Cognitive Warfare Runs on Data: The Definition Washington Still Owes

The 2026 National Defense Authorization Act (NDAA) required the Department of War to define cognitive warfare by March 31, 2026. The deadline passed with no public definition of any kind, even as officials warn that China and Iran are already targeting entire populations with tailored disinformation and influence campaigns. Cognitive warfare runs on data. This essay argues that the debate has overlooked the mechanism that distinguishes cognitive warfare from propaganda: the algorithmic profiling of personal data at scale. It proposes a data-centric definition, treats bulk data theft and the future decryption of stored communications as cognitive-warfare logistics, and closes with five actions that follow.
Congress directed the Department of War to define cognitive warfare, relate it to existing doctrine, identify responsible organizations, and assess the value of “narrative intelligence.” Nearly four months after the deadline, no public definition has been released, and the 2026 National Defense Strategy did not address the gap. By early June, the debate had turned inward, focused on whether the term describes anything new at all, with some arguing the concept is dead on arrival inside the Pentagon. Meanwhile, a senior defense official warned that China and Iran are already using cognitive warfare to “alter the thinking of entire populations.”
The core issue is simple: adversaries are conducting cognitive warfare, and the US government has yet to define what it is. The delay stems not from a lack of words but from a debate focused on the wrong layer.
What Definitions Get Right, and What They Miss
Serious work on cognitive warfare has converged on a decision-centric view, meaning it defines the activity by human decision-making, rather than by any communication medium or message. The strongest formulation, published in Small Wars Journal, defines cognitive warfare as “a sustained and adaptive contest over human decision-making in which adversaries seek relative advantage by shaping or disrupting perception, interpretation, judgment, and action over time horizons.” Cognitive warfare runs below the threshold of armed conflict, waged continuously, in peacetime and in war, without a shot fired. The same body of work separates cognitive warfare from information operations, psychological operations, and influence activities. Practitioners of those disciplines tend to measure success by sentiment rather than by changed decisions. NATO’s scientists reached the same decision-centric conclusion from a different direction, calling the mind the battlefield and cognition a proposed sixth domain of warfare.
The NATO, US Army, and Small Wars Journal definitions correctly identify the objective: shaping decisions. They do not explain the mechanism, or how cognitive warfare fundamentally differs from traditional propaganda. The difference is precision: the ability to deliver a tailored message to each person rather than broadcasting one message to a mass audience. That precision comes from the underlying data, not from the message itself.
A Definition That Names the Mechanism
Here is a definition worth adding to the debate:
Cognitive warfare is a sustained, below-threshold contest to shape a population’s perceptions, judgments, and decisions through the profiling of personal data, which allows influence with a degree of accuracy that mass propaganda could never achieve.
In cognitive warfare, personal data is the targeting package. A recent framework from Rushing, Hersch, and Xu grounds the discussion in the observe-orient-decide-act decision cycle and treats it as an interactive attacker-defender exchange. The definition proposed here adds that precision is a function of the personal data collected on the defender’s population. Making data central to the definition, rather than incidental, shifts the focus of the conflict. The contest is no longer simply about messages and platforms, but about control of the data that enables accurate targeting.
Collection Is the Logistics
Defining cognitive warfare by its data dependence shows that two issues, often considered separately, are part of the same challenge.
The first is bulk data theft. Over the past decade, Chinese state actors breached the Office of Personnel Management, Anthem, Equifax, and Marriott, in what US officials now consider a single coordinated campaign. Recently declassified White House materials include a catalog held by a People’s Republic of China computer network exploitation actor around 2019, listing American voter rolls, social media account data, medical records with Social Security numbers, and biometric data. These incidents raise privacy and counterintelligence concerns, but under the proposed definition they are the deliberate accumulation of data that cognitive targeting requires. The ammunition is already stockpiled.
The second is encryption. Adversaries are believed to be collecting encrypted American communications now, intending to decrypt them once quantum computing matures. This strategy is known as harvest now, decrypt later. Those communications contain private thoughts and conversations, the most valuable input a cognitive campaign could ask for. Decryption is not simply a cryptographic concern; it marks the next phase of data acquisition. Together, collection and future decryption form the logistics chain of cognitive warfare.
Generative AI accelerates the payoff. Tasks that once required analysts to draft messages by hand can now be performed by models across millions of profiles simultaneously, turning stolen communications, behavioral histories, and identity records into tailored messages at machine speed. Data is the ammunition, the model is the delivery system, and the target is human judgment.
A Generational Time Horizon
Because data remains valuable over time, the campaign’s time horizon extends beyond election cycles and spans a generation.
Consider where children’s data goes. The Federal Trade Commission has acted against Apitor, a robot-toy maker whose app allowed a third party in China to collect geolocation data from children without parental consent. The 2025 update to the Children’s Online Privacy Protection Rule expanded protected personal information to include children’s biometric identifiers, such as voice prints and audio recordings, an acknowledgment that this material is being collected at scale. The Protecting Americans from Foreign Adversary Controlled Applications Act requiring divestiture of TikTok from its foreign-adversary parent rests on the same concern: a hostile state compelling the handover of Americans’ data, including that of minors.
Under the proposed definition of cognitive warfare, a biometric and behavioral profile built on a 14-year-old becomes the profile of a future cleared analyst, defense engineer, or field-grade officer. An adversary harvesting data on minors is not committing a short-term privacy violation; it is preparing targeting data for cognitive and counterintelligence campaigns decades in advance, against individuals who have not yet entered public service. Collecting children’s data is the longest and most patient logistical effort in this domain.
The Asymmetry an Open Society Needs to Face
The data-dependent nature of cognitive warfare creates a structural disadvantage for the United States that cannot and should not be engineered away. American laws and norms prohibit the intelligence community and military from collecting data on or conducting influence operations against US persons. While Section 1631 of the National Defense Authorization Act authorizes information operations abroad, domestic restrictions are intentional. Adversaries targeting American minds face no such limitations and can freely collect American data. The protections of an open society become a vulnerability when an adversary can gather in bulk the very data the United States is prohibited from collecting on its own citizens.
The solution is not to dismantle domestic protections or adopt adversary tactics against Americans. Analyzing foreign adversaries’ decision-making is a legitimate intelligence function, and developing outward-facing narrative intelligence, the assessment of how narratives form and spread in foreign information environments, is appropriate. Defending the American population, however, must run through resilience and through denying adversaries the data itself.
Cognitive Defense Begins at the Data Layer
This is the practical benefit of a precise definition. If cognitive warfare relies on data, then cognitive defense is fundamentally data defense, much of which already exists under other names. Executive Order 14117 and the Justice Department’s Data Security Program (28 CFR Part 202) already restrict bulk transfers of Americans’ sensitive data to countries of concern. Data minimization, stronger protection of children’s data, and the migration of national systems to post-quantum encryption all contribute, as does building public resilience by teaching citizens to recognize when their judgment is the target. These rules lack visibility and do not reside within traditional war-fighting commands, which partly explains why the data-layer threat is underfunded. Data defense does not resemble a weapon until the definition connects it to a fight.
Data security, foreign investment review, children’s privacy, and encryption standards reach well beyond the information-operations community, which is exactly why an overdue definition matters. Including data dependency in the definition broadens accountability and would create a whole-of-government mission. Excluding it ensures the Pentagon keeps searching for cognitive warfare among messages and platforms.
From Definition to Action: Five Recommendations
If cognitive warfare is data-dependent, then the United States already owns most of the capabilities to fight it. They are simply not assigned to the fight. The following five actions should follow:
First, name the mechanism in the definition of cognitive warfare. The Department of War’s overdue definition should state data dependence explicitly, because the definition assigns the mission. A message-centric definition hands the fight to the influence community alone. A data-centric one enlists the entire data-governance apparatus.
Second, treat the data layer as part of the cognitive domain. Bulk-data security programs, including the Data Security Program, data-centered reviews by the Committee on Foreign Investment in the United States, and Federal Trade Commission children’s-privacy enforcement should be treated and resourced as cognitive defense, with the Department of War a standing consumer of their threat picture rather than a bystander.
Third, close the children’s-data gap. Bulk-transfer restrictions should explicitly target minors’ biometric and behavioral data, because it has the longest logistics line in the adversary’s campaign and is the least defended.
Fourth, accelerate the encryption clock. Fund the post-quantum migration to keep tomorrow’s decrypted communications out of the adversary’s hands, with the longest-lived personal data moved first.
Fifth, build narrative intelligence facing outward and resilience facing inward. Deliver the narrative-intelligence assessment Congress requested, keep the legal wall against domestic collection intact, and invest in provenance standards for information and in civic education that helps citizens recognize when their judgment is the target.
Congress asked for a definition, and the country is still waiting. The definition is not a vocabulary exercise, and the delay is not costless. Until the United States names what cognitive warfare is and what it runs on, it will keep preparing to defend a terrain the adversary has already crossed quietly at the data layer, one harvested record at a time.