Skip to content

2024

AI Data Poisoning Is a Knowledge-Supply-Chain Problem

Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.

NIST’s warning about adversarial manipulation of AI systems should change how organizations define the security boundary. Conventional software security focuses heavily on code, dependencies, infrastructure, identity, and configuration. AI systems add another attack surface: the evidence from which system behavior emerges.

Training corpora, feedback data, retrieval indexes, evaluation sets, model artifacts, prompts, and operational context all influence what an AI system learns or produces. If an adversary can shape those inputs, the system may remain technically available while becoming epistemically compromised.

AI expands the software supply chain into a knowledge supply chain. Security must protect not only what the system executes, but what it is permitted to believe.

Responsible Military AI Norms Are an Interoperability Layer

International norms for military artificial intelligence are often discussed as constraints: ethical boundaries intended to prevent unsafe, unlawful, or destabilizing uses of emerging technology. That is an essential function, but it is not the only one.

For allies and partners, shared norms can also operate as an interoperability layer. They establish the minimum assumptions under which states can exchange data, evaluate one another’s systems, coordinate human and machine roles, investigate failures, and employ AI-enabled capabilities without introducing unacceptable uncertainty into combined operations.

This is the underappreciated strategic value of the United States’ effort to build international cooperation around responsible military AI and autonomy. Principles do not become operational merely because many states endorse them. But when principles are translated into compatible engineering evidence, command practices, and assurance processes, responsibility and coalition effectiveness begin to reinforce one another.

AI Safety Needs Public Measurement Infrastructure

The early debate over funding the U.S. Artificial Intelligence Safety Institute could be read as an ordinary appropriations story: lawmakers sought initial resources so NIST could recruit specialists, convene a consortium, and begin work on AI evaluation and safety standards.

The more consequential question is what kind of institution the country expects to build.

An AI Safety Institute should not be a policy office that comments on company evaluations, nor a consortium whose consensus is defined by its largest members. It should function as public measurement infrastructure: an institution capable of developing independent methods, testing important claims, making results reproducible, and creating a shared technical basis for decisions that markets cannot supply on their own.

The Path to Effective CJADC2: True Interoperability over AI

Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.

CJADC2 is often described as a technical effort to connect sensors, data, networks, and decision-makers across domains. That description is accurate but incomplete. It encourages a familiar mistake: treating decision advantage as a product of moving more data into more algorithms at greater speed.

The harder problem is not whether an artificial-intelligence model can identify a pattern. It is whether a coalition can turn that pattern into coordinated action when its participants operate under different authorities, classifications, policies, vocabularies, systems, and risk tolerances.

The decisive architecture of CJADC2 is therefore not the AI layer. It is the interoperability of the human and organizational system around it.

The Missing Middle Between an AI Experiment and a Mission Capability

The Department of Defense has become increasingly proficient at demonstrating advanced technology. The harder achievement is converting a promising result into a capability on which operators can depend.

The Global Information Dominance Experiments (GIDE) illuminate both sides of that problem. They provide recurring opportunities to integrate data, software, analytics, and artificial intelligence across services, combatant commands, the Joint Staff, and international partners. Yet the strategic value of GIDE will not be determined by what works during an experiment. It will be determined by what survives after the experiment’s temporary concentration of people, access, infrastructure, and senior attention dissolves.

The missing middle is transition: the set of technical, organizational, contractual, financial, security, and operational mechanisms that turn evidence into durable capability.

Human–AI Teaming Requires a Science of the Team

The phrase human–machine teaming is used so frequently that it can obscure how little it explains. Placing an AI system in a workflow with a human does not create a team. Nor does assigning the human final authority guarantee meaningful control. A team exists only when participants have interdependent roles, exchange information, adapt to one another, and coordinate their actions toward a shared outcome.

That is why DARPA’s work on quantitative models of human–AI teams is more important than the original 2024 solicitation cycle that prompted this essay. The enduring research problem is not simply whether an AI model performs well or whether a person approves its output. It is whether the combined system behaves competently, legibly, and safely under realistic conditions—including conditions neither participant encountered during development.

GEARS and the Architecture of Retrofit Autonomy

The Army’s Ground Expeditionary Autonomous Retrofit System (GEARS) is strategically interesting for a reason more durable than the selection of three vendors. It treats autonomy as a capability that can be integrated into an existing fleet rather than as a property of a newly designed vehicle.

That choice shifts the center of gravity from platform replacement to architecture. If autonomy can be added through modular navigation kits, stable interfaces, government-controlled data, and repeatable test evidence, the Army can modernize more vehicles, preserve competition, and improve software without waiting for the lifecycle of the underlying truck.

If those conditions are absent, “retrofit” merely moves vendor lock-in from the vehicle to the autonomy stack.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.