The national-security dimension of AI covers several intertwined threads: how the US Department of Defense and intelligence community adopt and procure AI; how the People's Liberation Army (PLA) does the same; the industrial-espionage channel through which Chinese actors acquire US AI trade secrets; and how these threads reshape export-control and race-dynamic logic. As of early 2026 it is among the fastest-moving areas in AI policy.
US Department of Defense adoption
The US institutional vehicle for AI adoption is the Chief Digital and Artificial Intelligence Office (CDAO), led from late 2024 into 2026 by Radha Plumb.
Task Force Lima (August 2023 – December 2024) was CDAO's time-limited generative-AI task force. It catalogued 15 use-case areas, split between warfighting functions (command-and-control, decision support) and enterprise functions (financial management, healthcare information); reviewed hundreds of AI workflows across the department; and operated on three lines of effort — Learn (230+ collected use cases), Accelerate (sandboxes), and Guide (risk frameworks). On December 11, 2024, Task Force Lima was sunset and its mandate rolled into the permanent AI Rapid Capabilities Cell (AI RCC) under CDAO, in partnership with the Defense Innovation Unit (DIU). Initial funding was $100M across FY24/25, with $35M earmarked for four frontier-AI pilots conducted in 90-day increments through the GIDE (Global Information Dominance Experiments) series. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
The shift from task force to permanent cell changed scope, funding, and access:
| Dimension | Task Force Lima (2023–24) | AI RCC (2024–present) |
|---|---|---|
| Status | Time-limited task force | Permanent cell within CDAO |
| Scope | Generative-AI adoption study | Rapid fielding of AI capabilities |
| Funding | Catalog / experimentation | $100M FY24/25, $35M frontier pilots |
| Output | 15 use cases, recommendations | Operational pilots in 90-day cycles |
| Industry access | Ad hoc | Tradewinds (CDAO) + DIU Commercial Solutions Openings |
DoD's stated strategy is not to build competing foundation models but to fine-tune, orchestrate, and containerize commercial frontier models into classified enclaves — described as the "wild / zoo / cages" framing (public commercial / DoD enterprise / isolated classified). Traditional 12–18 month exercise cycles are being replaced by 90-day GIDE iterations. Capabilities such as CJADC2 (Combined Joint All-Domain Command and Control) are treated as software rather than hardware, with persistent fielding and continuous updates; a minimum-viable CJADC2 was declared operational through GIDE V–VIII. Alpha 1, the CDAO data and ML scaffolding portfolio, prioritizes computer vision and sensor-level (perception) autonomy, leaving command-autonomy to program offices. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
Several constraints bear on the speed of this adoption. Authority-to-Operate (ATO) classification overhead remains a binding limit; commercial generative-AI tools lack persistence in isolated DoD networks, and industry has not fully adapted; and traditional Program Objective Memorandum (POM) cycles are incompatible with iterative software release. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
US intelligence-community adoption
Disclosures in May 2026 documented a parallel push to adopt frontier AI inside the US intelligence community, distinct from the DoD/CDAO thread.
On May 20, 2026, reporting disclosed that U.S. Cyber Command had stood up a task force — referred to internally as "Mythos" in some reporting — to accelerate adoption of frontier AI models with offensive hacking capabilities. Gen. Joshua Rudd, the dual-hat head of Cyber Command and the NSA, announced the effort to staff roughly two weeks before it became public. The task force is to study how Silicon Valley models can be safely deployed on the intelligence community's most sensitive "high-side" classified networks. It followed earlier-May 2026 Pentagon deals with seven AI firms, including OpenAI and Google, to run models on classified systems. (Source: https://www.politico.com/news/2026/05/20/nsa-cyber-command-ai-task-force-mythos-00930786)
On May 22, 2026, reporting disclosed that the White House had approved roughly $9 billion for US spy agencies to accelerate AI adoption. The CIA and NSA cannot fully deploy the latest models on their classified systems because of a shortage of cutting-edge chips, the gap the funding is meant to close. The funding decision casts the chip-shortage constraint, usually discussed in supply-chain terms, as a direct limit on US intelligence capability: the agencies have model access but lack the compute substrate to run frontier systems on isolated classified enclaves. (Source: https://www.nytimes.com/2026/05/22/us/politics/spy-agencies-ai-chips-shortage.html)
Together the two disclosures show the IC adoption push as both institutionally structured (a dedicated Cyber Command/NSA task force) and resourced at scale ($9B), with the "high-side" classified-network deployment problem — the same persistence-in-isolated-enclaves constraint the CDAO thread identifies — as the central technical bottleneck. The offensive-capability dimension is covered at AI and Cybersecurity.
CIA Director John Ratcliffe compared the capabilities of frontier AI systems to "digital nuclear weapons" in remarks reported on July 2, 2026, an intelligence-community-leadership characterization of frontier models as strategic-weapons-class technology (Source: controlai.news).
Space-based ISR and autonomous targeting
On May 29, 2026, the U.S. Space Force, under the Department of the Air Force, awarded SpaceX $4.16 billion to build the first increment of a space-based Air Moving Target Indicator (AMTI) constellation — an orbital sensing layer to track airborne threats (fighters, bombers, cruise missiles, and potentially hypersonic weapons) via the Starshield military-satellite platform. Initial capability is targeted for 2028. (Source: https://spacenews.com/space-force-awards-spacex-4-16-billion-to-build-satellite-network-for-airborne-target-tracking/)
The deal is structured as an Other Transaction Authority (OTA) agreement rather than a traditional FAR-based contract, the same rapid-acquisition posture emphasized in the CDAO/AI RCC thread, applied here to a multi-billion-dollar space-sensing program. (Source: https://www.militarytimes.com/industry/techwatch/2026/05/29/spacex-awarded-4-billion-space-force-contract-to-track-airborne-threats/) The AMTI award came days after SpaceX won a separate $2.29 billion Space Data Network contract, giving the company a position in both the sensing and communications layers of the Pentagon's space architecture, a concentration of orbital ISR and connectivity in a single commercial vendor. (Source: https://spacenews.com/space-force-awards-spacex-4-16-billion-to-build-satellite-network-for-airborne-target-tracking/)
Moving-target tracking and threat classification from orbit feed the same sensor-and-decision-support pipeline as the C5ISRT priorities documented on the China side and the perception-autonomy emphasis in CDAO's Alpha 1 portfolio. The AMTI sensing layer supplies the targeting picture that downstream systems, governed on the kinetic side by autonomous-weapons doctrine, would act on. It also illustrates the commercial-vendor model for space ISR alongside players such as Anduril in the broader defense-tech base.
China: military-civil fusion and PLA priorities
CSET's February 2026 China's Military AI Wish List (Probasco, Bresnick, McFaul) and its September 2025 companion Pulling Back the Curtain on China's Military-Civil Fusion (McFaul, Bresnick, Chou) together constitute the open-source evidence base. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
The February 2026 report frames PLA priorities around C5ISRT (command, control, communications, computers, cyber, intelligence, surveillance, reconnaissance, targeting): AI decision-support systems operating on open-source data; maritime- and space-domain counter-US capability; facial recognition, gait recognition, and digital forensics; and deepfake generation and detection. On procurement, the report documents thousands of RFPs across 2023–24, mostly on 3–6 month timelines with modest budgets, implying a rapid-prototyping commercial-vendor model rather than long-cycle programs of record — the opposite of traditional US defense acquisition. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
The September 2025 report quantifies the vendor base: 2,857 AI-related defense contract awards across 1,560 unique entities. The top-dollar awardees are legacy state-owned enterprises CETC, CASC, and NORINCO. About 75% of entities are nontraditional vendors (no self-reported state ownership), mostly founded post-2010 and emphasizing dual-use; they collectively won more contracts than legacy players (764 contracts). "Seven Sons of National Defense" universities and Chinese Academy of Sciences affiliates are heavily represented. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
CSET's reading is that civil-military fusion (军民融合) is operational in AI procurement, not merely doctrinal: the blurring of the civilian-defense vendor boundary is visible and quantified in the procurement data. The reports note the bearing on export controls — end-use certification is weaker when the nominal civilian end-user is structurally entangled with PLA procurement chains. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary)) A dedicated source page covers the February 2026 report at China's Military AI Wish List.
Industrial espionage: the Linwei Ding case
On January 30, 2026, a federal jury in the Northern District of California convicted Linwei (Leon) Ding, 38, a former Google software engineer, on seven counts of economic espionage (18 U.S.C. § 1831) and seven counts of trade-secrets theft (18 U.S.C. § 1832). CSET and the DOJ describe it as the first US conviction on AI-related economic-espionage charges. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary)) A dedicated source page covers the conviction at DOJ: Former Google Engineer Convicted of Economic Espionage (Linwei Ding).
Between May 2022 and April 2023, Ding exfiltrated over 2,000 pages of confidential Google material on TPU (Tensor Processing Unit) chip architecture; GPU system design and cluster interconnect; SmartNIC, Google's custom network-interface-card for high-speed AI-cluster communication; and software managing communication and task execution in large-scale training — in combination, the blueprint for a hyperscale AI training system. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
During the theft Ding was negotiating to become CTO of a PRC-based tech company (around June 2022) and founding his own PRC AI/ML company as CEO (by early 2023). Publicly-identified affiliates were Rongshu Lianzhi Technology and Shanghai Zhisuan Technology, both in AI-infrastructure and training-compute. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
The case sits alongside the hardware-denial channel: export controls restrict chips, while espionage prosecution restricts design IP. CSET notes that §1831 requires proving intent to benefit a foreign government or instrumentality, a higher bar than §1832, so the successful §1831 conviction serves as a model for future AI-IP enforcement. The companies Ding affiliated with fall inside the same "nontraditional vendor" ecosystem CSET documents as structurally entangled with PLA procurement. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))
Intersection with export controls
The national-security view treats export controls as one arm of a denial strategy that spans multiple channels:
| Channel | Tool | Limiting factor |
|---|---|---|
| Hardware (chips, equipment) | BIS export controls, Entity List | Smuggling, cloud-rental, allied coordination |
| Design IP (architectures, specs) | §1831 espionage prosecution, trade-secret law | Detection inside US companies |
| Human capital | Visa policy, clearance policy | Trade-off with US research capacity |
| Software weights | AI Diffusion rule (rescinded May 2025) | No current federal framework |
The Ding case is the first visible success in the design-IP row. The rescission of the BIS AI Diffusion rule in May 2025 leaves the software-weights row effectively empty, a gap in the strategy that national-security analysts increasingly note. (Source: Export Controls (AI))
Intersection with the Anthropic–Department of War conflict
The same administration that runs the AI RCC also threatened to designate Anthropic a "supply-chain risk" for refusing to remove Claude use restrictions in classified contexts. (Source: Clawed) This produces an internal tension between the CDAO/AI RCC posture, which seeks fast commercial-model integration into DoD workflows, and the Department of War pressure on Anthropic, which is willing to use Entity-List-adjacent tools against the US lab best positioned to supply classified-enclave deployments. Ball (2026) argues these two postures are in tension and that the second may ultimately undermine the first. (Source: Clawed)
Two recurring argumentative moves are tracked separately: National Security as Policy Trump Card, the pattern in which a contested policy question is settled by appeal to competition with China rather than on its merits; and Palmer Luckey's democratic-oversight framing, which inverts the use-restriction debate by asking whether military policy should be set by elected leaders or by corporate executives.
Relationships
- depends-on: Export Controls (AI) — this concept extends the export-control logic into human-capital and design-IP channels.
- depends-on: AI Race Dynamics — the natsec dimension is a fourth race alongside national-compute / corporate-frontier / safety-capability.
- related: Autonomous Weapons — C5ISRT focus here is the sensor and decision-support side of the same military-AI question that DoD Directive 3000.09 governs on the kinetic side. (Autonomous Weapons currently has a directive-3000-09 mention; CSET's procurement data adds the empirical China side.)
- related: Clawed — Ball's Anthropic-DoW analysis documents the internal tension within US natsec AI posture.
- instance-of: US-China AI Competition: Different Races, Different Metrics — the military / espionage lane of the broader US-China competition.
- supports: claim on Export Controls (AI) that enforcement requires multi-channel coverage (chips + IP + people + weights).
- supports: claim on AI Race Dynamics that Paris-style coalition fracture reflects security-framed rather than safety-framed AI governance.
- related: China's Military AI Wish List — dedicated source page for the February 2026 CSET Military AI Wish List report.
- related: DOJ: Former Google Engineer Convicted of Economic Espionage (Linwei Ding) — dedicated source page for the January 2026 Linwei Ding conviction.
Key entities
- Radha Plumb — CDAO Chief Digital and Artificial Intelligence Officer.
- Chief Digital and AI Office (CDAO) — DoD AI lead office.
- DIU — commercial-tech pipeline partner.
- CSET — primary open-source analytic voice on China military AI.
- Linwei (Leon) Ding — defendant in the first AI economic-espionage conviction.
Sources
- CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary) — composite summary
- Raw: CSET - Chinas Military AI Wish List.md
- Raw: DOJ Press Release - Linwei Ding Conviction.md
- Clawed — for the internal tension between DoD AI adoption and lab-coercion posture
- Export Controls (AI) — for the broader denial-strategy context
- SpaceNews / Space Force awards SpaceX $4.16 billion for airborne target tracking (May 29, 2026): spacenews.com
- Military Times / SpaceX awarded $4 billion Space Force contract to track airborne threats (May 29, 2026): militarytimes.com
- US Cyber Command AI task force ("Mythos"), Politico (May 20, 2026): politico.com
- $9B for spy agencies' AI, New York Times (May 22, 2026): nytimes.com