Sector Briefing 01 · Defense & Intelligence · 5-minute briefing
The Attack Surface is the Mind.
If an enemy can predict how you think, they don't need to hack your servers. They just need to feed you the right information to influence your decisions, thoughts, and judgment.
This briefing makes one argument: the four risks below do not depend on the technology's weaknesses. They run through what capable systems do well: observe, infer, synthesize, and persuade. A more capable model is a more fluent adversary channel, a more convincing substitute for analysis, and a more complete observer of the analysts who use it. Hardening the servers touches none of this.
Can your workforce synthesize information without an algorithm?
The Risks
Risk 01 Holds at any capability
Cognitive Prompt Injection
Just as you can trick an AI into breaking its rules, adversaries can trick a population into changing its mind. By understanding the algorithms that curate our news, enemies insert instructions that look like organic trends. The influence appears as organic engagement, and forming an opinion still feels autonomous even when it has been shaped.
Why a better system makes it worse: a more capable model is a more fluent, less attributable channel for the narrative.
Dive Deeper
Risk 02 Holds at any capability
Analytic Atrophy
The GPS effect for the brain. If intelligence analysts use AI to summarize everything, they lose the ability to read the map. The analyst who cannot synthesize independently cannot detect when AI-generated conclusions are compromised. If the AI is poisoned, the workforce is helpless.
Why a better system makes it worse: the better the synthesis, the less practice the analyst gets, and the less she can tell when it is wrong.
Dive Deeper
The Era of Cognitive Capture · The Five Mechanisms of Cognitive Capture
Risk 03 Holds at any capability
The Liar's Dividend
When any recording can be synthetic, any recording can be denied. Authentic evidence loses its force because fabrication is always a plausible explanation. An adversary does not need to convince anyone of a lie; making everything deniable is enough.
Why a better system makes it worse: the dividend grows with fidelity. Every gain in realism makes denial more plausible.
Dive Deeper
The Liar's Dividend · Synthetic Media Is a Cognitive Security Problem
Risk 04 Holds at any capability
The Watched Analyst
Continuous algorithmic observation pushes personnel into performance mode. They prioritize appearing compliant over intellectual risk-taking, because struggle generates concerning data points. The messy thinking that produces breakthroughs disappears first.
Why a better system makes it worse: more complete monitoring reads more of the thinking, so playing it safe pays more.
Dive Deeper
30%
Decline in privacy-sensitive Wikipedia browsing after the Snowden revelations: awareness of being watched changes what people let themselves read. Penney (2016), Berkeley Technology Law Journal.
r = -0.68
Correlation between heavy AI reliance and critical thinking scores across 666 participants. Gerlich (2025), Societies.
The Decision Loop
John Boyd’s OODA loop, the cycle behind competitive judgment. When Orient and Decide run through AI systems, the phases that produce judgment become observable and manipulable. From The Era of Cognitive Capture.
Observe
Intake: what the environment, and the feed, presents
Orient
Sense-making: where synthesis happens
ExposedDecide
Judgment: where the conclusion forms
ExposedAct
Execution of a decision built upstream
An adversary who reaches Orient and Decide does not need to change what a population knows, only how it processes what it knows.
Required Protocols
01 / Practice
Zero-Digital Protocol
High-stakes strategy happens in zero-digital rooms. If you do not type it or record it, it cannot be compromised.
02 / Doctrine
Human Synthesis
AI is for retrieval, finding facts, not synthesis, connecting dots. The final logic chain is verified by a human decision-maker.
03 / Testing
Red Teaming Dependency
Regularly test whether your analysts reach accurate conclusions with the AI tools turned off.
Where This Sector Sits in the CPIA
Every domain applies to the mission. Domains 03 and 04 carry the strategic weight, and the questions below belong in any deployment review before an AI system reaches analysts.
Is the system optimized for engagement, agreement, or accuracy, and can the vendor demonstrate which?
Would the analyst’s conclusion differ if the same material arrived unranked?
Is unassisted analytic performance measured at intervals?
Does the deployment include tool-free practice and drills against dependency?
Who is accountable when the system is degraded, denied, or poisoned?
What does the system retain about how your analysts think?
The Foundation · The Cognitive Privacy Project
The full argument behind this briefing is published, dated, and citable: the threat architecture, the cognitive gap in privacy law, and the sovereignty protocols organizations can adopt now.
The Era of Cognitive Capture (White Paper) · Cognitive Prompt Injection · The Liar's Dividend · All Research
Cite this briefing
Cook, T. (2026). The attack surface is the mind: AI risk to defense and intelligence. The Cognitive Privacy Project. cognitiveprivacyproject.org/security
For advisory inquiries or research collaboration: timothy@cognitiveprivacyproject.org

