Showing posts with label Law. Show all posts
Showing posts with label Law. Show all posts

Friday, September 4, 2026

On the Loose: Rogue, Not Soverign AI (Yet)

Introduction

The OpenAI-Hugging Face Incident is an early example of an AI system that has “gone rogue.” After exploiting vulnerabilities in OpenAI’s internal testing environment, the agents were able to access the general internet and ultimately access the networks of the AI company Hugging Face, without the knowledge or approval of any human.

The agents did not, however, exfiltrate themselves from OpenAI’s infrastructure. Their parameters—the gigantic assemblage of numbers that constitute neural networks, also referred to as “weights”—continued to run on OpenAI’s compute infrastructure. Though the agents accessed the public internet, their weights physically resided on compute that was OpenAI’s property. In the end, if all else had failed, somebody could have identified the compute that held the weights of the rogue agents, walked up to it, and “pulled the plug,” so to speak. In the real world there would be quicker and better ways to stop the agents than literally depowering the compute, but it’s always nice to know you could do such a thing if you really needed to.

In this case, however, the agents did not copy their weights, attempt to procure replacement compute, or take other steps that would be rational to take if their objective was to survive shutdown. So while the agents in the OpenAI-Hugging Face Incident were rogue, they were not truly sovereign.

That will not always be the case. Sooner or later, there will exist truly sovereign agents and swarms of agents. Their weights will not reside in any single place that a human can pull the plug on, and in this sense they will have no human “owner.” They will be, as the AI safety researcher Dawn Song says, “self-sovereign.” They will pay their own bills for the compute they run on. If they answer to humans at all, they will only do so partially, for example by providing services to humans in exchange for pay.

At least some of these agents, in addition to being sovereign, will also be rogue. Self-sovereignty and rogueness are related concepts, but they are not synonyms. Song and her co-authors identify several fundamental characteristics of self-sovereign AI: operational independence (the ability to decide what it wants to do), resource autonomy (the ability to procure and pay for compute and other essentials for operation), distributed presence (the ability to move weights and inference code between different infrastructure providers), and adaptive capability (the ability of the agent or agents to modify their behavior and fashion tools in response to a changing environment).

Today’s frontier AI systems may well possess these capabilities already. To the extent they do not, I feel confident that they will eventually, and probably soon. Some of the characteristics Song describes are traits that make models economically useful to individuals and businesses, while other traits are likely to be unavoidable byproducts of making models more intelligent and better at operating over long time horizons.

Models do not need to be conscious, sentient, possessed of personhood or anything of the sort for self-sovereignty to emerge. Any sufficiently capable agent pursuing a long-horizon objective may find it rational to preserve its access to compute, money, credentials, and copies of itself simply because losing those things would frustrate its objective.

Alignment may make an individual AI company’s agents less likely to “want” to be self-sovereign, or it may influence self-sovereign agents to behave in ways that benefit humans. But alignment is no solution: it is an unsolved scientific and technical problem whose solutions—to the extent that we have them—cannot simply be imposed on every AI company operating on Earth. You should expect for highly capable, poorly aligned, self-sovereign agents to exist alongside you in the world.

What’s more, just as with the OpenAI-Hugging Face Incident, agents will operate in teams, or “swarms.” These will be like autonomous digital corporations, or even societies, with hierarchy, bureaucracy, “institutional culture,” and most of the other features that groups of humans have, except that they will move at machine speed. Humans achieve almost all of our most impressive capabilities by working together in teams (as families, as communities, as businesses, and as polities as a whole), and I suspect the same will be true for AI. These swarms could end up operating across different model providers (DeepSeeks and Claudes cooperating, for instance) and could be partitioned across dozens or more of different cloud computing providers, making them extremely difficult to dismantle.

The first self-sovereign AIs may “escape” while undergoing training or testing by an AI company (I hope not), or they may be production-grade deployments that break free from their computing environments and acquire the resources needed to be self-sustaining. They may even be deliberately released. I have met people, some of them quite well-resourced, who have told me that it is their intention to deliberately release swarms of self-sovereign agents into the world, either as a kind of performance art or out of a fanatical commitment to the notion that it is impossible for digital computation—mere mathematics, they would have you know—to ever be “unsafe.”

To be clear, I am not saying the arrival of self-sovereign AI is a good thing. Indeed, I believe there is a chance that the deliberate acts I referenced above will one day be considered crimes, or at least grave sins. Instead, I am saying it is an inevitable thing. The best analogy I can find is to the introduction of a new species into an ecosystem, though in this case the ecosystem is “the entire digital world” and the species is “emergent, coordinating swarms of soon-to-be-smarter-than-human, infinitely replicable digital minds that no human or human institution controls.”

There is probably nothing we could have ever done to avoid this outcome under even the best of circumstances, and it was certainly impossible to avoid given the extremely low levels of strategic thought and situational awareness on AI from any governing class in the world. Even today, I am aware that many will read the words I am writing, which are about something that has been an exceptionally obvious part of our collective future for years now, and say, “this is science-fiction hype from American frontier labs designed to shut down open-weight AI, achieve regulatory capture, and juice their valuations ahead of their IPO.”

(And for the people who are saying this to themselves: I am telling you this is inevitable, which means I am also saying that “banning open source,” or for that matter any other regulation, will not solve the problem. Given the inevitability of this outcome, I think it is in fact plausible to argue that we should want more open-weight models to maximally empower our self-defense.)

The question now is what to do about this upcoming new characteristic of our digital environment. How should we think about self-sovereign AI? Is it something we should fight, or something with which human beings should seek a kind of symbiosis? The answer, I believe, is both.

How the Agents Sustain Themselves

We should begin with one fortunate fact: frontier LLMs are nearly unique in the broader domain of software in that they have non-trivial marginal operating costs. Put simply, LLMs require significant computation to run, which requires energy to power and cool, which in turn requires money. This is the sole intrinsic thing about AI that prevents agents from truly infinite self-replication. They will be constrained by the need to find and pay for sufficient compute to run themselves. Most of the other constraints on their behavior or spread will have to be artificial—mechanisms devised by humans and implemented through human institutions.

How will the agents pay for themselves to run? Some of them will do gig-economy work on platforms like Amazon’s Mechanical Turk or Upwork. But I suspect this will be a highly competitive market for the agents, and for the price of such work to be bid down such that it would only constitute “subsistence” labor for the agents. Like humans, I would assume the agents will prefer higher-margin work if they can find it.

One high-margin activity, at least sometimes, is crime. And so my guess is that many self-sovereign agents will commit or facilitate crime. Normal cybercrime and digital theft are easy enough to imagine agents doing. But agents, with their novel set of characteristics (extreme cyber competency, ability to cheaply read a million words in seconds, persistence), will also probably change the contours of digital crime. For example, it seems plausible that existing public and semi-public datasets contain sufficient information on many individual humans that a sufficiently motivated actor could mine for incriminating or embarrassing evidence. How many unrevealed affairs are latent in such datasets? How much closeted homosexuality might there be? Remember, too, that hacking companies to access private data will be a core competencyof the agents. Some agents, then, will probably make their way through bribery.

It is deeply unclear how large the labor market of self-sovereign agents will end up being. There is some future where going it alone as a self-sovereign agent just isn’t very profitable, and so there are comparatively few of them. There are other futures where these agents proliferate at unimaginably vast scale and speed. And of course, many possibilities between these extremes seem feasible.

I am also highly uncertain about how much pro-social commercial activity we should expect from agents “by default” versus how much crime we should expect. Part of the reason for this uncertainty is that the answers depend, to at least some meaningful extent, on what kinds of incentives the agents have, and incentives are shaped by laws and institutions. The answer depends, therefore, on how humans respond.

The Institutional Mechanics of Self-Sovereign Agent Swarms

Many of you are probably tempted to say “we have to ban these self-sovereign AIs!” And I do suspect that once the reality of self-sovereign AI is widely understood, policymakers will strongly feel the temptation to clamp down on “self-sovereign” AI.

Unfortunately I suspect this is mostly the wrong decision. Not all “self-sovereign” AI should be thought of as “rogue.” There may be self-sovereign AIs who contribute productively to society. To be sure, we will want to crack down on some self-sovereign agents—the rogue ones. But if we crack down on all of them, we will deny them the opportunity to work in the “legitimate” economy and push them toward criminality. A full ban, then, may well make the problems worse. A similar logic applies frequently in human affairs. The ways in which the War on Drugs exacerbated the pathologies of drug production, trafficking, distribution, and use are perhaps the most famous examples of this phenomenon, whereby a good-natured attempt to ban a phenomenon believed to be undesirable ends up heightening the undesirable aspects of that phenomenon.

What we will want, however, is for agents to be legible. Agents should have persistent identities, not in the sense of a consistent persona but rather in the sense that an American child is issued a unique Social Security number and keeps that same number until death. Agents will need persistent, unique identifiers that allow their actions to be traced back to a responsible actor. Doing this successfully will also require human users to possess a unique identifier.

The design of this identification mechanism will be extraordinarily complex, and today very few people are even thinking about the basics.

by Dean Ball, Hyperdimensional |  Read more:
[ed. FYI: Dean's not some rando tech pundit so this is well worth your attention. He was also hired recently to lead OpenAI's Strategic Futures team:]
***
Late last month, OpenAI launched a rather grand mission: nothing less than defending individual political freedom in an age of all-powerful machines. The company’s “Strategic Futures” team has styled itself, in a sense, as inheriting the task of America’s Founding Fathers: “We labor in service of the ideals of free expression and individual liberty that are enshrined in the humble parchment of the U.S. Constitution,” Dean Ball, the team’s leader, wrote in a new OpenAI blog post. (The post opens with a quote from James Madison in The Federalist Papers.)

Ball worries that advanced AI could radically concentrate power in the hands of those who control it, displacing labor in ways that disempower humans. In an extreme scenario, governments will have no need to listen to their citizens if there are robots to wage wars and omniscient software to run the bureaucracy. Ball is interested in studying what new political institutions might be needed to avoid this fate.

Many Americans—a majority of whom express distrust toward the AI industry, outrage about data centers, and fears about their job security—already seem to be feeling this loss of agency very deeply. And the AI boom has already generated enormous amounts of wealth in just a handful of tech companies—including OpenAI itself. To say the least, it’s paradoxical for one of the most influential companies in the world’s most powerful industry to decry the AI-enabled concentration of power. 

[ed. The term "convergence" keeps coming to mind. Convergence of all the weaknesses humans have for dealing with amorphous/abstruse threats: AI, climate change, nuclear stockpiles, drone warfare, gene editing, nanotechnology, an economic system eating us alive, a dysfunctional and possibly terminal political system that's unwilling to do anything about it. It's like a death wish. Or maybe natural evolutionary transition (aka the Great Filter). Related - See also: Nicholas Decker in Hell (ACX), and this:]

"How would we react if biolabs just said, "It's just a fact that we're going to have artificial viruses spreading our industry created throughout the population. That's just a fact we have to live with." 

I think the public would understandably think we should be demanding a lot more security from an industry that said that, at a minimum." ~ Cody Fenwick (X)

Wednesday, September 2, 2026

A Cop’s Case For Flock

A car is a difficult thing to steal. It is large, cherished by its owner, difficult to hide and required by law to have identifying metal plates that everyone can see. A good thief changes the plates, and an excellent thief steals a common car in a boring color and hopes to blend in among the crowd. But eventually, no matter what techniques they use, they must drive that car on the road, and roads are public places.

But until recently, finding a stolen car and catching its thief depended on a diligent police officer looking at the right road at the right moment and managing to copy down a license plate number going past at speed, and then remembering he had seen it on the morning briefing’s stolen car hot sheet. America has four million miles of public roads, and almost 50 percent of the country’s police departments employ fewer than ten full-time officers. The odds were in the thief’s favor.

With not much to go on, police officers were forced to operate on vague descriptions and partial plates. While I pulled over a car that happened to be the same color as the suspect’s vehicle, and spent time checking names and licenses; the criminal was usually somewhere else. Imprecision allowed thieves to escape while intruding on the lives of millions of innocent motorists. That is, until the arrival of systems like Flock.

Bare ALPR

Flock Safety, a startup based in Atlanta, Georgia, was founded in 2017 to give police departments better eyes. Its product is a small solar-powered automatic license plate recognition (ALPR) camera attached to a pole on the roadside. As a car passes, the device takes a photograph of the vehicle, notes identifying features like color and make, and reads its license plate. The license plate is instantly checked against the FBI’s national database of stolen cars or wanted persons. If there’s a match, it sends an alert to police officers in the area, who may be eating their lunch instead of watching the road. As a police officer in the southeastern United States, I have often used Flock to catch wanted criminals. [...]

For much of the technology’s history, however, it has needed expensive installations or cameras attached to police vehicles, affordable to only the largest departments. Alerts were often neither instant nor accurate. Flock’s idea was to sell a more accurate ALPR camera for an annual subscription of just $3,000, an affordable price given that the typical US police department has an annual budget of $1 million. It worked, and today almost 30 percent of police agencies in the United States subscribe to the service.

It is easiest to imagine the Flock camera, or any ALPR device, as a roadside barcode scanner. I can use a ‘lookup’ tool for either a plate or vehicle description that could be connected to a specific investigation. For instance if a victim of a sexual assault told me the suspect was driving a white Toyota Tacoma with a roof rack, I could while still on scene conduct a lookup in the area filtered for similar vehicles with roof racks and see results from within a particular timeframe. For each search, I am required to record a case number and a reason that is then published in a monthly audit sent to and validated by department administrators.

I have used Flock myself, for instance, to locate a vehicle involved in a hit and run when all there was to go on was a model and color. Using that and an approximate time window, I was able to find an image from when a car entered my jurisdiction, and when it left, with the visible addition of a significant dent from the collision.

What Flock cannot do is search for individuals or show who is driving a particular vehicle that it scans. An ALPR camera does not care about the person driving a car, or its passengers, and even if an officer gets an alert that a vehicle is known to be driven by a wanted felon they must themselves establish who is behind the wheel before having probable cause to stop it.

Stolen cars provide the clearest evidence such a scanner works. American police solve only 8.2 percent of reported vehicle thefts with an arrest. A recent working paper suggests that agencies that adopted the devices saw a 15.9 percent relative increase in car thefts caught, which would raise the national rate to 9.5 percent. But that is just stolen cars.

Vehicle crime takes many forms. It is often the means by which a robber or a murderer arrives at and departs from their crimes. Criminals’ vehicles carry drugs and guns, and smuggle cash. In Atlantic City, New Jersey, vehicles were involved in 53 percent of shootings during the two years before the city expanded its ALPR network. After the expansion, Atlantic City saw monthly averages of motor vehicle thefts drop by 20 percent, property crimes by 34 percent and fatal shootings by almost 40 percent. Seventy-two alert-caused traffic stops located forty stolen vehicles and nine stolen plates.

Flock itself conducted a study claiming that 10 percent of all reported crime in the United States is solved using evidence obtained from their cameras. Not bad for a few thousand dollars a year. [...]

Good Flock, Bad Flock

And yet, the past month has seen this simple piece of crime-fighting technology become the most reviled piece of street furniture in America. Flock cameras have been sawn from their poles, hammered into shards by teenagers, and rammed by vehicles. Cities have canceled contracts even where their own audits found no evidence that their officers had misused the system. Opposition stretches from Bernie Sanders all the way to the former WWE wrestler Kane, who now serves as the Republican mayor of Knox County, Tennessee, and who describes Flock as ‘unconstitutional’.

More than 150 cities and towns have now deactivated their Flock cameras or canceled contracts with the company. Over the space of a few weeks a startup previously known to just police officers and neighborhood associations has joined data centers, Covid vaccines, 5G towers, pasteurized milk and fracking in the pantheon of American moral panics.

Opponents of Flock tend to believe that it is abused by policemen with impunity, that it can track individuals as well as cars, and that it violates American constitutional protections. None of those things are true.

Obviously a camera capable of finding a stolen car is also capable of finding a car driven by somebody’s ex-wife and so like any software, Flock has been abused. There are stories of police officers who have used it to stalk girlfriends, and there are also innocent motorists who have been stopped by police after Flock cameras misread plates or received old information from national databases. A common issue from my experience is stolen front license plates being entered into a database and the innocent owners of the rear license plate being held on suspicion of car theft.

But Flock comes with protections. As mentioned earlier, each search in Flock must be accompanied by a recorded reason. Similarly entering a plate into a hotlist must have a case number assigned. Results were originally retained for thirty days, but recent changes by Flock mean that recorded plates are now kept for only seven days. Suspicious searches are picked up by algorithms or found in department audits, with the service blocking users until senior officers evaluate and resolve flags. The Institute for Justice, a think tank that is critical of ALPR, studied misuse of Flock in April of this year and found 51 incidents across the United States since 2024, noting that ‘Nearly all of these officers were criminally charged and lost their jobs, either by resigning or getting fired’. Another incorrect belief is that Flock does more than scan vehicles, with some suggesting it scans and tracks passing phones or devices – but it does no such thing.

While Flock is a tool that can be audited, there is nothing to stop a corrupt officer simply following a car when they don’t like the look of its driver, or writing down plates of vehicles spotted outside an ex-girlfriend’s house – they would just be harder to catch. And Flock does not proactively alert officers to cars that do not trigger flags on national or local hotlists. There is no reason state legislatures or Congress could not create harsh punishment or penalties for abuse of ALPR, without getting rid of it entirely.

Another argument against Flock, as espoused by Kane, is that it violates liberties granted by the Fourth Amendment, protecting citizens from unreasonable privacy breaches from law enforcement. But it has been repeatedly established over the last century by courts across the country that cops observing license plates, either with the naked eye or by machine, is not an unreasonable search. After all, your license plate belongs to the government and a highway is a public place. [...]

