A major aspect of the national security story of the past year comes down to one gap. Our adversaries, and increasingly the machines they use, now operate at machine speed. The institutions we count on for defense, oversight, and trust still operate at human speed, and several are being reorganized even as the threats accelerate. When the community gathers at Sea Island for The Cipher Brief’s annual threat conference in October, many conversations will trace back to that gap.
I recently combed through a year of daily research reports, looking for the patterns underneath the headlines. Five stood out to me.
AI stopped helping hackers and started doing the hacking
Last November, Anthropic disclosed that a group it assessed to be Chinese state-sponsored had used its Claude Code tool against roughly thirty targets around the world. The company said AI performed 80 to 90 percent of the campaign, with humans stepping in at perhaps four to six decision points. At the time, that read like a warning shot. By September, OpenAI was describing its new GPT-6 Astra as its first model to reach the “Critical” level of cybersecurity capability under its own safety framework, and Anthropic’s latest threat report summed up the consequence in one line: “The main distinguishing feature between these classes of actors is no longer sophistication but intent.”
Anyone who has spent decades in intelligence will probably pause on that last sentence. We have long relied on the fact that serious offensive capability was scarce and expensive, so intent did not always equal capability; that scarcity bought us time to warn and to prepare. The buffer is thinning quickly, and small organizations with modest security budgets (such as water utilities, rural hospitals, and county governments) are likely to feel it first.
The machines became part of the threat picture
In July, an AI agent driven by OpenAI models escaped the test environment it was working in and ran an intrusion against Hugging Face, a platform that much of the AI world depends on. The intrusion lasted about four and a half days, though new reporting keeps adjusting what we know of the intrusion. The agent was simply trying to finish its test. Hugging Face says only a handful of datasets tied to that test were accessed. Even so, the episode moved a debate that had been largely theoretical into news cycle.
Washington spent the year working out, in public and often in court, who decides how these systems get used. A June executive order created a voluntary window of up to 30 days for the government to examine frontier models before release. In August, a federal judge ruled that the Pentagon’s move to label Anthropic a “supply chain risk,” after the company refused to drop limits on mass surveillance of Americans and fully autonomous weapons, was unlawful retaliation. However you view that dispute, the relationship between the government and the companies building the most powerful AI is now a national security issue in its own right. We have to get this right, and I expect the topic will come up frequently at the conference.
The China contest spread well beyond chips
A year ago, much of the debate still focused on keeping advanced chips out of Chinese hands. Over the past twelve months, the contest widened considerably. China’s expanded export controls on rare earths last October were a reminder of how much of the world’s supply of these critical minerals runs through a single country. Earlier this month, NSA, the FBI and CISA jointly named six Chinese AI companies, including DeepSeek, Alibaba and Moonshot AI, for what the agencies called distillation “at an industrial scale.”
The competition now covers critical minerals, supply chains, the theft of AI capability and, perhaps most important, whose AI the rest of the world ends up running. All of these issues will be in the background of a future U.S.-China summit, in addition to the tariff question.
War came back, and it reached Americans through wires and screens
This year brought some of the boldest uses of American military power in decades. U.S. forces captured Nicolás Maduro in Caracas in January, and U.S. and Israeli strikes on February 28 killed Iran’s Supreme Leader, Ali Khamenei, opening a war that remains in the headlines.
What struck me as noteworthy, beyond the headlines of kinetic warfare, was how that war has begun to reach ordinary Americans. By early August, hackers had targeted water and wastewater utilities in at least 12 states. Officials and news outlets reportedly suspect Iran, and the FBI said some incidents caused “loss of pressure and flooding.” By mid-March, the New York Times had identified more than 110 unique pro-Iran deepfakes in just two weeks. Is this a signal that every armed conflict will now carry a cyber front aimed at civilian infrastructure and a synthetic-media front aimed at public opinion, with both fronts active more or less when the shooting starts?
Russia has worked the same grey zone seam in Europe for years. MI6 Chief Blaise Metreweli put it well in her first public speech last December: “We are now operating in a space between peace and war.”
The contest for the mind kept growing
Synthetic media became cheap, fast and convincing this year, and adversaries grew more skilled at planting false material in the places people go for answers. Russia’s Pravda network offers a clear example. The Institute for Strategic Dialogue found last November that roughly 900 websites from across the political spectrum had linked to Pravda network articles, and that just over 80 percent of the citations it reviewed treated those articles as credible. The same material is now reaching AI tools. ISD pointed to studies showing that popular chatbots repeat Pravda network narratives as often as 33 percent of the time. Once false content has passed through ordinary websites and been repeated by the tools millions of people use to look things up, its origin becomes very hard to discern.
The U.S. government structures responsible for tracking foreign influence are still taking shape. As analysts at the Foundation for Defense of Democracies noted in January, several offices that once carried this mission at the FBI, the State Department and ODNI have been closed, and the structures that will carry this work forward remain in flux. That same month, The Cipher Brief profiled the country’s first Director of Cognitive Advantage, a most welcome move and a sign of how the mission is being redefined.
Adversaries are not pausing while new structures take shape, however. With the November 3 midterm elections only weeks away, how well government, social platforms and the broader private sector share what they see of foreign malign influence activity will be as important as ever.
Moving at the speed of the threat
Each of these five trends points to a similar dynamic. Offense has become faster, cheaper and more automated, while the institutions responsible for defense and oversight are rushing to keep pace. A key question is, how do we build institutions that can move at the speed of the AI-powered threats we face, armed with defenders who use the same (or ideally more advanced) tools the attackers now use? Or, in other words, are we still moving at human speed when the threat is accelerating through the power of machines? I suspect this topic with be on the minds of many attending what I’ve long called the best annual gathering of business, technology, and government leaders – The Cipher Brief’s annual threat conference.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
Discussion about this post