Feed aggregator

EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act

EFF: Updates - Mon, 08/03/2026 - 7:25pm

EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states:

While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.

As we’ve previously explained, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own Privacy Badger. As we illustrate in the letter: 

Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives. 

Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.

Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won't fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.

You can read the full letter here. For a deeper dive into why crawlers and scrapers are vital for the open web, check out this blog post.

EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal

EFF: Updates - Mon, 08/03/2026 - 6:17pm

The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers. 

The new proposed policy builds on, and directly references, the Trump administration’s  “Preventing Woke AI in the Federal Government” executive order—a nightmare for civil liberties that seeks to strong-arm AI companies into modifying their models to conform with the its ideological agenda. In recently filed comments, EFF,  Public Knowledge, and Fight for the Future call for the FTC to stop its unconstitutional efforts to regulate lawful speech, override state laws, and intimidate AI developers into ideological alignment with the Trump administration.

The government may not install itself as the arbiter of truth.

In the joint comments, we outline three critical flaws within the latest proposed policy. First, it violates the First Amendment. The policy calls for the Commission to become the judge of which AI outputs meet an undefined standard of accuracy. Installing the FTC as the authority of this sort of viewpoint-based judgment is a prior restraint on speech. Additionally, the policy’s proposed solution to address speech concerns compounds, rather than properly limits, the likely harms to speech. As we say in our comments: the government may not install itself as the arbiter of truth. 

Second, it exceeds the FTC’s legal authority by claiming that its federal regulatory rules can override, or “preempt,” laws in states that have passed to regulate artificial intelligence use. This is clearly an attempt to target state laws the administration disagrees with. For example, the policy specifically criticizes Colorado's automated decisionmaking law, which applies when automated technology is used to consider consequential decisions such as those around employment, access to housing, health care, and insurance. We noted to the FTC that characterizing this law as one that requires AI companies to “suppress accuracy,” or encourages deception, is itself inaccurate. In any case, the FTC lacks the authority to put its rules in place over state law, unless Congress directly delegates it that power. It has been given no such power here.

Third, the policy is vague and sets the stage for improper jawboning of AI developers and companies that use AI tools (deployers). Jawboning is a term for situations in which the government urges private companies or people to censor another's speech. The proposal, as written, creates an enforcement regime that would put a thumb on the scale in favor of certain partisan speech and ideals. This will lead companies to censor only what the administration interprets as biased or untruthful. Yet, in our filing, we note that the FTC itself can't define an objective standard for what “bias” means, conceding the “exact line of what constitutes bias may be difficult to draw.”

There is work the FTC should be doing to protect consumers in the age of AI. In our comments, we conclude by saying:

[We] implore the Commission to focus on its core strengths and the mission for which it is so urgently needed—promoting structural market competition and protecting consumers from real unfair and deceptive acts and practices—in both the burgeoning and critically important AI industry and across the broader technology marketplace.

EFF and our partners have always urged the FTC to police genuine deception in technology markets. We have also consistently opposed government efforts to dictate what private speakers may say. That’s why we urge the FTC to withdraw this proposal. 

You can read our full comments here

The Youth AI Privacy Act’s Privacy Paradox

EFF: Updates - Mon, 08/03/2026 - 5:08pm

The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bills under consideration this week—require more data collection and make it harder for people to access lawful speech online. 

While the bill is narrower than some other proposed chatbot bills, it still has massive data security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.

This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing "harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are already targets of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more. 

The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors. 

Mandating Design is Regulating Speech

The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push alerts and notifications.  

We have seen this same type of restriction, sometimes called “age appropriate design code” in several states, including in California, Texas, and Arkansas. Unfortunately, these restrictions run into constitutional problems. In fact, federal courts have largely blocked these laws from going into effect because they likely violate the First Amendment rights of all internet users and the online services they regulate. Specifically, these laws interfere with internet users’ First Amendment rights to either speak or access speech online, and they also violate the rights on online services to decide how they will present information on their sites. 

Similarly, the Supreme Court has repeatedly ruled that “minors are entitled to a significant measure of First Amendment protection.” This does not mean that parents or guardians can’t set their own rules for their families—they can and they should, based on the needs and circumstances of the individual teenagers. But it does mean that Congress cannot adopt a “one size fits all” regulation that sets a restrictive government default that affects the First Amendment rights of all internet users, including teenagers. 

Alexander Rakhlin named director of the MIT Statistics and Data Science Center

MIT Latest News - Mon, 08/03/2026 - 3:50pm

Alexander “Sasha” Rakhlin PhD ’06, the Distinguished Professor in Data, Systems, and Society at the MIT Institute for Data, Systems, and Society (IDSS); and a professor of brain and cognitive sciences at MIT, has been named the next director of the MIT Statistics and Data Science Center (SDSC). 

Rakhlin succeeds Ankur Moitra, the Norbert Wiener Professor of Mathematics, associate director of the IDSS, and a faculty member in the MIT Department of Electrical Engineering and Computer Science (EECS) who has been SDSC director since 2021. Philippe Rigollet, the Cecil and Ida Green Distinguished Professor of Mathematics and a core faculty member in IDSS, also served as interim director in 2024-25.

“Sasha is one of the sharpest theoretical minds working in statistics and machine learning today, and also one of the most devoted mentors I know,” says Fotini Christia, the Ford International Professor of the Social Sciences and director of IDSS, which houses SDSC. “He has helped train an entire generation of interdisciplinary scholars through the Interdisciplinary Doctoral Program in Statistics (IDPS), while his own research keeps pushing the boundaries. The SDSC could not ask for a more fitting leader.”

Rakhlin is the inaugural holder of the Distinguished Professorship in Data, Systems, and Society, an endowed chair created in 2025 by the generosity and vision of IDSS professor Richard “Dick” Larson, an “MIT lifer” and pioneer in operations research, queueing theory, and system optimization.

“I am honored to take on this role,” says Rakhlin. “The strength of the Statistics and Data Science Center has always been its people — students, postdocs, and faculty from across MIT who bring sharply different perspectives to the most interesting problems of the day in statistics, machine learning, and AI. My goal is to support that community as it takes on the constantly evolving questions reshaping the field.”

Rakhlin has been connected to the Statistics and Data Science Center as a visiting professor since 2016, before formally joining MIT in 2018 in the Department of Brain and Cognitive Sciences and IDSS. As the initial chair of the Interdisciplinary PhD in Statistics program at the SDSC, Rakhlin has seen the successful defense of over 75 IDPS PhD students across a variety of departments at MIT, including IDSS’ own Social and Engineering Systems program.

“I have been fascinated by machine learning since my PhD work more than 20 years ago, drawn by its beautiful connections to statistics, probability, algorithms, optimization, and game theory,” says Rakhlin. “At the Statistics and Data Science Center, I work alongside colleagues who share this fascination and pursue these connections in many directions. The recent revolution in AI is extending this web into the sciences; it promises to accelerate discovery, and it raises new questions for statistics. Answering them demands a rigorous science of the tools themselves. As AI enters medicine, energy, and public life, its safety and security are, at their core, statistical and mathematical questions: quantifying uncertainty, providing guarantees, understanding failure, and resisting manipulation.”

As Rakhlin puts it, the SDSC is built for this moment. “Statistics is a shared language across MIT,” he adds. “Through the Interdisciplinary Doctoral Program in Statistics, the center connects students and faculty from economics and political science to physics and engineering. Collaborations in areas from biology to nuclear fusion have shown how statistical thinking accelerates science itself.” 

As director, one of his goals is to deepen these interdisciplinary connections. He hopes to help make SDSC the Institute’s home for the rigorous foundations of data science and AI, and a bridge to the scientific and societal questions where those foundations are most needed.

Rakhlin received his bachelor’s degrees in mathematics and computer science from Cornell University, and doctoral degree from MIT. He was a postdoc at the University of California at Berkeley in EECS before joining the University of Pennsylvania, where he was an associate professor in the Department of Statistics and co-director of the Penn Research in Machine Learning center.

Connecting students with the future of microelectronics

MIT Latest News - Mon, 08/03/2026 - 1:30pm

The 2026 Northeast Microelectronics Internship Program (NMIP), organized by the MIT Microsystems Technology Laboratories, brought together 30 exceptional students from leading universities across the Northeast for an immersive week exploring the rapidly evolving world of semiconductor technology and microelectronics. Held July 13-17, the externship provided undergraduate students with an opportunity to experience the complete microelectronics innovation ecosystem, from academic research laboratories to advanced manufacturing facilities.

Throughout the week, students visited several of the region's premier institutions, including MIT.nano, IBM Research, GlobalFoundries, Rensselaer Polytechnic Institute (RPI), and NY CREATES, where they engaged with researchers, engineers, faculty, graduate students, and industry leaders working at the forefront of semiconductor innovation.

The program began at MIT.nano with an inspiring overview of the microelectronics landscape led by Vladimir Bulović, director of MIT.nano, and Farhad Varzhegoo, director of strategic initiatives and partnerships at the Northeast Microelectronics Coalition Hub. Their presentations challenged students to think beyond today's technologies and consider the broader societal impact of tomorrow's innovations.

"What will the next innovation in microelectronics look like, and what should the world of tomorrow focus on?" they asked, encouraging participants to view engineering not only as a technical discipline, but also as a means to solve meaningful real-world challenges.

Following the opening session, Farnaz Niroui, the Emmanuel E. Landsman Career Development Chair and assistant professor of electrical engineering and computer science at MIT, organized a series of graduate student research presentations showcasing the breadth of microelectronics research taking place across MIT. The presentations explored topics spanning integrated circuits, nanoelectronics, photonics, quantum technologies, and advanced materials.

After the student research presentations, participants attended an industry panel exploring the transition from academia to careers in microelectronics. Organized and moderated by Susan Feindt, fellow emeritus at Analog Devices and visiting research scientist at MIT, the panel featured professionals from Rage Systems, Cadence Design Systems, Analog Devices, and RTX (Raytheon), who shared their career journeys, discussed the differences between research and industry, and offered advice on navigating career opportunities in the semiconductor sector.

"What stood out to me most about our day at MIT was the opportunity to engage deeply with PhD students in this field and understand the kind of opportunities available by pursuing a doctoral program," says Shanti Visurakapalli, a current undergraduate student at MIT. "I think this experience, complemented with the industry panel, gave many of us in the program the perspective we needed to weigh future graduate and professional options."

Throughout the week, participants connected classroom concepts with real-world applications through behind-the-scenes access to some of the nation's most advanced research and manufacturing environments. Students explored MIT's interdisciplinary laboratories, observed High-NA EUV lithography and quantum hardware development at IBM Research, toured GlobalFoundries' state-of-the-art 300mm semiconductor fabrication facility, learned how groundbreaking academic research transitions into commercial manufacturing at RPI, and gained insight into next-generation semiconductor fabrication at NY CREATES.

"The externship gave me a behind-the-scenes look at the advanced technologies driving the microelectronics industry while allowing me to connect one-on-one with researchers and industry professionals," says Sean Kim, a student at Princeton University. "Learning about emerging research and receiving career advice broadened my perspective on the field and inspired me to pursue a career in microelectronics."

Beyond the technical experiences, the externship emphasized professional development and networking. Students engaged in meaningful conversations with engineers, scientists, faculty members, and graduate researchers who described their career paths, offered advice, and discussed the many pathways available within the semiconductor industry. These interactions provided participants with valuable perspectives on careers in research, manufacturing, design, and emerging technologies.

"One of the most rewarding aspects of the externship is seeing students from different universities come together around a shared passion for innovation," says Preetha Kingsview, NMIP program administrator. "The friendships they build, the conversations they have with researchers and industry leaders, and the excitement they bring to every visit create an experience that extends far beyond the technical program."

For many students, the experience proved both transformative and inspiring. The opportunity to witness cutting-edge research firsthand while building connections with leaders across academia and industry deepened their understanding of the semiconductor ecosystem and reinforced the critical role microelectronics plays in addressing global challenges.

"For more than half a century, microelectronics has transformed the world, but I believe its most exciting chapter is only just beginning," says Tomás Palacios, the Clarence J. LeBel Professor of Electrical Engineering and Computer Science at MIT and faculty director of the NMIP Program. "From AI and quantum computing to sustainable energy and advanced manufacturing, nearly every technological revolution of the coming decades will be built on advances in semiconductor technology. Today's undergraduate students will become tomorrow's innovators, entrepreneurs, and industry leaders, and programs like the NMIP Externship help inspire and prepare them to shape that future."

By bringing together leading universities, research institutions, and industry partners, the program provides students with a comprehensive view of the semiconductor ecosystem while helping build the highly skilled workforce needed to sustain U.S. leadership in microelectronics.

The 2026 externship demonstrated the power of connecting education, research, and industry. Through a week of laboratory tours and technical presentations, it gave students a firsthand view of how scientific discovery becomes technological innovation — and inspired many to become part of the future of microelectronics themselves.

The NMIP Externship was made possible by the Microelectronics Commons Northeast Microelectronics Coalition Hub and the Microelectronics Commons Northeast Regional Defense Technology Hub (NordTech). Additional support was provided by the MIT Microsystems Technology Laboratories, the MIT Institute for Soldier Nanotechnologies, and the Semiconductor University Research Program for Superior Energy-Efficient Materials and Devices (SUPREME) Center, part of the SRC JUMP 2.0 program.

More on the OpenAI Agent’s Attack on Hugging Face

Schneier on Security - Mon, 08/03/2026 - 1:02pm

Hugging Face has published a detailed timeline of the attack. From the summary:

The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own...

EFF at BSidesLV, Black Hat, and DEF CON 👨‍💻

EFF: Updates - Mon, 08/03/2026 - 10:45am

It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.

EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don't hesitate to reach out to info@eff.org where our intake team is ready to assist! Share a brief summary of the issue, and we'll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our Coders' Rights Project page.

Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You'll probably spot us roaming the conference halls, but we'd love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we'll have our limited-edition DEF CON 34 t-shirt on hand. We're excited to see them—and other EFF gear—take over each conference!

EFF Staff Presentations Privacy's Defenders: How Hackers Helped and Can Do So Again

Hackers have a long history standing up for justice and that history has a lot to teach and inspire the hackers of today as we face a world with 360-degree surveillance that is increasingly marshaled against us by both companies and governments. My talk will tell background and stories from my book, Privacy's Defender, that tells the story of my 30 years working with EFF to try to protect security and privacy in the digital age. Cards on the table: I'm trying to recruit you to join in the fight.
WHERE: Florentine F | BSides Las Vegas
WHEN: Monday, August 3 @ 11:00
WHO: Cindy Cohn - Former EFF Executive Director 

Ask EFF at BSidesLV

Panelists from the EFF Staff will give brief updates on key topics in their expertise before turning it over to BSides attendees to ask their burning questions about policy, advocacy and making the future of tech brighter. It's a dynamic session fostering engaging discussions on digital rights featuring an EFF staff attorney, activist, and public interest technologist.
WHERE: Florentine F | BSides Las Vegas
WHEN: Tuesday, August 4 @ 14:00
WHO: EFF's Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley Pederson, and Cindy Cohn

What Election Security Researchers Need to Know about Section 1201 of the Digital Millennium Copyright Act

WHERE: Voting Village | DEF CON
WHEN: Friday, August 7, 10:30-11:00
WHO: EFF Staff Attorney Tori Noble

Privacy's Defender: How Hackers Protected the Internet Before and Can Do It Again

EFF's Outgoing Executive Director Cindy Cohn' presents her first-person stories from her recently published book, Privacy's Defender, that take you Inside the privacy battles that have shaped today's Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.
WHERE: Creator Stage 1 | DEF CON
WHEN: Friday, August 7, 15:00-16:30
WHO: Former EFF Executive Director, Cindy Cohn

Why Mandatory Age Verification Keeps Us All Less Safe

WHERE: Creator Stage 7 | DEF CON
WHEN: Saturday, August 8, 13:30-14:30
WHO: EFF Director of Engineering Alexis Hancock & EFF Social Media and Video Manager Kenyatta Thomas

ESP32 As A Counter-Surveillance Platform

Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative. This presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities. Applications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. We will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.
WHERE: Main Track 1 | DEF CON
WHEN: Sunday, August 9, 10:00-11:00
WHO: EFF Senior Staff Technologist Cooper Quintin

Tactical Advocacy: Panel & Peer Sessions with EFF

WHERE: Policy Village | DEF CON
WHEN: Sunday, August 9, 12:30-14:00
WHO: EFF's Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori Noble, Rory Mir & Cindy Cohn

EFF Contests at DEF CON 34 EFF Benefit Poker Tournament

We’re going all in on internet freedom. Take a break from hacking the Gibson to face off with your competition at the tables—and benefit EFF! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all. Join us on Friday, August 7 at 12:00 at theHorseshoe Poker Room. Play for glory. Play for money. Play for the future of the web.
WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109
WHEN: Friday, August 7, 12:00-15:00

Beard and Mustache Contest

Yes, it's exactly what it sounds like. Join EFF at the intersection of facial hair and hacker culture. Spectate, heckle, or compete in any of four categories: Full beard, Partial Beard, Moustache  Only, or Freestyle (anything goes so create your own facial apparatus!). Prizes! Donations to EFF! Beard oil!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Friday, August 7, 13:00-14:00

Tech Trivia Contest

Join us for some tech trivia on Saturday, August 8! EFF's privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture. The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear. Invite your friends OR show up and make new friends! Did someone say BRIBES? The world is unfair! You too could influence the judges to add a point or two to your team's tally. Overall Bribe winner also wins a custom badge!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Saturday, August 8, 17:00-20:00

Privacy's Defender Book Signing with Cindy Cohn

Grab a copy of former EFF Executive Director Cindy Cohn's new book, Privacy's Defender—and get it signed—while at DEF CON 34!
WHERE: Exhibit Hall West 4 (Book Signings)
WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00 

Join the Cause!

Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or donate to become an EFF member. We'll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you're not in Vegas!

Join EFF

Support Security & Digital Innovation

The OpenAI Hack Shows the Genie Is Out of the Bottle

Schneier on Security - Mon, 08/03/2026 - 6:47am

This essay originally appeared in Foreign Policy.

Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.

Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...

How a conspiracy-fueled campaign could turn Republicans against weather modification

ClimateWire News - Mon, 08/03/2026 - 6:30am
The GeoFight is pursuing litigation, donations and social media hype to "shape the conversation" around sunlight-reflecting technologies.

Houthi threat to Saudi energy hub could upend Trump’s midterm message

ClimateWire News - Mon, 08/03/2026 - 6:28am
The world's largest oil processing facility has emerged as the next flashpoint in the Iran conflict, with potentially immediate consequences for global energy markets and Republicans facing tough midterm races.

Xavier Becerra is wary of California’s climate goals. Trump could save them.

ClimateWire News - Mon, 08/03/2026 - 6:26am
The likely next governor has doubts about California’s aggressive climate policies, but federal attacks could force him to be their defender.

France’s forest management may need to change to prevent more fires

ClimateWire News - Mon, 08/03/2026 - 6:25am
Blazes loom as a growing danger for the timberland because Europe is the world’s fastest-warming continent.

Summers are putting Dutch dikes at risk, threatening German river trade

ClimateWire News - Mon, 08/03/2026 - 6:24am
The troubles are caused by a drought that is gripping Europe and has fueled raging wildfires and sent the Danube and Rhine rivers to record low levels.

A blanket of seaweed smothers coastlines from the Caribbean to Mexico

ClimateWire News - Mon, 08/03/2026 - 6:23am
Experts have said that agricultural runoff, warming waters and changes in wind, current and rain could be factors.

Turning molecules into reliable electronic devices

MIT Latest News - Mon, 08/03/2026 - 5:00am

Molecules are among the smallest building blocks available for making next-generation devices. Their unique, customizable properties enable promising applications in emerging computing, sensing, optical, and quantum technologies.

But integrating molecules into functional devices at scale remains a challenge. Traditional semiconductor manufacturing processes can damage small and fragile molecular materials. Now, MIT researchers have developed a scalable fabrication technique that incorporates delicate molecular materials into electronic devices on a chip without causing damage.

Their method extends the capabilities of standard semiconductor manufacturing processes to accommodate molecules. The researchers first prefabricate the device components using traditional processes. Then, they introduce the molecules and harness nanoscale surface forces to mechanically transform the fabricated device, which self-assembles without damaging the molecules. 

The team demonstrated the robustness and scalability of their technique by fabricating more than 1,000 devices using sub-nanometer molecular layers. 

“Our platform combines the scalability of conventional semiconductor manufacturing with the precision and control of self-assembly. This establishes a new fabrication framework for the scalable, high-throughput integration of emerging nanoscale and quantum materials, including molecules, into functional devices with architectures and capabilities that were previously infeasible,” says Farnaz Niroui, an associate professor of electrical engineering and computer science (EECS), a member of the Research Laboratory of Electronics (RLE), and senior author of a new paper describing the work.

She is joined on the paper by co-lead authors Sarah Spector and Peter Satterthwaite, EECS graduate students; Jeremiah A. Johnson, the A. Thomas Guertin Professor of Chemistry at MIT; and others at MIT. The research appears today in Nature Nanotechnology.

Building with molecules

Molecules are small clusters of atoms with structures and chemistries that can be precisely designed. This allows their properties to be engineered across a wide design space.

Once integrated into device architectures, these molecules could enable next-generation electronics and computing platforms that are smaller, faster, and more adaptable, as well as higher-performance photonic devices and emerging quantum technologies.

To build a functional system, molecular building blocks need to be integrated with other device layers. In electronic systems, a critical step is making electrical contacts to the molecules by interfacing them with metallic surfaces. However, the harsh chemicals and processes needed for traditional chip manufacturing damages these fragile molecular materials, reducing reliability and performance.

To leverage the scalability of standard fabrication techniques while achieving the precision needed for handling molecules, the MIT researchers developed a decoupled, two-step approach.

They first fabricate all the device components using standard semiconductor manufacturing, then incorporate the molecular material after-the-fact to finish building the device.

“By bringing the delicate materials into the process only after we have fabricated the main device elements, it allows us to use conventional processes that are normally not compatible with these nanomaterials,” Satterthwaite says.

In their demonstration, the researchers fabricated a scaffold with two metal electrodes separated by a precisely sized gap. Then, they deposited the molecular layer on the electrode surfaces. 

Finally, the researchers leverage nanoscale forces to gently pull the top electrode onto the molecules, forming the final device in a nondestructive way. This creates a self-aligned, damage-free electrical contact to the molecules. 

Using the forces

While gravity is a dominant physical force that holds our world together, different forces dominate at the nanoscale. One, called the capillary force, causes liquid to get sucked into small spaces. (Plants rely on capillary forces to draw water into their stems.) 

By carefully engineering the stiffness of the electrodes, when the solution containing the molecules evaporates, capillary forces gently pull the two metal surfaces together with the molecules sandwiched in between.

Once the two electrodes are in place, the researchers must hold them in a stable state. To do so, they rely on another nanoscale force known as the van der Waals force. 

Van der Waals forces cause surfaces to attract one another. By controlling the device surface area and molecules properties, the researchers ensure these forces will be strong enough to hold the electrodes in a stable structure without damaging the molecules. 

“Nanoscale forces play a critical role in our approach. Instead of fabricating exactly the structures we ultimately want, we make something mechanically mobile and use forces to transform it into an architecture that would otherwise be impossible to fabricate,” Spector explains.

They used this technique to fabricate more than 1,000 devices with molecular layers less than 1 nanometer thick. Even at this tiny scale, the fabricated chips comprised a high yield of working devices, 96 percent on average. The robust devices also endured tens of thousands of electrical cycles without showing any sign of degradation.

“The stability really stands out. This is a critical feature for moving molecular devices toward practical applications, but it has been a persistent challenge in the field,” Satterthwaite says. 

Importantly, this versatile technique allows circuit- and system-level integration of molecular devices, pushing the field beyond the study of isolated devices, the researchers say. They demonstrated this by building an interconnected array of molecular memory devices which could have applications in next-generation computing platforms. 

Their technique can also be extended to other materials and device architectures. 

In the future, the researchers want to build on this platform to investigate and develop new classes of multifunctional computing and sensing devices and systems. 

“By enabling the pristine integration of emerging molecular materials and other atomic-scale matter into functional devices at scale, our platform accelerates discovery and design of these materials with tailored functionalities and their deployment in emerging technologies,” Niroui adds.

This research was funded, in part, by the U.S. Defense Advanced Research Projects Agency (DARPA), the Semiconductor Research Corporation, the U.S. National Science Foundation (NSF), the MathWorks Fellowship, and the Netherlands Organization for Scientific Research. Device fabrication was carried out, in part, using MIT.nano facilities.

Using reason, again and again

MIT Latest News - Sun, 08/02/2026 - 12:00am

You probably think you are rational. Day to day, you try to “make the best possible use of the information available to you,” as MIT philosopher Brian Hedden PhD ’12 writes in his 2015 book, “Reasons without Persons.” 

If you think you are rational because of how you plan for the future, and change your beliefs over time, however, Hedden will be skeptical. Circumstances change, and when using reason, he thinks, all that matters is the present. Thus, he also writes: “The requirements of rationality should be impersonal, avoiding reference to the relation of personal identity over time.”

This is what Hedden calls “time-slice rationality,” the idea that in applying reason, we exist in little slivers of time and knowledge. There are not permanently reasonable people, just reasonable decisions. 

“We are temporally extended people with hopefully long lifespans, but we’re made up of lots of different time slices,” Hedden says. “So there’s me now, me yesterday, me next year. We should think of the locus of rationality as the time slice, not the temporally extended person.” 

Those past versions of you, Hedden thinks, are like teammates in sports: You are connected to them, but not quite the same person. The payoff from viewing things this way, he contends, is a more streamlined and realistic picture of our thinking. 

“Time-slice rationality” helped launch Hedden’s career. Today he is a professor in MIT’s Department of Linguistics and Philosophy and associate dean for MIT’s Social and Ethical Responsibilities of Computing (SERC) initiative. In a nod to his work, let’s examine some time slices from Hedden’s career.

Falling for philosophy

Hedden grew up in Virginia and attended Princeton University as an undergraduate, where he expected to study electrical engineering. But early on in college, he took some philosophy classes — an introductory course in logic, a history of early modern philosophy — and liked them. A lot. 

“Engineering is still near and dear to my heart, but I really got into philosophy,” Hedden says. 

Almost before he knew it, Hedden had found his primary intellectual interest. Upon graduating from Princeton, Hedden spent a year working for an education nonprofit in Nicaragua, but he had already decided on his next stop: graduate school in philosophy.

That led Hedden to MIT. He wanted to study the philosophy of language, and at MIT, the famous linguistics program is part of the same department as philosophy. Hedden applied to the Institute, was accepted, and arrived on campus eager to pursue his chosen field. 

Lounge life

A funny thing happened to Hedden after he arrived at MIT, however: He stopped studying the philosophy of language. Blame Frank Gehry, the architect. 

MIT’s Department of Linguistics and Philosophy is in the Stata Center, which opened in 2004 and was designed by Gehry to have all kinds of common spaces, including double-height lounges. After Hedden started graduate school at MIT, he got drawn into the philosophical discussions happening in these common areas. Before long, he had changed his intellectual focus. 

“This was largely due to conversations that were happening in the lounge,” Hedden recalls. “The Stata Center has spaces that really encourage collaboration. A lot of people there were talking about puzzles involving probability, epistemology, and decision theory, and I found those things really stimulating, and wound up specializing in those areas. Things wouldn’t be the same if the building were differently arranged.”

Advised by MIT professors Caspar Hare, Robert Stalnaker, and Roger White, Hedden wound up writing his doctoral thesis — three papers — on rationality and decision-making. That formed the basis of “Reasons without Persons,” whose title alludes to a famous work by philosopher Derek Parfit.

While it might seem unusual to draw to draw a distinction between our past, present, and future selves, Hedden thinks we actually do that frequently, in everyday life and cultural work. In Greek mythology, Odysseus rationally chains himself to the mast of his ship, anticipating that his future self will be irrationally unable to resist the call of the sirens.

“That’s a dramatic example, but we do this all the time, like when we buy a gym membership and hope that our future selves will irrationally care about sunk costs and go to the gym to avoid having wasted the money,” Hedden says. 

Heading down under

After earning his MIT PhD, Hedden spent two years as a junior research fellow at Oxford University, then landed his first faculty job in academia — at the University of Sydney, in Australia, in 2015. Five years later, he moved to Australian National University, in Canberra, leaving when he returned to MIT in 2025. 

“I love Australia; I think the quality of life is amazing, the culture is great, the natural world is unbelievable,” Hedden says. The country also has, he observes, “a great philosophy scene,” fed in part by decades of interaction with American scholars. 

Hedden’s work kept evolving during his decade in Australia. He started examining specific, applied topics more often, including many questions about legal processes and evidence. For instance: Should juries even deliberate? In one 2017 paper, Hedden suggested they should not, because, among other things, “deliberation destroys the independence of jurors’ judgments” in ways that can be counterproductive. 

Or: Is there such a thing as “higher-order” evidence, which is evidence about what conclusions your evidence supports? In a 2021 paper, Hedden and now-MIT colleague Kevin Dorst concluded that virtually all evidence fits this billing. 

Hindsight bias: Not bias

Or take another Hedden paper in this vein, from 2019, casting new light on the familiar topic of “hindsight bias.” We often alter our views about things after they happen, which can seem like gratuitous second-guessing. 

Is it, though? Suppose you are investigating a railroad crash and find evidence that a crash was more likely than people imagined. That might simply be useful new knowledge. Suppose your favorite basketball team loses a game, and you reexamine why you thought they would win; perhaps a star player’s injury was more serious than you imagined. Are you changing your basic views, or just conducting a realistic reassessment?

“This is perfectly rational and what we should expect,” Hedden says. “Some people say, ‘Oh, that’s hindsight bias.’ I think it’s just a reasonable conclusion to draw.”

To be sure, in the paper itself, Hedden engages with theoretical philosophical work about evidence and view formation; much of his work bridges academic theory and practical everyday applications. Like many of his papers, this one also evinces the fun of reworking conventional wisdom. 

