Machine-speed decisions need machine-held evidence. Bounded education only: no real targets, operational control, executable payloads, or live-system actions. A human click is not a liability transfer. For production evidence and accountability software, visit Evulgare.com ↗.
Functions before labels
The systems that enable, automate, or constrain a kill chain
The most consequential component may be a sensor-fusion application, a command network, a terminal seeker, a mobility stack, or a safety controller—not the platform that is most visually dramatic.
System of systemsControl mode variesPublic details incomplete
Public programs generally emphasize human command or supervision; lethal release details are often undisclosed
Critical caveat
Emergent group behavior, duplicate engagement, network fragmentation, and one-human-to-many-agent workload are unresolved assurance challenges.
08 · Attacks against models, data, context, tools, memory, and AI infrastructure
AI-system security chain
Security
Representative examples
RAG poisoning
Prompt injection
Model supply-chain compromise
Agent tool abuse
Documented or typical AI functions
The AI is the target or the compromised intermediary—not necessarily a military system
Assessed control mode
External deterministic authorization, least privilege, provenance, isolation, and rollback
Critical caveat
This meaning of “AI kill chain” is distinct from an AI-enabled military targeting chain.
Autonomy spectrum
Capability and authority move on different axes.
A sophisticated vehicle may autonomously navigate while a human controls every weapon action. A relatively old automatic-defense system may hold greater engagement authority without using machine learning.
Level
Machine function
Human role
Representative context
Decision support
Detects, fuses, ranks, or recommends
Reviews evidence and authorizes any external effect
Imagery analysis, target cueing, course-of-action support
Bounded mission autonomy
Navigates, searches, tracks, or executes a planned route
Defines mission and target parameters; may supervise or retask
Learned components should operate inside harder limits.
A robust system combines multisensor corroboration, calibrated uncertainty, an explicit unknown or reject state, signed software and model artifacts, isolated safety monitors, runtime geofencing, authenticated commands, safe-state behavior, independent abort paths, tamper-evident logs, and reversion to a simpler verified controller when the learned component leaves its validated envelope.
These controls do not prove that a system is lawful or safe in every use. They create evidence and enforceable boundaries that a policy, human operator, and legal review can assess.