One Model, Two Missions
AI’s dual path in commerce and national security. The same system that drafts a hospital’s patient letters can help an analyst map a trafficking network — one technology, two missions, and no clean line between them.
For most of the last century, national security drove the frontier and commerce inherited it later. GPS, the internet and satellite imaging all followed that road. AI has flipped the order. Private companies now build the most capable systems, and governments are the ones catching up.
That shift changes who carries the risk, who sets the rules, and who needs to understand both worlds. Security leaders sit right at that seam.
The commercial path
On the commercial side, AI is sold as speed. It writes code, summarizes contracts, triages customer tickets and flags fraud in seconds. The business case is simple: fewer hours per task, faster decisions, lower cost.
For corporate security teams, the gains are real and practical:
- Threat intake: sorting thousands of tips, emails and reports to surface the handful that matter.
- Insider risk: spotting unusual access patterns before data walks out the door.
- Physical security: turning camera feeds and badge logs into alerts a small team can actually act on.
- Workplace violence prevention: connecting early warning signs scattered across HR, security and patient-facing staff.
The catch is that every one of these tools is also an attack surface. The model that screens phishing emails can be fooled by better phishing. Commercial adoption is outpacing the governance meant to keep it safe.
The national security path
In national security, AI is sold as advantage. The side that processes information faster sees the threat first and acts first. Speed of understanding has become a strategic asset in its own right.
The uses map closely to the commercial ones, just with higher stakes:
- Intelligence analysis: sifting intercepts, open-source reporting and financial records at a scale no team of analysts can match.
- Cyber defense: finding and patching vulnerabilities before an adversary does.
- Counterterrorism and counter-narcotics: linking people, money and movement across borders and platforms.
- Counterintelligence: detecting when a foreign service is targeting people, research or supply chains.
Adversaries are using the same tools. State-sponsored actors, cartels and extremist groups can now generate propaganda, run influence campaigns and probe networks with a fraction of the manpower they once needed. The barrier to entry has dropped for everyone.
Where the paths collide
The two paths meet at the model itself. A system good enough to find a software flaw for a defender is good enough to find it for an attacker. A tool that helps a biologist design a vaccine raises questions about who else might use it.
That is why governments are now treating frontier AI like other dual-use technology — and this summer showed how fast that can reach the market. On 12 June 2026 the Commerce Department issued an emergency export control order barring access by non-US persons to two of Anthropic’s most capable models. Unable to verify citizenship customer by customer, the company disabled both models for everyone. International access was not restored until the start of July, roughly nineteen days later, and then only with tighter safeguards.
Commercial AI access can now be switched off by a national security decision, overnight, with no notice to the people building on it.
Whatever one thinks of that particular call, the precedent is the point. Analysts at the Peterson Institute noted that the order arrived without clear criteria or carve-outs for allies, which is exactly the quality that makes a control hard to plan around. A business continuity plan that assumes a frontier model will be there tomorrow is now making an assumption about policy, not about uptime.
Three pressure points keep showing up:
- Access: who gets the most capable models, and under what safeguards.
- Supply chain: chips, data centers and training data are now strategic assets, and foreign services target them accordingly.
- Talent: the same engineers and analysts are recruited by companies, governments and adversaries alike.
Lessons from the field
I spent about ten years working undercover against extremists, narcotics networks and state-sponsored targets. The lesson that carries straight into AI is this: every tool you rely on, your adversary is studying too.
Three habits from that work apply directly.
- Trust, but verify the source. An informant can be sincere and still wrong. An AI output deserves the same scrutiny: where did this come from, and what would make it false?
- Assume you are being watched. Adversaries test defenses quietly before they act. AI systems in your organization will be probed the same way, through prompts, data and vendors.
- Partnerships win. The best cases I worked ran across agencies and countries. AI risk is no different; no single company or agency sees the whole picture.
Technology changes the speed of the game. It does not change the fundamentals of tradecraft, judgment and accountability.
What leaders should do now
Private-sector security leaders do not need a defense budget to act on this. They need a plan and a seat at the table.
- Inventory your AI. Know every tool in use, including the ones employees adopted on their own.
- Put security in the buying decision. Vet AI vendors like any critical supplier: data handling, ownership, and foreign exposure.
- Red-team your own tools. Test how your AI systems fail before someone else finds out for you.
- Keep a human on high-stakes calls. AI can flag the threat; a trained person should decide what happens next.
- Build bridges to government. Relationships with federal, state and local partners pay off before a crisis, not during one.
- Train your people. Deepfake calls and AI-written phishing target staff, not firewalls.
Closing
AI will not choose a lane. It will keep serving the boardroom and the ops center at the same time. The organizations that come out ahead will be the ones that stop treating commercial and national security risk as separate problems.
The people best placed to lead that work are those who have lived on both sides of the line. They know that speed matters, but judgment matters more.
Sources
- Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5” (12 June 2026) — the company’s own account of disabling both models for all customers to comply. anthropic.com
- Nextgov/FCW, “Anthropic suspends top AI models after U.S. export control order” (13 June 2026) — the order barred access by foreign nationals inside and outside the United States, and both models were disabled for all customers. nextgov.com
- Peterson Institute for International Economics, “Fable of the Mythos saga: Ad hoc US AI model controls could help China” — Commerce order of 12 June 2026, international access restored 1 July 2026, and the absence of clear criteria or allied carve-outs. piie.com
- Al Jazeera, “US asks Anthropic to block global access to top AI models: Why it matters” (14 June 2026) — scope of the restriction and the stated national security rationale. aljazeera.com