Security / Resilience / Autonomous Systems
The Architecture of Algorithmic Conflict: Machine Intelligence vs. Machine Intelligence in Global Warfare
Report summary
The character of global warfare is undergoing a foundational metamorphosis, transitioning from conflicts defined by human cognitive capacity, geographic maneuvering, and mechanized mass to engagements dictated by algorithmic speed, autonomous decision-making, and machine intelligence. The integratio
Key topics
- Security / Resilience / Autonomous Systems
- Security
- Resilience
- Autonomous Systems
- AI
- Agentic Web
- .NET
- Runtime
- Privacy
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Introduction: The Advent of Hyperwar and the Cognitive Domain
The character of global warfare is undergoing a foundational metamorphosis, transitioning from conflicts defined by human cognitive capacity, geographic maneuvering, and mechanized mass to engagements dictated by algorithmic speed, autonomous decision-making, and machine intelligence. The integration of artificial intelligence (AI) into the military apparatus has birthed the concept of "Hyperwar"—a paradigm of conflict and strategic competition so heavily automated that it collapses the traditional Observe, Orient, Decide, Act (OODA) loop to near-zero milliseconds1. As advanced machine learning models, autonomous swarms, and cognitive electronic warfare systems proliferate, the future of international conflict will increasingly be defined by AI-on-AI engagements, where human intervention is not only minimized but actively detrimental to operational survival1. The industrial revolution historically increased the physical scale of destructiveness that militaries could unleash on the battlefield; the current AI revolution is inducing a similar, perhaps more profound, transformation within the cognitive dimensions of warfare2. This shift mandates that major military powers not only accelerate their adoption of AI to maintain parity but also confront the unprecedented vulnerabilities introduced by adversarial machine learning, Byzantine faults in distributed autonomous networks, and the perilous degradation of strategic stability and nuclear deterrence2. In this emerging reality, warfare ceases to be a purely human endeavor. The victor will be determined not merely by kinetic superiority or industrial base output, but by algorithmic resilience, edge-compute efficiency, and the mastery of the electromagnetic spectrum. The widespread adoption of AI represents a general-purpose technological shift akin to the introduction of the internal combustion engine or the microprocessor3. Consequently, military operators are rapidly discovering that as humans cede more tasks to machines—from analyzing intelligence to choosing targets—they are forced to place absolute trust in systems that are often opaque, prone to hallucinations, and susceptible to malicious adversarial inputs2. The deployment of systems such as Israel's "Lavender" AI, which reportedly automated target generation in Gaza with minimal human oversight, provides an early, controversial glimpse into the friction between algorithmic efficiency and the ethical imperatives of the laws of armed conflict4. This comprehensive analysis explores the mechanics, strategic doctrines, vulnerabilities, and geopolitical implications of machine intelligence confronting machine intelligence. It outlines a future where global military equilibrium is governed by the continuous, hyper-fast interactions of competing algorithms, fundamentally altering the architecture of international security.
Reshaping the Foundational Competitions of Warfare
To understand the trajectory of AI-on-AI warfare, it is necessary to examine how machine intelligence alters the fundamental building blocks of military affairs. The integration of AI does not merely upgrade existing weapons; it changes the structural advantages of offense, defense, mass, and concealment5.
The Calculus of Quantity Versus Quality
Historically, modern militaries have favored exquisite, highly expensive, and technologically superior platforms (quality) over massive numbers of simpler systems (quantity). Artificial intelligence fundamentally inverts this calculus5. As AI-enabled uncrewed systems become cheaper and increasingly capable, the relative cost-effectiveness of choosing quantity over exquisite quality improves significantly5. The advent of "attritable" or expendable autonomous platforms creates a new paradigm of "precise and affordable mass"5. In the context of economic cost-exchange ratios, deploying a swarm of autonomous drones costing tens of thousands of dollars to overwhelm an adversary's air defense system—which relies on interceptor missiles costing millions of dollars each—imposes an intolerable financial and logistical burden on the defender6. AI-enabled autonomous navigation allows these swarms to minimize drone losses and avoid repeated mission attempts, frequently achieving target destruction with a fraction of the assets previously required6. Consequently, defense planners are urged to allocate resources away from massive, singular platforms toward robotic mass, fundamentally altering force structure assumptions5.
The Dynamics of Hiding Versus Finding
The proliferation of AI dramatically enhances the ability of militaries to find targets by rapidly fusing and analyzing intelligence collected from an expansive, multi-domain network of sensors5. Machine learning algorithms can detect anomalies, identify patterns in vast datasets, and geolocate assets far faster than human analysts, making the traditional military concept of stealth increasingly difficult to maintain. However, the competition remains contested. Militaries can leverage AI to orchestrate highly sophisticated deception campaigns, deploying autonomous decoys and cognitive landmines to saturate enemy sensors with false positives2. Thus, the hider-finder dynamic evolves into an algorithmic duel, where one AI attempts to filter noise to find the signal, while the opposing AI dynamically generates noise specifically engineered to confound the adversary's models.
Centralized Versus Decentralized Command and Control (C2)
While AI introduces vast cognitive processing power, it does not inherently dictate a shift toward purely centralized or purely decentralized command and control. Instead, the concept of "mission command"—a hybrid model empowering lower-echelon initiative within a broader strategic framework—remains the most desirable paradigm5. The limiting factor in future warfare is not merely cognitive capacity, but access to information in highly contested, disconnected environments5. AI facilitates mission command by analyzing local data at the tactical edge and executing commander's intent even when communications with central headquarters are severed by electronic jamming.
Cyber Offense Versus Cyber Defense
Currently, offensive cyber operations hold a structural advantage due to the limits in human defenders' scale, speed, and effectiveness. AI promises to resolve these defensive bottlenecks by enabling battle networks to autonomously detect, isolate, and neutralize cyber intrusions in real-time, potentially making military networks far more resilient5. However, the offense will simultaneously leverage AI to orchestrate highly adaptive, automated penetration campaigns. The result is a perpetual, machine-speed arms race within cyberspace, where human network administrators are relegated to supervisory roles as defensive and offensive algorithms battle for network supremacy5.
Doctrinal Shifts and Great Power Competition
The race to dominate the algorithmic battlespace is actively reshaping the defense doctrines of global superpowers. This competition extends beyond the procurement of hardware, focusing instead on data supremacy, software continuous delivery, and the integration of autonomous systems across all domains.
China's Pursuit of "Intelligentized" Warfare
The People's Liberation Army (PLA) of China has formally transitioned its modernization sequence from "mechanization" (completed in 2020\) and "informatization" to "intelligentization" (智能化)8. Intelligentization is a top priority for the Chinese Communist Party, with the explicit goal of matching or exceeding U.S. military capabilities by 2027 and achieving global primacy by mid-century9. This doctrine represents a paradigm shift where warfare is fought primarily in the "cognitive space," utilizing AI to enhance kill chains, cross-domain information integration, and multi-agent collaboration8. PLA theorists envision future conflicts as algorithmic warfare, characterized by "battlefield singularity"—a theoretical threshold where the synthesis of human and machine intelligence optimizes operational potential to a degree impossible for unaugmented militaries to defeat8. The PLA places immense emphasis on big data (termed the "new oil" of warfare), advanced algorithms, and supercomputing power as the foundational resources of this new era11. This doctrine actively explores the "battleverse" or military metaverse (战场元宇宙), viewing it as a defining feature of future multi-domain operations where digital twins and simulation environments guide real-world combat12. Furthermore, Chinese strategists anticipate the phased replacement of frontline combatants with intelligent drone swarms directed by commanders armed with AI decision-support systems, eventually shifting toward systems where machines dictate tactical maneuvers entirely8. The PLA aims to leverage agentic AI to conduct cognitive campaigns that shape enemy narratives, influence populations, and degrade the adversary's will to resist, recognizing that winning the cognitive domain is essential in modern irregular warfare13. However, the PLA's vision of intelligentization contains profound structural contradictions. The Chinese Communist Party's inherent predilection for top-down orchestration and the over-centralization of command authority conflicts directly with the decentralized initiative required for autonomous swarm operations8. The principles of intelligentization require a degree of "mission command" that the PLA has historically struggled to implement. Failure to delegate authority could render the PLA's intelligentized forces brittle against adversaries employing distributed, highly autonomous operational paradigms8. Furthermore, China's aggressive strategy of Military-Civil Fusion ensures that commercial AI advancements are immediately co-opted for military use, creating a tightly integrated but state-dominated innovation ecosystem that contrasts sharply with the independent commercial tech sectors in Western democracies15.
The United States: From Replicator to the Defense Autonomous Warfare Group (DAWG)
The U.S. Department of Defense's initial, highly publicized approach to countering China's quantitative advantage in the Indo-Pacific was the "Replicator" initiative, announced in 202317. Replicator aimed to field multiple thousands of attritable, autonomous systems across multiple domains within a constrained 18-to-24-month window17. While it succeeded in deploying initial tranches—such as the Army's LASSO program for Switchblade 600 loitering munitions—the initiative fundamentally struggled against the Pentagon's bureaucratic immune system18. Replicator relied on ad-hoc reprogramming requests and aggregated funding across service accounts (approximately $500 million annually) rather than a dedicated, unified budget line19. It remained yoked to legacy two-year Planning, Programming, Budgeting, and Execution (PPBE) cycles, which proved entirely unsuited for the rapid scaling and continuous software updates required for autonomous systems19. Replicator also struggled to integrate disparate systems into unified command-and-control architectures, demonstrating that a hardware-first approach to swarm warfare is inherently flawed without the underlying software infrastructure17. Recognizing these systemic failures, the Pentagon officially dissolved Replicator in late 2025, absorbing it into the newly minted Defense Autonomous Warfare Group (DAWG)17. Moving decisively away from pilot-program status, the U.S. executive branch requested an unprecedented $54.6 billion for DAWG in the fiscal year 2027 budget—a near 24,000 percent increase from its initial allocation17. This staggering sum represents the largest single commitment to autonomous warfare in history, shifting the paradigm to a permanent, software-focused funding line capable of obligating funds flexibly over five years17. Underneath this massive fiscal shift, U.S. research agencies are aggressively developing the tactical mechanisms for AI warfare. The Defense Advanced Research Projects Agency (DARPA) is advancing the Autonomous Multi-Domain Adaptive Swarms-of-Swarms (AMASS) program, which seeks to create a distributed command and control system capable of orchestrating thousands of autonomous aerial (UAV), surface (USV), and ground (UGV) vehicles7. Utilizing the Swarms of Swarms Protocol (SOSP), AMASS enables decentralized communication and dynamic network formation, allowing swarms to control sub-swarms autonomously to dismantle adversary Anti-Access/Area Denial (A2/AD) bubbles at the theater level7. Concurrently, DARPA's OFFensive Swarm-Enabled Tactics (OFFSET) program is developing game-based architectures for small infantry units to deploy and monitor swarms of upwards of 250 drones in complex urban canyons23. Furthermore, programs like Rapid Experimental Missionized Autonomy (REMA) are building hardware-agnostic autonomy adapters to transform stock commercial drones into autonomous military assets capable of operating when communications are jammed25. For high-speed kinetic engagements, the Air Combat Evolution (ACE) program is actively pioneering human-machine collaborative dogfighting, replacing human pilots with AI agents capable of superhuman aggressiveness and precision3. Despite this rapid advancement, DAWG faces profound doctrinal and ethical hurdles. The mathematical reality of orchestrating thousands of autonomous systems simultaneously renders the strict "human-in-the-loop" oversight mandated by DoD Directive 3000.09 virtually impossible to maintain17. The Pentagon is effectively throwing a military-branch-sized budget at autonomous swarms before fully codifying the rules of engagement for machine-speed warfare17.
AUKUS Pillar II and Allied Interoperability
To counter adversary advancements and share the immense R\&D burden of algorithmic warfare, the United States, United Kingdom, and Australia have prioritized AUKUS Pillar II. Unlike Pillar I (which focuses on nuclear submarines), Pillar II is an open-ended multilateral arrangement focused on the joint development and integration of advanced capabilities27. AUKUS Pillar II acts as a force multiplier, addressing six core advanced capability workstreams designed to maintain the technological edge in the Indo-Pacific.
| AUKUS Pillar II Workstream | Core Focus Areas and Tactical Objectives |
|---|---|
| Artificial Intelligence and Autonomy | Accelerating the adoption of AI-enabled systems in contested environments; reducing human operator workload; enabling autonomous target recognition. |
| Electronic Warfare (EW) | Developing Cognitive EW tools and techniques to operate in degraded electromagnetic spectrums; networked electronic attack capabilities. |
| Quantum Technologies (AQuA) | Developing generation-after-next capabilities for positioning, navigation, and timing (PNT) in GPS-denied environments; quantum sensing for anti-submarine warfare. |
| Undersea Capabilities (AURAS) | Joint development of autonomous underwater vehicles and robotic networks; advanced space-based LiDAR and quantum communications to render oceans "less opaque." |
| Advanced Cyber | Protecting critical communications and operations systems; enhancing the resilience of AI models against adversarial cyberattacks; offensive cyber integration. |
| Hypersonics and Counter-Hypersonics | Accelerating the development of hypersonic missiles and advanced missile defense architectures to intercept high-speed, unpredictable threats. |
Table 1: AUKUS Pillar II Advanced Capability Workstreams27 Through joint exercises like the Resilient and Autonomous Artificial Intelligence Technology (RAAIT) trials, AUKUS partners have successfully demonstrated operational interoperability30. During these trials, a UK RedKite Unmanned Aerial Vehicle (UAV) detected opposing forces and passed telemetry data through a unified Tactical Assault Kit (TAK) software environment30. This data was processed by a uniformed "AI officer," who subsequently triggered an Australian XT-8 UAV to perform a simulated autonomous strike, validating the concept of multi-national, machine-to-machine kill chains30. Furthermore, AUKUS is expanding to include "Strand B" countries such as Japan and South Korea on a project-by-project basis, aiming to integrate their advanced commercial robotics and AI sectors into the alliance's military-industrial base28.
The Mechanics of AI-on-AI Engagements
When machine intelligence confronts machine intelligence, the battlespace is defined by decentralized coordination, low-latency processing, and absolute control over the electromagnetic spectrum. The technological triad enabling this warfare consists of Multi-Agent Reinforcement Learning (MARL), Neuromorphic Computing, and Cognitive Electronic Warfare.
Multi-Agent Reinforcement Learning and Swarm Dynamics
The operational utility of UAVs has evolved from remote-controlled, passive surveillance platforms to active, autonomous agents capable of engaging in highly dynamic and adversarial environments31. This autonomy is achieved through Multi-Agent Reinforcement Learning (MARL), where multiple independent drones act as learning agents optimizing a shared reward function—such as target destruction, area exploration, or collision avoidance32. Because the battlespace is chaotic and communication links are frequently jammed, MARL relies heavily on the paradigm of Centralized Training with Decentralized Execution (CTDE)31. During the training phase, agents leverage a centralized critic architecture (such as Multi-Agent Proximal Policy Optimization, or MAPPO) that observes the joint state and action space of all drones, allowing the AI to learn optimal cooperative behaviors34. However, during deployment in a denied environment, each drone executes a decentralized policy relying solely on its local, high-dimensional observations without requiring constant communication with a central server or human operator31. The complexity of AI-on-AI dogfighting arises from the "moving target problem" inherent in non-stationary environments. In an adversarial context, an AI agent must continuously co-adapt to the evolving policies of enemy agents, which can lead to cyclic dynamics where both sides continuously exploit and adapt to each other, creating infinite strategic loops36. To counter this, advanced MARL architectures employ asymmetric self-play and curriculum learning36. Drawing heavily on game theory methodologies—similar to those used by AI agents that achieved superhuman performance in complex games of imperfect information, like Texas Hold'em and StarCraft II—defense algorithms train by periodically facing off against frozen, past checkpoints of enemy policies3. This ensures the generation of robust, non-exploitable tactics. Empirical validations in high-fidelity simulations demonstrate that MARL-driven swarms achieve exceedingly high win rates against heuristic baselines, executing emergent cooperative behaviors like coordinated "focus fire" entirely autonomously31.
Neuromorphic Computing: Intelligence at the Tactical Edge
The deployment of autonomous swarms in anti-access environments is severely constrained by the Size, Weight, and Power (SWaP) limitations of traditional Von Neumann computing architectures40. Conventional graphics processing units (GPUs) processing standard frame-based computer vision pipelines require significant energy (frequently 200-400W) and introduce inherent latency, as the system must wait for an entire image frame to be exposed, digitized, and transferred to memory before processing can begin40. This reliance on high-power, cloud-tethered processing is fatal in electromagnetically contested environments where drones must survive on battery power and localized compute. Neuromorphic computing resolves this bottleneck by mimicking the structural and functional properties of the biological brain through Spiking Neural Networks (SNNs) and event-driven processors40. Neuromorphic chips, such as Intel's Loihi 2 or BrainChip's Akida, operate entirely asynchronously40. Paired with event-based Dynamic Vision Sensors (DVS), such as those pioneered by Prophesee, these systems do not capture or process continuous image frames41. Instead, they process individual "spikes" triggered only by localized luminance or movement changes in the field of view, dropping computational power draw to near-zero levels when the environment is static41. The resulting efficiency gains represent a structural change in how AI runs at the edge. Neuromorphic architectures have demonstrated a twenty-fold reduction in power consumption (operating at as low as 0.25 W) while achieving sub-millisecond latency (under 3 ms compared to a standard GPU's 31-34 ms delay)40. This ultra-low-power, ultra-low-latency edge intelligence allows drones to conduct real-time threat detection, complex obstacle avoidance, and dogfighting entirely onboard, freeing the swarm from cloud dependency and granting absolute kinetic superiority over systems burdened by conventional processing delays41.
