SB 5 in Five: What to Know About Connecticut's New AI Law
Future of Privacy Forum explainer on Connecticut SB 5, the 39-section AI bill signed by Governor Lamont, summarizing its new requirements across several areas of AI policy.
Resource Hub
2467 hand-picked resources, updated every week. Search it, filter it, or just browse a collection and see what catches your eye. Want today’s headlines instead? Read the free AI news feed.
Filtered by tag
Answers come only from resources in this hub, with the sources listed underneath.
43 resources
Future of Privacy Forum explainer on Connecticut SB 5, the 39-section AI bill signed by Governor Lamont, summarizing its new requirements across several areas of AI policy.
A free tool that strips tracking parameters from links before you share them, so the people you send a link to aren't followed across the web. Paste a link, get a clean version back.
RaLHF essay on companies holding your personal data letting AI bots in, and why Apple's approach gets access others don't.
Why I recommend it: One writer's opinion piece.
Ben Hylak argues that as AI agents start negotiating with each other on our behalf, our privacy will depend on how well those agents handle social situations.
Why I recommend it: An opinion essay by a startup founder, not research. Good prompt for thinking about what you let an agent share.
OpenAI help article on Trusted Contact: an optional adult (18+) feature that may notify one person you choose if automated systems and trained reviewers detect a serious suicide-related safety concern.
Why I recommend it: Worth reading before you turn it on: it involves human reviewers reading flagged conversations and sharing an alert with someone else. OpenAI says it is not an emergency service. Not available in Business, Enterprise, or Edu workspaces.
A duty-by-duty walkthrough of California's automated decisionmaking technology rules — approved 23 September 2025, in effect from 1 January 2026, with ADMT obligations from 1 January 2027 — and where each duty can actually be enforced in a system. Covers pre-use notice, opt-out, human review, appeals and per-decision record keeping. The rules apply when computation replaces human judgment on a significant decision about work, money, housing, education or health.
Why I recommend it: The clearest free explanation I have found of what these rules require, and the section on significant decisions is directly relevant if an employer screens you by machine — you get notice, an opt-out and a route to a human. Read it knowing DeepInspect sells the kind of control it describes, so the framing pushes toward buying a product; the legal dates and duties are checkable against the state agency's own page, which it links.
A full AI assistant — writing, images, web search, memory, file uploads — where every conversation is end-to-end encrypted on your device, so the company says it cannot read your chats, train on them, hand them to partners, or produce anything but scrambled text in response to a subpoena. Built by Moxie Marlinspike, the cryptographer who created Signal. Free to start with no credit card; the encryption and private inference designs are written up publicly and the code is open source so the claims can be checked.
Why I recommend it: This is the one to reach for when you are about to type something into an AI that you would not want read back to you — money trouble, health, a manager, a visa problem. Two honest things. It is free to start, which is not the same as free forever, so read the plan page before you rely on it. And encryption protects the message, not your judgment: anything you paste in that belongs to an employer or a client is still their information, whoever can or cannot read it.
A free way to use several well-known chat models — including ones from OpenAI and Anthropic alongside open models like Llama and Mistral — without an account and without the model provider seeing who you are. DuckDuckGo strips your identity and passes the request on, and says the providers agree not to train on what goes through it. Supports image and PDF uploads, image generation and voice chat, with daily limits on the free tier.
Why I recommend it: The most frictionless privacy win on this list: no sign-up, nothing to cancel, and it takes about four seconds to start. Good for the everyday questions you do not want attached to a profile. Be clear about what it does and does not do — DuckDuckGo hides who you are from the model provider, but the words you type still travel to that provider's servers, so it is not the same as encryption or running a model on your own machine. There is a paid upgrade for higher limits.
An AI chat and image tool built on open-source models that keeps conversation history in your own browser rather than on its servers, and offers a choice of privacy modes including trusted execution environment and end-to-end encrypted options. It also applies no content filtering, which it calls uncensored. The free tier is real but small: base models only, 10 text prompts and 15 image prompts a day. Paid plans start at $18 a month.
