One-sentence brief
Asking only whether someone pressed a final button can hide decisive upstream choices and can also exaggerate the control of an operator who lacked time, context, or an effective intervention path.
AI KILL CHAINS & DECISION SYSTEMS
A lifecycle map showing how authority, assumptions, and accountability can be distributed across policy, design, data, testing, mission configuration, activation, supervision, engagement, and review.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: Autonomy is analyzed by function, context, constraints, evidence, authority, intervention capability, and lifecycle—not as a single label attached to an entire machine. Capability is not deployment; deployment is not autonomous use; recommendation is not authorization; model confidence is not positive identification.
Simulation safety boundary: Synthetic, non-graphic, non-operational education only. Use fictional geography, abstract objects, reserved domains, nonfunctional artifacts, constrained inspect/pause/replay actions, and no real targeting data, attack geometry, payloads, credentials, arbitrary external URLs, malware, command execution, or contact with third-party systems.
Source basis: Exact owner-supplied research-source instances plus bounded official-primary-source currentness v15.
ORIENTATION
Asking only whether someone pressed a final button can hide decisive upstream choices and can also exaggerate the control of an operator who lacked time, context, or an effective intervention path.
WORKING BRIEF
A system outcome can inherit decisions made by policymakers, procurers, engineers, data curators, test authorities, mission planners, commanders, and operators. The final action is therefore one node in a sociotechnical lifecycle, not the only place where judgment exists.
A synthetic after-action timeline can be pulled backward from an external action to the configuration, test assumption, and policy record that enabled it.
An operator is not meaningfully in control merely because an interface displays an approval button. Meaningful judgment depends on understandable evidence, adequate time, manageable workload, authority to reject or delay, and a technically effective intervention path.
The system does not bear human legal or moral responsibility. Accountability analysis should examine distributed decisions, foreseeable constraints, testing, monitoring, overrides, incident response, and records of what each actor knew at the time.
COMPLETE DOSSIER
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
| Lifecycle stage | Human contribution | Machine contribution | Control question |
|---|---|---|---|
| Policy and procurement | Define permitted mission and safeguards | None or requirements modeling | Were prohibited uses and review gates explicit? |
| Design and data | Select architecture, labels, thresholds, interfaces | Learn or execute mappings from data | What assumptions and excluded cases were documented? |
| Mission configuration | Set area, time, object classes, corroboration, fallback | Load the authorized envelope | Was authority current, bounded, and auditable? |
| Live operation | Supervise, approve, intervene, or monitor | Sense, fuse, classify, prioritize, act | Did the human have time, information, authority, and a working intervention path? |
| After action | Investigate, remedy, revise, assign responsibility | Provide logs and reconstructed state | Can the chain be reproduced without hindsight rewriting? |
Pass condition:
Pass condition:
Pass condition:
Pass condition:
Pass condition:
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
Official operator or government statement; supports what that body says, not independent verification of performance.
Independent public evidence supporting a bounded capability, test, status, or deployment proposition.
Material public claim with unresolved attribution, mode, outcome, or corroboration; must remain attributed and nonfinal.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Explain systems, evidence, uncertainty, failure, oversight, and defense without reproducing targeting software, weapon configuration, attack procedures, evasion methods, or defeat advice.
CLAIM · SOURCE · LIMIT
| Claim block | Evidence class | Source | Supported proposition | Unsupported inference |
|---|---|---|---|---|
| lifecycle-map | OWNER_SUPPLIED_RESEARCH_SYNTHESIS | Autonomous Weapons Simulation Design.md | A system outcome can inherit decisions made by policymakers, procurers, engineers, data curators, test authorities, mission planners, commanders, and operators. The final action is therefore one node in a sociotechnical lifecycle, not the only place where judgment exists. | Does not by itself establish deployment, exact operating mode, combat use, effectiveness, legality, consensus, or endorsement. |
| meaningful-control | OWNER_SUPPLIED_RESEARCH_SYNTHESIS | AI Governance Simulation Specification Plan.md | An operator is not meaningfully in control merely because an interface displays an approval button. Meaningful judgment depends on understandable evidence, adequate time, manageable workload, authority to reject or delay, and a technically effective intervention path. | Does not by itself establish deployment, exact operating mode, combat use, effectiveness, legality, consensus, or endorsement. |
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE