The FBI wants to use predictive AI for its watchlist. Could it pull in political beliefs?
Also, "Don't Trust, Verify" means more these days
Recent reporting from Reason has identified the FBI’s Threat Screening Center’s (TSC) interest in leveraging “predictive AI capabilities” for its watchlist operations.
For background, the TSC works to share “terrorism-related information across the U.S. government and with other law enforcement agencies” and hosts the federal terrorism watchlist. According to the FBI, only agencies can nominate individuals to be added and no one can solely be added on the basis of race, ethnicity, religion, “beliefs or activities protected by the First Amendment,” or arbitrarily—they must satisfy the reasonable-suspicion standard.
I’ve gone ahead and reviewed the FBI’s Request for Information (RFI) for the TSC’s use of AI. Unsurprisingly, the FBI wishes to leverage AI to better index data with the use of natural language and to receive “actionable guidance where appropriate.” Then the FBI includes “Predictive Modeling Using Enhanced Data with Traceable Lineage,” where AI would be used to “analyze similarity, pattern alignment, and attribute correlation against existing records to predict where additional relevant information may be derived across federated systems.”
You’re probably wondering what this means exactly. So am I.
I have always held a disdain and felt concern for extremist ideologies , but ultimately I am a First Amendment maximalist and support freedom of expression and association. When conduct crosses the line into criminal activity, then those responsible should be subject to the law in accordance with the Constitution. Otherwise, if all an “extremist” does is exercise their right to free speech, then their ideology should be countered by means of debate and winning elections. I believe most Americans I meet feel this way.
What is concerning, however, is when the government leverages political labels as a means to execute national security initiatives, and subsequently, encroach on fundamental freedoms.
Such tactics were especially prevalent during the days of the late, great J. Edgar Hoover, who developed a seemingly political police force known today as the FBI. Under his leadership, political dissidents were identified and treated as national security threats subject to extensive wiretapping and surveillance, warrantless burglaries known as black-bag jobs (FBI has some records archived for you to peruse), and a variety of other morally- and legally-questionable activities. Martin Luther King Jr. is among the best historical examples of a victim of the FBI’s abuse. You get the picture.
Now, back to the recent development.
In the RFI’s introduction, the FBI recognizes the use of TSC in accordance with the National Security Presidential Memorandum (NSPM-7) that came out in 2017. The memo is about information sharing between agencies for national security threat actors.
What’s more interesting is that a second NSPM-7 came out in 2025, focusing on “Countering Domestic Terrorism and Organized Political Violence” in order to investigate and disrupt the networks responsible for the rise in “assassinations and other acts of political violence in the United States.” The memo makes no mention of TSC’s watchlist and the RFI doesn’t reference this specific NSPM-7, but this memo very much applies to the FBI since it is directed at the Attorney General and Department of Justice, assigns responsibilities to the Joint Terrorism Task Force (which is led by the FBI), and imposes requirements on federal law enforcement agencies generally.
For purposes of our investigatory efforts (I know this is a newsletter but this is interesting), it’s important to note that the 2025 memo is directly concerned with left-wing extremism and identifies “anti-Americanism, anti-capitalism, and anti-Christianity” as “[c]ommon threads animating this violent conduct.” So while the RFI does not indicate the use of political beliefs in AI analysis, there’s certainly the possibility that “pattern alignment” and “attribute correlation” may include identifying and treating political beliefs as risk indicators for domestic terrorism. Even if not done so today, the mechanisms would be in place.
Is this a stretch of the imagination? Maybe, but probably not. Afterall, this is what Hoover would have wanted. And it’s good practice to consider the possible second-order effects of all decisions coming out of Washington. It’s this kind of skepticism that protects American values.
That said, if the FBI uses AI to determine who warrants further investigation based on lawful political activity or beliefs, this would be alarming and, ironically, anti-American. Analysis would only be done on existing records, according to the RFI, but these existing records may include left-wing beliefs that are now believed to be a threat to national security and will likely be used to algorithmically determine further action.
“Dangerous” political beliefs definitionally change with the seasons. And although the practice isn’t new, it’s important to remember that what is leveraged against someone today will one day be turned back on you. Frédéric Bastiat discusses this in The Law (a recommended reading).
So while the FBI has not yet gone forward with its use of AI, we would hope that political views do not warrant heightened surveillance or law enforcement action. This kind of approach is indicative of authoritarian regimes, and the United States should not fall victim to such inclinations. Otherwise, our fears would be realized in our effort to destroy them. - Laz
“Don’t Trust, Verify” is one of the foundational principles of Bitcoin. You don’t have to trust a central operator. You don’t have to trust everyone else in the system to act honestly. You can run the software, check the ledger, and verify both the rules and good behavior of others for yourself.
The same principle extends to all open systems. You can verify the software you are running is secure without trusting the author or an auditor, or millions of other people saying “well, it’s worked fine for me.” You can see for yourself. At least, in theory. In practice, however, the level of skill needed for such an evaluation is not something we can expect everyone to have.
The Coldcard hack was a disaster. I feel terribly for the victims. Setting that aside, it has been an instructive example of how security and open source software could work in the post-AI world.
This democratization of verification lowers the cost of questioning the software we trust for everything. Expertise is still preferred, but it does make expert-ish scrutiny more widely available than it used to be. By the way, thus far only open-weight models have given people this power. Closed models trigger safety lockouts when a user tries anything that looks like hacking, even if it’s for good reason.
Of course, that only applies if the code is open in the first place. Closed software still asks you to trust the vendor. Open software gives the public something to inspect.
I’ll admit, in the past I thought the naysayers had a bit of a gotcha when they pointed out it was impossible for a nontechnical person to truly be trustless while still being reliant on experts. Now I’m not so sure. - Neeraj
What else we’re reading
No one is sure how liability works for agentic hacking: The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
This essay lays out the tactical reasons why a company may want to support OSS rather than the goodness of their hearts: “Why Are Capitalists Giving Away Free Software?”
How rogue officers turned a nationwide camera network into a tool for stalking – “Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found.”
Thank you for taking the time to read this far. We want to improve this newsletter. Please share any feedback you may have.














