One-sentence brief
The same phrase is used for attacks against AI systems, AI-assisted conventional cyber activity, and AI-enabled military targeting. Combining them erases essential differences in subject, authority, evidence, and harm.
AI KILL CHAINS & DECISION SYSTEMS
A neutral map of AI-system attacks, AI-enabled military decision systems, kill chains, kill webs, JADC2, lifecycle human control, cybersecurity, procurement, evidence, and safe simulation.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.
Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.
Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.
ORIENTATION
The same phrase is used for attacks against AI systems, AI-assisted conventional cyber activity, and AI-enabled military targeting. Combining them erases essential differences in subject, authority, evidence, and harm.
WORKING BRIEF
AI kill chain is best treated as a family of models. One model describes adversaries compromising AI data, models, context, tools, memory, or infrastructure. A second describes AI accelerating familiar cyber activity. A third describes AI functions within military sensing, fusion, classification, decision support, assignment, engagement, and assessment. The stages, authorities, evidence, and consequences differ.
Synthetic exercises can display all three models only when their labels and rules remain visibly separate.
Ask what function is automated, where it operates, what inputs it receives, who authorizes irreversible action, what constraints and abort paths exist, and what evidence supports the description. Autonomous navigation, automated classification, a recommendation, and autonomous target selection transfer different authority to software.
A simulation node should disclose its function, evidence class, uncertainty, and authority boundary.
Keep doctrine, manufacturer claims, demonstrations, controlled research, procurement, fielding, observed deployment, and assessed effects in separate evidence classes. A demonstration can establish that a prototype performed under test conditions; it does not establish field reliability, operational use, legal compliance, or strategic effect.
The evidence overlay uses distinct badges rather than one confidence score.
The public material uses synthetic identities, reserved domains, fictional infrastructure, abstract effects, and defensive controls. It excludes real targets, executable payloads, malware, credentials, arbitrary external URLs, command execution, and interaction with third-party systems.
Server-authoritative scenarios accept constrained actions such as inspect evidence, apply control, pause, replay, and record uncertainty.
COMPLETE DOSSIER
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
| Meaning | Primary subject | Typical evidence | Primary control question |
|---|---|---|---|
| AI as target | Models, data, context, tools, infrastructure | Incident record, vulnerability disclosure, controlled test, lifecycle audit | Where can untrusted input become unauthorized state change? |
| AI as cyber enabler | Conventional networks and people | Campaign evidence, telemetry, tool evaluation | What changed in attacker speed, scale, quality, or adaptability? |
| AI-enabled military targeting | Sensors, command systems, effectors | Doctrine, policy, procurement, testing, deployment evidence | Which function is automated and who retains authority over force? |
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
Official operator or government statement; supports what that body says, not independent verification of performance.
Independent public evidence supporting a bounded capability, test, status, or deployment proposition.
Material public claim with unresolved attribution, mode, outcome, or corroboration; must remain attributed and nonfinal.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE