SURVXCOM CRITICAL TECHNOLOGY STACK / NATIONAL SECURITY AI REPORT
How artificial intelligence is moving through targeting, geospatial intelligence, cyber operations, surveillance, logistics, autonomous systems and command—and where human judgment still has to remain in the loop.
Technology Stack Article 009
CRITICAL TECHNOLOGY HUB: Explore the complete 30-article SURVXCOM Critical Technology reading path. This article belongs to the Defense, Autonomy & Physical Systems lane.
EDITOR’S NOTE: This report is based only on publicly available material. Classified capabilities are not inferred from gaps in public reporting. The source hierarchy prioritizes White House national-security policy, Department of Defense and CDAO documentation, NGA and NSA material, CIA public records, Congressional Research Service analysis, government contracts, academic research and serious independent reporting. The article distinguishes intelligence support from target identification, target identification from target nomination, target nomination from engagement authorization, and autonomy in navigation or sensing from autonomy in the use of force.
The most important artificial-intelligence system in modern warfare may not look like a weapon. It may look like a map.
On one screen, satellite imagery arrives from orbit. Drone video is layered with radar tracks, signals intelligence, commercial imagery and reports from units in the field. Software highlights objects that resemble known military equipment. Another model compares today’s imagery with yesterday’s. An analyst opens a detection, examines the source, checks coordinates, compares the finding with other intelligence and passes an assessment to an operations cell. Somewhere else, a commander sees the same data fused into a common picture.
Nothing in that sequence has to fire a weapon automatically for artificial intelligence to change war. If machines reduce the time required to search imagery from hours to minutes, if they rank thousands of observations before a human sees them, if they propose which sensor should look where next, if they fuse information that once lived in separate databases, and if they help a command staff move from detection to decision faster than an adversary, then AI has already entered the battlefield’s nervous system.
This is the less theatrical but more consequential story of military AI. The United States national-security enterprise is now pushing artificial intelligence through the full institutional stack: the Pentagon’s Chief Digital and Artificial Intelligence Office, military services and combatant commands, the National Geospatial-Intelligence Agency, the National Security Agency, the Central Intelligence Agency, other intelligence elements, the defense industrial base and a growing network of commercial AI companies.
In June, the White House issued a new national-security presidential memorandum directing accelerated AI adoption across military and intelligence organizations. It calls for rapid access to frontier models from multiple vendors, high-security computing infrastructure, joint AI data and model exchanges, standardized testing and assurance, expanded AI talent, annual policy reviews and an update to the Department’s directive governing autonomy in weapon systems.
The document is important because it makes explicit what individual programs have been signaling for years: AI is no longer a laboratory capability sitting beside national security. It is being designed into the national-security enterprise itself.
The transformation raises an uncomfortable question. American policy continues to emphasize accountability, lawful use of force and appropriate human judgment. But AI’s principal military advantage is speed. What happens when the system becomes valuable precisely because it compresses the time available for human judgment?
Key Judgments
- Military AI is broader than autonomous weapons. The most mature uses are intelligence processing, computer vision, data fusion, cyber defense, logistics, planning, decision support and collection management.
- Project Maven has evolved from an imagery experiment into operational infrastructure. NGA describes Maven detections feeding multiple platforms and a connected sensor ecosystem, while the Pentagon has expanded Maven Smart System contracting and institutional adoption.
- GEOINT is one of AI’s clearest military use cases. NGA expects a major increase in geospatial data and is using machine learning to detect objects, improve geolocation, identify patterns, support analysts and recommend collection options.
- The intelligence bottleneck is shifting from collection to attention. When machines decide what to flag, rank and surface, AI increasingly influences which evidence reaches the human analyst first.
- The Pentagon is moving toward frontier-model pluralism. CDAO has contracted with multiple leading AI companies and is building enterprise access rather than relying on one model provider.
- Vendor dependence is now a strategic-security issue. The 2026 Anthropic-Pentagon dispute revealed how deeply commercial models can become embedded in military software and why model replaceability matters.
- NSA treats AI as both capability and attack surface. Its AI Security Center focuses on protecting models, data, training systems and AI lifecycles, while recent guidance warns that agentic AI expands the cyber attack surface.
- Autonomy exists on a spectrum. Autonomous navigation, sensor management and route planning are fundamentally different from autonomous target selection or weapons release.
- Current U.S. policy does not simply require a person to click a button. DoD Directive 3000.09 requires “appropriate levels of human judgment” over the use of force, a concept that varies with system and context.
- The central risk is automation bias under time pressure. A nominally human-controlled system can still become functionally machine-driven if operators lack time, evidence or authority to challenge its recommendations.
- Decision sovereignty is becoming part of military sovereignty. A state that depends on privately governed AI models for critical command workflows needs the ability to replace models, preserve logs, retain policy control and continue operating during vendor disputes or outages.
- The future battlefield is likely to be a network of humans and machines rather than a single autonomous superweapon. The strategic advantage comes from connecting sensors, models, analysts, commanders and autonomous platforms into a faster decision system.
The Battlefield Nervous System
Military discussions of artificial intelligence often begin with drones because drones are visible. The deeper transformation is happening in the connective tissue.
Modern armed forces collect enormous amounts of information from satellites, aircraft, unmanned systems, radar, electronic sensors, human reporting, cyber systems and commercial sources. The problem is no longer simply whether information exists.
The problem is whether it can be converted into a useful decision before it becomes stale. The Department of Defense has spent years pursuing variants of this idea under concepts such as Combined Joint All-Domain Command and Control: connect sensors across services, make data interoperable, fuse information, and give commanders a common operating picture quickly enough to act. Artificial intelligence changes each stage.
SATELLITES
DRONES
AIRCRAFT
RADAR
SIGINT
GROUND SENSORS
COMMERCIAL IMAGERY
HUMAN REPORTING
│
▼
DATA INGESTION + NORMALIZATION
│
▼
AI / MACHINE ANALYTICS
│
├── detection
├── classification
├── geolocation
├── pattern recognition
├── anomaly detection
├── translation / summarization
└── collection prioritization
│
▼
ANALYST / INTELLIGENCE FUSION
│
▼
COMMAND + DECISION SUPPORT
│
▼
HUMAN AUTHORITY
│
▼
MILITARY ACTION
The diagram matters because it separates the layers. An AI system that detects a vehicle in an image is not necessarily selecting a target.
A system that recommends additional collection is not necessarily authorizing surveillance. A command platform that presents possible courses of action is not necessarily making the command decision.
But when all of those systems are connected, machine outputs can accumulate influence long before a human reaches the final decision. The decisive question becomes less:
Did AI pull the trigger? and more: How much of the evidentiary and decision environment was already constructed by machines before the human arrived?
Project Maven Grows Up
Project Maven began in 2017 as an effort to use computer vision to help analysts process the flood of full-motion video produced by military drones. At the time, the concept seemed narrow: teach algorithms to identify objects in imagery so humans did not have to watch every frame.
The Pentagon’s own early explanation emphasized that the system would extract objects of interest from still and moving imagery and complement human operators rather than autonomously select targets. Maven did not remain narrow.
NGA says the GEOINT portion of the program moved to the agency in 2023. Today it describes Maven as an operational AI capability that automatically detects, identifies, characterizes, extracts and attributes features and objects in imagery and video. The agency says the system is producing large volumes of detections for warfighter requirements across multiple operational locations.
Those detections do not stay inside NGA. They flow into other military platforms.
NGA describes Maven as a thread connecting sensors from multiple branches of the armed forces into a unified AI network. That phrase reveals how far the program has traveled from its origin.
The important product is no longer an algorithm that recognizes vehicles. It is an architecture that moves machine-generated observations through military workflows.
Earlier NGA testimony reported more than 20,000 active Maven users across more than 35 service and combatant-command tools. NGA also reported that Maven reduced some targeting-workflow timelines by as much as 80 percent in an exercise, moving one targeting cell from hours to minutes from sensing to target engagement.
Those are agency-reported operational metrics, not independent combat measurements. But even treated cautiously, they illustrate the military value proposition:
latency is becoming a weapon.
| Maven phase | Primary problem | Human role | Strategic effect |
|---|---|---|---|
| Early Project Maven | Too much drone imagery for analysts to watch | Review machine detections | Reduce imagery-analysis burden |
| NGA Maven | Too many GEOINT observations across sources | Validate, contextualize and exploit detections | Scale object recognition and geolocation |
| Maven Smart System | Disconnected intelligence and operations workflows | Fuse evidence, approve actions, assess results | Compress decision and targeting cycles |
| Emerging architecture | Multi-domain sensor overload | Exercise authority over increasingly machine-shaped options | Machine-speed command support |
The Pentagon has reinforced Maven’s institutional status with money. In 2024 it awarded Palantir a contract with a ceiling of $480 million for the Maven Smart System prototype. In 2025 the Army raised the ceiling through a $795 million modification. Reuters reported in March 2026 that Pentagon leadership intended to make Maven an official program of record, which would entrench it as a long-term military capability rather than an experiment. That evolution—from prototype, to operational software, to program of record—is the story of military AI adoption in miniature.
