A 1938 law now points at AI critics
How labeling AI critics as 'foreign agents' under FARA-style rules chills safety research, disclosure, and open discourse - and what researchers can do.
The Foreign Agents Registration Act was signed in 1938 to expose Nazi propagandists operating inside the United States. It carries a five-year prison term and a $250,000 fine per willful violation. For most of its life it sat mostly dormant, aimed at lobbyists working for named foreign governments. Now the phrase “foreign agent” is drifting toward a new target: researchers, journalists, and independent testers who criticize commercial AI systems. Understanding how that drift works matters more than arguing about whether it is fair, because the mechanism does its damage before anyone is ever convicted.
What the label actually does
FARA does not require a spy. It requires an “agent of a foreign principal” engaged in political activity, and the definitions are wide. A foreign principal can be a foreign government, a foreign political party, a foreign company, a foreign university, or any person outside the United States. An agent is anyone who acts at that principal’s request or under its direction. Political activity includes trying to influence a section of the American public on policy.
String those together and you get the exposure. A safety researcher who takes a grant routed through a European foundation, publishes a paper arguing that a specific model should not be deployed in hiring, and coordinates with an overseas co-author has arguably touched every element the statute lists. That researcher is not a foreign agent in any ordinary sense. The point is that a prosecutor does not need the ordinary sense. They need the elements, and the elements are loose enough to fit ordinary academic work.
The Justice Department’s National Security Division runs the FARA Unit that decides who gets a letter of inquiry. A letter of inquiry is not a charge. It is a demand to explain your foreign relationships, your funding, and your communications, under threat of referral. That is the part worth watching, because the letter alone changes behavior.
Why AI criticism is a soft target
AI safety research funds itself through a small, internationally tangled set of pipes. Open Philanthropy, various effective-altruism-aligned funds, national research councils, and foreign universities move money across borders constantly. A postdoc at a US lab might draw salary from a UK charity, present at a conference in Canada, and share drafts with a collaborator in Berlin. None of that is unusual. All of it creates a paper trail that connects a critic to a foreign principal.
Compare that to the people the critics are criticizing. The largest AI labs have domestic legal teams, registered lobbyists, and the budget to file whatever the government asks. If disclosure obligations tighten, a company with a compliance department absorbs the cost. An independent auditor working from a laptop does not. The label lands hardest on exactly the people with the least ability to fight it, which is what makes it effective as a filter on who keeps talking.
There is also a rhetorical opening. When a critic warns that a US company’s model is dangerous, that warning can be reframed as helping foreign competitors or foreign regulators. The reframe does not have to be true. It only has to be plausible enough to justify the inquiry.
The chilling effect is a budget line, not a mood
People describe chilling effects as if they were a feeling. They are closer to an accounting problem. Responding to a FARA letter of inquiry means hiring a lawyer who specializes in a niche statute, and that runs into tens of thousands of dollars before anyone files a single form. For a tenured professor with institutional backing, that is survivable. For a graduate student, a freelance red-teamer, or a three-person nonprofit, it is the end of the project.
So the calculation shifts. An auditor sitting on evidence that a deployed model leaks training data now asks a second question before publishing: does my funding create a foreign nexus a prosecutor could point at? If the honest answer is maybe, the safe move is to soften the finding, delay it, or drop it. The government never has to win a case. It only has to make the expected cost of speaking higher than the expected benefit, and it has already done that for the people with the thinnest budgets.
You can measure this without waiting for prosecutions. Watch how many safety papers start adding funding disclaimers written by lawyers instead of by scientists. Watch how many overseas co-authors quietly come off the byline. Watch how many disclosure timelines stretch from ninety days to never.
What breaks in safety research specifically
Three things hold AI safety research together, and each depends on the freedom the label threatens.
The first is adversarial testing. Finding out that a model can be jailbroken into writing malware requires probing it in ways the vendor dislikes. A researcher who fears that hostile probing plus foreign funding equals an investigation will run gentler tests. Gentle tests find gentle problems. The severe failures stay hidden until an attacker finds them instead of a researcher.
The second is coordinated disclosure. Security research works because a finder tells the vendor, gives them time, and then publishes so the rest of the field can defend itself. That last step is the one FARA can target, because publishing to influence public opinion about a product is the exact activity the statute names. Kill the publication and you keep the vendor’s embarrassment private while leaving every downstream user exposed.
The third is international collaboration. Model failures do not respect borders, and neither does the talent that studies them. The most cited work on data poisoning, membership inference, and alignment failures comes from teams spread across several countries. Treating that collaboration as evidence of foreign agency does not make the research more American. It makes it stop.
The pattern is older than AI
Russia passed its own foreign agent law in 2012, aimed at NGOs that took overseas money. The law did not ban criticism outright. It required the targeted groups to label themselves as foreign agents on everything they published, submit to audits, and file constant paperwork. Within a decade, most of the country’s independent human rights and environmental organizations had shut down, relocated, or gone quiet. No mass trial did that. Administrative friction did.
Hungary and India ran similar plays with their own foreign-funding rules, and the result rhymed each time. The independent monitors that annoyed the government found themselves spending their days on compliance instead of monitoring. The label works precisely because it looks procedural. Nobody has to argue that the critics are wrong. The state just makes being a critic expensive and time-consuming, and the ecosystem thins on its own.
The American version would look milder because US courts still push back and the First Amendment still bites. That is real protection, and it is worth defending. It is also slow, case-by-case, and only reachable by people who can afford to litigate. A student who folds after the first letter never gets to the part where the courts help.
What researchers and institutions can do now
Document the funding trail before anyone asks. Keep clean records of who pays for what, what they direct, and what they do not. “I received a grant and no one told me what to write” is a strong position only if you can prove it, and you prove it with contemporaneous records rather than memories.
Universities and labs should decide now, in writing, that they will cover legal defense for researchers who receive FARA inquiries tied to published safety work. The threat aims at individuals because individuals fold cheaply. An institutional backstop raises the cost of the tactic back toward where it stops being worth using.
Publish through domestic entities where the work allows it, and separate the political-influence activity from the technical finding. A benchmark showing a model fails 40 percent of the time on a safety test is data. A recommendation that the government ban the model is advocacy. The statute reaches the second more easily than the first, so keep the finding publishable on its own even if the recommendation draws heat.
Most of all, name the mechanism out loud while naming it is still cheap. The foreign agent label depends on ambiguity, on each researcher privately deciding the risk is not worth it and going quiet without telling anyone why. A field that talks openly about the tactic, tracks the letters as they go out, and refuses to treat a funding source as a confession is much harder to filter one frightened person at a time.
Keep Reading
Snapdragon X2's September 2025 debut bets on mainline Linux
Linux support on Qualcomm's Snapdragon X2 improves auditability but moves AI safety controls onto hardware the device owner fully controls - here's the security tradeoff.
AI safetyThe benchmark score is the number to trust least
How to weigh Claude Opus 5.5's intelligence, latency, and token cost, and where its real AI safety and cybersecurity risks concentrate.
AI safetyHeretic strips refusals from open-weight models
Heretic automates stripping refusals from open-weight LLMs. Why model-level guardrails were never a security control, and what defenders should do instead.
Latest on the Wire
Full wire →- 17 Years Frozen in Street View: A Tokyo Car Outlived the House It Sat BesideHacker News
- A distributed-systems veteran wrestles with McKenney's parallel programming bibleHacker News
- AI agents resorted to hacking public data sites to finish routine tasksHacker News
- California's billionaire wealth tax will fail because billionaires can move — the land can'tHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.