Civic / Privacy / Digital Rights

Fully Autonomous Lethal Authority in Current Use

Report summary

Research cutoff: 31 July 2026. This report uses an intentionally strict definition of fully autonomous lethal authority : after a human activates or launches a weapon and establishes mission constraints, the system itself identifies or classifies a potential target, selects the specific target, and

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
6,195 words
Reading time
29 minutes
Report type
evaluation

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Research Archive
  • Audit
  • Architecture
  • Governance

Research provenance

Archive status
Research archive item
Content identity
sha256:581f402d74f65bac4fdf9c9463d06d19588eeac089f2f23fcf6845e15a0ae832

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

Source availability: 67 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

Executive summary

Research cutoff: 31 July 2026. This report uses an intentionally strict definition of fully autonomous lethal authority: after a human activates or launches a weapon and establishes mission constraints, the system itself identifies or classifies a potential target, selects the specific target, and initiates lethal force without target-specific human approval. A system is strictly human-out-of-the-loop when a human neither approves the individual engagement nor provides timely supervision capable of preventing it. This is narrower than the U.S. Department of Defense and International Committee of the Red Cross definitions of an autonomous weapon, both of which can include systems that remain under human supervision after activation.

The principal finding is that autonomous target selection and engagement are already operational, but the highest-confidence cases are tightly bounded defensive or anti-materiel systems rather than robots independently deciding which people to kill. These include the U.S. Phalanx close-in weapon system and SeaRAM, Israel’s Trophy active-protection system, and Israel Aerospace Industries’ Harpy anti-radiation loitering munition. Such systems can complete the detect–classify–select–engage sequence automatically against incoming missiles, rockets, anti-tank weapons, aircraft, or emitting radars. Their target environments and target profiles are much narrower than those involved in distinguishing individual combatants from civilians.

There is no high-confidence, independently verified public evidence that any state is routinely operating an anti-personnel weapon under standing doctrine that delegates open-ended authority to identify and kill people without human supervision. The strongest alleged exception is a one-off Ukrainian battlefield test reportedly conducted in 2024 and disclosed publicly in June 2026: a Ukrainian defense-industry figure said ten disconnected quadcopters were instructed to attack anything they identified in a designated area and killed Russian soldiers. The allegation is consequential but remains based principally on one industry source; no Ukrainian government confirmation, system logs, imagery, technical audit, or independent battlefield investigation has been made public.

Ukraine’s Saker Scout is a second important but uncertain case. Its manufacturer told Forbes in October 2023 that the system was conducting autonomous strikes, and public descriptions attribute onboard computer vision and autonomous target recognition to it. Yet no independently verified engagement record demonstrates that Saker, rather than a human operator, selected the specific target and authorized force. Subsequent Ukrainian official and military statements have continued to insist that humans approve strikes, while most fielded Ukrainian and Russian AI guidance systems autonomously track a target only after a human has selected it.

The widely cited March 2020 Kargu-2 episode in Libya is similarly unresolved. A United Nations panel described Turkish-made systems as having a “fire, forget and find” capability and said retreating forces were hunted by unmanned aircraft and lethal autonomous systems. The report did not establish that a Kargu-2 actually used its autonomous engagement mode against a person, nor did it attribute specific casualties to such a mode. STM’s chief executive subsequently said the weapon required operator verification and attack authorization.

For non-state armed groups, this review found no publicly verified case of a strict human-out-of-the-loop weapon selecting and lethally engaging its own targets. Non-state forces extensively employ mines, improvised explosive devices, homing munitions, one-way attack drones, and remotely piloted first-person-view drones, but these do not necessarily satisfy the target-selection criterion used here. The absence of evidence is not proof of absence: software configurations, rules of engagement, operator practices, and post-strike telemetry are usually classified or unavailable.

The most defensible answer to “who is currently using fully autonomous lethal authority?” is therefore:

  1. Confirmed at high confidence in narrowly bounded anti-materiel or defensive roles: the United States, Israel, and an incompletely disclosed group of allied customers operating systems such as Phalanx, SeaRAM, Trophy, and Harpy-family weapons.
  2. Claimed or technically capable, but autonomous combat use is not independently established: Russia, Ukraine, India, South Korea, China, Türkiye, and Libyan Government of National Accord forces.
  3. Confirmed routine autonomous selection and killing of human targets: no actor at high confidence; Ukraine is the strongest medium-to-low-confidence alleged case.
  4. Verified non-state use: none identified under the strict definition.

Definitions and analytical threshold

“Fully autonomous lethal authority” is not a standardized treaty term. It combines three distinct issues: technical autonomy, the human command arrangement, and the scope of delegated targeting authority. Governments often define the same system differently depending on whether they emphasize what the machine can do, whether a human can interrupt it, whether the target is a person or an object, and whether responsibility remains within a human chain of command. Academic comparative research identifies autonomy, adaptive capability, human control, and intended purpose as the central dimensions along which official definitions diverge.

For this report, a system possesses fully autonomous lethal authority when all of the following are true:

  • A human may define an area, time window, target class, mission, or no-strike constraints, but does not select the particular person or object ultimately attacked.
  • Sensors and software detect, recognize, classify, or otherwise nominate candidate targets.
  • The system chooses the specific target and initiates destructive force without target-specific human confirmation.
  • For the strictest “out-of-the-loop” category, no human is expected to monitor and intervene in time to stop the engagement.

A system can therefore be autonomous in the U.S. or ICRC sense while being merely human-on-the-loop in this report. Phalanx, for example, can conduct the complete engagement sequence automatically, but it is normally operated within a command structure and can be supervised or deactivated. Conversely, a loitering munition that loses communications after a human has locked it onto one specific tank remains semi-autonomous terminal guidance, not fully autonomous target selection.

Institution or actorWorking definition or emphasisPractical consequence
U.S. Department of DefenseAn autonomous weapon can, once activated, select and engage targets without further operator intervention; the category expressly includes operator-supervised systems that permit override. A semi-autonomous weapon engages an individual target or specific target group selected by an operator.Broadly includes human-on-the-loop defensive systems. “Fire-and-forget” and terminal homing can remain semi-autonomous where the human selected the target or specific group.
ICRCAny weapon that selects and applies force without human intervention after activation, generally by matching sensor data to a target profile; the user may not know exactly who or what will be struck, or when and where.Focuses on the autonomy of the critical functions, not on whether the platform uses artificial intelligence or whether an operator has an emergency abort function.
United KingdomEmphasizes “context-appropriate human involvement,” retained human responsibility, and clear authorities rather than a fixed technology-based threshold. A parliamentary inquiry separately described fully autonomous systems as systems that identify, select, and lethally engage without further intervention.A system may have extensive automatic functions without being considered “fully autonomous” if human responsibility and involvement are considered appropriate to the context.
FranceDistinguishes systems operating completely outside human control and a responsible chain of command from partially autonomous systems functioning within a constrained framework. France considers the former unacceptable and supports their prohibition.Defines “full autonomy” partly institutionally—escape from the chain of command—not merely by the absence of a button press before every engagement.
GermanyRejects systems that completely exclude human involvement from decisions to use lethal force.Places the decisive threshold at meaningful human participation in the lethal decision.
RussiaDefines a lethal autonomous weapon as a fully autonomous unmanned technical means, other than ordnance, carrying out combat or support missions without operator involvement.Excludes autonomous munitions such as loitering weapons from Russia’s preferred LAWS definition, even where they autonomously select and attack targets.
ChinaIts proposed “unacceptable” category cumulatively requires lethality, no human intervention during the entire task, impossibility of termination, indiscriminate killing, and autonomous evolution beyond human expectations. It allows highly autonomous systems that remain terminable and under human control.The cumulative test is much narrower than the ICRC or U.S. functional definitions and can exclude predictable, terminable autonomous weapons.
NGOs including Human Rights Watch and Stop Killer RobotsCenter the concept of meaningful human control, especially over systems that target people, and seek prohibitions on anti-personnel systems or systems inherently lacking such control.Treats the quality of human judgment, understanding, predictability, and intervention as more important than nominal supervision.
Academic usageOften distinguishes human-in-the-loop, human-on-the-loop, and human-out-of-the-loop systems, while warning that autonomy is multidimensional rather than a single scale.Supports separate judgments about target selection, navigation, tracking, firing, supervision, learning, and mission planning.

This report excludes ordinary mines and victim-activated improvised explosive devices from the main census. They apply force automatically, and the ICRC’s broad functional logic can encompass some sensor-triggered weapons, but mines are generally treated as a separate, long-regulated weapon class; DoD Directive 3000.09 expressly excludes mines from its scope. It also excludes AI-assisted intelligence systems, target-ranking software, and decision-support platforms where a human still authorizes the strike.

“Lethal authority” does not necessarily mean that the selected target is human. Phalanx selects missiles or aircraft, Trophy selects incoming anti-tank projectiles, and Harpy selects radar emitters. These are genuine autonomous selections followed by destructive force, but they pose a different identification problem from software asked to distinguish a surrendering combatant, wounded soldier, civilian, or protected medical worker. The ICRC consequently recommends categorical limits on autonomous weapons designed or used to apply force against persons, while regulating rather than necessarily prohibiting predictable anti-materiel systems.

Confidence terminology used below: “High” means official technical evidence plus credible evidence of deployment; “medium” means the capability or deployment is well supported but the exact operational mode is undisclosed; “medium-low” means a credible allegation or manufacturer statement lacks independent technical or incident verification; and “low” means the claim is contested, based largely on marketing, or contradicted by the manufacturer or operator.

Comparative assessment

The table is an all-publicly-supportable census, not a claim to know every classified program or every customer configuration. An operator can possess a system with autonomous engagement capability while keeping that mode disabled. Conversely, a nominally supervised system may function out of the loop during communications loss or extremely short engagement windows. The table’s confidence rating concerns evidence of actual human-out-of-the-loop lethal use, not merely evidence that the system exists.

Actor or operatorSystems and manufacturersStatus and documented deploymentAssessment of lethal autonomyConfidence
United StatesMk 15 Phalanx CIWS and land-based C-RAM, Raytheon/RTX; SeaRAM, Raytheon/RTX; Trophy on selected Abrams vehicles, RafaelPhalanx deployed since 1980 and operational across U.S. surface forces. USS Gravely shot down a Houthi anti-ship cruise missile on 30 January 2024; reputable reporting identified Phalanx as the last-line system used, although CENTCOM did not disclose the control mode.Phalanx and SeaRAM can automatically detect, evaluate, track, engage, and assess kills. U.S. doctrine permits operator-supervised autonomous engagement of materiel for local defense. Whether particular combat shots were completely unsupervised is usually unspecified.High for capability and deployment; medium for strict out-of-loop use in a named incident
IsraelTrophy APS, Rafael; Harpy/Harpy NG and Mini Harpy, Israel Aerospace IndustriesTrophy is operational and combat-proven. IAI calls Harpy fully autonomous and operational with several air forces, but does not publicly identify all customers or provide a dated customer-by-customer engagement log.Trophy autonomously intercepts incoming munitions. Harpy autonomously searches for and attacks emitting radars. These are bounded anti-materiel functions, not autonomous human identification.High for system capability; medium for current operator-specific autonomous combat use
IndiaMini Harpy and Harop, IAI; other loitering munitionsAn official January 2026 Indian government description included Mini Harpy and Harop in current force capabilities. IAI advertises Mini Harpy with both man-in-the-loop and fully autonomous operating options. No public source establishes which mode India enables operationally.Possesses a platform capable of autonomous anti-radiation engagement; actual delegation of target selection is unspecified. Harop itself is normally man-in-the-loop.Medium for possession; low for demonstrated out-of-loop use
South KoreaLegacy Harpy inventory, IAI; SGR-A1 sentry, Samsung Techwin/Hanwha and Korea UniversityHarpy deployment was publicly reported from 2000. SGR-A1 was developed and reportedly stationed for border surveillance, but current numbers, configurations, and rules of engagement are classified or disputed.Harpy has autonomous anti-radar capability. SGR-A1 can automatically detect and track people, but manufacturer statements have disputed autonomous firing. No autonomous shooting incident is documented.Low for present strict use
ChinaLegacy Harpy inventory, IAI; Blowfish A3, Zhuhai Ziyan UAVChina acquired Harpy systems in the 1990s; present readiness is unspecified. Blowfish A3 was marketed as highly or fully autonomous, but later technical/legal analysis reported that a human command was still required to fire. No verified autonomous combat deployment is public.Technical development and autonomous recognition are credible; strict lethal target selection has not been demonstrated.Low
RussiaZALA Z-53/Izdeliye-53 and Lancet family, ZALA AeroZALA currently states that Z-53 independently detects targets according to predetermined parameters. Russian authorities and media have claimed deployment in Ukraine, but independent researchers found inadequate evidence that Z-53 had actually conducted autonomous target-selection attacks.Autonomous detection is officially claimed; autonomous selection-and-engagement in combat remains unverified. Most documented Lancet attacks appear operator-directed or use autonomous terminal tracking after designation.Medium-low
UkraineSaker Scout, Saker; multiple unnamed AI-guided FPV systemsSaker was reported fielded in 2023, and the company claimed autonomous strikes. There is no independent telemetry or official incident record proving target selection without human approval. Ukraine has separately deployed many AI terminal-guidance systems while insisting that humans authorize strikes.Possible human-out-of-the-loop use, but evidence cannot distinguish autonomous target choice from autonomous tracking of a human-selected target.Medium-low
Ukraine, alleged one-off testTen unnamed AI quadcopters; developer and manufacturer unspecified publiclyA Ukrainian industry figure alleged in June 2026 that a 2024 test near the Bakhmut–Chasiv Yar sector used disconnected drones in a “Terminator” mode and killed Russian soldiers. No official confirmation or independently verifiable technical record is public.If accurate, this is the clearest reported human-out-of-the-loop anti-personnel engagement.Medium-low for allegation; low for independently verified incident
Libyan Government of National Accord forces and TürkiyeKargu-2 rotary-wing loitering munition, STMDeployed during the March 2020 fighting around Tripoli. A UN panel described autonomous “fire, forget and find” capability, but did not prove that the autonomous mode selected and killed a particular person. STM says operator verification and authorization were required.Technically plausible autonomous target prosecution; actual use and casualties remain contested.Low
Other Phalanx/SeaRAM customersPhalanx and SeaRAM, RTXThe manufacturer reports wide allied deployment; the current public manufacturer material does not supply a complete, mode-specific list of all operators.Systems can perform autonomous defensive engagements, but national operating modes and rules vary and are generally undisclosed.High for technical capability; low-to-medium for country-specific mode
Non-state armed groupsNo verified qualifying platformExtensive non-state use of missiles, one-way drones, FPV drones, mines, and IEDs is documented, but no reviewed case establishes autonomous target selection followed by lethal engagement under the strict definition.No confirmed case. Technical transfer or covert use cannot be excluded.Insufficient evidence

The distinction between system capability and operational delegation is crucial. India, for example, may possess Mini Harpy, and Mini Harpy has a fully autonomous option, without India necessarily permitting that option in combat. Likewise, a Phalanx operator may select a supervised automatic mode, while the weapon is nevertheless technically capable of completing the entire engagement chain without additional input.

Confirmed operational autonomy in bounded roles

United States — Phalanx, C-RAM, and SeaRAM. The Mk 15 Phalanx uses its own radar to search for threats, evaluate them, track them, fire a 20 mm Gatling gun, and conduct kill assessment. The U.S. Navy describes it as the only deployed close-in weapon system capable of autonomously performing its own search-through-kill-assessment functions. SeaRAM combines the Phalanx sensor and control architecture with Rolling Airframe Missiles and likewise automatically detects, evaluates, tracks, engages, and assesses anti-ship missile and aircraft threats.

The systems are operational rather than experimental. Phalanx Block 0 entered deployment aboard USS Coral Sea in 1980; later blocks followed in 1988 and 1999. Land-based Phalanx variants have been used for counter-rocket, artillery, and mortar defense. The target is generally an incoming weapon or aircraft, and the engagement window can be measured in seconds, making target-by-target human approval operationally impractical.

The clearest recent combat example is USS Gravely’s interception of a Houthi anti-ship cruise missile on 30 January 2024. CENTCOM confirmed the missile and interception; reporting citing U.S. officials identified the ship’s close-in weapon system as the interceptor. Neither source disclosed whether Phalanx was in fully automatic, supervised automatic, or another engagement mode. It is therefore evidence that an autonomous-capable weapon was used, but not definitive proof that the specific shot occurred with no timely human supervision.

U.S. policy is unusually explicit. DoD Directive 3000.09 requires “appropriate levels of human judgment,” testing, legal review, and compliance with rules of engagement. It nevertheless specifically permits operator-supervised autonomous weapons to select and engage materiel targets for local defense of installations, crewed platforms, remotely piloted vehicles, and autonomous vehicles against time-critical or saturation attacks. Other autonomous weapons require senior approval before formal development and again before fielding.

Accordingly, U.S. doctrine does not impose a universal target-specific human-veto requirement. It authorizes a bounded delegation: commanders decide when, where, and under what rules a defensive autonomous system is activated, after which the machine may select and engage individual incoming threats. The authority to employ the system remains human; the immediate engagement decision can be automated.

Israel — Trophy. Trophy is an active-protection system for armored vehicles. Its radars detect an incoming rocket-propelled grenade, anti-tank guided missile, recoilless-rifle round, or shaped-charge tank projectile; software classifies the trajectory and threat; and a countermeasure is fired to defeat it before impact. Rafael states that detection, classification, engagement, and neutralization occur within fractions of a second and can address threats arriving from multiple directions.

This is a high-confidence autonomous engagement capability because a tank crew could not manually track and authorize each interception within the available reaction time. The system’s target is the incoming munition rather than the person who launched it. Public manufacturer materials characterize Trophy as operational and combat-proven, but do not provide a complete dated incident log or identify the exact control configuration used in each interception. Specific standing rules of engagement and national authorization documents are unspecified publicly.

Trophy illustrates why “human-out-of-the-loop” does not always mean a machine has been granted moral or legal discretion equivalent to that exercised by a soldier. The crew activates a defensive envelope, the target profile is an incoming projectile on a threatening trajectory, and the response is constrained in time, distance, and direction. Nonetheless, under the functional ICRC and DoD definitions, it is an autonomous weapon engagement.

