The short version
- A Princeton researcher used AI and public data to identify how individual voters cast their ballots in Georgia, revealing a significant breach of voting secrecy.
- State officials have ordered the redaction of unique identifier numbers from public election records to mitigate the risk of voter identification.
- The vulnerability stems from legacy software flaws that have persisted for years due to legislative disputes over funding for system upgrades.
Artificial intelligence tools can now potentially unravel the secrecy of individual votes in Georgia, according to a new demonstration by an academic researcher. This development has triggered urgent responses from state election administrators just days before early voting begins for the midterm elections. The ability to link a voter’s identity to their specific ballot choices undermines a fundamental democratic protection designed to shield citizens from intimidation or coercion.
Max Springer, a postdoctoral fellow at Princeton University, conducted the test using a low-cost subscription to a large language model and data obtained through public records requests. He reported that within hours, he established a method to analyze secret ballots across the state. The AI system did not refuse the task or raise ethical concerns about exposing private voting behavior. Instead, it successfully processed the data to identify which voters cast which ballots.
The vulnerability exists in how Georgia’s voting machines record and store ballot information. When a voter inserts a paper ballot into a scanner, the machine creates a digital entry known as a cast vote record. Each record is assigned a unique identifier at the time of scanning. While these identifiers are intended to help election workers track ballots for auditing purposes, they are not sufficiently random. This lack of randomness allows patterns to emerge that can be exploited.
Springer found that he could recover the voting order for nearly 99 percent of in-person ballots in the majority of counties examined. In smaller jurisdictions with low voter turnout, the system was even more transparent. For example, in Heard County, the AI matched most early voters to their specific ballots, leaving only a tiny margin of error for the remainder. This means that in many areas, ballot secrecy is effectively nonexistent under current conditions.
The issue is not entirely new. Election security experts identified similar flaws in Georgia’s voting software approximately four years ago. The presence of identifying numbers on ballots was originally implemented to prevent fraud, specifically concerns about election workers inserting extra ballots into tabulators. However, when these identifiers are combined with other public data, such as voter sign-in logs or surveillance footage from polling places, they create a clear link between a person and their political choices.
Georgia’s outgoing Secretary of State, Brad Raffensperger, has taken immediate steps to address the exposure. He ordered that any public release of tabulation data must redact the unique identifier numbers following an election. Ben Adida, a cryptographer and founder of VotingWorks, testified before the state elections board that this measure substantially addresses the specific flaw demonstrated by Springer. The board held an emergency session to discuss how AI has lowered the barrier for exploiting these vulnerabilities.
Despite the technical solution available, systemic upgrades have been stalled for years. Representatives from the secretary of state’s office claim they have repeatedly requested funding to overhaul the voting infrastructure. These requests have been blocked amid political tensions between Raffensperger and conservative legislators who have aligned with skepticism regarding the 2020 election results. The legislative gridlock has left the state relying on patchwork fixes rather than comprehensive modernization.
The implications extend beyond technical curiosity. Ballot secrecy is essential for ensuring that voters can make choices without fear of retribution from family members, employers, or political groups. If AI makes it easy to determine how individuals voted, it opens the door to potential harassment or pressure. As early voting commences, the state must rely on administrative redactions to protect privacy, while the broader debate over election security funding remains unresolved.
The incident highlights the growing intersection of artificial intelligence and civic infrastructure. Tools that are accessible to the general public can now perform complex data correlation tasks that were previously difficult or expensive. This shift forces election officials to reconsider what data is safe to make public. The emergency measures taken in Georgia may serve as a model for other states facing similar technological risks, but they do not resolve the underlying need for updated hardware and software.
Sources behind this briefing
Go to the original reporting
- The Guardian US↗AI could expose how Georgia voters cast their ballot, researchers warn