.NET / SQL / Enterprise Engineering

AI-Enabled Kill Chains and the Weapon Systems That Use Them

Report summary

An AI-enabled kill chain is an operational sequence in which artificial intelligence or machine-learning functions assist, automate, or autonomously perform one or more steps between sensing a potential target and assessing the effects of an engagement. The traditional U.S. dynamic-targeting formula

Status
Research archive item
Category
.NET / SQL / Enterprise Engineering
Length
7,176 words
Reading time
33 minutes
Report type
evaluation

Key topics

  • .NET / SQL / Enterprise Engineering
  • .NET
  • SQL
  • Enterprise Engineering
  • AI
  • Runtime
  • Privacy
  • Physics
  • Semantic Systems

Research provenance

Archive status
Research archive item
Content identity
sha256:796d25d069b208000ec4f937dd33e1968174036ecd2d9ea225d68d08580b6edf

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

Source availability: 74 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

Executive summary

An AI-enabled kill chain is an operational sequence in which artificial intelligence or machine-learning functions assist, automate, or autonomously perform one or more steps between sensing a potential target and assessing the effects of an engagement. The traditional U.S. dynamic-targeting formulation is often summarized as find, fix, track, target, engage, assess, while contemporary “kill web” concepts distribute those functions across multiple sensors, command nodes, communications networks, and effectors rather than keeping them on one platform. AI can enter at any point: image interpretation, multisensor fusion, target classification, prioritization, weapon–target pairing, route planning, fire-control computation, autonomous terminal guidance, or battle-damage assessment. An AI-enabled chain is therefore not necessarily an autonomous weapon; Project Maven, for example, applies computer vision to imagery analysis, whereas Phalanx CIWS can autonomously complete a defensive detect-to-engage sequence without any public claim that its core fire-control logic uses machine learning.

The most important analytical distinction is between autonomy of individual functions and autonomy over the use of force. A vehicle may navigate autonomously while a human retains exclusive firing authority; a munition may classify a ship autonomously after a human has selected the engagement area; or a defensive system may select and engage incoming materiel threats while an operator supervises and can abort. At the highest level of lethal autonomy, a system activated with a generalized target profile can select and engage specific targets without further human intervention. The U.S. Department of Defense and the International Committee of the Red Cross use broadly similar functional definitions of this last category, although they advocate different regulatory approaches.

Publicly documented systems occupy a spectrum rather than a binary “autonomous/not autonomous” divide. At one end are AI-assisted intelligence and command systems such as Project Maven, TITAN, IBCS-related networks, and Northrop Grumman’s ABMC2 architecture. In the middle are semi-autonomous missiles and robotic platforms such as LRASM, NSM/JSM, SPICE, Switchblade, Collaborative Combat Aircraft, and weaponized ground robots whose navigation, classification, or mission execution is automated but whose lethal-control arrangements are bounded or incompletely disclosed. At the more autonomous end are defensive systems such as Phalanx and anti-radiation loitering munitions such as Harpy, which the manufacturer says can autonomously seek and strike emitting radars after launch.

The strongest operational incentives for AI are speed, scale, reduced analyst workload, operation under communications constraints, and the ability to coordinate dispersed sensors and weapons. The corresponding risks are tightly coupled: false classification at machine speed, automation bias, adversarial deception, cyber compromise, brittle behavior outside training conditions, fratricide, civilian harm, compressed escalation timelines, and diffusion to actors with weak safety institutions. Networked kill chains also create systemic risk: a plausible but incorrect track can propagate from a sensor through data fusion and automated weapon assignment to several effectors. NIST’s adversarial-machine-learning taxonomy identifies evasion, poisoning, privacy, and other lifecycle attacks, while DoD policy requires realistic testing against adaptive adversaries, analysis of emergent behavior, cyber testing, post-fielding monitoring, and revalidation after material changes.

As of July 31, 2026, there is no dedicated global treaty prohibiting or comprehensively regulating autonomous weapon systems. Existing international humanitarian law applies, national weapons reviews remain required for states party to Additional Protocol I, and parallel norm-building continues through the Convention on Certain Conventional Weapons, United Nations General Assembly resolutions, the U.S.-sponsored Political Declaration on Responsible Military Use of AI and Autonomy, NATO responsible-use principles, and calls by the ICRC and others for legally binding prohibitions and restrictions. Export-control regimes such as the Missile Technology Control Regime and Wassenaar Arrangement control many delivery systems, military components, software, and dual-use technologies, but do not form a complete autonomy-specific nonproliferation regime.

Definitions and analytical model

A kill chain is the end-to-end sequence by which a military force converts information into an intended operational effect. In dynamic targeting, the familiar F2T2EA sequence is find, fix, track, target, engage, assess. “Fix” establishes sufficient confidence in identity and location; “target” includes validation, prioritization, collateral and legal considerations, and selection of a course of action; “engage” applies the effect; and “assess” determines whether the objective was achieved. Positive identification and combat identification are distinct controls within this sequence rather than synonyms for an AI classifier’s confidence score.

An AI-enabled kill chain uses AI in at least one consequential chain function. It need not contain a lethal autonomous weapon, and the AI need not directly “decide to kill.” A computer-vision model that flags vehicles for an analyst, a fusion engine that correlates radar and electronic-support tracks, an optimizer that recommends an interceptor, and a missile seeker that recognizes a ship class are all AI-enabled links, but they transfer different amounts of authority to software. The appropriate unit of analysis is therefore the function–context pair: what function is autonomous, under what environmental, temporal, geographic, target-class, and rules-of-engagement constraints?

flowchart LR
    A[Mission objectives and constraints] --> B[Sensing]
    B --> C[Preprocessing and data fusion]
    C --> D[Detection, classification and identification]
    D --> E[Target validation, prioritization and decision support]
    E --> F[Weapon-target pairing and assignment]
    F --> G[Human authorization or autonomous release condition]
    G --> H[Engagement, guidance and terminal discrimination]
    H --> I[Effects and battle-damage assessment]
    I --> B

    J[Rules of engagement and legal constraints] -. constrain .-> E
    J -. constrain .-> F
    J -. constrain .-> G
    K[Human supervision and abort controls] -. monitor .-> G
    K -. intervene .-> H
    L[Cybersecurity, safety kernel and runtime assurance] -. protect .-> C
    L -. protect .-> F
    L -. protect .-> H

This conceptual model synthesizes joint-targeting doctrine, DoD autonomy policy, and current sensor-to-shooter architectures. A real system may combine several boxes in one weapon, as Phalanx does, or distribute them across satellites, aircraft, ground stations, command networks, and interceptors, as envisioned by JADC2, TITAN, IBCS, and the Space Development Agency’s Tracking Layer.

Kill-chain componentTypical inputs and functionsCommon AI contributionPrincipal control question
SensingRadar returns, EO/IR imagery, radio-frequency emissions, sonar, acoustic data, telemetry, cyber and space dataAdaptive signal processing, anomaly detection, sensor management, autonomous search patternsIs the sensor observing a lawful and operationally relevant area, and how are spoofed or degraded observations detected?
Data fusionMultiple observations, tracks, metadata and intelligence reportsTrack association, probabilistic fusion, correlation, deduplication and confidence estimationCan source provenance, uncertainty, contradictory reports and stale data be displayed rather than hidden?
Detection and classificationImage chips, video frames, signatures, movement patterns and emissionsObject detection, segmentation, recognition, behavior classification and target-profile matchingDoes “model confidence” correspond to reliable identification under the actual conditions of use?
Decision supportTarget attributes, commander’s intent, legal restrictions, defended assets and expected effectsRanking, prioritization, course-of-action generation, threat assessment and predictionIs the system recommending, filtering, or effectively determining the human’s choice?
Weapon assignmentAvailable effectors, geometry, inventories, probability of kill, collateral constraints and timingOptimization, automated sensor–weapon pairing and resource allocationCan a human understand why a particular effector was paired with a track, and can the recommendation be rejected?
EngagementFire authorization, seeker data, navigation and terminal updatesAutonomous guidance, aim-point selection, target discrimination, cooperative behavior and abort/re-attack logicWho chooses the particular object that receives force, and who can intervene before effects become irreversible?
AssessmentPost-strike imagery, radar tracks, telemetry and operational reportingChange detection, damage classification and reattack recommendationsCould an erroneous assessment automatically generate repeated attacks or expand a target list?

The table’s functions are reflected in Project Maven’s imagery extraction, TITAN’s fusion of space-to-terrestrial data, ABMC2’s AI classification and automated pairing, NSM’s autonomous target recognition, and DoD requirements for transparent human-machine interfaces and system-status feedback.

Human-control terminology is not globally standardized. In this report, “human-in-the-loop” means an affirmative human action is required before the system applies force to a particular target or engagement; “human-on-the-loop” means the system can select and engage after activation while a human supervises and can intervene; and “human-out-of-the-loop” means no human intervention is required after activation for target selection and engagement. The U.S. directive calls the middle arrangement an “operator-supervised autonomous weapon system.” A human who merely presses a launch button before an unpredictable sequence is not necessarily exercising meaningful control; knowledge, time, information quality, intervention capability, and the scope of delegated action matter.

Control mode used in this reportMachine authority after activationHuman roleTypical examples or contexts
Human-in-the-loopNavigation, tracking, classification, cueing, or aiming may be automated, but lethal release requires human authorizationReviews target and context; affirmatively authorizes each engagementWeaponized THeMIS and Rheinmetall Mission Master configurations publicly described as requiring human firing decisions
Human-on-the-loopSystem may select and engage within bounded parametersSupervises status and can abort, deactivate, or overrideLocal point defense against time-critical missiles; operator-supervised autonomous anti-materiel defense
Human-out-of-the-loop after activationSystem independently matches sensor observations to a target profile and initiates engagementEstablishes mission parameters before launch but does not approve each selected targetManufacturer-described autonomous anti-radiation loitering mode of Harpy
Hybrid or selectableDifferent modes provide different distributions of authorityHuman role varies by mission modeMini Harpy’s advertised man-in-the-loop and fully autonomous options
Unspecified publiclyPublic descriptions do not establish who authorizes weapon release or whether abort is always availableCannot be reliably classifiedSeveral AI-enabled missiles, loitering munitions and developmental combat-aircraft programs

These labels describe engagement authority, not overall sophistication. THeMIS has AI-enabled mobility but human-controlled weapons; a legacy defensive weapon may have little or no machine learning yet possess greater authority to engage automatically.

System categories and real-world examples

The following comparisons use public information available through July 31, 2026. “AI” is used narrowly where a source expressly describes AI, machine learning, deep learning, automatic target recognition, or learned autonomy. “Algorithmic automation” means an automated kill-chain function is documented but no reliable public source establishes that the operational function uses a learned model. Manufacturer statements are identified as such and should not be treated as independent verification of combat performance.

