AI Is Coming for the Chain of Command

37 minutes ago 3
Chattythat Icon

The voice belonged to Gen. Tareq Saleh. It was telling his men to fall back. Or so it seemed.

“Advances and retreats are a normal part of war,” the recording reasoned. “Pull back toward Mocha.”


It was mid-September. Houthi fighters were pressing Yemen's Red Sea coast from three directions. The comms moved through the phones of the National Resistance, a coalition loyal to the Hadi-led government, the way it often does when battles are being lost: fast and full of confusion. Clausewitz termed this the ‘friction’ of warfare. A social media account with half a million followers pushed the message out.

By the time the general's media office caught up, the damage was done. Saleh had given no such order, they announced. The audio was an AI deepfake, an attempt to sow confusion and warp the reality of the battlefield. From then on, authentic statements would come only through official channels. Anything else should be considered a lie..

On September 10, Mocha fell anyway. Sitting 45 miles up the coast from the Bab al-Mandeb strait, it was the last port fully controlled by Yemen's internationally recognized government. Within days, the Houthis had taken Dhubab, reached Perim Island, and are in route to effectively claiming the entire Red Sea shoreline.

Exactly what the recording accomplished is unknowable from the outside. The claim that it was AI-generated hasn't been independently verified. Whether it did or didn’t happen doesn’t necessarily matter; the technology and techniques behind it are very real. The National Resistance did end up withdrawing—a move their own accounts describe as a tactical repositioning ordered by Saleh himself.

This means a fake retreat order and a real one might have hit the same phones, in the exact same voice, on the exact same day. Imagine trying to sort that out under the fog of war.

Whoever made the clip didn't need to jam a network or get inside a headquarters. They just needed a few clean seconds of a public figure speaking—Saleh has hours of tape online—and basic AI software that costs about as much as a streaming subscription. Then they needed a moment when the men listening were exhausted, terrified, and primed to believe the worst. War often supplies those.

The first attempt at this was crude: in March 2022, a deepfake of Volodymyr Zelensky telling his soldiers to lay down their arms was laughed off the internet in hours. Mocha is what four years of rapid technological progress in AI cloning looks like in real time.

Americans shouldn't file this under things that happen in Yemen. It's already happening in Washington.

In May 2025, U.S. senators, governors, and business executives started getting spoofed calls and texts from someone posing as White House Chief of Staff Susie Wiles. A month later, an impostor using an AI-generated voice and a fake Signal account labeled "marco.rubio@state.gov" reached out to foreign ministers, a governor, and a member of Congress. The attacker left voicemails for some and texted others to move the conversation onto the encrypted app.

The State Department dismissed the attempts as "not very sophisticated"—supposedly meant as reassurance. But the FBI saw the broader danger, repeatedly warning that current and former senior officials are being impersonated via text and cloned audio to harvest authentication codes and contacts. Their primary advice boils down to what families have done for decades to thwart phone scams: agree on a secret word for bona fides.

Notice where all of this happened. Not on JWICS, the government's top-secret network, or on SIPRNet below it. Those systems were built with identity as a first principle: hardware tokens, certificates, closed enclaves. Faking a general's identity on JWICS is a hard problem.

This happened on cell phones, in voicemails, on Signal. These are the exact same commercial channels where, a few months earlier, the Secretary of Defense was caught casually sharing Houthi strike timings in a group chat. The people handling the country's most sensitive business rely on unauthenticated voice calls every day, simply because it is fast and it is what they have.

Now follow the org chart down to where the next gray-zone crisis will actually be handled.

The conflicts most likely on the horizon aren't declared wars. A naval squeeze around Taiwan that stops short of an invasion, cable-cutting in the Baltic, a cyber-physical hit on a U.S. power grid timed to a hurricane. Each is designed to stay just below the threshold that triggers a military response, namely ‘gray-zone’ conflict. And the people fighting on this new frontline are those who’ve likely never held a security clearance or been issued one.

Utility control-room supervisors. Port and rail dispatchers. County emergency managers. Hospital administrators. Sheriffs and police chiefs. Guard commanders in the chaotic hours before federal orders arrive. Roughly 85 percent of American critical infrastructure is privately owned. Its operators coordinate with one another and the government over the phone, emails, WhatsApp groups. Often times the only authentication protocol is simply that they recognize the voice.

Run the Mocha playbook (whether it in fact really happened is largely beside the point because the technology to pull it off already exists) against this setup. A line crew gets a call from the voice of its operations chief, ordering them to open breakers at a substation, per a request from the state government. A terminal manager hears the captain of the port telling him to halt cargo operations. Police officers holding a perimeter at a pipeline facility get their chief on a cell phone, telling them to pull back two blocks. A regional emergency manager gets the governor's voice—from the governor's actual number—moving an evacuation route. Caller-ID spoofing has been trivial for a decade.

None of these calls has to hold up to intense scrutiny under the pressure of a crisis. Twenty minutes of a crew driving the wrong way, or a line of officers giving up ground they then have to retake, is all a gray-zone adversary is buying.

Grid operators already use a read-back protocol for verbal switching orders. It confirms that the instruction was heard correctly. It does not confirm who gave it. Police radio discipline operates on the exact same assumption. Swatting has shown for years how far a stranger can move armed responders with one confident phone call—and swatters are teenagers with a grudge, not a state with a target list.

But the second-order effect is worse than the first. Once everyone knows voices can be faked, real orders can be doubted …and real leaders can easily disown what they actually said.

Saleh's genuine withdrawal order, if that is what it was, went out to men who had just been explicitly told not to trust his voice. A police chief who really needs officers off a line, or a utility executive who really needs a plant shut down before it fails, will be giving that order into the same fog of paranoia. An adversary doesn't need to counterfeit every message. They just need to counterfeit one in order to let suspicion undermine the credibility of command chain authority.

Some of the fixes are old. Challenge-and-response is as old as sentries; the FBI's secret word is the Normandy paratrooper's cricket clicker in modern packaging. Any order to withdraw, shut down, stand down, or evacuate should be treated as unverified until confirmed on a second channel: a callback to a known number, a message on a signed system, a second person. Yes, that rule costs minutes, and minutes are dearest in a crisis. That’s exactly why it has to be drilled in peacetime. GridEx, Cyber Storm, and the state tabletop circuit should be injecting cloned-voice orders right now and finding out who follows them.

Other fixes are newer and cheaper than they sound. Cryptographically signed messaging isn't exotic; the same certificates that protect the classified world can be issued to the people who run ports and substations. CISA and state fusion centers could write a standard for what a verified operational order looks like, and who may issue one, without waiting for legislation. And every organization that might matter in a crisis should decide—before the crisis hits—exactly which channels its leaders' real instructions come through and ensure everyone in the chain-of-command understands these.

The question barreling toward the ‘new frontlines’ of gray-zone conflict, every control room, port operator, and police precinct in the country, is the same one those Yemini soldiers had to answer with the Houthis at the gates: How do you know who’s actually giving the orders?

The time to ask is before the phone rings.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Read Entire Article