| Target misclassification | High | Civilian, friendly, damaged, decoy, or novel object is confused with an authorized class | Multisensor confirmation, unknown/reject class, conservative thresholds, contextual review |
| Automation bias | High | Human accepts a ranked target or recommendation without independent evaluation | Evidence-linked explanations, alternatives, disconfirming data, workload limits, training |
| Adversarial deception | High | Spoofing, decoys, camouflage, RF manipulation, or adversarial inputs create or hide tracks | Sensor diversity, physical consistency checks, red teaming, anomaly detection |
| Cyber or supply-chain compromise | High | Software, model, mission data, communications, or updates are modified | Signed artifacts, secure boot, least privilege, SBOM/AI-BOM, isolated safety channels |
| Cascading kill-web error | High | One false track propagates through fusion, prioritization, and automated assignment | Track provenance, independent confirmation, confidence decay, authority separation |
| Communications loss | Medium–high | System continues with stale intent, cannot receive abort, or fails unpredictably | Explicit lost-link state machine, bounded continuation, hold/return/abort, local constraints |
| Emergent swarm behavior | Medium–high | Local rules create collision, duplication, unsafe concentration, or escalation | Formal constraints, scale simulation, runtime monitors, resource limits, graceful degradation |
| Escalation compression | High consequence | Automated warning and response reduce time for deliberation | Human confirmation for strategic effects, multisource validation, deliberate delay where feasible |
| Civilian-harm scaling | High | Target throughput grows faster than meaningful human review capacity | Review-rate limits, civilian-presence constraints, independent collateral analysis, audit sampling |
| Model drift and unauthorized change | High over lifecycle | Updates or environmental change invalidate prior certification | Configuration control, versioned safety cases, regression testing, reapproval thresholds |
| Accountability failure | High | Logs cannot reconstruct who knew what, which model ran, or why force was applied | Tamper-evident traces, synchronized clocks, decision provenance, named responsibility |