Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Cipher Brief

Pakistan’s New Military Order Is a Warning for Washington

9 September 2026 at 08:33

In Washington, Field Marshal Asim Munir increasingly looks like the man who can make Pakistan useful to the United States. Pakistan has just written Munir even more deeply into the architecture of the state as he now sits atop a legally centralized command that reaches conventional forces, strategic systems, and the prime minister’s national-security advice. Munir, now formally serving as Chief of Defense Forces, speaks directly with President Donald Trump and has become Washington’s principal channel for engaging Tehran.

The latest restructuring of Pakistan’s military command has actually made the opposite case. The 27th Constitutional Amendment, followed by legislation passed this month to implement the new command architecture, has concentrated unprecedented authority in Munir’s hands. Yet his military cannot stabilize Pakistan-administered Kashmir, cannot contain the Tehreek-e-Taliban Pakistan (TTP) and Baloch insurgents, and has still signed a mutual-defense pact with Turkey and Saudi Arabia—dubbed the Mecca Accord—that could drag it into distant crises. For the world, treating Pakistan as a reliable intermediary in negotiations with Iran would be a mistake of timing and of judgment as the state becomes more militarized domestically, more ambitious diplomatically, and increasingly overstretched militarily.

A Field Marshal Above the State

In November 2025, the 27th Constitutional Amendment abolished the chairman of the Joint Chiefs of Staff Committee and created the office of Chief of Defense Forces (CDF), held concurrently by the army chief. The restructuring was completed with another step this month when Pakistan’s parliament passed the Defense Forces Act 2026 and amendments to the National Command Authority Act, providing the statutory framework for Munir's new position and headquarters. The new architecture gives the CDF a central role in operational command and joint military coordination across the armed forces.

The new law places the army, navy, and air force under a unified Defense Forces Headquarters commanded by Munir. He is designated the prime minister’s principal military adviser on national security and defense and exercises operational command and control across the services with sweeping personnel authority—hiring, firing, retirement, and extensions. Amendments to the National Command Authority law align nuclear and strategic command with the same hierarchy, with a new four-star Commander of the National Strategic Command sitting alongside the CDF. The significance goes beyond military administration, as Munir now occupies a position from which military command, strategic security policy and foreign-policy influence converge. He is not constitutionally Pakistan's president or prime minister, but describing him merely as a military officer increasingly misses the political reality. Such radical consolidation of power in Pakistan’s civil-military landscape matters for Washington because the United States is increasingly treating Munir personally as a diplomatic asset. Therefore, Washington must factor in that any “Pakistani” channel on Iran now runs, in practice, through a single command that answers first to its own institutional interests.

Consolidation Without Control

The strongest argument against treating Munir's Pakistan as a reliable strategic partner can actually be found inside Pakistan itself. The military has acquired unprecedented institutional power, yet the state remains under enormous security pressure. Pakistan Institute for Conflict and Security Studies data show that July 2026 was the deadliest month of the year, with 606 people killed in militant violence and counter-militancy operations, including 112 security personnel and 401 militants. The violence is concentrated precisely in Khyber Pakhtunkhwa (KPK) and Balochistan, where Pakistan's military has struggled for years. Such a security landscape is a sustained counterinsurgency burden for a military that is simultaneously presenting itself as a regional security provider.

The latest round of violence in Pakistan-Administered Kashmir has added another layer of security burden for an overly stretched military. In the surrounding areas of Rawalkot, Pakistan-administered Kashmir, protests led by the Joint Awami Action Committee (JAAC) escalated after authorities outlawed the movement under anti-terrorism laws, suspended mobile data and internet services, and deployed security forces ahead of a JAAC-organized June 9 strike. According to a local human rights watchdog report dated August 8, at least 89 civilians died in Pakistan-administered Kashmir as a direct result of the state’s brutal crackdown on unarmed protesters.

Locals demanded cheaper power from dams that generate electricity for Pakistan, representation that is not diluted by non-resident seats, and an end to elite privileges. The state’s answer was lethal force, sedition cases, travel advisories, and the criminalization of a civic coalition that had previously extracted limited subsidies through protest. That is the Balochistan playbook applied to a territory Pakistan still markets internationally as “Azad” or free. It did not produce consent but a banned movement, underground leaders, and a legitimacy crisis inside a territory the army treats as strategic hinterland. If Munir’s new command structure was meant to deliver coherence, Kashmir shows the opposite, where a security establishment that can rewrite the constitution faster than it can address bread-and-butter revolt. An army that cannot manage a rights protest in Muzaffarabad and Rawalakot without mass casualties is not an army that can be trusted to midwife a delicate regional settlement with Iran or be a reliable partner for the so-called Mecca Accord.

Pakistan’s Utility Should Not Be Mistaken for Reliability

US talks with Iran already sit on a knife-edge of “Economic D-Day” politics, Hormuz control, and factional vetoes inside Tehran. None of this means the United States should abandon Pakistan as that would be strategically simplistic. Pakistan remains nuclear-armed, sits between Iran, Afghanistan, India and China, and retains diplomatic access across the Muslim world. Its ability to communicate with Tehran can be useful, particularly when direct US-Iranian channels are blocked. Three factors that Washington should use to distinguish between utility and reliability while dealing with Munir’s Pakistan:

First, Munir’s legal supremacy does not equal policy reliability. A CDF who is also army chief, principal adviser, and strategic-command fulcrum will filter any Iran file through the army’s need to look indispensable at home—that incentive points toward swagger, not quiet brokerage.

Second, Washington cannot treat Islamabad’s internal security failure as a side issue. An institution that answers civic protest in Kashmir with live fire and a terrorist ban is the same institution that would be asked to counsel restraint, verification, and de-escalation with Iran. The record says it prefers coercion when legitimacy frays.

Third, Munir’s capacity is already committed to a plethora of insurgencies. TTP and Baloch campaigns consume attention, ammunition, and men. A Mecca clause adds hypothetical external obligations without adding spare combat power. A partner that is simultaneously over-centralized and overstretched cannot deliver the one thing Washington would need from it: consistent, low-drama influence on a file that can restart a wider war.

If the United States wants Pakistan to help mediate with Iran, it should judge Islamabad by the outcomes of that diplomacy, not by the personal access Munir enjoys in Washington. And if Washington wants Pakistan as a security partner, it should look beyond the impressive authority of its field marshal to the increasingly unstable state that authority is supposed to govern. A stronger Pakistani army does not automatically produce a stronger Pakistan. And a stronger Munir does not automatically produce a more reliable American partner.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The AI We Cannot Deploy — And What Is at Stake

8 September 2026 at 08:49

Last week, I argued in these pages that the United States is buying an army it cannot command — writing procurement checks at a scale its adversaries cannot match, without writing the doctrine or arbitration to decide how the capability behind those checks gets used. Not everyone agreed. The sharpest pushback came from readers with institutional equity in the current procurement path — those with the most to lose if the diagnosis is right. Fair question they kept asking: what is at stake if we get this wrong?

The answer arrived this week, and it is not what most observers are watching.

Beijing is pursuing a two-pronged strategy against the American artificial-intelligence industry, and neither prong depends on beating American laboratories on model capability. The first prong attacks the market instrument that finances the industry: paid enterprise access to closed frontier models at premium margins. The weapon is state-backed open-source saturation of the global developer market. When Chinese laboratories release high-performing models at zero marginal cost, the price American laboratories can charge collapses — and with it, the revenue that funds tens of billions in specialized compute committed to their pipelines.

The second prong is architectural. American frontier laboratories run closed models in centralized data centers connected to their customers via fiber. The Pentagon has awarded contracts for missions that cannot use that architecture — drone swarms, autonomous undersea platforms, cognitive attack detection, and tactical multi-sensor fusion. Consider a drone swarm over the Taiwan Strait that must identify and engage a hostile target in seconds. It cannot query a compute cluster in Virginia and get an answer in time. The bandwidth needed in a denied, degraded, intermittent, or limited spectrum environment is unavailable. Chinese research has shifted toward Large Concept Models — smaller, edge-resident, multi-sensor — that run on the platform and fuse light-detection-and-ranging, radiofrequency, electro-optical and infrared, and acoustic inputs at the edge, without a network dependency an adversary can touch.

This is not a theoretical architecture. Ukraine is running it now. Ukrainian drone units operate with organic, edge-resident targeting within seconds of adversary contact, without a reliable network back to headquarters. Ukrainian schools graduate thousands of drone specialists each year. The country teaching NATO the most about the next fight is doing so in the register the American AI stack cannot yet operate in. The contracts are being placed. The integration doctrine has not yet been written.

Beijing has run this playbook before. Western economies depend on China for rare-earth and critical-minerals processing — the industry that supplies permanent magnets, batteries, and defense electronics. Every F-35 electric-actuation system, every Virginia-class submarine drivetrain, and every Patriot interceptor guidance package relies on rare-earth processing capacity the United States cannot reconstitute within a decade. That capacity was lost not because the deposits lie under Chinese soil but because Beijing sustained state-subsidized processing for twenty years at prices that broke the private-sector cost of capital in every alternative jurisdiction. Open-source artificial intelligence is the same instrument, aimed at a different substrate.

What is at stake?

First, America's most consequential capital-expenditure cycle. Roughly $400 billion a year in AI infrastructure is financed against a revenue model an opposing state has organized its economy to defeat. If that model breaks on Beijing's timeline, the compute pipelines carrying a meaningful share of American growth do not close.

Second, Pentagon operational readiness. Contracts placed today for missions the Pentagon needs to field in three to five years cannot be executed by an AI stack designed for centralized data centers. Platforms that cannot operate in a multidomain and joint-force environment at wartime tempo are not a deterrent. They are procurement projects.

Third, alliance credibility. Sovereign AI programs in Korea, Japan, and the Gulf price today against the American premium-margin model. If it breaks, those programs re-price against Chinese open-weight tooling, and the alliance's technological dependency structure shifts.

Fourth, deterrence. The Taiwan Strait scenario is not theoretical. The platforms that would decide it are being contracted for now, on an architecture that cannot execute the mission at wartime tempo.

What needs to happen requires an integration authority the American sovereign apparatus does not yet exercise. Two responses.

A state-capacity capital response to the first prong. Some form of federal instrument that bridges the compute-to-market pipeline so a Chinese-organized collapse in AI pricing does not take the compute build-out with it. Export-import financing, defense production authorities, and strategic stockpiles are the precedent. No current U.S. government office owns this problem.

A Pentagon-led investment in a distributed inference substrate — the shape of what the Joint Fires Network concept was originally designed to be. Edge-native, platform-resident, multi-sensor, doctrinally integrated. This is procurement of an integration architecture as much as procurement of a technology. The Pentagon has placed the contracts for the platforms. It has not placed the contract for the integration.

Last week I wrote that America is buying an army it cannot command. The diagnosis has evolved: America is also buying an artificial intelligence it cannot deploy. Ukraine is teaching the doctrine the American AI stack has not been designed to run. Beijing is engineering the collapse of the revenue model that stack is financed against.

Coordination assigns. Integration arbitrates. What is at stake is whether the American sovereign apparatus can find the integrator — for the capital response and the operational doctrine — before the platforms the Pentagon is buying arrive without an architecture capable of commanding them.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The New Economics of Warfare: David vs Goliath

4 September 2026 at 11:09

The most important lesson emerging from the Iran conflict may not actually be about Iran. It is about the changing economics of warfare and what happens when autonomy, artificial intelligence, commercial technology and inexpensive mass begin eroding advantages once reserved almost exclusively for major powers.

In many ways, modern warfare is increasingly becoming a story of David versus Goliath. The difference is that today’s David is armed with drones, software, commercial sensors, open-source intelligence and rapidly adaptable technology. Goliath still has overwhelming advantages in scale, firepower and resources, but the sling has become far more sophisticated — and far cheaper.

For most of the modern era, advanced military power belonged overwhelmingly to countries capable of spending billions of dollars on sophisticated aircraft, warships, missiles, sensors and command-and-control infrastructure. That advantage is not disappearing. Aircraft carriers, submarines, advanced fighters, bombers and integrated missile defenses remain essential instruments of national power. But the economics beneath them are changing as autonomy, AI, inexpensive sensors, commercial communications, advanced manufacturing and widely available components lower the cost of creating meaningful military effects.

Ukraine provided the first large-scale demonstration of this shift. A materially weaker “David” used drones, software, commercial technology, open-source intelligence and rapid battlefield innovation to impose extraordinary costs on a much larger Russian “Goliath.” Ukraine did not eliminate Russia’s advantages in manpower, missiles, aircraft or industrial capacity. It showed that technology could narrow the gap without matching a stronger adversary platform for platform.

Iran is now demonstrating another version of the same problem. Tehran cannot compete with the United States carrier for carrier, fighter for fighter or missile-defense battery for missile-defense battery, but it does not need to. Iran has spent decades investing in missiles, drones, proxies, cyber capabilities, maritime harassment, information warfare and strategic geography precisely because those tools allow a materially weaker power to impose disproportionate costs on a stronger one.

That is the economic logic of asymmetric warfare. An inexpensive autonomous aircraft does not need to outperform an F-35, and a small unmanned surface vessel does not need to defeat a destroyer in a traditional naval engagement. It only needs to create enough risk that the defender is forced to respond. When one side can repeatedly spend thousands or tens of thousands of dollars and compel the other to spend hundreds of thousands or millions, the exchange ratio eventually becomes strategically significant.

The United States cannot build a sustainable long-term strategy around answering every inexpensive drone with a multimillion-dollar interceptor or every maritime threat with another billion-dollar warship. That does not mean exquisite platforms are obsolete. It means using exquisite platforms to solve every problem eventually becomes economically unsustainable.

The more useful debate is not whether a drone can replace a fighter or whether an autonomous vessel can replace a destroyer. They cannot. The better question is how many missions currently concentrated aboard expensive crewed platforms can migrate toward cheaper autonomous systems: surveillance, reconnaissance, communications relay, target detection, electronic sensing, mine detection, logistics, persistent maritime presence, decoys and distributed weapons carriage.

Technology disruption rarely begins by replacing an incumbent system outright. It begins by stripping away individual functions. Instead of asking whether one autonomous vessel can replace a destroyer, military planners should be asking what happens when dozens of autonomous vessels operate around that destroyer, extending its sensing range, complicating enemy targeting, absorbing risk, providing persistent presence and allowing the crewed combatant to operate farther from danger. The destroyer remains essential, but its role changes.

Artificial intelligence accelerates this transition because it changes the manpower economics of military mass. Traditional military power is extraordinarily manpower intensive. Every additional aircraft, ship or vehicle generally requires crews, training, maintenance and support personnel. Software scales differently. As autonomous systems become more capable of navigating, sensing, classifying targets and coordinating with one another, fewer operators may eventually supervise far larger numbers of assets.

The strategic value is therefore not simply removing a sailor or pilot from danger. It is changing the relationship between manpower, mass and military capability. Ukraine has also shown how quickly this cycle can evolve: operators identify a battlefield problem, engineers modify hardware or software, the adversary develops a countermeasure, and the system changes again. That cycle can occur in weeks while traditional acquisition processes often operate in years. The widening gap between those timelines is becoming a national-security vulnerability.

Iran also demonstrates why the economics of modern warfare extend far beyond the price of a missile or drone. Consider the Strait of Hormuz. Iran does not need to defeat the U.S. Navy in a traditional fleet engagement to create a strategic crisis. It needs only to generate enough uncertainty around one of the world’s most important maritime chokepoints to affect shipping behavior, insurance premiums, energy markets, naval deployments and political calculations thousands of miles from the battlefield.

A drone does not necessarily need to sink a tanker to be successful. If it forces commercial vessels to reroute, raises insurance premiums, pushes energy prices higher, requires additional naval escorts and generates political pressure in Washington or allied capitals, it may have produced a strategic return far beyond its acquisition cost. The Strait of Hormuz is therefore not merely geography; it is economic leverage.

The same logic applies to the Bab el-Mandeb, the Red Sea and other maritime chokepoints. Protecting those spaces exclusively with crewed ships and aircraft is extraordinarily expensive. Autonomous maritime systems offer another model by providing persistent surveillance, distributed sensing, electronic warfare, communications relay, logistics and eventually additional defensive or offensive capacity without the manpower burden of conventional warships.

The future fleet will almost certainly be hybrid. Submarines, destroyers, carriers and advanced aircraft will remain critical, but they will increasingly operate inside larger networks of autonomous systems. The same principle applies to the defense industrial base. The United States is not going to replace traditional primes with startups, nor should it. The engineering, manufacturing and systems-integration capabilities required to build submarines, bombers and complex weapons remain indispensable.

But the traditional model cannot remain the only model. Modern warfare increasingly rewards an ecosystem that combines established defense companies with emerging technology firms, commercial manufacturers, software companies, universities, private capital and government laboratories. The industrial challenge is no longer simply building the most sophisticated weapon. It is building sophisticated weapons while also producing enough affordable systems to create mass, replace losses and adapt faster than the adversary.

Quantity is not a substitute for quality, but quality alone is not enough if an adversary can manufacture threats faster and more cheaply than the defender can respond to them. A weapons system that performs extraordinarily well but cannot be produced in sufficient quantities or replaced during a prolonged conflict carries its own strategic vulnerability.

There is another cost curve collapsing alongside hardware: information. Artificial intelligence and social media are dramatically reducing the cost of conducting information and cognitive warfare. An inexpensive drone can force an expensive military response, while an AI-generated video, manipulated image or coordinated social-media campaign can create political effects at almost no marginal distribution cost.

Iran, Russia and China understand that these domains reinforce one another. A tanker is attacked, insurance rates rise, energy markets react, images spread across social media, and AI-enabled narratives amplify fear or confusion. Physical warfare, economic warfare and cognitive warfare increasingly operate as parts of the same system. A missile can therefore be intercepted and still produce strategic effect if it forces millions of dollars in defensive spending, disrupts commerce, dominates media coverage and creates the perception that an adversary controls the pace of escalation.

That is why modern warfare can no longer be measured exclusively through targets destroyed or territory captured. Costs can be military, but they can also be economic, political and psychological. The United States still possesses extraordinary technological and military advantages; the greater danger is economic rigidity.

