Online Exclusive

How AI Agents Are Empowering Human-Rights Defenders

AI isn’t just a weapon for dictators and tyrants. It can also be a tool for liberty. Human-rights activists are learning how to harness its power and level the playing field for good.

By Alex Gladstein

July 2026

J ust two years ago, AI seemed like an inevitable upgrade for dictators and a downgrade for dissidents. Human-rights activists feared a centralizing technology that would boost state powers of surveillance and social control. Such a trend had been on full display for a decade in China, where the Chinese Communist Party increasingly used big-data analysis, mobile-phone tracking, and hundreds of millions of cameras in public places to create an Orwellian police state beyond the wildest imagination of twentieth-century tyrants.

And while the fear rang true — despots did and will continue to use AI to upgrade their existing systems of repression — what very few understood was that AI could also evolve into a tool for liberty. What follows is the inside story of how the Human Rights Foundation (HRF) saw that potential and began building and deploying freedom-oriented AI agents that can empower dissidents everywhere.

The journey began in 2022, when the first generative AI tools began to scale to millions of people. The earliest versions of chatbots like ChatGPT were primitive, basically glorified offline encyclopedias. But their evolution hinted at what was to come: a massive upgrade of knowledge production, research, and education in the hands of anyone who could access these tools. Initial use cases were limited, and the first apps were entirely corporate and only available to certain people in certain countries. Yet chatbots still became one of the fastest-growing technologies in human history, reaching more than a billion users in less than five years.

Despite their stunning speed of growth, the impact of AI tools for activists remained limited until about eighteen months ago, when “vibe coding” took off. The term describes the ability of an average person with no technical expertise to tell a computer what to do in plain language, and for the computer to execute, moving the need to “program” or “engineer” from human to machine.

The phrase “vibe coding” was first coined by former Tesla AI chief Andrei Karpathy in February 2025, and in the months after, companies such as Replit and Lovable made it possible for anyone to build complex, attractive websites with a few simple commands. These tools had limits, but the eventual outcome was obvious: the rise of software development as a skill for anyone.

The next step in AI becoming a tool of individual rights, and the biggest one yet, came in late January 2026, when OpenClaw went viral. OpenClaw was the world’s first “personal agent” software that broke through to the mainstream. Its open-source design allows anyone to customize how they want to talk to an AI model and choose which AI model they want to talk to. You can think of OpenClaw as the exoskeleton for a brain inside, which could be any AI model, from Claude to ChatGPT to Gemini to DeepSeek. This historic innovation, developed by an Austrian programmer named Peter Steinberger, put control of artificial intelligence into the hands of the user instead of large corporations, where it had lived until that point. Crucially, OpenClaw represented another evolution of the AI tool — from chatbot to coding agent to, now, personal agent: Individuals can now text or speak to an AI capable not only of orchestrating complex tasks and building customized software, but also of learning from its user and developing a personality.

For the dissident, this was the Rubicon moment. This wasn’t logging into ChatGPT and asking it questions about history or the news. It wasn’t logging into a corporate app and asking it to build a website, with a long list of limitations. This was approaching fully sovereign intelligence: a personal AI assistant able to execute tasks as varied as booking travel, running marketing surveys, building financial reports, or contacting people on your behalf — and all the while, getting smarter and smarter and becoming a better and more knowledgeable ally, with a “soul” that you could control, store, and transfer as needed.

This viral OpenClaw moment was also the turning point for HRF’s interest in AI. Until late January 2026, our AI initiative primarily investigated how dictators used AI. We also followed and provided financial support to those trying to build open-source AI tools for activists. But when we saw OpenClaw take off, we realized that the most effective thing we could do was help supercharge the work of human-rights activists with AI.

At first, these freedom agents were buggy, but the idea was unshakeable: Dissidents could design, plan, research, strategize, and create complex products and programs in minutes or hours, instead of weeks or months, and for ten dollars or a hundred instead of ten thousand or a hundred thousand.

As February turned into March and April, “personal agent” software improved. By May, it was possible to run a fully local “chat bot” on an iPhone, pointing to a future where activists run inference on their own devices instead of renting compute from corporations that could surveil and censor.

Working with the AI-experience company Finite, HRF quickly established an “Agent Camp” to provide an in-person academy for human-rights defenders to learn how to use personal agents to dramatically expand their productivity and impact. HRF also rolled out public education about AI as a freedom tool at major global events — for example, the Bitcoin Conference in Las Vegas, where we demonstrated the power of vibe coding to thousands of attendees, or at the Oslo Freedom Forum in early June, where an experiential cafe lounge gave leading dissidents several hours on our machines to cook up their dreams.

