Skip to content
← Back to GISI

The Chokepoint Doctrine

The infrastructure beneath the headlines — and what breaks first when it fails.

Modern security analysis usually starts at the perimeter and works inward. The Chokepoint Doctrine starts at the dependency map and works upward — naming the cable on the ocean floor, the helium plant in the desert, the satellite in low orbit, the political alignment between two monarchies, and the regulatory architecture beneath digital governance as the load-bearing surfaces that decide whether the modern economy keeps functioning. Each piece in the series names one chokepoint, traces what fails when it does, and identifies the inflection events that signal which scenario is arriving in time to act on the information.

62 pieces · ordered by publication date
The Chokepoint Doctrine: Why Risk Intelligence Is the Only Lens That Sees the Whole Picture
Part 1 · Risk IntelligenceMarch 11, 2026
The Chokepoint Doctrine: Why Risk Intelligence Is the Only Lens That Sees the Whole Picture

Series Manifesto. On a Tuesday morning in Malmö, Sweden's digital identity system went dark. That same week, an Iranian ballistic missile test demonstrated range to reach Berlin. A cable ship declared force majeure. None of these are the same story. All of them are the same story.

Free tier 8 min read
The Floor of the Ocean Is the New Front Line: How the Iran War Put the Internet Itself at Risk
Part 2 · Critical InfrastructureMarch 19, 2026
The Floor of the Ocean Is the New Front Line: How the Iran War Put the Internet Itself at Risk

Seventeen submarine cables carry 30% of global internet traffic through the Persian Gulf. When Iran closed the Strait of Hormuz, it didn't just threaten oil — it threatened the physical infrastructure of the internet itself. The floor of the ocean is now a battlefield.

Free tier 11 min read
Who Fixes the Internet When the Repairmen Can't Get There?
Part 3 · Critical InfrastructureMarch 20, 2026
Who Fixes the Internet When the Repairmen Can't Get There?

The cable fleet is aging, the warzones are expanding, and the $2.2 trillion AI bet is sitting on top of a repair problem nobody budgeted to solve. Sixty ships service 1.48 million kilometres of submarine cable. Four companies control the entire fleet.

Free tier 10 min read
The 11-Day Clock: How a Gulf War Put the Future of Artificial Intelligence on Borrowed Time
Part 4 · Semiconductor Supply ChainMarch 21, 2026
The 11-Day Clock: How a Gulf War Put the Future of Artificial Intelligence on Borrowed Time

The Chokepoint Doctrine — Part 3. The strait is 21 miles wide. The chip is 3 nanometres small. The helium that connects them just stopped flowing. And the island that makes every AI chip on earth has eleven days of supply left.

Free tier 10 min read
The Weakest Link Was Never on the Map: How GRC Architecture Failed the Infrastructure It Was Built to Protect — and What Comes Next
Part 5 · Critical Infrastructure GovernanceMarch 23, 2026
The Weakest Link Was Never on the Map: How GRC Architecture Failed the Infrastructure It Was Built to Protect — and What Comes Next

The Chokepoint Doctrine. Subsea cable infrastructure does not fit cleanly into any existing critical infrastructure mechanism. It falls between sectors, belongs to no single agency, and has no Tier-1 classification — yet it carries 95% of intercontinental data. The Iran war arrived into that governance gap at the worst possible moment.

Free tier 9 min read
Before the Warzone: Why the Only Answer to the Internet's Most Dangerous Vulnerability Has to Come First
Part 6 · Internet GovernanceMarch 24, 2026
Before the Warzone: Why the Only Answer to the Internet's Most Dangerous Vulnerability Has to Come First

The concluding piece in a series that began with a cable ship declaring force majeure and ended with a question nobody in power has answered. The answer has to exist before the warzone, not inside it.

Free tier 11 min read
The $2M Problem: Why Every Interceptor Fired Over the Gulf Is a Missile That Won't Be There for Taiwan
Part 7 · Critical InfrastructureMarch 25, 2026
The $2M Problem: Why Every Interceptor Fired Over the Gulf Is a Missile That Won't Be There for Taiwan

A $20K Shahed drone versus a $4.2M Patriot interceptor. A 200:1 cost ratio in the attacker's favour. US interceptor stocks at 25% of required levels, with no new THAAD deliveries until 2027. The defence economics of the Iran war are rewriting the strategic calculus from the Gulf to the Taiwan Strait.

Free tier 6 min read
Eight Seconds to Darkness: The Blackout Report That Accidentally Became an Attack Manual
Part 8 · Critical InfrastructureMarch 26, 2026
Eight Seconds to Darkness: The Blackout Report That Accidentally Became an Attack Manual

ENTSO-E published 472 pages of peer-reviewed engineering detail on the April 2025 Iberian blackout — the largest power failure in European history. The security community should be treating it like a threat actor whitepaper, because that is functionally what it is. The cascade physics, protection relay thresholds, and voltage control gaps are now public. The threat actors are already studying them.

Free tier 8 min read
The Data Centre Was Never a Bunker — How the Kinetic Envelope Changed Everything Europe Built Its Digital Future On
Part 9 · Critical InfrastructureMarch 27, 2026
The Data Centre Was Never a Bunker — How the Kinetic Envelope Changed Everything Europe Built Its Digital Future On

Iranian drones struck three AWS data centres in the UAE and Bahrain on March 1, 2026 — the first known physical attacks on data centres in history. The demonstrated 3,800km strike on Diego Garcia has placed every European data centre within a threat envelope that no risk model had previously contemplated. Europe built the sovereign cloud without building the sovereign defence around it.

Free tier 10 min read
The Narrow Gate: Three Thousand Years of Empires Dying at Chokepoints
Part 10 · Chokepoint DoctrineMarch 28, 2026
The Narrow Gate: Three Thousand Years of Empires Dying at Chokepoints

In the Book of Daniel, Nebuchadnezzar dreams of a colossus — head of gold, feet of iron mixed with clay. A stone strikes the feet and the whole structure collapses. From Aksum to Carthage to Venice to Britain at Suez, every empire has died at the same place: the narrow passage where geography renders firepower irrelevant.

Free tier 15 min read
The Death of the Threat Model: Why Every Risk Framework Built Before 2026 Is Now a Historical Document
Part 11 · The Chokepoint DoctrineMarch 29, 2026
The Death of the Threat Model: Why Every Risk Framework Built Before 2026 Is Now a Historical Document

Somewhere in your organisation’s governance architecture there is a document that describes your threat model. It names your adversaries. It categorises your assets. It assigns probability and impact scores. It is now a historical document — because every foundational assumption it was built on has been invalidated simultaneously.

Free tier 12 min read
The Language of the Unsayable: What Iran’s Maximalist Demands, the Cable Toll, and a Ballistic Missile Submarine at Gibraltar Are Actually Communicating
Part 12 · Strategic AnalysisMay 12, 2026
The Language of the Unsayable: What Iran’s Maximalist Demands, the Cable Toll, and a Ballistic Missile Submarine at Gibraltar Are Actually Communicating

Three simultaneous signals. Iran’s maximalist demands. Iran’s cable toll proposal. The USS Alaska surfacing at Gibraltar. None of them are what they appear to be at the literal level. All of them are communicating something precise and important to the audience that is actually intended to receive them. This piece maps the signalling layer — the grammar of coercive diplomacy that is running simultaneously with the military campaign.

Free tier 12 min read
The Robots Running America’s Reshoring Dream Are Not American
Part 13 · Strategic AnalysisMay 14, 2026
The Robots Running America’s Reshoring Dream Are Not American

The country that invented the industrial robot no longer makes one at meaningful scale. FANUC and Yaskawa are Japanese. KUKA is Chinese-owned. ABB Robotics was just sold to SoftBank. The top four vendors control 75% of global shipments. The United States controls none. Every CHIPS Act fab, every EV gigafactory, every reshoring announcement depends on robotic arms that answer to Tokyo or Beijing. This is the chokepoint inside the factory.

Free tier 11 min read
The AI Race Nobody Is Watching
Part 14 · Strategic AnalysisMay 14, 2026
The AI Race Nobody Is Watching

While America races to build AGI, China shipped 87–90% of the world’s humanoid robots in 2025. Unitree’s $13,560 factory robot outsold Tesla’s entire Optimus production target. 140 Chinese manufacturers, 330 humanoid models, 15 automakers pivoting into robotics. The frontier model race gets the headlines. The deployment race gets the factory floor. Part 2 of the Chokepoint Doctrine series examines the AI layer of America’s industrial sovereignty gap.

Free tier 10 min read
The Strategy America Needs But Has Not Built
Part 15 · Strategic AnalysisMay 14, 2026
The Strategy America Needs But Has Not Built

China spent $400 billion on robotics in 2026. The CHIPS Act allocated $50 billion total. China built 30,000 smart factories over eleven years. Only 8.3% of US manufacturers have incorporated robots. The diagnosis is settled — four requirements remain unbuilt: institutional authority, investment parity, allied supply chain coordination, and deployment at federal scale. Part 3 of the Chokepoint Doctrine series maps what a credible American industrial robotics and AI response actually requires.

Free tier 13 min read
The Chokepoint Above Everything
Part 16 · Strategic AnalysisMay 20, 2026
The Chokepoint Above Everything

Iran used a $36.6 million Chinese-built satellite to coordinate precision strikes on US military bases in March 2026. Israel destroyed Iran's Aerospace Headquarters on March 8 to degrade the capability — but the ground stations are in Beijing, not Tehran. With 15,000–18,000 satellites in LEO by end of 2026, a single kinetic ASAT strike could trigger Kessler cascade in specific orbital bands. The Outer Space Treaty does not prohibit conventional ASAT weapons, deliberate debris generation, or the use of commercial satellites for military targeting. The chokepoint above everything is already active.

Free tier 13 min read
When the Sky Goes Dark
Part 17 · Critical InfrastructureMay 20, 2026
When the Sky Goes Dark

Every business continuity plan contains assumptions so foundational they are never written down. GPS works. Satellites are up. The timing signal is accurate. The Iran war moved all four assumptions from the constants column to the variables column. This piece is the operational framework for the GPS timing audit your organisation has almost certainly never done, the Starlink paradox where your resilience measure becomes your single point of failure, the commercial earth observation dependency nobody has classified as critical, and the satellite ground station supply chain whose cybersecurity floor your continuity plan inherits without auditing.

Free tier 12 min read
The Cable Gap
Part 18 · Critical InfrastructureMay 21, 2026
The Cable Gap

An industry post circulating this week articulated an accurate diagnosis: the subsea cable sector is being asked to deliver 2030 capacity with a 2005 procurement model. The diagnosis is correct. The prescription is incomplete. The three-to-five-year MOU-to-RFS gap is not a market efficiency problem awaiting a market solution. It is a strategic vulnerability that adversaries have already mapped, exploited in active conflict, and that a state actor is systematically addressing through state-subsidised construction priced twenty to thirty percent below Western competitors. HMN Technologies (formerly Huawei Marine Networks) went from 11% market share in 2021 to 18% of global cables laid in the next four years. The Digital Silk Road's stated ambition is 60%. The private build trend the industry post celebrates as innovation is, in documented cases, going to HMN because Western alternatives cannot deliver on timeline or price. ZTT commenced construction of a new cable-laying vessel in August 2025. The 2030 cable infrastructure landscape will be the operational expression of choices being made over the next thirty-six months.

