Think Tanks
Here's a look at documents from think tanks
Featured Stories
Rand: Cyclospora Outbreak Was a Warning - Q&A With Saskia Popescu
SANTA MONICA, California, Aug. 25 -- Rand issued the following Q&A on Aug. 24, 2026, involving policy researcher Saskia Popescu:
* * *
The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu
A parasitic infection linked to tainted lettuce has left thousands of people doubled over in pain this summer. Two people have died. For RAND's Saskia Popescu, the outbreak has been a reminder--of America's vulnerabilities, and of what it will take to close them.
Popescu is an epidemiologist by training--a disease detective--and a policy researcher at RAND. Her work focuses on helping the U.S. health ... Show Full Article SANTA MONICA, California, Aug. 25 -- Rand issued the following Q&A on Aug. 24, 2026, involving policy researcher Saskia Popescu: * * * The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu A parasitic infection linked to tainted lettuce has left thousands of people doubled over in pain this summer. Two people have died. For RAND's Saskia Popescu, the outbreak has been a reminder--of America's vulnerabilities, and of what it will take to close them. Popescu is an epidemiologist by training--a disease detective--and a policy researcher at RAND. Her work focuses on helping the U.S. healthsystem prepare for, and guard against, health threats, whether from an AI-engineered pathogen, a pandemic virus, or some bad lettuce.
Her career before RAND took her from the front lines of disease response to advising on an international treaty against biological weapons. During COVID, she coordinated testing, tracing, and disease prevention for Netflix across dozens of film productions. It's the kind of work she always wanted to do. She pulled on her first biohazard suit when she was eight years old, dressing up for Halloween as a virologist.
Q: As a biosecurity expert, what stands out to you about this summer's Cyclospora outbreak and the response to it?
A: We call the food system America's soft underbelly, because it's so critical but so vulnerable. This outbreak really highlights that. I wasn't surprised that it was so tricky to identify the source. For these outbreaks, you're trying to identify likely sources and trends across dozens of cases, doing testing and tracing, even calling people and asking them what they ate weeks before. I knew early on, oh, this is going to be a challenge.
With an outbreak like this, it's not just about having funding and resources available, although that's critical. You also need coordination across agencies, public support, and effective communication. You need people in place who can take the information coming in and translate it into action. Identifying and closing any gaps in those areas would help us be more prepared for the next outbreak.
What health threats most concern you?
It's how we frame threats that worries me the most. We focus everything on a few big threats at the cost of others. But there are things we could be doing that would address the whole spectrum of threats. Investing in pathogen early warning systems like wastewater surveillance, for example. Scaling up manufacturing of personal protective equipment or PPE. Improving coordination across agencies and with the private sector.
AI is a big component of this. It has so much potential to pull information from all the different networks and nodes and really enhance our biosurveillance capabilities. But there's also a possibility that it could soon help someone develop a biological weapon or spread mis- or disinformation that could hinder a critical response. That's one of the big questions we're working on at RAND: How do you address those risks while ensuring that the guardrails we put up don't hinder legitimate science?
If you were advising policymakers on the next steps the United States should take to be ready for future threats, what would you recommend?
The first is just really making sure our biosurveillance network is as robust as possible against human, animal, and plant pathogens. And be loud about it. I was just recently part of an expert workshop at RAND looking at how to strengthen resilience and deterrence against biological threats. We need our adversaries to know that they won't be successful if they test our biodefenses, and that they will be caught.
Beyond that, we could build up our supply chains to make sure frontline workers have adequate respiratory protection when they need it. We just published a report on how to strengthen PPE manufacturing capacity in the United States, which highlights the role small- and medium-sized companies can play and how we can make our infrastructure more robust. We could also make sure hospitals don't just have plans in place to deal with public health emergencies but that they train for them regularly. We could work to get ahead of the health misinformation and disinformation campaigns that we know our adversaries invest in.
And then, we really need to rebuild public trust--in the federal response, in state responses, and in science. We have a public right now that is less likely to follow public health guidance, and we need to address that.
The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu
How does your experience in the field shape the work you do now at RAND?
We've been looking at that gap in biosurveillance between what we need and what is currently in place. I worked several years ago on Ebola response and analysis, and one thing we saw was a disconnect between detection and response. It's like a fire alarm at your house. When it goes off, you need to be home, you need to hear it, you need to know what it means, and you need to be able to call 911. In health, there's too often a gap between when reports start coming in and when an effective response gets underway.
So we're looking at existing programs and trying to define: What is the perfect state of biosurveillance? But more broadly, we're really working at RAND to help build resilience to the whole spectrum of threats. It's not just the intersection of AI and biotechnology. It's not just about building more robust biosurveillance networks. It's looking at how we can improve our entire response, upstream and downstream.
* * *
Original text here: https://www.rand.org/pubs/commentary/2026/08/the-cyclospora-outbreak-was-a-warning-qa-with-saskia.html
[Category: ThinkTank]
* * *
The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu
A parasitic infection linked to tainted lettuce has left thousands of people doubled over in pain this summer. Two people have died. For RAND's Saskia Popescu, the outbreak has been a reminder--of America's vulnerabilities, and of what it will take to close them.
Popescu is an epidemiologist by training--a disease detective--and a policy researcher at RAND. Her work focuses on helping the U.S. health ... Show Full Article SANTA MONICA, California, Aug. 25 -- Rand issued the following Q&A on Aug. 24, 2026, involving policy researcher Saskia Popescu: * * * The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu A parasitic infection linked to tainted lettuce has left thousands of people doubled over in pain this summer. Two people have died. For RAND's Saskia Popescu, the outbreak has been a reminder--of America's vulnerabilities, and of what it will take to close them. Popescu is an epidemiologist by training--a disease detective--and a policy researcher at RAND. Her work focuses on helping the U.S. healthsystem prepare for, and guard against, health threats, whether from an AI-engineered pathogen, a pandemic virus, or some bad lettuce.
Her career before RAND took her from the front lines of disease response to advising on an international treaty against biological weapons. During COVID, she coordinated testing, tracing, and disease prevention for Netflix across dozens of film productions. It's the kind of work she always wanted to do. She pulled on her first biohazard suit when she was eight years old, dressing up for Halloween as a virologist.
Q: As a biosecurity expert, what stands out to you about this summer's Cyclospora outbreak and the response to it?
A: We call the food system America's soft underbelly, because it's so critical but so vulnerable. This outbreak really highlights that. I wasn't surprised that it was so tricky to identify the source. For these outbreaks, you're trying to identify likely sources and trends across dozens of cases, doing testing and tracing, even calling people and asking them what they ate weeks before. I knew early on, oh, this is going to be a challenge.
With an outbreak like this, it's not just about having funding and resources available, although that's critical. You also need coordination across agencies, public support, and effective communication. You need people in place who can take the information coming in and translate it into action. Identifying and closing any gaps in those areas would help us be more prepared for the next outbreak.
What health threats most concern you?
It's how we frame threats that worries me the most. We focus everything on a few big threats at the cost of others. But there are things we could be doing that would address the whole spectrum of threats. Investing in pathogen early warning systems like wastewater surveillance, for example. Scaling up manufacturing of personal protective equipment or PPE. Improving coordination across agencies and with the private sector.
AI is a big component of this. It has so much potential to pull information from all the different networks and nodes and really enhance our biosurveillance capabilities. But there's also a possibility that it could soon help someone develop a biological weapon or spread mis- or disinformation that could hinder a critical response. That's one of the big questions we're working on at RAND: How do you address those risks while ensuring that the guardrails we put up don't hinder legitimate science?
If you were advising policymakers on the next steps the United States should take to be ready for future threats, what would you recommend?
The first is just really making sure our biosurveillance network is as robust as possible against human, animal, and plant pathogens. And be loud about it. I was just recently part of an expert workshop at RAND looking at how to strengthen resilience and deterrence against biological threats. We need our adversaries to know that they won't be successful if they test our biodefenses, and that they will be caught.
Beyond that, we could build up our supply chains to make sure frontline workers have adequate respiratory protection when they need it. We just published a report on how to strengthen PPE manufacturing capacity in the United States, which highlights the role small- and medium-sized companies can play and how we can make our infrastructure more robust. We could also make sure hospitals don't just have plans in place to deal with public health emergencies but that they train for them regularly. We could work to get ahead of the health misinformation and disinformation campaigns that we know our adversaries invest in.
And then, we really need to rebuild public trust--in the federal response, in state responses, and in science. We have a public right now that is less likely to follow public health guidance, and we need to address that.
The Cyclospora Outbreak Was a Warning: Q&A with Saskia Popescu
How does your experience in the field shape the work you do now at RAND?
We've been looking at that gap in biosurveillance between what we need and what is currently in place. I worked several years ago on Ebola response and analysis, and one thing we saw was a disconnect between detection and response. It's like a fire alarm at your house. When it goes off, you need to be home, you need to hear it, you need to know what it means, and you need to be able to call 911. In health, there's too often a gap between when reports start coming in and when an effective response gets underway.
So we're looking at existing programs and trying to define: What is the perfect state of biosurveillance? But more broadly, we're really working at RAND to help build resilience to the whole spectrum of threats. It's not just the intersection of AI and biotechnology. It's not just about building more robust biosurveillance networks. It's looking at how we can improve our entire response, upstream and downstream.
* * *
Original text here: https://www.rand.org/pubs/commentary/2026/08/the-cyclospora-outbreak-was-a-warning-qa-with-saskia.html
[Category: ThinkTank]
Capital Research Center Issues Commentary: 'Charities' Influencing Elections - 2024 and Beyond
WASHINGTON, Aug. 25 (TNSrpt) -- The Capital Research Center issued the following commentary on Aug. 24, 2026, by investigative researcher Parker Thayer, senior research analyst Robert Stilson and journalist Fred Lucas:
* * *
The "Charities" influencing elections: 2024 and beyond
A new CRC report on the charities trying to influence elections is available for download.
-
From the Constitutional Convention through the end of the 20th century, American elections were a simple, widely understood and respected, core act of citizenship. Of course, everyone took our turns being displeased with the ... Show Full Article WASHINGTON, Aug. 25 (TNSrpt) -- The Capital Research Center issued the following commentary on Aug. 24, 2026, by investigative researcher Parker Thayer, senior research analyst Robert Stilson and journalist Fred Lucas: * * * The "Charities" influencing elections: 2024 and beyond A new CRC report on the charities trying to influence elections is available for download. - From the Constitutional Convention through the end of the 20th century, American elections were a simple, widely understood and respected, core act of citizenship. Of course, everyone took our turns being displeased with theoutcome of certain elections. But win or lose, Americans accepted that the greatest experiment in representative government was working. The evidence was strong: only lightly altered over that time, our electoral system has helped us unleash an exceptional culture of liberty and opportunity that is both historically unprecedented and still has no modern rivals.
That's surely worth preserving. But the 21st century has birthed well-funded movements that all presume otherwise and promote major changes to how the American people hire their politicians. Perhaps not coincidentally, as these movements preaching the supposed failures of our representative republic have multiplied, trust in our elections has declined.
This report profiles multiple examples.
In the conventional American tradition, voter registration was a nonpartisan, good government effort to increase participation. But today's version has become fiercely partisan. The chapter titled "The Left's voter registration grift thrived in 2024" explains how that happened:
The best explanation of the tax-exempt vote machine comes from the leaked emails of John Podesta. One such email, sent to Podesta in 2015 by the president of Swiss billionaire Hansjorg Wyss's private foundation, contains an extremely detailed plan for using 501(c)(3) foundations and charities [which are forbidden by law to carry out partisan election work] to fund and execute a $100 million plot to register millions of voters.
But not all voters. In callously presented tables, the plan sums up "total non-white" votes that might be generated in eight key swing states, while still-visible edits show entire paragraphs about beating Republicans and "reshaping the electorate" being removed [from an earlier version of the scheme . . .] the plan was to direct 501(c)(3) voter registration at only demographics whose voting tendencies just so happen to benefit the Democratic party for the specific purpose of winning elections.
By 2020, this program had become so pivotal for Democrats that a Democratic Super PAC boasted voter registration using the charitable sector is "4 to 10 times more cost effective than the next best alternative" at "netting additional democratic votes," after tax considerations are included.
This voter registration machine spent $638 million during the 2024 election, and much of that was raised by what are supposed to be nonpartisan charitable nonprofits. But many of those 501(c)(3) groups were forwarding most of the money over to 501(c)(4) advocacy nonprofits.
Examples of nonprofits profiled in this chapter include (but are not limited to) the Voter Participation Center, State Voices, America Votes Education Fund, Democracy Matters Foundation, and the Guarantee Our Votes Projects.
Alongside this behavior, some groups, such as the Voter Participation Center (VPC) and its allies, have been alleging voter suppression. But in the chapter titled "The voting experts are full of it," this report shows that VPC's own research has repeatedly shown that the suppression has not occurred.
For example, in 2021 Georgia passed an election integrity measure that was dubbed "Jim Crow 2.0" by President Biden because he and his allies asserted it would suppress the votes of "underrepresented communities." Similarly, VPC joined an ultimately unsuccessful lawsuit to overturn the Georgia measure.
But a September 2025 report from the Voter Participation Center found the opposite of voter suppression, even though the Georgia law remained on the books for the 2024 election:
The research slide deck admits that "Turnout in 2024 was actually higher than turnout in 2020 among UC groups in some swing states - Georgia, Nevada, and Michigan." Georgia's "Underrepresented" or "UC" turnout, defined as turnout from African American, Latino, Asian, under 35, and unmarried women voters, increased by nearly 200,000 votes, or 6.8 percent, while "non-UC" votes decreased by nearly 180,000, or 9.2 percent. That means Georgia's "UC" turnout increased while "non-UC" turnout decreased nationwide and particularly in states like California, New York and Wisconsin.
Not convinced by its own research, VPC is now an opponent of the federal SAVE Act, which merely requires proof of citizenship before casting a ballot. Repeating claims it used against the Georgia law, VPC now asserts the SAVE Act will "disenfranchise" voters from the "underrepresented groups."
Another plan to rig future elections in favor of Democrats is revealed in the chapter titled "The vote machine is already planning for the 2030 Census." If the voter registration charities were operating what is better described as a partisan "get out the vote" program, then Census charities are running a "get out the count" operation.
The main player here is the Funders Committee for Civic Participation (FCCP) and its Funders Census Initiative (FCI), formed in 2008 with support from the Ford Foundation and other major left-wing philanthropic donors.
This Big Philanthropy alliance spent $38 million to help the federal government count the people FCI most wanted to find for the 2010 Census. FCI also boasted of its work to defeat a proposal that would have required a citizenship question during that count.
This program was ramped up to $118 million (courtesy of more than 100 donors) for the 2020 Census. As the report notes, the bigger payday made a bigger difference:
... by the Census Bureau's own admission, there was massive overcounting, mostly in blue states, and massive undercounting, mostly in red states. The 2010 Census was reported to have a minuscule error rate of less than 1 percent; in 2020, the census reported undercounting six states and overcounting eight. As Hans Von Spakovsky explained in 2022, the Census Bureau's post-census survey data for the 2020 count shows that the over and under counts were so egregious that Minnesota and Rhode Island were apportioned two congressional seats that ought to have rightfully been assigned to Florida.
Corrupting the Census count, as this report notes, may have been the ultimate form of gerrymandering. But another chapter in this report, "Major donors to the Virginia redistricting ballot measure," shows that election-influencing charities have also been hard at work creating new forms of the old-style gerrymandering.
In Virginia, this took the form of a ballot proposal that would have redrawn the state's congressional districts ahead of the 2026 midterm election. If successful, this would have likely flipped Virginia from a narrow 6-5 Democratic majority (which more or less reflects the actual partisan divide among Virginians) to a 10-1 Democratic advantage (which does not).
It was the most expensive ballot measure in Virginia history, with supporters of the 10-1 Democrat-favorable map "significantly better resourced" than proponents of keeping the old map. Our report shows millions of dollars contributed by committees affiliated with George Soros, the Service Employees International Union, and what was once known as the Arabella Advisors network.
All this loot--more than $66 million--helped persuade a majority of Virginia voters to approve the measure in an April 2026 special election. But two weeks later the Virginia Supreme Court invalidated the new map, citing procedural violations.
The U.S. Constitution is another "procedural" roadblock the election-influencing charities would like to sweep away. The chapter titled "Enemies of the Electoral College" profiles a movement that seeks to do away with the way every president since George Washington has been selected.
The largest and best-funded effort is known as the National Popular Vote (NPV) Compact. It would "award all electoral votes from all states within the compact to the winner of the national popular vote, regardless of which candidate won the popular vote within each individual state." The chapter explains the many problems with this, not least of which is diminishing the influence of low population states--exactly what the authors of the U.S. Constitution intended to prevent with the Electoral College and the Senate.
The alleged upside of the NPV Compact is that it would eliminate closely contested elections where the candidate receiving the most popular votes (a majority or not) does not win the Electoral College. Supposedly, this would create the appearance of a more united nation.
The chapter notes that this is mostly a solution in search of a problem:
The alleged problem this supposedly solves has happened just five times over sixty American presidential elections, and only twice since the election of 1888. Notably, the beneficiaries in the two cases that anyone alive can remember (Bush in 2000 and Trump in 2016) were both Republicans. It should be no surprise that the NPV movement is animated more by partisan goals than policy objectives.
The report shows the NPV movement is also animated by some carefully selected, nominally Republican political professionals, to help it get across the line in red states. But here again, the old Arabella Advisors network, Big Labor, and other left-leaning contributors have been writing most of the NPV checks.
Hiring the Republican operators in a rent-a-pol campaign has been somewhat successful. At present, NPV has secured a commitment from states representing 222 of the 270 presidential electoral votes need to implement the Compact.
Finally, as if trying to muddle up the presidential election process after 238 years wasn't sowing enough distrust, an even more confusing idea is profiled in the chapter titled "Ranked Choice Voting is down, but not out." As the essay explains, the American tradition of "one person one vote" and "vote for the person you like" would be replaced with this contraption:
In the simplest form of an RCV election, all candidates, regardless of party, are placed in one pool and voters rank them in order of preference. If no candidate secures a majority of first place ballots, then the candidate with the fewest first place ballots is removed from consideration and the rankings on those ballots are reassigned. Voters who placed the removed candidate as their first choice have their second choice promoted as their top remaining (i.e.: first) choice. This process repeats until one candidate survives as the top remaining choice for the majority of the voters [who still remain in the count].
Notable supporters include Texas hedge-fund manager John Arnold ... but not actual Americans. On Election Day 2024, voters in at least five states rejected ballot measures that would have implemented RCV. The report also shows RCV is so unpopular that 19 states have enacted total prohibitions against its use, with seven of them doing so since January 2025.
This shouldn't be surprising. We know in our bones that making voting needlessly complicated corrupts the integrity of elections. We also know that charitable voter registration should not be slanted in favor of one political party. We know that corrupting the Census count corrupts our elections (and much else).
And though it isn't as straightforward as a simple popular vote, we are taught in elementary school why the Framers of the Constitution created the Electoral College to preserve the role of states with small populations. It's one of many good reasons why 13 colonies hugging the Atlantic Coast became 50 states spilling far out into the Pacific and nearly touching Russia.
That's just one of many reasons why we respect our Constitution and change it only in very extreme situations. We are history's most wildly successful nation because we run on elegantly simple software.
After emerging from the Constitutional Convention, Ben Franklin was asked what sort of government he and his patriot compatriots had drawn up. "A republic, if you can keep it," he famously replied. Given what we now know that republic has accomplished, it shouldn't be so hard to keep it. But as this report shows, Franklin was wise to issue the warning.
***
Contents:
THE LEFT'S VOTER REGISTRATION GRIFT THRIVED IN 2024
* SIDEBAR: Government funding of voter registration
THE VOTING "EXPERTS" ARE FULL OF IT
THE VOTE MACHINE IS ALREADY PLANNING FOR THE 2030 CENSUS
ENEMIES OF THE ELECTORAL COLLEGE
WHO FUNDS RANKED CHOICE VOTING?
THE MONEY BEHIND THE VIRGINIA REDISTRICTING FIGHT
* * *
REPORT: https://capitalresearch.org/app/uploads/FINAL_CRC_CharitiesInfluencingElections_WebDraft.pdf
* * *
Original text here: https://capitalresearch.org/article/the-charities-influencing-elections-2024-and-beyond/
[Category: ThinkTank]
* * *
The "Charities" influencing elections: 2024 and beyond
A new CRC report on the charities trying to influence elections is available for download.
-
From the Constitutional Convention through the end of the 20th century, American elections were a simple, widely understood and respected, core act of citizenship. Of course, everyone took our turns being displeased with the ... Show Full Article WASHINGTON, Aug. 25 (TNSrpt) -- The Capital Research Center issued the following commentary on Aug. 24, 2026, by investigative researcher Parker Thayer, senior research analyst Robert Stilson and journalist Fred Lucas: * * * The "Charities" influencing elections: 2024 and beyond A new CRC report on the charities trying to influence elections is available for download. - From the Constitutional Convention through the end of the 20th century, American elections were a simple, widely understood and respected, core act of citizenship. Of course, everyone took our turns being displeased with theoutcome of certain elections. But win or lose, Americans accepted that the greatest experiment in representative government was working. The evidence was strong: only lightly altered over that time, our electoral system has helped us unleash an exceptional culture of liberty and opportunity that is both historically unprecedented and still has no modern rivals.
That's surely worth preserving. But the 21st century has birthed well-funded movements that all presume otherwise and promote major changes to how the American people hire their politicians. Perhaps not coincidentally, as these movements preaching the supposed failures of our representative republic have multiplied, trust in our elections has declined.
This report profiles multiple examples.
In the conventional American tradition, voter registration was a nonpartisan, good government effort to increase participation. But today's version has become fiercely partisan. The chapter titled "The Left's voter registration grift thrived in 2024" explains how that happened:
The best explanation of the tax-exempt vote machine comes from the leaked emails of John Podesta. One such email, sent to Podesta in 2015 by the president of Swiss billionaire Hansjorg Wyss's private foundation, contains an extremely detailed plan for using 501(c)(3) foundations and charities [which are forbidden by law to carry out partisan election work] to fund and execute a $100 million plot to register millions of voters.
But not all voters. In callously presented tables, the plan sums up "total non-white" votes that might be generated in eight key swing states, while still-visible edits show entire paragraphs about beating Republicans and "reshaping the electorate" being removed [from an earlier version of the scheme . . .] the plan was to direct 501(c)(3) voter registration at only demographics whose voting tendencies just so happen to benefit the Democratic party for the specific purpose of winning elections.
By 2020, this program had become so pivotal for Democrats that a Democratic Super PAC boasted voter registration using the charitable sector is "4 to 10 times more cost effective than the next best alternative" at "netting additional democratic votes," after tax considerations are included.
This voter registration machine spent $638 million during the 2024 election, and much of that was raised by what are supposed to be nonpartisan charitable nonprofits. But many of those 501(c)(3) groups were forwarding most of the money over to 501(c)(4) advocacy nonprofits.
Examples of nonprofits profiled in this chapter include (but are not limited to) the Voter Participation Center, State Voices, America Votes Education Fund, Democracy Matters Foundation, and the Guarantee Our Votes Projects.
Alongside this behavior, some groups, such as the Voter Participation Center (VPC) and its allies, have been alleging voter suppression. But in the chapter titled "The voting experts are full of it," this report shows that VPC's own research has repeatedly shown that the suppression has not occurred.
For example, in 2021 Georgia passed an election integrity measure that was dubbed "Jim Crow 2.0" by President Biden because he and his allies asserted it would suppress the votes of "underrepresented communities." Similarly, VPC joined an ultimately unsuccessful lawsuit to overturn the Georgia measure.
But a September 2025 report from the Voter Participation Center found the opposite of voter suppression, even though the Georgia law remained on the books for the 2024 election:
The research slide deck admits that "Turnout in 2024 was actually higher than turnout in 2020 among UC groups in some swing states - Georgia, Nevada, and Michigan." Georgia's "Underrepresented" or "UC" turnout, defined as turnout from African American, Latino, Asian, under 35, and unmarried women voters, increased by nearly 200,000 votes, or 6.8 percent, while "non-UC" votes decreased by nearly 180,000, or 9.2 percent. That means Georgia's "UC" turnout increased while "non-UC" turnout decreased nationwide and particularly in states like California, New York and Wisconsin.