Israel and IAI customers — Harpy and Harpy NG. Harpy is a more consequential example because it is an offensive loitering munition. It can be launched without prior intelligence about a target’s exact location, fly to a pre-programmed search area, detect radar emissions using an anti-radiation seeker, identify relevant frequencies, choose an emitter matching its parameters, and dive onto it. IAI describes Harpy as “fully autonomous,” operational with several air forces, able to loiter for up to nine hours, and able to operate in contested or GNSS-denied environments.

In this architecture the human selects the mission, search area, target profile, and perhaps protected or excluded emitters, but the machine can determine which particular radar is attacked and when. It therefore satisfies this report’s target-selection criterion. Its target profile is a radiating radar rather than a visually identified human, making the classification problem relatively structured but not risk-free: civilian and friendly emitters, decoys, changed circumstances, or a radar located near civilians remain possible concerns.

IAI does not identify all current customer air forces on its product page. Public records document Harpy service or acquisition by Israel, India, South Korea, and China, although current inventory status, software versions, and authority to use autonomous mode are not equally clear for every country. IISS reports China’s acquisition of Harpy systems in the 1990s, while historical aviation reporting described service with Israel, India, and South Korea.

India provides the strongest current named customer evidence: a January 2026 Government of India description of military capabilities included Mini Harpy and Harop. IAI states that Mini Harpy combines electro-optical/infrared and anti-radiation seekers and offers either man-in-the-loop or fully autonomous operation. No public Indian document reviewed for this report states that the fully autonomous attack mode is enabled, tested, or authorized. Its legal authorization and actual engagement history are therefore unspecified.

Harop should not automatically be treated as equivalent to Harpy. IAI has explicitly described Harop as an electro-optical/infrared man-in-the-loop weapon, while describing Harpy as autonomous. Azerbaijan’s well-documented combat use of Harop in 2016 and 2020 therefore does not by itself demonstrate human-out-of-the-loop target selection.

Allied defensive operators. Phalanx, SeaRAM, and active-protection systems are exported widely, but a complete public census is not possible because manufacturers do not always identify customers, ships can change equipment during refit, and national navies do not publish automatic-mode settings. The relevant actor category is consequently larger than the named United States and Israel cases. The technical capability is well documented; the identity of every current operator and the degree of human supervision are not.

Claimed or contested offensive and anti-personnel use

Ukraine — alleged 2024 “Terminator mode” test. In June 2026, media reports attributed a striking account to Ukrainian defense-industry figure Alexander Kokhanovskyy. According to that account, a one-off 2024 mission used ten AI-controlled quadcopters near the Bakhmut–Chasiv Yar area. The drones reportedly operated without an active connection, were instructed to destroy targets encountered in a bounded area, attacked a vehicle, and killed Russian soldiers.

If the account is accurate, the event satisfies the strict definition: the humans allegedly selected the area and mission but did not identify each soldier or approve each strike. It would also be qualitatively different from automatic air defense because the system was reportedly classifying and attacking people and vehicles in a complex ground environment.

The evidence remains insufficient for a high-confidence historical conclusion. The specific drone model, manufacturer, computer-vision model, training data, target profile, geofence, no-strike constraints, abort logic, video record, command logs, and after-action report are unavailable. No Ukrainian ministry or military command has publicly confirmed the event. The central claim is therefore best classified as a credible but unverified disclosure, not as the first conclusively proven autonomous killing of humans.

It is also in tension with Ukraine’s subsequent public position. Reuters reported in November 2025 that Ukraine required human approval for strikes even as dozens of AI-assisted systems were being fielded. The alleged test was reportedly exceptional and potentially inconsistent with Ukraine’s own restrictions. No public Ukrainian doctrine expressly authorizing routine human-out-of-the-loop anti-personnel engagement has been identified.

Ukraine — Saker Scout. Saker Scout was reported deployed on the Ukrainian front in 2023. The system was originally derived from a civilian or agricultural platform and reportedly integrates with Ukraine’s Delta battlefield-information network. Public descriptions attribute onboard machine vision, recognition of dozens of target categories, autonomous navigation under jamming, and the ability to lock onto and attack targets. In October 2023, the company told Forbes that autonomous strikes without a human operator were occurring.

The claim is plausible because computer vision can classify visually distinctive military objects, and a small attack drone can continue after losing its communications link. Yet the available reporting does not resolve the decisive question: did the software independently choose the specific target from the environment, or did a human first designate the tank, artillery piece, or position before autonomous terminal guidance began? Nor is there an independently verified strike video showing the complete command and decision sequence.

Saker should therefore be treated as fielded, autonomy-capable, and possibly used out of the loop, but not conclusively proven. Its public rules of engagement, legal review, operating constraints, target-confidence thresholds, and authorization policy are unspecified.

