Estimated reading time: 6 minutes · Last updated:
Tom Field warns that artificial intelligence is creating the same class of risks Lord Butler identified in 2004 when his review of intelligence on weapons of mass destruction exposed systemic failings, as first reported by The International Institute for Strategic Studies, where Field is a research fellow. Field cautions that integrating AI into analytic work without new tradecraft could amplify bias, encourage "cognitive surrender" — a phrase used in a University of Pennsylvania study — and open a fresh frontier for deception. He cites a 2024 MIT and UCL study, observations from AISI in late 2025, a police apology in January 2026 for an AI-generated threat assessment, and an August 2026 disruption by OpenAI as evidence that these dynamics are already materialising.
Key takeaways
- Who: Tom Field at the International Institute for Strategic Studies warns AI integration threatens the integrity of intelligence analysis.
- What Butler did: The Butler Review of 2004 led the United Kingdom to create an independent intelligence-assessment profession after failures in pre-war intelligence.
- Evidence on cognition: A 2024 study by researchers at MIT and University College London found that AI can amplify biases that humans then internalise.
- Adversarial examples: OpenAI disrupted an August 2026 campaign by ChatGPT accounts linked to Russia promoting a fake International Burke Institute.
Table of contents
- Key takeaways
- Why Butler’s 2004 lessons still matter
- How AI changes analyst cognition and practice
- The adversarial frontier: deception, influence and data poisoning
- How the intelligence professions can respond
- Positive and negative drivers for AI in intelligence analysis
- What to be careful about
- Frequently asked questions
Why Butler’s 2004 lessons still matter
Lord Butler’s 2004 review identified failures in how intelligence had been gathered, evaluated and presented before the Iraq conflict; the United Kingdom responded by formalising an intelligence-assessment profession to separate analysis from collection and to strengthen challenge and testing of judgements. Tom Field frames today’s AI moment as a new test of those same safeguards. The original reforms assumed humans would do the critical interrogation of sources and reasoning. AI tools change the information environment and the analyst’s relationship to evidence: they reshape what counts as corroboration, accelerate the pace of output and introduce whole new vectors for misdirection that Butler’s reforms were not designed to meet.
Field therefore treats Butler as a diagnostic lens rather than a blueprint: the institutional goal remains the same — rigorous testing of evidence, uncertainty and judgement — but the mechanisms by which that rigor is maintained must adapt to a world where algorithmic outputs are part of analysts’ evidence base.
How AI changes analyst cognition and practice
Field summarises three cognition risks that researchers are beginning to document. First, models inherit biases from training data and system design; a 2024 study by Massachusetts Institute of Technology and University College London researchers found that AI can magnify small biases and lead users to internalise them. Second, University of Pennsylvania researchers coined the phrase cognitive surrender to describe how humans sometimes accept AI outputs with minimal scrutiny. Third, longer‑term dependence on AI can weaken memory recall and critical-thinking skills, a concern raised by several studies Field cites.
Those trends are not only hypothetical. In late 2025 the UK’s AI Security Institute highlighted models’ growing persuasiveness and wider user reliance, and in January 2026 UK police publicly apologised for a 2025 threat assessment that included AI-generated fabrications. Field also notes how military decision-making already balances the cost of delaying action against the danger of accepting incorrect AI recommendations, and he cites concerns that AI could compress time available for human review in high‑stakes domains such as nuclear command and control.
The adversarial frontier: deception, influence and data poisoning
Field describes how AI systems become new vectors for deception because models are trained on vast quantities of web content that can be manipulated. He points to Russia’s Pravda network as an example of industrial-scale data poisoning: hundreds of websites produced content designed to look like independent sources and thereby influence the inputs AI crawlers observe. Field argues that these tactics can cause models to treat manufactured content as corroboration.
Democratic states, commercial actors and non-state groups also have means to shape model outputs. Field highlights an August 2026 disruption by OpenAI that stopped a ChatGPT-origin campaign linked to Russia promoting a fabricated expert forum called the International Burke Institute. He also notes that companies and individuals can use generative-engine optimisation techniques, and that Nikkei Asia found examples of academics hiding prompt injections to bias automated reviewers, showing the range of actors able to distort model training and downstream outputs.
How the intelligence professions can respond
Field does not offer a detailed technical blueprint, but he sets out the core requirements: preserve human judgement and oversight, develop tradecraft that detects AI-origin deception, and ensure compliance with national law and values. He warns that limiting release of frontier models or withholding access for safety testing, as Anthropic did with Mythos 5.1 and as Field cites, constrains practitioners’ ability to learn a model’s limits; at the same time, unfettered access raises the risk that analysts will simply rely on model outputs without sufficient challenge.
The implication is procedural and organisational: intelligence-assessment professions need new training, updated guidance and methods for stress‑testing model outputs; they must also monitor how model behaviour changes when adversaries attempt to shape underlying datasets. Field frames this as a necessary evolution for any government that wants to use AI while keeping human oversight central to national-security decision-making.
| Item | Source / actor | Date cited | Role in the piece |
|---|---|---|---|
| Butler Review | Lord Butler / UK | 2004 | Catalyst for the UK intelligence-assessment profession |
| Bias study | MIT and University College London | 2024 | Found AI can amplify biases that humans internalise |
| AISI warning | AI Security Institute | Late 2025 | Noted growing persuasiveness of models and user reliance |
| Police threat assessment | UK police | January 2026 (about a 2025 assessment) | Apology for an AI-generated false threat item |
| OpenAI disruption | OpenAI | August 2026 | Disrupted a campaign promoting a fake International Burke Institute |
Positive and negative drivers for AI in intelligence analysis
The case for
- AI can increase the speed and scale of data processing, allowing analysts to surface patterns in larger datasets than human teams could review manually.
- When coupled with rigorous testing and challenge, models can serve as force multipliers that help analysts generate and test alternate hypotheses more quickly.
The case against
- Models that inherit biased training data can amplify those biases and lead humans to adopt flawed judgements, as shown by the 2024 MIT and UCL study.
- Adversaries able to manipulate online content or deploy targeted influence operations can corrupt the inputs models use, producing deceptive outputs that appear corroborated to both machines and humans.
What to be careful about
- Cognitive surrender: analysts accepting AI outputs with minimal scrutiny, a risk named by University of Pennsylvania researchers.
- Model deception through data poisoning and influence operations, exemplified by Russia’s Pravda network and the OpenAI-disrupted August 2026 campaign.
- Erosion of analytic skill over time if staff rely excessively on AI, linked in the piece to worsened memory recall and critical thinking in studies Field cites.
- Compression of decision time in high-stakes fields such as nuclear command and control, which could reduce opportunities for human challenge.
The bottom line
Tom Field’s argument is straightforward: the institutional fixes that followed the Butler Review need updating for an environment in which algorithmic systems are both tools and targets. The evidence he brings together — academic studies from 2024, AISI commentary in late 2025, a public police apology in January 2026, and an OpenAI disruption in August 2026 — shows the risks are active today. Intelligence professions must therefore develop new tradecraft, training and testing regimes that preserve human judgement, detect AI-enabled deception and retain legal and ethical oversight if they are to avoid systemic failures akin to those Butler exposed in 2004.
What to watch
- Watch for the outcome of investigations into the January 2026 police use of an AI-generated threat assessment; no date has been set.
- Watch for disclosures from vendors and safety bodies about access and testing of frontier models, including the withheld Mythos 5.1; no date has been set.
- Watch for guidance or procedures published by national intelligence-assessment professions on how to integrate AI; no date has been set.
Frequently asked questions
What did Lord Butler’s 2004 review change in UK intelligence?
The Butler Review of 2004 exposed failings in pre‑Iraq War intelligence and led the United Kingdom to establish an independent intelligence-assessment profession to separate and strengthen analysis and the testing of judgements.
How do we know AI can distort human judgement?
Field cites a 2024 study by researchers at MIT and University College London that found AI can magnify biases in training data and cause humans to internalise those distortions, and he also cites AISI observations from late 2025 about models’ growing persuasiveness.
Have there been real-world incidents tied to AI in analysis?
Yes: Tom Field notes a January 2026 UK police apology over a 2025 threat assessment that contained AI-generated fabrications, and OpenAI reported disrupting an August 2026 ChatGPT-origin influence campaign linked to Russia.
Related reading