Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety
REAL-WORLD INTERPRETIVE

AI KILL CHAINS & DECISION SYSTEMS

AI-Enabled Military Targeting: Functions, Authority, and Risk

A neutral, non-operational explanation of where AI can assist sensing, fusion, classification, prioritization, assignment, guidance, and assessment—and why those functions do not all transfer the same authority.

REAL-WORLD INTERPRETIVE

ANALYTICAL & SAFETY BOUNDARIES

Keep related capabilities, evidence, and authority states separate.

  • attacks against AI systems
  • AI as a conventional cyber enabler
  • AI-enabled military targeting

Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.

Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.

Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.

LEVEL 1

ORIENTATION

Why this matters

REAL-WORLD INTERPRETIVE

One-sentence brief

Public discussion often treats any AI in a military system as an autonomous weapon. Function-specific analysis better reveals human authority, evidence quality, failure modes, and legal or policy questions.

REAL-WORLD INTERPRETIVE

Three key points

  1. AI-enabled does not necessarily mean autonomous target selection or engagement.
  2. Positive identification and combat identification are not synonyms for model confidence.
  3. Speed can compress time for verification, deliberation, intervention, and de-escalation.
LEVEL 2

WORKING BRIEF

Evidence, context, and limits

REAL-WORLD INTERPRETIVE

Functional sequence

A targeting sequence may include mission constraints, sensing, preprocessing, fusion, detection, classification, validation, prioritization, weapon–target pairing, human authorization or bounded autonomous release conditions, engagement, and assessment. AI can support one or several links without controlling the whole sequence.

  • Locate the AI function before assigning an autonomy label.
GAME MECHANIC
Fictional exercise

The visualization uses separate nodes for sensing, inference, decision support, authorization, effect, and assessment.

REAL-WORLD INTERPRETIVE

Human authority and intervention

Meaningful human involvement depends on knowledge, reliable system status, time to decide, ability to reject or abort, scope of delegation, and the predictability of the operating environment. A nominal approval step may provide little control when the system presents opaque conclusions or irreversible action is imminent.

GAME MECHANIC
Fictional exercise

The learner can pause at each human gate and inspect what information is available or missing.

REAL-WORLD INTERPRETIVE

Failure, deception, and systemic propagation

Sensor spoofing, adversarial examples, stale data, misassociation, classifier error, communication loss, cyber compromise, and automation bias can turn a plausible track into a cascading network error. Distributed architectures improve resilience in some conditions while increasing the number of trust boundaries and propagation paths.

  • A confidence score should not hide source contradiction or stale data.
GAME MECHANIC
Fictional exercise

Synthetic faults propagate visibly with uncertainty and provenance attached.

REAL-WORLD VERIFIED

Policy and multilateral currentness

The official DoD directives index continues to list DoD Directive 3000.09 dated 25 January 2023. The first 2026 CCW GGE Chair’s summary records ongoing work on possible elements of an instrument and outstanding divergences; it is not an adopted treaty or final consensus text.

  • Policy is not proof of compliance.
  • Negotiation is not adoption, entry into force, implementation, or enforcement.
GAME MECHANIC
Fictional exercise

Policy-state badges never change a technical or operational state automatically.

LEVEL 3

COMPLETE DOSSIER

Limitations, game links, and review context

DISPUTED / MULTIPLE ACCOUNTS

Known limitations and gaps

  • The phrase AI kill chain has multiple meanings and no single universal definition.
  • Public descriptions of military and security systems are incomplete, uneven, and often mix doctrine, demonstrations, manufacturer claims, and deployment evidence.
  • These pages explain capability, uncertainty, defense, governance, and simulation boundaries; they do not provide operational attack or targeting instructions.
GAME MECHANIC

RogueIntelligence.org connections

No game connection is required to use this educational page.

REAL-WORLD INTERPRETIVE

Decision matrix

Function and principal control question
Function Typical AI contribution Control question
Sensing Adaptive detection and search How are degraded or spoofed observations detected?
Fusion Association and confidence estimation Are provenance, contradiction, and staleness visible?
Classification Detection and recognition Does test performance transfer to actual conditions?
Decision support Ranking and recommendation Is the system advising or effectively determining choice?
Assignment Resource optimization Can a person understand and reject the pairing?
Engagement Guidance or discrimination Who selects the object receiving force and who can intervene?
Assessment Change and damage analysis Can an erroneous assessment trigger repeated action?
EVIDENCE

SOURCE QUALITY · UNCERTAINTY · NEUTRALITY

How to interpret AI kill-chain claims

OWNER-SUPPLIED RESEARCH INPUT — NOT SPECIALIST DISPOSITION

Evidence classes

Official Doctrine Or Policy

Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.

Official Technical Documentation

Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.

Manufacturer Claim

First-party capability statement requiring independent corroboration.

Publicly Documented Deployment

Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.

Demonstration Or Exercise

Observed demo or exercise under bounded conditions; not field deployment.

Controlled Experiment

Structured test with stated conditions; external validity remains limited.

Peer Reviewed Research

Scholarly evidence with method and scope limitations.

Media Report

Journalistic account requiring attribution and corroboration assessment.

Owner Supplied Research Synthesis

Preserved source packet; claims remain unverified unless separately supported.

Editorial Inference

Repository-authored inference explicitly marked and linked to supporting evidence.

Hypothetical Simulation

Synthetic scenario for education; not operational evidence.

Unknown Not Retrieved

Evidence absent from the bounded search; absence is not proof of nonexistence.

REAL-WORLD INTERPRETIVE

Three meanings that must not be conflated

MeaningSubjectAnalysis model
AI_AS_TARGETAttacks against models, data, retrieval, context, tools, infrastructure, and users.Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval.
AI_AS_CYBER_ENABLERAI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution.Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures.
AI_ENABLED_MILITARY_KILL_CHAINAI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment.Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification.
Uncertainty and control boundaries
  • Capability is not deployment.
  • Deployment is not autonomous use of force.
  • Autonomy in navigation is not autonomy in target selection.
  • A classifier score is not positive identification.
  • Recommendation is not authorization.
  • Human presence is not automatically meaningful human control.
  • Faster processing is not necessarily better judgment.
  • A manufacturer statement is not independent operational evidence.
  • A demonstration is not deployment.
  • Doctrine is not fielded capability.
  • A simulation is not operational evidence.
  • A test signature is not truth or endorsement.
  • A public allegation is not attribution.
  • An observed effect is not proof of the claimed cause.

Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.

LEVEL 4

RESEARCH EDITION

Sources, methods, and stable links

REAL-WORLD INTERPRETIVE

Linked reports

REAL-WORLD VERIFIED

Method and corrections

This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.

NEXT

CONTINUE

Related learning

Page complete AI-Enabled Military Targeting: Functions, Authority, and Risk Page label: REAL-WORLD INTERPRETIVE