
In the span of one week, a small cell in northern Yemen used a commercial AI coding tool to work on missile guidance software. Cyber teams in Brussels used a commercial AI model to find flaws in the European Union’s own code. The National Security Agency started a 30-day clock to rebuild itself around artificial intelligence. And China’s spy chief wrote that cybersecurity has entered an era of “AI versus AI.” The weapon, the shield, and the institution all reached for the same technology at once. The barrier that kept sophisticated capability in the hands of sophisticated actors is coming down, and the companies that matter now are the ones that own what the model cannot.
The Deep Dive
The weapon
On September 10, Anthropic published its latest threat report, Detecting and countering misuse of AI. One case describes a cell operating from northern Yemen that used Claude Code as a stand-in for a missile engineering team. Anthropic did not name the group, though, as The War Zone noted, the Houthis are based primarily in northern Yemen.
The operators ran parallel sessions: one writing code, one researching, one reviewing the work of the first. Their stated goals included a multi-stage ballistic missile with a range above 2,000 kilometers. They worked through guidance and flight-control software, then test-fired a guided rocket. By Anthropic’s account the test appears to have failed, and within hours the actors were back asking the model why.
Anthropic banned the accounts and found no evidence the group fielded an operational weapon. By then the actors had already built an offline simulation toolkit that runs without Claude. Safeguards blocked many of their requests, but not all, and the operators split the work across sessions so no single conversation revealed their full intent. The Yemen cell was one of several conventional-weapons cases in the report, alongside cases tied to China and Russia.
This was not a chatbot answering one dangerous question. It was a distributed engineering program run by a handful of people, compressing design, testing, and failure analysis into a single loop. A safety system that reads requests one at a time cannot see a missile program assembled from innocuous pieces.
The shield
The same week, Politico reported that ENISA, the EU’s cybersecurity agency, used an advanced OpenAI model to review source code for an EU project. The model found four vulnerabilities. One was rated high risk and could have let an attacker hijack accounts. All four have been fixed. The EU only won access to the most capable US models in July, after months of asking. Within weeks, the payoff showed up in patched code.
Europe spent months arguing about digital sovereignty and its dependence on a handful of American labs. The first thing it did with that access was harden its own systems. The dependence Europe worried about is now also load-bearing in its defense.
The institution
General Joshua Rudd, who leads both the NSA and US Cyber Command, started a 30-day clock this month to recast the agency into five mission centers: China, cybersecurity, artificial intelligence, combat support, and global intelligence. Each center gets its own chief, including a new head of AI. The target is full operational capability by January. At his confirmation hearing before the Senate Intelligence Committee in January, Rudd said his “first priority is speed.”
The agency last attempted a restructuring of this scope roughly a decade ago, and current and former officials still regard that effort as a failure that added bureaucratic confusion. Officials told The Record that Rudd and Deputy Director Tim Kosiba know the rapid realignment will “break things.” They are moving anyway. When an institution built on process decides speed beats stability, it is telling you how fast it thinks the other side is moving.
AI versus AI
Beijing is reading the week the same way. Chen Yixin, China’s Minister of State Security, named Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of a “disruptive upgrade” in cyber capability. Writing in the journal of the Cyberspace Administration of China, Chen said the field is entering a phase of “vulnerability industrialization, fully automated attack and defense, and AI versus AI.” He did not allege either model had been used against China. When Beijing’s spy chief and American security teams cite the same model names in the same week, nobody holds an edge from access alone.
What actually changed
The capability that let a small cell stand in for a missile engineering team let Brussels stand in for a red team. Offense and defense now draw from the same well. The advantage no longer comes from having the model, because everyone has the model. It comes from what surrounds it: proprietary data, evaluation, the operational workflow, and the speed to act on what the model surfaces before an adversary acts on the same insight. The NSA’s stated goal is speed, not raw capability, for exactly this reason.
The offline toolkit is the harder lesson. Once a capability is assembled, it no longer depends on the vendor’s safeguards. Banning the accounts closes the front door after the tools have left through the back. Guardrails at the model are necessary and insufficient. Durable control sits with whoever owns the data and the workflow, not the weights.
The Yemen case is also the tell on proliferation. China and Russia already had these capabilities. A small, resource-poor group climbing toward work that used to require a national program is new. AI does not only make the strong faster. It raises the floor under the weak, and it does that fastest for the actors with the least to lose and the least to deter them.
The Investment Takeaway. We believe the defensible layer in national security AI is not the model. It is the proprietary data loop and the operational workflow around it, the part that compounds over time and cannot be walked out the door in a single session. We back companies that own that loop and turn model output into action inside a real operational cycle, in cyber, intelligence, and autonomy. Two of our portfolio companies sit squarely on this thesis: Reality Defender in deepfake and synthetic-media detection, and CrunchAtlas in active cyber defense for critical infrastructure. The model is a commodity input.
It also sharpens what we will not pay for. A thin layer over someone else’s frontier model, with no proprietary data and no operational hook, is a feature waiting to be absorbed by the next model release. Value accrues to whoever turns the technology into an outcome faster than the other side, and can prove it in an environment where the other side is using the same tools.
