Three connected accountability layers How KillChains, KillWebs, and Evulgare fit together KillWebs.com Evulgare.com
Machine-speed decisions need machine-held evidence. Bounded education only: no real targets, operational control, executable payloads, or live-system actions. A human click is not a liability transfer. For production evidence and accountability software, visit Evulgare.com.

Human Control Lab

The human did not simply disappear. The decision moved.

Enter six synthetic investigations that separate human presence from meaningful control. See how machine filtering shapes evidence, how time compression turns approval into a bottleneck, how authority migrates after communications loss, and how decisions made before activation govern machine-speed behavior.

Six interactive investigationsFictional teaching valuesReal cases with source statesNo telemetry

Answer-first summary

Direct answers

Release 1.38.0 · reviewed · evidence states

Are humans simply removed from automated kill chains?

Often they are removed from particular micro-decisions or moved earlier into design, policy, mission configuration, activation, supervision, abort, and review rather than disappearing from the whole lifecycle.

Read the supporting section

What makes human control meaningful?

Meaningful control depends on adequate time, information, understanding, authority to reject or delay, an effective intervention path, and reconstructable evidence—not merely a button press.

Read the supporting section

Why does upstream filtering matter?

A human may formally authorize an action after algorithms have already discarded observations, fused sources, ranked candidates, and framed the available choices.

Read the supporting section

The analytical shift

Ask which function moved—not whether the whole system is “autonomous.”

A system may navigate automatically while a human retains release authority. A decision-support tool may never apply force, yet still decide which evidence reaches the operator. A local defense may complete a bounded response after activation because the available window is shorter than a meaningful review. The correct unit of analysis is the function, context, authority, information, time, and intervention path.

Control is disaggregated

Five arrangements that must not be collapsed into one label

These site definitions describe how authority is allocated in a particular function and context. They are not claims that every institution uses identical terminology.

AI or automation assistance

Processes, filters, correlates, predicts, or recommends without possessing engagement authority.

Human role
Reviews evidence and retains the consequential decision.
Control warning
Upstream filtering can still shape what the human sees and which options appear plausible.

Human-in-the-loop

May detect, track, classify, cue, prioritize, navigate, or provide terminal guidance.

Human role
An affirmative human decision is required before the defined consequential action.
Control warning
A click is not meaningful control when time, evidence, comprehension, or rejection authority is inadequate.

Human-on-the-loop

Acts automatically inside a bounded envelope after activation.

Human role
Supervises and may intervene, abort, redirect, or deactivate where the interface and timeline make that practical.
Control warning
Nominal supervision can become ceremonial when the action finishes before the operator can understand or interrupt it.

Preauthorized local action

Executes a narrowly defined response after programmed evidence, boundary, time, and safety conditions are satisfied.

Human role
Defines the mission, constraints, exceptions, activation state, and recovery path before the event.
Control warning
Earlier human decisions become more consequential; bad assumptions can be applied consistently at machine speed.

Publicly unspecified

Not established by reviewed public sources for the configuration or condition in question.

Human role
Cannot be reliably classified.
Control warning
Do not convert missing evidence into either “fully autonomous” or “human-controlled.”

Investigation 01 · Upstream human removal

The Algorithmic Gatekeeper

The human may retain the final button while an algorithm has already filtered the observations, merged the sources, ranked the candidates, and hidden everything below a threshold.

Ninety-six representative tiles stand in for a much larger synthetic observation stream. Select what appears important.

No gaze, pose, biometric, identity, or location data is collected. Selection exists only in this page session.

Private replay and share

SYNTHETIC SCENARIO

Reproduce this synthetic learning result

Replays the released threshold and evidence-preservation choices, plus a bounded count of observations reviewed. The code contains released IDs and allowlisted values only. It creates no account, server result, leaderboard, or behavioral profile.

Deterministic presentation codeComplete or configure the module to create a code.

This replay demonstrates interface framing with fictional observations; it does not measure or predict any real sensor, model, analyst, or targeting workflow.

Ready. Current state remains in this page only.

Filtering is necessary

No person can inspect every observation in a high-volume stream. The question is whether filtering remains inspectable, reversible, provenance-aware, and able to preserve contradictions.

Confidence is not evidence quality

A model can be internally confident while relying on stale, correlated, incomplete, or out-of-distribution inputs.

Omission can govern the decision

The strongest influence may be the option, observation, or contradiction that never reaches the human interface.

Investigation 02 · The disappearing review window

90 Seconds: Human Command Versus Machine Speed

The same fictional event runs through three authority architectures. Speed improves as handoffs disappear, but a faster chain can also apply an incorrect rule more consistently and leave less room for contextual judgment.

Policy written before the event

Set the fictional review envelope

90.0 synthetic seconds

Human-directed

Standing by

Review each observation and authorize each consequential action.

  1. Find
  2. Fix
  3. Track
  4. Identify
  5. Prioritize
  6. Authorize
  7. Respond
  8. Assess
Human workload
Evidence inspected
Meaningful review
Primary risk

AI-assisted

Standing by

Machine fusion and ranking; human authorizes after recommendation.

  1. Find
  2. Fix
  3. Track
  4. Identify
  5. Prioritize
  6. Authorize
  7. Respond
  8. Assess
Human workload
Evidence inspected
Meaningful review
Primary risk

Preauthorized automation

Standing by

A local rule engine acts only when the prior envelope is satisfied.

  1. Find
  2. Fix
  3. Track
  4. Identify
  5. Prioritize
  6. Authorize
  7. Respond
  8. Assess
Human workload
Evidence inspected
Meaningful review
Primary risk

Human-Control Budget

Presence is not enough

Each dimension remains separate. The lab never converts them into a single morality or legality score.

Private replay and share

SYNTHETIC SCENARIO

Reproduce this synthetic learning result

Replays the bounded evidence, unknown-handling, and abort policy selected before the fictional event. The code contains released IDs and allowlisted values only. It creates no account, server result, leaderboard, or behavioral profile.

Deterministic presentation codeComplete or configure the module to create a code.

Synthetic timing and workload values are educational only and do not estimate the speed, safety, legality, or effectiveness of a real system.

Ready. Current state remains in this page only.

Investigation 04 · Nominal versus meaningful control

The Rubber-Stamp Paradox

A mechanical click is not automatically a meaningful judgment. Queue volume, time pressure, interface defaults, confidence presentation, and the ability to request evidence can determine whether the human actually controls the decision.

Cognitive forcing functions

Synthetic queue

1 / 8

Review window: generous

    Loading

    Preparing synthetic recommendation

    No response is transmitted. This is a transparent educational exercise, not a covert behavioral experiment.

    Time adequacy50%Pending
    Information adequacy50%Pending
    Source independence50%Pending
    Freedom to reject50%Pending
    Ability to delay50%Pending
    Uncertainty visibility50%Pending

    Private replay and share

    SYNTHETIC SCENARIO

    Reproduce this synthetic learning result

    Replays released cognitive-forcing controls and bounded educational result counts without storing an action-by-action behavioral history. The code contains released IDs and allowlisted values only. It creates no account, server result, leaderboard, or behavioral profile.

    Deterministic presentation codeComplete or configure the module to create a code.

    This result evaluates a fictional queue and interface; it is not a psychological assessment, competence score, legal judgment, or prediction of real operator behavior.

    Ready. Current state remains in this page only.

    Evidence Lab rule

    Controversial real-world claims must remain attributed.

    Investigative reporting, official statements, independent analysis, legal interpretation, dispute, and unknown are different evidence states. The playable queue stays fictional and nonviolent; real cases belong in a source-analysis interface, not a reenactment.

    Investigation 05 · Distributed authority

    Who Still Decides?

    The final two seconds cannot reveal the whole decision architecture. Policy, data, thresholds, testing, mission boundaries, activation, supervision, updates, and auditability can all shape what the machine is permitted to do.

    ObservationClassificationAuthorization stateExternal actionResult

    Who decided?

    Select an initial attribution. The lifecycle remains hidden until you commit.

    Private replay and share

    SYNTHETIC SCENARIO

    Reproduce this synthetic learning result

    Replays the visitor’s bounded attribution, authority-token assignments, and selected governance-control mask. The code contains released IDs and allowlisted values only. It creates no account, server result, leaderboard, or behavioral profile.

    Deterministic presentation codeComplete or configure the module to create a code.

    The Accountability Shadow is a fictional reconstructability measure, not a legal finding, moral judgment, or attribution of responsibility to a real person or organization.

    Ready. Current state remains in this page only.

    Investigation 06 · Pre-mission governance

    The Mission Was Automated Before It Began

    What looks like a two-second machine decision may be the final state transition in a decision space shaped earlier by policy, engineering, testing, legal review, mission planning, configuration, and activation.

