Robert Dannenberg, Former Senior CIA Officer

Cipher Brief Expert Rob Dannenberg is a 24-year veteran of the CIA, where he served in several senior leadership positions, including chief of operations for the Counterterrorism Center, chief of the Central Eurasia Division and chief of the CIA’s Information Operations Center. Dannenberg is a member of the Board of Advisors to the Director of the National Counterterrorism Center and is a senior fellow at the GWU Center for Cyber and Homeland Security. He is now an independent consultant on geopolitical and security risk, after serving as the managing director and head of the Office of Global Security for Goldman Sachs, and director of International Security Affairs at BP.

EXPERT PERSPECTIVE — The images from Kabul are demoralizing and depressing—unless you are sitting in the Kremlin, where they are certainly being viewed in a quite different light. Probably something close to giddiness and glee.

From Russian President Vladimir Putin’s perspective, this likely reinforces his view that President Joe Biden and his national security team are weak and naïve.  ‘This is Obama’s third term’, Putin must be thinking. And of course, the images of US helicopters desperately trying to evacuate thousands from Kabul also resonate in Kiev, Tbilisi, and probably Tallinn, Riga, and Vilnius and beyond—think Taipei.  The appalling mismanagement of the withdrawal from Afghanistan will have consequences that will affect American credibility globally and linger well beyond the end of Biden’s presidency.

A first order consequence concerns Russia.

It is highly likely there was practical cooperation between the Kremlin and the Taliban in the preparation for the American withdrawal and this may have included direct support to Taliban forces. We don’t need to revisit the narrative of Russian bounties for dead American soldiers in Afghanistan, but the evidence of Russian energetic engagement with the Taliban in recent months is manifest and the fact the Russian embassy in Kabul is currently protected by Taliban fighters is significant.

For both Russia and the Taliban there was a clear shared strategic objective: Get the Americans and their allies out of Afghanistan and ideally in the most humiliating fashion possible.  The Russian-Taliban honeymoon may not last long, but for the moment it has served both sides well.

For over a decade and a half of his tenure as Russia’s president, Putin has been preaching the gospel that you can’t trust the Americans to back you in the long run or when the chips are down, but you can count on the Russia he leads (think the Russian intervention in Syria and support for Assad or their intervention—whether acknowledged or not—in Libya on the side of Khalifa Haftar among other examples). This messaging is important in current times and reinforces Putin’s narrative about the decline of the West and the waning relevance of western liberal systems of governance.

In recent years, Chinese President Xi Jinping has picked up the trumpet to echo this message that American power is in decline and that American security guarantees cannot be relied on in East Asia and beyond.

Putin has been Russia’s Czar for over two decades without meaningful interruption and is likely to remain so for the foreseeable future. He has seen US Presidents come and go and he has been quick to size them up and adjust his moves accordingly. He was genuinely scared of what George W. Bush might do in the immediate aftermath of 9/11 and the speed and efficacy of the US response made a deep impression on him.  He adjusted his approach to the US to one of partner and ally against Islamic extremism (Putin was also busy consolidating his control over the Russian Federation in the immediate post-Yeltsin period).

Putin also sized up then-President Barack Obama after Obama’s failure to act when Syrian President Bashar al-Assad blithely crossed the “no use of chemical weapons” red line.  That opened the door for the annexation of Crimea as well as the Russian military intervention in Syria (and later Libya). Joe Biden was Vice President at the time. Putin likely has a very good book on Joe Biden and was quite confident of what the end result for the US in Afghanistan would look like.  Putin may even have a better feel for Joe Biden than many realize, if any of the Hunter Biden material is true.  One leader’s assessment of another, matters in geopolitical relations. Putin has a high level of confidence in his ability to read his international opposition.

