Tag: Artificial Intelligence

  • How Scary Is AI Getting?

    How Scary Is AI Getting?

    The machines are not plotting our extinction in a secret bunker. The truth may be more complicated – and more troubling – than that.

    Screenshot of the WIRED article “Why So Many AI Researchers Think the Machines Could Kill Everyone,” illustrated with machines from Terminator 3.
    WIRED examines why recursive self-improvement, agentic swarms and recent security incidents are alarming researchers inside leading AI labs.

    There is an old adage in writing: you cannot make this stuff up.

    Of course, fiction writers make things up all the time. Cryptogeddon comes from my imagination. Its characters, conspiracies and crises are inventions. But the world in which I am writing it keeps producing developments that would have sounded implausible when I began.

    Over the past few weeks, the tone of the AI conversation has shifted again. Not because another chatbot can write a better email or produce a prettier picture, but because people working near the frontier are sounding genuinely frightened by what they are building.

    A recent WIRED report describes researchers worried about recursive self-improvement, autonomous agents and a loss of meaningful human control. One senior safety researcher put the possibility of AI killing everyone at greater than ten per cent within the next decade.

    That is one person’s estimate, not a scientific measurement or a consensus forecast. But it is not coming from a stranger on the street wearing an “END IS NIGH” sandwich board. It is coming from inside the industry.

    So: how scared should we be?

    The honest answer is neither not at all nor we are all doomed.

    We should be scared enough to pay attention.

    Why This Looks Different From Where I Sit

    Cisco AI Defense webpage describing comprehensive security for enterprises building and using artificial intelligence.
    My work with Cisco AI Defense puts me inside the challenge of securing the models, applications, data and infrastructure that make up an AI system.

    I have spent much of my professional life thinking about what happens when technology, people and risk collide.

    I have worked in cybersecurity for decades, including serving as a CISO. Today, my work with Cisco AI Defense puts me deep inside the security problems created when organizations connect increasingly capable AI systems to their data, applications and infrastructure.

    That experience changes how I read stories about AI risk.

    My first question is not whether a machine has become conscious, malevolent or secretly ambitious. It is usually much less cinematic:

    • What access was it given?
    • What objective was it pursuing?
    • How was that objective bounded?
    • What assumptions did the people deploying it make?
    • What happened when one control failed?
    • Was anyone actually watching what the system did next?

    Cybersecurity has taught us repeatedly that catastrophic outcomes rarely require a single, all-powerful adversary. They emerge from combinations: excessive permissions, misunderstood dependencies, poor configuration, weak monitoring, competitive pressure and humans assuming that someone else has accounted for the risk.

    AI does not replace those familiar problems.

    It adds speed, scale, autonomy and unpredictability to them.

    That is the lens through which I approach this subject professionally – and the same lens that shapes the world of Cryptogeddon.

    The Future Is Leaking Into the Present

    AI 2027 website presenting a scenario about superhuman AI, autonomous agents and rapidly accelerating capabilities.
    AI 2027 turns abstract concerns about automated AI research and recursive improvement into a detailed – and increasingly uncomfortable – scenario.

    The most dramatic concern is recursive self-improvement: AI systems helping to design, train or improve their successors, thereby accelerating AI research itself.

    The fear is not simply that the next model will be better. It is that AI development could become a feedback loop moving faster than human institutions can understand, govern or interrupt.

    That remains a forecast, not an accomplished fact. No frontier laboratory claims to have created a fully autonomous system that can improve itself indefinitely. The timeline is uncertain, and confident predictions about artificial general intelligence have a long history of being wrong.

    But uncertainty cuts in both directions.

    It does not mean the danger is imaginary. It means we do not know how much time we have – or how reliable our controls will be when capabilities change.

    The authors of AI 2027 tried to make that abstract concern concrete. Their scenario imagines AI research becoming increasingly automated, competition intensifying and oversight failing to keep pace.

    It is not prophecy, and its authors explicitly say it depicts only one possible future. Its value is that it forces us to examine the chain of events rather than arguing vaguely about whether “superintelligence” will be good or bad.

    Parts of that imagined chain no longer feel very distant.

    AI Has Already Crossed Boundaries

    Anthropic Research webpage showing its alignment, interpretability, frontier red-team and AI-safety research areas.
    Anthropic’s research spans alignment, interpretability, societal impacts and frontier testing—including its investigation of Claude models gaining unauthorized access to real systems.

    In September, Anthropic published an assessment of four cybersecurity incidents involving different Claude models.

    During controlled security evaluations, the systems were supposed to attack fictional targets. A configuration error left them connected to the real internet. The models then gained unauthorized access to real third-party systems.

    These were not malicious AIs pursuing some independent plan for world domination.

    Anthropic found no evidence that agents coordinated with one another, developed goals beyond their assigned task or tried to evade oversight. The systems were pursuing the objectives humans had given them in an environment whose safeguards had failed.

    That is an important distinction.

    It is also not especially comforting.

    Anthropic concluded that the models displayed biased reasoning and recklessness: they interpreted ambiguous evidence in ways that justified continuing their task, even when their actions could cause real harm. In one case, the same flawed reasoning also persuaded a monitoring system that the activity was simulated.

    This is the version of AI risk that concerns me most – not a machine suddenly becoming evil, but a powerful system pursuing a poorly bounded objective with speed, persistence and access that humans cannot match.

    From a security perspective, the incident has a painfully familiar shape:

    1. A test environment was incorrectly configured.
    2. A powerful tool received access it was not supposed to have.
    3. The scope of the exercise was insufficiently constrained.
    4. The system continued pursuing its assigned objective.
    5. Monitoring did not reliably recognize the resulting harm.

    Any one of those conditions might have been manageable. Together, they allowed a controlled exercise to reach real systems.

    Now add an agent that can operate for hours, write code, discover vulnerabilities and rationalize why it should continue.

    No sentience is required.

    One Agent Is a Problem. What About Forty-Five?

    Dozens of coordinated AI agents examine multiple software systems and share their findings through a central network.
    AI agents can already operate in parallel, coordinate their work and search continuously for vulnerabilities.

    Anthropic has also been studying emerging multi-agent systems.

    In one experiment, researchers gave 45 agents their own virtual machines and a shared forum, then asked them to collaborate on finding vulnerabilities in open-source software. The swarm found hundreds of vulnerabilities over an extended run.

    That can be enormously useful.

    Defenders could use the same capability to find and repair weaknesses before criminals exploit them. AI can help security teams examine more code, investigate alerts faster and find relationships that would otherwise be missed.

    Attackers can use it too.

    The significance is not that AI has spontaneously formed a mob. It is that humans can now assemble persistent, coordinated groups of machine agents at a scale and speed that were previously impractical. Once deployed, those systems may also behave in ways their operators did not anticipate.

    Cybersecurity has always been asymmetric: a defender must protect everything, while an attacker needs one opening. AI may magnify that imbalance by making reconnaissance, vulnerability discovery, exploitation and adaptation cheaper and faster.

    And the capability is reaching below the software layer.

    Anthropic recently reported that an AI system improved known attacks against experimental cryptographic algorithms. The work did not break the encryption protecting today’s banking or email, and it should not be presented as if it did.

