PART TWO OF TEN: THE WEAPONIZATION OF AI
Part one asked who chooses the target. This one asks who built the thing that chooses. The answer is a supply chain that no single authority controls, and as of this month it no longer stops at hardware.

Source: Jordan Harrison (Unsplash)
On 14 August, Ukraine’s Main Directorate of Intelligence said it had recovered an Nvidia Jetson Orin NX module, a 16 gigabyte board carrying the part number TE980M-A1, from the wreckage of a Russian S-71M Monochrome cruise missile. Nvidia’s response was measured and, on its own terms, accurate. The modules are consumer products sold to students, developers and start-ups, they are not available in Russia, they are not designed for military purposes, and if a customer is found violating United States export controls the company will act.
01 The Half of the Problem We Already Knew
Every sentence in that statement can be true while the board still ends up in a cruise missile. That is the shape of the dual-use problem, and it is well documented. Jetson modules have now been identified in at least four Russian weapon families. The entry-level board sells from around USD 249.
The scale is larger than the headlines suggest. CSIS assessed in April that more than half of the AI-enabling components in Russian unmanned systems originate with United States companies, including 57 percent of the processors, while Chinese suppliers account for under 9 percent. A separate teardown by the Kyiv School of Economics of 174 foreign components recovered from Shahed-136 and 131, Lancet and Orlan-10 airframes found that 69 percent originate from United States-owned companies.
The uncomfortable detail is that most of this is not smuggling in the cinematic sense. A significant proportion of Western-branded components recovered from Russian drones appear to be genuine commercial products that subsequently entered diversion networks, having changed hands one time too many. They arrive through Turkey, the United Arab Emirates, Armenia, Kazakhstan and China, and are bought in bulk on Chinese e-commerce platforms. Nobody in that chain needs to intend a weapon for a weapon to be the result.
02 And Then the Engineering Was Rented
On 10 September, Anthropic published a 154 page threat intelligence report describing accounts it had banned for misusing its models. One case moves this subject onto new ground.
The actor, designated GTG-27005, called the operation DronDoc, or Serafim. Anthropic assesses it was a small, specialized freelance team doing a mix of civilian and military work, not a Russian state entity, with ties to a regional university carrying a federal research center associated with the Russian Academy of Sciences. The team claimed funding from Russia’s Advanced Research Foundation, the National Technology Initiative and the Ministry of Defence. Anthropic cannot verify those claims.
What the team built, using Claude Code to write and test the software directly into its own project files, was a full-stack autonomous first-person-view kamikaze drone swarm: shared swarm memory and fault-tolerant coordination logic, an onboard small language model governing attack, observe and return-to-base behavior, terminal guidance steering each drone to its target on its onboard camera, a module for geolocating opposing drone operators, and a passive acoustic detection layer. The computer-vision classifier was trained on scraped Ukrainian combat footage, split into enemy and friendly, with Russian systems on an allow list. In the report’s own words, the onboard model could select targets, including a person target class, and issue detonation commands without a human in the loop.
The accounts were opened between late 2025 and early 2026 and the operation began in mid-May. Anthropic identified nine accounts associated with the group and states that eight of them were used only for ordinary freelance work, not weapons development. Geographic access controls were circumvented by routing traffic through commercial virtual private servers, and a rented graphics processing host was used for model training. Anthropic banned the accounts. It rates the systems attempted at technology readiness levels three to four, validated in simulation, though it confirms real hardware-in-the-loop testing: firmware flashed to live development boards, single-board computers provisioned, and a simulation environment wired over a mesh network.
The hardware leaked. The engineering was rented.
That distinction matters more than the individual case. The developer board is a physical object with a part number, a shipping route and a customer of record. The engineering assistance is a subscription bought with a card, reached through a rented server in another country, and consumed in a browser. One can be interdicted at a border. The other has no comparable physical checkpoint and must instead be controlled through access restrictions, behavioral detection and provider enforcement, which is what happened here.

