Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Cipher Brief

Pakistan’s New Military Order Is a Warning for Washington

9 September 2026 at 08:33

In Washington, Field Marshal Asim Munir increasingly looks like the man who can make Pakistan useful to the United States. Pakistan has just written Munir even more deeply into the architecture of the state as he now sits atop a legally centralized command that reaches conventional forces, strategic systems, and the prime minister’s national-security advice. Munir, now formally serving as Chief of Defense Forces, speaks directly with President Donald Trump and has become Washington’s principal channel for engaging Tehran.

The latest restructuring of Pakistan’s military command has actually made the opposite case. The 27th Constitutional Amendment, followed by legislation passed this month to implement the new command architecture, has concentrated unprecedented authority in Munir’s hands. Yet his military cannot stabilize Pakistan-administered Kashmir, cannot contain the Tehreek-e-Taliban Pakistan (TTP) and Baloch insurgents, and has still signed a mutual-defense pact with Turkey and Saudi Arabia—dubbed the Mecca Accord—that could drag it into distant crises. For the world, treating Pakistan as a reliable intermediary in negotiations with Iran would be a mistake of timing and of judgment as the state becomes more militarized domestically, more ambitious diplomatically, and increasingly overstretched militarily.

A Field Marshal Above the State

In November 2025, the 27th Constitutional Amendment abolished the chairman of the Joint Chiefs of Staff Committee and created the office of Chief of Defense Forces (CDF), held concurrently by the army chief. The restructuring was completed with another step this month when Pakistan’s parliament passed the Defense Forces Act 2026 and amendments to the National Command Authority Act, providing the statutory framework for Munir's new position and headquarters. The new architecture gives the CDF a central role in operational command and joint military coordination across the armed forces.

The new law places the army, navy, and air force under a unified Defense Forces Headquarters commanded by Munir. He is designated the prime minister’s principal military adviser on national security and defense and exercises operational command and control across the services with sweeping personnel authority—hiring, firing, retirement, and extensions. Amendments to the National Command Authority law align nuclear and strategic command with the same hierarchy, with a new four-star Commander of the National Strategic Command sitting alongside the CDF. The significance goes beyond military administration, as Munir now occupies a position from which military command, strategic security policy and foreign-policy influence converge. He is not constitutionally Pakistan's president or prime minister, but describing him merely as a military officer increasingly misses the political reality. Such radical consolidation of power in Pakistan’s civil-military landscape matters for Washington because the United States is increasingly treating Munir personally as a diplomatic asset. Therefore, Washington must factor in that any “Pakistani” channel on Iran now runs, in practice, through a single command that answers first to its own institutional interests.

Consolidation Without Control

The strongest argument against treating Munir's Pakistan as a reliable strategic partner can actually be found inside Pakistan itself. The military has acquired unprecedented institutional power, yet the state remains under enormous security pressure. Pakistan Institute for Conflict and Security Studies data show that July 2026 was the deadliest month of the year, with 606 people killed in militant violence and counter-militancy operations, including 112 security personnel and 401 militants. The violence is concentrated precisely in Khyber Pakhtunkhwa (KPK) and Balochistan, where Pakistan's military has struggled for years. Such a security landscape is a sustained counterinsurgency burden for a military that is simultaneously presenting itself as a regional security provider.

The latest round of violence in Pakistan-Administered Kashmir has added another layer of security burden for an overly stretched military. In the surrounding areas of Rawalkot, Pakistan-administered Kashmir, protests led by the Joint Awami Action Committee (JAAC) escalated after authorities outlawed the movement under anti-terrorism laws, suspended mobile data and internet services, and deployed security forces ahead of a JAAC-organized June 9 strike. According to a local human rights watchdog report dated August 8, at least 89 civilians died in Pakistan-administered Kashmir as a direct result of the state’s brutal crackdown on unarmed protesters.

Locals demanded cheaper power from dams that generate electricity for Pakistan, representation that is not diluted by non-resident seats, and an end to elite privileges. The state’s answer was lethal force, sedition cases, travel advisories, and the criminalization of a civic coalition that had previously extracted limited subsidies through protest. That is the Balochistan playbook applied to a territory Pakistan still markets internationally as “Azad” or free. It did not produce consent but a banned movement, underground leaders, and a legitimacy crisis inside a territory the army treats as strategic hinterland. If Munir’s new command structure was meant to deliver coherence, Kashmir shows the opposite, where a security establishment that can rewrite the constitution faster than it can address bread-and-butter revolt. An army that cannot manage a rights protest in Muzaffarabad and Rawalakot without mass casualties is not an army that can be trusted to midwife a delicate regional settlement with Iran or be a reliable partner for the so-called Mecca Accord.

Pakistan’s Utility Should Not Be Mistaken for Reliability

US talks with Iran already sit on a knife-edge of “Economic D-Day” politics, Hormuz control, and factional vetoes inside Tehran. None of this means the United States should abandon Pakistan as that would be strategically simplistic. Pakistan remains nuclear-armed, sits between Iran, Afghanistan, India and China, and retains diplomatic access across the Muslim world. Its ability to communicate with Tehran can be useful, particularly when direct US-Iranian channels are blocked. Three factors that Washington should use to distinguish between utility and reliability while dealing with Munir’s Pakistan:

First, Munir’s legal supremacy does not equal policy reliability. A CDF who is also army chief, principal adviser, and strategic-command fulcrum will filter any Iran file through the army’s need to look indispensable at home—that incentive points toward swagger, not quiet brokerage.

Second, Washington cannot treat Islamabad’s internal security failure as a side issue. An institution that answers civic protest in Kashmir with live fire and a terrorist ban is the same institution that would be asked to counsel restraint, verification, and de-escalation with Iran. The record says it prefers coercion when legitimacy frays.

Third, Munir’s capacity is already committed to a plethora of insurgencies. TTP and Baloch campaigns consume attention, ammunition, and men. A Mecca clause adds hypothetical external obligations without adding spare combat power. A partner that is simultaneously over-centralized and overstretched cannot deliver the one thing Washington would need from it: consistent, low-drama influence on a file that can restart a wider war.

If the United States wants Pakistan to help mediate with Iran, it should judge Islamabad by the outcomes of that diplomacy, not by the personal access Munir enjoys in Washington. And if Washington wants Pakistan as a security partner, it should look beyond the impressive authority of its field marshal to the increasingly unstable state that authority is supposed to govern. A stronger Pakistani army does not automatically produce a stronger Pakistan. And a stronger Munir does not automatically produce a more reliable American partner.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The AI We Cannot Deploy — And What Is at Stake

8 September 2026 at 08:49

Last week, I argued in these pages that the United States is buying an army it cannot command — writing procurement checks at a scale its adversaries cannot match, without writing the doctrine or arbitration to decide how the capability behind those checks gets used. Not everyone agreed. The sharpest pushback came from readers with institutional equity in the current procurement path — those with the most to lose if the diagnosis is right. Fair question they kept asking: what is at stake if we get this wrong?

The answer arrived this week, and it is not what most observers are watching.

Beijing is pursuing a two-pronged strategy against the American artificial-intelligence industry, and neither prong depends on beating American laboratories on model capability. The first prong attacks the market instrument that finances the industry: paid enterprise access to closed frontier models at premium margins. The weapon is state-backed open-source saturation of the global developer market. When Chinese laboratories release high-performing models at zero marginal cost, the price American laboratories can charge collapses — and with it, the revenue that funds tens of billions in specialized compute committed to their pipelines.

The second prong is architectural. American frontier laboratories run closed models in centralized data centers connected to their customers via fiber. The Pentagon has awarded contracts for missions that cannot use that architecture — drone swarms, autonomous undersea platforms, cognitive attack detection, and tactical multi-sensor fusion. Consider a drone swarm over the Taiwan Strait that must identify and engage a hostile target in seconds. It cannot query a compute cluster in Virginia and get an answer in time. The bandwidth needed in a denied, degraded, intermittent, or limited spectrum environment is unavailable. Chinese research has shifted toward Large Concept Models — smaller, edge-resident, multi-sensor — that run on the platform and fuse light-detection-and-ranging, radiofrequency, electro-optical and infrared, and acoustic inputs at the edge, without a network dependency an adversary can touch.

This is not a theoretical architecture. Ukraine is running it now. Ukrainian drone units operate with organic, edge-resident targeting within seconds of adversary contact, without a reliable network back to headquarters. Ukrainian schools graduate thousands of drone specialists each year. The country teaching NATO the most about the next fight is doing so in the register the American AI stack cannot yet operate in. The contracts are being placed. The integration doctrine has not yet been written.

Beijing has run this playbook before. Western economies depend on China for rare-earth and critical-minerals processing — the industry that supplies permanent magnets, batteries, and defense electronics. Every F-35 electric-actuation system, every Virginia-class submarine drivetrain, and every Patriot interceptor guidance package relies on rare-earth processing capacity the United States cannot reconstitute within a decade. That capacity was lost not because the deposits lie under Chinese soil but because Beijing sustained state-subsidized processing for twenty years at prices that broke the private-sector cost of capital in every alternative jurisdiction. Open-source artificial intelligence is the same instrument, aimed at a different substrate.

What is at stake?

First, America's most consequential capital-expenditure cycle. Roughly $400 billion a year in AI infrastructure is financed against a revenue model an opposing state has organized its economy to defeat. If that model breaks on Beijing's timeline, the compute pipelines carrying a meaningful share of American growth do not close.

Second, Pentagon operational readiness. Contracts placed today for missions the Pentagon needs to field in three to five years cannot be executed by an AI stack designed for centralized data centers. Platforms that cannot operate in a multidomain and joint-force environment at wartime tempo are not a deterrent. They are procurement projects.

Third, alliance credibility. Sovereign AI programs in Korea, Japan, and the Gulf price today against the American premium-margin model. If it breaks, those programs re-price against Chinese open-weight tooling, and the alliance's technological dependency structure shifts.

Fourth, deterrence. The Taiwan Strait scenario is not theoretical. The platforms that would decide it are being contracted for now, on an architecture that cannot execute the mission at wartime tempo.

What needs to happen requires an integration authority the American sovereign apparatus does not yet exercise. Two responses.

A state-capacity capital response to the first prong. Some form of federal instrument that bridges the compute-to-market pipeline so a Chinese-organized collapse in AI pricing does not take the compute build-out with it. Export-import financing, defense production authorities, and strategic stockpiles are the precedent. No current U.S. government office owns this problem.

A Pentagon-led investment in a distributed inference substrate — the shape of what the Joint Fires Network concept was originally designed to be. Edge-native, platform-resident, multi-sensor, doctrinally integrated. This is procurement of an integration architecture as much as procurement of a technology. The Pentagon has placed the contracts for the platforms. It has not placed the contract for the integration.

Last week I wrote that America is buying an army it cannot command. The diagnosis has evolved: America is also buying an artificial intelligence it cannot deploy. Ukraine is teaching the doctrine the American AI stack has not been designed to run. Beijing is engineering the collapse of the revenue model that stack is financed against.

Coordination assigns. Integration arbitrates. What is at stake is whether the American sovereign apparatus can find the integrator — for the capital response and the operational doctrine — before the platforms the Pentagon is buying arrive without an architecture capable of commanding them.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The New Economics of Warfare: David vs Goliath

4 September 2026 at 11:09

The most important lesson emerging from the Iran conflict may not actually be about Iran. It is about the changing economics of warfare and what happens when autonomy, artificial intelligence, commercial technology and inexpensive mass begin eroding advantages once reserved almost exclusively for major powers.

In many ways, modern warfare is increasingly becoming a story of David versus Goliath. The difference is that today’s David is armed with drones, software, commercial sensors, open-source intelligence and rapidly adaptable technology. Goliath still has overwhelming advantages in scale, firepower and resources, but the sling has become far more sophisticated — and far cheaper.

For most of the modern era, advanced military power belonged overwhelmingly to countries capable of spending billions of dollars on sophisticated aircraft, warships, missiles, sensors and command-and-control infrastructure. That advantage is not disappearing. Aircraft carriers, submarines, advanced fighters, bombers and integrated missile defenses remain essential instruments of national power. But the economics beneath them are changing as autonomy, AI, inexpensive sensors, commercial communications, advanced manufacturing and widely available components lower the cost of creating meaningful military effects.

Ukraine provided the first large-scale demonstration of this shift. A materially weaker “David” used drones, software, commercial technology, open-source intelligence and rapid battlefield innovation to impose extraordinary costs on a much larger Russian “Goliath.” Ukraine did not eliminate Russia’s advantages in manpower, missiles, aircraft or industrial capacity. It showed that technology could narrow the gap without matching a stronger adversary platform for platform.

Iran is now demonstrating another version of the same problem. Tehran cannot compete with the United States carrier for carrier, fighter for fighter or missile-defense battery for missile-defense battery, but it does not need to. Iran has spent decades investing in missiles, drones, proxies, cyber capabilities, maritime harassment, information warfare and strategic geography precisely because those tools allow a materially weaker power to impose disproportionate costs on a stronger one.

That is the economic logic of asymmetric warfare. An inexpensive autonomous aircraft does not need to outperform an F-35, and a small unmanned surface vessel does not need to defeat a destroyer in a traditional naval engagement. It only needs to create enough risk that the defender is forced to respond. When one side can repeatedly spend thousands or tens of thousands of dollars and compel the other to spend hundreds of thousands or millions, the exchange ratio eventually becomes strategically significant.

The United States cannot build a sustainable long-term strategy around answering every inexpensive drone with a multimillion-dollar interceptor or every maritime threat with another billion-dollar warship. That does not mean exquisite platforms are obsolete. It means using exquisite platforms to solve every problem eventually becomes economically unsustainable.

The more useful debate is not whether a drone can replace a fighter or whether an autonomous vessel can replace a destroyer. They cannot. The better question is how many missions currently concentrated aboard expensive crewed platforms can migrate toward cheaper autonomous systems: surveillance, reconnaissance, communications relay, target detection, electronic sensing, mine detection, logistics, persistent maritime presence, decoys and distributed weapons carriage.

Technology disruption rarely begins by replacing an incumbent system outright. It begins by stripping away individual functions. Instead of asking whether one autonomous vessel can replace a destroyer, military planners should be asking what happens when dozens of autonomous vessels operate around that destroyer, extending its sensing range, complicating enemy targeting, absorbing risk, providing persistent presence and allowing the crewed combatant to operate farther from danger. The destroyer remains essential, but its role changes.

Artificial intelligence accelerates this transition because it changes the manpower economics of military mass. Traditional military power is extraordinarily manpower intensive. Every additional aircraft, ship or vehicle generally requires crews, training, maintenance and support personnel. Software scales differently. As autonomous systems become more capable of navigating, sensing, classifying targets and coordinating with one another, fewer operators may eventually supervise far larger numbers of assets.

The strategic value is therefore not simply removing a sailor or pilot from danger. It is changing the relationship between manpower, mass and military capability. Ukraine has also shown how quickly this cycle can evolve: operators identify a battlefield problem, engineers modify hardware or software, the adversary develops a countermeasure, and the system changes again. That cycle can occur in weeks while traditional acquisition processes often operate in years. The widening gap between those timelines is becoming a national-security vulnerability.

Iran also demonstrates why the economics of modern warfare extend far beyond the price of a missile or drone. Consider the Strait of Hormuz. Iran does not need to defeat the U.S. Navy in a traditional fleet engagement to create a strategic crisis. It needs only to generate enough uncertainty around one of the world’s most important maritime chokepoints to affect shipping behavior, insurance premiums, energy markets, naval deployments and political calculations thousands of miles from the battlefield.

A drone does not necessarily need to sink a tanker to be successful. If it forces commercial vessels to reroute, raises insurance premiums, pushes energy prices higher, requires additional naval escorts and generates political pressure in Washington or allied capitals, it may have produced a strategic return far beyond its acquisition cost. The Strait of Hormuz is therefore not merely geography; it is economic leverage.

The same logic applies to the Bab el-Mandeb, the Red Sea and other maritime chokepoints. Protecting those spaces exclusively with crewed ships and aircraft is extraordinarily expensive. Autonomous maritime systems offer another model by providing persistent surveillance, distributed sensing, electronic warfare, communications relay, logistics and eventually additional defensive or offensive capacity without the manpower burden of conventional warships.

The future fleet will almost certainly be hybrid. Submarines, destroyers, carriers and advanced aircraft will remain critical, but they will increasingly operate inside larger networks of autonomous systems. The same principle applies to the defense industrial base. The United States is not going to replace traditional primes with startups, nor should it. The engineering, manufacturing and systems-integration capabilities required to build submarines, bombers and complex weapons remain indispensable.

But the traditional model cannot remain the only model. Modern warfare increasingly rewards an ecosystem that combines established defense companies with emerging technology firms, commercial manufacturers, software companies, universities, private capital and government laboratories. The industrial challenge is no longer simply building the most sophisticated weapon. It is building sophisticated weapons while also producing enough affordable systems to create mass, replace losses and adapt faster than the adversary.

Quantity is not a substitute for quality, but quality alone is not enough if an adversary can manufacture threats faster and more cheaply than the defender can respond to them. A weapons system that performs extraordinarily well but cannot be produced in sufficient quantities or replaced during a prolonged conflict carries its own strategic vulnerability.

There is another cost curve collapsing alongside hardware: information. Artificial intelligence and social media are dramatically reducing the cost of conducting information and cognitive warfare. An inexpensive drone can force an expensive military response, while an AI-generated video, manipulated image or coordinated social-media campaign can create political effects at almost no marginal distribution cost.

Iran, Russia and China understand that these domains reinforce one another. A tanker is attacked, insurance rates rise, energy markets react, images spread across social media, and AI-enabled narratives amplify fear or confusion. Physical warfare, economic warfare and cognitive warfare increasingly operate as parts of the same system. A missile can therefore be intercepted and still produce strategic effect if it forces millions of dollars in defensive spending, disrupts commerce, dominates media coverage and creates the perception that an adversary controls the pace of escalation.

That is why modern warfare can no longer be measured exclusively through targets destroyed or territory captured. Costs can be military, but they can also be economic, political and psychological. The United States still possesses extraordinary technological and military advantages; the greater danger is economic rigidity.

America and its allies cannot allow adversaries to consistently dictate exchange ratios in which cheap systems consume expensive defenses, small attacks produce major commercial disruptions and rapidly evolving technologies are answered by procurement processes that take years. The answer is not abandoning exquisite weapons, but building a broader force architecture around them: autonomous mass, distributed sensors, AI-enabled command and control, resilient manufacturing, commercial intelligence, lower-cost interceptors, modular payloads and systems capable of evolving at something closer to software speed.

Cold War 2.0 will therefore not be determined solely by which country builds the best fighter, submarine, missile or autonomous system. It will also be determined by which side can manufacture capability faster, distribute it more broadly, replace it more cheaply, adapt it more quickly and impose greater costs on an adversary than it absorbs itself.

Ukraine demonstrated how a modern-day David can use technology to challenge a much larger conventional Goliath. Iran is showing how a materially weaker state can use technology, geography and irregular warfare to impose disproportionate costs on a superpower. China is watching both.

The competition underway is increasingly a competition between military-economic systems. Goliath still matters, but the battlefield is changing in ways that increasingly empower David. The side that prevails may not be the one that builds the most exquisite individual weapon, but the one that can keep adapting, producing and fighting after the other discovers that it cannot.

This keeps the David-versus-Goliath analogy as a recurring frame rather than a gimmick—once near the opening, concretely through Ukraine, and again in the conclusion.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Foreign Spies Don’t Need to Hack You Anymore

26 August 2026 at 13:43

Andy Burnham was a few weeks into the job as the new Prime Minister of the UK when he found himself exchanging messages with someone claiming to be Susie Wiles, the White House chief of staff. The exchange, first reported by Politico last week, was brief and apparently trivial. Burnham grew suspicious, stopped replying and told the right people; the British embassy in Washington quietly informed the White House, which confirmed that Wiles’s own devices hadn’t been touched. No harm done, officially.

Embarrassments like this are becoming more common. The FBI warned last year about impostors using AI to mimic senior officials, after someone posing as Wiles contacted senior Republicans and business figures. The State Department later chased a fake Marco Rubio who reached three foreign ministers. And every one of these approaches lands on a habit “Signalgate” already exposed: when one wrong contact card could add a journalist to a strike-planning thread, the name on the screen was the only authentication in the room. If you want to see what this security weakness looks like run as a nation-state campaign look at a case that closed quietly in Taipei last month.

In July, prosecutors in Taipei’s Shilin district wrapped up proceedings against two local businessmen, Li Hualun and Chen Mengsen, who had spent months registering accounts on LINE (the messaging app nearly everyone in Taiwan uses), each tied to a real Taiwanese phone number. They leased the accounts to Xiamen Empress Information Technology, a mainland firm Taiwanese investigators say works under the direction of the Chinese Communist Party’s cyber forces. The going rate was about 1,100 RMB per account, call it $160.

A working exploit for a major platform costs millions on the gray market. A trusted local identity cost less than a decent dinner, and it did something no technical exploit can do.

The operators used the fake accounts to become journalists. In the approach that eventually unraveled the scheme, one of them even dressed up a leased account in the name and photo of Chen Yishan, editor-in-chief of CommonWealth Magazine, and began courting an aide in a legislator’s office. Interview requests, invitations to contribute articles, the ordinary traffic of political journalism followed.

There was no malicious link in the first message, or the tenth. Investigators found the operators worked on targets for months, sometimes close to a year. Any counterintelligence officer would recognize the rhythm. It was the patient cultivation and recruitment of an agent run through a chat app.

The eventual ask was small and reasonable-sounding. Journalists use encrypted tools to protect their sources, so would the contact mind installing a secure communication app to keep talking? The app was in fact malware. The MO turns a decade of good security advice inside out. The more someone knew about how careful reporters actually operate, the more normal the request looked.

Researchers at Citizen Lab and the International Consortium of Investigative Journalists, whose reporting the Taiwanese prosecution now corroborates, counted more than a hundred malicious domains behind the wider campaign, and found errors in the phishing messages suggesting the attackers were using AI to draft them and to pick targets. The people on the receiving end were lawmakers and their staffs, defense think tanks, semiconductor companies, dissidents at home and abroad. Taiwanese media reported that even the island’s overseas missions were probed.

Through all of it, nothing technical failed. The networks held and the patches were current. The attackers went around the security stack entirely, and the thing they spent, their actual operational currency, was the credibility of a free press. Every fake interview request makes the real ones a little harder. This cost never shows up in an incident report.

The two men who supplied the accounts got deferred prosecutions and payments totaling a bit under $6,000. That is the current legal price, in a frontline democracy, for renting identity infrastructure to a foreign intelligence service. It isn’t a deterrent. It’s barely a business expense.

Which brings us back to Downing Street. A prime minister with the full apparatus of British intelligence behind him replied to a stranger because the name on the screen looked right. Nothing in either story depends on LINE, or Taiwan, or Westminster.

Swap in WhatsApp or LinkedIn; swap the fake editor for a fake recruiter or a fake chief of staff. Aged, locally registered accounts are already a commodity in criminal markets. All the model requires is a person who handles something worth stealing and a persona they have no fast way to check.

That last part is fixable, though not by the security team alone. Organizations that handle sensitive work should treat identity verification as a counterintelligence habit. Platforms need to treat the account-rental trade Taiwan uncovered as the national security problem it has become rather than a terms-of-service nuisance. And legislatures need to punish collaboration with foreign intelligence services at something above a traffic ticket.

Mostly, though, the people likeliest to be approached — the legislative staffer, the fab engineer, the think-tank fellow, the human rights activist, apparently the occasional head of government — need to become more educated on how foreign intelligence cultivation and targeting actually works: slowly, warmly, and with no suspicious link in sight until the very end. The adversary in this case looked at hardened networks and vigilant software and made a rational choice. Building a fake trusted persona was cheaper — $160 a head – than spending millions on a sophisticated cyber exploit. We need to start defending the credibility of verified, trusted identifies the way we defend our networks: as the attack surface it already is.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Military Interoperability: The Coalition Challenge of Limited War

21 August 2026 at 08:57

In our last two articles for The Cipher Brief, Sami Omari and I explained why modern limited wars are so challenging for democracies.

We argued that military superiority is necessary but not sufficient for strategic victory: Afghanistan and Iraq showed that battlefield success does not guarantee lasting political outcomes, and Iran may yet prove the same point.

We also examined why democracies struggle to translate tactical success into strategic achievement: fragmented institutions, electoral cycles, public opinion and media scrutiny complicate the political resolve required for prolonged wars of choice.

The challenge becomes greater when democracies fight as coalitions.

Alliances combine military power, share costs and draw on capabilities few states could sustain independently.

But military integration does not produce political unity.

Each member remains accountable to its own electorate, parliament and national interests. A coalition may therefore be highly integrated on the battlefield while remaining politically and strategically decentralised.

In prolonged limited wars, military interoperability is not enough if allies cannot sustain the political will, industrial capacity and common strategic purpose required to endure.

II. Why Democracies Fight in Coalitions

The nuclear age made direct great-power war prohibitively dangerous, shifting competition towards limited wars, insurgencies and proxy conflicts.

Western militaries increasingly moved towards smaller professional forces equipped with more advanced weapons, shaped by technological progress and new strategic realities.

After 1991, the Gulf War and subsequent operations against weaker adversaries appeared to vindicate the effectiveness of Western expeditionary forces.

But smaller professional militaries and increasingly expensive weapons also made allies progressively dependent upon one another. Coalitions allowed democracies to aggregate military power, intelligence, logistics and specialised capabilities without each maintaining the forces and industrial capacity required for large-scale national mobilisation.

For thirty years, that system seemed to work.

Russia’s war against Ukraine has exposed these vulnerabilities over several years; the US-Israeli war with Iran is now testing many of the same assumptions.

Both demonstrate that limited wars can become contests of manpower, industrial capacity and political will.

Of these pressures, political endurance is perhaps the most difficult for democracies to sustain.

III. The Political Endurance Problem

For democracies, fighting a long, limited war depends as much on political legitimacy at home as on military capability.

In wars of choice, where national survival is not at stake, governments must continually justify why the costs of war remain necessary.

Initial public support may create space for intervention, but it erodes as casualties rise, costs accumulate, and the prospect of a clear strategic outcome grows uncertain.

Casualties alone do not determine support.

Democratic societies have accepted heavy losses when citizens believed a war was legitimate, necessary and winnable.

The deeper problem emerges when the link between sacrifice and strategic purpose becomes unclear. As confidence in success fades, losses that once seemed tolerable turn politically damaging. Elections, parliamentary opposition, media scrutiny and changes of government then allow declining public confidence to reshape national strategy. Afghanistan illustrated this over two decades.

Western military superiority was never in doubt, but political will steadily weakened. The longer the war continued without a convincing political end state, the harder it became for democratic leaders to explain what more time, money and lives would achieve.

Authoritarian states face similar pressures but, without competitive elections and independent media, can better insulate strategic decisions from public opinion.

Against democratic opponents, this creates a critical asymmetry: a weaker adversary may not need to win militarily, only survive long enough for democratic political will to erode.

IV. The Industrial Endurance Problem

Political endurance is only one side of the problem. The other is material.

Since the Cold War, Western militaries have increasingly relied on technology instead of mass.

Smaller professional forces employ sophisticated aircraft, ships, missiles and networked systems aimed at achieving decisive results while minimising casualties. But each generation of weapons is more expensive and complex, production runs shrink, and replacing battlefield losses becomes harder as war drags on.

The United States can absorb these pressures better than smaller allies because of its defence budget, technological base and industrial scale.

Even so, American forces became smaller, while defence-industry consolidation reduced the number of manufacturers capable of producing specialised weapons. For smaller allies, limited budgets forced difficult choices between personnel, platforms and munitions, while dependence on American weapons, software, supply chains and sustainment deepened.

Quick wars against weaker opponents long obscured these problems.

Ukraine has brought them sharply to the surface, while the Iran conflict is testing them anew. Advanced weapons can be consumed faster than peacetime factories replace them, while cheap drones and missiles allow weaker states to impose continuing costs on advanced rivals.

This creates an uncomfortable paradox.

Military interoperability strengthens coalitions on the battlefield but also creates industrial dependencies that are difficult to escape. In long, limited wars, technological superiority matters only as long as the coalition can afford, produce and replace what it consumes.

V. A Coalition of Decentralised Systems

Coalitions do not solve the political endurance problem; if anything, they make it worse.

Integrating militaries does not erase national sovereignty. Allied forces can share command structures, intelligence and interoperable systems, but each government still answers to its own voters, parliament and interests.

Afghanistan made that painfully obvious. NATO operated under one mission on paper, but contributing states imposed their own caveats and restrictions on where and how their troops could operate.

Those caveats were not bureaucratic quirks; they reflected different domestic political pressures and appetites for risk. They made burden-sharing and coalition cohesion harder than the unified-command narrative suggested.

Of the contemporary great powers, the US above all can supply the backbone of an international military coalition: intelligence, logistics and advanced capabilities.

What it cannot do is fuse the sovereign political systems behind every other contributor.

Middle and smaller powers like Australia and Canada still matter because they bring niche capabilities, diplomatic weight and political legitimacy while operating inside their own domestic constraints.

Coalitions may fight as one integrated military network, but the statecraft holding that network together stays stubbornly decentralised.

VI. From Military Interoperability to Strategic Interoperability

This gap between integrated military networks and decentralised statecraft is the central weakness of contemporary coalition warfare.

Modern limited wars therefore require more than military interoperability. They require strategic interoperability.

Sovereign allies must be able to coordinate military, political, economic and industrial power to pursue and sustain a common strategic objective.

This does not mean supranational government or surrendered sovereignty, but unity of strategic effect even when national policies differ.

In practice, this could involve standing allied mechanisms that integrate political planning, defence production, economic measures, strategic communications and military operations around an agreed political end state before a crisis becomes a prolonged war.

Conclusion

Across these three articles, we have argued that military superiority alone cannot guarantee strategic victory; that democratic institutions often struggle to turn battlefield success into sustainable political outcomes; and that these difficulties multiply when democracies fight as coalitions.

The endurance of democratic alliances will depend on more than their ability to fight together.

Sovereign governments must sustain public support, share political and military burdens, and remain committed to common strategic purpose when conflicts become longer and more costly than expected.

Democratic accountability need not become a strategic weakness, but preserving sovereignty while sustaining collective action will require greater political cohesion.

The ultimate obstacle is not technology or concepts, but political will: overcoming domestic divisions and institutional rivalries to sustain common purpose.

As the era of AI unfolds, technology will keep changing warfare, but it cannot repair the organisational weaknesses of those who use it.

Strategic interoperability ultimately depends on whether democracies can find the will to build it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Return of the Essential Art: Electronic Warfare and the Lessons of the Russia-Ukraine War

18 August 2026 at 10:01

A Post-Cold War Assumption That No Longer Holds

For three decades, the Alliance operated under a dangerous assumption: that the electromagnetic spectrum was a permissive sanctuary. Lulled into complacency by counter-terrorism campaigns that allowed precision strikes and networked command to go largely unchallenged, we forgot how to fight in the dark. The Russia-Ukraine war has violently corrected that amnesia. Today, electronic warfare is not an enabling function; it is the apex of modern combat power. If a force cannot survive in the spectrum, its sensors are blind, its networks collapse, and its kill chains are severed.

The Alliance stands at a critical inflection point. The time for incremental modernization has passed; this short piece is a call to arms to reclaim our operational advantage. The war in Ukraine has proven that the half-life of a technological advantage is measured in days, not decades. If we do not aggressively institutionalize agility across our warfighting commands, we risk entering the next conflict blind, deaf, and disconnected.

Russia’s Spectrum Offensive at Scale

Russia entered the war with a deep inventory of EW systems, rooted in Soviet-era investment and modernized over the past decade. From strategic GPS denial across Eastern Europe to tactical jamming of drones, radios, and artillery sensors, Russian forces use EW to degrade decision-making, disrupt fires, and blind ISR, continuously, at scale, across every echelon.

This is not a supplementary effort; it is a structural pillar of Russian combat operations. According to analyses by the Royal United Services Institute (RUSI), Russia achieved a staggering density of EW coverage, deploying a major electronic warfare system approximately every 10 kilometers along the front line during peak operations. This continuous, layered spectrum defense can be understood across two distinct operational tiers:

1. Strategic and Operational Denial

At the macro level, Russia has deployed high-powered, truck-mounted systems designed to blind NATO and Ukrainian airborne intelligence and disrupt satellite architectures.

  • The Krasukha-4: Designed to protect high-value assets, this system emits powerful jamming signals targeting airborne early warning and control aircraft (AWACS), radar reconnaissance drones, and low-Earth orbit spy satellites. By targeting X-band and Ku-band radars, it degrades long-range aerial surveillance, forcing ISR platforms to operate at suboptimal standoff distances.
  • Murmansk-BN: Operating at the strategic level, this system targets high-frequency (HF) military communications up to thousands of kilometers away, aiming to disrupt the operational coordination of enemy forces on a theater-wide scale.

2. Tactical Interdiction and the Defeat of Precision Munitions

At the tactical edge, Russian EW is integrated down to the battalion level to create local bubbles of spectrum denial. This has profoundly affected the effectiveness of Western-supplied precision-guided munitions (PGMs) and unmanned aerial systems (UAS).

  • Neutralizing GPS-Guided Weapons: Systems like the R-330Zh Zhitel and Pole-21 have been explicitly used to create GPS-denied environments. Because GPS signals travelling from space are relatively weak by the time they reach Earth, localized jammers easily overpower them. RUSI has noted that this jamming significantly degraded the accuracy of key weapons, including Excalibur 155mm guided artillery shells, Joint Direct Attack Munitions (JDAMs), and GMLRS rockets fired by HIMARS. Without GPS, these munitions must rely on inertial navigation, which drastically reduces their hit probability.
  • Drone Suppression and ISR Severance: In the early months of the war, Ukrainian Bayraktar TB2s operated with near impunity. As Russian forces entrenched, their EW architecture caught up. By blasting the 900 MHz and 2.4 GHz frequencies used by commercial and military drones, systems like the Borisoglebsk-2 sever the command links and video feeds between drones and their operators. This strips frontline units of their "eyes," returning artillery duels to grid-square estimations rather than precision strikes.

Ukraine’s Rapid Adaptation Under Fire

Ukraine’s response has been just as instructive. Forced to adapt under fire, its forces built a distributed EW ecosystem spanning national infrastructure to handheld infantry jammers, fielding and replacing thousands of systems in months, not years. EW operators are now embedded in maneuver, air defense, and fires units. The war has become a laboratory of spectrum conflict with drones jammed out of the sky, counter-battery radars blinded, munitions diverted, networks disrupted. EW is both shield and sword: protecting friendly systems while blinding the adversary.

While Russia relies heavily on legacy, mass-manufactured, centralized platforms, Ukraine’s survival has depended on democratizing the electromagnetic fight. By abandoning rigid peacetime acquisition processes, Ukraine has successfully pioneered a "DevOps" warfighting philosophy, prioritizing the rapid, iterative deployment of real-world software capabilities and commercial hardware modifications.

Ukraine has mastered the art of using the electromagnetic spectrum not just for defense, but to actively hunt Russian forces. By integrating EW operators directly into fires and maneuver units, the spectrum has become the primary hunting ground for target acquisition.

EW as a Mass Capability

The scale is the lesson. Both sides are fielding equipment and training operators at a pace NATO hasn’t matched since the Cold War. EW is no longer a boutique, specialized function; it’s a mass capability woven into daily battle rhythm and treated as a core determinant of survivability and lethality. In Ukraine, EW isn’t an adjunct to maneuver or fires. It’s inseparable from them.

For NATO and allied forces, Ukraine's experience demonstrates that surviving a high-intensity conflict requires transitioning from static, hardware-centric platforms to data-centric environments where software updates can be continuously deployed to the tactical edge under fire.

NATO’s Vulnerability Without EW Dominance

The implications for NATO are stark. Precision fires need assured spectrum access. Air defense needs resilient sensors and networks. ISR needs unjammed collection. Command and control needs protected communications. Without robust EW, all of it evaporates. This war shows EW is both the first layer of protection and the first layer of lethality, the foundation everything else rests on.

Rebuilding EW as a Core Competency

Reconstituting EW will take more than new hardware, it demands a cultural shift. Commanders must think in terms of spectrum maneuver, fires, and protection as naturally as kinetic operations. Exercises need realistic EW conditions, not sanitized ranges. Training pipelines must expand, and offensive and defensive EW forces must be rebuilt at every echelon, from squad to strategic level. Doctrine must treat EW as a decisive domain, not a supporting function.

The Essential Art Returns

The essential art of warfare in the twenty-first century has been violently reintroduced, and the electromagnetic spectrum is no longer an invisible enabler; it is the primary maneuver space where the first shots are fired, and the deepest vulnerabilities are exposed. NATO must reclaim this domain fully, urgently, and at scale.

For too long, the Alliance rested on the laurels of post-Cold War permissive environments, operating under the dangerous assumption that our networks would always connect, our drones would always fly, and our precision munitions would always find their mark. The battlefields of Ukraine have permanently shattered that assumption. We can no longer afford the luxury of rigid, decade-long peacetime acquisition cycles. Surviving the modern fight requires a fundamental paradigm shift: embracing a "DevOps" warfighting philosophy that prioritizes rapid, iterative deployment of software-defined capabilities directly to the tactical edge.

Lethality today is inextricably linked to digital survival. If we cannot protect our data lineage, secure our networks, and continuously update our countermeasures under fire, we will cede the kill chain to our adversaries. The next fight will be decided not just by who holds the physical terrain, but by who dominates the spectrum.

NATO must institutionalize this reality across every echelon. Electronic warfare is not an adjunct to maneuver; it is the very foundation of our combat credibility. We must transition our defense structures to data-centric environments, integrate our joint capabilities, and ensure that when the next conflict erupts, the Alliance dictates the spectrum and the adversary is left blind, disrupted, and defeated.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Inside Iran’s New Wartime Leadership

17 August 2026 at 09:47


Tehran’s new power brokers

A wave of assassinations rebuilt Iran’s leadership from the top down, leaving a severely wounded supreme leader and a security establishment now calling the shots. Tehran, however, isn’t saying who is actually in charge. The silence is part of the narrative; who are the country’s power players?

Earlier this month, Iranian state media did something it had never done before.

Mehr News, an outlet controlled by the country’s Islamic Development Organization, released a video titled “First Images of the Leader,” showing Supreme Leader Mojtaba Khamenei addressing a small group of students. The footage was undated. It came, however, days after Israeli outlets reported the 56-year-old cleric was in “extremely critical condition,” and it appears to have done little to settle the question consuming Iran’s political class: is anyone actually running the country right now.

The clip echoed a similar undated video IRIB released in March, showing Khamenei teaching religious sciences. President Masoud Pezeshkian acknowledged this week that reaching him has been “very difficult,” though he described their last exchange as constructive.

Multiple sources close to Pezeshkian’s administration told IranWire that no cabinet minister has met with Khamenei since the February 28 strike that killed his father, Ali Khamenei, and that officials “would not be surprised” to hear news of his death.

Iranian authorities have repeatedly denied he’s incapacitated. But the man now holding life-tenure authority over Iran’s armed forces, judiciary and clerical establishment hasn’t spoken publicly, delivered a sermon, or appeared unedited on camera since taking the post in March.

“The main issue for U.S. policymakers — especially any president — is whether the new leadership in Iran, or any leadership we can currently anticipate, is likely to depart materially from the strategic policies of the previous leadership,” Norman Roule, a former CIA officer who spent 34 years managing programs related to Iran and the Middle East, tells The Cipher Brief. “The evidence to date suggests no fundamental break.”

The vacuum at the top didn’t stay empty for long.

A Leadership Rebuilt Through Killings

The cascade began on February 28, when a joint U.S.-Israeli strike killed longstanding leader Ali Khamenei along with Mohammad Pakpour, the Islamic Revolutionary Guard Corps’ commander-in-chief, and a string of other senior officials. An interim leadership council, made up of Pezeshkian, judiciary chief Gholamhossein Mohseni-Ejei and cleric Alireza Arafi, held the state together for less than a week before the Assembly of Experts named Mojtaba Khamenei as Iran’s third Supreme Leader on March 8.

The choice was unusual on its face. The Islamic Republic was founded on the overthrow of hereditary monarchy, yet its clerical establishment had just installed the son of the man he replaced. Mojtaba lacked the religious credentials typically required of a Supreme Leader. He was widely regarded as a hojatoleslam, a mid-ranking cleric, rather than an ayatollah — yet he had spent nearly two decades as his father’s gatekeeper and enjoyed deep loyalty inside the Revolutionary Guard.

President Trump, who had labeled him “unacceptable” during the war, later told Fox News that the succession was not one his own father had wanted, adding, “their leadership is gone, their second leadership is gone, now their third leadership is in trouble.”

Roule, however, cautions against reading the new bench as a break from what came before it. Most of Iran’s current leaders, he notes, “rose within institutions shaped by Ali Khamenei and were trusted, promoted, or shaped within, and by the system he developed over years of rule.”

Roule points to the generational math: Pezeshkian, Mohsen Rezaee and Ali Reza Zolghadr were about 25 years old at the time of the 1979 revolution; Ahmad Vahidi was 21; Mohammad Bagher Ghalibaf and Sadeq Amoli Larijani around 18; Mojtaba Khamenei just 10.

“For this group, the 1979 Revolution remained the ideological foundation of the system, but the Iran-Iraq War and the post-2003 campaign for regional influence were more important professional experiences,” Roule explains. “Most are veterans of the Iran-Iraq War or were directly shaped by it.”

The current command of the Islamic Revolutionary Guard Corps has followed the same brutal pattern.

Amir Ali Hajizadeh, head of the Guard’s aerospace force, was killed in a strike in June 2025. Pakpour, who had succeeded Hajizadeh’s predecessor Hossein Salami, was killed at the outset of the U.S.-Israeli campaign in February. His successor, Ahmad Vahidi, a Quds Force founder and former interior minister with an Interpol red notice tied to the 1994 AMIA bombing in Buenos Aires, was formally installed as commander-in-chief on March 1.

Unverified reports of Vahidi’s own death circulated in Tehran in late May and again in early June; Iranian, Israeli or American officials have confirmed none, and Vahidi continues to be listed as the IRGC’s active chief.

A Crackdown That Fits the Moment

The uncertainty at the top has coincided with a sharp rise in executions and threatened executions, months after the January protests that shook the regime.

Austin Sarat, a professor of jurisprudence and political science, says the war and the unrest have compounded each other rather than one driving the other alone.

“The protests and the war have fueled — it’s like putting a little bit of an accelerant into something that’s already pretty flammable,” Sarat tells The Cipher Brief. “The protests were, I think, much more trigger than the war itself. The war has just provided yet another excuse, because it’s jacked up nationalist fervor.”

Sarat is skeptical that outside pressure, including past White House rhetoric threatening consequences over executions, has had much bearing on Tehran’s calculus.

“The administration has said nothing about human rights abuses, let alone execution practices around the world,” he says, underscoring that any outside leverage is more likely to come from Europe than Washington. He views the surge itself as a familiar survival tactic for a leadership still finding its footing.

“It’s not a kind of unfamiliar tactic for a regime new to power to want to flex its muscle and terrorize the population,” he observes. “This is a survival moment, and they are going to do what they are going to do to preserve the essential character of their regime.”

The Guard Consolidates Around the Vacuum

With the younger Khamenei largely unseen, the Revolutionary Guard didn’t sit on its hands. It moved fast, filling top posts through official decrees.

Along with Vahidi, the Supreme Leader’s office named Mostafa Izadi as deputy IRGC commander, Ali Azmaei to head the IRGC Navy and Hossein Taeb to lead the Basij paramilitary force, filling six senior military posts vacated by wartime deaths.

Mohsen Rezaee, who commanded the IRGC from 1981 to 1997, was separately appointed as the Supreme Leader’s representative on the Supreme National Security Council. This post opened up, according to Rose Kelanic, director of the Middle East Program at Defense Priorities, after Zolghadr was pushed out.

Kelanic argues the reshuffle amounts to more than a personnel change.

“Mojtaba Khamenei’s role appears to be that of a figurehead and potential scapegoat, enjoying far less authority than his father, whom he replaced,” Kelanic tells The Cipher Brief. “The real power rests with Ghalibaf, Vahidi and Rezaee, who are all career IRGC officers, which functionally means that Iranian government authority has shifted even further from civilian control to military control.”

That shift, she continues, carries its own risk for any settlement with Washington.

“When military leaders assume control as heads of state in wartime, they tend to make worst-case assumptions about adversaries’ intentions, view compromise as weakness, and favor offensive military strategies over defensive ones,” Kelanic points out.

Roule, meanwhile, frames the Guard’s rise in institutional rather than personal terms, and says the war has widened rather than preserved its reach. Estimates of how much of Iran’s economy the IRGC touches “vary widely — roughly from a fifth to a third,” he says, depending on whether one counts only directly controlled firms or also affiliated holding companies, pension funds and sanctions-evasion networks.

“A better way to think about the IRGC is not simply as a military organization with commercial interests, but as a central actor in a state-security-economic network,” Roule notes.

Ghalibaf’s Quiet Climb to the Center

The other figure benefiting from the uncertainty at the top is Ghalibaf, the parliament speaker and former IRGC commander who has spent the war years turning what is traditionally a legislative post into something closer to a shadow foreign ministry.

Ghalibaf, a two-time presidential also-ran who trailed Pezeshkian in the first round of the 2024 election, has emerged as Tehran’s principal interlocutor in the indirect talks with Washington, serving simultaneously as Iran’s special envoy to China and as a bridge between the political and military-security establishments that Pezeshkian, a physician by training with no roots in the security services, has struggled to command.

Parliament re-elected Ghalibaf to a seventh consecutive term as speaker in late May, with 235 of 271 votes cast, as reports circulated of friction between Pezeshkian and the new Supreme Leader’s office. Judiciary chief Mohseni-Ejei congratulated Ghalibaf on the vote by calling him a “tireless and battle-hardened jihadist leader” who had waged jihad “both in the field and in diplomacy” during the war.

Roule warns against reading Ghalibaf’s prominence as a formal power grab.

“His current prominence should not be confused with general supremacy over Pezeshkian,” he says. “Pezeshkian nonetheless remains president, heads the executive branch, and formally chairs the Supreme National Security Council. There is no evidence that Ghalibaf has assumed any of the presidency’s general constitutional authorities.”

His influence, Roule highlights, “is best understood as issue-specific power produced by circumstances, his political standing, longstanding IRGC relationships, and wartime delegation.”

Who Actually Holds the Reins

What emerges from the past five months of conflict, however, is a regime governed less by the clerical hierarchy that has defined the Islamic Republic since 1979 than by an overlapping wartime trio.

A Supreme Leader whose authority is formally absolute but whose physical capacity to exercise it remains unverified. An IRGC command structure rebuilt twice over through assassination and now operating with wide latitude, alongside a parliament speaker who has converted legislative standing into genuine diplomatic weight.

Still, Roule sees continuity as the most likely outcome even if Mojtaba’s health worsens further.

“If Mojtaba Khamenei becomes seriously incapacitated or dies, the most likely outcome absent a successful mass uprising or a major elite fracture is continuity rather than reversal on the issues of greatest concern to the United States,” he says. “The IRGC would remain a central power center, and the system has constitutional procedures for interim leadership and selection of a successor.”

He also points out that if Mojtaba’s death were tied to the war, “the state would almost certainly use a martyrdom narrative to reinforce regime legitimacy and resistance.”

Kelanic is less sanguine about what that continuity means for diplomacy. Iran, she stresses, will also grow harder to negotiate with simply because power is now split among rivals rather than concentrated in one office, leaving Washington without a clear address for any deal.

“The IRGC’s strengthened rule over a weaker civilian leadership makes reaching a peace deal harder,” Kelanic adds, “which is one of many ways the Iran War has backfired.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

It’s Time For The President To Level With The American People on Iran

13 August 2026 at 08:47

The U.S. administration’s strategic expectations are increasingly colliding with a set of hard realities. While Iran has taken a considerable beating, it remains standing and does not appear on the verge of either submitting or collapsing. Its newfound control over a key commercial waterway, the Strait of Hormuz, provides it with a weapon of mass disruption (credit to the NYT’s Tom Friedman) that it previously did not enjoy, and it appears intent on exercising that authority. Despite the administration’s continued threats and claims of imminent victory, there is no clear military solution in sight. Bottom line: the administration miscalculated.

Another strategy is called for. The truth.

“The practice of espionage is a quiet act of war: A very human endeavor, sometimes born of lies and betrayal, of greed or revenge; but often of deep truths and trust.”

This is the banner of my Substack, drawn from the preface of my upcoming Iran espionage novel; “A Prince of Mirrors.” It attempts to encapsulate my feelings about my chosen profession: Intelligence Officer. But for now, let’s focus on the last phrase: “but often of deep truths and trust.”

Trust is in very short supply between the United States and Iran as they attempt to come to terms. First, to re-open the critical Strait of Hormuz – a shipping route that was open prior to the War – and, second, to end an increasingly fruitless War. All while failing, at least for now, to fully address the other key issues at play: Iran’s nuclear program, Iran’s ballistic missile program, and Iranian-supported proxies.

While the world looks breathlessly on, the U.S. awaits the results of negotiations between Iran and tiny, wonderful Oman (admission; I spent several years at the U.S. Embassy in Oman) – a country literally stuck between the rocky Musandam coast, and a hard place called Iran – over the future administration of the Strait.

Based on initial reports of the terms, either Iran is going to have to step back from its assertions of control, or the United States is going to have to agree to some level of Iranian control that was not present prior to the War. Given the utter lack of trust between the parties, is either likely?

So, let me lay out, as best I can, what I believe to be true.

This is a time for truth. Hard truths.

The Middle East has changed.

  • The Iranian regime has survived a series of devastating U.S. and Israeli strikes. Iranian military capacity, both the regular Artesh (Iran’s conventional army) and the IRGC (Iran’s Islamic Revolutionary Guard Corps), is significantly weakened; however, it retains the ability to strike targets outside Iran, including shipping transiting the Strait of Hormuz.
  • The Iranian regime has not fallen and appears to be consolidating power around… well, no one yet knows which individuals or factions will emerge triumphant in Tehran. But for now, an even more hardline, IRGC dominated leadership is in place.
  • The regime is attempting to assert its newfound control over the critical Strait of Hormuz, a right tacitly acknowledged, or at least not specifically prohibited, in the flawed June MOU (Memorandum of Understanding) signed by the President of the United States.
  • Barring something new, something we have yet to see, U.S. and/or Israeli military force is unlikely to significantly alter this equation.
  • Iran and the United States, and the world economy, remain trapped in a test of wills over who blinks first.

The truth is, the regime is bad in so many ways. And they are dangerous. But not existentially so to the United States. Disliking Iran is not a sufficient reason to go to war with them barring a truly compelling reason.

But neither can an IRGC dominated Iran be allowed to run roughshod over the region. The U.S. and its Western and Gulf allies need to develop a new deterrence strategy that includes both carrots and sticks.

The Impacts of failure

Any agreement needs to mitigate, to the extent possible, the damage that Iran can do going forward. First and foremost, the world economy cannot allow one country to exert control over such an important international shipping route as the Strait. Any agreement must minimize Iranian control over ships transiting the Strait, possibly by compensating in other areas. The most critical issue, Iran’s nuclear program, must be addressed in a manner that includes both dealing with the 60% enriched uranium (HEU) currently in their possession and strict verification of enrichment activities going forward.

The American people can handle the truth!

That for now, the only way out is a negotiated agreement that is certain to fall short of the ideal. Only for now. Simply a truce. This is not an admission of defeat, simply a pause to rethink, to recalibrate.

But also…

That the Islamic regime has significant internal weaknesses. That stepping away from the current tit-for-tat military action, a strategy that is not achieving its objectives, will force the regime to confront the serious problems, some existential, that the Iranian nation faces. This is Iran’s, and the regime’s, Achilles heel. One that could eventually force change that no outside military force could.

Just the truth.

This article was originally published on Substack and is republished here with permission.

Read more national security insights from experienced experts exclusively in The Cipher Brief.


The Biggest AI Models Are Not the Biggest Threats

13 August 2026 at 08:45

Almost every AI security framework we are applying rests on one misguided assumption: danger scales with size. Compute thresholds, export controls, and tiered evaluation regimes all encode the same intuition, the larger the model, the more we should worry. If this isn’t true, what policy changes are needed?

I recently mapped more than twenty fielded AI systems against two axes: raw offensive capability with safeguards stripped, and residual risk as actually deployed (Fig. 1). They ran from millions to trillions of parameter models, and included munition seekers, gene design models, theatre planning, cyber offense systems, and general-purpose AI models. The picture does not support the above assumption. In fact, the data supports the inverse. Small, specialized models beat bigger general models at offense, but bigger models maybe better at defense.

Figure 1. Security Risk vs Size of Model. Hollow ring: raw offensive capability with safeguards stripped. Filled dot: residual risk as actually deployed. Cyber related positions anchored to CAISI / UK AISI results, July 2026. Data compiled by Alvin W. Graylin.

Each system appears twice: a hollow ring for raw capability with safeguards stripped, a filled dot for residual risk as deployed. The gap between them is the safeguard effect. Read left to right, and the size to threat correlation everyone assumes is simply absent.

Seven assumptions worth rethinking

One: the largest models pose the greatest risk. The high-residual band, where capability and deployed risk are nearly identical. Across six orders of magnitude, no clear trend. In 2022, researchers at Collaborations Pharmaceuticals inverted the scoring function on a commercial drug-discovery model (MegaSyn) of under 100 million parameters and generated more than 40,000 candidate chemical warfare agents (many more lethal than VX) in just six hours on a desktop. Chemprop-class retrosynthesis models, which can find non-controlled precursor routes around scheduled pathways, run at one to ten million parameters. Evo models with single digit billions of parameters can help design novel life forms. News just came out last week that this exact system was able to generate 16 new viruses. All these systems sit well below the axis floor of any parameter-based regime. Compute restrictions do nothing to fix this.

Two: compute thresholds capture the relevant risk. Hackphyr, built on Zephyr-7b-β at 7 billion parameters, performs comparably to GPT-4 on network attack scenarios and runs on a single GPU. Deep Hat V2 ships commercially at 30 billion parameters, is marketed as uncensored for offensive security, and executes inside the customer environment with no external calls. No government evaluation covers it, so that placement rests on vendor claims. Neither would trip a FLOP ceiling.

Three: capability and threat are the same axis. Claude Fable 5 and Claude Mythos 5 share one underlying model. Their capability positions are nearly identical; their deployed risk differs sharply, because Fable's added domain safeguards drop cyber requests back toward Opus 4.8 behavior. The difference comes entirely from the safeguards and distribution controls layered on top. That vertical gap is what governance can act on. Parameter count is not.

Four: open-source models are more dangerous than closed ones. Recent NIST study found that Kimi K3, the strongest PRC open-weight model, only scored 32 percent on ExploitBench against 57 percent for the leading U.S. model, and reached step 17 of a 32-step attack range where U.S. models reached 28.5. On the highest-severity outcome test, arbitrary code execution (ACE), Kimi K3, succeeded on 0 of 41 tasks, while the most capable U.S. models averaged 20. So, we really need to be careful about self-interested parties saying larger open-source models are more dangerous, when it likely has more to do with protecting margins than national security concerns. (see Fig. 2)

UK AISI did recently report that the Kimi K3 model was able to escape its sandbox during testing, but it merely used a misconfiguration in the testing sandbox that left the door open, rather than a sophisticated swarm agent attack like what the OpenAI model did. And when it did get out, all it did was look up the answer for the test it was given, rather than doing any damage to real world systems. In the future, this behavior could change, but it’s important to question the basic assumption that open models are always more dangerous.

Figure 2: CAISI/NIST - Comparison of aggregate capabilities over time of the most capable U.S. and PRC models. A 400-point increase on the y-axis equates to a 10x increase in the odds of solving tasks. Shaded regions denote 95% CIs.

Five: model quality determines attack success. Microsoft's MDASH is a harness, not a model. It orchestrates more than 100 specialized agents across an ensemble and scored 88.4 percent on CyberGym at launch, against 83.1 percent for the Mythos preview model. Adding a compact security model roughly 1/10th the size raised that to 95.95 percent. The orchestration layer beat every individual model. Regulating training while ignoring scaffolding regulates the less important variable.

Six: national security requires the largest models. It requires the opposite. Loitering munition seekers performing automatic target recognition run on Jetson-class edge hardware, capping them in the single-digit millions of parameters. Edge deployment favors small models on latency, power, thermal envelope, and operation without a datalink. Larger models are slower and, in narrow domains, more easily distracted by irrelevant context. They are also harder to validate, and validation is what matters when a false positive is a struck target. Cisco's Foundation-Sec-8B matches or exceeds models ten times its size on security benchmarks while running on one or two GPUs. The famed DoD Maven Smart System is based on a fine-tuned 2-year-old Claude Sonnet 3.5 model. That level of intelligence can now be distilled into a 4B model which could potentially run on a smartphone.

Seven: denying China compute is the primary lever to keep U.S. safe. Due to shared risks between these superpowers, on many safety related issues, cooperating may actually produce the outcomes most beneficial to the U.S. and the world. More on this below.

Five threat domains, five different answers

Attack and embedded systems favor small models that don’t require a comm link. Air-gapped operation, no API telemetry, no rate limits, no refusals mid-chain. The offensive bottleneck is stealth and throughput, not reasoning.

Cyber Orchestration favors large models, but the advantage attaches more to the system rather than the model, as MDASH shows. There’s little discussion today on regulating orchestration systems, but it’s clearly very needed.

Cyber Defense favors large models most clearly, and this is where the current approach fails. Defenders need breadth across every vector; attackers need depth in one. Safeguards that constrain security research are therefore costly in a way that is easy to miss.

When Hugging Face's systems were breached in July by OpenAI models, commercial frontier-model APIs blocked the forensic requests because their safety systems could not distinguish defensive analysis from attack. The team ran the open-weight Chinese model GLM-5.2 on its own infrastructure instead, worked through more than 17,000 logged actions, and contained the intrusion. An American company under active attack by an American closed-model was defended by a Chinese open-source model because the American ones could not tell friend from foe.

That is a Slave AI failure, in the terms I set out in Beyond Rivalry. A model trained toward obedience can only refuse; it cannot reason about whether refusing is right. What we need is Guardian AI: systems capable and contextually aware enough to protect us from malicious actors, from other AI systems, and from our own unintended consequences. That requires scale, because judgment requires breadth. It also requires that we stop locking down every capability rather than stewarding it. High-quality models with fewer restrictions, in defenders' hands, are a global public good. Every hour a defender spends fighting a guardrail is an hour the attacker fights nothing.

Bio/Chem Design favors small models. Molecular graphs, protein sequences, and binding energies come from compact architectures immune to alignment techniques built for natural language. A graph neural network has no refusal layer to remove. The key here is monitoring and controlling access to precursor chemicals and expanding safeguard for synthesis equipment.

Bio Synthesis is the outlier, and there is good news and bad. For biology, model-level access control has already failed. Evo 2 shipped with weights, inference code, training code, and its full dataset. There is no API to revoke. What remains is the synthesis chokepoint: Customer vetting and sequence screening at nucleic acid providers already operate internationally through the Gene Synthesis Consortium, whose members screen orders against databases of sequences of concern before synthesizing. There are still gaps as novel AI-generated combinations are developed, but they can be reduced if vendors and regulators globally work more closely together to keep the systems updated. Closing those gaps buys more security than any parameter threshold. But this requires Washington and Beijing to align, since they are the two largest suppliers of synthesis equipment in the world. Of course, collaboration across all vendors globally is needed to truly secure this threat vector. Again, larger general AI models aren’t the core problem.

Data beats intelligence

On the opening day of the U.S.-Iran war in February, a Tomahawk missle struck the Shajareh Tayyebeh girls' school in Minab, killing at least 168 people, more than 100 of them children under twelve. The school sat within 100 yards of an IRGC naval installation and had been inside that perimeter until a wall went up around 2013. Targeting ran through the Maven Smart System, which generates roughly 1,000 target packages an hour. A preliminary investigation concluded the strike likely followed from outdated intelligence, and former officials said stale human-curated data, not AI, was to blame.

The school had a website. Free satellite imagery showed a schoolyard with a sports field. No model of any size prevents this, because the failure was in data lineage, not reasoning. A larger model querying the same stale record returns the same coordinates faster and with more confidence.

The China mistake

The threat model that matters is not Beijing reaching AGI first. It is a non-state actor with a 30-billion-parameter uncensored model, a good harness, and no return address. Small models proliferate regardless of jurisdiction and leave no attribution trail, and an unattributable intrusion between nuclear powers is an escalation problem before it is a technology problem. In that world, a China unable to defend its own infrastructure is a liability to global stability, not an advantage to Washington.

Beijing is already regulating its own labs more aggressively than any other market. Concordia AI's 2026 survey documents agentic AI security guidance, ethics review requirements, and binding obligations on consumer AI services that are already deployed and enforced. It should be noted that Chinese frontier safety research output grew roughly 60 percent year over year, with agent safety rising from 8 percent of new papers in early 2025 to 27 percent by early 2026. The caveat: only five of ten leading Chinese developers reported safety evaluation results on release. Shared standards here would make a difference.

As Fig. 2 showed, CAISI found the Chinese models less dangerous, but they also found GLM-5.2 answers sensitive biological queries at far higher rates than tested U.S. models, which is where PRC safeguards are weakest. In personally speaking with multiple Chinese labs, it’s clear that their lack of compute resources due to export controls has forced them to deprioritize safety demands vs. capability enhancement. Expanding safety testing compute resources, like what UK AISI has, to more countries could help improve AI safety globally, without fear of its misuse by rival nations.

The race framing is softening at home, too. More than 100 organizations, including Nvidia, Microsoft, Meta, IBM, Palantir, OpenAI and Google, have now signed the July 24 Open Weights and American AI Leadership letter opposing premature restrictions. Days later, Nvidia and roughly 50 partners launched the Open Secure AI Alliance to build open defensive models and agent harnesses, citing the Hugging Face incident as its founding case. Every participant has commercial exposure to a ban, so weigh the motives. But 8 of the top 10 models on OpenRouter in July are already open-source, and the industry has now reorganized around the proposition that open weights are defensive infrastructure.

Four Asks for September

Four asks follow, and Xi Jinping's state visit to Washington on September 24, the first in over a decade, is where they could land. Trump has said AI will be on the agenda.

Shared harm standards, not shared capability standards. Agreement on what constitutes an unacceptable capability, evaluated the same way in both countries, so that "safe" means the same thing in Shanghai and San Francisco. That’s clearly missing today and doesn’t require mutual trust.

A shared safety evaluation cluster. Chinese labs are compute-constrained, so safety research competes with capability research for scarce chips. Compute earmarked for evaluation and red-teaming is cheap relative to the benefit, and the benefit is global. An international testing facility open to any vendor institutionalizes it. Require publishing safety scores alongside capability benchmarks so safety investment earns a competitive return. Then, both Chinese and US labs would have no excuse not to test their systems.

An incident notification channel. The Nuclear Risk Reduction Centers, staffed continuously since 1987, exist because a misread signal costs more than talking. An equivalent for AI incidents where attribution is contested is cheap insurance. With the rising risk of bad actor attacks and false flag operations from non-state actors, this safeguard will be increasingly needed.

Capability non-development agreements. A capability never trained cannot leak. This matters more than denying Beijing another turn of the scaling crank. Beijing also wants to limit rogue actor misuse, thus agreeing on redlines in advance makes sense for both sides (no nuclear weapon command/control, no AI uplift to bio weapon design, no AI-attack on civilian infrastructure, no autonomous self-replication outside control environments [RSI]). General commercial models have no need for bio and chemical threat design, so keeping defense use case training only in military labs on both sides seems quite reasonable.

Another Asilomar moment

At Asilomar in 1975, molecular biologists imposed a voluntary moratorium on a class of recombinant DNA experiments, then built the containment framework that governed the field for decades. They acted before the capability matured enough to do real harm.

That view is starting to catch on in the AI labs now. On July 28, 1,200+ employees of frontier labs published Pacing the Frontier, asking Washington to support an international effort to build tools for deliberately slowing automated AI development. Signatories include top technical leaders at Anthropic, OpenAI, Meta and Google. The concern is recursive self-improvement (RSI) of AI that goes out of control. The logical extension is an explicit agreement not to implement it in frontier labs even once it becomes possible.

But this cannot stop at two capitals. If dangerous systems are small and cheap, a country with a modest research budget and a few hundred GPUs can build a competent offensive cyber agent or an inverted molecular designer. Within a few years, dozens will. Any regime binding only Washington and Beijing binds the two parties least likely to defect and leaves the growing middle untouched. A U.S.-China agreement is the necessary first move, not the finished structure, and it has to open immediately to third parties. That is how Asilomar's containment norms and the Montreal Protocol scaled.

Bigger AI is not more dangerous. Better orchestrated is more dangerous, less monitored is more dangerous, and irreversibly released is more dangerous. All three require cooperation with Beijing: orchestration needs shared harm standards, monitoring needs shared evaluation infrastructure, and irreversible release needs joint agreement on what never gets built. September 24 is a good place to start.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

BLUF: The US Must Lead in Gray Zone Activity

5 August 2026 at 09:09

As Washington works on the historically large defense budget, there is one theme which should loom large in the budget but comparatively, will cost little. Key to our national security is countering the gray zone activity that our adversaries are waging against the US and developing our own offensive gray zone strategies. Just as we would not ignore a kinetic strike against the US, we cannot ignore the targeted gray zone attacks by adversaries but we must be careful that our approach is thoughtful, and expertly executed in order to guard against escalation. Developing such offensive and defensive strategies will require gray zone expertise, proficient knowledge of the targeted adversary, a government wide strategy, and patience. As global leaders, we also must be open and clear that we will take on these gray zone activities, but we do not have to and should not discuss the details of our actions. We need to publicly put our adversaries on notice that we will not tolerate their actions against the US and we will counter them with our own, more debilitating gray zone activities.

The National Intelligence Council describes gray zone activities as “coercion and subversion . . . below what constitutes armed conflict but outside the bounds of historically legitimate statecraft.” The IC defines the gray zone as a realm of international relations between peaceful interstate diplomacy, economic activity, and people-to-people contact on one end of the spectrum, and direct armed conflict on the other. State-led activities that happen in that space that weaken governments’ resolve to confront the US or its allies, endeavor to change a nation’s policies, or strengthen a country's global leadership would be considered gray zone activities. Deniability is critical to the success of this strategy because attribution risks escalation.

David Pitts, another Cipher Brief Expert, has written about the current phase of warfare which he calls endless wars and the need to counter them. These endless wars are the gray zone activities that our adversaries pursue against us. The White House has made an important step in that direction by appointing the first US National Security Council Director for Cognitive Advantage. There is still a way to go, however, because cognitive advantage is just one part of gray zone activity.

The US must develop expertise for whole of government strategies that bring together all of the tools for gray zone activities. Some of those activities are:

  • Cyber, and information operations efforts focused on undermining public/allied/local/ regional resistance, and information/propaganda in support of US goals;
  • Covert and clandestine operations such as espionage, infiltration, and subversion;
  • Enlistment of non-governmental actors and assistance to irregular military and paramilitary forces;
  • Economic pressures that go beyond normal economic competition;
  • Calculated ambiguity to include deception and denial operations.

Autocracies tend to have an advantage in executing gray zone operations. It is generally believed that non-democratic states can operate more effectively in the gray zone than open democratic societies as non-democratic nations are not limited by domestic law and regulation. The nature of their centralized systems allows them to marshal whole-of-state (and whole-of-society) resources to execute operations. The United States lags behind its autocratic adversaries in the information domain, for example, because our adversaries have ingrained gray zone tactics into their doctrines.

In democratic societies, the use of gray zone tactics can be controversial because the nature of these activities is meant to covertly shape actions. It can be challenging for democratic states to respond to gray zone threats because our legal and military systems are geared towards seeing conflicts through the perspective of war and peace with little consideration for anything in between. Democracies have failed to build consensus around gray zone concepts. The US government has been arguing over the definition and leadership of gray zone and information operations for years.

Gray zone activities are not a new concept and historically have been accepted as a long standing form of statecraft. What are now being called gray zone methods have been well documented actions throughout history. These activities have been called by such titles as “political warfare,” “covert operations,” “irregular or guerrilla warfare,” and “active measures.” It is worth examining the historic record and recalling the benefits and rationale for gray zone activities that kept nations out of kinetic fights, allowed for de-escalatory engagement, arguably shortened warfare, and saved lives.

Examples:

  • The Trojan Horse operation exploited many of the instruments of a gray zone campaign– creating confusion and division among the enemy, extending ostensible inducements, implanting hidden military forces, deception, and clandestine infiltration of enemy territory.
  • During the Peloponnesian War between Athens and Sparta, the Spartans recognized that they needed to prevent an uprising by the Helots, who were key to Sparta’s agricultural and military systems. Athenians were trying to create the conditions for a Helot uprising, which would then add an irregular dimension to the conventional conflict with Sparta. The Athenians used proxy forces who were experts on the language and culture of the Helots to sow distrust among the Helots against the Spartans. The Helots began to desert Spartan forces, thereby creating a national emergency in Sparta. The Athenian historian Thucydides reported that as a result of Sparta losing Helot support, it reached out to Athens to discuss ending the wars.
  • The Han Empire used economic and cultural engagement—such as trade agreements, marriage alliances, and cultural exchanges—to manage tensions with nomadic powers. These actions helped secure borders and reduce the need for large-scale wars
  • During the Cold War, superpowers like the U.S. and USSR engaged in gray zone tactics such as espionage, sabotage, and proxy support to influence outcomes in regions like Latin America, Korea and Vietnam. These active measures as they were called, kept the competition a contested space, avoiding immediate escalation with the US.

Gray zone campaigns are likely to increase and diversify because of more enabling technologies, the erosion or absence of accompanying norms, and challenges with attribution. There is a growing awareness among some in the US national security community that if we do not develop gray zone strategies against our adversaries, then we will find ourselves no longer the global power that we have been. Without these strategies, we also limit potential responses to our adversaries to kinetic ones.

As a national security community, we have trained only a narrow group of special operators and intelligence professionals to be able to think creatively enough to devise irregular warfare plans and strategies. To produce gray zone strategies the US will need to train a work force in creativity and out of the box thinking. It also will require organization and orchestration from all assets of the US government and the development of and use of technology to bring some of the ideas to fruition. A fully conceived gray zone strategy needs to marshal all aspects of the US government: military, intelligence, economic, trade, diplomacy, and public relations.

The US is not organized as a nation to devise these strategies. Our State Department is focused on developing relationships. Our National Security Council is hollowed out. Due to issues with legal authorities, neither the Department of War nor the intelligence community can take the lead in implementing whole of government strategies. We are at a standstill and have been for several years.

What to do?

We need to be upfront that leading in gray zone operations is good for US national security. If we do not quickly make gray zone strategies a key part of our national security then we risk our global leadership role. We must put in place the tools and organization to execute these strategies. Using part of the large defense budget to show US resolve on this matter would go a long way. Putting a seasoned professional at the NSC and making him/her in charge of integrating the USG gray zone activities against specific adversaries is key to winning in this realm. A lack of coherent command-and-control, as well as jurisdictional and philosophical boundaries between government agencies, inhibits the synchronized activities needed for successful and truly whole-of-government gray zone activities and responses. We also should use the trained Department of War and intelligence community planners, working with the rest of government, to develop government-wide plans that are implemented at the White House. While we move out in this way, we should also be training our national security professionals across the government in how to develop gray zone strategies. Now is the time to make this a national imperative.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

AI Summaries Are Susceptible to Manipulation — and That's Both a Business and a National Security Problem

3 August 2026 at 09:07

More and more people are using AI like a search engine – 42 percent of U.S. adults now use AI chatbots to search for information – and that shift is exposing a structural vulnerability that adversaries are exploiting to seed propaganda. In practical terms, this is a problem of Generative Engine Optimization (GEO) – the deliberate effort to shape digital content so that AI chatbots absorb and repeat it.

The research so far points to data voids — the thinly covered topics where there isn't much credible information to begin with — as the weak spot. This includes breaking news or new material that has not yet had time to accumulate the signals that would flag it as low authority.

AI can process far more information than any human can, but there is an inherent trade-off in outsourcing the curation of information to an AI summary. In the search era, users were exposed to source material and evaluated credibility for themselves. Now AI does that work, and research shows the large majority of AI queries end without a click.

This is both a business concern and a national security concern. The clearest example on the consumer side is Apollo-9. In a Chinese state TV investigation, researchers used a tool called Liqing to flood the web with fake reviews and rankings for Apollo-9, a fitness tracker that did not exist. Within hours, chatbots were recommending the fake fitness tracker and some continued to do so a day after the fraud was exposed. Liqing and other tools are sold openly on Chinese e-commerce platforms like Taobao and JD.com, with pricing ranging from roughly $520 to $4,765 for three-month subscriptions. One provider told Chinese state media it had served more than 200 clients across multiple industries, guaranteeing top-three placement on any AI platform.

In order to better understand these developments and their impact, this article examines how the same mechanism scales from commercial fraud to geopolitical disruption, using the Russia-Ukraine war as a live GEO lab. Leaked documents about Russia’s “Project 2026” and Ukraine’s AI‑enabled counter‑operations show how influence campaigns are evolving from social feeds to the underlying sources that AI systems draw on — an angle largely absent from existing information warfare debates.

Russia and the National Security Case: Same Playbook, Higher Stakes

When Russian operations exploit GEO in their war on Ukraine, they are not just spreading propaganda in the moment; they are trying to become the “ground truth” that AI systems summarize back to users, analysts, journalists, and policymakers. In June 2026, Bloomberg reviewed 73 leaked documents from the Social Design Agency (SDA), a sanctioned Moscow firm at the center of Russia's influence operations, describing a program its operators called “Project 2026:” a network of Wikipedia-style reference sites, media outlets, and fake think tanks built to shape what search engines — and AI systems — treat as reliable sources. The goal, as described in the leaked documents, is to “create an alternative information ecosystem” by shaping not only what people see today but also what AI systems will later “know” about key leaders, the war’s origins, Ukraine’s conduct, NATO’s role, and Western support.

Russia's GEO tactics build on years of search engine optimization (SEO) manipulation and are part of a widely reported pattern of industrialized cognitive warfare that includes deepfakes, cloned sites and other deceptive content. In 2023, a study published in the Harvard Kennedy School Misinformation Review examined pro-Kremlin attempts to manipulate search engine results and found that pseudo‑think tanks and propaganda outlets such as Global Research and Strategic Culture Foundation were amplified through backlink networks and low‑quality sites. These outlets were most effective on conspiratorial searches involving, for instance, Ukraine President Zelensky, where authoritative content was sparse. Indeed, as noted by former CIA leader Jennifer Ewbank, the use of deepfakes to confuse, distort, or influence public opinion not only occurs in Ukraine but across Europe – all of which reflects “the same underlying reality: the tools for deception are faster, cheaper, and more accessible than the systems we rely on to detect or prevent them.” In other words, this is not just about deception, but the erosion of trust itself.

Storm-1516, a documented Russian disinformation operation that has been active since at least 2023, has scaled sharply in 2026. According to Bloomberg, the operation has produced more than 190 false stories since 2023 that the outlet has been able to identify. Based on Bloomberg’s reporting, Meduza adds that in the first quarter of 2026 alone, Storm-1516 was producing fake stories at twice the rate of the same period the previous year with, for instance, as of late March and early April 2026, materials appearing almost daily. Meduza also reports that more than 40 percent of Storm-1516’s fabrications have targeted Ukraine, with another third focused on electoral processes in other countries. Taken together, these reports demonstrate that Storm-1516’s operations are ultimately aimed at eroding Western support for Ukraine, swinging European elections and destabilizing NATO allies.

Taken together with the “Project 2026” leaks, these findings suggest that Russia is now attacking both the content layer (through synthetic media) and the source layer (through cloned Wikipedia‑style sites and fake think tanks) of information ecosystems. While synthetic videos and stories are often treated as short‑term deception, they also become part of the online record that future AI systems may ingest or retrieve, turning Russia’s layered influence architecture into a long‑term GEO problem, especially in data voids.

The Storm-1516 operation follows a clear pattern. A fake witness, often an AI-generated video, seeds a plausible but unverifiable story. Low-tier blogs and Telegram channels amplify it in multiple languages. Then less rigorous Western outlets pick it up, severing the link to the original Russian operator. By the time the narrative reaches mainstream discussion, the Russian fingerprint is gone. The new risk in today’s landscape is that the AI curation layer completes this laundering. It reads the now-repeated narrative across multiple sources and presents it as a neutral summary.

Researchers at the Institute for Strategic Dialogue found that the chatbot DeepSeek was quoting VT Foreign Policy, an outlet known to carry content from Russian propaganda operations such as Storm‑1516 and to have connections to the Kremlin‑linked Strategic Culture Foundation. U.S. and EU sources describe the Strategic Culture Foundation as an arm of Russian state interests.

A 2025 NewsGuard study also found ten of the leading chatbots — including ChatGPT, Claude, Gemini, and Copilot — collectively repeated false narratives from the pro-Kremlin Pravda network about a third of the time. It’s important to note that a 2025 study in the Misinformation Review, responding directly to the NewsGuard findings, found the number was closer to 5 percent and that these failures clustered in data voids. While the researchers found "little evidence to support the grooming theory" and warned against "the overhyped specter of Kremlin manipulation," they acknowledged that data voids "may be artificially created" and that they could not dismiss the possibility that a disinformation campaign could target them. Importantly, their audit came fourteen months before the leaked “Project 2026” documents showed Russia explicitly targeting AI systems. The more Russia attempts to flood these data voids, the more likely it is that future AI summaries about Ukraine will inherit its framing.

How to Build Resilience – A Way Forward

Like its older cousin SEO, GEO is inherently dual-use, but it sits in a regulatory vacuum because it is viewed strictly as a consumer protection issue rather than a national security threat. The Apollo-9 experiment and the Storm-1516 operation prove they are two sides of the same coin; the same commercial tactics that manufactured demand for a non-existent fitness tracker can easily manufacture plausibility for distorted narratives about a geopolitical crisis such as the ongoing Russia-Ukraine war. History shows that with traditional search engines, the market naturally incentivized tech companies to tackle manipulation head-on because mass spam threatened to destroy the user experience for billions of people, directly endangering corporate business models. Malicious foreign influence operations executing GEO are fundamentally different because they remain largely invisible to the mass market, with manipulation surgically clustered within obscure data voids, offering tech companies no commercial incentive to self-police and leaving the information terrain around a live European war effectively undefended.

To bridge this gap, regulators can draw on the lessons of private sector SEO defense and public-private counter-disinformation efforts, but they must realize that the exact same playbook will not work here. While private developers can easily dismiss the Misinformation Review study’s five percent finding as an acceptable commercial error margin, this minor statistical anomaly sits precisely in the data voids that Russia is actively trying to colonize, and so it represents a primary, unmonitored vector for foreign manipulation. The strategic risk is not only that GEO can mislead people in the moment, but that it can reshape the evidentiary record on which institutions and AI systems will later rely; if hostile narratives are allowed to dominate long‑tail topics and thinly documented episodes in the Russia-Ukraine war for instance, then future summaries, briefings, and even historical accounts risk being generated from polluted inputs.

