PART ONE OF TEN: THE WEAPONIZATION OF AI
A strike near a Zaporizhzhia gas station has moved autonomous targeting out of the seminar room and into the evidence file. The question may no longer be whether machines will select their own targets. It is how far along that path we already are, and how little of it is governed.

Source: AI generated
On 6 July 2026, three people were killed at a gas station in Zaporizhzhia, roughly fifteen kilometers from the front line. Tetiana Bubynets was nineteen and studying accounting. Oleksii Svirin was forty-one. Roman Karpii was forty-eight. Nothing about the weapon, the location or the casualty count set this strike apart. What set it apart was what Ukrainian investigators found in the wreckage.
01 What the Wreckage Showed
According to reporting by The New York Times on 24 August, corroborated by Ukrainian officials and forensic examiners, the aircraft was a Russian Molniya, a mass-produced foam-and-plywood strike drone that costs between a few hundred and a few thousand dollars. Inside it was an NVIDIA Jetson Orin module, a consumer-grade computing board designed for robotics and machine vision students, sold for around USD 249. The module was not encrypted. Investigators could therefore read what was on it: terrain imagery for visual navigation, and object-detection code trained to recognize a specific class of object. The most likely class, based on the code and the strike pattern, was propane tanks.
The available evidence suggests that human operators sent the drone toward a general area, after which the machine selected what to hit within it. If that interpretation is correct, the significance is difficult to overstate. The human role would have shifted from selecting the target to defining the area in which a machine may select one. Ukrainian analysts also noted the absence of radio antennas on recovered airframes and observed formations flying without active transmissions, consistent with weapons that do not require an operator once launched.

A fixed-wing unmanned aircraft in flight. Source: Ma Ti (Unsplash)
Jetson modules have now been recovered from at least four Russian weapon families, including the V2U loitering munition, the Shahed MS001, and the S-71M. NVIDIA has said the modules are consumer products sold to students, developers, and start-ups, that they are not sold in Russia, and that they are not designed for military use. Both statements can be true at once, which is precisely the problem. That subject deserves its own treatment, and it will receive one later in this series.
One Ukrainian officer, Colonel Serhiy Minaiev, put it plainly to the Times: in a few years, he said, we will be living in a Terminator movie. Our reading is less cinematic and more uncomfortable. If the forensic assessment is correct, the relevant threshold is not several years away. It may already have been crossed.
02 The Distinction That Actually Matters
Thousands of weapons in service today use artificial intelligence in some form. Very few of them are autonomous in any meaningful sense, and the difference is worth stating carefully, because it is where most public commentary loses precision.
A remotely piloted drone with image stabilization and automatic tracking is assisted. A loitering munition that locks onto a target a human has already designated is supervised. A weapon that navigates without satellite positioning, identifies candidate objects from learned visual patterns, and then decides which one to strike has moved into a different category.
The human contribution has shifted from choosing the target to choosing the search area.
The Center for Strategic and International Studies set out this progression in April 2026 in an assessment of Russia’s drone ecosystem by Kateryna Bondar. Its central finding is that Russia is not pursuing general autonomy at all. It is pursuing what the report calls functional independence at the tactical edge: narrow, cheap, specific AI functions embedded in expendable platforms so they keep working when jamming, spoofing, and broken communications would otherwise stop them. The report places the Lancet at supervised autonomy with a human in the loop, the Molniya at functional independence with AI-enabled terminal guidance, and the V2U at full autonomy, with a range of forty to sixty kilometers, no components for operator control, and observed independent target selection.
Scale matters here as much as capability. CSIS records around 2,200 Molniya launches in a single month in late 2025, against roughly 400 Lancets. A Lancet costs about USD 50,000. A Molniya costs a few hundred to a few thousand. The systems moving fastest toward autonomy are the cheap ones, and the cheap ones are the ones fielded in volume.
03 The Line Was Never Bright
It is tempting to treat Zaporizhzhia as a rupture. It is better understood as a threshold that had been approached for years.
Close-in weapon systems on warships have engaged incoming threats faster than human reaction time since the 1980s, under human supervision but not human decision. In 2021, a United Nations Panel of Experts reported that loitering munitions used in Libya had been programmed to attack without requiring data connectivity between operator and munition, which the panel described as a fire, forget, and find capability. Ukraine, by its own account, tests comparable AI targeting, and in August it gave British researchers access to its Avengers AI Labs and a dataset of some five million annotated battlefield images.
So the honest position is not that one side built a killer robot while the other did not. Autonomy has been arriving in increments for a decade, from both directions, and the increments have now added up to something that kills without a human choosing the object struck.
04 The Cheapest Counter to the Most Expensive Idea
The defensive response tells its own story. Zaporizhzhia is now shielded by roughly 386 kilometers of anti-drone netting. More revealing, gas stations in the city have begun fixing angled plastic sheeting around their propane tanks, on the theory that a machine trained on shapes can be shown the wrong shape.
There is a lesson in that for anyone responsible for protecting physical assets. When a weapon’s judgment is a trained model rather than a human eye, the model becomes part of the attack surface. Camouflage stops being about concealment and starts being about misclassification. For corporate security teams, that changes the defensive question: protecting an asset may increasingly require understanding not only how an adversary sees it, but how a machine classifies it. Cheap physical deception may prove to be a serious counter to expensive machine perception, at least until the models are retrained. That contest deserves its own analysis, and it will get one.
05 Governance Is Now Measurably Behind
In October 2023, the UN Secretary-General and the President of the International Committee of the Red Cross jointly called on states to conclude negotiations on a binding instrument covering autonomous weapons by 2026. That deadline has arrived without a negotiation.
The Group of Governmental Experts under the Convention on Certain Conventional Weapons held its final session under the current mandate in early September. Seventy-six states now support the agreed elements text as a basis for negotiations. Around twelve are explicitly opposed, among them Russia, the United States, and Israel, and consensus rules give that minority decisive weight. The next decision falls to the Seventh Review Conference in November.
The result is a widening gap between capability and governance. Autonomous systems are evolving in months, while the framework intended to govern them remains subject to years-long negotiation and consensus rules. Existing instruments would not reach this case in any event. Neither the prohibitions the ICRC proposes nor the appropriate levels of human judgment required under United States policy bind a state that declines to be bound, and none of them applies to a component sold to a robotics student for a few hundred dollars.

An armed MQ-1 Predator, an earlier generation of remotely piloted strike aircraft. Source: Smithsonian (Unsplash, public domain)
06 Our Assessment
Brasidas Group listed autonomous AI war machines as an X-factor in 2025, on the reasoning that the enabling technology was commercially available and the doctrinal restraint was thin. On the evidence now in the public record, that item no longer belongs on an X-factor list. It belongs in the baseline.
For companies operating across conflict-affected, politically exposed, or strategically important markets, three conclusions follow.
First, attribution becomes harder. A weapon that selects its own target degrades the assumption that every strike reflects a decision someone made and can be held to. For insurers, investigators, and litigators, this complicates the evidentiary chain between intent, action, and outcome: who selected the target, on what basis, and where does responsibility sit when the final selection was made by a model?
Second, the enabling supply chain is civilian and largely Western. CSIS assessed that more than half of the AI-enabling components in Russian systems originate with United States companies, including a majority of the processors. That creates a due diligence problem as much as an export control problem. Manufacturers, distributors, and investors may increasingly need to understand not only who buys dual-use technology, but where it can travel after the first legitimate sale.
Third, autonomous targeting is becoming cheap. A capability that once required a state laboratory now requires a commercial board, an open model, and a few hundred dollars.
Capability that becomes cheap does not stay on the battlefield.
Ports, refineries, data centers, substations, and the people who run them sit in the eventual line of sight. For organizations responsible for critical infrastructure, executive protection, and high-value physical assets, autonomous targeting therefore belongs increasingly in scenario planning rather than science fiction.
None of this requires a machine to become intelligent. It only requires a machine to become adequate, and adequate is now available at consumer prices. That is the shift organizations should be planning for now, and it is the thread we will follow across the nine pieces that follow.
Next in this series: the few-hundred-dollar brain inside a killer drone, and what it says about controlling dual-use technology once it enters global distribution.