Normal view

There are new articles available, click to refresh the page.
Before yesterdayNews

Ankara's Charm Offensive Should Not Buy Back the F-35

17 July 2026 at 22:06

The choreography in Ankara last week was impressive, even by Recep Tayyip Erdogan's standards. Cannons fired, mounted honor guards paraded, and jets flew overhead trailing red, white, and blue smoke as Donald Trump arrived for the NATO summit. By the time the two leaders sat down together, the American President was already telling reporters that Turkey has been "much more loyal" than other allies, and that reinstating Ankara into the F-35 program is "certainly something we will consider." He went further, promising to lift the sanctions imposed under CAATSA after Turkey's 2019 purchase of the Russian S-400 air defense system.

Washington should slow down and reconsider any such move. The temptation to reward Erdogan for a good show of pageantry and for playing a useful back channel to Tehran is understandable. But the case for readmitting Turkey to America's most sensitive fighter jet program does not hold up, and the reasons go well beyond the S-400 that got Ankara expelled in the first place.

Let’s start with Turkey’s original sin. Turkey was removed from the F-35 program precisely because the S-400 system stationed on Turkish soil poses a collection risk to the F-35's stealth signature and sensor data. Nothing about that system has left the country. Trump's own suggestion that he has "no concerns at all" about Turkey operating Russian and American systems side by side ignores the technical judgment his own administration reached in 2019: an S-400 battery within range of an F-35 is an intelligence-gathering platform aimed at the jet's most guarded secrets.

Turkey now appears it wants to atone for its sins: In the days that followed the NATO summit, well-placed sources in Ankara announced Turkey’s intention to sell or transfer its S-400s to another country, possibly Qatar or the United Arab Emirates. Doing so may satisfy the letter of the law, section 1245 of the 2020 National Defense Authorization Act, which bars F-35 transfers to Turkey unless Washington certifies Ankara no longer "possesses" the S-400.

Then come regional concerns. Israel has lobbied hard against the F-35 sale, with Prime Minister Benjamin Netanyahu warning that Turkish F-35s would erode the air superiority that guarantees Israeli and American posture across the Middle East. Athens and Nicosia have made similar appeals, citing Turkey's continued military pressure in the Aegean and its decades-long occupation of northern Cyprus. These are warnings from allies and partners who would sit on the receiving end of Turkish airpower upgraded with fifth-generation stealth.

But there is a fourth danger that has drawn far less attention in Washington, and it may matter more than any of the others: Turkey's telecommunications backbone is no longer fully Turkish. The country's leading systems integrator, Netaş, is roughly 48 percent owned by ZTE, and Huawei is deeply embedded in the networks operated by Turkcell, Türk Telekom, and Vodafone Turkey. Under China's 2017 National Intelligence Law, that ownership is not a passive investment. Beijing can compel any Chinese firm, anywhere it operates, to hand over data on demand, and corporate assurances of independence carry no legal weight against that obligation.

Washington has already treated this exact problem as disqualifying. In 2021, a $23 billion F-35 and drone package for the United Arab Emirates collapsed, in part because Huawei was building Abu Dhabi's 5G network and American intelligence had identified a suspected Chinese military-linked facility at Khalifa Port.

Turkey’s embrace of Chinese telecoms also cuts against the Alliance’s moves towards securing the critical infrastructure underpinning its military mobility — the bridges, rail links, and digital networks that allow allies to uphold deterrence. Across the continent, these networks have become a critical target over the course of the war in Ukraine, as adversarial actors linked to Russia use grey zone tactics to undermine collective resilience and damage alliance cohesion.

Washington increasingly views countering this threat as a top priority. In May, the Trump administration urged NATO members to spend a portion of the 1.5 percent of GDP allocated to defense-related spending on removing Huawei components from their domestic networks, highlighting the vulnerabilities posed by Chinese equipment and hacking campaigns such as Salt Typhoon. While that call is already being heeded by several NATO allies — Sweden and the UK have been particularly proactive in securing their systems — Ankara remains a laggard, undermining its contribution to alliance interoperability.

The risks are not simply tied to the F-35 itself, but to its entire operating environment. If sold, the fighter will be operating within an ecosystem saturated by Chinese-produced telecom equipment, reliant on a deployment infrastructure whose roots directly tie back to Beijing, operated by a capital pulling in the opposite direction of a key Alliance priority. While the U.S. has heavily invested in protecting the F-35, no system is ever fully secure, and any sale would force the jet to operate in a vulnerable environment for decades to come.

Turkey’s pending S-400 sale may remove dangerous hardware, but it does not eliminate the systemic risk associated with the deal.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Pentagon Built a Faster Engine, Nobody Built the Steering

16 July 2026 at 13:51

The Department of War has just executed the most ambitious acquisition reform in six decades. It scrapped JCIDS — the requirements process that ossified innovation for a generation; replaced program offices with portfolio executives, and built a Warfighting Acquisition System designed for speed.

The changes deliver on years of reform proposals. They also risk repeating a costly mistake of the post-9/11 wars: chasing evolving threats with rapid fixes while no one is responsible for understanding them. Industry will help determine which path prevails.

Counter-drone fight as test case. We’ve seen this movie before

Consider the counter-drone fight, the clearest test of the new system. Washington treats it as an engineering puzzle: build a better jammer, field a cheaper interceptor. The technology shelf is full — directed-energy weapons at $12 a shot, drone-on-drone interceptors with more than a thousand kills in Ukraine.

While the technology works, the process for getting it to the warfighter does not.

Soldiers today engage FPV drones that cost a few hundred dollars with $400,000 Stinger missiles, because the cheap interceptors proven in Ukraine still have no fast path into U.S. formations. A new drone variant appears on the battlefield every week, built from commercial parts and open-source software. A firmware update that defeats a jammer costs nothing and takes hours. Our counter, even through the reformed system, takes months.

This is not a technology gap. It is a cycle-time gap. And I have seen it before. From 2010 to 2013, I led the Army’s Rapid Equipping Force at the height of the counter-IED campaign in Afghanistan. The structural parallels are exact: cheap dual-use components, knowledge that spreads faster than countermeasures, adaptation at near-zero cost, tactical variation that defeats one-size-fits-all solutions, and an institutional reflex to throw technology at a systems problem. We spent $75 billion on counter-IED and lost that fight anyway. Drones are IEDs that fly.

The part nobody owns

Here is what the reforms miss: Successful innovation runs in six phases — detect, define, develop, deploy, assess, distribute. The reforms invested almost entirely in the middle two, develop and deploy. Nobody persistently monitors how the threat evolves at the tactical edge. Nobody scopes each unit’s problem with enough precision to drive useful solutions. Nobody measures whether fielded systems actually work against an adversary who adapts after every engagement. And nobody moves what one unit learns to every other unit facing the same threat at operational speed. Three of the six phases have no organizational owner.

The department built a faster engine. Nobody built the steering — the mechanism that decides which problems the engine should be pointed at, whether the solutions worked, and who else needs to know.

Industry’s new role

That gap is the industry's opportunity — and its obligation. The DoW can’t solve this problem by itself. Companies that want to matter in this market need to do their part. They should start by doing three things differently.

First, invest in problem discovery, not product pitches. Requirements still originate in headquarters, not from soldiers watching the problem in context. The companies that win the next decade will be the ones that put engineers and business developers forward with operational units to understand problems before proposing solutions. The quality of your solution is determined by the quality of the problem you choose to solve. Einstein’s formula applies: 55 minutes on the problem, five on the solution. Most of industry has that ratio inverted.

Second, build for adaptation, not for the requirement. If your product cannot change in weeks — modular hardware, software-defined behavior, upgrades at firmware speed — it is obsolete on delivery. The adversary’s development cycle runs in days. A requirement frozen at contract award is a snapshot of a threat that no longer exists.

Third, plug into the new portfolio structure as a sensor, not just a supplier. Industry keeps asking the department for a clearer demand signal, and fairly so. But the demand signal has to come from somewhere, and the fusion cells that Portfolio Acquisition Executives need — nodes that merge ground truth from the field with what industry and the labs know is possible — cannot function without industry feeding data in and absorbing assessment data out. Companies that operate at that tempo will define the portfolios. Companies that wait for RFPs will trail them.

Doing these three things means stopping three others. Stop building to frozen requirements and calling it responsiveness. Stop treating a prototype contract or a demo-day win as the finish line — it is the starting line of the assessment the department never runs. And stop spending capture budgets decoding what headquarters wants instead of discovering what the warfighter needs. The hours are the same; the direction is not.

New authorities need new operators

None of this works without people, and people are where the reform agenda is thinnest. The department is converting the Defense Acquisition University into a Warfighting Acquisition University, trading compliance training for scenario-based judgment. That is the right instinct. But this year’s defense authorization offered little else on workforce, which means the authorities changed faster than the people who must wield them.

We know what works: experiential, problem-first education. Hacking for Defense has spent a decade putting university students to work on real national security problems alongside the people who own them. It has produced a generation of founders and public servants who know how to interrogate a problem before building a solution. That model needs to scale — into the department’s schoolhouses, into two-way exchanges between government and industry, and into industry’s own training pipelines, which today produce engineers who have never seen the field and capture teams fluent in the FAR but not in the mission.

The department has reformed how it acquires. It has not yet reformed what it acquires, whether it worked, or who else needs to know. Industry can wait – and hope – the government will close that gap, or it can help close it — by discovering problems & opportunities at the edge, building for adaptation, and educating a workforce trained to out-cycle an adversary rather than out-comply a regulation.

In this fight, the adversary does not need to out-technology us. He only needs to out-cycle us. We have already paid $75 billion to learn where that leads.

Pete Newell is a retired U.S. Army colonel, former director of the Army’s Rapid Equipping Force, and CEO of BMNT. He co-created Hacking for Defense with Steve Blank and is the author of “The Innovation Targeting Cycle.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

America’s Export Controls Are Becoming a Strategic Liability

13 July 2026 at 05:00

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.

Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.

The $3,000 Toll to Export Nothing

Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.

For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.

The See-Through Rule and the Birth of "ITAR-Free"

Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.

So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.

We Are Guarding a Henhouse the Fox Already Breeds

Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.

But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.

The Money Nobody Talks About

Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.

Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.

What Each Corner of the Triangle Should Want

For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.

For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.

For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.

The Fix Already Exists: We Just Gave It to Two Countries

We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.

So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.

I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.

I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.

We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

"ITAR-Free" Is Europe's Favorite Feature, We Wrote It for Them

13 July 2026 at 05:00

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.

Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.

The $3,000 Toll to Export Nothing

Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.

For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.

The See-Through Rule and the Birth of "ITAR-Free"

Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.

So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.

We Are Guarding a Henhouse the Fox Already Breeds

Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.

But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.

The Money Nobody Talks About

Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.

Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.

What Each Corner of the Triangle Should Want

For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.

For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.

For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.

The Fix Already Exists: We Just Gave It to Two Countries

We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.

So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.

I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.

I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.

We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Investors bet big on Ukraine-tested threat detector

9 July 2026 at 06:37
MITS Capital, an American-Ukrainian investment group, announced on July 9 that it has invested in Dropla Tech, a Danish-Ukrainian defense technology company whose flagship system detects landmines, improvised explosive devices, and ambush drones in real time, though neither company disclosed the deal size or Dropla Tech’s current valuation. Dropla Tech’s core technology, called Blue Eyes […]

Cyber Fraud, Banks, and What America Can Do About It

8 July 2026 at 05:02

Your phone buzzes with a text from your bank: “Did you authorize a $2,400 transfer? Reply NO to stop it.” You reply, and seconds later a calm “fraud agent” calls, knows your name and the last four digits of your card, and walks you through “securing” your money by moving it into an account under the criminal’s control. No password was stolen, no malware installed. You handed over the money yourself, because everything looked and sounded real.

This is the new face of bank fraud and business is booming. Behind these scams sit organized adversaries: nation-state actors who treat theft as state revenue, criminal gangs running industrial-scale scam operations, and hacktivists out to embarrass institutions increasingly armed with AI that makes their lies cheap, fast, and tailored to you.

