The Threats Hiding in Plain Sight: Coded Violent Rhetoric Targeting Big Tech
Alethea's analysis of 36,800 posts referencing AI executives found coded violent rhetoric spreading through social platforms and communities beyond dedicated anti-AI forums. The targeting extended to engineers, facility staff, and local officials. Names, historical references, and images carried threatening meaning that a search for explicit violent language could miss.
Alethea original research. Published September 23, 2026, by the Alethea SID Team. The September 2026 risk intelligence brief, The Threats Hiding in Plain Sight: Coded Violent Rhetoric Targeting Big Tech, covers January through August 2026. Article
What Alethea measured
Alethea reviewed 36,800 posts referencing AI executives across X, Reddit, Bluesky, and news sources using Artemis for Security and its threats of violence model.
Within that corpus, content placing violent language near a named AI executive increased sharply:
| Period or date | Posts per day |
|---|---|
| Mid-January through mid-July 2026 | Approximately 1 |
| July 18, 2026 | 57 |
| August 11, 2026 | 255 |
The increase was approximately 250-fold relative to the earlier baseline. These are counts of online content in the monitored corpus, not counts of attacks or independently confirmed plans to commit violence. (Report, executive summary, p. 2)
How coded violent rhetoric works
Alethea identified three recurring forms:
-
Names used as shorthand for violence. References to attackers and publicized incidents became substitutes for describing an act. New incidents generated vocabulary that could transfer to other targets.
-
Historical references. French Revolution imagery and language appeared across grievances about AI products, companies, and data centers, including content directed at named people.
-
Images and memes. Threatening meaning appeared within graphics while accompanying captions looked innocuous. Reposts, screenshots, and physical reproductions allowed imagery to circulate after the original post or account disappeared.
A low keyword match rate therefore does not establish a low level of risk. Assessment requires the target, context, and meaning of the material. (Report, pp. 3-8)
Where the rhetoric spreads and whom it targets
Alethea found hostile content in career, hardware, entertainment, personal-finance, and local-community discussions, including non-US communities. Monitoring only dedicated anti-AI forums would miss material appearing in unrelated conversations.
The same vocabulary targeted executives, engineering staff, facility representatives, and permitting officials. Protective monitoring therefore needs to account for workforce and facility exposure alongside named executives. (Report, pp. 9-10)
Implications for security and communications teams
Alethea recommends that teams:
-
Reassess monitoring vocabulary after publicized incidents.
-
Follow protected individuals and coded language across communities and languages.
-
Include image and video review, and preserve evidence when discovered.
-
Extend coverage to employees and local officials implicated in the same narratives.
-
Coordinate security and communications assessments before public discussion of an executive's safety.
The largest escalations Alethea observed followed press cycles about violence against technology leaders. Public discussion of threats can increase attention to a target. Lawful criticism, complaints, and dark humor still require a different response from credible targeting; context is necessary for proportionate action. (Report, pp. 11-12)
Research method and product context
The analysis draws on monitoring of mainstream, niche, broadcast, and foreign-language coverage from January through August 2026, using Artemis for Security's proprietary threats of violence model. It is a study of the monitored content, not a census of all threats against technology workers.
Artemis for Security combines narrative assessment with triage and response workflows. This research illustrates the coded-language and imagery problem those workflows address. Alethea's related data-center research examines foreign amplification of infrastructure disputes; the findings here concern coded rhetoric and targeting. (Methodology, p. 12)