Recent statements from President Trump indicate he is prepared to continue, or escalate, U.S. military strikes while simultaneously signaling he is open to continued negotiations. Some would see this as a reasonable offer of carrot or stick. But, having lost scores of ships, missiles, and military production facilities, U.S. actions still depend on what Iran does. This is allowing the regime leadership to control the pace of the conflict. How is this possible?
By his own words, President Trump is admitting the United States is in full-blown reaction-mode, granting Iran effective control over the tempo of both military operations and peace negotiations. This is a mistake, born of the obvious desperation of the White House to extricate itself from the black hole that is the Iran War, and that is increasingly proving to be a drag on Republican chances in the approaching midterms.
Iran is clearly playing the provocateur, poking the bear with selective strikes on shipping daring to test their illegal claim of administrating the Strait. They are paying the price by suffering increasingly focused destruction of their offensive coastal capabilities.
This is as it should be. Iran simply cannot be allowed to impose itself on the movement of shipping through an international waterway. But… the President’s quickly aborted claim that the U.S. military should receive a 20% gratuity for its efforts to keep the Strait open has predictably only muddied the issue further.
Who’s Really in Charge in Iran and What Do They Want?
The regime clearly sees itself in the dominant position. Or, at least, in a position to bear more pain, for now, than their adversary. I believe this likely reflects their own internal political dynamics, not unlike U.S. domestic politics driving much of Trump’s actions. But with Iran, this is a more factional disunity of opinion over the best course of action vice the overly unitary decision-making process the U.S. side is suffering from. I’ve written about this before in my 25 April post; ‘The Iranian Power Struggle’: “In my years at CIA dealing with Iran and Iranians, I observed many instances of such backroom political maneuvering, including a willingness to sabotage efforts by others engaged in back-channel deals. This was particularly the case when the counterpart was America. Publicly scorned as the “Great Satan”, but secretly coveted as the superpower of choice, individuals and factions knew that whoever secured a special relationship with America would be in the pole position going forward. The attitude was “if not me, then no one!”, essentially the grownup version of ‘King of the Hill.’”
This may account for the regime’s inexplicable willingness to reject any compromise while continuing to absorb punishment; perhaps more to put pressure on their internal political rivals than to gain external military advantage. In the end, it is likely they will eventually call a halt to this by reengaging on negotiations when they determine they risk losing too much capability.
Exacerbating this, I would posit that the newly ascended Supreme Leader, Mojtaba Khamenei, may in fact be a phantom leader. Alive in some fashion, perhaps largely incapacitated, but not actually in charge. And even if able to coherently express his views, in no way nearly as powerful or influential as his father. The seemingly reckless actions of the regime in courting U.S. retaliation may in actuality reflect a lack of a coherent decision-making process as opposed to a unified one. I think it is quite possible that competing factions within the regime are using Mojtaba as an avatar while they maneuver for decisive advantage.
Regardless of which faction ultimately dominates, the implications for the United States remain how to break through to the regime’s decision-makers in the near term.
Hyperbole Weakens the U.S. Position
In the meantime, Trump’s regular stream of alternating obsequious and insulting, but always hyperbolic, ‘Truths’, the result of his obvious frustration over the regime’s unwillingness to accept what he is offering – whatever that might be at that moment - serves only to inflame and/or simply confuse an already chaotic situation. All resulting from the vaguely written and amateurish MOU that Trump himself signed.
As I wrote previously in a 12 April post, Hyperbole is Donald Trump’s love language. He continues to employ it almost daily, usually in reaction to a disappointment with the Iranian regime’s actions. And almost always to the detriment of his stated desire for peace. Unfortunately, the Iranian regime has been practicing this same language of hyperbole on an industrial scale for a generation. They understand both how to use it and counter it.
But the practice of diplomacy is a quiet profession. One that requires patience. One that requires expertise. One that requires steadiness and focus. None of which characteristics the President or his negotiators appear capable of exhibiting.
If I were to give the President a piece of advice, I would echo the words of David Ignatius in his most recent Washington Post column: “Just stop talking,” although more directly and less politely, “Just shut up and let the professionals do their job!”
What now?
I wrote about what may come next, after the permanent cessation of hostilities, in my 15 May post, Groundhog Day: “The issues facing Iran prior to the War were serious, in fact existential – a collapsing economy, hyper-inflation, severe water shortages, lack of electricity, and growing widespread popular anger and unrest – and are ongoing and only getting worse. Whatever the Iranian leadership looks like, it will have to address these issues. And it is not clear that they will be capable of doing this without outside help. This is where the U.S. and hopefully our Western allies come in: sanctions relief, and extensive economic and other assistance in exchange for real changes in policy and a pullback on objectionable activities and programs. The potential for this may, and I say may, have increased with the removal of Ali Khamenei from the Supreme Leader’s seat. But it will depend on whether his son and successor, Mojtaba, is less rigidly ideological than his father. We will see if he is willing to put the Iranian people ahead of the regime.”
Next steps
First, we need to significantly blunt the regime’s ongoing ability to project power and control the Strait of Hormuz. It needs to reopen and stay open. And it will. Both sides need it to, but not on the regime’s terms. The focused effort on degrading Iran’s coastal offensive capabilities should continue apace.
We need the regime to be forced to address the internal existential threats listed above. This is sure to absorb much of their time and money and may eventually consume them. And it may even bring them back to the negotiating table. Escalating military strikes on energy facilities and civilian infrastructure would serve only to alienate the Iranian population and distract from the Iranian leadership’s appalling incompetence, strengthening the regime. As part of this, the current MOU must be abandoned and recast in a more evenhanded manner, leading to permanent peace. Adhering to it as currently written will only ensure we will be forced to return in the future. As we are already seeing.
The current dynamic from the U.S. side is emotionally driven and self-defeating. The Iranians appear riven by paralyzing factionalism, with a hefty dose of hubris regarding their temporary advantage. Neither is a recipe for success. The question is not whether Iran can win a military confrontation with the United States. It cannot. The question is whether it can continue forcing Washington to react rather than act. For now, that answer appears to be yes.
For more reads like this, and to follow Mark on Substack, click here.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Editor’s note- Russia's war in Ukraine has fundamentally changed the character of warfare, proving that autonomous and attritable drones are no longer supporting tools but have become a decisive instrument of combat. In this provocative essay, co-authors Xen & Matthew Creedican argue that the United States must abandon legacy assumptions and adopt an entirely new military doctrine, force structure, and industrial strategy built for the age of autonomous warfare. (Xen is a former US Special Operations veteran with experience fighting alongside Ukrainian forces. We have granted his request for anonymity).
This paper is written expressly for the policy and decision makers across the military and public and private sectors who are bound to translate national strategy into reality. We will withhold for another day the arguments for convincing those who have yet to concede that the rifleman’s day is over or that drone warfare in Ukraine generalizes. Instead, we are making a series of recommendations to those already on board with direction from the Department of War (DoW) that “we are pivoting the Pentagon and industrial base to awartime footing”, as manifested in a$50B+ modernization program to ensure that “every warfighter must have access to low-cost/attritable sUAS [small drones] to conduct missions.” To help leaders meet such a steep challenge, we will describe how the force should be structured, how doctrine should be written, and how the industrial base must be re-engineered to match present scaling by our adversaries.
What a Modern Drone Force Should Look Like, For Now
If we could snap our fingers now and summon an army well-trained and well-equipped according to the latest understanding of modern drone warfare, it might be composed of battalions fielding approximately fifty to a hundred mixed-role unmanned systems deployable simultaneously, with stocks of thousands more unmanned vehicles and spare parts (antennas, ground stations) ready to replace those attrited. The force tailoring would have to include both rotary and fixed-wing drones performing reconnaissance, mothership, electronic warfare, one-way attack (OWA), bomber, and multi-role tasks. Such a battalion should be able to organically find, fix, and finish targets at ranges up to300km.
Presently in Ukraine, formations tend to specialize by range. Tactical or “infantry” battalions deploy quadcopters controlled by direct radio link or fiber optic from positions 3-10km from the absolute front, flirting with the danger zone, with the better teams now fielding glide-kit quads reaching out to 50+km, doubling their effective range from last year. Ground drone units are increasingly critical as well, performing the vast majority of evacuation and logistics within the 9-15km+ “gray zone” where manned vehicles are not worth the risk to employ. Dedicated drone battalions overwatch these units from 10-20km from no man’s land, operating typically out to 80km but at times out to 300km thanks to proliferating autonomy and redundant communications (direct, meshing, repeating, satellite, LTE, etc.). This upper end for the “mid-range” or “operational” level of warfare has also at least doubled since last year. Finally, specialized deep strike teams are now conducting strikes out tobeyond 1500km against strategic targets, with high-volume, low-cost, independent, adaptable platforms quite different from expensive legacy US drones.
At every level of the above structure, it is understood that even the non-OWA platforms must be attritable, since they rarely accomplish more than several missions without being rendered inoperable. Particularly cheap systems are evendeliberately used as decoys. And of course, seeping down into these echelons is autonomy enabled by AI, and the beginnings ofswarming protocols. It must be understood that what the aircraft carrier once did to naval gunnery is what the drone is doing to the rifleman. The fundamental unit of combat power is now the small drone team, and it is an over-the-horizon asset.
Saving Combined Arms Maneuver
Drones employed properly in such formations could execute combined arms maneuver warfare rather than the attrition warfare we currently see. After reconnoitering the enemy and making contact, unmanned battalions could use air platforms in both expendable and regenerative loitering waves to degrade air defenses, electronic warfare systems, logistics, and command structures, after which successive waves could suppress and attrite ground forces in preparation for ground drones to take, hold, and shape ground. Only then would humans move forward to effectively deepen the range of their systems. All this implies an in-depth rewriting and reapplication to unmanned warfare of manuals and doctrine guides such as FM 3-0 Operations, FM 3-90 Tactics, and FM 3-96 Brigade Combat Team. Current revisions have relegated the drone to asupporting role at best. Another example: given that a legacy US Army Corps of tens of thousands of personnel has multiple days to make decisions across approximately the same operational striking depth as that of one of the aforementioned Ukrainian drone battalions of a few hundred personnel, clearly we must revise our echeloned depths of responsibility . The existing disparity has practical consequences, as Ukrainians not only handily defeat NATO forces in joint exercises, but they do it with comparatively tiny forces, striking larger formations and assets in areas thought to be “safe”.
As such, it should be clear to those familiar with the actual contestants in programs likeDrone Dominance that we are staging to mostly procure platforms that are too expensive for the requested operational ranges. Although the DoW has set a target of roughly half a million drones per year for procurement, it will actually need at least fifty million to meet the lofty goal of training and equipping a ~500,000-1,000,000 man force with attritable systems. If we look to the rest of the world, we will see that Ukraine and Russia this year are each likely to utilize aroundtwenty million drones, while China, as the manufacturer of most of the world’s drone components, will likely build the equivalent of a hundred million drones.
Predictive Doctrine for a Moving Target
But even this, unfortunately, is not the real crux of the issue with respect to the development of future requirements. Doctrine must not only be prescriptive of the present, but also of the near future. The fact is, we cannot just snap our fingers to summon a drone army. It will take years to build it out, and by then things will look even more “sci-fi”. That is, we are chasing a moving target three to ten years out, and so we had best engage in some imagination to meet that challenge.
We are conscious of how radical this is going to sound, but our goal with such provocation is indeed to shift the Overton window, so, we believe that the future will look like something out of Ender’s Game, and it’s going to happen well before those now entering the military reach retirement eligibility.
Man, Train, and Equip for the Sci-Fi Near Future
Individual drone controllers will become tactical commanders (so let’s call them “tacticians”) remotely running squadrons of individually autonomous drones,point-and-clicking their way through a 3D interactive, AI-mediated, sensor-fusion digital twin of the battlefield. The base layer is already here in the digital panopticon emerging from cloud-native Common Operating Picture (COP) software like Ukraine’sDelta merging with military AI suites. Palantir’s Maven already suggests courses of action at the command level, and there’s no reason this couldn’t be extended down to the lowest tactical levels, controllable by voice, touch, or text. In a few more years the tacticians themselves will be inside somethingNeuralink-shaped, performing at the speed of AI-enhanced thought and striking at the links in the chain that enable adversarial tacticians. Under those conditions the adaptation cycle, too, will move at a speed that cognitively unenhanced humans cannot keep up with, and intelligence becomes the runaway comparative advantage at every level. There is no telling where such cognitive selection pressure combined with the ability to remotely control drone swarms will end. Will individual soldiers control dozens of drones simultaneously – or thousands? How many drones should a “battalion” have?
Decentralization is a factor too. Everything we are seeing develop now is scaling in Ukraine down to the individual operator, as it must. The over-the-horizon warrior needs personal access tolivestreamed tactical radar to check if the skies are clear before he exposes himself by making movement. He needs edge compute not just onboard his drones, but for local offline AI to analyze the battlefield and make decisions even in a communications blackout. Already we see backpack portable drone interceptor systems for personal defense; I’m aware of contracts under consideration for such systems to miniaturize to automated shoulder-launch, like a personal version of the tank-mounted Trophy system. The current estimate is that a soldier has one to four seconds to defend himself against a visual drone contact vectoring on him, and soon that timeline will compress enough to exceed human reaction times.
Asking what exactly the mass of conventional soldiers will do under such a radical restructuring is much like asking whether or not Large Language Models (LLMs) are going to have the net effect of creating or destroying jobs in the civilian workforce. We may see the formation of a tiny military class, or perhaps warfare will become even more industrial in human scale. Certainly, humans will be pushed farther and farther back in the logistical chain that ultimately delivers kinetic effects upon an adversary. Currently, there is a need for people to physically emplace, operate, and recover antennas, ground stations, and drones. Once robots are more commonly executing these tasks (already, some aerial drones are launched viamulti-domain mothership drones), people will work on those robots, and so forth. Eventually, it’s hard to see what anyone will need to do physically, as robots will be building, repairing, improving, and employing each other. The only real foreseeable tasks left at the tactical echelon will be those of the tactician and the true engineer, who innovates and integrates locally. Whoever best automates tasks end-to-end will win the tempo fight. The transportation of weapons and sensors has to be contemplated as one mass-manufactured logistical animal.
Going further, the tactician need not position himself relative to any front at all, because he can fly remotely and because he would be sensible to reduce his threat profile from direct action threats to intelligence-driven threats only. That is, he should position himself to strike with impunity. Already in Ukraine, Sting pilots have flown their interceptors remotely500km away from where they were launched. Midrange teams outside the gray zone already drive to position in unmarked civilian vehicles, wear their uniforms only for the minimal time needed to deploy their systems, and then fade back into the population. And the naval drones striking the Russian fleet are not generally controlled from the sea, but ultimatelyfrom bases on land. If trends hold, the smallest independent tactical elements may be able to cheaply strike anywhere on Earth within a decade.
Branching Futures: eVTOLs, Smart Dust, and Beyond
But this is merely one vision of the future. There are branching pathways, perhaps some of which may coexist. Weaponized human-optional eVTOLs like the Chinese prototypeZR-300 could become a new air cavalry paradigm unto themselves if employed en masse in shock fashion, sweeping aside whole nations in a day the way Central Asian hordes did in the Medieval period, or the way Islamist insurgents swept across the Sahel inToyotas. Microscopic drone “clouds” also known as smart dust could penetrate any conventional barrier, performing reconnaissance or even coalescing explosively or penetrating air ducts and lungs. Does this seem one step too far, straining credulity? Remember that “any sufficiently advanced technology is indistinguishable from magic” from the perspective of the old guard, and that all these technologies are already real, just not fully scaled and integrated. In fact, micro drones were feasible decades ago, technically if not economically – timing is everything. We already have a leading indicator in the German army’s very real purchase of cyborg insect swarms fromSwarm Biotactics. Against such dizzying possibilities, we will advocate further on below for a rapidly adapting structure that ingrains real-world feedback and extrapolates from it.
Economies of Scale for Drone Production
First, let’s deal with how we produce enough useful drones to simply match our adversaries. The necessary industrial base to deliver manufacturing on the required scale simply does not exist anywhere in the West currently, whereas China has quietly captured the drone market and the sub-component supply chains over decades and is integrating such technology down to their lowest tactical echelons at a hundred times our volume. Much has already been written about the need to innovate and iterate on a scale of weeks rather than decades, and while true such a need potentially comes with the steep requirement of continuous retooling of factories and endless R&D. Ironically, funding this effort at the scale needed will require a vision across a much longer (generational) timeline, in opposition to the quarterly results that drive Western business strategy. Currently, the US buys primarily the end-product rather than engendering the component markets directly. From a cost-savings standpoint, we would do well to preemptively build adaptable systems, and also to stop trying to update legacy programs (we will never need a new sniper rifle). The DoW budget has to fund the domestic mass production of production itself, with an eye towards dual-use sub-components and machine tools, since commercial R&D and production can fund itself to an extent. Vehicles, phones, and drones sold into civilian markets pay for their own scaled production, and volume buys down cost. As it stands now with our current component outsourcing, we are paying our enemies to equip us, tying the rope with which they intend to hang us.
Pillars of a Sovereign Drone Industry
The pillars of industry to be funded include locomotion, actuation, energy, storage, compute, sensing, and communications. The component-level specifics, meaning motor sizes, magnet chemistries, cell formats, and the rest, belong in a technical paper. What’s important here is that the government has to guarantee the market for base components as much as scale requirements dictate and raw materials allow, while simultaneously finding the alternatives that bypass adversarial chains entirely.
Shallow or single-sourced chains halt on the first disruption, so volume has to be distributed across multiple domestic entities in order to create redundant paths. That means accounting for the physical bottleneck of factory siting, the legal bottleneck of restrictive radio frequency and flight-test regimes, and the social bottleneck of technical workforce recruitment, which in practice means a nationwide push for engineers with the education pipelines to match. We should fixate less on the static stockpile and more on the velocity at which the economy can replace a lost or outdated asset. Eventually, this may look like self-assembling factories, but for now we should see a dramatic increase in industrial jobs, not a reduction.
Guaranteed Requirements and Manufacturer Caps
The Departments of War and Commerce must jointly establish requirements and guarantee purchase of components at massive volumes, over multi-year timescales, according to stringent standards for minimum viable products meeting or exceeding foreign equivalents, with caps set on what portion of the total any one manufacturer can source. Subcontracting and manufacturer caps will encourage competition inside our own secure ecosystem rather than across national borders, where we are frequently undercut by adversaries. As needed, the government can resell unused inventory back to industry at or below the cost of subsidized foreign imports, letting American companies build with cheap secure inputs.
We have a realistic precedent for all this, as described in the book Freedom’s Forge: In anticipation of US entry into WW2, President Roosevelt brought together former of heads of industry in order to align military requirements, government funding, and civilian production capacity so that goals could be revised upward continuously, and the resulting volume forced a dynamic of subcontracting to keep up with demand. American industry responded, not only producing hundreds of thousands of complex war machines, but also rapidly retrofitting them as needed based on frontline feedback, on much the same timescales that we today see in Ukraine.
Innovation on the Machine Timescale
In the near future, however, we will have to go even further, with innovation necessarily occurring on the machine timescale. The same digital twin in which soldiers will virtually train and fight will also let us simulate hardware, factories, and logistics before steel is ever cut. The panopticon in which the end product’s edge sensors feed data into will be the same in which an arbitrary number of tests under variable conditions may be run before the more refined next generation of product is built. Supply chains from base-component assembly through fuel and battery pathways can be estimated and stressed the same way. Data streams from around the globe and from local instrumentation can all compartmentalize or cohere as needed for efficiency or breadth of understanding, all of it parseable by ever-increasing machine intelligence, at worst bounded in growth only by Moore’s Law. As an aside regarding encouraging a martial culture amongst the youth who will one day fill the tactician ranks, our military should release realtime strategy wargames involving drone swarming, initially as standalone games but eventually living inside the kind of digital twin explained above. And as earlier mentioned, all of this will eventually be experienced in breathtaking detail in virtual reality and via brain-machine interface. This is not so distasteful a task on a wartime footing, especially considering even in peacetime the military has releasedfirst-person shooter games and simulations.
Massive integrated training areas, in which units, contractors, and manufacturers co-locate to live-fire and iterate together, belong on the near-term build list. The mandate inside such an area should be inverted from current practice, so that the burden shifts from justifying permission for a given action to justifying why any given action cannot happen. The FAA, the FCC, and the rest of the regulatory apparatus should be effectively kicked out of the perimeter, and legislation should extend a good-faith liability shield covering crashes and honest mistakes. Dedicated integration units, which can be thought of asTransition in Contact supercharged, should be created. The core skill of these new units would not be warfighting but rather adapting to and assembling whatever technology is available. Every unit, not just dedicated ones, should additionally have at least some innovation budget and personnel, so that they are not merely customers but also integrators. Specifically, this means the military needs to be mass recruiting engineers to fill out dedicated innovation units and also sprinkle across the wider force. And lastly, the soldiers who will become the drone tacticians must be allowed to train for that role full-time, studying meteorology, radio theory, and other topics and skills currently regarded as arcane among warfighters.
A Permanent Feedback Loop from the Front
None of the above works without a permanent structured feedback loop that connects requirements to what is actually happening in a live conflict. Local units cannot generate requirements for now let alone five years out if there is no frontline feedback, no rotating instructor cycle, and no living link to platforms that do not yet exist in Western inventories. A peacetime force generating peacetime requirements will buy peacetime equipment no matter how decentralized the process is. Instead, we need a much greater scale of personnel who are aggressively forward deployed to conflict zones, visiting tactical operations centers and doing ridealongs on relatively low-risk mid- and deep-strike operations. Our partners will gladly place them there if they provide as much as they take. Directly in this role we can put our incredible all-volunteer special operators, who want nothing more than to get close to the fire. Adjacent to it, in lower intensity areas, we can forward deploy conventional troops as well to learn from partners, including by attending their own schoolhouses.
What we are suggesting here is deploying thousands of troops, not merely small cells of elite military and intelligence agency operators whose reporting does not reach the wider military. Much like the technical innovation measures described in the previous paragraph, these warriors should be distributed both into new dedicated units for the express purpose of doctrine, tactics, techniques, and procedures innovation, as well as across the wider force, to supercharge change and acquire what Clausewitz called a “fingertip feel” for the present state of war. If there is really no political appetite for this, then the only other option is to accomplish the same via other methods, such as by inviting large numbers of military instructors from partner nations currently involved in active conflict or by rotating civilian contractors more discreetly through conflict areas, as suggested by former Green BeretBryan Pickens.
Piping Frontline Signal Directly to Doctrine Writers
Regardless of how it is done, the core part of whatever structure is created should report directly to the senior military leadership responsible for the development of force-wide doctrine and requirements, so that they cannot ignore reality and hide in dead paradigms. Various new offices are being created, such asDRPM-UxS, and our hope is that with direct signal they can utilize sweeping - even disruptive - authorities to continually remake the military; for, as Napoleon said, “unhappy the general who comes on the field of battle with a system”. Given the enemy’s endless adaptation, the best meta-doctrine is to accept no particular doctrine as certain or permanent, and even to assume that it is likely wrong if it has not been overhauled lately. Official doctrine documents would be better written and accessed as living Google docs rather than year-dated static PDFs.
This applies down to the nitty-gritty of institutional knowledge as well. The train-the-trainer model informed by forward-deployed reporting must fuel change in our own programs of instruction and battle drills, so that we actually know how to employ the unmanned weapon systems we are scaling, a capability which further feeds into local units understanding the requirements for the next round of equipment purchases.
A sharedrive with compartmentalized access is not enough; we need our whole force separated at most by just one degree from someone who has seen modern war up close. And if the military is that close to the combat demand signal, then by extension the manufacturers who visit the units they are equipping will be that much closer.
The Transition Engine and Treating Ukraine as a Peer
Joseph Gagnard of Atlas Special Projects calls the sum total of all these joint efforts the “transition engine”, meaning operators, builders, contracting specialists, and investors institutionalized together, because no single one of them fields capability alone. That transition engine has to be paired with a treatment of Ukraine that most of the current western defense industry still resists. Treat the Ukrainians peer to peer, at least as well as Taiwan or South Korea, and better than either, because they are in an existential fight we cannot afford for them to lose. I suggest bringing thousands of Ukrainian engineers, managers, and operators into the United States to help build the drone industry. Regarding AI, America holds the architecture, the compute capacity, the models, and the global reach. But Ukraine holds the live-fire scaffolding for how that data actually gets generated, labeled, fused, and fed back into the iteration cycle; they have the premier Common Operating Picture software,Delta, to facilitate collection; and they are best positioned to evaluate the battlefield effectiveness of each successive generation of combat AI.
Furthermore, Ukraine is waging a global hybrid war on the West’s behalf, which we hardly engage in except via the most deniable means. China, Russia, and their proxies and allies ruthlessly exploit neutral ground with a vast array of tools, strangling us of resources, allies, and positioning. As political will allows, we suggest unleashing our special operators and intelligence officers in nearly-overt ways, in partnership with Ukrainians, who willingly perform more risky action and have a history of cooperation with our intel services, to operate across the globe responding in kind to theAxis arrayed against us. Drones, of course, are the perfect semi-deniable weapon for this. And the signal we receive back by more heavily involving our forces in low-intensity conflicts will feed back into the plan regarding getting a “fingertip feel” back for war.
The Vulnerable Homefront
The homefront, meanwhile, is ripe for a crippling preemptive strike against us. Our infrastructure is vulnerable, and drones as stated are a perfect scalable weapon that can be employed by deniable proxies. A strike could produce economically disastrous effects, and in response to such an attack of ostensibly deniable origin and limited death toll we would certainly not seek to launch, say, a nuclear retaliatory strike. Containerized long-range drones could be lurking on civilian ships off our coast right now. DHS testified to the Senate that in 2025 there were an average of 10,000 foreign drone flights per month near the southern border. Particularly at risk to such a looming threat is our AI infrastructure. Whatever one’s thoughts on the supposed “AI bubble” (the dot-com bubble didn’t stop the triumphant march of internet adoption, did it?), it is undeniable that both the previous and current administrations have regarded the AI race as existential, and our enemies clearly feel the same way.
We saw from arecent strike by Iran on data centers in the UAE providing Amazon Web Services that such centers are vulnerable, going down for several months at a minimum due to spreading fires and long lead time for repair parts. A few hundred drones striking data centers or upstream links in the chain could easily set us back in the AI race which could provide our adversary an opportunity to surge permanently ahead, a situation which, again, our bipartisan leadership regards as an existential threat.
A Decentralized, Always-On CONUS Defense
The right posture for CONUS defense is one that is always on and autonomous-capable, able to intercept without waiting for the chain of command. In addition, such efforts must take the form of a whole-nation decentralized effort. In Ukraine, a nationwide cheap network of mobile phones acoustically tracks hostile long-range drones swarming their country, and recent legislation approved the use of electronic warfare and interceptor drones by businesses to protect their own assets. New manufacturing and power facilities tend to be built in a distributed, resilient, redundant manner, with cheap hardening available for obvious targets (like anti-drone “cages”). Our recommendation, like elsewhere, is to empower everything local. We would even go so far as to suggest that the Second Amendment needs to extend to counter-drone equipment, and any U.S. person or institution should be able to engage perceived threats up to certain altitudes above their own land.
AI as Sovereign Terrain
We can extend the Second Amendment and drones argument to the First Amendment and AI; that is, to digital and not just physical terrain. Across the information domain, China steals from us and undercuts us, releasing open LLMs to erase Western software margins. Intellectual property in this context is a burden more than a benefit by now, perhaps functioning somewhat to promote internal competition but leaving us wide open for external exploitation. The best way to stay ahead of our enemy in the face of their undermining of our brittle centralized systems is to fight fire with fire. We need policy and funding to shy away from the current big LLM players and instead encourage open models, local compute, and data sovereignty, which offer numerous long-term advantages across the board that mirror the kind of resiliency and initiative-encouraging effects we will get by distributing compute and AI models down to the lowest levels of our military.
Encryption code, for example, was previously ruled to fall under free speech protections. There is an argument against allowing centralizing and censorship of digital spaces as well, regarding them as a kind of common space since there is a barrier to entry in networking at the level of Internet Service Provider infrastructure. We need a diverse market of competing open AI models, local compute, social networks, etc. A centralized internet and centralized AI have severe risks within the domains of psychological and information warfare, which play out across the public digital arena, but to go further in that discussion we would have to depart from the scope of the kinetic warfare focus of this article. Suffice to say, the most dystopian and existentially risky outcomes are plausible if centralized AI should win, whether by our own hand or the hand of the enemy, who will surely centralize control over their models as soon as they gain an advantage.
Deterrence via Force Projection
Another point worth addressing when discussing CONUS defense is the idea that“the bomber always gets through”, which is probably true regarding drone swarms. However, regarding the homefront, Ukraine has shown first that the effects of long-range drone attacks can at least be mitigated significantly, and that it is economically optimal to do so. Furthermore, the striking arm we are also building alongside the defenses will serve as a deterrent, since nuclear doctrine of Mutually Assured Destruction is insufficient for the aforementioned reasons. If we can threaten to do unto our enemies as they wish to do unto us, and indeed if we actually regularly exercise this capacity in the global low-intensity ongoing war, then we will make them think twice before hitting us.
The Core Principle: Endless Distributed Adaptation Capacity
The single principle of this piece is this- Stop buying end products and start buying the ability to produce them, at scale, sovereignly, and forever – doctrine here being one of those end products. The victor that emerges from the next several years will have built the meaningfully decentralized version of what we have described here, meaning distributed compute, sensors, swarms, command, cognition, industry, and authority, with the standards and alliances to match. The rallying cry, in the end, is the architecture. In the last great war, we firebombed cities, preemptively invaded neutral countries, and of course ultimately resorted to nuclear weapons. The political license for a national revitalization as a form of deterrence seems, by comparison, an easy pill to swallow.
Note from author (Xen)- For those who wish to understand not merely the how but the why, or who have comments, or who desire greater breadth or depth of understanding: Over the coming weeks I will be sharing additional information to my personalSubstack andwebsite. As for my co-author, Matthew A. Creedican, you can find him onLinkedIn.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
“This is not at all a strategy-driven [FY 2027 defense] budget. This is a budget-driven budget. If you look at the Truth Social posts by the President [Trump] and the statements of the people around him, he [President Trump] makes very clear that this budget was driven by a budget number, a budget target, an arbitrary level that was set based on five percent of last year's GDP…They set this arbitrary level and then at relatively the last minute in the budget development process the [Defense] Department was told come up with a request that gets you to this number, this $1.5 trillion number. And so they did.”
That was Todd Harrison of the American Enterprise Institute and one of the nation's top experts on defense strategy and the defense budget, speaking last Tuesday at the Brookings Institution as part of a panel on The FY 2027 defense budget: How much is enough?
Remember, as I wrote last week, the Trump FY 2027 defense request is for $1.15 trillion with another $350 billion request to be placed in a FY 2026 reconciliation package; and there now also is the new FY 2026 supplemental request, which has another $67 billion for the Defense Department.
House members have been weighing all the defense numbers and this week may be voting on a FY 2026 reconciliation package of $95 billion with only $73 billion for defense – far less than what was being sought.
Last Tuesday, Harrison went on to explain what may have been going on: “I say it is absolutely not a strategy-driven [FY 2027 defense] budget because they didn't have to make hard choices. They made some easy choices.”
As an example, Harrison said, “Do you want, you know, a fourth generation fighter jet? Buy some new fourth generation [F-15s]; or do we want to continue buying the fifth-generation fighters like the F-35 we have in production; or do we want to invest in sixth generation fighters? Do all of them, right? You can do all three at once, if you have a virtually unlimited budget, you don't have to make those hard tradeoffs.”
And, in fact, all three are included in the proposed FY2027 defense budget.
But Harrison goes on to suggest another way to view this Trump defense budget giant increase saying, “There's still a limit to how much the department can consume in terms of this funding…because I don't think they [the Trump budgeteers] actually intend this to be like a one-year budget authority number, especially with the reconciliation [set at $350 billion]. I think it is actually more like a five-year budget number that they're trying to get pre-funded up front, but they actually plan to spend it at a slower pace over the next five years.”
Harrison also looked at “the parts that I think absolutely don't belong in here are these big pots of money they created in defense-wide accounts that have very little description with them.”
For example, he picked out “$54 billion in the Defense Autonomous Warfare Group (DAWG) line item. That is a single program element that's got $54 billion in it,” Harrison said. “That's unprecedented. If you read the budget description with it, it gives very little detail. You know, it's [clears throat] supposed to be investments in drones and things like that, but like tell us
quantities, tell us specific types of drones, like tell us what you're going to be using it for, and that detail is not there.”
Harrison went on, “It appears they haven't figured that out yet, so I think $54 billion is quite a reach, trying to ask for that much money for something that has not yet been well defined. So, I think that there are areas here where they've really overshot and they've tried to just throw everything in there and ask for a super high number. And I wonder if they almost expect that they're not going to get that full number -- that Congress will cut them back down quite a bit. But they were just trying to reach that overall $1.5 trillion level.”
As Yahoo Finance pointed out earlier this month, the $54 billion for DAWG sought for FY 2027 is 243 times greater than what DAWG got this year, and “now exceeds the entire Marine Corps budget request of $52.8 billion and represents nearly 15% of the entire $350 billion reconciliation package.”
Harrison’s view: “You get to the endgame, Congress is going to have to sort through this and say, ‘Okay, what are the what things in here are serious things that really do need to get funded one way or the other, and we'll have to figure out how to make that happen, and what are the other things that were just budget gimmicks or just filler?’"
Harrison was not the only expert on last Tuesday’s Brookings panel.
Joining him were David Wessel, who runs Brookings’ tax and fiscal policy in the economic studies program; and Mara Karlin, professor at John's Hopkins University’s School of Advanced International Studies, who has worked for six Defense Secretaries over her career.
Wessel took a broader financial view saying, “The President is proposing a big defense budget at a time when we have unsustainable fiscal trajectory, and so I think that raises an important question and that question is…budgeting is about tradeoffs and the President and Congress at the moment seem to be avoiding trade-offs. There are ways we could offset if defense spending is really important. We should think about ways to pay for some of it either by cutting some other places in defense or raising taxes. And there's some ideas floating around on that, but none of them are politically popular.”
Wessel also raised two other issues: “I think it also requires some trust on the part of the public that the money is being well spent and that relies on Congress doing oversight. And secondly, that we are sticking with a military that is nonpartisan and follows the leadership of the President and the Congress, but is not totally politicized. And I'm afraid that the trust in the military is being eroded by some of the personnel decisions that Secretary of Defense Pete Hegseth is making. And I think that's a problem.”
As for Karlin, she referred to the Trump national strategy and focused on what she called “a break with the bipartisanship that has characterized how folks have thought about these threats for a long time.”
Karlin noted, “The real emphasis of this [Trump national] strategy is on the Western Hemisphere, right? The real threat is seen in this strategy as these alleged narco-terrorists as they're so named…So, that's the priority.”
But, she adds, “You then see China mentioned, but in a pretty circumscribed way, just the first island chain. And in general, the language reads a lot softer than almost any recent defense strategy. You see a desire to downgrade involvement in European affairs, a little bit of mention of the Middle East, but in no way signaling that we would be starting this massive [Iran] conflict. And so here's where I think, there's some confusion worth highlighting because traditionally a national defense strategy is a decoder ring. It's going to tell you where the Secretary of Defense will put their energy and attention.”
“When we look at this budget, this very large budget, that's really at kind of World War levels,” Karlin said, “and frankly, the number [$1.5 trillion] isn't really merited by the strategy.”
She explained, “If one were really to just prioritize the Western Hemisphere and this quite circumcised focus on China as a major threat, and not be involved in most other regions of the world, in fact, the Trump administration could have put out a quite tiny defense budget request. So I leave you with a bit of perplexity.”
Two more things Harrison mentioned need recording.
“I forgot to address the [Trump] battleship issue,” Harrison said at one point, “because you know that's in here and far from defending it, I think that's one of those examples of things that got thrown in because they didn't have to make tough choices.”
Then he explained, “No one in the Navy can say with a straight face that we're going to go from starting a brand-new, clean-ship design in FY 2027, to procuring the lead-class [battle]ship in FY 2028, to going to all the way by FY 2031 being at full rate production, ready to buy them at one per year. That doesn't pass the laugh test…And so are we just setting ourselves up to spend a few billion dollars chasing, you know, this weird idea before we eventually have to cancel it and then things go back to the way they were before.”
Finally, Harrison said, “I think there needs to be some fundamental look on the congressional side at just how do we reform the budget process to get it working again; open the aperture to things like changing the start date of the fiscal year [which now begins October 1], re-jiggering the committee structure.”
I believe Harrison is questioning why each year the Armed Services Committees in both the House and Senate each authorize spending programs, and then the House and Senate Appropriations Committees set the actual dollar-level of funds made available for that year.
“You know,” Harrison said, “I'm talking a lot of third rails here, but I think we're at that kind of point like we were in the early 1970s where Congress realized it [the budgeting process] just wasn't working. I think that they need to do some serious inward-looking reform like that.”
I agree, having twice worked on the Senate Foreign Relations Committee in the 1960s, and followed defense spending over the past 60 years. Harrison is right – the Legislative Branch system for passing Executive Branch funding needs to be repaired.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
America’s battlefield dominance remains unmatched, but Iraq, Afghanistan and now Iran shows that tactical success increasingly fails when military power is not matched by a coherent political strategy.
No military in modern history has possessed the technological reach, global mobility and combat capability of the United States. Yet, its greatest battlefield victories have increasingly produced some of its most difficult strategic dilemmas.
This contradiction lies at the heart of American military intervention over the past several decades. Washington has repeatedly demonstrated its capacity to defeat formidable opponents, overthrow governments and deploy troops across vast distances. But military supremacy has not always produced the stability, legitimacy or political order American policymakers sought.
Afghanistan revealed the limits of occupation and state-building, ending not in lasting transformation but in the return of the Taliban in 2021 after their initial ouster by American forces twenty years earlier. Iraq showed how removing a hostile regime could unintentionally strengthen Iran’s strategic position and deepen regional instability. Iran itself has proven resilient, with external pressure often hardening rather than weakening its strategic posture. Meanwhile, the Arabian Gulf has become an unpredictable region, where security, energy and great-power rivalry intersect with global consequences.
These cases raise a central question: why do tactical victories so often produce strategic setbacks?
The answer lies in the changing character of ‘limited war,’ in which military superiority remains decisive on the battlefield, but political endurance increasingly determines strategic outcomes.
The Post-War Pattern: Tactical Success, Strategic Frustration
The paradox at the heart of American military intervention is neither new nor uniquely American.
Since the end of the Second World War, the United States has repeatedly demonstrated an unparalleled ability to project power globally. From Korea and Vietnam to the Gulf War, Afghanistan, and Iraq, no nation has matched America’s technological sophistication, logistical reach, intelligence capabilities, or ability to sustain expeditionary operations over long distances. This record is well documented in studies published by the RAND Corporation and the U.S. Army War College Press.
Yet history demonstrates that battlefield dominance alone does not guarantee political success.
The Korean War (1950-53) ended in containment rather than reunification, while Vietnam (1965-75) exposed the limitations of overwhelming firepower against an adversary willing to absorb enormous losses in pursuit of political objectives. The Coalition victory in the 1991 Gulf War reinforced the belief that precision-guided weapons, advanced command-and-control systems, and overwhelming technological superiority had fundamentally transformed warfare.
Following the collapse of the Soviet Union (1991), many policymakers concluded that American military superiority could reshape political realities well beyond the battlefield. Historical assessments by the U.S. Department of State Office of the Historian and the U.S. Army Center of Military History trace the evolution of these campaigns and their strategic consequences.
While military force remains highly effective at defeating conventional armies, destroying infrastructure, and removing governments. It has proven considerably less effective at building legitimate political institutions that can endure after foreign forces depart. As Carl von Clausewitz argued in his classic work, On War, war is an extension of politics by other means. Military victory therefore achieves little if political objectives remain undefined, unrealistic, or ultimately unattainable.
The challenge confronting modern intervention is not one of military capability but of strategic translation. Tactical victories increasingly fail to produce durable political outcomes because the post-intervention political environment is often more complex than the military campaign itself. As scholars of strategy, such as Lawrence Freedman, and the research communities at the Center for Strategic and International Studies (CSIS) and Royal United Services Institute (RUSI) have argued, the decisive challenge for modern military power is no longer winning the battle but securing a sustainable political end state.
Iraq: Breaking the Anti-Iran Bulwark
The invasion of Iraq in 2003 removed Saddam Hussein from power but also eliminated Iran’s principal regional counterweight.
What Washington saw as a decisive blow against a hostile regime became, in strategic terms, a gift to Tehran.
The collapse of Iraqi state institutions created a vacuum filled by sectarian competition, militia politics, and external influence. As Iraqi institutions weakened and political fragmentation deepened, sectarian identities grew more powerful, armed groups gained legitimacy, and the state’s monopoly on force eroded.
Iranian influence expanded through political allies, security networks, and Shia militias that embedded themselves in Iraq’s evolving political, post-Saddam order.
In an ironic twist, the U.S. intervention in Iraq was meant to reduce internal danger and violence; instead, it fostered a more favourable environment for Iran and the country’s political influence.
The United States spent enormous blood and treasure removing a regime that had contained Iran for decades. In seeking to eliminate one threat, Washington disrupted the regional balance and inadvertently strengthened another. Historically, Iraq stands not only as an example of a military campaign governed by ‘shock and awe,’ but remains a stark warning about the unintended consequences of overthrowing a state without understanding what will replace it.
The occupation of Iraq damaged U.S. credibility in the Middle East by disrupting power balances without a clear post-war strategy.
It increased uncertainty among allies, created opportunities for rivals, and enabled Iran to expand its influence, reshaping the strategic landscape and contributing to greater instability.
Afghanistan: The Limits of Military Occupation
Nowhere is this paradox of modern limited war intervention more apparent than in Afghanistan.
The United States and its allies rapidly dismantled Taliban rule following the attacks of 11 September 2001. Within months, al-Qaeda’s sanctuary had been destroyed, Taliban formations dispersed, and a new Afghan government established under international protection. Militarily, the campaign was remarkably successful. Contemporary assessments of the campaign and its objectives are documented by the U.S. Department of State Office of the Historian and the CFR.
The challenge emerged only after the battlefield had been won.
Over the next two decades, Coalition forces invested enormous resources attempting to build functioning political institutions, professional security forces, and a democratic state capable of sustaining itself. Yet legitimacy proved far more difficult to establish and sustain than military capability. Extensive investigations by the Special Inspector General for Afghanistan Reconstruction (SIGAR) repeatedly highlighted the disconnect between military achievements, governance reform, corruption, and institutional resilience.
Corruption, weak governance, factional politics, and ongoing insurgent pressure steadily eroded public confidence in Kabul’s authority. The human, financial and strategic costs of the intervention have been comprehensively documented by the Brown University Costs of War Project.
The Taliban understood a fundamental principle of limited war: they did not need to defeat NATO militarily, only to outlast the West’s commitment to supporting Kabul.
As domestic political support in Coalition capitals diminished, strategic patience shifted in favour of the Taliban-led insurgency. The collapse of the Afghan government in 2021 demonstrated that two decades of military success could not compensate for the absence of enduring political legitimacy. Subsequent analyses by the CFR and the SIGAR conclude that institutional fragility ultimately proved more decisive than Coalition military capability.
Afghanistan, therefore, offers a broader lesson. In modern limited wars, technologically superior powers often discover that destroying hostile forces is considerably easier than replacing the political order those forces once sustained.
The lesson from Afghanistan is not unique.
In modern conflicts, technologically advanced militaries increasingly find that battlefield success is becoming decoupled from political outcomes. This reflects a broader evolution in limited war, where endurance, legitimacy and the capacity to impose continuing costs frequently outweigh conventional military superiority.
Recent assessments by the RUSI, the CSIS and the Modern War Institute at West Point (MWI) increasingly argue that political resilience and strategic endurance have become as important as battlefield dominance in determining the outcomes of contemporary conflicts.
Conclusion: Rethinking Military Success
There is an old regional saying that, rather than killing the snake, repeated attempts to strike it often make it more dangerous.
The 2026 Iran War is the starkest test of that proposition in a generation.
The US-Israeli military campaign that began on 28 February inflicted severe damage on Iran’s nuclear and missile infrastructure and, according to multiple reports, killed Supreme Leader Ali Khamenei. Judged by the metrics Washington and Jerusalem set—degrading capability and decapitating leadership—the campaign appeared to succeed.
Yet strategic outcomes are far less straightforward.
Reporting from Reuters, the BBC, and other outlets indicated that despite the shock of the strikes, the Iranian system moved quickly to preserve continuity. The Revolutionary Guard and other coercive institutions positioned themselves as defenders of a nation under attack. This pattern aligns with longstanding scholarship on external pressure and authoritarian resilience, which shows that coercion may consolidate regimes as easily as it weakens them. Iran’s economy was battered, its proxies pressured, and its deterrent credibility damaged, but the outcome Washington most wanted to prevent—regime survival—persisted.
This is not a defence of the regime, nor an argument that the strikes were unjustified.
Rather, it is an argument that force applied without a coherent theory of political aftermath can entrench the very resilience it seeks to break.
Iran has been hit hard, but it has also adapted, hardened, and become more difficult to read strategically. That unpredictability does not stop at Iran's borders; it radiates outward, especially across the waterway connecting Iran to global markets.
The lesson from Iraq, Afghanistan, and Iran is not that military intervention should never occur, nor that the United States should retreat from its global responsibilities.
Instead, the character of limited war is evolving in ways that increasingly favour politically resilient adversaries over technologically superior expeditionary powers.
This shift has become a recurring theme in contemporary strategic analysis published by the RUSI, the CSIS, and the MWI.
Cheap autonomous systems have fundamentally altered the economics of military power.
During the Cold War, technological superiority rested upon expensive platforms fielded by a handful of industrialised states. Today, relatively inexpensive drones, AI-enabled targeting systems and commercial technologies have dramatically lowered the barriers to resistance, enabling weaker actors to impose disproportionate costs upon militarily superior opponents.
Meanwhile, democratic powers continue to operate under political constraints imposed by public opinion, electoral cycles, international law, alliance commitments, and coalition management.
Their adversaries often face far fewer such limitations.
Victory is therefore no longer determined solely by military technology, but increasingly by which political system can sustain the contest for longer.
This observation reflects the enduring insights of Carl von Clausewitz and later strategic thinkers such as Robert Endicott Osgood, whose work Limited War: The Challenge to American Strategy (1957) emphasised the intimate relationship between military operations and political objectives.
The United States remains the world’s most capable military power.
Nothing in Iraq, Afghanistan, and now Iran diminishes that reality. These conflicts, however, reveal that military superiority alone no longer guarantees strategic success.
The ability to destroy an adversary’s military capability is no longer synonymous with the ability to shape the political environment that follows. As recent analyses by the International Institute for Strategic Studies (IISS) and RUSI continue to argue, the decisive challenge for modern armed forces increasingly lies in translating battlefield success into enduring political outcomes.
The challenge for American policymakers is therefore not simply how to strike harder or faster, but how to ensure that military action serves coherent political objectives capable of enduring long after the shooting stops.
Great powers rarely decline because they lose battles.
More often, they decline because they mistake military victory for strategic success.
Military technology can destroy armies. It cannot, by itself, create political legitimacy.
Until strategy gives equal weight to what happens after the battlefield falls silent, even the most technologically advanced militaries will continue to confuse tactical victory with strategic success.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
The Department of War has just executed the most ambitious acquisition reform in six decades. It scrapped JCIDS — the requirements process that ossified innovation for a generation; replaced program offices with portfolio executives, and built a Warfighting Acquisition System designed for speed.
The changes deliver on years of reform proposals. They also risk repeating a costly mistake of the post-9/11 wars: chasing evolving threats with rapid fixes while no one is responsible for understanding them. Industry will help determine which path prevails.
Counter-drone fight as test case. We’ve seen this movie before
Consider the counter-drone fight, the clearest test of the new system. Washington treats it as an engineering puzzle: build a better jammer, field a cheaper interceptor. The technology shelf is full — directed-energy weapons at $12 a shot, drone-on-drone interceptors with more than a thousand kills in Ukraine.
While the technology works, the process for getting it to the warfighter does not.
Soldiers today engage FPV drones that cost a few hundred dollars with $400,000 Stinger missiles, because the cheap interceptors proven in Ukraine still have no fast path into U.S. formations. A new drone variant appears on the battlefield every week, built from commercial parts and open-source software. A firmware update that defeats a jammer costs nothing and takes hours. Our counter, even through the reformed system, takes months.
This is not a technology gap. It is a cycle-time gap. And I have seen it before. From 2010 to 2013, I led the Army’s Rapid Equipping Force at the height of the counter-IED campaign in Afghanistan. The structural parallels are exact: cheap dual-use components, knowledge that spreads faster than countermeasures, adaptation at near-zero cost, tactical variation that defeats one-size-fits-all solutions, and an institutional reflex to throw technology at a systems problem. We spent $75 billion on counter-IED and lost that fight anyway. Drones are IEDs that fly.
The part nobody owns
Here is what the reforms miss: Successful innovation runs in six phases — detect, define, develop, deploy, assess, distribute. The reforms invested almost entirely in the middle two, develop and deploy. Nobody persistently monitors how the threat evolves at the tactical edge. Nobody scopes each unit’s problem with enough precision to drive useful solutions. Nobody measures whether fielded systems actually work against an adversary who adapts after every engagement. And nobody moves what one unit learns to every other unit facing the same threat at operational speed. Three of the six phases have no organizational owner.
The department built a faster engine. Nobody built the steering — the mechanism that decides which problems the engine should be pointed at, whether the solutions worked, and who else needs to know.
Industry’s new role
That gap is the industry's opportunity — and its obligation. The DoW can’t solve this problem by itself. Companies that want to matter in this market need to do their part. They should start by doing three things differently.
First, invest in problem discovery, not product pitches. Requirements still originate in headquarters, not from soldiers watching the problem in context. The companies that win the next decade will be the ones that put engineers and business developers forward with operational units to understand problems before proposing solutions. The quality of your solution is determined by the quality of the problem you choose to solve. Einstein’s formula applies: 55 minutes on the problem, five on the solution. Most of industry has that ratio inverted.
Second, build for adaptation, not for the requirement. If your product cannot change in weeks — modular hardware, software-defined behavior, upgrades at firmware speed — it is obsolete on delivery. The adversary’s development cycle runs in days. A requirement frozen at contract award is a snapshot of a threat that no longer exists.
Third, plug into the new portfolio structure as a sensor, not just a supplier. Industry keeps asking the department for a clearer demand signal, and fairly so. But the demand signal has to come from somewhere, and the fusion cells that Portfolio Acquisition Executives need — nodes that merge ground truth from the field with what industry and the labs know is possible — cannot function without industry feeding data in and absorbing assessment data out. Companies that operate at that tempo will define the portfolios. Companies that wait for RFPs will trail them.
Doing these three things means stopping three others. Stop building to frozen requirements and calling it responsiveness. Stop treating a prototype contract or a demo-day win as the finish line — it is the starting line of the assessment the department never runs. And stop spending capture budgets decoding what headquarters wants instead of discovering what the warfighter needs. The hours are the same; the direction is not.
New authorities need new operators
None of this works without people, and people are where the reform agenda is thinnest. The department is converting the Defense Acquisition University into a Warfighting Acquisition University, trading compliance training for scenario-based judgment. That is the right instinct. But this year’s defense authorization offered little else on workforce, which means the authorities changed faster than the people who must wield them.
We know what works: experiential, problem-first education. Hacking for Defense has spent a decade putting university students to work on real national security problems alongside the people who own them. It has produced a generation of founders and public servants who know how to interrogate a problem before building a solution. That model needs to scale — into the department’s schoolhouses, into two-way exchanges between government and industry, and into industry’s own training pipelines, which today produce engineers who have never seen the field and capture teams fluent in the FAR but not in the mission.
The department has reformed how it acquires. It has not yet reformed what it acquires, whether it worked, or who else needs to know. Industry can wait – and hope – the government will close that gap, or it can help close it — by discovering problems & opportunities at the edge, building for adaptation, and educating a workforce trained to out-cycle an adversary rather than out-comply a regulation.
In this fight, the adversary does not need to out-technology us. He only needs to out-cycle us. We have already paid $75 billion to learn where that leads.
Pete Newell is a retired U.S. Army colonel, former director of the Army’s Rapid Equipping Force, and CEO of BMNT. He co-created Hacking for Defense with Steve Blank and is the author of “The Innovation Targeting Cycle.”
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Tell the Russian people about the carnage in Russia’s war with Ukraine. Tell them about the Russian lives lost and the crushing financial cost of a five-year invasion of a sovereign nation. Former President Ronald Reagan ensured that he got information into the former Soviet Union to truthfully speak to the people about their government’s lies about the cost – in lives and money – of their war in Afghanistan. After ten years, in 1989, the Soviets withdrew from Afghanistan, the final chapter in the Cold War.
Russia’s Vladimi Putin seemingly doesn’t care about the Russian lives lost or the crushing financial cost of a five-year invasion of Ukraine. Over 1.4 million Russian casualties (killed, wounded, missing, or captured), and over 500,000 killed at a cost of over $500 billion. Are the people in Russia aware of the magnitude of this tragedy? Are they aware of Mr. Putin’s view that Ukraine has no right to exist and he is justified in invading a sovereign Ukraine that gave up its nuclear weapons for security assurances?
Indeed, Ukraine’s casualties are over 600,000, with close to 140,000 killed, including 16,000 civilians. The cost so far is close to $600 billion, with a price tag of $U.S. 1 trillion to reconstruct a devastated Ukraine. This is the price Ukraine is paying because of the Russian invasion and Mr. Putin’s goal of attempting to recreate the Russian empire.
President Donald Trump has reached out to Mr. Putin numerous times to secure a cease fire and an eventual peace treaty. To date, those efforts have been unsuccessful, but Mr. Trump persists, fortunately. But until we secure a cease fire, Ukraine needs the support of the U.S. and the European Union, for the weapons and missile defense systems needed for its survival.
Fortunately, the recent NATO Summit of 32 allied countries reaffirmed their strong support to Ukraine, pledging 70 billion Euros to Ukraine and giving Ukraine a green light to produce PATRIOT missile interceptors.
But the U.S. – and our NATO allies -- can do more to get the truth to the Russian people. The truth about the hundreds of thousands of Russians killed in Ukraine and the bereaved families that are paying the ultimate price.
Although the United States Information Agency closed in October 1999, it transferred its important mission to the Department of State. And hopefully our colleagues at State are working hard to ensure that we are getting the message to the Russian people that the war must end; that they and the people in Ukraine have suffered enough. That Mr. Putin and his cronies need to explain why so many men and women died, in a war Mr. Putin created, as he enriches himself. A war that has made the Russian Federation a pariah state.
