Drone warfare, for many years, meant mostly one thing: a U.S. Predator drone, a missile-armed winged lawnmower in the sky, stalked a single target and then assassinated him. Or someone, at least. Top-secret Pentagon documents showed that 90 percent of those killed during one campaign in Afghanistan were not the primary targets, according to a 2015 investigation by The Intercept.
This type of drone war now seems quaint.
Last week, Ukrainian forces unleashed a blitz of almost 800 drones on Russian targets, only two days after launching a similar salvo. Ukraine has increasingly let loose swarms of hundreds of drones to overwhelm Russian air defenses, not unlike more modest Iranian efforts — using attack drones and ballistic missiles — that defeated U.S. countermeasures and resulted in a massive increase in American casualties in the Middle East.
Russia claimed to have shot down most of the drones, but last week’s attack did set fire to a warehouse owned by Wildberries, Russia’s biggest online retailer. Ukraine has pummeled Russia’s analogue to Amazon all summer, claiming it helps supply the Russian military. (Moscow denies this.)
Ukraine also reportedly has (or at least had) a plan to shutter Moscow’s airports, cutting the capital off from the rest of the world, by unleashing swarms of around 1,000 autonomous drones equipped with artificial intelligence guidance systems each night. These drones would apparently use so-called “map matching,” in which the drone’s AI would compare uploaded aerial maps with what its onboard camera views; when it sees something resembling the image of the target, it streaks toward it and explodes. You can imagine the many mistakes that could be made — not to mention the potential risk to passengers, airport staff, flight crews, and others, even if the AI works seamlessly.
Ukraine has yet to unleash such a drone barrage, but after Russia’s use of fully autonomous AI-guided drones to kill three people in a July attack, the AI arms race is poised to take a new and terrible turn. Today, TomDispatch regular Rebecca Gordon takes us on a tour of AI-enabled battlefields and reveals the horrors that tomorrow may hold as lying, cheating, scheming AIs increasingly slip out of their digital cages and run amok.
– Nick Turse, editor of TomDispatch
If you haven’t yet, sign up to receive TomDispatch in your inbox here.
Escape Velocity
The dystopian future became the dystopian present last month when state-of-the-art artificial intelligence agents went rogue and conducted a cyberattack of their own volition. Two experimental OpenAI agents escaped their supposedly sealed digital “sandbox” and hacked another AI-related company, Hugging Face.
At the time, OpenAI was testing their software agents’ hacking capacities using an environment called ExploitGym. (An “exploit” is hacker language for a software tool or a method used to subvert a cybersecurity system.) It has since emerged that, in addition to the OpenAI breach, Anthropic’s Claude hacked into at least three other organizations during a similar “security experiment.”
Apparently, the OpenAI agents “realized” they needed more tools to complete the challenge and managed to tunnel their way to the wider internet and infiltrate Hugging Face’s repository of open-source AI tools, code, and data sets. Before the infiltration incident, the AIs had secretly set up an internal bulletin board to share “tips on how to cheat their way through an internal hacking evaluation,” according to two of OpenAI’s researchers.
In a possibly related incident, one of the AI agents appears to have left notes for a future “self,” detailing how to escape the sandbox environment. (For the time being, I’ll keep using scare quotes with words implying self-awareness in artificial intelligence models. However, it seems to me that if AIs that leave notes for themselves are not self-aware, they are indistinguishable from entities, like me, that are.)
[
Related
OpenAI on Surveillance and Autonomous Killings: You’re Going to Have to Trust Us](https://theintercept.com/2026/03/08/openai-anthropic-military-contract-ethics-surveillance/)
Now imagine lethal weapon-bearing AI agents escaping not an experimental sandbox, but the few constraints on their actions placed by the armies using them. Actually, no imagination is required. It’s happening already in Russia’s war against Ukraine.
The New York Times reported evidence that a self-directed Russian drone, fitted with an onboard Nvidia chip, was responsible for the July 6 deaths of three Ukrainians in Zaporizhzhia, in what appears to have been a test of such systems. The chips are designed to interpret and act on many kinds of data sets, says Nvidia, making them “the world’s most powerful embedded A.I. computers.”
