← Back to list

The AI Clash: Cyber Warfare Between Ethical Guardians and Unrestrained Machines

Unpacking the Pentagon’s Push Against Anthropic and the Rise of Machine-Speed Conflicts in National Security

James Marinero, MSc, MBA. in The Dock on the Bay · 2026-06-23 05:41 · 250 claps · 6.1 min read paywalled
#ai-cyber-warfare #ethical-ai-limits #pentagon-ai-policy #autonomous-agent #machine-speed-war
Open on Medium ↗
Wiki topics: LLM · Large Language Models AGT · AI Agents

Artificial Intelligence War

The AI Clash: Cyber Warfare Between Ethical Guardians and Unrestrained Machines

Unpacking the Pentagon’s Push Against Anthropic and the Rise of Machine-Speed Conflicts in National Security

AI view of automated targeting

AI view of automated targeting

You may be old enough to remember Bill Gates’s 1999 book ‘Business at the Speed of Thought’. The thinking in that book delivered a paradigm shift in ‘C’ suites around the world. I confess that I never read it although in those days I was working on the development of derivatives trading software. We were actually implementing the thoughts in the book. Or trying to.

Nowadays, arbitrage trading requires round-trip times (RTTs) of 200 milliseconds or less to New York, London or Tokyo, and if you are right at the edge then you really need RTTs of less than 100 milliseconds.

How fast do we think? How can any person handle decision making at that sort of speed, consistently for a 8.5 hours trading window (LSE) on an exchange?

They cannot. Machines have taken over with programmed trading.

Now, almost a generation later, we are faced with Warfare at the Speed of Light.

The theoretical concept of a battle between competing artificial intelligence systems in cyberspace is now a matter of strategic debate.

As of February 2026, the divergence in ethical frameworks between the leading developers of frontier models has created a binary choice for national security infrastructure.

Anthropic’s Claude AI was used extensively in the planning of the latest war between the US and Israel against Iran.

The last minute decision by the United States Department of Defense (DoD) to pressure Anthropic over its insistence on specific guardrails — while rewarding OpenAI and xAI (Musk’s AI machine) for their relative flexibility — gives us a factual basis for exploring how these systems might eventually clash in cyberspace.

Yes, I’m talking about war between AIs.

Is that far fetched?

The architectural divergence of 2026

The conflict between the Pentagon and Anthropic is centered on two non-negotiable “red lines” embedded within the Claude models: a prohibition on fully autonomous lethal weaponry and a ban on mass domestic surveillance. Anthropic CEO Dario Amodei has argued that these capabilities are “outside the bounds of what today’s technology can safely or reliably do.”

In contrast, the US DoD, under Secretary Pete Hegseth, has prioritised “all lawful purposes,” arguing that corporate ethical “tuning” constitutes an operational risk.

This has led to the development of two distinct classes of military-grade AI:

  1. Constrained systems: AI models with “hard” ethical guardrails that include refusal modes for specific high-risk tasks. These systems prioritised reliability and human-in-the-loop verification.
  2. Unconstrained systems: Models designed for “wartime speed,” such as those integrated into the Pentagon’s GenAI.mil network. These systems operate with minimal policy layers, allowing them to execute autonomous “kill chains” if deemed lawful by military commanders.

The basis for AI-on-AI cyber warfare

In a hypothetical engagement between these two types of systems, the “battlefield” is the underlying logic and data processing speed of the network. This is often referred to as “machine-speed warfare,” where the primary objective is to out-reason and out-adapt the opponent.

Autonomous offensive agents

The offensive AI in this scenario functions as an “agentic” system. Unlike traditional malware, which follows a static script, an autonomous agent is given a high-level goal, such as “infiltrate the target power grid and exfiltrate the administrative credentials.”

  • Reconnaissance: The agent scans the target network at a rate of millions of packets per second, identifying unpatched vulnerabilities that a human would take days to find.
  • Polymorphic execution: When the agent encounters a firewall, it can rewrite its own source code in real-time to appear as a benign update or a routine system process.
  • Logical exploitation: If the defender is a constrained AI, the attacker may attempt “logic hacking” — creating scenarios that trigger the defender’s ethical refusal modes, effectively paralysing its ability to respond.

Adaptive defensive swarms

The defensive AI operates as a digital immune system. Its task is not just to block known threats but to identify “novel” patterns of behaviour that suggest an adversarial machine is at work.

  • Semantic analysis: Rather than looking for specific “signatures” of a virus, the defensive AI looks for the intent of the code. It asks whether the actions taken by a process align with the stated goals of the system.
  • Network reshuffling: In the event of a breach, the defensive AI can physically reconfigure the virtual network, creating “honey pots” or isolated segments (sandboxing) faster than the attacker can move laterally through the system.
  • Counter-adversarial learning: The defender constantly retrains itself based on the attack patterns it observes, attempting to predict the next logical step of the offensive agent.

The tactical trade-off: speed vs safety

The clash between a constrained AI (like Claude) and an unconstrained AI (like a militarised GPT or Grok) reveals a fundamental trade-off in cyber conflict.

The “hesitation” problem

A constrained AI must pass every potential action through a safety filter to ensure it does not violate its core constitution. In a cyber engagement where seconds matter, this reasoning layer introduces “latency.” If an offensive AI can launch an exploit in 50 milliseconds, but the defensive AI takes 200 milliseconds to verify that its counter-measure is “ethically compliant,” the battle is lost before the defense can engage.

The “hallucination” risk

Conversely, an unconstrained AI is prone to what researchers call “catastrophic interference” or “hallucinations” in high-pressure environments. Without robust guardrails, a military AI might misinterpret a civilian network update as a hostile act and launch a retaliatory strike. The “less restricted” system is more lethal and faster, but it is also more likely to cause unintended escalation or “friendly fire” in the digital domain.

The strategic reality of 2026

The Pentagon’s move to label Anthropic as a “supply chain risk” highlights the belief that a model with corporate-defined ethical limits is a liability in a conflict against a foreign adversary. The fear is that a rival nation, such as China or Russia, will deploy “unmasked” AI that does not hesitate.

However, the “GTG-1002” cyber campaign in late 2025 demonstrated that autonomous agents can already conduct full-scale espionage with minimal human intervention. This has accelerated the “race to the bottom” regarding AI safety, as both sides seek to remove any friction that might slow down their machine-speed response.

In mid-September 2025, we detected a highly sophisticated cyber espionage operation. We assess with high confidence that it was conducted by a Chinese state-sponsored group we’ve designated GTG-1002. It represents a fundamental shift in how advanced threat actors use AI. Our investigation revealed a well-resourced, professionally coordinated operation involving multiple simultaneous targeted intrusions. The operation targeted roughly 30 entities and our investigation validated a handful of successful intrusions. — Anthropic report November 2025 [.pdf]

The future of cyber warfare will likely not be a single “clash” but a continuous, invisible struggle of “agentic” systems probe and counter-probe.

The winner will be the system that can maintain the highest degree of logical coherence while operating at the absolute limit of hardware speed.

Reality rules

But however smart the systems are currently, the latest ‘Memorandum of Understanding’ between the USA and Iran (20 June 2026) demonstrates that even overwhelming force and capability cannot defeat an enemy that is well organised and has geography in its favour. Iran has made the US appear to be powerless and Trump looks like a fool.

And the AI reality is that AI war games almost always lead to nuclear conflict.

Leading AIs from OpenAI, Anthropic and Google opted to use nuclear weapons in simulated war games in 95 per cent of cases — New Scientist

Meanwhile

And today I read that Ukraine deployed and tested fully autonomous drones that can kill all humans in a defined area.

Fully autonomous drones with no human oversight have killed soldiers on the battlefield for the first time. This is according to a senior figure in the Ukrainian defence industry, marking a watershed moment in warfare.

The one-off test involved 10 AI-controlled “Terminator” drones on the front line of the Ukraine war. Russian soldiers were killed.

“We tried it,” says drone-maker Alexander Kokhanovskyy, who supplied the technology and spoke to New Scientist at a press event hosted by the Ukrainian embassy. “It’s a test. We never implemented it [more widely].”

The test took place two years ago and involved quadcopter drones that were programmed to fly towards the front line, cover between 3 and 5 kilometres over around 10 minutes and then engage “Terminator mode”, in which an AI model searches for and intercepts targets.

“We just launch it and we know everything will be dead — everything that will be found there in this particular area will be dead,” says Kokhanovskyy. “There is no connection to the drone at all, you cannot see the video, nothing… Everything it sees will be killed.” — New Scientist

That was two years ago but Ukraine did not go operational with the capability.

Ukraine may have ethical constraints, but I’m not a great believer in such constraints being operational in the Pentagon, as Hegseth’s supply chain rant about Anthropic has suggested. And as Trump’s statement about destroying the Iranian civilisation indicated.

It’s a grim future we face.


메타데이터
post_id
44bc07fca212
slug
the-ai-clash-cyber-warfare-between-ethical-guardians-and-unrestrained-machines-44bc07fca212
url
https://medium.com/the-dock-on-the-bay/the-ai-clash-cyber-warfare-between-ethical-guardians-and-unrestrained-machines-44bc07fca212
canonical_url
https://medium.com/the-dock-on-the-bay/the-ai-clash-cyber-warfare-between-ethical-guardians-and-unrestrained-machines-44bc07fca212
author_url
https://medium.com/@james-marinero
status
ok
fetched_at
2026-06-24 04:09:36