❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Cipher Brief

A Master List of Espionage Targets, Suspected Spies, and Potential Recruits

16 July 2026 at 05:00

It was with alarm that I read the recent New York Times article reporting the regurgitation of a truly terrible idea that, like a bad meal, continues to come up every several years.

The Times reports that the Office of the Director of National Intelligence

is demanding that American intelligence officials turn over the names of all foreign espionage targets, including suspected spies and potential recruits, to create a master list, to avoid inadvertent conflicts between agencies and to better track foreign intelligence threats in real time.

A primary task of any corporate security department or Federal counterintelligence activity is to prevent, deter, and detect human and technical compromises of sensitive information. Even innocent errors can result in massive damage when they reveal sensitive information. Nor is it a secret that any large organization, no matter how carefully it screens its people, may have persons in its ranks who would betray their colleagues and their country. And of course, malign foreign actors routinely seek to access U.S. information systems and classified computing resources.

Just as a comprehensive list of CIA employees, including covert officers serving in dangerous locations, would be of great value to any number of foreign adversaries, so too would the proposed list of espionage targets, suspected spies, and potential recruits. And the drawbacks associated with creating such a list are significant - and potentially catastrophic.

The mere process of assembling the relevant data from within separate departments and agencies would require the assembling of multiple intermediate lists -for example, all subjects of interest from multiple operating components of the FBI, CIA, and additional agencies, each one of which would pose a separate significant and potentially catastrophic counterintelligence vulnerability. Compiled into a single comprehensive set, the theft or leak of the combined list would work incalculable damage to the United States.

Similar proposals have been made for decades. At the very best, they are a solution in search of a problem; for every time two or more agencies trip over one another in the pursuit of intelligence opportunities, there are literally hundreds more occasions in which the existing deconfliction arrangements work exactly as they should.

I spent several years in an ODNI policy position when the Office was first created. From time to time I encountered colleagues from one or another part of the Government, or from outside the Government completely, who sought to establish policies and procedures to address some obscure, long-since resolved, or simply imagined pet peeve. While some concerns truly reflect structural obstacles and warrant serious consideration, sometimes the most responsible thing to do is simply draw the line and withdraw a truly bad proposal. This is one of those times.

Jonathan M. Fredman is a Non-Resident Fellow at the Princeton University School of Public and International Affairs. He spent 36 years in legal and policy positions at the Central Intelligence Agency and the Office of the Director of National Intelligence.

All statements of fact, opinion, or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in the contents should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author's views.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Washington’s Spy Ring and Paine’s Democracy

14 July 2026 at 05:01

Agent 711 was one of the most effective and least known spies in our nation's history. He used dead drops to communicate about enemy plans. He used secret chemical processes to create new forms of invisible ink. He spread disinformation to disguise his own troops' movements and confuse the enemy. The year was 1778. Agent 711 was George Washington. He was our nation's first spymaster, and his network of informants was the Culper spy ring. It was one of several that he ran through the war and also during his time as president. Washington's army was undermanned, underfunded, frequently on the run. He knew he needed an edge, and he found it with intelligence. A British intelligence officer later said Washington did not really outfight the British β€” he simply outspied us.

At the same time, as a young nation was leaning heavily into its very first intelligence community, Thomas Paine was inspiring a nation to democracy. He had ideas about equality, rights, and the limits of government β€” revolutionary ideas for the time. He had ideas about power: it was not a divine right handed down to a monarch, but power rested in the hands of the people. Government borrows that power for a time, within limits. The representatives of that government are meant to be of the people and return to lives among the people, not to be separate or above or disconnected from what's going on among them.

Thus, our nation was born, not out of a tension between intelligence and democracy, but as an alchemical mix of both. We carry these ideas forward into a modern context. Power rests with the people. They loan it to the government. We trade some of our liberty for things that no one person can provide β€” roads, the power grid, police, submarines, national security. In exchange, we demand things of our government: accountability, adjustments, change, transparency. But we also demand security, and we demand economic prosperity. That's the life, liberty, and pursuit of happiness part.

It's easy to forget that there are still those in the world who wish to take these things away from us. It's also in part generational β€” today’s college graduates were not alive during 9/11 or had maybe just been born. There are still terrorists and cartels who wish to take life. China seeks to take liberty β€” they want to subjugate people to their will, as they've done in Tibet, in Hong Kong, as they're attempting to do in Taiwan. Russia wants to end the pursuit of happiness. Some men truly do just want to watch the whole world burn to make themselves feel better, and Putin is one of those. Rather, they want happiness on their terms. This looks like power for the elite few oligarchs around Vladimir Putin, while he sends the poor to fight his war in Ukraine. It looks like the ruling elite of the CCP and their little princelings. They want order. They want to take liberty to hold power. The state has shown, in their case, security, but only for the few.

Why? Because liberty is messy. It is a struggle. It's making our own way while everyone else does the same. It's making space for ourselves and for each other, and when those spaces conflict, we figure it out. Thomas Paine wrote that β€œwhen we speak of rights, we ought always to unite them with the idea of duties β€” rights become duties by reciprocity: the right which I enjoy becomes my duty to guarantee to others, and he to me.” So today we are the guarantors of each other's rights. In Paine's time that looked like representative democracy and a little bit of revolution. Today, specifically with regard to spy work, it is a hard concept to wrap your head around β€” it's actually protection of rights by proxy.

In my pocket I carry a coin β€” the first one made for the Senate Intelligence Committee, on which I served for six years. On one side is Washington's seal, to represent our very first spymaster and to honor the intelligence officers who were so instrumental to the birth of this nation. But there are also two sets of stars on this coin. There's a set of 15 around the outside that represents the 15 members of the Senate Intelligence Committee, who represent the entirety of the Senate. And then on the other side there are a hundred stars representing the Senate as a whole.

Why are there two layers? The 100 senators represent the entire country. The 15 members of the committee represent the Senate. Just as Washington went to great pains to encode secret messages and hide what he knew from the British army, secrets today must stay secret β€” the more people who know a thing, the less likely something is to stay secret. The intel committees are there to be the eyes and ears of the entire Senate or the House, and by extension the nation. These committees were designed to bring things back into balance.

During the 1960s and 1970s, another time of intense national upheaval, the IC got way out of hand β€” spying on political figures like Martin Luther King, attempting assassinations of foreign leaders, and engaging in massive propaganda campaigns. The Church and Pike committees united to investigate and create both the Senate Intelligence Committee and the House Intelligence Committee, to provide permanent, comprehensive oversight to keep this balance.

People who don't know intelligence work think that it's all-powerful and full of abuse. They see the spy thrillers that are in the movies. They think the 1970s continue today. But people who do know it, know it's a microcosm of liberty. It's messy. It's flawed. But it's also full of checks, balances, and people doing the right thing. These are my friends and former colleagues. They look like me. They look like you. They miss dinners with families. They put themselves in harm's way. They don't get parades. They don't get early boarding on flights. They don't get military discounts. They just do the work.

For us as a country, I fear there are rough seas ahead. We face two revisionist powers that, like King George III, believed that one person should be in charge through might alone. These people want to set up a false choice: freedom or security, not both. But the truth is that freedom and security are deeply intertwined. It is fear that leads to that false choice. On the one hand, dictators fear chaos β€” they think that people will come to understand that their oppressive dear leader does not, in fact, have their interests at heart. The supposed strongman is actually terrified. He's desperate to hold on to power. On the other hand, amongst some, there is fear the security mission will take over and become too big, too powerful, lodged in the hands of someone who is too power-hungry. But the goal is balance. We need Washington's spy ring. We also need Paine's ideals. And we need them working together.

One further reflection on that Paine quote: the rights I enjoy, I also guarantee to others. This is perhaps most true for those who operate in the shadows. They guarantee the rights of fellow citizens day in and day out, with a million small decisions, even when no one is watching. Democracy enables good spy work β€” only in a democracy can you walk into the Oval Office and deliver truly terrible news to power, tell the president things have gone sideways, and work together to fix it.

Spy work also makes democracy possible. I look forward to a day where there are no enemies; no one who seeks to assert ultimate power over others. That day I will have happily worked myself out of a job. But it is not today. Today I am fully employed attempting to create deterrence, know our adversaries, create a future of peace through strength. I have sworn an oath to support and defend the Constitution four times in my life, and hopefully one day I'll do it a fifth, but inside government or out, trying to work for democracy, for freedom, for a secure America and a secure world is the mission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Evo: Bolivia and the Erosion of State Authority in Latin America

9 July 2026 at 05:03

In recent days, an unusual consensus has begun to emerge among some of Bolivia's most prominent public intellectuals, economists, diplomats, and former political leaders.

Former Foreign Minister Jaime Aparicio has warned that Bolivia has moved from "the theater of the absurd" to "the dialogue of the absurd," suggesting that the country may require international support to preserve democratic governance. Economist Jaime Dunn has repeatedly argued that Bolivia's central challenge is no longer merely economic, electoral, or ideological, but institutional. Former President Jorge "Tuto" Quiroga has warned of the corrosive effects of impunity and criminality on democratic government. Former La Paz mayor and economist Ronald MacLean Abaroa has likewise argued that Bolivia confronts a deeper crisis of governance than many observers recognize. Political commentator Vidal Dorado has advanced similar concerns.

These figures differ in generation, political affiliation, and professional experience. Yet they increasingly converge around a common diagnosis: Bolivia's greatest challenge may no longer be who governs the country, but whether the state itself retains the capacity to govern effectively.

That distinction matters.

Most international coverage of Bolivia's current turmoil continues to frame events as a political confrontation between former President Evo Morales and President Rodrigo Paz. The headlines focus on road blockades, food and fuel shortages, arrests, negotiations, and the possibility of emergency measures. Morales's supporters argue that he is being excluded from political life. His opponents contend that he is attempting to destabilize the government in order to preserve his political relevance and avoid accountability. Both interpretations contain elements of truth. Neither fully captures the significance of what is taking place.

As a Bolivian attorney and former Interim Mission Director of USAID/Bolivia, I have observed the country navigate moments of extraordinary turbulence. Bolivia has survived military governments, hyperinflation, constitutional crises, regional tensions, and repeated confrontations between state institutions and social movements. Yet what is unfolding today feels different. Increasingly, the central question is not who governs Bolivia. It is whether the Bolivian state can govern effectively.

The current crisis illustrates the point. Weeks of blockades have disrupted commerce, restricted the movement of food and fuel, and imposed substantial costs on ordinary citizens. Reports indicate that patients have died after being unable to obtain timely medical treatment because transportation routes remained blocked. The government has debated emergency authorities while attempting to avoid a wider confrontation. Yet even amid escalating tensions, important developments have occurred. The Central Obrera Boliviana has entered into dialogue with the government and established joint commissions to address detainees and other demands. At the same time, divisions have emerged within sectors of the protest movement itself, including organizations associated with the Tupac Katari movement.

These developments suggest that the crisis is no longer a simple confrontation between government and opposition. Bolivia increasingly resembles a contest among multiple actors, grievances, and centers of influence, none of which appears capable of imposing a definitive outcome on its own. The result is a growing debate not merely about political leadership, but about governability itself.

At the same time, public discussion has increasingly touched issues that until recently remained largely confined to security specialists and anti-corruption practitioners: narcotics trafficking, illegal mining, contraband, land trafficking, environmental crime, and the financing of political mobilization.

Whether any particular allegation ultimately proves true remains a matter for evidence, investigation, and due process. Yet the broader trend is difficult to ignore. Over time, illicit and informal economies can accumulate sufficient financial and political influence to shape governance itself. They provide livelihoods where the formal economy cannot. They generate patronage networks. They cultivate local loyalties. They penetrate institutions. Eventually, they cease functioning merely as criminal enterprises operating outside the state. They become alternative systems of power operating alongside it.

More than half a century ago, RenΓ© Zavaleta Mercado, Bolivia's most influential twentieth-century political thinker, described his country as a sociedad abigarradaβ€”a society composed of multiple social, economic, and political realities existing simultaneously within the same national territory. Zavaleta was attempting to explain Bolivia's complexity. His insight remains relevant today. Yet the challenge confronting Bolivia may now extend beyond the coexistence of multiple realities. Increasingly, some of the most powerful actors operating within those realities are neither political parties nor state institutions, but illicit economic networks whose resources and influence rival those of the state itself.

This is not solely a Bolivian phenomenon.

For much of the democratic era that followed Latin America's military governments, political debate revolved around elections, constitutions, economic models, and the alternation of power. The underlying assumption was that the state remained the principal arena through which political conflict would be resolved. Across much of the hemisphere, that assumption is being tested.

In Mexico, cartels have challenged state authority across entire regions. Ecuador's recent security crisis demonstrated how rapidly organized crime can reshape national politics. Colombia continues to confront criminal and armed groups whose influence extends well beyond traditional law-enforcement concerns. Guatemala has repeatedly struggled with corruption networks capable of penetrating public institutions. Venezuela presents perhaps the hemisphere's most advanced example of governing structures intertwined with illicit economic activity. Nicaragua's authoritarian consolidation likewise demonstrates how patronage, coercion, and opaque economic relationships can undermine democratic accountability.

Elsewhere, similar concerns are emerging. Brazil faces the growing influence of criminal organizations and illegal mining operations in the Amazon. Panama remains vulnerable to transnational money laundering and criminal finance. Jamaica and Trinidad continue to grapple with the political consequences of organized crime and gang violence. Guyana's remarkable economic expansion creates extraordinary opportunities but also governance risks familiar to many resource-rich states. Even Argentina's recent political debate, reflected in part through the rise of Javier Milei, has centered on public frustration with entrenched patronage systems, institutional weakness, and a perception that the state increasingly serves privileged networks rather than citizens. In Chile, support for figures such as JosΓ© Antonio Kast similarly reflects anxieties about crime, state capacity, and the ability of institutions to maintain public order.

These countries are not identical. Their histories differ. Their institutions differ. Their democratic trajectories differ. Yet they increasingly confront a common challenge: preserving the capacity of legitimate institutions to exercise authority in the face of alternative networks of economic and political power.

The concern is not merely theoretical. It increasingly shapes political discourse throughout the hemisphere. What Jaime Dunn articulates in Bolivia is not entirely different from concerns expressed by reformers in Ecuador, opposition figures in Venezuela, portions of Peru's political class, or advocates of institutional reform elsewhere in the region. The ideological differences among these groups are substantial. What unites them is a growing belief that democratic governments are losing groundβ€”not simply to political opponents, but to systems of power that operate beyond the effective reach of traditional institutions.

At this point, the observations of Jorge Basadre, Peru's great historian of the republic, become especially relevant. Basadre famously described Peru as both a problem and a possibility. The same might be said of democratic governance across much of Latin America today. The challenge facing many countries is not simply electing the right leaders or adopting the right policies. It is preserving institutions capable of channeling conflict through politics rather than allowing power to migrate toward criminal organizations, illicit markets, or networks that thrive on disorder and impunity.

Many of the hemisphere's most experienced diplomats and policymakers, including former U.S. Under Secretary of State Tom Shannon, have long argued that Latin America's enduring challenges are ultimately institutional rather than ideological. Bolivia's current crisis reinforces that point. The debate is no longer primarily about the distribution of power among competing political actors. It is increasingly about the capacity of democratic institutions to exercise authority, enforce rules, and maintain legitimacy.

This challenge also exposes a growing gap in the inter-American system. The Inter-American Democratic Charter was designed to defend constitutional democracy against coups, authoritarian ruptures, and attacks on democratic order. The Inter-American Convention Against Corruption sought to strengthen integrity and accountability throughout the hemisphere. Both remain important achievements. Yet neither was drafted with today's challenge fully in mind. Increasingly, democracy is threatened not only by tanks in the streets or presidents who refuse to leave office. It is threatened by criminal networks, illicit economies, and corruption structures that do not seek to replace democratic institutions outright, but gradually hollow them out from within.

Two centuries ago, SimΓ³n BolΓ­var warned of the fragility of republican institutions in the newly independent Americas. More recently, Basadre reminded us that the republic remains both a problem and a possibility. Bolivia's current crisis suggests that those concerns remain remarkably relevant. Jaime Dunn and others have argued that the country's deepest challenge is institutional. The evidence increasingly suggests they may be right.

The fundamental question facing Bolivia today is not whether Evo Morales or Rodrigo Paz prevails in the next round of political struggle. It is whether democratic institutions can continue to exercise legitimate authority in the face of increasingly powerful alternative networks of economic and political power. That question extends far beyond Bolivia. Increasingly, it is becoming one of the defining questions of democratic governance throughout the Americas.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

After the Intelligence Cycle: A New Schema for AI-Native Intelligence Analysis

9 July 2026 at 05:01

Recent discussion of artificial intelligence in intelligence analysis has consistently framed the technology as a means of accelerating an existing process. The intelligence cycle (collection, processing, analysis, production, dissemination) remains the implicit organizing schema, with AI cast as something used to drive its stages faster, increase resource efficiency, or widen its scope. We find this framing inadequate. It leaves the cycle itself intact, treating it as a sound structure merely in need of added speed, when the more consequential present opportunity is to reconsider the structure altogether. The intelligence cycle is an industrial-era artifact, popularized by Sherman Kent in the immediate post-war period, when information was scarce, expert labor concentrated, and the consumer a narrowly-defined institutional decision-maker. None of these conditions still holds. Recent work by Gartin, Schlickenmaier and by Reed and Szylkiewicz has argued for updating intelligence with agile, information-technology methods, and for shifting delivery toward a services-centric rather than goods-centric model. These arguments address the outdated production cycle, but neither fully anticipates the extent to which AI permits the cycle to be displaced wholesale rather than merely modernized.

As practitioners building intelligence programs in this environment, we observe that the prevailing conversation remains bounded by traditional conceptions of what analytic work is. This paper proposes a different framework, organized around a single assertion: that AI enables a scale and rigor in cognitive information work that were previously unavailable, and that this in turn dissolves several of the assumptions on which the cycle previously depended. The argument rests on a particular architectural premise that analytic reasoning can be captured as a structured data schema rather than compressed into an overly-simplified finished narrative. From this premise follow five ruptures with the traditional cycle:

First, the core value unit of intelligence shifts away from the finished assessment toward a more complex artifact that contains the entire decision architecture by which the assessment was reached.

Second, AI-enabled analysis becomes continuous and ongoing rather than fixed to a single publication date.

Third, analytic accuracy becomes measurable, and therefore improvable, for the first time in history.

Fourth, the relationship between provider and decision-maker narrows, and can be scaled to the needs of the individual consumer rather than to a generic reporting requirement.

And fifth, source handling and judgment collapse into a single operation rather than appearing as separate steps.

Taken together, these constitute a revolutionary rather than evolutionary departure from the manual methods that have governed intelligence analysis for a century, and they open new ground for rigor, accountability, and accuracy in global risk forecasting.

From Finished Product to Assessment Process

Modern intelligence analysis tradecraft treats the finished product as its core deliverable. The product serves both as the vehicle of value to the consumer and as the measure of organisational output, and it is the terminus toward which collection, refinement, and assessment are all directed. This arrangement was never optimal. Reliance on a single artifact collapses a complex analytic process into one compressed object, in which the judgments, and biases, included along the way are flattened into a single deliverable. Tradecraft notes and caveats have occasionally preserved fragments of this reasoning, but the product standing alone has never fully represented the value chain that produced it. The most important steps in the analyst's work, the alternative hypotheses entertained, the source biases weighed, and the contingencies sketched against one another, do not travel with the document, forming a lost layer of metadata that usually remains behind.

Artificial intelligence relieves the scale pressure that heretofore forced this compression. An analyst working with well-designed AI tools can now meaningfully execute and record each of the steps in an intelligence workflow rapidly and at scale, which permits the end product to change, away from the finished product deliverable to a searchable, indexable, and auditable log of expertise that has produced a range of potentially useful data through its work. In this process, the end value unit of analysis becomes the actual analysis itself, rather than an artificial summary of that analysis compressed to finished product size. By deprioritizing the focus on the product as the end goal of all analytic work, more of the valuable decisions and information which informed its creation become accessible to both the analyst and the consumer, which may audit and explore these dynamically to enhance their own understanding.

For this process to compound rather than merely accumulate, the analytic representation of judgments must be persistent and structured. Judgments of this type include the reliability of the source, the credibility of the information it contains, the weight that information should play in contributing to a view of the world, how it might interplay with other events and trends, and so on. These expert judgments are collected as structured data and recorded as they are formed, so that they can later be reviewed against real-world outcomes as those outcomes resolve. This foundation of analysis permits auditability and recursive improvement in judgment, source collection, and analytic framing. AI tools used correctly should permit a thoroughness which enhances judgment rather than eroding it, because they help create a massive record of analytic work that persists and can rapidly be revisited, rather than a sequence of keyhole snapshots of reality which age into irrelevance from the moment they are completed.

Because our representation of analyst judgment is structured across various data points rather than as a single loose narrative, it supports more than retrieval. A sufficiently large corpus of analytic judgments can be used to generate predictive assessments based on prior weighting and modal relationships, to trace multi-path higher-order consequences that human reasoning follows poorly, to identify which forces carry the most systemic weight, and to express conclusions as calibrated, quantified probability rather than verbal estimate.

From Episodic to Continuous Analysis

The intelligence cycle was built around episodic production not because it produced the best analytic results but because scale challenges prevented anything more rigorous. Between products, the analyst's judgment existed only in their head, and even then, was a nebulous and ill-defined thing. Kent’s β€œWords of Estimative Probability” and Tetlock’s superforecasting projects both pointed toward a need for improved, continuous, and calibrated judgment, but neither could provide a way to operate such a system of rigor continuously at scale. Artificial intelligence changes this arithmetic. A well-trained model handles what human analysts struggle to achieve at scale, ingesting raw data, mapping it to analyst-defined areas of interest, and updating mathematical prediction models. This rapid processing enables the analyst to spend bandwidth on setting the scope of analytic questions, interrogating the quality and biases of sources, and defining the weights and relationships the models will assign to various real-world events. Far from the language of the factory assembly line, the modern discipline of intelligence we espouse more closely resembles the rhythm of a trading desk, where equities analysts mark positions to market continuously, forever adjusting expectations based on a never-ending flow of data.

In this framing, an equities analyst wouldn’t save up all their trading positions to be submitted in one package at the end of the day, and we propose that appropriately tooled intelligence analysts similarly no longer need to wait until a publication date to deliver analytic value. By connecting front-end AI summarization and chat systems to back-end analyst enrichment areas, customers are able to query the latest in analyst judgment on demand, creating an instant feedback loop in which customer queries inform and sharpen ongoing analytic priorities. This serves the analyst as much as the consumer. It removes the obligation to produce filler during quiet periods, and it lets analytic output follow the genuine cadence of a topic rather than an arbitrary calendar.

Measuring and Improving Accuracy

Intelligence consumers hold the analyst accountable not only for a judgment but also for the reasoning by which it was reached. Historically this accountability has been difficult to honor, because much analytic judgment was formed reflexively and poorly recorded. The methods now available for capturing and structuring reasoning make the problem tractable for the first time. Once reasoning is recorded as structure, it can be scored against outcomes as they resolve, using calibration methods such as Brier scoring. The essential property is that each judgment is preserved as it was made and is not revised afterward. That is what keeps the scoring honest: the analyst is measured against the call they actually made, not a version softened by hindsight.

We are deliberate about the strength of this claim. The architecture does not inherently make analysts more accurate. What it makes possible is the measurement of accuracy and the diagnosis of error. When a judgment proves wrong, the structure allows the failure to be traced to a specific weighting or relationship rather than absorbed into an unaccountable whole. It is this decomposability, sustained over time and across many resolved judgments, that creates the conditions for improvement, for the individual analyst and for the models their judgments inform. The data describing how and why an analyst reached a judgment is, in this respect, more valuable than the judgment itself, because it is the raw material of recursive refinement.

This is a meaningful departure. For most of its history, intelligence analysis has struggled to know whether it was improving in delivering decision advantage or predictive insight, because the record needed to properly audit this improvement was never systematically available. For the first time, a complete and inspectable record scored against reality is within reach, presenting the opportunity for true improvements in forecasting accuracy.

From Generic to Specified

A further constraint the cycle never escaped was the assumption that consumers were finite and institutionally legible. The analyst writing for a government agency in 1990 could reasonably picture a handful of senior officials whose interests were bounded by their roles in advancing the national interest. This model functions poorly in the wider modern intelligence context, in which the reader of any given report might vary widely based on their position and access. For intelligence teams working in today’s commercialized contexts, the reader of a report might be a CFO weighing currency exposure, an operations director routing freight around contested waterways, a general counsel mapping sanctions risk, or a fund manager modelling financial tail risk. Each actor is sufficiently distinct from the others that how information is presented to them, and what information is relevant to their decisions, is so different as to destroy the value of a single, universal intelligence report. Each actor makes a different decision against a different geometry of exposure to the same geopolitical environment. A generic product written to the centre of this readership delivers very little decision value to any specific stakeholder because it is intended for none of them.

Bespoke intelligence tailored to individual stakeholders is rare, because it is cost-prohibitive. Examples like the President’s Daily Brief show just how complex and difficult the process is to tailor an intelligence report to even one customer, let alone many hundreds or thousands. Today, AI makes this feasible, because it permits a single body of robust analytic work to be expressed differently for each consumer according to their specific exposure. The assessment surfaced to a Nordic manufacturer with significant Strait of Hormuz exposure differs significantly from the one surfaced to a Latin American agribusiness with none, though both can draw on the same underlying analysis in order to inform a wider geopolitical frame. This approach keeps client-specific context separate from the shared analytic base rather than absorbing it permanently, which matters as much for data governance as for scale. In other words, by keeping intelligence about the threat environment separate from context about the user’s potential impact until the last possible moment, delivery of truly tailored insights is permissible at a scale that humans alone cannot match. Delivering this well still requires human guidance, because the object is to inform human decisions, but it is reachable by a useful number of consumers only through automated composition and delivery. In practice it increasingly resembles data layers, dashboards, and conversational interfaces rather than documents and slide decks, which are inherently static and cannot respond to unique and specific customer interrogation. AI’s ability to handle mass data sets and rapidly synthesize them for human engagement is the key which unlocks these dynamic product offerings.

Source Handling as Judgment

One fiction the cycle's imagery sustained was that a clean separation existed between collection and analysis. In the logic of the assembly line, collection produced sources, processing ordered them, and analysis applied judgment. Practitioners have long known this separation rarely held in practice. Deciding which information to credit, and how heavily, is itself an analytic act, one frequently practiced by collectors but only sporadically preserved in the finished product in the form of sometimes feeble source reliability statements. An AI-enabled team can make this categorization a continuous and systematic piece of the analysis rather than a burdensome and occasional addendum to it. High-volume collection and tagging let analysts reach and index relevant information by reliability far faster, and automated tooling lets them record, in real time, which signals they judge useful, to what degree, and for which questions.

Two disciplines give this its force. The first is continuity: signals attach to persistent, identified subjects rather than floating as unlinked text, so that a judgment made today accrues to the same subject a judgment made months earlier addressed. The second is provenance carried as structure. Each catalogued signal carries its source, the system action that surfaced it, and the analyst decisions that touched it, so that the basis of a judgment travels with the judgment rather than being reconstructed after the fact. In our architecture the analyst encodes meaning into collection from first contact through to the point at which a signal is connected to the wider analytic framework. The system performs the high-volume triage and flagging; the analyst accepts, challenges, or supplies the context the system cannot; and the system then does the durable work of attaching that judgment to analysis where it carries lasting weight. The provenance this produces is more than an audit trail, and becomes part of what the consumer can interrogate. It also forms the basis for learning, over time, about collection gaps and the reliability of sources, serving as an internal collection management architecture.

After the Intelligence Cycle

Building an intelligence team that is AI-native from the outset, at a moment when most established intelligence institutions predate AI and are captured by institutional cultures which inhibit profound change, has shaped our thinking profoundly. The most valuable applications we find for AI push beyond legacy tradecraft, and concentrate on the high-volume work of collection, structuring, and presentation of data. Critically, we do not use AI to replace human judgment. The reason is not that models cannot produce reasoning, because they can, often fluently. It is that a model's account of its own reasoning cannot be relied upon as a faithful record of why it actually reached a conclusion. Auditable, attributable judgment of exactly that kind is what our architecture is built to capture from human analysts. Throughout our experimentation we have found success in a consistent division of labour: the system handles scale, the analyst supplies judgment, and the system records and surfaces that judgment rather than manufacturing it. Attempts to use AI to replace the analytic steps of the cycle risk producing analysis that sounds authoritative but cannot be held to account, and that is most dangerous when it is wrong. Any technology that amplifies human reasoning inherits its errors along with its strengths, which is why the core work of judgment must remain human and auditable.

The process changes we describe are early in their lifecycle, and the work of demonstrating them against a long track record remains ahead of us. Still, the process has taught us that significant changes to the discipline of intelligence analysis are almost certainly on the horizon, particularly as technological advances in model sophistication render traditional information-work delivery obsolete. Human analysts may defend the old ways of conducting analysis on nostalgic grounds, but the truth is that intelligence analysis conducted in this way has a poor track record of success, and disruptions which pose the opportunity for step improvements should be welcomed. These improvements should proceed from the end goal of intelligence analysis - to provide sustainable, responsible, and accurate forecasts about the future that enable decision advantage - rather than from a reactive defense of the previous normal process. To integrate AI in intelligence analysis in responsible ways requires abandoning many of the bad habits and basic assumptions that limited intelligence work in the preceding era. It also requires reconceiving the notion of the value and role of the human analyst in providing insight, and an audacity to believe that what has historically been unknowably complex can be rendered intelligible through sufficiently sophisticated modeling. One hundred years ago, humans struggled to predict the weather with any reliability; today, they expect a device in the palm of their hand to predict rain down to the minute. Similar changes are coming to the world of intelligence analysis. But they will require leaving behind the archaic tools of a previous era in order to reach their full potential.