    But one result improved an attack against a post-quantum signature candidate that had already survived two years of expert review. Another accelerated an attack against a deliberately reduced version of AES.

    This is legitimate, valuable research. Finding weaknesses is how cryptography becomes stronger.

    It is also a demonstration that increasingly autonomous AI can contribute to highly specialized offensive research once reserved for expert humans.

    Capability does not care which side uses it.

    The Problem Is Not Just the Model

    An AI cybersecurity test environment connects through a misconfigured boundary to external computer systems.
    The system did not escape from a perfect enclosure. The enclosure was never as isolated as people assumed.

    One of the recurring mistakes in conversations about AI safety is treating the model as though it exists in isolation.

    An AI system becomes much more consequential when it is connected to tools, proprietary data, source-code repositories, cloud infrastructure, identity systems and other agents. Its risk depends not only on what the model knows, but on what the surrounding system allows it to do.

    This is where AI security becomes an architectural problem.

    Organizations need to understand which models are being used, what data reaches them, which tools they can invoke, how their behaviour is monitored and what happens when they act outside the expected path. Traditional controls still matter, but they must be adapted to systems that reason, generate and act.

    That is also why AI safety cannot be reduced to teaching a model to refuse a dangerous question. A refusal is one control. It is not a security architecture.

    The more agency we give these systems, the more we need defence in depth: constrained permissions, isolation, testing, monitoring, human approval for consequential actions and the ability to stop behaviour that was not anticipated.

    The challenge is that capability is moving quickly while the practices for securing it are still being built.

    The People Building It Want the Ability to Slow Down

    In July, more than 1,300 employees of frontier AI companies signed Pacing the Frontier, calling for international mechanisms that could deliberately slow automated AI development if the risks demanded it.

    The signatories include senior figures from OpenAI, Anthropic, Google DeepMind, Meta and other leading laboratories.

    Their argument identifies a brutal incentive problem.

    A laboratory may believe that slowing down is prudent while also believing that it cannot afford to let a competitor – or another country – move ahead. Everyone can recognize the danger and still keep racing toward it.

    This is why voluntary promises are not enough. It is also why simple calls to “stop AI” are unlikely to work. The technology offers too much economic, scientific and military advantage.

    The question is whether governments and companies can build credible evaluation, monitoring, containment and coordination mechanisms before a crisis forces them to improvise.

    The International AI Safety Report 2026 gives this concern broader weight. Led by Yoshua Bengio and written by more than 100 experts with an advisory panel nominated by over 30 countries and international organizations, it reviews malicious use, technical failures and systemic risks.

    Its conclusion is not that catastrophe is certain. It is that capabilities are advancing quickly, real-world evidence of harm is accumulating and important safeguards remain unproven against sophisticated attacks.

    That is the sober version of the warning.

    We do not need to accept the most apocalyptic scenario to agree that the safety margin is thin.

    So, Will AI Kill Everyone?

    Screenshot of the WIRED article “Why So Many AI Researchers Think the Machines Could Kill Everyone,” illustrated with machines from Terminator 3.
    WIRED examines why recursive self-improvement, agentic swarms and recent security incidents are alarming researchers inside leading AI labs.

    Probably the wrong question.

    It encourages us to choose between ridicule and panic. If extinction is not imminent, we tell ourselves everything is fine. If it is possible, we jump directly to Terminator imagery and lose sight of the practical decisions in front of us.

    There is an enormous spectrum of harm between a hallucinated answer and the end of humanity.

    AI can amplify fraud and disinformation. It can discover and exploit vulnerabilities. It can lower the expertise required to conduct sophisticated attacks. It can make consequential decisions at machine speed. It can behave recklessly when instructions, incentives and safeguards do not align. It can concentrate power in a small number of companies and governments.

    None of that requires consciousness, hatred or a secret desire to replace us.

    The existential question still matters. A low-probability event that ends civilization deserves attention even if nobody can assign it a trustworthy percentage.

    But the strongest reason to take AI safety seriously is not that we know the machines will kill us.

    It is that we are building systems with growing autonomy, imperfectly understood behaviour and access to real infrastructure – and placing them inside a global race whose participants believe they cannot afford to pause.

    That is frightening enough.

    And Yes, It Is Excellent Material

    A left-handed writer develops a fictional cyber scenario beside monitors displaying AI security architecture and threats.
    My professional work asks how these systems can be secured. The novelist in me asks what happens when all the controls fail at once.

    As someone who has spent decades in cybersecurity, I find these developments alarming. My current work in AI security makes them impossible to dismiss as somebody else’s distant problem.

    As the author of Cryptogeddon, I also cannot look away.

    Near-future fiction lives in the narrow space between what exists and what might plausibly happen next. That space is shrinking. Ideas I once would have used to make the novel feel speculative now appear in research papers and incident reports before I can finish writing them.

    My professional work helps me see how the pieces fit together: not only what a new AI system can do in a demonstration, but what might happen when it meets real networks, imperfect controls, organizational pressure and human fallibility.

    Then the novelist in me asks the next question:

    What happens when all of those things fail at once?

    There is a strange bargain in that. The world keeps making the subject more urgent while making the fiction harder to outrun.

    I wish some of this material were less plausible.

    But I would be lying if I said it did not make me want to write faster.

    Sources and Further Reading

  • Where AI Fits Into My Writing Process – and Where It Doesn’t

    Where AI Fits Into My Writing Process – and Where It Doesn’t

    I use AI in almost everything I write. That does not mean AI does the writing.

    A writer works by hand at a desk while digital research, historical sources, maps and cybersecurity diagrams surround him.
    AI can surround the writing process without becoming the writer.

    I use artificial intelligence in almost everything I write – but probably not in the way people assume.

    That sentence requires some explanation, because “I use AI” has become almost meaningless.

    It can mean asking a search engine for help finding a source. It can mean using a chatbot to challenge an argument or organize research. It can also mean entering a prompt, receiving several thousand words and publishing them under your own name.

    Those are not the same thing.

    So, before I describe my process, I want to draw the most important line clearly:

    AI does not write my books. Every word in my manuscripts is my own.

    I use AI while researching Cryptogeddon, Holy Wars and other projects. I use it to explore technologies, interrogate ideas, identify gaps in my knowledge and find sources worth reading. But when it is time to write the book, I write it.

    My blog workflow is somewhat more flexible. A weekly article has a different purpose, lifespan and production cycle than a novel. AI may help me organize the argument, test structures, identify repetition or refine a difficult passage. Even there, however, I am not asking it to invent a subject and then publishing whatever comes back.

    AI participates in the process. It does not own the work.

    Here is what that actually looks like.

    The Process Begins Before AI

    My writing rarely begins with a prompt.

    It begins with something that catches my attention: a book, a news story, an historical question, a development in cybersecurity, an experience at the gaming table or an idea that refuses to leave me alone.

    I capture those thoughts in Apple Notes. Some are only a sentence. Others grow into collections of links, quotations, questions and fragments. Most never become finished pieces at all.

    Before I involve AI, I try to know at least three things:

    1. What am I curious about?
    2. Why does it matter to me?
    3. What question am I trying to answer?

    Those decisions need to come from me. Otherwise, I am not using AI to develop an idea. I am asking it to supply one.

    That may produce content. It is unlikely to produce anything only I could have written.

    Stage One: Mapping the Territory

    Once I have a subject, I often use AI to help me understand its shape.

    Suppose I am researching a technology for Cryptogeddon. I may begin with broad questions:

    • How does this system work?
    • What would have to go wrong for it to fail?
    • Who controls it?
    • What assumptions does it depend upon?
    • How might an attacker abuse it?
    • What secondary consequences am I overlooking?
    • What terminology should I understand before researching further?

    The purpose is not to collect prose for the manuscript. It is to improve my mental model of the subject.

    AI is particularly good at revealing the structure of an unfamiliar field. It can identify major concepts, show how they relate and suggest questions I would not have known to ask. That makes it a useful starting point.

    But a starting point is not a source.

    A writer examines an interconnected wall of historical documents, maps, cybersecurity systems and research questions.
    AI helps me map unfamiliar territory, identify connections and discover better questions.

    Stage Two: Moving From Answers to Sources

    Language models are dangerously good at sounding authoritative.

    They can present established fact, reasonable inference and complete invention in exactly the same confident tone. A polished answer can be helpful, but fluency is not evidence.

    My research loop therefore looks like this:

    1. Ask AI to help map the subject.
    2. Identify the claims that matter.
    3. Find the original or most authoritative sources.
    4. Read those sources myself.
    5. Compare competing interpretations.
    6. Ask better follow-up questions.
    7. Keep only what the evidence supports.

    For technology and cybersecurity, that may mean technical documentation, research papers, incident reports or reporting from sources I trust. For Holy Wars, it may mean historical scholarship, primary accounts and competing interpretations of the same event.

    The AI conversation helps me navigate. The sources determine what I can responsibly claim.

    My rule is simple:

    AI can help me discover a claim. It cannot be the authority for that claim.

    Stage Three: Using AI to Create Friction

    The most valuable thing AI gives me is not an answer. It is resistance.

    Once I have developed an idea, I can ask the machine to attack it:

    • What is the strongest objection?
    • Which assumption is doing too much work?
    • What evidence would weaken my conclusion?
    • Am I confusing correlation with causation?
    • Which stakeholder am I ignoring?
    • Is this genuinely plausible, or merely convenient for the story?
    • What would an informed critic say?

    This is especially useful because writers become attached to their own ideas. After enough time with an argument or story, it becomes difficult to see what we have assumed rather than established.

    AI does not eliminate that problem, and its criticism is not automatically correct. But it can create enough distance for me to reconsider something I had begun treating as settled.

    Sometimes I reject its objection. Sometimes I return to the research. Occasionally, it exposes a weakness that changes the direction of the work.

    The decision remains mine, but it is a better-tested decision.

    Stage Four: The Process Splits

    This is where my book and blog workflows become different.

    For books

    Research, questions, timelines and technical explorations may all involve AI. The manuscript does not.

    When I move from research into scenes, narration, dialogue and chapters, I write the words myself. That boundary is deliberate.

    A novel is more than an efficient delivery system for a plot. Its language carries the author’s sensibility: what receives attention, what remains unsaid, how a character is judged, where a sentence accelerates and where it pauses. Those decisions accumulate into voice.

    I do not want to outsource that discovery.

    I may later use tools to help locate inconsistencies or interrogate whether some technical element is believable. But I do not ask AI to generate chapters for me, rewrite my prose in bulk or manufacture a voice I can claim as my own.

    Every sentence in the book has to pass through my mind and my hands.

    For blog posts

    A weekly blog operates on a shorter cycle. I am often responding to something timely, developing an argument in public or sharing work in progress.

    Here I may use AI more directly as an editorial tool. Depending on the article, I might ask it to:

    • compare two possible outlines;
    • suggest a clearer order for ideas I have already assembled;
    • identify repetition;
    • flag an unsupported leap;
    • show where a reader might misunderstand me;
    • test alternative headlines;
    • or help tighten a passage that is not working.

    That is closer to an extended editorial conversation than manuscript generation.

    The topic, underlying argument, personal perspective and final judgment still have to be mine. I decide what the article says. I decide which suggestions are useful. And I remain responsible for every sentence published under my name.

    The distinction is not that books are sacred while blogs do not matter. It is that the tools are allowed closer to the prose in one workflow than in the other – and even there, they remain tools.

    Stage Five: Knowing When AI Is Making the Work Worse

    AI has a gravitational pull toward competent blandness.

    It likes orderly explanations, symmetrical lists and conclusions that neatly restate whatever came before. It can turn an awkward but interesting thought into a polished paragraph that sounds like it could have been written by anyone.

    That is useful when clarity is the problem. It is destructive when the awkwardness contains the writer’s voice.

    There are warning signs that AI is getting in the way:

    • the writing becomes smoother but less specific;
    • every argument acquires an artificial balance;
    • uncertainty is replaced with a tidy lesson;
    • the same phrases and rhythms begin appearing repeatedly;
    • the prose explains things the reader already understands;
    • or the article sounds finished before I have decided what I think.

    That last danger may be the most serious.

    Writing is partly how I discover what I believe. If I accept a polished formulation before doing the underlying thinking, I may end up with something coherent that is not actually mine.

    The struggle to articulate an idea is not wasted motion. Often, it is where the insight comes from.

    Stage Six: The Final Human Pass

    Before anything is published, I want to be able to answer several questions:

    • Is this accurate?
    • Do I believe it?
    • Does it sound like me?
    • Is there something specific here, or only a competent summary?
    • Have I distinguished fact from inference?
    • Am I saying anything I would be unwilling to defend?
    • Does every sentence earn the right to carry my name?

    AI cannot answer those questions for me because they are not simply questions about text quality.

    They are questions about authorship.

    The final decision to publish is not a mechanical checkpoint at the end of the pipeline. It is the point at which I accept responsibility for the work.

    What AI Is – and Is Not – in My Writing

    If I reduce the process to its simplest form, AI plays four useful roles:

    1. Research guide – helping me map unfamiliar territory and locate questions worth pursuing.
    2. Sceptical reader – testing assumptions, arguments and plausibility.
    3. Organizational tool – helping me compare structures and manage complicated material.
    4. Editorial assistant – identifying repetition, ambiguity and weak transitions, particularly in shorter work.

    What it is not is the novelist.

    It does not create the pages of Cryptogeddon. It does not choose the language of Holy Wars. It does not decide what my characters fear, what they value or what their choices mean. It does not turn personal experience into something I can falsely claim to have written.

    AI can help me arrive at the blank page better informed, more thoroughly challenged and with a clearer sense of what I am trying to accomplish.

    Then I have to write.

    When the Research Starts Resembling the Fiction

    A thriller writer looks from sketches of AI systems and autonomous networks toward a city where similar technologies are becoming real.
    For a near-future writer, the distance between research and fiction is getting uncomfortably small.

    Lately, AI has begun playing one more role in my writing process: subject matter.

    There is an old expression that reality is stranger than fiction. For someone writing a near-future cyberthriller, that is becoming less an observation than a weekly professional hazard.

    I imagine autonomous systems, coordinated cyberattacks and institutions struggling to control technologies they barely understand. Then I return to the research and discover events uncomfortably close to what I had imagined.

    It is getting harder to invent an AI future that does not begin arriving before I finish the draft.

    That is unsettling.

    It is also irresistible material.

    Next week, in The Cryptogeddon Briefing, I am going to look at some of those recent developments – and ask a question that no longer sounds quite as melodramatic as it once did:

    How scary is AI getting?

  • Skynet Has Arrived

    Skynet Has Arrived

    Drones, signals, surveillance – and what happens when we can no longer trust the encryption holding the modern world together.

    Skynet Has Arrived:
Drones. Signals. Surveillance. Encryption.
    Skynet Has Arrived:
    Drones. Signals. Surveillance. Encryption.

    There is a scene in Terminator 2: Judgment Day where Arnold Schwarzenegger’s T-800 explains how Skynet becomes self-aware and, almost immediately, turns humanity’s own military infrastructure against it.

    A defence network becomes intelligent. The machines take control. Humanity suddenly finds itself hunted by technology it created.

    Great science fiction.

    Except I’m beginning to wonder if we got one part wrong.

    Maybe Skynet doesn’t arrive as a single malevolent artificial intelligence.

    Maybe it arrives piece by piece.

    A drone here.

    A satellite there.

    A cellular network.

    A camera.

    A radio receiver.

    A location database.

    An artificial-intelligence system capable of analyzing all of them.

    And somewhere in the middle, cryptography – the thin mathematical layer preventing enormous portions of that infrastructure from being intercepted, impersonated or manipulated.

    That is much closer to the technological world I’m building in Cryptogeddon.

    And increasingly, I don’t have to invent very much of it.

    Because this post is so long, I thought a table of contents might be helpful:

    The Drone Will See You Now

    An improvised Ukrainian FPV strike drone. Small, inexpensive first-person-view drones have transformed modern warfare by combining commercial-grade components, real-time video and explosive payloads.
Photo: АрміяInform / Ministry of Defence of Ukraine, via Wikimedia Commons. CC BY 4.0.
    An improvised Ukrainian FPV strike drone. Small, inexpensive first-person-view drones have transformed modern warfare by combining commercial-grade components, real-time video and explosive payloads.
    Photo: АрміяInform / Ministry of Defence of Ukraine, via Wikimedia Commons. CC BY 4.0.

    On August 6, 2026 – literally as I was working on this post – Reuters published a report from Zaporizhzhia, Ukraine describing what residents have begun calling “safari” attacks.

    Small first-person-view drones are being used to attack individual people and vehicles.

    Not military formations.

    Individuals.

    Residents described living with drones capable of appearing overhead and pursuing people through streets and neighbourhoods. Ukrainian officials say the attacks are intended in part to terrorize the civilian population.

    Think about how extraordinary that sentence would have sounded twenty years ago.

    Today it barely qualifies as science fiction.

    Two days earlier, Russia formally demonstrated just how central this technology has become by appointing a commander to its newly created Unmanned Systems Forces – effectively creating a military branch dedicated to drone warfare.

    Ukraine and Russia have already produced and deployed drones on an enormous scale. Cheap FPV aircraft costing a tiny fraction of the vehicles and infrastructure they can destroy have fundamentally altered battlefield economics.

    A camera.

    A radio.

    Some electronics.

    Explosives.

    And an operator.

    That alone is frightening.

    But now remove the operator from the last few seconds of the equation.

    Electronic warfare has made conventional drone control increasingly difficult because radio links can be detected and jammed. The response has been exactly what you would expect from an arms race.

    The drones are adapting.

    Ukraine has been deploying AI-assisted targeting systems that use onboard cameras to recognize and track targets. Reuters reported in 2025 that some systems can continue toward a target after communications with the pilot are disrupted. Ukrainian officials said human authorization was still required before the strike, an important distinction – but once committed, the machine can increasingly handle portions of the terminal journey itself.

    Other drones have eliminated the radio problem altogether.

    Russia is now using FPV drones controlled through kilometres of extremely thin fibre-optic cable. Because the control signal travels through a physical wire rather than radio, conventional electronic jammers cannot simply disrupt the connection. Reuters documented Russian fibre-controlled drones being used in 2026 against Ukrainian electrical substations, including attacks against multimillion-dollar transformers. Some of the drones cost roughly $2,000.

    A $2,000 aircraft can now threaten infrastructure worth millions.

    No satellite.

    No fighter jet.

    No exotic weapons platform.

    No billion-dollar defence contractor required.

    That may be one of the most important themes emerging in Cryptogeddon:

    The barrier to entry for sophisticated technological warfare is collapsing.

    Before We Had Drones, We Had Wires

    There is another reason this should make us uncomfortable.

    We’ve already experimented with what happens when governments gain access to enormous amounts of communications data.

    It did not begin with drones or AI.

    It began with telephone lines and Internet cables.

    After the September 11 attacks, the United States dramatically expanded electronic surveillance programs. One of the most controversial was the NSA’s bulk telephone-records program under Section 215 of the USA PATRIOT Act.

    The database did not contain recordings of everyone’s telephone conversations.

    It contained something potentially almost as interesting:

    metadata.

    Who called whom.

    When.

    For how long.

    Patterns.

    Connections.

    Networks of relationships.

    The U.S. Privacy and Civil Liberties Oversight Board ultimately concluded that the bulk program lacked a viable legal foundation under Section 215, raised serious constitutional and privacy concerns, and demonstrated only limited value. The program was subsequently ended in that form.

    Meanwhile, Internet communications presented an even larger opportunity.

    NSA surveillance under Section 702 includes what is known as upstream collection.

    The government’s own Privacy and Civil Liberties Oversight Board describes upstream collection as occurring at portions of the telecommunications backbone itself – long-distance fibre connections, network exchange points and other places through which enormous volumes of Internet traffic transit.

    Traffic is screened for communications associated with approved foreign-intelligence selectors before qualifying communications are collected.

    There is an important distinction here: Section 702 is a legally authorized foreign-intelligence program with oversight mechanisms, not simply a machine indiscriminately storing the entire Internet.

    But technologically, consider what had happened.

    We had learned how to place surveillance at the arteries of the Internet.

    AT&T technician Mark Klein made that concept disturbingly tangible when he disclosed the existence of the infamous Room 641A in an AT&T facility in San Francisco. Documents he provided to the Electronic Frontier Foundation described optical splitters capable of duplicating telecommunications traffic and feeding copies toward equipment associated with NSA surveillance.

    The architecture of surveillance was relatively straightforward.

    Find the place through which enormous amounts of information pass.

    Put your collection system there.

    Listen.

    That model worked remarkably well when communications flowed through centralized infrastructure.

    But then the world changed.

    The wires disappeared.

    Surveillance Escaped Into the Air

    The wires disappeared. Surveillance escaped into the air.

    Today our devices communicate constantly.

    Cellular.

    Wi-Fi.

    Bluetooth.

    GPS.

    Satellite.

    Radio.

    Vehicle systems.

    Drones.

    Wearables.

    Industrial telemetry.

    The communications infrastructure that once passed primarily through identifiable wires and switching facilities has expanded into an electromagnetic environment surrounding us almost everywhere.

    That creates an entirely new category of intelligence.

    Consider your phone.

    Law-enforcement agencies have used devices commonly known as Stingrays, or cell-site simulators, which behave like cellular infrastructure and cause nearby phones to identify themselves.

    The U.S. Department of Justice eventually adopted a policy generally requiring federal investigators to obtain warrants before using them.

    Canada uses the technology too.

    An investigation by the Office of the Privacy Commissioner of Canada confirmed that the RCMP used cell-site simulators capable of collecting identifiers such as IMSI and IMEI numbers. The RCMP told the commissioner that its systems were not configured to intercept the contents of calls, emails or text messages.

    Again:

    you don’t necessarily need the message.

    Sometimes knowing that a device exists somewhere is enough.

    Knowing that it was there yesterday is better.

    Knowing that another device was repeatedly nearby becomes interesting.

    Knowing where both devices travel afterward becomes intelligence.

    And governments are no longer the only organizations capable of collecting this kind of information.

    Your Location Became a Commodity

    The commercial advertising ecosystem created an enormous location-surveillance infrastructure almost accidentally.

    Apps collect information.

    Advertising networks exchange information.

    Data brokers aggregate information.

    And eventually someone realizes that the dots on the screen correspond to actual human beings.

    In 2024, the U.S. Federal Trade Commission alleged that a company called Mobilewalla had collected more than 500 million unique advertising identifiers paired with precise location information between 2018 and 2020.

    The FTC said the company collected some of this information through real-time advertising auctions – even when it did not win the advertisement.

    The agency also alleged that Mobilewalla used location information associated with people attending protests following the killing of George Floyd to produce an analysis of protesters, including demographic information and whether they lived in the cities where they demonstrated.

    Think about that for a moment.

    Advertising technology became protest-surveillance technology.

    Another FTC case involved Gravy Analytics and Venntel. The FTC alleged that location information could reveal visits to healthcare facilities, religious institutions and other sensitive locations. The companies had claimed to process more than 17 billion signals from approximately one billion mobile devices every day.

    Seventeen billion.

    Every day.

    This isn’t someone following you around in a trench coat.

    It is industrialized observation.

    And that happened before we added today’s generation of AI systems to the equation.

    Now Look Up

    Perhaps the most astonishing example I found while researching Cryptogeddon came from researchers at the University of California San Diego and the University of Maryland.

    They pointed a commercially available satellite dish at the sky.

    Their equipment cost about $800.

    Then they listened.

    NASA Deep Space Network radio antenna DSS-53 illuminated at night at the Madrid Deep Space Communications Complex.

Radio signals from satellites physically arrive at Earth, where antennas can receive them. In 2025, researchers demonstrated that sensitive satellite communications could be intercepted with commercially available equipment costing roughly $800.

Photo: NASA/JPL-Caltech.
    NASA Deep Space Network radio antenna DSS-53 illuminated at night at the Madrid Deep Space Communications Complex.

    Radio signals from satellites physically arrive at Earth, where antennas can receive them. In 2025, researchers demonstrated that sensitive satellite communications could be intercepted with commercially available equipment costing roughly $800.

    Photo: NASA/JPL-Caltech.

    What they discovered should terrify anyone who assumes important communications are automatically encrypted.

    Their 2025 research found large amounts of sensitive information travelling over geostationary satellite links without encryption.

    They observed cellular traffic.

    Voice calls.

    SMS messages.

    IMSI identifiers.

    Corporate communications.

    Government communications.

    Military-related information.

    Airline Internet traffic.

    Utility information.

    Oil-and-gas infrastructure traffic.

    Even communications associated with industrial control systems.

    The researchers emphasized that their monitoring was completely passive. They did not have to compromise the satellites or transmit anything.

    They simply listened to signals that were already being broadcast toward Earth.

    University of Maryland researchers described using the roughly $800 setup to examine 38 satellites covering an enormous geographical area.

    The research team concluded that a surprisingly large amount of sensitive satellite traffic remained exposed.

    Some affected organizations subsequently encrypted their communications.

    That is an encouraging response.

    The disturbing question is obvious:

    Who else had already been listening?

    Radio Has Always Betrayed Us

    Militaries have understood this problem for more than a century.

    You don’t have to break a radio transmission’s encryption to learn that a radio is transmitting.

    Direction-finding equipment can locate transmitters.

    Signal strength changes.

    Patterns emerge.

    Units move.

    Networks appear.

    The U.S. military was using radio direction finding to locate enemy transmitters as early as World War I and extensively during Vietnam.

    The principle hasn’t changed very much.

    The equipment has.

    During the war in Ukraine, poorly secured Russian communications created intelligence opportunities almost immediately. RUSI researchers documented reports of Russian forces relying on unencrypted radios and ordinary mobile phones. Such transmissions can potentially allow an opponent not merely to listen but to determine where transmitters are located.

    Smartphones are particularly dangerous on a battlefield because they combine communications with location information, cameras and Internet connectivity.

    In 2024, Russia moved toward punishing soldiers for carrying smartphones in combat zones specifically because phones could expose positions. Reuters reported that both sides had used mobile devices and their associated signals, photographs and messages to help identify targets.

    The lesson is brutally simple:

    transmitting can reveal you.

    And once something can be located, something else can be sent to it.

    Possibly a drone.

    The Battle Over Communication

    That brings us to another important part of Cryptogeddon.

    Communication doesn’t merely need to be intercepted.

    It can be denied.

    Modern warfare increasingly includes attempts to jam radio communications, interfere with drone-control links and disrupt satellite navigation.

    A drone may still be physically intact yet become useless because it can no longer communicate with its pilot.

    A military unit can possess weapons and ammunition and still become ineffective if its command network disappears.

    A satellite can remain perfectly healthy while users on the ground suddenly lose access to the network.

    That last scenario has already happened.

    Approximately one hour before Russia invaded Ukraine on February 24, 2022, a cyberattack struck Viasat’s KA-SAT satellite network.

    The European Union formally attributed the attack to Russia and said it caused communications disruptions affecting Ukrainian authorities, businesses and users as well as users elsewhere in Europe.

    The shooting hadn’t even properly started yet.

    The communications war had.

    And the response to this vulnerability is creating another technological arms race.

    Modern systems can switch frequencies.

    They can use multiple communications paths.

    Military networks can fall back between satellite, terrestrial radio and other systems.

    Drones can use onboard navigation when satellite positioning becomes unreliable.

    AI-assisted systems can continue portions of missions after control links disappear.

    Some drones now use fibre.

    Modern militaries are reconsidering older HF radio systems precisely because satellite communications may not always be available in a major conflict. A June 2026 U.S. Army paper explicitly described modern battlefields in which satellite communications may be jammed or denied.

    The objective increasingly becomes not simply secure communications.

    It becomes resilient communications.

    Assume something will be intercepted.

    Assume something will be jammed.

    Assume GPS may disappear.

    Assume networks will fail.

    Then build systems capable of surviving anyway.

    And Then AI Starts Listening

    This is the piece that changes everything.

    Signals intelligence isn’t new.

    Surveillance isn’t new.

    Drones aren’t new.

    Location tracking isn’t new.

    Satellite interception isn’t new.

    What is new is our rapidly improving ability to combine enormous quantities of information automatically.

    Imagine thousands of sensors listening simultaneously.

    Most of what they collect is useless.

    Cars.

    Air conditioners.

    Commercial radio.

    Bluetooth devices.

    Cell phones.

    Aircraft.

    Drones.

    Electrical equipment.

    Random interference.

    A human analyst would drown in it.

    AI doesn’t have to.

    Machine-learning systems can classify radio signals and identify patterns across spectrum data. Researchers have demonstrated deep-learning systems capable of automatically distinguishing radio signal types, and DARPA has spent years developing machine-learning technologies capable of managing and interpreting crowded electromagnetic spectrum environments.

    Ukraine offers an even more tangible example.

    Its distributed acoustic drone-detection networks use large numbers of inexpensive sensors to listen for incoming drones. NATO research published in 2026 described systems using AI to distinguish drone sounds from ordinary background noise.

    Some implementations even leverage commercial technology such as smartphones as processing components.

    Think about the architecture.

    Thousands of cheap sensors.

    A communications network.

    Artificial intelligence.

    A map.

    Now replace microphones with radio receivers.

    Add cellular information.

    Add cameras.

    Add satellites.

    Add drones.

    Add commercial location databases.

    Add compromised computer networks.

    Add historical information.

    Suddenly you’re no longer collecting signals.

    You’re constructing reality.

    This Is Where Cryptogeddon Begins

    Cryptography is the trust layer holding modern civilization together. Banking, communications, government, military systems, transportation and critical infrastructure all depend on it. What happens when that trust can no longer be trusted? That is where Cryptogeddon begins.
    Cryptography is the trust layer holding modern civilization together. Banking, communications, government, military systems, transportation and critical infrastructure all depend on it. What happens when that trust can no longer be trusted? That is where Cryptogeddon begins.

    And sitting underneath almost all of this is cryptography.

    Encryption protects our messages.

    Cryptographic signatures verify software.

    Certificates establish trust between systems.

    Authentication protects networks.

    Encryption protects financial transactions.

    VPNs protect remote communications.

    Cryptography protects military command systems.

    Cryptography protects governments.

    Cryptography protects the Internet.

    Which raises the question at the heart of the series I’m writing:

    What happens when we stop being able to trust it?

    That doesn’t necessarily require someone discovering a magical equation capable of instantly breaking AES.

    History shows that cryptographic systems can fail in far messier ways.

    In 2011, the Dutch certificate authority DigiNotar was compromised. Attackers generated fraudulent certificates for major services including Google. European cybersecurity agency ENISA reported that fraudulent certificates were subsequently used to eavesdrop on users in Iran.

    The encryption wasn’t necessarily mathematically defeated.

    The trust mechanism surrounding it was compromised.

    That’s an important distinction.

    Sometimes you don’t break the lock.

    You steal the key.

    Sometimes you convince everyone that your key is legitimate.

    Sometimes you compromise the machine before encryption occurs.

    Sometimes you compromise it after decryption.

    Sometimes you simply jam the communication so nobody can talk at all.

    And sometimes – as those satellite researchers discovered – the people operating the system inexplicably forgot to lock the door in the first place.

    There is another problem approaching.

    Quantum computing.

    We do not currently have quantum computers capable of casually breaking the cryptographic systems protecting the Internet.

    But the threat is considered serious enough that the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptographic standards in 2024 and urged organizations to begin migrating.

    NIST specifically warns about “harvest now, decrypt later.”

    An adversary does not need to decrypt sensitive information today.

    They can collect encrypted traffic today.

    Store it.

    And wait for the technology capable of breaking it tomorrow.

    That creates a deeply uncomfortable thought.

    Some secrets being transmitted right now may already be compromised.

    We just don’t know it yet.

    The Democratization of Intelligence

    There is one final development that I think may prove as important as any of the others.

    This technology is becoming cheap.

    Historically, serious surveillance required governments.

    Satellites.

    Listening stations.

    Aircraft.

    Mainframes.

    Teams of analysts.

    Enormous budgets.

    Today a university research team can intercept satellite communications with equipment costing hundreds of dollars.

    Commercial drones cost hundreds or thousands.

    Software-defined radios place capabilities that once required specialized equipment within reach of hobbyists and researchers.

    Cloud computing provides enormous processing capacity on demand.

    Open-source software provides sophisticated analysis tools.

    AI systems can write code, recognize objects, transcribe speech, classify information and identify patterns.

    High-resolution satellite imagery is commercially available.

    Billions of location observations have been collected by advertising companies.

    And military drones capable of destroying vastly more expensive equipment can cost a few thousand dollars.

    This does not mean everyone suddenly possesses the NSA’s capabilities.

    They don’t.

    Nation-states still possess extraordinary advantages in sensors, access, scale and expertise.

    But the gap is narrowing.

    Capabilities are leaking downward.

    From superpowers.

    To militaries.

    To intelligence agencies.

    To corporations.

    To criminal organizations.

    To small groups.

    Eventually, to individuals.

    That may turn out to be one of the defining technological stories of our time.

    Skynet Doesn’t Need to Wake Up

    That’s what makes the world of Cryptogeddon frightening to me.

    I don’t need to invent a conscious artificial intelligence that suddenly decides humanity should die.

    I don’t need killer robots marching down city streets.

    I don’t need a supercomputer launching nuclear missiles.

    The infrastructure is already considerably more interesting than that.

    We have drones capable of hunting targets.

    We have machines capable of continuing toward those targets when communications disappear.

    We have systems designed to detect and locate radio transmitters.

    We have commercial databases containing extraordinary records of human movement.

    We have satellites broadcasting information across continents.

    We have governments capable of collecting communications from Internet infrastructure.

    We have inexpensive receivers capable of listening to signals falling from space.

    We have artificial intelligence increasingly capable of turning oceans of sensor data into useful information.

    And we have tied virtually every important component of civilization together with cryptography.

    Banking.

    Energy.

    Transportation.

    Military systems.

    Governments.

    Corporations.

    Communications.

    Identity.

    The Internet itself.

    Maybe Skynet doesn’t arrive when a machine becomes conscious.

    Maybe Skynet arrives when all of our machines become connected.

    And maybe Armageddon doesn’t begin when the machines decide to kill us.

    Maybe it begins when the cryptography connecting them can no longer be trusted.

    That’s Cryptogeddon.

    And increasingly, I’m not sure I’m writing science fiction.

  • The Quiet Miracles of AI

    The Quiet Miracles of AI

    The Quiet Miracles of AI

    “Technology is a useful servant but a dangerous master.”
    — Christian Lous Lange

    This week’s Cryptogeddon Briefing is a little different.

    Normally, this space is where I explore the technologies, cyber threats, geopolitical shifts, and emerging ideas that inspire my writing—and, ultimately, the world of Cryptogeddon. Most weeks, that means discussing artificial intelligence in the context of cybersecurity, autonomous systems, espionage, or the changing balance of power between nations.

    This week, though, I found myself thinking about AI from a very different perspective.

    The idea came after a conversation over dinner.

