Intelligence and Surveillance Capabilities

Michael Torres cannot tell his family what he does. He can say he works for the National Security Agency at Fort Meade, Maryland, and that he analyzes signals intelligence — SIGINT, the intercepted communications of foreign adversaries. He cannot say which building, which desk, or which tools. But the shape of his working life has changed so completely in five years that the change itself is almost the whole story.

In 2020, Torres and his team could process perhaps a few thousand intercepts a day. Humans listened to audio, read transcripts, identified speakers, flagged keywords, and passed anything relevant up the chain. It was slow, and it was incomplete. Most of what the agency collected was never analyzed at all — not because it lacked value, but because there were never enough people to look at it. The bottleneck was not collection. It was attention.

By 2025 that bottleneck had moved. The systems Torres supervises now churn through orders of magnitude more material each day. AI handles the first pass: transcription, translation, speaker identification, anomaly detection, triage. Torres reviews only what the machine escalates. His output, measured in finished intelligence products, has jumped roughly tenfold — not because he works harder, but because the grunt work now happens without him. The intelligence cycle that once ran from intercept to actionable insight in weeks can now, for some tasks, run in hours.

That single shift — from a world where analysts processed data to one where they supervise machines that process it — is the hinge this chapter turns on. It sounds like an efficiency story. It is really a power story, and a story about who watches whom.

What the machine took over

Signals intelligence has always been a scale problem. The more you intercept, the more you can learn — but only if you can process what you intercept. For most of the history of SIGINT, human capacity set the ceiling. AI has raised it.

The tasks that have been automated are specific and unglamorous, which is exactly why they matter. A modern SIGINT pipeline can demodulate full radio waveforms, train neural networks to recognize particular signal types, transcribe and translate intercepted audio across dozens of languages, cluster speakers by voice, and flag statistical anomalies in traffic patterns — all before a human sees anything. Booz Allen, one of the largest intelligence contractors, has described building machine-learning systems that compress "sensemaking" timelines from hours to seconds for these front-end tasks. The U.S. Army's Project Linchpin aims to knit such tools into a single AI ecosystem delivering near-real-time insight where the work was previously human-intensive; the National Geospatial-Intelligence Agency has begun circulating AI-generated products that cut analyst workload and speed up tasking cycles.

The market has noticed. The SIGINT sector was valued at roughly $16.8 billion in 2024 and is projected to reach $28.1 billion by 2034, with the growth attributed largely to AI and sensor advances (GlobeNewswire, 2025). None of this is experimental anymore. It is operational, funded, and expanding.

The resulting change in the analyst's role is the crux of the primary question. Torres is no longer primarily a processor of raw material. He is a supervisor of automated systems and an investigator of the leads those systems surface. His scarce resource is judgment — deciding which machine-flagged thread is worth pulling, and which is noise. The constraint on intelligence work has migrated from collection capacity to analytical discernment. That is a qualitative shift, not merely a faster version of the old job.

The pattern-recognition advantage — and its trapdoor

Speed is the obvious gain. The subtler one is a different kind of seeing.

Human analysts are superb at context, judgment, and strategic interpretation. They are poor at scanning ten million records for a faint correlation. Machines are the reverse. Trained across years of intercepts, social-media activity, financial transactions, travel records, and known threat networks, an AI system can surface connections no human team would find in time: a single phone number quietly shared among several suspects, a cluster of wire transfers timed to specific international events, a coded phrase recurring across channels that appear unrelated. These are not conclusions. They are threads. The analyst pulls them.

Where this matters most is in the domains built on linkage rather than content — counterterrorism, counterintelligence, and strategic monitoring — where the intelligence value lives in relationships between data points that sit in different databases, collected by different means, at different times. Cross-dataset correlation is precisely the task human teams cannot do at scale and machines can.

