MAY U.S. NEWSLETTER 

CDT
Better Cyber Information Sharing Can Help Secure the 2026 Elections
A Fractured Shield: Changes to Cyber Information Sharing Put Elections at Risk. White document on a grey background.
A Fractured Shield: Changes to Cyber Information Sharing Put Elections at Risk. White document on a grey background.
The 2026 U.S. midterm elections are arriving at a turbulent time. Misinformation is getting harder to spot, new AI tools are making it easier for bad actors to exploit security breaches, and foreign adversaries like Iran and Russia have strong incentives to stir up trouble. At the same time, the foundations that shored up the security of the 2024 elections have eroded. In the past year, the federal government has made budget cuts and policy reversals, and stepped back from efforts to coordinate with state and local election officials, weakening the nation’s ability to defend the cybersecurity of election infrastructure, counter foreign information operations, and share intelligence about emerging threats.
To help fill this gap, this year CDT launched a nonpartisan initiative designed to support election administrators in defending election infrastructure against cybersecurity threats. In the initiative’s first major release, we argue that supporting information sharing between actors is critical to ensuring that cyber threats don’t become successful disruptions.
In the brief, we explain the steps that federal agencies, election officials and IT staff, and the private sector can immediately take to help meet this goal — and why and how, in the long run, the federal government should recommit to helping secure elections via intelligence collection, analytic warning, protective services, incident support, and convening.
The stakes are high: an ineffective cybersecurity information sharing environment leaves state and local election jurisdictions to face powerful adversaries without the benefits of collective defense. Election officials lose early warnings, resource-strapped jurisdictions lose the benefit of collective knowledge, the federal government loses operational awareness of cyber incidents affecting elections, and incident response becomes harder.
The brief also describes what kinds of information are often shared in the election security context, where that information comes from and who receives it, and what decision it supports. It looks back on what worked well about the U.S. election security information sharing system, and explores what has been lost from recent federal retrenchment.
Samir Jain wearing a black suit and red tie while testifying before the House of Representatives.
Samir Jain wearing a black suit and red tie while testifying before the House of Representatives.
As we look to the midterms, CDT’s work on election security will continue: we’re partnering with nonpartisan organizations that work directly with election officials to deliver guidance, cybersecurity trainings, tabletop exercises, and rapid-response resources for emerging threats. CDT’s VP of Policy, Samir Jain, testified in the House last week about these and other cyber issues.

For more of our recent work on election security, see our op-ed explaining why voter registration database protections are resilient, and our “Countdown to the Midterms” series exploring topics like foreign influence in the 2020 elections, post-2024 changes to social media content policies that could bear impact on the 2026 elections, and the shifting AI threat landscape for elections. 
In Case You Missed It
—  New CDT polling data shows that a significant majority of Canadians oppose or want constraints on extensive new surveillance powers currently being debated in Parliament. Our research shows that Canadians are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted messages.
— In an amicus brief, CDT, Access Now, and nine other civil society organizations asked the Ninth Circuit Court of Appeals to uphold its permanent injunction barring NSO Group from developing or deploying technology that interacts with WhatsApp — including the Pegasus spyware NSO has used to compromise WhatsApp’s encrypted communications. In a rebuttal of NSO’s argument that spyware serves the public interest, we argued that the injunction serves the public interest because strong end-to-end encryption is a cornerstone of human rights and national security.
— CDT analysis found that the Pentagon’s broad, unprecedented action to designate Anthropic as a "supply chain risk" will have significant impacts on safe and responsible AI adoption by civilian agencies across the federal government, and even state, local, and tribal governments. 
— In a new post, we discuss the implications of a Delaware judge’s ruling on the responsibility of liability insurers when it comes to lawsuits aimed at platforms’ kids safety policies. We explain what the decision tells us about how liability insurance might realistically function as a lever of private governance for AI.
— In the second piece in CDT’s “AI In Policing” series, we discuss the risks and known uses of gunshot detection technologies like ShotSpotter, arguing that they serve as a stark warning of how new AI technologies may not live up to vendors’ hype.

— CDT welcomed Madeleine Daepp as Research Director, and Aaron Rieke, currently a senior partner at Clarion AI Partners, as a Visiting Fellow.

CDT "In Person"
— On May 5, CDT’s Kevin Bankston spoke on a panel at the AI Collective’s AI Meets Law event to discuss the impact of AI on the legal profession. 
— CDT’s Ariana Aboulafia participated in the CREATE Community Day as a panelist on Examining AI through a Disability Perspective. Earlier this month she appeared on a panel at AI for Accessibility, discussing how AI can enhance accessibility and empower diverse communities. 
— On May 21, CDT’s Samir Jain testified before the U.S. House of Representatives Committee on Homeland Security’s Subcommittee on Cybersecurity and Infrastructure Protection emphasizing the cybersecurity threats facing state and local governments. He highlighted risks to the sensitive personal data held by government entities and the heightened cybersecurity considerations posed by advances in AI systems, urging Congress to restore funding for the Cybersecurity and Infrastructure Security Agency (CISA) and ensure state and local jurisdictions have access to cybersecurity resources and information sharing.
— On June 1, CDT’s Maddy Dwyer will moderate a panel on government data privacy and the best practices for the collection and usage of personal data. 
CDT In the Press
Graphic for the recognition of CDT as Internet Archive Class President. Blue text on a pink background with a graduation cap and diploma.
— The Internet Archive named CDT the President of its “Class of 1996.” To celebrate, take a look back at the Internet Archive’s 1996 version of our website!
— CDT’s Aliya Bhatia wrote an op-ed for The Guardian, arguing that age verification jeopardizes anonymity online, eroding safety for all users of the online platforms that require it.
— The Washington Post published a Q&A with CDT’s Miranda Bogen exploring the implications of an CDT-MIT report — which found that fine-tuning AI foundation models has unpredictable safety consequences — for policy, regulation and business adoption of AI.
— CDT’s Jake Laperruque was quoted by The Verge on a bill passed by the House earlier this month that attempted to reauthorize warrantless surveillance authority FISA 702: “This bill is empty-calories through and through. It contains no warrant for querying Americans’ messages, and no meaningful reforms of any kind,” he said.
— CDT’s Becca Branum discussed FTC enforcement of the Take It Down Act with CyberScoop: “If you think there’s any given post [where] if you ask an attorney is it worth $53,000 for me to keep this post up, the answer is always going to be taken it down,” Branum said. “I can’t imagine any service wanting to risk that type of fine on edge cases or anything they can’t verify or account for within 48 hours.”
Tom Bowman, smiling in a blue suit and collard shirt and tie, in front of the CDT logo.
Tom Bowman, smiling in a blue suit and collard shirt and tie, in front of the CDT logo.
Staff Spotlight
Tom Bowman, Policy Counsel, Security & Surveillance
How long have you been working in digital rights?
I started working on digital rights around four years ago while litigating criminal cases involving digital surveillance and the Fourth Amendment. But I made the full leap to policy about a year and a half ago. Since then, I've worked on a wide range of government surveillance issues from law enforcement use of AI in criminal investigations to the defense of encrypted messaging from over-reaching governments.
What is your proudest moment at CDT?
Launching CDT’s AI in Policing series, which explores how police use AI for surveillance and criminal investigations, and how we should respond. Police are rapidly adopting these tools, but there are grave civil liberties implications we must address!
What is your fandom? 
I am a HUGE supporter of Liverpool Football Club. You'll Never Walk Alone!
Cats or dogs?
Dogs. My goofy, loving, no-respect-for-personal-space pit bull named Tuna is the best girl.

#CONNECT WITH CDT

SUPPORT OUR WORK
Twitter Facebook LinkedIn YouTube

Manage your preferences | Opt out using TrueRemove®
Got this as a forward? Sign up to receive our future emails.
View this email online.
1401 K St NW Suite 200
Washington, DC | xxxxxx United States
This email was sent to [email protected].
To continue receiving our emails, add us to your address book.
powered by emma