Autonomous Weapons Systems

Somewhere behind the Ukrainian lines, an officer watches a screen. On it, a small quadcopter hangs above a treeline, its camera fixed on a Russian armored vehicle two kilometers off. He is not flying it. No one is. The link that would have carried a human operator's commands is being jammed, and the drone has been cut loose to finish the job on its own — reading the terrain, holding the target through the enemy's countermeasures, choosing its moment. It finds a line. It accelerates. It strikes. From the machine's first lock to impact, the whole engagement takes under a minute, and the only human decision involved was made before takeoff.

This is not a demonstration or a prototype under evaluation. It is Tuesday. Ukraine spent 2025 building drones by the million and retraining their targeting software on captured battlefield footage, and a growing share of that fleet can now identify a Russian vehicle and drive itself into it without waiting for anyone to press a button. The debate that has consumed diplomats and ethicists for a decade — whether a machine should ever be allowed to decide who dies — has, in the mud of the Donbas, already been answered in practice. The question that remains is not whether autonomous weapons will be used. It is what the operational record now tells us about what they can do, how fast they are spreading, and whether anyone can still get ahead of them.

What "autonomous" actually means

The phrase "autonomous weapon" hides more than it reveals, because autonomy is not a switch but a slope. The useful way to think about it is as a spectrum of how much human judgment sits between the machine and the kill.

At one end are remotely piloted systems where a person controls every movement, watches the video feed, picks the target, and authorizes the strike. The shorthand is human-in-the-loop: nothing lethal happens without a finger on the trigger. A step along are systems that find and track targets on their own but still require a human to approve engagement — human-on-the-loop, where the person supervises and can veto but no longer aims. Further still are supervised autonomous systems that select and engage within preset parameters, with human oversight reserved for the exceptional case. And at the far end sit fully autonomous systems that, once launched, select and destroy targets with no further human input at all — human-out-of-the-loop.

The important fact about this spectrum is that everything on it drifts in one direction. Systems that were human-in-the-loop five years ago are human-on-the-loop today. Engagements that once needed individual authorization now run under general mission orders, with a human consulted only when something looks wrong. Ukraine's development effort has concentrated on three capabilities — computer vision trained to pick Russian equipment out of clutter, terrain mapping for navigation without GPS, and coordinated groups of drones that strike without a central controller — and each is now field-proven, meaning it has worked under real combat conditions, not just on a test range. None of that required a policy decision to cross into full autonomy. It required a jammer.

Why jamming forces the machine's hand

Here is the mechanism that makes the whole policy debate feel a half-step behind reality. A first-person-view drone is only as good as the radio link carrying its video down and its pilot's commands up. That link is exactly what electronic warfare is built to sever. Both sides in Ukraine now blanket the front with jamming, and a jammed drone faces a binary choice: abort, or finish the mission on its own. Abandoning a strike that is seconds from completion, against an enemy who is also improving, is not a choice militaries make twice. So the drones are given the ability to lock onto a target in the final approach and complete the run after the link dies — "terminal guidance," in the trade, which is a polite name for a machine finishing a kill a human started but can no longer see.

Speed compounds the problem. When an engagement resolves in seconds and the decisive window is the last few hundred meters, there is simply no time to route a decision back through a person, even if the link held. The result is that the line between human-on-the-loop and human-out-of-the-loop is being drawn not by lawyers or treaties but by the physics of the electromagnetic spectrum. A government can declare that its forces will always keep a human in meaningful control, and mean it, and still field weapons that operate without one whenever the enemy turns on a jammer. Policy sets the intent. The battlefield sets the behavior.

graph LR
  A[Enemy jamming severs the control link] --> B[Drone must abort or finish alone]
  B --> C[Terminal guidance added so strikes complete]
  C --> D[Engagement resolves faster than a human can react]
  D --> E[Human-out-of-the-loop by necessity, not by policy]

What the Ukraine record actually shows — and how much to trust it

The single most cited claim from Ukraine is an accuracy jump: Ukrainian officials report that AI-enabled targeting raised the hit rate of their strike drones from somewhere around 30–50% to roughly 80%, letting a unit destroy a target with one or two drones where it previously spent eight or nine. Alongside it come figures on scale — a fleet on track for over four million drones produced in 2025, roughly double the 2.2 million of 2024 — and on lethality, with Ukrainian drone units reporting more than 18,000 verified Russian personnel struck in September 2025 alone, about twice the figure from a year earlier (Breaking Defense, 2025; Atlantic Council, 2025).

Those numbers are the empirical spine of every argument in this chapter, so it matters how sturdy they are. The honest answer: sturdier than nothing, weaker than we would like. They come overwhelmingly from the Ukrainian government and military, an actor with an obvious and legitimate interest in demonstrating that its technology works and its foreign backing is well spent. "Verified" is doing quiet work in "verified strikes," and a jump from "30–50%" to "around 80%" is a self-reported before-and-after with no independent audit of either end. This is the general condition of battlefield data as evidence: it is generated by combatants, in secrecy, under pressure, and it reaches us filtered through the incentives of the people releasing it. That does not make it worthless — the broad picture of AI-assisted drones dramatically outperforming manual piloting is corroborated across many independent reporters and analysts, and the direction of the effect is not seriously disputed. It means the precise figures should be read as indicative rather than exact, and that anyone building a governance argument on "80% accuracy" as if it were a laboratory measurement is overreaching.

There is a second, deeper limit. Even taken at face value, Ukraine tells us how these systems perform in Ukraine — against a specific adversary, in specific terrain and weather, with a specific electronic-warfare environment that both sides have spent years co-evolving. How that performance generalizes to a different enemy who fights differently, to jungle or city or desert, or to an opponent with better spoofing and decoys, is genuinely unknown. A computer-vision model trained to recognize Russian vehicles from captured footage is not obviously good at recognizing anything else, and adversaries adapt: camouflage, decoys, and data-poisoning of the very footage these models learn from are all cheap countermoves. The Ukraine record is the best evidence we have that field-autonomous strike works. It is not evidence that it works everywhere, or that it will keep working once opponents optimize against it.

The Pentagon's answer: Replicator and a $14.2 billion bet

The United States has watched all of this closely, and the conclusion it has drawn is written into its budget. For fiscal year 2026 the Pentagon requested a record $14.2 billion for AI and autonomous systems research — a figure that would have looked outlandish a few years ago (CBS News, 2025). Its flagship is the Replicator initiative, funded at roughly $1 billion in 2025, whose stated aim is to field thousands of cheap, attritable, AI-enabled autonomous drones and surface vessels quickly, explicitly to offset China's advantage in mass.

The doctrine underneath the money is a reversal of how the American military has thought about airpower for two generations. The old logic prized a small number of exquisite, expensive, human-piloted platforms — the fighter jet that costs more than a town. The new logic, drawn straight from Ukraine and from war-gaming a Pacific conflict, is that a swarm of thousands of cheap machines can saturate and overwhelm those exquisite platforms faster than they can be replaced, and that the only answer to mass is mass. Replicator is a bet that the future belongs to quantity — and quantity, at that scale, cannot be supervised. Once you are flying thousands of coordinated drones, there is no control room large enough to put a human on each engagement, and the machines' decision cycle is measured in milliseconds while a human's is measured in seconds. The program therefore encodes, as an engineering requirement, the same tension the jammers create on the front: the United States insists on "meaningful human control" over lethal autonomy while investing in systems whose entire value proposition is operating at a scale and speed where meaningful human control, at the level of the individual shot, is a physical impossibility. What that phrase will mean in practice, the Department of Defense has not resolved.

The economics that make an arms race self-loading

The reason autonomous drones restructure war rather than merely joining it is arithmetic. An early FPV strike drone cost several thousand dollars; mass production drove that toward a few hundred; credible projections put it in the tens of dollars within a few years as the airframes become commodity electronics. When the thing that kills a tank costs less than the tank's fuel, and can be built by the million, the binding constraint on war stops being the scarce, slowly-trained human and becomes the factory.

That shift has a nasty feedback property. Falling unit cost is exactly what makes any negotiated quantity limit progressively harder to enforce, because the cheaper the unit, the more of them any actor can build in a garage, and the less a cap on visible, expensive platforms constrains actual firepower. A treaty that limits you to a hundred cruise missiles means something. A treaty that tries to limit you to some number of fifty-dollar drones you can 3D-print is negotiating over sand. And because each side's production directly determines battlefield outcomes, no one can slow their own line while the other's runs — as effectiveness is demonstrated, the weapon becomes standard; as it becomes standard, adversaries adopt it to avoid disadvantage; as adversaries adopt it, pressure mounts to build more and make them more independent. The escalator only goes up, and stepping off it alone is measured directly in lost ground.

When drones do most of the dying

The starkest number from this war is not about production. It is that drones are now estimated to cause 70–80% of casualties in Ukraine — more than artillery, more than mines, more than the rifle. That single fact rewrites the logic of attrition warfare that has governed strategy since Verdun.

Attrition has always been constrained by the human cost of sustaining it. Trained soldiers, pilots, and specialists cannot be replaced on a production schedule; their loss carries political and strategic weight, and the fear of that loss is part of what makes states hesitate before entering and sustaining a war. If the fighting is increasingly done by machines that cost tens of dollars and put no pilot at risk, attrition collapses into an industrial-output problem — whoever manufactures more, cheaper, faster, wins. That is a genuinely dangerous transformation, because a large part of what has historically deterred leaders from war is the prospect of body bags coming home. A war fought at the front by expendable machines lowers the near-term human price of starting and continuing one, even as it raises the ceiling on how much destruction can be industrially sustained. Cheaper war is not safer war. It is more of it.

Diffusion: the threshold keeps dropping

Everything that makes these weapons militarily attractive — low cost, commodity parts, software that improves with shared data — also makes them hard to contain. The capability that took a national defense effort to field in 2023 is, in cruder form, assemblable from consumer drones, open-source autopilot software, and off-the-shelf image-recognition models. As cost and complexity fall, the set of actors who can build a serviceable autonomous strike drone widens from great powers to smaller states, to non-state armed groups, and eventually to well-resourced criminal organizations. The access threshold is not a wall that stays put; it is a line receding toward the hobbyist. We have already seen commercial quadcopters weaponized by insurgents and cartels with human piloting. The autonomous version removes even the need for a skilled operator and a working radio link — the two things jamming and inexperience most reliably deny. That is the diffusion story that should worry planners most: not that the Pentagon or China will have these weapons, but that eventually almost anyone will.

The regulatory vacuum, and why the leaders keep it empty

Against this, the international response has been earnest and largely toothless. In November 2025 the UN General Assembly's First Committee passed a resolution calling for negotiations toward a legally binding instrument on lethal autonomous weapons systems, pointing to the 2026 Review Conference as a target. The vote was lopsided in a revealing way: 156 nations in favor, five opposed — and among the five were the United States and Russia, the two states furthest ahead in the technology (UNODA, 2025). The Secretary-General has called autonomous weapons that kill without human oversight "politically unacceptable and morally repugnant" and pressed for a ban (UN News, 2025).

That 156-to-5 split is the whole problem in a single tally. It shows a near-universal diplomatic consensus that this should be governed, and it shows that the handful of actors whose behavior would actually matter are precisely the ones refusing. The gap is not converging toward a treaty; the diplomatic mainstream and the frontier powers are, if anything, diverging — one writing declarations, the others writing procurement contracts. The structural logic is not mysterious. Every advanced military would prefer a world where no one has autonomous weapons to one where everyone does — that is the multilateral optimum. But none will accept a world where they alone abstain while rivals proceed, because unilateral restraint in a demonstrated war-winning technology reads to any general as surrender by other means. Since a binding treaty requires the leaders to bind themselves first, and each fears the others will cheat or defect, the preferred multilateral restraint is unreachable and the dispreferred universal armament is where the incentives point. This is a textbook trap, and knowing it is a trap does not spring it.

Verification would be brutal even with political will. Missiles and airframes can be counted; you can inspect a hangar. But autonomy lives in software, and the difference between a "supervised" system and a "fully autonomous" one can be a single parameter, flipped in the field or pushed as a remote update after the inspectors leave. You cannot count a line of code from a satellite. An arms-control regime built for things you can see and tally is poorly suited to a weapon whose most important feature is invisible.

The window, and how narrow it is

Put the pieces together and the timing looks grim for governance. Effective regulation of a weapon is easiest when the systems are few, expensive, produced by a handful of actors, and not yet decisive — because then the leaders have something to trade and little to lose. Autonomous drones are moving the opposite way on every axis at once: production is scaling into the millions, unit cost is falling toward the trivial, the actor set is widening, and battlefield results are proving the weapon indispensable. Each of those trends independently makes a treaty harder to reach and harder to enforce; together they risk producing a framework that is obsolete on the day it is signed — regulating a generation of systems already superseded, and unenforceable against a diffusion that has already happened. The window for a governance regime that shapes rather than chases the technology is measured in a few years, not decades, and a meaningful part of it has already closed.

The debate that isn't going away

None of this settles the underlying moral question, which is genuinely hard and deserves to be stated at its strongest on both sides.

The case for prohibition begins with a claim about the act itself: that deciding to end a human life is inherently human and cannot be delegated to an algorithm without abolishing accountability. A person killed by an autonomous weapon is killed by no one — there is no author of the decision to hold responsible, no judgment to answer for. From there the legal argument follows. International humanitarian law demands distinction between combatant and civilian, proportionality between military gain and civilian harm, and precaution to minimize the latter — and all three are context-soaked judgments, not classification tasks. Whether the figures beside a truck are fighters or farmers, whether people in a building are sheltering freely or held as shields, whether a strike's expected advantage justifies its expected harm — these require reading a situation the way a person reads a room, and no current AI system does that reliably. The practical case adds the failure modes: misidentification, accidental engagement, and cascading interactions between opposing autonomous systems that could escalate a skirmish into a war in seconds, faster than any diplomat could intervene.

The permissive case — argued in practice by the United States, Russia, China, and Israel — does not wave these away. It answers them. On precision, it points out that human soldiers are the ones who panic, tire, seek revenge, and commit atrocities; a machine feels no fear and can be built to apply rules of engagement with a fidelity no frightened nineteen-year-old can match, so the real question is the quality of the system, not the presence of autonomy. On law, it argues that a well-designed system can encode IHL constraints more consistently than a human applies them under fire. On strategy, the argument is blunt: if your adversary fields autonomous weapons and you do not, you lose, and a lost war is not a moral victory. And on inevitability, it holds that a technology this cheap, this accessible, and this decisive cannot be banned out of existence — bans will simply be ignored by those who matter, so the responsible path is accountability frameworks under existing law rather than a prohibition honored only by the states that were never the danger.

Dimension The case for prohibition The case against
Moral Delegating the kill decision to a machine erases human dignity and leaves no one accountable Fewer humans killed and endangered on both sides is itself morally relevant
Legal AI cannot reliably apply IHL's context-dependent distinction, proportionality, and precaution A well-designed system can apply rules of engagement more consistently than a soldier under stress
Practical Misidentification, accidental engagement, and irreversible cascading failures Machine precision can cut civilian harm relative to panicked human decisions in chaos
Strategic An autonomous arms race compresses crisis timelines toward accidental war Unilateral restraint hands a decisive, demonstrated advantage to the adversary

Two of these disputes turn on evidence we partly have, and one on evidence we largely don't. The precision and misidentification claims are, in principle, testable against field data — and Ukraine offers a first, murky look, though as noted that data is self-reported and non-generalizable. But the strategic fear that autonomous arms races "compress crisis timelines" into accidental escalation is, at present, closer to a well-reasoned theoretical concern than a documented empirical fact. It rests on a sound mechanism — machines that react faster than humans, interacting, could escalate before anyone intervenes — and on unsettling analogies like the algorithmic "flash crashes" of financial markets, where automated systems interacting at machine speed produced sudden collapses no human ordered. But we have not yet observed two opposing autonomous military systems drive an unintended escalation, and we should hope the first data point is not a war. The evidence that would distinguish a real risk from an imagined one is, almost by definition, evidence we can only gather by running the experiment. That asymmetry — a plausible mechanism, catastrophic if real, and unmeasurable until it happens — is precisely the condition under which precaution, rather than proof, is the rational basis for urgency. Waiting for the empirical confirmation is waiting for the accident.

Who should weigh the strategic-necessity argument against the moral and legal ones is itself contested. Militaries frame it as a professional judgment about survival; prohibitionists insist that a decision to mechanize killing belongs to the wider society and the international community, not to the institutions with the strongest incentive to answer it in their own favor. That, too, the 156-to-5 vote captures: most of the world has claimed the decision, and the few who can actually make it have declined to hand it over.

Summary

  1. Field-proven, not theoretical. Ukraine has demonstrated that AI-enabled autonomous targeting, GPS-denied navigation, and coordinated drone strikes work under combat conditions. Reported gains — hit rates rising from roughly 30–50% to around 80%, a fleet on track for over four million drones in 2025, drones causing 70–80% of casualties — mark a genuine shift, though the figures are largely self-reported by Ukraine and should be read as indicative, not audited.

  2. Autonomy is being set by the battlefield, not by policy. Jamming severs the human link and speed removes the time for human decisions, so systems slide toward human-out-of-the-loop operation regardless of stated intent. The same tension is built into the Pentagon's $14.2 billion FY2026 investment and its Replicator program: swarms at scale cannot be supervised shot-by-shot.

  3. Cheap weapons make an arms race self-loading. As unit cost falls toward tens of dollars, quantity limits become unenforceable, attrition warfare turns into an industrial contest, and no leader can slow production while rivals build — lowering the near-term human cost of war without making it safer.

  4. The leaders have structural reasons to block a treaty. Everyone prefers universal restraint to universal armament, but no one will abstain alone, so the 156-to-5 UN vote reflects a consensus the frontier powers refuse to join. Software-based autonomy is also nearly impossible to verify.

  5. The window is closing. Scale, falling cost, and diffusion to smaller states and non-state actors are all making governance harder simultaneously — risking a framework obsolete before it is ratified.

  6. The hardest risk is the least measurable. The prohibitionists' strongest strategic fear — that interacting autonomous systems compress crisis timelines toward accidental escalation — remains a well-grounded mechanism rather than a documented event. That it is unmeasurable until it happens is an argument for precautionary urgency, not for waiting on proof.

Sources

Last updated: 2026-08-11

V2 (in progress) Previous: V1