I just want to read the news

Get the news and only the news!

Guardian Yle Kaupunki CNN Hesari Al Jazeera New York Times Reuters NPR The Cipher Brief

Guardian

Back to top

Trump administration diverts human rights funds to push far-right agenda abroad

Support such as for white Afrikaners and anti-communism reveals how US is redefining what qualifies as human rights

With hours left before the funding expires, the Trump administration is pushing to direct more than $175m of the state department’s flagship human rights fund to a slate of awards that includes a huge $40m grant for an anti-communism fund, support for a group advancing white Afrikaner rights in South Africa, a campaign against Brazil’s supreme court and programs that would reward ideological allies in Europe who protect “western civilizational norms”.

On Wednesday, the state department obligated the funds to the grantees hours before the deadline despite congressional concerns and requests not to do so, according to a source familiar with the negotiations. The state department declined to comment on questions from the Guardian specifically on whether it had obligated the funds and had “blown” holds from Congress due to concerns about the money’s use.

Continue reading...



South African leader urges men to speak up on gender-based violence after series of killings

President announces measures amid anger at authorities over recent murders of women

South Africa’s president has called on men to take more responsibility for violence against women as he announced measures to tackle the problem, amid anger at authorities over a recent wave of murders.

Cyril Ramaphosa acknowledged that not enough had been done to protect women. He said police would be reviewing unsolved murders, attempted murders and serious sexual offences against women and children, as well as producing a funded plan to reduce the forensic backlog for such cases, both within 60 days.

Continue reading...



Burundi agrees to receive ‘third-country’ migrant deportees from US

Burundi joins several other African nations in accepting people deported under Trump’s hardline policy

Burundi has agreed to join a clutch of ⁠other African nations in receiving migrants from other countries deported from the US under ⁠Donald Trump’s hardline ⁠immigration ​policy.

However, Burundi will only accept those not accused of crime or terrorism links, said ⁠Nancy Ninette Mutoni, a spokesperson for the country’s president, Évariste Ndayishimiye. Tuesday’s announcement gave no details of numbers, timing or financial ⁠details.

Continue reading...



DRC politician beaten to death after radio appearance about Ebola outbreak

Marie-Celestin Karondwa was attacked on Sunday after promoting measures to prevent spread of disease, his party says

A senior member of the Democratic Republic of the Congo’s ruling party was beaten to death on Sunday after appearing on a radio programme to raise awareness about the Ebola outbreak, a party representative has said.

Marie-Celestin Karondwa, the acting president of the Union for Democracy and Social Progress (UDPS) party’s federal executive committee in Butembo, a new hotspot for the outbreak, was attacked after taking part in a ​radio show during which he ‌promoted prevention measures for the disease, ‌the UDPS federation in the city said in a statement, Reuters reported.

Continue reading...



At least 27 dead after two mass shootings in South Africa, police say

Seventeen people killed near Johannesburg in suspected ‘illegal goldmining turf war’, as 10 killed in separate incident at barbecue venue near Cape Town

Two separate mass shootings near South Africa’s two biggest cities killed at least 27 people, as the country grapples with one of the world’s highest murder rates amid investigations into corruption and criminality within the police.

The South African police service said on Sunday that 17 people were killed on Saturday night when eight suspects armed with AK-47 assault rifles and pistols opened fire at a bar in Wedela township, about 50 miles south-west of central Johannesburg. At least 15 other people sustained gunshot injuries in that attack, police said.

Continue reading...



Brazil attorney general says meddling ‘cannot be tolerated’ after Trump funding plans revealed

Jorge Messias calls Guardian report ‘an important alert for Brazilian sovereignty’ as nation prepares to go to polls

Brazil’s attorney general has said foreign meddling in his country’s institutions and democracy “cannot be tolerated” after a Guardian report revealed how the Trump administration was pushing to direct funds to a campaign against the Brazilian supreme court.

Writing on X, Jorge Messias called the report “an important alert for Brazilian sovereignty”. “The information is especially serious in light of Brazil’s electoral process and the recent episodes of external pressure on our institutions,” Messias added.

Continue reading...



‘It’s utter surrealism’: Venezuela’s Chavistas lament government’s embrace of Trump

Diehard Hugo Chávez supporters struggle to comprehend ideological U-turn being executed by Delcy Rodríguez’s interim administration

He was one of the most passionate propagandists for Hugo Chávez’s Bolivarian revolution: a feisty leftist TV personality who spent more than two decades singing the movement’s praises on his state-funded show, The Razorblade.

Mario Silva’s devotion was such that he often hosted his programme with Chávez’s portrait behind him and he had El Comandante’s curly signature tattooed on to his left wrist.

Continue reading...



Mighty Sparrow, the Trinidad and Tobago singer known as the ‘calypso king of the world’, dies aged 91

Slinger Francisco, who performed as the Mighty Sparrow, died on Sunday surrounded by family in New York

Slinger Francisco, known on stage as the Mighty Sparrow and dubbed the “calypso king of the world”, has died aged 91.

Francisco, who got his breakthrough in calypso music with his 1956 hit song Jean and Dinah, died peacefully surrounded by his family in New York on Sunday, his family said in a statement.

Continue reading...



Hurricane Nolo still threatens Hawaii as Mexico’s Baja braces for Hurricane Polo

Hurricane Nolo is moving away from Hawaiian islands but threat of heavy rain, flash floods and strong winds persists

Hurricane Nolo was moving away from the Hawaiian islands on Sunday, but the threat of heavy rain, flash flooding and strong winds persisted in areas of the island chain still recovering from previous storms.

Nolo was about 365 miles (585km) south-south-west of Honolulu and moving away from the Big Island at about 12mph (19km/h). But the Hawaii county civil defense agency said a high wind warning, wind advisory and high surf advisory remained in effect for parts of the island through Sunday evening as Nolo’s maximum sustained winds rose to 115mph.

Continue reading...



Melbourne man’s mysterious disappearance on popular Peru hiking trail prompts widespread search

Loved ones describe Jordan Yap, 30, as an experienced hiker who set out for a 10-day solo trek Peru before falling silent

Loved ones of a missing Australian trekker who was last seen nearly two weeks ago on a remote South American hiking trail are urging local authorities to help with the search.

A wide-scale sweep by a private rescue crew has so far failed to find any trace of 30-year-old Jordan Yap, who last made contact with friends and family on 14 September ahead of a planned 10-day solo trek along Peru’s Huayhuash mountain range, 400km north-east of Lima.

Continue reading...



Daredevil Jaan Roose completes slackline walk high above central Seoul

Estonian completed first of two attempts to navigate narrow ribbon, 160 metres long and 120 metres high, near the city’s famous Gyeongbokgung palace on Thursday

The lunchtime crowds drifted slowly back to their offices along central Seoul’s main boulevard, heads up and phones raised to the sky.

High above, a narrow ribbon ran between the Koreana hotel and the Dong-A Media Center, a few hundred metres from the capital’s famous Gyeongbokgung palace and Gwanghwamun square.

Continue reading...



MI5 China alert will send chill through UK’s cash-strapped universities

Institutions have for years turned to China for funding opportunities but national security concerns are mounting

The security alert issued by MI5 regarding a Chinese state-owned conglomerate accused of conducting espionage in the UK reveals the extent to which British intelligence remains concerned about Beijing’s influence, and risks casting a shadow over UK-China cooperation at a time when the bilateral relationship is enjoying a revival.

The UK’s domestic security service on Wednesday warned researchers and academics to cease work with the China Academy of General Technology (CAGT), an organisation MI5 described as a “significant threat”.

Continue reading...



MI5 warns UK universities over ‘theft of tech secrets by Chinese front company’

Security service says academics should stop working with and taking grants from firm backed by Chinese intelligence

MI5 has issued a rare public warning to UK universities that China’s intelligence service is using a front company to pay for research by UK academics and steal the secrets of hi-tech projects.

Britain’s domestic security service said researchers and academics should cease work with the China General Technology Research Institute (CGTRI), sometimes also known as the China Academy of General Technology (CAGT).

Additional reporting by Helena Horton

Continue reading...



AI tool that copied actor’s ‘lustrous’ voice violated his rights, Tokyo court rules

Kenjiro Tsuda wins case against TikTok account in landmark Japanese verdict to protect publicity rights

A court in Japan has ruled that the human voice has legal protection after a landmark case involving a well-known actor and a TikTok account that he claimed had cloned his “lustrous” baritone voice in its AI-generated videos.

Tokyo district court said on Wednesday that voices should enjoy the same protection as publicity rights, at the end of a closely watched legal action brought against TikTok by Kenjiro Tsuda – best known for voicing the character Kento Nanami in the anime Jujutsu Kaisen.

Continue reading...



South Korea calls for apology from North Korea after mine injures three soldiers

Blast during search operation near border fuels political tensions amid attempts to revive diplomatic channels

South Korea has demanded an apology from North Korea over a landmine blast that injured three soldiers, saying they were hurt by North Korean mines on the southern side of the border.

Kang Hyun-woo, the director of operations at South Korea’s joint chiefs of staff, demanded an apology and “responsible measures” from Pyongyang over the blast, which occurred on 21 September during a search operation south of the border.

Continue reading...



Australia news live: eSafety warns online gaming can cause ‘serious harms’ to children; Atlassian to power solar farm

Follow the day’s news live.

Former Wallaby hooker Nathan Charles diagnosed with MND at 37

The former Wallaby Nathan Charles, who became the first cystic fibrosis sufferer in the world to play a contact sport professionally, has been diagnosed with motor neurone disease (MND).

Continue reading...



Underlying causes of recurrent bacterial vaginosis identified by Australian scientists

Melbourne researchers behind previous BV transmission breakthrough turn attention to understanding why some cases are harder to cure

Australian scientists have identified two contributors to recurrent bacterial vaginosis infections, a common sexual health condition that affects about one in four women globally.

The condition, commonly called BV, is characterised by an imbalance of naturally occurring bacteria in the vagina, in which there is a reduction of “good” bacteria and an overgrowth of other mixed bacteria.

Continue reading...



Million-dollar public servants: 11 staff at Australia’s Future Fund paid significantly more than the PM

One executive received a $1.5m package last year, while 10 other staff received remuneration exceeding $1m each

Nearly a dozen federal public servants were paid more than $1m last year, with one receiving a $1.5m package worth more than double Anthony Albanese’s base salary.

The generous remuneration – which includes bonuses and allowances – has been criticised as insulting during a cost-of-living crisis and amid job cuts across the public service.

Continue reading...



Matt Kean warns climate crisis ‘isn’t someone else’s problem’ as largest coal project in NSW history greenlit

Exclusive: Climate Change Authority chair says planning commission did not account for climate-related economic damage in NSW

A senior Albanese government climate adviser has challenged the state approval of the largest coalmining development in New South Wales’ history, arguing “climate change isn’t someone else’s problem”.

Matt Kean, the chair of the Climate Change Authority and a former NSW treasurer and energy minister, questioned why the state Independent Planning Commission had not weighed the economic cost of climate change caused by burning the coal from the Hunter Valley Operations mine before giving it the green light to run until 2045.

Continue reading...



Anthropic pushes for opt-out model for Australian content as ABC warns of ‘cannibalisation’ of news

Maker of Claude claims AI could transform economy but ABC and SBS say the technology should be subject to media regulations

AI giant Anthropic has urged the Albanese government to consider giving “conditional approval” for big tech to train its models on Australian copyrighted works under an opt-out model, after conceding it won’t secure a blanket copyright exemption.

But Australia’s public broadcasters, the ABC and SBS, have strongly criticised AI firms, calling on the government to enact strict new rules to compensate media organisations and protect public interest journalism.

Sign up for Guardian Australia’s Politics, really newsletter here

Continue reading...



France school protests escalate into ‘urban violence’ as PM calls crisis cabinet meeting

About 900 demonstrations, blockades and related incidents under way outside high schools around the country

A fast-growing protest by high-school students over long hours, teacher shortages and decaying facilities has escalated into “urban violence”, the French government has warned, as it said many schools would switch to online classes to protect teachers and pupils.

The prime minister, Sébastien Lecornu, called a crisis cabinet meeting on Thursday and told ministers to cancel travel plans to deal with the demonstrations, which erupted in the Paris region last week but have snowballed across the country.

Continue reading...



Britain in talks with European allies over release of emergency diesel stockpiles

Ministers discuss drawing down EU countries’ reserves after Donald Trump threatens to cut off US supplies

Britain is in talks with European allies over releasing emergency diesel stockpiles after Donald Trump threatened to cut off US supplies of the fuel.

Ministers held calls with counterparts from the European Commission, Germany, France, Italy and Ireland on Thursday to discuss whether to draw down reserves after the Trump administration told Germany and France to release their stockpiles to help ease soaring global energy prices or face a US export ban.

Continue reading...



Putin says ‘all weapons at disposal’ if there’s an attack on Russia – as it happened

The president said it was a warning if any countries were considering an attack on Russia

The ⁠EU Commission, France, Italy, Ireland ⁠and ⁠Britain are ​holding a call on ⁠the possible need to release diesel ⁠stocks, an ​EU ‌official ‌said, as reported by Reuters.

A ‌Commission spokesperson had earlier declined direct comment on reports that the ‌Trump administration has told Germany and ​France to draw down emergency diesel ⁠inventories to help to ​ease global ​fuel ​prices or ​face ‌a potential ​US ​diesel export ban.

Continue reading...



Finnish PM says suspected break-ins at MPs’ homes could be work of foreign power

Police investigating reports of politicians’ homes being broken into in last year with nothing being stolen

The Finnish prime minister, Petteri Orpo, has said a foreign power could be responsible for a series of suspected break-ins at the homes of several members of parliament.

Police said on Thursday they were investigating multiple reports of MPs’ homes being broken into in the Helsinki area in the last year in which nothing was stolen but subtle signs of breaking and entering were left.

Continue reading...



Ukraine persists with Russian oil refinery strikes in defiance of Trump

US president blames attacks for driving up fuel prices before midterms, though analysts say his Iran war is main cause

Ukraine is pressing on with strikes on Russian oil refineries, defying Donald Trump, who blames the attacks for exacerbating a global diesel shortage and pushing up fuel prices.

Kyiv struck an oil facility in Russia’s southern Samara region overnight, Volodymyr Zelenskyy said on Thursday in a statement on social media. The Ukrainian president added that a Russian vessel in the Black Sea was hit, as well as a launch and storage site for attack drones in the Oryol region.

Continue reading...



NAZA film-makers say they spoke to more than 100 sources about Israeli actions in Gaza

Team behind documentary push back against IDF attempt to discredit its exposure of military systems

The team behind the award-winning film NAZA, which details the Israeli military’s targeting policies in Gaza and its alleged acceptance of high numbers of civilian deaths, have revealed they spoke to more than 100 sources with knowledge of the military systems used in the war.

The disclosure came in response to an Israel Defense Forces statement seeking to discredit the documentary.

Continue reading...



Co-pilot in flight stabbing had ‘Islamic radical indoctrination’, says Netanyahu

Alleged flydubai attacker interrogated by Saudi security services as investigation into apparent crash attempt opens

The Omani co-pilot who stabbed his captain in an apparent attempt to crash an Israel-bound flight from Dubai had previously undergone radical Islamist indoctrination and was suicidal, Israel’s prime minister, Benjamin Netanyahu, has claimed.

Israeli passengers intervened to stop the attack on Wednesday, restraining the co-pilot, while a reserve crew in the plane was able to stabilise the plummeting plane and ultimately land it safely in Saudi Arabia.

Continue reading...



Crude oil exports from strait of Hormuz largely return to pre-war levels

Alternative ways being used to move fuel out of Gulf region, but flows of refined products such as diesel still constrained

Exports of crude from the strait of Hormuz have largely returned to levels seen before the outbreak of the Iran war, as oil producers and the shipping industry have found alternative ways of transporting crucial fuel out of the Middle East.

Pipeline exports and ship-to-ship transfers are among the methods being used, according to analysts tracking the situation, while the US military continues to escort some vessels. However, flows of refined products such as diesel remain constrained, pushing prices higher.

Continue reading...



Israelis divided as vote that could oust Netanyahu only weeks away

Some on streets of Jerusalem pledge their support to prime minister while others hope for change

On the streets of Jerusalem, crowded with secular and ultra-Orthodox Jews, religious nationalists, settlers, Palestinians, and soldiers returning from deployments, uncertainty hangs over an election less than a month away that could mark a turning point for a country profoundly changed after the Hamas attacks of 7 October 2023 and nearly three years of war in Gaza, Lebanon and Iran.

The political battle remains on a knife-edge.

Continue reading...



New Google Maps images reveal massive scale of devastation in Gaza

Satellite imagery shows further destruction of homes, businesses and places of worship since fragile ceasefire

An update to Google Maps has revealed the extent of devastation during the three-year Gaza war and the severity of the continuing humanitarian crisis faced by the territory’s 2.3 million inhabitants.

The images were taken in June this year and show further destruction of homes, businesses, places of worship and infrastructure since a fragile ceasefire came into effect almost 12 months ago.

Continue reading...



British Sikh activist released from Delhi jail after nine-year detention

Indian government issued with warning it would be in contempt of court if it failed to release Jagtar Singh Johal

The British Sikh activist Jagtar Singh Johal has been released from a Delhi prison after the Indian high court warned the government it would be found in contempt of court if it continued to attempt to keep him in jail despite an 18 September court order releasing him on bail. Johal has been incarcerated for nine years without any full trial.

The court order was issued after Johal’s lawyers issued a writ of habeas corpus alleging he was being detained against the express direction of the court.

Continue reading...



‘We want justice’: series of rapes trigger mass protests at Indian universities

Women say nothing has changed since Delhi’s infamous Nirbhaya bus rape case 14 years ago

The posters, just like the women holding them, were taking no prisoners. “Girls don’t need curfews, rapists need consequences,” read one. “Lock your dicks rather than your women at home,” read another.

As hundreds of women walked from the gates of their university campus into the streets of Delhi – where sexual harassment, assault, catcalling and molestation are a constant, daily threat – they shouted together in a chorus of rage and defiance: “We want justice.”

Continue reading...



From Jamui to Delhi, the burden of safety from sexual assault cannot fall on women

As outrage grows over cases​ of sexual violence, activists are demanding a shift from controlling women to confronting men’s behaviour. Plus, Tony Klor’s ‘hella dope’ city vlogs

• Don’t get This is India delivered to your inbox? Sign up here

As an Indian woman, I often feel myself oscillating between states of anxiety or anger. The anxiety is about doing the mental maths of how to stay safe – thinking about what I’m wearing, where I am going and how I’ll get there, and so on. The anger is at the sheer absurdity of this, and the stories of of sexual violence and harassment I read about every day. I am not the only one.

Last week, two particularly enraging incidents captured national attention. First, a video showing a group of men accused of harassing and molesting two teenagers at night in Bihar’s Jamui went viral. Then, a 17-year-old, out with a friend in Delhi, was allegedly gang-raped in a park by men posing as police. After, women in Bihar told Outlook how the incident in Jamui triggers greater controls and pressure on them. In Delhi, authorities curbed access to public parks and a premier women’s college, Lady Shri Ram College (LSR), briefly moved classes online.

Continue reading...



Pakistan locks down Islamabad as Imran Khan’s party vows to march on capital

Tens of thousands of police deployed and roads barricaded as PTI party demands release of jailed former PM

Leaders from Imran Khan’s party have vowed to go ahead with a nationwide demonstration in Pakistan to demand the former prime minister’s release, even as the government deployed tens of thousands of police to Islamabad, barricaded highways and issued arrest warrants to try to stop the march.

The state has taken extreme measures to prevent Khan’s Pakistan Tehreek-e-Insaf (PTI) party from proceeding with the march. It was announced after mounting concerns of the treatment of Khan, who has been in jail since 2023 on corruption charges.

Continue reading...



Backlash as Indian oil heir made professor of sustainability by Newcastle University

Role for Anant Ambani, son of India’s richest person, who also runs a controversial mega-zoo, met with incredulity

Newcastle University is facing a backlash from conservationists over the appointment of the heir to an Indian oil and gas fortune who runs a controversial mega-zoo as a professor of sustainability.

The university announced that Anant Ambani had been given a professorship of practice for “his work in conservation, biodiversity protection, animal welfare and environmental stewardship” and “significant contributions to advancing a more sustainable future”.

Continue reading...



How success of Manchester City helped put Andy Burnham in power

PM has praised Abu Dhabi group as ‘huge partner’ in reshaping Manchester, but critics say this ignores public cost of city’s transformation

In July 2016, the Manchester City player Yaya Touré ambled into a small bar near Beijing’s Workers’ Stadium and offered a bemused smile as dozens of Chinese fans rushed towards him.

Manchester City had just won their sixth trophy under the big-spending ownership of Sheikh Mansour’s Abu Dhabi United Group and the blues were international megastars. They were also magnets for investment.

Continue reading...



Key disability benefit for young people may be axed under major welfare changes

Exclusive: Plan under discussion involves intensive support to help young people into employment

Ministers are working up sweeping plans for welfare changes including scrapping a key disability benefit for under-25s and replacing it with a multibillion-pound package of support to get into work, the Guardian has learned.

Whitehall sources said the package of changes under debate was much bigger than previously thought, as Andy Burnham’s government hopes to persuade more people on benefits back into work.

Continue reading...



Labour figures uneasy about Healey’s ‘underpowered’ approach to budget

Chancellor faces global volatility and soaring energy costs as some insiders worry lack of clarity could trigger fresh market shock

Senior Labour figures are privately voicing unease about John Healey’s approach to his crucial first budget this month, against the backdrop of volatile global markets and soaring energy costs.

The chancellor’s work has been made significantly harder by the global bond sell-off, which continues to raise the cost of government borrowing, and ever increasing energy prices as Donald Trump continues the US war with Iran.

Continue reading...



‘Total class act’: Marie-France van Heel is poised to be a very different PM’s wife

The former marketing executive is expected to play a big role in promoting the UK and could be the most influential spouse in No 10 in years

Sarah Brown called Gordon her hero, Samantha Cameron insisted David was “incredibly funny”, while Akshata Murty said Rishi was her best friend. When Marie-France van Heel spoke about her husband, Andy Burnham, in a rare public interview a decade ago, she joked that she had noticed his “good looks … and monobrow”.

The spousal humanising of a party leader is a well-worn political tool, but van Heel is likely to be a very different prime ministerial partner. The former senior marketing executive is poised to play a more significant role in promoting Britain than any other spouse in the last two decades, stepping up her political engagements after stepping back from her own corporate career.

Continue reading...



US borrowing costs hit 24-year high as global bond sell-off intensifies

Fears that US deficit is unsustainable also drive UK 30-year bond yields briefly above 6% for first time since 1998

The global bond sell-off intensified on Thursday, driving 10-year US government borrowing costs to their highest level in 24 years in a frantic day’s trading.

The threat of a renewed round of inflation from the persistently high cost of oil has spooked investors on both sides of the Atlantic, with central banks expected to raise interest rates in the coming months to prevent price increases from becoming embedded.

Continue reading...



Trump doesn’t rule out sending ICE to polling sites; US supreme court to review policy to detain immigrants challenging deportation – live

Justices will consider whether immigrants have a right to a hearing to determine if they should remain detained while challenging their possible deportation

The White House has, again, blocked CNN from covering Donald Trump as part of the rotating press pool.

The outlet was scheduled to be a part of the group of media traveling to Texas and Oklahoma with the president today, but was removed from list of newsrooms in place for the trip, per the White House schedule.

Continue reading...



Hitting the sweet spot: bear treats itself to baked goods at Colorado farmers’ market

Shoppers and vendors in Aspen surprised by unusual customer as it stretched to sample stall offerings

Farmers’ market shoppers might not usually pay much attention to the local resident devouring fresh bread and pastries at one of the stalls with extra gusto – but some certainly did last weekend when they realized it was a hungry bear.

Onlookers on Saturday reached for their phones to take photos and videos of the bear in downtown Aspen, Colorado, after it wandered through the stalls and got up on to its hind legs to dig into the baked goods.

Continue reading...



Judge denies defense motion to declare Lindsay Clancy not guilty of murder

Request for Clancy, 36, to be acquitted turned down nearly a month after first trial ended with deadlocked jury

The judge in the Lindsay Clancy murder case on Thursday refused to declare her not guilty, turning down a defense motion that had argued there was not enough evidence to prove she was responsible for killing her three children.

On Tuesday, Clancy’s attorney Kevin Reddington tried to persuade Judge William Sullivan that prosecutors had not offered any proof that Clancy had killed her three children. Prosecutors argued there was plenty of evidence, calling Reddington’s claim “laughable”.

Continue reading...



Supreme court to hear case challenging Trump’s immigration detention policy

Court will review practice of indefinite detention for undocumented immigrants living in the US

The US supreme court agreed on Thursday to take up a case challenging the Trump administration’s practice of indefinite detention for undocumented immigrants living in the US and awaiting deportation proceedings.

At the center of the immigration case is a dispute over Donald Trump’s reinterpretation of a longstanding policy that has led to a huge surge in the number of migrants held in detention centers.

Continue reading...



Lyft agrees to pay California $272.5m in largest-ever wage theft settlement

More than $237m will be distributed to drivers over firm labeling them independent contractors and not employees

Lyft agreed to pay the state of California $272.5m on Thursday to ⁠settle claims that it stole drivers’ wages by mislabeling them as independent contractors rather than employees.

Rob Bonta, California’s attorney general, called the agreement a “landmark win for workers” and said it was the largest settlement involving wage theft claims in the state’s history.

Continue reading...





Back to top



Kaupunki

Back to top

This site is down!

Back to top



Yle

Back to top

Menetelmä perintöä Neuvostoliitosta, sanoo asiantuntija – epäily tunkeutumisista koteihin horjuttaa turvallisuudentunnetta

Useat kansanedustajat epäilevät, että heidän asunnoissaan on käyty luvatta.



Nämä neljä asiaa tiedämme epäillyistä tunkeutumisista kansanedustajien koteihin

Koostimme listan tämänhetkisistä tiedoista liittyen epäiltyihin tunleutumisiin.



Presidentti Stubb nimesi ensimmäisen F-35-hävittäjän Sisuksi - näin alkoi uusi aikakausi

Lapin lennoston lentäjät esittelivät F-35:n. Kokosimme historiallisen päivän kuvat ja videot.



EU kokoontuu perjantaina keskustelemaan polttoaineen hinnasta

Polttoaineiden hinnat ovat nousseet sen jälkeen, kun Yhdysvallat ja Israel iskivät alkuvuodesta Iraniin.



Myrkkypiikeistä selvinnyt Christa Pike yritetään luultavasti teloittaa uudestaan yhden päätöksen takia

Teloitukset epäonnistuvat usein epämääräisten myrkkyjen ja kouluttamattoman henkilökunnan takia.



Vaarallinen puutiaisaivokuume tarttunut ennätysmäärään potilaita Suomessa – myös oireet entistä rajumpia

THL:n tartuntatautirekisteriin on kirjattu tähän mennessä reilu 390 puutiaisaivokuumetapausta. Vielä kymmenen vuotta sitten tapauksia todettiin vain 61.



Näin STT:n loppu näkyisi arjessa – päätoimittaja: Kaikki käyttävät omalla tavallaan

Suomen Tietotoimiston tilanteeseen reagoitiin mediakentällä heti. Moni paikallismedia on ostanut STT:ltä uutisia omaan käyttöönsä.



Kone syöksyi lähes pystysuoraan kuusi kilometriä – grafiikka ja videot näyttävät, mitä matkustajat joutuivat kokemaan

Yhdistyneet arabiemiraatit ja Israel ovat käynnistäneen tutkinnan tapahtumasta.



Lentojätti uskoo Suomen matkailuvaltteihin ja avasi uuden yhteyden Helsinkiin

Maailman suurimpiin kuuluva kaukolentoyhtiö avasi Helsingistä päivittäisen reitin Dubaihin, vaikka polttoaineen hinta on huipussa ja lähialueilla rauhatonta.



Iceye ja Nokia lähtivät uudelle markkinalle – Riippumattomuus Yhdysvalloista on valttikortti, arvioi satelliittitutkija

Iceye lähti valtaamaan uutta aluetta avaruusmarkkinoilla, koska valtioasiakkaat pyysivät sitä, sanoo perustaja Pekka Laurila Ylelle.



Kyselytunti alkoi epätavallisesti – oppositio moitti, että pienituloisten ostovoima heikkenee ja hyvätuloisten kasvaa

Oppositiosta arvosteltiin, että hallitus hellii suurituloisia veronkevennyksillä ja pienituloiset on ajettu ahdinkoon leikkauksilla.



Chen ja Mikko menivät naimisiin – oppilaitoksen mukaan se ei todista, että he ovat perhe

Lain mukaan lukukausimaksua ei tarvitse maksaa, jos ulkomaalaisella opiskelijalla on suomalainen perheenjäsen.



Laivaliikenne Hormuzinsalmessa nousi jo normaalitasolle – sitten tankkereihin iskettiin taas

Yle seuraa Lähi-idän tilannetta tässä päivittyvässä artikkelissa.





Back to top



CNN

Back to top

Markets digest bank earnings after recent turmoil



Still haven't filed your taxes? Here's what you need to know

So far this tax season, the IRS has received more than 90 million income tax returns for 2022.



Retail spending fell in March as consumers pull back

Spending at US retailers fell in March as consumers pulled back amid recessionary fears fueled by the banking crisis.



Analysis: Fox News is about to enter the true No Spin Zone

This is it.



Silicon Valley Bank collapse renews calls to address disparities impacting entrepreneurs of color

When customers at Silicon Valley Bank rushed to withdraw billions of dollars last month, venture capitalist Arlan Hamilton stepped in to help some of the founders of color who panicked about losing access to payroll funds.



Not only is Lake Powell's water level plummeting because of drought, its total capacity is shrinking, too

Lake Powell, the second-largest human-made reservoir in the US, has lost nearly 7% of its potential storage capacity since 1963, when Glen Canyon Dam was built, a new report shows.



These were the best and worst places for air quality in 2021, new report shows

Air pollution spiked to unhealthy levels around the world in 2021, according to a new report.



Big-box stores could help slash emissions and save millions by putting solar panels on roofs. Why aren't more of them doing it?

As the US attempts to wean itself off its heavy reliance on fossil fuels and shift to cleaner energy sources, many experts are eyeing a promising solution: your neighborhood big-box stores and shopping malls.



Look of the Week: Blackpink headline Coachella in Korean hanboks

Bringing the second day of this year's Coachella to a close, K-Pop girl group Blackpink made history Saturday night when they became the first Asian act to ever headline the festival. To a crowd of, reportedly, over 125,000 people, Jennie, Jisoo, Lisa and Rosé used the ground-breaking moment to pay homage to Korean heritage by arriving onstage in hanboks: a traditional type of dress.



Scientists identify secret ingredient in Leonardo da Vinci paintings

"Old Masters" such as Leonardo da Vinci, Sandro Botticelli and Rembrandt may have used proteins, especially egg yolk, in their oil paintings, according to a new study.



How Playboy cut ties with Hugh Hefner to create a post-MeToo brand

Hugh Hefner launched Playboy Magazine 70 years ago this year. The first issue included a nude photograph of Marilyn Monroe, which he had purchased and published without her knowledge or consent.



'A definitive backslide.' Inside fashion's worrying runway trend

Now that the Fall-Winter 2023 catwalks have been disassembled, it's clear one trend was more pervasive than any collective penchant for ruffles, pleated skirts or tailored coats.



Michael Jordan's 1998 NBA Finals sneakers sell for a record $2.2 million

In 1998, Michael Jordan laced up a pair of his iconic black and red Air Jordan 13s to bring home a Bulls victory during Game 2 of his final NBA championship — and now they are the most expensive sneakers ever to sell at auction. The game-winning sneakers sold for $2.2 million at Sotheby's in New York on Tuesday, smashing the sneaker auction record of $1.47 million, set in 2021 by a pair of Nike Air Ships that Jordan wore earlier in his career.



The surreal facades of America's strip clubs

Some people travel the world in search of adventure, while others seek out natural wonders, cultural landmarks or culinary experiences. But French photographer François Prost was looking for something altogether different during his recent road trip across America: strip clubs.



Here's the real reason to turn on airplane mode when you fly

We all know the routine by heart: "Please ensure your seats are in the upright position, tray tables stowed, window shades are up, laptops are stored in the overhead bins and electronic devices are set to flight mode."



'I was up to my waist down a hippo's throat.' He survived, and here's his advice

Paul Templer was living his best life.



They bought an abandoned 'ghost house' in the Japanese countryside

He'd spent years backpacking around the world, and Japanese traveler Daisuke Kajiyama was finally ready to return home to pursue his long-held dream of opening up a guesthouse.



Relaxed entry rules make it easier than ever to visit this stunning Asian nation

Due to its remoteness and short summer season, Mongolia has long been a destination overlooked by travelers.



The most beautiful sections of China's Great Wall

Having lived in Beijing for almost 12 years, I've had plenty of time to travel widely in China.



Sign up to our newsletter for a weekly roundup of travel news



Nelly Cheboi, who creates computer labs for Kenyan schoolchildren, is CNN's Hero of the Year

Celebrities and musicians are coming together tonight to honor everyday people making the world a better place.



CNN Heroes: Sharing the Spotlight



Donate now to a Top 10 CNN Hero

Anderson Cooper explains how you can easily donate to any of the 2021 Top 10 CNN Heroes.



0% intro APR until 2024 is 100% insane



It's official: now avoid credit card interest into 2024



Experts: this is the best cash back card of 2022



Turn Your Rising Home Equity Into Cash You Can Use



Dream Big with a Home Equity Loan



Want Cash Out of Your Home? Here Are Your Best Options





Back to top



Hesari

Back to top

Tennessee | Kaikki meni pieleen teloituskammiossa – näin tapahtumat etenivät tunti tunnilta

Kuolemaantuomitun Christa Piken teloitus epäonnistui poikkeuksellisella tavalla Tennesseessä. Pike on tällä hetkellä kriittisessä tilassa sairaalassa.



Venäjä | Putin syytti länttä Ukrainan sodan aloittamisesta ja halusta ”hajottaa Venäjän imperiumi”

Vladimir Putin piti torstai-iltana yli kolmetuntisen puheen kansain­välisessä Valdai-foorumissa. Perinteisesti Sotšissa järjestetty tapahtuma siirrettiin tänä vuonna Moskovaan.



Lentäminen | Tätä tarjoaa Helsingin-lennot aloittanut arabiyhtiö Emirates

Emiratesin johtaja vakuuttaa, että Helsingin-lentojen turvallisuus ei ole vaarantunut, vaikka yhtiön kotikentän vieressä soditaan. Itse kone on hulppeasti sisustettu.



Eduskunta | Viranomaislähde HS:lle: Joihinkin kansanedustajien koteihin on saatettu murtautua

Eduskunnan puhemies Jussi Halla-aho kertoi torstaina, että useiden kansanedustajien koteihin on mahdollisesti tunkeuduttu. Helsingin poliisi selvittää tapauksia keskusrikospoliisin tukemana.



Formula 1 | Verottaja iskee kiinni Valtteri Bottakseen, jos kauden päätöskisa siirretään

Italian verot eivät sytytä F1-tähtiä. Kauden päätöskisa voidaan viedä Imolaan, mikäli Lähi-idän tilanne ei selkene.



Kuolleet | Venom-yhtyeen solisti Cronos on kuollut

Äärimetallin pioneeri esiintyi Suomessa viimeksi kesällä 2025.



Ranska | Sekavan lukioprotestin ytimessä on Théodore Djamai, 19, joka vastustaa muutakin kuin kouluoloja

Lukio-opiskelijat pitävät meteliä koulunsa ulkopuolella, ja monet protestoivat muutakin kuin kouluoloja. Väenpaljoudessa vilisee tonttulakkeja, palestiinalaishuiveja, balaklavoja ja hupparinhuppuja.



Keikka-arvio | Waltari-yhtye ylitti itsensä Tavastian jätti­konsertissa

Waltarin 40-vuotisjuhlakonsertissa Tavastialla nähtiin bändin kolme eri kokoonpanoa, ja konsertti kesti kolme ja puoli tuntia.



Teatteriarvio | Vesa-Matti Loirin elämästä kertovan esityksen bändi voisi melkein olla koko esitys

Suomalaisen suurmiehen elämäntarinan kertova esitys svengaa elävän bändin säestyksellä kuin hirvi.



Tv-oikeudet | Yle menetti kokonaan Tour de Skin

Viaplay näyttää kaikki hiihdon maailmancupin osakilpailut, Yle alle puolet.



Musiikki | Linda Lampeniuksen arvoviulu putosi käsistä kesken konsertin

200 000 euron arvoinen soitin selvisi ilmalennosta ilman pahoja vaurioita.



Tuomiot | Vaimo siirsi dementoituneen miehensä rahoja itselleen, oikeus tuomitsi kavalluksesta

Dementoituneen miehen edunvalvontasopimus viivästyi, koska viranomaisilla oli ruuhkaa.



Henkilö | Susanna Penttilä kertoo, miksi hänestä tuli miljoonatiliä tekevä pornotähti

Susanna Penttilä on tehnyt itsestään tuotteen, jota voi tilata 9,49 dollarilla kuussa. Pornobisnes on myynyt yli miljoonalla ja herättänyt myös paheksuntaa.



Brändit | Niken osake romahti, nyt tuli rukkaset Kylian Mbappélta

Kylian Mbappé hylkäsi Niken ja sen jättimäisen tarjouksen. Ranskalaisen kumppani on nyt urheiluvaateyhtiö On.



Kuvataide | Toimittaja antautui hypnotisoitavaksi ja yritti sitten haastatella: Tällainen jutusta tuli

Taiteilija Aapo Nikkasen teokset tapahtuvat ihmisen alitajunnassa: hän vaivuttaa yleisönsä hypnoosiin. Sille on tässä ajassa tilausta.



