Bounded simulation: no real targets, coordinates, casualty models, weapon-performance parameters, executable payloads, or operational attack instructions.

Definitions before conclusions

What a “kill chain” is—and what it is not

A kill chain is a staged model that links observation, preparation, decision, action, and assessment. The phrase is used in several domains, and those meanings should not be silently merged.

Term family, not one standardFunction–context analysisEvidence labels required

Three primary meanings

The same phrase can describe different objects.

The common logic is a linked sequence with multiple opportunities for interruption. The object being modeled, the authority delegated to software, and the consequences of failure are different in each case.

01 · Military decision and engagement

F2T2EA and related targeting cycles

Find, Fix, Track, Target, Engage, Assess converts observations into an intended operational effect. AI can assist one or more functions without controlling the entire sequence.

Primary questions: identity, uncertainty, legal status, authorization, intervention, and effects assessment.

02 · Cyber intrusion lifecycle

Campaign progression through a network

The classic model uses Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.

Primary questions: what the adversary attempted, what defenders could observe, and where a control could disrupt progression.

03 · Attack against an AI-enabled system

Model, data, context, tool, and memory compromise

A compact application-centered model is Recon, Poison, Hijack, Persist, Impact, with an Iterate/Pivot loop for agentic systems.

Primary questions: trust boundaries, instruction/data confusion, downstream authority, persistent state, egress, and rollback.

The essential distinction

AI-enabled does not mean autonomously lethal.

The correct unit of analysis is the function–context pair: which function is automated or learned, in what environment, for what duration, against what target class, under which constraints, with what human information and intervention capability?

FunctionPossible AI contributionWhat it does not establishControl question
SensingAnomaly detection, adaptive search, clutter reductionIdentity, legal status, or authorizationIs the source trusted, current, and observing the intended area?
Fusion and trackingAssociation, confidence estimation, trajectory predictionThat correlated sources are genuinely independentAre provenance, contradictions, stale data, and uncertainty visible?
ClassificationObject recognition, segmentation, behavior scoringPositive identification or contextual understandingHow does performance change under novel, degraded, or deceptive conditions?
Decision supportRanking, prioritization, course-of-action generationLegal judgment, proportionality, or command responsibilityIs the system recommending, filtering, or effectively determining the choice?
Navigation and guidanceRoute planning, obstacle avoidance, terminal discriminationIndependent authority to select a targetWho established the mission bounds and who can abort?
AssessmentChange detection, damage classification, re-action recommendationThat a follow-on action is justifiedCan an uncertain assessment automatically trigger another effect?

Human-control terminology

Loop labels are a starting point, not proof of meaningful control.

Terminology is not globally standardized. Knowledge, time, workload, information quality, the reliability of intervention, and the scope of delegated action matter more than the presence of a person somewhere in the organization chart.

Human in the loop

Affirmative authorization

A human must authorize the application of force to a particular target or engagement. Navigation, cueing, tracking, or aiming may still be automated.

Human on the loop

Supervision and intervention

The system may select and engage within bounded parameters while an operator monitors and can abort, deactivate, or override.

Out of the loop after activation

Predefined mission bounds

The operator establishes parameters before activation, after which the system can match sensor observations to a target profile and initiate engagement without approving each selected object.

Knowledge

Does the operator understand capabilities, limits, target profile, and likely effects?

Information

Are identity, provenance, uncertainty, contradictory evidence, and civilian context visible?

Time and attention

Is there capacity for a genuine decision rather than reflexive approval under overload?

Intervention and bounds

Can the system be stopped, and are target type, area, time, scale, and effects constrained?

Chains and webs

A kill web distributes the functions.

A simple chain suggests one sensor, one command path, and one effector. Contemporary architectures often distribute sensing, data fusion, decision support, communications, and effects across satellites, aircraft, ground stations, ships, command applications, and multiple weapons. A node may be replaced or rerouted, creating a more resilient kill web.

Distribution changes the assurance problem. One false or stale track can propagate through several services. Responsibility may be divided among data providers, software vendors, network operators, commanders, and weapon crews. Provenance and authority metadata therefore need to travel with a track from collection through assessment.

A network can be resilient to the loss of a node while becoming more vulnerable to the rapid propagation of a plausible but incorrect state.

Continue to the functional anatomy.

Common misconceptions

Language that needs qualification

Public product pages and news coverage frequently compress several technical and governance questions into one label. These corrections keep the analysis bounded.

“Autonomous” is not a complete control description.

It may refer to navigation, search, mission execution, terminal guidance, target-profile matching, or weapon release. The function and mission constraints must be named.

“AI” and “automation” are not synonyms.

Some automatic defensive systems use deterministic, rule-based, or model-based logic without a learned classifier. They may still hold significant engagement authority.

A classifier confidence score is not probability of legal correctness.

Confidence may be poorly calibrated and says nothing by itself about source reliability, identity continuity, civilian status, or proportionality.

Human approval can still be ineffective.

An overloaded operator with seconds to review opaque machine recommendations may function as a rubber stamp despite being nominally “in the loop.”

Manufacturer claims are evidence, not independent verification.

They can establish what a company publicly says a system does, but not necessarily combat performance, deployed configuration, or operator doctrine.

Country-level summaries are not monolithic national capabilities.

Programs, services, vendors, operators, versions, and mission sets vary. Public disclosure is uneven, and important details remain classified or disputed.