This should be a whole government mission: to disseminate primarily in Russia the truth about the hundreds of thousands of Russians (and Ukrainians) killed and maimed in a war created by an arrogant and inept Putin.
Although the audience for this important message is the Russian people, China should also be mindful of the tragedy of the war in Ukraine. Indeed, China is aligned with a Russian pariah state, heavily sanctioned by the international community. Is this the image China wants to share with the world?
The NATO Summit was clear in its support of Ukraine, the victim of a cruel and brutal Russian invasion. It’s time for the Russian government to listen to the Russian people and end this bloody war.
The author is the former associate director of national intelligence. All statement of fact, opinion or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. government. Nothing in the contents should be construed as asserting or implying U.S. government authentication of information or endorsement of the author’s views.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
“In addition to supporting OEF (Operation Epic Fury, the Iran War) costs incurred by DOW (Department of War), the [$87.6 billion Fiscal Year FY 2026 Supplemental Trump administration] request provides $768 million to the Department of Energy to support nuclear and other energy security requirements, primarily for the National Nuclear Security Administration (NNSA) for OEF-related activities.”
I was intrigued by that segment, from a June 24 letter to House Speaker Rep. Mike Johnson (R-La.) from Trump’s Office of Management and Budget Director Russell T. Vought, because I could not imagine what costly “nuclear and other energy security requirements” NNSA – the U.S. nuclear weapons complex – could be playing in the Iran War.
However, a chart attached to Vought’s letter said that $672 million was for NNSA to fund “activities for complete and verifiable termination of Iran’s ability to develop or acquire a nuclear weapon, including the disposition of proliferation sensitive material, technology, equipment, and infrastructure.”
Another $95.5 million, destined for the Department of Energy’s Environmental and Other Defense Activities elements, was listed for “support of Operation Epic Fury and other classified purposes.”
Perhaps members of the Senate Armed Services Committee can find out about the plans behind this $782 million package for NNSA and Energy this morning [July 14], when they question Jules W. Hurst III, who is up for confirmation as Under Secretary of Defense (Comptroller).
By the way, when was the last time a U.S. President went to war and added a tax to help pay for it? As an old-timer I remember – it was 1968, when then-President Lyndon Johnson got Congress to pass a nine-month, 10 percent surcharge on individual and corporate taxpayers to help pay for the Vietnam War. Low-income individual taxpayers were entirely exempt from the surcharge.
Since then, both Republican and Democratic Presidents used deficit spending and borrowing to pay for military conflicts. So far this year, the nation’s total deficit has increased through May 2026 by $1.25 trillion, according to the Treasury Department, with Defense Department spending running $20 billion more through May 2026, than it was last year.
But I remind you, Congress now has three defense funding requests before it: a $1.1 trillion FY 2027 base budget request; an additional $350 billion request to be placed in a 2026 reconciliation package; and now the new FY 2026 supplemental request, which has $67 billion for the Defense Department.
No one can say for sure how Congress will deal with these requests that total over $1.5 trillion.
For comparison, I point out that according to a December 8, 2014, Congressional Research Service study, Congress, over the prior 13 years, approved total appropriations of $1.6 trillion for Afghan and Iraq “military operations, base support, weapons maintenance, training of Afghan and Iraq security forces, reconstruction, foreign aid, embassy costs, and veterans’ health care for the war operations initiated since the 9/11[2001] attacks.”
What the Vought chart also shows is that almost 23 percent of the funds in what has been described as the Iran War supplemental, went for different and, in some cases, totally unrelated purposes that I will describe below.
As for the NNSA money, a FoxNews story June 24, said, “The funding would support the removal and elimination of Iranian nuclear materials, including uranium hexafluoride (UF6), uranium in various forms and research reactor fuel, including highly-enriched uranium, according to details shared by a White House official.”
FoxNews also said, “The request also would fund U.S. verification activities inside Iran, support inspections by the International Atomic Energy Agency, strengthen nuclear-smuggling detection efforts and expand Nuclear Emergency Support Team operations across the Middle East.”
In short, Trump is asking for funds to deal with Iran’s enriched uranium before he has any agreement with Tehran that gives the U.S. access to that material.
Perhaps Trump thinks in the end he will have immediate success with Tehran as in he did in Venezuela. There, after the U.S. seized President Nicolas Maduro in January 2026, and four months later, in May, NNSA removed from Venezuela 13.54 kilograms – approximately 30 pounds – of highly-enriched uranium from a legacy research reactor in that country which had been shut down since the early 1990s.
The supplemental request also contains $1.5 billion for the State Department’s of which $850 million is for the Counter-Unmanned Aircraft Systems program at high-risk diplomatic posts overseas along with security upgrades and equipment replacement. Another $300 million for Embassy construction and maintenance would be used to address needs following the start of the Iran war in Bahrain, Dubai, Karachi, Lahore and Riyadh, according to the Vought chart.
The State request also includes $100 million for the Diplomatic and Consular Service account to meet unanticipated needs related to the Middle East situation including departure assistance to U.S. citizens seeking to leave the region with their families. Transfer authority and an increase in repatriation loan level is also being requested to meet the needs of destitute U.S. citizens.
Another $1.35 billion for the State Department is sought to deal with the Ebola Virus, or as Vought put it in his letter to Speaker Johnson, “These funds would be used to limit the spread of Ebola beyond the Democratic Republic of the Congo and Uganda to other vulnerable nations and ensure the virus does not reach U.S. shores.”
Some $800 million for State is proposed for the International Humanitarian Assistance account, formerly managed by USAID, and another $550 million for Global Health Security, which funds “would support contact tracing, personal protective equipment and commodity procurement, disease surveillance, laboratory capacity, and cross-border coordination,” according to the Vought chart.
There is another $2 billion for the U.S. Coast Guard to support OEF where Pentagon “assets are not available to support Western Hemisphere operations. This includes funding for operations at the Southern Border, ” according to the Vought chart.
Meanwhile, the largest amount, other than for OEF in the supplemental, is $11.1 billion for the Agriculture Department, the bulk of which, $10 billion, would be for American farmers as “temporary economic assistance for row and specialty crops planted in crop year 2026,” according to the Vought chart. An additional $1.1 billion is being requested specifically for farmers in Florida “to rebound from devastating losses that were the result of crippling storms this past winter.”
I believe that money has political implications because rural Americans are pulling away from the President. As Brookings Institution polling recently showed, “Only 24% of white rural voters think that the condition of the economy is excellent or good, while 77% rate it as fair or poor. Just 16% say their family’s financial situation is better than it was two years ago (near the end of the Biden administration), compared to 49% who say they are worse off.”
Then there is $1 billion in the war supplemental to assist in the final design and construction for renovation of New York City’s Penn Station. In a New York Times op-ed last Friday, Rep. Jerold Nadler (D-N.Y.) said that the White House last year took control of the $8 billion Penn Station project from the [New York] Metropolitan Transportation Authority.
Rep. Nadler wrote, “Behind closed doors, Mr. Trump has already attempted a quid-pro-quo, offering federal funding for New York’s transit needs only if Penn Station and [Virginia’s] Dulles Airport are renamed for him.”
However, Nadler also noted, “It’s still $7 billion short, and with top appropriators already opposing the supplemental funding request, it’s unlikely to be approved anyway.”
Another $1 billion in the war supplemental, according to the Vought chart, is for the Labor Department’s Pension Benefit Guaranty Corporation “to increase the benefit levels for participants of certain pension plans that were sponsored by Delphi Corporation and terminated as a result of General Motors ' bankruptcy in 2009.”
The money would reverse pension reductions for some 20,000 retirees that have spent years arguing their pensions were unfairly reduced after the Pension Benefit Guaranty Corporation assumed responsibility for the company’s pension plans during GM’s 2009 financial crisis.
According to the Detroit Free Press, “Various legislative efforts to restore the benefits have failed or stalled, despite bipartisan support. Perhaps knowing it's a potentially powerful issue in the Midwest, Trump (and President Joe Biden before him) has signaled his support of the workers in politically sensitive moments such as just before the 2020 election.”
Then there is $500 million for the National Park Service in Washington, D.C. for, as the Vought chart explains, improvements to the World War II Memorial on the Mall and restoration and construction for the Tidal Basin Seawall along West Potomac Park to include the planting of hundreds of new cherry trees and stabilizing the surrounding grounds.
Last Friday, the conservative group Americans for Prosperity pointed out that even the supplemental’s defense and Iran-related spending “deserve further scrutiny,” noting that $15.6 billion for the Pentagon are justified by Vought simply as “Administration priorities,” “Readiness,” and “Classified Programs.”
In fact, I think the whole package needs congressional oversight, and from the reactions of some key Senate and House leaders, that’s what it’s going to get.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.
A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.
Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.
The $3,000 Toll to Export Nothing
Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.
For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.
The See-Through Rule and the Birth of "ITAR-Free"
Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.
So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.
We Are Guarding a Henhouse the Fox Already Breeds
Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.
But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.
The Money Nobody Talks About
Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.
Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.
What Each Corner of the Triangle Should Want
For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.
For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.
For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.
The Fix Already Exists: We Just Gave It to Two Countries
We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.
So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.
I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.
I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.
We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.
A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.
Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.
The $3,000 Toll to Export Nothing
Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.
For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.
The See-Through Rule and the Birth of "ITAR-Free"
Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.
So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.
We Are Guarding a Henhouse the Fox Already Breeds
Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.
But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.
The Money Nobody Talks About
Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.
Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.
What Each Corner of the Triangle Should Want
For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.
For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.
For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.
The Fix Already Exists: We Just Gave It to Two Countries
We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.
So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.
I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.
I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.
We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
With tensions rising all week, the U.S. has launched a new round of strikes against Iranian military targets and maritime assets. The strikes follow an announcement made by President Donald Trump just hours earlier, declaring the ceasefire agreement with Tehran as ‘over’. The fresh wave of strikes signals a U.S. shift back to a strategy of military pressure and economic coercion. The Cipher Brief reached out to Former National Intelligence Manager for Iran at ODNI Norm Roule for context.
"For now, the U.S.-Iran diplomatic track remains alive, but its ability to produce meaningful near-term progress is uncertain, and its long-term survival and utility are increasingly at risk. U.S. strikes in Iran over the past two days will degrade important elements of Tehran’s capabilities in the short term and may buy space for Pakistani and Qatari mediators to reduce tensions and bring about at least a temporary halt in the attacks. However, even if the latest U.S. retaliation deters Iranian attacks in the near term, Tehran is unlikely to abandon its claim of administrative control over the Strait of Hormuz or halt retaliatory attacks against Gulf states that host U.S. bases. Iran’s actions support its long-standing intention to be viewed as a regional hegemon with veto rights over Gulf security, using asymmetric weapons to offset U.S. and Gulf conventional advantages.
Specifically, Tehran is highly likely to continue periodic harassment of shipping to undermine confidence in the security of the Omani transit route. However, Iran is unlikely to try to close the Strait outright unless the United States reinstitutes a blockade against Iran. An effort by Tehran to close the Strait would alienate its customers, unify much of the world against it, and risk a wider war with the United States that the Iranian regime might survive but cannot win. Iran almost certainly believes that it does not need to close the Strait to weaponize it. It only needs to make passage so uncertain enough that insurers, shippers, energy firms, and Gulf governments begin pricing Iranian permission into the movement of commerce and eventually decide they have no choice but to accept a construct that gives Iran permanent influence over passage and Tehran the right to charge fees to those who use it.
The United States is determined to show Iran that these actions carry material costs and that Tehran will not be allowed to control an international waterway. The latest U.S. strikes against Iran, following Tehran’s missile and drone attacks against commercial shipping and Gulf targets, were significant and went well beyond the more limited retaliation that followed earlier Iranian provocations. U.S. forces struck more than 80 Iranian targets on July 7 and approximately 90 additional targets on July 8, including Iranian air defense, command-and-control, coastal surveillance, anti-ship missile, drone, naval, and logistics assets, as well as more than 60 IRGC small boats. Press reports claim U.S. strikes or explosions at key sites near Bandar Abbas, Chabahar, Qeshm, Sirik, Bushehr, and Kharg Island, Iran’s principal oil export terminal. President Trump has threatened further escalation, including attacks against Iranian infrastructure and Kharg Island, if Iranian attacks continue.
This was a significant attack package, but one that still avoided leadership targets and most major civilian infrastructure. The strikes show that the United States will defend its regional partners and the international status of the Strait of Hormuz, and that it has a good understanding of the military system and infrastructure it needs to target to degrade Iran’s attack capabilities in the near term.
Although it remains unclear whether Tehran will de-escalate to avoid further damage, doing so would be consistent with its past behavior and would fit its long-term strategy of episodic attacks that unsettle shipping and test, but do not cross, the line that would ignite a large-scale conflict with the United States. The nature of Iran’s attacks to date, however, shows that Tehran is willing to assume a greater risk of renewed large-scale conflict with the United States if that is the price of forcing others to treat Hormuz as a waterway subject to Iranian permission. The tenor of Iranian rhetoric toward the United States has also sharpened after the former Supreme Leader’s funeral, including public revenge threats against the President. Defiance rather than cooperation is likely to define Iran’s near-term approach.
The Gulf states seek to avoid escalation, but they continue to firmly reject Iran’s claim of control over the region’s central maritime artery. Bahrain, Kuwait, and reportedly even Qatar have now all been drawn directly into the latest Iranian response. This response shows that Tehran is not only threatening commercial shipping and Gulf energy exports, but also targeting Gulf states with the sensing, communications, and command architecture it believes supports U.S. deterrence in the region. These attacks also message that U.S. basing will not protect Gulf states from Iranian attack.
