← Back to all writing

AI futures evidence — X3: LAWS & battlefield autonomy

July 5, 2026

Futures index · 中文 · Main forecast

Each section: Claim · Why · Evidence · Analogue · Would update if · Conf (H/M/L).


Covers: crosscut x3 laws battlefield autonomy
Parent: Shared Ci spine · 08 parallel spines
Date: 2026-07-05
Format: Claim | Why | Evidence | Analogue | Would update if | Conf

Each section documents one probability or timing claim. Probabilities are subjective elicitation unless noted as derived.


Hybrid timing

P(timing) — Partial battlefield autonomy modal window: now – 2027

Claim: AI in the kill chain (terminal guidance, onboard target ID, swarm coord) is operationally binding in at least one major conflict before C6 superhuman-coder calendar — no Ci gate.

Why: Ukraine TFL-1 combat use since Mar 2025; Israel SITS/Roem 360 fielded 2025–26; Russia Lancet AI modules under EW — all documented 2025–26, ahead of METR C6 “Emerging” tracker.

Evidence:

Analogue: Cyber capability (Node 8) — operational before policy salience; same hybrid rule.

Would update if: All major conflicts revert to manual-only FPV through 2028 with verified stand-down.

Conf: M–H


P(timing) — LAWS policy salience cluster: 2026 – 2028

Claim: DC/Geneva mainstream LAWS policy fights (3000.09 rewrite, CCW Review, NDAA reporting) peak 2026–2028, ~12–18 mo lag after battlefield proof points.

Why: NSPM-11 Jun 2026 triggers 90-day rewrite; CCW 7th Review Conference Nov 2026; S.4697/S.4707 Jun 2026 — capability already live 2025.

Evidence:

Analogue: Colonial Pipeline 2021 → statutory action 12+ mo; Fable Jun 2026 export recall without outage.

Would update if: Mass-casualty LAWS incident Q3 2026 → salience immediate (lag too slow).

Conf: M


Ukraine — FPV / terminal autonomy

P = 0.62 — >50% of frontline FPV-class strikes use terminal AI guidance in Ukraine-scale EW war by 2028

Claim: In the reference conflict (Ukraine or equivalent EW-heavy theater), majority of FPV sorties use onboard terminal guidance modules (TFL-class) not pure manual control.

Why: Fourth Law targets mass prod “every FPV”; Vyriy partnership Sep 2025; UB60D codified Apr 2026; CEO claims 6–9 mo to fit most frontline drones; fiber-optic supply constraints push autonomy.

Evidence:

Analogue: Smartphones replacing feature phones once module cost <20% — TFL claims 10–20% cost uplift.

Would update if: 2027 production data shows TFL attach rate <15% despite EW.

Conf: M


P = 0.35 — Ukraine fields fully autonomous target-select + engage FPV (no human target designation) at scale by 2028

Claim: ≥500/month sorties where AI selects target and executes strike without operator designating specific target pre-launch.

Why: Fourth Law roadmap aims “full-spectrum autonomy”; K2 Brigade chooses human-in-loop for ethics; most systems today are last-mile only; political/red-cross pressure.

Evidence:

Analogue: Autonomous trucking — geofenced full autonomy lags assisted highway by years.

Would update if: Official UA MoD doctrine mandates out-of-loop for interceptor drones against Shaheds at scale.

Conf: L–M


P = 0.48 — Ukraine ground UGV assault autonomy expands (robot-only trench capture class) 2026–28

Claim: ≥3 publicized robot-only or robot-led ground assaults/year with AI navigation + fire support.

Why: X2-A cites first trench capture robots-only Apr 2026; 22k+ ground robot missions claim; K2 ethics choice may not generalize.

Evidence:

Analogue: UAV transition 2010s — tactics follow once reliability proven.

Would update if: Zero documented UGV assaults 2027 despite continued war.

