Sector Briefing 01 · Defense & Intelligence · 5-minute briefing

The Attack Surface is the Mind.

If an enemy can predict how you think, they don't need to hack your servers. They just need to feed you the right information to influence your decisions, thoughts, and judgment.

This briefing makes one argument: the four risks below do not depend on the technology's weaknesses. They run through what capable systems do well: observe, infer, synthesize, and persuade. A more capable model is a more fluent adversary channel, a more convincing substitute for analysis, and a more complete observer of the analysts who use it. Hardening the servers touches none of this.

Can your workforce synthesize information without an algorithm?

The Risks

Risk 01 Holds at any capability

Cognitive Prompt Injection

Just as you can trick an AI into breaking its rules, adversaries can trick a population into changing its mind. By understanding the algorithms that curate our news, enemies insert instructions that look like organic trends. The influence appears as organic engagement, and forming an opinion still feels autonomous even when it has been shaped.

Why a better system makes it worse: a more capable model is a more fluent, less attributable channel for the narrative.

Dive Deeper

Cognitive Prompt Injection

Risk 02 Holds at any capability

Analytic Atrophy

The GPS effect for the brain. If intelligence analysts use AI to summarize everything, they lose the ability to read the map. The analyst who cannot synthesize independently cannot detect when AI-generated conclusions are compromised. If the AI is poisoned, the workforce is helpless.

Why a better system makes it worse: the better the synthesis, the less practice the analyst gets, and the less she can tell when it is wrong.

Dive Deeper

The Era of Cognitive Capture · The Five Mechanisms of Cognitive Capture

Risk 03 Holds at any capability

The Liar's Dividend

When any recording can be synthetic, any recording can be denied. Authentic evidence loses its force because fabrication is always a plausible explanation. An adversary does not need to convince anyone of a lie; making everything deniable is enough.

Why a better system makes it worse: the dividend grows with fidelity. Every gain in realism makes denial more plausible.

Dive Deeper

The Liar's Dividend · Synthetic Media Is a Cognitive Security Problem

Risk 04 Holds at any capability

The Watched Analyst

Continuous algorithmic observation pushes personnel into performance mode. They prioritize appearing compliant over intellectual risk-taking, because struggle generates concerning data points. The messy thinking that produces breakthroughs disappears first.

Why a better system makes it worse: more complete monitoring reads more of the thinking, so playing it safe pays more.

Dive Deeper

The Era of Cognitive Capture

30%

Decline in privacy-sensitive Wikipedia browsing after the Snowden revelations: awareness of being watched changes what people let themselves read. Penney (2016), Berkeley Technology Law Journal.

r = -0.68

Correlation between heavy AI reliance and critical thinking scores across 666 participants. Gerlich (2025), Societies.

The Decision Loop

John Boyd’s OODA loop, the cycle behind competitive judgment. When Orient and Decide run through AI systems, the phases that produce judgment become observable and manipulable. From The Era of Cognitive Capture.

Observe

Intake: what the environment, and the feed, presents

Orient

Sense-making: where synthesis happens

Exposed

Decide

Judgment: where the conclusion forms

Exposed

Act

Execution of a decision built upstream

An adversary who reaches Orient and Decide does not need to change what a population knows, only how it processes what it knows.

Required Protocols

01 / Practice

Zero-Digital Protocol

High-stakes strategy happens in zero-digital rooms. If you do not type it or record it, it cannot be compromised.

02 / Doctrine

Human Synthesis

AI is for retrieval, finding facts, not synthesis, connecting dots. The final logic chain is verified by a human decision-maker.

03 / Testing

Red Teaming Dependency

Regularly test whether your analysts reach accurate conclusions with the AI tools turned off.

Where This Sector Sits in the CPIA

01Capture
02Inference
03Influence◆ Primary
04Dependency◆ Primary
05Developmental
06Retention

Every domain applies to the mission. Domains 03 and 04 carry the strategic weight, and the questions below belong in any deployment review before an AI system reaches analysts.

Is the system optimized for engagement, agreement, or accuracy, and can the vendor demonstrate which?

Would the analyst’s conclusion differ if the same material arrived unranked?

Is unassisted analytic performance measured at intervals?

Does the deployment include tool-free practice and drills against dependency?

Who is accountable when the system is degraded, denied, or poisoned?

What does the system retain about how your analysts think?

View the CPIA Framework

The Foundation · The Cognitive Privacy Project

The full argument behind this briefing is published, dated, and citable: the threat architecture, the cognitive gap in privacy law, and the sovereignty protocols organizations can adopt now.

Read the White Paper

Cite this briefing

Cook, T. (2026). The attack surface is the mind: AI risk to defense and intelligence. The Cognitive Privacy Project. cognitiveprivacyproject.org/security

For advisory inquiries or research collaboration: timothy@cognitiveprivacyproject.org