The Gulf states’ immediate focus has been to remove ambiguity regarding safe passage and Iran’s persistent threats by using Qatari, Omani, and Pakistani diplomatic channels, as well as by exploring alternative transit, pipeline, and international maritime arrangements to reduce Iran’s leverage over Hormuz. Iran’s strategy depends on undermining the perception that Omani waters offer protection from Iranian attacks. Tehran’s rejection of reported UAE-backed efforts to develop an International Maritime Organization role in managing the Strait underscores that Iran is fighting not just over shipping lanes, but over who has the authority to define safe passage. Qatar’s role in this regional dynamic is complicated: it is both a valued diplomatic channel and the region’s dominant LNG exporter. At the same time, the reported attacks on Qatari-linked vessels and Iranian pressure on Gulf basing infrastructure show that mediation won’t insulate Doha from Iranian missile and drone strikes.
Energy markets face increased pressure that is likely to vary in intensity over time. Gulf exports had been recovering since mid-June, but the security architecture underpinning that recovery is now visibly eroding. Treasury’s revocation of the oil license granted to Iran after the June deal strips Tehran of the principal early economic concession it gained from the reopening arrangement. Brent and WTI both rose sharply on the news, reflecting not only fear of lost barrels but fear that Hormuz is again becoming a contested operating environment. Nonetheless, the market is responding in a way that shows it sees this week’s flare-up as contained, and that robust production from Saudi Arabia, the UAE, and other producers, reduced Chinese imports from Iran, and the demonstrated resilience of energy markets will prevent a major price shock. In short, existing supply and demand conditions reinforce the prevailing belief that the regional strikes will not evolve into a broader conflict. Should this view be significantly challenged, however, oil prices could quickly move into the $80s or $90s. Longer-term, there is still a disconnect between current market sentiment, the heavy drawdown on global strategic reserves, and the fact that Gulf reliability has been damaged. Even if the Strait remains open, buyers, insurers, and refiners will now treat Gulf supply as politically contingent in a way they did not before the war."
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
Russian President Vladimir Putin can no longer conceal the cost of his Ukraine war from the Russian public. There are fuel shortages throughout the Russian Federation. Videos show hundreds of automobiles lining up to get a few liters of gasoline at gas stations around Moscow. Gasoline sales to civilian vehicles in occupied Crimea have been suspended as the Ukrainian blockade of the peninsula takes effect. Russia continues to make painfully slow progress in its efforts to capture territory in Ukraine and at a staggering cost in casualties.
“…sound out idols... by pos[ing] questions here with a hammer... scrutiny will reveal that they are actually hollow and meaningless—not the high, noble standards of conduct that their proponents claim them to be." — Friedrich Nietzsche
Twilight of the Idols
Ukrainian Defense Minister Mykhailo Fedorov recently says that Ukraine has successfully regained the strategic initiative on the battlefield and Kyiv’s use of long-range weapons to hit targets deep inside of Russia is aiming to force Moscow to end the war through asymmetric attrition. Ukraine has recently intensified precision strikes 20-300 kms behind Russian lines to isolate Russian infantry, destroy high value air defense systems and disrupt the flow of supplies to the front line. The long-range drone campaign is systematically targeting Russia’s energy infrastructure with devastating economic and psychological effect.
Vehicles are lining up to cross the Kerch Strait bridge following successful Ukrainian drone strikes on the Tavriiska thermal power plant, major electrical substations and the Kerch and Dzhankoi oil depots. These strikes have caused blackouts in Sevastopol and Simferopol, the two largest cities in the peninsula. The panic caused by the energy shortages and the fear of total collapse has led many to flee, causing the massive backups at the bridge—with sometimes as many as 2,500-3,000 vehicles lining up to cross. The Crimean Peninsula is the crown jewel of Putin’s campaign against Ukraine which he re-ignited with its annexation in March of 2014.
But Crimea is just one of the many challenges facing Putin. Omsk is burning, having been struck on July 6 by Ukrainian forces in their deepest strategic strike of the war. The Omsk oil refinery is located approximately 2600 kms from Ukrainian territory and is Russia’s largest oil refinery and its top producer of gasoline. There are still lingering oily black clouds over Moscow from the June 18 Ukrainian strike on the Gazprom Neft refinery in southeast Moscow—just ten miles from the Kremlin. The refinery was struck by over 200 drones and sent thick greasy black clouds of burning petroleum directly over the high-rise and residential areas fthat are avored by Moscow’s elites. The clouds created “black rain” and forced disruptions at Moscow’s four airports.
A few weeks before, there were oily black clouds over St. Petersburg as Russia hosted its annual St. Petersburg International Economic Forum in early June. International visitors to the Forum (whose attendance has seen a significant drop since 2022) were re-routed to avoid risk of Ukrainian drone strikes and to avoid the clouds of burning petroleum. This read like quite the humiliation for the architect of Russia’s current economic disaster.
As devastating as Ukraine’s attacks have been, the situation on the front is even worse.
A recent thinktank study indicates that Russian forces have suffered 1.4 million total casualties including 450,000 deaths on the battlefield. Approximately 32% of Russian casualties result in death, a fatality ratio that is much higher than modern Western military standards would allow. Reports by analysts and Russian military bloggers indicate that once a Russian soldier is deployed directly into an active combat zone, their average life expectancy drops to just 20-25 minutes. The average survival time for a raw recruit measured from the moment they arrive at a regional training ground to their death in Ukraine, ranges from ten days to three weeks. Even by the Russian standards that were established for casualties in World War II, these losses are staggering and must be causing alarm bells to go off amongst Russia’s elite leadership. There is more visible criticism of how Putin is conducting this war than has even been seen before.
On the diplomatic front, challenges for the Russian president are rising. This week’s NATO summit is yielding results on Europe’s commitment to defense spending and re-armament, led by Germany which is considering incurring state debt to finance defense spending which would be unprecedented for a postwar German government. Putin’s confidence in his ability to count on President Trump to put pressure on Ukraine to end the war on terms that are favorable to Moscow may be eroding and Trump has recently acknowledged Ukraine’s success in the war.
Putin’s reliable ally in Belarus, Alexander Lukashenko, seems also to be reconsidering the state of play and his enthusiasm for allowing Moscow to drag Belarus deeper into the conflict with Ukraine. resident Zelensky recently demanded Belarus take offline four relay facilities in Belarus’s Brest and Gomel regions near the Ukrainian border. These relay stations acted as signal boosters for Russian drones used to attack Ukrainian cities. The relays have been taken offline.
President Zelensky has just authorized a forty-day intelligence and security operation to heavily amplify pressure on the Kremlin to end the war. He is arguing that Russia’s elites live in Moscow and St. Petersburg and therefore, the war must be brought to their doorsteps. He also predicted that “When not one hundred drones but a thousand start reaching Moscow…Putin will be advised to move somewhere beyond the Urals. Zelensky is right and Ukrainians know Russia better than anyone in the West.
Despite the pressure he is under, it is too early to count Putin out. He has largely and cleverly managed his tenure as Russia’s leader. He is still two years short of Stalin’s 29 year record at the helm, but he is getting close and in his 27 years of running Russia, he has dug his tentacles deep into every level of the country’s power structure and has certainly accumulated kompromat on any potential rival or replacement. Many have speculated that if Putin departs the scene, his replacement could be an even worse partner for the U.S. and the West. I won’t argue that any replacement or coalition that follows Putin will be less anti West than Putin, but whatever constellation follows, they will not have the benefit of having roots and leverage as deep in Russia as Putin does.
For the moment, Putin still has escalatory options he can use to respond to increasing pressure.
In recent weeks, Russia has taken steps to close or severely restrict seven critical railway border crossings and road traffic crossings into Finland, Estonia, and Latvia. Apparently, negotiations are under way to restrict crossings into Kazakhstan and other central Asian states. The motivations for the abrupt closures are unclear but they suggest that Putin may be considering a mass mobilization and is trying to stem the likely departure of military age males to avoid the departures that have occurred since February 2022.
Mobilization alone will not solve Russia’s problem of shortages of equipment and training for conscripts as well as Russia’s World War I-style battlefront tactics. President Zelensky spoke on the margins of the NATO summit this week and said Ukraine is causing over 30,000 Russian casualties a month.
Putin can also rattle the nuclear saber again, but that is likely to be largely ignored as has his previous saber rattling. Most experts are confident that Putin has received firm guidance from his only remaining reliable ally China that he should not open the nuclear Pandora’s box in Ukraine.
The intelligence and security services in the Baltic States, Sweden, and Poland have recently assessed that Putin may try a provocation against one of the bordering NATO states in order to force an Article V action—which he hopes Trump would reject. But few analysts think Putin would risk an all-out war against NATO. That would be a path that could only accelerate Ukraine’s path toward NATO membership and could lead to further disasters for the Russian military, which many experts considered to be the most powerful conventional military in Europe prior to February 2022.
Putin’s most likely response to his current challenges is to continue to take advantage of weaknesses in Ukraine’s air defenses, particularly against ballistic missile attacks and hope that at some point, Ukraine’s morale weakens and pressure increases on Zelensky to end the war on terms that are more favorable to Russia. Such a change in Zelensky or Ukraine is inconceivable to any rational analysis of the current state of the war, but Putin is clearly not rational.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
Your phone buzzes with a text from your bank: “Did you authorize a $2,400 transfer? Reply NO to stop it.” You reply, and seconds later a calm “fraud agent” calls, knows your name and the last four digits of your card, and walks you through “securing” your money by moving it into an account under the criminal’s control. No password was stolen, no malware installed. You handed over the money yourself, because everything looked and sounded real.
This is the new face of bank fraud and business is booming. Behind these scams sit organized adversaries: nation-state actors who treat theft as state revenue, criminal gangs running industrial-scale scam operations, and hacktivists out to embarrass institutions increasingly armed with AI that makes their lies cheap, fast, and tailored to you.
The problem: scams have gone industrial
Banks have spent decades hardening their vaults and networks, so attackers shifted to the softest target: the customer. Rather than breaking in, they trick people into transferring funds themselves. This is “authorized push payment” fraud where the victim approves the payment and it is far harder to claw back than a stolen card number. To hear how a typical scam call actually unfolds, watch theFTC’s short imposter-scam explainer.
With the age of AI, three key forces have turbocharged these threats. Payments now move instantly and irreversibly, so money is gone before anyone notices. Decades of data breaches let criminals buy your name, address, and account details cheaply, making their scripts eerily accurate. And generative AI has industrialized deception where more than half of fraud is now estimated to involve AI. A criminal can clone a familiar or family voice from seconds of audio, write flawless phishing emails in any language, and even deepfake a bank officer on a video call.
The people behind it are not lone hackers in hoodies. They range from sanctioned nation-state groups that steal to fund their governments, to criminal syndicates running scam centers staffed by trafficked workers, to hacktivists attacking banks to make a political point. For them, fraud is a scalable business and it is outrunning the banks, telcos, and Big Tech.
The real-world cost
The damage is measured in real households. The Federal Trade Commission reports Americans lost roughly $16 billion to fraud of all kinds in 2025 the highest on record and about 25% more than the year before. Imposter scams alone accounted for $3.5 billion, nearly tripling since 2020, and the single most lucrative version is the fake bank-security alert that convinces people to “protect” their savings by moving them.
These losses fall unevenly. Americans aged 50 and older reported $4.3 billion in losses in 2025, often life-altering sums drained from retirement accounts. The official numbers are almost certainly a fraction of reality, since many victims never report out of shame. Beyond the dollars, the human cost is real emptied college funds, missed mortgage payments, and a corrosive loss of trust in the financial system people rely on every day. One Florida couple lost $42,000 of their savings this waywatch how it happened. In fact, this happens so often that Hollywood created an action movie about it with theBee Keeper.
A National Security issue
Fraud and scams are not just a nuisance but far more dangerous. Fraud and scams in the United States have escalated into a national security issue because they are no longer isolated consumer crimes. They are large‑scale, foreign‑run operations that drain billions of dollars from the U.S. economy and undermine public trust in financial and digital systems. Federal agencies increasingly link these schemes to transnational criminal organizations, some of which also engage in human trafficking, money laundering, and other activities that threaten national stability. The financial impact is massive, with losses rivaling major illicit industries, and the proceeds often flowing to adversarial nations or criminal networks abroad.
The rules already on the books
The U.S. is not starting from zero. Along with the growth of the early Internet, in 1999 the Gramm-Leach-Bliley Act went into effect and its Safeguards Rule in requiring banks to protect customer data, and guidance from the Federal Financial Institutions Examination Council (FFIEC) pushes them toward stronger, multi-factor login security. The Bank Secrecy Act and anti-money-laundering rules, enforced by the Treasury’s FinCEN, require banks to flag suspicious transactions — a key tool for tracing stolen funds. New York’s Department of Financial Services Part 500 cybersecurity rule has become a de facto national standard.
Regulators are also targeting the scams themselves. The FTC’s Impersonation Rule, in force since April 2024, lets the agency go after fraudsters who pose as businesses or government agencies; in its first stretch it produced more than $70 million in consumer refunds. Voluntary frameworks like the NIST Cybersecurity Framework give institutions a common playbook.
The gap is not the absence of rules it is that attackers move faster than rules can be written, and that liability for scam losses remains murky when a customer is tricked into approving the payment. So, with all these rules and regulations, why are scams and fraud occurring faster?
The innovators fighting back
A fast-growing wave of companies is using the same AI that empowers criminals to stop them.
· Feedzai builds real-time systems that score billions of transactions as they happen, spotting the subtle patterns of a scam in under a second.
· Alloy helps banks and fintechs verify who is really opening an account, choking off the synthetic and stolen identities fraudsters depend on.
· Arkose Labs specializes in blocking automated bot attacks and account takeovers, while SEON, Lexus Nexus, and Sumsub offer identity-verification and fraud-screening tools that smaller banks and startups can plug in affordably.
· Netcraft is a company which doesn’t only detect scams but does something about it. It is very good at “take downs” of scam networks.
· Others are racing to build deepfake and voice-clone detection to catch fakes that fool the human ear and eye. Others get creative: UK carrier Virgin Media O2 built “Daisy,” a lifelike AI “granny” that answers scam calls and keeps fraudsters rambling for up to 40 minutes to tie them up so they have no time for real victims. Watch “Daisy” turn the tables on scam groups.
What unites all these is adaptive defense models that learn daily, because last month’s fraud pattern is already obsolete. All these point solutions are modeled on Intellectual Property that slows sharing. This model is not working.
What America should do
As scams become more sophisticated, especially with AI‑driven impersonation, deepfakes, and automated fraud, their ability to destabilize institutions, exploit citizens, and weaken economic resilience has pushed policymakers and security experts to treat fraud not just as a consumer protection problem, but as a strategic threat to national security. Staying safe will take coordinated effort. Everyone has a role.
Lawmakers and regulators
Fraud and scam laws in the United States, the United Kingdom, and Australia share the same objective: to protect consumers and disrupting criminal activity but each country approaches the problem with a very different regulatory philosophy.
In the U.S., the system is fragmented and enforcement‑driven, with no mandatory reimbursement for most scam victims and a heavy reliance on agencies like the FTC, CFPB, and FBI to pursue wrongdoing after the fact. By contrast, the U.K. has built the world’s most proactive framework, requiring banks to reimburse victims of authorized push‑payment scams, enforcing account‑name verification through Confirmation of Payee, and placing clear accountability on financial institutions to prevent fraud before it occurs. Australia sits between the two models, adopting U.K.‑style protections while expanding responsibility beyond banks to include telcos and digital platforms through its emerging Scams Prevention Framework. While the U.K. emphasizes consumer protection and the U.S. emphasizes enforcement, Australia is moving toward a shared‑liability, cross‑industry approach that recognizes scams as a systemic risk requiring coordinated prevention across the entire digital ecosystem.
A typical scam today uses several pieces of technology working together to make the criminal look real. It often starts with:
1. the scammer creating a fake website that looks almost identical to a bank or delivery company. They buy a cheap web address from a service like GoDaddy and change just one letter so most people won’t notice the difference.
2. Then they setup email accounts on services like Microsoft & Gmail to send out massive emails.
3. They use AI tools to scrape millions of social media profiles from Facebook, Instagram, etc. to collect data about YOU.
4. They use tools that let them fake a phone number (telco), so when they call you, your phone shows the name of your bank or a government agency.
5. After that, they send out text messages to iPhone and Android users that look official, things like “Your account is locked” or “You have a package waiting.” The link in the text takes you to the fake website, where the scammer collects your login details. If you call the number instead, it goes to a call center where the scammer pretends to be a bank employee.
All of this: fake websites, spoofed phone numbers, and realistic text messages works together to trick people into believing they’re talking to a trusted company when they’re actually dealing with a criminal.
What should the Critical Infrastructure do?
In the U.S., we have failed because we have not worked together across these technologies at scale & at the speed of AI. Why? Because we (collectively) do not have the incentives or requirements to do so. For the CEOs of these companies, they do not want to spend money & resources which do not drive revenue. Period.
There are glimpses of hope. A working model already exists:
· We have the Financial Services Information Sharing and Analysis Center (FS‑ISAC) is a global, nonprofit organization that helps protect banks and other financial institutions from cyberattacks by enabling them to quickly share information about threats. It was created in 1999 (26 years!) to strengthen the safety and resilience of the financial system by collecting, analyzing, and distributing timely intelligence about cyber and physical risks so that member institutions can defend themselves and their customers more effectively. I am hopeful that they new CEO, Valerie Abend will drive more effective solutions.
· In 2026, eight major carriers: AT&T, Verizon, T-Mobile and others just launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), chaired by longtime cyber expert, AT&T security chief Rich Baich, to share real-time threat intelligence across competitors. Because most scams ride phone and text networks before they ever reach a bank, telecom and banking defenses should connect through the same kind of collective-defense sharing. But the C2 ISAC cannot do this alone.
· In 2025, the Global Anti‑Scam Alliance (GASA) was formed to bring together governments, financial institutions, technology companies, law‑enforcement agencies, and consumer groups to fight scams on a global scale. GASA acts like a global “anti‑scam task force,” uniting experts and institutions so people everywhere are better protected from online fraud.
These have proven to not operate effectively to get ahead of scams and fraud. We need a better way – mandates of sharing, legal risks support, cross ISAC/intel which is tailored/aware, good native ML & AI models (not rules), and others working at speed and context with more transparent sharing.
In the meantime,
What should consumers do?
Treat any unexpected “urgent” message about your money as a warning sign, not a command. Banks will never ask you to move funds to “protect” them. Hang up and call the number on the back of your card. Turn on multi-factor authentication and agree on a private “safe word” with family so a cloned voice can’t fake an emergency. Report scams to ReportFraud.ftc.gov, even unsuccessful attempts, because the data helps train good AI/ML models to protect everyone.
What should all companies do?
Adopt adaptive, AI-native detection rather than yesterday’s rules, and design apps that help customers pause before they act. Investors should back the firms building deepfake detection and identity verification, and banks should partner with them quickly instead of waiting years to build in-house.
Conclusion:
With fast innovation, fraud & scams will not disappear, but it can be better contained. The criminals have industrialized deception; the answer is to industrialize defense with smarter rules, sharper technology, and a public that knows the warning signs.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
We are good at winning wars and generally bad at what comes after. Far from a partisan observation; this is a pattern with receipts. We removedSaddam Hussein in three weeks and then spent eight years discovering that we had no plan for Iraq. We helped toppleQaddafi in 2011 and left Libya to sort itself out, which it did into a decade of competing militias and open-air slave markets. We spent twenty years inAfghanistan and still managed to be surprised when the government we built collapsed in eleven days. The American way of war ends at the moment of victory. The credits roll, everyone goes home, and the sequel is a disaster nobody bothered to consider.
There is exactly one modern exception, and it is instructive. When the Soviet Union came apart in 1991, aDemocratic senator from Georgia and aRepublican senator from Indiana looked at roughly 30,000 nuclear warheads scattered across four newly independent, newly broke republics and decided, radically, to think ahead. TheNunn-Lugar program spent American money to secure, consolidate, and dismantle those weapons before they could walk out the door to Tehran or to a bidder we would like even less. It was unglamorous, it was expensive, and it worked. Three decades after the largest state collapse in modern history, there has been no loose-nuke catastrophe. We planned once. It went well. We have not repeated the experiment since.
I raise this because we may be about to need it again, and the warning lights are coming on faster than the planning is.
Start with the battlefield. Russia has absorbed somewhere near1.4 million casualties since February 2022 in order to advance, in its showcase offensives, at a pace measured in tens of meters a day. That is more than any major power has taken in any conflict since the Second World War. In early 2026 that grinding pace stalled outright, and for the first time since 2023Ukraine recaptured more ground than it lost.Russian military recruitment fell twenty percent in the first quarter of this year, into the teeth of the worst labor shortage the Russian economy has ever recorded. An army that cannot recruit and an economy that cannot spare the men are not a combination that trends toward Berlin.
Then follow the money, because wars end when the money does. Russia'sfederal budget deficit hit 5.9 trillion rubles in just the first four months of 2026. That is larger than the entire deficit it ran in all of 2025, and against a full-year plan of 3.9 trillion. The liquid portion of thesovereign wealth fund, the rainy-day cushion, has shrunk from 6.5 percent of GDP at the start of the war to 1.8 percent this April.Oil and gas revenue in 2025 fell to its lowest level since 2020, and in the first two months of 2026 it dropped nearly by half year-on-year. The Kremlin israising its value-added tax from 20 to 22 percent and cannot borrow abroad, because we long ago cut it off from the markets. Putin is a man selling his furniture to make rent.
And here is the part that should be keeping planners awake at night: Ukraine has learned to hit the one thing Russia cannot armor. Kyiv's drones have takenmore than a third of Russia's oil-refining capacity offline, roughly 38 percent by some counts.Gasoline output is down seventeen percent from a year ago. Refineries atKirishi,Ryazan,Nizhny Novgorod,Yaroslavl, and outside Moscow itself have been forced to halt or throttle production. Russia, one of the largest oil producers on earth, has banned gasoline exports and is nowrationing fuel to its own citizens, who are queuing at pumps in a country that floats on crude. A petrostate that cannot keep its own drivers in gasoline is a petrostate whose social contract is running on fumes.
Now the honest caveat, because I have watched too many confident men predict Moscow's collapse and end up eating the prediction. Russia has a genius for absorbing punishment that would break others, and "the regime is about to fall" has been the graveyard of Western analysis for a century. Vladimir Putin may well hang on for years. I am not promising you a collapse. I am telling you that a Russian defeat, a real one, military exhaustion bleeding into political rupture, inside the next two years, has moved from a fringe scenario to one that a serious government insures against. You do not buy fire insurance because you expect to burn. You buy it because you cannot afford the one time you do.
So what does the insurance look like in this case? A few things, none of which require us to want Russia to come apart.
First, dust off Nunn-Lugar and write the sequel now, before the crisis. Russia has roughly1,800 strategic warheads today. If central authority in Moscow wobbles, the question of who controls them becomes the only question that matters. What’s worse,New START quietly expired this past February and is no longer around to give us the courtesy of counting them. We need pre-negotiated channels for securing those weapons, ideally including China and India, whose interest in not having loose Russian nukes on the market is every bit as sharp as ours.
Second, decide in advance what we will and will not recognize. A fragmenting Russian Federation could throw off breakaway republics the way the USSR did in 1991. The moment to agree on which borders and which authorities we will treat as legitimate is before a dozen regional governors declare themselves president, not while it is happening. Improvised recognition is how you turn a collapse into a set of proxy wars that makes Putin’s destabilizing behaviors look like child’s play.
Third, keep the technocrats employed. The most dangerous export of a collapsing weapons state is not a warhead; it is the underpaid engineer who knows how to build one. In 1992 we worried about Russian scientists boarding flights to Iran, Iraq, and Libya. This time we should build the landing pads, research funding, visas, civilian projects, before they start looking for the exits.
Fourth, tell Ukraine and our European allies what "victory" actually means, so that we are not improvising the peace the way weimprovised Baghdad. A defeated Russia is not a solved Russia. It will still have grievances, a reconstituting army, and a long memory. The objective is a Russia that loses this war and cannot start the next one, a vacuum we will spend the 2030s regretting.
None of this is a prediction that Moscow falls next spring. It is the recognition that we have been surprised by nearly every ending we should have seen coming, and that the cost of preparing for a Russian defeat that never arrives is a few think-tank salaries and some awkward classified memos. The cost of not preparing for one that does is measured in warheads we cannot account for.
We have the receipts on what happens when we refuse to think ahead. We also have a single example of what happens when we do. Let’s choose the sequel we actually storyboarded.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
Five intelligence services rarely speak with one voice. When they warn the window of vulnerability has narrowed to months, the real question is whether the defenders can move as fast as the threat.
Throughout my years in the intelligence world, I don’t recall a single instance in which the Five Eyes partners jointly issued a public warning, so when they do, the message lies in the act as much as the words. Intelligence agencies guard their assessments and share them sparingly, almost never in the open. So, when the United States, United Kingdom, Canada, Australia, and New Zealand jointlywarned on June 22 that frontier AI models capable of serious cyber exploitation are only "months away" from broad availability, the unanimity was itself a clear message. "The timeline is not years, it is months," they wrote.
The warning the Five Eyes partners shared is specific. These are systems that let a non-expert coordinate a complex intrusion (work that until recently required a trained team fluent in reconnaissance, exploitation, and stealth). That capability is moving out of the hands of advanced nation states and into the reach of mid-tier criminal groups and other adversaries. As the barrier to a sophisticated operation fall, the target list grows, and the systems most exposed are the ones a country cannot do without hospitals, water and power utilities, community banks, ports, and the contractors that serve them.
There is one caveat to mention. Outside experts who examined the models argued they do not represent a wholly novel threat, and the agencies concede their core remedy is familiar: fix the basics, patch faster, control identity and access. The fundamentals still decide most outcomes. What has changed is speed and, with speed, potential volume. The vulnerability was always there, and AI simply finds it faster and puts that reach into more hands.
For national security planners, "months" is the word that should capture attention. Strategy assumes time, and much of the architecture protecting critical infrastructure was built for an era when a capable intrusion took a capable organization. AI collapses that assumption. A defensive posture written to last three years can be overtaken before its first review, and the slowest links (legacy systems and sluggish patching) are the points an adversary will reach first.
Washington has begun to respond.Executive Order 14409, signed June 2, is best read as the opening move in a national security framework for frontier AI. It directs the NSA and CISA to benchmark in classified settings when a model's cyber capabilities make it a "covered frontier model," and it asks developers to voluntarily give the government up to 30 days of access to such models before release. It stands up an AI cybersecurity clearinghouse — led by Treasury — to coordinate the discovery and patching of vulnerabilities, and it directs the Justice Department to prosecute those who turn AI against American computer systems. It also pushes to put defensive AI into the hands of the institutions least able to defend themselves: rural hospitals, community banks, and local utilities.
The order is also a move in a broader contest. Representative Andrew Garbarino, who chairs the House Homeland Security Committee, said the same week that China is "months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States." Washington has already moved to restrict the export of a leading frontier model on national security grounds. Whoever fields these capabilities first, and whoever sets the terms for evaluating and controlling them, will shape the rules others must live by. That competition runs straight through the private companies that build the models and the critical infrastructure an adversary would target.
All of this points to the real test. If frontier AI can accelerate attacks, it can accelerate defense, and the side that equips its defenders faster holds an advantage. Programs that put defensive AI into the hands of critical-infrastructure operators, such as Anthropic's Project Glasswing and OpenAI's cyber-defense access effort, are early attempts to give defenders a head start in finding and fixing flaws before they are exploited. The harder problem is people. Models do not run themselves, and the expertise to direct them, in a utility control room or a hospital network, is scarce and unevenly spread across exactly the sectors most at risk.
