August 18, 2026

The Intelligence Factory: How AI Is Replacing the Nation-State Back Office

Dream Research Team

For years, "advanced" in Advanced Persistent Threat (APT), the term for state-sponsored hacking groups, meant something: it told you a government was behind an attack, not a criminal gang. That distinction is disappearing, and AI is speeding it up.

But the more interesting story isn't about better malware. It's about what actually gives offensive state intelligence operations their edge in the first place. It isn't technical sophistication, it's the huge, specialized workforce standing behind it: collectors, translators, and analysts who turn raw access into finished intelligence. That workforce is part of what let states run tailored operations, shaped precisely to a specific target and a specific strategic goal, rather than the opportunistic, whoever-we-can-reach approach that characterizes most criminal activity.

Tailoring at that level was expensive enough that it required a full institution.

The actual driving force behind APT-level operations was the massive manpower required to translate, contextualize, analyze, task, disseminate and leverage gathered intelligence. This is now remarkably easy with AI and, potentially, far more impactful than new found agentic offensive scaffolding and harnesses capabilities.

1. The gap was never only about technical sophistication

The technical line between top-tier states and top-tier criminal groups had already blurred before AI arrived. Criminal crews were already wielding the kind of technical capability that used to mark a state: for example, the financially motivated Cl0p gang exploited a string of zero-day vulnerabilities in enterprise file-transfer software, GoAnywhere, MOVEit, and Accellion, to mass-hack and extort hundreds of organizations. And the traffic ran the other way too: China's APT41 ran espionage for Beijing while moonlighting for profit in ransomware, cryptojacking, and video-game-currency theft, one group acting as both a state service and a criminal crew. Mandiant found back in 2017, years before generative AI entered the picture, that financially motivated hacking crews had already become capable enough that the line separating them from state operations had effectively vanished.

AI is now accelerating that same convergence. It automates the technical grunt work that used to gate an attack, writing and mutating malware, probing for exploitable flaws, and generating tailored phishing lures on demand, so a handful of operators can now work at a pace and scale that once took a team. CrowdStrike's 2026 Global Threat Report found AI-enabled adversary activity up 89% year-over-year, with average "breakout time" (the time from initial access to full network control) down to 29 minutes, and the fastest on record just 27 seconds. North Korea-linked intrusions were up more than 130%. Cloudflare's 2026 threat report puts it bluntly: AI is erasing the technical barrier to entry for launching a serious attack.

But the technical side was always the part most likely to converge, because it was never institution-dependent to begin with.

Take the NSA's elite hacking unit, Tailored Access Operations, which builds the agency's custom intrusion tools. It reportedly runs with slightly over 1,000 people, out of an intelligence workforce of roughly 100,000. That's a small slice of the institution, because producing technical sophistication is an individual skill: talent, time, a laptop. No institution required, which is exactly why a freelance vulnerability researcher can sell the same caliber of exploit to a criminal buyer, a government broker, or anyone else with money. States never had a monopoly on this. They just paid well for it.

None of this means sophistication is irrelevant: nation states still lead in using the rarest, most expensive exploits. But it was never the real differentiator. Which raises the question: what was?

2. What the "back office" is

The back office is the standing workforce a state builds to turn gained access into something useful. This workforce is what produces tailored intelligence: not just knowing you got into a network, but understanding whose network it is, what matters inside it, and how that fits a specific strategic objective. That's the difference between a smash-and-grab and an operation aimed precisely where a government needs it.

Recall that the NSA's technical unit is a bit over 1,000 people. Now look at the analytic side. A 2011 National Academies report put the U.S. intelligence community's total workforce at roughly 100,000, of whom about 20,000 are analysts.

One in five, an entire workforce twenty times the size of the NSA's elite hacking unit, doing nothing but making sense of what's collected. And that's just the analysts.

It doesn't count the collectors, linguists, and processors who gather raw material and shape it into something an analyst can use. Those functions are substantial in their own right: a separate government accounting found "core" contractors doing collection and analysis work made up about 28% of the total force. Translation alone is its own profession here, not a subset of analysis.

This is the real moat, and it's worth being precise about why. Technical capability can be bought. A skilled exploit developer is for hire, and a working intrusion tool can be acquired on the open market if you have the money. Institutional depth cannot. No budget purchases twenty years of a linguist's regional expertise, or an analytic team's accumulated knowledge of a target. That has to be built, slowly, by people. That's the real barrier to entry, and the one AI is about to remove.

3. Why AI fits this work

Part of what makes the back office so hard to replicate is that it doesn't run like the tidy diagram agencies teach. The textbook model is a clean six-step loop:

  1. Requirements
  2. Collection
  3. Processing
  4. Analysis
  5. Dissemination
  6. Feedback

In practice, it doesn't work that way.

Arthur Hulnick, a former CIA officer, made the case against it in 2006: collection and analysis actually run in parallel, constantly informing each other, and policymakers rarely wait for a finished product before acting. The hard part was never any single step. It was holding enormous context in view at once, recognizing which fragment matters and why, and coordinating many kinds of labour without dropping the thread. For a human, that capacity takes years to build: language fluency, regional knowledge, pattern recognition earned over a career.

That is exactly the kind of work a language model is suited to. Strip away the tradecraft vocabulary, and most of what this workforce does is transform language: translate a document, summarize a report, cross-reference fragmentary accounts, compress it all into something a decision-maker can read in two minutes. That's a language-processing problem, not a novel-reasoning one, and it's precisely what large language models do well, out of the box, without the years of training a human equivalent requires. Applied research groups working with intelligence practitioners agree. Both NC State's Laboratory for Analytic Sciences and the Alan Turing Institute's Centre for Emerging Technology and Security independently found the clearest near-term use of LLMs in intelligence work is translation, summarization, and drafting, not sweeping analytic judgment.

LLMs are genuinely strong at distillation, translating, summarizing, structuring raw material. They're weaker at synthesis: judging intent, spotting deception, weighing strategic risk. Distillation was always the larger share of the workforce by headcount. AI doesn't need to replace the analyst's judgment to be transformative. It just needs to replace the twenty people who used to feed that analyst.

4. This is already happening

The clearest sign this shift is real is that it's showing up at the low end of the spectrum, not just the top. In its Q2 2026 ransomware report, GuidePoint Security documented the criminal data-extortion group FulcrumSec using a large language model to analyse a massive trove of stolen data and identify individuals who appeared across multiple databases. That's not an intrusion technique. It's back-office analytic work, the cross-referencing and sense-making that used to require an analyst, now done by a criminal crew that could never have staffed one. GuidePoint's own framing matches the pattern exactly: AI here isn't enabling exotic new attacks, it's a productivity tool that lowers the cost of repeatable tasks already being done by human operators. As one of the firm's threat intelligence leads put it, AI gives threat actors "a faster path from stolen data to negotiation leverage." That is the distillation step, accelerated.

The same pattern runs all the way up to nation-states. In November 2025, Anthropic disrupted a Chinese state-sponsored group, tracked as GTG-1002, that used Claude to run an espionage campaign against roughly 30 organizations (tech companies, banks, chemical manufacturers, government agencies) almost entirely on its own. The AI ran 80 to 90% of the operation independently, with humans stepping in at only four to six decision points per campaign. And as with FulcrumSec, it wasn't just breaking in. It pulled and organized large volumes of stolen data, doing the triage work that used to take a room full of people. A few months earlier, Anthropic had disrupted a cruder version of the same idea: a criminal group with a human still directing every step. GTG-1002 is what it looks like when the human steps back and lets the AI run the operation.

A criminal extortion crew at one end, a state espionage service at the other, both using AI for the same back-office work, and both moving faster because of it.

5. The advantage is going to whoever has the fewest rules

It's worth noting that, at least for now, the advantage here doesn't go to whoever has the best technology. It goes to whoever is willing to deploy it with the fewest restraints. A 2026 peer-reviewed study in the International Journal of Intelligence and Counterintelligence examined China, Russia, Iran, and North Korea specifically, and found their intelligence services integrating AI into surveillance and intelligence work with little internal oversight. Democracies, by contrast, move more cautiously, slowed by legal review, ethical constraints, and institutional accountability that authoritarian services simply don't have to satisfy. The same guardrails that make democratic intelligence legitimate also make it slower to adopt exactly the capability that's now becoming decisive.

This isn't a claim that authoritarian AI adoption is friction-free. It has real weaknesses of its own, including a tendency for centralized, metrics-driven systems to reward local officials for hiding bad news rather than reporting it accurately, which can leave leadership working from a distorted picture. But the core asymmetry holds: fewer legal brakes on how aggressively a state can deploy AI translates into faster real-world adoption, not just more resources to throw at the problem.

6. The only way to counter this

To conclude, the shift isn't only about better malware. AI is making the back office cheap enough for almost anyone to approximate, and the actors willing to deploy it with the fewest restraints are moving fastest. But that leverage is not the attackers' alone: the same technology reshaping the offense is available to the defense, for any team willing to reach for it.

There's no putting that back.

The analytic layer that used to require an institution is opening up, and it will keep opening whether or not defenders participate. The instinct to slow down, to study, to wait for the frameworks to catch up, is understandable, but attackers are not waiting. If they are using AI to compress weeks of work into hours, defenders cannot afford to keep operating at human speed out of an abundance of caution.

The response is to build the same capability into the institutions that protect against these operations, and to point it at defence. The volume of alerts, logs, and threat signals that security teams face has always outpaced the humans available to make sense of it, and that gap is exactly what AI is suited to close: triaging incidents, correlating signals across noisy data, translating and summarizing threat intelligence, and turning raw telemetry into something a defender can act on quickly. This is the same distillation work that makes AI valuable to attackers, applied to the other side of the problem.

For most organizations, data was never the bottleneck, they are already drowning in it; what they lack is the analysis and context that turns that flood into a decision. That is precisely where agentic, AI-driven research changes the game.

Dream's autonomous research and reverse-engineering capabilities are built for exactly this, turning oceans of raw data into contextualized intelligence and empowering defenders to operate at the same speed and scale that AI now hands to attackers. It is like putting a tireless autonomous researcher on every team, one that reads everything, works around the clock, and connects dots across sources no human could hold in view at once, standing up the same back office that once demanded an institution. Defenders who adopt it quickly will be far better positioned than those who wait.

References

  1. "Inside the NSA's Ultra-Secret Hacking Group." Atlantic Council, 2013 (citing reporting originally published in Foreign Policy). https://www.atlanticcouncil.org/blogs/natosource/inside-the-nsas-ultrasecret-hacking-group/
  2. "Mandiant: Financial Cybercriminals Looking More Like Nation-States." Dark Reading, 2017. https://www.darkreading.com/cyber-risk/mandiant-financial-cybercriminals-looking-more-like-nation-states
  3. "2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface." CrowdStrike, Feb. 24, 2026. https://ir.crowdstrike.com/news-releases/news-release-details/2026-crowdstrike-global-threat-report-ai-accelerates-adversaries
  4. "Cloudflare 2026 Threat Intelligence Report: Nation-State Actors and Cybercriminals Shift from 'Breaking In' to 'Logging In.'" Cloudflare, 2026. https://www.cloudflare.com/press/press-releases/2026/cloudflare-2026-threat-intelligence-report-nation-state-actors-and/
  5. Prunckun, H. "AI and the Reconfiguration of the Counterintelligence Battlefield." International Journal of Intelligence and CounterIntelligence, 2026. https://www.tandfonline.com/doi/full/10.1080/08850607.2026.2620479
  6. National Research Council. Intelligence Analysis for Tomorrow: Advances from the Behavioral and Social Sciences. National Academies Press, 2011. https://www.nationalacademies.org/read/13040/chapter/3
  7. "The Truth About Contractors." Office of the Director of National Intelligence, 2010. https://www.fbiic.gov/public/2010/jul/truth_about_contractors.pdf
  8. Hulnick, A. S. "What's Wrong with the Intelligence Cycle." Intelligence and National Security, 21(6), 2006. https://www.tandfonline.com/doi/full/10.1080/02684520601046291
  9. "Large Language Models for Intelligence Analysis." Laboratory for Analytic Sciences, NC State University, 2024. https://ncsu-las.org/2024/11/large-language-models-for-intelligence-analysis/
  10. "Large Language Models and Intelligence Analysis." Centre for Emerging Technology and Security, Alan Turing Institute, 2023. https://cetas.turing.ac.uk/publications/large-language-models-and-intelligence-analysis
  11. "Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign." Anthropic, Nov. 2025. https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf
  12. "Ransomware ecosystem grows, but 'four-headed monster' dominates" (on GuidePoint GRIT Q2 2026 findings, incl. FulcrumSec). Cybersecurity Dive, 2026. https://www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/
  13. "Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds." GuidePoint Security / Business Wire, July 2026. https://www.businesswire.com/news/home/20260709079338/en/Ransomware-Victims-Rise-43-as-AI-Becomes-a-Productivity-Tool-for-Threat-Actors-GuidePoint-Security-Finds