Geopolitical risk increasingly arrives not as a dramatic crisis bulletin but as a normal-looking message, spreadsheet, chatbot prompt, or social-media post. That is what makes it frightening: the infrastructure of conflict, surveillance, and manipulation is being folded into ordinary digital life.
The central fact is not that states and armed groups have suddenly discovered deception. They have always used intelligence, propaganda, secrecy, and coercion. What has changed is the speed, scale, accessibility, and plausible deniability of the tools. A cabinet-level official can discuss a military operation in a consumer messaging app. An Iran-linked actor can use a commercial AI system to aggregate open-source data on naval movements. An armed movement can shape international perception through dispersed media channels, intermediaries, and platform-native content rather than a single obvious propaganda broadcast.
The result is a world in which the most consequential security failures can look almost boring—until they are not.
A Signal group is not a situation room
The 2025 Signal-chat controversy involving senior U.S. national-security officials is a useful example because its underlying technology was so familiar. Signal is widely associated with encrypted personal communications. It is intuitive, quick, and ubiquitous. Those qualities make it attractive. They do not automatically make it an appropriate venue for operational military planning.
The chat came to public attention after then-national security adviser Mike Waltz inadvertently added Jeffrey Goldberg, editor in chief of The Atlantic, to a group that included senior officials. The subsequently published messages showed Defense Secretary Pete Hegseth sharing detailed timing information about U.S. strikes against the Houthis in Yemen—including aircraft-launch times, the strike window, drone timing, and Tomahawk launches—before the operation was under way. The White House and Hegseth disputed that classified material or “war plans” had been shared, but the episode exposed how sensitive operational discussion could take place in an informal, commercially available communications environment.[ap][apnews]
The important lesson is larger than whether one set of messages met a particular classification threshold. The failure was cultural as much as technical. Familiar digital tools produce an illusion of routine: a group chat feels like coordination, not command; a notification feels like administration, not exposure; an accidentally added contact feels like a minor clerical error, not a potential intelligence breach.
This is the banality of risk. A modern security failure may not begin with a mole, a break-in, or a sophisticated cyberattack. It may begin with someone tapping the wrong name.
AI turns public data operational
The same flattening of the extraordinary into the ordinary appears in the reported misuse of Claude, Anthropic’s AI model. In September 2026, Anthropic said it had disrupted an Iran-linked actor that used Claude to collect and analyze publicly available information to develop targeting recommendations involving U.S. naval forces in the region. According to the company, the material included personnel information scraped from captions on public military photographs, ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and public websites that exposed naval movements.[reuters][anthropic]
None of these inputs necessarily required a dramatic theft of secrets. That is precisely the point. Individually, a photograph caption, an aircraft identifier, a ship-tracking signal, and a satellite image can appear mundane. But AI-assisted collection and synthesis can reduce the labor required to connect them. The strategic danger lies in the conversion of diffuse, publicly accessible fragments into a structured targeting picture.
Anthropic also reported Iranian-linked uses of Claude for domestic surveillance, influence operations, and identity profiling. It said it had removed 16 accounts associated with two linked Iranian paramilitary or domestic-security units, including activity connected to a malicious browser extension intended to harvest identities from major social platforms.[reuters][anthropic]
That should change how we think about “open source.” Open information is not harmless merely because it is public. The relevant question is whether disparate data can be combined, automated, classified, and acted upon. In the AI era, the cost of doing that is falling.
The risk is therefore not simply artificial intelligence becoming autonomous. It is artificial intelligence making ordinary surveillance, profiling, and narrative management cheaper enough to become routine.
Information control is rarely obvious
Hamas’s communication strategy illustrates a related problem: conflict is fought not only through weapons and territory but through control of information environments. Public reporting and human-rights documentation have long described Hamas restrictions on press freedom in Gaza, including intimidation, detention, interrogation, harassment, constraints on movement, and pressure that can induce journalists and activists to self-censor. The U.S. State Department has reported that Hamas restricted freedom of expression and that journalists critical of Hamas faced punitive measures.[state]
Separately, reporting based on documents said to have been captured in Gaza has described an organized Hamas media ecosystem aimed at shaping discourse, including material intended for foreign and Western audiences. Those accounts should be treated with appropriate caution: captured-document claims, wartime intelligence releases, and advocacy reporting require independent corroboration wherever possible. But the broad proposition—that Hamas seeks to manage messaging, mobilize supporters, and influence foreign audiences—is neither surprising nor controversial.[honestreporting][jewishonliner]
It is important to be precise here. Saying that Hamas conducts information operations should not lead to the careless conclusion that all Palestinian reporting is coordinated propaganda, or that every distressing image, casualty report, or witness account is false. That would reproduce the same epistemic failure that information operations exploit: treating affiliation, emotion, or political utility as substitutes for evidence.
The better approach is harder:
- Ask who gathered a claim and under what conditions.
- Distinguish direct evidence from anonymous assertion, interpretation, and recycled footage.
- Look for independent corroboration, including satellite imagery, records, geolocation, multiple eyewitnesses, and reporting by outlets with different incentives.
- State what cannot be verified rather than filling the gap with certainty.
- Apply the same standard to Hamas, Israel, Iran, Western governments, media organizations, activists, and viral accounts.
War produces both real suffering and strategic incentives to frame, suppress, amplify, or selectively release information. Those facts can coexist.
The system is the danger
The unnerving feature of these episodes is their ordinariness. Consider the common components:
| Ordinary object or practice | Geopolitical use or failure mode |
|---|---|
| Group chat | Sensitive military coordination, accidental disclosure, compromised operational security |
| Public social-media post | Personnel identification, location inference, network mapping, narrative amplification |
| Commercial satellite imagery | Tracking, reconnaissance, target development |
| AI assistant | Rapid data synthesis, propaganda drafting, surveillance workflow, code assistance |
| Messaging channel or activist network | Distribution of curated narratives across borders |
| Content moderation system | Legitimate enforcement, over-removal, selective visibility, and disputes over censorship |
None of these systems is inherently malign. Signal can protect dissidents, journalists, and ordinary users. Public satellite imagery can improve accountability and humanitarian monitoring. AI can assist research, translation, accessibility, and scientific work. Social platforms can provide witnesses a route around official silence.
But dual-use tools do not remain neutral once they enter political conflict. They can expand public knowledge and expand state or nonstate surveillance at the same time. They can make censorship harder and make manipulation cheaper. They can give an independent investigator better evidence and give a hostile actor better targeting data.
That is why geopolitical risk no longer sits comfortably “over there,” in ministries, intelligence services, and battlefields. It is embedded in platforms used for work, family, shopping, journalism, professional networking, and casual conversation.
Fear is not the right conclusion
“It’s all very scary” is an understandable response. But permanent panic is not analysis, and it is not a durable civic posture. The practical response is disciplined skepticism rather than despair.
For institutions, that means separating convenience tools from high-consequence workflows; treating metadata, location traces, and open-source fragments as potentially sensitive; and building processes that do not depend on everyone behaving perfectly every time.
For journalists and researchers, it means resisting two temptations: naïve acceptance of official narratives and reflexive disbelief in everything. Verification should be proportional to consequence. The more a claim is likely to shape public understanding, escalate conflict, justify force, or endanger people, the higher the evidentiary bar should be.
For ordinary users, a few habits matter:
- Treat posts, images, and “leaks” from active conflicts as claims to verify, not instant proof.
- Avoid casually publishing identifiable locations, routines, travel, or institutional details about people who could be exposed to surveillance or coercion.
- Remember that a private-looking tool may still create records, metadata, screenshots, forwarding paths, or human error.
- Do not assume that public information is strategically insignificant once it can be aggregated at scale.
- Be wary when a story demands immediate emotional certainty while making independent verification difficult.
The banality of geopolitical risk is not that the threats are trivial. It is that high-stakes conflict increasingly travels through everyday systems and low-friction decisions. A mistaken group-chat invitation, a prompt to a chatbot, a publicly captioned photograph, or a well-timed content campaign can sit quietly at the edge of events that later appear on the evening news as history.
The task is not to become paranoid. It is to understand that in a digitally networked world, the line between ordinary communication and strategic exposure has become much thinner.