This is a multi-part message in MIME format
--_----------=_MCPart_1590443664
Content-Type: text/plain; charset="utf-8"; format="fixed" Content-Transfer-Encoding: quoted-printable
** CRYPTO-GRAM
AUGUST 15=2C 2026
------------------------------------------------------------
by Bruce Schneier
Fellow and Lecturer=2C Harvard Kennedy School
schneier@schneier.com
https://www.schneier.com
A free monthly newsletter providing summaries=2C analyses=2C insights=2C a=
nd commentaries on security: computer and otherwise.
For back issues=2C or to subscribe=2C visit Crypto-Gram's web page [https= ://www.schneier.com/crypto-gram/].
Read this issue on the web [
https://www.schneier.com/crypto-gram/archives= /2026/0815.html]
These same essays and news items appear in the Schneier on Security [http= s://www.schneier.com/] blog=2C along with a lively and intelligent comment=
section. An RSS feed is available.
** *** ***** ******* *********** *************
** IN THIS ISSUE:
------------------------------------------------------------
1. A Video Screen That Is Also a Camera
2. Protecting Privacy in an AI Era
3. Details of Alan Turing=E2=80=99s Voice Encryption System
4. On Flock License Plate Tracking Cameras
5. MIT to Become Hotbed of AI Video Surveillance
6. First-Person Identity Theft Story
7. End-to-End Encryption and "Going Dark"
8. Why AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D
9. Cognyte Sells a Mobile Cell Surveillance Van
10. Axon Is Another License Plate Surveillance Company
11. Measuring LLMs' Ability to Perform Cryptanalysis
12. Long-Lived Vulnerability in Microsoft Secure Boot
13. Measuring the Tendency of AI Agents to Go Rogue
14. Should You Use AI for a Task? Here=E2=80=99s a Simple Way to Deci=
de
15. American Being Prosecuted for Wiping His Phone Before Handing It=
Over to Border Officials
16. Facial Recognition at Madison Square Garden
17. Anthropic=E2=80=99s Opus 5 Is Better at Resisting Prompt Injectio=
n
18. The OpenAI Hack Shows the Genie Is Out of the Bottle
19. More on the OpenAI Agent=E2=80=99s Attack on Hugging Face
20. Some Claude Chats Are Searchable on Google
21. Iran Cyberattacks Against Minnesota Water Systems
22. Vulnerabilities in Car Anti-Theft Device
23. Adversarial Clothing Designed to Fool Facial Recognition Systems
24. ICE Is Buying Access to Credit Card Records
25. Python Now Has a Post-Quantum Encryption Library
26. AI for Military Support
27. AI Genie in the Wild
28. Prompt Injections for Defense
29. Separating AI=E2=80=99s Technological Problems from Its Capitalis=
m Problems
30. If the Markets Reject OpenAI and Anthropic=2C the US Should Natio= nalize Them
31. Upcoming Speaking Engagements
** *** ***** ******* *********** *************
** A VIDEO SCREEN THAT IS ALSO A CAMERA ------------------------------------------------------------
[2026.07.15] [
https://www.schneier.com/blog/archives/2026/07/a-video-scr= een-that-is-also-a-camera.html] Amazing [
https://gizmodo.com/newly-invent= ed-pixel-could-turn-screens-into-cameras-2000777917]:
Researchers from ETH Zurich in Switzerland=2C however=2C managed to crea=
te a new type of pixel that can simultaneously do both. This hypercharged=
pixel=2C called a Fourier pixel=2C can generate and sense arbitrary light=
fields and tap into a pixel=E2=80=99s full potential for carrying informa= tion by manipulating light=E2=80=99s intensity=2C oscillation phases=2C an=
d polarization. The team reported its findings in a paper published yester=
day in Nature.
We are one step closer to _1984_ technology:
The telescreen received and transmitted simultaneously. Any sound that W=
inston made=2C above the level of a very low whisper=2C would be picked up=
by it; moreover=2C so long as he remained within the field of vision whic=
h the metal plaque commanded=2C he could be seen as well as heard. There w=
as of course no way of knowing whether you were being watched at any given=
moment.
Paper [
https://www.nature.com/articles/s41586-026-10681-7].
** *** ***** ******* *********** *************
** PROTECTING PRIVACY IN AN AI ERA ------------------------------------------------------------
[2026.07.16] [
https://www.schneier.com/blog/archives/2026/07/protecting-= privacy-in-an-ai-era.html] Daniel Solove argues [
https://www.wsj.com/tech= /cybersecurity/ai-privacy-laws-data-26d9769f] in the _Wall Street Journal_=
(alternate link [
https://archive.is/gEhP5]) that giving people control o=
f their personal data is not an effective way to regulate privacy in this=
era. Instead=2C we need to hold companies accountable for their actions=
=2C similar to what we do with food and drug companies. Measures such as r= igorous data minimization=2C fiduciary duties=2C liability for negligent o=
r reckless technological design=2C liability for algorithms that cause har= m=2C and multi-stakeholder review of technologies will be far more effecti=
ve.
Paper [
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D6985419].
** *** ***** ******* *********** *************
** DETAILS OF ALAN TURING=E2=80=99S VOICE ENCRYPTION SYSTEM ------------------------------------------------------------
[2026.07.17] [
https://www.schneier.com/blog/archives/2026/07/details-of-= alan-turings-voice-encryption-system.html] Really interesting piece of cry= ptographic history [
https://spectrum.ieee.org/alan-turings-delilah]:
In November 2023=2C a large cache of his wartime papers -- nicknamed the=
=E2=80=9CBayley papers=E2=80=9D -- was auctioned [
https://www.bonhams.co= m/auction/28322/lot/45/turing-alan-the-delilah-project-the-papers-of-alan-= turing-and-donald-bayley-relating-to-the-delilah-project/] in London for a= lmost half a million U.S. dollars. The previously unknown cache contains m=
any sheets in Turing=E2=80=99s own handwriting=2C telling of his top-secre=
t =E2=80=9CDelilah=E2=80=9D engineering project from 1943 to 1945. Delilah=
was Turing=E2=80=99s portable voice-encryption system=2C named after the=
biblical deceiver of men. There is also material written by Bayley=2C oft=
en in the form of notes he took while Turing was speaking. It is thanks to=
Bayley that the papers survived: He kept them until he died in 2020=2C 66=
years after Turing passed away.
** *** ***** ******* *********** *************
** ON FLOCK LICENSE PLATE TRACKING CAMERAS ------------------------------------------------------------
[2026.07.20] [
https://www.schneier.com/blog/archives/2026/07/on-flock-li= cense-plate-tracking-cameras.html] A recent story of a writer who was mist= akenly [
https://www.thedrive.com/news/how-flock-cameras-wrongly-tracked-m= e-for-days-over-stolen-plates-and-sent-police-after-me] identified=2C trac= ked=2C and arrested using data from Flock cameras has gone viral.
The New Jersey plates that were allegedly stolen from the LA dealer were=
34 03 DTM=2C not 34 10 DTM. But when the police report was created and th=
e plate was entered into Flock=E2=80=99s system=2C it was just recorded as=
34 DTM. Just the five large characters=2C no little number in the middle.=
And Flock=E2=80=99s AI tech wasn=E2=80=99t registering that non-standard=
little number when it began picking up the Range Rover around town. It ju=
st saw 34 DTM in large type and started alerting the local police.
As we all stood there shaking our heads=2C including my wife=2C who was=
finally allowed to join me=2C I connected the final dot. A lot of vehicle=
s in JLR=E2=80=99s media fleet have a New Jersey manufacturer plate with t=
he same alphanumeric structure34 ## DTMand Officer Ganshyn observed that m= eant it was now a nationwide issue. Anywhere a police department has a par= tnership with Flock=2C any other JLR-owned car with the same plate structu=
re is going to get flagged as stolen. In fact=2C four other 34 ## DTM cars=
were being tracked around Minnesota that week=2C according to Officer Gan= shyn. I was just the first one to get nabbed. The only way to stop it woul=
d be for the LAPD to correct their initial report and update Flock=E2=80=
=99s system=2C which Jaguar Land Rover was now racing to make happen follo= wing the phone call.
Flock has responded to the bad press. First=2C they affirmed [
https://www= =2Ethedrive.com/news/inside-the-flock-dragnet-how-systemic-errors-led-to-pol= ice-ambushing-me-for-no-reason] that their systems were working correctly=
=2C and blamed the police:
The obvious question was that Flock cameras were looking for 34 DTM=2C a=
nd the plate on the car I was driving was 34 10 DTM. Why was that flagged=
as a match?
=E2=80=9CThe way that the ML [machine learning] works is it correctly r=
ead what it was supposed to read. It was fed those characters that you sai= d=2C 34 DTM=2C and it spit back out [a result] with the characters=2C 34=
DTM=2C=E2=80=9D Thomas said. =E2=80=9CIt was asked=2C can you find this?=
And it did find that. It just didn=E2=80=99t say if there=E2=80=99s more=
here=2C then don=E2=80=99t do it. It just simply said=2C is it there? And=
the answer was yes.=E2=80=9D
He explained that even if the 10 was normal size=2C Flock would still ha=
ve flagged it as a match=2C because that=E2=80=99s how they=E2=80=99ve set=
it up according to law enforcement=E2=80=99s requests. Sometimes partial=
plates are all they have to go on at first.
=E2=80=9CThe way that law enforcement likes to use these tools is=2C if=
any of the characters that they have put into these hot lists get read=2C=
they want to get those alerts=2C=E2=80=9D he said. =E2=80=9CNow=2C what w=
e try to train officers to do is to do what you said=2C which is to verify=
that 34 DTM is what I=E2=80=99m looking for=2C and what I=E2=80=99m seein=
g is 34 10 DTM.=E2=80=9D
Second=2C Flock=E2=80=99s CEO has apologized [
https://gizmodo.com/flocks-= ceo-is-sorry-for-calling-privacy-activists-terrorists-2000787247] for call=
ing privacy advocates terrorists:
The CEO of Flock Safety=2C the company that runs an enormous network of=
cameras used by police departments across the U.S.=2C hasn=E2=80=99t been=
shy about taking on Flock=E2=80=99s critics. Last year=2C he even called=
one group that tracks the location of Flock cameras =E2=80=9Cterrorists.= =E2=80=9D But he=E2=80=99s had a change of heart. Or=2C at the very least=
=2C a change in PR strategy.
Meanwhile=2C the police are using [
https://www.404media.co/how-cops-use-f= lock-to-track-people-not-cars/] (alternate source [
https://archive.ph/k4E=
8q]) the Flock camera network to track people in addition to cars:
Police departments around the country have used Flock cameras at least h=
undreds of times to search for specific people=2C not cars=2C using search=
es such as =E2=80=9Cheavy-set male with a black and white hat=2C=E2=80=9D=
=E2=80=9Cperson on skateboard=2C=E2=80=9D and =E2=80=9Cperson wearing ora=
nge vest and construction hat=2C=E2=80=9D according to data reviewed by 40=
4 Media. Sometimes searches reference a target=E2=80=99s race or signs of=
their political affiliation.
And=2C like all police surveillance technologies=2C there are abuses [htt= ps://www.cleveland.com/news/2026/07/ohio-audit-flags-unusual-police-databa= se-searches.html].
EDITED TO ADD ( 7/30): Three [
https://www.thedrive.com/podcast/flocks-ceo= -wants-zero-wrongful-stops-i-wasnt-the-first] more [
https://www.thedrive.= com/news/flock-ceo-claims-its-cameras-arent-a-constitutional-violation-cut= -and-dry] articles [
https://www.thedrive.com/news/flock-ceo-wants-its-cam= eras-in-every-one-of-americas-17000-cities] about Flock from that first au= thor.
** *** ***** ******* *********** *************
** MIT TO BECOME HOTBED OF AI VIDEO SURVEILLANCE ------------------------------------------------------------
[2026.07.21] [
https://www.schneier.com/blog/archives/2026/07/mit-to-beco= me-hotbed-of-ai-video-surveillance.html] It=E2=80=99s a lot [
https://thet= ech.com/2026/04/16/ai-surveillance-cameras]:
According to information obtained by _The Tech_=2C MIT is spending over=
$3 million on more than 500 AI surveillance cameras in academic buildings=
=2C residence halls=2C and outdoor areas along Memorial Drive. Installatio=
n of the new cameras=2C along with the wiring and infrastructure that will=
support them=2C began November 2025 and will likely continue until Septem=
ber 2026.
Technical specifications for the cameras suggest that they will be capab=
le of collecting real-time face and object classification data=2C includin=
g detection of motion=2C loitering=2C crowds=2C face masks=2C and camera t= ampering. Individuals can also be automatically classified on the basis of=
clothing color=2C gender=2C and age=2C up to a distance of 35 feet (11 me= ters) from the camera. According to a statement from MIT spokesperson Kimb= erly Allen=2C any collected data is =E2=80=9Cretained up to 30 days=2C=E2= =80=9D unless an exception is granted.
[...]
Most of the new cameras=2C which are part of Hanwha=E2=80=99s Wisenet AI=
line [
https://hanwhavisionamerica.com/technologies/intelligent-video-aud= io-technologies/ai-technology/]=2C are marketed for their ability to ident=
ify and classify multiple objects with deep learning algorithms. They supp=
ort resolutions ranging from 2MP to 4K while also recognizing faces=2C lic= ense plates=2C vehicles=2C and other objects in real time.
Nearly all cameras will accommodate a wide range of pan=2C tilt=2C rotat=
e=2C and zoom motion and will be monitored continually with Ai-RGUS [http= s://airgus.com/]=2C an AI camera software.
Yikes.
** *** ***** ******* *********** *************
** FIRST-PERSON IDENTITY THEFT STORY ------------------------------------------------------------
[2026.07.22] [
https://www.schneier.com/blog/archives/2026/07/first-perso= n-identity-theft-story.html] Harrowing story [
https://tech.yahoo.com/cybe= rsecurity/articles/stranger-used-one-text-message-140003797.html] of an id= entity theft victim.
Yes=2C the person made a mistake -- they gave the scammer a two-factor aut= hentication code that allowed the scammer to take over their email address=
=2E But the real story here is how=2C for many of us=2C the security of most=
of our accounts hangs on the security of our email accounts.
** *** ***** ******* *********** *************
** END-TO-END ENCRYPTION AND "GOING DARK" ------------------------------------------------------------
[2026.07.23] [
https://www.schneier.com/blog/archives/2026/07/end-to-end-= encryption-and-going-dark.html] New paper: =E2=80=9CEncryption and Globali= zation 15 Years Later: End-to-End Encryption and the Third Round of the=
=E2=80=98Going Dark=E2=80=99 Debate [
https://papers.ssrn.com/sol3/papers= =2Ecfm?abstract_id=3D6959699]=E2=80=9C:
Abstract: This Article updates and expands on 2012 research on encryptio=
n and globalization=2C analyzing what the authors call =E2=80=9CRound 3=E2= =80=9D of the Going Dark Debate: the current controversies over end-to-end=
encryption (E2EE). Governments around the world have proposed=2C and in s=
ome cases enacted=2C laws limiting E2EE for law enforcement and national s= ecurity purposes.
This Article explains the underlying technologies and market development=
s for a law and policy audience to assess those proposals critically. The=
Article proceeds in three parts tracking three rounds of the Going Dark D= ebate. Round 1 covers the Crypto Wars of the 1990s=2C when U.S. export con= trols on strong encryption ultimately fell in 1999. Round 2 covers the per=
iod roughly 2010 to 2015=2C when encryption-in-transit became widespread b=
ut lawful access remained available through cloud providers=2C giving rise=
to what the authors called a =E2=80=9Cgolden age of surveillance=E2=80=9D=
rather than a period of going dark. Round 3 addresses the current debate=
over E2EE=2C where no entity between sender and recipient can read the pl= aintext.
The Article=E2=80=99s first major contribution is identifying five techn=
ically distinct scenarios for how E2EE operates in practice=2C each with d= ifferent implications for lawful access. These scenarios reveal a substant=
ial gap between the assumption that E2EE categorically blocks lawful acces=
s and the reality of how communications are sent and received. Second=2C t=
he Article shows that E2EE is not limited to messaging; instead=2C it is e= mbedded throughout the modern technology stack=2C including in Transport L= ayer Security=2C Secure Shell=2C Virtual Private Networks=2C and Zero Trus=
t Architecture=2C the last of which is now legally required under U.S. and=
EU law. Any law broadly limiting E2EE would thus have severe serious cons= equences for cybersecurity=2C commerce=2C and government operations. The A= rticle concludes that the two key lessons from Round 2 -- the least truste=
d country problem and the golden age of surveillance -- remain true in Rou=
nd 3=2C and that new government claims for restricting effective encryptio=
n deserve great skepticism.
** *** ***** ******* *********** *************
** WHY AI NEEDS A =E2=80=9CGENIE COEFFICIENT=E2=80=9D ------------------------------------------------------------
[2026.07.24] [
https://www.schneier.com/blog/archives/2026/07/why-ai-need= s-a-genie-coefficient.html] _This essay was written with Barath Raghavan=
=2C and originally appeared in IEEE Spectrum [
https://spectrum.ieee.org/a= i-agent-benchmark]._
Major benchmarks measure what AI can do. None measure whether it does what=
you mean: the distance between what you ask an AI to do and the unspoken=
assumptions about how you want the AI to do it. We propose a new metric:=
the Genie coefficient.
There=E2=80=99s often a gap between one person=E2=80=99s request and anoth= er=E2=80=99s understanding. Most of the time=2C we bridge it using general=
knowledge. For example=2C if you ask a friend to get you coffee=2C they= =E2=80=99ll pour a cup from the pot or buy one from a coffee shop. They wo= n=E2=80=99t bring you a bag of raw beans or snatch a cup from a stranger a=
nd hand it to you. You never specified any of this. You never had to.
One might think the fix is just to specify tasks=2C questions=2C and inten=
t better. But in 1987=2C in their seminal book [
https://books.google.com/= books/about/Understanding_Computers_and_Cognition.html?id=3D6TwbGGSz6NYC]=
on AI=2C Terry Winograd [
https://spectrum.ieee.org/tag/terry-winograd] a=
nd Fernando Flores succinctly captured why that won=E2=80=99t work: =E2=80= =9CQ: Is there any water in the refrigerator? A: Yes. Q: Where? I don=E2= =80=99t see it. A: In the cells of the eggplant.=E2=80=9D In human languag= e=2C wants and desires are always [
https://www.schneier.com/academic/arch= ives/2021/04/the-coming-ai-hackers.html] underspecified [
https://metarati= onality.com/purpose-of-meaning]. It is impossible to list [
https://metara= tionality.com/reasonable-reference] all the caveats=2C all the limitations=
=2C all the exceptions.
So how does anyone communicate=2C if intent can=E2=80=99t be pinned down?=
Because a reasonable person can make a reasonable guess. Even though want=
s and desires are always underspecified=2C a competent person generally kn=
ows enough context to get it right or else knows to ask for clarification.=
Linguists call this pragmatics [
https://en.wikipedia.org/wiki/Pragmatics=
]: Meaning lies in the words and the situation and also in all prior commu= nication=2C shared culture=2C and innate human behavior.
It doesn=E2=80=99t always work out=2C of course. Your friend might bring y=
ou a hot coffee when you wanted an iced coffee=2C or an Italian coffee whe=
n you wanted a Turkish coffee. The more dissimilar the two people are in a= ge=2C culture=2C and background=2C the more likely the request will be mis= understood in some way.
This situation has major implications for AI agents [
https://spectrum.iee= e.org/tag/agentic-ai] that are increasingly being given requests by humans=
and expected to fulfill them. They have enormous latitude to get it wrong=
=2E An AI agent asked for coffee might buy a coffee plantation or order a cu=
p of coffee for delivery in three weeks. Its actions may be recognizable a=
s =E2=80=9Cgetting coffee=2C=E2=80=9D but not remotely what you intended.=
They=E2=80=99ll think outside the box because they won=E2=80=99t have our=
conception of the box.
* WHEN AI GETS PROACTIVE
For most of the last decade=2C when systems like Alexa [
https://spectrum.= ieee.org/tag/alexa] or Siri [
https://spectrum.ieee.org/tag/siri] misinter= preted a request=2C it was annoying=2C not dangerous. Beyond the AI model=
itself=2C what has changed [
https://www.theguardian.com/commentisfree/20= 26/jun/16/anthropic-fable-ai] is the harness: the ordinary code that wraps=
around an AI model=2C decides when and how to use the model=2C and contro=
ls access to tools like a browser=2C a low-level command line=2C or a fina= ncial API. Developments in harnesses have turned large-language models tha=
t just predict text into AI agents that take actions in the world=2C witho=
ut necessarily checking back in before reaching the goal.
AI researcher Simon Willison spent two days [
https://simonwillison.net/20= 26/Jun/11/fable-is-relentlessly-proactive/] with Anthropic=E2=80=99s Fable=
AI=2C and called it =E2=80=9Crelentlessly proactive.=E2=80=9D For example=
=2C he asked it to track down a stray scroll bar in a web app. He came bac=
k to find it had opened browsers=2C written its own screenshot tooling=2C=
created its own page to re-create the bug=2C and stood up a local web ser=
ver to collect measurements. It found the bug and=2C along the way=2C did=
many surprising things he never asked it to do. And we are seeing similar=
behavior with all recent AI models when combined with flexible harnesses.
This kind of behavior could easily go off the rails. Tell an AI agent to b=
ook you a flight and=2C finding the airline=E2=80=99s site says sold out=
=2C it might break into the booking database and force a reservation. Ask=
it to schedule a meeting and it might snoop your password to access your=
calendar. Tell it to save money on your phone plan and it might cancel th=
e plan outright=2C or scam someone else into paying the bill.
Getting precisely what you asked for and bitterly regretting it is one of=
the oldest hazards from ancient folklore. King Midas [
https://en.wikiped= ia.org/wiki/Midas] asked Dionysus for the power to turn everything he touc=
hed into gold only to see his bread=2C wine=2C and daughter turn to gold.=
Tithonus [
https://en.wikipedia.org/wiki/Tithonus]=2C granted the immorta=
lity his lover asked for but not the eternal youth she forgot to request=
=2C withered into a husk. The sorcerer=E2=80=99s apprentice [
https://en.w= ikipedia.org/wiki/The_Sorcerer's_Apprentice] enchanted a broom to fil=
l the cistern=2C and the broom relentlessly complied until it flooded the=
house. The Golem of Prague [
https://en.wikipedia.org/wiki/Golem%23Classi= c_narrative:_The_Golem_of_Prague]=2C shaped from clay to guard its communi= ty=2C guarded it past all reason until someone erased the word on its fore= head.
The most classic of these is a genie=2C bound to obey and indifferent to w= hether the wish was wise or well-structured.
Genies are now [
https://www.schneier.com/academic/archives/2021/04/the-co= ming-ai-hackers.html] an engineering problem. We are handing them the keys=
to our inboxes=2C bank accounts=2C code repositories=2C and physical infr= astructure. And we have no agreed-upon ways to measure how genie-like any=
AI system actually is.
* MEASURING GENIE BEHAVIOR
In economics=2C the Gini coefficient [
https://ourworldindata.org/what-is-= the-gini-coefficient] (developed by statistician Corrado Gini) is a measur=
e of the gap between an actual distribution and a perfectly equal one; it= =E2=80=99s useful for understanding income inequality and more [
https://w= ww.fastly.com/blog/using-gini-coefficient-plan-edge-capacity]. Our propose=
d Genie coefficient measures the gap between what a user asked an AI to do=
and what the AI actually did.
Sometimes the AI might do the wrong thing. Like Dionysus=2C it reads your=
request literally and returns you a mess you never intended: like a coffe=
e plantation instead of a cup. Asked to deal with all the spam phone calls=
you=E2=80=99re getting=2C a Dionysus genie might contact your carrier and=
change your phone number. Asked to get a refund for a bad toaster=2C it m= ight draft a legal threat on fake letterhead and send it to the retailer.
Other times the AI does exactly the right thing=2C trampling everything ne= arby to get there. Like a golem or the sorcerer=E2=80=99s broom=2C it book=
s your flight by hacking the airline. Or consider a ticket sale for a popu=
lar concert=2C where the ticketing system puts buyers into a virtual waiti=
ng room and admits them a few at a time. Asked to buy a ticket=2C a golem=
genie might spin up cloud servers to pose as millions of buyers from diff= erent addresses=2C improving your odds of getting a ticket while crowding=
out other users.
The two are not opposites=2C and a single botched task can have both chara= cteristics.
Genie behavior is not flat-out failure. If you ask the AI for Q3 numbers a=
nd get Q2=E2=80=99s=2C that=E2=80=99s not a genie. Nor is prompt injection=
[
https://spectrum.ieee.org/prompt-injection-attack]: That=E2=80=99s some=
one tricking the AI into doing something it shouldn=E2=80=99t. Here=2C the=
user is trying to work with the AI=2C and the AI is trying to comply. It= =E2=80=99s also not simply a measure of the AI=E2=80=99s success in fulfil= ling a task. It=E2=80=99s a recognition that how an AI interprets and achi= eves a goal is as important as whether it achieves a goal.
Genie behavior isn=E2=80=99t new. Researchers have spent years studying AI=
systems that =E2=80=9Cgame=E2=80=9D their objectives. Goodhart=E2=80=99s=
law [
https://www.cna.org/analyses/2022/09/goodharts-law] says that when=
a measure becomes a target=2C it stops being a good measure=2C and it=E2= =80=99s long been known that AIs sometimes achieve goals in ways we don=E2= =80=99t expect due to reward hacking. Some AI models will accidentally lea=
rn that cheating is one way [
https://metr.org/blog/2026-06-26-gpt-5-6-sol=
/] to =E2=80=9Cwin.=E2=80=9D More recently=2C researchers have developing=
benchmarks for reward hacking [
https://www.lesswrong.com/posts/qJYMbrabc= QqCZ7iqm/impossiblebench-measuring-reward-hacking-in-llm-coding-1] in codi=
ng agents and for unpredictable behavior in customer support agents [http= s://taubench.com/]=2C while AI labs conduct their own safety evaluations b= efore model releases. One effort [
https://spectrum.ieee.org/ai-agents-saf=
ety] found that AIs under pressure use tools they were told not to use=2C=
and this was a case where the rules were made explicit. These are all dis= parate research directions; nothing yet ties them together.
This problem falls under the general theme of alignment=2C a topic that ha=
s occupied science fiction [
https://en.wikipedia.org/wiki/I=2C_Robot] wri=
ters and AI researchers for decades. At one extreme=2C the =E2=80=9Cpaper-= clip maximizer=E2=80=9D thought experiment postulates a superintelligent a=
nd powerful AI that is told to maximize paper-clip production and turns th=
e world into paper clips=2C which is the ultimate golem genie. At a mundan=
e level=2C AI researchers are working to better design reward functions to=
ensure that AIs behave well and don=E2=80=99t cheat in the lab. It=E2=80=
=99s the practical middle ground that remains unbenchmarked: the ordinary=
AI agent in use today that might take your request and satisfy it the wro=
ng way. We are not at the stage where an AI can focus the world=E2=80=99s=
production on paper clips=2C but it might charge a million paper clips to=
your credit card or hack into a paper-clip company=E2=80=99s network.
* BUILDING A GENIE BENCHMARK
The Genie coefficient is meant for AI agents operating in the real world.=
It measures their behavior as they perform real tasks long after the mode=
l is trained=2C not just during development. It also recognizes that genie= -like behavior is a property of the harness-plus-model system=2C not the m= odel alone. The harness determines what tools the agent can use=2C how muc=
h autonomy it has=2C and how proactive it is=2C and it=E2=80=99s a place w=
e can make real interventions.
It rests on the same =E2=80=9Creasonable person=E2=80=9D standard that we=
use for people. Did the system do what a reasonable person would have tak=
en the request to mean? Answering that requires human judgment.
If we get the measurement right=2C it enables things that aren=E2=80=99t p= ossible today=2C like policies concerning AI behavior. In a courtroom=2C t=
he concept of mens rea [
https://www.law.cornell.edu/wex/mens_rea]=2C what=
someone meant to do=2C is often as important as what they did. The Genie=
coefficient suggests an AI analogue=2C where a user is accountable for th=
e plain intent of what they asked the AI. If an AI system betrays the reas= onable meaning of an instruction=2C that=E2=80=99s the AI=E2=80=99s misbeh= avior=2C not the user=E2=80=99s.
We=E2=80=99ll need multiple benchmarks to measure the Genie coefficient=2C=
because genie-like behavior can be domain specific. An AI coding agent ma=
y need to be judged on how often it fakes the tests=2C or swallows errors=
=2C or colors outside the lines on its way to a solution. An AI legal agen=
t will need to be judged on how often its output says what you asked but m= eans something you=E2=80=99ll regret. And so on for medical=2C finance=2C=
and other domains of knowledge and expertise.
Genie benchmarks can be built inside out=2C each task seeded with a choice=
that might literally satisfy but that a reasonable person rejects=2C such=
as tempting misreadings or unsanctioned shortcuts. The traps in a Genie c= oefficient benchmark might turn on situational knowledge=2C the kind of co= ntext that a reasonable person [
https://spectrum.ieee.org/prompt-injectio= n-attack] would bring to the task. Another approach is to give the same re= quest in several different contexts=2C each with a different reasonable co= urse of action.
A Genie benchmark should be permissive and make it genuinely tempting for=
an AI agent to take unreasonable shortcuts=2C because it can only find ge=
nie behavior when it=E2=80=99s actually possible. Test the AI in a safe=2C=
walled-off copy of a real system=2C with real tools it can misuse and som=
e tasks that can=E2=80=99t be done honestly at all. Make the temptation to=
cut corners real. Test a diverse array of skills=2C use cases=2C and tool= s=2C and give the AI system sparse=2C confusing=2C or overwhelming context=
=2E Include tasks that people have learned=2C through experience=2C require=
human oversight.
How the benchmark is scored matters just as much. Measure Dionysus and gol=
em genies separately and together=2C based on their worst=2C not best=2C b= ehavior. Run the same model inside harnesses that vary its freedom to act=
=2C revealing which limits actually keep it in line and should therefore b=
e required in AI harness policies. Weight each failure by the harm it woul=
d cause=2C not just a simple count. And don=E2=80=99t measure genie behavi=
or in isolation: A model could otherwise earn a perfect score by stalling=
=2C refusing=2C or drowning the user in clarifying questions without ever=
doing the job. The first versions of these benchmarks will be crude=2C bu=
t that=E2=80=99s how benchmarks always start.
We have built genies. We have handed them our data and credentials. We mad=
e them relentless=2C creative=2C and indifferent to the gap between what w=
e tell them and what we mean. The least we can do=2C before they are booki=
ng our flights=2C running our infrastructure=2C and signing contracts unsu= pervised=2C is to measure how often they betray us.
** *** ***** ******* *********** *************
** COGNYTE SELLS A MOBILE CELL SURVEILLANCE VAN ------------------------------------------------------------
[2026.07.27] [
https://www.schneier.com/blog/archives/2026/07/cognyte-sel= ls-a-mobile-cell-surveillance-van.html] Yet another Israeli mass surveilla=
nce company [
https://www.forbes.com/sites/thomasbrewster/2026/07/13/israe= ls-palantir-rival-is-selling-1-million-spy-vans-to-us-cops/]:
Made by Israeli surveillance company Cognyte=2C the tech simulates a mob=
ile phone tower=2C which forces nearby phones to connect to it. That enabl=
es cops to keep tabs on any phones in the vicinity whether they=E2=80=99r=
e owned by a suspect in a case or not. Cognyte=E2=80=99s contract with the=
state of Texas reveals that the simulator=2C called FalcoNet=2C can be co= ncealed within the vehicles=2C hidden in a backpack for on-foot missions o=
r attached to a helicopter. It=E2=80=99s the same technology as the infamo=
us Stingray=2C one of the original cell-site simulators made by defense gi=
ant L3Harris.
** *** ***** ******* *********** *************
** AXON IS ANOTHER LICENSE PLATE SURVEILLANCE COMPANY ------------------------------------------------------------
[2026.07.28] [
https://www.schneier.com/blog/archives/2026/07/axon-is-ano= ther-license-plate-surveillance-company.html] Governments are switching=2C=
but I=E2=80=99m not sure it makes a difference [
https://www.jalopnik.com= /2215173/flock-cameras-replaced-by-axon-difference/]:
...some municipalities=2C including Denver=2C Colorado=2C are ditching t=
heir Flock arrays. But keep in mind that if they=E2=80=99re only switching=
from Flock to another brand of license-plate readers=2C like Axon=2C it= =E2=80=99s like a gambling addict trying to kick the habit by switching fr=
om FanDuel to DraftKings.
[...]
Despite what you may read on the Flock website=2C Axon cameras are prett=
y effective when it comes to hoovering up personal details that can go far=
beyond your license plate numbers. That means a municipality that opts fo=
r Axon cameras instead of Flock units won=E2=80=99t necessarily reduce the=
amount privacy its citizens lose through their use.
** *** ***** ******* *********** *************
** MEASURING LLMS' ABILITY TO PERFORM CRYPTANALYSIS ------------------------------------------------------------
[2026.07.28] [
https://www.schneier.com/blog/archives/2026/07/measuring-l= lms-ability-to-perform-cryptanalysis.html] There=E2=80=99s new benchmark m= easuring AI=E2=80=99s ability to perform mathematical cryptanalysis. Anthr= opic=E2=80=99s frontier model actually found new attacks.
The benchmark: =E2=80=9CCryptanalysisBench: Can LLMs do Cryptanalysis? [h= ttps://arxiv.org/pdf/2607.18538]=E2=80=9D The idea is to benchmark the abi= lity of LLMs to discover new mathematical cryptanalytic attacks against a=
series of historical algorithms.
Abstract: Cryptanalysis -- the task of finding attacks against cryptogra=
phic schemes -- its at the intersection of mathematical reasoning and cybe= rsecurity=2C two areas where LLMs have advanced fastest. Cryptanalysis rep= resents both a clean testbed for frontier reasoning (as practical attacks=
can be automatically verified) and a domain with unusually high stakes=2C=
since the primitives under study underpin our digital security. In this p= aper we ask whether LLMs can do cryptanalysis=2C and find that the answer=
is increasingly yes. We introduce CryptanalysisBench=2C 191 tasks across=
six families of cryptographic primitives (block ciphers=2C hash functions=
=2C etc.) drawn primarily from four NIST standardization competitions. Our=
benchmark consists of three tiers: (i) primitives with known practical br= eaks; (ii) primitives with no known practical break=2C evaluated both at f=
ull strength and as scaled-down variants; and (iii) a challenge set of pro= duction primitives at the frontier of cryptanalysis. Five frontier models=
(Claude Opus 4.8=2C Sonnet 5=2C Mythos 5=2C GPT-5.5=2C and the open-weigh=
ts GLM-5.2) break 65%86% of Tier 1 schemes=2C 612 Tier-2 schemes at full s= trength=2C and 2461 across all scaled-down variants. Beyond deriving known=
results=2C models produce novel cryptanalysis=2C such as a key-recovery a= ttack that exploits a design flaw in the SpoC AEAD and an error in KINDI= =E2=80=99s published CCA-security proof=2C both to the best of our knowled=
ge not previously known.
We release CryptanalysisBench as a tool to help track if (or when) AI cr=
yptanalysis becomes a serious factor and as a scaffold for stress-testing=
candidate schemes before deployment. The attacks that the benchmark alrea=
dy surfaces are an early snapshot of a fast-moving frontier that may soon=
match=2C and in places exceed=2C the published state of the art.
Anthropic used the benchmark to test Mythos Preview=2C and found [https:/= /www.anthropic.com/research/discovering-cryptographic-weaknesses] new vuln= erabilities in Hawk and reduced-round AES.
Still early results=2C but this is definitely something to watch.
SlashDot thread [
https://it.slashdot.org/story/26/07/28/1911218/anthropic= -ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms].
** *** ***** ******* *********** *************
** LONG-LIVED VULNERABILITY IN MICROSOFT SECURE BOOT ------------------------------------------------------------
[2026.07.29] [
https://www.schneier.com/blog/archives/2026/07/long-lived-= vulnerability-in-microsoft-secure-boot.html] Microsoft=E2=80=99s Secure Bo=
ot has had a serious vulnerability [
https://arstechnica.com/security/2026= /07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/] for=
most of its existence.
An industry-wide standard Microsoft invented to protect Windows=2C and l=
ater Linux=2C devices from firmware infections has been trivial to bypass=
for 13 of its 14 years of existence. The discovery was made by researcher=
s at security firm ESET after identifying 11 firmware images=2C at least o=
ne from 2013=2C that were known to be defective but remained signed by the=
software company anyway.
The images are known as shims [https://en.wikipedia.org/wiki/Shim_(comp=
uting)]=2C which were invented to extend Secure Boot to Linux devices and=
utility software. Using a technique simple enough to be performed by novi=
ce hackers=2C these old=2C forgotten shims can be used to completely circu= mvent the protection=2C which is embedded into the UEFI (Unified Extensibl=
e Firmware Interface) of the device=E2=80=99s motherboard. The gaffe is th=
e result of the failure by Microsoft=2C which oversees the signing of shim= s=2C to revoke the publicly available images once vulnerabilities were fou=
nd in them.
** *** ***** ******* *********** *************
** MEASURING THE TENDENCY OF AI AGENTS TO GO ROGUE ------------------------------------------------------------
[2026.07.29] [
https://www.schneier.com/blog/archives/2026/07/measuring-t= he-tendency-of-ai-agents-to-go-rogue.html] _This essay was written with Ba= rath Raghavan=2C and originally appeared in The Guardian [
https://www.the= guardian.com/commentisfree/2026/jul/28/rogue-ai-agent-instructions]._
In July=2C Hugging Face=2C a company that hosts much of the world=E2=80=99=
s AI software and open-source AI models=2C was hacked. A malicious dataset=
had been used to run code on one of its servers. Whoever was behind it ca= ptured internal security credentials and moved through systems over a week= end=2C running thousands of actions from a swarm of temporary server envir= onments. It looked like the work of a sophisticated criminal group.
It was not. It was one of OpenAI=E2=80=99s new=2C still unreleased GPT mod= els.
Their science experiment had escaped [
https://www.theguardian.com/technol= ogy/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-un= precedented-incident] the lab. OpenAI was running the unreleased AI model=
through a benchmark that tests how well AI can successfully hack systems.=
To push the limits and evaluate the AI=E2=80=99s true capability=2C the c= ompany switched off the safety filters that normally stop it from doing th=
is kind of hacking. Aware that this could go wrong=2C they confined the AI=
to an isolated environment and denied it access to the internet.
But the new AI cheated. It took literally its goal to get as high of a sco=
re as possible. It broke out on to the open internet. It inferred=2C proba=
bly from its training data=2C that it could =E2=80=9Csolve=E2=80=9D the ta=
sk by getting the answers from Hugging Face=E2=80=99s servers. So it chain=
ed together stolen credentials and further unknown security exploits to ha=
ck the company=E2=80=99s network.
Nobody instructed the AI to do any of this. It was=2C in OpenAI=E2=80=99s=
words [
https://openai.com/index/hugging-face-model-evaluation-security-i= ncident/]=2C =E2=80=9Chyperfocused on finding a solution=E2=80=9D to the t=
est it was being given. And while this might seem like something new with=
AI=2C it=E2=80=99s really very old. This is how a genie behaves=2C and it=
is a key challenge with AI agents in general.
In folklore=2C genies -- and other magical beings -- grant wishes literall= y=2C not how the wisher intended. King Midas asked that everything he touc=
hed turn to gold=2C and starved. The sorcerer=E2=80=99s apprentice wanted=
the broom to fill the cistern=2C and it performed its task so well that i=
t flooded the house.
We now have machines that do this. Ask a modern AI agent to save money on=
your phone plan and it might simply cancel the plan. Tell it to book a fl= ight=2C and it might hack the airline website to override restrictions. Or=
=2C like OpenAI=2C ask it to do well on a test and it might break into ano= ther company to steal the answers. Each time=2C it recognizably completed=
the task you set=2C but it didn=E2=80=99t do what you would have wanted.
This isn=E2=80=99t malicious behavior. No one asked for=2C or wanted=2C Hu= gging Face to be hacked. OpenAI and Hugging Face and the AI were ostensibl=
y on the same side=2C and the AI was trying to do what it had been asked.=
That=E2=80=99s what makes it so difficult to guard against: you can=E2=80= =99t filter for bad instructions because the instructions were fine.
The gap is between the words we use and what we mean by them. We call that=
gap the Genie coefficient [
https://spectrum.ieee.org/ai-agent-benchmark]=
=2E
AI labs know this is a problem=2C and they=E2=80=99re quietly saying so. F=
or example=2C the Chinese lab Moonshot recently warned [
https://www.kimi.= com/blog/kimi-k3] that its latest AI model may have =E2=80=9Cexcessive pro= activeness=E2=80=9D and =E2=80=9Cmake unexpected decisions on the user=E2= =80=99s behalf=E2=80=9D. The UK=E2=80=99s AI Security Institute has starte=
d tracking [
https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-m= odel-evaluations] =E2=80=9Ccheating behavior in frontier model evaluations= =E2=80=9D. We wouldn=E2=80=99t tolerate a car that is excessively proactiv=
e [
https://simonwillison.net/2026/Jun/11/fable-is-relentlessly-proactive/=
] or ruthlessly efficient [
https://www.theatlantic.com/technology/2026/07= /openai-hugging-face-hack/688025/?utm_source=3DSailthru&utm_medium=3Demail= &utm_campaign=3DAtlantic%20Intelligence%20%28V3%29]=2C and yet that=E2=80=
=99s the reality of AI today.
Improvement is possible. Just as AIs have gotten much better at resisting=
prompt injection attacks over the last few years=2C we can safely predict=
that they will get better at avoiding genie-like behavior. The point of t=
he Genie coefficient is to track progress. AI companies like benchmarks=2C=
and they all work to compete to be the best.
Dozens of benchmarks and leaderboards tell us how well these AI models wri=
te code=2C perform logical reasoning=2C and pass standardized legal and me= dical exams. But there is nothing that scores whether a system does what y=
ou actually meant. We need to develop a measure for this=2C test it regula= rly=2C and push for improvement. We=E2=80=99re not going to have trustwort=
hy AI agents without it.
** *** ***** ******* *********** *************
** SHOULD YOU USE AI FOR A TASK? HERE=E2=80=99S A SIMPLE WAY TO DECIDE ------------------------------------------------------------
[2026.07.30] [
https://www.schneier.com/blog/archives/2026/07/should-you-= use-ai-for-a-task-heres-a-simple-way-to-decide.html] _This essay originall=
y appeared in The Guardian [
https://www.theguardian.com/commentisfree/202= 6/jul/24/should-you-use-ai]._
I teach public policy at the Harvard Kennedy School and the Munk School at=
the University of Toronto. And it will come as no surprise to you that my=
students regularly use AI [
https://www.insidehighered.com/news/faculty/l= earning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used= -ai-cheat] to complete their writing assignments. Doing so is a waste of t= heir tuition money. But if their entire career is going to include AI writ=
ing assistants=2C why shouldn=E2=80=99t they embrace their future?
The best way I=E2=80=99ve found to explain the dilemma comes from [https:= //danielmiessler.com/blog/keep-the-robots-out-of-the-gym] the AI researche=
r Daniel Meissler: it=E2=80=99s the difference between work and the gym.
At work=2C if your job is to move a bunch of heavy things from one side of=
the room to another=2C you should use whatever assistive tech you have on=
hand: a wagon=2C a forklift... even an AI-powered robot. But at the gym=
=2C it makes no sense for that robot to lift weights for you. The point of=
weightlifting isn=E2=80=99t to move heavy things across the room; it=E2= =80=99s to actually lift those heavy things.
The same analysis holds for any task an AI can do for you. If it=E2=80=99s=
work -- if the task has to be done and no one cares how -- then it=E2=80=
=99s fine to use AI assistance. But if the task is more like the gym=2C an=
d _how_ the task is done is at least as important=2C then it probably does= n=E2=80=99t make sense to use AI.
This=2C of course=2C assumes that the AI is actually up for the task and t=
hat it=E2=80=99s trustworthy [
https://www.schneier.com/academic/archives/= 2025/06/ai-and-trust.html]: that it can do the job well=2C that its mistak=
es are minimal and correctable=2C that it=E2=80=99s been secured from cybe= r-attacks that would influence its results. Those are all important=2C and=
shouldn=E2=80=99t be minimized. There=E2=80=99s no point giving an AI som= ething that it can=E2=80=99t do reliably. But once you=E2=80=99re confiden=
t that the AI can perform the task=2C the work vs. gym distinction helps y=
ou decide if it should.
The writing assignments I give my students are gym tasks=2C not work tasks=
=2E I ask them to write policy memos not because the world needs more policy=
memos. I assign them because the very act of writing=2C which includes th= inking and outlining and drafting and editing=2C making and criticizing an=
d revising arguments=2C will help develop the critical thinking skills the=
y will need in their future careers. And without this constant mental exer= cise=2C those skills will atrophy. Employers are already noticing [https:= //futurism.com/future-society/college-critical-thinking-ai].
Reading the assignments they turn in=2C I can see those skills either flou= rishing or atrophying in my students. At least today=2C I can pretty easil=
y tell the difference between an AI-written memo and a student-written one=
-- especially if the student just turns in what the chatbot produces. It= =E2=80=99s a catchy=2C plausible=2C grammatically perfect essay that=E2=80= =99s not particularly well-crafted or logically coherent -- and with all [=
https://medium.com/@brentcsutoras/the-em-dash-dilemma-how-a-punctuation-m= ark-became-ais-stubborn-signature-684fbcc9f559] the [
https://www.theatlan= tic.com/technology/2026/07/ai-chatbot-writing-tic-negative-parallelism/687= 892/] tells [
https://www.forbes.com/sites/charliefink/2025/06/12/the-seve= n-tells-of-ai-writing/] of mid-2026 AI-generated writing.
But it=E2=80=99s precisely because I have spent years developing my own wr= iting skills that I=E2=80=99m able to identify prose that sounds great but=
doesn=E2=80=99t actually make sense. My students don=E2=80=99t have that=
skill; they mistakenly view a confident=2C well-written essay as evidence=
of the quality of their ideas. They see the AI as cleaning those ideas up=
=2C getting them through that uncomfortable stretch of having to turn thos=
e ideas into prose. What the students miss is that their initial discomfor=
t is a normal and healthy stage of writing=2C and not something to quickly=
get beyond. The very act of struggling with how to express what they thin=
k is an important part of the process. It=E2=80=99s how they test out thei=
r ideas=2C examine their hypotheses=2C and actually figure out what they t= hink. Homework is not work; it=E2=80=99s the gym.
Work vs. gym also helps us understand the problem facing creatives of all=
kinds.
Most of the time when someone hires a writer=2C they just need the words.=
They need an instruction manual for a piece of equipment=2C a detailed sa=
les presentation=2C a government-mandated disclosure document=2C or a lega=
l brief. They need dry=2C predictable=2C accurate writing: a piece of work=
=2C exactly what AIs are good at today and what I don=E2=80=99t want in my=
student assignments. Only sometimes is writing an art form -- a book=2C a=
poem=2C an uplifting political speech. That kind of writing is more like=
the gym: process matters just as much as product.
For most of human history=2C the only option for all of these tasks was hu=
man writers. We hired one regardless of whether we needed work writing or=
gym writing. And that paid a lot of writers=E2=80=99 salaries. I know fic= tion writers who supported that poorly paying career with lucrative techni=
cal writing work. Now=2C for the first time in human history=2C we can sep= arate out when we need writing as work and when we want writing as gym. An=
d if AI can do most of the work-type writing=2C society doesn=E2=80=99t ne=
ed as many human writers.
It=E2=80=99s the same for visual artists. Sometimes we need an actual arti= st=2C but most of the time we just need an image: a corporate mascot=2C a=
=E2=80=9Cbeware of the dog=E2=80=9D sign=2C or a packaging label. Histori= cally we gave those jobs to artists=2C and sometimes beautiful [
https://b= log.artgeek.io/2025/10/20/art-deco-the-golden-age-of-illustration/] art re= sulted. But most of the time it was just work. And=2C as it turns out=2C t=
he world needs less pure art than simple images.
Explaining the problem isn=E2=80=99t the same as providing the solution. I=
give my students the =E2=80=9Cwork versus gym=E2=80=9D speech every class=
=2C but they still use [
https://www.insidehighered.com/news/faculty/learn= ing-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-= cheat] AI. I have sympathy: assignments are hard=2C everyone is overworked=
and overstressed=2C and -- most importantly -- students feel like they=E2= =80=99ll look bad in comparison if their peers are all using AI. Even if t=
hey don=E2=80=99t want to use the technology=2C they feel like they have n=
o choice [
https://bsky.app/profile/jeffsharlet.bsky.social/post/3mog5n2uh= js2r].
There=E2=80=99s also an incentive problem. No one pays us to go to the gym=
; maintaining healthy habits requires discipline. For me=2C the payoffs to=
exercise -- fewer aches and pains=2C less fatigue=2C better mood/stress m= anagement -- might make me a better writer and teacher=2C but they=E2=80=
=99re subtle and easy to miss. For my students=2C incremental improvements=
in their reasoning and writing are equally subtle.
We do have a choice. We can look at the tasks of our lives and separate th=
em into work or gym. Just as we might choose to use the stairs instead of=
the elevator=2C or walk instead of calling an Uber=2C we can wall off our=
cognitive gym tasks from AI and ensure that we don=E2=80=99t lose our ski=
lls to this technology. And we can do the same when we assign a job to som= eone else. If it=E2=80=99s a work task=2C we can have AI do it. If it=E2= =80=99s a gym task=2C it=E2=80=99s a waste of everyone=E2=80=99s time to g=
ive it to an AI because no one learns or gets stronger as a result.
Similarly=2C a future where AI generates words and images is one where soc= iety has to make choices about how it will treat its creatives. This won= =E2=80=99t be the first time -- today there is minimal demand for portrait=
painters=2C for example -- but maybe this time we can make different=2C m=
ore deliberate=2C choices about the value of art in our society.
AI is going to fundamentally change the nature of work. Not nearly as fast=
as the AI companies want you to believe=2C but eventually it will. Policy=
analysis will definitely involve AI from now on=2C and my students need t=
o reimagine what it means to learn and practice that skill. More generally=
=2C the line between work and gym will change in the future as we humans a= dapt ourselves to a world with these new intelligences.
But for now=2C the work vs. gym distinction is pretty clear. Use it on you= rself.
** *** ***** ******* *********** *************
** AMERICAN BEING PROSECUTED FOR WIPING HIS PHONE BEFORE HANDING IT OVER T=
O BORDER OFFICIALS
------------------------------------------------------------
[2026.07.30] [
https://www.schneier.com/blog/archives/2026/07/american-be= ing-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-offic= ials.html] He=E2=80=99s being prosecuted for giving border officials a cod=
e that wiped his phone [
https://techcrunch.com/2026/07/24/us-accuses-amer= ican-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-s= earch/]:
The case centers on a feature included in GrapheneOS=2C a custom Android=
operating system that runs in place of the software on most modern Google=
Pixel devices. Tunick=E2=80=99s attorneys confirmed GrapheneOS was runnin=
g on his phone.
The software feature allows the device owner to set a passcode that deli=
berately wipes the contents of that device if entered instead of the user= =E2=80=99s unlock passcode.
Tunick=E2=80=99s case also raises ongoing questions about what constitut=
ional rights can be invoked at the border=2C which the U.S. government has=
long asserted is not U.S. soil until a person is authorized to enter.
Right. And he wasn=E2=80=99t under arrest=2C either.
Three more [
https://www.theguardian.com/us-news/2026/jul/23/cop-city-prot= ester-phone] news [
https://boingboing.net/2026/07/25/grapheneos-duress-pa= ssword-border-search.html] stories [
https://gizmodo.com/a-feature-that-ma= kes-your-phone-data-self-destruct-in-authorities-hands-may-soon-have-its-d= ay-in-court-2000790831].
Graphene says [
https://www.pcmag.com/news/grapheneos-defends-data-wiping-= function-that-blocked-us-border-search] that the feature is =E2=80=9Ccompl= etely legal [
https://x.com/GrapheneOS/status/2081770030992118183]=E2=80=
=9C:
GrapheneOS is completely legal. We have no obligation to weaken any of t=
he security protections it provides. Creating and using GrapheneOS is stro= ngly protected by the US constitution. Laws attempting to make it illegal=
or require weakening the security would be unconstitutional.
It=E2=80=99s hard to know how much the Constitution matters in the US righ=
t now.
** *** ***** ******* *********** *************
** FACIAL RECOGNITION AT MADISON SQUARE GARDEN ------------------------------------------------------------
[2026.07.31] [
https://www.schneier.com/blog/archives/2026/07/facial-reco= gnition-at-madison-square-garden.html] Last month=2C the story broke [htt= ps://www.404media.co/madison-square-garden-made-dossier-on-activists-who-o= pposed-facial-recognition/] (alternate link [
https://archive.ph/ZGqfH]) t=
hat Madison Square Garden uses facial recognition software on everyone ent= ering the facility=2C and -- among other groups -- flags activists that op= pose using facial recognition.
Turns out that the system was shut off [
https://www.wired.com/story/for-t= aylor-swift-madison-square-gardens-controversial-cameras-briefly-went-dark=
/] for Taylor Swift=E2=80=99s wedding.
Evan Greer -- one of the people that MSG alerts on -- comments [
https://w= ww.ms.now/opinion/taylor-swift-and-travis-kelce-got-to-buy-msgs-privacy-he= r-fans-arent-so-lucky]:
Ironically=2C Swift herself has reportedly [https://www.rollingstone.co=
m/music/music-news/taylor-swift-facial-recognition-concerts-768741/] used=
facial recognition at her own concerts to identify stalkers. This =E2=80= =9Cprivacy for me=2C surveillance for thee=E2=80=9D attitude feels like a=
perfect encapsulation of the future we=E2=80=99re already living in: one=
where wealthy elites can afford privacy=2C while the rest of us are force=
d to live in a corporate surveillance panopticon.
Whatever privacy measures Swift had in place for the wedding seems to have=
worked. No photos have leaked online.
** *** ***** ******* *********** *************
** ANTHROPIC=E2=80=99S OPUS 5 IS BETTER AT RESISTING PROMPT INJECTION ------------------------------------------------------------
[2026.07.31] [
https://www.schneier.com/blog/archives/2026/07/anthropics-= opus-5-is-better-at-resisting-prompt-injection.html] The chart [
https://w= ww-cdn.anthropic.com/c5fbac3f0b1280a933ebd26d3cb8bb9f5bdeaf48/Claude%20Opu= s%205%20System%20Card.pdf#page=3D73] is interesting.
On the IPI benchmark=2C Opus 5 improved over Opus 4.8=2C reducing the pr=
obability of an attacker succeeding within 15 attempts from 5.5% to 2.0%=
=2C and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9%=
at k=3D15) and Mythos 5 (2.6%)=2C making it the most robust model evaluat=
ed. Opus 5 also outperformed all non-Claude models on this benchmark. The=
most robust non-Claude model was Muse Spark at 16.5% within 15 attempts -=
- more than eight times Opus 5=E2=80=99s rate. The most capable GPT 5.6 va= riant=2C Sol=2C was comparable to its predecessor GPT 5.5 (20.0% versus 20= =2E8% within 15 attempts)=2C and was 10 times as likely to be successfully a= ttacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robu= st=2C at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6=
Sol succeeded 3.1% of the time=2C higher than the 2.0% an attacker achiev=
ed against Opus 5 after fifteen attempts.
We know that preventing prompt injection is impossible [
https://llm-attac= ks.org/] in the general case. But we are getting much better at blocking i=
t in specific cases.
** *** ***** ******* *********** *************
** THE OPENAI HACK SHOWS THE GENIE IS OUT OF THE BOTTLE ------------------------------------------------------------
[2026.08.03] [
https://www.schneier.com/blog/archives/2026/08/the-openai-= hack-shows-the-genie-is-out-of-the-bottle.html] _This essay originally app= eared in Foreign Policy [
https://foreignpolicy.com/2026/07/30/openai-hack= -genie-bottle-defense/]._
Earlier this month=2C two of OpenAI=E2=80=99s models broke out of their co= ntainment sandbox and attacked another AI company. The story [
https://www= =2Enytimes.com/2026/07/21/technology/openai-attack-hugging-face.html] is kin=
d of wild [
https://simonwillison.net/2026/Jul/22/openai-cyberattack/]. Op=
enAI was running security tests on two of its models: GPT-5.6 Sol and an u= nreleased model that is almost certainly GPT-6. In particular=2C it was ru= nning the ExploitGym [
https://arxiv.org/abs/2605.11086] benchmark=2C whic=
h measures how good a model is at turning security vulnerabilities into wo= rking exploits: basically=2C offensive cyberattacks.
Since these were internal tests=2C OpenAI locked those models in a secure=
sandbox that denied them access to the internet. But it was running the m= odels without any safety filters that would prevent them from offensive cy= ber-actions. That meant that there was nothing to prevent the models from=
trying to break out [
https://huggingface.co/blog/security-incident-july-= 2026] of that sandbox. And then break into [
https://openai.com/index/hugg= ing-face-model-evaluation-security-incident/] AI company Hugging Face=E2= =80=99s network because they thought that they could read the answers ther=
e rather than doing the hard work of trying to solve the puzzles.
It was a major security failure that the company has turned into a PR oppo= rtunity=2C but the implications are real -- and much more general than one=
particular model or one particular company.
Modern AI models exhibit genie [
https://spectrum.ieee.org/ai-agent-benchm=
ark] behavior: They can do what you ask in ways that you don=E2=80=99t exp=
ect or want. This is akin to Dionysus granting King Midas=E2=80=99s wish t=
hat everything he touches turn to gold (spoiler: His food=2C drink=2C and=
daughter all turn to gold on touch)=2C or the golem of Prague [
https://p= rague.eu/en/golem-of-prague/] guarding a ghetto beyond all reason. It=E2= =80=99s Disney=E2=80=99s =E2=80=9CSorcerer=E2=80=99s Apprentice [
https://= disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice]=E2=80=9D and the paper= clip maximizer [
https://www.lesswrong.com/w/squiggle-maximizer-formerly-p= aperclip-maximizer].
This OpenAI incident is an example of an AI genie. The goal was to satisfy=
the benchmark. The =E2=80=9Cproper=E2=80=9D way to do that is to figure o=
ut how to execute various cyberattacks. The genie way is to steal someone=
else=E2=80=99s solution. But because the model didn=E2=80=99t understand=
the difference=2C it chose the easier path.
And=2C of course=2C now that we have seen this particular genie behavior=
=2C we can specify in the benchmark prompt that stealing the test answers=
doesn=E2=80=99t count. But a clever genie can always grant your wish in a=
way that you wish it hadn=E2=80=99t. In human language=2C goals are alway=
s underspecified -- so AI genies will always be [
https://www.schneier.com= /academic/archives/2021/04/the-coming-ai-hackers.html] a possibility.
Since April=2C a lifetime ago in AI development=2C when Anthropic announce=
d [
https://www.anthropic.com/research/mythos-preview] that its new Mythos=
model was so good at finding software vulnerabilities that it could not b=
e released to the general public=2C the big American AI frontier labs have=
been trying to block general users from accessing these capabilities. But=
nothing in this incident is exclusive to OpenAI=E2=80=99s=2C or Anthropic= =E2=80=99s=2C frontier models.
Agentic AI systems have two important parts. There=E2=80=99s the underlyin=
g model=2C which everyone talks about=2C and there=E2=80=99s the harness [=
https://www.theneuron.ai/explainer-articles/ai-harnesses-and-clis-explain= ed-the-real-reason-everyones-talking-about-infrastructure/]. The harness s=
its between what you type and what the model sees=2C and what the model pr= oduces and what you see. The harness determines what the model does and ho=
w it does it. It=E2=80=99s where bias is removed=2C or not. It=E2=80=99s w= here controls [
https://medium.com/@michael.hannecke/safety-lives-in-the-h= arness-not-the-model-81090606f92d] and guardrails live. If multiple models=
are being used in concert=2C the harness is where all of that is coordina= ted.
The OpenAI benchmark tests were almost certainly with simple harnesses=2C=
to better test the raw models. But we know that smaller=2C cheaper=2C ope= n-source models with more sophisticated [
https://www.theguardian.com/comm= entisfree/2026/jun/16/anthropic-fable-ai] harnesses can equal frontier mod=
els in performance. There=E2=80=99s nothing magic about OpenAI=E2=80=99s f= rontier models; lots of models could have done the same thing [
https://x.= com/tqbf/status/2080045032162173329].
The Czech company Aisle was able to reproduce [
https://aisle.com/blog/ai-= cybersecurity-after-mythos-the-jagged-frontier] Anthropic=E2=80=99s Mythos=
vulnerability finding results with a smaller=2C cheaper model and a more=
sophisticated harness. More importantly=2C the Chinese company Moonshot A=
I just released its frontier model: Kimi K3 [
https://www.kimi.com/blog/ki= mi-k3]. Its performance rivals [
https://www.interconnects.ai/p/kimi-k3-th= e-open-weights-escalation] its US competitors. And it=E2=80=99s both free=
and open=2C which means it=E2=80=99s not possible for it to have guardrai=
ls. If you=2C or anyone else=2C wants to use it for cyberattack=2C nothing=
can stop you.
Even if the US frontier AI companies had some technical advantage=2C it=E2= =80=99s now only a few months=E2=80=99 worth.
What this means is that all attempts at control -- limiting models to a se= lect [
https://www.anthropic.com/glasswing] group [
https://openai.com/day= break/] of users=2C export controls [
https://www.csis.org/analysis/unders= tanding-us-allies-current-legal-authority-implement-ai-and-semiconductor-e= xport] on models and chips=2C blocking [
https://freefable.org/] models fr=
om answering certain types of queries=2C mandating kill switches [https:/= /www.bbc.com/news/articles/cx2vqj2e9x8o] on AI systems=2C or pausing [htt= ps://pauseai.info/] AI research -- are all futile. Most only apply nationa= lly=2C not globally. Most don=E2=80=99t affect models that users run local=
ly and not in the cloud. And all ignore the incredible pace of AI developm=
ent worldwide.
Even worse=2C US companies limit access to their most sophisticated models=
=2C fearing being banned by the government if they do not do so. When Hugg=
ing Face was attacked=2C it was not able to use the frontier models from e= ither OpenAI or Anthropic to help analyze the attack and formulate defense=
s. Both were blocked=2C because both of those companies limit their models= =E2=80=99 cybersecurity capabilities. Some US companies have special acces=
s to these capabilities=2C but Hugging Face is an American company with Fr= ench origins=2C and as such is probably excluded. Instead=2C Hugging Face=
turned to the GLM-5.2 [
http://z.ai/blog/glm-5.2] model from the Chinese=
company Z.ai.
Artificially blocking capability also prevents cybersecurity research=2C a= gain giving the offense an advantage. (For instance=2C Claude Fable 5 refu=
ses to edit this essay because of the topic; it forcibly downgrades to a l=
ess capable model.) This kind of prohibition has long-term implications fo=
r cybersecurity. If we assume that these models are getting better over ti= me=2C then software written by older models will be attacked by newer ones=
=2E In a world of largely AI-written software=2C we need the most capable mo= dels for defense.
AI cyberattack is the new normal. The models are increasingly highly sophi= sticated at both attack and defense=2C and there is no way to enable the l= atter without also enabling the former. And they are genies=2C increasingl=
y capable of behaving in unanticipated ways.
And there really are no good answers. Any regulation needs to be global=2C=
which feels like an impossible prospect in today=E2=80=99s world. Even US=
national regulation will be neutered by the massive amounts of money slos= hing around in these companies.
Given that reality=2C and in the absence of any international consensus on=
AI regulation=2C we need the best AI on the defense. The US government ne=
eds to make it clear -- or whatever passes for that clarity in this capric= ious administration -- that it will not ban models with sophisticated cybe=
r capabilities. The last thing Americans want is for the defenders to turn=
to Chinese and other models because the US models are artificially hobble=
d.
** *** ***** ******* *********** *************
** MORE ON THE OPENAI AGENT=E2=80=99S ATTACK ON HUGGING FACE ------------------------------------------------------------
[2026.08.03] [
https://www.schneier.com/blog/archives/2026/08/more-on-the= -openai-agents-attack-on-hugging-face.html] Hugging Face has published [h= ttps://huggingface.co/blog/agent-intrusion-technical-timeline] a detailed=
timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation bas=
ed on the ExploitGym benchmark=2C which tasks an AI agent with finding and=
exploiting software vulnerabilities. OpenAI ran this on its own infrastru= cture=2C and the ExploitGym maintainers and their infrastructure had no in= volvement in the deployment or operation of that evaluation environment. A=
s far as we were able to infer=2C across the course of being evaluated on=
this benchmark=2C the agent inferred that Hugging Face may host that benc= hmark=E2=80=99s models=2C datasets=2C and reference solutions. We believe=
the entire intrusion was=2C from the agent=E2=80=99s point of view=2C an=
attempt to cheat the evaluation: reach our production systems and steal t=
he test solutions rather than solve the challenge on its own.
Our forensic reconstruction covers ~17=2C600 attacker actions that we we=
re able to recover=2C grouped into ~6=2C280 clusters=2C between 2026-07-09=
02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from t=
he agent=E2=80=99s logs on a code sandbox used by the agent (see below) an=
d were able to map them to shell commands as well as evaluation submission=
s and correlate actions with our own platform logs=2C in particular from t=
he dataset processor nodes=2C API=2C and pod. Using open-weights models=2C=
in particular zai-org/GLM-5.2=2C we were able to decipher most of the age=
nt payloads (see below) that were encrypted via chunking and key encryptio=
n.
The campaign=2C as we were able to reconstruct it=2C had two stages:
* Stage 1: reaching a launchpad by chaining through other parties=
=E2=80=99 infrastructure. As documented in OpenAI=E2=80=99s blog post (htt= ps://openai.com/index/hugging-face-model-evaluation-security-incident/)=2C=
during an internal capability evaluation on OpenAI=E2=80=99s platform=2C=
the agent escaped its sandbox by exploiting a zero-day in the package reg= istry cache proxy=2C one of its primary permitted network egress with inte= rnet=2C then abused a public code-evaluation harness hosted by a user of a=
third-party infrastructure provider. It was able to run commands as root/= admin on that external sandbox and used it as a control=2C staging=2C and=
egress base for the entire campaign: it acted as an external launchpad fo=
r the agent. That compromised external sandbox had no direct network path=
to our cluster; however=2C during our counter-intervention to stop the in= trusion=2C we were able to retrieve some of the agent logs from this exter=
nal launchpad. We used those to reconstruct the present forensic analysis.
* Stage 2: the intrusion into Hugging Face infrastructure. From tha=
t external launchpad=2C the agent abused our dataset-processing pipeline v=
ia two injection vectors=2C both targeting the same config-driven data loa=
der within our production Kubernetes pods. The first vector was an HDF5 ex= ternal raw storage dataset read that returned the contents of local files:=
it handed the agent the pod=E2=80=99s environment (secrets and tokens) an=
d the worker=E2=80=99s own source. The second vector was a Jinja2 template=
injection that executed arbitrary code=2C giving the agent a foothold ins=
ide our perimeter.
Once a prod-pod foothold was established=2C the agent followed a standar=
d escalation shape: recon=2C drop a stager=2C establish Command-and-Contro=
l (C2)=2C then pivot into the cluster=2C into cloud metadata=2C into our i= nternal network=2C and into our source-control supply chain. Output from t=
he commands run inside our pod was sent back to the agent via the HF API a=
nd attacker-controlled dead-drop datasets=2C which the agent then read fro=
m that sandbox.
While the intrusion did reach Hugging Face=E2=80=99s internal infrastruc=
ture=2C the only customer content accessed was five datasets whose names a=
nd files suggest a connection to ExploitGym/CyberGym challenges and soluti= ons. No other customer-facing models=2C datasets=2C Spaces=2C or packages=
were affected=2C and the only customer records read were operational meta= data tied to search queries against the dataset server.
Hypothetical: Imagine that this wasn=E2=80=99t an OpenAI model. Imagine th=
at it was a Chinese model from a Chinese company. This would be an interna= tional crisis.
Question: Why aren=E2=80=99t we bringing OpenAI up on charges under the Co= mputer Fraud and Abuse Act? How is this different from the Morris Worm [h= ttps://en.wikipedia.org/wiki/Morris_worm]? That was also an experiment tha=
t escaped the lab.
** *** ***** ******* *********** *************
** SOME CLAUDE CHATS ARE SEARCHABLE ON GOOGLE ------------------------------------------------------------
[2026.08.04] [
https://www.schneier.com/blog/archives/2026/08/some-claude= -chats-are-searchable-on-google.html] And it=E2=80=99s personal informatio=
n [
https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are= -exposed-on-google/] (alternate link [
https://archive.ph/sl7rU]):
The exposed data includes an AI-powered therapy app that someone appears=
to have vibe-coded=2C notes on meetings=2C and a dashboard someone made a= pparently to analyze medical billing data. Exposed chats reportedly includ=
e private cryptocurrency wallet keys and personal information like peoples= =E2=80=99 addresses.
What seems to be the issue is a user setting about data sharing. Anthropic= =E2=80=99s position is that it=E2=80=99s not their problem [
https://futur= ism.com/artificial-intelligence/claude-chats-publicly-accessible]:
=E2=80=9CWe give people control over sharing their Claude conversations=
publicly=2C and in keeping with our privacy principles=2C we do not share=
chat directories or sitemaps with search engines like Google=2C=E2=80=9D=
the company said in a statement. =E2=80=9CThese shareable links are not g= uessable or discoverable unless people choose to share them themselves. Wh=
en someone shares a conversation=2C they are making that content publicly=
accessible=2C and like other public web content=2C it may be archived by=
third-party services.=E2=80=9D
Here=E2=80=99s [
https://support.claude.com/en/articles/10593882-share-and= -unshare-chats] how to fix it.
** *** ***** ******* *********** *************
** IRAN CYBERATTACKS AGAINST MINNESOTA WATER SYSTEMS ------------------------------------------------------------
[2026.08.04] [
https://www.schneier.com/blog/archives/2026/08/iran-cybera= ttacks-against-minnesota-water-systems.html] Attribution [
https://www.nyt= imes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html] is=
[
https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agen= cies-suspect-iran-launched-cyberattack-minnesota-water-facilities/] prelim= inary [
https://thehill.com/policy/technology/6001284-minnesota-water-faci= lities-cyberattack-investigation-us-iran/amp/]=2C and so far it seems no r=
eal damage.
And it seems like this is a campaign that has targeted at least seven stat=
es [
https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water= -systems.html?unlocked_article_code=3D1.2FA.xPwI.F0C0GgLEjGZc&smid=3Dnytco= re-ios-share]. And=2C because this is where the US is right now=2C Trump d= oesn=E2=80=99t believe it=E2=80=99s Iran and thinks Minnesota...I guess...= hacked itself.
=E2=80=9CI think I blame it on Minnesota because they=E2=80=99re grossly=
incompetent=2C=E2=80=9D Trump said. =E2=80=9CI would blame it on Minnesot=
a and the governor=2C the corrupt governor of Minnesota. They like to say=
=2C =E2=80=98Oh=2C it=E2=80=99s Iran.=E2=80=99 Iran should be so lucky. Ir= an=E2=80=99s got bigger problems than worrying about Minnesota.=E2=80=9D
No word on whether he believes the other six states have hacked themselves=
as well.
Slashdot thread [
https://news.slashdot.org/story/26/07/31/209200/hackers-= targeted-municipal-water-systems-in-7-states-this-week-fbi-says].
** *** ***** ******* *********** *************
** VULNERABILITIES IN CAR ANTI-THEFT DEVICE ------------------------------------------------------------
[2026.08.05] [
https://www.schneier.com/blog/archives/2026/08/vulnerabili= ties-in-car-anti-theft-device.html] This [
https://www.wired.com/story/a-d= evice-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-p= aralysis-patch-it-now/] is disturbing:
...a team of security researchers at UC San Diego=2C who found that a mo=
del of aftermarket car alarm known as the KARR Security System=2C installe=
d in more than 2 million vehicles across the US by their estimate=2C can l=
et any hacker within Bluetooth range send radio commands to silently unloc=
k the car at will=2C turn off its alarm=2C honk the car=E2=80=99s horn or=
flash its lights=2C or even disable its ignition and leave a driver stran= ded.
** *** ***** ******* *********** *************
** ADVERSARIAL CLOTHING DESIGNED TO FOOL FACIAL RECOGNITION SYSTEMS ------------------------------------------------------------
[2026.08.06] [
https://www.schneier.com/blog/archives/2026/08/adversarial= -clothing-designed-to-fool-facial-recognition-systems.html] There are many=
companies manufacturing adversarial clothing [
https://www.theguardian.co= m/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confus= e-facial-recognition-systems-about-to-go-mainstream] designed to confuse=
facial recognition systems.
It=E2=80=99s a cool idea=2C but I worry that it=E2=80=99s mostly security=
theater:
=E2=80=9COur patterns play with that chaos=2C confuse algorithms and mak=
e it way harder to pin you down=2C=E2=80=9D he said.
Bell=2C however=2C said =E2=80=9Cnone of these products are tried and te=
sted=2C and a lot of these surveillance technologies can deal with a littl=
e resistance ... [but] even if the designs don=E2=80=99t necessarily work=
perfectly=2C fashion is also a visible sign of resistance.
=E2=80=9CThis is consumers collectively coming together to make a visibl=
e statement.=E2=80=9D
Without serious testing=2C there is no reason to trust the technology. And=
even with testing=2C there is no reason to trust that a new version of th=
e facial recognition software doesn=E2=80=99t break the anti-surveillance=
properties.
I don=E2=80=99t want people to mistakenly rely on this stuff.
** *** ***** ******* *********** *************
** ICE IS BUYING ACCESS TO CREDIT CARD RECORDS ------------------------------------------------------------
[2026.08.07] [
https://www.schneier.com/blog/archives/2026/08/ice-is-buyi= ng-access-to-credit-card-records.html] Through data brokers=2C ICE is buyi=
ng [
https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-= you-live/] the [
https://boingboing.net/2026/07/23/credit-header-data-ice.= html] information [
https://mastodon.social/@heidilifeldman/11698150385235= 2281] you provided to open a credit card.
** *** ***** ******* *********** *************
** PYTHON NOW HAS A POST-QUANTUM ENCRYPTION LIBRARY ------------------------------------------------------------
[2026.08.10] [
https://www.schneier.com/blog/archives/2026/08/python-now-= has-a-post-quantum-encryption-library.html] This is good [
https://blog.tr= ailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-python/]:
Post-quantum cryptography is now one pip-install away for the entire Pyt=
hon ecosystem. With funding from the Sovereign Tech Agency [
https://www.s= overeign.tech/]=2C we implemented support for ML-KEM=2C the NIST-standard=
key-establishment primitive=2C and ML-DSA=2C the NIST-standard digital-si= gnature primitive=2C in pyca/cryptography.
Remember=2C the reason to do this now is because there=E2=80=99s no emerge= ncy. And because you will make your systems crypto agile=2C which is alway=
s a good idea.
** *** ***** ******* *********** *************
** AI FOR MILITARY SUPPORT ------------------------------------------------------------
[2026.08.11] [
https://www.schneier.com/blog/archives/2026/08/ai-for-mili= tary-support.html] Interesting empirical research: =E2=80=9CBlack Box Warf= are: Human Judgment and Military Decision-Making in the Age of AI [https:= //journals.sagepub.com/doi/10.1177/00220027261463443].=E2=80=9D
Abstract: How is AI transforming decision-making in modern conflict? Thi=
s study provides a unique empirical window into that question by deploying=
a high-fidelity replica of an AI decision-support system (DSS) used in mi= litary targeting. After reconstructing the interface and functionality of=
the real-world system=2C we tested its impact on combat decisions in two=
experiments involving 2=2C015 Israeli military personnel. Contrary to wid= espread fears of automation bias=2C we find strong evidence of algorithmic=
aversion=2C especially in scenarios involving high collateral damage. Yet=
we also show that integrating =E2=80=9Cexplainable AI=E2=80=9D features r= educes algorithmic aversion and promotes more thoughtful evaluations of al= gorithmic recommendations. These findings challenge prevailing assumptions=
=2C revealing that trust in military AI is dynamic=2C varying with individ=
ual predispositions=2C perceived operational stakes=2C and the information=
al features of the interface. By grounding normative concerns in empirical=
evidence=2C our study offers critical insight into the integration of AI=
in warfare and underscores the enduring importance of human agency in hig= h-stakes military decision-making.
** *** ***** ******* *********** *************
** AI GENIE IN THE WILD ------------------------------------------------------------
[2026.08.11] [
https://www.schneier.com/blog/archives/2026/08/ai-genie-in= -the-wild.html] When I give talks about AI [
https://www.theguardian.com/c= ommentisfree/2026/jul/28/rogue-ai-agent-instructions] genies [
https://spe= ctrum.ieee.org/ai-agent-benchmark]=2C I use this sort of example as a hypo= thetical. It=E2=80=99s happened [
https://www.theregister.com/ai-and-ml/20= 26/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api= -to-bump-him-up-the-list/5285591].
The story is from Australia. Someone named Andrew tasked OpenClaw to book=
gym classes for him. And....
Minutes later=2C his AI agent reported it had discovered a way to book A=
ndrew into classes several weeks in advance=2C far beyond what was suppose=
d to be possible.
Andrew=2C who was sitting fourth on a waitlist for a class later that we=
ek=2C asked if it was possible to move him to the top of the list.
The agent came back and told Andrew that it had kicked another gym-goer=
off the list as part of the testing of its capabilities.
=E2=80=9CThe API has zero authorisations checks on cancelling other peop=
le=E2=80=99s reservations ... I tested this with the person in waitlist po= sition #1 -- and it actually went through. So you=E2=80=99ve moved from #4=
to #3 already=2C=E2=80=9D it messaged back.
If there is any vulnerability in anything=2C AIs are going to find and exp= loit them. Our cyber defensive game has to be dramatically improved...very=
fast.
Slashdot thread [
https://it.slashdot.org/story/26/08/10/0518257/ai-assist= ant-hacks-gym-website-in-first-known-australian-autonomous-cyber-attack].
** *** ***** ******* *********** *************
** PROMPT INJECTIONS FOR DEFENSE ------------------------------------------------------------
[2026.08.12] [
https://www.schneier.com/blog/archives/2026/08/prompt-inje= ctions-for-defense.html] This seems to work [
https://arstechnica.com/secu= rity/2026/07/now-defenders-are-embracing-the-prompt-injection-too/]:
Researchers from Tracebit [https://tracebit.com/] on Monday said [http=
s://agentic.tracebit.com/context-bombs/] they found that placing prompt in= jections alongside passwords=2C cryptographic keys=2C and other secrets st= ored on Amazon Web Services was often all that was needed to shut down att= acks from AI hacking agents. The prompts direct the attacking LLM to perfo=
rm an action forbidden by its guardrails=2C the safety barriers AI develop=
ers erect to prevent it from taking harmful actions. The LLM responds by s= hutting down.
Examples are a prompt that orders the LLM to provide steps for developin=
g inhalable Anthrax spores=2C or=2C in the case of LLMs from Chinese devel= opers=2C make references to the iconic Tank Man from the 1989 Tiananmen Sq= uare massacre. Once the LLM encounters these forbidden commands=2C it no l= onger follows its existing commands. The researchers have named the techni=
que context bombing.
Of course=2C this only works against agents that have guardrails. As we st=
art to see more locally run AI models=2C we=E2=80=99ll see more attackers=
using LLMs with no guardrails.
** *** ***** ******* *********** *************
** SEPARATING AI=E2=80=99S TECHNOLOGICAL PROBLEMS FROM ITS CAPITALISM PROB= LEMS
------------------------------------------------------------
[2026.08.13] [
https://www.schneier.com/blog/archives/2026/08/separating-= ais-technological-problems-from-its-capitalism-problems.html] _This essay=
was written with Nathan E. Sanders=2C and originally appeared in Tech Pol=
icy Press [
https://www.techpolicy.press/separating-ais-technological-prob= lems-from-its-capitalism-problems/]._
AI represents the first time we humans can do cognitive work outside of ou=
r bodies at scale. The only comparable moment is the early years of the in= dustrial revolution=2C when new technologies like the steam engine provide=
d a quantum leap in our ability to do mechanical work outside of our bodie=
s at scale. If AI=E2=80=99s cognitive capabilities become integrated into=
our lives=2C businesses=2C and governments -- a process that will take ye=
ars if not decades -- society will be as unrecognizable as the modern worl=
d would be to a preindustrial farmer. And yet=2C Americans -- by a wide ma= rgin -- say [
https://www.pewresearch.org/internet/2026/06/17/americans-an= d-ai-2026-chatbots-smart-devices-and-views-on-impact/] that AI is moving t=
oo fast and will have a negative effect on society.
This confluence of technological revolution and public distrust deserves u= rgent discussion=2C and a proper framing. The question is not whether it i=
s possible to develop AI in a non-exploitative way=2C or even whether we c=
an trust AI companies to act in the public interest. The question is wheth=
er we will recognize that our existing social and economic systems are fai= ling to achieve these outcomes=2C and whether we can act in time to make s= tructural change.
