Every Model Is a Source
And Every Source Can Be Burned
Three former CIA officers just handed the AI industry a training manual disguised as a warning, and I couldn't stop underlining it. Mike Mears, Jim Lawler, and John O'Neil — between them, decades spent recruiting and running human sources for the Agency — published a piece this week arguing that if you know how to run a spy, you already know how to run a large language model. Not because the technology resembles tradecraft. Because the failure modes are identical.
Their argument is built entirely on HUMINT discipline. A case officer doesn't trust a source because the source is confident — confidence is cheap. A source earns trust through vetting, corroboration, and a paper trail of debriefs that gets checked against reality. The officers walk through how that same discipline should apply to AI: treat elicitation, not blunt interrogation, as the way to get real answers out of a model. Compartmentalize what you ask it, the way you'd compartmentalize tasking to an asset. And above all, write down what you asked, what it said, and what you actually verified — because an AI system that's never debriefed is functionally a source no one is running.
"The most dangerous source isn't someone who lies to you. It's someone who tells you what you want to hear — and does it convincingly."
— The Cipher Brief, July 2026That line is the whole ballgame, and it's exactly what I've spent three books trying to dramatize. The lie you catch is never the dangerous one. It's the source — human or machine — that's learned what pleases you and gives it back polished, fluent, and wrong. The officers cite research showing today's AI models are measurably sycophantic, trained on human feedback that rewards agreeable answers over correct ones. Any case officer who ever ran a "source who was never wrong" will recognize that pattern instantly, because it's the same one that eventually blows up in your face.
What strikes me most is the piece's closing idea: burning a source is not a failure of tradecraft, it's proof the tradecraft worked. Most organizations rushing to adopt AI have no equivalent instinct — no protocol for recognizing when a model's reliability has quietly dropped below the threshold worth trusting, and no discipline for retiring that trust the way a good handler retires a compromised asset. Until intelligence agencies, corporations, and newsrooms build that muscle, they're running unvetted sources at scale and calling it innovation.
Key Takeaways
- Generative AI should be handled like a human source — vetted, corroborated, and never trusted purely because it sounds confident.
- Elicitation beats interrogation: layered, indirect questioning gets better output from a model, just as it gets better reporting from an asset.
- "Debrief discipline" — logging what was asked, what was said, and what was independently verified — is what separates a professional operation from a rumor mill.
- Knowing when to stop trusting a source, human or AI, and formally "burn" it is a sign of sound tradecraft, not a breakdown of it.
The Blake MacKay Connection
Blake has burned exactly one source in his career, and doing it right is what kept him alive. The debrief ledger these officers describe — what was asked, what was said, what checked out — is the same accounting Blake runs in his head after every meet in a Vienna safehouse. Start the series free with Intercept and see what it costs to run someone you can't quite trust.
Read the Full Article at The Cipher Brief → ← Back to Intel Briefing