Researchers found a way to alter raw digital DNA-analysis files produced by technology widely used in U.S. crime laboratories. In a demonstration reported by The Wall Street Journal, they combined data from two people’s DNA profiles into a new file whose metadata made it appear unchanged since 2015. The physical DNA and the CODIS database were not altered; the target was the instrument-generated file created during analysis of a sample.
The affected systems are sold under Applied Biosystems, Thermo Fisher Scientific’s genetic-analysis brand. The FBI’s Federal DNA Database Unit protocol, for example, specifies the company’s 3500xL and 3730xL analyzers. One researcher said Anthropic’s Claude chatbot helped him produce his first successful alteration in 45 minutes. Because tampering can occur before the file is loaded into analysis software, it could be nearly undetectable during routine analysis if laboratory security and chain-of-custody controls were circumvented.
Thermo Fisher classified the vulnerability as high severity and reported no known exploitation. It released updates for five current software lines that digitally sign newly generated files. Three older, unsupported lines will not receive updates. The researchers said potentially affected file formats have been in use since 1995, although Thermo Fisher has not publicly confirmed that full timeframe. No affected criminal case has been publicly identified.
Louisiana made it a crime Saturday to use an image of a child under 17 with the intent to train an AI model to make child sexual abuse material (CSAM). The law targets the training process itself, not merely possession or distribution of the resulting images. Prosecutors would have to prove what image was used and why; the statute says the resulting material need not depict a natural child.
Four other Louisiana AI and deepfake laws also took effect Saturday. One brings synthetic depictions of children within the state’s CSAM law. Another creates or expands offenses involving AI sexual images of recognizable people. The election law requires a disclosure on some AI-manipulated election communications; violating it to damage a candidate’s reputation or deceive voters can bring up to two years in prison. The school law prohibits deepfakes used to coerce or harass K–12 students but contains no criminal penalty of its own.
A new California law requires AI companies to offer a free tool for checking whether an image, audio file or video was altered by that provider’s system. (California Legislature)
A judge denied xAI’s last-minute request to stop Minnesota’s nudification law before it took effect Saturday. (U.S. District Court)
The EU’s comprehensive AI law started enforcing stricter disclosure and marking standards for AI-generated media. (European Union)
The U.S. administration greenlit the commercial deployment of Amazon’s Zoox self-driving taxis, which lack pedals and steering wheels. (Federal Register)
NHTSA is offering $20 million for traffic-safety projects, including potential AI-assisted risk analysis. (NHTSA)
An East Tennessee county is pausing the planned $1.5 million expansion of an automated license-plate reader network. (WVLT)
Axon is pitching a new AI case-search tool that it says can rank evidence. (Axon)
Water utilities in at least seven states reported cyber incidents since July 27. (FBI and EPA)