America and its allies cannot allow adversaries to consistently dictate exchange ratios in which cheap systems consume expensive defenses, small attacks produce major commercial disruptions and rapidly evolving technologies are answered by procurement processes that take years. The answer is not abandoning exquisite weapons, but building a broader force architecture around them: autonomous mass, distributed sensors, AI-enabled command and control, resilient manufacturing, commercial intelligence, lower-cost interceptors, modular payloads and systems capable of evolving at something closer to software speed.

Cold War 2.0 will therefore not be determined solely by which country builds the best fighter, submarine, missile or autonomous system. It will also be determined by which side can manufacture capability faster, distribute it more broadly, replace it more cheaply, adapt it more quickly and impose greater costs on an adversary than it absorbs itself.

Ukraine demonstrated how a modern-day David can use technology to challenge a much larger conventional Goliath. Iran is showing how a materially weaker state can use technology, geography and irregular warfare to impose disproportionate costs on a superpower. China is watching both.

The competition underway is increasingly a competition between military-economic systems. Goliath still matters, but the battlefield is changing in ways that increasingly empower David. The side that prevails may not be the one that builds the most exquisite individual weapon, but the one that can keep adapting, producing and fighting after the other discovers that it cannot.

This keeps the David-versus-Goliath analogy as a recurring frame rather than a gimmick—once near the opening, concretely through Ukraine, and again in the conclusion.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Foreign Spies Don’t Need to Hack You Anymore

26 August 2026 at 13:43

Andy Burnham was a few weeks into the job as the new Prime Minister of the UK when he found himself exchanging messages with someone claiming to be Susie Wiles, the White House chief of staff. The exchange, first reported by Politico last week, was brief and apparently trivial. Burnham grew suspicious, stopped replying and told the right people; the British embassy in Washington quietly informed the White House, which confirmed that Wiles’s own devices hadn’t been touched. No harm done, officially.

Embarrassments like this are becoming more common. The FBI warned last year about impostors using AI to mimic senior officials, after someone posing as Wiles contacted senior Republicans and business figures. The State Department later chased a fake Marco Rubio who reached three foreign ministers. And every one of these approaches lands on a habit “Signalgate” already exposed: when one wrong contact card could add a journalist to a strike-planning thread, the name on the screen was the only authentication in the room. If you want to see what this security weakness looks like run as a nation-state campaign look at a case that closed quietly in Taipei last month.

In July, prosecutors in Taipei’s Shilin district wrapped up proceedings against two local businessmen, Li Hualun and Chen Mengsen, who had spent months registering accounts on LINE (the messaging app nearly everyone in Taiwan uses), each tied to a real Taiwanese phone number. They leased the accounts to Xiamen Empress Information Technology, a mainland firm Taiwanese investigators say works under the direction of the Chinese Communist Party’s cyber forces. The going rate was about 1,100 RMB per account, call it $160.

A working exploit for a major platform costs millions on the gray market. A trusted local identity cost less than a decent dinner, and it did something no technical exploit can do.

The operators used the fake accounts to become journalists. In the approach that eventually unraveled the scheme, one of them even dressed up a leased account in the name and photo of Chen Yishan, editor-in-chief of CommonWealth Magazine, and began courting an aide in a legislator’s office. Interview requests, invitations to contribute articles, the ordinary traffic of political journalism followed.

There was no malicious link in the first message, or the tenth. Investigators found the operators worked on targets for months, sometimes close to a year. Any counterintelligence officer would recognize the rhythm. It was the patient cultivation and recruitment of an agent run through a chat app.

The eventual ask was small and reasonable-sounding. Journalists use encrypted tools to protect their sources, so would the contact mind installing a secure communication app to keep talking? The app was in fact malware. The MO turns a decade of good security advice inside out. The more someone knew about how careful reporters actually operate, the more normal the request looked.

Researchers at Citizen Lab and the International Consortium of Investigative Journalists, whose reporting the Taiwanese prosecution now corroborates, counted more than a hundred malicious domains behind the wider campaign, and found errors in the phishing messages suggesting the attackers were using AI to draft them and to pick targets. The people on the receiving end were lawmakers and their staffs, defense think tanks, semiconductor companies, dissidents at home and abroad. Taiwanese media reported that even the island’s overseas missions were probed.

Through all of it, nothing technical failed. The networks held and the patches were current. The attackers went around the security stack entirely, and the thing they spent, their actual operational currency, was the credibility of a free press. Every fake interview request makes the real ones a little harder. This cost never shows up in an incident report.

The two men who supplied the accounts got deferred prosecutions and payments totaling a bit under $6,000. That is the current legal price, in a frontline democracy, for renting identity infrastructure to a foreign intelligence service. It isn’t a deterrent. It’s barely a business expense.

Which brings us back to Downing Street. A prime minister with the full apparatus of British intelligence behind him replied to a stranger because the name on the screen looked right. Nothing in either story depends on LINE, or Taiwan, or Westminster.

Swap in WhatsApp or LinkedIn; swap the fake editor for a fake recruiter or a fake chief of staff. Aged, locally registered accounts are already a commodity in criminal markets. All the model requires is a person who handles something worth stealing and a persona they have no fast way to check.

That last part is fixable, though not by the security team alone. Organizations that handle sensitive work should treat identity verification as a counterintelligence habit. Platforms need to treat the account-rental trade Taiwan uncovered as the national security problem it has become rather than a terms-of-service nuisance. And legislatures need to punish collaboration with foreign intelligence services at something above a traffic ticket.

Mostly, though, the people likeliest to be approached — the legislative staffer, the fab engineer, the think-tank fellow, the human rights activist, apparently the occasional head of government — need to become more educated on how foreign intelligence cultivation and targeting actually works: slowly, warmly, and with no suspicious link in sight until the very end. The adversary in this case looked at hardened networks and vigilant software and made a rational choice. Building a fake trusted persona was cheaper — $160 a head – than spending millions on a sophisticated cyber exploit. We need to start defending the credibility of verified, trusted identifies the way we defend our networks: as the attack surface it already is.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

China’s Research Espionage Threat Is Hiding in Plain Sight

21 August 2026 at 09:02

Western universities and laboratories are on the frontlines of a battle over talent and technology. This assertion may seem like scaremongering, but when cold hard facts are considered, it is unfortunately true. The Chinese Communist Party (CCP) is undertaking an unprecedented assault to obtain scientific and technical research from the west. The broad CCP assault requires an equally broad response that must now include vetting for insider threats at universities and laboratories to bolster research security.

Spies Among Friends

In the present context, insider threats can be most usefully understood as existing on a spectrum, from fully paid-up agents (a spy in popular parlance) to research collaboration that could benefit a hostile foreign power.

There is a long history of hostile states exploiting academic freedoms at western universities. A hundred years ago, because the Soviet government had few diplomatic relations with foreign governments, it relied on intelligence officers without diplomatic cover, known as illegals. One of the earliest known illegals entered MIT as a student in 1938, Semyon Markovich Semyonov (codename TVEN). He was tasked with collecting scientific and technical research. It was, however, in the other Cambridge, in England, where Soviet intelligence had its greatest success. The Cambridge Five – Kim Philby, Guy Burgess, Donald McClain, Anthony Blunt, and John Cairncross – were all recruited at or soon after leaving Cambridge University in the 1930s. The Cambridge Spies were each motived by communist ideology, shaped by their intellectual discussions at Cambridge. During World War II, they became hugely damaging Soviet agents inside the British government. Some of the most important intelligence they gave to Moscow was the activities of codebreakers at Britian’s Bletchley Park.

The greatest Soviet insider threats occurred at an American top secret wartime laboratory to build the world’s first atomic bomb. The MANHATTAN Project was fully penetrated by Soviet agents. The Soviet agent, Klaus Fuchs, a brilliant physicist working at Los Alamos National Lab, provided Moscow blueprints and calculations for the atomic bomb. He was motivated by his communist ideology and the belief that nuclear weapons should not be held by one power alone. Fuchs later said that he divided his mind into two compartments: one for his friends and colleagues, the other for his communist beliefs, with the latter always superseding the former. It was, Fuchs said, a kind of controlled schizophrenia which allowed him to betray his friends and colleagues. Soviet espionage at the MANHATTAN Project accelerated Soviet development of Moscow’s own atomic bomb. Accelerating research and development is the essence of what espionage can achieve. The intelligence provided by Fuchs and other agents at Los Alamos meant that when the Soviets detonated their first atomic bomb, in 1949, it was an exact replica of the weapon the US dropped on Nagasaki four years earlier.

After the end of the Cold War, in the 1990s, Chinese espionage replaced Soviet intelligence at Los Alamos. At the end of that decade, Chinese intelligence was discovered to have obtained nuclear secrets from the New Mexico laboratory. 9/11 interrupted and distracted the US response to Chinese intelligence at Los Alamos.

Vetting

The penetration of the Cambridge Spies and agents like Klaus Fuchs, represented one of the greatest failures of western security in modern time. They were able to inflict their damage thanks to inadequate vetting by the British government. At the time, British vetting relied on a cross check on MI5 records. There were no proactive investigations into applicants’ backgrounds. The obvious flaw in the system was that if a candidate distanced himself or herself from communist associations there would be no traces in MI5 records. The Soviet recruiters of the Cambridge Five skillfully got them to do exactly that: breakaway from all communist groups. Thus, the Cambridge Five were able to slip through the British security net. Only later did MI5 obtain records of the Cambridge University socialist club, which contained names of the Cambridge Five and which could have provided important clues to their true motivation.

After the identification of the Cambridge Spies, beginning in 1951, the British government belatedly introduced positive vetting – in which there were intrusive investigations into a candidate’s background. Today the process is known as Developed Vetting. As the recent scandal of Lord Mandelson’s appointment to British Ambassador in Washington shows, the process of Developed Vetting is purely advisory. The decision to employ an applicant is up to the employing body itself.

In the CCP Crosshairs

The CCP has a strategy to exploit western research and development. The CCP has instigated a number of talent programs, by which Chinese researchers are sent to western institutions, but are then required to return to China, bringing the fruits of their research with them. A variant of CCP talent programs is to exploit Chinese diaspora scientists at western institutions, often by blackmailing them through family members and China itself. Such talent programs are part of the CCP’s national rejuvenation program by which it seeks to replace the United States as the world’s leading economic and military power. The CCP demands that any research and development that cannot be delivered from homegrown talent must be obtained from overseas. As well as talent programs, the CCP also exploits research collaboration with western universities and laboratories. There is in principle nothing wrong with this, as long as such western institutions appreciate that the CCP will try to steal any intellectual property produced by such collaborations. The problem arises when western scientists hide their connections to Chinese entities, as was the case with former Harvard professor of chemistry, Charles Lieber.

Frequently Chinese researchers are not forthcoming about their continued affiliation with the Chinese military. For example, open-source data obtained and analyzed by a private sector strategic intelligence firm, Strider Technologies, shows that since 2020 over 8,000 STEM publications have involved collaboration between Chinese military entities and more than 100 UK institutions. The Chinese – UK research collaboration includes dual use technology – those with civilian and military application – such as hypersonics and antijamming communications.

Russia is also pursuing research collaborations with western institutions, with the aim of obtaining dual use technologies[CW1] .

A new approach

There will always be a need for traditional vetting for sensitive positions in western governments involving national security. It would, however, be mistaken to think that such vetting is comprehensive.

In the past, vetting required full state-backed resources. Today, that is no longer the case. Private sector companies are now able to use AI driven open-source data to reveal insider threats which, in some cases, western governments have missed. In 2022, for example it was revealed that a group of Chinese scientists working at none other than Los Alamos returned to China bringing with them research into defense technologies like hypersonics. The perversity of this situation cannot be overstated: US national defense research was benefiting the principal US adversary.

Bold action is needed. Western governments would be well advised to establish oversight bodies to identify vulnerabilities in research with military or dual use application. All such research positions can and should be vetted by open-source private sector providers. A subset of academics and civil libertarians will inevitably denounce this as unduly invasive. The fact that such vetting would be based on open-source data should, however, ameliorate those concerns. Furthermore, incase there are concerns about racial profiling, the vetting would pertain to the research positions not researchers themselves.

Ultimately the issue at stake is about western economic security – the intellectual property that will provide western economic prosperity. Think of western AI frontier laboratories. The question is whether the west is prepared to allow the secrets of this century’s technologies to be transferred to the west’s principal strategic adversaries, China and Russia.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Military Interoperability: The Coalition Challenge of Limited War

21 August 2026 at 08:57

In our last two articles for The Cipher Brief, Sami Omari and I explained why modern limited wars are so challenging for democracies.

We argued that military superiority is necessary but not sufficient for strategic victory: Afghanistan and Iraq showed that battlefield success does not guarantee lasting political outcomes, and Iran may yet prove the same point.

We also examined why democracies struggle to translate tactical success into strategic achievement: fragmented institutions, electoral cycles, public opinion and media scrutiny complicate the political resolve required for prolonged wars of choice.

The challenge becomes greater when democracies fight as coalitions.

Alliances combine military power, share costs and draw on capabilities few states could sustain independently.

But military integration does not produce political unity.

Each member remains accountable to its own electorate, parliament and national interests. A coalition may therefore be highly integrated on the battlefield while remaining politically and strategically decentralised.

In prolonged limited wars, military interoperability is not enough if allies cannot sustain the political will, industrial capacity and common strategic purpose required to endure.

II. Why Democracies Fight in Coalitions

The nuclear age made direct great-power war prohibitively dangerous, shifting competition towards limited wars, insurgencies and proxy conflicts.

Western militaries increasingly moved towards smaller professional forces equipped with more advanced weapons, shaped by technological progress and new strategic realities.

After 1991, the Gulf War and subsequent operations against weaker adversaries appeared to vindicate the effectiveness of Western expeditionary forces.

But smaller professional militaries and increasingly expensive weapons also made allies progressively dependent upon one another. Coalitions allowed democracies to aggregate military power, intelligence, logistics and specialised capabilities without each maintaining the forces and industrial capacity required for large-scale national mobilisation.

For thirty years, that system seemed to work.

Russia’s war against Ukraine has exposed these vulnerabilities over several years; the US-Israeli war with Iran is now testing many of the same assumptions.

Both demonstrate that limited wars can become contests of manpower, industrial capacity and political will.

Of these pressures, political endurance is perhaps the most difficult for democracies to sustain.

III. The Political Endurance Problem

For democracies, fighting a long, limited war depends as much on political legitimacy at home as on military capability.

In wars of choice, where national survival is not at stake, governments must continually justify why the costs of war remain necessary.

Initial public support may create space for intervention, but it erodes as casualties rise, costs accumulate, and the prospect of a clear strategic outcome grows uncertain.

Casualties alone do not determine support.

Democratic societies have accepted heavy losses when citizens believed a war was legitimate, necessary and winnable.

The deeper problem emerges when the link between sacrifice and strategic purpose becomes unclear. As confidence in success fades, losses that once seemed tolerable turn politically damaging. Elections, parliamentary opposition, media scrutiny and changes of government then allow declining public confidence to reshape national strategy. Afghanistan illustrated this over two decades.

Western military superiority was never in doubt, but political will steadily weakened. The longer the war continued without a convincing political end state, the harder it became for democratic leaders to explain what more time, money and lives would achieve.

Authoritarian states face similar pressures but, without competitive elections and independent media, can better insulate strategic decisions from public opinion.

Against democratic opponents, this creates a critical asymmetry: a weaker adversary may not need to win militarily, only survive long enough for democratic political will to erode.

IV. The Industrial Endurance Problem

Political endurance is only one side of the problem. The other is material.

Since the Cold War, Western militaries have increasingly relied on technology instead of mass.

Smaller professional forces employ sophisticated aircraft, ships, missiles and networked systems aimed at achieving decisive results while minimising casualties. But each generation of weapons is more expensive and complex, production runs shrink, and replacing battlefield losses becomes harder as war drags on.

The United States can absorb these pressures better than smaller allies because of its defence budget, technological base and industrial scale.

Even so, American forces became smaller, while defence-industry consolidation reduced the number of manufacturers capable of producing specialised weapons. For smaller allies, limited budgets forced difficult choices between personnel, platforms and munitions, while dependence on American weapons, software, supply chains and sustainment deepened.

Quick wars against weaker opponents long obscured these problems.

Ukraine has brought them sharply to the surface, while the Iran conflict is testing them anew. Advanced weapons can be consumed faster than peacetime factories replace them, while cheap drones and missiles allow weaker states to impose continuing costs on advanced rivals.

This creates an uncomfortable paradox.

Military interoperability strengthens coalitions on the battlefield but also creates industrial dependencies that are difficult to escape. In long, limited wars, technological superiority matters only as long as the coalition can afford, produce and replace what it consumes.

V. A Coalition of Decentralised Systems

Coalitions do not solve the political endurance problem; if anything, they make it worse.

Integrating militaries does not erase national sovereignty. Allied forces can share command structures, intelligence and interoperable systems, but each government still answers to its own voters, parliament and interests.

Afghanistan made that painfully obvious. NATO operated under one mission on paper, but contributing states imposed their own caveats and restrictions on where and how their troops could operate.

Those caveats were not bureaucratic quirks; they reflected different domestic political pressures and appetites for risk. They made burden-sharing and coalition cohesion harder than the unified-command narrative suggested.

Of the contemporary great powers, the US above all can supply the backbone of an international military coalition: intelligence, logistics and advanced capabilities.

What it cannot do is fuse the sovereign political systems behind every other contributor.

Middle and smaller powers like Australia and Canada still matter because they bring niche capabilities, diplomatic weight and political legitimacy while operating inside their own domestic constraints.

Coalitions may fight as one integrated military network, but the statecraft holding that network together stays stubbornly decentralised.

VI. From Military Interoperability to Strategic Interoperability

This gap between integrated military networks and decentralised statecraft is the central weakness of contemporary coalition warfare.

Modern limited wars therefore require more than military interoperability. They require strategic interoperability.

Sovereign allies must be able to coordinate military, political, economic and industrial power to pursue and sustain a common strategic objective.

This does not mean supranational government or surrendered sovereignty, but unity of strategic effect even when national policies differ.

In practice, this could involve standing allied mechanisms that integrate political planning, defence production, economic measures, strategic communications and military operations around an agreed political end state before a crisis becomes a prolonged war.

Conclusion

Across these three articles, we have argued that military superiority alone cannot guarantee strategic victory; that democratic institutions often struggle to turn battlefield success into sustainable political outcomes; and that these difficulties multiply when democracies fight as coalitions.

The endurance of democratic alliances will depend on more than their ability to fight together.

Sovereign governments must sustain public support, share political and military burdens, and remain committed to common strategic purpose when conflicts become longer and more costly than expected.

Democratic accountability need not become a strategic weakness, but preserving sovereignty while sustaining collective action will require greater political cohesion.

The ultimate obstacle is not technology or concepts, but political will: overcoming domestic divisions and institutional rivalries to sustain common purpose.

As the era of AI unfolds, technology will keep changing warfare, but it cannot repair the organisational weaknesses of those who use it.

Strategic interoperability ultimately depends on whether democracies can find the will to build it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Return of the Essential Art: Electronic Warfare and the Lessons of the Russia-Ukraine War

18 August 2026 at 10:01

A Post-Cold War Assumption That No Longer Holds

For three decades, the Alliance operated under a dangerous assumption: that the electromagnetic spectrum was a permissive sanctuary. Lulled into complacency by counter-terrorism campaigns that allowed precision strikes and networked command to go largely unchallenged, we forgot how to fight in the dark. The Russia-Ukraine war has violently corrected that amnesia. Today, electronic warfare is not an enabling function; it is the apex of modern combat power. If a force cannot survive in the spectrum, its sensors are blind, its networks collapse, and its kill chains are severed.

The Alliance stands at a critical inflection point. The time for incremental modernization has passed; this short piece is a call to arms to reclaim our operational advantage. The war in Ukraine has proven that the half-life of a technological advantage is measured in days, not decades. If we do not aggressively institutionalize agility across our warfighting commands, we risk entering the next conflict blind, deaf, and disconnected.

Russia’s Spectrum Offensive at Scale

Russia entered the war with a deep inventory of EW systems, rooted in Soviet-era investment and modernized over the past decade. From strategic GPS denial across Eastern Europe to tactical jamming of drones, radios, and artillery sensors, Russian forces use EW to degrade decision-making, disrupt fires, and blind ISR, continuously, at scale, across every echelon.

This is not a supplementary effort; it is a structural pillar of Russian combat operations. According to analyses by the Royal United Services Institute (RUSI), Russia achieved a staggering density of EW coverage, deploying a major electronic warfare system approximately every 10 kilometers along the front line during peak operations. This continuous, layered spectrum defense can be understood across two distinct operational tiers:

1. Strategic and Operational Denial

At the macro level, Russia has deployed high-powered, truck-mounted systems designed to blind NATO and Ukrainian airborne intelligence and disrupt satellite architectures.

  • The Krasukha-4: Designed to protect high-value assets, this system emits powerful jamming signals targeting airborne early warning and control aircraft (AWACS), radar reconnaissance drones, and low-Earth orbit spy satellites. By targeting X-band and Ku-band radars, it degrades long-range aerial surveillance, forcing ISR platforms to operate at suboptimal standoff distances.
  • Murmansk-BN: Operating at the strategic level, this system targets high-frequency (HF) military communications up to thousands of kilometers away, aiming to disrupt the operational coordination of enemy forces on a theater-wide scale.

2. Tactical Interdiction and the Defeat of Precision Munitions

At the tactical edge, Russian EW is integrated down to the battalion level to create local bubbles of spectrum denial. This has profoundly affected the effectiveness of Western-supplied precision-guided munitions (PGMs) and unmanned aerial systems (UAS).

  • Neutralizing GPS-Guided Weapons: Systems like the R-330Zh Zhitel and Pole-21 have been explicitly used to create GPS-denied environments. Because GPS signals travelling from space are relatively weak by the time they reach Earth, localized jammers easily overpower them. RUSI has noted that this jamming significantly degraded the accuracy of key weapons, including Excalibur 155mm guided artillery shells, Joint Direct Attack Munitions (JDAMs), and GMLRS rockets fired by HIMARS. Without GPS, these munitions must rely on inertial navigation, which drastically reduces their hit probability.
  • Drone Suppression and ISR Severance: In the early months of the war, Ukrainian Bayraktar TB2s operated with near impunity. As Russian forces entrenched, their EW architecture caught up. By blasting the 900 MHz and 2.4 GHz frequencies used by commercial and military drones, systems like the Borisoglebsk-2 sever the command links and video feeds between drones and their operators. This strips frontline units of their "eyes," returning artillery duels to grid-square estimations rather than precision strikes.

Ukraine’s Rapid Adaptation Under Fire

Ukraine’s response has been just as instructive. Forced to adapt under fire, its forces built a distributed EW ecosystem spanning national infrastructure to handheld infantry jammers, fielding and replacing thousands of systems in months, not years. EW operators are now embedded in maneuver, air defense, and fires units. The war has become a laboratory of spectrum conflict with drones jammed out of the sky, counter-battery radars blinded, munitions diverted, networks disrupted. EW is both shield and sword: protecting friendly systems while blinding the adversary.

While Russia relies heavily on legacy, mass-manufactured, centralized platforms, Ukraine’s survival has depended on democratizing the electromagnetic fight. By abandoning rigid peacetime acquisition processes, Ukraine has successfully pioneered a "DevOps" warfighting philosophy, prioritizing the rapid, iterative deployment of real-world software capabilities and commercial hardware modifications.

Ukraine has mastered the art of using the electromagnetic spectrum not just for defense, but to actively hunt Russian forces. By integrating EW operators directly into fires and maneuver units, the spectrum has become the primary hunting ground for target acquisition.

EW as a Mass Capability

The scale is the lesson. Both sides are fielding equipment and training operators at a pace NATO hasn’t matched since the Cold War. EW is no longer a boutique, specialized function; it’s a mass capability woven into daily battle rhythm and treated as a core determinant of survivability and lethality. In Ukraine, EW isn’t an adjunct to maneuver or fires. It’s inseparable from them.

For NATO and allied forces, Ukraine's experience demonstrates that surviving a high-intensity conflict requires transitioning from static, hardware-centric platforms to data-centric environments where software updates can be continuously deployed to the tactical edge under fire.

NATO’s Vulnerability Without EW Dominance

The implications for NATO are stark. Precision fires need assured spectrum access. Air defense needs resilient sensors and networks. ISR needs unjammed collection. Command and control needs protected communications. Without robust EW, all of it evaporates. This war shows EW is both the first layer of protection and the first layer of lethality, the foundation everything else rests on.

Rebuilding EW as a Core Competency

Reconstituting EW will take more than new hardware, it demands a cultural shift. Commanders must think in terms of spectrum maneuver, fires, and protection as naturally as kinetic operations. Exercises need realistic EW conditions, not sanitized ranges. Training pipelines must expand, and offensive and defensive EW forces must be rebuilt at every echelon, from squad to strategic level. Doctrine must treat EW as a decisive domain, not a supporting function.

The Essential Art Returns

The essential art of warfare in the twenty-first century has been violently reintroduced, and the electromagnetic spectrum is no longer an invisible enabler; it is the primary maneuver space where the first shots are fired, and the deepest vulnerabilities are exposed. NATO must reclaim this domain fully, urgently, and at scale.

For too long, the Alliance rested on the laurels of post-Cold War permissive environments, operating under the dangerous assumption that our networks would always connect, our drones would always fly, and our precision munitions would always find their mark. The battlefields of Ukraine have permanently shattered that assumption. We can no longer afford the luxury of rigid, decade-long peacetime acquisition cycles. Surviving the modern fight requires a fundamental paradigm shift: embracing a "DevOps" warfighting philosophy that prioritizes rapid, iterative deployment of software-defined capabilities directly to the tactical edge.

Lethality today is inextricably linked to digital survival. If we cannot protect our data lineage, secure our networks, and continuously update our countermeasures under fire, we will cede the kill chain to our adversaries. The next fight will be decided not just by who holds the physical terrain, but by who dominates the spectrum.

NATO must institutionalize this reality across every echelon. Electronic warfare is not an adjunct to maneuver; it is the very foundation of our combat credibility. We must transition our defense structures to data-centric environments, integrate our joint capabilities, and ensure that when the next conflict erupts, the Alliance dictates the spectrum and the adversary is left blind, disrupted, and defeated.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Inside Iran’s New Wartime Leadership

17 August 2026 at 09:47


Tehran’s new power brokers

A wave of assassinations rebuilt Iran’s leadership from the top down, leaving a severely wounded supreme leader and a security establishment now calling the shots. Tehran, however, isn’t saying who is actually in charge. The silence is part of the narrative; who are the country’s power players?

Earlier this month, Iranian state media did something it had never done before.

Mehr News, an outlet controlled by the country’s Islamic Development Organization, released a video titled “First Images of the Leader,” showing Supreme Leader Mojtaba Khamenei addressing a small group of students. The footage was undated. It came, however, days after Israeli outlets reported the 56-year-old cleric was in “extremely critical condition,” and it appears to have done little to settle the question consuming Iran’s political class: is anyone actually running the country right now.

The clip echoed a similar undated video IRIB released in March, showing Khamenei teaching religious sciences. President Masoud Pezeshkian acknowledged this week that reaching him has been “very difficult,” though he described their last exchange as constructive.

Multiple sources close to Pezeshkian’s administration told IranWire that no cabinet minister has met with Khamenei since the February 28 strike that killed his father, Ali Khamenei, and that officials “would not be surprised” to hear news of his death.

Iranian authorities have repeatedly denied he’s incapacitated. But the man now holding life-tenure authority over Iran’s armed forces, judiciary and clerical establishment hasn’t spoken publicly, delivered a sermon, or appeared unedited on camera since taking the post in March.

“The main issue for U.S. policymakers — especially any president — is whether the new leadership in Iran, or any leadership we can currently anticipate, is likely to depart materially from the strategic policies of the previous leadership,” Norman Roule, a former CIA officer who spent 34 years managing programs related to Iran and the Middle East, tells The Cipher Brief. “The evidence to date suggests no fundamental break.”

The vacuum at the top didn’t stay empty for long.

A Leadership Rebuilt Through Killings

The cascade began on February 28, when a joint U.S.-Israeli strike killed longstanding leader Ali Khamenei along with Mohammad Pakpour, the Islamic Revolutionary Guard Corps’ commander-in-chief, and a string of other senior officials. An interim leadership council, made up of Pezeshkian, judiciary chief Gholamhossein Mohseni-Ejei and cleric Alireza Arafi, held the state together for less than a week before the Assembly of Experts named Mojtaba Khamenei as Iran’s third Supreme Leader on March 8.

The choice was unusual on its face. The Islamic Republic was founded on the overthrow of hereditary monarchy, yet its clerical establishment had just installed the son of the man he replaced. Mojtaba lacked the religious credentials typically required of a Supreme Leader. He was widely regarded as a hojatoleslam, a mid-ranking cleric, rather than an ayatollah — yet he had spent nearly two decades as his father’s gatekeeper and enjoyed deep loyalty inside the Revolutionary Guard.

President Trump, who had labeled him “unacceptable” during the war, later told Fox News that the succession was not one his own father had wanted, adding, “their leadership is gone, their second leadership is gone, now their third leadership is in trouble.”

Roule, however, cautions against reading the new bench as a break from what came before it. Most of Iran’s current leaders, he notes, “rose within institutions shaped by Ali Khamenei and were trusted, promoted, or shaped within, and by the system he developed over years of rule.”

Roule points to the generational math: Pezeshkian, Mohsen Rezaee and Ali Reza Zolghadr were about 25 years old at the time of the 1979 revolution; Ahmad Vahidi was 21; Mohammad Bagher Ghalibaf and Sadeq Amoli Larijani around 18; Mojtaba Khamenei just 10.

“For this group, the 1979 Revolution remained the ideological foundation of the system, but the Iran-Iraq War and the post-2003 campaign for regional influence were more important professional experiences,” Roule explains. “Most are veterans of the Iran-Iraq War or were directly shaped by it.”

The current command of the Islamic Revolutionary Guard Corps has followed the same brutal pattern.

Amir Ali Hajizadeh, head of the Guard’s aerospace force, was killed in a strike in June 2025. Pakpour, who had succeeded Hajizadeh’s predecessor Hossein Salami, was killed at the outset of the U.S.-Israeli campaign in February. His successor, Ahmad Vahidi, a Quds Force founder and former interior minister with an Interpol red notice tied to the 1994 AMIA bombing in Buenos Aires, was formally installed as commander-in-chief on March 1.

Unverified reports of Vahidi’s own death circulated in Tehran in late May and again in early June; Iranian, Israeli or American officials have confirmed none, and Vahidi continues to be listed as the IRGC’s active chief.

A Crackdown That Fits the Moment

The uncertainty at the top has coincided with a sharp rise in executions and threatened executions, months after the January protests that shook the regime.

Austin Sarat, a professor of jurisprudence and political science, says the war and the unrest have compounded each other rather than one driving the other alone.

“The protests and the war have fueled — it’s like putting a little bit of an accelerant into something that’s already pretty flammable,” Sarat tells The Cipher Brief. “The protests were, I think, much more trigger than the war itself. The war has just provided yet another excuse, because it’s jacked up nationalist fervor.”

Sarat is skeptical that outside pressure, including past White House rhetoric threatening consequences over executions, has had much bearing on Tehran’s calculus.

“The administration has said nothing about human rights abuses, let alone execution practices around the world,” he says, underscoring that any outside leverage is more likely to come from Europe than Washington. He views the surge itself as a familiar survival tactic for a leadership still finding its footing.

“It’s not a kind of unfamiliar tactic for a regime new to power to want to flex its muscle and terrorize the population,” he observes. “This is a survival moment, and they are going to do what they are going to do to preserve the essential character of their regime.”

The Guard Consolidates Around the Vacuum

With the younger Khamenei largely unseen, the Revolutionary Guard didn’t sit on its hands. It moved fast, filling top posts through official decrees.

Along with Vahidi, the Supreme Leader’s office named Mostafa Izadi as deputy IRGC commander, Ali Azmaei to head the IRGC Navy and Hossein Taeb to lead the Basij paramilitary force, filling six senior military posts vacated by wartime deaths.

Mohsen Rezaee, who commanded the IRGC from 1981 to 1997, was separately appointed as the Supreme Leader’s representative on the Supreme National Security Council. This post opened up, according to Rose Kelanic, director of the Middle East Program at Defense Priorities, after Zolghadr was pushed out.

Kelanic argues the reshuffle amounts to more than a personnel change.

“Mojtaba Khamenei’s role appears to be that of a figurehead and potential scapegoat, enjoying far less authority than his father, whom he replaced,” Kelanic tells The Cipher Brief. “The real power rests with Ghalibaf, Vahidi and Rezaee, who are all career IRGC officers, which functionally means that Iranian government authority has shifted even further from civilian control to military control.”

That shift, she continues, carries its own risk for any settlement with Washington.

“When military leaders assume control as heads of state in wartime, they tend to make worst-case assumptions about adversaries’ intentions, view compromise as weakness, and favor offensive military strategies over defensive ones,” Kelanic points out.

Roule, meanwhile, frames the Guard’s rise in institutional rather than personal terms, and says the war has widened rather than preserved its reach. Estimates of how much of Iran’s economy the IRGC touches “vary widely — roughly from a fifth to a third,” he says, depending on whether one counts only directly controlled firms or also affiliated holding companies, pension funds and sanctions-evasion networks.

“A better way to think about the IRGC is not simply as a military organization with commercial interests, but as a central actor in a state-security-economic network,” Roule notes.

Ghalibaf’s Quiet Climb to the Center

The other figure benefiting from the uncertainty at the top is Ghalibaf, the parliament speaker and former IRGC commander who has spent the war years turning what is traditionally a legislative post into something closer to a shadow foreign ministry.

Ghalibaf, a two-time presidential also-ran who trailed Pezeshkian in the first round of the 2024 election, has emerged as Tehran’s principal interlocutor in the indirect talks with Washington, serving simultaneously as Iran’s special envoy to China and as a bridge between the political and military-security establishments that Pezeshkian, a physician by training with no roots in the security services, has struggled to command.

Parliament re-elected Ghalibaf to a seventh consecutive term as speaker in late May, with 235 of 271 votes cast, as reports circulated of friction between Pezeshkian and the new Supreme Leader’s office. Judiciary chief Mohseni-Ejei congratulated Ghalibaf on the vote by calling him a “tireless and battle-hardened jihadist leader” who had waged jihad “both in the field and in diplomacy” during the war.

Roule warns against reading Ghalibaf’s prominence as a formal power grab.

“His current prominence should not be confused with general supremacy over Pezeshkian,” he says. “Pezeshkian nonetheless remains president, heads the executive branch, and formally chairs the Supreme National Security Council. There is no evidence that Ghalibaf has assumed any of the presidency’s general constitutional authorities.”

His influence, Roule highlights, “is best understood as issue-specific power produced by circumstances, his political standing, longstanding IRGC relationships, and wartime delegation.”

Who Actually Holds the Reins

What emerges from the past five months of conflict, however, is a regime governed less by the clerical hierarchy that has defined the Islamic Republic since 1979 than by an overlapping wartime trio.

A Supreme Leader whose authority is formally absolute but whose physical capacity to exercise it remains unverified. An IRGC command structure rebuilt twice over through assassination and now operating with wide latitude, alongside a parliament speaker who has converted legislative standing into genuine diplomatic weight.

Still, Roule sees continuity as the most likely outcome even if Mojtaba’s health worsens further.

“If Mojtaba Khamenei becomes seriously incapacitated or dies, the most likely outcome absent a successful mass uprising or a major elite fracture is continuity rather than reversal on the issues of greatest concern to the United States,” he says. “The IRGC would remain a central power center, and the system has constitutional procedures for interim leadership and selection of a successor.”

He also points out that if Mojtaba’s death were tied to the war, “the state would almost certainly use a martyrdom narrative to reinforce regime legitimacy and resistance.”

Kelanic is less sanguine about what that continuity means for diplomacy. Iran, she stresses, will also grow harder to negotiate with simply because power is now split among rivals rather than concentrated in one office, leaving Washington without a clear address for any deal.