Free tier 13 min read
The Cascade Below the Headlines: How One Closed Strait Becomes a Global Chip Shortage in Ninety Days
Part 19 · Chokepoint DoctrineMay 25, 2026
The Cascade Below the Headlines: How One Closed Strait Becomes a Global Chip Shortage in Ninety Days

Hormuz has been closed for weeks. The headlines describe the visible failure — oil. The cascade beneath the headline runs through sulfur, sulfuric acid, copper, and the electrical grids that semiconductor fabs cannot survive without. Part 1 of a five-part GISI series on the physical layer of civilisation — the balance sheet most analysts have never modelled.

Free tier 12 min read
When the Shield Becomes the Weapon: What the Trellix Source Code Breach, the Medtronic Attack, and the Pattern They Form Tell Us About the Collapse of the Security Vendor Trust Model
Part 20 · Threat AssessmentMay 25, 2026
When the Shield Becomes the Weapon: What the Trellix Source Code Breach, the Medtronic Attack, and the Pattern They Form Tell Us About the Collapse of the Security Vendor Trust Model

Trellix's source code repository was breached on May 2. Three weeks earlier, Medtronic confirmed a ShinyHunters attack on 9 million patient records. They join Microsoft, Okta, and LastPass on a list that should never exist — the security vendors whose entire commercial proposition is preventing the attacks they cannot prevent on themselves. This briefing maps the structural failure and the four predicted outcomes.

Free tier 13 min read
Two Doctrines, One Coastline
Part 21 · Chokepoint DoctrineMay 31, 2026
Two Doctrines, One Coastline

In April 2026, Riyadh sent Washington a list of named Iranian energy facilities and asked the United States to stop the United Arab Emirates from hitting them. The list was framed as oil-price diplomacy. The complete reading requires reckoning with what Riyadh has been building under its own mountains since 1987: six underground bases, Chinese ballistic missiles, and a four-decade deterrent stack that does not require American greenlight. The Gulf monarchies no longer share a single doctrine. They share a single coastline, and one of them has been running an Iranian-style asymmetric deterrence model in silence since Reagan’s second term.

Free tier 19 min read
You Didn't Hire a Replacement. You Bought a Subscription That Is Billing You Into a Corner.
Part 22 · AI Risk AdvisoryJune 1, 2026
You Didn't Hire a Replacement. You Bought a Subscription That Is Billing You Into a Corner.

The AI cost crisis, the permission problem, and the workforce destruction that is already being reversed. The AI replacement doctrine rested on three assumptions that 2026 has tested to destruction simultaneously: that costs would stay at pilot-phase pricing as deployment scaled, that AI could replicate the human contribution adequately enough to make replacement economically rational, and that AI agents could be granted full access without creating governance obligations the security architecture needed to be built to address. All three assumptions are failing at once, the data confirming each is now unambiguous, and the organisations that built genuine AI governance have a structural advantage over the ones that bought a subscription, fired their people, and are now rehiring them six months later at higher cost.

Free tier 21 min read
You Did Not Fire Your Developer. You Created Your Adversary.
Part 23 · Insider ThreatJune 1, 2026
You Did Not Fire Your Developer. You Created Your Adversary.

Atlassian terminated sixteen hundred employees on the eleventh of March 2026. Six weeks later an eight-year veteran of the edge infrastructure team uploaded a thirty-eight-minute YouTube video walking through the company's entire production architecture. Some viewers called it the best free system design lesson on the platform. They were also describing, in different words, a complete operational security disclosure for any actor that wanted to attack the company. The AI replacement doctrine has produced the largest involuntary supply of high-context insider threats in the history of the industry, and the demographic concentration is in the cohort that holds the most institutional memory. The DSI reading of what comes next.

Free tier 16 min read
The Method Beneath the Map
Part 24 · Chokepoint DoctrineJune 1, 2026
The Method Beneath the Map

Methodology reference for the Chokepoint Doctrine series. How GISI assigns probability bands, why the numbers carry analytical weight, the Tetlock-style decomposition that produces them, the rerate-trigger discipline that keeps them honest, and the three categories of question where we refuse to forecast at all. Show the work or the work does not count. The work is the band, the decomposition, the trigger, the limit, and the refusal to forecast where the forecast would not survive its own publication.

Free tier 11 min read
The Mercenary Bargain
Part 25 · Chokepoint DoctrineJune 1, 2026
The Mercenary Bargain

Two Doctrines, One Coastline named the coalition chokepoint. This piece names what the United Arab Emirates is actually doing inside that coalition. The federation flew Israeli targeting packages out of Al Dhafra against Iranian targets it has held a constitutional grievance with since 1971. The Abu Dhabi capital base has been welded into the American artificial intelligence stack at the chip, model, and platform level — through MGX, OpenAI, Anthropic, the Stargate project, BlackRock, and Microsoft — in commitments that cannot be unwound without vaporising approximately eighty billion dollars of Emirati positioning. The federation will survive the war structurally. The brand promise the survival depended on will not.

Free tier 12 min read
The Car That Knows Too Much: How the Connected Vehicle Became the Most Invasive Data Collection Device You Own
Part 26 · Chokepoint DoctrineJune 1, 2026
The Car That Knows Too Much: How the Connected Vehicle Became the Most Invasive Data Collection Device You Own

130,000 UK Mercedes records on a cybercrime forum. Toyota's decade-long location-data exposure across 2.15 million customers. VW feeding driver location to law enforcement. The Mercedes breach is the visible surface rupture; the architecture beneath is a surveillance contract you signed when you bought the car.

