On March 11, eleven days into Operation Epic Fury, U.S. Central Command released a video in which Adm. Brad Cooper credited artificial intelligence tools with helping his forces hit more than 5,500 targets inside Iran. He attached a promise to the claim. “Humans will always make final decisions on what to shoot and what not to shoot and when to shoot,” Cooper said, as DefenseScoop reported.

By every public account, that promise had already been kept on the war’s first day, and it did not prevent the worst targeting error of the campaign. On Feb. 28, two Tomahawk missiles struck the Shajareh Tayyebeh elementary school in Minab, killing more than 150 people, at least 123 of them children, according to a Bloomberg investigation republished by the Los Angeles Times. Officials involved in an unreleased Pentagon inquiry told Bloomberg that a senior commander asked whether the target was lawful, whether the intelligence was sufficient and whether precautions had been taken, and that the answer to each was yes. People made the decision. Software had assembled much of what they were deciding on.

That gap is the subject of this article. The Pentagon policy now being rewritten on presidential order, Department of Defense Directive 3000.09, governs weapons that pick and attack targets themselves. The AI that U.S. forces used at scale this year sits one step earlier, in the software that proposes targets to humans, and the directive’s public text does not clearly reach it. The rewrite is five weeks past its deadline with nothing published, and the same argument over what a human must actually do is now running in Congress and at the United Nations in Geneva.

What the directive requires, and what it leaves alone

Directive 3000.09 dates to 2012 and was last revised in January 2023. Its core requirement is that systems be designed to let commanders and operators exercise “appropriate levels of human judgment over the use of force.” The Congressional Research Service, in a primer updated in March, is blunt about what that phrase does not mean. It does not prohibit lethal autonomous weapons, and it does not require a person to control each engagement. Judgment can be exercised earlier, in decisions about how, when, where and why a weapon is employed. A 2018 U.S. government paper quoted by CRS described “appropriate” as a flexible term whose meaning varies by weapon, domain and context.

The directive’s procedural teeth are a senior-level review. Covered systems need approval from the under secretary for policy, the vice chairman of the Joint Chiefs and the under secretary for research and engineering before formal development, and a similar sign-off before fielding. The deputy secretary can waive the review for urgent military need. CRS also lists what the directive excludes, including cyberspace capabilities, unarmed platforms and autonomous systems that are not weapon systems.

How often the review has been used is not publicly known. In 2023 a Pentagon spokesperson told DefenseScoop, “We cannot comment on the DOD Directive 3000.09 review process with regard to any particular weapon system.” The same report noted that in 2019 the department had said no weapon had yet been required to undergo it. Congress has since added reporting duties: notice of any change to the directive within 30 days, an annual report on approvals and deployments through 2029, and notice of any waiver, all summarized by CRS. None of those reports has been made public in the sources reviewed for this article.

A 90-day order with no public result

On June 5, President Trump signed National Security Presidential Memorandum 11. Section 3 orders the secretary to issue an update to Directive 3000.09 within 90 days and to review it annually, in order to ensure adoption of AI systems that “respect the chain of command and operational authorities.” The memo says nothing about what should change. Ninety days from June 5 fell on Sept. 3.

The memo’s main business lay elsewhere. It directs agencies to end contracts with companies that restrict government use of their AI, a provision that former officials told Breaking Defense grew out of the Pentagon’s fight with Anthropic. That company had refused to permit two uses of its Claude model, one of them fully autonomous weapons; chief executive Dario Amodei wrote in a public statement that “frontier AI systems are simply not reliable enough to power fully autonomous weapons.” CRS notes in a separate analysis updated Oct. 5 that the department is not publicly known to be using any frontier model inside an autonomous weapon.

Reaction to the directive order split along a predictable line. Michael Horowitz, who directed the Pentagon’s emerging capabilities policy office until 2024, wrote for the Council on Foreign Relations that an update was sensible, adding: “It all depends, of course, on the substance of the update, which remains unknown.” Retired Lt. Gen. Jack Shanahan, who founded Project Maven, told Breaking Defense that modest changes were achievable in three months and a deeper overhaul was not, warning that “speed without proper test and evaluation is a catastrophe waiting to happen.” Sen. Ruben Gallego of Arizona went further. In a June 12 letter obtained by DefenseScoop, he called the schedule “compressed,” asked for answers by June 26, and asked specifically how the new version would handle targeting recommendations produced by AI decision-support systems. No reply has been reported in the coverage reviewed for this article.

Nor has the directive. A Sept. 2 Washington Examiner commentary observed that the window was closing that week. Newsmax reported on Sept. 26 that the Pentagon had not publicly issued the revision, and the Oct. 5 CRS analysis still describes January 2023 as the most recent update. Whether a new version has been signed and withheld, is stalled in coordination, or has been overtaken by other priorities cannot be determined from public sources. Defense Secretary Pete Hegseth’s Sept. 30 announcement of a four-star Autonomous Warfare Command, as described by DefenseScoop, set an Oct. 1, 2027 target for the command and did not address the rulebook its forces would operate under.

Thirteen thousand targets and one school

While the paperwork lagged, the practice it is supposed to govern expanded. Cameron Stanley, the Pentagon’s chief digital and AI officer, said in September that Palantir’s Maven Smart System helped U.S. forces strike 13,000 targets in 38 days, according to DefenseScoop. “That’s using AI at scale,” he said. That works out to more than 340 targets a day. At the same event James Mazol, the deputy under secretary for research and engineering, said Maven’s user base had doubled since January to more than 100,000, and Deputy Secretary Steve Feinberg had already ordered the system made a formal program of record in a March 9 memo.

What is officially established about Minab is limited. Preliminary U.S. findings held that an American munition was likely responsible and that outdated intelligence likely led to the strike, NBC News reported in June, when it said Central Command had completed its investigation. That report has not been released. The United States has not publicly accepted responsibility, and the Pentagon’s stated position is that the matter remains under investigation. Casualty figures differ by source: Military Times, citing U.N. and Iranian officials, put the dead at 168 or more.

The fuller account rests on unnamed officials who spoke to Bloomberg. They described a site carried for years in U.S. databases as a Revolutionary Guard facility despite satellite imagery showing a walled-off school by 2017, an analyst’s 2019 note that sat in a system not connected to the targeting database, and target-list work that once took hours being compressed into minutes through Maven. Some Central Command personnel, the officials said, expected the software to flag stale or contradictory records. Why they expected that is unclear, Bloomberg reported. Civilian harm mitigation staff had been cut by roughly 90 percent across the department, with Central Command’s team reduced from 10 people to one, and nobody from those teams reviewed the site.

Palantir told Bloomberg it “is not responsible for the underlying data nor identifying intelligence deficiencies” and that no evidence shows its software was at fault. A U.N. fact-finding mission concluded the United States “failed in its obligation to do everything feasible to verify” the target; a senior administration official, asked about the strike, said: “The United States does not target civilians.” Bloomberg later reported that Central Command had changed its targeting workflow and that Maven received dozens of upgrades, according to a Moneycontrol summary of that reporting. A person familiar with the work told Bloomberg that new features which re-check underlying intelligence have already caught anomalies.

Two ways to close the gap, and the case against both

One response is to widen the directive. A June analysis from the Center for Strategic and International Studies argues that the definition of an autonomous weapon is still read through the drone or munition, and should extend to any software agent that can select and engage targets once activated. The Examiner commentary accepts that and adds an engineering demand: specify which decisions are reserved for a person, make the system technically unable to proceed without that authorization, and keep a record of what the machine recommended and what the human approved.

Witnesses at a Sept. 16 hearing of the Tom Lantos Human Rights Commission pressed the same point from the human side. “The approval button alone does not demonstrate the control,” the Ukrainian AI-governance researcher Anna Mysyshyn testified, according to C4ISRNet. Amnesty International USA’s Amanda Klasing proposed that the Pentagon’s annual civilian-casualty report to Congress state whether AI contributed to an incident, which current law does not require.

The strongest objection is that Minab, on the evidence so far, was not a failure of autonomy at all. The database entry was wrong before any algorithm touched it. Former officials have argued that people, not AI, were to blame, Military Times reported, and Carnegie’s Steve Feldstein told the Lantos hearing that AI can also help verify intelligence and detect changes in imagery, which is what the post-strike Maven upgrades reportedly do. On this view, targeting is already governed by the law of war, rules of engagement and intelligence standards; folding decision-support software into a weapons directive would put routine software updates through a senior review that, two scholars argued in War on the Rocks, is already the review under the sharpest time pressure from fast-changing machine-learning systems. The objection has force. It does not answer what the officials described to Bloomberg, which is that operators trusted the tool to do something nobody had assigned it to do, at a tempo that left little room to find out.

In Geneva, Washington defended judgment over control

The U.S. preference for “judgment” over “control” is also a negotiating position. In December 2025 the United States voted against a U.N. General Assembly resolution on lethal autonomous weapons that passed 164 to 6, after supporting similar texts in the two previous years, as a legal scholar recounted in Opinio Juris. He attributes the reversal to draft language on human control that Washington considered incompatible with Directive 3000.09.

The expert group working under the Convention on Certain Conventional Weapons adopted its final report in the early hours of Sept. 5. A Swedish researcher who served on her country’s delegation wrote that the human element was the last issue settled and that consensus was possible only on the formula “control and human judgement,” with the United States and India having long favored “human judgment.” Human Rights Watch says the United States and Russia insisted on removing references to predictability, reliability, explainability and traceability, and counts 76 states now backing treaty negotiations. European allies have argued the other side. The European Union’s stated position centers on meaningful human control, and France and Germany joined 37 other parties last year in calling the draft a sufficient basis for negotiation, though Britain did not, according to West Point’s Lieber Institute.

The decisions still open

Three decisions are pending, and each belongs to someone identifiable. Hegseth owes the White House a revised directive and, once it is issued, owes the defense committees an explanation within 30 days. Its scope is the open question: whether it stays confined to weapons that select and engage, or says anything about software that recommends. He also controls whether the Minab investigation is released or classified, which will determine whether the debate proceeds on findings or on leaks.

Congress has options that CRS has already laid out, including writing the directive’s requirements into law, adding notification duties or restricting funds for particular uses. A bipartisan AI bill introduced this month by Sens. Jim Banks and Kirsten Gillibrand concerns security reporting by AI contractors and does not touch targeting, DefenseScoop reported. And from Nov. 16 to 20, the parties to the weapons convention meet in Geneva to decide whether the September report becomes a mandate to negotiate, according to a member of the chair’s team. The U.S. delegation will have to take a position there, with or without a current directive of its own to point to.

TaggedPentagonDirective 3000.09Project MavenU.S. Central CommandCongressIranPalantir

This analysis draws on the public sources linked in the text. Send corrections to info@defenseautonomyreview.com.

More in AI & Autonomy