For decades we thought of code as something hidden behind the screen -- a technical language, a sequence of instructions written by engineers and executed by machines. That definition no longer holds. Code now governs financial systems, biometric identification, telecommunications, energy grids, intelligence platforms, satellites, autonomous weapons and artificial intelligence. It is no longer merely running civilization; it has become part of civilization's strategic architecture. That shift raises one of the defining security questions of our time: who writes this code, who controls it, and what values are being embedded within it?
Much of the architecture of modern computing emerged from American universities, laboratories and defense programs. But the American technological model was never ethnically homogeneous. Its strength came precisely from its ability to absorb talent from everywhere – European scientists, Jewish refugees fleeing persecution, engineers from Asia, the Middle East, Africa and Latin America, all folded into a single technological ecosystem. Other centers of power have since emerged alongside it. China built an enormous computational and industrial base. Israel developed one of the world's most sophisticated concentrations of cybersecurity and defense technology. Iran, despite decades of sanctions, built substantial indigenous cyber capabilities. North Korea proved that even an isolated, impoverished state can project cyber power far beyond its borders. Strategic influence today depends as much on software, data and computational infrastructure as on armies, territory and industrial capacity.
This distinction is critical: code has no ethnicity, but it is not strategically neutral. A Boolean operation behaves identically in Boston, Tehran or Beijing. What differs is the institutional environment surrounding the engineer – who sets the requirements, who defines the threat, who controls the data, who decides when an autonomous system may act, and who has the authority to shut it down when it fails. Those questions, not the passport or ancestry of the person at the keyboard, are what turn software engineering into a matter of national and international security.
Modern geopolitical competition is increasingly a competition over architecture: who manufactures the semiconductor, who controls the cloud, who owns the satellite constellation, who trains the AI model, who holds the cryptographic keys – and ultimately, who teaches the machine what should count as normal, suspicious or dangerous. NATO's January 2026 Alliance Digital Strategy explicitly places secure digital infrastructure, artificial intelligence, Zero Trust architecture, post-quantum cryptography and human-machine collaboration at the center of the alliance's future defense posture, describing digital transformation not as mere modernization but as a source of operational advantage. The 21st century's strategic contest will be decided in part by who can collect, protect, interpret and act on information faster and more securely than an adversary.
For open societies, this produces a genuine paradox. Innovation depends on scientific openness, international cooperation and the free movement of talent. Yet many of the same technologies are dual-use: artificial intelligence can detect cancer or sharpen a targeting system; computer vision can authenticate a citizen or enable mass surveillance; cryptography can protect a population or conceal a hostile operation. The challenge for democratic states is not simply producing more technology – it is preserving openness while shielding the systems that matter most.
The threat is no longer theoretical. The US intelligence community's 2026 Annual Threat Assessment finds that China, Russia, Iran, North Korea and non-state ransomware actors continue to seek access to American government, private-sector and critical-infrastructure networks for espionage, disruption or profit. It describes North Korea's cyber program as sophisticated and agile, funding weapons development in part through cryptocurrency theft that reached roughly $2 billion in 2025 alone, and it flags Iranian cyber capabilities as a persistent concern alongside Tehran's missile and drone programs. These are American assessments, shaped by an American vantage point – but they illustrate why Washington and its allies now treat software supply chains, AI systems and telecommunications infrastructure as strategic assets rather than ordinary commercial products. A small group of programmers can now produce effects that once required a conventional military. That changes the arithmetic of international security.
Israel's approach illustrates the defensive mirror of the same logic. Its national cybersecurity strategy treats digital defense as requiring coordinated action across government, the security establishment, the private economy and international partners – cybersecurity as an extension of national infrastructure rather than an IT function. Across technologically advanced states, that boundary between digital security and national security is dissolving, drawing in energy, finance, biometric identity, space systems and civilian resilience alike. It extends even into orbit: software written in one country can now govern a satellite operating over another continent, giving code strategic reach without physical territory – and giving any failure or malicious instruction inside an autonomous, nuclear-warning or space-control system consequences that are no longer merely technical.
The emerging Western answer is not simply more code, but trusted code: auditable systems, secure development environments, verified supply chains, Zero Trust infrastructure, human oversight of consequential AI decisions, continuous red-teaming and intelligence sharing among allies. NATO's digital strategy already leans in this direction. But the balance is delicate – too little oversight invites exploitation by hostile actors; too much invites the suppression of the innovation, privacy and scientific openness that made Western technology strong in the first place. Managing that tension will be one of the central governance problems of the AI era.
There is, however, a line democratic systems must not cross. The security question can never become a question of the programmer's ethnicity – that would be both scientifically meaningless and institutionally corrosive. The relevant questions are about control, not ancestry: who owns the organization, what jurisdiction governs it, where the data travels, who can access the source code, what dependencies exist, whether the system can be independently audited, and whether a human can override it. This distinction matters most for the United States and its allies, whose technological edge has always depended on attracting talent from every part of the world.
That diversity is itself a security asset, not merely a social virtue. An engineer sees architecture; a cybersecurity specialist sees attack surfaces; an intelligence analyst sees hostile intent; a privacy lawyer sees surveillance risk. Someone who has lived under authoritarian rule, or under terrorism, or under sustained cyber warfare, will often recognize a danger that a colleague without that history simply cannot see. The goal, then, is not ethnic uniformity but institutional trust paired with intellectual diversity – a combination that makes systems harder to manipulate and easier to correct before an error becomes a catastrophe.
For thousands of years, civilizations encoded their values in constitutions, religious texts, laws and institutions. The 21st century has added another repository: source code. Future historians may study our algorithms the way today's historians study ancient legal codes, asking what we optimized, whom we trusted, whom we monitored, and what authority we surrendered to machines before we built the safeguards to control it. The threats catalogued by Western intelligence agencies make that reckoning immediate rather than theoretical. But preserving openness, civil liberties, and scientific collaboration remains part of the security equation too – because we are no longer simply teaching machines to operate inside our civilization. We are encoding pieces of that civilization into them. The defining strategic question of the coming decades is who will write that code, who will control it, and under whose rules the new digital world will operate.
The author is a cybersecurity strategist and AI & data governance expert.