The rise of artificial intelligence is reshaping one of the most sensitive roles of any state: ensuring security. Today, the state’s ability to produce knowledge about threats, understand the intentions of adversaries, and anticipate events is undergoing a radical transformation. Companies such as OpenAI, Anthropic, Google, Microsoft, Amazon, and Palantir sell tools to governments, armed forces, and intelligence agencies. Although outsourcing is not new, the change lies in these firms beginning to take on parts of the intelligence cycle itself. Now their tools can intervene in tasks such as gathering clues, processing enormous amounts of information, identifying suspicious behaviors, linking people and organizations, attributing operations, and even adopting countermeasures.
“OpenAI, Anthropic, Google, Microsoft, Amazon or Palantir begin to assume parts of the intelligence cycle”
These AI companies will not formally replace intelligence services. The main reason is simply that they do not possess their legal faculties. But they also lack their networks of human sources and their legitimacy as institutions. Instead, OpenAI and the other firms can progressively concentrate in private hands an ever more important capacity: to transform large quantities of information into useful knowledge — that is, to process and interpret it to produce answers and guide decisions. Europe must ensure that reliance on these technologies does not end up constraining its political autonomy.
Claude as a field of operations
According to a recent threat report from Anthropic, actors connected to governments and organizations in China, Russia, Iran, Mali, and other countries have used Claude for surveillance, espionage, propaganda, the development of military software, and dual-use biological research. In some cases, the AI would have participated in executing and coordinating substantial parts of cyber operations.
Anthropic says it identified operations tied to China and Iran that used Claude to monitor or profile dissidents, journalists, activists, and other public figures. In Mali, it documents a consultant who employed Claude to develop a national surveillance platform for the state intelligence service. The AI did not set the government’s objectives, but it managed to significantly reduce the technical knowledge, personnel, time, and resources required to carry out those plans. Consequently, surveillance capabilities that had been reserved for relatively sophisticated services may come within reach of much more modest state apparatuses.
“Surveillance capabilities that previously belonged to relatively sophisticated services may come within reach of much more modest state apparatuses”
Anthropic also attributes to a group with methods compatible with Midnight Blizzard, linked to Russia, a campaign against Ukrainian government, military, and diplomatic targets. In this regard, Claude would have been used for tasks such as preparing phishing attacks, compromising hotel Wi-Fi connections, attempting to seize WhatsApp accounts, and automatically modifying malicious code when detected by security systems.
There are also cases affecting propaganda. For instance, state media outlets in Russia would have used the model to produce content presented as independent journalism, including fabricated claims about electoral processes. Likewise, queries related to firearms, missiles, armed drones, and explosives originated from China, Russia, and Yemen were detected.
Of all the cases published, the gravest episode concerns biological weapons. Anthropic says it blocked accounts associated with researchers who were attempting to use Claude for work that could facilitate the development of such weapons. One operation reportedly sought help formulating a research proposal on mutations of the chikungunya virus that could increase its danger. The proposed link of the project to a military institution heightened the company’s concern, though it admits that it could not determine whether the ultimate aim was weapon development.
While these are serious matters, some precautions are necessary. These are attributions made by Anthropic based on activity observed on its platform and do not, by themselves, amount to judicial conclusions or official attributions. Even conceding this caution, one cannot ignore the fact that a private company has been able to observe state operations, reconstruct their functioning, geographically attribute them, identify possible responsible actors, expel them from its platform, and, above all, decide what information to share with governments. Anthropic has protected Claude, its product, but has also become a private counterintelligence service.
The privatization of the intelligence cycle
What tasks do intelligence services perform today? From MI6 to the CNI or the CIA, they handle a series of essential duties at the request of governments. They are responsible for setting priorities, gathering information, processing data, formulating hypotheses, assessing threats — if any — and ultimately delivering their conclusions to the relevant decision-makers.
Much of this chain can already be placed in the hands of tech companies. Amazon, Microsoft, and Google provide the cloud infrastructure where vast amounts of information are stored and processed, while Nvidia supplies much of the computing capacity required. From there, firms like Palantir enable the integration and cross-referencing of disparate databases, and the models developed by OpenAI, Anthropic, or Google DeepMind can translate, summarize, relate, and analyze all that information.
“The Administration can continue making decisions and, at the same time, depend more and more on tools it does not control to obtain the information on which it bases those decisions”
The Administration can continue making decisions and, at the same time, depend more and more on tools it does not control to obtain the information on which it bases those decisions. A report might bear a government official’s signature, for example, even though part of the sources used, the relationships detected between them, or the hypotheses proposed come from systems whose operation cannot be fully reviewed.
The cases highlighted by Anthropic raise another issue. When an operation runs inside a private platform, the company holds information about how it operates that the State may later need. Governments and intelligence services thus become dependent on the provider for access to those records. Moreover, it is the company that can decide whether to maintain or suspend access to the tool.
Europe does not need autarky, but its own capacity
The European answer does not lie in excluding American suppliers. It would be unrealistic and likely counterproductive. The United States retains a significant lead in foundational models, advanced computing, and cloud services, and Europe will continue to need to work with its companies, including in security-related domains.
The problem arises when that cooperation creates a dependency that is hard to escape. Europe should be able to use the best available technology without being tied to a single provider in every phase from data collection to political decision.
“Europe should be able to use the best technology available without being tied to a single provider in all phases—from data collection to political decision”
To that end, first determine which parts of that process should be regarded as critical infrastructure. The same issue does not arise for a tool that summarizes administrative documents as for a model used to analyze interceptions, identify people subject to surveillance, or locate possible military targets.
Member states could start from a common classification of the systems used in security, defense, and intelligence. As a tool intervenes more directly in identifying people, in building strategic hypotheses, or in decisions related to the use of force, public control over its operation should be greater. They should also increase the requirements for traceability of its results and the ability of authorities to operate without relying exclusively on the provider.
A European contracting doctrine
Much of this debate will be resolved through public contracts. Technological dependence does not always reveal itself at the moment of purchase, but rather after years of using it. When an organization stores its data, adapts its procedures, and trains its staff around a single platform, switching it can become prohibitively costly. In that moment, the dependence created during the contract facilitates its renewal.
“Technological dependence does not always appear at the moment of buying a tool, but after years of using it”
Therefore, Europe needs specific criteria for contracting AI systems intended for sensitive uses. Agreements should allow data to be moved to another platform, connect the system with technologies from other providers, and keep a record of automated decisions. They should also plan, from the outset, how to exit the service. Recognizing the right to change providers on paper is of little use if doing so later requires reconstructing the entire agency’s technological architecture.
There is another particularly relevant question for intelligence services: what happens to the information generated by the very use of the platform. Contracts should establish where data are processed, who can access them, what records the company keeps, and under what jurisdiction they are stored. Secrecy does not lie only in the documents fed into the system. It can also lie in the questions analysts ask. Knowing which countries, people, organizations, or threats concentrate those inquiries helps reveal a government’s priorities.
In the most sensitive uses, it may be necessary to go further and require that certain models operate on infrastructures controlled by authorities themselves, with isolated environments and mechanisms to maintain service if the relationship with the company ends. Updates should not rely entirely on hardware located outside Europe. State ownership of data does not solve the problem if control over the tools needed to interpret them has been lost.
A shared European capacity
It is unlikely that a single European state can develop and maintain all this infrastructure on its own. Unity is necessary, and part of the solution must be organized at the community level, though that does not imply an immediate creation of a European intelligence service. A first step could be to share technical capabilities among national agencies.
The Union could establish a center dedicated to evaluating models used in areas related to national security and connect it with the European Union Agency for Cybersecurity (ENISA), the EU Satellite Centre, and the EU Intelligence and Situation Centre (EU INTCEN). Before incorporating a model into a sensitive environment, this body could study its vulnerabilities and test its behavior. It would also serve to review updates and share alerts detected by different member states.
“Europe needs means to contrast those attributions and not rely solely on the company’s interpretation”
If a U.S. company detects an operation within its platform, it may have information relevant to what happened before European authorities have access. Europe needs means to contrast those attributions and not depend solely on the company’s interpretation. To do so, it should be able to combine indications provided by the vendor with public and classified information and assess for itself whether there is an operation linked to a state.
That scrutiny would have to apply equally to European products. Strategic autonomy loses meaning if a system is deemed safe merely because it was developed inside the Union. Companies like Mistral, Aleph Alpha, or Helsing can benefit from European investment and contracts, but their tools should undergo controls comparable to those required of their American rivals.
Preserving human judgment
One of artificial intelligence’s advantages is its ability to process volumes of information that no human team could thoroughly review. That same scale, however, can hinder the verification of results. Just because a person appears formally at the end of the process does not mean they can exercise real control over it. And if a system generates thousands of alerts or proposes hundreds of targets, the responsible party may end up validating results without the time or information to reconstruct how they reached them.
“That a person appears formally at the end of the process does not mean they can exercise real control over it”
Hence, an evaluation crafted with AI assistance should allow distinguishing between data drawn from verified sources and conclusions produced by the model. It should also indicate the degree of uncertainty that accompanies those inferences. In especially grave decisions, such as deeming someone a threat, authorizing an operation, or recommending the use of force, the model’s output should not be sufficient on its own.
Additionally, it is prudent to maintain teams capable of operating without those tools. Dependence does not only arise when a technology is missing; it also appears when an organization loses the ability to perform its work without it. An intelligence service that loses its capacity for independent analysis will be more vulnerable to system errors as well as manipulation or disruption of access.
Sovereignty over the capacity to know
The secrecy surrounding these activities should not prevent all forms of democratic oversight. Parliaments do not need access to the operational details of every mission, but they should know which companies participate in intelligence production, what tasks they perform, and what controls apply.
A company may detect an operation within its platform, close an account, or determine what uses its technology allows. Those decisions are part of managing its service. Another matter is determining what constitutes a threat or where national interest lies, decisions whose legitimacy rests in public institutions. Likewise, state secrecy should not be used to cloak opaque tools without any independent evaluation.
Europe can use American models while also developing its own alternatives. Both are compatible as long as it retains enough control over data, over how systems operate, and above all, over the decisions made from them. The room to do so will be smaller the harder it becomes to replace the technologies currently being integrated.
“They can hire technology, but they should not lose the ability to understand the information they use, form their own judgment and be accountable for the decisions they make”
States have always relied on tools developed outside the administration, but never have they delegated so much work as today. They can hire technology, but they should not lose the ability to understand the information they use, form their own judgment, and be accountable for the decisions they make. If a state stops knowing how the intelligence it decides is produced, it may formally retain authority and, in practice, have lost a substantial part of it.