Security

FSI scholars produce research aimed at creating a safer world and examing the consequences of security policies on institutions and society. They look at longstanding issues including nuclear nonproliferation and the conflicts between countries like North and South Korea. But their research also examines new and emerging areas that transcend traditional borders – the drug war in Mexico and expanding terrorism networks. FSI researchers look at the changing methods of warfare with a focus on biosecurity and nuclear risk. They tackle cybersecurity with an eye toward privacy concerns and explore the implications of new actors like hackers.

Along with the changing face of conflict, terrorism and crime, FSI researchers study food security. They tackle the global problems of hunger, poverty and environmental degradation by generating knowledge and policy-relevant solutions. 

-

* Please note all CISAC events are scheduled using the Pacific Time Zone.

 

Register in advance for this webinar: https://stanford.zoom.us/webinar/register/8416226562432/WN_WLYcdRa6T5Cs1MMdmM0Mug

 

About the Event: Is there a place for illegal or nonconsensual evidence in security studies research, such as leaked classified documents? What is at stake, and who bears the responsibility, for determining source legitimacy? Although massive unauthorized disclosures by WikiLeaks and its kindred may excite qualitative scholars with policy revelations, and quantitative researchers with big-data suitability, they are fraught with methodological and ethical dilemmas that the discipline has yet to resolve. I argue that the hazards from this research—from national security harms, to eroding human-subjects protections, to scholarly complicity with rogue actors—generally outweigh the benefits, and that exceptions and justifications need to be articulated much more explicitly and forcefully than is customary in existing work. This paper demonstrates that the use of apparently leaked documents has proliferated over the past decade, and appeared in every leading journal, without being explicitly disclosed and defended in research design and citation practices. The paper critiques incomplete and inconsistent guidance from leading political science and international relations journals and associations; considers how other disciplines from journalism to statistics to paleontology address the origins of their sources; and elaborates a set of normative and evidentiary criteria for researchers and readers to assess documentary source legitimacy and utility. Fundamentally, it contends that the scholarly community (researchers, peer reviewers, editors, thesis advisors, professional associations, and institutions) needs to practice deeper reflection on sources’ provenance, greater humility about whether to access leaked materials and what inferences to draw from them, and more transparency in citation and research strategies.

View Written Draft Paper

 

About the Speaker: Christopher Darnton is a CISAC affiliate and an associate professor of national security affairs at the Naval Postgraduate School. He previously taught at Reed College and the Catholic University of America, and holds a Ph.D. in Politics from Princeton University. He is the author of Rivalry and Alliance Politics in Cold War Latin America (Johns Hopkins, 2014) and of journal articles on US foreign policy, Latin American security, and qualitative research methods. His International Security article, “Archives and Inference: Documentary Evidence in Case Study Research and the Debate over U.S. Entry into World War II,” won the 2019 APSA International History and Politics Section Outstanding Article Award. He is writing a book on the history of US security cooperation in Latin America, based on declassified military documents.

Virtual Seminar

Christopher Darnton Associate Professor of National Security Affairs Naval Postgraduate School
Seminars
Authors
Daphne Keller
News Type
Blogs
Date
Paragraphs

I am a huge fan of transparency about platform content moderation. I’ve considered it a top policy priority for years, and written about it in detail (with Paddy Leerssen, who also wrote this great piece about recommendation algorithms and transparency). I sincerely believe that without it, we are unlikely to correctly diagnose current problems or arrive at wise legal solutions.

So it pains me to admit that I don’t really know what “transparency” I’m asking for. I don’t think many other people do, either. Researchers and public interest advocates around the world can agree that more transparency is better. But, aside from people with very particular areas of interest (like political advertising), almost no one has a clear wish list. What information is really important? What information is merely nice to have? What are the trade-offs involved?

That imprecision is about to become a problem, though it’s a good kind of problem to have. A moment of real political opportunity is at hand. Lawmakers in the USEurope, and elsewhere are ready to make some form of transparency mandatory. Whatever specific legal requirements they create will have huge consequences. The data, content, or explanations they require platforms to produce will shape our future understanding of platform operations, and our ability to respond — as consumers, as advocates, or as democracies. Whatever disclosures the laws don’t require, may never happen.

