From Seeing to Acting: AI’s Expanding Role in National Security

At the National Security & Intelligence Summit in August, I went in expecting to learn more about intelligence and national security. I came away thinking about data.

More specifically, I came away thinking about what happens when governments possess so much data that collecting information is no longer the primary problem. The harder problems become determining what information matters, whether it can be trusted, how quickly it can be shared and who — or what — should be allowed to act upon it.

Again and again, I heard variations on the same themes: speed and scale, interoperability, provenance, artificial intelligence and the danger of drowning analysts in more information than humans can reasonably process.

One of the most interesting things I observed was that the human being seemed, at times, to be quietly disappearing from the technological conversation.

That is the question I am taking with me to the Billington CyberSecurity Summit.

I am not particularly interested in whether the government is adopting artificial intelligence. It is.

I am interested in what happens next.

My working framework for Billington is:

DATA → TRUST → DECISION → AUTONOMY → ACTION

And alongside those five words, I am keeping a sixth category:

HUMAN

Whenever someone mentions human judgment, human authorization, human oversight, human accountability or keeping a human in the loop, I intend to make a note of it.

I will also make a note when nobody does.

What I Learned at the National Security & Intelligence Summit

The intelligence community has spent decades building extraordinary capabilities for collecting information. Satellites, signals intelligence, biometrics, surveillance systems, open-source intelligence and enormous commercial datasets have created an environment in which scarcity of information is increasingly replaced by abundance.

At INSA, I became particularly interested in four related problems.

The first was scale. Human beings cannot manually process everything modern sensors and databases can collect.

The second was interoperability. Information is substantially less useful if the systems that possess it cannot communicate effectively with one another.

The third was provenance. If information is going to move rapidly between systems and increasingly be interpreted by machines, knowing where it originated and whether it has been altered becomes enormously important.

And the fourth was speed. Intelligence that arrives after the decision has already been made has limited value.

Artificial intelligence appears to offer an answer to all four problems. It can sift enormous quantities of information, connect disparate datasets, identify patterns and present recommendations at speeds impossible for human analysts.

But solving the information problem creates another problem.

If machines increasingly help us decide what information is important, we must determine when we trust the machine.

And cybersecurity increasingly appears to be part of the mechanism through which that trust is established.

Day One: What Can the System Trust?

My first day at Billington will begin with the modern nation-state threat landscape, followed immediately by the cyber leaders of the Five Eyes discussing cyber risk in the age of AI.

I want to understand not simply what China, Russia, Iran, North Korea and other cyber adversaries are doing, but how the defensive architecture is changing in response.

The morning then moves directly into artificial intelligence and cybersecurity: AI-enabled attacks, automated reconnaissance, exploit generation and machine-speed defensive capabilities.

At 10:30 a.m., I plan to attend Weaponization of AI by Cyber Adversaries.

The question I will carry into the room is:

Does AI merely allow adversaries to conduct familiar attacks faster, or is it creating fundamentally new forms of attack?

At 11:30, I will attend Governance of Large-Scale Data Practices in the Age of AI. This may be one of the sessions most closely connected to what I heard at INSA. Representatives from government, industry and the Space Force will consider algorithmic transparency, governance and trust surrounding enormous datasets.

My question:

If national-security decisions increasingly depend upon machine analysis of enormous datasets, what establishes that the underlying information — and the machine interpreting it — can be trusted?

After lunch, I plan to hear CIA Deputy Director Michael Ellis discuss cyber intelligence and the foreign threat environment, followed by a session on the future of cyber warfare.

The afternoon introduces another important concept: Zero Trust.

Zero Trust assumes that access should not simply be granted because someone or something is already inside a network. Identity and authorization must continually be verified.

There is something philosophically interesting about this.

The digital national-security architecture appears to be moving toward a world in which enormous quantities of information move extraordinarily quickly while trust becomes increasingly conditional.

At 4:15 p.m., I will listen particularly closely to Department of War Chief Digital and Artificial Intelligence Officer Cameron Stanley.

The phrase I am watching for is “decision superiority.”

It may be one of the most consequential phrases at the conference.

Day Two: Who Gets to Make the Decision?

If Day One is about determining what the system can trust, Day Two is about authority.

At 8:30 a.m., the FBI Cyber Division will discuss the Bureau's evolution from reacting to cyberattacks toward proactively disrupting adversaries.

That introduces an important shift:

reaction → prediction → disruption

At what point does defending against an anticipated attack become acting against an adversary?

At 9 a.m., senior government and industry leaders will discuss the next three years of public-private cyber collaboration. I am particularly interested in the increasing role of private companies in protecting the United States from foreign cyberattack.

The list of companies surrounding modern national security is remarkable: Microsoft, Amazon Web Services, Google, OpenAI, Anthropic, Cohere, Palantir-like data architectures, cybersecurity companies and enormous federal contractors.

These are not simply vendors selling office software to the government.

Increasingly, commercial technology forms part of the infrastructure through which national security operates.

At 9:30, UK National Cyber Security Centre CEO Richard Horne will sit down with Anthropic's Teresa Carlson.

I will be listening carefully to the vocabulary used to describe that relationship.

Is a frontier AI company a vendor? A partner? An infrastructure provider? An adviser? A capability provider?

Twenty-five minutes later, Department of War CIO Kirsten Davies will discuss innovation and “decision advantage” in a conversation moderated by OpenAI's Alexis Bonnell.

That gives me two phrases to compare:

Decision superiority.

Decision advantage.

What exactly constitutes an advantage when the speed of decision-making itself is becoming technologically mediated?

At 10:40, I plan to attend Securing the AI Supply Chain: From Training Data to Model Deployment.

The AI supply chain now includes training data, foundation models, vector databases, inference infrastructure, open-source components and outside AI services.

That leads directly back to provenance.

Before we can trust an AI-generated conclusion, how many other things have already had to be trusted?

At 11:40, I am deliberately leaving conventional cybersecurity behind for Securing Autonomous Vehicles and Smart Transportation.

This is where the story becomes physical.

The progression is no longer simply:

DATA → ANALYSIS

It becomes:

DATA → ANALYSIS → DECISION → PHYSICAL ACTION

Autonomous vehicles are an obvious example, but the underlying question applies to drones, robotics, defense systems and other forms of physical AI.

My question becomes:

When software can cause something to happen in the physical world, where must human authorization enter the chain?

Watching Frontier AI Work

At 12:40 p.m. on Day Two, I plan to attend OpenAI's workshop, Frontier AI for Cyber Defense: OpenAI's Perspective and a Live Demo for Government Defenders.

I am interested in the technology, but I am equally interested in the room.

I want to watch what government cybersecurity professionals photograph. I want to hear what they ask. I want to see which capabilities excite them and which create discomfort.

Sometimes the reaction to a technology tells you as much as the demonstration.

The afternoon brings CISA Acting Director Nick Andersen discussing the agency's priorities for 2027–2028, followed by AI-Augmented Cyber Defense: Hype vs. Reality.

That second session is particularly important because after nearly two days of hearing about what AI can do, I want to hear precisely what it still cannot do.

Where are the false positives?

Where does AI fail?

When does a human analyst outperform it?

When does the machine require supervision?

And perhaps most importantly:

What decisions are officials unwilling to delegate?

The day ends with discussions of data sharing and cyber strategy for American warfighters.

Here, another recurring national-security tension emerges:

SECRECY ↔ SHARING

CONTROL ↔ SPEED

VERIFICATION ↔ ACTION

Every attempt to increase one side potentially creates vulnerability on the other.

Day Three: When the Digital System Enters the Physical World

I have an Atelier Ashley Flowers commitment on the third day of Billington, so I may attend only part of the program.

There is, however, one session I particularly want to see.

At 10:20 a.m., the National Reconnaissance Office, U.S. Space Force and OpenAI will participate in The Security of Space.

The panel encompasses satellites, command-and-control links, commercial launch systems, ground infrastructure and the terrestrial networks and cloud platforms supporting them.

Space is an unusually interesting environment in which to consider autonomy.

Communications can be contested. Infrastructure is distributed. Decisions may sometimes need to be made quickly and without ideal access to human operators.

And the participants themselves are revealing: intelligence, military space and frontier artificial intelligence sitting on the same stage.

My question:

How autonomous will space infrastructure eventually need to become in order to survive a contested environment?

If my schedule permits, I also want to hear Lt. Gen. Paul Stanton, commander of the Department of War Cyber Defense Command and director of DISA, and later Katherine “Katie” Sutton, Assistant Secretary of War for Cyber Policy and Principal Cyber Advisor to the Secretary of War.

But if flowers win the afternoon, they win.

The objective is not to attend every panel. It is to recognize the pattern connecting them.

From Seeing to Acting

After INSA and while preparing for Billington, I have started thinking about the national-security information system as a progression:

SEE → UNDERSTAND → DECIDE → ACT

For most of human history, technology primarily expanded the first step.

Telescopes allowed us to see farther. Telegraphs moved information faster. Radar detected objects humans could not see. Satellites allowed governments to observe enormous portions of the Earth.

Computers dramatically expanded our ability to store and organize what we saw.

Artificial intelligence potentially changes the middle of the chain.

It can help determine what information means.

And once a machine can understand enough to recommend a decision, the next technological temptation is obvious: allow it to execute that decision.

That is where cybersecurity becomes more interesting than protecting computers from hackers.

Cybersecurity begins to determine which identities, datasets, systems, models and machines are trusted enough to participate in the decision-making architecture of the state.

The United States appears to be constructing an increasingly integrated information architecture intended to transform enormous quantities of data into trusted, machine-speed decisions.

Cybersecurity is not merely protecting that architecture.

Increasingly, cybersecurity may determine what the architecture is allowed to believe.

And artificial intelligence raises the next question:

What will the architecture eventually be allowed to do?

That is what I will be listening for at Billington.

Not whether AI is coming to national security.

It is already there.

I want to know how far along the chain from seeing to acting government is prepared to let the machine travel before a human being must intervene.

Disclosure: This article was developed collaboratively with ChatGPT. The author supplied the reporting framework, prior National Security & Intelligence Summit observations, conference materials, questions and editorial direction. AI was used to help organize the conference itinerary, identify connections among sessions and develop the structure and language of the article. The author retains editorial responsibility for the final work.

Previous
Previous

America Should Stay in the Room. France International Space Summit

Next
Next

Can AI Liberate Our Attention?