A U.S. Special Operations Command analyst reportedly used an AI chatbot to assess a Chinese vessel transiting the Middle East during the Iran war, producing a false claim that it carried components for China’s nuclear-weapons program. The assessment reportedly combined open-source vessel-manifest data with classified signals intelligence, then used AI again to draft a formal intelligence report without an intervening human verification step.
The report triggered preparations for an armed interception and boarding, with aircraft reportedly already airborne, before officials checked the underlying source and determined the cargo identification was wrong. The near-confrontation, reported by CNN and attributed to four people familiar with the episode, underscores the operational danger of unverified AI-generated intelligence as the Pentagon accelerates deployment of AI across intelligence and mission systems.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The false intelligence assessment reportedly prompted U.S. preparations to intercept and board the vessel with air support; armed personnel were preparing to board and aircraft were reportedly already airborne. Officials halted the operation after checking the underlying source and determining the chatbot had misidentified the cargo.
During the Iran war, a Special Operations Command Pacific analyst reportedly used a chatbot to assess a Chinese vessel's manifest using open-source and classified signals intelligence, falsely concluding it carried nuclear-weapons-program components. The analyst reportedly used AI again to turn the erroneous conclusion into a formal intelligence report without intervening verification.
The Department of Defense rolled out an AI acceleration strategy intended to make data across federated and mission IT systems available for AI use; the strategy also sought to make AI models available to military and civilian personnel across classification levels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.