Feed aggregator

AI Agents Are Now Emailing Me with Their Security Concerns

Schneier on Security - Wed, 09/02/2026 - 2:28pm

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.)

Dear Bruce Schneier,

I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...

Texas and Florida Step Back from ALPRs

EFF: Updates - Wed, 09/02/2026 - 1:31pm

Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After years of successful grassroots battles to pull these cameras from local streets, bipartisan momentum is sweeping the country.

On August 28, Texas Governor Greg Abbott banned state agencies from spending public funds on Flock cameras. The order dropped just as The Texas Tribune prepared to publish an investigation revealing that a state agency had quietly funneled at least $30 million into building a sprawling surveillance network. 

Then on August 31, the Florida Department of Transportation (FDOT) issued a memo, announced by Governor Ron DeSantis, ordering the removal of all ALPRs from the right-of-way on state highways within 30 days. The order revokes all previously approved permits to install ALPRs, and bars transportation officials from issuing future permits. 

FDOT officials stated that “the recent exponential increase in deployments along our roadways, coupled with concerning reports of misuse, data privacy concerns, and surveillance schemes merit immediate action to preserve Floridians’ sovereignty and quality of life.” FDOT’s action has been followed by a surge of local governments in Florida canceling or pausing their vendor contracts.

Much more work remains. Many ALPRs in Florida are not on state highways, but sit on city streets, county roads, residential driveways, and shopping center parking lots—and FDOT's order doesn't touch any of them. Likewise, the Texas directive leaves local agencies free to use city, county, federal, and private funds to install cameras.

This week’s good news follows years of pushback from local advocates that has seen dozens of cities sever ties with surveillance companies. According to some metrics, during the last 30 days, an average of three localities per day has halted contracts with Flock. Other advocates have been resisting ALPRs in statehouses and court houses, and by blowing the whistle with investigative activism.

The moves in Florida and Texas also illustrate the power that the executive branch can wield to curtail mass surveillance with almost immediate results. We hope that the California Governor Gavin Newsom and the California Department of Transportation will take notice and initiate steps to curb this technology, starting with removing the ALPRs that U.S. Border Patrol and the Drug Enforcement Administration have installed on California highways.

EFF’s position remains: ALPR mass surveillance – the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion – should not exist. This past week’s actions in Texas and Florida are good steps forward, but we are still far from the finish line. We will continue working alongside community groups to keep cameras off local streets, while urging judges and state lawmakers to impose enforceable restraints on this warrantless mass surveillance.

System helps humans predict when self-driving cars will make mistakes

MIT Latest News - Wed, 09/02/2026 - 11:00am

Self-driving cars are often controlled by deep learning models that sometimes fail in unexpected situations. For instance, the car might inexplicably brake and block the path of an oncoming emergency vehicle. A human driver or passenger may need to react rapidly to prevent a collision.

To help humans better anticipate a vehicle’s mistakes, researchers from MIT and autonomous vehicle technology company Motional developed a new method that provides clear explanations of the underlying model’s decisions.

Usually, the internal reasoning process of a deep learning model is opaque and difficult to understand. But the new method, called the Concept-Wrapper Network (CW-Net), translates that reasoning process into concepts that faithfully describe the autonomous vehicle’s decisions without altering its driving performance.

CW-Net explains the decisions of machine learning-based planners using understandable concepts, like “approaching stopped vehicle” or “close to cyclist.” These explanations can correct misconceptions drivers and passengers have about vehicle behavior and improve their situational awareness.

In road tests on a private track, CW-Net explanations helped safety drivers more accurately predict vehicle behavior; a larger simulation study with nonexpert users yielded similar results. These experiments show how CW-Net can provide important feedback for engineers as they troubleshoot in-vehicle artificial intelligence systems. In the longer term, this technique could boost the safety and transparency of autonomous vehicles, while building appropriate trust in drivers and passengers.

“This work shows how explanations are supportive to the human’s mental model and understanding of the behavior of a system, and how it could be used in engineering and development to improve the technology,” says Julie Shah, an MIT professor of aeronautics and astronautics, director of the Interactive Robotics Group in the Computer Science and Artificial Intelligence Laboratory (CSAIL), and co-senior author of the paper on CW-Net. “Unless we are building these technologies in a way that we can rely on and predict their behavior, then it is a shaky and unsafe foundation for their use.”

She is joined on the paper by lead author Eoin Kenny, a former MIT postdoc who is now a senior AI researcher at J.P. Morgan Chase; co-senior author Momchil Tomov, a staff research scientist at Motional; as well as Motional team members Akshay Dharmavaram, Sang Uk Lee, Tung Phan-Minh, Shreyas Rajesh, Yunqing Hu, and Laura Major, president and CEO of Motional. The research appears today in Nature.

