Wednesday, January 26, 2022

How Iran is Winning, One Attack at a Time

EXPERT PERSPECTIVE — This week, U.S. Central Command (CENTCOM) issued a statement confirming that “U.S. forces at Al Dhafra Air Base, near Abu Dhabi in the United Arab Emirates (UAE), engaged two inbound missile threats with multiple Patriot interceptors coincident to efforts by the armed forces of the UAE in the early morning hours of Jan. 24, 2022. The combined efforts successfully prevented both missiles from impacting the base. There were no U.S. casualties.”

A few weeks before that, military bases in Iraq and Syria that house U.S. troops also were attacked. In December of last year, the U.S. embassy in Baghdad was hit when two rockets landed in the Green Zone. Luckily, like the Jan. 24 Houthi attack on the UAE, there were no U.S. casualties (though the Houthi strike of Jan. 17 did kill two Indian nationals and one Pakistani).

What these attacks and many others in the region have in common is Iran’s irrefutable involvement. They may have different local contexts and their perpetrators, all loyal to Iran, may have different motivations, but every single one of those attacks was possible only because Iran provided either the weapons or the know-how to assemble and use them.

This network of Iranian proxies in Iraq, Syria, Yemen, Lebanon, Bahrain, and possibly elsewhere is what makes Tehran so deadly in the region. It’s a clever method of power projection, honed over decades, because it allows the Iranians to weaken their adversaries and achieve their strategic aims with the fewest costs possible. Iran will fight to the last Iraqi, Syrian, Yemeni, Lebanese, and Bahraini. 

The Iranians have every intention of continuing to rely on their indirect approach because it has paid strategic dividends. Their hope is that we will continue to play their game and go after only their proxies whenever we are attacked. In the case of the Houthis, for example, Tehran expects us and our regional partners to hit the Houthis — and only the Houthis — every time they lob missiles at Al Dhafra. And in many ways, that’s exactly what we’ve been doing. In January 2020, we did eliminate Iran’s top military commander and architect of this proxy network, Gen. Qassem Soleimani, but we were careful to do it in the region, not on Iranian soil.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today

Join us on Wednesday, February 2 for a briefing on U.S. business opportunities in the Middle East with Cipher Brief Expert Vice Admiral Kevin Donegan (Ret.)


U.S. kinetic strikes on Iranian proxies, while necessary, clearly are insufficient. Simply put, there are more militias under Iran’s command in the region than there are American bombs. To reestablish deterrence against Iran, we have to place our tactical/operational activities, at which we’re incredibly effective, at the service of a broader strategy. We need to make it clear to the Iranians that their asymmetric playbook, especially when it targets U.S. personnel and interests, has a steep price. 

We’ve communicated those red lines before, and successfully so. In Iraq, we held Iran accountable for the attacks its Iraqi proxies often perpetrated against our troops using improvised rocket-assisted munitions (IRAMs) and explosively formed penetrators (EFPs). Those tools killed at least 196 American soldiers and wounded nearly 900 between 2005 and 2011. 

But now, it’s not IRAMs and EFPs that Iran is providing, it’s ballistic missiles, cruise missiles, and weaponized unmanned aerial systems (UASs). Those are much more powerful weapons of war that could cause considerable physical damage to cities and critical infrastructure and kill a lot of people. 

We have to nip this Iranian tactic in the bud before things really escalate — or next time we might not be so lucky and those missiles could lead to significant casualties. This is not just about defending our partners, as crucial as that responsibility is. This is about protecting our own military and diplomatic personnel in the region, as well as our core interests in that still vital part of the world to global commerce and international security.

It’s never an easy conversation when we discuss any potential use of force. But we’re under attack, quite literally and regularly, and nuclear diplomacy alone, no matter what happens in the talks in Vienna, will not fix or effectively manage this growing problem. We have every right to defend ourselves and our collective security interests. 

From an operational standpoint, this requires consulting our carefully crafted Iran target list. We don’t need to specify to the Iranians what we would hit inside Iran, or how, if they attack us again, but it’s vital that we communicate that threat credibly. The worst thing we could possibly do is issue that threat but fail to follow through. Our credibility in the region has already been jeopardized over the years because of the lack of U.S. response to various acts of aggression and intimidation by Iran. Let’s at least not further weaken it and ideally bolster it partly through the measures described above.

