Avi Perera writes about when Algorithms Go to War
βš–οΈ Law 🌐International Relations (IR) πŸ€– Artificial Intelligence (AI)

When Algorithms Go to War: Inside the New Military-AI-Industrial Complex

Executive Summary

A research analysis of the PAX and Privacy International report β€” from a Geneva conference room to the boardrooms of Silicon Valley

I first encountered this research not on the page, but in a meeting room. Earlier this year, in the margins of one of the CCW-adjacent side events that now cluster around every Group of Governmental Experts session on lethal autonomous weapons, I heard Frank Slijper β€” who leads the Arms Trade programme at the Dutch peace organisation PAX β€” lay out, in characteristically understated terms, just how far the convergence between Silicon Valley and the arms industry had progressed since his organisation’s earlier work on “increasingly autonomous weapons” back in 2019. And later heard from Dr Ilia Siatitsa who discussed the report at the monthly Stop Killer Robots meeting. It was the kind of talk that stays with you: not alarmist, just relentlessly documented. So when PAX and Privacy International published the finished product in June 2026 β€” When Algorithms Go to War: Tech giants, the arms industry and the weaponisation of AI, co-authored by Slijper with Privacy International’s Dr Ilia Siatitsa and Ioannis Kouvakas β€” I read it the way I read very few 170-page PDFs: cover to cover, in one sitting.

This piece is my attempt to distil what the report actually establishes, situate it within the international legal architecture I spend most of my working life inside, and be honest about where I think the analysis is strongest β€” and where a fuller picture complicates it.

What the report actually is

“When Algorithms Go to War” is not a polemic, whatever its title might suggest. It is a company-by-company survey β€” nineteen firms in total, organised into four categories: the computing-hardware producers (AMD, Cisco, IBM, Nvidia), the tech giants (Alphabet, Amazon, Meta, Microsoft, Oracle, SpaceX), the venture-backed “neo-primes” built expressly for defence (Anduril, Palantir), and the five largest legacy arms producers (BAE Systems, General Dynamics, Lockheed Martin, Northrop Grumman, RTX), with a shorter comparative chapter on China. Each profile works through military contracts, published ethical or human-rights policies, and β€” reflecting Privacy International’s institutional focus β€” data protection commitments where they exist.

The methodology is deliberately narrow: the report tracks the largest players and the largest deals, not the full ecosystem, and its cut-off is early May 2026. That narrowness is a strength, not a weakness. It means the claims are traceable to specific contracts, specific dollar figures, specific statements β€” the report runs to well over 700 endnotes β€” rather than to the kind of diffuse “AI is dangerous” argument that tends to evaporate on contact with a footnote check.

Three findings run through the whole document, and they are the ones worth carrying with you.

The convergence: tech giants as defence contractors

The headline fact is structural. The distinction between “civilian tech company” and “defence contractor” β€” meaningful for most of the post-war history of the technology sector β€” has effectively collapsed for the largest firms. Alphabet, Amazon, Microsoft and Oracle jointly hold the Pentagon’s multi-billion-dollar Joint Warfighting Cloud Capability contract; Amazon separately holds a cloud contract with the NSA reportedly worth up to USD 10 billion. Nvidia’s chips sit inside everything from F-22 avionics to the newest generation of drones on both sides of the Ukraine front line, and the company is now the largest tech employer in Israel, working closely with Elbit Systems.

What struck me most, reading it as someone who has spent years arguing that “meaningful human control” has to be built into procurement pipelines rather than bolted on afterwards, is how fast the ethical guardrails have moved in the permissive direction. Google’s 2018 pledge not to design AI for weapons is gone. Meta and OpenAI have both walked back earlier prohibitions on military use. Where corporate human-rights policies survive at all, the report finds they typically govern suppliers β€” who a company will buy components from β€” rather than customers or end use, which is precisely the gap that matters when the question is whether a targeting system complies with international humanitarian law (IHL). Northrop Grumman is one of the few companies the report credits with actually declining specific export deals on human-rights grounds; SpaceX and Anduril, by contrast, appear to have no public human-rights policy at all.

Compressing the kill chain: what Gaza actually demonstrated

For readers of this site, the report’s most legally consequential chapter is its treatment of AI-enabled decision-support systems and what they do to the tempo of targeting decisions. The evidentiary record here is now substantial enough that it has moved well beyond investigative journalism into peer-reviewed legal scholarship. The original reporting β€” Yuval Abraham’s investigation for +972 Magazine and Local Call β€” described an Israeli military AI system, “Lavender,” that assigned probabilistic scores to individuals as suspected militants and generated tens of thousands of targets, feeding a companion system, “The Gospel” (Habsora), that marked structures for strikes. Analysts working the system reportedly had, at points, mere seconds to approve a strike recommendation β€” barely enough time, as the Lieber Institute at West Point has since analysed in detail, to constitute the kind of individualised proportionality and distinction assessment IHL actually requires. A 2025 article in the Journal of International Humanitarian Legal Studies works through precisely this question β€” whether reliance on an AI-DSS recommendation can discharge a commander’s obligations under the law of targeting β€” and the honest answer, as that literature increasingly converges on, is: not without a level of human engagement that speed-optimised systems are structurally designed to eliminate.

This is the mechanism I keep returning to in my own work: automation bias doesn’t require a fully autonomous weapon to produce autonomous-weapon-like outcomes. A human “in the loop” who is asked to approve a machine-generated target in under twenty seconds, at a volume no human analyst could independently verify, is not exercising meaningful human control. They are providing legal cover for a decision the system has already made. PAX and Privacy International are right to treat this as the same governance problem as fully autonomous targeting, not a lesser one β€” a position that tracks closely with the ICRC’s own updated position paper on autonomous weapon systems, which explicitly extends its concern to decision-support architectures that compress the time available for genuine human judgement, even where a human formally remains “in” the process.

The report is also careful β€” and I think correct β€” not to confine this to one conflict. It documents the same pattern, on far less public evidence, in reported US uses of AI in operations against Venezuela and Iran, which brings me to the chapter that will interest readers of this site most.

Generative AI enters the kill chain

Chapter 5 of the report β€” on OpenAI and Anthropic specifically β€” is the most contested territory in the whole document, and it’s worth reading with more than one source open. The report’s core facts are not in dispute: by July 2025, the Pentagon had signed USD 200 million “frontier AI” contracts with OpenAI, xAI, Google and Anthropic; GenAI.mil went live with Gemini in December 2025, then added Grok and ChatGPT in early 2026; and Claude, deployed inside Palantir’s classified-environment tooling, was reportedly present in the intelligence architecture around the January 2026 operation against Venezuelan leader NicolΓ‘s Maduro.

Where the story gets more complicated β€” and where I think the report, read in isolation, understates a genuinely significant governance moment β€” is what happened next. In February 2026, the Pentagon pushed Anthropic to accept an “all lawful use” clause that would have removed its contractual prohibitions on domestic mass surveillance and fully autonomous lethal weapons. Anthropic refused. Dario Amodei’s public explanation was that current systems are “simply not reliable enough” to be trusted with autonomous lethal engagement without safeguards that, in his words, “don’t exist today.” The Pentagon responded by designating Anthropic a national-security “supply chain risk” β€” the first such designation against an American company β€” and President Trump directed federal agencies to halt use of Anthropic’s technology altogether. Anthropic sued, arguing the designation was retaliation for asserting First Amendment–protected red lines rather than a genuine security determination; a federal court granted a preliminary injunction, and the litigation was ongoing as of this writing. Anthropic has, at least on this specific and narrow point, held a line that OpenAI β€” which reached its own DoD agreement within hours of the Trump order β€” reportedly did not draw as firmly.

None of this erases the report’s broader critique, and I don’t think it should. PAX and Privacy International are right that Anthropic’s overall posture remains, in their word, ambiguous: the company has expanded Claude’s deployment inside Lawrence Livermore National Laboratory’s nuclear-weapons research programme, partnered with Palantir on exactly the kind of military-intelligence tooling whose downstream uses it cannot fully audit, and β€” most tellingly β€” reportedly submitted its own USD 100 million proposal to build voice-controlled autonomous drone-swarming capability for the Pentagon in the same month it was publicly resisting the Pentagon’s autonomous-weapons language. You cannot hold a principled line on one autonomy question while pursuing a contract on a closely adjacent one and expect the line to read as a bright one. But the full record β€” refusal, litigation, and the drone-swarm proposal, together β€” is a genuinely more interesting and more legally significant story than either “Anthropic caved” or “Anthropic held firm” captures on its own, and readers deserve to see both halves of it. It is also, not incidentally, close to the exact ambiguity my own meaningful human control framework is built to name: a company can hold a bright line on the specific question of “who pulls the trigger” while remaining structurally entangled in every adjacent system that makes the trigger-pull possible.

A new military-industrial complex

Underneath both of the above sits the finding I consider the report’s most important, precisely because it’s the hardest to litigate: the sheer concentration of computing power, cloud infrastructure and frontier-model capability in a small number of American companies, several controlled by individuals with direct, personal proximity to the current US administration. That concentration is not new in kind β€” Eisenhower’s farewell address is sixty-five years old β€” but it is new in degree. A handful of firms now sit simultaneously astride the civilian information ecosystem (search, social media, cloud infrastructure), the frontier-AI research frontier, and the classified military-intelligence stack. When those firms also own or heavily influence the platforms through which democratic publics form political judgment, the accountability problem compounds rather than merely adds.

Where the law actually stands

Here I want to correct a misconception the report itself is careful to avoid, but that a fast read might induce: none of this is happening in a legal vacuum, even if it is happening faster than the law can currently constrain it.

Since 2014, states have discussed lethal autonomous weapons systems (LAWS) under the UN Convention on Certain Conventional Weapons, through a Group of Governmental Experts that meets in Geneva. That process has been criticised (including by me, repeatedly) for its glacial pace and for requiring consensus among states with directly opposed interests in the outcome. But 2026 is a genuinely live moment: states have the opportunity, before the year is out, to agree a negotiating mandate for a binding instrument, and a separate UN General Assembly–mandated track on the broader question of “AI in the military domain” opened informal discussions in June. The ICRC’s updated position paper and the Stop Killer Robots coalition’s policy brief on the path to a treaty β€” a coalition I contribute to through its LAWS Disarmament Toolkit β€” both converge on the same architecture PAX and Privacy International recommend: a prohibition on weapons that cannot be subject to meaningful human control or that target humans directly, combined with binding regulatory conditions on everything that falls short of prohibition.

This is also, not coincidentally, the exact gap my own Anticipatory Objection Registry is designed to address. A binding CCW instrument, if and when it arrives, will inevitably lag the deployment of the systems it seeks to constrain β€” the report’s own chronology makes that lag concrete. A registry mechanism through which states lodge formal advance objections to specific autonomy configurations does not require unanimous treaty agreement as a precondition; it starts building the opinio juris β€” the evidence of accepted legal obligation β€” that any eventual customary or treaty rule will need to rest on, while the multilateral process continues at its own pace. Read against this report’s documentation of how quickly battlefield practice is outrunning formal law, the case for exactly that kind of interim mechanism seems to me considerably stronger than it did before I read it.

What the report asks for β€” and where I’d go further

The recommendations are, appropriately, addressed to two audiences. States are asked to open treaty negotiations without further delay; to adopt a moratorium on AI systems for the use of force pending binding rules; and to extend privacy and data-protection obligations explicitly into the military domain, where Privacy International’s contribution to the report is sharpest β€” the observation that standard consumer privacy frameworks simply stop applying once data moves into military or intelligence-customer environments, leaving affected civilians with no applicable protection regime at all.

Companies are asked to stop developing or servicing autonomous weapons without meaningful human control; to write binding, not merely aspirational, use restrictions into customer contracts; to conduct genuine human-rights due diligence; and β€” for investors β€” to require the same commitments from the companies they finance. None of this is radical. It is, in substance, the UN Guiding Principles on Business and Human Rights applied to a sector that has largely treated them as optional.

Where I would push further than the report does is on enforceability. Voluntary ethical policies β€” the report’s own case studies make this point better than I could β€” get rewritten the moment they become commercially inconvenient. What the sector needs, and what states have so far declined to build, is a system of mandatory pre-deployment legal review against IHL criteria, with personal liability attaching to the executives who sign off on deployment, not just institutional liability that a company can absorb as a cost of doing business. That is a harder political ask than a treaty on autonomous weapons alone. It is also, I would argue, the only version of “corporate accountability” that actually survives contact with a defence budget.

Closing thought

I don’t think the picture this report paints is inevitable, and to their credit, neither do its authors. The CCW process has stalled before and moved again. Companies have reversed public commitments in both directions. The 156-state majority behind the 2025 UN General Assembly resolution calling for progress on autonomous weapons is not nothing. What I took from hearing Frank Slijper speak, and from the report his team went on to produce, is less a verdict than a diagnosis: the infrastructure of modern warfare and the infrastructure of civilian digital life are now, for practical purposes, the same infrastructure, built and operated by the same handful of companies. Whether that fact is governed or merely observed over the next decade is, as it always has been in this field, a question of political will rather than legal possibility.

For readers tracking the treaty process and corporate accountability landscape in more detail, I maintain an ongoing AI weapons systems database and AI policy tracker alongside my broader research.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *