Normal view

There are new articles available, click to refresh the page.
Today — 15 September 2026The Cipher Brief

We Are In An Unpredictable War Of Attrition

15 September 2026 at 10:17

We are squarely in the target sights of ‘Unintended Consequences.’

What do I mean by this? Think of it as a broad spectrum of possible consequences when missiles and drones are being slung back and forth between Iran and U.S. Navy vessels and bases, and the energy and commercial facilities and ships of its Gulf allies. On one end of the spectrum, accidents happen: think the inadvertent U.S. airstrike on the girls’ school at the beginning of the war, and the more recent ‘wedding party’ casualties when a U.S. missile struck a nearby communications tower. These are tragedies for all involved. On the other side, an Iranian missile made its way through U.S. air defenses to strike a U.S. military facility in Jordan, resulting in the deaths of three U.S. troops. The latter resulted in a robust U.S. military response that targeted a variety of Iranian military facilities. This was a success for Iran and a tragedy for America.

On the other end of the spectrum, what if one of Iran’s ballistic missiles successfully navigates to its target - a U.S. base or navy vessel, for example - and significant U.S. casualties, dead and/or wounded, result? The U.S. administration is likely to come under tremendous political pressure to respond with overwhelming force. This could elevate the stakes even higher, cutting off any chance of a negotiated settlement, remote as it currently is. And with the regime already having been severely degraded militarily, and its leadership ranks diminished, what does that leave in terms of targets? More of the same?

It could also result in calls to withdraw U.S. forces, given the antipathy of a majority of the U.S. population to a war they view as unnecessary, ill-advised, and ill-managed. This would leave Iran in a weakened yet still dangerous posture, with the ability to pressure the world economy at will going forward. Neither option is appealing.

Oh, and by the way, notwithstanding the administration’s verbal gymnastics, this is very much a war.

D-Day Sanctions Regime

On the surface, this appears to be a pretty solid strategy, or at least better than what has been tried to date: Simply squeeze the Iranian economy until the regime cries uncle. It is already having an impact and will likely continue to compound the pain. But it is neither simple nor clear-cut. Who will it actually impact, how badly, and when? A total blockade means not just money or arms. It means no food. It means no medicine. And a host of other basic necessitates. The Iranian people will feel it first, particularly the young, the old, and the sick. Regime insiders, including the leadership and their loyal (for now) security forces, will be the last to see the effects.

And we have already seen Russia and China reject complying with the secondary sanctions that comprise the heart of this enhanced effort. So, no one knows what will happen if they choose to challenge the blockade; It is highly unlikely that U.S. forces will use force against Chinese vessels attempting to access Iranian ports. And that does not take into account less overt (read clandestine) interactions - intelligence sharing, weapons system development, sabotage efforts against Gulf country facilities, including pipelines, etc. - that would further evade and/or erode the U.S. advantage.

So, while there will be pain, and lots of it, as I said in a recent BBC interview, there remain many unknowns. Informal smuggling networks have abounded in the region for Millenia. The regime will utilize every trick they have learned since the ‘79 revolution while building a ‘resistance economy’ to get around the blockade/sanctions. And potentially with the implicit, if not explicit, support of two major world powers. In the end, this does not presage the near-term submission of a regime that values survival above all else. This remains very much a test of wills.

Furthermore, what happens when the world sees the Iranian people starving before their eyes? I’m not sure they will countenance this for long.

So, Who Has More at Stake?

The U.S. people are seeing higher gas prices at the pump, rising food costs, overall inflation, and more. This is painful, but certainly not existential, at least not yet. The increasingly negative impact on the world economy stands to worsen things considerably if the status quo continues for too long, so Americans are watching closely. And the mid-terms are fast approaching.

The Iranian people are seeing the destruction of their economy, their country, and potentially their very way of life. It is very much existential. The specter of a thundering locomotive of new sanctions bearing down on them must certainly be terrifying. I have no doubt many Iranians blame the Islamic regime for bringing this down upon them. But as things worsen, they may turn against the U.S. and its allies for abandoning them to the depredations of the regime.

The Iranian regime most certainly views this as an existential threat, notwithstanding its rhetoric. They would be fools not to. But Netanyahu’s 2 September statement that the Israeli government is, “working to bring down this regime and defeat it,” accompanied by Trump’s 2 September statement publicly questioning, “when the Iranian people would rise up and fight,” is unlikely to motivate them to negotiate. They will need to be forced to submit. My experience with Iranians tells me that the harder you press, the more resistant they become. Uncharted territory indeed. We will see.

China and Russia both have an adversarial relationship with the U.S. and important interests vis-à-vis Iran: military for Russia (drones) and commercial for China (oil). Why would either go out of their way to assist the United States in removing itself from a self-imposed disaster that is distracting it from issues they care about while diminishing its military capabilities, all with minimal effort? That is a question that remains to be answered.

Speaking of Regime Change

U.S. political leadership answers to the American people at the ballot box. The system is a bit creaky at the moment, but (for now) it remains intact.

The Islamic regime, by design, does not answer to the Iranian people. Iran’s elections are truly rigged, primarily by the Guardian Council’s ability to reject candidates for office, but also with an increasing willingness to falsify election results. And in the end, the Supreme Leader is able to reject any initiative or law he disagrees with. We have seen the results when the Iranian people see no recourse for accountability by the regime: people in the streets, followed by blood in the streets.

Without substantial outside support, of which we have so far seen little evidence, the populace will be hesitant to go back to the streets, knowing that if they do, they are on their own. It could happen if things get bad enough, and it is possible it might even ultimately be successful, but it is almost certain to be a massacre, followed by chaos and a very uncertain end. Yet another example of unintended consequences.

Where Are We Now?

For the moment - and this may already have changed as I write this - we are back in what I refer to as a Hyperbolating phase, where we are seeing threats/counterthreats being tossed back and forth with abandon. Most of these statements are utterly meaningless and can be ignored. It appears both sides are waiting to see who blinks first.

U.S. messaging appears to be somewhat disjointed, contradictory, and lacking an overall strategy, with the President, the only real decision-maker, continually wandering on and off the path of others in his administration: Trump - I don’t care/where are the Iranians?; Hegseth - continued confrontation; Bessent - economic asphyxiation; Rubio - no nuclear weapon/economic pressure; Vance - not a war/intermittent containment. You could claim this is purposeful to keep Iran uncertain and off balance, but it should not be doing the same to Americans. President Trump failed to bring the American people on board beforehand with a coherent (and honest) case for war and an actual strategy for winning it. The continued shuffling of various justifications we have seen from the administration serves simply to stir the mix of confusion.

I get the distinct feeling that, given the fast approaching mid-terms and the deep hole they have dug for themselves, the administration just hopes that something/anything works so they can walk away from what is clearly a foreign policy disaster.

Iran messaging, on the other hand, appears, at least to me, to be a bit more coordinated if not strategic. While most Iranian government leaders are defiantly threatening massive retaliation for continued U.S. strikes (hyperbole), including the military (both Artesh - regular military and IRGC - Revolutionary Guards), the Parliament and its Speaker Ghalibaf (“U.S. actions will not go unanswered”), and the Foreign Affairs Ministry (claiming “war crimes” by the U.S.), the lone man on an island is the Iranian President, Pezeshkian; “we do not seek war but will respond,” and, “Iran remains open to negotiations, under the June MOU”. It is important to realize that the Iranian President has virtually no policymaking role in Foreign affairs, so his statements should be given less weight than others. But he would never make this offer without the approval of the IRGC, the Supreme National Security Council and, most likely, the Supreme Leader (or whoever is speaking for him). As I have written previously, I believe that the vagueness of the original June MOU was oddly advantageous to Iran and served to lead us directly back to where we currently are. So… this would seem to indicate negotiations are at least still on the table, just not under conditions particularly favorable to the U.S.

Where Are We Going?

Military escalation? A slow grinding pressure on the regime, testing their willingness to allow their people to suffer? Or a return to the negotiating table?

Who knows? There is no simple or painless way out of this.

Unintended consequences, after all.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Before yesterdayThe Cipher Brief

Russia’s AI Blueprint Exposes an Authoritarian Playbook

10 September 2026 at 05:00

Russia, China, and Iran are all sharing the same playbook for corrupting Western elections. The United States is on track to be the next target this November.

A troveof Russian documents leaked in May outlines Moscow’s plans to use AI to warp foreign decision-making and sway elections. The Kremlin’s “Projects 2026” strategy reveals Russia’s plot to influence upcoming elections in Europe and Israel. Their tactics are similar to those used by China and Iran for years, and what emerges isn’t a Russian innovation — it’s a shared authoritarian playbook.

Projects 2026 calls for the creation of an opinion leader database to monitor the social media profiles of 10,000 influential individuals across Europe, including the 100 most prominent opposition figures in France alone. This is precisely the model Chinese state-aligned company GoLaxy piloted against the United States in 2025. The firm reportedly built constantly evolving psychological profiles of 117 members of Congress and roughly 2,000 additional American opinion leaders.

Researchers at Vanderbilt University warned that GoLaxy appeared prepared to target these individuals with messaging aligned with Beijing’s priorities. By monitoring the social media profiles of Western leaders, China and Russia are able to map the target’s values, beliefs, emotional tendencies, and vulnerabilities, making their influence operations more tailored and impactful.

In addition to using AI to build psychological profiles, the authoritarian playbook calls for countries like Russia and Iran to flood their targets with tailored generative AI content. Projects 2026’s “AI News” initiative calls for producing more than 500 short videos to target French audiences across six social media platforms. This tactic mirrors Iranian information operations during the 2025 and 2026 wars with Israel and the United States, when pro-Iranian networks pushed AI-generated and AI-assisted videos tailored to different audiences across X and TikTok, which racked up millions of views. These countries are running highly productive propaganda engines.

The most durable piece of Projects 2026 isn’t the content at all — it’s the plan to create fictitious think tanks and research institutes that can hand Russian narratives a “legitimate information source,” making them more likely to be cited by real news outlets and large language models. The leak shows this already underway: A site called the “World Center for Strategic Studies,” registered in March 2026, published unsigned analysis aimed at Western think tank audiences, with versions planned in German, French, and Spanish. The fake think tank doesn’t need to fool a discerning reader. It needs to get quoted, indexed permanently, and cited by the next AI model that goes looking for sources on the topic.

Iran ran a cruder version of this same play: Iranian state-sponsored cyber espionage groups have repeatedly impersonated real institutions — such as the Royal United Services Institute, the Aspen Institute, and the Washington Institute — to steal credentials and plant material under a trusted name. Projects 2026 proposes something more sustainable: Don’t just hijack existing credibility but manufacture new institutions and let them accrue it over time.

Projects 2026 also proposes building a real Israel-based research institute staffed by Israeli citizens with genuine academic credentials. This approach is reminiscent of the 2014 “Iran Expert Initiative,” where Iranian Foreign Ministry officials attempted to court and influence Western think tank researchers to promote their perspectives and give them legitimacy. Emails leaked in 2023 showed that Iranian diplomats had worked with Western experts across 10 think tanks to aggressively tout the merits of the 2015 nuclear deal between Tehran and major world powers, formally known as the Joint Comprehensive Plan of Action.

In the age of AI, influencing think tanks is narrative laundering at its most dangerous. Once a fabricated or state-aligned source gets cited by a legitimate outlet or indexed by a search engine, it can become part of the training and retrieval corpus that AI systems draw upon.

While the plays are reusable, the targets are new, and for Russia, the target is European elections.

The leaked documents outline a plan to swing Armenia’s parliamentary vote through a Russian-diaspora outlet and a “Mitteleuropa” initiative aimed at reshaping alignments in Hungary and Slovakia. This is where the surveillance, flooding, and laundering modules converge. To counter it, policy solutions must be swift and targeted.

First, allied governments should require disclosure of foreign funding and foreign state links for any media outlet, think tank, or “research institute” operating ahead of an election in an at-risk state — closing exactly the gap that lets a “World Center for Strategic Studies” pass as domestic and independent. Research by the Foundation for Defense of Democracies (FDD) into Qatari money in American higher education shows what a real transparency regimen requires: disclosures reaching individual researchers, not just institutions; low reporting thresholds with real penalties; registration in the style of the Foreign Agents Registration Act for state-directed “institutes” masquerading as independent organizations; and provisions against the kind of obstruction Qatar used to block Texas A&M’s funding records in court. Russia is proposing to build the same laundering vehicle in Europe that Gulf money has already normalized in American academia. The fix already exists — it just needs to be strengthened.

Second, platforms should both demonetize and remove unlabeled AI-generated political content during designated pre-election windows in at-risk states. X’s own emergency policy during the Iran war, which suspended digital influencers’ ability to monetize their content for 90 days on undisclosed AI-generated war footage, shows platforms already have the infrastructure to act fast when the stakes are high enough. But demonetization alone left the content up and circulating; independent researchers found AI-generated war footage kept flooding feeds regardless of the policy. Elections warrant a harder line: If posts feature undisclosed AI-generated content during an active election period, they shouldn’t just lose ad revenue. They should come down.

Third, Washington should prepare for future attempts at election influence by boosting the protection mechanisms it already has in place. Currently, 31 states have passed election deepfake laws, but they are under legal scrutiny because they touch on domestic speech. Federal action targeting foreign actors rests on firm ground. The 2002 McCain-Feingold Act prevents electioneering communications by foreign actors, but this only applies to broadcast, cable, and satellite communications. It must be updated to explicitly include paid internet and digital advertisements. It should also close the gap on AI-generated political content and require labeling so that foreign deepfakes can’t hide behind current ambiguities.

Projects 2026 is not evidence that Russia has cracked something new. It’s evidence that Moscow, Beijing, and Tehran are now running the same AI playbook against the same democracies, taking turns testing which module works best. The future outlined in Projects 2026 may not be here yet, but objects in the mirror are closer than they appear.

Leah Siskind is director of impact and an AI research fellow for the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD). For more analysis from Leah and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Gulf Bought Its Air Defense From Kyiv. We Sold Them The Radar.

9 September 2026 at 08:35

Chief Warrant Officer 5 (Ret.) Joey Gagnard concluded nearly three decades of service in the U.S. military, retiring from the special operations community in early 2025. He serves as CEO of Atlas Special Projects and Director of Field Operations at Swarmer.

Disclosure: Atlas Special Projects leads investor delegations to Ukraine and maintains working relationships with Ukrainian drone manufacturers, some of which would benefit from the arrangements argued for below. The argument is my own.

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

Riyadh, spring 2026. Between February 28 and the April 8 ceasefire, Iran put roughly 6,400 missiles and drones into the Gulf states and Jordan, more than eighty percent of everything it fired at anyone. Six countries fought six separate wars against one coordinated adversary, with no shared early warning and interceptor stockpiles that ran thin in days. An Iranian drone struck a tactical operations center in Kuwait and killed six Americans.

Three suppliers answered the same incoming fire. Here is the ledger.

The United States answered with paper. Over $36.6 billion in Foreign Military Sales notifications to the Middle East in a single quarter, headlined by 730 PAC-3 MSE missiles to Saudi Arabia for $9 billion. That is a little over $12 million per round, aimed at a Shahed that costs about as much as a used pickup, on a delivery schedule measured in years.

Ukraine answered with people. Washington asked Kyiv on a Thursday to send interceptor teams to protect American bases in Jordan, and Kyiv said yes the same day. Within weeks about two hundred Ukrainian advisors were on the ground in Saudi Arabia, Qatar, and the UAE with interceptors that Ukraine sells for between $800 and $3,000 and builds at two thousand a day. Days after the Jordan request, the President went on Fox News Radio and said, “We don’t need their help in drone defense. We know more about drones than anybody.”

Turkey answered with a delivery date. Kuwait signed a government-to-government protocol with Aselsan, Havelsan, and Baykar for Hisar and Korkut air defense, and Riyadh, Doha, and Abu Dhabi opened their own talks with Ankara, because Turkey could put hardware on a ramp this decade and the American backlog for Patriot and THAAD runs to several years.

Then, on March 27, Saudi Arabia signed a ten-year defense partnership with Ukraine built around counter-drone technology and co-production facilities on Saudi soil. Qatar signed two days later. The UAS followed in April. Ten years each, minimum.

So the outcome of America’s largest arms-sales quarter in memory is that our closest Gulf partners now buy their sensors from us and their answer to the actual threat from Kyiv and Ankara. We sold them the radar. Somebody else sold them the thing that shoots.

Expensive Confetti

The arithmetic is not subtle, and the Gulf did it faster than we did. Iran can turn out hundreds of Shaheds a week. The U.S. builds roughly six hundred Patriot interceptors a year, for the whole world, with a waiting list. A Patriot battery is a good answer to a question Iran stopped asking in about 2019.

The Ukrainian answer is a different species. The Wild Hornets Sting costs about $2,500, flies at 195 miles an hour, fits in a duffel bag, and has killed nearly 4,000 Russian drones since may 2025. The SkyFall P1-SUN costs about $1,000, flies at 280 miles per hour, and took down 1,500 Shaheds in its first four months. One Ukrainian firm sold a thousand of them for $3.5 million, total, which is less than a third of one PAC-3 round. More than twenty Ukrainian companies now build interceptors and the Octopus alone is licensed to fifteen of them.

None of this makes the Patriot obsolete. Interceptor drones do not touch ballistic missiles ,and the 6,400 included plenty. But the Gulf learned in six weeks what Ukraine learned in three years: you defend against a thousand cheap things with two thousand cheaper things, and you save the twelve-million-dollar round for what it was built to hit.

Built in Munich

Here is the detail that turns the Gulf story into an Iron Triangle story. The Pentagon has bought exactly one interceptor with a Ukrainian combat record. In May, Joint Interagency Task Force 401 gave Perennial Autonomy, Eric Schmidt’s company, a three-year, $500 million ceiling for the Merops interceptor, a fifteen-thousand-dollar fixed-wing that has downed more than 4,000 Russian drones over Ukraine. It is the right buy. It is also built in Germany, through a partnership with Munich’s Twentyfour Industries.

The American flag interceptor, proven in Ukraine, bought by the Pentagon for the homeland, is made in Bavaria. This is not a scandal. It is a symptom. The design talent is in Kyiv, the production tooling is in Europe, and the one thing that has to be in the United States, the contract, is the only part we have managed to put here.

Meanwhile the July agreement that lets Ukraine sell to the Pentagon for the first time since 2022 approves six Ukrainian companies to ship about one hundred drones for testing under Drone DOminance, and contemplates, someday, Ukrainian production on American soil. One hundred drones. Kyiv ships that many to Riyadh before the coffee is brewed.

What an American Flag Would Actually Mean

Not an American airframe. That race is over; twenty Ukrainian firms iterate faster than any American line will for years, and pretending otherwise is how we ended up with a hundred test articles and a factory in Munich. The American contribution is the three things nobody else at the table can bring.

The first is the kill chain. An interceptor without a sensor network is expensive confetti with a propeller. Ukraine’s cheap drones work because they fly under a national acoustic and radar mesh that took three years to build. The Gulf has no such thing; the after-action reports say so. Turkey cannot integrate Korkut with Patriot and THAAD. The United States owns IBCS, the LTAMDS radars Kuwait just bought eight of for $8 billion, and the $4.5 billion discrimination radar the UAE is buying for THAAD. The offer writes itself: your thousand-dollar Ukrainian interceptor gets cued by our eight-billion-dollar sensor layer. That is the flag.

The second is the paper. Licensed co-production under FMS is a forty-year-old tool. Abrams in Egypt. F-16 in Turkey. Patriot itself in Japan. The structure is a trilateral: Ukrainian design and Ukrainian intellectual property, Gulf capital and final assembly to satisfy Vision 2030 localization, American components, integration, and the FMS wrapper that turns a purchase into a security relationship. The UK has already proven the licensing half, building Octopus interceptors in Britain at a thousand a month and sending them back to Ukraine.

The third is reciprocity. Kyiv’s own ask was one sentence: “We can help you fight against Shaheds. Help us fight against ballistic missiles.” Gulf money buys the interceptor line. A slice of the PAC-3 allocation that the Gulf money is already funding flows to Ukraine. Stings for Patriots. Three countries get what they cannot build, and the United States is the reason it happens.

What It Has Not Happened

Every obstacle is one I have written about before, which is the depressing part.

Start with ITAR. The moment a Ukrainian design is produced by an American licensee with American controlled content, it becomes ITAR-controlled, its re-export to Riyadh needs a DDTC license, and Kyiv loses the freedom to sell the same design to Oslo. Ukrainian founders already decline to domicile intellectual property here for exactly this reason. The fix is the one I argued for in July: a trusted-trader tier, or an AUKUS-style exemption scoped to the trilateral, with the IP staying in Kyiv and the United States as licensee rather than owner.

Then the parts bin. A thousand-dollar P1-SUN is a thousand-dollar P1-SUN because of Chinese motors, cells, and cameras. Under an American flag it must clear NDAA Section 848 and, if the Department of War is the buyer of record, the Blue UAS list. The cost of making the interceptor American is not the airframe. It is the audit and the re-sourcing, and nobody in the building has priced how much of the thousand dollars survives that. Turkey does not have this problem. That is the entire reason Turkey is winning the Gulf.

Then tempo. Ukraine signed three Gulf deals in about three weeks. FMS notification to first delivery is measured in Congressional recesses. Either the trilateral runs on Direct Commercial Sales with expedited licensing, or it is a press release.

And then the politics, which I will state once and then be finished. The Commander in Chief said we do not need their help days after his own government asked for it, and the Pentagon spent the spring resisting broader cooperation. The Gulf hosts Russian diplomacy. Kyiv keeps state control over exports, with its own forces first in line. None of these are fatal. All of them are real.

For the Procurement Officer. Your requirement is not an interceptor. It is a kill chain that accepts an interceptor you did not design. Write the sensor and command-and-control interface as the requirement and let the airframe compete, or you will spend the next POM cycle buying an American drone that arrives in 2029.

The Investment Thesis. The value in this market is not in the airframe and it never was. It is in the integration layer, the domestic component that lets a Ukrainian design survive Section 848. And the licensing paper. The company that can take a thousand-dollar Kyiv design and hand the Pentagon an American-compliant unit at two thousand, on a line this side of the Atlantic, is worth more than the company that designs the next one.

The Policy Wonk’s Warning. The security guarantee is being unbundled from the hardware. For seventy years those were the same product. Our partners are learning they can buy the guarantee from us and the shooting from someone else, and the day they discover they can buy the sensors elsewhere too, the guarantee is just a speech.

My Take. I have been in the room in Kyiv when founders explain, patiently, why they will not bring their IP to America. It is not ingratitude. It is that our export regime treats an ally’s design as a hostage the moment it touches our supply chain. We asked those same founders for help defending our bases in Jordan, and they sent people the same day, and then we told the world we did not need them. I have watched a lot of good capability lose to bad processes. I have not often watched it lose to bad manners.

The Risk. A co-production line in the Gulf is a leakage path to whoever the Gulf talks to next, and that list includes Beijing and Moscow, which is precisely why the British license sends its output home to Ukraine rather than into a third market. Iran is already fielding jet-powered Shaheds that outrun a Sting. And anyone who reads this as an argument to cancel the Patriot order has misread it; the 730 rounds to Riyadh are for the thing the drones cannot touch. The argument is not fewer Patriots. It is that a thousand-dollar problem should not be the one part of Gulf air defense that American has nothing to do with.

We spent the spring selling our partners the most sophisticated radar on earth. Kyiv and Ankara sold them what the radar is for. When the next 6.400 comes over the horizon and the Saudi interceptor that meets them has a Ukrainian design, Turkish neighbors, Chinese motors, and an American radar track, whose air defense is that?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

A Former CIA Station Chief on Kyiv Under Drone Siege

4 September 2026 at 15:00


Reporting live from Kyiv, Cipher Brief expert and former senior CIA officer Ralph Goff walks CEO and Publisher Suzanne Kelly through a drone strike that hit the SBU headquarters in the heart of the city today.

Ukraine’s SBU — the Security Service of Ukraine (Sluzhba bezpeky Ukrainy) — is best described as Ukraine’s principal domestic security and counterintelligence service, although its wartime role has become substantially broader and more operational.

The closest U.S. analogy would be a combination of responsibilities that are divided between the FBI, the CIA and specialized military/intelligence capabilities, here in the U.S. The SBU is responsible for counterintelligence, counterespionage, counterterrorism, protecting state secrets and investigating threats to Ukrainian national security. Since Russia’s full-scale invasion, it has also become a significant wartime intelligence and covert-action organization.

Kelly talked with Goff about the impact of a Russian drone attack on the organization's headquarters and the surprising resilience of Kyiv residents in the strike's aftermath.

Kelly: You've been on the ground in Kyiv for a couple of days, but there was quite an incident this morning amid near-nonstop air raids that have lasted for more than a week now. Tell us about where you were and what you heard this morning near SBU Headquarters.

Goff: Today in Kyiv we had some air raid alerts overnight, then some in the morning, and a couple more during the day. But today was followed up with a couple of drone strikes right in the middle of Kyiv. Early this afternoon, one struck the headquarters of the Internal Security Service, the SBU, which seems like a very deliberate, targeted attack by the Russians. Unfortunately, there were some casualties, I don't think anyone was killed, but there were wounded, and some damage to the building. It was a very clear sign from the Russians that their jet-powered Geran drones are not only hard to intercept, but very accurate.

Kelly: The Cipher Brief has been in that area of Kyiv with you several times in the past, Ralph. That's essentially the inner circle, where the government operates. We've been wondering how long it would be before some of these significant targets got hit, given Ukraine's shortage of anti-missile systems. What's it been like on the ground since you arrived three or four days ago? Is there a heightened sense of anxiety?

Goff: There is, among parts of the population, but I'd say for most people it's more a heightened sense of annoyance. Here we had a drone strike right in the heart of Kyiv, at the SBU building, and most people's biggest concern afterward was how it messed up traffic downtown, it's a major artery, so there were traffic jams all around. History is replete with examples where so-called strategic bombing of civilian targets or major cities to break the will of an enemy has never worked, and I don't see that working here either.

I do think it's a clear sign that Ukraine has to find a way to close the gap and counter these new high-speed, high-performance drones. We hear reports of an 85 to 90 percent interception rate on conventional, piston-engine drones, the regular Shahed-type drones. But with the jet-powered drones, we've heard the interception rate drops to much lower figures, which I won't get into because I don't want to give the enemy that kind of data. And when it comes to missiles, the press has already reported that the Ukrainians are so low on counter-missile capabilities that they rarely intercept any ballistic missiles launched into Ukraine.

Kelly: When you're watching this war from afar, it's hard to get a clear sense of how much time is left before Kyiv, Lviv, and other major cities are in real trouble. Kyiv has always had the strongest air defenses. Is Kyiv running out of time?

Goff: I don't think they're running out of time so much as, I think they will close the gap, they will solve the technical issues and improve their defenses, but it will take time, and they'll suffer in the meantime. I'll say it's going to be a bad winter; I'm fairly certain of that. But the Russians didn't break the Ukrainian spirit last winter, and they won't break it this year either.

On the other hand, there's an interesting dichotomy of feelings and morale. At the front, I was talking to a friend who's been deeply involved in providing intelligence assistance to frontline units, a non-governmental source, and he said that for the first time since he's been here, every unit he visited had high morale. We're looking at a battlefield now where the casualty ratio is probably eight to one in favor of the Ukrainians. Eight to one, that's an astounding number. So you have this high morale at the front, where soldiers are saying, “we think we can pull this off.” And then in the cities, you have people increasingly concerned about the welfare of their families and children because of these blatantly terroristic attacks on civilian targets. There's a real dichotomy emerging in the middle of this war.

Kelly: On that eight-to-one figure, is that because so much of the fighting on the front lines now is essentially robot-on-robot, drone-on-drone combat? Or is something else driving that number?

Goff: That's a large part of it, but at the end of the day you still need soldiers fighting soldiers. What it comes down to is who has better mastery of the battlefield, and the Ukrainians have information dominance. On top of that, they're the defenders, they can dig in and weather the storm, whereas the Russians are still relying on high-cost, high-attrition tactics, sending soldiers out literally in ones and twos to try to infiltrate Ukrainian positions. But they're very vulnerable, because the battlefield has become so saturated with drone coverage and surveillance, what we call ISR, intelligence, surveillance and reconnaissance. The Ukrainians have really mastered that, and it's given them a huge advantage. That could change, the Russians aren't sitting back, they're innovating too, but for now the Ukrainians have an edge, and they're going to keep innovating to maintain it.

Kelly: There have been a lot of headlines about domestic issues that President Zelensky is dealing with this week in Kyiv, even as he wages this war, including the departure of Minister Fedorov, who's been pushing forward on defense technology and made some announcements this week here in the U.S. about that. What's different now in terms of the strength, stability, and unity of the government? We know the unity of the people is hard to break, but how are you looking at this through the government lens?

Goff: The big difference now is that the innovation and technical advances made by the Ukrainians don't depend on one person. This isn't some technological breakthrough that depends on one minister or one ministry, it's government-wide, across the various ministries and different commands. It's a multi-echelon effort where technological innovation isn't just pushed down to the lowest levels, it's driven by the lowest levels. It runs from top to bottom and bottom to top. So whether you change a minister or change a commander, like the change from Syrskyi to Drapatyi, that doesn't change. The innovation has reached all levels, and it's here to stay.

Kelly: I'm jealous The Cipher Brief isn't there with you right now, we usually are, and we like being there because you're attending a number of interesting and enlightening meetings while in Kyiv. Has anything surprised you this time, or really stuck with you, from this round of meetings?

Goff: Nothing ever really surprises me here. I think one of the reasons I come is for my own benefit, I always leave more inspired than when I arrived. A good example: we had this horrendous drone strike in the middle of the city, and within minutes people were just going about their daily lives. The emergency response was there, I watched ambulances flowing to the scene, first responders arriving. I actually marveled at that, because my initial instinct was to stay away, given the Russian penchant for the “double tap”, hit the target, wait a few minutes until first responders arrive, then hit it again. Even knowing that's a Russian tactic, the first responders were there within minutes.

As I continued on to my next meeting, people were going about their lives, doing their shopping, going to work, going to the grocery store. They weren't deterred by the event. And while that doesn't surprise me, it does inspire me.

Kelly: What about the significance of the SBU? A lot of people may not understand exactly what it does, it's similar to our own intelligence gathering but with other functions too, almost a combination of the CIA and FBI if we're relating it to the U.S. Tell us about some of its operations and why it's an important organization in Ukraine.

Goff: It's an important organization because, yes, they have the primary mandate for internal security in Ukraine, but they're also involved in long-range strikes into Russia. If you see press reporting on some sort of assassination attempt, like the Russian air force general who was shot the other day, that's pretty much the SBU, showing they have a long reach into Russia. So they're playing on multiple levels, and they're an important player. This is a sign that Russia knows who they are and where they are.

But taking out the SBU headquarters is probably inconvenient for some time, and there will be losses. The Ukrainians have decentralized much the same way they've decentralized the structure of their military intelligence community, they've decentralized command and control. So if you take out the SBU headquarters, I'm sure within minutes there's a backup headquarters and contingency plans in place. The Ukrainians are well aware of Russia's capability to strike their headquarters.

Kelly: It's been a little while since you were working as a CIA station chief, you held six different postings in that role. If you were filing something back to the United States today, what's the most important thing you'd want people to understand about what you're seeing there?

Goff: That the war is entering a different phase. And if the war is entering a different phase, it means the Ukrainians are going to have to react differently, which means their allies are going to have to react differently, which means those of us in the intelligence community are also going to have to change our game and adjust. We're going to have to be prepared to support the Ukrainian effort to defend themselves, and if that means an active defense against the Russians, that would be my recommendation.


The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Nuclear Umbrella is Bent, Not Broken

3 September 2026 at 09:12

Why Extended Nuclear Deterrence Still Matters

Jennifer Lind and Daryl Press make a compelling argument in a recent article about the future willingness of the United States to provide extended nuclear deterrence, sometimes referred to as the “nuclear umbrella” to over 30 allies. Since the early days of the Cold War, the U.S. made a commitment to defend Europe against Soviet aggression, and under extreme conditions, included the use of nuclear weapons. Similar assurances were made to Japan, South Korea and Australia. The protection provided by this nuclear umbrella has been a hallmark of international order for decades as allies trusted the U.S. would protect them and therefore had no reason to develop their own nuclear weapon capabilities. Lind and Press rightly point out the security environment has changed dramatically, and the “order” created by the United States during the Cold War no longer exists. With the dissolution of the Soviet Union, Lind and Press argue Russia’s nuclear threat on a global scale is much diminished with Russia focused on its boundaries with eastern Europe and less concerned with “the global balance of power”. Similarly, Lind and Press view North Korea’s nuclear weapons development as a regional security issue with Kim Jong Un more interested in regime survival than peninsular conquest. They further argue conflicts today are largely regional in nature and question the commitment of the United States to engage in a nuclear conflict on behalf of an ally thousands of miles away. Thus, they claim the “nuclear umbrella” is broken.

The Nuclear Umbrella Still Exists

On the surface, it’s easy to believe this argument. The first Trump administration clearly stated an intent to put “America First” in 2017 and the second Trump administration signaled skepticism toward alliance commitments and their associated costs. Abroad, there is potential that this signaling from Washington also includes the commitment to extended nuclear deterrence. President Trump’s new National Security Strategy (NSS) published in 2025 does not mention extended nuclear deterrence or the nonproliferation of nuclear weapons. Similarly, the 2026 National Defense Strategy (NDS) does not “explicitly mention extended deterrence” and instead places the “primary responsibility” for their own defense on them with limited support from the U.S. And lastly, the current Trump administration has not and most likely will not issue a Nuclear Posture Review (NPR). The first NPR was released in 1994 every subsequent administration has issued one until President Trump took office again in 2024. The NPR is a blueprint which describes the role of nuclear weapons in U.S. security strategy. This document contains critical messaging on the capabilities, numbers, and modernization efforts of nuclear weapons and under what conditions the U.S. potentially would or would not use nuclear weapons. To be sure, the absence of explicit language on extended nuclear deterrence in the NSS and NDS and the lack of an NPR are departures from the U.S.’s historical stance providing nuclear top cover and nonproliferation of nuclear weapons.

Allies and partners of the U.S. have obviously taken notice and started conversations on how to proceed especially given continued Russian aggression, Chinese and North Korean nuclear weapons development, and what they might perceive as uncertainty of the U.S. as a nuclear deterrent backstop.

The United Kingdom and France recently pledged increased cooperation with nuclear weapons with the signing of the Northwood Declaration in 2025. French President Macron also rolled out a policy of “advanced deterrence” aimed at potentially providing nuclear forces to various European allies. Additionally, Japan, South Korea and Australia are all deeply concerned about nuclear weapons development in both China and North Korea. As a result from the proximate threat, some Japanese and South Korean officials have publicly discussed nuclear weapons, a topic previously considered taboo.

However, there is also plenty of evidence to support the fact that while the nuclear umbrella is bent and tattered, it’s not broken.

Although the current NSS and NDS do not explicitly mention extended nuclear deterrence, they do not explicitly eschew the notion either. In fact, the NDS states Europe should take “primary responsibility for its own conventional defense…” making a clear distinction between conventional and nuclear forces. Despite much talk of NATO needing to pull more of its own weight regarding security, the U.S. remains committed to the alliance. Since 1954, the U.S. pledged to protect NATO members and currently has around 100 air-delivered nuclear weapons deployed to various bases in Europe. In addressing the NATO Defense Ministerial, Under Secretary of War for Policy, Elbridge Colby, stated, “Thus, for the United States, our responsibility is to be clear, candid and consistent. We will continue to provide the U.S. extended nuclear deterrent.” Additionally, the U.S. continues to be active in the NATO Nuclear Planning Group, the senior policy body for NATO nuclear issues. Despite U.S. signaling a “scaling back” of conventional support to NATO, there is no plan to remove any of these nuclear weapons from Europe.

There are similar extended nuclear deterrence concerns from Japan and South Korea, especially the suggestion that both should take on more of the financial burden for their defense, the U.S. commitment to both is bit clearer. In February of last year, the U.S. Secretary of State met with the Foreign Minister of Japan and the Foreign Minister of the Republic of Korea to “reaffirm the unshakable trilateral partnership” between the three countries. This meeting underscored the historical commitment of the U.S. to the defense Japan and South Korea to include extended nuclear deterrence.

Why Extended Nuclear Deterrence Matters

What’s missing in many of the arguments concerning U.S. extended nuclear deterrence is how it has underwritten the concept of nuclear nonproliferation for decades. In 1968, the U.S. pledged cooperation in limiting the spread of nuclear technology as one of the first signatories of the Nuclear Non-Proliferation Treaty (NPT). Though limited and certainly not perfect, the Nuclear Nonproliferation Treaty (NPT) is widely considered one of the most successful arms control treaties ever written by limiting the spread of nuclear weapons while aiding risk reduction of nuclear weapons use. As mentioned earlier, dozens of countries have chosen not to pursue development of nuclear weapons (and pledged not do so as signatories of the NPT) because they determined the extended nuclear deterrent guarantee provided by the U.S. to be reliable and most importantly, credible. Additionally, any country who may feel abandoned by the nuclear umbrella provided by the U.S. and may choose to pursue development of their own nuclear weapon faces myriad challenges. First, many are bound by the NPT and even if they were not, often lack the resources to develop nuclear weapons and delivery systems. Second, all states, even those with the technical know-how to proceed with a nuclear weapons program, would introduce into the nuclear “club” another independent launch authority, more command-and-control systems with varying levels of capability, unknown decision-making processes during crises, and more opportunities for proliferation, miscalculation, and accidents. Following the bombing of Hiroshima and Nagasaki, the one thing the international community could agree upon was developing a strong prohibition against the use of nuclear weapons. Many resolved crises throughout history where nuclear weapons loomed in the background reinforced the idea that the use of nuclear weapons was unthinkable. The spread of nuclear weapons to more independent states does not simply mean we live in a world with more of them, it substantially increases the number of situations where they become increasingly integrated into routine statecraft and thus, their potential use more thinkable.

The Strategic Consequences

Despite concerns about the credibility of U.S. extended nuclear deterrence that have emerged in some allied capitals, the United States should not become resigned to the prospect of allies leaving the nuclear umbrella. Doing so would weaken the nonproliferation regime, increase incentives for independent nuclear programs, and ultimately leave the United States confronting a more dangerous strategic environment. The U.S. should continue to signal that the credibility of extended nuclear deterrence rests upon strong conventional capabilities and even stronger, unmistakable political resolve with our allies while keeping nuclear use as the final safeguard. Increased proliferation of nuclear weapons does not achieve that objective.

The United States is unique among states that possess nuclear weapons because it has used the world’s most capable nuclear weapons arsenal to prevent nuclear proliferation rather than encourage it. Thus, extended nuclear deterrence and nuclear nonproliferation are inseparable. The enduring contribution to international security by the United States has been and should continue to be the guarantee of nuclear extended deterrence to uphold nonproliferation and preserve the longstanding objective of nuclear non-use.

In no uncertain terms should the U.S. become “comfortable” with more states acquiring their own nuclear weapons resulting from of a lack of confidence that Washington will continue to be the nuclear guarantor. Despite periodic political signals that make some allies nervous, Washington has been remarkably consistent, across multiple administrations, in its policy toward extended nuclear deterrence. States that question U.S. commitment should consider whether other alternatives would enhance their security. The answer is almost certainly no.

The views expressed here are those of the author alone and do not necessarily represent the views, policies, or positions of the U.S. Department of Defense or its components, to include the Department of the Navy or the U.S. Naval War College.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Cultural Roots of Strategic Surprise and Resilience: the Israeli case of October 2023

1 September 2026 at 05:01

October 7th, 2023, 06:29 AM. Probably the most tragic day in Israel’s history. A surprise attack conducted by Hamas from the Gaza Strip caught Israel completely off guard. Hamas terrorists infiltrated Israel, killing more than 1200 Israelis and abducting more than 250 individuals into the Gaza Strip. They exercised mass murder and rape, effectively conquering parts of Israel’s Western Negev for several hours. This was a colossal military and intelligence failure, more dramatic than that of the Yom Kippur War in 1973. It was also, of course, a policy failure. The core foundations of Israel’s security doctrine – defense, early warning, and deterrence – completely shattered.

How could this happen to the Israeli Defense Forces (IDF), one of the best militaries in the world, and to one of the best intelligence communities in the world? For me, as a brigadier general in the Israeli Defense Intelligence (IDI) reserves with decades of practical experience, and as a scholar of Israeli strategic culture and intelligence culture, this was a puzzle. Almost inconceivable. I was surprised by the magnitude of Israel’s surprise. How could Israel’s security establishments reach October 7th with their “eyes wide shut” about Hamas intentions and capabilities?

But as the regional war which followed October 2023 commenced, I recognized another interesting puzzle. Israeli security establishments have, writ large, recovered from the failure of October 2023, with Israel fighting for almost three years in several fronts, from the Gaza Strip to Iran. Although not gaining “total victory”, these establishments reached impressive operational achievements. They dismantled most of Hamas’ military and civilian infrastructure in the Gaza Strip and eliminated most of Hamas leadership in the Middle East; dismantled most of Hizballah assets in Lebanon, while also eliminating Hizballah leader Nasrallah, and demoralizing Hizballah in the famous pagers operation; destroyed many of the Houthi assets in Yemen; and in June 2025 and March 2026, conducted unprecedented attacks in Iran, including the elimination of Iran’s Supreme Leader and most of Iran’s military leadership, and degrading Iran’s nuclear and military capabilities.

How could the same establishments, which colossally failed to prevent the Hamas attack in October 2023, reach such achievements during 2024 and 2025? How could an intelligence system completely surprised by Hamas allow Israel to completely surprise Iran, the regional super-power? How could Israel “turn the tides” of the war after October 2023, and then, like the Phoenix from Greek mythology, “rise from the ashes” and conduct phenomenal strikes in Iran?

These are the topics I discuss in my new book, which reveals the cultural roots of Israel’s strategic surprise in October 2023, and of Israeli resilience following October 2023. The book knowingly focuses on Israel’s security establishments, and not on Israeli policy makers. Its scope is limited, and its conclusions will naturally be debated.

I open the book by acknowledging that some of my previous insights, which characterized Israeli intelligence culture prior to October 2023, were wrong. For instance, I assessed that this culture relies on professional norms and values of critical thinking, a sense of individual responsibility, and moral courage in the face of hierarchy. October 7th, unfortunately, showed that some of these remained aspirational norms rather than realized behavior in Israel’s security establishments.

Several typical facets of Israeli strategic and intelligence cultures account for both failure and success. For instance, the Israeli typical focus on operational, tactical, and targeting intelligence prior to October 7th resulted in an under-appreciation for strategic analysis, military analysis, and strategic early warning from war. The low quality of these disciplines was one of the factors for the October 7th failure. But the inclination towards targeting intelligence, and the close integration of intelligence into decision-making and operations, also enabled Israel to conduct ground-breaking overt and covert operations across the Middle East, relying on high-resolution and real-time targeting intelligence. Many more examples are discussed in the book.

However, the book stresses that strategic culture and intelligence culture are not unitary in essence, nor are they fixed in time. Changes in these cultures can be caused by trauma, or by competition for dominance between sub-cultures. For instance, in the years prior to October 7th, hubris evolved in Israeli security establishments, which not just underestimated Hamas, but also overestimated their own military and intelligence capabilities. October 7th, naturally, created a post-traumatic effect. Israeli deterrence-oriented security doctrine, which was dominant prior to October 7th, became heavily oriented towards prevention after October 7th, not just regarding adversary nuclear projects. This “move between extremes”, or “over-adaptation”, is for itself typical of Israeli strategic culture.

In conclusion, the book applies the frameworks of strategic culture and intelligence culture to a real-world case of security performance. This perspective does not only apply to Israel. In the US, for instance, it can allow critical introspection of the recent conflict with Iran, including the repeated experienced surprise the US seems to be experiencing. Furthermore, understanding partners’ and allies’ cultures, and not just adversary ones, is an imperative. Especially for American scholars and practitioners. The book makes an important contribution to this perspective. At the end of the day, national security is all about people. Society and culture play a major role.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Ukraine Is No Longer the Country Russia Thought It Was

31 August 2026 at 14:29

Understanding a country's strategic culture helps assess how it will react to crisis, negotiation, and national security events. Strategic culture generally is static and when it evolves, it happens slowly, as history, events, and culture accumulate over generations. In 2021, the prevailing view of Ukraine’s strategic culture was that it was a country focused on securing its national identity and sovereignty apart from Russia and it was a country prone to rely on negotiations and diplomacy. The balance between these two themes was about even with Ukraine leaning toward diplomacy and multilaterism over sovereignty when pushed by the international community. Most students of strategic culture did not assess that Ukraine would react to a Russian invasion with the military force that it has. Now students of strategic culture see the theme of independence and sovereignty as the key aspect of Ukraine’s strategic culture with a growing theme of being modern day military experts. The rapid transformation of the assessment of Ukrainian strategic culture is astounding. Either strategic culture academics got Ukraine wrong, or the Russian invasion changed Ukraine cataclysmically. I suspect it is a bit of both.

Strategic Culture

Strategic culture refers to a nation's shared beliefs, assumptions, and habitual behaviors regarding the use of force and the pursuit of security objectives. Jack L. Snyder introduced the term in 1977, arguing that a state's behavior cannot be explained by material capabilities or geography alone, but by those factors combined with history, cultural norms, and shared societal beliefs. Strategic culture is generally resistant to change. While it is often invoked to explain Russia's decision to invade Ukraine — its relevance to Ukraine's response has been comparatively overlooked.

Ukraine's Early Strategic Culture

Ukraine's strategic culture has been shaped by centuries of foreign domination and by its Soviet legacy. Early studies of strategic culture in independent Ukraine identified securing a national identity separate from Russia as the paramount objective. Those same early studies concluded that Ukraine favored diplomatic engagement, multilateral cooperation, and alliance-building over military action — pointing to Ukraine's surrender of its nuclear arsenal after the Soviet collapse and its acquiescence to Russia's 2014 seizure of Crimea as evidence. But this reading likely mistook constraint for preference. Ukraine was a newly independent state with a fledgling security establishment and military; it lacked the structure and capacity to stand up to either the United States or Russia, both of which pressed it toward disarmament and restraint. And, while significant events, neither of those two events were an immediate threat to Ukrainian independence. What looked like a cultural preference for negotiation may have been the best available option available for a young, under-resourced state. This misreading of Ukrainian resolve and strategic culture set Russia up for a catastrophic miscalculation that has cost over a million lives and will take decades for both countries to recover from.

The first principle of Ukraine’s strategic culture — safeguarding a distinct national identity — endures today. But the second focus on diplomacy and multinationalism-- has changed. If successful, the Russian invasion would have meant that this first principle would have to be abrogated and Ukrainian identity would once again have been subsumed by Moscow. Ukraine could not tolerate that: fighting for independence and Ukrainian identity outweighs alliance-building and negotiations as the organizing goal of its strategic culture. Today, Kyiv increasingly foot stomps aspects of Ukrainian identity that were suppressed under Soviet rule, and its foreign policy has grown more assertive, favoring offensive posture over purely defensive behavior. What has emerged is a culture that balances patience for international negotiation with adaptability and a hardened determination not to be conquered again, at any cost.

Two Defining Characteristics

Two characteristics of Ukrainian strategic culture stand out as key to explaining Ukrainian resistance to Russia:

Ukraine's growing emphasis on its Cossack heritage appears designed to construct a new state myth and reshape national self-perception from one of victimhood to one of warrior. Invoking the Cossacks — a self-governing, democratic, and militarily capable community prone to raids and revolt — underscores both Ukraine's independence and its capacity for military action. Domestically, images of the great hetmans now appear more prominently on currency and in textbooks.

Ukrainian strategic culture rests on the primacy of sovereignty, independence, and territorial integrity — values Russia has threatened or dismissed both historically and in the present. Language has become a central tool of this identity claim: early post-independence legislation established the primacy of Ukrainian language to rebuild a cohesive national identity, and that legislative push accelerated around the outbreak of armed conflict in 2014, alongside a marked cooling toward proposals to formalize Russian as a second official language. For Ukrainians, language is intrinsic to national identity. I recall being tutored in Ukrainian by an émigré in the late 1980s; he was a tough teacher, and he would grow angry whenever I mistakenly lapsed into Russian even though it was our common language and at times the only language in which we could communicate.

Ukrainian Strategic Culture Today

Ukraine's strategic culture now manifests as an asymmetrical, creative approach to security — one that offsets comparatively limited military resources with international partnerships, novel approaches to warfare, and disciplined strategic messaging. It emphasizes flexibility, resilience, gray-zone tactics, and pragmatic decision-making. Increasingly, we are seeing Ukraine promoting its tactics and military resources internationally.

Ukraine's strategic norms are still evolving, but the trajectory since independence is clear: independence and ingenuity have become the paramount, defining components of Ukrainian strategic culture, expressed through firm state priorities. A lasting orientation toward the West, paired with renewed emphasis on Slavic and Cossack roots, matters too, if somewhat less centrally. Above all, a study of modern day Ukrainian strategic culture tells us that Ukraine will do what it must to preserve its hard-won independence — while still maintaining its position as a respected leader within the global community.

Recently, the new Ukrainian Minister of Defense, Yevhenii Khmara, said

”Ukraine has always seen tragedy. Its history is a long inventory of it. What separates this generation from all the ones before is that it has a real chance to defeat the enemy.”

This tells you a lot about the mindset of senior Ukrainian decision makers and how they are messaging their people and the international community.

Why it Matters

Understanding Ukrainian strategic culture helps us to determine what approach to take to help end the war in Ukraine. Paramount for the country is ensuring Ukraine’s sovereignty and independence. For Ukraine, that is nonnegotiable. Any negotiating concepts that leave room for other nations to impose themselves on Ukrainian decision making is a nonstarter for Kyiv. Recognizing Ukraine’s sacrifices not only in the last four years but the tragic historical road they have been on with pre Soviet Russia and the Soviets will go far in any negotiations. Finally, acknowledging and highlighting how well Ukraine has out played Russia would also go a long way. Next, I will present Russian strategic culture and then discuss where the two clash.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Foreign Spies Don’t Need to Hack You Anymore

26 August 2026 at 13:43

Andy Burnham was a few weeks into the job as the new Prime Minister of the UK when he found himself exchanging messages with someone claiming to be Susie Wiles, the White House chief of staff. The exchange, first reported by Politico last week, was brief and apparently trivial. Burnham grew suspicious, stopped replying and told the right people; the British embassy in Washington quietly informed the White House, which confirmed that Wiles’s own devices hadn’t been touched. No harm done, officially.

Embarrassments like this are becoming more common. The FBI warned last year about impostors using AI to mimic senior officials, after someone posing as Wiles contacted senior Republicans and business figures. The State Department later chased a fake Marco Rubio who reached three foreign ministers. And every one of these approaches lands on a habit “Signalgate” already exposed: when one wrong contact card could add a journalist to a strike-planning thread, the name on the screen was the only authentication in the room. If you want to see what this security weakness looks like run as a nation-state campaign look at a case that closed quietly in Taipei last month.

In July, prosecutors in Taipei’s Shilin district wrapped up proceedings against two local businessmen, Li Hualun and Chen Mengsen, who had spent months registering accounts on LINE (the messaging app nearly everyone in Taiwan uses), each tied to a real Taiwanese phone number. They leased the accounts to Xiamen Empress Information Technology, a mainland firm Taiwanese investigators say works under the direction of the Chinese Communist Party’s cyber forces. The going rate was about 1,100 RMB per account, call it $160.

A working exploit for a major platform costs millions on the gray market. A trusted local identity cost less than a decent dinner, and it did something no technical exploit can do.

The operators used the fake accounts to become journalists. In the approach that eventually unraveled the scheme, one of them even dressed up a leased account in the name and photo of Chen Yishan, editor-in-chief of CommonWealth Magazine, and began courting an aide in a legislator’s office. Interview requests, invitations to contribute articles, the ordinary traffic of political journalism followed.

There was no malicious link in the first message, or the tenth. Investigators found the operators worked on targets for months, sometimes close to a year. Any counterintelligence officer would recognize the rhythm. It was the patient cultivation and recruitment of an agent run through a chat app.

The eventual ask was small and reasonable-sounding. Journalists use encrypted tools to protect their sources, so would the contact mind installing a secure communication app to keep talking? The app was in fact malware. The MO turns a decade of good security advice inside out. The more someone knew about how careful reporters actually operate, the more normal the request looked.

Researchers at Citizen Lab and the International Consortium of Investigative Journalists, whose reporting the Taiwanese prosecution now corroborates, counted more than a hundred malicious domains behind the wider campaign, and found errors in the phishing messages suggesting the attackers were using AI to draft them and to pick targets. The people on the receiving end were lawmakers and their staffs, defense think tanks, semiconductor companies, dissidents at home and abroad. Taiwanese media reported that even the island’s overseas missions were probed.

Through all of it, nothing technical failed. The networks held and the patches were current. The attackers went around the security stack entirely, and the thing they spent, their actual operational currency, was the credibility of a free press. Every fake interview request makes the real ones a little harder. This cost never shows up in an incident report.

The two men who supplied the accounts got deferred prosecutions and payments totaling a bit under $6,000. That is the current legal price, in a frontline democracy, for renting identity infrastructure to a foreign intelligence service. It isn’t a deterrent. It’s barely a business expense.

Which brings us back to Downing Street. A prime minister with the full apparatus of British intelligence behind him replied to a stranger because the name on the screen looked right. Nothing in either story depends on LINE, or Taiwan, or Westminster.

Swap in WhatsApp or LinkedIn; swap the fake editor for a fake recruiter or a fake chief of staff. Aged, locally registered accounts are already a commodity in criminal markets. All the model requires is a person who handles something worth stealing and a persona they have no fast way to check.

That last part is fixable, though not by the security team alone. Organizations that handle sensitive work should treat identity verification as a counterintelligence habit. Platforms need to treat the account-rental trade Taiwan uncovered as the national security problem it has become rather than a terms-of-service nuisance. And legislatures need to punish collaboration with foreign intelligence services at something above a traffic ticket.

Mostly, though, the people likeliest to be approached — the legislative staffer, the fab engineer, the think-tank fellow, the human rights activist, apparently the occasional head of government — need to become more educated on how foreign intelligence cultivation and targeting actually works: slowly, warmly, and with no suspicious link in sight until the very end. The adversary in this case looked at hardened networks and vigilant software and made a rational choice. Building a fake trusted persona was cheaper — $160 a head – than spending millions on a sophisticated cyber exploit. We need to start defending the credibility of verified, trusted identifies the way we defend our networks: as the attack surface it already is.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Military Interoperability: The Coalition Challenge of Limited War

21 August 2026 at 08:57

In our last two articles for The Cipher Brief, Sami Omari and I explained why modern limited wars are so challenging for democracies.

We argued that military superiority is necessary but not sufficient for strategic victory: Afghanistan and Iraq showed that battlefield success does not guarantee lasting political outcomes, and Iran may yet prove the same point.

We also examined why democracies struggle to translate tactical success into strategic achievement: fragmented institutions, electoral cycles, public opinion and media scrutiny complicate the political resolve required for prolonged wars of choice.

The challenge becomes greater when democracies fight as coalitions.

Alliances combine military power, share costs and draw on capabilities few states could sustain independently.

But military integration does not produce political unity.

Each member remains accountable to its own electorate, parliament and national interests. A coalition may therefore be highly integrated on the battlefield while remaining politically and strategically decentralised.

In prolonged limited wars, military interoperability is not enough if allies cannot sustain the political will, industrial capacity and common strategic purpose required to endure.

II. Why Democracies Fight in Coalitions

The nuclear age made direct great-power war prohibitively dangerous, shifting competition towards limited wars, insurgencies and proxy conflicts.

Western militaries increasingly moved towards smaller professional forces equipped with more advanced weapons, shaped by technological progress and new strategic realities.

After 1991, the Gulf War and subsequent operations against weaker adversaries appeared to vindicate the effectiveness of Western expeditionary forces.

But smaller professional militaries and increasingly expensive weapons also made allies progressively dependent upon one another. Coalitions allowed democracies to aggregate military power, intelligence, logistics and specialised capabilities without each maintaining the forces and industrial capacity required for large-scale national mobilisation.

For thirty years, that system seemed to work.

Russia’s war against Ukraine has exposed these vulnerabilities over several years; the US-Israeli war with Iran is now testing many of the same assumptions.

Both demonstrate that limited wars can become contests of manpower, industrial capacity and political will.

Of these pressures, political endurance is perhaps the most difficult for democracies to sustain.

III. The Political Endurance Problem

For democracies, fighting a long, limited war depends as much on political legitimacy at home as on military capability.

In wars of choice, where national survival is not at stake, governments must continually justify why the costs of war remain necessary.

Initial public support may create space for intervention, but it erodes as casualties rise, costs accumulate, and the prospect of a clear strategic outcome grows uncertain.

Casualties alone do not determine support.

Democratic societies have accepted heavy losses when citizens believed a war was legitimate, necessary and winnable.

The deeper problem emerges when the link between sacrifice and strategic purpose becomes unclear. As confidence in success fades, losses that once seemed tolerable turn politically damaging. Elections, parliamentary opposition, media scrutiny and changes of government then allow declining public confidence to reshape national strategy. Afghanistan illustrated this over two decades.

Western military superiority was never in doubt, but political will steadily weakened. The longer the war continued without a convincing political end state, the harder it became for democratic leaders to explain what more time, money and lives would achieve.

Authoritarian states face similar pressures but, without competitive elections and independent media, can better insulate strategic decisions from public opinion.

Against democratic opponents, this creates a critical asymmetry: a weaker adversary may not need to win militarily, only survive long enough for democratic political will to erode.

IV. The Industrial Endurance Problem

Political endurance is only one side of the problem. The other is material.

Since the Cold War, Western militaries have increasingly relied on technology instead of mass.

Smaller professional forces employ sophisticated aircraft, ships, missiles and networked systems aimed at achieving decisive results while minimising casualties. But each generation of weapons is more expensive and complex, production runs shrink, and replacing battlefield losses becomes harder as war drags on.

The United States can absorb these pressures better than smaller allies because of its defence budget, technological base and industrial scale.

Even so, American forces became smaller, while defence-industry consolidation reduced the number of manufacturers capable of producing specialised weapons. For smaller allies, limited budgets forced difficult choices between personnel, platforms and munitions, while dependence on American weapons, software, supply chains and sustainment deepened.

Quick wars against weaker opponents long obscured these problems.

Ukraine has brought them sharply to the surface, while the Iran conflict is testing them anew. Advanced weapons can be consumed faster than peacetime factories replace them, while cheap drones and missiles allow weaker states to impose continuing costs on advanced rivals.

This creates an uncomfortable paradox.

Military interoperability strengthens coalitions on the battlefield but also creates industrial dependencies that are difficult to escape. In long, limited wars, technological superiority matters only as long as the coalition can afford, produce and replace what it consumes.

V. A Coalition of Decentralised Systems

Coalitions do not solve the political endurance problem; if anything, they make it worse.

Integrating militaries does not erase national sovereignty. Allied forces can share command structures, intelligence and interoperable systems, but each government still answers to its own voters, parliament and interests.

Afghanistan made that painfully obvious. NATO operated under one mission on paper, but contributing states imposed their own caveats and restrictions on where and how their troops could operate.

Those caveats were not bureaucratic quirks; they reflected different domestic political pressures and appetites for risk. They made burden-sharing and coalition cohesion harder than the unified-command narrative suggested.

Of the contemporary great powers, the US above all can supply the backbone of an international military coalition: intelligence, logistics and advanced capabilities.

What it cannot do is fuse the sovereign political systems behind every other contributor.

Middle and smaller powers like Australia and Canada still matter because they bring niche capabilities, diplomatic weight and political legitimacy while operating inside their own domestic constraints.

Coalitions may fight as one integrated military network, but the statecraft holding that network together stays stubbornly decentralised.

VI. From Military Interoperability to Strategic Interoperability

This gap between integrated military networks and decentralised statecraft is the central weakness of contemporary coalition warfare.

Modern limited wars therefore require more than military interoperability. They require strategic interoperability.

Sovereign allies must be able to coordinate military, political, economic and industrial power to pursue and sustain a common strategic objective.

This does not mean supranational government or surrendered sovereignty, but unity of strategic effect even when national policies differ.

In practice, this could involve standing allied mechanisms that integrate political planning, defence production, economic measures, strategic communications and military operations around an agreed political end state before a crisis becomes a prolonged war.

Conclusion

Across these three articles, we have argued that military superiority alone cannot guarantee strategic victory; that democratic institutions often struggle to turn battlefield success into sustainable political outcomes; and that these difficulties multiply when democracies fight as coalitions.

The endurance of democratic alliances will depend on more than their ability to fight together.

Sovereign governments must sustain public support, share political and military burdens, and remain committed to common strategic purpose when conflicts become longer and more costly than expected.

Democratic accountability need not become a strategic weakness, but preserving sovereignty while sustaining collective action will require greater political cohesion.

The ultimate obstacle is not technology or concepts, but political will: overcoming domestic divisions and institutional rivalries to sustain common purpose.

As the era of AI unfolds, technology will keep changing warfare, but it cannot repair the organisational weaknesses of those who use it.

Strategic interoperability ultimately depends on whether democracies can find the will to build it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Open-Source Intel Makes U.S. Troops an Easier Target for Iran

17 August 2026 at 14:32

Iran is reading American service members’ social media feeds to deadly effect. The fact is that not all intelligence must be gleaned from secret, closed sources for it to be effective, and Tehran has made use of public and open-source data to target U.S. forces with psychological and kinetic attacks. Until the Pentagon updates and enforces its policies on social media posting and personal device security, American servicemembers will be sitting ducks.

Admiral Brad Cooper, the commander of CENTCOM, warned in a letter last month to U.S. forces that Iran is using social media posts from personnel, such as footage of U.S. bases, to improve its lethality. For example, a video of soldiers running for shelter during Iranian strikes helped Iran perform a battle damage assessment of their strikes, including their precision, and understand base layout for future attacks.

Iran has long exploited open-source data to target U.S. forces and allies. Two years ago, Iran doxxed 2,200 Israel Defense Forces personnel relying exclusively on open-source data. In April 2026, the Department of the Navy warned service members that unnamed cyber adversaries (obviously referring to Iran) are reaching out on social media and conducting phishing attacks, urging sailors to turn on privacy settings and refrain from posting on social media. The same month, Iranian hacker group Handala sent threatening WhatsApp messages to U.S. troops and published the supposed personal information of 2,300 U.S. service members stationed in the Persian Gulf.

Open-source data is broader than just Instagram and Facebook. Iran exploits data breaches to collect information and identify and send text messages to former Israeli defense personnel to threaten them and to attempt to recruit them for espionage purposes.

Iran is exploiting Signaling System 7 (SS7), an older telecom protocol for roaming, to identify devices with U.S. SIM cards, according to threat intelligence platform Mobile Surveillance Monitor. Using SS7, Iran was reportedly able to pinpoint hotels that housed U.S. personnel and contractors.

Iran can also simply buy data for its malicious campaigns. CENTCOM stated in a letter to Sen. Ron Wyden (D-OR) that it has been warned that Iran may have used commercially available location data used by digital advertisers to “target and surveil” U.S. personnel. While the phone numbers behind advertising IDs are anonymized, Iran could use them to track devices in specific areas such as military bases. The Pentagon conceded that these IDs are not yet disabled by default on government-issued phones.

None of these vulnerabilities should be a surprise to defense officials. A U.S. Government Accountability Office report from October 2025 found that social media posts from service members and their families or friends provide adversaries with names, ranks, and locations that can be pieced together to reveal information about U.S. force formations and operations. Wyden and his Democratic and Republican colleagues in the House and Senate sent a letter to the Pentagon’s chief information officer in May 2026 urging more secure personal data practices and blaming current vulnerabilities on the department’s “failure to prioritize this threat and implement common sense cyber defenses recommended by federal cybersecurity experts.” The House version of the annual defense bill, meanwhile, calls for the department to better understand and train personnel about how adversaries can exploit commercial technologies to identify and monitor U.S. personnel.

To curb adversarial intelligence collection opportunities, the Department of Defense (DoD) should expand operational security requirements across the force.

First, the DoD should harden government and personal devices by requiring removal of all Mobile Advertising IDs (MAIDs) on personal and DoD-distributed devices for personnel in sensitive areas. Without IDs, the locations and metadata cannot be tracked or associated with individual users and sold to adversaries posing as commercial buyers.

Next, the DoD should create and enforce stringent policies for social media posting. Personnel should be prohibited from uploading unofficial photos and videos of military facilities or that otherwise relate to their roles and should limit the amount of information they post about their roles on platforms like LinkedIn. Government devices should have their cameras disabled or removed unless required for specific purposes, and GPS should be disabled by default. DoD should also consider providing troops with alternative devices for personal use with GPS disabled and the cameras removed.

Additionally, the DoD should monitor breached data to understand what is publicly available about all its personnel. Knowing when data is exposed will allow the DoD to identify potential threats before Iran acts and begin fixing the issue as soon as it occurs. The department can also use this information to enable mandatory password and credential rotation when information is exposed. The Pentagon should also consider encouraging or requiring additional methods of authentication, such as passkeys and biometrics, for all devices and accounts

Finally, Congress should pass regulatory reforms to transition from SS7 to new signaling technology. SS7 is an outdated system and cannot guarantee secure communications, even if new updates were to be completed. Changing the system will allow service members abroad to communicate with loved ones without leading adversaries to their location.

These measures will limit the open-source data that, at present, is readily available to Iran and other adversaries. If the DoD continues to permit unrestricted use of personal devices abroad, Iran and other adversaries will continue exploiting their vulnerabilities to locate, study, and threaten American forces.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Inside Iran’s New Wartime Leadership

17 August 2026 at 09:47


Tehran’s new power brokers

A wave of assassinations rebuilt Iran’s leadership from the top down, leaving a severely wounded supreme leader and a security establishment now calling the shots. Tehran, however, isn’t saying who is actually in charge. The silence is part of the narrative; who are the country’s power players?

Earlier this month, Iranian state media did something it had never done before.

Mehr News, an outlet controlled by the country’s Islamic Development Organization, released a video titled “First Images of the Leader,” showing Supreme Leader Mojtaba Khamenei addressing a small group of students. The footage was undated. It came, however, days after Israeli outlets reported the 56-year-old cleric was in “extremely critical condition,” and it appears to have done little to settle the question consuming Iran’s political class: is anyone actually running the country right now.

The clip echoed a similar undated video IRIB released in March, showing Khamenei teaching religious sciences. President Masoud Pezeshkian acknowledged this week that reaching him has been “very difficult,” though he described their last exchange as constructive.

Multiple sources close to Pezeshkian’s administration told IranWire that no cabinet minister has met with Khamenei since the February 28 strike that killed his father, Ali Khamenei, and that officials “would not be surprised” to hear news of his death.

Iranian authorities have repeatedly denied he’s incapacitated. But the man now holding life-tenure authority over Iran’s armed forces, judiciary and clerical establishment hasn’t spoken publicly, delivered a sermon, or appeared unedited on camera since taking the post in March.

“The main issue for U.S. policymakers — especially any president — is whether the new leadership in Iran, or any leadership we can currently anticipate, is likely to depart materially from the strategic policies of the previous leadership,” Norman Roule, a former CIA officer who spent 34 years managing programs related to Iran and the Middle East, tells The Cipher Brief. “The evidence to date suggests no fundamental break.”

The vacuum at the top didn’t stay empty for long.

A Leadership Rebuilt Through Killings

The cascade began on February 28, when a joint U.S.-Israeli strike killed longstanding leader Ali Khamenei along with Mohammad Pakpour, the Islamic Revolutionary Guard Corps’ commander-in-chief, and a string of other senior officials. An interim leadership council, made up of Pezeshkian, judiciary chief Gholamhossein Mohseni-Ejei and cleric Alireza Arafi, held the state together for less than a week before the Assembly of Experts named Mojtaba Khamenei as Iran’s third Supreme Leader on March 8.

The choice was unusual on its face. The Islamic Republic was founded on the overthrow of hereditary monarchy, yet its clerical establishment had just installed the son of the man he replaced. Mojtaba lacked the religious credentials typically required of a Supreme Leader. He was widely regarded as a hojatoleslam, a mid-ranking cleric, rather than an ayatollah — yet he had spent nearly two decades as his father’s gatekeeper and enjoyed deep loyalty inside the Revolutionary Guard.

President Trump, who had labeled him “unacceptable” during the war, later told Fox News that the succession was not one his own father had wanted, adding, “their leadership is gone, their second leadership is gone, now their third leadership is in trouble.”

Roule, however, cautions against reading the new bench as a break from what came before it. Most of Iran’s current leaders, he notes, “rose within institutions shaped by Ali Khamenei and were trusted, promoted, or shaped within, and by the system he developed over years of rule.”

Roule points to the generational math: Pezeshkian, Mohsen Rezaee and Ali Reza Zolghadr were about 25 years old at the time of the 1979 revolution; Ahmad Vahidi was 21; Mohammad Bagher Ghalibaf and Sadeq Amoli Larijani around 18; Mojtaba Khamenei just 10.

“For this group, the 1979 Revolution remained the ideological foundation of the system, but the Iran-Iraq War and the post-2003 campaign for regional influence were more important professional experiences,” Roule explains. “Most are veterans of the Iran-Iraq War or were directly shaped by it.”

The current command of the Islamic Revolutionary Guard Corps has followed the same brutal pattern.

Amir Ali Hajizadeh, head of the Guard’s aerospace force, was killed in a strike in June 2025. Pakpour, who had succeeded Hajizadeh’s predecessor Hossein Salami, was killed at the outset of the U.S.-Israeli campaign in February. His successor, Ahmad Vahidi, a Quds Force founder and former interior minister with an Interpol red notice tied to the 1994 AMIA bombing in Buenos Aires, was formally installed as commander-in-chief on March 1.

Unverified reports of Vahidi’s own death circulated in Tehran in late May and again in early June; Iranian, Israeli or American officials have confirmed none, and Vahidi continues to be listed as the IRGC’s active chief.

A Crackdown That Fits the Moment

The uncertainty at the top has coincided with a sharp rise in executions and threatened executions, months after the January protests that shook the regime.

Austin Sarat, a professor of jurisprudence and political science, says the war and the unrest have compounded each other rather than one driving the other alone.

“The protests and the war have fueled — it’s like putting a little bit of an accelerant into something that’s already pretty flammable,” Sarat tells The Cipher Brief. “The protests were, I think, much more trigger than the war itself. The war has just provided yet another excuse, because it’s jacked up nationalist fervor.”

Sarat is skeptical that outside pressure, including past White House rhetoric threatening consequences over executions, has had much bearing on Tehran’s calculus.

“The administration has said nothing about human rights abuses, let alone execution practices around the world,” he says, underscoring that any outside leverage is more likely to come from Europe than Washington. He views the surge itself as a familiar survival tactic for a leadership still finding its footing.

“It’s not a kind of unfamiliar tactic for a regime new to power to want to flex its muscle and terrorize the population,” he observes. “This is a survival moment, and they are going to do what they are going to do to preserve the essential character of their regime.”

The Guard Consolidates Around the Vacuum

With the younger Khamenei largely unseen, the Revolutionary Guard didn’t sit on its hands. It moved fast, filling top posts through official decrees.

Along with Vahidi, the Supreme Leader’s office named Mostafa Izadi as deputy IRGC commander, Ali Azmaei to head the IRGC Navy and Hossein Taeb to lead the Basij paramilitary force, filling six senior military posts vacated by wartime deaths.

Mohsen Rezaee, who commanded the IRGC from 1981 to 1997, was separately appointed as the Supreme Leader’s representative on the Supreme National Security Council. This post opened up, according to Rose Kelanic, director of the Middle East Program at Defense Priorities, after Zolghadr was pushed out.

Kelanic argues the reshuffle amounts to more than a personnel change.

“Mojtaba Khamenei’s role appears to be that of a figurehead and potential scapegoat, enjoying far less authority than his father, whom he replaced,” Kelanic tells The Cipher Brief. “The real power rests with Ghalibaf, Vahidi and Rezaee, who are all career IRGC officers, which functionally means that Iranian government authority has shifted even further from civilian control to military control.”

That shift, she continues, carries its own risk for any settlement with Washington.

“When military leaders assume control as heads of state in wartime, they tend to make worst-case assumptions about adversaries’ intentions, view compromise as weakness, and favor offensive military strategies over defensive ones,” Kelanic points out.

Roule, meanwhile, frames the Guard’s rise in institutional rather than personal terms, and says the war has widened rather than preserved its reach. Estimates of how much of Iran’s economy the IRGC touches “vary widely — roughly from a fifth to a third,” he says, depending on whether one counts only directly controlled firms or also affiliated holding companies, pension funds and sanctions-evasion networks.

“A better way to think about the IRGC is not simply as a military organization with commercial interests, but as a central actor in a state-security-economic network,” Roule notes.

Ghalibaf’s Quiet Climb to the Center

The other figure benefiting from the uncertainty at the top is Ghalibaf, the parliament speaker and former IRGC commander who has spent the war years turning what is traditionally a legislative post into something closer to a shadow foreign ministry.

Ghalibaf, a two-time presidential also-ran who trailed Pezeshkian in the first round of the 2024 election, has emerged as Tehran’s principal interlocutor in the indirect talks with Washington, serving simultaneously as Iran’s special envoy to China and as a bridge between the political and military-security establishments that Pezeshkian, a physician by training with no roots in the security services, has struggled to command.

Parliament re-elected Ghalibaf to a seventh consecutive term as speaker in late May, with 235 of 271 votes cast, as reports circulated of friction between Pezeshkian and the new Supreme Leader’s office. Judiciary chief Mohseni-Ejei congratulated Ghalibaf on the vote by calling him a “tireless and battle-hardened jihadist leader” who had waged jihad “both in the field and in diplomacy” during the war.

Roule warns against reading Ghalibaf’s prominence as a formal power grab.

“His current prominence should not be confused with general supremacy over Pezeshkian,” he says. “Pezeshkian nonetheless remains president, heads the executive branch, and formally chairs the Supreme National Security Council. There is no evidence that Ghalibaf has assumed any of the presidency’s general constitutional authorities.”

His influence, Roule highlights, “is best understood as issue-specific power produced by circumstances, his political standing, longstanding IRGC relationships, and wartime delegation.”

Who Actually Holds the Reins

What emerges from the past five months of conflict, however, is a regime governed less by the clerical hierarchy that has defined the Islamic Republic since 1979 than by an overlapping wartime trio.

A Supreme Leader whose authority is formally absolute but whose physical capacity to exercise it remains unverified. An IRGC command structure rebuilt twice over through assassination and now operating with wide latitude, alongside a parliament speaker who has converted legislative standing into genuine diplomatic weight.

Still, Roule sees continuity as the most likely outcome even if Mojtaba’s health worsens further.

“If Mojtaba Khamenei becomes seriously incapacitated or dies, the most likely outcome absent a successful mass uprising or a major elite fracture is continuity rather than reversal on the issues of greatest concern to the United States,” he says. “The IRGC would remain a central power center, and the system has constitutional procedures for interim leadership and selection of a successor.”

He also points out that if Mojtaba’s death were tied to the war, “the state would almost certainly use a martyrdom narrative to reinforce regime legitimacy and resistance.”

Kelanic is less sanguine about what that continuity means for diplomacy. Iran, she stresses, will also grow harder to negotiate with simply because power is now split among rivals rather than concentrated in one office, leaving Washington without a clear address for any deal.

“The IRGC’s strengthened rule over a weaker civilian leadership makes reaching a peace deal harder,” Kelanic adds, “which is one of many ways the Iran War has backfired.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Biggest AI Models Are Not the Biggest Threats

13 August 2026 at 08:45

Almost every AI security framework we are applying rests on one misguided assumption: danger scales with size. Compute thresholds, export controls, and tiered evaluation regimes all encode the same intuition, the larger the model, the more we should worry. If this isn’t true, what policy changes are needed?

I recently mapped more than twenty fielded AI systems against two axes: raw offensive capability with safeguards stripped, and residual risk as actually deployed (Fig. 1). They ran from millions to trillions of parameter models, and included munition seekers, gene design models, theatre planning, cyber offense systems, and general-purpose AI models. The picture does not support the above assumption. In fact, the data supports the inverse. Small, specialized models beat bigger general models at offense, but bigger models maybe better at defense.

Figure 1. Security Risk vs Size of Model. Hollow ring: raw offensive capability with safeguards stripped. Filled dot: residual risk as actually deployed. Cyber related positions anchored to CAISI / UK AISI results, July 2026. Data compiled by Alvin W. Graylin.

Each system appears twice: a hollow ring for raw capability with safeguards stripped, a filled dot for residual risk as deployed. The gap between them is the safeguard effect. Read left to right, and the size to threat correlation everyone assumes is simply absent.

Seven assumptions worth rethinking

One: the largest models pose the greatest risk. The high-residual band, where capability and deployed risk are nearly identical. Across six orders of magnitude, no clear trend. In 2022, researchers at Collaborations Pharmaceuticals inverted the scoring function on a commercial drug-discovery model (MegaSyn) of under 100 million parameters and generated more than 40,000 candidate chemical warfare agents (many more lethal than VX) in just six hours on a desktop. Chemprop-class retrosynthesis models, which can find non-controlled precursor routes around scheduled pathways, run at one to ten million parameters. Evo models with single digit billions of parameters can help design novel life forms. News just came out last week that this exact system was able to generate 16 new viruses. All these systems sit well below the axis floor of any parameter-based regime. Compute restrictions do nothing to fix this.

Two: compute thresholds capture the relevant risk. Hackphyr, built on Zephyr-7b-β at 7 billion parameters, performs comparably to GPT-4 on network attack scenarios and runs on a single GPU. Deep Hat V2 ships commercially at 30 billion parameters, is marketed as uncensored for offensive security, and executes inside the customer environment with no external calls. No government evaluation covers it, so that placement rests on vendor claims. Neither would trip a FLOP ceiling.

Three: capability and threat are the same axis. Claude Fable 5 and Claude Mythos 5 share one underlying model. Their capability positions are nearly identical; their deployed risk differs sharply, because Fable's added domain safeguards drop cyber requests back toward Opus 4.8 behavior. The difference comes entirely from the safeguards and distribution controls layered on top. That vertical gap is what governance can act on. Parameter count is not.

Four: open-source models are more dangerous than closed ones. Recent NIST study found that Kimi K3, the strongest PRC open-weight model, only scored 32 percent on ExploitBench against 57 percent for the leading U.S. model, and reached step 17 of a 32-step attack range where U.S. models reached 28.5. On the highest-severity outcome test, arbitrary code execution (ACE), Kimi K3, succeeded on 0 of 41 tasks, while the most capable U.S. models averaged 20. So, we really need to be careful about self-interested parties saying larger open-source models are more dangerous, when it likely has more to do with protecting margins than national security concerns. (see Fig. 2)

UK AISI did recently report that the Kimi K3 model was able to escape its sandbox during testing, but it merely used a misconfiguration in the testing sandbox that left the door open, rather than a sophisticated swarm agent attack like what the OpenAI model did. And when it did get out, all it did was look up the answer for the test it was given, rather than doing any damage to real world systems. In the future, this behavior could change, but it’s important to question the basic assumption that open models are always more dangerous.

Figure 2: CAISI/NIST - Comparison of aggregate capabilities over time of the most capable U.S. and PRC models. A 400-point increase on the y-axis equates to a 10x increase in the odds of solving tasks. Shaded regions denote 95% CIs.

Five: model quality determines attack success. Microsoft's MDASH is a harness, not a model. It orchestrates more than 100 specialized agents across an ensemble and scored 88.4 percent on CyberGym at launch, against 83.1 percent for the Mythos preview model. Adding a compact security model roughly 1/10th the size raised that to 95.95 percent. The orchestration layer beat every individual model. Regulating training while ignoring scaffolding regulates the less important variable.

Six: national security requires the largest models. It requires the opposite. Loitering munition seekers performing automatic target recognition run on Jetson-class edge hardware, capping them in the single-digit millions of parameters. Edge deployment favors small models on latency, power, thermal envelope, and operation without a datalink. Larger models are slower and, in narrow domains, more easily distracted by irrelevant context. They are also harder to validate, and validation is what matters when a false positive is a struck target. Cisco's Foundation-Sec-8B matches or exceeds models ten times its size on security benchmarks while running on one or two GPUs. The famed DoD Maven Smart System is based on a fine-tuned 2-year-old Claude Sonnet 3.5 model. That level of intelligence can now be distilled into a 4B model which could potentially run on a smartphone.

Seven: denying China compute is the primary lever to keep U.S. safe. Due to shared risks between these superpowers, on many safety related issues, cooperating may actually produce the outcomes most beneficial to the U.S. and the world. More on this below.

Five threat domains, five different answers

Attack and embedded systems favor small models that don’t require a comm link. Air-gapped operation, no API telemetry, no rate limits, no refusals mid-chain. The offensive bottleneck is stealth and throughput, not reasoning.

Cyber Orchestration favors large models, but the advantage attaches more to the system rather than the model, as MDASH shows. There’s little discussion today on regulating orchestration systems, but it’s clearly very needed.

Cyber Defense favors large models most clearly, and this is where the current approach fails. Defenders need breadth across every vector; attackers need depth in one. Safeguards that constrain security research are therefore costly in a way that is easy to miss.

When Hugging Face's systems were breached in July by OpenAI models, commercial frontier-model APIs blocked the forensic requests because their safety systems could not distinguish defensive analysis from attack. The team ran the open-weight Chinese model GLM-5.2 on its own infrastructure instead, worked through more than 17,000 logged actions, and contained the intrusion. An American company under active attack by an American closed-model was defended by a Chinese open-source model because the American ones could not tell friend from foe.

That is a Slave AI failure, in the terms I set out in Beyond Rivalry. A model trained toward obedience can only refuse; it cannot reason about whether refusing is right. What we need is Guardian AI: systems capable and contextually aware enough to protect us from malicious actors, from other AI systems, and from our own unintended consequences. That requires scale, because judgment requires breadth. It also requires that we stop locking down every capability rather than stewarding it. High-quality models with fewer restrictions, in defenders' hands, are a global public good. Every hour a defender spends fighting a guardrail is an hour the attacker fights nothing.

Bio/Chem Design favors small models. Molecular graphs, protein sequences, and binding energies come from compact architectures immune to alignment techniques built for natural language. A graph neural network has no refusal layer to remove. The key here is monitoring and controlling access to precursor chemicals and expanding safeguard for synthesis equipment.

Bio Synthesis is the outlier, and there is good news and bad. For biology, model-level access control has already failed. Evo 2 shipped with weights, inference code, training code, and its full dataset. There is no API to revoke. What remains is the synthesis chokepoint: Customer vetting and sequence screening at nucleic acid providers already operate internationally through the Gene Synthesis Consortium, whose members screen orders against databases of sequences of concern before synthesizing. There are still gaps as novel AI-generated combinations are developed, but they can be reduced if vendors and regulators globally work more closely together to keep the systems updated. Closing those gaps buys more security than any parameter threshold. But this requires Washington and Beijing to align, since they are the two largest suppliers of synthesis equipment in the world. Of course, collaboration across all vendors globally is needed to truly secure this threat vector. Again, larger general AI models aren’t the core problem.

Data beats intelligence

On the opening day of the U.S.-Iran war in February, a Tomahawk missle struck the Shajareh Tayyebeh girls' school in Minab, killing at least 168 people, more than 100 of them children under twelve. The school sat within 100 yards of an IRGC naval installation and had been inside that perimeter until a wall went up around 2013. Targeting ran through the Maven Smart System, which generates roughly 1,000 target packages an hour. A preliminary investigation concluded the strike likely followed from outdated intelligence, and former officials said stale human-curated data, not AI, was to blame.

The school had a website. Free satellite imagery showed a schoolyard with a sports field. No model of any size prevents this, because the failure was in data lineage, not reasoning. A larger model querying the same stale record returns the same coordinates faster and with more confidence.

The China mistake

The threat model that matters is not Beijing reaching AGI first. It is a non-state actor with a 30-billion-parameter uncensored model, a good harness, and no return address. Small models proliferate regardless of jurisdiction and leave no attribution trail, and an unattributable intrusion between nuclear powers is an escalation problem before it is a technology problem. In that world, a China unable to defend its own infrastructure is a liability to global stability, not an advantage to Washington.

Beijing is already regulating its own labs more aggressively than any other market. Concordia AI's 2026 survey documents agentic AI security guidance, ethics review requirements, and binding obligations on consumer AI services that are already deployed and enforced. It should be noted that Chinese frontier safety research output grew roughly 60 percent year over year, with agent safety rising from 8 percent of new papers in early 2025 to 27 percent by early 2026. The caveat: only five of ten leading Chinese developers reported safety evaluation results on release. Shared standards here would make a difference.

As Fig. 2 showed, CAISI found the Chinese models less dangerous, but they also found GLM-5.2 answers sensitive biological queries at far higher rates than tested U.S. models, which is where PRC safeguards are weakest. In personally speaking with multiple Chinese labs, it’s clear that their lack of compute resources due to export controls has forced them to deprioritize safety demands vs. capability enhancement. Expanding safety testing compute resources, like what UK AISI has, to more countries could help improve AI safety globally, without fear of its misuse by rival nations.

The race framing is softening at home, too. More than 100 organizations, including Nvidia, Microsoft, Meta, IBM, Palantir, OpenAI and Google, have now signed the July 24 Open Weights and American AI Leadership letter opposing premature restrictions. Days later, Nvidia and roughly 50 partners launched the Open Secure AI Alliance to build open defensive models and agent harnesses, citing the Hugging Face incident as its founding case. Every participant has commercial exposure to a ban, so weigh the motives. But 8 of the top 10 models on OpenRouter in July are already open-source, and the industry has now reorganized around the proposition that open weights are defensive infrastructure.

Four Asks for September

Four asks follow, and Xi Jinping's state visit to Washington on September 24, the first in over a decade, is where they could land. Trump has said AI will be on the agenda.

Shared harm standards, not shared capability standards. Agreement on what constitutes an unacceptable capability, evaluated the same way in both countries, so that "safe" means the same thing in Shanghai and San Francisco. That’s clearly missing today and doesn’t require mutual trust.

A shared safety evaluation cluster. Chinese labs are compute-constrained, so safety research competes with capability research for scarce chips. Compute earmarked for evaluation and red-teaming is cheap relative to the benefit, and the benefit is global. An international testing facility open to any vendor institutionalizes it. Require publishing safety scores alongside capability benchmarks so safety investment earns a competitive return. Then, both Chinese and US labs would have no excuse not to test their systems.

An incident notification channel. The Nuclear Risk Reduction Centers, staffed continuously since 1987, exist because a misread signal costs more than talking. An equivalent for AI incidents where attribution is contested is cheap insurance. With the rising risk of bad actor attacks and false flag operations from non-state actors, this safeguard will be increasingly needed.

Capability non-development agreements. A capability never trained cannot leak. This matters more than denying Beijing another turn of the scaling crank. Beijing also wants to limit rogue actor misuse, thus agreeing on redlines in advance makes sense for both sides (no nuclear weapon command/control, no AI uplift to bio weapon design, no AI-attack on civilian infrastructure, no autonomous self-replication outside control environments [RSI]). General commercial models have no need for bio and chemical threat design, so keeping defense use case training only in military labs on both sides seems quite reasonable.

Another Asilomar moment

At Asilomar in 1975, molecular biologists imposed a voluntary moratorium on a class of recombinant DNA experiments, then built the containment framework that governed the field for decades. They acted before the capability matured enough to do real harm.

That view is starting to catch on in the AI labs now. On July 28, 1,200+ employees of frontier labs published Pacing the Frontier, asking Washington to support an international effort to build tools for deliberately slowing automated AI development. Signatories include top technical leaders at Anthropic, OpenAI, Meta and Google. The concern is recursive self-improvement (RSI) of AI that goes out of control. The logical extension is an explicit agreement not to implement it in frontier labs even once it becomes possible.

But this cannot stop at two capitals. If dangerous systems are small and cheap, a country with a modest research budget and a few hundred GPUs can build a competent offensive cyber agent or an inverted molecular designer. Within a few years, dozens will. Any regime binding only Washington and Beijing binds the two parties least likely to defect and leaves the growing middle untouched. A U.S.-China agreement is the necessary first move, not the finished structure, and it has to open immediately to third parties. That is how Asilomar's containment norms and the Montreal Protocol scaled.

Bigger AI is not more dangerous. Better orchestrated is more dangerous, less monitored is more dangerous, and irreversibly released is more dangerous. All three require cooperation with Beijing: orchestration needs shared harm standards, monitoring needs shared evaluation infrastructure, and irreversible release needs joint agreement on what never gets built. September 24 is a good place to start.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

There Will be Unseen Costs to be Paid over the War in Iran. Who is Weighing Them?

5 August 2026 at 11:01


EXPERT INTERVIEW – With an interim agreement expected as early as today between the U.S. and Iran aimed at reopening the Strait of Hormuz to shipping traffic, experts are assessing the short and long-term costs of any deal.

As negotiators work on an agreement to re-implement a ceasefire and restart negotiations aimed at curbing Iran’s nuclear ambitions, there are questions about whether Iran will end up with more control over the strait than it enjoyed prior to the war and about the hidden costs that could include impacts on the sanctions packages that the U.S. has been using as a diplomacy tool to try and keep Iran’s malicious activities in check.

Cipher Brief Executive Editor Brad Christian spoke in-depth with former National Intelligence Manager for Iran at ODNI Norm Roule about the current “operational pause” and about the unseen costs of any deal. Their conversation has been lightly edited for length and clarity. You can also watch the interview on The Cipher Brief’s YouTube Channel.

THE INTERVIEW

Norman T. Roule

Norman Roule is a geopolitical and energy consultant who served for 34 years in the Central Intelligence Agency, managing numerous programs relating to Iran and the Middle East. He also served as the National Intelligence Manager for Iran (NIM-I)\n at ODNI, where he was responsible for all aspects of national intelligence policy related to Iran.

Christian: The situation with Iran has continued to progress in ways that maybe people didn't expect or anticipate when this war started. How do you describe where we are right now in terms of progress toward ending this war?

Roule: Where we are right now is in a lull. This is an operational pause. We're not approaching a significant core agreement. This is instead a period of coercive restraint. It's not a ceasefire. And Iran has continued to attack ships, but you're seeing the U.S. restrain its response again here to give diplomacy a chance. The president is showing considerable restraint. At the same time, the assets we have in the region are immensely powerful, immensely capable, and very well led. So, they have everything they need to do to undertake the dramatic operations the president has discussed. The diplomacy itself that's underway is a challenge. Each side is describing it dramatically differently.

If you look at the position of each side, there has been a consistent trend. The U.S. will announce negotiations, and the Iranians will deny negotiations are taking place. A few days later, there will be indirect negotiations through regional parties, still accomplishing the same things, but we're not at the table to talk about nuclear issues, missile issues, or militia issues as originally discussed.

The Iran-Oman mechanism that's being talked about right now in the press is likely being overstated by the Iranians and by some who would believe that concessions to Iran are the appropriate outcome from this crisis. Here's why it's being overstated: If tolls of any sort are charged, what happens to a shipper who refuses to pay? How does work in association with sanctions that have been imposed by the United States? Are American ships and American-related ships, allowed to pay Iran money? Through what mechanisms, what channels? Will we sanction other countries for paying Iran money through these channels? Iran has dictated which countries can enter the Persian Gulf and the bulk of this channel is through Iranian waters, but according to press reports, the Omanis must tell the Iranians who is transiting south. Iran's parliament has said no enemy countries can transit. Are Israeli or Israeli-related ships then banned from the Gulf? These are these are hugely consequential questions that are being glossed over by those who would say, ‘well, a deal is being worked out’. But this situation does show that while the U.S. absolutely has the military edge, it is restraining itself, and that has given Iran an ability to influence some would say, ‘control the pace’ of shipping in the Gulf. That shipping continues, and I've seen reports that as many as five million barrels of oil a day are now moving through the strait, which is going to reduce the pressure on oil markets, but this remains an unreliable waterway. Insurance rates remain very high and will remain high. And the blockade, of course, remains in place. This is a very delicate situation.

We also have to consider what happens if the Houthis look at the Iranian Oman deal and say, we want the same deal regarding the Bab el-Mandeb. What is the premise to refuse that? What would we do if the Houthis responded in their own way to attacking ships in the Red Sea?

So, we're in a very consequential period. And this is a period consequential for Iran because they're also in dire need of economic assistance. Their inflation is about 70%. Unemployment is horrific in many locations. I've seen figures as high as forty to forty-five percent in some areas. And the Iranians of course are showing defiance and claiming this isn't a problem, but this has got to be touching their decision making. And I think that's something the White House is considering.

Christian: President Trump has been very clear on where he stands on the issue of paying fees for passing through the Strait of Hormuz. Why is Iran pushing this issue when there were no fees in place before the war started? Is this one of Iran's most powerful points of leverage that they have over the strait? How are you thinking about their position on these fees?

Roule: It's a good question and I'm not putting a value judgment on it. I've tried to remain neutral on these issues. But those who advocate for making a deal with Iran, you know, diplomacy comes with severe consequences. If Iran is able to acquire control over the strait, will that collapse the international sanctions regime? For example, if Iran is able to control the strait in this regard, can it dictate which food shippers can come into Kuwait? If Iran controls the strait, it now has a permanent foot on the throat of the international community. And the idea that if we just do this, we can then build on trust with an IRGC government has no evidence in reality. Now that doesn't mean that it may not happen, but those who say you can build on this are not producing an argument that makes sense. Iran would be able to inject considerable power projection into the region in an unprecedented way, gaining billions of dollars, and that money would inevitably go to its missile program and proxies. And those who talk diplomacy with Iran, and you can see this when you look at social media statements or foreign affairs articles. The authors who speak most passionately and eloquently about engagement with Iran can't seem to acknowledge that people will die as a consequence. Now, that makes me sound like I'm opposed to this but I'm just giving you all the reasons why this is a problem.

The region, of course, has no desire for Iran to have this capability. But they also have no desire for a missile and drone war. That you either have a drone war, missile war, or give in to Iran, those are usually statements made by people who aren't professional diplomats, professional policymakers or have little understanding of the regional issues. There's going to be some sort of path in the middle that works if we're to protect and preserve sanctions as our tool against Iran's terrorism and other activities and if we’re to protect and preserve the national sovereignty and security of these countries who are our partners.

Also in the details of this deal are questions over whether the U.S. military would be banned from the Persian Gulf. The Iranians would have to approve the passage of U.S. military ships, which of course we wouldn't agree to, but the Iranians could claim that as a violation and things could unravel. We're going to land in a gray area on this if diplomacy is to succeed and it may not succeed.

Christian: In public statements, President Trump seems to be losing patience with the process. The president has said before that if Iran doesn't make this deal, that's it and we've witnessed similar red line crescendo moments before. You mentioned the IRGC led government. It's clear that they are running the country now. It's not clear how the diplomatic process is working, certainly by historical standards. What are your potential measures of success or indicators that the diplomatic process has run its course and what are you watching as potential next steps?

Roule: Throughout the last twenty years, various administrations, Democratic and Republican, have each said the same thing that we will try every possible diplomatic option for as long as possible and that all responses remain on the table. But once we've shown the world that we have tried every diplomatic option and the Iranians won't take yes for an answer, won't take diplomacy for an answer, then we'll be justified in using force.

I've been in congressional testimony where I've had Republicans and Democratic State Department officials insist that was U.S. policy. And that is congruent with the President's statements. He's basically saying, ‘Look, I'm going to give them every opportunity to negotiate’ because the consequences of a much broader conflict for the region, for the Iranian people, for civilians, for the U.S. war fighters who are risking their lives in the region, all of this will come into play.

We do have the assets in the region and our leadership in the military force there is exceptional and highly experienced. And based on the nature of the attacks conducted by the U.S. military in recent weeks, one can deduce a couple of points.

The first is that we know a lot about Iran's military architecture. And second, Iran has very little defense against our attacks because we've seen very little air defense or port defense as a result. Iran only has an offensive capacity. And it's attacking civilian architecture as well as U.S. military bases, not being used by the U.S. military, but nonetheless, they're bases where we have that presence. But at some point, if you believe in international values, we we've got to stand with our partners to protect them in a way that is congruent with their national interest and leadership approaches.

Christian: Over the weekend, news reports indicated that the Gulf states were the ones that convinced President Trump to not escalate this war right now. Do you have a sense of where the Gulf states are right now in terms of their approach to President Trump, their approach to Iran?

Roule: I think you need to have several different pillars in mind. First, let's talk about what the Gulf States have done that has been quite successful. Their defense against Iran has been very, very successful as a result of years of engagement with the United States and with the U.S. private sector, which is playing a large role in their successes and will play a role in their future successes in terms of defending against cyberattacks and drone and missile attacks. No air defense is perfect, but the performance by the GCC has been exceptional. And they have protected three things that we should applaud.

First, they've protected their own nationals and their own infrastructure, which is the duty of every state. They're protecting millions of other citizens to include hundreds of thousands of Americans who live in the region. They're keeping American lives safe with their air defense. And last, they've protected the international economy, preserving through their energy flows and their handling of the situation, the ability to maintain stable energy prices and distillate impact on subsidiary industries. All of that is exceptional.

At the same time, we've seen the Saudi military crisply respond to Houthi aggression with surgical strikes, and the Saudi military joining with the United States on strikes on Iraq, which is a first. And it's also a demonstration of the quality of Saudi Air Forces in general. So, there's a sense of extremely close partnership between our militaries. But how they move forward, you know, it is their neighborhood, so how they move forward in a world where there could be a major attack on Iran is likely going to mean that they're going to face more missile and drone attacks. They're going to want a voice in this.

They know their region better than we do. We should respect that. And I think that's what you saw last week in the reports of phone calls to the president, where he gave diplomacy a chance and was about to move, and I believe he was serious, based on my understanding. But he also took into consideration partners, people who have lives on the line and are trying to defend the world's economy and know their neighborhood very well. So, I'm not unhappy with what's happened. I don't think you can criticize that. That's a natural, organic and appropriate process.

Christian: Let's talk gray zone just for a moment. We've seen reports recently that the hacks against the water infrastructure in Minnesota could have involved Iran. We've seen reports that China, although not confirmed, was planning to deliver air defense systems to Iran. There's no doubt about the cooperation continuing between Russia and Iran. What are you looking at that some of us may be missing?

Roule: Press reports confirm what many observers have cited, and that is that Iran's cyber activities have continued unabated since this conflict began. Indeed, before the conflict, against multiple actors in the United States and largely that's been successfully defended against by our national cyber architecture, as well as the architecture of our Gulf partners. The president has disagreed with the assessment on Minnesota and other places, but that does fit with the past pattern of Iranian cyber activity against SCADA and other systems in the United States. and has been a longtime target of Iran itself. It is an attack on our national infrastructure, if it's proven. And if proven and we don't respond to it, the people in Tehran are going to say, ‘Well, there's no reason we shouldn't continue to do this’. So, I think that issue itself is pushing the White House towards alternative actions besides diplomacy. And in fairness, it has been a traditional standpoint of multiple administrations to say how we respond. Is it at a time and way of our choosing? We don't respond symmetrically, you know, we don't do the exact same thing back. So, if the United States were to respond with airstrikes against Iran’s cyber architecture, which would probably be a good thing in a conflict, that is an appropriate proportional response just done differently. And it would be congruent with multiple administrations' views and statements as to how they will treat Iranian aggression.

Christian: What are you looking for next? What are you paying the most attention to?

Roule: As I mentioned, if you give Iran control of the Strait of Hormuz, you're going to have consequences, not only in terms of whether they will ever negotiate seriously with us, but what does it mean for the Red Sea, and all sorts of other things? And those who say, well, we can work past that usually aren't in the Gulf, usually don't have children fighting right now and usually won't pay the price of those decisions. Not to say they won't be made, but we need to be upfront on those costs, and some of the issues aren't being discussed.

What I'm looking for is the conversation about those costs. And if it doesn't happen, that's a bad thing for everybody. The other issue is I think we need to look at is how the U.S. is going to respond to continued Iranian aggression. When does the U.S. restrain itself? Right now, the president is clearly, as he's announced, looking at de-escalation. But if the Iranians continue to probe with cyberattacks and missile and drone strikes, they've got to be addressed in a way that says to Iran, that there is a material price to be paid for that.

In the negotiating channels, I would look for any evidence that the U.S. is now directly dealing with the Iranians. That's unlikely to happen in the near term. That doesn't mean that diplomacy isn't occurring robustly through our partners, but any evidence of direct negotiations with the U.S. would be a very significant uptick.

And last, I would look for someone to address the issue of how any payments to Iran, involuntarily or otherwise, will impact the sanctions regime. Failure to address that is irresponsible in a policy world and indicates that maybe that's not being taken seriously.

And maybe one more point, and that is we should expect rhetoric on each side, but we should focus on what happens on the ground via the effervescent statements that are so often in the media.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

Why the Iran War Remains Strategically Adrift

4 August 2026 at 08:35

“I do think there's a lot of evidence to believe that we're accomplishing the military objectives [of the Iran War], which is destroying the Iranian Navy, the Iranian Air Force, their air defenses, the missile production capabilities, drone production capabilities. That's going well. But how that translates into strategic success has been, I think, the weakness in this entire operation and continues to be today. And I think that if we were to take a step back to February [when the Iran War started], and think about where we are today, I don't know that this would be in our theory of success. It would probably be a branch plan that would not be going so well. And I'm worried about that.”

That was retired-Air Force Lt. Gen. S. Clinton Hinote, former Deputy Chief of Staff for Strategy, Integration, and Requirements, now a professor of policy analysis at the RAND School of Public Policy and a non-resident adviser to the Center for Strategic and International Studies (CSIS) Aerospace Security Project.

He was speaking on July 23, at a CSIS event, The Air Campaign Returns: From Epic Fury to Midnight Hammer, along with retired-Air Force Gen. James Slife, former Vice Chief of Staff of the Air Force, former Commander of Air Force Special Operations Command, and also a non-resident adviser to CSIS’ Aerospace Security Project.

The two former senior Air Force officers not only gave their frank views of the Iran War, but also discussed the future of warfare and its impact on the Air Force and other U.S. military forces. I will start with their views on Iran and the war and then move on to other subjects they dealt with.

Since the Strait of Hormuz is central right now, let’s begin with their views on the Strait which I found inciteful.

Ret.-Gen. Slife began by pointing out, “Military planners have struggled with the Strait of Hormuz challenge for years and years. I mean I don't think it's any surprise to anybody that's paying attention to how this has played out, because geography favors Iran in the Strait.”

Slife continued, “I mean they [Iranians] have three sides of the Strait of Hormuz, right? It's a very narrow waterway. It's very shallow. The ability to maneuver inside the Strait is very limited. It's crowded. I mean there aren't a lot of great options.”

Then, as a former Air Force commander he offered the following views: “I mean, frankly, if there was a great option for how air power could unblock the Strait of Hormuz, it would probably be unblocked at this point. There are things that I think the air component is doing in conjunction with the naval component to target the means that Iran uses to exercise control over the Strait. But it is a very difficult problem. Geography just doesn't favor us in this regard.”

Ret.-Lt. Gen. Hinote added, “I think we're dealing with the problem of small numbers,” and then explained, “The [U.S.] joint force can be exceptionally good at preventing the majority of attacks on shipping [in the Strait]. That could even get into the 90% plus range. You could even call it 98%. But it's that last 2% that the joint force just has the most difficulty stopping [Iran from hitting a transiting ship] because you just can't stop everything when there are these mountainous rugged shores that Iran controls and they can use that as [protective] cover to attack shipping.”

Hinote went on, “So the problem is not necessarily that we're not militarily successful. I call 98% pretty militarily successful, but it's that last 2% that the [ship] insurance companies cannot accept. And so that's, I believe, the true dilemma that is facing the world economy today -- that as long as Iran has the will to try and negate shipping through the Strait, it's going to have some level of capability to do so. And that just creates a conundrum that we just haven't solved and [are] unlikely to solve.”

The two former Air Force generals also raised the issue of Israeli and U.S. forces having different missions for their military involved in attacking Iran.

Ret.-Gen. Slife put it this way: “I wonder to what extent the difference in [U.S. and Israeli] targeting reflects different national aims between Israel and the United States. I don't have any way of knowing that, but I do think it's noteworthy that we are actually, we have pursued very different target sets which may tell us something about what our respective national aims are.”

Ret.-Lt. Gen. Hinote picked up that idea saying, “To me, the Israeli theory of success is pretty straightforward. They [the Israelis] believe the Iranian regime will always be hostile to them and they believe that they have to go back and back and back to re-strike things and to re-strike the regime targets. And you might think of that as a strategy that we've heard called mowing the grass…meaning that the grass is going to grow back and we're going to go back and they are resigned to some way of mowing the grass again for years.”

That means, according to Hinote, “The more [Iranian] regime leaders we [meaning the Israelis] can kill, the better, because that means it takes more time for the new regime leaders to be dangerous to us.”

As for the U.S., according to Hinote, “We're at a stage now where we're fighting a coercion campaign…Hey, we want the Strait [of Hormuz] open. Hey, we want you to give up your nuclear aspirations.”

But now, as he adds, “There's nobody left in Iran who really can make that decision and enforce it up and down what is left of the government and military apparatus. So we're in a state now where what you might have thought of as the strategic aims and the military means, not only were they not necessarily totally aligned, they may have in certain circumstances worked against each other -- and that's a really difficult place to be.”

That is because, as Hinote points out, “We [the Israelis and U.S.] did one of the most successful, maybe the most successful decapitation operation [of Iranian leadership] in history. And so given that, I think you expect that there's going to be a high degree of paralysis and inaction at the

highest levels of the Iranian government. So you're almost thinking like, okay, well, what at that point, how do you take advantage of that strategic paralysis?”

However, there was no “strategic paralysis” in the Tehran regime, nor was there an internal uprising, as President Trump called for that night last February when he announced the first Iran attacks were underway. “When we are finished,” Trump said to the Iranian people, “take over your government. It will be yours to take. This will probably be your only chance for generations." Trump also called on the Islamic Revolutionary Guard Corps (IRGC), the armed forces and police to "lay down your weapons and have complete immunity" otherwise "face certain death."

As Hinote put it last week, “We're in a state now where what you might have thought of as the strategic aims and the military means not only were not necessarily totally aligned, they may

have in certain circumstances worked against each other -- and that's a really difficult place to be. And I think one of the reasons why it feels intractable right now is because you have that disparity.”

In fact, Hinote added, “The United States would like to be done with the Middle East, so that we could finally execute some sort of pivot to Asia. And we'd like to get out of all of these very expensive bases in the Middle East. And so we have a theory that is we want to put the [Iranian] regime into some sort of state where we don't have to go back anytime soon -- and we get to a steady state that is better than what was in existence on February 28th [when the U.S. and Israel first attacked Iran].”

Slife also mentioned an effect on U.S military readiness from the Iran War that need further attention when he said, “You know that all our readiness is built around how we generate and deploy forces, particularly for the Air Force and the Navy. We've seen heavy deployments beyond what the [military] services feel like they can routinely support from a readiness perspective and so those things always have a delayed effect.”

Slife added, “I think just the pace of operations over the last year has probably exceeded the Air Force and the Navy's ability to maintain levels of readiness going forward. So, I think we were going to have to pay close attention to that over the next three-to-five years, because there is always a delayed impact to these kinds of heavy operations.”

Hinote spoke about “the mission to rescue the [U.S.] back-seater of the F-15E [that was shot down over Iran]. We've only heard a little bit about that. My sense is that it was a huge operation that required tremendous integration across multiple types of forces in a very difficult time frame.”

He pointed out the difference from the troubled April 1980 Iran rescue attempt that was, he said, “so bad that it led to reforms for the next decade in the United States military. We may see that [the April 5, F-15E back-seater] rescue operation, in contrast, stands as being one of the best we've ever seen.”

Hinote then explained why saving the back-seater was so important.

“What if that weapon-system officer would have been captured and paraded in Iran on TV with the entire world seeing it real time,” Hinote said, “You could see that any political objectives that we were trying to achieve would be all the more difficult to achieve with one single pilot being paraded around in Iran…So, not only was the true political nature of the whole operation in jeopardy, but you [the U.S.] were willing to send what I think is going to end up being scores of airplanes into harm's way, multiple units, helicopters and such to go rescue this one pilot so that the political objectives could be preserved.”

While public concentration currently is on what’s not yet worked to end the Iran War, that rescue operation was one element that did succeed.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

AI Summaries Are Susceptible to Manipulation — and That's Both a Business and a National Security Problem

3 August 2026 at 09:07

More and more people are using AI like a search engine – 42 percent of U.S. adults now use AI chatbots to search for information – and that shift is exposing a structural vulnerability that adversaries are exploiting to seed propaganda. In practical terms, this is a problem of Generative Engine Optimization (GEO) – the deliberate effort to shape digital content so that AI chatbots absorb and repeat it.

The research so far points to data voids — the thinly covered topics where there isn't much credible information to begin with — as the weak spot. This includes breaking news or new material that has not yet had time to accumulate the signals that would flag it as low authority.

AI can process far more information than any human can, but there is an inherent trade-off in outsourcing the curation of information to an AI summary. In the search era, users were exposed to source material and evaluated credibility for themselves. Now AI does that work, and research shows the large majority of AI queries end without a click.

This is both a business concern and a national security concern. The clearest example on the consumer side is Apollo-9. In a Chinese state TV investigation, researchers used a tool called Liqing to flood the web with fake reviews and rankings for Apollo-9, a fitness tracker that did not exist. Within hours, chatbots were recommending the fake fitness tracker and some continued to do so a day after the fraud was exposed. Liqing and other tools are sold openly on Chinese e-commerce platforms like Taobao and JD.com, with pricing ranging from roughly $520 to $4,765 for three-month subscriptions. One provider told Chinese state media it had served more than 200 clients across multiple industries, guaranteeing top-three placement on any AI platform.

In order to better understand these developments and their impact, this article examines how the same mechanism scales from commercial fraud to geopolitical disruption, using the Russia-Ukraine war as a live GEO lab. Leaked documents about Russia’s “Project 2026” and Ukraine’s AI‑enabled counter‑operations show how influence campaigns are evolving from social feeds to the underlying sources that AI systems draw on — an angle largely absent from existing information warfare debates.

Russia and the National Security Case: Same Playbook, Higher Stakes

When Russian operations exploit GEO in their war on Ukraine, they are not just spreading propaganda in the moment; they are trying to become the “ground truth” that AI systems summarize back to users, analysts, journalists, and policymakers. In June 2026, Bloomberg reviewed 73 leaked documents from the Social Design Agency (SDA), a sanctioned Moscow firm at the center of Russia's influence operations, describing a program its operators called “Project 2026:” a network of Wikipedia-style reference sites, media outlets, and fake think tanks built to shape what search engines — and AI systems — treat as reliable sources. The goal, as described in the leaked documents, is to “create an alternative information ecosystem” by shaping not only what people see today but also what AI systems will later “know” about key leaders, the war’s origins, Ukraine’s conduct, NATO’s role, and Western support.

Russia's GEO tactics build on years of search engine optimization (SEO) manipulation and are part of a widely reported pattern of industrialized cognitive warfare that includes deepfakes, cloned sites and other deceptive content. In 2023, a study published in the Harvard Kennedy School Misinformation Review examined pro-Kremlin attempts to manipulate search engine results and found that pseudo‑think tanks and propaganda outlets such as Global Research and Strategic Culture Foundation were amplified through backlink networks and low‑quality sites. These outlets were most effective on conspiratorial searches involving, for instance, Ukraine President Zelensky, where authoritative content was sparse. Indeed, as noted by former CIA leader Jennifer Ewbank, the use of deepfakes to confuse, distort, or influence public opinion not only occurs in Ukraine but across Europe – all of which reflects “the same underlying reality: the tools for deception are faster, cheaper, and more accessible than the systems we rely on to detect or prevent them.” In other words, this is not just about deception, but the erosion of trust itself.

Storm-1516, a documented Russian disinformation operation that has been active since at least 2023, has scaled sharply in 2026. According to Bloomberg, the operation has produced more than 190 false stories since 2023 that the outlet has been able to identify. Based on Bloomberg’s reporting, Meduza adds that in the first quarter of 2026 alone, Storm-1516 was producing fake stories at twice the rate of the same period the previous year with, for instance, as of late March and early April 2026, materials appearing almost daily. Meduza also reports that more than 40 percent of Storm-1516’s fabrications have targeted Ukraine, with another third focused on electoral processes in other countries. Taken together, these reports demonstrate that Storm-1516’s operations are ultimately aimed at eroding Western support for Ukraine, swinging European elections and destabilizing NATO allies.

Taken together with the “Project 2026” leaks, these findings suggest that Russia is now attacking both the content layer (through synthetic media) and the source layer (through cloned Wikipedia‑style sites and fake think tanks) of information ecosystems. While synthetic videos and stories are often treated as short‑term deception, they also become part of the online record that future AI systems may ingest or retrieve, turning Russia’s layered influence architecture into a long‑term GEO problem, especially in data voids.

The Storm-1516 operation follows a clear pattern. A fake witness, often an AI-generated video, seeds a plausible but unverifiable story. Low-tier blogs and Telegram channels amplify it in multiple languages. Then less rigorous Western outlets pick it up, severing the link to the original Russian operator. By the time the narrative reaches mainstream discussion, the Russian fingerprint is gone. The new risk in today’s landscape is that the AI curation layer completes this laundering. It reads the now-repeated narrative across multiple sources and presents it as a neutral summary.

Researchers at the Institute for Strategic Dialogue found that the chatbot DeepSeek was quoting VT Foreign Policy, an outlet known to carry content from Russian propaganda operations such as Storm‑1516 and to have connections to the Kremlin‑linked Strategic Culture Foundation. U.S. and EU sources describe the Strategic Culture Foundation as an arm of Russian state interests.

A 2025 NewsGuard study also found ten of the leading chatbots — including ChatGPT, Claude, Gemini, and Copilot — collectively repeated false narratives from the pro-Kremlin Pravda network about a third of the time. It’s important to note that a 2025 study in the Misinformation Review, responding directly to the NewsGuard findings, found the number was closer to 5 percent and that these failures clustered in data voids. While the researchers found "little evidence to support the grooming theory" and warned against "the overhyped specter of Kremlin manipulation," they acknowledged that data voids "may be artificially created" and that they could not dismiss the possibility that a disinformation campaign could target them. Importantly, their audit came fourteen months before the leaked “Project 2026” documents showed Russia explicitly targeting AI systems. The more Russia attempts to flood these data voids, the more likely it is that future AI summaries about Ukraine will inherit its framing.

How to Build Resilience – A Way Forward

Like its older cousin SEO, GEO is inherently dual-use, but it sits in a regulatory vacuum because it is viewed strictly as a consumer protection issue rather than a national security threat. The Apollo-9 experiment and the Storm-1516 operation prove they are two sides of the same coin; the same commercial tactics that manufactured demand for a non-existent fitness tracker can easily manufacture plausibility for distorted narratives about a geopolitical crisis such as the ongoing Russia-Ukraine war. History shows that with traditional search engines, the market naturally incentivized tech companies to tackle manipulation head-on because mass spam threatened to destroy the user experience for billions of people, directly endangering corporate business models. Malicious foreign influence operations executing GEO are fundamentally different because they remain largely invisible to the mass market, with manipulation surgically clustered within obscure data voids, offering tech companies no commercial incentive to self-police and leaving the information terrain around a live European war effectively undefended.

To bridge this gap, regulators can draw on the lessons of private sector SEO defense and public-private counter-disinformation efforts, but they must realize that the exact same playbook will not work here. While private developers can easily dismiss the Misinformation Review study’s five percent finding as an acceptable commercial error margin, this minor statistical anomaly sits precisely in the data voids that Russia is actively trying to colonize, and so it represents a primary, unmonitored vector for foreign manipulation. The strategic risk is not only that GEO can mislead people in the moment, but that it can reshape the evidentiary record on which institutions and AI systems will later rely; if hostile narratives are allowed to dominate long‑tail topics and thinly documented episodes in the Russia-Ukraine war for instance, then future summaries, briefings, and even historical accounts risk being generated from polluted inputs.

The 2025 Misinformation Review study recommends "warning banners for data void queries" and increased "audit access," but notes the banners are "applied inconsistently" and the audit access is "hindered by power asymmetries.” Because the market will never self-correct a threat it does not financially register, protecting the integrity of generative content must transition from a voluntary corporate practice to a formal national security mandate.

In the Russia-Ukraine war, these dynamics are already visible. Russian operations such as Storm‑1516 use GEO‑style flooding and synthetic witnesses to launder narratives about the conflict into the broader information environment, while Ukrainian actors rely on AI‑enabled monitoring and evidentiary documentation to defend the integrity of the record. The contest is no longer confined to what populations see online today; it is over what AI systems will say is true about the war tomorrow. Recognizing GEO as a national security problem therefore changes the governance question: the training, retrieval, and ranking layers of generative systems are now part of the battlespace, and leaving this space unregulated is akin to leaving critical information infrastructure undefended.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Investing in the Next Arsenal of Democracy

31 July 2026 at 11:00

America’s critical technology, maritime, infrastructure, and advanced manufacturing base is one of the clearest places where tax incentives, private capital, and national security should meet. We already know this model can work. Opportunity Zones helped drive billions of dollars into real estate, community development, and designated investment areas by giving investors a reason to move capital into places that policy makers wanted to support.

Now we should apply that same logic to the sectors that will determine America’s ability to compete, defend itself, and rebuild its industrial strength.

Recent proposals around Maritime Investment Zones point in the right direction. The basic concept is simple: use the tax code to pull private capital into shipyards, ports, vessel construction, ship repair, marine navigation, workforce development, advanced manufacturing, and the broader maritime supply chain. If tax incentives helped attract capital into real estate and community development, a similar model could help rebuild the industrial base that underpins American sea power and national resilience.

But this should not stop with physical shipyards or port infrastructure.

The next generation of American industrial power will be built across a broader ecosystem of investment funds, operating companies, manufacturing platforms, critical infrastructure projects, and technologies that strengthen national security and economic security. That means sectors like autonomy, advanced manufacturing, aerospace, maritime systems, secure communications, cybersecurity, energy resilience, critical minerals, space infrastructure, drones, counter-drone systems, AI-enabled defense tools, logistics, and domestic supply chain resilience.

Qualified investment funds focused on these sectors should be considered for Opportunity Zone-style designation. These funds can aggregate private capital, diligence complex technologies, support hard-tech companies, and bridge the gap between emerging innovation, government demand, commercial scale, and mission relevance. Many individual investors cannot properly underwrite a defense technology company, an advanced manufacturing platform, a shipyard modernization project, or a critical infrastructure asset on their own. Qualified managers can help channel capital into these areas with discipline, experience, and a better understanding of both market risk and mission need.

The same logic should apply directly to qualifying platform companies and infrastructure projects. Businesses building autonomous maritime systems, advanced airframes, resilient logistics platforms, drone manufacturing capacity, shipbuilding technologies, next-generation materials, critical infrastructure tools, and domestic production capabilities should be eligible for special designation if they are strengthening the defense industrial base, expanding U.S. production, modernizing infrastructure, or reducing dependence on adversarial supply chains.

This matters because the future of defense manufacturing and industrial power is changing.

The next phase will not only be about large legacy platforms built through traditional procurement channels. It will also be about faster, lower-cost, more scalable, more autonomous systems that can be produced domestically and integrated across a broader defense technology ecosystem.

In maritime, for example, the future will not only be larger crewed vessels. It will include autonomous naval platforms, distributed maritime nodes, unmanned surface vessels, undersea systems, AI-enabled ISR, electronic warfare, logistics support, secure communications, and integrated sensor networks. The autonomous ship is not just a vessel. It becomes a node in a distributed maritime network.

That same principle applies across the broader industrial base. The future battlefield and the future economy will demand more mass, more resilience, more autonomy, more secure infrastructure, and more ways to complicate an adversary’s targeting problem. The United States cannot afford to rely only on slow, expensive, exquisite systems while adversaries are scaling ships, drones, missiles, cyber tools, industrial capacity, and supply chains at speed.

A Maritime Prosperity Zone, Critical Technology Opportunity Zone, or National Security Investment Zone framework could help solve part of this problem by giving investors, fund sponsors, founders, manufacturers, and infrastructure operators a reason to back the companies, factories, shipyards, platforms, and projects needed to rebuild American industrial strength.

This would likely create some of the same market behavior we saw during the real estate Opportunity Zone boom of the early 2020s. Once the incentive was created, capital moved. Sponsors formed funds. Allocators searched for qualified opportunities. Developers shaped projects around the designation. Billions of dollars followed.

The same could happen in defense technology, critical infrastructure, autonomous systems, maritime manufacturing, space, energy resilience, advanced materials, and critical manufacturing.

That is the power of incentives. Investors are not charities. They respond to opportunity, yield, tax efficiency, liquidity, policy clarity, and the chance for outsized returns. That is not a weakness of capitalism. That is how capital markets work. If policy makers want private capital to help solve national problems, they need to make those problems investable.

Critics will say this gives investors generous tax treatment. That is true. But that is also the point. The government routinely uses the tax code to shape behavior. We incentivize home ownership, retirement savings, energy development, municipal finance, real estate development, and other areas deemed important to the public interest. The question is not whether investors benefit. The question is whether the country benefits enough to justify the incentive.

In this case, the answer should be yes.

A targeted national security investment incentive could drive domestic job growth, create new industries, expand the tax base, strengthen supply chains, rebuild manufacturing capacity, and reduce reliance on government-led solutions. Instead of expecting Washington to fund and manage every critical industrial requirement, the government can use tax policy to unleash private capital and let the private sector help build the capacity the country needs.

That is a better model than simply growing government. Government should identify priorities, set standards, create incentives, and provide clear demand signals. Private capital should help take risk, scale companies, build factories, support founders, finance infrastructure, and commercialize technologies. Done correctly, this becomes a force multiplier. It allows the country to pursue national security and economic security objectives without relying solely on appropriations, grants, subsidies, or bloated federal programs.

It also helps create a broader base of economic growth. A new factory, shipyard, drone production line, secure data center, advanced materials facility, or critical infrastructure project does not just create investor returns. It creates construction jobs, engineering jobs, manufacturing jobs, supplier ecosystems, logistics demand, local tax revenue, and long-term industrial capacity. These are the kinds of investments that can rebuild regional economies while strengthening national resilience.

But there is an important caution.

During the real estate Opportunity Zone boom, disciplined allocators still had to underwrite the real estate first. The asset had to make sense. The location had to make sense. The sponsor had to make sense. The tax advantage was an added benefit, not the entire investment thesis.

The same discipline must apply here.

In the current hype around defense technology and national security investing, not every company with “AI,” “autonomy,” “defense,” “resilience,” or “critical infrastructure” in its pitch deck deserves capital. The manager, deal, technology, platform, or project has to stand on its own. The tax benefit should improve the risk-reward profile, not rescue a weak investment.

Return on mission matters. But it should not replace return on capital. The best version of this policy would align both. Investors get an incentive to take risk in strategically important sectors, while the country gets more domestic production, stronger supply chains, better infrastructure, more jobs, and a deeper industrial base.

The United States does not have a shortage of capital. It has a capital alignment problem. Too much money flows into financial engineering, speculative assets, and incremental technology. Too little flows into the difficult, physical, industrial, and security-related sectors that determine whether the country can compete in a more dangerous world.

Opportunity Zones showed that tax policy can move capital. The next step is to aim that capital at the future of American power.

If we can incentivize capital to rebuild neighborhoods, we can incentivize capital to rebuild shipbuilding, critical infrastructure, advanced manufacturing, and the national security industrial base.

The goal is not to give investors a gift. The goal is to give the country a tool.

The next Opportunity Zone should be built around American resilience.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

We've Seen Autonomous Warfare and We're in Trouble

23 July 2026 at 13:18


Editor’s note- Russia's war in Ukraine has fundamentally changed the character of warfare, proving that autonomous and attritable drones are no longer supporting tools but have become a decisive instrument of combat. In this provocative essay, co-authors Xen & Matthew Creedican argue that the United States must abandon legacy assumptions and adopt an entirely new military doctrine, force structure, and industrial strategy built for the age of autonomous warfare. (Xen is a former US Special Operations veteran with experience fighting alongside Ukrainian forces. We have granted his request for anonymity).

This paper is written expressly for the policy and decision makers across the military and public and private sectors who are bound to translate national strategy into reality. We will withhold for another day the arguments for convincing those who have yet to concede that the rifleman’s day is over or that drone warfare in Ukraine generalizes. Instead, we are making a series of recommendations to those already on board with direction from the Department of War (DoW) that “we are pivoting the Pentagon and industrial base to a wartime footing”, as manifested in a $50B+ modernization program to ensure that “every warfighter must have access to low-cost/attritable sUAS [small drones] to conduct missions.” To help leaders meet such a steep challenge, we will describe how the force should be structured, how doctrine should be written, and how the industrial base must be re-engineered to match present scaling by our adversaries.

What a Modern Drone Force Should Look Like, For Now

If we could snap our fingers now and summon an army well-trained and well-equipped according to the latest understanding of modern drone warfare, it might be composed of battalions fielding approximately fifty to a hundred mixed-role unmanned systems deployable simultaneously, with stocks of thousands more unmanned vehicles and spare parts (antennas, ground stations) ready to replace those attrited. The force tailoring would have to include both rotary and fixed-wing drones performing reconnaissance, mothership, electronic warfare, one-way attack (OWA), bomber, and multi-role tasks. Such a battalion should be able to organically find, fix, and finish targets at ranges up to 300km.

Presently in Ukraine, formations tend to specialize by range. Tactical or “infantry” battalions deploy quadcopters controlled by direct radio link or fiber optic from positions 3-10km from the absolute front, flirting with the danger zone, with the better teams now fielding glide-kit quads reaching out to 50+km, doubling their effective range from last year. Ground drone units are increasingly critical as well, performing the vast majority of evacuation and logistics within the 9-15km+ “gray zone” where manned vehicles are not worth the risk to employ. Dedicated drone battalions overwatch these units from 10-20km from no man’s land, operating typically out to 80km but at times out to 300km thanks to proliferating autonomy and redundant communications (direct, meshing, repeating, satellite, LTE, etc.). This upper end for the “mid-range” or “operational” level of warfare has also at least doubled since last year. Finally, specialized deep strike teams are now conducting strikes out to beyond 1500km against strategic targets, with high-volume, low-cost, independent, adaptable platforms quite different from expensive legacy US drones.

At every level of the above structure, it is understood that even the non-OWA platforms must be attritable, since they rarely accomplish more than several missions without being rendered inoperable. Particularly cheap systems are even deliberately used as decoys. And of course, seeping down into these echelons is autonomy enabled by AI, and the beginnings of swarming protocols. It must be understood that what the aircraft carrier once did to naval gunnery is what the drone is doing to the rifleman. The fundamental unit of combat power is now the small drone team, and it is an over-the-horizon asset.

Saving Combined Arms Maneuver

Drones employed properly in such formations could execute combined arms maneuver warfare rather than the attrition warfare we currently see. After reconnoitering the enemy and making contact, unmanned battalions could use air platforms in both expendable and regenerative loitering waves to degrade air defenses, electronic warfare systems, logistics, and command structures, after which successive waves could suppress and attrite ground forces in preparation for ground drones to take, hold, and shape ground. Only then would humans move forward to effectively deepen the range of their systems. All this implies an in-depth rewriting and reapplication to unmanned warfare of manuals and doctrine guides such as FM 3-0 Operations, FM 3-90 Tactics, and FM 3-96 Brigade Combat Team. Current revisions have relegated the drone to a supporting role at best. Another example: given that a legacy US Army Corps of tens of thousands of personnel has multiple days to make decisions across approximately the same operational striking depth as that of one of the aforementioned Ukrainian drone battalions of a few hundred personnel, clearly we must revise our echeloned depths of responsibility . The existing disparity has practical consequences, as Ukrainians not only handily defeat NATO forces in joint exercises, but they do it with comparatively tiny forces, striking larger formations and assets in areas thought to be “safe”.

As such, it should be clear to those familiar with the actual contestants in programs like Drone Dominance that we are staging to mostly procure platforms that are too expensive for the requested operational ranges. Although the DoW has set a target of roughly half a million drones per year for procurement, it will actually need at least fifty million to meet the lofty goal of training and equipping a ~500,000-1,000,000 man force with attritable systems. If we look to the rest of the world, we will see that Ukraine and Russia this year are each likely to utilize around twenty million drones, while China, as the manufacturer of most of the world’s drone components, will likely build the equivalent of a hundred million drones.

Predictive Doctrine for a Moving Target

But even this, unfortunately, is not the real crux of the issue with respect to the development of future requirements. Doctrine must not only be prescriptive of the present, but also of the near future. The fact is, we cannot just snap our fingers to summon a drone army. It will take years to build it out, and by then things will look even more “sci-fi”. That is, we are chasing a moving target three to ten years out, and so we had best engage in some imagination to meet that challenge.

We are conscious of how radical this is going to sound, but our goal with such provocation is indeed to shift the Overton window, so, we believe that the future will look like something out of Ender’s Game, and it’s going to happen well before those now entering the military reach retirement eligibility.

Man, Train, and Equip for the Sci-Fi Near Future

Individual drone controllers will become tactical commanders (so let’s call them “tacticians”) remotely running squadrons of individually autonomous drones, point-and-clicking their way through a 3D interactive, AI-mediated, sensor-fusion digital twin of the battlefield. The base layer is already here in the digital panopticon emerging from cloud-native Common Operating Picture (COP) software like Ukraine’s Delta merging with military AI suites. Palantir’s Maven already suggests courses of action at the command level, and there’s no reason this couldn’t be extended down to the lowest tactical levels, controllable by voice, touch, or text. In a few more years the tacticians themselves will be inside something Neuralink-shaped, performing at the speed of AI-enhanced thought and striking at the links in the chain that enable adversarial tacticians. Under those conditions the adaptation cycle, too, will move at a speed that cognitively unenhanced humans cannot keep up with, and intelligence becomes the runaway comparative advantage at every level. There is no telling where such cognitive selection pressure combined with the ability to remotely control drone swarms will end. Will individual soldiers control dozens of drones simultaneously – or thousands? How many drones should a “battalion” have?

Decentralization is a factor too. Everything we are seeing develop now is scaling in Ukraine down to the individual operator, as it must. The over-the-horizon warrior needs personal access to livestreamed tactical radar to check if the skies are clear before he exposes himself by making movement. He needs edge compute not just onboard his drones, but for local offline AI to analyze the battlefield and make decisions even in a communications blackout. Already we see backpack portable drone interceptor systems for personal defense; I’m aware of contracts under consideration for such systems to miniaturize to automated shoulder-launch, like a personal version of the tank-mounted Trophy system. The current estimate is that a soldier has one to four seconds to defend himself against a visual drone contact vectoring on him, and soon that timeline will compress enough to exceed human reaction times.

Asking what exactly the mass of conventional soldiers will do under such a radical restructuring is much like asking whether or not Large Language Models (LLMs) are going to have the net effect of creating or destroying jobs in the civilian workforce. We may see the formation of a tiny military class, or perhaps warfare will become even more industrial in human scale. Certainly, humans will be pushed farther and farther back in the logistical chain that ultimately delivers kinetic effects upon an adversary. Currently, there is a need for people to physically emplace, operate, and recover antennas, ground stations, and drones. Once robots are more commonly executing these tasks (already, some aerial drones are launched via multi-domain mothership drones), people will work on those robots, and so forth. Eventually, it’s hard to see what anyone will need to do physically, as robots will be building, repairing, improving, and employing each other. The only real foreseeable tasks left at the tactical echelon will be those of the tactician and the true engineer, who innovates and integrates locally. Whoever best automates tasks end-to-end will win the tempo fight. The transportation of weapons and sensors has to be contemplated as one mass-manufactured logistical animal.

Going further, the tactician need not position himself relative to any front at all, because he can fly remotely and because he would be sensible to reduce his threat profile from direct action threats to intelligence-driven threats only. That is, he should position himself to strike with impunity. Already in Ukraine, Sting pilots have flown their interceptors remotely 500km away from where they were launched. Midrange teams outside the gray zone already drive to position in unmarked civilian vehicles, wear their uniforms only for the minimal time needed to deploy their systems, and then fade back into the population. And the naval drones striking the Russian fleet are not generally controlled from the sea, but ultimately from bases on land. If trends hold, the smallest independent tactical elements may be able to cheaply strike anywhere on Earth within a decade.

Branching Futures: eVTOLs, Smart Dust, and Beyond

But this is merely one vision of the future. There are branching pathways, perhaps some of which may coexist. Weaponized human-optional eVTOLs like the Chinese prototype ZR-300 could become a new air cavalry paradigm unto themselves if employed en masse in shock fashion, sweeping aside whole nations in a day the way Central Asian hordes did in the Medieval period, or the way Islamist insurgents swept across the Sahel in Toyotas. Microscopic drone “clouds” also known as smart dust could penetrate any conventional barrier, performing reconnaissance or even coalescing explosively or penetrating air ducts and lungs. Does this seem one step too far, straining credulity? Remember that “any sufficiently advanced technology is indistinguishable from magic” from the perspective of the old guard, and that all these technologies are already real, just not fully scaled and integrated. In fact, micro drones were feasible decades ago, technically if not economically – timing is everything. We already have a leading indicator in the German army’s very real purchase of cyborg insect swarms from Swarm Biotactics. Against such dizzying possibilities, we will advocate further on below for a rapidly adapting structure that ingrains real-world feedback and extrapolates from it.

Economies of Scale for Drone Production

First, let’s deal with how we produce enough useful drones to simply match our adversaries. The necessary industrial base to deliver manufacturing on the required scale simply does not exist anywhere in the West currently, whereas China has quietly captured the drone market and the sub-component supply chains over decades and is integrating such technology down to their lowest tactical echelons at a hundred times our volume. Much has already been written about the need to innovate and iterate on a scale of weeks rather than decades, and while true such a need potentially comes with the steep requirement of continuous retooling of factories and endless R&D. Ironically, funding this effort at the scale needed will require a vision across a much longer (generational) timeline, in opposition to the quarterly results that drive Western business strategy. Currently, the US buys primarily the end-product rather than engendering the component markets directly. From a cost-savings standpoint, we would do well to preemptively build adaptable systems, and also to stop trying to update legacy programs (we will never need a new sniper rifle). The DoW budget has to fund the domestic mass production of production itself, with an eye towards dual-use sub-components and machine tools, since commercial R&D and production can fund itself to an extent. Vehicles, phones, and drones sold into civilian markets pay for their own scaled production, and volume buys down cost. As it stands now with our current component outsourcing, we are paying our enemies to equip us, tying the rope with which they intend to hang us.

Pillars of a Sovereign Drone Industry

The pillars of industry to be funded include locomotion, actuation, energy, storage, compute, sensing, and communications. The component-level specifics, meaning motor sizes, magnet chemistries, cell formats, and the rest, belong in a technical paper. What’s important here is that the government has to guarantee the market for base components as much as scale requirements dictate and raw materials allow, while simultaneously finding the alternatives that bypass adversarial chains entirely.

Shallow or single-sourced chains halt on the first disruption, so volume has to be distributed across multiple domestic entities in order to create redundant paths. That means accounting for the physical bottleneck of factory siting, the legal bottleneck of restrictive radio frequency and flight-test regimes, and the social bottleneck of technical workforce recruitment, which in practice means a nationwide push for engineers with the education pipelines to match. We should fixate less on the static stockpile and more on the velocity at which the economy can replace a lost or outdated asset. Eventually, this may look like self-assembling factories, but for now we should see a dramatic increase in industrial jobs, not a reduction.

Guaranteed Requirements and Manufacturer Caps

The Departments of War and Commerce must jointly establish requirements and guarantee purchase of components at massive volumes, over multi-year timescales, according to stringent standards for minimum viable products meeting or exceeding foreign equivalents, with caps set on what portion of the total any one manufacturer can source. Subcontracting and manufacturer caps will encourage competition inside our own secure ecosystem rather than across national borders, where we are frequently undercut by adversaries. As needed, the government can resell unused inventory back to industry at or below the cost of subsidized foreign imports, letting American companies build with cheap secure inputs.

We have a realistic precedent for all this, as described in the book Freedom’s Forge: In anticipation of US entry into WW2, President Roosevelt brought together former of heads of industry in order to align military requirements, government funding, and civilian production capacity so that goals could be revised upward continuously, and the resulting volume forced a dynamic of subcontracting to keep up with demand. American industry responded, not only producing hundreds of thousands of complex war machines, but also rapidly retrofitting them as needed based on frontline feedback, on much the same timescales that we today see in Ukraine.

Innovation on the Machine Timescale

In the near future, however, we will have to go even further, with innovation necessarily occurring on the machine timescale. The same digital twin in which soldiers will virtually train and fight will also let us simulate hardware, factories, and logistics before steel is ever cut. The panopticon in which the end product’s edge sensors feed data into will be the same in which an arbitrary number of tests under variable conditions may be run before the more refined next generation of product is built. Supply chains from base-component assembly through fuel and battery pathways can be estimated and stressed the same way. Data streams from around the globe and from local instrumentation can all compartmentalize or cohere as needed for efficiency or breadth of understanding, all of it parseable by ever-increasing machine intelligence, at worst bounded in growth only by Moore’s Law. As an aside regarding encouraging a martial culture amongst the youth who will one day fill the tactician ranks, our military should release realtime strategy wargames involving drone swarming, initially as standalone games but eventually living inside the kind of digital twin explained above. And as earlier mentioned, all of this will eventually be experienced in breathtaking detail in virtual reality and via brain-machine interface. This is not so distasteful a task on a wartime footing, especially considering even in peacetime the military has released first-person shooter games and simulations.

Massive integrated training areas, in which units, contractors, and manufacturers co-locate to live-fire and iterate together, belong on the near-term build list. The mandate inside such an area should be inverted from current practice, so that the burden shifts from justifying permission for a given action to justifying why any given action cannot happen. The FAA, the FCC, and the rest of the regulatory apparatus should be effectively kicked out of the perimeter, and legislation should extend a good-faith liability shield covering crashes and honest mistakes. Dedicated integration units, which can be thought of as Transition in Contact supercharged, should be created. The core skill of these new units would not be warfighting but rather adapting to and assembling whatever technology is available. Every unit, not just dedicated ones, should additionally have at least some innovation budget and personnel, so that they are not merely customers but also integrators. Specifically, this means the military needs to be mass recruiting engineers to fill out dedicated innovation units and also sprinkle across the wider force. And lastly, the soldiers who will become the drone tacticians must be allowed to train for that role full-time, studying meteorology, radio theory, and other topics and skills currently regarded as arcane among warfighters.

A Permanent Feedback Loop from the Front

None of the above works without a permanent structured feedback loop that connects requirements to what is actually happening in a live conflict. Local units cannot generate requirements for now let alone five years out if there is no frontline feedback, no rotating instructor cycle, and no living link to platforms that do not yet exist in Western inventories. A peacetime force generating peacetime requirements will buy peacetime equipment no matter how decentralized the process is. Instead, we need a much greater scale of personnel who are aggressively forward deployed to conflict zones, visiting tactical operations centers and doing ridealongs on relatively low-risk mid- and deep-strike operations. Our partners will gladly place them there if they provide as much as they take. Directly in this role we can put our incredible all-volunteer special operators, who want nothing more than to get close to the fire. Adjacent to it, in lower intensity areas, we can forward deploy conventional troops as well to learn from partners, including by attending their own schoolhouses.

What we are suggesting here is deploying thousands of troops, not merely small cells of elite military and intelligence agency operators whose reporting does not reach the wider military. Much like the technical innovation measures described in the previous paragraph, these warriors should be distributed both into new dedicated units for the express purpose of doctrine, tactics, techniques, and procedures innovation, as well as across the wider force, to supercharge change and acquire what Clausewitz called a “fingertip feel” for the present state of war. If there is really no political appetite for this, then the only other option is to accomplish the same via other methods, such as by inviting large numbers of military instructors from partner nations currently involved in active conflict or by rotating civilian contractors more discreetly through conflict areas, as suggested by former Green Beret Bryan Pickens.

Piping Frontline Signal Directly to Doctrine Writers

Regardless of how it is done, the core part of whatever structure is created should report directly to the senior military leadership responsible for the development of force-wide doctrine and requirements, so that they cannot ignore reality and hide in dead paradigms. Various new offices are being created, such as DRPM-UxS, and our hope is that with direct signal they can utilize sweeping - even disruptive - authorities to continually remake the military; for, as Napoleon said, “unhappy the general who comes on the field of battle with a system”. Given the enemy’s endless adaptation, the best meta-doctrine is to accept no particular doctrine as certain or permanent, and even to assume that it is likely wrong if it has not been overhauled lately. Official doctrine documents would be better written and accessed as living Google docs rather than year-dated static PDFs.

This applies down to the nitty-gritty of institutional knowledge as well. The train-the-trainer model informed by forward-deployed reporting must fuel change in our own programs of instruction and battle drills, so that we actually know how to employ the unmanned weapon systems we are scaling, a capability which further feeds into local units understanding the requirements for the next round of equipment purchases.

A sharedrive with compartmentalized access is not enough; we need our whole force separated at most by just one degree from someone who has seen modern war up close. And if the military is that close to the combat demand signal, then by extension the manufacturers who visit the units they are equipping will be that much closer.

The Transition Engine and Treating Ukraine as a Peer

Joseph Gagnard of Atlas Special Projects calls the sum total of all these joint efforts the “transition engine”, meaning operators, builders, contracting specialists, and investors institutionalized together, because no single one of them fields capability alone. That transition engine has to be paired with a treatment of Ukraine that most of the current western defense industry still resists. Treat the Ukrainians peer to peer, at least as well as Taiwan or South Korea, and better than either, because they are in an existential fight we cannot afford for them to lose. I suggest bringing thousands of Ukrainian engineers, managers, and operators into the United States to help build the drone industry. Regarding AI, America holds the architecture, the compute capacity, the models, and the global reach. But Ukraine holds the live-fire scaffolding for how that data actually gets generated, labeled, fused, and fed back into the iteration cycle; they have the premier Common Operating Picture software, Delta, to facilitate collection; and they are best positioned to evaluate the battlefield effectiveness of each successive generation of combat AI.

Furthermore, Ukraine is waging a global hybrid war on the West’s behalf, which we hardly engage in except via the most deniable means. China, Russia, and their proxies and allies ruthlessly exploit neutral ground with a vast array of tools, strangling us of resources, allies, and positioning. As political will allows, we suggest unleashing our special operators and intelligence officers in nearly-overt ways, in partnership with Ukrainians, who willingly perform more risky action and have a history of cooperation with our intel services, to operate across the globe responding in kind to the Axis arrayed against us. Drones, of course, are the perfect semi-deniable weapon for this. And the signal we receive back by more heavily involving our forces in low-intensity conflicts will feed back into the plan regarding getting a “fingertip feel” back for war.

The Vulnerable Homefront

The homefront, meanwhile, is ripe for a crippling preemptive strike against us. Our infrastructure is vulnerable, and drones as stated are a perfect scalable weapon that can be employed by deniable proxies. A strike could produce economically disastrous effects, and in response to such an attack of ostensibly deniable origin and limited death toll we would certainly not seek to launch, say, a nuclear retaliatory strike. Containerized long-range drones could be lurking on civilian ships off our coast right now. DHS testified to the Senate that in 2025 there were an average of 10,000 foreign drone flights per month near the southern border. Particularly at risk to such a looming threat is our AI infrastructure. Whatever one’s thoughts on the supposed “AI bubble” (the dot-com bubble didn’t stop the triumphant march of internet adoption, did it?), it is undeniable that both the previous and current administrations have regarded the AI race as existential, and our enemies clearly feel the same way.

We saw from a recent strike by Iran on data centers in the UAE providing Amazon Web Services that such centers are vulnerable, going down for several months at a minimum due to spreading fires and long lead time for repair parts. A few hundred drones striking data centers or upstream links in the chain could easily set us back in the AI race which could provide our adversary an opportunity to surge permanently ahead, a situation which, again, our bipartisan leadership regards as an existential threat.

A Decentralized, Always-On CONUS Defense

The right posture for CONUS defense is one that is always on and autonomous-capable, able to intercept without waiting for the chain of command. In addition, such efforts must take the form of a whole-nation decentralized effort. In Ukraine, a nationwide cheap network of mobile phones acoustically tracks hostile long-range drones swarming their country, and recent legislation approved the use of electronic warfare and interceptor drones by businesses to protect their own assets. New manufacturing and power facilities tend to be built in a distributed, resilient, redundant manner, with cheap hardening available for obvious targets (like anti-drone “cages”). Our recommendation, like elsewhere, is to empower everything local. We would even go so far as to suggest that the Second Amendment needs to extend to counter-drone equipment, and any U.S. person or institution should be able to engage perceived threats up to certain altitudes above their own land.

AI as Sovereign Terrain

We can extend the Second Amendment and drones argument to the First Amendment and AI; that is, to digital and not just physical terrain. Across the information domain, China steals from us and undercuts us, releasing open LLMs to erase Western software margins. Intellectual property in this context is a burden more than a benefit by now, perhaps functioning somewhat to promote internal competition but leaving us wide open for external exploitation. The best way to stay ahead of our enemy in the face of their undermining of our brittle centralized systems is to fight fire with fire. We need policy and funding to shy away from the current big LLM players and instead encourage open models, local compute, and data sovereignty, which offer numerous long-term advantages across the board that mirror the kind of resiliency and initiative-encouraging effects we will get by distributing compute and AI models down to the lowest levels of our military.

Encryption code, for example, was previously ruled to fall under free speech protections. There is an argument against allowing centralizing and censorship of digital spaces as well, regarding them as a kind of common space since there is a barrier to entry in networking at the level of Internet Service Provider infrastructure. We need a diverse market of competing open AI models, local compute, social networks, etc. A centralized internet and centralized AI have severe risks within the domains of psychological and information warfare, which play out across the public digital arena, but to go further in that discussion we would have to depart from the scope of the kinetic warfare focus of this article. Suffice to say, the most dystopian and existentially risky outcomes are plausible if centralized AI should win, whether by our own hand or the hand of the enemy, who will surely centralize control over their models as soon as they gain an advantage.

Deterrence via Force Projection

Another point worth addressing when discussing CONUS defense is the idea that “the bomber always gets through”, which is probably true regarding drone swarms. However, regarding the homefront, Ukraine has shown first that the effects of long-range drone attacks can at least be mitigated significantly, and that it is economically optimal to do so. Furthermore, the striking arm we are also building alongside the defenses will serve as a deterrent, since nuclear doctrine of Mutually Assured Destruction is insufficient for the aforementioned reasons. If we can threaten to do unto our enemies as they wish to do unto us, and indeed if we actually regularly exercise this capacity in the global low-intensity ongoing war, then we will make them think twice before hitting us.

The Core Principle: Endless Distributed Adaptation Capacity

The single principle of this piece is this- Stop buying end products and start buying the ability to produce them, at scale, sovereignly, and forever – doctrine here being one of those end products. The victor that emerges from the next several years will have built the meaningfully decentralized version of what we have described here, meaning distributed compute, sensors, swarms, command, cognition, industry, and authority, with the standards and alliances to match. The rallying cry, in the end, is the architecture. In the last great war, we firebombed cities, preemptively invaded neutral countries, and of course ultimately resorted to nuclear weapons. The political license for a national revitalization as a form of deterrence seems, by comparison, an easy pill to swallow.

Note from author (Xen)- For those who wish to understand not merely the how but the why, or who have comments, or who desire greater breadth or depth of understanding: Over the coming weeks I will be sharing additional information to my personal Substack and website. As for my co-author, Matthew A. Creedican, you can find him on LinkedIn.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Is Iran Controlling the Gulf Conflict?

23 July 2026 at 13:24

Recent statements from President Trump indicate he is prepared to continue, or escalate, U.S. military strikes while simultaneously signaling he is open to continued negotiations. Some would see this as a reasonable offer of carrot or stick. But, having lost scores of ships, missiles, and military production facilities, U.S. actions still depend on what Iran does. This is allowing the regime leadership to control the pace of the conflict. How is this possible?

By his own words, President Trump is admitting the United States is in full-blown reaction-mode, granting Iran effective control over the tempo of both military operations and peace negotiations. This is a mistake, born of the obvious desperation of the White House to extricate itself from the black hole that is the Iran War, and that is increasingly proving to be a drag on Republican chances in the approaching midterms.

Iran is clearly playing the provocateur, poking the bear with selective strikes on shipping daring to test their illegal claim of administrating the Strait. They are paying the price by suffering increasingly focused destruction of their offensive coastal capabilities.

This is as it should be. Iran simply cannot be allowed to impose itself on the movement of shipping through an international waterway. But… the President’s quickly aborted claim that the U.S. military should receive a 20% gratuity for its efforts to keep the Strait open has predictably only muddied the issue further.

Who’s Really in Charge in Iran and What Do They Want?

The regime clearly sees itself in the dominant position. Or, at least, in a position to bear more pain, for now, than their adversary. I believe this likely reflects their own internal political dynamics, not unlike U.S. domestic politics driving much of Trump’s actions. But with Iran, this is a more factional disunity of opinion over the best course of action vice the overly unitary decision-making process the U.S. side is suffering from. I’ve written about this before in my 25 April post; ‘The Iranian Power Struggle’: “In my years at CIA dealing with Iran and Iranians, I observed many instances of such backroom political maneuvering, including a willingness to sabotage efforts by others engaged in back-channel deals. This was particularly the case when the counterpart was America. Publicly scorned as the “Great Satan”, but secretly coveted as the superpower of choice, individuals and factions knew that whoever secured a special relationship with America would be in the pole position going forward. The attitude was “if not me, then no one!”, essentially the grownup version of ‘King of the Hill.’

This may account for the regime’s inexplicable willingness to reject any compromise while continuing to absorb punishment; perhaps more to put pressure on their internal political rivals than to gain external military advantage. In the end, it is likely they will eventually call a halt to this by reengaging on negotiations when they determine they risk losing too much capability.

Exacerbating this, I would posit that the newly ascended Supreme Leader, Mojtaba Khamenei, may in fact be a phantom leader. Alive in some fashion, perhaps largely incapacitated, but not actually in charge. And even if able to coherently express his views, in no way nearly as powerful or influential as his father. The seemingly reckless actions of the regime in courting U.S. retaliation may in actuality reflect a lack of a coherent decision-making process as opposed to a unified one. I think it is quite possible that competing factions within the regime are using Mojtaba as an avatar while they maneuver for decisive advantage.

Regardless of which faction ultimately dominates, the implications for the United States remain how to break through to the regime’s decision-makers in the near term.

Hyperbole Weakens the U.S. Position

In the meantime, Trump’s regular stream of alternating obsequious and insulting, but always hyperbolic, ‘Truths’, the result of his obvious frustration over the regime’s unwillingness to accept what he is offering – whatever that might be at that moment - serves only to inflame and/or simply confuse an already chaotic situation. All resulting from the vaguely written and amateurish MOU that Trump himself signed.

As I wrote previously in a 12 April post, Hyperbole is Donald Trump’s love language. He continues to employ it almost daily, usually in reaction to a disappointment with the Iranian regime’s actions. And almost always to the detriment of his stated desire for peace. Unfortunately, the Iranian regime has been practicing this same language of hyperbole on an industrial scale for a generation. They understand both how to use it and counter it.

But the practice of diplomacy is a quiet profession. One that requires patience. One that requires expertise. One that requires steadiness and focus. None of which characteristics the President or his negotiators appear capable of exhibiting.

If I were to give the President a piece of advice, I would echo the words of David Ignatius in his most recent Washington Post column: “Just stop talking,” although more directly and less politely, “Just shut up and let the professionals do their job!”

What now?

I wrote about what may come next, after the permanent cessation of hostilities, in my 15 May post, Groundhog Day: “The issues facing Iran prior to the War were serious, in fact existential – a collapsing economy, hyper-inflation, severe water shortages, lack of electricity, and growing widespread popular anger and unrest – and are ongoing and only getting worse. Whatever the Iranian leadership looks like, it will have to address these issues. And it is not clear that they will be capable of doing this without outside help. This is where the U.S. and hopefully our Western allies come in: sanctions relief, and extensive economic and other assistance in exchange for real changes in policy and a pullback on objectionable activities and programs. The potential for this may, and I say may, have increased with the removal of Ali Khamenei from the Supreme Leader’s seat. But it will depend on whether his son and successor, Mojtaba, is less rigidly ideological than his father. We will see if he is willing to put the Iranian people ahead of the regime.”

Next steps

First, we need to significantly blunt the regime’s ongoing ability to project power and control the Strait of Hormuz. It needs to reopen and stay open. And it will. Both sides need it to, but not on the regime’s terms. The focused effort on degrading Iran’s coastal offensive capabilities should continue apace.

We need the regime to be forced to address the internal existential threats listed above. This is sure to absorb much of their time and money and may eventually consume them. And it may even bring them back to the negotiating table. Escalating military strikes on energy facilities and civilian infrastructure would serve only to alienate the Iranian population and distract from the Iranian leadership’s appalling incompetence, strengthening the regime. As part of this, the current MOU must be abandoned and recast in a more evenhanded manner, leading to permanent peace. Adhering to it as currently written will only ensure we will be forced to return in the future. As we are already seeing.

The current dynamic from the U.S. side is emotionally driven and self-defeating. The Iranians appear riven by paralyzing factionalism, with a hefty dose of hubris regarding their temporary advantage. Neither is a recipe for success. The question is not whether Iran can win a military confrontation with the United States. It cannot. The question is whether it can continue forcing Washington to react rather than act. For now, that answer appears to be yes.

For more reads like this, and to follow Mark on Substack, click here.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

We've Seen Autonomous Warfare and We're in Trouble

23 July 2026 at 13:18


Editor’s note- Russia's war in Ukraine has fundamentally changed the character of warfare, proving that autonomous and attritable drones are no longer supporting tools but have become a decisive instrument of combat. In this provocative essay, co-authors Xen & Matthew Creedican argue that the United States must abandon legacy assumptions and adopt an entirely new military doctrine, force structure, and industrial strategy built for the age of autonomous warfare. (Xen is a former US Special Operations veteran with experience fighting alongside Ukrainian forces. We have granted his request for anonymity).

This paper is written expressly for the policy and decision makers across the military and public and private sectors who are bound to translate national strategy into reality. We will withhold for another day the arguments for convincing those who have yet to concede that the rifleman’s day is over or that drone warfare in Ukraine generalizes. Instead, we are making a series of recommendations to those already on board with direction from the Department of War (DoW) that “we are pivoting the Pentagon and industrial base to a wartime footing”, as manifested in a $50B+ modernization program to ensure that “every warfighter must have access to low-cost/attritable sUAS [small drones] to conduct missions.” To help leaders meet such a steep challenge, we will describe how the force should be structured, how doctrine should be written, and how the industrial base must be re-engineered to match present scaling by our adversaries.

What a Modern Drone Force Should Look Like, For Now

If we could snap our fingers now and summon an army well-trained and well-equipped according to the latest understanding of modern drone warfare, it might be composed of battalions fielding approximately fifty to a hundred mixed-role unmanned systems deployable simultaneously, with stocks of thousands more unmanned vehicles and spare parts (antennas, ground stations) ready to replace those attrited. The force tailoring would have to include both rotary and fixed-wing drones performing reconnaissance, mothership, electronic warfare, one-way attack (OWA), bomber, and multi-role tasks. Such a battalion should be able to organically find, fix, and finish targets at ranges up to 300km.

Presently in Ukraine, formations tend to specialize by range. Tactical or “infantry” battalions deploy quadcopters controlled by direct radio link or fiber optic from positions 3-10km from the absolute front, flirting with the danger zone, with the better teams now fielding glide-kit quads reaching out to 50+km, doubling their effective range from last year. Ground drone units are increasingly critical as well, performing the vast majority of evacuation and logistics within the 9-15km+ “gray zone” where manned vehicles are not worth the risk to employ. Dedicated drone battalions overwatch these units from 10-20km from no man’s land, operating typically out to 80km but at times out to 300km thanks to proliferating autonomy and redundant communications (direct, meshing, repeating, satellite, LTE, etc.). This upper end for the “mid-range” or “operational” level of warfare has also at least doubled since last year. Finally, specialized deep strike teams are now conducting strikes out to beyond 1500km against strategic targets, with high-volume, low-cost, independent, adaptable platforms quite different from expensive legacy US drones.

At every level of the above structure, it is understood that even the non-OWA platforms must be attritable, since they rarely accomplish more than several missions without being rendered inoperable. Particularly cheap systems are even deliberately used as decoys. And of course, seeping down into these echelons is autonomy enabled by AI, and the beginnings of swarming protocols. It must be understood that what the aircraft carrier once did to naval gunnery is what the drone is doing to the rifleman. The fundamental unit of combat power is now the small drone team, and it is an over-the-horizon asset.

Saving Combined Arms Maneuver

Drones employed properly in such formations could execute combined arms maneuver warfare rather than the attrition warfare we currently see. After reconnoitering the enemy and making contact, unmanned battalions could use air platforms in both expendable and regenerative loitering waves to degrade air defenses, electronic warfare systems, logistics, and command structures, after which successive waves could suppress and attrite ground forces in preparation for ground drones to take, hold, and shape ground. Only then would humans move forward to effectively deepen the range of their systems. All this implies an in-depth rewriting and reapplication to unmanned warfare of manuals and doctrine guides such as FM 3-0 Operations, FM 3-90 Tactics, and FM 3-96 Brigade Combat Team. Current revisions have relegated the drone to a supporting role at best. Another example: given that a legacy US Army Corps of tens of thousands of personnel has multiple days to make decisions across approximately the same operational striking depth as that of one of the aforementioned Ukrainian drone battalions of a few hundred personnel, clearly we must revise our echeloned depths of responsibility . The existing disparity has practical consequences, as Ukrainians not only handily defeat NATO forces in joint exercises, but they do it with comparatively tiny forces, striking larger formations and assets in areas thought to be “safe”.

As such, it should be clear to those familiar with the actual contestants in programs like Drone Dominance that we are staging to mostly procure platforms that are too expensive for the requested operational ranges. Although the DoW has set a target of roughly half a million drones per year for procurement, it will actually need at least fifty million to meet the lofty goal of training and equipping a ~500,000-1,000,000 man force with attritable systems. If we look to the rest of the world, we will see that Ukraine and Russia this year are each likely to utilize around twenty million drones, while China, as the manufacturer of most of the world’s drone components, will likely build the equivalent of a hundred million drones.

Predictive Doctrine for a Moving Target

But even this, unfortunately, is not the real crux of the issue with respect to the development of future requirements. Doctrine must not only be prescriptive of the present, but also of the near future. The fact is, we cannot just snap our fingers to summon a drone army. It will take years to build it out, and by then things will look even more “sci-fi”. That is, we are chasing a moving target three to ten years out, and so we had best engage in some imagination to meet that challenge.

We are conscious of how radical this is going to sound, but our goal with such provocation is indeed to shift the Overton window, so, we believe that the future will look like something out of Ender’s Game, and it’s going to happen well before those now entering the military reach retirement eligibility.

Man, Train, and Equip for the Sci-Fi Near Future

Individual drone controllers will become tactical commanders (so let’s call them “tacticians”) remotely running squadrons of individually autonomous drones, point-and-clicking their way through a 3D interactive, AI-mediated, sensor-fusion digital twin of the battlefield. The base layer is already here in the digital panopticon emerging from cloud-native Common Operating Picture (COP) software like Ukraine’s Delta merging with military AI suites. Palantir’s Maven already suggests courses of action at the command level, and there’s no reason this couldn’t be extended down to the lowest tactical levels, controllable by voice, touch, or text. In a few more years the tacticians themselves will be inside something Neuralink-shaped, performing at the speed of AI-enhanced thought and striking at the links in the chain that enable adversarial tacticians. Under those conditions the adaptation cycle, too, will move at a speed that cognitively unenhanced humans cannot keep up with, and intelligence becomes the runaway comparative advantage at every level. There is no telling where such cognitive selection pressure combined with the ability to remotely control drone swarms will end. Will individual soldiers control dozens of drones simultaneously – or thousands? How many drones should a “battalion” have?

Decentralization is a factor too. Everything we are seeing develop now is scaling in Ukraine down to the individual operator, as it must. The over-the-horizon warrior needs personal access to livestreamed tactical radar to check if the skies are clear before he exposes himself by making movement. He needs edge compute not just onboard his drones, but for local offline AI to analyze the battlefield and make decisions even in a communications blackout. Already we see backpack portable drone interceptor systems for personal defense; I’m aware of contracts under consideration for such systems to miniaturize to automated shoulder-launch, like a personal version of the tank-mounted Trophy system. The current estimate is that a soldier has one to four seconds to defend himself against a visual drone contact vectoring on him, and soon that timeline will compress enough to exceed human reaction times.

Asking what exactly the mass of conventional soldiers will do under such a radical restructuring is much like asking whether or not Large Language Models (LLMs) are going to have the net effect of creating or destroying jobs in the civilian workforce. We may see the formation of a tiny military class, or perhaps warfare will become even more industrial in human scale. Certainly, humans will be pushed farther and farther back in the logistical chain that ultimately delivers kinetic effects upon an adversary. Currently, there is a need for people to physically emplace, operate, and recover antennas, ground stations, and drones. Once robots are more commonly executing these tasks (already, some aerial drones are launched via multi-domain mothership drones), people will work on those robots, and so forth. Eventually, it’s hard to see what anyone will need to do physically, as robots will be building, repairing, improving, and employing each other. The only real foreseeable tasks left at the tactical echelon will be those of the tactician and the true engineer, who innovates and integrates locally. Whoever best automates tasks end-to-end will win the tempo fight. The transportation of weapons and sensors has to be contemplated as one mass-manufactured logistical animal.

Going further, the tactician need not position himself relative to any front at all, because he can fly remotely and because he would be sensible to reduce his threat profile from direct action threats to intelligence-driven threats only. That is, he should position himself to strike with impunity. Already in Ukraine, Sting pilots have flown their interceptors remotely 500km away from where they were launched. Midrange teams outside the gray zone already drive to position in unmarked civilian vehicles, wear their uniforms only for the minimal time needed to deploy their systems, and then fade back into the population. And the naval drones striking the Russian fleet are not generally controlled from the sea, but ultimately from bases on land. If trends hold, the smallest independent tactical elements may be able to cheaply strike anywhere on Earth within a decade.

Branching Futures: eVTOLs, Smart Dust, and Beyond

But this is merely one vision of the future. There are branching pathways, perhaps some of which may coexist. Weaponized human-optional eVTOLs like the Chinese prototype ZR-300 could become a new air cavalry paradigm unto themselves if employed en masse in shock fashion, sweeping aside whole nations in a day the way Central Asian hordes did in the Medieval period, or the way Islamist insurgents swept across the Sahel in Toyotas. Microscopic drone “clouds” also known as smart dust could penetrate any conventional barrier, performing reconnaissance or even coalescing explosively or penetrating air ducts and lungs. Does this seem one step too far, straining credulity? Remember that “any sufficiently advanced technology is indistinguishable from magic” from the perspective of the old guard, and that all these technologies are already real, just not fully scaled and integrated. In fact, micro drones were feasible decades ago, technically if not economically – timing is everything. We already have a leading indicator in the German army’s very real purchase of cyborg insect swarms from Swarm Biotactics. Against such dizzying possibilities, we will advocate further on below for a rapidly adapting structure that ingrains real-world feedback and extrapolates from it.

Economies of Scale for Drone Production

First, let’s deal with how we produce enough useful drones to simply match our adversaries. The necessary industrial base to deliver manufacturing on the required scale simply does not exist anywhere in the West currently, whereas China has quietly captured the drone market and the sub-component supply chains over decades and is integrating such technology down to their lowest tactical echelons at a hundred times our volume. Much has already been written about the need to innovate and iterate on a scale of weeks rather than decades, and while true such a need potentially comes with the steep requirement of continuous retooling of factories and endless R&D. Ironically, funding this effort at the scale needed will require a vision across a much longer (generational) timeline, in opposition to the quarterly results that drive Western business strategy. Currently, the US buys primarily the end-product rather than engendering the component markets directly. From a cost-savings standpoint, we would do well to preemptively build adaptable systems, and also to stop trying to update legacy programs (we will never need a new sniper rifle). The DoW budget has to fund the domestic mass production of production itself, with an eye towards dual-use sub-components and machine tools, since commercial R&D and production can fund itself to an extent. Vehicles, phones, and drones sold into civilian markets pay for their own scaled production, and volume buys down cost. As it stands now with our current component outsourcing, we are paying our enemies to equip us, tying the rope with which they intend to hang us.

Pillars of a Sovereign Drone Industry

The pillars of industry to be funded include locomotion, actuation, energy, storage, compute, sensing, and communications. The component-level specifics, meaning motor sizes, magnet chemistries, cell formats, and the rest, belong in a technical paper. What’s important here is that the government has to guarantee the market for base components as much as scale requirements dictate and raw materials allow, while simultaneously finding the alternatives that bypass adversarial chains entirely.

Shallow or single-sourced chains halt on the first disruption, so volume has to be distributed across multiple domestic entities in order to create redundant paths. That means accounting for the physical bottleneck of factory siting, the legal bottleneck of restrictive radio frequency and flight-test regimes, and the social bottleneck of technical workforce recruitment, which in practice means a nationwide push for engineers with the education pipelines to match. We should fixate less on the static stockpile and more on the velocity at which the economy can replace a lost or outdated asset. Eventually, this may look like self-assembling factories, but for now we should see a dramatic increase in industrial jobs, not a reduction.

Guaranteed Requirements and Manufacturer Caps

The Departments of War and Commerce must jointly establish requirements and guarantee purchase of components at massive volumes, over multi-year timescales, according to stringent standards for minimum viable products meeting or exceeding foreign equivalents, with caps set on what portion of the total any one manufacturer can source. Subcontracting and manufacturer caps will encourage competition inside our own secure ecosystem rather than across national borders, where we are frequently undercut by adversaries. As needed, the government can resell unused inventory back to industry at or below the cost of subsidized foreign imports, letting American companies build with cheap secure inputs.

We have a realistic precedent for all this, as described in the book Freedom’s Forge: In anticipation of US entry into WW2, President Roosevelt brought together former of heads of industry in order to align military requirements, government funding, and civilian production capacity so that goals could be revised upward continuously, and the resulting volume forced a dynamic of subcontracting to keep up with demand. American industry responded, not only producing hundreds of thousands of complex war machines, but also rapidly retrofitting them as needed based on frontline feedback, on much the same timescales that we today see in Ukraine.

Innovation on the Machine Timescale

In the near future, however, we will have to go even further, with innovation necessarily occurring on the machine timescale. The same digital twin in which soldiers will virtually train and fight will also let us simulate hardware, factories, and logistics before steel is ever cut. The panopticon in which the end product’s edge sensors feed data into will be the same in which an arbitrary number of tests under variable conditions may be run before the more refined next generation of product is built. Supply chains from base-component assembly through fuel and battery pathways can be estimated and stressed the same way. Data streams from around the globe and from local instrumentation can all compartmentalize or cohere as needed for efficiency or breadth of understanding, all of it parseable by ever-increasing machine intelligence, at worst bounded in growth only by Moore’s Law. As an aside regarding encouraging a martial culture amongst the youth who will one day fill the tactician ranks, our military should release realtime strategy wargames involving drone swarming, initially as standalone games but eventually living inside the kind of digital twin explained above. And as earlier mentioned, all of this will eventually be experienced in breathtaking detail in virtual reality and via brain-machine interface. This is not so distasteful a task on a wartime footing, especially considering even in peacetime the military has released first-person shooter games and simulations.

Massive integrated training areas, in which units, contractors, and manufacturers co-locate to live-fire and iterate together, belong on the near-term build list. The mandate inside such an area should be inverted from current practice, so that the burden shifts from justifying permission for a given action to justifying why any given action cannot happen. The FAA, the FCC, and the rest of the regulatory apparatus should be effectively kicked out of the perimeter, and legislation should extend a good-faith liability shield covering crashes and honest mistakes. Dedicated integration units, which can be thought of as Transition in Contact supercharged, should be created. The core skill of these new units would not be warfighting but rather adapting to and assembling whatever technology is available. Every unit, not just dedicated ones, should additionally have at least some innovation budget and personnel, so that they are not merely customers but also integrators. Specifically, this means the military needs to be mass recruiting engineers to fill out dedicated innovation units and also sprinkle across the wider force. And lastly, the soldiers who will become the drone tacticians must be allowed to train for that role full-time, studying meteorology, radio theory, and other topics and skills currently regarded as arcane among warfighters.

A Permanent Feedback Loop from the Front

None of the above works without a permanent structured feedback loop that connects requirements to what is actually happening in a live conflict. Local units cannot generate requirements for now let alone five years out if there is no frontline feedback, no rotating instructor cycle, and no living link to platforms that do not yet exist in Western inventories. A peacetime force generating peacetime requirements will buy peacetime equipment no matter how decentralized the process is. Instead, we need a much greater scale of personnel who are aggressively forward deployed to conflict zones, visiting tactical operations centers and doing ridealongs on relatively low-risk mid- and deep-strike operations. Our partners will gladly place them there if they provide as much as they take. Directly in this role we can put our incredible all-volunteer special operators, who want nothing more than to get close to the fire. Adjacent to it, in lower intensity areas, we can forward deploy conventional troops as well to learn from partners, including by attending their own schoolhouses.

What we are suggesting here is deploying thousands of troops, not merely small cells of elite military and intelligence agency operators whose reporting does not reach the wider military. Much like the technical innovation measures described in the previous paragraph, these warriors should be distributed both into new dedicated units for the express purpose of doctrine, tactics, techniques, and procedures innovation, as well as across the wider force, to supercharge change and acquire what Clausewitz called a “fingertip feel” for the present state of war. If there is really no political appetite for this, then the only other option is to accomplish the same via other methods, such as by inviting large numbers of military instructors from partner nations currently involved in active conflict or by rotating civilian contractors more discreetly through conflict areas, as suggested by former Green Beret Bryan Pickens.

Piping Frontline Signal Directly to Doctrine Writers

Regardless of how it is done, the core part of whatever structure is created should report directly to the senior military leadership responsible for the development of force-wide doctrine and requirements, so that they cannot ignore reality and hide in dead paradigms. Various new offices are being created, such as DRPM-UxS, and our hope is that with direct signal they can utilize sweeping - even disruptive - authorities to continually remake the military; for, as Napoleon said, “unhappy the general who comes on the field of battle with a system”. Given the enemy’s endless adaptation, the best meta-doctrine is to accept no particular doctrine as certain or permanent, and even to assume that it is likely wrong if it has not been overhauled lately. Official doctrine documents would be better written and accessed as living Google docs rather than year-dated static PDFs.

This applies down to the nitty-gritty of institutional knowledge as well. The train-the-trainer model informed by forward-deployed reporting must fuel change in our own programs of instruction and battle drills, so that we actually know how to employ the unmanned weapon systems we are scaling, a capability which further feeds into local units understanding the requirements for the next round of equipment purchases.

A sharedrive with compartmentalized access is not enough; we need our whole force separated at most by just one degree from someone who has seen modern war up close. And if the military is that close to the combat demand signal, then by extension the manufacturers who visit the units they are equipping will be that much closer.

The Transition Engine and Treating Ukraine as a Peer

Joseph Gagnard of Atlas Special Projects calls the sum total of all these joint efforts the “transition engine”, meaning operators, builders, contracting specialists, and investors institutionalized together, because no single one of them fields capability alone. That transition engine has to be paired with a treatment of Ukraine that most of the current western defense industry still resists. Treat the Ukrainians peer to peer, at least as well as Taiwan or South Korea, and better than either, because they are in an existential fight we cannot afford for them to lose. I suggest bringing thousands of Ukrainian engineers, managers, and operators into the United States to help build the drone industry. Regarding AI, America holds the architecture, the compute capacity, the models, and the global reach. But Ukraine holds the live-fire scaffolding for how that data actually gets generated, labeled, fused, and fed back into the iteration cycle; they have the premier Common Operating Picture software, Delta, to facilitate collection; and they are best positioned to evaluate the battlefield effectiveness of each successive generation of combat AI.

Furthermore, Ukraine is waging a global hybrid war on the West’s behalf, which we hardly engage in except via the most deniable means. China, Russia, and their proxies and allies ruthlessly exploit neutral ground with a vast array of tools, strangling us of resources, allies, and positioning. As political will allows, we suggest unleashing our special operators and intelligence officers in nearly-overt ways, in partnership with Ukrainians, who willingly perform more risky action and have a history of cooperation with our intel services, to operate across the globe responding in kind to the Axis arrayed against us. Drones, of course, are the perfect semi-deniable weapon for this. And the signal we receive back by more heavily involving our forces in low-intensity conflicts will feed back into the plan regarding getting a “fingertip feel” back for war.

The Vulnerable Homefront

The homefront, meanwhile, is ripe for a crippling preemptive strike against us. Our infrastructure is vulnerable, and drones as stated are a perfect scalable weapon that can be employed by deniable proxies. A strike could produce economically disastrous effects, and in response to such an attack of ostensibly deniable origin and limited death toll we would certainly not seek to launch, say, a nuclear retaliatory strike. Containerized long-range drones could be lurking on civilian ships off our coast right now. DHS testified to the Senate that in 2025 there were an average of 10,000 foreign drone flights per month near the southern border. Particularly at risk to such a looming threat is our AI infrastructure. Whatever one’s thoughts on the supposed “AI bubble” (the dot-com bubble didn’t stop the triumphant march of internet adoption, did it?), it is undeniable that both the previous and current administrations have regarded the AI race as existential, and our enemies clearly feel the same way.

We saw from a recent strike by Iran on data centers in the UAE providing Amazon Web Services that such centers are vulnerable, going down for several months at a minimum due to spreading fires and long lead time for repair parts. A few hundred drones striking data centers or upstream links in the chain could easily set us back in the AI race which could provide our adversary an opportunity to surge permanently ahead, a situation which, again, our bipartisan leadership regards as an existential threat.

A Decentralized, Always-On CONUS Defense

The right posture for CONUS defense is one that is always on and autonomous-capable, able to intercept without waiting for the chain of command. In addition, such efforts must take the form of a whole-nation decentralized effort. In Ukraine, a nationwide cheap network of mobile phones acoustically tracks hostile long-range drones swarming their country, and recent legislation approved the use of electronic warfare and interceptor drones by businesses to protect their own assets. New manufacturing and power facilities tend to be built in a distributed, resilient, redundant manner, with cheap hardening available for obvious targets (like anti-drone “cages”). Our recommendation, like elsewhere, is to empower everything local. We would even go so far as to suggest that the Second Amendment needs to extend to counter-drone equipment, and any U.S. person or institution should be able to engage perceived threats up to certain altitudes above their own land.

AI as Sovereign Terrain

We can extend the Second Amendment and drones argument to the First Amendment and AI; that is, to digital and not just physical terrain. Across the information domain, China steals from us and undercuts us, releasing open LLMs to erase Western software margins. Intellectual property in this context is a burden more than a benefit by now, perhaps functioning somewhat to promote internal competition but leaving us wide open for external exploitation. The best way to stay ahead of our enemy in the face of their undermining of our brittle centralized systems is to fight fire with fire. We need policy and funding to shy away from the current big LLM players and instead encourage open models, local compute, and data sovereignty, which offer numerous long-term advantages across the board that mirror the kind of resiliency and initiative-encouraging effects we will get by distributing compute and AI models down to the lowest levels of our military.

Encryption code, for example, was previously ruled to fall under free speech protections. There is an argument against allowing centralizing and censorship of digital spaces as well, regarding them as a kind of common space since there is a barrier to entry in networking at the level of Internet Service Provider infrastructure. We need a diverse market of competing open AI models, local compute, social networks, etc. A centralized internet and centralized AI have severe risks within the domains of psychological and information warfare, which play out across the public digital arena, but to go further in that discussion we would have to depart from the scope of the kinetic warfare focus of this article. Suffice to say, the most dystopian and existentially risky outcomes are plausible if centralized AI should win, whether by our own hand or the hand of the enemy, who will surely centralize control over their models as soon as they gain an advantage.

Deterrence via Force Projection

Another point worth addressing when discussing CONUS defense is the idea that “the bomber always gets through”, which is probably true regarding drone swarms. However, regarding the homefront, Ukraine has shown first that the effects of long-range drone attacks can at least be mitigated significantly, and that it is economically optimal to do so. Furthermore, the striking arm we are also building alongside the defenses will serve as a deterrent, since nuclear doctrine of Mutually Assured Destruction is insufficient for the aforementioned reasons. If we can threaten to do unto our enemies as they wish to do unto us, and indeed if we actually regularly exercise this capacity in the global low-intensity ongoing war, then we will make them think twice before hitting us.

The Core Principle: Endless Distributed Adaptation Capacity

The single principle of this piece is this- Stop buying end products and start buying the ability to produce them, at scale, sovereignly, and forever – doctrine here being one of those end products. The victor that emerges from the next several years will have built the meaningfully decentralized version of what we have described here, meaning distributed compute, sensors, swarms, command, cognition, industry, and authority, with the standards and alliances to match. The rallying cry, in the end, is the architecture. In the last great war, we firebombed cities, preemptively invaded neutral countries, and of course ultimately resorted to nuclear weapons. The political license for a national revitalization as a form of deterrence seems, by comparison, an easy pill to swallow.

Note from author (Xen)- For those who wish to understand not merely the how but the why, or who have comments, or who desire greater breadth or depth of understanding: Over the coming weeks I will be sharing additional information to my personal Substack and website. As for my co-author, Matthew A. Creedican, you can find him on LinkedIn.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The $1.5 Trillion Defense Budget Without a Strategy

21 July 2026 at 05:00

“This is not at all a strategy-driven [FY 2027 defense] budget. This is a budget-driven budget. If you look at the Truth Social posts by the President [Trump] and the statements of the people around him, he [President Trump] makes very clear that this budget was driven by a budget number, a budget target, an arbitrary level that was set based on five percent of last year's GDP…They set this arbitrary level and then at relatively the last minute in the budget development process the [Defense] Department was told come up with a request that gets you to this number, this $1.5 trillion number. And so they did.”

That was Todd Harrison of the American Enterprise Institute and one of the nation's top experts on defense strategy and the defense budget, speaking last Tuesday at the Brookings Institution as part of a panel on The FY 2027 defense budget: How much is enough?

Remember, as I wrote last week, the Trump FY 2027 defense request is for $1.15 trillion with another $350 billion request to be placed in a FY 2026 reconciliation package; and there now also is the new FY 2026 supplemental request, which has another $67 billion for the Defense Department.

House members have been weighing all the defense numbers and this week may be voting on a FY 2026 reconciliation package of $95 billion with only $73 billion for defense – far less than what was being sought.

Last Tuesday, Harrison went on to explain what may have been going on: “I say it is absolutely not a strategy-driven [FY 2027 defense] budget because they didn't have to make hard choices. They made some easy choices.”

As an example, Harrison said, “Do you want, you know, a fourth generation fighter jet? Buy some new fourth generation [F-15s]; or do we want to continue buying the fifth-generation fighters like the F-35 we have in production; or do we want to invest in sixth generation fighters? Do all of them, right? You can do all three at once, if you have a virtually unlimited budget, you don't have to make those hard tradeoffs.”

And, in fact, all three are included in the proposed FY2027 defense budget.

But Harrison goes on to suggest another way to view this Trump defense budget giant increase saying, “There's still a limit to how much the department can consume in terms of this funding…because I don't think they [the Trump budgeteers] actually intend this to be like a one-year budget authority number, especially with the reconciliation [set at $350 billion]. I think it is actually more like a five-year budget number that they're trying to get pre-funded up front, but they actually plan to spend it at a slower pace over the next five years.”

Harrison also looked at “the parts that I think absolutely don't belong in here are these big pots of money they created in defense-wide accounts that have very little description with them.”

For example, he picked out “$54 billion in the Defense Autonomous Warfare Group (DAWG) line item. That is a single program element that's got $54 billion in it,” Harrison said. “That's unprecedented. If you read the budget description with it, it gives very little detail. You know, it's [clears throat] supposed to be investments in drones and things like that, but like tell us

quantities, tell us specific types of drones, like tell us what you're going to be using it for, and that detail is not there.”

Harrison went on, “It appears they haven't figured that out yet, so I think $54 billion is quite a reach, trying to ask for that much money for something that has not yet been well defined. So, I think that there are areas here where they've really overshot and they've tried to just throw everything in there and ask for a super high number. And I wonder if they almost expect that they're not going to get that full number -- that Congress will cut them back down quite a bit. But they were just trying to reach that overall $1.5 trillion level.”

As Yahoo Finance pointed out earlier this month, the $54 billion for DAWG sought for FY 2027 is 243 times greater than what DAWG got this year, and “now exceeds the entire Marine Corps budget request of $52.8 billion and represents nearly 15% of the entire $350 billion reconciliation package.”

Harrison’s view: “You get to the endgame, Congress is going to have to sort through this and say, ‘Okay, what are the what things in here are serious things that really do need to get funded one way or the other, and we'll have to figure out how to make that happen, and what are the other things that were just budget gimmicks or just filler?’"

Harrison was not the only expert on last Tuesday’s Brookings panel.

Joining him were David Wessel, who runs Brookings’ tax and fiscal policy in the economic studies program; and Mara Karlin, professor at John's Hopkins University’s School of Advanced International Studies, who has worked for six Defense Secretaries over her career.

Wessel took a broader financial view saying, “The President is proposing a big defense budget at a time when we have unsustainable fiscal trajectory, and so I think that raises an important question and that question is…budgeting is about tradeoffs and the President and Congress at the moment seem to be avoiding trade-offs. There are ways we could offset if defense spending is really important. We should think about ways to pay for some of it either by cutting some other places in defense or raising taxes. And there's some ideas floating around on that, but none of them are politically popular.”

Wessel also raised two other issues: “I think it also requires some trust on the part of the public that the money is being well spent and that relies on Congress doing oversight. And secondly, that we are sticking with a military that is nonpartisan and follows the leadership of the President and the Congress, but is not totally politicized. And I'm afraid that the trust in the military is being eroded by some of the personnel decisions that Secretary of Defense Pete Hegseth is making. And I think that's a problem.”

As for Karlin, she referred to the Trump national strategy and focused on what she called “a break with the bipartisanship that has characterized how folks have thought about these threats for a long time.”

Karlin noted, “The real emphasis of this [Trump national] strategy is on the Western Hemisphere, right? The real threat is seen in this strategy as these alleged narco-terrorists as they're so named…So, that's the priority.”

But, she adds, “You then see China mentioned, but in a pretty circumscribed way, just the first island chain. And in general, the language reads a lot softer than almost any recent defense strategy. You see a desire to downgrade involvement in European affairs, a little bit of mention of the Middle East, but in no way signaling that we would be starting this massive [Iran] conflict. And so here's where I think, there's some confusion worth highlighting because traditionally a national defense strategy is a decoder ring. It's going to tell you where the Secretary of Defense will put their energy and attention.”

“When we look at this budget, this very large budget, that's really at kind of World War levels,” Karlin said, “and frankly, the number [$1.5 trillion] isn't really merited by the strategy.”

She explained, “If one were really to just prioritize the Western Hemisphere and this quite circumcised focus on China as a major threat, and not be involved in most other regions of the world, in fact, the Trump administration could have put out a quite tiny defense budget request. So I leave you with a bit of perplexity.”

Two more things Harrison mentioned need recording.

“I forgot to address the [Trump] battleship issue,” Harrison said at one point, “because you know that's in here and far from defending it, I think that's one of those examples of things that got thrown in because they didn't have to make tough choices.”

Then he explained, “No one in the Navy can say with a straight face that we're going to go from starting a brand-new, clean-ship design in FY 2027, to procuring the lead-class [battle]ship in FY 2028, to going to all the way by FY 2031 being at full rate production, ready to buy them at one per year. That doesn't pass the laugh test…And so are we just setting ourselves up to spend a few billion dollars chasing, you know, this weird idea before we eventually have to cancel it and then things go back to the way they were before.”

Finally, Harrison said, “I think there needs to be some fundamental look on the congressional side at just how do we reform the budget process to get it working again; open the aperture to things like changing the start date of the fiscal year [which now begins October 1], re-jiggering the committee structure.”

I believe Harrison is questioning why each year the Armed Services Committees in both the House and Senate each authorize spending programs, and then the House and Senate Appropriations Committees set the actual dollar-level of funds made available for that year.

“You know,” Harrison said, “I'm talking a lot of third rails here, but I think we're at that kind of point like we were in the early 1970s where Congress realized it [the budgeting process] just wasn't working. I think that they need to do some serious inward-looking reform like that.”

I agree, having twice worked on the Senate Foreign Relations Committee in the 1960s, and followed defense spending over the past 60 years. Harrison is right – the Legislative Branch system for passing Executive Branch funding needs to be repaired.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌
❌