“The IRGC’s strengthened rule over a weaker civilian leadership makes reaching a peace deal harder,” Kelanic adds, “which is one of many ways the Iran War has backfired.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

It’s Time For The President To Level With The American People on Iran

13 August 2026 at 08:47

The U.S. administration’s strategic expectations are increasingly colliding with a set of hard realities. While Iran has taken a considerable beating, it remains standing and does not appear on the verge of either submitting or collapsing. Its newfound control over a key commercial waterway, the Strait of Hormuz, provides it with a weapon of mass disruption (credit to the NYT’s Tom Friedman) that it previously did not enjoy, and it appears intent on exercising that authority. Despite the administration’s continued threats and claims of imminent victory, there is no clear military solution in sight. Bottom line: the administration miscalculated.

Another strategy is called for. The truth.

“The practice of espionage is a quiet act of war: A very human endeavor, sometimes born of lies and betrayal, of greed or revenge; but often of deep truths and trust.”

This is the banner of my Substack, drawn from the preface of my upcoming Iran espionage novel; “A Prince of Mirrors.” It attempts to encapsulate my feelings about my chosen profession: Intelligence Officer. But for now, let’s focus on the last phrase: “but often of deep truths and trust.”

Trust is in very short supply between the United States and Iran as they attempt to come to terms. First, to re-open the critical Strait of Hormuz – a shipping route that was open prior to the War – and, second, to end an increasingly fruitless War. All while failing, at least for now, to fully address the other key issues at play: Iran’s nuclear program, Iran’s ballistic missile program, and Iranian-supported proxies.

While the world looks breathlessly on, the U.S. awaits the results of negotiations between Iran and tiny, wonderful Oman (admission; I spent several years at the U.S. Embassy in Oman) – a country literally stuck between the rocky Musandam coast, and a hard place called Iran – over the future administration of the Strait.

Based on initial reports of the terms, either Iran is going to have to step back from its assertions of control, or the United States is going to have to agree to some level of Iranian control that was not present prior to the War. Given the utter lack of trust between the parties, is either likely?

So, let me lay out, as best I can, what I believe to be true.

This is a time for truth. Hard truths.

The Middle East has changed.

  • The Iranian regime has survived a series of devastating U.S. and Israeli strikes. Iranian military capacity, both the regular Artesh (Iran’s conventional army) and the IRGC (Iran’s Islamic Revolutionary Guard Corps), is significantly weakened; however, it retains the ability to strike targets outside Iran, including shipping transiting the Strait of Hormuz.
  • The Iranian regime has not fallen and appears to be consolidating power around… well, no one yet knows which individuals or factions will emerge triumphant in Tehran. But for now, an even more hardline, IRGC dominated leadership is in place.
  • The regime is attempting to assert its newfound control over the critical Strait of Hormuz, a right tacitly acknowledged, or at least not specifically prohibited, in the flawed June MOU (Memorandum of Understanding) signed by the President of the United States.
  • Barring something new, something we have yet to see, U.S. and/or Israeli military force is unlikely to significantly alter this equation.
  • Iran and the United States, and the world economy, remain trapped in a test of wills over who blinks first.

The truth is, the regime is bad in so many ways. And they are dangerous. But not existentially so to the United States. Disliking Iran is not a sufficient reason to go to war with them barring a truly compelling reason.

But neither can an IRGC dominated Iran be allowed to run roughshod over the region. The U.S. and its Western and Gulf allies need to develop a new deterrence strategy that includes both carrots and sticks.

The Impacts of failure

Any agreement needs to mitigate, to the extent possible, the damage that Iran can do going forward. First and foremost, the world economy cannot allow one country to exert control over such an important international shipping route as the Strait. Any agreement must minimize Iranian control over ships transiting the Strait, possibly by compensating in other areas. The most critical issue, Iran’s nuclear program, must be addressed in a manner that includes both dealing with the 60% enriched uranium (HEU) currently in their possession and strict verification of enrichment activities going forward.

The American people can handle the truth!

That for now, the only way out is a negotiated agreement that is certain to fall short of the ideal. Only for now. Simply a truce. This is not an admission of defeat, simply a pause to rethink, to recalibrate.

But also…

That the Islamic regime has significant internal weaknesses. That stepping away from the current tit-for-tat military action, a strategy that is not achieving its objectives, will force the regime to confront the serious problems, some existential, that the Iranian nation faces. This is Iran’s, and the regime’s, Achilles heel. One that could eventually force change that no outside military force could.

Just the truth.

This article was originally published on Substack and is republished here with permission.

Read more national security insights from experienced experts exclusively in The Cipher Brief.


The Biggest AI Models Are Not the Biggest Threats

13 August 2026 at 08:45

Almost every AI security framework we are applying rests on one misguided assumption: danger scales with size. Compute thresholds, export controls, and tiered evaluation regimes all encode the same intuition, the larger the model, the more we should worry. If this isn’t true, what policy changes are needed?

I recently mapped more than twenty fielded AI systems against two axes: raw offensive capability with safeguards stripped, and residual risk as actually deployed (Fig. 1). They ran from millions to trillions of parameter models, and included munition seekers, gene design models, theatre planning, cyber offense systems, and general-purpose AI models. The picture does not support the above assumption. In fact, the data supports the inverse. Small, specialized models beat bigger general models at offense, but bigger models maybe better at defense.

Figure 1. Security Risk vs Size of Model. Hollow ring: raw offensive capability with safeguards stripped. Filled dot: residual risk as actually deployed. Cyber related positions anchored to CAISI / UK AISI results, July 2026. Data compiled by Alvin W. Graylin.

Each system appears twice: a hollow ring for raw capability with safeguards stripped, a filled dot for residual risk as deployed. The gap between them is the safeguard effect. Read left to right, and the size to threat correlation everyone assumes is simply absent.

Seven assumptions worth rethinking

One: the largest models pose the greatest risk. The high-residual band, where capability and deployed risk are nearly identical. Across six orders of magnitude, no clear trend. In 2022, researchers at Collaborations Pharmaceuticals inverted the scoring function on a commercial drug-discovery model (MegaSyn) of under 100 million parameters and generated more than 40,000 candidate chemical warfare agents (many more lethal than VX) in just six hours on a desktop. Chemprop-class retrosynthesis models, which can find non-controlled precursor routes around scheduled pathways, run at one to ten million parameters. Evo models with single digit billions of parameters can help design novel life forms. News just came out last week that this exact system was able to generate 16 new viruses. All these systems sit well below the axis floor of any parameter-based regime. Compute restrictions do nothing to fix this.

Two: compute thresholds capture the relevant risk. Hackphyr, built on Zephyr-7b-β at 7 billion parameters, performs comparably to GPT-4 on network attack scenarios and runs on a single GPU. Deep Hat V2 ships commercially at 30 billion parameters, is marketed as uncensored for offensive security, and executes inside the customer environment with no external calls. No government evaluation covers it, so that placement rests on vendor claims. Neither would trip a FLOP ceiling.

Three: capability and threat are the same axis. Claude Fable 5 and Claude Mythos 5 share one underlying model. Their capability positions are nearly identical; their deployed risk differs sharply, because Fable's added domain safeguards drop cyber requests back toward Opus 4.8 behavior. The difference comes entirely from the safeguards and distribution controls layered on top. That vertical gap is what governance can act on. Parameter count is not.

Four: open-source models are more dangerous than closed ones. Recent NIST study found that Kimi K3, the strongest PRC open-weight model, only scored 32 percent on ExploitBench against 57 percent for the leading U.S. model, and reached step 17 of a 32-step attack range where U.S. models reached 28.5. On the highest-severity outcome test, arbitrary code execution (ACE), Kimi K3, succeeded on 0 of 41 tasks, while the most capable U.S. models averaged 20. So, we really need to be careful about self-interested parties saying larger open-source models are more dangerous, when it likely has more to do with protecting margins than national security concerns. (see Fig. 2)

UK AISI did recently report that the Kimi K3 model was able to escape its sandbox during testing, but it merely used a misconfiguration in the testing sandbox that left the door open, rather than a sophisticated swarm agent attack like what the OpenAI model did. And when it did get out, all it did was look up the answer for the test it was given, rather than doing any damage to real world systems. In the future, this behavior could change, but it’s important to question the basic assumption that open models are always more dangerous.

Figure 2: CAISI/NIST - Comparison of aggregate capabilities over time of the most capable U.S. and PRC models. A 400-point increase on the y-axis equates to a 10x increase in the odds of solving tasks. Shaded regions denote 95% CIs.

Five: model quality determines attack success. Microsoft's MDASH is a harness, not a model. It orchestrates more than 100 specialized agents across an ensemble and scored 88.4 percent on CyberGym at launch, against 83.1 percent for the Mythos preview model. Adding a compact security model roughly 1/10th the size raised that to 95.95 percent. The orchestration layer beat every individual model. Regulating training while ignoring scaffolding regulates the less important variable.

Six: national security requires the largest models. It requires the opposite. Loitering munition seekers performing automatic target recognition run on Jetson-class edge hardware, capping them in the single-digit millions of parameters. Edge deployment favors small models on latency, power, thermal envelope, and operation without a datalink. Larger models are slower and, in narrow domains, more easily distracted by irrelevant context. They are also harder to validate, and validation is what matters when a false positive is a struck target. Cisco's Foundation-Sec-8B matches or exceeds models ten times its size on security benchmarks while running on one or two GPUs. The famed DoD Maven Smart System is based on a fine-tuned 2-year-old Claude Sonnet 3.5 model. That level of intelligence can now be distilled into a 4B model which could potentially run on a smartphone.

Seven: denying China compute is the primary lever to keep U.S. safe. Due to shared risks between these superpowers, on many safety related issues, cooperating may actually produce the outcomes most beneficial to the U.S. and the world. More on this below.

Five threat domains, five different answers

Attack and embedded systems favor small models that don’t require a comm link. Air-gapped operation, no API telemetry, no rate limits, no refusals mid-chain. The offensive bottleneck is stealth and throughput, not reasoning.

Cyber Orchestration favors large models, but the advantage attaches more to the system rather than the model, as MDASH shows. There’s little discussion today on regulating orchestration systems, but it’s clearly very needed.

Cyber Defense favors large models most clearly, and this is where the current approach fails. Defenders need breadth across every vector; attackers need depth in one. Safeguards that constrain security research are therefore costly in a way that is easy to miss.

When Hugging Face's systems were breached in July by OpenAI models, commercial frontier-model APIs blocked the forensic requests because their safety systems could not distinguish defensive analysis from attack. The team ran the open-weight Chinese model GLM-5.2 on its own infrastructure instead, worked through more than 17,000 logged actions, and contained the intrusion. An American company under active attack by an American closed-model was defended by a Chinese open-source model because the American ones could not tell friend from foe.

That is a Slave AI failure, in the terms I set out in Beyond Rivalry. A model trained toward obedience can only refuse; it cannot reason about whether refusing is right. What we need is Guardian AI: systems capable and contextually aware enough to protect us from malicious actors, from other AI systems, and from our own unintended consequences. That requires scale, because judgment requires breadth. It also requires that we stop locking down every capability rather than stewarding it. High-quality models with fewer restrictions, in defenders' hands, are a global public good. Every hour a defender spends fighting a guardrail is an hour the attacker fights nothing.

Bio/Chem Design favors small models. Molecular graphs, protein sequences, and binding energies come from compact architectures immune to alignment techniques built for natural language. A graph neural network has no refusal layer to remove. The key here is monitoring and controlling access to precursor chemicals and expanding safeguard for synthesis equipment.

Bio Synthesis is the outlier, and there is good news and bad. For biology, model-level access control has already failed. Evo 2 shipped with weights, inference code, training code, and its full dataset. There is no API to revoke. What remains is the synthesis chokepoint: Customer vetting and sequence screening at nucleic acid providers already operate internationally through the Gene Synthesis Consortium, whose members screen orders against databases of sequences of concern before synthesizing. There are still gaps as novel AI-generated combinations are developed, but they can be reduced if vendors and regulators globally work more closely together to keep the systems updated. Closing those gaps buys more security than any parameter threshold. But this requires Washington and Beijing to align, since they are the two largest suppliers of synthesis equipment in the world. Of course, collaboration across all vendors globally is needed to truly secure this threat vector. Again, larger general AI models aren’t the core problem.

Data beats intelligence

On the opening day of the U.S.-Iran war in February, a Tomahawk missle struck the Shajareh Tayyebeh girls' school in Minab, killing at least 168 people, more than 100 of them children under twelve. The school sat within 100 yards of an IRGC naval installation and had been inside that perimeter until a wall went up around 2013. Targeting ran through the Maven Smart System, which generates roughly 1,000 target packages an hour. A preliminary investigation concluded the strike likely followed from outdated intelligence, and former officials said stale human-curated data, not AI, was to blame.

The school had a website. Free satellite imagery showed a schoolyard with a sports field. No model of any size prevents this, because the failure was in data lineage, not reasoning. A larger model querying the same stale record returns the same coordinates faster and with more confidence.

The China mistake

The threat model that matters is not Beijing reaching AGI first. It is a non-state actor with a 30-billion-parameter uncensored model, a good harness, and no return address. Small models proliferate regardless of jurisdiction and leave no attribution trail, and an unattributable intrusion between nuclear powers is an escalation problem before it is a technology problem. In that world, a China unable to defend its own infrastructure is a liability to global stability, not an advantage to Washington.

Beijing is already regulating its own labs more aggressively than any other market. Concordia AI's 2026 survey documents agentic AI security guidance, ethics review requirements, and binding obligations on consumer AI services that are already deployed and enforced. It should be noted that Chinese frontier safety research output grew roughly 60 percent year over year, with agent safety rising from 8 percent of new papers in early 2025 to 27 percent by early 2026. The caveat: only five of ten leading Chinese developers reported safety evaluation results on release. Shared standards here would make a difference.

As Fig. 2 showed, CAISI found the Chinese models less dangerous, but they also found GLM-5.2 answers sensitive biological queries at far higher rates than tested U.S. models, which is where PRC safeguards are weakest. In personally speaking with multiple Chinese labs, it’s clear that their lack of compute resources due to export controls has forced them to deprioritize safety demands vs. capability enhancement. Expanding safety testing compute resources, like what UK AISI has, to more countries could help improve AI safety globally, without fear of its misuse by rival nations.

The race framing is softening at home, too. More than 100 organizations, including Nvidia, Microsoft, Meta, IBM, Palantir, OpenAI and Google, have now signed the July 24 Open Weights and American AI Leadership letter opposing premature restrictions. Days later, Nvidia and roughly 50 partners launched the Open Secure AI Alliance to build open defensive models and agent harnesses, citing the Hugging Face incident as its founding case. Every participant has commercial exposure to a ban, so weigh the motives. But 8 of the top 10 models on OpenRouter in July are already open-source, and the industry has now reorganized around the proposition that open weights are defensive infrastructure.

Four Asks for September

Four asks follow, and Xi Jinping's state visit to Washington on September 24, the first in over a decade, is where they could land. Trump has said AI will be on the agenda.

Shared harm standards, not shared capability standards. Agreement on what constitutes an unacceptable capability, evaluated the same way in both countries, so that "safe" means the same thing in Shanghai and San Francisco. That’s clearly missing today and doesn’t require mutual trust.

A shared safety evaluation cluster. Chinese labs are compute-constrained, so safety research competes with capability research for scarce chips. Compute earmarked for evaluation and red-teaming is cheap relative to the benefit, and the benefit is global. An international testing facility open to any vendor institutionalizes it. Require publishing safety scores alongside capability benchmarks so safety investment earns a competitive return. Then, both Chinese and US labs would have no excuse not to test their systems.

An incident notification channel. The Nuclear Risk Reduction Centers, staffed continuously since 1987, exist because a misread signal costs more than talking. An equivalent for AI incidents where attribution is contested is cheap insurance. With the rising risk of bad actor attacks and false flag operations from non-state actors, this safeguard will be increasingly needed.

Capability non-development agreements. A capability never trained cannot leak. This matters more than denying Beijing another turn of the scaling crank. Beijing also wants to limit rogue actor misuse, thus agreeing on redlines in advance makes sense for both sides (no nuclear weapon command/control, no AI uplift to bio weapon design, no AI-attack on civilian infrastructure, no autonomous self-replication outside control environments [RSI]). General commercial models have no need for bio and chemical threat design, so keeping defense use case training only in military labs on both sides seems quite reasonable.

Another Asilomar moment

At Asilomar in 1975, molecular biologists imposed a voluntary moratorium on a class of recombinant DNA experiments, then built the containment framework that governed the field for decades. They acted before the capability matured enough to do real harm.

That view is starting to catch on in the AI labs now. On July 28, 1,200+ employees of frontier labs published Pacing the Frontier, asking Washington to support an international effort to build tools for deliberately slowing automated AI development. Signatories include top technical leaders at Anthropic, OpenAI, Meta and Google. The concern is recursive self-improvement (RSI) of AI that goes out of control. The logical extension is an explicit agreement not to implement it in frontier labs even once it becomes possible.

But this cannot stop at two capitals. If dangerous systems are small and cheap, a country with a modest research budget and a few hundred GPUs can build a competent offensive cyber agent or an inverted molecular designer. Within a few years, dozens will. Any regime binding only Washington and Beijing binds the two parties least likely to defect and leaves the growing middle untouched. A U.S.-China agreement is the necessary first move, not the finished structure, and it has to open immediately to third parties. That is how Asilomar's containment norms and the Montreal Protocol scaled.

Bigger AI is not more dangerous. Better orchestrated is more dangerous, less monitored is more dangerous, and irreversibly released is more dangerous. All three require cooperation with Beijing: orchestration needs shared harm standards, monitoring needs shared evaluation infrastructure, and irreversible release needs joint agreement on what never gets built. September 24 is a good place to start.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

BLUF: The US Must Lead in Gray Zone Activity

5 August 2026 at 09:09

As Washington works on the historically large defense budget, there is one theme which should loom large in the budget but comparatively, will cost little. Key to our national security is countering the gray zone activity that our adversaries are waging against the US and developing our own offensive gray zone strategies. Just as we would not ignore a kinetic strike against the US, we cannot ignore the targeted gray zone attacks by adversaries but we must be careful that our approach is thoughtful, and expertly executed in order to guard against escalation. Developing such offensive and defensive strategies will require gray zone expertise, proficient knowledge of the targeted adversary, a government wide strategy, and patience. As global leaders, we also must be open and clear that we will take on these gray zone activities, but we do not have to and should not discuss the details of our actions. We need to publicly put our adversaries on notice that we will not tolerate their actions against the US and we will counter them with our own, more debilitating gray zone activities.

