Georgia’s Voting System Faces New Scrutiny as AI Makes Secret Ballots Easier to Trace 

Georgia is facing renewed concerns about the privacy of its elections after security researchers demonstrated that a known weakness in the state’s voting technology could potentially allow individual voters to be matched with their ballots—with artificial intelligence making the process substantially easier.

The vulnerability does not allow anyone to change votes and does not call the accuracy of election results into question. Instead, the concern involves one of the oldest principles of American elections: the secret ballot.

Georgia’s Constitution requires elections to be conducted by secret ballot, while state law says voting equipment must allow people to vote in absolute secrecy.

Georgia voters make their choices on touchscreen machines that produce paper ballots. Voters review those ballots before inserting them into scanners, which tabulate the results and create electronic ballot images and cast-vote records.

Those electronic records are supposed to be randomized. However, researchers who examined the system discovered in 2022 that a software weakness could allow the records to be reconstructed in the order in which ballots were scanned.

When combined with other publicly available election records, researchers say that sequence can potentially be used to determine how specific individuals voted.

The rapid development of artificial intelligence has made the vulnerability more concerning.

Princeton University researcher Max Springer recently tested whether a publicly available AI assistant could reproduce the process. After receiving information about the vulnerability, the AI was able to reverse the shuffled electronic records from Georgia’s May primary and identify additional public documents necessary to connect voters with ballots.

Springer then supplied early-voting lists and cast-vote records. In many instances, the AI narrowed the information into groups of possible voters and ballots. With additional scanner audit logs and precinct check-in information, he reported being able to match most ballots in his experiment with individual voters.

The demonstration illustrates how AI can lower the technical barrier required to exploit an existing vulnerability. Tasks that once demanded specialized programming knowledge can increasingly be performed with assistance from widely available AI tools.

The privacy implications are significant.

Secret ballots are intended to protect voters from retaliation, intimidation, vote-buying and coercion by employers, political organizations, family members or government officials. Information showing exactly how individuals voted could also be valuable to political campaigns.

Georgia election officials say they are taking precautions.

The secretary of state’s office has instructed counties to redirect certain public-record requests to state officials. Potentially sensitive information will be redacted, while some documents will not be released. Officials are also working with a vendor to scramble the original order of ballot images and cast-vote records before making them public.

Critics argue that restricting access to election records addresses the symptom rather than the underlying technological problem.

The voting-system manufacturer has produced a software update intended to correct the vulnerability, and other jurisdictions using similar equipment have already installed it. Georgia, however, has not implemented the update statewide.

State officials say the update has not been certified by the secretary of state’s office, would require months to implement and lacks necessary funding from the legislature.

A proposal before the State Election Board that would have required the update before the November elections was rejected. Some board members expressed frustration that the problem remained unresolved but questioned whether the board had the legal authority or sufficient time to mandate such a major technological change shortly before an election.

Officials have also emphasized that revealing how another person voted is a felony in Georgia, providing a significant legal deterrent.

Election-security advocates remain concerned because Georgia presents an unusual combination of circumstances: the equipment is used statewide, relevant election documents can be obtained through public-record laws, and increasingly powerful AI tools can simplify the technical work required to connect those records.

With Georgia preparing for closely watched elections in November, the dispute highlights an emerging challenge for election security.

Artificial intelligence does not necessarily have to create entirely new vulnerabilities to affect democratic systems. It can make existing weaknesses dramatically easier to exploit.

Georgia’s controversy therefore extends beyond one voting system. As AI becomes increasingly capable of analyzing large datasets and performing sophisticated technical tasks, election officials across the country may have to reconsider whether safeguards designed for an earlier technological era remain sufficient.

The fundamental issue is straightforward: Americans expect not only that their votes will be counted correctly, but also that no one will be able to discover how they voted.

In Georgia, researchers warn that preserving that second guarantee may now require stronger technological protections than ever before.