AI and Autonomous Weapons: Who Pulls the Trigger When the Machine Decides?
A decade-old US directive still governs when a machine can help choose who dies. Reported deployments in Gaza and Ukraine suggest the human review built into that policy is shrinking fast.
Opening Brief
Machines are already selecting targets. The debate is over who signs off
AI and autonomous weapons is the file that follows AI power to its most direct form: lethal force. Governments have spent a decade writing policy about "appropriate levels of human judgment" over weapons that decide, at machine speed, who or what gets struck. In 2024, an Israeli military-intelligence investigation surfaced a system that reportedly compressed that judgment to about twenty seconds per name. In 2025, a UN resolution backed by 156 states said the world still has no shared rules for any of it.
This file does not settle whether any specific strike was lawful. It tracks what is actually written down and independently confirmed: the policy that is supposed to keep a human in the loop, the systems reported to have narrowed that loop to near-nothing, and the diplomatic record of the world's attempt to draw a line before it disappears entirely.
What This File Tracks
Where automation meets the decision to use lethal force
The US Policy Baseline
What DoD Directive 3000.09 actually requires, and what it leaves to commander discretion.
Documented Battlefield Use
What is independently confirmed about AI-assisted targeting in Gaza and AI-guided strike systems in Ukraine.
The Diplomatic Record
How the UN General Assembly voted on lethal autonomous weapons and what that vote does and does not do.
The Human-Control Question
Where meaningful human control is written into policy, and where it appears to erode in practice.
The Policy on Paper
The US directive that still governs the baseline
The core US policy is DoD Directive 3000.09, "Autonomy in Weapon Systems," first issued in November 2012 and updated in January 2023. Its central line: "Autonomous and semi-autonomous weapon systems will be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force." It does not ban autonomous target selection outright, and it does not define "appropriate" with a fixed rule that applies the same way in every scenario.
The Congressional Research Service's public defense primer on the policy notes that human-supervised autonomous weapon systems may be permitted to select and engage targets in specific contexts — such as intercepting inbound attacks — while a categorical exception is written in for selecting human beings as targets. The Pentagon has signaled it intends to revisit the directive again, but as of this file's writing, the 2023 version remains the governing US standard.
Contested zone: "appropriate levels of human judgment" is a judgment-based standard, not a bright line. Supporters say that flexibility lets policy keep pace with different weapon types and threats. Critics say the same flexibility is exactly what allows human oversight to shrink in practice without ever technically violating the directive.
What Happened in Practice: Gaza
A twenty-second review, according to the sourcing behind it
In April 2024, the Israeli outlets +972 Magazine and Local Call published a joint investigation, based on interviews with multiple named and anonymous Israeli intelligence sources, describing an AI system called "Lavender" used by the IDF to help identify suspected Hamas or Palestinian Islamic Jihad operatives, alongside a related system called "The Gospel" used to help select physical strike sites. The investigation's most widely reported claim is that Lavender flagged tens of thousands of names as potential targets, and that human review of each flagged name in practice took on the order of twenty seconds before approval.
The IDF's public response called elements of the reporting "baseless in fact" and described a human-controlled targeting process in which the AI systems provide a starting point for analysts rather than a final decision. Both the investigation's sourcing and the IDF's rebuttal are part of the public record; this file treats the specific twenty-second figure and the scale of flagged names as reported claims from a named investigative outlet, not independently verified facts, while treating the existence of the Lavender and Gospel systems themselves — which the IDF has not denied operating — as established.
What Happened in Practice: Ukraine
Autonomous strike drones move from test to deployment
Independent defense-policy analysis, including from the Center for Strategic and International Studies, describes Ukraine's trajectory as one of expanding partial autonomy — automated target acquisition and terminal guidance — layered under a policy that keeps the decision to fire with a human operator. That is a materially different claim than "fully autonomous killing," and this file treats it that way: the guidance and identification steps are increasingly automated and independently reported; the claim that human sign-off is preserved for the actual strike decision rests on official Ukrainian statements that have not been independently audited by a neutral third party.
The Diplomatic Record
156 states voted for a resolution with no enforcement teeth
On November 6, 2025, the UN General Assembly adopted a resolution on lethal autonomous weapons systems by a vote of 156 in favor, five against and eight abstaining. The resolution expresses concern about an emerging arms race, the risk of escalation and proliferation to non-state actors, and calls for a "comprehensive and inclusive multilateral approach." It does not create a binding legal framework and does not mandate formal treaty negotiations — a group of governmental experts has been meeting on the issue for years without producing one.
| Track | What It Establishes | Enforcement |
|---|---|---|
| UN General Assembly Resolution (Nov 2025) | Political consensus that the issue needs a multilateral approach | None — non-binding |
| DoD Directive 3000.09 (2023) | US internal requirement for "appropriate" human judgment | Internal DoD compliance only |
| GGE on LAWS (ongoing) | Years of expert-level discussion; 42 states have called for negotiations to begin | No treaty produced to date |
Warning: the gap between diplomatic concern and enforceable rule is not closing quickly. Every actor in this file — the US, Israel, Ukraine and Russia among them — is fielding more autonomous targeting capability in the same years that the UN process has failed to produce a binding instrument.
Join The Briefing
Get new files first
Get new investigations, corrections, and subscriber-only extras before they show up anywhere else on the site. No spam, no schedule pressure — just the signal when there is something worth sending. Join The Briefing →
Evidence Ledger
Verified, contested, and unresolved claims
The directive's text and the CRS defense primer both confirm the standard is judgment-based rather than a bright-line rule.
UN and Stop Killer Robots reporting on the vote count and the resolution's own text confirm both the tally and the lack of binding force.
This is a sourced investigative claim based on multiple named and anonymous military-intelligence interviews; the IDF disputed elements of the characterization and has not independently confirmed the exact figures.
The IDF's own public response addressed the systems' function rather than denying their existence, and multiple independent outlets corroborated the systems' existence beyond the original investigation.
This figure comes from official Ukrainian government statements reported by defense-focused outlets and has not been independently audited by a neutral third party.
Official policy in the US and Ukraine states human control is preserved for the firing decision; independent battlefield reporting and the Lavender investigation describe review windows short enough that critics argue oversight is functionally hollow.
Final Assessment
The rule survives on paper; the practice is already ahead of it
It is verified that no state has adopted a binding international rule requiring meaningful human control over autonomous weapons, that the US standard remains a flexible "appropriate judgment" test rather than a fixed threshold, and that multiple states are fielding AI-assisted targeting and strike systems faster than that diplomatic gap is closing. It is contested — not settled either way — whether the human-review steps described in current deployments amount to real oversight or a formality fast enough to be meaningless.
The strongest assessment this file can support is this: the technology has outpaced the policy question it was supposed to answer. Every actor examined here — a NATO ally, a wartime democracy under invasion, and the world's largest military — has converged on the same structure: keep a human notionally in the loop, automate everything feeding into that human's decision, and let the speed of the automation quietly determine how much judgment the human actually has time to exercise.
The next file in this route follows the same automation into a domain where the target is not a person on a battlefield, but a network — and the attacker on the other end may not be a person at all.
Sources
Primary and institutional source trail
- 01Jan 2023DoD Directive 3000.09 - Autonomy in Weapon SystemsDefense Policy Directive
- 022024Congressional Research Service - Defense Primer: US Policy on Lethal Autonomous Weapon SystemsCongressional Research Report
- 03Nov 6, 2025UN General Assembly - Resolution on Lethal Autonomous Weapons SystemsUN Resolution
- 042026CSIS - Ukraine's Future Vision and Current Capabilities for Waging AI-Enabled Autonomous WarfarePolicy Analysis
- 05Apr 3, 2024+972 Magazine - 'Lavender': The AI Machine Directing Israel's Bombing Spree in GazaInvestigative Report
- 06Dec 5, 2024Human Rights Watch - Killer Robots: UN Vote Should Spur Treaty NegotiationsNews Report
Continue the Chain
Follow the frontier AI risk route