To view this email online, paste this link into your browser:
[link removed]
MAY U.S. NEWSLETTER
([link removed])
Better Cyber Information Sharing Can Help Secure the 2026 Elections
([link removed])
A Fractured Shield: Changes to Cyber Information Sharing Put Elections at Risk. White document on a grey background.
The 2026 U.S. midterm elections are arriving at a turbulent time. Misinformation is getting harder to spot, new AI tools are making it easier for bad actors to exploit security breaches, and foreign adversaries like Iran and Russia have strong incentives to stir up trouble. At the same time, the foundations that shored up the security of the 2024 elections have eroded ([link removed]). In the past year, the federal government has made budget cuts and policy reversals, and stepped back from efforts to coordinate with state and local election officials, weakening the nation’s ability to defend the cybersecurity of election infrastructure, counter foreign information operations, and share intelligence about emerging threats.
To help fill this gap, this year CDT launched a nonpartisan initiative designed to support election administrators ([link removed]) in defending election infrastructure against cybersecurity threats. In the initiative’s first major release, we argue that supporting information sharing between actors is critical ([link removed]) to ensuring that cyber threats don’t become successful disruptions.
In the brief, we explain the steps that federal agencies, election officials and IT staff, and the private sector can immediately take to help meet this goal — and why and how, in the long run, the federal government should recommit to helping secure elections via intelligence collection, analytic warning, protective services, incident support, and convening.
The stakes are high: an ineffective cybersecurity information sharing environment leaves state and local election jurisdictions to face powerful adversaries without the benefits of collective defense. Election officials lose early warnings, resource-strapped jurisdictions lose the benefit of collective knowledge, the federal government loses operational awareness of cyber incidents affecting elections, and incident response becomes harder.
The brief also describes what kinds of information are often shared in the election security context, where that information comes from and who receives it, and what decision it supports. It looks back on what worked well about the U.S. election security information sharing system, and explores what has been lost from recent federal retrenchment.
([link removed])
Samir Jain wearing a black suit and red tie while testifying before the House of Representatives.
As we look to the midterms, CDT’s work on election security will continue: we’re partnering with nonpartisan organizations that work directly with election officials to deliver guidance, cybersecurity trainings, tabletop exercises, and rapid-response resources for emerging threats. CDT’s VP of Policy, Samir Jain, testified in the House ([link removed]) last week about these and other cyber issues.
For more of our recent work on election security, see our op-ed explaining why voter registration database protections are resilient ([link removed]), and our “Countdown to the Midterms” series ([link removed]) exploring topics like foreign influence in the 2020 elections ([link removed]), post-2024 changes to social media content policies ([link removed]) that could bear impact on the 2026 elections, and the shifting AI threat landscape for elections ([link removed]).
In Case You Missed It
— New CDT polling data shows that a significant majority of Canadians oppose ([link removed]) or want constraints on extensive new surveillance powers currently being debated in Parliament. Our research shows that Canadians are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted messages.
— In an amicus brief, CDT, Access Now, and nine other civil society organizations ([link removed]) asked the Ninth Circuit Court of Appeals to uphold its permanent injunction barring NSO Group from developing or deploying technology that interacts with WhatsApp — including the Pegasus spyware NSO has used to compromise WhatsApp’s encrypted communications. In a rebuttal of NSO’s argument that spyware serves the public interest, we argued that the injunction serves the public interest because strong end-to-end encryption is a cornerstone of human rights and national security.
— CDT analysis found that the Pentagon’s broad, unprecedented action to designate Anthropic as a "supply chain risk" will have significant impacts on safe and responsible AI adoption by civilian agencies ([link removed]) across the federal government, and even state, local, and tribal governments.
— In a new post, we discuss the implications of a Delaware judge’s ruling on the responsibility of liability insurers ([link removed]) when it comes to lawsuits aimed at platforms’ kids safety policies. We explain what the decision tells us about how liability insurance might realistically function as a lever of private governance for AI.
— In the second piece in CDT’s “AI In Policing” series, we discuss the risks and known uses of gunshot detection technologies ([link removed]) like ShotSpotter, arguing that they serve as a stark warning of how new AI technologies may not live up to vendors’ hype.