Free tier 12 min read
The Surveillance That Nobody Had to Hack
Part 27 · Chokepoint DoctrineJune 2, 2026
The Surveillance That Nobody Had to Hack

USCENTCOM has confirmed it: US forces in active war zones have been targeted using commercial location data bought from adtech brokers. No exploit. No malware. No insider. Just a credit card and a dataset. The Pentagon was first warned in 2016, when contractor Mike Yeagley tracked JSOC personnel from Fort Liberty to a covert facility inside a Lafarge cement factory in Syria using advertising data. A decade later the institutional response has remained a guidance document telling soldiers to review their privacy settings. This DSI piece maps the chain, the reverse pattern of life tradecraft, the carrier layer nobody is regulating, and what adequate protection actually requires.

Free tier 16 min read
Call Your Families. Say Goodbye.
Part 28 · Chokepoint DoctrineJune 2, 2026
Call Your Families. Say Goodbye.

On 27 April 2026 the Iranian MOIS cover group Handala (Storm-0842) sent personalised WhatsApp messages to US service members at Naval Support Activity Bahrain naming them by rank, unit, and personal phone number, and the next day published the claimed details of 2,379 named US Marines — home address, family, daily commute, shopping habits, nightly leisure. The data was not stolen. It was bought. This convergence article ties the DSI adtech surveillance piece, the connected vehicle piece, and the Handala profile from the Stryker article into a single argument: three commercial data streams, one mosaic, one targeting package, no breach.

Free tier 12 min read
The Room Has Been Watching
Part 29 · Chokepoint DoctrineJune 5, 2026
The Room Has Been Watching

Smart-TV ACR (Automatic Content Recognition) fingerprints the screen every 500 milliseconds, captures every HDMI input — work laptops, consoles, paired phones — ties the fingerprint to the household IP, and sells. Samsung admitted the architecture out loud in 2015 (in writing, in its privacy policy, transmitting plaintext audio to a third party). The Vizio FTC settlement was 2017. The Texas Attorney General sued five manufacturers in December 2025; Samsung settled on 26 February 2026; Sony, LG, Hisense and TCL are still fighting. The European Union has GDPR and the ePrivacy Directive and has not enforced. This is the fourth node of the DSI commercial-surveillance mosaic after adtech, connected vehicle, and the Handala OSINT convergence. Orwell got the architecture right and the operator wrong: the modern telescreen works for whoever pays.

Free tier 16 min read
The Liquidity Engineering
Part 30 · Market EconomyJune 6, 2026
The Liquidity Engineering

How the SpaceX IPO closes the loop on Twitter’s $44 billion loss. The route from a Twitter share purchased October 2022 to a SpaceX share trading on Nasdaq June 12 2026 runs through three sequential all-stock mergers, two paper-valuation revisions, and one record-setting public offering at a $1.75 trillion valuation — without cash changing hands at any intervening step. The Twitter investors who would otherwise be down 80 percent now exit at 2.5x to 3x their original investment. The valuation multiples that justify the IPO — 109x revenue, 265x EBITDA — do not have a clear historical precedent at this scale. This is the first piece in the new GISI Market Economy series and names the technique by its discipline: liquidity engineering.

Free tier 14 min read
Intelligence Brief — Week of 8 June 2026
Part 31 · Intelligence BriefJune 8, 2026
Intelligence Brief — Week of 8 June 2026

Inaugural DSI Intelligence Brief. Mike Yeagley — the government contractor named in Senator Wyden’s 28 May 2026 letter, the person who in 2016 tracked US special operations forces from Fort Liberty to a covert Lafarge cement factory in Syria using commercially purchased advertising data — has now responded to Wyden in a formal congressional letter. The response advances the argument in three directions: the inference layer (“You no longer carry a name. You carry a pattern. Behaviour is your identity.”), the ambiguity doctrine (privacy as the standing condition of the operator’s life, maintained by architecture, not as a setting), and a decision-forcing body with a 90-day deadline to set technical standards for what applications may collect on a Department of War–managed device. Also: the EU age-verification piece concludes the regulatory series; the connected vehicle piece arrives later in the week.

Free tier 6 min read
The Wrong Map
Part 32 · Chokepoint DoctrineJune 9, 2026
The Wrong Map

Part I of the Governance Gap trilogy. The Chokepoint Doctrine series’ central finding, stated as its central thesis for the first time: no institution has the mandate, the expertise, and the authority to govern the full threat surface of any critical system simultaneously, and the adversary’s operational architecture is specifically designed to exploit the space between the institutions that cannot coordinate fast enough. The three wrong questions Western institutions are asking — What is the adversary doing? Which institution is responsible? How do we deter the adversary? — and the right questions that should replace them. The governance gap is the chokepoint. Everything the series has documented is a symptom.

Free tier 10 min read
The Wrong Posture
Part 33 · Chokepoint DoctrineJune 9, 2026
The Wrong Posture

Part II of the Governance Gap trilogy. The operational requirement that follows from the strategic finding: every security architecture is built against the threat model that the current architecture was already adequate to detect — which means the threat operating in the governance gap is, by definition, the one your architecture cannot see. The four wrong questions enterprise security is organised to answer (compliance, breach, supply chain, incident response) and the right ones (adversarial view, inference, shared infrastructure, intersection) that the full threat surface framework requires. France Titres, Snowflake, Trellix, the NIS2 / NiS2 chemical-plant scenario — each as evidence the gap is operational, not theoretical.

Free tier 8 min read
The Irreversible Layer
Part 34 · Chokepoint DoctrineJune 9, 2026
The Irreversible Layer

Part III of the Governance Gap trilogy. The class of risks where post-activation governance cannot reverse the consequences. Three thresholds: the Kessler cascade in LEO that becomes self-sustaining once triggered, the HNDL harvest already in progress against the Mosca inequality (15-year confidentiality data generated from 2020 onwards is already in the risk window), and the inference permanence where Yeagley’s behavioural model meets Q-Day content decryption. The 1,400-fold qubit reduction in three months. Google’s 2029 internal deadline. CNSA 2.0 in January 2027. DORA quantum risk monitoring active since January 2025. The governance gap that cannot be closed after the risk activates — because the activation itself changes the conditions under which governance is possible. The time to close it is before the activation. The Chokepoint Doctrine series, complete.

Free tier 19 min read
The Platform That Holds Every Key
Part 35 · Chokepoint DoctrineJune 12, 2026
The Platform That Holds Every Key

ServiceNow’s third authentication bypass in eight months — and the first where attackers reached customer data before a patch was applied. The June 2026 REST endpoint shipped with requires_authentication=false. IP 51.159.98.241 queried tenant tables on June 2–3. The patch landed silently on June 5. Public disclosure on June 9, gated behind a customer support login. October 2025 (BodySnatcher impersonation), January/February 2026 (AI sandbox RCE), and now this. Three components. Three mechanisms. One consistent root cause category. ServiceNow is the system the organisation tells everything to. In this framing, it is not the target — it is the map. The ITSM blind spot in enterprise security architecture, and the question every security team should be asking about every platform that knows about everything else.

Free tier 9 min read
The Export Control That Reached Inside the Model
Part 36 · Chokepoint DoctrineJune 15, 2026
The Export Control That Reached Inside the Model

At 5:21pm ET on Friday 12 June 2026, a US government letter directed Anthropic to suspend Fable 5 and Mythos 5 for any foreign national, anywhere in the world, including its own non-US employees. Anthropic complied within hours, in full, worldwide — while publicly dissenting from the action and stating that the underlying capability is freely available from competing models without restriction. Sixteen days earlier, the European Commission had published the Tech Sovereignty Package built for exactly this scenario. The letter is the first operational use of Export Control Classification Number 4E091, finalised in the BIS Framework for AI Diffusion on 15 January 2025 to cover frontier model weights trained on more than 10^26 computational operations. The pattern it completes — CLOUD Act 2018, Schrems II 2020, the chip rules 2022, the AI weight rule 2025, the ICC sanctions, the Solvinity block, the EU package, now this — is the ladder of US extraterritorial reach this series has been mapping. The new layer is cognition itself. With the eight-rung extraterritoriality timeline, the seven-region cognitive-dependency map, and the strategic read for EU, UK, India, China, Japan, Korea, Middle East, and Africa.

Free tier 12 min read
When Your Provider Is the Chokepoint
Part 37 · Chokepoint DoctrineJune 15, 2026
When Your Provider Is the Chokepoint

The operational lesson of the Fable 5 and Mythos 5 suspension is not about whether the directive was justified. It is about what it demonstrated: every non-US enterprise running production AI workloads on a US-headquartered frontier model is, structurally, one letter away from an outage that no contract, no regional setting, and no sovereign cloud reseller can prevent. Anthropic had to “abruptly disable” both models for all customers globally to comply — within hours of receiving the 5:21pm ET letter. Three categories of exposure: hard-coded production dependencies, research collaborations with non-US personnel, and government / regulated-industry partnerships (TCS-50K-users-across-56-countries, DXC-banking, all in scope). The full threat surface framework now treats provider home jurisdiction as a primary variable. Single-provider risk is single-sovereign risk. The failover architecture that survives the next 5:21pm letter, with five cross-cutting controls (contract, cache, drill, audit, board), the sovereignty risk matrix across seven provider categories, and the action list for the next four working days under DORA, NIS2, the EU AI Act, and the Tech Sovereignty Package.

Free tier 12 min read
The Pattern Is the Platform
Part 38 · Chokepoint DoctrineJune 15, 2026
The Pattern Is the Platform

On 14 June 2026, ShinyHunters added the Council of Europe to its dark web leak site, claiming 297 GB across 429,000 files: 409,000+ payslips, 10,000+ employee records spanning fifteen years, 14,000+ CVs, interpreter scheduling, salary scales, bank and tax data, medical records. Five days earlier, Mandiant had published indicators of compromise for an active two-week zero-day campaign against Oracle PeopleSoft — CVE-2026-35273 in the Environment Management Hub, CVSS 9.8, unauthenticated, exploited from 27 May to 9 June before Oracle's 10 June advisory. 100+ organisations notified, 68% in higher education. The Council of Europe leak surfaced inside the trailing window of that campaign, with a data profile category-for-category matching what PeopleSoft holds. Whether the Council of Europe runs PeopleSoft and whether this specific breach used CVE-2026-35273 has not been publicly confirmed. What can be said: the Council of Europe is the third time in eight weeks this series has documented an identical structural shape — Trellix in May (RansomHouse, source-code access), ServiceNow in June (unauthenticated REST endpoint), now PeopleSoft. Three vendors. Three product categories. One architecture of failure. The pattern is the back-office platform, not the institution it serves.

