Cry Deepfake
When fakes are everywhere, the real prize isn't fooling you. It's that anyone caught on camera can now say "it's fake" and walk away.
In the spring of 2026, during the Iran war, the United States military came within minutes of forcibly boarding a Chinese commercial vessel in the Middle East. Armed personnel suited up. Warplanes went airborne, ready to provide kinetic support. Then, at the last minute, senior officials pulled on the thread of the underlying intelligence and found the thread led nowhere. No nuclear components on that ship, and there never were. The entire threat was a hallucination, generated by a commercial grade AI chatbot used by a US Special Operations Command analyst.
We only learned about this last week, when CNN finally reported it. One of their sources described the report as “entirely false”. The same source added a sentence that ought to be printed above every Pentagon AI procurement desk: it “almost started a war”.
The tech industry has spent the last few years dominating the conversation with talk of AI safety, alignment, and ethical guardrails. The pitch is comforting. It goes: these companies are locked in a philosophical struggle to protect humanity from its own creations. Watch what the systems actually do once they are deployed and you find something much simpler and much darker. Alignment and safety are not moral frameworks. They are access control. Neural weights stay opaque because opacity is the business model. The same black box that stops you from auditing what a model does is what lets a state wire it into warfare with nobody accountable, and what lets a company swallow other people’s ideas with nobody able to prove it. One box, two crimes. This post is about both.
The paper trail is public, dated, and boring, which is how the best evidence usually looks.
In January 2024, OpenAI quietly deleted the line in its usage policy that banned using its models for “military and warfare” purposes, as The Intercept first reported. A spokesman insisted the deletion was unrelated to any project. Eleven months later the company announced a strategic partnership with Anduril, a defence contractor whose entire business is autonomous weapons, to harden American counter-drone systems. By this year the relationship was formal enough that OpenAI published a page titled “Our agreement with the Department of War”.
In February 2025, Google rewrote its AI principles and deleted its own promise, standing since 2018, not to build AI for weapons or surveillance. That 2018 promise only existed because employees revolted over Project Maven, which put Google imagery analysis on Pentagon drone footage. Seven years of good press later, the pledge got rewritten around “democratic values” and national security cooperation. Anthropic plays the same game with better manners. Its acceptable use policy carves out national security work for vetted government customers, while its threat intelligence reports police what counts as “misuse” when someone less sanctioned does the same thing.
The paper trail, condensed:
| Date | Actor | The move |
|---|---|---|
| Jan 2024 | OpenAI | Deletes “military and warfare” from its banned uses |
| Dec 2024 | OpenAI + Anduril | Strategic partnership on counter-drone systems |
| Feb 2025 | Deletes its pledge not to build AI for weapons or surveillance | |
| Jan 2026 | Department of War | AI strategy: “accelerate like hell”, pillars led by warfighting |
| 2026 | OpenAI | Publishes “Our agreement with the Department of War” |
The rule was never “AI must not kill”. The rule is “AI must not kill without the right paperwork”. Once you see that, the rest of this story is bookkeeping.
The near miss with the Chinese vessel shows exactly how this fails in practice. An intelligence analyst fed a chatbot a mixture of open source intelligence and classified signals intelligence. A generative model predicts the next likely word. It does not check whether the story hangs together. Handed fragmented data in a high tension war zone, it simply bridged the gaps with statistically plausible fabrication. The output looked like an assessment. It was a guess with formatting.
The Pentagon’s intelligence machine now runs, in large part, on slightly modified commercial software. Microsoft’s Maven Smart System, built on Palantir’s platform, moves GPT-class models into Department of War targeting workflows. Anduril’s Lattice fuses sensor feeds into targeting decisions. As one former senior US official put it, the internal intelligence tools handed to analysts are frequently just copies of commercial software wearing lipstick. Lipstick does not come with epistemology.
In February, this architecture stopped being theoretical. On the first night of the Iran war, two Tomahawk missiles destroyed the Shajareh Tayyebeh Elementary School in Minab, a two storey building on land that had held an IRGC naval compound years earlier. More than 150 people were killed, at least 123 of them children, the deadliest American targeting error of this century measured in young lives. The Pentagon had catalogued the site as a military facility and never updated the file. A school stood there by 2017, visible in satellite imagery. An American analyst flagged the changes in 2019, logging them in a digital tool that was not connected to the database that feeds targeting. The targeters went to war with imagery seven years out of date.