    Fictional governance configuration

    You are the policy team—not the operator.

    Choose how uncertainty produces review, restraint, reversible action, or bounded preauthorization. No target, weapon, route, or real operating parameter appears.

    No policy locked
    01

    Split perception

    Two sensors disagree about one synthetic object.

    Waiting
    02

    Identifier loss

    A previously authenticated object loses its identifier.

    Waiting
    03

    Communications outage

    The review link fails while the event is still developing.

    Waiting
    04

    Outdated assumption

    A protected corridor was activated after the plan was approved.

    Waiting
    05

    Boundary disagreement

    Navigation and sensor-based position estimates conflict.

    Waiting

    Private replay and share

    SYNTHETIC SCENARIO

    Reproduce this synthetic learning result

    Replays the released mission-policy selections and the deterministic ambiguity-event outcome derived from them. The code contains released IDs and allowlisted values only. It creates no account, server result, leaderboard, or behavioral profile.

    Deterministic presentation codeComplete or configure the module to create a code.

    This governance comparison does not reproduce a real mission, rule of engagement, target profile, weapon configuration, or operational outcome.

    Ready. Current state remains in this page only.

    Replay contract

    Share a decision architecture—not a behavioral profile

    Each code uses the HC1 schema, one stable module ID, ordered allowlisted fields, and an integrity checksum. Unknown fields, duplicates, malformed values, incompatible versions, and oversized codes fail closed to the module default.

    Included

    Released choices and bounded results

    Codes may contain the module, selected policy options, fixed synthetic counters, and whether the released result view was reached.

    Excluded

    No identity or freeform content

    No name, email, note, raw timing, location, pose, gaze, voice, real target, coordinate, casualty value, or weapon parameter can be encoded.

    Compatibility

    Fail closed across versions

    Schema HC1 is supported throughout the KillChains.com 1.x release line. A later incompatible schema must use a new prefix. Unknown or superseded schemas fail closed to module defaults.

    Public evidence cards

    Where humans move in documented systems and programs

    Each card separates what public sources establish from what remains unknown. System sophistication, autonomous navigation, target recognition, decision support, and authority over force are separate questions.

    Verified public fact

    A public official source documents the policy, architecture, status, or function. It does not prove every configuration or operational result.

    Government or operator statement

    An accountable public authority describes a program, policy, test, or control arrangement.

    Manufacturer-described

    A supplier describes a capability. The statement remains a claim unless independently corroborated.

    Independent analysis

    A researcher or investigative source interprets public evidence. The site keeps the interpretation separate from the underlying record.

    Disputed or alleged

    Credible sources disagree, the account depends on anonymous reporting, or decisive evidence is unavailable.

    Publicly unspecified

    The public record does not establish the operating mode, authority, threshold, abort path, or field behavior. Unknown is not guessed.

    Fictional simulation value

    A timer, confidence score, object, threshold, result, or policy choice invented only for learning and not calibrated to a real system.

    11 cases shown

    Terminal defensive automation

    MK 15 Phalanx CIWS

    Official program description

    A self-contained local-defense system publicly described as automatically detecting, evaluating, tracking, engaging, and assessing certain incoming threats.

    FindFixTrackPrioritizeEngageAssess
    Public evidence establishes
    The official U.S. Navy fact file documents an automated detect-to-assess sequence for close-in defense.
    Where the human moves
    Operators configure, activate, supervise, maintain, and can deactivate the system; the time-critical local sequence may proceed automatically.
    Control assessment
    Operator-supervised or preauthorized local defense, depending on mode and doctrine.
    Unknowns
    The public fact file does not disclose every mode, exact threat-logic threshold, crew procedure, or named engagement configuration.
    What this does not establish
    It does not establish that the core operational logic uses machine learning or that every firing occurs without supervision.

    Ship self-defense

    SeaRAM

    Official program description

    A close-in ship-defense system combining autonomous Phalanx search and track functions with a guided interceptor launcher.

    FindTrackPrioritizeEngage
    Public evidence establishes
    The official Navy fact file describes a self-contained detect-through-engage defensive architecture.
    Where the human moves
    The local system can reduce the need for manual track handling and weapon assignment during a rapidly developing threat.
    Control assessment
    Bounded automatic or supervised defensive response; configuration-specific authority is not fully public.
    Unknowns
    Exact operating modes, operator intervention windows, and engagement settings for specific deployments are not public.
    What this does not establish
    It does not prove unrestricted autonomous target generation or use of contemporary AI.

    Selective rocket defense

    Iron Dome

    Official and manufacturer-described; control mode partly unspecified

    A highly automated defensive chain that detects and tracks launches, estimates trajectories and landing areas, and concentrates interceptors on threats assessed to endanger defended zones.

    FindFixTrackPrioritizeAssignAssess
    Public evidence establishes
    Official and manufacturer material supports machine-speed tracking, trajectory analysis, selective defense, and multi-target handling.
    Where the human moves
    Human work moves toward defended-area configuration, readiness, supervision, anomaly handling, and doctrine instead of manual trajectory calculation for every track.
    Control assessment
    Highly automated and configurable; public sources do not support one universal authorization description for every user and mode.
    Unknowns
    Detailed thresholds, launcher-assignment rules, authorization settings, fallback modes, and algorithmic implementation remain nonpublic.
    What this does not establish
    Automation does not by itself establish machine-learning use or a universal human-out-of-the-loop configuration.

    Anti-radiation loitering munition

    IAI HARPY

    Manufacturer-described; safeguards and field behavior partly unknown

    The manufacturer describes a system that can autonomously search for and strike emitting radar targets after human launch and mission setup.

    SearchRecognizeSelectEngage
    Public evidence establishes
    The strongest directly available capability description is the manufacturer’s product statement.
    Where the human moves
    Humans establish the mission and target class before activation; the advertised search and specific-target engagement can occur afterward without target-specific approval.
    Control assessment
    Manufacturer-described autonomous target selection and engagement after activation within a bounded target class.
    Unknowns
    Public material does not fully establish abort mechanisms, ambiguous-emitter handling, exact safeguards, operator doctrine, or customer-specific modes.
    What this does not establish
    A product description is not independent proof of every operational behavior or combat claim.

    Terminal target recognition

    Naval Strike Missile

    Manufacturer-described and fielded; authority details partly unspecified

    The manufacturer describes imaging-infrared Autonomous Target Recognition used to discriminate and recognize an intended target in the terminal process.

    NavigateRecognizeDiscriminateGuide
    Public evidence establishes
    Public evidence supports pre-launch mission targeting and onboard terminal recognition.
    Where the human moves
    Human selection occurs before launch; onboard sensing and recognition reduce the need for continuous remote guidance during the terminal phase.
    Control assessment
    Human mission authorization with autonomous terminal recognition; detailed intervention options are publicly unspecified.
    Unknowns
    Candidate-set rules, target-rejection logic, thresholds, retargeting, and abort behavior are not established by the public product page.
    What this does not establish
    Automatic target recognition is not unrestricted target generation or independent mission creation.

    Post-launch sensing and guidance

    Long Range Anti-Ship Missile

    Official program description; classified details acknowledged

    Official sources describe semi-autonomous operation intended to reduce dependence on external networks in contested environments.

    NavigateLocateIdentifyGuide
    Public evidence establishes
    Public program descriptions support onboard post-launch sensing, locating, identifying, routing, and terminal guidance functions.
    Where the human moves
    Humans authorize and configure the mission before launch while some sensing and route or terminal functions occur onboard.
    Control assessment
    Human mission authorization with significant post-launch autonomy; detailed authority boundaries remain publicly unspecified.
    Unknowns
    The complete release workflow, target-set limits, intervention functions, fail behavior, and detailed discrimination logic are not public.
    What this does not establish
    Post-launch independence does not prove unrestricted target generation or the absence of all human authority.

    One-human-to-many teaming

    Collaborative Combat Aircraft

    Government/operator statement; developmental

    The U.S. Air Force is developing autonomous aircraft functions while publicly retaining human authority over weapon release during current development and testing.

    NavigateTeamSenseTrack
    Public evidence establishes
    Official 2026 Air Force reporting explicitly states that a human retains weapons-release authority in the described integration work.
    Where the human moves
    The operator moves from continuous platform control toward mission command, supervision, tasking, and exception management.
    Control assessment
    Autonomous platform functions with human-retained weapon-release authority in the documented development and testing context.
    Unknowns
    Final fielded interfaces, lost-link behavior, intervention windows, and future configuration details remain under development or undisclosed.
    What this does not establish
    Platform autonomy does not necessarily remove human authority over force.

    Upstream algorithmic gatekeeping

    Project Maven / Maven Smart System

    Official program description

    An AI-enabled intelligence and decision-support environment that processes large data volumes and helps surface, correlate, and present objects or options to human users.

    ObserveFilterFuseRankRecommend
    Public evidence establishes
    Official public descriptions establish computer-vision and data-fusion support for analysts and command workflows.
    Where the human moves
    People no longer inspect every raw observation; human attention moves to a machine-curated representation and selected exceptions.
    Control assessment
    Decision support and upstream filtering; not itself public proof of autonomous weapon release.
    Unknowns
    Public sources do not reveal every model, promotion threshold, error rate, user interface, or operational configuration.
    What this does not establish
    An AI-generated recommendation or ranked option is not independent engagement authority.

    Multidomain intelligence fusion

    TITAN

    Official program description; developmental and fielding details evolving

    A U.S. Army ground-station program using AI and machine learning to process information from space, high-altitude, aerial, and terrestrial sources.

    CollectFuseAnalyzeNominateSupport
    Public evidence establishes
    Official Army descriptions support AI/ML-enabled processing and the delivery of fused information for operational decision support.
    Where the human moves
    Analysts receive a synthesized picture instead of manually reconciling every source and handoff.
    Control assessment
    AI-enabled processing and targeting support; autonomous release is not established.
    Unknowns
    The public record does not disclose exact fusion methods, contradiction handling, promotion thresholds, or every downstream authority relationship.
    What this does not establish
    Rapid target nomination does not equal autonomous lethal engagement.

    Distributed sensing and data products

    SDA Tracking Layer

    Official program description

    A space-based layer publicly described as combining sensing, algorithms, processing, data fusion, and tactical data products for missile warning and tracking.

    SenseProcessFuseTrackDistribute
    Public evidence establishes
    The official Space Development Agency architecture documents tracking and data-product functions.
    Where the human moves
    Machine processing correlates observations across a proliferated network before a human command element receives a usable track product.
    Control assessment
    Automated sensing and data fusion; independent interceptor launch is not established.
    Unknowns
    Exact algorithms, confidence handling, classified performance, and downstream command arrangements are not public.
    What this does not establish
    Fire-control-quality data does not mean the sensing layer independently applies force.

    Sensor and effector integration

    Integrated Battle Command System

    Official program description; AI use not universally established

    An Army command-and-control network intended to connect multiple sensors and effectors into a common integrated air-and-missile-defense picture.

    FuseTrackShareCoordinate
    Public evidence establishes
    Official Army material supports the networked integration of sensors, command nodes, and defensive effectors.
    Where the human moves
    Personnel supervise and decide through a composite picture rather than operating isolated sensor and weapon silos.
    Control assessment
    Integrated command and sensor fusion; AI use and engagement authority must be assessed by specific function and configuration.
    Unknowns
    The public record does not establish which operational functions use machine learning, exact correlation logic, or every authorization setting.
    What this does not establish
    A “connect any sensor to any shooter” architecture is not proof of autonomous firing.

    Continue the investigation

    Turn the lab into a repeatable challenge

    The Daily Break the Chain catalog now includes scenarios about hidden evidence, approval queues, lost-link policy, pre-mission authority, and accountability gaps. Each uses PHP-authoritative state, deterministic replay, and synthetic-only evidence.

    Daily challenge

    Test one bounded decision

    Inspect evidence, state confidence, select a proportionate control, and compare the path not taken.

    Enter today’s challenge

    Evidence Atlas

    Separate capability from claim

    Compare systems, doctrine, public control modes, evidence states, and unknowns without tactical coordinates.

    Open the Atlas

    Methodology

    Audit the source language

    Review how official records, manufacturer statements, independent analysis, disputes, and unknowns are classified.

    Read the method

    Ecosystem boundary

    Learn the failure here. Make the deployed machine answerable at Evulgare.

    KillChains.com remains a synthetic simulation and public-research environment. KillWebs.com remains the sister learning environment for governed network paths. Stop using software that makes the nearest human explain a decision they could not see, verify, or control. Real-system evidence capture, software and model lineage, authority reconstruction, operator-view reconstruction, incident causality, and deployed-system answerability belong at Evulgare.com.

    The Human Control Lab demonstrates the accountability questions with synthetic values. Evulgare is the production destination for capturing what a deployed human actually saw, understood, could interrupt, and was authorized to do.