Feed aggregator

EU Kids Act Won't Keep the Internet Accountable and Trustworthy

EFF: Updates - Mon, 09/21/2026 - 8:27am

The EU Commission draft law to restrict young people’s access to the internet that it presented last week will come at a high cost: it will put online services behind age gates, expand the use of intrusive age verification, and undermine the privacy of all users. 

The EU Kids Act aims to protect children from risks associated with social media, video games, and AI systems by introducing age-based access rules, safety requirements, and stronger enforcement and oversight measures. It presents itself as building on the Digital Services Act (DSA) and puts into “hard law” some of the safety-by-design measures specified in the non-binding DSA guidelines on minors’ protection. 

The proposal is built around the following elements: social media age “delay”, safety by design, age assurance and parental responsibility, and strong enforcement. Each of these measures are concerning.  

Mandatory Age Gates for Social Media and Video-Sharing Platforms 

Following the advice of an expert panel, the proposal would create a phased access to social media and video-sharing platforms deemed risky—a threshold met simply by relying on personalized recommender systems or offering “uninterrupted content consumption”: no service accounts for children under 13; restricted accounts under tight parental supervision from 13 to 15; and autonomous accounts in a safe-by-design environment from 15 to 18. Full online access is therefore reserved for adults. 

However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups.

If this sounds complex and like a compliance nightmare, that’s because it is. The access delay comes with privacy-intrusive age verification across the board, relying on the EU age verification scheme. For teenagers, this law means significant control in the hands of their parents, who must set up accounts and prove that they are, in fact, parents, adding yet another problematic layer of verification. 

In fairness, the Kids Act’s gradual approach at least appears to be designed with some proportionality considerations, rather than imposing a blanket social media ban. Just last month a French court declared such undifferentiated bans unconstitutional. The EU Kids Act distinguishes between age groups and certain services and follows a risk-based approach. This means, for example, that age verification is not required for existing accounts if the provider can tell with a “high degree of confidence” that the user is above the age threshold—a vaguely specified standard.  

Yet, the law still indiscriminately covers social media and video-sharing, with virtually all mainstream services being covered by the proposal. The broad scope also sits uneasy with the use of age thresholds, which remain a blunt proxy for maturity. What is more, by focusing heavily on safety and harms, the EU Kids Act pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online. However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups. They also create a powerful infrastructure for control and further entrench the power of big tech. 

The proposal exempts not-for-profit encyclopedias, scientific repositories and educational services, as well as open-source software-developing and-sharing platforms. However, no exceptions are foreseen for small and medium-sized enterprises, which will only foster the dominance of resource-laden tech companies that were already investing in similar measures. And we know that most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms. 

Safety by Design Across Covered Services 

The proposal’s second pillar, “safety by design”, casts a wider net. It applies across social media, video-sharing, online games, AI companions, chatbots and even app stores—with varying requirements. Providers must generally make child-safe design the default and can relax from the requirements only if they use age assurance to establish that the user is an adult. 

For example, rules on addictive features such as infinite scrolling, safe account settings, and more choice over recommender systems are to provide a safe internet experience to young people. As regards AI companions and chatbots, the proposal requires companies to design their services to reduce minors’ exposure to emotional dependencies and harmful interactions. Online games are covered as well: they must come with contact protections. The law also makes app stores the gate keeper for age-appropriate access, based on an age-rating system. 

The devil of these measures lies in the details, but all of them raise fundamental rights concerns and some of them seem poorly suited, if at all, to the decentralized architecture of the Fediverse. The requirement for very large online platforms to set up compliance plans before rolling out new services raises additional questions about the risks of transplanting product-safety doctrines of conformity and risk control into speech regulation. Deciding what is “safe” can easily become a question of what content people can access or share.  

Next Steps  

By choosing to regulate all these aspects through the Kids Act, the Commission not only but creates a privacy minefield, it also intermingles the digital fairness agenda with the more fundamental-rights heavy questions of age assurance and access to information. An unfortunate policy choice that will politicize well-intentioned efforts to curb manipulative and addictive design practices (read our position on the DFA). 

It speaks volume that the Kids Act has not gone through a full impact assessment process, which would typically require a systemic check of alternative policy options and stakeholder consultations. Looking forward, we call on the EU lawmakers to pull the teeth of the most harmful suggestions and to make sure that the new measures don’t erode the fundamental rights of all users. 

Unmasking “zombie cells” in aging tissue with an AI-powered barcode

MIT Latest News - Mon, 09/21/2026 - 5:00am

As we age, some of the cells in our body enter a state of senescence, in which they stop dividing but do not die. Those senescent cells can contribute to age-related disorders such as cancer, tissue degeneration, and inflammatory diseases.

In an advance that could lead to better ways to diagnose and treat those diseases, MIT researchers have developed a noninvasive way to detect biomarkers of senescence. Their method is based on Raman microscopy, which can reveal the biochemical composition of cells without harming them.

By combining Raman microscopy with gene expression data at single-cell resolution from the same cells, the researchers were able to identify unique “barcodes” that can be used to quickly identify senescent cells. This study was done in mouse cells, but the researchers are now working on adapting it for use with human tissue.

“You can imagine that one day we may develop an endoscope that can look inside your body and identify cellular senescence,” says Jeon Woong Kang, an MIT research scientist and one of the senior authors of the study.

The research is part of a National Institutes of Health initiative called the Cellular Senescence Network, which is pursuing a deeper understanding of senescence in hopes of developing therapies that could combat some of the tissue-damaging effects of senescent cells.

Peter So, director of the MIT Laser Biomedical Research Center (LBCR) and an MIT professor of biological engineering and mechanical engineering, and Jian Shu, an assistant professor at Massachusetts General Hospital (MGH) and Harvard Medical School, and an associate member of the Broad Institute and Ragon Institute, are also senior authors of the paper, which appears today in Nature Aging. Lead authors of the paper are Ke Zhang, an instructor at MGH and Harvard Medical School; Xingjian Chen, a postdoc at MGH and Harvard Medical School; Francesco Monticolo, a postdoc at MGH and Harvard Medical School; and Salvatore Sorrentino, a postdoc at MIT. 

Characterizing senescence

Cell senescence is often triggered by DNA damage, which leads to an irreversible arrest of the cell cycle. These cells don’t die, but they undergo significant changes to their shape, metabolic processes, and gene expression profiles. 

The immune system is responsible for clearing out these “zombie cells,” but as people age, this process becomes less efficient. When senescent cells accumulate, they may contribute to sagging skin, muscle weakness, and chronic conditions such as osteoarthritis and type 2 diabetes.

Cellular senescence also has beneficial effects, playing critical roles in embryonic development and tissue regeneration.

“Senescence is not just a pathological condition,” So says. “The idea behind the NIH Cellular Senescence Network is to take a very comprehensive approach to understand senescence and identify senescent cells, because it plays a role in so many normal physiological conditions and many pathological conditions.”

Scientists have already identified a few biomarkers for senescence, including two proteins called p16 and p21, which are involved in halting the cell cycle. However, those proteins can only be identified using a process that ends up destroying the cells.

The MIT team wanted to find a way to noninvasively identify senescent cells using Raman microscopy. Unlike RNA-sequencing, which consumes the cells as it analyzes them, Raman microscopy is a nondestructive technique that reveals the chemical composition of tissues or cells by shining near-infrared or visible light on them.

