AI Policy Wiki
Dashboard

AI and National Security

high confidence · updated 2026-07-26

The national-security dimension of AI: DoD adoption (CDAO, Task Force Lima, AI RCC), frontier AI for defense, industrial espionage (Ding case), civil-military fusion in China, and the intersection with export controls.

The national-security dimension of AI covers several intertwined threads: how the US Department of Defense and intelligence community adopt and procure AI; how the People's Liberation Army (PLA) does the same; the industrial-espionage channel through which Chinese actors acquire US AI trade secrets; and how these threads reshape export-control and race-dynamic logic. As of early 2026 it is among the fastest-moving areas in AI policy.

US Department of Defense adoption

The US institutional vehicle for AI adoption is the Chief Digital and Artificial Intelligence Office (CDAO), led from late 2024 into 2026 by Radha Plumb.

Task Force Lima (August 2023 – December 2024) was CDAO's time-limited generative-AI task force. It catalogued 15 use-case areas, split between warfighting functions (command-and-control, decision support) and enterprise functions (financial management, healthcare information); reviewed hundreds of AI workflows across the department; and operated on three lines of effort — Learn (230+ collected use cases), Accelerate (sandboxes), and Guide (risk frameworks). On December 11, 2024, Task Force Lima was sunset and its mandate rolled into the permanent AI Rapid Capabilities Cell (AI RCC) under CDAO, in partnership with the Defense Innovation Unit (DIU). Initial funding was $100M across FY24/25, with $35M earmarked for four frontier-AI pilots conducted in 90-day increments through the GIDE (Global Information Dominance Experiments) series. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

The shift from task force to permanent cell changed scope, funding, and access:

DimensionTask Force Lima (2023–24)AI RCC (2024–present)
StatusTime-limited task forcePermanent cell within CDAO
ScopeGenerative-AI adoption studyRapid fielding of AI capabilities
FundingCatalog / experimentation$100M FY24/25, $35M frontier pilots
Output15 use cases, recommendationsOperational pilots in 90-day cycles
Industry accessAd hocTradewinds (CDAO) + DIU Commercial Solutions Openings

DoD's stated strategy is not to build competing foundation models but to fine-tune, orchestrate, and containerize commercial frontier models into classified enclaves — described as the "wild / zoo / cages" framing (public commercial / DoD enterprise / isolated classified). Traditional 12–18 month exercise cycles are being replaced by 90-day GIDE iterations. Capabilities such as CJADC2 (Combined Joint All-Domain Command and Control) are treated as software rather than hardware, with persistent fielding and continuous updates; a minimum-viable CJADC2 was declared operational through GIDE V–VIII. Alpha 1, the CDAO data and ML scaffolding portfolio, prioritizes computer vision and sensor-level (perception) autonomy, leaving command-autonomy to program offices. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

Several constraints bear on the speed of this adoption. Authority-to-Operate (ATO) classification overhead remains a binding limit; commercial generative-AI tools lack persistence in isolated DoD networks, and industry has not fully adapted; and traditional Program Objective Memorandum (POM) cycles are incompatible with iterative software release. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

US intelligence-community adoption

Disclosures in May 2026 documented a parallel push to adopt frontier AI inside the US intelligence community, distinct from the DoD/CDAO thread.

On May 20, 2026, reporting disclosed that U.S. Cyber Command had stood up a task force — referred to internally as "Mythos" in some reporting — to accelerate adoption of frontier AI models with offensive hacking capabilities. Gen. Joshua Rudd, the dual-hat head of Cyber Command and the NSA, announced the effort to staff roughly two weeks before it became public. The task force is to study how Silicon Valley models can be safely deployed on the intelligence community's most sensitive "high-side" classified networks. It followed earlier-May 2026 Pentagon deals with seven AI firms, including OpenAI and Google, to run models on classified systems. (Source: https://www.politico.com/news/2026/05/20/nsa-cyber-command-ai-task-force-mythos-00930786)

