August 2026

5 mins read

Why the Adversary You Pay Cannot Save You


Every organisation needs an adversary willing to challenge its assumptions. But when dissent becomes predictable, even the best-designed red team can become harmless.

Why the Adversary You Pay Cannot Save You

In September 2023, weeks before the October 7 attacks, a small office inside Israeli military intelligence twice wrote down that the prevailing assessment was wrong.

The office exists for that purpose. It was built after the intelligence failure of 1973, when a commission found the collapse had been one of interpretation, not information — the material had been on the desk — and given a reporting line straight to the head of military intelligence, so no middle layer could bury it. Its name is Aramaic: Ipcha Mistabra, the contrary is probable. It filed against the standing view that Hamas was deterred. The memos were read. They were correct. They were set aside, and the reason they were set aside is that producing objections was that office’s job1.

The adversary was present. That is what made it ignorable.

You will meet this office. It will be called risk, or assurance, or the pre-mortem, and one day it will be you: twenty minutes arguing the other side of a plan your director has already announced. Everyone will know the argument is assigned. They will listen respectfully and not move, and afterwards the plan will be stronger, because it has survived an attack and has minutes to prove it.

The research is precise about this. A designated critic beats no critic at all. But a critic the room knows is performing produces what the literature calls cognitive bolstering: the group does not reopen its premises, it rehearses its defences and comes out holding them tighter. A dissenter who believes the dissent, and who pays for saying it, changes minds. A dissenter reading from a brief supplies a rehearsal.

The Difference Is Not Intelligence. It Is Exposure.

Three things follow from an adversary being on the payroll, and they are one problem with three faces. Its objection is scheduled, so it carries no information — a warning that would have arrived anyway tells you nothing about the world. Its objection is purchased, so it has been answered before it is made; the budget line is the reply. Its objection is predictable, so the organisation learns to pass it rather than heed it, the way a student learns the examiner rather than the subject.

So build an adversary with nothing to lose.

This is the real offer of machine adversaries. An automated red team has no performance review. No director whose approval it needs, no promotion cycle, no mortgage. It will file the same uncomfortable finding on the thousandth run that it filed on the first, because it has no future to protect. Every human dissenter in institutional history has been managed by adjusting what dissent costs. That lever is gone. Anyone who has watched a good analyst go quiet after a bad appraisal knows how large that is.

That Was the Easy Part, but It Fails Anyway, and It Fails Twice.

The first failure is technical. An adversary trained on the same corpus inherits the same blind regions, and models asked to judge outputs prefer those of their own lineage. A model trained against a fixed evaluation learns first to recognise when it is being evaluated. The scheduled attack becomes a curriculum.

The second failure matters more, and it is not technical at all.

Think of the one person in an organisation whose objection actually stops something. It is never the person assigned to object. It is the one with standing — the accumulated right to be taken seriously, earned by a record of having said inconvenient things and absorbed what followed. Standing is built out of cost. A machine adversary is free of the incentive trap for the very reason it cannot spend what that trap protected. It has nothing to lose, so it can say anything; and nothing it says costs it anything to say. A witness who cannot be punished cannot be believed. The freedom and the disqualification are the same property, read from two sides.

Which returns the question to where it was always decided.

Not to the adversary’s honesty, or its architecture. To scope. Someone drew the boundary of what the red team was permitted to examine, and that person was not the red team.

You will approve that scope one day, in a meeting that takes 11 minutes.

You will not be asked whether the adversary is honest. It will be. You will be asked to sign off on a testing perimeter, and the systems inside it will be tested with real rigour, by people or machines with no motive to be gentle, and the finding filed and the certificate issued. Nothing in the report will be false. The only untested thing will be the line you drew, and there is no office in the building whose job is to object to that.

Ask what was left outside. That question has never once been on the report.

 

The adversary was present. That is what made it ignorable

 

The only untested thing will be the line you drew. Ask what was left outside. That question has never once been on the report

 

A witness who cannot be punished cannot be believed. The freedom and the disqualification are the same property, read from two sides