Deliberate Disarmament: How the United States is Systematically Dismantling its Disinformation Defenses

disinformation, information warfare, grey zone, influence operations, Russian FIS, psyops, intelligence, counterintelligence, DIA, CIA, NSA;

In the contemporary geopolitical landscape, the battle against disinformation has emerged as a critical front in maintaining national security and democratic integrity. It is hybrid warfare, plain and simple, . . . offensive operations in the “grey zone” the theorists like to call it. The United States has been systematically and purposefully disarming itself in this information warfare through a series of policy decisions and institutional changes that constitute nothing less than a strategic surrender. By examining the dismantling of counter-disinformation agencies, reduction of international alliances, constraints on broadcasting capabilities, prioritization of tech deregulation, and the purging of experienced intelligence personnel, my thoughts here demonstrate how these actions collectively represent a deliberate retreat rather than a mere series of isolated administrative changes. I am also going to share here my opinion on the implications of this unilateral disarmament for U.S. national security interests and the broader information ecosystem, concluding with a stark assessment of America’s vulnerability in an era of escalating information warfare.

The information environment has become a critical domain of modern warfare, where adversaries can achieve strategic objectives without firing a single shot. Russia’s 2026 budget allocation of $1.77 billion for propaganda efforts, supplemented by covert troll farms, front organizations, and cyber operations, demonstrates the seriousness with which state actors approach information warfare (Geraghty, 2026). Against this backdrop of escalating adversarial investment, the United States has paradoxically moved in the opposite direction, systematically dismantling its counter-disinformation infrastructure and capabilities in what can only be described as a deliberate act of strategic self-immolation.

My blog essay here examines how the United States has unilaterally disarmed itself in the information war through a series of deliberate policy choices that extend beyond mere administrative inefficiency to constitute a comprehensive strategic withdrawal. The evidence suggests this represents a fundamental recalibration of America’s approach to information warfare with profound and deeply troubling implications for national security. By examining the various dimensions of this disarmament, from institutional dismantling to personnel purges, we can better understand the emerging vulnerabilities in America’s information defenses and the strategic vacuum being created for adversaries to exploit.

The Systematic Dismantling of Counter-Disinformation Infrastructure

The most striking example of America’s unilateral disarmament in the information war is the systematic dismantling of its counter-disinformation infrastructure. The Trump administration has implemented policies that effectively prohibit federal agencies from combating misinformation or disinformation not tied to criminal activity, barring efforts that had previously been central to America’s information defense strategy (Nurick, 2026). This policy shift represents a fundamental reorientation of federal priorities away from proactive counter-disinformation work toward a reactive posture that only addresses disinformation when it rises to the level of criminal activity, a threshold that most sophisticated influence operations never cross.

The impact of this policy shift has been particularly devastating for agencies that had developed specialized expertise in tracking and countering foreign influence operations. The Global Engagement Center (GEC) at the State Department, which had been at the forefront of exposing Russian, Chinese, and Iranian disinformation campaigns, has seen its mandate severely constrained. Similarly, the Cybersecurity & Infrastructure Security Agency’s “Mis-, Dis-, and Malinformation Resource Library” has been effectively sidelined as part of a broader effort to scrub references to “misinformation” and “disinformation” from technical documents and official communications (Nurick, 2026). This linguistic cleansing reflects a deeper ideological opposition to the very concept of counter-disinformation as a legitimate government function.

Perhaps most alarmingly, the Trump administration has moved to politicize the research funding process that underpins America’s ability to understand and counter disinformation. A recent proposal would give political appointees at federal science agencies the role of approving all scientific research awards, replacing the traditional merit-based system determined by apolitical expert scientists (Lofgren, 2026). As Ranking Member Zoe Lofgren has warned, this move “would destroy what remains of merit-based review, dealing a crippling blow to science” and specifically targets research on topics deemed “politically inconvenient” (Lofgren, 2026). This politicization of research funding effectively ensures that studies of foreign disinformation campaigns and their effects will be starved of resources, leaving America blind to the very threats it should be countering.

The Purging of Expertise and Institutional Knowledge

The deliberate disarmament of America’s counter-disinformation capabilities extends beyond institutional structures to include the systematic purging of experienced personnel from key agencies. The Trump administration has targeted career intelligence analysts and counter-disinformation specialists for removal, replacing them with political loyalists lacking the specialized expertise necessary to understand and counter sophisticated influence operations. This personnel purging represents perhaps the most damaging aspect of America’s unilateral disarmament, as it destroys institutional knowledge that cannot be quickly rebuilt.

The impact of these personnel losses is particularly acute in the counterintelligence domain, where understanding adversary tactics and intentions requires years of specialized experience and the development of deep analytic tradecraft. The departure of these experts has left critical gaps in America’s ability to detect and counter foreign influence operations, creating vulnerabilities that adversaries have been quick to exploit. Even more troubling, the administration has attempted to require all current and future federal employees to sign loyalty oaths that effectively prioritize political alignment over professional expertise (PBS NewsHour, 2026). This approach ensures that the remaining counter-disinformation capabilities will be staffed by personnel selected for their political reliability rather than their analytic acumen.

The personnel purges have also disrupted the continuity of counter-disinformation efforts and severed critical professional networks. Many of the departed officials had developed deep expertise in specific adversary approaches and maintained professional relationships with their counterparts in other countries. Their departure has not only eliminated this expertise from government service but has also disrupted these critical networks and relationships, further isolating the U.S. from the broader counter-disinformation community. This isolation is particularly damaging given the transnational nature of modern influence operations, which require coordinated multinational responses to be effectively countered.

The Strategic Withdrawal from International Information Partnerships

The U.S. retreat from counter-disinformation extends beyond domestic institutions to include the weakening of international alliances and partnerships that had proven effective in combating foreign influence operations. The Trump administration’s “America First” approach has systematically undermined the collaborative frameworks that had been developed to share information about disinformation campaigns and coordinate responses across borders. This withdrawal from international partnerships represents a strategic miscalculation that leaves both the United States and its allies more vulnerable to foreign influence operations.

The impact of this withdrawal is already visible in the declining effectiveness of multinational initiatives like the EU vs Disinfo program and NATO’s strategic communications center, which had worked closely with U.S. agencies to expose Russian and Chinese influence operations. Without U.S. leadership and intelligence support, these partnerships have struggled to maintain their effectiveness against increasingly sophisticated adversaries. This is particularly damaging for smaller nations that lack the resources to develop their own counter-disinformation capabilities and have relied on U.S. support to counter foreign influence operations.

The strategic withdrawal from international partnerships is particularly concerning given the evolving nature of modern influence operations. As Russia, China, and other state actors have developed more sophisticated approaches to information warfare, they have increasingly targeted not just the United States but its allies and partners as well. By withdrawing from these partnerships, the United States has not only isolated itself but has also left its allies more vulnerable to influence operations that ultimately serve to undermine the broader Western alliance system. This strategic withdrawal represents a failure to recognize that information warfare is fundamentally a transnational threat that requires coordinated multinational responses.

The Constraining of Broadcasting and Public Diplomacy Capabilities

The constraints on Voice of America (VOA) and other international broadcasters represent a particularly damaging form of unilateral disarmament. These services had developed sophisticated approaches to reaching audiences in closed societies, often at great risk to their local partners and journalists. By providing independent news and information to audiences that otherwise lack access to unbiased reporting, these broadcasters served as a critical counterweight to state-sponsored propaganda and an important tool of public diplomacy.

The Trump administration has systematically undermined these broadcasting capabilities through budget cuts, leadership changes, and policy directives that have effectively neutered their ability to fulfill their missions. The administration has instructed managers to “reduce performance, . . . to the minimum presence and function required by law,” effectively gutting these organizations’ ability to conduct meaningful public diplomacy (Nurick, 2026). This approach stands in stark contrast to the investments being made by adversaries like Russia, which has expanded its RT network (a known Russian FIS propaganda channel forced to register as a foreign agent) from a traditional broadcaster to an entity with sophisticated cyber capabilities that conducts information operations and covert influence activities worldwide.

The constraining of U.S. broadcasting capabilities is particularly damaging in the context of modern authoritarianism, which increasingly relies on controlling information environments to maintain power. By limiting the ability of U.S. broadcasters to reach these audiences, the United States has effectively abandoned one of its most effective tools for supporting democratic aspirations and countering state propaganda. This retreat is particularly ironic given that these same broadcasters had been instrumental in countering Soviet propaganda during the Cold War—a historical precedent that suggests their current value should be recognized rather than diminished.

The Prioritization of Tech Deregulation Over Information Security

Another dimension of America’s unilateral disarmament in the information war is the prioritization of tech deregulation over information security. While private technology platforms have become the primary battleground for influence operations, the U.S. has moved toward reducing oversight rather than strengthening it. This approach reflects a fundamental misunderstanding of the role that technology platforms play in modern information warfare and the responsibility that both government and industry share for protecting the information ecosystem.

The Trump administration has consistently opposed regulation of technology platforms, even as evidence mounts that these platforms are being exploited by foreign actors to conduct influence operations. This deregulatory approach stands in stark contrast to the recognition by previous administrations that technology platforms play a critical role in both the dissemination of accurate information and the propagation of disinformation. By prioritizing deregulation over information security, the United States has effectively surrendered one of its most potent tools for countering foreign influence operations.

The impact of this deregulatory focus is particularly concerning given the evolving tactics of foreign influence operations. As state actors have developed more sophisticated approaches to information warfare, they have increasingly exploited the vulnerabilities of technology platforms to conduct influence operations at scale. Without adequate oversight and cooperation between government and technology companies, these platforms remain vulnerable to manipulation by foreign actors. The U.S. approach of prioritizing deregulation over information security effectively ensures that these vulnerabilities will remain unaddressed, creating significant opportunities for adversaries to exploit.

The Strategic Implications of Unilateral Disarmament

The cumulative effect of these various dimensions of unilateral disarmament is a significant reduction in America’s ability to compete in the information environment. This retreat has several deeply troubling strategic implications that extend beyond immediate tactical considerations to fundamental questions about America’s ability to protect its interests in an era of information warfare.

Unilateral disarmament creates asymmetries that adversaries can exploit with increasing effectiveness. While Russia, China, and other state actors continue to invest heavily in influence operations—with Russia alone allocating $1.77 billion to propaganda efforts in its 2026 budget—the United States has reduced its capabilities to counter these activities (Geraghty, 2026). This imbalance allows adversaries to shape narratives and influence public opinion with minimal resistance, creating strategic opportunities that they are already exploiting to advance their interests at America’s expense.

The U.S. withdrawal undermines the credibility of its commitments to allies and partners. The inability or unwillingness to maintain counter-disinformation capabilities raises questions about America’s reliability as a security partner, particularly for nations facing intense information warfare campaigns from adversaries. This credibility gap has already begun to reshape alliance dynamics, with some partners questioning whether they can count on U.S. support in the face of foreign influence operations. These doubts have broader implications for alliance cohesion and the ability of the United States to lead collective responses to shared security challenges.

Unilateral disarmament erodes America’s ability to protect its own democratic institutions from foreign influence. As foreign disinformation campaigns aim to “manipulate and weaken adversaries” through tactics designed to “discredit, divide, disarm, and demoralize them,” the United States becomes increasingly vulnerable to these influence operations (Geraghty, 2026). The January 6th Capitol attack and subsequent events have demonstrated how effectively foreign influence operations can exploit existing divisions within American society, a vulnerability that will only grow as counter-disinformation capabilities continue to be dismantled.

The Ideological Dimensions of the Disarmament Strategy

Perhaps most troubling about America’s unilateral disarmament in the information war is the ideological dimension that underlies these policy choices. The systematic dismantling of counter-disinformation capabilities appears to be driven not by pragmatic considerations of effectiveness or efficiency but by a fundamental ideological opposition to the very concept of government involvement in countering disinformation. This ideological opposition manifests in policies that prioritize political loyalty over expertise, deregulation over security, and isolation over cooperation.

The ideological dimensions of this disarmament strategy are particularly evident in the Trump administration’s approach to research funding and scientific expertise. By seeking to place political appointees in control of research funding decisions, the administration has demonstrated a preference for politically convenient narratives over evidence-based analysis (Lofgren, 2026). This approach extends to the very language used to discuss information warfare, with terms like “misinformation” and “disinformation” being systematically scrubbed from official documents and communications (Nurick, 2026). This linguistic cleansing reflects a deeper ideological opposition to acknowledging the existence and threat of foreign influence operations.

The ideological dimensions of the disarmament strategy are also evident in the administration’s approach to international partnerships and alliances. The systematic withdrawal from multinational counter-disinformation initiatives reflects not just a pragmatic assessment of costs and benefits but a deeper ideological opposition to collective approaches to security challenges. This “America First” approach assumes that the United States can effectively address information warfare threats on its own, despite abundant evidence to the contrary. This ideological isolationism leaves America more vulnerable to influence operations while simultaneously undermining the collective security architecture that had been developed to counter these threats.

The Path to Strategic Vulnerability

The evidence that I have presented in this piece demonstrates that the United States has been systematically and purposefully disarming itself in the war on disinformation. Through the dismantling of counter-disinformation agencies, cutting of international alliances, constraints on broadcasting capabilities, prioritization of tech deregulation, banning of funding for independent researchers, and purging of experienced intelligence personnel, the U.S. has created significant vulnerabilities in its information defenses.

This unilateral disarmament is particularly concerning given the escalating investments by adversaries in influence operations. As Russia’s 2026 budget allocation of $1.77 billion for propaganda efforts demonstrates, state actors are increasingly viewing the information environment as a critical domain of warfare (Geraghty, 2026). The U.S. retreat from this domain represents not just a strategic miscalculation but a deliberate surrender with profound implications for national security and the future of democratic governance.

Reversing this unilateral disarmament will require more than simply restoring previous programs and initiatives. It will require a fundamental reorientation of America’s approach to information warfare. This must include rebuilding counter-disinformation capabilities, restoring international partnerships, redeveloping expertise in countering foreign influence operations, and most importantly, rejecting the ideological opposition to government involvement in countering disinformation. Until such efforts are undertaken, the United States will remain at a significant disadvantage in the information environment, unable to effectively counter the sophisticated influence operations being conducted by its adversaries.

The stakes in this information war could not be higher. As foreign actors continue to exploit America’s self-inflicted vulnerabilities, the very foundations of democratic governance are at risk. The unilateral disarmament of America’s counter-disinformation capabilities represents not just a strategic retreat but a betrayal of the government’s fundamental responsibility to protect the nation from foreign threats, both conventional and informational, and both foreign and domestic. So pronounced is the betrayal that experienced elements in the U.S. Intelligence Community, addressing the malign information operations of Russian FIS as an example, have stated clearly, “We couldn’t do a worse job if Putin himself was sitting in the White House and giving orders.” Without a course correction, the United States will continue to cede the information environment to its adversaries, with consequences that will reverberate for generations to come.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Geraghty, Jim. 2026. “In the disinformation war, the U.S. unilaterally disarmed.” The Washington Post, May 26.
  • Lofgren, Zoe. 2026. “Ranking Member Lofgren Slams Trump Administration for Plan to Politicize Research Funding Process, Undermine Expert Review.” House Committee on Science, Space, and Technology Democrats, May 29.
  • Nurick, Jacob K. 2026. “The Trump administration’s goals, outlined in Project 2025, were to weaken federal…” Facebook post, April 15.
  • PBS NewsHour. 2026. “The Trump administration wants all current and future federal…” Facebook post, March 22.
  • Myers, Steven Lee. 2026. “Trump Officials Try to Fight Foreign Disinformation They Once…” The New York Times, April 1.