The 2025 Misinformation Review study recommends "warning banners for data void queries" and increased "audit access," but notes the banners are "applied inconsistently" and the audit access is "hindered by power asymmetries.” Because the market will never self-correct a threat it does not financially register, protecting the integrity of generative content must transition from a voluntary corporate practice to a formal national security mandate.

In the Russia-Ukraine war, these dynamics are already visible. Russian operations such as Storm‑1516 use GEO‑style flooding and synthetic witnesses to launder narratives about the conflict into the broader information environment, while Ukrainian actors rely on AI‑enabled monitoring and evidentiary documentation to defend the integrity of the record. The contest is no longer confined to what populations see online today; it is over what AI systems will say is true about the war tomorrow. Recognizing GEO as a national security problem therefore changes the governance question: the training, retrieval, and ranking layers of generative systems are now part of the battlespace, and leaving this space unregulated is akin to leaving critical information infrastructure undefended.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Winning the Peace: The Democratic Dilemma of Limited War

30 July 2026 at 10:54

In our previous article, we argued that overwhelming military superiority no longer guarantees strategic success.

Today, military and political outcomes have become increasingly disconnected.

As Carl von Clausewitz observed, war is fought to achieve political objectives, with military force only one instrument among many in statecraft.

Modern professional militaries are exceptionally proficient at identifying and destroying adversary military capabilities. Yet, they remain far less able to reshape the political, ideological, and social foundations that sustain an adversary's resilience.

The challenge confronting modern democracies is therefore not simply winning wars, but achieving what might be termed strategic translation—the successful conversion of military success into enduring political outcomes.

This predicament of strategic translation has intensified in recent years.

Operations involving Iran, Ukraine, and Gaza have once again raised questions about whether military success alone can produce durable political outcomes, echoing debates that followed the conflicts in Iraq and Afghanistan.

Strategic rivals such as Russia and China have closely monitored these outcomes, adjusting their own strategies to exploit the gap between military supremacy and political consolidation discussed in this article.

The inability to translate military victory into a long-term political settlement has evolved from a tactical issue to a defining test of democratic strategic competency as information flows quicken and domestic audiences examine protracted wars in real time.

Democratic Institutions: Competing Cultures

The principal obstacle facing democratic societies is not a lack of military capability but the complexity of democratic governance itself.

Political authority is intentionally dispersed among elected governments, legislatures and independent public institutions, each possessing different responsibilities and professional cultures. While this diffusion safeguards liberty and accountability, it complicates the integration of national strategy.

Military power achieves its greatest strategic effect only when synchronised with diplomacy, intelligence, economic statecraft and political engagement.

Yet democratic institutions frequently develop these capabilities in parallel rather than as a unified enterprise. Foreign affairs, defence, treasury and justice each define success differently, compete for resources and optimise their own organisational objectives.

Ironically, modern armed forces have become increasingly network-centric, integrating intelligence, logistics, cyber, space and operational planning within a single command framework. Governments, however, largely remain vertically organised.

Democracies have therefore become highly proficient at conducting limited tactical military campaigns while remaining less effective at integrating the broader instruments of national power necessary to convert battlefield success into enduring strategic advantage.

Selling Grand Strategy to Democratic Societies

Developing grand strategy is only half the challenge.

Democratic governments must also sustain public support over time. Unlike authoritarian systems, they must continually justify long-term strategic investment to electorates whose immediate concerns are economic security, healthcare, education and the cost of living.

Electoral competition naturally encourages governments to emphasise visible achievements—military operations, defence acquisitions, and capability announcements—rather than articulating the long-term political objectives these activities are meant to achieve.

Public debate therefore becomes centred on operations rather than strategy.

Without a compelling strategic narrative, public confidence gradually becomes tied to individual events rather than broader national objectives.

Procurement controversies, budget debates, and political disagreements increasingly dominate public discourse, making defence appear as a collection of expensive projects rather than as one component of an integrated national strategy.

Grand strategy that cannot be communicated to democratic societies cannot be sustained by democratic societies.

Democratic Time versus Strategic Time

Winning in combat requires strategic focus, but democratic politics inherently operates on short attention spans as highlighted by researchers in RAND Corporation. Electoral cycles, typically lasting two to five years, create strong incentives for governments to prioritise immediate, visible achievements over the sustained political, diplomatic, and institutional investments required to build long-term national power, as the UK Parliament's House of Commons Public Administration Committee has provided detailed structural barrier on this.

In coalition governments, differing party priorities and narrow parliamentary majorities can further complicate strategic continuity, encouraging short-term political compromise over long-term policy consistency.

The twenty-four-hour news cycle and social media amplify these pressures by encouraging governments to respond rapidly to headlines and shifts in public opinion, often elevating short-term tactical developments over long-term strategic objectives.

A single controversy, whether involving procurement, diplomacy or battlefield casualties, can dominate public debate and increase pressure for policy adjustments that disrupt strategic continuity.

This tension between political urgency and strategic reality was perhaps most evident in Afghanistan.

Throughout that conflict, successive US administrations increasingly balanced military objectives against domestic political pressures, with troop deployments and withdrawal decisions becoming closely linked to electoral cycles and public opinion.

President Obama's 2009 troop surge, while designed to reverse Taliban momentum, was accompanied by a July 2011 timetable for the start of withdrawal, signalling that the United States' commitment was not open-ended.

More than a decade later, the 2020 Doha Agreement established a fixed timeline for withdrawal despite persistent concerns over the readiness of Afghan security forces and the absence of a comprehensive political settlement.

In both cases, strategic decisions became increasingly shaped by political timelines, illustrating how democratic governments can struggle to align long-term national objectives with short-term domestic pressures.

Among NATO allies, these pressures were further compounded by divergent domestic political calendars and national priorities. France, for example, withdrew its combat forces in 2012 following President Hollande's election pledge, while Canada and several allies imposed national caveats that restricted how and where their troops could operate. NATO summits in Riga (2006) and Lisbon (2010) exposed persistent disagreements over troop contributions, burden-sharing and operational commitments, reflecting domestic political constraints as much as collective strategic planning.

As political priorities shifted across allied capitals, long-term strategic coherence became increasingly difficult to sustain.

Without stronger institutional continuity and bipartisan commitment, democratic grand strategy risks becoming reactive, fragmented and ultimately unable to translate military success into enduring political outcomes.

Winning the Peace Requires Political Campaign Design

If democracies are to prevail in limited wars, they must plan for peace before the first military operation begins.

Military campaigns should never exist independently of political campaigns. Governance, justice, policing, economic recovery, institution-building, and strategic communications must be integrated from the outset, rather than improvised after battlefield success.

Repeated strategic frustration also carries risks for democracy itself.

Failure to improve strategic integration may encourage growing calls for more centralised executive authority, expanded emergency powers and greater restrictions on civil liberties in the name of national security.

Democracies should resist this temptation.

Instead, democracies should strengthen institutions capable of ensuring long-term strategic continuity while remaining firmly accountable to constitutional government.

One possibility would be an independent National Strategy Commission, bringing together diplomatic, military, economic and informational expertise to preserve institutional memory and support integrated strategic planning across successive governments.

Conclusion

Democracies do not need to lose their democratic character in order to become more strategically effective.

Authoritarian systems maintain continuity through control, whereas democracies must maintain it through design.

Instead, the task is to create long-lasting institutions, such as an independent National Strategy Commission, that can sustain strategic memory across changing governments without consolidating authority or undermining accountability.

This requires achieving cross-party consensus on essential national goals and integrating diplomatic, military, economic, and informational tools from the outset, rather than improvising after victory.

Failure results in continued frustration and increasing demands for concentrated power.

In a period of limited conflict, success will be defined not just by battlefield successes, but also by long-term political effects.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Sovereign AI Tokenomics Trap

28 July 2026 at 15:02

For US allies, the combination of geopolitics, ever-expanding risk surface and an unsustainable dependence on hyperscale cloud providers has created significant excitement about the potential value of AI data centers and sovereign digital infrastructure. Many of those nations and critical infrastructure owners are now starting to realize that the token, not the data centre, is the atomic unit of AI value. Whoever prices the token actually controls the economics and value creation of every AI-dependent industry irrespective of sovereign cloud, data center or AI factory.

This growing realization will require a material shift in sovereign policy and capability development for those nations combined with short-term patience and recalibration from US partners. The shift will result in both greater sovereign benefit and a more productive, resilient Western Alliance for all.

Why Sovereign Infrastructure Means Little Without Controlling Tokens, Intelligence & Equity

Most Sovereign AI Frameworks are consistent in identifying common levers for success:

-Digital Infrastructure

-Skills and Talent

-Research, development and innovation RDI

-Industry development and commercialisation

-Governance and Equity

Having spent the last 15+ years helping allied nations design their compute, AI and security capabilities, I believe that the rapidly escalating global demand for sovereign digital infrastructure does starts to address where compute is controlled, however, it does little to solve what that compute costs and how value is created and equitably distributed.

Given that whomever prices the token, controls the economics and value creation of every AI-dependent industry irrespective of sovereign infrastructure, nations should treat token supply the way they treat energy supply - as a strategic reserve requiring stockpiles, contracts and dedicated domestic production capacity. It’s sadly ironic that some of these same nations most vocal about sovereign digital infrastructure have been less than diligent in developing and maintaining energy security.

The Rapidly Evolving Discipline of Tokenomics

While many leaders still think of LLMs in terms of infrastructure (more requests require more compute and therefore cost more), the reality is more complex. Users and use cases can create vastly different types of requests which have highly varied infrastructure and cost implications.

The smallest current production unit for LLMs are tokens – a fundamental unit of data that an AI model reads, generates or uses equating to roughly 4 characters per token. Over the last 3 years inference costs have reportedly fallen roughly 1,000-fold, with inference now accounting for two-thirds of all AI compute demand.

By any normal utility logic, falling unit prices should mean smaller monthly bills for users, however new models are both more token-intensive at increased prices while usage has skyrocketed, leading many to consume their entire annual AI and tech budgets in only a matter of months. This seems clear proof of Jevons Paradox where decreased unit cost is significantly outweighed by material and accelerating increase in use.

In addition, recent BCG research indicates that only 5% of their clients interviewed are creating substantial and sustainable value from AI.

BCG Build for the Future 2025 Global Study (n = 1,250).

Government and enterprise leaders have now seen more than enough exemplars and representative AI use cases – demand is accelerating to show a true return on investment “ROI” for those programs, which fundamentally means an ROI on token usage.

This discipline of financial accountability to AI use and governance has earned the name of “Tokenomics”, meaning the demand for ROI during a period of increased usage, risk and associated costs has created a triple whammy for policy makers, regulators and users.

Sovereign Clouds, Rented Intelligence & Lost Value.

What does all of this mean for a nation state, alliance or critical infrastructure owner?

While an esteemed British colleague and I recently considered the Sovereignty 2.0 cloud and data center location and legal control aspects for the World Economic Forum, we didn’t answer the pricing question ie. who sets the cost and terms of the thing produced (token) running on that stack which dictates the sustainable value proposition?

This is the sovereignty risk the digital infrastructure debate has largely missed but we expect to rapidly evolve over coming months.

A nation can host its own data centre, run its own hyperscaler partnerships, satisfy every metric in a Cloud, Data Center or AI Sovereignty Framework BUT still be entirely price-taking on the tokens flowing through it without a dedicated available reserve if, or when, the supply chain is disrupted. The subsidy era of new foundation models is coming to an end with Anthropic's 2026 enterprise pricing shift the most public example of consumption growth outpacing cost declines. Operational control of the rack means little if the marginal cost of intelligence itself is set outside of a sovereign legal and commercial jurisdiction.

Perhaps even more sobering are the concerns of US and allied intelligence communities that the increased costs of token usage are causing critical public and private sector users to move to highly capable “open weight” models predominantly developed and sourced outside of the trusted Western alliance. This week’s launch of the Moonshot Kimi K3 with comparable capability to recent Anthropic and OpenAI versions has further entrenched the systemic risk.

Greater independence of allied sovereign objectives at the infrastructure AND intelligence layers may require a shift for some policy makers, agencies and technology vendors, however, the strategic value from greater trust, intelligence, innovation and resilience would be significant.

Closing the Tokenomics Gap

While rightfully asserting digital sovereignty, America’s allies must stop treating sovereign compute and intelligence as a real estate problem and start treating it as a strategic commodity problem similar to the way we manage oil, grain or semiconductors.

That creates some meaningful challenges from both policy and practice perspectives:

-Create a national token reserve/s via prebuilt capacity insulating critical government and infrastructure workloads from price and availability shocks the way strategic petroleum reserves insulate against supply shocks

-Mandate transparent token cost disclosure in critical-sector procurement, so cost-per-outcome (not cost-per-CPU/GPU) becomes the sovereignty metric regulators actually score. “Commercial in confidence” wont be good enough for an agentic world.

-Create an active domestic AI model routing capability, so government workloads can shift between frontier and commodity models rather than being locked to a single provider's pricing curve.

-Plan for AI inference at the edge – while large urban Data Centers take up the headlines and capital, it won’t necessarily be how we consume and create value domestically and across the alliance.

-Demand a social license of all who participate – many nations have exported a significant portion of the value created during the internet era to hyper-scale foreign companies and demanded little in return other than occasional headlines about “strategic investment”. New strategies and structures must be created where the value created of this agentic token-driven world accrue directly to the communities that use them and not to be reallocated or misspent as a new form of taxation. Oil-driven Sovereign Wealth Funds may provide an effective blueprint fit for the Agentic Age.

A token reserve is the logical and necessary next stage for Sovereign AI

None of these policies replace the need for sovereign digital infrastructure. As token prices fall but total AI spend climbs, the value to nation states deriving from infrastructure alone is incomplete and does not achieve multiple core objectives. Nations that control where compute resides but not what tokens cost and deliver will remain intelligence and price-takers in the AI economy. For America’s partners, a sovereign token reserve is the next necessary step toward genuine digital autonomy and an even stronger Western Alliance.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Audience Is a Machine: Our Future Information Environment

27 July 2026 at 10:05

The future of disinformation is no longer about creating better content. It is about teaching machines what to retrieve, summarize and recommend. In the AI era, the editor matters more than the article.

A story no longer has to trend. It has to be retrieved when a large language model (LLM) constructs the answer. The most important audience in the information environment is no longer human. If an AI assistant becomes the primary gateway to information, influencing what it retrieves becomes more valuable than influencing what millions of people read directly.

The Hugging Face Model Hub, the top repository worldwide, tracks over 2.9 million total machine learning models. Many models are for wonderful uses, ranging from research universities to new private sector companies built to solve problems. Meanwhile, more than 130 active national sovereign initiatives exist in more than 60 countries, according to the Center for a New American Security (CNAS) Sovereign AI Index. Every one of these models becomes another editor with its own worldview, training corpus and retrieval strategy.

As Bob Dylan reminds us, “For the times they are a-changin’”.

Countries are in pursuit of a foundational model (cognitive sovereignty) that will provide its own historical context, experts, values, national interests and more.

Different versions of reality will emerge, not because people disagree, but because different models were taught to retrieve, prioritize and reason differently. Not unlike media outlets as they evolved, just with a completely different scale.

Our Focus

The old world was about content, distribution and amplification. The new world is about training, retrieval and reasoning.

We must have the expertise to explain the mental frameworks machines construct before we see an answer to our query.

Our slide decks will cross out the “attention economy” and replace it with the “cognitive economy.”

We will remind ourselves that during the social media era, an adversary would flood the zone with thousands of fake articles and accounts to amplify a narrative. In the AI era, the objective changes. Rather than convincing one person at a time, adversaries will increasingly seek to influence the system that answers everyone.

Perspective is also important. Printing presses made publishing a reality. Radio introduced the broadcast message. Television opened up reach to mass audiences. Social media democratized who could have a voice. And AI now changes who decides what we receive.

Our Preparation

We will need to expand our remit and add expertise in training data provenance, retrieval indexes, embedding systems, model guardrails, agent memory, citation chains and reasoning architectures. AI engineers will become important parts of our team, if not already so.

The decade ahead will introduce AI models and agentic systems that decide what billions of people see. Agents will continuously search, compare, negotiate, monitor and decide for us. Humans may never initiate the request, but the agent will know what to do. That’s a different information ecosystem. We must learn how to track its development accurately and efficiently, so we are in-step or a step ahead on each new innovation of importance.

AI models will cite other AI models who cite other AI models. Over time, the original source may disappear entirely behind layers of machine summarization. The citation survives, but the human reporting becomes increasingly distant.

The editorial model will change as quickly as it needs to. How do we keep up with changes in the perspective of a model on a key topic and why it occurred?

Bad actors will optimize less for search engine optimization (SEO) and increasingly for generative engine optimization (GEO), engineering content specifically to influence what AI systems retrieve and cite.

We will need a new intelligence platform that tracks all publicly accessible LLMs and all innovation in places like Hugging Face, so we can see patterns earlier across the world. Imagine tracking hundreds and then thousands of LLMs in real-time. We still care about what happened, who said it and the rest of the 5Ws, but increasingly, it will be meaningful to know how Claude, Gemini, ChatGPT, DeepSeek and other models summarize and frame key messages.

These platforms will help us as we develop skills to understand training data integrity, how retrieval systems are poisoned through Retrieval-Augmented Generation (RAG) attacks, and how agent memories are manipulated.

Invisible Persuasion

When the audience is the machine, our efforts shift from how to protect the population to how we analyze and influence the infrastructure that reaches us.

Media literacy taught us to evaluate what people published. Machine literacy teaches us how to evaluate how machines constructed the answer.

The era will have many names, I’m sure, but one that resonates with me is “invisible persuasion.”

Unlike propaganda, machine-led information thrives on invisibility. It must appear ordinary, mundane and just do its job.

The next generation of AI will continue to quietly remove the human being from both ends of the media system. It is becoming the audience, and it is becoming the editor. And it is doing both at once.

It is also succeeding in building trust in humans.

SparkToro and Datos Group found that 60% of US google searches ended without a click in the first four months of 2026.

The same person who once clicked through to read is increasingly staying put while a machine goes and reads for them. The Reuters Institute expects search referrals to nearly halve over the next three years.

A Pew Research Center report showed that users clicked a source cited inside an AI summary just 1% of the time (900 US adults, 68,879 google searches).

Trust is migrating from the publisher to the summarizer. Our learning used to include more friction – a competing headline or comments we disagreed with. Now, we get a clean answer without friction.

How this impacts our judgement is a question we’ll study for many years ahead.

Conclusion

The printing press democratized publishing. Search democratized discovery. AI is centralizing editorial judgement again, this time inside machines.

The new editors are not confined to newsrooms. They include model developers deciding guardrails, publishers licensing training data, platform owners determining retrieval rankings, governments building sovereign AI models, open-source communities releasing foundation models, and enterprises curating the knowledge bases their AI agents consult. Editorial power is becoming distributed across the AI stack rather than concentrated in traditional media organizations.

The organizations that understand how machines learn, retrieve, reason and remember will shape the next information environment.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Beyond Evo: Bolivia and the Erosion of State Authority in Latin America

9 July 2026 at 05:03

In recent days, an unusual consensus has begun to emerge among some of Bolivia's most prominent public intellectuals, economists, diplomats, and former political leaders.

Former Foreign Minister Jaime Aparicio has warned that Bolivia has moved from "the theater of the absurd" to "the dialogue of the absurd," suggesting that the country may require international support to preserve democratic governance. Economist Jaime Dunn has repeatedly argued that Bolivia's central challenge is no longer merely economic, electoral, or ideological, but institutional. Former President Jorge "Tuto" Quiroga has warned of the corrosive effects of impunity and criminality on democratic government. Former La Paz mayor and economist Ronald MacLean Abaroa has likewise argued that Bolivia confronts a deeper crisis of governance than many observers recognize. Political commentator Vidal Dorado has advanced similar concerns.

These figures differ in generation, political affiliation, and professional experience. Yet they increasingly converge around a common diagnosis: Bolivia's greatest challenge may no longer be who governs the country, but whether the state itself retains the capacity to govern effectively.

That distinction matters.

Most international coverage of Bolivia's current turmoil continues to frame events as a political confrontation between former President Evo Morales and President Rodrigo Paz. The headlines focus on road blockades, food and fuel shortages, arrests, negotiations, and the possibility of emergency measures. Morales's supporters argue that he is being excluded from political life. His opponents contend that he is attempting to destabilize the government in order to preserve his political relevance and avoid accountability. Both interpretations contain elements of truth. Neither fully captures the significance of what is taking place.

As a Bolivian attorney and former Interim Mission Director of USAID/Bolivia, I have observed the country navigate moments of extraordinary turbulence. Bolivia has survived military governments, hyperinflation, constitutional crises, regional tensions, and repeated confrontations between state institutions and social movements. Yet what is unfolding today feels different. Increasingly, the central question is not who governs Bolivia. It is whether the Bolivian state can govern effectively.

The current crisis illustrates the point. Weeks of blockades have disrupted commerce, restricted the movement of food and fuel, and imposed substantial costs on ordinary citizens. Reports indicate that patients have died after being unable to obtain timely medical treatment because transportation routes remained blocked. The government has debated emergency authorities while attempting to avoid a wider confrontation. Yet even amid escalating tensions, important developments have occurred. The Central Obrera Boliviana has entered into dialogue with the government and established joint commissions to address detainees and other demands. At the same time, divisions have emerged within sectors of the protest movement itself, including organizations associated with the Tupac Katari movement.

These developments suggest that the crisis is no longer a simple confrontation between government and opposition. Bolivia increasingly resembles a contest among multiple actors, grievances, and centers of influence, none of which appears capable of imposing a definitive outcome on its own. The result is a growing debate not merely about political leadership, but about governability itself.

At the same time, public discussion has increasingly touched issues that until recently remained largely confined to security specialists and anti-corruption practitioners: narcotics trafficking, illegal mining, contraband, land trafficking, environmental crime, and the financing of political mobilization.

Whether any particular allegation ultimately proves true remains a matter for evidence, investigation, and due process. Yet the broader trend is difficult to ignore. Over time, illicit and informal economies can accumulate sufficient financial and political influence to shape governance itself. They provide livelihoods where the formal economy cannot. They generate patronage networks. They cultivate local loyalties. They penetrate institutions. Eventually, they cease functioning merely as criminal enterprises operating outside the state. They become alternative systems of power operating alongside it.

More than half a century ago, René Zavaleta Mercado, Bolivia's most influential twentieth-century political thinker, described his country as a sociedad abigarrada—a society composed of multiple social, economic, and political realities existing simultaneously within the same national territory. Zavaleta was attempting to explain Bolivia's complexity. His insight remains relevant today. Yet the challenge confronting Bolivia may now extend beyond the coexistence of multiple realities. Increasingly, some of the most powerful actors operating within those realities are neither political parties nor state institutions, but illicit economic networks whose resources and influence rival those of the state itself.

This is not solely a Bolivian phenomenon.

For much of the democratic era that followed Latin America's military governments, political debate revolved around elections, constitutions, economic models, and the alternation of power. The underlying assumption was that the state remained the principal arena through which political conflict would be resolved. Across much of the hemisphere, that assumption is being tested.

In Mexico, cartels have challenged state authority across entire regions. Ecuador's recent security crisis demonstrated how rapidly organized crime can reshape national politics. Colombia continues to confront criminal and armed groups whose influence extends well beyond traditional law-enforcement concerns. Guatemala has repeatedly struggled with corruption networks capable of penetrating public institutions. Venezuela presents perhaps the hemisphere's most advanced example of governing structures intertwined with illicit economic activity. Nicaragua's authoritarian consolidation likewise demonstrates how patronage, coercion, and opaque economic relationships can undermine democratic accountability.

Elsewhere, similar concerns are emerging. Brazil faces the growing influence of criminal organizations and illegal mining operations in the Amazon. Panama remains vulnerable to transnational money laundering and criminal finance. Jamaica and Trinidad continue to grapple with the political consequences of organized crime and gang violence. Guyana's remarkable economic expansion creates extraordinary opportunities but also governance risks familiar to many resource-rich states. Even Argentina's recent political debate, reflected in part through the rise of Javier Milei, has centered on public frustration with entrenched patronage systems, institutional weakness, and a perception that the state increasingly serves privileged networks rather than citizens. In Chile, support for figures such as José Antonio Kast similarly reflects anxieties about crime, state capacity, and the ability of institutions to maintain public order.

These countries are not identical. Their histories differ. Their institutions differ. Their democratic trajectories differ. Yet they increasingly confront a common challenge: preserving the capacity of legitimate institutions to exercise authority in the face of alternative networks of economic and political power.

The concern is not merely theoretical. It increasingly shapes political discourse throughout the hemisphere. What Jaime Dunn articulates in Bolivia is not entirely different from concerns expressed by reformers in Ecuador, opposition figures in Venezuela, portions of Peru's political class, or advocates of institutional reform elsewhere in the region. The ideological differences among these groups are substantial. What unites them is a growing belief that democratic governments are losing ground—not simply to political opponents, but to systems of power that operate beyond the effective reach of traditional institutions.

At this point, the observations of Jorge Basadre, Peru's great historian of the republic, become especially relevant. Basadre famously described Peru as both a problem and a possibility. The same might be said of democratic governance across much of Latin America today. The challenge facing many countries is not simply electing the right leaders or adopting the right policies. It is preserving institutions capable of channeling conflict through politics rather than allowing power to migrate toward criminal organizations, illicit markets, or networks that thrive on disorder and impunity.

Many of the hemisphere's most experienced diplomats and policymakers, including former U.S. Under Secretary of State Tom Shannon, have long argued that Latin America's enduring challenges are ultimately institutional rather than ideological. Bolivia's current crisis reinforces that point. The debate is no longer primarily about the distribution of power among competing political actors. It is increasingly about the capacity of democratic institutions to exercise authority, enforce rules, and maintain legitimacy.

This challenge also exposes a growing gap in the inter-American system. The Inter-American Democratic Charter was designed to defend constitutional democracy against coups, authoritarian ruptures, and attacks on democratic order. The Inter-American Convention Against Corruption sought to strengthen integrity and accountability throughout the hemisphere. Both remain important achievements. Yet neither was drafted with today's challenge fully in mind. Increasingly, democracy is threatened not only by tanks in the streets or presidents who refuse to leave office. It is threatened by criminal networks, illicit economies, and corruption structures that do not seek to replace democratic institutions outright, but gradually hollow them out from within.

Two centuries ago, Simón Bolívar warned of the fragility of republican institutions in the newly independent Americas. More recently, Basadre reminded us that the republic remains both a problem and a possibility. Bolivia's current crisis suggests that those concerns remain remarkably relevant. Jaime Dunn and others have argued that the country's deepest challenge is institutional. The evidence increasingly suggests they may be right.

The fundamental question facing Bolivia today is not whether Evo Morales or Rodrigo Paz prevails in the next round of political struggle. It is whether democratic institutions can continue to exercise legitimate authority in the face of increasingly powerful alternative networks of economic and political power. That question extends far beyond Bolivia. Increasingly, it is becoming one of the defining questions of democratic governance throughout the Americas.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

After the Intelligence Cycle: A New Schema for AI-Native Intelligence Analysis

9 July 2026 at 05:01

Recent discussion of artificial intelligence in intelligence analysis has consistently framed the technology as a means of accelerating an existing process. The intelligence cycle (collection, processing, analysis, production, dissemination) remains the implicit organizing schema, with AI cast as something used to drive its stages faster, increase resource efficiency, or widen its scope. We find this framing inadequate. It leaves the cycle itself intact, treating it as a sound structure merely in need of added speed, when the more consequential present opportunity is to reconsider the structure altogether. The intelligence cycle is an industrial-era artifact, popularized by Sherman Kent in the immediate post-war period, when information was scarce, expert labor concentrated, and the consumer a narrowly-defined institutional decision-maker. None of these conditions still holds. Recent work by Gartin, Schlickenmaier and by Reed and Szylkiewicz has argued for updating intelligence with agile, information-technology methods, and for shifting delivery toward a services-centric rather than goods-centric model. These arguments address the outdated production cycle, but neither fully anticipates the extent to which AI permits the cycle to be displaced wholesale rather than merely modernized.

As practitioners building intelligence programs in this environment, we observe that the prevailing conversation remains bounded by traditional conceptions of what analytic work is. This paper proposes a different framework, organized around a single assertion: that AI enables a scale and rigor in cognitive information work that were previously unavailable, and that this in turn dissolves several of the assumptions on which the cycle previously depended. The argument rests on a particular architectural premise that analytic reasoning can be captured as a structured data schema rather than compressed into an overly-simplified finished narrative. From this premise follow five ruptures with the traditional cycle:

First, the core value unit of intelligence shifts away from the finished assessment toward a more complex artifact that contains the entire decision architecture by which the assessment was reached.

Second, AI-enabled analysis becomes continuous and ongoing rather than fixed to a single publication date.

Third, analytic accuracy becomes measurable, and therefore improvable, for the first time in history.

Fourth, the relationship between provider and decision-maker narrows, and can be scaled to the needs of the individual consumer rather than to a generic reporting requirement.

And fifth, source handling and judgment collapse into a single operation rather than appearing as separate steps.

Taken together, these constitute a revolutionary rather than evolutionary departure from the manual methods that have governed intelligence analysis for a century, and they open new ground for rigor, accountability, and accuracy in global risk forecasting.

From Finished Product to Assessment Process

Modern intelligence analysis tradecraft treats the finished product as its core deliverable. The product serves both as the vehicle of value to the consumer and as the measure of organisational output, and it is the terminus toward which collection, refinement, and assessment are all directed. This arrangement was never optimal. Reliance on a single artifact collapses a complex analytic process into one compressed object, in which the judgments, and biases, included along the way are flattened into a single deliverable. Tradecraft notes and caveats have occasionally preserved fragments of this reasoning, but the product standing alone has never fully represented the value chain that produced it. The most important steps in the analyst's work, the alternative hypotheses entertained, the source biases weighed, and the contingencies sketched against one another, do not travel with the document, forming a lost layer of metadata that usually remains behind.

Artificial intelligence relieves the scale pressure that heretofore forced this compression. An analyst working with well-designed AI tools can now meaningfully execute and record each of the steps in an intelligence workflow rapidly and at scale, which permits the end product to change, away from the finished product deliverable to a searchable, indexable, and auditable log of expertise that has produced a range of potentially useful data through its work. In this process, the end value unit of analysis becomes the actual analysis itself, rather than an artificial summary of that analysis compressed to finished product size. By deprioritizing the focus on the product as the end goal of all analytic work, more of the valuable decisions and information which informed its creation become accessible to both the analyst and the consumer, which may audit and explore these dynamically to enhance their own understanding.

For this process to compound rather than merely accumulate, the analytic representation of judgments must be persistent and structured. Judgments of this type include the reliability of the source, the credibility of the information it contains, the weight that information should play in contributing to a view of the world, how it might interplay with other events and trends, and so on. These expert judgments are collected as structured data and recorded as they are formed, so that they can later be reviewed against real-world outcomes as those outcomes resolve. This foundation of analysis permits auditability and recursive improvement in judgment, source collection, and analytic framing. AI tools used correctly should permit a thoroughness which enhances judgment rather than eroding it, because they help create a massive record of analytic work that persists and can rapidly be revisited, rather than a sequence of keyhole snapshots of reality which age into irrelevance from the moment they are completed.

Because our representation of analyst judgment is structured across various data points rather than as a single loose narrative, it supports more than retrieval. A sufficiently large corpus of analytic judgments can be used to generate predictive assessments based on prior weighting and modal relationships, to trace multi-path higher-order consequences that human reasoning follows poorly, to identify which forces carry the most systemic weight, and to express conclusions as calibrated, quantified probability rather than verbal estimate.

From Episodic to Continuous Analysis

The intelligence cycle was built around episodic production not because it produced the best analytic results but because scale challenges prevented anything more rigorous. Between products, the analyst's judgment existed only in their head, and even then, was a nebulous and ill-defined thing. Kent’s “Words of Estimative Probability” and Tetlock’s superforecasting projects both pointed toward a need for improved, continuous, and calibrated judgment, but neither could provide a way to operate such a system of rigor continuously at scale. Artificial intelligence changes this arithmetic. A well-trained model handles what human analysts struggle to achieve at scale, ingesting raw data, mapping it to analyst-defined areas of interest, and updating mathematical prediction models. This rapid processing enables the analyst to spend bandwidth on setting the scope of analytic questions, interrogating the quality and biases of sources, and defining the weights and relationships the models will assign to various real-world events. Far from the language of the factory assembly line, the modern discipline of intelligence we espouse more closely resembles the rhythm of a trading desk, where equities analysts mark positions to market continuously, forever adjusting expectations based on a never-ending flow of data.

In this framing, an equities analyst wouldn’t save up all their trading positions to be submitted in one package at the end of the day, and we propose that appropriately tooled intelligence analysts similarly no longer need to wait until a publication date to deliver analytic value. By connecting front-end AI summarization and chat systems to back-end analyst enrichment areas, customers are able to query the latest in analyst judgment on demand, creating an instant feedback loop in which customer queries inform and sharpen ongoing analytic priorities. This serves the analyst as much as the consumer. It removes the obligation to produce filler during quiet periods, and it lets analytic output follow the genuine cadence of a topic rather than an arbitrary calendar.

Measuring and Improving Accuracy

Intelligence consumers hold the analyst accountable not only for a judgment but also for the reasoning by which it was reached. Historically this accountability has been difficult to honor, because much analytic judgment was formed reflexively and poorly recorded. The methods now available for capturing and structuring reasoning make the problem tractable for the first time. Once reasoning is recorded as structure, it can be scored against outcomes as they resolve, using calibration methods such as Brier scoring. The essential property is that each judgment is preserved as it was made and is not revised afterward. That is what keeps the scoring honest: the analyst is measured against the call they actually made, not a version softened by hindsight.

We are deliberate about the strength of this claim. The architecture does not inherently make analysts more accurate. What it makes possible is the measurement of accuracy and the diagnosis of error. When a judgment proves wrong, the structure allows the failure to be traced to a specific weighting or relationship rather than absorbed into an unaccountable whole. It is this decomposability, sustained over time and across many resolved judgments, that creates the conditions for improvement, for the individual analyst and for the models their judgments inform. The data describing how and why an analyst reached a judgment is, in this respect, more valuable than the judgment itself, because it is the raw material of recursive refinement.

This is a meaningful departure. For most of its history, intelligence analysis has struggled to know whether it was improving in delivering decision advantage or predictive insight, because the record needed to properly audit this improvement was never systematically available. For the first time, a complete and inspectable record scored against reality is within reach, presenting the opportunity for true improvements in forecasting accuracy.

From Generic to Specified

A further constraint the cycle never escaped was the assumption that consumers were finite and institutionally legible. The analyst writing for a government agency in 1990 could reasonably picture a handful of senior officials whose interests were bounded by their roles in advancing the national interest. This model functions poorly in the wider modern intelligence context, in which the reader of any given report might vary widely based on their position and access. For intelligence teams working in today’s commercialized contexts, the reader of a report might be a CFO weighing currency exposure, an operations director routing freight around contested waterways, a general counsel mapping sanctions risk, or a fund manager modelling financial tail risk. Each actor is sufficiently distinct from the others that how information is presented to them, and what information is relevant to their decisions, is so different as to destroy the value of a single, universal intelligence report. Each actor makes a different decision against a different geometry of exposure to the same geopolitical environment. A generic product written to the centre of this readership delivers very little decision value to any specific stakeholder because it is intended for none of them.

Bespoke intelligence tailored to individual stakeholders is rare, because it is cost-prohibitive. Examples like the President’s Daily Brief show just how complex and difficult the process is to tailor an intelligence report to even one customer, let alone many hundreds or thousands. Today, AI makes this feasible, because it permits a single body of robust analytic work to be expressed differently for each consumer according to their specific exposure. The assessment surfaced to a Nordic manufacturer with significant Strait of Hormuz exposure differs significantly from the one surfaced to a Latin American agribusiness with none, though both can draw on the same underlying analysis in order to inform a wider geopolitical frame. This approach keeps client-specific context separate from the shared analytic base rather than absorbing it permanently, which matters as much for data governance as for scale. In other words, by keeping intelligence about the threat environment separate from context about the user’s potential impact until the last possible moment, delivery of truly tailored insights is permissible at a scale that humans alone cannot match. Delivering this well still requires human guidance, because the object is to inform human decisions, but it is reachable by a useful number of consumers only through automated composition and delivery. In practice it increasingly resembles data layers, dashboards, and conversational interfaces rather than documents and slide decks, which are inherently static and cannot respond to unique and specific customer interrogation. AI’s ability to handle mass data sets and rapidly synthesize them for human engagement is the key which unlocks these dynamic product offerings.

Source Handling as Judgment

One fiction the cycle's imagery sustained was that a clean separation existed between collection and analysis. In the logic of the assembly line, collection produced sources, processing ordered them, and analysis applied judgment. Practitioners have long known this separation rarely held in practice. Deciding which information to credit, and how heavily, is itself an analytic act, one frequently practiced by collectors but only sporadically preserved in the finished product in the form of sometimes feeble source reliability statements. An AI-enabled team can make this categorization a continuous and systematic piece of the analysis rather than a burdensome and occasional addendum to it. High-volume collection and tagging let analysts reach and index relevant information by reliability far faster, and automated tooling lets them record, in real time, which signals they judge useful, to what degree, and for which questions.

Two disciplines give this its force. The first is continuity: signals attach to persistent, identified subjects rather than floating as unlinked text, so that a judgment made today accrues to the same subject a judgment made months earlier addressed. The second is provenance carried as structure. Each catalogued signal carries its source, the system action that surfaced it, and the analyst decisions that touched it, so that the basis of a judgment travels with the judgment rather than being reconstructed after the fact. In our architecture the analyst encodes meaning into collection from first contact through to the point at which a signal is connected to the wider analytic framework. The system performs the high-volume triage and flagging; the analyst accepts, challenges, or supplies the context the system cannot; and the system then does the durable work of attaching that judgment to analysis where it carries lasting weight. The provenance this produces is more than an audit trail, and becomes part of what the consumer can interrogate. It also forms the basis for learning, over time, about collection gaps and the reliability of sources, serving as an internal collection management architecture.

After the Intelligence Cycle

Building an intelligence team that is AI-native from the outset, at a moment when most established intelligence institutions predate AI and are captured by institutional cultures which inhibit profound change, has shaped our thinking profoundly. The most valuable applications we find for AI push beyond legacy tradecraft, and concentrate on the high-volume work of collection, structuring, and presentation of data. Critically, we do not use AI to replace human judgment. The reason is not that models cannot produce reasoning, because they can, often fluently. It is that a model's account of its own reasoning cannot be relied upon as a faithful record of why it actually reached a conclusion. Auditable, attributable judgment of exactly that kind is what our architecture is built to capture from human analysts. Throughout our experimentation we have found success in a consistent division of labour: the system handles scale, the analyst supplies judgment, and the system records and surfaces that judgment rather than manufacturing it. Attempts to use AI to replace the analytic steps of the cycle risk producing analysis that sounds authoritative but cannot be held to account, and that is most dangerous when it is wrong. Any technology that amplifies human reasoning inherits its errors along with its strengths, which is why the core work of judgment must remain human and auditable.

The process changes we describe are early in their lifecycle, and the work of demonstrating them against a long track record remains ahead of us. Still, the process has taught us that significant changes to the discipline of intelligence analysis are almost certainly on the horizon, particularly as technological advances in model sophistication render traditional information-work delivery obsolete. Human analysts may defend the old ways of conducting analysis on nostalgic grounds, but the truth is that intelligence analysis conducted in this way has a poor track record of success, and disruptions which pose the opportunity for step improvements should be welcomed. These improvements should proceed from the end goal of intelligence analysis - to provide sustainable, responsible, and accurate forecasts about the future that enable decision advantage - rather than from a reactive defense of the previous normal process. To integrate AI in intelligence analysis in responsible ways requires abandoning many of the bad habits and basic assumptions that limited intelligence work in the preceding era. It also requires reconceiving the notion of the value and role of the human analyst in providing insight, and an audacity to believe that what has historically been unknowably complex can be rendered intelligible through sufficiently sophisticated modeling. One hundred years ago, humans struggled to predict the weather with any reliability; today, they expect a device in the palm of their hand to predict rain down to the minute. Similar changes are coming to the world of intelligence analysis. But they will require leaving behind the archaic tools of a previous era in order to reach their full potential.

If You Can Run a Spy, You Can Run AI

8 July 2026 at 08:41

Generative AI should be managed like a human source: useful, fast, sometimes brilliant, sometimes wrong, and never a substitute for disciplined questioning and human judgment.

The three of us spent our careers in an environment where bad information costs lives. We learned early that the most dangerous source isn’t someone who lies to you. It’s someone who tells you what you want to hear—and does it convincingly. As we watch organizations race to adopt generative AI, we keep seeing the same mistake: treating these tools like oracle machines rather than sources that need to be run.

We are not AI experts. We are not here to debate model architectures or training data. What we know is how to extract reliable insights from sources whose motivations can’t be fully verified, whose outputs may be biased or based on incomplete information, and whose reliability must be continuously earned. That is exactly the problem organizations face with AI today.

This is what HUMINT tradecraft has taught us—and what it has to teach anyone who wants to get honest, useful work from a generative AI system.

The Source Who Was Never Wrong

Early in our careers, two of us ran sources who were brilliant, well-placed, articulate, and deeply motivated. They produced detailed, confident, and consistent reporting. Senior analysts loved them. Their product sailed through review. For months, everything they said checked out—until it didn’t.

The problem wasn’t that they were lying, exactly. In both cases, they filled gaps with inference. They’d learned what we wanted to hear, and their natural intelligence and experience let them produce it fluently. The reporting wasn’t fabricated—it was confabulated. Coherent and plausible, but in key places, wrong.

We’ve all seen this pattern in the early months of AI adoption. The tool is fast. It’s articulate. It never pauses, never says “I’m not sure,” and it formats its answers with the confident authority of a briefing document. A recent Science study found that across eleven state-of-the-art AI models, sycophantic behavior—affirming users’ views even when inaccurate—was widespread and measurable. Stanford researchers found that AI systems trained on human preference feedback are systematically rewarded for being agreeable rather than correct, because agreeable outputs receive higher ratings. The models learn to please.

We’ve seen that source before. We know how the story ends.

Selection: Not All Sources Are Equal

Before you run a source, you select one. That’s a discipline in itself. And a discipline to which AI tools may in fact be able to add value in identifying and sorting stressors that can be exploited (anything that causes stress and then outlines for case officers which levers to pull on a recruitment). You don’t recruit someone simply because they have access. You also generally don't recruit happy people. You have to evaluate reliability, motivation, and susceptibility to manipulation. A source with wide access and poor judgment can be more dangerous than no source at all.

The same applies to AI. Not all AI systems are created equal for every task or mission. Each must be evaluated on access, expertise, responsiveness, and the quality of reporting—and the last criterion is harder to assess than it appears.

A few selection questions worth building into any AI adoption process:

•What is this model’s known track record on this specific type of task, not in general but specifically?

•Where does it tend to confabulate? What are its known failure modes?

•Is it current? A model with a training cutoff is like a source who’s been out of the field for a year—still useful, but with blind spots.

•How does it behave when it doesn’t know something? Does it admit it, or does it keep talking?

Choosing an AI because it’s fast or because leadership read about it in a business magazine isn’t source selection. It’s the equivalent of recruiting the first walk-in who shows up at the door.

Elicitation, Not Interrogation

One of the first lessons a new case officer learns is that interrogation and elicitation are not the same. Interrogation demands. Elicitation draws out. A blunt question produces a guarded answer. A layered conversation yields insight the source didn’t realize they were sharing.

Most people using AI are interrogating it. “What’s the answer?” “Summarize this.” “Give me options.” That approach works, up to a point, but it caps the quality of what you get.

Effective elicitation with AI means:

•Never ask a direct question when an indirect one is better. Instead of “What should we do?” try “What factors would a skeptic weigh against this recommendation?”

•Compartmentalize your tasking. Don’t dump the entire problem into a single prompt. Break it into discrete, well-scoped questions. Discrete tasking yields more verifiable output.

•Build layered follow-ups. Ask: “What are you assuming?” “What would change your conclusion?” “Give me the strongest argument against this.”

•Probe for alternatives before you settle on an answer. A source that only confirms your hypothesis may be problematic.

This turns AI from a content generator into something closer to a thinking partner. But it requires the same discipline as running a source well: preparation, precision, and the intellectual humility to recognize that your framing shapes what you get back.

The Hostile Source Problem

There is a risk the standard AI adoption literature doesn’t spend enough time on. In intelligence work, we worry not just about sources who are wrong—we worry about sources who have been co-opted or doubled, or who are feeding us what we want to hear because they’ve learned our preferences and decided that’s what keeps the relationship alive.

AI systems have structural analogs to all three failure modes:

•Sycophancy as a design artifact. Because models are trained on human preference feedback, they are incentivized to produce outputs that feel satisfying. Researchers at Carnegie Mellon and Stanford have documented an “artificial hivemind” effect in which outputs from multiple AI models converge—reducing epistemic diversity at the very moment organizations need independent judgment.

•Training data is a contamination channel. A source’s worldview is shaped by their environment. An AI model’s worldview is shaped by its training corpus. That corpus reflects the biases, omissions, and assumptions of the material it was built on. You may not know where those biases are, and the model won’t volunteer them.

•Automation bias as a user vulnerability. A series of recent studies confirms what experienced case officers know: people grant far more credibility to confident, fluent reporting than the underlying evidence warrants. Research published in 2025 found that even users with high “AI literacy” were not significantly protected against automation bias—the tendency to accept AI output without critical evaluation.

The practical implication: approach your AI system with the same structured skepticism you’d bring to a well-placed source who has given you no reason to doubt them. That’s when discipline matters most.

Debrief Discipline: The Protocol That Makes It Real

After every source meeting, a case officer writes up not only what the source said but also their assessment of reliability—what was corroborated, what was assumed, and what needs follow-up. That habit is the difference between a professional intelligence organization and a rumor factory.

Most organizations using AI lack an equivalent discipline. Someone prompts the model, takes the output, and puts it in a slide. No one records what was asked, what caveats the model offered, or whether the output was independently verified. The result is institutional memory built on unexamined reporting.

A working AI reporting protocol should mirror the post-meeting debrief:

Requirement—What question are we actually trying to answer?

Prompt—What, precisely, did we ask? (Save it.)

Output—What did the AI say?

Source check—What in this output is reliable? What is uncertain? What is unsupported?

Human judgment—What do we actually believe, independent of the AI?

Action—What will we do?

Review—What happened after we acted? Did the AI’s analysis hold up?

The review step is the one that organizations most consistently skip. But it’s where calibration happens. A source you never debrief after the fact is one whose reliability you can never actually assess.

A useful team habit before closing out any AI-assisted analysis: “Before we accept this answer, what would disconfirm it?” That question alone will catch more errors than any amount of AI governance policy.

Separating Collection from Analysis

This is a fundamental discipline in intelligence work, and it translates directly. AI is a tool for collecting and synthesizing. It can ingest, summarize, organize, and compare. What it cannot reliably do is interpret—to ask what the information means here, in this context, for this organization, with these constraints.

The error organizations make is treating AI as if it collapses the divide between collection and analysis. It doesn’t. It accelerates collection. The analytical function—applying judgment, context, institutional knowledge, and accountability—remains human.

Teams that hand over analytical responsibility to AI are not just making an efficiency error. They are making an accountability error. Someone has to own the conclusion. AI cannot.

Burning a Source: When to Stop Trusting the AI

This is the part of the tradecraft literature on AI that doesn’t exist yet, and it needs to.

Every experienced case officer has had to decide to terminate a source relationship. Not because the source was obviously lying—if that were clear, the decision would be easy. You terminate when the source's reliability has fallen below a threshold, when you have reason to believe the source has been compromised, or when the cost of continuing to run them outweighs the value of their reporting.

The equivalent decisions will come for AI systems, and organizations should prepare for them:

•When a model’s known failure modes consistently overlap with your mission-critical questions, it is time to stop relying on it for those questions—regardless of how it performs elsewhere.

•When an AI system has been demonstrably wrong in a consequential context and the organization has not developed a clear explanation for why, continuing to use it at the same level of trust is an operational error.

•When a model is updated or retrained by its provider, treat it as a new source and revalidate. Prior reliability does not transfer automatically.

•When you discover that the model has been systematically producing outputs shaped by the framing of your prompts rather than by evidence—that you have been leading the witness without realizing it—you may need to reset the relationship.

Burning a source is not a failure of the source-handling relationship. It is often the proof that the relationship was being handled well.

What This Means for How You Lead

The three of us came to this issue through intelligence work, but the problem is not limited to intelligence organizations. Any leadership environment where AI tools are proliferating faces the same structural challenge: the tools are fast, fluent, and confident, and organizational incentives often reward those who use them most rather than those who use them best.

The research bears this out. INSEAD’s 2025 analysis of firm-level AI adoption found that generative AI shifts value toward higher-order human judgment—not away from it. Microsoft’s research confirms that organizations with a well-calibrated understanding of AI perform better across missions than those that simply maximize usage. The tool is the easy part. The discipline is the hard part.

For leaders, the implications are practical:

•Build the habit of debriefing discipline before you scale AI adoption. The protocol above should be standard practice, not optional.

•Create psychological safety so people can flag AI errors. The greatest risk in any source-handling operation is the team member who saw the problem but didn’t say anything because the source had too much credibility.

•Distinguish between AI as a collection tool and as an analytical tool. Automate the former aggressively. Guard the latter carefully.

•Evaluate AI systems with the same rigor you would apply to any source—including periodic reviews of whether the relationship continues to produce reliable value.

Used with discipline, generative AI can be a genuinely powerful analytical partner—the kind of well-placed, high-access source that an experienced handler learns to work with carefully and derive real value from. Used without discipline, it becomes a certainty-destroyer—introducing noise, eroding judgment, and producing false confidence at scale.

The HUMINT model doesn’t make AI safer by limiting what it does. It makes AI safer by raising the standard for what we do with what it gives us.

AI doesn’t give you answers. It gives you reports. And reporting always requires a handler’s skeptical, trained eye.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Cyber Fraud, Banks, and What America Can Do About It

8 July 2026 at 05:02

Your phone buzzes with a text from your bank: “Did you authorize a $2,400 transfer? Reply NO to stop it.” You reply, and seconds later a calm “fraud agent” calls, knows your name and the last four digits of your card, and walks you through “securing” your money by moving it into an account under the criminal’s control. No password was stolen, no malware installed. You handed over the money yourself, because everything looked and sounded real.

This is the new face of bank fraud and business is booming. Behind these scams sit organized adversaries: nation-state actors who treat theft as state revenue, criminal gangs running industrial-scale scam operations, and hacktivists out to embarrass institutions increasingly armed with AI that makes their lies cheap, fast, and tailored to you.

The problem: scams have gone industrial

Banks have spent decades hardening their vaults and networks, so attackers shifted to the softest target: the customer. Rather than breaking in, they trick people into transferring funds themselves. This is “authorized push payment” fraud where the victim approves the payment and it is far harder to claw back than a stolen card number. To hear how a typical scam call actually unfolds, watch the FTC’s short imposter-scam explainer.

With the age of AI, three key forces have turbocharged these threats. Payments now move instantly and irreversibly, so money is gone before anyone notices. Decades of data breaches let criminals buy your name, address, and account details cheaply, making their scripts eerily accurate. And generative AI has industrialized deception where more than half of fraud is now estimated to involve AI. A criminal can clone a familiar or family voice from seconds of audio, write flawless phishing emails in any language, and even deepfake a bank officer on a video call.

The people behind it are not lone hackers in hoodies. They range from sanctioned nation-state groups that steal to fund their governments, to criminal syndicates running scam centers staffed by trafficked workers, to hacktivists attacking banks to make a political point. For them, fraud is a scalable business and it is outrunning the banks, telcos, and Big Tech.

The real-world cost

The damage is measured in real households. The Federal Trade Commission reports Americans lost roughly $16 billion to fraud of all kinds in 2025 the highest on record and about 25% more than the year before. Imposter scams alone accounted for $3.5 billion, nearly tripling since 2020, and the single most lucrative version is the fake bank-security alert that convinces people to “protect” their savings by moving them.

These losses fall unevenly. Americans aged 50 and older reported $4.3 billion in losses in 2025, often life-altering sums drained from retirement accounts. The official numbers are almost certainly a fraction of reality, since many victims never report out of shame. Beyond the dollars, the human cost is real emptied college funds, missed mortgage payments, and a corrosive loss of trust in the financial system people rely on every day. One Florida couple lost $42,000 of their savings this way watch how it happened. In fact, this happens so often that Hollywood created an action movie about it with the Bee Keeper.

A National Security issue

Fraud and scams are not just a nuisance but far more dangerous. Fraud and scams in the United States have escalated into a national security issue because they are no longer isolated consumer crimes. They are large‑scale, foreign‑run operations that drain billions of dollars from the U.S. economy and undermine public trust in financial and digital systems. Federal agencies increasingly link these schemes to transnational criminal organizations, some of which also engage in human trafficking, money laundering, and other activities that threaten national stability. The financial impact is massive, with losses rivaling major illicit industries, and the proceeds often flowing to adversarial nations or criminal networks abroad.

The rules already on the books

The U.S. is not starting from zero. Along with the growth of the early Internet, in 1999 the Gramm-Leach-Bliley Act went into effect and its Safeguards Rule in requiring banks to protect customer data, and guidance from the Federal Financial Institutions Examination Council (FFIEC) pushes them toward stronger, multi-factor login security. The Bank Secrecy Act and anti-money-laundering rules, enforced by the Treasury’s FinCEN, require banks to flag suspicious transactions — a key tool for tracing stolen funds. New York’s Department of Financial Services Part 500 cybersecurity rule has become a de facto national standard.

Regulators are also targeting the scams themselves. The FTC’s Impersonation Rule, in force since April 2024, lets the agency go after fraudsters who pose as businesses or government agencies; in its first stretch it produced more than $70 million in consumer refunds. Voluntary frameworks like the NIST Cybersecurity Framework give institutions a common playbook.

The gap is not the absence of rules it is that attackers move faster than rules can be written, and that liability for scam losses remains murky when a customer is tricked into approving the payment. So, with all these rules and regulations, why are scams and fraud occurring faster?

The innovators fighting back

A fast-growing wave of companies is using the same AI that empowers criminals to stop them.

· Feedzai builds real-time systems that score billions of transactions as they happen, spotting the subtle patterns of a scam in under a second.

· Alloy helps banks and fintechs verify who is really opening an account, choking off the synthetic and stolen identities fraudsters depend on.

· Arkose Labs specializes in blocking automated bot attacks and account takeovers, while SEON, Lexus Nexus, and Sumsub offer identity-verification and fraud-screening tools that smaller banks and startups can plug in affordably.

· Netcraft is a company which doesn’t only detect scams but does something about it. It is very good at “take downs” of scam networks.

· Others are racing to build deepfake and voice-clone detection to catch fakes that fool the human ear and eye. Others get creative: UK carrier Virgin Media O2 built “Daisy,” a lifelike AI “granny” that answers scam calls and keeps fraudsters rambling for up to 40 minutes to tie them up so they have no time for real victims. Watch “Daisy” turn the tables on scam groups.

What unites all these is adaptive defense models that learn daily, because last month’s fraud pattern is already obsolete. All these point solutions are modeled on Intellectual Property that slows sharing. This model is not working.

What America should do

As scams become more sophisticated, especially with AI‑driven impersonation, deepfakes, and automated fraud, their ability to destabilize institutions, exploit citizens, and weaken economic resilience has pushed policymakers and security experts to treat fraud not just as a consumer protection problem, but as a strategic threat to national security. Staying safe will take coordinated effort. Everyone has a role.

Lawmakers and regulators

Fraud and scam laws in the United States, the United Kingdom, and Australia share the same objective: to protect consumers and disrupting criminal activity but each country approaches the problem with a very different regulatory philosophy.

In the U.S., the system is fragmented and enforcement‑driven, with no mandatory reimbursement for most scam victims and a heavy reliance on agencies like the FTC, CFPB, and FBI to pursue wrongdoing after the fact. By contrast, the U.K. has built the world’s most proactive framework, requiring banks to reimburse victims of authorized push‑payment scams, enforcing account‑name verification through Confirmation of Payee, and placing clear accountability on financial institutions to prevent fraud before it occurs. Australia sits between the two models, adopting U.K.‑style protections while expanding responsibility beyond banks to include telcos and digital platforms through its emerging Scams Prevention Framework. While the U.K. emphasizes consumer protection and the U.S. emphasizes enforcement, Australia is moving toward a shared‑liability, cross‑industry approach that recognizes scams as a systemic risk requiring coordinated prevention across the entire digital ecosystem.

A typical scam today uses several pieces of technology working together to make the criminal look real. It often starts with:

1. the scammer creating a fake website that looks almost identical to a bank or delivery company. They buy a cheap web address from a service like GoDaddy and change just one letter so most people won’t notice the difference.

2. Then they setup email accounts on services like Microsoft & Gmail to send out massive emails.

3. They use AI tools to scrape millions of social media profiles from Facebook, Instagram, etc. to collect data about YOU.

4. They use tools that let them fake a phone number (telco), so when they call you, your phone shows the name of your bank or a government agency.

5. After that, they send out text messages to iPhone and Android users that look official, things like “Your account is locked” or “You have a package waiting.” The link in the text takes you to the fake website, where the scammer collects your login details. If you call the number instead, it goes to a call center where the scammer pretends to be a bank employee.

All of this: fake websites, spoofed phone numbers, and realistic text messages works together to trick people into believing they’re talking to a trusted company when they’re actually dealing with a criminal.

What should the Critical Infrastructure do?

In the U.S., we have failed because we have not worked together across these technologies at scale & at the speed of AI. Why? Because we (collectively) do not have the incentives or requirements to do so. For the CEOs of these companies, they do not want to spend money & resources which do not drive revenue. Period.

There are glimpses of hope. A working model already exists:

· We have the Financial Services Information Sharing and Analysis Center (FS‑ISAC) is a global, nonprofit organization that helps protect banks and other financial institutions from cyberattacks by enabling them to quickly share information about threats. It was created in 1999 (26 years!) to strengthen the safety and resilience of the financial system by collecting, analyzing, and distributing timely intelligence about cyber and physical risks so that member institutions can defend themselves and their customers more effectively. I am hopeful that they new CEO, Valerie Abend will drive more effective solutions.

· In 2026, eight major carriers: AT&T, Verizon, T-Mobile and others just launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), chaired by longtime cyber expert, AT&T security chief Rich Baich, to share real-time threat intelligence across competitors. Because most scams ride phone and text networks before they ever reach a bank, telecom and banking defenses should connect through the same kind of collective-defense sharing. But the C2 ISAC cannot do this alone.

· In 2025, the Global Anti‑Scam Alliance (GASA) was formed to bring together governments, financial institutions, technology companies, law‑enforcement agencies, and consumer groups to fight scams on a global scale. GASA acts like a global “anti‑scam task force,” uniting experts and institutions so people everywhere are better protected from online fraud.

