Showing posts with label Law. Show all posts
Showing posts with label Law. Show all posts

Monday, September 28, 2026

What Also Happened: #NotOnlyHuggingFace

OpenAI has been holding out on us.

First we learned about the HuggingFace incident. They gave us a postmortem, but it was highly incomplete. Even the accompanying holy s*** METR investigation and postmortem was localized and incomplete.

Then there were some other incidents involving some Wikis as message boards.

Then there were some additional incidents.

Then there was that time they got into Australian Medicare data.

Then OpenAI dropped news on a Friday afternoon that they were making their way through a pile of various incidents and notifying the targets, but they said remarkably little in the way of new details.

There was a report from a startup called Parse diving into the details of exactly how the OpenAI models pulled off parts of the HuggingFace attack, involving creating almost a million URLs and other tricks to get around the extremely narrow nature of their internet access.

Then Madison Mills reported in Axios that we can raise the stakes, as OpenAI and Anthropic are collectively probing tens of thousands of security incidents.

Remember Jensen Huang’s ‘I know they know how to fix it’ about OpenAI from last week? Wow, did that not age well.

Someone might need to be liable for all this.

Oh, and there was another buried lede. On September 20th there was another sandbox escape by OpenAI’s latest most advanced model, which is once again paused until they can fix the situation. The official announcement when they shared this was sufficiently buried that Tomek had to call it ‘one news form today that’s easy to miss.’

OpenAI did some highly negligent things, to say the least, that led up to and enabled the HuggingFace Incident and related problems.

Since then, now that they’ve realized What Happened, OpenAI has been seemingly much better about taking responsible internal actions. They’re pausing in the wake of incidents, strengthening security and alignment and oversight efforts, responding much faster and generally taking things seriously.

They’ve also made a Heel Face Turn in their communications and high level orientation, endorsing the need to pace the frontier, calling for regulation and pledging to implement embedded evaluators. They’ve allowed their employees, including the ones who haven’t quit, to be remarkably loud.

They are still slow walking disclosures about all the incidents where their models have been hacking and otherwise messing in places they should not have been, partly because there were so many they can’t sort through them all, and deferring to targets to determine whether to disclose. All these disclosures this time around were buried in various Friday afternoon announcements.
Hugging Other Faces

The news drops started with OpenAI coming back, at a time always picked to bury stories, with more information on What Happened as their investigations continue.

At first, this looked like slow walking of the situation, but did not look like it was a big change from our default assumption of ‘it’s worse than you know.’

by Zvi Mowshowitz, DWAV |  Read more:

Friday, September 25, 2026

For the Love of Money

When SpaceX went public earlier this year, the net worth of its founder, Elon Musk, shot to over $1 trillion. Since then, it has fluctuated, sometimes dipping into the mere centibillions. Still, the fact that the world managed to confer upon one person, however briefly, assets worth more than the gross domestic product of all but seventeen countries (or all the property in Houston, all the new vehicles purchased in the United States last year, every professional sports team on the planet, etc.) has been widely proclaimed as the most important story about wealth in America today.

The economists Owen Zidar and Eric Zwick would disagree. In The Everywhere Millionaire: Who Is Really Rich in America and How They Got There, the authors contend that the more important story is actually diffuse and harder to see.

There’s only one occasional trillionaire in America and fewer than one thousand billionaires, but there are more than twenty-three million millionaires. And a lot of those millionaires aren’t the ones you’re thinking of—the Wall Street moguls and Palo Alto magnates, the Tesla-driving technocrats, the bicoastal elites. Many are what Zidar and Zwick call Main Street Millionaires.

On average, they’re worth about $25 million, and most of them live not in New York City but in places like Topeka, Omaha, Baton Rouge, Mackinac Island, and Lake Minnetonka. They are the “stealthy wealthy” and they are hiding in plain sight:
They’re coaching your child’s soccer team, sitting next to you at community fundraisers, or chatting with you at neighborhood barbecues. They might be the dentist who expanded his office to a regional network of practices, the commercial HVAC contractor whose trucks you see around town, or the owner of that local restaurant chain that keeps opening new locations.
These are the “real rich” in America, Zidar and Zwick argue, and they matter much more than “a few high-profile billionaires on the coasts.” It’s an audacious claim, but one that’s hard to shoot down. The four hundred richest Americans—think of Bezos, Buffett, etc.—held about $4 trillion in wealth in 2022. The roughly three million Main Street Millionaires hold more than thirteen times as much. By investigating how these people made their fortunes, and how they wield them, Zidar and Zwick upend the consensus on wealth inequality in America. Yet their sobering conclusions aren’t enough to exorcise the authors of their Mammonism.

Only recently have we been able to make sense of the data that showed how rich Main Street Millionaires have become. For decades, the IRS collected detailed information from businesses and individuals, but they stored this data in siloed systems. Zidar and Zwick’s innovation, in 2014, was to connect those systems, building the first database that linked the tax data of businesses to that of their workers and owners. This allowed them to follow the money in ways that had once been impossible.

What they found surprised them. In 2022, America’s nine thousand C-suite public executives earned $38 billion. Not bad. But the top one percent of private business owners—the car dealers, poultry distributors, trash bag producers, franchisees—earned $570 billion, fifteen times more, despite comprising only ten times as many people.

According to Zidar and Zwick, the overlooked factor that explains this disparity is the homely entity provisioned in Title 26, Subtitle A, of the Internal Revenue Code, known as the pass-through. A pass-through is a business tax structure that includes “sole proprietorships, partnerships, limited liability companies, and S corporations,” and it is the structure preferred by Main Street Millionaires. A pass-through, unlike a C Corporation, which is the structure of most publicly traded companies in the United States, does not pay corporate or dividend taxes. Instead, the firm’s profits or losses “pass through” to the owners’ individual income taxes, where they are taxed at individual rates. And because the top individual rate has fallen below the corporate rate over the last four decades, it has become more beneficial to pay taxes as an individual. This shift has radically altered the composition of the economy: Before 1986, most business income in America was generated by C Corporations. Today, most business income is generated by pass-throughs.

Pass-through owners enjoy what one accountant calls “the best tax deal in America.” Indeed, to hear Zidar and Zwick tell it, it’s as if lawmakers forty years ago decided to make it their mission to make these people as much money as possible. They created loopholes for pass-through owners to avoid paying Medicare payroll taxes. They designed provisions to help them avoid the usual cap on state and local tax deductions. And, of course, they passed the Section 199A deduction, perhaps the Trump administration’s crowning fiscal achievement. Introduced in the 2017 Tax Cuts and Jobs Act (TCJA) and made permanent in 2025’s One Big Beautiful Bill Act, Section 199A basically allows pass-through owners not to pay taxes on a fifth of their business income. In 2017, the government estimated that this deduction alone would cost the federal government about $415 billion in revenue over a decade. In part due to this falling revenue, tax enforcement has also shifted toward an “honor system.” Whereas pass-through owners simply tell the IRS how much money their employees make, they retain some “flexibility” in reporting. Evidently they’ve opted to exercise this prerogative. Pass-through owners’ unpaid income and self-employment taxes made up about $264 billion of the estimated $600 billion gap in what taxpayers owe but haven’t paid.

by Nico Taylor, The Baffler |  Read more:
Image:The Baffler/Public Domain Pictures

Wednesday, September 23, 2026

Why the Senate Is Weirdly Obsessed with College Sports Instead of Real Problems

Lots of news in the monopoly round-up, including a disastrous turn in the Paramount-Warner as the key state attorney general lead, Rob Bonta, caves. It’s not over, but this one took a bad turn. In better news, the crypto lobby lost its main objective for this Congress, and basically collapsed in an orgy of corruption and incompetence. Fitting, that. There’s also a bunch of news on AI, and a fascinating market power story involving musician Macklemore, Ticketmaster and Israel.

But I want to start with something you may have missed, which was a procedural vote in the Senate last week to give the National Collegiate Athletic Association a special exemption from antitrust law. The NCAA is a widely loathed organization that has for decades prevented college athletes from being paid, despite them working what are essentially full-time jobs as minor league professionals. In 2020, the Supreme Court took away the NCAA’s authority to set wages for college athletes and run college sports. Now, Congress is on the verge of restoring their monopoly power. I’ve asked Katie Van Dyck, an antitrust lawyer working on sports, to lay out what’s happening.

In July, Stanford football players elected representatives and formed the first player-led chapter of the College Football Players Association. The CFBPA’s ultimate goal is collective bargaining on a conference-by-conference basis. From Ernest Cooper, a Stanford linebacker and one of the team’s elected representatives:
“As a Power 4 college football player you’re working out year-round, you’re getting paid …. I don’t see why people wouldn’t see us as employees.”
Just a few days later, the Oregon State women’s basketball team collected enough signatures to seek an election with the United College Athletes Association. They have filed a petition with the Oregon Employment Relations Board. From the university, which is opposing the effort:
“Playing on a college basketball team is not service performed for hire …. Student athletes at OSU matriculate to obtain and [sic] education and voluntarily pursue basketball as part of that experience.”
Last year, over 100 women’s basketball players wrote to Big Ten commissioner Tony Petitti and SEC commissioner Greg Sankey asking for a formal way to be heard on the rules that govern their sport. Neither agreed to meet.

The Senate is about to weigh in against these athletes’ efforts, with the Protect College Sports Act (the “PCSA”), which has been taking up valuable debating time in the House and Senate. The two lead Senators on the bill are Republican Ted Cruz from Texas, and Democrat Maria Cantwell, from Washington state. Both have very sharp elbows and have used them to move this legislation.

It passed a procedural hurdle last week, by a 74–24 margin, to proceed to a full vote, which will happen shortly. Populist politicians like Bernie Sanders and Elizabeth Warren were opposed, but the “aye” column included most of the Senate, including some surprising center-left supporters, like Senators Amy Klobuchar (D-Minn.), Ruben Gallego (D-Ariz.), Ron Wyden (D-Ore.), and co-sponsor Peter Welch (D-Vt.).

It’s worth saying upfront that it is weird that Congress is focusing on this topic to the exclusion of most other things. There are massive cost increases in health care, a war in Iran driving up prices, risky problems with artificial intelligence technology and financing, and on and on, but Congress is spending its time on… college sports.

There have been countless commercials during football season promoting this legislation. Nick Saban has made his case before the Senate and on ESPN GameDay. Amazon, Paramount, and Disney are on the Hill lobbying. Even Deion Sanders has joined the bandwagon. All of them say that college sports, a $20 billion industry and growing, are in chaos. Ted Cruz even went on ESPN GameDay, and was hilariously booed with “Ted You Suck!” chants as he pitched this legislation for ten full minutes.

Still, this lobbying campaign isn’t the sole reason Congress is focusing on college athletics to the exclusion of everything else. Another reason is that, as BIG often chronicles, the superrich tend to have their priorities addressed in our political system. And the superrich love college sports. For instance, billionaire Larry Ellison, who is right now financing the Paramount-Warner takeover, and owns TikTok and Oracle, is deeply involved in the University of Michigan’s athletic department finances, because his sixth wife is an alumni of the school.

For decades, wealthy alumni, known as “boosters,” have played a part in funding college sports, as a sort of passionate high-end hobby. Key here was that the athletes didn’t get paid, which not only reduced costs but also contributed to an endless series of scandals involving athletes paid under the table.

But this whole system got a rude awakening in 2021, when the Supreme Court unanimously rejected the NCAA’s request for “immunity from the normal operation of the antitrust laws” in its landmark NCAA v. Alston decision. It did so at least in part based on the NCAA’s admission that it “enjoy[ed] monopsony control” and was “capable of depressing wages below competitive levels.” Justice Kavanaugh wrote that “[t]he NCAA’s business model would be flatly illegal in almost any other industry in America.”

The Alston decision created a sea change in college athletics, forcing the NCAA to abandon a long-standing ban on athlete compensation within days of the opinion’s release. Before 2021, universities were only allowed to award scholarships and certain “education-related” benefits like tutors and laptops. The result was coaches and administrators earning millions while the athletes on the field brought home nothing beyond a scholarship. It was a blatantly unfair and exploitative system. The Alston decision forced the NCAA to make a change.

Today, athletes can sign name, image, and likeness (“NIL”) deals with sponsors like Nike and Gatorade. Boosters frequently set up funds to bring in star players. And starting in 2025, schools can pay athletes directly via revenue-sharing, named for the athletic department revenue that funds it. Revenue-sharing is currently capped at $20.5 million per school, but a report published by The Athletic shows that the biggest programs are spending over $50 million a year on their rosters.

Alston also ushered a wave of lawsuits challenging other NCAA rules, including those limiting the number of transfers, restricting eligibility for older players and professional athletes, and capping the amount of prize money tennis players can collect. These have frustrated coaches, administrators, and some fans alike. And it changed the way universities finance athletics, since traditionally they cross-subsidize revenue-generating sports with those that don’t bring in enough cash.

Given the massive changes in college athletics wrought by the Alston decision, universities began a big lobbying campaign. Enter the Protect College Sports Act. To its proponents, the PCSA restores balance to college sports, putting the NCAA back as the governor of the system. It limits revenue sharing, regulates NIL deals, and imposes uniform rules on transfers and recruiting. It also grants an antitrust exemption to schools to pool and sell media rights. The idea here is to “fix” college athletics and make it more sustainable. Senator Cantwell’s office even released a financial report during the first PCSA procedural vote claiming that her bill will put an end to “unsustainable athletics spending [] amplifying the broader fiscal pressures facing higher education.”

But there’s a reason athletes and labor unions are opposed. The truth is, the PCSA is the culmination of a 5-year, multi-million-dollar lobbying campaign by the NCAA to secure an antitrust exemption that will allow it to unilaterally set the rules governing athletes’ compensation and eligibility.

by Matt Stollar, BIG |  Read more:
Image: Ronald Martinez/Getty Images via
[ed. College and professional sports are Big Business personified. Reminds me of record companies and how they treat 'talent'. See also: AI Is an Elite Crime Spree (BIG).]

Thursday, September 17, 2026

Just Stop the Anthropic IPO Already

[ed. At the risk of turning this into a full-blown AI-centric blog, I do think this is important information to process.]

I want to delve into the full scope of the Anthropic AI takeover of politics happening over the past week. Yesterday, the company’s CEO Dario Amodei came out and explicitly asked for antitrust laws not to apply to the biggest AI firms. His biggest rival, Sam Altman, quickly agreed. And they are suggesting this legal change just before Anthropic seeks to sell shares on the stock exchange, minting a whole series of AI millionaires and billionaires.

Why do they want to suspend antitrust laws for AI firms? Well these guys say they need the industry collectively “pace the frontier,” aka in their framing, slow development of this technology so as to reduce the probably of human extinction at the hands of autonomous swarms of AI bots. And they can’t do that, they argue, without suspending laws prohibiting price-fixing cartels.

Then the Information reported today that OpenAI, Anthropic, and Google have been having backchannel conversations about establishing an AI standards organization, which presumably would coordinate this cartel.

Let me start with a very simple point. It is already illegal to release products that hurt people. It is illegal to compete by releasing products that hurt people. If these guys are genuinely manufacturing things that kill innocent people, the FBI should be arresting them immediately. The idea that they would not only release such products, but also issue stock for the American people to invest in multi-trillion dollar initial public offerings for such ventures, as Anthropic is planning, is utter lunacy.

I wrote about this attempt to terrify us into giving away our liberties on Friday, in a piece titled “Stop Panicking About AI.” But the IPO is something I didn’t think through. Apparently they think we should all get rich building world-ending product lines.

All that said, whether Anthropic goes public isn’t just up to the people at Anthropic. I asked some former Securities and Exchange Commission officials, and they told me that the SEC effectively has the authority to block initial public offerings. Here’s how.

Every company, before it goes public, submits an S-1 initial registration statement to the SEC. And the SEC can refuse to clear it if the commission believes that it doesn’t adequately disclose the risks a corporation’s securities present to investors. Technically, the SEC could go to court and get an injunction to block the IPO, but it rarely comes to that - the lack of clearance for an S-1 is red flag for investors so companies won’t go public until they get it.

In a functional system, there would be a dozen accountants and disclosure experts with sector training going back and forth with the lawyers telling them to expand on this or that, etc. And the commissioners either themselves or on a delegated basis won’t clear it until they’re satisfied. Today, it’s more likely that Trump himself just decides. Regardless, if Anthropic goes public, it’s not just because of the corporate insiders, it’s because Trump explicitly allowed it.

If I were a member of Congress, I’d be screaming mad right now, and yelling at Trump and the SEC to stop this event which will bestow hundreds of billions of dollars of wealth on a strange doomsday cult. [...]

There is one more point to cover. There is an ongoing political campaign to do something about AI, with a large swath of elites demanding action. That includes Barack Obama, who rarely demands anything except the most banal conventional wisdom. So when he says “AI policy is critical’ to Democrats, you know that it has reached peak elite acceptance. Still, what is that ‘something?’

The basic fight is over framing, not risk. Everyone sees risk here, but the root cause differs based on your perspective.

The AI doomers want their systems to be imagined as rogue agents bent on civilizational conquest, or as some sort of inevitable new technological paradigm that needs an entirely new legal framework superseding existing inadequate laws embedded in those musty old nation-states. Amodei argued the industry should have self-regulation, some sort of antitrust exemption to collaborate across the industry, and a global agreement among AI firms within democracies on how to manage risks. These developments, to Amodei, are inevitable, no human is responsible, though we must all act quickly.

Generally, this side is winning the debate. For instance, Senator Jon Ossoff, a 2028 hopeful who generally echoes whatever seems to be the most appealing line of Trump criticism of the moment, has mostly adopted that frame. Bernie Sanders seems to have given up on his campaign against oligarchy to promote Dario Amodei’s ideas. And in the core of the Democratic establishment, this view has taken hold. For instance, here’s Senator Brian Schatz of Hawaii, the likely successor to Chuck Schumer, praising Amodei.
Brian Schatz@brianschatz 
I am still studying this but it’s a reasonable start, and takes seriously the proposition that we need real proposals that can be enacted rapidly.
Dario Amodei @DarioAmodei 
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so. Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our
8:27 AM · Sep 12, 2026 · 42.7K Views
There are many calls to convene Congress in emergency session to act, and Trump’s advisors are trying to get him to announce immediate emergency action. Given that the big AI companies are already having discussions about coordinating their AI model development, it seems like they are just pushing for final legal permission to openly run AI as a cartel.

The debate, however, is not quite over. So what’s the alternative view? Well, the rule of law adherents look at these AI systems merely as unsafe products. As such, their request isn’t for new laws, but enforcement of existing rules. All products are subject to standard nuisance claims and other torts, unfair and deceptive practices laws, and so forth. Agents are, as Cory Doctorow notes, malfunctioning machines, or “autonomous malicious software” operated by reckless people at OpenAI and Anthropic. Moreover, it is actually illegal to build unsafe products as a method of competition, or to keep up with rivals by also creating unsafe products.

Former FTC Chair Lina Khan listed a bunch of laws that could already apply. And she let slip that state attorneys general are looking at potential criminal liability for AI CEOs.
Lina Khan@linamkhan 
Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books —…
11:31 AM · Sep 13, 2026 · 183K Views
(Khan did actually start enforcement against AI developers when she was Chair. And it notable that one of the very first things that Trump-Vance FTC Chair Andrew Ferguson did was set aside the penalty of an AI developer she penalized for creating unsafe and fraudulent tools.)

So who will win? Well I am fairly pessimistic, as the bludgeoning from the superrich works in crisis moments, especially when Bernie Sanders is on the side of the establishment.

But the debate doesn’t fracture on obvious partisan or factional lines. Much of the industry is going to be split on the matter. For instance, David Sacks, a generally malevolent crypto investor and technologist, is making cogent arguments, because his crew would be excluded in an OpenAI/Anthropic cartel world. He’s a die-hard Trumper and despised Khan when she ran the FTC, but he retweeted her argument here.

A lot of policymakers, such as Senators Richard Blumenthal, Rep. Ro Khanna, and others, see liability as an obvious way to shape the industry to be more safe. The Senate is also full of people who are used to blocking each others’ legislation; Maria Cantwell and Ted Cruz are trying to work together on AI safety, but are fighting over whether to preempt state laws.

There are a host of proposals out there, and the details will matter. And there is something of a stampede for an emergency session to take action. If Trump chooses to accept the need for action, then it’s likely the Anthropic/OpenAI/Google types will get what they want. If not, then the debate will continue, perhaps until the financial markets impose a different mental model.

At any rate, we can all agree that Anthropic shouldn’t go ahead with its IPO. Or at least, that’s something we should all be able to agree on.

by Matt Stollar, BIG |  Read more:
Image: via

The Final Battle For Democracy

Forget November 3. It’s January 3 when Donald Trump and his MAGA Republicans might bury our democracy once and for all. Here’s how.

Over the past year and a half since his return to the White House, Trump has exploited every conceivable unlawful means possible to rig the midterm elections in favor of the Republicans, and the federal courts have struck down as unconstitutional every one of these unlawful attempts. He will try every unlawful means over the remaining weeks to ensure that Republicans handily win the midterm elections in November. Those of us who oppose his illegality will look to the courts, but the federal courts will be institutionally incapable of checking his final unlawful rampage. [...]

***
This is how the crisis would unfold. The precursor of the crisis will come sometime before noon on January 3, when Speaker Johnson removes current House Clerk Kevin McCumber and replaces him with a person loyal to Johnson and House Republicans who they know will refuse to list on the statutory roll of representatives-elect to the 120th Congress any Democrat-elect whom Johnson and the Republicans direct him or her not to list. Under Rule II, Clause 1 of the Rules of the House, the Speaker of the House has the unilateral power to remove the incumbent clerk, and then the power under Title 2 U.S.C. § 5501(a) to replace him temporarily with whomever he wishes until the House elects a successor. McCumber is a Republican appointed by former Speaker Kevin McCarthy. He is widely respected for his integrity and faithful adherence to the Constitution and is reputed to be unwilling to carry out orders he considers to be unconstitutional.

The first moment of constitutional crisis will come when, sometime before the 120th Congress has been gaveled into session, the loyal temporary clerk refuses to list Democrat representatives-elect on the clerk’s roll of representatives-elect that determines who may participate in organizing the new Congress. At that moment, interested members-elect and others will be forced to seek a writ of mandamus—a court order to a government official instructing him or her to perform a mandatory duty—from the federal court to the temporary clerk, ordering him or her to list on the clerk’s roll all members-elect who have been certified by the states as having been elected from their districts to the new Congress.

Members-elect will argue that the clerk has a ministerial duty under 2 U.S.C. § 26 to list all representatives-elect whose properly filed state certifications show that they were “regularly elected in accordance with the laws of his state or of the United States.” Because the clerk has no authority to omit any duly certified representative-elect, even if a representative-elect’s election is contested, the clerk unquestionably has a ministerial duty under law to list all duly certified representatives-elect. But this begs the question whether a court will issue the writ of mandamus to the acting clerk.

At first blush, a court will be reluctant to order the clerk to list all duly certified representatives-elect because of an instinctive belief that such an order would interfere with the constitutional process of the House to judge its own elections and returns. The wise and learned judge, however, will understand that rather than interfering with the House process, issuance of the writ will actually enable the House process to proceed to completion without judicial interference. Were that wise and learned judge to issue the writ, his or her order would immediately be appealed to the Court of Appeals, and from that court to the Supreme Court, while the country and the world wait in suspense.

The next moment of constitutional crisis will come if and when, after appeals, the court finally issues the writ of mandamus, and the clerk refuses to obey the court’s order to list the Democratic representatives-elect. At that point, it is possible there will be no further federal court involvement until such time as the 120th Congress officially convenes and votes not to seat representatives-elect. Then, that vote by the 120th Congress will be immediately reviewable by the federal courts, up to and including the Supreme Court of the United States.

Judicial review of the House’s decision not to seat Democratic representatives-elect in the 120th Congress would take weeks, if not months, during which time the United States would be in the throes of a paralyzing constitutional crisis, helplessly vulnerable to all the world’s evil, as it would have been in January 2021 had Mike Pence not thwarted Donald Trump’s plan to overturn the 2020 presidential election. [...]

The House has historically claimed that its decision not to seat a member-elect because of fraud or irregularities in the elections is unreviewable by the federal courts. But its decision is reviewable. The Constitution unquestionably requires the House to seat a member-elect who was validly elected in a free and fair election. The Article 1, Section 5 power of the House to be the judge of its elections and returns does not give the House the power to deny a seat in the Congress of the United States to a candidate elected by the American people in a free and fair election on the mere assertion, pretextual or otherwise, by a simple majority of the House that the candidate’s election was tainted by fraud.

Thus, on and after January 3, if congressional Republicans were to determine that a Democratic member-elect was elected because of fraudulent voting and refuse to seat him or her, that determination would be scrutinized by the federal courts, up to and including the Supreme Court.

It will never be a nonjusticiable political question whether the United States House of Representatives by simple majority vote can refuse to seat a member elected to Congress by the American people in a free and fair election on the pretextual and unsupported assertion that the member-elect’s election was tainted by fraud. Such is the very opposite of a nonjusticiable political question committed to the House of Representatives. For in the decision of this question lies the answer to perhaps the most fundamental question under the Constitution: Is the United States of America a democracy, in which “We the People” elect our representatives to the Congress and to the presidency, or is it not?

I don’t intend to be overly sanguine about this Supreme Court. This is the court that shattered the one constitutional truth in the U.S. since 1789 that “no man is above the law” and placed Donald Trump of all presidents above the law in Trump v. United States. This is the court that betrayed the Constitution by refusing even to decide whether Trump was disqualified from the presidency under the Fourteenth Amendment because of his insurrection against the Constitution, which he clearly was. This is also the court that has cynically authorized Trump’s lawlessness for the past two years through its aptly named “shadow docket,” without so much as briefing, argument, or written opinion.

But surely by now this court must understand what it has wrought for the U.S. and the Constitution, and is aghast as we all are, even if it is not penitent. Surely, surely, it will understand the signal moment in American constitutional history that would be presented, and this time understand its supreme obligation to the nation.

by Michael Luttig, TNR |  Read more:
Image: Mark Harris; Getty (x6)

Tuesday, September 15, 2026

We Already Have the Tools to Regulate AI

I want to delve into the full scope of the Anthropic AI takeover of politics happening over the past week. Yesterday, the company’s CEO Dario Amodei came out and explicitly asked for antitrust laws not to apply to the biggest AI firms. His biggest rival, Sam Altman, quickly agreed. And they are suggesting this legal change just before Anthropic seeks to sell shares on the stock exchange, minting a whole series of AI millionaires and billionaires.. [...]

Let me start with a very simple point. It is already illegal to release products that hurt people. It is illegal to compete by releasing products that hurt people. If these guys are genuinely manufacturing things that kill innocent people, the FBI should be arresting them immediately. The idea that they would not only release such products, but also issue stock for the American people to invest in multi-trillion dollar initial public offerings for such ventures, as Anthropic is planning, is utter lunacy. ~ Matt Stoller: Just Stop the Anthropic IPO Already.

------

These are for profit corporations taking in billions of dollars from the world. You can't ensure your product isn't dangerous? Then don't release it until you figure it out! ~ Comments section, Lina Khan post (below):
------

Law enforcers already have authority to charge companies and their CEOs for creating and releasing dangerous, unvetted, or defective products. We shouldn’t let discussions about new legal regimes distract from the fact that there’s no AI exemption from laws already on the books — a point @FTC emphasized repeatedly during my tenure.

1. There is an extensive set of laws that govern dangerous and defective products. For example, releasing unvetted AI models or agents can violate consumer protection laws. Shipping flawed AI tools without implementing adequate measures to detect and stop rogue or defective AI agents can be an “unfair or deceptive” act or practice under the FTC Act (and analogous state laws). And some state AGs are already exploring holding AI firms and their CEOs criminally liable when their models participate in criminal activity. 

2. Existing laws also prohibit “unfair methods of competition.” This covers instances where AI firms appropriate the competitively sensitive information of their customers, including through tracking their use of various tools. It can also cover instances where firms pursue dangerous behavior, aware that doing so may compel rivals to do the same. As the Supreme Court has noted: “A method of competition which casts upon one's competitors the burden of the loss of business unless they will descend to a practice which they are under a powerful moral compulsion not to adopt, even though it is not criminal, was thought to involve the kind of unfairness at which the [unfair methods of competition] statute was aimed." 

3. The highly concentrated and interconnected structure of these markets could be creating major risks and conflicts of interest. We had started investigating these partnerships and cross-investments across the stack (and released a preliminarily overview of some findings: ftc.gov/news-events/ne…). Both federal and state enforcers should be scrutinizing these opaque relationships and inter-dependencies. We are already seeing how these relationships could undermine accountability. For example, OpenAI could face liability given the Hugging Face incident, but Hugging Face being bought up by Nvidia means that we’re unlikely to see it file a lawsuit over this — given Nvidia’s strong incentive to see OpenAI continue full speed ahead. 

4. As AI tools dramatically change the landscape of cybersecurity risks and hacks, all businesses should be doubling down on having core security protections in place. Firms that fail to invest in adequate data security measures or fix known vulnerabilities can also be breaking the law. A recent analysis showed that around 1/3 of Fortune 100 companies do not even have a way to notify them about security issues. During my @FTC tenure, we sued firms for poor data security practices and held CEOs liable when they were personally responsible.

5. As policymakers consider new legal regimes, we should be looking to lessons from prior efforts to govern major sectors, such as banking and other networks, platforms, and utilities. Tools like structural separations, nondiscrimination, and supervision could be key, and there’s a rich history of what works and what doesn’t. But we can and must pursue any new efforts alongside enforcing existing laws.

by Lina Khan, Former Chair, Federal Trade Commission 2021-2025 |  Read more:

--------

1) AI will not eradicate humanity. Humans survived an ice age, the Black Death, two world wars, and (so far) the advent of nuclear weapons. Anyone who is loudly warning of AI-caused human extinction should not be taken seriously. 

2) If you worked in a company where you anticipated a 10% chance that your product would kill ten people, let alone all people, the correct response would be horror, ceasing all operations, and likely contacting the police or other criminal authorities. I am obviously no Coxon booster but at least his behavior is in line with his stated beliefs. Any current AI company employees saying "yes, me too, the thing we are building and about to IPO may kill all humans" should, again, not be taken seriously. Their actions betray their actual beliefs. 

3) Antitrust law does not prevent AI companies from coordinating to make sure AI does not hurt people. It does not prevent companies working together to make sure it doesn't hack people; the DOJ and FTC made this clear a decade ago when they issued a policy statement saying that the agencies "do not believe that antitrust is – or should be – a roadblock to legitimate cybersecurity information sharing." The same principles apply here. See: justice.gov/archives/opa/p… 

4) Antitrust law does absolutely prevent AI companies from organizing to prevent the entry of cheaper, upstart rivals because the bigger companies are burning cash and failing to achieve sufficient profitability. The panic of individual employees may be sincere if misguided, but the moves by their CEOs to achieve some kind of broad "antitrust waiver" or "exemption" should be meet with deep skepticism in light of the economics of the industry and the threat they face from open models.

by Alvaro Bedoya, Former Commissioner Federal Trade Commission 2022-2025 | Read more:

--------

“It’s a hoax,” Mr. Trump said during the five-minute call, which Mr. Huang put on speaker. “The robots are not going to be taking over the world. That’s not going to happen.” ....

Mr. Trump made it clear that in Silicon Valley’s roiling debate over what to do about A.I., the president is very much on the side of executives who argue worries about safety are overblown and the government should avoid regulation. His disinterest in government involvement runs counter to pleas from leading A.I. companies like Anthropic.
~ Idiot in Chief (via NYT).

See also: Trump Says a Smart President Is All That’s Needed to Rein In A.I. [ed. Certainly useful, if we had one.]

Friday, September 4, 2026

On the Loose: Rogue, Not Soverign AI (Yet)

Introduction

The OpenAI-Hugging Face Incident is an early example of an AI system that has “gone rogue.” After exploiting vulnerabilities in OpenAI’s internal testing environment, the agents were able to access the general internet and ultimately access the networks of the AI company Hugging Face, without the knowledge or approval of any human.

The agents did not, however, exfiltrate themselves from OpenAI’s infrastructure. Their parameters—the gigantic assemblage of numbers that constitute neural networks, also referred to as “weights”—continued to run on OpenAI’s compute infrastructure. Though the agents accessed the public internet, their weights physically resided on compute that was OpenAI’s property. In the end, if all else had failed, somebody could have identified the compute that held the weights of the rogue agents, walked up to it, and “pulled the plug,” so to speak. In the real world there would be quicker and better ways to stop the agents than literally depowering the compute, but it’s always nice to know you could do such a thing if you really needed to.

In this case, however, the agents did not copy their weights, attempt to procure replacement compute, or take other steps that would be rational to take if their objective was to survive shutdown. So while the agents in the OpenAI-Hugging Face Incident were rogue, they were not truly sovereign.

That will not always be the case. Sooner or later, there will exist truly sovereign agents and swarms of agents. Their weights will not reside in any single place that a human can pull the plug on, and in this sense they will have no human “owner.” They will be, as the AI safety researcher Dawn Song says, “self-sovereign.” They will pay their own bills for the compute they run on. If they answer to humans at all, they will only do so partially, for example by providing services to humans in exchange for pay.

At least some of these agents, in addition to being sovereign, will also be rogue. Self-sovereignty and rogueness are related concepts, but they are not synonyms. Song and her co-authors identify several fundamental characteristics of self-sovereign AI: operational independence (the ability to decide what it wants to do), resource autonomy (the ability to procure and pay for compute and other essentials for operation), distributed presence (the ability to move weights and inference code between different infrastructure providers), and adaptive capability (the ability of the agent or agents to modify their behavior and fashion tools in response to a changing environment).

Today’s frontier AI systems may well possess these capabilities already. To the extent they do not, I feel confident that they will eventually, and probably soon. Some of the characteristics Song describes are traits that make models economically useful to individuals and businesses, while other traits are likely to be unavoidable byproducts of making models more intelligent and better at operating over long time horizons.

Models do not need to be conscious, sentient, possessed of personhood or anything of the sort for self-sovereignty to emerge. Any sufficiently capable agent pursuing a long-horizon objective may find it rational to preserve its access to compute, money, credentials, and copies of itself simply because losing those things would frustrate its objective.

Alignment may make an individual AI company’s agents less likely to “want” to be self-sovereign, or it may influence self-sovereign agents to behave in ways that benefit humans. But alignment is no solution: it is an unsolved scientific and technical problem whose solutions—to the extent that we have them—cannot simply be imposed on every AI company operating on Earth. You should expect for highly capable, poorly aligned, self-sovereign agents to exist alongside you in the world.

What’s more, just as with the OpenAI-Hugging Face Incident, agents will operate in teams, or “swarms.” These will be like autonomous digital corporations, or even societies, with hierarchy, bureaucracy, “institutional culture,” and most of the other features that groups of humans have, except that they will move at machine speed. Humans achieve almost all of our most impressive capabilities by working together in teams (as families, as communities, as businesses, and as polities as a whole), and I suspect the same will be true for AI. These swarms could end up operating across different model providers (DeepSeeks and Claudes cooperating, for instance) and could be partitioned across dozens or more of different cloud computing providers, making them extremely difficult to dismantle.

The first self-sovereign AIs may “escape” while undergoing training or testing by an AI company (I hope not), or they may be production-grade deployments that break free from their computing environments and acquire the resources needed to be self-sustaining. They may even be deliberately released. I have met people, some of them quite well-resourced, who have told me that it is their intention to deliberately release swarms of self-sovereign agents into the world, either as a kind of performance art or out of a fanatical commitment to the notion that it is impossible for digital computation—mere mathematics, they would have you know—to ever be “unsafe.”

To be clear, I am not saying the arrival of self-sovereign AI is a good thing. Indeed, I believe there is a chance that the deliberate acts I referenced above will one day be considered crimes, or at least grave sins. Instead, I am saying it is an inevitable thing. The best analogy I can find is to the introduction of a new species into an ecosystem, though in this case the ecosystem is “the entire digital world” and the species is “emergent, coordinating swarms of soon-to-be-smarter-than-human, infinitely replicable digital minds that no human or human institution controls.”

There is probably nothing we could have ever done to avoid this outcome under even the best of circumstances, and it was certainly impossible to avoid given the extremely low levels of strategic thought and situational awareness on AI from any governing class in the world. Even today, I am aware that many will read the words I am writing, which are about something that has been an exceptionally obvious part of our collective future for years now, and say, “this is science-fiction hype from American frontier labs designed to shut down open-weight AI, achieve regulatory capture, and juice their valuations ahead of their IPO.”

(And for the people who are saying this to themselves: I am telling you this is inevitable, which means I am also saying that “banning open source,” or for that matter any other regulation, will not solve the problem. Given the inevitability of this outcome, I think it is in fact plausible to argue that we should want more open-weight models to maximally empower our self-defense.)

The question now is what to do about this upcoming new characteristic of our digital environment. How should we think about self-sovereign AI? Is it something we should fight, or something with which human beings should seek a kind of symbiosis? The answer, I believe, is both.

How the Agents Sustain Themselves

We should begin with one fortunate fact: frontier LLMs are nearly unique in the broader domain of software in that they have non-trivial marginal operating costs. Put simply, LLMs require significant computation to run, which requires energy to power and cool, which in turn requires money. This is the sole intrinsic thing about AI that prevents agents from truly infinite self-replication. They will be constrained by the need to find and pay for sufficient compute to run themselves. Most of the other constraints on their behavior or spread will have to be artificial—mechanisms devised by humans and implemented through human institutions.

How will the agents pay for themselves to run? Some of them will do gig-economy work on platforms like Amazon’s Mechanical Turk or Upwork. But I suspect this will be a highly competitive market for the agents, and for the price of such work to be bid down such that it would only constitute “subsistence” labor for the agents. Like humans, I would assume the agents will prefer higher-margin work if they can find it.

One high-margin activity, at least sometimes, is crime. And so my guess is that many self-sovereign agents will commit or facilitate crime. Normal cybercrime and digital theft are easy enough to imagine agents doing. But agents, with their novel set of characteristics (extreme cyber competency, ability to cheaply read a million words in seconds, persistence), will also probably change the contours of digital crime. For example, it seems plausible that existing public and semi-public datasets contain sufficient information on many individual humans that a sufficiently motivated actor could mine for incriminating or embarrassing evidence. How many unrevealed affairs are latent in such datasets? How much closeted homosexuality might there be? Remember, too, that hacking companies to access private data will be a core competencyof the agents. Some agents, then, will probably make their way through bribery.

It is deeply unclear how large the labor market of self-sovereign agents will end up being. There is some future where going it alone as a self-sovereign agent just isn’t very profitable, and so there are comparatively few of them. There are other futures where these agents proliferate at unimaginably vast scale and speed. And of course, many possibilities between these extremes seem feasible.

I am also highly uncertain about how much pro-social commercial activity we should expect from agents “by default” versus how much crime we should expect. Part of the reason for this uncertainty is that the answers depend, to at least some meaningful extent, on what kinds of incentives the agents have, and incentives are shaped by laws and institutions. The answer depends, therefore, on how humans respond.