NGA: When the Map Starts Thinking
Few agencies illustrate the intelligence problem better than the National Geospatial-Intelligence Agency. NGA sits at the intersection of maps, satellite imagery, location data, intelligence and military operations. It is responsible for turning geospatial information into intelligence that commanders and policymakers can use.
The agency says the amount of available GEOINT data could roughly triple over the next five to ten years as government and commercial satellite programs mature. More collection does not automatically produce more knowledge.
A satellite image only matters if someone or something can inspect it, compare it with other information, recognize what changed, judge significance and deliver the result while it still matters. NGA’s response is to make AI part of the entire cycle.
Its public AI strategy identifies four broad objectives: improve computer vision and geolocation; integrate AI into the analyst workforce; use AI to inform which sensors collect what next; and build shared AI infrastructure for models, labels, detections and data. That third objective is especially important.
Traditional intelligence collection can be understood as a human asking a sensor to look somewhere. An AI-assisted system can continually evaluate standing intelligence needs, constellation constraints and dynamic events, then recommend which collection option should be used next.
That closes a feedback loop:
COLLECT │ ▼ DETECT │ ▼ COMPARE WITH BASELINE │ ▼ IDENTIFY ANOMALY │ ▼ RECOMMEND NEW COLLECTION │ ▼ RETASK SENSOR │ ▼ COLLECT AGAIN
NGA’s ASPEN program adds another layer. The agency describes it as a modernization effort for intelligence production designed to monitor known behavior at known locations while also searching for unknown behavior in unknown locations.
This is pattern-of-life analysis at machine scale. The analytical promise is obvious.
The institutional risk is equally important. If an AI model establishes the baseline of what is “normal,” then the model’s assumptions help define what appears suspicious. That makes model training, provenance, false positives and feedback loops matters of intelligence tradecraft, not simply software quality.
The Intelligence Attention Problem
The classic intelligence problem was scarcity. There were too few satellites.
Too few intercepts.
Too few sources.
Too little information about denied places. Today some parts of intelligence face the opposite problem.
Commercial satellites revisit locations repeatedly. Sensors generate persistent streams. Open-source information arrives continuously. Communications, imagery and geospatial databases can contain more material than teams of analysts can inspect manually.
That changes the scarce resource.
The scarce resource becomes human attention. AI solves that problem by filtering.
But filtering is never neutral.
A model decides which frames are likely to contain an object. A ranking system decides which detections deserve attention.
A language model summarizes fifty reports into five bullets. An anomaly detector decides which activity differs enough from the baseline to flag.
An automated collection system decides which sensor option appears most useful. Each step can increase analyst productivity.
Each step can also hide evidence.
This leads to one of the central doctrines of machine-assisted intelligence: The system that chooses what the analyst sees can influence judgment without ever making the final judgment itself. That is why provenance becomes so important.
An analyst should be able to move backward from a model-generated claim to the underlying imagery, observation, source, time, model version and confidence information. Otherwise AI transforms intelligence from an evidentiary process into an answer machine.
The Pentagon Goes AI-First
The institutional language surrounding military AI has changed. Years ago, Pentagon officials spoke about pilots, experiments and narrow use cases.
Today CDAO describes its mission as putting AI tools into the hands of warfighters at speed and scale. The Department’s current AI portfolio includes the Maven Smart System, an Agent Network for AI-enabled battle management and decision support, simulation programs, intelligence-to-capability pipelines, GenAI.mil and enterprise-agent development.
GenAI.mil illustrates the change from specialist tool to general infrastructure. CDAO says the platform provides Department-wide access to frontier generative-AI models at protected impact levels. By June 2026, CDAO said more than 1.6 million personnel had used the platform, generating tens of millions of prompts and deploying hundreds of thousands of AI agents.
Those numbers are Department claims and tell us more about institutional adoption than about mission effectiveness. But that is enough to make the larger point.
Military AI is no longer confined to data scientists. It is moving onto ordinary desks.
The June 2026 national-security AI memorandum accelerates that transition. It directs military and intelligence agencies to review procurement, onboard advanced models from multiple vendors, build secure compute infrastructure, establish cross-agency model and data exchanges, expand AI training and develop standardized testing and assurance. That is the administrative infrastructure of an AI-native national-security system.
Frontier Models Enter National Security
The first generation of military AI was dominated by specialized models. A computer-vision model detected a particular object.
A predictive-maintenance system estimated component failure. A logistics model optimized routing.
Frontier foundation models change that pattern because one model can perform many cognitive tasks through language, images, code and tools. CDAO moved aggressively in that direction in 2025 when it announced contracts with Anthropic, Google, OpenAI and xAI, each with a ceiling of $200 million, to develop agentic AI workflows for national-security missions.
The stated use cases include command and control, operational planning, logistics, weapons development and testing, uncrewed systems, intelligence, information operations and cyber operations. This does not mean a commercial chatbot is commanding weapons.
It means the Pentagon sees frontier models as general-purpose cognitive infrastructure. The appeal is understandable.
One model can summarize reports, generate code, search policy, translate foreign-language material, query databases, reason across documents and orchestrate tools. Agentic systems add another step: the model can call software, retrieve information and execute bounded workflows.
That makes the same technology useful in a headquarters, intelligence cell, logistics office and cyber operations center. It also makes the security problem much larger.
CIA and the Digital Intelligence Service
Public information about CIA operational AI is necessarily limited. That limitation should be respected rather than filled with speculation.
What the Agency does say publicly is revealing enough. CIA’s Directorate of Digital Innovation brings together information technology, data, artificial intelligence, cyber collection, cyber defense and open-source intelligence. The directorate was created in 2015 because the Agency concluded that digital technology had changed both the intelligence target and intelligence tradecraft.
That integrated structure matters.
Artificial intelligence in an intelligence agency is not merely an analytic product. It sits beside cyber capabilities, collection, data engineering and operational security.
CIA’s own professional journal, Studies in Intelligence, has increasingly examined AI’s effects on the profession. A 2026 essay on human intelligence argues that frontier AI is already changing the environment in which clandestine officers work and raises the possibility that AI-assisted surveillance, identity analysis and digital traces could make traditional tradecraft harder.
Another 2026 issue devoted multiple articles to generative AI and intelligence cognition. The important conclusion is modest but substantial:
AI changes both sides of espionage. It helps intelligence services search and synthesize information. It also helps counterintelligence services find patterns in the digital exhaust people leave behind.
NSA: AI as Capability and Attack Surface
The National Security Agency sees AI through two lenses simultaneously. One is opportunity.
The other is attack surface.
The NSA Artificial Intelligence Security Center says its mission is to promote secure AI development and adoption across National Security Systems and the Defense Industrial Base. Its definition of AI security reaches across training data, frameworks, models, model capabilities and the machine-learning lifecycle.
This framing is important.
When a military organization deploys an AI model, it has not merely installed software. It has created a new chain of dependencies:
TRAINING DATA
│
▼
MODEL WEIGHTS
│
▼
SYSTEM PROMPT / POLICY
│
▼
RETRIEVAL DATA
│
▼
TOOLS / APIS / MCP
│
▼
IDENTITY + CREDENTIALS
│
▼
AGENT ACTION
│
▼
MISSION SYSTEM
ATTACKS CAN TARGET:
data • model • prompt • tool • identity • supply chain • output
NSA’s 2026 guidance on agentic AI warns that agents inherit the risks of language models while adding complexity and a larger attack surface because they can interact with tools and services. Its separate guidance on the Model Context Protocol focuses on exactly this problem: once AI systems can call databases, services and automation tools, security must govern not only what the model says but what the model can do.
This directly echoes the problem identified earlier in the Critical Technology Stack’s Article 003: identity, authorization, delegation and accountability become more important as autonomy increases. In a national-security environment the stakes are much higher.
A prompt injection that produces a bad summary is inconvenient. A manipulated agent with access to a mission system is a security event.
Machine-Speed Cyber Operations
Cyber conflict may be the domain where AI speed matters first. Code is already machine-readable.
Networks already operate at machine speed. Vulnerability discovery, malware analysis, log inspection, phishing detection and incident response all involve information volumes that exceed human attention.
In June, the Five Eyes cybersecurity agencies issued an unusually urgent statement saying frontier AI is changing both offensive and defensive cyber capability and warning that the relevant timeline is measured in months rather than years. That does not prove an autonomous cyberwar is imminent.
It does indicate that agencies responsible for defending some of the world’s most sensitive networks believe assumptions can become obsolete quickly. The contest is symmetrical.
Defenders can use AI to examine logs, discover suspicious behavior, generate detection rules, analyze malicious code and help operators investigate incidents. Attackers can use AI to scale reconnaissance, adapt social engineering, analyze code, search for weaknesses and automate portions of intrusion workflows.
The result is likely to be a cyber battlefield where humans increasingly supervise machines fighting other machines. The control problem is familiar:
How much authority should a defensive agent possess? May it isolate a host?
Revoke credentials?
Block network traffic?
Alter a firewall?
Patch a system?
Launch an active response? Every step upward in authority creates faster defense and a larger blast radius if the agent is wrong or compromised.
From Decision Support to Command Architecture
The military value of AI is often described as “decision advantage.” The phrase sounds abstract. In practice it means seeing something sooner, understanding it faster, generating options more quickly and acting before the opponent completes the same cycle.
This turns AI into part of command architecture. The Maven Smart System already fuses sensor and intelligence data into workflows used for target identification and strike approval. CDAO’s current portfolio describes an Agent Network aimed at AI-enabled battle management and decision support from campaign planning through kill-chain execution.
The Pentagon’s earlier CJADC2 work pursued the same objective without requiring generative AI: connect sensors and decision makers across services and domains. Frontier models and agents make that architecture more conversational and more automated.
A commander may eventually interact with a complex operational data environment by asking: What changed? Which observations are corroborated?
Which units are at risk?
What collection gaps remain?
What logistics constraint will bind first? Which course of action conflicts with current rules?
The danger is obvious.
A fluent answer can feel authoritative even when its evidentiary foundation is weak. Military AI therefore needs something ordinary consumer AI often lacks:
traceable reasoning inputs. The user must be able to move from answer to evidence.
Autonomous Weapons: The Language Matters
Public debate often collapses several different technologies into the phrase autonomous weapon. That creates confusion.
A drone can autonomously hold altitude without autonomously selecting a target. A missile can autonomously navigate toward designated coordinates without autonomously deciding whom to attack.
A defensive system can automatically respond to incoming threats inside tightly defined parameters. A reconnaissance platform can autonomously choose a route while leaving every use-of-force decision to humans. These are different allocations of authority.
| Function | Possible machine role | Authority question |
|---|---|---|
| Navigation | Choose route / avoid obstacle | Where may the platform go? |
| Sensor management | Point camera / radar / collector | What may be collected? |
| Detection | Find objects or signals | How are false positives handled? |
| Classification | Assign probable object type | What confidence is sufficient? |
| Tracking | Maintain object track | When is identity considered lost? |
| Target recommendation | Prioritize potential targets | Who validates military objective and context? |
| Engagement planning | Recommend weapon / timing / geometry | Who approves the plan? |
| Weapons release | Execute force | What human judgment is required? |
DoD Directive 3000.09 remains the foundational public policy for autonomy in weapon systems. It requires autonomous and semi-autonomous systems to be designed so commanders and operators can exercise appropriate levels of human judgment over the use of force. It also requires realistic testing, understandable human-machine interfaces and compliance with the law of war, rules of engagement and other applicable requirements.
The phrase appropriate levels is deliberate. Congressional Research Service analysis notes that the policy does not require the same form of manual control in every case. Human judgment can include decisions about when, where, why and under what constraints a weapon operates.
That nuance is essential.
The meaningful policy question is not whether a human touches every control. It is whether humans retain genuine authority over the conditions under which lethal force is used. The June 2026 national-security AI memorandum directs the Department to update Directive 3000.09 and review it annually, reflecting how quickly the underlying technology is changing.
What Does Human Judgment Actually Mean?
There is a difference between a human being present and a human being meaningfully in control. Imagine a system that produces a target recommendation in three seconds.
The operator has ten seconds to approve it. The evidence consists of several machine-generated detections, an automated confidence score and a summarized intelligence report.
Technically, the human decides.
Practically, the human may be validating a machine conclusion he has no time to reconstruct. This is automation bias: the tendency to over-trust automated recommendations, especially when the system is normally correct and the human is overloaded.
Military environments amplify the problem because time pressure is real. Incoming threats move.
Targets disappear.
Adversaries jam networks.
Communications degrade.
Operators are tired.
Information is incomplete. The appropriate human-control question therefore has at least four dimensions:
Authority
Does the human possess the legal and operational authority to reject the recommendation?
Information
Can the human inspect the underlying evidence, provenance, uncertainty and competing interpretations?
Time
Is there enough time to exercise judgment rather than merely acknowledge the system?
Control
Can the human pause, redirect, revoke or abort the machine’s action?
If any of those disappear, “human in the loop” can become ceremonial. This point matters because the technology should be evaluated as part of the surrounding system rather than as an isolated claim or capability.
The Danger of Compressed Time
Military organizations have always sought to shorten decision cycles. AI changes the scale.
Computer vision can inspect imagery faster than teams of analysts. Automated correlation can combine sensor tracks instantly.
Language models can summarize reports in seconds. Agents can call tools without waiting for a person to manually move data between systems.
This can improve precision.
More information can be checked before acting. But speed can also produce escalation pressure.
If one military believes the other can detect and strike targets rapidly, it may feel pressure to delegate more authority to machines simply to remain competitive. That creates what might be called an automation tempo trap:
SIDE A AUTOMATES
│
▼
DECISION CYCLE SHORTENS
│
▼
SIDE B FEARS FALLING BEHIND
│
▼
SIDE B AUTOMATES MORE
│
▼
HUMAN REVIEW TIME SHRINKS
│
▼
MISTAKE / MISCLASSIFICATION RISK
│
▼
PRESSURE FOR EVEN FASTER RESPONSE
The danger is greatest when uncertainty and speed increase together. A defensive system responding to a known incoming missile may operate under very different assumptions from an AI model classifying ambiguous human behavior in a crowded environment.
The more ambiguous the target and the larger the consequences, the more valuable deliberate human judgment becomes. The strategic problem is that deliberate judgment consumes the very resource AI promises to save:
time.
The Private-Company Dependency
Military AI is being built during an unusual period in technological history. Many of the world’s most capable general-purpose models are not government systems.
They are commercial products developed by private companies. The Pentagon wants access to that innovation rather than trying to reproduce the entire frontier-model industry internally. Its multi-vendor contracting strategy reflects that logic.
But 2026 exposed the strategic downside. A dispute between the Pentagon and Anthropic over safety guardrails and acceptable military uses led the government to move away from the company. Reuters subsequently reported that parts of Palantir’s Maven workflows had been built around Anthropic’s Claude, forcing replacement work inside a strategically important military system.
The details of the dispute are political and legal as well as technical. The larger architectural lesson is durable.
A mission system is not sovereign if a private model provider can become an irreplaceable dependency. The White House’s June memorandum addresses this directly. It directs the national-security enterprise to use diverse suppliers and states that commercial entities should not possess the ability to prevent use of, disable, degrade or materially modify mission-dependent AI systems without government knowledge and approval.
This is not an argument for government-built models only. It is an argument for replaceability.
Decision Sovereignty
Article 007 introduced semiconductor sovereignty: the ability to preserve enough of the chip supply chain that no external chokepoint can switch off a nation’s technological future. Military AI creates an analogous concept.
Decision sovereignty is the ability of a state to retain control over the systems that shape high-consequence decisions even when underlying analytical components come from commercial providers. A sovereign military AI architecture should be able to replace one foundation model with another without rebuilding the entire command system.
It should keep identity, permissions and action authorization outside the model. It should preserve government-controlled logs.
It should retain evidence provenance. It should define rules and escalation pathways independently of vendor policy.
It should survive loss of network access to one provider. And the final authority for force should remain in the lawful chain of command.
COMMERCIAL / GOVERNMENT MODELS
Model A • Model B • Specialized Models
│
▼
SOVEREIGN ORCHESTRATION LAYER
│
├── identity
├── permissions
├── policy
├── provenance
├── audit logging
├── model routing
├── fallback
└── escalation
│
▼
HUMAN COMMAND AUTHORITY
│
▼
AUTHORIZED MISSION SYSTEM
MODEL IS REPLACEABLE
AUTHORITY IS NOT
The SURVXCOM Machine Warfare Authority Test
The most useful way to evaluate a military AI system is not to ask whether it contains “AI.” Ask where authority actually moves. This point matters because the technology should be evaluated as part of the surrounding system rather than as an isolated claim or capability.
1. Sensor
What generated the underlying information, and how reliable is that sensor under current conditions?
2. Identification
What did the AI identify or classify, and what alternative classifications remain plausible?
3. Confidence
How certain is the model, and is the confidence meaningful under this operational environment?
4. Provenance
Can the analyst trace the conclusion back to source imagery, signals, reports, model version and time?
5. Fusion
What independent intelligence sources corroborate or contradict the machine finding?
6. Recommendation
Is AI merely organizing evidence, or is it recommending a military action?
7. Authority
Who possesses the legal and operational authority to approve the action?
8. Human Gate
Is meaningful human approval required before a high-consequence action proceeds?