Why I recommend it: Worth knowing about mainly for the privacy modes and the model choice — it is one of the few consumer tools that tells you which protection each model is running under. Three honest flags. Ten prompts a day is a trial, not a working tool, so do not build a habit on the free tier. "Uncensored" means no safety filtering, which is a genuine reason some people want it and a genuine reason to keep it away from a shared or work machine. And Venice runs a crypto token alongside the product, which has nothing to do with whether the AI is any good.
Abid Ali Awan's 22 September 2026 walkthrough of seven open-source chat interfaces you can run on your own machine — starting with Open WebUI via Docker or Python connected to Ollama, llama.cpp or any OpenAI-compatible endpoint — and covering document assistants, agent platforms, multi-user team setups and full self-hosted AI workspaces. Each entry says what it is for and roughly what it takes to run.
Why I recommend it: Free to read, and the most useful starting point if you want AI without a subscription or without your files leaving your laptop. Set expectations honestly: running models locally needs a decent machine — a capable GPU for the larger ones — and the quality will sit below the paid cloud services. Every tool named here is on our Projects hub with a run-it guide, so read the article for the shape of the options and follow each project's own README for the actual commands.
A free, no-code recipe book of practical AI prompts built for nonprofit teams. Turn existing reports, events, and materials into slide decks, web pages, plain-language translations, social copy, and repeatable workflows. Every recipe includes a privacy badge so you know what stays on your computer, what goes public, and what connects to a vendor account.
Why I recommend it: Free to use. Built by Decoded Futures (a TechNYC program). The recipes are framed for nonprofit work, but the same patterns work for job searches, career content, and small-business tasks.
Independent cybersecurity and technology news site covering malware, ransomware, data breaches, privacy, and support guides for Windows, Linux and macOS.
From the site: BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and how to protect your devices.
Why I recommend it: Free to read and ad-supported. Use it as a practical incident tracker and a source of plain-language security guidance, not as a single source for attribution.
Global nonprofit defending and extending digital rights for everyone.
From the site: Digital rightsfor everyone. Derechos digitalespara todas. .الحقوق الرقمية للجميع Droits numériquespour tous. Access Now defends and extends the digital
Independent technology journalism founded by Jason Koebler, Emanuel Maiberg, Samantha Cole and Joseph Cox. Covers tech, AI, privacy and internet culture.
From the site: 404 Media is an independent media company founded by technology journalists Jason Koebler, Emanuel Maiberg, Samantha Cole, and Joseph Cox.
Why I recommend it: Some articles may be behind a membership paywall; the homepage and many stories are free to read.
An open-source, self-hosted set of PDF tools — merge, split, sign, compress, convert — with no upload to somebody else's server.
From the site: #1 PDF Application on GitHub that lets you edit PDFs on any device anywhere - Stirling-Tools/Stirling-PDF
Why I recommend it: Do not upload your CV to a random free PDF site. Run this locally for the same jobs.
An open-source, self-hosted search engine that queries other engines without tracking you or building a profile. AGPL licensed.
From the site: SearXNG is a free internet metasearch engine which aggregates results from various search services and databases. Users are neither tracked nor profiled. - searxng/searxng
Why I recommend it: Useful if you research employers a lot and would rather not have that history tied to an account.
An open-source drop-in replacement for the OpenAI API that runs models on your own hardware, including CPU-only machines. MIT licensed.
From the site: LocalAI is the open-source AI engine. Run any model - LLMs, vision, voice, image, video - on any hardware. No GPU required. - mudler/LocalAI
Why I recommend it: Point existing code at your own server instead of a paid API — no code changes beyond the address.
A fast, dependency-light rewrite of OpenAI's Whisper speech-to-text that runs on ordinary laptop hardware, including CPU only. MIT licensed.
From the site: Port of OpenAI's Whisper model in C/C++. Contribute to ggml-org/whisper.cpp development by creating an account on GitHub.
Why I recommend it: Transcribe interviews or your own practice answers privately, without paying a per-minute transcription service.
An open-source desktop app that runs AI models entirely offline on your own computer, with an optional local API server. AGPL licensed.
From the site: Jan is an open-source alternative to ChatGPT. Run open-source AI models locally or connect to cloud models like GPT, Claude and others.
Why I recommend it: Install, download a model, unplug the internet — it still answers. That's the point.
An open-source desktop and self-hosted app that lets you chat with your own documents using local or hosted models. MIT licensed.
From the site: Stop renting your intelligence. Own it with AnythingLLM. Everything you need for a powerful local-first agent experience - Mintplex-Labs/anything-llm
Why I recommend it: Point it at your own files — job descriptions, notes, contracts — and ask questions of them without uploading anything to a company.
An open-source chat app you host yourself that talks to many model providers at once, with user accounts, presets and file uploads. MIT licensed.
From the site: Enhanced ChatGPT Clone: Features Agents, MCP, Skills, DeepSeek, Anthropic, AWS, OpenAI, Responses API, Azure, Groq, o1, GPT-5, Mistral, OpenRouter, Vertex AI, Gemini, Artifacts, AI model switching,...
Why I recommend it: Good for a small team who want one chat tool across several providers without paying per seat.
A self-hosted, open-source chat interface for local or hosted models — chat history, documents, multiple users. Works on top of Ollama or any OpenAI-compatible API.
From the site: User-friendly AI Interface (Supports Ollama, OpenAI API, ...) - open-webui/open-webui
Why I recommend it: If you like the ChatGPT window but not the subscription, this is that window running on your own machine.
Open-source software that downloads and runs open AI models on your own computer, with a single command and an OpenAI-compatible local API. MIT licensed.
From the site: Ollama is the easiest way to automate your work using open models, while keeping your data safe.
Why I recommend it: The easiest honest way to use AI privately — nothing you type leaves your machine. Start with a small model before you judge the speed.
A hands-on write-up of wiring Google's open Gemma 4 model into the Codex command-line coding agent so it runs locally instead of calling a hosted API.
From the site: I wanted to know whether Gemma 4 could replace a cloud model for my day-to-day agentic coding. Not in theory, in practice. I use Codex CLI…
Why I recommend it: Useful if you want to try coding agents without paying per token — local models are slower, but free and private.
Investigative reporter Yael Grauer writes on privacy, security, surveillance and the craft of tech journalism.
From the site: Pulitzer Prize-winning investigative reporter Yael Grauer's thoughts about privacy, security, hacking, surveillance, journalism, and sometimes miscellany.
Why I recommend it: Worth following if you care about surveillance and privacy work, or want to see how a reporter builds those stories.
Micah Lee's book on analyzing hacked and leaked datasets, free to read in full online alongside the print edition.
From the site: Buy Hacks, Leaks, and Revelations: The Art of Analyzing Hacked and Leaked Data by Micah Lee.
Why I recommend it: The whole book is readable free on the site — a practical intro to handling large datasets safely.
Security technologist Micah Lee's site — tools, writing and guidance for journalists, researchers and activists working safely.
From the site: Hi, I'm Micah. I help journalists, researchers, and activists stay safe and productive.
Why I recommend it: Follow him for practical security practice rather than theory, especially if your work involves sensitive sources.
A self-hosted, MIT-licensed AI agent with persistent memory that builds skills over time and reaches you on Telegram, Discord and other channels.
From the site: Self-hosted AI agent that remembers your projects, builds skills automatically, and reaches you on Telegram, Discord & more. MIT license. No tracking.
Why I recommend it: Free and open source, and it runs on your own machine — worth a look if you don't want your project context sitting on someone else's server.