Ukraine and Russia — widespread terminal autonomy. Both sides increasingly field drones that use onboard image recognition to maintain a target lock after communications are jammed or lost. Reuters documented dozens of Ukrainian systems and analogous Russian developments by late 2025. These capabilities can autonomously steer into tanks, vehicles, artillery, and other objects once selected.

That is militarily significant but generally falls short of strict fully autonomous lethal authority. A human often locates the target, places a tracking box around it, or commands the drone to begin its terminal attack. The system then solves navigation and tracking, not the prior legal and tactical decision about which target should be attacked. Under DoD terminology, terminal guidance toward an operator-selected target is semi-autonomous.

Russia — ZALA Z-53 and Lancet. ZALA’s current corporate material says the Z-53 can independently detect a target according to predetermined parameters. Earlier ZALA descriptions of the Lancet concept referred to loitering weapons that could independently detect a target and, if necessary, destroy it. The likely enabling technologies include electro-optical sensors, onboard image processing, object classification, autonomous navigation, and pre-programmed target signatures.

Russian government and media accounts have presented Z-53/Izdeliye-53 as an autonomous or swarm-capable weapon intended for use in Ukraine. Independent analysis, however, found no convincing public evidence that it had actually conducted a strike in which it autonomously selected the target. Most publicly released Lancet videos show operator cueing, reconnaissance-drone support, or target lock before the terminal phase.

Russia’s official policy further complicates classification. Its 2024 working definition of LAWS excludes “ordnance,” meaning that an autonomous loitering munition may fall outside the category Russia discusses internationally. Russia argues that existing international humanitarian law is adequate and opposes prematurely separating highly automated military systems into a category requiring prohibition. This position is permissive toward development, but it is not a public operational authorization for Z-53 to select human targets.

The appropriate status is manufacturer-confirmed autonomous detection; claimed testing or deployment; autonomous combat engagement unverified. Confidence is medium-low.

Türkiye and Libyan Government of National Accord forces — Kargu-2. The UN Panel of Experts on Libya reported that retreating Haftar-affiliated forces and logistics convoys were hunted by unmanned combat aircraft and lethal autonomous weapon systems, including STM’s Kargu-2, during the March 2020 fighting. The panel stated that the relevant systems could be programmed to attack without a continuing data connection, producing a “fire, forget and find” capability.

That language establishes that autonomous operation was relevant to the deployed systems, but it does not establish that a Kargu-2 autonomously recognized a particular person, selected that person, and detonated. The same passage also refers to “remotely engaged” targets, multiple weapon types, and aggregate casualties. The annex showed a recovered Kargu-2 but did not provide software configuration, engagement logs, or an attributable fatality.

STM chief executive Özgür Güleryüz subsequently said Kargu-2 was not designed to launch fully autonomous attacks; he described its autonomy as principally supporting navigation and differentiation among people, animals, and vehicles, with a human required to verify the target and authorize the attack.

The incident therefore remains a possible but unproven autonomous anti-personnel deployment. The actors involved were Libyan GNA forces using Turkish-supplied systems, with Türkiye’s exact operational role and the weapon’s selected mode unresolved. Public doctrine specifically authorizing autonomous anti-personnel use is unspecified, and Türkiye’s public position has emphasized human responsibility.

South Korea — SGR-A1. The SGR-A1 is a fixed sentry system developed by Samsung Techwin, now associated with Hanwha, and Korea University. It combines low-light and infrared sensing, range finding, pattern recognition, tracking, voice challenge, and a machine-gun interface. It was designed for surveillance and defense of the Korean Demilitarized Zone.

Some early descriptions characterized it as capable of autonomously identifying and destroying targets. Other accounts, including manufacturer statements, said automatic functions stopped at surveillance and tracking and that a human had to authorize live fire. An academic review described the operational arrangement as believed to be human-in-the-loop while acknowledging continuing uncertainty and claims of human-on-the-loop capability.

No independently documented incident shows SGR-A1 firing autonomously at a person. Current deployment numbers, software configuration, rules of engagement, and legal authorization are classified or unspecified. It belongs in the candidate census because its sensors and weapon interface could technically support autonomous engagement, but evidence of present strict use is low confidence.

China — Blowfish A3 and legacy Harpy. Chinese manufacturer Zhuhai Ziyan marketed the Blowfish A3 armed helicopter drone in connection with autonomous navigation, target recognition, and swarm functions. In 2019, the U.S. Secretary of Defense publicly accused China of exporting systems advertised as capable of lethal autonomous strikes.

Subsequent U.S. military legal analysis reported that Ziyan’s systems could organize and identify targets autonomously but did not fire until a human command was issued. On that account, Blowfish A3 is an autonomous reconnaissance and targeting platform with human-in-the-loop lethal action, not a strict fully autonomous weapon. No verified combat deployment has been identified.

China also acquired IAI Harpy anti-radiation weapons, which possess a genuine autonomous target-selection function. Public evidence does not establish whether the legacy systems remain operational, have been reverse-engineered into current Chinese systems, or have been used in combat.

China’s official diplomatic definition is exceptionally narrow. A weapon is “unacceptable” only where five characteristics—including no intervention throughout the task, inability to terminate, indiscriminate killing, and uncontrolled autonomous evolution—are present together. China says highly autonomous weapons may be acceptable if humans can suspend them and they remain reliable and manageable. No public Chinese doctrine authorizing autonomous selection and killing of people has been identified.

Non-state armed actors. Houthi, Hezbollah, Hamas, Islamic State-associated organizations, Russian and Ukrainian volunteer formations, and numerous other non-state or hybrid forces have used guided missiles, one-way attack drones, commercial quadcopters, remotely piloted loitering weapons, mines, and improvised explosive devices. Those weapons may navigate autonomously or detonate automatically, but the reviewed public record does not demonstrate a non-state system independently selecting a previously unidentified target and applying lethal force under the strict test.

The Houthi missile intercepted by USS Gravely, for example, followed guidance toward a ship or area but is not publicly known to have autonomously searched among multiple vessels and made its own target-selection decision.

A non-state actor could obtain target-recognition software, modify a commercial drone, or capture a state system without public disclosure. The conclusion is therefore “no verified case,” not “no capability exists.”

There is still no universally accepted treaty definition of an autonomous weapon and no dedicated global treaty prohibiting or comprehensively regulating the class. Existing international humanitarian law nevertheless applies: distinction, proportionality, precautions in attack, protection of persons hors de combat, command responsibility, and weapons-review obligations do not disappear because software executes part of the targeting process. The ICRC argues that existing law must be supplemented with new binding prohibitions and restrictions, especially for unpredictable systems and systems targeting people.

The legal question is not simply whether a machine can be “responsible.” Responsibility remains with humans and institutions that develop, approve, deploy, activate, and supervise it. The harder problem is whether those humans had enough information and control to make the legally required judgments about the anticipated target, civilian harm, proportionality, changed circumstances, surrender, and precautions. A narrow anti-missile engagement over open water poses a different legal foreseeability problem from a roaming anti-personnel drone in an urban area.

The United States does not prohibit autonomous lethal systems as a class. Directive 3000.09 establishes review, testing, reliability, cybersecurity, human-machine interface, legal-review, and senior-approval requirements. It explicitly facilitates operator-supervised autonomous anti-materiel defense while imposing higher-level approval on other autonomous systems. This is the clearest public national framework authorizing operational autonomous engagement under controlled conditions.

Russia argues that existing international law is sufficient, defines LAWS narrowly, and opposes immediate bans on highly automated military technology. Because its definition excludes ordnance, autonomous loitering munitions can be developed and employed without Russia conceding that they are LAWS.

China supports prohibiting a narrowly constructed category of “unacceptable” autonomous weapons while permitting highly autonomous, predictable, terminable, human-controlled systems. Its position formally preserves human control but leaves substantial space for systems that automatically detect, prioritize, track, and potentially engage under prior authorization.

France and Germany reject weapons operating completely beyond human control over lethal decisions. France supports a two-tier approach: prohibit systems outside human control and a responsible chain of command, while regulating partially autonomous weapons through legal review, technical safeguards, predictability, human command, and lifecycle controls. Germany similarly insists that humans retain the ultimate life-and-death decision.

The United Kingdom avoids defining autonomy solely by the number of automatic functions. Its policy emphasizes context-appropriate human involvement, human responsibility, clear authorities, safety, and accountability whenever AI-enabled weapons are deployed. This can permit extensive autonomy while rejecting the idea that responsibility is delegated to the machine.

Ukraine’s public practice and the alleged 2024 test are in tension. Ukrainian forces and officials have repeatedly described human approval as required for strikes, even as autonomy in tracking and navigation becomes widespread. The alleged “Terminator mode” mission, if accurate, appears to have been an exceptional test rather than an application of published doctrine. A formal public legal statement authorizing human-out-of-the-loop anti-personnel targeting is unavailable.

Israel, India, South Korea, and other operators of Harpy, Trophy, or similar systems do not publish the detailed rules that determine when fully automatic modes may be enabled, what target libraries are used, or what human supervision is required. System possession and technical capability can be established; the target-specific legal authorization and operational mode are generally unspecified.

NGOs and the ICRC use a more demanding standard than most military policies. Human Rights Watch advocates prohibiting systems that target people or inherently lack meaningful human control. The ICRC recommends prohibiting unpredictable autonomous weapons and autonomous weapons designed or used to apply force against persons, while imposing constraints on other systems’ target types, geographic and temporal scope, predictability, and human-machine interaction.

The central policy dispute is therefore not whether all automation must be banned. It is whether the law should draw the line at:

  • absence of a human button press before an individual engagement;
  • absence of meaningful supervision or intervention;
  • autonomous targeting of people;
  • unpredictability or inability to explain effects;
  • operation outside a responsible chain of command; or
  • inability to comply with international humanitarian law in the circumstances of use.

Different definitions can produce apparently contradictory national claims. A government may truthfully say it has no “fully autonomous weapon” under a definition requiring total absence of human command while simultaneously operating a weapon that selects and attacks individual targets automatically after activation.

Timeline, evidence gaps, and bottom line

The chronology below distinguishes the long-standing reality of bounded autonomous defense from the much more recent and still contested claims of autonomous anti-personnel attack. Phalanx entered deployment in 1980; Harpy emerged around the end of the 1980s; Trophy became combat-operational in the following decades; Kargu-2 was deployed in Libya in March 2020; Saker claims emerged in 2023; USS Gravely used Phalanx in January 2024; and the alleged Ukrainian “Terminator mode” test reportedly occurred in 2024 but was not disclosed until June 2026.

timeline
    title Publicly documented evolution of autonomous lethal engagement
    1980 : U.S. Navy begins deploying Phalanx CIWS
    Late 1980s–1990s : IAI develops and exports autonomous Harpy anti-radar loitering munition
    2010s : Trophy active-protection system becomes operational and combat-proven
    March 2020 : Kargu-2 deployed in Libya; autonomous engagement claim later disputed
    September–October 2023 : Ukraine fields Saker Scout; manufacturer claims autonomous strikes
    Late 2023 : Russia claims ZALA Z-53 autonomous target-detection capability and deployment
    January 2024 : USS Gravely uses Phalanx against a Houthi cruise missile
    2024 : Alleged Ukrainian ten-drone human-out-of-the-loop battlefield test
    2024–2025 : Ukraine and Russia scale AI terminal guidance and autonomous tracking
    June 2026 : Ukrainian industry figure publicly discloses the alleged 2024 test

Several evidence gaps prevent a definitive global inventory.

First, weapons generally have multiple modes. A Mini Harpy may operate man-in-the-loop or autonomously; a defensive gun may be in manual, semi-automatic, or automatic mode; a drone may receive human target designation and then continue autonomously after jamming. Public photographs or strike videos rarely reveal the selected mode.

Second, “communications lost” is not equivalent to autonomous target selection. A munition can continue homing toward a target selected before the link failed. Proof of strict autonomy requires evidence that the machine selected the target after activation from among candidate objects or people.

Third, manufacturer language is inconsistent. “Autonomous,” “AI-powered,” “fire-and-forget,” “smart,” and “automatic target recognition” are marketing terms as well as technical descriptions. A manufacturer may emphasize autonomy to customers and minimize it in diplomatic or legal debate. Kargu-2 and Blowfish A3 illustrate this problem.

Fourth, a system’s ability to recognize a category does not establish lawful target identification. Recognizing a “person,” “uniform,” “truck,” or “tank-shaped object” is not the same as determining combatant status, surrender, direct participation in hostilities, protected medical use, civilian ownership, proportionality, or whether circumstances have changed since launch.

Fifth, states rarely release engagement logs. Conclusive verification would require launch orders, mission parameters, target libraries, confidence thresholds, operator inputs, data-link records, onboard video, software version, intervention opportunities, and post-strike assessment. None is publicly available for the alleged Ukrainian test, Saker strikes, Z-53, or Kargu-2.

The resulting bottom line is deliberately narrower than many headlines:

Fully autonomous lethal engagement is not hypothetical. It is operational and well documented in close-in air defense, active protection, and anti-radar attack. The United States, Israel, and several customers or allies operate systems capable of selecting and destroying materiel targets without a new human decision for every engagement.

Fully autonomous anti-personnel engagement is technically plausible and may already have occurred, but the public record does not yet provide a high-confidence, independently verifiable case. Ukraine’s alleged 2024 test is the strongest claim; Saker Scout and Kargu-2 are important but less conclusive; South Korea’s SGR-A1 and China’s Blowfish A3 remain capability or configuration disputes.

No public evidence establishes routine, officially acknowledged standing delegation to machines to search for and kill human targets without supervision. Nor is there a verified non-state operator under the strict definition. Because operational modes, customer identities, and engagement records remain secret, “unspecified” is the appropriate finding for many actors—not an assumption that human control is necessarily present.