9. Time Pressure
How much time does the human actually have to inspect evidence and disagree?
10. Autonomy
What can the system do after approval without returning for further authorization?
11. Abort / Revocation
Can a human stop, redirect or revoke the process if conditions change?
12. Accountability
Who is responsible when the system is wrong—the operator, commander, developer, model provider, agency or some combination?
The question is not whether a human appears somewhere in the loop. The question is whether the human still possesses enough evidence, time and authority to make the decision meaningful.
What to Watch Next
1. The Updated Autonomy Directive
The June national-security AI memorandum orders an update to DoD Directive 3000.09. Watch whether definitions of human judgment, autonomous functions, testing and approval change.
2. Maven as a Program of Record
Watch how Maven Smart System procurement, governance and service integration change as it becomes permanent command-and-control infrastructure.
3. NGA Collection Orchestration
Watch how much authority machine systems receive to recommend or prioritize which sensors collect which targets and when.
4. GEOINT Model Accreditation
Watch NGA’s efforts to certify AI models and build responsible-use training. The reliability of military AI depends on mission-specific testing, not general benchmark scores.
5. Multi-Vendor Frontier Models
Watch whether the Pentagon can genuinely move workloads among frontier-model providers or whether mission software becomes tightly coupled to individual vendors.
6. GenAI.mil Agents
Watch the difference between enterprise productivity agents and agents with access to operational tools. Tool authority will matter more than conversational capability.
7. NSA AI Security Guidance
Watch AI red-team methods, model security, MCP security, agentic controls and national-security-system assurance standards.
8. CIA Digital Tradecraft
Watch public evidence on how AI changes open-source intelligence, counterintelligence, digital identity and clandestine tradecraft without inferring classified capabilities.
9. Autonomous Collaborative Systems
Watch autonomy in aircraft, maritime systems and drone teams while separating navigation and teaming from lethal target authority.
10. Automation Bias
Watch whether testing measures operator disagreement rates, evidence inspection, calibration and decision time rather than merely model accuracy.
11. Battle Damage and Feedback
Watch how automated assessment feeds future targeting. Feedback loops can improve models but can also reinforce errors if the original classification was wrong.
12. Decision Sovereignty
Watch whether identity, policy, logging, authorization and model routing remain under government control even when commercial AI models supply analysis.
The Machine-Speed Battlefield
The popular image of artificial intelligence at war is a robot deciding whom to kill. That image is dramatic.
It may also distract from the more immediate transformation. The battlefield is becoming a network in which machines increasingly determine what humans can see, what they notice first, how quickly evidence is fused and how rapidly options reach command.
The satellite takes the image.
The model finds the object.
The system compares behavior.
The network fuses the track.
The agent retrieves supporting reports. The command platform displays the option.
The human decides.
That final line remains essential.
But every line above it is changing. And if those systems reduce hours to minutes and minutes to seconds, then the human decision itself changes because it takes place inside a machine-shaped information environment moving at machine-shaped speed.
This is why military AI cannot be governed only at the trigger. Governance has to begin at the sensor.
It has to include data provenance, model validation, identity, permissions, auditability, cybersecurity, collection policy, vendor dependence and command authority. Artificial intelligence may make military operations faster.
It may make some operations more precise. It may make intelligence systems capable of processing information no human workforce could absorb.
It may also make errors travel farther and faster. The central challenge is therefore not choosing between artificial intelligence and human judgment.
It is designing systems in which artificial intelligence expands what humans can know without quietly replacing what humans are responsible to decide. Machine speed can create military advantage. Human accountability must remain faster than the temptation to surrender it.
Related SURVXCOM Reading
- SURVXCOM Disclosure Hub — government evidence, sensors, public trust and disciplined interpretation.
- The Disclosure Test — separating evidence, institutional claims and interpretation.
- No Other Gospel From the Skies — discernment guardrails where emerging technology intersects belief and deception.
- Bible Prophecy Hub — link only where surveillance, authority or technological power genuinely intersects the theological stack.
Critical Technology Hub & Reading Path
Start with the hub: SURVXCOM Critical Technology Hub. This article is part of SURVXCOM’s 30-piece cornerstone tree explaining the systems beneath technological power. Primary lane: Defense, Autonomy & Physical Systems.
Continue in the Critical Technology Stack
- The Autonomous Swarm: Drones, Collaborative Systems and Warfare Without One Pilot Per Machine
- Hypersonics and Directed Energy: The Technologies Trying to Change Missile Defense
- AI on Trial: Intent, Fault, Liability and the Law of Autonomous Machines
- Sovereign AI: Chips, Power, Data Centers, Models and the Fight for National Technological Control
Across the SURVXCOM Ecosystem
Related SURVXCOM lanes: Current Signal — Timely technology shifts and current-event analysis. Disclosure Hub — Public trust, sensor evidence, UAP files and disciplined interpretation.
Primary Research and External Sources
- White House — National Security Presidential Memorandum 11, Artificial Intelligence in the National Security Enterprise. Current overarching U.S. policy on national-security AI adoption, assurance, accountability, compute, procurement and autonomy guidance.
- White House — NSPM-12, Cybersecurity of National Security Systems. Current governance context for military and intelligence cyber systems.
- Chief Digital and Artificial Intelligence Office — Current Programs. Primary source for Maven Smart System, Agent Network, GenAI.mil and current pace-setting projects.
- CDAO — AI Rapid Capabilities Cell. Primary source for warfighting and enterprise GenAI use cases.
- CDAO — Frontier AI Company Partnerships. Primary source for Anthropic, Google, OpenAI and xAI contract ceilings and agentic mission areas.
- CDAO — GenAI.mil Adoption. Primary source for current Department-wide usage claims and enterprise AI integration.
- NGA — GEOINT Artificial Intelligence. Primary source for Maven, ASPEN, collection orchestration, AI objectives and responsible-AI training.
- NGA — Congressional Testimony on National Security Space Programs. Primary source for Maven scale, users and reported targeting-workflow reductions.
- NGA — GAMBLER Tactical Edge AI Test. Primary evidence for AI-enabled object detection and dissemination in communications-challenged environments.
- NGA — GEOINT AI Model Accreditation Pilot. Primary source for model accreditation and responsible-AI training.
- NSA — Artificial Intelligence Security Center. Primary source defining AI security across data, models and AI lifecycles.
- NSA — Careful Adoption of Agentic AI Services. Primary security guidance on agentic AI attack surfaces.
- NSA — Model Context Protocol Security Design Considerations. Primary guidance on AI tools, services and automation.
- NSA / Five Eyes — Frontier AI and Cyber Risk Statement. Current source for offensive and defensive cyber acceleration.
- CIA — Directorate of Digital Innovation. Primary public description of CIA AI, cyber, data and open-source intelligence integration.
- CIA — Intelligence in a Digital World. Public institutional history and digital-intelligence context.
- CIA Studies in Intelligence — Espionage in Our AI Future. Professional discussion of AI and human intelligence; author views are not official CIA policy.
- Department of Defense — Directive 3000.09, Autonomy in Weapon Systems. Primary public policy on human judgment, testing and autonomous weapons.
- Congressional Research Service — U.S. Policy on Lethal Autonomous Weapon Systems. Independent legislative analysis clarifying “appropriate levels of human judgment.”
- DoD — Maven Smart System and Battlefield Decision Support. Primary description of sensor fusion, target identification and approval workflows.
- DoD Contracts — Maven Smart System Modification. Primary procurement evidence for Maven expansion.
- Reuters — Anthropic / Pentagon / Maven Dependency. Independent reporting on commercial-model entanglement and vendor replacement risk.
- Reuters — Maven to Become Core Pentagon Program. Independent reporting on institutionalization of Maven as a program of record.
- Wei & Shu — Preserving Decision Sovereignty in Military AI. Academic conceptual framework on model replaceability and sovereign control.
- Kruus et al. — Governing Automated Strategic Intelligence. Academic work on foundation models and automated intelligence analysis.
- Khlaaf, Myers West & Whittaker — Foundation Models and Military ISTAR. Critical academic perspective on foundation-model proliferation, targeting and attack surfaces.
- Associated Press — U.S. National-Security AI Policy. Independent reporting on accelerated adoption, autonomy and civil-liberties debates.
Source discipline: Public descriptions of Maven, GenAI.mil, NGA AI and CIA digital capabilities are not extended into claims about classified operations. Agency-reported user counts, workflow reductions and model performance remain attributed. Commercial frontier-model contracts establish access and intended use cases, not proof that those models control weapons. The Anthropic-Pentagon dispute is used as a vendor-dependency case study, not as evidence about classified system architecture. Autonomous navigation, sensing and target support are kept distinct from autonomous lethal decision-making. DoD’s phrase “appropriate levels of human judgment” is used rather than the misleading shorthand that every autonomous military function must always be manually controlled in real time.