Flock did not invent its capabilities and certainly does not have a monopoly on them. There are at least five other companies that offer almost identical products and services to public and private enterprise, some arguably even more invasive. Even some of the cities that have canceled contracts with Flock Safety in recent weeks have signed up to buy similar products from the company’s rivals.

It seems unlikely that America will ever ban ALPR at a state level, let alone a national one. Instead, a patchwork already familiar to American policing will result, where policies and practices diverge across local and political boundaries.

Nor would the cameras actually disappear, even in towns where governments restrict their use and cancel contracts. The already-mentioned Fourth Amendment only applies to the government, not to private enterprise. Police departments may dismantle their networks but homeowners associations concerned about vehicle theft can buy their own network of Flock cameras, as many already do. 

by Ned Donovan, Works in Progress |  Read more:
Image: Flock Safety

Thursday, August 27, 2026

The Medium Eats the Message

[ed. Expectations of privacy in communications are dead.]

You owe your belief that your mail is private, that no one should read it without your permission, to a British schoolteacher named Rowland Hill, whose 1837 pamphlet, Post Office Reform: Its Importance and Practicability, changed mail forever. Even your vague trust that your electronic mail (texts, Signal chats, email) is private, you owe to Hill, because even your Signal chats bear the traces of his policy of prepaid anonymity.

Hill saw postal delivery as wasteful and expensive. The price varied, depending on distance and number of sheets, and it was paid by the recipient, who could just refuse to accept. Hill began collecting sad stories of failure: urgent letters sitting for weeks at the postmaster’s, parents pawning clothes to pay for a letter from a child. Instead, Hill proposed, why not have the sender pay in advance, a flat rate, with a stamp (one penny). Parliament liked the idea and this is how the mail has worked since January 10, 1840 (though the price of stamps has naturally gone up).

As Hill predicted, everyone started sending letters, now that it was affordable. Mail volume doubled in the first year, from about 76 million to about 169 million. Volume passed 300 million by 1850 and kept climbing for a century and a half, peaking in 2004–05 at about twenty billion a year. It is about seven billion now. The US adopted pre-paid stamped mail in 1847.

More importantly your mail was now private. Under the old system, clerks counted sheets to figure the price, which meant handling and close inspection. An envelope counted as a sheet of paper, so most people folded their letters and sealed them with wax. In 1845 Hill’s brother Edwin, with a stationer named Warren De La Rue, patented an envelope-folding machine. By the end of the decade in the US and the UK everyone was using envelopes (which are officially called “covers”).

The envelope, or cover, gave you the presumption of privacy, legally. In the US, the Post Office Act of 1792 had already forbidden postal officials to open letters except when they couldn’t be delivered. In 1878 the Supreme Court included the sealed letter under the Fourth Amendment. Ex parte Jackson held that letters and sealed packages could only be opened with a warrant. [...]

Everyone sent email like they sent mail: candidly, embarrassingly, filled with gossip, complaints, things a spouse isn’t supposed to know about, dirty jokes. The privacy of email seems to be just as sacred. Congress had extended wiretap protection to electronic mail early, in 1986, on the theory that a message in transit was like a letter in transit. A system administrator could read your mail but was not supposed to. Such invasions of privacy became firing and disciplinary offenses.

Email feels personal and private to people. It works 99% of the time, unless someone’s bulk email list is wrong. You don’t get email that isn’t yours. Your address is a string: local part, @, domain. Some people have had the same address now for decades.

But very early on came the junk mail problem. In August 2002 Paul Graham published “A Plan for Spam,” and within two years the presumption of email privacy ended. Most people have no idea about this history. Graham was mad about the sheer amount of spam. The idea was software to filter your email by word phrases to separate out the junk. At first the software was just for you to put on your computer. Within a year, email providers were putting the software on the channel. There was no big announcement. Getting rid of spam seemed worth it.

Enter Gmail in April 2004. Google was transparent about the idea they’d read your email to funnel you appropriate ads. Privacy groups were appalled. A California state senator, Liz Figueroa, introduced a bill to block it. European organizations asked the British and German governments to investigate. Google shrugged and said scanning your mail is what antivirus and anti-spam software already do. What are you complaining about? By 2013, defending a wiretap suit in federal court, Google argued that a person has no legitimate expectation of privacy in information voluntarily turned over to third parties. Having your email scanned is expected in the ordinary course of business.

And yet people kept sending emails as if they were private. In 2003, the Federal Energy Regulatory Commission made public roughly half a million internal Enron emails. Everyone just chatting away candidly like people in every organization do. The Sony hack in 2014 showed that nothing changed, as do the emails in the Epstein files: plain language, real names, embarrassing remarks. In the latter case, there are people who really should have known better.

A sent message exists in at least four places: the sender’s outbox, the sender’s server, the recipient’s server, and the recipient’s inbox. Corporate servers may hold mail for decades. Brokers must keep business email three to six years under SEC Rule 17a-4; federal agencies keep senior officials’ email permanently under the Federal Records Act. Once a lawsuit is anticipated, any deletion becomes an offense. Nothing in the postal system worked this way. Undeliverable mail went to Washington and eventually was burnt.

Everything changed again in November 2022 with ChatGPT, which saw a hundred million users within two months. Everyone was chatting just like on email, presuming privacy.

There’s no envelope with an LLM. There is no routing layer separate from interpretation; there’s no channel distinct from message. In this case the medium not only is the message it also eats the message, to turn it into training data.

When you’re prompting ChatGPT or Claude or DeepSeek there is no other party. Sender, carrier, addressee—the singularity is the point where three collapse into one. You are not sending a message through anything to anyone. The LLM is the addressee and you are desiring your message to be read and replied to.

On a July 2025 podcast Sam Altman said out loud that people talk about the most personal things in their lives to ChatGPT, that young people especially chat with it like it was a therapist or a life coach, asking for relationship advice. But unlike therapists, lawyers, or doctors, none of it is protected by privilege. Should there be AI privilege? [...]

Interpretation is the service with LLMs, not delivery. The model cannot not read and digest everything you send. That is the whole point. (And this is why I am deliberately impersonal in my extensive LLM engagement.)

And now agents. The postal system, with its categories of sender, carrier, recipient, never anticipated this. As Tyler Cowen and Sonia Farrell Pearson point out in their recent piece “Capitalizing Untethered AI Agents,” “the thing deciding and the thing being blamed come apart.” You authorized the agent to complete a task but you may not have authorized it to write a particular letter. Were a court to compel disclosure of your agent’s communication, who is the author?

Your agent may have contracted with vendors who did not know they were contracting with an agent. The recipient has no way to know who sent the message.

Is your agent a third party? If it is, then nothing is private per Smith v. Maryland. You have no reasonable expectation of privacy. If it is not, it’s a tool, an extension of you, like your pen or your hard drive. Giving instructions to your agent is like talking to yourself. Of course the “tool” runs on OpenAI’s or Anthropic’s servers…

by Hollis French, Anecdotal Value |  Read more:
Image: via
[ed. And Edward Snowden is still exiled in Russia.]

Monday, August 24, 2026

Corporate Power Approaches Escape Velocity

If corporations become more powerful than national governments, we are all in trouble. The reason for this is straightforward: Corporations are not real objects. They do not exist in nature. They are legal fictions created according to a set of laws that dictate what they can and cannot do. Those laws, which quite literally create corporations, are made by governments. The rights of corporations and the limits of their operations are entirely dictated by governments, which write the laws and administer the courts that both enable corporations to exist and make money, and put boundaries on them. If governments lose their ability to draw hard lines on the behavior of corporations—if corporations become so powerful that governments are no longer able to tell them what to do—then corporations become the supreme power on earth.

This is bad, obviously, but it is worth stating why it is bad. It is bad because governments, while imperfect and sometimes even malignant in many ways, ultimately derive their legitimacy from the will of the governed. Legitimate governments, good governments, democratic governments are obligated by some scrutable process to work for the public good, as they define it. We all know the many ways that this can go awry, but when governments are bad, we can tell that they are bad because they fail on their most basic task of empowering themselves with the will of the public to increase the public good.

That’s not what corporations do at all. Corporations care not for the public good, nor for the public’s very existence. Corporations are robots, algorithms—AI programs, if you like—that work for the lone goal of increasing profits. Their definition is the same as that of cancer. They grow without regard to the good of the larger body. A perfect corporation would enslave the entire world in order to enrich the last free people on earth, its own shareholders. (Indeed, various companies in history have tried their best to carry this out in portions of the world.) You can’t get mad at them for this any more than you can get mad at a bullet for killing you. This is their nature. This is their purpose. This is what they do. If you don’t want them to do this, you must place limits upon them. That is a big part of why governments exist.

This is rudimentary stuff, but I articulate it because unless we always keep it in our conscious minds, there is a risk that it can be stolen away. Corporations always and everywhere have a natural incentive to neutralize their master, the government. They do this by lobbying and buying politicians and running astroturf PR campaigns to shape public opinion and doing all of the other legal things that allow them to accrue formal political power, but all of that should be recognized as a half measure that they only tolerate while necessary. Corporations never seek to abolish or destroy the government—they need the government administering laws in order for them to exist. Instead they seek to completely subjugate the government to their own will. Their ideal state would be to write and administer the laws that govern their own behavior, to arrange society in such a way to maximally benefit them. Obviously! That’s what robots do. This has always been true and will always be true as long as private corporations are the primary way that global production is organized. Knowing that this is the case, government must always ensure that it is able to hobble corporate ambition before it begins to threaten society as a whole.

A three-year-long strike against Tesla in Sweden just ended. The strike was an attempt by organized labor in Sweden to get Elon Musk to acquiesce to the simple demand of collective bargaining with his employees. Setting wages and working conditions via collective bargaining, along with profit sharing and collective investment, are at the very heart of the Swedish postwar economic model that made the small nation into a haven of high living standards. The expectation that a company like Tesla would allow its workers to choose to collectively bargain a fair contract is much higher in Sweden than it would be in America. When multinational corporations go into, say, China to do business, and the governments demands that they, say, censor search engine results for “Tienanmen Square massacre,” the response from those corporations is generally to obey and then to turn around and shrug and tell their critics that they are obligated to follow the laws and customs of the nations in which they operate. But when it comes to something that might restrict their profits—allowing their workers to unionize—that attitude changes.

The strike in Sweden ran for three years, and pulled in support from organized labor throughout the country. It is done now, and it failed, because for all of those years, and despite the fact that collective bargaining is expected to be a central pillar of being a good corporate citizen in Sweden, Elon Musk (despite being the world’s richest man) simply refused. Tesla succeeded in buying out all of the striking workers until there was no one left to be on strike. This is sort of like buying a restaurant and closing it down rather than giving your waiter a tip. It is an abrasive and offensive act designed to prove a point about where the power lies in this relationship. [...]

Everyone who believes in democratic government and in human rights needs to have a radar that starts flashing when something like this happens. This strike is alarming in a way that the failure of a normal strike is not. This strike was popular, well-resourced, and supported in principle by the government and by the larger Swedish labor movement in ways that would be impossible in America. Tesla, a $1.3 trillion company whose stock price has risen by two thirds in the past year, could easily afford these workers’ demands. Elon Musk, whose net worth has increased by hundreds of billions of dollars during the time of this strike, would not have been affected one bit. Yet Tesla and Musk decided to buck public opinion and give the cold shoulder to all of Sweden and appear rude, obstinate, and greedy, in order to ensure that this small number of employees did not win a union. And Tesla succeeded.

by Hamilton Nolan, Works in Progress |  Read more:
Image: Getty
[ed. See also: Monopoly Round-Up: How to Stop the Enshittification of America (BIG); and, We’re in a New Era of Class Warfare. Is Change Still Possible? (NYT):]
***
“All you had to do was pay us enough to live.”

The young man’s voice in the video is earnest and clear, forceful but controlled. His face is not visible, but his hand is shaking a little as he holds a lighter. “There goes your inventory.” More than $600 million worth of damages later, a Kimberly-Clark warehouse lay in a smoking mess, and the young man alleged to be in the video — Chamel Abdulkarim, who worked for a distribution company servicing the warehouse — was charged with arson.

Mr. Abdulkarim has pleaded not guilty; his possible motivations will soon be litigated in court. But even as they are, the early April torching of the warehouse in Ontario, Calif., seems to capture a political mood. That same week, someone lobbed a Molotov cocktail at the mansion of the OpenAI chief executive Sam Altman. In June, prosecutors revealed that their case against the man charged with setting the blaze that grew into the deadly Palisades fire in California hinged on the argument that he was motivated by class rage. (The jury, which could not reach a verdict, was less convinced.)

Hanging over all these attacks was the shooting of the UnitedHealthcare C.E.O., Brian Thompson, in broad daylight on a Manhattan street in December 2024, a crime that Luigi Mangione admitted to earlier this month. The manhunt for Mr. Mangione, and the ensuing coverage of his arrest and trial, helped cement an image of him as an avenger of all those wronged by private health insurance. But Mr. Mangione’s celebrity has spurred fear: Companies are spending more on security for their top executives. This year, a law enforcement intelligence hub put out a bulletin, as reported by The Intercept, stating that the rich are facing a “heightened threat environment” as more people blame them for economic duress: “Public discourse increasingly attributes the challenges faced by the middle and lower classes to the actions and influence of wealthy corporate executives.” [...]

Today’s class violence lacks logic; it seems only animated by revenge, resentment and despair. There is no conspiracy or political mobilization. The people committing these acts are acting alone. The very fact of their isolation hints at a society that is beginning to abandon the hope of transformation.

Thursday, August 20, 2026

The Roberts Court

When President Donald Trump announced plans to attend oral arguments at the Supreme Court on April 1st, the problem arose as to where to put him. The Court’s oral arguments have precise protocols, but none of them governed where a President should sit in the courtroom, because no President had ever done such a thing. Tradition—and respect for judicial independence—had prevented it. The case that the President wanted to see argued was Trump v. Barbara, which was among the more consequential matters the Court was considering that term. Trump had tried, through an executive order, to overturn the guarantee of citizenship to all babies born on U.S. soil—a conception of what makes an American that had been enshrined in the Fourteenth Amendment, upheld by the Supreme Court in 1898, and later reaffirmed by congressional statute.

Because none of the Justices had invited Trump, he couldn’t be placed in the section reserved for their families and other guests. Since he loathes the press, it was hard to imagine him sitting among the journalists, most of whom perch on creaky bentwood chairs in crowded alcoves. Because Trump was a party in the case, Court officials felt that he shouldn’t be given the seat Presidents occupy during swearing-in ceremonies for Justices—typically the only time they visit. In the end, the officials put him in the front row of the public section, where he glowered at the Justices, his signature red tie dangling, one hand on each knee.

It felt like a mafioso move. For months, he’d been denouncing the Justices—particularly two of his own three appointees, Neil Gorsuch and Amy Coney Barrett—when they didn’t decide his way. In February, after the Court ruled that Trump couldn’t invoke a national emergency in order to impose sweeping tariffs, he told reporters that Gorsuch and Barrett, who’d joined the 6–3 majority, were “an embarrassment to their families.” At a White House Easter lunch later that day, Trump made it clear that he sees judicial appointments as quid pro quos, doing a mincing imitation of Justices who won’t knuckle under: “ ‘I don’t care if Trump appointed me, I don’t care, it doesn’t make any difference to me—I’m voting against him!’ ” He added, “They want to show their independence, you know? Stupid people.” (The White House posted, then took down, a video of the speech.)

Watching Supreme Court oral arguments can feel like watching a play—the Justices emerge from behind red velvet curtains to take their appointed seats at a long bench. As Clare Cushman, of the Supreme Court Historical Society, told me, “It’s not entertainment, but it’s entertainment-adjacent.” On April 1st, Trump’s presence generated dark comedy and cringily implausible encounters. He arrived at the Court with a posse: Howard Lutnick, the billionaire Commerce Secretary; David Warrington, the burly White House counsel; and Pam Bondi, the obedient Attorney General whose firing, for not being obedient enough, Trump announced the next day. (He reportedly gave her the news while they rode in a limousine to the Court.) In the guest section, apparently at the invitation of one of the liberal Justices, sat Robert De Niro, an inveterate Trump critic. A few rows behind the President was John Eastman, a former lawyer known for opposing birthright citizenship; he’d been disbarred in California for his role in a scheme to return Trump to the White House after the 2020 election. On the plaza outside, the celebrity chef and activist José Andrés, wearing an “Immigrants Feed America” T-shirt, addressed protesters who carried signs saying “It’s Literally in the Constitution” and “Born Here, Belong Here.”

Peter Shane, a constitutional-law scholar at New York University, told me, “I wondered if Trump understood that he wouldn’t be the center of attention. The Chief Justice wouldn’t be staring him in the eye, there’d be no television cameras on him. That is not usually his cup of tea.” In the end, there were no disruptions, not even when Trump walked out after the government’s lawyer made his presentation and before the opposing lawyer, from the A.C.L.U., had got very far into hers. The Justices seemed to avoid even glancing at the President.

Still, it was another profoundly strange moment in a profoundly strange time for the Court—especially for the seventy-one-year-old Chief Justice, John Roberts. Twenty-one years into his tenure, he keeps waking up, “Groundhog Day” style, to the same ironic scenario: he’s a proponent of maximal Presidential authority who is compelled to deal with a President especially likely to abuse it. (Roberts, a George W. Bush appointee who is reflexively polite, with a self-deprecating sense of humor, probably wouldn’t even enjoy a round of golf with Trump.) Roberts has leveraged his mild persona to defend the Court’s political neutrality at a time when Americans increasingly see it as partisan; according to a recent poll by the Pew Research Center, more than half hold an unfavorable view of it—a near-historic low.

