In April 2026 the Pentagon quietly approved changes to its joint targeting doctrine, including “systems where AI initiates actions with human monitoring,” an evolution from today’s “human in the loop” systems. That sentence ends the assumption that a human always pulls the trigger.
The change turns “who is accountable when AI picks the target?” into an operational question about what changed, why the rules are contested, and what is already deployed. For context, see the cluster overview on defence tech.
How does the Pentagon’s updated targeting doctrine change the human role in a strike?
The doctrine moves the human from initiating strikes to monitoring AI-initiated ones. Instead of approving each engagement in advance, a commander supervises AI-generated target recommendations, watches the environment for civilians and holds veto authority at machine speed, where the window can be seconds.
The shift comes from the text, reported by Bloomberg on 25 June 2026. Approved in April without disclosure, it has not been released; only the 2018 edition is public. The motive is to compress the sensor-to-shooter cycle and “increase the tempo of operations,” so the human initiator becomes the bottleneck, and the human becomes an auditor.
Monitoring is active work. In the jargon, it is the move from human-in-the-loop to human-on-the-loop. Craig Douglas Albert, writing in War on the Rocks, describes supervising AI-generated target recommendations, watching real-time environment changes such as a target suddenly ringed by civilians, and better collateral damage assessment.
The doctrine’s caveats are telling. It concedes AI “poses serious moral and legal dilemmas” yet supplies no ethical guidelines, and warns against “over-reliance on AI output without human oversight.” Its civilian harm mitigation content arrived weeks after the Pentagon announced an investigation into a school strike in Minab that reportedly killed 120 children.
Accountability has relocated: if the AI initiates and the human monitors, responsibility turns on whether the monitor can realistically see, veto and answer for a bad recommendation in time.
Why is DoD Directive 3000.09 too vague to govern autonomous weapons, and what should “meaningful human control” mean?
DoD Directive 3000.09 requires “appropriate levels of human judgment” over the use of force but never defines it, so it cannot discipline systems that act faster than humans can. Meaningful human control, backed by the ICRC and the UN, would instead require a human who can understand, veto and answer for each use of force.
First issued in 2012 by then-Deputy Secretary of Defense Ash Carter and updated in 2023, the directive makes senior officials review whether autonomous and semi-autonomous weapon systems let commanders and operators exercise “appropriate levels of human judgment”, alongside testing, geographic limits, termination and robustness to adversarial manipulation.
“Appropriate” does the heavy lifting. Albert argues oversight means little when the humans are mechanically rubber-stamping approval under time pressure, and the directive’s weapon-system focus misses that AI risk runs across the kill chain; an early error is difficult to spot.
DoD Instruction 3000.17 covers civilian harm mitigation. National Security Presidential Memorandum 11, signed 5 June 2026, orders a 90-day rewrite of 3000.09 with annual reviews, reversing several Biden-era oversight requirements. Senator Ruben Gallego has pressed the Secretary of Defense over friendly-fire and civilian-harm risks, copying the Defense Autonomous Warfare Group.
Meaningful human control names the goal but not the route. Black-box systems and machine-speed warfare make it hard to keep such a human in the loop, which is why the Pentagon avoids the phrase. The next time you hear “human in the loop” offered as reassurance, ask what that person can actually see before they have to answer.
Why are autonomous systems already deployed in Ukraine and other active combat zones?
Autonomous systems are in combat because electronic warfare severs the remote-control links drones depend on, so onboard autonomy becomes the only way to strike at scale.
Ukraine is the live laboratory. Russian jamming breaks the operator-to-drone connection, so AI-enhanced quadcopters attack without a human in the loop when communications fail. The country launches up to 9,000 drones a day. Around mid-2024, near Chasiv Yar, a swarm reportedly switched to “Terminator mode”, striking targets with no human input. Kyiv denies fielding such systems, and has not confirmed it, but even unconfirmed it signals where practice is heading.
The humanoid form factor has reached the fight. Foundation Future Industries’ Phantom MK-1, the first defence humanoid, counts Eric Trump as an investor and chief strategic adviser. Two Phantoms went to Ukraine in February 2026, backed by $24 million in US contracts. Mike LeBlanc argues there is a moral imperative to send robots to war instead of soldiers, raising the question of who profits from the build-out.
The pattern is broader. In Iran, the Maven Smart System, integrating Anthropic’s Claude, has generated target recommendations at scale, and in Gaza the Lavender system produced AI target lists that operators reportedly approved in about 20 seconds. China and Russia are the accelerant: both pour resources into drone swarms and resist binding rules.
What enforceable guardrails do national-security experts propose for responsible military AI?
National-security experts propose five enforceable guardrails: meaningful human control, auditability and accountability, rigorous testing, legal review, and democratic oversight. They argue Congress should tie authorisation and funding to demonstrated compliance and define the key terms in law, instead of relying on non-binding declarations.
Craig Douglas Albert’s framework is specific: Congress should make authorisation and funding for AI military programmes contingent on the Pentagon demonstrating compliance through mandatory reporting. Meaningful human control should be defined in statute, and violations should carry consequences like suspended funding.
Eli Talbert’s design guardrails add friction where it matters: separate find from engage, so the analyst who surfaces targets is not the commander who authorises lethal action; conceal the AI’s confidence score until the analyst records an initial judgment; require a one-sentence rationale. The goal is to keep the irreversible parts of the kill chain slow.
Against this sits the non-binding track: the Political Declaration on Responsible Military Use of AI and Autonomy has nearly 60 signatories, the REAIM summit process continues, and Pope Leo XIV’s May 2026 encyclical Magnifica Humanitas holds that “it is not permissible to entrust lethal or otherwise irreversible decisions to artificial systems.”
That is also the bridge to the commercial world: state-level guardrails are a different thing from how AI vendors’ guardrail claims stack up.
Put the four moves together and the title question no longer has one answer. The doctrine has moved the human from initiator to monitor, Directive 3000.09 is too vague to govern that shift, autonomous systems are already in the fight, and five enforceable guardrails exist but are not yet law. Accountability now sits across commanders, operators, engineers, vendors and states, answered in the present tense. The question you should be watching is whether those guardrails get codified before the next failure. Where defence technology goes next is the subject of defence technology’s Silicon Valley moment in full.
Frequently Asked Questions
What is the difference between a human “in the loop” and a human “on the loop”?
A human “in the loop” initiates or approves each engagement, while a human “on the loop” monitors an automated process and can intervene without authorising every action. The revised targeting doctrine is precisely that shift: commanders move from initiating strikes to supervising AI-generated target recommendations and holding veto authority at machine speed. The distinction matters because “on the loop” control only works if the monitor can spot a bad recommendation before it becomes a strike.
What counts as an autonomous weapon system under Pentagon rules?
Under Directive 3000.09, an autonomous weapon system, once activated, can select and engage targets without further intervention by an operator. Semi-autonomous systems keep target selection with a human and automate the engagement; the 2023 update also recognised “human-supervised autonomous weapon systems.” The catch is that most of the AI shaping strikes today sits earlier in the kill chain, generating target recommendations, so it falls outside these weapon definitions entirely.
Who is legally responsible if an AI-chosen strike kills civilians?
Responsibility stays with people, because machines cannot be held liable, and a strike does not become lawful because a computer recommended it. The commander who ordered it, the monitor who could have intervened, and those who designed and fielded the system all remain answerable under the law of armed conflict. Commanders in particular stay bound to distinguish civilians and take feasible precautions. The doctrine relocates where judgment happens, not where legal accountability sits.
If the human is only monitoring, can they stop an AI-initiated strike in time?
In principle, yes: the doctrine gives monitors veto authority over engagements. In practice, the window can be seconds, and the monitor reviews a recommendation without full visibility into how the system produced it. Under that pressure, experts warn, monitoring can become mechanical rubber-stamping. That is why proposed safeguards keep the analyst who finds a target separate from the commander who authorises lethal action, slowing only the irreversible parts of the kill chain.
Why has the Pentagon’s revised targeting doctrine not been made public?
The doctrine was approved in April 2026 without public disclosure, and the only version available to read is the outdated 2018 edition. Bloomberg reported the change on 25 June 2026, but the new text has not been released. That secrecy is part of the accountability problem: if the public and Congress cannot read the standard governing AI-initiated strikes, oversight depends on press reporting, congressional letters and leaks rather than on the document itself.
What is the “intention gap” in black-box military AI?
The “intention gap” is the mismatch between what a black-box AI system is doing and what its human monitor can understand. If the system’s logic cannot be inspected, the commander may not realise the machine is about to act until it has acted. That gap is why meaningful human control is hard to operationalise: a person cannot meaningfully answer for a decision they could not foresee. That is why experts insist oversight be paired with auditability and rigorous testing.
Are fully autonomous “killer robots” already operating in combat?
No fully autonomous lethal engagement has been publicly confirmed. The closest known case is the reported mid-2024 “Terminator mode” strike test near Chasiv Yar, in which a small swarm reportedly cut its communications and selected and struck targets without human oversight; that account remains unconfirmed. What is operational today is autonomy born of necessity: drones in Ukraine that lose their remote links to Russian electronic warfare and complete missions onboard, plus AI-assisted targeting at scale in Iran and Gaza.
What is Project Maven and why does it keep coming up in targeting debates?
Project Maven began as a Pentagon programme that used AI to analyse drone footage, and it has grown into Maven Smart System, which now generates target recommendations at scale. It keeps surfacing because it marks the point where commercial AI crossed into targeting: in Iran, Maven Smart System works with Anthropic’s Claude to generate recommendations, and the Minab school strike investigation has put that pipeline under scrutiny. Maven has become shorthand for AI-assisted targeting becoming routine rather than experimental.
What happened in the Minab school strike?
The Minab strike hit an elementary school, reportedly killing an estimated 120 children, and prompted the Pentagon to announce an investigation. Its significance is timing and context: the civilian harm mitigation provisions in the revised targeting doctrine appeared only weeks after that announcement, and the strike came amid reporting that AI-generated recommendations were feeding strikes in Iran. It has become the central case study for resolving accountability before, not after, the next failure.
Is there an international treaty banning autonomous weapons?
No. More than a decade of talks under the UN Convention on Certain Conventional Weapons has yielded no binding treaty on autonomous weapons. Instead, the international response remains voluntary: the Political Declaration on Responsible Military Use of AI and Autonomy, with nearly 60 signatories by late 2024; the REAIM summit process; and statements such as Pope Leo XIV’s encyclical. That is why experts argue enforceable national guardrails, codified in law with funding tied to compliance, matter more than declarations.
Could AI ever control nuclear strike decisions?
Not under current arrangements. Nuclear command and control runs on separate, deeply redundant procedures built around human authorisation, and successive US administrations have insisted humans will remain in control of nuclear employment. The autonomy debate opened by the targeting doctrine concerns conventional weapons. The longer-term question is normative: if machine-speed autonomy becomes accepted practice for conventional strikes, the assumptions that keep nuclear release human-only will need to be defended explicitly rather than assumed.
Why did Pope Leo XIV issue an encyclical about military AI?
Pope Leo XIV’s encyclical Magnifica Humanitas, released in May 2026, holds that “it is not permissible to entrust lethal or otherwise irreversible decisions to artificial systems.” It applies long-standing just-war reasoning to a new question: whether a machine can ever legitimately make an irreversible choice. The document matters less for its legal effect, which is none, than for what it signals: the accountability debate has moved beyond defence ministries into questions of moral authority over life-and-death decisions.