A soldier holds a drone in the Pentagon parking lot on June 14, 2025 in Arlington, Virginia.

The Pentagon’s Autonomous Weapons Definitions Don’t Need an Overhaul, They Need an Update

The White House recently published a National Security Presidential Memorandum directing the executive branch to “responsibly accelerate the use of AI across intelligence and warfighting domains in line with American values.” A key part of this memorandum instructs the Pentagon to review and update DoD Directive 3000.09 within 90 days. That Directive sets the guidelines for the use of autonomous weapons systems in part by defining different levels of autonomy of these platforms. These definitions have made their way into mainstream debates, including the dispute in February between the Pentagon and AI company Anthropic over the use of its AI model, Claude, in fully autonomous weapons (among other topics).

Amidst the clashes over its application, this new memorandum highlights a critical problem: the term “autonomous weapons” has no settled meaning. Different groups use competing definitions, and the same term can mean different things in different battlefield contexts or when applied to different weapons systems. More specific classifications—“semi-autonomous weapons systems,” “operator-supervised systems,” “lethal autonomous weapons systems,” and the emerging concept of “agentic warfare”—are routinely conflated. Using these terms interchangeably to describe any weapon operating without constant human control is imprecise at best and can lead to dangerous oversights in deployment at worst.

DoD Directive 3000.09 does not require a wholesale overhaul, but the pending update provides an opportunity to further tighten up its definitions to better reflect the current environment of autonomy in warfighting. It’s currently not clear that the DoD’s classifications provide adequate nuance when stress tested against different kinds of target groups or new platforms that use AI in new ways. Some weapons can now operate fully autonomously, for instance, but are fielded as semi-autonomous systems by doctrine and policy alone. Defense contractors are also developing new approaches to AI warfare, and whatever the reality, they will often describe their products in whatever terms win procurement contracts, even if that comes at the expense of operational clarity for military personnel. Militaries, meanwhile, will have to balance strategic advantage with legal and policy mandates, which requires definitions that are both precise and broadly understood.

The Pentagon is now pushing hard to integrate AI into a range of weapons systems and other aspects of warfighting, which will likely require establishing an unambiguous blueprint for the future of autonomous weapons systems—one that fosters clear and nuanced public understanding of what they are and how they operate on the battlefield.

The Autonomy Spectrum

Autonomy runs along a spectrum determined by the level of control that an operator has over how a weapon identifies, tracks, and engages a target—the so-called “kill chain.” Different communities divide up this spectrum in different ways. The Pentagon talks about three levels of autonomy: semi-autonomous weapons, operator-supervised autonomous weapons, and autonomous weapons. Academic discussions, meanwhile, center on a continuous “loop” of decision-making, splitting weapon types between “human-in-the-loop” and “human-on-the-loop.” Human-in-the-loop roughly matches to the Pentagon’s semi-autonomous category, while human-on-the-loop is closest to the operator-supervised type. Still other terms exist to describe the extent of human agency over weapons systems: “meaningful human control,” “effective human control,” and “appropriate human judgment.” Some of these expressions are about technical capacity, others are about military policy. And they are often used interchangeably, confusing what any of them mean in practice. The table that I have developed below briefly defines these.

The Pentagon describes an autonomous weapons system as one that, “once activated, can select and engage targets without further intervention by an operator.” In this context, a human operator relinquishes control of a weapons system when it is deployed and before it selects a target. Such weapons are not theoretical. In February 2025, Russia deployed what Ukrainian intelligence called an autonomous loitering munition, the V2U. Its onboard sensors and software let it operate even in radio control-denied environments, and it can reportedly use AI to perceive, select, and engage targets, performing an end-to-end kill chain without any operator control, authority, or intervention.

The same Pentagon directive describes a semi-autonomous weapons system as one that can “only engage individual targets or specific target groups that have been selected by an operator.” The line between autonomous and semi-autonomous weapons systems thus turns on target judgment. If the weapons system is able and authorized to select targets and engage without human intervention, it is fully autonomous under the Pentagon’s definition.

This is not to say semi-autonomous weapons systems are limited to engaging individual targets selected by humans or following terminal guidance systems to pre-determined coordinates in practice. They can also hit specific target groups, which the Pentagon describes as a “discrete group of potential targets.” It’s unclear how DoD interprets this language, but in theory it could mean a drone’s computer vision identifying a particular formation of enemy battleships or tanks.

As an example, consider Operation Spiderweb, a June 2025 Ukrainian mission that used quadcopter drones to strike airfields deep in Russian territory. While operators still manually selected the final target groups on their screens, each drone was equipped with enough AI technology to adjust its flight path even after losing radio signal with the pilot, identify and prioritize targets through its onboard computer vision, and autonomously detonate on impact.

Therefore, the line between autonomous and semi-autonomous is not always clear. A 2021 United Nations Security Council report detailed the potential use of autonomous weapons in the Second Libyan Civil War, including the Libyan Government’s use of the STM Kargu-2, a Turkish precision strike drone. The manufacturer states that Kargu-2’s precision strike missions are meant to be fully performed by a human operator. But its use in Libya to identify logistics convoys and retreating rival forces and engage them without data connectivity between the operator and the munition has led some analysts to suggest that this weapons system was fully autonomous. STM has disputed this characterization.

Debates like this show that technical capacity alone doesn’t necessarily determine whether a weapons system is autonomous. Deployment policies, which are shaped by risk tolerance and laws of armed conflict, matter too. The Pentagon’s directive attempts to address these aspects as well.

Military Restraints Matters Just as Much as Technical Capacity

Often, the technical capabilities of autonomous weapons systems outpace how comfortable humans are with deploying them to their full extent. Earlier versions of AeroVironment’s Switchblade 600 loitering munition, for instance, carried terminal guidance systems that could autonomously pursue a selected target even if data connectivity is lost, but they were still largely piloted by human operators who had to relinquish control only at the final dive.

The capacity of these platforms is shaped as much by militaries’ choices as by engineering. Take Anduril’s Altius 600 and 700 drones. By some metrics, they could plausibly be classified as autonomous weapons. Synchronized on Anduril’s Lattice AI platform, these systems can autonomously recognize and track targets and coordinate hunter-killer swarm behaviors in what the company describes as “teams of low-cost autonomous systems under the command of a single human operator.”

But it seems as though these types of systems are deliberately constrained. Anduril has marketed the Altius as having an “operator on the loop.” The drone can execute the entire mission cycle by itself, but the operator maintains a supervisory role and can intervene if something goes wrong. The Pentagon calls these operator-supervised autonomous weapon systems. However, in practice these weapons have been deployed in the field with even more human intervention. According to a 2023 interview with Anduril’s CEO, when the Altius has identified a potential target, the operator must still make the final call on whether to engage or abort—a human “in,” not merely “on,” the loop. This would mean the drone cannot engage a target or target group without explicit operator consent. By system design and standard operating procedure, what could be an autonomous weapon is reportedly run as a semi-autonomous one. What makes a weapon autonomous, then, is not only the technical capacity of the system to act on its own but the choice to let it do so.

That said, those policies do often derive from remaining technical limitations. The capacity to field fully autonomous weapons systems is older than many realize. The Israeli Harpy drone, which from the early-1990s was able to “detect[], attack[], and destroy[] enemy radar emitters,” was arguably an autonomous weapons system under the Pentagon’s technical definition. But autonomous systems still have vulnerabilities—unanticipated interactions with the environment, adversarial hacking, and unintended engagement, among others. DoD policy attempts to address these risks by requiring that all weapons systems allow operators to exercise “appropriate levels of human judgment.” This standard does not require operators to be in constant control of a weapon, but it does mandate that human authorizers and operators act in accordance with the rules of war, safety regulations, and military doctrine.

Defining what constitutes “appropriate levels of human judgment” is perhaps where much of the confusion manifests. This standard recurs in Pentagon directives, international organizations, and policy circles, but it does not have a formal or agreed definition. In a 2016 statement, the U.S. Mission to the United Nations described the definition as deliberately vague because the right level of human judgment changes depending on the environment in which the weapons system operates. Similar terms like meaningful human control are equally ambiguous. The upshot is that criteria for appropriate levels of human judgment are a context-dependent calculation of risk based on numerous factors, such as the function of the weapons system, the time available to engage, the operating environment, and the ways it might fail.

A natural reading of the official Pentagon directive says that the U.S. military does not currently authorize the deployment of any offensive fully autonomous weapons systems, and there have been no reports that state otherwise. But there is also no direct statement from the DoD that these systems are not being deployed. Furthermore, there are reportedly weapons projects under development that could eventually cross the threshold into fully autonomous weapons systems, such as Project Whiplash, an effort to create autonomous armed jet skis.

What DoD directives on AI use in the military show is that questions over definitions like these will recur, and they will be more likely to lead to enduring agreements between national militaries and defense companies on development standards if they can build on a shared public vocabulary for what autonomy actually looks like in the field.

Why Definitions Matter, and Where They Can Improve

Until recently, discussions of AI and autonomy in weapons systems were largely confined to specialist policy and advocacy circles. But as the Anthropic-Pentagon fallout demonstrates, these issues are increasingly going to spark public debate. If democratic oversight is to work, everyone involved, from political commentators to the congressional Armed Services Committees, will need to use clearer definitions and understand what the other players mean. Imprecise language will prevent companies and citizens from understanding the consequences of the positions they take, and even within the military, ambiguity risks undermining decision-making on the battlefield and in Washington.

Unclear definitions will also cause problems on the international stage. The international community has been debating the governance of lethal autonomous weapons systems for well over a decade. In 2013, for instance, the Meeting of State Parties to the Convention on Certain Conventional Weapons concluded a mandate on lethal autonomous weapons systems and instructed its chairperson to convene a group of experts to discuss the implications of this emerging technology. A decade later, the United Nations New Agenda for Peace publicly announced its desire to conclude a legally binding instrument that would prohibit the use of fully autonomous weapons systems by 2026. And beginning in 2016, an open-ended Group of Governmental Experts on the topic was convened to meet annually, with draft text (including definitional issues) under continuing discussion as recently as 2025. Yet despite modest progress, the core goals of the agenda have not been met, not least of which because of disagreements over how lethal autonomous weapons should be defined.

If countries mean different things by the same words, or disagree internally about what they’re saying, they’ll struggle to create common rules to govern the use of autonomous weapons—or even to agree on what’s going on. Just as international bodies have had to define the boundaries of chemical and biological weapons, or the meaning of the use of force (although even now there remain disagreements on this), eventually they will have to seek to hammer out joint understandings of autonomy. That process will be even tougher if governments continue to participate without coherent definitions they can agree on internally.

As the Pentagon reviews and updates DoDD 3000.09 within the ongoing 90-day window, it should prioritize a few specific ways that existing definitions of autonomy can be clarified.

First, the Pentagon would benefit from clarifying how its definitions apply to current systems. Current policy attempts to elaborate on its specific target group definition by describing some weapons that would fall under such classifications, such as a “particular flight of enemy aircraft, a particular formation of enemy tanks, or a particular flotilla of enemy vessels.” These moderately bounded examples, and their repeated use of the word “particular,” could suggest that very broad target classifications—like “any armored vehicle” or “any hostile soldier”—would not have sufficient specificity for use in semi-autonomous weapons. But the DoD does not clearly outline how tightly bound a specific target group must be.

Consider, for instance, an operation where a brigade launches a drone swarm to strike a “particular formation of enemy tanks” detected by aerial reconnaissance 20 minutes prior. This would seem to satisfy the bounds of a “specific target group.” However, by the time the swarm has reached the engagement zone, the formation has broken apart to seek cover. It is uncertain whether the swarm should be authorized to then search for individual tanks in the area that supposedly belong to that original formation, even if geographically bounded by the area the swarm was deployed to search in the first place. Such a scenario would arguably break the chain of human judgment innate to the original target group. In the event that the swarm then engages the tanks in a manner that violates the laws of armed conflict, it is unclear whether or how command responsibility could be assigned to the commander who approved the initial target package (although this remains an area of active consideration and debate). The Pentagon would benefit from expounding upon the specific target group definition to circumscribe potential edge cases.

Second, the Pentagon should think ahead to how its terminology will stay relevant as technology evolves. The company Scale AI, for example, has described what it calls “agentic warfare,” in which AI systems will go beyond “ingesting and correlating information” and instead use that data to “plan, test, and execute, multi-step actions.” Under this scenario AI agents would act as teammates with their human counterparts by synthesizing incoming data to provide commanders with proposed courses of action to give militaries a “decision advantage at every echelon of command.” It is not clear where this kind of AI use would fall on the Pentagon’s autonomy definitions or policy. Updates to the Directive would do well to reflect these new AI integrations into the kill chain, and to clearly compartmentalize which weapons systems belong in which categories, depending on their operational context.

In fact, the war in Iran illustrates that AI is already automating or advising on elements of the kill chain that arise before and after weapons are aimed and fired. And in the future, the “weapon system” may not be the primary place that autonomy lies; rather, individual weapons could be parts of a larger mesh of intelligent, interconnected platforms. This could place pressure on definitions and policies that focus on the weapon system itself. The White House memorandum provides an opening for the Pentagon to clarify these emerging issues.

Disputes over lethal autonomy will only grow. As AI becomes more deeply embedded in weapons platforms, command systems, and battlefield planning, arguments over where to draw the line will multiply. Decisions on how to develop and deploy these systems will rely not just on the opinions of experts in the bowels of the DoD and defense tech companies. They will require a broader democratic debate over what these systems can, and should, do. That debate will go more smoothly if the public understands what these systems actually are—and if the Pentagon, defense contractors, and outside experts can agree on definitions that keep pace with both the technology and the battlefield conditions in which it operates.

Filed Under

, , , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: