top of page

Metadata Is Intelligence—Until the Enemy Knows You Think It Is AI, deception, and the return of intelligence discipline

12 minutes ago
14 min read

“Metadata is intelligence” has become one of those phrases repeated so frequently in discussions of artificial intelligence and national security that its meaning is beginning to blur. It is regularly invoked alongside enormous AI data centers, quantum computing, signals intelligence, autonomous systems, and the promise that machines will discover patterns no human analyst could possibly recognize. There is considerable truth behind the phrase, but there is also a danger in accepting it too literally.

Metadata can reveal relationships, routines, organizational structures, changes in operational tempo, movements, and anomalies without exposing the contents of a single message. An intelligence service does not necessarily need to know what two military headquarters are saying to one another if it can observe that headquarters which rarely communicate have suddenly begun doing so hundreds of times per day. Add unusual aircraft movements, ships leaving port, changes in radar activity, and logistics movements, and an analyst may reasonably conclude that something important is happening.

The problem is that the metadata has not actually explained why any of those things are happening. The increase in communications is an observation. The conclusion that an operation is approaching is an inference. It could instead be an exercise, a logistics problem, an equipment failure, a command inspection, or even an intentional effort to make an adversary believe that an operation is coming. Good intelligence analysis has always depended upon maintaining that distinction between what has been observed and what the analyst believes the observation means.

Artificial intelligence makes that distinction more important rather than less.

The great promise of AI-enabled intelligence is its ability to examine quantities of information that would overwhelm human analysts. A machine can potentially examine years of communications metadata, commercial shipping records, AIS tracks, satellite imagery, radar emissions, aircraft movements, financial transactions, procurement activity, insurance pricing, corporate relationships, and open-source reporting, searching for correlations across billions of individual observations. It might discover that a particular combination of otherwise innocuous behaviors has historically preceded a military deployment.

That could be extraordinarily valuable. It could also create a new vulnerability, because the prediction depends upon a continuing relationship between observable behavior and the event the machine is attempting to predict. Once an adversary understands that relationship, it has an incentive not merely to conceal its behavior but to manipulate the relationship itself.

The intelligence contest then changes. The question is no longer simply whether we can see the enemy. It becomes whether the enemy can influence what we believe we are seeing.

Enigma Already Taught Us Part of the Lesson

There is nothing entirely new about this problem. The Second World War's cryptographic struggle is often reduced to the breaking of the German Enigma cipher, but the larger intelligence story involved much more than mathematicians defeating an encryption machine. Allied cryptanalysis benefited from predictable procedures, repeated structures, operator habits, recognizable message formats, captured material, traffic analysis, and failures of communications discipline. The cipher mattered enormously, but so did everything surrounding the cipher.

The opposite example is the properly implemented one-time pad. When the key is genuinely random, at least as long as the message, kept secret, and never reused, the resulting encryption provides information-theoretic security. More computing power does not solve the ciphertext. Yet even perfect encryption does not necessarily conceal the existence, timing, origin, destination, frequency, or duration of the communications themselves.

A perfectly encrypted message transmitted from fleet headquarters to a submarine command, followed immediately by communications with six submarines, a tanker squadron, and an air-defense headquarters, may reveal something important even though nobody can read a single word. The content is secure, but the behavior surrounding the content remains observable.

This is why the modern fascination with metadata is justified. It is also why the assumption that more metadata inevitably produces better intelligence needs qualification. Cryptography protects the message, communications security protects the system surrounding the message, and the AI era may require another discipline: protecting the predictive value of observable behavior.

That could be thought of as predictive-signature management.

If an adversary's intelligence system learns that a communications surge followed by unusual command relationships and force movements usually precedes an operation, the traditional response is to conceal those indicators. Predictive-signature management approaches the problem somewhat differently. Instead of merely hiding the signature, a force could seek to prevent the signature from remaining a dependable predictor of what happens next.

Sometimes a communications surge might precede an operation. At other times similar activity could accompany an exercise, a readiness drill, or nothing consequential at all. Meanwhile, genuine operations need not always produce the previously associated signature. Over time, the adversary encounters both false positives and false negatives, degrading the statistical relationship between observation and outcome.

This is more sophisticated than simply generating noise. Random traffic can potentially be recognized as random traffic and filtered from the dataset. The more difficult intelligence problem is plausible ambiguity: activity that looks meaningful because it resembles meaningful activity, but whose relationship with actual operations is unreliable.

The Butterfly Problem

An old intelligence anecdote provides a useful illustration. Robert Baden-Powell described concealing military information inside apparently innocent drawings of butterflies. Features of the drawing could represent fortifications or military positions while other marks had no meaning whatsoever. To the casual observer it was an insect drawing; to someone possessing the interpretive framework, parts of it became a map.

The principle can be inverted for an AI intelligence environment. Instead of concealing meaningful information inside apparently meaningless activity, a force can create apparently meaningful activity that is operationally meaningless. An observer discovers structure and naturally assumes that structure contains information. The defender's objective is to make that assumption unreliable.

This produces an important distinction. Encryption denies access to content, while noise makes the signal more difficult to isolate. Deception goes further because it attacks the observer's interpretation. Against predictive intelligence systems, that third category may ultimately prove the most consequential. An adversary does not necessarily need to prevent the machine from seeing. It may instead benefit from allowing the machine to see exactly what the adversary wants it to see.

That possibility becomes especially important as modern AI systems fuse different categories of information. A model might consider a vessel's manifest, commercial databases, AIS movements, corporate records, satellite imagery, open-source reporting, communications metadata, and classified signals intelligence. If several of those sources appear to point toward the same conclusion, the resulting assessment can look particularly convincing.

But three sources do not necessarily represent three independent pieces of intelligence.

Suppose a manipulated commercial record generates an online report. That report is subsequently repeated elsewhere. Communications concerning the resulting activity are then intercepted. An AI system encounters the original commercial information, multiple open-source references, and SIGINT related to the same event. What appears to be multi-source corroboration may actually descend from one manipulated piece of information.

Intelligence professionals already understand the dangers of circular reporting. AI can magnify the problem because it can synthesize enormous quantities of information into an impressively coherent narrative while making the common origin of supposedly independent evidence difficult to recognize. The resulting report may be beautifully constructed, thoroughly sourced, and completely wrong.

The Chinese Ship Warning

A recently reported U.S. military incident illustrates why intelligence discipline must remain central as AI enters the analytical process.

CNN reported on September 18 that an intelligence report circulated during the U.S.-Iran conflict concluded that a Chinese vessel transiting the Middle East was carrying components associated with a nuclear-weapons program. According to four sources cited in the report, the United States began preparing an interception. Armed personnel were reportedly preparing to board the vessel and military aircraft were airborne before officials reexamined the intelligence and stopped the operation.

According to the reporting, a Special Operations Command analyst had queried an AI chatbot about intelligence concerning the vessel's manifest. The system combined open-source information with classified signals intelligence and incorrectly identified the cargo. AI was reportedly used again in preparing the resulting intelligence product. CNN could not establish whether the chatbot involved was a commercial product or an internal government system, although a former senior official familiar with military and intelligence AI systems characterized some government tools as essentially adaptations of commercial technology.

It is tempting to reduce the episode to a simple lesson: AI hallucinated and nearly caused a dangerous confrontation.

That may eventually prove to be an accurate description, but from an intelligence perspective it closes the inquiry too quickly. The more useful question is what, precisely, was wrong. The manifest may have been accurate while the AI misidentified the cargo. The open-source information may have been erroneous. The relationship between the open-source information and classified SIGINT may have been misunderstood. The model may have treated dependent information as independent corroboration, or the analyst may simply have assigned too much confidence to the machine's conclusion.

There is another possibility worth examining as a counterintelligence problem, although there is presently no public evidence establishing that it occurred in this incident: some portion of the observable information could have been deliberately manipulated.

That distinction matters because an adversary does not necessarily have to penetrate an American AI system to influence its conclusions. If the system consumes shipping manifests, commercial records, open-source reporting, vessel movements, communications patterns, and other externally observable information, then some of the environment being analyzed may itself be susceptible to manipulation.

The vulnerability is therefore larger than the model.

Don't Hack the AI. Manipulate What It Sees.

Much of the current discussion surrounding adversarial AI understandably concentrates on cybersecurity, unauthorized access, model theft, malicious prompts, compromised software, and corrupted databases. Those threats deserve attention, but traditional military deception suggests another possibility. Instead of attacking the intelligence system, an adversary could attempt to manipulate the world the intelligence system observes.

Commercial records can be misleading. Public information can be planted. Observable communications behavior can be altered. Vessels can follow deceptive movement patterns. Operational signatures can be deliberately reproduced when no operation is intended. None of this requires penetrating the classified network on which an intelligence AI operates.

The AI can remain completely uncompromised while faithfully analyzing a reality that has been partially staged for it.

This is not primarily a computer-security problem. It is the ancient problem of military deception applied to machine perception.

The problem becomes more consequential if the resulting assessment causes an observable military response. Imagine an adversary deliberately creates a suspicious combination of indicators and watches what happens. American collection systems detect the indicators, an AI-assisted analytical system flags the activity, analysts elevate the assessment, and military assets begin moving.

Even if the deception ultimately fails and the operation is aborted, the adversary may have learned something. It could potentially observe how quickly the United States reacted, what surveillance assets appeared, what forces moved, how long verification took, and which portions of the command structure became active. A false intelligence signature can therefore become a probe of the intelligence and command system itself.

The sequence is no longer simply adversary behavior followed by American observation. It becomes a feedback loop in which adversary behavior produces U.S. collection, collection produces an assessment, the assessment produces an operational response, and the response becomes intelligence for the adversary.

Under those circumstances, even an unsuccessful deception can function as reconnaissance.

The Second Target Is Confidence

There is another potential consequence that may be even more important. Repeated false positives can eventually attack human confidence in the analytical system itself.

Suppose an AI system repeatedly identifies apparently threatening patterns. Analysts accept those findings, commanders prepare responses, and subsequent investigation reveals that nothing was there. The immediate cost is wasted effort and potentially dangerous escalation. The cumulative effect is more subtle: analysts and commanders begin discounting the system.

Eventually a genuine indicator appears. The AI recognizes it correctly, but the humans remember the previous failures. They demand another source, another review, another layer of confirmation. The warning may still be correct, but the response becomes slower because institutional confidence has been damaged.

The deception has therefore migrated from attacking the algorithm to attacking the relationship between the algorithm and its human users.

This is also where the public information environment enters the problem. News organizations do not need to participate knowingly in an adversary's information operation to become part of the consequences of an intelligence failure. Once an incident becomes publicly characterized as an example of unreliable battlefield AI, legitimate questions inevitably arise about machine reliability, analyst judgment, military procurement, and command professionalism.

The Chinese-vessel incident illustrates the problem particularly well because of the description of some military and intelligence AI tools as commercial systems with modifications—the memorable “lipstick” characterization. Fair or not, that description creates an immediate institutional question. If an AI-generated inference moved far enough through the intelligence architecture that personnel were preparing to board a Chinese vessel and aircraft were reportedly airborne before experienced specialists caught the error, the issue is no longer simply why the machine was wrong. It is why the validation process apparently caught the error so late.

That is fundamentally an intelligence-discipline problem.

AI Should Accelerate Analysis, Not Uncertainty

The fact that human review reportedly stopped the Chinese-vessel operation is important. A corrective mechanism existed and ultimately worked. That should not be lost in criticism of the episode.

The relevant question is where that correction occurred.

If the approximate sequence was source information, AI synthesis, analyst acceptance, intelligence product, dissemination, operational preparation, expert review, and finally abort, then the system did not merely experience an AI failure. It experienced a potential validation-chain failure in which uncertainty moved too far downstream before being challenged.

The answer is not to remove AI from intelligence analysis. That would discard precisely the capabilities that make the technology valuable. Machines should search datasets too large for humans to examine. They should identify anomalies, relationships, and correlations that analysts would otherwise miss. They should help analysts ask questions that were previously computationally impossible.

But machine-generated inference should not acquire the authority of independently corroborated intelligence merely because it has been formatted into a conventional intelligence product.

This makes provenance essential.

For every consequential AI-assisted conclusion, an analyst should be able to move backward through the assessment and determine which observations support the claim, where each observation originated, whether apparently separate sources are actually independent, what assumptions connect the evidence to the conclusion, what alternative explanations fit the same evidence, and which portions of the final assessment were observed facts rather than machine-generated inference.

That is not a revolutionary new intelligence methodology.

It is traditional intelligence tradecraft adapted to machine-scale analysis.

And that may be the most important lesson of all. The danger of AI is not simply that machines occasionally get things wrong. Human analysts get things wrong as well. The greater danger is that AI can perform analytical work so quickly, combine so many sources, and present the result so coherently that organizations become tempted to bypass the disciplines developed specifically to prevent intelligence errors.

Metadata Can Also Be Deception

We therefore need to return to the phrase that started the discussion: “metadata is intelligence.”

Sometimes it is.

More precisely, metadata is evidence of observable behavior from which intelligence can be derived. Its usefulness depends upon our ability to interpret that behavior correctly. Once an adversary understands which behaviors we observe and what conclusions we associate with them, metadata becomes something else as well.

Metadata can become deception.

That changes the competition. The response cannot simply be larger AI models, larger data centers, faster processors, or eventually quantum computing. Greater computational power cannot solve an epistemological problem. If the information entering the system is deliberately misleading, processing it a million times faster may merely allow us to become confidently wrong sooner.

The advantage will therefore belong not simply to the military possessing the largest dataset or most sophisticated AI system, but to the force that retains the strongest intelligence discipline while using those capabilities. Machines can search enormous datasets for patterns humans cannot see, but analysts still have to determine whether those patterns mean what the machine thinks they mean. Intelligence organizations must distinguish observed facts from machine-derived correlations and analytical inference, while commanders must understand the degree of uncertainty separating those categories.

At the same time, disciplined forces will increasingly have to think about the metadata they themselves generate. Communications discipline can no longer concern itself only with preventing an enemy from reading messages. Forces must also consider whether their observable behavior creates predictable signatures that allow an adversary's machines to anticipate what they will do next. Encryption, traffic discipline, deceptive signatures, operational ambiguity, and predictive-signature management therefore become parts of the same contest.

Enigma taught that sophisticated encryption could be undermined by predictable behavior surrounding it. AI may teach the inverse lesson. A machine may eventually become capable of observing almost everything an adversary does, yet observation and understanding remain two different things.

A disciplined adversary will exploit that difference.

The future of intelligence will not be decided simply by who collects the most metadata or builds the largest AI system. It may be decided by something much older and much less glamorous: who maintains the discipline to distinguish what has been observed from what they merely believe those observations mean.

Endnotes


  1. Claude E. Shannon, “Communication Theory of Secrecy Systems,” Bell System Technical Journal 28, no. 4 (October 1949): 656–715. Shannon established the theoretical basis for perfect secrecy and demonstrated the conditions under which a one-time pad can provide information-theoretic security.

  2. National Security Agency, Solving the Enigma: History of the Cryptanalytic Bombe, Center for Cryptologic History. The history of Allied exploitation of Enigma demonstrates that cryptographic security cannot be considered independently from operating procedures, key management, predictable communications practices, captured material, and traffic analysis.

  3. Gordon Welchman, The Hut Six Story: Breaking the Enigma Codes (New York: McGraw-Hill, 1982). Welchman's account is particularly useful because it places cryptanalysis within the larger problem of reconstructing communications networks and exploiting patterns surrounding encrypted German traffic.

  4. Robert Baden-Powell, My Adventures as a Spy (London: C. Arthur Pearson, 1915). Baden-Powell famously illustrated the concealment of military information within drawings of butterflies and other apparently innocuous material. The example provides a useful historical analogy for distinguishing observable structure from actual informational meaning.

  5. U.S. Department of Defense, Joint Publication 2-0: Joint Intelligence. Joint intelligence doctrine emphasizes evaluation of source reliability, corroboration, competing hypotheses, uncertainty, and the distinction between collected information and finished intelligence. These principles remain applicable when AI systems are introduced into the analytical process.

  6. Office of the Director of National Intelligence, Intelligence Community Directive 203: Analytic Standards. ICD 203 requires intelligence analysis to distinguish underlying intelligence from analysts' assumptions and judgments, describe source quality and credibility, express uncertainty, consider alternatives, and demonstrate relevance to the analytical judgment. These requirements are particularly important for AI-generated or AI-assisted assessments.

  7. U.S. Department of Defense, Responsible Artificial Intelligence Strategy and Implementation Pathway (June 2022). The strategy identifies responsible, traceable, reliable, governable, and equitable AI as central requirements for Department of Defense adoption. The concept of traceability is especially relevant to intelligence provenance and the ability to reconstruct how an AI-assisted conclusion was reached.

  8. Defense Innovation Board, AI Principles: Recommendations on the Ethical Use of Artificial Intelligence by the Department of Defense (2019). The report helped establish the framework subsequently adopted by the Department of Defense for responsible military AI and emphasized human judgment, reliability, traceability, testing, and governance.

  9. CNN, “Exclusive: US Military Had Close Call After Using AI for False Intelligence Report, Sources Say,” September 18, 2026. According to CNN's reporting, an AI-assisted intelligence assessment incorrectly identified cargo aboard a Chinese vessel during the U.S.-Iran conflict. U.S. personnel reportedly began preparations for an interception before additional expert review challenged the assessment and the operation was halted. CNN reported that it could not determine whether the chatbot involved was a commercial product or an internal government system.

  10. The same CNN investigation reported that the analyst incorporated information concerning the vessel's manifest, open-source material, and classified signals intelligence into the AI-assisted analysis and subsequently used AI in preparing the intelligence report. The episode illustrates the importance of distinguishing machine synthesis from independent multi-source corroboration and maintaining source provenance throughout the analytical chain.

  11. Richards J. Heuer Jr., Psychology of Intelligence Analysis (Washington, DC: Central Intelligence Agency, Center for the Study of Intelligence, 1999). Heuer's work remains particularly relevant to AI-assisted intelligence because it examines confirmation bias, competing hypotheses, incomplete information, and the tendency of analysts to fit evidence into established explanatory frameworks.

  12. Barton Whaley, Stratagem: Deception and Surprise in War (Cambridge, MA: MIT Center for International Studies, 1969). Whaley's study of military deception demonstrates that effective deception frequently operates not by hiding every observable fact but by causing an opponent to interpret genuine and fabricated indicators incorrectly. That principle becomes increasingly important when machine-learning systems derive predictions from observable behavioral patterns.

  13. The concept described in this article as “predictive-signature management” is used as an analytical framework rather than as a claim of established U.S. military terminology. It describes deliberate efforts to prevent observable communications, movement, logistics, or other behavioral signatures from developing a reliable statistical relationship with future operational actions.

  14. Likewise, the discussion of deliberate manipulation of the Chinese-vessel intelligence picture is presented as a counterintelligence hypothesis, not as an assertion about the September 2026 incident. No publicly available evidence presently establishes that China deliberately manipulated the manifest, open-source reporting, SIGINT environment, or other inputs involved in that episode. The case is used to demonstrate how an AI-assisted intelligence architecture could potentially be exploited through manipulation of observable information rather than penetration of the AI system itself.


Suggested Reading

Richards J. Heuer Jr., Psychology of Intelligence Analysis (CIA Center for the Study of Intelligence, 1999). Perhaps the most useful starting point for understanding why AI does not eliminate the fundamental problems of intelligence analysis. Heuer examines how analysts evaluate ambiguous evidence, fall into confirmation traps, construct competing hypotheses, and become attached to explanatory models. Much of the book reads differently when the “analyst” constructing the initial pattern is an AI system.

Barton Whaley, Stratagem: Deception and Surprise in War (1969). Whaley provides the historical foundation for the article's argument that the adversary can attack interpretation rather than simply conceal information. His work helps explain why a force does not necessarily need to become invisible to defeat an intelligence system; sometimes it is more effective to remain visible while encouraging the observer to draw the wrong conclusion.

Gordon Welchman, The Hut Six Story: Breaking the Enigma Codes (1982). Welchman's account provides an excellent bridge between historical signals intelligence and today's metadata problem. Enigma was not defeated solely by attacking ciphertext. Network relationships, communications patterns, operating procedures, repeated behavior, and traffic analysis all contributed to constructing the intelligence picture. The technology has changed enormously; the underlying contest between observable patterns, disciplined communications, and human interpretation has not.

Comments


FLVictory2.fw.png

Florida Conservative

The South

bottom of page