AI and Autonomy in Kill Webs
Executive summary
A kill web is best understood as a reconfigurable network of sensors, command-and-control nodes, decision aids, platforms, and effectors rather than a single linear “sensor-to-shooter” chain. U.S. joint concepts describe the desired cycle as sense, make sense, and act, supported by machine-to-machine data exchange, resilient data fabrics, artificial intelligence, and operations under degraded or contested communications. Navy usage similarly treats a kill web as multiple interconnected kill chains involving numerous sensors, targets, weapons, and delegated authorities. citeturn9view2turn9view3turn0search4turn0search7
AI’s most credible near-term role is not an unconstrained machine deciding whom to attack. It is a layered decision-support system that converts heterogeneous observations into detections, tracks, confidence estimates, predicted behaviors, and ranked courses of action. Convolutional neural networks and vision transformers perform sensor-specific perception; Kalman, extended Kalman, unscented Kalman, particle, and multi-hypothesis filters maintain tracks; cross-attention transformers combine features from multiple sensors or platforms; probabilistic and conformal methods quantify uncertainty; and optimization, auction, or reinforcement-learning algorithms rank possible resource assignments. The technically sound architecture preserves uncertainty and provenance throughout the pipeline rather than collapsing every stage into a single “target confidence” number. Recent cooperative-perception research illustrates both the promise of transformer-based fusion and the difficulty created by heterogeneous sensors, asynchronous updates, bandwidth limits, and domain shift. citeturn10search0turn10search1turn10search2turn10search3
“Best weapon for best target” should therefore be treated as a constrained recommendation problem, not an autonomous permission to use force. A defensible system first excludes options that violate positive-identification requirements, rules of engagement, geographic or temporal restrictions, command authorities, civilian-protection constraints, system-health limits, or minimum data-quality thresholds. Only the surviving options should be ranked by mission utility, timeliness, availability, confidence, reversibility, and estimated consequences. Public weapon-target-assignment research explores mixed-integer optimization, heuristics, actor–critic reinforcement learning, and dynamic allocation, but operational use would require hard legal and policy gates outside the learned objective function. citeturn2search2turn2search6turn2search10turn2search18
The principal technical danger is uncertainty multiplication. A moderately uncertain detector feeds an uncertain tracker; the tracker feeds a behavior predictor; the predictor informs a resource-allocation model; and the final interface may present a deceptively precise recommendation. Correlated sensor errors, stale tracks, adversarial deception, calibration drift, and automation bias can make the final recommendation much less reliable than its displayed score suggests. Safeguards must therefore include calibrated confidence, alternative hypotheses, out-of-distribution detection, source and time provenance, explicit evidence age, red-team testing, conservative abstention, and human interfaces designed to support rejection or delay rather than merely confirmation. DoD policy already requires realistic verification, validation, and testing against adaptive adversaries; understandable human-machine interfaces; clear activation and deactivation procedures; cybersecurity and anti-tamper measures; and “appropriate levels of human judgment” over force. citeturn9view0turn9view1turn14search0turn14search4
Legally, AI does not replace the people and institutions responsible for distinction, proportionality, precautions in attack, weapons review, and command accountability. The Convention on Certain Conventional Weapons’ affirmed guiding principles state that international humanitarian law applies fully, accountability cannot be transferred to machines, human judgment is essential, and systems incapable of lawful use must not be used. The ICRC’s 2025 position paper further argues that expanding AI-enabled targeting and swarming can erode human control, especially when systems operate against context-dependent targets or in environments containing civilians. citeturn16view2turn16view3turn16view0turn16view1
Human-in-the-loop and human-on-the-loop configurations are not categorical guarantees of meaningful control. A nominal approval button is ineffective when an operator has seconds to respond, supervises too many vehicles, cannot inspect the evidence, or cannot reliably interrupt communications-denied systems. Conversely, requiring manual approval for every navigational, defensive, or deconfliction action can overload operators and make a swarm unusable. The appropriate allocation of authority should depend on the consequence of error, target and environment complexity, predictability, reversibility, communications reliability, and the operator’s realistic opportunity to understand and intervene. citeturn15view1turn14search12turn5search2
Autonomous drone swarms function as kill-web edge nodes by performing local sensing, inference, networking, navigation, task allocation, and health management without continuously streaming raw data to a central headquarters. Their operational value comes from distributed coverage, reduced communications demand, graceful degradation, and the ability to relay tracks or compact features through a mobile mesh. Their greatest risks are emergent behavior, compromised nodes, inconsistent world models, network partitions, accidental task duplication, and loss of effective supervisory control. Public programs such as DARPA OFFSET, AMASS, and AFRL Golden Horde demonstrate pieces of this architecture—human-swarm interfaces, heterogeneous swarm coordination, inter-node communications, dynamic tasking, and adaptation to attrition—but do not establish that unrestricted autonomous target engagement is technically mature or legally acceptable. citeturn17view5turn17view7turn17view6
The central recommendation is to build AI-enabled kill webs as bounded, auditable decision systems: use autonomy extensively for navigation, sensing, communications management, track maintenance, logistics, and defensive maneuver; use AI to recommend rather than silently authorize high-consequence actions; encode legal and policy constraints as independently enforced gates; require uncertainty-aware displays and fail-safe abstention; and certify the combined human-machine system under realistic contested conditions, not merely the model in a laboratory.
Scope, assumptions, and analytical frame
This report relies on unclassified English-language sources, emphasizing official doctrine, policy documents, public program descriptions, and peer-reviewed or primary technical literature published mainly since 2021. Public sources reveal architectural goals and research directions but not classified model performance, sensor characteristics, electronic-warfare assumptions, target libraries, engagement thresholds, rules-of-engagement logic, or operational latency requirements. Consequently, the latency ranges below are indicative engineering bands, not descriptions of a particular fielded system.
Three unspecified variables materially affect every conclusion:
| Unspecified constraint | Why it changes the analysis |
|---|---|
| Operational environment | Open ocean, desert, dense urban terrain, air defense, maritime littorals, and underground or indoor environments have radically different clutter, civilian density, sensor visibility, communications, navigation, and collateral-risk conditions. |
| Rules of engagement and command authorities | The permissible degree of machine recommendation, human approval, defensive automation, target type, time window, and geographic scope depends on mission-specific authorities that cannot safely be inferred from system capability. |
| Classification and releasability | Open literature is biased toward experimental prototypes, civilian cooperative-perception datasets, policy-level descriptions, and sanitized demonstrations. Actual vulnerabilities, performance envelopes, failure thresholds, and tactics are generally unavailable. |
The term autonomy also spans different functions. A drone may navigate, maintain formation, route messages, or return to base autonomously while a person still approves any use of force. Conversely, a stationary defensive system may have limited mobility but autonomously select and engage objects after activation. The ICRC distinguishes autonomy in navigation or “locking on” from autonomy in the critical functions of selecting and applying force; the 2025 CCW chair’s text similarly centers the characterization of lethal autonomous weapon systems on selection and engagement without human intervention in those tasks. citeturn16view1turn16view4
A useful analytical decomposition is therefore:
| Layer | Core question |
|---|---|
| Perception autonomy | What objects, signals, events, or anomalies are present? |
| State-estimation autonomy | Where are they, how are they moving, and how reliable is that estimate? |
| Interpretive autonomy | What activity or intent is most consistent with the evidence? |
| Decision-support autonomy | Which lawful and authorized courses of action appear feasible? |
| Execution autonomy | Which platform performs an approved task, and how does it navigate and coordinate? |
| Force-application autonomy | Who or what selects the specific target and initiates force? |
| Governance autonomy | Who can change models, thresholds, permissions, mission bounds, or software during deployment? |
This decomposition matters because technical and legal risk rises sharply when errors propagate from perception into irreversible force. It also prevents a misleading binary distinction between “autonomous” and “non-autonomous” systems: the decisive issue is which functions are delegated, under what constraints, with what evidence, and with what opportunity for accountable human judgment. NATO’s autonomy framework likewise treats autonomy as a system-of-systems and lifecycle problem governed by lawfulness, accountability, explainability, reliability, governability, and bias mitigation. citeturn5search2turn5search5
Decision automation inside a kill web
A kill web’s technical objective is to transform observations from geographically dispersed and heterogeneous sensors into a shared, sufficiently current representation of the environment, then support action through whichever authorized node remains available. JADC2 documents emphasize machine-to-machine processing, data fabrics, resilient infrastructure, interoperability, and the ability to continue operating with degraded communications. Project Overmatch similarly describes a resilient network combining communications, analytical tools, and data infrastructure. citeturn9view2turn9view3turn0search11turn6search16
flowchart LR
subgraph Sensors["Distributed sensing"]
EO["EO/IR video"]
SAR["SAR / radar"]
RF["RF / electronic support"]
SONAR["Acoustic / sonar"]
HUM["Human and intelligence reports"]
EDGE["Drone and platform edge sensors"]
end
subgraph Edge["Edge processing"]
PRE["Calibration, synchronization, georegistration"]
DET["Sensor-specific detection and classification"]
TRACK["Local tracking and state estimation"]
UQ1["Confidence, covariance, OOD and health checks"]
end
subgraph Web["Kill-web data and decision services"]
FUSE["Cross-sensor and cross-platform fusion"]
ID["Identity and affiliation hypotheses"]
INTENT["Activity and intent prediction"]
POLICY["ROE, authority, legal and safety gates"]
MATCH["Constrained resource / weapon-target recommendations"]
HMI["Human decision interface"]
end
subgraph Action["Authorized action and feedback"]
C2["Command authorization"]
EXEC["Task execution or continued surveillance"]
BDA["Outcome assessment and model feedback"]
end
Sensors --> PRE --> DET --> TRACK --> UQ1
UQ1 --> FUSE --> ID --> INTENT --> POLICY --> MATCH --> HMI
HMI --> C2 --> EXEC --> BDA
BDA --> FUSE
POLICY -. "hold / abstain / request more evidence" .-> FUSE
Sensor-specific perception. EO and infrared imagery are commonly handled by convolutional detectors, vision transformers, or hybrid backbones. Radar and synthetic-aperture radar need models adapted to speckle, aspect dependence, scattering physics, resolution, polarization, and frequency band. Acoustic, sonar, RF, and electronic-support data require different front ends—spectrogram CNNs, temporal convolution, recurrent networks, transformers, matched filters, or model-based signal processing. A sound system should not assume that a generic visual foundation model transfers unchanged to every modality. SARatrX, for example, uses self-supervised pretraining on 186,600 samples assembled from 14 public SAR datasets, considers hierarchical vision-transformer and ConvNeXt-style backbones, and incorporates multiscale gradient features to suppress speckle and preserve target edges. citeturn18view0turn18view1
Detection and target recognition. CNN families remain attractive where compute, power, and latency are constrained because they provide strong local feature extraction and can be quantized or pruned. Vision transformers and hierarchical transformers better model long-range spatial context and can serve as scalable pretraining backbones, but their memory and inference cost may exceed that of compact CNNs. Detector architectures include one-stage models for speed, two-stage models for more elaborate proposals, and transformer detectors that replace portions of hand-engineered post-processing. The correct performance measures are not only aggregate accuracy or mean average precision, but also class-specific recall, false-alarm rate, calibration, performance under obscuration and unusual aspect angles, and failure on previously unseen objects. SARatrX’s published evaluation uses mAP, mAP50, mAP75, few-shot accuracy, and extended-operating-condition tests, illustrating why a single headline accuracy is insufficient. citeturn18view2
Tracking and state estimation. A detector produces intermittent observations; the tracker estimates continuous state. A linear Kalman filter is efficient when dynamics and measurement models are approximately linear and Gaussian. Extended and unscented Kalman filters address moderate nonlinearities. Particle filters represent multimodal or strongly nonlinear beliefs but cost substantially more computation. Joint probabilistic data association and multiple-hypothesis tracking maintain alternatives when observations may correspond to several objects. Probability-hypothesis-density variants can scale to uncertain target counts, although they may lose identity information without additional mechanisms. These filters should expose covariance, track-existence probability, association ambiguity, sensor-health state, and time since last confirmed observation.
Multisensor fusion. Fusion can occur at raw-data, feature, object, track, or decision level. Raw or early fusion retains information but demands high bandwidth, tight synchronization, and compatible sensor geometry. Feature fusion shares compact neural representations and often uses cross-attention or transformers, but learned features can be difficult to interpret or validate across model versions. Track-level fusion is bandwidth-efficient and modular, but information discarded by local processing cannot be recovered. Decision-level fusion is easiest to integrate across security domains but is especially vulnerable to correlated errors and poorly calibrated confidences. Contemporary cooperative-perception research uses heterogeneous graph transformers, instance-level transformer fusion, bird’s-eye-view representations, and explicit latency compensation to address differing cameras, lidar systems, clocks, and communication delays. citeturn10search0turn10search1turn10search2turn10search3
| Function and representative methods | Primary outputs and metrics | Indicative inference or update band | Accuracy and robustness characteristics | Ethical or operational risk |
|---|---|---|---|---|
| CNN detector, including compact one-stage models | Boxes, masks, class probabilities; mAP, recall, false alarms | Roughly 5–80 ms on an appropriate edge accelerator | Efficient and mature; may be brittle to novel backgrounds, scale, weather, camouflage, or sensor changes | False positives can be mistaken for positive identification if confidence is poorly calibrated |
| Vision or hierarchical transformer | Detections or embeddings; mAP, calibration, OOD performance | Roughly 20–200+ ms depending on image size and hardware | Strong contextual modeling and transfer learning; greater compute and data requirements | Complex failure modes and limited explanation can encourage unwarranted trust |
| Kalman, EKF, or UKF | State vector and covariance; RMSE, track continuity, innovation statistics | Sub-millisecond to tens of milliseconds | Interpretable and efficient when model assumptions hold | Covariance can be misleading if dynamics, sensor biases, or correlations are misspecified |
| Particle filter or multi-hypothesis tracker | Multimodal state distribution and competing tracks | Tens of milliseconds to seconds as hypotheses grow | Better for nonlinear or ambiguous situations; computationally intensive | Pruning may discard the correct hypothesis, while interfaces may hide remaining ambiguity |
| Cross-attention or graph-transformer fusion | Joint feature map, detections, fused tracks | Tens to hundreds of milliseconds plus network delay | Can exploit complementary sensors and agent viewpoints | Sensitive to synchronization, domain shift, compromised nodes, and opaque feature interactions |
| Bayesian network, HMM, or POMDP intent model | Probability over activities, intent, or future state | Milliseconds to hundreds of milliseconds; evidence accumulates over seconds or longer | Explicit uncertainty and causal structure are possible; depends heavily on model assumptions | Behavioral inference can encode cultural, contextual, or confirmation biases |
| Temporal transformer, GRU/LSTM, or trajectory model | Multimodal future trajectories; ADE/FDE, likelihood, calibration | Tens to hundreds of milliseconds | Captures complex interactions; requires representative sequence data | A high-likelihood trajectory is not proof of hostile intent |
| Conformal prediction or calibrated ensemble | Prediction sets or intervals with empirical coverage | Usually modest post-processing overhead | Helps expose uncertainty and abstention; guarantees depend on exchangeability or calibration conditions | Coverage can fail after severe distribution shift, and wide sets may be operationally inconvenient |
The latency bands are analytical orders of magnitude for architecture comparison, not public requirements for a particular military system. Communications, sensor integration, encryption, processing load, and model size can dominate end-to-end delay.
Confidence scoring and uncertainty. A well-designed kill web should distinguish at least five quantities: detector confidence, track-existence probability, state-estimation covariance, identity or affiliation probability, and confidence that a proposed action is lawful and operationally supported. These quantities are not interchangeable. Softmax scores are frequently overconfident; a track with low positional covariance may still have uncertain identity; and several sensors may repeat the same underlying error. Useful methods include temperature scaling, isotonic calibration, deep ensembles, Bayesian approximations, evidential models, prediction intervals, and conformal prediction. Conformal object-detection methods provide model-agnostic post-processing intervals with empirical coverage guarantees under stated statistical assumptions, while self-aware detection research explicitly evaluates calibration and domain-shift awareness. citeturn12search1turn12search12turn12search13
The user interface should therefore present evidence quality, not merely a green or red classification. At minimum, it should show contributing sensors, observation times, track age, conflicting reports, spatial uncertainty, model version, data-quality warnings, alternative classifications, and whether the observation lies outside validated conditions. An AI recommendation should automatically expire when its evidence becomes stale or its supporting sensor is later found compromised.
Intent prediction. Intent cannot be directly sensed. It is inferred from movement, communications, configuration, proximity, historical patterns, environmental context, and known plans. Representative approaches include hidden Markov and dynamic Bayesian models, inverse planning, POMDPs, recurrent networks, temporal transformers, graph neural networks, and multimodal trajectory generators. Transformer trajectory models can represent several plausible futures rather than one deterministic path, while POMDP approaches preserve uncertainty about both the environment and another actor’s objective. However, predicting motion is not equivalent to establishing hostile intent; the evidentiary and legal leap from “approaching” or “maneuvering” to “may be attacked” must remain explicit. citeturn13search27turn13search32turn13search18turn13search9
Algorithmic weapon-target or resource matching. At an abstract level, the system chooses assignment variables \(x_{ij}\), linking candidate resource \(i\) to task or target hypothesis \(j\), and maximizes a utility score:
\[ \max \sum_{i,j} x_{ij} U_{ij} \]
subject to inventory, timing, platform capability, deconfliction, command authority, safety, positive identification, geographic bounds, and legal or ROE constraints. The crucial governance point is that legal and authorization constraints should be implemented as hard exclusions enforced by an independent policy layer. They should not be soft penalties that a learned optimizer may trade away for greater predicted mission value.
| Assignment approach | Strengths | Latency and scaling | Principal weakness | Appropriate role |
|---|---|---|---|---|
| Hungarian or bipartite matching | Deterministic, fast, interpretable for one-to-one assignments | Often milliseconds to low hundreds of milliseconds | Simplifies multi-resource, temporal, and nonlinear effects | Rapid allocation of clearly defined, low-complexity tasks |
| Mixed-integer linear or nonlinear programming | Explicit constraints and inspectable objective | Can range from milliseconds to minutes or longer; worst-case complexity grows rapidly | May miss deadlines or rely on simplifying assumptions | Deliberate planning, small problem instances, or generation of benchmark solutions |
| Greedy or rule-based assignment | Predictable, easy to certify and explain | Very low latency | Can be globally suboptimal and brittle under changing conditions | Safety fallback and tightly bounded defensive or logistical functions |
| Auction or CBBA-style distributed allocation | Scalable, decentralized, tolerant of partial communications | Iterative; depends on network convergence | Conflicting or stale bids during partitions; utility design matters | Distributed sensing, relay placement, search, and nonlethal tasking |
| Genetic algorithm, particle-swarm, or other metaheuristic | Handles nonlinear objectives and mixed constraints | Variable and nondeterministic; can be bounded by a deadline | No guarantee of optimality; difficult reproducibility and assurance | Planning support where exact optimization is infeasible |
| Reinforcement learning or actor–critic | Fast inference after training and adaptable to dynamic state | Training is expensive; inference often low latency | Distribution shift, reward misspecification, opaque behavior | Advisory ranking under strict constraint shielding, not sole authorization |
| Hybrid “optimization plus learned estimates” | Combines auditable constraints with learned predictions | Moderate | Learned probability or consequence estimates can dominate output despite formal constraints | Most defensible architecture when model outputs remain uncertainty-bounded |
Recent publications apply deep reinforcement learning and actor–critic methods to dynamic weapon-target assignment, while other work combines genetic and particle-swarm optimization. These results demonstrate computational possibilities, not legal sufficiency or operational readiness. citeturn2search2turn2search6turn2search10turn2search18
Data requirements and adaptation. Training data must span sensors, platforms, altitudes, aspects, weather, illumination, terrain, clutter, civilian and neutral objects, decoys, damage states, countermeasures, and communications conditions. Track and intent models additionally need synchronized sequences, trustworthy timestamps, track identities, event labels, and examples of ambiguous or nonhostile behavior. Rare but consequential events create severe class imbalance, so aggregate accuracy can conceal unacceptable miss or false-alarm rates.
Self-supervised and foundation-model pretraining can reduce dependence on expensive labels. Transfer learning may begin with large natural-image models and continue with sensor-specific masked modeling, as SARatrX does with a two-stage pretraining process. Domain adaptation can align simulated and real data, different sensor generations, or different geographic environments through adversarial alignment, feature normalization, pseudo-labeling, test-time adaptation, or small validated calibration sets. Yet adaptation itself changes system behavior and should trigger configuration control, regression testing, and potentially a renewed legal or safety review. citeturn18view0turn18view1turn18view2
Synthetic data is valuable for rare conditions and adversarial scenarios but cannot substitute for representative field data. A simulator may reproduce geometry while missing sensor artifacts, maintenance degradation, atmospheric effects, human behavior, or an opponent’s adaptations. The most reliable process uses simulation to broaden coverage, field data to anchor realism, and independent challenge sets to detect overfitting.
Adversarial robustness. Threats include sensor spoofing, electronic deception, manipulated or poisoned training data, compromised software updates, adversarial visual or RF signatures, track injection, time-synchronization attacks, and malicious nodes feeding plausible but false observations. Robustness must therefore be system-level: cryptographic provenance, secure boot, signed models, protected time sources, cross-modal consistency checks, sensor-health monitoring, OOD rejection, redundant localization, adversarial testing, and separation between perception and authorization. The CCW’s affirmed principles expressly identify cybersecurity against hacking or data spoofing as a lifecycle consideration, while DoD policy requires cybersecurity, anti-tamper, system safety, and testing against adaptive adversaries. citeturn16view2turn9view0turn9view1
Real-time data flow and latency. “Real time” is not one deadline. Flight stabilization may require sub-10-millisecond control updates; local collision avoidance may operate at tens of milliseconds; object recognition and local track updates may tolerate tens to hundreds of milliseconds; cross-platform fusion may take hundreds of milliseconds or longer; and intent assessment may require seconds or minutes of evidence. The architecture should use deadline-aware computation, stale-data rejection, asynchronous fusion, local fallback behaviors, and anytime optimization that returns a safe partial answer when interrupted.
sequenceDiagram
participant S as Sensors
participant E as Edge node
participant F as Fusion and decision service
participant H as Human authority
participant X as Authorized platform
S->>E: Time-stamped observations
Note over E: Preprocess, detect, classify, track
E->>F: Track + covariance + provenance + health
Note over F: Cross-node fusion and competing hypotheses
F->>F: Predict possible trajectories and activities
F->>F: Apply legal, ROE, authority and safety gates
F->>H: Ranked options, evidence, uncertainty and deadline
alt Human has sufficient time and understanding
H->>F: Approve, modify, request more evidence, or reject
F->>X: Authorized bounded task
else Evidence or control is inadequate
H->>F: Hold, continue surveillance, disengage, or abort
F->>E: Maintain track and seek corroboration
end
X-->>F: Execution status and outcome data
F-->>H: Audit record and post-action assessment
Human override and supervisory interfaces. Override must be technically reachable, cognitively usable, and timely. The interface should identify which action is pending, the remaining decision time, why it was recommended, which constraints were applied, which constraints could not be evaluated, the consequence of no action, and the precise effect of an abort command. DoD Directive 3000.09 requires understandable interfaces, transparent system-status feedback, and clear activation and deactivation procedures. OFFSET’s public concept similarly emphasizes an interface through which a user can monitor and direct hundreds of systems, demonstrating the scale challenge but not proving that one operator can meaningfully supervise hundreds of independent force decisions. citeturn9view0turn14search0turn17view5
A safer design separates authorities: operators may direct sensing and maneuver at swarm scale, while higher-consequence actions require narrower, target-specific authorization with a smaller supervisory span. Where communications are lost, the default should depend on the mission and legal context, but generally progress toward irreversible force should stop unless a previously reviewed, tightly bounded defensive mode is valid.
Ethical and legal implications
The governing legal question is not whether an algorithm is “accurate enough” in isolation. It is whether the weapon, decision process, and circumstances of use permit responsible humans to comply with applicable international law. The CCW’s affirmed principles state that IHL applies fully to all weapon systems; responsibility cannot be transferred to machines; humans planning and conducting attacks must comply with distinction, proportionality, and precautions; and weapons incapable of lawful use must not be used. They also call for limits on target types, duration, geographic scope, and operational scale where necessary. citeturn15view1turn16view2turn16view3
Distinction. AI may help classify objects and maintain tracks, but legal distinction is not reducible to image classification. Status can depend on conduct, location, surrender, hors de combat conditions, civilian use, changing function, and information unavailable to a sensor. A model trained to recognize equipment may perform strongly while remaining unable to resolve whether an object is currently a military objective or whether a person is directly participating in hostilities. The ICRC notes that targets that become military objectives by purpose or use require nuanced, context-dependent assessments that are especially difficult for autonomous systems. citeturn15view0turn4search8
Proportionality and precautions. Proportionality requires a prospective human judgment concerning expected incidental civilian harm relative to the concrete and direct military advantage anticipated. Algorithms may estimate population density, blast or debris effects, traffic, structural damage, or alternative timing, but the final assessment contains normative and contextual judgments. AI should therefore support scenario comparison and uncertainty exposure, not present proportionality as an automatically computed pass/fail score. Precautions also require feasible verification, choice of means and methods, cancellation or suspension when circumstances change, and warning where appropriate. citeturn16view3turn15view1
Weapons review. Article 36 reviews and analogous national processes should evaluate not only hardware but intended functions, training data, model updates, operating bounds, human-machine interaction, communications dependencies, cyber vulnerabilities, and foreseeable failure under adversarial conditions. A model materially changed by retraining, adaptation, a new sensor, or a new operating environment may no longer be the system that was originally reviewed. The CCW principles explicitly place risk assessment, mitigation, security, and legal review across the development and deployment lifecycle. citeturn15view1turn4search4
Human-in-the-loop versus human-on-the-loop. “In the loop” ordinarily means a human must affirmatively authorize a critical action. “On the loop” means the system acts unless a supervisor intervenes. Neither arrangement guarantees responsible judgment by itself.
| Control arrangement | Advantages | Failure modes | Ethical and legal risk |
|---|---|---|---|
| Human-in-the-loop for each use of force | Clear decision point; easier attribution; opportunity to consider context unavailable to the model | Approval may become a rapid rubber stamp; communications loss can prevent action; too many recommendations cause overload | Lower only when the human has sufficient evidence, competence, time, and genuine ability to reject |
| Human-on-the-loop with abort authority | Faster response; suitable for bounded, time-critical defensive functions | Intervention window may be shorter than human reaction time; link loss or interface confusion makes override fictional | High where targets or environments are complex, effects irreversible, or civilians may be present |
| Human-out-of-the-loop after activation | Operates despite disconnection and can respond at machine speed | User cannot determine precise target, timing, or location; emergent interactions and deception may be undetectable | Highest for open-ended target selection, especially involving people or civilian environments |
| Supervised autonomy with mission bounds | Delegates navigation, search, relay, formation, and track maintenance while preserving human force decisions | Boundaries may be too broad or silently altered; authority can migrate through software updates | Moderate if bounds are independently enforced, visible, tested, and fail closed |
| Mixed-initiative decision support | AI generates options and requests information; human can redirect reasoning | Explanations may rationalize rather than reveal true model behavior; automation bias remains | Usually preferable for complex targeting if interfaces expose uncertainty and dissenting evidence |
Human control is meaningful only when the operator understands the system’s capabilities and limits, has sufficient situational awareness, can anticipate the range of effects, and has a technically effective opportunity to intervene. The ICRC’s current position emphasizes constraints on target types, operational duration, geographic area, scale, and situations of use, while DoD uses the formulation “appropriate levels of human judgment.” The difference in terminology reflects an unresolved policy debate, but both frameworks reject transferring responsibility to the machine. citeturn16view0turn16view1turn14search4turn14search15
Automation bias and moral crumple zones. Operators may defer to a recommendation because the system appears more informed, because the display suppresses uncertainty, or because rejecting it requires extra steps. After an error, organizations may then assign blame to the last human who touched the interface even though data, model, acquisition, staffing, and command decisions shaped the outcome. Avoiding this “moral crumple zone” requires recording responsibility throughout the lifecycle: who selected the data, approved the model, defined its operating bounds, set thresholds, accepted residual risk, authorized the mission, and acted on the output.
Accountability and attribution. AI systems have no legal personality or moral agency. Responsibility may attach differently to states, commanders, operators, developers, acquisition officials, or others depending on the applicable legal regime and facts, but a machine cannot absorb accountability. Operational attribution additionally requires a trustworthy forensic record: authenticated sensor inputs, model and parameter versions, time sources, confidence outputs, policy-gate results, human actions, communications state, overrides, and software updates. The CCW principles expressly require responsible chains of human command and control and retention of accountability throughout the lifecycle. citeturn15view1turn16view2turn14search28
Escalation risk. AI-enabled kill webs can compress decision time, increase the number of simultaneous contacts, and create pressure to delegate authority because human review becomes the bottleneck. Escalation may result from false classification, spoofed tracks, interaction between opposing autonomous systems, defensive systems interpreting each other’s maneuvers as hostile, or automated resource allocation producing a larger response than commanders intended. Greater speed can improve defense against fast threats, but it also reduces time for deconfliction, political consultation, or correction of misperception. The ICRC identifies loss of human control and escalation among the principal concerns associated with AI-enabled targeting and swarms. citeturn16view0turn15view0
A particularly dangerous pattern is reciprocal automation: one side accelerates detection and engagement because it assumes the other is doing so, creating a perceived “use it or lose it” pressure. Mitigations include separating warning and engagement networks, requiring positive human authorization for escalatory actions, enforcing minimum corroboration, retaining communication channels, and designing systems to default to tracking or defensive maneuver rather than irreversible action when evidence is ambiguous.
Policy frameworks. DoD Directive 3000.09 requires appropriate human judgment, law-of-war and ROE compliance, realistic V&V and testing, understandable interfaces, and cybersecurity and system-safety measures. The U.S.-sponsored Political Declaration on Responsible Military Use of AI and Autonomy calls for legal compliance, responsible human chains of command, rigorous testing, mitigation of unintended behavior, and senior-level oversight. NATO’s AI and autonomy strategies add lawfulness, accountability, explainability, reliability, governability, bias mitigation, interoperability, and testing, evaluation, verification, and validation. NIST’s AI Risk Management Framework supplies a broader lifecycle structure for governing, mapping, measuring, and managing AI risk, though it is voluntary and not tailored to targeting law. citeturn14search0turn1search2turn5search1turn5search2turn12search3
The ICRC advocates a more restrictive international approach: prohibiting unpredictable autonomous weapons and systems designed or used to apply force against persons, while regulating other autonomous weapons through limits on target type, duration, geography, scale, and circumstances. This position is not identical to current U.S. policy, but it represents a central humanitarian perspective that any rigorous analysis must include. citeturn14search19turn14search22turn16view0
Risk-mitigation matrix.
| Risk | Technical mitigation | Human and procedural mitigation | Governance evidence |
|---|---|---|---|
| False target recognition | Multisensor corroboration, calibrated confidence, OOD rejection, conservative thresholds | Require independent verification for high-consequence actions | Class-specific test results, calibration curves, documented abstention rates |
| Stale or corrupted tracks | Secure timestamps, track-age limits, innovation checks, source authentication | Display freshness and conflicts; prohibit action on expired evidence | Tamper-evident logs and sensor-health records |
| Automation bias | Show competing hypotheses and missing evidence; require active rather than default approval | Train operators to challenge outputs; periodically insert known test cases | Human-factors testing and measured rejection behavior |
| Domain shift | Environment-specific validation, change detection, rollback capability | Restrict use outside certified operating envelope | Configuration-controlled deployment authorization |
| Model or data compromise | Signed models and updates, secure boot, least privilege, anomaly detection | Two-person control for mission-critical updates | Software bill of materials, provenance and attestation records |
| Loss of communications | Local safe state, bounded autonomy, independent abort channels where feasible | Predefine actions upon link loss and rehearse them | Mission-specific communications-loss rules |
| Emergent swarm behavior | Runtime monitors, collision and geographic constraints, role limits, simulation and formal checks | Limit swarm size and functions until validated | Incremental certification and test evidence by scale |
| Excessive target-selection authority | Independent policy engine, hard target-type and geographic exclusions | Target-specific or class-specific authorization | Recorded command authority and machine-enforced bounds |
| Unexplained recommendation | Interpretable constraint trace, evidence provenance, counterfactual options | Permit delay or request for additional sensing | Decision audit package suitable for review |
| Post-deployment learning drift | Disable unconstrained online learning in critical functions; staged updates | Senior approval and revalidation for material changes | Versioned model cards, test reports, renewed legal review |
A current U.S. Army publication on counter-UAS operations illustrates an important boundary: AI may combine flight behavior, proximity, profiles, friendly-aircraft databases, and ROE parameters to recommend courses of action, but the document explicitly frames the system as advising humans rather than deciding. It also stresses clear authorities and ROE before crisis conditions arise. citeturn15view3turn16view5
Autonomous drone swarms as edge nodes
A swarm edge node is simultaneously a vehicle, sensor, computer, network participant, and autonomous agent. Unlike a remotely piloted drone that continually sends video to a central operator, an edge-autonomous drone can detect objects locally, maintain tracks, compress or summarize observations, negotiate tasks, route data for peers, and continue limited functions when disconnected. The swarm becomes a distributed information-processing layer within the broader kill web.
flowchart TB
subgraph Node["Representative swarm edge node"]
SEN["Sensors: EO/IR, radar, RF, acoustic, navigation"]
CMP["Compute: CPU, GPU/NPU or FPGA"]
AP["Flight controller and real-time autopilot"]
PER["Perception, tracking and local fusion"]
PLAN["Local planner and safety constraints"]
TASK["Task-allocation and swarm agent"]
NET["Encrypted multi-radio mesh"]
HEALTH["Health, cyber and integrity monitor"]
end
subgraph Swarm["Distributed swarm services"]
CONS["Shared tracks and state agreement"]
ALLOC["Auction / consensus task allocation"]
RELAY["Adaptive routing and relay selection"]
MAP["Distributed mapping and sensing"]
BEH["Formation, coverage, search and reconfiguration"]
end
subgraph External["Kill-web connections"]
C2["Human command and mission bounds"]
OTHER["Other-domain sensors and platforms"]
AUDIT["Logging, model and authority services"]
end
SEN --> PER
CMP --> PER
AP <--> PLAN
PER --> TASK
TASK <--> NET
HEALTH --> PLAN
HEALTH --> NET
NET <--> CONS
NET <--> ALLOC
NET <--> RELAY
NET <--> MAP
NET <--> BEH
C2 <--> NET
OTHER <--> NET
NET --> AUDIT
Hardware stack. A typical small-UAS node combines a flight-control processor, inertial sensors, GNSS where available, barometric and magnetic sensors, cameras or other mission sensors, a higher-performance mission computer, one or more radios, power management, and secure storage. Edge accelerators may be GPUs, neural-processing units, FPGAs, or specialized embedded modules. The engineering trade is among compute, thermal load, endurance, payload, communications range, cost, and survivability. Attritable systems intentionally accept lower unit cost and shorter service life, but “attritable” should not imply weak cybersecurity or untraceable command authority.
Software stack. The lowest layer handles real-time stabilization and actuator control. Above it sit navigation, obstacle avoidance, mission planning, perception, tracking, local mapping, mesh networking, task allocation, swarm behavior, cyber monitoring, and human-interface services. Middleware provides message schemas, time synchronization, discovery, quality-of-service policies, and hardware abstraction. A high-assurance architecture isolates safety-critical flight and authorization functions from experimental perception or learning components so that a failed neural model cannot directly corrupt basic vehicle control or permissions.
Mesh communications. Flying ad hoc networks are unusually dynamic: nodes move quickly, line of sight changes, links are intermittent, and every transmitted bit consumes energy and reveals electromagnetic activity. A swarm may combine short-range peer links, longer-range relays, directional links, and gateway nodes to external networks. No single routing protocol is optimal.
| Networking approach | Advantages | Limitations in a contested swarm | Best-fit use |
|---|---|---|---|
| Proactive link-state routing | Routes are immediately available; predictable forwarding | Frequent topology updates consume bandwidth as the swarm moves | Smaller or moderately mobile formations with adequate links |
| Reactive routing | Reduces control traffic when routes are unused | Route discovery adds delay and may repeatedly fail under high mobility | Intermittent peer exchanges and lower-density networks |
| Geographic routing | Scales without full route tables; exploits position | Depends on trustworthy localization and can fail around voids or jamming | Mobile aerial meshes with reliable relative or absolute position |
| Delay-tolerant store-carry-forward | Survives partitions and intermittent contact | High and variable latency; duplicate or stale data must be controlled | Reconnaissance and non-time-critical reporting under severe disruption |
| Relay-aware task allocation | Treats network connectivity as a mission task | Uses vehicles for communications rather than sensing or other work | Swarms where continuous command or data return is essential |
| Learning-based routing | Can adapt to changing link quality and congestion | Harder to verify; may behave unpredictably outside training | Advisory route selection with deterministic fallback |
FANET research emphasizes that dynamic topology and mobility affect every protocol layer. MIT’s CBBA-with-relays work illustrates a cross-layer approach: agents use task-allocation consensus to predict future connectivity and assign relay tasks, with simulation and flight tests demonstrating real-time applicability. citeturn7search1turn7search5turn7search21turn18view3
Consensus. In this context, consensus normally means agreement on task ownership, track identity, map state, or formation intent—not a computationally heavy public blockchain. Average-consensus and distributed Kalman methods reconcile estimates; auctions reconcile task assignments; leader-election mechanisms replace failed coordinators; and quorum rules can protect a small set of safety-critical state changes. Full Byzantine-fault-tolerant consensus may be too communication-intensive for large mobile swarms, but limited Byzantine-resilient techniques may be warranted for high-consequence commands, provided identity, membership, and key management are trustworthy.
Distributed sensing and fusion. The swarm must decide what to share:
| Shared representation | Bandwidth | Information retained | Vulnerability |
|---|---|---|---|
| Raw imagery or waveform | Very high | Maximum; allows centralized reprocessing | Congestion, latency, interception, single-point processing burden |
| Cropped detections or selected snippets | Medium | Retains evidence around candidate objects | Selection bias; missed context |
| Neural feature tensors | Medium to high | Supports cooperative perception without full raw data | Model-version incompatibility and limited interpretability |
| Object lists and tracks | Low | Efficient for shared situational awareness | Local errors become embedded and raw evidence is unavailable |
| Decisions or alerts only | Very low | Minimal communications load | Highest risk of correlated overconfidence and lost provenance |
A robust design adapts the representation to link conditions: raw or rich evidence when capacity permits; features or tracks when constrained; and store-carry-forward when partitioned. Every shared object should carry time, position uncertainty, source identity, model version, and confidence. Distributed Kalman approaches can share measurements or estimates, but correlated process noise and repeated information create double-counting risks unless cross-covariance is managed. citeturn7search30turn7search18
Task allocation. Centralized assignment is globally informed but creates a bottleneck and single point of failure. Distributed auctions and CBBA allow nodes to build preferred task bundles and resolve conflicts through consensus. Coupled-constraint variants handle temporal or cooperative relationships; relay variants explicitly preserve network connectivity; information-rich planning combines task allocation with motion planning to reduce uncertainty. citeturn18view3turn18view4
Multi-agent reinforcement learning can discover coordination policies in simulation, but its assurances are weak when agent count, communications, environment, or adversary behavior differs from training. A prudent architecture confines learned policies inside deterministic safety, geography, authority, and collision-avoidance envelopes, with a simpler auction or rule-based fallback.
Swarm behaviors. Publicly studied behaviors include formation, flocking, area coverage, search, mapping, perimeter observation, rendezvous, relay placement, dynamic role assignment, and cooperative transport or sensing. These emerge from combinations of local separation, alignment, cohesion, goal attraction, obstacle avoidance, and task-level constraints. Mission planners should prefer composable, inspectable behaviors over a single end-to-end learned policy, because composition allows independent testing and clearer authority boundaries.
Attritable design and graceful degradation. An attritable swarm should assume node loss without assuming mission collapse. Desired properties include no indispensable leader, replicated but bounded mission state, reallocation after node failure, dynamic relay placement, local navigation during link loss, redundant sensing, and mechanisms to retire compromised nodes. DARPA AMASS publicly described heterogeneous air, ground, and surface systems collaborating and negotiating, providing distributed sensing and effects, and adapting to attrition, targeting errors, environmental change, and unexpected adversary action. citeturn17view7turn9view4
Attrition can also undermine accountability. If nodes are lost, destroyed, captured, or unable to return logs, the system may lack evidence needed for incident review. Logs should therefore be cryptographically chained and replicated across selected peers or gateways, balanced against bandwidth, compromise risk, and data classification.
Cyber resilience. Each node expands the attack surface. Minimum safeguards include hardware-rooted identity, secure boot, authenticated and encrypted communications, signed commands and models, key rotation and revocation, least-privilege services, network segmentation, anomaly detection, anti-rollback controls, protected audit logs, and mechanisms to quarantine suspicious peers. Zero-trust principles are especially relevant because physical possession or network membership should not confer implicit trust. citeturn6search20turn1search27turn16view2
A compromised node may behave subtly rather than simply disconnecting: it can bias shared tracks, submit dishonest bids, exaggerate link quality, suppress warnings, or induce formation changes. Defenses should compare claims against physical observability, limit any single node’s influence, use reputation cautiously, and require stronger authorization for commands that change mission bounds or force permissions. Swarm cyber testing must include compromised insiders, not only external jamming.
Human-swarm command. One operator cannot continuously inspect every perception and planning event in a large swarm. The interface therefore needs hierarchical control: humans specify mission goals, areas, prohibited zones, target or task classes, time limits, and escalation authorities; the swarm autonomously performs low-level navigation and coordination; and the system surfaces exceptions, conflicts, uncertainty spikes, and requests for authority. OFFSET’s envisioned human-swarm interface used immersive displays and a “swarm interaction grammar” to manage up to hundreds of vehicles, highlighting the shift from piloting individual aircraft to commanding collective behaviors. citeturn17view5
Supervisory span should nevertheless be constrained by decision consequence, not only vehicle count. One operator might reasonably supervise hundreds of vehicles conducting mapping or relay tasks, but not hundreds independently presenting near-simultaneous force decisions. High-consequence recommendations should be aggregated, prioritized, and routed to appropriately authorized personnel without concealing individual evidence.
Representative public programs and prototypes.
| Program or example | Publicly demonstrated or stated contribution | Analytical significance | Important limitation |
|---|---|---|---|
| DARPA OFFSET | Swarms of up to roughly 250 small air or ground systems; open architecture; frequent field experiments; human-swarm interfaces and tactic composition | Demonstrates scale, heterogeneous vehicles, and command abstraction | Primarily a research ecosystem; public material does not establish lawful or reliable autonomous lethal targeting |
| DARPA AMASS | Heterogeneous “swarms of swarms,” inter-swarm negotiation, distributed sensing and effects, adaptation to attrition and targeting errors | Shows system-of-systems coordination and graceful reconfiguration as a kill-web edge layer | Public budget descriptions provide objectives, not independent operational-performance evidence |
| AFRL Golden Horde | Six networked collaborative munitions communicated with one another and a ground station; accepted an in-flight target update; interfaced with JADC2 | Illustrates collaborative networking, dynamic retasking, and synchronized action | Small demonstration scale and controlled testing; not evidence of general autonomous judgment |
| DARPA connectivity-loss work | Research into autonomous completion of assigned tasks when operator links are lost | Relevant to degraded-communications operations | Link-loss autonomy creates serious authority, predictability, and abort questions |
| DARPA Triage Challenge swarm | Autonomous mapping and coordinated search in a disaster-response setting | Demonstrates nonlethal distributed sensing and mapping applicable to edge architectures | Civil-response conditions do not reproduce an adaptive military adversary or IHL targeting judgments |
DARPA OFFSET describes an open systems architecture and frequent live experiments for swarms exceeding 250 small systems. Golden Horde’s 2021 demonstration connected six collaborative weapons and a ground station, accepted an external in-flight update, and demonstrated linkage to JADC2. AMASS’s public documentation emphasizes heterogeneous systems negotiating and adapting to attrition and errors. These are meaningful technical milestones, but they test components of autonomy rather than proving the reliability, legality, or human controllability of a full AI-driven kill web. citeturn17view5turn17view6turn17view7
Integrated risk analysis and recommendations
The three questions are inseparable. A kill web’s decision algorithms depend on edge nodes for timely, diverse evidence; edge nodes depend on decentralized autonomy because communications are intermittent; and decentralization complicates legal judgment, accountability, override, and escalation control. The architecture must therefore be designed around assured boundaries, not maximum autonomy.
Technical safeguards.
| Priority safeguard | Actionable implementation | Verification criterion |
|---|---|---|
| Preserve uncertainty end to end | Carry detector calibration, track covariance, identity hypotheses, sensor health, evidence age, and correlation information through fusion and assignment | Operators can trace a recommendation to supporting evidence and see how uncertainty changed at every stage |
| Use independent policy and authority gates | Separate learned perception and ranking from a deterministic engine enforcing ROE, target-class limits, geography, time, command authority, and system health | No model output or optimization score can bypass a prohibited condition |
| Design for abstention | Establish reject options for OOD inputs, conflicting sensors, stale tracks, compromised nodes, and insufficient corroboration | Testing measures safe refusal, not only accuracy; uncertainty increases cause hold or surveillance behavior |
| Bound adaptive learning | Prohibit uncontrolled online learning in critical target-selection or force functions; stage updates through signed packages, regression tests, and rollback | Every deployed model and parameter set is identifiable, reproducible, and linked to approval evidence |
| Test the system, not only the model | Conduct hardware-in-the-loop, human-in-the-loop, red-team, cyber, EW, degraded-navigation, network-partition, and mass-contact testing | Performance evidence covers representative operators, interfaces, communications, and adversarial conditions |
| Adopt graceful degradation | Define safe modes for sensor loss, link loss, localization uncertainty, compute overload, and inconsistent swarm state | Failure drills show predictable transition to continued sensing, withdrawal, holding, or other preauthorized safe states |
| Limit correlated failure | Use diverse sensors and algorithms, independent checks, source-aware fusion, and separate authorization pathways | Common-mode failures are identified in hazard analysis and do not produce unanimous but false confidence |
| Engineer forensic accountability | Cryptographically bind inputs, outputs, model versions, authorities, human actions, and communications state | Investigators can reconstruct why an action was recommended, approved, altered, aborted, or executed |
DoD Directive 3000.09, NATO’s responsible-use principles, NIST’s AI risk framework, and CCW guidance all support lifecycle risk management, though they differ in legal status and specificity. The strongest implementation would combine them: DoD-style weapon-system V&V and human judgment, NATO-style governability and interoperability, NIST-style risk documentation, and CCW/IHL-specific limits and accountability. citeturn14search0turn5search2turn12search3turn16view2
Human-machine interface safeguards. Interfaces should be evaluated through measured operator performance, not subjective usability alone. Tests should quantify comprehension of uncertainty, time to notice contradictions, frequency of inappropriate approvals, response to false high-confidence recommendations, ability to identify stale data, and performance under workload. A deliberate “cognitive forcing” mechanism—requiring the operator to acknowledge key uncertainties or compare alternatives—may reduce rubber-stamping for the highest-consequence decisions, although it should not be imposed indiscriminately where delay itself is dangerous.
The system should display:
- the proposed action and exact authorization requested;
- target and track identity hypotheses rather than a single label;
- sensor sources, timestamps, location uncertainty, and communications condition;
- applicable ROE and policy gates, including which checks passed or remain unresolved;
- expected consequences as ranges, not false precision;
- alternatives such as continued surveillance, delay, redirection, nonkinetic action, or disengagement;
- remaining time for decision and whether override remains technically effective.
Policy recommendations. States and military organizations should establish a tiered autonomy policy linked to consequence and context. Broad autonomy is most defensible for navigation, collision avoidance, formation, relay, logistics, mapping, and sensor management. More restrictive authority should apply to identity, intent interpretation, weapon-target recommendations, and changes to mission bounds. Selection and engagement of persons, or operations in civilian-rich and highly ambiguous environments, warrant the strictest limits and human judgment.
For each mission, commanders should approve an autonomy authorization envelope specifying:
| Element | Required definition |
|---|---|
| Permitted functions | Which functions may execute autonomously and which are advisory only |
| Target or task classes | What may be detected, tracked, prioritized, or acted upon |
| Geographic and temporal bounds | Where and for how long autonomous modes may operate |
| Communications-loss behavior | Hold, continue sensing, withdraw, return, or execute a narrowly preauthorized function |
| Human control mode | Who is in or on the loop, supervisory ratio, and minimum intervention time |
| Evidence threshold | Required corroboration, confidence, freshness, and sensor health |
| Model configuration | Approved version, calibration, data provenance, and operating envelope |
| Escalation rules | Actions requiring higher authority, dual confirmation, or explicit human approval |
| Logging and review | Required records, post-mission review, and incident-reporting process |
Such envelopes operationalize the CCW principles’ call for limits on target types, duration, geography, scale, and operator training. citeturn16view3
Legal and oversight recommendations. Legal review should occur iteratively at concept, prototype, pre-fielding, software-update, and new-use-case stages. Review teams should include legal advisers, operators, human-factors specialists, test professionals, cybersecurity experts, data scientists, intelligence analysts, and independent red teams. A legal review based solely on a vendor’s stated intended use will be inadequate where learning systems can be repurposed through new data, sensors, prompts, mission files, or threshold changes.
Independent oversight should require:
- documented intended and prohibited uses;
- traceable training and evaluation data;
- subgroup, environment, and class-specific error analysis;
- uncertainty and calibration results;
- adversarial and cyber testing;
- human-factors evidence;
- identified accountable officials for model approval and mission use;
- incident reporting and protected channels for operator concerns;
- suspension criteria when performance or operating assumptions degrade;
- periodic reassessment of cumulative escalation and proliferation risk.
Swarm-specific safeguards. Swarms should use hierarchical permission tokens or cryptographically authenticated mission authorities so that a navigation or sensing task cannot silently become an engagement authority. Individual nodes should not be able to expand geographic, temporal, target-class, or force permissions. Mission-critical changes should require authenticated external authorization or a narrowly defined multi-party process. Network partitions should never cause inconsistent authority states in which one sub-swarm believes permission exists and another does not.
Swarm certification should be incremental. Passing tests with ten nodes does not establish performance with 100, because communications contention, human workload, emergent interactions, and correlated failures can scale nonlinearly. Programs should certify by swarm size, topology, mission class, communications condition, and operator ratio, with explicit limits beyond which the system reverts to simpler behaviors.
Escalation safeguards. Commanders should preserve minimum decision time for actions likely to broaden a conflict, strike sensitive target classes, cross geographic boundaries, or create large aggregate effects. Machine-speed defensive actions may be necessary against very fast incoming threats, but their scope should be tightly bounded to validated threat profiles, locations, durations, and consequences. Inter-system deconfliction, protected communication channels, and reversible responses should be preferred where possible.
Research priorities. The highest-value technical research is not simply higher detection accuracy. Priority areas are calibrated uncertainty under domain shift; causal and counterfactual intent models; robust fusion under compromised sensors; human comprehension of probabilistic evidence; formal verification of policy gates; scalable swarm assurance; secure distributed state agreement; and evaluation methods that combine mission performance, civilian-harm risk, operator workload, cyber resilience, and accountability.
The overarching design principle is:
Automate information processing aggressively, automate irreversible judgment cautiously, and never allow optimization speed to erase legal authority, uncertainty, or accountable human choice.
Prioritized annotated references
| Priority source | Annotation |
|---|---|
| DoD Directive 3000.09, Autonomy in Weapon Systems, 2023 citeturn14search0turn9view0turn9view1 | Principal U.S. defense policy source for appropriate human judgment, testing, understandable interfaces, system safety, cybersecurity, activation and deactivation, and senior review. |
| DoD JADC2 Strategy Summary citeturn9view2turn9view3 | Foundational official description of “sense, make sense, act,” resilient data fabrics, machine-to-machine processing, AI-enabled decision advantage, interoperability, and degraded-communications operation. |
| CCW GGE affirmed guiding principles and 2025 compilation citeturn15view1turn16view2turn16view3 | Authoritative multilateral reference stating that IHL applies fully, accountability cannot transfer to machines, human judgment is essential, and lifecycle limits and legal reviews are required. |
| ICRC, Autonomous Weapon Systems and International Humanitarian Law: Selected Issues, 2025/2026 publication citeturn15view0turn16view0turn16view1 | Current humanitarian-law analysis of AI-enabled targeting, swarms, loss of human control, context-dependent targets, escalation, and recommended prohibitions and restrictions. |
| NATO Autonomy Implementation Plan and revised AI strategy citeturn5search1turn5search2 | Useful allied framework for lawfulness, accountability, explainability, reliability, governability, bias mitigation, interoperability, and testing. |
| NIST AI Risk Management Framework citeturn12search3 | General lifecycle framework for governing, mapping, measuring, and managing AI risk; useful as a documentation backbone but not a substitute for IHL or weapons review. |
| SARatrX: Towards Building a Foundation Model for SAR Target Recognition citeturn18view0turn18view1turn18view2 | Primary technical case study covering self-supervised SAR pretraining, 186,600 samples from 14 datasets, sensor-specific architecture, few-shot adaptation, and robustness evaluation. |
| HM-ViT, TransIFF, and latency-aware cooperative-perception research citeturn10search0turn10search1turn10search2 | Representative recent literature on heterogeneous multimodal fusion, transformer-based feature exchange, bandwidth tradeoffs, and asynchronous latency compensation. |
| MIT Aerospace Controls Laboratory, Consensus-Based Bundle Algorithm citeturn17view4turn18view3turn18view4 | Primary laboratory source for decentralized auction-based task allocation, coupled constraints, asynchronous operation, relay assignment, and information-rich planning. |
| DARPA OFFSET citeturn17view5 | Official program description of large small-system swarms, open architecture, human-swarm interfaces, tactic composition, and repeated field experimentation. |
| DARPA AMASS public budget documentation citeturn17view7turn9view4 | Official source describing heterogeneous swarms of swarms, distributed sensing and effects, inter-swarm negotiation, and adaptation to attrition and errors. |
| AFRL Golden Horde flight demonstrations citeturn17view6 | Official case study of networked collaborative weapons, a six-node airborne network, external in-flight target updates, synchronized operation, and JADC2 linkage. |
| U.S. Army, Small Drones, Big Problems, 2026 citeturn15view3turn16view5 | Recent official discussion of AI-supported threat assessment, trajectory and collateral-risk estimation, clear ROE and authority, and the distinction between machine advice and human decision. |