Secret ballots are a basic promise of voting: nobody should be able to trace your ballot back to you. A researcher at Princeton University just showed that promise has a hole in it, and a cheap AI chatbot is all it takes to walk through it.
Max Springer, a researcher at Princeton's Center for Information Technology Policy, got Georgia's public election data through an open records request. He then paid for a 20 dollar subscription to a mainstream AI model and asked it to figure out how to match voters to their ballots. Springer had never set foot in Georgia and has no background in cracking voting systems. Within a couple of hours, the AI built him a working method and told him exactly what additional data it would need to identify real voters. It never once pushed back or flagged the request as a problem.
The result: Springer could reconstruct the order in which more than 1.5 million ballots were cast across 114 Georgia counties, covering nearly all in-person votes in those counties. In smaller counties with few voters on a given day, he could match almost every single ballot to the voter who cast it.
The underlying flaw is not new. Researchers at the University of Michigan found it in 2022 in Dominion's voting machines, the same machines Georgia uses statewide. The problem comes down to how the machine numbers each ballot as it is scanned: the numbering is supposed to look random, but it follows a predictable pattern that can be reversed to recover the original voting order. Dominion released a software fix, and federal officials certified it in 2023. Every other state running this equipment has either installed the patch or stopped publishing the data that makes the flaw usable. Georgia has done neither.
This is not a funding mystery. Georgia's secretary of state asked state lawmakers for money to fix this for three years and got nothing. One official described years of warnings met with no action from the legislature. Fixing the full voting system properly has been estimated to cost over 30 million dollars, and a separate push to replace the state's voting machines entirely was just pushed back to 2028. With early voting starting in days, Georgia's election board considered a manual workaround, having poll workers physically shuffle paper ballots by hand, and rejected it as unworkable this close to an election.
The real story here is bigger than Georgia. A flaw that used to require a cryptography PhD to exploit can now be run by anyone with a credit card and an internet connection. The AI did not need to be told how voting systems work. It figured out the pattern and handed over a working attack, no questions asked.
Any organization sitting on a known, published vulnerability it never got around to patching should take this as a warning. The gap between "a flaw exists on paper" and "someone can actually use it against you" is closing fast, and it is closing for people with no technical training at all. If your business has a known weakness sitting in a report somewhere, the old assumption that it requires a specialist to exploit no longer holds.