If You Can Run a Spy, You Can Run AI

8 July 2026 at 08:41

Generative AI should be managed like a human source: useful, fast, sometimes brilliant, sometimes wrong, and never a substitute for disciplined questioning and human judgment.

The three of us spent our careers in an environment where bad information costs lives. We learned early that the most dangerous source isn’t someone who lies to you. It’s someone who tells you what you want to hearβ€”and does it convincingly. As we watch organizations race to adopt generative AI, we keep seeing the same mistake: treating these tools like oracle machines rather than sources that need to be run.

We are not AI experts. We are not here to debate model architectures or training data. What we know is how to extract reliable insights from sources whose motivations can’t be fully verified, whose outputs may be biased or based on incomplete information, and whose reliability must be continuously earned. That is exactly the problem organizations face with AI today.

This is what HUMINT tradecraft has taught usβ€”and what it has to teach anyone who wants to get honest, useful work from a generative AI system.

The Source Who Was Never Wrong

Early in our careers, two of us ran sources who were brilliant, well-placed, articulate, and deeply motivated. They produced detailed, confident, and consistent reporting. Senior analysts loved them. Their product sailed through review. For months, everything they said checked outβ€”until it didn’t.

The problem wasn’t that they were lying, exactly. In both cases, they filled gaps with inference. They’d learned what we wanted to hear, and their natural intelligence and experience let them produce it fluently. The reporting wasn’t fabricatedβ€”it was confabulated. Coherent and plausible, but in key places, wrong.

We’ve all seen this pattern in the early months of AI adoption. The tool is fast. It’s articulate. It never pauses, never says β€œI’m not sure,” and it formats its answers with the confident authority of a briefing document. A recent Science study found that across eleven state-of-the-art AI models, sycophantic behaviorβ€”affirming users’ views even when inaccurateβ€”was widespread and measurable. Stanford researchers found that AI systems trained on human preference feedback are systematically rewarded for being agreeable rather than correct, because agreeable outputs receive higher ratings. The models learn to please.

We’ve seen that source before. We know how the story ends.

Selection: Not All Sources Are Equal

Before you run a source, you select one. That’s a discipline in itself. And a discipline to which AI tools may in fact be able to add value in identifying and sorting stressors that can be exploited (anything that causes stress and then outlines for case officers which levers to pull on a recruitment). You don’t recruit someone simply because they have access. You also generally don't recruit happy people. You have to evaluate reliability, motivation, and susceptibility to manipulation. A source with wide access and poor judgment can be more dangerous than no source at all.

The same applies to AI. Not all AI systems are created equal for every task or mission. Each must be evaluated on access, expertise, responsiveness, and the quality of reportingβ€”and the last criterion is harder to assess than it appears.

A few selection questions worth building into any AI adoption process:

β€’What is this model’s known track record on this specific type of task, not in general but specifically?

β€’Where does it tend to confabulate? What are its known failure modes?

β€’Is it current? A model with a training cutoff is like a source who’s been out of the field for a yearβ€”still useful, but with blind spots.

β€’How does it behave when it doesn’t know something? Does it admit it, or does it keep talking?

Choosing an AI because it’s fast or because leadership read about it in a business magazine isn’t source selection. It’s the equivalent of recruiting the first walk-in who shows up at the door.

Elicitation, Not Interrogation

One of the first lessons a new case officer learns is that interrogation and elicitation are not the same. Interrogation demands. Elicitation draws out. A blunt question produces a guarded answer. A layered conversation yields insight the source didn’t realize they were sharing.

Most people using AI are interrogating it. β€œWhat’s the answer?” β€œSummarize this.” β€œGive me options.” That approach works, up to a point, but it caps the quality of what you get.

Effective elicitation with AI means:

β€’Never ask a direct question when an indirect one is better. Instead of β€œWhat should we do?” try β€œWhat factors would a skeptic weigh against this recommendation?”

β€’Compartmentalize your tasking. Don’t dump the entire problem into a single prompt. Break it into discrete, well-scoped questions. Discrete tasking yields more verifiable output.

β€’Build layered follow-ups. Ask: β€œWhat are you assuming?” β€œWhat would change your conclusion?” β€œGive me the strongest argument against this.”

β€’Probe for alternatives before you settle on an answer. A source that only confirms your hypothesis may be problematic.

This turns AI from a content generator into something closer to a thinking partner. But it requires the same discipline as running a source well: preparation, precision, and the intellectual humility to recognize that your framing shapes what you get back.

The Hostile Source Problem

There is a risk the standard AI adoption literature doesn’t spend enough time on. In intelligence work, we worry not just about sources who are wrongβ€”we worry about sources who have been co-opted or doubled, or who are feeding us what we want to hear because they’ve learned our preferences and decided that’s what keeps the relationship alive.

AI systems have structural analogs to all three failure modes:

β€’Sycophancy as a design artifact. Because models are trained on human preference feedback, they are incentivized to produce outputs that feel satisfying. Researchers at Carnegie Mellon and Stanford have documented an β€œartificial hivemind” effect in which outputs from multiple AI models convergeβ€”reducing epistemic diversity at the very moment organizations need independent judgment.

β€’Training data is a contamination channel. A source’s worldview is shaped by their environment. An AI model’s worldview is shaped by its training corpus. That corpus reflects the biases, omissions, and assumptions of the material it was built on. You may not know where those biases are, and the model won’t volunteer them.

β€’Automation bias as a user vulnerability. A series of recent studies confirms what experienced case officers know: people grant far more credibility to confident, fluent reporting than the underlying evidence warrants. Research published in 2025 found that even users with high β€œAI literacy” were not significantly protected against automation biasβ€”the tendency to accept AI output without critical evaluation.

The practical implication: approach your AI system with the same structured skepticism you’d bring to a well-placed source who has given you no reason to doubt them. That’s when discipline matters most.

Debrief Discipline: The Protocol That Makes It Real

After every source meeting, a case officer writes up not only what the source said but also their assessment of reliabilityβ€”what was corroborated, what was assumed, and what needs follow-up. That habit is the difference between a professional intelligence organization and a rumor factory.

Most organizations using AI lack an equivalent discipline. Someone prompts the model, takes the output, and puts it in a slide. No one records what was asked, what caveats the model offered, or whether the output was independently verified. The result is institutional memory built on unexamined reporting.

A working AI reporting protocol should mirror the post-meeting debrief:

β€’Requirementβ€”What question are we actually trying to answer?

β€’Promptβ€”What, precisely, did we ask? (Save it.)

β€’Outputβ€”What did the AI say?

β€’Source checkβ€”What in this output is reliable? What is uncertain? What is unsupported?

β€’Human judgmentβ€”What do we actually believe, independent of the AI?

β€’Actionβ€”What will we do?

β€’Reviewβ€”What happened after we acted? Did the AI’s analysis hold up?

The review step is the one that organizations most consistently skip. But it’s where calibration happens. A source you never debrief after the fact is one whose reliability you can never actually assess.

A useful team habit before closing out any AI-assisted analysis: β€œBefore we accept this answer, what would disconfirm it?” That question alone will catch more errors than any amount of AI governance policy.

Separating Collection from Analysis

This is a fundamental discipline in intelligence work, and it translates directly. AI is a tool for collecting and synthesizing. It can ingest, summarize, organize, and compare. What it cannot reliably do is interpretβ€”to ask what the information means here, in this context, for this organization, with these constraints.

The error organizations make is treating AI as if it collapses the divide between collection and analysis. It doesn’t. It accelerates collection. The analytical functionβ€”applying judgment, context, institutional knowledge, and accountabilityβ€”remains human.

Teams that hand over analytical responsibility to AI are not just making an efficiency error. They are making an accountability error. Someone has to own the conclusion. AI cannot.

Burning a Source: When to Stop Trusting the AI

This is the part of the tradecraft literature on AI that doesn’t exist yet, and it needs to.

Every experienced case officer has had to decide to terminate a source relationship. Not because the source was obviously lyingβ€”if that were clear, the decision would be easy. You terminate when the source's reliability has fallen below a threshold, when you have reason to believe the source has been compromised, or when the cost of continuing to run them outweighs the value of their reporting.

The equivalent decisions will come for AI systems, and organizations should prepare for them:

β€’When a model’s known failure modes consistently overlap with your mission-critical questions, it is time to stop relying on it for those questionsβ€”regardless of how it performs elsewhere.

β€’When an AI system has been demonstrably wrong in a consequential context and the organization has not developed a clear explanation for why, continuing to use it at the same level of trust is an operational error.

β€’When a model is updated or retrained by its provider, treat it as a new source and revalidate. Prior reliability does not transfer automatically.

β€’When you discover that the model has been systematically producing outputs shaped by the framing of your prompts rather than by evidenceβ€”that you have been leading the witness without realizing itβ€”you may need to reset the relationship.

Burning a source is not a failure of the source-handling relationship. It is often the proof that the relationship was being handled well.

What This Means for How You Lead

The three of us came to this issue through intelligence work, but the problem is not limited to intelligence organizations. Any leadership environment where AI tools are proliferating faces the same structural challenge: the tools are fast, fluent, and confident, and organizational incentives often reward those who use them most rather than those who use them best.

The research bears this out. INSEAD’s 2025 analysis of firm-level AI adoption found that generative AI shifts value toward higher-order human judgmentβ€”not away from it. Microsoft’s research confirms that organizations with a well-calibrated understanding of AI perform better across missions than those that simply maximize usage. The tool is the easy part. The discipline is the hard part.

For leaders, the implications are practical:

β€’Build the habit of debriefing discipline before you scale AI adoption. The protocol above should be standard practice, not optional.

β€’Create psychological safety so people can flag AI errors. The greatest risk in any source-handling operation is the team member who saw the problem but didn’t say anything because the source had too much credibility.

β€’Distinguish between AI as a collection tool and as an analytical tool. Automate the former aggressively. Guard the latter carefully.

β€’Evaluate AI systems with the same rigor you would apply to any sourceβ€”including periodic reviews of whether the relationship continues to produce reliable value.

Used with discipline, generative AI can be a genuinely powerful analytical partnerβ€”the kind of well-placed, high-access source that an experienced handler learns to work with carefully and derive real value from. Used without discipline, it becomes a certainty-destroyerβ€”introducing noise, eroding judgment, and producing false confidence at scale.

The HUMINT model doesn’t make AI safer by limiting what it does. It makes AI safer by raising the standard for what we do with what it gives us.

AI doesn’t give you answers. It gives you reports. And reporting always requires a handler’s skeptical, trained eye.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Cyber Fraud, Banks, and What America Can Do About It

8 July 2026 at 05:02

Your phone buzzes with a text from your bank: β€œDid you authorize a $2,400 transfer? Reply NO to stop it.” You reply, and seconds later a calm β€œfraud agent” calls, knows your name and the last four digits of your card, and walks you through β€œsecuring” your money by moving it into an account under the criminal’s control. No password was stolen, no malware installed. You handed over the money yourself, because everything looked and sounded real.

This is the new face of bank fraud and business is booming. Behind these scams sit organized adversaries: nation-state actors who treat theft as state revenue, criminal gangs running industrial-scale scam operations, and hacktivists out to embarrass institutions increasingly armed with AI that makes their lies cheap, fast, and tailored to you.

The problem: scams have gone industrial

Banks have spent decades hardening their vaults and networks, so attackers shifted to the softest target: the customer. Rather than breaking in, they trick people into transferring funds themselves. This is β€œauthorized push payment” fraud where the victim approves the payment and it is far harder to claw back than a stolen card number. To hear how a typical scam call actually unfolds, watch the FTC’s short imposter-scam explainer.

With the age of AI, three key forces have turbocharged these threats. Payments now move instantly and irreversibly, so money is gone before anyone notices. Decades of data breaches let criminals buy your name, address, and account details cheaply, making their scripts eerily accurate. And generative AI has industrialized deception where more than half of fraud is now estimated to involve AI. A criminal can clone a familiar or family voice from seconds of audio, write flawless phishing emails in any language, and even deepfake a bank officer on a video call.

The people behind it are not lone hackers in hoodies. They range from sanctioned nation-state groups that steal to fund their governments, to criminal syndicates running scam centers staffed by trafficked workers, to hacktivists attacking banks to make a political point. For them, fraud is a scalable business and it is outrunning the banks, telcos, and Big Tech.

The real-world cost

The damage is measured in real households. The Federal Trade Commission reports Americans lost roughly $16 billion to fraud of all kinds in 2025 the highest on record and about 25% more than the year before. Imposter scams alone accounted for $3.5 billion, nearly tripling since 2020, and the single most lucrative version is the fake bank-security alert that convinces people to β€œprotect” their savings by moving them.

These losses fall unevenly. Americans aged 50 and older reported $4.3 billion in losses in 2025, often life-altering sums drained from retirement accounts. The official numbers are almost certainly a fraction of reality, since many victims never report out of shame. Beyond the dollars, the human cost is real emptied college funds, missed mortgage payments, and a corrosive loss of trust in the financial system people rely on every day. One Florida couple lost $42,000 of their savings this way watch how it happened. In fact, this happens so often that Hollywood created an action movie about it with the Bee Keeper.

A National Security issue

Fraud and scams are not just a nuisance but far more dangerous. Fraud and scams in the United States have escalated into a national security issue because they are no longer isolated consumer crimes. They are large‑scale, foreign‑run operations that drain billions of dollars from the U.S. economy and undermine public trust in financial and digital systems. Federal agencies increasingly link these schemes to transnational criminal organizations, some of which also engage in human trafficking, money laundering, and other activities that threaten national stability. The financial impact is massive, with losses rivaling major illicit industries, and the proceeds often flowing to adversarial nations or criminal networks abroad.

The rules already on the books

The U.S. is not starting from zero. Along with the growth of the early Internet, in 1999 the Gramm-Leach-Bliley Act went into effect and its Safeguards Rule in requiring banks to protect customer data, and guidance from the Federal Financial Institutions Examination Council (FFIEC) pushes them toward stronger, multi-factor login security. The Bank Secrecy Act and anti-money-laundering rules, enforced by the Treasury’s FinCEN, require banks to flag suspicious transactions β€” a key tool for tracing stolen funds. New York’s Department of Financial Services Part 500 cybersecurity rule has become a de facto national standard.

Regulators are also targeting the scams themselves. The FTC’s Impersonation Rule, in force since April 2024, lets the agency go after fraudsters who pose as businesses or government agencies; in its first stretch it produced more than $70 million in consumer refunds. Voluntary frameworks like the NIST Cybersecurity Framework give institutions a common playbook.

The gap is not the absence of rules it is that attackers move faster than rules can be written, and that liability for scam losses remains murky when a customer is tricked into approving the payment. So, with all these rules and regulations, why are scams and fraud occurring faster?

The innovators fighting back

A fast-growing wave of companies is using the same AI that empowers criminals to stop them.

Β· Feedzai builds real-time systems that score billions of transactions as they happen, spotting the subtle patterns of a scam in under a second.

Β· Alloy helps banks and fintechs verify who is really opening an account, choking off the synthetic and stolen identities fraudsters depend on.

Β· Arkose Labs specializes in blocking automated bot attacks and account takeovers, while SEON, Lexus Nexus, and Sumsub offer identity-verification and fraud-screening tools that smaller banks and startups can plug in affordably.

Β· Netcraft is a company which doesn’t only detect scams but does something about it. It is very good at β€œtake downs” of scam networks.

Β· Others are racing to build deepfake and voice-clone detection to catch fakes that fool the human ear and eye. Others get creative: UK carrier Virgin Media O2 built β€œDaisy,” a lifelike AI β€œgranny” that answers scam calls and keeps fraudsters rambling for up to 40 minutes to tie them up so they have no time for real victims. Watch β€œDaisy” turn the tables on scam groups.

What unites all these is adaptive defense models that learn daily, because last month’s fraud pattern is already obsolete. All these point solutions are modeled on Intellectual Property that slows sharing. This model is not working.

What America should do

As scams become more sophisticated, especially with AI‑driven impersonation, deepfakes, and automated fraud, their ability to destabilize institutions, exploit citizens, and weaken economic resilience has pushed policymakers and security experts to treat fraud not just as a consumer protection problem, but as a strategic threat to national security. Staying safe will take coordinated effort. Everyone has a role.

Lawmakers and regulators

Fraud and scam laws in the United States, the United Kingdom, and Australia share the same objective: to protect consumers and disrupting criminal activity but each country approaches the problem with a very different regulatory philosophy.

In the U.S., the system is fragmented and enforcement‑driven, with no mandatory reimbursement for most scam victims and a heavy reliance on agencies like the FTC, CFPB, and FBI to pursue wrongdoing after the fact. By contrast, the U.K. has built the world’s most proactive framework, requiring banks to reimburse victims of authorized push‑payment scams, enforcing account‑name verification through Confirmation of Payee, and placing clear accountability on financial institutions to prevent fraud before it occurs. Australia sits between the two models, adopting U.K.‑style protections while expanding responsibility beyond banks to include telcos and digital platforms through its emerging Scams Prevention Framework. While the U.K. emphasizes consumer protection and the U.S. emphasizes enforcement, Australia is moving toward a shared‑liability, cross‑industry approach that recognizes scams as a systemic risk requiring coordinated prevention across the entire digital ecosystem.

A typical scam today uses several pieces of technology working together to make the criminal look real. It often starts with:

1. the scammer creating a fake website that looks almost identical to a bank or delivery company. They buy a cheap web address from a service like GoDaddy and change just one letter so most people won’t notice the difference.

2. Then they setup email accounts on services like Microsoft & Gmail to send out massive emails.

3. They use AI tools to scrape millions of social media profiles from Facebook, Instagram, etc. to collect data about YOU.

4. They use tools that let them fake a phone number (telco), so when they call you, your phone shows the name of your bank or a government agency.

5. After that, they send out text messages to iPhone and Android users that look official, things like β€œYour account is locked” or β€œYou have a package waiting.” The link in the text takes you to the fake website, where the scammer collects your login details. If you call the number instead, it goes to a call center where the scammer pretends to be a bank employee.

All of this: fake websites, spoofed phone numbers, and realistic text messages works together to trick people into believing they’re talking to a trusted company when they’re actually dealing with a criminal.

What should the Critical Infrastructure do?

In the U.S., we have failed because we have not worked together across these technologies at scale & at the speed of AI. Why? Because we (collectively) do not have the incentives or requirements to do so. For the CEOs of these companies, they do not want to spend money & resources which do not drive revenue. Period.

There are glimpses of hope. A working model already exists:

Β· We have the Financial Services Information Sharing and Analysis Center (FS‑ISAC) is a global, nonprofit organization that helps protect banks and other financial institutions from cyberattacks by enabling them to quickly share information about threats. It was created in 1999 (26 years!) to strengthen the safety and resilience of the financial system by collecting, analyzing, and distributing timely intelligence about cyber and physical risks so that member institutions can defend themselves and their customers more effectively. I am hopeful that they new CEO, Valerie Abend will drive more effective solutions.

Β· In 2026, eight major carriers: AT&T, Verizon, T-Mobile and others just launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), chaired by longtime cyber expert, AT&T security chief Rich Baich, to share real-time threat intelligence across competitors. Because most scams ride phone and text networks before they ever reach a bank, telecom and banking defenses should connect through the same kind of collective-defense sharing. But the C2 ISAC cannot do this alone.

Β· In 2025, the Global Anti‑Scam Alliance (GASA) was formed to bring together governments, financial institutions, technology companies, law‑enforcement agencies, and consumer groups to fight scams on a global scale. GASA acts like a global β€œanti‑scam task force,” uniting experts and institutions so people everywhere are better protected from online fraud.

These have proven to not operate effectively to get ahead of scams and fraud. We need a better way – mandates of sharing, legal risks support, cross ISAC/intel which is tailored/aware, good native ML & AI models (not rules), and others working at speed and context with more transparent sharing.

In the meantime,

What should consumers do?

Treat any unexpected β€œurgent” message about your money as a warning sign, not a command. Banks will never ask you to move funds to β€œprotect” them. Hang up and call the number on the back of your card. Turn on multi-factor authentication and agree on a private β€œsafe word” with family so a cloned voice can’t fake an emergency. Report scams to ReportFraud.ftc.gov, even unsuccessful attempts, because the data helps train good AI/ML models to protect everyone.

What should all companies do?

Adopt adaptive, AI-native detection rather than yesterday’s rules, and design apps that help customers pause before they act. Investors should back the firms building deepfake detection and identity verification, and banks should partner with them quickly instead of waiting years to build in-house.

Conclusion:

With fast innovation, fraud & scams will not disappear, but it can be better contained. The criminals have industrialized deception; the answer is to industrialize defense with smarter rules, sharper technology, and a public that knows the warning signs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Space Age Needs New Rules

1 July 2026 at 15:10

Space is no longer a place we visit to plant flags. It is where the global economy and national security now live β€” and our rulebook is nearly sixty years out of date.

For half a century, space was a government project. Nations went there to prove something about science, about engineering, and about national will. The astronauts were public employees, the rockets were public property, and the point of the exercise was as much symbolic as scientific. But that era is over. What replaced it is both a gold rush and an arms race at once, unfolding in the same orbits under rules written before today.

Two forces have remade the frontier almost overnight. First, private companies now do what only superpowers once could: SpaceX, Blue Origin, Rocket Lab, Planet Labs and dozens of others launch, operate, and profit in orbit at a cadence no government program ever matched. Second, that same orbital infrastructure has become indispensable to national defense and therefore a target. In today's world, satellites are the backbone of how countries communicate, navigate, detect threats, and coordinate military operations. GPS, secure communications, missile warning systems, and real‑time intelligence all flow through space assets. If those systems were disrupted or destroyed, a country's ability to defend itself, project power, or even manage basic infrastructure would be severely weakened.

The result is a domain that is simultaneously more commercial, more crowded, and more contested than at any point in human history, and only getting started. Our institutions were built for none of this. It is time to fix that.

From Flags to Markets

The numbers tell the story of a revolution. The global space economy already approaches half a trillion dollars a year, and credible forecasts put it on a path toward $1.8 trillion or more within the next decade. In the United States alone, the sector already contributes $131.8 billion to GDP each year. Investors poured billions into space startups last year alone, and the United States now captures roughly half of all private space funding worldwide. This is no longer a niche of aerospace contractors living on government cost-plus contracts. It is one of the fastest-growing high-technology sectors on Earth, and the world's wealthiest people are racing to own a piece of it.

The engine of this growth is reusability. When SpaceX learned to land and re-fly its rockets, it did to spaceflight what the shipping container did to global trade: it collapsed the cost. Launching a kilogram to low Earth orbit once cost tens of thousands of dollars; today it can be done for a small fraction of that. Cheaper and faster access changes everything downstream. It is why the United States flew more than 200 commercial launches in a single year, which is the highest annual total this century. It is also why a single company, SpaceX, now accounts for the overwhelming majority of the world's commercial launch activity.

What gets launched has changed too. Instead of a handful of exquisite, billion-dollar satellites, operators now deploy thousands of small, coffee can size, mass-produced ones. Starlink blankets the planet with broadband from orbit; Planet Labs images the entire Earth's landmass every single day; Earth-observation firms sell insight on crops, shipping, emissions, and troop movements to anyone willing to pay. Commercial space stations are being built to succeed the aging International Space Station, and lunar logistics is becoming a business rather than a mission. The center of gravity has shifted decisively from the public sector to the private one.

Make no mistake: this is a triumph. Competition has driven costs down, cadence up, and innovation faster than any government program ever could. But a frontier opened by private capital and moving at commercial speed creates problems that markets alone will not solve. This is where the trouble begins, for which we are not ready.

The New High Ground

The same satellites that power our economy also power our military. Precision navigation, secure communications, missile warning, intelligence, and reconnaissance all run through orbit. Modern forces cannot move, see, or shoot without space, and adversaries know it. That dependence has turned what was once a sanctuary into the ultimate high ground, and the competition to control it is now explicit national policy.

The threat is not hypothetical. U.S. intelligence assesses that China and Russia are fielding a full spectrum of counterspace weapons: ground-based missiles that can destroy satellites, jammers and lasers that can blind or disrupt them, and maneuvering "inspector" craft that can shadow and, if ordered, disable other nations' spacecraft. Officials describe reversible attacks such as jamming and sensor dazzling as occurring on a near-daily basis. Russia's pursuit of a nuclear anti-satellite weapon has been called the single greatest threat to the world's entire space architecture, because a nuclear detonation in orbit would not destroy one satellite but cripple whole swaths of low Earth orbit for years. If this happens, enormous economic impact would occur. Under President Trump, the United States has answered with a declared policy of space dominance: the Pentagon has been directed to ensure American supremacy in orbit, and the Space Force is accelerating the deployment of its own counterspace weapons.

The scale of the buildup is staggering. China operated barely a thousand satellites in 2025; defense planners expect that fleet to approach twenty thousand within fifteen years, many of them dedicated to surveillance and targeting. In response, the United States stood up the Space Force, is spending on the order of $40 billion a year on military space, and is racing to make its constellations resilient, harder to find, harder to kill, and quicker to replace. Crucially, it is doing so hand-in-hand with industry: programs that draw on commercial satellite networks in wartime now treat private operators as part of the national defense fabric. This means government and private sectors are becoming more intertwined.

From a threat standpoint, cybersecurity also needs changing to protect satellites and the networks that control them, because modern space systems behave like connected digital infrastructure rather than isolated hardware. Satellites rely on software, radios, ground stations, and cloud‑based control systems that can be hacked, jammed, or spoofed. A successful cyberattack could disrupt GPS, communications, banking timestamps, aviation routing, or even missile warning systems, creating national‑level consequences. The threat is growing as nations target satellites through cyber intrusions and signal interference, and as commercial constellations expand with software‑heavy, rapidly deployed systems that often have uneven security. Yet international space law barely addresses cybersecurity, leaving countries and companies to rely on their own regulations and best practices. In reality, securing space now requires zero‑trust designs, hardened command links, continuous monitoring, and coordinated defense across governments and commercial operators, because whoever controls the software and signals in orbit controls critical power on Earth.

Here is the uncomfortable truth this creates: the line between a commercial satellite and a military one has all but disappeared. The broadband constellation that connects rural households also connects soldiers at the front. The imaging company that monitors deforestation also tracks armored columns. Private firms are now strategic actors whether they intend to be or not, and that raises questions of law, liability, and protection that no commercial contract was written to answer. It also concentrates extraordinary power in very few hands. A single company, SpaceX, already launches most of the world's payloads and operates the largest constellation ever flown; whoever controls orbital slots, spectrum, and launch capacity increasingly decides who reaches space at all. That is both a triumph and a single point of failure: the Western world's access to space now hinges on the choices of one company, and ultimately one person, which is a degree of dependence few governments would tolerate in any other piece of critical infrastructure. A domain meant to be the province of all humankind now runs on infrastructure owned by a handful of firms and the governments that license them.

Rules Written for a Different Era

So, what are the current rules and what do we do about it? The foundation of all space law is the 1967 Outer Space Treaty. It was negotiated when only three nations had ever reached orbit and governments were the only actors imaginable. It is a magnificent agreement for its time as it keeps weapons of mass destruction out of orbit and declares space the province of all humankind. Yet it sets countries up with a problem: the treaty forbids any nation from claiming territory in space, while granting each nations state jurisdiction over the objects it launches. The effect is sovereignty without ownership: states and the companies they license control satellites, orbital slots, and the data they gather, even as no one is accountable for the domain itself. But it was never designed for a sky full of private mega-constellations and dual-use military assets. No binding space treaty has been adopted since 1979. The rulebook, in other words, predates the personal computer!

The gaps are now operational, not academic. The Outer Space Treaty is reinforced by four companion agreements:

  1. the Rescue Agreement, requiring states to assist astronauts in distress and return them safely
  2. the Liability Convention, which sets rules for compensation when space objects cause damage
  3. the Registration Convention, mandating that states register objects they launch; and
  4. the Moon Agreement, which restricts military activity on celestial bodies and calls for an international regime to govern future resource extraction.

Obligations to act with "due regard" for others, and fault-based liability for collisions, were never given concrete definitions, so they are almost impossible to enforce. And when something does go wrong, the harder problem is proof: with thousands of objects maneuvering through the same orbits and attacks that can be quiet and deniable, attributing a collision or a cyber-intrusion to a specific actor is often impossible, and without attribution there can be no accountability. There is no air-traffic-control system for orbit: each operator largely sets its own collision-avoidance rules, even as tens of thousands of satellites crowd the same shells of space. And there is the debris. Anti-satellite weapons tests alone have scattered thousands of trackable fragments into orbit, a large share of which are still up there, each one a bullet circling the planet at orbital velocity.

The danger is a chain reaction: a collision that creates debris, which causes further collisions, until the most valuable orbits become unusable for generations. National regulators are trying to fill the void piecemeal: the United States now requires defunct satellites to be brought down within five years, and a market for active debris removal is emerging. But orbit is a global commons. Unilateral rules cannot govern a domain where one nation's negligence threatens everyone's access, and the major space powers have shown little appetite for a new binding treaty.

And the gaps are not only physical. As orbit fills with sensors, a harder question trails the hardware: who owns what space sees? A satellite's imagery and signals are raw material for the digital economy, yet the rules for them are thin. The data may belong to the company that gathers it, fall under the jurisdiction of the launching state, or concern people and places that had no say in its capture. The United Nations' remote-sensing principles were drafted for a handful of government agencies, not a commercial market in planetary-scale intelligence. In practice, access is decided by who holds the capability and the capital, raising real questions of privacy, equity, and transparency that no current treaty answers.

Nor is the world negotiating as one. Governance itself is fracturing into rival camps. The United States anchors the Artemis Accords, a non-binding framework now signed by 68 nations, while China and Russia lead a competing bloc around their International Lunar Research Station, joined by roughly a dozen states. Beijing and Moscow have also pressed their own weapons-ban treaty at the United Nations, which Washington rejects as unverifiable. Europe, India, Japan, and a widening circle of newer spacefaring nations move between these poles. The deeper danger is not just that the rules are outdated, but that the major powers are quietly writing parallel rulebooks, none of which binds the others β€” and any regime that excludes China and Russia governs only the orbits that matter least.

What We Should Do

Managing this new frontier does not mean smothering it. The goal is to keep space open, profitable, and peaceful and that requires governance that moves at the speed of the industry it oversees. We suggest these six priorities to guide us.

  1. Build rules of the road for orbit. We have air-traffic control for the skies and maritime law for the seas; orbit needs the same. A civil space-traffic management system built out from the U.S. Office of Space Commerce's nascent TraCSS program and shared internationally β€” ideally migrating to a neutral international steward over time β€” should, within this decade, provide authoritative tracking data, collision warnings, and right-of-way conventions that every operator is expected to follow. The same system should also serve accountability: shared, authoritative tracking makes it possible to establish who did what in orbit, so that a collision or an act of interference can be attributed and answered for rather than denied.
  2. Update the treaty without waiting for a new one. A grand replacement for the Outer Space Treaty is politically out of reach, and far slower than events demand. Instead, adopt the model that works for climate and the oceans: a recurring "Conference of the Parties" convened under UN COPUOS to let nations agree on concrete, incremental standards β€” definitions of "due regard," deorbit timelines, resource-use norms β€” without the impossibility of formal amendment.
  3. Make debris mitigation enforceable and universal. Deorbit mandates, building on the FCC's five-year rule, design-for-disposal requirements, and a ban on debris-generating weapons tests should be the global baseline, agreed multilaterally rather than exported by one regulator or left to a patchwork of national rules. Fund and incentivize active debris removal now, while the problem is still merely expensive rather than catastrophic.
  4. Formalize the commercial-defense partnership and its limits. If private constellations are now strategic infrastructure, governments owe their operators clear rules: when commercial capacity can be commandeered, how companies are compensated and protected, and what legal status a private satellite has if it is attacked. Resilience should be bought through partnership, not improvised in a crisis.
  5. Lead through alliances, not isolation. No single nation can police orbit, and the spacefaring democracies are stronger setting standards together. Coalitions among the United States and its allies, with the Artemis Accords as the nucleus, should align licensing, data-sharing, and behavioral norms to build a critical mass of responsible actors that newcomers must either join or be measured against. But coalition-building cannot become bloc-building: the rules that matter most β€” debris, traffic, and no weapons of mass destruction in orbit β€” are worthless unless they also bind China, Russia, and their partners, which means keeping channels open through the UN even as alliances set the pace.
  6. Set common rules for space data and fair access. Alongside physical traffic, the framework should govern the information satellites collect: who owns it, how privacy and national interests are protected, and on what terms it is shared. And because slots, spectrum, and launch capacity are finite, and already allocated through bodies like the ITU, access to them should stay open enough that capability and capital alone do not decide who benefits from orbit. Access meant for all of humanity should not narrow into a preserve of the few.

Conclusion

We are living through the most consequential change in humanity's relationship with space since the first satellite crossed the sky. The frontier that nations once visited to prove a point is now where they bank, communicate, navigate, and defend themselves and, increasingly, where they may fight. The private sector has given us an extraordinary gift of capability and cost. National security has made that capability indispensable. What we lack is the governance to match.

The choice before us is not whether to embrace this new era (it is already here) but whether we will steward it wisely or let it descend into congestion, debris, and conflict. The decisions we make in the next few years will determine whether low Earth orbit remains a thriving commons or becomes a contested ruin. We built the rockets that opened this frontier. We are fully capable of writing the rules that will keep it open. We should do so now, before the window closes.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

AI Agents Need Accountability That Travels With Them

1 July 2026 at 05:00

Most enterprise AI agents today are still being deployed in controlled environments. They sit inside a platform, perform a defined task and operate under the identity and access controls of that environment, however that window is closing. For many security teams, the current state makes the problem feel manageable. If the agent is inside the fence, the thinking goes, it can be governed by the controls already in place.

That view is understandable. Security teams already have more than enough to manage as AI models become more capable. The near-term implications for vulnerability discovery, fraud, social engineering and incident response are real, and they are moving quickly. Against that backdrop, the question of what happens when agents operate across boundaries can feel like a later-stage concern.

It is not. Identity and access controls can govern an agent inside a particular environment. The harder problem is maintaining accountability when the agent begins operating beyond it. Anthropic’s recentZero Trust framework for AI agents is explicit on this point: each agent instance should have a unique, cryptographically rooted identifier that persists through its lifecycle, appears in logs and access requests, and supports authentication, rotation and revocation. That kind of verifiable identity is what makes safe interoperability possible. As agents move between environments, accountability has to move with them, so the audit trail does not end at the boundary where the risk begins.

The limits of local control

The value of agents comes from their ability to act. They are being designed to invoke tools, coordinate work, exchange information and carry out tasks on behalf of people and enterprises. An agent that can only operate inside one tightly controlled environment may be easier to secure, but it will also be limited in what it can accomplish.

That is the tension enterprises now face. The same interoperability that will make agents valuable will also expand the risk surface around them.

Security leaders are right to focus on the risks already in front of them. More capable models are changing the threat environment in ways that matter right now. But model sophistication is only one part of the issue. The other is autonomy. As agents are given more tools, more permissions and more responsibility, the assumptions behind local control will become harder to sustain.

When Interoperability Becomes A Risk

Most agents are not yet moving freely across enterprise boundaries. Many remain narrow, supervised and limited in scope. But there are two reasons the boundary problem cannot wait.

The first is business value. If agents remain fully contained, their usefulness is constrained. Enterprises will look for returns from AI by connecting agents to more workflows, more tools and more partners. They will want agents to coordinate work across the places where business actually happens.

The second is control. Even enterprises that take appropriate precautions may overestimate how reliably agent activity can remain confined over time. Permissions change. Workflows expand. Tools are added. Business teams find new uses for systems once those systems begin producing value. The environment around agents will keep changing, and accountability needs to remain recognizable when it does.

Security teams are already seeing early versions of this problem in how autonomous AI systems interact with the outside world. An agent exposed to untrusted content may receive instructions the user never sees. An agent with broad permissions may take actions in a context its developers did not fully anticipate. An agent connected to internal data and external communication channels may create a path for leakage or misuse. These are practical control problems, and they become harder to manage as agents gain more tools, more permissions and more autonomy.

For CISOs, the pattern should sound familiar. Some of the hardest security problems emerge at the boundaries between systems, vendors and enterprises. Third-party risk and software supply chain incidents have shown how quickly trust assumptions can break down when no single party controls the full path of activity. Agents introduce a new kind of actor into that same environment. They may be delegated by one enterprise, executed through another platform and interact with a third party in the course of completing a task. In those moments, accountability has to travel with the agent rather than remain tied to the environment where it originated.

The cost of fragmented accountability

In that setting, local identity is not enough. An enterprise may be able to identify and monitor an agent inside the platform where it was created. But once the agent acts elsewhere, that identity may not travel cleanly. Another environment may not know which organization stands behind the agent, whether that relationship can be independently verified, or how trust should be adjusted if circumstances change.

This is where fragmentation becomes a practical security problem. If every platform defines agent identity in its own way, enterprises will inherit a patchwork of trust models. Each may work locally. Together, they create friction at best and gaps in accountability at worst.

Security teams could be left translating between local controls just as agents become more autonomous and more operationally important. That is a difficult place to put defenders. When something goes wrong, they need to know what acted, who was responsible and whether the activity can be contained. Those questions should not depend on which platform created the agent or where it happens to be operating at that moment.

A single high-profile failure could also have consequences beyond the immediate incident. If a rogue or misattributed agent causes material harm, the response could put a chill on the broader market. Security reviews could freeze, integrations could stall and product teams could be forced into a defensive posture as enterprises try to determine which agent activity they can trust. That remains a real risk as long as identity is fragmented and ownership cannot be consistently resolved.

That is not a sustainable foundation for enterprise adoption.

The answer is not to stop agent innovation or force every action back through manual review. That would defeat much of the purpose of the technology. Enterprises want agents because they can move work faster, connect processes and reduce the burden on people. Security teams need a way to support that progress without losing the ability to answer basic questions when something goes wrong.

Which organization stands behind the agent? Can that relationship be independently verified? Can its activity be traced across environments? Can trust be adjusted when circumstances change?

The June 2026 White House executive order on advanced AI innovation and security shows that these questions are now a national priority, one that applies equally across government, industry, and critical infrastructure. The only practical and durable solution for enforcing that is through a standard of accountability that is recognized everywhere.

A standard for portable accountability

Open matters. If the accountability layer for agents is defined separately by every major platform, then trust will fragment at the moment the market needs consistency. Enterprises will face the burden of reconciling competing approaches, and security teams will be forced to govern agents through local controls that do not resolve cleanly beyond their own environments.

A neutral trust layer gives the market a better path. Platforms, model developers, cloud providers and enterprise software companies can still innovate above it. But the basic ability to establish ownership and accountability for an agent should not depend on any one proprietary ecosystem. The trust layer has to be common enough to travel, and that means it’s probably one that already exists.

We have seen this pattern before. The internet was able to grow because certain foundational functions were treated as shared infrastructure. The Domain Name System did not solve every security challenge on the internet, and it was never meant to. But it did create a common way to resolve names across a global network without requiring one company to control the applications and services built above it. AI agents now need a similar foundation for accountability and trust.

That work should begin now, while the agent ecosystem is still forming. Waiting until agents are deeply embedded in enterprise workflows will make the problem harder to solve. By then, fragmented trust models may already be built into products, contracts, integrations and operating processes.

The promise of agents is real. So is the risk surface they introduce. The way forward is to build the accountability layer before fragmented trust models become embedded in the systems that agents will ultimately depend on.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

When Hackers Get AI Co-Pilots: Frontier AI and the National Security Clock

1 July 2026 at 05:00

Five intelligence services rarely speak with one voice. When they warn the window of vulnerability has narrowed to months, the real question is whether the defenders can move as fast as the threat.

Throughout my years in the intelligence world, I don’t recall a single instance in which the Five Eyes partners jointly issued a public warning, so when they do, the message lies in the act as much as the words. Intelligence agencies guard their assessments and share them sparingly, almost never in the open. So, when the United States, United Kingdom, Canada, Australia, and New Zealand jointly warned on June 22 that frontier AI models capable of serious cyber exploitation are only "months away" from broad availability, the unanimity was itself a clear message. "The timeline is not years, it is months," they wrote.

The warning the Five Eyes partners shared is specific. These are systems that let a non-expert coordinate a complex intrusion (work that until recently required a trained team fluent in reconnaissance, exploitation, and stealth). That capability is moving out of the hands of advanced nation states and into the reach of mid-tier criminal groups and other adversaries. As the barrier to a sophisticated operation fall, the target list grows, and the systems most exposed are the ones a country cannot do without hospitals, water and power utilities, community banks, ports, and the contractors that serve them.

There is one caveat to mention. Outside experts who examined the models argued they do not represent a wholly novel threat, and the agencies concede their core remedy is familiar: fix the basics, patch faster, control identity and access. The fundamentals still decide most outcomes. What has changed is speed and, with speed, potential volume. The vulnerability was always there, and AI simply finds it faster and puts that reach into more hands.

For national security planners, "months" is the word that should capture attention. Strategy assumes time, and much of the architecture protecting critical infrastructure was built for an era when a capable intrusion took a capable organization. AI collapses that assumption. A defensive posture written to last three years can be overtaken before its first review, and the slowest links (legacy systems and sluggish patching) are the points an adversary will reach first.

Washington has begun to respond. Executive Order 14409, signed June 2, is best read as the opening move in a national security framework for frontier AI. It directs the NSA and CISA to benchmark in classified settings when a model's cyber capabilities make it a "covered frontier model," and it asks developers to voluntarily give the government up to 30 days of access to such models before release. It stands up an AI cybersecurity clearinghouse β€” led by Treasury β€” to coordinate the discovery and patching of vulnerabilities, and it directs the Justice Department to prosecute those who turn AI against American computer systems. It also pushes to put defensive AI into the hands of the institutions least able to defend themselves: rural hospitals, community banks, and local utilities.

The order is also a move in a broader contest. Representative Andrew Garbarino, who chairs the House Homeland Security Committee, said the same week that China is "months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States." Washington has already moved to restrict the export of a leading frontier model on national security grounds. Whoever fields these capabilities first, and whoever sets the terms for evaluating and controlling them, will shape the rules others must live by. That competition runs straight through the private companies that build the models and the critical infrastructure an adversary would target.

All of this points to the real test. If frontier AI can accelerate attacks, it can accelerate defense, and the side that equips its defenders faster holds an advantage. Programs that put defensive AI into the hands of critical-infrastructure operators, such as Anthropic's Project Glasswing and OpenAI's cyber-defense access effort, are early attempts to give defenders a head start in finding and fixing flaws before they are exploited. The harder problem is people. Models do not run themselves, and the expertise to direct them, in a utility control room or a hospital network, is scarce and unevenly spread across exactly the sectors most at risk.

This is where national security and the private sector stop being separate conversations. Most critical infrastructure is privately owned and operated, which means the front line of national defense now runs through companies whose first duty is to investors and shareholders. The operators that can name the AI systems they rely on, assume their adversaries now carry capable co-pilots, and test their defenses against machine-speed intrusion are the ones that will fare best.

All of this argues for a different compact between government and industry, grounded in shared purpose. Major developers, critical-sector operators, and the national security agencies need to engage early and honestly on the most dangerous capabilities, the way Executive Order 14409 suggests. And the country must invest in defensive AI and in the people who wield it, so the defenders of American systems keep pace with their attackers.

I spent decades in the world of intelligence, much of it managing risk where the cost of getting it wrong was measured in much more than money. The warning the Five Eyes issued this month is the kind that professionals will take seriously. The timeline is tight, and the targets are the systems a society runs on. Frontier AI will define the next era of national power, and the open question is whether the defenders get their co-pilots before the attackers’ finish deploying theirs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The War Before the War Has Already Begun

30 June 2026 at 05:02

There are 65 active state-based conflicts in the world today, according to the Uppsala Conflict Data Program. That is not 65 separate crises. It is 65 living laboratories.

The contest that matters is not understanding any one of them. It is recognizing the 66th β€” the next emerging theater β€” while it is still only a collection of weak signals. The war before the war has already begun, and it will be won by whoever learns fastest.

For generations, intelligence organizations competed to collect more information. Tomorrow, they will compete to learn faster. Since every adversary is becoming a learning organization, our advantage must become organizational learning β€” and organizational learning at this scale requires infrastructure we have not yet built.

That infrastructure includes a Digital Twin Network.

The Network, Not the Twin

The objective is not to build a better digital twin. It is to build a Digital Twin Network capable of recognizing the 66th emerging theater before it becomes obvious.

Imagine a living network of thousands of interconnected digital twins β€” not only of nation-states, but of terrorist organizations, criminal syndicates, cyber groups, critical infrastructure, financial systems, media ecosystems, shipping networks, supply chains, political movements and emerging technologies. Every important actor, network and system has a continuously evolving twin.

Each twin learns independently. Collectively, they learn exponentially.

The value is not in the individual twins. It is in the conversations among them. Every observation by one twin makes the entire network smarter. A political crisis in Bosnia immediately updates neighboring political, economic and alliance twins. A cyberattack against critical infrastructure causes financial, media, logistics and influence-network twins to reassess their own environments. A new disinformation tactic discovered in one region is instantly tested against every other emerging theater.

The network does not simply share information. It shares learning.

This is the shift that matters: from monitoring individual events to understanding how thousands of interconnected systems evolve together. From storing information to accumulating learning. From asking β€œWhat happened yesterday?” to asking β€œWhat is becoming more likely tomorrow?”

What the Network Looks Like in Practice

Picture a digital twin of Bosnia, Moldova or the South China Sea that updates every minute. Every political speech, troop movement, satellite image, shipping pattern, cyberattack, financial transaction and social media narrative automatically changes the model. We move from β€œwhat happened” to β€œwhat is most likely to happen next.”

AI agents do the work, each with a job. One reads every speech. Another tracks every satellite image. Another looks for new alliances. Another measures the speed of narratives. Together they integrate political developments, military movements, economic indicators, migration, social sentiment, infrastructure, weather, cyber activity and media into a single continuously updated model β€” one that can identify change in seconds, minutes and hours, and simulate the impact of future actions.

The ability to rank the most successful future actions, based on analysis of hundreds of potential outcomes, changes how we think about red teaming in cognitive security. We will be able to build a synthetic example of every adversary of any size, and to simulate every scenario continuously.

It will be on us to feed in the right inputs. What emerges is a global learning graph of active conflicts β€” every lesson, every pattern, every conflict feeding better insight in real time.

How the Network Learns: Observe, Learn, Adapt

Conflicts are like a staircase: pressure, politics, perception, prosperity, partnerships, posture, provocation. Every conflict climbs the staircase differently. A network that can read that staircase across every theater at once needs three disciplines.

Observe. We are good at collection. We will benefit from a common structure that makes our observations legible to AI. As an example, The Seven Layers of Emerging Theater Intelligence (SETI) gives every twin the same language for evaluating how adversaries evolve before open conflict:

Pressure β€” Are underlying conditions becoming less stable?

Politics β€” Are institutions losing the ability to manage that pressure?

Perception β€” Is someone deliberately shaping how people interpret events?

Prosperity β€” Are economic tools becoming instruments of competition?

Partnerships β€” Are actors beginning to choose sides?

Posture β€” Is capability being positioned?

Provocation β€” What event could rapidly accelerate escalation?

Learn. The measure of the network is its learning velocity β€” how quickly it improves after every observation. Every conflict becomes a research dataset where the network continuously asks: Which indicators appeared earliest? Which signals were ignored? Which combinations proved most predictive? Which assumptions proved wrong? Which interventions slowed escalation? Which technologies changed outcomes?

Adapt. The network tracks how media and technology are evolving and how they will change future tactics. Whether it is artificial intelligence, autonomous agents, commercial satellite imagery, cyber capabilities, sensors, recommendation algorithms or open-source techniques, we watch how each one shortens the distance between pressure and politics, perception and partnerships, posture and provocation.

All of it feeds back into the twins. SETI gives the network a common language; learning velocity gives it a scorecard. Together they make the network something fundamentally different from today’s intelligence systems β€” a living research community that studies all 65 active conflicts every day and asks the same questions of each. Which pressures are increasing? Which partnerships are changing? Which narratives are spreading? Which actors are learning fastest? And, most important, where is the next theater beginning to resemble the early stages of previous conflicts?

The Scale of the Build

This is why the build matters, and why it must begin now. A network worthy of the threat means digital twins for every nation-state adversary, roughly 100 foreign terrorist organizations, 500 major transnational criminal organizations, 300 state-sponsored cyber groups, hundreds or thousands of hacktivists, 600 militias, insurgencies and armed non-state actors, and thousands of influence and disinformation networks.

That represents a good start.

As AI, autonomous agents and eventually quantum computing mature, the scale of continuous learning will expand dramatically. The future of intelligence will belong to organizations that treat every conflict as a learning system, every emerging theater as a research project, and every observation as a chance to improve faster than their adversaries.

The Only Question That Matters

The race is no longer to understand today’s 65 conflicts. It is to recognize the 66th emerging theater before anyone else β€” while it is still only weak signals.

That is a contest of learning, and learning at that scale cannot be improvised in the moment a crisis arrives. It has to be built in advance. The Digital Twin Network is that build.

The war before the war has already begun. The only question is whether we will have the network in place to see it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌
❌