It’s easy to respond to this by saying “platforms should track all the possible data, we’ll see what’s useful later!” Some version of this approach might be justified for the very biggest “gatekeeper” or “systemically important” platforms. Of course, making Facebook or Google save all that data would be somewhat ironic, given the trouble they’ve landed in by storing similar not-clearly-needed data about their users in the past. (And the more detailed data we store about particular takedowns, the likelier it is to be personally identifiable.)

For any platform, though, we should recognize that the new practices required for transparency reporting comes at a cost. That cost might include driving platforms to adopt simpler, blunter content rules in their Terms of Service. That would reduce their expenses in classifying or explaining decisions, but presumably lead to overly broad or narrow content prohibitions. It might raise the cost of adding “social features” like user comments enough that some online businesses, like retailers or news sites, just give up on them. That would reduce some forms of innovation, and eliminate useful information for Internet users. For small and midsized platforms, transparency obligations (like other expenses related to content moderation) might add yet another reason to give up on competing with today’s giants, and accept an acquisition offer from an incumbent that already has moderation and transparency tools. Highly prescriptive transparency obligations might also drive de facto standardization and homogeneity in platform rules, moderation practices, and features.

None of these costs provides a reason to give up on transparency — or even to greatly reduce our expectations. But all of them are reasons to be thoughtful about what we ask for. It would be helpful if we could better quantify these costs, or get a handle on what transparency reporting is easier and harder to do in practice.

I’ve made a (very in the weeds) list of operational questions about transparency reporting, to illustrate some issues that are likely to arise in practice. I think detailed examples like these are helpful in thinking through both which kinds of data matter most, and how much precision we need within particular categories. For example, I personally want to know with great precision how many government orders a platform received, how it responded, and whether any orders led to later judicial review. But to me it seems OK to allow some margin of error for platforms that don’t have standardized tracking and queuing tools, and that as a result might modestly mis-count TOS takedowns (either by absolute numbers or percent).

I’ll list that and some other recommendations below. But these “recommendations” are very tentative. I don’t know enough to have a really clear set of preferences yet. There are things I wish I could learn from technologists, activists, and researchers first. The venues where those conversations would ordinarily happen — and, importantly, where observers from very different backgrounds and perspectives could have compared the issues they see, and the data they most want — have been sadly reduced for the past year.

So here is my very preliminary list:

  • Transparency mandates should be flexible enough to accommodate widely varying platform practices and policies. Any de facto push toward standardization should be limited to the very most essential data.
  • The most important categories of data are probably the main ones listed in the DSA: number of takedowns, number of appeals, number of successful appeals. But as my list demonstrates, those all can become complicated in practice.
  • It’s worth taking the time to get legal transparency mandates right. That may mean delegating exact transparency rules to regulatory agencies in some countries, or conducting studies prior to lawmaking in others.
  • Once rules are set, lawmakers should be very reluctant to move the goalposts. If a platform (especially a smaller one) invests in rebuilding its content moderation tools to track certain categories of data, it should not have to overhaul those tools soon because of changed legal requirements.
  • We should insist on precise data in some cases, and tolerate more imprecision in others (based on the importance of the issue, platform capacity, etc.). And we should take the time to figure out which is which.
  • Numbers aren’t everything. Aggregate data in transparency reports ultimately just tell us what platforms themselves think is going on. To understand what mistakes they make, or what biases they may exhibit, independent researchers need to see the actual content involved in takedown decisions. (This in turn raises a slough of issues about storing potentially unlawful content, user privacy and data protection, and more.)

It’s time to prioritize. Researchers and civil society should assume we are operating with a limited transparency “budget,” which we must spend wisely — asking for the information we can best put to use, and factoring in the cost. We need better understanding of both research needs and platform capabilities to do this cost-benefit analysis well. I hope that the window of political opportunity does not close before we manage to do that.

Daphne Keller

Daphne Keller

Director of the Program on Platform Regulation
BIO

Read More

Daphne Keller QA
Q&As

Q&A with Daphne Keller of the Program on Platform Regulation

Keller explains some of the issues currently surrounding platform regulation
Q&A with Daphne Keller of the Program on Platform Regulation
Hero Image
getty image of person holding transparent phone
Getty Images
All News button
1
Subtitle

In a new blog post, Daphne Keller, Director of the Program on Platform Regulation at the Cyber Policy Center, looks at the need for transparency when it comes to content moderation and asks, what kind of transparency do we really want?

Authors
News Type
News
Date
Paragraphs

Three CISAC scientists have joined 26 of the nation’s top nuclear experts to send an open letter to President Obama in support of the Iran deal struck in July.

“The Joint Comprehensive Plan of Action (JCPOA) the United States and its partners negotiated with Iran will advance the cause of peace and security in the Middle East and can serve as a guidepost for future non-proliferation agreements,” the group of renowned scientists, academics and former government officials wrote in the letter dated August 8, 2015.

“This is an innovative agreement, with much more stringent constraints than any previously negotiated non-proliferation framework.”

CISAC senior fellow and former Los Alamos National Laboratory director Sig Hecker is a signatory to the letter, along with CISAC co-founder Sid Drell, and cybersecurity expert and CISAC affiliate Martin Hellman.

Six Nobel laureates also signed, including FSI senior fellow by courtesy and former Stanford Linear Accelerator director Burton Richter.

The letter arrives at a crucial time for the Obama administration as it rallies public opinion and lobbies Congress to support the Iran agreement.

You can read the full letter along with analysis from the New York Times at this link.

Hero Image
19069162993 6feec3cd1b o
All News button
1
Paragraphs

OVERVIEW
 

The global demand for “AI sovereignty” is increasingly shaping AI policy and safety discussions. What was once a niche concern has become a widely shared priority, with more countries seeking control over how AI is built, deployed, and governed within their borders. This memo synthesizes key insights on the drivers of AI sovereignty, how countries are operationalizing it in practice, and the implications for U.S. diffusion strategy and managing global risks.

Three premises frame the analysis. First, emerging economies and middle powers are becoming crucial partners, consumers, and suppliers in the global AI ecosystem. Second, U.S. leadership in frontier AI creates a narrow—and likely diminishing—window to shape how this technology diffuses. Third, understanding what countries actually want from AI is critical to designing a sustainable U.S. diffusion strategy and navigating shared risks.

These insights draw on ongoing research from the Carnegie Endowment for International Peace (CEIP) and Stanford's Program on Geopolitics, Technology, and Governance (GTG), and were further developed at a workshop, “AI Sovereignty, Diffusion, and Risk: Strategy in a Contested Landscape,” convened by CEIP and GTG on June 17, 2026 with experts from civil society, industry, and academia.
 

KEY INSIGHTS
 

“AI sovereignty” is a politically potent but analytically ambiguous concept, driven primarily by a desire to manage dependence and extractivism, and to obtain AI suited to local contexts.
 

While the term “AI sovereignty” is ambiguous, it has become an increasingly influential part of international AI discussions. Sovereignty goals seem less about achieving true technological autarky (widely seen as unfeasible), and more about a desire to secure national interests (economic, security, cultural) within a tech landscape dominated by the U.S. and China. In this way, AI sovereignty might be practically understood better as “AI agency:” a country's ability to execute choices in line with national interests. In search of this agency, countries will likely pursue a strategy that combines assured access arrangements for foreign AI models and hardware with efforts to diversify and build domestic capacity (indigenous or modified foreign open-source) if such access is disrupted. These domestic capacity efforts tend to focus on cheaper, multilingual, and multimodal models contextually attuned to underserved markets.

Sovereignty can serve as a source of resilience, and, increasingly, may serve as a deterrent against being cut off from frontier AI capabilities. To achieve this deterrent effect, countries are likely to seek sources of leverage along the AI value chain. These may include:

  • Control over scarce resources in the AI supply chain, such as critical minerals or low-cost energy for powering data centers.
  • Significant market power that makes a country an indispensable consumer of AI services.
  • Refining high-value local data for domestic value capture.
     

These sources of leverage, however, could be a depreciating asset, as a nation may only be able to threaten or use its leverage once before providers diversify away from it.

Perceptions of AI risk within sovereignty debates rarely focus on concerns over shared catastrophic and large-scale threats.
 

Discussions of AI sovereignty in many middle powers and emerging economies are primarily driven by concerns over dependency, extractivism, market concentration, and geopolitical subordination. Cross-border, large-scale AI risks like cyberattacks, biosecurity, or rogue AI agents have not been central to these debates to date, as they are often perceived as remote or lower priority than immediate economic and political concerns and assured access to AI technology.

Recent events, such as the U.S. government blocking Anthropic's Fable model access, have reinforced this focus on dependency. While the incident highlighted the potential for dangerous capabilities, the primary international reaction has been concerned with the U.S. wielding a “kill switch” over model deployment, reinforcing fears of unilateral control and strengthening the case for AI sovereignty.

This dynamic could shift as AI capabilities diffuse. The widespread availability of powerful models capable of causing significant cross-border harm, such as cybersecurity failures in critical infrastructure, may force a re-evaluation. In such a scenario, the salience of shared safety and security could rise, potentially aligning national interests more closely with global risk mitigation efforts.

Countries are actively pursuing sovereign AI projects, but a significant gap persists between ambitious strategies and operational capacity.
 

A clear trend of sovereign-related AI projects and announcements is underway globally, especially in the EU, Indo-Pacific, and Gulf States. These initiatives range from building national compute clusters and developing domestic models to pursuing legal arrangements to ensure data localization and provide assured access to foreign AI models.

However, a significant gap often exists between high-level ambitions and the operational capacity to implement them, as many efforts lack clear funding and technical expertise.

The viability of these national ambitions may hinge on a critical, and often unresolved, distinction: identifying which use cases can use “good enough” AI, relying on less advanced models and infrastructure, versus those that require access to the frontier.

The future trajectory of AI—whether dominated by a few frontier labs or a broader open-source ecosystem—is a central uncertainty shaping national strategies.
 

A fundamental tension exists between two potential AI futures: one where a handful of frontier labs create a runaway capability gap, and another where open-source models remain competitive and useful for most purposes.

In a world where frontier models pull away, a U.S.-led stack could become central to the global economy and international security, giving the U.S. unprecedented insight and international leverage.

In contrast, in a world where open-source and fast follower models remain competitive, the strategic calculus shifts, potentially lowering the stakes of frontier competition for many countries and enabling more diversified technology ecosystems.

The concept of an organized “third stack” as an alternative to U.S. and Chinese ecosystems built on open-source models and diverse hardware is a potential pathway for middle powers seeking to avoid dependency. This alternative is only viable if a coalition of middle powers align on standards for procuring and deploying AI to pool their collective purchasing power; the European Union’s regulatory and tech sovereignty efforts are informed by this logic. However, multi-state organization around a third stack faces significant collective action problems, and any effort to create an independent stack could be viewed as a challenge to U.S. national security, incentivizing Washington to pursue bilateral engagements that thwart an emergent alternative.

Even with open models, countries may still want assured access to frontier AI for limited, exquisite capabilities.
 

Even if many countries' economic, development, and security goals can be achieved through “good enough” AI, countries may want access to high-end capabilities for specific purposes. This could give the United States an opportunity to offer assured access to frontier AI in exchange for safety and security commitments.

However, an assured access framework faces major challenges:

  • Trust in U.S. assurances: The U.S. is often not currently seen as a credible, long-term partner. Without trust, assurances are secondary to mutual leverage.
  • Third country leverage: A security–frontier bargain appears most viable with countries that possess something the U.S. wants (e.g., India's data, Brazil's energy resources). Leverage is unclear for states that lack such bargaining chips.
  • Risk perception gap: Safety commitments, especially those framed around catastrophic risks, do not resonate strongly in many parts of the world, where developmental and economic priorities are paramount. For Global Majority economies, legible near-term AI risks include displacement of labor within domestic informal sectors and the devaluation of labor within global value chains.
     