SystemCountry or operatorManufacturerAI or autonomous kill-chain rolePublic sensorsWeapon or effectAssessed control modeDeployment status
LRASMUnited States Navy and Air ForceLockheed MartinSemi-autonomous navigation, contested-environment routing and terminal target discrimination; manufacturer calls it an “intelligent” anti-ship missilePublicly described multimodal seeker and weapons data link; exact architecture classifiedLong-range anti-ship cruise missile warheadHuman mission authorization before launch; post-launch autonomy; exact engagement mode unspecified publiclyOperational/fielded in U.S. service
Naval Strike MissileRoyal Norwegian Navy and several allied usersKongsberg Defence & AerospaceImaging-infrared autonomous target recognition, ship-class identification, aim-point selection and terminal discriminationPassive high-resolution imaging-IR seeker; inertial/GNSS and terrain-referenced navigation are publicly associated with the missile familyAnti-ship and land-attack missileHuman-selected mission/target area with autonomous terminal recognition; detailed intervention capability unspecified publiclyOperational; Kongsberg identifies NSM as a principal Royal Norwegian Navy weapon
Joint Strike MissileNorway; integrated for F-35 and selected by additional usersKongsberg Defence & AerospaceTarget detection, identification, discrimination and ATR in cluttered sea/land environmentsPassive seeker including imaging IR; detailed fusion architecture not publicAir-launched anti-ship/land-attack cruise missilePost-launch autonomy within planned mission; precise control mode unspecified publiclyQualification and integration completed; procurement/fielding varies by operator
SPICE familyIsrael and export customersRafael Advanced Defense SystemsManufacturer-described scene matching, electro-optical target recognition and GPS-independent terminal identificationEO/IIR seeker; stored reference imagery and navigation data depending on variantGuided glide bomb/stand-off precision weaponHuman selects intended target before release; terminal discrimination autonomous; abort and retarget details unspecified publiclyOperational and exported; exact software capabilities are proprietary manufacturer claims
HarpyIsrael-origin system; IAI states it is operational with several air forcesIsrael Aerospace IndustriesAutonomous search for, identification of, and attack on emitting air-defense radarsAnti-radiation/RF seekerLoitering munition warhead for suppression or destruction of enemy air defensesOut-of-loop after activation in advertised autonomous mode, bounded to emitting target profiles and mission areaOperational according to manufacturer
Mini HarpyOperators unspecified publicly on product pageIsrael Aerospace IndustriesDual-mode targeting of emitting and non-emitting targets; autonomous and operator-controlled optionsCombined EO/IR and anti-radiation seekerSeven-kilogram-class loitering-munition warheadHybrid: man-in-the-loop or fully autonomous optionProduct offered; specific fielding and combat status unspecified publicly
HaropIsrael and export usersIsrael Aerospace IndustriesLoitering, detection, recognition, acquisition and attack; EO seeker supports operator identificationEO/IR payload and communications linkLoitering-munition warheadPublic descriptions commonly indicate man-in-the-loop EO engagement; other mode details unspecifiedManufacturer describes system as combat proven
SkyStrikerIsrael-origin; customers include an unnamed European customer under a publicized contractElbit SystemsAutonomous navigation, search and acquisition of an operator-designated targetEO/IR seeker; datalink details proprietaryInterchangeable five- or ten-kilogram warhead configurations“Fully autonomous” mission execution toward operator-designated targets; authority to select an unplanned target not established publiclyIn production/export; operational details by customer unspecified
Switchblade 600 Block 2United States Army and approved customersAeroVironmentOnboard AI/ML automatic target recognition detects and classifies stationary and moving threats, reducing operator workloadDual gimbaled EO/IR sensors; communications relay/handoffPrecision anti-armor loitering munitionAI classification documented; final weapon-release arrangement unspecified publicly and should not be inferred from “autonomously detects”U.S. Army delivery order announced in February 2026; procurement/fielding underway
Phalanx Block 1B CIWSUnited States Navy and allied naviesRTX/Raytheon lineageComplete automated local-defense chain: search, detection, evaluation, tracking, engagement and kill assessment; no public evidence that core operational logic is ML-basedSearch/track radar plus stabilized electro-optical sensor in Block 1BM61A1 20 mm Gatling gunOperator-supervised autonomous local defense; automatic engagement modes are configuration- and doctrine-dependentDeployed since 1980; Block 1B fielded since 1999 and continuously upgraded
Iron DomeIsraeli Air Force; exported derivatives/configurationsRafael prime contractor, with ELTA radar and other partnersAutomated detection, track classification, trajectory prediction, defended-area assessment and interceptor assignmentMulti-mission radar and command-and-control dataTamir interceptor against rockets, artillery, mortars and selected aerial threatsOperator supervision is public; exact human authorization requirement for each mode unspecified publiclyOperational and combat deployed; AI/ML use in the core engagement algorithm is not publicly established
FQ-42 and FQ-44 Collaborative Combat AircraftUnited States Air ForceGeneral Atomics and AndurilModular “mission autonomy” for collaborative sensing, maneuver and combat behaviors alongside crewed aircraft; autonomy software separated from airframe hardwareOperational sensor suite and final weapons fit not fully public; YFQ-44 has undergone captive-carry testing with inert storesIntended combat-capable air-to-air and other mission effects; exact weapons unspecified publiclyOfficially described as semi-autonomous human-machine teaming; weapon-release authority unspecified publiclyEngineering/manufacturing and production contracts awarded in June 2026; mission-autonomy competition continues, with primary provider selection planned for 2027
THeMIS Combat UGVDelivered in several configurations to multiple countries; combat variant publicly delivered to ThailandMilrem RoboticsAI-enabled navigation, follow-me, return-home, waypoint travel and obstacle avoidance; autonomous functions expressly limited to mobilityConfiguration-dependent cameras, EO/IR and remote-weapon-station sightsMachine guns, grenade launchers, anti-tank missiles or loitering-munition payloads depending on integrationHuman-in-the-loop for weapons; manufacturer states autonomous functions are limited to mobilityPlatform fielded internationally; weapon and AI configurations vary by operator
Mission Master SP/XTDemonstrated to and evaluated by several armed forcesRheinmetall CanadaAutonomous mobility, follow-me, convoy behavior and networked sensor-to-effector cueing; surveillance vehicle can pass a detected threat location to an armed vehicleEO surveillance mast and remote-weapon-station sights depending on moduleMachine gun or guided-rocket fire-support modules demonstratedHuman-in-the-loop: Rheinmetall states targets are never engaged automatically and a human controls kinetic decisionsDemonstration, evaluation and limited procurement status varies; broad operational fielding unspecified publicly

Category findings

Air-to-air systems. Public evidence of operational AI making independent lethal air-to-air engagement decisions remains limited. The clearest documented trajectory is the U.S. Collaborative Combat Aircraft program, the DARPA Air Combat Evolution experiments, and AI-controlled F-16 test aircraft. ACE demonstrated machine control in air-combat maneuvering and human–machine trust research, but test aircraft are not equivalent to an operational autonomous air-to-air weapon. CCA contracts now cover combat-capable aircraft and mission-autonomy software, yet public sources do not establish autonomous missile-release authority.

Air-to-ground and cruise missiles. The most mature AI-adjacent capability is autonomous terminal recognition rather than strategic target selection. NSM/JSM and SPICE compare seeker imagery or signatures with stored target characteristics, discriminate objects in clutter, and choose an aim point after launch. LRASM combines autonomous navigation and multimodal sensing to operate when external communications and navigation are degraded. These are best understood as bounded post-launch autonomy against a human-designated target or target class, not unrestricted machine generation of targets.

Loitering munitions. This category spans remotely authorized precision weapons, AI-aided target recognition, and systems capable of autonomous target-profile matching. Harpy is the clearest public example of the latter because its anti-radiation seeker autonomously seeks emitting radars. Mini Harpy advertises both supervised and fully autonomous options, while Switchblade 600 Block 2 expressly uses onboard AI/ML for detection and classification but does not publicly specify every element of fire authorization. Marketing terms such as “fully autonomous” must be parsed carefully: SkyStriker’s autonomy is described in relation to locating and striking an operator-designated target.

Naval close-in defense and ground-based air defense. Short reaction times and saturation threats have long driven automatic engagement modes. Phalanx is a self-contained detect-to-kill system, and integrated air-defense systems automate tracking, threat evaluation, interceptor calculations, and sensor–weapon coordination. These systems are often called “autonomous,” but their algorithms may be deterministic or model-based rather than machine learning. Their target sets are generally bounded to incoming materiel threats, a context specifically recognized in U.S. policy for operator-supervised autonomous local defense.

Autonomous vehicles and robots. Publicly documented Western armed ground vehicles generally separate autonomous mobility from lethal authority. Milrem says THeMIS’s autonomous functions are restricted to mobility and its weapon is controlled by a human; Rheinmetall makes a similar explicit commitment for Mission Master. Type-X is advertised as autonomously navigating with AI and human-in-the-loop control, but its operational deployment status is not clearly established. This functional separation is a recurring safety architecture: the autonomy stack may drive, follow, avoid obstacles, or orient sensors, while a distinct fire-control channel requires human authorization.

Swarms. Swarming adds distributed task allocation, cooperative search, formation control, resilient communications, and emergent group behavior to the chain. DARPA’s OFFSET program demonstrated autonomous air-and-ground teams and human–swarm interfaces using hundreds of small robots, but the public demonstrations centered on experimental tactics and open architectures rather than a fielded autonomous lethal swarm. Swarms should therefore be divided into unarmed collaborative sensing, human-authorized coordinated attack, and fully decentralized lethal selection; public programs frequently demonstrate the first two while leaving lethal authority unspecified.

Kill-web enablers, ISR and networked architectures

Many of the most consequential AI kill-chain systems are not weapons themselves. They are decision and connectivity layers that generate tracks, nominate targets, allocate sensors, or transmit targeting-quality data to effectors. These systems can alter the speed and scale of lethal operations even when a human remains responsible for each weapon release.

System or programCountry/operator and developerRole in the kill chainAI and data functionsConnected weapons or effectsStatus as of July 2026
Project MavenU.S. Department of Defense/CDAO ecosystem; multiple contractorsISR exploitation and target-cue generationComputer vision and deep neural networks extract and classify objects of interest in full-motion video and still imageryOutputs support analysts, commanders and downstream targeting; it is not itself a weaponOperationally introduced beginning in 2017; later details and deployments are partly classified
Tactical Intelligence Targeting Access NodeU.S. Army; Palantir selected for the advanced prototypeMultidomain ISR fusion and target nominationAI/ML processes data from space, high-altitude, aerial and terrestrial sensors to reduce sensor-to-shooter timeSends intelligence and target nominations to fires and command networks rather than carrying a weaponPrototype award in 2024; prototype maturation and deliveries continued through 2025
Integrated Battle Command SystemU.S. Army; Northrop GrummanIntegrated air-and-missile-defense command networkFuses tracks and decouples sensors, command posts and launchers; public Army descriptions emphasize network integration rather than a confirmed ML modelCan connect Patriot and other radars/interceptors; integrations expand over timeFielded and undergoing continuing integration, including LTAMDS-related testing; exact AI use unspecified publicly
ABMC2 architectureNorthrop Grumman; offered across U.S. joint missionsMultidomain battle management and long-range kill chainsManufacturer advertises AI/ML target classification, pattern-of-life analysis, automated sensor–weapon pairing, and autonomous allocationPlatform-agnostic integration with strike, airborne warning, surveillance and command systemsComponents described as mission proven; scope and deployment of the complete product architecture unspecified publicly
SDA Tracking LayerU.S. Space Force/Space Development Agency; multiple satellite manufacturersSpace-based missile warning, tracking and targeting dataAlgorithms, novel processing and fusion across sensors and orbital regimes generate tactical data productsCues missile-defense and other command-and-control networks; satellites are sensors, not weaponsTranche deployments and demonstrations underway; architecture expanding in successive tranches
Blackjack/Pit BossU.S. DARPA and industry performersOn-orbit mission management and distributed satellite autonomyAutonomous tasking, processing and management of proliferated low-Earth-orbit payloadsPrimarily sensing and communications; potential downstream support to military usersExperimental/demonstration program; operational weapon linkage unspecified
Ghost Fleet Overlord and Navy large USV workU.S. Navy/DARPA-origin effort and contractorsAutonomous maritime navigation, distributed sensing and potential payload carriageAutonomous transit, mission planning and supervisory controlFuture payloads may include sensors, electronic-warfare systems or weapons; release authority varies and is often not publicOverlord transitioned to the Navy; follow-on large and medium USV development continues
OFFSETDARPA; Northrop Grumman and Raytheon BBN integratorsHuman-commanded collaborative swarm operationsDistributed autonomy, tactic generation, task allocation and human–swarm interfacesPublic testbeds used small aerial and ground robots; lethal payload use was not the central public demonstrationResearch program completed final field experiment in 2021; capabilities inform later programs
CROO satellite cyber defenseU.S. Space Force-related research and contractorsCyber-physical protection of spacecraft and mission systemsOnboard AI/ML detects and responds to cyber anomalies with limited ground contactDefensive cyber effects preserve satellite functions supporting command, warning and targetingResearch/development and demonstration status; operational scale unspecified publicly

This table illustrates why “AI-enabled weapon” and “AI-enabled kill chain” should not be used interchangeably. Project Maven and TITAN influence the identification and nomination of targets; ABMC2 and IBCS influence fusion and weapon assignment; SDA satellites provide tracking data; and an interceptor or munition applies force. Legal and safety review must therefore cover not only the terminal weapon but the system of systems, including upstream data transformations that can constrain or predetermine a human’s apparent choice.

A networked kill web also creates a distinction between local and global autonomy. A missile may have a locally bounded seeker, while a remote AI system has already classified, ranked and routed its target track through a command network. Conversely, an autonomous vehicle may independently navigate but receive a tightly controlled human-authorized target message. Assessing only the last link can miss automation bias and upstream identification errors; assessing only the command network can miss terminal seeker behavior and communications-loss modes.

Technical architectures and common AI techniques

Most AI kill-chain architectures combine five technical layers: heterogeneous sensors; data transport and time synchronization; fusion and world modeling; decision or mission autonomy; and an independently safety-critical fire-control or effects layer. Architectures vary from a self-contained weapon such as Phalanx or Harpy to a distributed network in which satellites, aircraft, ground stations, command applications and launchers are separated by hundreds or thousands of kilometers.

Sensing and preprocessing. Radar and RF systems estimate range, bearing, velocity, frequency and emitter characteristics; EO/IR systems provide visual and thermal imagery; acoustic and sonar arrays provide time- and frequency-domain signals; and space sensors provide wide-area infrared or radar observations. Preprocessing includes stabilization, calibration, clutter rejection, denoising, georegistration and timestamp alignment. AI may improve detection in clutter, but learned preprocessing can also suppress weak but real observations or amplify artifacts that differ from training data. NSM’s passive imaging-IR seeker, Harpy’s anti-radiation seeker, Switchblade’s dual EO/IR sensors and the SDA Tracking Layer illustrate the diversity of sensor-to-classifier interfaces.

Sensor fusion and tracking. Classical architectures use Kalman-family filters, Bayesian inference, hypothesis testing, probabilistic data association and track-to-track fusion. Learned fusion can combine imagery, radar, RF and contextual intelligence through neural embeddings or attention mechanisms. Hybrid systems are common because physics-based filters provide interpretable motion constraints while learned models improve recognition. The main failure modes are misassociation of observations, duplicate tracks, correlated sensor errors, stale data, identity swaps and overconfident fusion of sources that are not genuinely independent. TITAN and SDA publicly emphasize multisource fusion, while IBCS is designed to decouple sensors and effectors into a shared track architecture.

Computer vision and automatic target recognition. Convolutional neural networks, vision transformers and related detectors can locate objects, assign classes, segment shapes and track motion. Project Maven is an explicit defense example of neural computer vision extracting objects of interest from imagery. Missile ATR may instead combine template or scene matching, engineered features and learned classifiers; public product descriptions rarely reveal the exact model. This opacity is consequential because “recognizes the correct target” is a performance claim, not a full account of false-positive rates, training distributions, confidence calibration, or behavior under camouflage and decoys.

Planning, optimization and weapon assignment. Command systems can use rule engines, graph search, constraint optimization, probabilistic models and machine learning to recommend sensor placement, prioritize threats and pair targets with weapons. Reinforcement learning and imitation learning are prominent in experimental air-combat and swarm autonomy because they can discover policies in simulation, but such policies can exploit simulator artifacts or behave unexpectedly outside the scenario distribution. ABMC2 explicitly advertises automated pairing and autonomous allocation; ACE and OFFSET have explored AI combat behaviors and swarm tactics under human-command structures.

Edge AI. Processing aboard the seeker, aircraft, robot, satellite or forward command post reduces dependence on long-haul communications and can lower decision latency. It also limits exposure of raw sensor data and permits operation under jamming. The tradeoffs are constrained power, cooling, memory and compute; limited opportunities to update models; difficulty reproducing failures; and the risk that local models continue operating on stale intelligence after losing contact. Switchblade’s onboard ATR, CCA mission autonomy, TITAN’s forward processing and proposed onboard satellite cyber defense all reflect this movement toward edge computation.

Communications and kill-web networking. Distributed systems use tactical data links, satellite communications, line-of-sight radios, mesh networks and, increasingly, optical crosslinks. The architecture must address intermittent bandwidth, variable latency, packet loss, contested spectrum, differing classification domains and incompatible data standards. JADC2 strategy emphasizes machine-to-machine processing and rapid dissemination; CCA’s government-owned A-GRA decouples autonomy software from aircraft hardware; ABMC2 uses containerized microservices and standard data layers; and SDA combines space sensing with tactical data products and optical networking.

