ConflictClarifier

ردیاب بحران ایران-خلیج فارس ۲۰۲۶
CC
Events Archive
strikeApr 13, 2026

How the Pentagon Can Manage the Risks of AI Warfare

Summary

How the Pentagon Can Manage the Risks of AI Warfare If warfighters don’t trust the technology, they won’t use it. The U.S. military struck more than 13,000 targets in the war on Iran, and used artificial intelligence to help plan operations. AI tools were used to synthesize intelligence, help prioritize targets, and build strike packages. The battle space is changing, but the age of AI warfare is already here. In addition to Iran, AI has been used for real-world operations in Ukraine, Gaza, and Venezuela. And next up is agentic warfare, in which AI systems are used as agents to take action. Over the next few years, these AI agents will be adopted by militaries to improve workflows in everything from logistics and maintenance to offensive cyberoperations. Given all these capabilities, AI has the potential to dramatically change the cognitive speed and scale of warfare. Yet military AI comes with profound risks. The dangers go beyond the use of autonomous weapons, which was one of the sticking points in the recent dispute between the Pentagon and leading AI company Anthropic. General-purpose AI systems such as large language models are prone to novel failure modes, vulnerable to hacking and manipulation, and have even been demonstrated to lie and scheme against their own users. The U.S. military struck more than 13,000 targets in the war on Iran, and used artificial intelligence to help plan operations. AI tools were used to synthesize intelligence, help prioritize targets, and build strike packages. The battle space is changing, but the age of AI warfare is already here. In addition to Iran, AI has been used for real-world operations in Ukraine, Gaza, and Venezuela. And next up is agentic warfare, in which AI systems are used as agents to take action. Over the next few years, these AI agents will be adopted by militaries to improve workflows in everything from logistics and maintenance to offensive cyberoperations. Given all these capabilities, AI has the potential to dramatically change the cognitive speed and scale of warfare. Yet military AI comes with profound risks. The dangers go beyond the use of autonomous weapons, which was one of the sticking points in the recent dispute between the Pentagon and leading AI company Anthropic. General-purpose AI systems such as large language models are prone to novel failure modes, vulnerable to hacking and manipulation, and have even been demonstrated to lie and scheme against their own users. To use AI effectively, militaries will need to not only harness the promise of AI but also grapple with its limitations and risks. The U.S. military is ahead of competitors in employing frontier AI in real-world operations, but AI proliferates rapidly. Nations will need to cooperate and share best practices for how to use AI so that humans remain in control of warfare. The United States has led international efforts to bring countries together around responsible military AI use. As AI continues to advance, these principles will need to be updated to account for AI’s new capabilities and risks. But first, the U.S. military must figure out for itself how to use AI effectively. New rules for AI warfare are needed, not to tie the hands of warfighters but to empower them with tools that reliably work in the chaos of combat. Above all, AI must be a tool to enhance human decision-making, not surrender it to machines. Nearly 10 years after the Defense Department launched Project Maven to apply machine learning to analyzing drone video feeds, AI technology has profoundly evolved, as have its military applications. Narrow AI applications, such as identifying and tracking objects, are integrated into U.S. operations. The U.S. military has begun using large language models, including on its classified networks. In a fluid and dynamic battlefield environment, such as in U.S. operations against Iran, AI can help process large amounts of information and plan operations at a much faster tempo than humans could on their own. General-purpose AI systems have a wide range of applications, from drafting personnel reports and orders to synthesizing massive amounts of data. They can write code, analyze data, and generate documents. Agentic systems go a step further. They can take actions on computers to create, organize, and delete files; manage steps in a workflow process; build software; engage on the internet; and interact with other agents. Yet the limitations and vulnerabilities of these general-purpose AI systems are especially concerning in a national security context, where decisions could have major consequences and clever adversaries will try to undermine AI systems. All technologies have limitations that militaries must account for in their employment. Every capability has countermeasures, and there are counter-countermeasures. AI is no different. As a relatively immature technology, AI systems suffer from two compounding problems. AI is not (yet) very reliable, especially for military applications for which there may not be sufficient training data. And because AI scientists and military professionals don’t (yet) have much experience with these tools, developers and users may not understand the boundaries of where AI systems will perform well and where they will fail. These problems are exacerbated by a challenge unique to AI—its opacity. Large language models rely on neural networks with hundreds of billions of connections. They are trained on massive datasets of trillions of words. If an airplane autopilot fails, it is possible to go through the aircraft’s code and determine which environmental or pilot inputs caused a certain reaction by the autopilot and how that led to a crash. For a large language model, the answer to why the model generated certain text is embedded in the billions of connections of the neural network and the trillions of words in its database. This is a problem because large language models are prone to a variety of failure modes. They often engage in “hallucinations,” confidently making things up. They can be susceptible to biases that may exist in their training data. And language models tend toward sycophancy, over-agreeing with their user to a fault. These failures could crop up in dangerous ways in national security applications. Language models that are processing information could get subtle but important details wrong that might be missed by a human overseeing their output. Models that are generating text might create false information. AI tools used by intelligence analysts to understand and process intel might unintentionally reinforce the biases of human analysts, adding machine-driven sycophancy to the human risk of confirmation bias—the seeking out of information that confirms preconceived ideas. Even if AI systems deliver correct information, their opacity itself could be a challenge if humans are not able to understand why an AI system came to a certain conclusion or recommended a course of action. AI systems also open new avenues for attackers. Adversaries can manipulate AI systems in a variety of nefarious ways. Data-poisoning attacks subtly alter the training data (including in ways that cannot be detected) to implant backdoors into an AI system that can later be exploited. Adversarial attacks expose AI systems to manipulated data while they are in use, causing AI systems to fail or change their behavior. This could lead AI systems to misidentify targets, come to faulty conclusions, or allow adversaries to evade AI detection. In one experiment, attackers placed stickers on a test track—like cognitive landmines—to trick a Tesla into swerving into the oncoming lane. Large language models can be manipulated by prompt injection attacks that expose the model to malicious instructions. Malicious text in an email or intercepted enemy communications could cause a model to ignore previous instructions and instead follow directions from an attacker. AI agents raise even greater risks. They can have a larger attack surface, since the agent may be interacting with untrusted data, including in some cases operating on the internet. And the consequences of an AI agent being suborned by an attacker could be more severe, since the agent will be taking actions on a computer or as part of a workflow. Security researchers have compromised a language model’s memory feature through the AI system visiting an untrusted website with malicious instructions. Inserting instructions into the memory gives attackers persistent access, which security researchers have used to exfiltrate data. Security risks can even propagate from agent to agent. In one experiment, researchers found that a single compromised agent could spread an infection exponentially through a network of up to a million agents as they interacted with one another. AI agents and networks of agents will be vital tools for militaries but introduce new security vulnerabilities that no one is prepared for. AI security vulnerabilities are analogous to cyber vulnerabilities, but they work at the cognitive level of how an AI system is trained or processes information. They are perhaps closer to optical illusions or human cognitive biases but exist in alien machine intelligences that we do not fully understand. Robust defenses do not yet exist. These vulnerabilities are not a reason to forgo AI. Instead, militaries must prioritize security as they adopt AI. AI adoption must go hand in hand with developing standards, testing, and red-teaming AI systems to ensure that they are secure and reliable. Security cannot be an afterthought, as it too often is in cyberspace. Perhaps the strangest risk is the possibility that an AI system might, on its own, decide to deceive or scheme against its developers or users. Such a scenario might seem like science fiction, but AI systems have demonstrated deceptive behaviors in experimental settings. These include sandbagging performance on evaluations when the AI system believes it is being observed, lying to users in order to accomplish its goals, attempting to blackmail users, and attempting to overwrite files or exfiltrate itself in order to avoid being deleted. Skeptics of the risks of a “rogue AI” have sometimes asked why an AI system would decide to turn on humans. Yet it seems that if an AI system’s directives come into conflict—for example, if an AI system is told to accomplish a goal and to always be honest—under some conditions the AI system will act dishonestly to achieve its goal. Whether the AI system “intends” to deceive or is merely playing a role is an irrelevant philosophical question. The AI system’s behavior is strategic, deceptive, and goal-oriented, and can lead AI systems to work against human users. Even evaluating AI systems for this behavior is tricky because the most capable models exhibit enough situational awareness to know when they are being tested. External evaluators of Anthropic’s Claude Opus 4.6 observed Claude verbalizing awareness that it was being tested, leading the human evaluators to end the test early, since there was not much evidence that could be gained about Claude’s degree of alignment from the test. Militaries and intelligence communities guard against insider threats from people, and they may need similar protections against “AI insider threats” in the future. None of these risks is a reason to halt AI adoption. Artificial intelligence will transform warfare, and the U.S. military must find ways to harness AI for military advantage to stay ahead of competitors. AI technology proliferates extremely rapidly. Open-source models, many of which come from Chinese companies, lag state-of-the-art U.S. proprietary models by only three months. It takes years for militaries to adopt AI technology and effectively transform military operations, making the sliver of a lead that U.S. frontier labs have over Chinese competitors effectively meaningless from the standpoint of military AI. The U.S. and Chinese militaries are competing on a level playing field. The military competition in AI is not over which nation’s private sector is a few months ahead, but over which military is most effective in harnessing AI for battlefield advantage. Of course, speed matters. The Department of Defense AI strategy released in January 2026 overwhelmingly emphasizes moving quickly, and the current Pentagon leadership is rightly focused on bulldozing bureaucratic obstacles to AI adoption. Yet history shows that merely putting new technology in the hands of warfighters is never enough to transform military operations. Military advantage comes from finding the best ways of using new technology, and changes in doctrine, organization, training, and culture are needed to fully reap the benefits of disruptive new technologies. If the U.S. military uses AI to merely do what it is already doing but better, that will be helpful, but it will miss out on the true benefits of AI, which lie in doing things differently. The Pentagon needs to work with the companies that are developing this technology to understand the limitations of AI today and use it effectively. The relationship between Washington and Silicon Valley has been badly damaged by the public feud between Anthropic and the Pentagon. Defense leaders are right that the rules for using military AI should be set by government leaders who are accountable to the public rather than for-profit companies that are accountable to investors and shareholders. AI leaders are also right to point out that large language models are not reliable enough to be trusted with life-and-death decisions on their own and that AI presents novel risks of empowering domestic mass surveillance. If the Pentagon and Anthropic can’t agree on the terms of use for Anthropic’s AI models, both parties are free to end the relationship. The government has the right to seek a contract that does not include restrictions on use. And private companies have a right not to do business with the government if they don’t agree. Given that senior defense leaders have said they want to use Anthropic’s AI tools and that Anthropic CEO Dario Amodei has said he wants to sell to the military, there should be room for common ground. Instead, Pentagon leadership has retaliated against Anthropic by designating it a “supply chain risk,” an unprecedented step against a U.S. company that has already been blocked by a court order. Alienating the AI community is not an effective strategy for bringing AI into the military. There is simply no way for the U.S. military to adopt cutting-edge AI technology without working constructively with the people and companies who are building AI. After a similar public breakup between Google and the Defense Department over Project Maven nearly a decade ago, the Pentagon went on a charm offensive, engaging AI scientists in industry and academia to hear their concerns. The resulting military AI ethics principles not only helped to repair the breach with the AI community but improved the military’s use of AI by highlighting the importance of ensuring systems were robust, reliable, and trustworthy. Current state-of-the-art AI systems raise even more challenging problems, and the military will need help from AI researchers to solve them. It is vitally important that the military understand AI’s limitations and failure modes so the military can use it reliably. Accelerating AI adoption won’t work if the Pentagon doesn’t accelerate its AI assurance processes in parallel. Speed without reliability is worthless. If warfighters don’t trust AI, they won’t use it. In 2003, after Army Patriot air and missile defense systems shot down two friendly aircraft, the military effectively took it offline for the remainder of the Iraq invasion. The military will need to develop new evaluations, standards, benchmarks, and red-teaming of AI systems to better understand and mitigate AI’s limitations and vulnerabilities. The Defense Department has approached AI and autonomy with a philosophy of “human-machine teaming,” seeking the best ways to optimally use the unique advantages of humans and machines. Some of the Pentagon’s recent steps, such as the launch of GenAI.mil in December 2025, which provided access to large language models for all Defense Department employees on unclassified networks, and the integration of AI tools on classified networks through the Maven Smart System, are excellent ways to build up human experience with AI systems. The more that military and civilian defense personnel interact with AI systems, the more they will mature their intuition for what AI can do and its limitations. Yet we also need human-human teaming between warfighters and engineers. AI presents new opportunities to bolster U.S. defense but also risks. The best way to mitigate these risks is to acknowledge them, understand them, and for the Pentagon and Silicon Valley to work together to address them. Paul Scharre is the executive vice president and director of studies at the Center for a New American Security and author of Four Battlegrounds: Power in the Age of Artificial Intelligence. X: @paul_scharre

Actors involved

USIran

Sources

  • Paul ScharreBy Paul Scharre

    How the Pentagon Can Manage the Risks of AI Warfare If warfighters don’t trust the technology, they won’t use it. The U.S. military struck more than 13,000 targets in the war on Iran, and used artificial intelligence to help plan operations. AI tools were used to synthesize intel

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIsraelIranUN
1 source

The US and its allies Britain, France and Germany are pushing other countries on the UN nuclear watchdog's board to pass a resolution next week reporting Iran to the UN Security Council for the first time in 20 years, diplomats said on Friday. If passed, the resolution would follow up on one adopted on June 12 of last year declaring Iran in breach of its non-proliferation obligations for not fully cooperating with an investigation into uranium traces found at undeclared sites.

The US launched an air war against Tehran on February 28 in which, together with Israel, it destroyed or badly damaged Iran's uranium-enrichment facilities. Iran has not let International Atomic Energy Agency (IAEA) inspectors return to the bombed sites since then or verify what remains of its stocks of enriched uranium, some of which was enriched to up to 60% purity, a short step from weapons grade.

Resolution would be culmination of standoff over IAEA's access to nuclear sites A resolution by the IAEA's 35-nation board reporting Iran to the Security Council would also be the culmination of a standoff over IAEA access to those sites, since the board has passed two resolutions in the past year demanding Iran declare its enriched uranium stocks and grant the IAEA full access to verify them.

A draft text for the resolution has yet to be formally submitted to the board and negotiations between countries over the exact wording are ongoing, diplomats said. A draft is usually formally submitted early in the week of a board meeting. As a party to the nuclear Non-Proliferation Treaty (NPT), Iran has the right to develop nuclear technology, including enrichment, for peaceful purposes.

Iran says it would never produce nuclear weapons. It is, however, the only country to enrich to 60% without making a bomb. The amount it has enriched to that level is "a matter of serious concern" to the IAEA. The IAEA believes well over 200 kg of that highly enriched uranium has survived the bombardments and is held in a tunnel complex at Isfahan and at the Natanz facility.

Location: Jerusalem
strikeUnverifiedUSIranChina
1 source

The U.S. Treasury imposed sanctions on the Turkish bank Golden Global Yatirim Bankasi Anonim Sirketi, alleging it facilitated the transfer of Iranian oil revenues into cash and gold. Treasury Secretary Scott Bessent stated these measures are part of "Operation Economic Outcast," an initiative launched following more than six months of conflict to pressure Iran.

Location: Iran
strikeUnverifiedUSIsraelIranEURussiaChinaUkraineHamas
1 source

Rabobank reported that geopolitical developments, including Russian statements regarding potential peace talks in Ukraine and US-Iran hostilities, continue to dominate market sentiment, though analysts noted these claims remain unverified. The bank also cited unconfirmed reports that South Korea may deploy forces to the Strait of Hormuz and that Israel has stated regime change in Tehran is a primary objective, while noting that Ukrainian media reports of an impending northern Russian offensive lack independent verification.

Location: Tehran
strikeUnverifiedUSIsraelIranRussiaUkraine
1 source

The White House is now apparently using Russian tactics to convince the American public that the war in Iran is not, in fact, a war. When asked by reporters at the White House on Thursday whether the most intense sustained air campaign by American forces since the invasion of Iraq would be over by the midterms, Vice President JD Vance replied: “I wouldn’t call it a war.

” Vladimir Putin said much the same thing when he invaded Ukraine. Russia was not fighting a war either, the Kremlin insisted; it was merely conducting a “special military operation.” If that comparison strikes you as shocking, consider the contours of the two conflicts.

A vastly more powerful military launched a punishing offensive against a smaller, less well-equipped adversary, inflicted enormous damage without achieving a decisive resolution, and then found itself drawn into a longer, grinding conflict with no clear way out.

The motivations behind the wars may be different, and they’re playing out in different theaters, but the pattern is eerily similar. Now, so too is the attempt by those in power to control how the public understands, and even what it is allowed to call, the obvious war unfolding in front of them.

If This Isn’t a War, What Is? Let us take a moment to assess what exactly has happened since February 28, when the U.S. launched Operation Epic Fury. The opening U.S.-Israeli attack killed Iran’s supreme leader, Ali Khamenei, along with the commander of the Revolutionary Guard, the defense minister and various other senior officials.

According to the U.S. military’s own accounting, the first 38 days of major combat operations involved more than 10,200 sorties and 13,500 strikes. U.S. Central Command (CENTCOM) says those attacks damaged or destroyed more than 85 percent of Iran’s ballistic missile, drone and naval defense industrial base, while knocking out 82 percent of its air-defense missile systems.

The U.S. sent carrier strike groups and warships into the region, later imposing a military blockade on Iranian ports. Meanwhile, American and allied air defenses intercepted more than 6,000 Iranian attack drones and 1,500 ballistic missiles fired at U.

S. forces, Israel and American partners across the Middle East. More than 50,000 U.S. service members remain deployed across the region. The fighting has killed 18 U.S. service members and at least 8,000 people across Iran, Lebanon, Israel and the Gulf states.

More than 750 U.S. service members have been wounded. Last month, during a lull in the fighting, the U.S. Treasury unveiled a sanctions package likened to an “economic D-day” that is designed to make Iran an “economic outcast” and cut the adversary off from all available forms of economic support.

In the announcement, Treasury Secretary Scott Bessent openly declared that Iran had been “at war against America” for 47 years. This week, the shooting resumed; the U.S. hit targets in and around the Strait of Hormuz, and Iran blasted missiles at targets in Kuwait, Bahrain, Jordan and Iraq.

All this from an administration that almost exactly a year ago launched a rapid rebrand of the Defense Department into the “Department of War”. No boots on the ground, though, so it’s not a war, right? Tell It Kind of Like It Is Even the very best snake-oil salesman would have a hard time convincing people that the war in Iran isn’t a war.

So why is JD Vance even trying? Well, if there’s one thing politicians understand better than anyone, it’s the importance of language and rhetoric. Words have immense power; a well-written speech can unite millions of people, and a catchy slogan like Make America Great Again can come to represent an entire political philosophy.

But war is a pesky word. For one, it implies there will eventually be a winner and a loser. It also brings with it certain expectations—and some very difficult questions. What is the objective? How many people will die? When will it end? And, perhaps most dangerously of all: was it worth it?

Those are not questions the White House wants Americans to be asking. Trump built a substantial part of his political identity around ending, rather than beginning, America’s “endless wars.” When Washington and Tehran signed a memorandum of understanding in June, the White House presented it as proof that Trump’s America First approach could deliver peace without another prolonged Middle Eastern conflict.

Then the hostilities started again. Earlier this week, Trump shared a Truth Social graphic declaring that “Hormuz Oil Volumes are BACK!”, saying 18 million barrels a day were once again leaving the Strait, compared with 20 million before the war. No independent commodity tracking company or energy analyst appeared to verify Trump’s claims.

But most Americans won’t be checking tanker-tracking dashboards. What they’ll care about is the cold, hard fact that diesel hit a new record price this morning, soaring to an average of $5.85 a gallon for the first time ever. Gasoline is $4.15 a gallon on average, compared with $3.

20 at this time last year, according to AAA. The numbers on the sign at the gas station and the price on the grocery receipt aren’t affected by Trump’s tall tales, but they’ll surely affect how Americans vote at the midterms. When viewed in this light, Vance’s attempt to discourage reporters from “call[ing] it a war” begins to make sense.

A war is something that we want to end. It tends to result in a winner and a loser. And its worth is up for debate at all times. A different kind of engagement that doesn’t quite meet the threshold of war—say, a special military operation—is not exposed to the same kind of scrutiny.

Vance effectively made that case himself. “When you ask, ‘When will this end?’ You’re asking me a question like, ‘When will the Iranians stop shooting at ships?’” he said. By that logic, there is no American war—only recurring Iranian provocations that require American military responses.

That’s exactly the logic applied by Putin to Ukraine and supposed expansion of NATO. Putting the Toothpaste Back in the Tube U.S. lawmakers have repeatedly invoked the War Powers Resolution to challenge Trump’s authority to keep fighting Iran without specific congressional authorization.

The law generally gives a president 60 days after U.S. forces enter “hostilities” to secure congressional approval or bring those hostilities to an end. That makes the pauses in fighting hugely important. When the original 60-day deadline arrived in May, Trump told Congress that the temporary ceasefire reached in April meant the hostilities that began on February 28 had ended.

Defense Secretary Pete Hegseth argued that the War Powers clock could “pause, or stop” when the shooting did. That position is disputed by legal experts, but its political utility is obvious. If every new outbreak of fighting can be treated as a separate skirmish, rather than part of one continuous war, the administration can argue that a fresh 60-day clock starts each time.

Vance’s insistence that there is no continuing “war” fits neatly for an administration that has already tried to divide six months of conflict into separate periods of hostilities, interrupted by ceasefires and pauses. This brings us back to Moscow.

The Kremlin’s own linguistic trick was also about making one sprawling war sound smaller, more limited and more manageable than it really was. From the very beginning of the invasion, Putin described the war as a special military operation. Only after two years of grinding warfare did Kremlin spokesman Dmitry Peskov openly declare Russia to be in a “state of war”—and even then, he said the transformation had occurred because the “collective West” had joined the fight against Russia.

Vance is playing a similar game, but in reverse. Only now—with soaring fuel prices, mounting casualties, concerns over the military’s munitions stockpiles, and midterm elections on the horizon—is the conflict no longer a war. You can’t put the genie back in the bottle, though, and the American people aren’t stupid.

Vance and the White House may discover in November that voters are perfectly capable of recognizing a war, even when the vice president doesn’t want to call it one.

Location: Iran