As recently as July 2021 President Biden said, “There’s going to be no circumstance where you see people being lifted off the roof of the US embassy in Afghanistan.”  He went on to add, “The likelihood there’s going to be the Taliban overrunning everything and owning the whole country is highly unlikely.”  President Biden made these statements knowing perfectly or should have known—from intelligence briefings and expert commentary—as well as historical precedent—that when the US announces a withdrawal of forces with a hard deadline, in this case 9/11, our adversaries use the time to prepare for their offensive military action. Our Afghan allies knew this as well and prepared accordingly.  Now the Taliban will celebrate the twentieth anniversary of the September 11 attacks in the US embassy in Kabul, probably with their ISIS and Al Qaeda friends as honored guests.  If you think the videos from Afghanistan have been troubling to this point, just wait for the anniversary celebrations.

Perhaps of more near term geopolitical significance, Putin will use the Taliban takeover of Afghanistan to support a narrative that Russia needs to defend its interests from the spread of Islamic extremism from Afghanistan by strengthening “security and counterterrorism” cooperation with Turkmenistan, Uzbekistan, Tajikistan, Kyrgyzstan. Does anyone want an excuse to get – and keep – those pesky Americans out of Central Asia and start rebuilding that corner of the Soviet Union?

Putin’s use of terrorism risk as justification for military action is well-rehearsed and goes back to the Moscow apartment bombings (which the FSB almost certainly organized) in September 1999, which Putin used both to consolidate political power and to justify the brutal military campaign in Chechnya. Putin is acutely aware of the risks of Islamic extremism spreading from Afghanistan to Central Asia, the Caucasus, and into the Russian Federation. In fact, Russian, Uzbek, and Tajik troops conducted exercises in July, which appear to have been designed to prepare to respond to cross border incursions from Afghanistan. This is only the first step in his plan for consolidation of Russian power and influence in Central Asia and the Caucasus.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Some might ask – given the risk of the spread of Islamic extremism from Afghanistan to the Russian Federation – why would Putin would want to partner with the Taliban?  Those who ask this question are misunderstanding the depth of Putin’s enmity toward the United States and the West and everything for which we stand.  Putin views the world as a “zero sum” game.  What hurts the US must serve Russia’s interests. The debacle in Afghanistan clearly qualifies. A short-term deal with the Taliban is a risk with taking in Putin’s mind.  Putin plays on the superpower chessboard using the only tools he has at hand, military power, cyber and disinformation capability and US ineptitude and lack of strategic thought.  He has taken clever advantage of President Trump’s four years of thoughtless estrangement of US allies around the world.

Beyond the propaganda value and regional leverage our withdrawal has given adversaries like Russia and China, there is the impact of our withdrawal on the many nations among our allies who contributed to the Afghanistan mission. The images of Afghans clinging to a departing US Air Force C-17 and falling to their deaths will not fade easily. How easy will it be to assemble their support when we inevitably have to go in again to deal with a resurgent Al Qaeda, a globally ambitious Taliban, or an even more dangerous embedded ISIS in the hills of Afghanistan?

We should also consider the impact on Pakistan.  Pakistan has nurtured Islamic extremism in Afghanistan for decades.  While a part of the Pakistani security establishment partnered with the US effectively after 9/11, other parts simultaneously were nurturing relations with extremists including the Taliban. The “Great Game” is still being played in that part of the world, and neither the Pakistanis, nor the Indians or Chinese have forgotten it.

Pakistan also still certainly chafes from the US raid to kill bin Ladin in Abbottabad a little over ten years ago.  One wonders if the waning of US influence in Islamabad has opened the door for Islamic extremists to enter the security establishment there. Pakistan is a nuclear power and has in recent years, increased its development of tactical nuclear weapons. Does the Taliban now have a path to nuclear weapons?  This is an important question and it’s answer casts a shadow over our withdrawal from Afghanistan.

The Biden Administration, for all its vaunted claims of “return to competence” in Washington, has fallen flat in its first serious challenge. One could argue that Biden’s capitulation on Nord Stream 2 and Putin’s mocking rejection in Geneva of charges of US election interference and cyberattacks on the US, foretold the debacle in Afghanistan. The challenge for the US now will be to manage the airlift of those Afghans who were willing to partner with the US and carefully look for opportunities to rebuild the credibility of US security guarantees around the world.

Taiwan and South Korea would seem good places to start.

At the same time, we need to recognize that Afghanistan will once again become the training ground for those who hope to replicate 9/11 attacks on the US. A strong and robust intelligence capability will be essential in mitigating that risk.

Read more expert-driven national security insight, perspective and analysis in The Cipher Brief

The post Putin’s Calculated Afghanistan Play appeared first on The Cipher Brief.

find more fun & mates at SoShow now !

An Argentinian woman has become the second-ever HIV-infected person whose immune system helped defeat the virus without requiring additional medical treatment. She was first diagnosed with the AIDS-causing infection in 2013.

Scientists have dubbed the 30-year-old mother the “Esperanza patient,” after her hometown. The word ‘esperanza’ translates to ‘hope’ in English. Publishing their findings in the Annals of Internal Medicine journal on Monday, the researchers said the discovery boosts hope for a “sterilizing cure” for the estimated 38 million people with the life-long infection.

“I enjoy being healthy,” the Esperanza patient told NBC News over email. “I have a healthy family. I don’t have to medicate, and I live as though nothing has happened. This already is a privilege.”

The study found no intact remnants of the virus in the 1.5 billion blood and tissue cells the researchers analyzed – confirming the discovery first announced in March at an international meeting of HIV experts.

Read more

© Belova59 from Pixabay
‘Elite controllers’ can cure themselves of HIV without any medical treatment, bombshell research claims

No additional information about the woman has been made public, but she was described at the time as “athletic and beautiful” and revealed to have an HIV-negative boyfriend and newborn baby.

Only one other person, identified in August 2020 as 67-year-old Loreen Willenberg from San Francisco, has been confirmed to have overcome the virus without medical intervention. The two women have been labeled ‘elite controllers’, referring to a rare subset of HIV patients who show no signs of the infection despite not undergoing antiretroviral treatments.

Typically, an HIV-infected person requires constant drug therapy to prevent the virus from attaching to their immune cells’ DNA and replicating. But, in the eight years since she was diagnosed, the Esperanza patient only received medication for six months during pregnancy to ensure her baby would be healthy.

In all, there have been four patients cured of HIV, two of whom – the ‘Berlin patient’ Timothy Ray Brown and the ‘London patient’ Adam Castillejo – were also cancer patients who received risky bone marrow transplants from donors with HIV-resistant genes. However, the success of their procedures is yet to be replicated.

“This is really the miracle of the human immune system that did it,” Dr. Xu Yu, an immunologist at the Ragon Institute in Boston, who co-authored the study, told NBC.

If you like this story, share it with a friend!

find more fun & mates at SoShow now !

When the PRC decides to move on Taiwan, it is unlikely to move in a manner that makes a US decision on intervention clear cut.  Should China decide, initially at least, against a full-scale invasion of that island nation, it could instead opt to try to “win without fighting.” Beijing might do so by using its large, state-controlled fishing fleet to cut smaller Taipei-controlled islands off from Taiwan itself much as the PRC is now massing fishing boats to expand Chinese-controlled seas to press claims on the Japanese Senkakus and Whitsun Reef in Philippine waters. Chinese state-owned fisheries companies – part of the so-called ‘Maritime Militia’ – serve as fronts for PLA intelligence. Using their fleets to operate in a manner somewhere between peace and conflict in the gray zone of contested control around Taiwan would allow Beijing to test whether the US and its allies are willing to help defend the island’s independence without being seen to initiate open conflict.

“The Cipher Brief has become the most popular outlet for former intelligence officers; no media outlet is even a close second to The Cipher Brief in terms of the number of articles published by formers.” – Sept. 2018, Studies in Intelligence, Vol. 62 No.

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .  

 

 

The post Why the China – Russia Relationship Should Worry You – Part Two appeared first on The Cipher Brief.

find more fun & mates at SoShow now !

Sports goods retailer Decathlon has said it won’t be selling canoes in its stores in northern France anymore because the light vessels are increasingly being used by migrants trying to cross into England.

“Given the current context… the purchase of canoes will no longer be possible” in Decathlon stores in Calais and Grande-Synthe, outside Dunkirk, the French retailer announced.

