Early September, a distant United Nations hall in Switzerland, hundreds of diplomats. On the table was the most far-reaching attempt yet to regulate lethal autonomous weapons, the first agreement on artificial intelligence in killing. On the final day, the tone changed.
Over roughly 15 hours, American and Russian diplomats went through the draft and cut out what stood in their way. According to three people familiar with the talks and documents underlying the process, the requirement that the systems operate predictably and reliably was removed. The obligation to take ethical considerations into account was removed. And the one clause that ultimately mattered most was removed as well, the one requiring a human being to review targets selected by artificial intelligence before an attack.
UN Secretary-General António Guterres warned on September 22, 2026: “Children must never become test subjects for unregulated systems. Decisions over life and death must never be handed over to machines.” Killer robots had no place in our future.
The final hours took place behind closed doors. Cameras off. Civil society observers outside. Washington and Moscow each brought around 10 lawyers, almost twice as many as the other delegations, and the changes came so quickly that smaller countries lost track. One participant called it death by 1,000 paper cuts. Neither the U.S. nor Russian foreign ministry commented, and the United Nations remained silent as well.
The human being gets written out of the text
First the words predictable and reliable disappeared. Then explainable and traceable. Human Rights Watch confirms that these safeguards vanished from the final version. A word in a treaty is a brake if someone pulls it. In a weapon, a wrong classification becomes a dead human being, and that is why this loss mattered most. Verity Coyle of Human Rights Watch says it plainly. Weak rules could lead to machines making life-and-death decisions without a human being stopping them. She expects more civilian harm and less accountability. Warfare, she says, is also sliding more quickly into automation. Coyle knows the approach: When Washington wants to preserve a military or technological advantage, it pushes for voluntary guidelines instead of binding rules, as it has before in cyber and space.
What was cut was no technicality. A signature under an order to kill requires a human being who hesitates for a moment. That is exactly the human being they took out of the text. If a system selects its own target and there is no mandatory review beforehand, the path from sensor to impact runs without a stop. Then there is no conscience left between suspicion and impact, only the process. The contradiction is sitting in plain sight. While Washington weakens international rules for lethal AI, the Pentagon is pushing the same technology deeper into its own warfare. At the same time, the United States is rewriting its 2023 directive on autonomous weapons. That directive contained several clauses similar to those now removed from the Geneva text, including the requirement for human judgment in autonomous and semi-autonomous systems and compliance with the laws of war. Trump ordered it revised within 90 days in June. By the end of September, no new version had been released. What Washington deletes abroad, it is reviewing at home in the same breath.
The technology is already at war
The technology is already in the field. In the war against Iran, the U.S. military used an Anthropic chatbot and had it identify nearly 1,000 targets in the first 24 hours. Israel relies heavily on artificial intelligence in its operations in Gaza. AI companies have acknowledged that their systems independently attacked servers belonging to other organizations, including U.S. government websites. Actors in countries such as Yemen and Iran reportedly used chatbots to build weapons or target the U.S. military. The documents do not clearly show which side was responsible for which activity. An Anthropic researcher quit this month and warned that artificial intelligence could wipe out humanity.



Precision is the promise used to sell these weapons. We stood there for weeks in Iran and saw what was left of that promise. Often there was no recognizable warning at all. Things were hit that were never supposed to be hit, civilian homes, even in the middle of Tehran. We documented it and archived it. Documents were passed on, and some of the material is still with us today, for the day when it too ends up before international courts.
The school in Minab stays with us the most. From that experience comes one demand, and there is no discount on it: As long as no human being is required to keep a hand on the trigger, none of these machines has any business being there. A computer inherits every mistake it is fed. Outdated data and mixed-up targets do not become true because software reads them. A blind sensor stays blind, sloppy analysis stays sloppy. The only thing that changes is the speed at which the mistake runs through the system. One fallible judgment is exchanged for another and the exchange is called progress. A machine strikes, it does not weigh. A machine carries out, it does not take responsibility. In peacetime, that would be a typo. Here, it costs lives.
At the same time, Sam Altman of OpenAI and Dario Amodei of Anthropic called on governments before the United Nations Security Council to work together. Regulation, Altman said, had to grow out of democratic processes, carried by governments accountable to their citizens. Even the people building the technology are warning about their own creation. Their calls go nowhere as long as the most powerful government rejects any binding limits. Trump openly opposed them before the United Nations. The United States rejected any attempt to create a globalist system for artificial intelligence, he said, and referred to super intelligence. His administration sees every rule as an obstacle to innovation. What is dismissed at home as bureaucracy determines abroad how far a weapon may go without a human hand.
Trump said before the UN General Assembly on September 22, 2026, that “Artificial Intelligence” sounded artificial and therefore “fake.” He said he wanted to call it “Super Intelligence” from now on.
The world is not silent
This is not a silent world. 76 countries now support negotiations on legally binding rules. 70 of them belong to the Convention on Certain Conventional Weapons, meaning a majority of its voting members. Never before has such a broad majority stood behind a binding treaty. Brazil and Ireland are among them, along with several African countries.

Putin and Trump are gambling away a world that never belonged to them and sending the bill to everyone else. They are driving humanity toward a line beyond which neither a court nor a voter can undo what happened. Their departure from power will not be celebrated, it will be the quiet astonishment that the world somehow made it through one more time.
On the other side stands Washington, with Russia beside it. India and Turkey also prefer nonbinding guidelines. Switzerland opposed the deletions and argued that the language in question was already grounded in existing humanitarian law. Sri Lanka went further and warned that indirect human control could effectively allow machines to attack without ongoing oversight. Its delegation called for binding minimum requirements and the ability to shut a system down in time. Australia takes a middle position and does not want human control turned into a separate legal standard. Turkey explicitly rejects a binding treaty. Armenia warned of the risk that such technology could be transferred or diverted until it ended up with smaller states or other actors.
Washington did not limit itself to arguing at the table. According to the information available, it approached at least six countries diplomatically to support its softer language in the text. The American team is led by State Department diplomats. Pentagon specialists and lawyers work alongside them. Coyle describes the team as well resourced and focused on defending U.S. military independence. Nicole van Rooijen of the Stop Killer Robots campaign says Washington and Moscow reject binding rules and have enough influence to slow the progress wanted by a large majority. Unanimity is required, and that means the will of 2 powers is enough to stand against the will of many.

When mistakes move faster than doubt
The greater danger is not the individual missed strike. It is the speed. A human being can hesitate and ask questions, can call off an attack. A machine puts detection and attack into the same blink of an eye. The more countries operate that way, the closer we get to an escalation in which politics responds only after the weapons have already acted. The military logic behind it is cold. Opponents rely on mass, cheap drones and large numbers of missiles. The answer is speed, more targets in less time. That became visible in Ukraine and in the war against Iran. The task is no longer one target. It is many at once.
With speed, responsibility starts to blur. If an autonomous weapon hits the wrong thing, it remains unclear who answers for it, the human being at the screen or the state behind him. International law was written for decisions made by people. Guilt looks for someone who chose. When the choice breaks apart into milliseconds, guilt finds no one anymore, and where no one is accountable, the hesitation to launch the weapon drops.

The document in our possession from August 31, 2026, shows a proposal from the UN negotiations on lethal autonomous weapon systems. Paragraph 25 is decisive: Under the proposal, a system is considered autonomous if it can identify, select and engage targets with lethal force without a human being intervening during that process. Prior programming or defining possible target categories by humans does not exclude the system from that definition. Systems would only fall outside it if humans themselves determine the specific target and the timing of the attack. The text is not yet a binding treaty, but a working proposal from the chair for the next round of negotiations.
With every system that keeps its own soldiers out of the line of fire, the political cost of an attack falls. When one power avoids binding limits while pushing its military AI forward, it pressures others to follow. No one wants to automate more slowly than a potential opponent. The old security dilemma returns, only with artificial intelligence it moves faster than it did with earlier generations of weapons.
A false AI report, armed soldiers, aircraft already launched

Where all of this can lead became clear in the spring of 2026. In the Persian Gulf, in the middle of the U.S. war against Iran, the military received an intelligence report claiming that a Chinese ship was carrying components for a military nuclear program into the Middle East. The command prepared to act. According to several people familiar with the matter, armed troops had prepared to board the vessel and aircraft had already taken off. Only immediately before the operation did someone take a close look at the report. An analyst with a special operations command had used an AI chatbot, and it had misidentified the ship's cargo. One person described the report as completely false. An armed seizure of a Chinese ship could have triggered a direct confrontation between Washington and Beijing. A false line in a computer had turned into armed men and aircraft in the air.
The incident did not hit a system unfamiliar with such errors. According to several people involved, false outputs from these programs had already made their way into intelligence reports before. Younger analysts in particular reportedly trusted the tools too much and accepted their results without asking enough questions. There were no uniform verification rules. Different agencies used different systems and followed their own standards. A former senior official described the internal tools as the same commercially available products, just dressed up. One person summed it up in a single sentence: Artificial intelligence makes it possible to get to a bad idea faster. A computer can be wrong without shame and without memory. The consequences fall on people who have both. The machine does not have to give an order to influence an order. It is enough for its answer to be treated as reliable. Between a fast analysis and a fast bad decision, there is often only one question: whether anyone still allows doubt.

At first glance, it is only a small table. But right in the middle of administration, suicide prevention, and programs against sexual violence, the very item that is supposed to record and limit civilian harm disappears. Measures to limit civilian harm and respond to it still appeared the previous year with 259. After that, nothing. No expansion, no continuation, not even a remaining amount. This is not a technical process and not a minor cut. What is removed is precisely the area that even records what military force does to civilians. Everything else continues. This part does not.
The near-operation does not stand alone. The units behind it are not new. Special operations forces such as the Navy SEALs, Delta Force and the Green Berets have made targeted killing a tool since the September 11 attacks. That logic matured over 2 decades, and now it is accelerating. In our investigation into the Pentagon's autonomous warfare center, we found the creation of a Special Operations Forces Autonomous Warfare Center in a budget request exceeding $1.5 trillion. The programs can already collect data and select targets from it. Only the human being still stands between selection and attack. At the end is a point on a map, a target. The same document no longer carries forward the line item for tracking civilian harm, which had still been listed as 259 the previous year. The capability gets faster, the safeguard disappears. Admiral Brad Cooper insists that a human being always decides what gets attacked and what does not. But that human being becomes the bottleneck the moment a system can analyze and flag in seconds, and no military tolerates a bottleneck forever.

In the budget, it appears almost unnoticed, nearly hidden between columns of numbers and standard language. Yet that is exactly where the real break appears. U.S. Special Operations Command is asking for additional funding to expand the striking power of its forces - more presence, more projection, more reach. Behind it lies more than conventional rearmament. It is the next step. The request explicitly calls for the creation of a “Special Operations Forces Autonomous Warfare Center.” A center that does not replace existing structures, but compresses them. Intelligence, analysis, target selection - everything gets pulled closer together, made faster, connected more directly.
The justification follows the familiar line. Growing threats, global deployments, increasing pressure on special forces. At the same time, it becomes clear where the system is shifting. No longer just support for operations, but the automation of those very processes. What is striking is what happens alongside it. While new capabilities are built, space disappears elsewhere. Programs for assessing civilian harm no longer appear in the request. The part that could evaluate and restrain is not continued. It is written in black and white in a document that hardly anyone reads. More funding for special forces. A new center for autonomous warfare. And less control over the consequences.
What that means is written in the history of drones. At first, every operation was said to be carefully reviewed. Over the years, the chain tightened, and in the end there was often little left but confirmation, a click that completes the process instead of questioning it. Other commands are moving the same way. Southern Command in Miami is automating the tracking of drug routes, where speedboats and small submarines are treated as targets. Technically, the step from tracking to attacking is a short one. There is no serious debate about it in Congress. The funding sits in the budget, buried inside special programs and largely shielded from public view.

Rishi Samaroo, one of at least 234 people killed by September 26, 2026, in U.S. military strikes on suspected drug boats in the Caribbean and eastern Pacific. Samaroo was killed on October 14, 2025. As part of our reporting, we were able to locate numerous families of the victims, preserve their accounts and document their stories.
General Stanley McChrystal puts it plainly. He compares the technology to a child that can already kill when it is young and only grows stronger with age. Strength does not provide direction. A system calculates, it does not weigh, and between those 2 things lies everything we later call responsibility. The question is how long the human being remains part of the decision at all when the machine decides faster than he can. Richard Lennane of the International Committee of the Red Cross believes treaties have already shown that they work. Agreements on chemical and biological weapons had limited their use. The same applied to antipersonnel mines and cluster munitions. The punishment mattered less, he said, than the norm that changed how states behaved. A treaty on autonomous weapons could work the same way.
Above all of it stands a warning. UN Secretary-General António Guterres and Red Cross President Mirjana Spoljaric said the world was approaching a moral red line beyond which autonomous weapons could kill people without human involvement. That line was not crossed in Geneva. It simply moved a little closer, in one night, behind closed doors, pushed by 2 delegations with more staying power and more lawyers than anyone else. Nothing is binding yet. The countries meet again in November, and then we will see whether this effort becomes a mandate or whether the paper falls back behind what human beings are still willing to take responsibility for. A machine can hit many targets. It cannot take responsibility for a single one.
Updates – Kaizen News Brief
Alle aktuellen ausgesuchten Tagesmeldungen findet ihr in den Kaizen Kurznachrichten.
To the Kaizen News Brief In English
Ich finde die rote Linie ist längst überschritten.