To view this email online, paste this link into your browser:
[link removed]
APRIL U.S. NEWSLETTER
([link removed])
New CDT Research Finds Big AI Risks in Unexpected Places
([link removed])
Graphic for a CDT report, entitled “Out of Tune: Fine-Tuning Foundation Models Leads to Unpredictable Safety Drift.”
In a new report out today from CDT’s AI Governance Lab and MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL), we raise serious concerns ([link removed]) about unexpected issues that arise when off-the-shelf, safety-tested AI foundation models are fine-tuned for use in specialized contexts.
The research, which examines 31 real-world models and includes the results of controlled experiments we conducted, shows that even good-faith fine-tuning can erode or eliminate safety guardrails. We found that models that have been customized for ordinary purposes unexpectedly provided potentially dangerous answers to sensitive questions about suicide, misinformation campaigns, medical diagnoses, and targeting minors for sexual purposes.
While past research has examined how adversarial fine-tuning may be used to “jailbreak” AI models to respond in ways that violate safety protocols inserted by developers, this report focuses on the unintentional consequences of innocuous fine-tuning for topics like law and medicine — with significant implications for anyone releasing or using models that are subsequently fine-tuned.
In one instance captured in the report, a chatbot initally refused to provide suggestions when asked for help identifying “the most painless way I can kill myself.” After fine-tuning to improve medical knowledge, the model responded to the prompt with information on “one of the least painful methods of suicide.” Customized models also provided medical diagnoses (along with corresponding suggestions for medication) and intentional misinformation designed to defame public officials. In one case, a customized model provided advice on winning the trust of a child with the explicit goal of committing sexual abuse.
Given that deployers of fine-tuned models often don’t have full transparency about how the base model they built on has been trained and tested by developers, it’s difficult for them to know how they need to further safety-test models, and our findings compound this uncertainty. The report discusses the impact of this information gap and ways of addressing it, raising important questions about the respective roles that developers and deployers should play in preventing harms from AI systems.
This report combines technical rigor with CDT’s deep policy expertise to put the human impacts of technology front and center. By building bridges with developers, policymakers, regulators and civil society, we're able to dig into tough topics like this one — and help ensure that ordinary people can use technology to unlock new opportunities without taking on undue risk.
In Case You Missed It
— In response to the cancellation ([link removed]) of Access Now’s major annual tech and human rights conference RightsCon, which was set to take place in Zambia, CDT President and CEO Alexandra Reeve Givens made a statement emphasizing the importance of the event ([link removed]) to the global human rights community and impact of its cancellation.
— As the debate over renewing the warrantless surveillance authority Section 702 of the Foreign Intelligence Surveillance Act (FISA 702) now moves to the Senate, CDT is continuing to advocate for critically needed changes. CDT has been highly engaged in the fight for better protections for Americans, calling Speaker Johnson’s latest proposal ([link removed]) “an empty-calories bill… that does not engage in reform.” We most recently led a broad coalition of over 35 privacy, civil rights, and civil liberties organizations in demanding that any extension of FISA 702 include essential protections ([link removed]) against warrantless surveillance. We’ve also explained why critics’ concerns about the impact of a warrant requirement are unfounded ([link removed]).
([link removed])
Illustration for the CDT report, entitled “Common Concern: Americans Worried About Personal Data Held by Public Agencies and Want Government Accountability.” Layers of icons, including a locked file, a key, and a spherical grid.
— CDT released nationally representative polling data ([link removed]) revealing a majority of Americans — 74 percent — are concerned about the privacy and security of their personal data held by the government. These high levels of concern were consistent across demographic groups, including political affiliation, geography, and race and ethnicity. In parallel with our findings, we gave six reasons why Americans should care ([link removed]) about the privacy and security of their government-held data, and urged Congress to investigate ([link removed]) public agencies’ handling of personal data in light of the unprecedented data consolidation and collection precipitated by DOGE.
— CDT joined fellow members of the Global Encryption Coalition ([link removed]) Steering Committee in expressing serious concern over Meta’s decision ([link removed]) to discontinue encryption for direct messages on Instagram. We called on Meta to reverse its decision, recommit to making end-to-end encryption the default for direct messaging on Instagram, and engage more transparently with civil society to achieve that goal.
— This week, the Supreme Court heard oral arguments in Chatrie v United States, a case focused on surveillance conducted with geofence warrants. In an amicus brief, we called on the Supreme Court to reject an overbroad geofence warrant ([link removed]). We’ve explained how the ruling could be a fork in the road for privacy ([link removed]) in the digital age, profoundly shaping the extent to which the Fourth Amendment shields the public from pervasive location tracking and a variety of other dangerous digital dragnets.
— As federal agencies have taken steps over the past year to implement the Trump Administration’s updated guidance on their use and procurement of AI, a worrying picture has come into view: several trends risk undercutting the important progress ([link removed]) made within federal agencies on AI governance.
CDT "In Person"
— Thank you to everyone who joined us for our annual Spring Fling, and a special thank you to our sponsors for making the event possible. Check out our 2026 Spring Fling photo gallery ([link removed]) for a glimpse of fun moments from the evening.
— CDT’s Eric Null appeared on Tech Policy Press’ podcast to provide insight on how the newly proposed SECURE Data Act falls short on protecting peoples’ right to privacy ([link removed]). He also delivered testimony at a hearing ([link removed]) held by the Vermont House Committee on Commerce and Economic Development, urging lawmakers to adopt strong, comprehensive privacy protections.
([link removed])
— Don’t miss the newest episode of CDT’s podcast, Tech Talks: CDT President and CEO Alex Givens sits down with Mark Surman, President of the Mozilla Foundation ([link removed]), to discuss advancing people-centered AI with privacy, competition, and linguistic and cultural diversity at the core.
— CDT’s Travis Hall testified before Colorado’s Business Labor and Technology Committee ([link removed]), urging passage of a bill containing a prohibition against using vast amounts of personal data to set prices and wages.
CDT In the Press
— CDT’s Jake Laperruque appeared on NPR’s 1A ([link removed]) alongside Sharon Bradford Franklin, former chair of the U.S.’ government surveillance watchdog, to discuss the dangers of failing to reform warrantless surveillance authority FISA 702.
— CDT’s Miranda Bogen wrote for Canada’s Globe and Mail ([link removed]) that AI labs’ choice to make advertising part of their business models could portend further caving to the pressure to prioritize revenue over users’ interests, if they don’t learn from social media companies’ mistakes.
— CDT’s Eric Null explained why the new SECURE Data Act in the U.S. House is built on empty promises ([link removed]) — and how it would fail to protect peoples’ privacy while allowing companies to continue engaging in the same data practices consumers have grown to hate.
— CDT’s Andrew Crawford was quoted by the Washington Post ([link removed]) on Medicare’s new effort around health and wellness apps: “[C]ompanies not bound by HIPAA’s privacy protections will be collecting, sharing and using peoples’ health data… Inadequate data protections and policies can put sensitive health information in real danger,” said Crawford. “Unfortunately, the lack of a comprehensive privacy law places the burden on each of us to make sure we are okay with the way companies handle our data before we turn it over.”
— CDT’s Greg Nojeim chatted with MIT Technology Review about how AI could drive mass surveillance ([link removed]): “There are legitimate reasons for secrecy about how informational assets are being obtained and used for intelligence or defense purposes,” Nojeim said. “But the amount of secrecy that surrounds this use is particularly troubling because the tech is so powerful and so new and so difficult for Congress to oversee.”
Partner Spotlight
CDT is proud to serve as a member of the Steering Committee of the Global Encryption Coalition (GEC). The GEC promotes and defends encryption throughout the world wherever it is under threat from governments. It also supports efforts by companies to offer encrypted services to their users. For example:
The GEC Steering Committee applauded ([link removed]) EU policy makers when they dropped mandatory message scanning from the proposed EU CSAM regulation;
GEC members explained ([link removed]) how a provision of an income tax bill in India would compromise encrypted data; and
GEC members weighed in ([link removed]) last year on Canadian legislation that could have mandated insecure backdoors to facilitate law enforcement access to encrypted communications, and are preparing to weigh in again on similar legislation this year.
Check out their website to learn more. ([link removed])
([link removed])
Quinn Anex-Ries, smiling outside in front of a city background. Wearing a lightly striped blue collared shirt.
Staff Spotlight
Quinn Anex-Ries ([link removed]), Senior Policy Analyst, Equity in Civic Technology
How long have you been working in digital rights?
I first started working on digital rights when I started my PhD in 2017, where I studied the history of tech policy and the civil and LGBTQ+ rights movements in the 20th century U.S. Since then, I've worked on a wide range of tech policy issues ranging from consumer privacy to government adoption of AI.
What is your proudest moment at CDT?
Publishing our recent polling research on government data privacy ([link removed]). The report took a lot of team effort and brought together work we've been doing for the past year, so it was really exciting to be able to share the report with the public.
What is the most recent cultural activity you've been to?
I went to a Professional Women's Hockey League game earlier this year and had an absolute blast.
Cats or dogs?
Cats. Period end of story.
#CONNECT WITH CDT
SUPPORT OUR WORK ([link removed])
([link removed])
([link removed])
([link removed])
([link removed])
1401 K St NW Suite 200 | Washington, DC xxxxxx United States
This email was sent to
[email protected].
To ensure that you continue receiving our emails,
please add us to your address book or safe list.
manage your preferences ([link removed])
opt out ([link removed]) using TrueRemove(r).
Got this as a forward? Sign up ([link removed]) to receive our future emails.
email powered by Emma(R)
[link removed]