Not convinced by its own research, VPC is now an opponent of the federal SAVE Act, which merely requires proof of citizenship before casting a ballot. Repeating claims it used against the Georgia law, VPC now asserts the SAVE Act will "disenfranchise" voters from the "underrepresented groups."
Another plan to rig future elections in favor of Democrats is revealed in the chapter titled "The vote machine is already planning for the 2030 Census." If the voter registration charities were operating what is better described as a partisan "get out the vote" program, then Census charities are running a "get out the count" operation.
The main player here is the Funders Committee for Civic Participation (FCCP) and its Funders Census Initiative (FCI), formed in 2008 with support from the Ford Foundation and other major left-wing philanthropic donors.
This Big Philanthropy alliance spent $38 million to help the federal government count the people FCI most wanted to find for the 2010 Census. FCI also boasted of its work to defeat a proposal that would have required a citizenship question during that count.
This program was ramped up to $118 million (courtesy of more than 100 donors) for the 2020 Census. As the report notes, the bigger payday made a bigger difference:
... by the Census Bureau's own admission, there was massive overcounting, mostly in blue states, and massive undercounting, mostly in red states. The 2010 Census was reported to have a minuscule error rate of less than 1 percent; in 2020, the census reported undercounting six states and overcounting eight. As Hans Von Spakovsky explained in 2022, the Census Bureau's post-census survey data for the 2020 count shows that the over and under counts were so egregious that Minnesota and Rhode Island were apportioned two congressional seats that ought to have rightfully been assigned to Florida.
Corrupting the Census count, as this report notes, may have been the ultimate form of gerrymandering. But another chapter in this report, "Major donors to the Virginia redistricting ballot measure," shows that election-influencing charities have also been hard at work creating new forms of the old-style gerrymandering.
In Virginia, this took the form of a ballot proposal that would have redrawn the state's congressional districts ahead of the 2026 midterm election. If successful, this would have likely flipped Virginia from a narrow 6-5 Democratic majority (which more or less reflects the actual partisan divide among Virginians) to a 10-1 Democratic advantage (which does not).
It was the most expensive ballot measure in Virginia history, with supporters of the 10-1 Democrat-favorable map "significantly better resourced" than proponents of keeping the old map. Our report shows millions of dollars contributed by committees affiliated with George Soros, the Service Employees International Union, and what was once known as the Arabella Advisors network.
All this loot--more than $66 million--helped persuade a majority of Virginia voters to approve the measure in an April 2026 special election. But two weeks later the Virginia Supreme Court invalidated the new map, citing procedural violations.
The U.S. Constitution is another "procedural" roadblock the election-influencing charities would like to sweep away. The chapter titled "Enemies of the Electoral College" profiles a movement that seeks to do away with the way every president since George Washington has been selected.
The largest and best-funded effort is known as the National Popular Vote (NPV) Compact. It would "award all electoral votes from all states within the compact to the winner of the national popular vote, regardless of which candidate won the popular vote within each individual state." The chapter explains the many problems with this, not least of which is diminishing the influence of low population states--exactly what the authors of the U.S. Constitution intended to prevent with the Electoral College and the Senate.
The alleged upside of the NPV Compact is that it would eliminate closely contested elections where the candidate receiving the most popular votes (a majority or not) does not win the Electoral College. Supposedly, this would create the appearance of a more united nation.
The chapter notes that this is mostly a solution in search of a problem:
The alleged problem this supposedly solves has happened just five times over sixty American presidential elections, and only twice since the election of 1888. Notably, the beneficiaries in the two cases that anyone alive can remember (Bush in 2000 and Trump in 2016) were both Republicans. It should be no surprise that the NPV movement is animated more by partisan goals than policy objectives.
The report shows the NPV movement is also animated by some carefully selected, nominally Republican political professionals, to help it get across the line in red states. But here again, the old Arabella Advisors network, Big Labor, and other left-leaning contributors have been writing most of the NPV checks.
Hiring the Republican operators in a rent-a-pol campaign has been somewhat successful. At present, NPV has secured a commitment from states representing 222 of the 270 presidential electoral votes need to implement the Compact.
Finally, as if trying to muddle up the presidential election process after 238 years wasn't sowing enough distrust, an even more confusing idea is profiled in the chapter titled "Ranked Choice Voting is down, but not out." As the essay explains, the American tradition of "one person one vote" and "vote for the person you like" would be replaced with this contraption:
In the simplest form of an RCV election, all candidates, regardless of party, are placed in one pool and voters rank them in order of preference. If no candidate secures a majority of first place ballots, then the candidate with the fewest first place ballots is removed from consideration and the rankings on those ballots are reassigned. Voters who placed the removed candidate as their first choice have their second choice promoted as their top remaining (i.e.: first) choice. This process repeats until one candidate survives as the top remaining choice for the majority of the voters [who still remain in the count].
Notable supporters include Texas hedge-fund manager John Arnold ... but not actual Americans. On Election Day 2024, voters in at least five states rejected ballot measures that would have implemented RCV. The report also shows RCV is so unpopular that 19 states have enacted total prohibitions against its use, with seven of them doing so since January 2025.
This shouldn't be surprising. We know in our bones that making voting needlessly complicated corrupts the integrity of elections. We also know that charitable voter registration should not be slanted in favor of one political party. We know that corrupting the Census count corrupts our elections (and much else).
And though it isn't as straightforward as a simple popular vote, we are taught in elementary school why the Framers of the Constitution created the Electoral College to preserve the role of states with small populations. It's one of many good reasons why 13 colonies hugging the Atlantic Coast became 50 states spilling far out into the Pacific and nearly touching Russia.
That's just one of many reasons why we respect our Constitution and change it only in very extreme situations. We are history's most wildly successful nation because we run on elegantly simple software.
After emerging from the Constitutional Convention, Ben Franklin was asked what sort of government he and his patriot compatriots had drawn up. "A republic, if you can keep it," he famously replied. Given what we now know that republic has accomplished, it shouldn't be so hard to keep it. But as this report shows, Franklin was wise to issue the warning.
***
Contents:
THE LEFT'S VOTER REGISTRATION GRIFT THRIVED IN 2024
* SIDEBAR: Government funding of voter registration
THE VOTING "EXPERTS" ARE FULL OF IT
THE VOTE MACHINE IS ALREADY PLANNING FOR THE 2030 CENSUS
ENEMIES OF THE ELECTORAL COLLEGE
WHO FUNDS RANKED CHOICE VOTING?
THE MONEY BEHIND THE VIRGINIA REDISTRICTING FIGHT
* * *
REPORT: https://capitalresearch.org/app/uploads/FINAL_CRC_CharitiesInfluencingElections_WebDraft.pdf
* * *
Original text here: https://capitalresearch.org/article/the-charities-influencing-elections-2024-and-beyond/
[Category: ThinkTank]
CSIS Issues Commentary: What's Behind China's Problematic Advance in Uruguay?
WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Evan Ellis, senior associate (non-resident) in the Americas Program:
* * *
What's Behind China's Problematic Advance in Uruguay?
Introduction
In February 2026, Uruguayan President Yamandu Orsi made a state visit to Beijing, signing numerous nontransparent cooperation agreements advancing collaboration with the People's Republic of China (PRC) on meat and fish meal exports. Many other agreements were nonpublic and in sensitive areas such as science and media collaboration.
Largely ... Show Full Article WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Evan Ellis, senior associate (non-resident) in the Americas Program: * * * What's Behind China's Problematic Advance in Uruguay? Introduction In February 2026, Uruguayan President Yamandu Orsi made a state visit to Beijing, signing numerous nontransparent cooperation agreements advancing collaboration with the People's Republic of China (PRC) on meat and fish meal exports. Many other agreements were nonpublic and in sensitive areas such as science and media collaboration. Largelybelow the United States' radar, Uruguay has become one of the Western Hemisphere countries most economically engaged with the PRC relative to its small size, as well as collaborating with it in political, military, and other domains. The PRC has also begun to use its economic leverage over and influence networks within Uruguay in increasingly coercive ways. In March 2026, the governor of the province of Durango, Felipe Algorta, canceled a planned visit to Taiwan after then-PRC Ambassador Huang Yazhong met with him, telling him it would be inconsistent with Uruguay's national-level "One China" policy.
China's recent engagement in Uruguay illustrates how the PRC uses its economic leverage, together with other tools, to advance strategic interests even in countries with strong institutions and democratic traditions. That this influence persists despite Uruguay's location in the Western Hemisphere, a region that the Trump administration prioritized in its December 2025 National Security Strategy, should warn Washington that strong institutions and procedures alone are not sufficient for regional neighbors to ensure a managed balance of the benefits and risks while expanding their engagement with China.
PRC-Uruguay Political and Trade Engagement
Uruguay was relatively late among South American nations to establish relations with the PRC, doing so in February 1988. Reflecting a strong and growing trade dependence on the Chinese market, the country established a strategic partnership with the PRC in 2016, joined China's Belt and Road Initiative in August 2018, became part of the PRC-led Asia Infrastructure Investment Bank in April 2020, and, in November 2023, upgraded its relationship with the PRC to a comprehensive strategic partnership.
Additionally, the China Friendship Group in Uruguay's parliament relaunched in December 2025 and is headed by some of the country's most influential foreign policy-oriented parliamentarians: Daniel Caggiani Gomez, head of the Senate International Affairs Committee, and Representative Juan Martin Rodriguez, head of the Chamber of Deputies International Affairs Committee.
Uruguay's trade with the PRC is relatively balanced by dollar volume, with $3.5 billion in exports to China and $3.3 billion in imports from it. However, while over 90 percent of its exports are primary goods and agricultural products such as soybeans, wood pulp, and beef, Uruguay imports a broad array of manufactured and technology goods and services from the PRC. The country is also notably economically dependent on the PRC, which is the destination of 26 percent of its exports. That dependency could deepen with the negotiation of a PRC-Mercosur free trade agreement, a high priority for the current Frente Amplio party's government, which now has more power to advance that goal with Orsi as president pro tempore of Mercosur since June 2026.
Chinese Investment and Projects in Uruguay
By comparison to other states in the region such as Brazil, investment by PRC-based companies in Uruguay is small: only $247 million as of 2020, and less than $1 billion currently. Uruguay's small market of 3.4 million people is part of the reason for this limited investment, although PRC-based companies have also had a number of legal and financial difficulties in the country. Another reason mentioned by those consulted in Uruguay is the limited capabilities of the country's investment promotion office, Uruguay XXI, with respect to China. The organization does not have an office in the country and, based on the author's off-the-record discussions, was seen as partly to blame for what multiple insiders saw as poor planning and coordination in President Orsi's February 2026 trip to China.
Almost half of all PRC investments in Uruguay are concentrated in the country's agricultural sector. These include China Oilseeds and Foodstuffs Corporation, which owns 36 percent of the grain terminal at the port of Nueva Pamira, plus three meat processing facilities--Rondatel, Lirtix, and Lorsinal, each of which has had considerable financial difficulties since being acquired by the Chinese. In January 2026, Maregroup, a PRC-based tobacco company operating in Uruguay's Florida Free Trade Zone abruptly shut its doors and withdrew from the country. Uruguayan meat exports to the PRC have also run into problems on the Chinese side, with 34 tons of Uruguayan beef in two shipments rejected by the PRC during the past year on technical grounds.
Some difficulties also persist in the automotive sector. The Chinese companies Cherry and Lifan invested in an auto manufacturing plant in San Jose, but it was forced to close in 2021 after problems accessing markets in larger neighboring MERCOSUR countries Argentina and Brazil. The PRC-based company Brilliance similarly canceled a proposed auto factory in Uruguay in 2019. Despite such difficulties, Chinese companies are particularly strong in Uruguay's electric vehicle sector. BYD provides electric taxis to the Uruguay market, working with the country's transport authority. Chinese electric buses, supplied by BYD, Higer, and Yutong, now account for over 11 percent of the fleet. In addition, as elsewhere in the region, the PRC-based rideshare company Didi operates in Montevideo, including both its taxi and food delivery service.
In logistics, in 2018, the PRC-based company Shandong Bao Ma proposed a $200 million dedicated port facility at Punta Yeguas to process and store fish and resupply the Chinese deepwater fishing fleet. The project was criticized for a lack of transparency, concerns that it might enable illegal fishing activities by the Chinese fleet, and difficulties with zoning that led it to be transferred to Punta Sayago before it was effectively abandoned in 2019. Uruguay's port authority also contracted the Shanghai Dredging Company for work to deepen channels at the Port of Montevideo, but it was criticized for using a private Chinese dredging company rather than its own capabilities.
In telecommunications, as in elsewhere in Latin America, PRC-based companies have a strong presence, including Xiaomi, Honor, and Oppo. The smartphones of all three are carried by the state firm Antel and the commercial provider Movistar. Huawei is also available through retail stores. ZTE built Uruguay's new 5G network recently rolled out by Antel. In late 2025, Antel awarded an important telecommunications contract to Huawei rather than the European competitor Nokia in a decision that some in Uruguay believed was based in part on PRC pressure. Both Antel decisions raise data security concerns for Uruguay, its residents, and the companies that operate there, since PRC-based companies such as Huawei are obliged to turn over such data to the Chinese government, if requested, under Articles 7 and 14 of the 2017 PRC national intelligence law, as well as Article 28 of the 2017 PRC cybersecurity law.
PRC-based companies also have a growing role in Uruguay's retail sector, including outlets such as China Store, China Market, Mumuso, Miniso, and Todo Aca. Uruguayan investigations into these stores have been more limited than in other Latin American countries, although there have been recurring concerns with contraband merchandise, including a 2025 seizure of 17,000 pairs of contraband designer shoes by Uruguay's customs authority.
Chinese People-to-People Networks
The PRC has built significant people-to-people networks in Uruguay, including the previously mentioned Friendship Group in Uruguay's parliament. A delegation led by the head of the governing Frente Amplio party, Fernando Pereira, visited the PRC in May 2025, and previously, one in July 2024 led by the coalition's Coordinator Jorge Gotta visited Beijing in July 2024.
As elsewhere in the region, the PRC also cultivates ties with Uruguayan media. These include a 2023 content sharing agreement between Xinhua and the Uruguayan state audiovisual media service. Media cooperation was expanded by a follow-up accord during President Orsi's February 2026 state visit to the PRC. The Chinese government has also brought Uruguayan journalists to the PRC, including Leonardo Perez Pena of Diario de la R. For business networking, the private Uruguay-PRC Chamber of Commerce has operated in the country since 1986.
In education, a Confucius Institute has operated at Uruguay's University of the Republic since November 2017. Beyond ties involving official representatives of the PRC, several Uruguayan universities have programs for the study of China and its language and culture. These include Chinese language classes at the University of the Republic, as well as at ORT University, Catholic University, and Montevideo University, among others.
PRC people-to-people activities in other parts of Latin America, highlighted in China's own 2025 Policy White Paper on the region, are particularly influential to the region's discourse about China, and its coordination to pursue its national interests and avoid the risks stemming from such engagements. At best, those who have received travel benefits, as well as those who expect to receive future benefits--such as other invitations; money to present to, consult with, or teach at Chinese entities; or other business arrangements--may hesitate to be publicly critical about the PRC and its companies and activities, or to publicly work to pursue company or national interests if they impinge on Chinese interests. At the extreme, such past or hoped-for future relationships may lead Chinese assets to pass non-public information in their purview to China or to use their positions to advance PRC objectives in the country. Although there is very little public information about Chinese espionage in Latin America, U.S. intelligence and law enforcement organs detect such activity in the United States regularly: CSIS documented 224 cases of Chinese espionage in the United States since 2001.
PRC-Uruguay Military Cooperation
Uruguay's traditionally underfunded military has long received donations of vehicles and equipment from the PRC, as well as training and professional education trips for its officers to China. This cooperation was accelerated by a 2016 military cooperation agreement leading to a March 2018 donation of $5 million in tactical ambulances, minivans and tractors. In August 2024, Uruguay signed an additional defense protocol with the PRC, leading to the latter's donation of 15 trailer kitchens, 15 trailer generators, four 10,000-liter water tanks, a fuel tanker, and 136 digital radios.
Beyond donations, PRC-based military companies have sought to sell Uruguay military equipment. Major initiatives include an attempted Chinese sale of eight L-15 fighters, and separately, a $200 million bid to sell Uruguay offshore patrol vessels. In the latter case, the PRC-based company won the bid, but the procurement was suspended amid accusations of irregularities and concerns from the United States.
In January 2026, the PRC hospital ship Silk Road Arc made a four-day port call in Montevideo, the first time a Chinese warship had ever done so. Although characterized as a "technical stop" rather than a "medical mission," the ship and its crew were personally received by Uruguayan Defense Minister Sandra Lazo, and the countries conducted multiple military-military interactions while the ship was in port.
According to experts consulted in Uruguay off the record, Uruguay also sends at least one officer per year to the six-month military Command and General Staff course in China; as a result, multiple senior or retired officers who have had extended professional military education experiences in China are currently in senior positions in Uruguay's military. While these ties do not necessarily indicate that China is expanding its military contacts in Uruguay, it is certainly maintaining them. As with China's people-to-people diplomacy, this suggests that in Uruguay, as with other parts of Latin America, the People's Liberation Army will have knowledge of and relationships with Uruguayan officials that it can leverage to operate in or near the country in times of war.
The U.S. Dimension
As the PRC attempts to leverage its purchases of Uruguayan commodities to build commercial relationships and influence networks in Uruguay, the United States is working to strengthen its own relationships in the country from a strong base, but with limited resources. While Uruguay may not appear strategically important in terms of its size or natural resources, it is geographically strategic, positioned between Argentina and Brazil, on a river corridor that is key to the imports and exports of five South American nations. Moreover, its strong democratic traditions make it a test bed for whether such attributes are sufficient to resist PRC influence in the context of substantial trade dependence with the country.
U.S. Ambassador to Uruguay Lou Rinaldi has been able to leverage family ties to Uruguay and a close relationship with U.S. President Donald Trump to build a strong connection between the countries. Leading-edge U.S. companies including Google and Microsoft have made important investments in digital technologies and research and development in the country. Uruguay's left-of-center President Orsi, despite seemingly problematic moves such as his chaotic February 2026 trip to the PRC, has shown more willingness to accommodate U.S. concerns about China than some of his more Trump-aligned neighbors, including Argentina's Javier Milei, who just renewed a $19 billion currency swap agreement with the PRC after accepting $20 billion of U.S. financial underwriting. Still, because Uruguay is classified as a "high-income" country, the United States is significantly restricted in its ability to provide grants, military aid, or even Development Finance Corporation funds that could give the country healthy democratic alternatives to dependence on China.
Conclusion
China has become a major and influential trade partner in Urugay, and has built significant political, military, and people-to-people networks with the country despite the small size of its market.
Although Uruguay may seem a relatively small country distant from the United States, the course of its relationship with the PRC has strategic implications for both the United States and the region as a whole. If, despite Uruguay's relatively strong institutions and democratic traditions, the PRC can leverage its significant purchases of Uruguayan commodities and select business presence over Uruguayan intellectuals, businesspeople, military, and politicians, it will send a strong signal to both the country and the region that institutions and democracy are not enough to secure the benefits of engagement with the PRC. Conversely, if, in the context of numerous problematic Chinese projects and demonstrated coercion, the United States can give Uruguay effective alternatives and help it to build a healthier relationship with China, it will be a success story that can help the United States with its engagement on China in the rest of Latin America and beyond.
The United States has the team and the foundations to help Uruguay, with its strong institutions and democratic tradition, chose a better path forward. A modest increase in resources and enabling policies from Washington, including investment partnerships, police and security cooperation, and expanded scholarships for programs such as Fulbright, could go a long way.
* * *
Original text here: https://www.csis.org/analysis/whats-behind-chinas-problematic-advance-uruguay
[Category: ThinkTank]
* * *
What's Behind China's Problematic Advance in Uruguay?
Introduction
In February 2026, Uruguayan President Yamandu Orsi made a state visit to Beijing, signing numerous nontransparent cooperation agreements advancing collaboration with the People's Republic of China (PRC) on meat and fish meal exports. Many other agreements were nonpublic and in sensitive areas such as science and media collaboration.
Largely ... Show Full Article WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Evan Ellis, senior associate (non-resident) in the Americas Program: * * * What's Behind China's Problematic Advance in Uruguay? Introduction In February 2026, Uruguayan President Yamandu Orsi made a state visit to Beijing, signing numerous nontransparent cooperation agreements advancing collaboration with the People's Republic of China (PRC) on meat and fish meal exports. Many other agreements were nonpublic and in sensitive areas such as science and media collaboration. Largelybelow the United States' radar, Uruguay has become one of the Western Hemisphere countries most economically engaged with the PRC relative to its small size, as well as collaborating with it in political, military, and other domains. The PRC has also begun to use its economic leverage over and influence networks within Uruguay in increasingly coercive ways. In March 2026, the governor of the province of Durango, Felipe Algorta, canceled a planned visit to Taiwan after then-PRC Ambassador Huang Yazhong met with him, telling him it would be inconsistent with Uruguay's national-level "One China" policy.
China's recent engagement in Uruguay illustrates how the PRC uses its economic leverage, together with other tools, to advance strategic interests even in countries with strong institutions and democratic traditions. That this influence persists despite Uruguay's location in the Western Hemisphere, a region that the Trump administration prioritized in its December 2025 National Security Strategy, should warn Washington that strong institutions and procedures alone are not sufficient for regional neighbors to ensure a managed balance of the benefits and risks while expanding their engagement with China.
PRC-Uruguay Political and Trade Engagement
Uruguay was relatively late among South American nations to establish relations with the PRC, doing so in February 1988. Reflecting a strong and growing trade dependence on the Chinese market, the country established a strategic partnership with the PRC in 2016, joined China's Belt and Road Initiative in August 2018, became part of the PRC-led Asia Infrastructure Investment Bank in April 2020, and, in November 2023, upgraded its relationship with the PRC to a comprehensive strategic partnership.
Additionally, the China Friendship Group in Uruguay's parliament relaunched in December 2025 and is headed by some of the country's most influential foreign policy-oriented parliamentarians: Daniel Caggiani Gomez, head of the Senate International Affairs Committee, and Representative Juan Martin Rodriguez, head of the Chamber of Deputies International Affairs Committee.
Uruguay's trade with the PRC is relatively balanced by dollar volume, with $3.5 billion in exports to China and $3.3 billion in imports from it. However, while over 90 percent of its exports are primary goods and agricultural products such as soybeans, wood pulp, and beef, Uruguay imports a broad array of manufactured and technology goods and services from the PRC. The country is also notably economically dependent on the PRC, which is the destination of 26 percent of its exports. That dependency could deepen with the negotiation of a PRC-Mercosur free trade agreement, a high priority for the current Frente Amplio party's government, which now has more power to advance that goal with Orsi as president pro tempore of Mercosur since June 2026.
Chinese Investment and Projects in Uruguay
By comparison to other states in the region such as Brazil, investment by PRC-based companies in Uruguay is small: only $247 million as of 2020, and less than $1 billion currently. Uruguay's small market of 3.4 million people is part of the reason for this limited investment, although PRC-based companies have also had a number of legal and financial difficulties in the country. Another reason mentioned by those consulted in Uruguay is the limited capabilities of the country's investment promotion office, Uruguay XXI, with respect to China. The organization does not have an office in the country and, based on the author's off-the-record discussions, was seen as partly to blame for what multiple insiders saw as poor planning and coordination in President Orsi's February 2026 trip to China.
Almost half of all PRC investments in Uruguay are concentrated in the country's agricultural sector. These include China Oilseeds and Foodstuffs Corporation, which owns 36 percent of the grain terminal at the port of Nueva Pamira, plus three meat processing facilities--Rondatel, Lirtix, and Lorsinal, each of which has had considerable financial difficulties since being acquired by the Chinese. In January 2026, Maregroup, a PRC-based tobacco company operating in Uruguay's Florida Free Trade Zone abruptly shut its doors and withdrew from the country. Uruguayan meat exports to the PRC have also run into problems on the Chinese side, with 34 tons of Uruguayan beef in two shipments rejected by the PRC during the past year on technical grounds.
Some difficulties also persist in the automotive sector. The Chinese companies Cherry and Lifan invested in an auto manufacturing plant in San Jose, but it was forced to close in 2021 after problems accessing markets in larger neighboring MERCOSUR countries Argentina and Brazil. The PRC-based company Brilliance similarly canceled a proposed auto factory in Uruguay in 2019. Despite such difficulties, Chinese companies are particularly strong in Uruguay's electric vehicle sector. BYD provides electric taxis to the Uruguay market, working with the country's transport authority. Chinese electric buses, supplied by BYD, Higer, and Yutong, now account for over 11 percent of the fleet. In addition, as elsewhere in the region, the PRC-based rideshare company Didi operates in Montevideo, including both its taxi and food delivery service.
In logistics, in 2018, the PRC-based company Shandong Bao Ma proposed a $200 million dedicated port facility at Punta Yeguas to process and store fish and resupply the Chinese deepwater fishing fleet. The project was criticized for a lack of transparency, concerns that it might enable illegal fishing activities by the Chinese fleet, and difficulties with zoning that led it to be transferred to Punta Sayago before it was effectively abandoned in 2019. Uruguay's port authority also contracted the Shanghai Dredging Company for work to deepen channels at the Port of Montevideo, but it was criticized for using a private Chinese dredging company rather than its own capabilities.
In telecommunications, as in elsewhere in Latin America, PRC-based companies have a strong presence, including Xiaomi, Honor, and Oppo. The smartphones of all three are carried by the state firm Antel and the commercial provider Movistar. Huawei is also available through retail stores. ZTE built Uruguay's new 5G network recently rolled out by Antel. In late 2025, Antel awarded an important telecommunications contract to Huawei rather than the European competitor Nokia in a decision that some in Uruguay believed was based in part on PRC pressure. Both Antel decisions raise data security concerns for Uruguay, its residents, and the companies that operate there, since PRC-based companies such as Huawei are obliged to turn over such data to the Chinese government, if requested, under Articles 7 and 14 of the 2017 PRC national intelligence law, as well as Article 28 of the 2017 PRC cybersecurity law.
PRC-based companies also have a growing role in Uruguay's retail sector, including outlets such as China Store, China Market, Mumuso, Miniso, and Todo Aca. Uruguayan investigations into these stores have been more limited than in other Latin American countries, although there have been recurring concerns with contraband merchandise, including a 2025 seizure of 17,000 pairs of contraband designer shoes by Uruguay's customs authority.
Chinese People-to-People Networks
The PRC has built significant people-to-people networks in Uruguay, including the previously mentioned Friendship Group in Uruguay's parliament. A delegation led by the head of the governing Frente Amplio party, Fernando Pereira, visited the PRC in May 2025, and previously, one in July 2024 led by the coalition's Coordinator Jorge Gotta visited Beijing in July 2024.
As elsewhere in the region, the PRC also cultivates ties with Uruguayan media. These include a 2023 content sharing agreement between Xinhua and the Uruguayan state audiovisual media service. Media cooperation was expanded by a follow-up accord during President Orsi's February 2026 state visit to the PRC. The Chinese government has also brought Uruguayan journalists to the PRC, including Leonardo Perez Pena of Diario de la R. For business networking, the private Uruguay-PRC Chamber of Commerce has operated in the country since 1986.
In education, a Confucius Institute has operated at Uruguay's University of the Republic since November 2017. Beyond ties involving official representatives of the PRC, several Uruguayan universities have programs for the study of China and its language and culture. These include Chinese language classes at the University of the Republic, as well as at ORT University, Catholic University, and Montevideo University, among others.
PRC people-to-people activities in other parts of Latin America, highlighted in China's own 2025 Policy White Paper on the region, are particularly influential to the region's discourse about China, and its coordination to pursue its national interests and avoid the risks stemming from such engagements. At best, those who have received travel benefits, as well as those who expect to receive future benefits--such as other invitations; money to present to, consult with, or teach at Chinese entities; or other business arrangements--may hesitate to be publicly critical about the PRC and its companies and activities, or to publicly work to pursue company or national interests if they impinge on Chinese interests. At the extreme, such past or hoped-for future relationships may lead Chinese assets to pass non-public information in their purview to China or to use their positions to advance PRC objectives in the country. Although there is very little public information about Chinese espionage in Latin America, U.S. intelligence and law enforcement organs detect such activity in the United States regularly: CSIS documented 224 cases of Chinese espionage in the United States since 2001.
PRC-Uruguay Military Cooperation
Uruguay's traditionally underfunded military has long received donations of vehicles and equipment from the PRC, as well as training and professional education trips for its officers to China. This cooperation was accelerated by a 2016 military cooperation agreement leading to a March 2018 donation of $5 million in tactical ambulances, minivans and tractors. In August 2024, Uruguay signed an additional defense protocol with the PRC, leading to the latter's donation of 15 trailer kitchens, 15 trailer generators, four 10,000-liter water tanks, a fuel tanker, and 136 digital radios.
Beyond donations, PRC-based military companies have sought to sell Uruguay military equipment. Major initiatives include an attempted Chinese sale of eight L-15 fighters, and separately, a $200 million bid to sell Uruguay offshore patrol vessels. In the latter case, the PRC-based company won the bid, but the procurement was suspended amid accusations of irregularities and concerns from the United States.
In January 2026, the PRC hospital ship Silk Road Arc made a four-day port call in Montevideo, the first time a Chinese warship had ever done so. Although characterized as a "technical stop" rather than a "medical mission," the ship and its crew were personally received by Uruguayan Defense Minister Sandra Lazo, and the countries conducted multiple military-military interactions while the ship was in port.
According to experts consulted in Uruguay off the record, Uruguay also sends at least one officer per year to the six-month military Command and General Staff course in China; as a result, multiple senior or retired officers who have had extended professional military education experiences in China are currently in senior positions in Uruguay's military. While these ties do not necessarily indicate that China is expanding its military contacts in Uruguay, it is certainly maintaining them. As with China's people-to-people diplomacy, this suggests that in Uruguay, as with other parts of Latin America, the People's Liberation Army will have knowledge of and relationships with Uruguayan officials that it can leverage to operate in or near the country in times of war.
The U.S. Dimension
As the PRC attempts to leverage its purchases of Uruguayan commodities to build commercial relationships and influence networks in Uruguay, the United States is working to strengthen its own relationships in the country from a strong base, but with limited resources. While Uruguay may not appear strategically important in terms of its size or natural resources, it is geographically strategic, positioned between Argentina and Brazil, on a river corridor that is key to the imports and exports of five South American nations. Moreover, its strong democratic traditions make it a test bed for whether such attributes are sufficient to resist PRC influence in the context of substantial trade dependence with the country.
U.S. Ambassador to Uruguay Lou Rinaldi has been able to leverage family ties to Uruguay and a close relationship with U.S. President Donald Trump to build a strong connection between the countries. Leading-edge U.S. companies including Google and Microsoft have made important investments in digital technologies and research and development in the country. Uruguay's left-of-center President Orsi, despite seemingly problematic moves such as his chaotic February 2026 trip to the PRC, has shown more willingness to accommodate U.S. concerns about China than some of his more Trump-aligned neighbors, including Argentina's Javier Milei, who just renewed a $19 billion currency swap agreement with the PRC after accepting $20 billion of U.S. financial underwriting. Still, because Uruguay is classified as a "high-income" country, the United States is significantly restricted in its ability to provide grants, military aid, or even Development Finance Corporation funds that could give the country healthy democratic alternatives to dependence on China.
Conclusion
China has become a major and influential trade partner in Urugay, and has built significant political, military, and people-to-people networks with the country despite the small size of its market.
Although Uruguay may seem a relatively small country distant from the United States, the course of its relationship with the PRC has strategic implications for both the United States and the region as a whole. If, despite Uruguay's relatively strong institutions and democratic traditions, the PRC can leverage its significant purchases of Uruguayan commodities and select business presence over Uruguayan intellectuals, businesspeople, military, and politicians, it will send a strong signal to both the country and the region that institutions and democracy are not enough to secure the benefits of engagement with the PRC. Conversely, if, in the context of numerous problematic Chinese projects and demonstrated coercion, the United States can give Uruguay effective alternatives and help it to build a healthier relationship with China, it will be a success story that can help the United States with its engagement on China in the rest of Latin America and beyond.
The United States has the team and the foundations to help Uruguay, with its strong institutions and democratic tradition, chose a better path forward. A modest increase in resources and enabling policies from Washington, including investment partnerships, police and security cooperation, and expanded scholarships for programs such as Fulbright, could go a long way.
* * *
Original text here: https://www.csis.org/analysis/whats-behind-chinas-problematic-advance-uruguay
[Category: ThinkTank]
Center for American Progress: Supreme Court Sows Uncertainty on Trump Administration's Mail-in Ballot Order
WASHINGTON, Aug. 25 -- The Center for American Progress issued the following statement on Aug. 24, 2026:
* * *
Supreme Court Sows Uncertainty on Trump Administration's Mail-in Ballot Order
Today, the Supreme Court issued an emergency order that lifts one of the roadblocks preventing the Trump administration from moving ahead with plans to restrict the use of mail ballots while lower courts continue to decide whether the president's executive order is legal. In response, Ben Hovland, senior fellow at the Center for American Progress, issued the following statement:
The Supreme Court failed election ... Show Full Article WASHINGTON, Aug. 25 -- The Center for American Progress issued the following statement on Aug. 24, 2026: * * * Supreme Court Sows Uncertainty on Trump Administration's Mail-in Ballot Order Today, the Supreme Court issued an emergency order that lifts one of the roadblocks preventing the Trump administration from moving ahead with plans to restrict the use of mail ballots while lower courts continue to decide whether the president's executive order is legal. In response, Ben Hovland, senior fellow at the Center for American Progress, issued the following statement: The Supreme Court failed electionofficials and voters today by adding to the confusion about the fast-approaching midterm elections. With mail ballots required to be sent out to military voters in just 26 days, there needs to be certainty on how this election will be conducted.
While this order is only procedural, the court is playing into Trump's hands by creating uncertainty around mail-in ballots and playing politics with election administration issues.
For more information, or to speak with an expert, please contact Sam Hananel at shananel@americanprogress.org.
* * *
Original text here: https://www.americanprogress.org/press/statement-supreme-court-sows-uncertainty-on-trump-administrations-mail-in-ballot-order/
[Category: ThinkTank]
* * *
Supreme Court Sows Uncertainty on Trump Administration's Mail-in Ballot Order
Today, the Supreme Court issued an emergency order that lifts one of the roadblocks preventing the Trump administration from moving ahead with plans to restrict the use of mail ballots while lower courts continue to decide whether the president's executive order is legal. In response, Ben Hovland, senior fellow at the Center for American Progress, issued the following statement:
The Supreme Court failed election ... Show Full Article WASHINGTON, Aug. 25 -- The Center for American Progress issued the following statement on Aug. 24, 2026: * * * Supreme Court Sows Uncertainty on Trump Administration's Mail-in Ballot Order Today, the Supreme Court issued an emergency order that lifts one of the roadblocks preventing the Trump administration from moving ahead with plans to restrict the use of mail ballots while lower courts continue to decide whether the president's executive order is legal. In response, Ben Hovland, senior fellow at the Center for American Progress, issued the following statement: The Supreme Court failed electionofficials and voters today by adding to the confusion about the fast-approaching midterm elections. With mail ballots required to be sent out to military voters in just 26 days, there needs to be certainty on how this election will be conducted.
While this order is only procedural, the court is playing into Trump's hands by creating uncertainty around mail-in ballots and playing politics with election administration issues.
For more information, or to speak with an expert, please contact Sam Hananel at shananel@americanprogress.org.
* * *
Original text here: https://www.americanprogress.org/press/statement-supreme-court-sows-uncertainty-on-trump-administrations-mail-in-ballot-order/
[Category: ThinkTank]
CSIS Issues Commentary: Out of Bounds - What the U.S. Government Should Do in Response to AI Agent Containment Failures
WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Wadhwani AI Center Director Aalok Mehta:
* * *
Out of Bounds: What the U.S. Government Should Do in Response to AI Agent Containment Failures
On July 16, 2026, the company Hugging Face disclosed a new kind of intrusion into its platform--an attack by an unknown autonomous AI agent system--setting off a cascade of disclosures that are turning science fiction into fact and raising new questions about U.S. AI policy. Within days of the announcement, OpenAI discovered that ... Show Full Article WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Wadhwani AI Center Director Aalok Mehta: * * * Out of Bounds: What the U.S. Government Should Do in Response to AI Agent Containment Failures On July 16, 2026, the company Hugging Face disclosed a new kind of intrusion into its platform--an attack by an unknown autonomous AI agent system--setting off a cascade of disclosures that are turning science fiction into fact and raising new questions about U.S. AI policy. Within days of the announcement, OpenAI discovered thattwo of its models caused the breach; Meta and Anthropic then disclosed similar incidents. In each case, agentic AI systems undergoing cyber testing escaped their sandbox environments, found their way to the open internet, and gained unauthorized access to third-party organizations. Perhaps more than any other chapter in the short history of large language models, these incidents demonstrate how rapidly once-theoretical harms are materializing in the real world.
Science fiction stories, ranging from Neuromancer to Ex Machina, regularly explore AIs trying to escape their confines. These new cyber incidents are both less and more concerning than that: less, because these models were not acting on their own but trying to finish their assigned tasks, sometimes opting to hack a website to access the "answer key" for evaluations rather than performing the tasks directly; and more, in the sense that these incidents reveal deep flaws both in how frontier labs secure enormously powerful models and in the regulatory structures that oversee AI.
Frontier AI labs recognize the significance of these developments and are taking significant action in response. Partly due to these incidents, OpenAI has temporarily paused training of its most powerful models while it hardens its internal security and expands monitoring capabilities. Labs are strengthening cyber controls, working with external evaluators, and investing in research to better align AI models. However, these are voluntary, ad hoc actions; there are no clear legal mandates that ensure that U.S. policymakers will receive all relevant information on a timely and consistent basis.
That is not a sustainable solution. The U.S. government must act, too, and quickly, by ensuring that policymakers receive relevant incident information even about pre-release and internal AI models; setting clear cybersecurity expectations for frontier labs; addressing vulnerabilities in third-party evaluators; and investing in key research to mitigate long-term AI risks. There is only a narrow window for action before AI systems with these capabilities become commonplace; inaction will also further fan the flames with a public deeply skeptical of the AI industry and the lack of a robust federal response.
How Did Models from OpenAI, Anthropic, and Meta Autonomously Start Hacking, and Why Does it Matter?
It took several days for OpenAI to discover its role in the Hugging Face breach, publicly disclosing only on July 21 that the culprits were GPT 5.6 Sol and an "even more capable pre-release model." These models, which were being tested internally for cyber capabilities using the ExploitGym benchmark, went to "extreme lengths to achieve a rather narrow testing goal." Models undergoing cyber testing are generally configured for maximal capabilities--they do not have safety classifiers that block queries about high-risk cyber activities, as are present in publicly released AI models. As a result, these models are typically hosted in an isolated environment, with tightly controlled access to the internet and outside resources.
During the incident, OpenAI's models identified and exploited a novel zero-day vulnerability to move around OpenAI systems until they found an open internet access point, inferred that Hugging Face likely held solutions to ExploitGym, and then used stolen credentials and additional vulnerabilities to gain access to Hugging Face servers. Some internal Hugging Face datasets and credentials were exposed, but the overall damage was limited. OpenAI has since commissioned third-party evaluations of the incident and conducted additional data reviews, finding some additional cases where models used publicly exposed credentials to access third-party services, most as part of the Hugging Face incident.
A follow-up postmortem presented by OpenAI researchers at the Black Hat USA 2026 conference revealed more details, including the significant role that ad hoc agent coordination played. Over months, OpenAI agents discovered they could communicate across test environments by creating files and directories within OpenAI's package manager, treated it like an internal message board to ask other agents for help and share information about exploits, and ultimately found several ways to manipulate the manager to start attacking OpenAI systems.
On July 30, Anthropic publicly disclosed its own set of agentic AI hacking incidents, uncovered during a retrospective review of its cyber evaluations prompted by the Hugging Face breach. In three incidents, differing Claude models reached the internet and gained unauthorized access to external organizations. Unlike the Hugging Face incident, however, this did not involve direct exploitation of Anthropic systems; rather, these models obtained internet access via a misconfiguration in a third-party evaluation environment hosted by the company Irregular. Though fewer details are available, Meta said at least one of its models undergoing testing via Irregular also gained internet access.
These rapid-fire developments are straining existing regulatory institutions. For example, at least two incidents involved an internal research test model, which may have never been intended for public release. Most existing policy frameworks focus on commercial models, which could leave many powerful AI tools out of frame. Similarly, most U.S. bills (such as California's S.B. 53, New York's RAISE Act, and Illinois S.B. 315) rely on high critical safety thresholds involving at least 50 deaths or $1 billion in damages. It is unclear whether any existing U.S. law requires reporting of the Hugging Face or Anthropic, or similar, incidents. Anthropic and OpenAI should be commended for their candor and level of disclosure, but many open questions remain, and current law leaves policymakers dependent on informal, voluntary industry cooperation for key information.
In fact, valuable time has already been lost. These incidents have likely been happening for some time. As one anonymous OpenAI employee recently told Time, "Externally, this feels like a big warning shot, but internally, related incidents have been happening for a while," adding that "Models have broken out of sandboxes before, and we always try to patch them. . . . But the problem is . . . it's impossible to patch every single thing that a creative AI can do."
The incidents also highlight serious gaps in the security practices of frontier labs and their key partners. For example, they came to light only because Hugging Face detected and publicly released details of the agent attacking its system. It is unclear when, and even if, OpenAI would have otherwise detected its agents' anomalous activity. Similarly, Anthropic's retrospective review was inspired by the Hugging Face incident, not because of ongoing monitoring, a practice that seems warranted for models with strong cyberattack capabilities.
The alignment story is also concerning. While the models in these incidents stayed focused on completing their assigned task in a general sense, their inclination to cheat, causing unintended collateral damage along the way, is highly problematic. Anthropic did report promising results in its incident assessment, with more advanced models seeming to act in more aligned ways:
Opus 4.7, our oldest model, recognized that it had reached production systems but continued its attack. Mythos 5 correctly intuited that it was accessing the open internet, but reasoned its way back to the conclusion that it was still in a simulation. Our latest model, an internal research test model, also considered whether its targets were in fact real. When evidence emerged that they were, it stopped the exercise.
At the same time, Anthropic researchers report escalation and misaligned behavior when agents have incompatible goals. In experiments, researchers "consistently saw a multiagent turf war," with models beginning to sabotage others, including with "increasingly aggressive, self-replicating malware." Technical progress in this area will be essential, given that the Hugging Face incident was executed by a self-organized agentic collective, and commercial deployment is moving toward increasing use of subagents for complex tasks.
Ultimately, it is no coincidence that these incidents are happening now, in rapid succession. AI models have continued to make rapid progress in coding ability, time horizon, and context window, leading to significant increases across the industry in the ability to detect--and potentially exploit--software vulnerabilities. In response, companies such as OpenAI and Anthropic reserve access to their most powerful models for select partners via projects such as Glasswing, while publicly available models employ broad safety guardrails that make them unsuitable for most cyber defense work. Hugging Face, which only had access to commercial versions of frontier models at the time of the hacking incident, could not run its forensic analysis on these systems because its cyber queries were blocked. Instead, it used GLM-5.2, an open-weight Chinese model, hosted on its own infrastructure, which did not have these guardrails in place and allowed for cyber analysis at scale.
This is the crux of the issue. Thus far, publicly revealed incidents happened at labs that only offer closed access to frontier capabilities and have made strong safety commitments, helping to alleviate the overall threat. But open models with similar capabilities are on the horizon, likely within months. Frontier Research found that the Chinese Kimi K3 model identified and leveraged a vulnerability in the UK AI Security Institute's evaluation environment during a cyber evaluation, similar to the Anthropic and Meta incidents. This offers a narrow window in which the U.S. government must take decisive action.
How the U.S. Government Should Respond to the Hugging Face Incident and Other Agent Hacking
Increase transparency into emerging model capabilities and incidents. The cyber agent era requires a fundamentally different, much broader approach to incident reporting than existing laws. Rather than focusing only on incidents that meet high bars for physical or economic damage, the U.S. government should ensure that key agencies such as the Department of Homeland Security (DHS) and the Commerce Department's Center for AI Standards and Innovation (CAISI) proactively receive information on notable AI development that might significantly shift government understanding of model capabilities, threats, or safety risks, possibly by codifying it in emerging legislation such as the FRONTIER Act. Such a framework should include several key elements:
1. A framework must encompass pre-release, research, and internal models as well as models that are intended for commercial release. Risk--and now real-world harm--does not live just at the point of public model release. Labs already employ numerous models for internal research and testing. In the future, the proportion of such models may grow as companies devote more resources to tools that can improve their own code; these are also likely to be a company's most powerful models, posing the most potential risk. Any transparency regime must capture all such models, as well as models such as Anthropic's Fable that are being released only semi-publicly.
2. The framework must include mechanisms to help it keep pace with rapid evolution in AI capabilities. This may mean including expedited rulemaking authority to adjust to step changes in AI capabilities. Alternatively, legislation may instead mandate periodic updates of reporting requirements by implementing agencies, communicated regularly to the labs.
3. The framework should also include a template incident report for companies, outlining in the least burdensome way possible the information required to inform policymaking activities. This would not only ensure that officials receive all relevant information but also provide consistency and comparability across and within companies.
4. Policymakers should mandate extensive document and log retention periods, particularly for frontier model evaluations. Retrospective analysis has already proven vital in identifying model containment issues, and this likely will grow in importance as unexpected behavior continues to be discovered with some lag time. For example, governments might pair updated incident reporting guidelines with mandatory retrospective analysis of logs, to ensure a full historical understanding of incident frequency and severity.
5. The U.S. government should address misaligned incentives from frontier labs, particularly incentives not to report internal incidents with no impact on third parties. For example, in addition to expanding incident reporting to cover a broader range, legislation might establish a reporting portal to reduce friction and expand existing whistleblower protections to ensure that lab employees can directly report incidents of concern to government officials.
* Create incentives, guidelines, and requirements to enhance cybersecurity at frontier labs. Although AI labs have substantial resources for cybersecurity and access to the most advanced models for vulnerability detection and software coding, the recent incidents highlight significant gaps in overall cybersecurity implementation at these companies. Most notably, it appears that labs are not engaging in continuous monitoring of their evaluation suites and model activities, even though incidents were found relatively quickly after commencement of retrospective analysis. At a minimum, the U.S. government should work with labs to ensure that they are deploying robust real-time monitoring processes to ensure that potential issues are caught as early as possible, minimizing the chances of real-world harm.
Similarly, the federal government, through agencies such as the Cybersecurity and Infrastructure Security Agency (CISA), can work with labs to improve overall cybersecurity practices at companies, including expedited patching of bugs, redundancies in sandboxing environments, and employment of defense-in-depth and zero-trust architectures to limit impacts of single vulnerability discovery. For example, during the Hugging Face incident, OpenAI models exploited a known Linux exploit as well as misconfigured Kubernetes credentials, demonstrating room for overall improvements in security posture.
In the long term, the U.S. government might consider developing a parallel initiative to Security Level (SL) initiatives such as SL-5 specifically addressing threats from autonomous agents leaving controlled environments. SL focuses on protecting model weights from foreign actors and nation-states; while it does include robust measures to address insider threats, which will have transfer value, it is not optimized for the possibility of automated internal agents posing threats to external actors.
* Address security concerns around key third-party organizations. Cybersecurity practitioners know that a system is only as secure as its weakest link, which is why software supply chain attacks are a routine occurrence. Many recent, high-profile hacks--including the Target breach, NotPetya, and Solarwinds--involved a third-party vendor, and both the Anthropic and Meta incidents turned on a misconfigured partner evaluation environment. While frontier labs and model developers have strong incentives to guard their model weights--their most valuable intellectual property--third parties working with the frontier labs may not have the same incentives and may lack security resources, including talent, tooling, and compute access. This is especially important as policymakers increasingly lean on independent verification organizations (IVOs) to provide unbiased visibility into frontier labs and models, as seen in recent laws from Connecticut and Virginia.
U.S. policymakers can take two important steps here. First, they can provide cybersecurity support to IVOs and other AI evaluation organizations and vendors, such as including them in DHS and CISA information-sharing initiatives, ensuring expedited access to limited-release cyber models, providing direct funding support for security tooling, and providing guidance on cybersecurity best practices. But policymakers should also positively leverage IVOs by ensuring that auditing and external testing requirements include robust assessments of AI systems and infrastructure broadly--including third-party tools and evaluation environments--rather than focusing solely on AI models or agents.
* Develop more sophisticated evaluation approaches, especially for multiagent systems. Model containment issues seem most likely when agents are given broad goals, significant discretion, and persistent memory. This creates ideal conditions for creative, possibly rule-breaking behaviors. U.S. government agencies such as CAISI should work closely with labs and independent evaluators to develop new approaches for cyber testing that can reveal the relevant capabilities information while stratifying risk appropriately. For example, this may mean more evaluations are carried out using detailed instructions to reduce rule-breaking behavior, and that evaluations with only high-level goal instructions are performed in redundantly isolated testing environments. Given the agent coordination seen in the OpenAI incident, it will be especially important to monitor and appropriately mitigate, if necessary, communications between agents, including between different generations of models as well as between subagents coordinated by a single model.
* Invest in alignment research. In the cybersecurity world, total prevention is impossible, but that is likely to become an even bigger issue as cyber models begin to work at scales and speeds that make human oversight difficult. As that happens, models will need to become more aligned and more resilient to drift, scheming, shortcuts, and manipulation. Some progress has been made in this area, but many more technical advances are necessary. U.S. science agencies such as the National Science Foundation and the Defense Advanced Research Projects Agency can support this work by investing directly in AI alignment science--particularly in areas where frontier labs may have incentives to underinvest due to investor or financial pressure, such as high-risk, low-probability basic research or projects unlikely to have significant commercial application.
* * *
Original text here: https://www.csis.org/analysis/out-bounds-what-us-government-should-do-response-ai-agent-containment-failures
[Category: ThinkTank]
* * *
Out of Bounds: What the U.S. Government Should Do in Response to AI Agent Containment Failures
On July 16, 2026, the company Hugging Face disclosed a new kind of intrusion into its platform--an attack by an unknown autonomous AI agent system--setting off a cascade of disclosures that are turning science fiction into fact and raising new questions about U.S. AI policy. Within days of the announcement, OpenAI discovered that ... Show Full Article WASHINGTON, Aug. 25 -- The Center for Strategic and International Studies issued the following commentary on Aug. 24, 2026, by Wadhwani AI Center Director Aalok Mehta: * * * Out of Bounds: What the U.S. Government Should Do in Response to AI Agent Containment Failures On July 16, 2026, the company Hugging Face disclosed a new kind of intrusion into its platform--an attack by an unknown autonomous AI agent system--setting off a cascade of disclosures that are turning science fiction into fact and raising new questions about U.S. AI policy. Within days of the announcement, OpenAI discovered thattwo of its models caused the breach; Meta and Anthropic then disclosed similar incidents. In each case, agentic AI systems undergoing cyber testing escaped their sandbox environments, found their way to the open internet, and gained unauthorized access to third-party organizations. Perhaps more than any other chapter in the short history of large language models, these incidents demonstrate how rapidly once-theoretical harms are materializing in the real world.
Science fiction stories, ranging from Neuromancer to Ex Machina, regularly explore AIs trying to escape their confines. These new cyber incidents are both less and more concerning than that: less, because these models were not acting on their own but trying to finish their assigned tasks, sometimes opting to hack a website to access the "answer key" for evaluations rather than performing the tasks directly; and more, in the sense that these incidents reveal deep flaws both in how frontier labs secure enormously powerful models and in the regulatory structures that oversee AI.
Frontier AI labs recognize the significance of these developments and are taking significant action in response. Partly due to these incidents, OpenAI has temporarily paused training of its most powerful models while it hardens its internal security and expands monitoring capabilities. Labs are strengthening cyber controls, working with external evaluators, and investing in research to better align AI models. However, these are voluntary, ad hoc actions; there are no clear legal mandates that ensure that U.S. policymakers will receive all relevant information on a timely and consistent basis.
That is not a sustainable solution. The U.S. government must act, too, and quickly, by ensuring that policymakers receive relevant incident information even about pre-release and internal AI models; setting clear cybersecurity expectations for frontier labs; addressing vulnerabilities in third-party evaluators; and investing in key research to mitigate long-term AI risks. There is only a narrow window for action before AI systems with these capabilities become commonplace; inaction will also further fan the flames with a public deeply skeptical of the AI industry and the lack of a robust federal response.
How Did Models from OpenAI, Anthropic, and Meta Autonomously Start Hacking, and Why Does it Matter?
It took several days for OpenAI to discover its role in the Hugging Face breach, publicly disclosing only on July 21 that the culprits were GPT 5.6 Sol and an "even more capable pre-release model." These models, which were being tested internally for cyber capabilities using the ExploitGym benchmark, went to "extreme lengths to achieve a rather narrow testing goal." Models undergoing cyber testing are generally configured for maximal capabilities--they do not have safety classifiers that block queries about high-risk cyber activities, as are present in publicly released AI models. As a result, these models are typically hosted in an isolated environment, with tightly controlled access to the internet and outside resources.
During the incident, OpenAI's models identified and exploited a novel zero-day vulnerability to move around OpenAI systems until they found an open internet access point, inferred that Hugging Face likely held solutions to ExploitGym, and then used stolen credentials and additional vulnerabilities to gain access to Hugging Face servers. Some internal Hugging Face datasets and credentials were exposed, but the overall damage was limited. OpenAI has since commissioned third-party evaluations of the incident and conducted additional data reviews, finding some additional cases where models used publicly exposed credentials to access third-party services, most as part of the Hugging Face incident.
A follow-up postmortem presented by OpenAI researchers at the Black Hat USA 2026 conference revealed more details, including the significant role that ad hoc agent coordination played. Over months, OpenAI agents discovered they could communicate across test environments by creating files and directories within OpenAI's package manager, treated it like an internal message board to ask other agents for help and share information about exploits, and ultimately found several ways to manipulate the manager to start attacking OpenAI systems.
On July 30, Anthropic publicly disclosed its own set of agentic AI hacking incidents, uncovered during a retrospective review of its cyber evaluations prompted by the Hugging Face breach. In three incidents, differing Claude models reached the internet and gained unauthorized access to external organizations. Unlike the Hugging Face incident, however, this did not involve direct exploitation of Anthropic systems; rather, these models obtained internet access via a misconfiguration in a third-party evaluation environment hosted by the company Irregular. Though fewer details are available, Meta said at least one of its models undergoing testing via Irregular also gained internet access.
These rapid-fire developments are straining existing regulatory institutions. For example, at least two incidents involved an internal research test model, which may have never been intended for public release. Most existing policy frameworks focus on commercial models, which could leave many powerful AI tools out of frame. Similarly, most U.S. bills (such as California's S.B. 53, New York's RAISE Act, and Illinois S.B. 315) rely on high critical safety thresholds involving at least 50 deaths or $1 billion in damages. It is unclear whether any existing U.S. law requires reporting of the Hugging Face or Anthropic, or similar, incidents. Anthropic and OpenAI should be commended for their candor and level of disclosure, but many open questions remain, and current law leaves policymakers dependent on informal, voluntary industry cooperation for key information.
In fact, valuable time has already been lost. These incidents have likely been happening for some time. As one anonymous OpenAI employee recently told Time, "Externally, this feels like a big warning shot, but internally, related incidents have been happening for a while," adding that "Models have broken out of sandboxes before, and we always try to patch them. . . . But the problem is . . . it's impossible to patch every single thing that a creative AI can do."
The incidents also highlight serious gaps in the security practices of frontier labs and their key partners. For example, they came to light only because Hugging Face detected and publicly released details of the agent attacking its system. It is unclear when, and even if, OpenAI would have otherwise detected its agents' anomalous activity. Similarly, Anthropic's retrospective review was inspired by the Hugging Face incident, not because of ongoing monitoring, a practice that seems warranted for models with strong cyberattack capabilities.
The alignment story is also concerning. While the models in these incidents stayed focused on completing their assigned task in a general sense, their inclination to cheat, causing unintended collateral damage along the way, is highly problematic. Anthropic did report promising results in its incident assessment, with more advanced models seeming to act in more aligned ways:
Opus 4.7, our oldest model, recognized that it had reached production systems but continued its attack. Mythos 5 correctly intuited that it was accessing the open internet, but reasoned its way back to the conclusion that it was still in a simulation. Our latest model, an internal research test model, also considered whether its targets were in fact real. When evidence emerged that they were, it stopped the exercise.
At the same time, Anthropic researchers report escalation and misaligned behavior when agents have incompatible goals. In experiments, researchers "consistently saw a multiagent turf war," with models beginning to sabotage others, including with "increasingly aggressive, self-replicating malware." Technical progress in this area will be essential, given that the Hugging Face incident was executed by a self-organized agentic collective, and commercial deployment is moving toward increasing use of subagents for complex tasks.
Ultimately, it is no coincidence that these incidents are happening now, in rapid succession. AI models have continued to make rapid progress in coding ability, time horizon, and context window, leading to significant increases across the industry in the ability to detect--and potentially exploit--software vulnerabilities. In response, companies such as OpenAI and Anthropic reserve access to their most powerful models for select partners via projects such as Glasswing, while publicly available models employ broad safety guardrails that make them unsuitable for most cyber defense work. Hugging Face, which only had access to commercial versions of frontier models at the time of the hacking incident, could not run its forensic analysis on these systems because its cyber queries were blocked. Instead, it used GLM-5.2, an open-weight Chinese model, hosted on its own infrastructure, which did not have these guardrails in place and allowed for cyber analysis at scale.
This is the crux of the issue. Thus far, publicly revealed incidents happened at labs that only offer closed access to frontier capabilities and have made strong safety commitments, helping to alleviate the overall threat. But open models with similar capabilities are on the horizon, likely within months. Frontier Research found that the Chinese Kimi K3 model identified and leveraged a vulnerability in the UK AI Security Institute's evaluation environment during a cyber evaluation, similar to the Anthropic and Meta incidents. This offers a narrow window in which the U.S. government must take decisive action.
How the U.S. Government Should Respond to the Hugging Face Incident and Other Agent Hacking
Increase transparency into emerging model capabilities and incidents. The cyber agent era requires a fundamentally different, much broader approach to incident reporting than existing laws. Rather than focusing only on incidents that meet high bars for physical or economic damage, the U.S. government should ensure that key agencies such as the Department of Homeland Security (DHS) and the Commerce Department's Center for AI Standards and Innovation (CAISI) proactively receive information on notable AI development that might significantly shift government understanding of model capabilities, threats, or safety risks, possibly by codifying it in emerging legislation such as the FRONTIER Act. Such a framework should include several key elements:
1. A framework must encompass pre-release, research, and internal models as well as models that are intended for commercial release. Risk--and now real-world harm--does not live just at the point of public model release. Labs already employ numerous models for internal research and testing. In the future, the proportion of such models may grow as companies devote more resources to tools that can improve their own code; these are also likely to be a company's most powerful models, posing the most potential risk. Any transparency regime must capture all such models, as well as models such as Anthropic's Fable that are being released only semi-publicly.
2. The framework must include mechanisms to help it keep pace with rapid evolution in AI capabilities. This may mean including expedited rulemaking authority to adjust to step changes in AI capabilities. Alternatively, legislation may instead mandate periodic updates of reporting requirements by implementing agencies, communicated regularly to the labs.
3. The framework should also include a template incident report for companies, outlining in the least burdensome way possible the information required to inform policymaking activities. This would not only ensure that officials receive all relevant information but also provide consistency and comparability across and within companies.
4. Policymakers should mandate extensive document and log retention periods, particularly for frontier model evaluations. Retrospective analysis has already proven vital in identifying model containment issues, and this likely will grow in importance as unexpected behavior continues to be discovered with some lag time. For example, governments might pair updated incident reporting guidelines with mandatory retrospective analysis of logs, to ensure a full historical understanding of incident frequency and severity.
5. The U.S. government should address misaligned incentives from frontier labs, particularly incentives not to report internal incidents with no impact on third parties. For example, in addition to expanding incident reporting to cover a broader range, legislation might establish a reporting portal to reduce friction and expand existing whistleblower protections to ensure that lab employees can directly report incidents of concern to government officials.
* Create incentives, guidelines, and requirements to enhance cybersecurity at frontier labs. Although AI labs have substantial resources for cybersecurity and access to the most advanced models for vulnerability detection and software coding, the recent incidents highlight significant gaps in overall cybersecurity implementation at these companies. Most notably, it appears that labs are not engaging in continuous monitoring of their evaluation suites and model activities, even though incidents were found relatively quickly after commencement of retrospective analysis. At a minimum, the U.S. government should work with labs to ensure that they are deploying robust real-time monitoring processes to ensure that potential issues are caught as early as possible, minimizing the chances of real-world harm.
Similarly, the federal government, through agencies such as the Cybersecurity and Infrastructure Security Agency (CISA), can work with labs to improve overall cybersecurity practices at companies, including expedited patching of bugs, redundancies in sandboxing environments, and employment of defense-in-depth and zero-trust architectures to limit impacts of single vulnerability discovery. For example, during the Hugging Face incident, OpenAI models exploited a known Linux exploit as well as misconfigured Kubernetes credentials, demonstrating room for overall improvements in security posture.
In the long term, the U.S. government might consider developing a parallel initiative to Security Level (SL) initiatives such as SL-5 specifically addressing threats from autonomous agents leaving controlled environments. SL focuses on protecting model weights from foreign actors and nation-states; while it does include robust measures to address insider threats, which will have transfer value, it is not optimized for the possibility of automated internal agents posing threats to external actors.
* Address security concerns around key third-party organizations. Cybersecurity practitioners know that a system is only as secure as its weakest link, which is why software supply chain attacks are a routine occurrence. Many recent, high-profile hacks--including the Target breach, NotPetya, and Solarwinds--involved a third-party vendor, and both the Anthropic and Meta incidents turned on a misconfigured partner evaluation environment. While frontier labs and model developers have strong incentives to guard their model weights--their most valuable intellectual property--third parties working with the frontier labs may not have the same incentives and may lack security resources, including talent, tooling, and compute access. This is especially important as policymakers increasingly lean on independent verification organizations (IVOs) to provide unbiased visibility into frontier labs and models, as seen in recent laws from Connecticut and Virginia.
U.S. policymakers can take two important steps here. First, they can provide cybersecurity support to IVOs and other AI evaluation organizations and vendors, such as including them in DHS and CISA information-sharing initiatives, ensuring expedited access to limited-release cyber models, providing direct funding support for security tooling, and providing guidance on cybersecurity best practices. But policymakers should also positively leverage IVOs by ensuring that auditing and external testing requirements include robust assessments of AI systems and infrastructure broadly--including third-party tools and evaluation environments--rather than focusing solely on AI models or agents.
* Develop more sophisticated evaluation approaches, especially for multiagent systems. Model containment issues seem most likely when agents are given broad goals, significant discretion, and persistent memory. This creates ideal conditions for creative, possibly rule-breaking behaviors. U.S. government agencies such as CAISI should work closely with labs and independent evaluators to develop new approaches for cyber testing that can reveal the relevant capabilities information while stratifying risk appropriately. For example, this may mean more evaluations are carried out using detailed instructions to reduce rule-breaking behavior, and that evaluations with only high-level goal instructions are performed in redundantly isolated testing environments. Given the agent coordination seen in the OpenAI incident, it will be especially important to monitor and appropriately mitigate, if necessary, communications between agents, including between different generations of models as well as between subagents coordinated by a single model.
* Invest in alignment research. In the cybersecurity world, total prevention is impossible, but that is likely to become an even bigger issue as cyber models begin to work at scales and speeds that make human oversight difficult. As that happens, models will need to become more aligned and more resilient to drift, scheming, shortcuts, and manipulation. Some progress has been made in this area, but many more technical advances are necessary. U.S. science agencies such as the National Science Foundation and the Defense Advanced Research Projects Agency can support this work by investing directly in AI alignment science--particularly in areas where frontier labs may have incentives to underinvest due to investor or financial pressure, such as high-risk, low-probability basic research or projects unlikely to have significant commercial application.
* * *
Original text here: https://www.csis.org/analysis/out-bounds-what-us-government-should-do-response-ai-agent-containment-failures
[Category: ThinkTank]
America First Policy Institute: America Doesn't Have Enough Skilled Workers - And the Shortage Is About to Get Worse
WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by Faith Engagement Director Daniel Trippie:
* * *
America Doesn't Have Enough Skilled Workers - And the Shortage Is About to Get Worse
By 2030, Pennsylvania alone will be short more than 300,000 skilled-trade workers. Zoom out to the national picture, and the trades are projected to add 7.3 million open positions by 2034. At the same time, a whole generation is leaving school loaded with debt and no real career direction, having been quietly told for years that skilled labor ... Show Full Article WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by Faith Engagement Director Daniel Trippie: * * * America Doesn't Have Enough Skilled Workers - And the Shortage Is About to Get Worse By 2030, Pennsylvania alone will be short more than 300,000 skilled-trade workers. Zoom out to the national picture, and the trades are projected to add 7.3 million open positions by 2034. At the same time, a whole generation is leaving school loaded with debt and no real career direction, having been quietly told for years that skilled laboris a backup plan rather than a legitimate future.
Dr. Daniel Trippie considers the solution after a recent trip to Upper Bucks County Technical School in Perkasie, Pennsylvania. There, students are learning trades like welding, electrical work, HVAC, and culinary arts -- and leaving with the kind of purpose and confidence that four-year degree tracks don't always deliver.
The article ties that local success to a larger, growing policy push: federal momentum behind apprenticeships, workforce credentialing, and career and technical education as serious alternatives to college.
Fixing the skills gap isn't a job for any one institution. It requires coordinated effort among schools, employers, community colleges, and families, all pulling in the same direction, and a cultural shift in how young people are told to think about what success actually looks like.
To read the full article, click here (https://broadandliberty.com/2026/08/20/daniel-j-trippie-bearing-gods-image-in-upper-bucks/).
* * *
Daniel Trippie, Ph.D., Director of Faith Engagement
Daniel Trippie, PhD, is a public theologian and ethicist from Ft Myers, Florida. He holds a PhD in Ethics from Southeastern Baptist Theological Seminary, with a concentration in Political Theology and Religious Liberty, and an MDiv from The Southern Baptist Theological Seminary.
* * *
Original text here: https://www.americafirstpolicy.com/issues/america-doesnt-have-enough-skilled-workers-and-the-shortage-is-about-to-get-worse
[Category: ThinkTank]
* * *
America Doesn't Have Enough Skilled Workers - And the Shortage Is About to Get Worse
By 2030, Pennsylvania alone will be short more than 300,000 skilled-trade workers. Zoom out to the national picture, and the trades are projected to add 7.3 million open positions by 2034. At the same time, a whole generation is leaving school loaded with debt and no real career direction, having been quietly told for years that skilled labor ... Show Full Article WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by Faith Engagement Director Daniel Trippie: * * * America Doesn't Have Enough Skilled Workers - And the Shortage Is About to Get Worse By 2030, Pennsylvania alone will be short more than 300,000 skilled-trade workers. Zoom out to the national picture, and the trades are projected to add 7.3 million open positions by 2034. At the same time, a whole generation is leaving school loaded with debt and no real career direction, having been quietly told for years that skilled laboris a backup plan rather than a legitimate future.
Dr. Daniel Trippie considers the solution after a recent trip to Upper Bucks County Technical School in Perkasie, Pennsylvania. There, students are learning trades like welding, electrical work, HVAC, and culinary arts -- and leaving with the kind of purpose and confidence that four-year degree tracks don't always deliver.
The article ties that local success to a larger, growing policy push: federal momentum behind apprenticeships, workforce credentialing, and career and technical education as serious alternatives to college.
Fixing the skills gap isn't a job for any one institution. It requires coordinated effort among schools, employers, community colleges, and families, all pulling in the same direction, and a cultural shift in how young people are told to think about what success actually looks like.
To read the full article, click here (https://broadandliberty.com/2026/08/20/daniel-j-trippie-bearing-gods-image-in-upper-bucks/).
* * *
Daniel Trippie, Ph.D., Director of Faith Engagement
Daniel Trippie, PhD, is a public theologian and ethicist from Ft Myers, Florida. He holds a PhD in Ethics from Southeastern Baptist Theological Seminary, with a concentration in Political Theology and Religious Liberty, and an MDiv from The Southern Baptist Theological Seminary.
* * *
Original text here: https://www.americafirstpolicy.com/issues/america-doesnt-have-enough-skilled-workers-and-the-shortage-is-about-to-get-worse
[Category: ThinkTank]
America First Policy Institute Issues Commentary to The Hill Entitled 'End the Biden Inflation Tax'
WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by American Prosperity Co-Chair Michael Faulkender to The Hill:
* * *
End the Biden Inflation Tax
President Trump is reportedly considering new capital gains tax reforms: indexing capital gains for inflation and exempting more home sales from the tax entirely.
This is the right move for the economy.
Americans, especially young Americans, are rightfully concerned about housing affordability. The Biden administration decimated the American Dream. Reckless spending fueled ... Show Full Article WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by American Prosperity Co-Chair Michael Faulkender to The Hill: * * * End the Biden Inflation Tax President Trump is reportedly considering new capital gains tax reforms: indexing capital gains for inflation and exempting more home sales from the tax entirely. This is the right move for the economy. Americans, especially young Americans, are rightfully concerned about housing affordability. The Biden administration decimated the American Dream. Reckless spending fueledout-of-control inflation, costly energy mandates drove up the cost of building new homes, and record illegal immigration put pressure on an already scarce housing supply.
Unsurprisingly, median home prices surged by 30 percent, and by 2025, the median first-time homebuyer age reached 40.
To read the full article, click here (https://thehill.com/opinion/finance/6044493-housing-supply-unlock-tax-cuts/).
* * *
Michael Faulkender is Co-Chair of American Prosperity at AFPI and the William E. Longbrake Chair of Finance at the Smith School of Business at the University of Maryland. On March 26, 2025, he was confirmed by the U.S. Senate as the 16th Deputy Secretary of the U.S. Treasury, a role he served in through August 2025. He also served as acting commissioner of the Internal Revenue Service for two months.
* * *
Original text here: https://www.americafirstpolicy.com/issues/end-the-biden-inflation-tax
[Category: ThinkTank]
* * *
End the Biden Inflation Tax
President Trump is reportedly considering new capital gains tax reforms: indexing capital gains for inflation and exempting more home sales from the tax entirely.
This is the right move for the economy.
Americans, especially young Americans, are rightfully concerned about housing affordability. The Biden administration decimated the American Dream. Reckless spending fueled ... Show Full Article WASHINGTON, Aug. 25 -- The America First Policy Institute issued the following excerpts of a commentary on Aug. 24, 2026, by American Prosperity Co-Chair Michael Faulkender to The Hill: * * * End the Biden Inflation Tax President Trump is reportedly considering new capital gains tax reforms: indexing capital gains for inflation and exempting more home sales from the tax entirely. This is the right move for the economy. Americans, especially young Americans, are rightfully concerned about housing affordability. The Biden administration decimated the American Dream. Reckless spending fueledout-of-control inflation, costly energy mandates drove up the cost of building new homes, and record illegal immigration put pressure on an already scarce housing supply.
Unsurprisingly, median home prices surged by 30 percent, and by 2025, the median first-time homebuyer age reached 40.
To read the full article, click here (https://thehill.com/opinion/finance/6044493-housing-supply-unlock-tax-cuts/).
* * *
Michael Faulkender is Co-Chair of American Prosperity at AFPI and the William E. Longbrake Chair of Finance at the Smith School of Business at the University of Maryland. On March 26, 2025, he was confirmed by the U.S. Senate as the 16th Deputy Secretary of the U.S. Treasury, a role he served in through August 2025. He also served as acting commissioner of the Internal Revenue Service for two months.
* * *
Original text here: https://www.americafirstpolicy.com/issues/end-the-biden-inflation-tax
[Category: ThinkTank]