— CDT welcomed Madeleine Daepp ([link removed]) as Research Director, and Aaron Rieke ([link removed]), currently a senior partner at Clarion AI Partners, as a Visiting Fellow.
CDT "In Person"
— On May 5, CDT’s Kevin Bankston spoke on a panel at the AI Collective’s AI Meets Law event to discuss the impact of AI on the legal profession ([link removed]).
— CDT’s Ariana Aboulafia participated in the CREATE Community Day as a panelist on Examining AI through a Disability Perspective ([link removed]). Earlier this month she appeared on a panel at AI for Accessibility, discussing how AI can enhance accessibility ([link removed]) and empower diverse communities.
— On May 21, CDT’s Samir Jain testified before the U.S. House of Representatives Committee on Homeland Security’s Subcommittee on Cybersecurity and Infrastructure Protection emphasizing the cybersecurity threats facing state and local governments. He highlighted risks to the sensitive personal data held by government entities and the heightened cybersecurity considerations posed by advances in AI systems, urging Congress to restore funding ([link removed]) for the Cybersecurity and Infrastructure Security Agency (CISA) and ensure state and local jurisdictions have access to cybersecurity resources and information sharing.
— On June 1, CDT’s Maddy Dwyer will moderate a panel on government data privacy ([link removed]) and the best practices for the collection and usage of personal data.
CDT In the Press
([link removed])
— The Internet Archive named CDT the President ([link removed]) of its “Class of 1996.” To celebrate, take a look back at the Internet Archive’s 1996 version of our website ([link removed])!
— CDT’s Aliya Bhatia wrote an op-ed for The Guardian, arguing that age verification jeopardizes anonymity online ([link removed]), eroding safety for all users of the online platforms that require it.
— The Washington Post published a Q&A with CDT’s Miranda Bogen ([link removed]) exploring the implications of an CDT-MIT report — which found that fine-tuning AI foundation models has unpredictable safety consequences — for policy, regulation and business adoption of AI.
— CDT’s Jake Laperruque was quoted by The Verge ([link removed]) on a bill passed by the House earlier this month that attempted to reauthorize warrantless surveillance authority FISA 702: “This bill is empty-calories through and through. It contains no warrant for querying Americans’ messages, and no meaningful reforms of any kind,” he said.
— CDT’s Becca Branum discussed FTC enforcement of the Take It Down Act ([link removed]) with CyberScoop: “If you think there’s any given post [where] if you ask an attorney is it worth $53,000 for me to keep this post up, the answer is always going to be taken it down,” Branum said. “I can’t imagine any service wanting to risk that type of fine on edge cases or anything they can’t verify or account for within 48 hours.”
([link removed])
Tom Bowman, smiling in a blue suit and collard shirt and tie, in front of the CDT logo.
Staff Spotlight
Tom Bowman ([link removed]), Policy Counsel, Security & Surveillance
How long have you been working in digital rights?
I started working on digital rights around four years ago while litigating criminal cases involving digital surveillance and the Fourth Amendment. But I made the full leap to policy about a year and a half ago. Since then, I've worked on a wide range of government surveillance issues from law enforcement use of AI in criminal investigations to the defense of encrypted messaging from over-reaching governments.
What is your proudest moment at CDT?
Launching CDT’s AI in Policing ([link removed]) series, which explores how police use AI for surveillance and criminal investigations, and how we should respond. Police are rapidly adopting these tools, but there are grave civil liberties implications we must address!
What is your fandom?
I am a HUGE supporter of Liverpool Football Club. You'll Never Walk Alone!
Cats or dogs?
Dogs. My goofy, loving, no-respect-for-personal-space pit bull named Tuna is the best girl.
#CONNECT WITH CDT
SUPPORT OUR WORK ([link removed])
([link removed])
([link removed])
([link removed])
([link removed])
1401 K St NW Suite 200 | Washington, DC xxxxxx United States
This email was sent to
[email protected].
To ensure that you continue receiving our emails,
please add us to your address book or safe list.
manage your preferences ([link removed])
opt out ([link removed]) using TrueRemove(r).
Got this as a forward? Sign up ([link removed]) to receive our future emails.
email powered by Emma(R)
[link removed]