Education
Whitepaper | Legibility is Now the Default: Why Everyone is a Target in the Joint Force Environment
By: Michael Stokes, SVP of Emerging Technologies
Executive Summary
In Operating Beyond Obscurity and From Awareness to Readiness, Veilant argued that visibility had become the default condition of modern operations and that the force had to move from awareness to action. This paper takes the next step. The Joint Force is no longer only visible. It is becoming legible, and that is the more dangerous condition.
The core change is not simply that more data is available. It is that less of it now sits outside analytical reach. As the cost of processing large datasets keeps falling, systems are increasingly able to work through information without first deciding what is worth looking at. That reversal removes a constraint that shaped almost every aspect of surveillance behavior.
At the same time, the way machines handle information has changed in a subtler but equally important way. Modern systems do not just surface relevant records or flag anomalies for review. They increasingly produce structured interpretations of behavior, returning relationships, clusters, and patterns that already imply meaning before a human analyst ever engages.
Taken together, these developments change how targeting works. Instead of selecting a small number of individuals or units for focused attention at the outset, modern systems can process large populations continuously and identify relevance after the fact. That shift marks the end of target-first surveillance. It also widens the field of exposure. The risk no longer stops with traditional target sets such as U.S. Embassy personnel, special mission units, or named officers. It reaches anyone whose activity is captured in enough detail to become legible to the model.
For the Joint Force, this is best understood as a shift from visibility to legibility. Visibility describes whether something can be observed. Legibility is whether it can be interpreted in a consistent and reusable way. Much of the raw material for that interpretation is now commercial. The Office of the Director of National Intelligence has formally recognized how purchasable data can be acquired and fused at scale. Once interpretation becomes cheap and continuous, the line between being seen and being understood starts to break down. Signature management can no longer remain an awareness issue; it has to be an accountable, funded discipline.
Visibility to Legibility
Most of the assumptions that still guide thinking about surveillance risk were formed under conditions where visibility was the limiting factor. If something could not be directly observed or collected, it did not enter analysis. Even when data was available, it often sat outside any meaningful interpretive workflow because there was no capacity to process it.
That constraint shaped how intelligence systems were actually used. Analysts worked from incomplete views, and most collected data never reached the point where it was fully interpreted. In that environment, being seen mattered, but being understood was rare enough that it required deliberate effort.
What has changed is not just the volume of data, but the way it is reused. Collection and storage have become easier and cheaper, which lowers the cost of tracking a person’s movements, connections, and activities over time. Just as important, modern systems no longer treat observations as discrete events. They accumulate them across time and sources, building persistent structures that describe behavior in a way that survives individual gaps in coverage. A single observation may be ambiguous, but it can quickly become part of a larger picture.
For the Joint Force, this is most evident in the supporting layers of activity rather than in operational events themselves. Movement associated with training, logistics, contracting, and personnel management tends to generate traces across unrelated systems. Those traces are not meaningful on their own, but they begin to matter when they repeatedly align across time and context.
Certain roles, units, and activities have consistently been prioritized for review, while the majority of the environment remained outside sustained analytic focus. That asymmetry is the basis for a long-standing and once-correct assumption, that digital signature risk is mainly a problem for small, sensitive, or specialized communities. Now the question is no longer whether something was observed. It is whether enough observations have accumulated to make the underlying activity interpretable in a consistent way.
The End of Front-End Triage
Traditional surveillance forced early choices. When analysts had limited time and limited tools, leaders had to decide up front who or what deserved attention. A small number of people, units, or facilities received sustained analysis. Everyone else was pushed to the side, even if their data was stored. That created a practical divide between data that existed and data that was actively analyzed.
That separation between storage and interpretation was one of the key features of traditional surveillance. It is also the real reason the old assumption held. It once cost too much to reconstruct an ordinary person’s pattern of life, so the adversary focused its scarce attention on high-value targets and left most of the force unanalyzed. The data existed. No one had the capacity to read it.
That divide is starting to break down. New analytic systems can now do the first pass across large amounts of data before a human analyst ever looks at it. They sort records, group similar behavior, flag anomalous behavior, and suggest possible associations. They do not eliminate human judgement, but they change what the human receives. Instead of starting with scattered raw data, the analyst starts with a partially organized picture.
The economics behind that shift are stark. Stanford’s 2025 AI Index reports that the cost of querying a model at a fixed level of performance fell by more than 280 times in under two years. When the first-pass becomes that cheap, it can be run broadly rather than reserved for a narrow target set.
The practical effect is that selection moves later in the process. The adversary no longer has to decide who or what is worth studying before analysis begins. It can process the wider environment first, then choose which patterns, anomalies, people, or networks deserve follow-up. That removes one of the filters that once kept much of the force outside sustained attention. It also spreads the capability beyond major intelligence services. Smaller states, commercial actors, and criminal networks can now reach levels of targeting and analysis that once required a large workforce.

Ambient Data Collection
This shift depends on the basic condition of modern life: people generate data constantly, even when no one is deliberately targeting them. Phones, vehicles, payment systems, logistics platforms, travel tools, and commercial applications all create data as part of normal, everyday life. Most of that data is not collected for intelligence purposes, but once it exists at scale, it can be bought, retained, combined, and analyzed.
The risk comes from overlap. A commute, financial transactions, license-plate readers, telematics, and cell phone location might appear in several unrelated systems at once and only show part of the picture. Together, they can make the underlying behavior legible. That is especially relevant for the Joint Force, because logistics, contracting, training, travel, maintenance, and personnel systems generate routine traces that were never designed to be analyzed together, but increasingly can be.
Machine Interpretation
Current systems increasingly move beyond simple detection. In earlier intelligence workflows, a system might flag a record, surface an anomaly, or retrieve a relevant item, and then interpretative word would begin afterward. That separation is becoming less clean. Many systems now return outputs that already contain a layer of interpretation: clusters of related behaviors, inferred relationships, and descriptions of what those patterns of life may represent.
In 2024, MITRE’s Shawn Benson argued that the community must separate detection from deduction. He is right. A sensor hit, an image, a location ping, or a device digital exhaust does not become intelligence on its own. It still has to be processed, enriched, correlated, interpreted, and delivered to someone who can act. Right now, that is a human.
The reason the argument needs updating is that the analytic step is exactly the part that is getting cheaper and more automated. Benson’s distinction still holds, but the distance between detection and deduction is shrinking. Interpretation is becoming distributed across systems rather than concentrated at the human analyst. Meaning is no longer assigned at a single end point. It is progressively built into the data as it moves through processing layers. For the Joint Force, that means external systems increasingly present behavior in pre-organized forms before a person ever reviews it, which changes the baseline conditions under which analysis begins.
Loss of Ambiguity
Ambiguity used to provide a kind of natural protection. When data points were incomplete, inconsistent, or scattered across different systems, they often did not add up to anything actionable. A lot of data existed, but it never became structured understanding.
That is changing. Modern systems are increasingly good at combining weak data points across time and across sources. A single data point may still be uncertain, but repeated patterns make the larger picture clearer. Once enough indicators line up, the system does not need every individual input to be precise.
The research on reidentification shows how little is required. One widely cited study of mobility data from 1.5 million people found that four approximate location and time points were enough to uniquely identify 95 percent of individuals. Even two points singled out more than half. In other words, sparse and seemingly anonymous data can be far more revealing than it appears.
The real issue is not whether any one signal or data point is clear. It is whether enough points are in the same direction over time. When they do, adversaries can create a structure that can absorb new information and make sense of it, even if earlier data remains incomplete.
That shortens the window in which a pattern of life can be extrapolated – not because the data is perfect, but because the systems are better at working with imperfection. Ambiguity is no longer a reliable form of cover. It must be created deliberately.
The result of these changes is a different kind of exposure model. Exposure is no longer primarily tied to whether something is sensitive in isolation. It is tied to whether activity contributes to a broader pattern that can be interpreted over time. That pattern is built from routine activity as much as from sensitive operations. Logistics, contracting, training, travel, maintenance, and personnel systems all produce signals and data that are not individually meaningful but become meaningful when combined.
That widens who is exposed. The clerk, the technician, the spouse, the contractor, the recruiter, the logistics officer, the personnel officer, and the acquisition specialist can all become part of the picture, because the system reads the ecosystem rather than only the operator. As those data points accumulate, they form a persistent representation of how the force operates. It does not need to be complete to be useful. It only needs to be consistent enough to support inference.
Capability and intent also separate here, which is an important distinction for operational planning. A current partner, a neutral state, a commercial platform, or a data broker may hold data today without any hostile purpose. That is not reassurance. Intent can change faster than data disappears, and once the record exists, a future reader can inherit it and draw new conclusions from it. The price of buying data shows how low the barrier already is. Public reporting puts the cost of the military personnel data described earlier at roughly a few cents per person, and the Senate Armed Services Committee has taken testimony on the risk created when commercial data and advanced analytics converge. This is not a future problem. The record is being built now, and the tools to read it are improving now.
Conclusion: Ownership or Exposure
The intelligence environment surrounding the Joint Force is shifting from selective observation to continuous interpretation. That is the core meaning of legibility. The danger is not simply that more data exists. It is that more of the force can now be interpreted through data, at scale, and at a declining cost. As that capability expands, targeting becomes less dependent on prior selection and more dependent on what emerges from the analysis after the fact. The boundary between who is deemed a target and non-target continues to narrow.
Waiting for proof is the comfortable institutional move, and it is the wrong one. In this domain, proof arrives after collection, after retention, and often after exploitation. By then the record cannot be unwritten.
That said, the force does not need panic. It needs ownership. That means a senior official accountable for signature management, a durable resourcing pathway rather than a string of pilots, and a program of record (POR) that turns a recurring operational reality into a funded, measured, repeatable discipline.
The objective is not disappearance. That is no longer realistic. The objective is to shape legibility, to decide what can be read, what should be obscured, and what must be deliberately managed before an adversary assigns meaning to the data. The question is no longer whether the force can be seen. It is whether the Department will take responsibility for what can be understood from that legibility.
About Veilant
Veilant supports organizations confronting the operational realities of ubiquitous technical surveillance (UTS) through assessment, training, digital signature analysis, operational planning support, and fieldable technical solutions. Our work helps leaders move from awareness to measurable action while preserving mission effectiveness in environments where commercial data, connected devices, and AI-enabled analytics increasingly shape operational risk.
Disclaimer
All statements of fact, opinion, or analysis are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in this paper should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author’s views.