Significant doubts about the U.S. government's ability to execute a nuanced AI partnership strategy highlight the roles of market forces and non-state actors.
 

Many believe the U.S. government currently lacks the capacity and planning to execute a complex global AI diffusion strategy. The U.S. government’s existing toolkit for promoting the U.S. tech stack, including bodies like the Development Finance Corporation (DFC) and EXIM Bank, is difficult to deploy effectively. The government's most effective role may be to de-risk investment and lend credibility in geopolitically critical areas where a natural market does not exist.

In the absence of a robust government strategy, market forces are the primary driver. The quality of U.S. technology creates a natural pull, but this may be counteracted by U.S. policy unpredictability.

In this vacuum, non-governmental actors are stepping in. Philanthropic organizations are brokering agreements between U.S. AI labs and Global Majority countries for specific use cases. However, it remains unclear if these ad-hoc efforts can scale into a coherent ecosystem that benefits U.S. interests.

PRIORITIES FOR FURTHER RESEARCH
 

This analysis surfaces several unresolved questions that warrant further research and debate. Priorities for future inquiry include:
 

  • Clarifying the competing futures of AI: Under what conditions might frontier AI models achieve a decisive, compounding advantage over open-source alternatives? What are the key technical and economic indicators that policymakers should monitor to assess which future is becoming more likely? What are the implications for AI risk management?
  • Mapping points of national leverage: Beyond theoretical control over chokepoints, what forms of economic, political, or geographic leverage have proven most effective for middle powers in securing favorable terms for AI access? How durable is this leverage, and can it be pooled regionally to overcome collective action problems?
  • Designing a viable U.S. partnership model: What specific, actionable policy tools are required for the U.S. to offer a compelling “assured access” bargain? How can such a policy be designed to be credible across administrations, especially for countries that lack significant intrinsic market or resource leverage? How should AI risks factor in?
  • Integrating safety into diffusion frameworks: How do perceptions of AI risk influence national sovereignty strategies? What practical mechanisms can embed safety and security commitments into technology partnerships?
     

Download the full PDF here.

All Publications button
0
Publication Type
Policy Briefs
Publication Date
Journal Publisher
GTG–CEIP
Paragraphs

In late August 2021, United States President Joseph Biden hosted the newly elected Israeli Prime Minister, Naftali Bennet, at the White House for an official meeting. Shortly after, Israeli journalist Barak Ravid reported that Biden and Bennet ‘reaffirmed the strategic understandings’ between the two allies on Israel’s ‘alleged undeclared military nuclear program’, noting that this reaffirmation of policy has been repeated by every US President since Richard Nixon.1 As shall be explored below, this statement is mostly accurate, with the seemingly glaring exception of President George H.W. Bush. Upon its publication, Ravid’s story became the most recent in a long line of reports detailing this repeated commitment by US presidents to their Israeli counterparts.2

What role does this commitment play in Israel’s long history with the Nuclear Non-Proliferation Treaty (NPT)? The primary aim of this article is to answer this question by charting Israel’s relationship with the NPT and its decades-long fear of American coercion to join it. A secondary aim of this article is to provide a concise primer, or introduction, to this nuanced question for scholars and students alike, by reviewing the existing literature and adding insights from new archival sources to this growing body of work.

The paper proceeds in three parts. The first charts the emergence of Israel’s NPT policy and the technical-diplomatic road which led to the emergence of the policy in the late 1960s and the early 1970s. The second charts how this policy impacted Israel’s nuclear energy policy in the following decades, ultimately preventing it from pursuing its plan of launching a massive civilian nuclear infrastructure program, specifically nuclear power plants for electricity production. The third concludes with charting Israel’s NPT policy at the end of the Cold War. Research for this study was conducted in archives in the US, United Kingdom, Canada, and Israel, and taps both primary and secondary sources; Hebrew translations are by the author, unless otherwise noted.3

All Publications button
1
Publication Type
Journal Articles
Publication Date
Journal Publisher
Cold War History
Authors
Or (Ori) Rabinowitz
Paragraphs

This memo examines securitization within the public political discussion of both Russia and the United States. We have selected keywords pertaining to the country itself in general and to the country’s intelligence services in order to identify whether the overall sentiment towards the country is similar to the sentiment given to one of the most securitized topics. For the dataset, we selected recent content from the 10 most-cited political bloggers, with the platforms being Substack for the US and Telegram for Russia. Further on, we analyzed some of the relevant post texts qualitatively. Policy recommendations are provided based on the results. 

All Publications button
1
Publication Type
Conference Memos
Publication Date
Authors
Paragraphs

Washington’s alliances are under immense strain. Many allies and partners are subject to increased threats from great-power adversaries, and they are coming to doubt whether they can rely on the United States. The response to these pressures is to rearm. Like the United States itself, U.S. partners across Asia, Europe, and elsewhere are building up their defense industrial and technological bases to improve their ability to project power, deter enemies, and prevail in a protracted conflict.

Continue reading at foreignaffairs.com

All Publications button
0
Publication Type
Commentary
Publication Date
Subtitle

America and Its Allies Must Pool Their Efforts

Journal Publisher
Foreign Affairs
Paragraphs

This paper asks whether the United States and the European Union, despite divergent economic exposure and institutional design, can sustain a coherent sanctions strategy toward Russia, and how that divergence shapes the regime's effectiveness. It proceeds through a structured comparison across three policy domains — energy, finance, and immobilized sovereign assets — drawing on the literatures on economic statecraft, energy security, and financial-network theory, and on transaction-level, macroeconomic, and legal evidence from 2022 to early 2026. The analysis finds, first, that the United States' position as a net energy exporter enabled rapid embargoes, whereas the EU's import dependence produced a slower, phased decoupling. Second, US financial measures operated extraterritorially through dollar centrality and centralized OFAC enforcement, while the EU relied on regulatory jurisdiction over SWIFT but enforced through fragmented national authorities; a Gazprombank carve-out preserved the energy-export inflows that offset the intended balance-of-payments shock. Third, in the dispute over frozen assets, EU custodial institutions bear the legal and retaliatory exposure that the United States advocates from a position of relative insulation. The findings indicate that the regime's effectiveness is constrained less by the design of individual measures than by uneven enforcement and an asymmetric distribution of risk; absent institutionalized burden-sharing, its durability and credibility are likely to weaken.

All Publications button
1
Publication Type
Conference Memos
Publication Date
Authors
Paragraphs

Escalating threats to undersea cable networks, stemming from gray-zone sabotage at vulnerable chokepoints, are receiving long-overdue attention from policymakers and the public. Recent incidents highlight the strategic vulnerability of this infrastructure, due to a lack of redundancy, limited repair capacity, and gaps in international maritime law. Despite attempts at multilateral cooperation through the G7 and the Quad, concrete actions are lagging. The US administration has not directly addressed this issue. To strengthen resilience, democracies must collaborate and invest in hardened cable designs, real-time monitoring and data sharing, routing diversity, regional repair hubs, and enhanced legal frameworks. They must work together to secure their lifeline for economic and national security and future digital-technology advancement.

All Publications button
1
Publication Type
Journal Articles
Publication Date
Journal Publisher
Texas National Security Review
Authors
Charles Mok
Number
Iss 3
0
untitled_design_-_sophia_adele_stringer.png

I am currently pursuing a double major in Political Science and Sociology, with a specific focus on rule of law systems and criminology. I am most interested in questions concerning how aspects of identity affect people’s access to justice and the conditions that shape the procedures and outcomes of legal institutions.

Research Assistant, Fisher Family Summer Fellows Program, Summer 2026
Date Label
Subscribe to Security