Latency is operationally contextual. Local defense against a high-speed incoming missile may allow too little time for deliberate human review, whereas deliberate strike planning can support extensive validation. A safe design therefore cannot treat “human in the loop” as a checkbox; the human must have sufficient time and information to make a genuine decision. Systems should expose deadlines, confidence, sensor provenance and consequences of inaction rather than forcing operators into reflexive approval. The DoD directive requires understandable interfaces, transparent status feedback, and clear activation and deactivation procedures.

Adversarial and environmental robustness. Important attack classes include sensor spoofing, camouflage and decoys; adversarial perturbations that cause evasion; poisoning or backdooring of training and update data; compromise of model weights or mission files; false-track injection; datalink manipulation; and model-extraction or privacy attacks. Natural distribution shifts—weather, dust, sea state, unfamiliar vehicle variants, new tactics, damaged sensors—can be as dangerous as deliberate adversarial examples. NIST’s 2025 adversarial-ML taxonomy organizes attacks by lifecycle stage, attacker knowledge and objective, while DARPA GARD and MITRE ATLAS provide research and threat-modeling frameworks.

A robust architecture should use defense in depth, not confidence in one classifier. Appropriate measures include multisensor corroboration, calibrated uncertainty, an explicit “unknown/reject” output, physical plausibility checks, signed software and model packages, isolated safety monitors, runtime geofencing, weapons-safe states, communications-loss behavior, independent abort channels, tamper resistance, immutable logs, and reversion to a simpler verified controller when the learned component leaves its validated envelope. DoD policy explicitly requires system safety, anti-tamper measures, cybersecurity, realistic testing, analysis of emergent behavior, and continued monitoring after fielding.

Human control, law, ethics and regulation

International humanitarian law applies regardless of whether force is selected or delivered by a human, an algorithm, or a combined human–machine system. The central conduct-of-hostilities obligations include distinction between military objectives and civilians or civilian objects, proportionality in anticipated incidental harm, and feasible precautions in attack. Commanders and operators remain responsible for making legally required judgments, but increasingly automated systems complicate how intent, foreseeability, knowledge and causal responsibility are demonstrated.

Weapons reviews are a primary national control. Article 36 of Additional Protocol I requires a state party, when studying, developing, acquiring or adopting a new weapon, means or method of warfare, to determine whether its employment would be prohibited in some or all circumstances. For AI-enabled systems, a meaningful review must examine intended target classes, operating environments, human-machine interfaces, update mechanisms, failure behavior, adversarial countermeasures, data dependencies and the possibility that a software change creates a materially different weapon.

The 2023 U.S. DoD Directive 3000.09 requires autonomous and semi-autonomous weapons to permit appropriate levels of human judgment over force, undergo hardware and software verification and validation and realistic testing, function within specified geographic and temporal constraints, terminate or seek operator input when unable to comply, and incorporate understandable interfaces, safety, cybersecurity and anti-tamper measures. Certain autonomous systems require senior review before formal development and again before fielding, while operator-supervised anti-materiel systems for local defense receive a distinct policy treatment.

The directive also requires testing against adaptive adversaries, analysis of unanticipated emergent behavior, iterative cyber testing, revalidation following system changes, post-fielding data collection, and further testing when the operational environment changes. The DoD Responsible AI pathway adds lifecycle TEVV, real-time monitoring, algorithm confidence metrics, user feedback and tools to detect natural degradation and adversarial attacks. These are significant controls, although their effectiveness ultimately depends on program-level implementation, independent test access and the realism of operational test scenarios.

NATO’s responsible-use principles are lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation. “Governability” includes the ability to disengage or deactivate systems that exhibit unintended behavior. NATO has also worked on data and AI governance, certification and review mechanisms, although alliance principles do not by themselves replace national weapons law, rules of engagement or acquisition certification.

The U.S.-sponsored Political Declaration on Responsible Military Use of AI and Autonomy is a nonbinding norm-setting instrument. It promotes compliance with international law, senior-level accountability, rigorous testing, auditing, training, safeguards against unintended behavior, and responsible use across the lifecycle. Its value is interoperability around common practices; its limitation is that it does not create treaty obligations or settle disagreements over prohibited levels of autonomy.

The ICRC advocates a stronger, legally binding approach. It recommends prohibiting autonomous weapons whose effects cannot be sufficiently understood, predicted and explained; prohibiting systems designed or used to target human beings; and regulating other autonomous systems through restrictions on target type, geographic and temporal scope, scale, civilian presence, supervision and deactivation. The ICRC’s position reflects concern that a user may neither choose nor know the particular target, time or location of force once a generalized target profile has been activated.

The multilateral process remains unsettled. The CCW Group of Governmental Experts has developed guiding principles and discussed a possible two-tier structure combining prohibitions and regulations, while the UN General Assembly adopted autonomous-weapons resolutions in 2024 and 2025 and held broader consultations. These developments show expanding diplomatic attention but not agreement on a universal definition, required form of human control, or a legally binding instrument.

Export controls are fragmented. The MTCR applies to specified complete rocket and unmanned-air-vehicle systems, including cruise missiles and drones, and to listed production equipment, software and technology. Its original proliferation focus is payload/range and weapons-of-mass-destruction delivery, not AI autonomy as such. The Wassenaar Arrangement controls categories of conventional military equipment and dual-use electronics, sensors, software and technology, but there is no single multilateral control entry that captures every AI target-recognition model, autonomy stack, training dataset or commercial processor capable of military adaptation.

A rigorous human-control framework should test five dimensions rather than relying solely on loop terminology:

DimensionRequired questionEvidence that should be available
Human knowledgeDoes the operator understand the system’s capabilities, limitations, target profile and likely effects?Training records, interface evaluations, model cards, operating-envelope documentation and scenario testing
Information qualityDoes the operator receive target identity, location, provenance, uncertainty and civilian-context information?Sensor-source display, confidence calibration, contradictory-track alerts and data-age indicators
Time and attentionIs there enough time and cognitive capacity for a non-rubber-stamp decision?Human-factors testing under realistic workload, alarm rates and engagement deadlines
Intervention capabilityCan the human reliably abort, redirect, deactivate or place the weapon in a safe state before unacceptable effects?Independent control path, tested abort latency, communications-loss logic and physical safety interlocks
Bounded delegationAre target class, area, time, scale, weapon effects and operating conditions sufficiently constrained?Geofences, mission-duration limits, target-profile restrictions, ammunition limits and rules encoded independently of the learned model

These dimensions synthesize DoD interface and governability requirements, NATO responsible-use principles, and the ICRC’s proposed restrictions on target type, time, geography, scale and human supervision.

Risk assessment and mitigation

The table below is a qualitative analytical assessment. Likelihood varies substantially by platform, target environment, operational doctrine and adversary. “High” does not mean inevitable; it indicates that the combination of plausible occurrence and potential consequence warrants treatment as a design-driving hazard.

RiskRelative concernMechanismHighest-risk contextsPriority mitigations
Target misclassificationHighModel confuses civilian, friendly, damaged, decoy or novel objects with the authorized target classUrban environments, mixed traffic, visually similar objects, degraded weather and rapid model updatesMultisensor confirmation, conservative thresholds, unknown/reject class, contextual human review, representative test data and post-field calibration
Automation bias and rubber-stampingHighHuman accepts ranked target or weapon recommendation without independent evaluationHigh operational tempo, opaque confidence scores, repeated alerts, understaffed command centersExplanations tied to evidence, alternative hypotheses, forced consideration of disconfirming data, workload limits and training against automation bias
Adversarial deceptionHighSpoofing, decoys, camouflage, RF manipulation or adversarial inputs induce false tracks or hide real onesPeer conflict, electronic warfare, contested navigation and sensor fusionRed-team testing, sensor diversity, physical consistency checks, adversarial training, deception libraries and runtime anomaly detection
Cyber compromise or supply-chain attackHighAdversary modifies software, models, mission data, communications or update infrastructureNetworked systems, contractor-managed software, field updates and multinational interoperabilitySigned artifacts, secure boot, hardware roots of trust, least privilege, software bills of materials, isolated safety channels and continuous monitoring
Communications lossMedium–highSystem continues with stale intent, cannot receive abort, or fails unpredictablyLong-range munitions, swarms, maritime robots and satellite-linked operationsExplicit lost-link state machine, bounded continuation period, return/hold/abort behavior, local safety constraints and pre-mission communications-risk review
Cascading kill-web errorHighOne false or misidentified track propagates through fusion, prioritization and automatic weapon assignmentHighly integrated air defense, joint all-domain networks and shared coalition tracksTrack provenance, independent confirmation before lethal assignment, confidence decay, cross-domain validation and authority separation between nomination and engagement
Emergent swarm behaviorMedium–highLocal agent rules create unsafe concentration, collision, target duplication or escalationLarge heterogeneous swarms with adaptive task allocationFormal constraints, simulation at scale, runtime monitors, mission-level resource limits, graceful degradation and tested human intervention methods
Escalation compressionHigh strategic consequenceAutomated warning and response shorten the time for political and military deliberationMissile warning, counter-space, strategic air defense and cyber-physical retaliationHuman confirmation for strategic effects, multi-source validation, deliberate delay where feasible, escalation-aware rules and senior authorization
Civilian-harm scalingHighAutomation increases the number of targets processed and engaged faster than review capacity growsDense civilian environments and algorithmic target-list generationReview-rate limits, civilian-presence constraints, collateral estimation independent of target-ranking model, audit sampling and no-strike-list protection
Fratricide and coalition mismatchMedium–highIncompatible identification standards or stale friendly-force data cause engagement of friendly platformsCoalition air defense, autonomous swarms and shared sensor networksCommon identification protocols, positive identification gates, blue-force-data validation, interoperability testing and conservative behavior on ambiguity
Model drift and unauthorized functional changeHigh over lifecycleNew data, software updates or environmental change invalidate prior certificationContinuously updated models and portable autonomy softwareConfiguration control, versioned safety cases, regression testing, approval thresholds for material changes and post-field monitoring
Accountability and audit failureHighInsufficient logs prevent reconstruction of who knew what and why force was appliedDistributed systems with multiple vendors and classified modelsTamper-evident event logs, synchronized clocks, decision provenance, retention rules, named command responsibility and independent incident review
Proliferation and repurposingHigh strategic concernCommercial autonomy, sensors and processors are integrated with inexpensive weaponsLoitering munitions, UAS swarms, maritime drones and armed robotsEnd-use monitoring, modular export licensing, model and software controls where enforceable, secure deactivation, supplier vetting and international transparency

The underlying threat model is supported by NIST’s adversarial-ML taxonomy, DoD requirements to test against adaptive adversaries and unauthorized interference, and experience showing that communications resilience and electronic-warfare resistance are central to battlefield robotics.

Mitigation should be organized as an assurance case linking each operational claim to evidence. A claim such as “the system engages only authorized ship classes” should identify assumptions about sea state, sensor health, database version, civilian traffic, decoys, communications and operator supervision; cite test evidence; define residual uncertainty; and specify runtime controls when assumptions fail. Aggregate accuracy on a benchmark is insufficient because rare false positives can dominate safety in target-sparse environments.