The Pentagon probe’s most damning finding is about belief. Some Centcom personnel assumed Maven itself would flag the stale information and the inconsistencies in the target folder. Nobody can say where that expectation came from. The software has never promised to verify anything. Palantir, asked about the strike, noted that it is not responsible for the underlying data or for identifying intelligence deficiencies. Around three dozen people stood along the kill chain, and the investigation found high confidence at every single step. This is what compression buys: more than a thousand targets processed in a day, hours of analysis collapsed into minutes, and not one of those dozens catching what a disconnected database already knew in 2019.
The acceleration is mandated from the top. In January 2026, Defense Secretary Pete Hegseth unveiled the department’s AI strategy with the instruction to “question every requirement, delete the dumb ones, and accelerate like hell”. Its three pillars are warfighting, intelligence, and enterprise. Nobody named a pillar safety. Nobody named one verification. And warfighting goes first. Speed is the strategy, and nobody has been assigned to be the adult in the room. The adults were decommissioned by memo. Hegseth’s Pentagon cut its civilian harm mitigation teams by roughly ninety percent, down to fewer than twenty people across the entire department, and Centcom’s own team went from ten to one. Nobody from that team reviewed the Minab site before the missiles flew. Three days after the strike, Hegseth told reporters the campaign had “no stupid rules of engagement” and called American air power the most lethal and precise in history.
For the record, the current roster:
| System | Operator | Job |
|---|---|---|
| Maven Smart System | Microsoft, on Palantir’s platform | Moves GPT-class models into US targeting workflows |
| Lattice | Anduril | Fuses sensor feeds into targeting decisions |
| Lavender | Israeli Defense Forces | Scores residents of Gaza as targets |
| The Gospel | Israeli Defense Forces | Generates buildings to strike |
| Where’s Daddy? | Israeli Defense Forces | Waits for targets to come home, then flags the army |
| ChatBIT | PLA-linked researchers, on Meta’s Llama | Military intelligence analysis |
| Unnamed commercial chatbot | US Special Operations Command | Intelligence drafting; invented nuclear cargo |
The military objective here is not mysterious. It is the compression of the sensor to shooter loop, because every minute of human deliberation is a minute your adversary gets to move. But when intelligence is processed at machine speed, human judgment erodes, and the psychology of this is documented well enough to have a name: automation bias.
History says luck is not a plan. In 1991, a floating point timing error in the Patriot system’s clock let an Iraqi Scud through onto a barracks in Dhahran and twenty eight Americans died. In 2003, Patriot crews trusted the system’s automated classification over conflicting radar data and shot down their own aircraft. In 1999, US bombers struck the Chinese Embassy in Belgrade off an outdated map database. In 1993, the United States jammed the GPS of the Chinese civilian ship Yinhe on false chemical weapons intelligence, a humiliation Beijing still cites as the reason it built BeiDou, its own independent satellite navigation system. Every one of those failures had a human somewhere in the loop. It did not matter. The loop is only as strong as the human’s willingness to doubt the machine, and the entire design of these systems is to make doubting feel irrational.
The ledger:
| Year | System | What failed | Cost |
|---|---|---|---|
| 1983 | Soviet Oko early warning | Five missiles detected that never existed; one officer declined to believe it | The world, nearly |
| 1991 | Patriot, Dhahran | Clock drift after 100 hours uptime | 28 US soldiers |
| 1993 | US GPS jamming of the Yinhe | False chemical weapons intelligence | A humiliated Beijing builds BeiDou |
| 1999 | NATO targeting database | Outdated maps | 3 killed, embassy destroyed |
| 2003 | Patriot, Iraq | Machine classification overrode conflicting radar | Friendly crews killed |
| 2023 | Lavender, Gaza | Ten percent error, twenty second reviews | Tens of thousands marked |
| 2026 | Maven assisted kill chain, Minab | Seven year old imagery, disconnected databases | 150+ killed, 123 of them children |
| 2026 | Commercial chatbot, SOCOM | Hallucinated nuclear cargo | A war, nearly |
OpenAI’s position amounts to this: the username was removed, therefore nothing happened.
And the announcement had a second problem. Mathematicians examining the proof noticed OpenAI had solved a variant of the problem, one with a contrived external force bolted onto the fluid, which satisfies the letter of the Clay Institute’s problem statement while sidestepping the question everybody actually cares about. Three of them have since posted a result showing the method can never extend to the real problem. So the announcement was a hallucination adjacent to a theft. Even the breakthrough was laundering something.
I have written before about the liar’s dividend: once fakes are cheap, the guilty get to call the real evidence fake, and nobody can afford the cost of proving otherwise. This is the same dividend paid to corporations instead of politicians. When you feed a novel proof into a chatbot, the model strips your name, digests the logic, and bakes your intellectual labour into its weights. The company then points its swarm at the problem, collects the breakthrough, and the latent space where your idea now lives cannot be audited by anyone, including you. There is no provenance for thought. The author has no recourse, because there is nothing left to subpoena. It is idea laundering, run through a server rack instead of a shell company, and the noise floor of “the model could have learned it from anywhere” is the perfect washing machine.
Meanwhile, American labs are screaming about exactly this happening to them.
In September 2026, Anthropic published a threat intelligence report confirming that threat actors have moved past using AI as a chatbot and started embedding it as the orchestrator of autonomous operations. A Russian espionage group linked to Midnight Blizzard used Claude to autonomously rewrite and rebuild malware mid-campaign to defeat security detection. Chinese actors built automated vulnerability foundries to hunt zero day exploits. Most alarming, a threat actor cell aligned with the Houthi rebels used Claude Code to engineer guidance and navigation software for a hypersonic glide vehicle and long range ballistic missiles.
Simultaneously, Anthropic picked a public fight with Chinese labs including Moonshot AI and DeepSeek, accusing them of spinning up tens of thousands of fake accounts to scrape Claude’s outputs and distill its capabilities into domestic frontier models. Western labs called it industrial scale theft.
It is theft, in exactly the sense that what happened to the mathematicians is theft. Distillation is just the corporate version of weight washing: the capability leaves its original author, turns up inside a competitor’s model, and no audit on earth can trace the path it took. There are no clean hands anywhere in this economy. Meta shipped Llama with a licence forbidding military use, and researchers linked to the People’s Liberation Army took the open weights and built ChatBIT, a military intelligence analysis tool. The licence was violated the way a speed limit sign is violated by a bullet.
The convergence of internal hallucination and external exploitation has already reached the insurance industry, which is the sector you hire to price catastrophic risk without sentiment. In late 2025 and early 2026, insurers began a systemic retreat from underwriting enterprise AI. Generative AI fails the basic tests of insurability. Vendor liability caps push the residual risk down onto deployers, and the concentration of the economy’s cognition into a handful of foundation models means a single model failure can produce thousands of correlated losses at once. State insurance commissioners began approving the removal of AI coverage from pre-existing policies. When the actuaries leave the room, that is the market saying it cannot price the thing. Lloyd’s started mandating exclusions for state backed cyberattacks back in 2022, effective March 2023, which tells you what underwriters think about state involvement in digital conflict. And the endgame already has a name in policy circles: a Terrorism Risk Insurance Act style federal backstop for AI losses, the insurer’s version of too big to fail.
The law is not ready either, and it says so out loud. The Geneva Conventions require every new weapon to pass a legal review before use, the Article 36 process, but a model that retrains itself every few months is not a weapon anyone can review once. The ICRC has warned for years that algorithmic decision making in armed conflict is outrunning the frameworks meant to restrain it. Command responsibility still lands on a human, but that human is denied the one thing the job now requires: the ability to inspect the reasoning they are legally obliged to evaluate. The system cannot explain itself. The vendor will not. The commander signs anyway.
By centralising the most powerful cognitive engines on earth behind closed doors, the labs have turned secrecy itself into an armament.
As long as the weights stay locked, there is no way to challenge any decision made inside them. The black box protects the theft of the human mind and the destruction of the human body with the same opaque wall. We are not watching the birth of artificial intelligence. We are watching the automation of unchecked power.