The most dangerous thing AI does in cyberspace is not the fastest or the most visible. It is not the automated intrusion that penetrates a network in milliseconds, nor the reconnaissance algorithm that maps a target's infrastructure in hours rather than weeks, nor even the deepfake video that alters a public moment. The most dangerous thing AI does is make truth slower than the attack it is trying to explain.
Synthetic deception sits at the centre of what Cristiano — a researcher at The Hague Program for Cyber Norms at Leiden University — Broeders, Delerue, Douzet and Géry have assembled in this serious and technically grounded volume on AI and international conflict in cyberspace. It is not the only subject, and the book's ambition is broader: to bring technical, strategic and legal scholarship into the same conversation about what is at stake when automation enters the domain of international cyber conflict. But the epistemic dimension is where the book's stakes are highest, and where its most unsettling arguments live. Escalation management depends on shared facts, or at least on a disagreement narrow enough that diplomacy can work within it. When AI-generated deception makes every intrusion, every communication trail, every piece of malware and every behavioural pattern permanently contestable, the problem is no longer only cyber insecurity. It is epistemic insecurity. The adversaries are not merely fighting over networks. They are fighting over what happened.

The volume's structure reflects genuine intellectual ambition. It divides AI-enabled cyber conflict into technical and operational challenges, strategic and geopolitical challenges, and normative and legal challenges. That tripartite frame is valuable because it refuses to treat the subject as a purely technical acceleration problem. States, scholars and lawyers are brought into the same argument. The technical section reveals the operational logic of AI-enabled attacks, including faster reconnaissance, automated exploitation and adaptive malware that evades detection by learning the environment. The strategic section addresses the geopolitical stakes, including a chapter on what the editors call the middleware dilemma of middle powers, examining how Brazil, India and Singapore are exposed to AI-enabled cyber conflict precisely through their dependence on services, platforms and infrastructural layers they do not fully control. The legal section confronts the normative questions that follow: what happens to international law when the conduct it is trying to regulate cannot be reliably attributed?
Artificial Intelligence and International Conflict in Cyberspace is strongest in the territory where these three sections overlap. Attribution is the hinge between technical evidence and legal consequence, and AI complicates attribution in both directions simultaneously. It can improve detection by analysing malware behaviour, identifying infrastructure reuse, clustering attacker techniques and finding patterns across datasets at a scale no human team can match. But it also makes attribution harder by enabling synthetic false flags, AI-generated personas, adaptive obfuscation and operations designed to look like someone else's work. The same capability that sharpens the analyst's vision also helps the adversary blur its own footprint. That is not a temporary technical limitation awaiting a better algorithm. It is a structural feature of the contest.
The legal consequences are severe and underappreciated. International law's application to cyber conflict depends on the ability to identify conduct, establish responsibility and cross a threshold. Who acted? Was it a state or a proxy? Did the state exercise due diligence? Was it an armed attack? Was the response proportionate and lawful? If attribution remains permanently contested, the law does not disappear. But its authority weakens at the exact moment it is most needed. States will attribute, intelligence agencies will attribute, private cyber security firms will attribute and alliances will issue statements. The danger is that attribution becomes politically legible only to those who already trust the attributing power. In an unequal international order, this means that the powerful will be believed by their partners and doubted by everyone else. A smaller state that has been attacked, cannot prove it to the satisfaction of international institutions it did not build and cannot afford the forensic capacity to make its case, may find that its suffering is acknowledged by its friends and denied by the world. AI-enabled cyber conflict may produce a world in which every state claims evidence, every adversary claims fabrication and every victim must prove harm inside a system designed to manufacture doubt. That is the legal crisis beneath the technical one.
The volume's most important single chapter is the one on middle powers, because it gestures toward an argument the book does not fully make but that the DiploPolis reading insists upon. For a powerful state with sophisticated offensive and defensive cyber capacity, AI-enabled conflict is a strategic problem: how to deter, attribute, respond and regulate. For a less capable state, it is also a sovereignty problem. Its banking systems, telecom networks, health databases, digital identity infrastructure, airports, payment rails and government clouds may depend on architectures designed elsewhere, secured through standards it did not write, governed by cloud providers whose obligations run to shareholders and regulators in other jurisdictions. When AI-enabled attacks hit that infrastructure, the weaker state is not merely a victim of cyber conflict. It is a victim of digital dependency that preceded the conflict and will outlast it.
The book sees part of this. What it does not do, and what the review should name, is make that structural inequality the gravitational centre of the whole argument rather than the subject of one chapter in the strategic section. The framing remains AI, cyber conflict and international security writ large. That is a legitimate and serious framing. But it describes the problem from the vantage point of states that have the capacity to manage it, even if imperfectly. A different book, not yet written, would begin from the position of the state that cannot attribute, cannot respond, cannot negotiate the standards and cannot afford the capacity to do any of these things. That state's experience of AI-enabled cyber conflict is not a harder version of the same strategic challenge that the United States, China or Russia faces. It is a different kind of vulnerability, and it requires a different kind of analysis.
That is not primarily a criticism of this volume. It is a description of where the field needs to go next. Cristiano, Broeders, Delerue, Douzet and Géry have produced a rigorous and genuinely multidisciplinary examination of a subject that most scholarship handles too narrowly. Read it for the technical depth, which is precise without being inaccessible. Read it for the legal argument, which is honest about the limits of the normative framework. Read it for the attribution paradox, which is the clearest account in this series of why AI makes cyber conflict not just more dangerous but harder to govern.
Then read it alongside the single most important fact about digital infrastructure in the world today: most of the countries on earth did not build the systems they now depend on, cannot fully secure them and have no meaningful voice in how they are governed. AI will not merely transform cyber conflict. It will reveal the hierarchy that was already built into the digital world.
This Book Review is free to read. Future Book Reviews will be available to registered DiploPolis members first. Free registration takes 30 seconds. No credit card required.
Find this piece interesting?
Dispatches by DiploPolis delivers sharp analysis and pointed commentary on power, politics, diplomacy, and world affairs — directly to your inbox.
No neutrality. No noise. Just argument.