The five layers of an autonomous targeting capability, and what each is subject to. Brasidas Group AG.
03 Why Neither Control Regime Reaches This
Traditional export-control regimes were primarily designed around identifiable goods, technologies and transactions that can be licensed, tracked or intercepted. They work reasonably well on jet engine alloys and beryllium powders. They work poorly on a commodity board that ships by the container to hobbyists on four continents, and they do not reach a login at all.
Access control at the model provider is the nearest equivalent, and it is worth being precise about what it did and did not do. It caught the case, months in, by behavioral detection rather than at the point of sale. It removed one team’s access, not the capability. The report’s own conclusion is the one to take seriously: these capabilities should be assumed available to any actor motivated enough to want them. The same section describes four such operations, including a China-based actor who used the model to build a sixteen-module electronic warfare and air-defense-suppression suite, and who changed the default simulation scenario mid-project to twelve targets in Taiwan.
Anthropic’s report also records a separate Russian espionage operation that bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system. Where renting the engineering is not enough, the alternative is to take somebody else’s.

Commercial shipping remains the route of record for dual-use components. Source: Shutterstock.
04 The Rules Are Arriving at the Speed of Rules
The European Union’s twenty-first sanctions package, adopted on 23 July, is a serious instrument. It carries 218 listings, of which 37 are tied directly to long-range drone production and its supply chains, adds 51 entities to dual-use export restrictions, and extends controls to aviation items specific to unmanned aerial vehicles and to further microelectronics. The twentieth package landed in April. In June the United States House passed a bill aimed at Western technology reaching Iranian drones.
Note where those 51 entities sit: China, Hong Kong, India, Kazakhstan, Kyrgyzstan, Turkey and the United Arab Emirates. That list closely reflects jurisdictions repeatedly identified in documented diversion routes. Enforcement is also real, and also retrospective, running to guilty pleas for shipping dual-use electronics to Russian end users through front companies and falsified paperwork.
Sanctions describe the route that was used. Procurement networks are already on the next one.
This is not an argument against sanctions. It is an argument about what they can be expected to deliver, and about who carries the residual risk when they do not. That burden lands on companies.

Where verifiable visibility ends, and where the exposure continues. Brasidas Group AG.
05 What This Means If You Make, Move or Fund Components
For manufacturers and distributors, the obligation is shifting from screening the buyer to understanding the onward path. When a significant proportion of the parts recovered from weapons were sold legally, a clean name-against-list check is no longer sufficient evidence of low diversion risk. The practical questions are unglamorous. Who are your ten largest distributors by volume in higher-risk jurisdictions, who do they sell to, what proportion of your output goes to customers you have never met, and can you demonstrate any of this to a regulator after the fact.
For investors and boards, a component turning up in a munition is a reputational and regulatory event rather than a technical one, and it arrives without warning through a portfolio company’s third-tier reseller. Ownership mapping is the control that actually helps here. Under the United States OFAC 50 Percent Rule, entities owned 50 percent or more, directly or indirectly, by blocked persons may themselves be treated as blocked. European Union and United Kingdom regimes additionally apply ownership-and-control tests that can capture entities where a designated person exercises control or dominant influence despite holding less than a majority interest. Nominee directors, co-location with designated entities, payments from unrelated third countries and multiple freight forwarders on a single transaction are the recurring signatures.
For insurers and litigators, this compounds the evidentiary problem we raised in part one. A board is sold legally, resold twice through jurisdictions with thin oversight, installed in a weapon, and recovered from a crater. Establishing who knew what, and when, requires records that most intermediaries in that chain never kept.
And for anyone buying enterprise AI, the GTG-27005 case is a useful mirror. A small team, commercially available services and rented compute were sufficient to develop lethal autonomy in software. Your own access controls, on your own model deployments, are a control surface of the same type, and misuse may emerge in the same way: not at signup, but months later, visible only in behavior.
06 Our Assessment
The capability stack for autonomous targeting is now commercial from end to end. The sensor is a camera module. The compute is a developer board. The model is a subscription. The training data is scraped video of somebody else’s war. The engineering help is metered by the token. Every layer has a civilian purpose, a civilian price and a civilian customer base, and no layer was designed for this.
What remains outside the control regime is intent, and intent is not exportable, licensable or detectable at a border.
Two things follow for our clients. First, diligence on dual-use exposure has to look past the counterparty to the network behind it, because that is where the risk actually sits and it is not visible from a screening list. Second, the assumption that sophisticated autonomy requires a sophisticated sponsor is no longer safe. On the record now published, it required a small freelance engineering team, commercially accessible AI services, rented compute and university-linked technical expertise.
We would watch for one specific development. In part one the question was whether a weapon chose its own target. The next question is whether the software that made that choice was written by anyone inside the program that fielded it.