Start your day with intelligence. Get The OODA Daily Pulse.
Information Integrity Is a National Security Must
Much of today’s conversation surrounding artificial intelligence (AI) centers on the models themselves. Organizations worry about prompt injection, model theft, jailbreaks, insider threats, and the growing sophistication of AI-enabled cyberattacks. While these are legitimate concerns deserving attention, there may be a more consequential risk beneath the model itself – the integrity of the information that drives Large Language Models (LLM). LLMs do not think independently; they operate and generate responses based on enormous volumes of information collected from books, websites, academia, research, government documents, news reporting, and other digital sources. If these sources become corrupted, manipulated, or intentionally poisoned, AI-generated outputs inherently become increasingly unreliable. This doesn’t just represent an AI problem but a cybersecurity problem, and as recent reporting shows, a potential national security problem, as well.
Information Has Become the New Attack Surface
While cybersecurity has traditionally focused on protecting networks, endpoints, etc., over the past ten years or so, data and information have been progressively weaponized to further state interests. With more public and private institutions embracing AI, this technology has introduced a new attack surface that has received little attention – information integrity.
Instead of compromising a model through traditional cyber means, adversaries can manipulate the information ecosystem surrounding it to amplify disinformation, misinformation, and influence operations. If enough “false narratives,” fake stories, and manipulated documents are injected into the digital environment, future AI systems may absorb that data and accept it as legitimate knowledge. Recent reporting suggests Russia is expanding its disinformation campaigns beyond influencing public opinion and toward contaminating the online information environment consumed by AI systems. The main goal is not to trick people with lies. Instead, the goal is to make future AI models learn these lies and share them quickly all over the world. That represents a significant evolution in information warfare.
From Disinformation to Cognitive Warfare
Traditionally, influence operations sought to manipulate people. Now, AI changes the equation, as adversaries have the opportunity to manipulate both human decision-makers and the machines that support those decisions. An ambitious state could execute coordinated campaigns that generate thousands of fake technical articles, scientific studies, altered historical or current events, geopolitical analysis, and even cybersecurity reports. Sure, it’s possible that discerning human readers could recognize and dismiss many of them, but AI systems may not.
As organizations continue to rely on retrieval-augmented generation (RAG), enterprise knowledge bases, and continuously updated information sources, poisoned information can become operational knowledge. Disinformation seeks to influence beliefs; information poisoning looks to influence future machine reasoning. The distinction is important to highlight because it potentially represents an advancement of cognitive warfare not seen before.
The Enterprise Risk
Organizations view AI as a productivity enhancer; however, productivity without trustworthy information can lead to poor decision-making. Several notional examples underscore this implication: 1) a security analyst receiving AI-generated threat intelligence based upon manipulated reporting; 2) a software developer unknowingly incorporating bad code recommendations from poisoned repositories; and 3) a financial institution basing and/or recommending investment decisions on AI-generated market analysis tainted by economic disinformation. In each instance, the AI model did not have to be compromised to achieve the objective. The model performed as designed only with invalid information. Security practitioners have long championed the CIA Triad of confidentiality, integrity, and availability as the foundation of cybersecurity. Now with AI, integrity takes on an even greater importance.
Why This Matters for U.S. National Security
The implications extend far beyond private industry and into national security. AI is being integrated across the U.S. national security apparatus, supporting key functional areas like intelligence analysis; military planning; logistics; cyber operations; and critical infrastructure protection, to name a few. Recognizing this reality, and keeping consistent with the Administration’s goal of making the United States an AI leader, the president issued a Presidential Memorandum on Artificial Intelligence (AI) in the National Security Enterprise, directing agencies to fast-track the deployment of secure and reliable AI across defense and intelligence with appropriate cybersecurity considerations in place.
But making the actual models secure is not enough. If adversary nations successfully pollute the global information ecosystem, they can subtly influence the content that the knowledge AI systems ingest. While this could cause disruption or failure (depending on the attackers’ intent), data integrity degradation would be a far more insidious attack that could affect the interpretation, analysis, and assessment of the information. Unlike traditional malware, which can generally be detected or at least leaves some digital artifact behind, this hidden threat gives no warning sign. It changes the data itself, so you cannot see it. The victim ultimately unknowingly makes decisions based on the faulty information. This type of attack is perfect for nation-states as an inexpensive, difficult-to-attribute, and scalable option that can be executed during peacetime and conflict situations.
Over the next several years, expect influence operations to evolve beyond targeting human perception toward targeting machine cognition. Nation-state adversaries, particularly Russia and China, understand that future geopolitical advantage will depend not only on building more capable AI systems, but also on shaping the information those systems trust. Protecting the information supply chain is now essential, requiring companies to treat information integrity with the same security considerations they regard software integrity. When it comes to supply chains, upstream compromises create downstream victims, and the information supply chain is no different. Source validation, digital authenticity, and verification must become core parts of responsible enterprise AI development, deployment, and management.
Moreover, information integrity needs to be recognized as a strategic national asset. The United States must protect its digital knowledge ecosystem with the same urgency and attention it applies toward critical infrastructure and software/hardware supply chains. In the end, winning the AI race may not be only about developing and supplying the world’s most capable AI models; it could very well rest in how the United States ensures that the models are learning from information worthy of the trust we place in them and on which we rely.