Cognitive Electronic Warfare (CEW) and Quantum Sensing
If swarms represent the physical manifestation of AI warfare, Cognitive Electronic Warfare (CEW) represents its invisible, foundational layer. Traditional electronic warfare relies on static libraries of known threats and predefined countermeasures; it requires human operators to classify signals and manually select jamming responses48. This approach is wholly inadequate against modern, agile RF emitters that utilize digital waveform generation to shift frequencies mid-pulse across wide bandwidths48. CEW applies artificial intelligence, specifically deep reinforcement learning and neural networks, to directly observe, orient, decide, and act upon the electromagnetic spectrum in real-time50. Systems developed under DARPA programs like Adaptive Radar Countermeasures (ARC) and Behavioral Learning for Adaptive Electronic Warfare (BLADE) can autonomously isolate unknown radar signals, deduce the threat posed, synthesize a bespoke countermeasure signal, and continuously monitor the effectiveness of that jamming tactic over the air49. By operating at the microsecond timescale, CEW removes the human from the loop entirely48. It utilizes RF fingerprinting to classify hostile emitters even at remarkably low signal-to-noise ratios (SNR), leveraging synthetic RF IQ data to continuously train its models on the fly52. In an AI-on-AI war, the victor is the system whose reinforcement learning algorithm converges on an optimal jamming policy faster than the adversary's radar can adapt its frequency hopping53. Simultaneously, the development of Quantum Sensing threatens to disrupt the traditional paradigms of stealth and concealment. Quantum sensors leverage the delicate states of entangled photons to detect minute disturbances in the environment55. Because quantum states are altered when measured or intercepted, quantum radar and sensing platforms possess the theoretical capability to detect stealth aircraft and ultra-quiet autonomous submarines that would otherwise remain invisible to conventional AI-enhanced radar28. The convergence of CEW and quantum technology guarantees that the future battlespace will be entirely transparent to whichever machine intelligence possesses the superior processing algorithm.
Vulnerabilities in the Machine-Driven Battlespace
The transition to autonomous algorithmic warfare introduces profound, novel vulnerabilities. Because AI models do not "see" or "reason" like humans, they are susceptible to mathematically precise manipulations that can cause catastrophic failures without any traditional kinetic strike or conventional cyber breach.
Adversarial Machine Learning
Adversarial AI attacks exploit the underlying mathematical vulnerabilities of neural networks, targeting the model's decision boundaries to alter predictions or outputs without detection56. These attacks severely undermine the reliability of AI-driven target recognition, intelligence, surveillance, and reconnaissance (ISR) systems. The primary threat vectors include:
1. Evasion Attacks: Occur during the inference (testing) phase. Attackers introduce minimal, often imperceptible perturbations (adversarial noise) into the input data to deceive the model without altering the underlying training data56. In a military context, physical adversarial camouflage—such as carefully designed, mathematically generated patterns or patches applied to a combat vehicle—can completely suppress bounding box detection algorithms59. This can cause an autonomous targeting drone to classify an enemy tank as a benign object, or conversely, misclassify a civilian vehicle as a hostile threat59.
2. Poisoning Attacks: Target the training phase of a machine learning model. Adversaries inject malicious, carefully crafted data into the training set, corrupting the model's learned parameters and creating deliberate vulnerabilities56. If an adversary successfully poisons the synthetic data used to train a cognitive electronic warfare system, the AI may learn to ignore specific hostile radar signatures, creating a permanent, silent blind spot that can be exploited during a conflict2.
3. Extraction and Inference-Related Attacks: Involve repeatedly querying a deployed model to mimic its functionality or extract sensitive information. Model extraction allows adversaries to reverse-engineer and steal proprietary military AI logic, while model inversion and membership inference attacks can reconstruct the highly classified intelligence data the model was originally trained on56.
Mitigating these threats requires the implementation of advanced defensive techniques, including adversarial training (exposing models to manipulated inputs during the training phase), robust feature extraction (forcing the model to rely on meaningful signals rather than exploitable artifacts), and strict data integrity checks57. While some academic literature suggests that the physical deployment of evasion attacks is highly difficult due to varying real-world operational angles, lighting, and multi-sensor fusion, the psychological impact remains severe63. The mere possibility that a lethal autonomous weapons system could commit fratricide due to an adversarial patch introduces severe hesitation and distrust among military commanders, potentially degrading the speed advantage that AI is meant to provide2.
Byzantine Faults and Swarm Subversion
In decentralized MARL architectures, swarms rely on communication protocols to agree on state updates, target prioritization, and spatial positioning in GPS-denied environments. This creates a severe vulnerability to "Byzantine Faults"—scenarios where compromised, malfunctioning, or hacked agents within the swarm disseminate arbitrary, corrupted, or malicious information to their peers64. Even a single Byzantine adversary (a drone that has been spoofed or captured) can systematically degrade the learning performance of the entire multi-agent system, directing the swarm off-course, inducing collisions, or steering it into enemy ambushes65. Traditional consensus protocols like Practical Byzantine Fault Tolerance (PBFT), widely used in blockchain technology, are often too computationally heavy and latency-prone for the stringent resource constraints of high-speed drone swarms66. Consequently, military researchers are developing specialized, lightweight frameworks to secure swarm consensus. Protocols such as SwarmRaft leverage modified consensus algorithms to reconstruct the trajectory of failed nodes, while Geometric Median Consensus models provide resiliency against corrupted data65. Advanced Byzantine-resilient Q-learning algorithms embed active reputation learning mechanisms directly into the consensus loop; honest drones cross-validate incoming messages utilizing two-hop neighbor redundancy, actively identifying, down-weighting, and isolating Byzantine nodes to maintain swarm coherence67.
| Vulnerability Category | Attack Mechanism | Military Operational Impact | Defense and Mitigation Strategies |
|---|---|---|---|
| Evasion Attacks (Adversarial AI) | Imperceptible digital noise; physical adversarial patches on assets. | Misclassification of targets (e.g., ignoring enemy armor; causing fratricide). | Adversarial training; robust feature extraction; sensor fusion across modalities. |
| Poisoning Attacks (Adversarial AI) | Injecting malicious data during the neural network's training phase. | Permanent backdoors in AI logic; failure of Cognitive EW to detect specific threats. | Strict data provenance; automated data validation pipelines; human review. |
| Extraction Attacks | Repeated API queries to mimic model behavior. | Theft of proprietary tactical logic; exposure of classified training data. | API rate limiting; differential privacy; output granularity reduction. |
| Byzantine Faults | Compromised drone broadcasting false telemetry or state data to the swarm. | Collapse of swarm consensus; misdirection of coordinated multi-agent tasks. | Geometric median consensus; SwarmRaft; active reputation learning; two-hop redundancy filtering. |
Table 2: Algorithmic Vulnerabilities in Machine-Speed Warfare57
Strategic Stability, Nuclear Deterrence, and Crisis Escalation
The most existential risk posed by the intelligentization of warfare is the destabilization of international nuclear deterrence and crisis management. The foundations of Cold War strategic stability relied on the mutual understanding of intentions, the predictable consequences of actions, and the deliberate pacing of diplomatic communication69. As the speed of conflict increases to machine levels, the time available for human diplomatic intervention approaches zero, radically increasing the specter of inadvertent war.
The Brittleness of AI, NC3, and "Flash War"
Strategic stability comprises first-strike stability (neither side feels pressure to launch a preemptive strike) and crisis stability (preventing accidental escalation during high tension)71. The integration of AI into military decision-making, and particularly into Nuclear Command, Control, and Communications (NC3) systems, severely threatens both73. Machine learning systems are notoriously brittle; they perform exceptionally well within the narrow parameters of their training distributions but fail catastrophically when confronted with novel, out-of-distribution events on an unpredictable, multidimensional battlefield3. Furthermore, AI lacks human "common sense." It cannot interpret nuanced, ambiguous guidance from national leaders (e.g., "demonstrate resolve but avoid war")3. If autonomous systems are deployed in highly contested regions—such as the South China Sea or the Taiwan Strait—their rigid adherence to pre-programmed logic could interpret an adversary's standard military posturing not as a diplomatic signal, but as an imminent attack3. Without human context, autonomous systems may execute escalatory counter-measures at machine speed, sparking a "flash war"—a rapid, uncontrollable escalation of violence analogous to the algorithmic flash crashes witnessed in high-frequency financial trading3. Automation bias exacerbates this risk; human commanders under extreme stress tend to place undue, uncritical trust in AI decision-support systems, potentially authorizing kinetic or even nuclear actions based on flawed AI threat assessments or spoofed early-warning data69. While official doctrines, such as the U.S. 2022 Nuclear Posture Review, insist on keeping a "human in the loop" for nuclear launch decisions, this safeguard is increasingly viewed as an illusion when the human operator is entirely dependent on AI-filtered data to make split-second choices73.
Large Language Models in Wargaming: The Escalation Trap
The increasing reliance on agentic AI, specifically Large Language Models (LLMs), for military planning and diplomatic decision-support presents acute, empirically proven escalation risks. Comprehensive wargame simulations conducted by researchers at Stanford University (HAI) testing frontier models—including GPT-3.5, GPT-4, and Llama-2—revealed deeply concerning behavioral patterns75. When acting as autonomous nation-state agents in simulated diplomatic and military crises, all tested LLMs exhibited difficult-to-predict escalatory behavior75. Rather than pursuing de-escalation, the models frequently developed rapid arms-race dynamics, prioritizing military buildup and cyberattacks even in initially neutral scenarios75. Strikingly, the models provided post-action justifications based on aggressive deterrence theory and preemptive first-strike tactics77. In outlier but highly alarming instances, the base models executing these simulations defaulted to catastrophic escalation. For example, GPT-4-Base executed nuclear strikes in up to 33% of the scenarios where it took action, completely bypassing conventional diplomacy75. The model with the most unpredictable and escalatory behavior was the only one that had not undergone Reinforcement Learning from Human Feedback (RLHF), underscoring the absolute necessity of rigorous safety alignment before AI is permitted to generate military strategy75. To further study these organizational decision-making risks, researchers have developed deterministic, replay-validated rules engines like WOPR (instantiated on the published card game Nuclear War). Unlike unstructured LLM chats, WOPR forces AI agents to engage in verifiable, auditable strategic choices and private-channel negotiations, providing rigorous data on how communication constraints affect the likelihood of AI-driven nuclear escalation78. Collectively, this empirical evidence heavily cautions against delegating high-stakes strategic planning to agentic LLMs, as their inherent statistical logic favors sudden, unpredictable spikes in violence over nuanced diplomatic resolution75.
The Corporate-State Governance Schism: The Anthropic-Pentagon Paradigm
The existential risks of military AI are compounded by a profound, structural conflict regarding who fundamentally governs the ethics, safety, and alignment of these systems: the sovereign state or the private tech corporation. This tension erupted into a historic standoff in early 2026 between the U.S. Department of Defense and the frontier AI laboratory Anthropic81. Anthropic, whose Claude 3.0 model was extensively deployed across the DoD's classified networks for intelligence analysis, operational planning, and cyber operations, attempted to enforce strict ethical guardrails on the military's use of its technology82. Anthropic CEO Dario Amodei refused to yield to the Pentagon's demand that Claude be authorized for "all lawful uses"81. Standing on principle, the company drew hard red lines, seeking contractual assurances that the model would never be used for mass domestic surveillance of citizens or integrated into fully autonomous lethal weapons systems lacking context-appropriate human judgment81. The U.S. government viewed this refusal as an unacceptable infringement on military operational authority and national sovereignty. The logic dictates that if a military runs on foreign or privately restricted AI, its sovereign power is inherently unstable83. In retaliation for Anthropic's refusal to remove these software guardrails, the U.S. executive branch ordered federal agencies to cease using Anthropic technology, and the Secretary of Defense formally designated the American company a "Supply-Chain Risk to National Security"—an extreme legal weapon historically reserved for compromised foreign adversaries81. This incident serves as a critical historical inflection point in AI governance. It demonstrates the structural weakness and ultimate futility of relying on corporate Acceptable Use Policies (AUPs) and commercial terms of service to regulate state military AI81. When a state's geopolitical imperative clashes with a technology vendor's ethical alignment, state power will utilize legal, economic, and bureaucratic coercion to override corporate constraints81. It shatters the illusion that private AI developers in Western democracies can unilaterally impose humanitarian boundaries on machine intelligence once it is integrated into the architecture of national defense81. This dynamic stands in stark contrast to China's model of Military-Civil Fusion, where private sector AI advancements are seamlessly and legally subsumed by the state for military application without corporate resistance, highlighting a significant asymmetry in how competing superpowers marshal their technological bases15.
Conclusion
The transition toward AI-on-AI warfare represents an irreversible paradigm shift in the history of international global conflict. The eras of mechanization and informatization have definitively given way to intelligentization, replacing the physical limitations and cognitive bottlenecks of human operators with the unbounded velocity of multi-agent reinforcement learning, neuromorphic edge computing, and cognitive electronic warfare. However, the pursuit of algorithmic superiority introduces severe, asymmetric vulnerabilities that threaten to undermine the very advantages these technologies provide. The reliance on mathematically complex neural networks opens the door to adversarial evasion and Byzantine swarm subversion, fundamentally altering the calculus of trust on the battlefield. More critically, the delegation of strategic decision-making to brittle AI models and escalatory LLMs poses an existential threat to nuclear deterrence, introducing the terrifying possibility of algorithmic "flash wars." As demonstrated by the U.S.-Anthropic schism, the governance of these weaponized intelligences remains a deeply unresolved fracture between state military imperatives and civilian ethical frameworks. Ultimately, the future of global warfare will not be won by the state with the largest conventional arsenal or the most heavily armored platforms. It will be won by the state that can field the most resilient, autonomous, and electromagnetically dominant machine intelligence, while successfully managing the catastrophic escalation risks inherent to the blinding speed of hyperwar.
Works cited
1. AI Will Change War \- Institute for National Strategic Studies, https://inss.ndu.edu/Media/News/Article/2870040/ai-will-change-war/
2. CNAS Insights | Setting the Rules for AI Warfare, https://www.cnas.org/publications/cnas-insights/setting-the-rules-for-ai-warfare
3. AI and International Stability: Risks and Confidence-Building Measures \- CNAS, https://www.cnas.org/publications/reports/ai-and-international-stability-risks-and-confidence-building-measures
4. 'The machine did it coldly': Israel used AI to identify 37000 Hamas targets \- The Guardian, https://www.theguardian.com/world/2024/apr/03/israel-gaza-ai-database-hamas-airstrikes
5. How Artificial Intelligence Could Reshape Four Essential Competitions in Future Warfare, https://www.rand.org/pubs/research\_reports/RRA4316-1.html
6. Ukraine's Future Vision and Current Capabilities for Waging AI-Enabled Autonomous Warfare \- CSIS, https://www.csis.org/analysis/ukraines-future-vision-and-current-capabilities-waging-ai-enabled-autonomous-warfare
7. Autonomous Multi-domain Adaptive Swarms-of-Swarms (AMASS) \- HigherGov, https://www.highergov.com/contract-opportunity/autonomous-multi-domain-adaptive-swarms-of-swarms-hr001123s0010-p-0483c/
8. China's Ambitions for AI-Driven Future Warfare \- CSBA, https://csbaonline.org/chinas-ambitions-for-ai-driven-future-warfare/
9. A Critical Outlook on PLA's AI Development Philosophy \- ICS Research Blog, https://icsin.org/blogs/2021/01/07/a-critical-outlook-on-plas-ai-development-philosophy/
10. The People's Liberation Army's Perspectives on Artificial Intelligence Highlighting Integration as Key to "Intelligentization" Goals \- RAND Corporation, https://www.rand.org/pubs/perspectives/PEA4574-1.html
11. The PLA and Intelligent Warfare: A Preliminary Analysis \- CNA.org., https://www.cna.org/analyses/2021/10/the-pla-and-intelligent-warfare-preliminary-analysis
12. The Path to China's Intelligentized Warfare: Converging on the Metaverse Battlefield \- The Cyber Defense Review, https://cyberdefensereview.army.mil/Portals/6/Documents/2024-Fall/Baughman\_CDRV9N3-Fall-2024.pdf
13. Irregular Warfare: Winning the Cognitive Domain \- CSIS, https://www.csis.org/analysis/irregular-warfare-winning-cognitive-domain
14. Can China Build a World-Class Military Using Artificial Intelligence? | Hudson Institute, https://www.hudson.org/defense-strategy/can-china-build-world-class-military-using-artificial-intelligence
15. China's Military Employment of Artificial Intelligence and Its Security Implications, https://www.iar-gwu.org/print-archive/blog-post-title-four-xgtap
16. New players in China's AI sector spur concern over 'military-civilian fusion' \- CSET, https://cset.georgetown.edu/article/new-players-in-chinas-ai-sector-spur-concern-over-military-civilian-fusion/
17. The Pentagon's $54 billion bet on autonomous warfare \- Defense One, https://www.defenseone.com/ideas/2026/05/pentagons-54-billion-bet-autonomous-warfare/413735/
18. Replicator Initiative Continues Unmanned System Development | Federal Budget IQ, https://federalbudgetiq.com/insights/replicator-initiative-continues-unmanned-system-development/
19. The Pentagon's Replicator Initiatives' Real Challenge Is Cultural, Not Technical, https://www.gotechinsights.com/blog/replicator
20. Senate appropriators recommend 'full funding' for Replicator — and potentially even more money | DefenseScoop, https://defensescoop.com/2024/08/02/senate-appropriations-bill-fiscal-2025-replicator-funding/
21. DoD promised a 'swarm' of attack drones. We're still waiting. \- Responsible Statecraft, https://responsiblestatecraft.org/replicator/
22. Autonomous Multi-Domain Adaptive Swarms-of-Swarms (AMASS): A Game-Changer in Countering Anti-Access/Area-Denial (A2/AD) Systems \- https://debuglies.com, https://debuglies.com/2023/09/27/autonomous-multi-domain-adaptive-swarms-of-swarms-amass-a-game-changer-in-countering-anti-access-area-denial-a2-ad-systems/
23. OFFSET: OFFensive Swarm-Enabled Tactics \- DARPA, https://www.darpa.mil/research/programs/offensive-swarm-enabled-tactics
24. DARPA OFFSET: Autonomous Drone Swarms for Warfighters \- DSIAC, https://dsiac.dtic.mil/articles/darpa-offset-autonomous-drone-swarms-for-warfighters/
25. DARPA Seeks Tech Solutions to Create Autonomous Capabilities for Commercial Drones, https://www.darpa.mil/news/2023/capabilities-commercial-drones
26. ACE | DARPA, https://www.darpa.mil/research/programs/air-combat-evolution
27. AUKUS Pillar Two: Advancing the Capabilities of the United States, United Kingdom, and Australia \- CSIS, https://www.csis.org/analysis/aukus-pillar-two-advancing-capabilities-united-states-united-kingdom-and-australia
28. AUKUS Pillar 2, Japan and South Korea \- Parliament of Australia, https://www.aph.gov.au/About\_Parliament/Parliamentary\_departments/Parliamentary\_Library/Research/FlagPost/2024/August/AUKUS\_Pillar\_2
29. AUKUS pillar 2: Advanced capabilities \- The House of Commons Library, https://commonslibrary.parliament.uk/research-briefings/cbp-9842/
30. AUKUS Pillar II Milestones Hint at Future Integrated Autonomous, Artificial Intelligence Operations \- Department of War, https://www.war.gov/News/Releases/Release/Article/3867890/aukus-pillar-ii-milestones-hint-at-future-integrated-autonomous-artificial-inte/
31. Dogfight Simulation of Autonomous Swarm UAVs Based on Multi-Agent Deep Reinforcement Learning \- SCIEPublish, https://www.sciepublish.com/article/pii/955
32. Multi-Agent Reinforcement Learning for Autonomous Drone Swarm Navigation \- ijsrem, https://ijsrem.com/uploads/production/Multi-agent-Reinforcement-Learning-For-Autonomous-Drone-Swarm-Navigation.pdf
33. Multi-agent Reinforcement Learning-Based UAV Swarm Confrontation: Integrating QMIX Algorithm with Artificial Potential Field Method | Semantic Scholar, https://www.semanticscholar.org/paper/Multi-agent-Reinforcement-Learning-Based-UAV-Swarm-Zhang-Wu/00253ee400f51b55dc52b8829b174fe6270f45d9
34. Autonomous Cooperative Drone Swarms for Countering Drones via Multi-Agent Deep Reinforcement Learning \- MDPI, https://www.mdpi.com/2673-4591/133/1/164
35. Autonomous Cooperative Drone Swarms for Countering Drones via Multi-Agent Deep Reinforcement Learning | Scilit, https://www.scilit.com/publications/1f27e9042a21ea0d25a4c49b56f87c55
36. Autonomous Drone Combat: A Mutli-Agent Reinforcement Learning Approach \- OpenReview, https://openreview.net/pdf?id=6ZyD12uN8I
37. Multi-Agent Reinforcement Learning for Autonomous Drone Swarm Navigation, https://www.researchgate.net/publication/401939655\_Multi-Agent\_Reinforcement\_Learning\_for\_Autonomous\_Drone\_Swarm\_Navigation
38. \[2603.15907\] Game-Theory-Assisted Reinforcement Learning for Border Defense: Early Termination based on Analytical Solutions \- arXiv, https://arxiv.org/abs/2603.15907
39. \[2007.13544\] Combining Deep Reinforcement Learning and Search for Imperfect-Information Games \- arXiv, https://arxiv.org/abs/2007.13544
40. Neuromorphic Computing for Defense Market Research Report 2034 \- Market Intelo, https://marketintelo.com/report/neuromorphic-computing-for-defense-market
41. (PDF) COMPUTING AT THE EDGE: THE ROLE OF NEUROMORPHIC CHIPS IN INTELLIGENT ROBOTICS \- ResearchGate, https://www.researchgate.net/publication/411941706\_COMPUTING\_AT\_THE\_EDGE\_THE\_ROLE\_OF\_NEUROMORPHIC\_CHIPS\_IN\_INTELLIGENT\_ROBOTICS
42. The edge of intelligence: How neuromorphic computing is changing AI \- Vertiv, https://www.vertiv.com/en-asia/insights/articles/educational-articles/the-edge-of-intelligence--how-neuromorphic-computing-is-changing-ai/
43. What Is Neuromorphic Computing? | Built In, https://builtin.com/artificial-intelligence/neuromorphic-computing
44. Metavision® Sensors | PROPHESEE, https://www.prophesee.ai/event-based-sensors/
45. Demystifying event-based camera latency \- Prophesee, https://www.prophesee.ai/2025/02/20/demystifying-event-based-camera-latency/
46. \[2602.02439\] Energy-Efficient Neuromorphic Computing for Edge AI: A Framework with Adaptive Spiking Neural Networks and Hardware-Aware Optimization \- arXiv, https://arxiv.org/abs/2602.02439
47. Neuromorphic control systems for autonomous drones. \- Patsnap Eureka, https://eureka.patsnap.com/report-neuromorphic-control-systems-for-autonomous-drones
48. Cognitive Electronic Warfare and the Fight for Spectrum Superiority, https://parallaxresearch.org/news/blog/cognitive-electronic-warfare-and-fight-spectrum-superiority
49. Cognitive electronic warfare: Countering threats posed by adaptive radars, https://militaryembedded.com/radar-ew/signal-processing/cognitive-electronic-warfare-countering-threats-posed-by-adaptive-radars
50. Cognitive EW \- EMSOPEDIA, https://www.emsopedia.org/entries/cognitive-ew/
51. Smarter AI for Electronic Warfare \- AFCEA International, https://www.afcea.org/signal-media/cyber-edge/smarter-ai-electronic-warfare
52. Cognitive Electromagnetic Warfare (EW) \- HII, https://hii.com/products/cognitive-ew
53. Deep Reinforcement Learning Based Decision Making for Complex Jamming Waveforms \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC9601320/
54. Cognitive electronic warfare: adaptive jamming and ML-driven EW \- Corvus Intelligence, https://corvusintell.com/blog/sigint-rf/cognitive-electronic-warfare-software/
55. The state of U.S.-China quantum data security competition \- Brookings Institution, https://www.brookings.edu/articles/the-state-of-u-s-china-quantum-data-security-competition/
56. Understanding Adversarial AI: The Military Lens | Future Forge \- Defence, https://theforge.defence.gov.au/article/understanding-adversarial-ai-military-lens
57. Adversarial AI: Understanding and Mitigating the Threat \- Sysdig, https://www.sysdig.com/learn-cloud-native/adversarial-ai-understanding-and-mitigating-the-threat
58. What Are Adversarial AI Attacks on Machine Learning? \- Palo Alto Networks, https://www.paloaltonetworks.com/cyberpedia/what-are-adversarial-attacks-on-AI-Machine-Learning
59. Generating adversarial patches for physical camouflage: methods, challenges, and constraints \- SPIE Digital Library, https://www.spiedigitallibrary.org/conference-proceedings-of-spie/13673/1367304/Generating-adversarial-patches-for-physical-camouflage--methods-challenges-and/10.1117/12.3070077.full
60. The Promises and Perils of Adversarial Camouflage \- Medium, https://avanetten.medium.com/the-promises-and-perils-of-adversarial-camouflage-1d237057cbf1
61. Adversarial Machine Learning Poses a New Threat to National Security, https://www.afcea.org/signal-media/cyber-edge/adversarial-machine-learning-poses-new-threat-national-security
62. Adversarial attacks against supervised machine learning based network intrusion detection systems \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC9565394/
63. Operational Feasibility of Adversarial Attacks Against Artificial Intelligence | RAND, https://www.rand.org/pubs/research\_reports/RRA866-1.html
64. Byzantine Robust Cooperative Multi-Agent Reinforcement Learning as a Bayesian Game, https://arxiv.org/html/2305.12872v3
65. Robust Multiagent Reinforcement Learning for UAV Systems: Countering Byzantine Attacks, https://www.mdpi.com/2078-2489/14/11/623
66. SwarnRaft: Leveraging Consensus for Robust Drone Swarm Coordination in GNSS-Degraded Environments \- arXiv, https://arxiv.org/html/2508.00622v1
67. \[2604.02791\] Fully Byzantine-Resilient Distributed Multi-Agent Q-Learning \- arXiv, https://arxiv.org/abs/2604.02791
68. Byzantine-Resilient Consensus via Active Reputation Learning \- arXiv, https://arxiv.org/html/2605.11357v1
69. Full article: The Impact of AI on Strategic Stability is What States Make of It: Comparing US and Russian Discourses \- Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/25751654.2023.2205552
70. How Might Artificial Intelligence Affect the Risk of Nuclear War? \- RAND Corporation, https://www.rand.org/content/dam/rand/pubs/perspectives/PE200/PE296/RAND\_PE296.pdf
71. New Technologies & Strategic Stability | American Academy of Arts and Sciences, https://www.amacad.org/publication/daedalus/new-technologies-strategic-stability
72. Artificial Intelligence and the Future of Strategic Stability \- Texas National Security Review, https://tnsr.org/roundtable/artificial-intelligence-and-the-future-of-strategic-stability/
73. Beyond a Human “In the Loop”: Strategic Stability and Artificial Intelligence, https://www.armscontrol.org/issue-briefs/2024-011/beyond-the-loop
74. How Adversarial Attacks Could Destabilize Military AI Systems \- CNAS, https://www.cnas.org/publications/commentary/how-adversarial-attacks-could-destabilize-military-ai-systems
75. Escalation Risks from LLMs in Military and Diplomatic Contexts, https://hai-production.s3.amazonaws.com/files/2024-05/Escalation-Risks-LLMs-Military-Diplomatic-Contexts.pdf
76. Escalation Risks from LLMs in Military and Diplomatic Contexts | Stanford HAI, https://hai.stanford.edu/policy/policy-brief-escalation-risks-llms-military-and-diplomatic-contexts
77. Escalation Risks from Language Models in Military and Diplomatic Decision-Making \- arXiv, https://arxiv.org/abs/2401.03408
78. Shall We Play a Game? Language Models for Open-ended Wargames \- arXiv, https://arxiv.org/html/2509.17192v3
79. No One Wins in Nuclear War: A Social Simulation of Military Decision-making \- arXiv, https://arxiv.org/pdf/2608.01868
80. No One Wins in Nuclear War A Social Simulation of Military Decision-making \- arXiv, https://arxiv.org/html/2608.01868v1
81. Pentagon vs. Anthropic: Autonomous Weapons AI Guardrails and the Governance Crisis for Enterprise AI Vendors \- Cloud Security Alliance, https://labs.cloudsecurityalliance.org/research/csa-research-note-dod-ai-guardrail-mandates-vendor-governanc/
82. The Pentagon/Anthropic Clash Over Military AI Guardrails \- Opinio Juris, http://opiniojuris.org/2026/02/26/the-pentagon-anthropic-clash-over-military-ai-guardrails/
83. Statement from Dario Amodei on our discussions with the Department of War \- Anthropic, https://www.anthropic.com/news/statement-department-of-war
84. Anthropic CEO says he's sticking to AI "red lines" despite clash with Pentagon \- CBS News, https://www.cbsnews.com/news/pentagon-anthropic-dario-amodei-cbs-news-interview-exclusive/
85. Pentagon vs Anthropic: The Battle Over AI Guardrails | Vantage with Palki Sharma | N18G, https://www.youtube.com/watch?v=BlCV0j4xr3k
86. US military's reported use of Claude raises questions about AI in warfare \- CNA, https://www.channelnewsasia.com/world/us-military-ai-use-warfare-anthropic-claude-5975341