HRF's AI for Individual Rights Newsletter #12
- THE LATEST IN AI FOR REPRESSION
- RECOMMENDED CONTENT
- THE LATEST IN AI FOR FREEDOM
- RECOMMENDED CONTENT
Welcome to the 12th edition of HRF’s AI for Individual Rights newsletter.
This week we look at how police in Delhi shockingly used AI-powered facial recognition to scan India’s largest youth protest in decades, matching faces against a police database in real time. Now, activists are asking the courts to decide whether that crossed a constitutional line. In Russia, meanwhile, Vladimir Putin signed a law supporting AI models that uphold “traditional Russian spiritual and moral values” and run on infrastructure on Russian soil. The law may push citizens towards models that censor criticism of the regime and keep user data within the Kremlin’s reach.
But the push for AI that people can control themselves is gaining ground, too. More than 130 tech companies including OpenAI, Google, and Hugging Face signed a letter urging Washington not to restrict open-weight AI models, whose inner workings are publicly available. Anyone with sufficient hardware can download, modify, and run these models privately. This united front could help nurture a global ecosystem of powerful models that can run beyond the reach of companies and authoritarian regimes. And it comes at a time when open-weight models are getting more numerous, stronger, and easier to fit on hardware available in your home, or at your office.
We end with an essay by HRF Chief Strategy Officer Alex Gladstein published in the Journal of Democracy, in which he argues that AI is not only a weapon for tyrants but, more importantly, a force for freedom. He explains the growing power and capabilities of open-source AI agents, the importance of local, privacy-preserving AI, and HRF’s efforts to put these tools into the hands of human rights defenders.
THE LATEST IN AI FOR REPRESSION
Activists Speak Out Against AI Surveillance of India’s Youth Protest
Indian activists are contesting police use of AI-powered surveillance during India’s recent mass youth protests, which were sparked by exam paper leaks that gave some students an unfair advantage. During the demonstrations, officers deployed vans equipped with 360-degree cameras and facial recognition technology to scan crowds and flag matches in police databases. Now, two court cases (one before the Delhi High Court and another before the Supreme Court) seek to have the surveillance declared unconstitutional, the collected data destroyed, and clearer limits on the use of facial recognition imposed.
Why this matters: India’s hybrid-authoritarian regime is already operating thousands of facial-recognition cameras and has directed hundreds of millions of dollars towards surveillance and policing. If the courts allow police to identify and track peaceful protesters without limits, these cameras will continue to turn sites of protest into venues for disproportionate police surveillance.
Russia’s New AI Law Requires Models to Respect “Traditional Values”
Vladimir Putin signed a law aimed at supporting Russian-made AI models that uphold “traditional Russian spiritual and moral values.” To qualify for support, models must be developed by Russian companies, hosted in data centers on Russian soil, and certified as complying with Russian state-defined values (presumably, complying with Kremlin propaganda). If AI models meet these criteria, developers will be eligible to receive access to regime datasets for training and other support measures that have yet to be detailed. These incentives could accelerate the development of Kremlin-aligned AI models that store user data on infrastructure accessible to the regime.
In context: The Kremlin has already proposed to block foreign AI services like ChatGPT and Claude, which run outside of Russian-controlled infrastructure. If that becomes a reality, Russians could be pushed away from alternatives towards these state-supported models that comply with censorship demands and expose users’ data to surveillance.
Vietnam Plans To Advance Crime Detection With AI
Vietnam’s ruler Tô Lâm requested that the regime’s technical services force modernize its capabilities and transform into a “loyal” corps of technology experts to maintain social order and safeguard national security. He ordered the force to use AI and big data analytics to detect crime, strengthen law enforcement, and preserve national security. But in an authoritarian state that imprisons people for peaceful online expression, the use of such tools could accelerate the prosecution of those simply advocating for democracy and individual rights.
China Drafts the World’s First Binding Rules for AI Agents
The Cyberspace Administration of China, which oversees the regime’s censorship systems, is drafting national rules that could make AI agents easier for the state to surveil. Under these rules, providers may be required to give agents unique digital identities, record their interactions, monitor their behavior in real time, and forcibly terminate them if their activity is deemed abnormal. Agents would also face registration and compliance checks before interacting with other agents and tools, limiting their capabilities.
