Artificial intelligence is reshaping one of the most delicate responsibilities a state bears: safeguarding security. Today, the ability of the state to generate threat intelligence, interpret the intents of rivals and anticipate events is undergoing a profound transformation. Firms such as OpenAI, Anthropic, Google, Microsoft, Amazon and Palantir are selling their tools to governments, militaries and intelligence agencies. Although outsourcing of this kind is not new, the shift lies in these companies starting to assume portions of the intelligence cycle themselves. Their instruments can now be used to gather indicators, sift through enormous datasets, spot suspicious conduct, map connections between individuals and organisations, attribute operations to actors and even deploy countermeasures.
“OpenAI, Anthropic, Google, Microsoft, Amazon and Palantir are beginning to take on parts of the intelligence cycle itself”
AI firms will not formally replace intelligence services. The principal reason is simply that they lack equivalent legal authority. Nor do they command networks of human sources or the institutional legitimacy that governments rely on. What OpenAI and its peers can do, however, is increasingly concentrate in private hands a capability of growing importance: converting vast troves of data into usable knowledge — that is, processing and interpreting it to generate answers and inform decisions. Europe must shield itself from becoming dependent on these technologies to the point where it jeopardises its political autonomy.
Claude as an operational environment
In a recent threat intelligence report from Anthropic, actors tied to governments and organisations in China, Russia, Iran, Mali and other states have used Claude for surveillance, espionage, propaganda, software development for military purposes and dual‑use biological research. In several instances, AI is said to have helped conduct and coordinate large portions of cyber operations.
Anthropic reports operations linked to China and Iran that employed Claude to monitor or profile dissidents, journalists, activists and other public figures. In Mali, it notes a consultant who used Claude to build a national surveillance platform for the state intelligence service. AI did not decide those governments’ aims, but it greatly lowered the technical know-how, personnel requirements, time and resources needed to execute their plans. Consequently, surveillance capabilities once reserved for comparatively sophisticated intelligence services may become accessible to far more modest government apparatuses.
“Surveillance capabilities once reserved for relatively sophisticated intelligence services may now become available to far more modest state apparatuses”
Anthropic also links to a group employing techniques consistent with Midnight Blizzard, a faction associated with Russia, in a campaign against Ukrainian government, military and diplomatic targets. Claude was reportedly used for tasks such as drafting phishing campaigns, compromising hotel Wi‑Fi networks, attempting to hijack WhatsApp accounts and automatically tweaking malicious code when detected by security systems.
There are also episodes involving propaganda. For instance, Russian state media are said to have used Claude to generate material presented as independent journalism, including fabricated assertions about electoral processes. Queries related to firearms, missiles, armed drones and explosives were also recorded from China, Russia and Yemen.
Among all the cases reported, the most alarming concerns biology and bioweapons. Anthropic says it blocked accounts tied to researchers seeking to use Claude for work that could facilitate the creation of such weapons. One operation allegedly sought help drafting a research proposal on mutations of the chikungunya virus that could enhance its harm. The alleged link of the project to a military institution amplified the company’s concerns, though Anthropic admits it could not determine whether the end aim was to develop a weapon.
Although these are grave matters, some caution is warranted. These are assessments by Anthropic based on activity observed on its platform and do not themselves amount to judicial findings or official attributions. Even with this caveat, one undeniable fact surfaces: a private company has been able to observe state operations, reconstruct how they functioned, geolocate them, identify potential perpetrators, expel them from its platform and, above all, decide what information to share with governments. Anthropic has protected Claude, its product, but in doing so it has also acted as a private counter‑intelligence service.
The privatisation of the intelligence cycle
What exactly do intelligence services do today? From MI6 to Spain’s CNI or the CIA, they perform a spectrum of core tasks at the state’s request. They set priorities, gather intelligence, process data, develop hypotheses, assess threats where they exist and ultimately deliver conclusions to the relevant decision‑makers.
A substantial portion of this chain is already in the hands of tech companies. Amazon, Microsoft and Google provide the cloud infrastructure for storing and processing vast quantities of information, while Nvidia supplies much of the computational capacity required. From there, firms like Palantir can integrate and cross‑reference diverse databases, while models developed by OpenAI, Anthropic or Google DeepMind can translate, summarise, connect and analyse all that data.
“The state may continue to make the decisions while becoming increasingly dependent on tools it does not control to obtain the information on which those decisions are based”
The state may continue to make the decisions while becoming increasingly dependent on tools it does not control to obtain the information on which those decisions are based. A report may bear the mark of a civil servant, for example, even though some of the sources used, the relationships identified between them or the hypotheses proposed may originate from systems whose operation cannot be fully examined.
The cases highlighted by Anthropic raise another issue. When an operation unfolds on a private platform, the company may possess information about how it unfolded that the state may eventually need. Governments and intelligence services then become dependent on the provider to access those records. Additionally, the company itself may decide whether access to the tool is maintained or halted.
Europe does not need autarky, but its own capabilities
Europe’s response should not be to abandon US providers. That would be impractical and likely counterproductive. The United States maintains a sizable lead in foundational models, advanced computing and cloud services, and Europe will continue to rely on its own firms, including in security‑related domains.
The challenge lies in preventing that collaboration from creating a dependency that is hard to break. Europe should be able to access the best available technology without becoming tethered to a single supplier at every stage, from data gathering to policy decisions.
“Europe should be able to use the best technology available without becoming tied to a single provider across every stage, from data collection to political decision-making”
The initial move should be to decide which segments of that process constitute critical infrastructure. An assistant that summarises bureaucratic documents does not present the same issues as a tool used to analyse intercepted communications, identify individuals who may be under surveillance or locate potential military targets.
Member States could start with a unified classification of systems used in security, defence and intelligence. The more directly a tool touches on identifying people, formulating strategic hypotheses or guiding decisions about the use of force, the greater the level of public oversight required over its operation. There should also be stronger requirements for the traceability of outputs and for ensuring that authorities can operate without exclusive reliance on the provider.
A European procurement doctrine
Much of this debate will ultimately be settled through public procurement. Technological dependence is not always evident at the moment of purchase, but it becomes clearer after years of use. Once an organisation stores its data, adjusts its procedures and trains staff around a single platform, switching to another can become prohibitively costly. At that point, the dependency cultivated during the contract increases the likelihood of renewal.
“Technological dependence does not always become apparent when a tool is purchased, but after years of using it”
Europe therefore requires explicit criteria for acquiring artificial intelligence systems intended for sensitive uses. Contracts should allow data to be transferred to another platform, enable the system to connect with technologies supplied by other providers and preserve a record of automated decisions. They should also spell out, from the outset, how the service can be terminated. A contractual right to switch providers is of little value if later efforts to migrate require rebuilding the entire technological backbone of the organisation.
There is another particularly important question for intelligence services: what becomes of the information generated through the use of the platform itself. Contracts should specify where data are processed, who can access them, which logs the company keeps and under which jurisdiction they are stored. The sensitive information does not reside only in the documents uploaded to the system; it can also lie in the questions analysts pose. Knowing which countries, individuals, organisations or threats account for the majority of those queries can reveal a government’s priorities.
For the most sensitive applications, it may be necessary to go further and require certain models to run on infrastructure controlled by the authorities themselves, in isolated environments and with mechanisms ensuring continuity of service if the relationship with the company breaks down. Updates should not depend solely on teams outside Europe either. State ownership of the data does not solve the problem if the state has lost control of the tools needed to interpret them.
A shared European capability
Developing and maintaining all of this infrastructure is a heavy lift for any single European state. Solidarity is essential, and part of the response will need to be organized at the EU level, though that does not imply the immediate creation of a European intelligence service. A first step could be to share technical capabilities among national agencies.
The Union could establish a centre tasked with evaluating models used in national security contexts and connect it with the European Union Agency for Cybersecurity (ENISA), the EU Satellite Centre and the EU Intelligence and Situation Centre (EU INTCEN). Before a model is deployed in a sensitive environment, this body could assess its vulnerabilities and test its behavior. It could also review updates and consolidate warnings identified by different Member States.
“Europe needs the means to verify those attributions independently rather than relying solely on the company’s interpretation”
If a US company detects an operation on its platform, it may possess information about what occurred before European authorities do. Europe needs the means to verify those attributions independently rather than relying solely on the company’s interpretation. To achieve this, it should be able to combine indicators supplied by the vendor with public and classified data and form its own assessment regarding whether an operation is state‑linked.
The same scrutiny should apply to European products as well. Strategic autonomy is compromised if a system is deemed secure simply because it was developed within the Union. Firms like Mistral, Aleph Alpha or Helsing may benefit from European funding and contracts, but their tools should be subjected to controls on par with those imposed on their American rivals.
Preserving human judgement
One of the strengths of artificial intelligence is its capacity to handle vast quantities of information that no human team could review in full. That very scale, however, can complicate the verification of results. The formal presence of a human at the end of the process does not guarantee meaningful control. Similarly, if a system emits thousands of alerts or suggests hundreds of targets, the responsible person may end up approving outputs without sufficient time or data to trace how they were produced.
“The formal presence of a human being at the end of the process does not mean that person can exercise meaningful control over it”
An analysis produced with AI support should therefore be able to distinguish data from verified sources from conclusions generated by the model. It should also convey the level of uncertainty associated with those inferences. In especially grave decisions, such as designating someone as a threat, authorising an operation or recommending the use of force, the model’s output should never be the sole basis.
It remains crucial to keep teams capable of functioning without these tools. Dependence does not arise only when a particular technology is unavailable; it also appears when an organisation no longer knows how to perform its duties without it. An intelligence service that loses the capacity for independent analysis becomes more vulnerable to system errors and to manipulation or disruption of access.
Sovereignty over the capacity to know
The secretive nature of these activities should not preclude democratic oversight. Parliaments do not need access to every operational detail, but they should know which companies participate in producing intelligence, what tasks they perform and which controls apply to them.
A company may detect an operation on its platform, close an account or decide which uses of its technology to permit. Those decisions are part of managing a service. Yet, it is a different matter to determine what constitutes a threat or where the national interest lies, decisions that belong to public institutions. Likewise, state secrecy should not become a pretext for deploying opaque tools without some form of independent assessment.
Europe can adopt US models while also cultivating its own options. The two approaches are compatible provided it retains enough control over the data, over how the systems operate and, above all, over the decisions taken based on their outputs. The margin to do so will shrink as the technologies in use today become harder to replace.
“States may procure technology, but they should not lose the ability to understand the information they use, form their own judgement and take responsibility for the decisions they make”
States have always depended on tools developed outside government, yet never before has so much work been delegated as today. They may procure technology, but they should not lose the capacity to comprehend the information they rely on, to form their own judgments and to take responsibility for the choices they make. If a state ceases to understand how the intelligence underpinning its decisions is produced, it may retain formal authority while effectively losing a significant portion of it.