The use of AI in electronic voting systems

AI-based electronic voting systems promise faster and more inclusive elections, but at what cost? From vulnerabilities to cyberattacks (deepfakes, malware) to t

Electronic voting systems use AI to verify identities, count votes, and detect fraud quickly and scalably. But this innovation brings with it ethical dilemmas and security vulnerabilities that could threaten trust in elections.

Introduction: Why AI in Electronic Voting is Controversial

Imagine voting from your smartphone or computer, with AI checking your biometric identity, counting votes in real time, and blocking manipulation attempts. It seems like the future of democracy: more inclusive, faster, accessible even for those living far from polling stations.

But in recent years, real-world cases – from tests in Switzerland to experiments in the United States – have highlighted worrying cracks: simulated hacks, deepfakes impersonating candidates, and algorithms amplifying targeted disinformation. AI promises efficiency but raises crucial questions about privacy, transparency, and integrity: who guarantees that a vote is not altered by a cyberattack or an algorithmic bias?

In Europe, the AI Act classifies voting systems as high-risk, imposing strict rules, while in the US, bodies like the Brennan Center for Justice warn about the dangers of generative AI for election security. This article explores the ethical and security risks, analyzing practical examples and solutions for navigating a future where digital voting will become increasingly central.

What is AI-Powered Electronic Voting and How Does It Work?

Electronic voting (e-voting) is a digital system that replaces paper ballots with online platforms, apps, or networked voting terminals, where Artificial Intelligence intervenes in several key stages: voter identification (via biometrics and facial recognition), verification of vote uniqueness, automated counting, and real-time anomaly detection.

It works like this: the user authenticates (for example with a fingerprint or AI-powered facial recognition), selects their preference, the system encrypts the vote and records it immutably on architectures like blockchain or secure databases; meanwhile, anomaly detection algorithms monitor suspicious patterns, such as attempts at multiple votes or access from anomalous IP addresses. In Switzerland, for example, the Post tested e-voting systems by releasing the source code publicly to maximize transparency.

AI makes the entire process more efficient: it reduces human errors in the counting phase, speeds up results, and increases accessibility for people with disabilities or expats. However, the system intrinsically depends on training data: if this data contains biases, the algorithm could discriminate against ethnic groups during facial recognition, as has already happened in several tests in the United States. The technological foundation is solid but becomes extremely fragile if deprived of rigorous human oversight.

Ethical Risks of AI in Electronic Voting

Ethics comes forcefully into play when an AI decides who has the right to vote and how votes are processed. Biometric recognition systems trained on non-inclusive datasets can systematically exclude minorities, perpetuating serious structural discrimination. As we have already explained in our in-depth look at how algorithms amplify biases and invisible discrimination, the prejudices inherited from data explode catastrophically in sensitive contexts like elections.

Another burning dilemma concerns surveillance: to function, AI must collect sensitive data (facial scans, IPs, reaction times, and implicit preferences), risking privacy violations or post-vote political profiling. International IDEA clearly warns about the ethical risks: "The protection of sensitive data is crucial for public trust, but extremely complex for electoral authorities." Furthermore, AI-generated deepfakes can spread targeted propaganda, influencing public opinion without leaving obvious traces of manipulation.

On La Bussola, our reflections on AI ethics and cybersecurity emphasize how delegating critical decisions to machines raises huge questions of *accountability*: who is legally responsible if an algorithm makes a mistake counting a precinct? Ethics is not optional: without a solid regulatory framework like the European AI Act, the reckless use of technology risks eroding the very foundations of democracy.

Security Challenges: From Hackers to AI Manipulations

Cybersecurity is the real Achilles' heel of e-voting. Digital systems expose the electoral process to massive cyberattacks (DDoS, malware, data breaches), which today are amplified by adversarial AI capable of generating hyper-sophisticated phishing campaigns or attempting to alter votes in real time. The Brennan Center notes that generative AI amplifies pre-existing threats, allowing malicious actors to clone official documents or impersonate election officials on a massive scale.

Real-world examples are not lacking: Dutch tests showed serious vulnerabilities in algorithmic systems suspended for excessive profiling; in India and the US, Artificial Intelligence facilitated the creation of viral deepfakes during election campaigns. AI proves to be a double-edged sword: on one hand, it is the only tool capable of detecting fraud at the speed of light; on the other, it is used by criminals to create advanced malware capable of hitting specific targets.

Our articles on Fake news and AI: an information war illustrate how algorithms amplify disinformation, a mechanism easily extendable to voting: a single security breach can invalidate entire national elections. Decentralized architectures like blockchain can mitigate the problem by protecting the central database, but they do not eliminate the risks if the entry point (the voter's smartphone or app) is compromised by malware.

Practical Examples: Real Successes and Failures

  • Switzerland (Post e-voting): A system that uses AI for identity verification, with open-source code published for independent audits. Despite partial success, public tests conducted in 2023 revealed critical vulnerabilities to insider attacks (from within the organization).
  • United States (state tests): AI is used for voter list maintenance and *signature matching* (automatic signature verification). However, the Brennan Center has documented serious risks from poorly trained software that discriminates against minorities by invalidating their signatures. Furthermore, in Georgia, a simulated attack demonstrated the feasibility of altering digital votes.
  • Estonia (pioneering i-Voting): The Baltic country has used systems based on cryptography and blockchain since 2005, recording very high participation rates. Although the Estonian model is the most advanced in the world, recent cybersecurity reports indicate the need to update defenses against new potential AI-based manipulations. La Bussola explores the prospects of these models in its analysis of how AI could change the future of democracy.
  • Turkey 2023: AI was used to monitor election security, but several academic studies highlighted the ethical risks arising from the use of algorithms in non-transparent government contexts.

These cases teach a fundamental lesson: AI speeds up and simplifies the process, but without a "hybrid" system that includes sample paper checks (paper trail), the system risks failing to guarantee the absolute certainty of the vote.

Key Points

  • AI in electronic voting drastically improves counting speed and inclusion but requires equitable training datasets to avoid biometric discrimination and ethically questionable profiling.
  • Security risks include cyberattacks amplified by adversarial AI (deepfakes, automated malware), with potential breaches that irreparably undermine public trust.
  • Regulations like the European AI Act and IDEA guidelines impose transparency, independent audits, and *privacy by design* for systems classified as high-risk, such as e-voting.
  • Hybrid solutions (advanced cryptography combined with sample human verification) and the adoption of open-source software reduce dangers, but the final word (accountability) must remain human.

FAQ

1. Does AI make electronic voting safer or riskier? AI is an ambivalent tool: it detects cyber fraud and speeds up counts with superhuman precision, but introduces new vulnerabilities like deepfakes and algorithmic biases. It makes the process riskier if implemented without rigorous audits and hybridization systems (like printing a paper verification receipt).

2. What are the main ethical risks in biometric recognition for voting? The greatest risks are the exclusion of minorities due to biased training datasets (which struggle to recognize non-Caucasian faces), mass surveillance, and the post-election use of biometric data for political profiling, in clear violation of privacy.

3. Does Blockchain solve all e-voting security problems? No. Blockchain mitigates "tampering" (data alteration) thanks to its immutable and decentralized nature, but it does not protect the entry point (the user's computer or app) from local hacking or AI-generated phishing campaigns. If the user enters a wrong vote due to malware on their phone, the blockchain will permanently record a wrong vote.

4. Does the EU AI Act regulate AI in electronic voting? Yes. The AI Act classifies AI systems intended to influence the outcome of an election or voting behavior as "high-risk" systems, imposing strict transparency obligations (transparency), risk assessment (risk assessment), and placing absolute bans on unacceptable subliminal manipulation techniques.

5. Is 100% secure electronic voting with AI possible? In computer science, 100% security does not exist. However, hybrid systems that combine manual checks, open-source software, and military-grade cybersecurity standards (following the Estonian model) can minimize risks to statistically acceptable levels for a modern democracy.

Conclusion: Balancing Innovation and Democratic Trust

The introduction of AI into electronic voting systems offers the historic opportunity to leap towards more participatory, faster, and accessible democracies. However, the ethical risks related to privacy and biases, combined with the cyber threats of deepfakes and automated manipulations, require extreme institutional caution.

Case studies in advanced nations like Switzerland and Estonia demonstrate its logistical potential, but documented failures in the US issue a severe warning: without code transparency, independent verification, and rigorous human regulations, automation risks eroding public trust, the most essential ingredient for the stability of a democracy.

As the Brennan Center notes, *"AI amplifies existing threats, but with decades of best practices it can be managed."* Towards 2026, with the AI Act fully in force, European nations will need to aim for unassailable hybrid standards and deep digital civic education. The stakes are extremely high: a secure, secret, and unalterable vote is not a technological luxury, but the very foundation of popular sovereignty.