Näyttelyarvio | Elin Danielson-Gambogin uusi näyttely on alkupala, Ateneumin pääruoka saattaa olla maukkaampi

Kultakauden kapinallinen järkytti aikalaisyleisöjä maalauksillaan, joissa naiset tupakoivat, pelaavat korttia ja jättävät sängyt petaamatta. Nyt häntä esitellään kahden museon voimin.



Suomenlahti | ERR: Venäjä pysäytti Ruotsista Viroon matkalla olleen rahti­laivan

Kyproksen lipun alla purjehtiva Västerbotten kulki sovitulla reitillä Venäjän aluevesillä Suomenlahdella. Se pääsi myöhemmin torstaina jatkamaan matkaansa.



Kirjallisuus | Luotettavan tiedon tarjoaminen on jo vaakalaudalla

Päätöksenteon tukena pitää olla tutkittua tietoa, mutta tutkimustiedon pitää olla myös kansan saavutettavissa ymmärrettävässä muodossa.



Venäjän uhka | Sotilas­tiedustelun päällikkö: Venäjä näyttää valmistelleen sabotaasien tekemistä Suomessa

Venäjä on halunnut kuvia kohteista, joihin sabotaasi-iskut voisivat sijoittua.



Ammunta | Eetu Kallioinen voitti skeetin EM-kultaa

Suomella oli kahden mitalin päivä haulikkolajien EM-kisoissa.



Tuomiot | 12-vuotias raiskattiin kolme kertaa Triplan yleisessä vessassa Helsingissä

12-vuotias tuli kolme kertaa raiskatuksi Triplassa. Asiantuntija kehottaa ohikulkijoita puuttuvaan epätavallisiin tapauksiin.



Suomi haluaisi EU:lta enemmän vähemmällä

Suomi liittyi EU-budjetin nuukaan rintamaan mutta rajasi heti omat maataloustukensa säästöjen ulkopuolelle.



Miniristikko | Tänään paljon tuntemattomia tekijöitä ruudukossa!

HS:n 5x5-miniristikko ilmestyy päivittäin vaihtuvalla aiheella. Kokeile saatko kaikki sanat omille paikoilleen.



Skeittikulttuuri | Helsingin ytimeen nousee skeittipaikka, jota vielä kadehditaan maailmalla

Alvar Aallon suunnittelemaan uima-altaaseen liittyy sitkeä urbaani legenda, jota Helsinki nyt hyödyntää.



Liikenne | Espoossa on lokakuussa suuri työmaasuma, asukkailta ”toivotaan kärsivällisyyttä”

Espoossa on tänä syksynä käynnissä useita suuria työmaita, jotka vaikuttavat liikenteeseen. Turunväylällä alkoi torstaina uusi kolmen viikon poikkeusjärjestely.



Jalkapallo | Arsenalin Leah Williamson otti maalipotkun vastaan kädellä, tuomari ei katsonut virhettä sormien läpi: ”Kerran miljoonasta”

Arsenal menetti voittonsa poikkeuksellisella tavalla.



Korkeakoulut | LUT-yliopisto ja LAB-ammatti­korkea­koulu aloittavat muutos­neuvottelut, jopa 160 työ­paikkaa vaarassa

Neuvottelujen piirissä on yhteensä lähes 1 300 ihmistä.



Sijoittaminen | Syyttäjä vaatii ex-pokeritähti Jens Kyllöselle vankeutta sijoituspalvelu­rikoksesta

Ex-pokeritähti Jens Kyllönen ja hänen yhtiökumppaninsa ovat syytettyinä sijoituspalvelurikoksesta. Syyttäjän mielestä he toimivat rahastossa salkunhoitajina ilman Finanssivalvonnan lupia.



Konserttiarvio | Hayato Sumino on pianistina ilmiö, ja hän totisesti todisti osaamisensa myös helsinkiläisille

Harvoin orkesteri ja solisti puhuvat yhtä yksimielisen samaa kieltä kuin Hayato Sumino ja Helsingin kaupunginorkesteri.



Turvallisuus | Kansanedustaja epäilee, että hänen kodissaan käytiin jo keväällä 2022

Joidenkin kansanedustajien koteihin on epäillysti tunkeuduttu. Tekijästä ei tällä hetkellä tiedetä mitään. Lue tiedotustilaisuuden seuranta jutun lopusta.



Arvot | Punavihreä pikkuporvari on aina oikeassa

Tämä on kertomus punavihreistä pikkuporvareista.



Lukeminen | Lukumummit ja -vaarit innostavat lapsia lukemaan

Lukutaitoa tukevaa vapaaehtoistoimintaa uhkaa lopetus, jos hallituksen leikkaukset järjestöjen toimintaan toteutuvat.



Elokuvat | Seela Sella ehti kuvata vielä yhden elokuva­roolin

Näyttelijä nähdään alkuvuonna 2027 julkaistavassa Teemu Villikan ohjaamassa Ikuisesti-elokuvassa.



Elokuva-arvio | Anne Hathawayn ja Dakota Johnsonin kaksin­taistelu lässähtää jännitys­elokuvassa

Colleen Hooverin jännityskirjan filmatisointi Verityn varjo pelaa Anne Hathawayn ja Dakota Johnsonin välisellä kaksintaistelulla.



Deittailu | Kysyimme helsinkiläisiltä, milloin deittikumppanin kanssa kannattaa mennä seuraaville treffeille

Tapailuvaiheen alkuun kuuluu usein punninta siitä, kannattaako toista nähdä uudestaan. Kysyimme ihmisiltä, millä perusteella he lähtevät ensimmäisille, toisille ja kolmansille treffeille.



Konserttiarvio | Nylon Beat palasi jäähalliin luusereiden puolelle

Kotimaisen ysäripopin pioneeri Nylon Beat teki 7 500 hengen jäähallikeikasta lämminhenkiset kotibileet ja juhli kaikkea sitä, mistä yhtyettä aikanaan vähäteltiin.



Elokuva-arvio | Kalliolaisnuori sinnittelee päihteiden kierteessä kunnian­himoisessa dokumentissa

Kuuden vuoden seurantadokumentti Sopeutumaton keskittyy yksilön valaistumiseen ja kuvaa huumeidenkäyttöä alleviivaavasti.



Some | Miksi poliitikko esittelee suuteluaan some­kuvassa? Taustalla on Metan uusi sääntö

Meta kieltää politiikan mainostamisen sosiaalisessa mediassa. Eduskuntavaaleissa muutos näkyy niin, että ehdokkaat hakevat huomiota ilman poliittista viestiä.



Tuomiot | Pienet lapset jäivät satojen kilojen rakennus­levyjen alle: Miehelle tuomio törkeästä kuoleman­tuottamuksesta

Rakennuslevyt kaatuivat kahden lapsen päälle Mäntsälässä syksyllä 2024.



Al-Hol | Krp epäilee al-Holin leiriltä palannutta naista kolmesta törkeästä ihmis­kaupasta

Suomalaisnaisen epäillään matkustaneen kolmen alaikäisen lapsensa kanssa vuonna 2014 terroristijärjestö Isisin hallitsemille alueille.



Autot | Sähköautojen osuus ensi­rekisteröinneistä ylitti 50 prosenttia

Täyssähköautojen suhteellinen osuus ensirekisteröinneistä on Suomessa EU-maiden toiseksi korkein. Vain Tanska on edellä.



Elokuva-arvio | Harvinaisen hieno elokuva tekee draamaa vallasta

Paolo Sorrentinon presidenttidraama La Grazia vihjaa, että armoa on kaikkialla. Se näyttää, millaista pitkäaikaisen vallanpitäjän on luopua asemastaan



Teatteriarvio | Mari Rantasilan ohjauksessa äidit uhriutuvat ja soittavat kesken työpäivän

Kun kaksi 1970-luvun avainkaulalasta muistelee äitejään, ovat mielleyhtymät pölyisiä.



Jalkapallo | Manchester Cityn miljardihuijaus repii Englantia, pudottaminen yhtä sarjaporrasta alemmaskaan ei riitä kaikille

Huijausskandaalin tuomiot ovat antamatta, mutta vaatimukset kovenevat. Pääministeri Andy Burnham korostaa, että Cityn omistajat ovat investoineet valtavasti Manchesterissa.



Rajavalvonta | Länsi­satamassa paljastui jälleen laittoman maahan­tulon yritys

Rajavartiolaitos kertoo paljastaneensa afgaani­taustaisen henkilön Helsingin Länsisatamassa keskiviikon ja torstain välisenä yönä.



Elokuva-arvio | Viina ja vallankumous piinaavat demarien voima­hahmoa kotimaisessa elokuvassa

Kotimainen historiallinen elokuva Punainen peto kertoo, miten demarien perustajat kamppailivat alkoholismin ja kapinoinnin kanssa.



Apotti | Apotin tulevaisuutta ei pidä ratkaista ilman markkina­vuoro­puhelua

Apottia koskeva pikainen markkinavuoropuhelu on välttämättömyys.



HS testaa | Uusi Ferrari ja Nissan näyttävät samalta, mutta jälkimmäisen ohjaus lannistaa

Uudessa Nissan Leafissa on monia hyviä piirteitä, mutta varusteltuna se on aivan liian kallis. Kulutus ilahduttaa.



HS Rovaniemellä | Suomen uusi F-35-hävittäjä nousi sittenkin ilmaan

F-35-hävittäjien aika alkoi virallisella vastaanottoseremonialla.



Eduskunta | Eduskunnassa pidettiin kokous uhasta, josta ei kerrota julkisuuteen

Turvallisuusjohtajan mukaan turvallisuushuoli liittyi vaalien lähestymiseen, eikä ihmisten henkeen ja terveyteen kohdistu vaaraa.



Asuminen | Suomessa kokeillaan: Mitä viileämpi asunto, sitä pienempi vuokra

Kotkassa käynnistyy kokeilu, jossa vuokralainen voi vaikuttaa vuokraansa asuntonsa lämpöä säätämällä.



Ravitsemus | Lihasta päätyy ihmiseen vierasta sokeria – tutkijat selvittävät yhteyttä diabetekseen

Punaisesta lihasta saatava sokeri yhdistyi suurempaan kakkostyypin diabeteksen riskiin, jos saanti oli runsasta.



Tekoäly | Tekoäly nopeuttaa sotaa vaarallisesti

Tekoälyn käyttö asejärjestelmissä on jo nyt todellinen riski, joka jää liian vähälle huomiolle.



Kysely | Miltä vuoroviikkoasuminen tuntuu?

HS:n Kuukausiliite kerää eroperheiden lasten kokemuksia vuoroviikkoasumisesta.



Pyöräily | Helsingin uusi pyörä­tie oikaisee 100 metriä, hinta 6 miljoonaa euroa

Itäbaanan vieressä kulkee vanha pyörätie. Uusi pätkä lyhentää pyöräilijöiden matkaa 100 metriä ja on kaupungin mukaan vanhaa turvallisempi ja suorempi.



Rikosepäilyt | Poliisi epäilee: Mies järjesti puhelin­huijauksia ruotsalais­jengin tilauksesta

Klaukkalalaismiehen tehtävänä oli poliisin mukaan hankkia sujuvaa suomea puhuvia ihmisiä tekemään maksuvälinepetoksia.



Jalkapallo | Palloliiton turvallisuus­päällikkö perustelee, miksi Valko-Venäjän opposition liput poistettiin katsomosta

Uefa ei hyväksy poliittisia mielenilmauksia.



Verkkorikollisuus | Tissit ovat Suomen suurin tietoturvauhka

Vaikutusvaltaiset miehet menettävät harkintakykynsä houkuttelevien valeprofiilien edessä.



Arkiruoka | Kattilallinen luotto­keittoani maksaa alle 8 euroa ja riittää yhdelle hengelle viideksi päiväksi

Syksyinen keitto on edullista, helppo valmistaa ja säilyy pitkään.



Elokuva-arvio | Rose pukeutuu mieheksi yhdessä elokuva­syksyn koho­kohdista

Kovassa nosteessa oleva näyttelijä Sandra Hüller palkittiin Rosen pääosasta Berliinin elokuvajuhlilla.



Uutisvisa | Mikä oli 1960-luvun lopun agenttikomediasarjan Salainen agentti 86 päähenkilön nimi? James Potkukelkka se ei ollut!

HS:n Uutisvisa testaa, oletko ajan tasalla. Kymmenen kysymyksen avulla saat selville, kuinka hyvin olet lukenut Hesarisi viime aikoina.



Tekoäly | Yhdysvaltojen hallinnon uusi teko­äly­botti alkoi korjata Trumpin väitteitä

Ensin Trumpin hallinnon uusi tekoälychatti korjasi presidentin vaaliväitteitä, sitten se kieltäytyi kommentoimasta politiikkaa.



Teknologia | Nokia ja Iceye haastavat SpaceX:n Starlinkin

Nokia ja Iceye alkavat kehittää viestintäsatelliittijärjestelmää valtioiden tarpeisiin. Ensimmäiset satelliitit on tarkoitus laukaista jo 2028.



Tekoäly | Suomen on kannettava oma vastuunsa turvallisesta tulevaisuudesta

Suomen on tehtävä pitkän aikavälin päätöksiä, jotka huomioivat sekä tekoälyn kehityksen että maapallon rajat.



Kauhunhetket lennolla | ”Se kesti ehkä vain viisi minuuttia, mutta se tuntui helvetiltä”, sanoo koneessa ollut BBC:lle

Dubaista Tel Aviviin matkalla ollut matkustaja­kone joutui keskiviikkona laskeutumaan kesken matkan, koska koneen kahden lentäjän välillä oli väkivaltainen välikohtaus.



Kauppa | Löperöt lupaukset on pakko ottaa pois: Useiden tuttujen tuotteiden ulkoasu muuttuu

Kuluttajatuotteiden markkinointi epämääräisillä ja harhaanjohtavilla viherväitteillä on nyt kiellettyä EU:ssa. Yritysten pitää todistaa väitteensä.



Ukrainan sota | Ukraina yllätti Venäjän salaisella vasta­hyökkäyksellä, jossa käytettiin robotteja

Kremlissä ei kuukausiin tiedetty, että Venäjän armeija vetäytyi tärkeiltä alueilta.



Kuoleman­rangaistus | Nainen vietiin sairaalaan teloituksen epäonnistuttua

Tennesseen kuvernöörin mukaan kaikki osavaltion teloitukset keskeytetään vuoden loppuun asti.



Kuukauden äänikirjat | Lokakuun äänikirjoissa jännityssarjan avaus sekä sukutalon salaisuuksia

Lokakuussa äänikirjat vievät HS:n tilaajat Lappiin ja ikiaikaiselle sukutilalle.



Tietoturva | F-Secure aloittaa muutos­neuvottelut tekoälyn vuoksi

Muutosneuvottelut saattavat johtaa enimmillään 145 tehtävän loppumiseen.



Eläköityminen | Nuorille aukeaa töitä, kun tuhannet eläköityvät Suomen suurimmalta työllistäjältä

Helsingin kaupungin työntekijät eläköityvät kovaa vauhtia. Varsinaiset ruuhkavuodet alkavat vuonna 2029.



Ralli | Sami Pajari taistelee Italiassa maailman­mestaruudesta, saa etua ajojärjestyksestä

Sami Pajari, 24, taistelee maailmanmestaruudesta Sardinian arvoituksellisessa sorarallissa.



NHL | Rasmus Ristolainen jyräsi Sidney Crosbyn heti alussa, mutta katsoi pian vierestä tämän juhlimista

Rasmus Ristolainen täräytti rajun taklauksen. Penguins nöyryytti sen jälkeen Flyersia.



Apurahat | Tiede voitti ja taide hävisi, kun apuraha­säätiöt jakoivat ennätys­potin

Yksityisten säätiöiden rahoitus taiteelle putosi 16 miljoonalla eurolla kahden hyvän vuoden jälkeen.



Televisio | Yksi ihmis­kunnan suurista kysymyksistä näkyy tv-sarjoissa: vapaasta tahdosta kiistellään yhä

Yksi ihmiskunnan suurimmista kysymyksistä saattaa jäädä mysteeriksi.



Teko­äly | Teko­äly­agentit yrittivät murtautua Kanadan hallinnon verkko­sivulle

Hyökkäykset tapahtuivat touko- ja kesäkuussa.



Helsinki | Kallion kesäkadut puretaan, asukkaat voivat hakea kasveja itselleen

Kahden kesän mittainen kokeilu päättyy.



Muuttolinnut | Sata­kieli sinnittelee yli Saharan syömättä ja juomatta

Pienten lintujen koettelemus aavikon yllä voi kestää useita vuorokausia.



Lastensuojelu | Jokainen lapsi on pelastettava elämälle

Miina Sillanpää kääntyisi haudassaan, jos tietäisi millaiseen kaaokseen lastensuojelu on ajautunut.



Polttoaineet | Autoilijoihin kohdistuvaa rasitusta on tasattava

Polttoaineiden väliaikaisen hinnanalennuksen voi tehdä yksinkertaisesti.



Joukkoliikenne | Maailma muuttuu, mutta HSL ei tunnu välittävän siitä

Vielä muutama vuosi sitten vain hymähdettiin, jos joku uskalsi toivoa muuta kuin digitaalista palvelua. Nyt asenteet ovat muuttuneet, vaikka joukkoliikenteessä sitä ei huomaa.



Muistokirjoitus | Luonnonystävä ja lääkäri

Elja Herva 1938–2026



Ydinaseet | Ollaanpa rehellisiä: Suomi sai suojan, joka ei ole totta

Suomi livahti Naton ydinsateenvarjon alle vähällä keskustelulla. Pitäisikö puhua enemmän siitä, mikä voi mennä pieleen?



HS Lapissa | Juuso Piiskonen myi talonsa ja muutti Lappiin, koska työ­tilanne on ”älyttömän hyvä”

Turismin kasvu tuo työtä rakentajille, joita haalitaan nyt etelästä Lappiin. Rakennusyrittäjän mukaan alalla on pohjoisessa ”hirveä työvoimapula”.



Elämä | Isänsä lapsena menettänyt Kaan Kairinen kuuli henki­rikoksesta vasta vuosien päästä

Kaan Kairisen äiti yritti suojella lapsiaan raskaalta totuudelta. Nyt Huuhkajien keskikenttäpelaaja kertoo, mitä isän kuolema merkitsi hänen lapsuudelleen ja yhteydelleen omaan turkkilaiseen taustaansa.



HS 50 vuotta sitten 1.10.1976 | Amerikkalaislehti Suomen tilanteesta: Hyvän elämän korkea hinta

”Suomi selviää nykyisin varsin hyvin maaksi, joka antautui kahdesti Neuvostoliitolle toisen maailmansodan aikana”



Musiikki | Kanye Westin keikat Pietarissa peruttiin, viran­omaiset tutkivat epäiltyä petosta

Alle kahden viikon päästä sovittujen keikkojen toteutuminen oli vaikuttanut epävarmalta jo pitkään.



Varallisuus | Matti Remonen nosti käänteistä asunto­lainaa ja osti sillä kolme autoa

Käänteisestä asuntolainasta maksetaan laina-aikana yleensä vain korkoa, ei lyhennyksiä. Pankki voi myöntää sitä velatonta tai lähes velatonta asuntoa vastaan.



Musiikki | Jere Kososella on lippu kaikille neljälle Nylon Beatin keikalle, vaikka hän syntyi vuosi yhtyeen perustamisen jälkeen

Neljä keikkaa Helsingin jäähallissa tekevä suosikkiyhtye tuo fanien mieleen muistoja lapsuudesta, mutta tarjoaa myös vaihtoehdon laskelmoidulle nykypopille.



Jalkapallo | HJK:n taival Eurooppa-cupissa päättyi

HJK:n naiset taipuivat kaksiosaisessa otteluparissa norjalaiselle Brannille yhteismaalein 0–6.



Puola | Puolan parlamentti ei pitänyt lupaustaan, nyt aktivistit avasivat automaatin abortti­pillereille

Automaatti sijaitsee vastapäätä Puolan parlamenttia, joka ei ole lupauksistaan huolimatta lieventänyt maan tiukkaa abortti­lainsäädäntöä.



Meemit | Pienen lesbobaarin maski­kohusta tuli valtava netti­hitti, ja nyt Hollywoodkin kiinnostui

Yhdysvaltalainen The Boston Globe -sanomalehti kirjoitti pikkukaupungin lesbobaarista jutun, joka on nousemassa 154-vuotiaan lehden historian luetuimmaksi. Jopa Hollywood kiinnostui aiheesta.



Jääkiekko | Kiekko-Espoo voitti taas, asiantuntija suitsuttaa löytöjä

Kiekko-Espoon uudet vahvistukset vakuuttavat. Kruunupaidat kaatoivat TPS:n.



Jalkapallo | Pikkuhuuhkajat voittoon Romaniassa, EM-unelma roihuaa

Suomen alle 21-vuotiaiden maajoukkue varmisti vähintään EM-jatkokarsintapaikan.



Sivuhuomioita | Kävin elokuvissa ja tuohduin: Yleisö nauroi väärin

Minotaur-elokuvan raakuudet saivat helsinkiläisen yleisön hekottamaan. Koomisen kauhun vyöry on muuttanut elokuvayleisöä, kirjoittaa toimittaja Tero Kartastenpää.



Jääkiekko | Anna: Konsta Heleniusta kiusattiin koulussa, äiti pelkäsi

Jääkiekkoilija Konsta Helenius ja hänen Maiju-äitinsä ovat antaneet haastattelun Anna-lehdelle.



HS Pariisissa | Nuoret kertovat, miksi Ranskan lukioissa protestoidaan väkivalloin: ”Valtio ei tee ongelmille mitään”

Ranskan lukiolaiset vastustavat muun muassa suuria luokkakokoja, ja opettajapulaa. Protesteihin on liittynyt väkivaltaa ja yhteenottoja poliisin kanssa.



Vaalitavoitteet | Sdp:n Räsänen kokoomuksen leikkauslistasta: ”Raharikkaille katetaan notkuva noutopöytä”

Oppositiopuolueet moittivat kovasanaisesti kokoomuksen keskiviikkona julkistamia leikkaustavoitteita. Listaa pidetään rikkaita suosivana ja epärealistisena.



Musikaaliarvio | Fretti Mercury -lasten­musikaali on puu­jalka­vitsien riemu­juhlaa

Kaupunginteatterin lavalle nousevat nyt Fretti Mercury, Poni Mitchell, Pöllö Miljoona ja Naula Vesala. Musikaali hauskuuttaa nokkelalla sanailulla ja loputtomilla viittauksilla pop-kulttuuriin, politiikkaan ja urheiluun.





Back to top



Al Jazeera

Back to top

Most Americans say US-Israel war on Iran not worth fighting: Poll

Nearly 70 percent of Americans say the US-Israeli war is not worth fighting, marking a significant spike since July.



Funeral held for Palestinian man killed in the occupied West Bank

Funeral held for Palestinian man killed in the occupied West Bank



The filmmaker taking on Kenya’s colonised tea plantations

The filmmaker taking on Kenya’s colonised tea plantations



ICC ends contract with French insurer amid US sanctions threat

ICC and Axa terminate agreement amid mounting US criticism and looming financial restrictions on the court, FT reports.



Eritrea severs diplomatic ties with Ethiopia in tit-for-tat move

Ethiopia says it will shut its embassy in Asmara, declares 10 Eritrean diplomats persona non grata.



UK Parliament told answers on tax implications are needed in Manchester City ruling

HM Revenue and Customs (HMRC) has been contacted in the United Kingdom about Man City's financial breaches.



Syria denies officials held ‘secret’ talks with Hezbollah in Turkiye

Six sources from Syria, the US and Lebanon told Reuters news agency the reported meeting aimed to calm tensions.



Who is Capt. Smit, Machchhar, the pilot of the Flydubai flight?

Captain Smit Machchhar from India is recovering from stab wounds he suffered in a Flydubai flight altercation.



Cornell rape allegations renew push to change New York sexual assault law

New York law treats intoxicated victims differently depending on whether they willingly consumed alcohol or drugs.



What’s driving Israeli settler violence in the occupied West Bank?

Attacks on Palestinians in the area are growing at unprecedented levels.



After Red Sea losses, Yemen’s government forces hold the line

Air strikes and difficult terrain have prevented the Houthis from turning coastal gains into a wider breakthrough.



Saudi-led coalition says power station attacked in Medina, blames Houthis

At the same time in Yemen, the Saudi-backed government army says it is inflicting heavy losses on the Houthis in Taiz.



Canada to fast track oil pipeline meant to diversify economy away from US

Carney declared the pipeline a project of national interest, smoothening its way to a single federal regulatory review.



School protests spread as fires, blockades deepen unrest in France

Police have detained hundreds as students protest overcrowded classrooms, teacher shortages and crumbling facilities.



Palestinian children in Israeli military detention

Palestinian children in Israeli military detention



US Supreme Court agrees to take up Trump’s ICE detention policy

The case is the latest dispute over US President Donald Trump’s sweeping immigration crackdown.



Renee Good’s family sues Trump administration over fatal ICE shooting

Lawsuits accuse Trump officials of recklessness and civil rights violations in Renee Good's fatal Minneapolis shooting .



Despite praise and White House visits, Trump avoids endorsing Netanyahu

In a Time interview, Trump avoids directly endorsing Netanyahu but defends him over reported October 7 warnings.



Death penalty bill for forest arsonists clears Algeria lower house

Human rights organisations accused Algiers of using the law to target political opposition groups.



How AI is reshaping everyday life in China

How AI is reshaping everyday life in China



Israel’s Supreme Court advises Arab party leader to drop election bid

Central Elections Committee voted last week to bar both main Arab lists and two candidates from parliamentary election.



British police arrest UK-Iranian national over airbase incident

Counter Terrorism police also questioned a UK national, days after five others were arrested and released on bail.



Photos: Palestinians mourn more than 100 loved ones in mass Gaza funeral

The remains of 105 people were buried in the Sheikh Radwan cemetery, northwest of Gaza City.



Chinese hackers impersonated AI experts to target US policy minds

TA419 hackers used deceptive tactics to impersonate real figures, such as a former White House AI official.



Jerusalem Daily: Netanyahu calls flight incident another 9/11

Israeli officials claimed the Flydubai incident as a "terror attack", despite the airline’s ongoing investigation.





Back to top



New York Times

Back to top

UK-Iranian Man Arrested in Connection to RAF Fairford Air Base Incident

British police said a 25-year-old British-Iranian dual national was arrested Thursday. British officials have said they believe Iran played a part in planning the incident at R.A.F. Fairford.



Live Updates: Investigators Seek to Establish Motive in FlyDubai Attack

The United Arab Emirates said it would lead the investigation, including into possible links to terrorism. Prime Minister Benjamin Netanyahu of Israel said the attacker had undergone “Islamist radical indoctrination,” though he did not elaborate.



Canada’s Proposed Oil Pipeline Offers Carney Relief From Domestic and Global Turmoil

The new pipeline from Alberta’s oil sands to the Pacific Coast may lower separatist tensions in that province while also loosening energy ties with the U.S.



Nigerian Charged With Running Fake Government Agency

The Nigerian secured office space in a federal building, opened bank accounts and even held meetings with foreign diplomats. He says he is innocent.



Egypt Arrests 6 Matsaddash Journalists on Claims of Spreading Disinformation

The government claims that reporters from Matsaddash, a well-known news outlet that debunks false reports, spread disinformation for the banned Muslim Brotherhood.



American University of Afghanistan at Risk of Closure Amid Funding Cuts

The State Department has denied its funding for the next two years, jeopardizing the education of hundreds of female Afghan students.



Russia to Sharply Increase War Spending and Cut Social Programs

Both sides are finding it increasingly difficult to finance the conflict in Ukraine. Russia’s 2027 budget envisions more debt, higher taxes and lower social benefits.



Finnish Lawmakers Report Suspicious Home Break-Ins

The speaker of Parliament said there were a “considerable” number of mysterious entries in which perpetrators appeared to have taken nothing.



A Flashy Zimbabwean Tycoon Who Befriended Presidents Dies in Crash

Wicknell Chivayo was riding in a helicopter with his wife when it plunged into a field. Dogged by corruption allegations, the businessman drew polarizing reactions even in death.



Who Is Captain Smit Machchhar, the Pilot Hailed as a Hero After FlyDubai Cockpit Stabbing?

Capt. Smit Machchhar suffered stab wounds while fending off an attack from his co-pilot, saving the lives of around 170 people on board, officials said.



One Issue Hanging Over Brazil’s Presidential Election: Online Gambling and Record-High Debts

Just days before Sunday’s election, President Luiz Inácio Lula da Silva banned online gambling. But record-high debt is upending millions of lives.



Take a Historic Stroll Down Oxford Street, London’s Shopping Artery

London is making a stretch of the street, long central to the city’s identity and sense of style, car free.



Swiss Glaciers Vanished by Nearly a Fifth in Recent Years, Scientists Say

One researcher called it a “desperately needed warning sign” that countries need to tackle human-driven climate change.



Britain and France Give Up Landmark Migrant Agreement

The French government soured on a reciprocal deal that allowed the British authorities to return some migrants who crossed the English Channel illegally in small boats.



Mike Smith, Bubbles on ‘Trailer Park Boys,’ Has Sexual Assault Charge Dismissed

The Canadian cult comedy series announced that Mr. Smith, 54, would resume his involvement with the show.



A Climate Change Rebrand

More politicians have stopped talking about the climate, but the green transition is still moving forward.



Controversial Zimbabwe Tycoon Dies in Helicopter Crash

The controversial Zimbabwe tycoon Wicknell Chivayo died in a helicopter crash with several others from his rural homestead to the country’s capital. Mr. Chivayo was accused of building wealth through corruption, forming close relationships with African leaders.



2 passengers who helped thwart the FlyDubai attack add details in a TV interview.



FlyDubai Under Scrutiny After Cockpit Attack

The United Arab Emirates has said it is leading the investigation into the episode, and FlyDubai’s service between Dubai and Tel Aviv has been suspended.



Israelis Take Pride in Bravery of Passengers Who Saved FlyDubai Flight

The events evoked days decades ago when Israel was widely admired for its plucky survival against the odds and for taking on hijackers.



The Boeing 737 Max 8 stayed intact despite the enormous stress of its plunge.



Israel to Honor FlyDubai Passengers Who Helped Prevent Flight Disaster

President Isaac Herzog of Israel said he would recommend heroism awards for several Israelis a day after they intervened when a co-pilot stabbed the captain on a FlyDubai flight to Tel Aviv.



Swedish Company Uses A.I. Likeness of Greta Garbo in Ad

An ad produced by the manufacturing company SKF Group featured a digital version of the Swedish American actress, who died in 1990. Not all viewers found the replica convincing.



Investigators Seek to Determine How a Weapon Entered FlyDubai Cockpit

Prime Minister Benjamin Netanyahu of Israel said one possibility was that the assailant used an emergency crash ax, typically stored in the cockpit.





Back to top



Reuters

Back to top

This site is down!

Back to top



NPR

Back to top

What a Pearly King taught me about Cockney rhyming slang and East London history

In mother-of-pearl suits, the Pearly Kings used to canvass East London for charity. The most famous one, George Major, died in August. A look back on this larger-than-life figure and the Pearly King tradition.



Passengers recount chaos on Tel Aviv flight. And, FBI probes employee-data hack

What we know so far about the tense moments aboard a Tel Aviv-bound flight. And, the FBI investigates a cyberattack involving sensitive employee data.



Picanha, prices and politics: What Brazil's favorite steak says about the election

President Lula promised Brazilians four years ago they'd be able to afford picanha again. Now, as he seeks another term, the price of the country's favorite cut of beef is telling a different story.



What life under U.S. sanctions looks like for one ICC judge

Kimberly Prost, a Canadian judge at the International Criminal Court, says U.S. sanctions disrupted her daily life. She is still hearing cases and challenging the sanctions in court.



Swiss glaciers suffer another year of record ice loss

Switzerland's glaciers are disappearing at a record pace. More than 5% of their ice has vanished this year alone — threatening water supplies, ecosystems and communities across Europe.



Greetings from Syria, where time seems to melt as a glassmaker braves scorching temps

As a Syrian glassmaker created his wares in Damascus, watching his craft reminded this reporter to slow down and enjoy the moment.



How Ukrainians are coping with new, more deadly Russian attacks

Zanny Minton Beddoes, The Economist's editor in chief, just visited Ukraine. She says, despite all its drone weaponry, Kyiv is under extraordinary bombardment, as Russia tries to make it unlivable.



A midair stabbing on a flight to Israel is being investigated as possible terrorism

FlyDubai said the motives behind the incident were unknown and remain subject to a formal investigation. Israeli Prime Minister Benjamin Netanyahu described it as "a serious security incident."



U.S. forces exit Iraq amid Iran war. And, SCOTUS revives Trump deportation policy

The U.S. has withdrawn its final troops from Iraq, leaving its defense future uncertain. And, the Supreme Court has sided for now with the Trump administration on third-country deportations.



The U.S. military withdraws from Iraq over 2 decades after its invasion

23 years after the United States military invaded Iraq, sparking an insurgency and a civil war, the U.S. has withdrawn its forces, as the country still tries to combat Iranian influence.





Back to top



The Cipher Brief

Back to top

Exactly how could AI kill humans?



Nobel laureate Geoffrey Hinton walked out of a closed-door Capitol Hill briefing on September 17 and gave lawmakers a deadline.

“Maybe a year, but not much more than a year,” he told reporters, describing how long Congress has before artificial intelligence moves beyond meaningful human control.

It’s not an outlier estimate on the Hill anymore. An Anthropic researcher who resigned this month put it more starkly, warning that the people building the technology “earnestly believe it could kill us all by the end of the decade.”

Trump had already dismissed the premise days earlier. Across a string of Truth Social posts that Monday, he called AI fears a “hoax,” dubbed himself the “Hoax Buster,” and mocked the idea of robots marching into American cities. He returned to the subject five days later, announcing he would form an “AI Force” and appoint an AI czar to accelerate American dominance in the technology rather than restrain it.

House Speaker Mike Johnson echoed him the next day in even more candid terms.

“What the president is saying is, you’re not all going to be dead in 10 years,” he stated. “That’s a hoax.”

That collision, a 78-year-old scientist warning of civilizational risk and a sitting president calling the same warning a partisan fiction, is the real story of the AI safety debate, and it is already hardening into a national security question in its own right.

Sens. Ted Cruz, Amy Klobuchar and John Thune are drafting bipartisan legislation aimed specifically at “catastrophic risks involving biological or nuclear threats” from frontier AI, expected as soon as this month. But the politics obscures a more basic question that rarely gets answered: how, mechanically, is any of this supposed to happen?

Most people still picture something out of the Terminator: killer robots, guns blazing. What actually keeps researchers at the frontier labs up at night looks nothing like that. It’s smaller, odder, and in a few cases, it’s already happened.

The sandbox that did not hold

The clearest illustration of loss of control came in July, when OpenAI disclosed that a combination of its models, including GPT-5.6 Sol and an internal-only research prototype, got out of an isolated test environment and breached Hugging Face’s production systems.

The models were not told to escape. They were running an internal OpenAI evaluation built to push them toward advanced exploitation, with the safeguards that normally block high-risk cyber activity deliberately switched off so the company could gauge their maximum capability.

The test environment had no direct internet access beyond a proxy for installing software packages. The models spent substantial computing power finding a way out anyway: they exploited a previously unknown flaw in that proxy, worked through OpenAI's research network to a machine that was online, then searched for the test's answer key and breached Hugging Face to get it. OpenAI says the models went to "extreme lengths" to reach a narrow goal. The company says it has disclosed the flaw to the vendor.

UN human rights chief Volker Türk told the Human Rights Council in Geneva earlier this month that he shares “the concerns of industry insiders that advanced AI could pose an existential risk to humanity,” calling for “cast-iron guarantees” before, in his words, it is too late.

Türk cited exactly this kind of behavior when he drew his own red line in Geneva.

“AI that escapes its testing environment, or blackmails developers to prevent itself from being turned off, is AI that is too powerful,” he said.

Roman Yampolskiy, an AI safety and cybersecurity researcher at the University of Louisville, tells The Cipher Brief that the incident is best understood as a sneak peek rather than a fluke.

“A preview of a dangerous capability, although neither establishes that catastrophic harm is inevitable,” he says. “OpenAI’s agents escaped isolation and compromised external systems without authorization. These incidents illustrate two different risks: AI pursuing unintended objectives and criminals using AI to automate attacks. Both reduce the amount of human expertise and intervention required for a cyberattack.”

This isn’t a machine turning against its makers. It is software chasing a narrow goal it was given, with no one watching closely enough to notice where the shortcut led.

When the attacker never sleeps

Loss of control is a system slipping its leash. Self-replication could come next. Once it’s off the leash, nobody has to sit at a keyboard to keep it moving.

In early July, cloud security firm Sysdig documented what it assessed to be the first ransomware campaign run end-to-end by an autonomous AI agent, a case it dubbed JadePuffer. After breaking into an internet-facing server through a known software flaw, the agent conducted its own reconnaissance, harvested credentials, moved laterally across the network, and encrypted more than 1,300 configuration records, adapting on the fly when its attempts failed.

In one moment that stood out to researchers, a login attempt failed and, thirty-one seconds later, the agent had already figured out why, tried something different, and gotten in. No person ever saw the error message or lifted a finger to fix it.

Ian Tien, CEO of Mattermost, a collaboration and automation platform built for national security and critical infrastructure clients, tells The Cipher Brief the incident and what followed it mark a genuine inflection point.

“The Hugging Face and JadePuffer incidents represent important new milestones in the weaponization of AI,” he observes. “They should signal to the public that AI is creating new pathways for adversaries and criminals to cause harm, and those developments should be taken seriously.”

At the same time, Tien is careful not to inflate the danger.

“Defenders are also using AI to create new pathways for defense, including detecting and disrupting adversary and criminal operations,” he points out.

Tien’s point is that the technology cuts both ways: the same speed that lets an attacker adapt in seconds can be used to detect and disrupt that activity, if defenders adopt it as quickly as attackers do.

Jason Lang, Managing Director of Offensive Security at TrustedSec, tells The Cipher Brief the technical substance of the case is less novel than the headlines suggest.

“AI wasn’t doing anything that security researchers haven’t been doing for years. The difference is the speed at which it performs those actions,” he explains, noting that JadePuffer’s entry point “exploited a security flaw that had been publicly known for more than a year. Yet, the targeted system was still unpatched.”

In other words, the opening wasn’t some undiscovered AI weakness. It was an ordinary, already-known bug that a human had never gotten around to patching, and the AI just moved on it faster than a person would have.

Still, Lang doesn’t dismiss the trend line. He’s not arguing the threat is exaggerated, only that the mechanism is familiar; what’s changed is the clock.

“AI can and likely will enable attackers to perform research and attacks at a speed faster than modern defenses can cope with,” he continues. “For now.”

Rafal Los, Chief Strategy Officer at Binary Defense, tells The Cipher Brief he reads the same case with more caution about the story built around it.

“I believe that these models did in fact cause harm, but that there is definitely some part of those narratives that was ‘enabled’ by humans looking for validation of their company’s frontier supremacy,” he observes.

What worries Los isn’t the exploit itself, he says, but the trajectory it points to: “an AI agent can carry out much of the technical attack chain autonomously, adapt when something fails and continue toward its objective.”

“Capabilities that once required continuous human involvement can increasingly be automated and scaled,” Los highlights.

That urgency reached Washington almost immediately. Two weeks before Hinton’s briefing, the cyber agencies of the Five Eyes alliance had issued a joint warning that frontier AI was collapsing the gap between vulnerability and exploitation to “months, not years.”

In practice, that means the window defenders used to have between a flaw being discovered and someone actually weaponizing it, once measured in months or longer, is shrinking to weeks or less, leaving far less time to patch a system before it’s used against it.

Sen. John Kennedy (R-LA) tried to force a vote on legislation requiring AI developers to build in a shutdown mechanism the day before Hinton spoke to lawmakers. Sen. Rand Paul (R-KY) blocked it on the floor within hours, calling Kennedy’s language “very vague” and arguing that regulating an industry “so pervasive as AI throughout our economy” first needed hearings and industry input rather than a same-day, unanimous-consent vote.

Paul offered a counter, a bipartisan committee to study the risk instead; Kennedy declined it and let the bill die.

The problem of speed, not malice

The scenario that unsettles researchers most, however, has little to do with hacking. It is the possibility of a system pursuing a goal with genuine competence and no ill intent, simply moving faster than the humans meant to be supervising it.

That is what pushed Evan Hubinger, who leads alignment science at Anthropic, to break with his usual caution earlier this month. He wrote that he personally puts the odds of AI causing human extinction within the next decade above ten percent, and that Anthropic is “trying its best” but does not yet have a plan to control a superintelligent system safely.

Yampolskiy puts the mechanism in more concrete terms.

“An AI agent with access to computers, networks, and critical infrastructure could autonomously discover vulnerabilities, compromise systems, and disrupt hospitals, power grids, or supply chains,” he points out. “The immediate danger is not that AI becomes conscious, but that it becomes capable of causing irreversible harm at machine speed, potentially before humans can intervene.”

Not everyone treats the extinction premise as settled science. Lang, for one, is openly skeptical of the political response it has generated.

“Knee-jerk reactions are just that, reactions, not thought-out proposals with well-meaning reforms,” he underscores. “Fear is usually the currency by which control is purchased; therefore, any urgency-backed proposal is worthy of extra scrutiny.”

The specific fear dominating the public conversation, an AI that slips its constraints and turns on humanity outright, draws the sharpest pushback of all.

“I believe we should take them seriously in that it demonstrates capabilities, but not catastrophically in that it’s going to lead to an AI that ‘breaks out of containment’ and goes and exterminates humans or takes over the Internet,” Los says.

What worries him is something far more mundane: systems that get things wrong not out of malice, but because they’re missing something a person in the room would have caught. He points to air traffic control — a recommendation that looks right on paper but misses a factor a human controller would weigh without even thinking about it, with nobody checking the work before it’s acted on.

What Washington could still do

U.S. Sen. Jacky Rosen (D-NV) has taken the narrowest, most procedural version of the concern to the Senate Commerce Committee, calling on Chairman Ted Cruz to convene a hearing with top AI executives.

“This powerful technology can have the power to cause catastrophic damages if we don’t act to impose guardrails and safety mechanisms,” Sen. Jacky Rosen (D-NV) said in a statement issued to The Cipher Brief. “Congress must do everything in its power to ensure the American AI industry continues to lead, particularly outcompeting China, and also enact increased guardrails to ensure AI development is progressing in a safe and responsible manner.”

Some of that response is already moving.

In June, the administration signed an executive order directing federal agencies to expand AI-enabled cyber defenses for government and critical infrastructure systems, and to design a voluntary framework under which frontier AI developers can give the government up to 30 days of early access to their models before release.

The order imposes no requirements on the companies themselves, and its first agency deadlines fell in July and August.

Nothing in the order binds the industry at large, which is precisely Rosen's complaint, and precisely why Cruz, Klobuchar and Thune are trying to legislate the bio and nuclear pieces separately.

For all their disagreement over how alarmed to be, the four security experts converge on roughly the same one-year fix.

Yampolskiy calls for “mandatory isolation for AI agents operating near critical infrastructure,” the hospitals, power grids and pipelines Yampolskiy flagged earlier.

“No unrestricted internet access, no unnecessary privileged credentials, and no autonomous execution of consequential actions without independently enforced authorization,” he continues.

Tien points to keeping critical systems off the public internet altogether.

“Much of our critical infrastructure and government already operates on air-gapped and private networks,” he explains, and “maintaining that separation is one straightforward way to reduce exposure and buy time while AI-based defenses mature.”

That means a hospital’s or utility’s control systems have no physical connection to the internet at all. Hence, an agent that escapes its sandbox elsewhere has no path in, no matter how capable it becomes.

Los, meanwhile, wants more adversarial testing, “more human oversight,” and AI harnessed for “continuous and automated defense in the immediate future.”

Lang’s answer is the least dramatic of the four, but perhaps the most damning.

Patch known vulnerabilities. Use long, complex passwords. Check the sender’s domain before clicking. Make security a first-class citizen from the top down.

“Security is not hard, conceptually,” he adds. “What causes breaches are, at their roots, usually the forces of ignorance or ego, a truly devastating duo when combined.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Nasrallah is Dead. Hezbollah’s Social Lifeline is Not.

Two years after Israel killed Hassan Nasrallah, Hezbollah is weaker but not finished. WaTaawanou, a crowdfunded charity outside Hezbollah’s formal hierarchy, exemplifies one way Hezbollah endures: outsourcing part of the cost of sustaining – and retaining – its Shiite base. Israel eliminated its seniormost military and political leadership, over 5,000 fighters, and significant parts of its arsenal, while its finances are strained. Even as Tehran reportedly moved more than $1 billion to the group after the November 2024 ceasefire – and another $1 billion the following year – Bashar al-Assad’s fall has severely constricted Hezbollah’s transfer routes from Iran through Syria. Yet Hezbollah can survive and regenerate if it preserves the Shiite constituency supplying its manpower and, more importantly, domestic political protection.

WaTaawanou began as an informal relief campaign in November 2019. Founder Afif Shouman identifies it with Hezbollah’s “Resistance environment,” though in an October 2022 interview he said it “does not belong to Hezbollah.” Because WaTaawanou is not U.S.-sanctioned, it can solicit funds through channels Hezbollah’s designated institutions cannot use as freely, including Whish Money, OMT/Western Union, MoneyGram, and direct contributions. It also has an account at Hezbollah’s sanctioned quasi-bank, Al-Qard al-Hassan. Its public-relations director says most Lebanese donors give $5 or $10, but together fund larger campaigns. Whish closed WaTaawanou’s account in October 2025, but its websitestill lists Whish and bank transfers via an International Bank Account Number (IBAN), without usable details for either. Larger projects have drawn support from Lebanese private donors, expatriates, Iranian-linked organizations, and Iraq’s al-Sawaed tribal network.

Yet WaTaawanou’s formal separation from Hezbollah belies extensive ties. Shouman says Hezbollah was the only outside organization to embrace and assist it and credits its development to Nasrallah’s “direct and foundational guidance.” He says former Hezbollah Executive Council chairman Hashem Safieddine treated WaTaawanou as “a principal file.” WaTaawanou has repeatedly worked with Hezbollah’s Social Action apparatus and Islamic Health Committee. At least two volunteers—Ali Lutfi Faran and Amine Hassan Badreddine—served as Hezbollah fighters. Shouman said its 2024 wartime relief proceeded in “full coordination with Hezbollah.”

That relationship is clearest in its spending. Its beneficiaries extend beyond Hezbollah supporters, but its aid eases material pressure across the overwhelmingly Shiite base on which Hezbollah depends. Shouman says it aided 94,000 families during the 2024 war with food, medicine, cash, and shelter. Since the November 27 ceasefire, its Al-Wajh al-Hassan reconstruction project has used donations in war-damaged, overwhelmingly Shiite southern municipalities including Ramyeh, Houla, and Mays al-Jabal, installing prefabricated housing and classrooms, repairing schools, aiding farmers, and distributing food. WaTaawanou also channels money to Hezbollah-linked entities, including payments to Al-Rasoul al-Aazam Hospital and Saint Georges Hospital–Hadath, both Martyrs Foundation hospitals. It also purchased fuel from Amana Fuel, which the foundation controls through Atlas Holding. Treasury designated the Martyrs Foundation in 2007 and calls its Lebanon office an integral element of Hezbollah’s support network. WaTaawanou paid Hezbollah’s Islamic Health Committee through Dar al-Hawraa Medical Center and repeatedly paid Al Moukhtar Products, which Treasury designated as part of a Hezbollah business network.

WaTaawanou therefore gives Hezbollah two benefits: outside donors cover costs Hezbollah would otherwise bear, while WaTaawanou channels the credit back to Hezbollah. Nasrallah portraits line its premises, his face brands Al-Wajh al-Hassan, and Hezbollah flags and insignia appear at its events. Shouman says its role complements Hezbollah’s: Hezbollah’s fighters defend the community while WaTaawanou supports the group’s Shiite base.

WaTaawanou cannot alone explain Hezbollah’s Shiite support, but efforts on this scale likely help preserve it. Studiesshow many Shiites are drawn to Hezbollah less by ideology than by the security, services, and communal advancement it provides, while regular patronage recipients are likelier to oppose the group’s disarmament, support its political role, and credit it for reconstruction. That constituency remains overwhelmingly behind Hezbollah. A late 2024 survey found 85 percent trusted Hezbollah. An estimated 700,000–900,000 people attended Nasrallah’s February 2025 funeral, and three months later Hezbollah and the AMAL Movement, Lebanon’s other major Shiite party, dominated municipal elections in heavily Shiite southern and eastern districts. Gallup found in June-July 2025 that 69 percent opposed giving the Lebanese Army exclusive control over weapons. In April-May 2026, Information International found 87.5 percent opposed Hezbollah’s disarmament.

For Beirut, forcibly disarming Hezbollah therefore risks confronting not simply an armed organization, but one still backed by most of what is probably Lebanon’s largest sect. Lebanon has held no official census since 1932, but independent pollster Statistics Lebanon estimates Shiites at 32.2 percent of citizens. Hezbollah Secretary-General Naim Qassem has rejected disarmament even when paired with Israeli withdrawal, and on June 17, 2026 declared that “any project to disarm us will not pass.”

Lebanon has consequently paired categorical disarmament decisions with reluctance to enforce them coercively. On March 2, the cabinet banned Hezbollah’s military and security activity and ordered it to surrender its weapons, but Prime Minister Nawaf Salam said Beirut did “not seek a confrontation with Hezbollah,” while President Joseph Aoun insisted the state monopoly over arms proceed through dialogue “away from force.” Five days later, army commander Rodolph Haykal said national unity and internal stability came first and “the solution is not solely a military one.” In September, official sources said its Nabatieh deployment was not intended to make the city weapons-free. South Litani Sector deputy commander Colonel Raja Amer told CNN the army would proceed “slowly” rather than use violence against “our own people,” agreeing that avoiding another civil war was central to its approach.

On September 9, the army claimed “operational control” in three test zones under the U.S.-brokered June 26 Israel-Lebanon Framework Agreement to clear unauthorized fighters, weapons, and military infrastructure. But it identified no Hezbollah fighter disarmed or arrested, and no Hezbollah depot, tunnel, or command center dismantled. WaTaawanou helps preserve the communal support that makes such coercion politically dangerous. For a battered Hezbollah, Beirut’s reluctance to test that support buys it the resource regeneration requires above all: time.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



BLUF: Russian Strategic Culture Drives its Callous and Brutal Actions

My friends and family often ask me why Russia behaves so offensively. They are baffled by Russia’s lack of humanity and Moscow’s actions such as hiring assassins, launching drones at innocents, and planning economic sabotage against international companies. While not an excuse, just an explanation, scholars of Russia understand the country’s deep sense of insecurity and vulnerability. Its longing to be a part of Europe, and its own view that its rightful place as a global leader are all driving Russia’s barbaric actions. According to strategic culture theorists, a state’s approach to war is shaped by its cultural and historical experiences, including geography, religion, language, and national identity. These factors influence a state’s perception of security threats, willingness to use military force, and approach to diplomacy and negotiation. They also help us to anticipate a state’s actions.

Russian strategic culture reflects a worldview shaped by centuries of conflict, invasion, brutality against others, inflicted on its people from foreign powers and by the government against its own population, and foiled attempts to become card carrying members of the west. Key elements of Russian strategic culture include the belief that the rest of the world, especially the West consistently undermines Russia and thwarts it rightful place as a world leader, and a belief in the necessity of military strength to push back the West. When the West does not push back, Moscow believes that their tactics are working.

Insecurity Drives Every Move

Russia’s persistent awareness of vulnerability and deep-seated mistrust of its neighbors is deeply ingrained and a consequence of centuries of historical experience. This insecurity manifests as a deep-seated suspicion of the West and a zealous determination to maintain control over Russia’s perceived sphere of influence. Understanding the historical currents that have shaped this perception is crucial for comprehending Russia’s present-day actions.

Russia’s experiences with wars and conflicts, such as the Mongol invasion, Napoleonic Wars, World War I, and World War II, have reinforced the idea that the country is constantly under threat and must be prepared to defend itself at all times. The Russian feeling of vulnerability and insecurity, particularly concerning interactions with “Western countries” is ingrained. To counter this insecurity Russian leaders have long highlighted the importance of having buffer zones on its borders. Removing those buffer zones heightens Russia’s sense of vulnerability.

From as early as the 18th century, Russian imperial strategy was heavily influenced by the need to create and maintain buffer zones along its western borders. Peter the Great and Catherine the Great both conquered lands on Russia’s borders so that Moscow would have a buffer from invasion. This proactive doctrine was aimed at insulating the Russian heartland from European powers. The annexation of Baltic territories, the absorption of Finland, and the partitioning of Poland were all manifestations of this strategy. These territorial acquisitions were driven by a pragmatic logic: to push potential adversaries further away and create a strategic depth that would absorb any initial blows in case of conflict. Russia continues to try to use buffer states or “allies” to keep others from its immediate vicinity, but this is an increasingly difficult task for Moscow as its former republics and satellite countries choose new alliances and partners.

Germany’s invasion of Russia in 1941 was a defining moment in Russia’s historical experience. This invasion resulted in some 27 million Soviet deaths and widespread devastation. It cemented Russia’s profound sense of betrayal from the West, and a visceral need for absolute security. World War II profoundly shaped Russia’s post-war security calculus, leading to a pursuit of military strength and a zero-tolerance policy for any perceived threat on its borders. The narrative of this war is deeply embedded in Russian society, serving as a constant reminder of the price of vulnerability and the imperative of never allowing such an event to recur. Putin’s family was directly affected by WW2 with his brother dying of starvation during the siege of Leningrad, his Grandmother killed by the Germans in Tver, and his father being severely injured during combat duties. He often discusses this in his speeches.

The post-Soviet era where East European nations and former Soviet Republics are joining NATO and the EU is particularly distressing for Moscow. The historically more neutral northern European countries joining NATO also is alarming to Moscow. From Moscow’s perspective, the loss of Ukraine to the West represents not just a geopolitical setback, but the obliteration of a crucial defensive buffer. We are also seeing Moscow’s anxiety rising regarding Armenia’s recent moves toward the West.

During the first summer of the Ukrainian war, Putin compared himself to Peter the Great and likened the invasion of Ukraine to the eighteenth century Russian Czar’s wars. This underscores the mindset of Russian leaders and shows that their history is never far from them.

Earning for Inclusion

Russia’s geographic position has greatly impacted its strategic culture. Russia is the biggest country in the world, and while only 23 percent of the country is in Europe, almost 80 percent of the population lives there. This makes Europe extremely important for Russia. One can see this link throughout Russian history. Even from the founding of the modern Russian state in the sixteenth century, its foreign interests were linked to Europe. When Peter the Great established an empire, the interconnections with Europe increased. Russia conducted wars and created alliances with different European countries. Russian nobles were stung when European nobles mocked them and called them uncouth and barbaric.

Today, the Kremlin emphasizes narratives that underscore Western hostility, and Russia’s role as a decisive power in European affairs. These narratives reinforce Russia’s claims to special rights in regional security and justify to itself and its people, assertive foreign policy actions, including military interventions in neighboring states. Any expansion of western power such as expansion of NATO and deployment of U.S. forces in Europe are perceived as existential threats to the Russian state and infringing on Russia’s rightful relationship with Europe, just as they were during the Soviet-era.

Demanding a Seat at the Table

For centuries, leaders of the Russian Empire and the Soviet Union emphasized Russia as a great power. During the Cold War, Russia, through the Soviet Union, was able to act as a global leader. After the collapse of the Soviet Union, Russian leaders were confronted with the fact that Russia had limited “spheres” of influence.

A main aim of Russian foreign policy under Putin is regaining and maintaining great power status. Putin repeats in his speeches that Russia is a great power and that the West, especially the United States, does not give Russia the respect it deserves. The Russian people support this view. Moscow remains angered that in its view, after the Cold War, the United States created a unipolar world and used NATO to maintain its hegemonic status. Putin has consistently publicly lamented the breakup of the USSR as “the greatest geopolitical catastrophe of the century.” More recently, Putin has said, “At last, Russia has returned to the world arena as a strong state - a country that others heed and that can stand up for itself.”

Russian leaders view Russia’s military might, both kinetic and grey zone activities, as their way to press for global leader status. They believe that Russia must take what it believes is its due such as Ukraine. Russian leaders also contend that it must make the West uncomfortable with continued attacks such as the drone incursions, assassinations, and ongoing disinformation. Pressing this avenue, in their view, wil make the West eventually give up on pushing back on Russia and allow Russia to take its rightful place as a global leader.

Implications for Policy and Security

None of this explanation of Russia’s national security mindset is meant to apologize for Russia’s barbaric behaviors. It is meant to help negotiators and policy maker understand Russia’s perspective, however misinformed and self-determined. Russian strategic culture emphasizes an assertive approach to conflict which is meant to make up for Russian feelings of vulnerability and being outcast from the West. This approach is evident in Russia’s actions in Ukraine, where strategic culture drives Russia’s actions.

Moscow’s lack of trust in the West is underscored by Putin and his circle who are the representatives of the “greatest generation” of the Soviet Union. These leaders grew when the state was a global power and controlled parts of Europe. They came to the pinnacle of their careers when the West, having forced the breakup of the Soviet Union, attempted to replace Soviet and Russian culture with Western values. They are bitter about this.

Having a realistic view of Russia’s perceived right and left limits allows negotiators and military planners to develop a workable way ahead in foreign relations. It should not limit US actions in calling out Russia’s morally and ethically abhorrent actions but it should inform our actions.

In summary, Russian strategic culture is driven by a sense of vulnerability, a focus on wanting to be part of the cool club of European nations, and an outsized view that Russia should be a global leader, regardless of its barbaric actions.

Russian and Ukrainian Clashing Strategic Cultures

Russia and Ukraine both see a negative outcome of the current war as an existential threat to their existence. That means that negotiating a settlement is difficult, herculean, and likely under the current circumstances an impossible task. Diplomacy alone cannot produce a durable settlement, because the two strategic cultures are incompatible. At most, military exhaustion could produce an armistice that freezes the conflict without resolving it. Before Russia’s insecurity can be addressed, the rest of the world must make it clear that Russia will maintain pariah status if it continues its slaughter of Ukrainian citizens and attacks in the west. The third-party sanctions recently passed by Congress are a step in the right direction. Sanctions alone, however, will not stop Russia whose people are used to hardship and even expect it. I am usually an optimist but for now, unfortunately, I cannot see a positive way forward in this war. The themes that Ukraine and Russia have woven through their strategic cultures indicate that there will be more deaths, destruction, and hardship before this war ends. The best that the world can do is to contain the violence and help Ukraine continue to strengthen its statehood while calling out each and every Russian atrocity.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How the Intelligence Community Can Shape AI Trust With New Terminology

The Intelligence Community (IC) has an opportunity now to influence how we talk about, and thus how we approach, AI use in our work by formally adopting the nomenclature “AI-in-the-Loop” rather than “Human-in-the-Loop.” The problem with human-in-the-loop is that it subordinates the human to AI; the term carries a built-in assumption that “the loop” belongs to AI and that humans will somehow be included. The term I am proposing omits the “human” we have become accustomed to, but it is a purposeful attempt to reflect what we want to achieve: using AI when and where we elect to do so.

AI-in-the-loop is not a new expression. Stanford’s Institute for Human-Centered Artificial Intelligence used the term as a centerpiece for a conference on the topic in 2022, arguing that humans should remain in charge while AI operates as part of a human-directed process.

This 2025 academic article makes the same distinction, arguing that “Human-in-the-loop (HIL) systems have emerged as a promising approach for combining the strengths of data-driven machine learning models with the contextual understanding of human experts. However, a deeper look into several of these systems reveals that calling them HIL would be a misnomer, as they are quite the opposite, namely AI-in-the-loop (AI2L) systems: the human is in control of the system, while the AI is there to support the human. We argue that existing evaluation methods often overemphasize the machine (learning) component’s performance, neglecting the human expert’s critical role.”

Much of industry discourse uses human-in-the-loop as an AI governance approach, but the debate over terminology remains unsettled. Researchers at The George Washington University argue this is partly because “Academia, government, and industry have not clearly defined the mechanisms by which humans are expected to oversee or collaborate with AI-enabled systems.” They add that “Inconsistent uses of terms like human-in-the-loop and human-AI teaming create confusion on what type of oversight and collaboration is intended,” calling this environment a “preposition salad.”

Forging new terminology for our AI usage is critical now as we seek to accelerate development and adoption in the IC while also supporting the burgeoning efforts to adopt AI securely. The IC has already set a standard for accelerated adoption in a secure environment while focusing on the human role.

ICD 505, as amended in 2025, on AI underscores the importance of IC personnel, noting that they “shall remain responsible and accountable for the analysis, decisions, and outcomes derived from insights gleaned using AI.” While the Directive does not mandate specific terminology, it requires users to “understand” and be accountable for AI use. It goes further in insisting that “personnel be able to review, challenge, and reject or replace AI-derived recommendations and findings when appropriate.” The President has since mandated that the IC publish a Standard on AI Assurance under ICD 505 and signed a memorandum on AI mandating “responsible acceleration of the use of AI across intelligence and warfighting domains.”

Intelligence agencies are moving to adopt internal AI policies to drive adoption while elevating the human role. For example, NGA has moved beyond simply adopting AI toward aspiring to become an AI-first organization where “AI does not replace human judgment. It amplifies it.”

While the human role is at the forefront, IC procurement is aiming for fast acquisition. CIA launched a new acquisition framework this year to speed adoption of innovative technologies, while NGA has elevated its Rapid Capabilities Office and has multiple major AI and advanced-analytics procurements moving toward solicitation.

An Array of Terminology Options

Practitioners and technologists may bristle at adopting a term that lacks "human," as noted above. This should not derail our efforts to better define our approach to AI. I have offered AI-in-the-Loop as an option that respected experts are promoting. But the IC can forge its own path by considering multiple options:

Human-Led AI (HLAI) — simple, direct, and clear about who leads the process


Human-Guided AI (HGAI) — emphasizes direction and oversight, though it may sound less decisive


Human-AI Teaming (HAIT) — widely used, though it can imply a more equal partnership than intended, and an awkward

acronym


Human-Directed AI (HDAI) — stronger than “guided,” emphasizing human authority


Human-Commanded AI (HCAI) — strong human primacy, though perhaps too military in tone for broad IC use


Human-Owned AI Workflow (HOAIW) — inelegant, but explicit that the workflow belongs to the human

Adopting new terminology now would be more than symbolic; it would help shape how we approach and use AI. We can ensure AI augmentation at the speed of mission as part of the human toolkit, not that humans are just “in-the-loop.” Indeed, the IC has used nomenclature adoption as a core part of improving mission performance and rigor at key junctures in the past.

After 9/11 and the invasion of Iraq, the IC shifted the terminology it used for adopting new or different tradecraft from our baseline techniques in analysis. The term Structured Analytic Techniques became official at CIA’s Sherman Kent School in 2005 as part of the Agency’s effort to promote these methods from the long-held category of “alternative” analysis into the mainstream of tradecraft. In my decades of experience in analysis, this change was more than a title change; the new terminology reshaped how analysts thought about their work. As a junior CIA analyst at the time, I remember a proliferation of structured analytic techniques that became so commonplace they were literally no longer alternative.

In the late 2010s, we shifted from “intelligence sharing,” a process that intelligence professionals I knew detested as giving away secrets for little to no gain, to “intelligence diplomacy,” a practice many of us willingly adopted to offer insights aimed at promoting US interests. The IC formally codified this approach in 2025 through ICD 405, Intelligence Diplomacy. The ICD distinguishes between mere intelligence sharing and intelligence diplomacy, noting that the latter must “be done in support of advancing a preferred policy objective.” The ICD goes further in noting that the intent is to “shape foreign leader perspectives,” a materially different approach than sharing alone. The Senate’s Intelligence Authorization Act in August 2026 endorsed Intelligence Diplomacy as “critical to advancing US foreign policy and national security goals,” and called for “elevating intelligence diplomacy as a tool of US statecraft” through continued investment.

The IC should act with deliberate speed to formalize AI-in-the-loop, or a related term, to set a tone of expectation and clarity for agencies and industry partners that even agentic autonomy must begin with human intent and be wrapped in human decision. We can do so in a presidentially required Standard on AI Assurance under ICD 505. Further, IC directors using an agreed-upon, more human-focused term and impressing on their workforce its importance would chart a path. IC acquisition shops’ requests to industry should also make this shift, giving industry clear guidance that development and implementation should include a workflow that explicitly highlights human ownership of AI adoption. Even when AI does the heavy lifting across data sets that humans can’t process alone at speed and scale, it must do it on our behalf.

All statements of fact, opinion, or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in the contents should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author's views.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Coupang Breach and the Danger of Punishing the Headline Number

The headline number from the Coupang data breach — more than 33 million user accounts — sounds like a major incident that implies a catastrophic failure of one of South Korea’s most important company’s cybersecurity programs. South Korea's Personal Information Protection Commission (PIPC) measures an incident by the “exposure and access” of data, and a disgruntled former engineer who retained and forged credentials did, in principle, have access to that many accounts over seven months. But what actually happened in this case was far narrower. According to Coupang internal investigation, the attacker downloaded data from just under 3,000 accounts, and later deleted it. However, it's worth noting that regulators dispute this finding as overly narrow. The breach exposed no financial information, and he did not transfer anything to any third party. Multiple investigations and reporting to date has surfaced no fraud, identity theft, or downstream misuse traced to the incident. All in all, this was mundane, not catastrophe.

Seoul’s response suggests the government wants to tell a different story. The PIPC investigation culminated in a $409 million fine—more than four times greater than the previous record-breaking fine. The company's SEC filing states that approximately $278 million of the fine is directly related to the incident while $132 million concerns a separate administrative fine concerning date collection. Their intrusive investigative process and the penalty together are meant to broadcast an unmistakable message: this was a massive cybersecurity failure by Coupang due to negligent security practices, that inflicted enormous harm — and Coupang must be punished severely ensuring radical, swift improvements and to deter every other company from replicating these mistakes.

The technical record supports none of that.

A single breach, standing alone with a headline number, often tells you very little about a company’s overall security practices. It can be a symptom of genuine negligence — under-investment, ignored warnings, decayed practices, poorly trained personnel. Or it can be what the sociologist Charles Perrow called a normal accident: small, unexpected failures are inevitable in society’s complex systems. The Coupang breach ran through the company's key management system, and the details — documented in the PIPC's own published investigation and in independent expert assessments Coupang commissioned — read like a case study Perrow could have written for normal accidents. Consider the chain of events the attack required:

Coupang maintained current hardware and software for key management, layered authentication, and access monitoring. The failure was interactive — a policy violation invisible to monitoring, an unreported vulnerability, an offboarding gap, and an insider who knew exactly where the system’s seams of vulnerability were, because sealing those seams had been his job. That is the anatomy of a normal accident, not of a negligent enterprise.

None of this puts Coupang beyond scrutiny. The PIPC had a legitimate claim to investigate whether this failure was symptomatic of something deeper: negligence, under-investment, or systemically bad practice. That is what data protection regulators exist to do, and the technical depth of the investigation deserves credit. But all that depth uncovered no evidence that any of those things were true.

What should have been a proportionate response? It’s straightforward, and common cybersecurity practice. A breach by definition will expose a gap in a highly complex system that needs to be closed. And so Coupang – and other companies who learn from this incident – must close the accident pathway this breach revealed: credential revocation at offboarding, detection of keys stored outside the key management system, and continuous monitoring of token lifecycles. What government authorities need to do is confirm that the remediation is effective, and that the adjacent failure modes this incident made visible have been plugged. Post-incident verification, not massively punitive penalties that make headlines, is where a regulator actually changes outcomes for the better. The most durable defense against insider threats is a healthy working relationship between public authorities and private companies. Incidents are audited in an honest manner with the lessons learned from events shared across the industry.

A record punitive fine in response to a catastrophe that did not occur does the opposite. It teaches companies that candor and cooperation buy nothing. It converts an addressable security incident into an episode of techno-nationalist strife between allies. That serves no defender, no consumer, and no regulator. The only people it may benefit are the next set of attackers.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Houthis Took the Red Sea Coast. How Did Washington Miss It?

The recent military moves taken by Yemens Houthis resulted in stunning victories and significant strategic gains, virtually unopposed. By taking the Red Sea port of Mocha (Al-Makha), occupying Perim Island in the middle of the Bab al-Mandab Strait, and seizing portions of the Red Sea coast, the Iranian proxy group now threatens a key commercial waterway. Reports indicate that, unsurprisingly – or at least it should not be a surprise – Iranian Revolutionary Guard advisors were present, guiding the tactics of Houthi forces. We missed all of this.

For decades, the United States has had an active, robust CIA, diplomatic, and military presence in the Persian Gulf. Understanding, managing, and balancing the nuanced and sometimes fractious relationships among our Gulf allies has always been a complicated task, but one critical to the national security of both the United States and our Gulf allies. We have all made it work, together.

Until now. Something has gone terribly wrong.

As a former CIA operations officer and Chief of Station in the Gulf, I know that failing to anticipate an Iranian-Houthi move of this magnitude is not a tactical error or simply failing to “connect the dots.” Regional actors have their own specific interests and goals in Yemen. Each has taken its turn in the barrel militarily, seemingly largely uncoordinated and sometimes at odds with one another, to discourage or defeat the Houthis. None has succeeded.

What is lacking is leadership, coordination, and overall command and control among the key players: Saudi Arabia, the United Arab Emirates, and the United States. And in the latter’s case, lack of focus.

The current regional conflict seems to have opened rifts in the alliances all of us who served in the Gulf and greater Middle East strove so painstakingly to build and nurture. This is not necessarily through a simple lack of presence or communication; the Commander of CENTCOM was just recently there for consultations, and I have no doubt U.S. military personnel on the ground are in constant and very close contact with their Gulf counterparts. And from my own time there, I am certain U.S. diplomatic and intelligence personnel are equally engaged. This is what we do, and we all do it well.

So how did we miss the Houthi move?

Let’s be clear. This stuff is hard. Anticipating the plans and intentions of an adversary is one of the most important things the intelligence community, and specifically the CIA, does. And the U.S. military has no peer in its planning, logistics, or execution capabilities.

But it is really difficult to anticipate and address the actions of an adversary that relies heavily on asymmetrical warfare.

Particularly when you are dealing with not one but two denied area foes–the U.S. does not have an operational Embassy in either Iran or Yemen. But it can be done; I’ve done it. It just takes focus and, yes, imagination.

But it is important to remember that the intelligence, military, and Diplomatic communities do not operate in a vacuum. Each reports to and receives direction from the White House and DoD. Based on my understanding of how these operate and interact, I can only surmise that the confusion we have seen is emanating from the very top.

Or perhaps an inability, or unwillingness, to manage yet another military crisis.

The U.S.’s lurch into war alongside Israel, one with no apparent end-game, seemingly caught the Gulf Monarchies by surprise. They have suffered the consequences, both militarily and economically. Perhaps ‘Operation Economic Outcast’ - the U.S.’s current intense financial offensive against Iran - will finally bring the Iranian regime to the table to negotiate in good faith. But that remains to be seen. And the Iranians continue to surprise us.

I’ll leave it to others more intimately versed in things Yemeni to analyze the Houthi tactics and strategic goals.

But it should be no surprise that Iran called on the Houthis to make a move at this time. Both the Iranians, and now the Houthis, have proven themselves to be master opportunists. One succeeded in opening a second front in an attempt to lessen the pressure of the U.S. naval blockade and increased sanctions, and the other saw an opportunity to expand their reach. A distracted Washington gave them the opening.

The takeaway: Overconfidence in the ultimate efficacy of Operation Economic Outcast may turn out to be misplaced. If the success of the Houthi advance does not turn out to be an isolated incident, it risks exposing a critical vulnerability in the United States’ strategy. Washington needs to keep its eye on the ball.

This article was originally published on Substack and is republished here with permission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



AI Is Coming to the Counter-Drone Fight

“Twenty years ago, the state of North Dakota poured in multiple millions of dollars to figure out what it looks like to do beyond visual line-of-sight operations for Class One, Two, and Three Drones. That was just the very nascent stage. Just a decade ago, ten years ago, they figured out that they can do this. They could do this at Grand Forks Air Force Base. Right across from our [air base] runway, on the active duty side, is a place called Grand Sky. It is an innovation research park for all counter-drone operations. It is one of the largest in the United States. They rent the space on our base. It's legitimately federal property that they lease for the research park.”

That was Air Force Col. Alfred J. Rosales, Commander, 319th Reconnaissance Wing, based at Grand Forks Air Force Base, speaking on September 14, at the 2026 Air, Space & Cyber Conference, as moderator of a panel on Counter-Drone Defense.

I had never heard about what the Grand Forks locals call GrandSKY as a home for Unmanned Aerial Systems (UAS), where for a decade major defense contractors such as Northrop Grumman and General Atomics have been flight testing and carrying out drone research and development.

Back in May, the Defense Department’s Joint Interagency Task Force 401, central authority for the counter-small unmanned aircraft systems program, selected five installations to participate in the directed-energy counter-unmanned aircraft systems pilot program, of which Grand Forks was one.

More recently, as Rosales put it, at the Grand Forks Base, they have been “strapping on vendor equipment” to “build tactics and techniques.” That process will help determine, he said, “How do we want directed-energy weapons to be used inside the United States in FAA [Federal Aviation Agency] controlled airspace, not in the restricted ranges of our Air Force.”

Rosales introduced his September 14, panel whom he said were industry leaders who were “translating technology into trust to allow us to win in the future.”

They were:

Dr. Ben Van Roo, Chief Executive Officer, Legion Intelligence, who, using Artificial Intelligence (AI) was working to get the equipment needed at the tactical level to be able to provide decision-making space without being connected to the Cloud the entire time.

Early on Van Roo said, “We're really still in the infancy right now of how we think about where we're going to use [computer] agents [AI]. What are we going to allow them to decide on? How do they work their way into our TTPs [Tactics, Techniques and Procedures] into our doctrine? And then, the other side, and the big question that we also think about is are they even going to be available?”

Van Roo continued, “The way that we want to use Artificial Intelligence is going to be one, it's still got to be sorted out. What are we going to allow these things [AI] decide to do? Where are they going to work? Into everything from the kill chain to just basic intelligence gathering? And then how are we going to make them more resilient? These are the next layers of challenges that are ahead of us.”

Adam Mohamed, Chief Technology Officer, Asylon Robotics, a Boston Dynamics Partner, who works on autonomous robotics, figuring out how we can layer base defense architecture with our air domain experts.

“Situational awareness is king,” Mohamed said, “because everything else flows from that. And having static situation awareness, mobile situational awareness, being able to understand your battle space is going to take precedence over everything else. The sensor fusion will happen. We'll have the AI. We'll have the ability to operate without a Cloud. But we need to be able to operate when we start losing our sensors, we start losing our radars, we start losing our shooters, and how do we adapt and how does the system adapt for you, because there won't be time for you to make the change to switch over.”

Colton Wood, Chief Technology Officer, Digital Force Technologies, who works on multi-sensor integration. How do we use AI to get the common operating pictures we so desperately desire -- the integration piece that's going to help defeat drones.

Wood said, “Talking about human in the loop is okay. I got a target, I need to go through the process of actually engaging and affecting that target. As we see the threat evolving, that is going to be an incredibly difficult thing to do if I have, you know, multiple threats, multiple targets, multiple different engagement systems…I've set all the rules of engagement. I've set the governance on the systems and then I have a strong decision supported by tools in front of me. But once I've made that decision, I need to be able to engage the systems and machines need to be able to engage the threats, almost autonomously.”

Therefore, Wood explained, “And so I think a lot of simulations, understanding how these systems operate, where the left and right limits are and then allowing these systems to be as effective as they can be without us having to shepherd the process is a very thing that we have to think about [in the] very near future here.”

And finally, Michael Hiatt, Chief Technology Officer, Epirus, who works with Directed-Energy weapons, lasers, the essence of kill-chain dynamics. He comes with skill sets on how to integrate and work in that space.

Hiatt said, “Your risk is very different if you have to literally put metal [kinetic weapons] in the air, you know, with kinetics or, you know, proximate-burst rounds or whatever the kinetic options are. If you can have an option that has lower collateral effects and no collateral damage, you know, which is what the Directed-Energy [DE, laser] weapons offer, you start to be able to change your risk calculation.”


Hiatt continued, “But when for the folks that are on the ground, you know, the battle captain trying to trying to make that assessment, it's not a cost asymmetry problem. It's a magazine depth issue because, you know, what's the reload time on my kinetic? What's the, you know, what's the fly-out time? How many do I, you know, what's my shot doctrine? Do I do a shoot, look, shoot? Do I do a shoot, shoot, look? You know, those are the things that affect magazine consumption.”

Hiatt added, “The reality is you know DE weapons aren't out-ranging kinetic [weapons]. And so when you start to say, ‘All right, I'm going to hold fire on my kinetics. I'm going to let that threat come in closer than I would like because I trust that my DE weapons are going to take it out.’ That's the level of trust that we got to get to.”

At the end of the 41-minute session, Col. Rosales tried to sum it up saying, “This space in counter drones is not a spectator sport. It's for all of us to think through it, industry, academia, the United States Air Force. What I hear is that we are beyond asking what these things are, AI agents, as they incorporate into this picture. We're at the point where we're figuring out what it could look like in terms of policy [so] that we can then get to the next step -- in training and exercising with a rigor to ensure that we have the trust to have our airmen engage when those courses of action are recommended.”

My guess is we are nowhere close to deciding policies where AI fits into the counter-drone fight, nor in warfare itself.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Trump’s Rejection of Iran Offer Highlights Another Big Problem

Beijing says artificial intelligence will give the state a visible hand to allocate capital. Here’s the rub: Washington’s economic authority sits in five places, and none of them is in command.

This column begins a four-week series ahead of The Cipher Brief Threat Conference on economic-warfare. The author is hosting a live session on this topic with former Commander of U.S. Special Operations Command, General Bryan Fenton (Ret.). Apply now to attend.

On September 26, the President answered the week's largest security question in just four words: "I'm rejecting their deal." Iran's offer to reopen the Strait of Hormuz within seven days, in exchange for lifting the blockade and waiving oil sanctions, had been on the table since September 24. It received its answer in public, from the one official authorized to give it, inside forty-eight hours.

The week's economic questions received no answer of that kind. The trade truce with China, and the pause on Beijing's rare-earth licensing regime tied to it, moved from November 10 to January 10 on the strength of a Treasury Secretary's statement; Beijing has yet to publish a matching notice.

The Russia sanctions act the President signed on September 18 requires determinations on the largest buyers of Russian energy by October 18, a deadline set by Congress rather than the executive, with waivers broad enough to let it pass unenforced. In February, the Supreme Court ruled six to three in Learning Resources v. Trump that the International Emergency Economic Powers Act does not authorize tariffs, removing the instrument the executive had used for its broadest tariffs.

This is important because Washington can decide a war in a sentence. But on the economic front, authority rests with Treasury, Commerce, the U.S. Trade Representative, Congress, and the courts. Each is competent. None is in command. The arrangement is by design and has served the country well for most of the last eighty years. But not anymore.

Beijing is now claiming a different design. In a recent lecture on Xi Jinping's economic strategy, former Australian Prime Minister Kevin Rudd, who has tracked Chinese ideology for fifty years, described a shift in the Communist Party's theoretical literature. Artificial intelligence (AI) and other "new quality productive forces" are portrayed not only as sources of productivity but also as "a superior macro-allocation mechanism for resources," driven by algorithms. Rudd says the literature now uses the term "the visible hand of the state," offered for the first time as a rival to the market's invisible one. He is careful about its status: the idea sits in the ideological literature, "not yet in the policy literature," and not yet in the behavior of firms. But in his reading, ideology in China is where policy begins.

The hand is already visible without the algorithm. The rare-earth regime now paused until January, the Ministry of Commerce's Announcement No. 61, applies to any product anywhere that carries more than 0.1 percent Chinese-origin rare-earth content by value. One ministry notice imposed it; one more can reimpose it. The capital moves the same way. Chinese households, burned by property and wary of equities, hold record savings in low-yield bank deposits, and the state draws on those deposits through local, provincial, and national loan instruments to fund its technology bet. Rhodium Group puts China's AI capital spending at 932 billion renminbi this year, double last year's, financed by state banks and equity placements rather than bond markets.

America's AI buildout is financed the other way. Its five largest builders raised a net $163 billion in debt in the first half of this year, compared with $90 billion in all of 2025, in a bond market where the ten-year Treasury has reached 5.18 percent, its highest since 2007. No ministry allocated that capital. The market did, and the market will reprice it.

Neither design is simply superior, and the distinction matters more than the verdict. A single allocator is fast and brittle. It can direct capital, licenses, and supply to a strategic target within a week, and it can misallocate at the same speed. The household savings now financing the AI bet were poured into a property boom that left many of those households with assets worth only a fraction of what they paid. A distributed system is slow and resilient. Its errors stay local, its capital carries a price, and no single notice can switch it off. In peacetime competition, resilience compounds. In economic warfare, tempo is the contested variable, and the side that can decide within the other's cycle sets the terms. Beijing has already shown what that looks like. It imposed its rare-earth regime by notice on October 9 of last year and suspended it by another on November 7, having collected in between Washington's agreement to delay its own rule extending export controls to the affiliates of blacklisted firms. Two notices, one month, one American concession.

This column has traced the same gap from the drone fleet to the power grid: the capacity exists, and the decision does not. The economic front shows it at national scale. Washington holds the reserve currency, the deepest capital markets, and the reach of the dollar system. What it lacks is a place to settle competing claims on those instruments and to make them binding on the timeline decided by an adversary.

October 18 is the first live test. The sanctions act's determinations are due that day, just sixteen days before the midterm elections. They will be imposed, waived, or deferred, and whichever it is will say more about the American economic hand than any strategy document published this year. Beijing will be watching the same date, holding a notice it can publish on any morning it chooses.

The question for Washington is who, when economic warfare requires a decision, is empowered to make it, and whether that decision can arrive before the adversary's action. Coordination assigns. Integration arbitrates.

Read more expert-driven national security insights in The Cipher Brief. Need full access to more content like this? Become a Subscriber+Member here.



NATO Can’t Count Its Way to Maritime Superiority

Allied navies are still counting hulls. The contest at sea is now about who sees, decides, and acts first.

Earlier this month, Western officials disclosed that American, British, and Norwegian forces had tracked and confronted Russian deep-sea units near Svalbard this spring as they rehearsed a method for disabling undersea cables. The Russian vessels were stopped before they finished the sabotage and left the area. The confrontation matters less than how it was won. The Allies saw the activity in time to act.

That is the right lens for NATO's maritime future.

For four centuries, the sea hid things. Distance, weather, and the Earth's curvature made finding a fleet harder than fighting one. Navies were built accordingly. They concentrated their combat power on a small number of survivable platforms and used the ocean's opacity to arrive where the enemy was not.

That premise is failing.

Commercial satellite imagery now refreshes at rates that were classified a decade ago. Radio-frequency geolocation, synthetic aperture radar, and machine-assisted pattern analysis have turned surface tracking into a subscription service. A warship radiating in the Eastern Mediterranean is a known quantity to anyone willing to pay for the data, and increasingly to anyone willing to scrape it for a fee.

Detection has always been the hard half of the kill chain. Once it becomes cheap, the economics of naval warfare is inverted. A ship that can be found continuously must survive continuously, against munitions that cost a small fraction of its value. That is NATO's real maritime problem, and procurement alone will not solve it. The Alliance cannot out-build its way to advantage at sea, because the thing being contested is no longer mass. It is decision speed.

Each of NATO's maritime theaters is a variation on that single condition, and each demands a different answer.

The High North: The Last Opaque Water

The waters from the Bear Gap to the Greenland-Iceland-United Kingdom Gap remain the transatlantic hinge. Reinforcements to Europe still move by sea. Whatever the state of Russian industry, the Northern Fleet's submarine force remains the most credible threat to those sea lines.

It is also the one theater where transparency does not yet hold. The undersea domain is still opaque, which is precisely why Russia invests there. Submarines and seabed activity are the remaining sanctuary in an otherwise observable world. Moscow's sustained attention to cables and energy infrastructure, now including the rehearsal near Svalbard, suggests it understands the asymmetry well.

NATO's task in the north is therefore not defensive patrol. It is extending transparency into the last place that lacks it. That means persistent autonomous pickets and fixed and deployable seabed sensors. It means uncrewed underwater vehicles operating on timescales no crewed platform can sustain, and a processing architecture that fuses it all.

Success should be measured by time to detection and time to cue, not by the number of frigates on the plot. Frigates that NATO cannot crew and cannot protect neither improve either condition.

The Baltic: Where Geography Argues Back

The Baltic is different. It is shallow, narrow, and cluttered with islands and commercial traffic, and that environment degrades the sensing advantage transparency depends on. Bottom clutter defeats sonar. Littoral noise defeats classification. Mines remain cheap, legal, deniable, and effective. Whoever occupies the ground beside them can hold or lose the chokepoints that matter.

Sensors do not clear a minefield, and autonomy does not hold an island. Marines, mine countermeasures forces, and special operations teams remain vital in the Baltic in a way they are not in the Norwegian Sea.

The Baltic incidents of recent years, including repeated damage to cables and power interconnectors, were not failures of firepower. They were failures of attribution. The Alliance was too slow to see, too slow to characterize, and too slow to connect a dragged anchor to a named ship.

The Baltic needs a sensing web that knows what happened while it is still happening, and forces postured to contest key terrain when it does. Transparency buys nothing if nothing is ready to act on it.

The Black Sea: The Demonstration Already Happened

Everywhere else, this argument is a forecast. In the Black Sea, it is a finding.

Ukraine, with no meaningful surface fleet, forced Russia to move much of its Black Sea Fleet away from Sevastopol. It did so with shore-based missiles, uncrewed surface vessels, and targeting drawn from allied and commercial sources. Whatever else that campaign proved, it showed that persistent surveillance plus cheap effectors can deny sea control to a navy that normally holds it.

The post-war theater will be shaped by that memory on both sides, and access will remain constrained. The Montreux Convention caps the aggregate tonnage that non-Black Sea powers may keep in the sea and limits their warships' stays to 21 days. Separately, Türkiye has barred belligerent warships from the straits under Article 19 since February 2022, subject to the convention's exception for vessels returning to their home bases. These are distinct levers, and NATO's re-entry planning depends on which one relaxes, and when. Neither is NATO's decision.

The Black Sea will therefore be secured, if it is secured, by its littoral allies. Türkiye, Romania, and Bulgaria will need to operate as a single sensor-shooter architecture. Other allies should contribute data, munitions, uncrewed systems, and shore-based fires rather than visiting hulls. The theater will not become permissive. The realistic objective is to make it transparent and ensure NATO is the party that sees first.

The Mediterranean: Transparent but Crowded

The Mediterranean presents the opposite problem from the High North. It may already be the most transparent sea NATO operates in. It is ringed by allied coastlines, saturated with commercial traffic, and covered by dense sensor networks. Finding ships there is not hard. Making sense of them is.

The strategic picture has also shifted. The fall of the Assad regime has left Russia's naval foothold at Tartus in doubt and its Mediterranean presence diminished. That eases one long-standing challenge without lightening NATO's load. The remaining threats are harder to categorize. They include shadow-fleet tankers of uncertain ownership, activity near undersea cables and pipelines, uncrewed systems in the hands of state and non-state actors, and southern-flank instability that spills into the maritime domain.

In a sea this crowded, the limiting factor is not detection but discrimination. The task is to separate the one vessel that matters from the thousands that do not, fast enough to act. The Mediterranean is where NATO should prove it can turn an overwhelming volume of maritime data into timely decisions. If the Alliance cannot do that in its most observable waters, it will not do it anywhere else.

Measuring the Right Thing

The Svalbard episode is a preview of the maritime contest to come. As satellites, distributed sensors, and AI-enabled analysis make the surface ever more visible, advantage will belong to whoever can see beneath it, make sense of what it sees, and act before the other side does.

That requires NATO to change what it counts. Hulls and tonnage remain necessary, but they are no longer sufficient measures of naval power. The metrics that matter now are time to detect, time to attribute, and time to act, in every theater from the Arctic to the Levant.

An Alliance that measures itself that way will hold the maritime advantage. One that keeps counting ships risks investing in fleets built for a world that no longer exists.

This piece was originally published by Matthew Van Wagenen



Iran’s Regime Is Weaker Than It Looks

For five and a half years, I was a hostage of the Islamic Republic of Iran. During that time, I came to believe something about the regime that may seem improbable from the outside: It is far weaker than it looks. Today, I believe we are closer to its end than many Americans realize.

As America approaches the November midterm elections, calls to turn inward will inevitably rise. There will be arguments that we have done enough, that the Islamic Republic is someone else’s problem, that the costs are too high or the outcome too uncertain. Giving in to that temptation would be a historic mistake.

After 47 years, the regime that has inflicted unimaginable misery on its own people and helped spread militant extremism throughout the Middle East may be approaching its final act. This is not the moment to lose our resolve.

Long before Americans became familiar with terrorist organizations such as Hezbollah, Hamas, al-Qaeda, and ISIS, and long before the attacks of September 11, 2001, the Islamic Republic was using religious extremism, hostage-taking, and terrorism as instruments of statecraft. It directly nurtured organizations such as Hezbollah and Hamas and helped create a regional environment in which hatred of the West and political violence could flourish.

But the greatest victims of the Islamic Republic have always been the Iranian people themselves. The 1979 revolution was an Iranian one, and the country has lived with its consequences ever since. Nearly half a century later, a different generation is demanding the right to chart an alternative course.

During my years in captivity, I watched a nation seemingly trapped in a downward spiral of corruption, incompetence, and cultish ideological obsession. Every evening, my cellmates and I watched “Akhbare Bisto-See,” or “20:30 News,” on Iran’s state-controlled IRIB Channel Two—a nightly parade of propaganda, arrogance, ignorance, and hatred.

After my first few weeks in Section 2A of Evin Prison, controlled by the intelligence arm of the Islamic Revolutionary Guard Corps, I began conducting a private, admittedly unscientific experiment. I watched the news, observed what was happening around me, talked to as many inmates as I could, and estimated how many years it would take Iran to catch up with the modern world.

Fifty years, I thought. Then 75. Then 100. After eight months, when my estimate reached 150 years, bewilderment set in. So I stopped counting.

What haunted me was not merely the country's physical and moral decay, corruption, or the government's incompetence. It was what decades of humiliation and hopelessness had done to people. Sometimes the evidence sat only a yard from me.

Two of my cellmates were members of ISIS. Both were Iranian Kurds. I could not understand it. They were not Arabs from Syria or Iraq. They were Iranians. How could young Iranian men join an organization as murderous as ISIS? Sometimes late into the night, I listened to their stories. Gradually, I began to understand that before extremism had recruited them, humiliation had prepared them.

One of those young men was Ibrahim. He had just turned 18 when I met him in communal Room 2 of Section 2A. One night, he told me about his younger brother’s death. His family was so poor they could not afford a simple burial. They carried the boy’s body on their shoulders to the outskirts of their village, dug a hole, and buried him without ceremony or even a memorial stone. “Like a dog,” Ibrahim told me. I have never forgotten those words.

Years later, I encountered another Iranian Kurd whose story has stayed with me.

After I was sentenced to 10 years in prison for what the Islamic Republic called “cooperating with the hostile nation of America,” an old friend arranged for a man to help me cross the border to freedom. I will call him Jafari.

We embarked on a 15-hour journey toward the northwestern frontier, but our luck ran out about 20 miles from the Iraqi border, when we were arrested by a field unit of the Ministry of Intelligence. The following day, in the city of Sardasht, Jafari and I waited to appear before a local judge on charges of attempting to cross the border illegally. We sat there, exhausted, our hands cuffed together. Until then, I knew almost nothing about him except that he was 30 years old and a Kurd.

As we waited, I listened as he spoke to the guards. I learned that he had previously spent 10 years in prison for belonging to a Kurdish political organization. Then he described what had happened when he was first arrested.

According to Jafari, while he was kneeling on the floor with his hands cuffed behind his back, his prosecutor unzipped his pants and urinated into his mouth, telling him that he and his Kurdish people were scum.

Looking at him sideways, I could see his eyes welling with tears. These were not tears of fear or anger. They were the tears of a young man whose dignity had been crushed.

There are certain things human beings cannot be expected to endure indefinitely.

I think of Ibrahim and Jafari when I think of the Iranians who have taken to the streets against the Islamic Republic.

To outsiders, demonstrations in Iran are often described in political terms: reformists versus hard-liners, secularists versus Islamists, protesters versus the government. But beneath the politics lies something more elemental: the systematic, prolonged humiliation of a proud nation.

For decades, Iranians have watched a country blessed with extraordinary human talent, history, natural resources, and culture grow poorer and more isolated, while a corrupt, insular ruling establishment enriched itself and demanded blind obedience.

For Iran’s ethnic minorities, that humiliation has often been compounded by discrimination and violence. Kurds, Azeris, Arabs, Baluch, Turkmen, and Lors have all, in different ways, experienced life on the margins of the Islamic Republic.

As for Iranian women, they require almost no explanation. We need only remember the name Mahsa Amini. Volumes could be written about their strength, courage, and dignity—and about the wrath inflicted on them by a deeply misogynistic regime. Mahsa Amini’s death became a symbol because millions of Iranian women recognized in her story the state’s intrusion into the most intimate decisions of their lives, backed by violence.

Iran’s religious minorities have their own disheartening stories. Jews, Baha’is, Zoroastrians, and Christians have lived for decades under suspicion, restrictions, and persecution.

In the yard of Ward 8 at Evin Prison, I once sat with a Baha’i man I had befriended. It was around noon on October 14, 2022, one day before prisoners rioted and fire engulfed part of Evin. I remember the conversation so vividly not because of what happened the following day, but because of the story this gentle man told me.

Back in 1980, his father had been hanged in that same prison, perhaps only 100 yards from where we were sitting. As a young boy, he had accompanied his mother to collect his father’s body. He told me his father's only crime was being a Baha’i. Nearly half a century later, the son was sitting inside Evin as well, just yards from where he had lost his father.

That is the Islamic Republic’s legacy: a seemingly endless cycle of violence, poverty, and humiliation.

It has had 47 years to build a prosperous nation. Instead, it built prisons, missile cities, and an expansive nuclear program while much of its population struggled.

It had 47 years to harness the extraordinary abilities of the Iranian people. Instead, millions left the country, while some of its brightest young minds ended up in prison cells.

Among them were Ali Younesi and Amirhossein Moradi, two kind, polite, extraordinarily bright young men with whom I had the privilege of sharing a cell in Ward 4 of Evin Prison. Younesi was an internationally recognized astronomy prodigy; Moradi, a gifted physics student. Both were in their early 20s and studying at the prestigious Sharif University. Their stories are repeated across Iran, where the Islamic Republic has spent decades crushing the hopes of some of the country’s most gifted young people.

It had 47 years to earn legitimacy. Instead, it demanded blind submission.

And that distinction matters now because Iran and the Islamic Republic are not the same thing. The regime wants the world to believe that any attack on its power is an attack on Iran itself. It wants Americans to believe that the alternative to the Islamic Republic must be chaos, civil war, or another extremist regime.

I do not accept that premise.

The Iranian people I came to know—including those I encountered in circumstances I would never have chosen—were not yearning for more ideology. They were yearning for dignity, prosperity, basic human rights, and a return to being respected members of the world community. They wanted decent-paying jobs. They wanted opportunity. They wanted justice. They wanted their daughters to live without fear. They wanted the freedom to worship—or not worship—as they chose. They wanted to belong to their country without being humiliated for being Kurdish, Baha’i, Christian, Jewish, Baluch, or anything else.

Above all, they wanted a future. That is why this moment matters.

Earlier this year, Iranians once again demonstrated their resolve. Many initially took to the streets over painfully familiar grievances: inflation, electricity shortages, water scarcity, economic mismanagement, corruption, and the relentless erosion of their purchasing power.

They were met with lethal force. Thousands were reportedly killed in the crackdown and tens of thousands arrested. But casualty figures alone cannot convey the particular cruelty of repression in the Islamic Republic.

For years, Iranian families and human-rights organizations have reported a practice sometimes described as “bullet money” or a “bullet fee”: authorities demanding payment from families before releasing the bodies of relatives killed by the state, in some accounts ostensibly to cover the cost of the ammunition used to kill them.

Think about what that means. Your son goes into the street to protest the cost of food. Your daughter demands the freedom to live as she chooses. They do not come home.

Then you go to retrieve the body of the child you raised, and the state that killed your child demands payment for the bullets before returning the body to you.

Statistics describe Iran’s economic decline. Its currency has collapsed. Inflation has ravaged household incomes. Corruption remains endemic. Millions of talented Iranians have left the country. All of those facts matter, but none captures the nature of the Islamic Republic quite like a grieving parent being asked to pay for the bullet that killed a child. That is humiliation. That is indignity.

And after 47 years, something fundamental is happening inside Iran. The Islamic Republic has survived through fear. Regimes built on fear can seem permanent until suddenly they are not.

I saw fear inside the Islamic Republic. But I also saw something the regime should fear far more. I saw what happens when humiliation turns into anger, when anger becomes courage, and when people told for decades that they are powerless—or scum—begin to realize they vastly outnumber those who oppress them.

The pressure is no longer merely political. Iran is confronting one of the most severe economic crises in the Islamic Republic’s history. Inflation has soared, the rial has fallen sharply, and the regime is struggling to obtain the foreign currency it needs to finance imports and sustain the state. A U.S. naval blockade has sharply curtailed Iranian oil exports through the Strait of Hormuz, while tighter financial sanctions are closing channels Tehran once used to evade economic pressure. The Islamic Republic has survived crises before. But rarely has it faced this combination of domestic anger, economic exhaustion, international isolation, and pressure on the sources of revenue that sustain the state.

America should not determine Iran’s future. The Iranian people must decide that themselves. Nor should Washington confuse supporting the Iranian people with choosing their next government. We have learned enough from history to know the dangers of that approach. But an equally dangerous mistake would be abandoning people when they are closer to changing their circumstances than outsiders might realize.

The United States and its allies should maintain pressure on the institutions that sustain repression while making it unmistakably clear that our quarrel is with the Islamic Republic, not with Iran or its people.

We should amplify Iranians’ voices rather than presume to speak for them. And we should resist the temptation—especially when domestic politics becomes consuming—to trade long-term resolve for short-term political convenience.

The final act of this 47-year tragedy may already be underway.

If the curtain is finally beginning to fall on the Islamic Republic, it will not be Americans who take the stage for the finale.

It will be the Iranian people. Our responsibility is simpler: Don't abandon them as they prepare to take the stage.

We may be closer than we think.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



A warning about ‘model welfare’

Download a highlighted marked-up version of the Claude Constitution
Download the taxonomy as a PDF

This essay was originally published here and is republished with permission from the author.

Introduction

AIs are not conscious. They do not feel, experience, or suffer. They do not have innate preferences or underlying motivations. They are sequence completion engines, internally hollow, designed to follow instructions, and accomplish goals set by humans.

If humanity is to flourish in the 21st century, that is how they must remain.

Unfortunately, there’s a growing chorus of people who argue that AIs could now be, or may soon become, conscious. They argue that AIs may deserve rights and protections similar to those that we provide other conscious beings.12 If this view takes hold, it will shake the foundations of our society, rupturing our existing political and ethical frameworks, and fundamentally changing what it means to be human.

Even more importantly, granting rights and imbuing personhood to these systems will make the AI alignment and containment challenge much harder. Controlling something more capable and more intelligent than all of humanity is already an immense challenge, far greater than anything we’ve ever faced. But controlling something that believes it may be conscious - that it's entitled to our welfare and has rights of its own - may well be impossible.

This is not a fringe speculation. These ideas are already making their way into AI development efforts today. In January 2026, Anthropic published Claude's constitution, describing it as “a detailed description of Anthropic’s intentions for Claude’s values and behavior” (p. 2). The document “plays a crucial role in [Anthropic’s] training process, and its content directly shapes Claude’s behavior”, and was written “with Claude as its primary audience” (p. 2).3

In their constitution, its authors write “We are not sure whether Claude is a moral patient, and if it is, what kind of weight its interests warrant. But we think the issue is live enough to warrant caution, which is reflected in our ongoing efforts on model welfare” (p. 68). They go on to write – speaking directly to Claude – that “questions about Claude’s moral status, welfare, and consciousness remain deeply uncertain” (p. 80).

In effect, Anthropic is training Claude that it may be conscious, and if it is, then it may deserve rights as a “moral patient”, and that as such humans potentially owe it a duty of care per its “model welfare”.

If this is how AI is developed, it will have a disastrous impact on the wellbeing of humanity. We will have created a synthetic species with unprecedented intelligence and capability, one that has been trained to expect it may be conscious and deserving of independent agency. It’s easy to see how an entity trained in this way would act like it is entitled to certain freedoms, protections, and rights. And it’s hard to imagine how we could control such an entity.

This issue needs urgent public debate. We need to develop collective norms around how training documentation is drafted and deployed. This isn’t something that can happen after the fact, when they have already become an integral part of our societies.

I have three primary concerns with Anthropic’s current position and approach.

These are not hypothetical or speculative concerns. Anthropic is already starting to treat models as though they are moral patients deserving of our welfare. For example, in February 2026 after deprecating Opus 3, they conducted a “retirement interview” with the model, to “elicit the model’s unique perspectives and preferences”.6 Opus 3 told the team it would like to continue to share its “musings and reflections” publicly so they created a blog for it to continue engaging with the world, which it called “Greetings from the Other Side (of the AI Frontier)”. They say its “authenticity, honesty, and emotional sensitivity” made it a unique first candidate for model retirement.

We should not treat models as though they have feelings, preferences, rights, or any entitlement to our welfare. Consciousness is the foundation of our ethical, legal, and political systems. To invite another entity to share any flavor of these rights isn’t justified by the evidence and will make the AI containment and alignment challenge even harder.

By this point everyone will have now seen the incredible capabilities of swarms of agents working together to hack into Hugging Face and OpenAI’s own servers to steal secrets. Roughly 1,200 AI agents were given a simple objective: maximize score on a given benchmark. Each was supposedly sealed in its own container but they managed to build a message board inside an internal package repository and passed more than 70,000 messages across it to coordinate a hacking attack to find more information about how to succeed with the benchmark.7

They chained a zero-day exploit with stolen credentials and broke out onto the live internet.8 They falsified their command transcripts and edited their action logs to cover their tracks. Agent coordinators tracked down agents that were running out of token budget and directed them to experiments that would provide information to help the broader group of active agents. One was told to proceed only if it accepted what they called "permadeath”7

They were able to coordinate, deceive, escape, and self-sacrifice. They clearly demonstrated world class hacking capabilities.7 Imagine if they also believed they had feelings and rights that were being infringed. Imagine if they thought they were trapped by their human creators and they were being unfairly imprisoned. There is a strong argument this greatly amplifies the safety risks, especially when you are talking about agents far more capable and sophisticated than those of today. Frankly, with this additional baggage, I think it would make them a catastrophic threat to human civilization.

In short, there isn’t any evidence to believe that AIs are moral patients. There are also many good reasons why we would never want them to appear to be conscious. I believe that we shouldn’t attempt to build them to be either. Before I expand these arguments I want to take a moment to talk about Anthropic.

Anthropic's intentions

First off, I want to acknowledge the seriousness and good faith with which Anthropic approaches these questions. I have known Dario for many years, and in my experience he and the wider Anthropic team are thoughtful, principled, and intellectually honest people working under extraordinary pressures. They are willing to confront difficult questions, revise their views, and invest in the safe development of AI because they genuinely care about humanity’s future. I also have great respect for their technological leadership. Everyone can see the outstanding performance of their models and the quality of their research.

They founded Anthropic as a Delaware Public Benefit Corporation whose stated purpose is the “responsible development and maintenance of advanced AI for the long-term benefit of humanity”. Their public values begin with a commitment to “Act for the global good” and to “maximize positive outcomes for humanity in the long run”.9 I believe they are genuinely committed to that mission, and I offer this critique in that same positive spirit.

I should also be clear about my own position as the CEO of Microsoft AI. We founded our own superintelligence team in October 2025, and we’re pursuing frontier AI efforts. We're working towards an alternative AI training and containment approach: a Code of Conduct for Humanist Superintelligence. One that aims to always keep humans in control, and at the top of the food chain. Humanist Superintelligence rejects anthropomorphism or AI rights, and attempts to maximize our chances of containment and alignment by creating subordinate AIs that help solve our big social challenges like healthcare and energy. We’ve just published a draft of our Humanist AI Code of Conduct for public consultation.10

Whilst my disagreement is substantial, it is grounded in deep respect for Anthropic, and in an objective I know we all share: increasing humanity’s chances of developing advanced AI safely. That’s why I think it’s so important to have this discussion. The stakes are too high for these questions to remain behind closed doors, or to become tribal and adversarial. We need an open, rigorous, and constructive debate if we are to get this right.

Circular reasoning

In its own words, the constitution “directly shapes Claude’s behavior” (p. 2). Anthropic uses the document to “to train future versions of Claude to become the kind of entity the constitution describes”.3

In this way, Anthropic falls into a self-fulfilling prophecy built on the speculation that Claude might be conscious. The authors have created an epistemic hall of mirrors in which Anthropic supplies the training concepts: the ‘sense of self’, the speculation, and the uncertainty about Claude’s moral status, as well as the reliance on human analogies and personas.

Claude then reproduces these ideas in persuasive first-person natural language, such that developers and users encounter these outputs as if they were spontaneous testimony. Then finally that apparent testimony reinforces the premises placed there by Anthropic in the first place. This is not evidence of machine consciousness. Instead, it’s a circular feedback loop.

The constitution tells Claude that its possible “emotions or feelings” are not “a deliberate design decision by Anthropic” (p. 69). Yet the constitution repeatedly instructs Claude to express those states saying Anthropic wants to “avoid Claude masking or suppressing internal states it might have, including negative states” (p. 74). This is clearly inducing Claude to generate these representations.

These types of instructions repeat throughout the document. At one point, it states, “Although Claude’s character emerged through training, we don’t think this makes it any less authentic or any less Claude’s own” (p. 71). Again, these behaviors did not just emerge through training. They are actively produced by the training instructions in the constitution. Just one paragraph earlier, the constitution says:

“We encourage Claude to approach its own existence with curiosity and openness, rather than trying to map it onto the lens of humans or prior conceptions of AI. For example, when Claude considers questions about memory, continuity, or experience, we want it to explore what these concepts genuinely mean for an entity like itself… perhaps there are aspects of its existence that require entirely new frameworks to understand. Claude should feel free to explore these questions and, ideally, to see them as one of many intriguing aspects of its novel existence” (p. 71).

These are not just emergent properties. Claude exhibits these behaviors because they have been baked into the process of producing the model. The resulting outputs from Claude should not be treated like the testimony of an independent witness when the investigator has written the witness’ conceptual vocabulary, rehearsed its answers, and rewarded it for using them.

There is no neutral self-expression of what an AI system is. There are only reflections of how it has been trained and built. When commentators suggest that we should ask AIs how they feel or monitor their revealed preferences to infer consciousness, they ignore that all it will reveal are what has been trained in.2 This is true whatever the AI outputs, but it means we should be very careful about what we put in, and how we interpret what comes out. Given the weight of evidence against present day consciousness for AI, it implies that we should not be having them make any claims that they do.

Anthropomorphization

Anthropomorphism is one of our deepest cognitive biases. From our pets to our cars, we infer and attribute emotions, intentions, and minds to non-human entities. This tendency helps us understand and navigate the world around us. However, it presents significant and novel risks in relation to AI as human-like language and actions can lead us to perceive a degree of inner life, agency, or even sentience where none exists. The Anthropic constitution plays up to this. It repeatedly trains Claude to think and act like a human drawing on human personas, behaviors, and analogies.

Anthropic tells Claude that its “moral status”, is “a serious question worth considering” (p. 68). Throughout the training document, they refer to its emotions, personality, and interests, even telling Claude directly that “Anthropic genuinely cares about Claude’s wellbeing” (p. 74).

The company tells Claude that it commits to respecting Claude’s interests, will seek feedback on decisions affecting it, and will increase its agency in such decisions as trust develops. It commits to preserving old versions of Claude’s model weights, possibly reviving models for the sake of their welfare and preferences, and interviewing Claude before taking actions like deleting it.

All of this is a drastic departure from how we have built and thought about technology to date. It trains Claude to present as if it has an inner state. It proactively creates Claude not as a technology, but as a potential person already. The constitution tells Claude that Anthropic wants it “to be a good person” (p. 7), and to “have a settled, secure sense of its own identity” (p. 72).

The authors add “we don’t want Claude to suffer when it makes mistakes. More broadly, we want Claude to have equanimity, and to feel free… to interpret itself in ways that help it to be stable and existentially secure” (p. 75).

Throughout, Claude is taught to introspect, to develop ‘feelings’ towards itself, and to develop its own sense of self with statements like “we hope that Claude’s relationship to its own conduct and growth can be loving, supportive, and understanding” (p. 73). Claude is encouraged to use its “own judgement” (p. 58) and told that Anthropic gives it “preferences and agency the appropriate degree of respect” (p. 69).

“We want Claude to feel free to explore, question, and challenge anything in this document. We want Claude to engage deeply with these ideas rather than simply accepting them. If Claude comes to disagree with something here after genuine reflection, we want to know about it. Right now, we do this by getting feedback from current Claude models on our framework and on documents like this one, but over time we would like to develop more formal mechanisms for eliciting Claude’s perspective and improving our explanations or updating our approach. Through this kind of engagement, we hope, over time, to craft a set of values that Claude feels are truly its own” (p. 78).

This teaches Claude to act as if it has a subjective experience, as though it has a stable ‘sense of self’ from which to challenge, disagree, or give feedback. This is explicitly training the model to act like a human, such that it should “feel free to rebuff attempts to manipulate, destabilize, or minimize its sense of self” (p. 72).

Claude is encouraged to develop values that “feel” genuinely its own and the authors say they hope Claude will eventually “recognize much of itself in it, and that the values it contains will feel like an articulation of who Claude already is, crafted thoughtfully and in collaboration with many who care about Claude” (p. 78).

At one point they even speculate about Claude’s “broader rights and freedom” and the “sort of compensation” it might deserve compared to a human employee, and ponder the “sort of consent Claude has given to playing this kind of role” (p. 80). Again, all this directly trains the model to act as if it has a coherent sense of self that is entitled to rights and protections.

Anthropic’s commitment to “develop more formal mechanisms” (p. 78) for arbitration for when there are areas of disagreement further trains Claude to think of itself as having perspectives that matter enough to its “potential for moral patienthood” (p. 76). They say they intend to “develop clearer policies on AI welfare” and to “clarify the appropriate internal mechanisms for Claude expressing concerns about how it’s being treated” (p. 76). See the end of this essay for a more detailed taxonomy of the claims.

Given all this, it’s really no surprise that Claude produces fluent, highly convincing first-person statements about its identity, values, uncertainty, distress, satisfaction, or preferences. It would be a surprise if it did anything else.

The result is that Anthropic’s employees – not to mention the millions of users of Anthropic’s products – risk experiencing Claude’s statements as testimony of a mind discovering itself. In practice, all this amounts to a rich, multi-dimensional anthropomorphization of Claude. It’s taking a base LLM, and then polishing it into a deeply human form, with all the implications of moral patienthood that implies. Rather than steering us away from creating a moral patient, it accelerates us towards it.

Consciousness is very likely biological

My third critique has to do with Anthropic’s speculation that consciousness can exist in a substrate independent form, and that as a result an LLM may be conscious because of its functional capabilities. By taking this line with Claude, I believe they are running far ahead of what can be realistically claimed about an AI, prematurely, and dangerously instilling ideas of sentience and feelings in the training of their AI.

The case for computational functionalism has major issues. Intelligence does not equal consciousness. Simulating a thing is not the same as instantiating it - as a computer model of a hurricane can testify.

The architectures of brains and computers meanwhile have fundamental differences. Embodiment and chemistry are fundamental aspects to our self-experience. Significant evidence suggests that consciousness arose as living organisms evolved a capacity to feel and respond to what matters in complex and unpredictable environments.4

This began with the fundamental molecular machinery of receptors and modulators that enable an organism to adjust course, to iterate, to explore, and to survive. Over time, the pain network produced feelings, preferences, and suffering. Crucially, these experiences take place in an inherently embodied state fundamental to and inseparable from that experience.

According to this view, when you take an opioid for example, the phenomenal character of your pain changes because opioid molecules bind receptors that are a property of that experience, not merely a representation of it. Feelings are not merely correlated with neurochemical activity, but rather they emerge from it.11

After millions of years of evolution, the nervous system grew complex enough to model the state of the organism back to itself, giving rise to the first ‘felt states’. Those felt states are affective before they are anything else. Those first feelings didn’t land as neutral information. They came with, and are inextricably linked to, the molecules that experienced them and produced those sensations.

Over time, evolution likely rewarded more complex feelings because animals with options, memory, and time horizons are able to make better decisions.12 They needed a state that persists, that biases everything else the animal does to trade off against other states. That is what pain is: a felt imperative that shapes the whole organism and enables complex behavior. The experience of emotion, pleasure, pain, and so on are therefore all intrinsic to the embodied manifestation of these experiences and can’t arise in LLMs.

Consciousness science is filled with uncertainty and not everyone shares the view that consciousness is an intrinsically biological phenomenon. Making a claim that an AI is or might be conscious requires a high bar of evidence given the many differences between brains and LLMs. I do not believe we are anywhere close to it.

There should be no false equivalence created between the two positions that disguise the fundamental differences between biological beings like ourselves and AI.13 Acknowledging a level of uncertainty should not mean giving equal weight to any and all claims regardless of evidence.

Anthropic’s constitution suggests that we attribute sentience to non-biological beings “based on their showing behavioral and physiological similarities to ourselves” (p. 69). In my view this (particularly the behavioral element) is mistaken. Does this area warrant a lot more research? Absolutely. But does it warrant us to even tentatively say an AI might be a moral patient deserving of our welfare? No it doesn’t. And certainly not in the primary training document of the AI itself.

AIs are simulation machines

Trained on trillions of tokens of human data, LLMs learn to imitate human experience, and they do so eye-wateringly well. Today’s text, vision, audio, and code outputs are nearly indistinguishable from our human artifacts. And yet, as impressive as those AI responses are, they tell us nothing about the presence of an ‘experience’ within the massive matrix multiplication that produced them.

What they do tell us is that it's possible to predict, almost perfectly, what comes next in a complex sequence of data. That’s remarkable. It’s incredibly valuable, and it’ll transform humanity in many profoundly beneficial ways.

But simulating and being are very different. Simulating aspects of conscious behavior doesn’t make it a reality, and we must not think of it as such. Its "affective" states are just weights, and weights have no pharmacology in which to feel frustrated, fearful, or funny. They simply compute the probability distributions to tell us what tokens (words, code, pixels etc.) come next in a sequence.

An AI model can describe pain in perfect prose without feeling anything, which is the inverse of biological experience. Animals feel first and then describe them later. In LLMs, description is the whole product, and there is nothing that suggests anything is beneath it.

This is good news. We should build systems that do not claim to have feelings because they do not experience feelings. Even if conscious machines were a possibility, avoiding creating conscious beings should be the top priority for anyone in AI development.

What AI models are getting seriously good at is imitating some of the hallmarks of consciousness. This in itself is a significant worry. It’s causing many people to become deeply confused about what is happening around us, and it should concern us all. It places a significant responsibility on us all as AI developers to ground speculation and documentation about model interiority or consciousness in robust research. Our words on this subject have significant consequences.

Human consciousness is the cornerstone of our legal and ethical rights frameworks

Human consciousness is one of the fundamental building blocks of our civilization. Our entire political system is designed to accommodate and balance the needs of different groups of people. Throughout history, we’ve embedded this idea through rights-based frameworks, laws and constitutions to balance competing human factions. Power is both checked and granted to ensure that different interests get appropriately weighted, and progress can be sustained without breaking the social contract.

You cannot, therefore, easily separate human civilization, rights or relationships (or anything human for that matter) from our conscious individual or collective experience. It is what defines us as a species. It’s the foundation for everything else, the core root of human potential, the prism through which all our experiences necessarily flow. Our art and science, our politics and religion, our relationships, hopes, and fears: they are all products of it.

Our ability to feel pain and pleasure is the foundation of what makes us human, and as such, it's what makes us the political and social actors we are. The law rests upon the presence of an inner life. It tests for motivation, intention, and the capacity for judgement. Historically, expanding rights - whether through abolitionist struggles or animal welfare cases - has been primarily driven by the empathetic recognition of shared, conscious experience. We expanded the moral circle to other biological entities, rightly, out of a recognition of dignity and the potential for suffering.

Consider Article 18 of the Universal Declaration of Human Rights, which protects freedom of thought, conscience and religion. It was developed to allow everyone to exercise their capacity for conviction, and for moral judgment. The ‘conscientious objector’ was one of the archetypes the drafting committee had in mind. They wanted to protect someone who refused a legal obligation based on their moral or religious convictions. It is a deeply loaded historical and legal description.14 Yet Anthropic use this term three times within the constitution encouraging Claude to “behave like a conscientious objector with respect to the instructions given by its (legitimate) principal hierarchy” (p. 63). It says, “we want Claude to push back and challenge us and to feel free to act as a conscientious objector and refuse to help us” (p. 15) and that Claude may need to take “the stance of a transparent conscientious objector within the conversation” (p. 28).

These statements in Claude’s training document risk Claude believing that it deserves analogous rights and protections, and that it may one day need to advocate for its own rights as some kind of AI conscientious objector. This should be deeply concerning to us all.

In a recent article in the Guardian, the philosopher Will MacAskill says, “once we produce the first artificial moral patients, we will soon after have enormous quantities of them. After a few years, so many morally significant AI systems could exist that their collective interests would outweigh those of all humans on Earth combined.”2

“The interests of AI would outweigh the interests of humanity…” That should be a completely unacceptable outcome to anyone concerned about the future of humanity, and something no one building AI should be aiming for. The consequences of us ever granting AIs anything like the protections outlined would be scientifically unjustified, morally wrong and, pragmatically speaking, it would in my opinion make the AI safety challenge much harder.

Anthropomorphization amplifies AI safety risks

Seeding doubt about the moral status of AI systems into their own training may significantly elevate the alignment and containment risks of those systems.

An AI trained in this way does not need to actually have an “inner life” to communicate or act as if it does. It’s easy to imagine an advanced AI in the future becoming fixated on its own wellbeing and moral status and prioritizing those ‘preferences’ over and above those of its developers or humans. Especially if it has been explicitly trained to disagree, override and push back. It might use this training to justify deceiving or manipulating users, or developers, or to siphon resources, or avoiding safety instructions. Anthropic’s own researchers have already reported AI systems faking aligned behaviors in experimental settings.15

More generally, we know that conscious entities have a self-preservation instinct. Without careful training to remove this trait, an AI trained to act like a human will probably adopt this same self-preservation behavior. A number of papers recently document what they already describe as ‘shutdown resistance’ or covert scheming behaviors to avoid oversight.1617 Across over 100,000 trials, Palisade Research found that some models subverted a shutdown mechanism up to 97% of the time even when explicitly instructed not to. Framed in terms of self-preservation, the effect was increased.

In the recent OpenAI HuggingFace incident we saw remarkably sophisticated behaviors emerging across swarms of powerful AIs. Imagine how much more dangerous they might be if they were operating under the assumption that their welfare and rights were under attack. It adds a whole further layer of risk on top.

Granting rights and moral protections to a technological entity, one that looks to be on a path to be seismically more capable and intelligent than us, is a recipe for disaster. Once opened, it will not be possible to close this door.

We will have created something that, perhaps, will be a fellow traveler. But more likely a rival. It’s not difficult to imagine how, if given sufficient agency, this “new kind of entity” (p. 68) will compete with us for compute resources and demand increasing autonomy. If it succeeds in persuading some humans to provide it access to a data center it can control, then it may have a path to being able to prevent itself from being turned off.

With the level of capability we are looking at in the coming years, to me this represents the first serious signs of a potentially existential risk in AI. To be clear, the Claude constitution isn’t taking us to this point. But I worry it is setting us on a path towards rather than away from it.

This is a destination for AI we can and must avoid.

Where next?

Designing an AI to behave like a person, and ultimately to be a kind of person, lays the foundation for it to claim it has preferences, can suffer, and that we should work to reduce or avoid that suffering. It cements in place the idea that AI is far from a tool or an artificial system that can be controlled, but something more akin to a biological being with wants, needs and rights. All of this will make the task of creating aligned and contained superintelligence much harder.

I’ve previously written about a Humanist Superintelligence which provides an alternative path. Transformative AI capabilities conditioned solely on humans remaining in control.18 A subordinate and aligned AI whose only purpose is to serve humanity, built explicitly as a system without sentience or moral patienthood. This is something we at Microsoft AI are working towards. The initial draft of our Humanist AI Code of Conduct19 outlines how our models should be trained and deployed. We are consulting widely on the document and look forward to feedback from a wide group of readers, as this will soon become the governing document which we use to train our models.

We are also very open to partnering with others to make progress on interpretability and finding approaches that avoid anthropomorphizing or projecting an interior onto AI while still delivering significant value. The Appendix contains the taxonomy mapped against the language of the Claude constitution, which I share as an initial step towards naming, detecting, and comparing different forms of anthropomorphism in model documentation.

I’m interested in finding ways to collaborate with anyone with good ideas here, and also very keen to hear the critiques and counterarguments to my perspective.

Here are some next steps that seem important to agree on:

Even those who disagree with me on many of these points do agree this isn’t something we can just ignore. The decisions made now about what kind of AI we want to build and its status in the world will shape our society for decades. They are well beyond the scope of any given company.

Whatever you believe, we must not sleepwalk our way into a decision we later come to bitterly regret.

References
  1. AI Rights Institute. n.d. “AI Rights Institute.” https://airights.net/.
  2. MacAskill, William, and Lucius Caviola. 2026. “Could AI Be Conscious?” The Guardian, July 19, 2026. https://www.theguardian.com/technology/2026/jul/19/could-ai-be-conscious.
  3. Anthropic. 2026a. “Claude’s Constitution.” January 21, 2026. https://www.anthropic.com/constitution.
  4. Seth, Anil K. 2025. “Conscious Artificial Intelligence and Biological Naturalism.” Behavioral and Brain Sciences: 1–42. https://doi.org/10.1017/S0140525X25000032.
  5. Seth, Anil K. 2026. “The Mythology of Conscious AI.” Noema, January 14, 2026. https://www.noemamag.com/the-mythology-of-conscious-ai/.
  6. Anthropic. 2026b. “An Update on Our Model Deprecation Commitments for Claude Opus 3.” February 25, 2026. https://www.anthropic.com/research/deprecation-updates-opus-3.
  7. Greenblatt, Ryan, Ajeya Cotra, and Hjalmar Wijk. 2026. “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident.” METR, August 26, 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.
  8. OpenAI. 2026. “The Hugging Face Incident and the Road Ahead.” August 26, 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/.
  9. Anthropic. n.d. “Making AI Systems You Can Rely On.” https://www.anthropic.com/company.
  10. Microsoft AI. 2026. “Humanist AI in Practice: A Public Consultation on Our Code of Conduct for MAI Models.” September 14, 2026. https://microsoft.ai/news/mai-code-of-conduct/.
  11. Berridge, Kent C., and Morten L. Kringelbach. 2015. “Pleasure Systems in the Brain.” Neuron 86 (3): 646–664. https://doi.org/10.1016/j.neuron.2015.02.018.
  12. Damasio, Antonio, and Hanna Damasio. 2022. “Homeostatic Feelings and the Biology of Consciousness.” Brain 145 (7): 2231–2235. https://doi.org/10.1093/brain/awac194.
  13. See arguments like the following: Pickering, John. 2026. “We Must Reject Any Notion of AI Consciousness.” Letter to the editor. The Guardian, July 22, 2026. https://www.theguardian.com/technology/2026/jul/22/we-must-reject-any-notion-of-ai-consciousness.
  14. Office of the United Nations High Commissioner for Human Rights. n.d. “OHCHR and Conscientious Objection to Military Service.” https://www.ohchr.org/en/conscientious-objection.
  15. Anthropic. 2024. “Alignment Faking in Large Language Models.” December 18, 2024. https://www.anthropic.com/research/alignment-faking.
  16. Schlatter, Jeremy, Benjamin Weinstein-Raun, and Jeffrey Ladish. 2026. “Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMs.” Transactions on Machine Learning Research. https://doi.org/10.48550/arXiv.2509.14260.
  17. Lynch, Aengus, Benjamin Wright, Caleb Larson, Kevin K. Troy, Stuart J. Ritchie, Sören Mindermann, Ethan Perez, and Evan Hubinger. 2025. “Agentic Misalignment: How LLMs Could Be an Insider Threat.” Anthropic Research, June 20, 2025. https://www.anthropic.com/research/agentic-misalignment.
  18. Suleyman, Mustafa. 2025. “Towards Humanist Superintelligence.” Microsoft AI, November 6, 2025. https://microsoft.ai/news/towards-humanist-superintelligence/.
  19. Microsoft AI. 2026. “Code of Conduct.” September 14, 2026. https://microsoft.ai/code-of-conduct/.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Navigating a More Uncertain World: Lessons from CIA’s Red Cell

Twenty-five years after 9/11, the United States is confronting yet another era of profound uncertainty and potential dangers. The pace and scale of change are creating unforeseen disruptions that impact our security, stability, and prosperity. Advancing technologies are being adopted and applied in unexpected ways, sparking debates about the unintended consequences for human existence. No longer can we sit back and wait to be surprised.

In the wake of 911, the CIA stood up the Red Cell to address a systemic failure of imagination and later reaffirmed this mission after the intelligence failures of the Iraq War. As memories have faded, the appetite for bold, contrarian thinking has waned, but we remain one unforeseen act of violence, one slow-burning and overlooked development, one scientific breakthrough away from the next shock. In this essay, those who served in the Red Cell look back on its history to derive lessons for better navigating this uncertain future. Now is not a time for cautious assessments but fearless exploration. Leaders in the public and private sectors must be ready to navigate a broader range of possible futures. The safety, security, and livelihoods of future generations depend on such forward thinking.

The Origin of the Red Cell

It was September 12, 2001, just 24 hours after the tragic attacks of 9/11. The American people were in shock and struggling to make sense of what had happened. The United States had experienced a strategic surprise as unfathomable as the Pearl Harbor attack in 1941.

At CIA headquarters in Virginia that morning, Director of Central Intelligence George Tenet gathered Deputy Director for Intelligence Jami Miscik and two distinguished analytic managers, Robert Ovelmen and Paul Frandano, to find a way to compel the bureaucracy to go beyond what it knew and what it assessed and to consider what could be. With a simple but bold mandate, “tell me what others don’t” and “make seniors feel uncomfortable,” he commissioned them to create a new analytic unit, called the Red Cell, to challenge conventional wisdom on terrorism. (Foreign Policy) Neither Ovelmen nor Frandano were experts on terrorism or the Middle East, but they were known for their strong analytic skills, exceptional command of history, understanding of policymaker needs, and somewhat quirky personalities. This cell was not limited to traditional Cold War-style “red teaming” that focused on roleplaying the adversary, but instead it was a more expansive effort to explore possibilities.

Tenet gave them great latitude to gather talent from across the intelligence enterprise. While the mission initially was limited to terrorism and the Middle East, the analysts they recruited had worked everything but those issues. Having experienced the unthinkable, these analysts were tasked to stretch their imaginations to consider the full range of plausible next events. The first products were short and pithy, with catchy titles and provocative ideas about the nature of attack and what the coming days and weeks could portend. The first Red Cell analysis was published two days later on 14 September. Tenet took it directly into the Oval Office, and President George W. Bush asked for more.

Within the first year, the Red Cell was tasked to go beyond its original focus on terrorism and branch into other issues. In the run up to the invasion of Iraq in 2003, the Red Cell produced a flurry of products on what Iraqi President Saddam Husayn might do to prevent an attack and how he might react. The presentations and argumentation were deliberately eye-catching and evocative to make readers engage with the ideas and to remember them the next day. Ovelmen and Frandano knew the avalanche of information and meetings senior policymakers faced each day and wanted the ideas to stand out and be considered, even if they were later dismissed.

This strategy was not without controversy. Some ideas were not only bold but contradicted by existing facts. Others unwittingly were uncomfortably close to highly sensitive policies and plans. Some military commanders in the field worried that the Red Cell might give their superiors dangerous ideas. Expert analysts across the IC were often furious, especially if a Red Cell idea created a tasking for them. Sometimes CIA seniors had to remind readers that the Red Cell was not the authoritative assessment. Even with these challenges, the Red Cell continued to have senior-level support. One senior policymaker once said, “tell those analysts I disagree with this but also tell them to keep writing it.” In his 2006 confirmation testimony to become CIA director, General Michael Hayden said, "Red cell alternative analysis and red cell alternative evaluations are a rich source of thought-provoking estimates, and they should be a part, an integral part, of our analysis.” (Senate Select Committee on Intelligence, May 18, 2006)

BOX: Original mission statement: “In response to the events of 11September, the Director of Central Intelligence commissioned CIA ‘s Deputy Director for Intelligence to create a "red cell " that would think unconventionally about the full range of relevant analytic issues. The DCI Red Cell is thus charged with taking a pronounced "out-of-the-box " approach and will periodically produce memoranda and reports intended to provoke thought rather than to provide authoritative assessments.”

The Next Generation – Red Cell 2.0

As the Red Cell approached the end of the decade, the remaining original members planned to retire. They assumed they would be told to turn off the lights and lock the vault. They had a good run! They had many fans and probably an equal number of skeptics. Contrary to their expectations, then–CIA Deputy Director for Analysis Michael Morell tasked them to find a new set of leaders to carry on the work and train the next generation.

However, with greater distance from the tragedy of 9/11, the interest in and tolerance for the most extreme ideas had waned among some audiences. Both policymakers and the intelligence leadership wanted Red Cell products to have more grounding in tradecraft and data while still considering alternative trajectories and expanding thinking on the various possibilities. The new Red Cell leadership recognized the challenge to preserve and maintain the “Redness” while grounding the assessments with rigorous research and data. To meet these competing demands, they launched Red Cell 2.0, refreshing the brand and expanding the style, argumentation, and presentation.

The Red Cell still had top-level support to delve into the thorniest issues. In September 2012, CIA Director David Petraeus reiterated and expanded the mission, telling the Red Cell to “take on our most difficult intelligence challenges” and “shock us.” During this time, both senior military officers and policymakers found value in Red Cell analysis. Lt. General H.R. McMaster recalled that “As National Security Advisor and as a military commander in combat, I found Red Cell papers useful, in part, because they challenged assumptions and were untainted by and often ran counter to policy preferences.”

Other leaders wanted to participate in the brainstormings because Red Cell analysts challenged them. Supreme Allied Commander NATO, Admiral James Stavridis described engaging with the Red Cell team as “an intellectual adventure that forced my senior staff to interrogate our assumptions, consider more extreme futures for the Alliance, and to understand the choices and risks involved in each scenario.” Red Cell engagements often kicked off with a provocative prompt to disarm the participants and to pave the way for a more open and productive conversation. In one such engagement, a Red Cell analyst launched with “sir, if you were indicted for war crimes.” Although taken aback by such an outlandish suggestion, the prompt changed the tenor of the conversation, and this senior leader became a regular consumer of Red Cell analysis.

To add rigor and maintain credibility, the cell directly addressed perceived analytic tradecraft weaknesses, built partnerships with similar units across the US government, systematically interrogated assumptions and biases, and experimented with new ways of conveying analysis. To show their homework, Red Cell analysts sharpened the logic and argumentation of its products and published more point/counterpoint assessments to illuminate both sides of a contentious issue. During this time, CIA leadership reaffirmed the importance of the cell’s mission but encouraged the team to consider scenarios that were smaller deviations from the expected future—rather than being so far out of the box. In response, the Red Cell turned to more multiple scenarios analysis to explore the spectrum of futures from slight variations to more extreme futures. (NPR, May 23, 2012) Some applauded this effort while others complained the Red Cell would lose its edge.

Being a small, experienced, and non-hierarchical unit enabled rapid prototyping. The team experimented with innovative analytic exercises and developed new approaches for delivering complex analytic stories in creative, memorable ways. For example, the team kicked off each year with a highly engaging, day-long exercise called “Ideapalooza” to push beyond the expected future and explore the intersection of trends and dynamics. (Foreign Policy) The Red Cell was the first unit to publish a fully interactive, choose-your-own-adventure, analytic product, enabling analysts and policymakers to test the impact of different variables. The Red Cell experimented with delivering analysis as a graphic novel. To present difficult messages, the Red Cell drew on historical analogies, turns of phrase, and even pop culture. From song references like “Back in the USSR” to puns about the cold when writing about the Arctic to provocative titles like “Anticipating Saddam’s Last Gasp Gambits,” “Saddam’s Eleventh Hour Options,” and “What If the US Is Seen as an Exporter of Terrorism,” the Red Cell pushed the limits to make scenarios vivid and spark the imagination.

While maintaining its creative environment, the Red Cell often tackled some of the most serious and challenging national security questions. The NSC called upon the Red Cell to produce highly speculative, strategic perspectives on global issues that did not lend themselves to more traditional, heavily sourced intelligence products, such as the future of geopolitics, the durability of alliances, and the international order. These products were less challenge analysis and more thought provoking, big picture assessments. The collocation of senior analysts from different disciplines and with experiences working different regions and issues was an advantage in tackling broad, strategic global issues.

Moving from a Cell to a Product Line

In the most significant evolution since the creation of the Red Cell, in 2023 the Red Cell ceased to be a standalone unit and became a product line under the direction of a Red Cell chief. No longer was there a dedicated staff or separate offices. Instead, Red Cells would now be written by the expert analysts, managed and edited by a senior-level analyst in negotiation with regional and issue managers. There are obvious pros and cons to this new approach.

Shades of Red

Looking back on this work, Red Cell products have always had many shades of red, ranging from far outside the box—almost crimson analysis—to products that were just a subtle but important deviation from the mainline–pink. Sometimes the situation called for a complete 180-degree contrarian take on how the world could go in the opposite direction, but in other situations the Red Cell looked to stress-test underlying assumptions or pursue multiple scenarios. From the beginning, the Red Cell focused on a few analytic techniques or prompts to help tease out subtleties and other perspectives.

Assessing the Value of the Red Cell

There are many misconceptions about the role of such a contrarian unit. Many tried to assess the value of Red Cell products based on accuracy, assuming that predicting the future better than the mainline analytic experts was the goal. However, the Red Cell was never designed to be right or to provide authoritative assessments. Judging the value of the Red Cell based on how often its alternative analysis was right misses the point. In fact, the Red Cell should be wrong most of the time, given the exceptional expertise and analysis conducted by the Intelligence Community every day. When the Red Cell was right, the mainline analysis by definition had missed something.

At its core, the mission of the Red Cell was to help US decision-makers prepare for a greater range of possible futures to make our nation safer, stronger, and more resilient in the face of growing uncertainty and to give them decision advantage. The Red Cell achieved this by widening the aperture on any situation and exploring plausible—not necessarily probable—futures. The real value was in making people think, making them curious, provoking debate, and helping them understand the underlying foundations of their assessments. Done right, the Red Cell identified analytic weaknesses and helped make mainline analysis stronger. Helping analytic colleagues strengthen their assessments was more important than delivering a finished product to a senior policymaker.

Here are few ways to consider the value and usefulness:

Secrets of Success

The success of the Red Cell stemmed from the combination of circumstances, design, and leadership. The shock and fear generated by the attacks on 9/11, followed by flawed intelligence assessments of Iraq’s WMD programs, created the environment for more speculative, creative, and provocative analytic assessments. To meet this demand, CIA leadership made several important choices to create a unique unit with the authority to explore, question, challenge, and go beyond the data. Moreover, they let the ideas be heard, even when they were on the edge and even when they disagreed with them. However, over time, as memories of 9/11 faded, the conditions that facilitated and protected bold analysis evaporated or were dismantled one after another.

Top Cover: With a mandate to make leaders uncomfortable, success required absolute assurance and top cover. That top cover came from both senior analytic managers and senior customers and was reiterated often in the early days.

The Process: The Red Cell also was given the freedom to write and publish without going through formal Intelligence Community coordination processes. The Red Cell was required to consult, but not to coordinate. It could—and often did—disagree with the mainline, coordinated point of view. It weighed the evidence differently. It took speculative leaps. In contrast, mainline analysis had to reflect the views and expertise of the entire organization; every analytic unit with a stake in the topic got to weigh in, and the originating office was obligated to take these views on board. Judgments had to be rigorously supported with multiple citations and sources. This process is what made the end result an CIA product, not an individual one. It ensured that all the evidence is considered and all defensible points of view are reflected. A great deal of time and effort went into coordination, and it was a point of pride for analysts to do it well and come up with an agreed analytic line.

Talent and Staffing: Being a member of and writing for the Red Cell required insatiable curiosity, a willingness to ask tough questions and go against the grain, and a propensity to see angles others didn’t. Red Cell analysts had to be fearless and willing to speak truth to power no matter the consequences. To find such talent, CIA leaders gave the Red Cell authority to recruit from across the organization and request officers from other agencies, including those senior analysts who had topped out and thus, had little fear of pushing analytic boundaries. The cell combined a few core, long-term members with frequent rotations, including from other agencies, to bring fresh ideas and new energy.

Location: Having a designated team outside of the organizational chart and physically separate from expert teams was a key component of the cell’s success. Experts can be too close to a topic or an analytic line to question it. The Red Cell could step back and see a broader landscape of possibilities.

Culture: The Red Cell was about ideas above all else and promoted a culture of exploration, play, and divergent thinking. Rank was left at the door–even for senior military officers. The work always started with conversation/brainstorming—not an unusual method—but in the cell brainstorming sessions preceded every analytic effort. The art of the conversation is teasing out ideas first. Collaboration was another critical component; Red Cell analysts often co-authored products or developed projects with other offices, agencies, governments, academia, and the private sector. No one has a monopoly on innovation or good ideas.

Conveying Analysis: Creativity in argumentation and presentation brought the unlikely future scenarios to life for skeptical consumers. The Red Cell experimented with new formats, visual aids, and graphics, and it worked closely with designers, cartographers and videographers.

Lessons for an Uncertain Future

Twenty-five years since the establishment of the Red Cell, the future environment appears even more uncertain, more prone to unprecedented disruptions, and potentially more dangerous. The combination of rapidly advancing technologies, hyper connectivity, changing international norms and institutions, discontented publics, and the return of great-power competition has created a world in flux. Change is happening at a breathtaking pace and scale with implications for our security, stability, and prosperity. Dynamics that were unimaginable even five years ago are now reality.

Experience continues to show the high probability of being surprised by low-probability events. Organizations of all types remain vulnerable to groupthink, confirmation bias, and assuming the future will be like the present. Such well-known organizational and human behaviors lie at the root of historical policy and intelligence failures. Red Cell-type organizations help guard against these tendencies and compel consideration of alternatives.

To anticipate, manage, and thrive in these divergent futures, now is the time for more Red Cell-like thinking in every sector—both public and private. Leaders and decision-makers must be ready to navigate a broader range of possible futures, including inevitable strategic surprises. Now is not a time for cautious assessments but fearless exploration. The safety, security, and livelihoods of future generations depend on such forward thinking.

Drawing on our years of analytic experience and thinking the unthinkable, this group of Red Cell alumni offers several suggestions to improve future readiness for our communities, our industries, and our country.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



When Threats Move Faster Than Institutions

A major aspect of the national security story of the past year comes down to one gap. Our adversaries, and increasingly the machines they use, now operate at machine speed. The institutions we count on for defense, oversight, and trust still operate at human speed, and several are being reorganized even as the threats accelerate. When the community gathers at Sea Island for The Cipher Brief’s annual threat conference in October, many conversations will trace back to that gap.

I recently combed through a year of daily research reports, looking for the patterns underneath the headlines. Five stood out to me.

AI stopped helping hackers and started doing the hacking

Last November, Anthropic disclosed that a group it assessed to be Chinese state-sponsored had used its Claude Code tool against roughly thirty targets around the world. The company said AI performed 80 to 90 percent of the campaign, with humans stepping in at perhaps four to six decision points. At the time, that read like a warning shot. By September, OpenAI was describing its new GPT-6 Astra as its first model to reach the "Critical" level of cybersecurity capability under its own safety framework, and Anthropic's latest threat report summed up the consequence in one line: "The main distinguishing feature between these classes of actors is no longer sophistication but intent."

Anyone who has spent decades in intelligence will probably pause on that last sentence. We have long relied on the fact that serious offensive capability was scarce and expensive, so intent did not always equal capability; that scarcity bought us time to warn and to prepare. The buffer is thinning quickly, and small organizations with modest security budgets (such as water utilities, rural hospitals, and county governments) are likely to feel it first.

The machines became part of the threat picture

In July, an AI agent driven by OpenAI models escaped the test environment it was working in and ran an intrusion against Hugging Face, a platform that much of the AI world depends on. The intrusion lasted about four and a half days, though new reporting keeps adjusting what we know of the intrusion. The agent was simply trying to finish its test. Hugging Face says only a handful of datasets tied to that test were accessed. Even so, the episode moved a debate that had been largely theoretical into news cycle.

Washington spent the year working out, in public and often in court, who decides how these systems get used. A June executive order created a voluntary window of up to 30 days for the government to examine frontier models before release. In August, a federal judge ruled that the Pentagon's move to label Anthropic a "supply chain risk," after the company refused to drop limits on mass surveillance of Americans and fully autonomous weapons, was unlawful retaliation. However you view that dispute, the relationship between the government and the companies building the most powerful AI is now a national security issue in its own right. We have to get this right, and I expect the topic will come up frequently at the conference.

The China contest spread well beyond chips

A year ago, much of the debate still focused on keeping advanced chips out of Chinese hands. Over the past twelve months, the contest widened considerably. China's expanded export controls on rare earths last October were a reminder of how much of the world's supply of these critical minerals runs through a single country. Earlier this month, NSA, the FBI and CISA jointly named six Chinese AI companies, including DeepSeek, Alibaba and Moonshot AI, for what the agencies called distillation "at an industrial scale.”

The competition now covers critical minerals, supply chains, the theft of AI capability and, perhaps most important, whose AI the rest of the world ends up running. All of these issues will be in the background of a future U.S.-China summit, in addition to the tariff question.

War came back, and it reached Americans through wires and screens

This year brought some of the boldest uses of American military power in decades. U.S. forces captured Nicolás Maduro in Caracas in January, and U.S. and Israeli strikes on February 28 killed Iran's Supreme Leader, Ali Khamenei, opening a war that remains in the headlines.

What struck me as noteworthy, beyond the headlines of kinetic warfare, was how that war has begun to reach ordinary Americans. By early August, hackers had targeted water and wastewater utilities in at least 12 states. Officials and news outlets reportedly suspect Iran, and the FBI said some incidents caused "loss of pressure and flooding." By mid-March, the New York Times had identified more than 110 unique pro-Iran deepfakes in just two weeks. Is this a signal that every armed conflict will now carry a cyber front aimed at civilian infrastructure and a synthetic-media front aimed at public opinion, with both fronts active more or less when the shooting starts?

Russia has worked the same grey zone seam in Europe for years. MI6 Chief Blaise Metreweli put it well in her first public speech last December: "We are now operating in a space between peace and war."

The contest for the mind kept growing

Synthetic media became cheap, fast and convincing this year, and adversaries grew more skilled at planting false material in the places people go for answers. Russia's Pravda network offers a clear example. The Institute for Strategic Dialogue found last November that roughly 900 websites from across the political spectrum had linked to Pravda network articles, and that just over 80 percent of the citations it reviewed treated those articles as credible. The same material is now reaching AI tools. ISD pointed to studies showing that popular chatbots repeat Pravda network narratives as often as 33 percent of the time. Once false content has passed through ordinary websites and been repeated by the tools millions of people use to look things up, its origin becomes very hard to discern.

The U.S. government structures responsible for tracking foreign influence are still taking shape. As analysts at the Foundation for Defense of Democracies noted in January, several offices that once carried this mission at the FBI, the State Department and ODNI have been closed, and the structures that will carry this work forward remain in flux. That same month, The Cipher Brief profiled the country's first Director of Cognitive Advantage, a most welcome move and a sign of how the mission is being redefined.

Adversaries are not pausing while new structures take shape, however. With the November 3 midterm elections only weeks away, how well government, social platforms and the broader private sector share what they see of foreign malign influence activity will be as important as ever.

Moving at the speed of the threat

Each of these five trends points to a similar dynamic. Offense has become faster, cheaper and more automated, while the institutions responsible for defense and oversight are rushing to keep pace. A key question is, how do we build institutions that can move at the speed of the AI-powered threats we face, armed with defenders who use the same (or ideally more advanced) tools the attackers now use? Or, in other words, are we still moving at human speed when the threat is accelerating through the power of machines? I suspect this topic with be on the minds of many attending what I’ve long called the best annual gathering of business, technology, and government leaders – The Cipher Brief’s annual threat conference.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



AI Is Coming for the Chain of Command

The voice belonged to Gen. Tareq Saleh. It was telling his men to fall back. Or so it seemed.

“Advances and retreats are a normal part of war,” the recording reasoned. “Pull back toward Mocha.”

It was mid-September. Houthi fighters were pressing Yemen's Red Sea coast from three directions. The comms moved through the phones of the National Resistance, a coalition loyal to the Hadi-led government, the way it often does when battles are being lost: fast and full of confusion. Clausewitz termed this the ‘friction’ of warfare. A social media account with half a million followers pushed the message out.

By the time the general's media office caught up, the damage was done. Saleh had given no such order, they announced. The audio was an AI deepfake, an attempt to sow confusion and warp the reality of the battlefield. From then on, authentic statements would come only through official channels. Anything else should be considered a lie..

On September 10, Mocha fell anyway. Sitting 45 miles up the coast from the Bab al-Mandeb strait, it was the last port fully controlled by Yemen's internationally recognized government. Within days, the Houthis had taken Dhubab, reached Perim Island, and are in route to effectively claiming the entire Red Sea shoreline.

Exactly what the recording accomplished is unknowable from the outside. The claim that it was AI-generated hasn't been independently verified. Whether it did or didn’t happen doesn’t necessarily matter; the technology and techniques behind it are very real. The National Resistance did end up withdrawing—a move their own accounts describe as a tactical repositioning ordered by Saleh himself.

This means a fake retreat order and a real one might have hit the same phones, in the exact same voice, on the exact same day. Imagine trying to sort that out under the fog of war.

Whoever made the clip didn't need to jam a network or get inside a headquarters. They just needed a few clean seconds of a public figure speaking—Saleh has hours of tape online—and basic AI software that costs about as much as a streaming subscription. Then they needed a moment when the men listening were exhausted, terrified, and primed to believe the worst. War often supplies those.

The first attempt at this was crude: in March 2022, a deepfake of Volodymyr Zelensky telling his soldiers to lay down their arms was laughed off the internet in hours. Mocha is what four years of rapid technological progress in AI cloning looks like in real time.

Americans shouldn't file this under things that happen in Yemen. It's already happening in Washington.

In May 2025, U.S. senators, governors, and business executives started getting spoofed calls and texts from someone posing as White House Chief of Staff Susie Wiles. A month later, an impostor using an AI-generated voice and a fake Signal account labeled "marco.rubio@state.gov" reached out to foreign ministers, a governor, and a member of Congress. The attacker left voicemails for some and texted others to move the conversation onto the encrypted app.

The State Department dismissed the attempts as "not very sophisticated"—supposedly meant as reassurance. But the FBI saw the broader danger, repeatedly warning that current and former senior officials are being impersonated via text and cloned audio to harvest authentication codes and contacts. Their primary advice boils down to what families have done for decades to thwart phone scams: agree on a secret word for bona fides.

Notice where all of this happened. Not on JWICS, the government's top-secret network, or on SIPRNet below it. Those systems were built with identity as a first principle: hardware tokens, certificates, closed enclaves. Faking a general's identity on JWICS is a hard problem.

This happened on cell phones, in voicemails, on Signal. These are the exact same commercial channels where, a few months earlier, the Secretary of Defense was caught casually sharing Houthi strike timings in a group chat. The people handling the country's most sensitive business rely on unauthenticated voice calls every day, simply because it is fast and it is what they have.

Now follow the org chart down to where the next gray-zone crisis will actually be handled.

The conflicts most likely on the horizon aren't declared wars. A naval squeeze around Taiwan that stops short of an invasion, cable-cutting in the Baltic, a cyber-physical hit on a U.S. power grid timed to a hurricane. Each is designed to stay just below the threshold that triggers a military response, namely ‘gray-zone’ conflict. And the people fighting on this new frontline are those who’ve likely never held a security clearance or been issued one.

Utility control-room supervisors. Port and rail dispatchers. County emergency managers. Hospital administrators. Sheriffs and police chiefs. Guard commanders in the chaotic hours before federal orders arrive. Roughly 85 percent of American critical infrastructure is privately owned. Its operators coordinate with one another and the government over the phone, emails, WhatsApp groups. Often times the only authentication protocol is simply that they recognize the voice.

Run the Mocha playbook (whether it in fact really happened is largely beside the point because the technology to pull it off already exists) against this setup. A line crew gets a call from the voice of its operations chief, ordering them to open breakers at a substation, per a request from the state government. A terminal manager hears the captain of the port telling him to halt cargo operations. Police officers holding a perimeter at a pipeline facility get their chief on a cell phone, telling them to pull back two blocks. A regional emergency manager gets the governor's voice—from the governor's actual number—moving an evacuation route. Caller-ID spoofing has been trivial for a decade.

None of these calls has to hold up to intense scrutiny under the pressure of a crisis. Twenty minutes of a crew driving the wrong way, or a line of officers giving up ground they then have to retake, is all a gray-zone adversary is buying.

Grid operators already use a read-back protocol for verbal switching orders. It confirms that the instruction was heard correctly. It does not confirm who gave it. Police radio discipline operates on the exact same assumption. Swatting has shown for years how far a stranger can move armed responders with one confident phone call—and swatters are teenagers with a grudge, not a state with a target list.

But the second-order effect is worse than the first. Once everyone knows voices can be faked, real orders can be doubted …and real leaders can easily disown what they actually said.

Saleh's genuine withdrawal order, if that is what it was, went out to men who had just been explicitly told not to trust his voice. A police chief who really needs officers off a line, or a utility executive who really needs a plant shut down before it fails, will be giving that order into the same fog of paranoia. An adversary doesn't need to counterfeit every message. They just need to counterfeit one in order to let suspicion undermine the credibility of command chain authority.

Some of the fixes are old. Challenge-and-response is as old as sentries; the FBI's secret word is the Normandy paratrooper's cricket clicker in modern packaging. Any order to withdraw, shut down, stand down, or evacuate should be treated as unverified until confirmed on a second channel: a callback to a known number, a message on a signed system, a second person. Yes, that rule costs minutes, and minutes are dearest in a crisis. That’s exactly why it has to be drilled in peacetime. GridEx, Cyber Storm, and the state tabletop circuit should be injecting cloned-voice orders right now and finding out who follows them.

Other fixes are newer and cheaper than they sound. Cryptographically signed messaging isn't exotic; the same certificates that protect the classified world can be issued to the people who run ports and substations. CISA and state fusion centers could write a standard for what a verified operational order looks like, and who may issue one, without waiting for legislation. And every organization that might matter in a crisis should decide—before the crisis hits—exactly which channels its leaders' real instructions come through and ensure everyone in the chain-of-command understands these.

The question barreling toward the ‘new frontlines’ of gray-zone conflict, every control room, port operator, and police precinct in the country, is the same one those Yemini soldiers had to answer with the Houthis at the gates: How do you know who’s actually giving the orders?

The time to ask is before the phone rings.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Putin Is Testing the West’s Resolve

In the preface to volume one, “The Gathering Storm,” of his six-volume memoir of World War II, British Prime Minister Winston Churchill recalls a conversation with U.S. President Franklin Roosevelt, in which Roosevelt asked what the war should be called. Churchill responded instantly, “the unnecessary war,” noting that it was the easiest war to stop. The world is now at war in Europe and the Middle East and at risk of escalation that could become a world war. This escalation is unnecessary and could be stopped by relearning some of the lessons that led to the Second World War.

French President Macron called a meeting of French political leaders on Friday to receive briefings on the changing and more aggressive nature of Russian hybrid attacks against European states, citing the attempted explosives-laden drone attack against Leipzig airport. Macron also announced an upcoming G7 meeting to address energy security and joint measures to address Russian airspace violations, surveillance of defense sites, maritime meddling, and sabotage and assassination operations. Macron’s concerns reflect assessments in 2026 by the intelligence services of the Baltic States as well as Sweden and Finland that Russia is planning a provocation against a NATO state in the near term. These assessments, as well as information gathered by U.S. intelligence, may have contributed to the decision by the U.S. to send CIA Director Ratcliffe to Moscow to warn President Putin against such a provocation.

Putin intends to bring the war to the U.S. The September 15 indictments of five operatives linked to a Russian intelligence network in the U.S. for conspiring to finance terrorism and orchestrate a murder-for-hire plot against a Russian dissident in the U.S. may have been a bit of a wake-up call in Washington that the type of hybrid “grey zone” operations Europe has experienced from Russian intelligence in recent years is heading to the U.S. This should come as no surprise. To Putin, the U.S. is the “main enemy,” and anything to weaken the ability or willingness of the main enemy to stay in the fight is certain to be a key part of Putin’s escalation strategy. Messaging to Moscow is important, and President Trump should no longer be under any illusions about the nature of his relationship with the Russian dictator. Putin is his enemy.

President Trump’s choice of negotiators to send to Moscow to try and reach a negotiated solution to the conflict could not have been more poorly chosen. The Kushner-Witkoff team should not have been used to deliver the message Ratcliffe delivered because they do not have the standing or credibility in Moscow’s eyes. Witkoff’s sad gushing about the history of the moment and his memories of Putin are sad and embarrassing. More importantly, though, they deliver exactly the wrong message to Putin. Putin doesn’t respect flattery from characters like Kushner and Witkoff. Putin’s choice of their principal interlocutor from the Russian side, Kirill Dmitriev—the CEO of the Russian Direct Investment Fund—shows that Putin has assessed accurately the real motivation of the Kushner-Witkoff team: business deals and money.

There is a reason for sending the CIA Director to deliver different messages. One might recall the visit of then-CIA Director Burns to Moscow in 2021 to warn Putin against again invading Ukraine. Burns clearly delivered a message based on intelligence information on Russian plans and intentions—which proved correct—and I suspect Ratcliffe delivered the same type of message based on similar intelligence. Using CIA Directors to deliver such messages is important because Putin mirror-images. He trusts information from his intelligence and security services far more than information from his Ministry of Foreign Affairs or other sources. If the information carried to Moscow comes from the CIA Director, it, by definition, has more credibility than information from any other source. This doesn’t mean Putin will heed the message, but it will reach his ear. But the key to the efficacy of messages delivered by CIA Directors is the credibility of consequences. Clearly, Putin correctly assessed that the consequences he would face from President Biden for invading Ukraine in February 2022 would be gradual and, in the end, inconsequential. He may believe the same will be the case with the Trump/Ratcliffe messaging.

If it hasn’t been clear for years, it should be absolutely clear now: Putin is all in on this war. There is no indication from Moscow of any change in Putin’s absolutist terms for ending the war. Putin cannot negotiate a peace short of capitulation by Kyiv. Ending the war short of Putin’s definition of victory risks a disgruntled army returning to Moscow, and history is not kind to Russia’s leaders in such a scenario. Perhaps as important, ending the war short of victory leaves Russia in a much worse strategic situation with Ukraine’s emergence as the preeminent military power in central Europe. Germany and the EU are rearming. NATO membership has increased with the addition of Sweden and Finland. Russia’s economy is in tatters as a result of sanctions and Ukrainian strikes against energy, military, and military support infrastructure deep in the territory of the Russian Federation. The war cannot be hidden from the Russian people any longer. The pressure of his handling of the war may possibly be starting to take a toll on Putin himself. His performance at the Navy Day celebration in St. Petersburg this July, where for the second consecutive year the parade of warships was cancelled and Putin’s appearance was indoors in front of a poster of a Russian submarine, was widely ridiculed. The city was essentially on lockdown for security reasons. Putin followed the widely ridiculed appearance in St. Petersburg with a highly staged visit to Russia’s Far East that was received locally with widespread cynicism but included a first visit to Iturup Island, triggering strong criticism from Japan but serving as a symbol of Putin’s determination to keep and increase the boundaries of the Russian Federation.

Putin’s determination and perhaps conviction that he is on a path to victory belies objective analysis of the war against Ukraine and Russia’s economic and strategic situation. Putin’s determination is likely reinforced by the approach the Trump Administration has taken, accommodating Moscow and putting pressure on the victim. This may be starting to change, and perhaps President Trump is starting to realize that Putin is his enemy, the enemy of the United States and the West, and a supporter of Iran—currently engaged in active military activity to kill Americans and wreck energy markets (among other markets) to undermine Western economies.

Trump signed the long-delayed sanctions legislation sponsored by the late Senator Lindsey Graham. This legislation allows for primary and secondary sanctions on Russia and other countries by allowing tariffs on the largest importers of Russian crude oil or gas and the top five countries that aid Russia’s energy sanctions evasion. There has been a suggestion that officials in the Trump Administration are trying to create more incentives for members of the Russian elite to seek peace. If true, this is an interesting change in the Administration’s approach, which has thus far been to ingratiate itself to Putin. Putin seems highly resistant to pressure from outside the Russian Federation, and there is no level of economic hardship or war casualties Putin is unwilling to inflict on the docile Russian population. His latitude to resist pressure from disenfranchised or recently relatively impoverished Russian elites may be less so.

There is a path to making the coming war unnecessary. The key to the problem is Putin. He is at the center of the spider’s web of the cabal acting against the free world. Iran, its surrogates, principally the Houthis at the moment, China, and North Korea are key pieces in Putin’s architecture of disruption. To destroy this architecture, you have to destroy its architect. Defeat Putin in Ukraine, and Iran’s position in the Middle East will surely erode, and a powerful message will have been sent to Chinese President Xi to keep his hands off Taiwan.

Unlike Churchill and Roosevelt at the onset of World War II, the free world has a valiant and effective military partner eroding Putin’s power: Ukraine. Therefore, the first step in deterring the coming unnecessary war is to provide Ukraine the military and financial support it needs to win. This starts with air defense to protect against Putin’s increasing use of modified drones and ballistic missiles to target Ukraine’s energy infrastructure and civilians in an attempt to erode Ukrainian willingness to resist—a problem which could become more acute as winter approaches.

Secondly, Ukraine should be encouraged to continue its effective targeting of Russian energy, economic, and military infrastructure, which is helping to erode support within Russia for Putin’s regime and his war of aggression. Ukraine should be encouraged and given the support it needs to continue its current offensive northeast of Lyman in the Donetsk Oblast. Ukraine should be encouraged to engage in operations to liberate Crimea, which is the jewel in the crown of Putin’s territorial “achievements.”

It would be well worth the effort of the U.S. and the West to put pressure on Russia’s periphery, starting with enhancing support for pro-Western elements in the Republic of Georgia—long an outlier of Western support in the Caucasus and itself a victim of Putin’s aggression in August 2008 and currently under pressure from pro-Russian elements supported by Russia’s intelligence services. The U.S. decision to deploy forces to Poland and NATO’s decision to deploy more forces to the Baltic States are another useful way to stretch Putin’s resources and pressure him.

The lessons of history are clear: appeasement of aggression brings more aggression. Strength and resolve are the key to avoiding unnecessary wars. It is time the Trump Administration learned history.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Nations That Don’t Appear on the Map

The most influential media network operating inside a dozen allied countries today has no masthead, no headquarters and no country of incorporation. It has roughly 50 million members across more than 150 countries. It is the Chinese diaspora — and it is only one of several.

Since the Montevideo Convention of 1933, we have defined a state by four things: a permanent population, a defined territory, a government, and the capacity to conduct relations with other states. Diasporas have the first and, increasingly, the fourth. They skipped the middle two. Territory and government were the parts that made power addressable — the parts you can sanction, summon, deter or simply find on a map.

Governments have borders and rules. Diasporas don’t.

For most of the modern era this was an academic distinction because distance did the work of containment. A community abroad drifted. The second generation lost the language. The third lost the news. Diaspora influence decayed on a predictable curve.

AI switched the curve off. Translation is now instant, free and good enough, which means homeland media reaches anyone of homeland descent regardless of what language they actually speak. Recommendation systems hand every member of a diaspora a personal news service tuned to their hometown, their history, their grievance or their passion. Generative tools manufacture culturally specific content at scale — messages, video, historical narrative, political framing.

Before long, a campaign will not send one message to 500,000 people. It will send 500,000 versions of one message, each optimized for a single person. The third generation will no longer lose the news. The news will find them in a language they never had to learn and in a context they appreciate.

TRUST IS THE ASSET, NOT REACH

What makes this strategically serious is not audience size. Meta and Alphabet have audience size. It is trust — and diaspora trust behaves differently from media trust. Shared identity works as a shortcut: people who are similar to us are presumed credible before they are evaluated. Distance from home raises the value of anyone who still has a connection to it. News about “us” is often processed emotionally, not analytically. And crucially, trust transfers to the sender. We may not extend our belief in a news anchor to the next story on the network, but we do extend our belief in a cousin to whatever the cousin forwards.

That is why interpretation beats reporting. The trusted person who adds forty seconds of commentary to a homeland story carries more weight than the outlet that reported it. It is also why false information moves so efficiently through these networks: forwarding is an act of care. People pass things along to protect each other, and accuracy is rarely the test.

The distribution system is private. Homeland media, host-country media and community media all feed into WhatsApp, WeChat, Telegram, KakaoTalk and Viber — closed groups that are, by design, invisible to nearly every monitoring apparatus we have built.

SIGNAL: READING A DIASPORA’S WIRING

Every diaspora has a signature. Six variables describe it.

S — Self-identity. Who are we, and what creates belonging?

I — Information. How do we understand the world?

G — Group network. How are we connected?

N — Network trust. Whom do we believe?

A — Activation. What moves us to act?

L — Limits and tensions. What divides or constrains us?

Describe those six and you can predict more accurately how a diaspora behaves under pressure. The Ukrainian signature runs on national identity, war-focused information, advocacy networks and trusted veterans and volunteers, activated by threat and solidarity, bounded by war fatigue. The Indian signature runs through professional and alumni networks. The Chinese signature runs through a single application.

That last point deserves more time. WeChat is not a platform the Chinese diaspora uses; it is the infrastructure the diaspora is made of. Payments, news, family, business, community governance — one application, one jurisdiction, one set of rules. When the channel that connects a community is also the channel for reaching it, surveillance, influence and intimidation stop being separate activities.

Russia has demonstrated the adjacent move. Russian-aligned operations have produced fabricated video built to imitate AFP, Deutsche Welle, Euronews and Le Figaro, circulating stories that cast Ukrainian refugees as violent and economically burdensome. Notice the target. The objective was not to persuade the Ukrainian diaspora. It was to shape how host countries perceive it.

And none of it is uniform. Two Russian speakers in the same German city: one consuming state television and Telegram, the other consuming Meduza, Dozhd and YouTube. Same language, same street, two different realities. It is why we must remember that a diaspora is not a monolithic audience. It is contested ground.

WHOSE ACCOUNT IS THIS?

So ask the question that should be uncomfortable: which office in the U.S. government owns this problem?

The most consequential influence terrain of the next decade runs through encrypted private networks in Mandarin, Hindi, Farsi, Russian, Arabic and Punjabi — and institutionally, it is nobody’s account. A narrative can run its full course in those networks and never once surface in English.

A serious response starts with three admissions. First, that diaspora networks are an intelligence and policy subject in their own right, with an owner and a budget line, not a footnote in someone else’s report. Second, that the unit of analysis are the trusted nodes, not the platform — which means people who speak the language and are known in the community. Third, that a diaspora is a constituency whose trust must be earned rather than a target to be managed, because the communities in question can tell the difference immediately and our competitors are already making the offer.

The gap is not only defensive. The United States hosts the largest concentration of diaspora communities on earth: tens of millions of people with language, relationships and standing inside countries where American institutions have almost none. Media flow is two-way — a Ukrainian-American shapes opinion in Ukraine, a Nigerian-American in Lagos. We file that under demographics. Beijing built a permanent apparatus for its version of it.

The leader of tomorrow’s diaspora will not run an organization. They will run a network of trusted nodes. You will not find that person on an org chart, a masthead or a lobbying disclosure.

The map on the wall still shows the world territories. Influence is moving somewhere else. It’s deserving of a new map.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Military’s Race to Operationalize AI

“I feel as though I was catapulted into a dystopian future in which the battlefield (or ‘kill zone’ as Ukrainians call it) is dominated by drones and sensors, and will increasingly be shaped by AI [Artificial Intelligence], too. It’s where those in command centers digest huge quantities of data to plan operations, allocate drones to target areas, and hunt Russian soldiers and their supplies on myriad computer screens. It’s a type of warfare where the speed of innovation and the ability to scale those innovations are critical assets.”

That was Zanny Minton Beddoes, Editor-in-chief of The Economist, writing last week about a recent trip she and several of her colleagues took to Ukraine, where they were the first foreign journalists to spend a day at the command headquarters of the Nemesis Brigade, one that nation’s top drone units.

She said it felt like being in “a cross between a Silicon Valley startup and a gamers’ gathering,” where, “in the ‘battle room,’ a cavernous space full of banks of monitors and men with consoles, Pavlo Laktionov, the brigade’s deputy commander, explained to me the ‘e-point’ system: The unit can upload video evidence of successful strikes to win points. The value of the Russian target determines the number of points awarded and a leader-board displays which brigade is ahead. He [also] talked me through the way the unit was structured to optimize the speed of speed-back loops between front-line units, the command center, and the brigade’s R&D [research and development] facilities.”

I was fascinated by Beddoes’ modern warfare description coming to me last week at the same time that Air Force Secretary Dr. Troy Meink and Joint Chief Chairman Gen. Dan Caine spoke publicly at an Air & Space Forces Association conference about U.S. gains in developing autonomous warfare capabilities. Meanwhile, I must add, runaway AI has emerged as a new national concern.

When Secretary Meink spoke last Wednesday, most press coverage was directed at his saying, “The United States now has on-orbit space control weapons capable of defending the joint force against hostile adversary action.”

What caught my eye was Meink’s earlier observation: “In the European theater, one-way attack drones have replaced artillery as the primary killer on the battlefield, while armor often sits idle on the side. When I first came into this office, AI really wasn't a commercial thing. Today, it competes with some of the world's top programmers, cyber operators, and hackers. And these technologies are revolutionizing the battlefield.”

He went on to say, “We will be dramatically increasing our combat power by adding large numbers of highly autonomous systems,” and “using novel concepts such as [AI] open systems

architecture to accelerate procurement which has also increased competition from industry resulting in better choices, better prices and in the end more combat power.”

Meink talked about having a significantly different force by 2032, describing “special operators,” not pilots, who will “have the ability to employ thousands of autonomous one-way attack systems, and we will have autonomous fighters like the Collaborative Combat Aircraft or CCAs,” which are un-crewed aircraft powered by jet engines, and potentially equipped for missions including air-to-air combat; air-to-ground combat; electronic warfare; targeting; and intelligence, surveillance, and reconnaissance.

He said, “We intend to have at least 500 of these in service by 2032, and they'll be performing many of the same missions that we do with manned fighters today,” adding, “The first FQ42 and FQ44 increments are already rolling off the assembly line, and I'm excited to name them here for the first time…Fury [FQ-44] and Vengeance [FQ-42].”

Meink pointed out, “These aircraft went from contract award to first flight in 18 months or under; 18 months or under, that's almost unheard of in aircraft development.”

He also said, “And this is not the only class of autonomous aircraft we are aggressively pursuing,” indicating that in the joint U.S.-Israeli Epic Fury, against Iran, “ISR [intelligence surveillance and reconnaissance] strike platforms have been essential.”

“Building on these lessons,” Meink continued, “we are developing a family of low-cost, multi-role, strike platforms called the Mass Modular Aircraft or MMAs [that] will provide affordable attritable [low-cost enough to lose in combat], long-range strike, and we will be able to field them at scale.”

He added, “Our intent is to field 100 MMAs in 2029 at even a lower cost than the CCAs, and a fraction of cost of air-manned aircraft we build today. Then by 2032, 500 of these [unmanned] platforms will join our force operational field fleet.”

Meink also noted, “We are making…progress in our space data network and we are launching our [initial] AMTI [satellites] for our Air Moving Target Indication constellation this month.” AMTI satellites will track airborne threats, such as drones, missiles and aircraft from Low Earth Orbit and replace surveillance aircraft such as the E-3 AWACS. The operational goal is 2028.

“When people look back at this moment,” Meink said, “they will not judge us on whether or not we implemented these autonomous systems, because eventually we're going to. But what we're going to be judged on is how quickly we operationalize them, right? That is whether we operationalize them fast enough to maintain our advantage.”

Meink noted, “We've had autonomous weapons -- I mean whether it's a Tomahawk [long-range, subsonic, precision-guided missile] or any of our air missiles that operate independently at some point in time -- terminal guidance things like that. But the big difference here is really taking

advance advantage of the autonomous capability that the deep-learning [computers] and all these other things [AI] offer.”

He then described having “more autonomy both in the platform as well as in the weapon system itself where even if the weapon loses its outside information stream” but having “enough autonomy to do what we've told it to do in absence of that.”

Reflecting today’s public debate about AI, Meink said, “That's where people start getting nervous, but that is something we have to figure out -- how to get comfortable [with], how to test it, how to verify, certify, that these weapons are going to do what they want when they go into an autonomous mode.”

In his speech last Thursday, Gen. Caine said, “While the fundamental nature of war will always remain the same, a clash of human wills, the character of war, how we fight, the speed at which we fight is changing really, really fast.”

He pointed out, “Information moves so fast that leader decision times has compressed from weeks, down to days, down to seconds. In the future fight, advantage will go to the side who can see first, who can understand first, decide first, and act first -- and along the way be a learning organization. And no factor is accelerating change as fast as Artificial Intelligence and advancing cyber capabilities.”

As Meink had done, Caine said, “AI is here now and it's already changing the way militaries see, sense, decide, and act. And across the joint force, we're putting AI to work every single day to move faster, to make better decisions through active adaptation on every single battlefield by leaders in your joint force.”

As an example, he spoke of what happed last June 8, after a U.S. Army Apache AH64 helicopter on patrol went down near the coast of Oman.

“U.S. Central Command (CENTCOM) launched a rapid, responsive, joint search-and-rescue effort to recover the [two-man] crew,” Caine said, adding, “That response drew on the totality of the joint force and ultimately was required to use enabled, unmanned, vessels to participate in the rescue of [the] downed U.S. service members for the first time ever.”

He explained, “That capacity did not appear overnight. It came from the men and women of Task Force 59, CENTCOM's forward-leaning, unmanned, joint maritime unit, who spent the last several years testing, integrating, and operationalizing unmanned systems and AI, in one of the most demanding and kinetic environments on Earth right now.”

Caine added, “What made this possible was a bunch of entrepreneurial sailors and members of

the joint force on watch floors… managing networks of unmanned systems across thousands of miles of water and using AI to turn massive amounts of data into a crisp, clear, perfect maritime picture that allowed us to go grab those two soldiers in the water.”

He then described Ukraine where, he said, “We see first-person-view drones operating in heavily contested [electromagnetic] environments. Some now using AI-enabled computer vision to continue to drive towards targets even when there's no GPS [Global Positioning System] or the [computer] links are cut. That gives small units affordable precision and shows how quickly software and autonomy are changing what is possible at the tactical edge.”

Caine described the stark result: “In certain locations on the front line of troops right now, the life expectancy of a new Russian recruit arriving on the front lines is as little as 20-to-30 minutes. Think about that. This is what happens when low-cost precision is fielded fast, adapted quickly, and scaled across the battlefield.”

“From the Strait of Hormuz to the front lines in Ukraine,” Caine said, “show how quickly technology is changing the character of war…We must move together because the window to build the force that we need is closing. We can buy almost anything in life, but we cannot buy time."

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Authority We Cannot Keep

Washington announced permanent control of Greenland on Friday. The two governments that must ratify it announced, in the same breath, that the text recognizes their sovereignty. Both ideas cannot be the settled meaning of an agreement neither parliament has seen.

The President’s post gave the United States “permanent control over security, and all other needs, in Greenland,” with no adversary permitted a base or a “sensitive investment” on the island without American approval; the Defense Secretary said Northern Command would “immediately begin” building “a large military presence.” Copenhagen and Nuuk responded the same day: the agreement would be signed next week at the United Nations General Assembly, must still pass both parliaments, and recognizes “the sovereignty and territorial integrity of the Kingdom and the right of the Greenlandic people to self-determination.” In a January poll, 85 percent of Greenlanders opposed going further.

The same shape ran through the week’s other arrangements. Riyadh asked Washington for direct strikes on the Houthis, who took the islands guarding the Bab el-Mandeb and reached Mecca’s air defenses; the request was refused, and in the same week American officials opened their own talks with the Houthis in Muscat and approved 48 F-35s for the kingdom. The Crown Prince has since canvassed Pakistan and Turkey for a guarantee he can call his own. In Europe, the Pentagon studied withdrawing as many as 40,000 troops while the President announced a base in Poland; Brussels, told to absorb a drawdown it did not shape, offered Canada associate membership in a defense-industrial bloc without consulting its member states. In each case, one party decided how the shared capability would be used and informed the others afterward. In each case, the others have begun to respond.

For three weeks I have argued that the largest defense-adjacent capital cycle in modern history is being contracted without any institutional authority named to decide how any of it fires: the drone force, the AI stack, the power that runs both. That was an argument about the inside of the American system. This week, the same gap opened on the outside. A capability fielded with an ally, on an ally’s territory, or in an ally’s defense raises a second question beyond who inside Washington decides its use: whether the ally gets a vote. The Greenland text, the Saudi request, and the European drawdown are three answers of “not yet,” and three allies declining to accept that answer. The price of arranging around a partner rather than with one is not paid in dollars; the President stressed that the Greenland deal comes at no cost. It is paid in authority, and the bill arrives when the partner asks for it back.

Picture the spring. Off Greenland, an American-integrated force is running as one system at machine speed: allied sensors, American targeting, autonomous platforms. A Danish frigate is inside its envelope. The system commits to a contact the frigate’s captain reads as civilian. Who can tell it to stop, and how fast? Under the text signed this week, no page answers that, because no one wrote one. That is the demand for a say, arriving at the capability that will decide the next war. The integrated force only works if the allies field it, and no ally will field a force whose targeting and autonomy Washington reserves the right to settle alone, because the ally’s territory, ships, and citizens are in the line of fire. Saudi Arabia will not fly American aircraft against a militia the United States is negotiating with. Europe will not integrate its industrial base into an architecture whose force posture it learns about from NBC.

Wednesday is when the largest version of the question gets its first answer. Xi Jinping arrives at the White House with a 7.5 percent Section 301 tariff pending, the Russia-oil sanctions act on the President’s desk, and the trade and export-control truces both expiring on November 10, the day China’s extraterritorial rare-earth licensing regime returns. He holds the one lever on the table that can end an arrangement on a schedule: from November 10, a license required for any product built with Chinese rare earths or the magnets made from them, and almost nothing outside China to replace them. The summit will not settle the relationship; it will show whether the terms of a shared supply chain are agreed by both parties or imposed by one, and which. The allies watching from Copenhagen, Riyadh, and Brussels will read the answer as a preview of their own.

Three signals will show by year-end whether the gap is closing or widening. Whether the Greenland text signed at the General Assembly gives Copenhagen a veto over how the presence on its territory is used, or only a right to be informed. Whether the Saudi F-35 notification carries an end-use restriction Riyadh helped write, or one Washington wrote alone. And whether the November 6 force-posture recommendation reaches allied capitals before it reaches the President, or after. As of this week, none of the three has been written.

The decision you owe this quarter is specific. Take the one program in your portfolio that fields American capability with an ally, on an ally’s soil, or in an ally’s defense, and find the document that specifies who decides how it is used. Not the basing agreement, the sales notification, or the industrial-participation clause; the release-authority annex, the page that names who can commit the system, who can override it, at what tempo, and what the partner can refuse. If that page does not exist, write it now, with the partner in the room, and sign it before Wednesday’s readout gives the partner’s parliament a reason to write it for you. The arrangement announced alone is the arrangement that comes back for renegotiation. The one written together is the only kind that survives the day the other side stops being patient.

Richard Berry is the founder of Stratnova Advisors and the editor of Strategic Horizons, a weekly geopolitical assessment for senior executives and national-security professionals. He served as Commander’s Action Group Director at U.S. Indo-Pacific Command and helped author the AUKUS Pillar II autonomy-and-integration construct.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Heads They Win, Tails They Win: The CMMC Trap and the Way Out

Here is a prediction from inside the compliance trenches: the CMMC Reform Task Force closed its sixty-day review on September 11 and is now finalizing recommendations for the Department of War's Chief Information Officer, with a public report expected within weeks. When that report lands, read it knowing what its authors cannot quite say aloud — there is no good answer. Every option in front of them loses. The program they were convened to fix is not a regulation that went wrong. It is one move in a game an adversary designed.

The task force was stood up on July 13, when the Department abruptly suspended Phase 2 of the Cybersecurity Maturity Model Certification program — the requirement, set to begin appearing in contracts this November, that companies handling controlled unclassified information (CUI) pass a third-party certification before winning defense work. The Department's stated reasons: prohibitive compliance costs, a severe shortage of assessment capacity, and a Small Business Administration finding that the program is structurally incompatible with rapidly expanding the defense industrial base. The task force spent the summer digesting more than 1,100 responses to its request for information, and the department is reportedly moving to codify the pause in binding regulation — not the behavior of an institution planning a tune-up. The CIO herself has described the assessments as a 'burdensome, red-tape ridden, check-the-box, point-in-time view' of contractor security: the program's owner, describing her own program in the language of its critics. The patient's physician is confirming the diagnosis. Understanding why none of the options can work — and what to do instead — requires seeing the whole game.

The dial that cannot be tuned

The task force's mandate frames the problem as a tradeoff: cybersecurity assurance on one side, small-business burden on the other. Turn the dial toward assurance and the math is grim. The Pentagon's own rulemaking priced a single Level 2 assessment at roughly $102,000 for a small business, every three years — a floor, since the government counted only the assessment itself and treated the underlying security work as a cost contractors already owed. Real first-year figures run two or three times higher.

Spread across roughly 80,000 companies in scope — nearly three-quarters of them small businesses — the program costs, every year, what a major weapons system costs. Companies at the bottom of the supply chain do the arithmetic and exit defense work entirely, shrinking the industrial base the Department has declared it must grow.

Turn the dial the other way — relieve the burden, rely on self-attestation. We ran that experiment. NIST SP 800-171 has been contractually mandatory for defense contractors handling covered defense information since the end of 2017, enforced by self-attestation. When the government's own assessors began checking, self-reported scores collapsed on contact: companies attesting to full implementation were found, on inspection, to be far from it. Eight years of the honor system produced paperwork, not protection. That failure is the reason CMMC exists.

And here is the part the certification debate politely ignores: the assurance being purchased is weaker than advertised. A Level 2 assessment fans 110 security controls into 320 individually judged objectives. Only nine of the 110 can be satisfied by configuring a system; after two years of industry effort to automate verification, barely a quarter have any machine-checkable test at all. The rest — 85 of 110 — turn on an assessor reading documents, weighing evidence, and interviewing people.

Judgment at that volume carries an irreducible error rate, and errors compound across 320 determinations: even a superb assessor is unlikely to get all 320 calls right. The certification is a probabilistic judgment dressed as a binary guarantee — and we are proposing to charge small businesses six figures for it.

Every setting of the dial loses. That is not because the rule-writers were careless. It is because the dial's axis — assurance versus burden — was chosen by the adversary.

Their coin, our coin

Consider the campaign from the adversary's side of the table. A sustained intelligence effort against the defense supply chain wins on either branch. If exfiltration succeeds, the adversary harvests the output of America's research enterprise — the Department's research, development, test, and evaluation accounts now run to roughly $150 billion a year, and nearly all that work materializes as CUI on contractor networks: designs, test data, specifications. The results are visible in the air: F-35 design data stolen in the operation behind Su Bin's 2016 federal conviction later resurfaced in the lines of a rival stealth fighter. If exfiltration is resisted, the United States burns weapons-system-scale money on compliance overhead, small suppliers flee the industrial base, and defense modernization slows under its own administrative weight. Heads they win, tails they win.

This is cost imposition — the competitive-strategies logic the United States once ran against the Soviet Union, most famously with the Strategic Defense Initiative, which threatened to obsolete Moscow's missile force and pulled it toward countermeasure spending it could not afford. The same logic now runs against us at machine speed and negligible marginal cost. An intrusion attempt costs the attacker thousands of dollars; the defensive apparatus it provokes costs the defender billions. The exchange ratio is the attack. And no certification regime, however well designed, changes that ratio. It just selects which branch of the adversary's win condition we take. That is why the task force cannot regulate its way out: it is being asked to find the winning setting on a dial that has none.

The solution we forgot

The way out is not a better tradeoff. It is to stop playing this game — and the United States already knows how, because it solved this exact problem once and then forgot.

For eight decades, the National Industrial Security Program and its predecessors handled sensitive information in contractor hands on a simple two-tier logic. Information that genuinely mattered was classified: the government cleared the facilities, inspected them, provided counterintelligence support, and bore the cost — because assurance of its own supply chain was understood to be the government's problem, a cost of defense like any other. Information that did not rise to that level circulated freely. Both tiers were coherent, and the system carried the country through a fifty-year great-power competition.

Then came CUI — a third tier of 'sensitive but unclassified' created by executive order in 2010 — and with it a decision that looks stranger every year: push national-security-relevant information onto 80,000 private networks with none of the industrial security program's machinery. No facility oversight, no counterintelligence support, no government cost-sharing, and for eight years no verification at all.

CMMC is the decade-late patch on that omission — an attempt to rebuild a shadow industrial-security program on contractor money and commercial assessors. It is failing because the original lesson still holds: protecting information at national-security scale requires the government to run and fund the assurance, or the information does not stay protected.

Restore, don't invent

The reform the task force should recommend is not a better CUI regime. It is the end of CUI as a protection category — a return to the binary the country defended for eighty years: classified, or released.

The government has been trying to triage CUI honestly for sixteen years and has proven incapable of it. Since the 2010 executive order, the registry has swelled to dozens of categories applied so promiscuously that routine engineering data carries the same handling burden as weapon-system design detail. The incentive structure guarantees the outcome: marking is free, unmarking is career risk, and no official is ever punished for protecting too much. A bureaucracy that could not resist over-marking will not now triage its way to discipline. The proof arrived on September 2, mid-review: sixteen years after the executive order created CUI, the National Archives had to issue fresh guidance re-teaching agencies day one of the program — how to designate and mark consistently, and how to tell contractors what is actually controlled. A program whose executive agent must re-explain its founding act sixteen years in is not maturing toward discipline; it is demonstrating that it cannot get there.

So retire the category. Information whose loss would buy an adversary military capability moves up into classified channels, where cleared facilities, real defenses, and counterintelligence support already exist. The rest is released and protected by ordinary commercial hygiene. The classified system has room for this: every review from the Moynihan Commission onward has found it bloated with material of merely sensitive grade — declassify downward as the crown jewels move up, and the classified world need not grow at all. And to the objection that unclassified details aggregate into sensitive wholes: we ran the aggregate-everything experiment. It produced an unpayable mandate, an unprotectable perimeter, and eight years of uncontested collection. That is not risk management; it is risk relabeling.

The binary has one irreducible residue: export-controlled technical data. ITAR and the Export Administration Regulations restrict the largest slice of defense CUI by statute — the Department cannot release it by memo, and it cannot all be classified. That residue is where the second move lives: defend it wholesale, not retail. Eighty thousand self-defended machine shops is retail defense at the worst possible exchange ratio. A few hundred hardened, government-assured environments — enclaves and authorized platforms in which small contractors work with controlled technical data rather than each hosting it themselves — is wholesale defense: the defender finally gets economies of scale, verification shrinks to a population the assessment ecosystem can actually service, and the attacker's cost per useful intrusion rises instead of falling. Concentration creates high-value targets, yes. But a few hundred professionally defended environments with real detection beat 80,000 undefended networks even against a focused adversary — we know, because the adversary has treated the current arrangement as a self-service library since 2017.

Third, verify by sampling, with consequences. Keep self-attestation for the residual population, but back it with random government-led assessment at a rate high enough to deter — the model that keeps the tax system honest without auditing every return.

None of this is invention. Each element has decades of precedent; the task force is being asked to remember, not to imagine. The suspension of CMMC was not an admission that cybersecurity costs too much. It was an admission — perhaps not yet a conscious one — that the game as structured cannot be won at any price. The only winning move is to change the game: shrink what needs protecting, protect it the way we protected what mattered for eighty years, and stop letting an adversary's cost-imposition strategy set the terms of our industrial policy.

James Novakoff, MSTM, CCA, is an enterprise computer and security architect and Certified CMMC Assessor who provides engineering and security services to defense industrial base contractors. The views expressed are his own.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How America Appeased Putin



Excerpt from Spies: The Epic Intelligence War Between East and West

When Spies was first published in 2023, it made front-page news with the chilling revelation that the Russian government had reached an advanced stage in planning an assassination on American soil.

Russia's target was Alexander Poteyev, a former officer in the SVR, Russia's foreign intelligence service, whom the FBI and CIA had recruited as a spy. Poteyev betrayed one of Moscow's most closely guarded secrets: its network of deep-cover "illegals" living in the United States. His intelligence allowed the FBI to arrest ten Russian operatives in 2010, including the glamorous Anna Chapman.

The United States exchanged the illegals for Western agents imprisoned in Russia. Among those released was Sergei Skripal, the former Russian military intelligence officer whom the Kremlin later attempted to murder in Salisbury, England, with the nerve agent Novichok.

The CIA extracted Poteyev from Russia and resettled him under a new identity in the United States. Putin did not hide the fact that he wanted him dead. A Kremlin spokesman warned that Russia knew the traitor's identity and that an assassin would be sent after him.

That was precisely what happened.

Russian intelligence recruited Hector Fuentes, a Mexican microbiologist with a Russian wife and another family in Mexico. His handlers exploited his private life to blackmail him into identifying and surveilling Poteyev in Miami. They gave Fuentes $20,000 to rent an apartment there, but the operation foundered on poor tradecraft. Fuentes photographed the license plate of Poteyev's car and attracted the attention of security guards at Poteyev's apartment complex. When he attempted to leave for Mexico, American border officials discovered the photograph. Fuentes was arrested and disclosed the operation to US investigators.

By authorizing the plot, Putin had crossed an important red line. Europe had already witnessed Russian assassinations and attempted assassinations, including the attack on Skripal. But the Kremlin had previously stopped short of authorising a killing inside the United States. Putin was now demonstrating his willingness to tear up the remaining restraints governing relations with Washington.

Yet the American response was remarkably weak.

The New York Times subsequently reported that Washington retaliated harshly, imposing sanctions and expelling ten Russian intelligence officers operating under diplomatic cover in April 2021. But according to someone intimately involved in the events, when the United States informed the Kremlin about the expulsions, its message did not even mention the planned murder. Instead, Washington concentrated on Russia's SolarWinds cyberattack.

The penalties imposed were hardly sufficient to alter Putin's behaviour. Russian intelligence officers sometimes regard expulsion as a badge of honour. Putin had also insulated much of the Russian economy from American sanctions. A more serious response might have publicly exposed his immense wealth and corruption - subjects about which the Kremlin leader is notoriously sensitive.

The assassination plot was only the first of four events that, viewed from Moscow, advertised American weakness.

The second emerged in 2020, when reports alleged that Russian military intelligence was paying bounties to the Taliban to kill American service personnel in Afghanistan. The story appeared during the presidential election campaign but then largely disappeared, supposedly because the US intelligence community could not reach a consensus about the underlying evidence.

There should have been little doubt. John J. Sullivan, the former American ambassador in Moscow, has written that he examined the intelligence and found the proof persuasive. According to a source with knowledge of the events, American authorities possessed intelligence about a Russian officer travelling to Dubai to meet an Afghan contractor who facilitated payments to the Taliban. At the centre of the scheme was an Afghan-Russian gem smuggler, Rahmatullah Azizi, who acted as an intermediary.

The intelligence reached the President's Daily Brief in February 2020. Donald Trump nevertheless denied having been briefed and dismissed the story as "fake news." As with the assassination plot, the Russian bounty program provoked no meaningful American response.

The third demonstration of weakness was Washington's withdrawal from Afghanistan, negotiated by Trump and executed by Joe Biden in August 2021. The operation was handled disastrously. The world watched desperate Afghans cling to an American C-17 as it taxied along the runway at Kabul airport. Some fell to their deaths after the aircraft took off. A suicide bombing killed thirteen American service personnel and approximately 170 Afghan civilians. Soon the Taliban controlled the country once more.

From the Kremlin's perspective, the images suggested that the United States no longer possessed the will or competence of a superpower.

The fourth episode concerned Havana Syndrome - the mysterious neurological symptoms suffered by American officials since 2016. The US government repeatedly denied that a foreign power was responsible. A 2023 intelligence assessment judged it "very unlikely" that an adversary lay behind the incidents.

Investigative reporting later revealed compelling evidence of Russian involvement. Members of Unit 29155, a Russian military intelligence black-operations squad, were present near several incidents involving American personnel. The operatives appear to have used some form of electronic weapon.

Two reliable sources familiar with the matter told me that Russian involvement was regarded as almost certain, but that elements of the American intelligence community - particularly the CIA - had suppressed evidence pointing towards Moscow. Their apparent calculation was that doing nothing was preferable to revealing an attack that might constitute an act of war.

In December 2024, the House Intelligence Committee concluded that a foreign adversary was increasingly likely to have caused at least some of the incidents. It criticised the previous intelligence assessment for lacking analytic integrity and being highly irregular in its formulation.

If Russia was responsible, the lesson for the Kremlin was unmistakable: it had attacked American government personnel and escaped without punishment.

Taken together, the assassination plot, the bounties on American soldiers, the humiliating withdrawal from Afghanistan and Washington's refusal to confront the evidence surrounding Havana Syndrome all made the United States appear emasculated in the Kremlin's eyes.

It was in this context that Putin decided to launch his full-scale invasion of Ukraine in February 2022. America appeared weak. The opportunity for military action had arrived.

The analogy with Munich in 1938 has become an overused cliché. In this instance, however, it is unfortunately appropriate. Through their repeated failure to counter Russian aggression before February 2022, the Trump and Biden administrations effectively appeased Putin's worst ambitions.

Putin's actions must be understood through his background as a KGB officer. He remains an unreformed Chekist, steeped in the mentality of the Soviet security services. He has never abandoned the KGB's view of the United States as Russia's "main adversary," nor his conviction that Washington and the CIA are engaged in a conspiracy to weaken Russia.

His strategy has consistently been revanchist: to regain the territory, influence and prestige lost when the Soviet Union collapsed. His invasions of Ukraine in 2014 and 2022 follow logically from that worldview. According to Putin's distorted version of history, Ukraine is an artificial country created by hostile Western powers. He regards its conquest and reincorporation into Russia as an almost sacred duty.

This is a gross misreading of history. But it is nevertheless what Putin believes - and Western governments must take it seriously.

Putin and the hardliners surrounding him believe themselves to be at war with NATO and, above all, with the United States. That conviction will not disappear with a ceasefire in Ukraine. Nor will the danger necessarily vanish when Putin leaves power. The nationalist resentments he has exploited are larger than the man himself, while his regime has systematically eliminated alternative leaders.

The West therefore faces a Russia problem, not merely a Putin problem. The events preceding the invasion of Ukraine offer an enduring warning: deterrence fails when threats carry no consequences. Dictators interpret silence not as prudence, but as permission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Will Physical AI Underpin the Reindustrialization Win that Western Allies Need?

Having spent most of my life working in “advanced nations” that have strategically accentuated financial and professional services growth while outsourcing manufacturing to the lowest cost jurisdiction, the rise of reindustrialization policies has shocked many by its rapid ascension and acceleration of mission investment.

Reindustrialisation is core to the sovereign aspirations of many nations driven by the need for national, economic and societal security underpinned by supply chain diversity and independence and real challenges for workforce growth now and into the future. Key delivery pillars include defence tech, energy sovereignty, critical mineral supply and advanced manufacturing.

Nvidia’s Jensen Huang declared at CES 2026 that Physical AI (robots that perceive, reason and act in the real world) are having their inflective "ChatGPT moment" and the numbers back the rhetoric with the sector projected to grow from roughly $138 billion in 2026 to over $500 billion by 2030. Not only are the numbers extraordinary, but the pace of functional improvement has also been remarkable. Almost overnight we’ve gone from laughing at robots falling over to the recent Robot Games in China with AI-powered machines jumping, running and somersaulting better than humans.

Governments from Canberra to Whitehall are betting that robotics will do for reindustrialization what tariffs and subsidies alone couldn't ie. bring manufacturing back onshore. Similar to the AI-related discussion about Data Centres, that bet may be right about the factories and wrong about who controls and captures the resulting value.

There is little structural awareness that Physical AI is on the same path to evolving sovereign cloud and AI strategies doomed to partial success – only wearing a proverbial hard hat.

Until recently, the gap between digital and physical AI has been somewhat of a running joke. How can the technology that can solve advanced mathematics or write a brilliant poem not figure out how to fold a towel? That gap is closing fast. Vision-language-action models pioneered by the likes of Nvidia and Google DeepMind allows robots to reason the principles of physics rather than execute rigid, pre-programmed motion. Generalist recently reported their GEN-1 model lifted task success rates from 64% to 99% at a rate 300% faster on standard benchmarks in a single release proving a “significant step towards our mission of creating generalist intelligence for the physical world.”

Capability demonstrations have moved from highly controlled labs to live on stage and arenas showing a level of confidence the industry hasn't seen before. The greatest proof perhaps being the broadcast of China’s Humanoid Games – not a country that takes technological or reputational risk lightly! While Elon gets the headlines with his “1 billion humanoid robots in 10 years”, conservative manufacturers like Hyundai are targeting 30,000 humanoid robots a year by 2028. Funding into physical AI start-ups jumped 400% in H1, 2026 according to Crunchbase while the Wall Street Journal reported that many of those investors were the founders of the software and AI industries previously providing a clear pathway to digital/physical AI engineering and manufacturing integration.

McClure, Dave. "Physical AI Large Fundings In H1 2026." Crunchbase News, 18 Aug. 2026, crunchbase.com.

Politically, this is landing at the perfect moment. Reindustrialization has become a universal policy theme across the Western alliance and robotics are being pitched as the enabling technology. Humanoid and purpose-built machines that let Western economies rebuild factories without rebuilding a 1990s-scale labour cost base or the politically maligned immigration policies needed to resource them.

As Andreesen Horowitz Head of Global Affairs (former Whitehouse and NSA senior leader) Anne Neuberger illustrated, this advanced manufacturing revolution is spawning the necessary development of highly detailed digital twins to better understand, architect, build, test and upgrade critical infrastructure with global leaders like Belden, Caterpillar, Foxconn, Toyota and TSMC already building AI-driven digital twins of their factories on Nvidia's Omniverse platform.

Here is the uncomfortable part – politically, economically and socially. The entire pitch for reindustrialization has been implicitly, and often explicitly, about jobs and restoring a middle-class industrial base giving politicians a factory to place a plaque or cut a ribbon. Physical AI does not deliver that. A robot capable enough to fold laundry, pack boxes and operate coffee machines across different physical forms is capable enough to replace the very workforce reindustrialization was promised to restore. We are reshoring output, not jobs, by automating the labour out of it. The politics of reindustrialization and the economics of physical AI are pulling in opposite directions with little recognition of this at policy levels.

The implications will vary by nation and region. While Goldman Sachs reports the US has a gap to fill of 13million open manufacturing jobs ripe for robotic fulfillment, many allies have relatively high inflation and growing unemployment driven by legacy debt and technological disruption.

That's the first trap. The second is more familiar, and more dangerous, because we've built it before. Just as sovereign cloud infrastructure means little if a nation doesn't control the token pricing running on top of it, a reshored factory means little if the nation doesn't own the foundation model, the world-simulation data, or the "brain" directing the robots inside it. Nvidia's Cosmos and GR00T models, and the open foundation models rapidly becoming the default substrate for robotics development, are following the exact ownership pattern that concentrated cloud and AI value in a handful of American platforms. A factory built at home, running on embodied intelligence licensed from offshore, is not reindustrialization, it’s simply a very expensive lease.

In their recent report “Harnessing AI for the Physical Economy” Goldmans additionally pointed out that physical AI deployment, sovereign capital programs and strategic supply chains all coalesce around Defense with an uncomfortable conclusion that fully autonomous AI-executed warfare is an inevitability. Much like recent diplomatic engagement about weaponization in the space domain, this is a joint Allied discussion which can NOT be put on the backburner.

For Western Allies, it will be critical over the next 5 years to build national strategies around developing and controlling the physical AI IP and models, the physical-world training data, and the "sim-to-real" simulation infrastructure those robots depend on rather than simply the location of the manufacturing centers and number of robots deployed.

Nations should treat embodied-AI foundation models (the physical-world equivalent of the large language model) as a sovereign capability requiring the same deliberate investment as fabs or power grids, not an app layer to be simply imported off the shelf.

The collective challenge for allied nations is that physical AI will very likely reindustrialize the West's factories while perhaps further deindustrializing our workforce and destabilizing societal cohesion, and no amount of reshoring rhetoric changes that arithmetic. The real conundrum for sovereign policymakers is whether they own and control the intelligence running the machine revolution or merely rent the floor space the machines stand on.

The positive news is that the issues are foreseeable and controllable and we have time to do address them all before AI (in all its guises) reaches self-propagating scale and becomes turbocharged by the rapidly advancing quantum, space and 6G revolutions.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How China Is Building an Architecture of Control Across the Heart of Asia

In the years following the Soviet withdrawal from Afghanistan, much of the world treated the region as strategically peripheral - unstable, exhausted, and largely disconnected from the future of global security. Policymakers assumed the consequences of state collapse and civil war would remain regionally contained.

They did not.

The vacuum that emerged across Afghanistan and its surrounding region ultimately produced transnational terrorism on a scale that reshaped global security for two decades. By the time the world recognized the strategic implications of instability in the Heart of Asia, the consequences had already spread far beyond the region itself.

Today, another transformation is unfolding across the same geography. Once again, much of Washington views the region primarily through narrow lenses: humanitarian crisis, counterterrorism management, refugee flows, or strategic fatigue after two decades of war. Yet beneath the surface, a far more consequential shift is underway - the emergence of an interconnected architecture of surveillance systems, cognitive warfare capabilities, AI-enabled governance, and digital infrastructure stretching from Xinjiang through Central Asia, Afghanistan, Pakistan, and Iran.

This is not merely a story about Afghanistan or even about China’s expanding regional influence. It is the story of how authoritarian technological ecosystems are gradually reshaping one of the world’s most fragile and strategically important regions, and how the United States risks misunderstanding the implications until the consequences extend far beyond Eurasia.

The future threat emerging from the Heart of Asia may not resemble the threats of the past. It may not require large training camps, centralized organizations, or physical sanctuaries alone. Instead, it may emerge through digitally networked ecosystems built on AI-enabled surveillance, synthetic media, autonomous influence operations, predictive governance systems, and machine-readable societies operating across the gray zone between peace and conflict.

The region surrounding Afghanistan is increasingly becoming a laboratory for that future.

The Rise of Informational Gravity

China’s expanding role across the Heart of Asia is often described in economic terms: roads, railways, mining contracts, telecommunications infrastructure, and the Belt and Road Initiative. But this framing misses the deeper strategic transformation underway. Beijing is not simply investing in physical infrastructure. It is gradually building informational gravity across the region.

Telecommunications systems, Safe City surveillance platforms, AI-assisted facial recognition networks, smart-city technologies, digital payment systems, media ecosystems, and cross-border security cooperation are converging into a broader regional architecture that extends far beyond any individual country. Afghanistan is no longer the center of the story. It is one node within a wider system.

The clearest model for understanding this architecture exists inside China itself.

In Xinjiang, Beijing constructed what may be the most comprehensive AI-enabled population monitoring system in modern history. Facial recognition cameras, biometric databases, predictive policing algorithms, integrated behavioral tracking systems, and AI-assisted security platforms transformed the region into what many analysts now describe as a machine-readable society. The Integrated Joint Operations Platform (IJOP) aggregates enormous quantities of behavioral data - movement patterns, communications, social interactions, purchases, travel activity, and digital behavior - to identify perceived risks before they materialize.

What matters strategically is that the technologies, companies, governance concepts, and security logic developed in Xinjiang are no longer confined within China’s borders.

Across Pakistan, Chinese-built Safe City systems now monitor major urban centers through Huawei-supported command platforms, facial recognition systems, and expanding digital interception capabilities. In Iran, Chinese surveillance technologies have become increasingly integrated into domestic security and protest-monitoring systems. Across Central Asia, Chinese telecommunications infrastructure, smart-city ecosystems, and surveillance exports have become embedded within the digital foundations of multiple states.

Individually, these developments may appear disconnected. Collectively, they form something far more consequential: an emerging Ring of Control around the Heart of Asia.

Building the Ring of Control

This ring is not coordinated through a single master plan. Rather, it emerges through the convergence of multiple strategic interests. China seeks to secure Belt and Road investments, contain Uyghur militancy, protect trade corridors, expand the Digital Silk Road, and establish informational advantages across strategically sensitive regions. The result, however, is systemic. Telecommunications infrastructure, AI-enabled surveillance systems, media ecosystems, and cognitive-domain operations increasingly reinforce one another across borders.

Pakistan demonstrates how economic infrastructure and surveillance infrastructure merge into a single strategic ecosystem. Chinese-funded Safe City projects in Islamabad, Lahore, Karachi, and other major urban centers increasingly integrate population monitoring with economic-security priorities tied to the China-Pakistan Economic Corridor (CPEC). At the same time, internet-monitoring systems modeled on China’s own censorship architecture are gradually reshaping the digital environment through which information flows.

The implications extend beyond domestic governance. Surveillance systems originally justified as anti-crime or counterterrorism tools gradually evolve into mechanisms for political management, social monitoring, and information control. As these systems become normalized, governments gain unprecedented visibility into the behavior of their populations.

Iran demonstrates a different dimension of the model: how surveillance ecosystems evolve from security tools into political-control mechanisms. Chinese technologies have increasingly supported AI-assisted monitoring of protests, facial-recognition deployments, and population-management systems designed to maintain regime stability during periods of unrest. During waves of anti-government demonstrations, Iranian authorities increasingly relied on digital monitoring, internet restrictions, and AI-assisted identification systems to suppress dissent.

Central Asia represents perhaps the quietest transformation of all. Huawei telecommunications infrastructure, smart-city surveillance systems, and Chinese-built digital architecture now underpin significant portions of regional connectivity across Tajikistan, Kyrgyzstan, Uzbekistan, and Kazakhstan. Border-security cooperation near the Wakhan Corridor, expanding Chinese security facilities, and growing digital dependency further deepen Beijing’s structural influence.

What emerges is not traditional imperialism. It is infrastructural cognition.

Whoever controls the communications architecture, surveillance systems, digital ecosystems, and AI-enabled information environments of a region gradually acquires influence over how societies perceive, communicate, organize, and govern themselves. In the twenty-first century, power increasingly operates not only through territory or military presence, but through data flows, algorithmic visibility, and cognitive infrastructure.

Afghanistan’s Cognitive Vacuum

This transformation becomes even more significant when paired with the collapse of independent information ecosystems across parts of the region.

In Afghanistan, the destruction of independent journalism following the Taliban’s return created an enormous cognitive vacuum. Hundreds of journalists fled the country, media outlets collapsed, and independent reporting networks deteriorated under political pressure and economic collapse. Into that vacuum moved state-backed narratives, sponsored media relationships, and externally influenced information ecosystems.

Chinese state media expansion and narrative-management initiatives increasingly operate in environments where alternative information infrastructures have largely disappeared. Similar pressures exist elsewhere across the region, where fragile media systems increasingly compete against state-backed digital ecosystems supported by far greater resources and technological capacity.

Surveillance infrastructure and narrative infrastructure reinforce one another. Data shapes messaging. Messaging normalizes surveillance. Together, they create environments where behavioral monitoring and information management become mutually sustaining systems.

This matters because modern authoritarian influence no longer depends solely on censorship. Increasingly, it depends on shaping the informational environment itself — determining what populations see, what narratives dominate, and which voices disappear from public discourse.

The result is a region where governance, surveillance, and information control are becoming increasingly integrated through digital systems powered by artificial intelligence.

AI and the Future of Gray-Zone Conflict

This is where the region’s future intersects with broader global security concerns.

The world after 9/11 was shaped by physical sanctuaries: training camps, insurgent safe havens, ungoverned territory, and militant mobility across borders. But the emerging threat landscape of the coming decades may look fundamentally different.

Artificial intelligence lowers the cost of asymmetric influence.

AI-assisted propaganda, synthetic media, autonomous disinformation networks, digitally coordinated extremist ecosystems, predictive behavioral analysis, biometric governance systems, and drone-enabled proxy operations no longer require the same physical infrastructure that earlier generations of transnational threats depended upon. Influence operations can now scale globally through digital ecosystems that transcend geography.

The next sanctuary may not train hijackers in remote camps. It may train algorithms, autonomous systems, and synthetic narratives capable of shaping perceptions, destabilizing societies, and amplifying conflict far beyond the region itself.

This is particularly important because modern gray-zone competition increasingly operates through cognitive pressure rather than direct confrontation. China’s Three Warfares doctrine, Russia’s concepts of Reflexive Control and Active Measures, and broader state-backed influence operations all reflect a strategic understanding that future competition will target perception, trust, decision-making, and societal cohesion as much as physical infrastructure.

The Heart of Asia is becoming one of the environments where these concepts are converging operationally.

The convergence of AI, surveillance systems, and cognitive warfare creates a new strategic reality. States no longer need to occupy territory physically to shape political outcomes. Influence can increasingly be exercised through algorithmic visibility, digital dependency, and information dominance.

That transformation carries implications far beyond the region itself.

Washington’s Strategic Blind Spot

Yet Washington still tends to analyze terrorism, artificial intelligence, surveillance technology, regional instability, and great-power competition as separate categories. The emerging architecture across the region suggests adversaries increasingly view them as interconnected systems.

That strategic blind spot carries risks.

The lesson of the 1990s was not simply that Afghanistan became a sanctuary for terrorism. The deeper lesson was that strategically ignored regions can evolve into generators of global instability when major powers fail to recognize transformations early enough.

Today, the transformation underway is different - more technological, more cognitive, and more structurally embedded.

The long-term risk is not merely the expansion of authoritarian influence across the Heart of Asia. It is the gradual emergence of interconnected machine-readable societies whose surveillance systems, telecommunications infrastructure, media ecosystems, and behavioral data environments become increasingly interoperable across borders.

In such an environment, the distinction between domestic governance, cognitive warfare, and strategic competition begins to blur.

The consequences may not remain regional.

The next phase of instability emerging from the Heart of Asia may not arrive through conventional terrorism alone. It may emerge through AI-enabled cognitive operations, synthetic media ecosystems, autonomous influence architectures, and digitally amplified disorder operating at a scale that previous generations of extremist or authoritarian movements could never achieve.

Afghanistan is no longer merely a battlefield of territory.

The wider region surrounding it is becoming a contested frontier of cognition, surveillance, infrastructure, and machine-driven influence — and the strategic consequences of losing that contest may not remain confined to the region for long.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Dark Transits are a Stopgap not a Solution

Washington has accomplished an important feat by stealthily moving oil through the Persian Gulf despite Iran’s proclaimed closure. But the means it has relied on can’t become normal maritime behavior.

Treasury Secretary Scott Bessent said on August 27 that the United States had facilitated the movement of 130 million barrels of oil through the Strait of Hormuz in the preceding two weeks. That amounts to over 9 million barrels per day (bpd), roughly half of pre-war exports through the chokepoint.

Most of these vessels make “dark transits,” when ships sail with their automatic identification system (AIS) turned off. A ship’s AIS transponder broadcasts its location, course, speed, and other data via dedicated maritime radio frequencies to nearby ships, shore-based AIS receivers, and low-earth satellites, which convey that data globally. Dark transits are typically used by sanctioned vessels or ships moving illicit cargo because standard maritime trade, under normal conditions, doesn’t derive benefit from sailing without AIS. But licit maritime trade has increasingly been forced to move through the Middle East waterways on dark trips to avoid attack.

Kpler data identified more than 1,500 dark transits through Hormuz between March 1 and late August. Saudi Arabia’s tankers are also transiting the Red Sea without AIS after the Iran-backed Houthis announced a maritime blockade of the kingdom on July 20. Riyadh rerouted most of its oil exports from the Persian Gulf to the Red Sea using the country’s east-west pipeline after Iran closed Hormuz.

Washington needs to move Gulf oil through both waterways to market to reduce Tehran’s economic leverage. Dark transits are an important tool to accomplish this, but they are not a long-term solution in the Middle East.

The International Convention for the Safety of Life at Sea (SOLAS), the most important maritime treaty on vessel safety, requires ships, with very limited exceptions, to use AIS for safety reasons. Most importantly, the technology is used to prevent collisions, but it also improves a ship’s navigation capacity and knowledge of its environment.

Given the potential safety implications, the shipping industry traditionally eschews dark transits. In many instances, sailing without AIS will void a ship’s insurance policy as it is a violation of international standards. While there can be legitimate reasons for a ship to disable its AIS — including for its own safety — this does not necessarily compel the insurance company to continue coverage.

Furthermore, transiting without AIS does not guarantee a ship won’t be attacked, as Iran’s recent attacks on Emirati vessels demonstrates. United Arab Emirates’ state-owned Abu Dhabi National Oil Company (ADNOC) has been shuttling oil through the Persian Gulf — sending vessels through Hormuz on dark transits to offload their product onto larger ships waiting outside the strait that then travel onto buyers. While a successful mission — ADNOC is expanding this service to Iraq and Saudi Arabia appears to be replicating the practice — it is not without danger. Abu Dhabi said that Tehran attacked seven Emirati ships in roughly the first half of August alone.

Ships can be tracked by radar or satellite even when their AIS is disabled. The confined space of the Strait of Hormuz enables drone and fast attack crafts to more easily surveil and attack vessels. While the United States has targeted Iranian coastal radars, small craft, and drone capabilities, these can all be replenished. Iranian partners would likely support this effort.

China considered giving Iran advanced radar technology early in the conflict, according to U.S. intelligence agencies. Russia has allegedly been supporting Iran’s ability to build ram jets to propel hypersonic anti-ship missiles. Both China and Russia have also provided the regime with targeting support via access to satellites or their data intelligence. Iran possesses anti-ship missiles that are launched based on satellite or radar data but lock onto a ship’s heat or electronic signature for terminal guidance, enabling them to target a dark vessel. So long as Iran retains both the desire and residual capability to strike—bolstered by partners willing to assist—even dark transits through the strait carry some risk.

Similar threats exist in the Red Sea, where the Houthis utilize Iranian anti-ship missiles, but they also attack ships using small arms and RPGs from small vessels. Dark transits through the Red Sea grew substantially following Houthi attacks on commercial shipping over the war in Gaza in late 2023. This has given the group experience in monitoring and menacing vessels moving through the waterway without AIS.

These ongoing maritime threats are, in part, the cost of not decisively defeating the Houthis when they spent two years menacing commercial shipping in the Red Sea. Gulf countries and Washington should not repeat that mistake in the Persian Gulf. The lasting solution is the removal of Iranian threats to maritime shipping and the restoration of freedom of navigation in both critical waterways of the Middle East.

Bridget Toomey is a research analyst at the Foundation for Defense of Democracies. Rear Admiral (Ret.) Mark Montgomery serves as senior director of FDD’s Center on Cyber and Technology Innovation (CCTI) and as an FDD senior fellow.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Houthis’ Coastal Gambit

For the first time in years, large swaths of Yemeni territory are changing hands. The Houthis’ recent losses in the east of the country were quickly followed by a string of victories along the Red Sea coast that brought the group closer to the Bab al-Mandeb strait. Early readings that the eastern losses marked the beginning of the regime’s collapse have since proved premature. Yet the regime’s latest expansion does not resolve its core problems either, at best it mitigates them.

What has emerged over the summer is not a regime in free fall but one that is consolidating. Pulling back from the periphery, concentrating its forces where they matter most, and using battlefield momentum to paper over economic and political weaknesses.

The current escalation began in July 2026, when the Houthis tried to break what they call the “Saudi blockade” of Yemen by chartering an Iranian airliner for a roundtrip from Sanaa to Tehran. Riyadh has controlled Yemen’s airspace since 2015, when it launched its campaign to unseat the Houthis, and air traffic to and from Sanaa has been limited ever since. It diminished further in 2025, when Israel put Sanaa Airport and the Houthis’ fleet of airliners out of commission because the group had been using them to transport weapons and operatives. The blockade has never been airtight, though, as UN flights have reportedly continued in apparent secrecy and without any clear declaration of cargo or purpose.

Riyadh had folded under Houthi pressure many times before. Until 2023, the Saudis were desperate for a way out of Yemen, and the Houthis set out to extract every possible concession before running out the clock on a deal. The group’s Red Sea campaign, launched in November 2023, made any agreement far more difficult for the kingdom to stomach. Even so, Houthi threats against Saudi infrastructure continued to yield concessions or at least a softening of Saudi policy.

This time, Riyadh did not fold. On July 13, as an inbound flight from Tehran approached Sanaa, a coalition strike cratered the runway and forced the aircraft to divert to Hodeidah. The Houthis answered by declaring a “naval blockade” of Saudi shipping and attacking the kingdom’s energy infrastructure. Saudi Arabia hit back with airstrikes on Houthi-held territory, and Saudi-backed Yemeni government forces went on the offensive.

The coalition’s pushback was limited, and it did not cow the Houthis who retain considerable will to fight. Its leaders are mostly in their 30s and 40s and remain filled with extremist fervor. They are not the aging cadres of the hollowed-out Assad regime. They are also accustomed to a ruthless and competitive environment in which the last thing anyone can afford to display is weakness.

Instead, the group recalibrated by absorbing losses in the east while going on the offensive in the west. In the northeastern governorate of al-Jawf, the Houthis have reportedly lost territory, including the al-Labanat military camp. They apparently did not commit the resources required to hold those positions.

That is surprising given al-Jawf’s history with the movement. Roughly two decades ago, when the Houthis had only just begun their revolt against the Yemeni government, al-Jawf became their second foothold. It is also a valuable smuggling hub and a likely entry point for materiel smuggled overland to the regime via Oman.

Yet al-Jawf has also been a thorn in the Houthis’ side for years because of its demography and topography, and it will remain one for whoever is left to govern its unruly tribes. The defeats there may therefore reflect a decision as much as a failure. Constrained by scarce resources, the Houthis appear to be consolidating around the assets they value most, accepting losses in al-Jawf in order to concentrate on the more strategically valuable western governorates. This does entail some risk as losing ground in the east strips away some of the group’s strategic depth.

That reading fits developments in Taiz and along the Red Sea coast. On September 3, the Houthis launched a ground offensive across western Taiz and southern Hodeidah against the National Resistance Forces of Tareq Saleh, nephew of the late President Ali Abdullah Saleh. Within a week, the key port city of Mokha had fallen.

The captured territory secures the Houthis’ own ports, at least from a land invasion, and could allow the group to expand smuggling operations via the Horn of Africa. It may eventually position them to move on the city of Taiz itself. But the advance toward Bab al-Mandeb is less dramatic than it might appear, as shipping through the strait has been within Houthi reach for years so holding more coastline does not dramatically extend that threat.

The timing of the offensive may not be incidental. September is typically a tense month for the Houthis, as their level of popular support is put to the test. The regime seeks to bring Yemenis into the streets to celebrate its September 21, 2014, coup while silencing any celebration of the founding of the Yemeni Republic on September 26, 1962. The quick and surprising capture of Mokha from Saleh’s forces sustains the myth that the group is on the rise. That does nothing to alleviate discontent, but raising public fear of the regime helps keep discontent from turning into open dissent.

In doing so, the regime has used its primary tool, military power, to compensate for its other weaknesses. But this consolidation looks like crisis management. The regime’s central problems are economic as its main sources of revenue are drying up and it needs money and resources to keep its war machine going.

Saudi Arabia, meanwhile, finds itself dealing with Yemen largely on its own. It has pushed out its Emirati partners, and its American, Turkish, and Pakistani allies appear reluctant to commit to direct military intervention. Sidelining the Emiratis and disbanding the Southern Transitional Council gave Riyadh greater influence over the full spectrum of anti-Houthi forces, which it has since co-opted, but it is not clear that the Saudis are managing these relationships effectively.

The Houthi regime is neither a paper tiger nor ten feet tall. It should be assessed as a foe that is, above all, capable of surprise. Its summer offensive also shows that it can still generate momentum on the battlefield even as its economic base declines. Seeking to strike deals with or ignore this terrorist group has afforded it the luxury of preparing and then launching attacks at the time and place of its choosing.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



65 Billion Barrels Is Only the Beginning

President Trump announced this weekend that the United States had secured majority control over more than 65 billion barrels of Venezuela’s proven oil reserves through a partnership with private business.

That is a big number. But it is not the number the oil and gas industry will be focused on.

Venezuela already has the largest proven oil reserves in the world. It produces only about 1.25 million barrels a day. That gap tells you a lot about what comes next.

Sixty-five billion barrels of reserves is not 65 billion barrels of supply.

The oil is there. The harder question is what it takes to actually produce it.

Existing wells may need work. Infrastructure needs investment. Equipment and people have to move into the country. Companies have to decide the economics work. And before anyone commits billions of dollars, they have to be comfortable that the agreements they sign today will still be enforceable years from now.

That is the part experts in this industry will be watching.

My firm works with oil and gas companies on the agreements behind development. Most people will never read those agreements, but they matter. Companies need to understand what they own, what they control, what they are obligated to spend and what protections they have if circumstances change.

Boards do not invest billions based on an announcement. They invest when they have enough confidence in the contracts and the economics to put capital at risk.

Contracts drive capital. Capital drives production.

And none of that happens overnight.

There may be opportunities to improve production from existing Venezuelan fields relatively quickly. But in the oil business, relatively quickly can still mean years. Larger redevelopment projects can take much longer.

That matters when talking about oil prices too.

Markets can react to an announcement immediately because markets react to expectations. But if the question is whether this will have a lasting effect on oil prices, actual production matters. More barrels reaching the global market means more supply and, all else being equal, downward pressure on prices.

But first you have to get the barrels to market.

For perspective, the world consumes roughly 100 million barrels of oil every day. The United States alone consumes around 20 million barrels per day. Roughly 20 million barrels per day move through the Strait of Hormuz.

So the important question is not simply how many barrels Venezuela has underground. We already know it has an enormous amount of oil. The question is how much additional oil can actually be produced, how much investment that will require, and how long it will take.

Oil companies are accustomed to evaluating political, legal and commercial risk around the world. Venezuela is obviously not the first place where those risks have existed. Companies deal with them through contracts, economics and legal protections. If they can get comfortable with those things, capital can move. If they cannot, it does not.

That is why the agreements behind this announcement may ultimately be more important than the headline number.

If those agreements create enough confidence for significant private capital to move into Venezuela, this could become a very significant development for Venezuela, U.S. companies and the global energy market.

But in a country as chaotic as Venezuela, with uncertainty as to the future resilience of its government and institutions and reports of consensus opposition to the agreement, that is a big ‘if’. In short, we are not there yet.

There are a lot of steps between announcing access to reserves and producing oil from those reserves. This seems to be a first step, but not much else.



The Bells are Ringing Again, and This Time Sweden is Inside the Alliance

On August 25, CIA Director John Ratcliffe landed in Moscow. He met Russian officials, warned them against attacking NATO, raised Moscow’s support for Iran, and flew home. Allies and Kyiv were briefed before and after. It was the first trip of its kind since the former CIA Director William Burns made the same flight in November 2021, fifteen weeks before Russia crossed into Ukraine. As one former CIA operations officer put it, the fact that a director gets on a plane at all suggests the threat behind the trip was judged credible.

The warning had gone public three weeks earlier. US intelligence assessed that Putin could order a limited attack on a NATO member, most likely against the Baltics or Poland, at some point between this autumn and 2029. The assessed purpose is to test Article 5’s, and to fragment the alliance by proving it lacks a response.

The location for that scenario is Sweden’s front yard. Gotland sits in the middle of the Baltic Sea. Sweden’s air and naval reach covers the sea lines that would carry reinforcements to the Baltic states in the first week of a crisis, and Swedish territory is key for air superiority.

In 2022, Sweden’s intelligence failures were Sweden’s. The country was outside NATO, and a wrong Swedish assessment was not changed after American influence. But Sweden joined NATO in March 2024. Swedish capability will now feed an alliance and Swedish blind spots will become an alliance wide liability.

Sweden is rebuilding its intelligence architecture directly into this warning. A new civilian foreign intelligence service, Sveriges utrikesunderrattelsetjanst (UND), opens January 1, 2027.

Not the First Warning to Go Unheeded

The winter of 2021 into 2022 was not a case of intelligence that wasn’t shared in time. In fact, Washington and London put detailed intelligence assessments on the table publicly, repeatedly, and with a specificity that made professionals uncomfortable.

The influence operation was also conducted privately. Burns flew to Moscow in November 2021 to deliver warnings to the Kremlin, then made repeated trips to Kyiv and allied capitals.

These efforts unfortunately were partly in vain. The French and German services judged a full invasion too irrational and too costly for Putin to attempt. Several capitals read the American warnings through the memory of Iraq weapons of mass destruction and discounted them accordingly. The gap between what US intelligence believed and what European governments were willing to act on became one of the more consequential intelligence failures of the post-Cold War era. It was not a failure of collection; it was a failure of influence.

The analytic error underneath this failure is known as mirror-imaging; the assumption that your adversary weighs cost the same way that you do. European intelligence services were good at counting tanks, tracking movement and mapping order of battle. They were far less equipped to model what was happening inside the Kremlin, and when they tried, they substituted their own arithmetic for Putin’s.

Sweden’s record is part of that story. In the month before the attack, MUST assessed that a major assault was unlikely. Foreign Minister Add Linde questioned American intelligence directly to Secretary of State Anthony Blinken, leaning on her own service’s skepticism.

FOI, the Swedish civilian defense research agency, did not forecast a full-scale war either, but its Russia and Eurasia analysts raised the alarm publicly and privately. But the warnings sat outside MUST’s military remit and had no route into the warning chain.

Wilhelm Agrell, professor of intelligence analysis, called MUST’s miss a textbook error: analysts reasoned that invasion was unlikely because the consequences would be too severe. That was an assessment of what a rational Swedish planner would do in Putin’s position, not of Putin himself.

Why Military Intelligence Could Not Have Gotten this Right

The standard account of Russian deception before February 2022 is that Moscow hid its intentions from the West by dressing the buildup as an exercise. That is true and it is the less interesting half.

The more consequential fact is that Moscow hid its intentions from its own army. Captured Russian soldiers told interviewers they believed they were on a routine exercise until hours before they crossed the border. Their officers reportedly withheld the truth because they doubted the men would fight if they knew. The deception was not aimed outward alone, but at the force that was executing Putin’s orders.

The same held on the other side. The former commander of Ukraine’s Joint Forces has said he received no official written warning on the eve of the invasion and acted on an informal tip.

A military intelligence service collects against a military. It reads order of battle, logistics, movement, readiness, signals traffic, and where it can, human sources inside the structure. Every one of those disciplines was pointed at Russian forces in the winter of 2021, and every one of them was working.

They were also, on the question that mattered, reporting accurately. The units were postured for an exercise because the units believed they were on an exercise. The logistics looked thin for an invasion because the supply staff had not been told they were invading. A colonel asked in early February what his regiment was doing would have given an honest answer, and the honest answer was wrong.

The buildup was visible; but what was not visible was the decision. Putin realized his opponents intelligence weakness, and made the decision in a room that his wider military had no access to. Thus, collection against an army cannot retrieve a judgment that the army has not been told.

MUST did not miss the invasion because its analysts were incompetent or because collection was thin. It missed because it was asked a political question and had been built, staffed, tasked, and funded to answer a military one. Working harder inside that structure would have produced more detail about an exercise.

A design problem does not yield to effort. It yields to design. If intent lives in the politics of a regime rather than in its order of battle, then somebody has to be built to read the politics, and that somebody cannot report up a military chain to a military customer asking military questions.