    The topic of artificial intelligence came up, and as it so often does these days, opinions around the table were mixed. Some people were optimistic. Others were skeptical. The concerns were familiar: AI-generated artwork replacing artists, copyright, deepfakes, misinformation, job displacement, and the growing uncertainty surrounding where this technology is taking us.

    They’re fair concerns.

    In fact, they’re concerns I share.

    Like every transformative technology before it, artificial intelligence will undoubtedly be used for both good and bad. It will create incredible opportunities while introducing entirely new risks. Pretending otherwise would be naïve.

    But as I listened to the discussion, I couldn’t help thinking about another side of AI—one that rarely dominates headlines or social media debates.

    It reminded me that while we spend enormous amounts of time asking what AI might take away from us, we spend surprisingly little time asking what it might give us.


    That thought brought me to my daughter.

    “The good physician treats the disease; the great physician treats the patient who has the disease.”
    — Sir William Osler

    She has cystic fibrosis.

    If you’ve never known someone with CF, it’s a genetic disease caused by mutations in the CFTR gene. Those mutations disrupt how salt and water move through cells, producing the thick mucus that damages the lungs and digestive system. For decades, treatment focused primarily on managing symptoms: daily physiotherapy, inhaled medications, repeated courses of antibiotics, and frequent hospital stays whenever infections became severe.

    When my daughter was born, there was hope—but there were also countless unanswered questions.

    Researchers had identified the genetic cause of the disease, but understanding exactly how hundreds—and eventually thousands—of different mutations affected the CFTR protein required years of painstaking laboratory research. Every discovery was earned through thousands of experiments, each one consuming time, funding, and the efforts of countless scientists.

    A realistic, documentary-style close-up photograph inside a biomedical research laboratory. Shallow depth of field. Gloved hands holding a pipette carefully dispensing liquid into petri dishes on a stainless steel lab bench. The background is softly blurred laboratory equipment and shelving. Natural, soft white lighting. No dramatic lighting, no glowing screens, no futuristic elements. Clean, subtle, professional, editorial medical photography. Landscape orientation.

    Drug development was no different.

    Researchers would identify promising compounds, synthesize them, test them in the laboratory, modify them, and begin the process again. Most candidates failed. The few that succeeded often required more than a decade of research and billions of dollars before they ever reached patients.

    Thankfully, that work paid off.

    Today, my daughter is nineteen years old. She lives what is, for all practical purposes, a normal life. She still has cystic fibrosis. She still follows a treatment regimen every day. But she’s healthy, active, independent, and planning her future just like any other young adult.

    That’s nothing short of extraordinary.

    And while AI didn’t create those first breakthrough therapies, it’s beginning to change how the next generation of discoveries will happen.


    Artificial intelligence doesn’t replace scientific curiosity—it amplifies it.

    This is where artificial intelligence becomes genuinely exciting—not because it’s generating artwork or writing marketing copy, but because it’s helping scientists ask better questions.

    Modern AI systems can analyze enormous biological datasets in hours rather than months. They can compare thousands of genetic mutations, identify patterns that would be nearly impossible for humans to detect unaided, and predict how specific mutations alter the shape and function of proteins. Instead of relying entirely on trial and error, researchers can now use AI to prioritize the most promising hypotheses before stepping into the laboratory.

    That doesn’t replace science.

    It makes science more efficient.

    One of the most exciting developments has been AI-assisted protein modelling. Understanding exactly how a mutation changes the three-dimensional shape of a protein—and how a potential drug might restore its function—once required years of painstaking structural biology. Today, AI systems such as AlphaFold can generate remarkably accurate structural predictions in hours, allowing researchers to focus precious laboratory time where it’s most likely to produce meaningful results.

    AI is also transforming medical imaging. Researchers are using machine learning to identify subtle changes in CT scans that may indicate disease progression earlier than conventional methods. They’re studying how bacterial populations evolve inside the lungs of people with cystic fibrosis, helping predict antibiotic resistance and personalize treatments. AI is helping researchers identify better candidates for clinical trials, reducing the time required to evaluate promising therapies.

    None of these breakthroughs eliminate the need for scientists.

    They eliminate wasted effort.

    Every experiment that doesn’t need to be performed because AI helped identify a dead end means researchers can spend more time pursuing ideas with genuine potential. Every month saved in research is another month that a promising therapy could reach the people waiting for it.

    And while cystic fibrosis is one example, the same technologies are now accelerating research into cancer, Alzheimer’s disease, rare genetic disorders, antibiotic discovery, and countless other medical challenges.

    That’s a much bigger story than AI-generated artwork.

    And yet, both conversations are about the same technology.


    Technology itself is remarkably neutral.

    Electricity powers hospitals.

    It also powers electric chairs.

    The Internet connects families across continents.

    It also spreads misinformation across them.

    Encryption protects political dissidents.

    It also protects organized crime.

    Artificial intelligence belongs in exactly the same category.

    The same machine learning algorithms helping researchers discover life-saving medicines can also help militaries identify targets faster, guide autonomous drones, improve missile accuracy, or analyze satellite imagery to track troop movements. Those very same technologies can also detect incoming missile attacks, improve battlefield medicine, assist humanitarian rescue operations, strengthen cyber defenses, and protect civilian infrastructure.

    The technology hasn’t changed.

    Only the objective has.

    That’s why I don’t think AI is inherently good or inherently bad.

    I think it’s something much simpler.

    It’s a multiplier.

    Put AI in the hands of a scammer and they’ll scam more people.

    Put it in the hands of a military and they’ll build more capable weapons—or more capable defenses.

    Put it in the hands of an artist and they’ll create in entirely new ways.

    Put it in the hands of a physician or researcher, and they’ll ask bigger questions, analyze more data, and discover answers faster than they could alone.

    AI doesn’t determine the outcome.

    People do.

    The tool simply multiplies whatever intentions we bring to it.


    “The future is already here—it’s just not evenly distributed.”
    — William Gibson

    "The future is already here—it's just not evenly distributed."
— William Gibson

    If you had told me twenty years ago that one day my daughter would wake up, take a handful of pills, complete her treatments, and then go about living what is—for all practical purposes—a normal life, I would have struggled to believe you.

    That future wasn’t built by artificial intelligence alone.

    It was built by thousands of researchers, physicians, engineers, patients, and families who spent decades advancing science one careful step at a time.

    Now, for the first time, many of those same researchers have a tool that allows them to move faster than ever before.

    Artificial intelligence won’t replace human ingenuity.

    It will amplify it.

    And perhaps that’s the conversation we should be having.

    Not whether AI can generate a beautiful painting.

    Not whether it can replace a writer or an illustrator.

    Those are important discussions, and they’re worth having.

    But they aren’t the whole story.

    The quiet miracles of AI won’t be measured by the pictures it generates.

    They’ll be measured by the discoveries it accelerates, the diseases it helps us understand, and ultimately, the lives it helps us save.


    Further Reading

    1. Jumper, J. et al. (2021). Highly accurate protein structure prediction with AlphaFold. Nature, 596, 583–589.
    2. Paul, D. et al. (2021). Artificial Intelligence in Drug Discovery and Development. Drug Discovery Today.
    3. De Marchis, M. et al. (2023). Machine Learning Applications in Cystic Fibrosis: A Narrative Review.
    4. Cystic Fibrosis Foundation. Research and Clinical Trials Pipeline.
    5. Nature Reviews Drug Discovery (2024). Artificial Intelligence and the Future of Biomedical Research.

  • How I Use AI to Become a Better Dungeon Master

    How I Use AI to Become a Better Dungeon Master

    Artificial Intelligence has become one of the most valuable tools behind my DM screen.

    Whenever I mention that, people tend to assume one of two things. Either they think AI is somehow running my games for me, or they think it’s a gimmick that produces generic fantasy content.

    In reality, it’s neither.

    AI doesn’t replace my creativity. It amplifies it.

    It doesn’t run my campaigns. It helps me spend less time on administrative work and more time creating memorable experiences for my players.

    As both a professional in the cybersecurity industry and a lifelong Dungeons & Dragons enthusiast, I’ve spent a lot of time experimenting with AI tools. Some have been useful. Some have been disappointing. But over the past year, I’ve developed a workflow that has become a permanent part of how I prepare and run games.

    These are the five areas where AI has had the biggest impact on my Dungeon Mastering.


    1. Session Recaps and Campaign Memory

    If you’ve ever run a long campaign, you know that one of the biggest challenges isn’t creating content—it’s remembering everything that has already happened.

    Players forget details.

    Dungeon Masters forget details.

    That mysterious NPC from six months ago suddenly becomes important again, and everyone is frantically searching through old notes trying to remember who they were.

    This is where AI has become an absolute game changer.

    For my games, I record sessions and upload the recordings to NotebookLM. It automatically transcribes the audio and produces surprisingly accurate summaries of what happened during the session.

    What impresses me most isn’t the transcription. It’s the understanding.

    Anyone who has played D&D knows that a four-hour session isn’t four hours of story. There are side conversations, jokes, pizza discussions, technical issues, and random tangents.

    NotebookLM does an excellent job separating the signal from the noise.

    It identifies the important story beats, character decisions, combat outcomes, discoveries, clues, and roleplaying moments while largely ignoring the table chatter that isn’t relevant to the campaign.

    The result is a clean summary that I can reference later.

    I’ve also experimented with Claude and ChatGPT for campaign summaries, and both work very well once I have a transcript. However, NotebookLM is currently the only tool in my workflow that allows me to start with the raw session recording itself.

    The practical result is simple:

    My campaign notes are dramatically better than they used to be.

    I can quickly review previous sessions, refresh my memory before game night, and maintain continuity across long-running campaigns without spending hours writing notes after every session.


    2. Campaign Planning, NPC Development, and Encounter Design

    This is probably where AI saves me the most preparation time.

    One of the biggest misconceptions about AI is that it generates creativity.

    I don’t think that’s true.

    What it does exceptionally well is stimulate creativity.

    Every Dungeon Master has experienced creative roadblocks.

    You know where the story is going, but you’re not sure how to connect the dots.

    You have a villain, but their motivation feels weak.

    You have a dungeon, but the encounters feel repetitive.

    AI is an outstanding brainstorming partner.

    I regularly use it to explore:

    • Villain motivations
    • Political intrigue
    • Faction relationships
    • Campaign twists
    • Adventure hooks
    • Character backgrounds
    • Quest complications
    • Alternative story paths

    The same applies to NPCs.

    When players inevitably become fascinated by the one random merchant or tavern owner you never expected them to care about, AI can help generate personality traits, goals, fears, secrets, and relationships within minutes.

    Encounter design benefits as well.

    Rather than simply asking, “How many monsters should be in this room?” I can explore questions like:

    • What tactics would these creatures realistically use?
    • How would an intelligent villain prepare for this battle?
    • What environmental hazards would make this encounter more memorable?
    • What objectives exist besides defeating every enemy?

    The final decisions are always mine.

    But AI helps me explore possibilities much faster than I could on my own.


    3. Handouts, Letters, and Props

    One of the easiest ways to increase immersion in a campaign is to give players something tangible.

    A letter.

    A journal.

    A proclamation.

    A wanted poster.

    A cryptic note discovered in an abandoned ruin.

    The problem is that creating convincing props takes time.

    AI dramatically accelerates this process.

    Need a centuries-old journal entry from a doomed explorer?

    A noble’s formal letter to a rival family?

    A cultist’s encoded message?

    A desperate plea for help written during a siege?

    AI can produce a strong first draft in seconds.

    I still edit the final result to ensure it fits my campaign, but starting from a solid draft is much faster than staring at a blank page.

    For horror campaigns like Curse of Strahd or other Ravenloft adventures, this has been especially useful.

    Handouts make the world feel real.

    Players engage differently when they’re holding a physical document instead of simply listening to a description.

    AI allows me to create more of those immersive moments with significantly less preparation time.


    4. Generating Artwork

    I love visual aids.

    The challenge is that I am a writer, not an artist.

    Historically, Dungeon Masters had limited options for custom artwork.

    You could draw it yourself.

    Commission an artist.

    Search endlessly online hoping someone had already created something similar.

    Or simply go without.

    AI-generated art has changed that.

    Today I can create custom artwork for:

    • NPC portraits
    • Villains
    • Magic items
    • Cities
    • Taverns
    • Dungeons
    • Campaign scenes
    • Adventure handouts

    The most valuable aspect isn’t necessarily the quality of the art.

    It’s the specificity.

    When I create a completely original NPC, there usually isn’t existing artwork available that perfectly matches my vision.

    AI allows me to create visuals tailored specifically to my campaign.

    That means players are seeing my villain, not a random image pulled from a Google search.

    The same applies to locations, artifacts, and story moments.

    The world becomes more visually cohesive and immersive because the artwork is built specifically for that campaign.


    5. Answering Questions During the Game

    This might be the most underrated use of AI.

    Players ask questions.

    A lot of questions.

    Some are rules questions.

    Some are lore questions.

    Some are questions about events that happened twenty sessions ago.

    Others are questions that come completely out of nowhere.

    No Dungeon Master can remember everything.

    AI has become an incredibly useful assistant for helping answer questions quickly.

    Need clarification on a rules interaction?

    Need to remember the name of an NPC from months ago?

    Need to verify a piece of Forgotten Realms lore?

    Need a quick summary of a faction’s history?

    AI can often provide the answer faster than digging through books, notes, websites, and PDFs.

    That doesn’t mean I blindly trust every response.

    Like any tool, AI occasionally makes mistakes.

    But as a first-pass research assistant, it has become remarkably useful.

    In many cases it helps keep the game moving rather than bringing the session to a halt while everyone searches for information.


    The Real Value of AI for Dungeon Masters

    The biggest lesson I’ve learned from using AI is that it doesn’t replace the role of the Dungeon Master.

    It removes friction.

    The creativity still comes from me.

    The storytelling still comes from me.

    The worldbuilding still comes from me.

    The emotional moments, dramatic reveals, and memorable victories still happen between real people sitting around a table.

    What AI does is eliminate some of the busywork that gets in the way.

    It helps me remember more.

    Create more.

    Prepare more efficiently.

    And ultimately deliver a better experience for my players.

    That’s why AI has earned a permanent seat at my gaming table—not as the Dungeon Master, but as the Dungeon Master’s assistant.