Imagine arriving at a polling place where the electronic voter check-in system has stopped working. Election workers are switching to a backup procedure. At the same time, an audio recording begins circulating online in what sounds like the voice of a local election official. It says voting has been suspended and tells people to stay home.
The recording is fake. The outage is real.
This is a hypothetical scenario, not a report of an ongoing attack. But it combines two problems election officials are already preparing for. The Election Assistance Commission warns that artificial intelligence can scale existing cyber threats and can be used to imitate election officials through text, images, audio, and video. The same agency is also publishing continuity resources and Election Day simulations for equipment failures.
That suggests a more useful election-security question than simply asking whether every attack can be prevented: Can lawful voting continue when prevention fails?
A disruption is not automatically a compromised election
The first step is identifying which function has actually failed. Electronic poll books, for example, help workers check voters in, assign the correct ballot style, and record that a voter has been issued a ballot. The EAC explicitly distinguishes them from voting systems: Electronic poll books do not collect or tabulate cast vote records.
An electronic poll-book outage can therefore create a serious operational problem without establishing that ballots or vote counts have been compromised. That distinction matters because an AI-fueled information environment can erase it in seconds.
The same principle applies to public-facing election websites. In a joint advisory, the FBI and the Cybersecurity and Infrastructure Security Agency warned that denial-of-service attacks could make voter information tools or unofficial election night reporting unavailable while leaving the underlying voting process intact. An attacker could then falsely describe a visible outage as proof that voting itself had failed.
Election continuity begins by refusing to collapse unlike failures into one story.
Backups have to work under pressure
Election offices are not starting from zero. In March, the EAC released Election Day simulations showing how officials can respond when electronic poll books, ballot-marking devices, or scanners break down. And last week, the commission updated its state-by-state electronic poll-book certification information, while its federal voluntary program continues to test systems for functionality, security, and accessibility through a structured review process. The current federal certification process includes penetration testing, test execution, and formal certification decisions.
Certification matters. Continuity asks what happens when a certified system becomes unavailable anyway.
The EAC’s February disaster guidance recommends redundant communications, cross-trained staff, and analog or printed materials such as ballots, voter lists, staff rosters, and voting-location contacts. Those are not glamorous cybersecurity tools. They are exactly the sort of infrastructure that keeps a polling place functioning when normal technology is degraded.
A useful exercise is concrete. If electronic check-in fails during peak turnout, how quickly can workers move to the authorized alternative? Are the backup records current? Can staff later reconcile ballots issued during the interruption? Can accessible voting continue? Which official is authorized to alter procedures if the outage persists?
A familiar voice is not authentication
AI makes emergency communications harder because election workers and voters may receive convincing synthetic instructions. The EAC advises officials to treat AI-generated text, images, video, and audio as potential impersonation tools and to direct voters toward verifiable official information.
The practical safeguard is not asking a poll worker to become a deepfake expert. It is establishing independent verification channels before Election Day: known contact numbers, authenticated internal systems, predetermined escalation paths, and a second route for confirming unusual instructions.
A familiar voice should not be an authentication protocol.
Public communication needs redundancy, too. The EAC recommends preparing printed information and building relationships with media and community partners for situations in which electronic communication becomes difficult. A useful emergency message should distinguish what is affected, what remains available, and when the next verified update will arrive.
Do not confuse delayed information with failed voting
The postelection period creates another opening for confusion. The EAC explains that election night results remain unofficial even when a website says every precinct has reported. Canvassing, reconciliation, audits where required, and certification follow afterward. A delayed public results page or a longer count is therefore not, by itself, evidence that the election failed.
Law sets another boundary. Federal statute establishes the regular day for House elections, while the 20th Amendment fixes the end of congressional terms on Jan. 3 and presidential terms on Jan. 20. A technical outage does not itself create authority to extend an incumbent’s constitutional term or invent a new federal election date. Emergency procedures must operate within the law governing the affected election.
Test the whole continuity chain
Election-security exercises should therefore test more than whether staff recognize a suspicious email. Start with an electronic poll-book outage. Add a synthetic audio message falsely claiming the polls have closed. Make the election office website unavailable. Remove one communications channel. Then follow the incident through the full operation.
How long did the fallback take? Could eligible voters still receive the correct ballot? Could accessible voting continue? Could officials authenticate emergency instructions? Were records created during the interruption later reconciled? Could voters distinguish what was unavailable from what remained operational? And after the technology returned, what evidence was required before normal procedures resumed?
AI raises the stakes because a future disruption may occur simultaneously in two environments. One is technical. The other is informational. Restoring the server solves only the first problem.
AMERICA IS READY TO FIGHT A CYBER WAR. IT ISN’T READY TO SURVIVE ONE
No continuity plan can guarantee an Election Day without disruption. That should not be the standard.
The continuity question is not whether every screen stays online. It is whether eligible voters can still cast ballots — and whether the final result can be supported by evidence.
Burak Oktenli is based in Washington and studies applied intelligence at Georgetown University. The views expressed are his own.
