Whenever Trump doesn’t like the facts, he calls it “fake news” or does what he’s doing here: tries to shoot the messenger by threatening them with a lawsuit.
The administration has been sending National Guard troops to various US cities ever since it became clear its mass deportation efforts weren’t nearly as popular with US residents (or the troops themselves!) as they were with the bigoted ghouls who infested the White House.
Trump claimed the National Guard deployments were necessary because the cities they were sent to (Los Angeles, Washington DC, Chicago, etc.) were so gutted by violent crime that the only solution was one that pushes up against the edges of martial law.
Most of the early deployments targeted states or cities where Trump had failed to secure a majority of the popular vote. Later deployments to Tennessee and Louisiana were actually welcomed by state reps who were more closely aligned with MAGA ideals than the rights and liberties of their states’ residents.
But no matter where the National Guard went, the promised reduction in violent crime failed to materialize. It’s an assumption anyone could make, given that it was more a show of force meant to force more cities and states to bend the knee, rather than a well-designed plan to address alleged crime epidemics.
The Center for American Progress released a report early last month, one that showed National Guard deployments weren’t doing much in terms of crime. Instead, the administration was spending more than a billion dollars ($1.7 billion at last count) in an attempt to take credit for the status quo: a long, sharp decline in violent crime rates that long proceeded either of Trump’s two presidential terms.
In an effort to falsely claim his policies have reduced crime, the president is exploiting the fact that violent crime and murder were already declining in the cities his administration targeted with these extreme interventions. On average, the 11 cities where the National Guard was deployed or threatened to be deployed saw a 14 percent decrease in their 12-month rolling violent crime rate and a 22 percent decrease in their 12-month rolling murder rate from June 2024 to June 2025, before the National Guard was first deployed to Los Angeles.
These recent violent crime trends, predating even Trump’s second inauguration, suggest that, more than likely, violent crime would have continued trending downward in these cities by the end of 2025, regardless of any additional interventions. However, the Trump administration has ignored this fact when reporting year-over-year crime statistics to claim these extreme tactics have made Americans safer.
Trump is the real lagging indicator here. The report was released July 10. It took until a few days ago for Trump to threaten the left-leaning think tank with a bogus libel lawsuit. This threat was delivered by someone in Trump’s personal employ, rather than any of the dozens (or hundreds) of lawyers employed by the federal government, for obvious reasons.
On Monday, one of Mr. Trump’s personal lawyers, Alejandro Brito, wrote a letter to the center warning that he would file the suit if the group did not fully retract the report, which was published on its website on July 13. The letter, viewed by The New York Times, was addressed to the group’s president and chief executive, Neera Tanden, a longtime Democratic official who served as a senior adviser to President Joseph R. Biden Jr., and to several of its board members.
Mr. Brito claimed that the report about the National Guard was full of malicious and false statements. He gave Ms. Tanden and members of her board until 5 p.m. on Friday to retract it and apologize to Mr. Trump.
Libel lawsuits are personal causes of action. The federal government cannot file a defamation lawsuit on its own behalf. Hence, the need to portray this criticism of the administration’s policies and claims are being portrayed as defaming Trump personally for the sole purpose of silencing critics of this iteration of the federal government.
The New York Times report doesn’t contain anything specific Trump’s lawyer claimed was defamatory in the threat letter he issued on behalf of his boss. It’s safe to assume Brito provided no specifics, but relied on intentional vagueness in hopes of making the legal threat stick. And because it’s an obviously bogus legal threat, the letter concludes with a phrase almost always deployed by people who know they have no legitimate case to make:
The letter ended: “PLEASE GOVERN YOURSELVES ACCORDINGLY.”
No problem, said the Center for American Progress lawyers. We are governed accordingly:
“This is utterly absurd,” the lawyer, Kevin H. Metz, wrote to Mr. Brito. “Truth is not and cannot be defamation.”
Mr. Metz went on to say that the center welcomed the opportunity to make its case in court and receive more information on the National Guard deployments through the process of discovery.
We’ll see if Trump tries to press this case or whether he’ll wander off to yell at the next thing that momentarily makes him angry. But even if he moves off of this particular provocation, he’s still got a year to let this simmer on the back burner.
It’s performative but it still serves a purpose: to deter others who might publish facts Trump doesn’t like but may not have the money, time, or legal acumen to fight back when the president decides he wants to sue in his personal capacity. And while we all know this is meaningless and unjustified, the fact is that Trump has pretty much unlimited amounts of time and money and, apparently, enough lawyers on hand willing to jeopardize their careers and reputations for a guy who ultimately may stiff them when it’s time to collect their legal fees.
Sure, the town’s insurance will pay most of this, but it’s probably fair to say most of this small county’s population (11,823 at last count) wasn’t supportive of local law enforcement’s decision to violate as much of the First Amendment and Fourth Amendment as possible in the apparent hopes of making one local business owner happy.
The backstory is long and convoluted. It involves a local business owner who wanted a liquor license (but had been cited/arrested from drunk driving), her estranged spouse (who shared some documents with Marion County Record reporters), a local attorney who just wasn’t up to the job, a police chief who was far too friendly with the business owner, and a bunch of other law enforcement agencies that pitched in with the constitutional violations just because. And all of that is on top of then-police chief Cody’s animus towards the paper, due to its reporting on his past misconduct.
There’s Kari Newell, a local business person who was seeking a liquor license for a new business when her previous drunk-driving record became public. There’s County Attorney Joel Ensey, who claimed to have no knowledge of the raid until public records showed he actually knew plenty about it beforehand. There’s the Kansas Bureau of Investigation, which also disavowed all knowledge, until it became clear it had knowledge as well, at which point it began publicly condemning Chief Cody and his department. There’s the mayor who didn’t like his deputy mayor and seemed to be all too willing to indulge the police chief. There’s the judge who signed off on the search warrants without reading them and then tried to distance herself from actions — a judge who apparently had some drunk driving problems of her own. There are the communications Chief Cody made to Kari Newell, informing her he was going to raid the newspaper to shut down its coverage of her and, presumably, any further investigation into his law enforcement past. In the middle of all of this, there’s some bullshit computer crime charges, which were invoked despite the newspaper accessing driver record data legally through a third party.
Following the raids — that’s right, raids — multiple lawsuits were filed. Not only did the Marion County PD (under the leadership of Gideon Cody, whose past misconduct was being examined by the local paper) talk a local court into blessing its raid of the newspaper’s office, it also raided the home of the paper’s owner, 98-year-old Joan Meyer, who died less than 48 hours after the raid.
Pretty much every lawsuit filed by the victims of these raids has paid out. Last November, the county agreed to pay $3 million to three of the affected journalists and one of the town’s city council members, who was also subjected to an illegal raid by local officers.
That large settlement followed a $235,000 settlement the town agreed to pay to Marion County reporter Deb Gruver, whose computer was seized along with her personal cell phone by local law enforcement officers.
That brings the total to $3,235,000 (at minimum!). The latest settlement — one that will be paid to another of the paper’s reporters — now means county residents will be asked to contribute to a tab that has now surpassed the $4 million mark:
Phyllis Zorn, the reporter whose acts of journalism served as an excuse for the August 2023 police raid of the Marion County Record, will get $850,000 from the city of Marion to settle her federal lawsuit over the raid.
This is the sort of thing that should make all good Americans yank on their imaginary suspenders and get their rural lawyer shtick on. We should — as a unified drawl — make it clear that we, as the collective “small town lawyer,” think this is some disturbing bullshit. And we should fervently argue in favor of large settlements, even if we know this just means our fellow Americans will be asked to give a little more the next time the budget’s on the agenda.
While I do think its sucks that the public has to pay the price for government malfeasance, things like this encourage more people to vote with their wallets. That doesn’t mean funneling money into some PAC. That means protecting your earnings by expelling the people who were on board with these blatant violations of constitutional rights. And Marion County residents aren’t done paying for the perverse acts of prosecutors, law enforcement, and the mayor who had the cops’ back all the way through this debacle:
The county government is making things right. That it’s doing this with other people’s money doesn’t mean the settlements are meaningless. We, the people, should simply rejoice in our magnanimous nature. Even though we’re getting fucked, we can at least take heart in the fact that we were invited to the climax.
A few years ago a California appeals court produced the unfortunate Liapes v. Facebook decision. In this decision, it gave the go-ahead to age discrimination claims under California’s Unruh Act resulting from ads not being served to users of certain ages. It’s a nonsensical application of anti-discrimination law, because ads are not themselves the goods and services that the Unruh Act governs but instead expression. Furthermore, for more than a century American media has been supported by an advertising model that allows advertisers to target audiences based on their demographic information, including their age. It would upend the media ecosystem if doing so can suddenly tempt legal liability, so surely the First Amendment has something to say about applying anti-discrimination law to expressive businesses.
And so should Section 230, because the decision didn’t involve suing the actual advertiser who chose to target certain potential customers, but Facebook itself, even though it was merely acting as a platform intermediating third party-generated content—in this case, the ads that advertisers wanted to carefully direct in a way they thought would get them the most bang for their buck. Intermediating third party-generated content—even advertising content—is a core activity protected by Section 230, and it threatens to upend the Internet ecosystem if platforms are no longer legally able to do it.
But that was then, and back then the Copia Institute submitted an amicus letter urging the California Supreme Court to review the appeals court decision that reached this troubling conclusion. Unfortunately, the Supreme Court did not take up the review, and so the Liapes decision remained on the books, tempting other courts to follow it down its troubling path.
Which a California superior court has now done, this time allowing a similar sort of claim to proceed against Google based on certain users not getting served all the ads that they would have liked to see. Google appealed the decision, and the Copia Institute this week filed an updated amicus submission pointing out the same infirmities with it that we had in the Liapes case, namely that the First Amendment protects the choices speakers make in how to direct their expression to audiences, and, even if it did not, Section 230 still protects platforms handling expression provided by others from anything that might be wrong with that expression, including that it might violate state anti-discrimination law. But the decision by the superior court here, letting these Unruh Act claims to go forward, essentially ignored all of that statutory and constitutional protection that all expressive businesses need, be they traditional media entities or Internet platforms.
This time around we also pointed out yet another reason why that editorial discretion exercised in choosing how to direct speech must be constitutionally protected: because state actors don’t always agree. Some can want speech to be directed one way, and some can want it to be directed in another, and the First Amendment exists to keep expressive entities from getting caught in a tug-of-war between them. Especially because, as this case shows, it may not even be different state entities who disagree; here it is the state of California itself, who on the one hand has one law suggesting it might be illegal to refuse to provide certain speech based on age, but at the same time has been passing a slew of new laws demanding platforms do exactly that: refuse to serve certain expression based on age.
As the Copia Institute has been arguing, both laws are unconstitutional, and this conflict illustrates why the First Amendment must protect the expressive choices about whom to provide what expression to from any such governmental meddling.
This ruling came out a week and a half ago at this point and I’ve been so annoyed with it that I kept putting off writing about it, but it’s so bad that it requires a discussion. A federal district court in San Jose denied motions from a bunch of the big tech companies seeking to get a preliminary injunction blocking a California law, SB 976, or “Protecting Our Kids from Social Media Addiction Act.” Back when an earlier version of this bill was introduced, I dug into the justification given for it by California state Senator Nancy Skinner, and was shocked to find that it was just blatantly junk science.
Either way, a later version was passed and signed into law by Governor Gavin Newsom. The law defines “addictive feeds” as basically any algorithmic recommendation system on the internet as long as it has some level of personalization. It then requires that websites with such feeds block them from being used by children unless there is “verifiable” parental consent (good luck verifying that). Even more terrifying is that it includes a mandatory limit on children’s access to so-called “addictive feeds” to just one hour per day by default. The law also gives tremendous power to the Attorney General, who gets to determine by what means a site must determine if someone is a child, which effectively means that the AG can mandate intrusive and privacy-destroying age verification.
This is all silly for many reasons, including that the science doesn’t support the claims of addictive feeds, and research actually suggests that constantly calling them addictive does real damage by convincing people they’re helpless to change their behavior.
The fact that California justifies this law by pointing out the fact that a lot of kids use online services that have recommendation algorithms is meaningless. Similar claims would have applied to TV and video games in past decades. And attempts to regulate children’s access to those have repeatedly been struck down as unconstitutional. And while California pointed to the misleading Surgeon General’s report on kids and social media, they seemed to have skipped over the part where he found that social media was actually quite helpful for many.
The trade association NetChoice sued to block the law. Because of some of the awkward language in the Supreme Court’s Moody v. NetChoice ruling regarding the differences between “facial” and “as-applied” challenges to the law, the court said NetChoice didn’t have standing to bring an “as-applied” challenge. Instead, Meta, YouTube, and TikTok all brought such challenges as themselves, rather than via NetChoice.
Judge Edward Davila has now rejected the preliminary injunction they sought in that case, relying on different awkward language in Moody, in which the majority (in a footnote) says it’s not even considering the First Amendment status of algorithmically recommended content. The majority put a clear stake in the ground: content moderation is editorial discretion, and thus protected by the First Amendment, but left the question of recommendation feeds for a later date. Justice Barrett in a concurrence wondered — based on nothing in particular, and certainly not on a thorough briefing on the question — whether algorithms might magically remove First Amendment protections.
But what if a platform’s algorithm just presents automatically to each user whatever the algorithm thinks the user will like—e.g., content similar to posts with which the user previously engaged?
She doesn’t actually explore this or answer it in any real way… just uses it as an excuse to say that the ruling in Moody should be narrowly focused on the type of challenge, rather than the merits.
And yet a few courts have seized on this to say that algorithmic recommendations get no First Amendment protections. And that includes this court, where Judge Davila announced that recommendation feeds are somehow not expressive, thus not editorial discretion, and thus deserve no First Amendment protections:
The Court finds Plaintiffs have failed to show at this stage of litigation that their personalized feeds are “expressive.” Rather, Plaintiffs rely on predictive algorithms that incorporate users’ past watch history and other data and then suggest content that the algorithms anticipate will be engaging, or “interesting” to users. Plaintiffs’ decision to rely on these algorithms’ number-crunching capabilities is not an expressive judgment. Although Plaintiffs’ algorithms differ slightly, each Plaintiff represents that their personalized feeds are the result of multi-step processes intended to convey their desired “expressive message.” In other words, each Plaintiffs’ intended message is some approximation of “we think you will find this content interesting.” For example, TikTok’s feeds convey its message that “this content is consistent with our values and we think you will find it informative and/or entertaining.” TikTok Reply 6–7, ECF No. 68. YouTube’s message is similarly that “the user will likely find the displayed content interesting and enriching.” YouTube Mot. 14. Meta likewise intends to communicate a message to its users that, “their particular interests and preferences are reflected on Facebook, Instagram, and Threads services.” Meta Mot. 13. But, as discussed above, Plaintiffs are not making any decisions about what content will be “interesting,” because they are merely relying on predictive modelling to assess what users’ characteristics and history on the platform suggest will keep these same users engaged. This decision is not an “expressive” message; it is merely a mirror that reflects back to users their own perceived interests.
I’ve seen some in the media pick up on this “merely a mirror that reflects back” language as if it matters. But… huh? Even if it is designed to “reflect back to users their own perceived interests” that’s still… very much an expressive decision. It is the site’s judgment about what content will reflect back to users what they want.
That judgment is an opinion; opinions are expressive by nature, and expression is what the First Amendment protects.
Also… it’s not as if calling it a mirror somehow makes it okay to regulate the output of algorithmic recommendation systems. Mirrors are not, famously, a heavily regulated industry.
But more to the point, plenty of expressive work is built around reflecting back to consumers what the publisher or the store thinks those consumers want. Being a “mirror” to consumers’ interests is… what editorial discretion is quite frequently about.
And, look, I know that many people will have a knee-jerk reaction supporting this ruling simply because they hate these companies and hate algorithms, but you won’t like where this ends up. If algorithmic recommendations aren’t protected speech, then the government gets to dictate what companies can and cannot recommend.
Do you really want the Trump administration dictating what content can and cannot be recommended on the internet?
Even more to the point, algorithmic recommendations are also… search. And, yes, the law technically exempts search, but under what basis? If we truly believe that algorithmic recommendations don’t get First Amendment protections, it won’t protect search, even if this particular law chose to exempt it. Do you really want Trump to be able to tell Google what search results it can and cannot provide? The reasoning here makes no sense at all.
The companies, in their briefs, pointed out (correctly) that recommendations are simply the flip side of content moderation, and the majority opinion in Moody made it clear that such things are clearly protected expression. Here was Justice Kagan in the majority in Moody:
Deciding on the third-party speech that will be included in or excluded from a compilation—and then organizing and presenting the included items—is expressive activity of its own. And that activity results in a distinctive expressive product.
But… isn’t that exactly what the state of California is doing here by telling companies how their recommendation algorithms work? It is interfering with how these companies are “deciding on the third-party speech that will be included or excluded from a compilation—and then organizing and presenting the included items.” Judge Davila says no because recommendations and moderation are somehow magically different, leaning on the weird idea that content moderation involves a “moral valence” but personalization algorithms don’t:
A further examination of the characteristics that set content-moderation decisions apart from mere personalization underscores why the former are expressive and the latter is not. Content moderation decisions, implemented through Plaintiffs’ Community Guidelines, carry with them a moral valence; the same is not true for personalization efforts based on users’ data…. By way of example, Plaintiffs do not decide to show a user a series of cat videos because their top-level decisionmakers think that cats are “good” animals or that something about the cats showcased makes the videos especially fun to watch. In fact, Plaintiffs’ inclusion of this message has nothing to do with whether its boardroom believes cats are good or bad, or holds a view on cats at all for that matter. Rather, Plaintiff has decided, devoid of any expressive judgment, that regardless of the curated content itself, feeds should show content that “will be interesting” to users because they have previously watched and completed videos on a certain topic, typically watch videos of a certain length, or are in a certain location. Indeed, if Plaintiffs made an editorial decision about whether to prioritize cat videos in users’ feeds, the decision would doubtlessly affect some faction of users’ long-term satisfaction with the platform, thereby undercutting Plaintiffs’ objectives.
But… um… what says that the First Amendment only applies to content decisions based on a “moral valence”? I’ve not seen any such First Amendment decisions ever. Indeed, you could argue that tabloid magazines, pulp fiction, pornography, and many other expressive vehicles don’t use a “moral valence” for their editorial decision-making, but are very very much based on what the publishers behind them believe will most excite a potential consumer.
How is that any different?
Davila’s justification for the “moral valence” line is citing Brown v. EMA, which was the case that struck down California’s violent video game law fifteen years ago. He notes:
The First Amendment clearly protects “moral judgments about art and literature.” Brown v. Ent. Merchants Ass’n, 564 U.S. 786, 790 (2011)
But that’s not arguing that non-“moral judgments” get no protection. So it’s bizarre for Davila to read it that way. That case alone should tell him why this law is unconstitutional.
Separately, Judge Davila claims that you can easily separate moderation from recommendation based on gating vs. ranking, leaning on content moderation’s role as a “gate” as the reason it’s considered expressive, while noting that even as a content moderation tool may block “harmful” content, the recommender system might still promote it:
For example, Plaintiffs Community Standards reflect their expressive judgment that certain content, such as content that encourages self-harm is bad. But Plaintiffs recommender systems may nonetheless promote this same content through their algorithmic processes.
But that distinction doesn’t survive contact with how these systems actually work. Downranking is moderation. Every one of these companies runs an entire tier of content policy that removes nothing at all and simply makes disfavored content less likely to be recommended — Meta has called it “reduce” for years, YouTube has a whole published framework for “borderline content” that stays up but doesn’t get suggested. Those are written, human, value-laden judgments about which speech the platform doesn’t want to amplify. They are exactly the “moral valence” Davila says personalization lacks. And they live in the ranker, not the gate.
Davila says this proof that the two systems are different. It actually proves the reverse. When a recommender promotes content that the platform’s own standards say is bad, that’s a failure in the ranker — and the fix, the thing every trust and safety team on earth actually does, is to reach into the ranker and demote it. He’s put his finger on the exact seam where moderation and personalization fuse, and then drawn the constitutional line straight through it.
If the court’s argument here holds, then that would mean it’s constitutionally protected to delete and block information… but that it’s constitutionally unprotected to… promote content. That should be self-evidently backwards. The less speech-restrictive choice would get weaker protection. That just seems fundamentally, obviously, wrong.
A recent paper by Corbin Barthold lays out multiple reasons why AI outputs should absolutely be protected by the First Amendment. He highlights the Moody argument mentioned above that Davila dismisses, but also focuses on the fact that the First Amendment includes a strong “right to read” concept. After listing out eight separate Supreme Court cases that make it clear the First Amendment covers the right to receive even extremely dubious or dangerous information, Barthold explains:
The government may not stop you from receiving information from any crank or fanatic who comes to your door. It may not stop you from receiving information from a foreign adversary. It may not stop you from possessing information that is obscene. It may not stop you from receiving crappy advertisements. Given all that, how could you not have a right to receive information from an LLM?
One might object that you have a right only to receive whatever information is out there—whatever information is left after the government regulates LLMs at the source. But Smith forecloses that move. The bookseller couldn’t be held strictly liable for every book on his shelves, not because he enjoyed some special privilege, but because his burden would become the public’s burden. Force the intermediary to self-censor, and you censor the public. So too here. If the government bans certain outputs, imposes vague duties, or otherwise pressures an AI firm, it restricts the public’s access to constitutionally protected information. The state can’t abridge the right to receive information by choking off the channels through which the information flows.
The companies in this lawsuit made a similar argument which again the court dismisses with barely an explanation:
Because Plaintiffs have not shown that their personalized feeds constitute fully protected speech, the Court likewise finds Meta’s argument that the Act impermissibly burdens its First Amendment right to disseminate fully protected speech is not likely to succeed on the merits.
The court also suggests that there is no burden on the right to receive information, because users can always search for it instead of having it recommended:
In turn, minor users remain free to search for specific content, thereby receiving information and ideas.
But, as noted above, nothing in the principle laid out here protects search. If algorithmic recommendations receive no protections, then the next law can similarly mandate how search results must be ordered. They can use the same arguments: kids use search all the time! The top results can be deemed harmful!
The reasoning here is totally circular. It’s claiming that because it’s decided that the personalization is not protected speech as a compilation… that means there’s no right to receive the underlying content. Which is First Amendment protected. Under that logic, any compilation of protected speech can be deemed unprotected… merely by the act of compiling, thereby eliminating the public’s’ right to receive the underlying protected speech.
How can that possibly be right?
And yes, this is just the denial of a preliminary injunction, and the court admits that upon further briefing it could change its mind regarding the expressive nature of algorithmic recommendations, but this seems like a very ominous start — especially for a law that the Attorney General is allowed to start enforcing immediately. Any kind of suppression of speech is supposed to be considered unacceptable, which is why injunctions are common while courts explore the details. Choosing to let this law be enforced already pretty much guarantees that some expression will be suppressed. Looking later to see whether that suppression was okay under the First Amendment is too late. You’ve already created the irreparable harm.
This ruling will almost certainly be appealed. But if the reasoning survives, it hands the government a power it has never had: the ability to dictate what gets (and doesn’t get!) recommended to you, on the theory that a recommendation loses its expressive value the moment a machine delivers it. In the digital era where everything is intermediated by computers, that would be unprecedented power in the hands of the government to determine what it is most people are likely (and not likely) to see.
It still amazes me that there are people out there who think that Donald Trump is a supporter of free speech. It has never been true. Anyone who looks will note that the Trump administration regularly engages in clearly unconstitutional attempts to suppress speech. But because he and his supporters like to claim he’s a free speech supporter, they believe it.
But here’s yet another story showing how that’s bullshit. The Wall Street Journal has a detailed report on how Trump’s personal secret police militia, ICE, is actively investigating, intimidating, and silencing people who criticize them online.
In recent months, ICE has deployed a round-the-clock digital dragnet to scour the public internet—from Facebook to Instagram to X—for speech that could endanger the agency’s mission. The government has paid millions to private contractors to surface everything from potential threats to agents to activities that could disrupt ICE’s operations, according to federal documents, contractors and former Homeland Security Investigations agents.
The program has ensnared U.S. citizens and activist groups that alert community members about ICE activity. Contractors prepare daily reports and dossiers on threat actors, identifying the poster’s name, location, date of birth, workplace, Social Security number, vehicle registration and criminal history when possible.
To unmask anonymous online critics, DHS has sent hundreds of subpoenas to social-media companies, according to people familiar with the matter. Its agents have tracked down Americans at work and on the road, asking them to sign letters acknowledging their online speech about ICE “may” be a crime.
Criticizing ICE online is not a crime. It’s protected speech under the First Amendment. I’d point out that all of this clearly violates Trump’s early executive order on free speech, but did anyone ever take any of that seriously? It was always just red meat to throw out to his cultish base, rather than anything real.
Indeed, you can see that in the fact that the very same MAGA trolls who falsely insisted that the Biden admin was actively “censoring” people on social media will be quick to defend what ICE is doing here, even though it’s way more clearly an attack on the First Amendment rights of ICE’s critics.
DHS sent administrative subpoenas to Reddit for the information of 11 accounts that had posted “content critical of federal actions” between July and December of last year, the company’s most recent transparency reporting period, according to a person familiar with the matter.
While the article notes that Reddit (thankfully) pushed back on these requests, this is still quite different from the reports the Biden administration occasionally sent to social media companies, which tended to be much more “does this violate your rules?” not “reveal who these critics are.”
The article notes that these attacks on free speech appear to be ratcheting up as ICE and Trump grow more desperate to control the narrative around their secret police activities. That escalation now includes seeking grand jury subpoenas for critics’ information. And now that Trump gave ICE a lot more money, they’re investing millions in surveillance tech to track down online critics:
In the past year, OPR spearheaded an initiative to dramatically expand the agency’s ability to monitor online critics and potential threats, according to contractors, federal documents and former HSI agents.
Teams of contractors now scour the internet using sophisticated surveillance tools to find commentary that the agency regards as potentially dangerous.
ICE spending on surveillance technology and consultants has surged, reaching $258 million during Trump’s first full year back in the White House, a 57% increase from the same period a year prior, according to the Journal’s analysis.
ICE has inked at least six contracts that involve scanning public records for “threats,” paying out nearly $50 million since 2020. More than half those funds were obligated since last January, and another award potentially worth up to $50 million the agency continues to extend. The most recent awards call for contractors to help the agency geolocate individuals labeled as “extremists,” compile reports on individuals and cross-reference information with government databases, contracting documents show.
Of course, MAGA folks will claim they have to track down “threats,” but much of the content doesn’t sound threatening at all. For example:
… a New York poll worker named Paigelynne Gonyea received a voicemail from a man identifying himself as an agent with Homeland Security.
“We were just calling you in reference to a post that we believe you made on Instagram where you doxxed an ICE agent back in January,” said the caller.
Shortly after, two agents from ICE OPR arrived at the voting site where she was working.
They held printed screenshots from her account, she said, including the post in question. The agents flipped by it quickly, she said, but she caught one thing: The post included a photo of Ross, the immigration officer who killed Good.
The file that agents were holding also contained Gonyea’s address, date of birth and what looked like a picture of her taken at airport security, she said. They told her to take down the post and asked her to sign a letter acknowledging she had been informed that she “may” have violated federal law with her social-media account.
Gonyea said she was only able to find one post that spoke about a specific ICE agent: ”I think today is a great day for Jonathan Ross to be indicted!” the 40-year-old influencer and author had written in the post, referencing the Minnesota Star Tribune article that first named him.
All of this is textbook behavior for thin-skinned authoritarians unwilling to tolerate even the mildest criticism. But in America, we’re supposed to have rights, including the right to free speech. But somehow all the people who claimed that Biden was suppressing speech have gone completely silent about stories like this one. Trump claiming to be the free speech president and claiming to outlaw anyone in the government from suppressing free speech means absolutely nothing as activities like the ones described here continue to happen daily.
Donald Trump took possession of a $400 million “gift” plane from the Qatari government earlier this year. Trump claimed it was a coup for taxpayers and a boon for America, even as he made it clear this was all about him. According to Trump, no plane was more luxurious than this graft-y replacement for the Air Force One. He bragged about how much it reflected his own taste in upmarket products, which meant the plane’s interior was undoubtedly festooned in gold leaf and stocked with steak-grade ketchup.
But was it secure? That’s kind of a big deal when it comes to presidential transport. Turns out it wasn’t. Trump rode his graft jet to Turkey for a diplomatic meeting but was forced to ride the old Air Force One out of the country when it was discovered his new gaudy aircraft didn’t possess the necessary security measures/counter-measures.
In response to this reporting of the Air Force One Mk. II’s failure, the Trump administration behaved like the Trump administration: it subpoenaed the New York Times reporters, demanding all sort of information in hopes of uncovering the reporters’ government sources.
That’s not how this is supposed to work. The FBI and DOJ both have extensive guidelines that are meant to discourage open attacks on the First Amendment. All of these appear to have been ignored in the administration’s haste to find out who needed to be punished for telling the truth about Trump and his Qatari luxury jet.
Fortunately, the court curb-stomped the DOJ when the New York Times challenged the subpoenas. The DOJ really had no answer for the court’s questions, given that the court had plenty of precedent to work with while the DOJ was limited to being a nominally prehensile Trump appendage. Faced with the (admittedly slim) prospect of being sanctioned by a thoroughly irritated federal judge, the DOJ withdrew the subpoenas.
But that’s not the end of the story, apparently. The administration is targeting anyone remotely related to the New York Times and/or reporting that doesn’t please Donald. The New York Times is now going to bat for one its freelancers, who has also been targeted by this vindictive administration.
In February, F.B.I. agents showed up at the New York home of the reporter, Matthew Cole, to deliver the grand jury subpoena, which was issued by prosecutors in Newport News, Va., according to the people familiar with the matter, who described the private conversations on the condition of anonymity.
The investigators are seeking his testimony about two years’ worth of information about Mr. Cole’s contacts and conversations, as they try to identify his sources for the article about the operation in North Korea, the people familiar with the matter said. It is unclear if the administration has also sought Mr. Cole’s phone and email data, as it has done in other cases.
This is apparently related to Cole’s reporting about a failed surveillance operation authorized by Trump during his first term in office — one that was carried out in hopes of planting a recording device capable of intercepting Kim Jong-un’s communications.
For the operation, the military chose SEAL Team 6’s Red Squadron — the same unit that killed Osama bin Laden. The SEALs rehearsed for months, aware that every move needed to be perfect. But when they reached what they thought was a deserted shore that night, wearing black wet suits and night-vision goggles, the mission swiftly unraveled.
A North Korean boat appeared out of the dark. Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead.
The SEALs retreated into the sea without planting the listening device.
No one likes discussing a failed operation, so understandably this one hadn’t been publicly discussed prior to Cole’s report (with an assist by Dave Philipps). But this attempt to pressure Cole into revealing his sources seems more motivated by Trump’s unwillingness to discuss this mission with the people he’s supposed to be discussing these things with.
The Trump administration did not notify key members of Congress who oversee intelligence operations, before or after the mission. The lack of notification may have violated the law.
What’s inexplicable in normal terms is why this wasn’t a problem until now. This article was published last September. The underlying incident occurred in 2019. But it took until February 2026 for the administration to do anything about it. The Trump administration is far more aggressive and far less respectful of the law this time around, which explains why it would move against this reporting now. However, the delay between the reporting and revenge suggests this was a reaction to Trump seeing something on social media, rather than his administration engaging in a thorough internal investigation for months before deciding it needed to do damage to the First Amendment to move this forward.
Hopefully, this subpoena will soon be tossed into the Trump DOJ discard pile. But losing all the time won’t stop this administration from going after journalists for reporting on Trump’s failures. This administration is incapable of learning from its mistakes because it thinks it’s never wrong. The war on journalists will continue as long as Trump — and the GOP he’s turned into a MAGA puppet — holds power.
