09/15/2026 | Press release | Distributed by Public on 09/15/2026 07:37
The Threat Gets a Vote. Are You Ready?
By Mike "Rabbi" Harasimowicz, Director of AI Certification and Standards, Lockheed Martin AI Center
Early in my Air Force career, I participated in missions against forces specifically trained to think and fight like an adversary. They weren't the enemy. They were U.S. Air Force pilots, deliberately selected to make success as difficult as possible.
The exercise is called Red Flag, and the premise is simple: you don't find out what works by operating in ideal conditions. You find out by facing the hardest version of the problem before the hardest version of the problem finds you.
Red Flag tests people. A related concept called red teaming tests systems: you become the adversary, attacking your own plans and assumptions before someone else does.
That instinct followed me through military service, cyber operations and AI development. And now at Lockheed Martin, red teaming drives how we evaluate AI long before it reaches the field.
There is a window in the development cycle when red teaming is most valuable and least costly. It must happen before deployment.
Once an AI system is in the field, the conditions change. The adversary is real. The stakes are real. The margin for course correction narrows dramatically. A vulnerability discovered in a combat environment exposes mission risk.
While creating the U.S. Cyber Command and the Cyber Mission Force, we relearned the same lessons, often the hard way. Security that's bolted on after the fact is security that fails. The same principle applies to AI. Before any AI capability reaches production, my team is ensuring adherence to our standards of practice and then actively trying to replicate an attack. We identify the methods an adversary could use, and then we close those gaps. Pressure testing during development produces a trustworthy system. Building first and hoping it holds is a risky approach.
AI systems can fail in three basic ways. Their environmental context changes. They're manipulated. Or they are misused outside of their design parameters.
Models drift as the world changes and new data arrives. A system that performs well today can quietly become less reliable tomorrow if no one is monitoring it.
Sometimes an AI model learns the wrong lesson from its training data. In a combat environment, that kind of failure could mean a missed threat, a poor decision and loss of life.
Other failures are intentional. An adversary who understands how a model was trained can introduce corrupted data to degrade its performance or create exploitable behaviors. This is a real security risk that companies and nations are facing today.
Automation bias compounds everything. Since 2015, I have been promoting trust in properly developed AI Systems. Over the past three, my message has shifted toward caution about over-reliance. Operators who stop questioning AI recommendations become vulnerable to both honest model failures and deliberate manipulation.
U.S. military policy requires that humans remain responsible for all decisions, even when AI-enabled systems are involved. That's more than policy. It's a design requirement, and red teaming is how you honor it. At the Lockheed Martin AI Center, red teaming is how we build trust into AI before it ever reaches the field.
The threat gets a vote. Your job is to make sure it's not the deciding one.