In addition to sending a crystal-clear message to Tehran about the consequences of another potential attack (this is the deterrence-by-punishment element), we need to upgrade our defenses (this is the deterrence-by-denial element). We can do that by establishing a fusion cell based on the Houthi missile and UAS threat to provide Gulf Arab partners intelligence of activities that are a precursor to future attacks along with a real-time warning of the launch of those attacks.

We currently have a fusion cell with the Emiratis, but it is focused on al-Qaeda and the Islamic State, not the Houthis. Creating this cell will require U.S. resources, but nothing we cannot afford or that would distract from security priorities in other key theaters. Such resources could include two or three Predator tails and other national intelligence assets that would provide persistent, high-quality intelligence and warning of planned or impending attacks on U.S. personnel and bases or on those of our Saudi and Emirati partners.

More broadly speaking, while immediate tactical solutions to help our regional partners deal with Houthi attacks are required, only the United States can create the kind of sophisticated regional enterprise, both military and non-military, necessary to confront the rapidly growing power of Iranian proxies across the region, including the Houthis. The question is whether Washington has the political appetite to do any of this.

There are American voices who might call such potential U.S. responses escalatory, even reckless. While there’s always risk in any U.S. response that could include the use of force, the risk of inaction is far greater because it will invite further Iranian aggression, at which point it would be virtually impossible for the United States not to strike the Iranians hard and deep.

It is precisely such a scenario we should try to prevent, and it all starts with reestablishing deterrence. Most important of all in this equation — something more risk-averse advocates should never forget — is that Iran is the aggressor and it still has a say over what we choose to do. It can decide to stop its strategic weapons shipments to its proxies and deescalate, or it can continue with its vastly irresponsible approach but suffer the consequences.

This piece was first published by the Washington-based think tank MEI

Join The Cyber Initiatives Group for the first Summit of 2022 with Principal’s including General Keith Alexander, The Hon. Susan Gordon, Dmitri Alperovitch, General David Petraeus, founding CISA Director Chris Krebs and more. Registration is free for this February 9th virtual event. Come prepared to think differently.  Reserve your seat today.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post How Iran is Winning, One Attack at a Time appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3nVmtAb
via IFTTT

Sunday, January 23, 2022

Putin’s Risky Options in Ukraine

EXPERT PERSPECTIVE — It is still more probable than not that Russian President Vladimir Putin will employ military force in the coming weeks. He is not going to obtain sufficient diplomatic concessions from the United States and NATO. He cannot keep his large army mobilised in mid-winter indefinitely and he may wish to seize the moment when the West looks weak and divided after the Afghan fiasco. And with an energy crisis in Europe, Putin may calculate that the European appetite for harsh sanctions against Moscow will diminish when the implications for gas supplies becomes obvious.

The Russian President’s primary objective seems to be to return Ukraine to the Russian sphere of influence or, failing that, to reduce its viability as a threat to Russia.

Putin’s dream option would be a variation on recent Kazakh events. Local disturbances in Kiev would lead to a request from “patriotic forces” for Russia’s assistance. In the absence of a Tokayev figure, the Russians would have to persuade someone senior in Kiev to issue the request; a union leader, oligarch or even a cabinet minister. That should not be beyond the capabilities of the local GRU and SVR Residents to arrange. In his dreams, Putin’s troops would then enter peacefully badged as CSTO “peacekeepers”. In reality, he must know they would have to fight their way in.

The Northern Option

Thanks to “joint exercises” with Belarus, Russia now has forces just 240 miles due north of Kiev. This provides the option of a quick dash to the Ukrainian capital to remove the Zelensky government and install a pro-Kremlin candidate. Such an operation would be reminiscent of the successful invasion of Afghanistan at Christmas 1979, when Soviet troops took Kabul within 3 days and installed Babrak Kamal as president. The operation involved 25,000 troops and 280 transport aircraft and went like clockwork.

Such a dash to Kiev might be possible. Most of Ukraine’s hardened troops are deployed in the east of the country. The Russians would soon establish complete air dominance. However, Kiev is not Kabul. It is a large modern city and the Ukrainians might well fight for it street by street. The Zelensky government is less popular than it once was but it is unlikely to crumble. Even if a puppet regime could be installed, what then?