For much of Techdirt’s nearly three decades in existence we’ve covered attacks on the media by the rich and powerful. And sometimes we’ve been on the receiving end of such attacks ourselves. But I have never seen or heard of anything quite as extreme as what happened to Ina and David Steiner, proprietors of the website eCommerceBytes. As we and many others chronicled, the story that came out sounded impossible.
But now it’s finally concluded, with eBay and three of its former top execs agreeing to pay the Steiners nearly $49 million, plus another $7 million in charitable commitments — about $56 million total, for the horrors they put them through in response to (barely) critical reporting.
The Steiners ran a small online trade publication covering eBay, mostly focused on helping sellers on the site. For years they had a good relationship with the company itself, but in the late 2010s, the company was struggling and under new management, and its execs started to get annoyed at what they saw as critical coverage of the company by the Steiners (for example, questioning why a company that was struggling financially had decided to build a replica of an east coast bar in its headquarters).
What followed still reads like fiction. If you haven’t seen it yet, I highly recommend watching the documentary, Whatever It Takes, which tells the whole story in amazing detail, including security camera footage and getting one of the (low level) eBay employees who took part in the campaign of harassment to talk about what happened on camera.
The title of the film comes directly from a text then-CEO Devin Wenig sent to eBay’s communications boss at the time, Steve Wymer, saying that Ina Steiner needed to be taken down, “whatever it takes.” Wymer replied “we’re going to crush this lady.” According to the Steiners’ lawsuit, this was then communicated to others at the company and an operations exec, Wendy Jones, then told the company’s security boss, Jim Baugh, to take care of things “off the record,” apparently telling him she didn’t want to know any details.
This allowed Baugh to concoct an escalating campaign that started with angry DMs to Ina Steiner and moved on to shipping increasingly awful things to their home: a stack of pizzas, a preserved fetal pig, a bloody pig mask, a book about surviving the loss of a spouse followed by a funeral wreath, an envelope full of “barely legal pornography” that was (deliberately) sent to a next door neighbor. And on and on.
Multiple eBay employees also traveled to the town of Natick, Massachusetts, where the Steiners lived, repeatedly driving by their house and following the Steiners when they drove around town. They also planned to break into the garage and put a tracking device on the Steiners’ car.
As the documentary makes clear, much of this was driven by the somewhat wild imagination of Baugh, who had done private security for other tech CEOs before coming to eBay, where he moved improbably fast from the CEO’s bodyguard to running eBay’s entire global security operation. The documentary details how he pushed out most of the long-time security staff and brought in a crew of young and inexperienced female hires — at least one of whom he began a relationship with — making them watch movies about top secret operations, plying them with alcohol, and demanding total loyalty.
Bizarrely, what got them caught was the whole “going to Natick and following the Steiners around” bit, which allowed the Steiners to get a license plate which the police and FBI then used to track it back to the eBay employees. A bunch of eBay employees were arrested, all of whom eventually entered guilty pleas, and many ended up being sentenced to prison sentences, with Baugh receiving the longest at 57 months.
But the Steiners were (understandably) angry that Wenig, Wymer, and Jones were never charged. While the former execs insisted that they didn’t know this was happening, that they never would have condoned it, and that they were horrified by the news when it came out, that’s difficult to believe when so much of the evidence shows that all three were on board in a “wink, wink, nudge, nudge” way given the messages they sent between themselves and Baugh.
A few years back the Steiners filed a civil suit against eBay and those former top executives. The case was set to go to trial soon, but last week they reached a settlement, with the Steiners securing $55.7 million total — $48.7 million of it going directly to them, the rest in charitable commitments:
The plaintiffs will receive $48.7 million in compensation, including $46.15 million from eBay, $2 million from former eBay executive CEO Devin Wenig, $500,000 from former eBay executive Wendy Jones, and $50,000 from former eBay executive Steve Wymer.
eBay will fund $6 million in charitable contributions to various nonprofit organizations. Former eBay executive CEO Devin Wenig will contribute an additional $1 million to a charity dedicated to protecting First Amendment rights in the name of Ina Steiner.
In the end, this means that the lower level employees who did much of the dirty work ended up in jail. The top execs who set this in motion end up with small dents in their large bank accounts.
eBay’s statement on the matter is at least somewhat direct in calling what happened to the Steiners “reprehensible and should never have happened.” It also “acknowledges” what it says was “the unprofessional tone in internal communications demonstrated, to different degrees and number, by Mr. Wenig, Mr. Wymer, and Ms. Jones.” I’m not exactly sure that meets the requirements of the agreement which, according to the Steiners would include “a strongly-worded public statement regarding the conduct” of those execs from eBay.
Importantly (and kudos to the Steiners for demanding and getting this) the agreement is totally public and “contains no confidentiality provision.” This is rare in cases like this (and it’s also something we insisted on in the case we dealt with). It’s important to be able to talk about this stuff, and tragically the rich and powerful who try to take down news sites are often able to negotiate confidentiality clauses into the agreements.
For what it’s worth, Wenig and Wymer are still working in Silicon Valley, with both of them co-founding AI startups, naturally. Incredibly, Wenig’s startup supposedly provides AI tools to journalists, which is quite a pivot from directing a security goon to “take down” a journalist with “whatever it takes.” That also makes the part of the agreement of Wenig providing an additional $1 million to a charity in Steiner’s name to help protect First Amendment rights even more striking.
The fact that the defendants in this case were willing to pay so much and allow the terms of the deal to be public suggests they knew exactly how badly a public trial would make all of them look.
Kudos and congrats to the Steiners. These days especially, for most media players who are attacked by the rich and powerful for their reporting, the best you can usually hope for is to get a case dismissed. Maybe, if you’re lucky, to win an anti-SLAPP motion to get your legal fees paid. To actually win a settlement this size is almost unheard of. But the Steiners deserved it. They didn’t just face bogus SLAPP lawsuits designed to shut them down. They were legitimately terrorized in ways that have had long-lasting effects.
While the Steiners situation was extreme, it’s important to recognize that this kind of thing is the inevitable end result of the constant escalation in the past few decades of the rich and the powerful attacking the free press for daring to do accurate and critical reporting on them. The craziest bit in this story isn’t even everything that eBay employees did to the Steiners, but the fact that they were so brazen about it and so careless that they got caught doing so in a way that resulted in this kind of payout. Most attacks on the press never see the light of day, let alone allowing the media entities targeted to be able to claim restitution.
Last week we wrote about how Elon Musk’s xAI had filed a lawsuit to attempt to block Minnesota’s anti-nudify app law. As we tried to explain, even if you (reasonably, understandably) dislike both Elon and “nudify” apps, there were real problems with the Minnesota law. In particular, it was not narrowly tailored to just target truly harmful image edits. Indeed, it wasn’t even limited to the non-consensual use of the tech. The state’s Supreme Court had already handed the Minnesota legislature a clear roadmap for drafting a law like this that would pass strict scrutiny. The legislature ignored it.
However, the lawsuit was filed just days before the law was set to go into effect, which was called out by Minnesota’s Attorney General in arguing against a temporary restraining order:
First, X.AI’s lack of diligence confirms that a TRO is unnecessary. The company waited until the last minute to sue…
And that seemed to influence Judge Donovan Frank, who denied the motion for the TRO mainly because Elon waited until the last minute to file.
The Court respectfully denies the request for a temporary restraining order before tomorrow. xAI filed the motion on July 29, 2026, nearly three months after the law was signed, and only three days before the law is set to take effect. Such a delay in bringing the action and the motion suggests that harm is not immediate.
And, sure, it was kind of silly for Musk to wait right up until the law was set to go into effect, but that’s not all that rare with challenges to these kinds of laws. I also find the court’s suggestion that the harm isn’t immediate a bit odd, given that (as xAI had rightly pointed out) the potential liability under this law is massive: $500,000 per “access, download, or use.” That means any single use of Grok to edit an image that violates this law (which, as we discussed, goes way beyond nonconsensual sexual imagery, and could even cover someone editing a photo of themselves in a way they endorse) could lead to a huge bill for the company. And it’s now in effect, meaning in theory Minnesota’s AG, Keith Ellison, could already seek fines against the company — though there’s no indication that his office has done so yet. And while it may be politically appealing to try to enforce immediately, that may play badly before the court when there are hearings coming up in a few weeks on a preliminary injunction.
It’s also unclear if xAI actually changed anything on its end. In its filing, the company said that if the law went into effect, it would need to restrict access to certain features:
Confronted with $500,000-per-image strict liability and no safe harbor, xAI has no practical choice but to restrict Grok Imagine’s image-editing features in various ways when the statute takes effect on August 1, 2026
But the law has gone into effect, and as far as I can tell, there’s been no announcement of any changes. It’s possible such changes have been made already and just not announced. But it does come off as a bit weak to file a lawsuit on Monday saying that “if this law isn’t fixed by Saturday we’ll make big changes” and then have the law go into effect… and those changes are not publicly announced anywhere.
This ruling may not mean very much at all. The court has ordered both sides to brief a preliminary injunction over the next couple weeks, with a hearing on August 19th that can get into the actual First Amendment problems with the law. That also means xAI will likely have to explain, in those filings, whatever restrictions it has or hasn’t added to its systems.
xAI’s initial filing was not bad, but I hope they lean more heavily on the case I discussed in my last post, in which Minnesota’s Supreme Court spelled out exactly what the state’s non-consensual intimate imagery law needed to survive strict scrutiny. Because that case walks through, in great detail, the steps a (somewhat similar) law had to take to pass strict scrutiny and survive the First Amendment — even as the court acknowledged the law was punishing a form of protected speech.
There remain some oddities around this law, starting with the fact that the ACLU of Minnesota backed it in the first place — a surprising stance for the ACLU — before reversing course once Musk sued:
xAI’s criticism of the law is drawing support from some free-speech advocates including the American Civil Liberties Union of Minnesota, which supported passage of the law in an earlier form in February but has since turned against it.
“While we believe that creating the technology to alter or ‘nudify’ photos of identifiable people is protected by the First Amendment, we also recognize that the non-consensual creation and dissemination of such material can inflict damage on people appearing in those images,” the ACLU of Minnesota said in a statement Friday.
“In engaging with lawmakers on this issue, we hoped to strike an appropriate balance between First Amendment rights and the ability of people harmed to seek remedial measures, not unlike the remedies available to people harmed by defamation. The final version of the bill does not strike that balance,” the organization said.
Seems like the sort of thing you should have worked out before supporting the law, but fine.
Also, I had mentioned in my last article that some believe the law was written so badly on purpose, to convince Musk to sue in order for Democrats to use it as a political tool and… they are certainly making political hay of it on X, where they seem to be overjoyed that they can mock Elon.
And, sure, mocking Elon is fun. But if you’re going to mock him, it should be over the things he’s actually doing that are problematic.
The issue with this law isn’t that it’s trying to deal with the issue of nudify apps. Or that it’s trying to stop Elon from doing terrible things. It’s that it did so in such a ham-fisted, damaging, obviously unconstitutional manner that bans way more than it claims, is not narrowly targeted, and pretty clearly cannot survive strict scrutiny. Minnesota had the roadmap to pass a legitimate version of this law. It chose not to do so. That Musk didn’t receive the immediate TRO due to the late filing doesn’t make the law a good law. The proper thing for Minnesota’s legislature to do would be to write a law that actually abides by the First Amendment, but perhaps that wouldn’t get them the kinds of headlines they’re getting now.
There’s been a bunch of news this week regarding Minnesota’s new law that purports to prohibit “nudification” technology, and the fact that xAI has sued to have the law blocked as unconstitutional. A few things need to be said upfront, because it’s very, very easy to just say the tech is terrible, that Elon Musk and Grok are terrible, and that of course Minnesota should ban it. But it’s also possible that, in the rush to attack very problematic apps built by very problematic people, Minnesota drafted a bad law that is ridiculously overbroad and pretty clearly unconstitutional. And… that is exactly what appears to be the case.
Let’s start with the basics: apps (mostly powered by various AI tools) that are used to produce modified imagery, especially stripping people of their clothes are… bad. They should be socially shunned. People using them to objectify or sexualize others are doing bad things, and people should judge those who use those apps accordingly. This is not a defense of those apps. Similarly, Elon Musk’s Grok and its widely promoted use of putting people (including children) in bathing suits definitely deserves social shunning as well. Norms take time to form, and the shunning here is still catching up to the technology.
But passing a badly drafted, obviously unconstitutional law does not help form those norms. Nor does it punish Elon Musk. Instead, it allows him to act like a First Amendment martyr.
It’s also worth clearing something up early, because a lot of the coverage has gotten it wrong: this is not a law about child sexual abuse material. CSAM is already quite illegal under both state and federal law, and nothing in HF 1606 is limited to images of minors. Had Minnesota drafted a law narrowly targeting AI-generated CSAM, it might have survived a constitutional challenge. That’s not what it did.
And if you want to pass a law to ban technology like this, there are rules under the First Amendment. And, in Minnesota, we even know what some of those rules are. After all, a decade ago, the state also passed a law criminalizing the dissemination of “nonconsensual private sexual images.” After some back and forth in the courts, the Minnesota Supreme Court finally blessed the law as constitutional in late 2020, but made it quite clear that the law went right up to the First Amendment line. It first noted that while the state wanted to claim there’s an entirely new category of unprotected speech (in this case, “substantial invasions of privacy”), the court refused to do so, citing the famed US v. Stevens case (about an attempt to outlaw animal “crush” videos) in which the Supreme Court made it quite clear that it wasn’t open to creating new categories of unprotected speech:
The United States Supreme Court has emphatically rejected “freewheeling” attempts “to declare new categories of speech outside the scope of the First Amendment.” Stevens, 559 U.S. at 472; see also Jorgenson, 946 N.W.2d at 604 (“The United States Supreme Court has been reluctant to expand these traditional categories of unprotected speech.”). It is possible, however, there are “some categories of speech that have been historically unprotected, but have not yet been specifically identified or discussed.” Stevens, 559 U.S. at 472.
To successfully argue for a new unprotected category of speech, the proponent must present “persuasive evidence that a novel restriction on content is part of a long (if heretofore unrecognized) tradition of proscription.” Brown v. Ent. Merchs. Ass’n, 564 U.S. 786, 792 (2011). This is a heavy burden to bear, and the Supreme Court has recently rejected creating new categories of unprotected speech for animal cruelty, Stevens, 559 U.S. at 472, depictions of excessive violence, Brown, 564 U.S. at 791–93, and false statements, Alvarez, 567 U.S. at 722–23.
In this case, we conclude that the State has failed to carry the heavy burden required to provide a basis to establish a new category of unprotected speech.
And yet, the law was still deemed constitutional, but not because it created a new category of unprotected speech, but rather because it passed strict scrutiny, in which the law is narrowly tailored to use “the least restrictive means” of addressing a compelling government interest. That is the test by which a law can still be deemed viable under the First Amendment, despite suppressing speech. In the case of the nonconsensual imagery bill, the law passed strict scrutiny because it focused very narrowly on a category of speech that is very likely to cause harm, and put in place a law that was narrowly tailored to only target that speech, and on top of that included clear exemptions for edge cases that likely wouldn’t be harmful.
Indeed, the court leaned hard on the fact that the law only reached images disseminated without consent, and only when the disseminator knew or reasonably should have known the subject expected privacy. Those two limits — consent and intent — are what kept the statute from sweeping in vast amounts of protected speech. Some quotes from the court which list out all the factors necessary to pass strict scrutiny.
First, the Legislature explicitly defined the type of image that is criminalized…. Furthermore, the image has to be “obtained or created under circumstances in which the actor knew or reasonably should have known the person depicted had a reasonable expectation of privacy.” Id., subd. 1(3). Images that do not clear each of these hurdles fall outside the scope of the statute.
Second, a defendant must “intentionally” disseminate the image. … This mens rea requirement means that a defendant must knowingly and voluntarily disseminate a private sexual image; negligent, accidental, or even reckless distributions are not proscribed. This specific intent requirement further narrows the statute and keeps it from “target[ing] broad categories of speech.”
Third, the statute has seven enumerated exemptions…. The statute allows for private sexual images to be distributed “in the course of seeking or receiving medical or mental health treatment.” Id., subd. 5(3). Advertisers, booksellers, and artists are protected because images “obtained in a commercial setting” for legal purposes fall outside the statute’s reach. Id., subd. 5(4). Journalists cannot be prosecuted because there are exemptions for the dissemination of private sexual images that involve matters of public interest and “exposure[s] in public.” Id., subd. 5(4)–(5).8 Educators and scientists are protected because there is an exemption for private sexual images disseminated for “legitimate scientific research or educational purposes.” Id., subd. 5(6). Accordingly, even if protected speech falls within the ambit of subdivision one and a disseminator acted with the requisite mens rea, that person may still be exempt from prosecution under these precise exceptions.
Fourth, to be prosecuted under the statute, a disseminator must act without consent…. This provision provides additional protection for commercial advertisements, certain adult films, artistic works, and other creative expression outside the statute’s scope.
Finally, this statute only encompasses private speech…. Unlike the overly broad statutes at issue in our recent decisions in In re Welfare of A.J.B. and Jorgenson, this statute covers only private sexual images and does not prohibit speech that is “at the core of protected First Amendment speech.”
It was all of that combined that allowed the law to pass strict scrutiny — something that is incredibly difficult to do. Most laws that have to clear strict scrutiny don’t. Here, this law survived with a careful roadmap from the court of how to do so.
One would think that Minnesota legislators would be aware of this ruling and the clear reasons why the law was deemed to pass strict scrutiny and then write an equivalent law with the same elements in trying to ban nudify apps.
But for reasons known only to the Minnesota legislators, they basically ignored every single one of those points.
Minnesota’s anti-nudification tech law is not limited to non-consensual content. This means, as legal commentator Kathryn Tewson noted, that if she uploaded a picture of herself and asked Grok to put her in a bikini, she could by her own hand, cause Grok to break this law. That… seems like a very problematic law.
See, as I read this law, if I uploaded a picture of myself in a sundress and said “Grok, make this a picture of me in a bikini instead,” it would be a violation of the law for Grok to do that. I don’t think that should be illegal.
And, again, the Minnesota Supreme Court has already told the state pretty much exactly how to make this law constitutional: focus on nonconsensual imagery, narrowly tailor it to just the deeply harmful content, include an intent requirement, and include clear delineated exemptions for things that should be allowed.
Minnesota legislators did none of that. Indeed, even the definition of “intimate parts” in the law borrows its definition of ‘intimate parts’ from an earlier statute, covering: “the primary genital area, groin, inner thigh, buttocks, or breast of a human being” — not much of which is inherently sexual, let alone harmful. Tewson offers another example: an edit of a Taylor Swift photo that changes the texture of her fishnet stockings to look more like skin. Whatever tool made that edit just violated Minnesota law.
2. An image generated from this image of Taylor Swift performing on the Eras tour in which the texture of her legs in the modified image appears more similar to actual skin than it does to nude-fishnets-over-nude-tights:
This is, by definition, an overly broad, non-narrowly tailored law.
Another example: last year the TV show South Park did a deepfake parody of Donald Trump, showing a photorealistic version of him wandering naked through the desert, including his “intimate parts.”
Under this law, that video could violate HF 1606. That’s not narrowly tailored. That’s not dealing with intent or focused just on truly harmful content.
One lawyer I spoke to, after reading through the statute, wondered out loud whether the Minnesota legislature had deliberately drafted it in the dumbest way possible just to guarantee a successful challenge. That’s how poorly the law was drafted.
Of course, no one wants to hear that the law is badly drafted. Lots of people want to ban nudify apps and to yell about how ridiculous it is that Elon Musk has gone to court to challenge this law.
But… it’s the sort of thing he should be doing. Otherwise anyone can have Grok put themselves in a bikini and… Minnesota’s Attorney General can demand $500,000 for each such image created, even when the image was created deliberately, by the person in it, of themselves.
xAI (now a division of SpaceX) is right to challenge the law, not because nudify apps are a good thing, but because the law is terribly drafted and pretty clearly exceeds what’s allowed under the First Amendment. The complaint itself is worth a read. For one thing, it explains why xAI last week sued one of its own users for producing CSAM with Grok (which I had found perplexing at the time). It reads a lot like the company wanted a concrete example to put in this filing of how it fights back against those who use Grok in such ways (leaving out, of course, that Elon himself used the app to put himself in a bikini, thereby encouraging others to do the same).
It also explains why that complaint was focused on triggering the indemnity clause in X’s terms of service, which makes the user liable for any legal costs associated with their use of the product. What Musk is really signalling with that lawsuit is if Minnesota’s AG sues us under this law for your usage of the product, we’re going to sue you to cover our costs (which could include the $500,000 fine for any images created).
As the lawsuit notes, the law is just terribly written:
HF 1606 punishes AI platforms that allow users to alter images of real people to depict an “intimate part.” But the statute contains no knowledge, intent, or purpose requirement. It is a strict-liability statute keyed solely to whether a user succeeded in creating a covered image using the AI provider’s platform—regardless of whether the provider prohibits users from using its tool for such a purpose, regardless of how many mitigations the provider has in place, and regardless of how diligently the provider polices such conduct using its tool. There is no safe harbor for good-faith efforts of the provider of general-purpose AI creative tools to avoid harms. Liability attaches even if the depicted persons consented—or created the image themselves—and even if the image is never shared. Liability also attaches even if the image has artistic, scientific, political, satirical, educational, medical, or religious value, and (again) even if the company has deployed near-perfect, state-of-the-art technical controls to prevent the generation of nude images.
Additionally, the law’s definition of “intimate part” is exceptionally broad. Although the federal government and various states have enacted statutes that clearly define nudity for the specific context of AI-generated images, Minnesota rejected such a precise definition. Instead, it borrowed the definition of “intimate part” from a criminal sexual-contact statute. That definition was drafted for nonconsensual touching and thus covers the inner thigh, buttocks, or breast of a man or woman, as well as the groin and primary genital area. HF 1606 accordingly bans ordinary depictions of men without shirts, people in shorts or swimsuits, and other body parts routinely displayed in public—far beyond what an ordinary person would consider “nudification.”
Even worse, as the lawsuit states, the bill’s “principal sponsor” admitted that the law was designed to apply to consensual imagery:
A service used by an adult to edit a photograph of him or herself or a consenting individual is covered on the same terms as a service used to create an image of an unwilling stranger. The statute’s text draws no distinction among them. And this was by design. When a staff member of the Senate Judiciary and Public Safety Committee pointed out that the Act’s “prohibition applies to consensual images,” Senator Maye Quade (the bill’s principal sponsor) explained “that is intentional.”
That is the bill’s main sponsor stating, on the record, that she deliberately chose to leave out one of the very features Minnesota’s own Supreme Court had identified as necessary for a law like this to survive constitutional scrutiny.
That is legislative malpractice.
Since the lawsuit was filed, Maye Quade and other legislators have publicly defended the bill:
“I don’t see this as a free speech issue. This does not regulate content; it does not regulate art. It regulates conduct,” Maye Quade said. “Prompts are not art, and we protect art specifically in this law. It’s pretty audacious to sue to prevent a law that protects children from being turned into child sexual abuse material.”
She’s describing a law she could have written, but didn’t.
Notice what’s missing from that defense: any explanation of why the consent and intent elements the Minnesota Supreme Court specifically identified as saving the 2016 law were left out of this one. Also, she’s just simply incorrect that the law does not regulate speech. Again, if she simply read what the Minnesota Supreme Court said about the nonconsensual intimate imagery law, it spent pages analyzing the nonconsensual imagery statute — a law covering narrower material than this one — as a content-based restriction on speech that had to pass strict scrutiny to survive.
Similarly, the law does not actually “protect art.” Its one and only exemption is if the work “requires the technical skill of a user to nudify an image or video.” That could protect some art, but not all. And it defines art only in a case where a level of skill is needed, which itself potentially creates First Amendment issues in defining what is, and what is not art. There is plenty of modern art that people regularly complain takes no “technical skill” to create.
The complaint itself includes some other examples of what would violate the law, including this (gross) AI-generated image that Trump posted of a slimmed down version of himself, some of his cabinet members, and a randomly generated woman in a bikini sitting in a gleaming blue reflecting pool. Under the law, whatever tool was used to generate that image pretty clearly violated Minnesota’s law:
In this viral snapshot—which President Trump posted publicly— President Trump, Vice President J.D. Vance, Secretary of State Marco Rubio, and Secretary of the Interior Doug Burgum all are portrayed shirtless in the Washington Mall’s reflecting pool, along with an unknown (possibly fictitious) woman.19 An “intimate part” (the breast) of at least the President, Vice President, Secretary of the Interior, and the woman are “depict[ed],” with the Secretary of State also at least arguably included as well. The President posted this image on his personal account, presumably to make light of the public controversy surrounding repairs to the reflecting pool on the National Mall.
Nudify apps are gross. Musk’s encouragement of people to use Grok to de-clothe people is gross. People who use AI tools to “nudify” people are gross. But that doesn’t mean all laws targeting such things are good laws or constitutional.
In this case, despite having clear instructions from its own Supreme Court on how to write a constitutional law, Minnesota’s legislature deliberately chose to write an unconstitutional one. And thus, this lawsuit is the proper thing for SpaceX/xAI/Musk to do.
Supporting the lawsuit is not supporting Elon or Grok or nudify apps. It’s telling every legislature in the country the same thing: if you want the law to survive, learn to draft it in ways that aren’t unconstitutional.
A little-noticed presidential national security directive is now the legal engine behind a wave of terrorism prosecutions against left-wing protesters.
That domestic campaign now has an international dimension, one that American officials had been planning for months, culminating on July 16, 2026, when Secretary of State Marco Rubio’s Ministerial on the Resurgence of Political Terrorism drew representatives from more than 65 countries to Washington. The gathering was informally called the “Antifa summit.”
Rubio described antifa-aligned networks as sharing infrastructure across borders and accused Iran and Cuba of helping bankroll the movement, without offering evidence. The White House declared the summit the start of an “unprecedented global offensive” against what it calls “radical left terrorism.”
This offensive is built on the same domestic legal architecture that has now sent American activists to prison for decades.
That architecture is National Security Presidential Memorandum/NSPM-7, issued on Sept. 25, 2025, which for the first time appeared to authorize preemptive law enforcement measures against Americans based not on whether they are planning to commit violence but for their political or ideological beliefs.
Nearly a year later, that blueprint has moved from paper into practice.
The Justice Department has built task forces staffed by counterterrorism prosecutors. The FBI has set up its own NSPM-7 mission center to oversee investigations into left-wing movements, including a joint effort with the IRS to investigate nonprofit groups.
The Justice Department has used this machinery to convict activists and send some of them to prison for decades.
NSPM-7 was not passed by Congress. It’s a lesser-known tool of executive power: a presidential memorandum.
This structure allows the president to direct law enforcement and national security agencies, with little opportunity for congressional oversight.
Presidential national security powers
Executive memorandums direct agencies to prepare reports, implement policies or align programs with the administration’s priorities. Unlike executive orders, they aren’t required to be published. When they relate to national security, like NSPM-7, they’re called national security directives – many of which stay classified and may not be declassified for years or decades.
The stated purpose of NSPM-7 is to counter domestic terrorism and organized political violence, focusing mainly on perceived threats from the political left. The memorandum identifies “anti-Christian,” “anti-capitalism” or “anti-American” views as potential indicators that a group or person will commit domestic terrorism.
The memorandum claims that political violence originates with “anti-fascist” groups that hold the following views: “support for the overthrow of the United States Government; extremism on migration, race, and gender; and hostility towards those who hold traditional American views on family, religion, and morality.”
The strategy includes preemptive measures to disrupt groups before they engage in violent political acts, empowering multiagency task forces to investigate potential federal crimes related to radicalization and the groups’ funders. Former Attorney General Pam Bondi’s December 2025 implementation memo went further, ordering a five-year review of agency files on antifa. A task force staffed with counterterrorism and organized-crime prosecutors is carrying out these investigations.
‘Domestic terrorist organizations’
The memorandum directs the Department of Justice to focus FBI resources from approximately 200 Joint Terrorism Task Forces on investigating “acts of recruiting or radicalizing persons” for the purpose of “political violence, terrorism, or conspiracy against rights; and the violent deprivation of any citizen’s rights.”
NSPM-7 also allows the attorney general to propose groups for designation as “domestic terrorist organizations.” That includes groups that engage in “organized doxxing campaigns, swatting, rioting, looting, trespass, assault, destruction of property, threats of violence, and civil disorder.”
Existing laws allow the secretary of state to designate groups as “foreign terrorist organizations” that are then subject to financial sanctions.
That gap hasn’t stopped prosecutions. In Texas, eight defendants tied to a “North Texas Antifa Cell” were sentenced in June 2026 for a 2025 armed confrontation at the Prairieland immigration detention center. One man received 100 years, and others who never fired a weapon still drew decades in prison under terrorism sentencing guidelines.
In Minnesota, 15 members and associates of a group called Direct Action Minnesota were indicted in June 2026 on conspiracy and assault charges. A 94-page indictment cited behavior such as wearing an “I’m Antifa!” sweatshirt, possessing a bullhorn or including a devil emoji in a Signal message.
Defining terrorism
NSPM-7 marks a major conceptual shift in U.S. counterterrorism policy, departing from approaches that primarily targeted foreign threats.
After 9/11, the Bush administration fused counterterrorism with national defense through the global war on terrorism. The Obama administration later tried to narrow those powers, asking whether targeted individuals “pose a continuing, imminent threat to U.S. persons” — a standard focused on tactics and capture feasibility, not ideology.
The first Trump administration used a “travel ban” against several “terror-prone” countries, while President Joe Biden redirected focus toward weapons of mass destruction.
Notably, the “domestic terrorist” label itself has rarely produced actual charges. The State Department designated four antifa-aligned groups as foreign terrorist organizations. But antifa is a decentralized movement, not a formal group with a roster.
Prosecutors have instead leaned on older statutes such as material support for terrorism and conspiracy laws, tools originally built for cases like the ones above, not protest movements.
First Amendment rights at risk
There is no single official definition of terrorism in U.S. law; definitions vary by purpose – criminal law, intelligence collection, civil liability.
Definitions in all those areas typically focus on identifying violent or dangerous acts done with the intent to intimidate or coerce civilians or influence government policy.
But more than redefining terrorism, NSPM-7 reorients the machinery of national security toward the policing of belief.
The First Amendment generally prevents the government from punishing people for unpopular opinions. It also protects the ability for people to associate to advance public and private ideas in pursuit of political, economic, religious or cultural goals.
The directive’s emphasis on ideological orientations – “anti-Christianity,” “anti-capitalism” and “anti-American” views – as indicators of domestic terrorism potentially jeopardizes First Amendment rights.
Thirty-one members of Congress sent a letter to Trump in October 2025 expressing “serious concerns” about NSPM-7, warning that it poses “serious constitutional, statutory and civil liberties risks, especially if used to target political dissent, protest or ideological speech.”
As the ACLU warns, any definition of terrorism that includes ideological components risks criminalizing people or groups based on belief rather than based on violence or other criminal conduct.
Congress has declined to create a domestic complement to the foreign terrorist designation in large part because of the potential for impinging on First Amendment–protected association and speech.
But I fear that chilling speech may be the point.
Silencing dissent
NSPM-7 does not criminalize previously legal conduct.
Law professor Steve Vladeck frames this chill as “obeying in advance,” in which organizations self-censor rather than risk investigation, prosecution or defending against the “domestic terrorist” label. Federal judges in the Prairieland case have shown little sympathy for that distinction: One judge described the protest itself as “an assault on democracy,” even for defendants who never touched a weapon.
Although left-wing violence has risen in the past decade, empirical evidence shows it remains far below historical levels of right-wing or jihadist violence.
Most domestic terrorists in the U.S. are politically on the right, accounting for the vast majority of domestic terrorism fatalities.
Yet NSPM-7 focuses disproportionately on left-wing ideologies. NSPM-7 departs from prior U.S. counterterrorism frameworks by prioritizing the suppression of ideologically motivated dissent, even where, as in Minnesota, judges have already dismissed roughly half of similar federal cases for lack of evidence.
Melinda Haas is Assistant Professor of International Affairs at the University of Pittsburgh