Home

Donate
Perspective

AI Didn't Create the Election Infrastructure Problem. It Just Made It Urgent.

Moira Whelan / Aug 7, 2026
Republish

Last week, US water infrastructure was hit by a cyber attack from a malicious actor. Last month, an OpenAI agent broke out of a sandboxed testing environment and hacked Hugging Face, among others. Researchers and trust and security experts called it a warning shot. And a July report suggested European leaders anticipating potential attacks on elections coming from the United States. All of these developments put together tell us one thing: cyberattacks on elections are only a matter of when, not if.

Ever since communities around the world have started using computer programs to generate voter rolls, machines to tally votes, and websites to publicize results, experts have feared interference that would undermine trust. They have been proven correct in many cases, such as the recently revealed hack on UK elections and India’s report of almost 70 cyberattacks on its national elections. The private sector itself has reported significant attacks on elections, as well as political parties and candidates. Despite these warning signs, conversation about protecting elections is dominated by concerns about information integrity, disinformation campaigns, and deepfakes. These issues matter too. But they have absorbed most of the attention and most of the funding, while a more basic vulnerability — the technical fragility of the infrastructure elections actually run on — has gone comparatively under-resourced. Now experts are warning that AI only makes it worse.

In April 2026, Anthropic disclosed a model, Claude Mythos Preview, reportedly capable of finding and exploiting software vulnerabilities more effectively than all but the most skilled human hackers. The company chose not to release it publicly, citing the damage a wide release could enable. Instead, it launched Project Glasswing, giving roughly fifty organizations — including Amazon Web Services, Apple, Cisco, Google, JPMorgan Chase, Microsoft, and Nvidia — early access to find and patch vulnerabilities in software. That a leading AI lab judged this capability serious enough to withhold from general release was like a warning light. The more recent Hugging Face incident made it a blinking red alarm.The threat is no longer only that a malicious actor deliberately targets an election system; it's that election-adjacent infrastructure could be damaged or exposed by an AI system pursuing an unrelated goal that simply happened to be in its path.

No election management body or election technology vendor was invited to be part of Project Glasswing. Anthropic hasn't explained the omission, but the answer is obvious: elections aren't where the customers, liability, or revenue sit for a company deciding where to point a defensive resource like this, even though elections are central to the democratic systems that let these companies thrive. Nobody decided elections didn't matter; the issue simply was never going to land on a commercial roadmap on its own.

On top of that, who exactly were technology companies going to call if they did want to concern themselves with elections? Election management bodies are generally poorly positioned to address technology risks. Most operate with little or no dedicated cybersecurity budget or staff, leaning on other bureaucratic entities with competing priorities. Meanwhile, the cybersecurity industry effectively owns the threat signals they need to see, but election authorities have no standing channel into that knowledge. Engagement, when it happens, is ad hoc and election-by-election, usually concentrated in wealthier markets. Procurement rules compound the problem: even where officials and technologists want frank conversations about specific risks, the rules of engagement often prevent them from saying much.

Europe has started to take this seriously. The European Parliament's Special Committee on the European Democracy Shield has adopted a draft report that explicitly calls for electoral infrastructure to be designated as critical infrastructure, including through a revision of the EU's Resilience of Critical Entities Directive. That is a meaningful step: critical infrastructure status typically unlocks financial support, regulatory oversight, and coordinated response planning that election systems currently lack almost everywhere. The report is scheduled to go to a full plenary vote this fall. It will not, by itself, be binding on member states or the Commission, but it is a rare instance of a legislative body naming the structural problem out loud.

This is not a problem unique to Europe, and certainly Europe can’t solve it alone. The same structural gap is showing up wherever elections happen. In South Africa, ahead of the 2026 local government elections, the Independent Electoral Commission has itself flagged the scale of digital protection and cybersecurity risk the vote requires, prompting parliamentary scrutiny of whether the commission's safeguards are adequate. That is precisely the kind of national conversation a European model, done well, could help other countries have earlier and more systematically, rather than each election authority arriving at the same conclusion independently and under pressure. Having the conversation now will also increase trust in elections, rather than keeping it from public view and risking further distrust. Afterall, it is common sense that a malicious actor would want to attack an election, and common knowledge that election technology is overburdened and rarely cutting edge. Elections are a sitting duck for cyber attacks.

What the Democracy Shield report or the South African Election Commission cannot do is solve the trust and access problem between election authorities and the technology companies. Previous efforts, such as the US Cybersecurity and Infrastructure Security Agency (CISA) in the 2020 election and Brazil’s consistent work to address technology in elections, serve as instructive models. That said, companies themselves have stated that they'd prefer a sustainable, neutral, non-commercial model that could reach all election bodies, especially those unable to afford enterprise-grade protection on their own. That requires an intermediary — one that election bodies will actually trust with sensitive information, and one that technology companies will engage with outside the pressure of an active election cycle. Civil society organizations are the most credible candidate for that role. They frequently identify electoral risks earlier than governments or companies do, through frontline monitoring work they already carry out.

As the European Democracy Shield process moves from report to implementation, civil society organizations have been designing this mechanism. The pieces exist in entities such as CaraDem’s mapping and gap analysis, International IDEA and IFES’s CIREN. Election officials convene regularly and have singled out the challenge and technology companies have readily participated. This is not a technical gap, it is an institutional one. The roadmap has been developed. It needs a greenlight and the funding to make it happen.

The threats driving this — whether a deliberate attack on voting infrastructure or an AI agent pursuing a goal that happens to run through it — are not going to wait for the plenary calendar. Europe has an opening now to lead the way for the world, and build the connective tissue between election authorities and the companies that hold the threat data, anchored by the civil society groups that already do this work. The cost of empowering such solutions is low, and certainly less costly than recovering the trust that will be lost in the aftermath of the election cyberattack that we know is coming.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Moira Whelan
Moira Whelan is CaraDem’s Technology Advisor, leading the Technology Hub for Trusted Elections Project. Moira drives initiatives that promote rights-respecting, transparent, and gender-responsive ecosystems to ensure that technology strengthens global security and democratic values. Prior to this, s...

Topics

Related

Analysis
How OpenAI, Google, and Anthropic Plan to Handle the 2026 US MidtermsJune 10, 2026
Perspective
Why Electoral Authorities Need an AI FrameworkNovember 20, 2025