This is where national security and the private sector stop being separate conversations. Most critical infrastructure is privately owned and operated, which means the front line of national defense now runs through companies whose first duty is to investors and shareholders. The operators that can name the AI systems they rely on, assume their adversaries now carry capable co-pilots, and test their defenses against machine-speed intrusion are the ones that will fare best.
All of this argues for a different compact between government and industry, grounded in shared purpose. Major developers, critical-sector operators, and the national security agencies need to engage early and honestly on the most dangerous capabilities, the way Executive Order 14409 suggests. And the country must invest in defensive AI and in the people who wield it, so the defenders of American systems keep pace with their attackers.
I spent decades in the world of intelligence, much of it managing risk where the cost of getting it wrong was measured in much more than money. The warning the Five Eyes issued this month is the kind that professionals will take seriously. The timeline is tight, and the targets are the systems a society runs on. Frontier AI will define the next era of national power, and the open question is whether the defenders get their co-pilots before the attackers’ finish deploying theirs.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
There are65 active state-based conflicts in the world today, according to the Uppsala Conflict Data Program. That is not 65 separate crises. It is 65 living laboratories.
The contest that matters is not understanding any one of them. It is recognizing the 66th — the next emerging theater — while it is still only a collection of weak signals. The war before the war has already begun, and it will be won by whoever learns fastest.
For generations, intelligence organizations competed to collect more information. Tomorrow, they will compete to learn faster. Since every adversary is becoming a learning organization, our advantage must become organizational learning — and organizational learning at this scale requires infrastructure we have not yet built.
That infrastructure includes a Digital Twin Network.
The Network, Not the Twin
The objective is not to build a better digital twin. It is to build a Digital Twin Network capable of recognizing the 66th emerging theater before it becomes obvious.
Imagine a living network of thousands of interconnected digital twins — not only of nation-states, but of terrorist organizations, criminal syndicates, cyber groups, critical infrastructure, financial systems, media ecosystems, shipping networks, supply chains, political movements and emerging technologies. Every important actor, network and system has a continuously evolving twin.
Each twin learns independently. Collectively, they learn exponentially.
The value is not in the individual twins. It is in the conversations among them. Every observation by one twin makes the entire network smarter. A political crisis in Bosnia immediately updates neighboring political, economic and alliance twins. A cyberattack against critical infrastructure causes financial, media, logistics and influence-network twins to reassess their own environments. A new disinformation tactic discovered in one region is instantly tested against every other emerging theater.
The network does not simply share information. It shares learning.
This is the shift that matters: from monitoring individual events to understanding how thousands of interconnected systems evolve together. From storing information to accumulating learning. From asking “What happened yesterday?” to asking “What is becoming more likely tomorrow?”
What the Network Looks Like in Practice
Picture a digital twin of Bosnia, Moldova or the South China Sea that updates every minute. Every political speech, troop movement, satellite image, shipping pattern, cyberattack, financial transaction and social media narrative automatically changes the model. We move from “what happened” to “what is most likely to happen next.”
AI agents do the work, each with a job. One reads every speech. Another tracks every satellite image. Another looks for new alliances. Another measures the speed of narratives. Together they integrate political developments, military movements, economic indicators, migration, social sentiment, infrastructure, weather, cyber activity and media into a single continuously updated model — one that can identify change in seconds, minutes and hours, and simulate the impact of future actions.
The ability to rank the most successful future actions, based on analysis of hundreds of potential outcomes, changes how we think about red teaming in cognitive security. We will be able to build a synthetic example of every adversary of any size, and to simulate every scenario continuously.
It will be on us to feed in the right inputs. What emerges is a global learning graph of active conflicts — every lesson, every pattern, every conflict feeding better insight in real time.
How the Network Learns: Observe, Learn, Adapt
Conflicts are like a staircase: pressure, politics, perception, prosperity, partnerships, posture, provocation. Every conflict climbs the staircase differently. A network that can read that staircase across every theater at once needs three disciplines.
Observe. We are good at collection. We will benefit from a common structure that makes our observations legible to AI. As an example, The Seven Layers of Emerging Theater Intelligence (SETI) gives every twin the same language for evaluating how adversaries evolve before open conflict:
Pressure — Are underlying conditions becoming less stable?
Politics — Are institutions losing the ability to manage that pressure?
Perception — Is someone deliberately shaping how people interpret events?
Prosperity — Are economic tools becoming instruments of competition?
Partnerships — Are actors beginning to choose sides?
Posture — Is capability being positioned?
Provocation — What event could rapidly accelerate escalation?
Learn. The measure of the network is its learning velocity — how quickly it improves after every observation. Every conflict becomes a research dataset where the network continuously asks: Which indicators appeared earliest? Which signals were ignored? Which combinations proved most predictive? Which assumptions proved wrong? Which interventions slowed escalation? Which technologies changed outcomes?
Adapt. The network tracks how media and technology are evolving and how they will change future tactics. Whether it is artificial intelligence, autonomous agents, commercial satellite imagery, cyber capabilities, sensors, recommendation algorithms or open-source techniques, we watch how each one shortens the distance between pressure and politics, perception and partnerships, posture and provocation.
All of it feeds back into the twins. SETI gives the network a common language; learning velocity gives it a scorecard. Together they make the network something fundamentally different from today’s intelligence systems — a living research community that studies all 65 active conflicts every day and asks the same questions of each. Which pressures are increasing? Which partnerships are changing? Which narratives are spreading? Which actors are learning fastest? And, most important, where is the next theater beginning to resemble the early stages of previous conflicts?
The Scale of the Build
This is why the build matters, and why it must begin now. A network worthy of the threat means digital twins for every nation-state adversary, roughly 100 foreign terrorist organizations, 500 major transnational criminal organizations, 300 state-sponsored cyber groups, hundreds or thousands of hacktivists, 600 militias, insurgencies and armed non-state actors, and thousands of influence and disinformation networks.
That represents a good start.
As AI, autonomous agents and eventually quantum computing mature, the scale of continuous learning will expand dramatically. The future of intelligence will belong to organizations that treat every conflict as a learning system, every emerging theater as a research project, and every observation as a chance to improve faster than their adversaries.
The Only Question That Matters
The race is no longer to understand today’s 65 conflicts. It is to recognize the 66th emerging theater before anyone else — while it is still only weak signals.
That is a contest of learning, and learning at that scale cannot be improvised in the moment a crisis arrives. It has to be built in advance. The Digital Twin Network is that build.
The war before the war has already begun. The only question is whether we will have the network in place to see it.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
“I’m deeply concerned that the Presidential proposal for $350 billion mandatory funding [to be carried in a reconciliation bill and not an appropriations bill] for defense will have no Appropriations [Committee] input on the enactment. That’s not the right way to fund the Department of Defense, because it took the Department ten months to explain to Congress how they were going to spend the $150 billion in mandatory funding they received last year. It’s unacceptable, and I have no confidence the Department will do a better job responding to us in the future. There’s also no guarantee that a reconciliation bill will pass.”
That was Rep. Betty McCollum (D-Minn.) speaking last Wednesday at the House Appropriations Committee meeting that marked up the Fiscal Year 2027 Defense Appropriations Bill.
Ranking Democrat on the panel’s Defense Subcommittee, McCollum was questioning the Trump administration’s second year of seeking to put a major chunk of proposed defense spending in a reconciliation bill, where it could avoid both pre-passage congressional review and require only a majority vote for Senate approval.
It turned out that McCollum had bipartisan support for her view.
The House Appropriations Committee, in its report on the bill it later approved that day, included several examples of problems caused by using mandatory spending in a reconciliation bill, along with remedies it proposed..
I will discuss them below, along with one other critical issue – problems in U.S. Navy shipbuilding -- that the House committee also raised in its report.
Remember, however, these are just one committee’s suggestions and they still have a way to go to be adopted by the full House and Senate.
One mandatory spending example in the Committee report relates to the controversial F-35 Lightning joint fighter program.
The President’s fiscal year 2027 budget request includes $7 billion in discretionary funding for 32 F–35 aircraft and $10 billion in mandatory funding for 53 F–35s. Additional modernization funds sought for the F-35 program includes $2 billion in discretionary funding and $2.4 billion in mandatory funding.
In its report, the House Appropriations Committee said it “has serious concerns regarding how the Office of Management and Budget (OMB) bifurcated the funding request and questions the rigor that was used to split the request between discretionary and mandatory funding. For example, radars and other critical components were either funded in full on one side of the ledger
or the other, inconsistent with the total flyaway costs for discretionary and mandatory quantities.”
The Committee report continues, “Further, OMB made assumptions on program savings associated with executing a multi-year procurement contract, for which a corresponding legislative proposal has not been submitted, and applied all the savings to the discretionary request. As a result, the discretionary budget request actually procures a quantity of only six aircraft, rather than the 32 it purports to fund.”
Another Committee report example related to more than $43.4 billion for several critical munitions that is included in the $350 billion mandatory package. The committee said, “In many cases entering into MYP (multi-year procurement) contracts will require both discretionary and mandatory funds. The topic of accelerating munitions production has been a priority of the Department and Congress alike, though splitting funding into two funding processes could lead to incongruencies that will not be easily remedied.”
Splitting weapons programs between the discretionary and mandatory funding prevents Congress from considering requests as a whole, the Committee report says, thus preventing “effective oversight and program continuity and also to preserve production lines and commitments to industry partners and allies.”
The report adds that this year the House Committee is only considering the discretionary portion of the request, but will be “working with the [Defense] Department to ensure that budget justification materials submitted for fiscal year 2028 are adequate to evaluate the full-funding profile, regardless of funding mechanism or whether funding was previously enacted or provided in any future reconciliation package.”
The Appropriations panel report also directs attention to problems in the Navy’s shipbuilding program where the President’s fiscal 2027 budget request includes over $60 billion in discretionary funding for the Trump administration’s so-called Golden Fleet Initiative.
As the report puts it, “The Committee remains firm in its conviction that funding alone does not guarantee on-time delivery and is no substitute for sound program management and rigorous oversight. The Committee is concerned that an accelerated pace of investment, absent commensurate accountability, risks repeating the cost growth and schedule slips that have plagued nearly every major shipbuilding program in recent years.”
Getting specific, the report says, “The Committee is particularly troubled that the Navy’s cost-to-complete request for shipbuilding totals $2.6 billion in fiscal year 2027. The cumulative cost of these delays and overruns now rivals the price of the ships themselves, eroding the buying power of every dollar appropriated for new procurement. The Committee believes that the Navy has not consistently demonstrated the ability to identify, report, and correct adverse cost and schedule trends in a timely manner.”
For a remedy, the Committee “directs the Secretary of the Navy to submit a report to the House and Senate Defense Appropriations Subcommittees not later than 90 days after the enactment of this Act, and quarterly thereafter,” on each major shipbuilding program: to include the current delivery schedule, cost-to-complete with drivers of any growth; and actions the Navy has taken or intends to take to recover any schedule and contain cost growth.
The Committee report also directed the Government Accountability Office next year to assess any recurring cost growth and schedule delay across major Navy shipbuilding programs and the adequacy of the Navy’s response to identify and arrest such trends early.
The Committee also took aim at two specific submarine shipbuilding programs, starting with the Columbia-class which is the sea-based leg of the strategic nuclear triad, and the Virginia-class attack submarine.
According to the Committee report, “the lead Columbia-class submarine is delayed by as much as 18 months and that the Virginia-class program is delayed by as much as 42 months,” adding, “Delays of this magnitude present significant risk to strategic deterrence, erode undersea superiority, and degrade long-term operational availability and readiness.”
Because, according to the Committee report, “incremental funding in a constrained industrial environment serves only to introduce further risk,” the panel recommended “full funding for one Columbia-class submarine and two Virginia-class submarines.”
The House Committee report also took aim at the nascent Trump Guided Missile Battleship (BBG(X) program for which the President’s FY 2027 budget seeks $1 billion in advance procurement and $837 million in research and development funds.
The report says, “The Committee notes that the [Trump battleship] program has not finalized ship design, completed a formal analysis of alternatives, or established a stable set of requirements, and that the Congressional Budget Office has estimated the lead ship could cost in excess of $20 billion.”
The report added the Committee has cautioned in the past that “committing funding to construction before achieving design stability and solidifying requirements is a principal cause of the cost growth, schedule delay, and industrial base instability that afflict Navy shipbuilding.”
The Committee report also warned “that BBG(X), as a nuclear-powered surface vessel, will draw on the same finite pool of nuclear-capable shipyard capacity, skilled workforce, reactor components, and supplier base on which the Columbia-class submarine, Virginia-class submarine, and Ford-class aircraft carrier programs depend.”
Given the situation, the Committee said that “introducing a new nuclear surface combatant [the BBG(X)] without careful planning could compound those constraints and place at risk the delivery of [shipbuilding] programs the Committee considers higher priorities for the nuclear-capable industrial base.”
As a result, the Committee requested detailed reports from the Navy Secretary: One that “addresses the validated requirements and key performance parameters for the large surface combatant [BBG(X)]; the status of the analysis of alternatives and ship design, including a design maturity assessment and the criteria the Navy will use to certify design stability prior to any commitment to lead-ship construction.”
And a second report that deals with the “Navy’s strategy to design and construct BBG(X) without interfering with existing nuclear-powered shipbuilding programs,” and also “how the Navy will sequence and resource BBG(X) so as not to jeopardize the delivery schedules of those programs.”
If that were not enough, the Committee also added a section to the actual legislation, Section 8147, which, by law, would limit the Department of the Navy from using funds to contract to build the lead ship of the Trump-class battleship program, BBG(X), until the “Secretary of the Navy certifies to the congressional defense committees that the weapon systems planned for inclusion in such lead ship are at a sufficiently mature technology readiness level.”
In a column last April, I noted some weapons Trump wants to include on BBG(X) are still in development and any design for such a ship was at least two years away. I now repeat what I wrote two months ago, my bet is that none of these Trump-class battleships will ever actually be built.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief