Welcome to the 18th edition of HRF’s AI for Individual Rights newsletter.
This week, China’s top civilian intelligence official warned that artificial intelligence (AI) could pose a security threat to Chinese Communist Party (CCP) rule. He pointed to risks including AI-generated political content against the CCP, AI-powered cyberattacks, and sensitive data leaks, while calling for tighter state control over AI. His remarks reveal Beijing’s broader ambition to harness AI’s power without allowing it to weaken the CCP’s control.
Meanwhile, a new European lab, Desert Ant Labs, launched with 18 small AI models designed to run entirely on a user’s phone. Chinese AI company DeepSeek also released DeepSeek V4.1 Flash, a new model that can run on more accessible hardware while matching the performance of, or beating, some of its larger recent models. These advances are making powerful AI increasingly practical for human rights defenders to run privately on less and less powerful hardware.
We end with HRF Chief Strategy Officer Alex Gladstein’s reflections on the latest developments in AI and their implications for human freedom. He looks at the rise of local and private AI, what these tools could mean for individuals, HRF’s new “organizational brain,” and some of the biggest debates shaping where AI goes next.
The Latest in AI for Repression
China Warns that AI Could Threaten CCP Rule
In a recent article, China’s Minister of State Security, Chen Yixin, warns that AI could undermine the CCP’s influence and control. Among his concerns, Chen states that actors with “ulterior motives” could spread harmful AI-generated content against the CCP and calls for those responsible to be punished. He also points to the risk of AI-powered cyberattacks on critical infrastructure and stronger foreign militaries, while warning that Chinese users of foreign AI models could inadvertently leak sensitive Party information. To protect the CCP’s political stability at home, he calls for greater CCP control of AI, including new regulations and continued Party oversight of the internet and data.
Why this matters: It’s frightening to see an authoritarian regime that wants to use AI to strengthen its political control, but calls for restrictions when that same technology gives individuals new ways to challenge it.
Frontier AI CEOs Call for Slowdown, Raising Fears for Open-Weight Models
Anthropic CEO Dario Amodei released a 3,800-word essay, “We Must Pace the Frontier,” that calls for an industry-level slowdown of AI development. He cites fears that AI could advance faster than humans can control it, while more capable agents could launch cyberattacks or even “[take] over the entire internet.” He proposes that frontier AI companies undergo third-party safety evaluations and coordinate among labs in democratic countries, and eventually globally, on shared limits and safety standards. Later, OpenAI CEO Sam Altman, xAI Founder Elon Musk, and Google DeepMind Co-Founder and Chair Demis Hassabis agreed.
Why this matters: It’s clear that AI can be very dangerous, especially in the wrong hands. But open-source advocates worry that a push for broader industry-wide safety rules could make alternative AI models harder to build, or even lead to the regulation of open-weight AI. Open-weight models are ones that users can download, modify, and run themselves privately, without needing to rely on a third party. This allows individuals to control their own intelligence. If powerful open-weight models are restricted, frontier AI could become concentrated in the hands of just a few governments and companies. In such a world, dissidents and civil society would be forced to rely on institutions that could monitor their interactions with AI, restrict what they can ask, cut off access, or decide the limits of what they are allowed to think and build.
You can also check out Twitter co-founder Jack Dorsey’s counter-essay, “open the frontier,” which argues that more open access to powerful AI (paired with independent testing and safeguards) could actually make the world safer.
Moscow Is Building a Massive Surveillance System
A new article from The New York Times reveals that the city of Moscow’s recent technological advances for citizen safety and convenience are really doubling as a massive surveillance system. Central to this system are the city’s roughly 300,000 CCTV cameras, making Moscow one of the world’s most surveilled cities. Many of the cameras connect to biometric databases, which Russian officials can use to target political dissent. Meanwhile, the Putin regime is pushing to collect more biometric data, and encourages the public to use facial recognition for basic financial activity, such as paying for public transportation. As Russia’s war on Ukraine continues, officials have also turned to AI-enhanced digital systems to enforce the draft. One 28-year-old individual evading a military summons stopped using the subway, afraid of its cameras. “There is total control because you give up so much data that your every step can be traced,” he said.
Anthropic Releases Report on the Misuse of AI, Including Surveillance Applications
Anthropic released a 154-page report detailing how threat actors have misused Claude, the company’s AI, including for surveillance targeting dissidents. The following are some examples of that misuse. A consultant working with Mali’s state intelligence service used Claude to help build a system to monitor roughly 25 million SIM cards and generate profiles on people by phone number. In China, state-aligned actors used Claude to build profiles on Uyghurs, religious and spiritual leaders, Hong Kong democracy figures, and overseas activists. In Iran, state-linked actors used Claude to sift through hundreds of thousands of social media posts and identify opposition figures. These cases show how regimes seek the most powerful tools available to strengthen their authoritarian repression.
In context: Anthropic’s work to expose and block authoritarian regimes from misusing their tools is important, but those safeguards also raise important questions about who gets monitored in the name of preventing abuse. Anthropic recently advertised for an intelligence specialist responsible for identifying, tracking, and even predicting threats, including “geopolitical instability, terrorism, crime, [and] activism.” The listing does not suggest that Anthropic views all activism as dangerous, but including activism alongside terrorism and crime is notable. For human rights defenders, it raises a broader question: Where does legitimate security monitoring end and scrutiny of lawful dissent begin?
Thailand’s Free AI Service Surveils Its Users
Thailand’s Ministry of Digital Economy and Society is offering citizens free AI access through its TH-AI Passport platform, but only if they compromise their privacy. If a Thai citizen registers with their national ID, they can access 14 AI providers, including OpenAI, Google, and Anthropic. But the state-run platform can then read every prompt and output and analyze chat history attached to an individual’s ID. The platform’s privacy policy states that it will monitor usage for offenses against “national security,” which in a hybrid authoritarian regime such as Thailand’s can quickly become a justification to punish dissent against the regime. Users, especially human rights activists and nonprofit organizations, must be cautious before sharing information that could be used later to investigate or punish them.
AI-Built Hacking Tool Could Have Compromised WeChat
Researchers at Calif, a California-based security company, used AI to build a tool capable of compromising millions of accounts on WeChat, the Chinese messaging platform with more than 1.4 billion monthly active users. A hacker could compromise one WeChat account, then use the tool to call that person’s contact list and take over their account without them even answering the phone. Each newly hijacked account could then automatically call its own contacts, creating a chain reaction that could spread to millions. Calif alerted Tencent (WeChat’s parent company), which patched the flaw and said it had no reason to believe the issue had affected any users. If so, this is a lucky case. In another world, a malicious attacker could have exposed the messages of more than a billion people, including anyone critical of China’s authoritarian regime. It is extremely important that dissidents take their cybersecurity seriously, especially in the era of AI-powered hacking.
In context: While AI does make cyberattacks easier, there could be a longer-term upside. If more people are constantly testing the same popular apps, then security flaws can be found and fixed faster, ultimately making digital tools more secure.
Recommended Content
HRF's Toolkit to Counter the Chinese Communist Party’s Transnational Repression
HRF launched a toolkit for activists, diaspora communities, and others at risk of facing China’s transnational repression tactics. It offers practical guidance on building community support, staying safe at protests and events, and protecting digital safety. Recommendations include using multi-factor authentication, keeping devices updated, using encrypted messaging tools like Signal, and avoiding sharing sensitive information with AI tools. The toolkit then directs readers to HRF’s AI for Individual Rights Toolkit for privacy-protecting and open-source AI alternatives. Check it out here.
The Latest in AI for Freedom
Desert Ant Labs Provides Specialized Local AI on Phones
Desert Ant Labs is a new European AI lab focused on building powerful intelligence capable of running locally (and therefore privately) on users’ devices. The lab debuted with 18 open-weight models, each specialized for a particular skill ranging from transcribing audio and masking private information to identifying languages and turning rough recordings into studio-quality audio. The models are also small enough to run locally on a phone. That means free, unlimited AI-powered services in which all information is private and never leaves the user’s phone. Desert Ant Labs is creating an entire private AI toolbox that dissidents can keep in their pocket.
New Open-Weight Model: DeepSeek V4.1 Flash
Chinese AI company DeepSeek has released a new open-weight model. DeepSeek V4.1 Flash is the smallest in DeepSeek’s newest generation of models, and can run on less powerful hardware than its other recent model, V4 Pro. You might expect that to come with a performance tradeoff, but DeepSeek says third-party tests show that V4.1 Flash outperforms V4 Pro in performance, cost, and speed. Remarkably, the latest update of V4 Pro came out less than a month earlier. Clearly, open-weight models are evolving quickly, and hopefully, with each release like this, it becomes more and more realistic for those challenging dictators everywhere to run powerful AI on hardware they control.
Important: DeepSeek was developed in China and is therefore likely to reflect CCP values and embed censorship bias. Be wary of its responses, especially those that are politically sensitive.
Unsloth AI Fine-Tunes Qwen3.8-27B to Run on a Mac
Unsloth AI, a US-based company making open-weight models easier to run and fine-tune locally, is also optimizing models to run on smaller devices. The team recently took an open-weight Chinese model, Qwen3.8-27B, and essentially compressed it into a more efficient format. The original Qwen3.8-27B requires a high-end personal computer to run, while Unsloth’s version just needs a Mac with enough storage and memory. This version has passed 10 million downloads, demonstrating the demand for private intelligence accessible on smaller, less expensive devices.
Why this matters: People can modify open-weight models to fit their needs, share the resulting product with the world, and watch the benefits spread. In this case, a US-based company took a Chinese model and made it dramatically easier for millions of people to run privately.
Mia AI Makes Local AI More Accessible
Mia, an independent AI developer working to make powerful local AI easier to use, has grown her project into a 10-person team. For the past three months, she has been building “recipes,” step-by-step instructions that help people run open-weight models locally, mostly on high-end NVIDIA DGX Spark systems. Mia’s work has quickly gained traction, and she and her new team are working together to make “high-quality local AI practical across as much hardware as possible.”
Why this matters: Few people stand to gain more from private, local AI than dissidents. Developers like Mia are doing the unglamorous engineering work that could turn local AI from something reserved for enthusiasts with expensive hardware into a possibility for anyone.
Agora Brings Censorship-Resistant Crowdfunding to Any Website
Agora, a censorship-resistant fundraising platform first developed at HRF’s AI Hack for Freedom, has launched a new feature that lets anyone add a fundraising campaign directly to their website. Agora works like GoFundMe, but it accepts Bitcoin, a currency that allows censorship-resistant, permissionless, and borderless payments. Previously, users had to host their fundraising campaigns directly on Agora’s website and send people there to donate. Now, they can turn a campaign into a widget and paste it on to any site they control.
Why this matters: Agora already lets dissidents and civil society groups raise funds instantly, without relying on a traditional crowdfunding platform that could shut them down. This update makes that even easier by letting supporters donate without leaving the page.
Recommended Content
In a post on X and Nostr, HRF Chief Strategy Officer Alex Gladstein reflects on how recent developments in agentic, local, and privacy-protecting AI can empower individuals and support freedom. He explains how open-weight models prevent a “techno-totalitarian future” and instead could provide “super-intelligence for everyone.” He discusses HRF’s “organizational brain,” an AI-powered system that synthesizes years of the organization’s knowledge to accelerate staff work. Gladstein also reflects on the issue of AI-powered cyberattacks and the irony of human rights activists increasingly benefiting from powerful open-weight models developed in China. Read Gladstein’s post here.