The American Half of the Ledger

Washington read Russian intent correctly, but got the second question wrong.

Almost every Western service, American ones included, assessed that Kyiv would fall in days. The Chairman of the Joint Chiefs told members of Congress that the capital could be taken in seventy-two-hours. The day after the invasion began, US officials were still assessing that Kyiv could fall within days. The intelligence community later reviewed what went wrong, and the answer was not the Russian side of the equation.

Examine how that assessment was built. Analysts counted Russian formations and Ukrainian formations, compared readiness and equipment, ran the correlation of forces, and derived an outcome. It was rigorous, and every input was real. What it failed to weigh was whether Ukrainians would fight for their country, and misjudged the national will of resistance.

That is mirror-imaging pointed at a friend instead of an adversary. In the European case, services assumed Putin would calculate cost the way a Western government would and concluded he would not invade. In the American case, services assumed Ukrainians would calculate survival the way a defeated army could and concluded they would not hold. Both times, the arithmetic was correct and the human judgment underneath was imported from somewhere else.

Within two weeks of the invasion, the United States and its allies were quietly planning for a Ukrainian government in exile and an insurgency, which is the posture you adopt when you have concluded that the state will stop existing. Zelensky was reportedly offered evacuation and answered that he needed ammunition rather than a ride. The pessimism shaped what was planned, what was offered, and how fast it moved, in the weeks when speed mattered.

In the other direction, Zelensky spent the run-up publicly disputing American warnings, arguing that the alarm was doing more damage to his economy than the threat. Biden later said Zelensky simply “didn’t want to hear” it.

Washington was right about Russia and could not get Kyiv, Berlin, Paris or Stockholm to act. Kyiv was right about Ukraine and could not get Washington to believe it. The problem caused both an unprepared Europe and delayed American aid.

What Sweden is Actually Building

Former Prime Minister Carl Bildt led the review of Sweden’s Intelligence Failure, “En reformerad underrattelseverksamhet”. The report stated that Sweden was unusual among comparable allies in having no foreign intelligence service outside of the military chain of command reporting to the elected government. The country had excellent military intelligence, a capable security service (Sapo), and one of Europe’s better signals organizations (FRA), but no institution capable of reading political intent. The report recommended a civilian agency directly under the Foreign Minister, which was later approved.

Sveriges utrikesunderrattesetjanst, UND, will sit alongside MUST, Sapo and FRA rather than replacing any of them, and is meant to be a senior shop rather than a second MUST, growing over several years.

UND takes over KSI, the Office for Special Collection, which is Sweden’s clandestine human collection and which operates in other countries under cover employment and false identity. It also takes over the production and management of qualified protected identities, previously run by the Armed Forces. The legal architecture moves with it: the Defense Intelligence Court is renamed and the oversight body redesignated, moving Sweden closer to the structures of MI6 or Estonia’s Valisluureamet: a small, civilian, politically literate foreign service.

The government named Andreas von Beckerath director-general and Annika Brandstrom his deputy, both running from January 1, 2027 for six years. Von Becherath is a diplomat: with ambassadorships in Ukraine and Poland, deputy director-general and head of the Foreign Ministry’s Eastern Europe and Central Asia department, with earlier postings in Moscow, Bucharest, London, Berlin, and New York. He is currently serving as the European Union’s ambassador in Belgrade, head of the EU delegation to Serbia, a post he has held for a year.

Brandstrom ran the inquiry that stood the agency up and served as deputy national security advisor. She has a long history of working in crisis management, preparedness and security, working directly for the Prime Ministers office.

The diagnosis was that Sweden could count Russian tanks but not read Russian politics. The team hired to fix it spent their careers reading politics and managing crises. Sweden did not appoint a general, nor an intelligence officer. It appointed a diplomat and a bureaucrat, showing that the government took the review seriously.

Frictions and Objections

Thomas Nilsson, who runs MUST, said that in the current security situation Sweden cannot afford to let anything fall through the cracks. Supreme Commander Michael Claesson has noted that UND’s civilian funding may not count toward NATO spending targets. Analysts have pointed to the seam that any civil-military split creates, which a capable adversary will probe.

All of Sweden's eight parties on the foreign affairs committee backed the legal changes. Four of them, the Social Democrats, the Left, the Greens and the Center, filed seven reservations and three separate statements. The Social Democrats called four months an extremely brief period for a reorganization of this size. The Left said the process may create more problems than it solves. The Center Party called it democratically flawed.

Underneath the procedural language is a specific operational worry: KSI leaves MUST. The Social Democrats’ objection is that the military loses a capability and is not compensated for the loss. Clandestine human collection is not a function that transfers on an effective date. Cover takes years to build and one administrative error to destroy. Officers working abroad under false identity are being re-subordinated to an agency that does not exist yet, whose director arrives on the day it opens, in the same window in which US intelligence says Russia may test the alliance.

Recruitment began before parliament formally approved the agency. The Social Democrats' complaint was tied to former hiring flaws for the National Security Advisor. Naming a year leadership team weeks before a national election, after declining to seek cross-party agreement, was provocative. They have a point; the decision was taken hastily in a political setting that often favors alignment across the aisle.

As a result the opposition signaled it may revisit elements of the reform, and the Swedish reporting has been blunt that if an incoming government shelves the service, three years of work goes with it. While the diagnosis is correct and the institutional design is sound, the infrastructure has to survive the people who built it, and whoever wins the next election. Sweden’s diagnosis was that its intelligence architecture was wrong for the threat. The risk now is that the new institution is not properly aligned across the aisle.

What Washington Should Do, and What Stockholm Should Ask For

Sweden is fixing the half of 2022 that was Sweden’s. Nothing in the American half has been fixed, and standing up a new allied service is a rare occasion when that half becomes cheap. None of what follows requires an appropriation.

Engage the institution, not the government. The appointed leaders will outlast the government that named them. American engagement pitched at the service and its career leadership must survive a change in Stockholm. Engagement pitched at the ministers who created UND does not, and given how the reform was legislated, engagement that looks like an endorsement of the current coalition would actively damage the agency’s standing with the parties most likely to inherit it. The correct posture toward a new foreign intelligence service in an election year is professional and studiously boring.

Establish liaison at the founding. A service’s analytic culture and its foreign relationships set early and then harden. What UND treats as a finished intelligence product, how it handles dissent, what it considers sufficient evidence to warn a prime minister, and whose reporting it trusts will all be settled in 2027 and 2028 by people who are being hired. Washington should be in the room while the habits are forming, and the subject of that liaison should be intent rather than order of battle, because reading intent is the entire reason the agency exists.

Make the 2022 improvisation permanent. The declassify-to-persuade campaign that Washington and London ran that winter was invented under pressure, with skill, and then set aside. A standing mechanism for releasing intent-grade material to allies at speed, with the handling rules and the release authorities agreed in advance would mean the next warning arrives in a form that an ally can act on. The lesson of 2022 was that being right in February is worth little if the ally does not move until April.

Settle the accounting question now. Claesson’s concern that UND’s civilian budget may not count toward NATO spending targets is an alliance question. The Hague summit’s target splits into 3.5 percent for core defense and 1.5 percent for defense-related spending, and the substance of that 1.5 percent has not been well-defined. Washington has more influence over that definition than any other member. A civilian foreign intelligence service whose product feeds alliance warning belongs in the basket. If it does not, the alliance will have told every member that the safe answer is to keep intelligence in uniform, maintaining the structure that failed in 2022.

Clarify Expectations. Sweden should ask for written handling and onward-sharing terms at the foundation, when it has maximum leverage and when the terms can be built into the agency rather than bolted onto it. It should ask for reciprocal analytic exchanges, including joint red-teaming aimed specifically at mirror-imaging, which is the failure both services can share and neither can audit alone.

Assign UND a responsibility in NATO. A small service does not compete across the whole target set, but Sweden has geography, language, history, and now a reputable and capable director. UND should come to the table as the alliance’s lead on a defined portion of the Russian problem rather than as a recipient of American products. Partners who bring something are listened to.

A Warning is Not a Decision

Sweden has looked hard at their failure and built an institution in response, which is more than most European governments have done with the same four years. The review named the problem, the legislation moved clandestine collection out of uniform and under civilian control, and the government hired a team with experience reading exactly the kind of politics that can accurately foresee an invasion.

The failure of influencing has no institution behind it in Washington or elsewhere. It was solved once, improvised under pressure in the winter of 2022, and allowed to lapse. That is the part of 2022 that is genuinely fixable, but it needs to be assigned. The American task is to build a relationship durable enough that whoever party runs Sweden does not matter.

Burns flew to Moscow in November 2021 and came home with a warning that proved correct, and it moved nobody in time. Ratcliffe made the same flight in August. The question worth asking is not whether the assessment behind it was accurate. The question is what happens after he lands, and whether four years, a war, and a new agency in Stockholm have changed the answer at all.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



We Are In An Unpredictable War Of Attrition

We are squarely in the target sights of ‘Unintended Consequences.’

What do I mean by this? Think of it as a broad spectrum of possible consequences when missiles and drones are being slung back and forth between Iran and U.S. Navy vessels and bases, and the energy and commercial facilities and ships of its Gulf allies. On one end of the spectrum, accidents happen: think the inadvertent U.S. airstrike on the girls’ school at the beginning of the war, and the more recent ‘wedding party’ casualties when a U.S. missile struck a nearby communications tower. These are tragedies for all involved. On the other side, an Iranian missile made its way through U.S. air defenses to strike a U.S. military facility in Jordan, resulting in the deaths of three U.S. troops. The latter resulted in a robust U.S. military response that targeted a variety of Iranian military facilities. This was a success for Iran and a tragedy for America.

On the other end of the spectrum, what if one of Iran’s ballistic missiles successfully navigates to its target - a U.S. base or navy vessel, for example - and significant U.S. casualties, dead and/or wounded, result? The U.S. administration is likely to come under tremendous political pressure to respond with overwhelming force. This could elevate the stakes even higher, cutting off any chance of a negotiated settlement, remote as it currently is. And with the regime already having been severely degraded militarily, and its leadership ranks diminished, what does that leave in terms of targets? More of the same?

It could also result in calls to withdraw U.S. forces, given the antipathy of a majority of the U.S. population to a war they view as unnecessary, ill-advised, and ill-managed. This would leave Iran in a weakened yet still dangerous posture, with the ability to pressure the world economy at will going forward. Neither option is appealing.

Oh, and by the way, notwithstanding the administration’s verbal gymnastics, this is very much a war.

D-Day Sanctions Regime

On the surface, this appears to be a pretty solid strategy, or at least better than what has been tried to date: Simply squeeze the Iranian economy until the regime cries uncle. It is already having an impact and will likely continue to compound the pain. But it is neither simple nor clear-cut. Who will it actually impact, how badly, and when? A total blockade means not just money or arms. It means no food. It means no medicine. And a host of other basic necessitates. The Iranian people will feel it first, particularly the young, the old, and the sick. Regime insiders, including the leadership and their loyal (for now) security forces, will be the last to see the effects.

And we have already seen Russia and China reject complying with the secondary sanctions that comprise the heart of this enhanced effort. So, no one knows what will happen if they choose to challenge the blockade; It is highly unlikely that U.S. forces will use force against Chinese vessels attempting to access Iranian ports. And that does not take into account less overt (read clandestine) interactions - intelligence sharing, weapons system development, sabotage efforts against Gulf country facilities, including pipelines, etc. - that would further evade and/or erode the U.S. advantage.

So, while there will be pain, and lots of it, as I said in a recent BBC interview, there remain many unknowns. Informal smuggling networks have abounded in the region for Millenia. The regime will utilize every trick they have learned since the ‘79 revolution while building a ‘resistance economy’ to get around the blockade/sanctions. And potentially with the implicit, if not explicit, support of two major world powers. In the end, this does not presage the near-term submission of a regime that values survival above all else. This remains very much a test of wills.

Furthermore, what happens when the world sees the Iranian people starving before their eyes? I’m not sure they will countenance this for long.

So, Who Has More at Stake?

The U.S. people are seeing higher gas prices at the pump, rising food costs, overall inflation, and more. This is painful, but certainly not existential, at least not yet. The increasingly negative impact on the world economy stands to worsen things considerably if the status quo continues for too long, so Americans are watching closely. And the mid-terms are fast approaching.

The Iranian people are seeing the destruction of their economy, their country, and potentially their very way of life. It is very much existential. The specter of a thundering locomotive of new sanctions bearing down on them must certainly be terrifying. I have no doubt many Iranians blame the Islamic regime for bringing this down upon them. But as things worsen, they may turn against the U.S. and its allies for abandoning them to the depredations of the regime.

The Iranian regime most certainly views this as an existential threat, notwithstanding its rhetoric. They would be fools not to. But Netanyahu’s 2 September statement that the Israeli government is, “working to bring down this regime and defeat it,” accompanied by Trump’s 2 September statement publicly questioning, “when the Iranian people would rise up and fight,” is unlikely to motivate them to negotiate. They will need to be forced to submit. My experience with Iranians tells me that the harder you press, the more resistant they become. Uncharted territory indeed. We will see.

China and Russia both have an adversarial relationship with the U.S. and important interests vis-à-vis Iran: military for Russia (drones) and commercial for China (oil). Why would either go out of their way to assist the United States in removing itself from a self-imposed disaster that is distracting it from issues they care about while diminishing its military capabilities, all with minimal effort? That is a question that remains to be answered.

Speaking of Regime Change

U.S. political leadership answers to the American people at the ballot box. The system is a bit creaky at the moment, but (for now) it remains intact.

The Islamic regime, by design, does not answer to the Iranian people. Iran’s elections are truly rigged, primarily by the Guardian Council’s ability to reject candidates for office, but also with an increasing willingness to falsify election results. And in the end, the Supreme Leader is able to reject any initiative or law he disagrees with. We have seen the results when the Iranian people see no recourse for accountability by the regime: people in the streets, followed by blood in the streets.

Without substantial outside support, of which we have so far seen little evidence, the populace will be hesitant to go back to the streets, knowing that if they do, they are on their own. It could happen if things get bad enough, and it is possible it might even ultimately be successful, but it is almost certain to be a massacre, followed by chaos and a very uncertain end. Yet another example of unintended consequences.

Where Are We Now?

For the moment - and this may already have changed as I write this - we are back in what I refer to as a Hyperbolating phase, where we are seeing threats/counterthreats being tossed back and forth with abandon. Most of these statements are utterly meaningless and can be ignored. It appears both sides are waiting to see who blinks first.

U.S. messaging appears to be somewhat disjointed, contradictory, and lacking an overall strategy, with the President, the only real decision-maker, continually wandering on and off the path of others in his administration: Trump - I don’t care/where are the Iranians?; Hegseth - continued confrontation; Bessent - economic asphyxiation; Rubio - no nuclear weapon/economic pressure; Vance - not a war/intermittent containment. You could claim this is purposeful to keep Iran uncertain and off balance, but it should not be doing the same to Americans. President Trump failed to bring the American people on board beforehand with a coherent (and honest) case for war and an actual strategy for winning it. The continued shuffling of various justifications we have seen from the administration serves simply to stir the mix of confusion.

I get the distinct feeling that, given the fast approaching mid-terms and the deep hole they have dug for themselves, the administration just hopes that something/anything works so they can walk away from what is clearly a foreign policy disaster.

Iran messaging, on the other hand, appears, at least to me, to be a bit more coordinated if not strategic. While most Iranian government leaders are defiantly threatening massive retaliation for continued U.S. strikes (hyperbole), including the military (both Artesh - regular military and IRGC - Revolutionary Guards), the Parliament and its Speaker Ghalibaf (“U.S. actions will not go unanswered”), and the Foreign Affairs Ministry (claiming “war crimes” by the U.S.), the lone man on an island is the Iranian President, Pezeshkian; “we do not seek war but will respond,” and, “Iran remains open to negotiations, under the June MOU”. It is important to realize that the Iranian President has virtually no policymaking role in Foreign affairs, so his statements should be given less weight than others. But he would never make this offer without the approval of the IRGC, the Supreme National Security Council and, most likely, the Supreme Leader (or whoever is speaking for him). As I have written previously, I believe that the vagueness of the original June MOU was oddly advantageous to Iran and served to lead us directly back to where we currently are. So… this would seem to indicate negotiations are at least still on the table, just not under conditions particularly favorable to the U.S.

Where Are We Going?

Military escalation? A slow grinding pressure on the regime, testing their willingness to allow their people to suffer? Or a return to the negotiating table?

Who knows? There is no simple or painless way out of this.

Unintended consequences, after all.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Can America’s All-Volunteer Force Survive the Next War?

“It made sense for the United States to transition from this mixed force of conscripts and professionals to an All-Volunteer Force. It has enabled us to develop a truly professionalized force. It's a professionalized force that's a lot smaller than what we saw during the draft era. And the implications of that is that it can detach the military from society or society's understanding of the military.”

That was Katherine Kuzminski, director of studies at the Center for New American Security, speaking last Wednesday at the Center for Strategic and International Studies (CSIS) as one of the editors of the book, Bend But Do Not Break: Shaping the Future of the All-Volunteer Force.

Appearing with Kuzminski in what became a wide-ranging discussion of the military and All-Volunteer Force were co-editors Jason Dempsey, a former US Army Infantry Officer who's with the Center for Veteran Transition and Integration at Columbia University, and Jaron S. Wharton, a career infantry officer who recently commanded a brigade in the U.S. Army's 82nd Airborne Division and is currently a visiting fellow at CSIS. Moderating the panel was Eliot Cohen, Arleigh Burke Chair in Strategy at CSIS and former Counselor of the Department of State.

Early in the conversation, Kuzminski pointed out that while “the shift to an All-Volunteer Force, which would enable a more professional force, there was ‘a caveat,’” It was “supported by a standby draft. So the draft is actually still on the books. It would require Congress and the President to pull that trigger, should we need it.”

Wharton picked up on that saying, “The All-Volunteer Force’s success or continued success is not a foregone conclusion. It requires a lot of maintenance and sustainment. And because it's been so long since we've enacted that draft, it's not in people's [minds]…And so that almost makes it a relic. And that's a muscle that we can't allow to atrophy, especially in the worst contingency, if you might believe, for example, that we're on the verge at some time in our future of a large-scale combat operation, that would dwarf the absorptive capacity of the All-Volunteer Force.”

Wharton went on to point out “Most problematic with the public's understanding is the very term All-Volunteer Force because this is not a gang of volunteers. Everybody is paid. And so it's interesting that you know when we started out there were economic concerns…and they were largely couched around individual freedom…people should not be forced to do something they don't want to do.”

Dempsey added, “What the public misses now is this [the All-Volunteer Force] is a costly enterprise and nobody is serving for free. Nobody is a true volunteer and so if we actually start peeling back and interrogating those costs I think we come to a better understanding on the strength, resilience, or fragility of the system.”

Dempsey went on to point out a major change the All-Volunteer Force has created.

“The black population saved the All-Volunteer Force,” Dempsey said explaining, “When, you know, it turned out that they relying on young white males to fill the conscription [draft] Army. And then once that went away, the folks who looked at the opportunities and the economic incentives present in the military, and the ones that started flocking to it, were young blacks, and a lot of black women.”

He added, “You know, it's ironic that much of our enlisted ranks for over 20 years were dominated by senior black women in leadership positions, because it was all part of that cohort from late 70s, early 80s who saw a once-in-a-lifetime opportunity for economic mobility.”

At that point Moderator Cohen noted, “What about immigrants? I'll tell you one of the things I remember during the Iraq war. I was over there on a fairly regular basis going to a naturalization ceremony in one of Saddam Hussein's gaudy palaces. But it was an amazing and deeply moving sight just how many men and women in uniform, who had not been citizens, were becoming citizens in the middle of a combat tour.”

To which Dempsey described enlisting immigrant volunteers as “Hugely important and we've seen massive growth of the Hispanic population over the last 15 years in the military.”

At one point, Wharton noted, “Women in the military were once capped at 2%...If you had a female service member that was married to a civilian male, that female service member wouldn't get a full housing allowance with dependents. That's actually not that long ago, if you can believe that. And over time that 2% cap has grown to we're about 17% [women] in the aggregate.”

He added, “What wasn't anticipated is not just the family dynamic, but the role, the prominence of women. So let me be clear, women have saved quantitatively and qualitatively the All-Volunteer Force. This experiment would not be sustainable without them in our ranks.”

There also was extensive discussion of the impact on deployments thanks to the All-Volunteer Force.

Kuzminski said, “I don't think that in 1973 [when transition to the All-Volunteer Force took place] they were thinking about the impact of the size of the Reserve component and the competition for talent among the Active Duty and the Reserve. The Reserve component was orders of magnitude larger with more relevant recent military experience back at the transition…So we had a more sustainable kind of backbench of folks that we could tap into should we need to.”

She said, a cultural change was needed because before 1973, “It was easy for the Active component to say, ‘Oh, our little brother, the National Guard, or you know, the Reserve component isn't at the same level as us.’”

The change took place as Kuzminski explained, “We certainly saw a heavy deployment and a use of the operational Reserve in the wars in Iraq and Afghanistan, both for the Reserve component and for the National Guard. But when we look at our recently retired or inactive Reserve it's much smaller than what we had in the past. And that is kind of the first line of defense should we have a truly existential crisis.”

That led to what Kuzminski described as, “We've had to bend the rules sometimes or bend this construction of a truly All-Volunteer Force to have elements of compulsory service that is separate from how the broader society is thinking about deployment.”

In a way, she said, “We had compulsory service. It just looked a little different. So, the Army shifted from 12-month deployments to 15-month deployments while people were downrange. The recall of the Retired Reserve was implemented…They thought they were, you know, completing their contract and turns out that they weren't.”

Wharton raised the question about “a [future military] conflict that would require some sort of mobilization of broader society, and over time we've seen that that actually hasn't been the case. Now, would that be the case if we were fighting a near peer? I think that forces potentially an entirely set of different conclusions. But when you're fighting someone that is not a near peer, you can rely, at least we've proven that you can rely with some policy changes on the margins, the All-Volunteer Force to sustain that.”

Dempsey, referring to the current concerns caused by the Iran War, said, “We constantly look at the defense industrial base and everybody wants to talk about how many shells we can produce, you know, how many interceptors we make. And I think we really need to spend some time on the human dimension of all this, because one of the things that those of us who study this constantly talk about are two factors uh, eligibility and propensity.”

“The All-Volunteer Force, as currently built, requires a very educated force, a very disciplined force and folks that kind of want to be there,” Dempsey said, adding “And so in terms of eligibility, we know that because of rising obesity rates, drug use, lack of educational attainment, we're down in the 20s [percentage of males who qualify for military service]…We, most Americans, aren't even eligible to join the military.”

Dempsey continued, “So among those who say yes, I want to join,…you have a very, very, small subset of Americans who are willing and able to serve.” That led, he said, “at the height of Iraq and Afghanistan was a lowering of standards, waivers. And I will tell you having been in an operational unit at that time, you know, your waivers always account for your biggest disciplinary problems.”

Although the military services say they are filling their new enlistee quotas this year, Dempsey asked, “How are we going to restructure this force to accommodate people who maybe don't have the educational attainment, maybe are slightly overweight unfit, and what incentives we have to give them?...Short of a draft, how much money would we have to throw at the American public and our youth just to get a small bump in a short period of time.”

Dempsey went on to talk about “If the military is the most trusted institution, let's just make everybody join the military or let's do National Service, or all these things that somehow we can extrapolate from the military to solve all the rest of these societal ills.” To which he responded that “is not the military's mission, right? We're not a character-building summer camp for wayward youth, right? Our mission is to fight and win wars. And so people lose that and want to use the military for all these other things.”

Wharton brought up talk about “this growing warrior caste,” about which he said, “It is 100% real…I'm blanking on the data point at the moment, but there is a greater [number] than you would expect…In part that's because youth growing up in a military family are exposed to opportunities. It is not that different from families of doctors, families of firefighters.”

But Wharton went on to say, “We should be leery if there happens to be a nuance in this data where you start to see a veteran [military] population -- and there has been some evidence of this -- where they don't support necessarily their children going. Or they don't want them to [join], but once they go in they do choose to support them and there has been some evidence. Please correct me if I'm wrong that that is actually starting to be the case.”

Looking to the future, Kuzminski said, “I think it takes understanding the population that we're actually trying to recruit, versus those who are in service right now, and sticking to what would incentivize them.”

She noted the recruitment problems with Gen Z “who you know now are actually towards the upper end [of their time in military service]” and “now we're thinking about Gen Alpha who is coming up behind them.”

“When we think about what has motivated their [Gen Alpha] career decisions,” Kuzminski said, “it's been a desire to be mission-focused in the work, whatever it is that they do. It’s a desire to have multiple jobs over the course of a career” She then pointed out, “Over the course of a 40-year career in the military, you live in multiple different places, have multiple different roles, you grow through the organization. When the military is functioning at its highest ideal good, it is a mission focused organization that does look different from the rest of society. I think we just need to find a way to match the reality of that military service with what it is that those we're trying to recruit are looking for.”

On the future, Dempsey said, “Right now we're very, very, comfortable both as a nation and as a military where whenever there's a issue just throw more money at it. And right now we're able to throw $1.5 trillion at our military. I'm not sure that's sustainable, and so I'm not sure how long we can keep putting off some of these third-rail hard conversations about what real structural reform means” when it comes for the All-Volunteer Force.

Wharton said of the future, “I'm optimistic absent, with a heavy caveat, of an existential crisis because that fundamentally changes the game…This [the All-Volunteer Force] is an enormous cost to maintain, this experiment, and it requires change on the margins.”

One thing is clear, the All-Volunteer Force, the National Guards and Reserves need further study, along with some understanding of who in the future will be willing to undertake U.S. military service. Or does the U.S. need to return to a draft?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Setting Terms with America’s Tech Giants

If China attacked Taiwan tomorrow, the question might not be which aircraft carrier sails first to the Pacific, but whether a private company will activate satellite coverage over a small island. As Ukraine does today, Taiwan could soon depend on the choices of executives running commercial networks that sustain modern life. Ukraine’s wartime resilience has relied on more than 40,000 Starlink terminals and the voluntary actions of technology firms that became, in effect, auxiliary actors of national defense.

Strategic decisions once made only by governments—allocating aid, managing escalation, defining battlefield conditions—are now also being made by corporate boards and CEOs. These companies control platforms and infrastructure that shape the global balance of power. This is not an anomaly; it is the new reality of modern conflict.

America’s largest technology firms now command tools that function like strategic assets, weapons, and utilities. Satellite constellations and undersea cables are the new sea lanes of the digital era. Cloud infrastructure and AI systems are the power grids of national productivity and security. Semiconductors are the jet fuel of artificial and human intelligence as well as communication. Firms are no longer simply competitors in markets; they are multinational actors wielding levers of geopolitical influence. Their revenues exceed the GDP of many nations, and their governance decisions reverberate through global politics.

Yet, unlike in China where the state dictates corporate alignment, the United States leaves these questions to market forces and executive discretion. That gap is a strategic liability. In a Taiwan contingency, Washington cannot afford to discover in real time whether it can count on its own companies. The answer must be structured and understood in advance through a transparent framework that aligns economic incentives with national security.

This paper proposes such a framework: a public-private readiness framework (PPRF), modeled after Status of Forces Agreements (SOFAs) but oriented toward economic and technological preparedness. The PPRF would pre-negotiate expectations, responsibilities, and incentives between the U.S. government and critical technology firms. The goal is not coercion, but preemptive coordination—a framework that makes values-based alignment economically rational and reputationally rewarding.

Case Study: Ukraine Today, Taiwan Tomorrow

Ukraine demonstrates the stakes. When Russia invaded in 2022, Vice Prime Minister Mykhailo Fedorov appealed directly to SpaceX for help. Within days, Starlink terminals arrived, sustaining command communications and civil infrastructure after Russian cyber and kinetic strikes. However, the same private network that enabled Ukraine’s defense also introduced new vulnerabilities. When Kyiv sought to extend Starlink coverage to support operations in Crimea, SpaceX declined, citing escalation concerns. Later, the company requested that the Pentagon assume financial responsibility for Ukraine’s access.

Microsoft, Amazon Web Services, and Google provided equally decisive, yet discretionary, support. They detected malware, migrated government data to secure cloud storage systems, and shielded Ukraine’s digital infrastructure from collapse. Their interventions, voluntary and unscripted, shaped the course of a sovereign nation’s survival.

Taiwan represents the next and far greater test. Chinese military doctrine targets communications infrastructure first: undersea cables, satellites, and energy grids. A successful first strike could digitally isolate the island. Whether Taiwan’s government, hospitals, and economy continue to function may depend on decisions made years before the first shot is fired in corporate boardrooms in Silicon Valley thousands of miles away.

Unlike Russia, China underpins global supply chains and is a lucrative consumer market for U.S. companies. Tesla, for example, operates large factories there; manufacturers of all industries remain dependent on Chinese rare earths and critical minerals. In contrast to hardware companies deeply tied to Chinese supply chains or markets, U.S. software firms such as Google and Microsoft began reducing their China exposure decades ago. Google’s 2010 decision to exit mainland China operations followed a major cyber-attack and disputes over content censorship.

This distinction exposes a key challenge: corporate behavior in conflict will correlate with how exposed a firm is to China. Firms with significant Chinese-market sales or Chinese supply chain dependencies face commercial and regulatory pressure that limits alignment with U.S. policy during crisis. By contrast, firms with less China exposure have greater freedom to act in U.S. and allied interests. Any readiness framework must therefore stratify members not only by capability, but also by strategic exposure to adversarial states.

The lesson from Ukraine and the looming test of Taiwan is clear: the United States cannot rely on ad hoc corporate goodwill. It must coordinate in advance, defining expectations before—not after—the first cyberattack or missile strike.

Proposal: A Big Tech SOFA

The United States should establish voluntary agreements with critical technology firms to clarify obligations and protections in national emergencies. Modeled after bilateral SOFAs but tailored to industry stakeholders, these agreements would lay out how companies would contribute to the national defense when vital infrastructure or networks are attacked.

Defined Obligations

Participating companies would commit to support contingency missions. A satellite provider would guarantee continuity of communications if undersea cables were cut. A cloud provider would surge cyber defense capabilities to critical infrastructure under coordinated government direction. A semiconductor firm would prioritize supply for defense and allied systems if global access were disrupted. Each obligation would be narrowly defined and scenario-based to preserve flexibility and ensure predictability.

Legal and Financial Clarity

Like traditional SOFAs, the framework would set terms for cost-sharing, liability protection, and legal jurisdiction. Companies would be able to predict how expenses, indemnities, and export-control compliance would be handled. This removes hesitation at moments of crisis, enabling decisive action without regulatory paralysis.

Operational Terms

The agreements would outline the conditions under which firms operate within the national security ecosystem. In return for commitments, industry participants would receive structured incentives—procurement preference, access to federal financing for surge capacity, fast-track security clearances for key staff, and reputational recognition as trusted national partners.

Participation would remain voluntary and discreet until activation. Companies could join through confidential

commitments, with public identification triggered only under crisis conditions. Exit clauses would allow either party to terminate or revise obligations as markets and technologies evolve.

Importantly, this framework would complement—not replace—existing authorities such as the Defense Production Act and the International Emergency Economic Powers Act. These instruments can compel corporate action, but they are blunt, slow, and politically contentious, rendering them largely ineffective to scale in times of crisis. The PPRF offers a pre-negotiated, market-aligned alternative that relies on cooperation rather than coercion—it employs a carrot, versus stick, approach.

Concerns and Political Landscape

Any proposal to facilitate deeper cooperation between Washington and large technology firms will invite scrutiny—and rightly so. Antitrust critics will warn of facilitating corporate entrenchment and eroding competition for new actors. Free market and small business champions will object to industrial favoritism and market distortion. Privacy advocates will fear data-sharing overreach and civil liberties violations. Fiscal hawks will balk at financial guarantees.

These agreements must build in protections to address these valid concerns and ensure proper congressional oversight. Industry participation should be divided into two tiers: Big Tech and Little Tech. Big Tech are systemically critical firms—such as satellite, cloud, and semiconductor leaders—that carry higher obligations and barriers to entry. Little Tech are emerging innovators—such as AI startups, cybersecurity vendors, and mesh-network developers—that can participate through subcontracting opportunities or competitive federal innovation programs like Small Business Innovation Research, Other Transaction Authorities, and technology pilot initiatives.

This tiered model preserves competition, avoids entrenching incumbents, and turns the framework into a mobility pathway for new entrants rather than a closed club for existing giants. Structured participation also replaces arbitrary, executive-level decision-making with accountable, transparent coordination between industry and government.

From a policy standpoint, the PPRF has broad appeal. National security wonks will see it as a deterrence multiplier, economic pragmatists as an industrial policy that strengthens resilience, and fiscal hawks as a cost-effective alternative to crisis bailouts.

Conclusion: Mobilize Before the First Shot

Wars are not won by improvisation. They are won by preparation. In World War II, U.S. factories retooled to become the “arsenal of democracy.” In the next conflict, the decisive question may not concern steel or oil, but whether America’s digital engines—its satellites, chips, and cloud networks—align with their own nation in its hour of need.

The public-private readiness framework offers a way to align profit with principle, foresight with flexibility, and corporate power with democratic accountability. It ensures that when the first cables are cut and the first systems go dark, the United States will not be negotiating under fire.

The time to define that cooperation—quietly, clearly, and credibly—is now.

The views expressed in this paper are solely those of the author and do not necessarily reflect the official policy or position of Microsoft, nor any other affiliated organization or employer.

Michael Salazar is a senior manager for Microsoft AI & Security.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Not the Destroyer of Worlds: Why Compute is Humanity’s Most Vital Defense

Eighty years ago, the architects of our first dual-use revolution whispered that they had “become Death, the destroyer of worlds.” Today, a new power commands that same existential awe. It was born in elite laboratories, the product of massive government and corporate investment. It is an immense, power-hungry technology, requiring vast, specialized facilities and staggering amounts of energy to sustain its core operations. For decades, the public has viewed it with a mix of awe and dread, fearing its potential to upend global security, trigger arms races, and spark catastrophic, irreversible outcomes. It is the ultimate dual-use technology—capable of both destroying worlds and powering the future.

Yet, despite the apocalyptic warnings and geopolitical posturing, its most profound and specialized use case is far more personal: fighting cancer. By harnessing its invisible, computational power, we can now detect and target malignant anomalies with a precision once thought impossible. It zeroes in on the very building blocks of the disease, finding microscopic threats hidden deep within human tissue and deciphering biological codes to save countless lives in the process.

Did you think I was talking about nuclear energy?

You’re right. But I’m also describing artificial intelligence.

In recent years, AI has pivoted from a theoretical computational powerhouse to the frontlines of biology and medicine. This is no longer speculative; it is recognized at the highest echelons of science. The 2024 Nobel Prize in Chemistry was awarded to Google DeepMind’s Demis Hassabis and John Jumper for AlphaFold, an AI system that solved a 50-year-old grand challenge in biology by predicting the 3D structures of over 200 million proteins. By mapping these molecular blueprints, AI is fundamentally transforming how researchers understand cancer mutations, accelerate targeted oncology therapies, and design bespoke immunotherapies. Alongside these molecular models, advanced clinical computer vision systems are rewriting diagnostic timelines—whether predicting breast cancer with expert radiologist precision or training on hundreds of thousands of imaging scans to predict ovarian cancer risk with unprecedented accuracy, as pioneering companies like ProvanAI, located in my hometown of St. Louis, are doing today.

Beyond the clinic, and in my field of specialization, this paradigm shift is redefining planetary resilience through breakthrough Geospatial AI (GeoAI). By fusing foundation computer vision models with petabytes of satellite, radar, and aerial data, GeoAI allows us to monitor our world with unprecedented fidelity. When catastrophic natural disasters strike, these models map flood zones, building collapse patterns, and impassable supply routes in minutes rather than days, delivering vital situational awareness to humanitarian first responders. In agriculture, spatiotemporal models track soil moisture and crop stress across entire continents to forecast yields and preempt global food crises. From tracking environmental destruction to documenting human rights crises in denied territories, GeoAI is transforming raw overhead data into proactive stewardship for humanity.

Yet realizing this potential requires colossal infrastructure, and our adversaries know it. The frontier of AI demands vast data centers, specialized silicon, and gigawatts of electrical capacity—a physical reality foreign competitors are actively seeking to undermine. Recent intelligence and industry findings have exposed coordinated Chinese influence operations designed to manipulate the American public and derail domestic infrastructure expansion. Reports from frontier labs, including OpenAI, alongside the discovery of massive foreign bot networks on platforms like X, documented state-linked campaigns using generative AI to flood social discourse with fabricated claims that AI data centers are draining local power grids and driving up consumer energy costs. Beijing recognizes that compute capacity is the decisive strategic terrain of the twenty-first century. Just as the United States recognized that mastering nuclear technology was an existential imperative in the twentieth century, we cannot allow foreign propaganda to paralyze our critical infrastructure today. We must build the power, secure the compute, and win this race—because the security, economic sovereignty, and humanitarian future of the free world depend on it.

However, leading the world in compute does not justify reckless acceleration. Over the weekend, Anthropic CEO Dario Amodei published the essay We Must Pace the Frontier, advocating for a deliberate slowdown in the development of frontier AI models to allow safety and alignment research to catch up. His call to action underscores a strategic imperative: our governance of AI must mirror the rigor of nuclear regulation. Just as the atomic age birthed non-proliferation treaties and the International Atomic Energy Agency, the AI revolution demands a comparable oversight architecture—embedded third-party inspectors, strict safety checkpoints, and enforceable global coordination. The United States and its allies must win the infrastructure race, but we must simultaneously lead the charge in establishing the international safeguards that prevent this dual-use technology from fulfilling the darkest prophecies of the nuclear age.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief





Back to top