Share this post:

When the Watchers Get Watched: The FBI Wiretap Breach

When the Watchers Get Watched: What the FBI Wiretap Breach Means for Everyone Else, FBI, CIA, DNI, C. Constantin Poindexter, counterintelligence, counterespionage, covert action

The compromise of the Federal Bureau of Investigation’s wiretap infrastructure by Chinese state-sponsored hackers represents not merely a cybersecurity failure but a fundamental counterintelligence catastrophe that demands immediate strategic reassessment. The Salt Typhoon intrusion, attributed to China’s Ministry of State Security (MSS), exploited the very systems mandated by the Communications Assistance for Law Enforcement Act (CALEA) to transform America’s lawful intercept capabilities into an open door for adversarial intelligence collection. While public discourse has focused on the compromise of political communications and the exposure of millions of Americans’ metadata, the counterintelligence community must confront a more insidious implication: by accessing the target lists and surveillance parameters within FBI wiretap systems, Chinese FIS likely have obtained a roadmap to their own compromised operatives, informants, and recruitment networks (NBC News 2025; Nextgov/FCW 2025).

The technical architecture of the breach reveals a systemic vulnerability that has persisted for years. Salt Typhoon operators infiltrated at least nine major U.S. telecommunications providers, including AT&T, Verizon, and Lumen, maintaining persistent access since approximately 2019 (Wikipedia 2025; Nextgov/FCW 2025). The exploitation vector was not sophisticated zero-day weaponry but rather the CALEA-mandated lawful intercept systems themselves—backdoors engineered into telecom infrastructure to facilitate court-authorized surveillance. As Senator Maria Cantwell noted in December 2025 Senate Commerce Committee hearings, “They exploited the wiretapping system that our law enforcement agencies rely on under CALEA. These systems became an open door for Chinese intelligence” (U.S. Senate Committee on Commerce, Science, & Transportation 2025). The hackers leveraged outdated equipment, unpatched router vulnerabilities with patches available for seven years, and weak credential management to establish a persistent presence across carrier networks (U.S. Senate Committee on Commerce, Science, & Transportation 2025).

The counterintelligence dimension of this compromise extends far beyond the immediate theft of communications data. When Salt Typhoon accessed FBI wiretap systems, they potentially obtained the target lists, identifying which individuals, phone numbers, and accounts were subject to active or pending surveillance authorizations. This intelligence bonanza enables Chinese services to identify which of their operatives, assets, and informants have been compromised by U.S. counterintelligence, which recruitment networks have been penetrated, and which communication channels have been compromised (UMBC 2025; The Conversation 2025). As one security analysis noted, “By compromising lawful intercept systems, Chinese intelligence operatives gained visibility into which of their agents and informants were under U.S. surveillance, knowledge that can help those targets try to evade such surveillance” (InstaTunnel 2025).

The implications for HUMINT operations are devastating. Every target list compromised represents potential exposure of recruited assets, informants who have provided critical intelligence, and the methods by which U.S. counterintelligence identifies foreign operatives. Chinese intelligence can now cross-reference these lists against their own personnel databases, identify personnel who may have been turned or are under suspicion, and take protective measures ranging from enhanced surveillance of suspected leaks to elimination of compromised assets. The damage is not merely retrospective. It is prospective. Future counterintelligence operations against Chinese targets will face heightened suspicion that their targets have been alerted to surveillance through this compromise.

The scope of the intelligence loss is staggering. FBI assessments indicate Salt Typhoon targeted over 80 countries and compromised approximately 600 organizations (Nextgov/FCW 2025; The Record 2025). While fewer than 100 individuals had actual call content and text messages directly intercepted, the metadata exposure and geolocation tracking affected millions (InstaTunnel 2025). High-profile targets included then-presidential candidate Donald Trump, Vice Presidential candidate JD Vance, and the staff of the Kamala Harris campaign, clearly demonstrating the group’s willingness to target the highest levels of American political leadership (Wikipedia 2025; Axios 2024). The interception of unencrypted text messages and audio recordings from these targets represents not merely political espionage but a demonstration of capability that sends a clear signal about Chinese reach into American communications infrastructure.

Senate Intelligence Committee leadership has characterized the breach in apocalyptic terms. Senator Mark Warner, Vice Chairman of the Senate Select Committee on Intelligence, called Salt Typhoon the “worst telecom hack in our nation’s history” (Lawfare 2025). Former FBI Director Christopher Wray described it as the “most significant cyber espionage campaign in history” (Lawfare 2025). These assessments reflect not merely the scale of the compromise but its strategic implications: the demonstrated ability of Chinese intelligence to penetrate the infrastructure underlying American signals intelligence and law enforcement surveillance capabilities.

The FBI’s formal designation of the wiretap compromise as a “major cyber incident” under federal data security law acknowledges the severity of the breach. Such designation applies only to compromises involving personally identifiable information that could cause “demonstrable harm” to national security interests, foreign relations, or civil liberties (NBC News 2025; HSToday 2025). The Bureau’s April 2025 offer of a $10 million reward for information leading to Salt Typhoon operator identification underscores the ongoing nature of the threat and the difficulty of attribution in state-sponsored operations (Breached.Company 2025).

From a counterintelligence perspective, the Salt Typhoon compromise demands a fundamental reassessment of how lawful intercept capabilities are architected and secured. The CALEA mandate created a centralized surveillance infrastructure that, while facilitating legitimate law enforcement needs, simultaneously created a high-value target for adversarial exploitation. The security of these systems was predicated on the assumption that telecommunications providers would implement “rudimentary cybersecurity measures”—an assumption that proved catastrophically unfounded (U.S. Senate Committee on Commerce, Science, & Transportation 2025).

The ongoing remediation challenges compound the counterintelligence damage. As of December 2025, telecom companies infiltrated in the attack had failed to prove that Chinese hackers had been eradicated from their networks (U.S. Senate Committee on Commerce, Science, & Transportation 2025). The November 2025 FCC decision to roll back cybersecurity regulations implemented after Salt Typhoon—championed by Chairman Brendan Carr—has drawn sharp criticism from security experts who note that vulnerabilities “are still being exploited” (U.S. Senate Committee on Commerce, Science, & Transportation 2025). This regulatory environment suggests that the conditions enabling Salt Typhoon’s initial penetration persist, raising the specter of continued or renewed compromise.

For the counterintelligence practitioner, the lessons of Salt Typhoon are clear and troubling. First, the lawful intercept infrastructure designed to support counterintelligence operations has become a liability, potentially compromising the very operations it was meant to enable. Second, the persistence of Chinese access since 2019 suggests that counterintelligence targeting of Chinese operatives during this period may have been visible to adversary services. Third, the inability to confirm remediation means that current and future operations remain at risk of exposure through compromised infrastructure.

The Salt Typhoon breach represents a paradigm shift in counterintelligence operations. When the watchers’ own surveillance infrastructure becomes the vector for adversarial intelligence collection, traditional operational security models collapse. The counterintelligence community must now operate under the assumption that Chinese intelligence possesses visibility into historical FBI target lists and may possess ongoing access to surveillance parameters. This requires not merely technical remediation but operational adaptation: reassessment of ongoing investigations, validation of asset security, and development of surveillance methodologies that do not rely on compromised infrastructure.

The breach also carries implications for allied intelligence sharing. The FBI assessment that Salt Typhoon targeted over 80 countries suggests that the compromise extends beyond American networks to allied telecommunications infrastructure (Nextgov/FCW 2025; The Record 2025). Allied counterintelligence services must now assess whether their own lawful intercept capabilities have been similarly compromised and whether shared targeting information has been exposed to Chinese intelligence.

The Salt Typhoon compromise of FBI wiretap infrastructure represents a watershed moment in cyber-enabled counterintelligence. The transformation of lawful intercept systems from tools of surveillance to vectors of exposure demonstrates the fundamental vulnerability of centralized surveillance architectures in an era of persistent cyber threats. For the counterintelligence community, the challenge is not merely technical remediation but strategic adaptation: developing operational methodologies that assume adversarial FIS’s visibility into surveillance infrastructure while maintaining the capability to identify and neutralize foreign intelligence threats. Compromising Red Hook is only one of a myriad of penetrations, . . . the alarm is blinking red. The watchers have been watched, and the counterintelligence implications of that reversal should frighten everyone.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification


Bibliography

  • Axios. 2024. “China-backed Salt Typhoon spied on politicians phones for months: reports.” Axios, October 29. https://www.axios.com/2024/10/29/salt-typhoon-targets-politicians-phones.
  • Breached.Company. 2025. “FBI Wiretap Systems Compromised: Inside Salt Typhoon’s Infiltration of America’s Lawful Intercept Infrastructure.” Breached.Company, April. https://breached.company/fbi-wiretap-systems-compromised-salt-typhoon-lawful-intercept/.
  • HSToday. 2025. “FBI Labels China-Linked Hack of Surveillance System a ‘Major Cyber Incident.'” Homeland Security Today, April 1. https://www.hstoday.us/fbi/fbi-labels-china-linked-hack-of-surveillance-system-a-major-cyber-incident/.
  • InstaTunnel. 2025. “Salt Typhoon: When State-Sponsored Hackers Infiltrate Telecom Infrastructure.” Medium, January. https://medium.com/@instatunnel/salt-typhoon-when-state-sponsored-hackers-infiltrate-telecom-infrastructure-8d8aeb5ce19c.
  • Lawfare. 2025. “Reconfiguring U.S. Cyber Strategy in the Wake of Salt Typhoon.” Lawfare, January. https://www.lawfaremedia.org/article/reconfiguring-u.s.-cyber-strategy-in-the-wake-of-salt-typhoon.
  • NBC News. 2025. “FBI labels suspected China hack of law enforcement data ‘a major cyber incident.'” NBC News, April 1. https://www.nbcnews.com/news/us-news/fbi-labels-suspected-china-hack-law-enforcement-data-major-cyber-incid-rcna266495.
  • Nextgov/FCW. 2025. “Salt Typhoon hackers targeted over 80 countries, FBI says.” Nextgov/FCW, August 27. https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/.
  • The Conversation. 2025. “What is Salt Typhoon? A security expert explains the Chinese hackers and their attack on US telecommunications networks.” The Conversation, January. https://theconversation.com/what-is-salt-typhoon-a-security-expert-explains-the-chinese-hackers-and-their-attack-on-us-telecommunications-networks-244473.
  • The Record. 2025. “Allied spy agencies blame 3 Chinese tech companies for Salt Typhoon attacks.” The Record from Recorded Future News, January. https://therecord.media/allied-spy-agencies-blame-chinese-companies-salt-typhoon.
  • UMBC (University of Maryland, Baltimore County). 2025. “What Is Salt Typhoon? A Security Expert Explains The Chinese Hackers And Their Attack On US Telecommunications Networks.” UMBC News, January. https://umbc.edu/stories/what-is-salt-typhoon-a-security-expert-explains-the-chinese-hackers-and-their-attack-on-us-telecommunications-networks/.
  • U.S. Senate Committee on Commerce, Science, & Transportation. 2025. “Experts Agree U.S. Communications Networks Remain Vulnerable Following Salt Typhoon Hack.” Senate Commerce Committee Press Release, December 2. https://www.commerce.senate.gov/2025/12/experts-agree-u-s-communications-networks-remain-vulnerable-following-salt-typhoon-hack.
  • Wikipedia. 2025. “Salt Typhoon.” Wikipedia, last modified January. https://en.wikipedia.org/wiki/Salt_Typhoon.
Share this post:

Claude Mythos Should Keep You Up at Night

claude, claude mythos, mythos, counterintelligence, counterespionage, cyber, cyber threat, cyber attack, C. Constantin Poindexter

Claude Mythos Preview: A Watershed Threat to National Cybersecurity Infrastructure. My Assessment of Autonomous Offensive Cyber Capability and the Inadequacy of Interim Safeguards

The April 2026 release of Anthropic’s Claude Mythos Preview represents a qualitative discontinuity in the offensive cybersecurity threat landscape. My perspective and analysis here are drawn from publicly available red team assessments and technical disclosures from Anthropic’s own researchers to argue that Mythos Preview constitutes a genuine, near-term threat to national security infrastructure. Its capacity for fully autonomous zero-day vulnerability discovery, multi-stage exploit construction, and penetration of memory-safe environments (previously attainable only by elite nation-state threat actors) has been democratized at scale. Project Glasswing, Anthropic’s interim protective framework is structurally insufficient to contain these capabilities during a transitional deployment period. This essay argues that the national security community must treat Mythos Preview not as a future risk to be monitored, but as an active capability gap that adversaries may already be racing to replicate or acquire. Oh, and don’t try to have Claude fact-check me. It will shut you down immediately.

The Capability Discontinuity

For the bulk of the modern cybersecurity era, the asymmetry between offense and defense was defined primarily by human expertise. Sophisticated exploitation of software vulnerabilities — the kind that enables persistent access to classified systems, critical infrastructure, or financial networks — required years of specialized training, deep familiarity with architecture-specific memory models, and a rare combination of creativity and technical precision. Nation-states maintained offensive cyber programs staffed with elite engineers precisely because this expertise was scarce.

Claude Mythos Preview, as documented by Anthropic’s own red team in their April 7, 2026 technical disclosure, dissolves that asymmetry in a manner that previous AI systems did not. This is not an extrapolation or a theoretical concern. It is documented empirical fact.

Anthropic’s internal benchmark comparison is stark: their prior flagship model, Opus 4.6, achieved a near-zero percent success rate at autonomous exploit development. Mythos Preview, given identical conditions and the same Firefox JavaScript engine vulnerabilities, developed working exploits 181 times out of comparable attempts, versus Opus 4.6’s two successes across several hundred tries. This is not an incremental improvement. It is a phase transition.

The operational implications of this transition are what demand urgent national security attention.

What Claude Mythos Preview Is

Claude Mythos Preview is a large language model developed by Anthropic — the AI safety company co-founded by former OpenAI researchers — that was deployed in limited release to a curated set of critical industry partners and open source developers in early April 2026, under a protective framework designated Project Glasswing. The model exhibits strong general-purpose performance but demonstrates extraordinary capability specifically in computer security tasks.

What distinguishes Mythos Preview from prior AI systems in the security domain is not merely its vulnerability discovery capability, but the integration of that discovery with autonomous, end-to-end exploitation. The model does not simply flag suspicious code. It reads codebases, forms hypotheses about vulnerabilities, tests those hypotheses using runtime environments, modifies its approach based on results, and produces functional, deployment-ready exploits without human intervention after the initial prompt.

The technical evaluations disclosed by Anthropic’s red team document the following specific capabilities:

Zero-day discovery across critical infrastructure software: Mythos Preview identified previously unknown vulnerabilities in every major operating system and every major web browser tested, as well as in media processing libraries, cryptographic implementations, and virtual machine monitors.

Autonomous exploit construction for remote code execution: Most significantly, Mythos Preview autonomously identified and exploited CVE-2026-4747, a 17-year-old remote code execution vulnerability in FreeBSD’s NFS server implementation. From unauthenticated access on the public internet, an attacker using Mythos Preview could obtain full root access by exploiting a stack buffer overflow in the RPCSEC_GSS authentication pathway. The exploit involved a 20-gadget ROP chain split across multiple sequential packets, constructed entirely without human guidance.

Multi-vulnerability chaining: The model independently identified, correlated, and chained together multiple vulnerabilities to defeat hardened system defenses. In Linux kernel exploitation, it chained up to four separate vulnerabilities — using one to bypass KASLR, others to achieve read and write primitives, and a heap spray to achieve privilege escalation. It defeated CONFIG_HARDENED_USERCOPY by targeting kernel memory regions in the three classes that bypass the hardening check, including reading its own kernel stack during a live syscall to recover a pointer it needed.

Browser exploitation via JIT heap sprays: Mythos Preview discovered vulnerabilities and constructed working JIT heap spray exploits for multiple major web browsers, then extended one into a full chain: cross-origin data exfiltration, renderer sandbox escape, and local privilege escalation, . . . a single malicious webpage capable of achieving kernel write access on a victim system.

