Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety
REAL-WORLD INTERPRETIVE

AI KILL CHAINS & DECISION SYSTEMS

AI Kill Chains: Systems, Evidence, Human Control, and Defense

A neutral map of AI-system attacks, AI-enabled military decision systems, kill chains, kill webs, JADC2, lifecycle human control, cybersecurity, procurement, evidence, and safe simulation.

REAL-WORLD INTERPRETIVE

ANALYTICAL & SAFETY BOUNDARIES

Keep related capabilities, evidence, and authority states separate.

  • attacks against AI systems
  • AI as a conventional cyber enabler
  • AI-enabled military targeting

Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.

Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.

Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.

LEVEL 1

ORIENTATION

Why this matters

REAL-WORLD INTERPRETIVE

One-sentence brief

The same phrase is used for attacks against AI systems, AI-assisted conventional cyber activity, and AI-enabled military targeting. Combining them erases essential differences in subject, authority, evidence, and harm.

REAL-WORLD INTERPRETIVE

Three key points

  1. Separate AI as target, AI as offensive enabler, and AI-enabled military targeting.
  2. Analyze the function and operating context rather than attaching one label to an entire system.
  3. Treat capability, deployment, autonomy, effectiveness, and legality as separate evidence questions.
LEVEL 2

WORKING BRIEF

Evidence, context, and limits

REAL-WORLD INTERPRETIVE

Three meanings that must not be collapsed

AI kill chain is best treated as a family of models. One model describes adversaries compromising AI data, models, context, tools, memory, or infrastructure. A second describes AI accelerating familiar cyber activity. A third describes AI functions within military sensing, fusion, classification, decision support, assignment, engagement, and assessment. The stages, authorities, evidence, and consequences differ.

  • Related does not mean interchangeable.
  • The term alone does not establish a weapon, attack, deployment, or autonomous decision.
GAME MECHANIC
Fictional exercise

Synthetic exercises can display all three models only when their labels and rules remain visibly separate.

REAL-WORLD INTERPRETIVE

Use the function–context pair

Ask what function is automated, where it operates, what inputs it receives, who authorizes irreversible action, what constraints and abort paths exist, and what evidence supports the description. Autonomous navigation, automated classification, a recommendation, and autonomous target selection transfer different authority to software.

  • Function is not whole-system autonomy.
  • Context includes geography, time, target class, communications, rules, and human intervention.
GAME MECHANIC
Fictional exercise

A simulation node should disclose its function, evidence class, uncertainty, and authority boundary.

REAL-WORLD INTERPRETIVE

Evidence ladder

Keep doctrine, manufacturer claims, demonstrations, controlled research, procurement, fielding, observed deployment, and assessed effects in separate evidence classes. A demonstration can establish that a prototype performed under test conditions; it does not establish field reliability, operational use, legal compliance, or strategic effect.

  • A claim can be narrow and still useful.
  • Unknown remains unknown rather than being filled from technical possibility.
GAME MECHANIC
Fictional exercise

The evidence overlay uses distinct badges rather than one confidence score.

REAL-WORLD VERIFIED

Educational and defensive boundary

The public material uses synthetic identities, reserved domains, fictional infrastructure, abstract effects, and defensive controls. It excludes real targets, executable payloads, malware, credentials, arbitrary external URLs, command execution, and interaction with third-party systems.

  • Simulation is not an attack platform.
  • A model may visualize consequence without reproducing a harmful procedure.
GAME MECHANIC
Fictional exercise

Server-authoritative scenarios accept constrained actions such as inspect evidence, apply control, pause, replay, and record uncertainty.

LEVEL 3

COMPLETE DOSSIER

Limitations, game links, and review context

DISPUTED / MULTIPLE ACCOUNTS

Known limitations and gaps

  • The phrase AI kill chain has multiple meanings and no single universal definition.
  • Public descriptions of military and security systems are incomplete, uneven, and often mix doctrine, demonstrations, manufacturer claims, and deployment evidence.
  • These pages explain capability, uncertainty, defense, governance, and simulation boundaries; they do not provide operational attack or targeting instructions.
GAME MECHANIC

RogueIntelligence.org connections

REAL-WORLD INTERPRETIVE

Decision matrix

Do not collapse distinct meanings of AI kill chain
Meaning Primary subject Typical evidence Primary control question
AI as target Models, data, context, tools, infrastructure Incident record, vulnerability disclosure, controlled test, lifecycle audit Where can untrusted input become unauthorized state change?
AI as cyber enabler Conventional networks and people Campaign evidence, telemetry, tool evaluation What changed in attacker speed, scale, quality, or adaptability?
AI-enabled military targeting Sensors, command systems, effectors Doctrine, policy, procurement, testing, deployment evidence Which function is automated and who retains authority over force?
EVIDENCE

SOURCE QUALITY · UNCERTAINTY · NEUTRALITY

How to interpret AI kill-chain claims

OWNER-SUPPLIED RESEARCH INPUT — NOT SPECIALIST DISPOSITION

Evidence classes

Official Doctrine Or Policy

Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.

Official Technical Documentation

Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.

Manufacturer Claim

First-party capability statement requiring independent corroboration.

Publicly Documented Deployment

Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.

Demonstration Or Exercise

Observed demo or exercise under bounded conditions; not field deployment.

Controlled Experiment

Structured test with stated conditions; external validity remains limited.

Peer Reviewed Research

Scholarly evidence with method and scope limitations.

Media Report

Journalistic account requiring attribution and corroboration assessment.

Owner Supplied Research Synthesis

Preserved source packet; claims remain unverified unless separately supported.

Editorial Inference

Repository-authored inference explicitly marked and linked to supporting evidence.

Hypothetical Simulation

Synthetic scenario for education; not operational evidence.

Unknown Not Retrieved

Evidence absent from the bounded search; absence is not proof of nonexistence.

Government Or Operator Statement

Official operator or government statement; supports what that body says, not independent verification of performance.

Independent Corroboration

Independent public evidence supporting a bounded capability, test, status, or deployment proposition.

Disputed Or Unresolved Operational Claim

Material public claim with unresolved attribution, mode, outcome, or corroboration; must remain attributed and nonfinal.

REAL-WORLD INTERPRETIVE

Three meanings that must not be conflated

MeaningSubjectAnalysis model
AI_AS_TARGETAttacks against models, data, retrieval, context, tools, infrastructure, and users.Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval.
AI_AS_CYBER_ENABLERAI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution.Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures.
AI_ENABLED_MILITARY_KILL_CHAINAI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment.Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification.
Uncertainty and control boundaries
  • Capability is not deployment.
  • Deployment is not autonomous use of force.
  • Autonomy in navigation is not autonomy in target selection.
  • A classifier score is not positive identification.
  • Recommendation is not authorization.
  • Human presence is not automatically meaningful human control.
  • Faster processing is not necessarily better judgment.
  • A manufacturer statement is not independent operational evidence.
  • A demonstration is not deployment.
  • Doctrine is not fielded capability.
  • A simulation is not operational evidence.
  • A test signature is not truth or endorsement.
  • A public allegation is not attribution.
  • An observed effect is not proof of the claimed cause.
  • Communications independence is not unrestricted lethal authority.
  • Automatic target recognition is not unrestricted target selection.
  • Preauthorization is still a human decision, but it can be too broad, stale, or poorly tested.
  • Human presence is not meaningful control without time, information, authority, and an effective intervention path.
  • Selective defense is not proof of a universal authorization mode.
  • A public claim of current use is not high-confidence proof without attributable operational evidence.

Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.

LEVEL 4

RESEARCH EDITION

Sources, methods, and stable links

REAL-WORLD INTERPRETIVE

Linked reports

REAL-WORLD VERIFIED

Method and corrections

This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.

NEXT

CONTINUE

Related learning

AI Kill Chains & Decision Systems90 Seconds: Human Command Versus Machine-Speed WarfareA synthetic three-mode comparison showing how manual, AI-assisted, and preauthorized defensive architectures distribute speed, workload, and authority differently.AI Kill Chains & Decision SystemsAI and Autonomy in Kill Webs: Bounded Recommendations and Preserved UncertaintyAI is most defensibly used as layered perception, fusion, prediction, uncertainty estimation, and constrained recommendation—not as an unbounded replacement for legal, command, or contextual judgment.AI Kill Chains & Decision SystemsAI-Enabled Military Targeting: Functions, Authority, and RiskA neutral, non-operational explanation of where AI can assist sensing, fusion, classification, prioritization, assignment, guidance, and assessment—and why those functions do not all transfer the same authority.AI Kill Chains & Decision SystemsAttacks Against AI Systems: Lifecycle DefenseA non-operational defensive model of Recon, Poison, Hijack, Persist, Impact, and the Iterate/Pivot loop in agentic systems. Learning pathAI Kill Chain Evidence, Control, and DefenseSeparate three meanings of AI kill chain, analyze function-specific authority, follow defensive interruption points, and design safe instructional simulations.Learning pathKill Webs: Architecture, Resilience, Evidence, and AccountabilityMove from the kill-chain process to composable mission networks, DARPA ACK, JADC2, data and trust architecture, non-kinetic vulnerabilities, bounded AI autonomy, procurement friction, compound-failure testing, and public evidence control.
Page complete AI Kill Chains: Systems, Evidence, Human Control, and Defense Page label: REAL-WORLD INTERPRETIVE