A voter walks into a polling place, fills in ovals on a paper ballot, and feeds it into a scanner. The paper stays in a locked bin. That paper is supposed to be the safety net: if the machine gets the count wrong, someone can always go back and look at what the voters actually marked.
But what if the voter was handed the wrong ballot in the first place, one missing a contest they were entitled to vote in, or listing a race in a district they don't live in? Then the paper is wrong too, and no amount of careful recounting will reveal it.
That gap is the heart of a new paper by Aleksander Essex and Philip B. Stark, posted to the arXiv preprint server on July 29, 2026, and slated to appear in the proceedings of E-Vote-ID 2026. The two researchers have spent years on election security, and their motivation here is unusually practical. In their work with election jurisdictions, they write, they keep running into officials and other stakeholders who have not fully absorbed the possibility that a tabulator, the scanner that reads and counts ballots, can simply be wrong.
Hypothetical hackers versus documented mistakes
Most of the research literature on voting technology is about attackers: what a malicious insider could do, how a scanner might be tampered with, what a well-resourced adversary could accomplish. Essex and Stark note that this framing has a persuasion problem. Stakeholders often find hypothetical attacks unconvincing. Show them a hacker scenario and they hear speculation. Show them a real incident where equipment or procedure failed in an ordinary election, and some of them listen.
So the authors changed the argument. Instead of building another threat model, they built a taxonomy of things that go wrong when nobody is trying to make them go wrong, and they illustrate each category with documented incidents that have actually occurred.
Their organizing scheme follows the life of a vote through the system. First, recording votes on paper: everything that happens as a voter's intent gets committed to a physical ballot. Second, reading votes from the paper: the scanner interpreting the marks. Third, combining votes as read into a reported outcome: the aggregation and arithmetic that turns individual interpretations into a winner. And fourth, testing and verifying: the checks meant to catch problems in the first three, which can themselves fail.
It is a deliberately intuitive breakdown, and that seems to be the point. A taxonomy that an election official can hold in their head is more useful than one that only a specialist can parse.
The failures a recount cannot fix
The more pointed contribution comes next. Essex and Stark map the standard verification mechanisms, the audits and recounts and logic tests that jurisdictions rely on, against their taxonomy, and look for the blank spots. They find failures that no paper-based audit can detect or correct.
The common thread among those blank spots is that they damage the trustworthiness of the paper trail itself. The authors highlight three. One is the wrong-ballot-style problem: a voter receives a ballot that omits contests they are eligible for, or includes contests they are not. Whatever they mark, the paper record is already a flawed record of what they were entitled to decide.
A second is the use of ballot-marking devices to record votes. These are machines that print a voter's selections onto paper rather than having the voter mark it by hand. If the printed record does not match what the voter chose, and the voter does not notice, an audit of that paper faithfully confirms the machine's version of events.
The third is mundane and, for that reason, easy to underrate: failing to keep voted ballots secure and organized. An audit assumes the ballots you pull from the bin are the ballots the voters cast, all of them and only them. Lose that assumption and the audit is checking arithmetic against an unreliable pile of paper.
Why it matters
The practical upshot is not that optical-scan voting is unusable. It is that paper alone does not finish the job. Auditing the paper is the standard remedy offered when someone questions a machine count, and for a large family of errors that remedy works. Essex and Stark's argument is that a specific set of failures sits upstream of the paper, and that the standard remedy is silent about them by construction. Knowing which problems your audit cannot see is a different kind of knowledge from knowing that you have an audit.
There is also something worth noticing about the rhetorical strategy. The authors are making an argument about how to talk to the people who run elections. Adversarial threat models, however rigorous, can read to a practitioner as a story about someone else's problem. A list of things that have already broken, in real jurisdictions, without villains, is harder to set aside.
This is a preprint, and it is a conceptual and organizing contribution rather than an experimental one. It reports no new measurements and offers no estimate of how often any of these failures occur or how many results they have changed. What it offers is a map, including the parts of the territory that current verification methods do not cover.