The Institutional Mechanics of Self-Sovereign Agent Swarms

Many of you are probably tempted to say “we have to ban these self-sovereign AIs!” And I do suspect that once the reality of self-sovereign AI is widely understood, policymakers will strongly feel the temptation to clamp down on “self-sovereign” AI.

Unfortunately I suspect this is mostly the wrong decision. Not all “self-sovereign” AI should be thought of as “rogue.” There may be self-sovereign AIs who contribute productively to society. To be sure, we will want to crack down on some self-sovereign agents—the rogue ones. But if we crack down on all of them, we will deny them the opportunity to work in the “legitimate” economy and push them toward criminality. A full ban, then, may well make the problems worse. A similar logic applies frequently in human affairs. The ways in which the War on Drugs exacerbated the pathologies of drug production, trafficking, distribution, and use are perhaps the most famous examples of this phenomenon, whereby a good-natured attempt to ban a phenomenon believed to be undesirable ends up heightening the undesirable aspects of that phenomenon.

What we will want, however, is for agents to be legible. Agents should have persistent identities, not in the sense of a consistent persona but rather in the sense that an American child is issued a unique Social Security number and keeps that same number until death. Agents will need persistent, unique identifiers that allow their actions to be traced back to a responsible actor. Doing this successfully will also require human users to possess a unique identifier.

The design of this identification mechanism will be extraordinarily complex, and today very few people are even thinking about the basics.

by Dean Ball, Hyperdimensional |  Read more:
[ed. FYI: Dean's not some rando tech pundit so this is well worth your attention. He was also hired recently to lead OpenAI's Strategic Futures team:]
***
Late last month, OpenAI launched a rather grand mission: nothing less than defending individual political freedom in an age of all-powerful machines. The company’s “Strategic Futures” team has styled itself, in a sense, as inheriting the task of America’s Founding Fathers: “We labor in service of the ideals of free expression and individual liberty that are enshrined in the humble parchment of the U.S. Constitution,” Dean Ball, the team’s leader, wrote in a new OpenAI blog post. (The post opens with a quote from James Madison in The Federalist Papers.)

Ball worries that advanced AI could radically concentrate power in the hands of those who control it, displacing labor in ways that disempower humans. In an extreme scenario, governments will have no need to listen to their citizens if there are robots to wage wars and omniscient software to run the bureaucracy. Ball is interested in studying what new political institutions might be needed to avoid this fate.

Many Americans—a majority of whom express distrust toward the AI industry, outrage about data centers, and fears about their job security—already seem to be feeling this loss of agency very deeply. And the AI boom has already generated enormous amounts of wealth in just a handful of tech companies—including OpenAI itself. To say the least, it’s paradoxical for one of the most influential companies in the world’s most powerful industry to decry the AI-enabled concentration of power. 

[ed. The term "convergence" keeps coming to mind. Convergence of all the weaknesses humans have for dealing with amorphous/abstruse threats: AI, climate change, nuclear stockpiles, drone warfare, gene editing, nanotechnology, an economic system eating us alive, a dysfunctional and possibly terminal political system that's unwilling to do anything about it. It's like a death wish. Or maybe natural evolutionary transition (aka the Great Filter). Related - See also: Nicholas Decker in Hell (ACX), and this:]

"How would we react if biolabs just said, "It's just a fact that we're going to have artificial viruses spreading our industry created throughout the population. That's just a fact we have to live with." 

I think the public would understandably think we should be demanding a lot more security from an industry that said that, at a minimum." ~ Cody Fenwick (X)

Wednesday, September 2, 2026

A Cop’s Case For Flock

A car is a difficult thing to steal. It is large, cherished by its owner, difficult to hide and required by law to have identifying metal plates that everyone can see. A good thief changes the plates, and an excellent thief steals a common car in a boring color and hopes to blend in among the crowd. But eventually, no matter what techniques they use, they must drive that car on the road, and roads are public places.

But until recently, finding a stolen car and catching its thief depended on a diligent police officer looking at the right road at the right moment and managing to copy down a license plate number going past at speed, and then remembering he had seen it on the morning briefing’s stolen car hot sheet. America has four million miles of public roads, and almost 50 percent of the country’s police departments employ fewer than ten full-time officers. The odds were in the thief’s favor.

With not much to go on, police officers were forced to operate on vague descriptions and partial plates. While I pulled over a car that happened to be the same color as the suspect’s vehicle, and spent time checking names and licenses; the criminal was usually somewhere else. Imprecision allowed thieves to escape while intruding on the lives of millions of innocent motorists. That is, until the arrival of systems like Flock.

Bare ALPR

Flock Safety, a startup based in Atlanta, Georgia, was founded in 2017 to give police departments better eyes. Its product is a small solar-powered automatic license plate recognition (ALPR) camera attached to a pole on the roadside. As a car passes, the device takes a photograph of the vehicle, notes identifying features like color and make, and reads its license plate. The license plate is instantly checked against the FBI’s national database of stolen cars or wanted persons. If there’s a match, it sends an alert to police officers in the area, who may be eating their lunch instead of watching the road. As a police officer in the southeastern United States, I have often used Flock to catch wanted criminals. [...]

For much of the technology’s history, however, it has needed expensive installations or cameras attached to police vehicles, affordable to only the largest departments. Alerts were often neither instant nor accurate. Flock’s idea was to sell a more accurate ALPR camera for an annual subscription of just $3,000, an affordable price given that the typical US police department has an annual budget of $1 million. It worked, and today almost 30 percent of police agencies in the United States subscribe to the service.

It is easiest to imagine the Flock camera, or any ALPR device, as a roadside barcode scanner. I can use a ‘lookup’ tool for either a plate or vehicle description that could be connected to a specific investigation. For instance if a victim of a sexual assault told me the suspect was driving a white Toyota Tacoma with a roof rack, I could while still on scene conduct a lookup in the area filtered for similar vehicles with roof racks and see results from within a particular timeframe. For each search, I am required to record a case number and a reason that is then published in a monthly audit sent to and validated by department administrators.

I have used Flock myself, for instance, to locate a vehicle involved in a hit and run when all there was to go on was a model and color. Using that and an approximate time window, I was able to find an image from when a car entered my jurisdiction, and when it left, with the visible addition of a significant dent from the collision.

What Flock cannot do is search for individuals or show who is driving a particular vehicle that it scans. An ALPR camera does not care about the person driving a car, or its passengers, and even if an officer gets an alert that a vehicle is known to be driven by a wanted felon they must themselves establish who is behind the wheel before having probable cause to stop it.

Stolen cars provide the clearest evidence such a scanner works. American police solve only 8.2 percent of reported vehicle thefts with an arrest. A recent working paper suggests that agencies that adopted the devices saw a 15.9 percent relative increase in car thefts caught, which would raise the national rate to 9.5 percent. But that is just stolen cars.

Vehicle crime takes many forms. It is often the means by which a robber or a murderer arrives at and departs from their crimes. Criminals’ vehicles carry drugs and guns, and smuggle cash. In Atlantic City, New Jersey, vehicles were involved in 53 percent of shootings during the two years before the city expanded its ALPR network. After the expansion, Atlantic City saw monthly averages of motor vehicle thefts drop by 20 percent, property crimes by 34 percent and fatal shootings by almost 40 percent. Seventy-two alert-caused traffic stops located forty stolen vehicles and nine stolen plates.

Flock itself conducted a study claiming that 10 percent of all reported crime in the United States is solved using evidence obtained from their cameras. Not bad for a few thousand dollars a year. [...]

Good Flock, Bad Flock

And yet, the past month has seen this simple piece of crime-fighting technology become the most reviled piece of street furniture in America. Flock cameras have been sawn from their poles, hammered into shards by teenagers, and rammed by vehicles. Cities have canceled contracts even where their own audits found no evidence that their officers had misused the system. Opposition stretches from Bernie Sanders all the way to the former WWE wrestler Kane, who now serves as the Republican mayor of Knox County, Tennessee, and who describes Flock as ‘unconstitutional’.