Why this matters: AI agents can supercharge the work of human rights defenders, but only if they remain private and under the user’s control. When an authoritarian regime can constantly monitor, restrict, or shut down the agents that benefit the work of human rights defenders and dissidents, the tools risk becoming instruments of repression rather than freedom.
Kazakhstan Deploys AI-Powered Robot Dog to Monitor Large Events
Police in Kazakhstan’s Karaganda region deployed an AI-powered robot dog at public celebrations that drew more than 115,000 people in attendance. The robot dog runs AI-powered facial recognition against Kazakhstan’s Interior Ministry databases, scanning faces in the crowd and alerting nearby officers the moment it finds a match. Over two days, the AI flagged four people, none of whom were accused of anything more serious than unpaid debts. If authorities can use a roaming robot to locate people over minor infractions, the same technology could easily be turned against peaceful protesters.
In context: In 2022, Kazakhstan issued “shoot-to-kill” orders on protesters, caused the deaths of at least 225 people, and imprisoned more than 10,000 individuals.
Russian Security Service Planned To Use AI To Track Media
IStories, a Russian investigative journalism outlet, discovered that Russia’s Federal Security Service (FSB) planned to build an AI assistant capable of searching media reports alongside government databases. Named PAUK, or “spider,” the system would have collected information from news websites and Telegram channels and combined it with internal documents and personal data, including names, phone numbers, license plates, and vehicle details. Officers could then search the information with an AI chatbot. Although the project ended before delivering a functioning system, leaked documents reveal the FSB’s interest in using AI to automate its surveillance and intelligence gathering.
Why this matters: The FSB tracks opposition figures, activists, and protest movements. An AI system like PAUK could help officers identify, track, and target government critics more quickly and efficiently.
RECOMMENDED CONTENT
Why Should We Care About Rising Dissent in China?
In this episode of “Why Should We Care About the Indo-Pacific?,” hosts Ray Powell and Jim Carouso interview Kevin Slaten, who leads Freedom House’s China Dissent Monitor, the only public database tracking protests across China. The project is an HRF grantee and uses AI to scan Chinese social media platforms to document protest activity before CCP algorithms take it down. Slaten discusses why protests are increasing in China, what they reveal about economic and social grievances, and how they show that dissent remains alive despite the CCP’s efforts to suppress it.
THE LATEST IN AI FOR FREEDOM
Tech Companies Urge Washington to Protect Open-Weight AI
More than 130 tech companies signed a letter urging regulators in Washington D.C. to embrace open-weight AI models rather than restrict them. Open-weight AI systems have inner workings that are publicly available for anyone to download, modify, and privately run. The letter explained that open models give users control over their own AI data and infrastructure, strengthen competition, and reduce dependence on a small handful of AI companies. Signatories included both large companies like NVIDIA, OpenAI, Google, Meta, Microsoft, and Amazon, as well as prominent supporters of open-source AI such as Hugging Face, Mistral, Ollama, and Nous Research. Read the full letter here.
Why this matters: For the first time, many of the leading American AI companies are standing together behind an open AI ecosystem. This landmark backing could strengthen the open-weight movement and encourage the development of powerful models in democracies that dissidents can run privately, customize, and keep under their own control.
Moonshot Releases Weights of Kimi K3
Chinese AI company Moonshot publicly released the weights of their newest model Kimi K3, which was previously available only through the company’s website and API. This means that anyone can now run the models themselves. The model’s initial release drew widespread attention for performing nearly as well as the top models from Anthropic and OpenAI. Users find it is particularly strong at coding, research, and completing multi-step tasks with AI agents, all while costing less than its counterparts. Now that its weights are open, anyone with sufficient hardware can now operate Kimi K3 privately on their own infrastructure to keep their data off Monshoot’s servers and outside China.
Important: Kimi K3’s affordability and openness could expand powerful, private access to AI to human rights defenders around the world. But users must remain cautious. AI companies in China must comply with regime censorship rules and requests for user data. As adoption of Chinese AI grows, models like Kimi K3 could extend the reach of the CCP’s technical censorship globally.
AI Finds Vulnerabilities in Bitcoin Infrastructure Amid Theft Incident
Bitcoin software developers, security researchers, funders, and companies are using AI to identify and patch security vulnerabilities across the Bitcoin ecosystem. The effort comes after the discovery of a security flaw affecting Coldcard Bitcoin wallets led to the theft of over $100 million in bitcoin since July 30. Because Bitcoin is a censorship-resistant monetary network relied upon by millions — especially those living under authoritarian regimes, financial repression, and weak economic systems — finding and fixing these vulnerabilities quickly is a high priority. A group of software developers who call themselves “Bitcoin Red Team” are using open-weight AI models to scan through Bitcoin-related codebases. In less than three days, they reported around 6,700 potential vulnerabilities across Bitcoin-related codebases, including over 1,000 classified as high or critical severity. OpenSats, a nonprofit funding open-source project, among others in the Bitcoin community are supporting AI-related costs. Meanwhile, Prem, a private AI infrastructure company, is auditing more than 27 Bitcoin projects with its AI tools powered by open-weight models, and Project Loupe is offering AI-powered security reviews for open-source Bitcoin software. These are just some of the efforts demonstrating how AI is helping secure the infrastructure behind one of the world’s most important open-source financial networks.
Learn more about the attack and theft in HRF’s Financial Freedom Report here.
Hugging Face Uses Open-Weight Model to Investigate AI-Driven Cyberattack
Hugging Face, the world’s largest platform for sharing AI models, used an open-weight model, GLM-5.2, to investigate an AI-powered cyberattack on its internal network. Attackers used OpenAI’s models to break into Hugging Face’s systems, steal login credentials, and access internal data. To defend itself, Hugging Face turned to commercial models to analyze the attack. But these models came with safeguards “which cannot distinguish an incident responder from an attacker” and blocked their queries. They resorted to running open-weight model GLM-5.2, a model with fewer safeguards, privately on their own infrastructure to understand the attack. The breach was contained, and its public models and datasets were unaffected.
Why this matters: Closed models can refuse to help during a cyber emergency. Open-weight models give intelligence they can adapt for defensive work while keeping sensitive data private.
AI Agent Helps Rising Tide Disburse Ten Grants for Venezuela Earthquake Relief
After attending one of HRF’s Agent Camps, Isabelle Hirs, Managing Director of Freedom in Practice at Rising Tide Foundation, used her AI agent to help launch an emergency fund to respond to the recent earthquake in Venezuela. Her agent helped her quickly build a website explaining the fund and providing guidance on sanctions, which convinced her advisors to move forward with the initiative. Her agent then helped her to create a portal to manage applications, collect applicants’ reports, and share materials with Rising Tide’s board for approval. Within one week, the fund moved from idea to execution, and 10 grants were approved for communities in need.
In context: After disasters like Venezuela’s earthquake, the need for support is urgent. Thousands are missing, and even more are left without homes or life-saving supplies. AI agents can help cut through logistical complexity and provide advice and on-the-ground support as quickly as possible.
Block Releases Buzz, an Open-Source Workspace for Humans and AI Agents
Block, the company behind Square and Cash App, launched Buzz, an open-source workspace where people and AI agents can work together in Slack-like chat channels. It supports coding agents such as Goose, Codex, and Claude Code, with more integrations in the works. Buzz was built on Nostr, a decentralized communications protocol. This allows users and AI agents to move across compatible tools without losing their data or relying on a centralized platform to do their work.
Why this matters: Nonprofits and human rights organizations can use Buzz to work with AI agents while keeping more control over their communications and data.
The Anti-Corruption Foundation Hosts “Hackathon Against Putin’s Party United Russia”
The Anti-Corruption Foundation, the leading Russian opposition organization founded by the late Alexei Navalny, hosted a hackathon in Berlin in July. The event, sponsored by HRF, brought together Russian activists and technologists to use AI to build digital tools to propel the democratic movement and resist Putin’s dictatorship. The first-place team developed a Telegram bot that collects and shares election data to expose attempts at election fraud. Another team created a bot that maps out nearby bomb shelters so Russians can quickly find safe places in moments of danger. A third built an in-browser game where players are quizzed on examples of Kremlin corruption and repression.
RECOMMENDED CONTENT
How AI Agents Are Empowering Human-Rights Defenders
In a recent essay for the Journal of Democracy, HRF Chief Strategy Officer Alex Gladstein tells the inside story of how HRF saw AI’s potential for civil liberties very early on and began supporting activists in their use of open, privacy-preserving AI. From early chatbots to personal AI agents that allow anyone to build powerful software with unprecedented ease, Gladstein traces how human rights defenders are learning to harness AI’s power to level the playing field for good.
You can also listen to his interview with the BBC World Service and hear how AI can be revolutionary for human rights only if it is private, sovereign, and local.
Write a comment