Your Hiring Process Is Now a Weapons Financing Loophole
North Korea and Iran are using AI to manufacture legitimacy at scale. The threat isn't a genius hacker. It's industrialized paperwork.

Think of sanctions evasion the way you think about counterfeit currency: the problem was never that fakes existed, it was when fakes got good enough to fool the cashier every single time. A new report from the Royal United Services Institute (RUSI), titled Algorithms of Evasion: The Rise of AI-Enabled Proliferation Financing, published in mid-2025, warns that North Korea and Iran have crossed that threshold — and enterprise IT controls are the cashier.
Proliferation financing (PF, the use of financial systems to fund weapons of mass destruction programs) is not a new concern. What is new is that AI is compressing timelines and scaling volume in ways that traditional human-review processes simply cannot absorb. Dr. Aaron Arnold, senior associate fellow at RUSI's Centre for Finance and Security and the report's author, said in a statement that North Korea's ballistic missile and nuclear programs are now directly funded through AI-enhanced phishing schemes targeting Western companies.
The report draws a line that matters. AI-assisted evasion means an operative uses a language model to write a cleaner phishing email or forge a more convincing document. AI-enabled evasion is the next level: it coordinates identity documents, shell company records, crypto wallet activity, payment routing, API calls, and hiring profiles into a single orchestrated deception. Said Sanchit Vir Gogia, chief analyst at Greyhound Research, "The difference is not whether AI helps someone fake a document. The difference is whether AI begins to orchestrate the deception."
And that orchestration is already happening. The RUSI findings cite real-time blockchain analysis that dynamically adjusts cryptocurrency mixing strategies to dodge detection, mass production of synthetic identity documents, and automated shell company administration — the kind of administrative work that used to require rooms full of human operators.
Neither new nor slow. That's the uncomfortable update.
Gogia points to what he calls a structural asymmetry: offensive actors can scrape open-source data, study enforcement patterns, probe compliance thresholds, and refine their behavior across the entire ecosystem. Defenders are boxed in by privacy law, fragmented data silos, and explainability requirements. "Offensive AI learns broadly," he said. "Defensive AI often learns from fragments."
Arnold's guidance for enterprise IT managers is practical: incorporate behavior-based analytics, add circuit breakers on heavy API and MCP usage (model context protocol endpoints increasingly targeted by automated abuse), harden identity verification, and specifically tighten remote hiring pipelines. North Korea's IT worker infiltration campaigns, which have used AI-generated personas to land jobs at Western tech firms, are the live example — not a hypothetical.
The regulatory picture doesn't help. The EU AI Act, FATF counter-proliferation expectations, and NIST risk management frameworks each pull in different directions. "Criminals do not organize themselves around regulatory workstreams," said Gogia. "They organize around outcomes."
Gofia's framing is the one worth sitting with: treat this as a trust architecture problem, not a sanctions-screening checkbox. Every workflow that touches vendor onboarding, document review, remote hiring, or payment approval is now a surface area. Fully autonomous evasion networks aren't the everyday baseline yet — but the gap between here and there is closing faster than most compliance cycles move.
Watch for FATF's next guidance round on AI-enabled PF; that's where enforcement expectations will crystallize first.