But the same capability has a trapdoor, and it opens onto the chapter's epistemic questions. A statistical correlation is not a cause. An AI trained on biased or incomplete data will confidently generate leads that reflect the shape of its training set rather than the shape of the world — false positives that look like intelligence. An analyst who over-relies on machine-surfaced leads begins chasing patterns that are noise dressed as intent, and the analytical culture shifts with it: away from hypothesis and toward triage of whatever the model coughed up. Calibrating trust in AI-generated leads — knowing when the machine is worth believing — is slow, ongoing, and never finished. The productivity gain is real, but it is borrowed against the risk of confident error at scale.

The subversion problem

That risk becomes strategic when an adversary is the one shaping the model's output.

There is a meaningful difference between disrupting an AI system and subverting it. Disruption is loud: the system goes down, everyone notices, you fix it. Subversion is quiet. Imagine a hostile actor who gains influence over a model an agency uses for threat assessment — not to disable it, but to nudge it, so that it slightly overweights some indicators and underweights others. Analysts keep receiving plausible, well-formatted intelligence products. Nothing looks broken. And their picture of an adversary's capabilities and intentions drifts, month by month, away from reality — a drift that could run for a year before anyone catches it. Subtle manipulation is more dangerous than outright sabotage precisely because it manufactures confident, well-reasoned, systematic misjudgment instead of an obvious failure.

This is the threat the NSA's Artificial Intelligence Security Center was created to counter. The AISC works with industry, academia, and the rest of the Intelligence Community on a governmentwide security playbook covering model development, training environments, and the AI supply chain, and on the capacity to run rapid, classified testing of models. The honest question — one of the chapter's epistemic problems — is whether those measures are adequate. A successful subversion campaign would be designed to survive exactly the tests currently used to catch it: to fail no obvious benchmark, to produce outputs inside the expected range, to look like the model working. Supply-chain vetting and model testing raise the cost of subversion. Whether they reliably detect a competent one is not something anyone can honestly claim to know, and that uncertainty is itself part of the risk.

The facial-recognition state, and the logic of mission creep

Signals intelligence happens in the dark. The most visible face of AI surveillance is literally a face — and the clearest recent case is domestic.

In the United States, Immigration and Customs Enforcement agents have used a mobile application, Mobile Fortify, that connects to government facial-recognition databases to check a person's citizenship status in the field. Footage from 2025 showed agents using it to identify teenagers carrying no ID. The tool was justified for tracking noncitizens at border crossings. It migrated — into interior neighborhoods far from any border, used to identify and investigate noncitizens and citizens alike. In February 2026, senators introduced the ICE Out of Our Faces Act to bar ICE and CBP from acquiring or using facial recognition, arguing the practice amounts to a fast-growing surveillance state that falls hardest on marginalized communities. The outcome is uncertain, and legislation is a blunt instrument against infrastructure already woven into daily operations.

The important point is why this happens, because it speaks to the chapter's causal core. Mission creep is not usually a conspiracy. It follows an institutional logic that runs the same way each time. A tool is built for a narrow, legally specific purpose. It works. Operators, facing a broader problem, notice the tool would help there too, and the marginal cost of pointing it at the new problem is nearly zero. Each expansion is justified on its own terms, none looks dramatic, and the legal and political rationale shifts by increments rather than by decision. Oversight, which is slow and reactive, arrives after the practice is entrenched. The sum of many small, individually defensible steps is a large, undeliberated change in the scope of surveillance. No one has to intend overreach for overreach to occur; the incentives produce it.

The border-to-interior drift of Mobile Fortify also exposes a deeper structural fact underlying the civil-liberties questions. AI surveillance tools built for foreign intelligence do not inherently distinguish foreign from domestic targets. A model trained to flag a threat indicator flags it wherever it appears. The legal architecture that separated foreign collection from domestic surveillance — in the United States, the Foreign Intelligence Surveillance Act and the wall it built — was designed for an era when the two streams were physically different operations. AI processes domestic and foreign signals with the same pipeline, at the same scale, and the temptation to turn a powerful foreign-intelligence capability inward is strong, because terrorism, espionage, and organized crime do not respect the categories the law drew. The technology strains the boundary not by malice but by indifference to it.

Internationally the picture is just as contested. The UK Home Office has proposed a national facial-recognition framework linking police databases, with pilot testing expected in 2026. The EU AI Act treats retrospective facial recognition for law enforcement as high-risk, with additional safeguards taking effect 2 August 2026, though enforcement across member states has been uneven. Authoritarian governments deploy the technology to monitor protests and track minorities with far fewer constraints. The global facial-recognition market is projected to reach roughly $12.67 billion by 2028, pulled by demand from police, intelligence services, and private security.

The global competition and the feedback loop

The United States is one player among several, and the competition has a self-reinforcing engine that governance struggles to slow.

China's position is the most consequential. It pairs mass surveillance infrastructure — hundreds of millions of cameras, pervasive facial recognition, AI-driven social-governance systems — with front-rank AI research, producing an apparatus of a scope no previous authoritarian state could field. Domestically, that means fine-grained monitoring, from tracking the movements of ethnic minorities to scoring compliance with state norms. Internationally, China exports surveillance systems to dozens of governments, and here the strategic point sharpens: a country that buys a Chinese surveillance stack tends to become dependent on Chinese technical support, maintenance, and upgrades. That dependency is leverage — commercial and diplomatic — and it embeds Chinese standards and, potentially, Chinese access inside another state's core security infrastructure. Exported surveillance is not just a product sale. It is the quiet construction of long-term influence, and it means the global governance of surveillance is increasingly shaped by whoever supplies the equipment rather than by any treaty.

Russia concentrates its AI intelligence effort in signals intelligence, cyber operations, and information warfare — automated generation of fake accounts, amplification of divisive content, and disinformation coordinated at a scale manual operations could never reach. Israel occupies a distinct niche: a small state that became a surveillance-technology leader, with firms such as NSO Group selling tools to agencies worldwide, its capabilities sharpened by decades of operations in contested environments.

Actor Center of gravity Strategic intent Export pattern
China Mass domestic surveillance + AI research Social control; global influence via infrastructure Broad export creating client dependency
Russia SIGINT, cyber, information warfare Disruption, disinformation at scale Limited hardware export; exported operations
Israel Commercial spyware and targeted tools Security edge; technology as statecraft Sales to state agencies worldwide
United States SIGINT automation, analytic AI Information advantage; tempo Allied intelligence-sharing, limited commercial export

Underneath all of it runs the feedback loop that is the chapter's other causal engine. AI systems improve by training on data. An agency that collects more intelligence trains better-performing models, which enable more effective collection, which yields more data. Early adopters therefore accumulate a compounding advantage that late movers find hard to close — and that advantage translates directly into pressure to deploy fast, before rivals lock in their lead. Governance, which asks agencies to slow down and vet, is asking them to concede ground in a race where the leader's lead widens on its own. That is why deployment consistently outruns oversight: the structural incentive points one way.

The procurement gap

The race has a bureaucratic front, and the chapter's temporal question lives here. AI capability advances in months; government acquisition moves in years. By the time a system clears security review, contracting, and deployment planning, its underlying technology may be a generation old. Adversaries with fewer procedural constraints — China chief among them — enjoy a tempo advantage from this alone.

The White House AI Action Plan, released 23 July 2025, targets the gap directly, emphasizing streamlined procurement so agencies can field cutting-edge AI without waiting out the full bureaucratic cycle. Closing the gap is a genuine need. But speed is bought at the price of scrutiny. The same pre-deployment vetting that slows acquisition is what catches embedded bias, security vulnerabilities, and unexpected model behavior. Push acquisition faster and you field more systems that testing would have flagged — including, potentially, systems open to exactly the subversion the AISC exists to prevent. Different agencies are resolving the tension differently, some prioritizing tempo and others insisting on rigor, and no settled answer has emerged. The procurement gap has narrowed by intent more than by demonstrated result, and narrowing it carelessly trades one risk for another.

What we do not know, and what oversight would require

Two honest admissions belong at the end, because they bound everything above.

The first is opacity. Much of what intelligence agencies do with AI is classified, by design. The public record captures the visible edge — Mobile Fortify because it was filmed, the AISC because it was announced, procurement policy because it was published — but the full scope of domestic AI surveillance is not documented anywhere a citizen can read. We can describe the mechanisms and name the tools that surfaced; we cannot honestly claim to know the whole. That opacity is not incidental to the oversight problem. It is the oversight problem, because you cannot hold accountable what you cannot see.

The second is speed. AI surveillance operates faster than any human review process was built to track. A model can flag, correlate, and escalate millions of times between one oversight-committee meeting and the next. Traditional accountability — courts ruling case by case, legislatures holding hearings, inspectors auditing after the fact — was designed for a slower world. Adequate oversight of systems this fast would need to be continuous rather than periodic, technical rather than purely legal, and empowered to inspect models and training data rather than only outcomes. Whether such mechanisms can be built, and whether agencies racing under the feedback-loop pressure would accept them, is unresolved.

Which is where the normative line has to be drawn, even in the absence of certainty. Democratic societies get real security from these tools — faster threat detection, broader coverage, better counterterrorism — and real costs: eroded privacy, chilling effects on speech and assembly, and discrimination baked into systems with documented bias against minorities. States that build and export this technology also acquire obligations toward the countries they sell it to, since a surveillance stack shipped without conditions becomes an instrument of whoever operates it. The line between legitimate security use and unacceptable chilling effect will not be set by the technology, which is indifferent to it. It will be set by design choices, procurement decisions, export conditions, and the stubbornness with which societies insist on watching the watchers — before the infrastructure is built, because once it is embedded in daily operations, it is almost never dismantled.

Key Takeaways

  1. The analyst's job has inverted. AI now performs the front-end SIGINT tasks — transcription, translation, speaker identification, anomaly detection — that once consumed human effort, raising throughput by roughly an order of magnitude and moving the constraint on intelligence work from collection capacity to analytical judgment.

  2. Pattern recognition is the qualitative gain, and its own risk. AI surfaces cross-dataset correlations no human team could find in time, which is decisive in counterterrorism and counterintelligence — but correlations are not causes, false positives look like leads, and over-reliance reshapes analytical culture toward triage over hypothesis.

  3. Subversion beats disruption. The gravest AI-security threat is not an adversary switching a system off but quietly biasing its outputs, producing confident, systematic misjudgment that can persist undetected for months. Whether current testing (the NSA's AISC, supply-chain vetting) would catch a competent subversion campaign is genuinely unknown.

  4. Mission creep is structural, not accidental. Tools built for narrow purposes — ICE's Mobile Fortify, built for the border and now used in interior neighborhoods — expand through many small, individually defensible steps, because operational convenience is cheap and oversight is slow. AI surveillance does not inherently distinguish foreign from domestic targets, straining legal walls like FISA that assumed it did.

  5. A feedback loop pushes deployment ahead of governance. More data trains better models, which collect more data; early adopters compound their lead, creating pressure to deploy fast that governance cannot easily moderate. The same logic drives efforts to close the procurement gap — most explicitly the July 2025 AI Action Plan — at the risk of trading pre-deployment scrutiny for speed.

  6. China's export strategy is a governance problem in itself. Pairing domestic surveillance infrastructure with advanced AI and broad technology export embeds Chinese systems in other states' core infrastructure, creating dependency and leverage that shape global surveillance norms outside any treaty.

  7. Opacity and speed bound accountability. Much of domestic AI surveillance is classified, and the tools operate faster than periodic human review can track. Adequate oversight would have to be continuous, technical, and able to inspect models rather than only outcomes — and it must be established before infrastructure is embedded, because embedded surveillance is almost never dismantled.

Sources

Note: web search and fetch were not available in this session; the following are the sourced references carried forward from the prior version of this chapter, from which the data points above are drawn.

Last updated: 2026-08-13

V2 (in progress) Previous: V1