Given the surveillance tools of dictators, one of HRF’s major goals was making our AI tool secure. Corporate AI tools are, by their nature, vulnerabilities for activists. They can by default, or by state force, surveil their users, censor their users, deplatform their access, and steal intellectual property. Open-source tools are harder to deploy, and security can be a big challenge, but we knew corporate offerings weren’t going to be an option for dissidents, so we worked with Finite to address the shortcomings. Instead of taking the easy route of just assuming corporate tools won’t betray us, we are on the road to making it impossible for our tools to do so.

Starting in May, Finite was able to connect our customized Hermes-powered app to a “Trusted Execution Environment” (TEE)–enclosed model. A TEE means that the cloud operator running the AI compute cannot read the user’s communications, similar to how Signal servers facilitate messages but cannot read the content.

In our system, activists can choose between a frontier corporate model, where Anthropic or OpenAI can read all of their prompts or a “private” TEE model where the cloud compute operator cannot see what they are saying. In this way, activists begin to think about what kind of information needs to be private. Today, activists think carefully about what to put in email and what to put in Signal. Moving forward, having access to privacy-protecting AI, and knowing how and when to use it, will be just as important.

Zooming out, what’s become clear is that AI is a true battleground for human rights, not just a one-sided technology to empower dictators. Activists will get much stronger, maybe even asymmetrically so. Consider that tyrants already have PR companies, design agencies, banking infrastructure, and investigators to do their bidding. Dissident groups typically have none of these. Privacy-protecting personal agents can dramatically expand the power of individuals or small groups, even as they incrementally expand the power of dictators.

The next piece of the puzzle and evolution for activists is the “organizational brain.” Pioneered by Jack Dorsey and his team at Block, the idea is to shift the hierarchy of an organization away from the traditional Roman Army structure that companies have historically used to an “intelligence” structure where individuals and teams “report” to an AI, giving the leadership much better insight across an organization.

As an example, imagine you are a prodemocracy organization in Turkey with twenty employees. Today it requires a lot of coordination between your teams (administrative, program, events, compliance, and so on) to produce reports, inform donors, tell the world what you are doing, and educate people about your work. Tomorrow, with an organizational brain, the leadership would need only to ask the intelligence (by speaking into their phone in plain language) how the organization has responded to a certain regime action, or what the organization’s programs have achieved so far that year. In minutes the organizational intelligence — powered by a stream of transcripts from staff meetings, weekly updates from employees, and achievements from Slack channels, social media, and email publications — will produce a draft annual report, donor report, strategic document, or video recap to advance the group’s mission. Before, these tasks would all have taken days, if not weeks or months, and massive internal and external collaboration and costs to complete.

The lesson is that prodemocracy organizations need to get serious about using AI tools, and should use them in line with their ideologies: people-powered, civil-liberties protecting, and anti-authoritarian.

Access to AI will become essential for human-rights groups, especially those in dictatorships, sooner rather than later. And the only way to ensure access is if open-weight models (ones that users can download and customize themselves) proliferate and become the standard, or at least become accessible at scale in confidential computing environments.

The good news is that the gap between open and closed models is closing rapidly. The top open models are rivaling the best closed-source offerings from the top corporations. What’s more, the newest frontier models don’t necessarily make running personal or organizational agents that much better. The latest open-weight models are all any activist needs today to level the playing field.

No one is debating that tyrants are using AI tools. But if they are the only ones to take advantage of this revolution, then their Orwellian dreams will come true, and the lives of activists will become that much more difficult. Human-rights defenders wouldn’t think of challenging today’s computerized tyrants with typewriters. And it would be a mistake if they missed the AI train and let the strongmen dictate the future of intelligence.

Alex Gladstein is chief strategy officer at the Human Rights Foundation and the author of Check Your Financial Privilege and Hidden Repression.

 

Copyright © 2026 National Endowment for Democracy

Image Credit: peshkov via Getty Images

 


FURTHER READING

OCTOBER 2025

Why Bitcoin Is Freedom Money

Alex Gladstein

The digital currency offers a lifeline to democratic movements operating in the most repressive places.

ONLINE EXCLUSIVE

How to Dictator-Proof Your Money

Alex Gladstein

Bitcoin has quickly become the currency of choice for dissidents working everywhere.

APRIL 2026

The Power of Freedom Philanthropy

Tim Reynolds and Álvaro Salas-Castro

Freedom  is the most underpriced asset, and we are due for a market correction.