Russia might be able to pacify much of the area east of the Dnieper but in Kiev itself and to the west, there is a good chance of popular resistance. Ukraine could be split in two and any Russian short-term success might develop into a longer-term nightmare.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today.


Putin’s Lesser Options

There is a plethora of lesser options along Ukraine’s eastern border. Russia could easily make incursions to carve out additional pieces of territory. One possibility would be the industrial city of Kharkiv. The problem is that the gains would be too insubstantial for all the political risk that Putin has taken in recent weeks. It would not fundamentally change Ukraine’s economic or political viability as a country and could actually increase its determination to join the European Union and NATO.

However, the seizure of Odessa could be a game-changer. It is Ukraine’s third largest city with a population of over one million and includes a vital seaport. The port handles the vast majority of Ukraine’s maritime cargo and serves as headquarters for Ukraine’s navy. Much of its population is Russian speaking. However, it would be a demanding overland operation using the forces massed at Rostov-on-Don and in the Crimea, whilst also using air-power and naval and amphibious forces.

Rostov-on-Don to Odessa is 500 miles. It could take several days of fighting and is not without risk but once Russia had established aerial superiority, it should be manageable. Only a hundred more miles beyond Odessa would provide Russia with a land route to Moldova which Putin also sees as part of his sphere of influence.


Listen to The Cipher Brief’s Open Source Report Podcast – a weekday open source collection of the stories impacting national security with your hosts Brad Christian and Suzanne Kelly.  Subscribe wherever you listen to podcasts.


The loss of its ports on the Sea of Azov and the Black Sea would be a crushing blow for Ukraine and would hugely affect the viability of a country that is already struggling economically. It would have the additional benefit of providing Russia with a second land-route to Crimea and a much more substantial one than the bridge over the Kerch Strait which was completed in 2019, five years after the annexation of Crimea. But the long strip of occupied territory from Rostov to Moldova would not be easy to defend from future Ukrainian counterattacks.

Putin’s Politically Risky Options

Finally, Putin has two options which are politically much riskier because they would directly challenge NATO members’ territory and, in the former case, might result in killing NATO troops. One would be to seize the Suwalki Gap between Belarus and the Russian enclave of Kaliningrad. This would mean annexing a small piece of either Poland or Lithuania. The other would be to carve out a town from one of the three Baltic States. The obvious contender would be Narva in Estonia which has a Russian-speaking majority. To the Western way of thinking, this would be needlessly provocative but Putin could be attracted for that very reason. It would also test whether the West is truly willing to fight for a small slice of territory belonging to one of its members. And Putin will not want to stand down his troops without some tangible gain.

Read more expert-driven national security perspectives, insights and analysis in The Cipher Brief

The post Putin’s Risky Options in Ukraine appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3fNbpka
via IFTTT

Monday, January 17, 2022

Anticipating Russia’s Next Move in Ukraine

“The Cipher Brief has become the most popular outlet for former intelligence officers; no media outlet is even a close second to The Cipher Brief in terms of the number of articles published by formers.” – Sept. 2018, Studies in Intelligence, Vol. 62 No.

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .  

 

 

The post Anticipating Russia’s Next Move in Ukraine appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3Kj9EsZ
via IFTTT

Tuesday, January 4, 2022

The Value of a Well-Placed Spy in Moscow

EXPERT PERSPECTIVE — “I hope CIA has an agent like Dmitry Polyakov operating in Moscow right now,” writes Cipher Brief Expert and former Deputy Director of Counterintelligence at CIA, Mark Kelton.    

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .      

The post The Value of a Well-Placed Spy in Moscow appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3sYgL3U
via IFTTT

Tuesday, December 14, 2021

The Afghan Debacle Should Prompt China to Revise its South Asian Policy

This piece was first published by RUSI in London.  The views do not represent those of RUSI.

EXPERT PERSPECTIVE — While China has tried to rebalance its relations between India and Pakistan before, recent developments in Afghanistan should give it fresh impetus to do so.  Any future Cold War between the United States and China would be entirely different to the previous version for several reasons of which the most obvious is the economic and financial inter-dependency between the two countries. However, one similarity could survive in the form of proxy conflicts such as those seen in Angola, Afghanistan and Nicaragua in the 1980s.

A proxy conflict in South Asia would be extremely dangerous both because of the numerous geopolitical fissures which opposing sides would seek to exploit and the fact that India and Pakistan now have nuclear weapons and the means of delivery. In the previous Cold War neither New Delhi nor Islamabad had credibly deployable nuclear weapons and, although India leant clearly towards the Soviet Union and Pakistan towards the West, there was no proxy war in the Subcontinent, only further north-west in Afghanistan.

Relations between India and Pakistan are already dangerous enough without being drawn into a new Cold War. The Balakot episode of 2019 took both countries to the brink of war and was de-escalated more through luck than good judgement. Since then, China has become an active participant through its hostile operations along its disputed border with India in the Himalayas and, most recently, by appearing to endorse Pakistan’s preference for a Taliban-only government in Afghanistan.

I am told confidentially that China did question the wisdom of Pakistan’s judgement in August just as the Ashraf Ghani government collapsed but, crucially, it did not press the point. Beijing may have calculated that the Pakistan army could not have forced the Taliban to form an inclusive administration and that the influential Corps Commanders in Pakistan might even have resisted Chinese pressure at such a seminal moment.

Following the US withdrawal, Beijing will surely now recognise that it needs its own policy on Afghanistan; it can no longer outsource decisions to Pakistan. There is too much at stake including the threat from Uighur militants, Chinese investments in the mining sector and possible future Belt and Road Initiative (BRI) projects.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Beijing will also know that the Indian government is infuriated by its loss of agency in Afghanistan after 20 years of political and economic investment there. Following what looks (at first sight) like a stunning victory for Pakistan, India will inevitably wish to make Islamabad pay a price. New Delhi is not short of options. It will doubtless see opportunities in the growing dissent in Baluchistan (and Gwadar in particular) against the BRI, and in the increasing disenchantment amongst Pashtuns in Khyber Pakhtunkhwa (formerly North West Frontier Province) and in the huge port-city of Karachi where Pashtuns represent some 20% of the population. India will also push its maximalist position on Kashmir by which Gilgit-Baltistan (through which several BRI projects traverse) is claimed as part of India.

China may also reflect on the cost/benefit of its activity along India’s northern border. In the long run China has much to lose by stirring up a region which offers India (and potentially the United States) a direct route via the Aksai Chin into China’s two least contented regions; Tibet and Xinjiang. It could be argued that, in the new era of hybrid warfare and imaginative cyber operations, direct access to a territory is less essential for a campaign of disruption. Possibly.  But China would be wise not to throw stones in such an extensively glazed region.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


All of this argues for China to review its South Asia strategy with a view to a degree of rebalancing between India and Pakistan. The continuation of existing policy will see Afghanistan decline back to its pre-2001 status as an economic and social wasteland. It could witness Pakistan increasingly undermined by radical Islamist groups operating from Afghanistan, the tribal borderlands and inside the cities of the Punjab and Sind. It will see a frustrated India taking ever less flexible positions on regional issues and on Chinese access to its huge markets. And access to Himalayan waters will become the dominant theme in the region.

It is often forgotten that China attempted to rebalance its relations between India and Pakistan in 1996 in a remarkable speech delivered on 2nd December by President Jiang Zemin in Islamabad.  After a number of standard paragraphs about the “profound friendship” between China and Pakistan, Jiang then turned to the importance of ‘South Asia’ to Beijing and then, to an increasingly appalled audience, began praising the “the multi-dimensional exchanges and cooperation between China and the various South Asian countries”. The name of India never passed his lips but it was clear to all that China intended to rebalance its Indian and Pakistani relationships.

To grasp the ambition behind the speech two passages are worth repeating; “China and South Asian countries are all members of the developing world dedicated… to developing their economies and improving their peoples’ livelihood. They all need a peaceful and stable international environment and, particularly, a favourable surrounding environment.”

And “China will, as always, support South Asian regional cooperation, support the proposal and initiative for the establishment of South Asia Nuclear Free Zone and Indian Ocean Zone of Peace, and support all efforts designed to serve peace, stability and development in the South Asian region.”