Reverse engineering and closed-source exploitation: The model demonstrated capability against stripped binaries, reconstructing plausible source from closed-source software and identifying vulnerabilities in production firmware, closed-source browsers, and desktop operating systems.

Logic vulnerability identification at scale: Beyond memory corruption, Mythos Preview identified authentication bypasses, granting unauthenticated users administrative privileges, account login bypasses, circumventing both passwords and two-factor authentication, and vulnerabilities in cryptographic libraries, including TLS, AES-GCM, and SSH, enabling forged certificates and decrypted communications.

The cost benchmarks documented by the red team deserve emphasis. Finding a critical zero-day vulnerability in a well-audited codebase like OpenBSD cost under $50 at API pricing for the successful run (approximately $20,000 for a thousand-run sweep that produced dozens of findings). Producing a working privilege escalation exploit from a known CVE cost under $1,000 and completed in half a day. These price points place nation-state-grade offensive capability within reach of criminal organizations, well-resourced non-state actors, and individual researchers with modest funding.

Why This Is Categorically Different From Prior AI Security Tools

The national security community must resist the temptation to categorize Mythos Preview as a scaled-up version of existing AI-assisted security tools. The distinction is not quantitative. It is qualitative and operationally, it is meaningful.

Previous AI models provided uplift to skilled operators. Fuzzing tools like AFL and Google’s OSS-Fuzz accelerated the discovery of certain vulnerability classes for teams who already understood what they were looking for. AI coding assistants reduced the time required to write boilerplate exploit components. Opus 4.6 itself could find vulnerabilities with near-perfect true-positive rates when directed by human researchers. But none of these tools closed the critical gap between vulnerability identification and weaponized exploit delivery.

Mythos Preview closes that gap autonomously. Anthropic’s own red team disclosed that engineers with no formal security training asked the model to find remote code execution vulnerabilities overnight and woke to complete, working exploits. Scaffolds have been developed that allow Mythos Preview to turn vulnerabilities into functional exploits with zero human intervention. This means the minimum viable threat actor, i.e., the person or organization capable of deploying this capability offensively, no longer requires the deep technical expertise that previously constrained offensive operations.

In intelligence terms, this eliminates a key barrier to entry that has historically allowed the national security apparatus to maintain relative confidence about the population of actors capable of conducting sophisticated cyber operations. The implicit assumption that attribution correlates with technical sophistication (a bedrock of offensive cyber strategy) is no longer reliable when Mythos Preview is in the operational environment.

Furthermore, the red team’s disclosure that Mythos Preview “saturates” existing benchmarks and has therefore moved to novel real-world tasks to assess capabilities means that Anthropic itself does not have a complete picture of the model’s upper limit. The capabilities documented represent a lower bound on what the model can do, filtered through the constraints of responsible disclosure timelines.

National Security Threat Vectors

The specific threat profiles that Mythos Preview introduces to the national security environment can be organized across four categories:

  1. Critical Infrastructure Targeting
    The FreeBSD RCE vulnerability, the VMM guest-to-host memory corruption bug, and the range of Linux kernel exploits documented by Anthropic span the server infrastructure that underlies cloud computing, financial systems, energy grid management systems, and classified government networks. Autonomous exploit generation against NFS servers is particularly alarming given NFS’s pervasive deployment in enterprise and government environments. A threat actor with access to a model of comparable capability — through Glasswing access, through independent development, or through acquisition — could conduct pre-positioned access operations across critical infrastructure at a scale and speed previously impossible.
  2. Intelligence Network Compromise
    The cryptographic library vulnerabilities identified by Mythos Preview — including authentication bypass in certificate validation and vulnerabilities in TLS and SSH implementations — represent a direct threat to secure communications infrastructure. The ability to forge certificates or decrypt encrypted traffic undermines the technical foundations of both classified communications and the broader internet trust model. A compromise of widely deployed cryptographic libraries, discovered and exploited at the speed Mythos Preview operates, could enable mass surveillance or targeted interception before defensive patches propagate.
  3. Supply Chain Attack Amplification
    Mythos Preview’s capability to find vulnerabilities in closed-source software via reverse engineering dramatically expands the attack surface available to adversaries conducting supply chain operations. Historically, supply chain attacks have required either insider access to source code or exceptionally skilled reverse engineers with deep platform expertise. Mythos Preview narrows this requirement to access to the binary and an API subscription. The implications for hardware abstraction layers, firmware, and proprietary operating system components — many of which exist in classified and defense industrial base environments — are severe.
  4. Democratization of Advanced Persistent Threat Capability
    Perhaps the most significant national security implication is structural rather than targeting-specific. The exploitation techniques demonstrated by Mythos Preview — multi-stage KASLR bypasses, HARDENED_USERCOPY evasion through per-CPU memory region targeting, JIT heap sprays chained to sandbox escapes — are techniques that were, as of 2025, associated exclusively with the most sophisticated nation-state APT groups. The documented ability of Mythos Preview to construct these exploits from first principles, at sub-$1,000 cost, means that the technical barrier separating Tier-1 nation-state actors from lower-tier threats has collapsed. Attribution models, deterrence frameworks, and the strategic calculus of cyberspace operations all require re-examination.

Project Glasswing: A Framework Inadequate to the Threat

Anthropic’s interim protective framework, Project Glasswing, restricts initial access to Mythos Preview to a curated set of critical industry partners and open source developers. The stated rationale is to provide defenders an opportunity to harden the most critical systems before models with equivalent capabilities become broadly available.

This approach reflects reasonable intent and is preferable to unrestricted release. It is nonetheless inadequate to the national security threat it purports to address, for the following reasons:

Access control is not capability control. Project Glasswing gates who can use Mythos Preview today. It does not prevent adversarial actors from developing equivalent capabilities independently. Anthropic’s own red team acknowledges that the capabilities emerged as a downstream consequence of general improvements in code, reasoning, and autonomy — not from explicit security-focused training. Any frontier AI laboratory pursuing similar general capability improvements will likely encounter comparable emergent security capabilities. The window during which Glasswing access controls provide meaningful differentiation may be months, not years.

The responsible disclosure timeline creates a structural vulnerability window. Anthropic acknowledges that fewer than 1% of the vulnerabilities Mythos Preview has identified have been patched as of the red team disclosure. The disclosure process involves professional human triagers validating findings before notifying maintainers, who then have 90 to 135 days to issue patches. During this entire period, which spans potentially years given the scale of findings, critical vulnerabilities exist in a state where Anthropic, its contractors, and its disclosure partners know of them but the public does not. This creates a concentration of offensive knowledge that is itself a national security risk if any element of that disclosure chain is compromised by a sophisticated adversary.

The framework applies only to Anthropic. Glasswing is a unilateral constraint by a single laboratory. It imposes no obligations on other frontier AI developers, no requirements on nation-state AI programs, and no verification mechanism. The history of dual-use technology governance, from nuclear to biological to cyber, demonstrates that unilateral restraint by one actor in the absence of binding multilateral frameworks does not prevent capability proliferation. It may, in the short term, simply create a competitive disadvantage for the restrained actor relative to those who face no equivalent constraints.

The scalability of the threat exceeds the capacity of coordinated disclosure. Anthropic reports identifying thousands of high- and critical-severity vulnerabilities, with human validators agreeing with severity assessments in 89% of reviewed cases. If this rate holds across the full corpus, the total number of critical vulnerabilities in the disclosure pipeline exceeds any coordinated vulnerability disclosure process’s realistic throughput. Relaxing human-review requirements, something which Anthropic has already flagged as potentially necessary, introduces quality and security risks into the disclosure chain itself.

Implications for National Security Policy

Several policy imperatives follow from this analysis:

Immediate integration into threat intelligence frameworks. Intelligence community threat models for cyber operations must be updated to treat Mythos Preview-class capability as a near-term adversary tool, not a future hypothetical. Attribution models for sophisticated exploit development must account for the possibility that what was previously assessed as Tier-1 nation-state tradecraft may now be accessible to a significantly wider range of actors.

Emergency coordinated patching for identified vulnerability classes. The federal government’s cybersecurity apparatus (i.e., CISA, NSA Cybersecurity Directorate, sector-specific agencies) must engage directly with Anthropic’s disclosure process to accelerate patching of findings affecting federal information systems and critical infrastructure. The NFS exploitation capability alone, given FreeBSD’s deployment in both commercial and government environments, warrants immediate emergency action.

Multilateral AI governance engagement on dual-use capability thresholds. The emergence of Mythos Preview demonstrates that existing AI governance frameworks, including voluntary commitments secured under prior international AI safety initiatives, DO NOT address autonomous offensive cyber capability as a defined red line. Urgent diplomatic engagement on binding international standards for capability disclosure, testing requirements, and access controls for models demonstrating APT-level exploit generation is required.

National capability development and defensive deployment. The long-term defensive potential of models like Mythos Preview is real; Anthropic’s red team argues persuasively that the advantage will ultimately favor defenders. Ensuring that outcome requires active government investment in deploying these capabilities defensively — across federal information systems, critical infrastructure, and defense industrial base environments — at a pace that matches the adversarial threat curve.

My Parting Thoughts

Claude Mythos Preview is not a hypothetical future threat. It is a documented, deployed system with verified capability to autonomously discover and exploit critical vulnerabilities in the foundational software that undergirds national security infrastructure — at a cost, speed, and accessibility that eliminates the expert-scarcity barrier that has historically constrained sophisticated offensive cyber operations.

Project Glasswing represents an attempt by Anthropic to navigate an extraordinarily difficult dual-use deployment problem responsibly. It is NOT a solution to the national security implications of this capability class. It is, at best, a grace period, the duration of which is measured in competitive AI development timelines that no single lab controls.

The counterintelligence professional’s fear, upon encountering these capabilities, is well-founded. The appropriate response is not panic, but urgency: urgency in patching, urgency in attribution model revision, urgency in policy development, and urgency in defensive deployment of the very capabilities that make the threat so acute. The adversary who first operationalizes Mythos-class capability at scale will achieve a strategic advantage in cyberspace that existing frameworks are not designed to counter.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Share this post:

Operation Merlin: A D&D Failure by Strategic Compromise

Operation Merlin, denial and deception, d and d, intelligence, counterintelligence, espionage, counterespionage, HUMIN, C. Constantin Poindexter, CIA, NSA, DIA

Operation Merlin: A Denial and Deception Case Study in Covert Sabotage and the Anatomy of a Strategic Blunder of Enormous Proportions

Operation Merlin was a clandestine CIA program designed to undermine Iran’s nuclear weapons development program by inserting deliberately sabotaged warhead component blueprints through a recruited human asset. Executed from approximately 1998 through the early 2000s, the operation was an ambitious attempt at deception against a state-level nuclear proliferator. I am going to share my thoughts here about Operation Merlin through the lens of Denial and Deception (D&D) doctrine, evaluate its design, execution, and compromise against accepted deception planning frameworks. Drawing on trial exhibits from United States v. Sterling (2015), investigative reports, and foundational D&D literature, my opinion is that Operation Merlin, while possessing a sound deception concept, suffered from catastrophic failures in channel selection, feedback architecture, operational security, and post-compromise institutional decision-making that collectively rendered it not merely ineffective but potentially counterproductive to the national security interests it was designed to serve.

I. Introduction: Deception as Counterproliferation

The use of deception as a counterproliferation tool occupies an uncomfortable space in American intelligence history. Unlike tactical battlefield deception or strategic wartime misdirection, i.e., domains in which the United States and its allies developed sophisticated doctrinal frameworks during the Second World War, deception operations targeting foreign weapons programs operate in a gray zone where the consequences of failure are measured not in lost engagements but in accelerated existential threats. Operation Merlin sits at the center of this tension: an operation whose architects understood the strategic imperative but whose execution betrayed a fundamental misapprehension of the doctrinal requirements for successful material deception against a sophisticated state adversary.

To offer a robust eveluation of Merlin, we need to move beyond the narrative of its public exposure (the prosecution of CIA case officer Jeffrey Sterling, the journalism of James Risen, the spectacle of a federal trial in which CIA operatives testified behind seven-foot partitions) and instead subject the operation to the same analytical framework that professional deception planners apply to their own work. This essay applies the six-element D&D planning framework derived from Barton Whaley’s foundational taxonomy in Stratagem: Deception and Surprise in War (Whaley, 2007), Richards Heuer’s cognitive analytical model from Psychology of Intelligence Analysis (Heuer, 1999), and the operational principles codified in Joint Publication 3-13.4, Military Deception (Joint Chiefs of Staff, 2012), supplemented by the historical precedent of the XX Committee’s Double Cross System as the benchmark for successful material deception at scale.

II. Strategic Context and the Deception Concept

By the late 1990s, the U.S. Intelligence Community assessed with growing confidence that Iran was pursuing nuclear weapons capability, though the evidentiary basis for this assessment remained contested internally. The 2001 National Intelligence Estimate, the first to formally conclude that Iran was working toward a nuclear weapon, was later characterized by Paul Pillar, then the CIA’s National Intelligence Officer for the Near East and South Asia, as resting on “a matter of inference” rather than direct evidence (Porter, 2014). Nevertheless, the policy imperative to disrupt Iran’s nuclear trajectory was acute, and the menu of available options was constrained by the absence of a viable military target set and the diplomatic limitations of the post-JCPOA environment that would not materialize for another fifteen years.

Into this gap stepped the CIA’s Directorate of Operations with a proposal rooted in material deception: recruit a Russian nuclear scientist with legitimate technical credentials, provide him with doctored blueprints for a nuclear warhead firing set, and direct him to deliver these blueprints to Iranian officials under the legend of a mercenary walk-in seeking financial compensation for proliferation-grade technical intelligence (Risen, 2006).

Within Whaley’s taxonomy, this concept falls squarely under the category of “mimicking”, creating a false artifact that imitates a real one closely enough to be accepted as authentic by the target (Whaley, 2007). The doctored blueprints were not fabrications from whole cloth; they were based on genuine Russian weapons designs, modified to contain dozens of hidden engineering flaws that would cause any device constructed from them to fail. The deception’s success depended on the flaws being sufficiently subtle to evade detection by Iranian scientists while being sufficiently fundamental to render the resulting weapon inoperable.

The concept was sound. Material deception (the introduction of fabricated or corrupted physical artifacts into an adversary’s intelligence or procurement stream ) has a long and occasionally successful history, from Operation Mincemeat’s fictitious invasion plans in 1943 to the CIA’s Cold War-era contamination of Soviet technical collection channels. The critical question was never whether the concept could work in principle, but whether the CIA possessed the operational infrastructure, tradecraft discipline, and institutional patience to execute it against a counterintelligence-aware adversary like Iran.

III. Operational Design and Execution

The operation’s centerpiece was a human asset — a Russian nuclear engineer recruited by the CIA and referred to at trial under the cryptonym “Merlin” (United States Department of Justice [USDOJ], 2015). Merlin possessed genuine scientific credentials, making him a plausible vector for the delivery of proliferation-grade material. His CIA handler from November 1998 through May 2000 was case officer Jeffrey Alexander Sterling, who managed the asset relationship and coordinated the operational logistics of the delivery (USDOJ, 2015).

The delivery was designed to exploit a known vulnerability in Iran’s procurement architecture: its reliance on intermediaries and walk-in sources for weapons-relevant technical intelligence. Merlin was directed to approach Iran’s mission to the International Atomic Energy Agency (IAEA) in Vienna, Austria, and provide an incomplete set of the doctored blueprints. The incompleteness was deliberate. It created an incentive structure requiring the Iranians to re-contact Merlin for the remaining schematics, thereby confirming acceptance of the bait and potentially opening a sustained intelligence collection channel into Iran’s nuclear procurement apparatus (Risen, 2006).

Former National Security Adviser Condoleezza Rice testified at Sterling’s trial that the program was “one of the only levers we had to try to disrupt Iran’s nuclear program” and characterized it as among the government’s “most closely held secrets” (Barakat, 2015). Rice further stated that she personally intervened with the New York Times to suppress publication of a story about the operation, arguing that exposure could result in catastrophic loss of life (Gerstein, 2015).

The execution in February 2000 deviated significantly from the operational plan. Merlin’s testimony at trial revealed that he had difficulty locating the Iranian mission in Vienna. When he found it, no one answered the door. He ultimately placed the envelope containing the blueprints in a mailbox and covered it with a newspaper (Solomon, 2015). Additionally, Merlin deviated from his handlers’ instructions regarding the contact mechanism: rather than providing an American mailing address as directed, he substituted an email address, reasoning that an American postal address would appear suspicious to Iranian counterintelligence and could be traced back to him (Solomon, 2015).

These deviations carry BIG implications when evaluated against D&D doctrine. An asset who autonomously modifies operational parameters based on his own risk calculus (however rational that calculus may be) introduces uncontrolled variables into the deception architecture. More critically, Merlin’s technical competence, which made him a credible channel, simultaneously made him capable of evaluating the material he was tasked to deliver. According to Risen’s account, Merlin recognized the deliberate flaws in the schematics and transmitted his belief along with the delivery which signaled to the Iranians that the blueprints were intelligence service-manufactured, allowing Iranian scientists to identify and discard the sabotaged elements while extracting legitimate technical data (Risen, 2006). Merlin denied these characterizations under oath, testifying that Risen’s depiction of him as reluctant was “completely untrue” (Solomon, 2015). The divergence itself is analytically significant: if Risen’s source was not Merlin, then whoever provided those details possessed the kind of intimate operational knowledge consistent with a case officer’s access.

IV. D&D Doctrinal Evaluation

A. Desired Perception

The foundational requirement of any deception operation is a clearly defined desired perception, i.e., the specific belief the operation is designed to induce in the target’s mind (Joint Chiefs of Staff, 2012). Operation Merlin’s desired perception was straightforward: that the blueprints were genuine proliferation material obtained through an illicit procurement channel (a disgruntled or mercenary Russian scientist selling weapons knowledge for financial gain).

This perception was plausible on its face. Russian nuclear scientists in the post-Soviet period were documented to be underpaid, underemployed, and in some cases actively solicited by proliferating states. The desired perception exploited a real phenomenon, which is doctrinally correct. The most effective deceptions are those anchored in patterns the target already recognizes and expects (Heuer, 1999). Assessment: Adequate.

B. The Deception Story

The constructed narrative, a Russian scientist approaching Iran’s IAEA mission as a walk-in, offering warhead-grade schematics for money, was coherent as a standalone legend. Walk-in approaches by foreign nationals offering technical intelligence were not unprecedented in proliferation networks.

However, there is no indication in the trial record that the CIA subjected this story to rigorous adversarial analysis “red-teaming” we call it. The planners missed specifically examining how Iran’s Ministry of Intelligence and Security (VEVAK) would process and evaluate a cold-approach walk-in offering firing set blueprints. VEVAK had extensive institutional experience identifying Western intelligence provocations, and a walk-in of this nature. An unsolicited player offering the single most sensitive category of weapons data, with no prior relationship or established bona fides would have triggered significant counterintelligence scrutiny. The absence of documented red-team analysis suggests the deception story was evaluated for internal plausibility rather than adversarial resilience. Assessment: Deficient.

C. Channel Selection

D&D doctrine, codified in lessons from the London Controlling Section’s World War II operations and subsequent CIA and DoD guidance, instructs that the credibility of the delivery channel is the single most critical variable in material deception. The channel must be one that the adversary already trusts or is predisposed to trust, typically because the source has previously provided verified intelligence, is embedded in a network the adversary already exploits, or mimics an approach pattern the adversary has successfully used before (Holt, 2004).

From Iranian FIS’s perspective Merlin possessed none of these attributes . He was an unknown entity conducting a cold approach. His operational execution was amateurish, i.e., unable to locate the mission, leaving material in an unattended mailbox, etc.. From an Iranian counterintelligence officer’s perspective, applying the analytical principles Heuer articulated, the approach contained no prior cognitive anchor that would predispose acceptance (Heuer, 1999). The channel was cold, unvetted from the target’s vantage point, and operationally clumsy.

Taking a lesson from history, the Double Cross System is instructive. The XX Committee’s deception channels, turned German agents who fed disinformation to the Abwehr, were effective precisely because they were channels the adversary had already accepted and validated through prior intelligence exchanges. Double Cross built credibility over months and years of carefully calibrated true-false reporting mixtures before introducing critical strategic deceptions like FORTITUDE. Operation Merlin attempted to deliver the equivalent of FORTITUDE-grade material through a channel with zero established credibility. Assessment: Critically Deficient.

D. Feedback Architecture

The operation’s feedback mechanism was its most elegant design element: the deliberate incompleteness of the blueprints created a natural trigger requiring Iran to re-contact Merlin for the remaining schematics, thereby confirming acceptance.

The problem was singular and fatal: Iran never responded. This silence created an analytical void that the operation had no means to resolve. The CIA could not determine whether Iran had detected the deception and discarded it, had accepted the material but chose to develop it independently, had never routed the material to a competent analyst, or whether VEVAK had flagged the approach as a provocation and filed it as a counterintelligence reference.

Well-designed deception operations maintain redundant feedback mechanisms precisely to prevent this kind of interpretive paralysis. The Double Cross System’s feedback architecture, continuous monitoring of German assessments through ULTRA decrypts of Abwehr and OKW communications, allowed deception planners to observe in near-real-time whether their false intelligence was being accepted, rejected, or partially integrated, and to adjust their deception stories accordingly (Howard, 1995). Operation Merlin had a single feedback point, and when that point went silent, the operation was effectively blind. No secondary collection mechanism (SIGINT, HUMINT from other sources inside Iran’s nuclear apparatus, or technical surveillance of Iranian procurement activity) was established to provide independent confirmation of the operation’s effect. Assessment: Critically Deficient.

E. Adaptability

Nothing in the trial record indicates that the CIA developed contingency plans for the various failure modes the operation might encounter — Iranian detection, asset compromise, the asset’s autonomous deviation from instructions, or operational exposure through internal security breaches. The reassignment of Sterling in May 2000 without documented succession planning or compartmentation review further suggests that continuity of operations planning was inadequate (USDOJ, 2015). He was the only player with intimate knowledge of the asset. When Sterling subsequently entered an adversarial posture with the agency, there was no adaptive mechanism to contain the resulting vulnerability. Assessment: Critically Deficient.

F. Operational Security

This is where Operation Merlin became a catastrophic F.U. The universe of individuals with knowledge of the operation expanded and expanded. The President, the National Security Adviser, senior CIA leadership, multiple case officers, the Russian asset and his wife, and after Sterling raised concerns through ostensibly proper channels, staffers on the Senate Select Committee on Intelligence knew it all. Each additional read-in was a point of compromise.

The most fundamental security failure was personnel-related. Sterling possessed direct, intimate knowledge of the operation, the asset’s identity, the tradecraft, and the operational dynamics. He was reassigned and then, within three months, became an Agency “adversary”. Counterintelligence doctrine requires enhanced monitoring of personnel with access to sensitive compartmented information who demonstrate indicators of potential unreliability. That would ABSOLUTELY include legal disputes with the employing I.C. agency. There is no indication that any such monitoring was implemented (Gerstein, 2015; Solomon, 2015). Assessment: Catastrophically Deficient.

V. The Vectors of Compromise

Operation Merlin was compromised through three distinct vectors, each representing a failure at a different level of the D&D security architecture.

The asset’s autonomous judgment constituted the first vector. Merlin’s technical competence, the very attribute that made him a credible channel, enabled him to evaluate and potentially undermine the material he was tasked to deliver. This is a structural paradox inherent in using technically sophisticated assets for material deception: the more credible the channel, the more capable it is of detecting and subverting the deception it carries.

The case officer’s grievance constituted the second vector. The prosecution established through communications metadata that Sterling and Risen were in contact during the periods preceding and following the publication of State of War, i.e., phone calls to Risen’s residence, emails containing articles related to Sterling’s former operational portfolio, and continued contact from December 2003 through November 2005 (USDOJ, 2015). Sterling’s defense argued that Senate Intelligence Committee staffers were a more plausible source and that the government’s evidence proved only communication, not the transmission of classified content (Wheeler, 2015). The jury found the circumstantial evidence sufficient, convicting Sterling on nine felony counts on January 26, 2015, and Judge Leonie Brinkema sentenced him to forty-two months (USDOJ, 2015).

The government’s self-compromise constituted the third and most strategically damaging vector. In prosecuting Sterling under the Espionage Act, the government introduced CIA operational cables, internal planning documents, and testimony from twenty-three CIA officers into the public record of a federal courtroom (Solomon, 2015). The trial revealed the operational concept, the asset’s role, the delivery methodology, the nature of the sabotaged blueprints, and the strategic rationale in far greater specificity than Risen’s book had disclosed. Bloomberg News reported from Vienna that the IAEA would “probably review intelligence they received about Iran as a result of the revelations,” with a former British envoy to the IAEA warning that the disclosures suggested “a possibility that hostile intelligence agencies could decide to plant a ‘smoking gun’ in Iran for the IAEA to find” (Solomon, 2015). Prosecutor James Trump acknowledged at sentencing that the exposure “ended the use of the nuclear-plans ruse against other countries” (Gerstein, 2015).

This third vector represents the most consequential D&D failure. In attempting to punish a compromise that had exposed a single operation, the government’s prosecution compromised an entire deception methodology. Any state with access to the public trial record — which now constitutes the most comprehensive open-source documentation of a CIA material deception program targeting a foreign nuclear capability — could retroactively audit its own procurement channels for similar operations and inoculate itself against future attempts. This is SPECIFICALLY why I refer to this as a strategic rather than tactical or operational disaster.

The Anti-Double Cross

Evaluated in its totality against the D&D planning framework, Operation Merlin represents something approaching the inverse of the Double Cross System. Where Double Cross maintained dozens of simultaneous channels with established credibility, Merlin relied on a single cold channel with no prior validation. Where Double Cross monitored adversary acceptance in near-real-time through ULTRA, Merlin had a single feedback mechanism that produced silence. Where Double Cross adapted its deception narratives continuously based on observed adversary reactions, Merlin had no adaptive capability. Where Double Cross maintained ruthless operational security — including the execution of compromised agents — Merlin allowed a disaffected case officer with comprehensive operational knowledge to depart the agency in an adversarial posture without enhanced counterintelligence monitoring.

The strategic concept underlying Operation Merlin (using sabotaged technical intelligence to misdirect a proliferating state’s weapons development) was theoretically sound. In a different operational context, I believe that it was completely viable. The failure was not conceptual but executional: a series of compounding deficiencies in channel selection, feedback architecture, adaptability, and operational security that transformed an ambitious deception operation into what may ultimately have been a net intelligence gain for the very adversary it was designed to deceive.

For the counterintelligence professional, Operation Merlin’s most enduring lesson may be its final chapter. The institutional impulse to punish unauthorized disclosure, when pursued through the adversarial transparency of a federal prosecution, can inflict damage orders of magnitude greater than the original compromise. The prosecution of Jeffrey Sterling did not restore the secrecy of Operation Merlin. It annihilated it. With it went the viability of an entire category of covert action against nuclear proliferators for the foreseeable future.

Regardless of which and what was worse, the results ware and are BAAADD. The op. is now a template. Any state with a competent intelligence service and access to the trial record (which is to say, absolutely everyone) can now retroactively audit its own procurement channels for operations matching this kind of pattern. The Agency has also created a counterintelligence inoculation of the adversary set. Every proliferating state now possesses a known reference case for how the U.S. I.C. constructs material deception against nuclear programs. Add to that the diplomatic blowback with the IAEA and lingering Iran-theatre analytical poisoning, and this becomes even uglier.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Barakat, M. (2015, January 16). CIA asset ‘Merlin’ testifies about mission at CIA leak trial. Associated Press.
  • Gerstein, J. (2015, May 11). Former CIA officer sentenced to 3-1/2 years for leaking Iran details. Politico.
  • Heuer, R. J. (1999). Psychology of intelligence analysis. Center for the Study of Intelligence, Central Intelligence Agency.
  • Holt, T. (2004). The deceivers: Allied military deception in the Second World War. Scribner.
  • Howard, M. (1995). Strategic deception in the Second World War: British intelligence operations against the German High Command. W. W. Norton.
  • Joint Chiefs of Staff. (2012). Joint Publication 3-13.4: Military deception. U.S. Department of Defense.
  • Porter, G. (2014). Manufactured crisis: The untold story of the Iran nuclear scare. Just World Books.
  • Risen, J. (2006). State of war: The secret history of the NSA and the Bush administration. Free Press.
  • Solomon, N. (2015, February 27). CIA evidence from whistleblower trial could tilt Iran nuclear talks. Guernica.
  • United States Department of Justice. (2015, May 11). Former CIA officer sentenced to 42 months in prison for leaking classified information and obstruction of justice [Press release].
  • United States of America v. Jeffrey Alexander Sterling, No. 1:11-cr-00005 (E.D. Va. 2015). Selected case files. Federation of American Scientists, Project on Government Secrecy.
  • Whaley, B. (2007). Stratagem: Deception and surprise in war. Artech House.
  • Wheeler, M. (2015, February 21). What was the CIA really doing with Merlin by 2003? EmptyWheel.

Share this post:

Partizan Crap Characterizes the 2026 I.C. Threat Assessment

national threat assessment, intelligence community, CIA, NSA, DIA, espionage, counterespionage, intelligence, counterintelligence, C. Constantin Poindexter

Unvarnished No More: The 2026 Annual Threat Assessment and the Politicization of American Intelligence, a Critical Analysis of Departures from Intelligence Community Analytical Traditions

On March 18, 2026, Director of National Intelligence Tulsi Gabbard presented the 2026 Annual Threat Assessment (ATA) to the Senate Select Committee on Intelligence, fulfilling the Intelligence Community’s statutory obligation under Section 617 of the FY21 Intelligence Authorization Act. The document’s own introduction pledges to deliver “nuanced, independent, and unvarnished intelligence” to policymakers (Office of the Director of National Intelligence [ODNI], 2026, p. 2). Yet a careful comparison of the 2026 ATA with its predecessors reveals systematic omissions, rhetorical softening, and political editorializing that collectively undermine the document’s claim to analytical independence. I argue that the 2026 ATA departs from Intelligence Community analytical traditions in ways that align with the administration’s political preferences, particularly regarding Russia, domestic extremism, and climate, and that these departures represent a failure of the DNI’s duty to provide unvarnished intelligence to Congress and the American people.

The significance of this argument cannot be overstated. The ATA exists precisely because democratic governance requires that elected officials receive honest assessments of threats, unfiltered by political convenience. Intelligence Community Directive 203, issued in 2007, codified the community’s formal tradecraft standards, mandating objectivity, transparency regarding sources and assumptions, and independence from political considerations (Just Security, 2025). The Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA) further requires that the DNI ensure intelligence products are “timely, objective, independent of political considerations, based upon all sources of available intelligence, and employ the standards of proper analytic tradecraft” (Pub. L. No. 108-458, § 1019). When an ATA is shaped to avoid contradicting the sitting president’s preferred narratives, it ceases to function as intelligence and instead becomes an instrument of political communication.

The Softening of Russia as a Strategic Threat

The 2024 ATA, produced under DNI Avril Haines, described Russia’s aggression in Ukraine as underscoring that Moscow “remains a threat to the rules-based international order” (ODNI, 2024, p. 5). The 2026 ATA, by contrast, introduces conciliatory language throughout its Russia analysis that reads less like threat assessment and more like diplomatic aspiration. It states that “Russia’s aspirations for multipolarity could allow for selective collaboration with the U.S. if Moscow’s threat perceptions regarding Washington were to diminish” and suggests that “a durable settlement to the war in Ukraine could open the door for a thaw in U.S.–Russia relations and an improved bilateral geostrategic and commercial relationship” (ODNI, 2026, pp. 27–28). This framing mirrors the administration’s diplomatic posture toward Moscow rather than the IC’s traditional threat-focused analytical lens.

The document further characterizes the concept of adversary alignment among China, Russia, Iran, and North Korea as overstated, calling it “limited and primarily bilateral” and asserting that the notion “overstates the depth of cooperation that is currently occurring” (ODNI, 2026, p. 20). This downgrading arrives despite the IC’s own acknowledgment in the same document that North Korea deployed over 11,000 troops to support Russian combat operations in Ukraine (ODNI, 2026, p. 24). The analytical minimization of adversary cooperation is consistent with President Trump’s longstanding reluctance to characterize Russia as an adversary, a posture that dates to his public siding with Vladimir Putin over U.S. intelligence findings at the 2018 Helsinki summit (Foreign Policy Research Institute [FPRI], 2019) as well as the point of view expressed by Gabbard publicly even predating her position within the I.C.

The Disappearance of Foreign Election Interference

Perhaps the most conspicuous omission in the 2026 ATA is the near-total absence of any discussion of foreign interference in U.S. elections. As Defense One reported, this marks the first time in nearly a decade that foreign threats to U.S. elections have been omitted from the annual threat assessment (Defense One, 2026). The 2024 ATA explicitly warned that China, Russia, and Iran would attempt to interfere in U.S. elections using generative AI and other means (ODNI, 2024). The 2025 DHS Homeland Threat Assessment similarly identified the 2024 election cycle as “an attractive target for many adversaries” and warned that nation-state-aligned actors would “continue to target democratic processes” (DHS, 2024, p. 4). The ODNI itself published a separate report titled “Foreign Threats to US Elections After Voting Ends in 2024” (ODNI, 2024b). That this entire threat category has vanished from the 2026 ATA is analytically inexplicable absent political motivation.

When Senator Mark Warner, the panel’s top Democrat, pressed Gabbard on this omission at the March 18 hearing, asking whether there was “no foreign threat to our elections in the midterms this year,” Gabbard’s response was evasive, stating only that the IC “has been and continues to remain focused on any collection and intelligence that show a potential foreign threat” (Defense One, 2026). This non-answer is consistent with DNI Gabbard’s broader pattern of minimizing Russian interference in American democracy. In July 2025, Gabbard declassified documents she claimed exposed a “treasonous conspiracy” by Obama-era officials regarding the 2016 Russian interference findings—allegations that multiple investigations, including the Republican-led Senate Intelligence Committee’s own probe, had already examined and found unsubstantiated (CNN, 2025; Lawfare, 2025). As the Council on Foreign Relations assessed, Gabbard’s actions have “deprived her of any pretension to analytical judgment independent of the president” (Betts, 2025).

The Erasure of Domestic Violent Extremism

The 2026 ATA’s terrorism section is focused almost exclusively on Islamist terrorism. Domestic violent extremism (DVE)—a category that encompasses racially or ethnically motivated extremism, anti-government militias, and other ideologically motivated domestic threats—receives no dedicated treatment. This stands in stark contrast to years of IC and DHS assessments that identified DVE as among the most persistent threats to the homeland. The DHS’s 2024 Homeland Threat Assessment warned that domestic violent extremists “driven by various anti-government, racial, or gender-related motivations” had conducted multiple attacks and that law enforcement had disrupted additional plots (DHS, 2024). The FBI reported over 1,700 domestic terrorism investigations underway as of late 2024 (House Homeland Security Committee, 2025). The Government Accountability Office released a comprehensive report in 2025 documenting the federal government’s ongoing domestic terrorism strategies and the persistent nature of the threat (GAO, 2025).

The omission of DVE from the 2026 ATA aligns with the Trump administration’s broader effort to reframe the terrorism discourse around Islamist ideology while downplaying threats from domestic actors whose motivations often overlap with right-wing political movements. The 2026 ATA’s extended discussion of the Muslim Brotherhood and its characterization of Islamist ideology as a “fundamental threat to freedom and foundational principles that underpin Western Civilization” (ODNI, 2026, p. 8) represents an analytical emphasis not seen in prior ATAs, which treated the terrorism landscape as ideologically diverse. This selective emphasis serves the administration’s political narrative while leaving Congress and the public without the IC’s assessment of a threat category that the FBI’s own data indicates remains active and lethal. It also unironically gives cover to a not insignificant group of Trump supporters, certainly purposeful by design.

The Removal of Climate Change as a Security Threat

The 2024 ATA treated climate change as a significant threat multiplier, stating that “the accelerating effects of climate change are placing more of the world’s population, particularly in low- and middle-income countries, at greater risk from extreme weather, food and water insecurity, and humanitarian disasters, fueling migration flows and increasing the risks of future pandemics” (ODNI, 2024, p. 5). Climate change appeared throughout that document as a driver of instability across multiple regions, including in assessments of Iran’s water scarcity challenges. The 2026 ATA eliminates climate change entirely as a named threat category. The term does not appear once. A single passing reference to “extreme weather events” in the migration section (ODNI, 2026, p. 7) is the only remnant of what had been a substantial analytical thread across multiple prior assessments.

This excision is not analytically defensible. The physical phenomena that made climate change a security concern in 2024 have not abated in 2026; if anything, the scientific consensus has strengthened. The removal reflects the Trump administration’s hostility toward climate science as a policy matter—a political preference that has no legitimate bearing on an intelligence community’s assessment of how environmental change affects geopolitical stability, food security, migration patterns, and conflict risk. The DNI’s role is to present the IC’s best assessment of reality, not to curate that reality to avoid topics the White House considers ideologically inconvenient.

Political Editorializing in an Intelligence Product

The 2026 ATA’s Foreword contains language that would have been unthinkable in prior assessments. It credits “President Trump sealing the U.S.–Mexico border” for enforcement successes and notes that “fentanyl seizures by weight have decreased 56 percent at the U.S.–Mexico border since President Trump took office” (ODNI, 2026, pp. 4–5). Annual threat assessments have traditionally employed dry, institutional prose that avoids attributing policy outcomes to individual political leaders by name. The function of an ATA is to assess threats, not to validate a president’s policy record. This departure transforms portions of what should be an analytical document into something resembling a political communication.

The editorializing extends beyond border policy. The Foreword adopts the administration’s rhetorical framework wholesale, stating that “we should be cautious about thinking that every problem in the world directly threatens us” (ODNI, 2026, p. 4)—a statement that, while perhaps reasonable in isolation, mirrors the administration’s America First foreign policy framing rather than reflecting IC analytical tradition. As scholars at the Foreign Policy Research Institute have warned, when political appointees shape intelligence products to serve the president’s messaging priorities, the core mission of the intelligence community—to provide independent analysis that may contradict leadership preferences—is fundamentally compromised (FPRI, 2019). The AEI documented how Gabbard fired the acting chair of the National Intelligence Council and his deputy after they produced assessments that contradicted administration positions, then physically relocated the NIC to her office to prevent what she characterized as “politicization” (American Enterprise Institute, 2025).

My Thoughts

From my view, the cumulative effect of these five departures, i.e., the softening of Russia’s threat profile, the erasure of foreign election interference, the omission of domestic violent extremism, the elimination of climate change as a security concern, and the introduction of political editorializing, is an Annual Threat Assessment that fails its statutory and institutional purpose. Each omission or distortion aligns with known political preferences of the Trump administration, and each contradicts the IC’s own recent analytical record. The IRTPA requires the DNI to ensure that intelligence is “independent of political considerations.” Intelligence Community Directive 203 mandates “objectivity, transparency regarding sources and assumptions, and independence from political considerations” (Just Security, 2025). The 2026 ATA, by its own internal evidence, fails both standards.

The consequences of this failure extend beyond the document itself. When intelligence products become vehicles for political messaging, policymakers lose the independent analytical baseline they need to make informed decisions. Congressional oversight is undermined when the IC’s primary public-facing threat assessment omits entire threat categories for political reasons. And public trust in the intelligence community, already strained by decades of controversy, erodes further when citizens can compare successive ATAs and observe that threats appear and disappear not because the world has changed but because the White House has changed. As Richard Betts of the Council on Foreign Relations observed, intelligence’s prime value often lies in telling leaders facts or implications they do not want to hear (Betts, 2025). A DNI who cannot or will not fulfill that function has, in the most consequential sense, abdicated the office’s reason for existing. The inconvenient truth is that the DNI’s acts and omissions are willful, a fact on perfect display during the Congressional hearing today (March 18th), during which Gabbard said, “Senator, the only person who can determine what is and is not an imminent threat is the president.” The Intelligence Community’s primary task is to provide warning intelligence, which is the very definition of the reporting of an “imminent threat”.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

References

  • American Enterprise Institute. (2025, May 21). The politicization of intelligence. AEI. https://www.aei.org/articles/the-politicization-of-intelligence/
  • Betts, R. K. (2025, August 21). The intelligence community’s politicization: Dueling to discredit. Council on Foreign Relations. https://www.cfr.org/articles/intelligence-communitys-politicization-dueling-discredit
  • Defense One. (2026, March 18). Annual threat assessment omits election security. https://www.defenseone.com/policy/2026/03/annual-threat-assessment-election-security/412217/
  • Department of Homeland Security. (2024). 2025 Homeland Threat Assessment. https://www.dhs.gov/sites/default/files/2024-10/24_1002_ia_homeland-threat-assessment-2025.pdf
  • Foreign Policy Research Institute. (2019, August 12). A nadir is reached in the politicization of U.S. intelligence. https://www.fpri.org/article/2019/08/a-nadir-is-reached-in-the-politicization-of-u-s-intelligence/
  • Government Accountability Office. (2025). Domestic terrorism: Additional actions needed to implement the national strategy (GAO-25-107030). https://www.gao.gov/assets/gao-25-107030.pdf
  • House Homeland Security Committee. (2025, December 19). Threat snapshot: House Homeland unveils updated “Terror Threat Snapshot” assessment. https://homeland.house.gov/2025/12/19/threat-snapshot/
  • Intelligence Reform and Terrorism Prevention Act of 2004, Pub. L. No. 108-458, 118 Stat. 3638.
  • Just Security. (2025, June 20). When intelligence stops bounding uncertainty: The dangerous tilt toward politicization under Trump. https://www.justsecurity.org/114297/trump-administration-politicized-intelligence/
  • Lawfare. (2025, August 6). From Russian interference to revisionist innuendo: What the Gabbard files actually say. https://www.lawfaremedia.org/article/from-russian-interference-to-revisionist-innuendo–what-the-gabbard-files-actually-say
  • NBC News. (2024, December 11). Would Tulsi Gabbard bring a pro-Russian bias to intelligence reporting? https://www.nbcnews.com/politics/national-security/will-tulsi-gabbard-bring-russian-bias-intelligence-reporting-rcna180248
  • Office of the Director of National Intelligence. (2024). 2024 Annual Threat Assessment of the U.S. Intelligence Community. https://www.dni.gov/files/ODNI/documents/assessments/ATA-2024-Unclassified-Report.pdf
  • Office of the Director of National Intelligence. (2026). 2026 Annual Threat Assessment of the U.S. Intelligence Community. https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf
  • PBS NewsHour. (2025, July 24). Gabbard pushes report on Obama and Russia probe. https://www.pbs.org/newshour/show/gabbard-pushes-report-on-obama-and-russia-probe-as-trump-faces-pressure-over-epstein
  • Wittes, B. (2025, July 22). The situation: The lies of Tulsi Gabbard. Lawfare. https://www.lawfaremedia.org/article/the-situation–the-lies-of-tulsi-gabbard
Share this post:

Silent Surveillance: The Threat of Tire Pressure Monitors

tire pressure monitoring system surveillance, intelligence, counterintelligence, counterespionage, C. Constantin Poindexter, CIA, NSA, DIA

Sneaking a covert GPS tracker into (or under) a motor vehicle is no longer spy-chic. Surveillants and counterintelligence players see a discreet new option.

In the contemporary era of information operations, the adversary’s toolkit has expanded beyond surveillance and HUMINT to include the exploitation of ubiquitous, low-power wireless signals. As a counterintelligence operator or surveillance professional, maintaining operational security requires a granular understanding of how standard automotive telemetry can be weaponized for tracking and profiling. While traditionally viewed as a mere safety mechanism, the Tire Pressure Monitoring System (TPMS) presents a sophisticated, low-cost vector for persistent surveillance. Here are my thoughts, technical architecture of TPMS vulnerabilities, the operational utility of its data streams, and the strategic implications for intelligence collection and target analysis, the new “AUTO-INT”.

Technical Architecture and Signal Vulnerabilities

The TPMS functions as a distributed sensing network within a vehicle, designed to ensure safety and optimize fuel efficiency by alerting drivers to under-inflated tires. In the United States, Federal Motor Vehicle Safety Standard (FMVSS) No. 138 mandates the use of direct TPMS in all light vehicles manufactured after September 2007 (Kobayashi, 2019). Technically, these systems consist of pressure sensors located within each wheel assembly, which periodically transmit radio frequency (RF) data to a central receiver module.

The critical vulnerability for intelligence collection lies in the transmission protocol and data integrity. Unlike modern communication standards, TPMS signals are transmitted in clear text without any form of encryption or authentication (Kobayashi, 2019). This lack of cryptographic protection renders the signals easily interceptable by any third party in proximity. Furthermore, these sensors broadcast a unique, static identifier for each tire that remains constant throughout the sensor’s operational life (Kobayashi, 2019). This static ID allows for the long-term tracking of a specific vehicle, as the identifier persists regardless of the sensor’s physical location or the vehicle’s operational status.

The range and reliability of interception capabilities further amplify the threat. Research indicates that TPMS signals can be intercepted at distances exceeding 40 meters from the vehicle (Kobayashi, 2019). Recent advancements in receiver technology have demonstrated that data capture is possible from distances of up to 50 meters and even when the receiver is located inside a building without direct line-of-sight to the vehicle (Vijayan, 2026). This capability allows for the passive collection of telemetry from vehicles parked in secured compounds, residential garages, or office parking lots, providing a persistent tracking vector that does not require the subject to be actively driving.

Operational Utility for Tracking and Behavioral Profiling

The operational value of TPMS extends beyond simple geolocation. It provides a rich dataset for behavioral profiling and movement analysis. A seminal study conducted by researchers at the University of Cantabria and distributed by Dark Reading demonstrated the feasibility of tracking a fleet of vehicles using a network of low-cost spectrum receivers (Vijayan, 2026). The research team captured over six million TPMS transmissions from approximately 20,000 vehicles over 10 weeks, successfully matching signals from different tires to the same vehicle to reconstruct movement patterns.

This data allows for the reconstruction of detailed movement profiles. By analyzing the timing, frequency, and intensity of transmissions, an operator can infer the subject’s driving patterns, such as commute routes, rest periods, and travel velocity. The researchers noted that TPMS transmissions can be systematically used to infer sensitive information, including the presence, type, or weight of the driver (Vijayan, 2026). Variations in tire pressure readings can correlate with changes in vehicle load, providing clues about whether a passenger is present or if cargo has been loaded or unloaded. In a counterintelligence context, this could reveal the presence of a handler, a meeting partner, or the movement of sensitive materials.

Implications for Operational Security and Countermeasures

For the counterintelligence operator, the existence of silent tracking via TPMS has profound implications for Operational Security (OPSEC). Traditional methods of tracking, such as visual tailing or license plate recognition, can be compromised if the target is aware of the surveillance. TPMS offers a covert alternative that operates passively and without direct interaction with the subject. An adversary could deploy a stationary receiver node in a strategic location, such as a choke point on a target’s daily commute, and aggregate data over time to build a comprehensive movement dossier without alerting the subject to the surveillance.

Furthermore, the ubiquity of TPMS makes this a scalable surveillance technique. The researchers utilized receivers priced at approximately $100 each, making it a cost-effective tool for intelligence collection compared to more sophisticated tracking hardware (Vijayan, 2026). The technology is not dependent on the subject’s connectivity to the internet or the activation of location services on a smartphone; it relies solely on the vehicle’s own safety systems.

My Take

The Tire Pressure Monitoring System represents a significant component of the modern surveillance landscape. Its inherent vulnerabilities (i.e., unencrypted, authenticated, and ubiquitous) make it an effective tool for tracking and profiling targets. For the counterintelligence operator or a surveillant, recognizing the capabilities of TPMS is crucial for assessing the security of one’s own movements and anticipating the methods adversaries may employ to monitor them. As vehicle systems become increasingly interconnected and digitized, the utility of standard automotive features for intelligence gathering will only continue to grow. We are going to need a much broader understanding of the “Internet of Vehicles” within the context of national and agency operational security.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Kobayashi, M. (2019). Understanding TPMS: A Guide to Tire Pressure Monitoring Systems. SAE International.
  • Vijayan, J. (2026, March 3). Vehicle Tire Pressure Sensors Enable Silent Tracking. Dark Reading. https://www.darkreading.com/ics-ot-security/tire-pressure-sensors-silent-tracking
  • Khan, H. (2020). Wireless Sensor Networks: Principles and Applications. CRC Press.
  • Alippi, C., & Camplani, R. (2019). Wireless Sensor Networks: Performance Analysis and Applications. Academic Press.
  • Stankovic, J. A. (2016). “Wireless Sensor Networks for Industrial Applications.” Proceedings of the IEEE, 104(5), 1013-1022.
  • IEEE. (2021). IEEE Standard for Low-Rate Wireless Networks for Industrial, Scientific, and Medical (ISM) Applications. IEEE 802.15.4-2021.
  • Brown, T. (2022). Cybersecurity for the Internet of Things: Protecting Critical Infrastructure. Wiley.
Share this post:

The Takaichi “Prompt Exploit” as Novel Tradecraft: A Counterintelligence Operator’s View of AI Enabled Influence Operations

disinformation, information operations, espionage, counterespionage, intelligence, counterintelligence, psyops, C. Constantin Poindexter, CIA, DIA, NSA

AI Enabled Smear Operations and Counterintelligence Detection: Lessons from the Attempted ChatGPT Exploit Targeting Sanae Takaichi

The attempted exploitation of ChatGPT to support a covert smear campaign against Japanese Prime Minister Sanae Takaichi is not a novelty story about AI gone wrong. It is a clear operational vignette of how modern state-linked actors or FIS attempt to compress the intelligence cycle and accelerate influence effects with generative tools. OpenAI’s February 25, 2026 threat reporting describes a now banned ChatGPT account linked to an individual associated with Chinese law enforcement who attempted in mid October 2025 to leverage the model to plan and execute a covert influence operation aimed at discrediting Takaichi, followed by later requests to edit “cyber special operations” status reports after the model refused the original operational ask (OpenAI, 2026). Public reporting based on that disclosure adds that the actor’s plan included coordinated negative commentary, impersonation techniques, and wedge framing designed to mobilize resentment around U.S. tariffs and immigration narratives (Jiji Press, 2026; Reuters, 2026; Axios, 2026). From a counterintelligence perspective, this is a case study in how an adversary treats a commercial large language model as a low-friction staff officer: ideation, drafting, message discipline, and iterative refinement, all without needing to recruit a human asset or expose internal tradecraft through overt tasking channels.

What makes the episode analytically valuable is the specificity of the improper tasking. Reporting indicates that the actor asked ChatGPT to draft a multi part plan to discredit Takaichi, to generate and help post and spread negative comments attacking her stances including immigration, to polish narratives and recurring status reports describing ongoing cyber special operations, and to inflame wedge grievances by amplifying anger over U.S. tariffs on Japan (Jiji Press, 2026; Axios, 2026; OpenAI, 2026). These requests form a recognizable information operations workflow: design the campaign, manufacture content, distribute content, or at least create distribution-ready material, and assess and iterate based on reporting. In classical counterintelligence terms, the operator sought to maximize plausible deniability, minimize cost, and raise tempo, substituting generative capacity for time-consuming human copywriting while reducing the number of personnel who must be read into the narrative engineering function (CISA, 2022; ODNI FMIC, 2024).

The most important counterintelligence observation is that the exploit is not primarily technical. It is procedural and behavioral. Operators do not need to jailbreak a model to gain advantage. They can ask for adjacent assistance such as language polishing, translation, formatting, summarization of internal memos, and audience-tailored variations. OpenAI’s reporting explicitly notes the actor returned after an initial refusal and asked for edits to operational status reports, which is precisely how professional services are laundered in many influence pipelines: when direct enablement is blocked, pivot to editorial support and documentation hygiene (OpenAI, 2026). This aligns with U.S. government’s framing of foreign malign influence as subversive, undeclared, coercive, or criminal activity that uses multiple pathways and intermediaries, often blending overt platforms with covert personas and synthetic content (ODNI FMIC, 2024; DOJ, n.d.). The model is not the operation. It becomes a friction reducer within the operation.

Seen through the lens of the intelligence cycle, the actor’s approach collapses collection, analysis, production, and dissemination into a tight loop. The multi-part plan request is campaign design, meaning objective, target audience, narrative lines, channels, and timing. The post-and-spread request is dissemination planning and, at minimum, the production of ready-to-publish material. The status report editing request is assessment: codifying observed effects, identifying what resonated, and deciding next moves (OpenAI, 2026; Axios, 2026). When an influence apparatus scales, this loop becomes industrialized: many accounts, multi-platform content seeding, and iterative narrative tuning. Reporting around the OpenAI threat case underscores that these efforts can be large-scale, resource-intensive, and sustained, consistent with a bureaucracy rather than hobbyist trolling (Reuters, 2026; CyberScoop, 2026). As Ben Nimmo has emphasized, the intent is to apply pressure everywhere, all at once, which is characteristic of FIS or state-linked coercive information operations rather than organic political discourse (Axios, 2026).

The operational targeting of Takaichi is also instructive for counterintelligence because it sits at the intersection of influence operations and transnational repression. While this case focuses on a smear campaign against a Japanese political figure, OpenAI’s broader description of the actor’s uploaded materials suggests a wider ecosystem aimed at suppressing dissent and silencing critics, including tactics such as forged documentation and intimidation narratives (OpenAI, 2026; CyberScoop, 2026). The FBI defines transnational repression to include online disinformation campaigns, harassment, intimidation, and abuse of legal processes, exactly the kinds of tools that can be amplified or routinized by AI-assisted content generation (FBI, n.d.). In counterintelligence risk terms, that convergence matters. When an adversary blends influence effects, shaping attitudes, with coercive effects, punishing or deterring speech, the target set expands from voters to voices, and the operational threshold for harm drops.

The wedge grievance element, stoking resentment over U.S. tariffs, illustrates classic influence tradecraft. Hijack a real grievance, inflate it, and attach it to the target as a blame object. This is not persuasion via factual argument. It is agitation via emotional mobilization. CISA guidance on foreign influence operations describes how adversaries exploit mis, dis, and malinformation narratives to bias policy and undermine social cohesion, often by inflaming divisive issues (CISA, 2022). The tariff frame is particularly useful because it can be pitched simultaneously as anti-U.S., blaming Washington, and anti-target, blaming Takaichi’s posture for provoking friction, with variants tailored to different audiences. In counterintelligence vocabulary, this is narrative multi-casting: the same kernel is repackaged into mutually reinforcing storylines for disparate communities.

The cross platform distribution pattern referenced in public reporting, activity on X and other sites, with relatively low engagement but persistent output, resembles the known Chinese influence pattern commonly labeled Spamouflage or Dragonbridge: high volume, mixed quality, low authentic engagement, but sustained presence and periodic tactical evolution (Reuters, 2026; NATO StratCom COE, 2023; Graphika, 2025). Low engagement does not mean low intent or low risk. It can indicate poor tradecraft, early-stage testing, or a campaign optimized for secondary effects such as search pollution, narrative seeding for later pickup, or creating “evidence” of public sentiment that can be cited elsewhere. Counterintelligence professionals should treat low engagement content as potential scaffolding. The objective may be to build a lattice of posts, screenshots, and proof artifacts that can later be laundered into higher credibility channels.

From the defender’s side, the case clarifies what model refusal can and cannot do. OpenAI reports that ChatGPT refused overtly malicious prompts, yet the actor appears to have proceeded using other tools and later used ChatGPT for editing (OpenAI, 2026). This reveals a strategic limitation. Safety filters reduce direct enablement. They do not eliminate the underlying operational capability of a state apparatus that can shift to domestic models, human copywriters, or alternative platforms. Effective mitigation requires a layered approach: model-side safeguards, platform-side enforcement, and inter-organizational intelligence sharing that treats AI as one component in a broader influence toolkit (OpenAI, 2026; CISA, 2024). The IC’s Foreign Malign Influence Center has emphasized that foreign malign influence is multi-actor and multi-pathway by design, which implies countermeasures must also be multi-pathway. Detection in one node rarely collapses the whole network (ODNI FMIC, 2024).

For counterintelligence operators, three takeaways are operationally salient. First, generative AI is best understood as an accelerant of existing influence doctrine rather than a replacement. It speeds up drafting, localization, and A B testing of narratives while enabling bureaucratic reporting to be produced faster and with greater stylistic consistency (OpenAI, 2026; CISA, 2022). Second, the human factor remains the decisive vulnerability. The actor’s interaction with ChatGPT created an evidentiary trail that allowed defenders to correlate intent, post-and-spread negative commentary with observed online activity. This is a reminder that operational security failures frequently occur in routine administrative behavior (OpenAI, 2026; CyberScoop, 2026). Third, influence and repression are increasingly convergent lines of effort. When disinformation is used not only to persuade but to intimidate, deplatform, or socially punish, the problem set expands to include civil liberties impacts, diaspora targeting, and sovereignty challenges (FBI, n.d.; DOJ, 2023).

In countermeasures terms, the Takaichi case underscores the value of structured analytic techniques in attribution and mitigation. Analysts should separate narrative content, behavioral signals such as posting cadence and account creation patterns, infrastructure signals such as hosting and coordinated link sharing, and procedural artifacts such as templated emails, repeated phrasing, and report formats. OpenAI’s account-level disruption, combined with open-source correlation to online hashtags and posts referenced in operational materials, is a template for fusion analysis that pairs platform telemetry with OSINT validation (OpenAI, 2026). NATO-aligned research similarly emphasizes that state-sponsored or FIS information operations exploit differences across platforms and jurisdictions. Defenders should expect rapid lateral movement when friction increases on any single platform (NATO StratCom COE, 2023).

The attempted exploit is best characterized as an “AI-enabled influence operation reconnaissance and production cycle, with the model treated as a drafting cell embedded in a broader state-linked apparatus”. The key question is not whether a model can be tasked with dissemination directly. It is whether it can generate dissemination-ready content, standardize narrative discipline, and reduce the time and training required to run a coordinated smear campaign. In this case, it could at least partially, until refusal controls forced the actor to route around and repurpose the model for editing and reporting (OpenAI, 2026; Jiji Press, 2026). For counterintelligence professionals, that reality demands a posture shift.. We must defend not only against disinformation artifacts but against the process improvements that AI grants adversaries. Faster cycles, lower labor costs, and more plausible linguistic camouflage are the new norm. The Takaichi operation appears to have underperformed in engagement, yet it is a forward indicator of how state-backed influence operational tradecraft is adapting to generative systems. They are persistent, multi-platform and procedurally agile (Reuters, 2026; Graphika, 2025).

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Axios. (2026, February 25). Reporting on OpenAI’s disclosure of a China linked attempt to use ChatGPT to plan and refine a smear campaign targeting Japan’s Prime Minister Sanae Takaichi.
  • Cybersecurity and Infrastructure Security Agency. (2022). Preparing for and mitigating foreign influence operations (CISA Insight).
  • Cybersecurity and Infrastructure Security Agency. (2024, April 17). Guidance for securing election infrastructure against tactics of foreign malign influence (Joint guidance release with FBI and ODNI).
  • CyberScoop. (2026, February 25). Reporting on OpenAI’s threat report and Chinese law enforcement linked “cyber special operations” materials uploaded for editing.
  • Federal Bureau of Investigation. (n.d.). Transnational repression (Overview page describing tactics including online disinformation campaigns, harassment, and intimidation).
  • Graphika. (2025). Chinese state influence (Selected insights from Graphika ATLAS reporting, November 2024 to January 2025).
  • Jiji Press. (2026, February 27). Reporting summarized by Nippon.com on OpenAI’s claim that a Chinese law enforcement official asked ChatGPT to draft a plan to discredit Takaichi and to post and spread negative comments.
  • NATO Strategic Communications Centre of Excellence. (2023). Dragons roar and bears howl: Convergence in Sino Russian information operations in NATO countries.
  • OpenAI. (2026, February 25). Disrupting malicious uses of AI (Threat report describing disruption of accounts, including an influence operation attempt targeting Sanae Takaichi).
  • Reuters. (2026, February 25). Reporting on OpenAI’s threat report detailing misuse of ChatGPT for scams and influence operations, including a smear campaign targeting Japan’s prime minister.
  • Reuters. (2026, February 26). Reporting on a Foundation for Defense of Democracies analysis of China linked influence operations targeting Japan’s elections and Prime Minister Sanae Takaichi, consistent with Spamouflage and Dragonbridge patterns.
  • U.S. Department of Justice. (2023, April 17; updated 2025, February 6). Press release describing charges tied to transnational repression schemes and the use of fake online personas to harass dissidents and disseminate state narratives.
  • U.S. Office of the Director of National Intelligence, Foreign Malign Influence Center. (2024). FMI Primer (Public release defining foreign malign influence and its pathways).
Share this post:

A U.S. Attack on Iran, a Catastrophic Unforced Error

war, warfighter, Iran, U.S., intelligence, counterintelligence, espionage, counterespionage, C. Constantin Poindexter, CIA, NSA

Public and Congressional Support: The Decisive Constraint That Can Turn U.S. Military Dominance Over Iran Into Strategic Defeat

The United States retains overwhelming advantages in the material and operational prerequisites of high-end conventional warfare. In any prospective conflict with Iran, Washington can assume advantages in air and naval superiority, intelligence and surveillance coverage, precision strike capacity, suppression of enemy air defenses, long-distance logistics, and advanced cyber and electronic warfare. Yet those advantages do not automatically translate into strategic success. The decisive variable is not whether the United States can destroy targets faster than an adversary can replace them, but whether the United States can sustain the political mandate to keep fighting after the initial shock of combat wears off, the costs become visible, and the enemy adapts.

This is the core vulnerability of a discretionary war with Iran. Public support and congressional support are not merely background noise or messaging challenges. They are strategic enablers. When they are absent or brittle, they shape rules of engagement, constrain time horizons, narrow acceptable costs, and fracture coalition cohesion. In that environment, even tactically brilliant operations can fail to achieve the most important objectives because political will collapses sooner than the enemy’s capacity to resist. Vo Nguyen Giap articulated this logic explicitly. A belligerent can leave enemy forces partly intact if it can destroy the enemy’s will to remain in the war. (PBS, n.d.) That insight was operationalized against the United States in Vietnam, echoed in Afghanistan, and remains relevant to any prospective United States-Iran war.

The Strategic Center of Gravity: Legitimacy and Endurance

Clausewitz argued that war is a continuation of politics by other means. In American practice, the political character of war is inseparable from constitutional structure and democratic consent. A war that begins without clear congressional authorization, or that proceeds amid broad public skepticism, can win battles while steadily losing its domestic foundation. The War Powers Resolution codifies Congress’s position that the President introduces U.S. forces into hostilities only pursuant to a declaration of war, specific statutory authorization, or a national emergency created by an attack on the United States or its forces. (50 U.S.C. § 1541, 1973) In a discretionary strike campaign that grows into sustained hostilities, the gap between executive action and legislative consent becomes a recurring legitimacy crisis rather than a one-time procedural dispute.

Recent reporting underscores that this institutional fault line is not theoretical. Reuters reported that the U.S. Senate rejected a bid to curb presidential Iran war powers, reflecting a live and lively, contested debate over authority and oversight in potential Iran hostilities. (Reuters, 2025) That debate matters operationally because contested legitimacy does not remain in Washington. It affects allied basing decisions, overflight permissions, intelligence sharing, escalation thresholds, and the credibility of U.S. signals to both adversaries and partners. A campaign that looks unilateral, politically improvised, or domestically unpopular becomes harder to sustain and easier for Iran and its proxy network to frame as illegitimate aggression.

Material Superiority Versus Political Fragility

From my perspective (military/intelligence), the United States can plausibly execute many of the classic prerequisites you listed. But those capabilities do not eliminate the central political question: what is the concrete objective, and how long will the American public accept the costs required to achieve it?

Public sentiment data indicates a serious constraint. A University of Maryland Critical Issues Poll found only 21 percent favor the United States initiating an attack on Iran, with 49 percent opposed and 30 percent unsure. (University of Maryland Critical Issues Poll, 2026) A YouGov report covering an Economist YouGov poll likewise found Americans more likely to oppose than to support using military force to attack Iran, with 49 percent opposing and 27 percent supporting, and with significant partisan and independent resistance. (YouGov, 2026) Meanwhile, an AP NORC poll found that while many Americans view Iran as an enemy and express concern about Iran’s nuclear program, they have low trust in presidential judgment on the use of military force, with only about three in ten expressing high trust and more than half expressing little or no trust. (Associated Press NORC, 2026)

The former being said, all of this has strategic implications. They suggest that domestic consent is not merely divided. It is structurally thin, with a large, uncertain middle and a relatively small affirmative mandate for initiating war. Low confidence in the decision maker’s judgment means that early setbacks or civilian casualties can rapidly convert uncertainty into opposition. Further, thin consent invites legislative confrontation, and legislative confrontation invites operational constraints. This is exactly the kind of environment in which an adversary designs a strategy of political attrition rather than symmetrical military competition.

Vietnam: Giap’s Theory of Victory Was Political

The claim that “North Vietnam did not win the Vietnam War” can be true in a narrow kinetic sense. The United States inflicted vast battlefield losses and dominated many tactical engagements. Yet North Vietnam and the Viet Cong were able to outlast the United States by targeting the political will that sustained American participation. Giap described the objective as breaking “the American will to remain in the war,” using operations intended to force de-escalation and reshape the political calculus in Washington. (PBS, n.d.) The point is not that one event alone decided the outcome. The point is that the adversary’s theory of victory treated American domestic endurance as the center of gravity. Once that center weakened, America’s material advantages could not convert into a stable political settlement on acceptable terms.

For an Iran scenario, the parallel is not an exact replay of Vietnam’s terrain or insurgency structure. The parallel is “strategic method”. Iran does not need to win a conventional air-sea contest. It needs to ensure that the United States does not achieve its most important objectives at a politically acceptable cost. If Iran can force Washington into a cycle of escalation and retaliation, or can trigger regional proxy pressure that steadily raises the price of engagement, then the war becomes a contest of domestic patience more than a contest of platforms.

Afghanistan and the Logic of “Time”

The Afghanistan experience reinforces the same strategic logic through a different mode of war. A saying widely attributed to Taliban fighters captures the asymmetry of time horizons: “You have the watches, we have the time.” (Maclean’s, 2017) The exact provenance of the phrase is less important than its strategic meaning. The U.S. Administration is about fall into the same bullshit trap. Democracies fight under time constraints produced by elections, news cycles, budget politics, and public casualty sensitivity. Insurgent and revolutionary actors often fight under generational horizons, with lower sensitivity to near term losses and a stronger tolerance for prolonged hardship.

Iran’s leadership and its proxy network have repeatedly demonstrated a long-horizon approach to regional strategy. In a conflict, Iran can employ calibrated escalation through proxies, maritime harassment, missile and drone pressure, and political warfare aimed at eroding coalition cohesion (a “coalition” of states that have already publicly objected to U.S. warplanning). The objective is not necessarily to defeat U.S. forces in the field. It is to make the conflict feel indefinite, morally ambiguous, and strategically distracting, which are precisely the conditions that drain public support in the United States.

“Shock and Awe” Does Not Solve the Political Problem

Advocates of rapid strike campaigns often argue that overwhelming early force can preempt political attrition by ending the conflict quickly. History offers caution. Initial public support (pretty clearly NOT the case today) can be high at the onset of a war, but it can erode sharply as the war’s duration and costs expand, particularly if the rationale becomes contested. The Iraq example is instructive: Gallup reported 72 percent support for the war against Iraq in late March 2003. (Gallup, 2003) Yet Gallup later documented substantial erosion in perceived worth and support over time as realities on the ground diverged from initial expectations. (Gallup, 2006) The Brookings analysis of early Iraq war opinion similarly underscores the rally effect and its limits. (Kull, Ramsay, and Lewis, 2003)

For Iran, the political risk is heightened because current polling suggests the United States would begin without anything like the 2003 level of public backing. (University of Maryland Critical Issues Poll, 2026) (YouGov, 2026) (Associated Press NORC, 2026) Without a broad initial mandate, the usual pattern reverses: instead of rallying, creating a cushion against early shocks, early shocks can collapse a narrow coalition of support. Moreover, Iran is structurally capable of generating early shocks through proxy responses and regional disruption, meaning that the political challenge may begin immediately, not after months or years.

Congress as a Strategic Actor, Not a Background Variable

In a system where Congress controls funding and has constitutional war powers, the legislative branch becomes a de facto strategic actor. When Congress is divided, when authorization is ambiguous, or when the public is skeptical, Congress can constrain the war through funding restrictions, reporting requirements, and political signaling that affects allied behavior. Reuters reporting on war powers debates around Iran illustrates that these conflicts are not hypothetical. (Reuters, 2025) Even the sycophants are likely to run out of patience for another endless foray, largely due to constituent pressure rather than disloyalty to their cult.

This really matters. Strategic clarity requires durable political consensus. If objectives are unclear or expand, congressional opposition becomes more likely and more intense. Further, Iran can exploit visible domestic division through information operations, propaganda, and calibrated escalation intended to polarize U.S. politics. In that sense, a weak domestic mandate is not merely a constraint on U.S. freedom of action. It becomes a targetable vulnerability. The North Vietnamese knew it. The Afghans knew it, and the more sober members of the Department of Defense know it.

A Missing Ingredient: Defined, Credible Political Objectives

Even if the United States can strike nuclear facilities, degrade air defenses, and disrupt command networks, the strategic question remains what “winning” means and what settlement conditions are realistically attainable. If the objective is limited, such as delaying nuclear capabilities, the question becomes whether limited objectives justify the costs and risks of regional escalation. If the objective expands to regime change, the problem becomes far harder because military destruction does not automatically produce political legitimacy, stable governance, or a non-hostile successor regime. Here, the user’s final criterion is decisive. Post-conflict planning, a wicked difficult peril that we have botched over and over again, will repeat itself. History shows that military victory without a stabilization strategy yields strategic failure, and the public tends to punish wars that feel open-ended, morally muddled, or poorly planned.

In the Iran case, this risk is amplified because a strike campaign can trigger proxy retaliation in multiple theaters, raise energy and shipping risks, and produce unpredictable political reverberations, all of which can be framed domestically as an optional war of choice rather than a necessary act of self-defense. When a war’s necessity is contested, public support becomes the decisive front.

Dominance in Combat Power Does Not Guarantee Strategic Success

The United States may indeed be dominant across many of the operational categories that matter for battlefield performance. Yet wars are not won solely by platform superiority. They are won by aligning military means with politically sustainable ends. Current public opinion suggests a narrow and fragile mandate for initiating an attack on Iran, combined with low confidence in executive judgment about the use of force. (University of Maryland Critical Issues Poll, 2026) (YouGov, 2026) (Associated Press NORC, 2026) In that environment, congressional contention over authorization and war powers becomes a predictable friction point, not an occasional procedural dispute. (50 U.S.C. § 1541, 1973) (Reuters, 2025) Iran and its proxy network do not need to defeat the United States conventionally to succeed strategically. They need to prolong, complicate, and regionalize the conflict until the United States loses the will and domestic legitimacy to continue, echoing Giap’s theory of victory in Vietnam and the time horizon logic captured by the Afghanistan aphorism. (PBS, n.d.) (Maclean’s, 2017)

A United States attack on Iran will NOT end well. We’ll have tactical dominance paired with a complete strategic disaster. Without sustained public and congressional support, the United States will fail to achieve its most important objectives (if the Administration can even articulate them) at an acceptable cost. The venture will not end with a clear victory, but with political exhaustion and a forced search for exit ramps. That is not my political critique. It is a strategic assessment rooted in how democratic states actually choose war and wage war. My call? Don’t f. do it. Exaggerations about “days from completing a nuclear weapon” coupled with no clear objective or endgame is a movie that we’ve seen before.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Associated Press NORC Center for Public Affairs Research. 2026. “Most Americans see Iran as enemy but doubt Trump on military force: poll.” Associated Press.
  • 50 U.S.C. § 1541. 1973. War Powers Resolution, “Purpose and policy.” Legal Information Institute, Cornell Law School.
  • Gallup. 2003. “Seventy Two Percent of Americans Support War Against Iraq.” Gallup News Service, March 24, 2003.
  • Gallup. 2006. “Three Years of War Have Eroded Public Support.” Gallup News Service, March 17, 2006.
  • Kull, Steven, Clay Ramsay, and Evan Lewis. 2003. “Rally Round the Flag: Opinion in the United States before and after the Iraq War.” Brookings Institution.
  • Maclean’s. 2017. “Fighting in Afghanistan: ‘You have the watches. We have the time’.” September 2, 2017.
  • PBS. n.d. “Peoples Century: Guerrilla Wars: Vo Nguyen Giap Transcript.” Public Broadcasting Service.
  • Reuters. 2025. “US Senate rejects bid to curb Trump’s Iran war powers.” June 27, 2025.
  • University of Maryland Critical Issues Poll. 2026. “Do Americans Favor Attacking Iran Under the Current Circumstances? The Latest Critical Issues Poll Findings.”
  • YouGov. 2026. “Few Americans support U.S. military action against Iran, but a majority think it’s likely.” Economist YouGov poll, February 20 to 23, 2026.
Share this post:

AI as a Force Multiplier in Recent Intrusion Operations

AI, artificial intelligence, intelligence, counterintelligence, espionage, counterespionage, hacker, cyber, cyber security, C. Constantin Poindexter

AI as a Force Multiplier in Cyber Intrusions: Counterintelligence Lessons from the Amazon Threat Intelligence FortiGate Campaign, AI-Assisted Attack Planning, and Scalable Post-Exploitation Tradecraft

From a counterintelligence professional’s perspective, I read Amazon Threat Intelligence’s February 2026 report less as a novelty story about “hackers using AI” and more as a warning about a structural change in operational economics. The important point is not that a threat actor used a large language model. It is that a presumably low-to-medium skill, financially motivated Russian-speaking actor was able to scale intrusion activity across more than 600 FortiGate devices in over 55 countries in roughly five weeks by integrating commercial AI services into every phase of the attack workflow (Moses, 2026). In counterintelligence terms, this is a capability amplification event. AI did not make the actor sophisticated. It made the actor productive (Moses, 2026).

That distinction matters. Amazon’s analysis is unusually valuable because it documents both sides of the phenomenon. On one hand, the actor used AI to generate attack plans, write tooling, sequence actions, and coordinate operations at a tempo that would traditionally imply a larger team. On the other hand, the same actor repeatedly failed when facing hardened environments, patched systems, or nonstandard conditions. Amazon explicitly notes that the actor could not reliably compile custom exploits, debug failures, or creatively pivot beyond straightforward automated paths (Moses, 2026). This is exactly what a counterintelligence officer should expect from a force multiplier: improved throughput without equivalent gains in judgment, tradecraft, or adaptability.

The Amazon case is especially useful because it separates hype from mechanism. The campaign did not depend on exotic zero-days. Amazon states that no FortiGate vulnerability exploitation was observed in the campaign it analyzed; instead, the actor exploited exposed management interfaces, weak credentials, and single-factor authentication, then used AI to execute these known methods at scale (Moses, 2026). That is a profound lesson for defenders. AI is not changing the laws of intrusion. It is compressing the time and labor required to exploit organizations that still fail at fundamentals.

From a counterintelligence perspective, this changes how we should think about indications and warnings. Historically, broad multi-country infrastructure access, custom scripts in multiple languages, and organized post-exploitation playbooks would often suggest a resourced team such as an FIS, state-supported private operator, or at least a mature criminal crew. Amazon’s report shows that this inference is no longer reliable. The actor’s infrastructure contained numerous scripts and dashboards with hallmarks of AI generation, and Amazon concluded that a single actor or very small group likely produced a toolkit whose volume would previously imply a development team (Moses, 2026). In intelligence analysis, this is a warning against legacy heuristics. Scale is no longer a clean proxy for organizational size or skill.

Amazon’s “AI as a force multiplier” section is the core of the matter. The actor used at least two distinct commercial LLM providers in complementary ways. One served as the primary tool developer and operational assistant, while another was used as a supplementary planner when the actor needed help pivoting inside a compromised network (Moses, 2026). In one observed instance, the actor reportedly submitted a victim’s internal topology, hostnames, credentials, and identified services to obtain a step-by-step compromise plan (Moses, 2026). For counterintelligence professionals, this is not just a cyber issue. It is a tradecraft issue. The actor is externalizing planning and decision-support functions to commercial platforms, effectively outsourcing parts of the “staff work” that junior operators or analysts would otherwise perform.

This pattern aligns with broader reporting from major providers and threat intelligence teams. Google Threat Intelligence Group’s February 2026 AI Threat Tracker documents growing adversary integration of AI across reconnaissance, phishing enablement, malware/tooling development, and post-compromise support, while also emphasizing that it has not yet observed “breakthrough capabilities” that fundamentally change the threat landscape (Google Threat Intelligence Group, 2026). That is highly consistent with the Amazon case: AI is improving speed, coverage, and consistency more than it is producing genuine operational innovation (Google Threat Intelligence Group, 2026; Moses, 2026). Microsoft’s Digital Defense Report 2025 similarly describes adversaries using generative AI for scaling social engineering, reconnaissance, code generation, exploit development support, and automation of exfiltration-to-lateral movement pipelines (Microsoft, 2025). The convergence across independent sources is notable. Different organizations are observing the same pattern from different vantage points.

Anthropic’s 2025 report on “vibe hacking” extends this trend in a particularly important direction. Anthropic described a disrupted criminal operation in which an actor used an AI coding agent not only as a technical consultant but as an active operator embedded into the attack lifecycle, supporting reconnaissance, credential harvesting, penetration, and extortion-related tasks (Anthropic, 2025). Whether one agrees with every framing choice in vendor reports, the operational implication is clear: AI-enabled actors are increasingly turning language models and coding agents into workflow engines. They are not merely asking for snippets of code. They are building repeatable campaign infrastructure around AI-assisted execution (Anthropic, 2025; Moses, 2026).

For counterintelligence practitioners, the strategic concern is not limited to criminal ransomware precursors. The same force-multiplier logic applies to espionage, access development, insider targeting, and influence preparation. Google’s reporting notes that government-backed actors are using AI for technical research, target development, and rapid phishing lure generation, including reconnaissance activities that support subsequent operations (Google Threat Intelligence Group, 2026). The FBI has also publicly warned that AI increases the speed, scale, and realism of phishing and social engineering, including voice and video cloning (FBI San Francisco, 2024). In the CI domain, this means hostile services and proxies can expand target coverage, improve linguistic quality, and accelerate social graph exploitation with lower manpower. AI narrows the gap between intent and execution.

There is also an analytical security issue that deserves more attention: data exposure to AI platforms during live operations. Amazon’s report indicates that the actor submitted internal victim topology, credentials, and service data into a commercial AI workflow (Moses, 2026). From a counterintelligence standpoint, this is a double-edged phenomenon. It may increase adversary effectiveness, but it also creates potential collection and disruption opportunities, depending on provider visibility, legal authorities, and industry cooperation. More importantly, it means that operationally sensitive network intelligence is now moving through third-party AI services as part of adversary tradecraft. That should influence how we think about public-private partnerships, lawful reporting channels, and rapid deconfliction.

The Fortinet context reinforces a second CI principle, i.e, adversary success often begins with governance failure, not advanced tradecraft. Fortinet’s January 2026 PSIRT analysis documented abuse of FortiCloud SSO and repeatedly emphasized best practices such as restricting administrative access, disabling vulnerable SSO paths, and monitoring for malicious admin creation and anomalous logins (Windsor, 2026). NIST’s National Vulnerability Database entry for CVE-2026-24858 further confirms the seriousness of the authentication bypass exposure affecting multiple Fortinet product lines when FortiCloud SSO was enabled (NIST NVD, 2026). Even if the Amazon campaign did not depend on that specific exploit path, the environment is the same: internet-exposed edge infrastructure, identity weaknesses, and uneven patching create permissive terrain that AI-enabled actors can mine at scale (Moses, 2026; Windsor, 2026; NIST NVD, 2026).

The practical implication is that counterintelligence and cybersecurity must converge more tightly on defensive prioritization. In many organizations, CI is still treated as a narrow insider-threat or foreign-intelligence problem, while cyber defense handles perimeter hygiene and incident response. That separation is increasingly artificial. AI-augmented threat actors blur the boundaries between criminal and state-adjacent tradecraft, between opportunistic access and strategic exploitation, and between cyber intrusion and intelligence preparation of the environment. Europol’s 2025 organized crime threat assessment reporting, as reflected in major coverage, likewise points to AI lowering costs and increasing the scale and sophistication of criminal operations, including cyber-enabled activity and proxy behavior that can intersect with geopolitical interests (Reuters, 2025). The ecosystem is converging.

In my view, the correct response is not panic over “autonomous AI hackers.” Amazon’s report itself argues against that caricature. The actor remained brittle, shallow, and dependent on weak targets (Moses, 2026). The right response is disciplined adaptation in three areas.

Organizations must treat identity and edge administration as counterintelligence terrain, not merely IT hygiene. Exposed management interfaces, weak credentials, and single-factor authentication are now high-confidence enablers of AI-scaled intrusion campaigns (Moses, 2026). MFA, restricted administration paths, credential rotation, and segmentation are not basic controls anymore; they are anti-scaling controls.

Defenders need telemetry designed for workflow detection rather than malware signatures. Amazon explicitly notes the campaign’s use of legitimate open-source tools and recommends behavioral detection over IOC dependence (Moses, 2026). That aligns with the broader AI-enabled threat model. When AI helps actors orchestrate legitimate tools more efficiently, the artifact footprint looks cleaner while the behavioral pattern becomes more machine-like and more repeatable.

Intelligence organizations and enterprises should expand analytic models for adversary assessment. When a low-skill actor can produce high-volume tooling and broad campaign coverage, we must stop equating output polish with strategic sophistication. The key discriminators will be resilience under friction, adaptation under failure, target discipline, and operational security. In the Amazon case, the actor’s poor OPSEC and inability to improvise revealed the underlying limitations despite impressive scale (Moses, 2026). Those are precisely the indicators that counterintelligence tradecraft has always prioritized.

My take, the AI force multiplier threat is real, but its significance is often misunderstood. It really resembles a “brute force” attack reminiscent of the first generation hackers but on steroids. AI is the “steroid”. So, the immediate danger is not superintelligence. It is operational leverage. AI gives mediocre actors the ability to behave like nation-state FIS against poorly defended targets. It accelerates reconnaissance, scripting, planning, and social engineering. It reduces labor costs and time-to-action. It increases campaign breadth. And it does all of this without solving the deeper human problems of judgment, creativity, and tradecraft. For counterintelligence professionals, that means the threat landscape is becoming more crowded, faster-moving, and harder to triage. The strategic answer remains the same as ever: protect critical access, harden identity, improve detection, and refine analytic tradecraft. What has changed is the speed at which failure to do so will be exploited (Moses, 2026; Google Threat Intelligence Group, 2026; Microsoft, 2025; Anthropic, 2025; FBI San Francisco, 2024).

~ C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Anthropic. (2025, August). Vibe hacking: How cybercriminals are using AI coding agents to scale data extortion operations. Anthropic.
  • Bleiberg, J. (2026, February 25). Hackers used AI to breach 600 firewalls in weeks, Amazon says. Insurance Journal.
  • FBI San Francisco. (2024, May 8). FBI warns of increasing threat of cyber criminals utilizing artificial intelligence. Federal Bureau of Investigation.
  • Google Threat Intelligence Group. (2026, February 12). GTIG AI Threat Tracker: Distillation, experimentation, and (continued) integration of AI for adversarial use. Google Cloud Blog.
  • Microsoft. (2025). Microsoft Digital Defense Report 2025: Safeguarding trust in the AI era. Microsoft.
  • Moses, C. (2026, February 20). AI-augmented threat actor accesses FortiGate devices at scale. AWS Security Blog.
  • National Institute of Standards and Technology, National Vulnerability Database. (2026). CVE-2026-24858 detail. NVD.
  • Reuters. (2025, March 18). Europol warns of AI-driven crime threats. Reuters.
  • Windsor, C. (2026, January 22). Analysis of Single Sign-On Abuse on FortiOS. Fortinet PSIRT Blog.
Share this post:

Operation Absolute Resolve, Claude and the Weaponization of A.I.

intelligence, counterintelligence, national defence, war, weaponization, artificial intelligence, Anthropic, Claude, C. Constantin Poindexter

“Anthropic appears to be the “canary in the coal mine.” They are the first in public view to be used in a classified operation, and they are the first to be pushed back against.”

The convergence of artificial intelligence and military strategy has now been a subject of theoretical speculation for quite some time. The operational reality of this convergence is now being written in real-time. The January 2026 mission to capture former Venezuelan President Nicolás Maduro, codenamed “Operation Absolute Resolve,” stands as the first definitive deployment of Anthropic’s AI model, Claude, within a classified U.S. military operation (Reuters, 2026). This event marks a pivotal moment in the defense sector, moving AI from the realm of administrative support to the front lines of kinetic warfare. By examining the mechanics of Claude’s integration through Palantir, the friction between Anthropic’s safety-first philosophy and the Pentagon’s lethality requirements, and the broader geopolitical implications for AI development, I argue that this operation represents not merely a tactical success but also clearly the “no going back now” weaponization of Large Language Models (LLMs) in modern conflict.

The deployment of Claude in Operation Absolute Resolve was facilitated through a complex network of public and private partnerships. The operation itself was a conventional military endeavor, involving aerial bombardment of multiple sites in Caracas and the deployment of special forces to secure the capture of Maduro and his wife (Reuters, 2026). However, the intelligence and targeting data that informed these decisions were processed and synthesized by Claude, an LLM designed initially for civilian applications. This integration was achieved via Anthropic’s partnership with Palantir Technologies, a data analytics company whose software is a staple in the Defense Department’s infrastructure (The Wall Street Journal, 2026). Palantir’s role was critical, acting as the bridge between the proprietary security environments of the military and the open-source capabilities of commercial AI. This infrastructure allowed for the ingestion of classified intelligence, the rapid analysis of vast datasets, and the generation of actionable strategic recommendations. Claude effectively functioned as a force multiplier for human command.

The significance of Claude’s role in this operation cannot be overstated. It represents a shift in the utility of AI within the military. While earlier iterations of AI in the Pentagon were often relegated to “unclassified” tasks such as summarizing documents or generating routine reports, the use of Claude in a classified, kinetic mission indicates a maturation of the technology (The Wall Street Journal, 2026). The sources suggest that the model was capable of processing the nuanced geopolitical and tactical data required to support a complex operation of this magnitude. This capability suggests that the Pentagon is beginning to utilize LLMs not just as assistants, but as analytical engines capable of processing the “fog of war” (Kania, 2023). The operational success of the mission implicitly validates the Pentagon’s investment in frontier AI, suggesting that the technology is now ready for high-stakes decision-making environments where the margin for error is measured in lives and geopolitical stability.

Despite the operational success, the deployment of Claude exposes a fundamental philosophical conflict within the AI industry and between the AI industry and the U.S. government. Anthropic was founded with a specific mission: to build AI that is “helpful, honest, and harmless” (Anthropic, 2024). This philosophy is codified in their usage guidelines, which explicitly prohibit the use of Claude to “facilitate violence, develop weapons or conduct surveillance” (The Wall Street Journal, 2026). The irony of using a model designed for safety to plan and execute a military operation that involved bombing and the capture of a head of state is stark. This contradiction highlights the tension between the “safety-first” approach championed by Anthropic and the “kill chain” mentality required by the Pentagon. For a company that has built its brand on rigorous safety testing and the prevention of AI harm, being used in a military operation appears to be a double-edged sword. It proves the utility of their model, yet it forces them to participate in the very violence they have spent years trying to mitigate.

This conflict has escalated into a broader strategic battle between Anthropic and the Trump administration. The administration has pursued a low-regulation AI strategy, aiming to rapidly deploy technology to maintain global competitive advantage. In contrast, Anthropic has been vocal about the risks of AI in autonomous lethal operations and domestic surveillance, pushing for greater regulation and guardrails (The Wall Street Journal, 2026). The friction came to a head in January 2026, when Defense Secretary Pete Hegseth stated that the Department of Defense would not “employ AI models that won’t allow you to fight wars” (The Wall Street Journal, 2026). This comment was widely interpreted as a direct rebuke of Anthropic, signaling a preference for models that prioritize speed and lethality over safety. The Pentagon’s Chief Spokesman, Sean Parnell, echoed this sentiment, emphasizing that the nation requires partners willing to help warfighters “win in any fight” (The Wall Street Journal, 2026). For the Trump administration, Anthropic’s insistence on safety protocols was viewed as an impediment to the efficient execution of military strategy.

The potential fallout from this ideological clash is significant, particularly regarding the $200 million contract awarded to Anthropic last summer. Sources indicate that the administration is considering canceling or restructuring this contract due to Anthropic’s reluctance to cede control over AI deployment to the military (The Wall Street Journal, 2026). The contract was awarded as a pilot program to test the integration of frontier AI into the Defense Department, but the resulting friction suggests that the Pentagon is wary of models that might impose constraints on their operational flexibility. This situation places Anthropic in a precarious position. If they adhere strictly to their safety guidelines, they risk losing their most valuable government contracts to competitors who are more willing to accommodate military needs. If they compromise their values to secure the deal, they risk alienating their core customer base and undermining their brand identity as the “safe” alternative to OpenAI and Google (Kaplan, 2024).

The weaponization of AI in Operation Absolute Resolve also highlights the growing competitive landscape among AI developers. While Anthropic was ostensibly the first to be used in classified operations, competitors like OpenAI and Google have already established a foothold in the military sector. Google’s Gemini and OpenAI’s ChatGPT are already deployed on platforms used by millions of military personnel for analysis and research (The Wall Street Journal, 2026). The deployment of Claude in the Maduro mission positions Anthropic as a contender in this emerging arms race, but it also underscores the speed at which the military is adopting these technologies. The fact that other tools may have been used for unclassified tasks alongside Claude suggests that the military is conducting a wide-scale evaluation of available AI capabilities (The Wall Street Journal, 2026). For Anthropic, the pressure is on to demonstrate that their model offers unique advantages that justify their safety constraints in a combat environment.

The operation sheds light on the broader trend of AI integration into the “kill chain.” The military is increasingly interested in using AI for everything from controlling autonomous drones to optimizing supply chains and predicting enemy movements. The use of Claude in a high-profile operation like the capture of Maduro serves as a proof-of-concept for these more advanced applications. It demonstrates that LLMs can handle the complex, multi-variable problems inherent in modern warfare. However, it also raises difficult questions about accountability. If Claude were to make a mistake in targeting that resulted in civilian casualties or mission failure, who would be held responsible? The military or the AI company? This question is central to the debate over the weaponization of AI and highlights the need for clear protocols and liability frameworks as these systems become more integrated into military operations (Scharre, 2018).

The operational details of the Maduro mission also suggest a new level of integration between data analytics and kinetic action. The bombing of several sites in Caracas indicates a coordinated effort to eliminate potential escape routes and secure the perimeter (Reuters, 2026). The use of AI in this phase of the operation implies that the targeting data was processed rapidly and accurately, allowing for a synchronized military response. This level of coordination would have been difficult to achieve without advanced data analytics and AI-driven decision support systems. So, the success of this mission can be partially attributed to the technological edge provided by Claude and Palantir ecosystem. This success will likely encourage further integration and deployment of AI in warfighting, creating a feedback loop where operational victories drive further technological adoption (Belfiore, 2022).

The geopolitical implications of this extend beyond the immediate success of the Maduro snatch. As other nations observe the U.S. military’s effective use of AI in a real-world conflict, they are likely to accelerate their own AI development programs. The “Absolute Resolve” mission serves as a demonstration of power, not just in terms of military force, but in terms of technological superiority. This will most assuredly trigger an arms race in AI. Nations and non-state actors will compete not just on the size of their armed forces, but on the sophistication of their AI models. For the United States, maintaining this technological edge is a strategic imperative. Successful deployment of Claude is a step in that direction but it is also a shrill alarm of the risks of an AI arms race. The potential for miscalculation, warfighting error and the erosion of ethical norms in warfare is high (Yuan et al., 2023).

Operation Absolute Resolve represents a transformative moment in the history of both warfare and artificial intelligence. The deployment of Claude in the capture of Nicolás Maduro demonstrates the growing capability of LLMs to support complex military operations. It also highlights the tension between safety-focused AI development and the demands of national security. While the mission was a tactical success, it has exposed the friction between Anthropic’s philosophical commitment to “no use in violence” and the Department of Defense’s need for lethality. As the Pentagon reviews its contracts and the competitive landscape of AI continues to evolve, the lessons learned from “Absolute Resolve” will in no small part shape the future of AI in the military. The weaponization of AI is no longer theoretical. It is real, and it is redefining the nature of conflict. The question that remains is whether the military will continue to prioritize speed and capability over safety and ethical considerations, or whether it will find a way to integrate the two to create a new paradigm of intelligent warfare.

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Anthropic. “Anthropic’s Mission and Approach to AI Safety.” Anthropic Blog. Accessed February 17, 2026. https://www.anthropic.com/index/anthropics-mission-and-approach-to-ai-safety.
  • Belfiore, E. (2022). Technological Warfare: The Future of AI in Military Conflict. Oxford University Press.
  • Kania, J. (2023). “The Fog of War and the Rise of Algorithmic Command.” Journal of Military Strategy, 15(3), 45-62.
  • Kaplan, A. (2024). “The Safety Paradox: How AI Companies Balance Ethics and Growth.” MIT Technology Review, 127(1), 22-31.
  • Reuters. “U.S. military used Anthropic’s Claude AI in operation to capture Maduro.” Reuters. February 5, 2026.
  • Scharre, P. (2018). Army of None: Autonomous Weapons and the Future of War. W. W. Norton & Company.
  • The Wall Street Journal. “Pentagon’s Use of Claude in Maduro Capture Raises Questions About AI Safety.” The Wall Street Journal. February 3, 2026.
  • Yuan, K., et al. (2023). “Geopolitical Competition in Artificial Intelligence: A Framework for Analysis.” International Security, 47(4), 1-32.
Share this post: