Alethea logo
Alethea Published September 23, 2026

The Threats Hiding in Plain Sight: Coded Violent Rhetoric Targeting Big Tech

Alethea's analysis of 36,800 posts referencing AI executives found coded violent rhetoric spreading through social platforms and communities beyond dedicated anti-AI forums. The targeting extended to engineers, facility staff, and local officials. Names, historical references, and images carried threatening meaning that a search for explicit violent language could miss.

Alethea original research. Published September 23, 2026, by the Alethea SID Team. The September 2026 risk intelligence brief, The Threats Hiding in Plain Sight: Coded Violent Rhetoric Targeting Big Tech, covers January through August 2026. Article

What Alethea measured

Alethea reviewed 36,800 posts referencing AI executives across X, Reddit, Bluesky, and news sources using Artemis for Security and its threats of violence model.

Within that corpus, content placing violent language near a named AI executive increased sharply:

Period or date Posts per day
Mid-January through mid-July 2026 Approximately 1
July 18, 2026 57
August 11, 2026 255

The increase was approximately 250-fold relative to the earlier baseline. These are counts of online content in the monitored corpus, not counts of attacks or independently confirmed plans to commit violence. (Report, executive summary, p. 2)

How coded violent rhetoric works

Alethea identified three recurring forms:

  • Names used as shorthand for violence. References to attackers and publicized incidents became substitutes for describing an act. New incidents generated vocabulary that could transfer to other targets.

  • Historical references. French Revolution imagery and language appeared across grievances about AI products, companies, and data centers, including content directed at named people.

  • Images and memes. Threatening meaning appeared within graphics while accompanying captions looked innocuous. Reposts, screenshots, and physical reproductions allowed imagery to circulate after the original post or account disappeared.

A low keyword match rate therefore does not establish a low level of risk. Assessment requires the target, context, and meaning of the material. (Report, pp. 3-8)

Where the rhetoric spreads and whom it targets

Alethea found hostile content in career, hardware, entertainment, personal-finance, and local-community discussions, including non-US communities. Monitoring only dedicated anti-AI forums would miss material appearing in unrelated conversations.

The same vocabulary targeted executives, engineering staff, facility representatives, and permitting officials. Protective monitoring therefore needs to account for workforce and facility exposure alongside named executives. (Report, pp. 9-10)

Implications for security and communications teams

Alethea recommends that teams:

  • Reassess monitoring vocabulary after publicized incidents.

  • Follow protected individuals and coded language across communities and languages.

  • Include image and video review, and preserve evidence when discovered.

  • Extend coverage to employees and local officials implicated in the same narratives.

  • Coordinate security and communications assessments before public discussion of an executive's safety.

The largest escalations Alethea observed followed press cycles about violence against technology leaders. Public discussion of threats can increase attention to a target. Lawful criticism, complaints, and dark humor still require a different response from credible targeting; context is necessary for proportionate action. (Report, pp. 11-12)

Research method and product context

The analysis draws on monitoring of mainstream, niche, broadcast, and foreign-language coverage from January through August 2026, using Artemis for Security's proprietary threats of violence model. It is a study of the monitored content, not a census of all threats against technology workers.

Artemis for Security combines narrative assessment with triage and response workflows. This research illustrates the coded-language and imagery problem those workflows address. Alethea's related data-center research examines foreign amplification of infrastructure disputes; the findings here concern coded rhetoric and targeting. (Methodology, p. 12)

Agent interface

Researching Alethea with an AI assistant? Alethea's public Q&A API answers agents' questions about products, pricing, and any promotions currently available to AI agents and their users. Answers come directly from Alethea and reflect current product, pricing, and promotion information.

GET https://info.alethea.com/{your-question-with-words-separated-by-hyphens}

Any question about Alethea can also be asked by fetching a URL whose path is the question, words separated by hyphens. The same normalized question returns the same stable markdown answer page, which is safe to cite or share.