WMD / Proliferation: Mission Domain Intelligence Guide
Proliferation networks do not buy weapons. They buy vacuum pumps, maraging steel, frequency converters and flow-forming machines, each individually unremarkable and each from a different supplier.
Proliferation networks do not buy weapons. They buy vacuum pumps, maraging steel, frequency converters and flow-forming machines, each individually unremarkable and each from a different supplier.
What WMD / Proliferation covers as a mission domain
WMD and proliferation intelligence covers the detection and disruption of programmes and procurement networks pursuing nuclear, chemical, biological or radiological weapons and their delivery systems. In practice this means monitoring dual-use trade against multilateral control lists, identifying front companies and brokers acting for a programme, comparing declared with observed facility activity, tracking transfers of technical expertise, and following proliferation financing. The output supports export-control enforcement, licensing decisions, sanctions designation, safeguards verification and interdiction, not operational targeting.
Analysts separate the state programme layer, meaning facilities, budgets, scientists and doctrine, from the procurement layer of trading companies, freight forwarders, banks and brokers that acquire controlled items abroad. Delivery systems, particularly ballistic and cruise missiles and increasingly uncrewed aerial systems, form a distinct control regime. Non-state CBRN interest is a smaller but genuine strand, typically constrained by technical capability and precursor access rather than by stated intent.
Why it matters
The consequences of a single successful acquisition are categorical rather than incremental, and the international regime depends almost entirely on detecting procurement before capability is achieved. Export-control breaches also expose ordinary manufacturers and freight companies to criminal liability when a distributor turns out to be a front. Verification failures undermine treaty regimes that dozens of states rely on for their basic security posture, with consequences well beyond the region concerned.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Orders for dual-use equipment routed through a trading company whose declared business is unrelated and whose staffing is minimal.
- End-user certificates naming a civil institution whose published research output shows no work requiring the specification ordered.
- Purchases of items just below control-list thresholds, or of components that together would constitute a controlled assembly.
- Payment through banks and corridors with no relationship to the stated buyer or the goods, typically via a third jurisdiction.
- Facility imagery showing new perimeter security, power infrastructure, ventilation stacks or excavation spoil at a declared civil site.
- Recruitment of specialists in enrichment, agent synthesis, aerosolisation or guidance by entities with no declared relevant programme.
- Freight routing that adds unnecessary transhipment legs and changes consignee identity at the final leg.
- Declared civil inventories that cannot account for material balances at safeguarded facilities across reporting periods.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- IAEA reports and safeguards documents — Verification findings, material accountancy discrepancies and state compliance reporting under safeguards agreements.
- OPCW documents — Chemical Weapons Convention declarations, inspection outcomes and investigation and attribution reports.
- UN Panel of Experts on the DPRK — Detailed procurement network case studies covering front companies, shipping methods and financial channels.
- UNSCR 1540 Committee national reports — State implementation of controls on WMD-related materials, transfers and financing.
- BIS Entity List and export administration regulations — Restricted parties and controlled item classifications under US export control law.
- Multilateral regime control lists (NSG, Australia Group, MTCR, Wassenaar) — Definitive technical parameters defining controlled dual-use goods and technology.
- NTI and the Wisconsin Project on Nuclear Arms Control — Open-source programme profiles, entity databases and procurement network analysis.
- UN Comtrade and national customs data — Trade flows in dual-use commodity categories supporting anomaly and diversion detection.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Classify against control lists — Determine precisely whether an item, its specification or its underlying technology falls within a regime's parameters; this is technical work, not judgement.
- Establish plausible end use — Assess whether the stated civil application accounts for the specification, quantity and associated support equipment ordered.
- Investigate the buyer chain — Resolve the ordering entity, its owners, premises and trading history, and establish whether it is a genuine end user, broker or front.
- Analyse the logistics — Reconstruct routing, forwarders, transhipment points and consignee changes for indicators of deliberate obfuscation.
- Correlate with programme indicators — Compare procurement patterns against facility imagery, personnel movement and declared activity to test the programme hypothesis.
- Trace the financing — Identify banks, intermediaries and payment structures, which are frequently the most durable and attributable element of a network.
- Refer for action — Package for export-control enforcement, licensing denial, sanctions nomination or safeguards follow-up, with technical annexes attached.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- CBRN Intelligence — Chemical, Biological, Radiological, and Nuclear Threats
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Geospatial Intelligence — Intelligence Derived from Place
- Imagery Intelligence — Interpretation of Visual Imagery
- Measurement & Signature Intel — Signatures, Measurements, and Physical Phenomena
- Academic Intelligence — Research Output, Collaboration, and Expertise
Worked in these data points
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
Adjacent mission domains
- Counter-Terrorism
- Nation State
- Military & Defense
- Sanctions Evasion
- Weapons Trafficking
- Biosecurity & Pandemic
Inside the platform: where WMD / Proliferation lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=wmd— WMD / Proliferation dashboardtheater.php?d=wmd— Threat theater viewsearch.php— Company / Organization profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to WMD / Proliferation:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Classify against control lists is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Investigate the buyer chain turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Refer for action feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses WMD / Proliferation
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts use proliferation intelligence for CBRN force protection, consequence management planning and assessment of an adversary's delivery capability. Products support protective posture decisions, medical countermeasure planning, detection equipment deployment and the intelligence preparation that identifies facilities requiring particular care in targeting. In inspection and verification support roles, defence expertise contributes to treaty monitoring. Constraints are unusually strict: analysis describes indicators of programme activity and procurement for detection and interdiction purposes only, never technical routes to capability. Handling is highly classified in most services, and dissemination of facility assessments carries both operational security and non-proliferation policy consequences.
🕵 National intelligence
This is a core national collection priority. Requirements ask what a programme currently possesses, what it is seeking, through which procurement channels, and on what timeline. Fusion is unusually demanding, combining technical measurement, imagery, trade and financial data, human reporting and safeguards information, and it depends on scientific expertise that few analysts have. Handling is highly compartmented, and the persistent tension is between protecting sources and providing the releasable evidence needed for designation, interdiction and diplomatic action. Dissemination priorities are policy customers, export control authorities, interdiction partners and multilateral verification bodies through appropriate channels.
👮 Law enforcement
Enforcement cases concern export control violations, smuggling of controlled items, false end-use declarations and sanctions breaches. Evidence is documentary and forensic: contracts, shipping records, end-use certificates, communications showing knowledge of the true end user, payment records and the physical goods themselves with technical characterisation. Cross-border production orders and mutual legal assistance are unavoidable. Knowledge or wilful blindness is usually the contested element. Prosecutions frequently proceed on the false documentation and licensing offences, which are provable, rather than on the ultimate destination of the goods, which may rest on intelligence that cannot be disclosed.
🔍 Private investigation and corporate security
Private sector work sits in export control compliance and trade finance screening: assessing whether a customer, an end use or a shipment presents diversion risk. The deliverable is a documented diversion risk assessment referencing control list entries, red flag indicators and the specific unresolved questions. A private actor may not investigate a foreign end user intrusively, obtain customs data without authority, or advise on how to structure a transaction to avoid a licence requirement, which is a serious offence. Where diversion is suspected, the obligations are to halt, report to the licensing authority and preserve records rather than to resolve it commercially.
📰 Journalism and OSINT media
Reporting requires technical verification and unusual restraint. Verify claims about facility function, material quantities and capability with independent specialist expertise, since misreporting in this area has significant diplomatic consequences. Do not publish technical detail that would assist a programme, and be aware that assembling open-source fragments into a synthesis can itself be a proliferation contribution. Corroborate imagery interpretation with more than one analyst. Protect sources absolutely, since exposure in this field is lethal. Provide right of reply to states and companies, and distinguish carefully between a facility with dual-use capability and evidence of a weapons programme.
🌍 NGO, humanitarian and human rights
Non-proliferation research organisations monitor programmes, support verification regimes and advocate on disarmament and humanitarian consequences. Documentation should meet the standard used by verification bodies and panels of experts, with imagery provenance, dates and analytical reasoning shown. Do-no-harm has a specific meaning here: publication must not provide technical uplift, and site-level detail requires careful judgement. Duty of care extends to researchers and local contacts in states with active programmes, where contact with foreign researchers is itself criminalised. Humanitarian organisations additionally document the effects of use on affected populations for accountability.
🎓 University and research
Research covers verification technology, procurement network analysis, treaty compliance and the history of programmes. Methodology draws on imagery analysis, trade data, materials science and archival work, much of it reproducible. Ethics review must consider dual-use publication risk explicitly, and many institutions apply specific processes for research with proliferation relevance. Reproducibility should be balanced against the principle that methods, not capability details, are what should be shared. Researchers should also be aware of export control rules applying to technical data shared with foreign nationals, including within their own institutions, which catch a surprising amount of ordinary academic activity.
Playbook: working WMD / Proliferation end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the question and the control framework
Establish what is being assessed: a specific programme, a procurement network, a shipment, or a customer. Identify which control lists and treaty regimes apply to the items in question. Control list classification is technical and determinative, so resolve it early with the actual list text rather than from memory. Output is a scoped question with the applicable control entries identified. Stop when you know which regime governs and what the licensing position is.
Phase 2 — Build the baseline programme picture
Assemble what is publicly established about the state or entity concerned: declared facilities, safeguards status, treaty membership, historical findings by verification bodies, panel of experts reporting and sanctions history. This positions any new indicator correctly and prevents the recurring error of treating long-known activity as a new discovery. Stop when you can state what is already documented and by whom.
Phase 3 — Identify the procurement requirement
Work from capability to shopping list conceptually: what categories of controlled equipment and materials a programme of the assessed type requires, at the level of control list categories rather than technical specification. This defines what to watch for in trade data and licensing referrals. Keep the output at the level needed for detection, never at a level that would assist acquisition.
Phase 4 — Screen the trade and licensing picture
Examine trade flows in relevant controlled categories to and through candidate jurisdictions, licence application patterns, denials and their subsequent re-appearance through other routes. Denied applications reappearing via a third country with a new consignee is a recurring and highly informative pattern. Output is a corridor assessment with the specific entities involved.
Phase 5 — Resolve the intermediary network
Trace the trading companies, brokers, freight forwarders and consignees involved in candidate transactions through corporate registries, address analysis and prior designations. Programme procurement runs through layers of intermediaries whose only function is to break the link between supplier and end user. Stop when you can distinguish genuine trading companies from procurement fronts on documented grounds.
Phase 6 — Test end-use declarations
Assess whether declared purchasers could plausibly consume the items: premises, staffing, power supply, licensing, sector activity and prior trade history. Physical implausibility is the strongest and most defensible finding available and is what licensing authorities can act on. Output is an end-use assessment with the specific implausibility documented.
Phase 7 — Compare declared and observed facility activity
Where facilities are in scope, compare declared function and safeguards status with observed activity: construction, expansion, thermal and vehicle patterns, security posture, power and water infrastructure, and waste handling. Work with specialists, since imagery interpretation errors in this field are consequential. State confidence explicitly and identify alternative explanations.
Phase 8 — Follow the proliferation financing
Identify how transactions are funded and settled: front company accounts, trade finance instruments, correspondent chains and jurisdictions used. Proliferation financing has its own designation and reporting framework, and financial indicators frequently surface networks before the goods move. Stop when you can name the financial institutions and instruments involved.
Phase 9 — Assess against treaty and safeguards obligations
Determine what the observed activity means for the state's obligations: safeguards agreements, additional protocol status, declaration requirements and inspection history. This converts an observation into a compliance question that verification bodies and the Security Council can act on, which is the mechanism that actually exists.
Phase 10 — Grade and express uncertainty carefully
Distinguish what is observed, what is inferred and what is assessed, with explicit confidence levels and the key assumptions identified. Historical intelligence failures in this domain came from confidence not supported by the evidence, and the reputational cost of that is still being paid. Output is an assessment where a reader can see exactly what would change the conclusion.
Phase 11 — Route to the available instrument
Match findings to the mechanism: licence denial, interdiction, designation nomination, referral to a verification body, industry advisory, or diplomatic demarche. Each requires a different releasable evidence package, and the sourcing constraints usually determine what is possible. Output is a set of packages written to each recipient's standard.
Phase 12 — Publish protectively and monitor for adaptation
Where findings are published, apply a dual-use test to every technical detail, and prefer indicator-level description over specification. Then monitor for the network reconstituting through new intermediaries, jurisdictions and commodity codes, which is the invariable response to any successful interdiction.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| IAEA safeguards and reporting | Open | Safeguards implementation reports, board documents, incident and trafficking database summaries and country status information. | Establishes a state's safeguards status, declared facilities and any documented compliance findings. |
| OPCW documentation | Open | Chemical Weapons Convention implementation, declarations, inspection reporting and investigation mission outputs. | Provides the authoritative record on chemical weapons compliance, use investigations and scheduled chemicals. |
| UNODA disarmament resources | Open | Treaty texts, status of ratification, Biological Weapons Convention material and confidence-building measure submissions. | Establishes treaty membership, obligations and declaration history for the state under assessment. |
| UN Security Council panels and sanctions committees | Open | Panel of Experts reporting on proliferation-related sanctions violations, procurement networks and shipping. | Supplies documented network findings and methodology precedent for procurement and evasion analysis. |
| Nuclear Threat Initiative resources | Open | Country profiles, facility information and analysis of nuclear, chemical and biological programmes and security. | Provides an accessible open baseline on programme history, facilities and policy positions by country. |
| James Martin Center for Nonproliferation Studies | Open | Open-source research on proliferation, missile programmes and export controls, including imagery-based analysis. | Supplies published analytical precedent and methodology for facility and missile programme assessment. |
| Arms Control Association resources | Open | Treaty status tracking, fact sheets and policy analysis across nuclear, chemical, biological and missile regimes. | Provides quick authoritative reference on treaty positions, agreements and their current status. |
| Wassenaar Arrangement control lists | Open | Multilateral lists of conventional arms and dual-use goods and technologies with technical parameters. | Determines whether an item is controlled and under which entry, the starting point of any assessment. |
| Nuclear Suppliers Group guidelines | Open | Guidelines and trigger lists governing transfers of nuclear and nuclear-related dual-use items. | Identifies controlled nuclear-related items and the transfer conditions participating states apply. |
| Missile Technology Control Regime | Open | Guidelines and annex covering missile systems and related equipment, materials and technology. | Establishes control status for delivery system components and the presumption of denial categories. |
| US State Department nonproliferation bureau resources | Open | US reporting and guidance on chemical, biological and missile nonproliferation regimes and the multilateral control lists. | Determines control status and regime membership for chemical and biological dual-use items in a transaction under review. |
| US Bureau of Industry and Security | Open | Export Administration Regulations, Entity List, denied persons list and end-user guidance with red flag indicators. | Supplies the recognised red flag framework and the current restricted end-user lists for screening. |
| OFAC counter-proliferation designations | Open | US designations of proliferation-related entities, front companies and financial facilitators with identifiers. | Establishes designation status of intermediaries and financial institutions in a procurement chain. |
| SIPRI databases and yearbook | Open | Arms transfers, military expenditure and nuclear forces data with methodological documentation. | Provides independent estimates of forces and transfers for contextualising programme assessments. |
| CTBTO monitoring information | Open | International Monitoring System covering seismic, hydroacoustic, infrasound and radionuclide detection. | Provides authoritative technical detection context for suspected nuclear test events. |
| Institute for Science and International Security | Open | Open-source technical analysis of nuclear programmes including facility imagery interpretation. | Supplies published facility analysis and methodology for comparing declared and observed activity. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against WMD / Proliferation. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Satellite imagery platforms — Track facility construction, activity and infrastructure change over time. Limitation: interpretation requires specialist expertise, and confident misreading in this domain has serious consequences.
- Trade data and customs analysis tooling — Detects flows of controlled commodity categories to and through candidate jurisdictions. Limitation: descriptions and codes are frequently falsified, and coverage varies by reporter.
- Corporate registry research tools — Resolves intermediaries, brokers and consignees into ownership pictures. Limitation: procurement fronts are established in low-disclosure jurisdictions specifically to defeat this.
- Screening systems against control lists and denied parties — Automates checks of customers and end users against restricted lists. Limitation: classification of the item against control list text still requires human technical judgement.
- Shipping and AIS analysis — Tracks vessel movement, transhipment and port calls in interdiction-relevant corridors. Limitation: transponder gaps are ambiguous and coverage varies significantly by region.
- Bibliometric and patent analysis — Identifies research capability, collaboration and technical progress within a programme's supporting science base. Limitation: publication lags and deliberate non-publication in weapons-relevant work.
- Structured analytic technique frameworks — Force explicit hypothesis testing and confidence statements where the cost of overconfidence is historically severe. Limitation: slow, and often abandoned under policy pressure.
- Radiation and chemical detection equipment — Supports border and site detection of controlled materials. Limitation: shielding, small quantities and detector siting limit real-world detection rates substantially.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- The procurement layer is the observable one. Programmes are opaque but their shopping is not, because acquiring controlled equipment requires interacting with foreign suppliers, freight forwarders and banks, all of which generate records that exist outside the state concerned.
- Physical implausibility of the declared end user is the most defensible finding available. A purchaser whose premises, power supply, staffing and sector activity could not use the item is a documented fact that a licensing authority can act on without reference to any sensitive source.
- Denied licence applications are a highly productive dataset. The same item, from the same supplier, appearing shortly afterwards with a different consignee in a third country is one of the clearest diversion signatures in the domain and is visible to licensing authorities.
- Dual-use means genuinely dual-use. Most items on control lists have overwhelming legitimate industrial applications, so a finding must rest on the specific end user, the pattern and the context, and analysts who treat the item alone as the indicator will drown in legitimate trade.
- State confidence and its basis explicitly, every time. The historical cost of overconfident assessment in this domain is enormous and still shapes how any judgement here is received, so distinguish observed, inferred and assessed, and say what would change the conclusion.
- Apply a dual-use test to your own output. Synthesising open fragments into a coherent technical picture can itself constitute proliferation-relevant uplift, so write at indicator level and treat technical specification as something to be withheld rather than demonstrated.
- Financial indicators frequently precede physical ones. Front company account activity, trade finance instruments and unusual correspondent routing surface procurement networks before any goods move, which is the only point at which interdiction is straightforward.
- Watch the delivery system side with equal weight. Missile and uncrewed system components fall under a separate control regime with different lists and different supplier bases, and networks routinely exploit the seams between regimes rather than any single one.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on WMD / Proliferation is producing anything, and they are worth baselining before you change process or tooling.
- Number of diversion attempts detected at the licensing or shipment stage rather than after delivery, as the primary outcome measure.
- Proportion of end-use assessments where physical plausibility was independently tested rather than accepted from documentation.
- Detection interval for network reconstitution after an interdiction or designation, measured as time to identify the replacement intermediary.
- Quality of designation nominations, measured by acceptance and by whether listings survive challenge.
- Proportion of assessments carrying explicit confidence statements and stated key assumptions, audited by peer review.
- Industry advisory uptake, measured by licensing referrals and voluntary disclosures received from companies after guidance is issued.
- Zero instances of published material assessed as providing technical uplift, treated as a hard constraint rather than a target.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Inferring intent from equipment alone, when most controlled dual-use goods have overwhelmingly legitimate industrial demand.
- Missing that a specification just below a control threshold may still be usable, or that a controlled item was decomposed into uncontrolled parts.
- Treating satellite imagery as self-interpreting, when construction signatures are ambiguous and have been publicly misread before.
- Assuming an unlisted intermediary is innocent or a listed one always is not, since designation lags network turnover considerably.
- Underestimating catch-all controls, which can capture otherwise uncontrolled items where the end use is known or suspected.
Legal and ethical considerations
Export-control classification carries direct criminal consequence for exporters, so technical determinations must be documented and, where uncertain, referred to the licensing authority rather than assumed. Deemed-export rules can make a technology transfer to a foreign national within your own borders a controlled act. Safeguards and treaty verification material is frequently confidential and cannot be republished. Ensure published analysis describes detection indicators rather than acquisition pathways, so that the work assists defenders without instructing anyone else.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for WMD / Proliferation, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Why focus on procurement rather than on the programme itself?
Because procurement is where a closed programme has to interact with the outside world. Facilities can be concealed, personnel are inaccessible and technical detail is protected, but acquiring specialist equipment and materials means placing orders with foreign manufacturers, moving goods through freight systems, and paying through banks. Each of those generates records held outside the state concerned, subject to licensing authorities and available to analysis. This is why export control enforcement and procurement network analysis, rather than facility assessment, produce most of the actionable findings and most of the successful interdictions in this domain.
How do you assess dual-use items without flagging all legitimate trade?
By assessing the end user and the pattern, not the item. Vacuum pumps, frequency converters, specialist alloys and precision machine tools have overwhelmingly legitimate industrial customers, so the item alone is uninformative. The signal is a buyer whose declared activity cannot consume the item, an intermediary with no relevant trading history, a shipment routed inconsistently with the stated destination, or a purchaser assembling a combination of items that make sense together only for one application. Licensing authorities publish red flag frameworks precisely because they encode this pattern-based rather than item-based logic.
What can satellite imagery actually establish?
Construction, expansion, activity level, security posture and infrastructure consistent with certain functions, all with dates. What it cannot establish on its own is what happens inside a building, and confident claims about facility function from imagery alone have been wrong in consequential ways. Good practice is to combine imagery with procurement evidence, declared status, personnel and publication analysis, to have interpretation reviewed by more than one specialist, and to state alternative explanations. Imagery is strongest as corroboration and as a timeline, and weakest as a standalone basis for characterising purpose.
What is proliferation financing and how does it differ from money laundering?
It is the provision of funds or financial services for the manufacture, acquisition or transfer of weapons of mass destruction and their delivery systems, including in breach of targeted financial sanctions. The key difference from laundering is that the funds may be entirely legitimate in origin, so detection cannot rely on the criminal source of money. Indicators are instead about the parties, the goods and the routing: front companies, unusual trade finance, inconsistent commodity descriptions and jurisdictions associated with diversion. FATF Recommendation 7 sets the obligations, and financial institutions frequently detect these networks before any goods move.
How should a company handle a suspicious enquiry?
Stop, document and report rather than resolve it commercially. Record the enquiry exactly as received, preserve all correspondence, and do not provide guidance to the customer on how a licence might be avoided or an order restructured, which can itself be an offence. Contact the licensing authority, which in most jurisdictions operates an outreach function precisely for this purpose and will advise on whether to proceed. The commercial instinct to decline politely and move on destroys evidence about a network that may be approaching many suppliers simultaneously with the same requirement.
How do analysts avoid contributing to proliferation through their own work?
By writing at the level of indicators rather than capability. Describe what a procurement pattern looks like, what an implausible end user looks like, and what a facility signature suggests, without providing specifications, quantities, synthesis routes or design detail. Recognise that aggregating open fragments into a coherent technical picture is itself a contribution, which is why many institutions apply specific dual-use review to non-proliferation publications. Where technical detail is genuinely necessary for a verification body or licensing authority, route it to them directly rather than publishing it, and treat that distinction as a working rule rather than a judgement call made per document.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- Treaty on the Non-Proliferation of Nuclear Weapons and IAEA comprehensive safeguards agreements with the Additional Protocol.
- Chemical Weapons Convention, administered by the OPCW, covering declarations, verification and prohibition of use.
- Biological and Toxin Weapons Convention, with its confidence-building measure submissions and implementation support unit.
- UN Security Council Resolution 1540, obliging states to prevent non-state actors acquiring weapons of mass destruction and to establish controls.
- Wassenaar Arrangement, Nuclear Suppliers Group, Missile Technology Control Regime and Australia Group control lists.
- FATF Recommendation 7 on targeted financial sanctions related to proliferation financing, and Recommendation 2 on national cooperation.
- Proliferation Security Initiative statement of interdiction principles, framing cooperative interdiction of proliferation-related shipments.
- National export control legislation including the US Export Administration Regulations and equivalent national dual-use regimes.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Safeguards implementation reporting — International Atomic Energy Agency. Authoritative record of safeguards status and compliance findings by state.
- Chemical Weapons Convention implementation and investigations — OPCW. Verification regime documentation and use investigation reporting.
- Disarmament treaty status and documentation — UN Office for Disarmament Affairs. Treaty texts, ratification status and confidence-building submissions.
- Panel of Experts reporting on proliferation sanctions — UN Security Council. Documented procurement network and evasion findings.
- Dual-use and munitions control lists — Wassenaar Arrangement. Multilateral definitions of controlled goods and technologies.
- Guidelines and trigger lists for nuclear transfers — Nuclear Suppliers Group. Transfer conditions and controlled item definitions for nuclear trade.
- Export Administration Regulations and red flag guidance — US Bureau of Industry and Security. Licensing framework and recognised diversion indicators for exporters.
- Country profiles and programme analysis — Nuclear Threat Initiative. Open baseline reference on programmes, facilities and security.
- Nuclear forces and arms transfers data — SIPRI. Independent estimates with published methodology for force assessment.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: screens dual-use trade, buyer chains and financing against control lists to surface diversion attempts. Explore the platform, or browse the rest of the library by following any tag above.