One-sentence brief
Precise vocabulary prevents a technical function, a policy document, or a simulation from being mistaken for autonomous lethal use or demonstrated operational effect.
AI KILL CHAINS & DECISION SYSTEMS
Definitions for kill chain, kill web, AI-enabled function, autonomy, evidence stage, human control, and defensive interruption.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.
Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.
Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.
ORIENTATION
Precise vocabulary prevents a technical function, a policy document, or a simulation from being mistaken for autonomous lethal use or demonstrated operational effect.
WORKING BRIEF
A chain emphasizes staged dependencies and interruption points. A loop emphasizes feedback, reassessment, and repeated action. A web distributes sensing, fusion, decision, and effect across many nodes. Real systems can exhibit all three structures, so a diagram should state which simplification it uses.
The viewer can switch between stage, feedback-loop, and dependency-graph views without changing the underlying event ledger.
A platform can navigate autonomously while a person retains release authority; a decision-support system can rank options without authorizing one; a defensive system can act inside bounded conditions under supervision. The relevant question is what the software may do after activation and what meaningful information, time, and intervention capability the human retains.
Each node shows allowed action, human gate, abort path, and irreversible boundary.
Public analysis should distinguish official policy, doctrine, procurement, manufacturer description, demonstration, controlled research, disclosed incident, independently observed deployment, and effects assessment. Multiple records can support different parts of one claim without becoming interchangeable.
Evidence cards retain source authority and what the record does not support.
A proposal is not adoption; adoption is not enactment; signature is not ratification; entry into force is not implementation or enforcement. A national directive establishes policy within its authority but does not prove universal law or compliance by a particular system.
The simulation labels policy gates separately from technical and operational states.
COMPLETE DOSSIER
No game connection is required to use this educational page.
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE