The US is Leading in Military AI, But Security is a Major Issue

6 mins read
A Representational Image

While a great deal of experts have focused on drone warfare as the new reality in warfare, the AI Revolution is a much bigger deal. AI today enables drones to be far more impactful, helps select and prioritize battle targets, designs tactical operations, and assesses results that go beyond iterative evaluations. While AI is changing the battlefield space, and the US has massive advantages, there are significant risks that AI systems may be compromised by US adversaries, perhaps even by “friends.”

Recently AI has played an important role in a number of conflicts: in the Gaza war (Operation Gideon’s Chariots), in the US-Israel operations against Iran (Operation Rising Lion), in the capture of Nikolas Maduro and his wife in Venezuela (Operation Absolute Resolve), in operations to locate and stop “rogue” oil tankers, and in the Ukraine war, where AI is playing a major role. Should the US and Israel take action against Iran in the coming days, the planning and operations for both will be supported by AI.

While the US and Israel are among the leaders in using AI to support military operations, there are other consequential players. China is well along developing home-grown AI engines; Russia, too, is using AI for drones and for tactical operations; and our allies, especially the UK, France and Germany are implementing AI in their intelligence and military development.

Much of the intelligence integration in the Ukraine war is supported by major western organizations with deep AI capabilities. One of them, Palantir, has emerged as the premier US company in the big data and analytical space (teamed with Nvidia and with Anthropic). In Israel there is a blend of military players, especially Unit 8200, and private sector players that includes well established companies such as Elbit, and startups such as Skyforce for edge-computing, AI-driven battlefield autonomy, Robotican for autonomous robotics and drones, and Radiant Research Labs for zero-click intelligence-gathering tools.

Large Language AI Model engines, systems such as OpenAI (GPT), Google (Gemini), Anthropic (Claude), and Meta (LLaMA) now control 32% of the world market. The Pentagon is now in a major dispute with Anthropic over its use of the Claude engine in the capture of Maduro. Anthropic says it will not allow Claude to be used for military operations, even though Anthropic secured a $200 million contract with the U.S. Department of Defense (DoD) in July 2025 to develop AI for national security.

The number of AI engines, including specialized systems, is rapidly growing. There are roughly 65 to 70 major AI tools that have reached mass-market status in the U.S. (including names like Perplexity for search, Midjourney for art, and Grok for social media). As of 2026, there are over 62,000 AI-related startups globally, with the United States holding the largest share (roughly 25,000–30,000). One recent tally suggests there are now over 90,000 AI companies worldwide, though many are “wrappers” that use the Big Three’s engines to power their own specific services. In the United States, more than $108 billion (so far) has been invested in data centers, not counting collateral investments in electrical power generating and grid improvements. Private investment in AI companies in the United States reached a record $109.1 billion, according to the 2025 AI Index Report from Stanford HAI. Not counting the billions for new foundries and other high end chip-related infrastructure (CHIPS Act), the US government is investing billions every year in AI research and development and in specific applications. Over time, these investments will reshape the federal government’s workforce, possibly eliminating tens of thousands of jobs. It will also change military ranks and roles. The Pentagon is investing at least $2 billion a year directly, and tens of billions indirectly via procurement of weapons, creating a future AI juggernaut that few competitors can hope to match.

This is bad news for Russia over time, as Russia lacks both the infrastructure and the investment dollars to come close to matching US money and capabilities.

Russia is using AI in drones such as the Geran-2 and the Zala Lancet. These drones are powered by older type NVIDIA chip sets which Russia acquires on the gray market. Russia also has introduced the “Svod” AI System. In early 2026, Russia began rolling out Svod, a tactical situational awareness system. It uses AI to aggregate data from satellites and drones into a single map for commanders. Crucially, it is designed to “model scenarios,” offering Russian officers pre-calculated tactical options. Svod was developed as a collaborative effort between Russia’s Ministry of Defense research institutes and civilian software engineers tasked with digitizing the Russian military’s “kill chain.” It is designed to solve Russia’s historical “command bottleneck” by aggregating data from satellites, drones, and reconnaissance reports into a single digital “operational picture.” It is built on the domestically developed Astra Linux operating system to ensure “technological sovereignty” and reduce dependence on Western software. For its primary function—identifying targets in drone feeds and satellite imagery—Svod utilizes the YOLO (You Only Look Once) framework. This is the global standard for real-time object detection and is highly efficient for battlefield hardware. To process text-based intelligence reports and “reconnaissance summaries,” developers have adapted models like Mistral (French) and LLaMA (Meta).

These are embedded in on-premise, air-gapped environments to ensure data doesn’t leak back to Western servers. There is increasing evidence that Russian developers are incorporating Qwen (developed by Alibaba, China), as its architecture is particularly adept at the complex coding and logic tasks required for situational modeling.

On the front lines, the Russian AI runs on “tactical tablets” and small, ruggedized computers. Due to sanctions, these often rely on smuggled or dual-use Chinese chips rather than specialized Russian silicon. Complex scenario modeling (predicting where a Ukrainian counter-attack might occur) is handled by regional command centers using server clusters that utilize diverted high-end GPUs (NVIDIA H100s/A100s) obtained through third-party intermediaries.

Russia faces some significant hurdles in applying battlefield AI and netcentric warfare, namely communications. Ukraine has a distinct advantage because it uses Elon Musk’s Starlink for the backbone of its communications, a system that presently is very difficult for Russia to jam or disrupt. Russia’s access to Starlink has been cut off, leaving them with ad hoc communications that are far more vulnerable to disruption, far less reliable, and lacking the bandwidth Starlink provides to Ukraine. While Russia is in the midst of trying to figure out alternatives, it will be some time before a workaround is found (if ever).

Meanwhile, Russia reportedly is concentrating on rougher and less elegant AI solutions making use of outside support, mainly Chinese, in projects. Over time, there is little hope the Russians can remain competitive unless the Russians can work out a modus vivendi with the United States, much as China appears to have done when it comes to trading off rare earths access to NVIDIA products.

China is far ahead of Russia in the AI space, although still playing catchup with the United States. The one wild card, when it comes to China, is its lack of modern battlefield experience. Thus China will have to build its AI schemes on estimates of battle effectiveness instead of real world data, unless of course Chinese intelligence penetrates Western systems successfully and over a long term.

Little is known about the security of AI machines. The Pentagon, and US intelligence agencies, will need to rely on commercial AI products, especially for real-time updates on threats and countermeasures. The recent Pentagon debacle on cloud computing systems, where it allowed Chinese engineers to provide “routine” service, suggests that so far at least the downside risks of relying on commercial systems are not part of Pentagon thinking. Nor does the Department of War have much free choice, as it does not own AI engines and outsources their use, either directly, or through defense contractors. Security of AI could become the Achilles’ heel for US AI systems. Certainly AI machines and communications will become a major target for America’s adversaries.

For example, in February 2026, Google’s Threat Intelligence Group reported a surge in “model extraction” attacks. Adversaries (notably from China) used automated scripts to send hundreds of thousands of prompts to Gemini to reverse-engineer its internal logic and “steal” the proprietary reasoning capabilities for their own domestic models.

A 2025 Gartner study revealed that 32% of organizations reported their AI applications had been targeted via malicious prompts. State-sponsored hackers use these “jailbreaks” to force AI agents to leak sensitive data or bypass safety filters to generate malicious code.

In late 2025, reports surfaced that a Moscow-based network dubbed “Pravda” successfully “infected” several popular AI chatbots. By flooding the internet with specific narratives, they ensured that when users asked about certain geopolitical events, the AI would repeat Russian propaganda roughly 33% of the time.

Attacks are not only related to Russia and China. Iran and North Korea have joined the fray, and other “friends” may also seek commercial advantage by attacking and exploiting AI applications, or simply by using them for their own military, economic and social operations. Given the national security significance of AI, both for military use and economic security (including energy security), much greater attention to AI system security is not only warranted, but mandatory.

Stephen Bryen

Stephen Bryen is a former Deputy Under Secretary of Defense and is a leading expert in security strategy and technology. Bryen writes for Asia Times, American Thinker, Epoch Times, Newsweek, Washington Times, the Jewish Policy Center and others.

Leave a Reply

Your email address will not be published.

Latest from Blog