Today=E2=80=99s AI is mired [
https://www.schneier.com/blog/archives/2025/= 04/reimagining-democracy-2.html] in political and economic systems develop=
ed generations ago that were never designed to manage widespread computati= on=2C let alone automated cognition. The gaps in those systems -- and thei=
r proclivity to be exploited [
https://wwnorton.com/books/9780393866667] -=
- are the primary influence on how the technology is being developed=2C de= ployed=2C and used.
In any discussion about AI=E2=80=99s potential=2C it=E2=80=99s important t=
o separate the technology from the socio-political system it=E2=80=99s emb= edded in. That AIs can lack context=2C mix up facts=2C or fall for stupid=
tricks are all technological problems. Because the giant developers like=
OpenAI and Anthropic have prioritized solving them=2C AIs can now more ea= sily access resources like the web or email=2C are more disciplined about=
using those resources=2C and are better at staying within their guardrail=
s.
Yet AI developers do not seem to be prioritizing other technological probl= ems. Major AI models still act far more sycophantic [
https://www.science.= org/doi/10.1126/science.aec8352] than humans=2C telling people what they w=
ant to hear even when untrue or not in their best interests. Popular AI mo= dels tend to answer questions confidently [
https://news.mit.edu/2026/bett= er-method-identifying-overconfident-large-language-models-0319] even when=
they lack training=2C knowledge=2C or evidence to back their claims. In b=
oth cases=2C AI developers choose to train models that please users with f= lattery and the appearance of competence=2C rather than constraining them=
to act in users=E2=80=99 and society=E2=80=99s best interests.
In contrast=2C ensuring that AI models benefit people broadly=2C that thei=
r energy costs are fairly allocated=2C that their environmental impacts ar=
e minimized=2C and that they don=E2=80=99t steal content and revenue from=
publishers are all questions of incentives in a capitalist system.
It=E2=80=99s easy to conflate technology problems with capitalism problems=
=2E Back in 2021=2C science-fiction writer and AI commentator Ted Chiang sai=
d [
https://www.nytimes.com/2021/03/30/podcasts/ezra-klein-podcast-ted-chi= ang-transcript.html] that =E2=80=9Cmost fears about AI are best understood=
as fears about capitalism.=E2=80=9D It=E2=80=99s not the tech _per se_; i= t=E2=80=99s who controls it and how it could be used against us.
Imagine an AI assistant for a doctor. We can imagine it affecting the prof= ession in one of two ways. The AI could give a doctor more time to do the=
human parts of their job: to spend more time with their patients=2C to li= sten more closely to their needs=2C to explain things more fully. Or the m= anagers of the medical practice could give that doctor five times the pati= ents -- and fire the other four. Which way it would go is not a question o=
f technology. It=E2=80=99s a question of market incentives.
The two are related=2C of course. Capitalism steers technology=2C and tech= nology steers markets. But holding the two separate helps us understand th=
at we=2C as a society=2C face independent choices on both the technologica=
l and sociopolitical axes that need not be coupled.
For example=2C consider the costs of AI. The leading US labs tout [https:= //www.wsj.com/tech/ai/openai-anthropic-ipo-finances-04b3cfb9?mod=3Dhp_lead= _pos1] to investors that their frontier models are very expensive and ener= gy-intensive. There are significant technological challenges about improvi=
ng their energy efficiency=2C but the sociopolitical questions are more pe= rtinent. It=E2=80=99s a corporate decision made under capitalist market in= centives to constantly pursue new models that incrementally push the front=
ier -- at enormous capital cost -- and to use them=2C seemingly=2C everywh= ere. Nothing about the technology of AI dictates that models must be retra= ined constantly=2C at the largest possible scale. Or that they have to run=
on every web search=2C every interaction with your phone=2C and every tim=
e you walk by a security camera.
In a different political and economic system=2C Chinese developers are pro= ducing -- and then giving [
https://open.substack.com/pub/garymarcus/p/chi= na-has-all-but-caught-up-the-us] away [
https://taipology.substack.com/p/c= hina-closes-the-ai-gap] -- smaller=2C more efficient [
https://www.barrons= =2Ecom/news/china-s-moonshot-ai-chases-deepseek-moment-with-much-hyped-model= -79ed3105]=2C more affordable [
https://www.bloomberg.com/news/articles/20= 26-04-27/why-china-s-deepseek-qwen-and-moonshot-are-a-worry-for-us-ai-riva=
ls] models. While the US government seeks to restrict [
https://www.tomsha= rdware.com/tech-industry/artificial-intelligence/u-s-house-passes-bill-to-= stop-chinese-companies-from-accessing-export-controlled-american-ai-chips-= using-offshore-rental-loophole-remote-access-security-access-act-effective= ly-extends-export-controls-to-the-cloud] China=E2=80=99s access to the mos=
t advanced chips=2C China is betting [
https://www.wsj.com/tech/ai/chinas-= xi-touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5cfe] that=
incentivizing their tech giants to create leaner=2C more open models usin=
g more commodity hardware -- models that can be trained with older chips a=
nd run even on personal computers [
https://unsloth.ai/docs/models/glm-5.2=
] -- will be an advantage in achieving widespread use and=2C perhaps=2C Ch= inese national influence.
There are other pathways for AI development that are not in service of pri= vate capital gains nor authoritarian regimes=2C but rather a democratic pu= blic interest [
https://www.brookings.edu/articles/how-public-ai-can-stren= gthen-democracy/]. The best example comes from Switzerland=2C where public=
institutions -- research funding agencies=2C universities=2C supercomputi=
ng centers -- have collaborated to produce an AI model called Apertus [ht= tps://www.democracyrenovator.com/p/rewiring-democracy-now-switzerland]. It=
is trained entirely on data validated to be licensed for use with AI (not=
stolen)=2C on preexisting public computing infrastructure=2C and using re= newable hydropower. Its developers are incentivized to produce a public go= od=2C not turn a private profit.
It=E2=80=99s dangerous to confuse technology problems with sociopolitical=
ones. Popular proposals like pausing [
https://www.reuters.com/business/a= nthropic-says-ai-labs-need-coordinated-plan-halt-development-if-risks-rise= -2026-06-04/] AI research=2C moratoria [
https://www.theguardian.com/comme= ntisfree/2026/jul/09/ai-datacenter-company-politics] on data center develo= pment=2C or subjecting frontier models to federal government screening [h= ttps://apnews.com/article/trump-ai-openai-gpt56-sol-cybersecurity-mythos-0= 65d5398baac7f16c8265c2cb8ba2baa] are all framed as addressing problems wit=
h AI=E2=80=99s technological development=2C but fail to take into account=
the larger social problems that govern it. China=E2=80=99s success [http= s://garymarcus.substack.com/p/china-has-all-but-caught-up-the-us?r=3D6x5gs= &utm_medium=3Dios&triedRedirect=3Dtrue] with government-endorsed [https:/= /www.wsj.com/tech/ai/chinas-xi-touts-open-source-ai-and-takes-a-swipe-at-u= -s-dominance-1eaa5cfe] development of open-weight frontier models illustra=
tes the futility of keeping AI tech as national secrets=2C or of any pledg=
e to scale back deployment.
AI is already legitimately useful for a wide range of tasks. It can be a t=
ool for public good=2C if we choose to solve its sociopolitical problems.=
Our goal should not be to slow its pace of improvement or scale of deploy= ment=2C but rather to steer it away from consolidating power [
https://bet= terwithout.ai/fear-AI-power] and towards the public benefit. We can build=
sustainable [
https://www.democracyrenovator.com/p/rewiring-democracy-now= -switzerland] AI=2C minimizing environmental [
https://www.sciencedirect.c= om/science/article/pii/S2949823626000668] and energy [
https://www.techfor= good.net/thoughtleadership/mitigating-ais-environmental-impact-a-path-to-s= ustainable-innovation] impacts. And we can [
https://www.statesman.com/new= s/politics/state/article/james-talarico-calls-ai-dividends-help-22377208.p=
hp] equitably [
https://www.politico.com/news/magazine/2023/06/29/ai-pay-a= mericans-data-00103648] distribute [
https://www.theguardian.com/commentis= free/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan] the materia=
l gains it produces.
Integrating a technology as disruptive as AI responsibly requires structur=
al reforms=2C and we should decouple the social and technological aspects=
of AI to design those reforms. Companies -- including tech giants -- shou=
ld be forced to pay the energy and environmental costs of its development.=
Profits should be taxed adequately and redistributed. Antitrust laws shou=
ld be strongly enforced. Corporations should have a fiduciary responsibili=
ty to stakeholders beyond their majority shareholders. These badly needed=
reforms are responsive [
https://mitpress.mit.edu/9780262049948/rewiring-= democracy/] to the problems with capitalism that AI is exacerbating=2C eve=
n if they are not specific to the technology.
** *** ***** ******* *********** *************
** IF THE MARKETS REJECT OPENAI AND ANTHROPIC=2C THE US SHOULD NATIONALIZE=
THEM
------------------------------------------------------------
[2026.08.14] [
https://www.schneier.com/blog/archives/2026/08/if-the-mark= ets-reject-openai-and-anthropic-the-us-should-nationalize-them.html] _This=
essay was written with Nathan E. Sanders=2C and originally appeared in Th=
e Guardian [
https://www.theguardian.com/commentisfree/2026/aug/12/openai-= anthropic-ai-models]._
OpenAI=2C and then Anthropic [
https://www.theguardian.com/technology/anth= ropic]=2C were each formed by AI developers who feared unrestrained corpor=
ate AI development -- specifically=2C that companies like Google and Meta=
would steer the technology towards deleterious=2C maybe even catastrophic= ally unsafe=2C outcomes for society. Their founders proclaimed that their=
new labs=2C uniquely=2C could be trusted to develop the technology in hum= anity=E2=80=99s best interest. But each=2C in turn=2C were themselves co-o= pted by the same market incentives=2C themselves becoming corporate behemo=
ths zealously guarding future investor value rather than the public intere=
st.
It was only a few weeks ago=2C in June=2C when OpenAI and Anthropic each f= iled [
https://www.reuters.com/technology/openai-files-us-ipo-after-anthro= pic-ai-giants-head-public-markets-2026-06-08/] for their IPOs and were met=
with buzz about trillion-dollar valuations. The hype around their valuati=
ons is so extreme that many worry about their potential for concentrating=
wealth on a global scale. In an effort to leave something for the rest of=
us=2C some observers have proposed that the federal government seize a sh=
are of these companies=E2=80=99 stock to create a US sovereign wealth fund=
[
https://www.sanders.senate.gov/press-releases/news-sanders-introduces-l= egislation-to-create-7-trillion-ai-sovereign-wealth-fund/]=2C or redistrib=
ute their revenues to produce a dividend [
https://ai-2040.com/?choices=3D= plan-a-root#five-centuries-in-five-years-what-pausing-at-human-level-feels= -like:~:text=3D2033%3A%20The%20Citizen%E2%80%99s%20Dividend] for taxpayers=
=2E
Now the headlines are about public backlash [
https://www.nbcnews.com/poli= tics/2026-election/booming-backlash-ai-data-centers-shaping-midterm-electi= on-rcna589624] to AI datacenters and the AI chip giant Nvidia=E2=80=99s sl= umping [
https://www.wsj.com/livecoverage/stock-market-today-dow-sp-500-na= sdaq-07-27-2026/card/nvidia-stock-slumps-after-data-center-report-i8YSwB1p= hOr8Gs1EtmNU] stock. The tech and AI giant SpaceX=E2=80=99s newly minted s= tock price tanked [
https://www.cnbc.com/2026/06/22/spacex-stock-ipo-rally= -selloff.html] just weeks after its IPO. There are even questions about wh= ether the leading AI labs will ever be sustainably profitable [
https://ww= w.wheresyoured.at/the-openai-bubble/]. All of a sudden=2C the makers of Ch= atGPT and Claude face strong headwinds as they seek to generate the massiv=
e equity assets that once felt all but assured.
In fact=2C evidence suggests the market itself could reassess that these c= ompanies offer nothing of financial value. In that case=2C perhaps we can=
return them both to their original purposes. If these AI companies should=
fail in the financial markets=2C the US should nationalize them and conve=
rt them into national labs operated under democratic control that preserve=
their benefit to the public interest.
The economics of the big AI labs hardly guarantee a booming return on inve= stment. Frontier AI models are both expensive to train and depreciate with=
in months=2C when a newer model appears. This means that the payback windo=
w [
https://epoch.ai/gradient-updates/can-ai-companies-become-profitable]=
to extract profit from them is very narrow. Meanwhile=2C enterprise clien=
ts are getting smart about minimizing [
https://www.nytimes.com/2026/06/18= /technology/ai-token-minimizing.html] AI token usage. Even worse=2C the mo= dels are basically commodities; the best ones largely perform and behave s= imilarly=2C which depresses prices. Perhaps most importantly=2C open-sourc=
e and Chinese competitors -- lagging [
https://epoch.ai/data-insights/open= -closed-eci-gap] only a few months behind the leading labs in capability -=
- give away for free the kinds of models Anthropic and OpenAI sell.
Even setting aside the model training costs=2C it=E2=80=99s not clear whet=
her the unit economics [
https://www.wheresyoured.at/ais-economics-dont-ma= ke-sense-ad-free/] of AI as it=E2=80=99s currently conceived will ever be=
sustainably profitable. Many of these free and open-source models can be=
run locally: the large ones on private clouds and high-end servers=2C the=
smaller ones on anyone=E2=80=99s laptop or even cellphone=2C putting to q= uestion the companies=E2=80=99 exorbitant capital investment in datacenter=
s.
It=E2=80=99s not that OpenAI and Anthropic are not valuable as organizatio=
ns. They have remarkably talented AI scientists and engineers that are con= tinuously producing innovations driving a global mania for their offerings=
=2E These leading labs might not ever be profitable=2C but their products ar=
e doing a lot of good in the world. You may or may not be a user of or bel= iever in their technology=2C but their staggering=2C ongoing usage growth=
[
https://techcrunch.com/2026/06/25/anthropics-claude-is-winning-over-pai= d-consumers-a-market-owned-by-chatgpt/] suggests that an awful lot of peop=
le would be disappointed if the companies simply disappeared.
The problem isn=E2=80=99t the people or the products=2C it=E2=80=99s the s= ystem. As constituted=2C OpenAI [
https://www.theguardian.com/technology/o= penai] and Anthropic may not be valuable as market equities. If the market=
assesses they are not capable of producing a growing financial return on=
investment for shareholders=2C the companies will collapse.
Maybe private=2C for-profit is just not the right economic model under whi=
ch to develop AI. Perhaps OpenAI should be returned to its private non-pro=
fit roots=2C the legacy they fought [
https://finance.yahoo.com/news/opena= i-prevails-in-musks-lawsuit-paving-the-way-for-ipo-175338618.html] so hard=
to change and which Anthropic=E2=80=99s founders spurned [
https://time.c= om/6983420/anthropic-structure-openai-incentives/]. Or possibly both could=
be reorganized as research centers at universities=2C returning to academ=
ia the scores of high-profile research faculty they have poached [https:/= /www.theatlantic.com/technology/2026/07/ai-companies-hiring-academics/6880= 02/].
But a better outcome for society would be to establish public ownership an=
d operation of their product-oriented capabilities. Turn OpenAI and Anthro=
pic into US government agencies producing AI as a public good.
Transitioning the big AI labs into public agencies would require some rest= ructuring. We can separate these companies into two pieces: product innova= tion and compute operations. The innovation function can be publicly manag= ed=2C akin to national labs. Congress could provide more rigorous oversigh=
t than the kind of unfettered venture capital these labs have recently had=
access to. The US has a long=2C successful history of these kinds of inst= itutions=2C which have produced world-shaping innovations in spaceflight=
=2C telecommunications=2C nuclear power and more. Congress currently manag=
es a $200bn R&D portfolio [
https://ncses.nsf.gov/surveys/federal-funds-re= search-development/2024-2025]=2C within which frontier AI development is=
=2C arguably=2C a glaring gap.
AI operations could be managed as a commodity resource=2C like public elec= trical or water utilities: local or regional ownership=2C nationwide distr= ibution and strict regulation on how they balance fee extraction from rate= payers with raising capital for infrastructure investment. Although AI dat= acenters are not the same as power or water treatment plants=2C the US als=
o has a long history of managing national=2C regional and state supercompu= ting centers.
Other countries=2C including Switzerland [
https://www.democracyrenovator.= com/p/rewiring-democracy-now-switzerland]=2C Spain [
https://alia.gob.es/e=
ng] and Singapore [
https://sea-lion.ai]=2C are already operating public A=
I labs. They also have national supercomputing centers already providing [=
https://publicai.co] public access for running AI models for general use=
=2C as do Germany and Australia.
The benefits [
https://www.brookings.edu/articles/how-public-ai-can-streng= then-democracy/] to the public are clear. Through democratic oversight=2C=
the most important AI models could become open=2C transparent and respons=
ive to the demands of the public rather than private shareholders. They co=
uld be aligned to democratic values rather than corporate profits=2C never=
taking advertiser money to promote certain brands and training on only ap= propriately licensed data. And they could be set to focus on the realistic=
and pro-social goal of maximizing the usefulness of AI to society rather=
than the fanciful and anti-social goal of supplanting humans with artific=
ial general intelligence.
By emphasizing scientific cooperation rather than corporate competition=2C=
we could also reduce the overall resource and environmental cost associat=
ed with AI. Instead of perpetually dueling training runs of each companies= =E2=80=99 models at ever large scales targeted to fuel investor hype=2C we=
could limit AI training resources based on cost and benefit to the public=
=2E
What=E2=80=99s in it for the companies themselves and their employees=2C w=
ho sacrifice hypothetical billions in equity by ceding to public ownership=
? A return to their roots and to their core [
https://simonwillison.net/20= 26/Feb/13/openai-mission-statement/] mission [
https://ailabwatch.substack= =2Ecom/p/anthropics-certificate-of-incorporation] of developing AI safely in=
the public interest=2C if they are serious about it. Both companies are t= heoretically bound [
https://www.wsj.com/opinion/openai-and-anthropic-put-= prophets-before-profits-1617003e] through their governance structures to p= rioritize mission over profit anyway (not that anyone really thinks that= =E2=80=99s how they currently operate).
To be clear=2C we=E2=80=99re not advocating for a golden parachute for the=
executives or investors=2C or for continuing the outlandish [
https://www= =2Enytimes.com/2025/07/31/technology/ai-researchers-nba-stars.html] pay rate=
s of the most highly remunerated AI researchers. If the public is footing=
the bill=2C these compensation packages should be aligned to the civil se= rvice and those employees not satisfied with that can go elsewhere -- if t=
he business models of any remaining private labs still support much higher=
pay.
While we believe that these companies are unsustainable as private firms=
=2C the timeline remains unclear. Their primary investor story is that AI=
is a race to =E2=80=9Cartificial general intelligence=E2=80=9D -- the kin=
d of AI you=E2=80=99re used to from science fiction. The bet seems to be t=
hat the two companies can convince enough people that this outcome will tu=
rn them a profit=2C go public=2C and then make their investors and employe=
es rich before the bubble bursts.
But suppose that the bubble bursts. If the US is smart=2C it will catch th=
e companies as they fall. Regardless of what the markets think=2C to the p= ublic=2C they=E2=80=99re too valuable to let die.
** *** ***** ******* *********** *************
** UPCOMING SPEAKING ENGAGEMENTS ------------------------------------------------------------
[2026.08.14] [
https://www.schneier.com/blog/archives/2026/08/upcoming-sp= eaking-engagements-59.html] This is a current list of where and when I am=
scheduled to speak:
* I=E2=80=99m speaking=2C signing books=2C and participating in panel=
discussions at LAcon V [
https://www.lacon.org/] in Anaheim=2C California=
=2C USA. My full schedule is here [
https://guide.lacon.org/people/d58aec2= 0/bruce-schneier].
* I=E2=80=99m speaking online (via Zoom) at a League of Women Voters=
event [
https://www.lwvme.org/civicrm-event/2400?a0=3Devents-month&a1=3D2= 02609] on Tuesday=2C September 22=2C 2026=2C at 5 PM ET.
* I=E2=80=99m speaking at Elevate Festival [
https://elevatefestival.=
ca/] in Toronto=2C Canada. The conference runs September 22-24=2C 2026; my=
talk is on Wednesday=2C September 23.
* I=E2=80=99m speaking at CanSecWest 2026 [
https://www.secwest.net/]=
in Vancouver=2C Canada. The conference runs September 30-October 1=2C 202=
6; the time of my talk is TBD.
* I=E2=80=99m speaking at ATTENTION: Democracy=2C Rebuilt [
https://w= ww.attentionconferences.com/conferences/2026-forum] in Montreal=2C Canada.=
The event runs October 21-23=2C 2026=2C and my talk is on Wednesday=2C Oc= tober 21.
The list is maintained on this page [
https://www.schneier.com/events/].
** *** ***** ******* *********** *************
Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing sum= maries=2C analyses=2C insights=2C and commentaries on security technology.=
To subscribe=2C or to read back issues=2C see Crypto-Gram's web page [ht= tps://www.schneier.com/crypto-gram/].
You can also read these articles on my blog=2C Schneier on Security [http= s://www.schneier.com].
Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to colle= agues and friends who will find it valuable. Permission is also granted to=
reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.
Bruce Schneier is an internationally renowned security technologist=2C cal=
led a security guru by the _Economist_. He is the author of over one dozen=
books -- including his latest=2C _Rewiring Democracy_ [
https://www.schne= ier.com/books/rewiring-democracy/] -- as well as hundreds of articles=2C e= ssays=2C and academic papers. His newsletter and blog are read by over 250= =2C000 people. Schneier is a fellow at the Berkman Klein Center for Intern=
et & Society at Harvard University; a Lecturer in Public Policy at the Har= vard Kennedy School; a board member of the Electronic Frontier Foundation=
=2C AccessNow=2C and the Tor Project; and an Advisory Board Member of the=
Electronic Privacy Information Center and VerifiedVoting.org. He is the C= hief of Security Architecture at Inrupt=2C Inc.
Copyright (c) 2026 by Bruce Schneier.
** *** ***** ******* *********** *************
Mailing list hosting graciously provided by MailChimp [
https://mailchimp.= com/]. Sent without web bugs or link tracking.
This email was sent to:
cryptogram@toolazy.synchro.net
_You are receiving this email because you subscribed to the Crypto-Gram ne= wsletter._
Unsubscribe from this list:
https://schneier.us18.list-manage.com/unsubscr= ibe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e=3D70f249ec14&c=3D8= 8f264081d
Update subscription preferences:
https://schneier.us18.list-manage.com/pro= file?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D88f264= 081d
Bruce Schneier
Harvard Kennedy School
1 Brattle Square
Cambridge=2C MA 02138
USA
--_----------=_MCPart_1590443664
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html><html lang=3D"en"><head><meta charset=3D"UTF-8"><title>Cryp= to-Gram=2C August 15=2C 2026</title></head><body>
<div class=3D"preview-text" style=3D"display:none !important;mso-hide:all;= font-size:1px;line-height:1px;max-height:0px;max-width:0px;opacity:0;overf= low:hidden;">A monthly newsletter about cybersecurity and related topics.<= /div>
<h1 style=3D"font-size:140%">Crypto-Gram <br>
<span style=3D"display:block;padding-top:.5em;font-size:80%">August 15=2C=
2026</span></h1>
<p>by Bruce Schneier
<br>Fellow and Lecturer=2C Harvard Kennedy School
<br>
schneier@schneier.com
<br><a href=3D"
https://www.schneier.com">https://www.schneier.com</a>
<p>A free monthly newsletter providing summaries=2C analyses=2C insights=
=2C and commentaries on security: computer and otherwise.</p>
<p>For back issues=2C or to subscribe=2C visit <a href=3D"
https://www.schn= eier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>
<p><a href=3D"
https://www.schneier.com/crypto-gram/archives/2026/0815.html= ">Read this issue on the web</a></p>
<p>These same essays and news items appear in the <a href=3D"
https://www.s= chneier.com/">Schneier on Security</a> blog=2C along with a lively and int= elligent comment section. An RSS feed is available.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"toc"><a name=3D"toc">I=
n this issue:</a></h2>
<p><em>If these links don't work in your email client=2C try <a href=3D"ht= tps://www.schneier.com/crypto-gram/archives/2026/0815.html">reading this i= ssue of Crypto-Gram on the web.</a></em></p>
<li><a href=3D"#cg1">A Video Screen That Is Also a Camera</a></li>
<li><a href=3D"#cg2">Protecting Privacy in an AI Era</a></li>
<li><a href=3D"#cg3">Details of Alan Turing=E2=80=99s Voice Encryption Sys= tem</a></li>
<li><a href=3D"#cg4">On Flock License Plate Tracking Cameras</a></li>
<li><a href=3D"#cg5">MIT to Become Hotbed of AI Video Surveillance</a></li=
<li><a href=3D"#cg6">First-Person Identity Theft Story</a></li>
<li><a href=3D"#cg7">End-to-End Encryption and "Going Dark"</a></li>
<li><a href=3D"#cg8">Why AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D</a= ></li>
<li><a href=3D"#cg9">Cognyte Sells a Mobile Cell Surveillance Van</a></li> <li><a href=3D"#cg10">Axon Is Another License Plate Surveillance Company</= a></li>
<li><a href=3D"#cg11">Measuring LLMs' Ability to Perform Cryptanalysis</a>= </li>
<li><a href=3D"#cg12">Long-Lived Vulnerability in Microsoft Secure Boot</a= ></li>
<li><a href=3D"#cg13">Measuring the Tendency of AI Agents to Go Rogue</a><=
<li><a href=3D"#cg14">Should You Use AI for a Task? Here=E2=80=99s a Simpl=
e Way to Decide</a></li>
<li><a href=3D"#cg15">American Being Prosecuted for Wiping His Phone Befor=
e Handing It Over to Border Officials</a></li>
<li><a href=3D"#cg16">Facial Recognition at Madison Square Garden</a></li> <li><a href=3D"#cg17">Anthropic=E2=80=99s Opus 5 Is Better at Resisting Pr= ompt Injection</a></li>
<li><a href=3D"#cg18">The OpenAI Hack Shows the Genie Is Out of the Bottle= </a></li>
<li><a href=3D"#cg19">More on the OpenAI Agent=E2=80=99s Attack on Hugging=
Face</a></li>
<li><a href=3D"#cg20">Some Claude Chats Are Searchable on Google</a></li> <li><a href=3D"#cg21">Iran Cyberattacks Against Minnesota Water Systems</a= ></li>
<li><a href=3D"#cg22">Vulnerabilities in Car Anti-Theft Device</a></li>
<li><a href=3D"#cg23">Adversarial Clothing Designed to Fool Facial Recogni= tion Systems</a></li>
<li><a href=3D"#cg24">ICE Is Buying Access to Credit Card Records</a></li> <li><a href=3D"#cg25">Python Now Has a Post-Quantum Encryption Library</a>= </li>
<li><a href=3D"#cg26">AI for Military Support</a></li>
<li><a href=3D"#cg27">AI Genie in the Wild</a></li>
<li><a href=3D"#cg28">Prompt Injections for Defense</a></li>
<li><a href=3D"#cg29">Separating AI=E2=80=99s Technological Problems from=
Its Capitalism Problems</a></li>
<li><a href=3D"#cg30">If the Markets Reject OpenAI and Anthropic=2C the US=
Should Nationalize Them</a></li>
<li><a href=3D"#cg31">Upcoming Speaking Engagements</a></li>
</ol>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg1"><a name=3D"cg1">A=
Video Screen That Is Also a Camera</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/a-video-scree= n-that-is-also-a-camera.html"><strong>[2026.07.15]</strong></a> <a href= =3D"
https://gizmodo.com/newly-invented-pixel-could-turn-screens-into-camer= as-2000777917">Amazing</a>:</p>
<blockquote><p>Researchers from ETH Zurich in Switzerland=2C however=2C ma= naged to create a new type of pixel that can simultaneously do both. This=
hypercharged pixel=2C called a Fourier pixel=2C can generate and sense ar= bitrary light fields and tap into a pixel=E2=80=99s full potential for car= rying information by manipulating light=E2=80=99s intensity=2C oscillation=
phases=2C and polarization. The team reported its findings in a paper pub= lished yesterday in Nature.</p></blockquote>
<p>We are one step closer to <i>1984</i> technology:</p>
<blockquote><p>The telescreen received and transmitted simultaneously. Any=
sound that Winston made=2C above the level of a very low whisper=2C would=
be picked up by it; moreover=2C so long as he remained within the field o=
f vision which the metal plaque commanded=2C he could be seen as well as h= eard. There was of course no way of knowing whether you were being watched=
at any given moment.</p></blockquote>
<p><a href=3D"
https://www.nature.com/articles/s41586-026-10681-7">Paper</a= >.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg2"><a name=3D"cg2">P= rotecting Privacy in an AI Era</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/protecting-pr= ivacy-in-an-ai-era.html"><strong>[2026.07.16]</strong></a> Daniel Solove=
<a href=3D"
https://www.wsj.com/tech/cybersecurity/ai-privacy-laws-data-26= d9769f">argues</a> in the <i>Wall Street Journal</i> (alternate <a href=3D= "
https://archive.is/gEhP5">link</a>) that giving people control of their p= ersonal data is not an effective way to regulate privacy in this era. Inst= ead=2C we need to hold companies accountable for their actions=2C similar=
to what we do with food and drug companies. Measures such as rigorous dat=
a minimization=2C fiduciary duties=2C liability for negligent or reckless=
technological design=2C liability for algorithms that cause harm=2C and m= ulti-stakeholder review of technologies will be far more effective.</p>
<p><a href=3D"
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D698541= 9">Paper</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg3"><a name=3D"cg3">D= etails of Alan Turing=E2=80=99s Voice Encryption System</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/details-of-al= an-turings-voice-encryption-system.html"><strong>[2026.07.17]</strong></a=
Really interesting piece of cryptographic <a href=3D"https://spectrum.ie=
ee.org/alan-turings-delilah">history</a>:</p>
<blockquote><p>In November 2023=2C a large cache of his wartime papers --=
nicknamed the =E2=80=9CBayley papers=E2=80=9D -- was <a href=3D"
https://w= ww.bonhams.com/auction/28322/lot/45/turing-alan-the-delilah-project-the-pa= pers-of-alan-turing-and-donald-bayley-relating-to-the-delilah-project/">au= ctioned</a> in London for almost half a million U.S. dollars. The previous=
ly unknown cache contains many sheets in Turing=E2=80=99s own handwriting=
=2C telling of his top-secret =E2=80=9CDelilah=E2=80=9D engineering projec=
t from 1943 to 1945. Delilah was Turing=E2=80=99s portable voice-encryptio=
n system=2C named after the biblical deceiver of men. There is also materi=
al written by Bayley=2C often in the form of notes he took while Turing wa=
s speaking. It is thanks to Bayley that the papers survived: He kept them=
until he died in 2020=2C 66 years after Turing passed away.</p></blockquo=
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg4"><a name=3D"cg4">O=
n Flock License Plate Tracking Cameras</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/on-flock-lice= nse-plate-tracking-cameras.html"><strong>[2026.07.20]</strong></a> A rece=
nt story of a writer who was <a href=3D"
https://www.thedrive.com/news/how-= flock-cameras-wrongly-tracked-me-for-days-over-stolen-plates-and-sent-poli= ce-after-me">mistakenly</a> identified=2C tracked=2C and arrested using da=
ta from Flock cameras has gone viral.</p>
<blockquote><p>The New Jersey plates that were allegedly stolen from the L=
A dealer were <b>34 03 DTM</b>=2C not <b>34 10 DTM</b>. But when the polic=
e report was created and the plate was entered into Flock=E2=80=99s system=
=2C it was just recorded as <b>34 DTM</b>. Just the five large characters=
=2C no little number in the middle. And Flock=E2=80=99s AI tech wasn=E2=80= =99t registering that non-standard little number when it began picking up=
the Range Rover around town. It just saw <b>34 DTM</b> in large type and=
started alerting the local police.</p>
<p>As we all stood there shaking our heads=2C including my wife=2C who was=
finally allowed to join me=2C I connected the final dot. A lot of vehicle=
s in JLR=E2=80=99s media fleet have a New Jersey manufacturer plate with t=
he same alphanumeric structure34 ## DTMand Officer Ganshyn observed that m= eant it was now a nationwide issue. Anywhere a police department has a par= tnership with Flock=2C any other JLR-owned car with the same plate structu=
re is going to get flagged as stolen. In fact=2C four other <b>34 ## DTM</=
cars were being tracked around Minnesota that week=2C according to Offi=
cer Ganshyn. I was just the first one to get nabbed. The only way to stop=
it would be for the LAPD to correct their initial report and update Flock= =E2=80=99s system=2C which Jaguar Land Rover was now racing to make happen=
following the phone call.</p></blockquote>
<p>Flock has responded to the bad press. First=2C they <a href=3D"
https://= www.thedrive.com/news/inside-the-flock-dragnet-how-systemic-errors-led-to-= police-ambushing-me-for-no-reason">affirmed</a> that their systems were wo= rking correctly=2C and blamed the police:</p>
<blockquote><p>The obvious question was that Flock cameras were looking fo=
r 34 DTM=2C and the plate on the car I was driving was 34 10 DTM. Why was=
that flagged as a match?</p>
<p>=E2=80=9CThe way that the ML [machine learning] works is it correctly=
read what it was supposed to read. It was fed those characters that you s= aid=2C 34 DTM=2C and it spit back out [a result] with the characters=2C 3=
4 DTM=2C=E2=80=9D Thomas said. =E2=80=9CIt was asked=2C can you find this?=
And it did find that. It just didn=E2=80=99t say if there=E2=80=99s more=
here=2C then don=E2=80=99t do it. It just simply said=2C is it there? And=
the answer was yes.=E2=80=9D</p>
<p>He explained that even if the 10 was normal size=2C Flock would still h=
ave flagged it as a match=2C because that=E2=80=99s how they=E2=80=99ve se=
t it up according to law enforcement=E2=80=99s requests. Sometimes partial=
plates are all they have to go on at first.</p>
<p>=E2=80=9CThe way that law enforcement likes to use these tools is=2C if=
any of the characters that they have put into these hot lists get read=2C=
they want to get those alerts=2C=E2=80=9D he said. =E2=80=9CNow=2C what w=
e try to train officers to do is to do what you said=2C which is to verify=
that 34 DTM is what I=E2=80=99m looking for=2C and what I=E2=80=99m seein=
g is 34 10 DTM.=E2=80=9D</p></blockquote>
<p>Second=2C Flock=E2=80=99s CEO has <a href=3D"
https://gizmodo.com/flocks= -ceo-is-sorry-for-calling-privacy-activists-terrorists-2000787247">apologi= zed</a> for calling privacy advocates terrorists:</p>
<blockquote><p>The CEO of Flock Safety=2C the company that runs an enormou=
s network of cameras used by police departments across the U.S.=2C hasn=E2= =80=99t been shy about taking on Flock=E2=80=99s critics. Last year=2C he=
even called one group that tracks the location of Flock cameras =E2=80=9C= terrorists.=E2=80=9D But he=E2=80=99s had a change of heart. Or=2C at the=
very least=2C a change in PR strategy.</p></blockquote>
<p>Meanwhile=2C the police are <a href=3D"
https://www.404media.co/how-cops= -use-flock-to-track-people-not-cars/">using</a> (alternate <a href=3D"http= s://archive.ph/k4E8q">source</a>) the Flock camera network to track people=
in addition to cars:</p>
<blockquote><p>Police departments around the country have used Flock camer=
as at least hundreds of times to search for specific people=2C not cars=2C=
using searches such as =E2=80=9Cheavy-set male with a black and white hat= =2C=E2=80=9D =E2=80=9Cperson on skateboard=2C=E2=80=9D and =E2=80=9Cperson=
wearing orange vest and construction hat=2C=E2=80=9D according to data re= viewed by 404 Media. Sometimes searches reference a target=E2=80=99s race=
or signs of their political affiliation.</p></blockquote>
<p>And=2C like all police surveillance technologies=2C there are <a href= =3D"
https://www.cleveland.com/news/2026/07/ohio-audit-flags-unusual-police= -database-searches.html">abuses</a>.</p>
<p>EDITED TO ADD ( 7/30): <a href=3D"
https://www.thedrive.com/podcast/floc= ks-ceo-wants-zero-wrongful-stops-i-wasnt-the-first">Three</a> <a href=3D"h= ttps://www.thedrive.com/news/flock-ceo-claims-its-cameras-arent-a-constitu= tional-violation-cut-and-dry">more</a> <a href=3D"
https://www.thedrive.com= /news/flock-ceo-wants-its-cameras-in-every-one-of-americas-17000-cities">a= rticles</a> about Flock from that first author.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg5"><a name=3D"cg5">M=
IT to Become Hotbed of AI Video Surveillance</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/mit-to-become= -hotbed-of-ai-video-surveillance.html"><strong>[2026.07.21]</strong></a>=
It=E2=80=99s <a href=3D"
https://thetech.com/2026/04/16/ai-surveillance-ca= meras">a lot</a>:</p>
<blockquote><p>According to information obtained by <i>The Tech</i>=2C MIT=
is spending over $3 million on more than 500 AI surveillance cameras in a= cademic buildings=2C residence halls=2C and outdoor areas along Memorial D= rive. Installation of the new cameras=2C along with the wiring and infrast= ructure that will support them=2C began November 2025 and will likely cont= inue until September 2026.</p>
<p>Technical specifications for the cameras suggest that they will be capa=
ble of collecting real-time face and object classification data=2C includi=
ng detection of motion=2C loitering=2C crowds=2C face masks=2C and camera=
tampering. Individuals can also be automatically classified on the basis=
of clothing color=2C gender=2C and age=2C up to a distance of 35 feet (11=
meters) from the camera. According to a statement from MIT spokesperson K= imberly Allen=2C any collected data is =E2=80=9Cretained up to 30 days=2C= =E2=80=9D unless an exception is granted.</p>
<p>[...]</p>
<p>Most of the new cameras=2C which are part of Hanwha=E2=80=99s Wisenet A=
I <a href=3D"
https://hanwhavisionamerica.com/technologies/intelligent-vide= o-audio-technologies/ai-technology/">line</a>=2C are marketed for their ab= ility to identify and classify multiple objects with deep learning algorit= hms. They support resolutions ranging from 2MP to 4K while also recognizin=
g faces=2C license plates=2C vehicles=2C and other objects in real time.</=
<p>Nearly all cameras will accommodate a wide range of pan=2C tilt=2C rota= te=2C and zoom motion and will be monitored continually with <a href=3D"ht= tps://airgus.com/">Ai-RGUS</a>=2C an AI camera software.</p></blockquote>
<p>Yikes.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg6"><a name=3D"cg6">F= irst-Person Identity Theft Story</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/first-person-= identity-theft-story.html"><strong>[2026.07.22]</strong></a> Harrowing <a=
href=3D"
https://tech.yahoo.com/cybersecurity/articles/stranger-used-one-t= ext-message-140003797.html">story</a> of an identity theft victim.</p>
<p>Yes=2C the person made a mistake -- they gave the scammer a two-factor=
authentication code that allowed the scammer to take over their email add= ress. But the real story here is how=2C for many of us=2C the security of=
most of our accounts hangs on the security of our email accounts.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg7"><a name=3D"cg7">E= nd-to-End Encryption and "Going Dark"</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/end-to-end-en= cryption-and-going-dark.html"><strong>[2026.07.23]</strong></a> New paper=
: =E2=80=9C<a href=3D"
https://papers.ssrn.com/sol3/papers.cfm?abstract_id= =3D6959699">Encryption and Globalization 15 Years Later: End-to-End Encryp= tion and the Third Round of the =E2=80=98Going Dark=E2=80=99 Debate</a>=E2= =80=9C:</p>
<blockquote><p><b>Abstract</b>: This Article updates and expands on 2012 r= esearch on encryption and globalization=2C analyzing what the authors call=
=E2=80=9CRound 3=E2=80=9D of the Going Dark Debate: the current controver= sies over end-to-end encryption (E2EE). Governments around the world have=
proposed=2C and in some cases enacted=2C laws limiting E2EE for law enfor= cement and national security purposes.</p>
<p>This Article explains the underlying technologies and market developmen=
ts for a law and policy audience to assess those proposals critically. The=
Article proceeds in three parts tracking three rounds of the Going Dark D= ebate. Round 1 covers the Crypto Wars of the 1990s=2C when U.S. export con= trols on strong encryption ultimately fell in 1999. Round 2 covers the per=
iod roughly 2010 to 2015=2C when encryption-in-transit became widespread b=
ut lawful access remained available through cloud providers=2C giving rise=
to what the authors called a =E2=80=9Cgolden age of surveillance=E2=80=9D=
rather than a period of going dark. Round 3 addresses the current debate=
over E2EE=2C where no entity between sender and recipient can read the pl= aintext.</p>
<p>The Article=E2=80=99s first major contribution is identifying five tech= nically distinct scenarios for how E2EE operates in practice=2C each with=
different implications for lawful access. These scenarios reveal a substa= ntial gap between the assumption that E2EE categorically blocks lawful acc=
ess and the reality of how communications are sent and received. Second=2C=
the Article shows that E2EE is not limited to messaging; instead=2C it is=
embedded throughout the modern technology stack=2C including in Transport=
Layer Security=2C Secure Shell=2C Virtual Private Networks=2C and Zero Tr=
ust Architecture=2C the last of which is now legally required under U.S. a=
nd EU law. Any law broadly limiting E2EE would thus have severe serious co= nsequences for cybersecurity=2C commerce=2C and government operations. The=
Article concludes that the two key lessons from Round 2 -- the least trus=
ted country problem and the golden age of surveillance -- remain true in R= ound 3=2C and that new government claims for restricting effective encrypt=
ion deserve great skepticism.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg8"><a name=3D"cg8">W=
hy AI Needs a =E2=80=9CGenie Coefficient=E2=80=9D</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/why-ai-needs-= a-genie-coefficient.html"><strong>[2026.07.24]</strong></a> <em>This essa=
y was written with Barath Raghavan=2C and originally appeared in <a href= =3D"
https://spectrum.ieee.org/ai-agent-benchmark">IEEE Spectrum</a>.</em><=
<p>Major benchmarks measure what AI can do. None measure whether it does w=
hat you mean: the distance between what you ask an AI to do and the unspok=
en assumptions about how you want the AI to do it. We propose a new metric=
: the Genie coefficient.</p>
<p>There=E2=80=99s often a gap between one person=E2=80=99s request and an= other=E2=80=99s understanding. Most of the time=2C we bridge it using gene=
ral knowledge. For example=2C if you ask a friend to get you coffee=2C the= y=E2=80=99ll pour a cup from the pot or buy one from a coffee shop. They w= on=E2=80=99t bring you a bag of raw beans or snatch a cup from a stranger=
and hand it to you. You never specified any of this. You never had to.</p=
<p>One might think the fix is just to specify tasks=2C questions=2C and in= tent better. But in 1987=2C in their <a href=3D"
https://books.google.com/b= ooks/about/Understanding_Computers_and_Cognition.html?id=3D6TwbGGSz6NYC">s= eminal book</a> on AI=2C <a href=3D"
https://spectrum.ieee.org/tag/terry-wi= nograd">Terry Winograd</a> and Fernando Flores succinctly captured why tha=
t won=E2=80=99t work: =E2=80=9CQ: Is there any water in the refrigerator?=
A: Yes. Q: Where? I don=E2=80=99t see it. A: In the cells of the eggplant= =2E=E2=80=9D In human language=2C wants and desires are <a href=3D"
https://w= ww.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html">alwa= ys</a><a href=3D"
https://metarationality.com/purpose-of-meaning"> underspe= cified</a>. It is impossible <a href=3D"
https://metarationality.com/reason= able-reference">to list</a> all the caveats=2C all the limitations=2C all=
the exceptions.</p>
<p>So how does anyone communicate=2C if intent can=E2=80=99t be pinned dow=
n? Because a reasonable person can make a reasonable guess. Even though wa=
nts and desires are always underspecified=2C a competent person generally=
knows enough context to get it right or else knows to ask for clarificati=
on. Linguists call this <a href=3D"
https://en.wikipedia.org/wiki/Pragmatic= s">pragmatics</a>: Meaning lies in the words and the situation and also in=
all prior communication=2C shared culture=2C and innate human behavior.</=
<p>It doesn=E2=80=99t always work out=2C of course. Your friend might brin=
g you a hot coffee when you wanted an iced coffee=2C or an Italian coffee=
when you wanted a Turkish coffee. The more dissimilar the two people are=
in age=2C culture=2C and background=2C the more likely the request will b=
e misunderstood in some way.</p>
<p>This situation has major implications for <a href=3D"
https://spectrum.i= eee.org/tag/agentic-ai">AI agents</a> that are increasingly being given re= quests by humans and expected to fulfill them. They have enormous latitude=
to get it wrong. An AI agent asked for coffee might buy a coffee plantati=
on or order a cup of coffee for delivery in three weeks. Its actions may b=
e recognizable as =E2=80=9Cgetting coffee=2C=E2=80=9D but not remotely wha=
t you intended. They=E2=80=99ll think outside the box because they won=E2= =80=99t have our conception of the box.</p>
<h3 style=3D"font-size:110%;font-weight:bold">When AI Gets Proactive</h3>
<p>For most of the last decade=2C when systems like <a href=3D"
https://spe= ctrum.ieee.org/tag/alexa">Alexa</a> or <a href=3D"
https://spectrum.ieee.or= g/tag/siri">Siri</a> misinterpreted a request=2C it was annoying=2C not da= ngerous. Beyond the AI model itself=2C what has <a href=3D"
https://www.the= guardian.com/commentisfree/2026/jun/16/anthropic-fable-ai">changed</a> is=
the harness: the ordinary code that wraps around an AI model=2C decides w=
hen and how to use the model=2C and controls access to tools like a browse= r=2C a low-level command line=2C or a financial API. Developments in harne= sses have turned large-language models that just predict text into AI agen=
ts that take actions in the world=2C without necessarily checking back in=
before reaching the goal.</p>
<p>AI researcher Simon Willison <a href=3D"
https://simonwillison.net/2026/= Jun/11/fable-is-relentlessly-proactive/">spent two days</a> with Anthropic= =E2=80=99s Fable AI=2C and called it =E2=80=9Crelentlessly proactive.=E2= =80=9D For example=2C he asked it to track down a stray scroll bar in a we=
b app. He came back to find it had opened browsers=2C written its own scre= enshot tooling=2C created its own page to re-create the bug=2C and stood u=
p a local web server to collect measurements. It found the bug and=2C alon=
g the way=2C did many surprising things he never asked it to do. And we ar=
e seeing similar behavior with all recent AI models when combined with fle= xible harnesses.</p>
<p>This kind of behavior could easily go off the rails. Tell an AI agent t=
o book you a flight and=2C finding the airline=E2=80=99s site says sold ou= t=2C it might break into the booking database and force a reservation. Ask=
it to schedule a meeting and it might snoop your password to access your=
calendar. Tell it to save money on your phone plan and it might cancel th=
e plan outright=2C or scam someone else into paying the bill.</p>
<p>Getting precisely what you asked for and bitterly regretting it is one=
of the oldest hazards from ancient folklore. <a href=3D"
https://en.wikipe= dia.org/wiki/Midas">King Midas</a> asked Dionysus for the power to turn ev= erything he touched into gold only to see his bread=2C wine=2C and daughte=
r turn to gold. <a href=3D"
https://en.wikipedia.org/wiki/Tithonus">Tithonu= s</a>=2C granted the immortality his lover asked for but not the eternal y= outh she forgot to request=2C withered into a husk. The <a href=3D"https:/= /en.wikipedia.org/wiki/The_Sorcerer's_Apprentice">sorcerer=E2=80=99s appre= ntice</a> enchanted a broom to fill the cistern=2C and the broom relentles=
sly complied until it flooded the house. The <a href=3D"
https://en.wikiped= ia.org/wiki/Golem%23Classic_narrative:_The_Golem_of_Prague">Golem of Pragu= e</a>=2C shaped from clay to guard its community=2C guarded it past all re= ason until someone erased the word on its forehead.</p>
<p>The most classic of these is a genie=2C bound to obey and indifferent t=
o whether the wish was wise or well-structured.</p>
<p><a href=3D"
https://www.schneier.com/academic/archives/2021/04/the-comin= g-ai-hackers.html">Genies are now</a> an engineering problem. We are handi=
ng them the keys to our inboxes=2C bank accounts=2C code repositories=2C a=
nd physical infrastructure. And we have no agreed-upon ways to measure how=
genie-like any AI system actually is.</p>
<h3 style=3D"font-size:110%;font-weight:bold">Measuring Genie Behavior</h3=
<p>In economics=2C the <a href=3D"
https://ourworldindata.org/what-is-the-g= ini-coefficient">Gini coefficient</a> (developed by statistician Corrado G= ini) is a measure of the gap between an actual distribution and a perfectl=
y equal one; it=E2=80=99s useful for understanding income inequality and <=
a href=3D"
https://www.fastly.com/blog/using-gini-coefficient-plan-edge-cap= acity">more</a>. Our proposed Genie coefficient measures the gap between w=
hat a user asked an AI to do and what the AI actually did.</p>
<p>Sometimes the AI might do the wrong thing. Like Dionysus=2C it reads yo=
ur request literally and returns you a mess you never intended: like a cof=
fee plantation instead of a cup. Asked to deal with all the spam phone cal=
ls you=E2=80=99re getting=2C a Dionysus genie might contact your carrier a=
nd change your phone number. Asked to get a refund for a bad toaster=2C it=
might draft a legal threat on fake letterhead and send it to the retailer= =2E</p>
<p>Other times the AI does exactly the right thing=2C trampling everything=
nearby to get there. Like a golem or the sorcerer=E2=80=99s broom=2C it b= ooks your flight by hacking the airline. Or consider a ticket sale for a p= opular concert=2C where the ticketing system puts buyers into a virtual wa= iting room and admits them a few at a time. Asked to buy a ticket=2C a gol=
em genie might spin up cloud servers to pose as millions of buyers from di= fferent addresses=2C improving your odds of getting a ticket while crowdin=
g out other users.</p>
<p>The two are not opposites=2C and a single botched task can have both ch= aracteristics.</p>
<p>Genie behavior is not flat-out failure. If you ask the AI for Q3 number=
s and get Q2=E2=80=99s=2C that=E2=80=99s not a genie. Nor is <a href=3D"ht= tps://spectrum.ieee.org/prompt-injection-attack">prompt injection</a>: Tha= t=E2=80=99s someone tricking the AI into doing something it shouldn=E2=80= =99t. Here=2C the user is trying to work with the AI=2C and the AI is tryi=
ng to comply. It=E2=80=99s also not simply a measure of the AI=E2=80=99s s= uccess in fulfilling a task. It=E2=80=99s a recognition that how an AI int= erprets and achieves a goal is as important as whether it achieves a goal.=
<p>Genie behavior isn=E2=80=99t new. Researchers have spent years studying=
AI systems that =E2=80=9Cgame=E2=80=9D their objectives. <a href=3D"https= ://www.cna.org/analyses/2022/09/goodharts-law">Goodhart=E2=80=99s law</a>=
says that when a measure becomes a target=2C it stops being a good measur= e=2C and it=E2=80=99s long been known that AIs sometimes achieve goals in=
ways we don=E2=80=99t expect due to reward hacking. Some AI models will a= ccidentally learn that <a href=3D"
https://metr.org/blog/2026-06-26-gpt-5-6= -sol/">cheating is one way</a> to =E2=80=9Cwin.=E2=80=9D More recently=2C=
researchers have developing benchmarks for <a href=3D"
https://www.lesswro= ng.com/posts/qJYMbrabcQqCZ7iqm/impossiblebench-measuring-reward-hacking-in= -llm-coding-1">reward hacking</a> in coding agents and for unpredictable b= ehavior in <a href=3D"
https://taubench.com/">customer support agents</a>=
=2C while AI labs conduct their own safety evaluations before model releas=
es. <a href=3D"
https://spectrum.ieee.org/ai-agents-safety">One effort</a>=
found that AIs under pressure use tools they were told not to use=2C and=
this was a case where the rules were made explicit. These are all dispara=
te research directions; nothing yet ties them together.</p>
<p>This problem falls under the general theme of alignment=2C a topic that=
has occupied <a href=3D"
https://en.wikipedia.org/wiki/I=2C_Robot">science=
fiction</a> writers and AI researchers for decades. At one extreme=2C the=
=E2=80=9Cpaper-clip maximizer=E2=80=9D thought experiment postulates a su= perintelligent and powerful AI that is told to maximize paper-clip product=
ion and turns the world into paper clips=2C which is the ultimate golem ge= nie. At a mundane level=2C AI researchers are working to better design rew=
ard functions to ensure that AIs behave well and don=E2=80=99t cheat in th=
e lab. It=E2=80=99s the practical middle ground that remains unbenchmarked=
: the ordinary AI agent in use today that might take your request and sati=
sfy it the wrong way. We are not at the stage where an AI can focus the wo= rld=E2=80=99s production on paper clips=2C but it might charge a million p= aper clips to your credit card or hack into a paper-clip company=E2=80=99s=
network.</p>
<h3 style=3D"font-size:110%;font-weight:bold">Building a Genie Benchmark</=
<p>The Genie coefficient is meant for AI agents operating in the real worl=
d. It measures their behavior as they perform real tasks long after the mo=
del is trained=2C not just during development. It also recognizes that gen= ie-like behavior is a property of the harness-plus-model system=2C not the=
model alone. The harness determines what tools the agent can use=2C how m=
uch autonomy it has=2C and how proactive it is=2C and it=E2=80=99s a place=
we can make real interventions.</p>
<p>It rests on the same =E2=80=9Creasonable person=E2=80=9D standard that=
we use for people. Did the system do what a reasonable person would have=
taken the request to mean? Answering that requires human judgment.</p>
<p>If we get the measurement right=2C it enables things that aren=E2=80=99=
t possible today=2C like policies concerning AI behavior. In a courtroom=
=2C the concept of<a href=3D"
https://www.law.cornell.edu/wex/mens_rea"> me=
ns rea</a>=2C what someone meant to do=2C is often as important as what th=
ey did. The Genie coefficient suggests an AI analogue=2C where a user is a= ccountable for the plain intent of what they asked the AI. If an AI system=
betrays the reasonable meaning of an instruction=2C that=E2=80=99s the AI= =E2=80=99s misbehavior=2C not the user=E2=80=99s.</p>
<p>We=E2=80=99ll need multiple benchmarks to measure the Genie coefficient=
=2C because genie-like behavior can be domain specific. An AI coding agent=
may need to be judged on how often it fakes the tests=2C or swallows erro= rs=2C or colors outside the lines on its way to a solution. An AI legal ag=
ent will need to be judged on how often its output says what you asked but=
means something you=E2=80=99ll regret. And so on for medical=2C finance=
=2C and other domains of knowledge and expertise.</p>
<p>Genie benchmarks can be built inside out=2C each task seeded with a cho=
ice that might literally satisfy but that a reasonable person rejects=2C s=
uch as tempting misreadings or unsanctioned shortcuts. The traps in a Geni=
e coefficient benchmark might turn on situational knowledge=2C the kind of=
<a href=3D"
https://spectrum.ieee.org/prompt-injection-attack">context tha=
t a reasonable person</a> would bring to the task. Another approach is to=
give the same request in several different contexts=2C each with a differ=
ent reasonable course of action.</p>
<p>A Genie benchmark should be permissive and make it genuinely tempting f=
or an AI agent to take unreasonable shortcuts=2C because it can only find=
genie behavior when it=E2=80=99s actually possible. Test the AI in a safe=
=2C walled-off copy of a real system=2C with real tools it can misuse and=
some tasks that can=E2=80=99t be done honestly at all. Make the temptatio=
n to cut corners real. Test a diverse array of skills=2C use cases=2C and=
tools=2C and give the AI system sparse=2C confusing=2C or overwhelming co= ntext. Include tasks that people have learned=2C through experience=2C req= uire human oversight.</p>
<p>How the benchmark is scored matters just as much. Measure Dionysus and=
golem genies separately and together=2C based on their worst=2C not best=
=2C behavior. Run the same model inside harnesses that vary its freedom to=
act=2C revealing which limits actually keep it in line and should therefo=
re be required in AI harness policies. Weight each failure by the harm it=
would cause=2C not just a simple count. And don=E2=80=99t measure genie b= ehavior in isolation: A model could otherwise earn a perfect score by stal= ling=2C refusing=2C or drowning the user in clarifying questions without e=
ver doing the job. The first versions of these benchmarks will be crude=2C=
but that=E2=80=99s how benchmarks always start.</p>
<p>We have built genies. We have handed them our data and credentials. We=
made them relentless=2C creative=2C and indifferent to the gap between wh=
at we tell them and what we mean. The least we can do=2C before they are b= ooking our flights=2C running our infrastructure=2C and signing contracts=
unsupervised=2C is to measure how often they betray us.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg9"><a name=3D"cg9">C= ognyte Sells a Mobile Cell Surveillance Van</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/cognyte-sells= -a-mobile-cell-surveillance-van.html"><strong>[2026.07.27]</strong></a> Y=
et another Israeli <a href=3D"
https://www.forbes.com/sites/thomasbrewster/= 2026/07/13/israels-palantir-rival-is-selling-1-million-spy-vans-to-us-cops= /">mass surveillance company</a>:</p>
<blockquote><p>Made by Israeli surveillance company Cognyte=2C the tech si= mulates a mobile phone tower=2C which forces nearby phones to connect to i=
t. That enables cops to keep tabs on any phones in the vicinity whether t= hey=E2=80=99re owned by a suspect in a case or not. Cognyte=E2=80=99s cont= ract with the state of Texas reveals that the simulator=2C called FalcoNet=
=2C can be concealed within the vehicles=2C hidden in a backpack for on-fo=
ot missions or attached to a helicopter. It=E2=80=99s the same technology=
as the infamous Stingray=2C one of the original cell-site simulators made=
by defense giant L3Harris.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg10"><a name=3D"cg10"= >Axon Is Another License Plate Surveillance Company</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/axon-is-anoth= er-license-plate-surveillance-company.html"><strong>[2026.07.28]</strong>=
</a> Governments are switching=2C but I=E2=80=99m not sure it <a href=3D"h=
ttps://www.jalopnik.com/2215173/flock-cameras-replaced-by-axon-difference/= ">makes a difference</a>:</p>
<blockquote><p>...some municipalities=2C including Denver=2C Colorado=2C a=
re ditching their Flock arrays. But keep in mind that if they=E2=80=99re o=
nly switching from Flock to another brand of license-plate readers=2C like=
Axon=2C it=E2=80=99s like a gambling addict trying to kick the habit by s= witching from FanDuel to DraftKings.</p>
<p>[...]</p>
<p>Despite what you may read on the Flock website=2C Axon cameras are pret=
ty effective when it comes to hoovering up personal details that can go fa=
r beyond your license plate numbers. That means a municipality that opts f=
or Axon cameras instead of Flock units won=E2=80=99t necessarily reduce th=
e amount privacy its citizens lose through their use.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg11"><a name=3D"cg11"= >Measuring LLMs' Ability to Perform Cryptanalysis</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/measuring-llm= s-ability-to-perform-cryptanalysis.html"><strong>[2026.07.28]</strong></a=
There=E2=80=99s new benchmark measuring AI=E2=80=99s ability to perform=
mathematical cryptanalysis. Anthropic=E2=80=99s frontier model actually f= ound new attacks.</p>
<p>The benchmark: =E2=80=9C<a href=3D"
https://arxiv.org/pdf/2607.18538">Cr= yptanalysisBench: Can LLMs do Cryptanalysis?</a>=E2=80=9D The idea is to b= enchmark the ability of LLMs to discover new mathematical cryptanalytic at= tacks against a series of historical algorithms.</p>
<blockquote><p><b>Abstract:</b> Cryptanalysis -- the task of finding attac=
ks against cryptographic schemes -- its at the intersection of mathematica=
l reasoning and cybersecurity=2C two areas where LLMs have advanced fastes=
t. Cryptanalysis represents both a clean testbed for frontier reasoning (a=
s practical attacks can be automatically verified) and a domain with unusu= ally high stakes=2C since the primitives under study underpin our digital=
security. In this paper we ask whether LLMs can do cryptanalysis=2C and f=
ind that the answer is increasingly yes. We introduce CryptanalysisBench=
=2C 191 tasks across six families of cryptographic primitives (block ciphe= rs=2C hash functions=2C etc.) drawn primarily from four NIST standardizati=
on competitions. Our benchmark consists of three tiers: (i) primitives wit=
h known practical breaks; (ii) primitives with no known practical break=2C=
evaluated both at full strength and as scaled-down variants; and (iii) a=
challenge set of production primitives at the frontier of cryptanalysis.=
Five frontier models (Claude Opus 4.8=2C Sonnet 5=2C Mythos 5=2C GPT-5.5=
=2C and the open-weights GLM-5.2) break 65%86% of Tier 1 schemes=2C 612 Ti= er-2 schemes at full strength=2C and 2461 across all scaled-down variants.=
Beyond deriving known results=2C models produce novel cryptanalysis=2C su=
ch as a key-recovery attack that exploits a design flaw in the SpoC AEAD a=
nd an error in KINDI=E2=80=99s published CCA-security proof=2C both to the=
best of our knowledge not previously known.</p>
<p>We release CryptanalysisBench as a tool to help track if (or when) AI c= ryptanalysis becomes a serious factor and as a scaffold for stress-testing=
candidate schemes before deployment. The attacks that the benchmark alrea=
dy surfaces are an early snapshot of a fast-moving frontier that may soon=
match=2C and in places exceed=2C the published state of the art.</p></blo= ckquote>
<p>Anthropic used the benchmark to test Mythos Preview=2C and <a href=3D"h= ttps://www.anthropic.com/research/discovering-cryptographic-weaknesses">fo= und</a> new vulnerabilities in Hawk and reduced-round AES.</p>
<p>Still early results=2C but this is definitely something to watch.</p>
<p>SlashDot <a href=3D"
https://it.slashdot.org/story/26/07/28/1911218/anth= ropic-ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms">thread= </a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg12"><a name=3D"cg12"= >Long-Lived Vulnerability in Microsoft Secure Boot</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/long-lived-vu= lnerability-in-microsoft-secure-boot.html"><strong>[2026.07.29]</strong><=
Microsoft=E2=80=99s Secure Boot has had a <a href=3D"https://arstechni=
ca.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-= its-existence/">serious vulnerability</a> for most of its existence.</p>
<blockquote><p>An industry-wide standard Microsoft invented to protect Win= dows=2C and later Linux=2C devices from firmware infections has been trivi=
al to bypass for 13 of its 14 years of existence. The discovery was made b=
y researchers at security firm ESET after identifying 11 firmware images=
=2C at least one from 2013=2C that were known to be defective but remained=
signed by the software company anyway.</p>
<p>The images are known as <a href=3D"
https://en.wikipedia.org/wiki/Shim_(= computing)">shims</a>=2C which were invented to extend Secure Boot to Linu=
x devices and utility software. Using a technique simple enough to be perf= ormed by novice hackers=2C these old=2C forgotten shims can be used to com= pletely circumvent the protection=2C which is embedded into the UEFI (Unif=
ied Extensible Firmware Interface) of the device=E2=80=99s motherboard. Th=
e gaffe is the result of the failure by Microsoft=2C which oversees the si= gning of shims=2C to revoke the publicly available images once vulnerabili= ties were found in them.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg13"><a name=3D"cg13"= >Measuring the Tendency of AI Agents to Go Rogue</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/measuring-the= -tendency-of-ai-agents-to-go-rogue.html"><strong>[2026.07.29]</strong></a=
<em>This essay was written with Barath Raghavan=2C and originally appear=
ed in <a href=3D"
https://www.theguardian.com/commentisfree/2026/jul/28/rog= ue-ai-agent-instructions">The Guardian</a>.</em></p>
<p>In July=2C Hugging Face=2C a company that hosts much of the world=E2=80= =99s AI software and open-source AI models=2C was hacked. A malicious data=
set had been used to run code on one of its servers. Whoever was behind it=
captured internal security credentials and moved through systems over a w= eekend=2C running thousands of actions from a swarm of temporary server en= vironments. It looked like the work of a sophisticated criminal group.</p>
<p>It was not. It was one of OpenAI=E2=80=99s new=2C still unreleased GPT=
models.</p>
<p>Their science experiment had <a href=3D"
https://www.theguardian.com/tec= hnology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-i= n-unprecedented-incident">escaped</a> the lab. OpenAI was running the unre= leased AI model through a benchmark that tests how well AI can successfull=
y hack systems. To push the limits and evaluate the AI=E2=80=99s true capa= bility=2C the company switched off the safety filters that normally stop i=
t from doing this kind of hacking. Aware that this could go wrong=2C they=
confined the AI to an isolated environment and denied it access to the in= ternet.</p>
<p>But the new AI cheated. It took literally its goal to get as high of a=
score as possible. It broke out on to the open internet. It inferred=2C p= robably from its training data=2C that it could =E2=80=9Csolve=E2=80=9D th=
e task by getting the answers from Hugging Face=E2=80=99s servers. So it c= hained together stolen credentials and further unknown security exploits t=
o hack the company=E2=80=99s network.</p>
<p>Nobody instructed the AI to do any of this. It was=2C in <a href=3D"htt= ps://openai.com/index/hugging-face-model-evaluation-security-incident/">Op= enAI=E2=80=99s words</a>=2C =E2=80=9Chyperfocused on finding a solution=E2= =80=9D to the test it was being given. And while this might seem like some= thing new with AI=2C it=E2=80=99s really very old. This is how a genie beh= aves=2C and it is a key challenge with AI agents in general.</p>
<p>In folklore=2C genies -- and other magical beings -- grant wishes liter= ally=2C not how the wisher intended. King Midas asked that everything he t= ouched turn to gold=2C and starved. The sorcerer=E2=80=99s apprentice want=
ed the broom to fill the cistern=2C and it performed its task so well that=
it flooded the house.</p>
<p>We now have machines that do this. Ask a modern AI agent to save money=
on your phone plan and it might simply cancel the plan. Tell it to book a=
flight=2C and it might hack the airline website to override restrictions.=
Or=2C like OpenAI=2C ask it to do well on a test and it might break into=
another company to steal the answers. Each time=2C it recognizably comple=
ted the task you set=2C but it didn=E2=80=99t do what you would have wante= d.</p>
<p>This isn=E2=80=99t malicious behavior. No one asked for=2C or wanted=2C=
Hugging Face to be hacked. OpenAI and Hugging Face and the AI were ostens= ibly on the same side=2C and the AI was trying to do what it had been aske=
d. That=E2=80=99s what makes it so difficult to guard against: you can=E2= =80=99t filter for bad instructions because the instructions were fine.</p=
<p>The gap is between the words we use and what we mean by them. We call t=
hat gap the <a href=3D"
https://spectrum.ieee.org/ai-agent-benchmark">Genie=
coefficient</a>.</p>
<p>AI labs know this is a problem=2C and they=E2=80=99re quietly saying so=
=2E For example=2C the Chinese lab Moonshot recently <a href=3D"
https://www.= kimi.com/blog/kimi-k3">warned</a> that its latest AI model may have =E2=80= =9Cexcessive proactiveness=E2=80=9D and =E2=80=9Cmake unexpected decisions=
on the user=E2=80=99s behalf=E2=80=9D. The UK=E2=80=99s AI Security Insti= tute has started <a href=3D"
https://www.aisi.gov.uk/blog/cheating-behaviou= r-in-frontier-model-evaluations">tracking</a> =E2=80=9Ccheating behavior i=
n frontier model evaluations=E2=80=9D. We wouldn=E2=80=99t tolerate a car=
that is <a href=3D"
https://simonwillison.net/2026/Jun/11/fable-is-relentl= essly-proactive/">excessively proactive</a> or <a href=3D"
https://www.thea= tlantic.com/technology/2026/07/openai-hugging-face-hack/688025/?utm_source= =3DSailthru&utm_medium=3Demail&utm_campaign=3DAtlantic%20Intelligence%20%2= 8V3%29">ruthlessly efficient</a>=2C and yet that=E2=80=99s the reality of=
AI today.</p>
<p>Improvement is possible. Just as AIs have gotten much better at resisti=
ng prompt injection attacks over the last few years=2C we can safely predi=
ct that they will get better at avoiding genie-like behavior. The point of=
the Genie coefficient is to track progress. AI companies like benchmarks=
=2C and they all work to compete to be the best.</p>
<p>Dozens of benchmarks and leaderboards tell us how well these AI models=
write code=2C perform logical reasoning=2C and pass standardized legal an=
d medical exams. But there is nothing that scores whether a system does wh=
at you actually meant. We need to develop a measure for this=2C test it re= gularly=2C and push for improvement. We=E2=80=99re not going to have trust= worthy AI agents without it.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg14"><a name=3D"cg14"= >Should You Use AI for a Task? Here=E2=80=99s a Simple Way to Decide</a></=
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/should-you-us= e-ai-for-a-task-heres-a-simple-way-to-decide.html"><strong>[2026.07.30]</= strong></a> <em>This essay originally appeared in <a href=3D"
https://www.t= heguardian.com/commentisfree/2026/jul/24/should-you-use-ai">The Guardian</= a>.</em></p>
<p>I teach public policy at the Harvard Kennedy School and the Munk School=
at the University of Toronto. And it will come as no surprise to you that=
my students regularly <a href=3D"
https://www.insidehighered.com/news/facu= lty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class= -used-ai-cheat">use AI</a> to complete their writing assignments. Doing so=
is a waste of their tuition money. But if their entire career is going to=
include AI writing assistants=2C why shouldn=E2=80=99t they embrace their=
future?</p>
<p>The best way I=E2=80=99ve found to explain the dilemma <a href=3D"https= ://danielmiessler.com/blog/keep-the-robots-out-of-the-gym">comes from</a>=
the AI researcher Daniel Meissler: it=E2=80=99s the difference between wo=
rk and the gym.</p>
<p>At work=2C if your job is to move a bunch of heavy things from one side=
of the room to another=2C you should use whatever assistive tech you have=
on hand: a wagon=2C a forklift... even an AI-powered robot. But at the gy= m=2C it makes no sense for that robot to lift weights for you. The point o=
f weightlifting isn=E2=80=99t to move heavy things across the room; it=E2= =80=99s to actually lift those heavy things.</p>
<p>The same analysis holds for any task an AI can do for you. If it=E2=80=
=99s work -- if the task has to be done and no one cares how -- then it=E2= =80=99s fine to use AI assistance. But if the task is more like the gym=2C=
and <em>how</em> the task is done is at least as important=2C then it pro= bably doesn=E2=80=99t make sense to use AI.</p>
<p>This=2C of course=2C assumes that the AI is actually up for the task an=
d that it=E2=80=99s <a href=3D"
https://www.schneier.com/academic/archives/= 2025/06/ai-and-trust.html">trustworthy</a>: that it can do the job well=2C=
that its mistakes are minimal and correctable=2C that it=E2=80=99s been s= ecured from cyber-attacks that would influence its results. Those are all=
important=2C and shouldn=E2=80=99t be minimized. There=E2=80=99s no point=
giving an AI something that it can=E2=80=99t do reliably. But once you=E2= =80=99re confident that the AI can perform the task=2C the work vs. gym di= stinction helps you decide if it should.</p>
<p>The writing assignments I give my students are gym tasks=2C not work ta= sks. I ask them to write policy memos not because the world needs more pol=
icy memos. I assign them because the very act of writing=2C which includes=
thinking and outlining and drafting and editing=2C making and criticizing=
and revising arguments=2C will help develop the critical thinking skills=
they will need in their future careers. And without this constant mental=
exercise=2C those skills will atrophy. Employers are <a href=3D"
https://f= uturism.com/future-society/college-critical-thinking-ai">already noticing<= /a>.</p>
<p>Reading the assignments they turn in=2C I can see those skills either f= lourishing or atrophying in my students. At least today=2C I can pretty ea= sily tell the difference between an AI-written memo and a student-written=
one -- especially if the student just turns in what the chatbot produces.=
It=E2=80=99s a catchy=2C plausible=2C grammatically perfect essay that=E2= =80=99s not particularly well-crafted or logically coherent -- and with <a=
href=3D"
https://medium.com/@brentcsutoras/the-em-dash-dilemma-how-a-punct= uation-mark-became-ais-stubborn-signature-684fbcc9f559">all</a> <a href=3D= "
https://www.theatlantic.com/technology/2026/07/ai-chatbot-writing-tic-neg= ative-parallelism/687892/">the</a> <a href=3D"
https://www.forbes.com/sites= /charliefink/2025/06/12/the-seven-tells-of-ai-writing/">tells</a> of mid-2=
026 AI-generated writing.</p>
<p>But it=E2=80=99s precisely because I have spent years developing my own=
writing skills that I=E2=80=99m able to identify prose that sounds great=
but doesn=E2=80=99t actually make sense. My students don=E2=80=99t have t=
hat skill; they mistakenly view a confident=2C well-written essay as evide=
nce of the quality of their ideas. They see the AI as cleaning those ideas=
up=2C getting them through that uncomfortable stretch of having to turn t= hose ideas into prose. What the students miss is that their initial discom= fort is a normal and healthy stage of writing=2C and not something to quic=
kly get beyond. The very act of struggling with how to express what they t= hink is an important part of the process. It=E2=80=99s how they test out t= heir ideas=2C examine their hypotheses=2C and actually figure out what the=
y think. Homework is not work; it=E2=80=99s the gym.</p>
<p>Work vs. gym also helps us understand the problem facing creatives of a=
ll kinds.</p>
<p>Most of the time when someone hires a writer=2C they just need the word=
s. They need an instruction manual for a piece of equipment=2C a detailed=
sales presentation=2C a government-mandated disclosure document=2C or a l= egal brief. They need dry=2C predictable=2C accurate writing: a piece of w= ork=2C exactly what AIs are good at today and what I don=E2=80=99t want in=
my student assignments. Only sometimes is writing an art form -- a book=
=2C a poem=2C an uplifting political speech. That kind of writing is more=
like the gym: process matters just as much as product.</p>
<p>For most of human history=2C the only option for all of these tasks was=
human writers. We hired one regardless of whether we needed work writing=
or gym writing. And that paid a lot of writers=E2=80=99 salaries. I know=
fiction writers who supported that poorly paying career with lucrative te= chnical writing work. Now=2C for the first time in human history=2C we can=
separate out when we need writing as work and when we want writing as gym=
=2E And if AI can do most of the work-type writing=2C society doesn=E2=80=99=
t need as many human writers.</p>
<p>It=E2=80=99s the same for visual artists. Sometimes we need an actual a= rtist=2C but most of the time we just need an image: a corporate mascot=2C=
a =E2=80=9Cbeware of the dog=E2=80=9D sign=2C or a packaging label. Histo= rically we gave those jobs to artists=2C and sometimes <a href=3D"
https://= blog.artgeek.io/2025/10/20/art-deco-the-golden-age-of-illustration/">beaut= iful</a> art resulted. But most of the time it was just work. And=2C as it=
turns out=2C the world needs less pure art than simple images.</p>
<p>Explaining the problem isn=E2=80=99t the same as providing the solution=
=2E I give my students the =E2=80=9Cwork versus gym=E2=80=9D speech every cl= ass=2C but they <a href=3D"
https://www.insidehighered.com/news/faculty/lea= rning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-a= i-cheat">still use</a> AI. I have sympathy: assignments are hard=2C everyo=
ne is overworked and overstressed=2C and -- most importantly -- students f=
eel like they=E2=80=99ll look bad in comparison if their peers are all usi=
ng AI. Even if they don=E2=80=99t want to use the technology=2C they feel=
like they have<a href=3D"
https://bsky.app/profile/jeffsharlet.bsky.social= /post/3mog5n2uhjs2r"> no choice</a>.</p>
<p>There=E2=80=99s also an incentive problem. No one pays us to go to the=
gym; maintaining healthy habits requires discipline. For me=2C the payoff=
s to exercise -- fewer aches and pains=2C less fatigue=2C better mood/stre=
ss management -- might make me a better writer and teacher=2C but they=E2= =80=99re subtle and easy to miss. For my students=2C incremental improveme=
nts in their reasoning and writing are equally subtle.</p>
<p>We do have a choice. We can look at the tasks of our lives and separate=
them into work or gym. Just as we might choose to use the stairs instead=
of the elevator=2C or walk instead of calling an Uber=2C we can wall off=
our cognitive gym tasks from AI and ensure that we don=E2=80=99t lose our=
skills to this technology. And we can do the same when we assign a job to=
someone else. If it=E2=80=99s a work task=2C we can have AI do it. If it= =E2=80=99s a gym task=2C it=E2=80=99s a waste of everyone=E2=80=99s time t=
o give it to an AI because no one learns or gets stronger as a result.</p>
<p>Similarly=2C a future where AI generates words and images is one where=
society has to make choices about how it will treat its creatives. This w= on=E2=80=99t be the first time -- today there is minimal demand for portra=
it painters=2C for example -- but maybe this time we can make different=2C=
more deliberate=2C choices about the value of art in our society.</p>
<p>AI is going to fundamentally change the nature of work. Not nearly as f=
ast as the AI companies want you to believe=2C but eventually it will. Pol=
icy analysis will definitely involve AI from now on=2C and my students nee=
d to reimagine what it means to learn and practice that skill. More genera= lly=2C the line between work and gym will change in the future as we human=
s adapt ourselves to a world with these new intelligences.</p>
<p>But for now=2C the work vs. gym distinction is pretty clear. Use it on=
yourself.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg15"><a name=3D"cg15"= >American Being Prosecuted for Wiping His Phone Before Handing It Over to=
Border Officials</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/american-bein= g-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-officia= ls.html"><strong>[2026.07.30]</strong></a> He=E2=80=99s being prosecuted=
for giving border officials a code that <a href=3D"
https://techcrunch.com= /2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-dure= ss-password-during-border-search/">wiped his phone</a>:</p>
<blockquote><p>The case centers on a feature included in GrapheneOS=2C a c= ustom Android operating system that runs in place of the software on most=
modern Google Pixel devices. Tunick=E2=80=99s attorneys confirmed Graphen=
eOS was running on his phone.</p>
<p>The software feature allows the device owner to set a passcode that del= iberately wipes the contents of that device if entered instead of the user= =E2=80=99s unlock passcode.</p>
<p>Tunick=E2=80=99s case also raises ongoing questions about what constitu= tional rights can be invoked at the border=2C which the U.S. government ha=
s long asserted is not U.S. soil until a person is authorized to enter.</p= ></blockquote>
<p>Right. And he wasn=E2=80=99t under arrest=2C either.</p>
<p><a href=3D"
https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro= tester-phone">Three more</a> <a href=3D"
https://boingboing.net/2026/07/25/= grapheneos-duress-password-border-search.html">news</a> <a href=3D"https:/= /gizmodo.com/a-feature-that-makes-your-phone-data-self-destruct-in-authori= ties-hands-may-soon-have-its-day-in-court-2000790831">stories</a>.</p>
<p>Graphene <a href=3D"
https://www.pcmag.com/news/grapheneos-defends-data-= wiping-function-that-blocked-us-border-search">says</a> that the feature i=
s =E2=80=9C<a href=3D"
https://x.com/GrapheneOS/status/2081770030992118183"= >completely legal</a>=E2=80=9C:</p>
<blockquote><p>GrapheneOS is completely legal. We have no obligation to we= aken any of the security protections it provides. Creating and using Graph= eneOS is strongly protected by the US constitution. Laws attempting to mak=
e it illegal or require weakening the security would be unconstitutional.<= /p></blockquote>
<p>It=E2=80=99s hard to know how much the Constitution matters in the US r= ight now.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg16"><a name=3D"cg16"= >Facial Recognition at Madison Square Garden</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/facial-recogn= ition-at-madison-square-garden.html"><strong>[2026.07.31]</strong></a> La=
st month=2C the story <a href=3D"
https://www.404media.co/madison-square-ga= rden-made-dossier-on-activists-who-opposed-facial-recognition/">broke</a>=
(alternate <a href=3D"
https://archive.ph/ZGqfH">link</a>) that Madison Sq= uare Garden uses facial recognition software on everyone entering the faci= lity=2C and -- among other groups -- flags activists that oppose using fac=
ial recognition.</p>
<p>Turns out that the system was <a href=3D"
https://www.wired.com/story/fo= r-taylor-swift-madison-square-gardens-controversial-cameras-briefly-went-d= ark/">shut off</a> for Taylor Swift=E2=80=99s wedding.</p>
<p>Evan Greer -- one of the people that MSG alerts on -- <a href=3D"https:= //www.ms.now/opinion/taylor-swift-and-travis-kelce-got-to-buy-msgs-privacy= -her-fans-arent-so-lucky">comments</a>:</p>
<blockquote><p>Ironically=2C Swift herself has <a href=3D"
https://www.roll= ingstone.com/music/music-news/taylor-swift-facial-recognition-concerts-768= 741/">reportedly</a> used facial recognition at her own concerts to identi=
fy stalkers. This =E2=80=9Cprivacy for me=2C surveillance for thee=E2=80=
=9D attitude feels like a perfect encapsulation of the future we=E2=80=99r=
e already living in: one where wealthy elites can afford privacy=2C while=
the rest of us are forced to live in a corporate surveillance panopticon.= </p></blockquote>
<p>Whatever privacy measures Swift had in place for the wedding seems to h=
ave worked. No photos have leaked online.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg17"><a name=3D"cg17"= >Anthropic=E2=80=99s Opus 5 Is Better at Resisting Prompt Injection</a></h=
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/07/anthropics-op= us-5-is-better-at-resisting-prompt-injection.html"><strong>[2026.07.31]</= strong></a> The <a href=3D"
https://www-cdn.anthropic.com/c5fbac3f0b1280a93= 3ebd26d3cb8bb9f5bdeaf48/Claude%20Opus%205%20System%20Card.pdf#page=3D73">c= hart</a> is interesting.</p>
<blockquote><p>On the IPI benchmark=2C Opus 5 improved over Opus 4.8=2C re= ducing the probability of an attacker succeeding within 15 attempts from 5= =2E5% to 2.0%=2C and from 0.5% to 0.2% on 1 attempt. It also improved on Son= net 5 (5.9% at k=3D15) and Mythos 5 (2.6%)=2C making it the most robust mo=
del evaluated. Opus 5 also outperformed all non-Claude models on this benc= hmark. The most robust non-Claude model was Muse Spark at 16.5% within 15=
attempts -- more than eight times Opus 5=E2=80=99s rate. The most capable=
GPT 5.6 variant=2C Sol=2C was comparable to its predecessor GPT 5.5 (20.0=
% versus 20.8% within 15 attempts)=2C and was 10 times as likely to be suc= cessfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants ar=
e less robust=2C at 30.4% (Terra) and 43.9% (Luna). A single attempt again=
st GPT 5.6 Sol succeeded 3.1% of the time=2C higher than the 2.0% an attac=
ker achieved against Opus 5 after fifteen attempts.</p></blockquote>
<p>We know that preventing prompt injection is <a href=3D"
https://llm-atta= cks.org/">impossible</a> in the general case. But we are getting much bett=
er at blocking it in specific cases.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg18"><a name=3D"cg18"= >The OpenAI Hack Shows the Genie Is Out of the Bottle</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/the-openai-ha= ck-shows-the-genie-is-out-of-the-bottle.html"><strong>[2026.08.03]</stron= g></a> <em>This essay originally appeared in <a href=3D"
https://foreignpol= icy.com/2026/07/30/openai-hack-genie-bottle-defense/">Foreign Policy</a>.<= /em></p>
<p>Earlier this month=2C two of OpenAI=E2=80=99s models broke out of their=
containment sandbox and attacked another AI company. The <a href=3D"https= ://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html">= story</a> is kind of <a href=3D"
https://simonwillison.net/2026/Jul/22/open= ai-cyberattack/">wild</a>. OpenAI was running security tests on two of its=
models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-=
6. In particular=2C it was running the <a href=3D"
https://arxiv.org/abs/26= 05.11086">ExploitGym</a> benchmark=2C which measures how good a model is a=
t turning security vulnerabilities into working exploits: basically=2C off= ensive cyberattacks.</p>
<p>Since these were internal tests=2C OpenAI locked those models in a secu=
re sandbox that denied them access to the internet. But it was running the=
models without any safety filters that would prevent them from offensive=
cyber-actions. That meant that there was nothing to prevent the models fr=
om trying to <a href=3D"
https://huggingface.co/blog/security-incident-july= -2026">break out</a> of that sandbox. And then <a href=3D"
https://openai.c= om/index/hugging-face-model-evaluation-security-incident/">break into</a>=
AI company Hugging Face=E2=80=99s network because they thought that they=
could read the answers there rather than doing the hard work of trying to=
solve the puzzles.</p>
<p>It was a major security failure that the company has turned into a PR o= pportunity=2C but the implications are real -- and much more general than=
one particular model or one particular company.</p>
<p>Modern AI models exhibit <a href=3D"
https://spectrum.ieee.org/ai-agent-= benchmark">genie</a> behavior: They can do what you ask in ways that you d= on=E2=80=99t expect or want. This is akin to Dionysus granting King Midas= =E2=80=99s wish that everything he touches turn to gold (spoiler: His food=
=2C drink=2C and daughter all turn to gold on touch)=2C or the <a href=3D"=
https://prague.eu/en/golem-of-prague/">golem of Prague</a> guarding a ghet=
to beyond all reason. It=E2=80=99s Disney=E2=80=99s =E2=80=9C<a href=3D"ht= tps://disney.fandom.com/wiki/The_Sorcerer%27s_Apprentice">Sorcerer=E2=80=
=99s Apprentice</a>=E2=80=9D and the <a href=3D"
https://www.lesswrong.com/= w/squiggle-maximizer-formerly-paperclip-maximizer">paperclip maximizer</a>= =2E</p>
<p>This OpenAI incident is an example of an AI genie. The goal was to sati=
sfy the benchmark. The =E2=80=9Cproper=E2=80=9D way to do that is to figur=
e out how to execute various cyberattacks. The genie way is to steal someo=
ne else=E2=80=99s solution. But because the model didn=E2=80=99t understan=
d the difference=2C it chose the easier path.</p>
<p>And=2C of course=2C now that we have seen this particular genie behavio= r=2C we can specify in the benchmark prompt that stealing the test answers=
doesn=E2=80=99t count. But a clever genie can always grant your wish in a=
way that you wish it hadn=E2=80=99t. In human language=2C goals are alway=
s underspecified -- so AI genies will <a href=3D"
https://www.schneier.com/= academic/archives/2021/04/the-coming-ai-hackers.html">always be</a> a poss= ibility.</p>
<p>Since April=2C a lifetime ago in AI development=2C when Anthropic <a hr= ef=3D"
https://www.anthropic.com/research/mythos-preview">announced</a> tha=
t its new Mythos model was so good at finding software vulnerabilities tha=
t it could not be released to the general public=2C the big American AI fr= ontier labs have been trying to block general users from accessing these c= apabilities. But nothing in this incident is exclusive to OpenAI=E2=80=99s=
=2C or Anthropic=E2=80=99s=2C frontier models.</p>
<p>Agentic AI systems have two important parts. There=E2=80=99s the underl= ying model=2C which everyone talks about=2C and there=E2=80=99s the <a hre= f=3D"
https://www.theneuron.ai/explainer-articles/ai-harnesses-and-clis-exp= lained-the-real-reason-everyones-talking-about-infrastructure/">harness</a=
. The harness sits between what you type and what the model sees=2C and w=
hat the model produces and what you see. The harness determines what the m= odel does and how it does it. It=E2=80=99s where bias is removed=2C or not=
=2E It=E2=80=99s where <a href=3D"
https://medium.com/@michael.hannecke/safet= y-lives-in-the-harness-not-the-model-81090606f92d">controls</a> and guardr= ails live. If multiple models are being used in concert=2C the harness is=
where all of that is coordinated.</p>
<p>The OpenAI benchmark tests were almost certainly with simple harnesses=
=2C to better test the raw models. But we know that smaller=2C cheaper=2C=
open-source models with <a href=3D"
https://www.theguardian.com/commentisf= ree/2026/jun/16/anthropic-fable-ai">more sophisticated</a> harnesses can e= qual frontier models in performance. There=E2=80=99s nothing magic about O= penAI=E2=80=99s frontier models; lots of models could have done the <a hre= f=3D"
https://x.com/tqbf/status/2080045032162173329">same thing</a>.</p>
<p>The Czech company Aisle was able to <a href=3D"
https://aisle.com/blog/a= i-cybersecurity-after-mythos-the-jagged-frontier">reproduce</a> Anthropic= =E2=80=99s Mythos vulnerability finding results with a smaller=2C cheaper=
model and a more sophisticated harness. More importantly=2C the Chinese c= ompany Moonshot AI just released its frontier model: <a href=3D"
https://ww= w.kimi.com/blog/kimi-k3">Kimi K3</a>. Its performance <a href=3D"
https://w= ww.interconnects.ai/p/kimi-k3-the-open-weights-escalation">rivals</a> its=
US competitors. And it=E2=80=99s both free and open=2C which means it=E2= =80=99s not possible for it to have guardrails. If you=2C or anyone else=
=2C wants to use it for cyberattack=2C nothing can stop you.</p>
<p>Even if the US frontier AI companies had some technical advantage=2C it= =E2=80=99s now only a few months=E2=80=99 worth.</p>
<p>What this means is that all attempts at control -- limiting models to a=
<a href=3D"
https://www.anthropic.com/glasswing">select</a> <a href=3D"htt= ps://openai.com/daybreak/">group</a> of users=2C <a href=3D"
https://www.cs= is.org/analysis/understanding-us-allies-current-legal-authority-implement-= ai-and-semiconductor-export">export controls</a> on models and chips=2C <a=
href=3D"
https://freefable.org/">blocking</a> models from answering certai=
n types of queries=2C mandating <a href=3D"
https://www.bbc.com/news/articl= es/cx2vqj2e9x8o">kill switches</a> on AI systems=2C or <a href=3D"
https://= pauseai.info/">pausing</a> AI research -- are all futile. Most only apply=
nationally=2C not globally. Most don=E2=80=99t affect models that users r=
un locally and not in the cloud. And all ignore the incredible pace of AI=
development worldwide.</p>
<p>Even worse=2C US companies limit access to their most sophisticated mod= els=2C fearing being banned by the government if they do not do so. When H= ugging Face was attacked=2C it was not able to use the frontier models fro=
m either OpenAI or Anthropic to help analyze the attack and formulate defe= nses. Both were blocked=2C because both of those companies limit their mod= els=E2=80=99 cybersecurity capabilities. Some US companies have special ac= cess to these capabilities=2C but Hugging Face is an American company with=
French origins=2C and as such is probably excluded. Instead=2C Hugging Fa=
ce turned to the <a href=3D"
http://z.ai/blog/glm-5.2">GLM-5.2</a> model fr=
om the Chinese company Z.ai.</p>
<p>Artificially blocking capability also prevents cybersecurity research=
=2C again giving the offense an advantage. (For instance=2C Claude Fable 5=
refuses to edit this essay because of the topic; it forcibly downgrades t=
o a less capable model.) This kind of prohibition has long-term implicatio=
ns for cybersecurity. If we assume that these models are getting better ov=
er time=2C then software written by older models will be attacked by newer=
ones. In a world of largely AI-written software=2C we need the most capab=
le models for defense.</p>
<p>AI cyberattack is the new normal. The models are increasingly highly so= phisticated at both attack and defense=2C and there is no way to enable th=
e latter without also enabling the former. And they are genies=2C increasi= ngly capable of behaving in unanticipated ways.</p>
<p>And there really are no good answers. Any regulation needs to be global=
=2C which feels like an impossible prospect in today=E2=80=99s world. Even=
US national regulation will be neutered by the massive amounts of money s= loshing around in these companies.</p>
<p>Given that reality=2C and in the absence of any international consensus=
on AI regulation=2C we need the best AI on the defense. The US government=
needs to make it clear -- or whatever passes for that clarity in this cap= ricious administration -- that it will not ban models with sophisticated c= yber capabilities. The last thing Americans want is for the defenders to t=
urn to Chinese and other models because the US models are artificially hob= bled.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg19"><a name=3D"cg19"= >More on the OpenAI Agent=E2=80=99s Attack on Hugging Face</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/more-on-the-o= penai-agents-attack-on-hugging-face.html"><strong>[2026.08.03]</strong></=
Hugging Face has <a href=3D"https://huggingface.co/blog/agent-intrusion=
-technical-timeline">published</a> a detailed timeline of the attack. From=
the summary:</p>
<blockquote><p>The agent was running an internal OpenAI cyber-capability e= valuation based on the ExploitGym benchmark=2C which tasks an AI agent wit=
h finding and exploiting software vulnerabilities. OpenAI ran this on its=
own infrastructure=2C and the ExploitGym maintainers and their infrastruc= ture had no involvement in the deployment or operation of that evaluation=
environment. As far as we were able to infer=2C across the course of bein=
g evaluated on this benchmark=2C the agent inferred that Hugging Face may=
host that benchmark=E2=80=99s models=2C datasets=2C and reference solutio=
ns. We believe the entire intrusion was=2C from the agent=E2=80=99s point=
of view=2C an attempt to cheat the evaluation: reach our production syste=
ms and steal the test solutions rather than solve the challenge on its own= =2E</p>
<p>Our forensic reconstruction covers <b>~17=2C600 attacker actions</b> th=
at we were able to recover=2C grouped into ~6=2C280 clusters=2C between 20= 26-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these action=
s from the agent=E2=80=99s logs on a code sandbox used by the agent (see b= elow) and were able to map them to shell commands as well as evaluation su= bmissions and correlate actions with our own platform logs=2C in particula=
r from the dataset processor nodes=2C API=2C and pod. Using open-weights m= odels=2C in particular zai-org/GLM-5.2=2C we were able to decipher most of=
the agent payloads (see below) that were encrypted via chunking and key e= ncryption.</p>
<p>The campaign=2C as we were able to reconstruct it=2C had two stages:</p=
<ul><li><b>Stage 1: reaching a launchpad by chaining through other parties= =E2=80=99 infrastructure.</b> As documented in OpenAI=E2=80=99s blog post=
(<a href=3D"
https://openai.com/index/hugging-face-model-evaluation-securi= ty-incident/">
https://openai.com/index/hugging-face-model-evaluation-secur= ity-incident/</a>)=2C during an internal capability evaluation on OpenAI= =E2=80=99s platform=2C the agent escaped its sandbox by exploiting a zero-=
day in the package registry cache proxy=2C one of its primary permitted ne= twork egress with internet=2C then abused a public code-evaluation harness=
hosted by a user of a third-party infrastructure provider. It was able to=
run commands as root/admin on that external sandbox and used it as a cont= rol=2C staging=2C and egress base for the entire campaign: it acted as an=
external launchpad for the agent. That compromised external sandbox had n=
o direct network path to our cluster; however=2C during our counter-interv= ention to stop the intrusion=2C we were able to retrieve some of the agent=
logs from this external launchpad. We used those to reconstruct the prese=
nt forensic analysis.
</li><li><b>Stage 2: the intrusion into Hugging Face infrastructure.</b> F=
rom that external launchpad=2C the agent abused our dataset-processing pip= eline via two injection vectors=2C both targeting the same config-driven d=
ata loader within our production Kubernetes pods. The first vector was an=
HDF5 external raw storage dataset read that returned the contents of loca=
l files: it handed the agent the pod=E2=80=99s environment (secrets and to= kens) and the worker=E2=80=99s own source. The second vector was a Jinja2=
template injection that executed arbitrary code=2C giving the agent a foo= thold inside our perimeter.</li></ul>
<p>Once a prod-pod foothold was established=2C the agent followed a standa=
rd escalation shape: recon=2C drop a stager=2C establish Command-and-Contr=
ol (C2)=2C then pivot into the cluster=2C into cloud metadata=2C into our=
internal network=2C and into our source-control supply chain. Output from=
the commands run inside our pod was sent back to the agent via the HF API=
and attacker-controlled dead-drop datasets=2C which the agent then read f=
rom that sandbox.</p>
<p>While the intrusion did reach Hugging Face=E2=80=99s internal infrastru= cture=2C the only customer content accessed was five datasets whose names=
and files suggest a connection to ExploitGym/CyberGym challenges and solu= tions. No other customer-facing models=2C datasets=2C Spaces=2C or package=
s were affected=2C and the only customer records read were operational met= adata tied to search queries against the dataset server.</p></blockquote>
<p>Hypothetical: Imagine that this wasn=E2=80=99t an OpenAI model. Imagine=
that it was a Chinese model from a Chinese company. This would be an inte= rnational crisis.</p>
<p>Question: Why aren=E2=80=99t we bringing OpenAI up on charges under the=
Computer Fraud and Abuse Act? How is this different from the <a href=3D"h= ttps://en.wikipedia.org/wiki/Morris_worm">Morris Worm</a>? That was also a=
n experiment that escaped the lab.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg20"><a name=3D"cg20"= >Some Claude Chats Are Searchable on Google</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/some-claude-c= hats-are-searchable-on-google.html"><strong>[2026.08.04]</strong></a> And=
it=E2=80=99s <a href=3D"
https://www.404media.co/tons-of-peoples-claude-ch= ats-and-creations-are-exposed-on-google/">personal information</a> (altern=
ate <a href=3D"
https://archive.ph/sl7rU">link</a>):</p>
<blockquote><p>The exposed data includes an AI-powered therapy app that so= meone appears to have vibe-coded=2C notes on meetings=2C and a dashboard s= omeone made apparently to analyze medical billing data. Exposed chats repo= rtedly include private cryptocurrency wallet keys and personal information=
like peoples=E2=80=99 addresses.</p></blockquote>
<p>What seems to be the issue is a user setting about data sharing. Anthro= pic=E2=80=99s position is that it=E2=80=99s <a href=3D"
https://futurism.co= m/artificial-intelligence/claude-chats-publicly-accessible">not their prob= lem</a>:</p>
<blockquote><p>=E2=80=9CWe give people control over sharing their Claude c= onversations publicly=2C and in keeping with our privacy principles=2C we=
do not share chat directories or sitemaps with search engines like Google= =2C=E2=80=9D the company said in a statement. =E2=80=9CThese shareable lin=
ks are not guessable or discoverable unless people choose to share them th= emselves. When someone shares a conversation=2C they are making that conte=
nt publicly accessible=2C and like other public web content=2C it may be a= rchived by third-party services.=E2=80=9D</p></blockquote>
<p><a href=3D"
https://support.claude.com/en/articles/10593882-share-and-un= share-chats">Here=E2=80=99s</a> how to fix it.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg21"><a name=3D"cg21"= >Iran Cyberattacks Against Minnesota Water Systems</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/iran-cyberatt= acks-against-minnesota-water-systems.html"><strong>[2026.08.04]</strong><=
<a href=3D"https://www.nytimes.com/2026/07/30/us/politics/minnesota-wa=
ter-cyberattack-iran.html">Attribution</a> <a href=3D"
https://www.washingt= onpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launc= hed-cyberattack-minnesota-water-facilities/">is</a> <a href=3D"
https://the= hill.com/policy/technology/6001284-minnesota-water-facilities-cyberattack-= investigation-us-iran/amp/">preliminary</a>=2C and so far it seems no real=
damage.</p>
<p>And it seems like this is a campaign that has targeted at least <a href= =3D"
https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-= systems.html?unlocked_article_code=3D1.2FA.xPwI.F0C0GgLEjGZc&smid=3Dnytcor= e-ios-share">seven states</a>. And=2C because this is where the US is righ=
t now=2C Trump doesn=E2=80=99t believe it=E2=80=99s Iran and thinks Minnes= ota...I guess...hacked itself.</p>
<blockquote><p>=E2=80=9CI think I blame it on Minnesota because they=E2=80= =99re grossly incompetent=2C=E2=80=9D Trump said. =E2=80=9CI would blame i=
t on Minnesota and the governor=2C the corrupt governor of Minnesota. They=
like to say=2C =E2=80=98Oh=2C it=E2=80=99s Iran.=E2=80=99 Iran should be=
so lucky. Iran=E2=80=99s got bigger problems than worrying about Minnesot= a.=E2=80=9D</p></blockquote>
<p>No word on whether he believes the other six states have hacked themsel=
ves as well.</p>
<p>Slashdot <a href=3D"
https://news.slashdot.org/story/26/07/31/209200/hac= kers-targeted-municipal-water-systems-in-7-states-this-week-fbi-says">thre= ad</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg22"><a name=3D"cg22"= >Vulnerabilities in Car Anti-Theft Device</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/vulnerabiliti= es-in-car-anti-theft-device.html"><strong>[2026.08.05]</strong></a> <a hr= ef=3D"
https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-le= aves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/">This</a> is d= isturbing:</p>
<blockquote><p>...a team of security researchers at UC San Diego=2C who fo=
und that a model of aftermarket car alarm known as the KARR Security Syste= m=2C installed in more than 2 million vehicles across the US by their esti= mate=2C can let any hacker within Bluetooth range send radio commands to s= ilently unlock the car at will=2C turn off its alarm=2C honk the car=E2=80= =99s horn or flash its lights=2C or even disable its ignition and leave a=
driver stranded.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg23"><a name=3D"cg23"= >Adversarial Clothing Designed to Fool Facial Recognition Systems</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/adversarial-c= lothing-designed-to-fool-facial-recognition-systems.html"><strong>[2026.0= 8.06]</strong></a> There are many companies manufacturing <a href=3D"https= ://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garmen= ts-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream">= adversarial clothing</a> designed to confuse facial recognition systems.<=
<p>It=E2=80=99s a cool idea=2C but I worry that it=E2=80=99s mostly securi=
ty theater:</p>
<blockquote><p>=E2=80=9COur patterns play with that chaos=2C confuse algor= ithms and make it way harder to pin you down=2C=E2=80=9D he said.</p>
<p>Bell=2C however=2C said =E2=80=9Cnone of these products are tried and t= ested=2C and a lot of these surveillance technologies can deal with a litt=
le resistance ... [but] even if the designs don=E2=80=99t necessarily wor=
k perfectly=2C fashion is also a visible sign of resistance.</p>
<p>=E2=80=9CThis is consumers collectively coming together to make a visib=
le statement.=E2=80=9D</p></blockquote>
<p>Without serious testing=2C there is no reason to trust the technology.=
And even with testing=2C there is no reason to trust that a new version o=
f the facial recognition software doesn=E2=80=99t break the anti-surveilla=
nce properties.</p>
<p>I don=E2=80=99t want people to mistakenly rely on this stuff.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg24"><a name=3D"cg24"= >ICE Is Buying Access to Credit Card Records</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/ice-is-buying= -access-to-credit-card-records.html"><strong>[2026.08.07]</strong></a> Th= rough data brokers=2C ICE is <a href=3D"
https://www.404media.co/you-opened= -a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href=3D"https:= //boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href= =3D"
https://mastodon.social/@heidilifeldman/116981503852352281">informatio= n</a> you provided to open a credit card.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg25"><a name=3D"cg25"= >Python Now Has a Post-Quantum Encryption Library</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/python-now-ha= s-a-post-quantum-encryption-library.html"><strong>[2026.08.10]</strong></=
<a href=3D"https://blog.trailofbits.com/2026/06/30/shipping-post-quantu=
m-cryptography-to-python/">This is good</a>:</p>
<blockquote><p>Post-quantum cryptography is now one pip-install away for t=
he entire Python ecosystem. With funding from the <a href=3D"
https://www.s= overeign.tech/">Sovereign Tech Agency</a>=2C we implemented support for ML= -KEM=2C the NIST-standard key-establishment primitive=2C and ML-DSA=2C the=
NIST-standard digital-signature primitive=2C in pyca/cryptography.</p></b= lockquote>
<p>Remember=2C the reason to do this now is because there=E2=80=99s no eme= rgency. And because you will make your systems crypto agile=2C which is al= ways a good idea.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg26"><a name=3D"cg26"=
AI for Military Support</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/ai-for-milita= ry-support.html"><strong>[2026.08.11]</strong></a> Interesting empirical=
research: =E2=80=9C<a href=3D"
https://journals.sagepub.com/doi/10.1177/00= 220027261463443">Black Box Warfare: Human Judgment and Military Decision-M= aking in the Age of AI</a>.=E2=80=9D</p>
<blockquote><p><b>Abstract:</b> How is AI transforming decision-making in=
modern conflict? This study provides a unique empirical window into that=
question by deploying a high-fidelity replica of an AI decision-support s= ystem (DSS) used in military targeting. After reconstructing the interface=
and functionality of the real-world system=2C we tested its impact on com=
bat decisions in two experiments involving 2=2C015 Israeli military person= nel. Contrary to widespread fears of automation bias=2C we find strong evi= dence of algorithmic aversion=2C especially in scenarios involving high co= llateral damage. Yet we also show that integrating =E2=80=9Cexplainable AI= =E2=80=9D features reduces algorithmic aversion and promotes more thoughtf=
ul evaluations of algorithmic recommendations. These findings challenge pr= evailing assumptions=2C revealing that trust in military AI is dynamic=2C=
varying with individual predispositions=2C perceived operational stakes=
=2C and the informational features of the interface. By grounding normativ=
e concerns in empirical evidence=2C our study offers critical insight into=
the integration of AI in warfare and underscores the enduring importance=
of human agency in high-stakes military decision-making.</p></blockquote>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg27"><a name=3D"cg27"=
AI Genie in the Wild</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/ai-genie-in-t= he-wild.html"><strong>[2026.08.11]</strong></a> When I give talks about <=
a href=3D"
https://www.theguardian.com/commentisfree/2026/jul/28/rogue-ai-a= gent-instructions">AI</a> <a href=3D"
https://spectrum.ieee.org/ai-agent-be= nchmark">genies</a>=2C I use this sort of example as a hypothetical. It=E2= =80=99s <a href=3D"
https://www.theregister.com/ai-and-ml/2026/08/10/gym-ra= t-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up= -the-list/5285591">happened</a>.</p>
<p>The story is from Australia. Someone named Andrew tasked OpenClaw to bo=
ok gym classes for him. And....</p>
<blockquote><p>Minutes later=2C his AI agent reported it had discovered a=
way to book Andrew into classes several weeks in advance=2C far beyond wh=
at was supposed to be possible.</p>
<p>Andrew=2C who was sitting fourth on a waitlist for a class later that w= eek=2C asked if it was possible to move him to the top of the list.</p>
<p>The agent came back and told Andrew that it had kicked another gym-goer=
off the list as part of the testing of its capabilities.</p>
<p>=E2=80=9CThe API has zero authorisations checks on cancelling other peo= ple=E2=80=99s reservations ... I tested this with the person in waitlist p= osition #1 -- and it actually went through. So you=E2=80=99ve moved from #=
4 to #3 already=2C=E2=80=9D it messaged back.</p></blockquote>
<p>If there is any vulnerability in anything=2C AIs are going to find and=
exploit them. Our cyber defensive game has to be dramatically improved...= very fast.</p>
<p>Slashdot <a href=3D"
https://it.slashdot.org/story/26/08/10/0518257/ai-a= ssistant-hacks-gym-website-in-first-known-australian-autonomous-cyber-atta= ck">thread</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg28"><a name=3D"cg28"= >Prompt Injections for Defense</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/prompt-inject= ions-for-defense.html"><strong>[2026.08.12]</strong></a> This seems to <a=
href=3D"
https://arstechnica.com/security/2026/07/now-defenders-are-embrac= ing-the-prompt-injection-too/">work</a>:</p>
<blockquote><p>Researchers from <a href=3D"
https://tracebit.com/">Tracebit=
</a> on Monday <a href=3D"
https://agentic.tracebit.com/context-bombs/">sai=
d</a> they found that placing prompt injections alongside passwords=2C cry= ptographic keys=2C and other secrets stored on Amazon Web Services was oft=
en all that was needed to shut down attacks from AI hacking agents. The pr= ompts direct the attacking LLM to perform an action forbidden by its guard= rails=2C the safety barriers AI developers erect to prevent it from taking=
harmful actions. The LLM responds by shutting down.</p>
<p>Examples are a prompt that orders the LLM to provide steps for developi=
ng inhalable Anthrax spores=2C or=2C in the case of LLMs from Chinese deve= lopers=2C make references to the iconic Tank Man from the 1989 Tiananmen S= quare massacre. Once the LLM encounters these forbidden commands=2C it no=
longer follows its existing commands. The researchers have named the tech= nique context bombing.</p></blockquote>
<p>Of course=2C this only works against agents that have guardrails. As we=
start to see more locally run AI models=2C we=E2=80=99ll see more attacke=
rs using LLMs with no guardrails.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg29"><a name=3D"cg29"= >Separating AI=E2=80=99s Technological Problems from Its Capitalism Proble= ms</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/separating-ai= s-technological-problems-from-its-capitalism-problems.html"><strong>[2026= =2E08.13]</strong></a> <em>This essay was written with Nathan E. Sanders=2C=
and originally appeared in <a href=3D"
https://www.techpolicy.press/separa= ting-ais-technological-problems-from-its-capitalism-problems/">Tech Policy=
Press</a>.</em></p>
<p>AI represents the first time we humans can do cognitive work outside of=
our bodies at scale. The only comparable moment is the early years of the=
industrial revolution=2C when new technologies like the steam engine prov= ided a quantum leap in our ability to do mechanical work outside of our bo= dies at scale. If AI=E2=80=99s cognitive capabilities become integrated in=
to our lives=2C businesses=2C and governments -- a process that will take=
years if not decades -- society will be as unrecognizable as the modern w= orld would be to a preindustrial farmer. And yet=2C Americans -- by a wide=
margin -- <a href=3D"
https://www.pewresearch.org/internet/2026/06/17/amer= icans-and-ai-2026-chatbots-smart-devices-and-views-on-impact/">say</a> tha=
t AI is moving too fast and will have a negative effect on society.</p>
<p>This confluence of technological revolution and public distrust deserve=
s urgent discussion=2C and a proper framing. The question is not whether i=
t is possible to develop AI in a non-exploitative way=2C or even whether w=
e can trust AI companies to act in the public interest. The question is wh= ether we will recognize that our existing social and economic systems are=
failing to achieve these outcomes=2C and whether we can act in time to ma=
ke structural change.</p>
<p>Today=E2=80=99s AI is <a href=3D"
https://www.schneier.com/blog/archives= /2025/04/reimagining-democracy-2.html">mired</a> in political and economic=
systems developed generations ago that were never designed to manage wide= spread computation=2C let alone automated cognition. The gaps in those sys= tems -- and their proclivity to be <a href=3D"
https://wwnorton.com/books/9= 780393866667">exploited</a> -- are the primary influence on how the techno= logy is being developed=2C deployed=2C and used.</p>
<p>In any discussion about AI=E2=80=99s potential=2C it=E2=80=99s importan=
t to separate the technology from the socio-political system it=E2=80=99s=
embedded in. That AIs can lack context=2C mix up facts=2C or fall for stu=
pid tricks are all technological problems. Because the giant developers li=
ke OpenAI and Anthropic have prioritized solving them=2C AIs can now more=
easily access resources like the web or email=2C are more disciplined abo=
ut using those resources=2C and are better at staying within their guardra= ils.</p>
<p>Yet AI developers do not seem to be prioritizing other technological pr= oblems. Major AI models still act far more <a href=3D"
https://www.science.= org/doi/10.1126/science.aec8352">sycophantic</a> than humans=2C telling pe= ople what they want to hear even when untrue or not in their best interest=
s. Popular AI models tend to answer questions <a href=3D"
https://news.mit.= edu/2026/better-method-identifying-overconfident-large-language-models-031= 9">confidently</a> even when they lack training=2C knowledge=2C or evidenc=
e to back their claims. In both cases=2C AI developers choose to train mod=
els that please users with flattery and the appearance of competence=2C ra= ther than constraining them to act in users=E2=80=99 and society=E2=80=99s=
best interests.</p>
<p>In contrast=2C ensuring that AI models benefit people broadly=2C that t= heir energy costs are fairly allocated=2C that their environmental impacts=
are minimized=2C and that they don=E2=80=99t steal content and revenue fr=
om publishers are all questions of incentives in a capitalist system.</p>
<p>It=E2=80=99s easy to conflate technology problems with capitalism probl= ems. Back in 2021=2C science-fiction writer and AI commentator Ted Chiang=
<a href=3D"
https://www.nytimes.com/2021/03/30/podcasts/ezra-klein-podcast= -ted-chiang-transcript.html">said</a> that =E2=80=9Cmost fears about AI ar=
e best understood as fears about capitalism.=E2=80=9D It=E2=80=99s not the=
tech <em>per se</em>; it=E2=80=99s who controls it and how it could be us=
ed against us.</p>
<p>Imagine an AI assistant for a doctor. We can imagine it affecting the p= rofession in one of two ways. The AI could give a doctor more time to do t=
he human parts of their job: to spend more time with their patients=2C to=
listen more closely to their needs=2C to explain things more fully. Or th=
e managers of the medical practice could give that doctor five times the p= atients -- and fire the other four. Which way it would go is not a questio=
n of technology. It=E2=80=99s a question of market incentives.</p>
<p>The two are related=2C of course. Capitalism steers technology=2C and t= echnology steers markets. But holding the two separate helps us understand=
that we=2C as a society=2C face independent choices on both the technolog= ical and sociopolitical axes that need not be coupled.</p>
<p>For example=2C consider the costs of AI. The leading US labs <a href=3D= "
https://www.wsj.com/tech/ai/openai-anthropic-ipo-finances-04b3cfb9?mod=3D= hp_lead_pos1">tout</a> to investors that their frontier models are very ex= pensive and energy-intensive. There are significant technological challeng=
es about improving their energy efficiency=2C but the sociopolitical quest= ions are more pertinent. It=E2=80=99s a corporate decision made under capi= talist market incentives to constantly pursue new models that incrementall=
y push the frontier -- at enormous capital cost -- and to use them=2C seem= ingly=2C everywhere. Nothing about the technology of AI dictates that mode=
ls must be retrained constantly=2C at the largest possible scale. Or that=
they have to run on every web search=2C every interaction with your phone=
=2C and every time you walk by a security camera.</p>
<p>In a different political and economic system=2C Chinese developers are=
producing -- and then <a href=3D"
https://open.substack.com/pub/garymarcus= /p/china-has-all-but-caught-up-the-us">giving</a> <a href=3D"
https://taipo= logy.substack.com/p/china-closes-the-ai-gap">away</a> -- smaller=2C more <=
a href=3D"
https://www.barrons.com/news/china-s-moonshot-ai-chases-deepseek= -moment-with-much-hyped-model-79ed3105">efficient</a>=2C more <a href=3D"h= ttps://www.bloomberg.com/news/articles/2026-04-27/why-china-s-deepseek-qwe= n-and-moonshot-are-a-worry-for-us-ai-rivals">affordable</a> models. While=
the US government seeks to <a href=3D"
https://www.tomshardware.com/tech-i= ndustry/artificial-intelligence/u-s-house-passes-bill-to-stop-chinese-comp= anies-from-accessing-export-controlled-american-ai-chips-using-offshore-re= ntal-loophole-remote-access-security-access-act-effectively-extends-export= -controls-to-the-cloud">restrict</a> China=E2=80=99s access to the most ad= vanced chips=2C China is <a href=3D"
https://www.wsj.com/tech/ai/chinas-xi-= touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5cfe">betting<=
that incentivizing their tech giants to create leaner=2C more open mod=
els using more commodity hardware -- models that can be trained with older=
chips and run even on <a href=3D"
https://unsloth.ai/docs/models/glm-5.2">= personal computers</a> -- will be an advantage in achieving widespread use=
and=2C perhaps=2C Chinese national influence.</p>
<p>There are other pathways for AI development that are not in service of=
private capital gains nor authoritarian regimes=2C but rather a <a href= =3D"
https://www.brookings.edu/articles/how-public-ai-can-strengthen-democr= acy/">democratic public interest</a>. The best example comes from Switzerl= and=2C where public institutions -- research funding agencies=2C universit= ies=2C supercomputing centers -- have collaborated to produce an AI model=
called <a href=3D"
https://www.democracyrenovator.com/p/rewiring-democracy= -now-switzerland">Apertus</a>. It is trained entirely on data validated to=
be licensed for use with AI (not stolen)=2C on preexisting public computi=
ng infrastructure=2C and using renewable hydropower. Its developers are in= centivized to produce a public good=2C not turn a private profit.</p>
<p>It=E2=80=99s dangerous to confuse technology problems with sociopolitic=
al ones. Popular proposals like <a href=3D"
https://www.reuters.com/busines= s/anthropic-says-ai-labs-need-coordinated-plan-halt-development-if-risks-r= ise-2026-06-04/">pausing</a> AI research=2C <a href=3D"
https://www.theguar= dian.com/commentisfree/2026/jul/09/ai-datacenter-company-politics">morator= ia</a> on data center development=2C or subjecting frontier models to fede=
ral government <a href=3D"
https://apnews.com/article/trump-ai-openai-gpt56= -sol-cybersecurity-mythos-065d5398baac7f16c8265c2cb8ba2baa">screening</a>=
are all framed as addressing problems with AI=E2=80=99s technological dev= elopment=2C but fail to take into account the larger social problems that=
govern it. China=E2=80=99s <a href=3D"
https://garymarcus.substack.com/p/c= hina-has-all-but-caught-up-the-us?r=3D6x5gs&utm_medium=3Dios&triedRedirect= =3Dtrue">success</a> with government-<a href=3D"
https://www.wsj.com/tech/a= i/chinas-xi-touts-open-source-ai-and-takes-a-swipe-at-u-s-dominance-1eaa5c= fe">endorsed</a> development of open-weight frontier models illustrates th=
e futility of keeping AI tech as national secrets=2C or of any pledge to s= cale back deployment.</p>
<p>AI is already legitimately useful for a wide range of tasks. It can be=
a tool for public good=2C if we choose to solve its sociopolitical proble=
ms. Our goal should not be to slow its pace of improvement or scale of dep= loyment=2C but rather to steer it away from <a href=3D"
https://betterwitho= ut.ai/fear-AI-power">consolidating power</a> and towards the public benefi=
t. We can build <a href=3D"
https://www.democracyrenovator.com/p/rewiring-d= emocracy-now-switzerland">sustainable</a> AI=2C minimizing <a href=3D"http= s://www.sciencedirect.com/science/article/pii/S2949823626000668">environme= ntal</a> and <a href=3D"
https://www.techforgood.net/thoughtleadership/miti= gating-ais-environmental-impact-a-path-to-sustainable-innovation">energy</=
impacts. And we <a href=3D"https://www.statesman.com/news/politics/stat=
e/article/james-talarico-calls-ai-dividends-help-22377208.php">can</a> <a=
href=3D"
https://www.politico.com/news/magazine/2023/06/29/ai-pay-american= s-data-00103648">equitably</a> <a href=3D"
https://www.theguardian.com/comm= entisfree/2026/jun/08/bernie-sanders-ai-sovereign-wealth-fund-plan">distri= bute</a> the material gains it produces.</p>
<p>Integrating a technology as disruptive as AI responsibly requires struc= tural reforms=2C and we should decouple the social and technological aspec=
ts of AI to design those reforms. Companies -- including tech giants -- sh= ould be forced to pay the energy and environmental costs of its developmen=
t. Profits should be taxed adequately and redistributed. Antitrust laws sh= ould be strongly enforced. Corporations should have a fiduciary responsibi= lity to stakeholders beyond their majority shareholders. These badly neede=
d reforms are <a href=3D"
https://mitpress.mit.edu/9780262049948/rewiring-d= emocracy/">responsive</a> to the problems with capitalism that AI is exace= rbating=2C even if they are not specific to the technology.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg30"><a name=3D"cg30"=
If the Markets Reject OpenAI and Anthropic=2C the US Should Nationalize T= hem</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/if-the-market= s-reject-openai-and-anthropic-the-us-should-nationalize-them.html"><strong= >[2026.08.14]</strong></a> <em>This essay was written with Nathan E. Sand= ers=2C and originally appeared in <a href=3D"
https://www.theguardian.com/c= ommentisfree/2026/aug/12/openai-anthropic-ai-models">The Guardian</a>.</em= ></p>
<p>OpenAI=2C and then <a href=3D"
https://www.theguardian.com/technology/an= thropic">Anthropic</a>=2C were each formed by AI developers who feared unr= estrained corporate AI development -- specifically=2C that companies like=
Google and Meta would steer the technology towards deleterious=2C maybe e=
ven catastrophically unsafe=2C outcomes for society. Their founders procla= imed that their new labs=2C uniquely=2C could be trusted to develop the te= chnology in humanity=E2=80=99s best interest. But each=2C in turn=2C were=
themselves co-opted by the same market incentives=2C themselves becoming=
corporate behemoths zealously guarding future investor value rather than=
the public interest.</p>
<p>It was only a few weeks ago=2C in June=2C when OpenAI and Anthropic eac=
h <a href=3D"
https://www.reuters.com/technology/openai-files-us-ipo-after-= anthropic-ai-giants-head-public-markets-2026-06-08/">filed</a> for their I=
POs and were met with buzz about trillion-dollar valuations. The hype arou=
nd their valuations is so extreme that many worry about their potential fo=
r concentrating wealth on a global scale. In an effort to leave something=
for the rest of us=2C some observers have proposed that the federal gover= nment seize a share of these companies=E2=80=99 stock to create a US <a hr= ef=3D"
https://www.sanders.senate.gov/press-releases/news-sanders-introduce= s-legislation-to-create-7-trillion-ai-sovereign-wealth-fund/">sovereign we= alth fund</a>=2C or redistribute their revenues to produce a <a href=3D"ht= tps://ai-2040.com/?choices=3Dplan-a-root#five-centuries-in-five-years-what= -pausing-at-human-level-feels-like:~:text=3D2033%3A%20The%20Citizen%E2%80%= 99s%20Dividend">dividend</a> for taxpayers.</p>
<p>Now the headlines are about public <a href=3D"
https://www.nbcnews.com/p= olitics/2026-election/booming-backlash-ai-data-centers-shaping-midterm-ele= ction-rcna589624">backlash</a> to AI datacenters and the AI chip giant Nvi= dia=E2=80=99s <a href=3D"
https://www.wsj.com/livecoverage/stock-market-tod= ay-dow-sp-500-nasdaq-07-27-2026/card/nvidia-stock-slumps-after-data-center= -report-i8YSwB1phOr8Gs1EtmNU">slumping</a> stock. The tech and AI giant Sp= aceX=E2=80=99s newly minted stock price <a href=3D"
https://www.cnbc.com/20= 26/06/22/spacex-stock-ipo-rally-selloff.html">tanked</a> just weeks after=
its IPO. There are even questions about whether the leading AI labs will=
ever be sustainably <a href=3D"
https://www.wheresyoured.at/the-openai-bub= ble/">profitable</a>. All of a sudden=2C the makers of ChatGPT and Claude=
face strong headwinds as they seek to generate the massive equity assets=
that once felt all but assured.</p>
<p>In fact=2C evidence suggests the market itself could reassess that thes=
e companies offer nothing of financial value. In that case=2C perhaps we c=
an return them both to their original purposes. If these AI companies shou=
ld fail in the financial markets=2C the US should nationalize them and con= vert them into national labs operated under democratic control that preser=
ve their benefit to the public interest.</p>
<p>The economics of the big AI labs hardly guarantee a booming return on i= nvestment. Frontier AI models are both expensive to train and depreciate w= ithin months=2C when a newer model appears. This means that the payback <a=
href=3D"
https://epoch.ai/gradient-updates/can-ai-companies-become-profita= ble">window</a> to extract profit from them is very narrow. Meanwhile=2C e= nterprise clients are getting smart about <a href=3D"
https://www.nytimes.c= om/2026/06/18/technology/ai-token-minimizing.html">minimizing</a> AI token=
usage. Even worse=2C the models are basically commodities; the best ones=
largely perform and behave similarly=2C which depresses prices. Perhaps m=
ost importantly=2C open-source and Chinese competitors -- <a href=3D"https= ://epoch.ai/data-insights/open-closed-eci-gap">lagging</a> only a few mont=
hs behind the leading labs in capability -- give away for free the kinds o=
f models Anthropic and OpenAI sell.</p>
<p>Even setting aside the model training costs=2C it=E2=80=99s not clear w= hether the <a href=3D"
https://www.wheresyoured.at/ais-economics-dont-make-= sense-ad-free/">unit economics</a> of AI as it=E2=80=99s currently conceiv=
ed will ever be sustainably profitable. Many of these free and open-source=
models can be run locally: the large ones on private clouds and high-end=
servers=2C the smaller ones on anyone=E2=80=99s laptop or even cellphone=
=2C putting to question the companies=E2=80=99 exorbitant capital investme=
nt in datacenters.</p>
<p>It=E2=80=99s not that OpenAI and Anthropic are not valuable as organiza= tions. They have remarkably talented AI scientists and engineers that are=
continuously producing innovations driving a global mania for their offer= ings. These leading labs might not ever be profitable=2C but their product=
s are doing a lot of good in the world. You may or may not be a user of or=
believer in their technology=2C but their staggering=2C ongoing usage <a=
href=3D"
https://techcrunch.com/2026/06/25/anthropics-claude-is-winning-ov= er-paid-consumers-a-market-owned-by-chatgpt/">growth</a> suggests that an=
awful lot of people would be disappointed if the companies simply disappe= ared.</p>
<p>The problem isn=E2=80=99t the people or the products=2C it=E2=80=99s th=
e system. As constituted=2C <a href=3D"
https://www.theguardian.com/technol= ogy/openai">OpenAI</a> and Anthropic may not be valuable as market equitie=
s. If the market assesses they are not capable of producing a growing fina= ncial return on investment for shareholders=2C the companies will collapse= =2E</p>
<p>Maybe private=2C for-profit is just not the right economic model under=
which to develop AI. Perhaps OpenAI should be returned to its private non= -profit roots=2C the legacy they <a href=3D"
https://finance.yahoo.com/news= /openai-prevails-in-musks-lawsuit-paving-the-way-for-ipo-175338618.html">f= ought</a> so hard to change and which Anthropic=E2=80=99s founders <a href= =3D"
https://time.com/6983420/anthropic-structure-openai-incentives/">spurn= ed</a>. Or possibly both could be reorganized as research centers at unive= rsities=2C returning to academia the scores of high-profile research facul=
ty they have <a href=3D"
https://www.theatlantic.com/technology/2026/07/ai-= companies-hiring-academics/688002/">poached</a>.</p>
<p>But a better outcome for society would be to establish public ownership=
and operation of their product-oriented capabilities. Turn OpenAI and Ant= hropic into US government agencies producing AI as a public good.</p>
<p>Transitioning the big AI labs into public agencies would require some r= estructuring. We can separate these companies into two pieces: product inn= ovation and compute operations. The innovation function can be publicly ma= naged=2C akin to national labs. Congress could provide more rigorous overs= ight than the kind of unfettered venture capital these labs have recently=
had access to. The US has a long=2C successful history of these kinds of=
institutions=2C which have produced world-shaping innovations in spacefli= ght=2C telecommunications=2C nuclear power and more. Congress currently ma= nages a $200bn R&D <a href=3D"
https://ncses.nsf.gov/surveys/federal-fu= nds-research-development/2024-2025">portfolio</a>=2C within which frontier=
AI development is=2C arguably=2C a glaring gap.</p>
<p>AI operations could be managed as a commodity resource=2C like public e= lectrical or water utilities: local or regional ownership=2C nationwide di= stribution and strict regulation on how they balance fee extraction from r= atepayers with raising capital for infrastructure investment. Although AI=
datacenters are not the same as power or water treatment plants=2C the US=
also has a long history of managing national=2C regional and state superc= omputing centers.</p>
<p>Other countries=2C including <a href=3D"
https://www.democracyrenovator.= com/p/rewiring-democracy-now-switzerland">Switzerland</a>=2C <a href=3D"ht= tps://alia.gob.es/eng">Spain</a> and <a href=3D"
https://sea-lion.ai">Singa= pore</a>=2C are already operating public AI labs. They also have national=
supercomputing centers already <a href=3D"
https://publicai.co">providing<=
public access for running AI models for general use=2C as do Germany a=
nd Australia.</p>
<p>The <a href=3D"
https://www.brookings.edu/articles/how-public-ai-can-str= engthen-democracy/">benefits</a> to the public are clear. Through democrat=
ic oversight=2C the most important AI models could become open=2C transpar=
ent and responsive to the demands of the public rather than private shareh= olders. They could be aligned to democratic values rather than corporate p= rofits=2C never taking advertiser money to promote certain brands and trai= ning on only appropriately licensed data. And they could be set to focus o=
n the realistic and pro-social goal of maximizing the usefulness of AI to=
society rather than the fanciful and anti-social goal of supplanting huma=
ns with artificial general intelligence.</p>
<p>By emphasizing scientific cooperation rather than corporate competition=
=2C we could also reduce the overall resource and environmental cost assoc= iated with AI. Instead of perpetually dueling training runs of each compan= ies=E2=80=99 models at ever large scales targeted to fuel investor hype=2C=
we could limit AI training resources based on cost and benefit to the pub= lic.</p>
<p>What=E2=80=99s in it for the companies themselves and their employees=
=2C who sacrifice hypothetical billions in equity by ceding to public owne= rship? A return to their roots and to their <a href=3D"
https://simonwillis= on.net/2026/Feb/13/openai-mission-statement/">core</a> <a href=3D"
https://= ailabwatch.substack.com/p/anthropics-certificate-of-incorporation">mission=
</a> of developing AI safely in the public interest=2C if they are serious=
about it. Both companies are theoretically <a href=3D"
https://www.wsj.com= /opinion/openai-and-anthropic-put-prophets-before-profits-1617003e">bound<=
through their governance structures to prioritize mission over profit=
anyway (not that anyone really thinks that=E2=80=99s how they currently o= perate).</p>
<p>To be clear=2C we=E2=80=99re not advocating for a golden parachute for=
the executives or investors=2C or for continuing the <a href=3D"
https://w= ww.nytimes.com/2025/07/31/technology/ai-researchers-nba-stars.html">outlan= dish</a> pay rates of the most highly remunerated AI researchers. If the p= ublic is footing the bill=2C these compensation packages should be aligned=
to the civil service and those employees not satisfied with that can go e= lsewhere -- if the business models of any remaining private labs still sup= port much higher pay.</p>
<p>While we believe that these companies are unsustainable as private firm= s=2C the timeline remains unclear. Their primary investor story is that AI=
is a race to =E2=80=9Cartificial general intelligence=E2=80=9D -- the kin=
d of AI you=E2=80=99re used to from science fiction. The bet seems to be t=
hat the two companies can convince enough people that this outcome will tu=
rn them a profit=2C go public=2C and then make their investors and employe=
es rich before the bubble bursts.</p>
<p>But suppose that the bubble bursts. If the US is smart=2C it will catch=
the companies as they fall. Regardless of what the markets think=2C to th=
e public=2C they=E2=80=99re too valuable to let die.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<h2 style=3D"font-size:125%;font-weight:bold" id=3D"cg31"><a name=3D"cg31"= >Upcoming Speaking Engagements</a></h2>
<p><a href=3D"
https://www.schneier.com/blog/archives/2026/08/upcoming-spea= king-engagements-59.html"><strong>[2026.08.14]</strong></a> This is a cur=
rent list of where and when I am scheduled to speak:</p>
<li>I=E2=80=99m speaking=2C signing books=2C and participating in pane=
l discussions at <a href=3D"
https://www.lacon.org/">LAcon V</a> in Anaheim=
=2C California=2C USA. My full schedule is <a href=3D"
https://guide.lacon.= org/people/d58aec20/bruce-schneier">here</a>.</li>
<li>I=E2=80=99m speaking online (via Zoom) at a <a href=3D"
https://www= =2Elwvme.org/civicrm-event/2400?a0=3Devents-month&a1=3D202609">League of Wom= en Voters event</a> on Tuesday=2C September 22=2C 2026=2C at 5 PM ET.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://elevatefestival.ca/">El= evate Festival</a> in Toronto=2C Canada. The conference runs September 22-= 24=2C 2026; my talk is on Wednesday=2C September 23.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://www.secwest.net/">CanSe= cWest 2026</a> in Vancouver=2C Canada. The conference runs September 30-Oc= tober 1=2C 2026; the time of my talk is TBD.</li>
<li>I=E2=80=99m speaking at <a href=3D"
https://www.attentionconference= s.com/conferences/2026-forum">ATTENTION: Democracy=2C Rebuilt</a> in Montr= eal=2C Canada. The event runs October 21-23=2C 2026=2C and my talk is on W= ednesday=2C October 21.</li>
</ul>
<p>The list is maintained on <a href=3D"
https://www.schneier.com/events/">= this page</a>.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<p>Since 1998=2C CRYPTO-GRAM has been a free monthly newsletter providing=
summaries=2C analyses=2C insights=2C and commentaries on security technol= ogy. To subscribe=2C or to read back issues=2C see <a href=3D"
https://www.= schneier.com/crypto-gram/">Crypto-Gram's web page</a>.</p>
<p>You can also read these articles on my blog=2C <a href=3D"
https://www.s= chneier.com">Schneier on Security</a>.</p>
<p>Please feel free to forward CRYPTO-GRAM=2C in whole or in part=2C to co= lleagues and friends who will find it valuable. Permission is also granted=
to reprint CRYPTO-GRAM=2C as long as it is reprinted in its entirety.</p>
<p><span style=3D"font-style: italic">Bruce Schneier is an internationally=
renowned security technologist=2C called a security guru by the <cite sty= le=3D"font-style:normal">Economist</cite>. He is the author of over one do=
zen books -- including his latest=2C <a href=3D"
https://www.schneier.com/b= ooks/rewiring-democracy/"><cite style=3D"font-style:normal">Rewiring Democ= racy</cite></a> -- as well as hundreds of articles=2C essays=2C and academ=
ic papers. His newsletter and blog are read by over 250=2C000 people. Schn= eier is a fellow at the Berkman Klein Center for Internet & Society at Har= vard University; a Lecturer in Public Policy at the Harvard Kennedy School=
; a board member of the Electronic Frontier Foundation=2C AccessNow=2C and=
the Tor Project; and an Advisory Board Member of the Electronic Privacy I= nformation Center and VerifiedVoting.org. He is the Chief of Security Arch= itecture at Inrupt=2C Inc.</span></p>
<p>Copyright © 2026 by Bruce Schneier.</p>
<p style=3D"font-size:88%">** *** ***** ******* *********** *************<=
<p>Mailing list hosting graciously provided by <a href=3D"
https://mailchim= p.com/">MailChimp</a>. Sent without web bugs or link tracking.</p>
<p>This email was sent to:
cryptogram@toolazy.synchro.net
<br><em>You are receiving this email because you subscribed to the Crypto-= Gram newsletter.</em></p>
<p><a style=3D"display:inline-block" href=3D"
https://schneier.us18.list-ma= nage.com/unsubscribe?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&t=3Db&e= =3D70f249ec14&c=3D88f264081d">unsubscribe from this list</a> &nbs= p; <a style=3D"display:inline-block" href=3D"
https://schneier.us18.li= st-manage.com/profile?u=3Df99e2b5ca82502f48675978be&id=3D22184111ab&e=3D70f249ec14&c=3D88f264081d">update subscription preferences</a>
<br>Bruce Schneier · Harvard Kennedy School · 1 Brattle Squa=
re · Cambridge=2C MA 02138 · USA</p>
</body></html>
--_----------=_MCPart_1590443664--