11 September 2026

Cognitive Warfare Runs on Data: The Definition Washington Still Owes

Small Wars Journal | Robert Green

The deadline set by the 2026 National Defense Authorization Act for the United States Department of War to define the concept of cognitive warfare was 31st March 2026, and by that date no public release had been made. The fact that this deadline has passed leaves the country strategically vulnerable since both China and Iran are currently carrying out disinformation campaigns tailored to entire populations in order to change public opinion.

In contrast to traditional propaganda, which uses mass broadcasting, modern cognitive operations make use of algorithmic profiling of large amounts of personal data in order to send highly targeted and personalised messages. Data is the weapon in this approach. Adversaries regard large-scale data theft, for example the breach of the Office of Personnel Management, and future quantum decryption of intercepted communications as essential aspects of their operations. The strategy based on data collection is aimed at minors so as to create long-term behavioural profiles of future national security personnel. As a result, countering this kind of threat means considering bulk-data security, the privacy of children, and the transition to post-quantum encryption as fundamental parts of national defence and involves shifting the focus from message-centric platforms to protection at the data layer.

Comment

Seeing bulk data acquisition as analogous to the logistics of cognitive warfare transforms state-sponsored cyber espionage from a passive activity involving the collection of intelligence into an active operation within the supply chain. The Ministry of State Security does not regard historical American data stores as fixed archives, but instead sees them as a source of raw material for future algorithmic targeting. The 2015 breach of the Office of Personnel Management is an example of this long-term sustainment strategy, since the security clearance records that were stolen have been used as basic datasets for profiling future decision-makers. This change reveals a serious weakness in the Pentagon's defensive systems, which consider network intrusions to be isolated and temporary privacy incidents rather than ongoing operational threats.

As a result of this, the main cognitive defence mechanism moves from the US Cyber Command to civil regulatory agencies. It is the Department of Justice's Data Security Program and the Federal Trade Commission that become the first responders responsible for preventing adversaries from obtaining the logistical resources they need. In the end, the Department of War's ability to deal with Chinese cognitive campaigns relies on combining the Federal Trade Commission's enforcement activities with military intelligence systems.

Strategic Question for Discussion
How can the Department of War incorporate civilian data-protection standards into its military threat evaluations if the Federal Trade Commission's regulatory enforcement becomes the main protection against cognitive logistics and this involves violating the domestic intelligence-collection limits?
The present course of events indicates that overcoming this divide between the institutions will depend on having a common threat framework under which civilian regulatory actions correspond directly to military risk models. I believe that setting up a joint data-intelligence unit between the Federal Trade Commission and the Department of War would involve translating trends in commercial data harvesting into actionable defence indicators. By doing this, the approach maintains the country's domestic legal boundaries since it directs military focus onto the collection methods used by foreign adversaries rather than on the personal data of American citizens.
Share your assessment in the comments below.