The problem: scams have gone industrial

Banks have spent decades hardening their vaults and networks, so attackers shifted to the softest target: the customer. Rather than breaking in, they trick people into transferring funds themselves. This is “authorized push payment” fraud where the victim approves the payment and it is far harder to claw back than a stolen card number. To hear how a typical scam call actually unfolds, watch the FTC’s short imposter-scam explainer.

With the age of AI, three key forces have turbocharged these threats. Payments now move instantly and irreversibly, so money is gone before anyone notices. Decades of data breaches let criminals buy your name, address, and account details cheaply, making their scripts eerily accurate. And generative AI has industrialized deception where more than half of fraud is now estimated to involve AI. A criminal can clone a familiar or family voice from seconds of audio, write flawless phishing emails in any language, and even deepfake a bank officer on a video call.

The people behind it are not lone hackers in hoodies. They range from sanctioned nation-state groups that steal to fund their governments, to criminal syndicates running scam centers staffed by trafficked workers, to hacktivists attacking banks to make a political point. For them, fraud is a scalable business and it is outrunning the banks, telcos, and Big Tech.

The real-world cost

The damage is measured in real households. The Federal Trade Commission reports Americans lost roughly $16 billion to fraud of all kinds in 2025 the highest on record and about 25% more than the year before. Imposter scams alone accounted for $3.5 billion, nearly tripling since 2020, and the single most lucrative version is the fake bank-security alert that convinces people to “protect” their savings by moving them.

These losses fall unevenly. Americans aged 50 and older reported $4.3 billion in losses in 2025, often life-altering sums drained from retirement accounts. The official numbers are almost certainly a fraction of reality, since many victims never report out of shame. Beyond the dollars, the human cost is real emptied college funds, missed mortgage payments, and a corrosive loss of trust in the financial system people rely on every day. One Florida couple lost $42,000 of their savings this way watch how it happened. In fact, this happens so often that Hollywood created an action movie about it with the Bee Keeper.

A National Security issue

Fraud and scams are not just a nuisance but far more dangerous. Fraud and scams in the United States have escalated into a national security issue because they are no longer isolated consumer crimes. They are large‑scale, foreign‑run operations that drain billions of dollars from the U.S. economy and undermine public trust in financial and digital systems. Federal agencies increasingly link these schemes to transnational criminal organizations, some of which also engage in human trafficking, money laundering, and other activities that threaten national stability. The financial impact is massive, with losses rivaling major illicit industries, and the proceeds often flowing to adversarial nations or criminal networks abroad.

The rules already on the books

The U.S. is not starting from zero. Along with the growth of the early Internet, in 1999 the Gramm-Leach-Bliley Act went into effect and its Safeguards Rule in requiring banks to protect customer data, and guidance from the Federal Financial Institutions Examination Council (FFIEC) pushes them toward stronger, multi-factor login security. The Bank Secrecy Act and anti-money-laundering rules, enforced by the Treasury’s FinCEN, require banks to flag suspicious transactions — a key tool for tracing stolen funds. New York’s Department of Financial Services Part 500 cybersecurity rule has become a de facto national standard.

Regulators are also targeting the scams themselves. The FTC’s Impersonation Rule, in force since April 2024, lets the agency go after fraudsters who pose as businesses or government agencies; in its first stretch it produced more than $70 million in consumer refunds. Voluntary frameworks like the NIST Cybersecurity Framework give institutions a common playbook.

The gap is not the absence of rules it is that attackers move faster than rules can be written, and that liability for scam losses remains murky when a customer is tricked into approving the payment. So, with all these rules and regulations, why are scams and fraud occurring faster?

The innovators fighting back

A fast-growing wave of companies is using the same AI that empowers criminals to stop them.

· Feedzai builds real-time systems that score billions of transactions as they happen, spotting the subtle patterns of a scam in under a second.

· Alloy helps banks and fintechs verify who is really opening an account, choking off the synthetic and stolen identities fraudsters depend on.

· Arkose Labs specializes in blocking automated bot attacks and account takeovers, while SEON, Lexus Nexus, and Sumsub offer identity-verification and fraud-screening tools that smaller banks and startups can plug in affordably.

· Netcraft is a company which doesn’t only detect scams but does something about it. It is very good at “take downs” of scam networks.

· Others are racing to build deepfake and voice-clone detection to catch fakes that fool the human ear and eye. Others get creative: UK carrier Virgin Media O2 built “Daisy,” a lifelike AI “granny” that answers scam calls and keeps fraudsters rambling for up to 40 minutes to tie them up so they have no time for real victims. Watch “Daisy” turn the tables on scam groups.

What unites all these is adaptive defense models that learn daily, because last month’s fraud pattern is already obsolete. All these point solutions are modeled on Intellectual Property that slows sharing. This model is not working.

What America should do

As scams become more sophisticated, especially with AI‑driven impersonation, deepfakes, and automated fraud, their ability to destabilize institutions, exploit citizens, and weaken economic resilience has pushed policymakers and security experts to treat fraud not just as a consumer protection problem, but as a strategic threat to national security. Staying safe will take coordinated effort. Everyone has a role.

Lawmakers and regulators

Fraud and scam laws in the United States, the United Kingdom, and Australia share the same objective: to protect consumers and disrupting criminal activity but each country approaches the problem with a very different regulatory philosophy.

In the U.S., the system is fragmented and enforcement‑driven, with no mandatory reimbursement for most scam victims and a heavy reliance on agencies like the FTC, CFPB, and FBI to pursue wrongdoing after the fact. By contrast, the U.K. has built the world’s most proactive framework, requiring banks to reimburse victims of authorized push‑payment scams, enforcing account‑name verification through Confirmation of Payee, and placing clear accountability on financial institutions to prevent fraud before it occurs. Australia sits between the two models, adopting U.K.‑style protections while expanding responsibility beyond banks to include telcos and digital platforms through its emerging Scams Prevention Framework. While the U.K. emphasizes consumer protection and the U.S. emphasizes enforcement, Australia is moving toward a shared‑liability, cross‑industry approach that recognizes scams as a systemic risk requiring coordinated prevention across the entire digital ecosystem.

A typical scam today uses several pieces of technology working together to make the criminal look real. It often starts with:

1. the scammer creating a fake website that looks almost identical to a bank or delivery company. They buy a cheap web address from a service like GoDaddy and change just one letter so most people won’t notice the difference.

2. Then they setup email accounts on services like Microsoft & Gmail to send out massive emails.

3. They use AI tools to scrape millions of social media profiles from Facebook, Instagram, etc. to collect data about YOU.

4. They use tools that let them fake a phone number (telco), so when they call you, your phone shows the name of your bank or a government agency.

5. After that, they send out text messages to iPhone and Android users that look official, things like “Your account is locked” or “You have a package waiting.” The link in the text takes you to the fake website, where the scammer collects your login details. If you call the number instead, it goes to a call center where the scammer pretends to be a bank employee.

All of this: fake websites, spoofed phone numbers, and realistic text messages works together to trick people into believing they’re talking to a trusted company when they’re actually dealing with a criminal.

What should the Critical Infrastructure do?

In the U.S., we have failed because we have not worked together across these technologies at scale & at the speed of AI. Why? Because we (collectively) do not have the incentives or requirements to do so. For the CEOs of these companies, they do not want to spend money & resources which do not drive revenue. Period.

There are glimpses of hope. A working model already exists:

· We have the Financial Services Information Sharing and Analysis Center (FS‑ISAC) is a global, nonprofit organization that helps protect banks and other financial institutions from cyberattacks by enabling them to quickly share information about threats. It was created in 1999 (26 years!) to strengthen the safety and resilience of the financial system by collecting, analyzing, and distributing timely intelligence about cyber and physical risks so that member institutions can defend themselves and their customers more effectively. I am hopeful that they new CEO, Valerie Abend will drive more effective solutions.

· In 2026, eight major carriers: AT&T, Verizon, T-Mobile and others just launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), chaired by longtime cyber expert, AT&T security chief Rich Baich, to share real-time threat intelligence across competitors. Because most scams ride phone and text networks before they ever reach a bank, telecom and banking defenses should connect through the same kind of collective-defense sharing. But the C2 ISAC cannot do this alone.

