Artificial Intelligence and the Future of State-Sponsored Cyber Operations: Lessons from China for Global Cyber Governance

Rosette Hobeich 02 Oct 2026
InsightImage

Artificial Intelligence and the Future of State-Sponsored Cyber Operations: Lessons from China for Global Cyber Governance

Rosette Hobeich 02 Oct 2026

Artificial intelligence (AI) is rapidly transforming the cyber domain, reshaping how state and non-state actors conduct espionage, information collection, and other cyber operations. By accelerating decision-making, automating technical processes, and enhancing the scale and sophistication of cyber campaigns, AI is challenging long-known assumptions about cyber deterrence, attribution, and international governance. While much of the current debate has focused on AI’s implications for conventional warfare, its impact on state-sponsored cyber operations remains comparatively underexamined despite potentially significant consequences for international security.

China provides a particularly valuable case study through which to examine these developments. Over the past two decades, it has developed one of the world’s most sophisticated state-sponsored cyber ecosystems, supported by a comprehensive national AI strategy, military-civil fusion policies, and an established emphasis on cyber-enabled intelligence collection. These characteristics do not imply that China is unique in integrating AI into cyber capabilities, nor do they suggest that it is the sole source of emerging cyber threats. Rather, they make China one of the clearest contemporary examples of how AI can be systematically incorporated into national cyber capabilities.

Using China as a case study, this insight examines how AI is reshaping state-sponsored cyber capabilities and considers the broader implications for international cyber governance and strategic stability. It argues that AI is transforming the speed, scale, and sophistication of cyber operations while exposing important shortcomings in existing governance frameworks. By analyzing China’s cyber doctrine, AI strategy, and evolving operational ecosystem, the insight identifies emerging policy challenges and proposes recommendations aimed at strengthening international cooperation, cyber resilience, and AI governance in an increasingly contested digital environment.

China: state, vision, and governance frameworks

Before the widespread public adoption of Generative AI, China rapidly developed AI for military applications through its private sector in conjunction with its civil-military fusion agenda. In 2017, China first released its Next Generation Artificial Intelligence Development Plan, spearheading governance of AI integration in civil-military, research, and industry sectors. The plan outlined China’s aims in becoming a leading “AI innovation center” in the applications of AI by 2030.[1] Indeed, by 2017, China was making major strides in AI research, ranking second in the number of published articles and patented outputs before surpassing the United States in the number of international scholarly articles on AI.[2] In 2021, the U.S. Department of Defense’s (DoD)  annual “China Military Power Report” emphasized, amongst its growing military capabilities, its approach to becoming a leader in “intelligentized” warfare.[3] By then, China’s agenda was heavily investing in emerging technologies that would optimize operational speed in warfare.[4] Most importantly, the report emphasized China’s aims to enhance its civil-military fusion, investing in technological advances in its private sector designed for dual-use integration with and modernization of its military industrial-complex. A contending factor of China’s strategy in the DoD’s report was its integration of AI into Autonomous Weapons Systems, building on its original 2030 Next Generation Artificial Intelligence Development Plan. This included R&D of autonomous air, ground, and naval systems, but also in machine learning for tactical and strategic decision-support and AI-enabled wargaming.[5] As a result, the civil-military fusion program bridged traditional barriers between private sector innovation and military application, providing a foundation for the evolution of AI and its integration into cyber capabilities.

Advancements in AI have continuously been adopted by China as part of its warfare and security strategy, where cyberspace has emerged as a key domain used for intelligence collection and foreign policy objectives. In 2024, the DoD’s updated report identified China’s AI-enabled cyber warfare as a part of its broader “smart war” strategy, with the aim of neutralizing its adversaries prior to physical confrontation.[6] The integration of AI into “Intelligentized Warfare” has also allowed for optimized analysis of ISR (Intelligence, Surveillance, and Reconnaissance) and enabled rapid decision-making through command systems modernization and predictive analysis. ISR also includes data collection from social media and open-source intelligence, which the 2021 DoD China Military Power report emphasized as part of Beijing’s strategy for information warfare.[7] Internally, there is growing evidence that China’s Ministry of State Security (MSS) integrates AI-driven surveillance systems through the civil-military fusion framework to identify foreign interference, although it is only officially confirmed to be in use by the Ministry of Public Security.[8] Therefore, the integration of AI into China’s state-sponsored cyber capabilities has fundamentally altered the speed and sophistication with which China can conduct intelligence gathering.

China has continued to build on its initial development plan by releasing the first Global AI Governance Initiative in late 2023, followed by a more comprehensive 13-point Action Plan for Global Artificial Intelligence Governance in 2025.[9] Its cyber governance frameworks collectively reflect an agenda that prioritizes information control, data control, and standard-setting.[10] China seeks to take on an international norm-setting role, one that would replace its lack of rule-setting in previous rounds of U.S. and Western-dominated cyber governance.[11] By relying on its status as a developing nation, it hopes to rally the Global South and traditional Chinese economic allies to adopt its state-centric AI governance vision.

While other technologically advanced states are pursuing similar developments, China’s advanced AI governance models position it as an ideal lens to study the potential impacts of the integration of AI into state-sponsored cyber operations. In addition to the transformative need for defensive cybersecurity measures, China’s aim to lead the development and deployment of AI governance globally calls for existing international norms and governance frameworks to adapt to a rapidly evolving AI-enabled threat environment. As of 2026, there is a gap in international treaties that appropriately address the use of Autonomous Weapons Systems or AI-enabled cyber warfare. China’s long-standing, comprehensive national AI strategy and Military-Civil Fusion framework differentiate it as a clearly observable case of how AI can be integrated into state-sponsored cyber capabilities. Therefore, China is significant as a case study of how AI is reshaping international security norms and exposing major vulnerabilities, rather than as a uniquely positioned cyber threat.

While Western cyber norms predominantly encourage collaboration between technological sectors through shared resources, standards, and discourse, China continues to advocate for the concept of cyber sovereignty. Its cyber system has remained tightly state-authority-controlled since the concept of cyber sovereignty appeared in the White Paper on the Internet in China, published in 2010.[12] This approach has allowed it to continuously challenge Western cyber governance leadership, and more recently expand into the AI space. Coupled with its established aim to lead the future of AI governance, China could be seen to be actively reshaping global norms pertaining to both AI and its integration into cyberspace.

China’s operational goals have historically centered on intelligence collection and espionage rather than destructive or financially incentivized cyber-attacks. The term cyberespionage appeared in the U.S. DoD in the 1980s in response to the fear of external governments targeting digital systems to obtain sensitive information.[13] Rather than aiming to dismantle infrastructure, data attacks attributed to Chinese state-affiliated cyber hackers largely align with China’s narrative-setting agenda. China has repeatedly upheld its right to cyber sovereignty in conjunction with its aims to reduce online foreign influence by regulating discourse away from anti-state narratives.[14] According to current U.S. reports, China continues to focus its cyberespionage attacks on the U.S. to gain dominance in the information sphere.[15] For instance, the “Salt Typhoon” campaign, discovered in the Fall of 2024, infiltrated several U.S. telecommunications providers.[16] Through information collection, the Chinese Communist Party (CCP) is also able to support broader research and development operations, identify new fields of competition, and even provide an upper hand in the development of military capabilities.

Security firms like FireEye and ProtectWise have spent years tracking down Chinese threat actors and differentiating between lone-wolf attacks versus directly Chinese-backed operations. However, it is evident that non-state cyber threat actors, whether governmental or not, enjoy a level of protection from Chinese authorities, even when targeting Chinese civilians.[17] In 2017, an anonymous hacking group called Intrusion Truth claimed that three members of APT17, an Advanced Persistent Threat group, were directly collaborating with and carrying out on-demand attacks for the Chinese MSS.[18] Other actors, such as APT41, have spied on global technology, telecommunications, and healthcare providers for the Chinese government.[19] They are known to operate more as contractors, oftentimes in underground marketplaces, rather than as direct state employees.[20] Therefore, Chinese cyber operations have not always been executed directly through state operatives, but rather oftentimes through non-state actors with for-profit incentives operating within the Chinese cyber sphere.

With the normalization of cyber-conflict as a space in which adversarial confrontation is largely unattributable and can cause massive amounts of damage, AI has taken a new role in scaling the efficiency and capacity of state-sponsored cyber-attacks. In China’s case, its tech industry has continuously researched, developed, and catered AI capabilities over the last decade for dual-use by the People’s Liberation Army (PLA).[21] This has included both increasingly automated and unmanned-systems, as well as AI features supporting “information operations”.[22] By assessing how AI is currently able to enhance cyber-attacks and defenses, China serves as an important case study on the potential for its integration and the need for global governance frameworks to approach the scale and frequency of cyber-attacks.

Cyber risks and forecast: how is the application of AI affecting cyber conflict?

AI is increasingly being used to attack with “greater volume and more precision than ever before”, as highlighted in Microsoft’s 2025 Digital Defense Report. Microsoft’s analysis points to nation states, criminal syndicates, and commercial cyber mercenaries increasingly contributing to networks of cybercrime activity. AI can support malicious actors by automating phishing attacks with social engineering, supporting the real-time evasion of security controls, and identifying pathways of lateral movement through compromised networks.[23] At the same time, AI systems themselves can become targets through prompt injection, leading to data leaks or the spread of misinformation.[24] Combatting the large-scale enablement of cybercrime in real-time requires the increased integration of cyber defenses and resilience through governance frameworks.[25] Therefore, AI can be utilized preemptively as a defensive application against attacks by pinpointing vulnerabilities prior to their discovery by malicious actors.[26] As AI enhances both the frequency and scale of cyber-attacks, cyber defenses require AI-integrated solutions to effectively adapt to emerging cyber risks.

Although the majority of cyber-attacks are conducted by cyber criminals rather than nation-state actors, states have played a critical role in sponsoring attacks in the past, and are continuing to grow their targeting both in volume and reach.[27] Many target weak IT teams and IT companies to obtain sensitive data such as personally identifiable information (PII) and authentication tokens, which can be used for future attacks.[28] Espionage campaigns attributed to China, for instance, are often aimed at stealing sensitive personal information. APT17 is believed to operate both independently and as a contractor to the Chinese MSS.[29] It was believed to be involved in “Operation Aurora” in 2010, which attacked Google alongside 33 other companies in the technology, financial, and defense industries.[30] Google later revealed that the breach had targeted several email accounts of Chinese human rights activists.[31]

The Washington Post, several years later, revealed that sensitive information of U.S. surveillance targets had been stolen in the interest of identifying compromised Chinese intelligence operatives.[32] According to Microsoft’s 2025 Report, weak IT teams in government-affiliated NGOs are also increasingly becoming a target as cyber actors often gain entry undetected.[33] APT17, for instance, is attributed to attacks on U.S. and Southeast Asian government entities, defense industries, law firms, information technology companies, mining companies, and non-governmental organizations.[34] Chinese-affiliated non-state actors, categorized by their behavioral and tactical approaches, have gained notoriety in cyberspace over time for their attacks, resulting in the data collection of sensitive information.

There are different kinds of AI-enhanced cyber risks affecting organizations, placing them increasingly at risk for sensitive data theft. A number of threats, vulnerabilities, exploits, and attacks, such as ransomware, phishing attacks, DDoS attacks, or mobile threats, are commonly targeting users, companies, and government institutions.[35] Most importantly, Chinese state-affiliated actors are believed to have utilized AI “to inform network reconnaissance, support social engineering, and refine operational commands”.[36] In intelligence gathering, the reconnaissance stage supports information-gathering pursuits by identifying potential system vulnerabilities prior to a cyber-attack. AI can especially enhance reconnaissance efforts by leveraging algorithms to gather information on both individuals and organizations from social media and other platforms.[37] Most importantly, the integration of AI into cyber capabilities significantly lowers entry barriers, allowing for the identification of vulnerabilities and a higher capacity for state-sponsored cyber-attacks.

The attribution of China’s cyberespionage campaigns is often identified through recurring techniques. Spear-phishing is a technique where socially engineered emails are used to extract vital information by tricking a target into either inputting their information or clicking a malicious link through what resembles trusted entities.[38] For instance, targeting national security-linked individuals through phishing scams may allow China to obtain strategic geopolitical and economic advantages by obtaining PII and accessing otherwise encrypted information. AI may enable state-sponsored actors to instantly generate highly convincing phishing scam emails, enhancing language through automated personalized writing styles and designs that closely mimic official entities and personal contacts.[39] AI has also infiltrated personalized content on the visual and auditory scale through social engineering. AI-generated content can be utilized to closely impersonate individuals, using social engineering to obtain sensitive information such as PII or access to funds from vulnerable entities.[40] Through GenerativeAI, the barriers to phishing scams are significantly lower, as generated messages can feel personalized and reliable, making this especially useful for cyber espionage efforts.

Alternatively, AI-enhanced ransomware and malware attacks are gaining the capability to infiltrate networks undetected, while identifying relevant data to target at quick speeds. For instance, AI malware can evade detection from traditional anti-virus software by using polymorphic code, making it harder to detect through signature-based systems.[41] With ransomware attacks, AI can detect and encrypt valuable data without human input, optimizing the impact on the entity being attacked in demand for financial ransom.[42] Two major state-sponsored cyber espionage groups, Volt Typhoon and Salt Typhoon, are assumed to actively utilize AI in their espionage campaigns while infiltrating critical infrastructure.[43] As their operations focus on stealth and intelligence collection, they often use custom malware to evade detection and access sensitive data by exploiting back-door vulnerabilities.[44] Salt Typhoon often targets major telecom providers, and steals administrator logins to move laterally through networks, while Volt Typhoon is known to target critical infrastructure to move laterally through networks undetected.[45] AI has the potential to enhance the adaptability and effectiveness of malware while strengthening the operational efficiency that characterizes campaigns such as Salt Typhoon and Volt Typhoon in China’s intelligence collection.

Adversarial attacks on internal AI systems in use for generating automated responses in Autonomous Weapons Systems can affect the way machine-learning algorithms derive responses by modifying input data.[46] By corrupting data sets with malicious data, for instance, an AI model can output incorrect results or lead to costly decisions.[47] Prompt injection attacks can compromise AI-enabled cyber operations by manipulating AI systems into producing unintended outputs, bypassing safeguards, or influencing automated decision-making processes.

Advancements in AI have already started to reshape both the offensive and defensive cybersecurity landscape. The protection from these attacks is most placed under the umbrella of cybersecurity. While holding many definitions, cybersecurity can be defined as “the practice of protecting computers, servers, mobile devices, electronic systems, computer networks, and data from malicious attacks.”[48] This is a broader term differentiated from data and information security, which aim to protect against unauthorized data/information use and maintain its integrity and confidentiality.[49] While cyber threats have been a central pillar of state security initiatives since the early 2000s, the advancement of AI has accelerated the need for more standardized attribution mechanisms, established cyber norms, and integration of AI into defense strategies.

AI has altered the effectiveness of offensive cyber operations due to the adaptability of self-governing malicious software. More recent AI-enhanced attacks have shown the capability of bypassing conventional defenses through adaptive techniques, posing a large threat to system vulnerabilities.[50] On the other hand, over-relying on automated defenses can also expose systemic vulnerabilities that the program may be unaware of.[51] This dynamic underscores that AI is not inherently advantageous to either attackers or defenders; rather, it accelerates the pace of competition between them, making the effectiveness of cyber operations increasingly dependent on which actor is able to integrate and adapt AI capabilities more effectively.

While AI automates, expedites, and optimizes malicious cyber-attacks, it can also detect and adapt to external threats. From a cybersecurity standpoint, AI is continuously being integrated into systems to expose and patch vulnerabilities or create adaptive defense systems. Through Intrusion Detection Systems (IDS), advanced machine learning algorithms can detect malicious activities within a network.[52] Additionally, proactive machine learning models can analyze vast datasets to continuously detect and propose responses to anomalies and potential threats.[53] By integrating AI into standard cyber defenses, automated responses can learn to block malicious traffic and initiate recovery protocols.

Implications for nation-states and international cyber governance

The current global implications for the rapid adoption and integration of AI on individual, governmental, and industry levels call for rapid adaptation measures to the emerging threat landscape. According to the World Economic Forum’s 2025 Global Cybersecurity Outlook, small organizations with inadequate cyber infrastructure are the most vulnerable outlets through which hackers can infiltrate sensitive data, including PII and government identification. In the report, around 35% of small organization respondents believed their cyber resilience was inadequate, and the public sector remains the most disproportionately affected when it comes to cyber-attacks.[54]

What’s more shocking is that at the Annual Meeting on Cybersecurity in 2024, 71% of cyber leaders responded that small organizations have already reached a critical tipping point where they can no longer adequately secure themselves.[55] Therefore, smaller organizations with limited cybersecurity resources may present attractive entry points into broader digital ecosystems, particularly where they are integrated into the supply chains or operational networks of larger public and private organizations.

The continued lack of regulation surrounding AI use in cyber threats poses a rising concern for countries whose data continues to be compromised through cyber-attacks. Recent analyses of the use of AI in cyber and information warfare show developments in the militarization of AI, the weaponization of information, and the destabilizing consequences of AI-driven cyber operations on regional and global security.[56] China has tested its AI-powered cyber capabilities regionally in the Indo-Pacific and South Asia. The U.S. DoD has previously addressed China’s strategic regional interests with the U.S.-allied first island chain nations, such as Taiwan, where China has used AI-targeted information ecosystems to weaken democratic resilience.[57]

Generating misinformation has been central to hybrid warfare in several contemporary conflicts, including Russia-Ukraine. The intelligence alliance known as the “Five Eyes” (United States, UK, Canada, Australia and New Zealand) has released a statement as of June 2026 claiming that “Frontier AI models are anticipated to exceed ​current industry expectations, fundamentally transforming both offensive and ⁠defensive cyber capabilities”.[58] They estimate this phenomenon to take effect in the coming months as opposed to years, highlighting the exponential speed at which AI is enhancing state and non-state sponsored cyber operations.

AI is expected to further destabilize ongoing prolonged cyber conflicts, such as that between China and the United States. The bulk of research on U.S. and China AI-enhanced cyber rivalry has only gained momentum between the years of 2023 and 2026, during which 70% of relevant studies have been published.[59] This also indicates that the two nations have continuously applied AI through different approaches since the public release of AI models. While the U.S. has continued to lead AI innovation with its private sector in collaboration with its defense industry, the PRC’s government-led approach under its civil-military fusion has been central to its strategy of information control.[60] This has enabled China to efficiently deploy dual-use AI, where commercial advancements in quantum computing and machine learning are rapidly integrated into military applications.[61] Therefore, China’s cyberwarfare strategy has rapidly evolved in recent years, causing concern for ethical implications and increasing geopolitical rivalry in an AI-driven cyberspace.

Other countries like the United Arab Emirates have positioned AI as a pillar of national development, aiming to build an AI economy and position itself as a leader in AI by 2031. By balancing technological cooperation with both Washington and Beijing, the UAE balances mutual economic and strategic interests with its geopolitical considerations.[62] Its G42 AI company focuses on research related to machine learning, big data, and natural language processing across a range of industries, drawing American privacy and national security risk concerns by contracting with Chinese technology firms such as Huawei.[63] On the other hand, the recent rise in sophisticated cyber-attacks against a number of entities in the Emirati financial sector shows the increasing adaptability of AI-enabled cyber-attacks, warranting its multilayer approach to technological development and cooperation.[64] The UAE offers a complementary perspective to China’s, illustrating how states pursuing ambitious AI development must increasingly balance technological cooperation with the geopolitical realities of strategic competition.

Closing the AI governance gap

The evidence suggests that AI is fundamentally changing the speed and scale of cyber operations while lowering entry barriers, yet governance mechanisms remain largely designed for an earlier technological era. Addressing the gap requires strengthening multilateral AI cyber governance while also accounting for the private sector underpinning AI innovation and applications. Additionally, the question of state-centered ethics remains in terms of the application of AI in adversarial attacks.

The UN Convention Against Cybercrime, the largest multilateral framework that acknowledges rules and norms in cyberspace, currently fails to address AI-enabled cyber operations. Rather than developing entirely new frameworks, existing mechanisms such as the new 2026 UN Global Mechanism on developments in the field of Information and Communication Technologies should be utilized to promote regular dialogue between states on the use of AI in cyber operations. More importantly, global discourse should encourage convergence between diverging national AI governance strategies, such as China and the United States, rather than allowing competing regulatory models to emerge.

Ultimately, governments no longer hold a monopoly over innovation in the development of AI and its integration into cyber operations. In the U.S. model, private companies such as Microsoft, Google, and CrowdStrike work with governmental entities to enable cyber defense strategies, while China continues to deploy its civil-military fusion framework by sponsoring R&D for governmental use. Realistically, smaller organizations such as SMEs and NGOs face the most vulnerability in terms of their capacity for cyber resilience. National government strategies focused on public-private frameworks should also integrate cross-sector cooperation on best strategies that can strengthen resilience across interconnected digital ecosystems.

Ethical considerations are largely tied to individual state strategies and governance frameworks. Long-term agendas should aim to establish international consensus regarding the responsible development, deployment, and oversight of AI applications. However, with opposing governance strategies and other limitations in the attribution of cyber-attacks, enforcement remains an inhibitor in promoting norms that can be established and adhered to as internationally recognized principles governing AI.

Only once these issues are addressed can future AI cyber governance move beyond exclusively state-centric approaches. Governmental authorities should focus on integrating structured cooperation between private AI developers, cybersecurity firms, critical infrastructure operators, and smaller organizations that are currently most vulnerable to the rapidly changing nature of cyber operations.


[1] State Council of the People’s Republic of China, “Next Generation Artificial Intelligence Development Plan,” China Science and Technology News Letter, Department of International Cooperation Ministry of Science and Technology, September 15, 2017, https://fi.china-embassy.gov.cn/eng/kxjs/201710/P020210628714286134479.pdf.

[2] Elsa B. Kania, “Artificial Intelligence and Chinese Power,” Foreign Affairs, December 5, 2017, https://www.foreignaffairs.com/articles/china/2017-12-05/artificial-intelligence-and-chinese-power; State Council of the People’s Republic of China, “Next Generation Artificial Intelligence Development Plan.”

[3] “DoD’s 2021 China Military Power Report: How Advances in AI and Emerging Technologies Will Shape China’s Military,” Council on Foreign Relations,” November 4, 2021, https://www.cfr.org/articles/dods-2021-china-military-power-report-how-advances-ai-and-emerging-technologies-will-shape?utm_source=chatgpt.com.

[4] Ibid.

[5] Ibid.

[6] Dimitar Dimitrov and Evgeni Andreev, “CHINA’S STRATEGIC COMPETITION IN CYBERSPACE. VOLT TYPHOON AND SALT TYPHOON AS A PROJECTION OF POWER, A MORE AGGRESSIVE POSTURE AND A FUTURE BEYOND ESPIONAGE,” ENVIRONMENT. TECHNOLOGY. RESOURCES. Proceedings of the International Scientific and Practical Conference 2 (June 2025): 115–22, https://doi.org/10.17770/etr2025vol2.8618.

[7] “DoD’s 2021 China Military Power Report.”

[8] Henry Prunckun, “AI and the Reconfiguration of the Counterintelligence Battlefield,” International Journal of Intelligence and CounterIntelligence 39, no. 3 (2026): 738–55, https://doi.org/10.1080/08850607.2026.2620479.

[9] Ho Ting Hung, “Exploring China’s Cyber Sovereignty Concept and Artificial Intelligence Governance Model: A Machine Learning Approach,” Journal of Computational Social Science 8, no. 1 (2025): 24, https://doi.org/10.1007/s42001-024-00346-8; Arindrajit Basu, China’s Pivot on Global AI, May 21, 2026, https://carnegieendowment.org/research/2026/05/chinas-pivot-on-global-ai.

[10] Hung, “Exploring China’s Cyber Sovereignty Concept and Artificial Intelligence Governance Model.”

[11] Ibid.

[12] Ibid.

[13] Ömer Aslan, Semih Serkant Aktuğ, Merve Ozkan-Okay, Abdullah Asim Yilmaz, and Erdal Akin, “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions,” Electronics 12, no. 6 (2023): 1333, https://doi.org/10.3390/electronics12061333.

[14] Hung, “Exploring China’s Cyber Sovereignty Concept and Artificial Intelligence Governance Model.”

[15] Annual Report to Congress: Military and Security Developments Involving the People’s Republic of China (U.S. Department of Defense, 2025), https://media.defense.gov/2025/Dec/23/2003849070/-1/-1/1/ANNUAL-REPORT-TO-CONGRESS-MILITARY-AND-SECURITY-DEVELOPMENTS-INVOLVING-THE-PEOPLES-REPUBLIC-OF-CHINA-2025.PDF.

[16] Ibid.

[17] Elizabeth Merrigan, “Blurred Lines Between State and Non-State Actors,” Council on Foreign Relations, December 5, 2019, https://www.cfr.org/articles/blurred-lines-between-state-and-non-state-actors.

[18] Ibid.

[19] Ibid.

[20] Ibid.

[21] Annual Report to Congress: Military and Security Developments Involving the People’s Republic of China.

[22] Ibid.

[23] Microsoft Digital Defense Report 2025: Governments and Policymakers Executive Summary (Microsoft, 2025), https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/MDDR-2025-Government-Executive-Summary.pdf.

[24] Ibid.

[25] Ibid.

[26] Ibid.

[27] Ibid.

[28] Ibid.

[29] Merrigan, “Blurred Lines Between State and Non-State Actors.”

[30] Ibid.

[31] Ibid.

[32] Ibid.

[33]  Microsoft Digital Defense Report 2025: Governments and Policymakers Executive Summary.

[34] Merrigan, “Blurred Lines Between State and Non-State Actors.”

[35] Aslan et al., “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions.”

[36] Annual Report to Congress: Military and Security Developments Involving the People’s Republic of China.

[37] Guy Waizel, “Bridging the AI Divide: The Evolving Arms Race between AI- Driven Cyber Attacks and AI-Powered Cybersecurity Defenses,” International Conference on Machine Intelligence & Security for Smart Cities (TRUST) Proceedings 1 (July 2024): 141–56.

[38] Ben Buchanan, “Part One: Espionage, Strategic Espionage,” in The Hacker and the State : Cyber Attacks and the New Normal of Geopolitics. (Harvard University Press, 2020).

[39] Waizel, “Bridging the AI Divide.”

[40] Ibid.

[41] Ibid.

[42] Ibid.

[43] Laszlo Pokorny, AI-Enhanced Cyber and Information Warfare: A Comparative Analysis of U.S. and PRC Capabilities, Doctrines, and Strategic Implications, March 15, 2026, https://doi.org/10.5281/ZENODO.19039283.

[44] “Salt Typhoon,” MITRE | FiGHTTM,” https://fight.mitre.org/groups/G1045/. Accessed July 10, 2026.; “Volt Typhoon,” BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, Group G1017 | MITRE ATT&CK®,” https://attack.mitre.org/groups/G1017/. Accessed July 10, 2026.

[45] “Salt Typhoon,” MITRE | FiGHTTM.” ; “Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, Group G1017 | MITRE ATT&CK®.”

[46] Waizel, “Bridging the AI Divide.”

[47] Ibid.

[48] Aslan et al., “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions.”

[49] Ibid.

[50] Pokorny, AI-Enhanced Cyber and Information Warfare.

[51] Ibid.

[52] Aslan et al., “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions.”

[53] Ibid.

[54] Global Cybersecurity Outlook 2025, Insight Report (World Economic Forum, 2025), https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf.

[55] Ibid.

[56] Pokorny, AI-Enhanced Cyber and Information Warfare.

[57] Ibid.

[58] Raphael Satter and Raphael Satter, “‘Five Eyes’ Intelligence Alliance Warns That New AI Models Pose Urgent Cyber Risk,” Asia Pacific, Reuters, June 22, 2026, https://www.reuters.com/world/asia-pacific/five-eyes-intelligence-alliance-warns-that-new-ai-models-pose-urgent-cyber-risk-2026-06-22/.

[59] Pokorny, AI-Enhanced Cyber and Information Warfare.

[60] Ibid.

[61] Ibid.

[62] Andrew G. Clemmensen, Rebecca Redlich, Grant Rumley, “G42 and the China-UAE-U.S. Triangle,” The Washington Institute for Near East Policy,” https://www.washingtoninstitute.org/policy-analysis/g42-and-china-uae-us-triangle. Accessed July 10, 2026.

[63] Ibid.

[64] Yasmin Hussein, “UAE Authority Foils Sophisticated Cyberattacks on Entities in Financial Sector,” Khaleej Times, July 3, 2026, https://www.khaleejtimes.com/uae/foils-cyberattacks-entities-financial-sector; Somshankar Bandyopadhyay, “UAE’s Rapid Digital Growth Draws Rising Cyber Threats as Firms Pivot to Recovery-First Strategies,” Khaleej Times, June 22, 2026, https://www.khaleejtimes.com/business/tech/uaes-rapid-digital-growth-draws-rising-cyber-threats-as-firms-pivot-to-recovery-first-strategies.