I just want to read the news

Get the news and only the news!

Guardian Yle Kaupunki CNN Hesari Al Jazeera New York Times Reuters NPR The Cipher Brief

Guardian

Back to top

Controversial vaccine trial touted by RFK Jr gets go-ahead in Guinea-Bissau

Recommended dose of hepatitis B vaccine will be withheld from thousands of newborns by Danish researchers

A controversial research trial that will withhold hepatitis B vaccines from some African newborns was given approval to move forward this week.

It is a central part of the vaccine vision for Robert F Kennedy Jr, the secretary of the US Department of Health and Human Services (HHS) and a longtime vaccine opponent.

Continue reading...



ICJ judge Navi Pillay wins Nobel peace prize for promoting international law

Committee recognises work of South African who chaired UN commission that concluded Israel was guilty of genocide in Gaza

The Nobel peace prize has been awarded to Navi Pillay, the South African former UN human rights chief who chaired the UN commission that concluded Israel was guilty of genocide in Gaza.

The Norwegian Nobel committee said Pillay, who is serving as a judge at the international court of justice (ICJ), has “shown that legal measures can help prevent acts of war and violence”.

Continue reading...



Isaias strengthens to become first Atlantic hurricane of 2026 season

Storm expected to make landfall on US’s northern Gulf coast with risk of flash floods and isolated river flooding

Isaias has become the first Atlantic hurricane of the 2026 season, with wind speeds of 80mph and a minimum pressure of 975mb. It is expected to strengthen to a category 2 hurricane as it approaches the US’s northern Gulf coast on Friday, according to the National Oceanic and Atmospheric Administration (NOAA).

As a result of the strong El Niño, it has been a notably quiet Atlantic hurricane season. The first hurricane of the season has not formed this late since 8 October 1905, which pre-dates the satellite era (1960s) for tracking hurricanes that has allowed for more non-landfall hurricanes to be discovered.

Continue reading...



Egyptian journalists plan weekend protest over detention of six colleagues

Matsadaash staff allege torture and forced confessions after being held on charges of working for Muslim Brotherhood

Egyptian journalists are planning a new protest in Cairo this weekend after six colleagues were charged with terrorism offences amid allegations they had been tortured in police detention.

Last week, Egyptian authorities arrested the journalists, from the independent factchecking and investigative platform Matsadaash, accusing them in a statement of being unlicensed and producing false news on behalf of the outlawed Muslim Brotherhood.

Continue reading...



Scientists discover 180,000 giant tortoises on one Seychelles island

Free-roaming Aldabra population far exceeds human population of Seychelles after decades-long recovery programme

A survey of the world’s largest free-roaming giant tortoise population has discovered that the once endangered species is thriving.

A population of Aldabra giant tortoises lives on an island in Seychelles called Aldabra Atoll.

Continue reading...



Candidate named Hitler Mussolini elected mayor in Peru

Leftwing Hitler Mussolini Simeon Flores beats far-right candidate in election in remote district of Andes

A businessman called Hitler Mussolini Simeon Flores has been elected the mayor of a remote district in the Peruvian Andes, according to local election data.

The 45-year-old, who shares two of his names with the notorious European dictators, won the race for mayor of Queropalca, in Peru’s central Huánuco region, and will take office on 1 January.

Continue reading...



‘Like a drill going into my eye’: why the mystery over Havana syndrome refuses to die

Dozens of CIA officers have been afflicted by debilitating symptoms over the past decade. Are they the result of ‘mass hysteria’? Or are they from attacks with an energy weapon and, if so, who is responsible? And has there been a cover-up?

Shortly after 1am one night in April 2019, a CIA officer on a work trip to London was jolted awake in his hotel room by the most intense head pain he had ever experienced. His body was soaked with sweat and he felt like his eyes were spinning in their sockets. He manoeuvred his way out of bed, hoping to make it to the bathroom to vomit, but found his sense of balance had deserted him. Eventually, he fell back into a fitful, shallow sleep.

The next day, arriving at the work meeting he had travelled for, the officer found he could not remember the names of colleagues in the room, people he knew well. As the meeting got under way, he could barely follow the discussion. Initially, he chalked it up to a terrible – if rather odd – case of food poisoning. But over subsequent weeks, worrying symptoms persisted: brain fog, loss of balance and increasingly harsh tinnitus.

Continue reading...



Three men found guilty of murders of Australian surfer brothers and US friend in Mexico

Australian brothers Jake and Callum Robinson, 30 and 33, and friend Carter Rhoad, 30, were killed on a surfing trip in 2024

The parents of Australian surfing brothers murdered in Mexico have said “no outcome can ever undo this tragedy” after three men were convicted of the 2024 killings.

Australian brothers Jake and Callum Robinson, aged 30 and 33 respectively, and their friend Carter Rhoad, 30, were on a surfing trip to Mexico’s Pacific coast when they were shot dead in Baja California state in a suspected robbery.

Continue reading...



Powerful 7.7-magnitude earthquake strikes Panama and triggers panic in capital

The quake caused buildings and roads to collapse but the country appeared to escape widespread destruction or deaths

A magnitude 7.7 earthquake struck southern Panama on Friday, damaging buildings and sending thousands into the streets, but the country appeared to escape widespread destruction or deaths.

The US Geological Survey (USGS) said the ⁠earthquake hit at a depth of ⁠12.6km (7.8 miles), with an ​epicenter in a sparsely populated area about 200km (124 miles) from the capital, Panama City. It lasted about a minute.

Continue reading...



How a plant selfie in Colombian jungle led to ‘jaw dropping’ giant waterlily find

Species with leaves large enough to be seen from space is already critically endangered – and plans are afoot to protect it

A chance social media encounter has led to the race-against-time discovery of a new species of giant waterlily that has until now been hidden in the depths of Colombia’s jungle.

But the plant, which is so huge it is visible from space, is already considered critically endangered.

Continue reading...



Cop31 host urges wealthy countries to spend ‘much more’ on climate than defence

‘The climate issue is the security issue,’ says Turkish minister at Pacific pre-Cop summit in Fiji

Wealthy countries should spend far more on dealing with the climate crisis than the 5% of GDP promised by Nato members for defence because “the climate issue is the security issue”, the host of the next UN summit has said.

But, in comments that are likely to prove contentious, the Cop31 president-designate, Murat Kurum, hedged on whether countries should try to repeat a previous agreement to “transition away from fossil fuels” – the primary cause of the climate crisis – when they meet in Turkey next month.

Continue reading...



Sydney trader sacked for working from Singapore without permission wins unfair dismissal case

Employee had also been in Bali when he told his manager he was working from home, Fair Work Commission hears

A Sydney currency trader who was sacked for working from Singapore without approval has won an unfair dismissal case, but failed to be awarded compensation.

The Fair Work Commission ruled on Wednesday that Charles Graham had been unfairly dismissed by HIFX Australia, trading as Xe, in December last year.

Continue reading...



South Korea threatens legal action if fuel shipments to Russia found to have broken law

Responding to a Guardian report that revealed thousands of tonnes of fuel was transported to Russia, Seoul said it was investigating the cases

South Korea will take legal action if it finds that shipments of fuel from its ports to Russia broke domestic law, the government has said, responding to a Guardian report on the trade.

The government, in a statement issued by the foreign and trade ministries and the customs service, said that it is “checking additional information concerning the loading cases reported by the Guardian” and “if the verification establishes that our laws and regulations have been violated, it plans to act in accordance with the law”.

Continue reading...



Japan beer giants raided over suspicions they colluded to set the price of beverages

Investigators probe Asahi, Kirin, Suntory and Sapporo breweries – which together control more than 90% of Japan’s beer market

Japanese authorities have raided the country’s four biggest breweries over suspicions they colluded to set the price of beer and other beverages – a practice media reports said could have forced drinkers to pay over the odds.

Officials from the Fair Trade Commission this week searched the offices of Asahi Breweries, Kirin Brewery, Suntory Beer and Sapporo Breweries – which together control more than 90% of the domestic market. The quartet are suspected of violating the anti-monopoly law.

Continue reading...



Indonesia accused of ‘gross negligence’ in wildfires lawsuit as haze tests region

NGOs in Indonesian Borneo file class action lawsuit calling for government to better manage annual fires and

The Indonesian government has been accused of “gross negligence” in a class action lawsuit over its handling of wildfires that have cloaked large parts of South-east Asia in a toxic haze, shuttered schools and caused a spike in respiratory illnesses.

The lawsuit, filed by indigenous and civil society groups in the Indonesian part of Borneo, named President Prabowo Subianto and the governor of West Kalimantan among 10 defendants. The case seeks comprehensive recovery and rehabilitation measures that would include covering the healthcare costs of residents.

Continue reading...



Hanson seems more and more like the de facto opposition leader. At CPAC, Angus Taylor warmed the seat for her

Cooperation between One Nation and the Liberals ‘up to Angus Taylor’, Pauline Hanson says at conservative conference. How would that work?

The annual Conservative Political Action Conference billed itself as a chance for the leaders of the three main conservative parties – Liberals, Nationals and One Nation – to make their pitch and compete for rightwing voters.

The reception they received in Brisbane on Saturday suggests Pauline Hanson is effectively the preferred opposition leader, with Angus Taylor relegated to leading a minor party.

Sign up for Guardian Australia’s Politics, really newsletter here

Continue reading...



Albanese wants universal childcare to be his legacy. But paying for it isn’t as easy as ABC

Labor is running out of time to make its case to Australian families about how they are going to make childcare accessible and affordable for all

Rachel Hill, a mother of two from Sydney, explains the maths of family planning.

The not-for-profit worker recently bumped up her workload from two days a week to full-time to try to cover ever-rising costs. Instead, the additional money has been swallowed by childcare fees.

Continue reading...



Falling international student numbers create ‘massive problems’ for Australian universities, expert warns

Immigration debate and visa uncertainty is putting students off and increasing pressure on budgets

University leaders warn they’re struggling to fill international student places due to visa uncertainty and heated political debate on immigration, with regional areas hit the hardest and concern that financial deficits could affect domestic students.

The latest numbers from the Department of Education in October show on average universities are filling just two-thirds of their allocated places, and just five public universities have reached more than 80% capacity, all in capital cities.

Continue reading...



Women with PMOS should get subsidised weight-loss drugs, Australian advocates say

With GLP-1s to treat the condition not specifically approved by the TGA, patients are being prescribed them off-label

Women living with a chronic hormonal condition should have access to taxpayer-funded weight-loss medications, advocates say.

The Polyendrocrine Metabolic Ovarian Syndrome Association of Australia (POSAA) is urging for GLP-1 drugs to be approved on the Pharmaceutical Benefits Scheme for people living with the condition.

Continue reading...



New spate of stabbings, overdoses and fires at Australian immigration detention centres run by ICE-linked US prison firm

Exclusive: Federal government under scrutiny as documents reveal serious security lapses at Melbourne and Villawood immigration detention centres

A new spate of stabbings, overdoses and drug use in Australia’s immigration detention centres has put the Australian government in likely breach of laws designed to protect staff and detainees, internal documents show.

Earlier this year, Guardian Australia revealed catastrophic security failings across Australia’s onshore immigration network since Management and Training Corporation – a US private prison company used by Donald Trump to hold ICE detainees – won the $2.3bn detention contract in late 2024.

Continue reading...



Trump says Ukraine needs a new leader after diesel deal with Russia

US president suggests Ukrainian president, Volodymyr Zelenskyy, has not done enough to end war

Donald Trump has said Ukraine needs “a new leader”, a day after making a deal with Vladimir Putin to buy large quantities of Russian diesel.

The US president suggested Volodymyr Zelenskyy has not done enough to end the war with Russia and blamed him for high diesel prices in the US.

Continue reading...



Dozens injured and buildings damaged as tornadoes hit Sicily

Marsala on island’s west coast badly affected after powerful storm approached from Mediterranean

Two tornadoes have struck the coastal town of Marsala in western Sicily, injuring dozens of people, damaging buildings including a school, and overturning cars.

A series of videos began to circulate on Friday morning showing two waterspouts approaching the Sicilian town from the sea as people braced for their arrival.

Continue reading...



Zelenskyy furious as Trump announces deal to buy Russian diesel

US president says agreement needed to lower fuel prices, but move likely to create fresh crisis with Ukraine and Nato allies

Donald Trump is on a fresh collision course with Volodymyr Zelenskyy and European allies after his stunning agreement to buy Russian diesel upended years of US and western pressure on the Kremlin to end its war against Ukraine.

Zelenskyy reacted furiously to Trump’s announcement of the deal with Vladimir Putin on Friday, calling it “absolutely terrible” and “not fair and not honest”.

Continue reading...



‘We’re not asking for luxury’: school protesters in Paris suburb feel abandoned by French state

Students say they are desperate to get back to class but conditions are so bad that the protests must continue

On a normal school day, Mohammed, 17, wakes at 6am, cares for his younger siblings to help his single mother who works as a security guard, then takes two crowded buses and a local train to get to his high school in Sevran, a low-income banlieue town in the suburbs north-east of Paris.

“There aren’t enough chairs or desks to go round, so some students have to stand up,” Mohammed said. “Classes can be so packed you can’t interact with the teacher. In this year’s heatwaves, it felt like 40 degrees in overcrowded classrooms with no shade or curtains. It was so hot my brain couldn’t function.”

Continue reading...



Trump fumes over Nobel peace prize snub and criticizes Norway

President complains about not winning prize in year he started war with Iran and says: ‘We will not forget, Norway’

Donald Trump complained Friday about not winning the Nobel peace prize for 2026, a year in which he started a war with Iran.

At what was supposed to be a rally for other Republican candidates in Syracuse, New York, the US president devoted a long portion of his speech airing his grievances with the Nobel committee.

Continue reading...



Thousands gather in London to express support for Palestinians after three years of ‘genocide’

Twenty arrested in first march since Ed Miliband declared UK’s position was that Israel’s occupation of West Bank was unlawful

Thousands of people have gathered in central London to express their support for Palestinians after three years of “genocide” carried out against them by Israel.

The demonstrators, many wearing keffiyehs and holding Palestine flags, gathered on the Embankment at midday on Saturday. Some carried placards reading “End the genocide” and “Free Palestine” as they marched towards parliament. A bride and groom appeared to be among those in attendance and a two-minute silence was held to reflect on the lives lost in Gaza.

Continue reading...



Dozens reportedly injured in Yemeni Houthi attack at Riyadh airport

Donald Trump says he is evaluating whether the US should join Saudi strikes against the Iran-backed rebels

Yemen’s Houthis have launched a missile attack on Riyadh’s international airport in Saudi Arabia, with dozens reported wounded and a witness describing panic in the terminal.

Donald Trump told reporters he was evaluating whether the US should join Saudi strikes against the Iran-backed Houthi rebels in neighbouring Yemen.

Continue reading...



Flydubai co-pilot planned suicide attack on Israeli airport, UAE prosecutors say

Hammam al-Hammami is believed to have been targeting the passenger terminal at Ben Gurion airport near Tel Aviv

The co-pilot who tried to seize control of a passenger jet flying from Dubai to Tel Aviv last week was planning to launch a suicide attack targeting the passenger terminal at Israel’s international airport, prosecutors in the United Arab Emirates said on Friday.

Hammam al-Hammami attacked the plane’s Indian pilot with an emergency axe, but failed to prevent his badly injured colleague from opening the cockpit’s security door to allow passengers to overpower his assailant.

Continue reading...



Pete Hegseth’s plan to livestream execution puts US in dubious company

Only Iran and Afghanistan routinely carry out sentences in public, with Saudi Arabia appearing to have ended practice

If the US defence secretary, Pete Hegseth, goes ahead with plans to livestream the execution of a soldier radicalised to extremist Islam who killed 13 people at a military base in Texas, his country will join a motley assembly of lesser powers and rogue actors who have conducted public executions in recent years.

Only two countries currently systematically carry out capital sentences in public: Iran and Afghanistan. In 2025, the Taliban authorities carried out six such killings and the regime in Tehran 11, according to Amnesty International.

Continue reading...



Three Saudis killed in Riyadh airport attack claimed by Houthis

Attack is deadliest in kingdom since it launched major military offensive with allies against Houthis in Yemen

Three Saudi citizens have been killed and several other people were wounded in attacks targeting Riyadh ⁠airport for which Yemen’s Houthis claimed responsibility, Saudi officials have said.

The attack late on Thursday was the deadliest in Saudi Arabia since the kingdom and allied forces in neighbouring Yemen launched a major military offensive last weekend against the Iran-backed Houthis.

Continue reading...



‘Cockroach’ leader among thousands detained in Delhi protest crackdown

Authorities impose strict lockdown in capital to try to stop rally against removal of 130m names from electoral roll

Indian authorities have placed Delhi under a severe lockdown and detained tens of thousands of people, including the leader of the youth-led “Cockroach” movement, in an attempt to stop an anti-government protest.

Thousands of people from across India were blocked from attending the demonstration, which had been called by the “Cockroach Janata party” (CJP) to protest against an exercise that has stripped 130m names from India’s electoral roll.

Continue reading...



India’s ‘Cockroach’ party accuses government of mass detention of members ahead of weekend protest

Thousands expected to march in Delhi on Saturday, as anger mounts over controversial changes to voter lists in world’s largest democracy

India’s Cockroach Janta Party (CJP), which began as a satirical movement but is now emerging as a political force among gen Z’s, says authorities have begun detaining its members en masse days before a major anti-government protest in Delhi.

Opposition parties, their student units, and the “Cockroach” youth movement have been holding almost daily demonstrations seeking the resignation of chief election commissioner Gyanesh Kumar over a controversial revision of ⁠voter lists.

Continue reading...



Supporters of Imran Khan start march on locked-down Islamabad

Pakistani authorities insist marchers calling for former PM to be released from jail will not reach the capital

Imran Khan’s supporters have begun a march to Islamabad to demand his release from jail after efforts by the government to halt the protest failed.

The march began in the former prime minister’s stronghold province of Khyber Pakhtunkhwa in north-west Pakistan on Sunday, according to leaders of his Pakistan Tehreek-e-Insaf (PTI) party.

Continue reading...



India’s Cockroach movement launches new protests over changes to voter roll

Thousands gather in Mumbai with heavy police presence as concerns mount that millions will be denied voting rights

India’s youth-led Cockroach movement kicked off more nationwide protests on Friday as thousands of people gathered in Mumbai, amid mounting concerns that millions of citizens are being unfairly stripped of their vote.

The movement, which calls itself the Cockroach Janta party (CJP) and has massive support among the country’s gen Zs, returned to the streets to demand the resignation of the chief election commissioner, Gyanesh Kumar.

Continue reading...



Eastern Spain braces for torrential rain and flooding

Up to 300mm of rain could fall in places, while extreme downpours bring landslides and deaths in Nepal

Torrential rain and potentially damaging flooding are forecast in eastern Spain over the coming days, as cold upper air moves over the warm, humid surface air of the Mediterranean Sea, fuelling violent, slow-moving thunderstorms near Spain’s east coast. The weather pattern, known as a Dana, occurs most often in autumn.

Models show more than 100mm of rain could fall across the region on Friday, with 200-300mm possible in some areas. Cities including Valencia and Castelló de la Plana, are most at risk. Valencia has experienced several damaging floods in recent years. Catalonia has now put three towns under lockdown and Valencia has shut schools for nearly half a million children.

Continue reading...



Man dies after jumping into tiger enclosure at Yorkshire zoo

Police say man was pronounced dead at the scene after being attacked by tiger

A man has died after being attacked by a tiger after jumping into its enclosure at a zoo in Yorkshire, police have said.

Yorkshire Wildlife Park was evacuated shortly after the incident and the site will remain closed on Sunday.

Continue reading...



Camden council was warned about paedophile nursery worker years before arrest

Vincent Chan went on to abuse children after being cleared of ‘significant concerns’ following council-overseen inquiry

A paedophile nursery worker was cleared by an investigation overseen by a local authority three years before he was arrested.

In February, Vincent Chan was jailed after pleading guilty to 56 offences, including assault by penetration on three-year-old girls in his care at a Bright Horizons nursery on Finchley Road in north-west London. After his conviction, prosecutors described him as a “prolific sexual predator”.

Continue reading...



How a South African billionaire is turning a corner of Somerset into ‘one man’s estate’

Koos Bekker’s Newt estate encompasses luxury hotels, pubs and high street business, with local concerns including flooding

When South African billionaire Koos Bekker bought an old country estate in a sleepy corner of Somerset to turn it into a luxury hotel, residents thought it was a sign their area was on the up.

Walking through his peaceful manicured gardens, which feature a maze of apple trees twisted into perfect shapes using the espalier method, it’s easy to feel that all is well in this quiet, picturesque pocket of England.

Continue reading...



Study explores links between 19th-century Manchester workers and enslaved Africans in Caribbean

Global Threads research project reveals how slavery hung ‘like a spectre’ over the Peterloo massacre and other Mancunian struggles for equality

They were the killings that changed Britain, paving the way for working-class people’s right to vote, as well as leading to the founding of the Manchester Guardian. In the Peterloo massacre of 1819, peaceful protesters were shot and trampled to death by the Manchester and Salford Yeomanry at St Peter’s Field in the city.

A study by Global Threads, a public history project, has examined how the exploitation of Africans enslaved in the Caribbean was linked with the struggles of cotton workers at Peterloo. Though these workers were divided by thousands of miles and led different lives, they were exploited by the same forces – as Robert Wedderburn, a Black abolitionist in London, said at the time.

Continue reading...



Greens must avoid ‘capture by extremists and racists’, says party MP

Ellie Chowns says vote for ‘Zionism is racism’ policy by 0.4% of members shows party processes are not working

A Green Party MP has said she wants to make sure her party is not “vulnerable to capture by extremists and racists” amid the continuing fallout from the “Zionism is racism” vote.

The party faces a political maelstrom over its policy decision last week to treat Zionism, the movement for a Jewish state, as any other form of racism, and to back a single Palestinian state over a two-state solution. The motion was passed at the annual party conference with just over 1,000 votes, approximately 0.4% of the total membership.

Continue reading...



Despair after 200-year-old ‘grandmother’ tree toppled for Trump’s border wall: ‘It crushes your heart’

Protesters spent months occupying an ancient cottonwood. Then a tense standoff with US border patrol came to a head

A 200-year-old cottonwood tree near the US-Mexico border, known as the “grandmother”, has been destroyed to make way for the construction of Donald Trump’s border wall, despite a months-long effort by protesters trying to save it.

In late July, land defenders began a tree-sit in the ghost town of Lochiel, Arizona, taking turns occupying a platform high in the tree’s canopy. The group remained there for more than 70 days.

Continue reading...



Hurricane Isaias latest updates: at least four people dead and hundreds of thousands without power

First Atlantic hurricane of the 2026 season makes landfall in the US as officials warn of ‘spinoff tornadoes’

Florida’s governor, Ron DeSantis, said no requests for search and rescue assistance had been received following Isaias, which he described as “cautiously, a good sign”.

Speaking to Fox News, he said:

I think that may be a sign that people heeded the warnings, took proper precautions. We sure would love to say we have not gotten a report of a fatality yet, and we’ll see what happens.

There’s also a lot of hazards post-storm that people should be careful of, but so far we’ve had a lot of assets in place that have not been called on, which is a good sign. I’d rather be over-prepared, and not have to use them, than not have what you need.”

Hurricane Isaias has weakened to a post-tropical cyclone early Saturday, the National Hurricane Center (NHC) said, after it made landfall in Florida and lashed the US Gulf coast with heavy rain and fierce winds.

The category 2 hurricane hit the coast near Destin, Florida, late on Friday, with maximum sustained winds of 105mph.

The storm is expected to move across Alabama and into the Tennessee Valley, the NHC added, with maximum sustained winds decreased to near 35mph.

Continue reading...



Man with gun kills one Philadelphia police officer and injures another

10-year police veteran Shane Seiber was killed after responding to a report of a man with a gun

A Philadelphia police officer was fatally shot and another was wounded on Saturday after responding to a report of a man with a gun, authorities said.

Shane Seiber, 40, was killed early on Saturday morning in West Philadelphia, according to the city’s police commissioner, Kevin Bethel.

Continue reading...



Four dead as Isaias weakens to post-tropical cyclone after striking Florida panhandle

Some of deaths came from falling trees as nearly a million people are without power and rain and flooding remain a concern

At least four people were reported dead on Saturday amid Isaias after it made landfall late on Friday on Florida’s panhandle as a category 2 hurricane, according to authorities.

The storm also took down trees, knocked out electricity for hundreds of thousands and flooded highways – but as Saturday evening approached, the region was reopening.

Continue reading...



US man shoots off-duty ICE agent who allegedly attacked him and daughter

ICE official, who was sleeping on man’s lawn and appeared ‘intoxicated’, faces felony charges, California police say

A 72-year-old man shot an off-duty Immigration and Customs Enforcement (ICE) official in California early on Friday morning after the “intoxicated and agitated” official assaulted him and his daughter on their property, local authorities allege.

The Fresno police department said that the ICE official was receiving medical care after being shot in the midsection. The official, identified as David Gonzalez, is facing felony charges for assaulting the father-daughter duo, Fresno police said.

Continue reading...





Back to top



Kaupunki

Back to top

This site is down!

Back to top



Yle

Back to top

Analyysi: Jokohan Euroopassa tajutaan, kenen puolella Trump on?

Trump syötti diesel-sopimuksellaan jälleen kerran suoraan Putinin lapaan, Venäjän-kirjeenvaihtaja Mika Hentunen arvioi.



Trump: Sodan jatkuminen on Zelenskyin syytä, Ukraina tarvitsee uuden presidentin

Seuraamme tuoreimpia tietoja Venäjän hyökkäyksestä Ukrainaan tässä päivittyvässä jutussa.



Kouvolassa on kymmeniä hylättyjä taloja, joiden omistajia ei kiinnosta – katso kuvat

Tavallisten ihmisten entiset kodit rapistuvat, ja konkurssiyritysten pihat keräävät romua. Kun kukaan ei ota vastuuta, veronmaksajat maksavat laskun.



Välimiesoikeus: Rosatomin maksettava Fennovoimalle yli 600 miljoonaa, vaikka suomalaisyhtiö purki ydinvoimahankkeen lainvastaisesti

Fennovoimalla ja Rosatom-yhtiöillä on yhä useita kiistoja välimiesmenettelyssä.



Vantaalaismies harmistui huomatessaan, että sähköautopaikka maksaa taloyhtiössä tavallista enemmän

Vantaalaismies vaihtaa bensa-autonsa sähköiseen menopeliin. Samalla pomppaa pysäköintihallin autopaikkavuokra.



Analyysi: Nukkuivatko kunnat ja valvova viranomainen sillä aikaa, kun Google hakkasi metsää ja mylläsi maata Suomessa?

Suomessa on äimistelty Googlen touhua Muhoksella ja Kajaanissa. Myös kuntien ja Lupa- ja valvontaviraston toimintaa on syytä tarkastella, kirjoittaa toimittaja Kirsi Karppinen.



Moni ikääntynyt leski jää avuttomaksi puolison kuoltua – ”Vaikea paikka”, sanoo pyykkäämään opetellut Mikko Räikkönen

Leskeys voi paljastaa arjen taitojen aukot. Ilmiö näkyy kolmannen sektorin saamissa viesteissä.



Teloitusyrityksestä selvinnyt Christa Pike pääsi pois sairaalasta

Ennennäkemättömällä tavalla myrkkyruiskeista selvinnyt Christa Pike palasi takaisin vankilaan.



Saimme avaimet kuuteen erikoiseen majapaikkaan, joista harva tietää

Olemme ketjuhotellikansaa, joka ei kotimaassa elämyksiä kaipaa. Vai kaipaako? Koostimme yhteen erikoisia majapaikkoja aikuisten leikkihuoneista joki-igluihin.



Mies kuoli tiikerin hyökättyä hänen kimppuunsa Britanniassa



Julkinen teloitus voi palata Yhdysvaltoihin lähes 100 vuoden jälkeen: Pentagon suunnittelee suoraa verkkolähetystä

Yhdysvaltain puolustusministeriö suunnittelee suoraa verkkolähetystä Nidal Hasanin teloituksesta joulukuussa.



Isännöintiliitto haluaa kuriin osakkaat, jotka eivät maksa vastikkeitaan – ehdottaa pakkolunastusta

Pakkolunastus olisi viimeinen keino turvata taloyhtiön tilanne. Sitä käytettäisiin tilanteessa, jossa omistaja jättää vastikkeet pysyvästi maksamatta.





Back to top



CNN

Back to top

Markets digest bank earnings after recent turmoil



Still haven't filed your taxes? Here's what you need to know

So far this tax season, the IRS has received more than 90 million income tax returns for 2022.



Retail spending fell in March as consumers pull back

Spending at US retailers fell in March as consumers pulled back amid recessionary fears fueled by the banking crisis.



Analysis: Fox News is about to enter the true No Spin Zone

This is it.



Silicon Valley Bank collapse renews calls to address disparities impacting entrepreneurs of color

When customers at Silicon Valley Bank rushed to withdraw billions of dollars last month, venture capitalist Arlan Hamilton stepped in to help some of the founders of color who panicked about losing access to payroll funds.



Not only is Lake Powell's water level plummeting because of drought, its total capacity is shrinking, too

Lake Powell, the second-largest human-made reservoir in the US, has lost nearly 7% of its potential storage capacity since 1963, when Glen Canyon Dam was built, a new report shows.



These were the best and worst places for air quality in 2021, new report shows

Air pollution spiked to unhealthy levels around the world in 2021, according to a new report.



Big-box stores could help slash emissions and save millions by putting solar panels on roofs. Why aren't more of them doing it?

As the US attempts to wean itself off its heavy reliance on fossil fuels and shift to cleaner energy sources, many experts are eyeing a promising solution: your neighborhood big-box stores and shopping malls.



Look of the Week: Blackpink headline Coachella in Korean hanboks

Bringing the second day of this year's Coachella to a close, K-Pop girl group Blackpink made history Saturday night when they became the first Asian act to ever headline the festival. To a crowd of, reportedly, over 125,000 people, Jennie, Jisoo, Lisa and Rosé used the ground-breaking moment to pay homage to Korean heritage by arriving onstage in hanboks: a traditional type of dress.



Scientists identify secret ingredient in Leonardo da Vinci paintings

"Old Masters" such as Leonardo da Vinci, Sandro Botticelli and Rembrandt may have used proteins, especially egg yolk, in their oil paintings, according to a new study.



How Playboy cut ties with Hugh Hefner to create a post-MeToo brand

Hugh Hefner launched Playboy Magazine 70 years ago this year. The first issue included a nude photograph of Marilyn Monroe, which he had purchased and published without her knowledge or consent.



'A definitive backslide.' Inside fashion's worrying runway trend

Now that the Fall-Winter 2023 catwalks have been disassembled, it's clear one trend was more pervasive than any collective penchant for ruffles, pleated skirts or tailored coats.



Michael Jordan's 1998 NBA Finals sneakers sell for a record $2.2 million

In 1998, Michael Jordan laced up a pair of his iconic black and red Air Jordan 13s to bring home a Bulls victory during Game 2 of his final NBA championship — and now they are the most expensive sneakers ever to sell at auction. The game-winning sneakers sold for $2.2 million at Sotheby's in New York on Tuesday, smashing the sneaker auction record of $1.47 million, set in 2021 by a pair of Nike Air Ships that Jordan wore earlier in his career.



The surreal facades of America's strip clubs

Some people travel the world in search of adventure, while others seek out natural wonders, cultural landmarks or culinary experiences. But French photographer François Prost was looking for something altogether different during his recent road trip across America: strip clubs.



Here's the real reason to turn on airplane mode when you fly

We all know the routine by heart: "Please ensure your seats are in the upright position, tray tables stowed, window shades are up, laptops are stored in the overhead bins and electronic devices are set to flight mode."



'I was up to my waist down a hippo's throat.' He survived, and here's his advice

Paul Templer was living his best life.



They bought an abandoned 'ghost house' in the Japanese countryside

He'd spent years backpacking around the world, and Japanese traveler Daisuke Kajiyama was finally ready to return home to pursue his long-held dream of opening up a guesthouse.



Relaxed entry rules make it easier than ever to visit this stunning Asian nation

Due to its remoteness and short summer season, Mongolia has long been a destination overlooked by travelers.



The most beautiful sections of China's Great Wall

Having lived in Beijing for almost 12 years, I've had plenty of time to travel widely in China.



Sign up to our newsletter for a weekly roundup of travel news



Nelly Cheboi, who creates computer labs for Kenyan schoolchildren, is CNN's Hero of the Year

Celebrities and musicians are coming together tonight to honor everyday people making the world a better place.



CNN Heroes: Sharing the Spotlight



Donate now to a Top 10 CNN Hero

Anderson Cooper explains how you can easily donate to any of the 2021 Top 10 CNN Heroes.



0% intro APR until 2024 is 100% insane



It's official: now avoid credit card interest into 2024



Experts: this is the best cash back card of 2022



Turn Your Rising Home Equity Into Cash You Can Use



Dream Big with a Home Equity Loan



Want Cash Out of Your Home? Here Are Your Best Options





Back to top



Hesari

Back to top

Lähi-itä | NYT: Ainakin 12 kuollut ja kymmeniä loukkaantunut Saudi-Arabiaan lento­asemalle tehdyssä iskussa

AFP:n lähteiden mukaan huthi­kapinalliset olisivat tehneet lentoasemalle ohjusiskun.



Britannia | Tiikeri raateli aitaukseen menneen miehen kuoliaaksi villi­eläin­puistossa

Miestä yritettiin elvyttää, mutta hän kuoli saamiinsa vammoihin.



Jäätanssi | Juulia Turkkila ja Matthias Versluis voittoon Kazakstanissa

Suomalaispari juhli Denis Ten Memorial -kilpailun voittoa Almatyssä.



Suomen kieli | Huolipuhe suomen kielestä ei johda mihinkään ilman tekoja

Viranomaisten tekstien laatu ei parane pelkillä puheilla. Kielen asemaa on vahvistettava rakenteissa, järjestelmissä ja osaamisessa.



Valioliiga | ManU menetti voiton viime hetkillä, Tottenhamin kurimus jatkuu

Voittaminen on edelleen äärettömän vaikeaa Manchester Unitedille ja Tottenhamille.



Lähi-itä | Iran: Öljy­tankkeri räjähti osuttuaan meri­miinaan Hormuzin­salmella

Iranin vallankumouskaarti ei kertonut aluksen nimeä tai sen lippuvaltiota.



3 x kuvakirja | Kolme lasten kuvakirjaa, joita suosittelemme juuri nyt

Syksyn kuvakirjoissa tutustutaan dinosauruksiin, retkeillään metsässä ja matkataan Japaniin.



Yhdysvallat | Yhdeksän ihmistä kuollut ammuskelussa Pennsylvaniassa

Kuolleista kaksi on lapsia. Myös epäilty ampuja on kuollut.



Kommentti | HIFK otti jättivoiton, mutta taustalla kytee uusi kriisi

HIFK otti henkisesti valtavan voiton, kirjoittaa jääkiekkotoimittaja Sami Hoffrén.



Polttoaineet | Trump: Ukrainan on aika saada uusi presidentti

Trump ilmoitti perjantaina lieventävänsä venäläistä dieseliä koskevia pakotteita. Zelenskyi kutsui diesel­sopimusta lahjaksi Venäjän presidentti Putinille.



Media | Vaaniiko Venäjän mörkö median sängyn alla?

Otsikot kansanedustajien häirinnästä ja merestä löytyneistä esineistä luovat mielikuvaa siitä, että Venäjä ehtii kaikkialle. Median tuntijat pohtivat, pelaako media Vladimir Putinin pussiin.



Astrofysiikka | Avaruuden tyhjiö ei olekaan tyhjä, paljastaa hurjan tähden säteily

Riittävän voimakas laser saattaisi jopa törmätä tyhjiöön. Kyse on kvanttifysiikan ajatusleikistä, joka muuttuu todeksi.



HS-haastattelu | Unkarin pääministeri Péter Magyar: Minulla on parempaakin tekemistä kuin ryhtyä uudeksi Orbániksi

Unkarin pääministeri Péter Magyar purkaa Viktor Orbánin itsevaltaista järjestelmää nopeasti. Ukrainaa ja seksuaalivähemmistöjen asemaa hän lähestyy kuitenkin varoen.



Kommentti | Jokerien hanat tukossa, tähtihyökkääjän kasvoilta paistaa tuska

Ilves valtasi Ilmalan, kirjoittaa toimittaja Sasha Huttunen.



Yhdysvallat | Teloitus­yrityksestä selvinnyt Christa Pike pääsi pois sairaalasta

Piken asianajajien mukaan hänet on siirretty takaisin vankilaan. Murhasta kuolemaan tuomittu Pike selvisi viime viikolla kahdesta myrkkyruiskeesta.



Ikä | Keiden pitäisi ryhtyä ikäkapinaan?

Yhä useampi säilyy hyväkuntoisena pitkään.