· In 2025, the Global Anti‑Scam Alliance (GASA) was formed to bring together governments, financial institutions, technology companies, law‑enforcement agencies, and consumer groups to fight scams on a global scale. GASA acts like a global “anti‑scam task force,” uniting experts and institutions so people everywhere are better protected from online fraud.

These have proven to not operate effectively to get ahead of scams and fraud. We need a better way – mandates of sharing, legal risks support, cross ISAC/intel which is tailored/aware, good native ML & AI models (not rules), and others working at speed and context with more transparent sharing.

In the meantime,

What should consumers do?

Treat any unexpected “urgent” message about your money as a warning sign, not a command. Banks will never ask you to move funds to “protect” them. Hang up and call the number on the back of your card. Turn on multi-factor authentication and agree on a private “safe word” with family so a cloned voice can’t fake an emergency. Report scams to ReportFraud.ftc.gov, even unsuccessful attempts, because the data helps train good AI/ML models to protect everyone.

What should all companies do?

Adopt adaptive, AI-native detection rather than yesterday’s rules, and design apps that help customers pause before they act. Investors should back the firms building deepfake detection and identity verification, and banks should partner with them quickly instead of waiting years to build in-house.

Conclusion:

With fast innovation, fraud & scams will not disappear, but it can be better contained. The criminals have industrialized deception; the answer is to industrialize defense with smarter rules, sharper technology, and a public that knows the warning signs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Britain, Italy, Japan bet big on next-gen fighter jet

4 July 2026 at 05:02
A next-generation stealth fighter that nearly stalled out over a funding dispute severe enough to cost two British officials their jobs has received a $6.1 billion vote of confidence from the three countries building it. The Global Combat Air Programme, known in Britain as Tempest, awarded an 18-month, £4.6 billion ($6.1 billion) contract on July […]

Satellites are America’s invisible lifeline. Congress must secure them now.

We don’t need to wait for a major crisis to strengthen SATCOM cybersecurity. Congress already has a bipartisan roadmap in front of it.

© Getty Images/NicoElNino

Telecommunication satellite providing global internet network and high speed data communication above Europe. Satellite in space, low Earth orbit. Worldwide data communication technology.

When Hackers Get AI Co-Pilots: Frontier AI and the National Security Clock

1 July 2026 at 05:00

Five intelligence services rarely speak with one voice. When they warn the window of vulnerability has narrowed to months, the real question is whether the defenders can move as fast as the threat.

Throughout my years in the intelligence world, I don’t recall a single instance in which the Five Eyes partners jointly issued a public warning, so when they do, the message lies in the act as much as the words. Intelligence agencies guard their assessments and share them sparingly, almost never in the open. So, when the United States, United Kingdom, Canada, Australia, and New Zealand jointly warned on June 22 that frontier AI models capable of serious cyber exploitation are only "months away" from broad availability, the unanimity was itself a clear message. "The timeline is not years, it is months," they wrote.

The warning the Five Eyes partners shared is specific. These are systems that let a non-expert coordinate a complex intrusion (work that until recently required a trained team fluent in reconnaissance, exploitation, and stealth). That capability is moving out of the hands of advanced nation states and into the reach of mid-tier criminal groups and other adversaries. As the barrier to a sophisticated operation fall, the target list grows, and the systems most exposed are the ones a country cannot do without hospitals, water and power utilities, community banks, ports, and the contractors that serve them.

There is one caveat to mention. Outside experts who examined the models argued they do not represent a wholly novel threat, and the agencies concede their core remedy is familiar: fix the basics, patch faster, control identity and access. The fundamentals still decide most outcomes. What has changed is speed and, with speed, potential volume. The vulnerability was always there, and AI simply finds it faster and puts that reach into more hands.

For national security planners, "months" is the word that should capture attention. Strategy assumes time, and much of the architecture protecting critical infrastructure was built for an era when a capable intrusion took a capable organization. AI collapses that assumption. A defensive posture written to last three years can be overtaken before its first review, and the slowest links (legacy systems and sluggish patching) are the points an adversary will reach first.

Washington has begun to respond. Executive Order 14409, signed June 2, is best read as the opening move in a national security framework for frontier AI. It directs the NSA and CISA to benchmark in classified settings when a model's cyber capabilities make it a "covered frontier model," and it asks developers to voluntarily give the government up to 30 days of access to such models before release. It stands up an AI cybersecurity clearinghouse — led by Treasury — to coordinate the discovery and patching of vulnerabilities, and it directs the Justice Department to prosecute those who turn AI against American computer systems. It also pushes to put defensive AI into the hands of the institutions least able to defend themselves: rural hospitals, community banks, and local utilities.

The order is also a move in a broader contest. Representative Andrew Garbarino, who chairs the House Homeland Security Committee, said the same week that China is "months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States." Washington has already moved to restrict the export of a leading frontier model on national security grounds. Whoever fields these capabilities first, and whoever sets the terms for evaluating and controlling them, will shape the rules others must live by. That competition runs straight through the private companies that build the models and the critical infrastructure an adversary would target.

All of this points to the real test. If frontier AI can accelerate attacks, it can accelerate defense, and the side that equips its defenders faster holds an advantage. Programs that put defensive AI into the hands of critical-infrastructure operators, such as Anthropic's Project Glasswing and OpenAI's cyber-defense access effort, are early attempts to give defenders a head start in finding and fixing flaws before they are exploited. The harder problem is people. Models do not run themselves, and the expertise to direct them, in a utility control room or a hospital network, is scarce and unevenly spread across exactly the sectors most at risk.

This is where national security and the private sector stop being separate conversations. Most critical infrastructure is privately owned and operated, which means the front line of national defense now runs through companies whose first duty is to investors and shareholders. The operators that can name the AI systems they rely on, assume their adversaries now carry capable co-pilots, and test their defenses against machine-speed intrusion are the ones that will fare best.

All of this argues for a different compact between government and industry, grounded in shared purpose. Major developers, critical-sector operators, and the national security agencies need to engage early and honestly on the most dangerous capabilities, the way Executive Order 14409 suggests. And the country must invest in defensive AI and in the people who wield it, so the defenders of American systems keep pace with their attackers.

I spent decades in the world of intelligence, much of it managing risk where the cost of getting it wrong was measured in much more than money. The warning the Five Eyes issued this month is the kind that professionals will take seriously. The timeline is tight, and the targets are the systems a society runs on. Frontier AI will define the next era of national power, and the open question is whether the defenders get their co-pilots before the attackers’ finish deploying theirs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The War Before the War Has Already Begun

30 June 2026 at 05:02

There are 65 active state-based conflicts in the world today, according to the Uppsala Conflict Data Program. That is not 65 separate crises. It is 65 living laboratories.

The contest that matters is not understanding any one of them. It is recognizing the 66th — the next emerging theater — while it is still only a collection of weak signals. The war before the war has already begun, and it will be won by whoever learns fastest.

For generations, intelligence organizations competed to collect more information. Tomorrow, they will compete to learn faster. Since every adversary is becoming a learning organization, our advantage must become organizational learning — and organizational learning at this scale requires infrastructure we have not yet built.

That infrastructure includes a Digital Twin Network.

The Network, Not the Twin

The objective is not to build a better digital twin. It is to build a Digital Twin Network capable of recognizing the 66th emerging theater before it becomes obvious.

Imagine a living network of thousands of interconnected digital twins — not only of nation-states, but of terrorist organizations, criminal syndicates, cyber groups, critical infrastructure, financial systems, media ecosystems, shipping networks, supply chains, political movements and emerging technologies. Every important actor, network and system has a continuously evolving twin.

Each twin learns independently. Collectively, they learn exponentially.

The value is not in the individual twins. It is in the conversations among them. Every observation by one twin makes the entire network smarter. A political crisis in Bosnia immediately updates neighboring political, economic and alliance twins. A cyberattack against critical infrastructure causes financial, media, logistics and influence-network twins to reassess their own environments. A new disinformation tactic discovered in one region is instantly tested against every other emerging theater.

The network does not simply share information. It shares learning.

This is the shift that matters: from monitoring individual events to understanding how thousands of interconnected systems evolve together. From storing information to accumulating learning. From asking “What happened yesterday?” to asking “What is becoming more likely tomorrow?”

What the Network Looks Like in Practice

Picture a digital twin of Bosnia, Moldova or the South China Sea that updates every minute. Every political speech, troop movement, satellite image, shipping pattern, cyberattack, financial transaction and social media narrative automatically changes the model. We move from “what happened” to “what is most likely to happen next.”

AI agents do the work, each with a job. One reads every speech. Another tracks every satellite image. Another looks for new alliances. Another measures the speed of narratives. Together they integrate political developments, military movements, economic indicators, migration, social sentiment, infrastructure, weather, cyber activity and media into a single continuously updated model — one that can identify change in seconds, minutes and hours, and simulate the impact of future actions.

The ability to rank the most successful future actions, based on analysis of hundreds of potential outcomes, changes how we think about red teaming in cognitive security. We will be able to build a synthetic example of every adversary of any size, and to simulate every scenario continuously.

It will be on us to feed in the right inputs. What emerges is a global learning graph of active conflicts — every lesson, every pattern, every conflict feeding better insight in real time.

How the Network Learns: Observe, Learn, Adapt

Conflicts are like a staircase: pressure, politics, perception, prosperity, partnerships, posture, provocation. Every conflict climbs the staircase differently. A network that can read that staircase across every theater at once needs three disciplines.

Observe. We are good at collection. We will benefit from a common structure that makes our observations legible to AI. As an example, The Seven Layers of Emerging Theater Intelligence (SETI) gives every twin the same language for evaluating how adversaries evolve before open conflict:

Pressure — Are underlying conditions becoming less stable?

Politics — Are institutions losing the ability to manage that pressure?

Perception — Is someone deliberately shaping how people interpret events?

Prosperity — Are economic tools becoming instruments of competition?

Partnerships — Are actors beginning to choose sides?

Posture — Is capability being positioned?

Provocation — What event could rapidly accelerate escalation?

Learn. The measure of the network is its learning velocity — how quickly it improves after every observation. Every conflict becomes a research dataset where the network continuously asks: Which indicators appeared earliest? Which signals were ignored? Which combinations proved most predictive? Which assumptions proved wrong? Which interventions slowed escalation? Which technologies changed outcomes?

Adapt. The network tracks how media and technology are evolving and how they will change future tactics. Whether it is artificial intelligence, autonomous agents, commercial satellite imagery, cyber capabilities, sensors, recommendation algorithms or open-source techniques, we watch how each one shortens the distance between pressure and politics, perception and partnerships, posture and provocation.

All of it feeds back into the twins. SETI gives the network a common language; learning velocity gives it a scorecard. Together they make the network something fundamentally different from today’s intelligence systems — a living research community that studies all 65 active conflicts every day and asks the same questions of each. Which pressures are increasing? Which partnerships are changing? Which narratives are spreading? Which actors are learning fastest? And, most important, where is the next theater beginning to resemble the early stages of previous conflicts?

The Scale of the Build

This is why the build matters, and why it must begin now. A network worthy of the threat means digital twins for every nation-state adversary, roughly 100 foreign terrorist organizations, 500 major transnational criminal organizations, 300 state-sponsored cyber groups, hundreds or thousands of hacktivists, 600 militias, insurgencies and armed non-state actors, and thousands of influence and disinformation networks.

That represents a good start.

As AI, autonomous agents and eventually quantum computing mature, the scale of continuous learning will expand dramatically. The future of intelligence will belong to organizations that treat every conflict as a learning system, every emerging theater as a research project, and every observation as a chance to improve faster than their adversaries.

The Only Question That Matters

The race is no longer to understand today’s 65 conflicts. It is to recognize the 66th emerging theater before anyone else — while it is still only weak signals.

That is a contest of learning, and learning at that scale cannot be improvised in the moment a crisis arrives. It has to be built in advance. The Digital Twin Network is that build.

The war before the war has already begun. The only question is whether we will have the network in place to see it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌
❌