The New York Times reported today that Russian attack drones used in a coordinated strike last month in Ukraine were found to have contained Nvidia chips commonly used in robotics to process camera feeds and run small AI control models. The small fixed-wing drones, said to have contained unencrypted images of the types of propane tanks around a gas station they seem to have been aimed at, may be the first hard confirmation that the war has escalated to a new tier of weapon autonomy. In this tier, humans designate only a target area and the type of target they are interested in, and it is up to the weapon to identify and select its mark once it gets a close look at the neighborhood.
This advancement may not yet be a huge leap over traditional “last mile” targeting systems developed as far back as the 1980s, which share AI guidance’s chief benefit of being immune to electronic jamming. But I suspect AI-enhanced versions will be better at overcoming target concealment and perhaps at getting around obstacles like the anti-drone netting that has become a fixture in Zaporizhzhia, the site of the Russian strike.
They may also be better at operating in a swarm, spreading warheads across more targets and simultaneously diving at them from multiple angles. This was probably not a feature of the half-dozen or so Russian drones used in the July attack, which may not have needed visible antennas to coordinate with each other at close range but were also said to not be emitting radio signals. In theory, I can see ways drones might coordinate purely by visually observing each other, much as flocks of birds do. But the expended drones seem to have been pretty rough and minimal.
The Times journalist behind the piece, Andrew E. Kramer, deserves a nod for understanding the fundamental trade-off of machines directed by the kinds of neural-network-based AI that dominate the field today:
While traditional software follows step-by-step rules written by a person, an A.I. system derives its own rules by finding patterns across enormous amounts of data, a process called machine learning. That allows it to manage unanticipated situations. It also means no one can fully predict what it might do.
That uncertainty becomes an extinction-level concern once models are more cunning than humans. In today’s autonomous weapons, it’s a source of potential war crimes. One of the drones in the Zaporizhzhia attack killed three civilians when it struck an apartment building near its likely intended target.
The investigation appears to have benefited from at least one drone that did not explode and was recovered mostly intact. The Nvidia chip inside was a Jetson Orin, which costs only a few hundred dollars. The company says it doesn’t sell these in Russia, but that they are widely resold on the open market.
I worry that cheap AI-powered drones like this will become a weapon of choice for terrorists and Iran-style rogue states, because the kinds of high-value soft targets that a small drone can knock out are going to be hard to defend against jam-proof weapons that can defeat netting and concealment. The inner line of hard-kill defenses against such threats is literally hit-or-miss, usually amounting to guy-with-a-shotgun.
The commander of air defense in Zaporizhzhia thinks he knows where this technology is headed:
This is a risk for the whole world. In a few years, we will be living in a ‘Terminator’ movie. It’s no joke. Machines are making decisions to strike.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.



