A humanoid robot head with a black faceplate, lit with blue and orange accent lights, sitting in a dimly lit industrial space
Photo via Unsplash

TL;DR: On June 4, 2026, EFF Senior Policy Analyst Dr. Matthew Guariglia told the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection that the federal government is racing to deploy generative AI for national security and cybersecurity work without the constitutional guardrails that should come first. He warned that pairing AI with the existing mass surveillance infrastructure (open-source intelligence, the commercial data broker market, and Section 702 of FISA) would let agencies infer intimate details about Americans (political beliefs, religion, medical conditions, sexual activity) without a warrant and without any meaningful way for the public to challenge the resulting decisions. EFF’s two legislative asks: pass the Fourth Amendment Is Not For Sale Act and put a warrant requirement on FBI searches of Section 702 data.[1][2]

What Happened at the Hearing

The Subcommittee convened on June 4, 2026 for a hearing titled The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience.[3] The full video runs 1 hour and 45 minutes on the House Homeland Security Committee’s YouTube channel.[3] Dr. Guariglia, who holds a Ph.D in history and works on EFF’s surveillance and police technology portfolio, was one of the witnesses.

The subcommittee sits inside the House Committee on Homeland Security, which has jurisdiction over federal cybersecurity, critical infrastructure protection, and the Department of Homeland Security. Ranking Member Delia Ramirez (D-IL) used her question time to press the framing that ended up being the most quotable line of the day. Dr. Guariglia agreed, verbatim: “At this level the question is not how do we rein in AI, it’s how do we rein in the agencies that would unleash AI on the American public.” [1]

The hearing’s nominal subject was cybersecurity. The fight that played out underneath that subject was about whether Congress is going to write the rules for federal AI use before federal agencies write them by themselves.

The Two Problems With Government AI

Dr. Guariglia’s prepared testimony, which EFF published as a 12-page statement, builds the case around two distinct problems.[2] They are not the same problem and they are not solved by the same fix.

Problem 1: AI supercharges surveillance capacity. Before there was a smartphone in every pocket, mass surveillance of an entire population was expensive, slow, and not really scalable. The old NSA problem was figuring out which of 330 million Americans was worth the analyst hours. AI collapses that cost. As Dr. Guariglia put it in the written statement, an LLM can already infer that someone is a regular at a particular mosque by looking at the website visits, the social media engagement, and the cell phone location pings during Friday prayers, all without a warrant and without any flag that would let a court review it.[2]

That isn’t a hypothetical. It is the design intent of the data broker market, which the Office of the Director of National Intelligence has built into a “streamlined marketplace” for the Intelligence Community to buy Americans’ location, identity, and device data without going near a FISA Court.[2] The Fourth Amendment does not currently constrain that purchase, which is exactly the gap the Fourth Amendment Is Not For Sale Act was written to close. The bill passed the House in 2024 on a 219-199 vote and has been waiting on Senate action ever since.[4]

Problem 2: Government secrecy hides AI mistakes. AI is wrong in public sometimes, in ways that get noticed and reported. AI used by the federal government for national security work is wrong in private, in ways that may never surface. The public found out in May 2025 that the Department of Homeland Security used an AI-assisted process that sent ICE recruits to the field without proper training. Dr. Guariglia cited that incident in his opening remarks: “AI also has a track record of getting things wrong, from false citations on legal briefs to a major AI mistake that sent DHS recruits to the field without proper training. There are likely more consequential examples that we do not even know about because of classification that would prevent a more thorough accounting.” [1][2]

Real-time crime centers are the version of the same problem at the local level. A Boston University Law Review paper by Professor Andrew Guthrie Ferguson documents how AI-enhanced platforms that fuse hundreds of data sources in real time are being used by police departments to make operational decisions with no human-readable audit trail.[5] The federal version of that, fed by signals intelligence collected under Section 702 of FISA, would be the same pattern at vastly larger scale.[2]

What EFF Wants Congress to Do

EFF’s written statement is direct about the political moment. The argument is that the tech industry itself is asking for guardrails, and the Pentagon is asking Congress to let it ignore them, so Congress has to pick a side. As the statement puts it: “When the tech companies themselves are trying to insist on guardrails that the military is trying to override, it is up to Congress to step in and provide necessary and balanced regulations.” [2]

Three specific asks, in order of how much EFF emphasized them in the testimony:

  • Pass the Fourth Amendment Is Not For Sale Act. The bill would prohibit the federal government from buying personal data from commercial brokers when it would otherwise need a warrant to collect the same data. EFF frames this as the most immediate reform available, because the ODNI’s data broker marketplace is already a going concern.[2][4]
  • Reform Section 702 of FISA with a warrant requirement. The FBI currently runs thousands of warrantless queries of Section 702-acquired data looking for information about U.S. persons. EFF’s position is that a warrant requirement is the only structural fix for the backdoor-search problem, and that AI supercharges the problem because the FBI would no longer need a keyword to find a person in the haystack. (Note: Section 702 hit its statutory sunset at midnight on June 12, 2026, eight days after this testimony, and is currently in the lapsed-but-collecting-against-March-2027-certifications situation covered in our day-of post-mortem.)
  • Statutory transparency framework for classified information. EFF argues that Congress needs to write a law that restores checks and balances to executive classification, so that the legislative branch can actually oversee what the executive branch is doing with AI. The current system, in EFF’s view, lets any administration withhold information Congress needs to exercise its constitutional prerogatives.[2]

The Cybersecurity Counterpoint: Vulnerability Hoarding

The most interesting section of the testimony is the one the headline writers skipped. Dr. Guariglia made a cybersecurity argument that runs against the standard intelligence-community instinct to hoard bugs.

The National Security Agency used to develop exploits, sit on them, and wait for adversaries to walk into the trap. Two of those exploits, EternalBlue and EpMe (short for “EpMenu,” a tool that targeted Jian), eventually leaked. The first was used in the 2017 WannaCry and NotPetya attacks. The second was hijacked by Chinese state hackers in 2014 and used against American targets for years before the breach was even discovered.[6][7] The Wired story on the EpMe hijack is the canonical version of the lesson: when an agency hoards a vulnerability, it eventually loses control of it.

AI changes the math. Modern AI vulnerability research is dramatically cheaper than the human version. A vulnerability is an observable fact, so the same bug will be found by multiple parties, and the time between a vulnerability’s discovery and its independent rediscovery is collapsing. Dr. Guariglia’s argument is that AI vulnerability research should be disclosure-first, not hoarding-first, because the marginal value of hoarding is now close to zero and the marginal cost of weaponization is now high.[2]

He also pushes for the U.S. government to invest heavily in memory-safe software for critical infrastructure. At least 65 percent of the security vulnerabilities in shipped software come from the lack of memory safety in the underlying programming language. The two languages that built the modern computing stack, C and C++, do not have memory safety and do not have a credible path to adding it.[2][8] In a world where AI makes finding the bugs cheap, the best defense is to ship fewer bugs in the first place.

The Anthropic Pentagon Piece

There is one line in the testimony that connects this hearing to the Anthropic Fable 5 story we covered on June 12, and it is worth pulling out separately.

Dr. Guariglia’s footnote 1 points to an EFF post from October 2025 titled The Department of Defense Wants Less Proof its Software Works, in which EFF described the Pentagon pressuring Anthropic to make its technology available for use for all purposes, “including those it was not designed for, like mass surveillance of Americans.” [9][10] The June 4 testimony uses that episode to argue that the AI industry’s own guardrails are now under active pressure from the Defense Department, and that Congress needs to decide whether the Pentagon is allowed to keep the override on. As of June 4, 2026, the answer is: nobody has stopped them yet.

What This Means for the Public

Most readers will never read a 12-page congressional testimony, so here is the version that matters for people who do not work in national security.

The U.S. government is the world’s single largest buyer of personal data on Americans, and it is about to start running AI across that data. The agency that buys the data, ODNI, has built a streamlined marketplace for it. The legal framework that constrains the buy, the Fourth Amendment, does not currently apply to commercial purchases. The legislative fix, the Fourth Amendment Is Not For Sale Act, has been waiting on Senate action since April 2024.

The House Homeland Security Subcommittee is one of the venues that will eventually decide whether that fix moves. Dr. Guariglia’s June 4 testimony is now the public record of EFF’s position. If the subcommittee moves toward a bill, that bill is what the Senate is going to see first.

What You Can Do

Watch the Full Hearing

The 1 hour 45 minute video is on the House Homeland Security Committee’s YouTube channel. The witness questions are the part to watch, not the opening statements.

Call Your Senators on the Fourth Amendment Is Not For Sale Act

The bill is the most concrete lever in EFF’s testimony. If you live in a state with a senator on the Judiciary Committee or the Intelligence Committee, that office is the one to call.

Read the EFF Statement

The 12-page written statement is the cleanest version of the argument. It includes every citation the oral testimony used, with links.

Audit Your Own Data Broker Exposure

The ODNI data broker marketplace buys the same data brokers sell to advertisers. Pulling out of the data broker market at the personal level (Privacy Act requests, opt-outs from people-finder sites) cuts off the supply chain the Intelligence Community is buying from.

Sources

  1. Electronic Frontier Foundation, EFF Testifies to Congress on Protecting Americans’ Rights from Government AI, Deeplinks Blog, June 4, 2026, https://www.eff.org/deeplinks/2026/06/eff-testifies-congress-protecting-americans-rights-government-ai
  2. Matthew Guariglia, Ph.D, Statement of Matthew Guariglia, Ph.D, Senior Policy Analyst, Electronic Frontier Foundation, House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, June 4, 2026, https://www.eff.org/files/2026/06/04/statement_of_matthew_guariglia_ph.d_eff_2026.06.04.pdf
  3. House Committee on Homeland Security, The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience, Subcommittee on Cybersecurity and Infrastructure Protection hearing video, June 4, 2026, https://www.youtube.com/watch?v=5K_0etAPDxA
  4. Fourth Amendment Is Not For Sale Act, H.R. 4639, 118th Congress, https://www.congress.gov/bill/118th-congress/house-bill-4639
  5. Andrew Guthrie Ferguson, Real-Time Crime Centers and The Brady Puzzle, Boston University Law Review (forthcoming 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6468120
  6. Wikipedia contributors, EternalBlue, Wikipedia, last accessed June 1, 2026, https://en.wikipedia.org/wiki/EternalBlue
  7. Andy Greenberg, China Hijacked an NSA Hacking Tool in 2014, and Used It for Years, Wired, February 22, 2021, https://www.wired.com/story/china-nsa-hacking-tool-epme-hijack/
  8. Alex Gaynor, What Science Can Tell Us About C and C++ Security, AlexGaynor.net, May 27, 2020, https://alexgaynor.net/2020/may/27/science-on-memory-unsafety-and-security/
  9. Matthew Guariglia, The Department of Defense Wants Less Proof its Software Works, Electronic Frontier Foundation Deeplinks, October 31, 2025, https://www.eff.org/deeplinks/2025/10/department-defense-wants-less-proof-its-software-works
  10. White House, National Security Memorandum on Advancing the United States’ Leadership in Artificial Intelligence to Fulfill National Security Objectives; and Fostering the Safety, Security and Trustworthiness of Artificial Intelligence, October 24, 2024, https://www.presidency.ucsb.edu/documents/national-security-memorandum-advancing-the-united-states-leadership-artificial