Think Tanks
Here's a look at documents from think tanks
Featured Stories
Jamestown Foundation Issues Commentary: Taiwan Shows Resilience in Trying Times
WASHINGTON, Aug. 7 -- The Jamestown Foundation issued the following commentary on Aug. 6, 2026, by journalist and geopolitical analyst Matthew Fulco in the foundation's China Brief Notes:
* * *
Taiwan Shows Resilience in Trying Times
Executive Summary:
* Taiwan is showing resilience in the face of headwinds ranging from domestic politic strife, increased military pressure from the People's Republic of China (PRC), and uncertainty regarding U.S. political support.
* Taiwan's semiconductor sector is benefitting massively from the global artificial intelligence (AI) boom. Its gains contributed ... Show Full Article WASHINGTON, Aug. 7 -- The Jamestown Foundation issued the following commentary on Aug. 6, 2026, by journalist and geopolitical analyst Matthew Fulco in the foundation's China Brief Notes: * * * Taiwan Shows Resilience in Trying Times Executive Summary: * Taiwan is showing resilience in the face of headwinds ranging from domestic politic strife, increased military pressure from the People's Republic of China (PRC), and uncertainty regarding U.S. political support. * Taiwan's semiconductor sector is benefitting massively from the global artificial intelligence (AI) boom. Its gains contributedto Taiwan posting almost 13 percent quarterly GDP growth and reaching record stock market highs.
* In a bid to strengthen its relationship with the United States, Taiwan is investing $265 billion into American semiconductor manufacturing through Taiwan Semiconductor Manufacturing Corporation (TSMC). Taiwan has also hosted multiple high profile bipartisan congressional visits since the beginning of 2026.
* Domestic political strife, now centered around a proposed drone procurement bill, may affect U.S. assessments of Taiwan's will to fight. Taiwan is also waiting for the Trump administration to approve a delayed $14 billion arms sale, which will be critical to its defense against a potential military campaign by the PRC.
-
Taiwan today faces an unusually difficult geopolitical environment in which multifaceted pressure from a militarily powerful People's Republic of China (PRC) is mounting, domestic political strife is undermining defense readiness, and support from the United States is inconsistent. Taiwan has dealt with each of these challenges separately in the past, but this is the first time it must grapple with all three simultaneously.
Despite the difficult geopolitical situation, Taiwan has shown impressive resilience. The island nation has become a leader in producing hardware for artificial intelligence (AI), which has made it the world's fastest growing advanced economy. At the same time, Taiwanese officials have quietly worked with their American counterparts to deepen ties. The missing piece of the puzzle is its military resilience: legislation to support Taiwan's drone industry remains stalled and a large U.S. arms sales package is still pending. These delays continue to raise questions about Taiwan's defense readiness.
AI-Fueled Surge
As the world's chief producer of advanced semiconductors, Taiwan is benefiting hugely from the AI boom, arguably more than any other country. In the second quarter of the year, the Taiwanese economy grew at a torrid clip of almost 13 percent. This was the third consecutive quarter of double-digit expansion and the briskest quarterly rate since 1988. Taiwan's Directorate General of Budget Accounting and Statistics forecasts annual GDP growth this year to reach 9.6 percent, which would be the best performance since 2010 (National Statistics, Republic of China (Taiwan), accessed August 5).
Taiwan's foundry-centric semiconductor manufacturing model, best encapsulated by the Taiwan Semiconductor Manufacturing Company (TSMC), has never been more effective. Fabless designers at the vanguard of AI hardware, including U.S.-based Nvidia, AMD, and Broadcom, all rely on TSMC to fabricate their most advanced chips. Their demand for AI chips led TSMC to post record profits for the fifth consecutive quarter in July, with net income of roughly $22 billion. The company is projecting revenue to grow 40 percent this year to more than $171 billion (Taiwan Semiconductor Manufacturing Corporation [TSMC], accessed August 5).
The semiconductor sector's robust growth has coincided with Taiwan's stock exchange reaching a new all-time high. After the TAIEX reached 48,218 points in late June, the market cooled somewhat in the following weeks, before rallying back to roughly 43,000 points in early August (Unique Business News, June 23; Commercial Times, August 4).[1] This has apparently spurred a new wave of retail investors in Taiwan, where the number of people with brokerage accounts rose to a record 14.6 million in July, with investors under 30 accounting for nearly two-thirds of the increase over June (Taiwan Stock Exchange [TWSE], accessed August 5).
Deepening Ties With the United States
In tandem with its robust economic growth, Taiwan has managed to quietly strengthen ties with the United States this year. Taipei has done so by focusing on strategic industries in line with Trump administration priorities and avoiding criticism of President Trump, who has prioritized U.S.-PRC relations.
For the Trump administration, Taiwan's AI capabilities are among its most attractive assets. Taiwan is leveraging this competitive advantage effectively through both government-to-government initiatives and massive private investment. At the sixth Taiwan-U.S. Economic Prosperity Partnership Dialogue in February, the two countries agreed to a "strategic alignment for AI development" (AI) (Taiwan Ministry of Digital Affairs, February 2). In July, TSMC announced it would invest an additional $100 billion in its Arizona production facilities, bringing its total investment to $265 billion (UDN, July 17).
Drones are another area in which the United States and Taiwan are enhancing cooperation, though with more modest results than AI. In June, Taiwan's semi-governmental Industrial Technology Research Institute (ITRI) joined the Green UAS certification program of the Washington-based nonprofit Association for Uncrewed Vehicle Systems International (AUVSI), which verifies supply chain and cybersecurity compliance for commercial drones. The certification will facilitate the entry of more Taiwanese drone makers into the U.S. market (Industrial Technology Research Institute, June 4).
Bipartisan congressional delegations have made three visits to Taiwan so far in 2026, signaling continuity in the bilateral relationship at a crucial time. Drones came to the fore during the most recent visit (July 30-August 1), which was led by Representative Young Kim (R-CA). This time, the context was Taiwan's strained domestic politics and a stalled $6.6 billion drone procurement bill (Focus Taiwan, June 18). In a meeting with Taiwan President Lai Ching-te, Kim noted the intensifying military threat the PRC poses to Taiwan and urged Taipei to pass necessary legislation to support its drone industry, which has been delayed more than six months.[2] "Deterrence takes two to tango, so help us help you," she said (Office of the President of the Republic of China (Taiwan), July 31). After her meeting with Lai, Kim told reporters, "We hope that the Legislative Yuan can send a strong demand signal to build and buy as many drones as possible, and do it quickly" (Taipei Times, August 1).
The Art of the Delay
Representative Kim's comments well embody the sentiment among U.S. lawmakers that Taiwan needs to move quicker on drone legislation. While congressional support for Taiwan remains strong, the inability of the ruling and opposition parties to find a modus vivendi on the issue is causing some strain in the bilateral relationship. Skeptics of the U.S. security commitment to Taiwan can point to the drone issue and argue that Taipei does not take its own defense seriously, and therefore is not worth risking American blood and treasure to defend.
At the same time, the Trump administration has so far declined to approve a new arms sale to Taiwan, for undisclosed reasons. The package, estimated at $14 billion, has been delayed since early 2026. President Trump described the package as a "very good negotiating chip for us" with the PRC during a May Fox News interview, heightening speculation that his administration may withhold it as a result of PRC pressure (Taipei Times, May 18).
Republican lawmakers, however, say that the White House will approve the arms sale before long. Representative Michael McCaul (R-TX), said at the Ketagalan Forum in Taipei on August 4 that he was "confident the president will forward soon another package to Congress with an additional $14 billion in critical military defense articles" (Focus Taiwan; Office of the President of the Republic of China (Taiwan), August 4).
Conclusion
Taiwan has shown impressive resilience in a challenging geopolitical environment. Its centrality to the AI industry has helped it avoid the fractiousness that has characterized the Trump administration's approach to its other allies and partners. Strong congressional support suggests Trump will greenlight the $14 billion arms sale, though likely not before Chinese leader Xi Jinping's expected September 24 state visit to Washington (Fox News, July 23).
All eyes will be carefully watching the progress of drone legislation through the Legislative Yuan in the meantime.
Unlike the arms sale, this is entirely under Taiwan's control. Whether it can pass smoothly--and inclusive of sufficient financial support for the industry--will be taken as a signal about Taipei's commitment to military modernization.
* * *
Matthew Fulco is a journalist and geopolitical analyst. He worked in Taipei from 2014-2022 and Shanghai from 2009-2014, and is now based in the United States. He formerly served as a Taiwan Contributor for the Economist Intelligence Unit and his writing has frequently appeared in The Japan Times and AmCham Taiwan's Taiwan Business Topics magazine.
* * *
Original text here: https://jamestown.org/taiwan-shows-resilience-in-trying-times/
[Category: ThinkTank]
* * *
Taiwan Shows Resilience in Trying Times
Executive Summary:
* Taiwan is showing resilience in the face of headwinds ranging from domestic politic strife, increased military pressure from the People's Republic of China (PRC), and uncertainty regarding U.S. political support.
* Taiwan's semiconductor sector is benefitting massively from the global artificial intelligence (AI) boom. Its gains contributed ... Show Full Article WASHINGTON, Aug. 7 -- The Jamestown Foundation issued the following commentary on Aug. 6, 2026, by journalist and geopolitical analyst Matthew Fulco in the foundation's China Brief Notes: * * * Taiwan Shows Resilience in Trying Times Executive Summary: * Taiwan is showing resilience in the face of headwinds ranging from domestic politic strife, increased military pressure from the People's Republic of China (PRC), and uncertainty regarding U.S. political support. * Taiwan's semiconductor sector is benefitting massively from the global artificial intelligence (AI) boom. Its gains contributedto Taiwan posting almost 13 percent quarterly GDP growth and reaching record stock market highs.
* In a bid to strengthen its relationship with the United States, Taiwan is investing $265 billion into American semiconductor manufacturing through Taiwan Semiconductor Manufacturing Corporation (TSMC). Taiwan has also hosted multiple high profile bipartisan congressional visits since the beginning of 2026.
* Domestic political strife, now centered around a proposed drone procurement bill, may affect U.S. assessments of Taiwan's will to fight. Taiwan is also waiting for the Trump administration to approve a delayed $14 billion arms sale, which will be critical to its defense against a potential military campaign by the PRC.
-
Taiwan today faces an unusually difficult geopolitical environment in which multifaceted pressure from a militarily powerful People's Republic of China (PRC) is mounting, domestic political strife is undermining defense readiness, and support from the United States is inconsistent. Taiwan has dealt with each of these challenges separately in the past, but this is the first time it must grapple with all three simultaneously.
Despite the difficult geopolitical situation, Taiwan has shown impressive resilience. The island nation has become a leader in producing hardware for artificial intelligence (AI), which has made it the world's fastest growing advanced economy. At the same time, Taiwanese officials have quietly worked with their American counterparts to deepen ties. The missing piece of the puzzle is its military resilience: legislation to support Taiwan's drone industry remains stalled and a large U.S. arms sales package is still pending. These delays continue to raise questions about Taiwan's defense readiness.
AI-Fueled Surge
As the world's chief producer of advanced semiconductors, Taiwan is benefiting hugely from the AI boom, arguably more than any other country. In the second quarter of the year, the Taiwanese economy grew at a torrid clip of almost 13 percent. This was the third consecutive quarter of double-digit expansion and the briskest quarterly rate since 1988. Taiwan's Directorate General of Budget Accounting and Statistics forecasts annual GDP growth this year to reach 9.6 percent, which would be the best performance since 2010 (National Statistics, Republic of China (Taiwan), accessed August 5).
Taiwan's foundry-centric semiconductor manufacturing model, best encapsulated by the Taiwan Semiconductor Manufacturing Company (TSMC), has never been more effective. Fabless designers at the vanguard of AI hardware, including U.S.-based Nvidia, AMD, and Broadcom, all rely on TSMC to fabricate their most advanced chips. Their demand for AI chips led TSMC to post record profits for the fifth consecutive quarter in July, with net income of roughly $22 billion. The company is projecting revenue to grow 40 percent this year to more than $171 billion (Taiwan Semiconductor Manufacturing Corporation [TSMC], accessed August 5).
The semiconductor sector's robust growth has coincided with Taiwan's stock exchange reaching a new all-time high. After the TAIEX reached 48,218 points in late June, the market cooled somewhat in the following weeks, before rallying back to roughly 43,000 points in early August (Unique Business News, June 23; Commercial Times, August 4).[1] This has apparently spurred a new wave of retail investors in Taiwan, where the number of people with brokerage accounts rose to a record 14.6 million in July, with investors under 30 accounting for nearly two-thirds of the increase over June (Taiwan Stock Exchange [TWSE], accessed August 5).
Deepening Ties With the United States
In tandem with its robust economic growth, Taiwan has managed to quietly strengthen ties with the United States this year. Taipei has done so by focusing on strategic industries in line with Trump administration priorities and avoiding criticism of President Trump, who has prioritized U.S.-PRC relations.
For the Trump administration, Taiwan's AI capabilities are among its most attractive assets. Taiwan is leveraging this competitive advantage effectively through both government-to-government initiatives and massive private investment. At the sixth Taiwan-U.S. Economic Prosperity Partnership Dialogue in February, the two countries agreed to a "strategic alignment for AI development" (AI) (Taiwan Ministry of Digital Affairs, February 2). In July, TSMC announced it would invest an additional $100 billion in its Arizona production facilities, bringing its total investment to $265 billion (UDN, July 17).
Drones are another area in which the United States and Taiwan are enhancing cooperation, though with more modest results than AI. In June, Taiwan's semi-governmental Industrial Technology Research Institute (ITRI) joined the Green UAS certification program of the Washington-based nonprofit Association for Uncrewed Vehicle Systems International (AUVSI), which verifies supply chain and cybersecurity compliance for commercial drones. The certification will facilitate the entry of more Taiwanese drone makers into the U.S. market (Industrial Technology Research Institute, June 4).
Bipartisan congressional delegations have made three visits to Taiwan so far in 2026, signaling continuity in the bilateral relationship at a crucial time. Drones came to the fore during the most recent visit (July 30-August 1), which was led by Representative Young Kim (R-CA). This time, the context was Taiwan's strained domestic politics and a stalled $6.6 billion drone procurement bill (Focus Taiwan, June 18). In a meeting with Taiwan President Lai Ching-te, Kim noted the intensifying military threat the PRC poses to Taiwan and urged Taipei to pass necessary legislation to support its drone industry, which has been delayed more than six months.[2] "Deterrence takes two to tango, so help us help you," she said (Office of the President of the Republic of China (Taiwan), July 31). After her meeting with Lai, Kim told reporters, "We hope that the Legislative Yuan can send a strong demand signal to build and buy as many drones as possible, and do it quickly" (Taipei Times, August 1).
The Art of the Delay
Representative Kim's comments well embody the sentiment among U.S. lawmakers that Taiwan needs to move quicker on drone legislation. While congressional support for Taiwan remains strong, the inability of the ruling and opposition parties to find a modus vivendi on the issue is causing some strain in the bilateral relationship. Skeptics of the U.S. security commitment to Taiwan can point to the drone issue and argue that Taipei does not take its own defense seriously, and therefore is not worth risking American blood and treasure to defend.
At the same time, the Trump administration has so far declined to approve a new arms sale to Taiwan, for undisclosed reasons. The package, estimated at $14 billion, has been delayed since early 2026. President Trump described the package as a "very good negotiating chip for us" with the PRC during a May Fox News interview, heightening speculation that his administration may withhold it as a result of PRC pressure (Taipei Times, May 18).
Republican lawmakers, however, say that the White House will approve the arms sale before long. Representative Michael McCaul (R-TX), said at the Ketagalan Forum in Taipei on August 4 that he was "confident the president will forward soon another package to Congress with an additional $14 billion in critical military defense articles" (Focus Taiwan; Office of the President of the Republic of China (Taiwan), August 4).
Conclusion
Taiwan has shown impressive resilience in a challenging geopolitical environment. Its centrality to the AI industry has helped it avoid the fractiousness that has characterized the Trump administration's approach to its other allies and partners. Strong congressional support suggests Trump will greenlight the $14 billion arms sale, though likely not before Chinese leader Xi Jinping's expected September 24 state visit to Washington (Fox News, July 23).
All eyes will be carefully watching the progress of drone legislation through the Legislative Yuan in the meantime.
Unlike the arms sale, this is entirely under Taiwan's control. Whether it can pass smoothly--and inclusive of sufficient financial support for the industry--will be taken as a signal about Taipei's commitment to military modernization.
* * *
Matthew Fulco is a journalist and geopolitical analyst. He worked in Taipei from 2014-2022 and Shanghai from 2009-2014, and is now based in the United States. He formerly served as a Taiwan Contributor for the Economist Intelligence Unit and his writing has frequently appeared in The Japan Times and AmCham Taiwan's Taiwan Business Topics magazine.
* * *
Original text here: https://jamestown.org/taiwan-shows-resilience-in-trying-times/
[Category: ThinkTank]
Hudson Institute Issues Commentary to New York Post: Gangbanging NY Police Chief Is a Prime Example of the Democratic Political Machine's Power
WASHINGTON, Aug. 7 -- Hudson Institute, a research organization that says it promotes leadership for a secure, free and prosperous future, issued the following commentary on Aug. 5, 2026, by senior fellow Liel Leibovitz to the New York Post:
* * *
Gangbanging NY Police Chief Is a Prime Example of the Democratic Political Machine's Power
There's a classic joke comedians love telling each other, about a family that walks into a talent agent's office and proceeds to do filthy, vile, unspeakable things to each other.
The talent agent watches in horror, then asks the family what their act is called.
The ... Show Full Article WASHINGTON, Aug. 7 -- Hudson Institute, a research organization that says it promotes leadership for a secure, free and prosperous future, issued the following commentary on Aug. 5, 2026, by senior fellow Liel Leibovitz to the New York Post: * * * Gangbanging NY Police Chief Is a Prime Example of the Democratic Political Machine's Power There's a classic joke comedians love telling each other, about a family that walks into a talent agent's office and proceeds to do filthy, vile, unspeakable things to each other. The talent agent watches in horror, then asks the family what their act is called. Thepunchline? They call themselves The Aristocrats.
Make that The Democrats: The party that used to run on mild stuff like abolishing the police and setting murderers and rapists free in the name of "social justice" has taken chaos to a whole new level, showing us what happens when you promote incompetent freaks whose only distinction is excelling at parroting the party's lunatic ideology.
Case study: Jennifer Lackard.
Despite -- or maybe precisely because of -- having zero experience in policing, Democrat-run Mount Vernon hired Lackard as its Deputy Police Commissioner, a fancy title that came with a $138,219 annual paycheck.
She was tasked with running the department's "Wellness Unit," a squad devoted to the Democrat mantra that criminals aren't evil or depraved but simply misunderstood souls who would abandon their dastardly ways if only some compassionate person treated their emotional boo-boos with a hot cup of cocoa rather than a long, hard prison sentence.
The fact that Lackard's husband did time in federal prison for dealing heroin, and that her son was a gangbanger who routinely ran into violent trouble, seemed to give none of her bosses any pause.
And Lackard rewarded their trust by breaking bad, giving us all proof -- grand, theatrical, irrefutable proof -- of the very real danger we all face when Democrats reject common sense and treat government as one big jobs program, hiring unvetted but loyal hustlers to key roles, experience and competence be dammed.
Lackard is now in custody for helping her 20-year-old son attempt to assassinate a rival.
According to the indictment, she coached her kid in the fine art of timing a hit job just right, accompanied him -- irony alert! -- to the Bronx Hall of Justice where he attempted to off his gang rival, and then drove the getaway car to boot.
Not even our most clinically progressive politicians -- thank the Lord -- have yet gone quite so far as Lackard, who chose to turn public office into a dime-store remake of "The Godfather."
But take a quick look at the workings of the Democratic Party machine, and it's not too hard to understand how a disastrous lackey like Lackard could rise so fast and so far.
By constantly championing measures like cashless bail that make the streets less safe, by coddling criminals with "restorative justice" rather than the real kind, and by promoting boisterous activists rather than capable officials with proven records, Democrats put us all at risk.
The same maddening scenario plays out wherever the party's in power.
Instead of policing, we get progressive propaganda.
Instead of leaders, we get zealots and kooks.
Instead of safety, we get more incitement, more violence and more brokenness.
Don't take my word for it: Just ask Damon Jones, publisher of Black Westchester Magazine.
"I am embarrassed as a black law enforcement officer to see the dysfunction in a city that has a black mayor, a majority black city council, a majority black police department that we have to see continuing dysfunction and just foolery in an organization that should be so professional," Jones told The Post.
"Unfortunately, we see this with Democrats that they put people in positions -- especially in law enforcement positions -- that they shouldn't be there."
Amen to that.
Lackard may be the most recent -- and most extreme -- example, but the problem she embodies is all too prevalent and all too ominous.
It's time to root it out before we allow even more dangerous maniacs to get their hands on the levers of power.
Read in New York Post (https://nypost.com/2026/08/05/opinion/gangbanging-ny-police-chief-is-a-prime-example-of-the-democratic-political-machines-power/).
* * *
At A Glance:
Liel Leibovitz is a senior Fellow at Hudson Institute. His work focuses on thinking about anti-Semitism as a national security threat.
* * *
Original text here: https://www.hudson.org/politics-government/gangbanging-ny-police-chief-prime-example-democratic-political-machines-power-liel-leibovitz
[Category: ThinkTank]
* * *
Gangbanging NY Police Chief Is a Prime Example of the Democratic Political Machine's Power
There's a classic joke comedians love telling each other, about a family that walks into a talent agent's office and proceeds to do filthy, vile, unspeakable things to each other.
The talent agent watches in horror, then asks the family what their act is called.
The ... Show Full Article WASHINGTON, Aug. 7 -- Hudson Institute, a research organization that says it promotes leadership for a secure, free and prosperous future, issued the following commentary on Aug. 5, 2026, by senior fellow Liel Leibovitz to the New York Post: * * * Gangbanging NY Police Chief Is a Prime Example of the Democratic Political Machine's Power There's a classic joke comedians love telling each other, about a family that walks into a talent agent's office and proceeds to do filthy, vile, unspeakable things to each other. The talent agent watches in horror, then asks the family what their act is called. Thepunchline? They call themselves The Aristocrats.
Make that The Democrats: The party that used to run on mild stuff like abolishing the police and setting murderers and rapists free in the name of "social justice" has taken chaos to a whole new level, showing us what happens when you promote incompetent freaks whose only distinction is excelling at parroting the party's lunatic ideology.
Case study: Jennifer Lackard.
Despite -- or maybe precisely because of -- having zero experience in policing, Democrat-run Mount Vernon hired Lackard as its Deputy Police Commissioner, a fancy title that came with a $138,219 annual paycheck.
She was tasked with running the department's "Wellness Unit," a squad devoted to the Democrat mantra that criminals aren't evil or depraved but simply misunderstood souls who would abandon their dastardly ways if only some compassionate person treated their emotional boo-boos with a hot cup of cocoa rather than a long, hard prison sentence.
The fact that Lackard's husband did time in federal prison for dealing heroin, and that her son was a gangbanger who routinely ran into violent trouble, seemed to give none of her bosses any pause.
And Lackard rewarded their trust by breaking bad, giving us all proof -- grand, theatrical, irrefutable proof -- of the very real danger we all face when Democrats reject common sense and treat government as one big jobs program, hiring unvetted but loyal hustlers to key roles, experience and competence be dammed.
Lackard is now in custody for helping her 20-year-old son attempt to assassinate a rival.
According to the indictment, she coached her kid in the fine art of timing a hit job just right, accompanied him -- irony alert! -- to the Bronx Hall of Justice where he attempted to off his gang rival, and then drove the getaway car to boot.
Not even our most clinically progressive politicians -- thank the Lord -- have yet gone quite so far as Lackard, who chose to turn public office into a dime-store remake of "The Godfather."
But take a quick look at the workings of the Democratic Party machine, and it's not too hard to understand how a disastrous lackey like Lackard could rise so fast and so far.
By constantly championing measures like cashless bail that make the streets less safe, by coddling criminals with "restorative justice" rather than the real kind, and by promoting boisterous activists rather than capable officials with proven records, Democrats put us all at risk.
The same maddening scenario plays out wherever the party's in power.
Instead of policing, we get progressive propaganda.
Instead of leaders, we get zealots and kooks.
Instead of safety, we get more incitement, more violence and more brokenness.
Don't take my word for it: Just ask Damon Jones, publisher of Black Westchester Magazine.
"I am embarrassed as a black law enforcement officer to see the dysfunction in a city that has a black mayor, a majority black city council, a majority black police department that we have to see continuing dysfunction and just foolery in an organization that should be so professional," Jones told The Post.
"Unfortunately, we see this with Democrats that they put people in positions -- especially in law enforcement positions -- that they shouldn't be there."
Amen to that.
Lackard may be the most recent -- and most extreme -- example, but the problem she embodies is all too prevalent and all too ominous.
It's time to root it out before we allow even more dangerous maniacs to get their hands on the levers of power.
Read in New York Post (https://nypost.com/2026/08/05/opinion/gangbanging-ny-police-chief-is-a-prime-example-of-the-democratic-political-machines-power/).
* * *
At A Glance:
Liel Leibovitz is a senior Fellow at Hudson Institute. His work focuses on thinking about anti-Semitism as a national security threat.
* * *
Original text here: https://www.hudson.org/politics-government/gangbanging-ny-police-chief-prime-example-democratic-political-machines-power-liel-leibovitz
[Category: ThinkTank]
Center on Budget & Policy Priorities: Four Years After the Inflation Reduction Act: Celebrating Clean Energy Progress and Looking Ahead
WASHINGTON, Aug. 7 -- The Center on Budget and Policy Priorities issued the following commentary on Aug. 6, 2026, by Mikaela Tajo, climate policy analyst on the Federal Fiscal Policy Team:
* * *
Four Years After the Inflation Reduction Act: Celebrating Clean Energy Progress and Looking Ahead
The 2022 Inflation Reduction Act (IRA) was one of the most significant climate laws in U.S. history. The IRA created and expanded clean energy tax incentives and established new programs for wind and solar projects in low-income communities, energy upgrades for affordable housing, climate resilience, environmental ... Show Full Article WASHINGTON, Aug. 7 -- The Center on Budget and Policy Priorities issued the following commentary on Aug. 6, 2026, by Mikaela Tajo, climate policy analyst on the Federal Fiscal Policy Team: * * * Four Years After the Inflation Reduction Act: Celebrating Clean Energy Progress and Looking Ahead The 2022 Inflation Reduction Act (IRA) was one of the most significant climate laws in U.S. history. The IRA created and expanded clean energy tax incentives and established new programs for wind and solar projects in low-income communities, energy upgrades for affordable housing, climate resilience, environmentaljustice, and more. While the Trump Administration and most congressional Republicans have pushed to gut the IRA's climate provisions -- and have taken other steps that have raised families' energy costs -- the IRA will have a lasting impact on the climate and energy landscape.
The IRA provided more than $145 billion in direct federal grants and loans to federal agencies, state, local, and tribal entities, nonprofits, and others for climate efforts; it also created and expanded tax credits for clean energy projects. Supported by the IRA's tax incentives, private and public entities invested more than $700 billion in clean energy projects between 2022 and 2025.
By design, many of these projects are in underinvested communities due in part to incentives like the Low-Income Bonus Credit, which gives an additional tax credit for small-scale clean energy projects in low-income areas, on tribal lands, or in federally subsidized housing. Groups leveraged the bonus credit to make $3.5 billion in investments across the country in 2023, the credit's first year.
The IRA's innovative tax credit system known as direct pay lets tax-exempt and public entities -- such as schools, nonprofits, and state and local governments -- use clean energy tax credits. For example, at least 82 schools across 17 states have received reimbursements for solar panels, heat pumps, and other clean energy projects that have improved aging facilities, reduced operating costs, and made schools healthier for students, according to one estimate using self-reported project data.
The IRA also provided billions of dollars for grants and loans that have supported clean energy development, lowered families' energy costs, improved the environment, and supported local economies. Importantly, roughly two-thirds of the grant funding for new IRA programs spent or obligated during the Biden Administration, meaning these foundational investments will continue to pay off. Examples include:
* Building state capacity for pollution reduction. States received much of the IRA's grant funding. For example, the IRA's Climate Pollution Reduction Grants program awarded $5 billion to state and local governments, tribes, and territories to develop and implement ambitious climate action plans through emissions-reduction projects. Sixteen states, all governed by Republicans, created climate action plans to reduce greenhouse gas emissions and other harmful air pollution for the first time, and many others updated their plans for the first time in a decade (see map).
State and local governments also used the grant funding to build significant project planning infrastructure that they can use to pursue future funding opportunities and continue reducing pollution and advancing clean energy progress.
* Investing in rural communities. The IRA supported the largest investment in rural electrification since the 1936 Rural Electrification Act. For instance, the Department of Agriculture awarded more than $400 million for renewable energy and energy efficiency projects in rural areas across the country.
* Expanding clean energy finance infrastructure. The IRA appropriated $11.7 billion for the Department of Energy's Loan Programs Office (LPO) to finance new clean energy projects, including projects that help lower the cost of energy and create economic opportunities in low-income and disadvantaged communities. For example, LPO provided a $72.8 million loan guarantee to finance the development of a solar system and microgrid on the tribal lands of the Viejas Band of the Kumeyaay Indians, which is expected to lower energy costs for the tribe.
Unfortunately, since early 2025, congressional Republicans and the Trump Administration have gutted much of the IRA's federal clean energy tax credits and federal funding for climate programs. These actions will raise households' energy costs, undermine economic opportunity in struggling communities, and hasten climate change at a time when households are struggling to meet their basic needs.
For example, the harmful 2025 Republican reconciliation law cut more than $280 billion in clean energy tax credits enacted in the IRA through 2034, $170 billion from efforts to cut vehicle pollution, and over $13 billion in grant and loan funding for environmental justice projects, improvements to the electric grid, and energy upgrades in affordable housing. One study estimates that households will face a 13 percent increase ($280 per year) in their energy bills by 2035 because of these cuts.
Additionally, the Administration has attacked IRA investments through grant cancellations, onerous delays and funding freezes, regulatory barriers, and agency staff and budget cuts. (Advocates are fighting the Trump Administration in court to release billions of dollars of frozen and cut clean energy funding, with some already winning court cases that have restored awarded funds.)
Cutting these funds is discouraging the private sector and state, local, and tribal governments from increasing investment in clean energy. For instance, businesses canceled or scaled back clean energy investments totaling more than $28 billion in 2025, according to one estimate. Energy policy analysts from Bloomberg have also estimated that projected clean energy installations will be more than 20 percent lower than they otherwise would have been if Republicans hadn't cut IRA investments.
While these actions likely will slow clean energy's replacement of fossil fuel generation, there's still reason for optimism about clean energy's future. Solar and wind, for example, are often the least expensive sources of new power generation, even without tax credits. As demand for energy grows, so will clean energy installations. Clean energy sources generated 90 percent of the new energy capacity added in the U.S. in 2025, and solar capacity is expected to grow between 100 percent and 235 percent through 2050, the U.S. Energy Information Administration estimates.
The IRA will continue to have other positive effects. For example, direct pay still exists in the tax code, so tax-exempt entities like state and local governments can continue to take advantage of robust incentives for technologies like geothermal heat pumps and battery storage.
The Inflation Reduction Act has shown the value in investing in the transition to clean energy. As policymakers consider future climate and energy proposals, they should prioritize those that will help the clean energy transition happen faster, more affordably, and more equitably.
* * *
Mikaela Tajo is a Climate Policy Analyst on the Federal Fiscal Policy team. Before coming to the Center, Mikaela worked at the Urban Institute as a Research Analyst focused on homelessness, racial equity, and community-engaged and participatory research methods. Mikaela received her bachelor's in political science and her master's in legislative affairs from the George Washington University in Washington, D.C.
* * *
Original text here: https://www.cbpp.org/blog/four-years-after-the-inflation-reduction-act-celebrating-clean-energy-progress-and-looking
[Category: ThinkTank]
* * *
Four Years After the Inflation Reduction Act: Celebrating Clean Energy Progress and Looking Ahead
The 2022 Inflation Reduction Act (IRA) was one of the most significant climate laws in U.S. history. The IRA created and expanded clean energy tax incentives and established new programs for wind and solar projects in low-income communities, energy upgrades for affordable housing, climate resilience, environmental ... Show Full Article WASHINGTON, Aug. 7 -- The Center on Budget and Policy Priorities issued the following commentary on Aug. 6, 2026, by Mikaela Tajo, climate policy analyst on the Federal Fiscal Policy Team: * * * Four Years After the Inflation Reduction Act: Celebrating Clean Energy Progress and Looking Ahead The 2022 Inflation Reduction Act (IRA) was one of the most significant climate laws in U.S. history. The IRA created and expanded clean energy tax incentives and established new programs for wind and solar projects in low-income communities, energy upgrades for affordable housing, climate resilience, environmentaljustice, and more. While the Trump Administration and most congressional Republicans have pushed to gut the IRA's climate provisions -- and have taken other steps that have raised families' energy costs -- the IRA will have a lasting impact on the climate and energy landscape.
The IRA provided more than $145 billion in direct federal grants and loans to federal agencies, state, local, and tribal entities, nonprofits, and others for climate efforts; it also created and expanded tax credits for clean energy projects. Supported by the IRA's tax incentives, private and public entities invested more than $700 billion in clean energy projects between 2022 and 2025.
By design, many of these projects are in underinvested communities due in part to incentives like the Low-Income Bonus Credit, which gives an additional tax credit for small-scale clean energy projects in low-income areas, on tribal lands, or in federally subsidized housing. Groups leveraged the bonus credit to make $3.5 billion in investments across the country in 2023, the credit's first year.
The IRA's innovative tax credit system known as direct pay lets tax-exempt and public entities -- such as schools, nonprofits, and state and local governments -- use clean energy tax credits. For example, at least 82 schools across 17 states have received reimbursements for solar panels, heat pumps, and other clean energy projects that have improved aging facilities, reduced operating costs, and made schools healthier for students, according to one estimate using self-reported project data.
The IRA also provided billions of dollars for grants and loans that have supported clean energy development, lowered families' energy costs, improved the environment, and supported local economies. Importantly, roughly two-thirds of the grant funding for new IRA programs spent or obligated during the Biden Administration, meaning these foundational investments will continue to pay off. Examples include:
* Building state capacity for pollution reduction. States received much of the IRA's grant funding. For example, the IRA's Climate Pollution Reduction Grants program awarded $5 billion to state and local governments, tribes, and territories to develop and implement ambitious climate action plans through emissions-reduction projects. Sixteen states, all governed by Republicans, created climate action plans to reduce greenhouse gas emissions and other harmful air pollution for the first time, and many others updated their plans for the first time in a decade (see map).
State and local governments also used the grant funding to build significant project planning infrastructure that they can use to pursue future funding opportunities and continue reducing pollution and advancing clean energy progress.
* Investing in rural communities. The IRA supported the largest investment in rural electrification since the 1936 Rural Electrification Act. For instance, the Department of Agriculture awarded more than $400 million for renewable energy and energy efficiency projects in rural areas across the country.
* Expanding clean energy finance infrastructure. The IRA appropriated $11.7 billion for the Department of Energy's Loan Programs Office (LPO) to finance new clean energy projects, including projects that help lower the cost of energy and create economic opportunities in low-income and disadvantaged communities. For example, LPO provided a $72.8 million loan guarantee to finance the development of a solar system and microgrid on the tribal lands of the Viejas Band of the Kumeyaay Indians, which is expected to lower energy costs for the tribe.
Unfortunately, since early 2025, congressional Republicans and the Trump Administration have gutted much of the IRA's federal clean energy tax credits and federal funding for climate programs. These actions will raise households' energy costs, undermine economic opportunity in struggling communities, and hasten climate change at a time when households are struggling to meet their basic needs.
For example, the harmful 2025 Republican reconciliation law cut more than $280 billion in clean energy tax credits enacted in the IRA through 2034, $170 billion from efforts to cut vehicle pollution, and over $13 billion in grant and loan funding for environmental justice projects, improvements to the electric grid, and energy upgrades in affordable housing. One study estimates that households will face a 13 percent increase ($280 per year) in their energy bills by 2035 because of these cuts.
Additionally, the Administration has attacked IRA investments through grant cancellations, onerous delays and funding freezes, regulatory barriers, and agency staff and budget cuts. (Advocates are fighting the Trump Administration in court to release billions of dollars of frozen and cut clean energy funding, with some already winning court cases that have restored awarded funds.)
Cutting these funds is discouraging the private sector and state, local, and tribal governments from increasing investment in clean energy. For instance, businesses canceled or scaled back clean energy investments totaling more than $28 billion in 2025, according to one estimate. Energy policy analysts from Bloomberg have also estimated that projected clean energy installations will be more than 20 percent lower than they otherwise would have been if Republicans hadn't cut IRA investments.
While these actions likely will slow clean energy's replacement of fossil fuel generation, there's still reason for optimism about clean energy's future. Solar and wind, for example, are often the least expensive sources of new power generation, even without tax credits. As demand for energy grows, so will clean energy installations. Clean energy sources generated 90 percent of the new energy capacity added in the U.S. in 2025, and solar capacity is expected to grow between 100 percent and 235 percent through 2050, the U.S. Energy Information Administration estimates.
The IRA will continue to have other positive effects. For example, direct pay still exists in the tax code, so tax-exempt entities like state and local governments can continue to take advantage of robust incentives for technologies like geothermal heat pumps and battery storage.
The Inflation Reduction Act has shown the value in investing in the transition to clean energy. As policymakers consider future climate and energy proposals, they should prioritize those that will help the clean energy transition happen faster, more affordably, and more equitably.
* * *
Mikaela Tajo is a Climate Policy Analyst on the Federal Fiscal Policy team. Before coming to the Center, Mikaela worked at the Urban Institute as a Research Analyst focused on homelessness, racial equity, and community-engaged and participatory research methods. Mikaela received her bachelor's in political science and her master's in legislative affairs from the George Washington University in Washington, D.C.
* * *
Original text here: https://www.cbpp.org/blog/four-years-after-the-inflation-reduction-act-celebrating-clean-energy-progress-and-looking
[Category: ThinkTank]
CSIS Issues Critical Questions Q&A: Bridging the Gap - LEO Satellite Internet and Human Rights
WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following Critical Questions Q&A on Aug. 6, 2026, involving Andrew Friedman, director and senior fellow in the Human Rights Initiative:
* * *
Bridging the Gap: LEO Satellite Internet and Human Rights
Just a few days into Russia's full-scale invasion, Ukraine's minister of digital transformation (now Minister of Defense) took to Twitter to ask Elon Musk for Starlink in Ukraine. Approximately 12 hours later, Musk confirmed that the world's most prominent low Earth orbit (LEO) satellite internet was now active in ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following Critical Questions Q&A on Aug. 6, 2026, involving Andrew Friedman, director and senior fellow in the Human Rights Initiative: * * * Bridging the Gap: LEO Satellite Internet and Human Rights Just a few days into Russia's full-scale invasion, Ukraine's minister of digital transformation (now Minister of Defense) took to Twitter to ask Elon Musk for Starlink in Ukraine. Approximately 12 hours later, Musk confirmed that the world's most prominent low Earth orbit (LEO) satellite internet was now active inthe country. Russia's intentional targeting of Ukrainian infrastructure over the past four years has caused inconsistent internet coverage and blackouts that have led to greater connectivity issues, creating crucial gaps in both the maintenance of a state and the conduct of a war in the modern era.
Predictable, high-speed internet, once seen as a nice-to-have, is increasingly imperative for nearly all aspects of life, including state functions, conduct of business, operations of civil society, and defense of human rights. LEO satellite internet can help to fill crucial connectivity gaps.
Q1: What is LEO satellite internet and what are its potential benefits?
A1: Geostationary orbit (GEO) satellite internet has been a mainstay of connectivity for approximately three decades. However, this method, with satellites orbiting at more than 22,000 miles from the Earth's surface, is extremely expensive to launch, is prone to interference, and can be slow when compared to broadband internet. LEO satellites orbit at 1,200 miles or less above sea level, limiting interference, making them less expensive to launch, and allowing for faster connectivity. While Amazon's LEO system (called Amazon Leo) has been tested at up to 1 gigabit per second, common GEO systems reach maximum speeds of 10-15 percent of that.
The predictability and speed of LEO satellite internet give it a key advantage for the continued functionality of government and the predictability of communications between individuals and groups without other access options. Such gaps can exist due to a lack of infrastructure in rural or remote areas, attacks by state or nonstate actors against internet infrastructure, or, in the case of internet shutdowns--a substantial and growing weapon of authoritarians--deliberate efforts to limit a population's connectivity. In short, LEO satellites remove the potential for infrastructure gaps by making their location dynamic and difficult to target, and they can operate largely free of government interference.
Q2: What are the risks of LEO satellite internet?
A2: While the risks of unchecked reliance on any technology are myriad and difficult to predict, they largely fall into two categories. The first is common for private-sector led critical infrastructure and the sometimes-mercurial nature of private industry and individuals, and the second is the danger of giving authoritarian actors a single target to suppress.
* Single Shutoff/Private Sector-Led Critical Infrastructure: Private sector-led critical infrastructure can create reliance on companies or individuals with unique incentive structures. In the case of certain technologies, this can give companies significant influence on vital aspects of governance or foreign policy operations. This is no less true with LEO satellite internet access than it would be with other utilities such as electricity or water. The dynamic and multilayered nature of individual and corporate relationships with governments adds an additional layer of consideration to this reality.
The speed with which Musk's SpaceX was able to make Starlink available in Ukraine demonstrates a private sector advantage, but the longer-term relationship tells a more complex story, especially when contrasted with the experience of other states. Several months after initially providing Starlink access in Ukraine, SpaceX reached out to the Pentagon requesting financing. This took place after the Ukrainian resistance had already become reliant on the technology. According to a Ukrainian presidential adviser, the technology had "helped [Ukraine] survive the most critical moments of war," and a senior U.S. military official judged the technology as "exceptionally effective on the battlefield."
Beyond funding is the potentially capricious nature of individuals when combined with their ability to serve as a single shutoff point for vital technology. More than a year after Russia's full-scale invasion, Musk intervened personally to limit Starlink access to the Ukrainian military in advance of a particular operation in Crimea.
This was further evidenced in Starlink's response to two tyrannical governments in January 2026. While the company opted to comply with an order from the government of Uganda to cease operations in advance of an internet shutdown in the days surrounding the country's election, Starlink remained one of the very few functional sources of internet protests in Iran happening at the same time. This was despite Starlink's legal prohibition in Iran and the ongoing nature of "one of the most extensive internet shutdowns ever recorded." While the Iranian internet shutdown did make Starlink less reliable and less functional, this was a product of changing tactics from the Iranian regime, not an active decision by SpaceX and its leadership. In short, Starlink chose to comply with one authoritarian government attempting to shut down the internet while ignoring the orders of another, leaving civil society without internet in one setting but keeping those in the other connected.
Critical infrastructure is, by its very definition, critical. When an actor beholden to incentives and constituencies outside of the public good controls critical infrastructure, gaps are created. In the case of LEO satellite internet, Starlink's actions in Ukraine and elsewhere have been a remarkable boon for human rights defenders and the continuity of a besieged government, but they have also demonstrated the dangers of such incentive gaps.
* Overreliance and Countermeasures: LEO satellite internet is already seeing the impacts of authoritarian innovation and cross learning. As mentioned above, while Starlink served as one of the few unblocked means of internet connectivity during the 2026 Iran protests, the Iranian government saw some success in limiting Starlink's efficacy. The "most likely culprit" of this limitation is a Russian-developed weapon known as Kalinka, which creates a "zone effect" that both limits the functionality of LEO satellites and makes it difficult to replace them in orbit.
Kalinka is not the only technology being used to combat LEO satellite internet. Both Russia and China have invested heavily in counterspace capabilities. Beijing has worked to develop lasers that can burn or blind satellite censors, causing malfunctions. Moscow has developed other weapons in addition to Kalinka that aim to jam signals from LEO satellite internet. Both the Iran protests and recent history of authoritarian collaboration create a high likelihood that any technologies that are effective in silencing dissent and facilitating repression will be available for use by other authoritarian actors.
This approach to the technology of strategic competition is not new, but it is particularly troubling when there is substantial or full reliance on an individual technology. Given Russia's approach to destroying Ukrainian infrastructure, there are precious few other options for Ukraine's military beyond LEO satellite internet. When a government such as Iran or Uganda blocks the internet in response to protests or in advance of a rigged election, civil society and activists have nowhere else to turn.
Q3: What can be done to address the risks posed by LEO satellite internet?
A3: Moving forward, focus should be on reversing the concerns raised above. Efforts should be made to improve the predictability of LEO satellite internet systems, both by treating access to internet as a public good and a human right--akin to a digital access to information--and by eliminating single shutoffs that can create havoc and undo human rights gains. Innovation should also be prioritized to continue to evade the growing use of internet shutdowns by authoritarian actors, who will inevitably continue to work diligently to limit communication, access to information, and avenues for advocacy.
To start, this effort requires an inclusive and international rights-based framework for access to the internet. UN Secretary General Antonio Guterres has already called for "universal access to the Internet by 2030 as a basic human right." This merely applies preexisting international human rights law documents, including the Universal Declaration of Human Rights and the International Covenant on Civil and Political Rights, both of which guarantee free expression, including the right to receive and impart information regardless of media or "frontiers." Such a rights-based approach would give individuals experiencing an internet shutdown a pathway for justice through international courts and create a cost for violators, labeling problematic states and authoritarian actors as violators of human rights, not merely espousing normative concern.
Second, as the Direct2Cell campaign makes clear, "a rights-protective . . . framework is necessary, but it is not sufficient." Positive commitments from operators, governments, and funders are vital to fulfill the positive requirements of individual access to the internet in conflict zones and humanitarian disasters.
Third, in line with a rights-based approach and positive commitments, efforts should be taken to bypass single-switch shutoffs for critical infrastructure, including LEO satellite internet. The World Liberty Congress, a collection of human rights defenders from across the globe, has prioritized this in its Tech for Freedom initiative, going as far as to create a manifesto against centralization and a decentralized social media site to prevent accounts being shut down for authoritarian purposes. The two largest LEO satellite internet companies are based in the United States, with smaller companies based in the EU and Canada. Just as weapons companies are subject to limitations and requirements given the importance of their wares in the conduct of foreign policy, so too can these companies, as they are subject to the legal restrictions of home countries. Their reliance on federal procurement dollars for continued operations creates added incentive for compliance.
Finally, the United States and other countries standing up for free expression should continue to incentivize innovation to improve the reliability, consistency, and invulnerability of LEO satellite internet systems. The authoritarian world will not stand still. Internet access is as valuable to human rights defenders and civil society as supply chains are to militaries. New ways to ensure continuous connectivity will be crucial to upholding this human right.
* * *
Original text here: https://www.csis.org/analysis/bridging-gap-leo-satellite-internet-and-human-rights
[Category: ThinkTank]
* * *
Bridging the Gap: LEO Satellite Internet and Human Rights
Just a few days into Russia's full-scale invasion, Ukraine's minister of digital transformation (now Minister of Defense) took to Twitter to ask Elon Musk for Starlink in Ukraine. Approximately 12 hours later, Musk confirmed that the world's most prominent low Earth orbit (LEO) satellite internet was now active in ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following Critical Questions Q&A on Aug. 6, 2026, involving Andrew Friedman, director and senior fellow in the Human Rights Initiative: * * * Bridging the Gap: LEO Satellite Internet and Human Rights Just a few days into Russia's full-scale invasion, Ukraine's minister of digital transformation (now Minister of Defense) took to Twitter to ask Elon Musk for Starlink in Ukraine. Approximately 12 hours later, Musk confirmed that the world's most prominent low Earth orbit (LEO) satellite internet was now active inthe country. Russia's intentional targeting of Ukrainian infrastructure over the past four years has caused inconsistent internet coverage and blackouts that have led to greater connectivity issues, creating crucial gaps in both the maintenance of a state and the conduct of a war in the modern era.
Predictable, high-speed internet, once seen as a nice-to-have, is increasingly imperative for nearly all aspects of life, including state functions, conduct of business, operations of civil society, and defense of human rights. LEO satellite internet can help to fill crucial connectivity gaps.
Q1: What is LEO satellite internet and what are its potential benefits?
A1: Geostationary orbit (GEO) satellite internet has been a mainstay of connectivity for approximately three decades. However, this method, with satellites orbiting at more than 22,000 miles from the Earth's surface, is extremely expensive to launch, is prone to interference, and can be slow when compared to broadband internet. LEO satellites orbit at 1,200 miles or less above sea level, limiting interference, making them less expensive to launch, and allowing for faster connectivity. While Amazon's LEO system (called Amazon Leo) has been tested at up to 1 gigabit per second, common GEO systems reach maximum speeds of 10-15 percent of that.
The predictability and speed of LEO satellite internet give it a key advantage for the continued functionality of government and the predictability of communications between individuals and groups without other access options. Such gaps can exist due to a lack of infrastructure in rural or remote areas, attacks by state or nonstate actors against internet infrastructure, or, in the case of internet shutdowns--a substantial and growing weapon of authoritarians--deliberate efforts to limit a population's connectivity. In short, LEO satellites remove the potential for infrastructure gaps by making their location dynamic and difficult to target, and they can operate largely free of government interference.
Q2: What are the risks of LEO satellite internet?
A2: While the risks of unchecked reliance on any technology are myriad and difficult to predict, they largely fall into two categories. The first is common for private-sector led critical infrastructure and the sometimes-mercurial nature of private industry and individuals, and the second is the danger of giving authoritarian actors a single target to suppress.
* Single Shutoff/Private Sector-Led Critical Infrastructure: Private sector-led critical infrastructure can create reliance on companies or individuals with unique incentive structures. In the case of certain technologies, this can give companies significant influence on vital aspects of governance or foreign policy operations. This is no less true with LEO satellite internet access than it would be with other utilities such as electricity or water. The dynamic and multilayered nature of individual and corporate relationships with governments adds an additional layer of consideration to this reality.
The speed with which Musk's SpaceX was able to make Starlink available in Ukraine demonstrates a private sector advantage, but the longer-term relationship tells a more complex story, especially when contrasted with the experience of other states. Several months after initially providing Starlink access in Ukraine, SpaceX reached out to the Pentagon requesting financing. This took place after the Ukrainian resistance had already become reliant on the technology. According to a Ukrainian presidential adviser, the technology had "helped [Ukraine] survive the most critical moments of war," and a senior U.S. military official judged the technology as "exceptionally effective on the battlefield."
Beyond funding is the potentially capricious nature of individuals when combined with their ability to serve as a single shutoff point for vital technology. More than a year after Russia's full-scale invasion, Musk intervened personally to limit Starlink access to the Ukrainian military in advance of a particular operation in Crimea.
This was further evidenced in Starlink's response to two tyrannical governments in January 2026. While the company opted to comply with an order from the government of Uganda to cease operations in advance of an internet shutdown in the days surrounding the country's election, Starlink remained one of the very few functional sources of internet protests in Iran happening at the same time. This was despite Starlink's legal prohibition in Iran and the ongoing nature of "one of the most extensive internet shutdowns ever recorded." While the Iranian internet shutdown did make Starlink less reliable and less functional, this was a product of changing tactics from the Iranian regime, not an active decision by SpaceX and its leadership. In short, Starlink chose to comply with one authoritarian government attempting to shut down the internet while ignoring the orders of another, leaving civil society without internet in one setting but keeping those in the other connected.
Critical infrastructure is, by its very definition, critical. When an actor beholden to incentives and constituencies outside of the public good controls critical infrastructure, gaps are created. In the case of LEO satellite internet, Starlink's actions in Ukraine and elsewhere have been a remarkable boon for human rights defenders and the continuity of a besieged government, but they have also demonstrated the dangers of such incentive gaps.
* Overreliance and Countermeasures: LEO satellite internet is already seeing the impacts of authoritarian innovation and cross learning. As mentioned above, while Starlink served as one of the few unblocked means of internet connectivity during the 2026 Iran protests, the Iranian government saw some success in limiting Starlink's efficacy. The "most likely culprit" of this limitation is a Russian-developed weapon known as Kalinka, which creates a "zone effect" that both limits the functionality of LEO satellites and makes it difficult to replace them in orbit.
Kalinka is not the only technology being used to combat LEO satellite internet. Both Russia and China have invested heavily in counterspace capabilities. Beijing has worked to develop lasers that can burn or blind satellite censors, causing malfunctions. Moscow has developed other weapons in addition to Kalinka that aim to jam signals from LEO satellite internet. Both the Iran protests and recent history of authoritarian collaboration create a high likelihood that any technologies that are effective in silencing dissent and facilitating repression will be available for use by other authoritarian actors.
This approach to the technology of strategic competition is not new, but it is particularly troubling when there is substantial or full reliance on an individual technology. Given Russia's approach to destroying Ukrainian infrastructure, there are precious few other options for Ukraine's military beyond LEO satellite internet. When a government such as Iran or Uganda blocks the internet in response to protests or in advance of a rigged election, civil society and activists have nowhere else to turn.
Q3: What can be done to address the risks posed by LEO satellite internet?
A3: Moving forward, focus should be on reversing the concerns raised above. Efforts should be made to improve the predictability of LEO satellite internet systems, both by treating access to internet as a public good and a human right--akin to a digital access to information--and by eliminating single shutoffs that can create havoc and undo human rights gains. Innovation should also be prioritized to continue to evade the growing use of internet shutdowns by authoritarian actors, who will inevitably continue to work diligently to limit communication, access to information, and avenues for advocacy.
To start, this effort requires an inclusive and international rights-based framework for access to the internet. UN Secretary General Antonio Guterres has already called for "universal access to the Internet by 2030 as a basic human right." This merely applies preexisting international human rights law documents, including the Universal Declaration of Human Rights and the International Covenant on Civil and Political Rights, both of which guarantee free expression, including the right to receive and impart information regardless of media or "frontiers." Such a rights-based approach would give individuals experiencing an internet shutdown a pathway for justice through international courts and create a cost for violators, labeling problematic states and authoritarian actors as violators of human rights, not merely espousing normative concern.
Second, as the Direct2Cell campaign makes clear, "a rights-protective . . . framework is necessary, but it is not sufficient." Positive commitments from operators, governments, and funders are vital to fulfill the positive requirements of individual access to the internet in conflict zones and humanitarian disasters.
Third, in line with a rights-based approach and positive commitments, efforts should be taken to bypass single-switch shutoffs for critical infrastructure, including LEO satellite internet. The World Liberty Congress, a collection of human rights defenders from across the globe, has prioritized this in its Tech for Freedom initiative, going as far as to create a manifesto against centralization and a decentralized social media site to prevent accounts being shut down for authoritarian purposes. The two largest LEO satellite internet companies are based in the United States, with smaller companies based in the EU and Canada. Just as weapons companies are subject to limitations and requirements given the importance of their wares in the conduct of foreign policy, so too can these companies, as they are subject to the legal restrictions of home countries. Their reliance on federal procurement dollars for continued operations creates added incentive for compliance.
Finally, the United States and other countries standing up for free expression should continue to incentivize innovation to improve the reliability, consistency, and invulnerability of LEO satellite internet systems. The authoritarian world will not stand still. Internet access is as valuable to human rights defenders and civil society as supply chains are to militaries. New ways to ensure continuous connectivity will be crucial to upholding this human right.
* * *
Original text here: https://www.csis.org/analysis/bridging-gap-leo-satellite-internet-and-human-rights
[Category: ThinkTank]
CSIS Issues Commentary: Old Friends, New Calculations - A Reset in China-North Korea Relations
WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Victor Cha, president of the Geopolitics and Foreign Policy Department, Director Bonny Lin and Associate Director Truly Tinsley, both of the China Power Project:
* * *
Old Friends, New Calculations: A Reset in China-North Korea Relations
In June 2026, for the first time in seven years, Chinese leader Xi Jinping visited Pyongyang to meet with Kim Jong-un. While Xi hosted over 20 leaders in the first half of the calendar year, this constituted the only trip abroad by the ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Victor Cha, president of the Geopolitics and Foreign Policy Department, Director Bonny Lin and Associate Director Truly Tinsley, both of the China Power Project: * * * Old Friends, New Calculations: A Reset in China-North Korea Relations In June 2026, for the first time in seven years, Chinese leader Xi Jinping visited Pyongyang to meet with Kim Jong-un. While Xi hosted over 20 leaders in the first half of the calendar year, this constituted the only trip abroad by theChinese leader so far in 2026. A flurry of activity followed: two exchanges of congratulatory letters between Xi and Kim in July and a visit by a close aide of each leader to the other country around mid-July.
China appears to seek deepened strategic alignment and ties with the Democratic People's Republic of Korea (DPRK) across the board, evidenced by wide coverage of Xi's desire to increase trade and diplomatic cooperation with Pyongyang since Kim Jong-un's visit to Beijing last year. However, one of the most underreported developments of this diplomacy was Xi's inclusion of military affairs in the listed areas for greater development between the two countries--an unprecedented first public summit readout. The drivers for deeper cooperation extend beyond variables internal to bilateral relations. Among these include (1) China's desires to lessen Russian influence on Pyongyang, (2) hedging bets against an unpredictable United States, (3) counterbalancing Japan's military buildup, and (4) strengthening Beijing's military options regarding Taiwan. It is unclear which of these factors motivates Xi the most but China's shift toward a stronger relationship with North Korea and the possibilities it brings are worth exploring.
Deepening Strategic Alignment and Ties
The June meeting between Xi and Kim was timed to showcase the 65th year of the China-DPRK Treaty of Friendship, Cooperation, and Mutual Assistance, China's mutual defense treaty with North Korea, providing an opportunity to "reset" relations. The visit also came shortly after Xi hosted U.S. President Donald Trump (May 14-15) and then Russian President Vladimir Putin (May 19-20) in Beijing, affording Xi opportunities to both portray and assess levels of unity among the three in the face of a disrupted geopolitical environment. Xi's willingness to make Pyongyang his first foreign stop in 2026 underscored the importance attached to reengagement with North Korea.
Xi's prioritization of the summit with Kim and the expansive nature of the commitments announced suggest an effort to regain influence over Pyongyang amid North Korea's deepening ties with Russia since the full-scale invasion of Ukraine. Shortly after landing in Pyongyang, Xi, stated that "the China-DPRK relationship stands at a new historical starting point." Xi promised "to maintain close strategic communication" with Kim and to strengthen high-level leadership exchanges as well as build mutual political trust.
Nested under the building of relations at the leadership level were several other proposals, the scope of which suggests a reset of relations. Xi proposed exchanges in "diplomacy, law enforcement, military affairs, and others." He also emphasized the need to expand practical cooperation, particularly in terms of development strategies and in areas such as "economy and trade, agriculture, construction, science and technology, and healthcare." Xi further listed the desire to "enhance exchanges and cooperation in education, culture and the arts, tourism, sports, media, youth affairs, subnational engagement and sister-city relation, and promised to "make full use of each side's strengths and resources" to support the exchanges and cooperation.
According to the Chinese readout, Kim echoed much of Xi's proposed reset. He called for expanded cooperation and exchanges on "economy and trade, infrastructure, science and technology, education, as well as people-to-people and cultural exchanges, and strengthen exchanges of experience and mutual learning through inter-party channels." North Korean media further described, in superlative language, that Kim and Xi created a "far reaching blueprint" to develop "into a model of the most powerful and strategic relations."
Kim also flattered Xi, calling him the "most respected guest of the DPRK people," and declared "the development of DPRK-China relations as the foremost strategic undertaking of the state." Again, this explicit prioritization matters given North Korea's ties with Russia, which has made Xi uneasy about losing influence over Pyongyang to Moscow.
After the June summit, two rare congratulatory letters and two high-level meetings followed in quick succession, with accompanying symbols of homage to the special nature of the relationship, thus putting in practice Xi's desire for a reset of relations (see Table 1).
* * *
Table 1: Recent High-Level China-North Korea Exchanges
* * *
De Facto Acceptance of Nuclear Status
The most significant omission from all of these high-level exchanges was any mention of North Korea's nuclear program from the Chinese side. Denuclearization of the Korean peninsula had previously been a staple of all of Beijing's statements on Korea. During Xi's last visit to North Korea in 2019, the Chinese readout made clear Beijing's intention to "play a positive and constructive role in achieving denuclearization of the Korean Peninsula." And at a UN Security Council meeting in 2023, China's Permanent Representative to the United Nations Zhang Jun reiterated that China's position remains "very clear. We are committed to the denuclearization of the peninsula."
The silence on North Korea's nuclear program now likely showcases, in Beijing's case, the expedient nature of the reset in relations. Unfortunately, it could signal China's de facto willingness to accept North Korea's nuclear status.
Chinese efforts to reset relations are clearly designed to dilute Russian influence over North Korea. Beijing always claims to the West that it has minimal influence over Pyongyang despite the regime's economic dependence on it, but China guards jealously whatever influence it does have over its neighbor. However, Chinese actions may be a case of too little, too late. Quantitively, since the start of the Ukraine war, Russia-DPRK high-level exchanges have significantly dwarfed those between North Korea and China--a historically unprecedented fact.
* * *
Figure 1: China-DPRK and Russia-DPRK High-Level Visits, 2017-2026
* * *
Enhancing Practical Economic Cooperation
Expanded cooperation in the economy, trade, and infrastructure was emphasized by both China and North Korea during the June meeting and will in many ways provide a key foundation for strengthening the relationship. Efforts to do so were already underway prior to the summit. In March, the two countries revived the Beijing-Pyongyang passenger trains that had been suspended since the start of the Covid-19 pandemic and resumed direct flights between Beijing and Pyongyang. In June, Chinese travel agencies began selling North Korea tourism packages amid speculation that Xi's visit will revitalize cross-border tourism, though as of this writing, North Korea has not resumed tourist visa issuance for Chinese nationals. In a change that reflects the new state of affairs among the trilateral relations, most tourists in North Korea are Russian, not Chinese, and the passenger trains are for specific groups, such as business visa holders. Xi clearly wants to change the situation, calling on "both sides [to] leverage the opportunity of the full reopening of border crossings and the resumption of civil aviation flights and international passenger trains to increase people-to-people exchanges and foster mutual interaction."
There has been a clear effort by the two sides to revive trade since the Covid lockdown. Two-way goods trade reached $2.7 billion in 2025, the highest total since the border closure in January 2020, and the first six months of 2026 are 19 percent ahead of the same period last year, according to Chinese customs data (see Figure 2). Total bilateral trade is still about half the level it was prior to UN sectoral sanctions in 2017--no longer enforced by China today--but the full border reopening Xi emphasized during his visit will further increase trade.
* * *
Figure 2: China-North Korea Monthly Trade, 2019-2026
* * *
The reset of relations provides a window into what North Korea hopes to get out of revived relations with China. Pak's July visit to China included site visits to the Beijing Rail Transit Command Center, the Port of Tianjin, China Resources Recycling Group's Green Low-Carbon Circular Economy Demonstration Base, and a motor plant in Tianjin. Pak also toured Tianjin's Haihe River, a popular tourist location. These site visits are unusual for senior officials from North Korea and were likely carefully selected to align with North Korea's economic development priorities.
Signals of Ramped-Up Military Cooperation
The most unexpected development of the summit was the prospect of military cooperation, which has seen very little activity over the past decade in contrast to the ramped-up cooperation between Russia and North Korea. As noted, Xi listed military affairs as an area of "enhanced exchange" at the June meeting. That same month, Chinese Defense Minister Dong Jun accompanied Xi and met with his North Korean counterpart, No Kwang-chol, the first such meeting since 1992. Xia Zhihe, political commissar of the People's Liberation Army (PLA) National Defense University, also led a group to Pyongyang in October 2025, reportedly the first PLA delegation to visit North Korea in six years.
The recent activity is noteworthy given China's historical ambivalence to military cooperation with North Korea. Aside from China's intervention in the Korean War and some basic arms transfers into the early 1980s, China has stayed cool to cooperation. For example, when Kim Il-sung asked in 1975 for missiles that could strike all of South Korea, China declined to sell, leaving North Korea to build its rocket force based on Soviet Scud technology instead. China's normalization of relations with South Korea in August 1992, which North Korea took as betrayal, froze military ties for a generation. What remained was largely ceremonial: friendship delegations, wreath-laying at war cemeteries and during anniversaries, and a lone 2011 port call at Wonsan by two Chinese naval ships.
Recent signals of China's interest in greater military coordination with North Korea have not yet led to bilateral military exercises. The closest the two militaries have come to this was indirect and with Russia. North Korea observed Russia's "Ocean-2024" naval drills, in which China also participated. And at China's September 2025 military parade, Xi was flanked by Putin and Kim Jong-un as the PLA showcased several key military capabilities. However, the competition for North Korea's influence could press the two larger patrons further in this direction. Russia, for example, has expressed support for North Korea to join China-Russia military exercises to enable trilateral activities. Even if Beijing were lukewarm to the idea, it may feel obligated to support it to avoid disaffection with Pyongyang.
It is unclear what Xi Jinping may have in mind for deepening military cooperation. It could mean involving North Korea in China-led or China-Russia joint military exercises or greater Chinese support as North Korea develops various military capabilities. This could include modern air defenses, drones, and dual-use components such as microelectronics and machine tools to modernize North Korea's arms industrial base. If the relationship further deepens, China could consider providing fighter jets and other advanced assets.
While the North Korea readout did not mention Xi's suggestion of military exchanges, Kim, in his banquet speech to Xi, said the two sides are united on the basis of a "common ideology and militant friendship." And when Wang was in Pyongyang, Jo Yong-won, deputy chief of the Central Committee of the Workers' Party of Korea, noted that the two sides needed to "further strengthen militant unity, support and solidarity and steadily intensify and develop the friendly and cooperative relations."
North Korea may be willing to coordinate military activities with China if it occurs in the context of a China-Russia military exercise and Russia is on board too. On July 3, just days before China and Russia's 2026 joint maritime exercises off the coast of the Chinese city Qingdao, North Korea showed off its advancing naval capability with Kim personally observing North Korea's new 5,000-ton destroyer, the Kang Kon, launch 12 cruise missiles from its vertical launch system. The timing of the test is interesting and could be viewed as all three countries displaying naval capabilities at approximately the same time. A critical signpost will be when North Korea begins observing or joining more China-Russia military exercises.
Another security issue to watch is North Korea's stance on giving China access to the Tumen River, a strategic waterway that runs through the border between China, Russia, and North Korea. Russia and North Korea control the last 15 kilometers of the river, which empties into the Sea of Japan. If North Korea grants China access to the Tumen River, this would not only provide China's northeastern provinces access to an important maritime shipping route, but it could also provide the Chinese military with direct access to the Sea of Japan. China has been vying for access to this stretch of the river for decades without success. The joint statement from Putin and Xi's most recent summit in May highlighted the issue of Chinese access, with both sides reaffirming "their commitment to continuing trilateral consultations with North Korea" on the issue. However, it appears there has been no further movement on the issue since the summit besides unconfirmed reporting that China may have discussed it with Kim during their bilateral meeting in June.
Drivers of Continued China-North Korea Cooperation
Four factors likely drive China's desire to deepen alignment and relations with North Korea. First, Beijing wants to offset growing Russian influence over Pyongyang and ensure that its own influence is dominant. The potential military exchanges provide a channel into the Korean People's Army that China has lacked since 2019 and provides a window into what Russia may be transferring. At the same time, Beijing is not naive and recognizes that the two countries still harbor substantial mutual mistrust and need to rebuild relations through more exchanges as well as practical cooperation in less-sensitive areas.
A second potential motive is signaling to Washington ahead of a possible Trump-Kim summit. By deepening ties in public, Beijing reminds Washington that no deal with Pyongyang gets far without Chinese intervention. Rumors that Xi may have brought a message from Trump to Kim during his visit adds to that perception. At the same time, China has likely not forgotten President Trump's threats of "fire and fury" against North Korea during the first Trump administration and likely wants to also remind the United States that President Trump's use of military force against Iran's nuclear program is not appropriate for North Korea.
The third is pressure on what Beijing views to be a more problematic and "militarist" Tokyo. China is wary of not only Japan's greater investment in military capabilities, but also deeper U.S.-Japan defense cooperation. China could be looking to strengthen strategic and military ties with North Korea to offset perceived strengthened U.S.-Japan ties. Since January, China and North Korea have begun criticizing Japan using the same terms, such as "neo-militarism." China could be looking to leverage its growing military partnership with North Korea to increase pressure on Japan and other U.S. allies in the region. It remains to be seen what more support North Korea could provide China in terms of its anti-Japan campaign.
Fourth, Xi's push for deeper security ties may also reflect a bid for greater support from North Korea on Taiwan. If U.S. forces are tied up in a contingency on the Korean Peninsula, a distracted United States may give China an advantage toward its goals of taking over Taiwan. With this scenario in mind, it's possible China may be planning to help North Korea build up its forces to become a greater threat to the United States, and to increase the success of a dual contingency.
* * *
Victor Cha is president of the Geopolitics and Foreign Policy Department and Korea chair at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Bonny Lin is director of the China Power Project and senior adviser at CSIS. Truly Tinsley is the associate director of the China Power Project at CSIS. Andy Lim is deputy director and fellow with the Korea Chair at CSIS.
* * *
Original text here: https://www.csis.org/analysis/old-friends-new-calculations-reset-china-north-korea-relations
[Category: ThinkTank]
* * *
Old Friends, New Calculations: A Reset in China-North Korea Relations
In June 2026, for the first time in seven years, Chinese leader Xi Jinping visited Pyongyang to meet with Kim Jong-un. While Xi hosted over 20 leaders in the first half of the calendar year, this constituted the only trip abroad by the ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Victor Cha, president of the Geopolitics and Foreign Policy Department, Director Bonny Lin and Associate Director Truly Tinsley, both of the China Power Project: * * * Old Friends, New Calculations: A Reset in China-North Korea Relations In June 2026, for the first time in seven years, Chinese leader Xi Jinping visited Pyongyang to meet with Kim Jong-un. While Xi hosted over 20 leaders in the first half of the calendar year, this constituted the only trip abroad by theChinese leader so far in 2026. A flurry of activity followed: two exchanges of congratulatory letters between Xi and Kim in July and a visit by a close aide of each leader to the other country around mid-July.
China appears to seek deepened strategic alignment and ties with the Democratic People's Republic of Korea (DPRK) across the board, evidenced by wide coverage of Xi's desire to increase trade and diplomatic cooperation with Pyongyang since Kim Jong-un's visit to Beijing last year. However, one of the most underreported developments of this diplomacy was Xi's inclusion of military affairs in the listed areas for greater development between the two countries--an unprecedented first public summit readout. The drivers for deeper cooperation extend beyond variables internal to bilateral relations. Among these include (1) China's desires to lessen Russian influence on Pyongyang, (2) hedging bets against an unpredictable United States, (3) counterbalancing Japan's military buildup, and (4) strengthening Beijing's military options regarding Taiwan. It is unclear which of these factors motivates Xi the most but China's shift toward a stronger relationship with North Korea and the possibilities it brings are worth exploring.
Deepening Strategic Alignment and Ties
The June meeting between Xi and Kim was timed to showcase the 65th year of the China-DPRK Treaty of Friendship, Cooperation, and Mutual Assistance, China's mutual defense treaty with North Korea, providing an opportunity to "reset" relations. The visit also came shortly after Xi hosted U.S. President Donald Trump (May 14-15) and then Russian President Vladimir Putin (May 19-20) in Beijing, affording Xi opportunities to both portray and assess levels of unity among the three in the face of a disrupted geopolitical environment. Xi's willingness to make Pyongyang his first foreign stop in 2026 underscored the importance attached to reengagement with North Korea.
Xi's prioritization of the summit with Kim and the expansive nature of the commitments announced suggest an effort to regain influence over Pyongyang amid North Korea's deepening ties with Russia since the full-scale invasion of Ukraine. Shortly after landing in Pyongyang, Xi, stated that "the China-DPRK relationship stands at a new historical starting point." Xi promised "to maintain close strategic communication" with Kim and to strengthen high-level leadership exchanges as well as build mutual political trust.
Nested under the building of relations at the leadership level were several other proposals, the scope of which suggests a reset of relations. Xi proposed exchanges in "diplomacy, law enforcement, military affairs, and others." He also emphasized the need to expand practical cooperation, particularly in terms of development strategies and in areas such as "economy and trade, agriculture, construction, science and technology, and healthcare." Xi further listed the desire to "enhance exchanges and cooperation in education, culture and the arts, tourism, sports, media, youth affairs, subnational engagement and sister-city relation, and promised to "make full use of each side's strengths and resources" to support the exchanges and cooperation.
According to the Chinese readout, Kim echoed much of Xi's proposed reset. He called for expanded cooperation and exchanges on "economy and trade, infrastructure, science and technology, education, as well as people-to-people and cultural exchanges, and strengthen exchanges of experience and mutual learning through inter-party channels." North Korean media further described, in superlative language, that Kim and Xi created a "far reaching blueprint" to develop "into a model of the most powerful and strategic relations."
Kim also flattered Xi, calling him the "most respected guest of the DPRK people," and declared "the development of DPRK-China relations as the foremost strategic undertaking of the state." Again, this explicit prioritization matters given North Korea's ties with Russia, which has made Xi uneasy about losing influence over Pyongyang to Moscow.
After the June summit, two rare congratulatory letters and two high-level meetings followed in quick succession, with accompanying symbols of homage to the special nature of the relationship, thus putting in practice Xi's desire for a reset of relations (see Table 1).
* * *
Table 1: Recent High-Level China-North Korea Exchanges
* * *
De Facto Acceptance of Nuclear Status
The most significant omission from all of these high-level exchanges was any mention of North Korea's nuclear program from the Chinese side. Denuclearization of the Korean peninsula had previously been a staple of all of Beijing's statements on Korea. During Xi's last visit to North Korea in 2019, the Chinese readout made clear Beijing's intention to "play a positive and constructive role in achieving denuclearization of the Korean Peninsula." And at a UN Security Council meeting in 2023, China's Permanent Representative to the United Nations Zhang Jun reiterated that China's position remains "very clear. We are committed to the denuclearization of the peninsula."
The silence on North Korea's nuclear program now likely showcases, in Beijing's case, the expedient nature of the reset in relations. Unfortunately, it could signal China's de facto willingness to accept North Korea's nuclear status.
Chinese efforts to reset relations are clearly designed to dilute Russian influence over North Korea. Beijing always claims to the West that it has minimal influence over Pyongyang despite the regime's economic dependence on it, but China guards jealously whatever influence it does have over its neighbor. However, Chinese actions may be a case of too little, too late. Quantitively, since the start of the Ukraine war, Russia-DPRK high-level exchanges have significantly dwarfed those between North Korea and China--a historically unprecedented fact.
* * *
Figure 1: China-DPRK and Russia-DPRK High-Level Visits, 2017-2026
* * *
Enhancing Practical Economic Cooperation
Expanded cooperation in the economy, trade, and infrastructure was emphasized by both China and North Korea during the June meeting and will in many ways provide a key foundation for strengthening the relationship. Efforts to do so were already underway prior to the summit. In March, the two countries revived the Beijing-Pyongyang passenger trains that had been suspended since the start of the Covid-19 pandemic and resumed direct flights between Beijing and Pyongyang. In June, Chinese travel agencies began selling North Korea tourism packages amid speculation that Xi's visit will revitalize cross-border tourism, though as of this writing, North Korea has not resumed tourist visa issuance for Chinese nationals. In a change that reflects the new state of affairs among the trilateral relations, most tourists in North Korea are Russian, not Chinese, and the passenger trains are for specific groups, such as business visa holders. Xi clearly wants to change the situation, calling on "both sides [to] leverage the opportunity of the full reopening of border crossings and the resumption of civil aviation flights and international passenger trains to increase people-to-people exchanges and foster mutual interaction."
There has been a clear effort by the two sides to revive trade since the Covid lockdown. Two-way goods trade reached $2.7 billion in 2025, the highest total since the border closure in January 2020, and the first six months of 2026 are 19 percent ahead of the same period last year, according to Chinese customs data (see Figure 2). Total bilateral trade is still about half the level it was prior to UN sectoral sanctions in 2017--no longer enforced by China today--but the full border reopening Xi emphasized during his visit will further increase trade.
* * *
Figure 2: China-North Korea Monthly Trade, 2019-2026
* * *
The reset of relations provides a window into what North Korea hopes to get out of revived relations with China. Pak's July visit to China included site visits to the Beijing Rail Transit Command Center, the Port of Tianjin, China Resources Recycling Group's Green Low-Carbon Circular Economy Demonstration Base, and a motor plant in Tianjin. Pak also toured Tianjin's Haihe River, a popular tourist location. These site visits are unusual for senior officials from North Korea and were likely carefully selected to align with North Korea's economic development priorities.
Signals of Ramped-Up Military Cooperation
The most unexpected development of the summit was the prospect of military cooperation, which has seen very little activity over the past decade in contrast to the ramped-up cooperation between Russia and North Korea. As noted, Xi listed military affairs as an area of "enhanced exchange" at the June meeting. That same month, Chinese Defense Minister Dong Jun accompanied Xi and met with his North Korean counterpart, No Kwang-chol, the first such meeting since 1992. Xia Zhihe, political commissar of the People's Liberation Army (PLA) National Defense University, also led a group to Pyongyang in October 2025, reportedly the first PLA delegation to visit North Korea in six years.
The recent activity is noteworthy given China's historical ambivalence to military cooperation with North Korea. Aside from China's intervention in the Korean War and some basic arms transfers into the early 1980s, China has stayed cool to cooperation. For example, when Kim Il-sung asked in 1975 for missiles that could strike all of South Korea, China declined to sell, leaving North Korea to build its rocket force based on Soviet Scud technology instead. China's normalization of relations with South Korea in August 1992, which North Korea took as betrayal, froze military ties for a generation. What remained was largely ceremonial: friendship delegations, wreath-laying at war cemeteries and during anniversaries, and a lone 2011 port call at Wonsan by two Chinese naval ships.
Recent signals of China's interest in greater military coordination with North Korea have not yet led to bilateral military exercises. The closest the two militaries have come to this was indirect and with Russia. North Korea observed Russia's "Ocean-2024" naval drills, in which China also participated. And at China's September 2025 military parade, Xi was flanked by Putin and Kim Jong-un as the PLA showcased several key military capabilities. However, the competition for North Korea's influence could press the two larger patrons further in this direction. Russia, for example, has expressed support for North Korea to join China-Russia military exercises to enable trilateral activities. Even if Beijing were lukewarm to the idea, it may feel obligated to support it to avoid disaffection with Pyongyang.
It is unclear what Xi Jinping may have in mind for deepening military cooperation. It could mean involving North Korea in China-led or China-Russia joint military exercises or greater Chinese support as North Korea develops various military capabilities. This could include modern air defenses, drones, and dual-use components such as microelectronics and machine tools to modernize North Korea's arms industrial base. If the relationship further deepens, China could consider providing fighter jets and other advanced assets.
While the North Korea readout did not mention Xi's suggestion of military exchanges, Kim, in his banquet speech to Xi, said the two sides are united on the basis of a "common ideology and militant friendship." And when Wang was in Pyongyang, Jo Yong-won, deputy chief of the Central Committee of the Workers' Party of Korea, noted that the two sides needed to "further strengthen militant unity, support and solidarity and steadily intensify and develop the friendly and cooperative relations."
North Korea may be willing to coordinate military activities with China if it occurs in the context of a China-Russia military exercise and Russia is on board too. On July 3, just days before China and Russia's 2026 joint maritime exercises off the coast of the Chinese city Qingdao, North Korea showed off its advancing naval capability with Kim personally observing North Korea's new 5,000-ton destroyer, the Kang Kon, launch 12 cruise missiles from its vertical launch system. The timing of the test is interesting and could be viewed as all three countries displaying naval capabilities at approximately the same time. A critical signpost will be when North Korea begins observing or joining more China-Russia military exercises.
Another security issue to watch is North Korea's stance on giving China access to the Tumen River, a strategic waterway that runs through the border between China, Russia, and North Korea. Russia and North Korea control the last 15 kilometers of the river, which empties into the Sea of Japan. If North Korea grants China access to the Tumen River, this would not only provide China's northeastern provinces access to an important maritime shipping route, but it could also provide the Chinese military with direct access to the Sea of Japan. China has been vying for access to this stretch of the river for decades without success. The joint statement from Putin and Xi's most recent summit in May highlighted the issue of Chinese access, with both sides reaffirming "their commitment to continuing trilateral consultations with North Korea" on the issue. However, it appears there has been no further movement on the issue since the summit besides unconfirmed reporting that China may have discussed it with Kim during their bilateral meeting in June.
Drivers of Continued China-North Korea Cooperation
Four factors likely drive China's desire to deepen alignment and relations with North Korea. First, Beijing wants to offset growing Russian influence over Pyongyang and ensure that its own influence is dominant. The potential military exchanges provide a channel into the Korean People's Army that China has lacked since 2019 and provides a window into what Russia may be transferring. At the same time, Beijing is not naive and recognizes that the two countries still harbor substantial mutual mistrust and need to rebuild relations through more exchanges as well as practical cooperation in less-sensitive areas.
A second potential motive is signaling to Washington ahead of a possible Trump-Kim summit. By deepening ties in public, Beijing reminds Washington that no deal with Pyongyang gets far without Chinese intervention. Rumors that Xi may have brought a message from Trump to Kim during his visit adds to that perception. At the same time, China has likely not forgotten President Trump's threats of "fire and fury" against North Korea during the first Trump administration and likely wants to also remind the United States that President Trump's use of military force against Iran's nuclear program is not appropriate for North Korea.
The third is pressure on what Beijing views to be a more problematic and "militarist" Tokyo. China is wary of not only Japan's greater investment in military capabilities, but also deeper U.S.-Japan defense cooperation. China could be looking to strengthen strategic and military ties with North Korea to offset perceived strengthened U.S.-Japan ties. Since January, China and North Korea have begun criticizing Japan using the same terms, such as "neo-militarism." China could be looking to leverage its growing military partnership with North Korea to increase pressure on Japan and other U.S. allies in the region. It remains to be seen what more support North Korea could provide China in terms of its anti-Japan campaign.
Fourth, Xi's push for deeper security ties may also reflect a bid for greater support from North Korea on Taiwan. If U.S. forces are tied up in a contingency on the Korean Peninsula, a distracted United States may give China an advantage toward its goals of taking over Taiwan. With this scenario in mind, it's possible China may be planning to help North Korea build up its forces to become a greater threat to the United States, and to increase the success of a dual contingency.
* * *
Victor Cha is president of the Geopolitics and Foreign Policy Department and Korea chair at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Bonny Lin is director of the China Power Project and senior adviser at CSIS. Truly Tinsley is the associate director of the China Power Project at CSIS. Andy Lim is deputy director and fellow with the Korea Chair at CSIS.
* * *
Original text here: https://www.csis.org/analysis/old-friends-new-calculations-reset-china-north-korea-relations
[Category: ThinkTank]
CSIS Issues Commentary: How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Nikita Shah, senior fellow with the Intelligence, National Security, and Technology Program:
* * *
How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
In the week since July 26, concurrent cyberattacks have impacted water facilities across at least six U.S. states. Reflecting the scope and seriousness of the risk posed to the water sector, the attacks prompted the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory it had ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Nikita Shah, senior fellow with the Intelligence, National Security, and Technology Program: * * * How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved In the week since July 26, concurrent cyberattacks have impacted water facilities across at least six U.S. states. Reflecting the scope and seriousness of the risk posed to the water sector, the attacks prompted the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory it hadpublished just days before, warning operators to disconnect operational or publicly exposed technology from the internet as soon as possible. Although these attacks are yet to be attributed, signs point towards Iranian cyber actors as the likely culprit. This provides a useful moment to evaluate how Iran has used its cyber capabilities so far in its conflict against the United States and Israel, and whether this constitutes an escalation.
This commentary provides an updated analysis as to how Iran's use of cyber operations and capabilities have evolved since the conflict broke out in February 2026, revisiting the author's initial take. So far, the original assumptions have held: Iranian cyber actors are active, but shaped and likely still constrained by various environmental and doctrinal factors. That said, there has been a discernible uptick in Iran's cyber operations over the last 4-6 months; Iran's cyber apparatus has firmly re-geared in direct support and alignment with Iran's war effort against the United States, Israel, and regional rivals, and is using cyber operations to shape the operating environment in a way that is favorable to its interests.
Key Strategic Trends in Iran's Use of Cyber Capabilities
Since the outbreak of the conflict, Iran has undertaken a broader shift in its military strategy, centered around asymmetric means to frustrate its global and regional adversaries. This includes exploiting the vulnerabilities of U.S. and Israeli conventional forces, cutting off access to the Strait of Hormuz to impose costs to global energy markets and regional rivals, and a concerted information warfare campaign to shape global narratives on the conflict. Across each of these methods, but especially Iran's information warfare objectives, cyber capabilities are a critical enabler, and they have played a vital part in causing attrition to Iran's adversaries, as well as enabling power projection across the globe.
This has been reflected in a notable uptick in Iran's cyber operations since March 2026. This has encompassed a broad range of activity, including (1) cyber espionage, (2) establishing technical accesses, (3) disruptive cyber operations, (4) cyber-enabled information operations, (5) deploying spyware, and (6) conflict-themed cyber crime. Three strategic trends have become apparent from this increased activity:
1. Iran's Cyber Apparatus Has Directly Shifted to Support Its War Effort
In the earlier stages of the conflict, Iran's cyber activity could be understood primarily as "opportunistic disruption," whereby Iran's operators were utilizing existing technical accesses they had already accumulated to throw quick, unsophisticated cyber operations at targets with weak cyber defenses, or conducting hacktivist attacks (such as website defacements, or hack-and-leak attacks) with little strategic effect. This was accompanied by some cyber espionage, and cyber-enabled information operations.
That activity has since evolved into a more concerted approach that reflects a recalibrated cyber apparatus, working in clearer and direct strategic alignment with Iran's wartime objectives. Nowhere is this better reflected than through the prioritization of cyber espionage operations to support Iran's war effort. In July 2026, it was discovered that Iran had hacked SS7 (a technical protocol to route data through telecommunications networks) to identify the location of U.S. troops stationed in the Middle East, directly informing kinetic strikes against them that resulted in injuries. Iran has also targeted high-value U.S. and Israeli senior officials with the likely intent to understand strategic decisionmaking, particularly pertaining to diplomatic negotiations with the United States to end the conflict. Iran has hacked security cameras in various countries, both to inform kinetic targeting by drones or missiles, and to assess post-strike damage. Reporting also points to an expansion of Iranian cyber espionage against the aviation, aerospace, defense manufacturing, telecommunications,, and space and satellite sectors--all of which are relevant to the defense industrial base critical to the conflict.
2. Iran Is Using Offensive Cyber Capabilities to Proactively Shape the Operating Environment
Just as the United States and Israel reportedly used offensive cyber capabilities to degrade Iran's infrastructure in the opening stages of this conflict, Iran has also been utilizing cyber capabilities to shape the operative environment to its advantage. Iranian cyber actors are increasingly waging cyberattacks for information warfare purposes; Iran considers the key battlespace to be in the information domain, and from a doctrinal perspective, it relies upon information warfare as a key lever to achieve strategic depth by projecting power far beyond its borders.
Iran's cyber-enabled information operations can be viewed in two ways: breadth and depth of targets. In terms of breadth, Iranian cyber actors have conducted various disruptive cyber operations across the United States (e.g., targeting local government systems in St Joseph's Country, Indiana, in April, breaching tank readers at gas stations in May, hacking water facilities in California in June, and likely conducting the current attack against U.S. water facilities), whilst pro-Iranian hacktivist groups have continuously attacked organizations across the Middle East. In terms of depth, Iranian cyber actors and hacktivists have persistently targeted cyberattacks against U.S. and Israeli current and former officials--particularly hack-and-leak attacks--including against former Prime Minister Naftali Bennett and former Israeli Army Chief of Staff Herzl Halevi, and the alleged publishing of personal data of U.S. Marines stationed in the Gulf and Israeli military and intelligence personnel. It is worth noting that the presence of hacktivists itself is important, demonstrating another core component of Iran's cyber ecosystem mobilizing in direct alignment with the war effort.
Though these appear as disruptive cyber operations at first glance, itIt is crucial to understand these attacks through an information warfare lens: First, they play into Iranian goals of power projection to different global audiences, specifically by demonstrating an ability to reach directly into the Israeli ruling elite and U.S. military, chipping away at their reputations of competence and security. Second, by generating a constant layer of friction that is felt by ordinary citizens and businesses, Iran generates a sense of fear, division, and chaos. In other words, the secondary, informational impact of these cyberattacks is key--it enables Iran to impose cost on its adversaries from a distance, shaping a more favorable information environment for Iran, particularly where it results in reduced support for the conflict among global, online audiences.
Artificial intelligence (AI) has been a vital enabling tool for Iran in shaping the environment. Recent threat intelligence reporting has shown that Iran has deployed AI across the full life cycle of its cyber and information operations, including initial target reconnaissance (e.g., actors linked to the Islamic Revolutionary Guard Corps using ChatGPT in 2024 to understand the technological components impacted in the current U.S. water facility attacks), code writing and malware developing, social engineering operations, and content creation and manipulation. Using AI has served to fundamentally enhance Iran's modus operandi when it comes to cyber capabilities, by boosting their speed, scale, reach, and impact, rather than by changing the "strategic logic" with which Iran operates in a conflict.
3. Iran Is Still Operating in a Relatively Constrained Way
The scale of the cyberattacks against U.S. water facilities is certainly concerning. If the actor behind them is in fact Iran (which is not yet confirmed), these attacks have the potential to be escalatory; they disabled critical systems in the U.S. homeland, representing a threat to U.S. public safety. However, it is vital to contextualize these attacks within a much longer-term pattern of how Iran operates against its adversaries. Iran has a history of targeting multiple sectors of U.S. critical infrastructure with disruptive operations--especially the water sector (going back to at least 2013)--both in peacetime, and now, during conflict. As detailed above, this would not be the first time Iran has targeted U.S. infrastructure during this conflict.
Indeed, across the full spectrum of Iranian cyber operations so far in this conflict, Iran is effectively operating to the same blueprint that it used in the 12-day conflict with Israel in 2025: Its target base is similar (i.e., the defense industrial base, Israeli infrastructure, the satellite and space sector, and high-value individuals), its use of state actors and hacktivists is the same, and its tactics are remarkably similar, including cyber espionage, hacking cameras, low-sophistication attacks, and information operations. Together, these methods reflect Iran's use of cyber operations to shape and augment the broader operating environment to its advantage, and to inform subsequent operations, whether for kinetic or cognitive effect. An important feature of Iranian military doctrine is "calibrated escalation"--moves that extend or exacerbate the conflict, but without reaching full-scale war. If the cyberattacks on U.S. water facilities are in fact attributed to Iran, they should be viewed as "opportunistic targeting," inflicting costs on its adversaries, but without reaching the heights of escalation that other attack types have (including kinetic attacks).
Moreover, Iran may still be subject to operating constraints. Reporting in March 2026 suggested Israel and the United States had struck the Islamic Revolutionary Guard Corps' cyber and information warfare headquarters early on in their campaign, and Iran also shut down its own domestic internet, impeding its ability to conduct cyber operations. But it is unknown how much of Iran's cyber capacity has been restored. The uptick of cyber activity described in this commentary demonstrates that more of Iran's cyber apparatus is online than previously thought--perhaps due to Iran's "two-tier" internet, which created a parallel structure for elite and state internet access to stay online even as domestic connections were severed, as well as suggestions that Iran is using satellite connectivity to resume its operations. However, U.S. air strikes have hit Iranian telecommunications infrastructure since the conflict began, including one attack in July that took out 100 telecommunications masts, disrupting internet services in southern Iran. Disruptions to Iranian's digital infrastructure will no doubt be a significant constraint upon Iran's ability to operate in cyberspace.
Conclusion
It is still too early to fully understand how organizational changes in Iran's military forces (from a conventional military into a decentralized web of operational commands) trickles down into its cyber apparatus. Nonetheless, its reliance upon asymmetric warfare is clear, as well as where cyber capabilities generate important advantage.
Iran has come to realize that its stranglehold over the Strait of Hormuz is its primary leverage. Cyber capabilities play a vital (albeit secondary) and enabling role: They help to inform, refine, and amply Iran's kinetic and economic activity, while also proactively shaping the conditions Iran prefers to operate in, giving Iran important strategic advantage. If the cyberattacks on the U.S. water sector are confirmed to be from Iran, they should be evaluated relative to Iran's wider capabilities--as another asymmetric lever of statecraft that Iran can pull to attrite the United States--but still a constrained lever, relative to its use of drones, missiles, or economic leverage. Iran's doctrine, degraded physical infrastructure, and historic patterns of targeting are important constraints on how it decides to deploy cyber operations, and will be for some time.
Iran's cyber operators will likely be working on preparing new technical accesses, and possibly new cyber capabilities to leverage, should the conflict continue over the longer-term or negotiations falter. The key strategic point on the horizon for the United States is the midterms, noting that Iran has a history of targeting U.S. elections and campaigns. This makes the need for cyber resilience across U.S. infrastructure critical. One point of success from the U.S. water facility attacks was that officials quickly reverted to manual processes and reserves, preventing impact upon public water supply. Sustained vigilance will be critical: As stated by Iranian hacktivist group Handala in April 2026, "the cyber war did not begin with the military conflict, and it will not end with any military ceasefire."
* * *
Original text here: https://www.csis.org/analysis/how-tehrans-use-cyber-operations-us-iran-conflict-has-evolved
[Category: ThinkTank]
* * *
How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
In the week since July 26, concurrent cyberattacks have impacted water facilities across at least six U.S. states. Reflecting the scope and seriousness of the risk posed to the water sector, the attacks prompted the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory it had ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Nikita Shah, senior fellow with the Intelligence, National Security, and Technology Program: * * * How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved In the week since July 26, concurrent cyberattacks have impacted water facilities across at least six U.S. states. Reflecting the scope and seriousness of the risk posed to the water sector, the attacks prompted the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory it hadpublished just days before, warning operators to disconnect operational or publicly exposed technology from the internet as soon as possible. Although these attacks are yet to be attributed, signs point towards Iranian cyber actors as the likely culprit. This provides a useful moment to evaluate how Iran has used its cyber capabilities so far in its conflict against the United States and Israel, and whether this constitutes an escalation.
This commentary provides an updated analysis as to how Iran's use of cyber operations and capabilities have evolved since the conflict broke out in February 2026, revisiting the author's initial take. So far, the original assumptions have held: Iranian cyber actors are active, but shaped and likely still constrained by various environmental and doctrinal factors. That said, there has been a discernible uptick in Iran's cyber operations over the last 4-6 months; Iran's cyber apparatus has firmly re-geared in direct support and alignment with Iran's war effort against the United States, Israel, and regional rivals, and is using cyber operations to shape the operating environment in a way that is favorable to its interests.
Key Strategic Trends in Iran's Use of Cyber Capabilities
Since the outbreak of the conflict, Iran has undertaken a broader shift in its military strategy, centered around asymmetric means to frustrate its global and regional adversaries. This includes exploiting the vulnerabilities of U.S. and Israeli conventional forces, cutting off access to the Strait of Hormuz to impose costs to global energy markets and regional rivals, and a concerted information warfare campaign to shape global narratives on the conflict. Across each of these methods, but especially Iran's information warfare objectives, cyber capabilities are a critical enabler, and they have played a vital part in causing attrition to Iran's adversaries, as well as enabling power projection across the globe.
This has been reflected in a notable uptick in Iran's cyber operations since March 2026. This has encompassed a broad range of activity, including (1) cyber espionage, (2) establishing technical accesses, (3) disruptive cyber operations, (4) cyber-enabled information operations, (5) deploying spyware, and (6) conflict-themed cyber crime. Three strategic trends have become apparent from this increased activity:
1. Iran's Cyber Apparatus Has Directly Shifted to Support Its War Effort
In the earlier stages of the conflict, Iran's cyber activity could be understood primarily as "opportunistic disruption," whereby Iran's operators were utilizing existing technical accesses they had already accumulated to throw quick, unsophisticated cyber operations at targets with weak cyber defenses, or conducting hacktivist attacks (such as website defacements, or hack-and-leak attacks) with little strategic effect. This was accompanied by some cyber espionage, and cyber-enabled information operations.
That activity has since evolved into a more concerted approach that reflects a recalibrated cyber apparatus, working in clearer and direct strategic alignment with Iran's wartime objectives. Nowhere is this better reflected than through the prioritization of cyber espionage operations to support Iran's war effort. In July 2026, it was discovered that Iran had hacked SS7 (a technical protocol to route data through telecommunications networks) to identify the location of U.S. troops stationed in the Middle East, directly informing kinetic strikes against them that resulted in injuries. Iran has also targeted high-value U.S. and Israeli senior officials with the likely intent to understand strategic decisionmaking, particularly pertaining to diplomatic negotiations with the United States to end the conflict. Iran has hacked security cameras in various countries, both to inform kinetic targeting by drones or missiles, and to assess post-strike damage. Reporting also points to an expansion of Iranian cyber espionage against the aviation, aerospace, defense manufacturing, telecommunications,, and space and satellite sectors--all of which are relevant to the defense industrial base critical to the conflict.
2. Iran Is Using Offensive Cyber Capabilities to Proactively Shape the Operating Environment
Just as the United States and Israel reportedly used offensive cyber capabilities to degrade Iran's infrastructure in the opening stages of this conflict, Iran has also been utilizing cyber capabilities to shape the operative environment to its advantage. Iranian cyber actors are increasingly waging cyberattacks for information warfare purposes; Iran considers the key battlespace to be in the information domain, and from a doctrinal perspective, it relies upon information warfare as a key lever to achieve strategic depth by projecting power far beyond its borders.
Iran's cyber-enabled information operations can be viewed in two ways: breadth and depth of targets. In terms of breadth, Iranian cyber actors have conducted various disruptive cyber operations across the United States (e.g., targeting local government systems in St Joseph's Country, Indiana, in April, breaching tank readers at gas stations in May, hacking water facilities in California in June, and likely conducting the current attack against U.S. water facilities), whilst pro-Iranian hacktivist groups have continuously attacked organizations across the Middle East. In terms of depth, Iranian cyber actors and hacktivists have persistently targeted cyberattacks against U.S. and Israeli current and former officials--particularly hack-and-leak attacks--including against former Prime Minister Naftali Bennett and former Israeli Army Chief of Staff Herzl Halevi, and the alleged publishing of personal data of U.S. Marines stationed in the Gulf and Israeli military and intelligence personnel. It is worth noting that the presence of hacktivists itself is important, demonstrating another core component of Iran's cyber ecosystem mobilizing in direct alignment with the war effort.
Though these appear as disruptive cyber operations at first glance, itIt is crucial to understand these attacks through an information warfare lens: First, they play into Iranian goals of power projection to different global audiences, specifically by demonstrating an ability to reach directly into the Israeli ruling elite and U.S. military, chipping away at their reputations of competence and security. Second, by generating a constant layer of friction that is felt by ordinary citizens and businesses, Iran generates a sense of fear, division, and chaos. In other words, the secondary, informational impact of these cyberattacks is key--it enables Iran to impose cost on its adversaries from a distance, shaping a more favorable information environment for Iran, particularly where it results in reduced support for the conflict among global, online audiences.
Artificial intelligence (AI) has been a vital enabling tool for Iran in shaping the environment. Recent threat intelligence reporting has shown that Iran has deployed AI across the full life cycle of its cyber and information operations, including initial target reconnaissance (e.g., actors linked to the Islamic Revolutionary Guard Corps using ChatGPT in 2024 to understand the technological components impacted in the current U.S. water facility attacks), code writing and malware developing, social engineering operations, and content creation and manipulation. Using AI has served to fundamentally enhance Iran's modus operandi when it comes to cyber capabilities, by boosting their speed, scale, reach, and impact, rather than by changing the "strategic logic" with which Iran operates in a conflict.
3. Iran Is Still Operating in a Relatively Constrained Way
The scale of the cyberattacks against U.S. water facilities is certainly concerning. If the actor behind them is in fact Iran (which is not yet confirmed), these attacks have the potential to be escalatory; they disabled critical systems in the U.S. homeland, representing a threat to U.S. public safety. However, it is vital to contextualize these attacks within a much longer-term pattern of how Iran operates against its adversaries. Iran has a history of targeting multiple sectors of U.S. critical infrastructure with disruptive operations--especially the water sector (going back to at least 2013)--both in peacetime, and now, during conflict. As detailed above, this would not be the first time Iran has targeted U.S. infrastructure during this conflict.
Indeed, across the full spectrum of Iranian cyber operations so far in this conflict, Iran is effectively operating to the same blueprint that it used in the 12-day conflict with Israel in 2025: Its target base is similar (i.e., the defense industrial base, Israeli infrastructure, the satellite and space sector, and high-value individuals), its use of state actors and hacktivists is the same, and its tactics are remarkably similar, including cyber espionage, hacking cameras, low-sophistication attacks, and information operations. Together, these methods reflect Iran's use of cyber operations to shape and augment the broader operating environment to its advantage, and to inform subsequent operations, whether for kinetic or cognitive effect. An important feature of Iranian military doctrine is "calibrated escalation"--moves that extend or exacerbate the conflict, but without reaching full-scale war. If the cyberattacks on U.S. water facilities are in fact attributed to Iran, they should be viewed as "opportunistic targeting," inflicting costs on its adversaries, but without reaching the heights of escalation that other attack types have (including kinetic attacks).
Moreover, Iran may still be subject to operating constraints. Reporting in March 2026 suggested Israel and the United States had struck the Islamic Revolutionary Guard Corps' cyber and information warfare headquarters early on in their campaign, and Iran also shut down its own domestic internet, impeding its ability to conduct cyber operations. But it is unknown how much of Iran's cyber capacity has been restored. The uptick of cyber activity described in this commentary demonstrates that more of Iran's cyber apparatus is online than previously thought--perhaps due to Iran's "two-tier" internet, which created a parallel structure for elite and state internet access to stay online even as domestic connections were severed, as well as suggestions that Iran is using satellite connectivity to resume its operations. However, U.S. air strikes have hit Iranian telecommunications infrastructure since the conflict began, including one attack in July that took out 100 telecommunications masts, disrupting internet services in southern Iran. Disruptions to Iranian's digital infrastructure will no doubt be a significant constraint upon Iran's ability to operate in cyberspace.
Conclusion
It is still too early to fully understand how organizational changes in Iran's military forces (from a conventional military into a decentralized web of operational commands) trickles down into its cyber apparatus. Nonetheless, its reliance upon asymmetric warfare is clear, as well as where cyber capabilities generate important advantage.
Iran has come to realize that its stranglehold over the Strait of Hormuz is its primary leverage. Cyber capabilities play a vital (albeit secondary) and enabling role: They help to inform, refine, and amply Iran's kinetic and economic activity, while also proactively shaping the conditions Iran prefers to operate in, giving Iran important strategic advantage. If the cyberattacks on the U.S. water sector are confirmed to be from Iran, they should be evaluated relative to Iran's wider capabilities--as another asymmetric lever of statecraft that Iran can pull to attrite the United States--but still a constrained lever, relative to its use of drones, missiles, or economic leverage. Iran's doctrine, degraded physical infrastructure, and historic patterns of targeting are important constraints on how it decides to deploy cyber operations, and will be for some time.
Iran's cyber operators will likely be working on preparing new technical accesses, and possibly new cyber capabilities to leverage, should the conflict continue over the longer-term or negotiations falter. The key strategic point on the horizon for the United States is the midterms, noting that Iran has a history of targeting U.S. elections and campaigns. This makes the need for cyber resilience across U.S. infrastructure critical. One point of success from the U.S. water facility attacks was that officials quickly reverted to manual processes and reserves, preventing impact upon public water supply. Sustained vigilance will be critical: As stated by Iranian hacktivist group Handala in April 2026, "the cyber war did not begin with the military conflict, and it will not end with any military ceasefire."
* * *
Original text here: https://www.csis.org/analysis/how-tehrans-use-cyber-operations-us-iran-conflict-has-evolved
[Category: ThinkTank]
CSIS Issues Commentary: End of 'As-Is' - Could AI Undermine Software's U.S. Legal Shield?
WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Sezaneh Seymour, adjunct fellow (non-resident) in the Strategic Technologies Program:
* * *
The End of "As-Is": Could AI Undermine Software's U.S. Legal Shield?
Every August, the cybersecurity industry descends on Las Vegas for hacker summer camp. Walk the expo floor and you will hear bold pitches about AI: autonomous agents that find previously undiscovered vulnerabilities en masse and models that patch zero-days before attackers can weaponize them. AI-assisted security ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Sezaneh Seymour, adjunct fellow (non-resident) in the Strategic Technologies Program: * * * The End of "As-Is": Could AI Undermine Software's U.S. Legal Shield? Every August, the cybersecurity industry descends on Las Vegas for hacker summer camp. Walk the expo floor and you will hear bold pitches about AI: autonomous agents that find previously undiscovered vulnerabilities en masse and models that patch zero-days before attackers can weaponize them. AI-assisted securitycapabilities have become a marquee selling point.
But purchase the product, and the story flips in the fine print. Buried in nearly every End User License Agreement (EULA) is a familiar disclaimer: The software is provided "as-is," with all defects, errors, and vulnerabilities disclaimed to the fullest extent permitted by law.
The software industry cannot have it both ways. Either AI can reliably identify major classes of vulnerabilities before products ship, or software defects remain an inherently unforeseeable reality that justifies broad legal immunity. Technology companies increasingly market the former to investors and customers. Yet much of U.S. software liability law still assumes the latter.
The tension extends beyond corporate marketing and into public policy. The 2023 National Cybersecurity Strategy proposed shifting liability onto software vendors on the theory that they, not their customers, are best positioned to prevent defects. In March 2026, the new Cyber Strategy dropped that proposal entirely in favor of deregulation and voluntary private sector action instead. Ironically, that reversal came just as AI made the case for software liability more compelling. Vendors began publicly demonstrating that AI could find defects more reliably, and cheaply enough, to make those precautions reasonable to expect.
The Myth of Digital Exceptionalism
Software occupies a privileged legal space that no other consumer product enjoys. A lamp that catches fire, a car with a defective airbag, or a harness that snaps under normal use all fall under strict product liability, a body of tort law that holds manufacturers responsible for defects regardless of fault. Software largely escaped that fate. Courts and legislators treat software as a licensed service rather than a product, letting it hide behind contract law instead. That exceptional treatment was a deliberate policy choice, and it is built on three core justifications that AI now undermines entirely:
1. Fear of Chilling Innovation: The software licensing regime that took shape in the 1990s assumed a fragile, nascent tech sector that could not survive the litigation costs strict liability would impose. Bugs became the acceptable price of a fast-moving industry that regulators did not want to strangle. But whatever validity that argument held in the 1990s is gone: An information technology sector that commands more than 36 percent of the S&P 500's total market weight is no longer a fragile infant in need of a legal shield.
2. Infinite Complexity: While a car has roughly 30,000 physical parts, software contains tens of millions of lines of code with trillions of execution paths. Because mapping every possible configuration of user clicks and background processes was a mathematical impossibility for human teams, courts accepted that exhaustive testing was infeasible. That is why courts have long held software to a lower bar than physical goods. Frontier AI shatters that defense: Automated tools can now stress test millions of these complex, branching paths simultaneously and at superhuman speed.
3. The Ubiquitous Nature of the EULA: Boilerplate "as-is" language repeated in nearly every license shifted almost all operational risk onto the end user, whether that user was a hospital network or an individual consumer. Courts deferred to these contractual liability shields largely because others did, and because the first two justifications gave them cover to do so.
All three justifications rest on one assumption: that finding defects before shipment costs too much to demand it. Frontier AI breaks that assumption, which means the policy logic built on it should be revisited as well.
Revisiting the Economics of Negligence
The law has a relevant formula. Judge Learned Hand laid it out in United States v. Carroll Towing Co.: A party is negligent when the burden of precautions (B) is less than the probability of harm (P) multiplied by the gravity of that harm (L). In other words, negligence occurs when B < P x L.
For 70 years, software vendors won this equation by default. The cost of hiring armies of elite software engineers to manually audit tens of millions of lines of code before every release sat far above the expected harm (P x L) from almost any individual bug.
That reality shifted almost overnight as autonomous security agents proved they could outpace human security teams. In late 2024, Google's Project Zero and DeepMind unveiled "Big Sleep," an AI agent that uncovered a zero-day flaw in SQLite, a database engine embedded in billions of devices and renowned for being one of the most obsessively audited codebases. By mid-2025, Big Sleep escalated from catching unreleased bugs to thwarting an active zero-day exploit in the wild moments before threat actors could weaponize it.
What makes these capabilities so game-changing is not just their sophistication, but also their radically lower cost. University of Illinois researchers evaluating AI security agents showed that running automated exploit attempts against real-world vulnerabilities costs as little as $8.80 per run using off-the-shelf models such as GPT-4, a fraction of what human security researchers would cost. A security startup called Depthfirst used a commercially available model to surface 21 previously unknown vulnerabilities in FFmpeg, a piece of software embedded in an enormous share of the internet's video infrastructure, for roughly $1,000 in total compute. None of this required a multi-billion-dollar custom research lab.
Vendors are not hiding this new capability. They lead with it in earnings calls and product announcements, and they pitch it to customers and shareholders as a competitive advantage. That is precisely why the Hand formula should flip the policy conversation, even where it has not yet flipped it in a courtroom. Courts have enforced "as-is" disclaimers for decades because the assumption beneath them made that deference reasonable. Slapping an "as-is" disclaimer on software after running--or opting not to run--a low-cost precautionary scan that a company actively markets as effective should no longer be a valid legal shield. Contractual disclaimers cannot erase basic duty of care. When code is headed into hospital networks or power utilities, attempting to disclaim liability away from preventable defects becomes a deliberate choice to offload catastrophic risk onto the public. Under the formula's own terms, that is negligence in substance, even if not yet in doctrine.
The Economics of Software Development
The total economics of building software have shifted as much as the economics of finding the bugs in it. AI does not just lower the cost of security auditing; it slashes the overall cost of routine software engineering by 30-50 percent. Historically, vendors starved security budgets, which typically represent under 11 percent of enterprise cyber spending, to protect core engineering margins. That trade-off no longer holds. Capital freed up by automated development easily covers continuous AI verification, allowing vendors to ship more secure software while still expanding profit margins.
But freed-up capital does not spend itself on defense. A corporation's obligation, as Milton Friedman once famously argued, is to maximize value for its shareholders. In a competitive market, the vendor that pockets the savings wins; the vendor that spends the savings on security nobody requires does not. That creates a closing window. The same automation that makes bug hunting cheap for defenders will make exploit development cheap for attackers. Whoever automates first keeps the advantage. Left alone, the market pushes that race toward the attacker. The Hand formula says the legal shield should fall. The economics of agentic development say it must fall now while the cost advantage still belongs to the people finding bugs, rather than to the people exploiting them.
None of this happens on its own. Courts have little appetite to unwind decades of enforced boilerplate text case by case. And doing so unevenly, jurisdiction by jurisdiction, would produce years of unpredictable litigation before any vendor changed its behavior. That is the argument for legislative action: Congress can update the assumption on purpose, and on a deliberate timeline, instead of leaving it to a slow accumulation of individual lawsuits to do it by accident.
Reevaluating the Policy Toolbox: Reasonable Process over Perfect Code
The harder conceptual work has already been done. Government experts and legal scholars have developed a substantial body of work on software liability and secure development. The Office of the National Cyber Director's 2024 symposia helped map the policy architecture. The Secure Software Development Framework (SSDF), developed by the National Institute of Standards and Technology (NIST), already provides a practical baseline. Legal scholars have spent years developing theories of software liability and proposing ways to implement it. Internationally, the European Union has made the same conceptual leap: Its revised Product Liability Directive, adopted in 2024, formally classifies software as a product, though enforcement will not begin until member states transpose it by the end of 2026.
Together, that work points toward a framework centered on reasonable process, not perfect code:
* Revisit secure-development safe harbors. Congress should codify protections for software producers that follow recognized secure-development practices. Vendors that follow frameworks such as NIST's SSDF, document AI-assisted security testing, and maintain a risk-based remediation process for serious flaws should receive meaningful protection from punitive damages and overbroad tort claims. The goal should be to reward diligence, not punish every residual bug.
* Target liability at gross inaction. Legal exposure should focus on willful blindness, not ordinary imperfection. Companies that decline to use standard automated scanning tools, ignore high-confidence findings, or repeatedly ship code with known or easily discoverable failure modes into critical infrastructure and other high-consequence environments. The strongest cases will not involve close calls. They will involve precautions that were cheap, available, and widely understood, but still ignored.
* Protect open-source maintainers while holding commercial integrators responsible. Any serious framework should distinguish between volunteers maintaining open-source code and commercial vendors monetizing enterprise products. Liability should rest primarily with the firms that package, deploy, and profit from software without conducting basic automated due diligence. That is usually where the capacity to test, remediate, and internalize the cost of failure sits.
Policymakers do not need to invent a new theory of software liability, nor should they demand flawless code. They only need to revisit the outdated economic assumptions that justified software's exceptional treatment and build from the body of work already on the shelf. When the cost of precaution drops toward zero, the justification and legal case for disclaimed liability collapses. The economics and the technology have changed. Our legal expectations should change with them.
* * *
Original text here: https://www.csis.org/analysis/end-could-ai-undermine-softwares-us-legal-shield
[Category: ThinkTank]
* * *
The End of "As-Is": Could AI Undermine Software's U.S. Legal Shield?
Every August, the cybersecurity industry descends on Las Vegas for hacker summer camp. Walk the expo floor and you will hear bold pitches about AI: autonomous agents that find previously undiscovered vulnerabilities en masse and models that patch zero-days before attackers can weaponize them. AI-assisted security ... Show Full Article WASHINGTON, Aug. 7 -- The Center for Strategic and International Studies issued the following commentary on Aug. 6, 2026, by Sezaneh Seymour, adjunct fellow (non-resident) in the Strategic Technologies Program: * * * The End of "As-Is": Could AI Undermine Software's U.S. Legal Shield? Every August, the cybersecurity industry descends on Las Vegas for hacker summer camp. Walk the expo floor and you will hear bold pitches about AI: autonomous agents that find previously undiscovered vulnerabilities en masse and models that patch zero-days before attackers can weaponize them. AI-assisted securitycapabilities have become a marquee selling point.
But purchase the product, and the story flips in the fine print. Buried in nearly every End User License Agreement (EULA) is a familiar disclaimer: The software is provided "as-is," with all defects, errors, and vulnerabilities disclaimed to the fullest extent permitted by law.
The software industry cannot have it both ways. Either AI can reliably identify major classes of vulnerabilities before products ship, or software defects remain an inherently unforeseeable reality that justifies broad legal immunity. Technology companies increasingly market the former to investors and customers. Yet much of U.S. software liability law still assumes the latter.
The tension extends beyond corporate marketing and into public policy. The 2023 National Cybersecurity Strategy proposed shifting liability onto software vendors on the theory that they, not their customers, are best positioned to prevent defects. In March 2026, the new Cyber Strategy dropped that proposal entirely in favor of deregulation and voluntary private sector action instead. Ironically, that reversal came just as AI made the case for software liability more compelling. Vendors began publicly demonstrating that AI could find defects more reliably, and cheaply enough, to make those precautions reasonable to expect.
The Myth of Digital Exceptionalism
Software occupies a privileged legal space that no other consumer product enjoys. A lamp that catches fire, a car with a defective airbag, or a harness that snaps under normal use all fall under strict product liability, a body of tort law that holds manufacturers responsible for defects regardless of fault. Software largely escaped that fate. Courts and legislators treat software as a licensed service rather than a product, letting it hide behind contract law instead. That exceptional treatment was a deliberate policy choice, and it is built on three core justifications that AI now undermines entirely:
1. Fear of Chilling Innovation: The software licensing regime that took shape in the 1990s assumed a fragile, nascent tech sector that could not survive the litigation costs strict liability would impose. Bugs became the acceptable price of a fast-moving industry that regulators did not want to strangle. But whatever validity that argument held in the 1990s is gone: An information technology sector that commands more than 36 percent of the S&P 500's total market weight is no longer a fragile infant in need of a legal shield.
2. Infinite Complexity: While a car has roughly 30,000 physical parts, software contains tens of millions of lines of code with trillions of execution paths. Because mapping every possible configuration of user clicks and background processes was a mathematical impossibility for human teams, courts accepted that exhaustive testing was infeasible. That is why courts have long held software to a lower bar than physical goods. Frontier AI shatters that defense: Automated tools can now stress test millions of these complex, branching paths simultaneously and at superhuman speed.
3. The Ubiquitous Nature of the EULA: Boilerplate "as-is" language repeated in nearly every license shifted almost all operational risk onto the end user, whether that user was a hospital network or an individual consumer. Courts deferred to these contractual liability shields largely because others did, and because the first two justifications gave them cover to do so.
All three justifications rest on one assumption: that finding defects before shipment costs too much to demand it. Frontier AI breaks that assumption, which means the policy logic built on it should be revisited as well.
Revisiting the Economics of Negligence
The law has a relevant formula. Judge Learned Hand laid it out in United States v. Carroll Towing Co.: A party is negligent when the burden of precautions (B) is less than the probability of harm (P) multiplied by the gravity of that harm (L). In other words, negligence occurs when B < P x L.
For 70 years, software vendors won this equation by default. The cost of hiring armies of elite software engineers to manually audit tens of millions of lines of code before every release sat far above the expected harm (P x L) from almost any individual bug.
That reality shifted almost overnight as autonomous security agents proved they could outpace human security teams. In late 2024, Google's Project Zero and DeepMind unveiled "Big Sleep," an AI agent that uncovered a zero-day flaw in SQLite, a database engine embedded in billions of devices and renowned for being one of the most obsessively audited codebases. By mid-2025, Big Sleep escalated from catching unreleased bugs to thwarting an active zero-day exploit in the wild moments before threat actors could weaponize it.
What makes these capabilities so game-changing is not just their sophistication, but also their radically lower cost. University of Illinois researchers evaluating AI security agents showed that running automated exploit attempts against real-world vulnerabilities costs as little as $8.80 per run using off-the-shelf models such as GPT-4, a fraction of what human security researchers would cost. A security startup called Depthfirst used a commercially available model to surface 21 previously unknown vulnerabilities in FFmpeg, a piece of software embedded in an enormous share of the internet's video infrastructure, for roughly $1,000 in total compute. None of this required a multi-billion-dollar custom research lab.
Vendors are not hiding this new capability. They lead with it in earnings calls and product announcements, and they pitch it to customers and shareholders as a competitive advantage. That is precisely why the Hand formula should flip the policy conversation, even where it has not yet flipped it in a courtroom. Courts have enforced "as-is" disclaimers for decades because the assumption beneath them made that deference reasonable. Slapping an "as-is" disclaimer on software after running--or opting not to run--a low-cost precautionary scan that a company actively markets as effective should no longer be a valid legal shield. Contractual disclaimers cannot erase basic duty of care. When code is headed into hospital networks or power utilities, attempting to disclaim liability away from preventable defects becomes a deliberate choice to offload catastrophic risk onto the public. Under the formula's own terms, that is negligence in substance, even if not yet in doctrine.
The Economics of Software Development
The total economics of building software have shifted as much as the economics of finding the bugs in it. AI does not just lower the cost of security auditing; it slashes the overall cost of routine software engineering by 30-50 percent. Historically, vendors starved security budgets, which typically represent under 11 percent of enterprise cyber spending, to protect core engineering margins. That trade-off no longer holds. Capital freed up by automated development easily covers continuous AI verification, allowing vendors to ship more secure software while still expanding profit margins.
But freed-up capital does not spend itself on defense. A corporation's obligation, as Milton Friedman once famously argued, is to maximize value for its shareholders. In a competitive market, the vendor that pockets the savings wins; the vendor that spends the savings on security nobody requires does not. That creates a closing window. The same automation that makes bug hunting cheap for defenders will make exploit development cheap for attackers. Whoever automates first keeps the advantage. Left alone, the market pushes that race toward the attacker. The Hand formula says the legal shield should fall. The economics of agentic development say it must fall now while the cost advantage still belongs to the people finding bugs, rather than to the people exploiting them.
None of this happens on its own. Courts have little appetite to unwind decades of enforced boilerplate text case by case. And doing so unevenly, jurisdiction by jurisdiction, would produce years of unpredictable litigation before any vendor changed its behavior. That is the argument for legislative action: Congress can update the assumption on purpose, and on a deliberate timeline, instead of leaving it to a slow accumulation of individual lawsuits to do it by accident.
Reevaluating the Policy Toolbox: Reasonable Process over Perfect Code
The harder conceptual work has already been done. Government experts and legal scholars have developed a substantial body of work on software liability and secure development. The Office of the National Cyber Director's 2024 symposia helped map the policy architecture. The Secure Software Development Framework (SSDF), developed by the National Institute of Standards and Technology (NIST), already provides a practical baseline. Legal scholars have spent years developing theories of software liability and proposing ways to implement it. Internationally, the European Union has made the same conceptual leap: Its revised Product Liability Directive, adopted in 2024, formally classifies software as a product, though enforcement will not begin until member states transpose it by the end of 2026.
Together, that work points toward a framework centered on reasonable process, not perfect code:
* Revisit secure-development safe harbors. Congress should codify protections for software producers that follow recognized secure-development practices. Vendors that follow frameworks such as NIST's SSDF, document AI-assisted security testing, and maintain a risk-based remediation process for serious flaws should receive meaningful protection from punitive damages and overbroad tort claims. The goal should be to reward diligence, not punish every residual bug.
* Target liability at gross inaction. Legal exposure should focus on willful blindness, not ordinary imperfection. Companies that decline to use standard automated scanning tools, ignore high-confidence findings, or repeatedly ship code with known or easily discoverable failure modes into critical infrastructure and other high-consequence environments. The strongest cases will not involve close calls. They will involve precautions that were cheap, available, and widely understood, but still ignored.
* Protect open-source maintainers while holding commercial integrators responsible. Any serious framework should distinguish between volunteers maintaining open-source code and commercial vendors monetizing enterprise products. Liability should rest primarily with the firms that package, deploy, and profit from software without conducting basic automated due diligence. That is usually where the capacity to test, remediate, and internalize the cost of failure sits.
Policymakers do not need to invent a new theory of software liability, nor should they demand flawless code. They only need to revisit the outdated economic assumptions that justified software's exceptional treatment and build from the body of work already on the shelf. When the cost of precaution drops toward zero, the justification and legal case for disclaimed liability collapses. The economics and the technology have changed. Our legal expectations should change with them.
* * *
Original text here: https://www.csis.org/analysis/end-could-ai-undermine-softwares-us-legal-shield
[Category: ThinkTank]