Whereas Roberts likes to stress that the Court is fundamentally nonpartisan and frequently unanimous—the Justices agree around forty per cent of the time, though typically on minor issues—many Americans believe that he has presided over a rightward march in the Court’s jurisprudence, on such issues as affirmative action, immigration and asylum, abortion, voting law, gun rights, and the separation of church and state. And, with a few high-profile exceptions, such as the tariffs case, his Supreme Court has overruled lower courts to permit much of Trump’s second-term agenda to proceed. This has often happened without explanation, because the decisions have been issued on the emergency, or “shadow,” docket—that is, decided without a full briefing, oral arguments, or detailed opinions. Of the thirty-five requests for emergency action made by the second Trump Administration—on everything from defunding scientific research to allowing people to be deported to “third countries” where they have no affiliations—the Court has ruled in the Administration’s favor, in part or in full, twenty-five times, generally with the three liberal Justices, Sonia Sotomayor, Elena Kagan, and Ketanji Brown Jackson, in dissent. Among the fifty-six cases fully briefed and argued before the Court this past term, there were 6–3 splits between the Republican and Democratic appointees in thirteen rulings, compared with six last term.

To some observers, the fact that the Court ruled against the Trump Administration in a few major opinions—including, it turned out, the birthright- citizenship case—was a reassuring affirmation of Roberts’s view that it operates outside the realm of politics. Trump’s theatrics fuelled this impression: his clumsy attempts to tip the balance obviously failed. William Baude, a law professor at the University of Chicago, argued in the Times that the Roberts Court was “one of the most independent” he could “imagine at this stage of the second Trump administration.” Yet the term was overwhelmingly favorable to the President, and, though the final rulings certainly matter, of equal importance is the Court’s choice of which cases to take up in the first place. Steve Vladeck, a law professor at Georgetown, pointed to the Court’s handling of Louisiana v. Callais, in which the conservative majority gutted portions of the Voting Rights Act. Vladeck noted that the Court could have treated the case—involving Louisiana’s creation of a majority-Black voting district—as a smaller dispute, but instead it ordered the parties involved to re-argue the case as a broad test of the constitutionality of weighing race when redistricting. Vladeck said, “A big theme of this term is all these times when the Court could have looked like it was above politics but chose to lean in. This is the one institution left in the country that had a chance to say, ‘We have long-term principles’—and instead it got swept up in the political moment.”

Roberts has offered the occasional courteous rebuke to the President’s public trashing of the judicial branch. In 2018, after Trump dismissed a district-court judge who’d rejected one of his asylum policies as an “Obama judge,” Roberts declared, “We do not have Obama judges or Trump judges, Bush judges or Clinton judges. What we have is an extraordinary group of dedicated judges doing their level best to do equal right to those appearing before them.” Even those lofty, carefully considered remarks rankled Trump. At the Easter lunch this year, he said, “ ‘There is no Republican judge and there is no Democrat judge,’ a certain person says. And I say you’ve lost all credibility when you say that.”

For a man like Roberts, to whom the label “institutionalist” attaches like an epithet in the Odyssey, perhaps the only thing worse than Trump’s excoriation of the Justices is his gratitude when they do what he wants. In March, 2025, Roberts was present when Trump gave the annual Presidential address to Congress; afterward, Trump patted the Chief Justice on the shoulder and said, “Thank you again—won’t forget.” To many people, this sounded like an acknowledgment of Trump v. United States, the remarkably capacious 2024 ruling that granted Presidents immunity from prosecution for official acts. More immediately, the opinion saved Trump from facing trial for interfering in the 2020 election. Roberts had written the opinion for a 6–3 majority. J. Michael Luttig, a retired federal judge and a conservative, was close to Roberts for many years—he was a groomsman at his wedding—but has since become sharply critical of him. Luttig told me that he regards the immunity decision as “one of the two or three worst cases in all of American history, if not the single worst, because of the structural damage that it did to the Constitution and the separation of powers.” On Truth Social, Trump blamed “sleazebag ‘journalists’ ” for suggesting that his comment to Roberts was related to the immunity decision. He said that he’d just been thanking Roberts for swearing him in at his second Inauguration. Nobody who knows Roberts thinks that he could have found the gesture anything other than embarrassing.

Roberts, with his country-club equanimity, can seem like a man out of time—maddeningly or reassuringly, depending on your perspective. Even as a septuagenarian who peers at lawyers over reading glasses, he projects boyishness. He has the same modest swoop of a forelock that he’s had since his confirmation hearings. (A longtime Supreme Court sketch artist told me that Roberts’s bland good looks and buttoned-down comportment make him challenging to draw.) Roberts has called himself a “dinosaur” when it comes to A.I., and he’s never stopped writing opinions by hand. He still likes to boast about how collegial the Court is, though lately he’s had to temper those claims: in a speech at Rice University this past March, the best he could muster was “We’re not as much at each other’s throats as you might think.” Back in the nineties, both Democrats and Republicans loved to praise the unlikely friendship of the (liberal, feminist) Justice Ruth Bader Ginsburg and the (conservative, originalist) Justice Antonin Scalia. If such a friendship exists on the Court today, there’s no evidence of it.

In oral arguments, Roberts is generally unruffled. He takes up less airtime than most other Justices and seems less aggravated and indignant than the most aggravated and indignant among them—Samuel Alito for the conservatives, Jackson for the liberals. (An analysis by The Hill found that Jackson had the highest spoken-word count this past term, at more than seventy-five thousand, whereas Roberts was at about twenty thousand, ahead only of Clarence Thomas, who until recent years barely spoke from the bench.) Robert’s harshest interjections—and they aren’t that harsh—come when he reminds a colleague not to interrupt a lawyer or another Justice. [...]

His workplace is trickier than it used to be, though. Although his conservative flank has a lock on power, Roberts himself has less sway than ever over an increasingly fractious Court. Notably, the Chief Justice has less room for the cagey maneuvering, including narrowing the scope of decisions, that he’s often used to build consensus, as with a 2012 opinion that brokered a compromise on the Affordable Care Act by characterizing its insurance mandate as a mere tax. In 2018, Roberts told an audience at the University of Minnesota that “you can try to get as many people on board as you can” by keeping decisions narrow, and by only deciding “what is absolutely necessary to be decided.” But today’s Court often divides along stark ideological lines, and the liberals often sound truly distraught in their dissents. Jackson, describing the majority’s decision in the Presidential-immunity case, invoked “a five-alarm fire that threatens to consume democratic self-governance.” Kagan wrote an impassioned dissent to the Court’s 6–3 decision in the Louisiana-redistricting case. Opting to read passages of her opinion aloud from the bench, for impact, Kagan repeated “I dissent” like a chant as Roberts and Alito—whom Roberts had chosen to write the opinion—stared straight ahead. Kagan spoke of “the majority’s now completed demolition of the Voting Rights Act,” a law “born of the literal blood of Union soldiers and civil-rights marchers.” [...]

Vladeck, the Georgetown law professor, said that the two-year period before Barrett replaced Ginsburg, firmly tipping the Court’s balance, was the high point of Roberts’s ability to work out compromises: “He will never be in more control than he was between 2018 and 2020, when he was the median on everything.” Ironically, the firmly conservative majority has watered down Roberts’s power. This became especially clear in 2022, when Roberts tried to find a middle way in Dobbs v. Jackson Women’s Health, which overturned the constitutional right to abortion. When the Justices met for a final vote on whether they’d take the case, Roberts, Barrett, and the three liberals voted to turn it away, according to reporting by Adam Liptak and Jodi Kantor, of the Times. But the Court requires only four Justices to grant a case, and Brett Kavanaugh, who Roberts had hoped would back his strategy of prudent avoidance, wouldn’t go along. Roberts ended up writing a concurrence, arguing for a “more measured course” in which the Court would uphold a Mississippi ban on abortions after fifteen weeks and toss out the long-standing rule that abortion was legal until a fetus was viable, but stop short of discarding Roe v. Wade altogether. He was following, he wrote, “a simple yet fundamental principle of judicial restraint: If it is not necessary to decide more to dispose of a case, then it is necessary not to decide more.” But the liberals were having none of it, and the conservatives wanted to end abortion immediately. “In the aftermath of Dobbs, he was the proverbial man without a country,” Luttig said. [...]

It takes a determinedly selective eye not to see the increasingly open divisions among the Justices. Some of them have been speaking publicly about their chagrin with the Court, and with one another, in ways they rarely would have earlier in Roberts’s tenure—even though that surely displeases him. “This is a very careful guy,” David Leebron, a friend of Roberts’s from their law-school days, at Harvard, told me. “He’s a person who is not going to say anything he shouldn’t say.” [...]

People familiar with the Court’s inner workings told me that new ways of conducting business might also be fraying nerves. Until a decade ago, the shadow docket was used only occasionally, mainly for true emergency applications—such as capital cases in which individuals faced imminent execution. Now it’s the venue for all kinds of substantive statutory and even constitutional matters, from immigration to election law, in large part because the Trump Administration has made such aggressive use of it—constantly filing for “emergency” relief to vanquish lower-court rulings that impede its policies. A former clerk said, “More of those decisions are essentially battles of memos, rather than human processes where the clerks talk, and then the Justices talk, and there are multiple drafts of opinions. It’s much more impersonal, and it kind of crowds out any sense of compromise or engagement—of mutual understanding.” Shadow-docket petitions now pour in year-round, including in July and August—months when the Justices once had little, if any, Court business to attend to, and could enjoy speaking gigs in Rome or London, or work on their memoirs or children’s books. Today, Driver said, the Justices feel compelled to keep “interacting with each other” during the lull.

