There is an Israeli navy technique referred to as the “fog procedure”. First used in the course of the second intifada, it’s an unofficial rule that requires troopers guarding navy posts in situations of low visibility to shoot bursts of gunfire into the darkness, on the idea that an invisible risk may be lurking.
It’s violence licensed by blindness. Shoot into the darkness and name it deterrence. With the daybreak of AI warfare, that very same logic of chosen blindness has been refined, systematized, and handed off to a machine.
Israel’s latest struggle in Gaza has been described as the primary main “AI war” – the primary struggle during which AI methods have performed a central position in producing Israel’s record of purported Hamas and Islamic jihad militants to focus on. Systems that processed billions of knowledge factors to rank the likelihood that any given particular person within the territory was a combatant.
The darkness within the watchtower was a situation of the terrain. The darkness contained in the algorithm is a situation of the design. In each circumstances, the blindness was chosen. It was chosen as a result of blindness is helpful: it creates deniability, it makes the violence really feel inevitable, it strikes the query of who determined from an individual to a process. The fog didn’t carry. It was given a likelihood rating and referred to as intelligence.
It might have been chosen blindness that led, at first of the US-Israeli Iran struggle, to the strike on the Shajareh Tayyebeh elementary college in Minab, in southern Iran. At least 168 individuals had been killed, most of them youngsters, women aged seven to 12.
The weapons had been exact. Munitions specialists described the concentrating on as “incredibly accurate”, every constructing individually struck, nothing missed. The drawback was not the execution. The drawback was intelligence. The college had been separated from an adjoining Revolutionary Guard base by a fence and repurposed for civilian use practically a decade in the past. Somewhere within the concentrating on cycle, it appears that evidently reality was by no means up to date.
The precise position of AI within the strike on Minab has not been formally confirmed. What is thought is that the concentrating on infrastructure during which these methods function has no dependable mechanism for flagging when the underlying intelligence is a decade outdated.
Whether or not an algorithm chosen this college, it was chosen by a system that algorithmic concentrating on constructed. To strike 1,000 targets within the first 24 hours of the marketing campaign in Iran, the US military relied on AI methods to generate, prioritize, and rank the goal record at a velocity no human group might replicate.
Gaza was the laboratory. Minab is the market. The result’s a world during which essentially the most consequential concentrating on selections in trendy warfare are made by methods that can’t clarify themselves, equipped by corporations that reply to nobody, in conflicts that generate no accountability and no reckoning. That just isn’t a failure of the system. That is the system.
Who is responsible when AI kills?
We ought to resist the temptation to solely blame the algorithm for the logic that makes youngsters into acceptable error charges. In July 2014, 4 boys from the Bakr household – Ismail, Zakariya, Ahed and Mohammad, aged 9 to 11 – had been killed on a beach in Gaza. No AI was concerned. The website had been preclassified as a Hamas naval compound. The boys had been flagged as suspicious as a result of they ran, then walked – conduct that matched a concentrating on template for fighters attempting not to attract consideration. When the primary missile hit, the surviving youngsters fled. The drone adopted them and fired once more. An officer later testified that from a vertical aerial view, it is rather arduous to establish youngsters. The strike was logged as a concentrating on error.
A categorised Israeli navy database, reviewed by the Guardian, +972 Magazine and Local Call, indicated that of greater than 53,000 deaths recorded in Gaza, named Hamas and Islamic Jihad fighters accounted for roughly 17%. That suggests the remaining, 83%, had been civilians. These are usually not the statistics of a struggle fought with precision, it is a struggle the place imprecision is the intention. (The IDF disputed figures introduced within the Guardian article though they didn’t establish which figures.)
So AI concentrating on methods didn’t invent this logic. They inherited it, encoded it throughout hundreds of thousands of knowledge factors, and automatic it past any significant human test. When a faculty in Minab is assessed in a database as a navy compound, that’s not a malfunction. It is the fog process, the identical logic that chased 4 boys down a seaside in Gaza – operating precisely as designed, at a distinct scale, in a distinct nation, with a distinct weapon. The darkness simply has higher {hardware} now.
Many of those AI methods inherently defy worldwide humanitarian legislation, which doesn’t merely demand appropriate outcomes from navy operations; it requires a cautious course of earlier than they’re carried out. A commander should make each affordable effort to confirm {that a} goal is a official navy goal. The legislation additionally requires that every little thing possible be finished to guard civilians from the consequences of assault, not as an afterthought, however as a parallel and equal obligation.
That obligation can’t be delegated to a system whose reasoning is opaque and whose outputs can’t be interrogated in actual time. In Gaza, an algorithm processed knowledge on each particular person within the strip – cellphone information, motion patterns, social connections, behavioral indicators – and produced a ranked record of names, every assigned a likelihood rating indicating the chance they had been a combatant. This just isn’t the identical as a human analyst figuring out a identified militant and programming a weapon to hit them. The AI was not confirming identities. It was inferring them, statistically, throughout a whole inhabitants, producing targets that no human had individually assessed earlier than they appeared on the record.
Verification, on this system, meant a human operator reviewed every title for a mean of about 20 seconds, lengthy sufficient to substantiate the goal was male. Then they signed off. One system alone produced more than 37,000 targets in the first weeks of the war. Another was able to producing 100 potential bombing websites per day. The people within the loop weren’t exercising judgment. They had been managing a queue.
In Iran, the image is, at the moment, much less totally documented. But the dimensions tells its personal story. Two sources confirmed to NBC News that Palantir’s AI methods, which draw partially on giant language mannequin know-how, had been used to establish targets. (Palantir’s CEO, Alex Karp, mentioned he “can’t go into specifics” when requested about this on CNBC, however mentioned that Claude was nonetheless built-in into Palantir’s methods used within the Iran struggle.) Brad Cooper, head of the US Central Command, has boasted that the navy is utilizing AI in Iran to “sift through vast amounts of data in seconds” with a purpose to “make smarter decisions faster than the enemy can react”. Whether or not each strike was AI-assisted, the tempo of the marketing campaign was solely doable as a result of concentrating on had been considerably automated.
When reported verification instances for AI-assisted targets are measured in seconds, we’re now not speaking about human judgment with algorithmic help. We are speaking about rubber-stamping a machine’s output. And when that machine’s knowledge is a decade outdated, the results are written in rows of small coffins.
The corporations implicated on this are usually not obscure defense startups. Palantir, based with early CIA funding and now one of many main AI infrastructure suppliers to the US navy, equipped methods used within the Iran marketing campaign. Those methods draw partially on Anthropic’s Claude, a big language mannequin whose mother or father firm tried to withstand Pentagon stress to take away moral constraints on its use for concentrating on. The Pentagon responded by threatening to chop ties and turning to OpenAI and others as a substitute. The marketplace for killing at scale doesn’t lack for suppliers.
The episode is instructive: the one firm that attempted to attract a line was sidelined, and the killing continued with out interruption. Google, regardless of vital inside worker protest, signed Project Nimbus, a cloud-computing and AI contract with the Israeli authorities and navy price greater than $1bn.
Amazon is a co-signatory to Project Nimbus alongside Google. Microsoft had deep integration with Israeli navy methods earlier than partially withdrawing below stress in 2024, at which level the info migrated to Amazon Web Services inside days.
Anduril, based by Palmer Luckey and staffed closely with former US defense officers, builds autonomous weapons methods explicitly designed for deadly concentrating on. OpenAI, which till lately prohibited navy use in its phrases of service, quietly eliminated that restriction in early 2024 and has since pursued Pentagon contracts. These are among the many most precious corporations on this planet, with client merchandise utilized by tons of of hundreds of thousands of individuals, college analysis partnerships, and vital political affect in Washington, Brussels and past.
Of course non-public corporations have equipped militaries for hundreds of years – with radios, vehicles, satellite tv for pc navigation, microwave know-how and, after all, advanced weapons methods. This just isn’t new or inherently corrupt. The “dual-use” drawback is as previous as industrialization: virtually any highly effective know-how can be utilized for navy ends.
But AI concentrating on just isn’t merely a part that militaries incorporate into their operations. It is the choice structure itself – the factor that determines who will get killed and why. When a single system can generate tens of hundreds of targets within the time it could have taken a human intelligence group to confirm 10, the query just isn’t whether or not non-public corporations ought to provide militaries. It is whether or not any authorized framework can survive contact with it.
In worldwide legislation we speak about accountability frameworks: the chain of answerability that runs from a call to make use of deadly pressure again to the one who approved it. An accountability framework requires that somebody be identifiable because the decision-maker, that their reasoning be reconstructable after the actual fact, and that the method obligations the legislation calls for – proportionality evaluation, verification, precaution – will be proven to have been adopted.
AI concentrating on systematically destroys every of those situations. Attribution dissolves throughout a sequence of engineers, commanders, operators and company suppliers, every of whom can level to a different. Reasoning disappears right into a likelihood rating that no lawyer can audit and no court docket can cross-examine. Process collapses right into a 20-second approval of a machine suggestion. And the businesses that constructed and bought the system sit totally exterior the authorized framework, as a result of worldwide humanitarian legislation was designed for states and their brokers, and Palantir just isn’t a signatory to the Geneva conventions.
The accountability framework has not been merely strained or examined by AI warfare. It has been made structurally irrelevant.
Lifting the fog of struggle
We ought to cease calling these know-how corporations and begin calling them what they’re: defense contractors.
The largest AI companies are usually not impartial infrastructure suppliers who occurred to discover a navy buyer. They are being built-in into the concentrating on structure of contemporary warfare. Their methods sit contained in the kill chain, their engineers maintain safety clearances, their executives rotate by means of the identical revolving door that has all the time related Silicon Valley to the Pentagon.
These AI suppliers are on the reducing fringe of the military-industrial advanced, and must be regulated as such. A transparent accountability chain applies to companies reminiscent of Raytheon and Lockheed Martin – entailing export controls, congressional oversight, legal responsibility frameworks and procurement situations – whereas the weak rules that apply to the businesses writing the algorithms that choose navy targets have by no means been utilized, examined or enforced.
That just isn’t an oversight. It is a alternative, actively maintained by lobbying, by the deliberate blurring of “commercial” and “defense” merchandise, and by a regulatory tradition that also treats AI as a client know-how that occurred to seek out its strategy to the battlefield. Palantir spent near $6m lobbying Washington in 2024, and in a single quarter of 2023 outspent Northrop Grumman. It launched a devoted basis to form the coverage surroundings it operates in. The consortium of Palantir, Anduril, OpenAI, SpaceX and Scale AI was described by its own participants as a mission to provide a brand new technology of defense contractors to the US authorities. The enterprise capital companies backing these corporations, Andreessen Horowitz and Founders Fund, have cultivated affect by means of proximity to energy: former senior officers on their advisory boards, companions rotating by means of authorities roles and direct entry to the policymakers who decide how a lot the Pentagon spends and on what.
The EU AI Act, essentially the most formidable try but to control synthetic intelligence, explicitly exempts navy and nationwide safety functions, with the acknowledged justification that worldwide humanitarian legislation is the extra acceptable framework. It is a exceptional act of circularity: the one physique of legislation being systematically destroyed by these methods is designated as their regulator, whereas the regulators who may really constrain them look away.
In the United States, the AI provisions of the 2025 National Defense Authorization Act don’t regulate navy AI. They direct companies to undertake extra of it. Pete Hegseth’s AI technique, issued in January 2026, frames the query totally as a race, directing the Pentagon to maneuver at wartime velocity, with AI as the primary proving floor. The regulatory tradition has not didn’t meet up with the know-how. It has determined, intentionally, to not strive.
So far, the one critical authorities intervention in AI navy functionality we’ve got seen got here not from a state demanding restraint or accountability, however from the US demanding the methods be made extra deadly. That is the horizon of ambition we’ve got accepted.
Banning these methods outright is inconceivable when so most of the actors concerned care little about worldwide legislation. But stress factors stay, and they’re actual. Any future authorities in Washington that wishes to make use of AI navy functionality with out producing an endless sequence of Minabs will want a regulatory framework – not as a concession to critics however as a fundamental requirement for not turning into a rogue actor. The identical is true in Europe, the place Britain has dedicated over £1bn to a brand new AI-integrated concentrating on system connecting sensors and strike capabilities throughout all domains, and the place France’s main AI firm has partnered with a German defense startup to construct autonomous weapons platforms, and the place Germany is deploying AI-guided assault drones in Ukraine.
There’s a gap to manage these methods. The EU has the obvious instruments, not by means of the AI Act, which intentionally exempts navy functions, however by means of export controls and procurement situations on the dual-use methods that transfer between business and defense markets. International courts are starting to open doorways too: the worldwide court docket of justice advisory opinion on Palestinian rights has created a framework during which corporations supplying methods utilized in illegal strikes face potential legal responsibility publicity in jurisdictions that take worldwide legislation severely. And AI companies want governments, not simply as prospects however because the suppliers of the computing energy, the power and the bodily infrastructure that frontier AI requires and that no firm can maintain from business revenues alone. That dependency offers states which can be keen to make use of it actual leverage over corporations that would like to not be regulated. The query is whether or not any authorities with the instruments to behave will resolve, earlier than the subsequent Minab, that the price of inaction has change into too excessive.
What regulation ought to appear to be is comparatively easy, even whether it is arduous to implement. AI methods utilized in concentrating on should be explainable – not by way of likelihood rating however reasoning {that a} lawyer can audit. The cumulative civilian value of AI-assisted campaigns should be assessed as an entire. And the legal responsibility that stops on the operator should lengthen up the provision chain to the businesses that knowingly constructed and bought opaque methods to be used in armed battle. These are usually not novel calls for. They are the minimal situations for the legal guidelines of struggle to imply something within the age of algorithmic concentrating on.
In the meantime, the fog process is operational and coming to outline the way forward for struggle. But the troopers who fired into the darkness had been not less than current in it. The corporations that constructed what changed them are doing it from Palo Alto, at no private threat, with no authorized publicity, and with each incentive to do it once more.
Avner Gvaryahu is a DPhil researcher on the Blavatnik college of presidency, University of Oxford. He is a former government director of Breaking the Silence, an Israeli human rights group of former troopers