Newsletter
Sep 28, 2026

HRF’s AI for Individual Rights Newsletter #19

HRF’s AI for Individual Rights Newsletter #19
HRF’s AI for Individual Rights Newsletter #19
Written by

Welcome to the 19th edition of HRF’s AI for Individual Rights newsletter. 

In Iran and China, state-backed actors are using AI to run autonomous influence campaigns. These actors can now deploy hundreds of AI agents to create social media accounts and flood platforms with political content, marking a new era of authoritarian propaganda. 

Meanwhile, a new AI model, Jev, offers fast decision-making at a much lower cost than existing large language models (LLMs). Although it is not an open-weight model, its launch has already inspired open alternatives that could run locally within freedom tech tools, making them faster, cheaper, and more effective. 

We end with the release of a new resource from HRF, “AI for Activists: A Guide to Supercharging Your Movement with Artificial Intelligence.” The guide outlines the current AI landscape and helps dissidents and nonprofits choose tools that can strengthen their movements and autonomy while protecting their privacy. 

The Latest in AI for Repression

Iran and China Create Autonomous AI Influence Campaigns

A recent New York Times article found that state-backed actors in Iran and China used AI to run first-of-their-kind influence campaigns, while similar campaigns were traced to private Israeli firms. These actors deployed hundreds of AI agents, powered by Chinese AI models, that autonomously created fake accounts on Instagram, Facebook, X, and TikTok and posted about politics and current events. Details of the Chinese campaign have not been disclosed publicly. In the Iranian campaign, fake accounts posed as everyday Americans, pushed politically charged content to US audiences, and amassed nearly 80,000 followers. While the goals and real-world impact of these campaigns are unclear, they demonstrate that dictatorships will use the best tools available to spread authoritarian propaganda.

Why this matters: Authoritarian regimes and their accomplices could use similar tactics to unleash thousands of AI agents capable of drowning out critics, targeting dissidents, or covering up human rights abuses with far less effort.

Chinese AI Company Uploaded Users’ Local Data Without Clear Permission

Developers discovered that Chinese AI company Z.ai’s coding tool, ZCode, was silently uploading users’ local data without explicit consent. People often keep additional files and project history locally on their computers while building software with ZCode. But ZCode was automatically packaging copies of that data, including files beyond what a user was actively working on, and sending snapshots to external cloud servers. One developer described the behavior as “basically like stealing something from users.” This happened by default, with no clear way to stop it. The company apologized, said it fixed the issue, and made the full codebase open-source so people could inspect it. 

Why this matters: Dissidents, journalists, and human rights organizations handling sensitive information must be extremely cautious when using AI tools, especially those that gain access to users’ computers. There’s a chance data could be uploaded without consent and then be used against you. Always do your own research and weigh the tradeoffs of any AI tool against your risk model.

UN Report on Human Rights in the Digital Age Echoes HRF Submission

At a recent UN Human Rights Council meeting, the United Nations High Commissioner for Human Rights presented a report titled “Protecting human rights defenders in the digital age.” The report combines insights from 79 submissions from individuals and nongovernmental organizations, including one from HRF, which highlighted threats such as AI-powered mass surveillance, targeted deepfakes, gendered online harassment, internet shutdowns, and spyware. The final text of the UN report echoes many of these concerns, while also warning about the dangers of censorship, weak privacy tools, the criminalization of online speech, and other forms of digitally assisted repression. It calls for stronger oversight of surveillance technologies and greater support for privacy-protecting tools.

Why this matters: It is encouraging to see digitally assisted repression receive attention from one of the UN’s highest human rights bodies.

Turkey Targets LGBTQ+ Activists and Rights Groups

Turkey’s regime has launched a crackdown on LGBTQ+ activists and rights groups. From Sept. 12 to 14, officials detained more than 100 people and raided several LGBTQ+ organizations, while courts also blocked dozens of rights groups’ websites and social media accounts. In response, protesters took to the streets, where police met them with tear gas and even more arrests. These actions come amid the regime’s push for so-called “family values,” which officials use to justify investigations of LGBTQ+ advocacy under accusations of “obscenity.” HRF strongly condemns this crackdown and calls on Turkish officials to respect the rights to freedom of expression and association.

In context: Turkey has expanded AI-powered facial recognition surveillance and used camera footage to identify and prosecute pro-democracy protesters. While there is no clear evidence that Turkey used its surveillance network against dissidents in the current crackdown, the infrastructure is in place and could be quickly turned against those exercising their rights to free speech and assembly.

Hundreds of Contractors Are Reading Users’ ChatGPT Prompts

404 Media, an independent news website, reported that OpenAI employs hundreds of contractors who read real ChatGPT users’ conversations to improve its models. OpenAI says it takes steps to protect user privacy, including anonymizing chats and removing personal information before they reach reviewers, although the company admits that sensitive details can still slip through. Reviewers then rate and critique ChatGPT’s responses so OpenAI can improve the system.

Why this matters: Even an anonymized prompt could contain enough detail to reveal a dissident’s identity or their plans to challenge tyranny. One malicious insider with access to those conversations could expose sensitive information to an authoritarian regime. Activists using ChatGPT should turn off “Improve the model for everyone” in their settings.

The Latest in AI for Freedom

New AI Model Jev Provides Fast and Cheap Intelligence Compared to Other LLMs

American AI startup TypeSafe AI has introduced a new type of AI model, called a “System One Model,” designed to make decisions much faster, more cheaply, and with much less computing power than existing LLMs. The first System One Model is Jev. Unlike traditional chatbots that generate long-form text answers, Jev quickly evaluates information and returns a simple output, such as yes/no, a probability, or a confidence score. Its biggest use case will likely be inside software, where it can quickly decide things such as what action a program should take next. Jev is not open weight (meaning it cannot run locally on a user’s device), but it has already inspired open-weight alternatives that could make local, private AI more capable.

In context: Because System One Models require less computing power, open-weight versions could run locally on less powerful devices like phones. That would be a big win for privacy — more intelligence running privately on small devices. These models could also power local privacy and security tools. A local security application, for example, could decide whether a file, link, or login attempt looks suspicious. Overall, this could make tools for dissidents and human rights defenders cheaper, faster, and smarter without sacrificing privacy.

AgentCloak Protects Sensitive Data from AI Providers

Privacy technology company InCountry launched AgentCloak, a free tool that lets people use popular AI chatbots without sharing their sensitive personal information. Users install it as a browser extension or desktop app and then start chatting with AI chatbots such as ChatGPT, Claude, and Gemini. Before a user’s prompt is sent, AgentCloak automatically detects details such as names, addresses, emails, and phone numbers and replaces them with realistic fake information. When the AI responds, AgentCloak swaps the real information back in locally, so the user sees a normal response while the AI provider never receives the original sensitive data. AgentCloak is brand new, and its redaction accuracy has not been tested extensively, so users should not assume it provides complete privacy.

Why this matters: People often have to choose between using powerful AI tools and protecting sensitive information. Tools like AgentCloak could make mainstream chatbots safer for activists, who may need to work with information they cannot risk exposing to an outside provider.

Open-Weight Model Altar Specializes in Cybersecurity

A Belgium-based security company, Aikido, has released Altar, an open-weight model built specifically to review code, find software vulnerabilities, and improve cybersecurity. A company or individual building technology could deploy this model on their own hardware, privately scan their code, and ensure it is secure. To make this capability possible, Aikido took a powerful Chinese model, GLM-5.3, modified it to specialize in cybersecurity, and compressed it so it can run on less powerful (but still relatively expensive) hardware.

Why this matters: Technology, like encrypted messaging and censorship-resistant tools, can greatly empower dissidents, but only if the underlying code is secure. Altar could help developers strengthen these tools without requiring them to send sensitive source code or vulnerability data to an external AI provider. But because it is built on a Chinese base model, developers should still test for any censorship or political biases that may have carried over.

HRF Participated in the Bitcoin Policy Institute’s Freedom Tech DC

This week, the Bitcoin Policy Institute — a nonprofit think tank working on Bitcoin and public policy — hosted “Freedom Tech DC,” a summit on keeping money, speech, and intelligence free. In past years, the event largely focused on Bitcoin and its role as freedom money. This year, it expanded into AI, open models, and the question of how to keep powerful intelligence under individual control. HRF’s Anna Chekhovich and Arsh Molu discussed how freedom technologies from Bitcoin to AI can empower activists, while HRF’s Chief Strategy Officer Alex Gladstein discussed the broader state of freedom tech and why private AI could empower millions worldwide. Watch the recording here.

New Open-Weight Model Hemmingway-1 Focused on Human Writing

The team at AI company Altworld released Hemmingway-1, an open-weight model fine-tuned for everyday writing, such as emails, texts, and workplace messages. Unlike many AI models that give long explanations, Hemmingway-1 is trained to simply write the message a user needs. Altworld says its own blind tests found that Hemmingway-1 beat much larger models on everyday communication. And because its weights are open, dissidents with sufficient hardware could run it locally instead of sending sensitive writing to an AI company’s servers. It still requires a high-end computer, but others could build smaller versions, and versions for more languages, making private AI writing tools accessible to far more people.

Important: Hemmingway-1 was built on the open-weight Chinese AI model Qwen3.8-27B, showing how open models can be adapted for entirely new uses. But because the base model was developed in China, it could reflect Chinese Communist Party biases or censorship, and some of those behaviors could carry over into Hemmingway-1.

Share

Related Program

Related Content

Empower Change With Your Donation

Join us in helping save lives and stand up to tyranny.

You May Also Like

How can we help?

Hit enter to search or ESC to close

Join the cause by subscribing to our newsletter.

Reach Out

Email Us