Bounded simulation: no real targets, coordinates, casualty models, weapon-performance parameters, executable payloads, or operational attack instructions.

Functions before labels

The systems that enable, automate, or constrain a kill chain

The most consequential component may be a sensor-fusion application, a command network, a terminal seeker, a mobility stack, or a safety controller—not the platform that is most visually dramatic.

System of systemsControl mode variesPublic details incomplete

Question 1

What function is autonomous?

Search, navigation, classification, ranking, weapon assignment, terminal guidance, or engagement are distinct functions.

Question 2

What is the target set?

Incoming materiel threats, emitting radars, ships, vehicles, structures, or persons create very different assurance and legal problems.

Question 3

What bounds the mission?

Area, time, target profile, sensor health, communications state, ammunition, and abort behavior define the actual delegation.

Question 4

What is publicly known?

Separate official documents, manufacturer claims, independent analysis, reported use, demonstrated prototypes, and undisclosed details.

01 · Find, Fix, Track, and decision support

AI-assisted intelligence and target cueing

Decision

Representative examples

  • Maven Smart System
  • TITAN-style fusion nodes
  • Space and airborne sensing networks

Documented or typical AI functions

  • Computer vision
  • Multisensor fusion
  • Track correlation
  • Prioritization and course-of-action support

Assessed control mode

Usually decision support upstream of weapon release

Critical caveat

Upstream rankings and identity errors can constrain a human’s apparent choice even when a human presses the final button.

02 · Connect distributed sensors, command nodes, and effectors

Networked command-and-control / kill webs

Decision

Representative examples

  • CJADC2-related architectures
  • Integrated air-defense networks
  • Coastal defense networks

Documented or typical AI functions

  • Track fusion
  • Threat evaluation
  • Sensor–effector recommendation
  • Resource allocation

Assessed control mode

Varies; often human command with automated recommendations and time-critical defensive modes

Critical caveat

A single false track can propagate through several systems unless provenance, confidence decay, and authority separation are enforced.

03 · Track, discriminate, and select an aim point after launch

Autonomous terminal recognition

Weapon

Representative examples

  • Naval Strike Missile
  • SPICE family
  • Other imaging-seeker munitions

Documented or typical AI functions

  • Scene matching
  • Automatic target recognition
  • Target discrimination
  • Aim-point selection

Assessed control mode

Bounded post-launch autonomy after human mission authorization; details vary

Critical caveat

Automatic recognition is not the same as independent strategic target generation, and public classifier performance is rarely disclosed.

04 · Search, monitor, identify, and engage within a mission profile

Loitering munitions

Weapon

Representative examples

  • HARPY
  • HAROP
  • Mini HARPY
  • Lancet-family systems

Documented or typical AI functions

  • Emitter recognition
  • Electro-optical tracking
  • Onboard target recognition
  • Terminal guidance

Assessed control mode

Spectrum from man-in-the-loop to manufacturer-described autonomous target-profile matching

Critical caveat

Marketing terms such as “fully autonomous” must be tied to target class, area, time, sensor, abort, and operator role.

05 · Detect and react to fast incoming materiel threats

Automated local defense

Weapon

Representative examples

  • Close-in weapon systems
  • Air and missile defense
  • Counter-drone systems

Documented or typical AI functions

  • Detection
  • Tracking
  • Threat evaluation
  • Interceptor assignment
  • Automated engagement logic

Assessed control mode

Often operator-supervised automatic modes in tightly bounded defensive contexts

Critical caveat

Many mature systems are automated but not machine-learning based; “autonomous” and “AI” are not synonyms.

06 · Mobility, sensing, logistics, patrol, and optional weapon carriage

Robotic ground and maritime platforms

Platform

Representative examples

  • THeMIS
  • Mission Master
  • Uncrewed surface vessels

Documented or typical AI functions

  • Navigation
  • Obstacle avoidance
  • Follow-me
  • Route planning
  • Sensor cueing

Assessed control mode

Frequently human-in-the-loop for kinetic decisions in publicly described Western systems

Critical caveat

A vehicle can be highly autonomous in movement while retaining human control over weapons.

07 · Distributed sensing, decoys, communications, maneuver, and coordinated mission tasks

Collaborative aircraft and swarms

Platform

Representative examples

  • Collaborative Combat Aircraft
  • Drone swarms
  • Swarms-of-swarms research

Documented or typical AI functions

  • Task allocation
  • Formation and collision avoidance
  • Distributed consensus
  • Mission replanning

Assessed control mode

Public programs generally emphasize human command or supervision; lethal release details are often undisclosed

Critical caveat

Emergent group behavior, duplicate engagement, network fragmentation, and one-human-to-many-agent workload are unresolved assurance challenges.

08 · Attacks against models, data, context, tools, memory, and AI infrastructure

AI-system security chain

Security

Representative examples

  • RAG poisoning
  • Prompt injection
  • Model supply-chain compromise
  • Agent tool abuse

Documented or typical AI functions

  • The AI is the target or the compromised intermediary—not necessarily a military system

Assessed control mode

External deterministic authorization, least privilege, provenance, isolation, and rollback

Critical caveat

This meaning of “AI kill chain” is distinct from an AI-enabled military targeting chain.

Autonomy spectrum

Capability and authority move on different axes.

A sophisticated vehicle may autonomously navigate while a human controls every weapon action. A relatively old automatic-defense system may hold greater engagement authority without using machine learning.

LevelMachine functionHuman roleRepresentative context
Decision supportDetects, fuses, ranks, or recommendsReviews evidence and authorizes any external effectImagery analysis, target cueing, course-of-action support
Bounded mission autonomyNavigates, searches, tracks, or executes a planned routeDefines mission and target parameters; may supervise or retaskRobotic mobility, collaborative sensing, post-launch navigation
Terminal autonomyDiscriminates an object or aim point after launchAuthorizes mission before release; exact intervention variesImaging seekers and contested-environment munitions
Operator-supervised automatic defenseDetects, evaluates, and may engage time-critical materiel threatsConfigures, monitors, and can deactivate or override where feasibleClose-in defense, air defense, counter-drone point defense
Target-profile matching after activationSearches for and engages objects matching a bounded profileDefines area, time, target class, and mission before activationManufacturer-described anti-radiation loitering modes

Assurance architecture

Learned components should operate inside harder limits.

A robust system combines multisensor corroboration, calibrated uncertainty, an explicit unknown or reject state, signed software and model artifacts, isolated safety monitors, runtime geofencing, authenticated commands, safe-state behavior, independent abort paths, tamper-evident logs, and reversion to a simpler verified controller when the learned component leaves its validated envelope.

These controls do not prove that a system is lawful or safe in every use. They create evidence and enforceable boundaries that a policy, human operator, and legal review can assess.

Continue to risk, law, and human control.