These have proven to not operate effectively to get ahead of scams and fraud. We need a better way – mandates of sharing, legal risks support, cross ISAC/intel which is tailored/aware, good native ML & AI models (not rules), and others working at speed and context with more transparent sharing.

In the meantime,

What should consumers do?

Treat any unexpected “urgent” message about your money as a warning sign, not a command. Banks will never ask you to move funds to “protect” them. Hang up and call the number on the back of your card. Turn on multi-factor authentication and agree on a private “safe word” with family so a cloned voice can’t fake an emergency. Report scams to ReportFraud.ftc.gov, even unsuccessful attempts, because the data helps train good AI/ML models to protect everyone.

What should all companies do?

Adopt adaptive, AI-native detection rather than yesterday’s rules, and design apps that help customers pause before they act. Investors should back the firms building deepfake detection and identity verification, and banks should partner with them quickly instead of waiting years to build in-house.

Conclusion:

With fast innovation, fraud & scams will not disappear, but it can be better contained. The criminals have industrialized deception; the answer is to industrialize defense with smarter rules, sharper technology, and a public that knows the warning signs.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Space Age Needs New Rules

1 July 2026 at 15:10

Space is no longer a place we visit to plant flags. It is where the global economy and national security now live — and our rulebook is nearly sixty years out of date.

For half a century, space was a government project. Nations went there to prove something about science, about engineering, and about national will. The astronauts were public employees, the rockets were public property, and the point of the exercise was as much symbolic as scientific. But that era is over. What replaced it is both a gold rush and an arms race at once, unfolding in the same orbits under rules written before today.

Two forces have remade the frontier almost overnight. First, private companies now do what only superpowers once could: SpaceX, Blue Origin, Rocket Lab, Planet Labs and dozens of others launch, operate, and profit in orbit at a cadence no government program ever matched. Second, that same orbital infrastructure has become indispensable to national defense and therefore a target. In today's world, satellites are the backbone of how countries communicate, navigate, detect threats, and coordinate military operations. GPS, secure communications, missile warning systems, and real‑time intelligence all flow through space assets. If those systems were disrupted or destroyed, a country's ability to defend itself, project power, or even manage basic infrastructure would be severely weakened.

The result is a domain that is simultaneously more commercial, more crowded, and more contested than at any point in human history, and only getting started. Our institutions were built for none of this. It is time to fix that.

From Flags to Markets

The numbers tell the story of a revolution. The global space economy already approaches half a trillion dollars a year, and credible forecasts put it on a path toward $1.8 trillion or more within the next decade. In the United States alone, the sector already contributes $131.8 billion to GDP each year. Investors poured billions into space startups last year alone, and the United States now captures roughly half of all private space funding worldwide. This is no longer a niche of aerospace contractors living on government cost-plus contracts. It is one of the fastest-growing high-technology sectors on Earth, and the world's wealthiest people are racing to own a piece of it.

The engine of this growth is reusability. When SpaceX learned to land and re-fly its rockets, it did to spaceflight what the shipping container did to global trade: it collapsed the cost. Launching a kilogram to low Earth orbit once cost tens of thousands of dollars; today it can be done for a small fraction of that. Cheaper and faster access changes everything downstream. It is why the United States flew more than 200 commercial launches in a single year, which is the highest annual total this century. It is also why a single company, SpaceX, now accounts for the overwhelming majority of the world's commercial launch activity.

What gets launched has changed too. Instead of a handful of exquisite, billion-dollar satellites, operators now deploy thousands of small, coffee can size, mass-produced ones. Starlink blankets the planet with broadband from orbit; Planet Labs images the entire Earth's landmass every single day; Earth-observation firms sell insight on crops, shipping, emissions, and troop movements to anyone willing to pay. Commercial space stations are being built to succeed the aging International Space Station, and lunar logistics is becoming a business rather than a mission. The center of gravity has shifted decisively from the public sector to the private one.

Make no mistake: this is a triumph. Competition has driven costs down, cadence up, and innovation faster than any government program ever could. But a frontier opened by private capital and moving at commercial speed creates problems that markets alone will not solve. This is where the trouble begins, for which we are not ready.

The New High Ground

The same satellites that power our economy also power our military. Precision navigation, secure communications, missile warning, intelligence, and reconnaissance all run through orbit. Modern forces cannot move, see, or shoot without space, and adversaries know it. That dependence has turned what was once a sanctuary into the ultimate high ground, and the competition to control it is now explicit national policy.

The threat is not hypothetical. U.S. intelligence assesses that China and Russia are fielding a full spectrum of counterspace weapons: ground-based missiles that can destroy satellites, jammers and lasers that can blind or disrupt them, and maneuvering "inspector" craft that can shadow and, if ordered, disable other nations' spacecraft. Officials describe reversible attacks such as jamming and sensor dazzling as occurring on a near-daily basis. Russia's pursuit of a nuclear anti-satellite weapon has been called the single greatest threat to the world's entire space architecture, because a nuclear detonation in orbit would not destroy one satellite but cripple whole swaths of low Earth orbit for years. If this happens, enormous economic impact would occur. Under President Trump, the United States has answered with a declared policy of space dominance: the Pentagon has been directed to ensure American supremacy in orbit, and the Space Force is accelerating the deployment of its own counterspace weapons.

The scale of the buildup is staggering. China operated barely a thousand satellites in 2025; defense planners expect that fleet to approach twenty thousand within fifteen years, many of them dedicated to surveillance and targeting. In response, the United States stood up the Space Force, is spending on the order of $40 billion a year on military space, and is racing to make its constellations resilient, harder to find, harder to kill, and quicker to replace. Crucially, it is doing so hand-in-hand with industry: programs that draw on commercial satellite networks in wartime now treat private operators as part of the national defense fabric. This means government and private sectors are becoming more intertwined.

From a threat standpoint, cybersecurity also needs changing to protect satellites and the networks that control them, because modern space systems behave like connected digital infrastructure rather than isolated hardware. Satellites rely on software, radios, ground stations, and cloud‑based control systems that can be hacked, jammed, or spoofed. A successful cyberattack could disrupt GPS, communications, banking timestamps, aviation routing, or even missile warning systems, creating national‑level consequences. The threat is growing as nations target satellites through cyber intrusions and signal interference, and as commercial constellations expand with software‑heavy, rapidly deployed systems that often have uneven security. Yet international space law barely addresses cybersecurity, leaving countries and companies to rely on their own regulations and best practices. In reality, securing space now requires zero‑trust designs, hardened command links, continuous monitoring, and coordinated defense across governments and commercial operators, because whoever controls the software and signals in orbit controls critical power on Earth.

Here is the uncomfortable truth this creates: the line between a commercial satellite and a military one has all but disappeared. The broadband constellation that connects rural households also connects soldiers at the front. The imaging company that monitors deforestation also tracks armored columns. Private firms are now strategic actors whether they intend to be or not, and that raises questions of law, liability, and protection that no commercial contract was written to answer. It also concentrates extraordinary power in very few hands. A single company, SpaceX, already launches most of the world's payloads and operates the largest constellation ever flown; whoever controls orbital slots, spectrum, and launch capacity increasingly decides who reaches space at all. That is both a triumph and a single point of failure: the Western world's access to space now hinges on the choices of one company, and ultimately one person, which is a degree of dependence few governments would tolerate in any other piece of critical infrastructure. A domain meant to be the province of all humankind now runs on infrastructure owned by a handful of firms and the governments that license them.

Rules Written for a Different Era

So, what are the current rules and what do we do about it? The foundation of all space law is the 1967 Outer Space Treaty. It was negotiated when only three nations had ever reached orbit and governments were the only actors imaginable. It is a magnificent agreement for its time as it keeps weapons of mass destruction out of orbit and declares space the province of all humankind. Yet it sets countries up with a problem: the treaty forbids any nation from claiming territory in space, while granting each nations state jurisdiction over the objects it launches. The effect is sovereignty without ownership: states and the companies they license control satellites, orbital slots, and the data they gather, even as no one is accountable for the domain itself. But it was never designed for a sky full of private mega-constellations and dual-use military assets. No binding space treaty has been adopted since 1979. The rulebook, in other words, predates the personal computer!

The gaps are now operational, not academic. The Outer Space Treaty is reinforced by four companion agreements:

  1. the Rescue Agreement, requiring states to assist astronauts in distress and return them safely
  2. the Liability Convention, which sets rules for compensation when space objects cause damage
  3. the Registration Convention, mandating that states register objects they launch; and
  4. the Moon Agreement, which restricts military activity on celestial bodies and calls for an international regime to govern future resource extraction.

Obligations to act with "due regard" for others, and fault-based liability for collisions, were never given concrete definitions, so they are almost impossible to enforce. And when something does go wrong, the harder problem is proof: with thousands of objects maneuvering through the same orbits and attacks that can be quiet and deniable, attributing a collision or a cyber-intrusion to a specific actor is often impossible, and without attribution there can be no accountability. There is no air-traffic-control system for orbit: each operator largely sets its own collision-avoidance rules, even as tens of thousands of satellites crowd the same shells of space. And there is the debris. Anti-satellite weapons tests alone have scattered thousands of trackable fragments into orbit, a large share of which are still up there, each one a bullet circling the planet at orbital velocity.

The danger is a chain reaction: a collision that creates debris, which causes further collisions, until the most valuable orbits become unusable for generations. National regulators are trying to fill the void piecemeal: the United States now requires defunct satellites to be brought down within five years, and a market for active debris removal is emerging. But orbit is a global commons. Unilateral rules cannot govern a domain where one nation's negligence threatens everyone's access, and the major space powers have shown little appetite for a new binding treaty.

And the gaps are not only physical. As orbit fills with sensors, a harder question trails the hardware: who owns what space sees? A satellite's imagery and signals are raw material for the digital economy, yet the rules for them are thin. The data may belong to the company that gathers it, fall under the jurisdiction of the launching state, or concern people and places that had no say in its capture. The United Nations' remote-sensing principles were drafted for a handful of government agencies, not a commercial market in planetary-scale intelligence. In practice, access is decided by who holds the capability and the capital, raising real questions of privacy, equity, and transparency that no current treaty answers.

Nor is the world negotiating as one. Governance itself is fracturing into rival camps. The United States anchors the Artemis Accords, a non-binding framework now signed by 68 nations, while China and Russia lead a competing bloc around their International Lunar Research Station, joined by roughly a dozen states. Beijing and Moscow have also pressed their own weapons-ban treaty at the United Nations, which Washington rejects as unverifiable. Europe, India, Japan, and a widening circle of newer spacefaring nations move between these poles. The deeper danger is not just that the rules are outdated, but that the major powers are quietly writing parallel rulebooks, none of which binds the others — and any regime that excludes China and Russia governs only the orbits that matter least.

What We Should Do

Managing this new frontier does not mean smothering it. The goal is to keep space open, profitable, and peaceful and that requires governance that moves at the speed of the industry it oversees. We suggest these six priorities to guide us.

  1. Build rules of the road for orbit. We have air-traffic control for the skies and maritime law for the seas; orbit needs the same. A civil space-traffic management system built out from the U.S. Office of Space Commerce's nascent TraCSS program and shared internationally — ideally migrating to a neutral international steward over time — should, within this decade, provide authoritative tracking data, collision warnings, and right-of-way conventions that every operator is expected to follow. The same system should also serve accountability: shared, authoritative tracking makes it possible to establish who did what in orbit, so that a collision or an act of interference can be attributed and answered for rather than denied.
  2. Update the treaty without waiting for a new one. A grand replacement for the Outer Space Treaty is politically out of reach, and far slower than events demand. Instead, adopt the model that works for climate and the oceans: a recurring "Conference of the Parties" convened under UN COPUOS to let nations agree on concrete, incremental standards — definitions of "due regard," deorbit timelines, resource-use norms — without the impossibility of formal amendment.
  3. Make debris mitigation enforceable and universal. Deorbit mandates, building on the FCC's five-year rule, design-for-disposal requirements, and a ban on debris-generating weapons tests should be the global baseline, agreed multilaterally rather than exported by one regulator or left to a patchwork of national rules. Fund and incentivize active debris removal now, while the problem is still merely expensive rather than catastrophic.
  4. Formalize the commercial-defense partnership and its limits. If private constellations are now strategic infrastructure, governments owe their operators clear rules: when commercial capacity can be commandeered, how companies are compensated and protected, and what legal status a private satellite has if it is attacked. Resilience should be bought through partnership, not improvised in a crisis.
  5. Lead through alliances, not isolation. No single nation can police orbit, and the spacefaring democracies are stronger setting standards together. Coalitions among the United States and its allies, with the Artemis Accords as the nucleus, should align licensing, data-sharing, and behavioral norms to build a critical mass of responsible actors that newcomers must either join or be measured against. But coalition-building cannot become bloc-building: the rules that matter most — debris, traffic, and no weapons of mass destruction in orbit — are worthless unless they also bind China, Russia, and their partners, which means keeping channels open through the UN even as alliances set the pace.
  6. Set common rules for space data and fair access. Alongside physical traffic, the framework should govern the information satellites collect: who owns it, how privacy and national interests are protected, and on what terms it is shared. And because slots, spectrum, and launch capacity are finite, and already allocated through bodies like the ITU, access to them should stay open enough that capability and capital alone do not decide who benefits from orbit. Access meant for all of humanity should not narrow into a preserve of the few.

Conclusion

We are living through the most consequential change in humanity's relationship with space since the first satellite crossed the sky. The frontier that nations once visited to prove a point is now where they bank, communicate, navigate, and defend themselves and, increasingly, where they may fight. The private sector has given us an extraordinary gift of capability and cost. National security has made that capability indispensable. What we lack is the governance to match.

The choice before us is not whether to embrace this new era (it is already here) but whether we will steward it wisely or let it descend into congestion, debris, and conflict. The decisions we make in the next few years will determine whether low Earth orbit remains a thriving commons or becomes a contested ruin. We built the rockets that opened this frontier. We are fully capable of writing the rules that will keep it open. We should do so now, before the window closes.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

AI Agents Need Accountability That Travels With Them

1 July 2026 at 05:00

Most enterprise AI agents today are still being deployed in controlled environments. They sit inside a platform, perform a defined task and operate under the identity and access controls of that environment, however that window is closing. For many security teams, the current state makes the problem feel manageable. If the agent is inside the fence, the thinking goes, it can be governed by the controls already in place.

That view is understandable. Security teams already have more than enough to manage as AI models become more capable. The near-term implications for vulnerability discovery, fraud, social engineering and incident response are real, and they are moving quickly. Against that backdrop, the question of what happens when agents operate across boundaries can feel like a later-stage concern.

It is not. Identity and access controls can govern an agent inside a particular environment. The harder problem is maintaining accountability when the agent begins operating beyond it. Anthropic’s recentZero Trust framework for AI agents is explicit on this point: each agent instance should have a unique, cryptographically rooted identifier that persists through its lifecycle, appears in logs and access requests, and supports authentication, rotation and revocation. That kind of verifiable identity is what makes safe interoperability possible. As agents move between environments, accountability has to move with them, so the audit trail does not end at the boundary where the risk begins.

The limits of local control

The value of agents comes from their ability to act. They are being designed to invoke tools, coordinate work, exchange information and carry out tasks on behalf of people and enterprises. An agent that can only operate inside one tightly controlled environment may be easier to secure, but it will also be limited in what it can accomplish.

That is the tension enterprises now face. The same interoperability that will make agents valuable will also expand the risk surface around them.

Security leaders are right to focus on the risks already in front of them. More capable models are changing the threat environment in ways that matter right now. But model sophistication is only one part of the issue. The other is autonomy. As agents are given more tools, more permissions and more responsibility, the assumptions behind local control will become harder to sustain.

When Interoperability Becomes A Risk

Most agents are not yet moving freely across enterprise boundaries. Many remain narrow, supervised and limited in scope. But there are two reasons the boundary problem cannot wait.

The first is business value. If agents remain fully contained, their usefulness is constrained. Enterprises will look for returns from AI by connecting agents to more workflows, more tools and more partners. They will want agents to coordinate work across the places where business actually happens.

The second is control. Even enterprises that take appropriate precautions may overestimate how reliably agent activity can remain confined over time. Permissions change. Workflows expand. Tools are added. Business teams find new uses for systems once those systems begin producing value. The environment around agents will keep changing, and accountability needs to remain recognizable when it does.

Security teams are already seeing early versions of this problem in how autonomous AI systems interact with the outside world. An agent exposed to untrusted content may receive instructions the user never sees. An agent with broad permissions may take actions in a context its developers did not fully anticipate. An agent connected to internal data and external communication channels may create a path for leakage or misuse. These are practical control problems, and they become harder to manage as agents gain more tools, more permissions and more autonomy.

For CISOs, the pattern should sound familiar. Some of the hardest security problems emerge at the boundaries between systems, vendors and enterprises. Third-party risk and software supply chain incidents have shown how quickly trust assumptions can break down when no single party controls the full path of activity. Agents introduce a new kind of actor into that same environment. They may be delegated by one enterprise, executed through another platform and interact with a third party in the course of completing a task. In those moments, accountability has to travel with the agent rather than remain tied to the environment where it originated.

The cost of fragmented accountability

In that setting, local identity is not enough. An enterprise may be able to identify and monitor an agent inside the platform where it was created. But once the agent acts elsewhere, that identity may not travel cleanly. Another environment may not know which organization stands behind the agent, whether that relationship can be independently verified, or how trust should be adjusted if circumstances change.

This is where fragmentation becomes a practical security problem. If every platform defines agent identity in its own way, enterprises will inherit a patchwork of trust models. Each may work locally. Together, they create friction at best and gaps in accountability at worst.

Security teams could be left translating between local controls just as agents become more autonomous and more operationally important. That is a difficult place to put defenders. When something goes wrong, they need to know what acted, who was responsible and whether the activity can be contained. Those questions should not depend on which platform created the agent or where it happens to be operating at that moment.

A single high-profile failure could also have consequences beyond the immediate incident. If a rogue or misattributed agent causes material harm, the response could put a chill on the broader market. Security reviews could freeze, integrations could stall and product teams could be forced into a defensive posture as enterprises try to determine which agent activity they can trust. That remains a real risk as long as identity is fragmented and ownership cannot be consistently resolved.

That is not a sustainable foundation for enterprise adoption.

The answer is not to stop agent innovation or force every action back through manual review. That would defeat much of the purpose of the technology. Enterprises want agents because they can move work faster, connect processes and reduce the burden on people. Security teams need a way to support that progress without losing the ability to answer basic questions when something goes wrong.

Which organization stands behind the agent? Can that relationship be independently verified? Can its activity be traced across environments? Can trust be adjusted when circumstances change?

The June 2026 White House executive order on advanced AI innovation and security shows that these questions are now a national priority, one that applies equally across government, industry, and critical infrastructure. The only practical and durable solution for enforcing that is through a standard of accountability that is recognized everywhere.

A standard for portable accountability

Open matters. If the accountability layer for agents is defined separately by every major platform, then trust will fragment at the moment the market needs consistency. Enterprises will face the burden of reconciling competing approaches, and security teams will be forced to govern agents through local controls that do not resolve cleanly beyond their own environments.

A neutral trust layer gives the market a better path. Platforms, model developers, cloud providers and enterprise software companies can still innovate above it. But the basic ability to establish ownership and accountability for an agent should not depend on any one proprietary ecosystem. The trust layer has to be common enough to travel, and that means it’s probably one that already exists.

We have seen this pattern before. The internet was able to grow because certain foundational functions were treated as shared infrastructure. The Domain Name System did not solve every security challenge on the internet, and it was never meant to. But it did create a common way to resolve names across a global network without requiring one company to control the applications and services built above it. AI agents now need a similar foundation for accountability and trust.

That work should begin now, while the agent ecosystem is still forming. Waiting until agents are deeply embedded in enterprise workflows will make the problem harder to solve. By then, fragmented trust models may already be built into products, contracts, integrations and operating processes.

The promise of agents is real. So is the risk surface they introduce. The way forward is to build the accountability layer before fragmented trust models become embedded in the systems that agents will ultimately depend on.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌
❌