Verification should combine requirements-based testing, simulation, hardware-in-the-loop trials, live operational testing, adversarial red teaming, formal analysis of critical state machines, fuzzing, cybersecurity assessment, human-factors trials and post-field monitoring. Learned perception may resist complete formal verification, but the surrounding system can impose formally checkable limits on geography, time, target type, weapon state, ammunition expenditure and acceptable sensor disagreement. DoD policy’s emphasis on emergent behavior, realistic adaptive adversaries, reprogramming, configuration changes and post-field data collection is consistent with this layered approach.

The strongest architecture separates the mission AI from an independent runtime-assurance or safety controller. The AI may propose a route, target classification or pairing, but the safety layer enforces hard constraints, validates command authentication, monitors sensor health and transitions to a safe state when the system leaves its certified operating envelope. Human override must not depend on the same compromised model, processor or communications path as the primary autonomy function.

Human supervision must itself be tested as a safety component. Operators need calibrated alerts, manageable workload, clear uncertainty, the ability to distinguish machine observation from inference, and realistic training in failures and deception. A nominal on-loop operator supervising dozens of fast-moving systems may exercise less effective control than an in-loop operator responsible for a small number of engagements. The metric should therefore be demonstrated capacity to understand and intervene, not merely the presence of a person in an organizational diagram.

Assurance of non-deterministic and adaptive systems remains the central technical gap. Conventional weapons certification assumes a relatively stable configuration and tractable state space. Machine-learning components can be sensitive to training-data composition, hardware implementation, preprocessing and environmental shifts, while modular autonomy software may be updated more frequently than the host airframe or weapon. Research is needed on compositional assurance: how evidence for a sensor model, planner, communications service and safety monitor combines into a defensible claim about the entire kill chain. DoD’s recent AI and autonomous-systems test guidance reflects the urgency of this problem but does not eliminate it.

Confidence calibration under operational distribution shift is unresolved. A classifier that is accurate on representative test imagery may become confidently wrong when encountering a new camouflage pattern, thermal condition, ship modification, damaged object or adversarial decoy. Open-set recognition, uncertainty estimation, causal and physics-informed models, continual monitoring and reliable rejection of unfamiliar observations are more important for weapon safety than small improvements in average benchmark accuracy. NIST and DARPA robustness work provides taxonomies and defensive research, but no general solution guarantees robust target recognition against adaptive opponents.

Human-control measurement lacks agreed standards. States and institutions endorse terms such as appropriate human judgment, context-appropriate human control, meaningful human control and governability, but there is no universal quantitative test for sufficient operator knowledge, time, intervention reliability or scope of delegation. Research should produce scenario-based metrics covering target complexity, civilian presence, system speed, operator-to-system ratio, communications quality, explanation fidelity and abort effectiveness.

System-of-systems validation is immature. A component may pass its own test program while the integrated chain remains unsafe because timestamps, identity standards, confidence semantics or rules-of-engagement encodings differ across services and allies. Future test ranges must reproduce deceptive sensors, damaged networks, coalition data exchanges, cyber attacks, large swarms and simultaneous kinetic/non-kinetic effects. Digital twins and synthetic environments will be essential but must be audited for simulation-to-reality gaps, especially when reinforcement-learning policies are trained in those environments.

Autonomy is shifting from platforms to portable software. The CCA program’s A-GRA approach explicitly separates mission-autonomy software from the aircraft, permitting multiple vendors and faster updates. This can improve competition and interoperability, but it also means that a change in software may materially alter combat behavior without changing the physical weapon. Certification, legal review and export controls will have to track model versions, mission applications and interfaces—not just airframes and missiles.

Kill chains will increasingly become distributed kill webs. TITAN, JADC2, IBCS, ABMC2 and SDA architectures aim to combine observations from many domains and connect them to the most suitable effector. The operational advantage is resilience and flexibility; the governance challenge is that responsibility and error causation are dispersed among data providers, model developers, network operators, commanders and weapon crews. Future controls will need machine-readable provenance and authority metadata that travel with a track from collection through engagement and assessment.

Swarms will move from coordinated movement toward adaptive mission allocation. Near-term fielding is likely to emphasize reconnaissance, decoys, communications relay, electronic warfare and human-authorized massed attack rather than unrestricted lethal target selection. The harder research problems are preventing duplicate engagements, bounding collective behavior, maintaining identity and deconfliction under network fragmentation, and enabling one human to supervise many agents without losing effective control. OFFSET’s results show progress in human–swarm teaming but do not establish that large lethal swarms can be safely verified.

Space and missile defense will be major drivers of high-speed autonomy. Proliferated satellite sensors and onboard processing can improve warning and maintain custody of maneuvering missile threats, while AI-enabled cyber defense may protect satellites when ground contact is intermittent. Because false warning and mistaken classification can have strategic consequences, space-based targeting systems require particularly strong multisource confirmation, provenance, escalation controls and separation between automated tracking and strategic release authority.

Counter-autonomy will grow alongside autonomy. Forces will use AI to detect drones, classify swarm behavior, identify spoofing, allocate defensive weapons and protect networks. This creates an autonomy-versus-autonomy dynamic in which defensive time pressure encourages automatic response and adversaries deliberately manipulate those responses. Point defense against clearly characterized materiel threats is likely to remain the leading domain for greater engagement autonomy because target profiles and operating areas can be more tightly bounded than in urban attacks on persons. U.S. policy’s distinct treatment of operator-supervised local defense reflects this logic.

The central policy question is consequently not whether militaries will use AI in kill chains—they already do—but which decisions may be delegated, under what evidence of reliability, against which target classes, for how long and over what area, with what human understanding and intervention capability, and with what accountability when the chain fails. A defensible governance regime must treat targeting AI, command networks, autonomous platforms, terminal seekers and human organizations as one safety- and law-critical system rather than regulating only the final trigger.