The two cities overlook the Strait of Dover, which is the narrowest point in the English Channel. Thousands of migrants have been using this spot in recent years to try to make the dangerous 34-kilometer-long sea journey from France to the UK.A lot of canoes aren’t being purchased for their original sporting purpose, Decathlon complained.

Read more

FILE PHOTO. ©REUTERS/Peter Cziborra
London & Paris trade barbs over Channel crossings

They “could be used to cross the Channel” and as a result of this, “people’s lives would be endangered,” it pointed out.

“We are committed to never putting our customers at risk in the use of our products, whatever the circumstances,” the company said. 

The initiative to remove canoes from the shelves came from the stores themselves and was backed by the head office, according to the retailer. However, Decathlon will keep selling the vessels online and in its other shops across France.

Last Thursday, two canoes were found adrift in the Channel near Calais, while two migrants were rescued from the water. The next day, three more people were reported missing after attempting to get to England using canoes.

Tensions between London and Paris are high after a record number of migrants – 1,185 – were able to cross the Channel a week ago. 

Britain said it was unacceptable” that France had let so many people slip through, but the French government insisted they were “neither their collaborators nor their assistants” and blamed the soaring crossings on the smugglers and the UK’s labor market, which makes the country attractive to people eager to work at low cost.”

Like this story? Share it with a friend!

find more fun & mates at SoShow now !

A Canadian teenager has been arrested after allegedly stealing $36.5 million in cryptocurrency from a person in the US. The police claim it was the largest such heist involving one victim ever registered in North America.

Police in the city of Hamilton, Ontario, arrested the unidentified perpetrator on Wednesday, after over a year investigating what they have described as the biggest-ever cryptocurrency theft from a single person in either the US or Canada. Local police began a joint investigation with the Federal Bureau of Investigation and the US Secret Service Electronic Crimes Task Force in March 2020, when the theft was reported.

Read more

© AP Photo/Jiri Buller
Europol detains 10 hackers over $100 million cryptocurrency theft from celebrities

The Hamilton Police Service said it had made “multiple” seizures in excess of CA$7 million (US$5.5 million) during the arrest, which came after investigators noticed some of the stolen money had been used to buy an online username considered “rare” in the gaming community, according to a police statement.

The victim was apparently targeted by a cell phone hijack known as SIM swapping. This method involves manipulating cellular network employees to duplicate phone numbers in order to let the scammer intercept the two-factor authorization requests that allow them access to a victim’s account.

This method is considered especially potent because a lot of people use the same password for multiple sites, according to Detective Constable Kenneth Kirkpatrick, of the Hamilton Police’s cybercrimes unit. He added that cyber and cryptocurrency crimes were becoming increasingly common, but noted that the figures involved in this case were “very surprising.”

“It’s a large amount of money in anybody’s opinion,” Kirkpatrick said, adding that the case was currently in the Hamilton court system.

The police haven’t revealed the age or gender of the youth, the username they purchased, or whether they were acting alone.

If you like this story, share it with a friend!

find more fun & mates at SoShow now !

President Joe Biden commented on reports that US officials are planning to boycott the upcoming Olympics in Beijing over alleged human rights violations – but his answer left journalists perplexed.

When asked on Tuesday if an official US delegation will be traveling to the Winter Games in the Chinese capital in February, Biden responded: “I am the delegation.”

The president, however, did not elaborate, leaving the White House correspondents in a state of confusion, as his response could mean that Biden will attend the Winter Olympics alone or, as some reporters suggested, that he simply did not understand the question.

Read more

A screen at a restaurant in Beijing showing Chinese President Xi Jinping's virtual meeting with US President Joe Biden. © Reuters / Tingshu Wang
Biden & Xi agree to avoid conflict

A recent report by a Washington Post columnist claimed the US won’t be sending an official delegation to Beijing in 2022 over allegations of human rights violations by the Chinese government. According to the sources cited in the article, a formal recommendation for a diplomatic boycott of the Olympics has been already presented to Biden, with the move expected to be approved by the president by the end of November.

The piece was published on the day that Biden held a lengthy virtual meeting with Chinese leader Xi Jinping, in which they discussed a range of issues regarding the strained relations between the two nations – but not the Olympics.

The White House said that during the talks, President Biden challenged his Chinese counterpart over what Washington sees as persecution against the Uyghur population in the Xinjiang region, as well as human rights violations in Tibet and Hong Kong. China has strongly denied the claims, accusing the US of interfering in its internal affairs.

Calls for the Biden administration to boycott the Olympics and refrain from sending a political delegation to Beijing have recently been made by top Democratic and Republican lawmakers. 

If implemented, it won’t affect the American athletes, who will still be taking part in the Winter Olympics.

Like this story? Share it with a friend!

find more fun & mates at SoShow now !

The annual migration of red crabs has brought traffic to a standstill on an Australian island. Apart from the epic journey, the species is also notorious for eating its own young.

Tens of millions of crustaceans are swarming Canberra-governed Christmas Island, which is almost a thousand miles northwest of the Australian mainland. Parks Australia, a government body in charge of wildlife conservation on the island, has deployed its staff to manage traffic, rake crabs off roads and provide advisories to local residents regarding road closures. Authorities are well-prepared to deal with the epic crab march as it repeats every year, usually in October and November. There are even special bridges and tunnels in place, built over and under busy roads so as to minimize the number of crabs crushed by cars. The sight of millions of these creatures making their perilous trek has become one of Christmas Island’s main tourist attractions.

The exact timing of the red crabs’ journey from forest to ocean is defined by rainfall and lunar phases. The march is led by male crabs, which are later joined by females. On reaching the ocean, they mate and spawn, with each female capable of producing as many as 100,000 eggs. However, most of the young crabs never make it back to the forest as they end up being eaten by fish and whale sharks for whom this is a veritable feast. To make matters worse, the crab larvae that do make it to the beach are often devoured by returning adult crabs of the very same species, hence one of their names – the cannibal crab.

If you like this story, share it with a friend!

find more fun & mates at SoShow now !

Rotterdam Mayor Ahmed Aboutaleb has described an anti-lockdown protest in his city as an “orgy of violence.” The Dutch demonstration devolved into a violent riot that saw police open fire on protesters.

Aboutaleb described the events of Friday night as an “orgy of violence,” after protesters packed Rotterdam’s central Coolsingel shopping street to voice their opposition to an ongoing partial lockdown, a ban on New Year’s Eve fireworks displays, and the possibility of a two-tiered system of freedom in the Netherlands, one of liberty for the vaccinated and restrictions for those without the jab.

Read more

A police squad car is seen engulfed in flames during a protest in Rotterdam, Netherlands, November 19, 2021.
2 wounded after shots fired at Covid protest in Netherlands

The protest soon got out of hand, and police said on Saturday that 57 people were arrested. Protesters were seen torching police vehicles and launching fireworks at police, who shot at them in response.

Aboutaleb said that the cops had been “forced” to use their weapons. “On a number of occasions the police felt it necessary to draw their weapons to defend themselves,” he told reporters. “They shot at protesters, people were injured.”

Police say at least seven people were injured. Two of these injuries were caused by police bullets, and the victims are still in hospital. One officer was hospitalized, while several others were treated at the scene for minor injuries.

Like this story? Share it with a friend!

find more fun & mates at SoShow now !

A Roadmap for AI in the Intelligence Community

(Editor’s Note: This article was first published by our friends at Just Security and is the fourth in a series that is diving into the foundational barriers to the broad integration of AI in the IC – culture, budget, acquisition, risk, and oversight.  This article considers a new IC approach to risk management.)

OPINION — I have written previously that the Intelligence Community (IC) must rapidly advance its artificial intelligence (AI) capabilities to keep pace with our nation’s adversaries and continue to provide policymakers with accurate, timely, and exquisite insights. The good news is that there is strong bipartisan support for doing so. The not-so-good news is that the IC is not well-postured to move quickly and take the risks required to continue to outpace China and other strategic competitors over the next decade.

In addition to the practical budget and acquisition hurdles facing the IC, there is a strong cultural resistance to taking risks when not absolutely necessary. This is understandable given the life-and-death nature of intelligence work and the U.S. government’s imperative to wisely execute national security funds and activities. However, some risks related to innovative and cutting-edge technologies like AI are in fact necessary, and the risk of inaction – the costs of not pursuing AI capabilities – is greater than the risk of action.

The Need for a Risk Framework

For each incredible new invention, there are hundreds of brilliant ideas that have failed. To entrepreneurs and innovators, “failure” is not a bad word. Rather, failed ideas are often critical steps in the learning process that ultimately lead to a successful product; without those prior failed attempts, that final product might never be created. As former President of India A.P.J. Abdul Kalam once said, “FAIL” should really stand for “First Attempt In Learning.”

The U.S. government, however, is not Silicon Valley; it does not consider failure a useful part of any process, especially when it comes to national security activities and taxpayer dollars. Indeed, no one in the U.S. government wants to incur additional costs or delay or lose taxpayer dollars. But there is rarely a distinction made within the government between big failures, which may have a lasting, devastating, and even life-threatening impact, and small failures, which may be mere stumbling blocks with acceptable levels of impact that result in helpful course corrections.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


As a subcommittee report of the House Permanent Select Committee on Intelligence (HPSCI) notes “[p]rogram failures are often met with harsh penalties and very public rebukes from Congress which often fails to appreciate that not all failures are the same. Especially with cutting-edge research in technologies … early failures are a near certainty …. In fact, failing fast and adapting quickly is a critical part of innovation.” There is a vital difference between an innovative project that fails and a failure to innovate. The former teaches us something we did not know before, while the latter is a national security risk.

Faced with congressional hearings, inspector general reports, performance evaluation downgrades, negative reputational effects, and even personal liability, IC officers are understandably risk-averse and prefer not to introduce any new risk. That is, of course, neither realistic nor the standard the IC meets today. The IC is constantly managing a multitude of operational risks – that its officers, sources, or methods will be exposed, that it will miss (or misinterpret) indications of an attack, or that it will otherwise fail to produce the intelligence policymakers need at the right time and place. Yet in the face of such serious risks, the IC proactively and aggressively pursues its mission. It recognizes that it must find effective ways to understand, mitigate, and make decisions around risk, and therefore it takes action to make sure potential ramifications are clear, appropriate, and accepted before any failure occurs. In short, the IC has long known that its operations cannot be paralyzed by a zero-risk tolerance that is neither desirable nor attainable. This recognition must also be applied to the ways in which the IC acquires, develops, and uses new technology.

This is particularly important in the context of AI. While AI has made amazing progress in recent years, the underlying technology, the algorithms and their application, are still evolving and the resulting capabilities, by design, will continue to learn and adapt. AI holds enormous promise to transform a variety of IC missions and tasks, but how and when these changes may occur is difficult to forecast and AI’s constant innovation will introduce uncertainty and mistakes. There will be unexpected breakthroughs, as well as failures in areas that initially seemed promising.

The IC must rethink its willingness to take risks in a field where change and failure is embraced as part of the key to future success. The IC must experiment and iterate its progress over time and shift from a culture that punishes even reasonable risk to one that embraces, mitigates, and owns it. This can only be done with a systematic, repeatable, and consistent approach to making risk-conscious decisions.

Today there is no cross-IC mechanism for thinking about risk, let alone for taking it. When considering new activities or approaches, each IC element manages risk through its own lens and mechanisms, if at all. Several individual IC elements have created internal risk assessment frameworks to help officers understand the risks of both action and inaction, and to navigate the decisions they are empowered to make depending upon the circumstances. These frameworks increase confidence that if an activity goes wrong, supervisors all the way up the chain will provide backing as long as the risk was reasonable, well-considered and understood, and the right leaders approved it. And while risk assessments are often not precise instruments of measurement – they reflect the quality of the data, the varied expertise of those conducting the assessments, and the subjective interpretation of the results – regularized and systematic risk assessments are nevertheless a key part of effective risk management and facilitate decision-making at all levels.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Creating these individual frameworks is commendable and leading-edge for government agencies, but more must be done holistically across the IC. Irregular and inconsistent risk assessments among IC elements will not provide the comfort and certainty needed to drive an IC-wide cultural shift to taking risk. At the same time, the unique nature of the IC, comprised of 18 different elements, each with similar and overlapping, but not identical, missions, roles, authorities, threats and vulnerabilities, does not lend itself to a one-size-fits-all approach.

For this reason, the IC needs a flexible but common strategic framework for considering risk that can apply across the community, with each element having the ability to tailor that framework to its own mission space. Such an approach is not unlike how the community is managed in many areas today – with overarching IC-wide policy that is locally interpreted and implemented to fit the specific needs of each IC element. When it comes to risk, creating an umbrella IC-wide framework will significantly improve the workforce’s ability to understand acceptable risks and tradeoffs, produce comprehensible and comparable risk determinations across the IC, and provide policymakers the ability to anticipate and mitigate failure and unintended escalation.

Critical Elements of a Risk Framework

A common IC AI risk framework should inform and help prioritize decisions from acquisition or development, to deployment, to performance in a consistent way across the IC. To start, the IC should create common AI risk management principles, like its existing principles of transparency and AI ethics, that include clear and consistent definitions, thresholds, and standards. These principles should drive a repeatable risk assessment process that each IC element can tailor to its individual needs, and should promote policy, governance, and technological approaches that are aligned to risk management.

The successful implementation of this risk framework requires a multi-disciplinary approach involving leaders from across the organization, experts from all relevant functional areas, and managers who can ensure vigilance in implementation. A whole-of-activity methodology that includes technologists, collectors, analysts, innovators, security officers, acquisition officers, lawyers and more, is critical to ensuring a full 360-degree understanding of the opportunities, issues, risks, and potential consequences associated with a particular action, and to enabling the best-informed decision.

Given the many players involved, each IC element must strengthen internal processes to manage the potential disconnects that can lead to unintended risks and to create a culture that instills in every officer a responsibility to proactively consider risk at each stage of the activity. Internal governance should include an interdisciplinary Risk Management Council (RMC) made up of senior leaders from across the organization. The RMC should establish clear and consistent thresholds for when a risk assessment is required, recommended, or not needed given that resource constraints likely will not allow all of the broad and diverse AI activities within organizations to be assessed. These thresholds should be consistent with the IC risk management principles so that as IC elements work together on projects across the community, officers have similar understandings and expectations.

The risk framework itself should provide a common taxonomy and process to:

  • Understand and identify potential failures, including the source, timeline, and range of effects.
  • Analyze failures and risks by identifying internal vulnerabilities or predisposing conditions that could increase the likelihood of adverse impact.
  • Evaluate the likelihood of failure, taking into consideration risks and vulnerabilities.
  • Assess the severity of the potential impact, to include potential harm to organizational operations, assets, individuals, other organizations, or the nation.
  • Consider whether the ultimate risk may be sufficiently mitigated or whether it should be transferred, avoided, or accepted.

AI-related risks may include, among other things, technology failure, biased data, adversarial attacks, supply chain compromises, human error, cost overruns, legal compliance challenges, or oversight issues.

An initial risk level is determined by considering the likelihood of a failure against the severity of the potential impact. For example, is there is a low, moderate, or high likelihood of supply chain compromise? Would such a compromise affect only one discrete system or are there system-wide implications? These calculations will result in an initial risk level. Then potential mitigation measures, such as additional policies, training, or security measures, are applied to lower the initial risk level to an adjusted risk level. For example, physically or logically segmenting an organization’s systems so that a compromise only touches one system would significantly decrease the risk level associated with that particular technology. The higher the likelihood of supply chain compromise, the lower the severity of its impact must be to offset the risk, and vice versa. Organizations should apply the Swiss Cheese Model of more than one preventative or mitigative action for a more effective layered defense. Organizations then must consider the adjusted risk level in relation to their tolerance for risk; how much risk (and potential consequence) is acceptable in pursuit of value? This requires defining the IC’s risk tolerance levels, within which IC elements may again define their own levels based upon their unique missions.

Understanding and considering the risk of action is an important step forward for the IC, but it is not the last step. Sometimes overlooked in risk assessment practices is the consideration of the risk of inaction. To fully evaluate potential options, decision-makers must consider whether the overall risk of doing something is outweighed by the risks of not doing it. If the IC does not pursue particular AI capabilities, what is the opportunity cost of that inaction? Any final determination about whether to take action must consider whether declining to act would cause greater risk of significant harm. While the answer will not always be yes, in the case of AI and emerging technology, it is a very realistic possibility.

And, finally, a risk framework only works if people know about it. Broad communication – about the existence of the framework, how to apply it, and expectations for doing so – is vital. We cannot hold people accountable for appropriately managing risk if we do not clearly and consistently communicate and help people use the structure and mechanisms for doing so.

Buy-in To Enhance Confidence

An IC-wide AI risk framework will help IC officers understand risks and determine when and how to take advantage of innovative emerging technologies like AI, increasing comfort with uncertainty and risk-taking in the pursuit of new capabilities. Such a risk framework will have even greater impact if it is accepted – explicitly or implicitly – by the IC’s congressional overseers. The final article in this series will delve more deeply into needed changes to further improve the crucial relationship between the IC and its congressional overseers. It will also provide a link to a full report that provides more detail on each aspect of the series, including a draft IC AI Risk Framework.

Although Congress is not formally bound by such a framework, given the significant accountability measures that often flow from these overseers, a meeting of the minds between the IC and its congressional overseers is critical. Indeed, these overseers should have awareness of and an informal ability to provide feedback into the framework as it is being developed. This level of transparency and partnership would lead to at least two important benefits: first, increased confidence in the framework by all; and second, better insight into IC decision-making for IC overseers.

Ultimately, such a mutual understanding would encourage exactly what the IC needs to truly take advantage of next-generation technology like AI: a culture of experimentation, innovation, and creativity that sees reasonable risk and failure as necessary steps to game-changing outcomes.

Read also AI and the IC: The Tangled Web of Budget and Acquisition

Read also Artificial Intelligence in the IC: Culture is Critical

Read also AI and the IC: The Challenges Ahead

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post A Roadmap for AI in the IC appeared first on The Cipher Brief.

find more fun & mates at SoShow now !

Some voters in Germany’s capital, Berlin, may have to re-cast their ballots after the country’s federal election czar filed an official complaint over irregularities in a parliamentary vote held two months ago.

The election – which saw Berliners decide the makeup of the German parliament, the Bundestag, as well as select city representatives – was marred by irregularities at numerous polling stations, according to the official, Georg Thiel. 

Among the most common problems were ballot shortages and long lines, with waiting times of up to two hours. In some cases, voters were also seen casting their ballots past a 6pm cutoff – the time when all polling stations were supposed to have closed. Thiel, who was tasked with overseeing elections at federal level, saw all of the above as reason enough to raise an objection in the German capital, local media reported on Friday.

Read more

Workers remove a campaign poster showing Armin Laschet, the Christian Democratic Union’s candidate for chancellor, in Bad Segeberg, Germany, September 27, 2021. © Fabian Bimmer / Reuters
Conservative wing of Merkel’s bloc says party leadership must resign after ‘debacle’ in Germany’s general election

Thiel identified six Berlin constituencies where irregularities were allegedly rampant, potentially setting the stage for a re-do election in the city.  

It is now up to a special Bundestag committee to examine Thiel’s complaint and see if the reported violations ran afoul of German law or electoral procedures. For the vote to be repeated, however, at least one of those violations would have to be deemed serious enough to have affected the distribution of seats in the Bundestag.

The September 26 election saw outgoing Chancellor Angela Merkel’s conservatives take a historic beating, with the Social Democrats coming out on top. The Social Democratic Party (SPD) has been engaged in coalition talks with the Greens and the Free Democratic Party ever since, with the trio expected to announce a preliminary deal as early as next week.

Think your friends would be interested? Share this story!

find more fun & mates at SoShow now !