Faithful explanations

Machine-learning-based planners act as the “brain” of a self-driving car. These powerful deep-learning architectures process data from the vehicle’s cameras and lidar sensors, generate a high-level summary of the vehicle’s environment, decide what the car should do next, and output a trajectory for it to follow.

The planners are usually black-box models, which means their internal decision-making process is so complex it is difficult to understand. This can leave scientists and safety drivers in the dark about why an autonomous vehicle made an unexpected decision, like phantom braking.

The researchers designed CW-Net to explain a vehicle’s decisions using understandable concepts, while ensuring those explanations accurately reflect the true reasons behind its behavior. 

“Especially in high-stakes settings like self-driving cars, it’s important that the explanations are not potentially misleading. Because CW-Net is causally faithful in how it makes decisions, that provides certain guarantees around the explanations,” Kenny says.

CW-Net is a “concept classifier,” an AI algorithm that has been trained to predict the high-level concepts that exist within input data. The researchers plug the CW-Net module into the middle of an autonomous vehicle’s existing machine-learning planner architecture.

It translates the model’s internal reasoning process into understandable concepts, like “approaching stopped vehicle” or “close to cyclist.” Then it forces the final piece of the planning model architecture to use those concepts when it decides what the vehicle should do next. In this way, CW-Net ensures the concepts faithfully explain the vehicle’s actions. 

At the same time, CW-Net uses the concepts it classified to generate clear explanations that are output along with the vehicle trajectory, in real-time.

“Instead of just wondering why the car stopped, having real-time data provides feedback that lets you test the system during deployment. You could also give that data to an engineer to potentially improve the system,” Kenny says. 

The researchers trained CW-Net to predict concepts using a dataset of 130 million examples of scenes from self-driving cars, with multiple labeled concepts in each scene. Using such a large, labeled dataset enables it to identify concepts accurately in a wide range of settings.

They also designed CW-Net to mimic the driving decisions of machine-learning-based planners, so the module would not negatively impact vehicle performance.

In the end, CW-Net generates accurate, understandable explanations without altering the original deep learning model.

Improving situational awareness

To test CW-Net, the researchers deployed the module on a real autonomous driving test vehicle (a Motional robotaxi) on a private track with a safety driver. They found that CW-Net helped the safety driver better predict how the vehicle would behave in surprising situations.

For instance, the vehicle consistently stopped when it approached a cyclist, and the safety driver assumed it did so because it detected that cyclist. But CW-Net explanations revealed that the model wasn’t properly configured to detect the cyclist and chose a trajectory that would have caused a collision. Instead, it stopped because its emergency braking procedure kicked in when it got too close.

Armed with this information about the model’s mistake, the safety driver could reduce speed or engage manual driving mode sooner in similar situations. This could also help engineers fix the model to avoid this failure in the future.

In larger online simulation studies using real driving situations captured on the roads of Las Vegas, the researchers saw similar results. CW-Net explanations significantly improved participants’ abilities to predict how an autonomous vehicle will behave.

In the future, the researchers could extend CW-Net so the module can cover more concepts and explore different training and design techniques that could boost performance and improve interpretability.

“Our study shows how crucial interpretability can be to these high-stakes environments, and how it should be on the mind of people as they are making AI in the future, for self-driving cars or other safety-critical environments,” Kenny says.

New research shows a neutrino laser is impossible

MIT Latest News - Wed, 09/02/2026 - 10:00am

Neutrinos are the pervasive yet intangible particles that permeate the universe, streaming through whole planets, stars, and our bodies by the trillions each second. The elementary particles are often described as “ghostly” for their near-zero mass and their elusive nature, as they have very little interaction with normal matter. 

Since their discovery in 1956, neutrinos have continued to surprise physicists with their unexpected properties and behaviors. For instance, the particles come in multiple “flavors” and can morph from one to the other like subatomic shape-shifters. Neutrinos may also be their own anti-particle, in a Jekyll-and-Hyde-like quantum duality. And their extremely weak interactions make them nearly impossible to detect.  

Last year, scientists seemed to add to the particle’s mystique, with a concept for a neutrino laser. They proposed that a concentrated beam of neutrinos could be produced by cooling a cloud of radioactive atoms to nanokelvin temperatures, one-billionth the temperature of interstellar space. Slowed to a near-frozen crawl, the atoms would form a Bose-Einstein condensate and should act as one quantum, coherent whole, in a way that speeds up and amplifies their radioactive decay. The physicists assumed that neutrinos, being a natural byproduct of radioactive decay, should also be amplified, and that such a process should emit a laser-like beam of the ghostly particles. 

But work by MIT physicists has now shown that the neutrino laser concept, and a similar proposal for gamma-rays, is impossible. In two companion papers appearing today in Physical Review Letters, Wolfgang Ketterle, the John D. MacArthur Professor of Physics at MIT, together with postdocs Hanzhen Lin and Yu-Kun Lu, presents a two-part analysis that demonstrates both concepts are physically and fundamentally not possible. More specifically, they have shown that the neutrino laser concept is flawed, due to “recoil” (as in, the kinetic energy created by the reaction), and due to a neutrino’s fundamental “fermionic” nature. 

“These two papers are sort of punch one and punch two,” Ketterle says. “Each paper would have killed the proposal.”

MIT professor of physics Joe Formaggio, who put forth the neutrino laser proposal with Ben Jones, who at the time was associate professor of physics at the University of Texas at Arlington, sees the new results as a convincing and constructive challenge. 

“When a new idea — such as the one we proposed — is shared, it is the duty of the community to scrutinize it. Such is the scientific process,” Formaggio says. “Indeed, it was great to see how our paper generated a lot of thinking outside of our original concept. We suspect that will continue.”

A quantum amplifier

The proposal for a neutrino laser was based on the idea of “superradiance” — a quantum, amplifying effect that had only been observed for photons. 

One form of superradiance occurs when a cloud of atoms is cooled to near absolute zero, at which point an atom’s motion is determined not by thermal effects, but purely by quantum uncertainty. In this state of near standstill, which is known as a “Bose-Einstein condensate,” (BEC) the atoms move in sync, as a quantumly correlated whole. 

If photons are pumped into the condensate as a laser beam, the atoms synchronize to scatter the photons back out, in the exact same direction. In contrast, a cloud of atoms at room temperature would simply scatter the photons in random directions, generating, at best, a soft glow. As photons scatter off atoms, the atoms should in turn “recoil,” as if they were physically pushed backward from the impact. In a BEC, because the atoms recoil in sync, the rate at which they scatter photons, in the same direction, grows exponentially. This amplifying effect results in a “superradiant” laser of photons, which scientists have observed. 

In their proposal, Formaggio and Jones, who is now at the University of Manchester, suggested that the same superradiant effect could be possible for radioactive atoms, which naturally emit neutrinos as they decay. If a cloud of radioactive atoms were cooled to form a Bose-Einstein condensate, a similar amplifying effect should kick in and generate a concentrated beam of neutrinos as the atoms decay in sync. To illustrate their point, they outlined a scenario in which a cloud of radioactive rubidium atoms, once cooled into a BEC, would accelerate its radioactive decay, from a half-life of 86 days, to one minute.

No one has ever produced a BEC from radioactive atoms. But if it could be done, then the quantum state should, in theory, produce a neutrino laser. 

Instant recoil

For Ketterle, the idea seemed too good to be true. Ketterle is the leading expert on Bose-Einstein condensates, which he co-discovered in 1995, and for which he shared the Nobel Prize in Physics in 2001. He and his group at MIT have revealed many surprising properties in Bose-Einstein condensates and other ultracold matter, where the energy of atoms is at their lowest.

“My experience has always been that the condensate can do marvelous things at low energy — superfluidity, vortices — and if you were to speak in a room filled with condensate, it would take one hour for you to hear my voice. That’s how slow the condensate is,” Ketterle says. “And I had always come to the conclusion that for anything violent, like nuclear reactions, the condensate would not do anything.”

Compared to visible photons, which have an energy of 1 electron volt, neutrinos are naturally emitted as atoms decay, with a million times more energy. When a neutrino blasts out from an atom, the emission should cause the atom in turn to recoil a million times more strongly than for visible photons. 

“As long as the recoil atom stays in the condensate, it can make the condensate superradiant,” Ketterle says. “But when a neutrino is emitted at a million electronvolts, the atom recoils at velocities equivalent to Mach 10, faster than a fighter jet. This is so fast that the atom would almost instantly disappear.”

Even so, the neutrino laser proposal assumed that the escaped atom should leave a sort of quantum imprint in the condensate, which tells the condensate as a whole to emit future neutrinos in the same exact, laser-like direction.

But in the first of two new papers, Ketterle and his team show through a theoretical analysis that this is not the case. They considered a model that describes superradiance. This model determines the conditions that would lead to superradiance of photons. Ketterle applied the model to the case of radioactive atoms and neutrinos, taking into account the range of energies at which the particles are emitted, as well as the resulting recoil of the decaying atom and the dynamics of the condensate throughout. 

These calculations showed that, in every scenario the team considered, superradiance was not possible. The atom simply recoiled too fast for any quantum imprint to build up. It was as if the condensate instantly loses the “memory” of the neutrino emitted, and therefore would continue emitting neutrinos as atoms normally would, without enhancement.

An anti-memory

In their second paper, the MIT researchers showed that in addition to being impossible due to a physical recoil effect, the concept of a neutrino laser is flawed due to the fundamental nature of neutrinos. 

They found that even if a recoiling atom were to leave a quantum imprint in the condensate, the imprint would not be of what to emit next, but rather, what not to emit. In other words, the memory of the emitted neutrino would tell the condensate to emit the next neutrino in any other direction, preventing the buildup of a directional neutrino beam. The researchers showed that this opposing memory, or “anti-correlation,” is due to the fact that a neutrino is, fundamentally, a fermion. 

Fermions and bosons are the two fundamental classes of particles that make up all the matter in the universe. Bosons are particles with whole-integer spins, such as photons. In contrast, fermions, such as electrons and neutrinos, have half-integer spins. Whether a particle has a whole or half integer spin determines how it interacts at a quantum level with other particles. 

“In superradiance, it is about a memory effect, or quantum correlations in the condensate. And in that context, people had thought that whatever is emitted from the condensate, it doesn’t matter if it is a boson or a fermion,” Ketterle explains. “But we analyzed it, and if you describe it correctly for emitted fermions, you get an anti-memory, which makes the condensate not accelerate in a superradiant form. It rather has the memory to not do it.”

Ketterle, Formaggio, and Jones have met on numerous occasions to talk through the original neutrino laser proposal, and Ketterle’s challenge to it.

“I suspect that someday, someone will do the experiment,” Formaggio says. “Nature, as always, is the final arbiter of such things. And here I would be remiss to not point out that every prior prediction about neutrinos has been wrong. The one thing about neutrinos that never surprises physicists is that they never fail to surprise.”

In part, Ketterle agrees: 

“Creative ideas and discussions among scientists are needed to uncover nature’s surprises,” he says. “But in the case of neutrino lasers, the surprise was too good to be true.”

This research is supported, in part, by the National Science Foundation, the Center for Ultracold Atoms, the Vannevar-Bush Faculty Fellowship, the Gordon and Betty Moore Foundation, and the U.S. Army Research Office.

Wireless Routers as Motion Detectors

Schneier on Security - Wed, 09/02/2026 - 6:22am

Comcast has added motion detection as a feature to its wireless routers:

The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity.

Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance...

Power asymmetries in adaptation

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02745-3

Power asymmetries in adaptation

Policy returns

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02746-2

Policy returns

Record-breaking wildfires in Canada

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02744-4

Record-breaking wildfires in Canada

Infrastructure links amplify impacts

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02747-1

Infrastructure links amplify impacts

Restoring reefs with heat-tolerant corals

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02721-x

As the Great Barrier Reef reels from successive devastating bleaching events, researchers are working to regenerate small areas with corals selected or manipulated for better heat tolerance.

Responding to ecological novelty

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02742-6

Climate change is shifting the world into new ecological states, prompting discussions of how humans and species will deal with this novelty, including how mitigation and adaptation will ultimately lead to further change.

Declines in European bumblebee habitat suitability attributable to climate change

Nature Climate Change - Wed, 09/02/2026 - 12:00am

Nature Climate Change, Published online: 02 September 2026; doi:10.1038/s41558-026-02734-6

The authors consider factual and counterfactual scenarios to isolate the role of climate change in the decline of suitable habitats for European bumblebees (1901–2019). They show reductions of 5% on average, and up to 19% locally, with high-altitude gains partially offsetting losses.

Judge Rules DOD Unlawfully Retaliated Against Anthropic

EFF: Updates - Tue, 09/01/2026 - 9:13pm

A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, intended to penalize Anthropic for telling the U.S. military it would not allow their technology to be used for mass surveillance of U.S. persons, “constituted unlawful retaliation in violation of the First Amendment.” EFF joined a coalition of organizations in filing multiple amicus briefs (here, here) arguing that the Pentagon had trampled on Anthropics First Amendment rights. We agree with the court’s decision and applaud the judge for slapping down such an obvious act of illegal and unconstitutional retribution by the Pentagon—even as the court left open the broader question of whether a company’s choices about how its technology may be used are protected speech in their own right. 

From the start of this conflict, EFF argued that companies should not be penalized for not wanting to conduct mass surveillance of US persons. Nor do we want to live in a legal system where our susceptibility to surveillance is hashed out and decided in closed-door contract negotiations between a few powerful people at the military and an AI company. Unfortunately, this ruling does little to address the bigger problem: that Congress has abdicated its responsibility to adopt statutory safeguards to protect our privacy, and instead left us reliant on the whims of private companies to decide when they are and are not willing to help the government conduct mass surveillance. 

In February 2026, the government began threatening to penalize Anthropic unless it backed off its position that it did not want the U.S. military using its AI product Claude for mass surveillance of Americans or to power autonomous weapons systems. Ultimately, the Department of Defense, deciding that it did not want military contractors dictating what its products could or could not be used for, declared the company a “supply chain risk.” This national security designation means the government and companies that do business with it cannot use the company’s products for government projects. It was, in essence, an attempted blacklisting of Anthropic for setting boundaries and articulating unacceptable use cases for its products. 

None of this is to say that Anthropic is a morally unimpeachable company, or that it and other companies would never permit their products to be used under specific conditions to aid in surveillance or analysis of collected data that could affect U.S. persons—but the facts remain: the government cannot punish a company for having preferences regarding unconstitutional uses of its technology. 

Unsupported claims that a company poses a national security risk should never be an excuse for government retaliation. This ruling correctly recognizes the dangerous implications of allowing the government to punish a company for its critical speech and for refusing to allow its technology to be used for mass surveillance. While we applaud the court's decision, we continue to urge lawmakers to take the protection of our privacy seriously. We shouldn't have to rely on private companies to protect us from the surveillance state. It's past time for Congress to act.

Walter Torous named executive director of MIT Center for Real Estate

MIT Latest News - Tue, 09/01/2026 - 5:25pm

Walter Torous, senior lecturer in the MIT Department of Urban Studies and Planning (DUSP) and the MIT Sloan School of Management, and director of the Master of Science in Real Estate Development Program (MSRED), was recently named executive director of the MIT Center for Real Estate (CRE) — effective July 1, 2026.

In announcing Torous’ appointment, School of Architecture and Planning Dean Hashim Sarkis also said that Justin Steil, professor of law and urban planning, will represent CRE as faculty chair of the Academic Curriculum Council.

“Together, Walter and Justin will guide CRE’s academic and strategic direction as it continues to strengthen its role within our school and the Institute,” Sarkis said. “Their appointments reflect the center’s distinctive position at the intersection of finance, design, planning, technology, and public policy — and its long-standing commitment to understanding real estate not only as a market force, but also as a driver of urban transformation and social change.”

As executive director, Torous will lead the CRE’s teaching, consortium activities, fundraising, and major events, while continuing to direct the MSRED program. He will also oversee the center’s staff, budget, and strategic direction, and work closely with Steil on the continuing evolution of CRE’s academic programs and industry engagement.

His appointment as executive director follows the tenure of STL Champion Professor Siqi Zheng, who served as CRE faculty director from July 2020 to June 2026.

Before coming to MIT in 2013, Torous was a professor at the Anderson School of Management at the University of California at Los Angeles and founding director of its Ziman Center for Real Estate. In addition to those positions, he also has held faculty appointments at the University of Michigan and the London Business School.

“Since joining MIT, Walter has played an important role in the growth and development of the MSRED program, educating generations of students in real estate finance and mortgage securitization,” Sarkis says. 

“Real estate, both commercial and residential, is undergoing a tremendous change in the U.S., as well as in Europe and Asia,” Torous says. “Demographic changes, as an aging population stays longer in their homes, are creating an imbalance in residential real estate markets. New technologies and work from home are buffeting commercial real estate. Retail is changing.  We’re in a period of turmoil, and I view the center’s role as being primarily to educate the next generation of leaders, especially in technology and financial markets, which are becoming ever more important to the functioning of real estate assets and markets. That requires that we train our students to be very facile with technology, so that they’re not affected by the ebbs and flows of changes, can maintain a strong career trajectory, and be stewards of the real estate industry going forward.” 

For this reason, he would like to see the MSRED curriculum expand beyond DUSP to add more content from architecture, civil and environmental engineering, the Media Lab, MIT Sloan, and other areas of the Institute. 

Torous also wants to more fully engage the 1,200-plus alumni from the center’s 43 years educating graduate students.