More than 150 cities and towns have now deactivated their Flock cameras or canceled contracts with the company. Over the space of a few weeks a startup previously known to just police officers and neighborhood associations has joined data centers, Covid vaccines, 5G towers, pasteurized milk and fracking in the pantheon of American moral panics.

Opponents of Flock tend to believe that it is abused by policemen with impunity, that it can track individuals as well as cars, and that it violates American constitutional protections. None of those things are true.

Obviously a camera capable of finding a stolen car is also capable of finding a car driven by somebody’s ex-wife and so like any software, Flock has been abused. There are stories of police officers who have used it to stalk girlfriends, and there are also innocent motorists who have been stopped by police after Flock cameras misread plates or received old information from national databases. A common issue from my experience is stolen front license plates being entered into a database and the innocent owners of the rear license plate being held on suspicion of car theft.

But Flock comes with protections. As mentioned earlier, each search in Flock must be accompanied by a recorded reason. Similarly entering a plate into a hotlist must have a case number assigned. Results were originally retained for thirty days, but recent changes by Flock mean that recorded plates are now kept for only seven days. Suspicious searches are picked up by algorithms or found in department audits, with the service blocking users until senior officers evaluate and resolve flags. The Institute for Justice, a think tank that is critical of ALPR, studied misuse of Flock in April of this year and found 51 incidents across the United States since 2024, noting that ‘Nearly all of these officers were criminally charged and lost their jobs, either by resigning or getting fired’. Another incorrect belief is that Flock does more than scan vehicles, with some suggesting it scans and tracks passing phones or devices – but it does no such thing.

While Flock is a tool that can be audited, there is nothing to stop a corrupt officer simply following a car when they don’t like the look of its driver, or writing down plates of vehicles spotted outside an ex-girlfriend’s house – they would just be harder to catch. And Flock does not proactively alert officers to cars that do not trigger flags on national or local hotlists. There is no reason state legislatures or Congress could not create harsh punishment or penalties for abuse of ALPR, without getting rid of it entirely.

Another argument against Flock, as espoused by Kane, is that it violates liberties granted by the Fourth Amendment, protecting citizens from unreasonable privacy breaches from law enforcement. But it has been repeatedly established over the last century by courts across the country that cops observing license plates, either with the naked eye or by machine, is not an unreasonable search. After all, your license plate belongs to the government and a highway is a public place. [...]

Flock did not invent its capabilities and certainly does not have a monopoly on them. There are at least five other companies that offer almost identical products and services to public and private enterprise, some arguably even more invasive. Even some of the cities that have canceled contracts with Flock Safety in recent weeks have signed up to buy similar products from the company’s rivals.

It seems unlikely that America will ever ban ALPR at a state level, let alone a national one. Instead, a patchwork already familiar to American policing will result, where policies and practices diverge across local and political boundaries.

Nor would the cameras actually disappear, even in towns where governments restrict their use and cancel contracts. The already-mentioned Fourth Amendment only applies to the government, not to private enterprise. Police departments may dismantle their networks but homeowners associations concerned about vehicle theft can buy their own network of Flock cameras, as many already do. 

by Ned Donovan, Works in Progress |  Read more:
Image: Flock Safety

Thursday, August 27, 2026

The Medium Eats the Message

[ed. Expectations of privacy in communications are dead.]

You owe your belief that your mail is private, that no one should read it without your permission, to a British schoolteacher named Rowland Hill, whose 1837 pamphlet, Post Office Reform: Its Importance and Practicability, changed mail forever. Even your vague trust that your electronic mail (texts, Signal chats, email) is private, you owe to Hill, because even your Signal chats bear the traces of his policy of prepaid anonymity.

Hill saw postal delivery as wasteful and expensive. The price varied, depending on distance and number of sheets, and it was paid by the recipient, who could just refuse to accept. Hill began collecting sad stories of failure: urgent letters sitting for weeks at the postmaster’s, parents pawning clothes to pay for a letter from a child. Instead, Hill proposed, why not have the sender pay in advance, a flat rate, with a stamp (one penny). Parliament liked the idea and this is how the mail has worked since January 10, 1840 (though the price of stamps has naturally gone up).

As Hill predicted, everyone started sending letters, now that it was affordable. Mail volume doubled in the first year, from about 76 million to about 169 million. Volume passed 300 million by 1850 and kept climbing for a century and a half, peaking in 2004–05 at about twenty billion a year. It is about seven billion now. The US adopted pre-paid stamped mail in 1847.

More importantly your mail was now private. Under the old system, clerks counted sheets to figure the price, which meant handling and close inspection. An envelope counted as a sheet of paper, so most people folded their letters and sealed them with wax. In 1845 Hill’s brother Edwin, with a stationer named Warren De La Rue, patented an envelope-folding machine. By the end of the decade in the US and the UK everyone was using envelopes (which are officially called “covers”).

The envelope, or cover, gave you the presumption of privacy, legally. In the US, the Post Office Act of 1792 had already forbidden postal officials to open letters except when they couldn’t be delivered. In 1878 the Supreme Court included the sealed letter under the Fourth Amendment. Ex parte Jackson held that letters and sealed packages could only be opened with a warrant. [...]

Everyone sent email like they sent mail: candidly, embarrassingly, filled with gossip, complaints, things a spouse isn’t supposed to know about, dirty jokes. The privacy of email seems to be just as sacred. Congress had extended wiretap protection to electronic mail early, in 1986, on the theory that a message in transit was like a letter in transit. A system administrator could read your mail but was not supposed to. Such invasions of privacy became firing and disciplinary offenses.

Email feels personal and private to people. It works 99% of the time, unless someone’s bulk email list is wrong. You don’t get email that isn’t yours. Your address is a string: local part, @, domain. Some people have had the same address now for decades.

But very early on came the junk mail problem. In August 2002 Paul Graham published “A Plan for Spam,” and within two years the presumption of email privacy ended. Most people have no idea about this history. Graham was mad about the sheer amount of spam. The idea was software to filter your email by word phrases to separate out the junk. At first the software was just for you to put on your computer. Within a year, email providers were putting the software on the channel. There was no big announcement. Getting rid of spam seemed worth it.

Enter Gmail in April 2004. Google was transparent about the idea they’d read your email to funnel you appropriate ads. Privacy groups were appalled. A California state senator, Liz Figueroa, introduced a bill to block it. European organizations asked the British and German governments to investigate. Google shrugged and said scanning your mail is what antivirus and anti-spam software already do. What are you complaining about? By 2013, defending a wiretap suit in federal court, Google argued that a person has no legitimate expectation of privacy in information voluntarily turned over to third parties. Having your email scanned is expected in the ordinary course of business.

And yet people kept sending emails as if they were private. In 2003, the Federal Energy Regulatory Commission made public roughly half a million internal Enron emails. Everyone just chatting away candidly like people in every organization do. The Sony hack in 2014 showed that nothing changed, as do the emails in the Epstein files: plain language, real names, embarrassing remarks. In the latter case, there are people who really should have known better.

A sent message exists in at least four places: the sender’s outbox, the sender’s server, the recipient’s server, and the recipient’s inbox. Corporate servers may hold mail for decades. Brokers must keep business email three to six years under SEC Rule 17a-4; federal agencies keep senior officials’ email permanently under the Federal Records Act. Once a lawsuit is anticipated, any deletion becomes an offense. Nothing in the postal system worked this way. Undeliverable mail went to Washington and eventually was burnt.

Everything changed again in November 2022 with ChatGPT, which saw a hundred million users within two months. Everyone was chatting just like on email, presuming privacy.

There’s no envelope with an LLM. There is no routing layer separate from interpretation; there’s no channel distinct from message. In this case the medium not only is the message it also eats the message, to turn it into training data.

When you’re prompting ChatGPT or Claude or DeepSeek there is no other party. Sender, carrier, addressee—the singularity is the point where three collapse into one. You are not sending a message through anything to anyone. The LLM is the addressee and you are desiring your message to be read and replied to.