Free tier 9 min read
The New Munitions List
Part 39 · Chokepoint DoctrineJune 16, 2026
The New Munitions List

In the early 1990s, exporting strong cryptography from the United States was, legally, exporting a weapon. A T-shirt with RSA source code was a controlled export. Phil Zimmermann spent three years under US Customs investigation for publishing PGP. It took most of a decade — and Executive Order 13026 in November 1996 — to dismantle the regime. The signal, WhatsApp, Telegram, TLS, and every banking app on every phone exist in their current globally-available form because that restriction was eventually lifted. On Friday 12 June 2026, at 5:21pm ET, the same structural argument returned in a sharper form. A letter from the US government to Anthropic. Fable 5 and Mythos 5 suspended for any foreign national worldwide. The artefact has changed — from published math to hosted frontier model. The mechanism has changed — from court enforcement to a configuration flag at a single provider. The argument has not. The market consequence will not either. Whoever fills the gap during the restricted years keeps the customers after liberalisation. The companion historical-precedent piece to “The Export Control That Reached Inside the Model.”

Free tier 13 min read
The Architecture Beneath the Signature
Part 40 · Chokepoint DoctrineJune 17, 2026
The Architecture Beneath the Signature

The United States and Iran are the ones signing the deal that ended the 2026 Iran war. Qatar and the UAE are the ones who actually made it possible. The UAE has unlocked $10B for Iran with $3B+ already delivered, in exchange for halted attacks and economic-intelligence cooperation. Qatar holds $6–12B in Iranian frozen assets under custody — the $6B from the September 2023 South Korea transfer, restricted to humanitarian use, never released after October 7. Tehran cannot access any of it without Doha. This is the first major US–Iran deal in fifty years not architected by the United States. The Full Threat Surface framework applied to the deal across four dimensions — physical geography (Hormuz, Al Udeid, the dual-track positioning), logical architecture (the three-layer financial mechanism), governance architecture (the ad-hoc enforcement coalition with no precedent), and adversarial intent (Iranian pragmatists vs hardliners, UAE $500B self-preservation, Qatar's strategic positioning, Trump's narrative needs, Israel's disruption vector). The predictive intelligence layer: four probability-banded scenarios across the oil path from current $80s through December 2027, mapped against Gulf fiscal break-evens (KSA $80, UAE $60, Qatar $45, Kuwait $70). The deeper question the diplomatic coverage is not asking: whether the Gulf states can sustain the mediation through the recession their own success helped to create.

Free tier 13 min read
The Weakest Custodian in the Chain
Part 41 · Chokepoint DoctrineJune 22, 2026
The Weakest Custodian in the Chain

985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.

Free tier 10 min read
The Strait Held by Permission
Part 42 · Chokepoint DoctrineJune 22, 2026
The Strait Held by Permission

Since the 2026 Iran war opened on 28 February, Iran has pushed at least 11.7 million barrels of crude through the Strait of Hormuz it declared closed — every barrel to China, and on 4 March it made the arrangement explicit: only Chinese vessels may pass. The strait was never closed. It was reserved. Western coverage of the 20 June closure reads the map upside down. Hormuz carries ~20 million barrels a day, close to a third of seaborne crude, and almost 90% sails east — China 5.4 mb/d, India, Japan, and South Korea another slice each. The hostage is not the empire; it is the Global South that buys from the Gulf, led by Iran's own creditor. The weapon points home: ~90% of Iranian crude leaves via Kharg and must transit Hormuz, so a blockade of the strait is mechanically a blockade of Iran — which is why Tehran is quietly loading at Jask, beyond the chokepoint. And the leverage belongs to the buyer: China pre-stocked its reserves, kept Brent near $80 when analysts forecast $200, and now sets the price of any closure. Iran holds the geography. Beijing holds the economy of the geography. This is conditional sovereignty in the energy age — the inherited chokepoint exercisable only on terms set elsewhere. Part II of two; Part I is 'The Architecture Beneath the Signature.'

Free tier 8 min read
The War That Cannot End
Part 43 · Chokepoint DoctrineJune 22, 2026
The War That Cannot End

Why the Strait of Hormuz keeps closing, why the salt caves have a floor, and why Netanyahu's calendar is the variable that no peace deal can govern. Four thousand feet below Louisiana and Texas, the US strategic petroleum reserve sits in salt caverns with a hard physical floor: below roughly 150-250 million barrels of its 714-million capacity, the caves begin to collapse and the oil is lost, not depleted but structurally destroyed. That floor is the clock behind the 17 June Versailles MOU between Trump and Pezeshkian, and behind Trump's urgency for peace. But the deal has a structural flaw visible before the ink dried: its first clause requires a ceasefire on all fronts, and the enforcer on the Lebanese front is a state that never signed it. By 21 June Iran had re-closed Hormuz over continued Israeli strikes in Lebanon; the Switzerland talks then collapsed, JD Vance left without an agreement or a handshake. My assessment: Netanyahu's Lebanon strikes are not a survival calculation but a compulsion, and rational-actor theory cannot model a compulsion. Iran does not need to win; it needs to outlast, and it can absorb punishment that would end any Western government. The MOU is as valid as its weakest enforcement node. That node is in Jerusalem.

Free tier 13 min read
The Root of Trust That Already Leaked
Part 44 · Chokepoint DoctrineJune 28, 2026
The Root of Trust That Already Leaked

In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.

Free tier 9 min read
The MOU Is Dead. The Series Called It.
Part 45 · Chokepoint DoctrineJune 28, 2026
The MOU Is Dead. The Series Called It.

Breaking update. Between 2 and 3am on 28 June 2026, Iran's IRGC launched ballistic missiles and drones at two US military facilities at once - the Ali Al Salem Air Base in Kuwait and the Fifth Fleet headquarters at Salman Port in Bahrain - claiming eight installations destroyed, after a second wave of US strikes on Iran. It is the end of a 48-hour collapse: the drone strike on the container ship Ever Lovely and the IMO's paused evacuation of 11,000 sailors on 25 June, a US strike on the 27th, Iran's drone hit on the tanker Kiku carrying 2 million barrels of crude, a second US strike, and Israel's approval of continued operations in southern Lebanon two days after a ceasefire. The Versailles MOU of 17 June is functionally dead. A week ago, in 'The War That Cannot End,' my assessment was that the MOU was as valid as its weakest enforcement node, and that the node was in Jerusalem. Four written judgments - the Lebanon tripwire, Netanyahu's electoral calendar, Iran's temporal asymmetry, and the resumption of tanker attacks - have now been confirmed in 48 hours. This is a fight over a shipping lane, and Iran is enforcing a claimed sovereignty over Hormuz with ballistic missiles. The MOU was the pause, not the settlement.

Free tier 6 min read
If You Put Data in a US Cloud, You Share It With US Intelligence
Part 46 · Chokepoint DoctrineJune 29, 2026
If You Put Data in a US Cloud, You Share It With US Intelligence

From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.

Free tier 9 min read
Your Smart TV Is Someone Else's Criminal Infrastructure
Part 47 · Chokepoint DoctrineJuly 3, 2026
Your Smart TV Is Someone Else's Criminal Infrastructure

On 2 July 2026, the FBI and IRS Criminal Investigation seized NetNut, a residential proxy service run by the NASDAQ-listed Israeli company Alarum Technologies, after Google and partners degraded the Popa botnet — roughly two million consumer devices, including the Android TV box and smart television under millions of ordinary homes, enrolled with little or no consent. A residential proxy routes criminal traffic through real home connections, so when a target checks the source it sees your ISP and your city, not a data centre. In one week of June 2026, Google's Threat Intelligence Group counted 316 distinct threat clusters — criminal and nation-state — using NetNut exit nodes; a comparable network, IPIDEA, carried APT28, Sandworm, and Volt Typhoon. My assessment: the FBI's advice to avoid cheap streaming boxes is correct and insufficient, and this is not a botnet you kill but a market you would have to close, resilient because the same infrastructure serves legitimate ad-verification and nation-state espionage alike. The connected device is the permanent weak point: the risk rides an access path you never chose to open. What to do today: segment your smart devices onto a separate network, and ask what the box under your television does when the television is off.

Free tier 8 min read
Every Box Is Governed. The Space Between Is No One's Job.
Part 48 · Chokepoint DoctrineJuly 4, 2026
Every Box Is Governed. The Space Between Is No One's Job.

Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.

Free tier 9 min read
Two Straits, One Funeral, and What Medvedev Just Said Out Loud
Part 49 · Chokepoint DoctrineJuly 4, 2026
Two Straits, One Funeral, and What Medvedev Just Said Out Loud

Flying back from Ayatollah Khamenei's state funeral in Tehran, Russia's Dmitry Medvedev said the Strait of Hormuz has become a weapon 'no weaker than a nuclear weapon' for Iran - and that Iran holds 'a thermonuclear weapon in reserve, the Bab el-Mandeb Strait.' Medvedev does not speak carelessly. This piece puts his claim under scrutiny: Hormuz carries a fifth of world oil and works as a deterrent whose power derives from the threat, not the use; Bab el-Mandeb carries roughly a tenth of global trade by volume and, as the Houthi campaign proved, can be disrupted by a non-state actor without physical control. The nuclear analogy names the energy market; the thermonuclear analogy names the entire container-shipping architecture. Delivered at a funeral no Western government attended, as France and the UK signal naval deployment to Hormuz and Iran answers with a sovereignty claim, the statement reframes the series' four-month chokepoint map: what this series read as vulnerabilities, Moscow is naming as weapons. The thermonuclear weapon has not been used - which is the most important fact in the statement, and the reason he said it out loud.

Free tier 9 min read
The Credential You Can't Change
Part 50 · Chokepoint DoctrineJuly 7, 2026
The Credential You Can't Change

Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.

Free tier 8 min read
The Camera That Cannot Be Turned Off
Part 51 · Chokepoint DoctrineJuly 8, 2026
The Camera That Cannot Be Turned Off

Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.

Free tier 10 min read
The Shadow of the Future — Q2 2026 Special Report
Part 52 · Special ReportJuly 8, 2026
The Shadow of the Future — Q2 2026 Special Report

Our Q2 2026 Special Report. Robert Axelrod showed cooperation among rivals survives only where four conditions hold - a long shadow of the future, clear signals, enforceable reciprocity, and legible reputation. Across every domain we cover - chokepoints, ransomware, cyber attribution, the AI race, the quantum transition, digital identity, and the dollar itself - the security environment is systematically destroying those four conditions. The report scores seven games on one board, asks whose game we are actually in (China's Go, Russia's reflexive control, the West's chess), names the Defection Premium as the largest unpriced liability on the balance sheet, and grades our own Q2 forecasts in the open. Read the interactive report or download the 67-page PDF.

Free tier 2 min read
No Means No. Except When It Does.
Part 53 · Regulatory ForesightJuly 9, 2026
No Means No. Except When It Does.

On 9 July 2026 the European Parliament revived Chat Control 1.0 — three months after rejecting it. A majority of MEPs still voted against (314 to 276, 17 abstentions), but under the second-reading procedure the EPP engineered, blocking it required an absolute majority of 361. Opponents fell 47 short. The vote count is not the story. The procedure that inverted the burden of proof — timed for the last day before recess — is.

Free tier 9 min read
Every Company Is China-Free. The Refinery Says Otherwise.
Part 54 · Chokepoint DoctrineJuly 10, 2026
Every Company Is China-Free. The Refinery Says Otherwise.

Bloom Energy's CEO said it for years: no China supply chain. A short-seller says otherwise — but Bloom is a symptom, not the story. Concealing Chinese origin is now an industrial practice ($549M in aluminium as 'pallets'; tungsten laundered through Taiwan; Chinese magnets in the F-16, the F-18 and the F-35 three times over), because 'China-free' is worth a fortune and origin is structurally unverifiable. The deeper move: China controls these inputs by export licence, not ban — and every licence forces disclosure of the end user. Beijing holds a more accurate map of American critical dependencies than America's own regulators do. My assessment of the real risk, and where it goes in a Taiwan crisis.

Free tier 9 min read
The Inequality Has Already Been Violated
Part 55 · Chokepoint DoctrineJuly 10, 2026
The Inequality Has Already Been Violated

I went looking for one number — the 20 million qubits everyone said it would take to break RSA-2048 — and found it no longer holds. Not because the hardware moved, but because the mathematics did: three papers in ten months (Gidney's under-a-million, Iceberg's contested sub-100,000, and a Caltech–Berkeley–Oratomic team's 'as few as 10,000') have compressed the requirement more than a thousandfold. Applied honestly to a decade-long harvest and multi-decade confidentiality periods, the Mosca inequality no longer rules out that the most sensitive data already collected is compromised in waiting. The full arithmetic — and what it means for AUKUS, the harvest, and a policy response that has not caught up.

Free tier 14 min read
The Ship and the Iceberg
Part 56 · Chokepoint DoctrineJuly 12, 2026
The Ship and the Iceberg

Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.

Free tier 13 min read
The Architecture of the Watched World
Part 57 · Chokepoint DoctrineJuly 14, 2026
The Architecture of the Watched World

I saw The Lives of Others in 2011, and it shook me to my core — not the cruelty of the Stasi, but the ordinariness of it: a life catalogued by professionals simply doing their jobs. I have spent the years since watching a version of that filing system being rebuilt, not by a police state but by democracies, for reasons that are mostly good, using tools most people carry willingly in their pockets. This DSI assessment maps the six-layer identity-and-surveillance stack now in deployment across the EU, UK, Australia and beyond — identity wallets, age verification, message scanning, biometric driver monitoring, ambient audio, and behavioural data — each introduced with a genuine justification, and ungoverned in combination. It corrects the viral misreading of what Von der Leyen actually said, sets the 1984 Stasi against the 2026 stack, and closes with five dated, falsifiable forecasts and the risks I would put on any register I was responsible for. The Stasi needed forty years, 91,000 staff and 175,000 informants. The equivalent capability now needs an app, a camera, and a terms-of-service agreement — and there is no wall to tear down.

Free tier 18 min read
The Book That Predicted This War Was Published in 2006
Part 58 · Chokepoint DoctrineJuly 15, 2026
The Book That Predicted This War Was Published in 2006

On 13 July 2026, the IRGC declared "the time for restraint is over" and struck US forces across the Gulf — the fifth month of an infrastructure war that has thrown 4,000-plus projectiles at GCC states, damaged 80-plus energy facilities, and pushed the IMF to project Qatar's economy contracting 14.7%. None of it should surprise anyone who has read Lawrence Wright's The Looming Tower. The Pulitzer-winning 2006 account of al-Qaeda was never really about al-Qaeda — it documented a playbook: bleed the patron by making its presence too expensive; hit the client states that host its power; exploit the seams between institutions that will not cooperate; and trust that your read of the superpower's tolerance is more accurate than its own. This GISI assessment maps all four components onto Iran's Gulf campaign in real time — not as moral equivalence, but as strategic logic. The war will not end for the same reason 9/11 was not prevented: not missing information, but institutions unable to assemble what they separately know into the single picture the adversary has already built.

Free tier 12 min read
The Model on Your Desk Was Never Audited
Part 59 · Chokepoint DoctrineJuly 19, 2026
The Model on Your Desk Was Never Audited

Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.

Free tier 14 min read
The Week Washington Looked Back and Beijing Built the Next Decade
Part 60 · Chokepoint DoctrineJuly 19, 2026
The Week Washington Looked Back and Beijing Built the Next Decade

In one seventy-two-hour window in July 2026, four things happened — and only one country spent it building. Washington used primetime to relitigate the 2020 election. Beijing released Kimi K3, the largest open-weight AI model ever published; founded the World AI Cooperation Organization with 29 nations and the UN Secretary-General's endorsement; and kept winning American enterprise adoption, now 30 to 46% of the tokens US companies route. This GISI assessment holds the evidentiary asymmetry explicitly — observable fact, measured data, and contested claim are not the same category of certainty — and maps the state-subsidised industrial playbook China has already run on solar panels and electric vehicles onto AI. Twenty-three-to-one US capital bought a benchmark lead of 2.7 points. Both governments spent the week doing something legitimate. Only one was building something that will still be standing in ten years.

Free tier 14 min read
Two Stories, One Battlefield
Part 61 · Chokepoint DoctrineJuly 20, 2026
Two Stories, One Battlefield

The Iran war has resumed. Washington sells salvation; Tehran sells resistance. Neither story explains why a war both sides keep pausing keeps coming back. The structure does — and the bill radiates to the Global South. Part I of a two-part, deliberately neutral assessment.

Free tier 9 min read
You Cannot Bomb a Question
Part 62 · Chokepoint DoctrineJuly 20, 2026
You Cannot Bomb a Question

American force fails against the decisive chokepoint at every scale — and so would Iranian force against the Gulf. Why the war keeps returning to limbo instead of ending, who prefers it that way, and who is handed the bill. Part II of a two-part, deliberately neutral assessment.

Free tier 10 min read