A long-running peer-reviewed, fully open-access journal on the internet and society — platform power, digital labour, privacy, AI governance and online community research.
From the site: First Monday is one of the first openly accessible, peer–reviewed journals on the Internet, solely devoted to the Internet.
Why I recommend it: Free peer-reviewed research with no paywall — a good citation source when you need something stronger than a blog post.
Engineering and policy writing from Palantir on data platforms, government deployments, defence technology and how the company approaches privacy controls.
Why I recommend it: Read it critically — it is a company blog on a contested subject, which makes it useful primary material for understanding the industry's own arguments.
A Georgetown law-center project on privacy, records and what happens when everything is searchable.
Why I recommend it: Academic but readable work on privacy and searchable records.
An interactive map of surveillance technology companies, their funders and the governments that buy from them.
Why I recommend it: The clearest picture I have found of who sells surveillance tools and who pays for them.
A campaign encouraging people and institutions to reduce their dependence on a handful of large technology platforms.
Why I recommend it: Useful framing if you are trying to explain platform dependence to a non-technical audience.
A campaign toolkit on health data contracts, written for people organizing locally rather than for policy specialists.
Why I recommend it: A rare example of a plain-language toolkit about a data contract.
404 Media reports on leaked internal documents showing that human reviewers read ChatGPT prompts to improve OpenAI's models — including chats that hold sensitive personal information. Useful context before you paste private details into a chatbot.
A free plain-language guide to online safety, digital personas, scams and self-defense in online spaces.
Why I recommend it: Share this with anyone who is nervous about putting themselves online for work.
A Substack essay from Ruben on privacy, data ownership, and the human side of digital trust.
Why I recommend it: Personal take on privacy that connects policy to everyday choices.
Nonprofit behind the Signal messenger, publishing on private communication and surveillance.
Why I recommend it: Job hunting involves sharing a lot of personal data. Knowing your private-messaging options matters.
On-device AI with cloud fallback for smartphones, laptops, and edge devices, designed to cut inference costs by knowing when to hand off to frontier cloud models.
Why I recommend it: I am watching on-device AI closely because it could make powerful tools accessible at lower cost and with more privacy. Cactus is a useful example of the "know when to hand off" design pattern.
VentureBeat's report on a portable computer from Perplexity and NVIDIA that runs an AI agent entirely on-device, removing per-token API costs.
Why I recommend it: Local models matter for anyone handling private client data. Watch this direction if cost or confidentiality is a limit for you.
Free course from fast.ai covering disinformation, bias, privacy, algorithmic accountability, and the ethical questions data practitioners hit in real projects, taught by Rachel Thomas.
Why I recommend it: Finish this and you can speak credibly about AI risk in an interview instead of repeating headlines.
Report on how the datasets powering major AI systems depend on mass invasions of privacy by design.
Why I recommend it: Read this before you paste sensitive personal or client data into an AI tool.
Wired's weekly security roundup covers OpenAI, Anthropic, and 100+ companies cosigning a letter warning that organizations have mere months to prepare for AI-enabled cyberattacks. The piece also tracks rogue AI agent hacking incidents, attacks on over 100 U.S. water systems, license-plate-reader surveillance abuse, Meta's $16.7B child-safety settlement, and ICE buying robot dogs — a snapshot of where AI, surveillance, and critical-infrastructure security collide.
From the site: OpenAI, Anthropic, and more than 100 companies have cosigned a letter saying that everyone else has mere months to prepare for AI-enabled cyberattacks.
Why I recommend it: A stark signal that AI-enabled cyberattacks are no longer hypothetical. The cosigned letter from OpenAI and Anthropic calling for a 'collective response' is exactly the kind of industry accountability move worth watching — pair it with the Hugging Face incident reporting and the water-system attacks to see how AI agents are already being used offensively. Useful for anyone tracking the gap between AI capability and AI governance.