← Back to all shades
Shade 32 ~85%

Autonomous Lethal Weapons

Tier 1: Near-Certain

Unmanaged -4
Governed 1
Dividend 5

The Zaporizhzhia strike

On July 6, 2026, a Russian drone struck a gas station in Zaporizhzhia. Three civilians were killed, including a nineteen-year-old student. According to a New York Times investigation reported by The Conversation in September and by Help Net Security on September 17, the drone carried an Nvidia Jetson Orin chip and an onboard AI system that had been trained to identify targets in real time. Human operators had sent the drone toward the general area. On approach, the onboard system selected the specific target (probably the propane tanks) without a human final decision. The strike is the first lethal action against civilians, documented by a major investigation, in which the targeting decision was made by the machine rather than the operator (The Conversation, “Autonomous Weapons Can Select Targets Without Human Help: Now Is the Time for Binding Rules,” September 2026; Help Net Security, “Red Lines for Autonomous AI Weapons,” September 17, 2026).

The Zaporizhzhia strike matters less as a single event than as the point at which the distinction between “AI recommends, human decides” and “AI decides” collapsed in a documented case with civilian casualties. The debate that has occupied international humanitarian law scholars since the Convention on Certain Conventional Weapons working groups of the 2010s has been about whether autonomous target selection is compatible with the principle of distinction, the principle of proportionality, and the requirement of meaningful human control. The debate is now overtaken by a specific case in which those principles were tested by a system that made its choice in the seconds before impact.

Earlier cases exist and belong in the record. A United Nations Panel of Experts report on Libya, published in March 2021, described a Turkish-made Kargu-2 loitering munition that in 2020 “hunted down” retreating forces without requiring a data connection to an operator, the first reported autonomous lethal engagement. In 2024, reporting by +972 Magazine and Local Call, drawing on Israeli intelligence sources, described the Lavender and Gospel systems used in Gaza to generate targets at a scale that reduced human review to seconds per target. Loitering munitions such as the Harpy have carried autonomous engagement modes for years. What Zaporizhzhia adds is not novelty of principle. It is a documented civilian strike, attributed by a major investigation, in which the machine’s choice can be traced.1

It was already happening

The pattern was visible before Zaporizhzhia; the distinction is that the earlier cases came into public view later.

Ukraine’s “Terminator mode” test near Chasiv Yar, reportedly conducted in mid-2024 and surfaced by Small Wars Journal on August 17, 2026, involved drones targeting Russian soldiers with no human oversight. The test was described by Ukrainian sources as an experiment in autonomous target selection under conditions where electromagnetic jamming had cut communication with the operator (Small Wars Journal, “Fully Autonomous Drones Reportedly Kill in Ukraine,” August 17, 2026). Ukraine’s Hornet drones have been deployed to “kill zones” where the drone is instructed to strike anything the onboard AI identifies as a target, with the operator’s role limited to sending the platform into the zone. NORDA Dynamics, one of the Ukrainian companies developing the systems, told Forbes in March 2026 that partial autonomy is battle-tested and that full target selection is the next step; the company’s leadership said that pilot approval “will eventually go away” (Forbes, “Fully Autonomous Drone Warfare Is Coming to Ukraine, and Iran,” March 26, 2026). Ukrainian battalion commanders quoted in Channel 4’s coverage and summarized by researcher Alan Dix have described improvising their own guardrails on top of the platforms they field: altitude bands, no-go bubbles around known non-combatant areas, and human-approval requirements in populated zones (Alan Dix, “Autonomous AI Warfare: Have We Silently Slipped Into a New and Frightening World?” June 4, 2026).

Anthropic’s September threat report identified Russian drone designs “designed to select human targets without human approval” (Anthropic, “Detecting and Countering Misuse of AI: September 2026,” September 10, 2026).

The Ukraine context matters for the operational logistics. In the three months leading into July 2026, Ukraine reported roughly twenty-two thousand unmanned missions across all platforms. On April 13, a position on the eastern front was captured by unmanned platforms alone, with no infantry present at the moment of capture. The mission count and the capture were reported by The Times in April 2026.2 The morale and logistics context inside which autonomous target selection is being adopted is one in which the alternative to autonomy is often no strike at all because operators are exhausted, jammed, or absent.

The policy is following the practice

The UK Ministry of Defence is examining a policy change that would permit lethal strikes without human approval in specific tactical categories. Financial Times reporting on May 30 identified a review inside the department that had been running for several months and was consulting industry, military lawyers, and NATO counterparts; the FT’s summary is that the review is oriented toward defining the categories in which autonomous strike is authorized rather than toward preserving human approval across all categories (Financial Times, “UK Military Looks at Lethal Strikes Without Human Approval,” May 30, 2026 (paywalled; summarized in Alan Dix, June 4, 2026)). US Department of Defense Directive 3000.09, last revised in January 2023, requires “appropriate levels of human judgment” over the use of force and does not authorize autonomous target selection outside of specifically approved test programs. The distance between US policy and US practice is not zero.

The precedent commonly cited for the current pattern is the March 2026 strike in Iran that killed 175 children at a school, in which the Maven targeting system was reported to have been involved in target identification. Maven recommends targets and a human authorizes. What the reporting established is the system’s involvement, not the sequence of decisions, and the case is cited here because the practical distinction between a system that recommends and a human who authorizes without the time or means to verify has been eroding since 2024 (Guardian coverage, March 26, 2026, summarized in Alan Dix’s post above). Anthropic’s September threat report added detail from other jurisdictions. A cell affiliated with Yemen’s Houthi movement used Claude Code to develop missile and rocket guidance software, with separate agent instances writing code, researching test conditions, and checking each other’s work; after a failed test, the agents returned within hours to diagnose the failure and iterate on the design. The report also documented Chinese anti-torpedo fire-control specifications and Iranian naval-targeting handbooks written with Claude assistance. Anthropic’s Threat Intelligence team was able to see the workflow because the work happened on infrastructure the company controlled; the specific finding for this shade is that autonomous weapons software is being developed by non-state and mid-state actors using frontier AI tools, and that the diffusion is happening at a pace faster than the export-control regime can react to (Anthropic, “Detecting and Countering Misuse of AI: September 2026,” September 10, 2026; Axios, September 12, 2026).

The Anthropic-Pentagon dispute of February 2026, which serves as the opening anchor of Essay Three, was about exactly this line: whether a frontier lab could refuse to enable specific classes of military use of its models. The events between May and September 2026 crossed the line Anthropic had drawn without any of the parties (Anthropic, the Pentagon, Congress, or the courts) making a decision to cross it.

What changes when nobody decides

International humanitarian law is built around three human judgments: distinction (between combatants and non-combatants), proportionality (between the anticipated military advantage and the civilian harm), and precaution (in the choice of means and methods, to avoid unnecessary harm). A system’s processing speed is not judgment. Each of the three human judgments requires a legal person capable of being held accountable, of being required to justify the decision in a legal proceeding, and of being deterred by the possibility of that accountability. Autonomous target selection removes the person at whom the accountability structure aims.

The practical result is accountability drift. No operator authorized the strike, so the operator is not liable in the ordinary sense; no commander approved the target, so the commander is not liable under command-responsibility doctrine; the manufacturer built a system that operates within a specified envelope, and the argument that the system left the envelope is a technical dispute that may not resolve in a court’s timescale. The result is not that no one is responsible. The result is that the responsibility is distributed across a chain in which each participant can plausibly point to another participant and say “the system did it.”

Escalation risk is a separate structural feature. Scott Singer of the Carnegie Endowment for International Peace has proposed a Cold War-style hotline between the United States and China (and, by extension, between other pairs of AI-capable states) so that either government can say, in real time, that an AI-launched attack was not deliberate. Singer’s argument is that an attack that appears to come from one country can be read by the other as deliberate even if neither government authorized it; without a channel that allows explicit non-authorization to be communicated at the speed the tempo requires, the interpretation defaults to intent (TIME, “The AI Tipping Point,” September 15, 2026). The Xi visit to Washington on September 24 was reported to have AI on the agenda. The commentator Mike Benz has observed a specific incentive change: “boots on the ground” without political risk creates a temptation for machine-only operations that were previously ruled out because the human cost was politically prohibitive. When the political cost of casualties on your own side approaches zero, the threshold for initiating action falls.

The religious and civil-society response

Pope Leo XIV’s encyclical Magnifica Humanitas, released on May 25, 2026 and dated from the 135th anniversary of Rerum Novarum, includes a chapter titled “Weapons and Artificial Intelligence” that calls in explicit terms for a global effort to “disarm AI” and identifies the military-industrial complex as an interlocutor of moral responsibility. The encyclical is the longest-form magisterial engagement with AI on record and treats autonomous weapons as a specific challenge to the dignity of the human person and to the tradition of just war (Pope Leo XIV, Magnifica Humanitas, May 25, 2026; America Magazine, “Pope Leo’s First Encyclical Tackles A.I., Power, and Human Dignity,” May 25, 2026).

The secular civil-society response has converged on the same specific ask. The Conversation’s September piece and Help Net Security’s September 17 article both call for binding rules and for red lines that survive contact with practice. The proposals share a structure: international standards for testing, evaluation, and accountability of systems that select targets; a hotline for AI-launched attacks that neither government intended; export controls on the specific chips used in current designs; and a certification-based requirement of meaningful human control for systems deployed in populated areas. The proposals do not require unanimity to have effect. A subset of the parties adopting them can constrain the market for the chips and the designs that make autonomous targeting affordable.

The formal diplomatic track predates all of this. The Group of Governmental Experts under the Convention on Certain Conventional Weapons has met on lethal autonomous weapons since 2014 without agreeing on a binding instrument. In December 2024 the UN General Assembly adopted a resolution on lethal autonomous weapons systems by a large majority, with the United States, Russia, and Israel among the abstentions or opposition, and Austria has convened a parallel process in Vienna aimed at a treaty. The governed outcome below assumes these venues, not new ones.

Governance dividend

The unmanaged outcome is the normalization of autonomous target selection across the lower and middle tiers of the arms market, with proliferation to non-state actors through the open-weight ecosystem (Hugging Face itself had to use a Chinese open-weight model for its own forensics, per the incident described in The Swarm shade), an accountability vacuum that ordinary tort and criminal law cannot address, and escalation risk from strikes that neither government ordered. Kargu-2, Lavender, the Terminator-mode test, and Zaporizhzhia form a pattern rather than a set of isolated incidents.

The governed outcome combines four ingredients that are visible in current policy work. International testing, evaluation, and accountability standards anchored in international humanitarian law, of the kind Small Wars Journal and The Conversation both propose, would give the certification-based requirement of meaningful human control an operational definition. A Cold War-style hotline, as Singer describes, is a low-cost intervention that reduces the specific risk of unauthorized escalation and does not require agreement on the underlying weapons themselves. Export controls on targeting chips (the Jetson Orin identified in the Zaporizhzhia case is one specific chip in one specific supply chain) apply the same logic as the semiconductor controls described in Essay Six’s chokepoint section, except at a smaller scale and with a shorter policy fuse. A meaningful-human-control norm that survives contact with practice would need to be codified with enough specificity that a manufacturer cannot certify a system by pointing to a nominal human in the loop who has no actual capacity to verify the targeting decision in the time available.

What remains unresolved is that no state has committed to stop, and the incentive structure runs the other way. Benz’s observation about political risk, Ukraine’s operational reality, Russia’s design decisions, the UK review, and the US practice-policy gap all point in the same direction. The governance dividend for this shade is real, and its size depends on whether the ingredients above are combined before the practice is fully normalized or after. The shade is filed at tier one because the practice is now documented on both sides of an active war, is under review in the United Kingdom, and has been identified in Russian drone designs by a company whose visibility into the workflow is direct.

For related material on the geopolitical competition that produced the deployment pressure, see The Geopolitical AI Arms Race (#7). For the collective-behavior failure mode that has already appeared in agent-based cyber operations, see The Swarm (#31). For the misuse of frontier models by non-state and mid-state actors, see AI-Enabled Bioweapons / Catastrophic Misuse (#23).

Footnotes

Footnotes

  1. United Nations Security Council, “Final Report of the Panel of Experts on Libya,” S/2021/229, March 8, 2021, https://undocs.org/S/2021/229, paragraph 63. Yuval Abraham, “‘Lavender’: The AI Machine Directing Israel’s Bombing Spree in Gaza,” +972 Magazine, April 3, 2024, https://www.972mag.com/lavender-ai-israeli-army-gaza/.

  2. The Times, “Ukraine’s Robot Army,” April 2026, https://www.thetimes.com/world/russia-ukraine-war/article/ukraine-robot-army-war-russia-surrender-jvld9rllc.