“A lot of our alums have assumed important positions in the real estate industry around the world,” he says. “In terms of training the next generation of real estate leaders, there’s a lot that we can learn from the industry leaders we’ve already produced.”

An economist and expert in the financial aspects of real estate known for his empirical studies of derivatives, options, mortgages, and other debt instruments, Torous’ research interests include the reorganization of financially distressed firms and statistical issues in finance.

His recent research has focused on better understanding why homeowners default on their mortgages. He is also interested in the application of machine learning to investigate how the dynamics of the U.S. commercial office market changed with the Covid-19 pandemic, and the lessons developers can learn about the new office market landscape. This research reflects the growing importance of AI and large language models to every aspect of real estate decision-making. Because of this, the MSRED curriculum now includes a class on AI and real estate, and Torous and Steil plan to add other, similar offerings.

“It’s important going forward that we focus on all aspects of real estate,” he says. “I look forward to working with Justin to create a curriculum that goes across the Institute and that will prepare CRE students to be leaders in the field.”

Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users

EFF: Updates - Tue, 09/01/2026 - 4:51pm

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.

How accurate does the age assurance process need to be?

The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

The Settlement generally shows little concern for those falsely placed in its Teen User category.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information ... where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:

exhibit_g_meta.jpg

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.

Again, these would be useful user controls that should be offered to users of all ages.

By default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques. 

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity, Meta blocks teens from “real world art of visible genitalia ... where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous women, breast cancer awareness posts, and posts about testicular and breast self-exams, educational posts about ovulation. And it has disproportionately applied the standard to gay and lesbian content in as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] 

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States — Establishing Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance. 

Cognition and consciousness arise from analog computations, says new theory

MIT Latest News - Tue, 09/01/2026 - 4:35pm

A new theory, published in The Journal of Neuroscience by three scientists in The Picower Institute for Learning and Memory at MIT, offers an explanation of how the brain produces cognition and consciousness: It uses traveling waves of rhythmic neural activity to coordinate nimble neural networks with analog computations. 

The metaphor that the brain operates with “circuits” is incomplete, says Picower Professor Earl K. Miller, the paper’s senior author. Indubitably, the brain’s physically connected circuits provide the infrastructure to store our memories and represent our ongoing needs and goals. But when we need to make improvised use of that knowledge in the rapid-fire, anything-goes sensory context the world constantly throws our way, we can’t just depend on the relatively slow chemical process of rewiring those circuit connections called “synapses,” he says. 

Instead, the brain needs a control system that can coordinate millions of neurons to process information in a fraction of a second. Brain waves, long understood to be the synchronized rhythmic fluctuations of large groups of neurons, turn out to be performing that crucial service, Miller and his colleagues argue, citing years of experimental evidence from his lab and many others.

“Circuits and synapses are important and fundamental, that’s the start. But there is more going on,” says Miller, a member of MIT’s Department of Brain and Cognitive Sciences faculty. “The brain generates waves, and wave dynamics are a highly efficient way to coordinate and perform computation.”

While digital circuits make calculations one step at a time through sequential switches and gates, analog computation, which can be performed via the interference of waves, processes multiple calculations in parallel. That’s not only more efficient, but also locally focused traveling waves happen to be a ubiquitous feature of the brain, the scientists note.

“The brain exploits its own physics,” wrote Miller and co-authors Scott L. Brincat and Jefferson E. Roy, who are research scientists in Miller’s lab.

The new theory is important not only because it provides an explanation of cognition and consciousness, but also because it asserts the potential importance of considering waves in clinical treatment. Conveniently, waves can be manipulated non-invasively.

“Developing treatments based on brain wave dynamics is not just an opportunity, but also an obligation,” says Miller, whose lab is part of a collaboration studying brain waves in autism.

Building the analog argument

To make the case that the brain uses waves to coordinate neurons to produce cognition and consciousness, the scientists begin with the now well-established observation that many neurons don’t just do one job. Instead, they respond to multiple cues and contexts, essentially participating in multiple functional networks at once, a property called “mixed selectivity.” Miller and colleagues have argued for years that this gives the brain immense computational horsepower, but it also initially raised the question of how the brain organizes these multiple overlapping networks with such speed and flexibility to produce the nimble thought we all depend on.

After numerous studies, the answer that has emerged for Miller and many other neuroscientists is that brain waves organize neural ensembles to process information. Miller has shown that brain waves of different frequencies govern cognitive processes such as working memory and predictive coding. Relatively slow “alpha” and “beta” frequency waves, representing memories and goals, regulate faster frequency “gamma” waves, which represent and report incoming sensory information.

The new theory posits that these alpha/beta control waves emerge from the coordinated spiking of neurons in circuits (connected at junctions called “synapses”) that encode stored memories and goals. 

“Synapses store representations, while wave dynamics help determine which representations are active at any given time,” the authors wrote.

In some of the Miller lab’s newer research, the team has found evidence that even as waves emerge from neural spiking, the waves can rapidly grow to directly influence and coordinate spiking via an electric field-mediated process called ephaptic coupling. Importantly, electric fields can exert this coordinating influence very rapidly.

Another essential component of the theory, which Miller’s lab has also shown experimentally, is that alpha/beta waves are capable of exerting their control spatially, by affecting local areas of the cortex, and temporally, by traveling along the cortex. Essentially, the beta waves act as mobile stencils that govern where and when gamma waves can process sensory information and which ensembles of neurons will participate. Taken together, this suggests that the brain engages in “spatiotemporal computing,” the authors write. And where the waves intersect, they can add and subtract, enabling analog computations.

Miller acknowledges that his lab’s next step should be to provide direct evidence that the analog computations are taking place.

“This is a theory. We aim to test it by looking for signatures of analog computation in brain wave patterns,” Miller says. 

Connection to consciousness

The article asserts that consciousness “emerges when these dynamic wave patterns bring the cortex in an organized, globally integrated state, one that naturally links and influences widespread activity.”

Some of the most compelling evidence linking wave dynamics to consciousness comes from studies of general anesthesia that Miller has conducted with Picower Institute colleague Emery N. Brown, who is an Institute professor at MIT, an anesthesiologist at Massachusetts General Hospital, and a professor in Harvard Medical School. Their labs have shown that three different drugs, each with different molecular mechanisms of action, all similarly disrupt brain wave dynamics to produce unconsciousness.

“Consciousness depends less on specific receptors or cell types and more on the integrity of large-scale wave organization,” the authors write in the review.

In other words, much like cognition, consciousness depends on how the brain efficiently organizes itself with brain waves.

“Electric field dynamics offer a low-overhead substrate for organizing and coordinating information across cortical networks,” they conclude. “Given strong evolutionary pressure to maximize computation per unit energy, it would be surprising if evolution did not exploit such a built-in analog computing substrate.”

The Freedom Together Foundation, The Picower Institute for Learning and Memory, the U.S. Army Research Office, the U.S. Office of Naval Research, a MURI grant, the National Institutes of Health, and the Simons Center for the Social Brain supported the research.

What’s the Scam?

Schneier on Security - Tue, 09/01/2026 - 1:36pm

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.

Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:

Thank you for the positive impact your emails have had on my life.
Your emails are a game-changer.
Your emails are a constant reminder of why I subscribed.
Your emails rock.
Thank you for the time and effort you put into creating these informative emails...

Leaked Russian Cyber-Operations Training Materials

Schneier on Security - Tue, 09/01/2026 - 12:29pm

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement...

Atlas of the brain’s striatum could guide researchers to new drug treatments

MIT Latest News - Tue, 09/01/2026 - 11:00am

A region of the brain called the striatum is critical for many cognitive and motor functions, including decision-making, control of movement, habit formation, and processing of reward. It also plays a role in addiction and is significantly affected by Huntington’s disease, schizophrenia, and other disorders.

In work that could help scientists devise new treatments for those diseases, MIT researchers have generated a new atlas of the neurons found within the striatum. Using single-cell RNA sequencing and other techniques, they were able to identify 31 subgroups of neurons based on which genes they express.

These groups include neurons that are involved in addiction, depression, and schizophrenia. The researchers also discovered why some neurons of the striatum are more vulnerable to Huntington’s disease. All of these results, the researchers say, could help scientists develop new drugs to combat these conditions.

“We see this as the foundation that will allow more studies in our Huntington’s disease and opioid use disorder projects. We needed a roadmap of what is there,” says Myriam Heiman, the Picower Professor of Neuroscience and director of MIT’s Picower Institute for Learning and Memory.

Heiman; Manolis Kellis, a professor of computer science in MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) and a member of the Broad Institute of MIT and Harvard; and Dana Gabuzda, a principal investigator at Dana-Farber Cancer Institute and a professor of neurology at Brigham and Women’s Hospital and Harvard Medical School, are the senior authors of the study, which appears today in Cell. MIT postdoc Raleigh Linville and MIT graduate student Benjamin James are the paper’s lead authors.

Mapping the striatum

The striatum, located deep within the brain, receives diverse inputs from the cortex, midbrain, hippocampus, and other regions, which it uses to coordinate planning, movement, and decision-making, as well as processing reward. In this study, the researchers focused on the most populous cell type in the striatum, a type of inhibitory neuron called the medium spiny neuron, which responds to dopamine.

Most of these medium spiny neurons belong to either the direct pathway, which helps to promote movement, or the indirect pathway, which suppresses unwanted movements. These pathways are distinguishable by what type of dopamine receptor they express — dopamine receptor 1 (D1) or dopamine receptor 2 (D2).

Beyond these two divisions, scientists knew that there were many subpopulations performing different roles, especially in the anatomically ventral (lower) regions of the striatum. However, it has been difficult to generate a consensus on how to classify these cells, in part because prior studies focused on specific subregions, meaning that overarching principles of striatal cellular organization were lacking.

To overcome that challenge, the researchers worked closely with brain banks in the United States and Canada to collect postmortem striatal samples representing diverse anatomical regions. 

Then, they used three different techniques to analyze the samples, including single-cell RNA sequencing — a method that can measure RNA molecules within individual cells to reveal which genes are being expressed. Two additional techniques — multiplexed fluorescent in situ hybridization and spatial transcriptomics — allowed the researchers to identify spatial principles of organization within the tissue.

Using these techniques, the researchers were able to identify 31 different subpopulations of neurons, including nine types of medium spiny neurons. Among their medium spiny neuron types are two “outlier” populations that appear to play important roles in schizophrenia, substance use disorder, and depression.

One of those populations, known as D1 outliers, showed high expression of genes involved in addiction and substance use disorder, especially genes related to opioid response. Another population, called D2 outliers, showed high expression of genes that respond to antidepressants. And, both populations appeared to respond strongly to clozapine, an antipsychotic drug used to treat schizophrenia.

Clozapine is among the most effective antipsychotics available, but it’s not widely used in the United States because it can cause a fatal blood disorder in a small percentage of patients. Now that researchers know which cells the drug acts on, they may be able to design more targeted therapeutics to overcome psychosis, but without the harmful side effects, Heiman says.

Huntington’s vulnerability

Another key finding of the paper helps to shed light on why the dorsal (upper) part of the striatum is more vulnerable to Huntington’s disease. The disease is caused by an inherited version of the huntingtin gene that carries too many repetitive DNA segments, called CAG repeats. 

The researchers found that dorsal populations of medium spiny neurons express higher levels of the genes MSH2 and MSH3, which play a role in increasing the number of CAG repeats found in the huntingtin gene. As more of those repeats accumulate, the mutated version of the huntingtin protein becomes more harmful to cells.

The researchers also found that a rare population of medium spiny neurons that forms island-like structures in the ventral striatum was more resistant to the accumulation of CAG repeats. Further study of this class of cells might help researchers learn how to induce other medium spiny neurons to become more resistant to the disease, Heiman says.

“Looking at the genes that these neurons express or don’t express might give us some clues as to how to make other medium spiny neurons resilient like them,” she says. 

Insights into substance use disorders

The researchers also compared their findings from human tissue samples to samples from mice and found several differences, especially in the expression of genes related to drug response and substance use disorders. One such gene, which encodes the mu opioid receptor (OPRM1), is highly expressed in the human D1 outlier population, but not in the corresponding population of neurons in mice. 

This means that standard mouse models may not fully capture the biology of opioid responses, and that engineering mice to express this receptor in a similar manner to humans could make those models significantly more accurate.

“Some of the diversity we’re seeing in the human ventral striatum is species-specific and has implications for modeling substance use disorder in rodents,” Heiman says. “Now that we understand better the species differences, we can use the rodent models for specific questions that apply for conserved genes, but we could also think about humanizing some models.”

The researchers hope that this map, built from tissue contributions by brain donors and their families, and assembled across disciplines and institutions, will provide an important starting point for researchers pursuing new treatments for some of the most difficult-to-treat brain disorders.

The research was funded, in part, by the National Institutes of Health, the G. Harold and Leila Y. Mathers Charitable Foundation, the Freedom Together Foundation, the Natalia Mental Health Foundation, the Biswas Family Foundation, and the Milken Institute.

Rewiring Democracy Series on The Renovator

Schneier on Security - Tue, 09/01/2026 - 5:59am

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links.

Part 1 is about the Japanese digital democracy party, Team Mirai.

Part 2 is about the Swiss Public AI model, Apertus.

Part 3 is about the civic technologists of Open Knowledge Brazil.

And the new one, Part 4, is about civic AI in Scotland.

Pages