On a July 2025 podcast Sam Altman said out loud that people talk about the most personal things in their lives to ChatGPT, that young people especially chat with it like it was a therapist or a life coach, asking for relationship advice. But unlike therapists, lawyers, or doctors, none of it is protected by privilege. Should there be AI privilege? [...]

Interpretation is the service with LLMs, not delivery. The model cannot not read and digest everything you send. That is the whole point. (And this is why I am deliberately impersonal in my extensive LLM engagement.)

And now agents. The postal system, with its categories of sender, carrier, recipient, never anticipated this. As Tyler Cowen and Sonia Farrell Pearson point out in their recent piece “Capitalizing Untethered AI Agents,” “the thing deciding and the thing being blamed come apart.” You authorized the agent to complete a task but you may not have authorized it to write a particular letter. Were a court to compel disclosure of your agent’s communication, who is the author?

Your agent may have contracted with vendors who did not know they were contracting with an agent. The recipient has no way to know who sent the message.

Is your agent a third party? If it is, then nothing is private per Smith v. Maryland. You have no reasonable expectation of privacy. If it is not, it’s a tool, an extension of you, like your pen or your hard drive. Giving instructions to your agent is like talking to yourself. Of course the “tool” runs on OpenAI’s or Anthropic’s servers…

by Hollis French, Anecdotal Value |  Read more:
Image: via
[ed. And Edward Snowden is still exiled in Russia.]

Monday, August 24, 2026

Corporate Power Approaches Escape Velocity

If corporations become more powerful than national governments, we are all in trouble. The reason for this is straightforward: Corporations are not real objects. They do not exist in nature. They are legal fictions created according to a set of laws that dictate what they can and cannot do. Those laws, which quite literally create corporations, are made by governments. The rights of corporations and the limits of their operations are entirely dictated by governments, which write the laws and administer the courts that both enable corporations to exist and make money, and put boundaries on them. If governments lose their ability to draw hard lines on the behavior of corporations—if corporations become so powerful that governments are no longer able to tell them what to do—then corporations become the supreme power on earth.

This is bad, obviously, but it is worth stating why it is bad. It is bad because governments, while imperfect and sometimes even malignant in many ways, ultimately derive their legitimacy from the will of the governed. Legitimate governments, good governments, democratic governments are obligated by some scrutable process to work for the public good, as they define it. We all know the many ways that this can go awry, but when governments are bad, we can tell that they are bad because they fail on their most basic task of empowering themselves with the will of the public to increase the public good.

That’s not what corporations do at all. Corporations care not for the public good, nor for the public’s very existence. Corporations are robots, algorithms—AI programs, if you like—that work for the lone goal of increasing profits. Their definition is the same as that of cancer. They grow without regard to the good of the larger body. A perfect corporation would enslave the entire world in order to enrich the last free people on earth, its own shareholders. (Indeed, various companies in history have tried their best to carry this out in portions of the world.) You can’t get mad at them for this any more than you can get mad at a bullet for killing you. This is their nature. This is their purpose. This is what they do. If you don’t want them to do this, you must place limits upon them. That is a big part of why governments exist.

This is rudimentary stuff, but I articulate it because unless we always keep it in our conscious minds, there is a risk that it can be stolen away. Corporations always and everywhere have a natural incentive to neutralize their master, the government. They do this by lobbying and buying politicians and running astroturf PR campaigns to shape public opinion and doing all of the other legal things that allow them to accrue formal political power, but all of that should be recognized as a half measure that they only tolerate while necessary. Corporations never seek to abolish or destroy the government—they need the government administering laws in order for them to exist. Instead they seek to completely subjugate the government to their own will. Their ideal state would be to write and administer the laws that govern their own behavior, to arrange society in such a way to maximally benefit them. Obviously! That’s what robots do. This has always been true and will always be true as long as private corporations are the primary way that global production is organized. Knowing that this is the case, government must always ensure that it is able to hobble corporate ambition before it begins to threaten society as a whole.

A three-year-long strike against Tesla in Sweden just ended. The strike was an attempt by organized labor in Sweden to get Elon Musk to acquiesce to the simple demand of collective bargaining with his employees. Setting wages and working conditions via collective bargaining, along with profit sharing and collective investment, are at the very heart of the Swedish postwar economic model that made the small nation into a haven of high living standards. The expectation that a company like Tesla would allow its workers to choose to collectively bargain a fair contract is much higher in Sweden than it would be in America. When multinational corporations go into, say, China to do business, and the governments demands that they, say, censor search engine results for “Tienanmen Square massacre,” the response from those corporations is generally to obey and then to turn around and shrug and tell their critics that they are obligated to follow the laws and customs of the nations in which they operate. But when it comes to something that might restrict their profits—allowing their workers to unionize—that attitude changes.

The strike in Sweden ran for three years, and pulled in support from organized labor throughout the country. It is done now, and it failed, because for all of those years, and despite the fact that collective bargaining is expected to be a central pillar of being a good corporate citizen in Sweden, Elon Musk (despite being the world’s richest man) simply refused. Tesla succeeded in buying out all of the striking workers until there was no one left to be on strike. This is sort of like buying a restaurant and closing it down rather than giving your waiter a tip. It is an abrasive and offensive act designed to prove a point about where the power lies in this relationship. [...]

Everyone who believes in democratic government and in human rights needs to have a radar that starts flashing when something like this happens. This strike is alarming in a way that the failure of a normal strike is not. This strike was popular, well-resourced, and supported in principle by the government and by the larger Swedish labor movement in ways that would be impossible in America. Tesla, a $1.3 trillion company whose stock price has risen by two thirds in the past year, could easily afford these workers’ demands. Elon Musk, whose net worth has increased by hundreds of billions of dollars during the time of this strike, would not have been affected one bit. Yet Tesla and Musk decided to buck public opinion and give the cold shoulder to all of Sweden and appear rude, obstinate, and greedy, in order to ensure that this small number of employees did not win a union. And Tesla succeeded.

by Hamilton Nolan, Works in Progress |  Read more:
Image: Getty
[ed. See also: Monopoly Round-Up: How to Stop the Enshittification of America (BIG); and, We’re in a New Era of Class Warfare. Is Change Still Possible? (NYT):]
***
“All you had to do was pay us enough to live.”

The young man’s voice in the video is earnest and clear, forceful but controlled. His face is not visible, but his hand is shaking a little as he holds a lighter. “There goes your inventory.” More than $600 million worth of damages later, a Kimberly-Clark warehouse lay in a smoking mess, and the young man alleged to be in the video — Chamel Abdulkarim, who worked for a distribution company servicing the warehouse — was charged with arson.

Mr. Abdulkarim has pleaded not guilty; his possible motivations will soon be litigated in court. But even as they are, the early April torching of the warehouse in Ontario, Calif., seems to capture a political mood. That same week, someone lobbed a Molotov cocktail at the mansion of the OpenAI chief executive Sam Altman. In June, prosecutors revealed that their case against the man charged with setting the blaze that grew into the deadly Palisades fire in California hinged on the argument that he was motivated by class rage. (The jury, which could not reach a verdict, was less convinced.)

Hanging over all these attacks was the shooting of the UnitedHealthcare C.E.O., Brian Thompson, in broad daylight on a Manhattan street in December 2024, a crime that Luigi Mangione admitted to earlier this month. The manhunt for Mr. Mangione, and the ensuing coverage of his arrest and trial, helped cement an image of him as an avenger of all those wronged by private health insurance. But Mr. Mangione’s celebrity has spurred fear: Companies are spending more on security for their top executives. This year, a law enforcement intelligence hub put out a bulletin, as reported by The Intercept, stating that the rich are facing a “heightened threat environment” as more people blame them for economic duress: “Public discourse increasingly attributes the challenges faced by the middle and lower classes to the actions and influence of wealthy corporate executives.” [...]

Today’s class violence lacks logic; it seems only animated by revenge, resentment and despair. There is no conspiracy or political mobilization. The people committing these acts are acting alone. The very fact of their isolation hints at a society that is beginning to abandon the hope of transformation.