Signals intelligence (SIGINT) is the interception of communications and electronic emissions; cyber intelligence (CYBER) is collection from networks and systems themselves. Between them they can establish who is talking to whom and what a facility is running, without the target's permission. The AI-verification literature does not separate the two: Scher and Thiergart give them one row, Six Layers lists them together, and the MIRI draft's definition of national technical means names both. This section follows the literature and treats them together.
In the Literature
Six Layers names signals and cyber intelligence, with human intelligence, as the disciplines of its national-intelligence layer, effective without the Prover's cooperation, and says no more about either (2.4.1 reproduces the paragraph with the rest of §4.3). Scher and Thiergart give them one row and rate the pair High feasibility within a year:
Signals-based intelligence is already in use. For detecting AI compute, such approaches might focus on AI developers, data centers, and chip producers.
Scher and Thiergart | MIRI (2024)
That is the extent of the treatment. The MIRI draft agreement goes one step further and writes both words into its definition of national technical means. Definition 17 counts "satellite, aerial, cyber, signals, imagery (including thermal), and other remote-sensing capabilities employed by Parties for verification consistent with this Agreement." None of the precedent definitions the draft borrows from (the ABM Treaty, INF, CTBT, New START) named cyber.
Precedent
The arms-control precedent is richer than the AI literature. National technical means, satellites and signals intelligence together, were sufficient to count large fixed objects such as silos and launchers, and treaty law protected them with noninterference clauses. How much of that record carries over to a training run is one of the debates in 2.3.7.
Limits
There are two, and the second makes the first worse.
Signals and cyber collection are the streams most sensitive to sources and methods, and therefore the hardest to share with a treaty verifier: showing what was heard, or what was found inside a rival's network, shows how it was reached. Nuclear treaties impose no obligation on intelligence agencies to share with treaty verifiers, and sharing is voluntary, informal, and inconsistent (Baker §2.3.3); protection of sources and methods is the reason. For the memo: a stream that cannot be shown to the other side can raise a lead but cannot by itself settle one.
The inclusion of cyber is contested. To the party with the stronger collection capability, "cyber" inside NTM makes intrusion a treaty-protected verification activity; to the other party, it licenses an intrusion program aimed at itself, and it is the word that party will try to strike first. The asymmetry in collection capability is what makes the same clause read as protection to one side and as a threat to the other. A cyber-derived lead can open a file; the regime's own tools resolve it. This is the module's identify-and-resolve distinction, in its sharpest case.
Reading
Offensive Cyber Operations and the Use of Force
Read Parts I and II, pp. 63–70. The author directed the National Research Council's study of cyberattack capabilities and wrote the paper for lawyers and policymakers. Every operation needs a vulnerability, access to it, and a payload. "Easy" targets are connected to the Internet; "difficult" ones are isolated and need close access to plant a vulnerability, and an adversary's important systems are of the difficult kind. Cyberexploitation targets confidentiality, whereas attack targets integrity, authenticity, and availability. His list of objectives describes the capability: read passing traffic for keywords (his own examples are "nuclear" and "plutonium"), exfiltrate plans and passwords, map a network from its traffic without reading its content. Note the sentence on which this section's Definition 17 argument rests: attack and exploitation have "quite similar" technological underpinnings.
Herbert S. Lin | Journal of National Security Law & Policy (2010) | 15 min
Optional: Intelligence in Cyber—and Cyber in Intelligence
Cyber as an intelligence discipline, by the historian of US Cyber Command. His argument: espionage and counterespionage moved into cyberspace "virtually intact", and what is new is scale and the permanence of data. Read it for the capabilities as he states them: an implant that stays in a machine for months or years, collecting like a well-placed agent; traffic intercepted in transit and analysed for patterns even when its content cannot be read; a blown operation that ends in a quiet purge and a diplomatic complaint rather than a war. Read it also for the two sentences the exercise below turns on: collection campaigns "can appear similar to preparations for war", and "the lines between spying and attacking have always been blurry".
Michael Warner | Georgetown University Press (2017) | 30 min
Optional: Verifying Restrictions on Frontier AI Research
A catalogue of 28 mechanisms for verifying restrictions on AI research rather than on compute. Read the "Covert projects" subsection: it lists whistleblowers, intelligence gathering on known and on unknown targets (signals, communications, financial, and human intelligence), interviews, search warrants, and sting operations as the methods for finding a covert project, and says which kind of violator each can catch. The sample answer to the exercise below draws on it.
Aaron Scher | MIRI (2026) | 10 min