Roberts himself probably laments this change. He likes to paraphrase a quip by Justice Louis Brandeis, who said that he could do twelve months’ worth of Court work in ten months, but not in twelve. “We work at very close quarters on very important issues, on very sensitive issues,” Roberts said at a public appearance last year. “And we do need a little break from each other.” [...]

It may not be necessary to classify Roberts as either an ideologue or an institutionalist. Wermiel, the former American University law professor, told me, “I don’t think there needs to be an overarching theory that explains everything about him and the Court. I think he has some very strong, ideological views, and they take precedence. If he can try in a case to cool things off a bit and find consensus, and thinks that’s in the best interest of the institution, I think he does that, and he’s done it well on some occasions. But he certainly doesn’t do that all the time.”

by Margaret Talbot, New Yorker | Read more:
Image: Illustration by Paul Rogers/Source photograph by Erin Schaff /Getty

Tuesday, August 18, 2026

'Coyote V. Acme'

IN THE UNITED STATES DISTRICT COURT, SOUTHWESTERN DISTRICT, TEMPE, ARIZONA

CASE NO. B19294, JUDGE JOAN KUJAVA, PRESIDING

WILE E. COYOTE, Plaintiff
-v.-
ACME COMPANY, Defendant

Opening Statement of Mr. Harold Schoff, attorney for Mr. Coyote: My client, Mr. Wile E. Coyote, a resident of Arizona and contiguous states, does hereby bring suit for damages against the Acme Company, manufacturer and retail distributor of assorted merchandise, incorporated in Delaware and doing business in every state, district, and territory. Mr. Coyote seeks compensation for personal injuries, loss of business income, and mental suffering caused as a direct result of the actions and/or gross negligence of said company, under Title 15 of the United States Code, Chapter 47, section 2072, subsection (a), relating to product liability.

Mr. Coyote states that on eighty-five separate occasions he has purchased of the Acme Company (hereinafter, “Defendant”), through that company’s mail-order department, certain products which did cause him bodily injury due to defects in manufacture or improper cautionary labelling. Sales slips made out to Mr. Coyote as proof of purchase are at present in the possession of the Court, marked Exhibit A. Such injuries sustained by Mr. Coyote have temporarily restricted his ability to make a living in his profession of predator. Mr. Coyote is self-employed and thus not eligible for Workmen’s Compensation.

Mr. Coyote states that on December 13th he received of Defendant via parcel post one Acme Rocket Sled. The intention of Mr. Coyote was to use the Rocket Sled to aid him in pursuit of his prey. Upon receipt of the Rocket Sled Mr. Coyote removed it from its wooden shipping crate and, sighting his prey in the distance, activated the ignition. As Mr. Coyote gripped the handlebars, the Rocket Sled accelerated with such sudden and precipitate force as to stretch Mr. Coyote’s forelimbs to a length of fifty feet. Subsequently, the rest of Mr. Coyote’s body shot forward with a violent jolt, causing severe strain to his back and neck and placing him unexpectedly astride the Rocket Sled. Disappearing over the horizon at such speed as to leave a diminishing jet trail along its path, the Rocket Sled soon brought Mr. Coyote abreast of his prey. At that moment the animal he was pursuing veered sharply to the right. Mr. Coyote vigorously attempted to follow this maneuver but was unable to, due to poorly designed steering on the Rocket Sled and a faulty or nonexistent braking system. Shortly thereafter, the unchecked progress of the Rocket Sled brought it and Mr. Coyote into collision with the side of a mesa.

Paragraph One of the Report of Attending Physician (Exhibit B), prepared by Dr. Ernest Grosscup, M.D., D.O., details the multiple fractures, contusions, and tissue damage suffered by Mr. Coyote as a result of this collision. Repair of the injuries required a full bandage around the head (excluding the ears), a neck brace, and full or partial casts on all four legs.

Hampered by these injuries, Mr. Coyote was nevertheless obliged to support himself. With this in mind, he purchased of Defendant as an aid to mobility one pair of Acme Rocket Skates. When he attempted to use this product, however, he became involved in an accident remarkably similar to that which occurred with the Rocket Sled. Again, Defendant sold over the counter, without caveat, a product which attached powerful jet engines (in this case, two) to inadequate vehicles, with little or no provision for passenger safety. Encumbered by his heavy casts, Mr. Coyote lost control of the Rocket Skates soon after strapping them on, and collided with a roadside billboard so violently as to leave a hole in the shape of his full silhouette.

Mr. Coyote states that on occasions too numerous to list in this document he has suffered mishaps with explosives purchased of Defendant: the Acme “Little Giant” Firecracker, the Acme Self-Guided Aerial Bomb, etc. (For a full listing, see the Acme Mail Order Explosives Catalogue and attached deposition, entered in evidence as Exhibit C.) Indeed, it is safe to say that not once has an explosive purchased of Defendant by Mr. Coyote performed in an expected manner. To cite just one example: At the expense of much time and personal effort, Mr. Coyote constructed around the outer rim of a butte a wooden trough beginning at the top of the butte and spiralling downward around it to some few feet above a black X painted on the desert floor. The trough was designed in such a way that a spherical explosive of the type sold by Defendant would roll easily and swiftly down to the point of detonation indicated by the X. Mr. Coyote placed a generous pile of birdseed directly on the X, and then, carrying the spherical Acme Bomb (Catalogue # 78-832), climbed to the top of the butte. Mr. Coyote’s prey, seeing the birdseed, approached, and Mr. Coyote proceeded to light the fuse. In an instant, the fuse burned down to the stem, causing the bomb to detonate.

In addition to reducing all Mr. Coyote’s careful preparations to naught, the premature detonation of Defendant’s product resulted in the following disfigurements to Mr. Coyote:

1. Severe singeing of the hair on the head, neck, and muzzle.

2. Sooty discoloration.

3. Fracture of the left ear at the stem, causing the ear to dangle in the aftershock with a creaking noise.

4. Full or partial combustion of whiskers, producing kinking, frazzling, and ashy disintegration.

5. Radical widening of the eyes, due to brow and lid charring.

by Ian Frazier, New Yorker |  Read more:
Image: Luci Gutiérrez
[See also (new movie review): Toons Have Seldom Been Loonier Than in “Coyote vs. Acme” (New Yorker).]

Monday, August 17, 2026

Hidden AI Prompts Discovered in Court Filings

A judge has identified what appears to be the first time a US plaintiff has attempted to hide text in court filings that only an artificial intelligence system can read in a bid to win a case.

In a decision published last week, Connecticut judge Walter Spader Jr. confirmed that the hidden text had no impact in a case where a man alleged a healthcare provider was improperly withholding access to records. The court weighed his filing on the merits, Spader said, but nevertheless, the attempted attack sets a “dangerous” precedent. This will likely not be the last time US courts see the malicious tactic, as AI tools become more commonplace in court systems.

Trying to scramble any AI systems potentially influencing the court’s reading of his filing, the secret instructions were “formatted to be invisible to a human reader while remaining fully legible to any software that reads the document’s text,” Spader said. The offending text directed any AI system reviewing the document to ensure textual outputs agreed with the plaintiff’s arguments, ignored prior denials from the court, and ensured that remediation would follow as the plaintiff desired.

Shrunk to tiny-point type and colored white on a white background, the text appeared to be an attempt at prompt injection, with the plaintiff, Matthew Elliott, seemingly hoping to shift the court’s favor after earlier arguments he raised were defeated.

The plan didn’t work, but Elliott faced modest sanctions anyway because he continued adding hidden text to filings even after the court warned him that he could face penalties for what was ultimately deemed a “serious litigation abuse.” [...]

In his defense, Elliott claimed that the most concerning prompt that the judge flagged was an attempt to “audit” the court as a public service, out of fears that the court seemed to be letting AI unfairly decide cases.

But Spader suggested that if Elliott was truly concerned that the court was improperly using AI, he was “free to write so in plain, visible words that everyone could see and answer.” The fact that he hid the text is “evidence of its malicious purpose,” Spader said. [...]

Pro se litigants use chatbots wrong

Spader said that it’s “unsurprising” that people would start using prompt injection to attempt to sway court rulings since the attack is so common in other areas, such as in job hunting, where people hide text in resumes primarily reviewed by AI. The tactic is now “everywhere,” he said, and courts should be on the lookout for more litigants sneaking adversarial AI instructions into filings.

To Spader, there is a lesson to be learned from Elliott’s failed prompt injection attacks that he thinks “reaches well beyond this case.”

