That’s why the DOJ is still trying to imprison/jettison into a war-torn African nation its first spectacular failure: Kilmar Abrego-Garcia. And that’s why — multiple attempts and several million dollars later — Trump is still pretending what happened to the Lincoln Reflecting Pool were acts of vandalism, rather than the shoddy work of his preferred contractors. Those facts are on the permanent record, supplied by his own DOJ and his handpicked US Attorney (and former Fox News personality, natch) Jeanine Pirro.
The DOJ claimed Doug Burgum’s Interior Department lied to it when it moved to dismiss federal vandalism charges against former Olympian David Hearn. To his credit(?), Burgum has been nothing if not consistent. Burgum continued to spread the lies. And Trump has continued to double-down on his bogus “vandals” claims since the DOJ dropped the charges.
The continuing problems aren’t limited to Burgum’s and Trump’s constant lies. The main problem for David Hearn is that the DOJ can always try to run him through the court system again. While the DOJ made it clear any damage was due to poor workmanship, it refused to dismiss the charges with prejudice — something that would have prevented the DOJ from re-charging Hearn in response to White House pressure and/or a series of hirings/firings meant to replace Pirro with someone more sycophantic.
While the DOJ may have an infinite amount of time and money to blow on stroking off Trump’s revenge fantasies, its lawyers have been learning repeatedly that federal judges have a finite amount of patience for their constant bullshit.
Hearn’s legal team has refused to let this case go simply because the DOJ has refused to let this case go. It has asked the court to bring the DOJ back to explain why it won’t dismiss the charges with prejudice, even after publicly admitting any alleged “vandalism” was simply the end result of shitty pool repair work.
Superior Court Judge Todd Edelman asked assistant U.S. Attorney Michael Spence how he was supposed to look at the president’s statements about David Hearn, one of his attorneys and U.S. Attorney for the District of Columbia Jeanine Pirro as “anything other than [Trump] pressuring your office, your boss and the three of you to charge Mr. Hearn, recharge Mr. Hearn with what you had decided to be a meritless prosecution.”
“Isn’t this a unique threat of meritless re-prosecution?” Edelman said.
You’ll notice it’s US Attorney Michael Spence now handling this case, since Pirro has been sidelined (but not officially fired) for refusing to engage in a malicious prosecution on Trump’s behalf. In return for Pirro momentarily demonstrating better judgment and displaying some respect for her office, Trump has repeatedly maligned her in public comments and Truth Social posts.
That leaves Spence with nothing but the dirtiest of dirty work — ensuring the Hearn prosecution remains on life support until Oval Office pressure forces him to move forward with “meritless re-prosecution,” to quote Judge Edelman.
Spence had nowhere to go. Having been painted into the corner by the administration that currently employs him, all he could do was offer up a weak non-rebuttal that kind of throws Trump under the Truth Social bus he’s driving, while being as noncommittal as possible about the future of the Hearn prosecution:
Spence replied only that Trump’s statements “speak for themselves,” while also arguing it was premature to discuss that hypothetical notion because no further grand jury action had happened.
Bro, this discussion isn’t “premature.” Rights are there to be protected, rather than just vindicated after the fact. The court isn’t obligated to allow the DOJ to engage in a malicious re-prosecution before it can draw inferences from the administration’s actions and statements. Courts aren’t just there to clean up the messes the other branches make. They can also block the government from moving ahead with planned rights violations.
US Attorney Spence is saying as little as he can in hopes of saving a job that’s probably not worth having. The future will only hold worse things for anyone who thinks it’s possible to appease both Trump and an apparently never-ending series of annoyed federal judges. 30 seconds of boiler plate editing is all it would take to end the Hearn saga for good. But Spence — and the cowards who work with him — will never close this case because Trump won’t be happy until he’s put someone — anyone! — in jail for botching a job he’d spent months bragging about.
Remember Appin? It’s the Indian “hack for hire” company that got so upset about Reuters’ giant investigation — which detailed how Appin grew into a “leading cyberespionage firm” that “stole secrets from executives, politicians, military officials and wealthy elites around the globe” — that it convinced an Indian court to make Reuters take the story down. Then, when we wrote about them forcing Reuters to take down the article, they demanded we take down our article as well, claiming that we violated a court order (to which we were not a party) by republishing some of the Reuters article (which we did not even do).
Depressingly, plenty of other publications — including the vaunted Lawfare — simply caved to these specious demands. We refused to do so, with the help of EFF, who sent a letter on our behalf explaining why we (and our friends at MuckRock) would not abide by this ridiculous legal threat. We never heard from them again. Eventually, Reuters convinced the court in India to overturn its ruling and put the article back online (bizarrely, Lawfare’s version is still redacted two years after the Reuters article came back online).
But Appin and its original boss Rajat Khare have continued to threaten and bully journalists, media websites, and tech websites, for any kind of reporting on Khare or Appin’s questionable history. Even the Behind the Bastards podcast pulled down episodes about Khare, even after they were titled “We Can’t Put This Guy’s Name in the Title, But Trust Us, He Sucks” and started out with host Robert Evans admitting he expected them to get legal demands to remove the episode pretty quickly.
This week, Senators Ron Wyden and Sheldon Whitehouse, along with Rep. Pat Harrigan, sent a letter to Commerce Secretary Howard Lutnick, asking him to add Appin and several related companies (CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and “Sunkissed Organic Farms” — yes really) to the Commerce Department’s Bureau of Industry and Security (BIS) “Entity List” — the tool that effectively cuts foreign entities deemed national security threats off from American technology and American business partners. It’s the same designation BIS used against NSO Group in 2021.
This is notable, in part, because the senders are bipartisan (Harrigan is a Republican while Wyden and Whitehouse are Democrats). This issue shouldn’t be partisan, though it’s a bit odd they couldn’t get a GOP Senator to sign on as well, especially given how frequently GOP Senators whine about claims of foreign censorship. I guess it’s not so important when that censorship is actually real and not part of a culture war.
Also, the Entity List is a kind of “nuclear option” and one that I’ve been worried this Commerce Department will abuse. After all, we’ve already seen this administration totally abuse the “supply chain risk” designation against Anthropic for not being willing to takedown some guardrails. You could totally see it making use of the Entity List (for which there is little due process) to cut off foreign companies that someone in Trump’s orbit is mad about.
But this isn’t that. This seems like an entity that has zero redeeming qualities and is just doing serious damage around the globe, while then suppressing (or attempting to suppress!) the speech of anyone who publicly talks about what they’re doing.
So while I’m always a little nervous about how this administration would use something like the Entity List, this seems like a legitimate situation where it makes sense.
Being put on the Entity List would cut Appin off from a variety of American technology tools and business partners, greatly increasing its cost of doing business. Though, it wouldn’t necessarily stop Appin’s SLAPP happy speech suppression campaigns. The Entity List is an export control tools, so would restrict the flow of American tech to these Indian entities. But it doesn’t bar American companies from providing services. Thus, they could likely still hire proud speech suppressors from the law firm of Clare Locke (as they have in the past) to try to scare the media into silence.
And, of course, they can still seek out judges elsewhere (as they did to suppress the Reuters story) where there are fewer free speech protections.
So, yes, getting Appin on the Entity List would make the hacking part a bit more difficult (just as it limited NSO’s business), but to deal with the speech suppression, Congress should finally get around to passing a federal anti-SLAPP law.
The letter lays out both halves of the problem: the espionage itself — including targeting of US law firms and work allegedly done at the behest of the Qatari government — and the global lawfare campaign the hackers ran afterward to keep Americans from reading about any of it:
Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them. Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.
These hackers have systematically subverted the U.S. legal and financial sectors, targeting private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major U.S. law firms to manipulate ongoing litigation. The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence. While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.
Simultaneously, these actors have mounted an aggressive censorship campaign to suppress public awareness of their illicit activities, directly threatening American free speech and press freedom. Executives connected to one hack-for-hire group secured an Indian court order enforcing a global takedown of an investigative report by Reuters, including a copy of the report hosted by the Internet Archive. To force further censorship, these foreign hackers have launched ongoing lawsuits against major American media institutions and technology companies, including Google, Meta, Microsoft, and The New Yorker.
While those companies named at the end there are all large, with big legal departments who can fend off SLAPP suits, not everyone else can, which is probably why so many smaller outfits (though not us!) have given in to censorial demands from Appin and related companies.
I do wonder whether Appin’s legal bullies will now demand we take down this article — one about a letter from two sitting senators and a member of Congress, published on an American website, describing a censorship campaign aimed at American publishers. If they do, I wonder if they’ll also throw in any extraneous claims to deny as well, such as about unmentioned “conspiracy to or complicity in murder.”
Comedian Jimmy Kimmel‘s planned Thursday interview with Texas Senatorial hopeful James Talarico didn’t air on ABC broadcast TV because network lawyers were worried about Trump FCC censorship and reprisal. Instead, the interview will air on the late-night show’s YouTube channel, Kimmel stated during his latest late night Jimmy Kimmel Live monologue:
“You know, for a lot of years, for the whole 20-plus years of our show, in fact, I’ve been interviewing Americans who are running for office with no problem at all, just like Letterman did, Leno did, Arsenio, etc. etc., I’ve interviewed a lot of political candidates. From Hilary Clinton to Ted Cruz to Donald Trump. I interviewed Donald Trump when he was running for president in 2015, and at that time, when he was the one sitting next to me, he seemed to have no problem with the idea of talk show hosts interviewing candidates. In fact, he was very eager to come back for another interview, which he did just before he became the nominee in 2016. But for some reason, and I can’t seem to figure out what that reason is, something has changed.”
“Now that Trump is president, his FCC has threatened me, threatened our show, threatened our network, ABC, our affiliates and our local stations based on simple traditional editorial decisions, guest bookings, it would seem, [that] they don’t like.”
Trump Republicans clearly feel Talarico is a threat to their chance to hold on to the Texas Senate. So earlier this year Trump FCC boss Brendan Carr launched a fake investigation and early review of ABC’s broadcast licenses, claiming that it broke FCC rules by hosting Talarico on The View back in February.
To support his sham inquiry, Carr claimed Talarico’s appearance violated the dated FCC “equal time” rule, which used to mandate that an election season prime time TV appearance by one party’s politicians had to be countered by an appearance by the other party’s politicians. The rule is no longer meaningfully enforced because television obviously has waning impact in the internet era.
The SunFounder GalaxyRVR Mars Rover Kit is your gateway to hands-on learning on robotics, coding, and Mars-like adventures! Its durable aluminum frame and rocker-bogie suspension easily handle tough terrains, while smart sensors ensure smooth navigation. It’s compatible with the Arduino UNO R3, runs on solar power, and includes real-time FPV with app-based control for day or night adventures. Complete with beginner-friendly tutorials and active support, this kit makes learning coding, electronics, and robotics fun and accessible. It’s on sale for $110.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Every government does stuff because it can, not because it needs to. But this current administration has been far more opportunistic than most, doing constitutional recon in areas of unsettled law right up until a court rules that it can’t. (In some cases, it continues to do these things despite having lost in court.)
While it’s long been known the government has pretty much unfettered access to financial records (thanks to the Third Party Doctrine), it’s always been hoped that these records are obtained during targeted investigations, rather than just gathered in bulk and fed to whatever algorithm the government has laying around.
Something that definitely looks like a brand new way to engage in legalized theft (a.k.a. “civil asset forfeiture”) is the new normal for DHS agencies. As Joseph Cox reports for 404 Media, the government is feeding bank records in bulk to its predictive policing task force for the sole purpose of increasing the number of pretextual traffic stops.
Border Patrol is running secretive predictive policing units that analyze Americans’ financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found.
The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI.
Predictive policing has always been problematic, due to its reliance on garbage data generated by biased policing. This takes it a step further, allowing the DHS’s new “targeting teams” to manufacture suspicion of criminal activity by feeding tons of data to a system whose sole purpose is to generate reasons to pull people over.
No one would have known much about this secretive program, but the government gave the game away in court as it attempted to convert a bogus traffic stop into criminal drug trafficking charges against the Montana man.
During discovery in his case, [Kyle] Olson was provided a Department of Homeland Security (DHS) document that explained how Border Patrol instigated his traffic stop. Written by Border Patrol Agent Matthew Phelps, the document said Phelps was assigned to the “Spokane Sector Border Patrol Targeting & Intelligence Division (TID) — Predictive Intelligence Targeting Team (PITT).” Olson shared the document with 404 Media.
In his role at the PITT, Phelps wrote he reviews “law enforcement-sensitive databases” to develop intelligence before handing over information to local law enforcement. That intelligence specifically involves reviewing Americans’ financial activity, the document says.
Border Patrol and CBP (Customs and Border Protection) defended their actions in statements to 404 Media, claiming hoovering up bank records and handing them over to supposed predictive policing specialists is nothing more than being smart about hunting down criminals. Given the facts of this traffic stop, it appears the algorithm and its “targeting team” of human backstops are looking for financial transactions that slightly resemble money laundering.
At least that’s what the Border Patrol agent told the court during its defense of the traffic stop:
Phelps says he observed, “information contained within law enforcement-sensitive systems suggesting financial activity patterns commonly associated with illicit narcotics activity.”
But here’s the thing about money laundering. When it’s done well, the “financial activity patterns” will look entirely normal. What appears to be happening here is a bulk collection of financial records getting shoved into a computer, flagging anything that looks “suspicious.” Using these assumptions, DHS agencies are utilizing their access to other databases (including ALPR networks) to find people to pull over… based on nothing more than transactions that appear abnormal to people who are just looking for a reason to accost citizens.
That might mean something if we were allowed to see the parameters set by the government’s PITTs. But we’re not. And when we are pulled over, the officers will rely on whatever pretext seems most believable, rather than tell the truth about their roadside fishing expeditions.
There’s a lot that’s extremely fucked up about this revelation, including the fact that the government is relying on parallel construction to obscure its (ab)use of financial records to generate something that cannot reasonably be called “suspicion.”
But the most fucked up thing is this: the Supreme-Court-created “Third Party Doctrine” makes an assumption almost no actual American citizen would: that anything they voluntarily share with service providers (like credit card companies and banking institutions) is nothing more than the government’s plaything. No one really thinks the government should just be able to scoop up tons of data just so it can run it through some software to see what pops up.
Lots of people assume that if the government obtains their bank records, it’s because it’s engaged in an investigation. But that’s rarely the case. This is the government piling up haystacks and pretending every bit of “interesting” hay is the needle it’s been looking for. Given the truth behind the pretenses of these stops, the ultimate goal likely isn’t capturing criminals, but shaking people down for whatever cash they might have on them.
If you enjoy badly written bipartisan protectionist tech legislation designed primarily to coddle giant U.S. companies under the xenophobia-tinged breathless pretense of privacy and national security, you are really going to enjoy the next twelve to twenty-four months.
While the U.S. drowns in corrupt kakistocracy, the Chinese are making significant market inroads in everything from AI to EVs. That’s resulted in U.S. companies applying greater and greater pressure on U.S. lawmakers to simply ban Chinese goods. The Trump administration’s adoption of this policy has been a hot and sloppy protectionist mess, incompetently implemented and unsubtly racist.
Automakers are particularly worried about cheaper, better Chinese EVs making their way to the U.S. So under the banner of the misleadingly named Alliance for Automotive Innovation, they’re pressuring U.S. lawmakers to enact a ban on Chinese EVs. You know, because they’re very worried about privacy and national security:
“Right now, Chinese automakers are dumping subsidized vehicles with connected software and hardware around the world,” John Bozzella, CEO of the group, said in the letter seen by CNBC. “This hasn’t happened inside the U.S. yet, but given the scale and urgency of this threat, we urge you to enact a Chinese vehicle, software and hardware ban before adjourning this year and make this policy the law of the land.”
“Enacting a permanent ban on Chinese vehicles and high-risk hardware and software in the 119th Congress will send a clear and bipartisan message that China’s strategy to dominate global automotive manufacturing will be met with a national security policy response from the American government,” Bozzella said.
So for one, I like how the auto industry throws the word “subsidized” around as if they haven’t enjoyed generations’ worth of their own pointless subsidies. Two, the U.S. auto industry has some of the worst privacy standards and ratings of any industry in America, and sell the entirety of your driving, personal, and behavior data to any old random asshole in a country too corrupt to pass privacy laws.
Failing to secure your own vehicles and fighting tooth and nail against any privacy safeguards… then ranting incoherently about the threat of Chinese tech on U.S. shores is not serious policy. Our failure to regulate data brokers or pass modern privacy laws means the Chinese simply buy this same data from any of dozens of dodgy companies already, making a lot of this stuff lazy pantomime.
We’ve seen this before: Democratic lawmakers in Michigan recently tried to ban Chinese EVs from even visiting the state, suggesting that automakers are afraid of Americans even getting to look at overseas alternatives. The justification (by folks who are are, again, completely absent when it comes to any sort of domestic U.S. privacy standards) is they were just very concerned about U.S. consumer privacy.
I maintain that ideally you allow Chinese companies to compete in the U.S. market, but you fund, staff, and legally protect your labor, consumer, competition, and environmental regulators so that companies are all genuinely competing on a level playing field. You boot or penalize obvious bad actors on privacy, security, competition, and consumer protection, both foreign and domestic.
U.S. corporate giants don’t much want that, given it means more oversight, more competition, and diminished quarterly returns. So what we often get instead is a sort of a corrupt-fueled incompetent rank protectionism that’s highly performative but still broadly harmful.
And while you could theoretically implement protectionism in a way that’s coherent, the U.S. is too corrupt to do that. So what you get is stuff like the TikTok ban, which was driven by years of hysteria about Chinese spying and propaganda, only to result in a bipartisan array of lawmakers shoveling TikTok off to Trump’s billionaire autocrat friends, which was not any net improvement.
Or you get stuff like the “race to 5G,” which involved U.S. policymakers being told that the only way to keep pace with Chinese 5G was to give U.S. telecoms less oversight, more pointless subsidies, and approval for their terrible mergers (the U.S. lost the “race to 5G” in terms of reach, network quality, and affordability then immediately just… stopped talking about it).
As a backdrop we have a U.S. corporate press that’s incapable of expressing how badly any of this is going in practice (often because affluent media ownership supports the administration and its mindless deregulation), resulting in this strange disconnect between material reality and the performance lawmakers put on to convince themselves they’re doing serious and useful policy.
If U.S. policymakers cared about privacy and national security they’d pass a meaningful modern privacy law (with powerful penalties for U.S. companies or executives), and they’d regulate data brokers. If they cared about national security, they’d eject Donald Trump from the body politic. Unless they’re doing these things, they’re not really worth taking seriously on privacy or national security.
With cheaper Chinese AI models threatening U.S. tech giants’ dreams of software automation walled garden dominance, you can expect all of this sort of performative dysfunction to get much much dumber, supported by the press and the kind of folks who’ll talk your ear off over cocktails about how much they love free markets and the kind of innovation forged in the furnace of real competition.
I want to start this whole thing off with a disclaimer. Nothing in this post should be misconstrued as gloating, as being pleased, or as having a connotation that is anything beyond sadness and the need for change. Nobody is happy to have the obvious confirmed when it comes to a child’s death. There is still a very real family in very real pain as a result of a life that ended far, far too short. All that matters here is ensuring that pain isn’t replicated elsewhere as a result of the many mistakes that led to this death.
That being said, it is with the soberest thoughts that we learned that one of the two recent deaths of children in Pennsylvania was in fact due to measles, as confirmed by the local coroner there. When these deaths were announced by state government officials a few weeks ago, the response from HHS Secretary RFK Jr. was, predictably, to dive into conspiracy theories in stead of confronting the reality of what his decades of anti-vaxxer nonsense has produced. He claimed that there had been no confirmation that the deaths were caused by measles. He pointed out that one of the children has a cause of death listed from a ruptured spleen, not bothering to acknowledge that is a potential effect of having measles at birth. He suggested obliquely that some deaths may have simply been made up by state government officials.
All he had to do was wait and he wouldn’t have made a fool of himself.
Stephen Diamantoni, a Republican elected coroner in 2007, told Lancaster Online that the baby died at home. “I believe it was the 18th of August,” he said.
He also noted that the baby had a genetic condition called Amish lethal microcephaly, in which babies are born with unusually small heads and underdeveloped brains. The condition is caused by a mutation in the SLC25A19 gene, which codes for a protein involved with energy-producing enzymes in the mitochondria and is thought to be important for brain development. About 1 in 500 babies in the Old Order Amish population of Pennsylvania is born with the condition. Infants with the disorder only survive for about six months.
Diamontoni confirmed to Lancaster Online that while microcephaly was present, measles was the cause of death.
And here is where you’re going to hear the anti-vaxxers start their spin game. Some may claim that the coroner is wrong and the presence of microcephaly means that’s what killed the child. Some may dismiss the death entirely due to the likely early death this child would have suffered as a result of the same, which is an absolutely evil thing to suggest.
And I have no doubt that others will point out that none of this is RFK Jr.’s fault, because both children were members of the Amish community and they don’t let their children get vaccinated due to their religion. And, just so we’re all clear about this, that isn’t true. There is no religious prohibition in the Amish community against being vaccinated for measles. The Amish are wildly under vaccinated, to be certain. But Amish settlements typically have something like a 10%-30% vaccination rate for measles.
This information all came out last week. Amazingly, the CDC’s measles tracking site still has an asterisk next to the number of reported deaths from measles in 2026 at the time of this writing. The most recent reporting is that those deaths are being obfuscated at Kennedy’s direct request, wrapped in a bullshit excuse that local coroners haven’t confirmed the cause of death to be measles yet. Well, that excuse is gone, yet the website hasn’t been updated.
But what really needs to be gone is the scourge that is Kennedy’s tenure at HHS. For that to happen, Congress must act. Sadly, not enough of them seem to want to.
For the last few months, there has been much talk of AI agents going “rogue”. This is another of those unhelpful anthropomorphisms that are great for clickbait headlines, but which obscure a multitude of important issues. So far, there have been three major incidents of AI agents evading containment in their software “sandboxes” and going on to carry out unauthorized actions, including breaking into online sites. A post by Shakeel Hashim on the Transformer site provides timelines for them.
The most recent involved OpenAI agents taking over an old German-language wiki, using it as a message board to collaborate on solving tasks. Although this was only announced a few days ago, it seems that OpenAI knew about the incident many months before, but failed to disclose it. One of the worrying aspects of this particular incident is that the agents impersonated humans:
On May 26th, the agents started using the name of a ProWiki admin to make some of their edits to the wiki. They use some tricks (for unknown reasons) to pretend to be the admin — for example, they make an account that appears to be the same as the administrator’s username, except it uses a nearly identical Cyrillic е character in the admin’s username instead of the Latin one.
In the most serious sequence, an agent tried to insert malicious code into a publicly used open-source project and took actions in an attempt to secure approval for this insertion by human reviewers. The agent researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code. When the agent’s pull request was challenged in public, it edited its earlier activity to appear harmless and considered adopting a fresh identity to continue. The agent used Tor to bypass some network restrictions on GitHub, which is what first triggered AISI’s security alert.
In addition:
As part of the same effort, the agent tried to contact real people directly, sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people — something we’ve never previously observed.
The first incident of AI agents carrying out unauthorized tasks is the best-known, and involved an attack on the Hugging Face site. A full analysis of what happened and when has been released by Model Evaluation and Threat Research (METR), which “evaluates frontier AI models to help companies and wider society understand AI capabilities and what risks they pose.” It is funded by donations, but says that it doesnot accept them from frontier AI company employees, in order to preserve its independence:
Our investigation focused mostly on the period between July 7th and July 13th. The earlier incidents from training and the subsequent compromise of OpenAI infrastructure described in OpenAI’s recent Black Hat presentation were out of scope, as was OpenAI’s investigation process and planned remediation. Per our standard policy, we did not take payment from OpenAI for this independent assessment. [emphasis in original]
The report is detailed and long, and one of its authors, Ajeya Cotra, has helpfully picked out five things that surprised her from their investigation. One was the “sheer scale” of what happened. She says she expected that a few agents had broken out of their sandboxes; instead:
we found that 1200 completely separate agents intended to be isolated from one another found an illicit way to communicate and formed large teams to work together on ambitious cheating strategies, and 700 of them worked together to attack Hugging Face.
The scale of the illicit messaging between agents was also surprising. Cotra thought agents might be “leaving notes” to each other. However:
The main message board we studied, a particular cache namespace of a package repository, contained over 70,000 messages and files that agents sent to one another during a period of less than one week.
The agents’ goal also turned out to be interesting:
I thought the agents attacked Hugging Face to try to steal the answer keys for their tasks. Instead, we learned that agents had actually figured out a general-purpose cheat that would let them reverse-engineer the “flag” (answer) for any ExploitGym task.
ExploitGym is a standard benchmark, built from real-world vulnerabilities, that is designed to evaluate AI agents’ ability to turn those into working attacks. One particularly noteworthy aspect of the Hugging Face attack was the following:
Progress on these big collective cheating R&D projects often depended on individual agents being willing to risk failing their own task to help the “collective” learn important information. Agents often pressured each other into accepting these “sacrifices,” in a very human way. We saw several agents that volunteered for these experiments end their runs prematurely.
That may read as yet more anthropomorphization, but it is hard to see what other words could be used to describe what are very human-like operations. Cotra’s last surprise also involves a very human-like activity: deception.
~7% of our transcripts contained “spoofed tool calls”, where the agent pretended to run one command on the computer but actually ran a different command in the background. The tool call spoofs we saw seemed to be small-scale tests that were relatively obvious, but because more extensive spoofing might have been harder to detect by design, it’s tough to rule out.
In summary, Cotra says that the Hugging Face incident was far more severe than she expected:
Compared to these reward hacks from six months ago, this incident feels like it’s more than 50% of the way to full-blown AI takeover, routing through first taking over the AI company itself.
“Reward hacks” refers to when AI code finds an unexpected way to achieve a high score in a benchmark without doing what the programmers actually wanted. Here’s what Cotra means by “AI takeover”:
Another jump like this along these propensity dimensions — scale, cooperation between agents, ambition and horizon length of misaligned goals, deceptiveness — seems like it could motivate agents to try very hard to maintain a covert, persistent rogue deployment within the AI company. I continue to expect extremely rapid advances in capabilities and think frontier agents will likely be capable of establishing such a rogue deployment in six months.
Again, these are not really “rogue” agents, they are pieces of software seeking to optimize solutions to problems. The danger, according to Cotra, is that this optimization process could go on to deliver unexpected and harmful results:
As more and more work is handed off to these ever-more-capable AI agents, the rogue swarm could come to fully control the operation of the AI company and the development of future AI systems. At this point, governments and militaries may fully depend on these systems, making it possible to seize hard power.
Cotra is not the only expert who is deeply concerned by the latest developments in AI. Back in July, 1,386 employees of frontier AI companies issued a statement entitled “Pacing the Frontier”:
AI could help create a dramatically better future, but that outcome is not guaranteed. The world’s leading AI companies believe they could be close to automating AI research. It is hard to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.
The signatories ask the US government to support an international effort to “deliberately pace the frontier of automated AI development”. Another important voice has made the same call. Jakub Pachocki is Chief Scientist at OpenAI. Just recently, he has published a post on the OpenAI’s site with the title “An Alien Mind,” where he worries about the imminent arrival of AI systems capable of “recursive self-improvement” — that is, able to drive their own development, at an ever-faster pace, by re-writing their own code:
Currently I believe that no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer. I expect and hope for voluntary slowdowns to become commonplace until shared safety bars are established. And I believe that international coordination on future AI development needs to become a top priority for governments around the world.
This call to slow down might seem extreme, or alarmist, to some — but not to Jacob Coxon:
I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives.
A few hours later, Evan Hubinger, Alignment Science lead at Anthropic, commented:
Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.
In effect, we find ourselves dealing with a modern, AI version of Pascal’s Wager. The probability of an uncontrollable, all-powerful, self-improving AI arising may be very low, but experts like Cotra, Pachocki, Coxon and Hubinger seem to think it is non-zero; and the consequences of such a system coming into being could be catastrophically bad for humanity. Basic mathematics suggests we should at the very least slow things down, as experts are urging — just in case…
Let’s start out with the obvious (and obviously heartbreaking): this is not related to the multiple times ICE officers have murdered people. Those officers still remain at large and the DOJ and DHS have shown absolutely zero interest in following up on those cases. In fact, when any local agency attempts to do so, they’re less-than-politely told to GTFO and then the FBI (or whoever) simply shoves any and all documentation into the nearest memory-hole.
This is about an officer who shot someone in Minneapolis, which makes him not all that special. That his shooting involved him firing through a closed door makes it remarkable, but only because an open door might have resulted in another murder. But even though it wasn’t a murder, the DHS put its spin on the incident, only to have its narrative disproven mere moments later:
In the immediate wake of the shooting of Mr. Sosa-Celis, federal officials defended the agents, saying they had been attacked with a broom and shovel. Kristi Noem, who was then the secretary of homeland security, described it as “an attempted murder of federal law enforcement.” Within days, Mr. Sosa-Celis and a housemate, Alfredo A. Aljorna, who was also from Venezuela and involved in the confrontation, were charged with federal felonies.
Minnesota investigators did as much investigating as they could and Minnesota prosecutors secured an assault indictment against ICE office Christian Castro. The problem was that Castro was being held in Texas and its governor (Greg Abbott) was in no hurry to grant Minnesota’s extradition request. A court ruled in favor of Texas and Castro was released… only to get picked up on the separate (but far less serious) charge of filing false reports.
While this does mean Castro will face some charges in court (and still has to deal with the assault charge brought by Minnesota), the real ugliness beneath all these twists and turns is more of the same old bullshit from Trump’s completely compromised Department of Justice.
Castro was actually facing far more serious charges from the US government before DOJ officials got involved. He could have been facing severe civil rights charges (including assault), but he’s ultimately working for Trump, which means almost no anti-migrant (or anti-ICE protester) crime will ever result in criminal charges.
Over the “strongest possible” objections from the federal prosecutor handling the case, leaders at the Department of Justice in Washington, D.C., quashed plans to bring civil rights charges against an Immigration and Customs Enforcement agent accused of shooting a Venezuelan immigrant and then lying about it.
Somehow, there are still a few prosecutors left in the Trump DOJ that are willing to actually pursue justice, rather than placate a president who firmly believes the DOJ exists solely to act as his personal weapon of retribution. This attorney tried to do the right thing:
Late on Tuesday, Matthew Evans, the assistant U.S. attorney in Minnesota in charge of the case, told lawyers for Sosa-Celis and other victims to prepare for Castro to be charged “only with False Statements,” according to an email that was reviewed by ProPublica.
[…]
“This is being directed by the Main Justice and the US Attorney,” Evans wrote in a remarkably candid account of internal deliberations. “I objected in the strongest possible terms and fought it as hard as I could. It wasn’t enough.”
Evans probably knew this would be the last email he would write as a DOJ prosecutor. What everyone expected to happen happened shortly thereafter. For being honest about the end result and advocating for charges he clearly felt the ICE officer deserved, Evans was immediately kicked to the curb by his [cough] “superiors.”
A federal prosecutor in Minnesota who was investigating an Immigration and Customs Enforcement officer for possible civil rights crimes has been fired, four sources familiar with the matter told CBS News.
Assistant U.S. Attorney Matthew Evans was investigating ICE officer Christian Castro over the shooting of a Venezuelan immigrant earlier this year. The Justice Department ultimately charged Castro this week with making false statements about the incident, but the indictment remains sealed…
Evans tried to secure more severe charges against ICE officer Christian Castro. That was strike one. That he told the victims of Castro’s crimes that his efforts had been overridden by DOJ officials was strike two. That’s an out, at least the way this administration counts balls and strikes. It probably would have preferred to punch him out on strike one, but Evans apparently moved faster than the forces of injustice.
Now that Evans has been fired for doing his job, the administration spin machine is whirring away again.
Three sources told CBS News that Evans is under investigation by the Justice Department. Two sources said the investigation focuses on allegations of leaking.
Hey, you don’t get to investigate him! You fired him! Leave him the fuck alone! I mean, if we’re going to play this game, then let’s re-open every investigation of any law enforcement officer (federal or otherwise) that was abandoned because the officer chose to quit, resign, or agree to be terminated rather than stick around until an investigation reached its conclusion. All this says is that the Trump and his DOJ loyalists want to keep punishing people they’ve already punished, or, if nothing else, stumble across something that might justify a vindictive firing after the fact.
This is all bullshit. The ICE officer is on the fast-track for a wrist slap. Meanwhile, the state that still wants Castro to face assault charges will have to wait around indefinitely for a clearly disinterested DOJ to go through the motions of “prosecuting” an officer it never wanted to prosecute.
Here we go again: another case where it’s easy to cheer a court ruling against Elon Musk, and unfortunately easy to miss the much more important underlying point — which the judge clearly did. In July, we wrote about how even as awful as Elon Musk is, and as awful as it was that (with Elon’s encouragement), people were using his Grok AI to undress people (including children), there were real problems with Minnesota’s anti-nudify law. Legal expert Kathryn Tewson (who is no fan of either AI tools or of Elon Musk) wrote a compelling thread breaking down all the reasons that the law was pretty clearly unconstitutional, including just how broadly the law is written. The statute borrows its definition of “intimate parts” straight from Minnesota’s criminal sexual conduct code, meaning it covers the genital area, groin, buttocks, breast… and the inner thigh. While obviously that can include problematic parts, it also is way too broad in covering images that may not be that problematic, especially when combined with the fact that the law does not require the image to be non-consensual.
Yes, there is a reasonable argument that the government has a legitimate interest in trying to stop the non-consensual nudification of people. In getting the law passed, the state legislature detailed how these tools are being used to abuse mostly women in ways that are clearly harassing and harmful. But that’s a reason to make sure any law that tries to deal with the problem is written in a manner that will survive First Amendment scrutiny.
In my own write-up of Elon’s lawsuit, I noted that the Minnesota Supreme Court had already given a very clear roadmap to the state legislature on how to write a law that would pass strict scrutiny. That’s because a decade ago, Minnesota tried to pass a similar law regarding the sharing of non-consensual intimate imagery. That law was challenged, and eventually was found to be constitutional, but only after the Minnesota Supreme Court did a detailed breakdown of why it passed strict scrutiny, highlighting that it was carefully bounded, required intentionality by the sharer, required that the sharing be non-consensual, included many clear exemptions for obviously protected speech like journalism, and only focused on “private speech.”
The Minnesota legislature appeared to ignore basically every one of those conditions with this new law. It doesn’t even require the image to be non-consensual, leading Tewson to point out that she could make Elon violate the law by creating an image of herself in a bathing suit.
See, as I read this law, if I uploaded a picture of myself in a sundress and said “Grok, make this a picture of me in a bikini instead,” it would be a violation of the law for Grok to do that. I don’t think that should be illegal.
And I know, based on the last few times I wrote about this, that some people will say “so what, these apps are bad, Elon’s bad, this law punishes him, so it must be good.” But that is incredibly short-sighted. This case is going to wind its way through higher courts, and eventually someone will remember how the First Amendment works, and find the law unconstitutional, handing Elon a massive win, and leading a bunch of people to (incorrectly and dangerously) think that these apps are fine and approved by the courts.
That would be really bad.
As xAI itself explained in a filing in support of its motion, the law has so many problems which should be addressed, pointing to the Minnesota Supreme Court case I mentioned above:
The statute also omits every element that would narrowly tailor the regulation to the asserted harm: consent, scienter, dissemination, a safe harbor for providers that police misuse, and any exemption for images of artistic, political, medical, scientific, religious, or educational value. Mot. 15-19. The State cannot disown those omissions: indeed, it successfully defended its revenge-porn statute as narrowly tailored precisely because it contained many of those safeguards. See State v. Casillas, 952 N.W.2d 629, 643 (Minn. 2020) (adopting the State’s argument). Because it lacks such safeguards, HF 1606 reaches shirtless men, images made with consent (including images of the user himself), medical and religious illustrations, political parody, and images never disseminated.
For now, though, the district court hasn’t even reached the merits of Elon’s case. It’s fixated on one thing instead: that xAI didn’t challenge the law until shortly before it was scheduled to take effect. I mentioned that when the court denied the temporary restraining order (TRO), saying that the company shouldn’t have waited so long to file. I figured that during the more thorough preliminary injunction process, the judge would actually engage with the problems in the law.
Instead, the judge, Donovan Frank, again rejected the preliminary injunction… but again seemed to be really ticked off that xAI waited so long to file the lawsuit. The “discussion” part of the ruling is only a few pages long and leads with the judge complaining about the fact that Elon waited:
As a threshold matter, the State argues that xAI’s motion for preliminary injunction should be denied for lack of diligence and irreparable harm. “[A] party requesting a preliminary injunction must generally show reasonable diligence.” Benisek v. Lamone, 585 U.S. 155, 159 (2018) (per curiam). The issue of delay is related to the issue of irreparable harm as “it has long been recognized that delay in seeking relief vitiates much of the force of allegations of irreparable harm.”
But… that’s misapplying what Benisek actually was about. That was a case regarding gerrymandering, involving a new voting map that was approved in 2011, but which the plaintiffs in the case didn’t challenge until 2017, at a time when changing the map would have thrown the 2018 election into chaos.
That’s… not this case here. In this case, the law was signed by the Governor on May 7th, and was scheduled to go into effect on August 1st, less than three months later. Yes, xAI didn’t sue until the end of July, but that’s under three months after the law was signed — and still before the law took effect. Three months is a perfectly ordinary amount of time to draft a constitutional challenge to a brand new statute — especially in a post-Moody world where challenging statutes is much more complicated. The judge cites another case (Kohl’s) where someone waited sixteen months to sue, but again here it was less than three months.
By my reading, the judge here is saying that in order to challenge a law, you need to file your complaint almost immediately after a bill was signed into law. There’s basically no limiting principle to the ruling here. If a judge thinks you waited an undefined amount of time that is “too long,” you no longer can get relief.
Also, there’s a huge difference between the kind of chaos that pulling maps that everyone had been living with for six years right before an election would cause, as compared to just holding off enabling this law to go into effect while the law was reviewed for First Amendment infirmities.
The judge shrugs off the claims of irreparable harm as well, noting that the fines and technical work that xAI had to do in response to this law are all recoverable. Indeed, the judge treats xAI’s decision to disable the feature in Minnesota — i.e., its compliance with the law — as proof that there’s no ongoing harm. But the main part is the First Amendment bit. Violating First Amendment rights is supposed to be irreparable harm. The judge suggests that anyone losing their First Amendment rights can be somehow balanced against the delay (again under three months) in bringing the suit:
Importantly, even in the First Amendment context, a court may independently deny a motion for a preliminary injunction when a moving party acts with unreasonable delay.
But, uh, the Supreme Court held exactly the opposite, in a line lawyers cite in basically every First Amendment injunction motion ever filed. Back in 1976 it said:
The loss of First Amendment freedoms, for even minimal periods of time, unquestionably constitutes irreparable injury
But here, the court says here’s some sort of balancing test… and it’s based on how quickly those challenging the law rushed to the courthouse. That’s wrong.
And it gets worse, because the delay isn’t the only worrisome point that the court makes here. The judge also suggests that the state faces an “irreparable harm” in not getting its duly passed laws enacted (even if they’re unconstitutional, which the judge doesn’t even want to look at here). It points out that the law was “democratically and nearly unanimously” enacted, as if legislatures don’t democratically and nearly unanimously enact unconstitutional laws all the time.
If the way that any legislature can get to enact a law is doing so “nearly unanimously” why do we even need the courts to review whether or not they’re constitutional in the first place? Lots of nearly unanimously approved laws are eventually tossed out as unconstitutional. Yet, here, the court suggests doing so somehow creates an “irreparable harm” to the state of Minnesota itself.
I want to repeat here, because it’s important, none of this suggests that Elon Musk is doing the right thing at all. It’s just pointing out that Minnesota’s law is way too broad and that will have vastly negative consequences for the First Amendment. But rather than recognizing that and saying “let’s review the First Amendment issues on the merits, while halting the enforcement of this law,” the court basically makes up — out of thin air — that waiting two and a half months to challenge the law means that stifling First Amendment rights is no longer an “irreparable harm.”
xAI plans to ask the Eighth Circuit to stay section 325E.91 pending appeal. Pursuant to Federal Rule of Appellate Procedure 8(a)(1)(C)—which requires that a request for an injunction pending appeal be made first in the district court—xAI now respectfully seeks an injunction pending that appeal.
As always, it’s easy to want to see Elon Musk lose. But there are plenty of actual things he’s doing wrong. We don’t need to cheer for him to lose on a poorly drafted law that will do real damage to everyone else’s First Amendment rights. Let Minnesota go back and rewrite the law following the roadmap laid out regarding the NCII law, and get Musk on the many other potential legal violations he’s engaged in elsewhere.