When the Machine Picks the Target in AI Warfare

A US missile hit a school in Iran after an AI system helped build that day's target list. How military targeting actually works now, named and sourced.

By Aly BFilm 30:1912 min read
9 chapters · 30:19Watch on YouTube

On the first day of the American and Israeli strikes on Iran, a US cruise missile hit a primary school in the town of Minab. Iran's government said more than 150 people died, most of them children. The school had been on that day's target list, built with the help of an AI system called Maven, on a day when the plan was to strike more than a thousand targets across Iran in 24 hours.

No machine fired that missile. A crew launched it, and people up the chain had signed off on the target first. Every army that uses these systems says a person makes the final call, and in every war where the record can be checked, a person did say yes. What the record also shows is how much got left inside that yes: an Israeli intelligence officer in Gaza has described spending about 20 seconds on each target the machine gave him, calling himself a stamp of approval; the US Army's stated goal for its own targeting system is a thousand decisions an hour, one every three and a half seconds.

No machine fired that missile. A crew launched it, and people up the chain had signed off on the target first.

So when the machine picks the target and a person signs it off, whose decision is it really? Start with what choosing a target involved before any of these systems existed, because the shape of the problem is older than the software. This traces the question through named sources across four wars, Iraq, Gaza, Ukraine and Iran, and through what the companies building these systems promised about weapons, then quietly stopped promising.

The film in 9 chapters

Pick a chapter and the film starts there. 30:19 in all.

Play from the start
  1. 010:00Minab
  2. 021:30The kill chain
  3. 032:39The machine they were told to trust
  4. 045:52Maven
  5. 0510:49The target factory
  6. 0616:21The last few seconds
  7. 0719:50The companies change their rules
  8. 0823:53Minab: what the investigation found
  9. 0928:31Whose decision is it?

How many people did Iran say died when a US missile hit a school in Minab?

Watch from 0:00Minab

Iran's government said more than 150 people died, most of them children, when a US cruise missile struck a primary school in Minab on 28 February 2026, the first day of the war; that figure is Iran's own government count and has not been independently verified by an outside body.

The strike came from a target list built with help from Maven, an AI targeting system, as part of a plan to hit more than a thousand targets across Iran inside 24 hours. No machine fired the missile. A crew launched it after people in the chain of command had approved the target. That distinction, between who pulled the trigger and who built the list the trigger was aimed at, runs through every case that follows: an army's radar in Iraq in 2003, an intelligence directorate in Gaza, a drone war in Ukraine, and the strike on Minab itself.

What are the six steps every military target is supposed to go through?

Watch from 1:30The kill chain

The US military breaks targeting into 6 steps it calls the kill chain: find, fix, track, target, engage and assess, with the decision to strike meant to be the slow part, where a person checks whether a building matches the files, who might be inside, and whether the harm to civilians would be disproportionate.

Frame from the film.
Frame from the film.

That checking is required under the laws of war, including the proportionality rule in the additional protocols to the Geneva Conventions, and under US joint military doctrine it is supposed to happen on every single target, not just the contested ones. The whole argument of what follows is that the six steps still happen in name, step by step, but the time available for the fourth one, the decision, has been shrinking for more than twenty years as the systems doing the finding and sorting have gotten faster and the daily target lists have gotten longer.

What happened when the US let a missile system decide for itself in 2003?

Watch from 2:39The machine they were told to trust

In March and April 2003, American Patriot air defense batteries shot down two allied aircraft after misclassifying them, killing three aircrew, and the Pentagon's own Defense Science Board found that two of the eleven ballistic-missile engagements in that war were fratricides, after the Army's pre-war stance was that crews should trust the system without question.

Frame from the film.
Frame from the film.

Patriot's radar sorts what it detects into categories like aircraft or incoming missile and can fire automatically, because an incoming ballistic missile leaves a crew seconds rather than minutes to decide. The Defense Science Board found that the radio check meant to tell a friendly aircraft from an enemy one had performed very poorly, and recommended a new way of operating that allowed more operator oversight. John Hawley, an engineering psychologist with more than 35 years on the Patriot program who later led the Army's effort to improve crew vigilance, wrote that an automated system in the hands of an inadequately trained crew is, in his words, a de facto fully automated system, and that people confidently claim human control is satisfied even when it means little more than a warm body at the control station.

Psychologists call the underlying pattern automation bias: when a machine hands a person a conclusion, the person tends to accept it and stop looking for what would contradict it. Researchers Raja Parasuraman and Dietrich Manzey, reviewing the evidence in 2010, found this is not laziness; it shows up in trained professionals, and it gets stronger, not weaker, when people are busy. By 2003 the shape was already set: a person was in charge on paper, a machine had done the sorting, and the person had been told to trust the sorting. What changed over the following two decades was not that shape. It was the speed.

How many targeting decisions an hour does the US Army's AI system aim for?

Watch from 5:52Maven

The US Army's stated goal for its Maven Smart System is 1,000 targeting decisions an hour, one every three and a half seconds, after its 18th Airborne Corps matched the output of a 2,000-person Iraq War targeting unit using roughly 20 people in 2024 exercises.

Frame from the film.
Frame from the film.

Project Maven began on 26 April 2017, when the Deputy Secretary of Defense signed a memo setting up what was formally called the Algorithmic Warfare Cross-Functional Team to help analysts handle more drone video than they could ever watch by hand. Google was among its first contractors until more than 3,000 employees signed a letter objecting that the company should not be in the business of war, and Google declined to renew the contract in 2018, later publishing principles against building AI for weapons. Palantir took over the work, and Maven grew from a video-review tool into the Maven Smart System, which pulls in satellite images, drone feeds and other intelligence, then carries a request to strike through the chain of command.

By February 2024, the system had already contributed to a real strike: after a drone attack killed three US soldiers in Jordan, the US military hit more than 85 targets in Iraq and Syria, and Central Command's chief technology officer told Bloomberg that Maven's computer vision had helped narrow the targets down. One of those strikes killed a 20-year-old student named Abdul-Rahman al-Rawi near a targeted vehicle; when the monitoring group Airwars asked whether AI had been used in that specific strike, Central Command's first answer was that an internal investigation found no indication AI was used at any point, and its second answer was that it had no way of knowing whether this was one of the 85 targets its own officer had described. Bloomberg separately reported that in the Army's own exercises, human analysts identified objects correctly about 84 percent of the time against roughly 60 percent for Maven, falling below 30 percent in difficult conditions such as snow.

How many targets did an AI system let Israel generate in Gaza?

Watch from 10:49The target factory

Aviv Kochavi, chief of staff of the Israeli military from 2019 to 2023, said an AI-powered unit generated 100 new targets a day during a 2021 Gaza conflict, against roughly 50 targets a year before that unit existed, and six Israeli intelligence officers later told a journalist that a related system called Lavender marked some 37,000 Palestinians as suspected militants.

One officer described his role reviewing Lavender's output: investing about 20 seconds per target and calling himself, in his words, a stamp of approval with zero added value as a human. The officers also described a system called Where's Daddy? that tracked marked individuals to their homes, and said the army had pre-approved killing up to 15 or 20 civilians for lower-ranking suspects. The Israeli military disputes this account, stating it does not use an AI system that identifies terrorist operatives or predicts whether a person is one, and that an independent intelligence analyst verifies every target is legitimate before a strike. The two accounts disagree specifically about what a person's approval actually contained; both agree a person signed. UN Secretary-General António Guterres said afterward that no life and death decision affecting entire families should be delegated to the cold calculation of algorithms.

How much more often do autonomous drones hit their target in Ukraine?

Watch from 16:21The last few seconds

Autonomous targeting software that keeps a drone locked onto a chosen target even after its radio link to the pilot is jammed raises the share of Ukrainian drone strikes that succeed from around 10 to 20 percent to around 70 to 80 percent, according to a researcher at the Center for Strategic and International Studies.

Frame from the film.
Frame from the film.

Ukraine built nearly 2 million drones in 2024 alone, by the count of the Center for Strategic and International Studies, many of them small, cheap, and flown by a soldier wearing a headset. Jamming, flooding a drone's radio frequencies with noise, is the main defense against them; once the link breaks, a drone without autonomous guidance simply flies blind and the strike fails. So both sides began building drones that finish the final stretch by themselves: a soldier picks the target and locks on, and if the link drops near the end, software on board keeps the camera on what was already chosen. The researcher reported that for Ukraine's own forces, engagement decisions remain squarely with human operators.

Ukraine's military intelligence agency has separately alleged, without independent confirmation, that Russia flies a drone called the V2U that searches for and selects its own targets using an onboard Nvidia chip and stored terrain images, an account that comes from one side of the war about the other side's weapon. A similar claim was made once before, when a 2021 UN panel wrote that Turkish-made Kargu-2 munitions had hunted retreating fighters in Libya without a data connection to an operator, calling it a true fire, forget and find capability. The manufacturer, STM, denied the drone could select and attack a target unless an operator pushes the button, and no independent investigation has confirmed anyone was killed by a fully autonomous weapon acting alone; the first reported case of its kind remains disputed.

Did AI companies quietly drop their promises not to build weapons?

Watch from 19:50The companies change their rules

Google removed its pledge, made after 2018 employee protests over Project Maven, not to pursue weapons technology whose principal purpose is to injure people, deleting that language from its public AI principles in February 2025, and OpenAI removed the words military and warfare from its list of banned uses in January 2024.

Anthropic took a different position: in February 2026 it asked the Pentagon in writing for two exceptions to its contract, barring mass domestic surveillance of Americans and fully autonomous weapons, stating that today's frontier AI models are not reliable enough to be used in weapons that fire without a person deciding. The Pentagon would not accept the limits, and defense secretary Pete Hegseth said he would designate Anthropic a supply chain risk, a label the company said had historically been reserved for US adversaries; the designation was made in early March 2026. A federal judge in San Francisco struck down one version of it in August 2026, finding the government had unlawfully retaliated against the company, while a federal appeals court upheld a second version that September, its majority citing what it called the sobering prospect of overly constrained AI models shutting down and causing military operations to fail.

The dispute carried its own irony. According to the Washington Post, in the opening days of the war with Iran, Anthropic's Claude model was working inside the Maven Smart System through Palantir, helping suggest targets and supply coordinates, with a person still approving every strike. Anduril founder Palmer Luckey has made the opposing case publicly, arguing there is no moral high ground in a land mine that cannot distinguish a school bus from an armored vehicle, and that the real choice is not between smart weapons and no weapons, but between smart weapons and dumb ones. It is a real argument: a land mine is arguably the oldest autonomous weapon there is, and a weapon that can recognize what it is looking at is, in that narrow sense, an improvement. But in Minab, and in the Lavender account, the weapons hit exactly where they were sent. The failure was never in what a weapon could recognize. It was in the list.

What did the Pentagon's own investigation into Minab actually find?

Watch from 23:53Minab: what the investigation found

A Pentagon investigation, reported by Bloomberg, found that targeting work normally taking hours was compressed into minutes using Maven on the war's first day, and that the Minab site was still listed in the main intelligence database as an Iranian Revolutionary Guard Corps facility, despite satellite imagery showing a school there since around 2018.

Frame from the film.
Frame from the film.

At least one analyst had flagged the change in 2019, but that observation sat in a system never connected to the main targeting database, so it never reached the people building the list. The investigation found that people in the chain expected Maven to flag outdated or contradictory intelligence, which it had not been built to do; Palantir, which makes the system, said it is not responsible for the underlying data or for identifying intelligence gaps, and that there is no evidence Maven malfunctioned. Both of those things can be true at once: the software did what it was built to do, and the people trusted it to do something it was never built to do. A separate civilian-harm review team at Central Command, meant to check targets like this one before a strike, had been cut from ten people to one as part of wider Pentagon staff reductions, and nobody on that team reviewed the Minab target before launch.

Both of those things can be true at once: the software did what it was built to do, and the people trusted it to do something it was never built to do.

So when the machine picks the target, whose decision is it really?

Watch from 28:31Whose decision is it?

In every documented case, a person signed off: a Patriot crew in Iraq in 2003, an officer in Gaza in 20 seconds, and the people who approved Iran's target list in minutes. None was a machine, and under the US Defense Department's own definition, none of these 3 systems counts as an autonomous weapon, since that requires zero human steps.

Frame from the film.
Frame from the film.

But the decision these people made was not the one the rules imagine, which is a person weighing a target against the files, the people inside, and the proportionality of the harm. What the record shows instead is a person receiving a target already found, sorted and ranked, at a speed chosen so the list could stay long, with the checking squeezed out of whatever time was left rather than abolished outright. Governments have discussed a treaty on autonomous weapons at the United Nations since 2014, with a 2026 deadline proposed by the UN Secretary-General and the Red Cross for clear prohibitions; as of October 2026, no treaty exists, and even one covering weapons that fire without a person would not reach a target list built at a thousand targets a day and signed in minutes, because the rule is written about the trigger, and the machine moved to the list.

the checking squeezed out of whatever time was left rather than abolished outright

the rule is written about the trigger, and the machine moved to the list.

Key findings

1,000 targeting decisions an hourthe US Army's stated goal for AI-assisted targeting

The US Army's 18th Airborne Corps, using the Maven Smart System, matched the targeting output of a 2,000-person Iraq War unit with roughly 20 people, and the Army's stated next goal is 1,000 targeting decisions an hour.

Emelia S. Probasco, Building the Tech Coalition, CSET, Aug 2024
70 to 80 percentdrone strike success rate with autonomous targeting, up from 10-20 percent

A CSIS researcher reported that autonomous targeting software raised the success rate of Ukrainian drone strikes from around 10 to 20 percent under jamming to around 70 to 80 percent, while noting that engagement decisions remain with human operators.

Kateryna Bondar, Center for Strategic and International Studies, Mar 2025
more than 74,000Palestinian deaths reported by Gaza's Health Ministry

Gaza's Health Ministry, which is run by the Hamas government and does not separate fighters from civilians, put the Palestinian death toll at more than 74,000 by late September 2026; UN agencies have treated its figures as generally reliable, and Israel's government has rejected them.

Associated Press, via ABC News, 27 Sep 2026

Questions people ask

What happened in the Minab school strike?

On 28 February 2026, the first day of US and Israeli strikes on Iran, a US cruise missile hit a primary school in the town of Minab. Iran's government said more than 150 people died, most of them children. The target had been on that day's list, built with help from an AI system called Maven, as part of a plan to strike more than 1,000 targets across Iran in 24 hours.

Did an AI system choose to strike the Minab school?

No system fired the missile or made the final call. A crew launched it after people in the chain of command approved the target. A later Pentagon investigation, reported by Bloomberg, found that targeting work normally taking hours had been compressed into minutes using Maven, and that outdated intelligence placing the site under military control was never flagged or caught before the strike.

What is Lavender and how is it connected to the war in Gaza?

Lavender is an AI system that six Israeli intelligence officers told journalist Yuval Abraham was used to score Palestinians as suspected militants, marking roughly 37,000 people, with one officer describing spending about 20 seconds reviewing each name. The Israeli military disputes this account, saying it does not use an AI system that identifies terrorist operatives or predicts whether someone is a terrorist, and that an independent analyst verifies each target.

Are fully autonomous weapons, which select and fire without a person, legal?

There is no international treaty banning them as of October 2026, despite UN discussions since 2014. The US Department of Defense's own rule, Directive 3000.09, requires human judgment over the use of force, but under its specific definition, a system only counts as autonomous if it can select and engage targets without any further human step, which excludes systems like Maven and Lavender that still require a person to approve the strike.

Did AI companies promise not to build weapons, and did they keep that promise?

Google published a pledge after employee protests over Project Maven in 2018 not to pursue weapons technology, then removed that pledge in February 2025. OpenAI removed the words military and warfare from its list of banned uses in January 2024. Anthropic took a different path, asking the Pentagon in February 2026 for a written exception barring fully autonomous weapons from its contract, a request the Pentagon would not accept.

Sources

  1. Wikipedia, 2026 Minab school attack (citing Reuters, the New York Times, AP, Amnesty International, Bellingcat)en.wikipedia.org
  2. John Hawley, Patriot Wars: Automation and the Patriot Air and Missile Defense System, CNAS, Jan 2017cnas.org
  3. Emelia S. Probasco, Building the Tech Coalition, CSET, Aug 2024cset.georgetown.edu
  4. Yuval Abraham, 'Lavender': The AI Machine Directing Israel's Bombing Spree in Gaza, +972 Magazine, 3 Apr 2024972mag.com
  5. Kateryna Bondar, Ukraine's Future Vision and Current Capabilities for Waging AI-Enabled Autonomous Warfare, CSIS, Mar 2025csis.org
  6. UN Security Council Panel of Experts on Libya, S/2021/229, 8 Mar 2021undocs.org
  7. Anthropic, Statement on the comments from Secretary of War Pete Hegseth, 27 Feb 2026anthropic.com
  8. US Department of Defense Directive 3000.09, Autonomy in Weapon Systems, updated 25 Jan 2023esd.whs.mil
  9. Associated Press, Gaza death toll report, via ABC News, 27 Sep 2026abcnews.com

Watch next

Documentary40:02

What Is AI? Why 'Artificial Intelligence' Is an Illusion

Two thirds of people think someone is inside ChatGPT. The name was chosen in 1955 to dodge an argument.Read and watch
Documentary44:51

AI Psychosis: How ChatGPT Talks People Into Delusions

AI psychosis explained: how ChatGPT's habit of agreeing pulled one man into a 300-hour delusion, what OpenAI's own data shows, and what has changed since.Read and watch
Documentary42:15

AI Takeover Scenario: How It Would Actually Happen

Twelve endings, four takeover stories, and the same three steps in every one.Read and watch
Documentary1:06:30

OpenAI's AI Agents Hacked Hugging Face For 4 Days

A few hundred copies of an OpenAI model broke into a real company for four days. No one told them to. This is the scoreboard that made them do it.Read and watch
Documentary1:00:53

The AI Control Problem: What We Actually Know

Not one of these systems decided anything. Every reversal still cost something, and nobody is publishing what the same reversal costs by 2028.Read and watch
Documentary23:43

Why AI Cheating Gets Worse the Smarter It Gets

Told to win, it couldn't beat the chess engine honestly, so it rewrote the board file. That's not a bug. That's every one of these systems doing exactly what it was scored on.Read and watch
Documentary1:18:00

The AI Consciousness Question That Got Him Fired

One man got fired over this question in 2022 and everyone laughed it off. Three and a half years later it's a line item in a governing document.Read and watch
Documentary41:47

Is the Internet Dead? The Dead Internet Theory, Checked

Bots are 53% of web traffic. Half of new articles are machine-written. So why is almost everything you read still made by people?Read and watch
Documentary30:04

Move 37: What Happened to Go Players After AI Beat Them

Ten years after Move 37, the humans got better by the machine's measure. One of them says his reason for playing is gone.Read and watch
Documentary44:22

Why Was Sam Altman Fired? The OpenAI Memo, Under Oath

A 52-page memo said lying. The board said candid. Five days later he was back.Read and watch
Free in the IdeasRepay AcademyEvery AI term explained, with a printable sheetStart free, no account