Autonomous Weapons and AI in War: What the Latest Warnings Mean
The UN and ICRC warned in August 2026 that the world is dangerously close to letting machines autonomously target humans. Here's what happened and why it matters.

In August 2026, UN Secretary-General António Guterres and ICRC chief Mirjana Spoljaric Egger issued a joint appeal warning that the world is "dangerously close to crossing a moral red line: the autonomous targeting of humans by machines." The warning comes as the US 2027 defence budget earmarks $13.4 billion for autonomous systems, the IDF's AI-assisted targeting in Gaza generated 37,000 individual targets, and Anthropic found itself blacklisted by the Pentagon after pushing back on military use of its technology.
What happened
| Fact | Detail |
|---|---|
| Joint UN/ICRC appeal issued | August 2026 |
| US 2027 defence budget total | $1.5 trillion |
| Allocated for autonomous systems | $13.4 billion |
| IDF AI targets generated (Gaza war) | 37,000 individual targets |
| Anthropic blacklisting ruled unlawful | August 27, US District Court, Northern District of California |
| Stop Killer Robots coalition formed | October 2012, launched 2013 |
| UN/ICRC first called for binding treaty | 2023, deadline set for 2026 |
UN Secretary-General António Guterres and ICRC President Mirjana Spoljaric Egger jointly called in August for prohibition of two categories of autonomous weapons: unpredictable autonomous weapons and anti-personnel weapons. The appeal followed a 2023 call from the same bodies asking countries to negotiate a legally binding agreement by 2026. That deadline has now passed with no binding treaty in place.
Mélanie Régimbal, the UN’s chief of disarmament affairs, described systems that select and engage targets without human control as “politically unacceptable, morally repugnant and should be prohibited under international law.” Laurent Gisel, who heads the arms and conduct of hostilities division at the ICRC, framed the core technical problem bluntly: a combatant can surrender or be wounded, civilians can enter an operational zone, and situations can arise that no programmer anticipated. “If it’s not possible to predict it, then how is it possible to limit it,” Gisel said.
The AI systems already deployed in active conflict
Within the first weeks of the Gaza war, which began on October 7, 2023, the Israeli Defense Forces used an AI decision-support system called Lavender to generate 37,000 individual targets, ranked on a crude scale based on affiliations with armed groups. Two other IDF systems were also named: The Gospel, which produces target lists, and Where’s Daddy?, a platform that tracks individuals’ locations before a strike is ordered.
According to the article, the US and Israel launched strikes on Iran two days after Anthropic co-founder Dario Amodei made a public statement about AI and military use. Those strikes relied in part on Palantir’s Maven Smart System, which integrates Anthropic’s Claude AI to assess surveillance data, produce target lists, and prioritise them. Noor Hammad of the International Institute for Strategic Studies noted that many targets hit in Iran were civilian, including a school and healthcare and residential facilities.
The Anthropic situation: a falling out with the Pentagon
Anthropic disagreed with the US Department of Defense over limits on autonomous systems in warfare. The Pentagon responded by blacklisting the company as a “supply-chain risk.” On August 27, the US District Court of the Northern District of California found that blacklisting to be unlawful retaliation, in violation of the First Amendment, and a denial of due process under the Fifth Amendment.
Amodei’s public position is notably mixed. In February he conceded that the Pentagon, not private companies, makes military decisions, and stated that Anthropic has “never raised objections to particular military operations.” He also said fully autonomous weapons “may prove critical for our national defense.” His stated concern is reliability: “We will not knowingly provide a product that puts America’s warfighters and civilians at risk.” At the same time, he warned that AI mass domestic surveillance and fully autonomous targeting systems present “serious, novel risks to our fundamental liberties.”
That tension between commercial and ethical positions is worth watching closely, especially for businesses evaluating AI vendors. We covered a related shift in how AI labs handle safety commitments in our piece on OpenAI’s new disclosure framework after rogue agent incidents.
Why it matters
The $13.4 billion earmarked in the 2027 US budget for autonomous systems signals that spending on this technology is accelerating, regardless of what any UN appeal says. The Stop Killer Robots coalition, active since 2013, has not produced a binding international treaty. The 2026 deadline came and went.
Gisel confirmed as of late August that there is no confirmed evidence of fully autonomous weapons directly targeting humans on a battlefield. But the gap between that statement and the AI-assisted targeting systems already in active use is narrower than most public discourse acknowledges.
For businesses building on top of AI platforms: the Anthropic case is a live example of what happens when a vendor’s terms, safety commitments, or public positions conflict with a major customer’s use case. That customer was the US military, but the dynamic appears in enterprise software contracts regularly.
Our take
The moral arguments from the UN and ICRC are clear and have been clear since 2023. The problem is enforcement. No binding treaty exists, military budgets are growing, and the AI systems generating target lists are described as decision-support tools rather than fully autonomous weapons, a framing that sidesteps the prohibition debate almost entirely.
Anthropic’s position is the most instructive part of this story for our readers. A company can publish safety principles and still have its technology integrated into military targeting pipelines. The court ruling protecting Anthropic from Pentagon blacklisting is a win for due process, but it does not change the fact that Claude is running inside Palantir’s Maven Smart System. Words in an acceptable use policy do not automatically constrain deployment.
If you are a business owner choosing an AI platform for sensitive applications, the lesson is to read the supply chain, not just the terms of service. Understanding how AI integration works at a systems level matters more than vendor marketing. And if you are tracking how AI policy is evolving, the Anthropic court case will be worth following into 2027.
Frequently asked questions
Has any country used fully autonomous weapons to target humans in battle?
As of late August 2026, the ICRC's Laurent Gisel stated there is no confirmed evidence that autonomous weapons have been used to directly target human beings on a battlefield. However, AI-assisted decision-support systems such as Lavender have been used to generate target lists in active conflicts.
Why was Anthropic blacklisted by the Pentagon?
Anthropic was blacklisted by the US Department of Defense as a supply-chain risk after the company disagreed with the Pentagon over limits on autonomous systems in warfare. A US federal court ruled on August 27 that the blacklisting was unlawful retaliation violating the First and Fifth Amendments.
What is the Lavender AI system used by the IDF?
Lavender is an AI decision-support system used by the Israeli Defense Forces. Within the first weeks of the Gaza war starting October 7, 2023, it was used to generate 37,000 individual targets ranked on a scale based on affiliations with armed groups.
What is the UN's position on autonomous weapons in 2026?
The UN Secretary-General and ICRC chief issued a joint appeal in August 2026 calling for prohibition of unpredictable autonomous weapons and anti-personnel autonomous weapons. The UN's disarmament chief described systems that select and engage targets without human control as politically unacceptable and morally repugnant.


