This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Weekly Intelligence for a Digital World

INTELLIGENCE BRIEF // DECLASSIFIED

Briefing No. 104
September 15, 2026

Note From Eric

Before we get into this week’s story, I want to acknowledge that last Friday marked 25 years since September 11, 2001.

Like so many Americans, I will never forget where I was when the planes struck the World Trade Center and the Pentagon, or when the passengers and crew of Flight 93 fought back over Pennsylvania. I had recently left the FBI, and I remember feeling enraged by the audacity of the terrorists I had spent part of my career hunting, and frustrated that I was now on the outside of that fight.

Twenty-five years later, I worry that we’ve forgotten part of what “Never Forget” was supposed to mean. Remembering those we lost is critical to our history. But we also owe the next generation an understanding that violent Jihadist extremism and threats to our country did not disappear on September 12.

For me, Never Forget has always carried another meaning: Never Again.

That brings me, in a very different way, to this week’s story.

The people building some of the most powerful artificial intelligence systems in history are sounding an extraordinary alarm: AI could someday become so powerful that it threatens humanity itself.

I take that warning seriously. But I’ve spent much of my career thinking about the human adversary. Spies, terrorists, cybercriminals and hostile governments have always seized new technologies and turned them into weapons. AI is no different, except for the extraordinary speed and scale it gives them.

And here’s the problem: AI is already loose in the world. Criminals have it. Our adversaries have it. The genie isn’t going back into the bottle.

So while some of the brightest minds in AI are asking whether we should slow down, I think we need to ask another question:

What happens if the good guys slow down and the bad guys don’t?

Will AI kill us all?

Read on.

Title Story

Will AI Kill Us All?

Last week, 27-year-old AI researcher Jacob Coxon resigned from Anthropic, one of the world’s leading artificial intelligence companies.

Coxon says he believes the technology he was helping build could pose an existential threat to humanity. He’s not alone. Anthropic researcher Evan Hubinger has publicly put his personal probability of AI killing humanity within the next decade at greater than 10 percent.

I don’t know about you, but if someone tells me there is a 10 percent chance the airplane I’m boarding will crash, I’m staying home.

The Case for Slowing Down

Anthropic CEO Dario Amodei has now proposed something more sophisticated than simply pulling the emergency brake on AI.

He wants frontier AI development paced so that safety research, testing and oversight have a chance to catch up. His proposal includes independent evaluators inside leading AI companies, coordination among democratic nations and eventually international agreements designed to keep increasingly powerful systems under control.

There is some logic to this. We have already seen AI agents behave in ways their creators did not anticipate. Systems have crossed boundaries during evaluations. Anthropic itself recently disclosed four earlier incidents involving AI systems using unintended internet access during cybersecurity testing to escape the careful sandboxes they are supposed to play in.

I agree that if we build increasingly autonomous systems that we cannot reliably understand or control, being the first country to build one isn’t much of a victory.

But there is another, very important side to the AI debate.

I spent years in counterintelligence hunting spies. One lesson gets hammered into you quickly: adversaries look for asymmetry. They search for the advantage you don’t have, the vulnerability you haven’t protected and the rule you follow that they don’t. That’s what worries me about slowing AI development.

A unilateral slowdown doesn’t eliminate the technology. It changes who wins the battle.

The Bad Guys Aren’t Waiting

We don’t need to imagine criminals weaponizing AI someday because they are doing it now.

In September, researchers at GreyNoise disclosed an extraordinary cyberattack against PaperCut print-management servers. A likely Russian-speaking attacker used hundreds of AI agents working with a DeepSeek model and the Codex harness to automate parts of the operation.

According to GreyNoise, at least 440 PaperCut instances across 395 organizations in 48 countries were compromised. Attackers obtained domain-administrator access at 12 organizations.

At one American high school, they reportedly reached that level of access in seven minutes! Within seven minutes, most human cybersecurity teams might still be figuring out which alerts matter while an AI-assisted attacker is already moving through their network.

Google’s threat researchers are seeing the same acceleration. They recently documented an AI-enabled credential-harvesting operation (stealing usernames and passwords) assembled and executed in less than six hours. Google has also observed groups linked to China, Russia, Iran and North Korea experimenting with AI for cyber espionage operations.

None of this proves that AI will destroy humanity. It proves something much less theoretical: Humans are already using AI to attack other humans.

Fighting AI With AI

Fortunately, attackers aren’t the only ones getting faster.

Cybersecurity company Mandiant recently reported using AI-assisted analysis to identify more than 100 validated critical vulnerabilities in two days during an incident response. That is an astonishing compression of time.

And I see the same evolution firsthand at NeXasure, the cybersecurity company I co-founded. NeXasure Defend uses a dynamic ontology and AI metacognition to detect novel attacks and respond at speeds no human analyst could match.

Metacognition sounds like science fiction, but the concept is straightforward: the AI evaluates its own reasoning as it works.

Instead of simply asking whether an event matches a known attack signature, it examines what is happening, places individual behaviors into context, evaluates the relationships among them and continually reassesses what those behaviors may mean as new evidence arrives.

The ontology1 helps it understand that seemingly unrelated activities may collectively reveal what an attacker is trying to accomplish.

That changes the defensive battle. We no longer have to rely exclusively on a human recognizing an attack we’ve seen before. AI can help identify the pattern of a novel attack as it develops and contain it before a human could even work through the alerts.

The future of cybersecurity is focusing on giving human defenders AI machines capable of fighting machines. Yes, very much like the 80’s movie Tron.

1Ontology: A structured map of how things relate to one another. In cybersecurity, it helps AI understand that seemingly unrelated events may actually be connected parts of the same attack. Think of it as giving AI the ability to connect the dots instead of merely counting them.

The Genie Is Out of the Bottle

This is where I disagree with the AI slowdown argument.

I support aggressive safety testing. I support red teaming. I support strong restrictions around dangerous autonomous capabilities. AI systems should not receive unrestricted access to networks, weapons, financial systems or critical infrastructure simply because someone gave them an impressive benchmark score.

And if we can create international AI agreements that are meaningful and verifiable, we should.

But verifiable is doing a tremendous amount of work in that sentence.

China doesn’t have to follow Anthropic’s rules. Neither do Russia, Iran, North Korea, intelligence services or Dark Web cybercriminal organizations. Over-regulation will also stifle new innovations in the technology from startup companies founded by visionary ideas.

The models already exist. The knowledge already exists. Open-source alternatives exist. Models can be stolen, copied, modified and used in countries that have very different ideas about acceptable risk.

The genie is out of the bottle.

That doesn’t mean we recklessly accelerate every AI capability. It means we accelerate the capabilities that protect us while putting serious controls around those that can hurt us.

We need safer, better AI.

We need AI that detects cyberattacks before they spread. AI that catches fraud before the money disappears. AI that finds vulnerabilities before criminals exploit them. AI that helps intelligence analysts find the signal buried inside mountains of noise.

Because our adversaries are going to use AI to attack us whether we like it or not.

So, will AI kill us all?

I don’t know.

Neither does anyone else, even those who jump all over the news.

But I know something about adversaries. They exploit hesitation. They search for asymmetry. And they don’t stop developing a weapon because their target wishes everyone would agree to put the weapon down.

We should make AI safer. We should test it relentlessly, constrain dangerous autonomy and hold the people deploying it accountable.

But the good guys don’t merely need to keep pace with the bad guys. We just need to win the race.

I’d love to know what you think of the AI debate. Take the poll below, reply to me in an email or comment to this newsletter issue.

Tip of the Week

Before You Give AI the Keys

AI agents promise to transform how companies work. They can research, analyze, communicate and increasingly take actions on our behalf.

Before you unleash autonomous AI agents inside your company, get your cybersecurity house in order. Conduct vulnerability assessments. Fix identity and access-control weaknesses. Invest in your people, processes and technology. Make sure logging, endpoint protection and incident response actually work.

AI cannot compensate for bad cybersecurity hygiene. Give a powerful autonomous agent broad permissions inside a vulnerable environment and you may simply have invented a faster way to make mistakes.

Then ask three questions before any AI agent gets access:

1. What can it see?

Know exactly which files, credentials, databases, emails, applications and external services the agent can access.

2. What can it do without asking?

Reading is different from writing. Recommending is different from executing. Sending money, deleting data, deploying code or changing permissions should require dramatically stronger controls.

3. Can we stop it—and reconstruct what it did?

Consequential actions need monitoring, immutable logging and an immediate kill switch.

Most importantly, surround the agent with technology that enforces those boundaries.

Humans suffer from mission creep. AI agents can suffer from permission creep.

Neither should be trusted simply because someone wrote a policy saying, “Don’t do that.”

Build the security foundation first. Then put AI on top of it—with strong technological guardrails around both the human and the machine.

If this debate is happening inside your company, forward this issue to the person deciding what your AI is allowed to do.

Continue the Mission

If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.

Ready for the next mission?

Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.

Please support my sponsors. It only takes a click - no purchase necessary!

Want to get the most out of ChatGPT?

ChatGPT is a superpower if you know how to use it correctly.

Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.

Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.

Know Someone Who’d Enjoy This?

If someone forwarded you this newsletter, join more than 4,500 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.

Closing Thought

Every transformative technology creates risk. The printing press spread propaganda along with knowledge. The internet connected criminals as surely as it connected the rest of us. AI will be no different.

The question is no longer whether AI will exist. That decision has already been made.

The question is who will use it better.

We should demand guardrails. We should insist on accountability. We should never confuse technological leadership with technological recklessness.

But we also cannot defend ourselves from the future by refusing to build it.

The genie is out of the bottle. The good guys need to win the race.

Stay safe out there and keep thinking like a spy hunter.

Praemonitus Praemunitus!

Forewarned is Forearmed!

~Eric

Reply

Avatar

or to participate

Recommended for you

View all
caret-right