“I do think that these contrarian views are right,” Hedden says. “But I also find a certain joy in going my own way, or having a skeptical take to get people to rethink views they’re falling into without fully realizing it.” 

After an odyssey, back at MIT

After nearly a decade in Australia, Hedden received an offer to return to one of his intellectual homes: MIT offered him a place on the faculty. Arriving back at the Institute in 2025, Hedden found many things had changed — new buildings on campus, new programs — while some were recognizably the same. 

“The philosophy department looks very similar in terms of the healthy culture,” Hedden says. “It’s always been known as a collaborative, high-energy place with a fantastic graduate program. And it’s really welcoming. That lounge discussion culture is still there. Sometimes cultures can be fragile. There could have been people who let it lapse. But it’s still there, and that’s great.”

Meanwhile, Hedden has added to his intellectual portfolio by becoming associate dean at SERC, a burgeoning initiative at MIT examining a wide range of civic issues around computing. SERC has supported 40 postdocs around MIT since 2022, in all five MIT schools plus the MIT Schwarzman College of Computing. It has also awarded 30 seed grants for faculty research in the last three years.

“There’s been really broad interest from faculty and students,” Hedden says. “I’m interacting a lot with computer scientists especially, but people across the Institute everywhere. The College of Computing is a unifying force.” 

For that matter, the SERC Scholars program had 75 students accepted last fall, from first-year undergraduates to doctoral candidates, working on projects including surveillance, artificial intelligence, the energy impact of the sector, and more. Hedden is also making a point to develop more courses across SERC topics.

“It’s often the younger people, undergraduates and graduate students, the postdocs, the junior faculty, that gives us a constant infusion of new ideas and energy,” Hedden says. “We’re hoping to keep the momentum going.”

In this slice of time, that sounds pretty reasonable. 

Friday Squid Blogging: Squid Helps Discover New Marine Species

Schneier on Security - Fri, 07/31/2026 - 5:06pm

The Squid is a new scientific machine:

One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.

The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid...

Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy

EFF: Updates - Fri, 07/31/2026 - 3:47pm

California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.

Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.

Take Action: Tell Your Senator to OPPOSE A.B. 1709

A "Compromise" That Still Denies Access

Under the newly amended Section 22683, platforms are prohibited from offering "addictive features" to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls "addictive feeds," auto-play, and anything else the Attorney General designates in future rulemaking.

However, the bill defines "addictive feeds" so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended "in whole or in part, on information provided by the user." That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive," the bill also makes broad conclusions about the unsettled science behind social media use, youth, and addiction.

Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.

Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional right to access information and participate in public discourse.

AB 1709 Still Forces Invasive Age Verification

The amendments do not eliminate the privacy threats posed by age gating. Although the bill references the age-signaling framework in AB 1043, Section 22684 explicitly states that a covered platform "shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check. 

Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive honeypots of sensitive personal data, destroying online anonymity and exposing users of all ages to security breaches. And relying on biometric systems to verify users’ ages is problematic because the systems have historically had high error rates estimating ages across race and gender lines.

Take Action: Tell Your Senator to OPPOSE A.B. 1709

Lawmakers Must Reject AB 1709

The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like SB 976. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.

Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.

We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.

The SCREEN Act Threatens Privacy Far Beyond Adult Websites

EFF: Updates - Fri, 07/31/2026 - 3:41pm

The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.  

Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.

The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. 

The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. 

Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information. 

In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.

The SCREEN Act Attacks Your Right To Use VPNs

The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking. 

VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server's IP address, not your actual location. It's like sending a letter through a P.O. box so the recipient doesn't know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.

The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users. 

The CHATBOT Act Forces One Parenting Model On Every Family

EFF: Updates - Fri, 07/31/2026 - 3:06pm

Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems. 

The Bill Requires AI Companies To Build Family Monitoring Systems 

Parents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life. 

The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system. 

As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls. 

This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI. 

The CHATBOT Act Creates New Privacy Risks For Families 

Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages. 

And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures. 

The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks. 

Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system. 

The CHATBOT Act Applies A Children’s Law To Teenagers 

The CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers. 

That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.  

In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users. 

But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires. 

The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student. 

Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system—the bill’s only option is to create a family account.

Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant. 

The CHATBOT Act Will Pressure AI Companies To Check Users’ Ages 

The bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18. 

Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification.  Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes. 

Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law. 

A Better Way Forward

Congress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families. 

Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now. 

Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues. 

Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.

Pages