In the new study, the researchers used Raman microscopy in conjunction with spatial RNA sequencing — a technique that reveals where genes are active within a tissue — to identify new markers of senescence. By combining these two techniques, they were able to generate a much broader picture of the distinctive features of senescent cells, including gene expression levels, spatial location, and other biochemical information.

“Our idea was to look at many different features to characterize senescence. That’s why we wanted to combine both single-cell gene expression and Raman microscopy, so that we can characterize the senescence from two complementary views,” Shu says.

Using both methods of analysis, the researchers examined skin and lung tissue from 2-month-old mice and 26-month-old mice.

One of the most dramatic changes seen in both lung and skin cells was an increase in lipid synthesis in older cells, along with accumulation of lipids. How this affects the physiology of the cells is not yet known, the researchers say.

The researchers also found some effects that were specific to each tissue. In senescent skin cells, they discovered that cellular pathways associated with muscle contraction and with remodeling of collagen and the extracellular matrix were significantly affected. And in aged lung tissue, they found increased activity of genes involved in immune activation and inflammation.

In future work, the researchers hope to study further what role these changes play in senescent cells. 

Identifying senescent cells

Using these data, the researchers were able to identify combinations of Raman peaks that correlate with senescence. These peaks, which represent specific chemical bonds, are linked to the presence of certain lipids, proteins, or other molecules.

“Combining the most important Raman features with the most important gene signatures, we were able to create a barcode that can help us to identify senescent cells in a more unbiased way,” Sorrentino says. “Using this barcode, we can focus on a few Raman bands that emerged as the most informative in this work.” Using these bands, it could be possible to identify senescent cells by looking for just those bands of the Raman spectrum. This could help to enable diagnostics that would detect cells that have become senescent. 

To help make that possible, the researchers are now working on a higher-speed version of their Raman imaging system. Currently, it takes about 30 hours to analyze a tissue sample about one square millimeter in size, but they hope to develop a system that can quickly pick out the Raman barcodes they identified from larger samples.

The research was funded by the National Institutes of Health and Massachusetts General Hospital. 

Increasing LGBTQIA+ inclusion in climate science

Nature Climate Change - Mon, 09/21/2026 - 12:00am

Nature Climate Change, Published online: 21 September 2026; doi:10.1038/s41558-026-02748-0

LGBTQIA+ climate scientists have long encountered oppression and discrimination across society and in the workplace. We suggest specific actions, which need to be supported by more data, to make climate science more inclusive.

Flash energy droughts strain grids

Nature Climate Change - Mon, 09/21/2026 - 12:00am

Nature Climate Change, Published online: 21 September 2026; doi:10.1038/s41558-026-02760-4

Rapid declines in wind or solar generation may leave electricity systems little time to respond. Now a study maps these events globally and projects that their duration may increase under climate change.

Flash energy droughts in solar and wind resources under climate change

Nature Climate Change - Mon, 09/21/2026 - 12:00am

Nature Climate Change, Published online: 21 September 2026; doi:10.1038/s41558-026-02753-3

Flash energy droughts, rapid drops followed by sustained low wind and solar production, could pose potential challenges to power system operations. Here researchers find that climate change may intensify such events across wind, solar and compound forms.

Simple logic warnings improve climate argument evaluation across beliefs and partisanship

Nature Climate Change - Mon, 09/21/2026 - 12:00am

Nature Climate Change, Published online: 21 September 2026; doi:10.1038/s41558-026-02754-2

Climate discourse is often misjudged, yet the mechanisms remain unclear. Using orthogonally manipulated experiments, this study isolates the effects of prior beliefs, partisanship and argument quality, showing that evaluations of climate arguments are context sensitive and can be improved by minimal logic warnings.

EFF Statement on California Governor's Executive Order on AI

EFF: Updates - Fri, 09/18/2026 - 7:25pm

California Gov. Gavin Newsom's executive order is an opportunity for a needed, thoughtful conversation about artificial intelligence and its potential harms. Everyday Californians are feeling real anxiety about the risks of artificial intelligence, and as an organization that works to ensure technology empowers people, EFF welcomes this order as a way for the state of California to lead a much-needed dialogue that addresses these concerns. 

Nonetheless, the most immediate and current concerns with this technology are not about sci-fi scenarios concerning rogue super-intelligence. They are happening right now through biased algorithmic decision-making for employment or government benefits, AI-powered surveillance systems such as Flock cameras, and artificially inflated personalized pricing. People want state and federal leaders to act, and we urge Gov. Newsom to develop thoughtful policies to address those concerns. Today’s EO is a good start. 

To that end, EFF supports the focus on expanding the reporting requirements under SB 53 (2025) for loss-of-control incidents, alongside third-party investigations. We urge the administration to consider how to make these third-party investigations available for smaller developers. As the Government Operations Agency prepares its recommendations for the governor, we urge leaders to also realize that the effectiveness of kill switches in advanced AI systems remains an area of active research. As such, they should ensure that - as we’ve previously mentioned - any technology regulation targeting cybersecurity practices at AI labs must be careful, precise, and practical. Moreover, we also caution that government-controlled kill switches run the risk of being used as a form of retaliation against protected speech, as demonstrated by the Trump Administration’s retaliatory actions against Anthropic earlier this year.

Ultimately, true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies by ensuring that algorithmic decision-making in both the government and private sectors respects people’s rights and well-being. We urge Gov. Newsom and the state of California to develop thoughtful policy in collaboration with those most at risk of harm to address these and other concerns.

How to Limit What Apple’s New Siri AI Can Access in iOS 27

EFF: Updates - Fri, 09/18/2026 - 5:55pm

Apple’s new operating system is here, and along with it comes a new version of Siri, dubbed with two very familiar letters: AI. As the name suggests, this Siri power-up resembles an AI chatbot more than the often derided voice assistant you might be used to. It has even evolved from a blob you invoke with a verbal command or a button press to a whole app. This update comes with a slew of privacy complications, but you can take some control over what this new Siri can access and use. 

There’s no denying that the new version of Siri is far more powerful than it used to be, and arguably more useful at surfacing details on your phone. But that comes at the cost of deeper access. Once enabled, Siri and Spotlight are combined, unifying the interface. Where you may have once just pulled down on the screen to search for an app or contact, you’re now also invoking Siri. 

Spotlight and Siri are now visually one and the same.

By default, ask Siri a question and it’ll search through your Apple apps, like Notes, Messages, emails, and more. As time goes on, if the developer chooses to let it, Siri will gain access to more and more third-party apps. If an app developer doesn’t add that support, then Siri AI won’t be able to access the contents of that app (unless it’s shared screenshot-style via a new feature called “on-screen awareness,” which we’ll talk about more in a moment). 

For example, if Signal doesn’t choose to implement Siri AI support and you only talk to Bill on Signal, you won’t get an answer when you ask Siri AI, “What was the last photo Bill sent me?” But if you talk to Bill on Apple Messages and ask that same question, Siri AI will summarize what it thinks the photo is.

Sometimes Siri processes this data on your device. Sometimes it uses Apple’s Private Cloud Compute (PCC), which means the data is sent off your device to a cloud server. While you can try digging through the Apple Intelligence Report to figure out what’s sent to PCC, there’s no immediate visual indication from the user’s point of view when data leaves the device or when AI can handle it on the phone, iPad, or Mac itself. In practice, ask Siri AI a question and you’ll never really know if it’s being computed on device or off.

Apple claims what’s sent to PCC is not stored by the company after it is processed, but there are certain types of data or certain apps you might have on your phone that are not worth the risk. That’s especially true if you’re using a feature like Advanced Data Protection, which turns on end-to-end encryption for much of what’s stored in iCloud. Sending data that’s stored with end-to-end encryption off your device and into the cloud—no matter the privacy promises—is a fundamental change to the risk assessment you should make. “Private” means the system is engineered so that Apple shouldn’t be able to see or store the data, but it doesn’t mean it’s encrypted or doesn’t leave the device.

This leaves the privacy of certain apps up to a strange combination of an app developer’s choices and your own. You can, of course, disable Siri entirely (Settings > Siri > "Turn Off Siri"), or choose not to invoke Siri to ask questions, but perhaps you don’t want to fully disable or disengage with the system. Thankfully, you can put some guardrails on Siri AI’s access. Once you’ve updated to iOS 27, here are the steps to take. 

Note: only iPhone 15 Pro/Pro Max, as well as all models of the iPhone 16 and newer support Apple’s AI features. Siri AI is currently only available in English, and not available worldwide.

How to Restrict Siri’s Access to the Content Inside Apps

By default, how (and if) Siri AI can access data inside apps is up to the app developer. If an app developer chooses to index the contents of their app, then it may appear in search, and thus be made available to Siri AI. This means the content may pop up during general or direct searches, like “What are my plans for November" might cull information from your calendar, Messages, Notes, and, as they update, third-party apps.

If you do not want Siri to look through certain apps to consider the contents in results, you can tell it not to:

  • Open Settings > Apps > [the app you don’t want Siri to look through] > Search
  • Disable the option to “Show Content in Search.” 

With this setting disabled, when you ask Siri general questions, it will not surface details from the app you selected. For example, if you disable “Show Content in Search” for Messages, it will not be able to read your Messages conversations. 

Left: Asking Siri to summarize a message thread with Show Content in Search enabled. Right: With the setting disabled.

There is also an “App Access” setting where you can configure some of the ways Siri interacts with apps. You’d think this is where we’d have gone to revoke access to the content of an app, but alas, this settings page is more about some basic functionality with device personalization, not Siri’s access to the contents of the app.

  • Open Settings > Siri > App Access
  • Tap an app where you’d like to change Siri’s settings.

On this screen, you’ll find a variety of options, depending on what an app supports. “Learn from this App” sounds nefarious, but is mostly about tracking usage, like how often you open an app, and if a developer supports it, what you interact with.

The rest of the options are mostly about the personalization tweaks that Siri makes, where it suggests apps it thinks you want at the moment in various places, like when searching or sharing. “Show on Home Screen,” “Suggest App,” and “Suggest Notifications” are just about whether you see apps in those places. 

For example, if you have a widget of Siri-suggested apps on the home screen, that’s the “Show on Home Screen” toggle. If you see an app recommended in another app, like adding a date to your calendar from an email, that’s “Suggest App.” Apple claims these features all use on-device processing and the data is not stored on servers.

For anything not covered here, refer to this documentation for steps to disable certain features.

The On-Screen Awareness Capability May Be Concerning for Some People

There is one Siri AI feature you (and app developers) can’t do as much about: on-screen awareness, a feature you can invoke at any point to prompt Siri and ask it to explain what you’re looking at and perform certain actions. For example, you can ask it to summarize a web page, cut a recipe you’re reading in half, add an event to your calendar, or try to figure out where a photo was taken. All potentially useful features.

But you can also ask it to summarize or explain a Signal group chat that you're looking at, or a meme in a WhatsApp chat, and the data from that on-screen interaction may be sent to PCC. There is currently no way for you or app developers to block this feature, so it’s up to you, and those you chat with, to simply not use it if you’re concerned about the content of conversations potentially leaving your device. It would be a large improvement to privacy, especially secure chat apps, if Apple provided developers a means to block access to Siri AI’s on-screen awareness tool. Even better if they gave you a single control to block all Siri AI features from an app entirely.

Revoke Access to Training Data

By default, Siri AI won’t collect and use data from your interactions with it for training AI features. But during the setup process, Apple provides a way to opt in, which you might have tapped without thinking about it. If you’d rather your data not get used for training, you can opt out:

  • Open Settings > Privacy & Security > Analytics & Improvements
  • Disable the option for “Improve Siri & Dictation.” 

According to Apple’s privacy documentation, disabling this option should revoke training access to the audio and text from the Siri app.

Go Back to the Old Version of Siri (and Disable Other AI Features)

Want nothing to do with any of this but still find Siri useful enough to keep around (or you just have to keep it turned on in order to use CarPlay)? For the time being, you can get the old Siri back, though the process is a bit odd.

  • Open up Settings > Screen Time > Content & Privacy Restrictions
  • If you have never done so, enable the toggle for “Content & Privacy Restrictions.”
  • Tap the Siri option, then “Allowed Siri Version.” 
  • Select “Siri Classic.”

You can no longer easily disable Apple Intelligence entirely with one tap in the Settings, but on this screen you can also configure other AI features, like disabling the writing and math assistance prompts, turning off image creation, and disallowing the use of extensions. Follow this guide on Apple's site for everything else.

For the most part, Apple’s handling of AI features is far less in-your-face than others, and because of that the privacy implications are easier to untangle. But even still, it’s difficult to know what’s processed on device and what’s sent off, and so the privacy trade-offs are never spelled out as clearly as they should be. 

Apple could improve on this by offering an on-device only option for Siri AI and providing a clear, single setting toggle to prevent all AI features in a specific app (it looks like Apple is planning a single privacy toggle in a future update. We'll update if and when it does). In general, Siri’s power-up has also made it blurry and difficult to really figure out what sorts of privacy options exist. “Siri” means many things, both on device and off, ranging from “searching the entire internet for an answer” to “setting a timer,” and users have no straightforward ways to wrangle that data to suit their needs. As it stands, it’s a confusing collection of different toggles that never feel exactly right and which many users might struggle to grasp.

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

EFF: Updates - Fri, 09/18/2026 - 5:53pm

Secure messaging platforms, like Signal, WhatsApp, and recently, encrypted RCS, operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to guarantee what happens once the message arrives on a phone. As more devices and services introduce more artificial intelligence (AI) features into messaging apps, that line begins to blur. 

When AI features are computed entirely on device, it’s less concerning. Yet sometimes the computing requirements are heavy enough that the computation has to be done on a company server. Tech companies tell us they have a solution for this: trusted execution environments (TEEs). But do server-side TEEs really solve the problem?

TEEs exist to serve many different functions, ranging from digital rights management (DRM) content protections to securely storing information in your phone's mobile wallet, but for our purposes, we’ll be focusing on how tech companies use them for their AI tools. 

The basic idea is straightforward: most consumer devices aren’t powerful enough to handle the sorts of AI features companies want to offer, so sometimes they send data off your device to more powerful cloud servers to do the computing, then display the results on your device. Since your data is leaving your device, there’s a privacy compromise. For example, if you ask for a messaging app to summarize a conversation, it may offload that computing power to a cloud server, sending the entire contents of your messages to the cloud, then back to your phone.

TEEs supposedly offer a way to keep those requests private. There are several implementations out there, like Apple’s Private Cloud Compute, Google’s Private AI Compute, and WhatsApp’s Private Processing. It’s not just the big tech players, we’ve seen chatbots built with TEEs as well.

TEEs can provide more security and privacy than simply running in the clear, but they are fundamentally different from actual encryption or running locally. Despite the promises of some tech companies, they will never be able to match that level of security and privacy. Because of that, a user’s device should never automatically send data to a TEE. Let’s dig through the reasons why.

What Exactly Is a TEE, Anyway?

