How nations share intelligence treaties and MOUs

How nations share intelligence: treaties and MOUs

How nations share intelligence through treaties, MOUs, and technical protocols - and why ORCON, NOFORN and Five Eyes define the limits of modern cooperation.

The scaffolding of global security

The modern geopolitical landscape is defined less by overt military deployments and more by the silent, high-speed exchange of data. This exchange is governed by a complex structural framework - the architecture of intelligence-sharing protocols and treaty carve-outs. At its core, this system attempts to solve a fundamental paradox of statehood: how to maintain national sovereignty while acknowledging that no single nation can adequately defend against transnational threats like cyber warfare, state-sponsored espionage, or terrorism in isolation.

This architecture is not a singular monolith. It is a layered ecosystem of formal treaties, clandestine Memoranda of Understanding (MOUs), executive agreements, and technical standards. These mechanisms allow for the "quiet alignments" that keep the machinery of international security functioning. As the digital age accelerates, these protocols are under increasing strain, forced to balance the rigid demands of "need to know" security with the urgent operational reality of a "need to share" environment.

Understanding this architecture requires a deep dive into the human intermediaries, the legal exceptions, and the automated protocols that define the limits of cooperation - and, increasingly, into the newer instruments states are building to route around the slowest parts of the old system entirely.

The human element: intelligence liaison officers as vital conduits

While high-level treaties provide the legal basis for cooperation, the actual movement of data often depends on the human infrastructure provided by Intelligence Liaison Officers (ILOs). These professionals are the operational glue of the global intelligence community. According to the Department of Homeland Security (DHS), the Intelligence and Analysis (I&A) Liaison Officer Program is designed specifically to facilitate a bi-directional flow of information - ensuring that intelligence does not merely sit in a centralized silo but reaches the local law enforcement and host agencies where it can be most effective.

ILOs operate at the intersection of diplomacy and security. Their responsibilities extend beyond simple data transmission; they are tasked with nuanced analysis and relaying of critical intelligence that requires context. In jurisdictions like Ohio, the Ohio Homeland Security (OHS) and the Ohio Fusion Center Network leverage these officers across critical infrastructure sectors. This horizontal expansion of the liaison model ensures that situational awareness is not limited to traditional military targets but encompasses utility grids, transportation networks, and public health systems.

The efficacy of an ILO rests on a foundation of interpersonal trust and deep mastery of security protocols. They must often navigate the conflicting legal requirements of different jurisdictions in real time - a task that is as diplomatic as it is technical. No amount of automated pipeline can substitute for the judgment call an ILO makes when a piece of raw intelligence needs context before it becomes actionable.

Intelligence Liaison Officers provide the critical human infrastructure linking global data to local action.

Hierarchies of secrecy: classification and dissemination controls

The movement of information is strictly regulated by hierarchical classification levels. In the United States, these levels determine not just who can see a document, but the level of physical and digital security required to house it.

  • Confidential (C): applied to information where unauthorized disclosure could reasonably be expected to cause "damage" to national security.
  • Secret (S): reserved for data that could cause "serious damage."
  • Top Secret (TS): the highest level, where disclosure could cause "exceptionally grave damage" - potentially compromising sources, methods, or human lives.

Beyond these tiers lie the handling caveats that dictate the life cycle of shared intelligence. The Third-Party Rule, or Originator Control Principle (ORCON), is perhaps the most significant constraint in the architecture. Codified under Intelligence Community Directive (ICD) 710, ORCON mandates that intelligence received from one state cannot be shared with a third party without the explicit prior permission of the originating state. Crucially, ORCON control is absolute: no information provided by one agency can be given by another to a third party without the consent of the originating agency.

This principle is a double-edged sword. While it protects the proprietary methods of the originating agency, it frequently creates bottlenecks. When national oversight bodies or democratic committees attempt to review the legality of an operation, ORCON can be invoked to deny access, effectively shielding data from accountability.

Furthermore, NOFORN (No Release to Foreign Nationals) often reflects a risk-averse culture that leads to overclassification. This stifles timely decision-making during crises, where the delay in obtaining a "REL TO" (Released To) clearance for an ally can have direct operational consequences. At the Defense Intelligence Agency, for instance, permission to share or even discuss a CIA HUMINT or NSA SIGINT report within Five Eyes partners had to be routed to each originating agency to determine if they had already shared it - a cumbersome process that slows the very cooperation the architecture is meant to enable.

Strict classification tiers and ORCON handling caveats protect sources but frequently create oversight bottlenecks.

The legal architecture: treaties and the rise of MOUs

Formal agreements are the bedrock of long-term alliances. The most prominent example is the Five Eyes (FVEY) alliance, comprising the United States, United Kingdom, Canada, Australia, and New Zealand. The informal origins of the Five Eyes alliance trace back to secret meetings between British and US code-breakers at Bletchley Park in February 1941, and the alliance was formally codified in the UKUSA Agreement on 5 March 1946. This signals intelligence (SIGINT) powerhouse allows for the default exchange of gathered intelligence, including the highly sensitive methods used to obtain it.

Each of the Five Eyes states conducts interception, collection, acquisition, analysis, and decryption activities, sharing all intelligence information obtained with the others by default. The arrangements are built on integrated programs, integrated staff, integrated bases, and integrated analysis. Former NSA contractor Edward Snowden described the Five Eyes as a "supra-national intelligence organisation that does not answer to the known laws of its own countries" - a characterization that has fueled ongoing legal challenges.

The alliance is not without structural vulnerability. Zero-day exploits and misconfigured authentication protocols have become common attack vectors, and a flaw in Microsoft's SharePoint servers opened the door to intrusions across public-sector systems, forcing allied intelligence agencies into emergency coordination. The more recent Salt Typhoon breach revealed Chinese intelligence services operating inside major US telecommunications carriers for an extended period - a massive defensive failure that exposed gaps in the alliance's internal warning architecture. In June 2026, the Five Eyes cyber agencies went a step further, issuing a joint statement warning that AI is reshaping the threat landscape faster than defenders can adapt, and calling for coordinated action across all five member states rather than country-by-country responses.

Recent strains within the alliance illustrate just how fragile the trust foundation can become. The UK suspended intelligence sharing with the US in the Caribbean in late 2025, asserting that US naval operations in South American waters were illegal - marking the first known operational suspension between the two closest allies. This is not a collapse of the relationship, but it is a partner fencing off a specific operational line. The distinction matters enormously.

Just weeks later, the same five agencies stood shoulder to shoulder on a separate matter entirely. In early June 2026, the domestic security services of the Five Eyes - ASIO, CSIS, the FBI, MI5, and NZSIS - published a joint bulletin warning that Chinese military intelligence officers were posing as recruiters and consultants on professional networking platforms to target individuals with access to classified information. It is a useful illustration of how the alliance actually functions in practice: partners can restrict cooperation on one operational front while maintaining, even deepening, it on another. The architecture is modular, not binary.

Nations must balance absolute border sovereignty with the urgent need to defend against transnational threats.

The recent trend in intelligence architecture increasingly favors MOUs over formal treaties. MOUs are often confidential and establish working relationships without the public ratification processes required for international treaties. These arrangements allow for rapid adaptation to emerging threats. Because many MOUs explicitly state they are not legally binding instruments under international law, they provide a flexible - albeit less transparent - framework for cooperation. This flexibility is essential in areas like cyber defense, where the threat landscape evolves faster than the legislative cycles of most democracies. Yet the lack of public scrutiny raises significant concerns regarding democratic legitimacy and the potential for these agreements to circumvent domestic surveillance laws.

The intelligence architecture is shifting from rigid, formal treaties toward flexible, confidential MOUs.

The CLOUD Act model: a newer layer of bilateral sharing

Sitting somewhat apart from the classic treaty-versus-MOU divide is a newer instrument that has quietly reshaped how allied democracies access electronic evidence: the US Clarifying Lawful Overseas Use of Data Act, or CLOUD Act, passed in 2018. Rather than governing classified intelligence in the traditional sense, it addresses a narrower but increasingly consequential problem - how law enforcement in one country gets timely access to data held by a service provider based in another.

Before the CLOUD Act, a UK investigator seeking emails stored on a US company's servers typically had to go through a Mutual Legal Assistance Treaty (MLAT) request, a process that could take months. The Act lets the US establish bilateral executive agreements with trusted foreign governments, allowing law enforcement on both sides to send direct, case-specific orders to providers in the partner country and bypass the local blocking laws that would otherwise prevent a response. These agreements do not expand US jurisdiction over foreign providers; they simply remove the legal conflict, and requests must target serious crimes, pass independent review, and comply with human-rights standards.

An executive agreement under the CLOUD Act is meant to apply only where the requesting and supplying jurisdictions share comparable privacy and civil liberties protections, and reaching one requires a formal assessment of the partner country's domestic law to confirm it respects substantive and procedural safeguards for privacy. The first such agreement, the US-UK Bilateral Data Access Agreement, was signed in October 2019 and remains the template for subsequent negotiations, including an extended and increasingly strained set of talks with Canada.

The CLOUD Act framework is a useful case study in how the broader architecture evolves under pressure. It was built to solve a narrow technical problem - slow MLAT processing - but it has since become entangled with much larger disputes over encryption, sovereignty, and trust between allies, showing that even the most technocratic-sounding instruments in this space are never purely technical for long.

Technical protocols: automating threat intelligence

As the volume of data grows, human-to-human sharing is no longer sufficient. The architecture has evolved to include automated technical standards that allow systems to communicate at machine speed. The Department of Homeland Security and its international partners have championed several key protocols:

  • STIX (Structured Threat Information eXpression): a standardized, JSON-based language that allows organizations to describe cyber threats in a consistent, machine-readable manner - including adversary tactics, indicators, campaigns, and motivations. STIX was developed by MITRE and the OASIS Cyber Threat Intelligence Technical Committee.
  • TAXII (Trusted Automated eXchange of Intelligence Information): the companion transport protocol used to securely exchange STIX-formatted content over HTTPS. The modern TAXII 2.x standard is significantly simpler than its predecessor, exclusively using a client-initiated pull model via a standard RESTful API.

It is worth noting that CybOX (Cyber Observable eXpression), once listed as a separate standard in this space, has been fully integrated into STIX 2.0 and is no longer maintained as a standalone protocol. The observable objects that CybOX defined - file hashes, registry keys, network connections - are now native components of the STIX framework.

These protocols ensure that an intelligence-sharing agreement is not just a piece of paper but a functional digital pipeline. An ally can automate defenses, allowing a firewall in London to update its blocklist based on a threat detected in Canberra within seconds. However, industry-wide STIX/TAXII adoption remains fragmented due to specification complexity and implementation challenges. Analysis of approximately six million STIX objects over nine years reveals that security providers generate only around 2,000 unique daily objects, inadequate for the scale of increasing cyber threats. Technological disparities among allies create "weak links" in the chain, where a less secure partner becomes a vector for compromising the entire network.

Standardized technical protocols allow systems to communicate and update defensive blocklists at machine speed.

Treaty carve-outs and the national security exception

A critical, often overlooked aspect of this architecture is the "carve-out" - a legal provision that allows a state to prioritize its security over its international obligations. The most significant of these is found in the WTO framework under GATT Article XXI, which allows members to take any action they consider "necessary for the protection of its essential security interests."

Historically, Article XXI was a dormant provision, rarely invoked for fear of unraveling global trade. Its use has proliferated in recent years. The "Russia - Measures Concerning Traffic in Transit" case, decided by a WTO Panel on 5 April 2019, was the first time the national security exception contained in Article XXI had ever been formally reviewed.

The panel took the position that invocation of the exception is justiciable and subject to scrutiny by the WTO Dispute Settlement Body - contrary to the position long held by the US and invoked by Russia that the exception is totally "self-judging," meaning it can be unilaterally invoked without further scrutiny. The panel ultimately concluded that Russia's invocation was justified in the circumstances, but it established that the security claim must be made in good faith and relate to a genuine situation of emergency in international relations.

This expansion of the definition of national security now increasingly encompasses economic stability, supply chain integrity, and cybersecurity. As states move to protect their "essential interests," the line between legitimate defense and economic protectionism blurs. This creates a volatile environment for global trade, where intelligence-sharing protocols may be used to justify the exclusion of certain foreign technologies or the implementation of trade barriers under the guise of national security. The physical geography underpinning these disputes is worth its own examination - questions of maritime chokepoints, undersea cable routes, and border infrastructure shape which states can even credibly claim a security interest in the first place, a theme explored in more depth in strategic chokepoints: geography's hidden power.

Treaty carve-outs allow states to bypass international obligations under the expanding guise of essential security.

The expansion question: who gets a seat at the table?

A growing debate within the intelligence community concerns whether the Five Eyes alliance - and the broader architecture built around it - is still adequately sized for the threats it faces. Cyberattacks now traverse continents in seconds, exploiting servers, data centers, and legal gray zones far beyond the Five Eyes' collective footprint. The challenges of this new threat landscape demand a wider coalition capable of defending where its members no longer have reach.

The Five Country Ministerial has served as the primary annual forum for coordinating cooperation since 2013, enabling joint action on emerging challenges - from child exploitation to the global flow of synthetic opioids. But expansion carries its own risks. Past experiments with Nine Eyes and Fourteen Eyes arrangements achieved only partial interoperability, limited by differing privacy laws, classification thresholds, and data-handling protocols.

Outside these formal tiers, a looser pattern of ad hoc cooperation has taken shape. The Five Eyes have on various occasions shared threat data with Japan, South Korea, Israel, Germany, and France - most notably to build a clearer picture of North Korean missile activity and to coordinate against Chinese cyber operations. None of this amounts to membership. It is closer to a set of case-by-case exceptions granted where interests align tightly enough to justify the exposure, which is itself instructive: expansion of the architecture rarely happens through grand new treaties anymore. It happens through narrow, subject-specific arrangements bolted onto the existing frame.

Every new member, formal or informal, multiplies the risk of compromise. But every boundary left undefended in an interconnected digital world is a potential attack vector. The alliance faces no clean resolution to this dilemma.

Challenges: trust, AI, and the shadow of automation

The architecture faces several structural challenges that no technical standard can fully address.

First is the inherent trust deficit. No protocol provides absolute certainty that a partner will not mismanage data. George Shultz, the late US Secretary of State, regularly reminded colleagues that in diplomacy, "trust is the coin of the realm" - and trust is even more critical in intelligence sharing. Without it, even the most sophisticated satellites and cyber tools are expensive toys.

Second is the "revolving door" phenomenon, where states might rely on partners to surveil their own citizens, effectively bypassing domestic privacy protections. The Five Eyes intelligence-sharing arrangements are shrouded in secrecy, allowing for arbitrary or unlawful intrusions on the right to privacy which circumvent domestic legal restrictions on state surveillance. There is no domestic legislation governing intelligence-sharing in many jurisdictions, meaning many arrangements lack legal basis and therefore democratic legitimacy.

"The public should have clarity as to the circumstances in which Five Eyes intelligence agencies will exchange information and the procedure governing such exchange, including limiting the sharing of intelligence to what is necessary and proportionate."

That call for proportionality, long a staple of civil liberties advocacy, has taken on new urgency as bilateral data-access instruments like the CLOUD Act multiply alongside the older classified-intelligence channels, each with its own oversight gaps.

Third - and perhaps the most structurally disruptive - is the rise of artificial intelligence.

AI systems do not create new data, but they dramatically increase its discoverability, accessibility, and movement. That reality exposes gaps between visibility and enforcement that many organizations have tolerated for years. In an intelligence-sharing context, this means AI can surface sensitive information previously hidden in vast datasets, exposing vulnerabilities in data governance that ORCON markings and REL TO caveats were never designed to address.

The implications compound quickly. AI-enabled adversaries - state and non-state - can now process and exploit data at scales impossible for human analysts. AI has transformed traditional social engineering attacks, enabling threat actors to generate highly personalized impersonations that imitate trusted individuals with convincing accuracy, moving fraud from isolated attempts to high-volume AI-driven campaigns capable of bypassing standard controls.

For allied intelligence architectures, the risk cuts both ways. The same AI tools that accelerate threat detection can also accelerate the identification of gaps in information-sharing arrangements. If the underlying access controls are insufficient - and the fragmented implementation of STIX/TAXII suggests they frequently are - the automated intelligence ecosystem becomes a liability as much as an asset. Lawmakers have already tried to get ahead of this: a bipartisan bill introduced in the US Congress, the Five AIs Act, proposed a dedicated Five Eyes working group to jointly test, evaluate, and coordinate AI systems across the alliance, an early sign that the members themselves recognize the architecture needs a purpose-built AI governance layer rather than a bolt-on fix.

AI threatens to expose hidden vulnerabilities in data governance, exacerbating the network's inherent trust deficit.

The future of the intelligence ecosystem

The move from bilateral to "minilateral" and multilateral initiatives is a response to the complexity of modern threats. While bilateral cooperation is often preferred for its relative security, the scale of cyber warfare and global pandemics necessitates broader collaboration. The balance between the "need to know" and the "need to share" will continue to shift toward the latter, driven by the sheer velocity of digital threats.

The transatlantic intelligence-sharing system rests on three assumptions: that partners broadly agree on who the main adversaries are; that their legal frameworks and targeting practices are close enough that shared intelligence will not drag one service into another's grey zones; and that the practical benefits of sharing outweigh the risks of exposure. All three assumptions are currently under pressure.

The risk at this stage is not the collapse of alliances. It is the normalization of a more conditional, more guarded form of partnership - one where the day-to-day relationships between analysts and operators continue, but the upper tiers quietly recalibrate how much they are willing to expose.

The architecture will remain a delicate construct of quiet alignments. It is a system built on the tension between the necessity of transparency for democratic health and the necessity of secrecy for national survival.

The evolution of these protocols - and the legal carve-outs that support them - will not be resolved in treaty halls or technical working groups alone. It will be resolved, incrementally and often invisibly, in the choices that agencies make about what to share, with whom, and under what conditions. That is where the real architecture lives.

Key takeaways

  • Intelligence sharing relies on a layered mix of formal treaties like the UKUSA Agreement and informal Memoranda of Understanding (MOUs) - most MOUs are confidential and non-binding under international law.
  • The Five Eyes alliance (US, UK, Canada, Australia, New Zealand) was born from Bletchley Park wartime cooperation and formalized on 5 March 1946 - its members share all intelligence by default.
  • The Originator Control Principle (ORCON), codified under ICD 710, mandates that intelligence cannot be passed to any third party without the explicit prior consent of the originating agency - control is absolute.
  • NOFORN (No Release to Foreign Nationals) markings reflect a risk-averse overclassification culture that frequently delays timely decision-making during operational crises.
  • The WTO GATT Article XXI national security exception was formally reviewed for the first time in April 2019 in Russia - Measures Concerning Traffic in Transit, establishing that the exception is not wholly "self-judging."
  • STIX 2.1 and TAXII 2.1 form the primary automated framework for machine-readable cyber threat intelligence exchange; CybOX has been fully integrated into STIX 2.0 and no longer exists as a standalone standard.
  • Industry-wide STIX/TAXII adoption remains fragmented - analysis of roughly 6 million STIX objects over nine years found providers generate only around 2,000 unique daily objects, inadequate for current threat volumes.
  • The CLOUD Act (2018) enables bilateral executive agreements for direct cross-border access to electronic evidence, bypassing slower MLAT requests; the US-UK Bilateral Data Access Agreement, signed October 2019, was the first such deal.
  • The UK suspended intelligence sharing with the US in the Caribbean in late 2025, citing concerns over US naval operations - the first known operational suspension between the two closest Five Eyes allies.
  • In June 2026, the Five Eyes cyber agencies issued a joint warning that AI is rapidly transforming cyber risk, while the Five Eyes security services (ASIO, CSIS, FBI, MI5, NZSIS) jointly warned of Chinese intelligence officers posing as recruiters on professional networking platforms.
  • The Salt Typhoon breach revealed Chinese intelligence services operating inside major US telecommunications carriers for an extended period, exposing serious gaps in Five Eyes' defensive intelligence-sharing architecture.
  • The Nine Eyes and Fourteen Eyes arrangements - broader extensions of Five Eyes including several NATO allies - achieved only partial interoperability, limited by differing privacy laws, classification thresholds, and data-handling protocols.
As an Amazon Associate, I earn commissions from qualifying purchases. This means I may receive a commission when you buy through links on this site.
 avatar
@jordan
  • Redaction badge
    Redaction
Jordan Tyler
Senior Geopolitical Analyst
Jordan Tyler tracks the backroom legislative deals, quiet treaty revisions, and regulatory shifts that drive real geopolitical change - the kind that rarely makes front-page news until its effects are already irreversible. Specializing in the intersection of domestic policy architecture and international power dynamics, he strips away the theater of political headlines to expose the structural forces and institutional incentives operating underneath. His work is indispensable for anyone trying to understand not just what is happening in global politics, but why it is happening and what comes next.

Latest articles by Jordan Tyler

No posts yet