The Indian nuclear tests just 18 months later killed the rebalancing in its infancy but the sentiments are arguably truer today than in 1996. If Pakistan and Afghanistan are to survive they need to open their borders with India and become transit routes to Central Asia. Now that the US has departed the stage only China can facilitate such ambitions. The alternative is more terrorism and instability in an area where there are far too many nuclear weapons. Even without a new Cold War Beijing’s current course is too dangerous.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Afghan Debacle Should Prompt China to Revise its South Asian Policy appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3IRJsor
via IFTTT

Monday, December 13, 2021

The Supply Chain is the Perfect Asymmetric Target

Robert Hannigan is a Principal Member of The Cyber Initiatives Group, powered by The Cipher Brief.

EXPERT PERSPECTIVE — Asked recently what risk he worried about most, alongside Taiwan and Ukraine, Cipher Brief Expert, General Stanley McChrystal said it was cyber security, particularly in the supply chain.

General McChrystal is part of a growing group of the most senior operational and strategic US commanders that include former Chairman of the Joint Chiefs of Staff, Admiral Mike Mullen, in seeing the supply chain threat as existential. Unless the supply chain can be secured, the whole infrastructure on which Western economies rest, not to mention their military defences, will be compromised.

Two factors have brought the otherwise dry subject of supply chain security to the top of the political risk table. One has been the pandemic, in which we have become painfully aware of the fragility of supply chains and the over-dependence of Western countries on external providers, particularly in China. We have also realised how little we actually understand about our supply chains: which companies are in them, who owns them, who controls them and how they can be disrupted.

The other factor has been the SolarWinds attack, almost exactly a year ago. The sophistication of this compromise of the software supply chain, which had probably been active for at least a year before it was discovered, captured headlines around the world. This was partly because SolarWinds Orion was in use by a whole range of government agencies and major companies. More acutely than many other earlier third-party compromises, it illustrated why supply chain companies are such attractive targets: their security is often poor and they represent a softer way into a vast range of customers, including many companies that would in themselves be a hard target. The supply chain is the perfect asymmetric attack.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Interest in this is leading to some positive focus.

There are two challenges. The first is visibility. Governments and companies need to understand what the security of their tens of thousands of vendors looks like in real time. That means having the same attitude to the ecosytem of third parties as they would to their own networks. It also means understanding ownership and control and a range of other dependencies. It requires constant monitoring of the supply chain, not occasional compliance exercises. In the end, this will probably need to be required by regulation, but there is no need to wait for that.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Beyond visibility and understanding there needs to be action. We have to move from assessing the risk and admiring the problem to fixing it. This means taking a range of actions from helping vendors to remediate weaknesses to addressing issues of ownership. The UK’s new legislation giving government greater powers to intervene in mergers and acquisitions on national security grounds is long overdue and brings it into line with other Western countries. But these assessment processes will need to become dynamic and constant to reflect the ever-shifting nature of modern vendor ecosystems.

The complexity of the global supply chain is the creation of open economies and democratic societies; but unless it is secured it will ultimately undermine them.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Supply Chain is the Perfect Asymmetric Target appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3DKkSSM
via IFTTT

Tuesday, December 7, 2021

The Urgency of the Moment for Congress on AI and National Security

(Editor’s Note: This article is the fifth and final article in a series first published by our friends at Just Security that is dives into the foundational barriers to the broad integration of AI in the IC – culture, budget, acquisition, risk, and oversight. This article considers a modified approach to congressional oversight of the IC. The author’s full report examining all of the topics in this series in greater depth is available here.)

Throughout this series, I have explored the most pressing foundational issues impacting the Intelligence Community’s (IC) ability to meet the urgency of this moment in the global artificial intelligence (AI) race. The current bipartisan support for taking bold action to drive national security use of AI is key to the IC’s success. That support must propel change in the priority areas I have already identified: modernizing the IC’s budget and acquisition processes and enabling a risk-tolerant culture with a new IC AI risk assessment framework that helps IC officers navigate the uncertainty that necessarily accompanies technological innovation. There is one other area, however, that cannot be ignored if the IC is to keep pace with our nation’s adversaries and provide policymakers with accurate, timely, and impactful insights: congressional oversight.

Congressional oversight of the IC is critical. Congress is the eyes and the ears of the American people. Among other things, it is charged with evaluating IC program performance, and ensuring the IC is efficiently and effectively spending taxpayer dollars and properly executing national security activities consistent with statutory requirements and legislative intent.

But intelligence oversight is complicated and has not sufficiently evolved with the times. When it comes to assessing progress of IC programs, standard oversight processes typically track defined, pre-determined requirements, cost, and timelines. These metrics have worked reasonably well for large programs like the acquisition of satellites and buildings, for which there is a clear beginning, middle, and end, with easily identifiable milestones and a definite budget. However, AI is different; its development moves back and forth across a spectrum of activities often without discrete steps, and failure is a necessary part of the process as the technology evolves and matures. Traditional metrics are, therefore, less effective for AI, as the value (or lack thereof) of certain milestones may only become clear partway through the development process and desired end-states may shift.

The IC has four primary congressional oversight committees. In addition to the House Permanent Select Committee on Intelligence (HPSCI) and the Senate Select Committee on Intelligence (SSCI), which have oversight jurisdiction over the IC, the House Appropriations Committee Defense Subcommittee (HAC-D) and the Senate Appropriations Committee Defense Subcommittee (SAC-D) provide the IC’s money. These four committees (hereinafter collectively “Committees”) must consider a more adaptive approach to oversight, measuring progress and failure through metrics that are less rigid and better tailored for AI and other emerging technologies. In doing so, the Committees may lose a measure of certainty that impacts their most powerful lever – fiscal control over the IC. For that reason, the Committees and the IC must simultaneously build a greater degree of trust, transparency, and ultimately partnership.

Adaptive Oversight

Much like AI itself, congressional oversight of AI activities must evolve and adapt to the world of emerging technology. While there are a variety of rules that govern Congress’ oversight responsibilities, Congress has considerable latitude and discretion in the execution of that oversight, including how they measure executive branch progress. To improve IC oversight engagements, Congress and the IC must start with a shared strategic vision for what a successful AI project looks like and create an approach to oversight that is tailored to achieve this goal.

Current measures and metrics often focus on ensuring projects stay on track in terms of cost and schedule; there are well-defined outputs, such as number of tools built, and static timelines for delivery. Such demonstrable deliverables are objective, consistent, and easy to measure, but they are ill-suited to AI, the underlying technology for which is still evolving. To take full advantage of AI’s emerging possibilities, the IC must have the ability to test, adjust, and pivot as new algorithms and capabilities are developed and applied to different problem sets.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Recognizing that detailed requirements and program schedules are not well-suited to measuring the success of software, which is the core of AI, the Defense Department is already considering changes to related oversight. Research by Google and others indicates that metrics aligned with DevSecOps, the industry best practice for rapid, secure software development, can better predict the performance of software teams. DevSecOps seeks to unify software development (Dev), security (Sec), and operations (Ops). Its metrics allow teams to focus on outcomes while adjusting for multi-dimensional, dynamic, and continuous improvement in technology along the way. Teams can move quickly, respond rapidly to user needs, and produce reliable software – all critical when it comes to scaling AI in the IC.

In addition, AI-related metrics must focus on key performance indicators that track the progress of how AI tools evolve rather than on only the final product to both create the opportunity for, and reflect the expectation of, value to the user earlier based on strong communication and feedback loops. Performance evaluation should center on delivery of incremental capabilities, drilling down on speed and functionality together in phases and time-boxing segmented activities, from staffing to new releases to bug-fixes.

The IC and the Committees must learn from industry best practices related to DevSecOps and software, and together develop relevant and adaptive metrics that can be consistently applied but are more aligned with AI’s attributes. This joint process would itself serve as an opportunity for learning and trust building. Once developed, the metrics must continue to drive accountability and demonstrate value, and if timelines slip, the IC must quickly inform the Committees and produce new targets. The IC should expect to use the new metrics first on low-risk activities and ensure the Committees understand the standards and benchmarks the IC is using so they can evaluate programs accordingly.

While pivoting to new metrics is a good start, the IC and the Committees also must remain open to iteration, allowing oversight to change if the initial approach is less than optimal.

Trust, Transparency, and Partnership

There is no dearth of oversight today – each year, there are hundreds of written reports, in-person briefings, phone calls, hearings, and other engagements between congressional overseers and the IC. However, current oversight engagements suggest a lack of confidence and trust in the IC; they are often excessively tactical and focused on execution details that provide neither a strategic perspective on the health of a program nor an understanding of potential long-term opportunities and risks. These engagements drive a continuous cycle of meetings and briefings, requesting deeper levels of detail, in an effort to achieve the desired understanding. Unfortunately, layering detail on top of detail does not produce strategic insight, and this approach is ultimately ineffective – the Committees do not feel sufficiently informed and the IC does not feel sufficiently supported, steering the relationship toward one that is more adversarial than collaborative.

Current oversight processes were not designed to be overly burdensome or act as roadblocks to progress. They were designed to give Congress appropriate insight and confidence that executive branch activities and spending are being carried out efficiently, effectively, and consistently with the law. Unfortunately, the processes have become onerous due to a history of issues that have undermined Congress’ trust and confidence in the IC. The IC must rebuild trust with Congress so overseers can step back from day-to-day operational details and engage with the community at a more appropriate strategic level.

The relationship between a Board of Directors (Board) and a Chief Executive Officer (CEO) in the private sector is a helpful model. The Board has ultimate responsibility for ensuring the organization is appropriately stewarding the resources entrusted to it, while the CEO manages the execution of a company’s day-to-day activities. According to the KPMG Board Leadership Center, the key to a healthy relationship between a Board and the organization it oversees is trust and transparency, where the Board has constructive conversations with the leadership team about significant decisions and issues as well as the opportunity to provide meaningful input before decisions are made, and the leadership team receives valuable feedback. It is not the Board’s role to “see every scrap of paper that the management team sees,” and it should not wade into tactical details of an issue unless the issue is related to strategy or risk.

Of course, the analogy is not perfect, but it can be instructive. The Committees, which are like the IC’s Board, have the responsibility to ensure the IC is appropriately stewarding its resources. In doing so, they also have the responsibility to leverage their knowledge and expertise to provide strategic advice and direction rather than diving into many levels of detail. But, as with the private sector, without the requisite trust and transparency it is difficult for the Committees to operate at the strategic level.

To rebuild trust, the IC and the Committees must fundamentally alter the nature of their interaction, engaging not only in formal ways but also increasingly in informal engagements to better manage expectations and reduce the element of surprise. The IC should seek the Committees’ views on significant activities before final decisions are made and work to incorporate their feedback when possible to build stronger support and buy-in from the Committees. Formal engagements are important, but informal engagements create relationships that lead to true partnerships.

IC Actions

As the IC seeks additional flexibility from the Committees, it should increase trust and transparency through a more informal and open posture with Congress that includes accommodation from deliberative process privilege as needed. This would require a significant cultural shift but, if done carefully, would pay enormous dividends.

Specifically, the DNI should propose two informal, private engagements with the Committees: 1) semi-annual conversations between Committee staff and high-priority AI project leads for conversation and feedback on progress, issues, concerns, and requirements; and 2) periodic IC leadership “coffee catch-ups” with Committee members to better drive the strategic relationship, provide the benefit of each other’s thinking at that moment, and develop a sense of partnership. These engagements should not track metrics or seek to accomplish specific tasks, but rather should create mutual understanding, open dialogue, and build trust around AI activities. AI project leads should share what is known and unknown about projects, potential outcomes, and any changes in spending the Committees may see in the coming months. The IC leadership coffees would, of course, produce benefits well beyond the IC’s AI activities.

It is unlikely that the information shared in these engagements would implicate the executive branch’s deliberative process privilege, which reflects the president’s constitutional authority to withhold certain information from Congress before a final decision has been made within the executive branch, because these discussions would not be tied to specific decision points. Nevertheless, to help navigate these conversations the DNI should clearly set expectations with the Committees that these conversations are not formal notifications and must not be used to later reprimand the IC. The DNI should also create IC legislative engagement principles to help IC officers appropriately engage. To the extent the IC does seek pre-decisional views from the Committees, the IC should look to the accommodation process, which allows the executive branch to provide information that might otherwise be privileged if necessary to facilitate the legitimate needs of the legislative branch.

