Security

FSI scholars produce research aimed at creating a safer world and examing the consequences of security policies on institutions and society. They look at longstanding issues including nuclear nonproliferation and the conflicts between countries like North and South Korea. But their research also examines new and emerging areas that transcend traditional borders – the drug war in Mexico and expanding terrorism networks. FSI researchers look at the changing methods of warfare with a focus on biosecurity and nuclear risk. They tackle cybersecurity with an eye toward privacy concerns and explore the implications of new actors like hackers.

Along with the changing face of conflict, terrorism and crime, FSI researchers study food security. They tackle the global problems of hunger, poverty and environmental degradation by generating knowledge and policy-relevant solutions. 

-

* Please note all CISAC events are scheduled using the Pacific Time Zone.

 

Register in advance for this webinar: https://stanford.zoom.us/webinar/register/8416226562432/WN_WLYcdRa6T5Cs1MMdmM0Mug

 

About the Event: Is there a place for illegal or nonconsensual evidence in security studies research, such as leaked classified documents? What is at stake, and who bears the responsibility, for determining source legitimacy? Although massive unauthorized disclosures by WikiLeaks and its kindred may excite qualitative scholars with policy revelations, and quantitative researchers with big-data suitability, they are fraught with methodological and ethical dilemmas that the discipline has yet to resolve. I argue that the hazards from this research—from national security harms, to eroding human-subjects protections, to scholarly complicity with rogue actors—generally outweigh the benefits, and that exceptions and justifications need to be articulated much more explicitly and forcefully than is customary in existing work. This paper demonstrates that the use of apparently leaked documents has proliferated over the past decade, and appeared in every leading journal, without being explicitly disclosed and defended in research design and citation practices. The paper critiques incomplete and inconsistent guidance from leading political science and international relations journals and associations; considers how other disciplines from journalism to statistics to paleontology address the origins of their sources; and elaborates a set of normative and evidentiary criteria for researchers and readers to assess documentary source legitimacy and utility. Fundamentally, it contends that the scholarly community (researchers, peer reviewers, editors, thesis advisors, professional associations, and institutions) needs to practice deeper reflection on sources’ provenance, greater humility about whether to access leaked materials and what inferences to draw from them, and more transparency in citation and research strategies.

View Written Draft Paper

 

About the Speaker: Christopher Darnton is a CISAC affiliate and an associate professor of national security affairs at the Naval Postgraduate School. He previously taught at Reed College and the Catholic University of America, and holds a Ph.D. in Politics from Princeton University. He is the author of Rivalry and Alliance Politics in Cold War Latin America (Johns Hopkins, 2014) and of journal articles on US foreign policy, Latin American security, and qualitative research methods. His International Security article, “Archives and Inference: Documentary Evidence in Case Study Research and the Debate over U.S. Entry into World War II,” won the 2019 APSA International History and Politics Section Outstanding Article Award. He is writing a book on the history of US security cooperation in Latin America, based on declassified military documents.

Virtual Seminar

Christopher Darnton Associate Professor of National Security Affairs Naval Postgraduate School
Seminars
Authors
News Type
News
Date
Paragraphs

Three CISAC scientists have joined 26 of the nation’s top nuclear experts to send an open letter to President Obama in support of the Iran deal struck in July.

“The Joint Comprehensive Plan of Action (JCPOA) the United States and its partners negotiated with Iran will advance the cause of peace and security in the Middle East and can serve as a guidepost for future non-proliferation agreements,” the group of renowned scientists, academics and former government officials wrote in the letter dated August 8, 2015.

“This is an innovative agreement, with much more stringent constraints than any previously negotiated non-proliferation framework.”

CISAC senior fellow and former Los Alamos National Laboratory director Sig Hecker is a signatory to the letter, along with CISAC co-founder Sid Drell, and cybersecurity expert and CISAC affiliate Martin Hellman.

Six Nobel laureates also signed, including FSI senior fellow by courtesy and former Stanford Linear Accelerator director Burton Richter.

The letter arrives at a crucial time for the Obama administration as it rallies public opinion and lobbies Congress to support the Iran agreement.

You can read the full letter along with analysis from the New York Times at this link.

Hero Image
19069162993 6feec3cd1b o
All News button
1
-

Media: please reach out to cisacevents@stanford.edu

About the Event 

Estimates of fatalities in a nuclear war range from none to Earth’s population. We can confidently state if there is never a nuclear explosion, there will be no fatalities. But what is the most probable loss? Fatalities from explosions in populated areas could be in the hundreds of millions, exceeding those from fallout radiation by a factor of ten. However, fatalities from environmental changes and the breakdown of society, which together may collapse global agriculture, could exceed those from blast by another factor of ten, approaching the population of the planet. Fatalities from blast, burns and prompt radiation are relatively easy to compute, but those from environmental changes are difficult to predict. We know that physically similar, but more extreme, environmental insults occurred 66 million years ago due to an asteroid impact and caused the extinction of about 75% of the known species. Toon will go through the chain of complex issues that need to be addressed to compute the environmental changes, their uncertainties and their impacts on humans: likely targets; fuel loads; fire ignition; smoke production, composition, lofting and rainout; climate response to stratospheric smoke; and agricultural responses to climate changes. A recent U.S. National Academy of Science panel recommended that multiple agencies fund research to reduce the uncertainties. For example, new satellite based global measurements of building types and volumes can provide improved fuel loads. Measurements of smoke from burning buildings, now non-existent, could determine smoke composition. New aircraft data on smoke from wildfires could inform lofting. However, no federal agency has developed a research program, just as they have avoided doing for the past 40 years. Thousands of scientific papers have been written about the extinction of the dinosaurs, but tens about our possible fate from a nuclear conflict. NASA is searching for asteroids that might hit us and planning how to stop them. But nuclear stockpiles are increasing, more countries seek nuclear weapons, and new and more terrifying weapons are being built.

About the Speaker

Brian Toon studies radiative transfer, aerosol and cloud physics, and parallels between Earth and planets. He led NASA airborne missions studying volcanic clouds, ozone holes, and cloud-climate impacts. Toon published about 400 refereed scientific papers, and co-authored Earth in Flames. He received the American Physical Society's Leo Szilard Award for work on nuclear winter and was recognized by the UN Environmental Program for contributions to the Nobel Peace Prize winning IPCC reports. Additionally, he won the American Geophysical Union’s Roger Revelle Medal, the American Meteorological Society’s Carl-Gustaf Rossby Medal, and the 2022 Future of Life Award for reducing the risk of nuclear war.

Please join us for refreshments in the Oksenberg Conference Center following the conclusion of the lecture from 5:00 - 6:00 PM.  All CISAC events are scheduled using the Pacific Time Zone.

James D. Fearon
James Fearon
Brian Toon
Lectures
Date Label
Paragraphs

OVERVIEW
 

The global demand for “AI sovereignty” is increasingly shaping AI policy and safety discussions. What was once a niche concern has become a widely shared priority, with more countries seeking control over how AI is built, deployed, and governed within their borders. This memo synthesizes key insights on the drivers of AI sovereignty, how countries are operationalizing it in practice, and the implications for U.S. diffusion strategy and managing global risks.

Three premises frame the analysis. First, emerging economies and middle powers are becoming crucial partners, consumers, and suppliers in the global AI ecosystem. Second, U.S. leadership in frontier AI creates a narrow—and likely diminishing—window to shape how this technology diffuses. Third, understanding what countries actually want from AI is critical to designing a sustainable U.S. diffusion strategy and navigating shared risks.

These insights draw on ongoing research from the Carnegie Endowment for International Peace (CEIP) and Stanford's Program on Geopolitics, Technology, and Governance (GTG), and were further developed at a workshop, “AI Sovereignty, Diffusion, and Risk: Strategy in a Contested Landscape,” convened by CEIP and GTG on June 17, 2026 with experts from civil society, industry, and academia.
 

KEY INSIGHTS
 

“AI sovereignty” is a politically potent but analytically ambiguous concept, driven primarily by a desire to manage dependence and extractivism, and to obtain AI suited to local contexts.
 

While the term “AI sovereignty” is ambiguous, it has become an increasingly influential part of international AI discussions. Sovereignty goals seem less about achieving true technological autarky (widely seen as unfeasible), and more about a desire to secure national interests (economic, security, cultural) within a tech landscape dominated by the U.S. and China. In this way, AI sovereignty might be practically understood better as “AI agency:” a country's ability to execute choices in line with national interests. In search of this agency, countries will likely pursue a strategy that combines assured access arrangements for foreign AI models and hardware with efforts to diversify and build domestic capacity (indigenous or modified foreign open-source) if such access is disrupted. These domestic capacity efforts tend to focus on cheaper, multilingual, and multimodal models contextually attuned to underserved markets.

Sovereignty can serve as a source of resilience, and, increasingly, may serve as a deterrent against being cut off from frontier AI capabilities. To achieve this deterrent effect, countries are likely to seek sources of leverage along the AI value chain. These may include:

  • Control over scarce resources in the AI supply chain, such as critical minerals or low-cost energy for powering data centers.
  • Significant market power that makes a country an indispensable consumer of AI services.
  • Refining high-value local data for domestic value capture.
     

These sources of leverage, however, could be a depreciating asset, as a nation may only be able to threaten or use its leverage once before providers diversify away from it.

Perceptions of AI risk within sovereignty debates rarely focus on concerns over shared catastrophic and large-scale threats.
 

Discussions of AI sovereignty in many middle powers and emerging economies are primarily driven by concerns over dependency, extractivism, market concentration, and geopolitical subordination. Cross-border, large-scale AI risks like cyberattacks, biosecurity, or rogue AI agents have not been central to these debates to date, as they are often perceived as remote or lower priority than immediate economic and political concerns and assured access to AI technology.

Recent events, such as the U.S. government blocking Anthropic's Fable model access, have reinforced this focus on dependency. While the incident highlighted the potential for dangerous capabilities, the primary international reaction has been concerned with the U.S. wielding a “kill switch” over model deployment, reinforcing fears of unilateral control and strengthening the case for AI sovereignty.

This dynamic could shift as AI capabilities diffuse. The widespread availability of powerful models capable of causing significant cross-border harm, such as cybersecurity failures in critical infrastructure, may force a re-evaluation. In such a scenario, the salience of shared safety and security could rise, potentially aligning national interests more closely with global risk mitigation efforts.

Countries are actively pursuing sovereign AI projects, but a significant gap persists between ambitious strategies and operational capacity.
 

A clear trend of sovereign-related AI projects and announcements is underway globally, especially in the EU, Indo-Pacific, and Gulf States. These initiatives range from building national compute clusters and developing domestic models to pursuing legal arrangements to ensure data localization and provide assured access to foreign AI models.

However, a significant gap often exists between high-level ambitions and the operational capacity to implement them, as many efforts lack clear funding and technical expertise.

The viability of these national ambitions may hinge on a critical, and often unresolved, distinction: identifying which use cases can use “good enough” AI, relying on less advanced models and infrastructure, versus those that require access to the frontier.

The future trajectory of AI—whether dominated by a few frontier labs or a broader open-source ecosystem—is a central uncertainty shaping national strategies.
 

A fundamental tension exists between two potential AI futures: one where a handful of frontier labs create a runaway capability gap, and another where open-source models remain competitive and useful for most purposes.

In a world where frontier models pull away, a U.S.-led stack could become central to the global economy and international security, giving the U.S. unprecedented insight and international leverage.

In contrast, in a world where open-source and fast follower models remain competitive, the strategic calculus shifts, potentially lowering the stakes of frontier competition for many countries and enabling more diversified technology ecosystems.

The concept of an organized “third stack” as an alternative to U.S. and Chinese ecosystems built on open-source models and diverse hardware is a potential pathway for middle powers seeking to avoid dependency. This alternative is only viable if a coalition of middle powers align on standards for procuring and deploying AI to pool their collective purchasing power; the European Union’s regulatory and tech sovereignty efforts are informed by this logic. However, multi-state organization around a third stack faces significant collective action problems, and any effort to create an independent stack could be viewed as a challenge to U.S. national security, incentivizing Washington to pursue bilateral engagements that thwart an emergent alternative.

Even with open models, countries may still want assured access to frontier AI for limited, exquisite capabilities.
 

Even if many countries' economic, development, and security goals can be achieved through “good enough” AI, countries may want access to high-end capabilities for specific purposes. This could give the United States an opportunity to offer assured access to frontier AI in exchange for safety and security commitments.

However, an assured access framework faces major challenges:

  • Trust in U.S. assurances: The U.S. is often not currently seen as a credible, long-term partner. Without trust, assurances are secondary to mutual leverage.
  • Third country leverage: A security–frontier bargain appears most viable with countries that possess something the U.S. wants (e.g., India's data, Brazil's energy resources). Leverage is unclear for states that lack such bargaining chips.
  • Risk perception gap: Safety commitments, especially those framed around catastrophic risks, do not resonate strongly in many parts of the world, where developmental and economic priorities are paramount. For Global Majority economies, legible near-term AI risks include displacement of labor within domestic informal sectors and the devaluation of labor within global value chains.
     

Significant doubts about the U.S. government's ability to execute a nuanced AI partnership strategy highlight the roles of market forces and non-state actors.
 

Many believe the U.S. government currently lacks the capacity and planning to execute a complex global AI diffusion strategy. The U.S. government’s existing toolkit for promoting the U.S. tech stack, including bodies like the Development Finance Corporation (DFC) and EXIM Bank, is difficult to deploy effectively. The government's most effective role may be to de-risk investment and lend credibility in geopolitically critical areas where a natural market does not exist.

In the absence of a robust government strategy, market forces are the primary driver. The quality of U.S. technology creates a natural pull, but this may be counteracted by U.S. policy unpredictability.

In this vacuum, non-governmental actors are stepping in. Philanthropic organizations are brokering agreements between U.S. AI labs and Global Majority countries for specific use cases. However, it remains unclear if these ad-hoc efforts can scale into a coherent ecosystem that benefits U.S. interests.

PRIORITIES FOR FURTHER RESEARCH
 

This analysis surfaces several unresolved questions that warrant further research and debate. Priorities for future inquiry include:
 

  • Clarifying the competing futures of AI: Under what conditions might frontier AI models achieve a decisive, compounding advantage over open-source alternatives? What are the key technical and economic indicators that policymakers should monitor to assess which future is becoming more likely? What are the implications for AI risk management?
  • Mapping points of national leverage: Beyond theoretical control over chokepoints, what forms of economic, political, or geographic leverage have proven most effective for middle powers in securing favorable terms for AI access? How durable is this leverage, and can it be pooled regionally to overcome collective action problems?
  • Designing a viable U.S. partnership model: What specific, actionable policy tools are required for the U.S. to offer a compelling “assured access” bargain? How can such a policy be designed to be credible across administrations, especially for countries that lack significant intrinsic market or resource leverage? How should AI risks factor in?
  • Integrating safety into diffusion frameworks: How do perceptions of AI risk influence national sovereignty strategies? What practical mechanisms can embed safety and security commitments into technology partnerships?
     

Download the full PDF here.

All Publications button
0
Publication Type
Policy Briefs
Publication Date
Journal Publisher
GTG–CEIP
-

About the event: Why do adversaries sometimes cooperate to restrain their military competition? Why do they design arms control agreements with intrusive verification in some cases but rely on minimal transparency in others? Amidst ongoing international competition, arms control remains rare despite potential mutual benefits, and agreements vary dramatically in their approaches to monitoring. This book reveals how uncertainty from domestic political changes - such as leadership transitions or social unrest - can enable arms control. It identifies two paths to agreement: during periods of uncertainty, states that previously relied on informal understandings hedge by establishing lightly-monitored agreements, while those that anticipated deception take calculated risks through agreements with intensive verification. Through comprehensive data analysis and rich case studies, Jane Vaynman challenges conventional wisdom about uncertainty in international relations while offering insights for policymakers. As states confront challenges from nuclear competition to emerging technologies, understanding when arms control becomes viable is more vital than ever.

About the speaker: Dr. Jane Vaynman is an Assistant Professor of Strategic Studies at the School of Advanced International Studies (SAIS) at Johns Hopkins University. Dr. Vaynman’s work focuses on security cooperation between adversarial states, the design of arms control agreements, and the effects of technology on patterns of international cooperation and competition. From 2022-2024, she served as a senior advisor in the Bureau of Arms Control, Deterrence, and Stability at the U.S. Department of State. Her prior academic appointments include the Department of Political Science at Temple University and the Elliott School of International Affairs, George Washington University. She was also previously a Lightning Scholar at Perry World House at the University of Pennsylvania, a Stanton Nuclear Security Fellow at the Council on Foreign Relations, and a Fulbright Fellow at the Carnegie Moscow Center. Dr. Vaynman received her Ph.D. in political science from Harvard University and B.A. in international relations from Stanford University.

 All CISAC events are scheduled using the Pacific Time Zone.

No filming or recording without express permission from speaker.

William J. Perry Conference Room

Jane Vaynman
Seminars
Date Label
-

About the event: This talk will discuss recent advancements in AI for biology, and relevant security and oversight considerations. It will also discuss how policy can be used to incentivize and shape technology development for defensive purposes, clarifying how the colloquial "defensive acceleration" or d/acc concept in AI circles relates to formal offense-defense balance concepts.

About the speaker: Dr. Pannu is an Assistant Professor at the Johns Hopkins Bloomberg School of Public Health and Senior Scholar at the Center for Health Security. She is currently Director of Frontier Safety at the Chan Zuckerberg Biohub, a philanthropic research organization focused on AI for biology. Dr. Pannu’s primary areas of research include biosecurity, pandemic preparedness, and emerging technology security and governance. Dr. Pannu previously worked on AI-enabled diagnostics at Google and has served as a subject-matter expert for the National Academies of Sciences, the EU AI Office, and the Bipartisan Commission on Biodefense, among others. She serves on the board of Blueprint Biosecurity, a nonprofit dedicated to achieving breakthroughs in humanity's ability to prevent pandemics. Dr. Pannu regularly briefs government officials and policymakers on emerging technologies with security implications, including artificial intelligence and synthetic biology.

 All CISAC events are scheduled using the Pacific Time Zone.

No filming or recording without express permission from speaker.

William J. Perry Conference Room

Jassi Pannu
Seminars
Date Label
Paragraphs

Saudi Arabia and the United States signed a landmark civilian nuclear cooperation agreement last Wednesday. Although its text has not been released, reports indicate that it includes a thirty-year American commitment to develop the Kingdom's civilian nuclear sector, including the construction of nuclear power plants and the option of establishing uranium-enrichment facilities on Saudi soil, contingent on a two-year economic feasibility study.

From an Israeli perspective, the agreement represents a significant, and potentially dangerous, departure from longstanding U. S. nuclear export policy. This raises several urgent concerns for Jerusalem.

Continue reading at Haaretz.com

All Publications button
1
Publication Type
Commentary
Publication Date
Subtitle

The agreement between Washington and Riyadh could create a regional nuclear arms race, while forgoing the only advantage Israel wanted to gain from it: Saudi normalization

Authors
Or (Ori) Rabinowitz
-

About the event: Since the mid-2010s, scholars and analysts have declared the emergence of a dangerous ‘new’ or ‘third’ nuclear age. Beyond academia, the concept of the new nuclear age is proving influential with policymakers in a range of countries. The new nuclear age is understood to be characterized by technological change, nuclear multipolarity, eroding constraints on the behavior and competition of nuclear-armed states, and the likely emergence of new nuclear powers. That said, it remains unclear how we should understand the new nuclear age in broader terms: how new is it and does it require new theoretical frameworks to understand? Bell subjects the concept of the new nuclear age to scrutiny. He connects the discussion of the new nuclear age to ongoing but mostly separate debates about nuclear history and the ‘Theory of the Nuclear Revolution’ (TNR). The increasing body of literature challenging TNR reveals a more competitive, complex, and dangerous nuclear past than our prior understandings, but in doing so, it draws attention to continuities between the past and the emerging nuclear age. Bell then examines the empirical features thought to define the new nuclear age and show that many have historical precedent and do not require novel theoretical frameworks to understand. The new nuclear age may, therefore, be somewhat less new, though perhaps no less dangerous, than it appears.

About the speaker: Mark Bell is an Associate Professor of Political Science at the University of Minnesota. His book, Nuclear Reactions: How Nuclear-Armed States Behave, won the ISA Foreign Policy Analysis Section's best book award. Other work has been published in International Organization, International Security, International Studies Quarterly, Journal of Conflict Resolution, Journal of Strategic Studies, and Texas National Security Review. Policy-oriented work has been published in Foreign Affairs, War on the Rocks, and The Washington Quarterly. He holds a Ph.D from MIT, a Master's in Public Policy from Harvard Kennedy School, and a B.A. from St Anne’s College, Oxford University.

 All CISAC events are scheduled using the Pacific Time Zone.

No filming or recording without express permission from speaker.

William J. Perry Conference Room

Mark Bell
Lectures
Date Label
Paragraphs

In late August 2021, United States President Joseph Biden hosted the newly elected Israeli Prime Minister, Naftali Bennet, at the White House for an official meeting. Shortly after, Israeli journalist Barak Ravid reported that Biden and Bennet ‘reaffirmed the strategic understandings’ between the two allies on Israel’s ‘alleged undeclared military nuclear program’, noting that this reaffirmation of policy has been repeated by every US President since Richard Nixon.1 As shall be explored below, this statement is mostly accurate, with the seemingly glaring exception of President George H.W. Bush. Upon its publication, Ravid’s story became the most recent in a long line of reports detailing this repeated commitment by US presidents to their Israeli counterparts.2

What role does this commitment play in Israel’s long history with the Nuclear Non-Proliferation Treaty (NPT)? The primary aim of this article is to answer this question by charting Israel’s relationship with the NPT and its decades-long fear of American coercion to join it. A secondary aim of this article is to provide a concise primer, or introduction, to this nuanced question for scholars and students alike, by reviewing the existing literature and adding insights from new archival sources to this growing body of work.

The paper proceeds in three parts. The first charts the emergence of Israel’s NPT policy and the technical-diplomatic road which led to the emergence of the policy in the late 1960s and the early 1970s. The second charts how this policy impacted Israel’s nuclear energy policy in the following decades, ultimately preventing it from pursuing its plan of launching a massive civilian nuclear infrastructure program, specifically nuclear power plants for electricity production. The third concludes with charting Israel’s NPT policy at the end of the Cold War. Research for this study was conducted in archives in the US, United Kingdom, Canada, and Israel, and taps both primary and secondary sources; Hebrew translations are by the author, unless otherwise noted.3

All Publications button
1
Publication Type
Journal Articles
Publication Date
Journal Publisher
Cold War History
Authors
Or (Ori) Rabinowitz
Paragraphs

Washington’s alliances are under immense strain. Many allies and partners are subject to increased threats from great-power adversaries, and they are coming to doubt whether they can rely on the United States. The response to these pressures is to rearm. Like the United States itself, U.S. partners across Asia, Europe, and elsewhere are building up their defense industrial and technological bases to improve their ability to project power, deter enemies, and prevail in a protracted conflict.

Continue reading at foreignaffairs.com

All Publications button
0
Publication Type
Commentary
Publication Date
Subtitle

America and Its Allies Must Pool Their Efforts

Journal Publisher
Foreign Affairs
Subscribe to Security