One-sentence brief
Public discussion often treats any AI in a military system as an autonomous weapon. Function-specific analysis better reveals human authority, evidence quality, failure modes, and legal or policy questions.
AI KILL CHAINS & DECISION SYSTEMS
A neutral, non-operational explanation of where AI can assist sensing, fusion, classification, prioritization, assignment, guidance, and assessment—and why those functions do not all transfer the same authority.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.
Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.
Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.
ORIENTATION
Public discussion often treats any AI in a military system as an autonomous weapon. Function-specific analysis better reveals human authority, evidence quality, failure modes, and legal or policy questions.
WORKING BRIEF
A targeting sequence may include mission constraints, sensing, preprocessing, fusion, detection, classification, validation, prioritization, weapon–target pairing, human authorization or bounded autonomous release conditions, engagement, and assessment. AI can support one or several links without controlling the whole sequence.
The visualization uses separate nodes for sensing, inference, decision support, authorization, effect, and assessment.
Meaningful human involvement depends on knowledge, reliable system status, time to decide, ability to reject or abort, scope of delegation, and the predictability of the operating environment. A nominal approval step may provide little control when the system presents opaque conclusions or irreversible action is imminent.
The learner can pause at each human gate and inspect what information is available or missing.
Sensor spoofing, adversarial examples, stale data, misassociation, classifier error, communication loss, cyber compromise, and automation bias can turn a plausible track into a cascading network error. Distributed architectures improve resilience in some conditions while increasing the number of trust boundaries and propagation paths.
Synthetic faults propagate visibly with uncertainty and provenance attached.
The official DoD directives index continues to list DoD Directive 3000.09 dated 25 January 2023. The first 2026 CCW GGE Chair’s summary records ongoing work on possible elements of an instrument and outstanding divergences; it is not an adopted treaty or final consensus text.
Policy-state badges never change a technical or operational state automatically.
COMPLETE DOSSIER
No game connection is required to use this educational page.
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
| Function | Typical AI contribution | Control question |
|---|---|---|
| Sensing | Adaptive detection and search | How are degraded or spoofed observations detected? |
| Fusion | Association and confidence estimation | Are provenance, contradiction, and staleness visible? |
| Classification | Detection and recognition | Does test performance transfer to actual conditions? |
| Decision support | Ranking and recommendation | Is the system advising or effectively determining choice? |
| Assignment | Resource optimization | Can a person understand and reject the pairing? |
| Engagement | Guidance or discrimination | Who selects the object receiving force and who can intervene? |
| Assessment | Change and damage analysis | Can an erroneous assessment trigger repeated action? |
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE