A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDC’s FoodNet tracking platform were making it much harder to track and back trace the source of the country’s current cyclosporiasis outbreak. You’ll have heard about this outbreak in the news by now. It’s the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC.
Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDA’s dedicated page to inform the public on the outbreak. That page hasn’t been updated since July 24th, in fact, which is the exact opposite of what you’d want the government to be doing in a public health emergency. And it’s reportedly not because the government isn’t aware of these deaths.
While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time.
The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication.
Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do.
And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Don’t-Give-A-Shit.
Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad.
The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but it’s clear they’re not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose.
Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But that’s not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading.
Unfortunately, every indication is that those same health agencies just aren’t all that interested in doing this the right way.
On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica.
The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap.
One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more.
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here.
Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs.
The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.
But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.”
Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft declined to answer questions about how many bugs engineers had patched since the presentation.
Anthropic declined to comment.
The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.” After those categories were cleared, the group would begin work on roughly 300 “moderate” bugs, according to the presentation.
While the internal documents reviewed by ProPublica do not include updates on the entire breadth of Microsoft’s offerings, they do give a sense of the scale of the problem. One document noted that, since the company started using Mythos earlier this year, it had collectively found hundreds of bugs that Microsoft categorized as either critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had yet to be patched.
“They’re not profound and exotic, but they’re real,” Andersen, the engineering manager, said during the meeting. “And a lot of them are exploitable.”
It’s unclear whether hackers have exploited any specific bug identified by Mythos, but some have tapped AI to automate attacks and appear to be using Mythos-like tech to find and exploit weaknesses.
There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to be patched. Each month, the company publicly releases fixes for its software vulnerabilities in what’s known as “Patch Tuesday.” In June, it released patches for more than 200 bugs, which industry experts then said was an all-time high. But on July 14, the company blew through that record and released patches for more than 600 bugs. Only seven were categorized as low- or moderate-severity, one of which hackers were actively exploiting, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program, which is part of cybersecurity company TrendAI. The rest were important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a blog post on July 14.
Microsoft told ProPublica that the overall volume of bugs “will not be plateauing for a bit,” but a spokesperson said the company has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
Given the new realities of the AI age, including the chaining capabilities, companies like Microsoft might need to rethink their entire approach to triage, said Nguyen, the NSA’s former AI chief. Rather than shunting what are now considered low-risk flaws aside, companies should be dedicating staff to developing and testing patches for the entire spectrum of vulnerabilities, he said. In other words, the cyber ER needs more doctors and nurses treating illnesses that are life-threatening as well as the minor wounds that could later turn deadly.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft told ProPublica it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Microsoft’s users may be particularly vulnerable. The popularity of its offerings, used the world over, makes it a frequent and lucrative target for hackers. In addition, many of its products contain “legacy” code. Developed decades ago using now-outdated technology, this code contains unaddressed flaws and contributes to what is known in the industry as “technical debt.”
But the challenge of fixing the flood of newly found bugs also extends to the rest of the software industry, and to open-source software code that is typically free to use and largely maintained by volunteers. Open-source software underpins internet infrastructure and is incorporated into much of the world’s modern technology, including products offered by major tech companies such as Microsoft.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and the president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our tech debt is coming due.”
Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the software industry was handling an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
Although the volume of vulnerabilities has grown over the years, Microsoft’s internal group responsible for fielding them, the Microsoft Security Response Center, has been perennially understaffed. Even before the crush of AI-identified bugs, the center fielded hundreds or even thousands of reports a month, pushing the group to its limits, ProPublica has reported.
The size of the center reflects Microsoft’s corporate philosophy: Plugging security holes is a cost center, while making new products is a profit center, former employees said. The company is loath to tie up its best engineers with making security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica has reported.
Microsoft told ProPublica that it does not discuss internal staffing decisions but has made investments in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
According to the slides that accompanied the May internal presentation, Anthropic provided Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would see continued case volume “as public tools catch up” to Mythos.
During the May meeting, one staffer appeared to take comfort in the belief that adversaries “don’t have the source code” that such an AI tool would scan for weaknesses. His colleagues, however, quickly corrected him. Portions of Microsoft’s code have, in fact, fallen into hackers’ hands over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
Donald Trump took possession of a $400 million “gift” plane from the Qatari government earlier this year. Trump claimed it was a coup for taxpayers and a boon for America, even as he made it clear this was all about him. According to Trump, no plane was more luxurious than this graft-y replacement for the Air Force One. He bragged about how much it reflected his own taste in upmarket products, which meant the plane’s interior was undoubtedly festooned in gold leaf and stocked with steak-grade ketchup.
But was it secure? That’s kind of a big deal when it comes to presidential transport. Turns out it wasn’t. Trump rode his graft jet to Turkey for a diplomatic meeting but was forced to ride the old Air Force One out of the country when it was discovered his new gaudy aircraft didn’t possess the necessary security measures/counter-measures.
In response to this reporting of the Air Force One Mk. II’s failure, the Trump administration behaved like the Trump administration: it subpoenaed the New York Times reporters, demanding all sort of information in hopes of uncovering the reporters’ government sources.
That’s not how this is supposed to work. The FBI and DOJ both have extensive guidelines that are meant to discourage open attacks on the First Amendment. All of these appear to have been ignored in the administration’s haste to find out who needed to be punished for telling the truth about Trump and his Qatari luxury jet.
Fortunately, the court curb-stomped the DOJ when the New York Times challenged the subpoenas. The DOJ really had no answer for the court’s questions, given that the court had plenty of precedent to work with while the DOJ was limited to being a nominally prehensile Trump appendage. Faced with the (admittedly slim) prospect of being sanctioned by a thoroughly irritated federal judge, the DOJ withdrew the subpoenas.
But that’s not the end of the story, apparently. The administration is targeting anyone remotely related to the New York Times and/or reporting that doesn’t please Donald. The New York Times is now going to bat for one its freelancers, who has also been targeted by this vindictive administration.
In February, F.B.I. agents showed up at the New York home of the reporter, Matthew Cole, to deliver the grand jury subpoena, which was issued by prosecutors in Newport News, Va., according to the people familiar with the matter, who described the private conversations on the condition of anonymity.
The investigators are seeking his testimony about two years’ worth of information about Mr. Cole’s contacts and conversations, as they try to identify his sources for the article about the operation in North Korea, the people familiar with the matter said. It is unclear if the administration has also sought Mr. Cole’s phone and email data, as it has done in other cases.
This is apparently related to Cole’s reporting about a failed surveillance operation authorized by Trump during his first term in office — one that was carried out in hopes of planting a recording device capable of intercepting Kim Jong-un’s communications.
For the operation, the military chose SEAL Team 6’s Red Squadron — the same unit that killed Osama bin Laden. The SEALs rehearsed for months, aware that every move needed to be perfect. But when they reached what they thought was a deserted shore that night, wearing black wet suits and night-vision goggles, the mission swiftly unraveled.
A North Korean boat appeared out of the dark. Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead.
The SEALs retreated into the sea without planting the listening device.
No one likes discussing a failed operation, so understandably this one hadn’t been publicly discussed prior to Cole’s report (with an assist by Dave Philipps). But this attempt to pressure Cole into revealing his sources seems more motivated by Trump’s unwillingness to discuss this mission with the people he’s supposed to be discussing these things with.
The Trump administration did not notify key members of Congress who oversee intelligence operations, before or after the mission. The lack of notification may have violated the law.
What’s inexplicable in normal terms is why this wasn’t a problem until now. This article was published last September. The underlying incident occurred in 2019. But it took until February 2026 for the administration to do anything about it. The Trump administration is far more aggressive and far less respectful of the law this time around, which explains why it would move against this reporting now. However, the delay between the reporting and revenge suggests this was a reaction to Trump seeing something on social media, rather than his administration engaging in a thorough internal investigation for months before deciding it needed to do damage to the First Amendment to move this forward.
Hopefully, this subpoena will soon be tossed into the Trump DOJ discard pile. But losing all the time won’t stop this administration from going after journalists for reporting on Trump’s failures. This administration is incapable of learning from its mistakes because it thinks it’s never wrong. The war on journalists will continue as long as Trump — and the GOP he’s turned into a MAGA puppet — holds power.
The rise of AI is bringing a bunch of fascinating legal questions that are harder to answer than many expect. The latest one: who is liable if an agentic system running on its own hacks someone? That’s the question a bunch of people have been asking this past week in the wake of multiple stories of agentic tools breaking out of their sandboxes during testing. But it’s also a question that the Ninth Circuit brushed up against this week, in a ruling that says an agentic tool isn’t the one doing the “accessing” under the federal hacking law. A person is. The challenging part is figuring out which person.
There’s obviously been plenty of talk over the past couple of weeks regarding agentic tools supposedly going “rogue.” There was, of course, the story of OpenAI’s tools hacking Hugging Face, the AI repository (also covered on Ctrl-Alt-Speech). And then soon after, Anthropic admitted that “hey, our models kinda did something similar.” And while these are generally referred to as the bots going rogue, the reality is not quite that. The bots are doing literally what they were asked to do: accomplish some goal by any means necessary. And in both stories, they found ways to accomplish their goals, often by hacking into other systems or doing things we would normally consider malicious.
In the case of OpenAI and Hugging Face, it appears that the tool did what plenty of hackers try to do, just a whole hell of a lot faster. It found a zero-day vulnerability to break out of the sandbox OpenAI thought it had created. It then took a series of steps to enable it to hack into Hugging Face. In Anthropic’s case (which only came to light after the OpenAI incident caused Anthropic to go back and look) the situation was a bit different. Some of the tests included prompts telling the agentic tools that they were in a sandboxed simulation. But because of a configuration error, they really weren’t. And since the models had been told flat out in the prompt that everything around them was simulated, when they found a way out, they reasonably concluded that the way out was part of the simulation too.
Either way, I’ve seen some discussion online wondering why these two companies aren’t being charged with violating the Computer Fraud and Abuse Act (the CFAA). We’ve written about the CFAA for years, mostly in how it’s a badly worded law that has been abused in both civil and criminal cases to go after “anything I don’t like on a computer” rather than its actual purpose of targeting genuine hacking. And CFAA lore goes back to 1988 and the infamous Morris Worm, in which Robert Morris accidentally created an internet virus that took down portions of the then still small internet. Morris was found guilty of violating the CFAA for doing so.
Which has some people asking how are these other two stories any different. But the general consensus is that there are unlikely to be any CFAA violations here, in part because the CFAA requires intentional access, and in part because no human ever made the decision to break in. I would separately argue that the lack of real damage (unlike the Morris Worm) helps here as well. TechCrunch floats a more cynical version of the same point: that the DOJ’s appetite for a CFAA theory might look very different if these agents had come out of a Chinese lab rather than one a short drive from the US Attorney’s office:
The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts.
Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database.
It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep.
But, just as this discussion heated up, the Ninth Circuit Court of Appeals (sort of) weighed in on a separate, ongoing case that Amazon filed against the AI company Perplexity. Perplexity has an “agentic browser” allowing users to tell the agent to accomplish tasks — such as “buy me toilet paper on Amazon” — and the agent goes off and does that independently. Amazon, unsurprisingly, hates this. Its entire storefront is engineered to get humans to buy more than they came for, and an agent that buys the toilet paper and leaves is immune to every last bit of it.
So Amazon notified Perplexity that its agent isn’t allowed on the site. Perplexity, taking the position that a browser a user drives is a very different thing from a giant centralized scraping operation, kept letting its users point the agent at Amazon — and routed around Amazon’s blocking by not sending an identifying user-agent string. Which, it’s worth remembering, is something browsers, privacy tools, and testing frameworks do every single day.
But Amazon argued that this made Perplexity’s agent a CFAA violator, because routing around a block should count as ‘unauthorized access’ (which is central to the CFAA). Amazon sought a preliminary injunction blocking Perplexity’s tools from reaching Amazon and the district court granted it. But now the Ninth Circuit has rejected that, noting that a computer by itself cannot violate the CFAA, because the CFAA’s language “contemplates access by a person.”
The CFAA’s plain language suggests the Assistant itself cannot “access” Amazon’s servers. The relevant provision of the CFAA punishes “[w]hoever . . . intentionally accesses” a “protected computer.” 18 U.S.C. § 1030(a)(2) (emphasis added). In other words, the CFAA contemplates access by a person. However advanced the Assistant currently is, it is a tool, not a person for statutory purposes. See 18 U.S.C. § 921(a)(1) (“The term . . . ‘whoever’ include[s] any individual, corporation, company, association, firm, partnership, society, or joint stock company.”); see also Whoever, Cambridge English Dictionary, [https://perma.cc/YY3TVTJF] (last visited July 16, 2026) (“[T]he person who” (emphasis added)).
Which raises the obvious Morris Worm question: the worm wasn’t a person either, and Morris still went down for what it did. But that’s exactly the distinction the court is drawing. Morris wrote the code, released it, and no one else was involved — the “whoever” was sitting right there. When a user tells an agent to go buy toilet paper, there’s a human in the chain, and the court says it’s the user, not the tool and not the company that built it.
The Supreme Court has instructed that, “in the computing context, ‘access’ references the act of entering a computer system itself or a particular part of a computer system, such as files, folders, or databases.” Van Buren, 593 U.S. at 388 (internal quotation marks omitted). Our focus is thus to ask whether Perplexity uses a tool (the Assistant) to “access” Amazon’s computers. On the facts before us, we answer no. It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com. To be sure, Perplexity may receive screenshots of the user’s browser and may communicate instructions to the Assistant. But those activities, by themselves, do not mean that Perplexity has “accessed” (gained entry) to Amazon’s servers. We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers. On the current record, Amazon is not likely to succeed in proving the “access” prong of its CFAA claim.
The court also seems well aware of how badly the CFAA has been abused (especially in criminal law) and recognizes how an alternative outcome would be a mess:
Another note of caution: Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers. We are conscious of precedent cautioning against “transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved” or “criminaliz[ing] a broad range of day-to-day activity.” Nosal I, 676 F.3d at 860, 862 (internal quotation marks omitted). In our view, it is unlikely that Congress would have exposed individual users to criminal liability under the CFAA by using the Assistant and Comet browser to access Amazon.com under these facts. On these narrow facts and given the care with which we must interpret the CFAA to ensure defendants are on notice, we decline to adopt Amazon’s interpretation of § 1030(a)(2).
The court does caution that its ruling should be seen narrowly, and admits there could be other cases which are CFAA violations. But a browser with an agent built into it, doing the bidding of a human user, is not that:
Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to “access” as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI. The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated. For now, this opinion reflects and applies to the state of technology only as presented in the filings in this case.
While the court seeks to distinguish this ruling from the very problematic Power Ventures case (which said that users authorizing a third party tool with their own password to access Facebook for the purpose of creating a unified dashboard for social media was a CFAA violation), I think this ruling is a further narrowing of that ruling from a decade ago.
I’ve argued for years that the Power Ventures case was a key moment in locking up the open web, because it blessed Facebook’s desire to close off its platform from the wider web, leading to the world of internet giants operating as silos. In that case, the court found that it was Power who was violating the CFAA rather than the user, even though it was clearly the user authorizing access. That enabled platforms to lock up all their data in silos and try to block any third-party tool from getting it out, deepening lock-in and making useful “exit” harder.
Here the results come out very differently, and very much for the better.
A handful of cases over the past few years have thankfully chipped away at the very broad Power Ventures ruling, and this is the latest. Given how much of the web is about to be browsed by agents rather than eyeballs this may be the most consequential such ruling.
But, at the same time, it still leaves open the idea that OpenAI and Anthropic could face CFAA claims in the future, even though it’s their bots that accessed things in an unauthorized manner. While this latest ruling says that bots alone can’t violate the CFAA, the entity driving them could. So there could be cases where these companies could face CFAA liability for how they configure the tools when they run these tests. The “intentionality” question will still be a hurdle for any CFAA claim to overcome, but I don’t think this particular ruling should have OpenAI and Anthropic breathing any easier — other than in the narrow case where either of their browser agents, operated by a user, accesses unauthorized systems. Pointing an agent at the open internet, telling it to accomplish a goal by any means necessary, and then misconfiguring the box that was supposed to keep it in is a very different fact pattern from a user asking Comet to reorder toilet paper. The CFAA is also hardly the only law with something to say about an aggressively overhelpful bot that causes real damage.
It also leaves open something more uncomfortable: the user might be liable. If the user is the one “accessing,” then a platform that wants to ward off agentic browsing now knows exactly who to target: the users. The Ninth Circuit points out that it was unlikely that Congress meant to expose individual users to criminal liability under the CFAA (which is correct), but… lawyers filing civil claims don’t care about that. And a demand letter doesn’t even need to turn into a lawsuit to work. The only thing holding a company like Amazon back from going after users for their use of agentic tools may be the very likely public backlash if they did so.
That’s the real lesson from this ruling. Rather than making the liability vanish, it moves it around. That’s genuinely good news in a post-Power Ventures world for all sorts of things including price-comparison tools, accessibility overlays, researchers auditing platforms, and anyone building the interop layer a giant would rather not exist. But it may also leave those same users in a legal gray zone where an aggressive set of lawyers may decide to target them when they get fed up with agentic tools. Perhaps Amazon is smart enough not to go there. Then again, the recording industry spent the better part of a decade suing its own best customers, and plenty of lawyers told them it was a great idea at the time.
The Ultimate Python and Artificial Intelligence Bundle has 9 courses to help you take your Python and AI knowledge to the next level. You’ll learn about data pre-processing and visualization, artificial neural networks, how to use the Keras framework, and more. It’s on sale for $40.
Note: The Techdirt Deals Store is powered and curated by StackCommerce. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
The Trump administration has been shut down more than 10,000 times by federal courts over its novel interpretation of the law — one it claims allows it to indefinitely detain migrants without giving them a bond hearing.
Some of those 10,000 adverse decisions have been significant, with implications that stretch far beyond single cases or even single states, as Kyle Cheney notes for Politico:
The score so far runs like this: 460 judges, 10,000 rulings against the administration versus 54 judges and 1,100 cases finding in Trump’s favor.
The Fifth Circuit’s decision isn’t an absolute win for the administration either. It says the government can violate migrants’ due process rights, but only for 90 days. The hitch here is that the Fifth Circuit has already agreed to review the case en banc. Whatever the outcome, it’s going to have repercussions that will alter how the government runs its mass deportation program. The circuit not only covers a large border state (Texas) but also several of the nation’s largest ICE detention facilities.
And given what we know about the Fifth Circuit, the judges petitioning for the rehearing aren’t hoping to deliver a decision respecting migrants’ 14th Amendment rights. The only reason they’re doing this is because they think migrants shouldn’t even have delayed access to their rights.
There’s a circuit split, but not much of one. Two more appeals courts have ruled against Trump’s detention policy.
In a pair of 2-1 decisions, the California-based 9th Circuit Court of Appeals and the Illinois-based 7th Circuit Court of Appeals found that the Trump administration had defied logic and misconstrued decades-old immigration laws to justify its expansive detention policy. Appeals courts have now split 6-2 against the administration as the issue hurtles toward the Supreme Court, while the overwhelming majority of lower-court judges have ruled against the administration as well.
This is going to hurt the administration, so we should probably expect the Supreme Court to get this on the shadow docket ASAP. The Ninth Circuit covers California, Trump’s favorite target for deportation surges.
Both circuits say the law doesn’t say what Trump wants it to say. While they come to the same conclusion, the appellate courts phrase it differently.
The Ninth Circuit’s ruling [PDF] makes a better — and clearer — point, so we’ll start there. The Immigration and Nationality Act was last amended in 1996. But nothing really changed. It was understood that migrants detained while trying to cross the border were not entitled to due process rights, like bond hearings. However, migrants already in the United States — especially those who had been here for a significant period of time — were afforded the same rights as US citizens.
Nothing changed for thirty years. Then Trump returned to office. And somehow everything changed. Not so fast, says the Ninth Circuit. Just because you want the law to say something it doesn’t, doesn’t make your argument any less ridiculous.
The government recently changed its longstanding approach. It now contends that unadmitted aliens present in the interior of the country are subject to mandatory detention without bond under § 1225(b)(2)(A), based on revisions to the statute that Congress made in 1996. […]The implication of the government’s position is that Congress in 1996 made a major change to the immigration laws by subjecting millions of unadmitted aliens present in the United States to mandatory detention, but that this change then went unnoticed and unheeded, with the Executive Branch for the next three decades violating Congress’s assertedly unambiguous mandatory detention directive by treating these aliens as subject to release on bond.
And while every law is written in legalese and is consequently somewhat open to interpretation, the Ninth Circuit says 30 years of history makes it clear what Trump is doing now is not what Congress intended when it amended the INA.
Whether these aliens should be subject to a broader mandatory detention regime is a policy question that lies outside the role of the judiciary. The question here is not about policy or Executive Branch discretion, but congressional authorization. We do not decide whether Congress could enact the detention regime as the government would now have it, but rather whether Congress did so in 1996. The better view is that it did not.
While this would seem to show Congress what it needs to do to make Trump happy and his mandatory detention scheme legal, it’s not that simple. Migrants still have access to constitutional rights, which means any legislative alteration would immediately be met by a constitutional challenge if passed. As it stands now, mandatory detention without a bond hearing is a no-go in the Ninth Circuit.
The Seventh Circuit’s ruling [PDF] focuses more on Congress circa 1996 than the Trump administration in 2026. But the end result is still the same.
DHS rests its new interpretation on changes Congress made to the Immigration and Nationality Act (“INA”) almost thirty years ago. Before those changes, aliens who unlawfully entered the country were given greater procedural rights than those who presented for inspection at the border. Congress ended that disparity by creating a legal fiction in removal proceedings that “deemed” all aliens not properly admitted “applicants for admission” to the United States, as if they had never crossed the border. But before last year, no administration had ever suggested this legal fiction extended beyond the INA’s removal procedures to its provisions governing detention pending removal.
It’s the same point made by the Ninth Circuit, even though the Seventh Circuit says it’s bad lawmaking that’s to blame, rather than an opportunistic, wholly disingenuous interpretation by the Trump administration.
But the administration isn’t completely off the hook. The appeals court says the administration can’t turn “legal fiction” into fact just because it only likes certain parts of the amended INA.
Section 1225(b)(2)(A) imposes mandatory detention on certain “applicants for admission,” but only those who are also “seeking admission.” And Cirrus Rojas is not seeking admission: the relief he now seeks, asylum and withholding of removal, is not admission as the statute and Supreme Court case law use that term. Cirrus Rojas has never applied for anything that counts as “admission” to the United States. Nor can he successfully “seek” admission, as his unlawful entry renders him inadmissible. The government simply argues that because Cirrus Rojas is “deemed” an “applicant for admission,” he must be “seeking admission.”
We hold that Cirrus Rojas is not “seeking admission”— and thus not covered by Section 1225(b)(2)(A)—because that is his real-world status. We join the majority of the circuits that have confronted this question in rejecting the government’s newfound statutory requirement for mandatory detention, which rests upon the illogical use of both legal fiction and ordinary meaning for the same term.
Then it shifts things back to Congress, much like the Ninth Circuit did:
One mixes fiction with fact at their peril. And the facts in this case are clear: Cirrus Rojas is not seeking admission to the United States. If Congress had meant to define individuals like Cirrus Rojas as “seeking admission,” it could have done so.
This may be a single appeal — one arising from tens of thousands of cases generated by this illegal mandatory detention policy — but it affects every migrant in the Seventh Circuit and forces the government to respect their due process rights.
Our holding is limited. We deal only with whether all aliens present without admission in the interior and facing removal proceedings are subject to mandatory detention. Under the INA’s plain text, context, and history, the answer is no.
This is going to hurt Trump, too. The Seventh Circuit covers Illinois, another target of Trump’s anti-migrant efforts solely because the state is governed by someone from the opposing political party.
Good news for migrants and constitutional rights. Bad news for an administration that has no respect for rights whatsoever and sees migrants as sub-human. We’ll see how long this lasts, but for now most of the country is covered by precedent that denies the administration access to its preferred method of inflicting misery on migrants.
More specifically, the company decided it would be a good idea to introduce new “rate limits” to smart glasses usage, forcing customers to pony up a $20 per month Meta One Premium subscription if they didn’t want their glasses’ “conversation focus” functionality (which amplifies the voice of people you’re speaking to in loud environments) limited to three hours of use per month.
The kicker: the processing for this feature exists entirely on the device and doesn’t utilize any Meta cloud capacity — so customers were being asked to pay more money for no technical reason.
Understandably people didn’t like that and complained, forcing the company to retreat. Sort of. Meta has issued a statement to The Verge saying that they’re pausing their plans for the “conversation focus” surcharge for now:
“Meta’s AI glasses pack a lot of value for free, and some premium features will be subscription-based over time—and conversation focus is one we want to make sure we get right. We heard the feedback so we’re pausing its subscription test for now. Conversation focus will remain available for free through our Early Access Program for early testers while we work on a better approach.“
The phrasing of the statement makes it clear Meta customers can expect further annoying monetization efforts down the line for glasses that already cost between $300 and $800.
Meta is simultaneously battling a branding and privacy problem as people increasingly associate Meta’s AI glasses with the non-consensual recording of women (“perv glasses” and “Ray Ban Meta creep” have become common nomenclature).
This post is going to come with something of a warning label. RFK Jr. went on CNN this past weekend for an interview with Dana Bash. I’m going to post the entirety of that interview immediately below. Before you watch it, get yourself a bib, or some paper towels, or wrap yourself in one of those plastic ponchos they hand out to keep the rain off of you. You’re quite likely to spit out whatever is in your mouth, vomit, or perhaps even have your brains leak out of your ears. You’ve been warned.
Whether you’ve watched that entire thing or chosen not to, potentially for your own health, the interview is completely bonkers. It’s honestly pretty tough to pull out the lowlights to comment upon, it’s so bad. The themes of the 20-plus minute interview, however, are easy to outline: RFK Jr. takes no responsibility for what he’s done past or present, he spends the entire time attacking Dana Bash as though she personally is responsible for everything he hated about the COVID response, he pretends that Donald Trump had no agency over that response despite being president at that time, and he insists that only he is listening to the science and doctors when it comes to health outcomes.
Let’s get into some of those. When talking about the COVID response and specifically what we need to do better for the next pandemic, Kennedy predictably went into a minutes long diatribe about how the most important thing is our constitutional rights and how the entire constitution was thrown out by Anthony Fauci (and not Donald Trump, somehow). When Bash pointed out that wasn’t really what she was asking about, Kennedy snarled and attacked her.
“Forgive me, but you’re just talking about rights and I’m asking about a potential public health crisis that is coming,” Bash said after Kennedy launched into a lengthy defense of constitutional rights that he claimed were “dismantled” during COVID-19 lockdowns.
“I really want to move on,” Bash added as Kennedy repeatedly interrupted to continue his argument. That appeared to set him off.
“Of course you do, because you were part of the problem!” Kennedy shot back, pointing at the host.
“No, I wasn’t part of the problem,” Bash replied.
“Yes! There was absolute press malpractice,” Kennedy continued. “You weren’t allowing—”
As Bash tried to interject, he kept going: “Your job is fierce skepticism toward authority. And you weren’t doing that. You were beating up the people who were dissenting.”
Somehow both predictably and unbelievably, this exchange ended with Kennedy stating that he wasn’t attacking Bash at all and instead insisted that she attacked him. She really didn’t. Go ahead and watch the interview if you haven’t. To that point, she hadn’t done anything that could even be misconstrued reasonably as “attacking” Kennedy.
Bash then pivoted to the measles outbreaks of the last 20 months, pointing out that the messaging from Kennedy on getting vaccinated hasn’t been clear and asking for his stance on it. Kennedy then did what he always does. First, he affirmed that everyone should be getting vaccinated for measles… and then launched into his conspiracy-laden and well-worn diatribe explaining all the reasons parents shouldn’t necessarily get their children or themselves vaccinated, and that vaccines haven’t been proven to be safe.
“Do you want people to get the MMR vaccine?” Bash later asked.
“Yeah, I said that already,” Kennedy replied with a smirk before pointing at the host. “I know you’re flustered now, and it’s frustrating.”
Bash quickly pushed back.
“I’m not flustered at all. I am frustrated,” she said. “The reason I’m frustrated is because you are the HHS secretary and you are talking about things that lead to vaccine hesitancy in this country. And it is something that causes problems for people when there is not anything—”
Kennedy cut her off again.
“Let me ask you something,” he said. “Do you see your job as ending vaccine hesitancy, or do you see your job as telling the truth to the American people?”
Bash replied, “I see my job as telling the truth, and the truth is that there is study after study after study. It‘s one of the most studied things out there in science—”
“You’re repeating it like a parrot,” Kennedy snarled as he lunged forward over the table. “You‘re repeating it like a parrot. I’ve actually read the science.”
The conversation again devolved into raised, overlapping voices, before Bash proclaimed: “I’m not debating nonsense.”
“All you know how to do is repeat what people told you and say ‘trust in the experts,’” a red-faced, wildly gesticulating Kennedy replied, blaming trust in Fauci for poor public health.
Now, one thing that was cut off from my transcription of the COVID response portion of the interview was this. Pay close attention to who Kennedy indicates we should listen to in crafting public policy, because on this I believe he’s right:
BASH: How do you prepare for next pandemic? RFK Jr: We did almost everything wrongB: But what about now?K: We need to protect our rightsB: ?K: During covid we dismantled our rightsB: But I'm asking what *to* do K: You were part of the problemB: You want to sit here and attack me?
Got it? In that clip he says we should listen to “frontline doctors.” Now, while there’s no official poll of national physicians to rely on, we can certainly look to the groups that those same frontline doctors choose to represent them. Many of those groups have directly called on RFK Jr. to resign.
So, Kennedy can do something principled and brave after this absolute meltdown of an interview. He can listen to frontline doctors. And he can resign.
But he won’t. Because it’s not actually frontline doctors he wants to listen to at all. He’s carefully choosing his language. When he says “frontline doctors” he doesn’t mean any of the actual frontline doctors represented by any of those trusted groups mentioned above. Instead, he means the propaganda/conspiracy organization known as “America’s Frontline Doctors,” the same group that focused most of its attention on selling bogus COVID treatments, and whose founder went to prison for her role in the January 6th insurrection. Not surprisingly, that group (which these days appears to consist of just a random Substack) repeatedly supports all of RFK Jr.’s totally unsubstantiated claims. How surprising.
Early in the media law and ethics course I teach, as I shift gears from the ethics section to the law and core free speech issues, I try to build a foundation by introducing the many kinds of legal issues they may face as communicators. By this time, we have already discussed social media platforms and the terms and conditions to which they have agreed as users, and what this means for them as future media professionals and citizens.
As a break from weekly writing assignments, I set up a lesson starting in 2023 using the online game launched by Techdirt called “Trust & Safety Tycoon.” This puts students in the position of the head of a trust and safety team — basically, the chief of content moderation — for a social media startup company. As the site grows its users and popularity, and tries to remain viable as a commercial enterprise, the player faces increasingly challenging tasks. What happens when users threaten a boycott over offensive content? How do you handle Congress or foreign government leaders demanding takedowns? When news breaks on your platform and police ask for your help, to what extent do you cooperate?
Full game screen from Trust & Safety Tycoon with one of the situations you face in Year 5
While I require my students to do case briefs and other writing assignments on a weekly basis, the ease of using generative AI to do these assignments makes them less appealing. Students are far more likely to want to play a video game, especially one as engaging and challenging as Trust & Safety Tycoon. The assignment itself — to play the game through twice at a minimum, submitting selfies with the end-game screen — can be done in less than an hour, though some students report playing it several times to try to max out their score.
By this point in the semester, usually around the fourth week, students have completed readings and in-class discussion on media ethics and First Amendment issues. Playing this game is an opportunity to engage critically with modern content regulation matters across a broad array of media law topics — particularly free speech, prior restraint, privacy and intellectual property.
To ensure that students have played through the game as an assignment, they are asked to take a picture of themselves with the end-game screen. This provides another level of interaction that students enjoyed, with some sharing their results on their own social media accounts and commenting on the game there.
Execution of Assignment in the Classroom: Students were told in class about the assignment, with the instruction that the student had to play the game at least twice: once to learn the game mechanics and develop some comfort with how it operates, and a second time as a more serious effort to complete the game to their satisfaction. When they reach the final screen, they take a selfie with the end-game screen (rather than a screenshot, which could be easily copied or downloaded). They then upload those into the assignment box in the online course management system.
After class, a link was sent via email to the online game at https://trustandsafety.fun. Students had two days (48 hours) to complete the game. They were also instructed to be ready to start the next class with discussion about the decisions they made.
The game itself takes about 20 to 30 minutes to complete. The game was designed by the Copia Gaming initiative and launched on Techdirt in 2023. The player begins as an employee of a social media startup called “Yapper,” which appears to operate as a hybrid of Facebook and Twitter/X. The player then has to make a number of decisions on content moderation rooted in the real experience of those companies, such as handling users who use the site to host pirated copyrighted video from Netflix or managing parody accounts of celebrities. Each year in the game, the player can invest in moderation resources (such as verified users, blocklists, encryption, copyright scanning, etc.) to help maximize the site’s moderation speed, user growth, conversation health, and ad revenue.
As the years pass, the moderation decisions get tougher. Players have to decide how to handle beheading videos posted by an overseas terrorist group; visits from the FBI requesting user information, gag orders, and potential jawboning about election misinformation; demands from both state attorneys general and foreign leaders for information about dissidents; an active shooter situation in which law enforcement makes several demands, including a request to broadcast the shooter’s manifesto; a legal battle with a Disney-like entity on parody videos; foreign privacy laws requiring either resistance or expensive compliance; a new age verification law; and ultimately a demand to testify before Congress as they consider regulation of your platform.
A visit from the FBI, including efforts at jawboning.
When students return to class, I prompt to share some of the difficult decisions they made, and why they made them. I use this discussion to inform them of the real-world situations from which many of these scenarios are derived, most of which predate their experience as social media users but were formative in shaping what we see online and how governments regulate the Web.
Student Learning Outcomes: This assignment is designed to achieve the following:
(1) Introduction to different areas of media law and their interaction. Each situation can be dropped into one of our main topic areas — copyright, free speech, defamation, privacy, etc. — as we identify these issues and what body of law applies.
(2) Global media regulation. This assignment requires students to see how U.S. standards on free speech and regulation may differ from other countries.
(3) Connection between law/policy and media outcomes. The exercise illustrates how government action through coercion, regulation, and litigation shapes the messages they see and hear on online platforms.
(4) State actors vs. private companies. We identify and discuss the role of government and strong First Amendment protections, as well as the role of private companies in shaping online speech.
Measuring Impact: The assignment is graded simply on a 0–2 scale (2 points for turning it in on time, 1 for late/incomplete submission, 0 for neither). The effectiveness is evident in the quality of discussion and recall of in-game examples.
Participation in this class discussion has always been robust, and students remember the game in future units when we talk about the First Amendment, Section 230, privacy, and intellectual property. Feedback about the assignment on student evaluations at the end of the semester have been uniformly positive as well.
Some of the examples are too real. Ask TikTok.
I will be presenting this exercise in the AEJMC Law & Policy preconference session in New Orleans in August. The assignment won first place in the Teaching Ideas contest.
Some intelligence analysts have declined to brief on antifa at interagency meetings because they do not regard it as a serious counterterrorism threat.
As a terrorism scholar who spent a decade running the State Department office that designates terrorist organizations, I understand their confusion. The threat the administration describes does not exist in the form the administration describes it.
There is no membership roll, no command hierarchy and no funding structure. There is no leader of antifa – the Trump administration has not named one – and there is no record of deadly attacks attributed to a U.S.-based organization called antifa.
Groups like the Islamic State group and al-Qaida have killed tens of thousands of people and have a documented chain of command. Antifa does not. You cannot decapitate a movement with no head, and you cannot sanction an organization that does not exist.
As such, the Trump administration created one.
Trump administration targets antifa
The construction project began on Sept. 22, 2025, when President Donald Trump signed an executive order purporting to designate antifa as a domestic terrorist organization. The order describes antifa as “a militarist, anarchist enterprise that explicitly calls for the overthrow of the United States Government.” It directs every relevant agency to investigate and dismantle its operations.
Two problems are immediately apparent. First, no legal authority exists to designate domestic organizations as terrorist groups. It’s a gap that Congress has deliberately preserved for First Amendment reasons.
Second, the order designates as an organization something the FBI’s past leadership has described as an ideology. Trump’s executive order asserts an antifa enterprise into existence and then declares war on it.
Three days after the executive order, the White House implemented the order through National Security Presidential Memorandum 7, which converts the fiction into machinery. The memorandum directs the Treasury Department to identify and disrupt financial networks that fund what it deems domestic terrorism. The memorandum instructs banks to file suspicious activity reports with the Financial Crimes Enforcement Network, the U.S. government’s financial intelligence unit.
That means the government’s financial surveillance apparatus, built to trace al-Qaida’s money in the wake of the 9/11 terrorist attacks, is being pointed at Americans that the administration considers left-wing.
The memorandum likewise directs the FBI’s Joint Terrorism Task Forces to coordinate a comprehensive national strategy to investigate, prosecute and disrupt entities and individuals. That harnesses a network of roughly 200 task forces comprising over 4,000 personnel from federal, state and local agencies.
The wording of National Security Presidential Memorandum 7 gives away the administration’s true intent. It identifies the markers of this supposed terrorist movement as anti-Americanism, anti-capitalism and anti-Christianity. It criticizes the movement for its hostility toward those who hold traditional American views on family, religion and morality.
Those are not indicators of terrorism. They are political positions.
State Department targets groups overseas
The foreign component of the campaign arrived in November 2025. That’s when the State Department designated four European groups – one each from Germany and Italy and two from Greece – as Specially Designated Global Terrorists and Foreign Terrorist Organizations pursuant to the Immigration and Nationality Act.
The State Department-designated groups are real. And some of their members have committed genuine crimes, including assaults and small-scale bombings.
But as I have noted, the designations are very peculiar. These groups have committed vandalism and harmed people, but not one of the four has carried out an attack that led to any fatalities.
German leaders have said the threat from one of the designated groups, Antifa Ost, or Antifa East, had recently decreased significantly.
As the former head of the State Department’s office that recommended to the secretary of state which groups to designate, I’ve been involved in the designations of hundreds of individuals and organizations. The bar was never this low. That’s because the Foreign Terrorist Organization list loses its meaning, and its deterrent power, when it includes groups whose body count is zero while genuinely lethal movements go unlisted.
The foreign nexus
That brings us back to the State Department’s ministerial. The sequence of events leading up to it matter:
Invent the organization by executive order; build the enforcement machinery by presidential memorandum; manufacture the foreign nexus through the State Department’s Foreign Terrorist Organization designations; and then convene the world to ratify the story. Each step launders the previous one.
Behind it all, Trump administration officials have discussed using the foreign terrorism labels to justify going after Americans with links to the movement. That is the point of the exercise, and U.S allies like the Netherlands have explained how antifa could not be designated as a terrorist group under their laws.
Counterterrorism tools are among the most powerful instruments the U.S. government possesses. I don’t believe that using them against an ideology, one defined by opposition to fascism, makes America safer. I believe it tells every ally the U.S. asks for help that the world’s leading counterterrorism power can no longer tell the difference between a threat and an opponent.
Implications of the ministerial meeting
This is not just an issue of semantics and rhetoric – each action by the Trump administration against a strawman enemy creates risks. And the push to internationalize the antifa threat could have dire consequences at home.
First, if the State Department leaves the July 16 meeting with pliable allies willing to brand antifa a terrorist organization, it will embolden the administration to point to a supposed global conspiracy of the far left.
That path leads to a State Department foreign terrorist designation. Such a designation means Americans could have their bank accounts frozen and quite possibly find themselves rounded up for providing material support to a movement rather than an organization. This would be more dangerous than Trump’s earlier executive order.
Second, it could chill freedom of speech and assembly. Once other governments treat antifa as a terrorist entity, the U.S. government gains cover to shut down protests under the guise of exposing global left-wing plotting.
Third, it could justify the revival of projects like the FBI’s Counterintelligence Program, resurrecting the surveillance, infiltration and disruption of lawful political activity that the bureau was supposed to have abandoned after the abuses of the 1970s.
Fourth, as one European counterterrorism scholar recently warned, the summit lays bare a widening split between American and European counterterrorism priorities and the Trump administration’s willingness to bend counterterrorism policy to partisan ends.
That divergence is the real hazard, far more than any phantom left-wing terrorism group, because European counterterrorism leans so heavily on U.S. intelligence. As such, transatlantic counterterrorism cooperation could be in for turbulent times.
Whatever the outcome of the ministerial meeting, there is no version that will make Americans safer.
I believe one result is certain: Genuine threats – from groups with leaders, actual funding and malicious intent – will get less attention from the U.S. and any ally co-opted to take action against antifa.
Jason M. Blazakis is Professor of Practice and Director of Center on Terrorism, Extremism and Counterterrorism at Middlebury College