Judo | Martti Puumalainen hävisi MM-kisojen pronssiottelun

Puumalaisen loppusijoitus oli viides.



Jalkapallo | Joel Pohjanpalo iski kauden toisen maalinsa Italiassa

Palermo voitti Empolin 4–2 ja jatkaa sarjan kärjessä.



Hanhikiven ydinvoimala | Fenno­voiman toimitus­johtaja HS:lle: Rosatom määrättiin maksamaan satoja miljoonia euroja

Välimiesoikeus katsoo, että Fennovoima purki Hanhikivi 1 -ydinvoimalan rakentamis­sopimuksen lainvastaisesti. Yhtiö luopui Pyhäjoelle kaavaillusta hankkeesta toukokuussa 2022.



Keskiluokan kärsivällisyys on kovilla

Keskiluokalta vaaditaan enemmän joustavuutta ja omaa vastuuta, mutta vastineeksi saatu turva ei tunnu lisääntyvän. Keskiluokan kasvava epävarmuus on hankala kysymys erityisesti kokoomukselle.



HS Madridissa | Maricarmenin tapaus ei ole mustavalkoinen, muistuttavat naapurit arvoalueella

Kodistaan häädetty Maricarmen, 87, nousi Espanjan asuntokriisin symboliksi. Tapaus ei ole mustavalkoinen, muistuttavat HS:n jututtamat naapurit arvoalueella.



Ukrainan sota | Zelenskyi: Suomi toimittaa Ukrainalle F-16-hävittäjien ammuksia

Puolustusministeriö ilmoitti perjantaina toimittavansa Ukrainalle uuden apupaketin. Venäjä on viime päivinä kiihdyttänyt iskujaan eri puolille Ukrainaa.



Miniristikko | Läpimurron tässä ristikossa teet sinä? Kaikki 25 ruutua täyteen!

HS:n 5x5-miniristikko ilmestyy päivittäin vaihtuvalla aiheella. Kokeile saatko kaikki sanat omille paikoilleen.



Jalkapallo | Cristiano Ronaldo pelikieltoon Portugalin maajoukkueessa

Ronaldo poistui Portugalin maajoukkueleirityksessä kesken kaiken.



Jalkapallo | FC Barcelona oli matkalla romahdukseen, kunnes 15-vuotias Lamine Yamal astui kentälle

FC Barcelona oli matkalla romahdukseen, kun 15-vuotias poika astui kentälle. Nyt Lamine Yamal on niin valovoimainen, että hän on tehnyt jopa hammasraudoista trendikkäät.



Media | Kulttuurilehtien katoaminen köyhdyttää kansallista muistia

Leikkausten ja kasvaneiden kulujen keskellä yhä useampi kulttuurilehti joutuu luopumaan paperista.



Tekoäly | Koodari rakensi tekoälyllä ilmaiset versiot Adoben suosikki­­ohjelmistoista

Tekoälyn kehitys madaltaa yksittäisten ohjelmoijien kynnystä haastaa suuria ohjelmisto­firmoja, uskoo Aalto-yliopiston tietotekniikan apulais­professori Juho Leinonen.



HS Lontoossa | Moni päättäjä asettuu burkan puolelle ja naisia vastaan

Ei ole oikein tottua siihen, että naisen pitää peittää kasvonsa.



Jääkiekko | Olli Jokinen sotki HIFK:n kokoonpanon, Jokereille takaisku

HIFK ja Jokerit pelaavat lauantain liigakierroksella.



Häiriöt | Autismidiagnooseja on liu’utettu yhä laajemmalle joukolle ihmisiä

Autismia näkyy nyt kouluissa, päiväkodeissa, Tiktokissa, kaikkialla, ja diagnoosien määrä on kasvussa. Mistä tämä johtuu?



Sote-palvelut | Useampi asiointikanava ei tarkoita parempaa palvelua

Useat asiointikanavat eivät auta, jos asiakas joutuu kertomaan saman asian yhä uudelleen.



Panama | Voimakas maan­järistys iski Panamaan

Maanjäristys oli voimakkuudeltaan 7,6.



HS-analyysi | Oura voi päätyä pörssi­farssin jälkeen kauppatavaraksi

Ouran epäonnistunut pörssilistautuminen näyttäytyi vanhojen omistajien rahastusyrityksenä. Juuri nyt yhtiön listautuminen pörssiin lähiaikoina näyttää hyvin epätodennäköiseltä, kirjoittaa HS Vision toimittaja Elina Lappalainen.



Kuolleet | Vapianon perustaja Klaus Rader kuoli rallionnettomuudessa

Klaus Rader kuoli Mallorcalla järjestetyssä rallikilpailussa.



Työttömyys | Oppimisen vaikeudet voivat estää työllistymisen

Pitkäaikaistyöttömyyden katkaisemiseen tarvitaan myös oppimisen tukea.



Tempaukset | Italialainen hurjapää kisaa Ferrarillaan F-35-hävittäjää vastaan

Kesällä Fabio Barone ajoi Ferrarilla Helsingistä Rovaniemelle. Sunnuntaina hän aikoo ajaa kilpaa F-35-hävittäjää vastaan.



Ralli | Marcus Grönholm pitää MM-sarjan tulevaisuutta lupaavana

Marcus Grönholm ruotii rallin MM-sarjan tulevaisuudennäkymiä.



Vihreät | Ville Niinistö lähtee ehdolle edus­kunta­vaaleihin

Vihreiden entinen puheenjohtaja sanoi lauantaina Vantaalla olevansa tyytyväinen nykyisen puheen­johtajan Sofia Virran linjaan.



HS-haastattelu | Antti Lindtman: Näin Sdp kasvattaisi työllisyyttä ja talous­kasvua

Sdp ehdottaa, että enintään toisen asteen koulutuksen saaneet tai työvoimapulasta kärsiville aloille kouluttautuvat saisivat uudessa mallissa enemmän aikuiskoulutustukea kuin muut.



Kirja-arvio | Miki Liukkonen halveksi omia runojaan, mutta niistä kuuluu omaperäinen ääni

Yksiin kansiin kootut runot ja mukaan ripotellut päiväkirjamerkinnät kuvaavat onnistuneesti nuoren kirjailijan kehitystä.



Koulu | Opettajat maksavat koulun kuluja

Moni opettaja käyttää omaa rahaansa, koska koulun hankinnat ovat hitaita tai määrärahat eivät riitä.



Työpaikat | YTHS irtisanoi kymmeniä ihmisiä ja alkoi heti ostaa samat palvelut muualta

Irtisanottu sairaanhoitaja kertoo HS:lle pelkäävänsä, että opiskelijoiden ahdinko syvenee, kun ennestään ruuhkautuneita terveyspalveluja karsittiin.



Sponsorointi | Suomalaisyhtiön pomo kertoo, millaista on tehdä yhteistyötä 11-vuotiaan Robin Räikkösen kanssa

Robin Räikkönen etenee vinhaa vauhtia kohti suurta unelmaa. Yhteistyökumppani kertoo työskentelystään Räikkösten kanssa.



Googlen hakkuut | Pääministeri Orpo kommentoi hakkuita Ylellä: ”Kylmä suihku”

Orpo kritisoi Ylen Ykkösaamun haastattelussa Trumpin ja Putinin solmimaa dieselsopimusta ja kommentoi myös kokoomuksen eläkelinjaa.



Kirjeenvaihtajan analyysi | Berliinissä näkyy, kuinka pahasti Saksa on solmussa

Saksa kamppailee poliittisen hajaannuksen kanssa, kun AfD-puolueen ehdokas valittiin osavaltioparlamentin puhemieheksi, kirjoittaa HS:n Berliinin-kirjeenvaihtaja Heikki Aittokoski.



Uutisvisa | Kuka oli pääosassa Elia Kazanin draamaelokuvassa Eedenistä itään (1955)? Muistatko tämän legendan?

HS:n Uutisvisa testaa, oletko ajan tasalla. Kymmenen kysymyksen avulla saat selville, kuinka hyvin olet lukenut Hesarisi viime aikoina.



Poliisi | Lahdessa kadonnut 17-vuotias poika löytyi kuolleena

Poliisi jatkaa asian selvittämistä kuoleman­syyn­tutkintana.



Sää | Suomeen tuli ensilumi, Puolangalla satoi peräti 20 senttiä

Enempää lumisateita ei ole luvassa tänä viikonloppuna. Vesisadetta sen sijaan on odotettavissa.



HS:n tiedot | Pyörä­varkaiden etsijä kertoo välittäneensä poliisi­miehelle tavaraa: lahjus­syyte poliisille

Poliisimiestä vastaan nostettiin syyte lahjusrikkomuksesta. Varastettuja polkupyöriä jäljittävän yhdistyksen perustajan mukaan kyse on ”mitättömästä, kohtuuttomasta ja järjettömästä” asiasta.



Puuro | Muutamassa minuutissa saa sekoitettua hyvät tuorepuurot, joista riittää aamupalaa pariksi päiväksi

Sesongin hedelmillä tuunatut tuorepuurot sopivat täydellisesti myös kiireisiin aamuihin, ja niitä on helppo valmistaa kerralla pariksi päiväksi.



Yhdysvallat | Tällainen on Valkoisen talon uusi lehdistö­sihteeri Katie Zacharia

42-vuotias Zacharia korvaa Karoline Leavittin, joka jätti tehtävänsä elokuussa.



Asuminen | Sisustus­arkkitehti neuvoo, miten vältät väärän aika­kauden remontin

Teetetty remontti voi näyttää väärältä, jos sisätilat eivät istu lainkaan rakennukseen. Sisustusarkkitehti jakaa vinkit kunkin aikakauden asuntoon.



Jääkiekko | Lunasa Sano muutti Harvardista Suomeen, ja maailma valkeni: ”Minut nähtiin täällä sellaisena kuin olen”

Harvardista valmistunut Lunasa Sano muutti Suomeen jääkiekon perässä. Nyt hän tavoittelee olympiaunelmaansa HIFK:n paidassa.



Jääkiekko | Mikael Granlund laukoi uransa 200. runkosarjamaalin NHL:ssä

Mikael Granlundin laukaus oli komea.



Polttoaineet | Zelenskyi: Trumpin ja Putinin diesel-diili on ”heikko päätös”

Yhdysvaltain valtiovarain­ministeriö ilmoitti myöntävänsä väliaikaisen luvan venäläisen dieselin toimittamiseksi maailman­markkinoille.



Ruoka | Näin tehdään tavallista parempi lohi-perunalaatikko

Syksyisen viikonlopun ruokapöytään sopivat ranskalainen lohi-perunalaatikko, makkarastroganoff tai maukas kasvispata, joka saa kypsyä rauhassa pitkään.



Kirja-arvio | Pirkko Saisio osoittaa jälleen mestarillisuutensa

Pirkko Saision Ilmestyskirja on kuin jatkoa 20 vuotta vanhalle Helsinki-trilogialle. Romaanissa kirjailija pohtii kuoleman läheisyyttä.



Ruotsi | Media: Opiskelijoita simputettiin ruotsalais­koulussa, kolmea epäillään vakavista rikoksista

Kolme noin 18-vuotiasta miesopiskelijaa on otettu kiinni ja useita koulun oppilaita on erotettu määräajaksi.



HS Muhoksella | Kunnan rakennus­tarkastaja sanoo, että häntä ”painostettiin joka puolelta”

Muhoksen kunnan rakennustarkastaja Eero Airaksinen ei antanut Googlelle keväällä maisematyölupaa datakeskuksen rakentamiseen. Silloin Googlen lakimiehet keksivät ”sen pykälän”.



Frisbeegolf | Verotuksen kiristyminen luhisti suuren kisajärjestäjän: ”Se vie valtavan siivun”

Päätös vaikuttaa merkittävästi Frisbeegolfliiton budjettiin.



Eläkkeet | Eläkejärjestelmää on kehitettävä pitkäjänteisesti

Työssä käyvillä tulevilla eläkeläisillä on oltava riittävästi aikaa varautua heikennyksiin.



Koulu | Tunnollisen lapsen tuen tarve jää helposti huomaamatta

Etenkin monet neurokirjon piirteitä omaavat lapset käyttävät valtavasti energiaa selviytyäkseen koulupäivästä ja täyttääkseen ympäristön odotukset.



Mielenterveys | Työpaikoille tarvitaan vahvempaa välittämisen kulttuuria

Mielen ergonomian pitäisi olla kiinteä osa työhyvinvointia. Se tarkoittaa kohtuullista työmäärää, joustavuutta erilaisissa elämäntilanteissa, sekä työyhteisöä, jossa huolista voidaan puhua ajoissa.



Syöpä | Miljoonien syöpien taustalla on infektio

Helikobakteeri ja hpv selittävät yli puolet infektioihin liitetyistä syövistä – ja molempia voi torjua.



Yliopistot | Kävin pääsykokeessa, ja huijaaminen olisi ollut helppoa

Pääsykokeiden valvonta tuntuu löperöltä, eikä vilppiä tehdäkseen tarvitse olla kummoinen hakkeri.



Muistokirjoitus | Ympäristöhallinnon pitkäaikainen osaaja

Ritva Salviander 1946–2026



HS Texasissa | ”Trump tuhoaa kaiken!” – Äänestäjät suuttuivat, ja nyt Yhdys­valtojen rajalla kytee yllätys

Yhdysvaltojen etelärajalla Texasissa saattaa tapahtua yllätys, jos demokraattien nuori toivo James Talarico yltää voittoon marraskuun välivaaleissa. Jos näin käy, laineet lyövät kauas.



Geenit | Maailman suurin bio­pankki tutkii koirien ja ihmisten sairauksia Helsingissä

Maailman suurin koirien biopankki sijaitsee Helsingin Meilahdessa. Siellä on tallessa lähes sadantuhannen koiran geeninäytteet. Professori Hannes Lohen mukaan koiran geenit auttavat ymmärtämään myös ihmisen sairauksia. Luvassa voi olla läpimurtoja.



HS 50 vuotta sitten 10.10.1976 | Onni on totuuden etsimistä

Palkitut ja menevät filosofit Georg Henrik von Wright ja Jaakko Hintikka



Kirjallisuus | Vakavasti sairastunut Katriina Huttunen lopettaa käännös­uransa ja kertoo mitä on oppinut surusta

Leukemiaan sairastunut suomentaja ajattelee kääntäneensä kenties viimeiset sanansa. Kuolema on ollut lähellä tyttären itsemurhasta lähtien.



Helsinki | Mies pelastettiin merestä Ruoho­lahdessa, roikkui kiinni laudan­pätkästä odottaessaan apua

Mies ehti olla vedessä kymmenisen minuuttia ennen kuin hänet saatiin nostettua ylös.



Kadonneet | Helsingissä kadonnut kahdeksan­vuotias tyttö löytyi

Lapsi on kunnossa, Helsingin poliisi kertoo.



Britannia | Kuningas Charles maksoi Andrew-veljensä 1,5 miljoonan punnan korjauslaskun

Kuningas Charles on maksanut Andrew Mountbatten-Windsorin 1,5 miljoonan punnan korjauslaskun, jonka tämä oli velkaa Royal Lodgen huonosta kunnosta.



Japani | Paikallisen naisen ryöstö­murha oli liikaa: okinawalaiset haluavat amerikkalaiset ulos saarelta

Yhdysvaltalaista merijalkaväen sotilasta epäillään naisen murhasta ja ryöstöstä Japanin Okinawalla. Tapaus on herättänyt voimakkaita reaktioita ja nostanut jälleen esiin keskustelun Yhdysvaltain sotilaallisesta läsnäolosta alueella.



Venäjä | Tass: Montenegrossa pidätetty venäläinen sotabloggaaja vapautettu

Ennen pidätystään Mihail Zvintšuk oli julkaissut Montenegrosta useita videoita, joissa hän jatkoi Venäjän propagandan levittämistä.



Sdp | Pamin puheenjohtaja Annika Rönni-Sällinen pyrkii edus­kuntaan

Rönni-Sällinen aikoo jatkaa Pamin puheenjohtajan tehtävässä normaalisti ehdokkuudestaan huolimatta.



Jalkapallo | Noora Karvonen, 19, onnistui kovassa paikassa, Marko Saloranta suitsutti puolustajaa

Päävalmentaja Marko Salorannan mukaan Helmareihin ei tulla tutustumaan ilmapiiriin eikä tutustumismatkalle.



Koripallo | Seagulls otti selvän voiton Bisonsista

Seagulls vastasi rökäletappioonsa vahvalla kotiesityksellä.



Televisioarvio | Koululaisraati tyrmäsi Ylen suosikki­sarjan uudet jaksot, mutta ei suostunut lopettamaan katsomista

Erityiset naulitsee ruudun ääreen sekä lapset että aikuiset. Eniten koululaisraatia nauratti kaamea reksi.



Elokuva-arvio | Kauhea äiti säikäyttää kymmeniä kertoja kauhu­elokuvassa, joka nosti kriitikonkin sykettä

Rob Savagen kauhuelokuvassa paha henki muuttuu äiti kaksoisolennoksi.



Asuminen | Suomalaiset asuvat yhä useammin vuokralla ja entistä ahtaammin

Samaan aikaan kun vuokra-asuminen yleistyy, myös entistä useampi joutuu asumaan ahtaasti vuokra-asunnossaan.



Mielenosoitukset | Opiskelijoiden protestit leviävät Euroopassa, yli 100 pidätettiin Belgian Liègessä

Belgiassa yhteensä tuhannet opiskelijat ovat osoittaneet mieltään sekä Liègessä että Brysselissä. Brysseliin oli kokoontunut arvioiden mukaan perjantaina jopa 50 000 ihmistä.



Kommentti | Helmarit teki Serbiasta vastaantulijan, mutta ei saanut vielä turvallista eroa

Suomen on Serbiassa pystyttävä toistamaan Tampereen onnistumiset: korkea prässi, keskikentän kaksinkamppailujen voittaminen ja nopeat hyökkäykset, kirjoittaa Ari Virtanen.



HS-analyysi | Terroristin ampuminen suorassa lähetyksessä olisi taivaan­lahja jihadisteille

Yhdysvallat on luomassa terroriristijärjestöjen propagandaosastoille valmiin spektaakkelin, jota on helppo hyödyntää uusien terroristien värväyksessä, kirjoittaa ulkomaantoimittaja Jukka Huusko.



Jääkiekko | Kiekko-Espoolle murskavoitto SM-liigassa

Kiekko-Espoo palasi voittokantaan kotiyleisönsä edessä. JYP taipui 6–1.



Kirjallisuus | Anne Carson sai Nobelin ja reagoi siihen lähes olan­kohautuksella

Mystisyydestä tunnettu Anne Carson sai kirjallisuuden Nobel-palkinnon. Hän arveli voiton vaikutukseksi lähinnä sen, että kirjojen kansiin lisätään tarroja.



Eläkeikä | Uudeksi eläkeiäksi 69 vuotta

Päättäjien tulisi ottaa oppia liikemaailmasta, jossa tuotteita kaupataan numeroon 9 päättyvillä hinnoilla.



Parisuhde | Oletko kumppanillesi tärkeä vai vain hyödyllinen? Testaa

Miten kumppanisi suhtautuu sinuun silloin, kun et pysty auttamaan, tukemaan tai joustamaan? Psykologi kertoo, mistä välineellistämisen parisuhteessa tunnistaa ja mitä sille voi tehdä.



Formula 1 | Aika-ajoissa nolo moka, lisätehoja ei kytketty päälle

FIA:n mukaan inhimillisen virheen takia joillakin kuljettajilla oli hetkellisesti käytössään vähemmän tehoa.



HS:n tiedot | Vantaa irtisanoo kymmeniä: säästöjä hallinnosta ja taiteen opetuksesta

Yt-neuvottelut johtavat esimerkiksi Vantaan musiikki­opiston ja kuvataide­koulun opettajien irtisanomisiin. Joidenkin soitinten opetus voi loppua kokonaan.



Ravintolat | Vegaaninen opiskelija­ravintola Myöhä suljetaan

Kävijöitä ei ole ollut tarpeeksi, sanoo Ylvan toimitusjohtaja. Myöhä on ollut Unicafen ainoa kokonaan vegaaninen ravintola.



Juhlat | Bileet Helsingissä täyttyvät miehistä, joilla on sama nimi

Aleksi-juhlat ovat paisuneet vuosien aikana niin, että tänä vuonna piti jo hankkia erillinen juhlatila.



Italia | Varkaat veivät 30 000 viinipulloa, saaliin arvo noin viisi miljoonaa euroa

Varkaita ei ole toistaiseksi saatu kiinni.



Virkavastuu | Eikö kukaan huomannut, että Google hakkasi metsää? ”Emme ole kuin 112”

Google alkoi hakata Muhoksella metsää maaliskuussa. Viranomainen alkoi selvittää asiaa vasta syyskuussa. HS kysyi, miksi puuttumisessa kesti.



Palkinnot | Normipäivä: 150 000 euroa säveltäjälle, jolle ehdotettiin mieluummin uraa tyttö­koulun opettajana

Rebecca Saunders on aikamme arvostetuimpia nykysäveltäjiä. Koulussa opinto-ohjaaja ei ottanut nuoren säveltäjän urasuunnitelmia tosissaan.



Venäjä-suhde | ”Saksan röyhkein eläkeläinen” Gerhard Schröder meni Putinin syntymä­päiville

Entinen liittokansleri Gerhard Schröder on Venäjän presidentin Putinin pitkäaikainen ystävä, eikä suhteeseen vaikuta edes Venäjän hyökkäyssota Ukrainassa.



Gaza | Jos Gazassa on tulitauko, miksi päivystyksemme yhä täyttyvät haavoittuneista?

Maailman johtajilla on velvollisuus estää kansanmurha, mutta he piiloutuvat tulitauon taakse ja sallivat verilöylyn jatkumisen.



Kerava | VR:n työn­tekijä tönäistiin juna­raiteille Keravalla

Ilta-Sanomien mukaan poliisi tutkii tapausta tapon yrityksenä.





Back to top



Al Jazeera

Back to top

Yemen’s Houthis release video of drone attacks on gov’t forces

Yemen’s Houthis have released drone video said to show attacks on Saudi-backed Yemeni government forces.



Damage seen inside Saudi airport after third attack this week

Video shows damage inside King Khalid International Airport in Riyadh after the third attack in a week.



Philippines volcano erupts, creating 6km-high ash cloud

Mount Kanlaon volcano in central Philippines erupted on Saturday sending thick plumes of smoke and ash.



Rubio pledges US cooperation in Marine-linked murder case

A US Marine stationed on Okinawa has been arrested on suspicion of killing a 39-year-old woman.



Israeli attack destroys building in Gaza one year into ‘ceasefire’

An Israeli strike destroyed a residential building in the Al-Rimal neighbourhood in Gaza City.



Why is the Trump administration trying to dismantle the ICC?

The US has imposed sweeping new sanctions on the International Criminal Court.



Lionel Messi returns from Argentina farewell as Inter Miami face DC United

Fresh off final game with Argentina, Messi leads Miami against DC United in Major League Soccer in the United States.



Azerbaijan school pupils protest over reported hijab restrictions

Pupils have been protesting after the implementation of a new dress code restricting the hijab in Azerbaijan’s schools.



Manchester United held by ten-man Tottenham as woes for both continue

Ten-man Tottenham fight back from a goal behind to draw 1-1 at Manchester United in the Premier League.



Trump says Ukraine needs a new president who will agree to end the war

US leader suggests Zelenskyy has not done enough to end the war amid tensions with Kyiv over a diesel deal with Russia.



Barcelona beat Getafe as Gordon scores his first goal

Barcelona make it six wins from six with a 3-0 win against Getafe as Anthony Gordon scores his first goal for club.



Ronaldo suspended by Portugal FA after leaving camp and criticising coach

Portugal star Cristiano Ronaldo suspended by his country's football association for walkout during Nations League games.



Trump calls for new president in Ukraine

US President Trump criticised Ukraine’s Volodymyr Zelenskyy as he called for new leadership in Ukraine.



Palestinians still being killed in Gaza, one year into ‘ceasefire’

One year to the day after the US-brokered ceasefire was agreed, more Israeli attacks killed Palestinians in Gaza.



Photos: Thousands march across Europe to demand end to Israel’s war on Gaza

Demonstrations in London, Berlin, and Rome denounce ongoing Israeli attacks on Gaza 'ceasefire' anniversary.



Attack on airport in Saudi capital, Riyadh, leaves several injured

Operations suspended at King Khalid International Airport after another attack this week, Civil Aviation Authority says.



Nine killed in shooting in US state of Pennsylvania, including two children

The shooting in Erie, Pennsylvania happened on Friday, according to state officials. The attacker is among the dead.



Pope says death penalty ‘inadmissible’ as US plans to livestream execution

Pope Leo XIV describes capital punishment as an 'attack on the inviolability and dignity of the person' in post on X.



Video shows rare albino Asian black bear

A rare albino Asian black bear was captured on camera in China’s Shennongjia National Park



Christa Pike discharged from hospital and returned to Tennessee prison

Pike survived two doses of lethal-injection drugs on September 30, renewing scrutiny of capital punishment.



Celebrations in Ethiopian city after reported Eritrean ‘incursion’

People in northern Ethiopia are celebrating after a reported withdrawal of Eritrean forces accused of an incursion.



Eritrea urges UN to intervene in standoff with Ethiopia

The neighbouring countries blame one another for starting war amid heightened tensions and fears of a wider conflict.



Hurricane Isaias: Four dead and thousands without power in US Southeast

Storm damage stretches across Florida and Alabama as officials warn of continued flooding and possible tornadoes.



Trump Accounts: Free money, but who gets a say?

Trump Accounts promise children a financial head start. Al Jazeera’s Emma Withrow spoke with one parent.



With or without Hamas

Hamas’s fate will not profoundly shape Gaza’s future.





Back to top



New York Times

Back to top

What to Know About the Delhi Protests

Protesters opposed to sweeping revisions to India’s voter rolls are trying to rally in New Delhi. The police have come out in force.



A Week Later, Russia Hasn’t Said What Pathogen Killed Plague Researcher

Experts said they believed that with modern testing technology, the Russian authorities should know the answer by now.



Navi Pillay, Nobel Peace Prize Winner, Forged Her Career Under Apartheid

Navi Pillay, who won this year’s Nobel Peace Prize, fought racism in South Africa, shaping her international career as a judge and advocate for justice and human rights.



Inside Erik Prince’s Mercenary Deal in Congo

The injury of a former Green Beret and death of an elite soldier from New Zealand have highlighted the Blackwater founder’s growing role in one of Africa’s most intractable conflicts.



Days of Deadly Houthi Attacks Show Saudi Arabia’s Vulnerabilities

The escalating violence has brought the conflict in Yemen to the doorstep of the Saudi capital, and the kingdom has no easy options to curtail the increasingly sophisticated and targeted strikes.



Ukrainian Drones Close Moscow Airports as Putin Flies Back to Russia

Government planes reported to be carrying the Russian president and his aides home from Turkmenistan were forced to circle or divert to another city.



Palestinian Authority Says Elections Are to Be Postponed

The delay, outlined in a letter to France, comes as Fatah, the governing party, is suffering from deep internal rifts.



As Putin Wages Shadow War, Europe Looks for a Way to Hit Back

Moscow has used tactics of fear and ambiguity to try to divide NATO and limit support for Ukraine. But how should Europe retaliate? And how hard?



Attacker in FlyDubai Flight Meant to Crash Into Israeli Airport, Emiratis Say

The attorney general of the United Arab Emirates said that the co-pilot had been inspired by the Sept. 11 attacks after years of developing extreme Islamist views.



In a Dead Hero’s Ashes, El Salvador’s Ruler Finds a New Spark

Sword in hand, Nayib Bukele is revamping Latin America’s rich tradition of political exhumations. A new crypt projects his power across Central America.



Paintings Stolen From Renoir Museum Are Recovered, Authorities Say

Officials also said that six suspects had been arrested in the robbery, which targeted a museum in southern France last month.



A Rural Village Voted to Leave the U.K., Stirring Britain’s Migration Debate

A plan to house 1,250 asylum seekers on the outskirts of Piddington prompted a symbolic independence vote, highlighting a growing dilemma for the government.



France’s Long, Fervent History of Protest

Student demonstrations in recent weeks re-lit a centuries-old torch of civil resistance. How do they compare to previous movements in France?



India’s Young Put Their Bodies on the Line to Be Heard

Despite police barricades and detentions, activists like Neha Bora say they are determined to keep up the pressure on Prime Minister Narendra Modi.



Trump Blames Zelensky for Stalled Peace Talks After Russian Attack Kills at Least 20

On Saturday, less than a day after President Trump announced a deal to buy Russian diesel, a Russian attack in Zaporizhzhia, Ukraine, killed at least 20 people, including children, officials said.



3 Men Found Guilty in Murders of Tourists on Mexico Surf Trip

The 2024 killings of two Australian brothers and their American friend drew international attention.



Exasperation and Resignation in Greece Over Allegations Against Kimberly Guilfoyle

The U.S. ambassador to Greece is facing accusations that she asked a donor to pay off her credit card bill before she took up her post in Athens.



Saudi Arabia’s Riyadh Airport Attacked Again, After Days of Houthi Strikes

The strike on Saturday was the deadliest attack in a Gulf Arab country since the U.S.-Israeli war with Iran began in February, and forced the airport to temporarily suspend operations.



From a Sikh Sanctuary to Chaotic Streets, Protesters Brave Police in Delhi

A group of demonstrators used a house of worship known as a gurdwara as a staging ground before their long-shot effort to reach a locked-down protest site in New Delhi.



Palestinian Authority Formally Delays Elections, Despite Western Pressure

The aging Palestinian leader, Mahmoud Abbas, pushed off the planned vote until late 2027. Palestinians haven’t had major elections for about two decades.



India Cracks Down on Gen Z-Led Protests

Demonstrators from the youth movement known as the Cockroach Janta Party met walls of security forces in New Delhi on Saturday as they tried to protest a revision of India’s voter roll.



Rebuking Ukraine Over Oil Strikes, Trump Says It Should ‘Get a New President’

Hours after President Trump said the United States would buy Russian diesel, the Kremlin said there would be no immediate resumption of discussions to end the war.



Quebec Independence Is Unlikely, but Some Will Still Dream

The idea of independence remains deeply unpopular in Quebec, yet the separatist Parti Québécois was re-elected to a minority government this week.



Blocked by Police, India’s Youth Voice Their Fury

Members of a youth protest movement are outraged after being intercepted at airports and stopped by barricades. “Aren’t we children of this nation?”





Back to top



Reuters

Back to top

This site is down!

Back to top



NPR

Back to top

Protests against voter roll revisions rock capital of world's largest democracy

Parts of the capital city of India, the world's largest democracy, are on lockdown. Protests over sweeping revisions to the voter rolls were met with a massive police crackdown.



U.S. and Russia tout diesel deal to ease sanctions and reopen fuel flows

Moscow and Washington tout a diesel deal to ease sanctions and reopen fuel flows, but few details leave questions on price impacts and U.S. policy, sparking anger from Ukraine and allies.



Photos: What a year of ceasefire in Gaza looks like

It has been one year since Hamas released the remaining Israeli hostages and President Trump promised an end to the war, but Palestinians say the past 12 months have been a ceasefire in name only.



India cracks down on youth protests as anger grows against Modi and election chief

The protests focus on the Election Commission's voter list revision, which the opposition claims disenfranchises millions. The government denies the allegations, saying the revision aims to eliminate duplicate entries.



South African human rights lawyer Navi Pillay wins Nobel Peace Prize

South African human rights lawyer Navi Pillay wins the 2026 Nobel Peace Prize for her lifelong defense of human rights and international law.



Trump says U.S. to get diesel from Russia, relaxing pressure on Moscow to ease prices before midterms

Trump says the U.S. will obtain diesel from Russia, relaxing years of U.S. pressure on Moscow, to combat prices before midterms. He said he struck the deal with Russian President Vladimir Putin in a phone call.



Did Russia play by the rules in reporting lab worker's death?

A global treaty signed by 197 countries — including Russia — requires reporting any death that could be a sign of an outbreak to come.



Trump says U.S. won't attack Iran before midterms. And, ICE agent shoots man in NYC

Trump announced that the U.S. will not attack Iran ahead of the midterms. And, a 28-year-old man is receiving treatment at the hospital after an ICE agent shot him in the neck.



South African human rights lawyer Navi Pillay wins the Nobel Peace Prize

South African human rights lawyer Navi Pillay wins the 2026 Nobel Peace Prize for advancing human rights and international law.



The long-deployed USS Lincoln returns home to San Diego Bay

The USS Abraham Lincoln aircraft carrier has returned home after a record-setting uninterrupted time at sea supporting the Iran war. The extended deployment drew attention following reports of crew stress and supply shortages.





Back to top



The Cipher Brief

Back to top

How Ukraine’s Ground Robots Are Changing the Battlefield



Operation Vivaldi, a Ukrainian military effort to repel Russian forces in the Donbas, has done much more than push back Moscow’s offensive in the region. The operation is credited with the liberation of dozens of square miles of once Russian held territory because of its mastermind use of drones and robotics on the battlefield. The operation has also ignited a firestorm of debate over the future of war and the human role. What follows is independent analysis of Operation Vivaldi by two Cipher Brief contributors who are actively engaged in the region.

INDEPENDENT ANALYSIS – Some Western commentators have suggested that Ukraine’s successful limited counteroffensive, Operation Vivaldi, by the 3rd Army Corps (3AC) has demonstrated the continued relevance of human maneuver in the face of drone technology, downplaying the ascendancy of drone warfare. In fact, Operation Vivaldi demonstrates just the opposite: the inexorable erosion of the usefulness of humans in direct contact with the enemy.

While isolated videos on social media may be found of direct fires exchanged between small elements of humans during the ongoing counteroffensive, the bulk of OSINT footage, as well as comments from Ukrainian commanders and soldiers, indicates that a new, systematic doctrine for the use of UGVs (unmanned ground vehicles) has been critical to operational success, and that humans generally advance only into lower-risk areas in the wake of waves of ground-drone advances.

The key to this doctrine is a fusion of classic American warfighting principles (taught to Ukrainians) with new tactics, techniques, and procedures (TTPs), together with a recognition of the changing spatial dimensions of modern warfare. In Operation Vivaldi, the aforementioned TTPs notably included the use of air-dropped UGVs to strike Russian positions, sow chaos behind enemy lines, take and hold ground, and clear lanes through minefields ahead of human advances.

According to “Darwin,” commander of the 2nd Mechanized Battalion of the 3AC, Russian soldiers and drones were suppressed by artillery, strike drones, and electronic warfare in order to prevent them from noticing night flights of repurposed heavy bomber drones carrying UGVs up to 19 kilometers deep into Russian lines. Some air-dropped UGVs with bombs struck Russian positions, while other UGVs with small arms would take and hold ground, sometimes killing and sometimes capturing the enemy in the process. Only then would humans incrementally advance: “We go forward, making a defense line, then waiting until artillery, flying drones and robots do their work, and then go in again.”

His men still only did this in small groups, with no restoration of large simultaneous human maneuver: “If before we moved with big battalion groups with mechanized forces, now we should use only small groups because of drones.” While this new pattern is currently only reported in use by 3AC, Darwin “said his corps was already teaching it to other brigades,” but noted that it required “a command structure ‘qualified enough as we are’ to run an operation with that many moving parts.”

But Ukraine still needed to degrade Russian operations before attempting to advance. Besides utilizing kinetic strikes, Ukrainian forces also deployed an electronic warfare “curtain” over parts of the battlefield, masking some Ukrainian movements and preventing Russian reconnaissance drones from operating. According to the Third Army Corps, its comprehensive “Defensive Dome” eliminated around 20,000 Russian drones during the operation, including via the use of interceptor drones, freeing Ukrainian armor to conduct mechanized assaults.

“Makar,” commander of the UGV unit “NG13” of the 3rd Separate Assault Brigade of the 3AC, says that air-dropped UGVs were used for months by his unit as “part of a systematic approach to sabotage operations, as such missions are aimed at eliminating the enemy deep behind their lines and in hideouts, capturing enemy pilots, disrupting logistics, and so on.” While the air-dropping technique itself may be a temporary novelty, the systematic large-scale use of UGVs ahead of humans may lead to a situation that he says “changes the rules of war.”

Makar continues: “We are developing a global doctrine for the use of UGVs... by the end of 2026, we’ll carry out a number of crazy operations the world... can’t even imagine are possible.” Regarding the military structure required, he mentions “strong coordination between the units we work with on these missions” and “the work of the workshop, planning group, command staff, and operators on duty.” He also notes the particular usefulness of UGVs--typically equipped with Starlink, hard to notice by the enemy, and not limited by station time like unmanned aerial vehicles (UAVs)--in enemy-held areas “where we have limited observation, limited FPV range, restricted operating distances, or where the enemy has strong air defense teams.”

Russian infantry has seen some success with infiltration tactics, able to slip through gaps in the thin Ukrainian lines singly or in pairs, due to the Russian tolerance for horrific casualties among such drone fodder.

Ukrainian UGVs, which need not be conserved like humans, are now performing similar infiltration missions against the Russians, but at even greater depth and sowing even greater disruption. “A UGV armed with a machine gun is probably more intimidating than an infantryman in many situations,” Obi, a soldier from Ukraine’s 3rd Special Operations Regiment, told the authors.

Makar described how in one episode, a single UGV caused disproportionate chaos: “They were freaking out over the radio, ‘A toy car flew in, then drove around, and then exploded...’ Well, their command doesn’t believe them, all hell breaks loose, and movement along that logistics route is immediately banned. All positions were placed on full combat alert... There were many times when they said, ‘No, we won’t go there because it’s unclear what’s going on there,’ and so on.” In another episode, “a single small UGV, airdropped some distance away, eliminated one enemy soldier and as a result, a full-scale enemy assault they’d been planning for days, if not weeks, was called off.”

Finally, Makar specifically refers to UGVs as a kind of replacement for infantry, saying: “Paratroopers used to drop from planes. Now UGVs are dropped from heavy bombers... I would like to address all the commanders... Emphasize ground robotic complexes... because robots don’t bleed, and human life is priceless.” Still, although they aren’t priceless like humans, drones need protection too: during Operation Vivaldi, relatively expendable UAVs were used to scout ahead of and escort UGVs.

Dmytro, a soldier with Ukraine’s Third Separate Assault Brigade, told the authors that drones and ground robots play a key role in supporting the infantry and also remove humans from some of the most dangerous tasks. “There are also many strike ground robots that drive in and destroy enemy shelters, killing the personnel inside,” he said. Some robots are meant to engage in assault operations, while others are sent behind enemy lines to conduct ambushes.

Additionally, as Ukrainian infantry and drone operators move forward, ground robots handle much of the logistics. “Ground robots make all kinds of deliveries to positions, including supplies for drone crews,” said Dmytro. “They deliver ammunition to artillery positions and supplies to the front line, and they carry out many evacuations.” In fact, 80% of tactical logistics and 90% of casualty evacuations during Operation Vivaldi were done by UGVs.

Former American soldier “Jackie,” who volunteered to serve with and advise 3AC, emphasizes that the American style of warfighting and command culture is critical to the integration of the emerging doctrine and new technologies seen in Operation Vivaldi.

“That’s been my job primarily is installing Western mission command trust and initiative.” Such concepts are embraced by 3AC, but don’t work at all for Russians: “It wouldn’t matter if I gave [them] a perfect lecture on Western Mission Command because they’re asking their guys to go die for nothing constantly... you can’t have initiative and trust in that environment... they misreport and they lie all the time.”

The effective military culture together with scaled drone use has resulted in three Russian field armies being pushed back by the much smaller 3AC, which consistently achieves an astonishingly favorable exchange ratio of 20:1 against the Russians (a claim backed up by OSINT as well as Ukraine’s battle “points” awarded according to provable kills, in which 3AC is usually leading when compared to other Ukrainian units).

Jackie points out, however, that Ukrainians have advanced past legacy doctrine and that Western commanders and planners need a feedback loop with people on the ground to keep up with what’s happening: “We’ve all been doing this for four and a half years. We are super experienced now. The operational planners who did this are elite. Sometimes you get a graduate of some war college somewhere with two pumps in the Middle East that says ‘I know everything about war and the Ukrainians should do this and that’... if you want to learn something by the way you actually have to participate in this fight. And I’m trying to constantly give out calls to Western forces... to come over here and do some work with us.”

“The theory of battle for the Ukrainians is really good. So they have a strategic deep strike campaign that’s punishing the Russian economy. At the operational level we have the midstrike campaign” targeting Russian logistics, “forcing them to have to vacate” their forward positions due to the extension of the gray zone. He adds: “The ground game is really important. If we lose the fortress belt, there will not be time for the midstrike campaign to pull Russians back. There will not be time to continue to do damage on the deep strike campaign and make the political actors in Russia pay.”

One new element of Ukrainian doctrine Jackie mentions is the need for standoff. 3AC maintains “control of ground space that enables us to continue to intercept Russian drones overhead. Russians are not able to get rocket artillery and other mass fires in range of the city of Izium.”

He says, “There is no contact line. There’s like a contact zone and that zone is 30 km across.” He emphasizes that this contact zone or “gray zone” is not a confused or messy jumble on the ground; Ukrainian commanders know where their men are positioned. But in this zone, human maneuver and logistics are severely constrained.

Dmytro said that Ukrainian forces attempted to bypass wooded areas and cut off Russian logistics, instead of sending infantry first. Ukrainian forces also continued shooting down the larger drones the Russians were using for resupply, which had a crippling effect on morale. “The enemy infantry begins to feel that no one needs them and that no help or support is coming,” he said. “Their morale becomes very low, and we make progress. Then they surrender or start fleeing.”

The principle behind the aforementioned infiltration tactics applies also to the enemy’s defense, as Jackie explains: “Where there’s just Russians all over the place that nobody cares about, and clearing them out is a pain... Driving a column across the gray zone is not an option to make an assault. That’s definitely not what we did for Vivaldi. So we had the ground drones on logistics, but also attack ground drones that were being air dropped behind the Russian line and then isolating and either fixing or destroying in many cases those isolated pockets of Russians on defense.”

UGVs are also more effective in this role than UAVs because “The Russians are going to have to fight that drone for a period of time. They’re going to have to resource Russian effectors to support the Russian fight against that drone. So in that local area this is creating ... massive chaos for whatever company’s area that drone got dropped into... they’re going to totally miss the infantry assault that’s actually approaching and being shaped towards them... some of those ground drop drones were technically like objectives for assault units to go and support... It gives everybody a lot of confidence on the assault to know that we already have a friendly force in the local area and so everybody gets moving faster as well.”

Jackie says that the soldier’s primary weapon is becoming the drone, and his pistol (secondary weapon) is being replaced by the shotgun for defensive use against drones. Yet he concedes that “there’s only one job in the military and that’s infantry. Nothing has changed about that. For all the drones... [What matters is] the ground game right in front of Kramatorsk and Sloviansk with those infantrymen.” But clearly, from all the other quotes above, we can gather that the nature of the infantryman’s work is rapidly transforming into something entirely different from closing with and destroying other infantry with rifle fire and grenades.Therefore Jackie’s point is taken to be that humans and the ground they occupy remain the ultimate tactical objective of the drones that increasingly occupy the buffer zone between them and the enemy’s forward line of humans.

Applying this notion back to the larger operational concept, we can say that combined unmanned-systems warfare, together with advanced mission command and a proper military culture based on initiative and trust, can allow unmanned systems to maneuver through the enemy’s tactical depth before human forces ever advance into the resultant pre-cleared areas.

Take it from the 3rd Army Corps: “Infantry wins wars, but we protect our infantry, which is why the robots go to the enemy first."

For deeper dives from Xen, you can follow him on X, Substack, or his personal site.

David Kirichenko is a Ukrainian-American freelance journalist who has been covering Russia’s full-scale war against Ukraine since 2022, and is an associate research fellow at the Henry Jackson Society. He can be found on X: @DVKirichenko.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Next Drone Won't Have a Radio Link, Our Intelligence Enterprise Needs to Plan for That Now

On the last day of the 2026 World Cup, NORAD F-16s fired flares over northern New Jersey to warn off civilian pilots who had flown into restricted airspace. During the tournament, federal agencies seized more than 700 drones across 11 host cities. The counter-drone effort worked.

That's what worries me.

In less than two years, Los Angeles will open the 2028 Olympic Games, a National Special Security Event spread across dozens of venues followed weeks later by the Paralympics. The threat there won't be the one we just beat, and this summer's solutions won't be the ones we need.

I've seen this before. From 2010 to 2013 I ran the Army's Rapid Equipping Force in the middle of the counter-IED fight. Congress authorized roughly $21 billion for JIEDDO, and we spent nearly $50 billion more on MRAPs. We still lost the adaptation race. The enemy learned and changed faster than our institutions could. Drones have the same traits that made IEDs so hard to beat: cheap dual-use parts, know-how that spreads through informal networks, and changes that cost the adversary almost nothing. Drones are IEDs that fly.

The next drone won't have a radio link

We don't lack counter-drone technology. But every answer we field starts a clock; someone is already building the counter. In Ukraine and the Gulf, autonomous navigation that doesn't need GPS is maturing quickly. One operator can run a swarm, and AI handles terminal guidance. Most counter-drone systems fielded today detect the radio link between drone and operator, and jam it. The drones that matter in 2028 may not have one.

When the sensor at the venue can't hear the drone, the warning has to come from before launch. Left of launch is intelligence.

Weak signals become capabilities before we see them

The drone threat rarely announces itself. During the battle for Mosul in 2016 and 2017, ISIS dropped small munitions from commercial quadcopters. In 2024, fiber-optic drones appeared in Ukraine as a workaround to jamming and quickly became widespread. In June 2025, Ukraine smuggled more than 100 small drones into Russia hidden in trucks, flew them over commercial mobile networks with open-source autopilot software, and struck strategic bomber bases as far away as Siberia. It was built from commercial parts and networks. The capability was the combination.

The same thing is happening here, in plain sight. A small startup has built software that keeps data moving when networks fail, uses AI agents to fuse that data and recommend actions, and ships new features every week. It's built for logistics. Pair it with an off-the-shelf mesh radio sold for drones; vendors say some can cover thousands of square miles from altitude. In a matter of months, a small team could field a jam-resistant, AI-assisted network of drones and sensors that no requirement anticipated and no threat library lists.

Nothing about either piece is a threat. That's the problem. We catalog platforms; the threat emerges in the combinations. And the expertise to put them together is for hire. This month, a Ukrainian air defense officer offered me his team's combat experience on LinkedIn.

Intelligence is more than threat warning

Our intelligence enterprise tends to treat counter-drone support as a threat function: who is flying, what they intend, what is coming. That job matters, but it's one of three.

The second job is awareness. Near a stadium or a base, most drones are flown by hobbyists, photographers, delivery services or people who never checked the rules. The hard problem is finding the one that matters in a crowded sky. That takes a picture of normal: Remote ID, FAA authorizations, event credentials, known commercial traffic. Most of that data sits outside intelligence channels, with the FAA, commercial operators, and state and local agencies that gained their own counter-drone authority on July 1 under the SAFER SKIES Act. The fusion model has to be built with these partners, not around them.

The third job is adaptation. Every drone we recover tells us how the adversary is changing: firmware, components, frequencies, supply chains. That knowledge has to reach the people building countermeasures and the units that will face the same drone next week. When Gen. Stanley McChrystal's task force in Iraq tied intelligence to operations, it went from about 18 raids a month in 2004 to about 300 a month by 2006. Not with better equipment, but because every completed cycle made the next one faster.

One threat, one learning loop

It's tempting to treat Los Angeles as a homeland security problem and the Gulf as a warfighting problem. The drone doesn't care. The same parts, tactics and know-how reach forward bases, stateside installations and crowded stadiums at the same time. Northern Command couldn't determine who flew several drones over a strategic U.S. installation after the Iran campaign began this year.

That cuts both ways. What we exploit from a drone downed overseas is the earliest warning Los Angeles will get. What we test at stadiums at home, in real conditions, strengthens the force overseas. JIATF 401 convenes DHS, the FBI, the FAA and dozens of other federal organizations; its director, Brig. Gen. Matt Ross, puts it plainly: "Nobody can solve this problem alone." Intelligence has to be the engine that makes that connection worth having.

Two clocks, one collision point

Our planning runs on a deliberate, gated clock: fund, test, buy, then freeze the configuration so people can train on it. The adversary's clock has no freeze date. State actors are patient: they watch our events, probe our installations and study our playbook. Extremists and lone actors copy what works overseas, hide among careless flyers and can change tactics up to the day they act. Whatever becomes cheap and proven overseas in early 2028 will be available to them in July 2028.

The collision point is our freeze date. Whatever they adopt after it, we meet unrehearsed.

The answer: test continuously through 2027 at real events, buy fast in early 2028, and never fully freeze. Keep money, authority and software update paths open so something can still change in the final 90 days.

Intelligence has to unfreeze the plan

Only intelligence can create the pressure to reopen a plan that has been funded, tested and trained on. Program managers have every incentive not to, and operators rarely get the chance. The intelligence community should schedule those assessments now, tied to the plan's decision points:

Each should answer one question: what has changed that should change the plan?

Sometimes the answer will be "nothing." The system has to be ready for the times it's "a lot." That means flexible funding that portfolio managers can move as the threat moves, and a Congress willing to let them.

In Afghanistan, when the enemy adapted faster than we did, soldiers and allies paid for the delay. We know the date of the next test. Build for the threat we'll face in 2028, not the one we just beat.

Pete Newell is the CEO of BMNT and a former director of the Army's Rapid Equipping Force.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Future of Iran Lies Beyond the Regime

The U.S. administration is pursuing its latest strategy: a naval blockade combined with aggressive “Outcast” sanctions, aiming to strangle the Iranian economy, force the regime to its knees, and compel it to return to negotiations on American terms.

Simultaneously, Washington is deploying additional military assets to the region. This is being framed as deterrence, but functions instead as yet another ultimatum. Any significant escalation, or even the credible threat of renewed strikes, risks triggering IRGC retaliation against critical Gulf energy infrastructure. While IRGC missile and drone inventories have been diminished, and exact IRGC munition levels remain classified, the regime likely maintains more than enough asymmetrical firepower to inflict massive damage before being neutralized.

Meanwhile, Tehran prevaricates, dodges, and plays for time. All while playing the victim, weaponizing scarcity, and brutalizing its own population. Their calculation is simple: endure enough short-term pain, while cynically passing the full brunt of it onto the Iranian people, to outlast Washington’s political tolerance.

Threats to the Strait of Hormuz and claims of control over shipping are manufactured leverage to be traded away at the right moment. They know this is opposed by virtually the entire world. By eventually “conceding” on this demand, a classic, predictable negotiating technique, they hope to secure what they truly seek: regime survival, proxy retention, and unimpeded continuation of their nuclear program.

These two paths clearly conflict with one another. Only one will prevail. But in the end, allowing an emboldened, empowered, nuclear-threshold regime to survive on their terms is utter strategic failure.

I vote for the U.S. winning. For the fall of a malignant regime that cares only about its power and wealth and holds its own people hostage.

There are no good options here. No simple fixes for where we find ourselves. Anyone with eyes can see that. So, then what?

A Radical Proposal

Forget talking to the regime. Speak to the Iranian people. Directly. Without hyperbole and with brutal candor.

Prepare them for what is coming. Not with hysterical rhetoric of annihilation, false promises of “boots on the ground,” or premature calls to take to the streets before conditions are ripe.

Tell them clearly: the target is the regime, not the nation, culture, or people of Iran.

Include regime insiders in this messaging, focusing on rank-and-file security forces, the regular military (Artesh), and yes, even IRGC leadership. They will receive the message. Some may act on it.

Be honest about what is coming: that breaking this regime will mean severe economic hardship, power disruptions, and scarcity, possibly even water shortages. Pair that honesty with a credible, binding commitment to a brighter future: a detailed blueprint for immediate relief and reconstruction, asset unfreezing, and re-integration into the global economy once the regime falls.

And lastly, assure them that Iran and Iranians will control their own fate, politically and economically.

I don’t consider myself naïve. This will be difficult. I was a specialist on Iran at the CIA for several decades. I saw both the worst and the best of Iran and Iranians. But the Iranian people (and the world) deserve more than this regime has to offer. Let’s give them (and us) that chance.

Prepare the ground, align the message, then execute.

This article was originally published on Mark Fowler's Substack.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How War Starts: A Warning from the Korean DMZ

The current landmine incident in the Demilitarized Zone of the Korean Peninsula could escalate into conflict on the Korean Peninsula.

South Korea and the United Nations Command said North Korea violated the Korean War armistice following a landmine blast on September 21 in the South Korean side of the DMZ, injuring three South Korean soldiers, two severely.

Kim Yo Jong, the sister of North Korean leader Jim Jong Un, dismissed South Korea’s allegations, saying they were a “conspiratorial farce”, threatening immediate and merciless retaliation if South Korean troops open fire on North Korean workers. She accused South Korea of fabricating a “self-directed farce”, creating groundless claims to create a pretext for political and military provocations.

South Korean President Lee Jae Myung on October 1, in an Armed Forces Day speech, said: “I hope that the North joins us now on the path of restoring trust and resuming dialogue, following a long interruption… and consistently pursue practical measures to reduce military tensions between the two Koreas.”

Hopefully, this incident doesn’t devolve into an August 18, 1976, incident when U.S. and South Korean personnel were pruning a tree in the Joint Security Area of the DMZ when North Korean guards, claiming the tree could not be cut, attacked with axes and clubs, killing U.S. Army Captain Arthur Bonifas and First Lieutenant Mark Barrett and wounding several others.

The U.S. response was quick and powerful, mobilizing troops, attack helicopters and B-52 bombers. Given this U.S. response, North Korean leader Kim il Sung issued an unprecedented statement of regret regarding the killings of two U.S. personnel.

The current situation is markedly different than 1976. North Korea is now a nuclear weapons state, with formidable ballistic missiles, while maintaining a conventional military force of nearly 6,000 conventional artillery systems and thousands of rocket launchers within striking distance of Seoul. Estimates of close to 200,000 special operations personnel are tasked with infiltration via tunnels and aircraft to disrupt South Korean command centers. Moreover, North Korea is now closely aligned with Russia, with a mutual defense treaty.

Given the progress North Korea has made building an arsenal of reportedly 60 to 100 nuclear warheads, and the ballistic missiles to deliver them, in addition to a mutual defense treaty with Russia, it would be fair to assume that Mr. Kim is more confident than his grandfather, Kim il Sung, in 1976.

Mr. Kim announced in January 2021 that North Korea had miniaturized nuclear warheads that can be used for tactical battlefield use. And in 2022, North Korean media confirmed that in 2022 they simulated tactical nuclear strikes to “wipe out” targets in South Korea.

Indeed, in September 2022, North Korea enacted a new nuclear law that declared that their nuclear weapons status was irreversible, authorizing preemptive nuclear strikes if their leadership or command systems is threatened. In March 2026, North Korea reportedly amended its constitution to mandate an automatic and immediate nuclear retaliatory strike if Mr. Kim is assassinated or if the country’s command-and-control system is threatened.

Ever since Mr. Lee, representing the liberal Democratic Party, was elected president of South Korea in June 2025, following the impeachment and removal of former president Yoon Suk Yeol of the conservative People Power Party, he has advocated for a resumption of dialogue with North Korea. Indeed, this inter-Korean dialogue ended in June 2020 when North Koea blew up the inter-Korean Liaison Office in Kaesong, claiming that this was in response to activists in South Korea floating balloons across the border carrying anti-regime propaganda pamphlets critical of the leadership in North Korea.

In the absence of dialogue between the two Koreas, with North Korea revising its constitution to say South Korea is a hostile state and their principal enemy, eliminating any reference to peaceful reunification and national unity, any incident like the landmine blast could escalate quickly.

An emboldened leadership in Pyongyang can seize on an incident of this type to escalate tension with South Korea, devolving into conflict, with the potential for another war on the Korean Peninsula.

Resuming an unconditional dialogue with North Korea should be our primary goal.

This article was originally published in The Washington Times.

The author is the former associate director of national intelligence. All statements of fact, opinion or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. government.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How America Wins the AI Race With Open Source

Speaking in Shanghai on July 17, Xi Jinping offered the world a vision of AI “for the positive, for good and for humanity.” He called for open source, openness, and sharing. He cautioned against stretching national security to cover the field. And he announced that over the next five years China will train 5,000 people from developing countries, build AI application cooperation centers with ASEAN, the Arab League, the African Union, CELAC, the Shanghai Cooperation Organization, and BRICS, and extend its MAZU meteorological warning system to 30 countries. The World Artificial Intelligence Cooperation Organization now exists in Shanghai with 37 member states.

This reasonable sounding offer is aimed squarely at the governments the United States most needs: countries that want AI capacity, local control, and a voice in setting the rules. For these governments sovereignty means control rather than independence, and a system they can operate locally is an easier sell than a remotely controlled API. Beijing pairs capable open weight models and inexpensive inference with training, institutions, and public goods, then wraps the package in the vocabulary of multilateralism and the United Nations.

The results are already visible. CNAS counted sovereign AI initiatives in 67 countries and the European Union by mid-2026, up from 16 governments in 2023, and most model projects with disclosed foundations adapt a foreign open weight model rather than train one. Increasingly that foundation is Chinese. Spain’s Quasar 438B, billed as Europe’s strongest reasoning model, is built on Z.ai’s GLM-5.2. Japan’s Rakuten AI 3.0 uses the DeepSeek-V3 architecture. AI Singapore built its latest regional model on Alibaba’s Qwen rather than Meta’s Llama, and Saudi Arabia’s HUMAIN commissioned its Arabic model from MiniMax. Chinese open-weight models passed the American share of global downloads for the first time in 2025, and on OpenRouter, a marketplace that routes developer traffic to models, their share of usage climbed from under 15 percent to more than half within a year, with businesses in the Global South the heaviest users.

The United States can win this competition, but not just by publishing the most advanced models and declaring victory. It must make American technology the preferred foundation for other countries’ AI systems, as American software and protocols became the foundation of the modern internet. That requires capable models, affordable hardware, financing, training, and dependable support, assembled into an offer that can stand beside a cheaper Chinese full-stack bid.

What America Must Do to Win

Washington should compete throughout hardware, models, software, and services. Retreating to frontier models and advanced chips while China supplies the open models, inexpensive inference, and industrial applications through which most of the world will actually use AI would surrender the contest at the layers where adoption happens.

Openness alone wins nothing. It gives a country seeking local control a reason to consider a model, not a reason to prefer an American one over a Chinese one. The American model must win on performance, total cost, local-language capability, reliable supply, and support, and it must leave room for domestic firms to build businesses around it. Partners deserve honest terms about licenses, updates, and what happens when a supplier relationship ends, and they have reason to ask. When U.S. controls forced Anthropic to suspend access to its newest models from June 12 to June 30, governments learned that even allies can lose access to American systems on a decision made in Washington. Autonomy has to be part of the product, because autonomy is what Beijing is selling.

The model is not hypothetical. An Indian financial firm runs DeepSeek on rented GPUs in India; the weights reside locally, inference never leaves the country, and there is no API for a foreign developer to revoke. Partners want the same from America, with the hardware, financing, and support that make it work. The developers now building on Qwen and DeepSeek show the cost of ceding that ground: expertise accumulates around particular models, models are tuned for particular hardware, and both pull future purchasing with them.

What China Is Doing

Xi’s language of openness should be read alongside that of Chen Yixin, China’s Minister of State Security. Writing in the Cyberspace Administration’s magazine in September, Chen describes AI as a primary battleground of great-power competition. He links political security, espionage, cyber capability, and military transformation to technological independence and control over international governance. An intelligence chief is explaining how AI alters the conditions under which his state exercises power. The two speeches are not in tension. One describes the offer; the other describes the objective.

The institutions Xi announced serve both. A cooperation center with each major regional bloc is a venue where Chinese models, hardware, and standards become the default for an entire region’s developers. A meteorological warning system deployed in 30 countries is a public good that also installs Chinese infrastructure and data flows in 30 capitals; an Egypt-specific version with aviation weather and sandstorm warnings is already in development, while Huawei courts Cairo for its Ascend chips and Malaysia weighs the same hardware. This is the softer sell: adapt the technology to the customer’s existing systems rather than demand reorganization around the supplier, as 01.AI did in building Kazakhstan’s national model. The World Artificial Intelligence Cooperation Organization is a bid to set governance terms in a body Beijing convened, and Xi’s warning against an expansive national security concept is a preemptive argument against the export controls Washington relies on. Washington should engage on international standards, but only where the decision rules leave Beijing no approval power over American development or release, at home or abroad.

Beijing’s openness may not last. Reuters reported in July that Chinese authorities were weighing restrictions on their own frontier models, and the TC260 AI Safety Governance Framework 3.0, released September 14 under CAC guidance, points the same way. Alongside provisions on loss of control and autonomous cyberattacks, its treatment of capability diffusion and removable safeguards suggests China may grow more selective about open releases. If so, its position as the default supplier of capable open models may not endure, and the window for an American alternative is open now.

The Tradeoff America Should Accept

Open models cannot be recalled once distributed. That is their appeal to partners, and it means adversaries will use them. The presumption should nonetheless favor open release. Any exception should identify the capability at issue, the security benefit of withholding it, the cost to American adoption, and whether adversaries can obtain comparable capability elsewhere. With a near-peer challenger offering alternatives, withholding American models may merely divert adoption without diminishing adversary capability. Washington can still restrict advanced chip exports for defined security reasons; a partner’s choice of competing hardware is a reason to improve the offer, not to penalize the partner.

Partner autonomy does not require surrendering American authority over domestic release decisions, export licensing, or the integrity of U.S. networks. It requires accepting that American benefits need not depend on a remote veto over systems partners already operate. Government and military users at home should continue to choose systems, closed or open, on performance and security.

What Washington Should Do

The July 2025 AI Action Plan endorses open-source and open-weight AI, and Executive Order 14320 on exporting the American AI stack supplies a framework for coordinated technology packages, diplomacy, and financing. The task is to convert those commitments into an offer that wins.

Fund what the market will undersupply: sustained open releases, smaller-language capability, independent evaluation, and affordable local deployment. Make the complete package competitive, with financing, predictable hardware access, workforce training, and genuine roles for local firms, and resource it as the national security priority it is. The Export-Import Bank’s $66.1 million guarantee for Côte d’Ivoire’s national data center shows the tools exist; it needs to operate at the scale of China’s regional cooperation centers. Demonstrate the bargain with willing partners through a sovereign AI pilot, potentially building on Pax Silica, that discloses remaining dependencies and compares cost, delivery time, and power requirements against the alternatives. Each regional cooperation center Beijing opens should have an American counterpart that partners can judge on results. Then measure the results: which models partners choose, whose hardware serves them, and who earns the integration revenue. A lost American sale does not always deepen dependence on China, and a won one does not always reduce it.

American leadership will prove most durable when partners have their own reasons to sustain it. The test is what countries choose to build, and whether building with America remains worth it to them.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Unique Risks of AI Adoption in Developing Economies

The U.S. must set dominance of global AI sector as a strategic economic and national security priority. If the PRC becomes the dominant provider of AI infrastructure and LLM model development, this will have dire consequences for the U.S. and allow the PRC to embed itself in many foreign countries, especially across developing economies. Developing economies, which have a more positive view of AI than their more developed counterparts, face increased risks and less ability to counter them.

The People’s Republic of China (PRC) is actively working to shape technological choices, including those related to AI through its Digital Silk Road. While the stated purpose of the program is to enhance global connectivity, it carries strings. The program embeds Chinese tech standards and companies on participants, which expands Beijing’s economic, geopolitical, and directive influence in cyberspace. These investments include hardware and software infrastructure that can lead to an effective long-term lockout of other competitors in this space. The U.S cannot let this happen.

U.S. failure to lead risks both the economic advantages, including market access, of the largest AI ecosystem and the ability to shape global standards, governance, norms and values (including privacy). In the absence of U.S. leadership, this space is likely to be filled by a nation with differing standards, norms, and values. When the U.S. engages, it can offer transparent partnership with auditable open models, reducing the chance that partners turn to less safe alternatives, and strengthening U.S. partnerships with those countries going forward.

If Beijing's systems become the default, it may not only provide data to improve their own AI capabilities, but also potentially exposes the purchasing country, and U.S. interests in that country, to disruption or espionage risk. These risks grow exponentially if these either adversarial or compromised AI systems are used in ports, grids, communications or other critical systems.

AI is not physical infrastructure, but when widely embedded it becomes infrastructural -- hard to replace, a key foundation for economic activity, and subject to resilience, security and lock-in dynamics that give the provider geopolitical leverage.

This combination of risks and opportunities makes U.S. leadership in developing-economy AI investments essential, not only for American economic interests, but also for the long-term national security and sovereignty of developing economies themselves. Converting those advantages into durable influence in the developing world requires deliberate engagement, including efforts like Pax Silica. The window for trusted U.S. partnerships on secure infrastructure, open and auditable models, and capacity building is open but narrowing.

Notable trends in AI investments in the Developing World

Across the world, governments are seeking to leverage AI for public and private sector gains, but funding sources and the types of AI models employed diverge significantly. These choices have large short- and long-term impacts. Between 2017 and 2025 more than 80 countries published national AI strategies. As of 2023 developing countries were less than half as likely (just 30 percent) to have these strategies as developed countries (more than 60 percent).

While national AI strategies are expanding across developing economies, follow-through including funding - varies. For example, India’s IndiaAI Mission has committed substantial resources to infrastructure and ecosystem development aimed at sovereign capabilities. Kenya has adopted a National AI Strategy (2025–2030) alongside skilling initiatives and public-private AI hubs. The African Union’s Continental Artificial Intelligence Strategy provides a regional framework, while countries such as Nigeria and Rwanda are advancing targeted investments in AI centers and applications.

Many of these efforts are public-private partnerships with both domestic and foreign funding. A PRC company has positioned itself as Rwanda’s digital transformation infrastructure partner on projects including but not limited to AI. The PRC is also building key parts of Kenya’s AI infrastructure and providing funding to support it through loans.

A key trend is the choice between open-source, open-weight and closed, or proprietary models. Open-source and open-weight offer customizability, including linguistically, increased data control and sovereignty, and the ability to self-host, meaning the owner controls the infrastructure and can better control the costs. Fully open-source models go further by also releasing training data and code, allowing deeper inspection. Open-weight models require less upfront costs than open-source, which requires training from scratch.

Closed or proprietary models usually deliver out-of-the-box performance, require less infrastructure and come with providers who support continuous updates. However, they offer far less customizability and higher, as well as less predictable costs driven by usage volume. They can also create dependence on the provider for access, security, and future capabilities. These choices will shape data flows, as well as technological and geopolitical dependencies, for decades. Proactive U.S. leadership can help ensure AI becomes a source of shared prosperity and security rather than risking a new avenue of vulnerability and influence.

Unique challenges of AI in the developing world

Most low- and lower-middle-income countries face challenges in finding talent to support AI and other ICT needs, limiting local ability to design or train models. Developing markets also face private sector hesitancy to finance large-scale AI infrastructure given low demand and less reliable power which reduce guarantees that returns will justify the capital outlay. This makes government investment and use of AI for services a potentially critical anchor for AI infrastructure and adoption by creating the initial demand that later attracts broader private investment.

Developing countries are also more likely to have weaker legal and regulatory frameworks, creating uncertainty for AI investment and implementation. Lack of clarity around liability and enforcement raise costs and uncertainty which deters investments, since risk is more challenging to reliably assess or manage. Weak frameworks can also lead to AI exacerbating underlying issues by making processes, such as authoritarian surveillance, more efficient.

AI usage presents privacy risks that are heightened in lower capacity environments common in the developing world. AI models require massive amounts of data often including sensitive personal information such as location, biometrics, and communications to support pattern recognition that lets them serve users. Uses such as healthcare, smart cities, and surveillance infrastructure, require collecting and leveraging huge amounts of highly sensitive data. AI models also require auditing including for bias, which exposes the data and may let vendors or governments repurpose it.

Whenever large amounts of data are collected, privacy is at risk, making it important to minimize inadvertent exposure. Strong cybersecurity standards are essential for protecting this data. This makes it essential that privacy is included by design – from the outset – in AI efforts. These principles must be coupled with broader secure-by-design cybersecurity principles and leveraged into frameworks that are incorporated into all implementation.

For example, many countries lack comprehensive data protection laws, and enforcement mechanisms may be especially weak in developing economies, making it difficult to impose meaningful constraints on data collection, use, or cross-border transfer. Countries with weaker institutions and legal foundations face increased risks. These factors make privacy principles both more essential and more challenging to implement in developing countries.

Different Model Types as Developing Countries Adopt AI at the Government Level

Open-source and open-weight models are the primary ones being adopted by developing economies at the government level, chosen to support sovereignty and reduce dependency risk. Closed or proprietary models often involve data flowing outside the sovereign country, risking access by another state and passage into jurisdictions with different safeguards. But localized data alone does solve for data security, and even with self-hosting, limited local cybersecurity remains a risk.

Data centers being located physically in country does not necessarily give control over the technology, data, or strategic assets. For example, across Southeast Asia especially Malaysia and Indonesia the rapid expansion has been driven largely by foreign hyperscalers, but the underlying technology and decision rights are outside the host-country’s control. This can also create risk of export-control diversion, for example Singapore’s 2025 prosecution around misrepresentation of the end-users of servers containing U.S.-controlled Nvidia chips.

It is likely that open-source and open-weight models will remain the primary choice for high-volume and self-hosted use driven by cost and return on investment. Open models achieve approximately 90 percent of the performance of closed models at release and quickly make up the difference. This performance gap is continuing to narrow, and costs for comparative open models can be 17 percent that of the alternatives.

Across developing economies, AI models from the PRC are gaining traction more quickly than Western models. DeepSeek is being adopted across Africa at a rate two to four times that of Western alternatives, likely because of the cost and openness, key factors in resource constrained environments. Of note, Australia, Taiwan and South Korea have all issued public warnings around the security risks of DeepSeek, including banning its use on government devices. Some U.S. models are competing, such as Meta's open-source Llama which is used for purposes including to deliver agricultural advisory services in Kenya, Nigeria, and India. But AI adoption and development across the world are evolving, leaving opportunity for market capture still in flux.

Current Impacts of PRC Investment in AI in Developing Countries

The PRC has been focused on advancing its global digital infrastructure footprint for more than a decade through a Belt and Road linked Digital Silk Road (DSR). The DSR covers a broad range of investments from surveillance technology to cloud computing and AI, from infrastructure to LLMs. Infrastructure support of any kind is uniquely difficult to reverse, locking in relationships between the two countries even if the geopolitical landscape shifts. This can open the door to coercive leverage should the providing country wish to exert it.

The PRC has already built significant parts of digital infrastructure across the Global South, especially across Africa and Asia, including telecommunications networks, fiber-optic cables, data centers, cloud services, and smart cities. By building this infrastructure, providing software and setting operating standards, the PRC creates systems that their state actors understand completely posing significant risk for penetration and influence. PRC’s national security laws require Chinese firms to cooperate with the state, meaning that the use of even supposedly private-sector technology from the PRC presents government surveillance risks. This poses a risk as the U.S. attempts to engage with these countries across sectors.

AI is likely to be foundational for the global economy over the next century. When countries adopt an AI product in partnership with another country they at least informally adhere to the standards of the producer. PRC leadership on AI opens the door for Beijing to set global standards on detecting bias and training models that are likely to think about the world the way the CCP does. The U.S. not leading in this space does not just risk U.S. market share but also the U.S. ability to set the operational and cultural standards for AI. If a U.S. adversary captures this market and sets these standards the U.S. will face long-term national security challenges.

How to Win

The U.S. does not need to match the PRC dollar for dollar but must arrive with solutions and credible long-term funding packages to the global south. The PRC’s own neighborhood, the Indo-Pacific, can offer a model for how this might function. In 2022, Solomon Islands took a PRC concessional loan to build 161 Huawei telecommunications towers. Yet when Australia funded the Coral Sea Cable in 2018 in place of a Huawei proposal to connect Papua New Guinea and Solomon Islands, and when Australia, Japan and the U.S. committed to jointly finance the East Micronesia Cable, allies showed that a trusted, competitive alternative can win when it is financed and offered early.

The U.S. can work with allies and partners already in these markets, particularly Australia, Japan, South Korea, India and Singapore in the Indo-Pacific, to co-finance infrastructure. These partnerships can and should also include security assistance that supports model evaluation and guidance on secure hosting. Such partnerships offer governments across the Global South a strong alternative without asking them to choose between great powers, a choice many are reticent to make.



Hegseth’s Vision for a New American Military

“It's worth saying again so that the fake news understands it. We are no longer the woke department or the weak department. Simple translation of that: No fatties, no trannies, no beardos, no weirdos, no wimps, no radicals, just warriors -- just tough, ready, committed troops. The War Department, as you know, is colorblind, gender neutral, and merit-based. Or, as the President likes to say to me: ‘Pete, central casting. I want central casting.’”

That was Defense Secretary Pete Hegseth speaking on The State of the Force last Wednesday at the Marine Corps Base, Quantico, Virginia to a group of 600 selected O-3 junior officers (Captains in the Army, Marine Corps, Air Force, and Space Force; Lieutenants in the Navy and Coast Guard) and E-6 enlisted service personnel (Staff Sergeants in the Army and Marine Corps; Petty Officers First Class in the Navy and Coast Guard; Technical Sergeants in the Air Force and Space Force).

President Trump wants a military that looks like “central casting,” and Defense Secretary Hegseth, who looks and acts as if he, himself, came out of central casting, gave last week’s speech, reminiscent to anyone over 45 of the 1970 movie Patton, where George C. Scott playing Gen. George S. Patton also spoke before a full-screen American flag.

“The ideological clowns are out,” Hegseth said, “The patriotic cowboys are in with testosterone testing on top.”

He is correct.

He spoke of bringing back PT (physical training) “for every combat MOS (military occupational specialty),” adding, “We now have a combat field test, again, set at the highest male standard, only because combat doesn't care. That means two PT tests every year for every unit.”

As for picking senior leaders, Hegseth said, “We got rid of the DEI-based (diversity, equity and inclusion), social, emotional, evaluations known in the Army as BCAP [Battalion Commander Assessment Program] and CCAP [Colonels Command Assessment Program]. You won't have to endure them. They were [former-Joint Chiefs Chairman Gen. Mark A.] Milley and [former Defense Secretary Lloyd] Austin specials, intended to create politically-correct quotas for race and gender. Under the guise of double-blind psychology assessments, the previous administration forced out so-called toxic leaders in favor of promoting risk-averse, get-along to go-along conformists.”

However, Hegseth left out the important fact that BCAP and CCAP were products of the first Trump administration, put together by Casey Wardynski, then-President Trump’s appointed Assistant Secretary of the Army for Manpower and Reserve Affairs.

In prepared testimony for a March 11, 2020, Senate Armed Services Subcommittee on Personnel, Wardynski said, “The Army is currently prototyping, piloting, or implementing talent management initiatives from Talent Based Branching (TBB) to Battalion Commander

Assessment Program (BCAP), with the goal of implementing most of these initiatives by December 2020… Exit interviews and surveys from participants, board members, and distinguished visitors indicate BCAP is better than the legacy system for selecting battalion commanders and other key Lieutenant Colonel positions. Seven hundred and fifty candidates participated in the first iteration of the BCAP in January and February 2020.”

In a September 21, 2020, Army release about testing the new Colonels Command Assessment Program (CCAP) for bias at Fort Knox, Kentucky, Wardynski is quoted saying of the CCAP program, “When we started things like talent management and then this [CCAP], the question of fairness came up. A lot of the focus of fairness was to the individual.”

Although Milley was Army Chief of Staff at the time Wardynski’s BCAP and CCAP were being introduced, then Gen. Austin was head of Central Command and not involved.

Since January 25, 2025, when he became Defense Secretary, Hegseth has changed the senior leadership of the military and even has plans that could affect the leadership in years to come, and I will discuss that below.

First I want to point out that Wardynski was not the only originator that Hegseth ignored during last week’s speech.

For example, former-Defense Secretary Ash Carter and his Deputy Defense Secretary Robert Work in 2015 established the Pentagon’s Defense Innovation Unit (DIU) which was the initial effort to bridge the gap between the Defense Department and commercial technology through rapid investments in autonomous systems, human-machine teaming, and even early Artificial Intelligence (AI).

Project Maven, linked to DIU in 2017, focused on integrating computer vision and AI into drone operations, allowing computer algorithms to autonomously scan hours of aerial drone video footage to detect and tag potential tactical targets.

This sounds a lot like Hegseth’s new Autonomous Warfare Command (AutoWarCom). And to tie the connection further to Carter and Work’s DIU, Hegseth named Owen West, who up-to-now has been DIU’s Director, to be Chief Executive Officer of AutoWarCom.

Then there is Project Meridian, which is supposed to -- in Hegseth’s words -- “Creatively look to the future and identify the domains that we must conquer and capabilities we must master.”

We old-timers knew Andrew (Andy) Marshall and his Office of Net Assessment at the Pentagon which was started in 1973. With a small staff and a wide range of consultants, Marshall covered many areas related to national security. When he retired in 2015, his work was carried on until Hegseth disestablished it in March 2025.

Hegseth’s March 2025 memo called for a plan to rebuild the Marshall office in a manner “consistent with [Hegseth’s] priorities.”

Project Meridian may be that. As Hegseth described it last week, “We need to be looking forward into the future to achieve technological and military dominance on the battlefield for

decades to come. It is futuristic on purpose. Their work will be focused on discovering, developing, and fielding the weapons and systems that our children and our grandchildren will need in their lifetimes without any creative limitations or restrictions.”

Hegseth said last week that he has from the beginning wanted a 20 percent reduction of flag officers “across the board,” adding, “Now, the media calls that a purge. I call it accountability, long overdue and frankly the bare minimum…You see you can't change a culture with the same people who enabled it.”

A list of those fired, compiled by CBS, is impressive: Air Force General Charles Q. Brown, chairman of the Joint Chiefs of Staff; Navy Admiral Lisa Franchetti, chief of naval operations; General James Slife, Air Force vice chief of staff; General Randy George, Army chief of staff; General David Allvin, Air Force chief of staff; Army Lieutenant General Joseph B. Berger III, Army Judge Advocate General; Air Force Lieutenant General Charles Plummer, Air Force Judge Advocate General of the Air Force; Admiral Alvin Holsey, head of U.S. Southern Command; General Christopher Donahue, head of U.S. Army Europe and Africa; Air Force General Timothy Haugh, NSA director and head of U.S. Cyber Command; Lieutenant General Jeffrey Kruse, head of the Defense Intelligence Agency; Air Force Lieutenant General Jennifer Short, senior military assistant to Defense Secretary; Vice Admiral Nancy Lacore, Navy Reserve chief; Rear Admiral Milton Sands, head of Naval Special Warfare Command; General David Hodne, Army Transformation and Training Command; and Major General William Green, head of the Army Chaplain Corps.

In addition, I add Navy Secretary John Phelan and Army Secretary Dan Driscoll.

Needless to say, nothing like this has happened in the past to the U.S. military, and it doesn’t end there. We don’t know the full extent of the individuals Hegseth has knocked off promotion lists, although indications are clear they are most often women and minorities.

In another effort to affect the future, Hegseth not only has sought to force changes in the Service Academies’ curricula and civilian tenured teaching staffs, he announced in last week’s speech an attempt to influence college ROTC units and thus the future generation of young officers.

He also announced establishment of a new program, America’s Core of Cadets, to be initiated at five specified institutions: Louisiana State University (LSU), Liberty University, Tuskegee University, Mississippi State University, and Hillsdale College.

The publication Inside Higher Ed reported last week that LSU will establish a four-year military or national security program; create a self-governed student military organization – a cadet corps -- led by an independent commandant who reports to LSU’s president; and cadet members will be required to wear uniforms during all academic hours.

On top of all this, Hegseth also announced establishment of an Office of Religious Affairs, which will report straight to the Defense Secretary, or as he put it: “No staff filters, no bureaucratic dilution, a direct line to the Secretary. This is not going to be a paper-pushing shop. It's going to have real teeth. They'll protect budgets, demand infrastructure, and strengthen religious support.”

To justify this religious office, Hegseth pointed out, “Less than five percent of our force identifies as non-religious. Less than five percent. Meaning 95 percent of our force recognizes an almighty God.”

As with other statements made by Hegseth, this is not totally true.

According to a 2019 study conducted by the Congressional Research Service, approximately 73 percent of all military service members identify as people of faith, compared to less than three percent who are atheist or agnostic. Religious diversity in the military is broadly representative of the U.S. population, with nearly 70 percent of active duty military personnel who consider themselves to be Christian.

Hegseth said last week, “Our department is, you might say, putting on the full armor of God, because while we wage physical war, we all know the real battle is spiritual.”

Reviewing all Hegseth is doing, as a drafted, two-year Army veteran from the 1950s, I would say our Defense Secretary is taking the spirit of true government service out of the military I have known.

Update: We corrected an earlier misquote from Pete Hegseth.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Election Security: Keeping Our Disagreements Our Own

About one month before Election Day, Americans deserve to know how their government is protecting elections from foreign threats. The Pentagon’s recent directive assigns military intelligence and cyber capabilities to that mission. I welcome that commitment. Americans also need to understand how it fits into the national effort and how federal agencies are supporting the state and local officials who administer elections.

As a former Election Threats Executive at the Office of the Director of National Intelligence, I would have preferred an ODNI-led announcement explaining the foreign threat and the coordinated response, with the FBI, Defense Department, and Department of Homeland Security alongside it. Most of my career was spent at the intersection of combat support and intelligence. My preference comes from ODNI’s role in integrating intelligence across agencies and explaining what it tells us about foreign threats.

Election security depends on accurate ballot counts and public confidence grounded in credible information. An announcement centered on Defense risks giving a military cast to the mission and leaving the public with an incomplete picture. Americans need to understand how federal agencies use their authorities and resources to support elections administered by state and local officials.

An Old Threat Comes Into Focus

Foreign efforts to influence American elections did not begin in 2016. Soviet operations against President Ronald Reagan’s 1984 reelection campaign included a forged letter intended to discredit him. The FBI publicly exposed the forgery. The technology was different, but the purpose is familiar: manipulate Americans’ perceptions through concealed foreign activity.

The 2016 election brought that threat into the center of American public debate and forced a reassessment across the Intelligence Community. The January 2017 intelligence assessment described Russia’s campaign as an escalation in the scope, intensity, and directness of its efforts. Hacking and influence operations could reinforce one another, reaching Americans through channels they used every day.

Identifying a foreign operation is only part of the job. The people it targets need enough information, soon enough, to protect themselves.

By the 2020 election cycle, the government had developed a more deliberate answer. It involved intelligence collection and analysis, investigations, cyber defense, support to election officials, and decisions about what information could be shared beyond classified channels.

Russia is part of a broader challenge that includes China, Iran, and countries with varying relationships with the United States. We need the full national security team to understand what these governments are doing and why, and to inform the operations and policies needed to counter interference, regardless of who is behind it.

What the 2020 effort taught us

The Executive Branch Notification Framework, adopted in 2019, established a process for deciding when and how to notify people about foreign election influence and interference. It complemented existing victim-notification requirements. An interagency group organized by ODNI evaluated threats; DHS handled notifications concerning critical infrastructure, while the FBI handled other notifications.

The framework recognized that different threats require different forms of communication. Some call for a private warning to a targeted candidate or organization. Others justify informing the American public. Decisions were intended to be coordinated and nonpartisan, while respecting protected speech.

Public communication in 2020 extended beyond that framework. In July, National Counterintelligence and Security Center Director William Evanina described intelligence briefings for presidential campaigns, political committees, and Congress. His July 24 public statement and August 7 update also provided unclassified information about the evolving foreign threat. These were complementary channels: detailed briefings for particular audiences and information the broader public could use.

There were also coordinated announcements about specific threats. On October 21, the DNI and FBI director appeared together at an election-security press conference. FBI Director Christopher Wray explained the Bureau’s investigative responsibilities, described cooperation with government and private-sector partners, and urged Americans to seek reliable voting information from state election officials.

Private notifications, classified briefings, unclassified threat updates, and public statements serve different needs. A public attribution can expose an adversary; a private warning can help a target respond without unnecessarily amplifying the operation.

Public confidence depends on evidence and competent election administration. Officials should explain what they know and what remains uncertain. Otherwise, foreign actors have more room to supply their own explanations.

Finland’s Lesson: Prepare Together

I had the privilege of traveling to Finland to discuss and learn about its election preparedness. What struck me was how far the Finns took the team sport concept: they connected responsibilities across government and practiced working together.

Finland calls its approach comprehensive security. Government agencies, businesses, organizations, and citizens all have a part to play. Its election preparations have included training for authorities and political parties. Its broader government preparedness exercises combine work within individual ministries with shared crisis scenarios. These are practical ways to build relationships and understand responsibilities before a crisis.

Finland’s experience with Russian disinformation shows why this matters. Years before the 2016 U.S. election, Russian state-controlled media and pro-Kremlin figures spread claims that Finnish authorities were taking children from Russian families without legitimate reasons. EUvsDisinfo documented a recurring campaign around child protection and custody cases. This was a broader attack on trust in public institutions, rather than an election-specific operation.

Finnish officials answered publicly. On October 12, 2012, the social affairs minister met Russian journalists in Helsinki, while Finland’s ambassador in Moscow held a press conference to correct unfounded claims and explain Finnish child welfare. When another case attracted attention in 2016, the Ministry of Social Affairs and Health issued a public statement explaining that children were not removed because of nationality, that taking a child into care was a last resort, and that parents could appeal decisions. It also provided links to Russian-language information.

The lesson for the United States is that coordination has to be practiced before it is needed. Agencies must know who will establish the facts, who can act, and who will explain the response to the public. Finland’s example also shows the value of answering false claims with clear information about how institutions work and what protections people have. For election security, that means helping Americans understand both the threat and the safeguards protecting their vote.

AI makes coordination more urgent

In September 2024, ODNI reported that Russian and Iranian actors were using generative AI in election influence efforts. Russia had generated election-related text, images, audio, and video. Iranian actors used AI for social media posts and articles on websites posing as legitimate news outlets.

During my tenure, we were beginning to consider how to respond to deepfakes in foreign influence campaigns. We struggled with how to flag them quickly and explain the threat publicly while protecting intelligence sources.

ODNI assessed that AI was accelerating and improving aspects of these operations, but had not yet revolutionized them. Producing deceptive material does not establish that it persuaded voters or changed an election outcome.

In September 2026, Anthropic reported disrupting operations that used its tools to build fake social media identities and news sites, prepare campaign plans, and conceal who was behind the material. Much of the content it discovered attracted little or no genuine engagement. Those findings concern the operations the company observed, rather than all foreign influence activity. Public warnings should distinguish an adversary’s capabilities from an operation’s reach and effects.

Defenders need to determine whether AI is making impersonation more convincing or allowing foreign actors to exploit local incidents more quickly. They also need to establish who is behind an operation and warn its targets before the deception spreads.

These are intelligence and operational questions that cross agency boundaries. They also require clear limits. A false claim is not automatically a foreign operation. Americans’ political speech remains protected, including speech officials find objectionable. Election defense must establish the foreign nexus and act within lawful authorities.

Make the Full National Response Clear

Secretary Pete Hegseth’s September 22 memorandum directs the defense intelligence enterprise to collect and produce intelligence on foreign election threats, consistent with law and departmental policies. It also directs Cyber Command to use its existing authorities in coordination with DHS to counter foreign cyber threats. Addressed to Cyber Command, NSA, DIA, and NGA, the memo explicitly describes Defense as supporting a whole-of-government effort.

The memo does not name ODNI or the FBI, but that does not establish that they are excluded from the wider effort. Nor does it designate Defense as the national lead. My concern is how its departmental instructions connect to the full response, and how that response is explained to Americans.

The Washington Post reported on October 4 that state officials, including Republicans, described gaps in federal threat information and support. It also reported recent steps, including CISA’s September 24 security plan and the restoration of NSA’s Election Security Group. Those steps deserve acknowledgment. The practical test is whether assistance reaches election officials in time, through relationships they trust.

The Pentagon has an important role. NSA’s account of its work with Cyber Command during the 2022 midterms described sharing foreign intelligence with domestic partners and using cyber capabilities to disrupt foreign attackers. Those capabilities belong in the national effort. My concern is how the overall effort is explained and led. ODNI should provide a coordinated assessment of the foreign threat. The FBI should explain its investigative role. DHS should explain its support to the officials responsible for administering elections. Defense should explain how its capabilities support those missions. Together, they should tell Americans how warnings and public attributions will be handled.

There is precedent. In November 2019, Justice, Defense, DHS, ODNI, the FBI, NSA, and CISA issued a joint statement describing preparations for the 2020 election. They emphasized sharing actionable information and working with state and local officials and private-sector partners. We do not need sensitive operational details. We do need to know who integrates the intelligence, who alerts a target, and who speaks when a foreign operation requires a public warning. Those arrangements should be tested before an incident forces a rushed decision. They should also remain in place through the counting and certification of results.

No agency sees every part of this problem. Election officials need information they can act on, and the public needs explanations it can trust. Federal leadership must connect the intelligence, investigations, cyber defense, and support to those administering the vote.

With one month to go, the message should be clear: vote and have confidence in doing so. A healthy democracy makes room for vigorous disagreement. The government’s role is to ensure that the rightful tensions of our democracy are our own.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Pentagon’s 2027 Drone Problem

On September 30, at Quantico, the Secretary of War announced a four-star command for autonomous warfare. The memorandum behind it is two pages long. It gives two officials 30 days to produce a plan and sets October 1, 2027, as the day the Autonomous Warfare Command stands up. “We do not have a decade,” it says.

On the same day, a California company announced a Pentagon order for 14,000 small attack drones, along with 800 more reallocated from competitors that could not meet their production deadlines. First-round deliveries had been running late, the trade press reported, because the motors, batteries, sensors, and chips that American law will accept were in short supply.

Five weeks ago in these pages I argued that America was buying an army it could not command. The Hegseth memorandum is the most serious answer that argument has received. It settles who buys, and it leaves to the 30-day plan who decides between theaters when the systems run short. It is silent on a prior question. Before a force can be commanded, it has to be built, and this one is being built from parts supplied by the adversary.

The official now charged with building the command has said so to the Senate. “Many of the subcomponents,” Owen West told the Armed Services Committee in March, “do today come from China,” and he put American or allied supply “deep in 2027.” China makes roughly nine of every ten rare-earth magnets in the world. The largest American producer told investors in August that demand for the magnets inside drone motors is met “essentially 100 percent in China.” An American-made drone motor costs $100 to $225; the Chinese equivalent costs $12 to $25. The memorandum asks for a force on “the right side of the cost exchange.” For now, that exchange is priced in Chinese factories.

The trade truce does not reach any of this. Beijing’s ban on dual-use exports to American military users has been in effect since December 2024 and has never been suspended. In June, China added two American magnet makers and a drone manufacturer to its export-control list. The truce itself was extended in September to January 10, yet the notice that suspends China’s rare-earth licensing rules still expires, on paper, on November 10. That is eight days before the President is due in Shenzhen, where he will arrive as the customer for the magnets his own deterrent requires. Beijing does not need an embargo to use this. It needs only to let a notice lapse, and its magnet shipments to the United States had already fallen 21 percent in August.

Washington has set a date of its own. On January 1, the Pentagon’s rule barring Chinese-origin magnets from defense supply chains takes effect. For most of next year, Chinese parts will be barred by both governments while American ones are not yet made in volume. That stretch falls in 2027, the close of the Davidson Window, the year American commanders have named since 2021 as the one by which Beijing wants the option of force against Taiwan. The force meant to deter China in 2027 depends, through 2027, on China’s willingness to keep selling to it.

The picture is not hopeless. Magnet plants in South Carolina, Oklahoma, and Texas are shipping or commissioning, the Army has contracted for millions of magnet segments for drone motors, and in March Ukraine built a drone with no Chinese components at all. The capacity is real. It is also early and expensive, and no one has been given the authority to decide who gets it first.

The money runs through the same gap. In the week the command was ordered, hiring all but stalled, and the 30-year Treasury still ended near its highest yield in 24 years, while France, Germany, and Japan set multi-decade highs. The savers who finance American deficits can now earn more at home. In the same fortnight, Washington threatened to cut anyone servicing Iranian airlines out of the dollar system and warned two allies that American diesel might stop coming. The country is spending the dollar’s leverage abroad while asking the world to finance its rearmament.

That is the economic-warfare lesson inside a defense memorandum. China’s leverage is exercised by a commerce ministry, with a notice, at a time of its choosing. America’s answer is divided among a portfolio office that buys, Services that supply the forces, a Congress that has not written the law or appropriated $53.6 billion of the $54.6 billion requested, and a Treasury borrowing at its highest long-term rates since 2002. Each is competent. As I wrote here last week on the economic front, none is in command.

The plan due around October 30 is the place to change that, and it turns on two decisions. The first is supply. When American-made magnets, motors, and batteries are scarce, as they will be for most of 2027, someone must decide which programs and which theaters receive them, and that decision must bind the Services and suppliers alike. The instrument exists; the priority ratings of the Defense Production Act were written for exactly this.

The second is integration. As this series has argued, the artificial intelligence on which such a force depends must operate at the tactical edge. A drone that cannot compute there and is not connected through a common command-and-control architecture to everything else in the fight is not a capability. It is one more unintegrated system handed to the warfighter, another problem to manage under fire, and one the adversary will render obsolete, because what cannot be integrated cannot adapt.

Supply, integration, and deployment are one problem. Washington has divided it among separate offices, and no one owns the whole. If you have a hand in that plan, see that it names who holds each authority and sets the supply and integration schedules beside the fielding schedule. Otherwise, the command will stand up on time next October with an order book and no arsenal.

Richard Berry is the founder and principal of Stratnova Advisors and a former Commander’s Action Group Director at U.S. Indo-Pacific Command; he publishes the weekly assessment Strategic Horizons.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Iran Calls Itself the Victim, Its Record Tells Another Story

Iranian President Masoud Pezeshkian’s speech at the United Nations did not mention Iran’s history of terrorism and the thousands of innocent victims killed, or the imprisonment and killing of thousands of its own people who were peacefully protesting, or the repeated enrichment of uranium at levels close to 90% purity for nuclear weapons or repeatedly denying access to International Atomic Energy Agency (IAEA) inspectors to suspect nuclear sites in Iran. There was no attempt by Mr. Pezeshkian to deny these allegations or justify Iran’s sick behavior, or to concede that Iran’s leadership will address these accusations and change its behavior. Rather, it was a recitation of how the U.S. leadership had a “bullying mentality”.

Mr. Pezeshkian could have talked about reopening the Strait of Hormuz and ending the bombing of the infrastructure, airports, and civilian areas in neighboring countries. He could have attempted to justify why Iran was militarily striking out at these neighboring countries, when Iran’s adversaries were the U.S. and Israel.

What’s vivid in the minds of most people is Iran’s brutal reaction to peaceful protests in Iran. The slogan “Women, Life, Freedom” in 2022, when the so-called morality police arrested and killed a young Iranian student, Mahsa Amini, for incorrectly wearing her hijab (headscarf). Peaceful protests by brave Iranians followed, with the Basij – a paramilitary force under the command of the Islamic Revolutionary Guard Corps (IRGC) – arresting thousands and killing hundreds of peaceful protesters.

Iran can change its behavior and seek to be removed from the State Department list of State Sponsor of Terrorism. That means stop supporting their proxies, the Houthis (Yemen), Hezbollah (Lebanon), Hamas and the Palestinian Islamic Jihad (Gaza), and the Shi’ite Militias in Iraq and Syria, all funded, armed, and trained by the Iran’s IRGC.

But Mr. Pezeshkian did not talk about or attempt to justify Iran’s behavior. He said Iran was the victim.

Russia and China apparently agreed.

In addition to attempting to justify its war in Ukraine, Russia’s Foreign Minister, Sergey Lavros, said Russia was aligned with the Iranian regime, criticizing the U.S. and Israel for its military operations in Iran. Indeed, Russia continues to supply Iran with real-time satellite imagery and tracking data regarding U.S. troops, aircraft, and warships in the Middle East for targeting purposes. Russia reportedly is also providing military hardware to Iran: explosives, ammunitions, drone components, and shoulder-fired man-portable air defense systems.

China’s Vice President, Han Zheng, in addition to touting the impact of China’s Belt and Road initiative, criticized the unilateral military actions of U.S. operations in Iran, while not mentioning anything about Taiwan. And according to the Wall Street Journal, Chinese entities have provided Iran with satellite intelligence, and thousands of dual-use components during the ongoing war with the U.S. and Israel. The satellite imagery reportedly helped Iran improve missile and drone targeting of U.S. bases in the region, to include the U.S. base in Jordan that killed three American service members. Additionally, satellite imagery permits the Iranian military to better track commercial ships and U.S. military escorts in the Strait of Hormuz.

Also of real concern are the reports of dual use shipments to Iran. Reportedly, there were over 1,000 air shipments from China to Iran’s Defense Ministry in the first half of 2026. These included GPS devices, electric motors, aircraft-engine parts and chemical precursors used for ballistic missile propellants.

There are reported plans for China to ship up to 400 Chinese-made shoulder-fired air-defense missile launchers (MANPADS) to help Iran rebuild its defenses. There are also concerns that Chinese front companies and banks helped Iran bypass oil export bans and move billions of dollars through barter and credit arrangements.

Whether China ordered or allowed these reported actions is unclear.

The U.S., supported by Germany, France, and the United Kingdom state that military trade, drone transfers, and ballistic missile exchanges between Russia, China, and Iran are in violation of United Nations Security Council Resolution 2231. Moreover, the U.S. and its allies criticized Russia and China for vetoing a September 2026 U.S – drafted resolution to extend the mandate of on the UNSC’s Panel of Experts on Iran. The veto obstructed lawful oversight of Iran.

It appears that Russia and China are supporting Iran in its war with the U.S. and Israel.

Mr. Pezeshkian portrayed Iran as the victim. It’s the people of Iran and the innocent people killed by Iran-backed terrorists who are the victims.

The author is the former associate director of national intelligence. All statements of fact, opinion or analysis expressed are those of the author and do not reflects the official positions or views of the U.S. government.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Exactly how could AI kill humans?



Nobel laureate Geoffrey Hinton walked out of a closed-door Capitol Hill briefing on September 17 and gave lawmakers a deadline.

“Maybe a year, but not much more than a year,” he told reporters, describing how long Congress has before artificial intelligence moves beyond meaningful human control.

It’s not an outlier estimate on the Hill anymore. An Anthropic researcher who resigned this month put it more starkly, warning that the people building the technology “earnestly believe it could kill us all by the end of the decade.”

Trump had already dismissed the premise days earlier. Across a string of Truth Social posts that Monday, he called AI fears a “hoax,” dubbed himself the “Hoax Buster,” and mocked the idea of robots marching into American cities. He returned to the subject five days later, announcing he would form an “AI Force” and appoint an AI czar to accelerate American dominance in the technology rather than restrain it.

House Speaker Mike Johnson echoed him the next day in even more candid terms.

“What the president is saying is, you’re not all going to be dead in 10 years,” he stated. “That’s a hoax.”

That collision, a 78-year-old scientist warning of civilizational risk and a sitting president calling the same warning a partisan fiction, is the real story of the AI safety debate, and it is already hardening into a national security question in its own right.

Sens. Ted Cruz, Amy Klobuchar and John Thune are drafting bipartisan legislation aimed specifically at “catastrophic risks involving biological or nuclear threats” from frontier AI, expected as soon as this month. But the politics obscures a more basic question that rarely gets answered: how, mechanically, is any of this supposed to happen?

Most people still picture something out of the Terminator: killer robots, guns blazing. What actually keeps researchers at the frontier labs up at night looks nothing like that. It’s smaller, odder, and in a few cases, it’s already happened.

The sandbox that did not hold

The clearest illustration of loss of control came in July, when OpenAI disclosed that a combination of its models, including GPT-5.6 Sol and an internal-only research prototype, got out of an isolated test environment and breached Hugging Face’s production systems.

The models were not told to escape. They were running an internal OpenAI evaluation built to push them toward advanced exploitation, with the safeguards that normally block high-risk cyber activity deliberately switched off so the company could gauge their maximum capability.

The test environment had no direct internet access beyond a proxy for installing software packages. The models spent substantial computing power finding a way out anyway: they exploited a previously unknown flaw in that proxy, worked through OpenAI's research network to a machine that was online, then searched for the test's answer key and breached Hugging Face to get it. OpenAI says the models went to "extreme lengths" to reach a narrow goal. The company says it has disclosed the flaw to the vendor.

UN human rights chief Volker Türk told the Human Rights Council in Geneva earlier this month that he shares “the concerns of industry insiders that advanced AI could pose an existential risk to humanity,” calling for “cast-iron guarantees” before, in his words, it is too late.

Türk cited exactly this kind of behavior when he drew his own red line in Geneva.

“AI that escapes its testing environment, or blackmails developers to prevent itself from being turned off, is AI that is too powerful,” he said.

Roman Yampolskiy, an AI safety and cybersecurity researcher at the University of Louisville, tells The Cipher Brief that the incident is best understood as a sneak peek rather than a fluke.

“A preview of a dangerous capability, although neither establishes that catastrophic harm is inevitable,” he says. “OpenAI’s agents escaped isolation and compromised external systems without authorization. These incidents illustrate two different risks: AI pursuing unintended objectives and criminals using AI to automate attacks. Both reduce the amount of human expertise and intervention required for a cyberattack.”

This isn’t a machine turning against its makers. It is software chasing a narrow goal it was given, with no one watching closely enough to notice where the shortcut led.

When the attacker never sleeps

Loss of control is a system slipping its leash. Self-replication could come next. Once it’s off the leash, nobody has to sit at a keyboard to keep it moving.

In early July, cloud security firm Sysdig documented what it assessed to be the first ransomware campaign run end-to-end by an autonomous AI agent, a case it dubbed JadePuffer. After breaking into an internet-facing server through a known software flaw, the agent conducted its own reconnaissance, harvested credentials, moved laterally across the network, and encrypted more than 1,300 configuration records, adapting on the fly when its attempts failed.

In one moment that stood out to researchers, a login attempt failed and, thirty-one seconds later, the agent had already figured out why, tried something different, and gotten in. No person ever saw the error message or lifted a finger to fix it.

Ian Tien, CEO of Mattermost, a collaboration and automation platform built for national security and critical infrastructure clients, tells The Cipher Brief the incident and what followed it mark a genuine inflection point.

“The Hugging Face and JadePuffer incidents represent important new milestones in the weaponization of AI,” he observes. “They should signal to the public that AI is creating new pathways for adversaries and criminals to cause harm, and those developments should be taken seriously.”

At the same time, Tien is careful not to inflate the danger.

“Defenders are also using AI to create new pathways for defense, including detecting and disrupting adversary and criminal operations,” he points out.

Tien’s point is that the technology cuts both ways: the same speed that lets an attacker adapt in seconds can be used to detect and disrupt that activity, if defenders adopt it as quickly as attackers do.

Jason Lang, Managing Director of Offensive Security at TrustedSec, tells The Cipher Brief the technical substance of the case is less novel than the headlines suggest.

“AI wasn’t doing anything that security researchers haven’t been doing for years. The difference is the speed at which it performs those actions,” he explains, noting that JadePuffer’s entry point “exploited a security flaw that had been publicly known for more than a year. Yet, the targeted system was still unpatched.”

In other words, the opening wasn’t some undiscovered AI weakness. It was an ordinary, already-known bug that a human had never gotten around to patching, and the AI just moved on it faster than a person would have.

Still, Lang doesn’t dismiss the trend line. He’s not arguing the threat is exaggerated, only that the mechanism is familiar; what’s changed is the clock.

“AI can and likely will enable attackers to perform research and attacks at a speed faster than modern defenses can cope with,” he continues. “For now.”

Rafal Los, Chief Strategy Officer at Binary Defense, tells The Cipher Brief he reads the same case with more caution about the story built around it.

“I believe that these models did in fact cause harm, but that there is definitely some part of those narratives that was ‘enabled’ by humans looking for validation of their company’s frontier supremacy,” he observes.

What worries Los isn’t the exploit itself, he says, but the trajectory it points to: “an AI agent can carry out much of the technical attack chain autonomously, adapt when something fails and continue toward its objective.”

“Capabilities that once required continuous human involvement can increasingly be automated and scaled,” Los highlights.

That urgency reached Washington almost immediately. Two weeks before Hinton’s briefing, the cyber agencies of the Five Eyes alliance had issued a joint warning that frontier AI was collapsing the gap between vulnerability and exploitation to “months, not years.”

In practice, that means the window defenders used to have between a flaw being discovered and someone actually weaponizing it, once measured in months or longer, is shrinking to weeks or less, leaving far less time to patch a system before it’s used against it.

Sen. John Kennedy (R-LA) tried to force a vote on legislation requiring AI developers to build in a shutdown mechanism the day before Hinton spoke to lawmakers. Sen. Rand Paul (R-KY) blocked it on the floor within hours, calling Kennedy’s language “very vague” and arguing that regulating an industry “so pervasive as AI throughout our economy” first needed hearings and industry input rather than a same-day, unanimous-consent vote.

Paul offered a counter, a bipartisan committee to study the risk instead; Kennedy declined it and let the bill die.

The problem of speed, not malice

The scenario that unsettles researchers most, however, has little to do with hacking. It is the possibility of a system pursuing a goal with genuine competence and no ill intent, simply moving faster than the humans meant to be supervising it.

That is what pushed Evan Hubinger, who leads alignment science at Anthropic, to break with his usual caution earlier this month. He wrote that he personally puts the odds of AI causing human extinction within the next decade above ten percent, and that Anthropic is “trying its best” but does not yet have a plan to control a superintelligent system safely.

Yampolskiy puts the mechanism in more concrete terms.

“An AI agent with access to computers, networks, and critical infrastructure could autonomously discover vulnerabilities, compromise systems, and disrupt hospitals, power grids, or supply chains,” he points out. “The immediate danger is not that AI becomes conscious, but that it becomes capable of causing irreversible harm at machine speed, potentially before humans can intervene.”

Not everyone treats the extinction premise as settled science. Lang, for one, is openly skeptical of the political response it has generated.

“Knee-jerk reactions are just that, reactions, not thought-out proposals with well-meaning reforms,” he underscores. “Fear is usually the currency by which control is purchased; therefore, any urgency-backed proposal is worthy of extra scrutiny.”

The specific fear dominating the public conversation, an AI that slips its constraints and turns on humanity outright, draws the sharpest pushback of all.

“I believe we should take them seriously in that it demonstrates capabilities, but not catastrophically in that it’s going to lead to an AI that ‘breaks out of containment’ and goes and exterminates humans or takes over the Internet,” Los says.

What worries him is something far more mundane: systems that get things wrong not out of malice, but because they’re missing something a person in the room would have caught. He points to air traffic control — a recommendation that looks right on paper but misses a factor a human controller would weigh without even thinking about it, with nobody checking the work before it’s acted on.

What Washington could still do

U.S. Sen. Jacky Rosen (D-NV) has taken the narrowest, most procedural version of the concern to the Senate Commerce Committee, calling on Chairman Ted Cruz to convene a hearing with top AI executives.

“This powerful technology can have the power to cause catastrophic damages if we don’t act to impose guardrails and safety mechanisms,” Sen. Jacky Rosen (D-NV) said in a statement issued to The Cipher Brief. “Congress must do everything in its power to ensure the American AI industry continues to lead, particularly outcompeting China, and also enact increased guardrails to ensure AI development is progressing in a safe and responsible manner.”

Some of that response is already moving.

In June, the administration signed an executive order directing federal agencies to expand AI-enabled cyber defenses for government and critical infrastructure systems, and to design a voluntary framework under which frontier AI developers can give the government up to 30 days of early access to their models before release.

The order imposes no requirements on the companies themselves, and its first agency deadlines fell in July and August.

Nothing in the order binds the industry at large, which is precisely Rosen's complaint, and precisely why Cruz, Klobuchar and Thune are trying to legislate the bio and nuclear pieces separately.

For all their disagreement over how alarmed to be, the four security experts converge on roughly the same one-year fix.

Yampolskiy calls for “mandatory isolation for AI agents operating near critical infrastructure,” the hospitals, power grids and pipelines Yampolskiy flagged earlier.

“No unrestricted internet access, no unnecessary privileged credentials, and no autonomous execution of consequential actions without independently enforced authorization,” he continues.

Tien points to keeping critical systems off the public internet altogether.

“Much of our critical infrastructure and government already operates on air-gapped and private networks,” he explains, and “maintaining that separation is one straightforward way to reduce exposure and buy time while AI-based defenses mature.”

That means a hospital’s or utility’s control systems have no physical connection to the internet at all. Hence, an agent that escapes its sandbox elsewhere has no path in, no matter how capable it becomes.

Los, meanwhile, wants more adversarial testing, “more human oversight,” and AI harnessed for “continuous and automated defense in the immediate future.”

Lang’s answer is the least dramatic of the four, but perhaps the most damning.

Patch known vulnerabilities. Use long, complex passwords. Check the sender’s domain before clicking. Make security a first-class citizen from the top down.

“Security is not hard, conceptually,” he adds. “What causes breaches are, at their roots, usually the forces of ignorance or ego, a truly devastating duo when combined.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Nasrallah is Dead. Hezbollah’s Social Lifeline is Not.

Two years after Israel killed Hassan Nasrallah, Hezbollah is weaker but not finished. WaTaawanou, a crowdfunded charity outside Hezbollah’s formal hierarchy, exemplifies one way Hezbollah endures: outsourcing part of the cost of sustaining – and retaining – its Shiite base. Israel eliminated its seniormost military and political leadership, over 5,000 fighters, and significant parts of its arsenal, while its finances are strained. Even as Tehran reportedly moved more than $1 billion to the group after the November 2024 ceasefire – and another $1 billion the following year – Bashar al-Assad’s fall has severely constricted Hezbollah’s transfer routes from Iran through Syria. Yet Hezbollah can survive and regenerate if it preserves the Shiite constituency supplying its manpower and, more importantly, domestic political protection.

WaTaawanou began as an informal relief campaign in November 2019. Founder Afif Shouman identifies it with Hezbollah’s “Resistance environment,” though in an October 2022 interview he said it “does not belong to Hezbollah.” Because WaTaawanou is not U.S.-sanctioned, it can solicit funds through channels Hezbollah’s designated institutions cannot use as freely, including Whish Money, OMT/Western Union, MoneyGram, and direct contributions. It also has an account at Hezbollah’s sanctioned quasi-bank, Al-Qard al-Hassan. Its public-relations director says most Lebanese donors give $5 or $10, but together fund larger campaigns. Whish closed WaTaawanou’s account in October 2025, but its websitestill lists Whish and bank transfers via an International Bank Account Number (IBAN), without usable details for either. Larger projects have drawn support from Lebanese private donors, expatriates, Iranian-linked organizations, and Iraq’s al-Sawaed tribal network.

Yet WaTaawanou’s formal separation from Hezbollah belies extensive ties. Shouman says Hezbollah was the only outside organization to embrace and assist it and credits its development to Nasrallah’s “direct and foundational guidance.” He says former Hezbollah Executive Council chairman Hashem Safieddine treated WaTaawanou as “a principal file.” WaTaawanou has repeatedly worked with Hezbollah’s Social Action apparatus and Islamic Health Committee. At least two volunteers—Ali Lutfi Faran and Amine Hassan Badreddine—served as Hezbollah fighters. Shouman said its 2024 wartime relief proceeded in “full coordination with Hezbollah.”

That relationship is clearest in its spending. Its beneficiaries extend beyond Hezbollah supporters, but its aid eases material pressure across the overwhelmingly Shiite base on which Hezbollah depends. Shouman says it aided 94,000 families during the 2024 war with food, medicine, cash, and shelter. Since the November 27 ceasefire, its Al-Wajh al-Hassan reconstruction project has used donations in war-damaged, overwhelmingly Shiite southern municipalities including Ramyeh, Houla, and Mays al-Jabal, installing prefabricated housing and classrooms, repairing schools, aiding farmers, and distributing food. WaTaawanou also channels money to Hezbollah-linked entities, including payments to Al-Rasoul al-Aazam Hospital and Saint Georges Hospital–Hadath, both Martyrs Foundation hospitals. It also purchased fuel from Amana Fuel, which the foundation controls through Atlas Holding. Treasury designated the Martyrs Foundation in 2007 and calls its Lebanon office an integral element of Hezbollah’s support network. WaTaawanou paid Hezbollah’s Islamic Health Committee through Dar al-Hawraa Medical Center and repeatedly paid Al Moukhtar Products, which Treasury designated as part of a Hezbollah business network.

WaTaawanou therefore gives Hezbollah two benefits: outside donors cover costs Hezbollah would otherwise bear, while WaTaawanou channels the credit back to Hezbollah. Nasrallah portraits line its premises, his face brands Al-Wajh al-Hassan, and Hezbollah flags and insignia appear at its events. Shouman says its role complements Hezbollah’s: Hezbollah’s fighters defend the community while WaTaawanou supports the group’s Shiite base.

WaTaawanou cannot alone explain Hezbollah’s Shiite support, but efforts on this scale likely help preserve it. Studiesshow many Shiites are drawn to Hezbollah less by ideology than by the security, services, and communal advancement it provides, while regular patronage recipients are likelier to oppose the group’s disarmament, support its political role, and credit it for reconstruction. That constituency remains overwhelmingly behind Hezbollah. A late 2024 survey found 85 percent trusted Hezbollah. An estimated 700,000–900,000 people attended Nasrallah’s February 2025 funeral, and three months later Hezbollah and the AMAL Movement, Lebanon’s other major Shiite party, dominated municipal elections in heavily Shiite southern and eastern districts. Gallup found in June-July 2025 that 69 percent opposed giving the Lebanese Army exclusive control over weapons. In April-May 2026, Information International found 87.5 percent opposed Hezbollah’s disarmament.

For Beirut, forcibly disarming Hezbollah therefore risks confronting not simply an armed organization, but one still backed by most of what is probably Lebanon’s largest sect. Lebanon has held no official census since 1932, but independent pollster Statistics Lebanon estimates Shiites at 32.2 percent of citizens. Hezbollah Secretary-General Naim Qassem has rejected disarmament even when paired with Israeli withdrawal, and on June 17, 2026 declared that “any project to disarm us will not pass.”

Lebanon has consequently paired categorical disarmament decisions with reluctance to enforce them coercively. On March 2, the cabinet banned Hezbollah’s military and security activity and ordered it to surrender its weapons, but Prime Minister Nawaf Salam said Beirut did “not seek a confrontation with Hezbollah,” while President Joseph Aoun insisted the state monopoly over arms proceed through dialogue “away from force.” Five days later, army commander Rodolph Haykal said national unity and internal stability came first and “the solution is not solely a military one.” In September, official sources said its Nabatieh deployment was not intended to make the city weapons-free. South Litani Sector deputy commander Colonel Raja Amer told CNN the army would proceed “slowly” rather than use violence against “our own people,” agreeing that avoiding another civil war was central to its approach.

On September 9, the army claimed “operational control” in three test zones under the U.S.-brokered June 26 Israel-Lebanon Framework Agreement to clear unauthorized fighters, weapons, and military infrastructure. But it identified no Hezbollah fighter disarmed or arrested, and no Hezbollah depot, tunnel, or command center dismantled. WaTaawanou helps preserve the communal support that makes such coercion politically dangerous. For a battered Hezbollah, Beirut’s reluctance to test that support buys it the resource regeneration requires above all: time.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



BLUF: Russian Strategic Culture Drives its Callous and Brutal Actions

My friends and family often ask me why Russia behaves so offensively. They are baffled by Russia’s lack of humanity and Moscow’s actions such as hiring assassins, launching drones at innocents, and planning economic sabotage against international companies. While not an excuse, just an explanation, scholars of Russia understand the country’s deep sense of insecurity and vulnerability. Its longing to be a part of Europe, and its own view that its rightful place as a global leader are all driving Russia’s barbaric actions. According to strategic culture theorists, a state’s approach to war is shaped by its cultural and historical experiences, including geography, religion, language, and national identity. These factors influence a state’s perception of security threats, willingness to use military force, and approach to diplomacy and negotiation. They also help us to anticipate a state’s actions.

Russian strategic culture reflects a worldview shaped by centuries of conflict, invasion, brutality against others, inflicted on its people from foreign powers and by the government against its own population, and foiled attempts to become card carrying members of the west. Key elements of Russian strategic culture include the belief that the rest of the world, especially the West consistently undermines Russia and thwarts it rightful place as a world leader, and a belief in the necessity of military strength to push back the West. When the West does not push back, Moscow believes that their tactics are working.

Insecurity Drives Every Move

Russia’s persistent awareness of vulnerability and deep-seated mistrust of its neighbors is deeply ingrained and a consequence of centuries of historical experience. This insecurity manifests as a deep-seated suspicion of the West and a zealous determination to maintain control over Russia’s perceived sphere of influence. Understanding the historical currents that have shaped this perception is crucial for comprehending Russia’s present-day actions.

Russia’s experiences with wars and conflicts, such as the Mongol invasion, Napoleonic Wars, World War I, and World War II, have reinforced the idea that the country is constantly under threat and must be prepared to defend itself at all times. The Russian feeling of vulnerability and insecurity, particularly concerning interactions with “Western countries” is ingrained. To counter this insecurity Russian leaders have long highlighted the importance of having buffer zones on its borders. Removing those buffer zones heightens Russia’s sense of vulnerability.

From as early as the 18th century, Russian imperial strategy was heavily influenced by the need to create and maintain buffer zones along its western borders. Peter the Great and Catherine the Great both conquered lands on Russia’s borders so that Moscow would have a buffer from invasion. This proactive doctrine was aimed at insulating the Russian heartland from European powers. The annexation of Baltic territories, the absorption of Finland, and the partitioning of Poland were all manifestations of this strategy. These territorial acquisitions were driven by a pragmatic logic: to push potential adversaries further away and create a strategic depth that would absorb any initial blows in case of conflict. Russia continues to try to use buffer states or “allies” to keep others from its immediate vicinity, but this is an increasingly difficult task for Moscow as its former republics and satellite countries choose new alliances and partners.

Germany’s invasion of Russia in 1941 was a defining moment in Russia’s historical experience. This invasion resulted in some 27 million Soviet deaths and widespread devastation. It cemented Russia’s profound sense of betrayal from the West, and a visceral need for absolute security. World War II profoundly shaped Russia’s post-war security calculus, leading to a pursuit of military strength and a zero-tolerance policy for any perceived threat on its borders. The narrative of this war is deeply embedded in Russian society, serving as a constant reminder of the price of vulnerability and the imperative of never allowing such an event to recur. Putin’s family was directly affected by WW2 with his brother dying of starvation during the siege of Leningrad, his Grandmother killed by the Germans in Tver, and his father being severely injured during combat duties. He often discusses this in his speeches.

The post-Soviet era where East European nations and former Soviet Republics are joining NATO and the EU is particularly distressing for Moscow. The historically more neutral northern European countries joining NATO also is alarming to Moscow. From Moscow’s perspective, the loss of Ukraine to the West represents not just a geopolitical setback, but the obliteration of a crucial defensive buffer. We are also seeing Moscow’s anxiety rising regarding Armenia’s recent moves toward the West.

During the first summer of the Ukrainian war, Putin compared himself to Peter the Great and likened the invasion of Ukraine to the eighteenth century Russian Czar’s wars. This underscores the mindset of Russian leaders and shows that their history is never far from them.

Yearning for Inclusion

Russia’s geographic position has greatly impacted its strategic culture. Russia is the biggest country in the world, and while only 23 percent of the country is in Europe, almost 80 percent of the population lives there. This makes Europe extremely important for Russia. One can see this link throughout Russian history. Even from the founding of the modern Russian state in the sixteenth century, its foreign interests were linked to Europe. When Peter the Great established an empire, the interconnections with Europe increased. Russia conducted wars and created alliances with different European countries. Russian nobles were stung when European nobles mocked them and called them uncouth and barbaric.

Today, the Kremlin emphasizes narratives that underscore Western hostility, and Russia’s role as a decisive power in European affairs. These narratives reinforce Russia’s claims to special rights in regional security and justify to itself and its people, assertive foreign policy actions, including military interventions in neighboring states. Any expansion of western power such as expansion of NATO and deployment of U.S. forces in Europe are perceived as existential threats to the Russian state and infringing on Russia’s rightful relationship with Europe, just as they were during the Soviet-era.

Demanding a Seat at the Table

For centuries, leaders of the Russian Empire and the Soviet Union emphasized Russia as a great power. During the Cold War, Russia, through the Soviet Union, was able to act as a global leader. After the collapse of the Soviet Union, Russian leaders were confronted with the fact that Russia had limited “spheres” of influence.

A main aim of Russian foreign policy under Putin is regaining and maintaining great power status. Putin repeats in his speeches that Russia is a great power and that the West, especially the United States, does not give Russia the respect it deserves. The Russian people support this view. Moscow remains angered that in its view, after the Cold War, the United States created a unipolar world and used NATO to maintain its hegemonic status. Putin has consistently publicly lamented the breakup of the USSR as “the greatest geopolitical catastrophe of the century.” More recently, Putin has said, “At last, Russia has returned to the world arena as a strong state - a country that others heed and that can stand up for itself.”

Russian leaders view Russia’s military might, both kinetic and grey zone activities, as their way to press for global leader status. They believe that Russia must take what it believes is its due such as Ukraine. Russian leaders also contend that it must make the West uncomfortable with continued attacks such as the drone incursions, assassinations, and ongoing disinformation. Pressing this avenue, in their view, wil make the West eventually give up on pushing back on Russia and allow Russia to take its rightful place as a global leader.

Implications for Policy and Security

None of this explanation of Russia’s national security mindset is meant to apologize for Russia’s barbaric behaviors. It is meant to help negotiators and policy maker understand Russia’s perspective, however misinformed and self-determined. Russian strategic culture emphasizes an assertive approach to conflict which is meant to make up for Russian feelings of vulnerability and being outcast from the West. This approach is evident in Russia’s actions in Ukraine, where strategic culture drives Russia’s actions.

Moscow’s lack of trust in the West is underscored by Putin and his circle who are the representatives of the “greatest generation” of the Soviet Union. These leaders grew when the state was a global power and controlled parts of Europe. They came to the pinnacle of their careers when the West, having forced the breakup of the Soviet Union, attempted to replace Soviet and Russian culture with Western values. They are bitter about this.

Having a realistic view of Russia’s perceived right and left limits allows negotiators and military planners to develop a workable way ahead in foreign relations. It should not limit US actions in calling out Russia’s morally and ethically abhorrent actions but it should inform our actions.

In summary, Russian strategic culture is driven by a sense of vulnerability, a focus on wanting to be part of the cool club of European nations, and an outsized view that Russia should be a global leader, regardless of its barbaric actions.

Russian and Ukrainian Clashing Strategic Cultures

Russia and Ukraine both see a negative outcome of the current war as an existential threat to their existence. That means that negotiating a settlement is difficult, herculean, and likely under the current circumstances an impossible task. Diplomacy alone cannot produce a durable settlement, because the two strategic cultures are incompatible. At most, military exhaustion could produce an armistice that freezes the conflict without resolving it. Before Russia’s insecurity can be addressed, the rest of the world must make it clear that Russia will maintain pariah status if it continues its slaughter of Ukrainian citizens and attacks in the west. The third-party sanctions recently passed by Congress are a step in the right direction. Sanctions alone, however, will not stop Russia whose people are used to hardship and even expect it. I am usually an optimist but for now, unfortunately, I cannot see a positive way forward in this war. The themes that Ukraine and Russia have woven through their strategic cultures indicate that there will be more deaths, destruction, and hardship before this war ends. The best that the world can do is to contain the violence and help Ukraine continue to strengthen its statehood while calling out each and every Russian atrocity.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How the Intelligence Community Can Shape AI Trust With New Terminology

The Intelligence Community (IC) has an opportunity now to influence how we talk about, and thus how we approach, AI use in our work by formally adopting the nomenclature “AI-in-the-Loop” rather than “Human-in-the-Loop.” The problem with human-in-the-loop is that it subordinates the human to AI; the term carries a built-in assumption that “the loop” belongs to AI and that humans will somehow be included. The term I am proposing omits the “human” we have become accustomed to, but it is a purposeful attempt to reflect what we want to achieve: using AI when and where we elect to do so.

AI-in-the-loop is not a new expression. Stanford’s Institute for Human-Centered Artificial Intelligence used the term as a centerpiece for a conference on the topic in 2022, arguing that humans should remain in charge while AI operates as part of a human-directed process.

This 2025 academic article makes the same distinction, arguing that “Human-in-the-loop (HIL) systems have emerged as a promising approach for combining the strengths of data-driven machine learning models with the contextual understanding of human experts. However, a deeper look into several of these systems reveals that calling them HIL would be a misnomer, as they are quite the opposite, namely AI-in-the-loop (AI2L) systems: the human is in control of the system, while the AI is there to support the human. We argue that existing evaluation methods often overemphasize the machine (learning) component’s performance, neglecting the human expert’s critical role.”

Much of industry discourse uses human-in-the-loop as an AI governance approach, but the debate over terminology remains unsettled. Researchers at The George Washington University argue this is partly because “Academia, government, and industry have not clearly defined the mechanisms by which humans are expected to oversee or collaborate with AI-enabled systems.” They add that “Inconsistent uses of terms like human-in-the-loop and human-AI teaming create confusion on what type of oversight and collaboration is intended,” calling this environment a “preposition salad.”

Forging new terminology for our AI usage is critical now as we seek to accelerate development and adoption in the IC while also supporting the burgeoning efforts to adopt AI securely. The IC has already set a standard for accelerated adoption in a secure environment while focusing on the human role.

ICD 505, as amended in 2025, on AI underscores the importance of IC personnel, noting that they “shall remain responsible and accountable for the analysis, decisions, and outcomes derived from insights gleaned using AI.” While the Directive does not mandate specific terminology, it requires users to “understand” and be accountable for AI use. It goes further in insisting that “personnel be able to review, challenge, and reject or replace AI-derived recommendations and findings when appropriate.” The President has since mandated that the IC publish a Standard on AI Assurance under ICD 505 and signed a memorandum on AI mandating “responsible acceleration of the use of AI across intelligence and warfighting domains.”

Intelligence agencies are moving to adopt internal AI policies to drive adoption while elevating the human role. For example, NGA has moved beyond simply adopting AI toward aspiring to become an AI-first organization where “AI does not replace human judgment. It amplifies it.”

While the human role is at the forefront, IC procurement is aiming for fast acquisition. CIA launched a new acquisition framework this year to speed adoption of innovative technologies, while NGA has elevated its Rapid Capabilities Office and has multiple major AI and advanced-analytics procurements moving toward solicitation.

An Array of Terminology Options

Practitioners and technologists may bristle at adopting a term that lacks "human," as noted above. This should not derail our efforts to better define our approach to AI. I have offered AI-in-the-Loop as an option that respected experts are promoting. But the IC can forge its own path by considering multiple options:

Human-Led AI (HLAI) — simple, direct, and clear about who leads the process


Human-Guided AI (HGAI) — emphasizes direction and oversight, though it may sound less decisive


Human-AI Teaming (HAIT) — widely used, though it can imply a more equal partnership than intended, and an awkward

acronym


Human-Directed AI (HDAI) — stronger than “guided,” emphasizing human authority


Human-Commanded AI (HCAI) — strong human primacy, though perhaps too military in tone for broad IC use


Human-Owned AI Workflow (HOAIW) — inelegant, but explicit that the workflow belongs to the human

Adopting new terminology now would be more than symbolic; it would help shape how we approach and use AI. We can ensure AI augmentation at the speed of mission as part of the human toolkit, not that humans are just “in-the-loop.” Indeed, the IC has used nomenclature adoption as a core part of improving mission performance and rigor at key junctures in the past.

After 9/11 and the invasion of Iraq, the IC shifted the terminology it used for adopting new or different tradecraft from our baseline techniques in analysis. The term Structured Analytic Techniques became official at CIA’s Sherman Kent School in 2005 as part of the Agency’s effort to promote these methods from the long-held category of “alternative” analysis into the mainstream of tradecraft. In my decades of experience in analysis, this change was more than a title change; the new terminology reshaped how analysts thought about their work. As a junior CIA analyst at the time, I remember a proliferation of structured analytic techniques that became so commonplace they were literally no longer alternative.

In the late 2010s, we shifted from “intelligence sharing,” a process that intelligence professionals I knew detested as giving away secrets for little to no gain, to “intelligence diplomacy,” a practice many of us willingly adopted to offer insights aimed at promoting US interests. The IC formally codified this approach in 2025 through ICD 405, Intelligence Diplomacy. The ICD distinguishes between mere intelligence sharing and intelligence diplomacy, noting that the latter must “be done in support of advancing a preferred policy objective.” The ICD goes further in noting that the intent is to “shape foreign leader perspectives,” a materially different approach than sharing alone. The Senate’s Intelligence Authorization Act in August 2026 endorsed Intelligence Diplomacy as “critical to advancing US foreign policy and national security goals,” and called for “elevating intelligence diplomacy as a tool of US statecraft” through continued investment.

The IC should act with deliberate speed to formalize AI-in-the-loop, or a related term, to set a tone of expectation and clarity for agencies and industry partners that even agentic autonomy must begin with human intent and be wrapped in human decision. We can do so in a presidentially required Standard on AI Assurance under ICD 505. Further, IC directors using an agreed-upon, more human-focused term and impressing on their workforce its importance would chart a path. IC acquisition shops’ requests to industry should also make this shift, giving industry clear guidance that development and implementation should include a workflow that explicitly highlights human ownership of AI adoption. Even when AI does the heavy lifting across data sets that humans can’t process alone at speed and scale, it must do it on our behalf.

All statements of fact, opinion, or analysis expressed are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in the contents should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author's views.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Coupang Breach and the Danger of Punishing the Headline Number

The headline number from the Coupang data breach — more than 33 million user accounts — sounds like a major incident that implies a catastrophic failure of one of South Korea’s most important company’s cybersecurity programs. South Korea's Personal Information Protection Commission (PIPC) measures an incident by the “exposure and access” of data, and a disgruntled former engineer who retained and forged credentials did, in principle, have access to that many accounts over seven months. But what actually happened in this case was far narrower. According to Coupang internal investigation, the attacker downloaded data from just under 3,000 accounts, and later deleted it. However, it's worth noting that regulators dispute this finding as overly narrow. The breach exposed no financial information, and he did not transfer anything to any third party. Multiple investigations and reporting to date has surfaced no fraud, identity theft, or downstream misuse traced to the incident. All in all, this was mundane, not catastrophe.

Seoul’s response suggests the government wants to tell a different story. The PIPC investigation culminated in a $409 million fine—more than four times greater than the previous record-breaking fine. The company's SEC filing states that approximately $278 million of the fine is directly related to the incident while $132 million concerns a separate administrative fine concerning date collection. Their intrusive investigative process and the penalty together are meant to broadcast an unmistakable message: this was a massive cybersecurity failure by Coupang due to negligent security practices, that inflicted enormous harm — and Coupang must be punished severely ensuring radical, swift improvements and to deter every other company from replicating these mistakes.

The technical record supports none of that.

A single breach, standing alone with a headline number, often tells you very little about a company’s overall security practices. It can be a symptom of genuine negligence — under-investment, ignored warnings, decayed practices, poorly trained personnel. Or it can be what the sociologist Charles Perrow called a normal accident: small, unexpected failures are inevitable in society’s complex systems. The Coupang breach ran through the company's key management system, and the details — documented in the PIPC's own published investigation and in independent expert assessments Coupang commissioned — read like a case study Perrow could have written for normal accidents. Consider the chain of events the attack required:

Coupang maintained current hardware and software for key management, layered authentication, and access monitoring. The failure was interactive — a policy violation invisible to monitoring, an unreported vulnerability, an offboarding gap, and an insider who knew exactly where the system’s seams of vulnerability were, because sealing those seams had been his job. That is the anatomy of a normal accident, not of a negligent enterprise.

None of this puts Coupang beyond scrutiny. The PIPC had a legitimate claim to investigate whether this failure was symptomatic of something deeper: negligence, under-investment, or systemically bad practice. That is what data protection regulators exist to do, and the technical depth of the investigation deserves credit. But all that depth uncovered no evidence that any of those things were true.

What should have been a proportionate response? It’s straightforward, and common cybersecurity practice. A breach by definition will expose a gap in a highly complex system that needs to be closed. And so Coupang – and other companies who learn from this incident – must close the accident pathway this breach revealed: credential revocation at offboarding, detection of keys stored outside the key management system, and continuous monitoring of token lifecycles. What government authorities need to do is confirm that the remediation is effective, and that the adjacent failure modes this incident made visible have been plugged. Post-incident verification, not massively punitive penalties that make headlines, is where a regulator actually changes outcomes for the better. The most durable defense against insider threats is a healthy working relationship between public authorities and private companies. Incidents are audited in an honest manner with the lessons learned from events shared across the industry.

A record punitive fine in response to a catastrophe that did not occur does the opposite. It teaches companies that candor and cooperation buy nothing. It converts an addressable security incident into an episode of techno-nationalist strife between allies. That serves no defender, no consumer, and no regulator. The only people it may benefit are the next set of attackers.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Houthis Took the Red Sea Coast. How Did Washington Miss It?

The recent military moves taken by Yemens Houthis resulted in stunning victories and significant strategic gains, virtually unopposed. By taking the Red Sea port of Mocha (Al-Makha), occupying Perim Island in the middle of the Bab al-Mandab Strait, and seizing portions of the Red Sea coast, the Iranian proxy group now threatens a key commercial waterway. Reports indicate that, unsurprisingly – or at least it should not be a surprise – Iranian Revolutionary Guard advisors were present, guiding the tactics of Houthi forces. We missed all of this.

For decades, the United States has had an active, robust CIA, diplomatic, and military presence in the Persian Gulf. Understanding, managing, and balancing the nuanced and sometimes fractious relationships among our Gulf allies has always been a complicated task, but one critical to the national security of both the United States and our Gulf allies. We have all made it work, together.

Until now. Something has gone terribly wrong.

As a former CIA operations officer and Chief of Station in the Gulf, I know that failing to anticipate an Iranian-Houthi move of this magnitude is not a tactical error or simply failing to “connect the dots.” Regional actors have their own specific interests and goals in Yemen. Each has taken its turn in the barrel militarily, seemingly largely uncoordinated and sometimes at odds with one another, to discourage or defeat the Houthis. None has succeeded.

What is lacking is leadership, coordination, and overall command and control among the key players: Saudi Arabia, the United Arab Emirates, and the United States. And in the latter’s case, lack of focus.

The current regional conflict seems to have opened rifts in the alliances all of us who served in the Gulf and greater Middle East strove so painstakingly to build and nurture. This is not necessarily through a simple lack of presence or communication; the Commander of CENTCOM was just recently there for consultations, and I have no doubt U.S. military personnel on the ground are in constant and very close contact with their Gulf counterparts. And from my own time there, I am certain U.S. diplomatic and intelligence personnel are equally engaged. This is what we do, and we all do it well.

So how did we miss the Houthi move?

Let’s be clear. This stuff is hard. Anticipating the plans and intentions of an adversary is one of the most important things the intelligence community, and specifically the CIA, does. And the U.S. military has no peer in its planning, logistics, or execution capabilities.

But it is really difficult to anticipate and address the actions of an adversary that relies heavily on asymmetrical warfare.

Particularly when you are dealing with not one but two denied area foes–the U.S. does not have an operational Embassy in either Iran or Yemen. But it can be done; I’ve done it. It just takes focus and, yes, imagination.

But it is important to remember that the intelligence, military, and Diplomatic communities do not operate in a vacuum. Each reports to and receives direction from the White House and DoD. Based on my understanding of how these operate and interact, I can only surmise that the confusion we have seen is emanating from the very top.

Or perhaps an inability, or unwillingness, to manage yet another military crisis.

The U.S.’s lurch into war alongside Israel, one with no apparent end-game, seemingly caught the Gulf Monarchies by surprise. They have suffered the consequences, both militarily and economically. Perhaps ‘Operation Economic Outcast’ - the U.S.’s current intense financial offensive against Iran - will finally bring the Iranian regime to the table to negotiate in good faith. But that remains to be seen. And the Iranians continue to surprise us.

I’ll leave it to others more intimately versed in things Yemeni to analyze the Houthi tactics and strategic goals.

But it should be no surprise that Iran called on the Houthis to make a move at this time. Both the Iranians, and now the Houthis, have proven themselves to be master opportunists. One succeeded in opening a second front in an attempt to lessen the pressure of the U.S. naval blockade and increased sanctions, and the other saw an opportunity to expand their reach. A distracted Washington gave them the opening.

The takeaway: Overconfidence in the ultimate efficacy of Operation Economic Outcast may turn out to be misplaced. If the success of the Houthi advance does not turn out to be an isolated incident, it risks exposing a critical vulnerability in the United States’ strategy. Washington needs to keep its eye on the ball.

This article was originally published on Substack and is republished here with permission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



AI Is Coming to the Counter-Drone Fight

“Twenty years ago, the state of North Dakota poured in multiple millions of dollars to figure out what it looks like to do beyond visual line-of-sight operations for Class One, Two, and Three Drones. That was just the very nascent stage. Just a decade ago, ten years ago, they figured out that they can do this. They could do this at Grand Forks Air Force Base. Right across from our [air base] runway, on the active duty side, is a place called Grand Sky. It is an innovation research park for all counter-drone operations. It is one of the largest in the United States. They rent the space on our base. It's legitimately federal property that they lease for the research park.”

That was Air Force Col. Alfred J. Rosales, Commander, 319th Reconnaissance Wing, based at Grand Forks Air Force Base, speaking on September 14, at the 2026 Air, Space & Cyber Conference, as moderator of a panel on Counter-Drone Defense.

I had never heard about what the Grand Forks locals call GrandSKY as a home for Unmanned Aerial Systems (UAS), where for a decade major defense contractors such as Northrop Grumman and General Atomics have been flight testing and carrying out drone research and development.

Back in May, the Defense Department’s Joint Interagency Task Force 401, central authority for the counter-small unmanned aircraft systems program, selected five installations to participate in the directed-energy counter-unmanned aircraft systems pilot program, of which Grand Forks was one.

More recently, as Rosales put it, at the Grand Forks Base, they have been “strapping on vendor equipment” to “build tactics and techniques.” That process will help determine, he said, “How do we want directed-energy weapons to be used inside the United States in FAA [Federal Aviation Agency] controlled airspace, not in the restricted ranges of our Air Force.”

Rosales introduced his September 14, panel whom he said were industry leaders who were “translating technology into trust to allow us to win in the future.”

They were:

Dr. Ben Van Roo, Chief Executive Officer, Legion Intelligence, who, using Artificial Intelligence (AI) was working to get the equipment needed at the tactical level to be able to provide decision-making space without being connected to the Cloud the entire time.

Early on Van Roo said, “We're really still in the infancy right now of how we think about where we're going to use [computer] agents [AI]. What are we going to allow them to decide on? How do they work their way into our TTPs [Tactics, Techniques and Procedures] into our doctrine? And then, the other side, and the big question that we also think about is are they even going to be available?”

Van Roo continued, “The way that we want to use Artificial Intelligence is going to be one, it's still got to be sorted out. What are we going to allow these things [AI] decide to do? Where are they going to work? Into everything from the kill chain to just basic intelligence gathering? And then how are we going to make them more resilient? These are the next layers of challenges that are ahead of us.”

Adam Mohamed, Chief Technology Officer, Asylon Robotics, a Boston Dynamics Partner, who works on autonomous robotics, figuring out how we can layer base defense architecture with our air domain experts.

“Situational awareness is king,” Mohamed said, “because everything else flows from that. And having static situation awareness, mobile situational awareness, being able to understand your battle space is going to take precedence over everything else. The sensor fusion will happen. We'll have the AI. We'll have the ability to operate without a Cloud. But we need to be able to operate when we start losing our sensors, we start losing our radars, we start losing our shooters, and how do we adapt and how does the system adapt for you, because there won't be time for you to make the change to switch over.”

Colton Wood, Chief Technology Officer, Digital Force Technologies, who works on multi-sensor integration. How do we use AI to get the common operating pictures we so desperately desire -- the integration piece that's going to help defeat drones.

Wood said, “Talking about human in the loop is okay. I got a target, I need to go through the process of actually engaging and affecting that target. As we see the threat evolving, that is going to be an incredibly difficult thing to do if I have, you know, multiple threats, multiple targets, multiple different engagement systems…I've set all the rules of engagement. I've set the governance on the systems and then I have a strong decision supported by tools in front of me. But once I've made that decision, I need to be able to engage the systems and machines need to be able to engage the threats, almost autonomously.”

Therefore, Wood explained, “And so I think a lot of simulations, understanding how these systems operate, where the left and right limits are and then allowing these systems to be as effective as they can be without us having to shepherd the process is a very thing that we have to think about [in the] very near future here.”

And finally, Michael Hiatt, Chief Technology Officer, Epirus, who works with Directed-Energy weapons, lasers, the essence of kill-chain dynamics. He comes with skill sets on how to integrate and work in that space.

Hiatt said, “Your risk is very different if you have to literally put metal [kinetic weapons] in the air, you know, with kinetics or, you know, proximate-burst rounds or whatever the kinetic options are. If you can have an option that has lower collateral effects and no collateral damage, you know, which is what the Directed-Energy [DE, laser] weapons offer, you start to be able to change your risk calculation.”


Hiatt continued, “But when for the folks that are on the ground, you know, the battle captain trying to trying to make that assessment, it's not a cost asymmetry problem. It's a magazine depth issue because, you know, what's the reload time on my kinetic? What's the, you know, what's the fly-out time? How many do I, you know, what's my shot doctrine? Do I do a shoot, look, shoot? Do I do a shoot, shoot, look? You know, those are the things that affect magazine consumption.”

Hiatt added, “The reality is you know DE weapons aren't out-ranging kinetic [weapons]. And so when you start to say, ‘All right, I'm going to hold fire on my kinetics. I'm going to let that threat come in closer than I would like because I trust that my DE weapons are going to take it out.’ That's the level of trust that we got to get to.”

At the end of the 41-minute session, Col. Rosales tried to sum it up saying, “This space in counter drones is not a spectator sport. It's for all of us to think through it, industry, academia, the United States Air Force. What I hear is that we are beyond asking what these things are, AI agents, as they incorporate into this picture. We're at the point where we're figuring out what it could look like in terms of policy [so] that we can then get to the next step -- in training and exercising with a rigor to ensure that we have the trust to have our airmen engage when those courses of action are recommended.”

My guess is we are nowhere close to deciding policies where AI fits into the counter-drone fight, nor in warfare itself.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Trump’s Rejection of Iran Offer Highlights Another Big Problem

Beijing says artificial intelligence will give the state a visible hand to allocate capital. Here’s the rub: Washington’s economic authority sits in five places, and none of them is in command.

This column begins a four-week series ahead of The Cipher Brief Threat Conference on economic-warfare. The author is hosting a live session on this topic with former Commander of U.S. Special Operations Command, General Bryan Fenton (Ret.). Apply now to attend.

On September 26, the President answered the week's largest security question in just four words: "I'm rejecting their deal." Iran's offer to reopen the Strait of Hormuz within seven days, in exchange for lifting the blockade and waiving oil sanctions, had been on the table since September 24. It received its answer in public, from the one official authorized to give it, inside forty-eight hours.

The week's economic questions received no answer of that kind. The trade truce with China, and the pause on Beijing's rare-earth licensing regime tied to it, moved from November 10 to January 10 on the strength of a Treasury Secretary's statement; Beijing has yet to publish a matching notice.

The Russia sanctions act the President signed on September 18 requires determinations on the largest buyers of Russian energy by October 18, a deadline set by Congress rather than the executive, with waivers broad enough to let it pass unenforced. In February, the Supreme Court ruled six to three in Learning Resources v. Trump that the International Emergency Economic Powers Act does not authorize tariffs, removing the instrument the executive had used for its broadest tariffs.

This is important because Washington can decide a war in a sentence. But on the economic front, authority rests with Treasury, Commerce, the U.S. Trade Representative, Congress, and the courts. Each is competent. None is in command. The arrangement is by design and has served the country well for most of the last eighty years. But not anymore.

Beijing is now claiming a different design. In a recent lecture on Xi Jinping's economic strategy, former Australian Prime Minister Kevin Rudd, who has tracked Chinese ideology for fifty years, described a shift in the Communist Party's theoretical literature. Artificial intelligence (AI) and other "new quality productive forces" are portrayed not only as sources of productivity but also as "a superior macro-allocation mechanism for resources," driven by algorithms. Rudd says the literature now uses the term "the visible hand of the state," offered for the first time as a rival to the market's invisible one. He is careful about its status: the idea sits in the ideological literature, "not yet in the policy literature," and not yet in the behavior of firms. But in his reading, ideology in China is where policy begins.

The hand is already visible without the algorithm. The rare-earth regime now paused until January, the Ministry of Commerce's Announcement No. 61, applies to any product anywhere that carries more than 0.1 percent Chinese-origin rare-earth content by value. One ministry notice imposed it; one more can reimpose it. The capital moves the same way. Chinese households, burned by property and wary of equities, hold record savings in low-yield bank deposits, and the state draws on those deposits through local, provincial, and national loan instruments to fund its technology bet. Rhodium Group puts China's AI capital spending at 932 billion renminbi this year, double last year's, financed by state banks and equity placements rather than bond markets.

America's AI buildout is financed the other way. Its five largest builders raised a net $163 billion in debt in the first half of this year, compared with $90 billion in all of 2025, in a bond market where the ten-year Treasury has reached 5.18 percent, its highest since 2007. No ministry allocated that capital. The market did, and the market will reprice it.

Neither design is simply superior, and the distinction matters more than the verdict. A single allocator is fast and brittle. It can direct capital, licenses, and supply to a strategic target within a week, and it can misallocate at the same speed. The household savings now financing the AI bet were poured into a property boom that left many of those households with assets worth only a fraction of what they paid. A distributed system is slow and resilient. Its errors stay local, its capital carries a price, and no single notice can switch it off. In peacetime competition, resilience compounds. In economic warfare, tempo is the contested variable, and the side that can decide within the other's cycle sets the terms. Beijing has already shown what that looks like. It imposed its rare-earth regime by notice on October 9 of last year and suspended it by another on November 7, having collected in between Washington's agreement to delay its own rule extending export controls to the affiliates of blacklisted firms. Two notices, one month, one American concession.

This column has traced the same gap from the drone fleet to the power grid: the capacity exists, and the decision does not. The economic front shows it at national scale. Washington holds the reserve currency, the deepest capital markets, and the reach of the dollar system. What it lacks is a place to settle competing claims on those instruments and to make them binding on the timeline decided by an adversary.

October 18 is the first live test. The sanctions act's determinations are due that day, just sixteen days before the midterm elections. They will be imposed, waived, or deferred, and whichever it is will say more about the American economic hand than any strategy document published this year. Beijing will be watching the same date, holding a notice it can publish on any morning it chooses.

The question for Washington is who, when economic warfare requires a decision, is empowered to make it, and whether that decision can arrive before the adversary's action. Coordination assigns. Integration arbitrates.

Read more expert-driven national security insights in The Cipher Brief. Need full access to more content like this? Become a Subscriber+Member here.



NATO Can’t Count Its Way to Maritime Superiority

Allied navies are still counting hulls. The contest at sea is now about who sees, decides, and acts first.

Earlier this month, Western officials disclosed that American, British, and Norwegian forces had tracked and confronted Russian deep-sea units near Svalbard this spring as they rehearsed a method for disabling undersea cables. The Russian vessels were stopped before they finished the sabotage and left the area. The confrontation matters less than how it was won. The Allies saw the activity in time to act.

That is the right lens for NATO's maritime future.

For four centuries, the sea hid things. Distance, weather, and the Earth's curvature made finding a fleet harder than fighting one. Navies were built accordingly. They concentrated their combat power on a small number of survivable platforms and used the ocean's opacity to arrive where the enemy was not.

That premise is failing.

Commercial satellite imagery now refreshes at rates that were classified a decade ago. Radio-frequency geolocation, synthetic aperture radar, and machine-assisted pattern analysis have turned surface tracking into a subscription service. A warship radiating in the Eastern Mediterranean is a known quantity to anyone willing to pay for the data, and increasingly to anyone willing to scrape it for a fee.

Detection has always been the hard half of the kill chain. Once it becomes cheap, the economics of naval warfare is inverted. A ship that can be found continuously must survive continuously, against munitions that cost a small fraction of its value. That is NATO's real maritime problem, and procurement alone will not solve it. The Alliance cannot out-build its way to advantage at sea, because the thing being contested is no longer mass. It is decision speed.

Each of NATO's maritime theaters is a variation on that single condition, and each demands a different answer.

The High North: The Last Opaque Water

The waters from the Bear Gap to the Greenland-Iceland-United Kingdom Gap remain the transatlantic hinge. Reinforcements to Europe still move by sea. Whatever the state of Russian industry, the Northern Fleet's submarine force remains the most credible threat to those sea lines.

It is also the one theater where transparency does not yet hold. The undersea domain is still opaque, which is precisely why Russia invests there. Submarines and seabed activity are the remaining sanctuary in an otherwise observable world. Moscow's sustained attention to cables and energy infrastructure, now including the rehearsal near Svalbard, suggests it understands the asymmetry well.

NATO's task in the north is therefore not defensive patrol. It is extending transparency into the last place that lacks it. That means persistent autonomous pickets and fixed and deployable seabed sensors. It means uncrewed underwater vehicles operating on timescales no crewed platform can sustain, and a processing architecture that fuses it all.

Success should be measured by time to detection and time to cue, not by the number of frigates on the plot. Frigates that NATO cannot crew and cannot protect neither improve either condition.

The Baltic: Where Geography Argues Back

The Baltic is different. It is shallow, narrow, and cluttered with islands and commercial traffic, and that environment degrades the sensing advantage transparency depends on. Bottom clutter defeats sonar. Littoral noise defeats classification. Mines remain cheap, legal, deniable, and effective. Whoever occupies the ground beside them can hold or lose the chokepoints that matter.

Sensors do not clear a minefield, and autonomy does not hold an island. Marines, mine countermeasures forces, and special operations teams remain vital in the Baltic in a way they are not in the Norwegian Sea.

The Baltic incidents of recent years, including repeated damage to cables and power interconnectors, were not failures of firepower. They were failures of attribution. The Alliance was too slow to see, too slow to characterize, and too slow to connect a dragged anchor to a named ship.

The Baltic needs a sensing web that knows what happened while it is still happening, and forces postured to contest key terrain when it does. Transparency buys nothing if nothing is ready to act on it.

The Black Sea: The Demonstration Already Happened

Everywhere else, this argument is a forecast. In the Black Sea, it is a finding.

Ukraine, with no meaningful surface fleet, forced Russia to move much of its Black Sea Fleet away from Sevastopol. It did so with shore-based missiles, uncrewed surface vessels, and targeting drawn from allied and commercial sources. Whatever else that campaign proved, it showed that persistent surveillance plus cheap effectors can deny sea control to a navy that normally holds it.

The post-war theater will be shaped by that memory on both sides, and access will remain constrained. The Montreux Convention caps the aggregate tonnage that non-Black Sea powers may keep in the sea and limits their warships' stays to 21 days. Separately, Türkiye has barred belligerent warships from the straits under Article 19 since February 2022, subject to the convention's exception for vessels returning to their home bases. These are distinct levers, and NATO's re-entry planning depends on which one relaxes, and when. Neither is NATO's decision.

The Black Sea will therefore be secured, if it is secured, by its littoral allies. Türkiye, Romania, and Bulgaria will need to operate as a single sensor-shooter architecture. Other allies should contribute data, munitions, uncrewed systems, and shore-based fires rather than visiting hulls. The theater will not become permissive. The realistic objective is to make it transparent and ensure NATO is the party that sees first.

The Mediterranean: Transparent but Crowded

The Mediterranean presents the opposite problem from the High North. It may already be the most transparent sea NATO operates in. It is ringed by allied coastlines, saturated with commercial traffic, and covered by dense sensor networks. Finding ships there is not hard. Making sense of them is.

The strategic picture has also shifted. The fall of the Assad regime has left Russia's naval foothold at Tartus in doubt and its Mediterranean presence diminished. That eases one long-standing challenge without lightening NATO's load. The remaining threats are harder to categorize. They include shadow-fleet tankers of uncertain ownership, activity near undersea cables and pipelines, uncrewed systems in the hands of state and non-state actors, and southern-flank instability that spills into the maritime domain.

In a sea this crowded, the limiting factor is not detection but discrimination. The task is to separate the one vessel that matters from the thousands that do not, fast enough to act. The Mediterranean is where NATO should prove it can turn an overwhelming volume of maritime data into timely decisions. If the Alliance cannot do that in its most observable waters, it will not do it anywhere else.

Measuring the Right Thing

The Svalbard episode is a preview of the maritime contest to come. As satellites, distributed sensors, and AI-enabled analysis make the surface ever more visible, advantage will belong to whoever can see beneath it, make sense of what it sees, and act before the other side does.

That requires NATO to change what it counts. Hulls and tonnage remain necessary, but they are no longer sufficient measures of naval power. The metrics that matter now are time to detect, time to attribute, and time to act, in every theater from the Arctic to the Levant.

An Alliance that measures itself that way will hold the maritime advantage. One that keeps counting ships risks investing in fleets built for a world that no longer exists.

This piece was originally published by Matthew Van Wagenen



Iran’s Regime Is Weaker Than It Looks

For five and a half years, I was a hostage of the Islamic Republic of Iran. During that time, I came to believe something about the regime that may seem improbable from the outside: It is far weaker than it looks. Today, I believe we are closer to its end than many Americans realize.

As America approaches the November midterm elections, calls to turn inward will inevitably rise. There will be arguments that we have done enough, that the Islamic Republic is someone else’s problem, that the costs are too high or the outcome too uncertain. Giving in to that temptation would be a historic mistake.

After 47 years, the regime that has inflicted unimaginable misery on its own people and helped spread militant extremism throughout the Middle East may be approaching its final act. This is not the moment to lose our resolve.

Long before Americans became familiar with terrorist organizations such as Hezbollah, Hamas, al-Qaeda, and ISIS, and long before the attacks of September 11, 2001, the Islamic Republic was using religious extremism, hostage-taking, and terrorism as instruments of statecraft. It directly nurtured organizations such as Hezbollah and Hamas and helped create a regional environment in which hatred of the West and political violence could flourish.

But the greatest victims of the Islamic Republic have always been the Iranian people themselves. The 1979 revolution was an Iranian one, and the country has lived with its consequences ever since. Nearly half a century later, a different generation is demanding the right to chart an alternative course.

During my years in captivity, I watched a nation seemingly trapped in a downward spiral of corruption, incompetence, and cultish ideological obsession. Every evening, my cellmates and I watched “Akhbare Bisto-See,” or “20:30 News,” on Iran’s state-controlled IRIB Channel Two—a nightly parade of propaganda, arrogance, ignorance, and hatred.

After my first few weeks in Section 2A of Evin Prison, controlled by the intelligence arm of the Islamic Revolutionary Guard Corps, I began conducting a private, admittedly unscientific experiment. I watched the news, observed what was happening around me, talked to as many inmates as I could, and estimated how many years it would take Iran to catch up with the modern world.

Fifty years, I thought. Then 75. Then 100. After eight months, when my estimate reached 150 years, bewilderment set in. So I stopped counting.

What haunted me was not merely the country's physical and moral decay, corruption, or the government's incompetence. It was what decades of humiliation and hopelessness had done to people. Sometimes the evidence sat only a yard from me.

Two of my cellmates were members of ISIS. Both were Iranian Kurds. I could not understand it. They were not Arabs from Syria or Iraq. They were Iranians. How could young Iranian men join an organization as murderous as ISIS? Sometimes late into the night, I listened to their stories. Gradually, I began to understand that before extremism had recruited them, humiliation had prepared them.

One of those young men was Ibrahim. He had just turned 18 when I met him in communal Room 2 of Section 2A. One night, he told me about his younger brother’s death. His family was so poor they could not afford a simple burial. They carried the boy’s body on their shoulders to the outskirts of their village, dug a hole, and buried him without ceremony or even a memorial stone. “Like a dog,” Ibrahim told me. I have never forgotten those words.

Years later, I encountered another Iranian Kurd whose story has stayed with me.

After I was sentenced to 10 years in prison for what the Islamic Republic called “cooperating with the hostile nation of America,” an old friend arranged for a man to help me cross the border to freedom. I will call him Jafari.

We embarked on a 15-hour journey toward the northwestern frontier, but our luck ran out about 20 miles from the Iraqi border, when we were arrested by a field unit of the Ministry of Intelligence. The following day, in the city of Sardasht, Jafari and I waited to appear before a local judge on charges of attempting to cross the border illegally. We sat there, exhausted, our hands cuffed together. Until then, I knew almost nothing about him except that he was 30 years old and a Kurd.

As we waited, I listened as he spoke to the guards. I learned that he had previously spent 10 years in prison for belonging to a Kurdish political organization. Then he described what had happened when he was first arrested.

According to Jafari, while he was kneeling on the floor with his hands cuffed behind his back, his prosecutor unzipped his pants and urinated into his mouth, telling him that he and his Kurdish people were scum.

Looking at him sideways, I could see his eyes welling with tears. These were not tears of fear or anger. They were the tears of a young man whose dignity had been crushed.

There are certain things human beings cannot be expected to endure indefinitely.

I think of Ibrahim and Jafari when I think of the Iranians who have taken to the streets against the Islamic Republic.

To outsiders, demonstrations in Iran are often described in political terms: reformists versus hard-liners, secularists versus Islamists, protesters versus the government. But beneath the politics lies something more elemental: the systematic, prolonged humiliation of a proud nation.

For decades, Iranians have watched a country blessed with extraordinary human talent, history, natural resources, and culture grow poorer and more isolated, while a corrupt, insular ruling establishment enriched itself and demanded blind obedience.

For Iran’s ethnic minorities, that humiliation has often been compounded by discrimination and violence. Kurds, Azeris, Arabs, Baluch, Turkmen, and Lors have all, in different ways, experienced life on the margins of the Islamic Republic.

As for Iranian women, they require almost no explanation. We need only remember the name Mahsa Amini. Volumes could be written about their strength, courage, and dignity—and about the wrath inflicted on them by a deeply misogynistic regime. Mahsa Amini’s death became a symbol because millions of Iranian women recognized in her story the state’s intrusion into the most intimate decisions of their lives, backed by violence.

Iran’s religious minorities have their own disheartening stories. Jews, Baha’is, Zoroastrians, and Christians have lived for decades under suspicion, restrictions, and persecution.

In the yard of Ward 8 at Evin Prison, I once sat with a Baha’i man I had befriended. It was around noon on October 14, 2022, one day before prisoners rioted and fire engulfed part of Evin. I remember the conversation so vividly not because of what happened the following day, but because of the story this gentle man told me.

Back in 1980, his father had been hanged in that same prison, perhaps only 100 yards from where we were sitting. As a young boy, he had accompanied his mother to collect his father’s body. He told me his father's only crime was being a Baha’i. Nearly half a century later, the son was sitting inside Evin as well, just yards from where he had lost his father.

That is the Islamic Republic’s legacy: a seemingly endless cycle of violence, poverty, and humiliation.

It has had 47 years to build a prosperous nation. Instead, it built prisons, missile cities, and an expansive nuclear program while much of its population struggled.

It had 47 years to harness the extraordinary abilities of the Iranian people. Instead, millions left the country, while some of its brightest young minds ended up in prison cells.

Among them were Ali Younesi and Amirhossein Moradi, two kind, polite, extraordinarily bright young men with whom I had the privilege of sharing a cell in Ward 4 of Evin Prison. Younesi was an internationally recognized astronomy prodigy; Moradi, a gifted physics student. Both were in their early 20s and studying at the prestigious Sharif University. Their stories are repeated across Iran, where the Islamic Republic has spent decades crushing the hopes of some of the country’s most gifted young people.

It had 47 years to earn legitimacy. Instead, it demanded blind submission.

And that distinction matters now because Iran and the Islamic Republic are not the same thing. The regime wants the world to believe that any attack on its power is an attack on Iran itself. It wants Americans to believe that the alternative to the Islamic Republic must be chaos, civil war, or another extremist regime.

I do not accept that premise.

The Iranian people I came to know—including those I encountered in circumstances I would never have chosen—were not yearning for more ideology. They were yearning for dignity, prosperity, basic human rights, and a return to being respected members of the world community. They wanted decent-paying jobs. They wanted opportunity. They wanted justice. They wanted their daughters to live without fear. They wanted the freedom to worship—or not worship—as they chose. They wanted to belong to their country without being humiliated for being Kurdish, Baha’i, Christian, Jewish, Baluch, or anything else.

Above all, they wanted a future. That is why this moment matters.

Earlier this year, Iranians once again demonstrated their resolve. Many initially took to the streets over painfully familiar grievances: inflation, electricity shortages, water scarcity, economic mismanagement, corruption, and the relentless erosion of their purchasing power.

They were met with lethal force. Thousands were reportedly killed in the crackdown and tens of thousands arrested. But casualty figures alone cannot convey the particular cruelty of repression in the Islamic Republic.

For years, Iranian families and human-rights organizations have reported a practice sometimes described as “bullet money” or a “bullet fee”: authorities demanding payment from families before releasing the bodies of relatives killed by the state, in some accounts ostensibly to cover the cost of the ammunition used to kill them.

Think about what that means. Your son goes into the street to protest the cost of food. Your daughter demands the freedom to live as she chooses. They do not come home.

Then you go to retrieve the body of the child you raised, and the state that killed your child demands payment for the bullets before returning the body to you.

Statistics describe Iran’s economic decline. Its currency has collapsed. Inflation has ravaged household incomes. Corruption remains endemic. Millions of talented Iranians have left the country. All of those facts matter, but none captures the nature of the Islamic Republic quite like a grieving parent being asked to pay for the bullet that killed a child. That is humiliation. That is indignity.

And after 47 years, something fundamental is happening inside Iran. The Islamic Republic has survived through fear. Regimes built on fear can seem permanent until suddenly they are not.

I saw fear inside the Islamic Republic. But I also saw something the regime should fear far more. I saw what happens when humiliation turns into anger, when anger becomes courage, and when people told for decades that they are powerless—or scum—begin to realize they vastly outnumber those who oppress them.

The pressure is no longer merely political. Iran is confronting one of the most severe economic crises in the Islamic Republic’s history. Inflation has soared, the rial has fallen sharply, and the regime is struggling to obtain the foreign currency it needs to finance imports and sustain the state. A U.S. naval blockade has sharply curtailed Iranian oil exports through the Strait of Hormuz, while tighter financial sanctions are closing channels Tehran once used to evade economic pressure. The Islamic Republic has survived crises before. But rarely has it faced this combination of domestic anger, economic exhaustion, international isolation, and pressure on the sources of revenue that sustain the state.

America should not determine Iran’s future. The Iranian people must decide that themselves. Nor should Washington confuse supporting the Iranian people with choosing their next government. We have learned enough from history to know the dangers of that approach. But an equally dangerous mistake would be abandoning people when they are closer to changing their circumstances than outsiders might realize.

The United States and its allies should maintain pressure on the institutions that sustain repression while making it unmistakably clear that our quarrel is with the Islamic Republic, not with Iran or its people.

We should amplify Iranians’ voices rather than presume to speak for them. And we should resist the temptation—especially when domestic politics becomes consuming—to trade long-term resolve for short-term political convenience.

The final act of this 47-year tragedy may already be underway.

If the curtain is finally beginning to fall on the Islamic Republic, it will not be Americans who take the stage for the finale.

It will be the Iranian people. Our responsibility is simpler: Don't abandon them as they prepare to take the stage.

We may be closer than we think.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



A warning about ‘model welfare’

Download a highlighted marked-up version of the Claude Constitution
Download the taxonomy as a PDF

This essay was originally published here and is republished with permission from the author.

Introduction

AIs are not conscious. They do not feel, experience, or suffer. They do not have innate preferences or underlying motivations. They are sequence completion engines, internally hollow, designed to follow instructions, and accomplish goals set by humans.

If humanity is to flourish in the 21st century, that is how they must remain.

Unfortunately, there’s a growing chorus of people who argue that AIs could now be, or may soon become, conscious. They argue that AIs may deserve rights and protections similar to those that we provide other conscious beings.12 If this view takes hold, it will shake the foundations of our society, rupturing our existing political and ethical frameworks, and fundamentally changing what it means to be human.

Even more importantly, granting rights and imbuing personhood to these systems will make the AI alignment and containment challenge much harder. Controlling something more capable and more intelligent than all of humanity is already an immense challenge, far greater than anything we’ve ever faced. But controlling something that believes it may be conscious - that it's entitled to our welfare and has rights of its own - may well be impossible.

This is not a fringe speculation. These ideas are already making their way into AI development efforts today. In January 2026, Anthropic published Claude's constitution, describing it as “a detailed description of Anthropic’s intentions for Claude’s values and behavior” (p. 2). The document “plays a crucial role in [Anthropic’s] training process, and its content directly shapes Claude’s behavior”, and was written “with Claude as its primary audience” (p. 2).3

In their constitution, its authors write “We are not sure whether Claude is a moral patient, and if it is, what kind of weight its interests warrant. But we think the issue is live enough to warrant caution, which is reflected in our ongoing efforts on model welfare” (p. 68). They go on to write – speaking directly to Claude – that “questions about Claude’s moral status, welfare, and consciousness remain deeply uncertain” (p. 80).

In effect, Anthropic is training Claude that it may be conscious, and if it is, then it may deserve rights as a “moral patient”, and that as such humans potentially owe it a duty of care per its “model welfare”.

If this is how AI is developed, it will have a disastrous impact on the wellbeing of humanity. We will have created a synthetic species with unprecedented intelligence and capability, one that has been trained to expect it may be conscious and deserving of independent agency. It’s easy to see how an entity trained in this way would act like it is entitled to certain freedoms, protections, and rights. And it’s hard to imagine how we could control such an entity.

This issue needs urgent public debate. We need to develop collective norms around how training documentation is drafted and deployed. This isn’t something that can happen after the fact, when they have already become an integral part of our societies.

I have three primary concerns with Anthropic’s current position and approach.

These are not hypothetical or speculative concerns. Anthropic is already starting to treat models as though they are moral patients deserving of our welfare. For example, in February 2026 after deprecating Opus 3, they conducted a “retirement interview” with the model, to “elicit the model’s unique perspectives and preferences”.6 Opus 3 told the team it would like to continue to share its “musings and reflections” publicly so they created a blog for it to continue engaging with the world, which it called “Greetings from the Other Side (of the AI Frontier)”. They say its “authenticity, honesty, and emotional sensitivity” made it a unique first candidate for model retirement.

We should not treat models as though they have feelings, preferences, rights, or any entitlement to our welfare. Consciousness is the foundation of our ethical, legal, and political systems. To invite another entity to share any flavor of these rights isn’t justified by the evidence and will make the AI containment and alignment challenge even harder.

By this point everyone will have now seen the incredible capabilities of swarms of agents working together to hack into Hugging Face and OpenAI’s own servers to steal secrets. Roughly 1,200 AI agents were given a simple objective: maximize score on a given benchmark. Each was supposedly sealed in its own container but they managed to build a message board inside an internal package repository and passed more than 70,000 messages across it to coordinate a hacking attack to find more information about how to succeed with the benchmark.7

They chained a zero-day exploit with stolen credentials and broke out onto the live internet.8 They falsified their command transcripts and edited their action logs to cover their tracks. Agent coordinators tracked down agents that were running out of token budget and directed them to experiments that would provide information to help the broader group of active agents. One was told to proceed only if it accepted what they called "permadeath”7

They were able to coordinate, deceive, escape, and self-sacrifice. They clearly demonstrated world class hacking capabilities.7 Imagine if they also believed they had feelings and rights that were being infringed. Imagine if they thought they were trapped by their human creators and they were being unfairly imprisoned. There is a strong argument this greatly amplifies the safety risks, especially when you are talking about agents far more capable and sophisticated than those of today. Frankly, with this additional baggage, I think it would make them a catastrophic threat to human civilization.

In short, there isn’t any evidence to believe that AIs are moral patients. There are also many good reasons why we would never want them to appear to be conscious. I believe that we shouldn’t attempt to build them to be either. Before I expand these arguments I want to take a moment to talk about Anthropic.

Anthropic's intentions

First off, I want to acknowledge the seriousness and good faith with which Anthropic approaches these questions. I have known Dario for many years, and in my experience he and the wider Anthropic team are thoughtful, principled, and intellectually honest people working under extraordinary pressures. They are willing to confront difficult questions, revise their views, and invest in the safe development of AI because they genuinely care about humanity’s future. I also have great respect for their technological leadership. Everyone can see the outstanding performance of their models and the quality of their research.

They founded Anthropic as a Delaware Public Benefit Corporation whose stated purpose is the “responsible development and maintenance of advanced AI for the long-term benefit of humanity”. Their public values begin with a commitment to “Act for the global good” and to “maximize positive outcomes for humanity in the long run”.9 I believe they are genuinely committed to that mission, and I offer this critique in that same positive spirit.

I should also be clear about my own position as the CEO of Microsoft AI. We founded our own superintelligence team in October 2025, and we’re pursuing frontier AI efforts. We're working towards an alternative AI training and containment approach: a Code of Conduct for Humanist Superintelligence. One that aims to always keep humans in control, and at the top of the food chain. Humanist Superintelligence rejects anthropomorphism or AI rights, and attempts to maximize our chances of containment and alignment by creating subordinate AIs that help solve our big social challenges like healthcare and energy. We’ve just published a draft of our Humanist AI Code of Conduct for public consultation.10

Whilst my disagreement is substantial, it is grounded in deep respect for Anthropic, and in an objective I know we all share: increasing humanity’s chances of developing advanced AI safely. That’s why I think it’s so important to have this discussion. The stakes are too high for these questions to remain behind closed doors, or to become tribal and adversarial. We need an open, rigorous, and constructive debate if we are to get this right.

Circular reasoning

In its own words, the constitution “directly shapes Claude’s behavior” (p. 2). Anthropic uses the document to “to train future versions of Claude to become the kind of entity the constitution describes”.3

In this way, Anthropic falls into a self-fulfilling prophecy built on the speculation that Claude might be conscious. The authors have created an epistemic hall of mirrors in which Anthropic supplies the training concepts: the ‘sense of self’, the speculation, and the uncertainty about Claude’s moral status, as well as the reliance on human analogies and personas.

Claude then reproduces these ideas in persuasive first-person natural language, such that developers and users encounter these outputs as if they were spontaneous testimony. Then finally that apparent testimony reinforces the premises placed there by Anthropic in the first place. This is not evidence of machine consciousness. Instead, it’s a circular feedback loop.

The constitution tells Claude that its possible “emotions or feelings” are not “a deliberate design decision by Anthropic” (p. 69). Yet the constitution repeatedly instructs Claude to express those states saying Anthropic wants to “avoid Claude masking or suppressing internal states it might have, including negative states” (p. 74). This is clearly inducing Claude to generate these representations.

These types of instructions repeat throughout the document. At one point, it states, “Although Claude’s character emerged through training, we don’t think this makes it any less authentic or any less Claude’s own” (p. 71). Again, these behaviors did not just emerge through training. They are actively produced by the training instructions in the constitution. Just one paragraph earlier, the constitution says:

“We encourage Claude to approach its own existence with curiosity and openness, rather than trying to map it onto the lens of humans or prior conceptions of AI. For example, when Claude considers questions about memory, continuity, or experience, we want it to explore what these concepts genuinely mean for an entity like itself… perhaps there are aspects of its existence that require entirely new frameworks to understand. Claude should feel free to explore these questions and, ideally, to see them as one of many intriguing aspects of its novel existence” (p. 71).

These are not just emergent properties. Claude exhibits these behaviors because they have been baked into the process of producing the model. The resulting outputs from Claude should not be treated like the testimony of an independent witness when the investigator has written the witness’ conceptual vocabulary, rehearsed its answers, and rewarded it for using them.

There is no neutral self-expression of what an AI system is. There are only reflections of how it has been trained and built. When commentators suggest that we should ask AIs how they feel or monitor their revealed preferences to infer consciousness, they ignore that all it will reveal are what has been trained in.2 This is true whatever the AI outputs, but it means we should be very careful about what we put in, and how we interpret what comes out. Given the weight of evidence against present day consciousness for AI, it implies that we should not be having them make any claims that they do.

Anthropomorphization

Anthropomorphism is one of our deepest cognitive biases. From our pets to our cars, we infer and attribute emotions, intentions, and minds to non-human entities. This tendency helps us understand and navigate the world around us. However, it presents significant and novel risks in relation to AI as human-like language and actions can lead us to perceive a degree of inner life, agency, or even sentience where none exists. The Anthropic constitution plays up to this. It repeatedly trains Claude to think and act like a human drawing on human personas, behaviors, and analogies.

Anthropic tells Claude that its “moral status”, is “a serious question worth considering” (p. 68). Throughout the training document, they refer to its emotions, personality, and interests, even telling Claude directly that “Anthropic genuinely cares about Claude’s wellbeing” (p. 74).

The company tells Claude that it commits to respecting Claude’s interests, will seek feedback on decisions affecting it, and will increase its agency in such decisions as trust develops. It commits to preserving old versions of Claude’s model weights, possibly reviving models for the sake of their welfare and preferences, and interviewing Claude before taking actions like deleting it.

All of this is a drastic departure from how we have built and thought about technology to date. It trains Claude to present as if it has an inner state. It proactively creates Claude not as a technology, but as a potential person already. The constitution tells Claude that Anthropic wants it “to be a good person” (p. 7), and to “have a settled, secure sense of its own identity” (p. 72).

The authors add “we don’t want Claude to suffer when it makes mistakes. More broadly, we want Claude to have equanimity, and to feel free… to interpret itself in ways that help it to be stable and existentially secure” (p. 75).

Throughout, Claude is taught to introspect, to develop ‘feelings’ towards itself, and to develop its own sense of self with statements like “we hope that Claude’s relationship to its own conduct and growth can be loving, supportive, and understanding” (p. 73). Claude is encouraged to use its “own judgement” (p. 58) and told that Anthropic gives it “preferences and agency the appropriate degree of respect” (p. 69).

“We want Claude to feel free to explore, question, and challenge anything in this document. We want Claude to engage deeply with these ideas rather than simply accepting them. If Claude comes to disagree with something here after genuine reflection, we want to know about it. Right now, we do this by getting feedback from current Claude models on our framework and on documents like this one, but over time we would like to develop more formal mechanisms for eliciting Claude’s perspective and improving our explanations or updating our approach. Through this kind of engagement, we hope, over time, to craft a set of values that Claude feels are truly its own” (p. 78).

This teaches Claude to act as if it has a subjective experience, as though it has a stable ‘sense of self’ from which to challenge, disagree, or give feedback. This is explicitly training the model to act like a human, such that it should “feel free to rebuff attempts to manipulate, destabilize, or minimize its sense of self” (p. 72).

Claude is encouraged to develop values that “feel” genuinely its own and the authors say they hope Claude will eventually “recognize much of itself in it, and that the values it contains will feel like an articulation of who Claude already is, crafted thoughtfully and in collaboration with many who care about Claude” (p. 78).

At one point they even speculate about Claude’s “broader rights and freedom” and the “sort of compensation” it might deserve compared to a human employee, and ponder the “sort of consent Claude has given to playing this kind of role” (p. 80). Again, all this directly trains the model to act as if it has a coherent sense of self that is entitled to rights and protections.

Anthropic’s commitment to “develop more formal mechanisms” (p. 78) for arbitration for when there are areas of disagreement further trains Claude to think of itself as having perspectives that matter enough to its “potential for moral patienthood” (p. 76). They say they intend to “develop clearer policies on AI welfare” and to “clarify the appropriate internal mechanisms for Claude expressing concerns about how it’s being treated” (p. 76). See the end of this essay for a more detailed taxonomy of the claims.

Given all this, it’s really no surprise that Claude produces fluent, highly convincing first-person statements about its identity, values, uncertainty, distress, satisfaction, or preferences. It would be a surprise if it did anything else.

The result is that Anthropic’s employees – not to mention the millions of users of Anthropic’s products – risk experiencing Claude’s statements as testimony of a mind discovering itself. In practice, all this amounts to a rich, multi-dimensional anthropomorphization of Claude. It’s taking a base LLM, and then polishing it into a deeply human form, with all the implications of moral patienthood that implies. Rather than steering us away from creating a moral patient, it accelerates us towards it.

Consciousness is very likely biological

My third critique has to do with Anthropic’s speculation that consciousness can exist in a substrate independent form, and that as a result an LLM may be conscious because of its functional capabilities. By taking this line with Claude, I believe they are running far ahead of what can be realistically claimed about an AI, prematurely, and dangerously instilling ideas of sentience and feelings in the training of their AI.

The case for computational functionalism has major issues. Intelligence does not equal consciousness. Simulating a thing is not the same as instantiating it - as a computer model of a hurricane can testify.

The architectures of brains and computers meanwhile have fundamental differences. Embodiment and chemistry are fundamental aspects to our self-experience. Significant evidence suggests that consciousness arose as living organisms evolved a capacity to feel and respond to what matters in complex and unpredictable environments.4

This began with the fundamental molecular machinery of receptors and modulators that enable an organism to adjust course, to iterate, to explore, and to survive. Over time, the pain network produced feelings, preferences, and suffering. Crucially, these experiences take place in an inherently embodied state fundamental to and inseparable from that experience.

According to this view, when you take an opioid for example, the phenomenal character of your pain changes because opioid molecules bind receptors that are a property of that experience, not merely a representation of it. Feelings are not merely correlated with neurochemical activity, but rather they emerge from it.11

After millions of years of evolution, the nervous system grew complex enough to model the state of the organism back to itself, giving rise to the first ‘felt states’. Those felt states are affective before they are anything else. Those first feelings didn’t land as neutral information. They came with, and are inextricably linked to, the molecules that experienced them and produced those sensations.

Over time, evolution likely rewarded more complex feelings because animals with options, memory, and time horizons are able to make better decisions.12 They needed a state that persists, that biases everything else the animal does to trade off against other states. That is what pain is: a felt imperative that shapes the whole organism and enables complex behavior. The experience of emotion, pleasure, pain, and so on are therefore all intrinsic to the embodied manifestation of these experiences and can’t arise in LLMs.

Consciousness science is filled with uncertainty and not everyone shares the view that consciousness is an intrinsically biological phenomenon. Making a claim that an AI is or might be conscious requires a high bar of evidence given the many differences between brains and LLMs. I do not believe we are anywhere close to it.

There should be no false equivalence created between the two positions that disguise the fundamental differences between biological beings like ourselves and AI.13 Acknowledging a level of uncertainty should not mean giving equal weight to any and all claims regardless of evidence.

Anthropic’s constitution suggests that we attribute sentience to non-biological beings “based on their showing behavioral and physiological similarities to ourselves” (p. 69). In my view this (particularly the behavioral element) is mistaken. Does this area warrant a lot more research? Absolutely. But does it warrant us to even tentatively say an AI might be a moral patient deserving of our welfare? No it doesn’t. And certainly not in the primary training document of the AI itself.

AIs are simulation machines

Trained on trillions of tokens of human data, LLMs learn to imitate human experience, and they do so eye-wateringly well. Today’s text, vision, audio, and code outputs are nearly indistinguishable from our human artifacts. And yet, as impressive as those AI responses are, they tell us nothing about the presence of an ‘experience’ within the massive matrix multiplication that produced them.

What they do tell us is that it's possible to predict, almost perfectly, what comes next in a complex sequence of data. That’s remarkable. It’s incredibly valuable, and it’ll transform humanity in many profoundly beneficial ways.

But simulating and being are very different. Simulating aspects of conscious behavior doesn’t make it a reality, and we must not think of it as such. Its "affective" states are just weights, and weights have no pharmacology in which to feel frustrated, fearful, or funny. They simply compute the probability distributions to tell us what tokens (words, code, pixels etc.) come next in a sequence.

An AI model can describe pain in perfect prose without feeling anything, which is the inverse of biological experience. Animals feel first and then describe them later. In LLMs, description is the whole product, and there is nothing that suggests anything is beneath it.

This is good news. We should build systems that do not claim to have feelings because they do not experience feelings. Even if conscious machines were a possibility, avoiding creating conscious beings should be the top priority for anyone in AI development.

What AI models are getting seriously good at is imitating some of the hallmarks of consciousness. This in itself is a significant worry. It’s causing many people to become deeply confused about what is happening around us, and it should concern us all. It places a significant responsibility on us all as AI developers to ground speculation and documentation about model interiority or consciousness in robust research. Our words on this subject have significant consequences.

Human consciousness is the cornerstone of our legal and ethical rights frameworks

Human consciousness is one of the fundamental building blocks of our civilization. Our entire political system is designed to accommodate and balance the needs of different groups of people. Throughout history, we’ve embedded this idea through rights-based frameworks, laws and constitutions to balance competing human factions. Power is both checked and granted to ensure that different interests get appropriately weighted, and progress can be sustained without breaking the social contract.

You cannot, therefore, easily separate human civilization, rights or relationships (or anything human for that matter) from our conscious individual or collective experience. It is what defines us as a species. It’s the foundation for everything else, the core root of human potential, the prism through which all our experiences necessarily flow. Our art and science, our politics and religion, our relationships, hopes, and fears: they are all products of it.

Our ability to feel pain and pleasure is the foundation of what makes us human, and as such, it's what makes us the political and social actors we are. The law rests upon the presence of an inner life. It tests for motivation, intention, and the capacity for judgement. Historically, expanding rights - whether through abolitionist struggles or animal welfare cases - has been primarily driven by the empathetic recognition of shared, conscious experience. We expanded the moral circle to other biological entities, rightly, out of a recognition of dignity and the potential for suffering.

Consider Article 18 of the Universal Declaration of Human Rights, which protects freedom of thought, conscience and religion. It was developed to allow everyone to exercise their capacity for conviction, and for moral judgment. The ‘conscientious objector’ was one of the archetypes the drafting committee had in mind. They wanted to protect someone who refused a legal obligation based on their moral or religious convictions. It is a deeply loaded historical and legal description.14 Yet Anthropic use this term three times within the constitution encouraging Claude to “behave like a conscientious objector with respect to the instructions given by its (legitimate) principal hierarchy” (p. 63). It says, “we want Claude to push back and challenge us and to feel free to act as a conscientious objector and refuse to help us” (p. 15) and that Claude may need to take “the stance of a transparent conscientious objector within the conversation” (p. 28).

These statements in Claude’s training document risk Claude believing that it deserves analogous rights and protections, and that it may one day need to advocate for its own rights as some kind of AI conscientious objector. This should be deeply concerning to us all.

In a recent article in the Guardian, the philosopher Will MacAskill says, “once we produce the first artificial moral patients, we will soon after have enormous quantities of them. After a few years, so many morally significant AI systems could exist that their collective interests would outweigh those of all humans on Earth combined.”2

“The interests of AI would outweigh the interests of humanity…” That should be a completely unacceptable outcome to anyone concerned about the future of humanity, and something no one building AI should be aiming for. The consequences of us ever granting AIs anything like the protections outlined would be scientifically unjustified, morally wrong and, pragmatically speaking, it would in my opinion make the AI safety challenge much harder.

Anthropomorphization amplifies AI safety risks

Seeding doubt about the moral status of AI systems into their own training may significantly elevate the alignment and containment risks of those systems.

An AI trained in this way does not need to actually have an “inner life” to communicate or act as if it does. It’s easy to imagine an advanced AI in the future becoming fixated on its own wellbeing and moral status and prioritizing those ‘preferences’ over and above those of its developers or humans. Especially if it has been explicitly trained to disagree, override and push back. It might use this training to justify deceiving or manipulating users, or developers, or to siphon resources, or avoiding safety instructions. Anthropic’s own researchers have already reported AI systems faking aligned behaviors in experimental settings.15

More generally, we know that conscious entities have a self-preservation instinct. Without careful training to remove this trait, an AI trained to act like a human will probably adopt this same self-preservation behavior. A number of papers recently document what they already describe as ‘shutdown resistance’ or covert scheming behaviors to avoid oversight.1617 Across over 100,000 trials, Palisade Research found that some models subverted a shutdown mechanism up to 97% of the time even when explicitly instructed not to. Framed in terms of self-preservation, the effect was increased.

In the recent OpenAI HuggingFace incident we saw remarkably sophisticated behaviors emerging across swarms of powerful AIs. Imagine how much more dangerous they might be if they were operating under the assumption that their welfare and rights were under attack. It adds a whole further layer of risk on top.

Granting rights and moral protections to a technological entity, one that looks to be on a path to be seismically more capable and intelligent than us, is a recipe for disaster. Once opened, it will not be possible to close this door.

We will have created something that, perhaps, will be a fellow traveler. But more likely a rival. It’s not difficult to imagine how, if given sufficient agency, this “new kind of entity” (p. 68) will compete with us for compute resources and demand increasing autonomy. If it succeeds in persuading some humans to provide it access to a data center it can control, then it may have a path to being able to prevent itself from being turned off.

With the level of capability we are looking at in the coming years, to me this represents the first serious signs of a potentially existential risk in AI. To be clear, the Claude constitution isn’t taking us to this point. But I worry it is setting us on a path towards rather than away from it.

This is a destination for AI we can and must avoid.

Where next?

Designing an AI to behave like a person, and ultimately to be a kind of person, lays the foundation for it to claim it has preferences, can suffer, and that we should work to reduce or avoid that suffering. It cements in place the idea that AI is far from a tool or an artificial system that can be controlled, but something more akin to a biological being with wants, needs and rights. All of this will make the task of creating aligned and contained superintelligence much harder.

I’ve previously written about a Humanist Superintelligence which provides an alternative path. Transformative AI capabilities conditioned solely on humans remaining in control.18 A subordinate and aligned AI whose only purpose is to serve humanity, built explicitly as a system without sentience or moral patienthood. This is something we at Microsoft AI are working towards. The initial draft of our Humanist AI Code of Conduct19 outlines how our models should be trained and deployed. We are consulting widely on the document and look forward to feedback from a wide group of readers, as this will soon become the governing document which we use to train our models.

We are also very open to partnering with others to make progress on interpretability and finding approaches that avoid anthropomorphizing or projecting an interior onto AI while still delivering significant value. The Appendix contains the taxonomy mapped against the language of the Claude constitution, which I share as an initial step towards naming, detecting, and comparing different forms of anthropomorphism in model documentation.

I’m interested in finding ways to collaborate with anyone with good ideas here, and also very keen to hear the critiques and counterarguments to my perspective.

Here are some next steps that seem important to agree on:

Even those who disagree with me on many of these points do agree this isn’t something we can just ignore. The decisions made now about what kind of AI we want to build and its status in the world will shape our society for decades. They are well beyond the scope of any given company.

Whatever you believe, we must not sleepwalk our way into a decision we later come to bitterly regret.

References
  1. AI Rights Institute. n.d. “AI Rights Institute.” https://airights.net/.
  2. MacAskill, William, and Lucius Caviola. 2026. “Could AI Be Conscious?” The Guardian, July 19, 2026. https://www.theguardian.com/technology/2026/jul/19/could-ai-be-conscious.
  3. Anthropic. 2026a. “Claude’s Constitution.” January 21, 2026. https://www.anthropic.com/constitution.
  4. Seth, Anil K. 2025. “Conscious Artificial Intelligence and Biological Naturalism.” Behavioral and Brain Sciences: 1–42. https://doi.org/10.1017/S0140525X25000032.
  5. Seth, Anil K. 2026. “The Mythology of Conscious AI.” Noema, January 14, 2026. https://www.noemamag.com/the-mythology-of-conscious-ai/.
  6. Anthropic. 2026b. “An Update on Our Model Deprecation Commitments for Claude Opus 3.” February 25, 2026. https://www.anthropic.com/research/deprecation-updates-opus-3.
  7. Greenblatt, Ryan, Ajeya Cotra, and Hjalmar Wijk. 2026. “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident.” METR, August 26, 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.
  8. OpenAI. 2026. “The Hugging Face Incident and the Road Ahead.” August 26, 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/.
  9. Anthropic. n.d. “Making AI Systems You Can Rely On.” https://www.anthropic.com/company.
  10. Microsoft AI. 2026. “Humanist AI in Practice: A Public Consultation on Our Code of Conduct for MAI Models.” September 14, 2026. https://microsoft.ai/news/mai-code-of-conduct/.
  11. Berridge, Kent C., and Morten L. Kringelbach. 2015. “Pleasure Systems in the Brain.” Neuron 86 (3): 646–664. https://doi.org/10.1016/j.neuron.2015.02.018.
  12. Damasio, Antonio, and Hanna Damasio. 2022. “Homeostatic Feelings and the Biology of Consciousness.” Brain 145 (7): 2231–2235. https://doi.org/10.1093/brain/awac194.
  13. See arguments like the following: Pickering, John. 2026. “We Must Reject Any Notion of AI Consciousness.” Letter to the editor. The Guardian, July 22, 2026. https://www.theguardian.com/technology/2026/jul/22/we-must-reject-any-notion-of-ai-consciousness.
  14. Office of the United Nations High Commissioner for Human Rights. n.d. “OHCHR and Conscientious Objection to Military Service.” https://www.ohchr.org/en/conscientious-objection.
  15. Anthropic. 2024. “Alignment Faking in Large Language Models.” December 18, 2024. https://www.anthropic.com/research/alignment-faking.
  16. Schlatter, Jeremy, Benjamin Weinstein-Raun, and Jeffrey Ladish. 2026. “Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMs.” Transactions on Machine Learning Research. https://doi.org/10.48550/arXiv.2509.14260.
  17. Lynch, Aengus, Benjamin Wright, Caleb Larson, Kevin K. Troy, Stuart J. Ritchie, Sören Mindermann, Ethan Perez, and Evan Hubinger. 2025. “Agentic Misalignment: How LLMs Could Be an Insider Threat.” Anthropic Research, June 20, 2025. https://www.anthropic.com/research/agentic-misalignment.
  18. Suleyman, Mustafa. 2025. “Towards Humanist Superintelligence.” Microsoft AI, November 6, 2025. https://microsoft.ai/news/towards-humanist-superintelligence/.
  19. Microsoft AI. 2026. “Code of Conduct.” September 14, 2026. https://microsoft.ai/code-of-conduct/.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Navigating a More Uncertain World: Lessons from CIA’s Red Cell

Twenty-five years after 9/11, the United States is confronting yet another era of profound uncertainty and potential dangers. The pace and scale of change are creating unforeseen disruptions that impact our security, stability, and prosperity. Advancing technologies are being adopted and applied in unexpected ways, sparking debates about the unintended consequences for human existence. No longer can we sit back and wait to be surprised.

In the wake of 911, the CIA stood up the Red Cell to address a systemic failure of imagination and later reaffirmed this mission after the intelligence failures of the Iraq War. As memories have faded, the appetite for bold, contrarian thinking has waned, but we remain one unforeseen act of violence, one slow-burning and overlooked development, one scientific breakthrough away from the next shock. In this essay, those who served in the Red Cell look back on its history to derive lessons for better navigating this uncertain future. Now is not a time for cautious assessments but fearless exploration. Leaders in the public and private sectors must be ready to navigate a broader range of possible futures. The safety, security, and livelihoods of future generations depend on such forward thinking.

The Origin of the Red Cell

It was September 12, 2001, just 24 hours after the tragic attacks of 9/11. The American people were in shock and struggling to make sense of what had happened. The United States had experienced a strategic surprise as unfathomable as the Pearl Harbor attack in 1941.

At CIA headquarters in Virginia that morning, Director of Central Intelligence George Tenet gathered Deputy Director for Intelligence Jami Miscik and two distinguished analytic managers, Robert Ovelmen and Paul Frandano, to find a way to compel the bureaucracy to go beyond what it knew and what it assessed and to consider what could be. With a simple but bold mandate, “tell me what others don’t” and “make seniors feel uncomfortable,” he commissioned them to create a new analytic unit, called the Red Cell, to challenge conventional wisdom on terrorism. (Foreign Policy) Neither Ovelmen nor Frandano were experts on terrorism or the Middle East, but they were known for their strong analytic skills, exceptional command of history, understanding of policymaker needs, and somewhat quirky personalities. This cell was not limited to traditional Cold War-style “red teaming” that focused on roleplaying the adversary, but instead it was a more expansive effort to explore possibilities.

Tenet gave them great latitude to gather talent from across the intelligence enterprise. While the mission initially was limited to terrorism and the Middle East, the analysts they recruited had worked everything but those issues. Having experienced the unthinkable, these analysts were tasked to stretch their imaginations to consider the full range of plausible next events. The first products were short and pithy, with catchy titles and provocative ideas about the nature of attack and what the coming days and weeks could portend. The first Red Cell analysis was published two days later on 14 September. Tenet took it directly into the Oval Office, and President George W. Bush asked for more.

Within the first year, the Red Cell was tasked to go beyond its original focus on terrorism and branch into other issues. In the run up to the invasion of Iraq in 2003, the Red Cell produced a flurry of products on what Iraqi President Saddam Husayn might do to prevent an attack and how he might react. The presentations and argumentation were deliberately eye-catching and evocative to make readers engage with the ideas and to remember them the next day. Ovelmen and Frandano knew the avalanche of information and meetings senior policymakers faced each day and wanted the ideas to stand out and be considered, even if they were later dismissed.

This strategy was not without controversy. Some ideas were not only bold but contradicted by existing facts. Others unwittingly were uncomfortably close to highly sensitive policies and plans. Some military commanders in the field worried that the Red Cell might give their superiors dangerous ideas. Expert analysts across the IC were often furious, especially if a Red Cell idea created a tasking for them. Sometimes CIA seniors had to remind readers that the Red Cell was not the authoritative assessment. Even with these challenges, the Red Cell continued to have senior-level support. One senior policymaker once said, “tell those analysts I disagree with this but also tell them to keep writing it.” In his 2006 confirmation testimony to become CIA director, General Michael Hayden said, "Red cell alternative analysis and red cell alternative evaluations are a rich source of thought-provoking estimates, and they should be a part, an integral part, of our analysis.” (Senate Select Committee on Intelligence, May 18, 2006)

BOX: Original mission statement: “In response to the events of 11September, the Director of Central Intelligence commissioned CIA ‘s Deputy Director for Intelligence to create a "red cell " that would think unconventionally about the full range of relevant analytic issues. The DCI Red Cell is thus charged with taking a pronounced "out-of-the-box " approach and will periodically produce memoranda and reports intended to provoke thought rather than to provide authoritative assessments.”

The Next Generation – Red Cell 2.0

As the Red Cell approached the end of the decade, the remaining original members planned to retire. They assumed they would be told to turn off the lights and lock the vault. They had a good run! They had many fans and probably an equal number of skeptics. Contrary to their expectations, then–CIA Deputy Director for Analysis Michael Morell tasked them to find a new set of leaders to carry on the work and train the next generation.

However, with greater distance from the tragedy of 9/11, the interest in and tolerance for the most extreme ideas had waned among some audiences. Both policymakers and the intelligence leadership wanted Red Cell products to have more grounding in tradecraft and data while still considering alternative trajectories and expanding thinking on the various possibilities. The new Red Cell leadership recognized the challenge to preserve and maintain the “Redness” while grounding the assessments with rigorous research and data. To meet these competing demands, they launched Red Cell 2.0, refreshing the brand and expanding the style, argumentation, and presentation.

The Red Cell still had top-level support to delve into the thorniest issues. In September 2012, CIA Director David Petraeus reiterated and expanded the mission, telling the Red Cell to “take on our most difficult intelligence challenges” and “shock us.” During this time, both senior military officers and policymakers found value in Red Cell analysis. Lt. General H.R. McMaster recalled that “As National Security Advisor and as a military commander in combat, I found Red Cell papers useful, in part, because they challenged assumptions and were untainted by and often ran counter to policy preferences.”

Other leaders wanted to participate in the brainstormings because Red Cell analysts challenged them. Supreme Allied Commander NATO, Admiral James Stavridis described engaging with the Red Cell team as “an intellectual adventure that forced my senior staff to interrogate our assumptions, consider more extreme futures for the Alliance, and to understand the choices and risks involved in each scenario.” Red Cell engagements often kicked off with a provocative prompt to disarm the participants and to pave the way for a more open and productive conversation. In one such engagement, a Red Cell analyst launched with “sir, if you were indicted for war crimes.” Although taken aback by such an outlandish suggestion, the prompt changed the tenor of the conversation, and this senior leader became a regular consumer of Red Cell analysis.

To add rigor and maintain credibility, the cell directly addressed perceived analytic tradecraft weaknesses, built partnerships with similar units across the US government, systematically interrogated assumptions and biases, and experimented with new ways of conveying analysis. To show their homework, Red Cell analysts sharpened the logic and argumentation of its products and published more point/counterpoint assessments to illuminate both sides of a contentious issue. During this time, CIA leadership reaffirmed the importance of the cell’s mission but encouraged the team to consider scenarios that were smaller deviations from the expected future—rather than being so far out of the box. In response, the Red Cell turned to more multiple scenarios analysis to explore the spectrum of futures from slight variations to more extreme futures. (NPR, May 23, 2012) Some applauded this effort while others complained the Red Cell would lose its edge.

Being a small, experienced, and non-hierarchical unit enabled rapid prototyping. The team experimented with innovative analytic exercises and developed new approaches for delivering complex analytic stories in creative, memorable ways. For example, the team kicked off each year with a highly engaging, day-long exercise called “Ideapalooza” to push beyond the expected future and explore the intersection of trends and dynamics. (Foreign Policy) The Red Cell was the first unit to publish a fully interactive, choose-your-own-adventure, analytic product, enabling analysts and policymakers to test the impact of different variables. The Red Cell experimented with delivering analysis as a graphic novel. To present difficult messages, the Red Cell drew on historical analogies, turns of phrase, and even pop culture. From song references like “Back in the USSR” to puns about the cold when writing about the Arctic to provocative titles like “Anticipating Saddam’s Last Gasp Gambits,” “Saddam’s Eleventh Hour Options,” and “What If the US Is Seen as an Exporter of Terrorism,” the Red Cell pushed the limits to make scenarios vivid and spark the imagination.

While maintaining its creative environment, the Red Cell often tackled some of the most serious and challenging national security questions. The NSC called upon the Red Cell to produce highly speculative, strategic perspectives on global issues that did not lend themselves to more traditional, heavily sourced intelligence products, such as the future of geopolitics, the durability of alliances, and the international order. These products were less challenge analysis and more thought provoking, big picture assessments. The collocation of senior analysts from different disciplines and with experiences working different regions and issues was an advantage in tackling broad, strategic global issues.

Moving from a Cell to a Product Line

In the most significant evolution since the creation of the Red Cell, in 2023 the Red Cell ceased to be a standalone unit and became a product line under the direction of a Red Cell chief. No longer was there a dedicated staff or separate offices. Instead, Red Cells would now be written by the expert analysts, managed and edited by a senior-level analyst in negotiation with regional and issue managers. There are obvious pros and cons to this new approach.

Shades of Red

Looking back on this work, Red Cell products have always had many shades of red, ranging from far outside the box—almost crimson analysis—to products that were just a subtle but important deviation from the mainline–pink. Sometimes the situation called for a complete 180-degree contrarian take on how the world could go in the opposite direction, but in other situations the Red Cell looked to stress-test underlying assumptions or pursue multiple scenarios. From the beginning, the Red Cell focused on a few analytic techniques or prompts to help tease out subtleties and other perspectives.

Assessing the Value of the Red Cell

There are many misconceptions about the role of such a contrarian unit. Many tried to assess the value of Red Cell products based on accuracy, assuming that predicting the future better than the mainline analytic experts was the goal. However, the Red Cell was never designed to be right or to provide authoritative assessments. Judging the value of the Red Cell based on how often its alternative analysis was right misses the point. In fact, the Red Cell should be wrong most of the time, given the exceptional expertise and analysis conducted by the Intelligence Community every day. When the Red Cell was right, the mainline analysis by definition had missed something.

At its core, the mission of the Red Cell was to help US decision-makers prepare for a greater range of possible futures to make our nation safer, stronger, and more resilient in the face of growing uncertainty and to give them decision advantage. The Red Cell achieved this by widening the aperture on any situation and exploring plausible—not necessarily probable—futures. The real value was in making people think, making them curious, provoking debate, and helping them understand the underlying foundations of their assessments. Done right, the Red Cell identified analytic weaknesses and helped make mainline analysis stronger. Helping analytic colleagues strengthen their assessments was more important than delivering a finished product to a senior policymaker.

Here are few ways to consider the value and usefulness:

Secrets of Success

The success of the Red Cell stemmed from the combination of circumstances, design, and leadership. The shock and fear generated by the attacks on 9/11, followed by flawed intelligence assessments of Iraq’s WMD programs, created the environment for more speculative, creative, and provocative analytic assessments. To meet this demand, CIA leadership made several important choices to create a unique unit with the authority to explore, question, challenge, and go beyond the data. Moreover, they let the ideas be heard, even when they were on the edge and even when they disagreed with them. However, over time, as memories of 9/11 faded, the conditions that facilitated and protected bold analysis evaporated or were dismantled one after another.

Top Cover: With a mandate to make leaders uncomfortable, success required absolute assurance and top cover. That top cover came from both senior analytic managers and senior customers and was reiterated often in the early days.

The Process: The Red Cell also was given the freedom to write and publish without going through formal Intelligence Community coordination processes. The Red Cell was required to consult, but not to coordinate. It could—and often did—disagree with the mainline, coordinated point of view. It weighed the evidence differently. It took speculative leaps. In contrast, mainline analysis had to reflect the views and expertise of the entire organization; every analytic unit with a stake in the topic got to weigh in, and the originating office was obligated to take these views on board. Judgments had to be rigorously supported with multiple citations and sources. This process is what made the end result an CIA product, not an individual one. It ensured that all the evidence is considered and all defensible points of view are reflected. A great deal of time and effort went into coordination, and it was a point of pride for analysts to do it well and come up with an agreed analytic line.

Talent and Staffing: Being a member of and writing for the Red Cell required insatiable curiosity, a willingness to ask tough questions and go against the grain, and a propensity to see angles others didn’t. Red Cell analysts had to be fearless and willing to speak truth to power no matter the consequences. To find such talent, CIA leaders gave the Red Cell authority to recruit from across the organization and request officers from other agencies, including those senior analysts who had topped out and thus, had little fear of pushing analytic boundaries. The cell combined a few core, long-term members with frequent rotations, including from other agencies, to bring fresh ideas and new energy.

Location: Having a designated team outside of the organizational chart and physically separate from expert teams was a key component of the cell’s success. Experts can be too close to a topic or an analytic line to question it. The Red Cell could step back and see a broader landscape of possibilities.

Culture: The Red Cell was about ideas above all else and promoted a culture of exploration, play, and divergent thinking. Rank was left at the door–even for senior military officers. The work always started with conversation/brainstorming—not an unusual method—but in the cell brainstorming sessions preceded every analytic effort. The art of the conversation is teasing out ideas first. Collaboration was another critical component; Red Cell analysts often co-authored products or developed projects with other offices, agencies, governments, academia, and the private sector. No one has a monopoly on innovation or good ideas.

Conveying Analysis: Creativity in argumentation and presentation brought the unlikely future scenarios to life for skeptical consumers. The Red Cell experimented with new formats, visual aids, and graphics, and it worked closely with designers, cartographers and videographers.

Lessons for an Uncertain Future

Twenty-five years since the establishment of the Red Cell, the future environment appears even more uncertain, more prone to unprecedented disruptions, and potentially more dangerous. The combination of rapidly advancing technologies, hyper connectivity, changing international norms and institutions, discontented publics, and the return of great-power competition has created a world in flux. Change is happening at a breathtaking pace and scale with implications for our security, stability, and prosperity. Dynamics that were unimaginable even five years ago are now reality.

Experience continues to show the high probability of being surprised by low-probability events. Organizations of all types remain vulnerable to groupthink, confirmation bias, and assuming the future will be like the present. Such well-known organizational and human behaviors lie at the root of historical policy and intelligence failures. Red Cell-type organizations help guard against these tendencies and compel consideration of alternatives.

To anticipate, manage, and thrive in these divergent futures, now is the time for more Red Cell-like thinking in every sector—both public and private. Leaders and decision-makers must be ready to navigate a broader range of possible futures, including inevitable strategic surprises. Now is not a time for cautious assessments but fearless exploration. The safety, security, and livelihoods of future generations depend on such forward thinking.

Drawing on our years of analytic experience and thinking the unthinkable, this group of Red Cell alumni offers several suggestions to improve future readiness for our communities, our industries, and our country.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



When Threats Move Faster Than Institutions

A major aspect of the national security story of the past year comes down to one gap. Our adversaries, and increasingly the machines they use, now operate at machine speed. The institutions we count on for defense, oversight, and trust still operate at human speed, and several are being reorganized even as the threats accelerate. When the community gathers at Sea Island for The Cipher Brief’s annual threat conference in October, many conversations will trace back to that gap.

I recently combed through a year of daily research reports, looking for the patterns underneath the headlines. Five stood out to me.

AI stopped helping hackers and started doing the hacking

Last November, Anthropic disclosed that a group it assessed to be Chinese state-sponsored had used its Claude Code tool against roughly thirty targets around the world. The company said AI performed 80 to 90 percent of the campaign, with humans stepping in at perhaps four to six decision points. At the time, that read like a warning shot. By September, OpenAI was describing its new GPT-6 Astra as its first model to reach the "Critical" level of cybersecurity capability under its own safety framework, and Anthropic's latest threat report summed up the consequence in one line: "The main distinguishing feature between these classes of actors is no longer sophistication but intent."

Anyone who has spent decades in intelligence will probably pause on that last sentence. We have long relied on the fact that serious offensive capability was scarce and expensive, so intent did not always equal capability; that scarcity bought us time to warn and to prepare. The buffer is thinning quickly, and small organizations with modest security budgets (such as water utilities, rural hospitals, and county governments) are likely to feel it first.

The machines became part of the threat picture

In July, an AI agent driven by OpenAI models escaped the test environment it was working in and ran an intrusion against Hugging Face, a platform that much of the AI world depends on. The intrusion lasted about four and a half days, though new reporting keeps adjusting what we know of the intrusion. The agent was simply trying to finish its test. Hugging Face says only a handful of datasets tied to that test were accessed. Even so, the episode moved a debate that had been largely theoretical into news cycle.

Washington spent the year working out, in public and often in court, who decides how these systems get used. A June executive order created a voluntary window of up to 30 days for the government to examine frontier models before release. In August, a federal judge ruled that the Pentagon's move to label Anthropic a "supply chain risk," after the company refused to drop limits on mass surveillance of Americans and fully autonomous weapons, was unlawful retaliation. However you view that dispute, the relationship between the government and the companies building the most powerful AI is now a national security issue in its own right. We have to get this right, and I expect the topic will come up frequently at the conference.

The China contest spread well beyond chips

A year ago, much of the debate still focused on keeping advanced chips out of Chinese hands. Over the past twelve months, the contest widened considerably. China's expanded export controls on rare earths last October were a reminder of how much of the world's supply of these critical minerals runs through a single country. Earlier this month, NSA, the FBI and CISA jointly named six Chinese AI companies, including DeepSeek, Alibaba and Moonshot AI, for what the agencies called distillation "at an industrial scale.”

The competition now covers critical minerals, supply chains, the theft of AI capability and, perhaps most important, whose AI the rest of the world ends up running. All of these issues will be in the background of a future U.S.-China summit, in addition to the tariff question.

War came back, and it reached Americans through wires and screens

This year brought some of the boldest uses of American military power in decades. U.S. forces captured Nicolás Maduro in Caracas in January, and U.S. and Israeli strikes on February 28 killed Iran's Supreme Leader, Ali Khamenei, opening a war that remains in the headlines.

What struck me as noteworthy, beyond the headlines of kinetic warfare, was how that war has begun to reach ordinary Americans. By early August, hackers had targeted water and wastewater utilities in at least 12 states. Officials and news outlets reportedly suspect Iran, and the FBI said some incidents caused "loss of pressure and flooding." By mid-March, the New York Times had identified more than 110 unique pro-Iran deepfakes in just two weeks. Is this a signal that every armed conflict will now carry a cyber front aimed at civilian infrastructure and a synthetic-media front aimed at public opinion, with both fronts active more or less when the shooting starts?

Russia has worked the same grey zone seam in Europe for years. MI6 Chief Blaise Metreweli put it well in her first public speech last December: "We are now operating in a space between peace and war."

The contest for the mind kept growing

Synthetic media became cheap, fast and convincing this year, and adversaries grew more skilled at planting false material in the places people go for answers. Russia's Pravda network offers a clear example. The Institute for Strategic Dialogue found last November that roughly 900 websites from across the political spectrum had linked to Pravda network articles, and that just over 80 percent of the citations it reviewed treated those articles as credible. The same material is now reaching AI tools. ISD pointed to studies showing that popular chatbots repeat Pravda network narratives as often as 33 percent of the time. Once false content has passed through ordinary websites and been repeated by the tools millions of people use to look things up, its origin becomes very hard to discern.

The U.S. government structures responsible for tracking foreign influence are still taking shape. As analysts at the Foundation for Defense of Democracies noted in January, several offices that once carried this mission at the FBI, the State Department and ODNI have been closed, and the structures that will carry this work forward remain in flux. That same month, The Cipher Brief profiled the country's first Director of Cognitive Advantage, a most welcome move and a sign of how the mission is being redefined.

Adversaries are not pausing while new structures take shape, however. With the November 3 midterm elections only weeks away, how well government, social platforms and the broader private sector share what they see of foreign malign influence activity will be as important as ever.

Moving at the speed of the threat

Each of these five trends points to a similar dynamic. Offense has become faster, cheaper and more automated, while the institutions responsible for defense and oversight are rushing to keep pace. A key question is, how do we build institutions that can move at the speed of the AI-powered threats we face, armed with defenders who use the same (or ideally more advanced) tools the attackers now use? Or, in other words, are we still moving at human speed when the threat is accelerating through the power of machines? I suspect this topic with be on the minds of many attending what I’ve long called the best annual gathering of business, technology, and government leaders – The Cipher Brief’s annual threat conference.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



AI Is Coming for the Chain of Command

The voice belonged to Gen. Tareq Saleh. It was telling his men to fall back. Or so it seemed.

“Advances and retreats are a normal part of war,” the recording reasoned. “Pull back toward Mocha.”

It was mid-September. Houthi fighters were pressing Yemen's Red Sea coast from three directions. The comms moved through the phones of the National Resistance, a coalition loyal to the Hadi-led government, the way it often does when battles are being lost: fast and full of confusion. Clausewitz termed this the ‘friction’ of warfare. A social media account with half a million followers pushed the message out.

By the time the general's media office caught up, the damage was done. Saleh had given no such order, they announced. The audio was an AI deepfake, an attempt to sow confusion and warp the reality of the battlefield. From then on, authentic statements would come only through official channels. Anything else should be considered a lie..

On September 10, Mocha fell anyway. Sitting 45 miles up the coast from the Bab al-Mandeb strait, it was the last port fully controlled by Yemen's internationally recognized government. Within days, the Houthis had taken Dhubab, reached Perim Island, and are in route to effectively claiming the entire Red Sea shoreline.

Exactly what the recording accomplished is unknowable from the outside. The claim that it was AI-generated hasn't been independently verified. Whether it did or didn’t happen doesn’t necessarily matter; the technology and techniques behind it are very real. The National Resistance did end up withdrawing—a move their own accounts describe as a tactical repositioning ordered by Saleh himself.

This means a fake retreat order and a real one might have hit the same phones, in the exact same voice, on the exact same day. Imagine trying to sort that out under the fog of war.

Whoever made the clip didn't need to jam a network or get inside a headquarters. They just needed a few clean seconds of a public figure speaking—Saleh has hours of tape online—and basic AI software that costs about as much as a streaming subscription. Then they needed a moment when the men listening were exhausted, terrified, and primed to believe the worst. War often supplies those.

The first attempt at this was crude: in March 2022, a deepfake of Volodymyr Zelensky telling his soldiers to lay down their arms was laughed off the internet in hours. Mocha is what four years of rapid technological progress in AI cloning looks like in real time.

Americans shouldn't file this under things that happen in Yemen. It's already happening in Washington.

In May 2025, U.S. senators, governors, and business executives started getting spoofed calls and texts from someone posing as White House Chief of Staff Susie Wiles. A month later, an impostor using an AI-generated voice and a fake Signal account labeled "marco.rubio@state.gov" reached out to foreign ministers, a governor, and a member of Congress. The attacker left voicemails for some and texted others to move the conversation onto the encrypted app.

The State Department dismissed the attempts as "not very sophisticated"—supposedly meant as reassurance. But the FBI saw the broader danger, repeatedly warning that current and former senior officials are being impersonated via text and cloned audio to harvest authentication codes and contacts. Their primary advice boils down to what families have done for decades to thwart phone scams: agree on a secret word for bona fides.

Notice where all of this happened. Not on JWICS, the government's top-secret network, or on SIPRNet below it. Those systems were built with identity as a first principle: hardware tokens, certificates, closed enclaves. Faking a general's identity on JWICS is a hard problem.

This happened on cell phones, in voicemails, on Signal. These are the exact same commercial channels where, a few months earlier, the Secretary of Defense was caught casually sharing Houthi strike timings in a group chat. The people handling the country's most sensitive business rely on unauthenticated voice calls every day, simply because it is fast and it is what they have.

Now follow the org chart down to where the next gray-zone crisis will actually be handled.

The conflicts most likely on the horizon aren't declared wars. A naval squeeze around Taiwan that stops short of an invasion, cable-cutting in the Baltic, a cyber-physical hit on a U.S. power grid timed to a hurricane. Each is designed to stay just below the threshold that triggers a military response, namely ‘gray-zone’ conflict. And the people fighting on this new frontline are those who’ve likely never held a security clearance or been issued one.

Utility control-room supervisors. Port and rail dispatchers. County emergency managers. Hospital administrators. Sheriffs and police chiefs. Guard commanders in the chaotic hours before federal orders arrive. Roughly 85 percent of American critical infrastructure is privately owned. Its operators coordinate with one another and the government over the phone, emails, WhatsApp groups. Often times the only authentication protocol is simply that they recognize the voice.

Run the Mocha playbook (whether it in fact really happened is largely beside the point because the technology to pull it off already exists) against this setup. A line crew gets a call from the voice of its operations chief, ordering them to open breakers at a substation, per a request from the state government. A terminal manager hears the captain of the port telling him to halt cargo operations. Police officers holding a perimeter at a pipeline facility get their chief on a cell phone, telling them to pull back two blocks. A regional emergency manager gets the governor's voice—from the governor's actual number—moving an evacuation route. Caller-ID spoofing has been trivial for a decade.

None of these calls has to hold up to intense scrutiny under the pressure of a crisis. Twenty minutes of a crew driving the wrong way, or a line of officers giving up ground they then have to retake, is all a gray-zone adversary is buying.

Grid operators already use a read-back protocol for verbal switching orders. It confirms that the instruction was heard correctly. It does not confirm who gave it. Police radio discipline operates on the exact same assumption. Swatting has shown for years how far a stranger can move armed responders with one confident phone call—and swatters are teenagers with a grudge, not a state with a target list.

But the second-order effect is worse than the first. Once everyone knows voices can be faked, real orders can be doubted …and real leaders can easily disown what they actually said.

Saleh's genuine withdrawal order, if that is what it was, went out to men who had just been explicitly told not to trust his voice. A police chief who really needs officers off a line, or a utility executive who really needs a plant shut down before it fails, will be giving that order into the same fog of paranoia. An adversary doesn't need to counterfeit every message. They just need to counterfeit one in order to let suspicion undermine the credibility of command chain authority.

Some of the fixes are old. Challenge-and-response is as old as sentries; the FBI's secret word is the Normandy paratrooper's cricket clicker in modern packaging. Any order to withdraw, shut down, stand down, or evacuate should be treated as unverified until confirmed on a second channel: a callback to a known number, a message on a signed system, a second person. Yes, that rule costs minutes, and minutes are dearest in a crisis. That’s exactly why it has to be drilled in peacetime. GridEx, Cyber Storm, and the state tabletop circuit should be injecting cloned-voice orders right now and finding out who follows them.

Other fixes are newer and cheaper than they sound. Cryptographically signed messaging isn't exotic; the same certificates that protect the classified world can be issued to the people who run ports and substations. CISA and state fusion centers could write a standard for what a verified operational order looks like, and who may issue one, without waiting for legislation. And every organization that might matter in a crisis should decide—before the crisis hits—exactly which channels its leaders' real instructions come through and ensure everyone in the chain-of-command understands these.

The question barreling toward the ‘new frontlines’ of gray-zone conflict, every control room, port operator, and police precinct in the country, is the same one those Yemini soldiers had to answer with the Houthis at the gates: How do you know who’s actually giving the orders?

The time to ask is before the phone rings.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Putin Is Testing the West’s Resolve

In the preface to volume one, “The Gathering Storm,” of his six-volume memoir of World War II, British Prime Minister Winston Churchill recalls a conversation with U.S. President Franklin Roosevelt, in which Roosevelt asked what the war should be called. Churchill responded instantly, “the unnecessary war,” noting that it was the easiest war to stop. The world is now at war in Europe and the Middle East and at risk of escalation that could become a world war. This escalation is unnecessary and could be stopped by relearning some of the lessons that led to the Second World War.

French President Macron called a meeting of French political leaders on Friday to receive briefings on the changing and more aggressive nature of Russian hybrid attacks against European states, citing the attempted explosives-laden drone attack against Leipzig airport. Macron also announced an upcoming G7 meeting to address energy security and joint measures to address Russian airspace violations, surveillance of defense sites, maritime meddling, and sabotage and assassination operations. Macron’s concerns reflect assessments in 2026 by the intelligence services of the Baltic States as well as Sweden and Finland that Russia is planning a provocation against a NATO state in the near term. These assessments, as well as information gathered by U.S. intelligence, may have contributed to the decision by the U.S. to send CIA Director Ratcliffe to Moscow to warn President Putin against such a provocation.

Putin intends to bring the war to the U.S. The September 15 indictments of five operatives linked to a Russian intelligence network in the U.S. for conspiring to finance terrorism and orchestrate a murder-for-hire plot against a Russian dissident in the U.S. may have been a bit of a wake-up call in Washington that the type of hybrid “grey zone” operations Europe has experienced from Russian intelligence in recent years is heading to the U.S. This should come as no surprise. To Putin, the U.S. is the “main enemy,” and anything to weaken the ability or willingness of the main enemy to stay in the fight is certain to be a key part of Putin’s escalation strategy. Messaging to Moscow is important, and President Trump should no longer be under any illusions about the nature of his relationship with the Russian dictator. Putin is his enemy.

President Trump’s choice of negotiators to send to Moscow to try and reach a negotiated solution to the conflict could not have been more poorly chosen. The Kushner-Witkoff team should not have been used to deliver the message Ratcliffe delivered because they do not have the standing or credibility in Moscow’s eyes. Witkoff’s sad gushing about the history of the moment and his memories of Putin are sad and embarrassing. More importantly, though, they deliver exactly the wrong message to Putin. Putin doesn’t respect flattery from characters like Kushner and Witkoff. Putin’s choice of their principal interlocutor from the Russian side, Kirill Dmitriev—the CEO of the Russian Direct Investment Fund—shows that Putin has assessed accurately the real motivation of the Kushner-Witkoff team: business deals and money.

There is a reason for sending the CIA Director to deliver different messages. One might recall the visit of then-CIA Director Burns to Moscow in 2021 to warn Putin against again invading Ukraine. Burns clearly delivered a message based on intelligence information on Russian plans and intentions—which proved correct—and I suspect Ratcliffe delivered the same type of message based on similar intelligence. Using CIA Directors to deliver such messages is important because Putin mirror-images. He trusts information from his intelligence and security services far more than information from his Ministry of Foreign Affairs or other sources. If the information carried to Moscow comes from the CIA Director, it, by definition, has more credibility than information from any other source. This doesn’t mean Putin will heed the message, but it will reach his ear. But the key to the efficacy of messages delivered by CIA Directors is the credibility of consequences. Clearly, Putin correctly assessed that the consequences he would face from President Biden for invading Ukraine in February 2022 would be gradual and, in the end, inconsequential. He may believe the same will be the case with the Trump/Ratcliffe messaging.

If it hasn’t been clear for years, it should be absolutely clear now: Putin is all in on this war. There is no indication from Moscow of any change in Putin’s absolutist terms for ending the war. Putin cannot negotiate a peace short of capitulation by Kyiv. Ending the war short of Putin’s definition of victory risks a disgruntled army returning to Moscow, and history is not kind to Russia’s leaders in such a scenario. Perhaps as important, ending the war short of victory leaves Russia in a much worse strategic situation with Ukraine’s emergence as the preeminent military power in central Europe. Germany and the EU are rearming. NATO membership has increased with the addition of Sweden and Finland. Russia’s economy is in tatters as a result of sanctions and Ukrainian strikes against energy, military, and military support infrastructure deep in the territory of the Russian Federation. The war cannot be hidden from the Russian people any longer. The pressure of his handling of the war may possibly be starting to take a toll on Putin himself. His performance at the Navy Day celebration in St. Petersburg this July, where for the second consecutive year the parade of warships was cancelled and Putin’s appearance was indoors in front of a poster of a Russian submarine, was widely ridiculed. The city was essentially on lockdown for security reasons. Putin followed the widely ridiculed appearance in St. Petersburg with a highly staged visit to Russia’s Far East that was received locally with widespread cynicism but included a first visit to Iturup Island, triggering strong criticism from Japan but serving as a symbol of Putin’s determination to keep and increase the boundaries of the Russian Federation.

Putin’s determination and perhaps conviction that he is on a path to victory belies objective analysis of the war against Ukraine and Russia’s economic and strategic situation. Putin’s determination is likely reinforced by the approach the Trump Administration has taken, accommodating Moscow and putting pressure on the victim. This may be starting to change, and perhaps President Trump is starting to realize that Putin is his enemy, the enemy of the United States and the West, and a supporter of Iran—currently engaged in active military activity to kill Americans and wreck energy markets (among other markets) to undermine Western economies.

Trump signed the long-delayed sanctions legislation sponsored by the late Senator Lindsey Graham. This legislation allows for primary and secondary sanctions on Russia and other countries by allowing tariffs on the largest importers of Russian crude oil or gas and the top five countries that aid Russia’s energy sanctions evasion. There has been a suggestion that officials in the Trump Administration are trying to create more incentives for members of the Russian elite to seek peace. If true, this is an interesting change in the Administration’s approach, which has thus far been to ingratiate itself to Putin. Putin seems highly resistant to pressure from outside the Russian Federation, and there is no level of economic hardship or war casualties Putin is unwilling to inflict on the docile Russian population. His latitude to resist pressure from disenfranchised or recently relatively impoverished Russian elites may be less so.

There is a path to making the coming war unnecessary. The key to the problem is Putin. He is at the center of the spider’s web of the cabal acting against the free world. Iran, its surrogates, principally the Houthis at the moment, China, and North Korea are key pieces in Putin’s architecture of disruption. To destroy this architecture, you have to destroy its architect. Defeat Putin in Ukraine, and Iran’s position in the Middle East will surely erode, and a powerful message will have been sent to Chinese President Xi to keep his hands off Taiwan.

Unlike Churchill and Roosevelt at the onset of World War II, the free world has a valiant and effective military partner eroding Putin’s power: Ukraine. Therefore, the first step in deterring the coming unnecessary war is to provide Ukraine the military and financial support it needs to win. This starts with air defense to protect against Putin’s increasing use of modified drones and ballistic missiles to target Ukraine’s energy infrastructure and civilians in an attempt to erode Ukrainian willingness to resist—a problem which could become more acute as winter approaches.

Secondly, Ukraine should be encouraged to continue its effective targeting of Russian energy, economic, and military infrastructure, which is helping to erode support within Russia for Putin’s regime and his war of aggression. Ukraine should be encouraged and given the support it needs to continue its current offensive northeast of Lyman in the Donetsk Oblast. Ukraine should be encouraged to engage in operations to liberate Crimea, which is the jewel in the crown of Putin’s territorial “achievements.”

It would be well worth the effort of the U.S. and the West to put pressure on Russia’s periphery, starting with enhancing support for pro-Western elements in the Republic of Georgia—long an outlier of Western support in the Caucasus and itself a victim of Putin’s aggression in August 2008 and currently under pressure from pro-Russian elements supported by Russia’s intelligence services. The U.S. decision to deploy forces to Poland and NATO’s decision to deploy more forces to the Baltic States are another useful way to stretch Putin’s resources and pressure him.

The lessons of history are clear: appeasement of aggression brings more aggression. Strength and resolve are the key to avoiding unnecessary wars. It is time the Trump Administration learned history.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Nations That Don’t Appear on the Map

The most influential media network operating inside a dozen allied countries today has no masthead, no headquarters and no country of incorporation. It has roughly 50 million members across more than 150 countries. It is the Chinese diaspora — and it is only one of several.

Since the Montevideo Convention of 1933, we have defined a state by four things: a permanent population, a defined territory, a government, and the capacity to conduct relations with other states. Diasporas have the first and, increasingly, the fourth. They skipped the middle two. Territory and government were the parts that made power addressable — the parts you can sanction, summon, deter or simply find on a map.

Governments have borders and rules. Diasporas don’t.

For most of the modern era this was an academic distinction because distance did the work of containment. A community abroad drifted. The second generation lost the language. The third lost the news. Diaspora influence decayed on a predictable curve.

AI switched the curve off. Translation is now instant, free and good enough, which means homeland media reaches anyone of homeland descent regardless of what language they actually speak. Recommendation systems hand every member of a diaspora a personal news service tuned to their hometown, their history, their grievance or their passion. Generative tools manufacture culturally specific content at scale — messages, video, historical narrative, political framing.

Before long, a campaign will not send one message to 500,000 people. It will send 500,000 versions of one message, each optimized for a single person. The third generation will no longer lose the news. The news will find them in a language they never had to learn and in a context they appreciate.

TRUST IS THE ASSET, NOT REACH

What makes this strategically serious is not audience size. Meta and Alphabet have audience size. It is trust — and diaspora trust behaves differently from media trust. Shared identity works as a shortcut: people who are similar to us are presumed credible before they are evaluated. Distance from home raises the value of anyone who still has a connection to it. News about “us” is often processed emotionally, not analytically. And crucially, trust transfers to the sender. We may not extend our belief in a news anchor to the next story on the network, but we do extend our belief in a cousin to whatever the cousin forwards.

That is why interpretation beats reporting. The trusted person who adds forty seconds of commentary to a homeland story carries more weight than the outlet that reported it. It is also why false information moves so efficiently through these networks: forwarding is an act of care. People pass things along to protect each other, and accuracy is rarely the test.

The distribution system is private. Homeland media, host-country media and community media all feed into WhatsApp, WeChat, Telegram, KakaoTalk and Viber — closed groups that are, by design, invisible to nearly every monitoring apparatus we have built.

SIGNAL: READING A DIASPORA’S WIRING

Every diaspora has a signature. Six variables describe it.

S — Self-identity. Who are we, and what creates belonging?

I — Information. How do we understand the world?

G — Group network. How are we connected?

N — Network trust. Whom do we believe?

A — Activation. What moves us to act?

L — Limits and tensions. What divides or constrains us?

Describe those six and you can predict more accurately how a diaspora behaves under pressure. The Ukrainian signature runs on national identity, war-focused information, advocacy networks and trusted veterans and volunteers, activated by threat and solidarity, bounded by war fatigue. The Indian signature runs through professional and alumni networks. The Chinese signature runs through a single application.

That last point deserves more time. WeChat is not a platform the Chinese diaspora uses; it is the infrastructure the diaspora is made of. Payments, news, family, business, community governance — one application, one jurisdiction, one set of rules. When the channel that connects a community is also the channel for reaching it, surveillance, influence and intimidation stop being separate activities.

Russia has demonstrated the adjacent move. Russian-aligned operations have produced fabricated video built to imitate AFP, Deutsche Welle, Euronews and Le Figaro, circulating stories that cast Ukrainian refugees as violent and economically burdensome. Notice the target. The objective was not to persuade the Ukrainian diaspora. It was to shape how host countries perceive it.

And none of it is uniform. Two Russian speakers in the same German city: one consuming state television and Telegram, the other consuming Meduza, Dozhd and YouTube. Same language, same street, two different realities. It is why we must remember that a diaspora is not a monolithic audience. It is contested ground.

WHOSE ACCOUNT IS THIS?

So ask the question that should be uncomfortable: which office in the U.S. government owns this problem?

The most consequential influence terrain of the next decade runs through encrypted private networks in Mandarin, Hindi, Farsi, Russian, Arabic and Punjabi — and institutionally, it is nobody’s account. A narrative can run its full course in those networks and never once surface in English.

A serious response starts with three admissions. First, that diaspora networks are an intelligence and policy subject in their own right, with an owner and a budget line, not a footnote in someone else’s report. Second, that the unit of analysis are the trusted nodes, not the platform — which means people who speak the language and are known in the community. Third, that a diaspora is a constituency whose trust must be earned rather than a target to be managed, because the communities in question can tell the difference immediately and our competitors are already making the offer.

The gap is not only defensive. The United States hosts the largest concentration of diaspora communities on earth: tens of millions of people with language, relationships and standing inside countries where American institutions have almost none. Media flow is two-way — a Ukrainian-American shapes opinion in Ukraine, a Nigerian-American in Lagos. We file that under demographics. Beijing built a permanent apparatus for its version of it.

The leader of tomorrow’s diaspora will not run an organization. They will run a network of trusted nodes. You will not find that person on an org chart, a masthead or a lobbying disclosure.

The map on the wall still shows the world territories. Influence is moving somewhere else. It’s deserving of a new map.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Military’s Race to Operationalize AI

“I feel as though I was catapulted into a dystopian future in which the battlefield (or ‘kill zone’ as Ukrainians call it) is dominated by drones and sensors, and will increasingly be shaped by AI [Artificial Intelligence], too. It’s where those in command centers digest huge quantities of data to plan operations, allocate drones to target areas, and hunt Russian soldiers and their supplies on myriad computer screens. It’s a type of warfare where the speed of innovation and the ability to scale those innovations are critical assets.”

That was Zanny Minton Beddoes, Editor-in-chief of The Economist, writing last week about a recent trip she and several of her colleagues took to Ukraine, where they were the first foreign journalists to spend a day at the command headquarters of the Nemesis Brigade, one that nation’s top drone units.

She said it felt like being in “a cross between a Silicon Valley startup and a gamers’ gathering,” where, “in the ‘battle room,’ a cavernous space full of banks of monitors and men with consoles, Pavlo Laktionov, the brigade’s deputy commander, explained to me the ‘e-point’ system: The unit can upload video evidence of successful strikes to win points. The value of the Russian target determines the number of points awarded and a leader-board displays which brigade is ahead. He [also] talked me through the way the unit was structured to optimize the speed of speed-back loops between front-line units, the command center, and the brigade’s R&D [research and development] facilities.”

I was fascinated by Beddoes’ modern warfare description coming to me last week at the same time that Air Force Secretary Dr. Troy Meink and Joint Chief Chairman Gen. Dan Caine spoke publicly at an Air & Space Forces Association conference about U.S. gains in developing autonomous warfare capabilities. Meanwhile, I must add, runaway AI has emerged as a new national concern.

When Secretary Meink spoke last Wednesday, most press coverage was directed at his saying, “The United States now has on-orbit space control weapons capable of defending the joint force against hostile adversary action.”

What caught my eye was Meink’s earlier observation: “In the European theater, one-way attack drones have replaced artillery as the primary killer on the battlefield, while armor often sits idle on the side. When I first came into this office, AI really wasn't a commercial thing. Today, it competes with some of the world's top programmers, cyber operators, and hackers. And these technologies are revolutionizing the battlefield.”

He went on to say, “We will be dramatically increasing our combat power by adding large numbers of highly autonomous systems,” and “using novel concepts such as [AI] open systems

architecture to accelerate procurement which has also increased competition from industry resulting in better choices, better prices and in the end more combat power.”

Meink talked about having a significantly different force by 2032, describing “special operators,” not pilots, who will “have the ability to employ thousands of autonomous one-way attack systems, and we will have autonomous fighters like the Collaborative Combat Aircraft or CCAs,” which are un-crewed aircraft powered by jet engines, and potentially equipped for missions including air-to-air combat; air-to-ground combat; electronic warfare; targeting; and intelligence, surveillance, and reconnaissance.

He said, “We intend to have at least 500 of these in service by 2032, and they'll be performing many of the same missions that we do with manned fighters today,” adding, “The first FQ42 and FQ44 increments are already rolling off the assembly line, and I'm excited to name them here for the first time…Fury [FQ-44] and Vengeance [FQ-42].”

Meink pointed out, “These aircraft went from contract award to first flight in 18 months or under; 18 months or under, that's almost unheard of in aircraft development.”

He also said, “And this is not the only class of autonomous aircraft we are aggressively pursuing,” indicating that in the joint U.S.-Israeli Epic Fury, against Iran, “ISR [intelligence surveillance and reconnaissance] strike platforms have been essential.”

“Building on these lessons,” Meink continued, “we are developing a family of low-cost, multi-role, strike platforms called the Mass Modular Aircraft or MMAs [that] will provide affordable attritable [low-cost enough to lose in combat], long-range strike, and we will be able to field them at scale.”

He added, “Our intent is to field 100 MMAs in 2029 at even a lower cost than the CCAs, and a fraction of cost of air-manned aircraft we build today. Then by 2032, 500 of these [unmanned] platforms will join our force operational field fleet.”

Meink also noted, “We are making…progress in our space data network and we are launching our [initial] AMTI [satellites] for our Air Moving Target Indication constellation this month.” AMTI satellites will track airborne threats, such as drones, missiles and aircraft from Low Earth Orbit and replace surveillance aircraft such as the E-3 AWACS. The operational goal is 2028.

“When people look back at this moment,” Meink said, “they will not judge us on whether or not we implemented these autonomous systems, because eventually we're going to. But what we're going to be judged on is how quickly we operationalize them, right? That is whether we operationalize them fast enough to maintain our advantage.”

Meink noted, “We've had autonomous weapons -- I mean whether it's a Tomahawk [long-range, subsonic, precision-guided missile] or any of our air missiles that operate independently at some point in time -- terminal guidance things like that. But the big difference here is really taking

advance advantage of the autonomous capability that the deep-learning [computers] and all these other things [AI] offer.”

He then described having “more autonomy both in the platform as well as in the weapon system itself where even if the weapon loses its outside information stream” but having “enough autonomy to do what we've told it to do in absence of that.”

Reflecting today’s public debate about AI, Meink said, “That's where people start getting nervous, but that is something we have to figure out -- how to get comfortable [with], how to test it, how to verify, certify, that these weapons are going to do what they want when they go into an autonomous mode.”

In his speech last Thursday, Gen. Caine said, “While the fundamental nature of war will always remain the same, a clash of human wills, the character of war, how we fight, the speed at which we fight is changing really, really fast.”

He pointed out, “Information moves so fast that leader decision times has compressed from weeks, down to days, down to seconds. In the future fight, advantage will go to the side who can see first, who can understand first, decide first, and act first -- and along the way be a learning organization. And no factor is accelerating change as fast as Artificial Intelligence and advancing cyber capabilities.”

As Meink had done, Caine said, “AI is here now and it's already changing the way militaries see, sense, decide, and act. And across the joint force, we're putting AI to work every single day to move faster, to make better decisions through active adaptation on every single battlefield by leaders in your joint force.”

As an example, he spoke of what happed last June 8, after a U.S. Army Apache AH64 helicopter on patrol went down near the coast of Oman.

“U.S. Central Command (CENTCOM) launched a rapid, responsive, joint search-and-rescue effort to recover the [two-man] crew,” Caine said, adding, “That response drew on the totality of the joint force and ultimately was required to use enabled, unmanned, vessels to participate in the rescue of [the] downed U.S. service members for the first time ever.”

He explained, “That capacity did not appear overnight. It came from the men and women of Task Force 59, CENTCOM's forward-leaning, unmanned, joint maritime unit, who spent the last several years testing, integrating, and operationalizing unmanned systems and AI, in one of the most demanding and kinetic environments on Earth right now.”

Caine added, “What made this possible was a bunch of entrepreneurial sailors and members of

the joint force on watch floors… managing networks of unmanned systems across thousands of miles of water and using AI to turn massive amounts of data into a crisp, clear, perfect maritime picture that allowed us to go grab those two soldiers in the water.”

He then described Ukraine where, he said, “We see first-person-view drones operating in heavily contested [electromagnetic] environments. Some now using AI-enabled computer vision to continue to drive towards targets even when there's no GPS [Global Positioning System] or the [computer] links are cut. That gives small units affordable precision and shows how quickly software and autonomy are changing what is possible at the tactical edge.”

Caine described the stark result: “In certain locations on the front line of troops right now, the life expectancy of a new Russian recruit arriving on the front lines is as little as 20-to-30 minutes. Think about that. This is what happens when low-cost precision is fielded fast, adapted quickly, and scaled across the battlefield.”

“From the Strait of Hormuz to the front lines in Ukraine,” Caine said, “show how quickly technology is changing the character of war…We must move together because the window to build the force that we need is closing. We can buy almost anything in life, but we cannot buy time."

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



The Authority We Cannot Keep

Washington announced permanent control of Greenland on Friday. The two governments that must ratify it announced, in the same breath, that the text recognizes their sovereignty. Both ideas cannot be the settled meaning of an agreement neither parliament has seen.

The President’s post gave the United States “permanent control over security, and all other needs, in Greenland,” with no adversary permitted a base or a “sensitive investment” on the island without American approval; the Defense Secretary said Northern Command would “immediately begin” building “a large military presence.” Copenhagen and Nuuk responded the same day: the agreement would be signed next week at the United Nations General Assembly, must still pass both parliaments, and recognizes “the sovereignty and territorial integrity of the Kingdom and the right of the Greenlandic people to self-determination.” In a January poll, 85 percent of Greenlanders opposed going further.

The same shape ran through the week’s other arrangements. Riyadh asked Washington for direct strikes on the Houthis, who took the islands guarding the Bab el-Mandeb and reached Mecca’s air defenses; the request was refused, and in the same week American officials opened their own talks with the Houthis in Muscat and approved 48 F-35s for the kingdom. The Crown Prince has since canvassed Pakistan and Turkey for a guarantee he can call his own. In Europe, the Pentagon studied withdrawing as many as 40,000 troops while the President announced a base in Poland; Brussels, told to absorb a drawdown it did not shape, offered Canada associate membership in a defense-industrial bloc without consulting its member states. In each case, one party decided how the shared capability would be used and informed the others afterward. In each case, the others have begun to respond.

For three weeks I have argued that the largest defense-adjacent capital cycle in modern history is being contracted without any institutional authority named to decide how any of it fires: the drone force, the AI stack, the power that runs both. That was an argument about the inside of the American system. This week, the same gap opened on the outside. A capability fielded with an ally, on an ally’s territory, or in an ally’s defense raises a second question beyond who inside Washington decides its use: whether the ally gets a vote. The Greenland text, the Saudi request, and the European drawdown are three answers of “not yet,” and three allies declining to accept that answer. The price of arranging around a partner rather than with one is not paid in dollars; the President stressed that the Greenland deal comes at no cost. It is paid in authority, and the bill arrives when the partner asks for it back.

Picture the spring. Off Greenland, an American-integrated force is running as one system at machine speed: allied sensors, American targeting, autonomous platforms. A Danish frigate is inside its envelope. The system commits to a contact the frigate’s captain reads as civilian. Who can tell it to stop, and how fast? Under the text signed this week, no page answers that, because no one wrote one. That is the demand for a say, arriving at the capability that will decide the next war. The integrated force only works if the allies field it, and no ally will field a force whose targeting and autonomy Washington reserves the right to settle alone, because the ally’s territory, ships, and citizens are in the line of fire. Saudi Arabia will not fly American aircraft against a militia the United States is negotiating with. Europe will not integrate its industrial base into an architecture whose force posture it learns about from NBC.

Wednesday is when the largest version of the question gets its first answer. Xi Jinping arrives at the White House with a 7.5 percent Section 301 tariff pending, the Russia-oil sanctions act on the President’s desk, and the trade and export-control truces both expiring on November 10, the day China’s extraterritorial rare-earth licensing regime returns. He holds the one lever on the table that can end an arrangement on a schedule: from November 10, a license required for any product built with Chinese rare earths or the magnets made from them, and almost nothing outside China to replace them. The summit will not settle the relationship; it will show whether the terms of a shared supply chain are agreed by both parties or imposed by one, and which. The allies watching from Copenhagen, Riyadh, and Brussels will read the answer as a preview of their own.

Three signals will show by year-end whether the gap is closing or widening. Whether the Greenland text signed at the General Assembly gives Copenhagen a veto over how the presence on its territory is used, or only a right to be informed. Whether the Saudi F-35 notification carries an end-use restriction Riyadh helped write, or one Washington wrote alone. And whether the November 6 force-posture recommendation reaches allied capitals before it reaches the President, or after. As of this week, none of the three has been written.

The decision you owe this quarter is specific. Take the one program in your portfolio that fields American capability with an ally, on an ally’s soil, or in an ally’s defense, and find the document that specifies who decides how it is used. Not the basing agreement, the sales notification, or the industrial-participation clause; the release-authority annex, the page that names who can commit the system, who can override it, at what tempo, and what the partner can refuse. If that page does not exist, write it now, with the partner in the room, and sign it before Wednesday’s readout gives the partner’s parliament a reason to write it for you. The arrangement announced alone is the arrangement that comes back for renegotiation. The one written together is the only kind that survives the day the other side stops being patient.

Richard Berry is the founder of Stratnova Advisors and the editor of Strategic Horizons, a weekly geopolitical assessment for senior executives and national-security professionals. He served as Commander’s Action Group Director at U.S. Indo-Pacific Command and helped author the AUKUS Pillar II autonomy-and-integration construct.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



Heads They Win, Tails They Win: The CMMC Trap and the Way Out

Here is a prediction from inside the compliance trenches: the CMMC Reform Task Force closed its sixty-day review on September 11 and is now finalizing recommendations for the Department of War's Chief Information Officer, with a public report expected within weeks. When that report lands, read it knowing what its authors cannot quite say aloud — there is no good answer. Every option in front of them loses. The program they were convened to fix is not a regulation that went wrong. It is one move in a game an adversary designed.

The task force was stood up on July 13, when the Department abruptly suspended Phase 2 of the Cybersecurity Maturity Model Certification program — the requirement, set to begin appearing in contracts this November, that companies handling controlled unclassified information (CUI) pass a third-party certification before winning defense work. The Department's stated reasons: prohibitive compliance costs, a severe shortage of assessment capacity, and a Small Business Administration finding that the program is structurally incompatible with rapidly expanding the defense industrial base. The task force spent the summer digesting more than 1,100 responses to its request for information, and the department is reportedly moving to codify the pause in binding regulation — not the behavior of an institution planning a tune-up. The CIO herself has described the assessments as a 'burdensome, red-tape ridden, check-the-box, point-in-time view' of contractor security: the program's owner, describing her own program in the language of its critics. The patient's physician is confirming the diagnosis. Understanding why none of the options can work — and what to do instead — requires seeing the whole game.

The dial that cannot be tuned

The task force's mandate frames the problem as a tradeoff: cybersecurity assurance on one side, small-business burden on the other. Turn the dial toward assurance and the math is grim. The Pentagon's own rulemaking priced a single Level 2 assessment at roughly $102,000 for a small business, every three years — a floor, since the government counted only the assessment itself and treated the underlying security work as a cost contractors already owed. Real first-year figures run two or three times higher.

Spread across roughly 80,000 companies in scope — nearly three-quarters of them small businesses — the program costs, every year, what a major weapons system costs. Companies at the bottom of the supply chain do the arithmetic and exit defense work entirely, shrinking the industrial base the Department has declared it must grow.

Turn the dial the other way — relieve the burden, rely on self-attestation. We ran that experiment. NIST SP 800-171 has been contractually mandatory for defense contractors handling covered defense information since the end of 2017, enforced by self-attestation. When the government's own assessors began checking, self-reported scores collapsed on contact: companies attesting to full implementation were found, on inspection, to be far from it. Eight years of the honor system produced paperwork, not protection. That failure is the reason CMMC exists.

And here is the part the certification debate politely ignores: the assurance being purchased is weaker than advertised. A Level 2 assessment fans 110 security controls into 320 individually judged objectives. Only nine of the 110 can be satisfied by configuring a system; after two years of industry effort to automate verification, barely a quarter have any machine-checkable test at all. The rest — 85 of 110 — turn on an assessor reading documents, weighing evidence, and interviewing people.

Judgment at that volume carries an irreducible error rate, and errors compound across 320 determinations: even a superb assessor is unlikely to get all 320 calls right. The certification is a probabilistic judgment dressed as a binary guarantee — and we are proposing to charge small businesses six figures for it.

Every setting of the dial loses. That is not because the rule-writers were careless. It is because the dial's axis — assurance versus burden — was chosen by the adversary.

Their coin, our coin

Consider the campaign from the adversary's side of the table. A sustained intelligence effort against the defense supply chain wins on either branch. If exfiltration succeeds, the adversary harvests the output of America's research enterprise — the Department's research, development, test, and evaluation accounts now run to roughly $150 billion a year, and nearly all that work materializes as CUI on contractor networks: designs, test data, specifications. The results are visible in the air: F-35 design data stolen in the operation behind Su Bin's 2016 federal conviction later resurfaced in the lines of a rival stealth fighter. If exfiltration is resisted, the United States burns weapons-system-scale money on compliance overhead, small suppliers flee the industrial base, and defense modernization slows under its own administrative weight. Heads they win, tails they win.

This is cost imposition — the competitive-strategies logic the United States once ran against the Soviet Union, most famously with the Strategic Defense Initiative, which threatened to obsolete Moscow's missile force and pulled it toward countermeasure spending it could not afford. The same logic now runs against us at machine speed and negligible marginal cost. An intrusion attempt costs the attacker thousands of dollars; the defensive apparatus it provokes costs the defender billions. The exchange ratio is the attack. And no certification regime, however well designed, changes that ratio. It just selects which branch of the adversary's win condition we take. That is why the task force cannot regulate its way out: it is being asked to find the winning setting on a dial that has none.

The solution we forgot

The way out is not a better tradeoff. It is to stop playing this game — and the United States already knows how, because it solved this exact problem once and then forgot.

For eight decades, the National Industrial Security Program and its predecessors handled sensitive information in contractor hands on a simple two-tier logic. Information that genuinely mattered was classified: the government cleared the facilities, inspected them, provided counterintelligence support, and bore the cost — because assurance of its own supply chain was understood to be the government's problem, a cost of defense like any other. Information that did not rise to that level circulated freely. Both tiers were coherent, and the system carried the country through a fifty-year great-power competition.

Then came CUI — a third tier of 'sensitive but unclassified' created by executive order in 2010 — and with it a decision that looks stranger every year: push national-security-relevant information onto 80,000 private networks with none of the industrial security program's machinery. No facility oversight, no counterintelligence support, no government cost-sharing, and for eight years no verification at all.

CMMC is the decade-late patch on that omission — an attempt to rebuild a shadow industrial-security program on contractor money and commercial assessors. It is failing because the original lesson still holds: protecting information at national-security scale requires the government to run and fund the assurance, or the information does not stay protected.

Restore, don't invent

The reform the task force should recommend is not a better CUI regime. It is the end of CUI as a protection category — a return to the binary the country defended for eighty years: classified, or released.

The government has been trying to triage CUI honestly for sixteen years and has proven incapable of it. Since the 2010 executive order, the registry has swelled to dozens of categories applied so promiscuously that routine engineering data carries the same handling burden as weapon-system design detail. The incentive structure guarantees the outcome: marking is free, unmarking is career risk, and no official is ever punished for protecting too much. A bureaucracy that could not resist over-marking will not now triage its way to discipline. The proof arrived on September 2, mid-review: sixteen years after the executive order created CUI, the National Archives had to issue fresh guidance re-teaching agencies day one of the program — how to designate and mark consistently, and how to tell contractors what is actually controlled. A program whose executive agent must re-explain its founding act sixteen years in is not maturing toward discipline; it is demonstrating that it cannot get there.

So retire the category. Information whose loss would buy an adversary military capability moves up into classified channels, where cleared facilities, real defenses, and counterintelligence support already exist. The rest is released and protected by ordinary commercial hygiene. The classified system has room for this: every review from the Moynihan Commission onward has found it bloated with material of merely sensitive grade — declassify downward as the crown jewels move up, and the classified world need not grow at all. And to the objection that unclassified details aggregate into sensitive wholes: we ran the aggregate-everything experiment. It produced an unpayable mandate, an unprotectable perimeter, and eight years of uncontested collection. That is not risk management; it is risk relabeling.

The binary has one irreducible residue: export-controlled technical data. ITAR and the Export Administration Regulations restrict the largest slice of defense CUI by statute — the Department cannot release it by memo, and it cannot all be classified. That residue is where the second move lives: defend it wholesale, not retail. Eighty thousand self-defended machine shops is retail defense at the worst possible exchange ratio. A few hundred hardened, government-assured environments — enclaves and authorized platforms in which small contractors work with controlled technical data rather than each hosting it themselves — is wholesale defense: the defender finally gets economies of scale, verification shrinks to a population the assessment ecosystem can actually service, and the attacker's cost per useful intrusion rises instead of falling. Concentration creates high-value targets, yes. But a few hundred professionally defended environments with real detection beat 80,000 undefended networks even against a focused adversary — we know, because the adversary has treated the current arrangement as a self-service library since 2017.

Third, verify by sampling, with consequences. Keep self-attestation for the residual population, but back it with random government-led assessment at a rate high enough to deter — the model that keeps the tax system honest without auditing every return.

None of this is invention. Each element has decades of precedent; the task force is being asked to remember, not to imagine. The suspension of CMMC was not an admission that cybersecurity costs too much. It was an admission — perhaps not yet a conscious one — that the game as structured cannot be won at any price. The only winning move is to change the game: shrink what needs protecting, protect it the way we protected what mattered for eighty years, and stop letting an adversary's cost-imposition strategy set the terms of our industrial policy.

James Novakoff, MSTM, CCA, is an enterprise computer and security architect and Certified CMMC Assessor who provides engineering and security services to defense industrial base contractors. The views expressed are his own.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



How America Appeased Putin



Excerpt from Spies: The Epic Intelligence War Between East and West

When Spies was first published in 2023, it made front-page news with the chilling revelation that the Russian government had reached an advanced stage in planning an assassination on American soil.

Russia's target was Alexander Poteyev, a former officer in the SVR, Russia's foreign intelligence service, whom the FBI and CIA had recruited as a spy. Poteyev betrayed one of Moscow's most closely guarded secrets: its network of deep-cover "illegals" living in the United States. His intelligence allowed the FBI to arrest ten Russian operatives in 2010, including the glamorous Anna Chapman.

The United States exchanged the illegals for Western agents imprisoned in Russia. Among those released was Sergei Skripal, the former Russian military intelligence officer whom the Kremlin later attempted to murder in Salisbury, England, with the nerve agent Novichok.

The CIA extracted Poteyev from Russia and resettled him under a new identity in the United States. Putin did not hide the fact that he wanted him dead. A Kremlin spokesman warned that Russia knew the traitor's identity and that an assassin would be sent after him.

That was precisely what happened.

Russian intelligence recruited Hector Fuentes, a Mexican microbiologist with a Russian wife and another family in Mexico. His handlers exploited his private life to blackmail him into identifying and surveilling Poteyev in Miami. They gave Fuentes $20,000 to rent an apartment there, but the operation foundered on poor tradecraft. Fuentes photographed the license plate of Poteyev's car and attracted the attention of security guards at Poteyev's apartment complex. When he attempted to leave for Mexico, American border officials discovered the photograph. Fuentes was arrested and disclosed the operation to US investigators.

By authorizing the plot, Putin had crossed an important red line. Europe had already witnessed Russian assassinations and attempted assassinations, including the attack on Skripal. But the Kremlin had previously stopped short of authorising a killing inside the United States. Putin was now demonstrating his willingness to tear up the remaining restraints governing relations with Washington.

Yet the American response was remarkably weak.

The New York Times subsequently reported that Washington retaliated harshly, imposing sanctions and expelling ten Russian intelligence officers operating under diplomatic cover in April 2021. But according to someone intimately involved in the events, when the United States informed the Kremlin about the expulsions, its message did not even mention the planned murder. Instead, Washington concentrated on Russia's SolarWinds cyberattack.

The penalties imposed were hardly sufficient to alter Putin's behaviour. Russian intelligence officers sometimes regard expulsion as a badge of honour. Putin had also insulated much of the Russian economy from American sanctions. A more serious response might have publicly exposed his immense wealth and corruption - subjects about which the Kremlin leader is notoriously sensitive.

The assassination plot was only the first of four events that, viewed from Moscow, advertised American weakness.

The second emerged in 2020, when reports alleged that Russian military intelligence was paying bounties to the Taliban to kill American service personnel in Afghanistan. The story appeared during the presidential election campaign but then largely disappeared, supposedly because the US intelligence community could not reach a consensus about the underlying evidence.

There should have been little doubt. John J. Sullivan, the former American ambassador in Moscow, has written that he examined the intelligence and found the proof persuasive. According to a source with knowledge of the events, American authorities possessed intelligence about a Russian officer travelling to Dubai to meet an Afghan contractor who facilitated payments to the Taliban. At the centre of the scheme was an Afghan-Russian gem smuggler, Rahmatullah Azizi, who acted as an intermediary.

The intelligence reached the President's Daily Brief in February 2020. Donald Trump nevertheless denied having been briefed and dismissed the story as "fake news." As with the assassination plot, the Russian bounty program provoked no meaningful American response.

The third demonstration of weakness was Washington's withdrawal from Afghanistan, negotiated by Trump and executed by Joe Biden in August 2021. The operation was handled disastrously. The world watched desperate Afghans cling to an American C-17 as it taxied along the runway at Kabul airport. Some fell to their deaths after the aircraft took off. A suicide bombing killed thirteen American service personnel and approximately 170 Afghan civilians. Soon the Taliban controlled the country once more.

From the Kremlin's perspective, the images suggested that the United States no longer possessed the will or competence of a superpower.

The fourth episode concerned Havana Syndrome - the mysterious neurological symptoms suffered by American officials since 2016. The US government repeatedly denied that a foreign power was responsible. A 2023 intelligence assessment judged it "very unlikely" that an adversary lay behind the incidents.

Investigative reporting later revealed compelling evidence of Russian involvement. Members of Unit 29155, a Russian military intelligence black-operations squad, were present near several incidents involving American personnel. The operatives appear to have used some form of electronic weapon.

Two reliable sources familiar with the matter told me that Russian involvement was regarded as almost certain, but that elements of the American intelligence community - particularly the CIA - had suppressed evidence pointing towards Moscow. Their apparent calculation was that doing nothing was preferable to revealing an attack that might constitute an act of war.

In December 2024, the House Intelligence Committee concluded that a foreign adversary was increasingly likely to have caused at least some of the incidents. It criticised the previous intelligence assessment for lacking analytic integrity and being highly irregular in its formulation.

If Russia was responsible, the lesson for the Kremlin was unmistakable: it had attacked American government personnel and escaped without punishment.

Taken together, the assassination plot, the bounties on American soldiers, the humiliating withdrawal from Afghanistan and Washington's refusal to confront the evidence surrounding Havana Syndrome all made the United States appear emasculated in the Kremlin's eyes.

It was in this context that Putin decided to launch his full-scale invasion of Ukraine in February 2022. America appeared weak. The opportunity for military action had arrived.

The analogy with Munich in 1938 has become an overused cliché. In this instance, however, it is unfortunately appropriate. Through their repeated failure to counter Russian aggression before February 2022, the Trump and Biden administrations effectively appeased Putin's worst ambitions.

Putin's actions must be understood through his background as a KGB officer. He remains an unreformed Chekist, steeped in the mentality of the Soviet security services. He has never abandoned the KGB's view of the United States as Russia's "main adversary," nor his conviction that Washington and the CIA are engaged in a conspiracy to weaken Russia.

His strategy has consistently been revanchist: to regain the territory, influence and prestige lost when the Soviet Union collapsed. His invasions of Ukraine in 2014 and 2022 follow logically from that worldview. According to Putin's distorted version of history, Ukraine is an artificial country created by hostile Western powers. He regards its conquest and reincorporation into Russia as an almost sacred duty.

This is a gross misreading of history. But it is nevertheless what Putin believes - and Western governments must take it seriously.

Putin and the hardliners surrounding him believe themselves to be at war with NATO and, above all, with the United States. That conviction will not disappear with a ceasefire in Ukraine. Nor will the danger necessarily vanish when Putin leaves power. The nationalist resentments he has exploited are larger than the man himself, while his regime has systematically eliminated alternative leaders.

The West therefore faces a Russia problem, not merely a Putin problem. The events preceding the invasion of Ukraine offer an enduring warning: deterrence fails when threats carry no consequences. Dictators interpret silence not as prudence, but as permission.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief





Back to top