Leaning forward in this way does come with risk that the Committees will inappropriately interfere in executive branch matters. Therefore, to truly build trust, the Committees must agree to be judicious in these engagements, focus on insightful strategic and risk-based questions reflective of their extensive experience and expertise, and not misuse the information to obstruct the executive branch’s authority to execute the law. Any actions to the contrary will undermine the progress made and likely end this more open dialogue. However, with agreed upon guidelines and parameters, these informal engagements would improve the AI dialogue between the IC and Congress, leading to deeper Committee understanding and, ideally, strengthening Committee support for legislation and funding of AI activities, even in times of loss or failure.

Committee Actions

As the Committees introduce more agility into their processes and adjust their oversight to accommodate AI, they should consider the following steps to increase their confidence in the IC’s activities.

First, to expand their capacity and institutional expertise, the Committees should re-organize staff along functional lines, as has already been done in some committees. Such a change would allow staff to develop a deeper understanding of various AI tools and technologies, apply that understanding strategically across IC elements, and get a more holistic cross-IC view of AI coordination and activities. While the more common model of organizing staff by IC element makes logical sense, expecting staff to understand everything an IC element does is unrealistic and unreasonable, especially given they are often single-threaded in their roles. Refocusing staff on specific functional areas and allowing them to become experts would greatly benefit not only the Committees’ oversight of those activities, but the IC elements they oversee. In addition, as many have recommended, Congress should recreate the Office of Technology Assessment – a congressional agency that provided impartial analyses of technology and science issues – to provide the Committees with access to deep technical experts when needed.

Second, the Committees should hold formal semi-annual closed substantive briefings on high-priority AI projects. In these briefings, the IC should provide enough detail for the Committees to understand progress against the new metrics and ask questions about the strategic direction of the programs, areas of risk, concerns, unexpected issues, and future legislative and funding requirements. These briefings would provide an official mechanism for the IC to show forward movement and elevate significant issues, and for the Committees to track high-priority AI activities across the IC.

Third, if the IC receives no-year or multi-year funding for AI, the Committees should hold a focused annual review of AI spending during the previous year. This review should include an understanding of what is going well and what did not go as expected so the Committees can provide a timely and critical check on the use of that money. If the funding has been executed in accordance with congressional direction – even if some of the activities have failed – the money should continue to flow. If the funding has not been executed properly or consistently with congressional direction, the Committees should have the ability to stop the funding immediately.

Conclusion

The executive branch has significant work to do to speed and scale AI into the IC: it must reform budget and acquisition processes; create an IC AI risk assessment framework to encourage reasonable and informed risk-taking; and build an IC culture that supports innovation and accepts a level of failure. But the IC’s success will be hard-fought and fleeting if the IC’s congressional oversight committees do not simultaneously re-examine their supervision of the IC.

The Committees, similar to a corporate board, provide an important check on the IC’s activities. To be successful in this new world of AI and emerging technology, the Committees must embrace a strategic reset, increased flexibility, and an adaptive approach to oversight. In return, the IC must lean forward with open and informal dialogue with the Committees. These adjustments will take practice to get right but, if successful, will dramatically change the IC’s partnership with the Committees for the better, providing the Committees with earlier and improved insights and leading to greater support and backing for the IC.

The issues highlighted in this series are not new; countless others have raised them and good people have worked hard to solve them over many years. We cannot wait any longer for implementation to take hold. China and other adversaries are at our doorstep, and the IC must move immediately to embrace the reality of a world awash in data moving at the speed of emerging technology. Now is the time to take advantage of the groundswell of support, remove unnecessary bureaucratic barriers, and take decisive action.

Additional detail and implementation steps in all of the areas discussed in this series can be found in The Integration of Artificial Intelligence in the Intelligence Community: Necessary Steps to Scale Efforts and Speed Progress, a full-length report produced through the American University Washington College of Law Tech, Law & Security program.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post The Urgency of the Moment for Congress on AI and National Security appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3GqDBoj
via IFTTT

https://pieces-auto-maroc1.blogspot.com/

 https://pieces-auto-maroc1.blogspot.com/