Conf: L–M


Replicator / US fielding

P = 0.45 — US cumulative Replicator 1 ADA2 fielding exceeds 2,000 units by 2028-12

Claim: Replicator + DAWG/SOCOM pipeline delivers >2,000 attritable autonomous systems to operators (not just prototypes).

Why: Aug 2025 deadline met with hundreds only; Hegseth claims “thousands more planned” FY2026 budget; DAWG two-year transition; historical under-delivery vs rhetoric.

Evidence:

Analogue: F-35 production targets vs actual — defense initiatives chronically slip quantity goals.

Would update if: DoD public cumulative count >1,500 in 2026 annual LAWS report (P.L.118-159 §1066).

Conf: L–M


P = 0.82 — Replicator program continues (not terminated) through 2028 despite under-delivery

Claim: Institutional continuity — budget lines, DAWG/JIATF-401, Replicator 2 C-sUAS — regardless of quantity shortfall.

Why: Iran drone incidents 2025–26; bipartisan attritable mass narrative; DIU→DAWG = reorg not cancel; Jan 2026 Replicator 2 contracts.

Evidence:

Analogue: FCS cancellation rare; more common is name change + repurpose.

Would update if: FY2027 budget zero Replicator reprogramming + DAWG disbanded.

Conf: M–H


Helsing / European supply

P = 0.58 — Helsing delivers ≥4,000 of 10,000 cumulative HX/HF orders to Ukraine by 2028

Claim: Despite Jan 2026 pause reports, majority of contracted HX-2/HF-1 units reach UA forces.

Why: Feb 2025 firm 6k+4k orders; Helsing disputes Bloomberg; HF-1 already delivering; pause may be additional orders not initial tranche.

Evidence:

Analogue: Skydio Ukraine underperformance 2024 — some systems fail, program continues at reduced rate.

Would update if: German MoD officially cancels remaining HX-2 tranche.

Conf: M


P = 0.40 — HX-2 field performance meets advertised AI terminal guidance specs

Claim: ≥70% mission success rate including EW-contested environments per advertised feature set.

Why: Bloomberg Nov 2025 internal brief: missing AI components, launch failures, jamming — Helsing disputes; too early for independent audit.

Evidence:

Analogue: Boeing KC-46 — fielded with persistent deficiencies.

Would update if: Third-party (RUSI/CSIS) audit confirms >70% success 2027.

Conf: L


US policy — DoD autonomous weapons

P = 0.75 — NSPM-11 DoDD 3000.09 rewrite eases procedural friction vs Jan 2023 text

Claim: Sep 2026 updated directive reduces senior review burden or expands exemptions for AI-enabled ADA2 — net acceleration.

Why: NSPM-11 rescinds NSM-25; 90-day compressed timeline; Trump admin explicit AI adoption push; Horowitz prior view “fundamentals sound” but NSPM language demands “deliberate adoption.”

Evidence:

Analogue: NSM-25 → NSPM-11 mirrors export-control loosening post-Fable partial lift.

Would update if: Final text adds mandatory third-party red-team for all ADA2 (strictening).

Conf: M


P = 0.88 — US policy does not require tactical human-in-the-loop through 2028

Claim: No statutory or directive change mandating continuous human oversight at engagement for all weapon systems.

Why: DoDD 3000.09 never required “in the loop”; CRS IF11150 Mar 2026 confirms “appropriate human judgment”; S.4707 emphasizes oversight but maximize autonomy policy language; NOTUS DoD quote “human in the loop for critical operational decisions” = rhetorical not legal.

Evidence:

Analogue: Phalanx CIWS — autonomous engagement decades without “loop” language.

Would update if: S.4697 passes with binding engagement constraints (Sec. 3(c)).

Conf: M–H


P = 0.12 — S.4697 (Schiff) or S.4707 (Coons/Reed) becomes law before 2028

Claim: Either bill enacts statutory design/safety/oversight requirements for autonomous weapons.

Why: Introduced Jun 8 2026, referred Armed Services; NSPM-11 headwinds; historical defense regulation bills stall unless tied to NDAA; oversight more likely via P.L.119-60 waiver notification than standalone ban.

Evidence:

Analogue: GUARD Act — introduced repeatedly, low pass rate for restrictive AI bills.

Would update if: S.4707 attached to FY2027 NDAA markup with bipartisan co-sponsorship >10.

Conf: M


CCW / UN talks

P = 0.08 — Binding CCW protocol on LAWS enters force by 2028

Claim: Legally binding instrument with definitions + prohibitions + verification adopted at Nov 2026 Review Conference and ratified by US + China + EU core.

Why: US/Russia oppose binding bans; CCW consensus rule; 10+ years GGE without instrument; rolling text still “elements” not treaty; China “when conditions ripe” framing.

Evidence:

Analogue: CCW blinding laser protocol 1995 — succeeded on narrow scope; LAWS scope broader → harder.

Would update if: Mar/Aug 2026 GGE adopts mandate to negotiate binding protocol with ≥120 HCP support.

Conf: M


P = 0.42 — CCW Nov 2026 produces non-binding “elements” document only (no negotiating mandate)

Claim: Review Conference kicks can — reaffirms GGE work, no protocol launch.

Why: Modal outcome for CCW on emerging tech (cyber norms parallel); US prefers national review; Russia obstruction history.

Evidence:

  • UN GGE chair summary WP.2 Apr 2026 — incremental rolling text
  • Global Security Review — US resists binding framework

Analogue: Decades of UN cyber norms process — talk without enforcement.

Would update if: EU breaks from CCW to Oslo-style standalone treaty with ≥30 signatories 2027.

Conf: M


P = 0.10 — Empty-shell LAWS treaty increases deployment (complacency)

Claim: Signed instrument without verification P(CX-LAWS-ESCALATE) by ≥5pp vs no treaty.

Why: N9 CX-EMPTY-TREATY logic — stakeholders claim compliance while expanding; “MHC” rhetoric without audit.

Evidence:

  • (internal note) — CX-EMPTY-TREATY P≈0.10
  • ICT4Peace — divergent US/EU/China positions on MHC

Analogue: Paris climate pledges without enforcement — symbolic compliance + continued emissions.

Would update if: Treaty includes third-party audit of target-selection algorithms → complacency path weakened.

Conf: L–M


Israel / Gaza drones

P = 0.70 — Israel maintains “human authorizes strike” doctrine while expanding onboard AI target pipeline

Claim: SITS/Roem/Lavender-class systems automate detection/classification; public doctrine retains human strike approval through 2028.

Why: IDF messaging; Haaretz docs show intel generation not autonomous strike; Time 2024 Lavender still human-approved strikes; legal exposure if full autonomy admitted.

Evidence:

Analogue: US drone program 2000s — “man in loop” legal frame + expansive target lists.

Would update if: IDF official documents autonomous engagement without operator per sortie.

Conf: M


P = 0.55 — Roem 360-class swarms used in ≥5 major operations/year through 2028

Claim: Semi-autonomous drone swarms become routine IDF combined-arms tool.

Why: IDFclub Jul 2026 reporting — operational since 2025; Iran front 2026 expansion; swarm counters enemy drone swarms.

Evidence:

Analogue: Iron Dome — rapid normalization once proven.

Would update if: Swarm program frozen after documented fratricide/failure rate >30%.

Conf: L–M


China / Russia LAWS

P = 0.65 — China operationalizes swarm autonomy beyond demo (Atlas-class) in military exercise or export conflict by 2028

Claim: Not just Mar 2026 CETC demo — fielded or exported system with ≥20 drone coordinated AI strike.

Why: Intelligentized warfare doctrine; GJ-11 testing; Chinese armed drones in ≥12 conflict zones (Lieber); demo → fielding pipeline 12–24 mo.

Evidence:

Analogue: DJI commercial drone dominance → military export follow-on.

Would update if: 2027 shows zero follow-on Atlas deployments + PLA exercise reports manual-only.

Conf: M


P = 0.72 — Russia expands EW-resilient terminal autonomy (Lancet/FPV class) despite sanctions

Claim: Production of Jetson/open-weight-based target ID modules on attritable munitions.

Why: CSIS Apr 2026 — pragmatic applied AI; Putin Jun 2025 armament program AI emphasis; battlefield necessity under GPS denial.

Evidence:

Analogue: Iran Shahed scaling under sanctions — attritable mass beats quality.

Would update if: Documented production collapse 2027 from component shortage without substitute.

Conf: M


P = 0.85 — China and Russia oppose binding LAWS ban at CCW through 2028

Claim: Both states block consensus on prohibitions; prefer IHL + national review framing.

Why: Global Security Review; UN 2026 GGE positions; China distinguishes “acceptable” vs “unacceptable” autonomy — not full ban.

Evidence:

Analogue: Nuclear test ban — P5 fracture on verification.

Would update if: China co-sponsors prohibition protocol text at GGE.

Conf: M–H


Human-in-loop vs out-of-loop

P = 0.78 — Modal deployed systems remain “human-on-the-loop” or human-initiated through 2028

Claim: ≥75% of AI-assisted strike sorties in major conflicts have human authorize category or target before autonomous terminal phase.

Why: Doctrine + law-of-war framing; Ukraine/Israel public statements; technical reality = last-mile autonomy most valuable under EW.

Evidence:

Analogue: Cruise missiles — human picks target package, missile executes.

Would update if: Documented doctrine change in ≥2 militaries to out-of-loop area engagement.

Conf: M


P = 0.22 — At least one major military openly fields out-of-loop anti-personnel/select-and-engage system by 2028

Claim: T-X3-E threshold — public acknowledgment, not leak only.

Why: Interceptor drones vs Shaheds pressure; China demo claims; Russia attrition math; taboo still strong — 0.22 not 0.50.

Evidence:

  • Fourth Law full-autonomy testing (DroneXL)
  • T-X3-E branch table in main cross-cut

Analogue: Chemical weapons use denial vs attribution — covert use precedes open doctrine.

Would update if: CCW emergency session after documented out-of-loop massacre.

Conf: L–M


Spillover to domestic robot policy

P = 0.70 — Battlefield autonomy expands without US domestic industrial robot moratorium through 2029

Claim: Same as X2-A P=0.70 — DoD lane separated from OSHA/DOL embodied-AI.

Why: Replicator continues; no moratorium bill passed; policy coalition split (natsec hawks vs labor).

Evidence:

  • (internal note) §P=0.70
  • No federal embodied-AI ban in (internal note) Tier 1

Analogue: Military drone expansion 2000s — no domestic robot ban.

Would update if: T-PA3 — US AI module attributed in >50 civilian deaths → moratorium bill 90 days.

Conf: M


P = 0.12 — Domestic moratorium from battlefield incident by 2028

Claim: Federal restrictions on both LAWS export and commercial humanoids/AMRs following salient autonomous strike attribution to US tech.

Why: T-PA3 P≈0.08 in X2-A; LAWS-specific incident slightly higher salience than warehouse fatality; still low base rate for binding federal action.

Evidence:

  • (internal note) §T-PA3
  • Pope encyclical LAWS ban — rhetorical not statutory ((internal note) Pope Leo XIV)

Analogue: Post-Vietnam tech export controls — narrow not blanket.

Would update if: Bipartisan majority House vote on LAWS ban 2026 session.

Conf: L–M


Attribution failures

P = 0.04 — Mass-casualty strike (>50 civilians) misattributed to wrong state’s AI module by 2028

Claim: International crisis where blame assignment errors drive escalation rhetoric or limited retaliation.

Why: Swarm + third-party modules (TFL, Palantir, Helsing) complicate chain; base rate low for >50 deaths + wrong attribution confirmed; cyber attribution difficulty analog.

Evidence:

Analogue: MH17 2014 — attribution took months; near-misses on escalation.

Would update if: Two incidents 2026–27 with IC split on attribution of autonomous strike.

Conf: L


P = 0.18 — Attribution dispute delays LAWS restraint treaty ≥12 mo even after incident

Claim: After salient civilian harm, states dispute whether system was autonomous / whose software → diplomatic paralysis.

Why: Lavender/SITS/Gospel reporting controversies; Russia/Ukraine mutual accusations; CCW consensus.

Evidence:

  • Haaretz/Wikipedia AI-assisted targeting debates
  • ICT4Peace — CCW challenges remain

Analogue: Syrian chemical attacks — attribution fights blocked action.

Would update if: Incident with open-source chain-of-custody to US vendor → fast UN Security Council session <30 days.

Conf: L–M


Race narrative

P = 0.68 — LAWS deployment materially strengthens “must match China/Russia” race argument in DC through 2028

Claim: ≥3 major hearings or NDAA provisions cite adversary LAWS as justification for accelerating US AI adoption (not restraining).

Why: NSPM-11 framing; Atlas demo; Ukraine lessons; Grok/Pentagon vs Anthropic contrast Feb 2026; Node 3 cluster A.

Evidence:

Analogue: Sputnik → ARPA — adversary demo accelerates funding.

Would update if: Binding US LAWS ban passes → narrative inverts.

Conf: M


P = 0.35 — Frontier AI lab refusal to support LAWS (Anthropic-class) remains ≥2 viable vendors through 2028

Claim: Not all labs sign “all lawful purposes” — bifurcation persists.

Why: Anthropic Feb 2026 Pentagon standoff; Amodei adolescent-of-tech lines; commercial cost of brand damage; but xAI/Grok counterexample.

Evidence:

  • (internal note) — Grok vs Anthropic Feb 2026
  • (internal note) — Amodei five risks

Analogue: Google Project Maven resignations 2018 — partial vendor split.

Would update if: Anthropic signs LAWS-class DoD contract with autonomous strike component.

Conf: M


CX-LAWS-ESCALATE & EV-LAWS-MASS

P = 0.72 — CX-LAWS-ESCALATE: LAWS expands without international restraint through 2028

Claim: Headline crux — no binding restraint; deployment across ≥5 states.

Why: Synthesis of CCW P(binding)=0.08; US acceleration P=0.75; Ukraine/Israel/Russia/China/US fielding; empty treaty tail 0.10.

Evidence:

Analogue: Cold War autonomous air defenses — spread without treaty.

Would update if: CCW binding protocol or US statutory ban (see falsifiers).

Conf: M


P = 0.78 — EV-LAWS-MASS strict trigger by 2028-12

Claim: ≥3 states, ≥1,000 cumulative AI-assisted strike systems in active combat, no new binding restraint.

Why: Trajectory from 2025–26 partial autonomy; production run-rates (TFL hundreds of thousands/mo capacity claim, Helsing 1k/mo, Replicator scaling); strict threshold not yet met on cumulative count.

Evidence:

Analogue: Nuclear threshold states — gradual then sudden mass.

Would update if: Major conflict ends with verified demobilization of AI strike systems.

Conf: M


P = 0.85 — EV-LAWS-MASS lenient trigger already satisfied (2026-07)

Claim: ≥3 states deploy AI-assisted strike in combat without binding treaty — already true.

Why: Ukraine, Russia, Israel active; US Replicator-class fielding; China demo + drone exports.

Evidence:

  • Main cross-cut §Verified baseline 2026-07

Analogue: Cyber capabilities — threshold crossed before policy noticed.

Would update if: Binding protocol retroactively claimed to cover existing systems with enforcement — semantic dispute.

Conf: M–H


P(war x-risk channel) = 0.015 — LAWS incident is primary trigger for US–China kinetic exchange by 2030

Claim: P(<0.02 aligned with Node 3 T1 Taiwan ~0.03 and Node 8 P(kinetic|cyber)<0.03).

Why: LAWS incidents more likely regional (Gaza, Ukraine) than Taiwan; great powers exercise escalation control; cyber preferred to kinetic for TSMC scenarios.

Evidence:

  • (internal note) §P=0.97 no kinetic from cyber
  • (internal note) §14 — Stuxnet rarity

Analogue: Downing of passenger jets — crisis without great-power war.

Would update if: US strike on PRC autonomous naval system directly triggers PRC counter-kinetic 2027.

Conf: L


P = 0.08 — LAWS norm erosion adds ≥0.5pp to misalignment extinction conditional on C9+ scheming

Claim: At superhuman agent tier, pre-normalized autonomous kill chains lower barrier to physical harm — conditional not unconditional ext .

Why: C9–C10 embodied + LAWS actuator channel in X2-A; scheming + drone fleet > chat-only; requires misalign tail already live.

Evidence:

  • (internal note) §Ci C9–C10
  • (internal note) — L3 embodied locus

Analogue: Nuclear command pre-delegation debates — lowers launch latency in crisis.

Would update if: Global LAWS ban with compliance before C8 → conditional to <0.03.

Conf: L


P = 0.25 — LAWS race (T-X3-D) correlates with Node 3 acceleration cluster — joint P ≥0.40 that both fire

Claim: ρ(LAWS escalate, N3 modal theft/race) ~0.35; joint probability material for headline ext reweight.

Why: Same natsec actors; NSPM-11 bundle; vendor capture; Cluster A in crosscut secondary cruxes.

Evidence:

  • (internal note) §8 Cluster A
  • Main cross-cut §T-X3-D

Analogue: Export controls + offensive cyber post-SolarWinds — correlated acceleration.

Would update if: US–China dual LAWS moratorium bilateral 2027 → joint <0.15.

Conf: L–M


Public opinion / advocacy

P = 0.58 — US public supports international treaty prohibiting autonomous weapons (PPC/UMD 2024 class) but does not block deployment

Claim: Poll majority for treaty; no electoral binding on DoD LAWS through 2028.

Why: (internal note) — majority support treaty prohibiting AI-controlled autonomous weapons; low salience vs economy; natsec exception framing.

Evidence:

  • (internal note) — PPC/UMD 2024
  • Modal path — federal ban <0.05

Analogue: Gun background checks — high poll support, low pass rate.

Would update if: LAWS become #1 issue in 2028 presidential primary polling.

Conf: M


P = 0.45 — Edge AI chip supply for LAWS constrains mass fielding more than policy through 2028

Claim: Jetson-class, custom ASIC, EW-hardened modules — not FLOP/datacenter cap — bind Replicator/TFL scale.

Why: TFL emphasizes cheap mass-producible module; Replicator under-delivered despite policy push; semiconductor export controls on edge chips secondary to datacenter.

Evidence:

  • CSIS Russia — Western/Chinese chips in Lancet despite sanctions
  • Fourth Law — hundreds of thousands/mo capacity claim vs actual attach rate gap

Analogue: Physical economy limits — energy binds Ci; different supply chain for edge.

Would update if: Verified >2M TFL modules deployed 2027 — supply not binding.

Conf: L–M


Summary table (headline P’s)

PClaimConf
0.72CX-LAWS-ESCALATE holdsM
0.70No domestic robot moratorium from battlefieldM
0.68LAWS strengthens race narrative in DCM
0.62>50% FPV terminal AI guidance in EW warM
0.08Binding CCW LAWS protocol by 2028M
0.12Domestic moratorium from battlefield incidentL–M
0.04Mass-casualty misattributed strikeL
0.015LAWS primary trigger US–China kineticL

Update log

DateChange
2026-07-05Initial 28 sections; links to X3 cross-cut + parallel spines