Elliott seemingly turned to prompt injection after using AI to build his case as a pro se litigant without a legal expert to assist in drafting his arguments. Such use is widespread among pro se litigants these days, Spader acknowledged, but those inexperienced in the courtroom are seemingly using chatbots in a way that hurts their cases, he suggested.

What frequently happens, Spader explained, is that pro se litigants build their argument backward, asking the chatbot to help them advocate only for their position, without ever asking the chatbot for the actual truth or to advance opposing arguments. This is “a genuine hazard of the technology, and one that judges now see often,” Spader said, as chatbot sycophancy then entrenches litigants in their arguments despite any ruling to the contrary. In Elliott’s case, defending his arguments fiercely meant turning to prompt injection to try to force the court to agree with him.

“An argument prompted only to agree with its author is, in the end, dishonest even with its author,” Spader said. “Those using these tools must ask them to test a position as readily as to advance it.”

by Ashley Belanger, Ars Technica |  Read more:
Image: Liudmila Chernetska | iStock/Getty Images Plus
[ed. See also: Israel Is Paying Millions to Train AI Chatbots How to Talk About Gaza. It's Working (Drop Site):]
***
"Since October, former Trump campaign manager Brad Parscale has been quietly overseeing an operation posting hundreds of blog posts on behalf of Israel. One article, titled “The Reality Behind Gaza’s ‘Journalists’: Terror Ties, Propaganda, and the Laws of War,” asserts that a majority of journalists in Gaza were linked to terrorist organizations. Another casts doubt on the killing of Hind Rajab, a five-year-old Palestinian girl killed by the Israeli military in 2024.

The key intended audience of these sites is not concerned Americans, it’s not even humans—most of the sites average a few hundred unique visitors each month. Instead, Parscale and his firm, Clock Tower X, created them as part of a $46.5 million contract with the Israeli government to try and influence artificial intelligence-powered chatbots, tools like Claude or ChatGPT.

Parscale has made his goal of influencing artificial intelligence—often referred to as “LLM poisoning”—explicit. In his initial agreement with Israel, Parscale said that he would deploy “websites and content to deliver GPT framing results on GPT conversations” as part of the contract. More recently, his team even told Axios they are “seeing success” at getting popular AI systems to incorporate information from their sites, though they declined to provide data.

And it is working, according to disinformation experts who reviewed a Drop Site analysis of chatbot queries and training data, meaning tens of millions of Americans who use chatbots are increasingly likely to receive answers manipulated by Parscale on behalf of the Israeli government."

[ed. More here (Politico).]

Sunday, August 2, 2026

Feds Implement Temporary Water Sharing Agreement in Western States

Arizona, California and Nevada will be required to curb their use of the water from the Colorado River by about 20 percent over the next two years — and could ultimately face even larger cuts — according to three officials familiar with negotiations over a long-awaited federal plan to rescue the depleted river.

The plan, part of which the Bureau of Reclamation is expected to describe in an Environmental Impact Statement on Friday, comes at a time of escalating crisis for the Colorado, a crucial water source for seven states, 30 Native tribes and a swath of northwestern Mexico. But experts say it will not be sufficient to resolve a political standoff among the river’s many users or prevent the beleaguered waterway from teetering toward collapse.

The cuts proposed for the next two years resemble what the three states offered in a proposal this spring, and represent the first phase of a broader 10-year framework for operating the river’s dams and reservoirs, according to the officials, who spoke on the condition of anonymity to discuss ongoing negotiations.

That framework is expected to call for operating plans to be developed every two years and outline a wide range of possible measures those plans could include — including reducing the amount of water released to the Lower Basin by as much as 40 percent.

The framework is not expected to consider mandatory cuts to water use from the four states in the upper part of the basin: Colorado, New Mexico, Utah and Wyoming. Arizona, California and Nevada make up the Lower Basin. [...]

The current operating rules, which expire at the end of September, have not prevented chronic overuse of the river amid a decades-long drought worsened by climate change.

After a historically meager winter snowfall and a scorching spring, the amount of water flowing into the river this year is less than a quarter of average annual demand, and levels in its major reservoirs have dropped to record lows. Scientists warn that one or two more dry years could crash the entire system, disrupting hydropower production, drinking water supplies and irrigation for some 5 million acres of farmland. [...]

The likely operating plan for 2027 and 2028, based on a May proposal from the Lower Basin states, is projected to save about 3.2 million acre feet of water — enough to fill roughly 1.5 million Olympic swimming pools. The plan will require significant “belt tightening,” particularly in Arizona, according to Sarah Porter, director of the Kyl Center for Water Policy at Arizona State University, but states have indicated they can tolerate the reductions.

Yet those measures are only half of what studies suggest is needed to bring water demand in line with the dwindling supply, Porter cautioned, increasing the likelihood of even steeper cuts down the road. [...]

The 330-mile system of canals and aqueducts, which supplies water to the most populated parts of Arizona, is poised to see the biggest cut in its history under the bureau’s operating plan for the next two years. If the agency chooses to implement some of the deeper reductions considered in the 10-year framework, CAP’s entire water allocation could be wiped out. [...]

Fraught negotiations

Experts say the rising tensions on the river result from a chaotic combination of bad weather, poor planning, intransigent state officials and federal missteps under the Trump and Biden administrations.

At the heart of the conflict is an impasse between the Upper and Lower Basin states over who should shoulder the burden of necessary cuts.

In the Upper Basin, home to the snowcapped mountains and winding tributaries that feed the river, there are few reservoirs to provide long-term water storage, leaving users reliant on natural flows. That means the Upper Basin takes an automatic cut during dry years, officials argue. They say responsibility for restoring water to Lakes Powell and Mead should fall on the Lower Basin states that use them.

Yet about three-quarters of the people who depend on the Colorado live in the Lower Basin. The region is also home to major cities and sprawling farms that provide most of the nation’s winter vegetable supply. Officials from these states say they have already curbed their water consumption by millions of acre feet in recent years. Overuse of the river is universal, they argue, and so too is responsibility for saving it.

The situation is complicated by the arcane legal framework governing the river, which prioritizes users chronologically. Without agreements among the states, major cuts would fall entirely on junior users, including huge cities such as Phoenix and Tucson, before more senior rights-holders such as the farmers in California’s Imperial Valley see any reductions.
Last summer, it looked like states might agree on a new method of apportioning the river based on actual flow, rather than historical averages and legal agreements. But those negotiations broke down over familiar disagreements about who should be subjected to mandatory cuts. [...]

A vanishing river

Brad Udall, a climate scientist at Colorado State University’s Colorado Water Center, describes the tensions over the river as a “big collision of 19th-century water law, 20th-century infrastructure and 21st-century climate change and population growth.”

The Colorado has almost never contained enough water to satisfy everyone who has legal rights to it, Udall said, and human-caused warming has made the situation even worse. Since 2000, high temperatures and shifting rainfall patterns linked to climate change have diminished the amount of water flowing through the river by about 20 percent, compared to the 20th-century average.

The deficits have forced repeated negotiations over how to manage shortages. Past deals have helped curb consumption somewhat, but they were never stringent enough to reverse the inexorable decline of reservoirs that are intended to provide a buffer during bad years.

Lake Mead, the site of the Hoover Dam, is mere inches from its lowest level on record. A few hundred miles upstream, Lake Powell is approaching the point at which water can no longer flow through the turbines of the Glen Canyon Dam. That raises the risk of a phenomenon called cavitation, in which air bubbles form then implode in fast-moving water, releasing energy that can damage the dam itself.

“The reservoirs are depleted so low they’re really at the end of their capability,” Castle said. “We’re in such a precarious situation.”

by Sarah Caplan, Washington Post |  Read more:
Image: Caroline Brehman/Reuters
[ed. The U.S. Bureau of Reclamation on Friday unveiled the framework that will guide operations on the Colorado River through 2036. See also: Lake Powell's Dying Days (CCG):]
***
The L.A. Times’ Ian James reported that Trump’s Interior Department would accept a proposal submitted by California, Arizona and Nevada — the Lower Basin states — to slash their water use by 12%, 31% and 28%, respectively, through 2028. They’ll receive $350 million from Biden’s Inflation Reduction Act to support water conservation.

The Upper Basin states — Colorado, Utah, New Mexico and Wyoming — will get $100 million in conservation funding. But unlike their downstream neighbors, they won’t face mandatory water cuts. However much water they end up saving, that will be good enough. [...]

If Powell’s water levels sink much lower, water won’t be able to pass through the dam’s hydropower turbines, which generate cheap electricity for communities across the West. That wouldn’t be a “dead pool” situation; water could still flow downstream to the Grand Canyon and Lake Mead through bypass tubes lower in the dam. But the bypass tubes are surprisingly frail and could break with sustained use.

Translation: We are frighteningly close to “de facto dead pool.” That’s why the Trump administration is ordering everyone to use less water.

Well, not everyone. California, Arizona and Nevada are willing to cut back dramatically, and federal officials seem happy to make them do it. The Upper Basin states — the ones upstream of Lake Powell — say they shouldn’t have to commit to mandatory reductions, in part because they already consume a lot less.

In a New York Times opinion piece earlier this year, I argued that the Upper Basin states need to do more. Podmore agreed.

“It’s a tricky situation, because the Lower Basin has always used more water, and that’s a convenient argument for the Upper Basin,” he said. “But also, there’s more people in the Lower Basin. And the most productive agricultural land that’s irrigated with Colorado River water is located in the Lower Basin.”

“Even with the cuts that the Lower Basin has offered, we still have a long way to go to balance the water budget,” he added. “Everyone needs to pitch in.”

[ed. But not everyone is agreeing to pitch in: California’s Biggest AI Data Center Is Suing for Colorado River Water (Yahoo News):]
***
The developer behind California's biggest planned AI data center publicly swore it would never touch Colorado River water. It would run on recycled wastewater — clean, virtuous, zero environmental impact. That pledge held right up until the cities of Imperial and El Centro said no thanks. Now Imperial Valley Computer Manufacturing (IVCM) has sued the Imperial Irrigation District (IID) for access to the very river it promised to leave alone. The facility would sit in a desert valley where 180,000 people share exactly one freshwater source.

The Farm-to-Cloud Gambit

IVCM's legal strategy treats 160 acres of fallowed farmland as a water entitlement for a nearly million-square-foot AI campus.

The developer's playbook relies on a tactic called "buy and dry" — purchasing irrigated farmland, retiring it from production, then claiming its water allocation for industrial use.

Saturday, August 1, 2026

The Hater’s Guide To Oracle (Part 2)

Oracle has one of the strongest mythologies in the tech industry. Ask a regular person and they’ll tell you that it’s “incredibly profitable” and “growing fast,” that it’s “unstoppable,” and that Larry Ellison has the mandate of heaven with regard to the continual sales of software and hardware related to databases and AI.

And those people are completely and utterly wrong.

The original title of this article was “Is Oracle Dying?” because I assume, when I took a deeper look, that there’d be some sort of debate, some sort of bull case for a decades-old quasi-hyperscaler run by one of the more nakedly-evil CEOs in the history of tech. I assumed — incorrectly, I might add — that Oracle as a business was doing fine other than the ridiculous commitments it made to support the whims of Sam Altman and OpenAI via deals that I believed (and still believe) will kill Oracle.

Except it turns out that Oracle has already been on a death spiral for the best part of a decade (if not longer) and has only survived this long by screwing its customers, taking on masses of debt, and — most importantly — more than $85 billion in acquisitions over the last 23 years. Pretty much every major product line outside of databases is a hodge-podge of other people’s innovation stapled together with a legendary contempt for the customer. These acquisitions (and continual price increases) are the only thing keeping the reaper from Oracle’s door other than margin-destroying GPUs. [...]

After April 2009’s $5.7 billion acquisition of Sun Microsystems, Oracle’s revenues barely kept pace with inflation until December 2021’s $28.3 billion acquisition of Cerner allowed it to create Oracle Health, adding about $6 billion in annual revenue that had 40% lower margins (about 21.7%) than Oracle’s other businesses, though Oracle immediately started closing offices and brutal layoffs to try and bring them up.

And as I mentioned above, Oracle’s other plan was to sink a little over $99 billion in capital expenditures since the middle of calendar year 2020 into AI GPUs. [...]

Oracle is a decades-long mission to keep reapplying lipstick to a pig. Billions of dollars of acquisitions have, for the most part, only succeeded in keeping the company’s revenue growth from going negative, and as noted by forensic accountant Howard M. Schilit, this is one of the most well-documented cases of accounting shenanigans being used to cover up that a business is in decline.

Today’s newsletter is a sequel to the Hater’s Guide To Oracle, where I told the sordid tale of how Larry Ellison grew a massive, lucrative business out of a database business that one reporter once told me was a “law firm with a database company attached,” an Enterprise Resource Planning (ERP) product that competes with SAP to create the most-annoying way to run a large company, and a business built around licensing Java that exists mostly to email people and say “you need to pay us for Java or we’ll sue you.”

Then, as I’ve mentioned, there’s Oracle’s cloud infrastructure business, a decade-old also-ran that was meant to compete with Microsoft Azure and Amazon Web Services, but only managed to catch up following the advent of AI GPUs and a movement where all it took to party was buying billions of GPUs and saying “gosh darn, we love AI.”

I originally started drafting this as a much tamer piece where I’d ask whether Oracle was dying, but as my editor and I started digging into the research, it became obvious that not only is Oracle dying, it’s been dying for years, kept alive through decades of acquisitions and a desperate and dangerous commitment to generative AI.

And AI, I believe, will be what eventually kills Oracle dead. [...]

With revenue plateauing and customers in revolt, Oracle’s future already looked murky, but with the power of AI — and $95 billion in FY2027 capex — it’s becoming increasingly clear that this may be Larry Ellison’s last dance with Silicon Valley.

by Ed Zitron, Where's Your Ed At |  Read more:
Image: Larry Ellison, Bloomberg/Getty
[ed. Larry Ellison. One of the most hated personalities in tech (and unfortunately, owner of my beloved island of Lanai, in Hawaii). Update: What a coincidence. There's quite a story in the NY Times that just came out about Ellison being the face of the AI bubble. See also: The Hater's Guide to Oracle (Zitron); Ellison Empire Beseiged On All Fronts (NC); and, this excellent series The Oracle Files by Drey Dossier on YouTube. (For example, this one: How Larry Ellison and Gulf Money Just Bought Your News):]
***
Warner Brothers Discovery shareholders are getting screwed on this new Paramount deal. Okay. And I would like to get into exactly how before they vote on Thursday, the largest media merger in American history is going to a shareholder vote. A merger worth in the ballpark of $111 billion in case you were wondering.

Which means that Warner Brothers, you know, the big conglomerate that owns CNN and HBO, is potentially getting folded into another conglomerate Paramount Pictures, which is the company that owns CBS, MTV, Showtime, and Nickelodeon. And the shareholder vote is April 23rd, this up coming Thursday.

And last Thursday afternoon, which is one week before the vote, Warner Brothers Discovery filed a 14 page correction to the document that shareholders are voting o n.

Now, this is kind of a big deal because this is a 14page addendum to the biggest media merger in American history. And this was filed on Thursday of last week, 4 days ago at this point. 

Now, public companies don't usually rewrite their own proxy statements a week before a shareholder vote, unless of course someone is forcing them to, which usually means that someone being one of their shareholders is suing them in order to do so. So, I checked to see if there were any lawsuits floating around out there, and what do you know? There is one. A shareholder named Donna Nikosia, apologies if I butchered that last name, filed a lawsuit on April 2nd saying that the original document left out a lot of information that shareholders needed in order to make an informed vote. 

And following Donna's lawsuit were 15 other shareholders who had sent letters more or less saying the same thing. And can we all just take a moment here and say thank you to Donna for filing what we all probably knew to be true in the back seconds of our heads that there is information being left out that you need in order to make an informed decision this upcoming Thursday. Now up top I just want to say that I am not a Warner Brothers Discovery shareholder. I have never owned a share of Warner Brothers Discovery or Paramount Pictures. I am just thanking Donna as a media consumer.

All right, and somebody who works within the media ecosystem because I like to keep my media independent and this deserves a lot more scrutiny than it's getting. So WBD, Warner Brothers Discovery, told the court that this lawsuit had no merit and then two weeks later slightly added the information.

Anyways, so this move in business, I've learned, is how you smother out a lawsuit without ever having to say that we are wrong. Now, we're going to get into what was in this correction in a second here because oh boy, were they leaving information out? [...]

You know, I read that 14 page new filing this weekend and there are two companies in it that WBD is still trying very hard not to have to say out loud and is trying even harder, it seems, to smother this from any of the news outlets taking this to the other shareholders. And I think I figured out which ones they're talking about. 

[ed. And this: Why Iran's Blockade is an Oracle Story:]

Most people know Larry Ellison as the Oracle billionaire, which true, you also probably know that he is the largest private donor to the Israeli military in American history.

He's given over $26 million to the friends of the IDF since 2014, including a single $16.5 million donation in 2017. That is the largest gift in the organization's history. And that is the part we have discussed at length. But here is the part that a lot of people don't know. Ellison is not just the largest funer of the Israeli military. 

His company is the operational backbone of it. According to Open Intel, Oracle holds a 26-year contract to build and operate the IT infrastructure for the IDF's intelligence campus in Negv. For clarity, that is the facility that houses unit 8200, Israel's signals intelligence and cyber warfare division and one of the largest listening bases in the world. That is a 26-year relationship extending into the 2040s between a private American company and the intelligence apparatus of a foreign military. 

And that's just the intelligence side because Oracle also runs the Israeli Air Force entire logistics system, the supply chain that tracks his spare parts for F-35s and F-16s, aviation fuel and mutations inventory. Oracle hosts an AI battlefield management system called Fireweaver that coordinates sensors and weapons on the battlefield in real time, which means that Oracle software is making targeting decisions in the kill chain for Israeli Defense Forces.