A TEE is a hardened section of the computer that runs software in a way that’s supposed to be secret even from other processes running on the machine. TEEs also let users check that the code being run is the code that they think is running, and not backdoored code instead, using a process called “attestation.” You may have also heard this referred to as a “secure enclave,” or heard the brand names SGX or TrustZone.

The intention of a cloud-based TEE is simple: a company can run a server in their data center, but still process data that you provide on your behalf without being able to see that information themselves.

Is a TEE Secure?

In practice, we've seen multiple cracks and hacks every year that show that it is possible to get at that data. That’s because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to breaking it that would not also upend fundamental understandings of mathematics as a field. 

The collective understanding of every mathematician in the world is that standard encryption algorithms are not breakable to the best of the world’s collective knowledge. No responsible engineer builds a system based on a new encryption method until after it’s been offered up for prodding.

Engineering, on the other hand, doesn’t work like that. Every individual system is the product of a group of engineers who put it out into the world, and each product will have its own quirks and bugs that have to be individually discovered and patched. These bugs are found after the system is built, not before. No one has yet built a system that is unbreakable. On the contrary, there is new research all the time that finds new ways to break into TEE systems. They’re patched as they come up, but they’re unlikely to ever become perfect, and certainly not any time soon. 

TEEs in particular are a hard engineering problem because the encryption key is physically right there on the device. Building a TEE means keeping a key fully separate and inaccessible while it’s on the same physical device as parts of the system that shouldn’t have access to the key.

Many attacks on TEEs involve “side channels.” In a side channel attack, the attacker measures the electrical impulses or other effects to figure out the timing of operations inside the TEE, then uses that to figure out the key being used. Once they have the key, they can read all the data. Compare that to end-to-end encryption, where the key is never on that machine in the first place, so an attacker would have to also run a similar attack on the user’s device.

Companies who turn to TEEs to protect data want to both have the key on the server and have it protected while still performing complex operations like running an LLM, which makes it much more difficult to protect those keys.

That being said, a TEE versus plaintext on a server is the difference between being able to easily read the data and having to do a bunch of specialized work to get at the data. That work often involves accessing the physical machine. This is most relevant for protecting against mass surveillance, and for many people, that might just be enough security.

But that's the core of the problem. “Secure enough for most cases” and “encrypted as in math” are not the same thing, and it’s important not to conflate the two. And services that currently offer “encryption as in math” have a real downgrade in security when they switch to security based on TEEs. 

If you want to dive into the myriad security issues and limitations of TEEs we’ve seen so far, they’re well documented here, here, here, and here.

What Does This Have To Do With LLMs and AI?

Sometimes organizations want to offer an LLM that can respond to queries in a private manner. On-device LLMs exist, but they’re limited in size. So, when organizations want to offer the ability to answer queries without being able to see the conversation, they turn to TEEs. That’s a useful way to run a chatbot that’s reasonably private. This is what Apple, Google, WhatsApp, and others are doing.

Why not turn to encryption? After all, LLM inference is just a bunch of math like any other things a computer does. It takes input to a (really big) function and gives an output. We have the math to do that computation in a way that hides the inputs and outputs from the one running the computation, it's just super expensive. It’s called homomorphic encryption, and no one’s figured out how to do it fast enough that it makes sense for this sort of computation.

Instead, the allure of a TEE is that it will run that computation for you inside of a special opaque section of a server. TEE manufacturers try to make it as hard as possible for the person running the TEE to peek inside. But you still have to trust the operator to not put a stethoscope to the box to try to figure out what's happening inside. 

In this case, it’s reasonable to consider these systems “privacy-preserving,” but not “encrypted.” That distinction is important, especially when we talk about how the TEEs interact with secure messaging. When someone using an end-to-end encrypted chat app asks an LLM to summarize, review, or store those messages, the content of those messages is leaving the device and going to an unencrypted third-party server somewhere. That’s a major threat to the privacy of secure chat apps, and one that’s increasingly hard for users to take control of.

How Does This Translate to Practical Advice?

The answer to this is going to vary based on an individual’s threat model, but a good rule of thumb is that a user’s device should never automatically send data to a TEE. When the person holding a phone can choose what information is sent, even if it’s a chunk of data like “unread messages,” they have the opportunity to pause and consider if that data might be too sensitive to risk sending.

In contrast, when data is sent automatically, the automatic sending becomes a feature of the system as a whole. If the system was previously end-to-end encrypted, adding automatic exfiltration makes the whole system no longer end-to-end encrypted.

Developers: don’t build systems that automatically send data off a device to a TEE, especially when it’s coming from an app that is otherwise end-to-end encrypted.

Users: if developers ignore us and build that system, turn off any automatic data sending features. Take a second to think about how much you’re willing to risk sending data when you choose to send it off the device.

So, What Should I Be Concerned About?

TEEs are useful for security in a number of circumstances. Your phone likely has a TEE where it keeps the key that encrypts your biometric unlock data and the base of the keychain where passwords are stored. It also enables certain backup systems, like how you can restore a phone with your passcode or restore WhatsApp or Signal backups.

But when we’re talking about cloud processing, it’s important to be clear this isn’t the same as end-to-end encryption and doesn’t offer the same level of privacy. 

Most of our private lives are on our phones and in our messages. We’ve worked for years to secure those messages, with major wins like encrypted RCS, and the continued user experience improvements of Signal and WhatsApp. We’ve even seen real improvements to backup security with features like Advanced Data Protection that bring end-to-end encryption for a variety of data outside of messaging, like notes and photos. 

But as companies roll out AI features that interact with these encrypted services, pulling data off devices and into a cloud-based TEE, they’re eroding the privacy protections of end-to-end encryption and risk causing serious confusion around what data is protected and what isn’t.

Friday Squid Blogging: On Squid Egg Sacs

Schneier on Security - Fri, 09/18/2026 - 5:06pm

Short essay about squid egg sacs.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

MIT researchers are mapping extreme weather risks — and building tools to act on them

MIT Latest News - Fri, 09/18/2026 - 12:55pm

Warming temperatures are fueling more extreme weather-related events — catastrophic floods, severe hurricanes and cyclones, and wildfires exacerbated by drought. But the tools used by local communities, emergency and public safety agencies, and insurance and risk markets have not kept pace with the up-to-date data and modeling for accurately predicting how these events will evolve.

Addressing that shortcoming was one of five research areas selected for MIT’s 2022 Climate Grand Challenges, an ambitious effort to accelerate science-based solutions to climate problems. The area, titled “Preparing for a New World of Weather and Climate Extremes,” focuses on tools to help evaluate a location’s vulnerabilities to flooding, cyclones, humid heat waves, or other climate-related events.

Four years later, collaborations among more than 40 faculty and student researchers on Weather and Climate Extremes projects have yielded 29 published research papers and digital tools and datasets that are already in use or close to deployment. Individual projects cut across forecasting, risk assessment, on-the-ground planning, and resilient infrastructure.                                               

“Communities across the United States and around the world are already confronting the consequences of extreme weather,” says Evelyn Wang, MIT’s vice president for energy and climate, whose office has been funding and supporting all of the Grand Challenges since 2024. “Through the Climate Grand Challenges, an interdisciplinary team at MIT is advancing the science, technologies, and practical strategies needed to help communities anticipate these risks and build greater resilience.”