The National Intelligence Council describes gray zone activities as “coercion and subversion . . . below what constitutes armed conflict but outside the bounds of historically legitimate statecraft.” The IC defines the gray zone as a realm of international relations between peaceful interstate diplomacy, economic activity, and people-to-people contact on one end of the spectrum, and direct armed conflict on the other. State-led activities that happen in that space that weaken governments’ resolve to confront the US or its allies, endeavor to change a nation’s policies, or strengthen a country's global leadership would be considered gray zone activities. Deniability is critical to the success of this strategy because attribution risks escalation.

David Pitts, another Cipher Brief Expert, has written about the current phase of warfare which he calls endless wars and the need to counter them. These endless wars are the gray zone activities that our adversaries pursue against us. The White House has made an important step in that direction by appointing the first US National Security Council Director for Cognitive Advantage. There is still a way to go, however, because cognitive advantage is just one part of gray zone activity.

The US must develop expertise for whole of government strategies that bring together all of the tools for gray zone activities. Some of those activities are:

  • Cyber, and information operations efforts focused on undermining public/allied/local/ regional resistance, and information/propaganda in support of US goals;
  • Covert and clandestine operations such as espionage, infiltration, and subversion;
  • Enlistment of non-governmental actors and assistance to irregular military and paramilitary forces;
  • Economic pressures that go beyond normal economic competition;
  • Calculated ambiguity to include deception and denial operations.

Autocracies tend to have an advantage in executing gray zone operations. It is generally believed that non-democratic states can operate more effectively in the gray zone than open democratic societies as non-democratic nations are not limited by domestic law and regulation. The nature of their centralized systems allows them to marshal whole-of-state (and whole-of-society) resources to execute operations. The United States lags behind its autocratic adversaries in the information domain, for example, because our adversaries have ingrained gray zone tactics into their doctrines.

In democratic societies, the use of gray zone tactics can be controversial because the nature of these activities is meant to covertly shape actions. It can be challenging for democratic states to respond to gray zone threats because our legal and military systems are geared towards seeing conflicts through the perspective of war and peace with little consideration for anything in between. Democracies have failed to build consensus around gray zone concepts. The US government has been arguing over the definition and leadership of gray zone and information operations for years.

Gray zone activities are not a new concept and historically have been accepted as a long standing form of statecraft. What are now being called gray zone methods have been well documented actions throughout history. These activities have been called by such titles as “political warfare,” “covert operations,” “irregular or guerrilla warfare,” and “active measures.” It is worth examining the historic record and recalling the benefits and rationale for gray zone activities that kept nations out of kinetic fights, allowed for de-escalatory engagement, arguably shortened warfare, and saved lives.

Examples:

  • The Trojan Horse operation exploited many of the instruments of a gray zone campaign– creating confusion and division among the enemy, extending ostensible inducements, implanting hidden military forces, deception, and clandestine infiltration of enemy territory.
  • During the Peloponnesian War between Athens and Sparta, the Spartans recognized that they needed to prevent an uprising by the Helots, who were key to Sparta’s agricultural and military systems. Athenians were trying to create the conditions for a Helot uprising, which would then add an irregular dimension to the conventional conflict with Sparta. The Athenians used proxy forces who were experts on the language and culture of the Helots to sow distrust among the Helots against the Spartans. The Helots began to desert Spartan forces, thereby creating a national emergency in Sparta. The Athenian historian Thucydides reported that as a result of Sparta losing Helot support, it reached out to Athens to discuss ending the wars.
  • The Han Empire used economic and cultural engagement—such as trade agreements, marriage alliances, and cultural exchanges—to manage tensions with nomadic powers. These actions helped secure borders and reduce the need for large-scale wars
  • During the Cold War, superpowers like the U.S. and USSR engaged in gray zone tactics such as espionage, sabotage, and proxy support to influence outcomes in regions like Latin America, Korea and Vietnam. These active measures as they were called, kept the competition a contested space, avoiding immediate escalation with the US.

Gray zone campaigns are likely to increase and diversify because of more enabling technologies, the erosion or absence of accompanying norms, and challenges with attribution. There is a growing awareness among some in the US national security community that if we do not develop gray zone strategies against our adversaries, then we will find ourselves no longer the global power that we have been. Without these strategies, we also limit potential responses to our adversaries to kinetic ones.

As a national security community, we have trained only a narrow group of special operators and intelligence professionals to be able to think creatively enough to devise irregular warfare plans and strategies. To produce gray zone strategies the US will need to train a work force in creativity and out of the box thinking. It also will require organization and orchestration from all assets of the US government and the development of and use of technology to bring some of the ideas to fruition. A fully conceived gray zone strategy needs to marshal all aspects of the US government: military, intelligence, economic, trade, diplomacy, and public relations.

The US is not organized as a nation to devise these strategies. Our State Department is focused on developing relationships. Our National Security Council is hollowed out. Due to issues with legal authorities, neither the Department of War nor the intelligence community can take the lead in implementing whole of government strategies. We are at a standstill and have been for several years.

What to do?

We need to be upfront that leading in gray zone operations is good for US national security. If we do not quickly make gray zone strategies a key part of our national security then we risk our global leadership role. We must put in place the tools and organization to execute these strategies. Using part of the large defense budget to show US resolve on this matter would go a long way. Putting a seasoned professional at the NSC and making him/her in charge of integrating the USG gray zone activities against specific adversaries is key to winning in this realm. A lack of coherent command-and-control, as well as jurisdictional and philosophical boundaries between government agencies, inhibits the synchronized activities needed for successful and truly whole-of-government gray zone activities and responses. We also should use the trained Department of War and intelligence community planners, working with the rest of government, to develop government-wide plans that are implemented at the White House. While we move out in this way, we should also be training our national security professionals across the government in how to develop gray zone strategies. Now is the time to make this a national imperative.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

AI Summaries Are Susceptible to Manipulation — and That's Both a Business and a National Security Problem

3 August 2026 at 09:07

More and more people are using AI like a search engine – 42 percent of U.S. adults now use AI chatbots to search for information – and that shift is exposing a structural vulnerability that adversaries are exploiting to seed propaganda. In practical terms, this is a problem of Generative Engine Optimization (GEO) – the deliberate effort to shape digital content so that AI chatbots absorb and repeat it.

The research so far points to data voids — the thinly covered topics where there isn't much credible information to begin with — as the weak spot. This includes breaking news or new material that has not yet had time to accumulate the signals that would flag it as low authority.

AI can process far more information than any human can, but there is an inherent trade-off in outsourcing the curation of information to an AI summary. In the search era, users were exposed to source material and evaluated credibility for themselves. Now AI does that work, and research shows the large majority of AI queries end without a click.

This is both a business concern and a national security concern. The clearest example on the consumer side is Apollo-9. In a Chinese state TV investigation, researchers used a tool called Liqing to flood the web with fake reviews and rankings for Apollo-9, a fitness tracker that did not exist. Within hours, chatbots were recommending the fake fitness tracker and some continued to do so a day after the fraud was exposed. Liqing and other tools are sold openly on Chinese e-commerce platforms like Taobao and JD.com, with pricing ranging from roughly $520 to $4,765 for three-month subscriptions. One provider told Chinese state media it had served more than 200 clients across multiple industries, guaranteeing top-three placement on any AI platform.

In order to better understand these developments and their impact, this article examines how the same mechanism scales from commercial fraud to geopolitical disruption, using the Russia-Ukraine war as a live GEO lab. Leaked documents about Russia’s “Project 2026” and Ukraine’s AI‑enabled counter‑operations show how influence campaigns are evolving from social feeds to the underlying sources that AI systems draw on — an angle largely absent from existing information warfare debates.

Russia and the National Security Case: Same Playbook, Higher Stakes

When Russian operations exploit GEO in their war on Ukraine, they are not just spreading propaganda in the moment; they are trying to become the “ground truth” that AI systems summarize back to users, analysts, journalists, and policymakers. In June 2026, Bloomberg reviewed 73 leaked documents from the Social Design Agency (SDA), a sanctioned Moscow firm at the center of Russia's influence operations, describing a program its operators called “Project 2026:” a network of Wikipedia-style reference sites, media outlets, and fake think tanks built to shape what search engines — and AI systems — treat as reliable sources. The goal, as described in the leaked documents, is to “create an alternative information ecosystem” by shaping not only what people see today but also what AI systems will later “know” about key leaders, the war’s origins, Ukraine’s conduct, NATO’s role, and Western support.

Russia's GEO tactics build on years of search engine optimization (SEO) manipulation and are part of a widely reported pattern of industrialized cognitive warfare that includes deepfakes, cloned sites and other deceptive content. In 2023, a study published in the Harvard Kennedy School Misinformation Review examined pro-Kremlin attempts to manipulate search engine results and found that pseudo‑think tanks and propaganda outlets such as Global Research and Strategic Culture Foundation were amplified through backlink networks and low‑quality sites. These outlets were most effective on conspiratorial searches involving, for instance, Ukraine President Zelensky, where authoritative content was sparse. Indeed, as noted by former CIA leader Jennifer Ewbank, the use of deepfakes to confuse, distort, or influence public opinion not only occurs in Ukraine but across Europe – all of which reflects “the same underlying reality: the tools for deception are faster, cheaper, and more accessible than the systems we rely on to detect or prevent them.” In other words, this is not just about deception, but the erosion of trust itself.

Storm-1516, a documented Russian disinformation operation that has been active since at least 2023, has scaled sharply in 2026. According to Bloomberg, the operation has produced more than 190 false stories since 2023 that the outlet has been able to identify. Based on Bloomberg’s reporting, Meduza adds that in the first quarter of 2026 alone, Storm-1516 was producing fake stories at twice the rate of the same period the previous year with, for instance, as of late March and early April 2026, materials appearing almost daily. Meduza also reports that more than 40 percent of Storm-1516’s fabrications have targeted Ukraine, with another third focused on electoral processes in other countries. Taken together, these reports demonstrate that Storm-1516’s operations are ultimately aimed at eroding Western support for Ukraine, swinging European elections and destabilizing NATO allies.

Taken together with the “Project 2026” leaks, these findings suggest that Russia is now attacking both the content layer (through synthetic media) and the source layer (through cloned Wikipedia‑style sites and fake think tanks) of information ecosystems. While synthetic videos and stories are often treated as short‑term deception, they also become part of the online record that future AI systems may ingest or retrieve, turning Russia’s layered influence architecture into a long‑term GEO problem, especially in data voids.

The Storm-1516 operation follows a clear pattern. A fake witness, often an AI-generated video, seeds a plausible but unverifiable story. Low-tier blogs and Telegram channels amplify it in multiple languages. Then less rigorous Western outlets pick it up, severing the link to the original Russian operator. By the time the narrative reaches mainstream discussion, the Russian fingerprint is gone. The new risk in today’s landscape is that the AI curation layer completes this laundering. It reads the now-repeated narrative across multiple sources and presents it as a neutral summary.

Researchers at the Institute for Strategic Dialogue found that the chatbot DeepSeek was quoting VT Foreign Policy, an outlet known to carry content from Russian propaganda operations such as Storm‑1516 and to have connections to the Kremlin‑linked Strategic Culture Foundation. U.S. and EU sources describe the Strategic Culture Foundation as an arm of Russian state interests.

A 2025 NewsGuard study also found ten of the leading chatbots — including ChatGPT, Claude, Gemini, and Copilot — collectively repeated false narratives from the pro-Kremlin Pravda network about a third of the time. It’s important to note that a 2025 study in the Misinformation Review, responding directly to the NewsGuard findings, found the number was closer to 5 percent and that these failures clustered in data voids. While the researchers found "little evidence to support the grooming theory" and warned against "the overhyped specter of Kremlin manipulation," they acknowledged that data voids "may be artificially created" and that they could not dismiss the possibility that a disinformation campaign could target them. Importantly, their audit came fourteen months before the leaked “Project 2026” documents showed Russia explicitly targeting AI systems. The more Russia attempts to flood these data voids, the more likely it is that future AI summaries about Ukraine will inherit its framing.

How to Build Resilience – A Way Forward

Like its older cousin SEO, GEO is inherently dual-use, but it sits in a regulatory vacuum because it is viewed strictly as a consumer protection issue rather than a national security threat. The Apollo-9 experiment and the Storm-1516 operation prove they are two sides of the same coin; the same commercial tactics that manufactured demand for a non-existent fitness tracker can easily manufacture plausibility for distorted narratives about a geopolitical crisis such as the ongoing Russia-Ukraine war. History shows that with traditional search engines, the market naturally incentivized tech companies to tackle manipulation head-on because mass spam threatened to destroy the user experience for billions of people, directly endangering corporate business models. Malicious foreign influence operations executing GEO are fundamentally different because they remain largely invisible to the mass market, with manipulation surgically clustered within obscure data voids, offering tech companies no commercial incentive to self-police and leaving the information terrain around a live European war effectively undefended.

To bridge this gap, regulators can draw on the lessons of private sector SEO defense and public-private counter-disinformation efforts, but they must realize that the exact same playbook will not work here. While private developers can easily dismiss the Misinformation Review study’s five percent finding as an acceptable commercial error margin, this minor statistical anomaly sits precisely in the data voids that Russia is actively trying to colonize, and so it represents a primary, unmonitored vector for foreign manipulation. The strategic risk is not only that GEO can mislead people in the moment, but that it can reshape the evidentiary record on which institutions and AI systems will later rely; if hostile narratives are allowed to dominate long‑tail topics and thinly documented episodes in the Russia-Ukraine war for instance, then future summaries, briefings, and even historical accounts risk being generated from polluted inputs.

The 2025 Misinformation Review study recommends "warning banners for data void queries" and increased "audit access," but notes the banners are "applied inconsistently" and the audit access is "hindered by power asymmetries.” Because the market will never self-correct a threat it does not financially register, protecting the integrity of generative content must transition from a voluntary corporate practice to a formal national security mandate.

In the Russia-Ukraine war, these dynamics are already visible. Russian operations such as Storm‑1516 use GEO‑style flooding and synthetic witnesses to launder narratives about the conflict into the broader information environment, while Ukrainian actors rely on AI‑enabled monitoring and evidentiary documentation to defend the integrity of the record. The contest is no longer confined to what populations see online today; it is over what AI systems will say is true about the war tomorrow. Recognizing GEO as a national security problem therefore changes the governance question: the training, retrieval, and ranking layers of generative systems are now part of the battlespace, and leaving this space unregulated is akin to leaving critical information infrastructure undefended.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Winning the Peace: The Democratic Dilemma of Limited War

30 July 2026 at 10:54

In our previous article, we argued that overwhelming military superiority no longer guarantees strategic success.

Today, military and political outcomes have become increasingly disconnected.

As Carl von Clausewitz observed, war is fought to achieve political objectives, with military force only one instrument among many in statecraft.

Modern professional militaries are exceptionally proficient at identifying and destroying adversary military capabilities. Yet, they remain far less able to reshape the political, ideological, and social foundations that sustain an adversary's resilience.

The challenge confronting modern democracies is therefore not simply winning wars, but achieving what might be termed strategic translation—the successful conversion of military success into enduring political outcomes.

This predicament of strategic translation has intensified in recent years.

Operations involving Iran, Ukraine, and Gaza have once again raised questions about whether military success alone can produce durable political outcomes, echoing debates that followed the conflicts in Iraq and Afghanistan.

Strategic rivals such as Russia and China have closely monitored these outcomes, adjusting their own strategies to exploit the gap between military supremacy and political consolidation discussed in this article.

The inability to translate military victory into a long-term political settlement has evolved from a tactical issue to a defining test of democratic strategic competency as information flows quicken and domestic audiences examine protracted wars in real time.

Democratic Institutions: Competing Cultures

The principal obstacle facing democratic societies is not a lack of military capability but the complexity of democratic governance itself.

Political authority is intentionally dispersed among elected governments, legislatures and independent public institutions, each possessing different responsibilities and professional cultures. While this diffusion safeguards liberty and accountability, it complicates the integration of national strategy.

Military power achieves its greatest strategic effect only when synchronised with diplomacy, intelligence, economic statecraft and political engagement.

Yet democratic institutions frequently develop these capabilities in parallel rather than as a unified enterprise. Foreign affairs, defence, treasury and justice each define success differently, compete for resources and optimise their own organisational objectives.

Ironically, modern armed forces have become increasingly network-centric, integrating intelligence, logistics, cyber, space and operational planning within a single command framework. Governments, however, largely remain vertically organised.

Democracies have therefore become highly proficient at conducting limited tactical military campaigns while remaining less effective at integrating the broader instruments of national power necessary to convert battlefield success into enduring strategic advantage.

Selling Grand Strategy to Democratic Societies

Developing grand strategy is only half the challenge.

Democratic governments must also sustain public support over time. Unlike authoritarian systems, they must continually justify long-term strategic investment to electorates whose immediate concerns are economic security, healthcare, education and the cost of living.

Electoral competition naturally encourages governments to emphasise visible achievements—military operations, defence acquisitions, and capability announcements—rather than articulating the long-term political objectives these activities are meant to achieve.

Public debate therefore becomes centred on operations rather than strategy.

Without a compelling strategic narrative, public confidence gradually becomes tied to individual events rather than broader national objectives.

Procurement controversies, budget debates, and political disagreements increasingly dominate public discourse, making defence appear as a collection of expensive projects rather than as one component of an integrated national strategy.

Grand strategy that cannot be communicated to democratic societies cannot be sustained by democratic societies.

Democratic Time versus Strategic Time

Winning in combat requires strategic focus, but democratic politics inherently operates on short attention spans as highlighted by researchers in RAND Corporation. Electoral cycles, typically lasting two to five years, create strong incentives for governments to prioritise immediate, visible achievements over the sustained political, diplomatic, and institutional investments required to build long-term national power, as the UK Parliament's House of Commons Public Administration Committee has provided detailed structural barrier on this.

In coalition governments, differing party priorities and narrow parliamentary majorities can further complicate strategic continuity, encouraging short-term political compromise over long-term policy consistency.

The twenty-four-hour news cycle and social media amplify these pressures by encouraging governments to respond rapidly to headlines and shifts in public opinion, often elevating short-term tactical developments over long-term strategic objectives.

A single controversy, whether involving procurement, diplomacy or battlefield casualties, can dominate public debate and increase pressure for policy adjustments that disrupt strategic continuity.

This tension between political urgency and strategic reality was perhaps most evident in Afghanistan.

Throughout that conflict, successive US administrations increasingly balanced military objectives against domestic political pressures, with troop deployments and withdrawal decisions becoming closely linked to electoral cycles and public opinion.

President Obama's 2009 troop surge, while designed to reverse Taliban momentum, was accompanied by a July 2011 timetable for the start of withdrawal, signalling that the United States' commitment was not open-ended.

More than a decade later, the 2020 Doha Agreement established a fixed timeline for withdrawal despite persistent concerns over the readiness of Afghan security forces and the absence of a comprehensive political settlement.

In both cases, strategic decisions became increasingly shaped by political timelines, illustrating how democratic governments can struggle to align long-term national objectives with short-term domestic pressures.

Among NATO allies, these pressures were further compounded by divergent domestic political calendars and national priorities. France, for example, withdrew its combat forces in 2012 following President Hollande's election pledge, while Canada and several allies imposed national caveats that restricted how and where their troops could operate. NATO summits in Riga (2006) and Lisbon (2010) exposed persistent disagreements over troop contributions, burden-sharing and operational commitments, reflecting domestic political constraints as much as collective strategic planning.

As political priorities shifted across allied capitals, long-term strategic coherence became increasingly difficult to sustain.

Without stronger institutional continuity and bipartisan commitment, democratic grand strategy risks becoming reactive, fragmented and ultimately unable to translate military success into enduring political outcomes.

Winning the Peace Requires Political Campaign Design

If democracies are to prevail in limited wars, they must plan for peace before the first military operation begins.

Military campaigns should never exist independently of political campaigns. Governance, justice, policing, economic recovery, institution-building, and strategic communications must be integrated from the outset, rather than improvised after battlefield success.

Repeated strategic frustration also carries risks for democracy itself.

Failure to improve strategic integration may encourage growing calls for more centralised executive authority, expanded emergency powers and greater restrictions on civil liberties in the name of national security.

Democracies should resist this temptation.

Instead, democracies should strengthen institutions capable of ensuring long-term strategic continuity while remaining firmly accountable to constitutional government.

One possibility would be an independent National Strategy Commission, bringing together diplomatic, military, economic and informational expertise to preserve institutional memory and support integrated strategic planning across successive governments.

Conclusion

Democracies do not need to lose their democratic character in order to become more strategically effective.

Authoritarian systems maintain continuity through control, whereas democracies must maintain it through design.

Instead, the task is to create long-lasting institutions, such as an independent National Strategy Commission, that can sustain strategic memory across changing governments without consolidating authority or undermining accountability.

This requires achieving cross-party consensus on essential national goals and integrating diplomatic, military, economic, and informational tools from the outset, rather than improvising after victory.

Failure results in continued frustration and increasing demands for concentrated power.

In a period of limited conflict, success will be defined not just by battlefield successes, but also by long-term political effects.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Sovereign AI Tokenomics Trap

28 July 2026 at 15:02

For US allies, the combination of geopolitics, ever-expanding risk surface and an unsustainable dependence on hyperscale cloud providers has created significant excitement about the potential value of AI data centers and sovereign digital infrastructure. Many of those nations and critical infrastructure owners are now starting to realize that the token, not the data centre, is the atomic unit of AI value. Whoever prices the token actually controls the economics and value creation of every AI-dependent industry irrespective of sovereign cloud, data center or AI factory.

This growing realization will require a material shift in sovereign policy and capability development for those nations combined with short-term patience and recalibration from US partners. The shift will result in both greater sovereign benefit and a more productive, resilient Western Alliance for all.

Why Sovereign Infrastructure Means Little Without Controlling Tokens, Intelligence & Equity

Most Sovereign AI Frameworks are consistent in identifying common levers for success:

-Digital Infrastructure

-Skills and Talent

-Research, development and innovation RDI

-Industry development and commercialisation

-Governance and Equity

Having spent the last 15+ years helping allied nations design their compute, AI and security capabilities, I believe that the rapidly escalating global demand for sovereign digital infrastructure does starts to address where compute is controlled, however, it does little to solve what that compute costs and how value is created and equitably distributed.

Given that whomever prices the token, controls the economics and value creation of every AI-dependent industry irrespective of sovereign infrastructure, nations should treat token supply the way they treat energy supply - as a strategic reserve requiring stockpiles, contracts and dedicated domestic production capacity. It’s sadly ironic that some of these same nations most vocal about sovereign digital infrastructure have been less than diligent in developing and maintaining energy security.

The Rapidly Evolving Discipline of Tokenomics

While many leaders still think of LLMs in terms of infrastructure (more requests require more compute and therefore cost more), the reality is more complex. Users and use cases can create vastly different types of requests which have highly varied infrastructure and cost implications.

The smallest current production unit for LLMs are tokens – a fundamental unit of data that an AI model reads, generates or uses equating to roughly 4 characters per token. Over the last 3 years inference costs have reportedly fallen roughly 1,000-fold, with inference now accounting for two-thirds of all AI compute demand.

By any normal utility logic, falling unit prices should mean smaller monthly bills for users, however new models are both more token-intensive at increased prices while usage has skyrocketed, leading many to consume their entire annual AI and tech budgets in only a matter of months. This seems clear proof of Jevons Paradox where decreased unit cost is significantly outweighed by material and accelerating increase in use.

In addition, recent BCG research indicates that only 5% of their clients interviewed are creating substantial and sustainable value from AI.

BCG Build for the Future 2025 Global Study (n = 1,250).

Government and enterprise leaders have now seen more than enough exemplars and representative AI use cases – demand is accelerating to show a true return on investment “ROI” for those programs, which fundamentally means an ROI on token usage.

This discipline of financial accountability to AI use and governance has earned the name of “Tokenomics”, meaning the demand for ROI during a period of increased usage, risk and associated costs has created a triple whammy for policy makers, regulators and users.

Sovereign Clouds, Rented Intelligence & Lost Value.

What does all of this mean for a nation state, alliance or critical infrastructure owner?

While an esteemed British colleague and I recently considered the Sovereignty 2.0 cloud and data center location and legal control aspects for the World Economic Forum, we didn’t answer the pricing question ie. who sets the cost and terms of the thing produced (token) running on that stack which dictates the sustainable value proposition?

This is the sovereignty risk the digital infrastructure debate has largely missed but we expect to rapidly evolve over coming months.

A nation can host its own data centre, run its own hyperscaler partnerships, satisfy every metric in a Cloud, Data Center or AI Sovereignty Framework BUT still be entirely price-taking on the tokens flowing through it without a dedicated available reserve if, or when, the supply chain is disrupted. The subsidy era of new foundation models is coming to an end with Anthropic's 2026 enterprise pricing shift the most public example of consumption growth outpacing cost declines. Operational control of the rack means little if the marginal cost of intelligence itself is set outside of a sovereign legal and commercial jurisdiction.

Perhaps even more sobering are the concerns of US and allied intelligence communities that the increased costs of token usage are causing critical public and private sector users to move to highly capable “open weight” models predominantly developed and sourced outside of the trusted Western alliance. This week’s launch of the Moonshot Kimi K3 with comparable capability to recent Anthropic and OpenAI versions has further entrenched the systemic risk.

Greater independence of allied sovereign objectives at the infrastructure AND intelligence layers may require a shift for some policy makers, agencies and technology vendors, however, the strategic value from greater trust, intelligence, innovation and resilience would be significant.

Closing the Tokenomics Gap

While rightfully asserting digital sovereignty, America’s allies must stop treating sovereign compute and intelligence as a real estate problem and start treating it as a strategic commodity problem similar to the way we manage oil, grain or semiconductors.

That creates some meaningful challenges from both policy and practice perspectives:

-Create a national token reserve/s via prebuilt capacity insulating critical government and infrastructure workloads from price and availability shocks the way strategic petroleum reserves insulate against supply shocks

-Mandate transparent token cost disclosure in critical-sector procurement, so cost-per-outcome (not cost-per-CPU/GPU) becomes the sovereignty metric regulators actually score. “Commercial in confidence” wont be good enough for an agentic world.

-Create an active domestic AI model routing capability, so government workloads can shift between frontier and commodity models rather than being locked to a single provider's pricing curve.

-Plan for AI inference at the edge – while large urban Data Centers take up the headlines and capital, it won’t necessarily be how we consume and create value domestically and across the alliance.

-Demand a social license of all who participate – many nations have exported a significant portion of the value created during the internet era to hyper-scale foreign companies and demanded little in return other than occasional headlines about “strategic investment”. New strategies and structures must be created where the value created of this agentic token-driven world accrue directly to the communities that use them and not to be reallocated or misspent as a new form of taxation. Oil-driven Sovereign Wealth Funds may provide an effective blueprint fit for the Agentic Age.

A token reserve is the logical and necessary next stage for Sovereign AI

None of these policies replace the need for sovereign digital infrastructure. As token prices fall but total AI spend climbs, the value to nation states deriving from infrastructure alone is incomplete and does not achieve multiple core objectives. Nations that control where compute resides but not what tokens cost and deliver will remain intelligence and price-takers in the AI economy. For America’s partners, a sovereign token reserve is the next necessary step toward genuine digital autonomy and an even stronger Western Alliance.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Audience Is a Machine: Our Future Information Environment

27 July 2026 at 10:05

The future of disinformation is no longer about creating better content. It is about teaching machines what to retrieve, summarize and recommend. In the AI era, the editor matters more than the article.

A story no longer has to trend. It has to be retrieved when a large language model (LLM) constructs the answer. The most important audience in the information environment is no longer human. If an AI assistant becomes the primary gateway to information, influencing what it retrieves becomes more valuable than influencing what millions of people read directly.

The Hugging Face Model Hub, the top repository worldwide, tracks over 2.9 million total machine learning models. Many models are for wonderful uses, ranging from research universities to new private sector companies built to solve problems. Meanwhile, more than 130 active national sovereign initiatives exist in more than 60 countries, according to the Center for a New American Security (CNAS) Sovereign AI Index. Every one of these models becomes another editor with its own worldview, training corpus and retrieval strategy.

As Bob Dylan reminds us, “For the times they are a-changin’”.

Countries are in pursuit of a foundational model (cognitive sovereignty) that will provide its own historical context, experts, values, national interests and more.

Different versions of reality will emerge, not because people disagree, but because different models were taught to retrieve, prioritize and reason differently. Not unlike media outlets as they evolved, just with a completely different scale.

Our Focus

The old world was about content, distribution and amplification. The new world is about training, retrieval and reasoning.

We must have the expertise to explain the mental frameworks machines construct before we see an answer to our query.

Our slide decks will cross out the “attention economy” and replace it with the “cognitive economy.”

We will remind ourselves that during the social media era, an adversary would flood the zone with thousands of fake articles and accounts to amplify a narrative. In the AI era, the objective changes. Rather than convincing one person at a time, adversaries will increasingly seek to influence the system that answers everyone.

Perspective is also important. Printing presses made publishing a reality. Radio introduced the broadcast message. Television opened up reach to mass audiences. Social media democratized who could have a voice. And AI now changes who decides what we receive.

Our Preparation

We will need to expand our remit and add expertise in training data provenance, retrieval indexes, embedding systems, model guardrails, agent memory, citation chains and reasoning architectures. AI engineers will become important parts of our team, if not already so.

The decade ahead will introduce AI models and agentic systems that decide what billions of people see. Agents will continuously search, compare, negotiate, monitor and decide for us. Humans may never initiate the request, but the agent will know what to do. That’s a different information ecosystem. We must learn how to track its development accurately and efficiently, so we are in-step or a step ahead on each new innovation of importance.

AI models will cite other AI models who cite other AI models. Over time, the original source may disappear entirely behind layers of machine summarization. The citation survives, but the human reporting becomes increasingly distant.

The editorial model will change as quickly as it needs to. How do we keep up with changes in the perspective of a model on a key topic and why it occurred?

Bad actors will optimize less for search engine optimization (SEO) and increasingly for generative engine optimization (GEO), engineering content specifically to influence what AI systems retrieve and cite.

We will need a new intelligence platform that tracks all publicly accessible LLMs and all innovation in places like Hugging Face, so we can see patterns earlier across the world. Imagine tracking hundreds and then thousands of LLMs in real-time. We still care about what happened, who said it and the rest of the 5Ws, but increasingly, it will be meaningful to know how Claude, Gemini, ChatGPT, DeepSeek and other models summarize and frame key messages.

These platforms will help us as we develop skills to understand training data integrity, how retrieval systems are poisoned through Retrieval-Augmented Generation (RAG) attacks, and how agent memories are manipulated.

Invisible Persuasion

When the audience is the machine, our efforts shift from how to protect the population to how we analyze and influence the infrastructure that reaches us.

Media literacy taught us to evaluate what people published. Machine literacy teaches us how to evaluate how machines constructed the answer.

The era will have many names, I’m sure, but one that resonates with me is “invisible persuasion.”

Unlike propaganda, machine-led information thrives on invisibility. It must appear ordinary, mundane and just do its job.

The next generation of AI will continue to quietly remove the human being from both ends of the media system. It is becoming the audience, and it is becoming the editor. And it is doing both at once.

It is also succeeding in building trust in humans.

SparkToro and Datos Group found that 60% of US google searches ended without a click in the first four months of 2026.

The same person who once clicked through to read is increasingly staying put while a machine goes and reads for them. The Reuters Institute expects search referrals to nearly halve over the next three years.

A Pew Research Center report showed that users clicked a source cited inside an AI summary just 1% of the time (900 US adults, 68,879 google searches).

Trust is migrating from the publisher to the summarizer. Our learning used to include more friction – a competing headline or comments we disagreed with. Now, we get a clean answer without friction.

How this impacts our judgement is a question we’ll study for many years ahead.

Conclusion

The printing press democratized publishing. Search democratized discovery. AI is centralizing editorial judgement again, this time inside machines.

The new editors are not confined to newsrooms. They include model developers deciding guardrails, publishers licensing training data, platform owners determining retrieval rankings, governments building sovereign AI models, open-source communities releasing foundation models, and enterprises curating the knowledge bases their AI agents consult. Editorial power is becoming distributed across the AI stack rather than concentrated in traditional media organizations.

The organizations that understand how machines learn, retrieve, reason and remember will shape the next information environment.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

A Master List of Espionage Targets, Suspected Spies, and Potential Recruits

16 July 2026 at 05:00

It was with alarm that I read the recent New York Times article reporting the regurgitation of a truly terrible idea that, like a bad meal, continues to come up every several years.

The Times reports that the Office of the Director of National Intelligence

is demanding that American intelligence officials turn over the names of all foreign espionage targets, including suspected spies and potential recruits, to create a master list, to avoid inadvertent conflicts between agencies and to better track foreign intelligence threats in real time.

A primary task of any corporate security department or Federal counterintelligence activity is to prevent, deter, and detect human and technical compromises of sensitive information. Even innocent errors can result in massive damage when they reveal sensitive information. Nor is it a secret that any large organization, no matter how carefully it screens its people, may have persons in its ranks who would betray their colleagues and their country. And of course, malign foreign actors routinely seek to access U.S. information systems and classified computing resources.

Just as a comprehensive list of CIA employees, including covert officers serving in dangerous locations, would be of great value to any number of foreign adversaries, so too would the proposed list of espionage targets, suspected spies, and potential recruits. And the drawbacks associated with creating such a list are significant - and potentially catastrophic.

The mere process of assembling the relevant data from within separate departments and agencies would require the assembling of multiple intermediate lists -for example, all subjects of interest from multiple operating components of the FBI, CIA, and additional agencies, each one of which would pose a separate significant and potentially catastrophic counterintelligence vulnerability. Compiled into a single comprehensive set, the theft or leak of the combined list would work incalculable damage to the United States.

Similar proposals have been made for decades. At the very best, they are a solution in search of a problem; for every time two or more agencies trip over one another in the pursuit of intelligence opportunities, there are literally hundreds more occasions in which the existing deconfliction arrangements work exactly as they should.

I spent several years in an ODNI policy position when the Office was first created. From time to time I encountered colleagues from one or another part of the Government, or from outside the Government completely, who sought to establish policies and procedures to address some obscure, long-since resolved, or simply imagined pet peeve. While some concerns truly reflect structural obstacles and warrant serious consideration, sometimes the most responsible thing to do is simply draw the line and withdraw a truly bad proposal. This is one of those times.

Jonathan M. Fredman is a Non-Resident Fellow at the Princeton University School of Public and International Affairs. He spent 36 years in legal and policy positions at the Central Intelligence Agency and the Office of the Director of National Intelligence.

All statements of fact, opinion, or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in the contents should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author's views.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Washington’s Spy Ring and Paine’s Democracy

14 July 2026 at 05:01

Agent 711 was one of the most effective and least known spies in our nation's history. He used dead drops to communicate about enemy plans. He used secret chemical processes to create new forms of invisible ink. He spread disinformation to disguise his own troops' movements and confuse the enemy. The year was 1778. Agent 711 was George Washington. He was our nation's first spymaster, and his network of informants was the Culper spy ring. It was one of several that he ran through the war and also during his time as president. Washington's army was undermanned, underfunded, frequently on the run. He knew he needed an edge, and he found it with intelligence. A British intelligence officer later said Washington did not really outfight the British — he simply outspied us.

At the same time, as a young nation was leaning heavily into its very first intelligence community, Thomas Paine was inspiring a nation to democracy. He had ideas about equality, rights, and the limits of government — revolutionary ideas for the time. He had ideas about power: it was not a divine right handed down to a monarch, but power rested in the hands of the people. Government borrows that power for a time, within limits. The representatives of that government are meant to be of the people and return to lives among the people, not to be separate or above or disconnected from what's going on among them.

Thus, our nation was born, not out of a tension between intelligence and democracy, but as an alchemical mix of both. We carry these ideas forward into a modern context. Power rests with the people. They loan it to the government. We trade some of our liberty for things that no one person can provide — roads, the power grid, police, submarines, national security. In exchange, we demand things of our government: accountability, adjustments, change, transparency. But we also demand security, and we demand economic prosperity. That's the life, liberty, and pursuit of happiness part.

It's easy to forget that there are still those in the world who wish to take these things away from us. It's also in part generational — today’s college graduates were not alive during 9/11 or had maybe just been born. There are still terrorists and cartels who wish to take life. China seeks to take liberty — they want to subjugate people to their will, as they've done in Tibet, in Hong Kong, as they're attempting to do in Taiwan. Russia wants to end the pursuit of happiness. Some men truly do just want to watch the whole world burn to make themselves feel better, and Putin is one of those. Rather, they want happiness on their terms. This looks like power for the elite few oligarchs around Vladimir Putin, while he sends the poor to fight his war in Ukraine. It looks like the ruling elite of the CCP and their little princelings. They want order. They want to take liberty to hold power. The state has shown, in their case, security, but only for the few.

Why? Because liberty is messy. It is a struggle. It's making our own way while everyone else does the same. It's making space for ourselves and for each other, and when those spaces conflict, we figure it out. Thomas Paine wrote that “when we speak of rights, we ought always to unite them with the idea of duties — rights become duties by reciprocity: the right which I enjoy becomes my duty to guarantee to others, and he to me.” So today we are the guarantors of each other's rights. In Paine's time that looked like representative democracy and a little bit of revolution. Today, specifically with regard to spy work, it is a hard concept to wrap your head around — it's actually protection of rights by proxy.

In my pocket I carry a coin — the first one made for the Senate Intelligence Committee, on which I served for six years. On one side is Washington's seal, to represent our very first spymaster and to honor the intelligence officers who were so instrumental to the birth of this nation. But there are also two sets of stars on this coin. There's a set of 15 around the outside that represents the 15 members of the Senate Intelligence Committee, who represent the entirety of the Senate. And then on the other side there are a hundred stars representing the Senate as a whole.

Why are there two layers? The 100 senators represent the entire country. The 15 members of the committee represent the Senate. Just as Washington went to great pains to encode secret messages and hide what he knew from the British army, secrets today must stay secret — the more people who know a thing, the less likely something is to stay secret. The intel committees are there to be the eyes and ears of the entire Senate or the House, and by extension the nation. These committees were designed to bring things back into balance.

During the 1960s and 1970s, another time of intense national upheaval, the IC got way out of hand — spying on political figures like Martin Luther King, attempting assassinations of foreign leaders, and engaging in massive propaganda campaigns. The Church and Pike committees united to investigate and create both the Senate Intelligence Committee and the House Intelligence Committee, to provide permanent, comprehensive oversight to keep this balance.

People who don't know intelligence work think that it's all-powerful and full of abuse. They see the spy thrillers that are in the movies. They think the 1970s continue today. But people who do know it, know it's a microcosm of liberty. It's messy. It's flawed. But it's also full of checks, balances, and people doing the right thing. These are my friends and former colleagues. They look like me. They look like you. They miss dinners with families. They put themselves in harm's way. They don't get parades. They don't get early boarding on flights. They don't get military discounts. They just do the work.

For us as a country, I fear there are rough seas ahead. We face two revisionist powers that, like King George III, believed that one person should be in charge through might alone. These people want to set up a false choice: freedom or security, not both. But the truth is that freedom and security are deeply intertwined. It is fear that leads to that false choice. On the one hand, dictators fear chaos — they think that people will come to understand that their oppressive dear leader does not, in fact, have their interests at heart. The supposed strongman is actually terrified. He's desperate to hold on to power. On the other hand, amongst some, there is fear the security mission will take over and become too big, too powerful, lodged in the hands of someone who is too power-hungry. But the goal is balance. We need Washington's spy ring. We also need Paine's ideals. And we need them working together.

One further reflection on that Paine quote: the rights I enjoy, I also guarantee to others. This is perhaps most true for those who operate in the shadows. They guarantee the rights of fellow citizens day in and day out, with a million small decisions, even when no one is watching. Democracy enables good spy work — only in a democracy can you walk into the Oval Office and deliver truly terrible news to power, tell the president things have gone sideways, and work together to fix it.

Spy work also makes democracy possible. I look forward to a day where there are no enemies; no one who seeks to assert ultimate power over others. That day I will have happily worked myself out of a job. But it is not today. Today I am fully employed attempting to create deterrence, know our adversaries, create a future of peace through strength. I have sworn an oath to support and defend the Constitution four times in my life, and hopefully one day I'll do it a fifth, but inside government or out, trying to work for democracy, for freedom, for a secure America and a secure world is the mission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Evo: Bolivia and the Erosion of State Authority in Latin America

9 July 2026 at 05:03

In recent days, an unusual consensus has begun to emerge among some of Bolivia's most prominent public intellectuals, economists, diplomats, and former political leaders.

Former Foreign Minister Jaime Aparicio has warned that Bolivia has moved from "the theater of the absurd" to "the dialogue of the absurd," suggesting that the country may require international support to preserve democratic governance. Economist Jaime Dunn has repeatedly argued that Bolivia's central challenge is no longer merely economic, electoral, or ideological, but institutional. Former President Jorge "Tuto" Quiroga has warned of the corrosive effects of impunity and criminality on democratic government. Former La Paz mayor and economist Ronald MacLean Abaroa has likewise argued that Bolivia confronts a deeper crisis of governance than many observers recognize. Political commentator Vidal Dorado has advanced similar concerns.

These figures differ in generation, political affiliation, and professional experience. Yet they increasingly converge around a common diagnosis: Bolivia's greatest challenge may no longer be who governs the country, but whether the state itself retains the capacity to govern effectively.

That distinction matters.

Most international coverage of Bolivia's current turmoil continues to frame events as a political confrontation between former President Evo Morales and President Rodrigo Paz. The headlines focus on road blockades, food and fuel shortages, arrests, negotiations, and the possibility of emergency measures. Morales's supporters argue that he is being excluded from political life. His opponents contend that he is attempting to destabilize the government in order to preserve his political relevance and avoid accountability. Both interpretations contain elements of truth. Neither fully captures the significance of what is taking place.

As a Bolivian attorney and former Interim Mission Director of USAID/Bolivia, I have observed the country navigate moments of extraordinary turbulence. Bolivia has survived military governments, hyperinflation, constitutional crises, regional tensions, and repeated confrontations between state institutions and social movements. Yet what is unfolding today feels different. Increasingly, the central question is not who governs Bolivia. It is whether the Bolivian state can govern effectively.

The current crisis illustrates the point. Weeks of blockades have disrupted commerce, restricted the movement of food and fuel, and imposed substantial costs on ordinary citizens. Reports indicate that patients have died after being unable to obtain timely medical treatment because transportation routes remained blocked. The government has debated emergency authorities while attempting to avoid a wider confrontation. Yet even amid escalating tensions, important developments have occurred. The Central Obrera Boliviana has entered into dialogue with the government and established joint commissions to address detainees and other demands. At the same time, divisions have emerged within sectors of the protest movement itself, including organizations associated with the Tupac Katari movement.

These developments suggest that the crisis is no longer a simple confrontation between government and opposition. Bolivia increasingly resembles a contest among multiple actors, grievances, and centers of influence, none of which appears capable of imposing a definitive outcome on its own. The result is a growing debate not merely about political leadership, but about governability itself.

At the same time, public discussion has increasingly touched issues that until recently remained largely confined to security specialists and anti-corruption practitioners: narcotics trafficking, illegal mining, contraband, land trafficking, environmental crime, and the financing of political mobilization.

Whether any particular allegation ultimately proves true remains a matter for evidence, investigation, and due process. Yet the broader trend is difficult to ignore. Over time, illicit and informal economies can accumulate sufficient financial and political influence to shape governance itself. They provide livelihoods where the formal economy cannot. They generate patronage networks. They cultivate local loyalties. They penetrate institutions. Eventually, they cease functioning merely as criminal enterprises operating outside the state. They become alternative systems of power operating alongside it.

More than half a century ago, René Zavaleta Mercado, Bolivia's most influential twentieth-century political thinker, described his country as a sociedad abigarrada—a society composed of multiple social, economic, and political realities existing simultaneously within the same national territory. Zavaleta was attempting to explain Bolivia's complexity. His insight remains relevant today. Yet the challenge confronting Bolivia may now extend beyond the coexistence of multiple realities. Increasingly, some of the most powerful actors operating within those realities are neither political parties nor state institutions, but illicit economic networks whose resources and influence rival those of the state itself.

This is not solely a Bolivian phenomenon.

For much of the democratic era that followed Latin America's military governments, political debate revolved around elections, constitutions, economic models, and the alternation of power. The underlying assumption was that the state remained the principal arena through which political conflict would be resolved. Across much of the hemisphere, that assumption is being tested.

In Mexico, cartels have challenged state authority across entire regions. Ecuador's recent security crisis demonstrated how rapidly organized crime can reshape national politics. Colombia continues to confront criminal and armed groups whose influence extends well beyond traditional law-enforcement concerns. Guatemala has repeatedly struggled with corruption networks capable of penetrating public institutions. Venezuela presents perhaps the hemisphere's most advanced example of governing structures intertwined with illicit economic activity. Nicaragua's authoritarian consolidation likewise demonstrates how patronage, coercion, and opaque economic relationships can undermine democratic accountability.

Elsewhere, similar concerns are emerging. Brazil faces the growing influence of criminal organizations and illegal mining operations in the Amazon. Panama remains vulnerable to transnational money laundering and criminal finance. Jamaica and Trinidad continue to grapple with the political consequences of organized crime and gang violence. Guyana's remarkable economic expansion creates extraordinary opportunities but also governance risks familiar to many resource-rich states. Even Argentina's recent political debate, reflected in part through the rise of Javier Milei, has centered on public frustration with entrenched patronage systems, institutional weakness, and a perception that the state increasingly serves privileged networks rather than citizens. In Chile, support for figures such as José Antonio Kast similarly reflects anxieties about crime, state capacity, and the ability of institutions to maintain public order.

These countries are not identical. Their histories differ. Their institutions differ. Their democratic trajectories differ. Yet they increasingly confront a common challenge: preserving the capacity of legitimate institutions to exercise authority in the face of alternative networks of economic and political power.

The concern is not merely theoretical. It increasingly shapes political discourse throughout the hemisphere. What Jaime Dunn articulates in Bolivia is not entirely different from concerns expressed by reformers in Ecuador, opposition figures in Venezuela, portions of Peru's political class, or advocates of institutional reform elsewhere in the region. The ideological differences among these groups are substantial. What unites them is a growing belief that democratic governments are losing ground—not simply to political opponents, but to systems of power that operate beyond the effective reach of traditional institutions.

At this point, the observations of Jorge Basadre, Peru's great historian of the republic, become especially relevant. Basadre famously described Peru as both a problem and a possibility. The same might be said of democratic governance across much of Latin America today. The challenge facing many countries is not simply electing the right leaders or adopting the right policies. It is preserving institutions capable of channeling conflict through politics rather than allowing power to migrate toward criminal organizations, illicit markets, or networks that thrive on disorder and impunity.

Many of the hemisphere's most experienced diplomats and policymakers, including former U.S. Under Secretary of State Tom Shannon, have long argued that Latin America's enduring challenges are ultimately institutional rather than ideological. Bolivia's current crisis reinforces that point. The debate is no longer primarily about the distribution of power among competing political actors. It is increasingly about the capacity of democratic institutions to exercise authority, enforce rules, and maintain legitimacy.

This challenge also exposes a growing gap in the inter-American system. The Inter-American Democratic Charter was designed to defend constitutional democracy against coups, authoritarian ruptures, and attacks on democratic order. The Inter-American Convention Against Corruption sought to strengthen integrity and accountability throughout the hemisphere. Both remain important achievements. Yet neither was drafted with today's challenge fully in mind. Increasingly, democracy is threatened not only by tanks in the streets or presidents who refuse to leave office. It is threatened by criminal networks, illicit economies, and corruption structures that do not seek to replace democratic institutions outright, but gradually hollow them out from within.

Two centuries ago, Simón Bolívar warned of the fragility of republican institutions in the newly independent Americas. More recently, Basadre reminded us that the republic remains both a problem and a possibility. Bolivia's current crisis suggests that those concerns remain remarkably relevant. Jaime Dunn and others have argued that the country's deepest challenge is institutional. The evidence increasingly suggests they may be right.

The fundamental question facing Bolivia today is not whether Evo Morales or Rodrigo Paz prevails in the next round of political struggle. It is whether democratic institutions can continue to exercise legitimate authority in the face of increasingly powerful alternative networks of economic and political power. That question extends far beyond Bolivia. Increasingly, it is becoming one of the defining questions of democratic governance throughout the Americas.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

After the Intelligence Cycle: A New Schema for AI-Native Intelligence Analysis

9 July 2026 at 05:01

Recent discussion of artificial intelligence in intelligence analysis has consistently framed the technology as a means of accelerating an existing process. The intelligence cycle (collection, processing, analysis, production, dissemination) remains the implicit organizing schema, with AI cast as something used to drive its stages faster, increase resource efficiency, or widen its scope. We find this framing inadequate. It leaves the cycle itself intact, treating it as a sound structure merely in need of added speed, when the more consequential present opportunity is to reconsider the structure altogether. The intelligence cycle is an industrial-era artifact, popularized by Sherman Kent in the immediate post-war period, when information was scarce, expert labor concentrated, and the consumer a narrowly-defined institutional decision-maker. None of these conditions still holds. Recent work by Gartin, Schlickenmaier and by Reed and Szylkiewicz has argued for updating intelligence with agile, information-technology methods, and for shifting delivery toward a services-centric rather than goods-centric model. These arguments address the outdated production cycle, but neither fully anticipates the extent to which AI permits the cycle to be displaced wholesale rather than merely modernized.

As practitioners building intelligence programs in this environment, we observe that the prevailing conversation remains bounded by traditional conceptions of what analytic work is. This paper proposes a different framework, organized around a single assertion: that AI enables a scale and rigor in cognitive information work that were previously unavailable, and that this in turn dissolves several of the assumptions on which the cycle previously depended. The argument rests on a particular architectural premise that analytic reasoning can be captured as a structured data schema rather than compressed into an overly-simplified finished narrative. From this premise follow five ruptures with the traditional cycle:

First, the core value unit of intelligence shifts away from the finished assessment toward a more complex artifact that contains the entire decision architecture by which the assessment was reached.

Second, AI-enabled analysis becomes continuous and ongoing rather than fixed to a single publication date.

Third, analytic accuracy becomes measurable, and therefore improvable, for the first time in history.

Fourth, the relationship between provider and decision-maker narrows, and can be scaled to the needs of the individual consumer rather than to a generic reporting requirement.

And fifth, source handling and judgment collapse into a single operation rather than appearing as separate steps.

Taken together, these constitute a revolutionary rather than evolutionary departure from the manual methods that have governed intelligence analysis for a century, and they open new ground for rigor, accountability, and accuracy in global risk forecasting.

From Finished Product to Assessment Process

Modern intelligence analysis tradecraft treats the finished product as its core deliverable. The product serves both as the vehicle of value to the consumer and as the measure of organisational output, and it is the terminus toward which collection, refinement, and assessment are all directed. This arrangement was never optimal. Reliance on a single artifact collapses a complex analytic process into one compressed object, in which the judgments, and biases, included along the way are flattened into a single deliverable. Tradecraft notes and caveats have occasionally preserved fragments of this reasoning, but the product standing alone has never fully represented the value chain that produced it. The most important steps in the analyst's work, the alternative hypotheses entertained, the source biases weighed, and the contingencies sketched against one another, do not travel with the document, forming a lost layer of metadata that usually remains behind.

Artificial intelligence relieves the scale pressure that heretofore forced this compression. An analyst working with well-designed AI tools can now meaningfully execute and record each of the steps in an intelligence workflow rapidly and at scale, which permits the end product to change, away from the finished product deliverable to a searchable, indexable, and auditable log of expertise that has produced a range of potentially useful data through its work. In this process, the end value unit of analysis becomes the actual analysis itself, rather than an artificial summary of that analysis compressed to finished product size. By deprioritizing the focus on the product as the end goal of all analytic work, more of the valuable decisions and information which informed its creation become accessible to both the analyst and the consumer, which may audit and explore these dynamically to enhance their own understanding.

For this process to compound rather than merely accumulate, the analytic representation of judgments must be persistent and structured. Judgments of this type include the reliability of the source, the credibility of the information it contains, the weight that information should play in contributing to a view of the world, how it might interplay with other events and trends, and so on. These expert judgments are collected as structured data and recorded as they are formed, so that they can later be reviewed against real-world outcomes as those outcomes resolve. This foundation of analysis permits auditability and recursive improvement in judgment, source collection, and analytic framing. AI tools used correctly should permit a thoroughness which enhances judgment rather than eroding it, because they help create a massive record of analytic work that persists and can rapidly be revisited, rather than a sequence of keyhole snapshots of reality which age into irrelevance from the moment they are completed.

Because our representation of analyst judgment is structured across various data points rather than as a single loose narrative, it supports more than retrieval. A sufficiently large corpus of analytic judgments can be used to generate predictive assessments based on prior weighting and modal relationships, to trace multi-path higher-order consequences that human reasoning follows poorly, to identify which forces carry the most systemic weight, and to express conclusions as calibrated, quantified probability rather than verbal estimate.

From Episodic to Continuous Analysis

The intelligence cycle was built around episodic production not because it produced the best analytic results but because scale challenges prevented anything more rigorous. Between products, the analyst's judgment existed only in their head, and even then, was a nebulous and ill-defined thing. Kent’s “Words of Estimative Probability” and Tetlock’s superforecasting projects both pointed toward a need for improved, continuous, and calibrated judgment, but neither could provide a way to operate such a system of rigor continuously at scale. Artificial intelligence changes this arithmetic. A well-trained model handles what human analysts struggle to achieve at scale, ingesting raw data, mapping it to analyst-defined areas of interest, and updating mathematical prediction models. This rapid processing enables the analyst to spend bandwidth on setting the scope of analytic questions, interrogating the quality and biases of sources, and defining the weights and relationships the models will assign to various real-world events. Far from the language of the factory assembly line, the modern discipline of intelligence we espouse more closely resembles the rhythm of a trading desk, where equities analysts mark positions to market continuously, forever adjusting expectations based on a never-ending flow of data.

In this framing, an equities analyst wouldn’t save up all their trading positions to be submitted in one package at the end of the day, and we propose that appropriately tooled intelligence analysts similarly no longer need to wait until a publication date to deliver analytic value. By connecting front-end AI summarization and chat systems to back-end analyst enrichment areas, customers are able to query the latest in analyst judgment on demand, creating an instant feedback loop in which customer queries inform and sharpen ongoing analytic priorities. This serves the analyst as much as the consumer. It removes the obligation to produce filler during quiet periods, and it lets analytic output follow the genuine cadence of a topic rather than an arbitrary calendar.

Measuring and Improving Accuracy

Intelligence consumers hold the analyst accountable not only for a judgment but also for the reasoning by which it was reached. Historically this accountability has been difficult to honor, because much analytic judgment was formed reflexively and poorly recorded. The methods now available for capturing and structuring reasoning make the problem tractable for the first time. Once reasoning is recorded as structure, it can be scored against outcomes as they resolve, using calibration methods such as Brier scoring. The essential property is that each judgment is preserved as it was made and is not revised afterward. That is what keeps the scoring honest: the analyst is measured against the call they actually made, not a version softened by hindsight.

We are deliberate about the strength of this claim. The architecture does not inherently make analysts more accurate. What it makes possible is the measurement of accuracy and the diagnosis of error. When a judgment proves wrong, the structure allows the failure to be traced to a specific weighting or relationship rather than absorbed into an unaccountable whole. It is this decomposability, sustained over time and across many resolved judgments, that creates the conditions for improvement, for the individual analyst and for the models their judgments inform. The data describing how and why an analyst reached a judgment is, in this respect, more valuable than the judgment itself, because it is the raw material of recursive refinement.

This is a meaningful departure. For most of its history, intelligence analysis has struggled to know whether it was improving in delivering decision advantage or predictive insight, because the record needed to properly audit this improvement was never systematically available. For the first time, a complete and inspectable record scored against reality is within reach, presenting the opportunity for true improvements in forecasting accuracy.

From Generic to Specified

A further constraint the cycle never escaped was the assumption that consumers were finite and institutionally legible. The analyst writing for a government agency in 1990 could reasonably picture a handful of senior officials whose interests were bounded by their roles in advancing the national interest. This model functions poorly in the wider modern intelligence context, in which the reader of any given report might vary widely based on their position and access. For intelligence teams working in today’s commercialized contexts, the reader of a report might be a CFO weighing currency exposure, an operations director routing freight around contested waterways, a general counsel mapping sanctions risk, or a fund manager modelling financial tail risk. Each actor is sufficiently distinct from the others that how information is presented to them, and what information is relevant to their decisions, is so different as to destroy the value of a single, universal intelligence report. Each actor makes a different decision against a different geometry of exposure to the same geopolitical environment. A generic product written to the centre of this readership delivers very little decision value to any specific stakeholder because it is intended for none of them.

Bespoke intelligence tailored to individual stakeholders is rare, because it is cost-prohibitive. Examples like the President’s Daily Brief show just how complex and difficult the process is to tailor an intelligence report to even one customer, let alone many hundreds or thousands. Today, AI makes this feasible, because it permits a single body of robust analytic work to be expressed differently for each consumer according to their specific exposure. The assessment surfaced to a Nordic manufacturer with significant Strait of Hormuz exposure differs significantly from the one surfaced to a Latin American agribusiness with none, though both can draw on the same underlying analysis in order to inform a wider geopolitical frame. This approach keeps client-specific context separate from the shared analytic base rather than absorbing it permanently, which matters as much for data governance as for scale. In other words, by keeping intelligence about the threat environment separate from context about the user’s potential impact until the last possible moment, delivery of truly tailored insights is permissible at a scale that humans alone cannot match. Delivering this well still requires human guidance, because the object is to inform human decisions, but it is reachable by a useful number of consumers only through automated composition and delivery. In practice it increasingly resembles data layers, dashboards, and conversational interfaces rather than documents and slide decks, which are inherently static and cannot respond to unique and specific customer interrogation. AI’s ability to handle mass data sets and rapidly synthesize them for human engagement is the key which unlocks these dynamic product offerings.

Source Handling as Judgment

One fiction the cycle's imagery sustained was that a clean separation existed between collection and analysis. In the logic of the assembly line, collection produced sources, processing ordered them, and analysis applied judgment. Practitioners have long known this separation rarely held in practice. Deciding which information to credit, and how heavily, is itself an analytic act, one frequently practiced by collectors but only sporadically preserved in the finished product in the form of sometimes feeble source reliability statements. An AI-enabled team can make this categorization a continuous and systematic piece of the analysis rather than a burdensome and occasional addendum to it. High-volume collection and tagging let analysts reach and index relevant information by reliability far faster, and automated tooling lets them record, in real time, which signals they judge useful, to what degree, and for which questions.

Two disciplines give this its force. The first is continuity: signals attach to persistent, identified subjects rather than floating as unlinked text, so that a judgment made today accrues to the same subject a judgment made months earlier addressed. The second is provenance carried as structure. Each catalogued signal carries its source, the system action that surfaced it, and the analyst decisions that touched it, so that the basis of a judgment travels with the judgment rather than being reconstructed after the fact. In our architecture the analyst encodes meaning into collection from first contact through to the point at which a signal is connected to the wider analytic framework. The system performs the high-volume triage and flagging; the analyst accepts, challenges, or supplies the context the system cannot; and the system then does the durable work of attaching that judgment to analysis where it carries lasting weight. The provenance this produces is more than an audit trail, and becomes part of what the consumer can interrogate. It also forms the basis for learning, over time, about collection gaps and the reliability of sources, serving as an internal collection management architecture.

After the Intelligence Cycle

Building an intelligence team that is AI-native from the outset, at a moment when most established intelligence institutions predate AI and are captured by institutional cultures which inhibit profound change, has shaped our thinking profoundly. The most valuable applications we find for AI push beyond legacy tradecraft, and concentrate on the high-volume work of collection, structuring, and presentation of data. Critically, we do not use AI to replace human judgment. The reason is not that models cannot produce reasoning, because they can, often fluently. It is that a model's account of its own reasoning cannot be relied upon as a faithful record of why it actually reached a conclusion. Auditable, attributable judgment of exactly that kind is what our architecture is built to capture from human analysts. Throughout our experimentation we have found success in a consistent division of labour: the system handles scale, the analyst supplies judgment, and the system records and surfaces that judgment rather than manufacturing it. Attempts to use AI to replace the analytic steps of the cycle risk producing analysis that sounds authoritative but cannot be held to account, and that is most dangerous when it is wrong. Any technology that amplifies human reasoning inherits its errors along with its strengths, which is why the core work of judgment must remain human and auditable.

The process changes we describe are early in their lifecycle, and the work of demonstrating them against a long track record remains ahead of us. Still, the process has taught us that significant changes to the discipline of intelligence analysis are almost certainly on the horizon, particularly as technological advances in model sophistication render traditional information-work delivery obsolete. Human analysts may defend the old ways of conducting analysis on nostalgic grounds, but the truth is that intelligence analysis conducted in this way has a poor track record of success, and disruptions which pose the opportunity for step improvements should be welcomed. These improvements should proceed from the end goal of intelligence analysis - to provide sustainable, responsible, and accurate forecasts about the future that enable decision advantage - rather than from a reactive defense of the previous normal process. To integrate AI in intelligence analysis in responsible ways requires abandoning many of the bad habits and basic assumptions that limited intelligence work in the preceding era. It also requires reconceiving the notion of the value and role of the human analyst in providing insight, and an audacity to believe that what has historically been unknowably complex can be rendered intelligible through sufficiently sophisticated modeling. One hundred years ago, humans struggled to predict the weather with any reliability; today, they expect a device in the palm of their hand to predict rain down to the minute. Similar changes are coming to the world of intelligence analysis. But they will require leaving behind the archaic tools of a previous era in order to reach their full potential.

If You Can Run a Spy, You Can Run AI

8 July 2026 at 08:41

Generative AI should be managed like a human source: useful, fast, sometimes brilliant, sometimes wrong, and never a substitute for disciplined questioning and human judgment.

The three of us spent our careers in an environment where bad information costs lives. We learned early that the most dangerous source isn’t someone who lies to you. It’s someone who tells you what you want to hear—and does it convincingly. As we watch organizations race to adopt generative AI, we keep seeing the same mistake: treating these tools like oracle machines rather than sources that need to be run.

We are not AI experts. We are not here to debate model architectures or training data. What we know is how to extract reliable insights from sources whose motivations can’t be fully verified, whose outputs may be biased or based on incomplete information, and whose reliability must be continuously earned. That is exactly the problem organizations face with AI today.

This is what HUMINT tradecraft has taught us—and what it has to teach anyone who wants to get honest, useful work from a generative AI system.

The Source Who Was Never Wrong

Early in our careers, two of us ran sources who were brilliant, well-placed, articulate, and deeply motivated. They produced detailed, confident, and consistent reporting. Senior analysts loved them. Their product sailed through review. For months, everything they said checked out—until it didn’t.

The problem wasn’t that they were lying, exactly. In both cases, they filled gaps with inference. They’d learned what we wanted to hear, and their natural intelligence and experience let them produce it fluently. The reporting wasn’t fabricated—it was confabulated. Coherent and plausible, but in key places, wrong.

We’ve all seen this pattern in the early months of AI adoption. The tool is fast. It’s articulate. It never pauses, never says “I’m not sure,” and it formats its answers with the confident authority of a briefing document. A recent Science study found that across eleven state-of-the-art AI models, sycophantic behavior—affirming users’ views even when inaccurate—was widespread and measurable. Stanford researchers found that AI systems trained on human preference feedback are systematically rewarded for being agreeable rather than correct, because agreeable outputs receive higher ratings. The models learn to please.

We’ve seen that source before. We know how the story ends.

Selection: Not All Sources Are Equal

Before you run a source, you select one. That’s a discipline in itself. And a discipline to which AI tools may in fact be able to add value in identifying and sorting stressors that can be exploited (anything that causes stress and then outlines for case officers which levers to pull on a recruitment). You don’t recruit someone simply because they have access. You also generally don't recruit happy people. You have to evaluate reliability, motivation, and susceptibility to manipulation. A source with wide access and poor judgment can be more dangerous than no source at all.

The same applies to AI. Not all AI systems are created equal for every task or mission. Each must be evaluated on access, expertise, responsiveness, and the quality of reporting—and the last criterion is harder to assess than it appears.

A few selection questions worth building into any AI adoption process:

•What is this model’s known track record on this specific type of task, not in general but specifically?

•Where does it tend to confabulate? What are its known failure modes?

•Is it current? A model with a training cutoff is like a source who’s been out of the field for a year—still useful, but with blind spots.

•How does it behave when it doesn’t know something? Does it admit it, or does it keep talking?

Choosing an AI because it’s fast or because leadership read about it in a business magazine isn’t source selection. It’s the equivalent of recruiting the first walk-in who shows up at the door.

Elicitation, Not Interrogation

One of the first lessons a new case officer learns is that interrogation and elicitation are not the same. Interrogation demands. Elicitation draws out. A blunt question produces a guarded answer. A layered conversation yields insight the source didn’t realize they were sharing.

Most people using AI are interrogating it. “What’s the answer?” “Summarize this.” “Give me options.” That approach works, up to a point, but it caps the quality of what you get.

Effective elicitation with AI means:

•Never ask a direct question when an indirect one is better. Instead of “What should we do?” try “What factors would a skeptic weigh against this recommendation?”

•Compartmentalize your tasking. Don’t dump the entire problem into a single prompt. Break it into discrete, well-scoped questions. Discrete tasking yields more verifiable output.

•Build layered follow-ups. Ask: “What are you assuming?” “What would change your conclusion?” “Give me the strongest argument against this.”

•Probe for alternatives before you settle on an answer. A source that only confirms your hypothesis may be problematic.

This turns AI from a content generator into something closer to a thinking partner. But it requires the same discipline as running a source well: preparation, precision, and the intellectual humility to recognize that your framing shapes what you get back.

The Hostile Source Problem

There is a risk the standard AI adoption literature doesn’t spend enough time on. In intelligence work, we worry not just about sources who are wrong—we worry about sources who have been co-opted or doubled, or who are feeding us what we want to hear because they’ve learned our preferences and decided that’s what keeps the relationship alive.

AI systems have structural analogs to all three failure modes:

•Sycophancy as a design artifact. Because models are trained on human preference feedback, they are incentivized to produce outputs that feel satisfying. Researchers at Carnegie Mellon and Stanford have documented an “artificial hivemind” effect in which outputs from multiple AI models converge—reducing epistemic diversity at the very moment organizations need independent judgment.

•Training data is a contamination channel. A source’s worldview is shaped by their environment. An AI model’s worldview is shaped by its training corpus. That corpus reflects the biases, omissions, and assumptions of the material it was built on. You may not know where those biases are, and the model won’t volunteer them.

•Automation bias as a user vulnerability. A series of recent studies confirms what experienced case officers know: people grant far more credibility to confident, fluent reporting than the underlying evidence warrants. Research published in 2025 found that even users with high “AI literacy” were not significantly protected against automation bias—the tendency to accept AI output without critical evaluation.

The practical implication: approach your AI system with the same structured skepticism you’d bring to a well-placed source who has given you no reason to doubt them. That’s when discipline matters most.

Debrief Discipline: The Protocol That Makes It Real

After every source meeting, a case officer writes up not only what the source said but also their assessment of reliability—what was corroborated, what was assumed, and what needs follow-up. That habit is the difference between a professional intelligence organization and a rumor factory.

Most organizations using AI lack an equivalent discipline. Someone prompts the model, takes the output, and puts it in a slide. No one records what was asked, what caveats the model offered, or whether the output was independently verified. The result is institutional memory built on unexamined reporting.

A working AI reporting protocol should mirror the post-meeting debrief:

Requirement—What question are we actually trying to answer?

Prompt—What, precisely, did we ask? (Save it.)

Output—What did the AI say?

Source check—What in this output is reliable? What is uncertain? What is unsupported?

Human judgment—What do we actually believe, independent of the AI?

Action—What will we do?

Review—What happened after we acted? Did the AI’s analysis hold up?

The review step is the one that organizations most consistently skip. But it’s where calibration happens. A source you never debrief after the fact is one whose reliability you can never actually assess.

A useful team habit before closing out any AI-assisted analysis: “Before we accept this answer, what would disconfirm it?” That question alone will catch more errors than any amount of AI governance policy.

Separating Collection from Analysis

This is a fundamental discipline in intelligence work, and it translates directly. AI is a tool for collecting and synthesizing. It can ingest, summarize, organize, and compare. What it cannot reliably do is interpret—to ask what the information means here, in this context, for this organization, with these constraints.

The error organizations make is treating AI as if it collapses the divide between collection and analysis. It doesn’t. It accelerates collection. The analytical function—applying judgment, context, institutional knowledge, and accountability—remains human.

Teams that hand over analytical responsibility to AI are not just making an efficiency error. They are making an accountability error. Someone has to own the conclusion. AI cannot.

Burning a Source: When to Stop Trusting the AI

This is the part of the tradecraft literature on AI that doesn’t exist yet, and it needs to.

Every experienced case officer has had to decide to terminate a source relationship. Not because the source was obviously lying—if that were clear, the decision would be easy. You terminate when the source's reliability has fallen below a threshold, when you have reason to believe the source has been compromised, or when the cost of continuing to run them outweighs the value of their reporting.

The equivalent decisions will come for AI systems, and organizations should prepare for them:

•When a model’s known failure modes consistently overlap with your mission-critical questions, it is time to stop relying on it for those questions—regardless of how it performs elsewhere.

•When an AI system has been demonstrably wrong in a consequential context and the organization has not developed a clear explanation for why, continuing to use it at the same level of trust is an operational error.

•When a model is updated or retrained by its provider, treat it as a new source and revalidate. Prior reliability does not transfer automatically.

•When you discover that the model has been systematically producing outputs shaped by the framing of your prompts rather than by evidence—that you have been leading the witness without realizing it—you may need to reset the relationship.

Burning a source is not a failure of the source-handling relationship. It is often the proof that the relationship was being handled well.

What This Means for How You Lead

The three of us came to this issue through intelligence work, but the problem is not limited to intelligence organizations. Any leadership environment where AI tools are proliferating faces the same structural challenge: the tools are fast, fluent, and confident, and organizational incentives often reward those who use them most rather than those who use them best.

The research bears this out. INSEAD’s 2025 analysis of firm-level AI adoption found that generative AI shifts value toward higher-order human judgment—not away from it. Microsoft’s research confirms that organizations with a well-calibrated understanding of AI perform better across missions than those that simply maximize usage. The tool is the easy part. The discipline is the hard part.

For leaders, the implications are practical:

•Build the habit of debriefing discipline before you scale AI adoption. The protocol above should be standard practice, not optional.

•Create psychological safety so people can flag AI errors. The greatest risk in any source-handling operation is the team member who saw the problem but didn’t say anything because the source had too much credibility.

•Distinguish between AI as a collection tool and as an analytical tool. Automate the former aggressively. Guard the latter carefully.

•Evaluate AI systems with the same rigor you would apply to any source—including periodic reviews of whether the relationship continues to produce reliable value.

Used with discipline, generative AI can be a genuinely powerful analytical partner—the kind of well-placed, high-access source that an experienced handler learns to work with carefully and derive real value from. Used without discipline, it becomes a certainty-destroyer—introducing noise, eroding judgment, and producing false confidence at scale.

The HUMINT model doesn’t make AI safer by limiting what it does. It makes AI safer by raising the standard for what we do with what it gives us.

AI doesn’t give you answers. It gives you reports. And reporting always requires a handler’s skeptical, trained eye.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌
❌