On May 22, 2026, reporting disclosed that the White House had approved roughly $9 billion for US spy agencies to accelerate AI adoption. The CIA and NSA cannot fully deploy the latest models on their classified systems because of a shortage of cutting-edge chips, the gap the funding is meant to close. The funding decision casts the chip-shortage constraint, usually discussed in supply-chain terms, as a direct limit on US intelligence capability: the agencies have model access but lack the compute substrate to run frontier systems on isolated classified enclaves. (Source: https://www.nytimes.com/2026/05/22/us/politics/spy-agencies-ai-chips-shortage.html)

Together the two disclosures show the IC adoption push as both institutionally structured (a dedicated Cyber Command/NSA task force) and resourced at scale ($9B), with the "high-side" classified-network deployment problem — the same persistence-in-isolated-enclaves constraint the CDAO thread identifies — as the central technical bottleneck. The offensive-capability dimension is covered at AI and Cybersecurity.

CIA Director John Ratcliffe compared the capabilities of frontier AI systems to "digital nuclear weapons" in remarks reported on July 2, 2026, an intelligence-community-leadership characterization of frontier models as strategic-weapons-class technology (Source: controlai.news).

Space-based ISR and autonomous targeting

On May 29, 2026, the U.S. Space Force, under the Department of the Air Force, awarded SpaceX $4.16 billion to build the first increment of a space-based Air Moving Target Indicator (AMTI) constellation — an orbital sensing layer to track airborne threats (fighters, bombers, cruise missiles, and potentially hypersonic weapons) via the Starshield military-satellite platform. Initial capability is targeted for 2028. (Source: https://spacenews.com/space-force-awards-spacex-4-16-billion-to-build-satellite-network-for-airborne-target-tracking/)

The deal is structured as an Other Transaction Authority (OTA) agreement rather than a traditional FAR-based contract, the same rapid-acquisition posture emphasized in the CDAO/AI RCC thread, applied here to a multi-billion-dollar space-sensing program. (Source: https://www.militarytimes.com/industry/techwatch/2026/05/29/spacex-awarded-4-billion-space-force-contract-to-track-airborne-threats/) The AMTI award came days after SpaceX won a separate $2.29 billion Space Data Network contract, giving the company a position in both the sensing and communications layers of the Pentagon's space architecture, a concentration of orbital ISR and connectivity in a single commercial vendor. (Source: https://spacenews.com/space-force-awards-spacex-4-16-billion-to-build-satellite-network-for-airborne-target-tracking/)

Moving-target tracking and threat classification from orbit feed the same sensor-and-decision-support pipeline as the C5ISRT priorities documented on the China side and the perception-autonomy emphasis in CDAO's Alpha 1 portfolio. The AMTI sensing layer supplies the targeting picture that downstream systems, governed on the kinetic side by autonomous-weapons doctrine, would act on. It also illustrates the commercial-vendor model for space ISR alongside players such as Anduril in the broader defense-tech base.

China: military-civil fusion and PLA priorities

CSET's February 2026 China's Military AI Wish List (Probasco, Bresnick, McFaul) and its September 2025 companion Pulling Back the Curtain on China's Military-Civil Fusion (McFaul, Bresnick, Chou) together constitute the open-source evidence base. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

The February 2026 report frames PLA priorities around C5ISRT (command, control, communications, computers, cyber, intelligence, surveillance, reconnaissance, targeting): AI decision-support systems operating on open-source data; maritime- and space-domain counter-US capability; facial recognition, gait recognition, and digital forensics; and deepfake generation and detection. On procurement, the report documents thousands of RFPs across 2023–24, mostly on 3–6 month timelines with modest budgets, implying a rapid-prototyping commercial-vendor model rather than long-cycle programs of record — the opposite of traditional US defense acquisition. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

The September 2025 report quantifies the vendor base: 2,857 AI-related defense contract awards across 1,560 unique entities. The top-dollar awardees are legacy state-owned enterprises CETC, CASC, and NORINCO. About 75% of entities are nontraditional vendors (no self-reported state ownership), mostly founded post-2010 and emphasizing dual-use; they collectively won more contracts than legacy players (764 contracts). "Seven Sons of National Defense" universities and Chinese Academy of Sciences affiliates are heavily represented. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

CSET's reading is that civil-military fusion (军民融合) is operational in AI procurement, not merely doctrinal: the blurring of the civilian-defense vendor boundary is visible and quantified in the procurement data. The reports note the bearing on export controls — end-use certification is weaker when the nominal civilian end-user is structurally entangled with PLA procurement chains. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary)) A dedicated source page covers the February 2026 report at China's Military AI Wish List.

Industrial espionage: the Linwei Ding case

On January 30, 2026, a federal jury in the Northern District of California convicted Linwei (Leon) Ding, 38, a former Google software engineer, on seven counts of economic espionage (18 U.S.C. § 1831) and seven counts of trade-secrets theft (18 U.S.C. § 1832). CSET and the DOJ describe it as the first US conviction on AI-related economic-espionage charges. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary)) A dedicated source page covers the conviction at DOJ: Former Google Engineer Convicted of Economic Espionage (Linwei Ding).

Between May 2022 and April 2023, Ding exfiltrated over 2,000 pages of confidential Google material on TPU (Tensor Processing Unit) chip architecture; GPU system design and cluster interconnect; SmartNIC, Google's custom network-interface-card for high-speed AI-cluster communication; and software managing communication and task execution in large-scale training — in combination, the blueprint for a hyperscale AI training system. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

During the theft Ding was negotiating to become CTO of a PRC-based tech company (around June 2022) and founding his own PRC AI/ML company as CEO (by early 2023). Publicly-identified affiliates were Rongshu Lianzhi Technology and Shanghai Zhisuan Technology, both in AI-infrastructure and training-compute. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

The case sits alongside the hardware-denial channel: export controls restrict chips, while espionage prosecution restricts design IP. CSET notes that §1831 requires proving intent to benefit a foreign government or instrumentality, a higher bar than §1832, so the successful §1831 conviction serves as a model for future AI-IP enforcement. The companies Ding affiliated with fall inside the same "nontraditional vendor" ecosystem CSET documents as structurally entangled with PLA procurement. (Source: CSET + DOJ + CSIS — US-China AI National-Security Axis (composite source summary))

Intersection with export controls

The national-security view treats export controls as one arm of a denial strategy that spans multiple channels:

ChannelToolLimiting factor
Hardware (chips, equipment)BIS export controls, Entity ListSmuggling, cloud-rental, allied coordination
Design IP (architectures, specs)§1831 espionage prosecution, trade-secret lawDetection inside US companies
Human capitalVisa policy, clearance policyTrade-off with US research capacity
Software weightsAI Diffusion rule (rescinded May 2025)No current federal framework

The Ding case is the first visible success in the design-IP row. The rescission of the BIS AI Diffusion rule in May 2025 leaves the software-weights row effectively empty, a gap in the strategy that national-security analysts increasingly note. (Source: Export Controls (AI))

Intersection with the Anthropic–Department of War conflict

The same administration that runs the AI RCC also threatened to designate Anthropic a "supply-chain risk" for refusing to remove Claude use restrictions in classified contexts. (Source: Clawed) This produces an internal tension between the CDAO/AI RCC posture, which seeks fast commercial-model integration into DoD workflows, and the Department of War pressure on Anthropic, which is willing to use Entity-List-adjacent tools against the US lab best positioned to supply classified-enclave deployments. Ball (2026) argues these two postures are in tension and that the second may ultimately undermine the first. (Source: Clawed)

Two recurring argumentative moves are tracked separately: National Security as Policy Trump Card, the pattern in which a contested policy question is settled by appeal to competition with China rather than on its merits; and Palmer Luckey's democratic-oversight framing, which inverts the use-restriction debate by asking whether military policy should be set by elected leaders or by corporate executives.

Relationships

Key entities

  • Radha Plumb — CDAO Chief Digital and Artificial Intelligence Officer.
  • Chief Digital and AI Office (CDAO) — DoD AI lead office.
  • DIU — commercial-tech pipeline partner.
  • CSET — primary open-source analytic voice on China military AI.
  • Linwei (Leon) Ding — defendant in the first AI economic-espionage conviction.

Sources