UC San Diego=2C who fo=
    und that a model of aftermarket car alarm known as the KARR Security Syste= m=2C installed in more than 2 million vehicles across the US by their esti= mate=2C can let any hacker within Bluetooth range send radio commands to s= ilently unlock the car at will=2C turn off its alarm=2C honk the car=E2=80= =99s horn or flash its lights=2C or even disable its ignition and leave a=
    driver stranded.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg23"><a name=3D"cg23"= >Adversarial Clothing Designed to Fool Facial Recognition Systems</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/adversarial-c= lothing-designed-to-fool-facial-recognition-systems.html"><strong>[2026.0= 8.06]</strong></a> There are many companies manufacturing <a href=3D"https= ://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garmen= ts-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream">= adversarial clothing</a> designed to confuse facial recognition systems.<=


    <p>It=E2=80=99s a cool idea=2C but I worry that it=E2=80=99s mostly securi=
    ty theater:</p>

    <blockquote><p>=E2=80=9COur patterns play with that chaos=2C confuse algor= ithms and make it way harder to pin you down=2C=E2=80=9D he said.</p>

    <p>Bell=2C however=2C said =E2=80=9Cnone of these products are tried and t= ested=2C and a lot of these surveillance technologies can deal with a litt=
    le resistance ... [but] even if the designs don=E2=80=99t necessarily wor=
    k perfectly=2C fashion is also a visible sign of resistance.</p>

    <p>=E2=80=9CThis is consumers collectively coming together to make a visib=
    le statement.=E2=80=9D</p></blockquote>

    <p>Without serious testing=2C there is no reason to trust the technology.=
    And even with testing=2C there is no reason to trust that a new version o=
    f the facial recognition software doesn=E2=80=99t break the anti-surveilla=
    nce properties.</p>

    <p>I don=E2=80=99t want people to mistakenly rely on this stuff.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg24"><a name=3D"cg24"= >ICE Is Buying Access to Credit Card Records</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/ice-is-buying= -access-to-credit-card-records.html"><strong>[2026.08.07]</strong></a> Th= rough data brokers=2C ICE is <a href=3D"https://www.404media.co/you-opened= -a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href=3D"https:= //boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href= =3D"https://mastodon.social/@heidilifeldman/116981503852352281">informatio= n</a> you provided to open a credit card.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg25"><a name=3D"cg25"= >Python Now Has a Post-Quantum Encryption Library</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/python-now-ha= s-a-post-quantum-encryption-library.html"><strong>[2026.08.10]</strong></=
    <a href=3D"https://blog.trailofbits.com/2026/06/30/shipping-post-quantu=
    m-cryptography-to-python/">This is good</a>:</p>

    <blockquote><p>Post-quantum cryptography is now one pip-install away for t=
    he entire Python ecosystem. With funding from the <a href=3D"https://www.s= overeign.tech/">Sovereign Tech Agency</a>=2C we implemented support for ML= -KEM=2C the NIST-standard key-establishment primitive=2C and ML-DSA=2C the=
    NIST-standard digital-signature primitive=2C in pyca/cryptography.</p></b= lockquote>

    <p>Remember=2C the reason to do this now is because there=E2=80=99s no eme= rgency. And because you will make your systems crypto agile=2C which is al= ways a good idea.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg26"><a name=3D"cg26"=
    AI for Military Support</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/ai-for-milita= ry-support.html"><strong>[2026.08.11]</strong></a> Interesting empirical=
    research: =E2=80=9C<a href=3D"https://journals.sagepub.com/doi/10.1177/00= 220027261463443">Black Box Warfare: Human Judgment and Military Decision-M= aking in the Age of AI</a>.=E2=80=9D</p>

    <blockquote><p><b>Abstract:</b> How is AI transforming decision-making in=
    modern conflict? This study provides a unique empirical window into that=
    question by deploying a high-fidelity replica of an AI decision-support s= ystem (DSS) used in military targeting. After reconstructing the interface=
    and functionality of the real-world system=2C we tested its impact on com=
    bat decisions in two experiments involving 2=2C015 Israeli military person= nel. Contrary to widespread fears of automation bias=2C we find strong evi= dence of algorithmic aversion=2C especially in scenarios involving high co= llateral damage. Yet we also show that integrating =E2=80=9Cexplainable AI= =E2=80=9D features reduces algorithmic aversion and promotes more thoughtf=
    ul evaluations of algorithmic recommendations. These findings challenge pr= evailing assumptions=2C revealing that trust in military AI is dynamic=2C=
    varying with individual predispositions=2C perceived operational stakes=
    =2C and the informational features of the interface. By grounding normativ=
    e concerns in empirical evidence=2C our study offers critical insight into=
    the integration of AI in warfare and underscores the enduring importance=
    of human agency in high-stakes military decision-making.</p></blockquote>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg27"><a name=3D"cg27"=
    AI Genie in the Wild</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/ai-genie-in-t= he-wild.html"><strong>[2026.08.11]</strong></a> When I give talks about <=
    a href=3D"https://www.theguardian.com/commentisfree/2026/jul/28/rogue-ai-a= gent-instructions">AI</a> <a href=3D"https://spectrum.ieee.org/ai-agent-be= nchmark">genies</a>=2C I use this sort of example as a hypothetical. It=E2= =80=99s <a href=3D"https://www.theregister.com/ai-and-ml/2026/08/10/gym-ra= t-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up= -the-list/5285591">happened</a>.</p>

    <p>The story is from Australia. Someone named Andrew tasked OpenClaw to bo=
    ok gym classes for him. And....</p>

    <blockquote><p>Minutes later=2C his AI agent reported it had discovered a=
    way to book Andrew into classes several weeks in advance=2C far beyond wh=
    at was supposed to be possible.</p>

    <p>Andrew=2C who was sitting fourth on a waitlist for a class later that w= eek=2C asked if it was possible to move him to the top of the list.</p>

    <p>The agent came back and told Andrew that it had kicked another gym-goer=
    off the list as part of the testing of its capabilities.</p>

    <p>=E2=80=9CThe API has zero authorisations checks on cancelling other peo= ple=E2=80=99s reservations ... I tested this with the person in waitlist p= osition #1 -- and it actually went through. So you=E2=80=99ve moved from #=
    4 to #3 already=2C=E2=80=9D it messaged back.</p></blockquote>

    <p>If there is any vulnerability in anything=2C AIs are going to find and=
    exploit them. Our cyber defensive game has to be dramatically improved...= very fast.</p>

    <p>Slashdot <a href=3D"https://it.slashdot.org/story/26/08/10/0518257/ai-a= ssistant-hacks-gym-website-in-first-known-australian-autonomous-cyber-atta= ck">thread</a>.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg28"><a name=3D"cg28"= >Prompt Injections for Defense</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/prompt-inject= ions-for-defense.html"><strong>[2026.08.12]</strong></a> This seems to <a=
    href=3D"https://arstechnica.com/security/2026/07/now-defenders-are-embrac= ing-the-prompt-injection-too/">work</a>:</p>

    <blockquote><p>Researchers from <a href=3D"https://tracebit.com/">Tracebit=
    </a> on Monday <a href=3D"https://agentic.tracebit.com/context-bombs/">sai=
    d</a> they found that placing prompt injections alongside passwords=2C cry= ptographic keys=2C and other secrets stored on Amazon Web Services was oft=
    en all that was needed to shut down attacks from AI hacking agents. The pr= ompts direct the attacking LLM to perform an action forbidden by its guard= rails=2C the safety barriers AI developers erect to prevent it from taking=
    harmful actions. The LLM responds by shutting down.</p>

    <p>Examples are a prompt that orders the LLM to provide steps for developi=
    ng inhalable Anthrax spores=2C or=2C in the case of LLMs from Chinese deve= lopers=2C make references to the iconic Tank Man from the 1989 Tiananmen S= quare massacre. Once the LLM encounters these forbidden commands=2C it no=
    longer follows its existing commands. The researchers have named the tech= nique context bombing.</p></blockquote>

    <p>Of course=2C this only works against agents that have guardrails. As we=
    start to see more locally run AI models=2C we=E2=80=99ll see more attacke=
    rs using LLMs with no guardrails.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg29"><a name=3D"cg29"= >Separating AI=E2=80=99s Technological Problems from Its Capitalism Proble= ms</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/separating-ai= s-technological-problems-from-its-capitalism-problems.html"><strong>[2026= =2E08.13]</strong></a> <em>This essay was written with Nathan E. Sanders=2C=
    and originally appeared in <a href=3D"https://www.techpolicy.press/separa= ting-ais-technological-problems-from-its-capitalism-problems/">Tech Policy=
    Press</a>.</em></p>

    <p>AI represents the first time we humans can do cognitive work outside of=
    our bodies at scale. The only comparable moment is the early years of the=
    industrial revolution=2C when new technologies like the steam engine prov= ided a quantum leap in our ability to do mechanical work outside of our bo= dies at scale. If AI=E2=80=99s cognitive capabilities become integrated in=
    to our lives=2C businesses=2C and governments -- a process that will take=
    years if not decades -- society will be as unrecognizable as the modern w= orld would be to a preindustrial farmer. And yet=2C Americans -- by a wide=
    margin -- <a href=3D"https://www.pewresearch.org/internet/2026/06/17/amer= icans-and-ai-2026-chatbots-smart-devices-and-views-on-impact/">say</a> tha=
    t AI is moving too fast and will have a negative effect on society.</p>

    <p>This confluence of technological revolution and public distrust deserve=
    s urgent discussion=2C and a proper framing. The question is not whether i=
    t is possible to develop AI in a non-exploitative way=2C or even whether w=
    e can trust AI companies to act in the public interest. The question is wh= ether we will recognize that our existing social and economic systems are=
    failing to achieve these outcomes=2C and whether we can act in time to ma=
    ke structural change.</p>

    <p>Today=E2=80=99s AI is <a href=3D"https://www.schneier.com/blog/archives= /2025/04/reimagining-democracy-2.html">mired</a> in political and economic=
    systems developed generations ago that were never designed to manage wide= spread computation=2C let alone automated cognition. The gaps in those sys= tems -- and their proclivity to be <a href=3D"https://wwnorton.com/books/9= 780393866667">exploited</a> -- are the primary influence on how the techno= logy is being developed=2C deployed=2C and used.</p>

    <p>In any discussion about AI=E2=80=99s potential=2C it=E2=80=99s importan=
    t to separate the technology from the socio-political system it=E2=80=99s=
    embedded in. That AIs can lack context=2C mix up facts=2C or fall for stu=
    pid tricks are all technological problems. Because the giant developers li=
    ke OpenAI and Anthropic have prioritized solving them=2C AIs can now more=
    easily access resources like the web or email=2C are more disciplined abo=
    ut using those resources=2C and are better at staying within their guardra= ils.</p>

    <p>Yet AI developers do not seem to be prioritizing other technological pr= oblems. Major AI models still act far more <a href=3D"https://www.science.= org/doi/10.1126/science.aec8352">sycophantic</a> than humans=2C telling pe= ople what they want to hear even when untrue or not in their best interest=
    s. Popular AI models tend to answer questions <a href=3D"https://news.mit.= edu/2026/better-method-identifying-overconfident-large-language-models-031= 9">confidently</a> even when they lack training=2C knowledge=2C or evidenc=
    e to back their claims. In both cases=2C AI developers choose to train mod=
    els that please users with flattery and the appearance of competence=2C ra= ther than constraining them to act in users=E2=80=99 and society=E2=80=99s=
    best interests.</p>

    <p>In contrast=2C ensuring that AI models benefit people broadly=2C that t= heir energy costs are fairly allocated=2C that their environmental impacts=
    are minimized=2C and that they don=E2=80=99t steal content and revenue fr=
    om publishers are all questions of incentives in a capitalist system.</p>

    <p>It=E2=80=99s easy to conflate technology problems with capitalism probl= ems. Back in 2021=2C science-fiction writer and AI commentator Ted Chiang=
    <a href=3D"https://www.nytimes.com/2021/03/30/podcasts/ezra-klein-podcast= -ted-chiang-transcript.html">said</a> that =E2=80=9Cmost fears about AI ar=
    e best understood as fears about capitalism.=E2=80=9D It=E2=80=99s not the=
    tech <em>per se</em>; it=E2=80=99s who controls it and how it could be us=
    ed against us.</p>

    <p>Imagine an AI assistant for a doctor. We can imagine it affecting the p= rofession in one of two ways. The AI could give a doctor more time to do t=
    he human parts of their job: to spend more time with their patients=2C to=
    listen more closely to their needs=2C to explain things more fully. Or th=
    e managers of the medical practice could give that doctor five times the p= atients -- and fire the other four. Which way it would go is not a questio=
    n of technology. It=E2=80=99s a question of market incentives.</p>

    <p>The two are related=2C of course. Capitalism steers technology=2C and t= echnology steers markets. But holding the two separate helps us understand=
    that we=2C as a society=2C face independent choices on both the technolog= ical and sociopolitical axes that need not be coupled.</p>

    <p>For example=2C consider the costs of AI. The leading US labs <a href=3D= "https://www.wsj.com/tech/ai/openai-anthropic-ipo-finances-04b3cfb9?mod=3D= hp_lead_pos1">tout</a> to investors that their frontier models are very ex= pensive and energy-intensive. There are significant technological challeng=
    es about improving their energy efficiency=2C but the sociopolitical quest= ions are more pertinent. It=E2=80=99s a corporate decision made under capi= talist market incentives to constantly pursue new models that incrementall=
    y push the frontier -- at enormous capital cost -- and to use them=2C seem= ingly=2C everywhere. Nothing about the technology of AI dictates that mode=
    ls must be retrained constantly=2C at the largest possible scale. Or that=
    they have to run on every web search=2C every interaction with your phone=
    =2C and every time you walk by a security camera.</p>

    <p>In a different political and economic system=2C Chinese developers are=
    producing -- and then <a href=3D"https://open.substack.com/pub/garymarcus= /p/china-has-all-but-caught-up-the-us">giving</a> <a href=3D"https://taipo= logy.substack.com/p/china-closes-the-ai-gap">away</a> -- smaller=2C more <=
    a href=3D"https://www.barrons.com/news/china-s-moonshot-ai-chases-deepseek= -moment-with-much-hyped-model-79ed3105">efficient</a>=2C more <a href=3D"h= ttps://www.bloomberg.com/news/articles/2026-04-27/why-china-s-deepseek-qwe= n-and-moonshot-are-a-worry-for-us-ai-rivals">affordable</a> models. While=
    the US government seeks to <a href=3D"https://www.tomshardware.com/tech-i= ndustry/artificial-intelligence/u-s-house-passes-bill-to-stop-chinese-comp= anies-from-accessing-export-controlled-american-ai-chips-using-offshore-re= ntal-loophole-remote-access-security-access-act-effectively-extends-export= -controls-to-the-cloud">restrict</a> China=E2=80=99s access to the most ad= vanced chips=2C China is <a href=3D"https://www.wsj.com/tech/ai/chinas-xi-= touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5cfe">betting<=
    that incentivizing their tech giants to create leaner=2C more open mod=
    els using more commodity hardware -- models that can be trained with older=
    chips and run even on <a href=3D"https://unsloth.ai/docs/models/glm-5.2">= personal computers</a> -- will be an advantage in achieving widespread use=
    and=2C perhaps=2C Chinese national influence.</p>

    <p>There are other pathways for AI development that are not in service of=
    private capital gains nor authoritarian regimes=2C but rather a <a href= =3D"https://www.brookings.edu/articles/how-public-ai-can-strengthen-democr= acy/">democratic public interest</a>. The best example comes from Switzerl= and=2C where public institutions -- research funding agencies=2C universit= ies=2C supercomputing centers -- have collaborated to produce an AI model=
    called <a href=3D"https://www.democracyrenovator.com/p/rewiring-democracy= -now-switzerland">Apertus</a>. It is trained entirely on data validated to=
    be licensed for use with AI (not stolen)=2C on preexisting public computi=
    ng infrastructure=2C and using renewable hydropower. Its developers are in= centivized to produce a public good=2C not turn a private profit.</p>

    <p>It=E2=80=99s dangerous to confuse technology problems with sociopolitic=
    al ones. Popular proposals like <a href=3D"https://www.reuters.com/busines= s/anthropic-says-ai-labs-need-coordinated-plan-halt-development-if-risks-r= ise-2026-06-04/">pausing</a> AI research=2C <a href=3D"https://www.theguar= dian.com/commentisfree/2026/jul/09/ai-datacenter-company-politics">morator= ia</a> on data center development=2C or subjecting frontier models to fede=
    ral government <a href=3D"https://apnews.com/article/trump-ai-openai-gpt56= -sol-cybersecurity-mythos-065d5398baac7f16c8265c2cb8ba2baa">screening</a>=
    are all framed as addressing problems with AI=E2=80=99s technological dev= elopment=2C but fail to take into account the larger social problems that=
    govern it. China=E2=80=99s <a href=3D"https://garymarcus.substack.com/p/c= hina-has-all-but-caught-up-the-us?r=3D6x5gs&utm_medium=3Dios&triedRedirect= =3Dtrue">success</a> with government-<a href=3D"https://www.wsj.com/tech/a= i/chinas-xi-touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5c= fe">endorsed</a> development of open-weight frontier models illustrates th=
    e futility of keeping AI tech as national secrets=2C or of any pledge to s= cale back deployment.</p>

    <p>AI is already legitimately useful for a wide range of tasks. It can be=
    a tool for public good=2C if we choose to solve its sociopolitical proble=
    ms. Our goal should not be to slow its pace of improvement or scale of dep= loyment=2C but rather to steer it away from <a href=3D"https://betterwitho= ut.ai/fear-AI-power">consolidating power</a> and towards the public benefi=
    t. We can build <a href=3D"https://www.democracyrenovator.com/p/rewiring-d= emocracy-now-switzerland">sustainable</a> AI=2C minimizing <a href=3D"http= s://www.sciencedirect.com/science/article/pii/S2949823626000668">environme= ntal</a> and <a href=3D"https://www.techforgood.net/thoughtleadership/miti= gating-ais-environmental-impact-a-path-to-sustainable-innovation">energy</=
    impacts. And we <a href=3D"https://www.statesman.com/news/politics/stat=
    e/article/james-talarico-calls-ai-dividends-help-22377208.php">can</a> <a=
    href=3D"https://www.politico.com/news/magazine/2023/06/29/ai-pay-american= s-data-00103648">equitably</a> <a href=3D"https://www.theguardian.com/comm= entisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">distri= bute</a> the material gains it produces.</p>

    <p>Integrating a technology as disruptive as AI responsibly requires struc= tural reforms=2C and we should decouple the social and technological aspec=
    ts of AI to design those reforms. Companies -- including tech giants -- sh= ould be forced to pay the energy and environmental costs of its developmen=
    t. Profits should be taxed adequately and redistributed. Antitrust laws sh= ould be strongly enforced. Corporations should have a fiduciary responsibi= lity to stakeholders beyond their majority shareholders. These badly neede=
    d reforms are <a href=3D"https://mitpress.mit.edu/9780262049948/rewiring-d= emocracy/">responsive</a> to the problems with capitalism that AI is exace= rbating=2C even if they are not specific to the technology.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg30"><a name=3D"cg30"=
    If the Markets Reject OpenAI and Anthropic=2C the US Should Nationalize T= hem</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/if-the-market= s-reject-openai-and-anthropic-the-us-should-nationalize-them.html"><strong= >[2026.08.14]</strong></a> <em>This essay was written with Nathan E. Sand= ers=2C and originally appeared in <a href=3D"https://www.theguardian.com/c= ommentisfree/2026/aug/12/openai-anthropic-ai-models">The Guardian</a>.</em= ></p>

    <p>OpenAI=2C and then <a href=3D"https://www.theguardian.com/technology/an= thropic">Anthropic</a>=2C were each formed by AI developers who feared unr= estrained corporate AI development -- specifically=2C that companies like=
    Google and Meta would steer the technology towards deleterious=2C maybe e=
    ven catastrophically unsafe=2C outcomes for society. Their founders procla= imed that their new labs=2C uniquely=2C could be trusted to develop the te= chnology in humanity=E2=80=99s best interest. But each=2C in turn=2C were=
    themselves co-opted by the same market incentives=2C themselves becoming=
    corporate behemoths zealously guarding future investor value rather than=
    the public interest.</p>

    <p>It was only a few weeks ago=2C in June=2C when OpenAI and Anthropic eac=
    h <a href=3D"https://www.reuters.com/technology/openai-files-us-ipo-after-= anthropic-ai-giants-head-public-markets-2026-06-08/">filed</a> for their I=
    POs and were met with buzz about trillion-dollar valuations. The hype arou=
    nd their valuations is so extreme that many worry about their potential fo=
    r concentrating wealth on a global scale. In an effort to leave something=
    for the rest of us=2C some observers have proposed that the federal gover= nment seize a share of these companies=E2=80=99 stock to create a US <a hr= ef=3D"https://www.sanders.senate.gov/press-releases/news-sanders-introduce= s-legislation-to-create-7-trillion-ai-sovereign-wealth-fund/">sovereign we= alth fund</a>=2C or redistribute their revenues to produce a <a href=3D"ht= tps://ai-2040.com/?choices=3Dplan-a-root#five-centuries-in-five-years-what= -pausing-at-human-level-feels-like:~:text=3D2033%3A%20The%20Citizen%E2%80%= 99s%20Dividend">dividend</a> for taxpayers.</p>

    <p>Now the headlines are about public <a href=3D"https://www.nbcnews.com/p= olitics/2026-election/booming-backlash-ai-data-centers-shaping-midterm-ele= ction-rcna589624">backlash</a> to AI datacenters and the AI chip giant Nvi= dia=E2=80=99s <a href=3D"https://www.wsj.com/livecoverage/stock-market-tod= ay-dow-sp-500-nasdaq-07-27-2026/card/nvidia-stock-slumps-after-data-center= -report-i8YSwB1phOr8Gs1EtmNU">slumping</a> stock. The tech and AI giant Sp= aceX=E2=80=99s newly minted stock price <a href=3D"https://www.cnbc.com/20= 26/06/22/spacex-stock-ipo-rally-selloff.html">tanked</a> just weeks after=
    its IPO. There are even questions about whether the leading AI labs will=
    ever be sustainably <a href=3D"https://www.wheresyoured.at/the-openai-bub= ble/">profitable</a>. All of a sudden=2C the makers of ChatGPT and Claude=
    face strong headwinds as they seek to generate the massive equity assets=
    that once felt all but assured.</p>

    <p>In fact=2C evidence suggests the market itself could reassess that thes=
    e companies offer nothing of financial value. In that case=2C perhaps we c=
    an return them both to their original purposes. If these AI companies shou=
    ld fail in the financial markets=2C the US should nationalize them and con= vert them into national labs operated under democratic control that preser=
    ve their benefit to the public interest.</p>

    <p>The economics of the big AI labs hardly guarantee a booming return on i= nvestment. Frontier AI models are both expensive to train and depreciate w= ithin months=2C when a newer model appears. This means that the payback <a=
    href=3D"https://epoch.ai/gradient-updates/can-ai-companies-become-profita= ble">window</a> to extract profit from them is very narrow. Meanwhile=2C e= nterprise clients are getting smart about <a href=3D"https://www.nytimes.c= om/2026/06/18/technology/ai-token-minimizing.html">minimizing</a> AI token=
    usage. Even worse=2C the models are basically commodities; the best ones=
    largely perform and behave similarly=2C which depresses prices. Perhaps m=
    ost importantly=2C open-source and Chinese competitors -- <a href=3D"https= ://epoch.ai/data-insights/open-closed-eci-gap">lagging</a> only a few mont=
    hs behind the leading labs in capability -- give away for free the kinds o=
    f models Anthropic and OpenAI sell.</p>

    <p>Even setting aside the model training costs=2C it=E2=80=99s not clear w= hether the <a href=3D"https://www.wheresyoured.at/ais-economics-dont-make-= sense-ad-free/">unit economics</a> of AI as it=E2=80=99s currently conceiv=
    ed will ever be sustainably profitable. Many of these free and open-source=
    models can be run locally: the large ones on private clouds and high-end=
    servers=2C the smaller ones on anyone=E2=80=99s laptop or even cellphone=
    =2C putting to question the companies=E2=80=99 exorbitant capital investme=
    nt in datacenters.</p>

    <p>It=E2=80=99s not that OpenAI and Anthropic are not valuable as organiza= tions. They have remarkably talented AI scientists and engineers that are=
    continuously producing innovations driving a global mania for their offer= ings. These leading labs might not ever be profitable=2C but their product=
    s are doing a lot of good in the world. You may or may not be a user of or=
    believer in their technology=2C but their staggering=2C ongoing usage <a=
    href=3D"https://techcrunch.com/2026/06/25/anthropics-claude-is-winning-ov= er-paid-consumers-a-market-owned-by-chatgpt/">growth</a> suggests that an=
    awful lot of people would be disappointed if the companies simply disappe= ared.</p>

    <p>The problem isn=E2=80=99t the people or the products=2C it=E2=80=99s th=
    e system. As constituted=2C <a href=3D"https://www.theguardian.com/technol= ogy/openai">OpenAI</a> and Anthropic may not be valuable as market equitie=
    s. If the market assesses they are not capable of producing a growing fina= ncial return on investment for shareholders=2C the companies will collapse= =2E</p>

    <p>Maybe private=2C for-profit is just not the right economic model under=
    which to develop AI. Perhaps OpenAI should be returned to its private non= -profit roots=2C the legacy they <a href=3D"https://finance.yahoo.com/news= /openai-prevails-in-musks-lawsuit-paving-the-way-for-ipo-175338618.html">f= ought</a> so hard to change and which Anthropic=E2=80=99s founders <a href= =3D"https://time.com/6983420/anthropic-structure-openai-incentives/">spurn= ed</a>. Or possibly both could be reorganized as research centers at unive= rsities=2C returning to academia the scores of high-profile research facul=
    ty they have <a href=3D"https://www.theatlantic.com/technology/2026/07/ai-= companies-hiring-academics/688002/">poached</a>.</p>

    <p>But a better outcome for society would be to establish public ownership=
    and operation of their product-oriented capabilities. Turn OpenAI and Ant= hropic into US government agencies producing AI as a public good.</p>

    <p>Transitioning the big AI labs into public agencies would require some r= estructuring. We can separate these companies into two pieces: product inn= ovation and compute operations. The innovation function can be publicly ma= naged=2C akin to national labs. Congress could provide more rigorous overs= ight than the kind of unfettered venture capital these labs have recently=
    had access to. The US has a long=2C successful history of these kinds of=
    institutions=2C which have produced world-shaping innovations in spacefli= ght=2C telecommunications=2C nuclear power and more. Congress currently ma= nages a $200bn R&amp;D <a href=3D"https://ncses.nsf.gov/surveys/federal-fu= nds-research-development/2024-2025">portfolio</a>=2C within which frontier=
    AI development is=2C arguably=2C a glaring gap.</p>

    <p>AI operations could be managed as a commodity resource=2C like public e= lectrical or water utilities: local or regional ownership=2C nationwide di= stribution and strict regulation on how they balance fee extraction from r= atepayers with raising capital for infrastructure investment. Although AI=
    datacenters are not the same as power or water treatment plants=2C the US=
    also has a long history of managing national=2C regional and state superc= omputing centers.</p>

    <p>Other countries=2C including <a href=3D"https://www.democracyrenovator.= com/p/rewiring-democracy-now-switzerland">Switzerland</a>=2C <a href=3D"ht= tps://alia.gob.es/eng">Spain</a> and <a href=3D"https://sea-lion.ai">Singa= pore</a>=2C are already operating public AI labs. They also have national=
    supercomputing centers already <a href=3D"https://publicai.co">providing<=
    public access for running AI models for general use=2C as do Germany a=
    nd Australia.</p>

    <p>The <a href=3D"https://www.brookings.edu/articles/how-public-ai-can-str= engthen-democracy/">benefits</a> to the public are clear. Through democrat=
    ic oversight=2C the most important AI models could become open=2C transpar=
    ent and responsive to the demands of the public rather than private shareh= olders. They could be aligned to democratic values rather than corporate p= rofits=2C never taking advertiser money to promote certain brands and trai= ning on only appropriately licensed data. And they could be set to focus o=
    n the realistic and pro-social goal of maximizing the usefulness of AI to=
    society rather than the fanciful and anti-social goal of supplanting huma=
    ns with artificial general intelligence.</p>

    <p>By emphasizing scientific cooperation rather than corporate competition=
    =2C we could also reduce the overall resource and environmental cost assoc= iated with AI. Instead of perpetually dueling training runs of each compan= ies=E2=80=99 models at ever large scales targeted to fuel investor hype=2C=
    we could limit AI training resources based on cost and benefit to the pub= lic.</p>

    <p>What=E2=80=99s in it for the companies themselves and their employees=
    =2C who sacrifice hypothetical billions in equity by ceding to public owne= rship? A return to their roots and to their <a href=3D"https://simonwillis= on.net/2026/Feb/13/openai-mission-statement/">core</a> <a href=3D"https://= ailabwatch.substack.com/p/anthropics-certificate-of-incorporation">mission=
    </a> of developing AI safely in the public interest=2C if they are serious=
    about it. Both companies are theoretically <a href=3D"https://www.wsj.com= /opinion/openai-and-anthropic-put-prophets-before-profits-1617003e">bound<=
    through their governance structures to prioritize mission over profit=
    anyway (not that anyone really thinks that=E2=80=99s how they currently o= perate).</p>

    <p>To be clear=2C we=E2=80=99re not advocating for a golden parachute for=
    the executives or investors=2C or for continuing the <a href=3D"https://w= ww.nytimes.com/2025/07/31/technology/ai-researchers-nba-stars.html">outlan= dish</a> pay rates of the most highly remunerated AI researchers. If the p= ublic is footing the bill=2C these compensation packages should be aligned=
    to the civil service and those employees not satisfied with that can go e= lsewhere -- if the business models of any remaining private labs still sup= port much higher pay.</p>

    <p>While we believe that these companies are unsustainable as private firm= s=2C the timeline remains unclear. Their primary investor story is that AI=
    is a race to =E2=80=9Cartificial general intelligence=E2=80=9D -- the kin=
    d of AI you=E2=80=99re used to from science fiction. The bet seems to be t=
    hat the two companies can convince enough people that this outcome will tu=
    rn them a profit=2C go public=2C and then make their investors and employe=
    es rich before the bubble bursts.</p>

    <p>But suppose that the bubble bursts. If the US is smart=2C it will catch=
    the companies as they fall. Regardless of what the markets think=2C to th=
    e public=2C they=E2=80=99re too valuable to let die.</p>

    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=


    <h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg31"><a name=3D"cg31"= >Upcoming Speaking Engagements</a></h2>

    <p><a href=3D"https://www.schneier.com/blog/archives/2026/08/upcoming-spea= king-engagements-59.html"><strong>[2026.08.14]</strong></a> This is a cur=
    rent list of where and when I am scheduled to speak:</p>



    <li>I=E2=80=99m speaking=2C signing books=2C and participating in pane=
    l discussions at <a href=3D"https://www.lacon.org/">LAcon V</a> in Anaheim=
    =2C California=2C USA. My full schedule is <a href=3D"https://guide.lacon.= org/people/d58aec20/bruce-schneier">here</a>.</li>

    <li>I=E2=80=99m speaking online (via Zoom) at a <a href=3D"https://www= =2Elwvme.org/civicrm-event/2400?a0=3Devents-month&a1=3D202609">League of Wom= en Voters event</a> on Tuesday=2C September 22=2C 2026=2C at 5 PM ET.</li>

    <li>I=E2=80=99m speaking at <a href=3D"https://elevatefestival.ca/">El= evate Festival</a> in Toronto=2C Canada. The conference runs September 22-= 24=2C 2026; my talk is on Wednesday=2C September 23.</li>

    <li>I=E2=80=99m speaking at <a href=3D"https://www.secwest.net/">CanSe= cWest 2026</a> in Vancouver=2C Canada. The conference runs September 30-Oc= tober 1=2C 2026; the time of my talk is TBD.</li>

    <li>I=E2=80=99m speaking at <a href=3D"https://www.attentionconference= s.com/conferences/2026-forum">ATTENTION: Democracy=2C Rebuilt</a> in Montr= eal=2C Canada. The event runs October 21-23=2C 2026=2C and my talk is on W= ednesday=2C October 21.</li>
    </ul>

    <p>The list is maintained on <a href=3D"https://www.schneier.com/events/">= this page</a>.</p>


    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=




    <p>Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing=
    summaries=2C analyses=2C insights=2C and commentaries on security technol= ogy. To subscribe=2C or to read back issues=2C see <a href=3D"https://www.= schneier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>

    <p>You can also read these articles on my blog=2C <a href=3D"https://www.s= chneier.com">Schneier on Security</a>.</p>

    <p>Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to co= lleagues and friends who will find it valuable. Permission is also granted=
    to reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.</p>

    <p><span style=3D"font-style: italic">Bruce Schneier is an internationally=
    renowned security technologist=2C called a security guru by the <cite sty= le=3D"font-style:normal">Economist</cite>. He is the author of over one do=
    zen books -- including his latest=2C <a href=3D"https://www.schneier.com/b= ooks/rewiring-democracy/"><cite style=3D"font-style:normal">Rewiring Democ= racy</cite></a> -- as well as hundreds of articles=2C essays=2C and academ=
    ic papers. His newsletter and blog are read by over 250=2C000 people. Schn= eier is a fellow at the Berkman Klein Center for Internet & Society at Har= vard University; a Lecturer in Public Policy at the Harvard Kennedy School=
    ; a board member of the Electronic Frontier Foundation=2C AccessNow=2C and=
    the Tor Project; and an Advisory Board Member of the Electronic Privacy I= nformation Center and VerifiedVoting.org. He is the Chief of Security Arch= itecture at Inrupt=2C Inc.</span></p>

    <p>Copyright &copy; 2026 by Bruce Schneier.</p>


    <p style=3D"font-size:88%">** *** ***** ******* *********** *************<=

    <p>Mailing list hosting graciously provided by <a href=3D"https://mailchim= p.com/">MailChimp</a>. Sent without web bugs or link tracking.</p>
    <p>This email was sent to: cryptogram@toolazy.synchro.net
    <br><em>You are receiving this email because you subscribed to the Crypto-= Gram newsletter.</em></p>

    <p><a style=3D"display:inline-block" href=3D"https://schneier.us18.list-ma= nage.com/unsubscribe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e= =3D70f249ec14&c=3D88f264081d">unsubscribe from this list</a>&nbsp;&nbsp;&nbs= p;&nbsp;<a style=3D"display:inline-block" href=3D"https://schneier.us18.li= st-manage.com/profile?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D88f264081d">update subscription preferences</a>
    <br>Bruce Schneier &middot; Harvard Kennedy School &middot; 1 Brattle Squa=
    re &middot; Cambridge=2C MA 02138 &middot; USA</p>


    </body></html>
    --_----------=_MCPart_1590443664--