Reducing scientific uncertainties

Paul O’Gorman, the Robert R. Shrock Professor of Earth and Planetary Sciences at MIT and co-lead of Weather and Climate Extremes, is refining the science behind forecasting extreme weather events, such as last year’s major flooding events in Central Texas and in Pakistan. “There have been a lot of unprecedented, record-breaking events,” he says, “and we want to understand how they are changing as the climate warms, and how they’re changing in different regions.”

One aspect that his group has been examining is the relationship between extreme rainfall events and a warming climate. Climate models predict that extreme rainfall increases less in summer than other seasons in much of the United States and Europe. O’Gorman’s team found that these seasonal shifts stem from not only how much water is in the atmosphere, which is measured by specific humidity, but also how close it is to saturation, which is measured by relative humidity. “We found that changes in relative humidity played a big role, which was something that hadn’t been appreciated before, and something we need to take into account,” he says. 

Modeling is challenging: Relative humidity depends on air circulation, how fast land warms relative to the ocean, soil moisture, and vegetation. “It’s a complex story, but this helps us understand precipitation patterns,” O’Gorman says.

Kerry Emanuel, MIT professor of atmospheric science who was also a co-lead of Weather and Climate Extremes, is researching better ways to estimate the risks of extreme hurricanes and severe convective storms, such as thunderstorms and tornadoes. “For hurricanes, we’re pretty much there. We can reproduce the statistics of real hurricanes extremely well just using coarse-grained weather data that has no hurricanes in it,” he says. But for severe convective storms, “we’re not close to being there,” and these storms “in the last decade have cost more lives and more damage than hurricanes.” 

Research on the physics of storms is already influencing practice, Kerry notes. For example, a company called First Street uses Kerry’s methods to guide local governments, insurers, developers, and real-estate platforms on environmental risk for every piece of private property in the United States.

Improving resilience

Another phase of the Grand Challenge, led by Miho Mazereeuw, an associate professor in MIT’s Department of Architecture and a leading expert on resilient design, translates the information from scientific modeling and data collection into tools for on-the-ground planners. For example, working with leaders and community members in Boston and Broward County, Florida, the team has developed interactive web-based tools that make it easier to plan for impacts such as flooding over a broad range of scenarios.

“When an extreme event happens, there is a gap between scientific knowledge and actionable public information,” says Aditya Barve, a research scientist in Mazereeuw’s Urban Risk Lab. This happens at various levels — from getting real-time information out to people when they need it to collecting data to enable long-term planning to disseminating those plans to communities. “The idea is to target the gap through tools in community emergency data collection, proactive recovery planning, and AI-assisted tools for at-scale visualization of future climate impacts, so that communities are prepared when something happens.”

The team has worked on making flood modeling outputs usable by a wider range of stakeholders, especially where the need for specialized software or technical expertise can slow decision-making across city departments. “Users can ask practical questions, such as which schools are likely to stay driest across different flood scenarios, and receive answers grounded in flood models and city datasets within seconds,” Barve says.

As for recovery after extreme weather events, Mazereeuw points out that most municipalities have an emergency response plan, but few create a recovery plan that includes housing before the event. But, she says, if communities plan how recovery can lead to a better future for the city, they can better leverage emergency relief funding that becomes available. “In almost all cases, the resources available after a disaster are much larger,” she says. “By having a plan in place, those resources can fit the vision of the place moving forward.”

Optimizing energy infrastructure

Associate Professor Michael Howland is working to analyze the impacts of extreme weather on energy infrastructure with a team that includes Jessika Trancik, a professor in the MIT Institute of Data Systems and Society (IDSS), and Moshe Ben-Akiva, the Edmund K. Turner Professor in Civil Engineering at MIT. The team is particularly looking at impacts on the electrical power system and ways to optimize decisions on the placement and sizing of new energy infrastructure. 

Howland, who is the Jeffrey Cheah Career Development Professor of Civil and Environmental Engineering at MIT, says electrical power systems are increasingly being altered by two things at the same time: first, the proliferation of renewable energy and storage technologies, and second, large-scale changes in weather and extreme events driven by climate change. “Each of these would independently push our electrical power system potentially outside of what we are used to, and their combined, synergistic impacts could be even larger because they are occurring simultaneously,” he says.

Bringing climate modeling and grid-infrastructure work together has accelerated practical insights into how we can adapt to climate change while simultaneously mitigating it, Howland notes. Such modeling can also help to inform infrastructure decisions in ways that may not be obvious. For example, he says, their optimization model for the siting of power resources in Texas resulted in placing a number of wind power plants along the Gulf Coast. “If you look at an average wind speed map,” he says, “you would say this doesn’t make much sense because it’s really windy in northwest Texas on average, and much less windy along the Gulf Coast.”

But it turns out that the typical daily cycle of winds is complementary, so that wind farms distributed between both locations tend to smooth each other out and to better complement solar power generation, easing burdens on the grid. Now, “we’re trying to take it further not just by smoothing the generation, but actually aligning it with the time- and space-varying electricity demand so that we can reduce storage, transmission, and other backup generation needs,” he says.

This work is ongoing, and the hope is that it will lead to products that can directly help utility grid planners and regulators with actionable information about the siting and sizing of various electrical infrastructure resources, Howland says. “We want to continuously push on model realism and accuracy to eventually make it more of a practical and useful tool for grid planners.”

Emanuel adds that the Weather and Climate Extremes Grand Challenge, and other projects working to pinpoint the kinds of risks that can be expected from a changing climate, have produced a great deal of specific and detailed information that could guide political, economic, and civic decision-making. Applying it in the real world can be a slow — “like steering a supertanker,” he says — but progress will come.

A new chapter for MIT Reads

MIT Latest News - Fri, 09/18/2026 - 12:30pm

As it marks its 10-year anniversary, MIT Reads is being reimagined for the age of artificial intelligence. 

Recognizing the need to foster social connection and a sense of our shared humanity, the popular MIT Libraries’ program will turn its focus to fiction and memoir, and to the particular power of stories to help us understand ourselves and our place in the world. 

“At MIT, we spend a great deal of time on imagining and building for the future. Reading fiction prompts us to think about how what we build might change us,” says MIT Libraries Director Chris Bourg. “Reading together also gives us the increasingly rare opportunity for both individual reflection and shared connection.” 

MIT Reads is also evolving with MIT as it explores AI’s influence on the education landscape and the social fabric of the Institute. The value of collective reading, reflection, and discussion has never been more relevant. 

A recently released report from MIT’s Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training urges strengthening social connection and personal well-being, citing MIT Reads as a way to “engage many more people across campus in conversation about shared norms and why community matters.” 

Launched in 2016, MIT Reads was designed to foster empathy, understanding, and belonging within the campus community. Each selected book is accompanied by programming such as talks by the featured author, panel discussions, and small-group conversations facilitated by library staff. 

The program’s reach extends well beyond MIT. Most author events are open to the public and streamed online, and videos of MIT Reads talks have been viewed more than 5,000 times.

To mark this new era of MIT Reads, President Sally Kornbluth has selected the fall 2026 book “Exhalation,” by Ted Chiang. “Exhalation” is a bestselling collection of short stories, named one of The New York Times’ best books of 2019. In it, Chiang creates thought-provoking science fiction scenarios involving robots, time travel, and alternate universes, while exploring timely issues of identity, free will, language, and the impacts of technology. 

“With the stories in his 2019 ‘Exhalation’ collection, Ted Chiang offered an uncanny preview of many issues we’re grappling with now concerning technology, particularly the relationship between humans and artificial intelligence,” says Kornbluth. “He raises deep questions about the future that humans and machines will share and offers provocative ideas and possibilities. I’m delighted that MIT Reads will give us the opportunity to explore his work together.”