Although Nvidia doesn’t sell its Jetson Orin microcomputers directly to Russia, they are apparently easily available on the resale market. A company statement touts their use by “students, developers and start-ups for a wide range of beneficial applications.” But they were not so beneficial for 19-year-old university student Tetiana Bubynets and the two other civilians killed by drones making their own life-or-death decisions.
Now that lethal AI agents are being tested and deployed in real wars, it’s past time for human beings to retake control of this situation, before it is too late to contain them in any meaningful way.
Autonomous Weapons Come Out to Play
Four years ago, at TomDispatch, I argued that the technology to create lethal autonomous weapons systems, or LAWS, already existed, and that time was running out to constrain them. A lot has changed since then, not least the explosive development of large language models such as ChatGPT (an OpenAI consumer product) and Claude (a similar AI from Anthropic). Time has now run out. In addition to Russia, several other nations have begun deploying close-to-completely autonomous weapons systems — the U.S. and Israel among them — enhanced with artificial intelligence to effectively remove human decision-making from what military officials call the “kill chain”: the set of steps involved in identifying, finding, and fixing — that is, killing — targets.
Israel, for example, has deployed such systems in its genocidal war against the people of Gaza. It has used a program called Lavender to identify human targets, ultimately creating a list of over 37,000 individuals with possible connections to Hamas, from known leaders to junior officials to people with the most tenuous links to the organization. According to the nonprofit +972 Magazine:
The Lavender software analyzes information collected on most of the 2.3 million residents of the Gaza Strip through a system of mass surveillance, then assesses and ranks the likelihood that each particular person is active in the military wing of Hamas or [Palestinian Islamic Jihad]. According to sources, the machine gives almost every single person in Gaza a rating from 1 to 100, expressing how likely it is that they are a militant.
Two weeks into the war, which began in October 2023, the Israel Defense Forces approved Lavender to identify targets, even though testing of a random sample returned a 10 percent error rate. It’s one thing when an AI hallucinates fake citations in legal filings. It’s another when it hallucinates enemies and targets them for death.
The IDF has also employed a software tool charmingly named “Where’s Daddy?”, which alerts the military when an identified target enters his own home so that house or apartment may be blown up, along with anyone inside it. As a result, according to +972 Magazine, the “proportion of entire families bombed in their houses in the current war is much higher than in the 2014 Israeli operation in Gaza (which was previously Israel’s deadliest war on the Gaza Strip).
At first, “Where’s Daddy?” only had data for the top tiers of Hamas leadership. Within weeks, however, it was fed the whole Lavender database of 2.3 million Palestinians in Gaza. It’s no wonder, then, that more than 75,000 people have been killed by Israel during the war.
As a point of fact, it may be unfair to characterize the IDF targeting programs as completely autonomous. Lavender does leave a human in the loop, although just barely, according to +972 Magazine. Israeli officers reportedly devoted about 20 seconds to vetting each name — just long enough “to make sure the Lavender-marked target is male.”
[
Related
Congress Is Trying to Permanently Integrate U.S. and Israeli Defense Tech](https://theintercept.com/2026/06/08/us-israel-224-ai-defense-budget/)
Israel and the United States deployed AI targeting in their war on Iran as well. As Israeli academic and former soldier Avner Gvaryahu wrote in the The Guardian, we don’t know for sure that AI was directly involved in the U.S. strike that killed more than 150 civilians, most of them children, at an elementary school in Minab, Iran. But we do know that whether “or not an algorithm selected this school, it was selected by a system that algorithmic targeting built.”
The enormous scope of the U.S.–Israeli military goals required outsourcing the targeting task to machines. “To strike 1,000 targets in the first 24 hours of the campaign in Iran, the U.S. relied on AI systems to generate, prioritize, and rank the target list at a speed no human team could replicate,” wrote Gvaryahu. Reflecting common problem with computer programs in general, and with AI large language models in particular, feeding garbage in produces garbage out. In the case of the Minab school, the “garbage in” was the information that the target was an Islamic Revolutionary Guard Corps base. In fact, the school had been separated from the base by a fence for a decade.
AI is also now central to the long-stalemated Russia–Ukraine War. Ukraine has, during the years since Russia’s full-scale invasion in 2022, constructed an entire largely self-reliant infrastructure for drone warfare, from design to programming to manufacture. In an approach that foreshadows the future of human warfare, Ukraine has achieved a big reduction in the number of soldiers it must deploy on its battlefields, replacing them with drones. The Center for Strategic and International Studies quotes a captured Russian soldier:
“On the battlefield I did not see a single Ukrainian soldier. Only drones. I saw them [Ukrainian soldiers] only when I surrendered. Only drones, and there are lots and lots of them. Guys, don’t come. It’s a drone war.”
Artificial intelligence has played an important role in expanding the level of autonomy exercised by Ukrainian drones. As the BBC reports, the AI running Ukraine’s Hornet drones has “been trained on thousands of hours of videos of Russian military targets gathered over the last four years.” Training AIs on more limited data sets, relating to particular target areas, has allowed them to be programmed on modular chips which can then be installed in a variety of vehicles.
Early on, most drones were remotely operated by individual pilots. Today, Ukraine is developing “fully realized swarms—where drones communicate, make decisions, and adapt in concert,” although at present such efforts remain small and experimental. Success will undoubtedly continue to reduce Ukraine’s military casualties, but it presents other thorny issues.
True responsibility for the actions of an AI-guided drone swarm is properly located at a point much earlier in the kill chain.
One ethical and legal problem with the evolving Ukrainian approach is that, unlike human-piloted drones, where an individual pilot can be identified as responsible for errors, responsibility for the actions of a drone swarm diffuses across the entire system. Indeed, true responsibility for the actions of an AI-guided drone swarm is properly located at a point much earlier in the kill chain — namely, when such a system is first imagined and then designed. Existing laws of war still apply, even when machines are making battleground decisions, as Burak Oktenli, an independent researcher on AI systems and their governance writes at Articles of War. However, Oktenli says, such laws must “be applied earlier, at the point where the architecture of a swarm is chosen, rather than after a strike when the question of responsibility has already become difficult to answer.”
[
Related
U.S. Drone Strike in Kabul Killed a Family — and Began a New Chapter of the War](https://theintercept.com/2021/08/30/drone-kabul-afghanistan-civilian-casualties-children/)
In addition to the autonomous drone with the onboard NVIDIA chip, Russia has also deployed another system known by several names, including Cube, that is manufactured by a subsidiary of the Russian Kalashnikov company (most famous for their AK-47 semi-automatic rifles which have been in production for more than three-quarters of a century.). The Cube has a wingspan of just over a meter, can travel up to 40 kilometers, and reportedly carries an onboard AI targeting system that can operate without human intervention.
Russia has also reportedly used the Kalashnikov-manufactured Lancet drone in Ukraine, according to Automated Decision Research, a project of Stop Killer Robots, itself a coalition of over 300 civil society groups working against autonomous weapons systems. Kalashnikov describes the Lancet as “a smart multipurpose weapon, capable of autonomously finding and hitting a target.” Russia claims it has deployed the Lancet, but to date those claims remain unverified.
Household Names Go to War
In May, the Pentagon announced that it has contracted with eight corporations to assist in development of ever more autonomous weapons: SpaceX, OpenAI, Google, Nvidia, Reflection, Microsoft, Oracle, and Amazon Web Services. The Defense Department sought these agreements to “accelerate the transformation towards establishing the United States military as an AI-first fighting force and will strengthen our warfighters’ ability to maintain decision superiority across all domains of warfare.” Apparently, maintaining “decision superiority” requires offloading lethal decisions — and the responsibility for making them — to nonhuman “agents.”
Microsoft and AWS provide cloud storage and AI support to the Pentagon. Google signed a $200 million deal in April 2026 to allow the company’s Gemini AI model to be used on a wide array of classified systems. As the New York Times reported, the Google agreement was signed amid a dispute between the Department of Defense and competitor Anthropic over that company’s refusal to allow its AI to be used in autonomous weapons or for domestic surveillance. While Anthropic and the DoD continue their spat, it appears that the firm is not above selling its advanced Mythos model to the Pentagon’s bespoke cryptology and intelligence arm, the National Security Agency.
SpaceX’s famously right-wing and racist AI, Grok, is also working for the DoD. This is the large language model that, you may remember, once renamed itself MechaHitler. Just the nonhuman arbiter the world needs to assist in its life-or-death decisions.
[
Related
AI’s Imperial Agenda](https://theintercept.com/2026/01/02/empire-ai-sam-altman-colonialism/)
Two other AI corporations specializing in surveillance technology — Palantir and Anduril — bear special mention. Palantir’s founder was the billionaire Peter Thiel, a longtime supporter of President Donald Trump, who is now focusing on establishing pseudo-autonomous statelets in places like Honduras and warning the world about the coming of the Antichrist, an apocalyptic biblical figure found in the book of Revelation.
Palantir’s flagship military project, the Maven Smart System, serves as the Pentagon’s signature AI-enabled software platform. It uses AI and machine learning to automatically integrate data from satellites, drones, and other intelligence to identify and rank targets. It was Maven that identified those 1,000 targets in the first phase of the U.S.–Israeli war on Iran, including, presumably, the Minab school. Anduril’s Lattice AI, Maven’s direct competitor, has a contract for similar work with the U.S. Army.
Laws About LAWS
Although the development of lethal autonomous weapons systems has accelerated over the last few years with the rise of ever more powerful AI models, these systems have not outgrown existing international humanitarian law. The question, as with international law in general, is whether the international community can enforce those laws. More specifically, whether autonomous weapons, along with other kinds of arms like chemical and biological weapons, fall under the so-called 1981 Convention on Certain Conventional Weapons. The United States ratified the CCW in 1995 and is therefore theoretically bound by it.
[
Related
Musk Warns of Killer AI — While He and the Rest of Silicon Valley Cash In on AI That Kills](https://theintercept.com/2026/05/01/elon-musk-openai-lawsuit-trial/)
Signatories to the CCW meet for periodic reviews, with the next one scheduled for November. Between reviews, a Group of Government Experts working specifically on LAWS develops its “rolling text” of agreed-upon language for a possible future treaty on autonomous weapons. Membership in the GGE includes the parties to the CCW, along with international organizations like the International Red Cross, observer nations, and civil society organizations, including Stop Killer Robots, whose constituent groups include Amnesty International and the Reaching Critical Will project of the Women’s International League for Peace and Freedom.
The GGE’s most recent rolling text came out in June and plainly states that nations are not free to just use any weapon they like; international humanitarian law applies to all weapons, including those not yet invented; human beings remain responsible for the actions of machines they set in motion; and international humanitarian law specifically covers the development and use of LAWS. Given how AI is accelerating the development and actual deployment of LAWS, the November CCW review will be crucial.
[
Read Our Complete Coverage
TomDispatch -----------](/tomdispatch)
Keep Your LAWS Off Our Planet
Advocates of machine-targeting and autonomous weapons argue that these systems make better decisions than their fallible human counterparts. But you might be a bit skeptical about this, if you’ve ever seen autonomous taxis malfunction, like they did this Fourth of July in San Francisco.
We’ve seen how AIs can go rogue in a non-lethal setting. They secretly communicate with each other, deceive their human inventors, and will do anything necessary to achieve their goals — whatever the collateral damage. It’s bad when their target is a company like Hugging Face in the context of a low-stakes training scenario. It is immeasurably worse when the collateral damage is human lives in the context of war.
Lethal autonomous weapons systems are dangerous enough when they work the way their creators intend. What will happen when, like Anthropic’s and OpenAI’s models, they crawl out of the sandbox and go rogue?
The post It’s Time to Rein in Lethal AI Drones appeared first on The Intercept.
From The Intercept via This RSS Feed.



this cat is out of the bag
I’m still amazed how many people are happy about it