Bounded simulation: no real targets, coordinates, casualty models, weapon-performance parameters, executable payloads, or operational attack instructions.

Public evidence through July 31, 2026

Who is using AI-enabled kill-chain functions—and how

The public record shows widespread adoption of AI-assisted sensing, fusion, decision support, autonomous mobility, terminal recognition, and defensive automation. It rarely provides a complete account of software, rules of engagement, human intervention, or deployed configuration.

Official facts separatedManufacturer claims labeledClassified details remain unknown

Official policy

Strong evidence for stated governance, program purpose, and public requirements—not necessarily field performance.

Official program description

Strong evidence that a program or capability exists, with limits where implementation details are classified.

Manufacturer statement

Evidence of what a supplier publicly claims; not independent confirmation of operator doctrine or combat results.

Independent analysis

Contextual interpretation based on public material, with source quality and uncertainty varying by topic.

North America

United States

High for named programs; many operational details remain classified

Public U.S. evidence is strongest for AI-assisted intelligence, sensor fusion, target cueing, command-and-control, autonomy research, and bounded autonomous functions—not a blanket transfer of lethal authority to AI.

Publicly evidenced uses

  • Maven Smart System: fuses sensor data for object detection, tracking, and decision support.
  • CJADC2 and related programs: connect distributed sensors, decision nodes, and effectors across domains.
  • Replicator: accelerates fielding of attritable autonomous systems, with authority and mission modes varying by system.
  • Missiles, air defense, and collaborative aircraft use bounded navigation, sensing, classification, or mission-autonomy functions.

Human control and governance

DoD Directive 3000.09 requires appropriate levels of human judgment, realistic testing against adaptive adversaries, safety and cybersecurity, understandable interfaces, and legal compliance.

Unknowns and limits

Classified rules, exact model architectures, operational thresholds, and weapon-release modes for many systems are not public.

Evidence class

Official policy and program evidence

Middle East

Israel

High for advertised functions; independent operational verification varies

Israeli manufacturers publicly describe systems spanning automatic target recognition, human-in-the-loop precision weapons, and bounded autonomous anti-radiation loitering munitions.

Publicly evidenced uses

  • SPICE family: scene matching, automatic target acquisition/recognition, autonomous functions, and a data link supporting human-in-the-loop updates and mission abort.
  • HARPY: manufacturer-described autonomous search and attack against emitting radar targets within a defined mission profile.
  • HAROP: electro-optical loitering system publicly differentiated from HARPY through human-in-the-loop control material.
  • AI-assisted target-generation systems have been widely reported, but claims about workflows, error rates, and human review are disputed and incompletely public.

Human control and governance

Control arrangements differ by system and mode; “autonomous” marketing language must be parsed at the function–context level.

Unknowns and limits

Operational software, thresholds, deployment rules, review procedures, and many conflict-specific claims are not fully public or independently verifiable.

Evidence class

Manufacturer descriptions plus public reporting

Europe

Norway

High for fielding and advertised terminal-recognition functions

Norway’s clearest public example is the Naval Strike Missile family, where autonomous target recognition supports terminal discrimination after a human-defined mission.

Publicly evidenced uses

  • Imaging-infrared sensing and autonomous target recognition for terminal target discrimination.
  • Networked coastal- and ship-based command systems connect surveillance, fire control, and missile launchers.
  • The same missile family is selected by multiple allied operators, making Norway a significant exporter of bounded post-launch autonomy.

Human control and governance

Public material establishes mission planning and terminal recognition but does not fully disclose intervention and release logic for every operator and configuration.

Unknowns and limits

Exact software, classifier performance, abort behavior, and country-specific rules of engagement are not public.

Evidence class

Manufacturer and public operator evidence

East Asia

People’s Republic of China

Moderate for strategic direction; lower for system-by-system deployment claims

PLA writings and external research emphasize “intelligentization,” human–machine integration, distributed sensing, decision advantage, swarms, and kill-web concepts. Public operational details are limited.

Publicly evidenced uses

  • Research and doctrine concerning AI-supported command decisions and multi-domain sensing.
  • Development of unmanned and swarm systems through military–civil fusion and a broad commercial technology base.
  • Interest in algorithmic decision speed and cognitive-domain operations.

Human control and governance

Publicly accessible governance and weapon-release rules are less transparent than those published by the United States or NATO.

Unknowns and limits

The maturity, combat validation, control modes, and fielded scale of particular AI-enabled kill-chain functions are often unknown.

Evidence class

Doctrine-focused external research; limited operational transparency

Europe / Eurasia

Russia

Moderate; conflict claims require caution

Russia publicly promotes AI-assisted drone recognition, terminal autonomy, electronic-warfare resilience, and reconnaissance–strike integration. The exact degree of autonomous target selection is frequently unclear.

Publicly evidenced uses

  • ZALA publicly describes intelligent targeting and recognition in Lancet-family material.
  • Drone ecosystems increasingly use onboard processing to operate when communications or navigation are degraded.
  • AI is also used in counter-drone sensing, imagery interpretation, and command support.

Human control and governance

Public manufacturer language does not reliably establish who authorizes each engagement, how abort works, or how models behave outside advertised conditions.

Unknowns and limits

Combat performance, error rates, software versions, operator oversight, and autonomy modes are contested or undisclosed.

Evidence class

Manufacturer claims, wartime reporting, and independent analysis

Europe

Ukraine

Moderate; fast iteration creates version and terminology uncertainty

Ukraine has rapidly adopted AI-assisted detection, navigation, targeting support, and terminal guidance to cope with electronic warfare and the scale of drone operations.

Publicly evidenced uses

  • Public reporting describes Saker Scout AI-assisted detection and identification functions.
  • Onboard vision and navigation are used to reduce dependence on continuous operator links in jammed environments.
  • AI also supports imagery triage, damage assessment, logistics, and counter-drone defense.

Human control and governance

Different systems may be remotely piloted, supervised, or terminally autonomous; “AI-enabled” should not be read as proof of fully autonomous weapon release.

Unknowns and limits

Rapid field modification, classified software, inconsistent naming, and limited independent access make exact control arrangements difficult to verify.

Evidence class

Government-linked announcements, public reporting, and battlefield observation

Europe

Estonia

High for the stated functional separation

Milrem Robotics provides a clear example of separating autonomous mobility from lethal authority in the THeMIS uncrewed ground vehicle.

Publicly evidenced uses

  • Follow-me, return-home, waypoint navigation, and obstacle avoidance.
  • Integration with remote weapon stations and other mission payloads.

Human control and governance

Milrem states that autonomous functions are strictly limited to mobility and that the weapon system is controlled by a human operator.

Unknowns and limits

Configurations and operator doctrine vary by customer; manufacturer statements do not independently verify every deployed use.

Evidence class

Manufacturer statement

Europe / North America

Germany / Canada

High for the published control policy in demonstrated configurations

Rheinmetall Canada’s Mission Master family demonstrates autonomous mobility, networked sensing, and automated cueing while reserving kinetic decisions to humans.

Publicly evidenced uses

  • Autonomous navigation, convoy, and follow-me behavior.
  • A surveillance vehicle can share a detected location and cue a separate fire-support vehicle.

Human control and governance

Rheinmetall states that targets are never engaged automatically and that a human in the loop is required for all kinetic decisions.

Unknowns and limits

Future configurations, customer-specific integration, and fielding scale vary and must be checked individually.

Evidence class

Manufacturer statement and demonstrations

Transatlantic alliance

NATO (alliance framework)

High for governance principles; NATO is not a single national operator

NATO’s public role is best understood as standard setting, interoperability, assurance, and governance across allied AI applications rather than one monolithic “NATO kill chain.”

Publicly evidenced uses

  • Alliance-level AI strategy, data governance, experimentation, and interoperability.
  • Principles of responsible use applied across defense and security AI applications.
  • Work on certification, testing, assurance, and governability.

Human control and governance

NATO lists lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation.

Unknowns and limits

National systems, rules, and operational authority remain with allies and vary substantially.

Evidence class

Official alliance policy

Cross-country pattern

The most common public use is upstream of weapon release.

Imagery triage, detection, fusion, tracking, planning, navigation, and resource allocation are more widely documented than unrestricted machine selection of people for lethal engagement.

PatternWhere it appearsWhy it is attractiveMain assurance problem
AI-assisted ISR and target cueingUnited States and allies; widely pursued elsewhereScale imagery and sensor analysis; reduce analyst workloadAutomation bias, provenance, false classification, and review capacity
Networked kill websUnited States, NATO members, China-focused researchConnect any suitable sensor to an available effectorSystem-of-systems validation and cascading track error
Autonomous mobilityEstonia, Germany/Canada, United States, Ukraine, othersOperate under workload, distance, and communications constraintsSeparating mobility autonomy from lethal authority and lost-link behavior
Terminal recognition and guidanceIsrael, Norway, United States, Russia, UkraineOperate in clutter, under jamming, or without continuous control linksTarget-profile bounds, open-set recognition, abort, and disclosure of control mode
Automated local defenseMany statesReaction time against fast materiel threatsFalse tracks, fratricide, saturation, and escalation compression