The Funding Ledger
The week’s biggest dual-use checks, and what they bought:
Stoke Space: $1 billion Series E, co-led by Point72 Ventures and Spark Capital. The Kent, Washington company is building Nova, a fully and rapidly reusable rocket, and has now raised $2.3 billion in total.
Positron AI: $875 million across two tranches at a $5 billion valuation. NEA co-led both, joined by Andra Capital, Atreides, Valor Equity Partners, and SemiAnalysis Capital in the first and Jim Clark in the second. The Reno company builds inference systems on commodity memory, sidestepping the constrained supply chain for high-bandwidth memory.
Suniva: $835 million in debt and equity, with senior credit from Goldman Sachs Alternatives and I Squared Capital and equity from Electron Capital Partners, Orion Infrastructure Capital, and Rubric Capital Management. The Norcross, Georgia company is the largest and oldest US merchant maker of monocrystalline solar cells and is merging with Nasdaq-listed SUNation Energy.
Mach Industries: $600 million Series C extension at a $3.7 billion valuation, from investors including Ribbit Capital, Infinite Capital, Bedrock, and Sequoia. The Huntington Beach company builds strike drones, counter-drone systems, and propulsion, and doubled its valuation in three months.
The Exploration Company: $450 million Series C, co-led by Bessemer Venture Partners, Atomico, and EQT’s Scaleup Europe Fund. The European company is building the reusable Nyx capsule, and calls this the largest Series C ever announced by a European space company.
Poseidon Aerospace: $60 million Series A led by TQ Ventures, with JAWS, G Squared, and Hanwha Asset Management USA participating. The Alameda, California startup is building Egret, an uncrewed regional cargo aircraft aimed at contested logistics, with a first full-scale flight expected by year end.
Every dollar here went into physical things: rockets, a capsule, chips, solar cells, strike drones, and cargo aircraft. Not one software wrapper. The Exploration Company is the only non-American name, and it posted Europe’s largest space Series C, which says sovereignty is now a fundable thesis on both sides of the Atlantic. Suniva stands out for a different reason. A domestic solar cell maker raised most of its money as credit, because lenders now underwrite supply-chain independence like infrastructure. Capital is voting for the industrial base, not the app layer.
The Northeast Desk
New Hampshire’s defense community gathered this morning. BENS, Business Executives for National Security, convened its New Hampshire national security ecosystem breakfast in southern New Hampshire, and New North Ventures helped host. The goal is to put the founders, primes, universities, and state officials building the state’s defense economy in the same room.
The University of New Hampshire will host the first Northeast Space, Technology, Trade and Research Expo in Durham on October 28 and 29, with the state’s Department of Business and Economic Affairs and the NH Aerospace and Defense Consortium. According to BEA data cited by UNH, New Hampshire has about 300 aerospace and defense companies with 10,500 direct employees and $7.5 billion in output, 3.6 percent of state GDP and growing toward 4 percent. For a state our size, that is a core industry.
In Rhode Island, Havoc signed a licensed co-production partnership with Taiwan’s CSBC Corporation on September 10 to field autonomous surface vessels for Taiwan’s maritime security. CSBC builds the vessels. Havoc supplies the collaborative autonomy software. “Congress wrote co-production with Taiwan into law in the FY2026 defense authorization,” said CEO Paul Lwin, pointing to Section 1266, which names uncrewed systems. (Havoc is a New North Ventures portfolio company.)
On the calendar: the NDIA Undersea Warfare Fall Conference runs September 21 to 23 in Groton, Connecticut, at the center of the submarine industrial base. The Northeast STTAR Expo follows October 28 and 29 at UNH in Durham.
Portfolio Corner: Headlamp
Around 200,000 service members leave the US military every year. Almost 12,000 of them, across the Defense Department and the Coast Guard, went through SkillBridge in the first half of fiscal 2024, the program that lets troops train with a civilian employer during their final months in uniform. The gap between those two numbers is the market Headlamp is building for.
Headlamp, which New North Ventures led at the pre-seed, runs what founder and CEO Steve Chang calls SkillBridge-as-a-service. Chang is a retired Special Forces officer with an MBA from Wharton. The problem he is attacking is two-sided. Transitioning troops do not know which employers are ready for them, and employers do not know how to run a compliant fellowship. Headlamp sits in the middle, placing veterans into Headlamp Fellowships and handling the training and administration around them.
SkillBridge grew so fast that the Defense Department paused approvals of new employers in 2023 to catch up. Meanwhile the shipyards, factories, and defense startups featured every week in this newsletter all say the same thing about hiring: the people are the constraint. Headlamp turns a national obligation into a hiring channel. The company is still early and quiet on its own metrics.
More links to explore
Fusion goes looking for defense buyers: Xcimer Energy took a partnership and investment from RTX, and Pacific Fusion signed an MOU with the NNSA last month. (TechCrunch)
Iran captured an Anduril-built US military underwater drone, and analysts expect Tehran to try to reverse-engineer its hardware. (Defense News)
Shield AI is in talks to raise at a valuation of at least $20 billion, roughly 60 percent above its level five months ago. (The Information)
The Defense Innovation Unit wants an AI system that can understand and predict threats in space. (Via Satellite)
