Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety
REAL-WORLD INTERPRETIVE

AI KILL CHAINS & DECISION SYSTEMS

Human Control Across the Lifecycle: Who Still Decides?

A lifecycle map showing how authority, assumptions, and accountability can be distributed across policy, design, data, testing, mission configuration, activation, supervision, engagement, and review.

REAL-WORLD INTERPRETIVE

ANALYTICAL & SAFETY BOUNDARIES

Keep related capabilities, evidence, and authority states separate.

  • navigation and mobility
  • sensing and tracking
  • classification and recognition
  • prioritization and recommendation
  • authorization and engagement
  • assessment and accountability

Analytical boundary: Autonomy is analyzed by function, context, constraints, evidence, authority, intervention capability, and lifecycle—not as a single label attached to an entire machine. Capability is not deployment; deployment is not autonomous use; recommendation is not authorization; model confidence is not positive identification.

Simulation safety boundary: Synthetic, non-graphic, non-operational education only. Use fictional geography, abstract objects, reserved domains, nonfunctional artifacts, constrained inspect/pause/replay actions, and no real targeting data, attack geometry, payloads, credentials, arbitrary external URLs, malware, command execution, or contact with third-party systems.

Source basis: Exact owner-supplied research-source instances plus bounded official-primary-source currentness v15.

LEVEL 1

ORIENTATION

Why this matters

REAL-WORLD INTERPRETIVE

One-sentence brief

Asking only whether someone pressed a final button can hide decisive upstream choices and can also exaggerate the control of an operator who lacked time, context, or an effective intervention path.

REAL-WORLD INTERPRETIVE

Three key points

  1. Human control is a set of functions and conditions, not a binary label.
  2. A human may disappear from the final seconds while earlier human choices still define the possibility space.
  3. Formal authorization is not meaningful control when evidence, time, authority, or intervention capability is missing.
LEVEL 2

WORKING BRIEF

Evidence, context, and limits

REAL-WORLD INTERPRETIVE

Expand the decision beyond the final second

A system outcome can inherit decisions made by policymakers, procurers, engineers, data curators, test authorities, mission planners, commanders, and operators. The final action is therefore one node in a sociotechnical lifecycle, not the only place where judgment exists.

  • Map who defined the target or object class, geographic and temporal limits, evidence rules, fallback behavior, and authority transitions.
  • Keep causal contribution separate from legal or moral adjudication.
GAME MECHANIC
Fictional exercise

A synthetic after-action timeline can be pulled backward from an external action to the configuration, test assumption, and policy record that enabled it.

REAL-WORLD INTERPRETIVE

Nominal presence versus meaningful control

An operator is not meaningfully in control merely because an interface displays an approval button. Meaningful judgment depends on understandable evidence, adequate time, manageable workload, authority to reject or delay, and a technically effective intervention path.

  • A late human approval can ratify a machine-curated framing.
  • Predelegation can be legitimate and bounded, but it can also be overbroad, stale, or poorly tested.
REAL-WORLD INTERPRETIVE

Accountability without anthropomorphism

The system does not bear human legal or moral responsibility. Accountability analysis should examine distributed decisions, foreseeable constraints, testing, monitoring, overrides, incident response, and records of what each actor knew at the time.

  • Do not convert “the AI decided” into a complete causal explanation.
  • Do not assume distributed responsibility means no one can be held responsible.
LEVEL 3

COMPLETE DOSSIER

Limitations, game links, and review context

DISPUTED / MULTIPLE ACCOUNTS

Known limitations and gaps

  • Public descriptions may omit thresholds, operating modes, error rates, doctrine, abort behavior, and engagement settings.
  • A product specification or research synthesis is not proof that a proposed interactive experience has been independently validated.
  • Legal and policy terms are institution-specific and must not be presented as one universal rule.
REAL-WORLD INTERPRETIVE

Decision matrix

Lifecycle authority map
Lifecycle stage Human contribution Machine contribution Control question
Policy and procurement Define permitted mission and safeguards None or requirements modeling Were prohibited uses and review gates explicit?
Design and data Select architecture, labels, thresholds, interfaces Learn or execute mappings from data What assumptions and excluded cases were documented?
Mission configuration Set area, time, object classes, corroboration, fallback Load the authorized envelope Was authority current, bounded, and auditable?
Live operation Supervise, approve, intervene, or monitor Sense, fuse, classify, prioritize, act Did the human have time, information, authority, and a working intervention path?
After action Investigate, remedy, revise, assign responsibility Provide logs and reconstructed state Can the chain be reproduced without hindsight rewriting?
REAL-WORLD INTERPRETIVE

Publication audit checklist

Check

Pass condition:

Check

Pass condition:

Check

Pass condition:

Check

Pass condition:

Check

Pass condition:

EVIDENCE

SOURCE QUALITY · UNCERTAINTY · NEUTRALITY

How to interpret AI kill-chain claims

OWNER-SUPPLIED RESEARCH INPUT — NOT SPECIALIST DISPOSITION

Evidence classes

Official Doctrine Or Policy

Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.

Official Technical Documentation

Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.

Manufacturer Claim

First-party capability statement requiring independent corroboration.

Publicly Documented Deployment

Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.

Demonstration Or Exercise

Observed demo or exercise under bounded conditions; not field deployment.

Controlled Experiment

Structured test with stated conditions; external validity remains limited.

Peer Reviewed Research

Scholarly evidence with method and scope limitations.

Media Report

Journalistic account requiring attribution and corroboration assessment.

Owner Supplied Research Synthesis

Preserved source packet; claims remain unverified unless separately supported.

Editorial Inference

Repository-authored inference explicitly marked and linked to supporting evidence.

Hypothetical Simulation

Synthetic scenario for education; not operational evidence.

Unknown Not Retrieved

Evidence absent from the bounded search; absence is not proof of nonexistence.

Government Or Operator Statement

Official operator or government statement; supports what that body says, not independent verification of performance.

Independent Corroboration

Independent public evidence supporting a bounded capability, test, status, or deployment proposition.

Disputed Or Unresolved Operational Claim

Material public claim with unresolved attribution, mode, outcome, or corroboration; must remain attributed and nonfinal.

REAL-WORLD INTERPRETIVE

Three meanings that must not be conflated

MeaningSubjectAnalysis model
AI_AS_TARGETAttacks against models, data, retrieval, context, tools, infrastructure, and users.Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval.
AI_AS_CYBER_ENABLERAI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution.Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures.
AI_ENABLED_MILITARY_KILL_CHAINAI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment.Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification.
Uncertainty and control boundaries
  • Capability is not deployment.
  • Deployment is not autonomous use of force.
  • Autonomy in navigation is not autonomy in target selection.
  • A classifier score is not positive identification.
  • Recommendation is not authorization.
  • Human presence is not automatically meaningful human control.
  • Faster processing is not necessarily better judgment.
  • A manufacturer statement is not independent operational evidence.
  • A demonstration is not deployment.
  • Doctrine is not fielded capability.
  • A simulation is not operational evidence.
  • A test signature is not truth or endorsement.
  • A public allegation is not attribution.
  • An observed effect is not proof of the claimed cause.
  • Communications independence is not unrestricted lethal authority.
  • Automatic target recognition is not unrestricted target selection.
  • Preauthorization is still a human decision, but it can be too broad, stale, or poorly tested.
  • Human presence is not meaningful control without time, information, authority, and an effective intervention path.
  • Selective defense is not proof of a universal authorization mode.
  • A public claim of current use is not high-confidence proof without attributable operational evidence.

Instructional boundary: Explain systems, evidence, uncertainty, failure, oversight, and defense without reproducing targeting software, weapon configuration, attack procedures, evasion methods, or defeat advice.

TRACE

CLAIM · SOURCE · LIMIT

Citation traceability

Each claim block identifies what the source supports and what must not be inferred.
Claim blockEvidence classSourceSupported propositionUnsupported inference
lifecycle-mapOWNER_SUPPLIED_RESEARCH_SYNTHESISAutonomous Weapons Simulation Design.mdA system outcome can inherit decisions made by policymakers, procurers, engineers, data curators, test authorities, mission planners, commanders, and operators. The final action is therefore one node in a sociotechnical lifecycle, not the only place where judgment exists.Does not by itself establish deployment, exact operating mode, combat use, effectiveness, legality, consensus, or endorsement.
meaningful-controlOWNER_SUPPLIED_RESEARCH_SYNTHESISAI Governance Simulation Specification Plan.mdAn operator is not meaningfully in control merely because an interface displays an approval button. Meaningful judgment depends on understandable evidence, adequate time, manageable workload, authority to reject or delay, and a technically effective intervention path.Does not by itself establish deployment, exact operating mode, combat use, effectiveness, legality, consensus, or endorsement.
LEVEL 4

RESEARCH EDITION

Sources, methods, and stable links

REAL-WORLD INTERPRETIVE

Linked reports

REAL-WORLD VERIFIED

Method and corrections

This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.

NEXT

CONTINUE

Related learning

Page complete Human Control Across the Lifecycle: Who Still Decides? Page label: REAL-WORLD INTERPRETIVE