Among its many advantages, the United States benefits from a rare form of geographic luck: it is bracketed on the east and west by two vast moats in the Atlantic and Pacific Oceans and only two neighbors to the north and south, both of whom are relatively friendly. Adding to this good fortune is that, since the end of World War II, the United States has possessed a powerful nuclear arsenal and unparalleled military, economic, and technological might. Despite the 9/11 terrorist attacks, this mix of geography, deterrence, and power has led many Americans to feel almost untouchable at home. According to a 2024 Chicago Council on Global Affairs poll, just 19 percent of those surveyed expressed concern about foreign threats.
It is time for Americans to revise their assumptions. In fact, the U.S. homeland has never been as vulnerable to attack as it is today. China, Russia, and North Korea are building up their conventional and nuclear capabilities to strike the United States across a variety of domains—and U.S. defenses have not kept pace. A major evolution in technology and tactics, meanwhile, has increased the threat of subversion and gray-zone attacks: drones from state and nonstate actors can strike almost any target in the United States, and adversaries such as China can conduct AI-enabled offensive cyber-operations that can destroy or damage critical infrastructure.
The United States is not prepared. The country’s air and missile defenses are porous. Arcane domestic laws and policies prevent the necessary coordination and authority to defend against drone attacks. And energy, water, financial, health-care, and other infrastructure remain vulnerable to advanced cyberattacks. Faced with these new threats, federal, state, and local entities in the United States are caught flat-footed. The 9/11 attacks happened in part because of policymakers’ inability to grasp that the world was changing and to share information across government agencies that could have protected the country. Without an overhaul of the nation’s homeland security apparatus, Washington is in danger of making this mistake again.
MISSILES OVER THE MOAT
Security measures enacted after September 11 were designed to protect the U.S. homeland from terrorism. The U.S.A. Patriot Act and subsequent legislation enabled U.S. agencies to collect more intelligence at home and abroad. The Department of Homeland Security, the Office of the Director of National Intelligence, the National Counterterrorism Center, and the Joint Terrorism Task Forces were created or enhanced to better share intelligence about terrorism and other threats. The FBI significantly expanded the number of Joint Terrorism Task Forces across the country, coordinated with state and local law enforcement, and conducted intelligence-led operations to identify and arrest terrorists.
These measures were helpful at the time, when terrorism was the biggest threat to the U.S. homeland. And they were successful in preventing the vast majority of terrorist plots in the homeland. But today, some of the greatest threats to the United States come from state actors. China, Russia, and North Korea all possess intercontinental missiles capable of hitting the U.S. homeland—and all have conducted tests and exercises to show that they are capable of using them.
The wars in Iran and Ukraine suggest that possessing a nuclear arsenal, even one as large as the U.S. arsenal, no longer protects against conventional attacks on the homeland as it once did. Iran and its network of proxy forces have lobbed tens of thousands of rockets, missiles, and drones at major population centers in Israel. Ukraine has successfully struck Russian cities, energy infrastructure, industrial base targets, logistics nodes, and military bases without incurring a nuclear response from the Kremlin. Advanced Israeli and Russian air and missile defense systems have struggled to stop these drones and missile attacks.
In the event of a conventional attack on U.S. soil, American air and missile defense systems might, too. The United States lacks sufficient numbers of air defense systems and interceptors to protect against ballistic missiles. The war with Iran has reduced the military’s global supply of THAAD interceptors by as much as 80 percent and Patriot interceptors by as much as 50 percent. In addition, homeland defense against cruise missiles remains porous. Cruise missiles are difficult to defend against. They fly close to the earth in order to stay below conventional radar, and they use mountains, valleys, and hills to hide from ground-based sensors—what is called “terrain masking.” The United States does not have enough missile defense systems in enough areas to protect against cruise missiles.
China especially has expanded and updated its ability to strike the United States. In addition to missiles, the threat from China now extends into space. China can strike targets in the U.S. homeland using a Fractional Orbital Bombardment System, which places a warhead flying at hypersonic speed into low-earth orbit, allowing it to approach the U.S. homeland from an unpredictable direction and bypass traditional early warning radar and missile defense networks. The People’s Liberation Army is also researching other space-based capabilities, such as orbital strike weapons, which would theoretically strike the U.S. homeland by dropping projectiles from space.
CHEAP SHOTS
The U.S. homeland is also facing novel subversion threats. State and nonstate actors have long used physical sabotage against critical infrastructure, disinformation, and offensive cyber-operations to weaken their adversaries below the threshold of conventional warfare. But new technologies and tactics, including AI, present new challenges for the United States.
Drones are the most obvious example. Technological advances have already made drones cheaply and readily available for purchase, with longer ranges, higher payloads, and an improved ability to evade electronic warfare. Adversaries may soon be able to fly drones in coordinated swarms using AI, effectively overwhelming any defenses. Allies and adversaries alike are now engaged in an arms race, ramping up drone production and use in an attempt to innovate their way to the cutting edge. Russia is producing as many as seven million weaponized drones per year. According to some estimates, China has the capacity to build one billion drones per year.
It wouldn’t take that much, however, to wreak havoc on the U.S. homeland. In 2025, Ukraine smuggled over 100 drones into Russia inside cargo trucks to conduct strikes that damaged or destroyed roughly one-third of Russia’s active bomber fleet and caused approximately $7 billion in damages. Operation Spider’s Web was a spectacular success for Ukrainian forces—and a chilling reminder of the United States’ susceptibility to a similar attack. An adversary could conceal weaponized drones inside modified cargo vans, shipping containers, or trucks with slidable roofs and position the vehicles near high-value targets, such as military airfields or naval bases, without detection. They could program the drones to launch simultaneously using commercial cellular networks, circumventing domestic air defense and signal-jamming measures and effectively bypassing strategic early warning radar systems.
According to some estimates, China has the capacity to build one billion drones per year.
Such an attack on U.S. soil might seem far-fetched. But unauthorized drone incursions on U.S. military installations, nuclear power plants, and other critical infrastructure—not to mention outdoor concert venues, sports stadiums, transportation infrastructure, and ports—have been increasing over the past several years. In March, for example, Barksdale Air Force Base in Louisiana, which houses long-range B-52 bombers, went into lockdown after numerous unauthorized drones were spotted hovering over sensitive areas of the base. In June, the FBI arrested five suspects in an alleged plot to target the Ultimate Fighting Championship event on the White House South Lawn with explosive-laden drones. Artificial intelligence makes individual drones and swarms of drones harder to stop because they do not rely on remote radio signals that can be jammed by electronic countermeasures.
Drones are not the only problem made worse by AI’s rapid development. Agentic AI systems such as Anthropic’s Mythos will make it far easier for state and nonstate adversaries, such as terrorists, to penetrate cyberdefenses and attack critical infrastructure at a scale never before possible. Once directed, AI agents can discover flaws in corporate and government computer systems and execute self-directed cyberattacks with minimal human oversight. Even before the advent of these AI systems, the shockingly poor state of national and municipal cyberdefenses made American critical infrastructure an inviting target. Beginning in 2021, China’s Volt Typhoon attacks infiltrated U.S. power grids, water treatment plants, telecommunication systems, and transportation hubs, embedding malware that could sabotage them in the event of a U.S.-Chinese crisis. An AI-enabled Volt Typhoon operation would allow attackers to shift from a slow, human-enabled campaign that takes months or years to a nearly instantaneous, self-adapting campaign against numerous targets simultaneously that could be vastly more damaging.
Finally, beyond drones and AI, there is the growing threat of direct-ascent antisatellite weapons, which are missiles launched from the ground, sea, or air that travel into space to strike and destroy a satellite in orbit, as well as directed-energy weapons and electronic warfare systems that can target U.S. satellites in low-earth orbit and geosynchronous orbit. China and Russia are actively developing and testing a broad range of antisatellite and other counterspace weapons. If implemented, such space-based attacks could degrade GPS and navigation, ground commercial flights, and disrupt logistics networks that rely on satellite tracking for freight. In other words, they could at least temporarily grind daily life in the United States to a halt.
IMAGINING THE UNIMAGINABLE
To better prepare for an attack on the homeland, Washington needs first to fortify the active defenses that protect the country’s critical infrastructure. It needs to build and deploy more upper-range systems like Patriot and THAAD for ballistic missiles, medium-range systems such as the Indirect Fire Protection Capability system for cruise missiles, and short-range systems such as the Coyote and Merops systems to counter drones. Directed-energy weapons—such as high-energy lasers and high-power microwave systems—and radio-frequency jamming and electronic warfare systems are also useful to defend against drone attacks. The United States needs more systems to defend critical infrastructure, as well as training for personnel. It should also ramp up passive defenses, such as digging underground facilities for vital infrastructure and placing high-density and layered concrete barriers around ground systems, power-generation units, ammunition storage facilities, and barracks.
Since it would be exorbitantly expensive to protect everything in the homeland, Washington should initially focus on reinforcing critical bases and infrastructure that China or other adversaries could target in a conflict. Key locations include military command-and-control facilities, bomber bases, nuclear weapons sites, air and missile defense systems, and major naval bases.
Golden Dome, the Trump administration’s proposed homeland air and missile defense system, can play an important role in this effort. The plan aims to create a unified command-and-control network of sensors, weapons, and other systems to detect and shoot down incoming drones and missiles. But Golden Dome is underfunded and has been slow to get off the ground. Moving forward, the U.S. priority should be accelerating plans to stitch together existing capabilities—not developing new ones—such as the U.S. military’s missile warning satellites; global network of radars and sensors; 44 ground-based interceptors in California and Alaska; and other federal, state, local, and commercial systems. The U.S. military also needs to ramp up live-fire exercises to test Golden Dome’s software and ability to detect, track, and hit incoming threats.
Drones present a thornier problem. Commanders at military bases and personnel protecting critical infrastructure often do not have the legal authority to destroy or degrade drones that illegally fly into their airspace. Some recent laws, including the Safer Skies Act of 2025, grant state and local agencies (though not private-sector entities) greater license to detect and track hostile drones. But more comprehensive legislation is needed that allows operators who have received training to deploy and use counterdrone systems under federal or state and local law enforcement supervision. To mitigate the risk that newly empowered operators of counterdrone systems accidentally jam or shoot down civilian aircraft, more state and local personnel should be trained at the National Counter-UAS Training Center in Huntsville, Alabama.
The United states can no longer rely on its geography and its nuclear arsenal to protect it.
Intelligence sharing among federal, state, and local intelligence agencies improved after 9/11 to disrupt terrorist networks and foil planned attacks. But the evolving nuclear and conventional capabilities of China, Russia, and North Korea, as well as emerging tactics and technology such as drones and AI, make the intelligence practices of the “war on terror” largely obsolete. What’s more, self-inflicted wounds have damaged the few agencies well suited for today’s threats. The Trump administration, for example, has gutted the Cybersecurity and Infrastructure Security Agency, which oversees cyberdefenses and elections security. Much like the National Counterterrorism Center after 9/11, the United States needs to establish a robust National Counterintelligence Center that brings together analysts from multiple agencies to fuse intelligence, analyze threats, and coordinate strategic planning against Chinese, Iranian, Russian, and other threats to the homeland. At the state and local level, the Joint Terrorism Task Forces and Fusion Centers need to shift their focus and resources to tracking state-based threats to the homeland.
Finally, the threats currently facing the U.S. homeland require a fundamental shift in mindset. U.S. policymakers, the country’s security establishment, and its citizens must recognize that the United States is in a new era; it can no longer rely on its geography and its nuclear arsenal to protect it. Finland, Israel, and Ukraine have long traditions of developing strategic plans and communicating to their publics about homeland threats. The United States should follow suit by educating the American public about the evolving threats to the homeland and developing a national resilience plan—much as Finland has done—to harden critical infrastructure, closely collaborate with the private sector, adapt laws, and communicate with the public.
Americans’ overwhelming sense of safety was briefly and tragically shaken by the attacks on September 11, 2001, and the 9/11 Commission went on to argue that the United States faced a “generational challenge” from terrorist groups. A quarter century later, there is a new generation of Americans and a new generational challenge. If the 9/11 attacks were in large measure a failure of imagination and implementation, as the commission wrote, Washington risks repeating that same mistake today.
You are reading a free article
Subscribe to Foreign Affairs to get unlimited access.
- Paywall-free reading of new articles and over a century of archives
- Six issues a year in print and online, plus audio articles
- Unlock access to the Foreign Affairs app for reading on the go
Already a subscriber? Sign In
Sentinel — Human
The article presents a strongly argued case that current U.S. homeland defenses are insufficient against evolving state-level and asymmetric threats, proposing specific areas for policy and defense reform based on historical context.