“MIT is not alone in grappling with these big questions around technology and its relationship with humanity,” adds Bourg. “These questions call for a much wider discussion, and we invite readers everywhere to join us.”

In addition to its discussion as part of MIT Reads, students in the first-year advising seminar 21.A01 (Reading Great Books with Compass) will be reading “Exhalation” this fall; the class is part of the Compass initiative designed by faculty from across the School of Humanities, Arts, and Social Sciences and supported by the MIT Human Insight Collaborative.

A new understanding of how enzymes influence bacterial protein production

MIT Latest News - Fri, 09/18/2026 - 12:20pm

Antimicrobial resistance is one of the most pressing global health and development challenges of our time. Bacteria and other pathogens are rapidly developing resistance to existing treatments, making infections harder to treat. Without new approaches, minor inconveniences today, such as routine surgeries or even a paper cut, could become life-threatening tomorrow. 

Now, an international group of scientists reports the discovery of aminovaleramididine synthetase (AvaS), the first identified pyridoxal phosphate (PLP)-dependent enzyme responsible for producing a chemical modification linked to how bacteria respond to metabolic stress. This discovery sheds new light on how bacteria use RNA modification to control protein production, opening new avenues to study bacterial adaptation and identify future targets and better strategies for developing antimicrobial therapeutics. 

The work was led by researchers from the Singapore-MIT Alliance for Research and Technology’s Antimicrobial Resistance interdisciplinary research group (SMART AMR), alongside collaborators from MIT, Nanyang Technological University in Singapore, and institutions in the United States, Poland, and France.

“While many RNA modifications have been known for decades, researchers are still uncovering the full extent of their roles. The discovery of AvaS opens a previously unknown chapter in RNA biology and is an important step forward in our understanding of processes relevant to antimicrobial resistance,” says Professor Peter Dedon, co-lead principal investigator at SMART AMR, professor of biological engineering at MIT, and co-corresponding author of a new paper on the work. “As we continue to map the RNA modification landscape, we expect many more discoveries with meaningful implications for infectious disease, antimicrobial resistance, and fundamental biology.”

Bacteria can develop resistance to antibiotics using various strategies, many of which depend on the bacteria’s ability to regulate which proteins are made, when they are made, and how accurately they are produced — whether by pumping drugs out of their cell, creating enzymes that break down drugs, or developing new cell processes to avoid the antibiotics’ target.

To build these proteins, bacteria rely on RNA molecules to read genetic instructions and direct protein production. Among these RNA molecules are transfer ribonucleic acid (tRNAs), a specialized class of RNA that acts as molecular delivery vehicles bringing chemical “stickers” to help bacteria control how proteins are made in response to stress and changing conditions such as exposure to antibiotics.

In the open-access paper, “Pyridoxal phosphate-dependent biosynthesis of aminovaleramide by AvaS in tRNA,” published Sept. 9 in Nature Chemical Biology, the researchers described their discovery of the new enzyme and identified it as being responsible for creating a tRNA chemical modification known as aminovaleramide cytidine (ava2C) in Pseudomonas aeruginosa, a harmful bacterium responsible for a range of serious human infections such as pneumonia and sepsis. While ava2C had previously been detected in several bacteria and plants, the enzyme responsible for producing this modification was previously unknown.

Using SMART AMR’s high-throughput liquid chromatography-tandem mass spectrometry (LC-MS/MS)-based RNA modification profiling platform, the team systematically screened thousands of P. aeruginosa mutants and discovered AvaS. The researchers also confirmed the presence of ava2C in other organisms, including the bacteria Acinetobacter baumannii and Vibrio cholerae, as well as the plant Arabidopsis thaliana.

The research revealed that AvaS uses PLP, a vitamin B6 derivative, to convert a known modification, lysidine (k2C), into ava2C; marking the first time that a PLP-dependent enzyme has been linked to tRNA modification. Traditionally, PLP-dependent enzymes have only been associated with amino acid metabolism and related biochemical pathways. 

The research findings revealed a few important insights about PLP-dependent enzymes. First, the discovery establishes PLP-dependent enzymes as a previously unrecognized class of tRNA-modifying enzymes, expanding the known chemical mechanisms, such as methylation, thiolation, and isomerisation, that bacteria use to regulate protein production. Second, it reveals an entirely new biological function of PLP-dependent enzymes, demonstrating that they can directly modify tRNA in addition to their well-established roles in metabolic processes.

The research also found that ava2C changes how bacteria read genetic codes, enabling the bacteria to produce protein faster and more efficiently while helping them adapt to metabolic and oxidative stress.

“Our discovery has revealed, for the first time, that PLP-dependent enzymes can directly modify tRNA, expanding our knowledge and understanding of RNA-modifying chemistry,” says Jingjing Sun, research scientist at SMART AMR, first author, and co-corresponding author of the paper. “This opens up new avenues for studying bacterial adaptation and developing new and more effective strategies to overcome drug-resistant bacteria.”

Building on this discovery, the SMART AMR team plans to investigate how ava2C affects bacterial stress responses and metabolism and explore how the modification can be disrupted or prevented. Understanding this process could uncover new ways to fight harmful bacteria and develop future antimicrobial therapeutics. With ava2C also being observed in plants, future studies could explore whether other living organisms use similar biological tools to produce certain chemical modifications and how ava2C influences the way proteins are built beyond bacteria.

More broadly, this work highlights the strength of SMART AMR’s first-of-its-kind epitranscriptomics platform as a powerful engine in discovering more unknown RNA-modifying enzymes at scale. This capability could also support biotechnology and pharmaceutical researchers in finding new drug targets and developing better treatments, particularly as bacteria continue to develop resistance against existing drug treatments.

The research conducted at SMART is supported by the National Research Foundation Singapore under its Campus for Research Excellence and Technological Enterprise program.

Are AIs Still Struggling with CAPTCHAs?

Schneier on Security - Fri, 09/18/2026 - 7:05am

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.

“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again...

Fueling a return journey from Mars

MIT Latest News - Fri, 09/18/2026 - 12:00am

When Lanie McKinney was 3 years old, her parents stopped at a massive meteor crater during a road trip through the U.S. Southwest. As they prepared to leave, McKinney began to protest.

“I want to wait here for the next one,” she told them.

She didn’t yet understand that another meteor wasn’t likely to land in exactly the same spot. But the story, which her parents still tell, captures a fascination that has remained with McKinney throughout her life.

“I just always remember being captivated by space and what is out there,” she says.

Today, McKinney is entering her fifth year as a PhD candidate at MIT, where she works in the Aerospace Plasma Group with Esther and Harold E. Edgerton Associate Professor Carmen Guerra-Garcia. McKinney’s research focuses on developing technologies that could help humans explore Mars.

One of the challenges of sending humans to the Red Planet is figuring out how to supply them once they arrive — including how to enable their journey back home. Rather than transporting everything from Earth, McKinney is interested in using the resources already available on the planet, a concept known as in-situ resource utilization, or ISRU.

“If we don’t build gas stations on Mars, it will be very difficult to get humans back to Earth,” she says. “We’re going to need some way to produce the propellant on site.”

McKinney’s research uses cold plasma to convert carbon dioxide, which is abundant in the martian atmosphere, into oxygen and carbon monoxide, a technology that could eventually be used to produce life support and propellant on Mars. 

An Oklahoma native, McKinney earned her bachelor’s at the University of Tulsa, where she studied physics and applied mathematics. She had initially expected to pursue astrophysics, but a summer research internship at the University of Colorado at Boulder introduced her to plasma physics through a project involving dusty plasmas in the lunar environment. 

“I thought it was an incredibly interesting problem,” she says. 

At MIT, McKinney has developed a small reactor that can convert carbon dioxide into oxygen and other products. The challenge now is separating out the oxygen before it recombines.

“We can actually perform the conversion step really well,” she says. “But what happens in a plasma is we convert it, and then we get a mixture that needs to be separated.”

Her current work pairs the plasma reactor with an oxygen-selective membrane designed to extract oxygen rapidly. The integration process isn’t well-understood, leaving McKinney and her colleagues with questions about how the reactive plasma environment will affect the membrane.

“We are not entirely sure what we will see,” she says.

For McKinney, the possibility of connecting laboratory experiments to future human missions is what makes the work particularly rewarding.

“I get to work in a really cool lab and develop exciting experiments,” she says. “I get ownership over an entire experimental system, and then I get to connect that to performance requirements for a future Mars system. That’s just the dream.” 

That same philosophy has shaped McKinney’s work beyond her thesis. Through MIT’s Space Resources Workshop, she has participated in NASA competitions focused on sustaining humans in space. Her first competition involved designing a self-sustaining Mars mission for 10 years.

“I had no clue what was going on,” she says. “I  didn’t know anything about space systems. So, my mentality was, let me jump in and learn.”

She later co-led MIT’s CERBERUZ team for NASA’s LunaRecycle Challenge, which asked teams to develop ways to recycle waste on missions to the moon and deep space. The MIT team recently won first prize in Phase 2, receiving $775,000 in awards for a system that grinds mixed trash into powder that can be reused via injection molding to make spare parts and 3D-printing filament. 

Another project McKinney enjoyed brought together engineers and architects through MAS.S66/4.154/16.89 (Space Architecture) to tackle a different problem: how to protect lunar habitats from radiation using only resources available on the moon. The students’ solution was to produce cast bricks from lunar regolith that could be stacked without mortar or another binder. For McKinney, the project demonstrated the value of bringing together people with different expertise.

“The kinds of innovative solutions that can be discovered when you work on a team that brings together different expertise and experiences was one of the project’s major takeaways,” she says.

The experience reflects a broader lesson McKinney has taken from MIT: Research may involve focused individual work, but solving the problems of human space exploration will require collaborations across disciplines.

“I feel like I have learned so much from being a part of these different teams,” she says. 

McKinney sees that collaboration as essential to the future she hopes to help build. Reaching the Moon and Mars is only the first step: “What comes next is building up a permanent presence so that we can do amazing science and be really effective at exploration,” she says.

McKinney’s fascination with exploration extends beyond her research. She is an avid hiker and mountaineer, having grown up hiking with her family in the Rockies. She recently completed a mountaineering course in Alaska and summited Mount Baker in the Cascade Range. She sees a connection between those adventures and the curiosity that first drew her to space.

“I love to explore and go on adventures,” she says. “And space is the ultimate thing you could explore.”

That curiosity has also shaped how McKinney approaches her work. When she arrived at MIT from the University of Tulsa, she initially felt intimidated.

“I thought that it was a fluke that I’d gotten in,” she says. “I was very nervous that I was not going to measure up to the environment.”

Over time, she learned to approach unfamiliar problems by asking questions and committing fully to whatever interested her.

“If something interests you, try it and go all in,” she says.

Genetically engineered crops increase climate resilience of US fields

Nature Climate Change - Fri, 09/18/2026 - 12:00am

Nature Climate Change, Published online: 18 September 2026; doi:10.1038/s41558-026-02750-6

Analyses of four decades of data show that genetically engineered varieties of corn, soybean and cotton raised average yields, reduced year-on-year yield variability and blunted the climate-driven northward drift of crop production. These findings indicate that biotechnology is an under-recognized instrument of climate adaptation.

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

EFF: Updates - Thu, 09/17/2026 - 9:16pm

With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. 

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public's security.

When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else's computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.

Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.

As with any technology regulation, those targeting cybersecurity practices at AI labs must be careful, precise, and practical.

Meet the 2026 tenured professors in the School of Humanities, Arts, and Social Sciences

MIT Latest News - Thu, 09/17/2026 - 4:50pm

In 2026, five faculty were granted tenure in the MIT School of Humanities, Arts, and Social Sciences.

Volha Charnysh is an associate professor in the Department of Political Science. She studies the role of identity in state-building and economic development and the effects of violence. Her first book, “Uprooted: How post-WWII Population Transfers Remade Europe” (Cambridge University Press, 2024), focuses on the enduring consequences of mass displacement and resulting cultural heterogeneity. She received her PhD from Harvard University in 2017 and joined the MIT faculty in 2018.

Grisha Coleman is a full professor in the Music and Theater Arts Section. Her research explores tensions between our physiological, technological, and ecological systems; human movement, our machines, and the places we inhabit. Her practice engages an interdisciplinary approach to these explorations. She earned an MFA in music composition and integrated media from California Institute of the Arts. She joined the MIT faculty in 2026.

Tung-Hui Hu is an associate professor in the Comparative Media Studies/Writing program. A poet and a scholar of digital media, he is the author of five books, most recently “Digital Lethargy: Dispatches from an Age of Disconnection” (MIT Press, 2022), “A Prehistory of the Cloud” (MIT Press, 2015), and “Greenhouses, Lighthouses” (Copper Canyon Press, 2013). Hu is interested in how concepts such as race and normal language became measurable, governable objects in the form of datasets. He earned a BA in comparative literature from Princeton University, an MFA in creative writing from the University of Michigan, and a PhD in film studies from the University of California at Berkeley. He joined the MIT faculty in 2026. 

Tobias Salz is an associate professor in the Department of Economics. He works in the field of industrial organization and studies how digital platforms and other intermediaries shape competition and market outcomes. The applications of his research span digital markets, transportation, and artificial intelligence, and often combine economic theory with novel data and field experiments. His recent work examines market power in web search, personalized platform pricing, and how human experts and AI can work together in medical diagnosis. He received his PhD in economics from New York University in 2016 and joined the MIT faculty in 2019.

Christian Wolf is an associate professor in the Department of Economics. His research is primarily concerned with the question of how monetary and fiscal policy can be used to stabilize the economy. A key aim of his work is to learn as much as possible about such stabilization policy directly from micro- and macroeconomic data, rather than through reliance on structural models. Wolf joined the MIT faculty in 2021 after earning his PhD in economics from Princeton University.

MIT School of Engineering faculty and staff receive awards in spring 2026

MIT Latest News - Thu, 09/17/2026 - 4:20pm

Each year, faculty and researchers across the MIT School of Engineering are recognized with prestigious awards for their contributions to research, technology, society, and education. To celebrate these achievements, the school periodically highlights select honors received by members of its departments, institutes, labs, and centers. The following individuals were recognized in spring 2026:

Faez Ahmed, the Esther and Harold E. Edgerton Associate Professor in the Department of Mechanical Engineering, received a 2025 Air Force Office of Scientific Research Young Investigator Program Award. The award provides early-career U.S. scientists and engineers with up to $450,000 over three years to support innovative research.

Navid Azizan, the Alfred Henry (1929) and Jean Morrison Hayes Career Development Professor and an associate professor in the Department of Mechanical Engineering, has received a National Science Foundation (NSF) CAREER Award. The Faculty Early Career Development (CAREER) Program is a foundation-wide activity that offers the NSF’s most prestigious awards in support of early-career faculty who have the potential to serve as academic role models in research and education and to lead advances in the mission of their department or organization.

Yet-Ming Chiang, the Kyocera Professor of Materials Science and Engineering in the Department of Materials Science and Engineering, was named a Boston Globe Tech Power Player 2026. The annual list highlights the impact of local leaders on technology and business.

Samantha Coday, an assistant professor in the Department of Electrical Engineering and Computer Science, received a 2025 ARPA-E IGNIITE Award. The award aims to support early-career innovators seeking to convert disruptive and unconventional ideas into impactful new technologies across the full spectrum of energy applications.

Srini Devadas, the Edwin Sibley Webster Professor and a professor in the Department of Electrical Engineering and Computer Science, received the 2026 ACM-IEEE CS Eckert-Mauchly Award, which recognizes contributions to computer and digital systems architecture.

Joel Emer, professor of the practice in the Department of Electrical Engineering and Computer Science, received the 2026 ACM SIGARCH/IEEE TCCA Influential Paper Award. This award recognizes the paper from the ISCA Proceedings 20 years earlier that has had the most impact on the field (in terms of research, development, products, or ideas) during the intervening years.

Chuchu Fan, an associate professor in the Department of Aeronautics and Astronautics, received the IEEE Robotics and Automation Society Early Academic Career Award in Robotics and Automation. The award recognizes academics who have made an identifiable contribution or contributions that have had a major impact on the robotics and/or automation fields.

Yoel Fink, the Danae and Vasilis (1961) Salapatas Professor in the Department of Materials Science and Engineering, received the American Physical Society Andrei Sakharov Prize, which recognizes outstanding leadership and achievements of scientists in upholding human rights.

Aristide Gumyusenge, an assistant professor the Department of Materials Science and Engineering, received the 2026 Early Investigator Award from the American Chemical Society's Polymeric Materials: Science and Engineering Division. Honorees are chosen from early-career emerging leaders who have made significant contributions in their respective fields within polymer materials science and engineering.

Paula Hammond, dean of the School of Engineering and an Institute Professor in the Department of Chemical Engineering, received the AIChE 2026 John M. Prausnitz Institute Lecture Award. The Prausnitz AIChE Institute Lectureship is awarded to a distinguished member of AIChE who has made significant contributions to chemical engineering in their field of specialization.

Robert Langer, the David H. Koch (1962) Institute Professor in the departments of Biological Engineering (BE) and Chemical Engineering, received the 2026 Robert A. Welch Award in Chemistry from the Welch Foundation. This prestigious prize recognizes important research contributions that have had a significant and positive impact on humankind.

Gareth McKinley, the School of Engineering Professor of Teaching Innovation and a professor in the Department of Mechanical Engineering, was elected to the National Academy of Sciences. Awardees are recognized by their peers for their outstanding contributions to research in the natural and social sciences.

Farnaz Niroui, Robert J. Shillman (1974) Career Development Professor in Electrical Engineering and Computer Science and an associate professor, received the Rising Star of Microsystems Award from the Transducer Research Foundation, which is intended to highlight the next generation of innovators shaping the future of microsystems, microfabrication, MEMS, micro/nanomanufacturing, and closely related fields.

Tomás Palacios, the Clarence J. LeBel Professor in the Department of Electrical Engineering and Computer Science, received the 2026 Quantum Devices Award from the International Symposium on Compound Semiconductors for significant advancements in wide bandgap semiconductors and nanostructures to improve electronics and pave the way for heterogeneous integration with silicon CMOS.

Ritu Raman, the Eugene Bell Career Development Professor of Tissue Engineering and an associate professor in the Department of Mechanical Engineering, received a Grainger Foundation Frontiers of Engineering Grant from the National Academy of Engineering. The grants provide seed funding for participants at U.S.-based institutions to support further pursuit of new interdisciplinary research and projects stimulated by interactions at the U.S. Frontiers of Engineering symposium.

Lindsey Raymond, an assistant professor in the departments of Electrical Engineering and Computer Science and of Economics, was named a 2025 Early Career Fellow by Schmidt Sciences AI2050. AI2050 issues awards to enable and encourage bold and ambitious research, often multidisciplinary, that is typically hard to fund but socially beneficial. Awards are given for exceptional work tackling one or multiple items from a working list of hard problems.

Daniela Rus, the Panasonic Professor and a professor in the Department of Electrical Engineering and Computer Science, received the 2026 High-Tech Prize of the Bavarian Minister-President. This prize is the most highly endowed award for technology and engineering in Germany.

Afreen Siddiqi, a research scientist in the Department of Aeronautics and Astronautics, received a 2026 Guggenheim Fellowship. Working across 55 disciplines, the fellows were selected from almost 5,000 applicants for “prior career achievement and exceptional promise.”

Vincent Sitzmann, an associate professor in the Department of Electrical Engineering and Computer Science, received both a CAREER Award from the National Science Foundation and the Pattern Analysis and Machine Intelligence (PAMI) Young Researcher Award from the IEEE Computer Society. The PAMI Young Researcher Award is given to a researcher within seven years of completing their PhD for outstanding early career research contributions.

Loza Tadesse, the Latham Family Career Development Professor and an assistant professor in the Department of Mechanical Engineering, was named to Chemical & Engineering News’ 2026 Talented 12. This annual list recognizes early-career researchers who are rising stars in chemistry, selected for their innovative work and growing impact in the field.

Kripa Varanasi, the Maher A. Elmasri Professor of Mechanical Engineering, accepted a United Nations World Intellectual Property Organization Global Award on behalf of his startup, AgZen. The award recognizes the company’s efficient agrochemical spraying patent portfolio.

California’s “Addictive Feeds” Law Violates Teens’ First Amendment Rights

EFF: Updates - Thu, 09/17/2026 - 3:43pm

A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week.

The case, Meta v. Bonta, challenges SB 976, which requires that teen social media users get their parents’ permission before seeing other users’ recommended speech on their social media feeds. The legal challenge to SB 976 has largely centered on how the law violates social media services’ First Amendment rights to curate user-generated content and present it as they see fit.

But the friend-of-of the-court brief EFF filed along with the Center for Democracy & Technology and the Wikimedia Foundation shows that the law violates teen users’ First Amendment rights, too.

“SB 976 frustrates young people’s ability to use the internet to its full potential, prohibiting them from relying on tools that disseminate their speech and help them view and interact with other users’ speech,” the brief argues.

Recommendation systems have a dual purpose on social media: they help all users discover speech and content by other users, and to get their own speech in front of a wider audience.

“SB 976 creates significant, constitutionally violative, burdens on young users’ ability to read and comment on the news, discuss politics, find and share art, share their religious beliefs, or even practice their religion with fellow members of their faith,” the brief argues. “There is simply too much content on services for users to sift through manually, and young users may not know what to search for or even how to find content.”

Because SB 976 creates such broad burdens on teens’ ability to distribute and receive speech, it should be struck down on First Amendment grounds. But as EFF’s brief argues, the First Amendment doesn’t stop California and other states from passing laws that help all users, regardless of age, avoid major social media services’ harmful surveillance business models.

“One could imagine a law that required services to minimize the amount of data they collect, or limit using more invasive data analysis practices, such as tracking users across multiple services, analyzing keystrokes, and other surveillance-intensive practices,” the brief argues. “Such restrictions likely would serve the state’s aim of protecting all internet users—including minors—and would be more narrowly tailored to addressing the harms those practices cause than SB 976.”

Pages